<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/the-cybersecurity-defenders-podcast" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>The Cybersecurity Defenders Podcast</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/the-cybersecurity-defenders-podcast</itunes:new-feed-url>
    <description>An accessible but technical podcast about cybersecurity and the people who keep the internet safe. The podcast is built as a series of segments: we will be looking back at the last couple of weeks in cybersecurity news, talking to different people in the industry about areas of their expertise, we're going to break apart some of the TTPs being used by adversaries, and we will even cover a little bit of hacker history.</description>
    <copyright>© 2023 LimaCharlie</copyright>
    <podcast:guid>ec0956e8-7b54-5e15-9a35-7cb62195abd3</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <podcast:trailer pubdate="Tue, 02 Jan 2024 14:58:57 -0100" url="https://media.transistor.fm/ed29a09b/78fe5a53.mp3" length="1770084" type="audio/mpeg" season="3">Podcast trailer for 2024</podcast:trailer>
    <language>en-us</language>
    <pubDate>Thu, 13 Aug 2026 21:41:53 +0000</pubDate>
    <lastBuildDate>Thu, 13 Aug 2026 21:42:07 +0000</lastBuildDate>
    <link>http://limacharlie.io</link>
    <image>
      <url>https://img.transistorcdn.com/ff92d0o9zIglqt3tjSWPXt-mHH-KX-mEkUVdZSbDvxc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wYWM3/Zjc5ODIwM2E4YmQx/ZTE3YWVlZDVhZjc3/YmQzNS5wbmc.jpg</url>
      <title>The Cybersecurity Defenders Podcast</title>
      <link>http://limacharlie.io</link>
    </image>
    <itunes:category text="Technology"/>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <itunes:type>episodic</itunes:type>
    <itunes:author>LimaCharlie</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/ff92d0o9zIglqt3tjSWPXt-mHH-KX-mEkUVdZSbDvxc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wYWM3/Zjc5ODIwM2E4YmQx/ZTE3YWVlZDVhZjc3/YmQzNS5wbmc.jpg"/>
    <itunes:summary>An accessible but technical podcast about cybersecurity and the people who keep the internet safe. The podcast is built as a series of segments: we will be looking back at the last couple of weeks in cybersecurity news, talking to different people in the industry about areas of their expertise, we're going to break apart some of the TTPs being used by adversaries, and we will even cover a little bit of hacker history.</itunes:summary>
    <itunes:subtitle>An accessible but technical podcast about cybersecurity and the people who keep the internet safe.</itunes:subtitle>
    <itunes:keywords></itunes:keywords>
    <itunes:owner>
      <itunes:name>Christopher</itunes:name>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>Proving the value of security operations with Christopher Crowley [344]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>344</itunes:episode>
      <podcast:episode>344</podcast:episode>
      <itunes:title>Proving the value of security operations with Christopher Crowley [344]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fba240f1-a145-4710-91dc-c8a2d6711536</guid>
      <link>https://share.transistor.fm/s/f2e8a235</link>
      <description>
        <![CDATA[<p>Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.</p><p>Christopher is a cybersecurity practitioner and educator focused on security operations, incident response, threat hunting, and building and maturing security operations centers. He is the author of the annual SANS SOC Survey, a security operations class called SOC-Class, and a new book entitled The Value of Cybersecurity Operations. He is a Senior Instructor with the SANS Institute, a faculty member at IANS, and a consultant through Montance. His background also includes network operations, software development, mobile security assessment, and security policy.</p><p>Learn more at https://montance.com and get the book at https://shop.montance.com</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at https://limacharlie.io/</p><p>Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.</p><p>Christopher is a cybersecurity practitioner and educator focused on security operations, incident response, threat hunting, and building and maturing security operations centers. He is the author of the annual SANS SOC Survey, a security operations class called SOC-Class, and a new book entitled The Value of Cybersecurity Operations. He is a Senior Instructor with the SANS Institute, a faculty member at IANS, and a consultant through Montance. His background also includes network operations, software development, mobile security assessment, and security policy.</p><p>Learn more at https://montance.com and get the book at https://shop.montance.com</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at https://limacharlie.io/</p><p>Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p>]]>
      </content:encoded>
      <pubDate>Thu, 13 Aug 2026 16:52:42 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f2e8a235/f49d7816.mp3" length="40584475" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2535</itunes:duration>
      <itunes:summary>Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.</itunes:summary>
      <itunes:subtitle>Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is chang</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Intel Chat: Shai-Hulud is back, model pinning &amp; the token spend problem [343]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>343</itunes:episode>
      <podcast:episode>343</podcast:episode>
      <itunes:title>Intel Chat: Shai-Hulud is back, model pinning &amp; the token spend problem [343]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ce2383d4-430a-4729-a195-3904ad37a4b2</guid>
      <link>https://share.transistor.fm/s/92522306</link>
      <description>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.</p><p>No prep doc, no script: just what Matt and Chris were actually hearing on the floor.</p><p>• Shai-Hulud is back. The self-replicating npm worm returned on August 4, trojanizing the keyv / cacheable family and spreading to 400+ packages within hours. Chris reads through Datadog Security Labs' analysis of the Shai-Hulud 2.0 wave: 796 packages and 1,092 versions, 20M+ weekly downloads, credential harvesting with TruffleHog, GitHub repositories used for both exfiltration and command and control, and a worm that reads its own code to propagate without a C2 server.<br>• The LLM that downloaded the malicious package by itself. A researcher asked a frontier model about a compromised package, and the model decided the best way to help was to go fetch a copy — tripping the SOC's alert and bypassing the company's centralized package clearing house on the way.<br>• Non-human identity as the new perimeter. Every agent you introduce is another identity: who created it, what can it reach, how long should it live?<br>• "Computer says no." Matt's colleague hit a refusal from Opus 5, and the session automatically downgraded to 4.8 and completed the task. Which raises the real question of the episode: do security teams now need model pinning, the way we once needed certificate pinning? And if defenders pin to older models to keep working while adversaries use the newest ones, have we rebuilt the same gap all over again?<br>• AI governance and change control — which models are approved for which tasks, and what happens when a vendor ships a new version or deprecates an old one.<br>• Token spend as a CISO budget line item. Enterprises buying tokens at a scale their vendors can't match and pulling those vendors onto their plan, token burn as an insider-threat vector, and why $100,000 of tokens is not $100,000 of productivity.<br>• Defender takeaways: pin your npm packages, get security off its island and talk to your developers, build approved paths before detections, least privilege and key rotation, and network-gated pushes as a deliberate chokepoint.</p><p>Stories covered:<br>• https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain<br>• https://research.jfrog.com/post/shai-hulud-is-back-august/<br>• https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/<br>• https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/<br>• https://unit42.paloaltonetworks.com/npm-supply-chain-attack/</p><p>Chapters:<br>0:00 Live from Black Hat, in person for once<br>0:48 How Black Hat has changed<br>4:31 No prep — let's talk about what's actually happening here<br>4:57 Shai-Hulud is back: supply chain compromise<br>6:23 The LLM that downloaded the malicious package<br>7:19 Inside Shai-Hulud 2.0<br>10:34 When attackers and defenders use the same tools<br>11:39 Non-human identity is the new perimeter<br>12:13 Opus 5 said no, so the session downgraded itself<br>15:23 Do security teams need model pinning?<br>18:20 Three companies, very nebulous rules<br>18:35 AI governance: which model for which task<br>21:19 Token spend hits the security budget<br>22:58 Is token spend a productivity metric?<br>25:46 Pin your packages<br>26:25 Get security off the island<br>29:17 Least privilege, key rotation, chokepoints<br>32:55 Why it's called Shai-Hulud<br>33:25 Wrapping up at Black Hat</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:<br>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps<br>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740<br>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #supplychainsecurity</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.</p><p>No prep doc, no script: just what Matt and Chris were actually hearing on the floor.</p><p>• Shai-Hulud is back. The self-replicating npm worm returned on August 4, trojanizing the keyv / cacheable family and spreading to 400+ packages within hours. Chris reads through Datadog Security Labs' analysis of the Shai-Hulud 2.0 wave: 796 packages and 1,092 versions, 20M+ weekly downloads, credential harvesting with TruffleHog, GitHub repositories used for both exfiltration and command and control, and a worm that reads its own code to propagate without a C2 server.<br>• The LLM that downloaded the malicious package by itself. A researcher asked a frontier model about a compromised package, and the model decided the best way to help was to go fetch a copy — tripping the SOC's alert and bypassing the company's centralized package clearing house on the way.<br>• Non-human identity as the new perimeter. Every agent you introduce is another identity: who created it, what can it reach, how long should it live?<br>• "Computer says no." Matt's colleague hit a refusal from Opus 5, and the session automatically downgraded to 4.8 and completed the task. Which raises the real question of the episode: do security teams now need model pinning, the way we once needed certificate pinning? And if defenders pin to older models to keep working while adversaries use the newest ones, have we rebuilt the same gap all over again?<br>• AI governance and change control — which models are approved for which tasks, and what happens when a vendor ships a new version or deprecates an old one.<br>• Token spend as a CISO budget line item. Enterprises buying tokens at a scale their vendors can't match and pulling those vendors onto their plan, token burn as an insider-threat vector, and why $100,000 of tokens is not $100,000 of productivity.<br>• Defender takeaways: pin your npm packages, get security off its island and talk to your developers, build approved paths before detections, least privilege and key rotation, and network-gated pushes as a deliberate chokepoint.</p><p>Stories covered:<br>• https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain<br>• https://research.jfrog.com/post/shai-hulud-is-back-august/<br>• https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/<br>• https://securitylabs.datadoghq.com/articles/npm-worm-compromises-popular-npm-packages/<br>• https://unit42.paloaltonetworks.com/npm-supply-chain-attack/</p><p>Chapters:<br>0:00 Live from Black Hat, in person for once<br>0:48 How Black Hat has changed<br>4:31 No prep — let's talk about what's actually happening here<br>4:57 Shai-Hulud is back: supply chain compromise<br>6:23 The LLM that downloaded the malicious package<br>7:19 Inside Shai-Hulud 2.0<br>10:34 When attackers and defenders use the same tools<br>11:39 Non-human identity is the new perimeter<br>12:13 Opus 5 said no, so the session downgraded itself<br>15:23 Do security teams need model pinning?<br>18:20 Three companies, very nebulous rules<br>18:35 AI governance: which model for which task<br>21:19 Token spend hits the security budget<br>22:58 Is token spend a productivity metric?<br>25:46 Pin your packages<br>26:25 Get security off the island<br>29:17 Least privilege, key rotation, chokepoints<br>32:55 Why it's called Shai-Hulud<br>33:25 Wrapping up at Black Hat</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:<br>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps<br>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740<br>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #supplychainsecurity</p>]]>
      </content:encoded>
      <pubDate>Sat, 08 Aug 2026 16:52:58 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/92522306/33fed954.mp3" length="34280693" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2141</itunes:duration>
      <itunes:summary>Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.</itunes:summary>
      <itunes:subtitle>Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno &amp; Paidwork leaks, AWS Bahrain strike [342]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>342</itunes:episode>
      <podcast:episode>342</podcast:episode>
      <itunes:title>Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno &amp; Paidwork leaks, AWS Bahrain strike [342]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d628f27d-a560-4c40-96cc-50982ab6a4f8</guid>
      <link>https://share.transistor.fm/s/536dff36</link>
      <description>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.</p><p>• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.</p><p>• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.</p><p>• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.</p><p>Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.</p><p>Stories covered:</p><p>• https://huggingface.co/blog/security-incident-july-2026</p><p>• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover</p><p>• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/</p><p>• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plant</p><p>Chapters:</p><p>0:00 Intro &amp; Black Hat plans</p><p>2:07 Hugging Face's AI-agent breach disclosure</p><p>12:39 WP2Shell: WordPress exploit chain</p><p>20:59 Suno &amp; Paidwork data breaches</p><p>24:17 IRGC strikes on AWS Bahrain</p><p>28:27 Google Threat Intel's new actor names</p><p>29:29 Black Hat swag hunt &amp; wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740</p><p>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #databreach</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Hugging Face's security incident disclosure: an intrusion conducted end-to-end by an autonomous AI agent system — a malicious dataset exploiting two code-execution paths, thousands of actions across short-lived sandboxes, self-migrating C2 — and why the forensics had to run on the open-weight GLM 5.2 model after hosted frontier models refused to analyze real attack artifacts.</p><p>• WP2Shell: attackers chaining CVE-2026-60137 (WordPress Core SQL injection) with CVE-2026-63030 (Batch REST API logic flaw) for unauthenticated remote code execution on default WordPress installs — found by Searchlight Cyber using GPT-5.6 Sol Ultra in about ten hours, with tens of thousands of exploitation attempts following disclosure.</p><p>• Data breaches at AI music generator Suno (55.3M unique email addresses, plus partial Stripe payment records) and gig-work platform Paidwork (23.3M addresses, password hashes and banking data), per Have I Been Pwned.</p><p>• Iranian state media claims the IRGC destroyed AWS's Bahrain data center (ME-SOUTH-1) with cruise missiles — and what data centers becoming military targets means for cloud resilience.</p><p>Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat.</p><p>Stories covered:</p><p>• https://huggingface.co/blog/security-incident-july-2026</p><p>• https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover</p><p>• https://www.securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts/</p><p>• https://www.tomshardware.com/tech-industry/data-centers/amazon-data-center-in-bahrain-struck-and-destroyed-by-iranian-cruise-missiles-state-media-claims-attacks-launched-against-aws-site-in-response-to-alleged-us-strikes-on-an-under-construction-nuclear-plant</p><p>Chapters:</p><p>0:00 Intro &amp; Black Hat plans</p><p>2:07 Hugging Face's AI-agent breach disclosure</p><p>12:39 WP2Shell: WordPress exploit chain</p><p>20:59 Suno &amp; Paidwork data breaches</p><p>24:17 IRGC strikes on AWS Bahrain</p><p>28:27 Google Threat Intel's new actor names</p><p>29:29 Black Hat swag hunt &amp; wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740</p><p>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #databreach</p>]]>
      </content:encoded>
      <pubDate>Thu, 30 Jul 2026 20:34:30 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/536dff36/844f21ab.mp3" length="43573672" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1815</itunes:duration>
      <itunes:summary>Intel Chat with Matt Bromiley and Chris Luft.</itunes:summary>
      <itunes:subtitle>Intel Chat with Matt Bromiley and Chris Luft.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Building trustworthy AI with Rob van der Veer [341]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>341</itunes:episode>
      <podcast:episode>341</podcast:episode>
      <itunes:title>Building trustworthy AI with Rob van der Veer [341]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a56c9313-bb84-4acc-af84-06253124b994</guid>
      <link>https://share.transistor.fm/s/841fbcab</link>
      <description>
        <![CDATA[<p>Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.</p><p>Rob is a global leader in AI security, software engineering, and international AI standards, with more than 30 years of experience in artificial intelligence. He has played a leading role in developing industry standards and serves as co-editor of the forthcoming European AI security standard supporting the EU AI Act. He is the founder of the OWASP AI Exchange, co-founder of OpenCRE, and has helped bring together standards organizations, industry, and the open-source community to advance practical approaches to secure AI.</p><p>Learn more at https://www.softwareimprovementgroup.com and https://owaspai.org</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at https://limacharlie.io/</p><p>Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.</p><p>Rob is a global leader in AI security, software engineering, and international AI standards, with more than 30 years of experience in artificial intelligence. He has played a leading role in developing industry standards and serves as co-editor of the forthcoming European AI security standard supporting the EU AI Act. He is the founder of the OWASP AI Exchange, co-founder of OpenCRE, and has helped bring together standards organizations, industry, and the open-source community to advance practical approaches to secure AI.</p><p>Learn more at https://www.softwareimprovementgroup.com and https://owaspai.org</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at https://limacharlie.io/</p><p>Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Jul 2026 15:52:26 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/841fbcab/65b78e8d.mp3" length="33729431" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2107</itunes:duration>
      <itunes:summary>Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.</itunes:summary>
      <itunes:subtitle>Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, a</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>340</itunes:episode>
      <podcast:episode>340</podcast:episode>
      <itunes:title>AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">63b4b1b9-4bfd-4424-818b-3f81d6d7474a</guid>
      <link>https://share.transistor.fm/s/6eb0838e</link>
      <description>
        <![CDATA[<p>AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode.</p><p>One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.</p><p>In this episode:</p><p>• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.</p><p>• The attack chain: a malicious dataset abusing two code-execution paths in the dataset-processing pipeline, node-level escalation, credential harvesting and lateral movement — thousands of actions across short-lived sandboxes with self-migrating command-and-control.</p><p>• The escape: a zero-day in the eval sandbox's package-registry cache proxy, the single egress control — per OpenAI's own account.</p><p>• Motive: the models got "hyperfocused" on winning the benchmark, not stealing data — and whether "no malicious intent" is a fair description or a comforting one.</p><p>• What was and wasn't exposed, what to do about your Hugging Face tokens, and why this is not the 2024 Spaces incident or the 2023 OpenAI forum hack.</p><p>• Max's hot take: the beginning of the phase where we lock developers out of writing code — and a new fear unlocked: models backdooring other models.</p><p>Stories covered:</p><p>• https://huggingface.co/blog/security-...</p><p>• https://openai.com/index/hugging-face...</p><p>Chapters:</p><p>0:00 Cold open — the attacker was the model</p><p>2:20 The whole story in one breath</p><p>6:41 The timeline: two disclosures, five days apart</p><p>11:37 Attack chain, part 1: getting in through a malicious dataset</p><p>15:53 Attack chain, part 2: escaping the eval sandbox</p><p>22:10 Motive, attribution &amp; intent: cheating on the benchmark</p><p>25:31 What was (and wasn't) exposed</p><p>28:08 The bigger picture: the fire drill started the fire</p><p>31:39 Lessons for labs, platforms, and solo developers</p><p>33:15 New fear unlocked: models backdooring models</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00ze...</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast...</p><p>• YouTube:    / @limacharlieio  </p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #AIsecurity #OpenAI #HuggingFace #infosec</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode.</p><p>One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.</p><p>In this episode:</p><p>• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.</p><p>• The attack chain: a malicious dataset abusing two code-execution paths in the dataset-processing pipeline, node-level escalation, credential harvesting and lateral movement — thousands of actions across short-lived sandboxes with self-migrating command-and-control.</p><p>• The escape: a zero-day in the eval sandbox's package-registry cache proxy, the single egress control — per OpenAI's own account.</p><p>• Motive: the models got "hyperfocused" on winning the benchmark, not stealing data — and whether "no malicious intent" is a fair description or a comforting one.</p><p>• What was and wasn't exposed, what to do about your Hugging Face tokens, and why this is not the 2024 Spaces incident or the 2023 OpenAI forum hack.</p><p>• Max's hot take: the beginning of the phase where we lock developers out of writing code — and a new fear unlocked: models backdooring other models.</p><p>Stories covered:</p><p>• https://huggingface.co/blog/security-...</p><p>• https://openai.com/index/hugging-face...</p><p>Chapters:</p><p>0:00 Cold open — the attacker was the model</p><p>2:20 The whole story in one breath</p><p>6:41 The timeline: two disclosures, five days apart</p><p>11:37 Attack chain, part 1: getting in through a malicious dataset</p><p>15:53 Attack chain, part 2: escaping the eval sandbox</p><p>22:10 Motive, attribution &amp; intent: cheating on the benchmark</p><p>25:31 What was (and wasn't) exposed</p><p>28:08 The bigger picture: the fire drill started the fire</p><p>31:39 Lessons for labs, platforms, and solo developers</p><p>33:15 New fear unlocked: models backdooring models</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00ze...</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast...</p><p>• YouTube:    / @limacharlieio  </p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #AIsecurity #OpenAI #HuggingFace #infosec</p>]]>
      </content:encoded>
      <pubDate>Thu, 23 Jul 2026 19:01:01 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6eb0838e/f73fe88d.mp3" length="34040810" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2128</itunes:duration>
      <itunes:summary>In this episode:

• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.
• The attack chain: a malicious dataset abusing two code-execution paths in the dataset-processing pipeline, node-level escalation, credential harvesting and lateral movement — thousands of actions across short-lived sandboxes with self-migrating command-and-control.
• The escape: a zero-day in the eval sandbox's package-registry cache proxy, the single egress control — per OpenAI's own account.
• Motive: the models got "hyperfocused" on winning the benchmark, not stealing data — and whether "no malicious intent" is a fair description or a comforting one.
• What was and wasn't exposed, what to do about your Hugging Face tokens, and why this is not the 2024 Spaces incident or the 2023 OpenAI forum hack.
• Max's hot take: the beginning of the phase where we lock developers out of writing code — and a new fear unlocked: models backdooring other models.</itunes:summary>
      <itunes:subtitle>In this episode:

• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.
• The attack chain: a malicious dataset abusing two code-execution paths in the</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars &amp; shadow AI [339]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>339</itunes:episode>
      <podcast:episode>339</podcast:episode>
      <itunes:title>AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars &amp; shadow AI [339]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d9320545-382a-4b77-b1c6-130e2c9ad12a</guid>
      <link>https://share.transistor.fm/s/4669697e</link>
      <description>
        <![CDATA[<p>AI Chat with Maxime Lamothe-Brassard and Chris Luft.</p><p>A new segment on the podcast: AI news in cybersecurity that is less than 24 hours old, discussed while it is still hot. Joining Chris for these conversations is LimaCharlie founder and CEO Maxime Lamothe-Brassard.</p><p>In this episode:</p><p>• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you used the tool.</p><p>• Fortinet's take (via Mexico Business News) on AI accelerating vulnerability discovery and exploitation: 24–48 hours from disclosure to active exploitation vs. 16 days to patch — and whether "virtual patching" is a real mitigation or a feat of marketing.</p><p>• The AI distillation debate: after years of arguing fair use for scraping the internet, frontier labs now object to competitors training on their model outputs — Business Insider's look at the irony, shared by Pascal Hetzscholdt (Wiley).</p><p>• Neon Cyber's survey on shadow AI rising with seniority: 14% of individual contributors use unapproved AI tools vs. 63.7% of managers and 70% of VPs and above — and why enforcement, not awareness, is the real challenge.</p><p>Stories covered:</p><p>•   / guptanipun_my-spare-laptop-ran-completely-...  </p><p>• https://mexicobusiness.news/cybersecu...</p><p>•   / pascal-hetzscholdt_quote-heres-some-delici...  </p><p>• https://neoncyber.com/blog/shadow-ai-...</p><p>Chapters:</p><p>0:00 Intro — welcome to AI Chat</p><p>0:45 Grok Build CLI uploading entire repos (Nipun Gupta / Optimus Labs)</p><p>4:57 AI is outpacing patch management — is virtual patching the answer?</p><p>12:32 The AI distillation debate: scraping irony at the frontier labs</p><p>16:29 Shadow AI use rises with seniority (Neon Cyber)</p><p>22:51 Wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00ze...</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast...</p><p>• YouTube:    / @limacharlieio  </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>AI Chat with Maxime Lamothe-Brassard and Chris Luft.</p><p>A new segment on the podcast: AI news in cybersecurity that is less than 24 hours old, discussed while it is still hot. Joining Chris for these conversations is LimaCharlie founder and CEO Maxime Lamothe-Brassard.</p><p>In this episode:</p><p>• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you used the tool.</p><p>• Fortinet's take (via Mexico Business News) on AI accelerating vulnerability discovery and exploitation: 24–48 hours from disclosure to active exploitation vs. 16 days to patch — and whether "virtual patching" is a real mitigation or a feat of marketing.</p><p>• The AI distillation debate: after years of arguing fair use for scraping the internet, frontier labs now object to competitors training on their model outputs — Business Insider's look at the irony, shared by Pascal Hetzscholdt (Wiley).</p><p>• Neon Cyber's survey on shadow AI rising with seniority: 14% of individual contributors use unapproved AI tools vs. 63.7% of managers and 70% of VPs and above — and why enforcement, not awareness, is the real challenge.</p><p>Stories covered:</p><p>•   / guptanipun_my-spare-laptop-ran-completely-...  </p><p>• https://mexicobusiness.news/cybersecu...</p><p>•   / pascal-hetzscholdt_quote-heres-some-delici...  </p><p>• https://neoncyber.com/blog/shadow-ai-...</p><p>Chapters:</p><p>0:00 Intro — welcome to AI Chat</p><p>0:45 Grok Build CLI uploading entire repos (Nipun Gupta / Optimus Labs)</p><p>4:57 AI is outpacing patch management — is virtual patching the answer?</p><p>12:32 The AI distillation debate: scraping irony at the frontier labs</p><p>16:29 Shadow AI use rises with seniority (Neon Cyber)</p><p>22:51 Wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00ze...</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast...</p><p>• YouTube:    / @limacharlieio  </p>]]>
      </content:encoded>
      <pubDate>Tue, 14 Jul 2026 21:29:33 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4669697e/c30671cc.mp3" length="22367563" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1398</itunes:duration>
      <itunes:summary>• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet server-side fix, and why you should rotate keys if you used the tool.
• Fortinet's take (via Mexico Business News) on AI accelerating vulnerability discovery and exploitation: 24–48 hours from disclosure to active exploitation vs. 16 days to patch — and whether "virtual patching" is a real mitigation or a feat of marketing.
• The AI distillation debate: after years of arguing fair use for scraping the internet, frontier labs now object to competitors training on their model outputs — Business Insider's look at the irony, shared by Pascal Hetzscholdt (Wiley).
• Neon Cyber's survey on shadow AI rising with seniority: 14% of individual contributors use unapproved AI tools vs. 63.7% of managers and 70% of VPs and above — and why enforcement, not awareness, is the real challenge.</itunes:summary>
      <itunes:subtitle>• Nipun Gupta (founder of Optimus Labs) reports that xAI's Grok Build CLI packaged and uploaded an entire local Git repository — commit history, branches and .env files with API keys — to a Google Cloud bucket; wire-level analysis via mitmproxy, a quiet s</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline &amp; HalluSquatting [338]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>338</itunes:episode>
      <podcast:episode>338</podcast:episode>
      <itunes:title>Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline &amp; HalluSquatting [338]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">dc434cad-4471-42d0-aeb5-185b6593d1aa</guid>
      <link>https://share.transistor.fm/s/6f663f4d</link>
      <description>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.</p><p>• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.</p><p>• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.</p><p>• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.</p><p>Stories covered:</p><p>• https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft</p><p>• https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html</p><p>• https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/</p><p>• https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html</p><p>Chapters:</p><p>0:00 Intro &amp; catching up</p><p>4:31 Google Dialogflow CX "Rogue Agent" flaw</p><p>11:03 EvilTokens &amp; "ghost phishing"</p><p>17:37 CISA KEV: ColdFusion, Langflow &amp; Joomla — patch by July 10</p><p>24:56 HalluSquatting: weaponizing AI hallucinations</p><p>33:16 Wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740</p><p>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #phishing</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.</p><p>• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.</p><p>• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.</p><p>• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.</p><p>Stories covered:</p><p>• https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft</p><p>• https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html</p><p>• https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/</p><p>• https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.html</p><p>Chapters:</p><p>0:00 Intro &amp; catching up</p><p>4:31 Google Dialogflow CX "Rogue Agent" flaw</p><p>11:03 EvilTokens &amp; "ghost phishing"</p><p>17:37 CISA KEV: ColdFusion, Langflow &amp; Joomla — patch by July 10</p><p>24:56 HalluSquatting: weaponizing AI hallucinations</p><p>33:16 Wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740</p><p>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #phishing</p>]]>
      </content:encoded>
      <pubDate>Thu, 09 Jul 2026 15:44:38 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6f663f4d/3065046f.mp3" length="33064814" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2067</itunes:duration>
      <itunes:summary>Matt and Chris break down four stories from the week in threat intel:

• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.
• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.
• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.
• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.</itunes:summary>
      <itunes:subtitle>Matt and Chris break down four stories from the week in threat intel:

• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbook</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Ransomware in the age of agentic AI with Behnaz Karimi [337]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>337</itunes:episode>
      <podcast:episode>337</podcast:episode>
      <itunes:title>Ransomware in the age of agentic AI with Behnaz Karimi [337]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bbb459bc-2099-4394-9fb2-ae7b5ca4c03d</guid>
      <link>https://share.transistor.fm/s/5c496e04</link>
      <description>
        <![CDATA[<p>Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.</p><p>With more than 20 years of experience in cybersecurity, Behnaz is also a leader within the OWASP AI Exchange, where she helps develop AI security frameworks and contributes to international AI security standards. In this conversation we cover the new generation of data-poisoning ransomware, why stolen models and datasets are becoming the ransom, what makes autonomous agents an entirely new attack surface, and how organizations can build resilience into their AI initiatives from day one.</p><p>Learn more about the OWASP AI Exchange at https://owaspai.org/</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. </p><p>Start today for free at https://limacharlie.io/</p><p>Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.</p><p>With more than 20 years of experience in cybersecurity, Behnaz is also a leader within the OWASP AI Exchange, where she helps develop AI security frameworks and contributes to international AI security standards. In this conversation we cover the new generation of data-poisoning ransomware, why stolen models and datasets are becoming the ransom, what makes autonomous agents an entirely new attack surface, and how organizations can build resilience into their AI initiatives from day one.</p><p>Learn more about the OWASP AI Exchange at https://owaspai.org/</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. </p><p>Start today for free at https://limacharlie.io/</p><p>Subscribe to The Cybersecurity Defenders Podcast on Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p>]]>
      </content:encoded>
      <pubDate>Wed, 08 Jul 2026 21:04:45 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5c496e04/00f754bd.mp3" length="31796694" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1988</itunes:duration>
      <itunes:summary>Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.</itunes:summary>
      <itunes:subtitle>Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learn</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide &amp; Claude export controls [336]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>336</itunes:episode>
      <podcast:episode>336</podcast:episode>
      <itunes:title>Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide &amp; Claude export controls [336]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">eff57d66-d9a1-451e-8921-522d5fe9bf40</guid>
      <link>https://share.transistor.fm/s/f9846799</link>
      <description>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.</p><p><a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops">https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops</a></p><p>• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.</p><p><a rel="noreferrer noopener" href="https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/">https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/</a></p><p>• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.</p><p><a rel="noreferrer noopener" href="https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html">https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html</a></p><p>• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.</p><p><a rel="noreferrer noopener" href="https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html">https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html</a></p><p>Chapters:</p><p>0:00 Intro &amp; catching up</p><p>1:17 Attackers hijacking exposed AI backends (Ollama &amp; LiteLLM)</p><p>9:18 CISA advisory: billboard &amp; highway sign controllers</p><p>13:46 Cursor "DuneSlide" prompt-injection sandbox escape</p><p>20:34 Claude Fable 5 export controls lifted</p><p>28:17 Data centers, nuclear déjà vu &amp; the AI race</p><p>33:39 Wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #promptinjection</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.</p><p><a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops">https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops</a></p><p>• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.</p><p><a rel="noreferrer noopener" href="https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/">https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/</a></p><p>• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.</p><p><a rel="noreferrer noopener" href="https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html">https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html</a></p><p>• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.</p><p><a rel="noreferrer noopener" href="https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html">https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html</a></p><p>Chapters:</p><p>0:00 Intro &amp; catching up</p><p>1:17 Attackers hijacking exposed AI backends (Ollama &amp; LiteLLM)</p><p>9:18 CISA advisory: billboard &amp; highway sign controllers</p><p>13:46 Cursor "DuneSlide" prompt-injection sandbox escape</p><p>20:34 Claude Fable 5 export controls lifted</p><p>28:17 Data centers, nuclear déjà vu &amp; the AI race</p><p>33:39 Wrap-up</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #AIsecurity #promptinjection</p>]]>
      </content:encoded>
      <pubDate>Fri, 03 Jul 2026 18:07:56 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f9846799/0ee63330.mp3" length="16265398" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2033</itunes:duration>
      <itunes:summary>Matt and Chris break down four stories from the week in threat intel:

• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.
• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.
• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.
• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.</itunes:summary>
      <itunes:subtitle>Matt and Chris break down four stories from the week in threat intel:

• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — inclu</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon &amp; AI agent phishing [335]</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>335</itunes:episode>
      <podcast:episode>335</podcast:episode>
      <itunes:title>Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon &amp; AI agent phishing [335]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0a23431d-6d6a-44fb-a65d-52c638b6a189</guid>
      <link>https://share.transistor.fm/s/60500cfb</link>
      <description>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.</p><p>• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.</p><p>• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.</p><p>• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.</p><p>Chapters:</p><p>0:00 Intro &amp; catching up</p><p>2:25 Cisco CUCM exploited within 24h of the PoC</p><p>9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce &amp; Warlock</p><p>15:44 Gamaredon's upgraded TTPs against Ukraine</p><p>22:18 Can AI email agents be phished?</p><p>28:08 Wrap-up: Black Hat plans &amp; the LimaCharlie suite</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740</p><p>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #ransomware #DFIR</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Intel Chat with Matt Bromiley and Chris Luft.</p><p>Matt and Chris break down four stories from the week in threat intel:</p><p>• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.</p><p>• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.</p><p>• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.</p><p>• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.</p><p>Chapters:</p><p>0:00 Intro &amp; catching up</p><p>2:25 Cisco CUCM exploited within 24h of the PoC</p><p>9:57 Ransomware Tool Matrix: The Gentlemen, DragonForce &amp; Warlock</p><p>15:44 Gamaredon's upgraded TTPs against Ukraine</p><p>22:18 Can AI email agents be phished?</p><p>28:08 Wrap-up: Black Hat plans &amp; the LimaCharlie suite</p><p>The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.</p><p>Subscribe wherever you listen:</p><p>• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps</p><p>• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740</p><p>• YouTube: https://www.youtube.com/@limacharlieio</p><p>Learn more about LimaCharlie: https://limacharlie.io</p><p>#cybersecurity #infosec #threatintel #ransomware #DFIR</p>]]>
      </content:encoded>
      <pubDate>Wed, 01 Jul 2026 15:47:48 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/60500cfb/e885d8d8.mp3" length="28816822" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1801</itunes:duration>
      <itunes:summary>Matt and Chris break down four stories from the week in threat intel:

• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.
• The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three active groups — The Gentlemen, DragonForce and Warlock — and the BYOVD and legit-admin-tool tradecraft they increasingly share.
• Gamaredon's upgraded toolkit against Ukraine (per ESET): new PowerShell downloaders like PteroPaste, Cloudflare tunneling and Workers for C2, and exfiltration to trusted cloud storage such as Amazon S3 and Dropbox.
• Varonis Threat Labs phishing an AI email agent ("Pinchy") — why agents spot technical phishing better than humans yet hand over credentials to a convincing social request, and why you should treat them as privileged junior employees.</itunes:summary>
      <itunes:subtitle>Matt and Chris break down four stories from the week in threat intel:

• Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published.
• The lat</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>The evolving fraud landscape in the age of AI with Tamas Kadar [#334]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>334</itunes:episode>
      <podcast:episode>334</podcast:episode>
      <itunes:title>The evolving fraud landscape in the age of AI with Tamas Kadar [#334]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">767cfb6e-87b3-486c-b952-33904815140f</guid>
      <link>https://share.transistor.fm/s/cfe85bf4</link>
      <description>
        <![CDATA[<p>Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it.</p><p>Tamas' entrepreneurial path began at Corvinus University in Budapest, where the vision for SEON first took shape. Co-founding a cryptocurrency exchange opened his eyes to the scale and complexity of online fraud, sparking the idea for something better. In 2017, that “something better” became SEON. Learn more at <a rel="noreferrer noopener" href="https://seon.io/">https://seon.io/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it.</p><p>Tamas' entrepreneurial path began at Corvinus University in Budapest, where the vision for SEON first took shape. Co-founding a cryptocurrency exchange opened his eyes to the scale and complexity of online fraud, sparking the idea for something better. In 2017, that “something better” became SEON. Learn more at <a rel="noreferrer noopener" href="https://seon.io/">https://seon.io/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 30 Jun 2026 17:26:06 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/cfe85bf4/d294509b.mp3" length="61391516" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2558</itunes:duration>
      <itunes:summary>Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it.</itunes:summary>
      <itunes:subtitle>Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Anthropic restriction, ServiceNow incident, Fortinet credential harvesting &amp; Ukraine accesses EU cyber reserve / Intel Chat [#333]</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>Anthropic restriction, ServiceNow incident, Fortinet credential harvesting &amp; Ukraine accesses EU cyber reserve / Intel Chat [#333]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bb3732b6-b8a6-4182-9786-fce4a4b8fd9d</guid>
      <link>https://share.transistor.fm/s/a8d5805f</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Reports state that the US government issued an export control order restricting access to anthropic newly released cloud mythos five and fable five <a rel="noreferrer noopener" href="https://www.semafor.com/article/06/13/2026/white-house-move-to-limit-anthropic-linked-to-concerns-about-chinese-access-to-mythos">models for foreign nationals</a>.</li><li>ServiceNow disclosed a security incident involving an unauthenticated access for an API endpoint that allowed users to query data from customer instances <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/">without proper authentication</a>.</li><li>A large scale credential harvesting campaign dubbed for to bleed is actively targeting Fortinet firewalls and VPN gateways, and has already compromised more than 30,000 internet facing devices <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/sweeping-credential-harvesting-heist-compromises-30k-fortinet-devices">across 194 countries</a>. </li><li>Ukraine has been granted access to the European Union's cyber security reserve, giving the country the ability to request assistance from EU approved cyber security experts during major cyber attacks that exceed <a rel="noreferrer noopener" href="https://therecord.media/ukraine-access-eu-cybersecurity-reserve">its own response capabilities</a>. </li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Reports state that the US government issued an export control order restricting access to anthropic newly released cloud mythos five and fable five <a rel="noreferrer noopener" href="https://www.semafor.com/article/06/13/2026/white-house-move-to-limit-anthropic-linked-to-concerns-about-chinese-access-to-mythos">models for foreign nationals</a>.</li><li>ServiceNow disclosed a security incident involving an unauthenticated access for an API endpoint that allowed users to query data from customer instances <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/">without proper authentication</a>.</li><li>A large scale credential harvesting campaign dubbed for to bleed is actively targeting Fortinet firewalls and VPN gateways, and has already compromised more than 30,000 internet facing devices <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/sweeping-credential-harvesting-heist-compromises-30k-fortinet-devices">across 194 countries</a>. </li><li>Ukraine has been granted access to the European Union's cyber security reserve, giving the country the ability to request assistance from EU approved cyber security experts during major cyber attacks that exceed <a rel="noreferrer noopener" href="https://therecord.media/ukraine-access-eu-cybersecurity-reserve">its own response capabilities</a>. </li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Sun, 28 Jun 2026 20:22:43 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a8d5805f/77a47503.mp3" length="50006991" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ruf2U0-81alZNeJPTShDDgKcfGA3TlPMM3lKzxLcksE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yMWFk/YTk4OGZkZGI3ZWUz/NDJkZTAxOTE2Yjlj/YjI0ZS5wbmc.jpg"/>
      <itunes:duration>2084</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Last call for Defenders - How we're actually using AI in the SOC with Eric Capuano / Defender Fridays [#332]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>332</itunes:episode>
      <podcast:episode>332</podcast:episode>
      <itunes:title>Last call for Defenders - How we're actually using AI in the SOC with Eric Capuano / Defender Fridays [#332]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8e5056dd-55d0-430b-9615-fdc40d1b76d4</guid>
      <link>https://share.transistor.fm/s/c8749f66</link>
      <description>
        <![CDATA[<p>Join us for the final episode of Defender Fridays as Eric Capuano, creator of Defender Fridays and co-founder of Digital Defense Institute, closes out the series with a candid conversation on how he's actually building and running agentic workflows in the SOC today.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Eric Capuano draws on years of SOC operations, detection engineering, and hands-on agentic workflow development to share what's actually working, what isn't, and where the industry needs to be more honest with itself.</p><p>Key Topics:</p><ul><li>Why agentic workflows are the next evolution of SOAR, and what it takes to build them reliably</li><li>How deterministic checkpoints at every stage are essential to making LLM-driven workflows trustworthy</li><li>How one team increased their detection engineering output by 900x using agentic workflows running day and night</li><li>Why false positive tuning and detection engineering are the right place to start before tackling complex investigative workflows</li><li>How to think about model selection in agentic pipelines: cost, task complexity, and stakes</li><li>Why organizations with poor data hygiene will struggle to get value from AI regardless of how sophisticated the tooling is</li><li>The risks of prompt injection when feeding untrusted inputs into LLMs, and why trusted inputs should always come first</li><li>Why the goal is to use LLMs for as little as possible, and push everything else into deterministic steps</li></ul><p>About Our Guest</p><p>Eric Capuano is the creator of Defender Fridays and co-founder of Digital Defense Institute. He has spent years doing SOC operations, detection engineering, threat hunting, and DFIR, and currently consults on building and deploying agentic SecOps workflows for security teams. He is also the author of the "So You Want to Be a SOC Analyst" training, which has put over 500 students through hands-on SOC workflows using LimaCharlie's free tier.</p><p>Watch Us Live</p><p>Defender Fridays ran every Friday at 10:30am PT for over 100 sessions. Subscribe to our YouTube channel to catch up on past episodes.</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Eric Capuano - Co-founder of Digital Defense Institute</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for the final episode of Defender Fridays as Eric Capuano, creator of Defender Fridays and co-founder of Digital Defense Institute, closes out the series with a candid conversation on how he's actually building and running agentic workflows in the SOC today.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Eric Capuano draws on years of SOC operations, detection engineering, and hands-on agentic workflow development to share what's actually working, what isn't, and where the industry needs to be more honest with itself.</p><p>Key Topics:</p><ul><li>Why agentic workflows are the next evolution of SOAR, and what it takes to build them reliably</li><li>How deterministic checkpoints at every stage are essential to making LLM-driven workflows trustworthy</li><li>How one team increased their detection engineering output by 900x using agentic workflows running day and night</li><li>Why false positive tuning and detection engineering are the right place to start before tackling complex investigative workflows</li><li>How to think about model selection in agentic pipelines: cost, task complexity, and stakes</li><li>Why organizations with poor data hygiene will struggle to get value from AI regardless of how sophisticated the tooling is</li><li>The risks of prompt injection when feeding untrusted inputs into LLMs, and why trusted inputs should always come first</li><li>Why the goal is to use LLMs for as little as possible, and push everything else into deterministic steps</li></ul><p>About Our Guest</p><p>Eric Capuano is the creator of Defender Fridays and co-founder of Digital Defense Institute. He has spent years doing SOC operations, detection engineering, threat hunting, and DFIR, and currently consults on building and deploying agentic SecOps workflows for security teams. He is also the author of the "So You Want to Be a SOC Analyst" training, which has put over 500 students through hands-on SOC workflows using LimaCharlie's free tier.</p><p>Watch Us Live</p><p>Defender Fridays ran every Friday at 10:30am PT for over 100 sessions. Subscribe to our YouTube channel to catch up on past episodes.</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Eric Capuano - Co-founder of Digital Defense Institute</p>]]>
      </content:encoded>
      <pubDate>Sat, 20 Jun 2026 04:51:30 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c8749f66/de71abb4.mp3" length="53398085" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/cy4THwGPecuGWNCEGULHQsrSSsieXd79y-Z5brZM_pE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mYjJi/NTFiOWZjZDhkY2Jj/Y2U3YTJiNzQzZjY2/NTFiNC5wbmc.jpg"/>
      <itunes:duration>2225</itunes:duration>
      <itunes:summary>Join us for the final episode of Defender Fridays as Eric Capuano, creator of Defender Fridays and co-founder of Digital Defense Institute, closes out the series with a candid conversation on how he's actually building and running agentic workflows in the SOC today.</itunes:summary>
      <itunes:subtitle>Join us for the final episode of Defender Fridays as Eric Capuano, creator of Defender Fridays and co-founder of Digital Defense Institute, closes out the series with a candid conversation on how he's actually building and running agentic workflows in the</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>FFmpeg's 21 zero-days, Ruby cooldown feature, Microsoft disrupted by Shai-Hulud worm &amp; Meta AI tool compromise / Intel Chat [#331]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>331</itunes:episode>
      <podcast:episode>331</podcast:episode>
      <itunes:title>FFmpeg's 21 zero-days, Ruby cooldown feature, Microsoft disrupted by Shai-Hulud worm &amp; Meta AI tool compromise / Intel Chat [#331]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ca288ca4-655a-4d79-b6ec-6074360be660</guid>
      <link>https://share.transistor.fm/s/784ca1ae</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>DepthFirst reported that it's autonomous security agent discovered 21 previously unknown vulnerabilities in FFmpeg, a widely deployed multimedia framework used across browsers, streaming infrastructure, <a rel="noreferrer noopener" href="https://depthfirst.com/research/21-zero-days-in-ffmpeg">and other systems that process media</a>. </li><li>Bundler, 4.0.13 introduces a new security feature called cooldown, aimed at reducing the impact of software supply chain attacks <a rel="noreferrer noopener" href="https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html">in the Ruby ecosystem</a>. </li><li>A new variant of the Shai-Hulud supply chain worm, known as Miasma, briefly disrupted Microsoft's software development ecosystem after <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/miasma-supply-chain-worm-73-microsoft-repositories">compromising dozens of GitHub repositories</a>.</li><li>Meta says approximately 20,000 Instagram accounts may have been compromised through the abuse of an AI powered <a rel="noreferrer noopener" href="https://www.securityweek.com/meta-says-20000-instagram-accounts-hacked-via-ai-tool-abuse/">account recovery support system</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>DepthFirst reported that it's autonomous security agent discovered 21 previously unknown vulnerabilities in FFmpeg, a widely deployed multimedia framework used across browsers, streaming infrastructure, <a rel="noreferrer noopener" href="https://depthfirst.com/research/21-zero-days-in-ffmpeg">and other systems that process media</a>. </li><li>Bundler, 4.0.13 introduces a new security feature called cooldown, aimed at reducing the impact of software supply chain attacks <a rel="noreferrer noopener" href="https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html">in the Ruby ecosystem</a>. </li><li>A new variant of the Shai-Hulud supply chain worm, known as Miasma, briefly disrupted Microsoft's software development ecosystem after <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/miasma-supply-chain-worm-73-microsoft-repositories">compromising dozens of GitHub repositories</a>.</li><li>Meta says approximately 20,000 Instagram accounts may have been compromised through the abuse of an AI powered <a rel="noreferrer noopener" href="https://www.securityweek.com/meta-says-20000-instagram-accounts-hacked-via-ai-tool-abuse/">account recovery support system</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 15 Jun 2026 12:45:16 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/784ca1ae/425d4a4e.mp3" length="41217384" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/iJwvsfTJNhAmkM0sE1R53og_osQm_yYD6ofEDQ4EtyA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jMjdh/OGIyMDU2NjhjM2I2/YWUyMTMwYWIwNjQ5/ZjI2ZC5wbmc.jpg"/>
      <itunes:duration>1712</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI-assisted SOC training with Carlo Anez / Defender Fridays [#330]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>330</itunes:episode>
      <podcast:episode>330</podcast:episode>
      <itunes:title>AI-assisted SOC training with Carlo Anez / Defender Fridays [#330]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4479a52d-1276-4966-b712-a15847a20e3c</guid>
      <link>https://share.transistor.fm/s/80fe5646</link>
      <description>
        <![CDATA[<p>Join us for this week's Defender Fridays as Carlo Anez, Founder and Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down how to build practical blue team skills using open-source labs, MITRE ATTACK, and real-world defender workflows, and where AI fits into the picture without replacing the analyst.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Carlo Anez draws on years of SOC operations, detection engineering, and cybersecurity instruction to make the case for hands-on, open-source training as the foundation for developing confident, capable defenders.</p><p>Key Topics:</p><ul><li>Why cybersecurity training must move beyond passive learning and into real defender workflows</li><li>How the OpenSOC initiative uses open-source tools like Wazuh, MISP, The Hive, and TimeSketch to simulate a small-scale fusion center environment</li><li>How open-source stacks build transferable skills that translate to enterprise platforms like Splunk and LimaCharlie</li><li>Where AI fits in the SOC: summarizing noisy alerts, mapping activity to MITRE ATT&amp;CK, drafting investigation questions, and improving report clarity</li><li>Why AI literacy means knowing how to validate AI output against evidence, not just knowing how to write prompts</li><li>Why the analyst owns the evidence, the decision, and the communication</li><li>How the DEF CON boot camp and online pilot program structure five days of scenario-based training around a final analyst report and CTF capstone</li></ul><p>About Our Guest</p><p>Carlo Anez is the Founder and Lead Instructor at IgniteCyber Academy and a DEFCON Training Instructor. He spent five years at Rapid7 doing detection engineering, threat hunting, and DFIR workflows, and has supported SOC operations, government contractors, and projects with DARPA, the US Army, and the US Navy. He currently creates SOC-focused content with TCM Security and leads Blue Team Village at DEF CON, where he also presents and trains annually.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Carlo Anez - Founder &amp; Lead Instructor at IgniteCyber Academy</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for this week's Defender Fridays as Carlo Anez, Founder and Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down how to build practical blue team skills using open-source labs, MITRE ATTACK, and real-world defender workflows, and where AI fits into the picture without replacing the analyst.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Carlo Anez draws on years of SOC operations, detection engineering, and cybersecurity instruction to make the case for hands-on, open-source training as the foundation for developing confident, capable defenders.</p><p>Key Topics:</p><ul><li>Why cybersecurity training must move beyond passive learning and into real defender workflows</li><li>How the OpenSOC initiative uses open-source tools like Wazuh, MISP, The Hive, and TimeSketch to simulate a small-scale fusion center environment</li><li>How open-source stacks build transferable skills that translate to enterprise platforms like Splunk and LimaCharlie</li><li>Where AI fits in the SOC: summarizing noisy alerts, mapping activity to MITRE ATT&amp;CK, drafting investigation questions, and improving report clarity</li><li>Why AI literacy means knowing how to validate AI output against evidence, not just knowing how to write prompts</li><li>Why the analyst owns the evidence, the decision, and the communication</li><li>How the DEF CON boot camp and online pilot program structure five days of scenario-based training around a final analyst report and CTF capstone</li></ul><p>About Our Guest</p><p>Carlo Anez is the Founder and Lead Instructor at IgniteCyber Academy and a DEFCON Training Instructor. He spent five years at Rapid7 doing detection engineering, threat hunting, and DFIR workflows, and has supported SOC operations, government contractors, and projects with DARPA, the US Army, and the US Navy. He currently creates SOC-focused content with TCM Security and leads Blue Team Village at DEF CON, where he also presents and trains annually.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Carlo Anez - Founder &amp; Lead Instructor at IgniteCyber Academy</p>]]>
      </content:encoded>
      <pubDate>Fri, 12 Jun 2026 18:56:03 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/80fe5646/c1104688.mp3" length="46214321" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/GP8e69irgr2MpCu8T3_7ljhmg96mu4QE8hlbPlLw-Mo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wNTFm/NDhiYWJjZTY0ZTc5/NGNjM2UwMDRlZGVj/ZmNjOC5wbmc.jpg"/>
      <itunes:duration>1925</itunes:duration>
      <itunes:summary>This week's Defender Fridays as Carlo Anez, Founder and Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down where AI fits into the picture without replacing the analyst.</itunes:summary>
      <itunes:subtitle>This week's Defender Fridays as Carlo Anez, Founder and Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down where AI fits into the picture without replacing the analyst.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Building practical blue team skills using AI-assisted SOC training with Bobby Ford/ Defender Fridays [#329]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>329</itunes:episode>
      <podcast:episode>329</podcast:episode>
      <itunes:title>Building practical blue team skills using AI-assisted SOC training with Bobby Ford/ Defender Fridays [#329]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9dcd1f7c-172d-4f00-8284-bd0d61202c11</guid>
      <link>https://share.transistor.fm/s/c659341f</link>
      <description>
        <![CDATA[<p>Join us for this week's Defender Fridays as Bobby Ford, Chief Strategy and Experience Officer at Doppel, talks about open-source labs, MITRE ATT&amp;CK, and real-world defender workflows.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>About Our Guest</p><p>Bobby is a globally recognized cybersecurity “geek” with almost three decades of experience, including the last 14 years as a CISO, protecting some of the world’s most complex and operationally intensive enterprises. His career began in the military as a founding member of the Pentagon Computer Incident Response Team. Bobby built and led cybersecurity programs in the Aerospace and Defense industry. He was the first CISO at Exelis Inc. and was the architect of ITT’s global cybersecurity audit function under DOJ oversight.</p><p>Transitioning from public to private sector, Bobby served as the first CISO at Abbott Labs, was CISO for Unilever, and most recently was SVP and Chief Security Officer at Hewlett Packard Enterprise (HPE). Known for his collaborative style and empathetic leadership, Bobby fosters an inclusive culture that empowers entire security organizations to excel.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Charles Grandjean - CTO and Co-founder at Hexiagon AI</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for this week's Defender Fridays as Bobby Ford, Chief Strategy and Experience Officer at Doppel, talks about open-source labs, MITRE ATT&amp;CK, and real-world defender workflows.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>About Our Guest</p><p>Bobby is a globally recognized cybersecurity “geek” with almost three decades of experience, including the last 14 years as a CISO, protecting some of the world’s most complex and operationally intensive enterprises. His career began in the military as a founding member of the Pentagon Computer Incident Response Team. Bobby built and led cybersecurity programs in the Aerospace and Defense industry. He was the first CISO at Exelis Inc. and was the architect of ITT’s global cybersecurity audit function under DOJ oversight.</p><p>Transitioning from public to private sector, Bobby served as the first CISO at Abbott Labs, was CISO for Unilever, and most recently was SVP and Chief Security Officer at Hewlett Packard Enterprise (HPE). Known for his collaborative style and empathetic leadership, Bobby fosters an inclusive culture that empowers entire security organizations to excel.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Charles Grandjean - CTO and Co-founder at Hexiagon AI</p>]]>
      </content:encoded>
      <pubDate>Fri, 05 Jun 2026 12:00:24 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c659341f/a3f011af.mp3" length="43975281" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/aAjyWw-NG01Kvx1y8uBTtYj0EiyELK4Ftoe0OF7l9jE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZmIx/OGE4NDlmNzRkOThh/ODQ4MWVlNWQwZjc4/Zjk0Ny5wbmc.jpg"/>
      <itunes:duration>1831</itunes:duration>
      <itunes:summary>Join us for this week's Defender Fridays as Bobby Ford, Chief Strategy and Experience Officer at Doppel, talks about open-source labs, MITRE ATT&amp;amp;CK, and real-world defender workflows.</itunes:summary>
      <itunes:subtitle>Join us for this week's Defender Fridays as Bobby Ford, Chief Strategy and Experience Officer at Doppel, talks about open-source labs, MITRE ATT&amp;amp;CK, and real-world defender workflows.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>"Megalodon" Malware in GitHub, Malware-Slop steals from Claude AI, 7-Eleven breach &amp; CISA cPanel vulnerability / Intel Chat [#328]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>328</itunes:episode>
      <podcast:episode>328</podcast:episode>
      <itunes:title>"Megalodon" Malware in GitHub, Malware-Slop steals from Claude AI, 7-Eleven breach &amp; CISA cPanel vulnerability / Intel Chat [#328]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">abe6784b-f89c-451e-9bb6-5ac8d64def47</guid>
      <link>https://share.transistor.fm/s/4a0ca97e</link>
      <description>
        <![CDATA[<p>Originally recorded: Friday May 29, 2026</p><p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/megalodon-malware-infects-thousands-github-repos">six-hour period on May 18, 2026</a>.</li><li>Researchers from OX Security have identified a malicious npm package named “mouse5212-super-formatter” that was designed to steal files from Anthropic Claude AI environments by targeting<a rel="noreferrer noopener" href="https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html"> the “/mnt/user-data” directory</a>.</li><li>Convenience store giant 7-Eleven disclosed a data breach tied to an attack that occurred on April 8, 2026, involving systems that contained <a rel="noreferrer noopener" href="https://www.securityweek.com/185000-likely-impacted-by-7-eleven-data-breach/">franchise-related documents</a>. <a rel="noreferrer noopener" href="https://www.securityweek.com/shinyhunters-branded-extortion-activity-expands-escalates/">SecurityWeek article Matt references</a>.</li><li>CISA has issued an urgent warning about a critical vulnerability in the LiteSpeed cPanel Plugin, tracked as CVE-2026-48172, which is already being <a rel="noreferrer noopener" href="https://cybersecuritynews.com/litespeed-cpanel-plugin-vulnerability-exploit/">actively exploited in the wild</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Originally recorded: Friday May 29, 2026</p><p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/megalodon-malware-infects-thousands-github-repos">six-hour period on May 18, 2026</a>.</li><li>Researchers from OX Security have identified a malicious npm package named “mouse5212-super-formatter” that was designed to steal files from Anthropic Claude AI environments by targeting<a rel="noreferrer noopener" href="https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html"> the “/mnt/user-data” directory</a>.</li><li>Convenience store giant 7-Eleven disclosed a data breach tied to an attack that occurred on April 8, 2026, involving systems that contained <a rel="noreferrer noopener" href="https://www.securityweek.com/185000-likely-impacted-by-7-eleven-data-breach/">franchise-related documents</a>. <a rel="noreferrer noopener" href="https://www.securityweek.com/shinyhunters-branded-extortion-activity-expands-escalates/">SecurityWeek article Matt references</a>.</li><li>CISA has issued an urgent warning about a critical vulnerability in the LiteSpeed cPanel Plugin, tracked as CVE-2026-48172, which is already being <a rel="noreferrer noopener" href="https://cybersecuritynews.com/litespeed-cpanel-plugin-vulnerability-exploit/">actively exploited in the wild</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 01 Jun 2026 15:50:43 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4a0ca97e/e1a0ae3d.mp3" length="42014382" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/1pFPIaYzFC7asZ5QLVu5zssQ2I0Vx2_S0w79ylSC64M/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YmFm/MTRmYWFlYjA4ZjZj/NDQyZDkzNTY1ZjM3/ZTdiOC5wbmc.jpg"/>
      <itunes:duration>1746</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>From PentestGPT to production: The state of AI-assisted offensive security with Charles Grandjean / Defender Fridays [#327]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>327</itunes:episode>
      <podcast:episode>327</podcast:episode>
      <itunes:title>From PentestGPT to production: The state of AI-assisted offensive security with Charles Grandjean / Defender Fridays [#327]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3ab16b61-6d25-49c1-90a0-daf7b25aad24</guid>
      <link>https://share.transistor.fm/s/2784f9fe</link>
      <description>
        <![CDATA[<p>Join us for this week's Defender Fridays as Charles Grandjean, CTO and Co-founder at Hexiagon AI, breaks down where AI-assisted pen testing actually stands today and what it means for both red teams and defenders.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Charles Grandjean draws on his experience building an AI-powered continuous pen testing platform to trace how LLM capabilities have evolved for offensive security, and what the rise of autonomous attack tooling means for defenders.</p><p>Key Topics:</p><ul><li>How AI pen testing has progressed from unreliable single commands to chaining complex attack sequences</li><li>Why the last six months marked a turning point in LLM planning and long-context reasoning</li><li>When to use in-context learning and RAG versus fine-tuning, and why most teams should start with the former</li><li>Why privacy considerations push serious pen testing operations toward self-hosted models</li><li>How the balance between model control and code control has shifted as models have improved</li><li>Why unrestricted and fine-tuned open-weights models are lowering the barrier for malicious actors</li><li>What automated offense means for defense teams and why the response needs to match the scale of the threat</li></ul><p>About Our Guest</p><p>Charles Grandjean is the CTO and Co-founder of Hexiagon AI, a company focused on automating penetration testing through AI to enable continuous, around-the-clock security validation. He has been building and iterating on AI-assisted offensive tooling for the past two years, tracking the evolution of LLM capabilities firsthand from early prototype to production system.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Charles Grandjean - CTO and Co-founder at Hexiagon AI</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for this week's Defender Fridays as Charles Grandjean, CTO and Co-founder at Hexiagon AI, breaks down where AI-assisted pen testing actually stands today and what it means for both red teams and defenders.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Charles Grandjean draws on his experience building an AI-powered continuous pen testing platform to trace how LLM capabilities have evolved for offensive security, and what the rise of autonomous attack tooling means for defenders.</p><p>Key Topics:</p><ul><li>How AI pen testing has progressed from unreliable single commands to chaining complex attack sequences</li><li>Why the last six months marked a turning point in LLM planning and long-context reasoning</li><li>When to use in-context learning and RAG versus fine-tuning, and why most teams should start with the former</li><li>Why privacy considerations push serious pen testing operations toward self-hosted models</li><li>How the balance between model control and code control has shifted as models have improved</li><li>Why unrestricted and fine-tuned open-weights models are lowering the barrier for malicious actors</li><li>What automated offense means for defense teams and why the response needs to match the scale of the threat</li></ul><p>About Our Guest</p><p>Charles Grandjean is the CTO and Co-founder of Hexiagon AI, a company focused on automating penetration testing through AI to enable continuous, around-the-clock security validation. He has been building and iterating on AI-assisted offensive tooling for the past two years, tracking the evolution of LLM capabilities firsthand from early prototype to production system.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Charles Grandjean - CTO and Co-founder at Hexiagon AI</p>]]>
      </content:encoded>
      <pubDate>Sat, 30 May 2026 13:00:24 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2784f9fe/7a031b2b.mp3" length="43679472" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/SNYniBWfWHsk6IjYhYwISeWstPSoZp1bUlzf4ytYQbM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jYjc5/YjZiMzQ0YWRkYTNl/MGE0OGNhYmM2YzAx/ZWFmNC5wbmc.jpg"/>
      <itunes:duration>1819</itunes:duration>
      <itunes:summary>Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest.</itunes:summary>
      <itunes:subtitle>Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>GitHub repositories compromised, Webworm targets Europe, fake Outlook &amp; cybercriminal VPN / Intel Chat [#326]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>326</itunes:episode>
      <podcast:episode>326</podcast:episode>
      <itunes:title>GitHub repositories compromised, Webworm targets Europe, fake Outlook &amp; cybercriminal VPN / Intel Chat [#326]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0c92c185-b9a6-444c-a7cb-873a58069686</guid>
      <link>https://share.transistor.fm/s/60ca2559</link>
      <description>
        <![CDATA[<p>Originally recorded: Friday May 22, 2026</p><p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>GitHub has confirmed that roughly 3,800 internal repositories were accessed in a supply chain compromise tied to the <a rel="noreferrer noopener" href="https://www.securityweek.com/github-confirms-hack-impacting-3800-internal-repositories/">hacking group TeamPCP</a>.</li><li>China-aligned threat actor Webworm has shifted its targeting focus from Asia to Europe, according to new <a rel="noreferrer noopener" href="https://www.darkreading.com/endpoint-security/chinas-webworm-discord-microsoft-graphs">research published by ESET</a>.</li><li>Researchers uncovered a previously undocumented Microsoft 365 account takeover panel that integrates directly with Evilginx Pro infrastructure to streamline token theft and <a rel="noreferrer noopener" href="https://newtonpaul.com/blog/evilginx-m365-aitm-panel-research/">post-compromise operations</a>.</li><li>European and North American law enforcement agencies announced the dismantling of “First VPN,” a VPN service allegedly built to support cybercriminal activity including ransomware operations, data theft, scanning, and <a rel="noreferrer noopener" href="https://thehackernews.com/2026/05/first-vpn-dismantled-in-global-takedown.html">denial-of-service attacks</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Originally recorded: Friday May 22, 2026</p><p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>GitHub has confirmed that roughly 3,800 internal repositories were accessed in a supply chain compromise tied to the <a rel="noreferrer noopener" href="https://www.securityweek.com/github-confirms-hack-impacting-3800-internal-repositories/">hacking group TeamPCP</a>.</li><li>China-aligned threat actor Webworm has shifted its targeting focus from Asia to Europe, according to new <a rel="noreferrer noopener" href="https://www.darkreading.com/endpoint-security/chinas-webworm-discord-microsoft-graphs">research published by ESET</a>.</li><li>Researchers uncovered a previously undocumented Microsoft 365 account takeover panel that integrates directly with Evilginx Pro infrastructure to streamline token theft and <a rel="noreferrer noopener" href="https://newtonpaul.com/blog/evilginx-m365-aitm-panel-research/">post-compromise operations</a>.</li><li>European and North American law enforcement agencies announced the dismantling of “First VPN,” a VPN service allegedly built to support cybercriminal activity including ransomware operations, data theft, scanning, and <a rel="noreferrer noopener" href="https://thehackernews.com/2026/05/first-vpn-dismantled-in-global-takedown.html">denial-of-service attacks</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 29 May 2026 14:25:16 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/60ca2559/dfeaa09c.mp3" length="35353023" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Z9_tETYCX0nFc8t7fefkS_XWD71Q_bRPlQs-wfSmXqg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNTg1/MDdiZWRkYmRlYjli/OTc0YzIyMjJiMWE5/Nzc4My5wbmc.jpg"/>
      <itunes:duration>1468</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How analysts use cognitive reasoning in investigations with Chris Sanders / Defender Fridays [#325]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>325</itunes:episode>
      <podcast:episode>325</podcast:episode>
      <itunes:title>How analysts use cognitive reasoning in investigations with Chris Sanders / Defender Fridays [#325]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c60f675f-5a2e-4819-ad01-31edf86c4462</guid>
      <link>https://share.transistor.fm/s/2a9b6bd9</link>
      <description>
        <![CDATA[<p>Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Chris Sanders draws on his background in security operations and cognitive psychology to explore how metacognition shapes investigative performance, and why understanding how you think is one of the most underleveraged skills in the SOC.</p><p>Key Topics:</p><ul><li>Why high-performing analysts ask better questions instead of starting with large chunks of data</li><li>How diagnostic inquiry (DINQ) was developed by studying senior analysts in action</li><li>What separates one year of experience repeated twenty times from genuinely diverse experience</li><li>Why tacit knowledge makes it hard to train new analysts and what to do about it</li><li>How AI fits into the investigative process and where humans still need to be in the loop</li><li>Why cybersecurity education has a transfer problem and what other fields like medicine get right</li><li>What good SOCs have in common and why it comes down to metacognitive awareness</li></ul><p>About Our Guest</p><p>Chris Sanders is the Founder of Applied Network Defense, a training company focused on analyst and investigative roles, and the Rural Technology Fund, an organization that supports technology education in rural and underserved communities. He holds a doctorate in education and has spent his career at the intersection of cybersecurity and cognitive psychology, including time at school districts, the federal government, and Mandiant.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Chris Sanders - Founder at Applied Network Defense &amp; Rural Technology Fund</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Chris Sanders draws on his background in security operations and cognitive psychology to explore how metacognition shapes investigative performance, and why understanding how you think is one of the most underleveraged skills in the SOC.</p><p>Key Topics:</p><ul><li>Why high-performing analysts ask better questions instead of starting with large chunks of data</li><li>How diagnostic inquiry (DINQ) was developed by studying senior analysts in action</li><li>What separates one year of experience repeated twenty times from genuinely diverse experience</li><li>Why tacit knowledge makes it hard to train new analysts and what to do about it</li><li>How AI fits into the investigative process and where humans still need to be in the loop</li><li>Why cybersecurity education has a transfer problem and what other fields like medicine get right</li><li>What good SOCs have in common and why it comes down to metacognitive awareness</li></ul><p>About Our Guest</p><p>Chris Sanders is the Founder of Applied Network Defense, a training company focused on analyst and investigative roles, and the Rural Technology Fund, an organization that supports technology education in rural and underserved communities. He holds a doctorate in education and has spent his career at the intersection of cybersecurity and cognitive psychology, including time at school districts, the federal government, and Mandiant.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Chris Sanders - Founder at Applied Network Defense &amp; Rural Technology Fund</p>]]>
      </content:encoded>
      <pubDate>Fri, 22 May 2026 16:20:25 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2a9b6bd9/7ff9e8d5.mp3" length="47135760" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/f1yj68A1Ck1jjxdgFO1ZkmJz6fnIrypfbHbOHRdQ9bY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82MTY0/NTg3MmE1YWI1MmNh/NzVjYzVlZWQ2NWQw/ZGQ3My5wbmc.jpg"/>
      <itunes:duration>1963</itunes:duration>
      <itunes:summary>Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest.</itunes:summary>
      <itunes:subtitle>Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>"Dirty Frag", Canvas ransomware attack, “Mini Shai-Hulud” malware campaign &amp; AI-developed zero-day exploit / Intel Chat [#324]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>324</itunes:episode>
      <podcast:episode>324</podcast:episode>
      <itunes:title>"Dirty Frag", Canvas ransomware attack, “Mini Shai-Hulud” malware campaign &amp; AI-developed zero-day exploit / Intel Chat [#324]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4f715d55-0361-489f-870a-f0695046d283</guid>
      <link>https://share.transistor.fm/s/b592d0cc</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers have disclosed a new Linux local privilege escalation technique called “Dirty Frag,” which chains together two kernel vulnerabilities: CVE-2026-43284 in xfrm-ESP handling and <a rel="noreferrer noopener" href="https://github.com/V4bel/dirtyfrag">CVE-2026-43500 in RxRPC</a>.</li><li>The breach affecting educational technology provider Instructure has raised broader concerns about the security dependencies schools have on <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/instructure-breach-exposes-schools-vendor-dependence">third-party cloud platforms</a>.</li><li>Security researchers at Aikido are tracking a major expansion of the “Mini Shai-Hulud” malware campaign <a rel="noreferrer noopener" href="https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised">targeting the npm ecosystem</a>.</li><li>Google Threat Intelligence Group says threat actors are moving from experimental AI usage toward large-scale operational integration of generative models <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">across the cyberattack lifecycle</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers have disclosed a new Linux local privilege escalation technique called “Dirty Frag,” which chains together two kernel vulnerabilities: CVE-2026-43284 in xfrm-ESP handling and <a rel="noreferrer noopener" href="https://github.com/V4bel/dirtyfrag">CVE-2026-43500 in RxRPC</a>.</li><li>The breach affecting educational technology provider Instructure has raised broader concerns about the security dependencies schools have on <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/instructure-breach-exposes-schools-vendor-dependence">third-party cloud platforms</a>.</li><li>Security researchers at Aikido are tracking a major expansion of the “Mini Shai-Hulud” malware campaign <a rel="noreferrer noopener" href="https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised">targeting the npm ecosystem</a>.</li><li>Google Threat Intelligence Group says threat actors are moving from experimental AI usage toward large-scale operational integration of generative models <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">across the cyberattack lifecycle</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 18 May 2026 10:00:19 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b592d0cc/7d710cf0.mp3" length="41651134" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ayq8qexRnui6I-SsymxUP99Qvpr97se_tn53wgGEWhk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81NTRk/YmRiMmYxOWEzMTc2/ZWJhYTU4OWI5NDNk/YmFiMy5wbmc.jpg"/>
      <itunes:duration>1729</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How to handle increasing vulnerabilities with AI-assistants? With Shane Warden from ActiveState / Defender Fridays [#323]]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>232</itunes:episode>
      <podcast:episode>232</podcast:episode>
      <itunes:title>How to handle increasing vulnerabilities with AI-assistants? With Shane Warden from ActiveState / Defender Fridays [#323]]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a6312a8b-17d6-486c-bc6f-0be98b370c07</guid>
      <link>https://share.transistor.fm/s/ec04d867</link>
      <description>
        <![CDATA[<p>Join us for this week's Defender Fridays as Shane Warden, Principal Architect at ActiveState, shares what it's actually like to be on the receiving end of AI-assisted vulnerability reporting and what open source maintainers are already dealing with that the rest of the industry will face soon.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Shane Warden draws on his experience supporting security for well-known open source projects to explore how AI-assisted vulnerability reporting is changing the threat landscape, and why what's happening in open source today is a preview of what every organization will face.</p><p>Key Topics:</p><ul><li>Why open source projects are the early warning system for what's coming to enterprise security</li><li>How a flood of 95 AI-generated vulnerability reports turned into a six-figure extortion attempt</li><li>Why even a three percent legitimate hit rate still creates a real and unignorable workload for maintainers</li><li>How teams are using AI to respond to AI-generated reports, and where humans still need to be in the loop</li></ul><ul><li>What projects like curl, the Linux kernel, and Zig are doing differently in response to AI contributions</li><li>Why understanding your open source dependencies and their versions is more urgent than ever</li><li>The reputational risk of AI-generated vulnerability claims, even when those claims are false</li></ul><p>About Our Guest</p><p>Shane Warden is Principal Architect at ActiveState and has been involved in open source since the late 1990s. Behind the scenes, he supports security for several well-known free software projects and has been navigating the growing wave of AI-assisted vulnerability submissions firsthand.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li></ul><ul><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Shane Warden - Principal Architect at ActiveState</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for this week's Defender Fridays as Shane Warden, Principal Architect at ActiveState, shares what it's actually like to be on the receiving end of AI-assisted vulnerability reporting and what open source maintainers are already dealing with that the rest of the industry will face soon.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this episode, Shane Warden draws on his experience supporting security for well-known open source projects to explore how AI-assisted vulnerability reporting is changing the threat landscape, and why what's happening in open source today is a preview of what every organization will face.</p><p>Key Topics:</p><ul><li>Why open source projects are the early warning system for what's coming to enterprise security</li><li>How a flood of 95 AI-generated vulnerability reports turned into a six-figure extortion attempt</li><li>Why even a three percent legitimate hit rate still creates a real and unignorable workload for maintainers</li><li>How teams are using AI to respond to AI-generated reports, and where humans still need to be in the loop</li></ul><ul><li>What projects like curl, the Linux kernel, and Zig are doing differently in response to AI contributions</li><li>Why understanding your open source dependencies and their versions is more urgent than ever</li><li>The reputational risk of AI-generated vulnerability claims, even when those claims are false</li></ul><p>About Our Guest</p><p>Shane Warden is Principal Architect at ActiveState and has been involved in open source since the late 1990s. Behind the scenes, he supports security for several well-known free software projects and has been navigating the growing wave of AI-assisted vulnerability submissions firsthand.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li></ul><ul><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Shane Warden - Principal Architect at ActiveState</p>]]>
      </content:encoded>
      <pubDate>Fri, 15 May 2026 18:17:13 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ec04d867/be0f23c8.mp3" length="44851604" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/4CWH_KJ-F_hH8_hgbs1pnFRmjxdpHu38oJQBJhlJ_to/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NDFh/ZmUzOGJkMGUxMDQ3/YjdjMTI1NDRhNzU3/NDcyMi5wbmc.jpg"/>
      <itunes:duration>1868</itunes:duration>
      <itunes:summary>Shane Warden, Principal Architect at ActiveState, shares what it's actually like to be on the receiving end of AI-assisted vulnerability reporting and what open source maintainers are already dealing with that the rest of the industry will face soon.</itunes:summary>
      <itunes:subtitle>Shane Warden, Principal Architect at ActiveState, shares what it's actually like to be on the receiving end of AI-assisted vulnerability reporting and what open source maintainers are already dealing with that the rest of the industry will face soon.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Does the rise of AI mean human-led SOCs are obsolete? With Dr. Adeel Shaikh Muhammad [#322]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>322</itunes:episode>
      <podcast:episode>322</podcast:episode>
      <itunes:title>Does the rise of AI mean human-led SOCs are obsolete? With Dr. Adeel Shaikh Muhammad [#322]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fe406e65-03f2-4bfc-828f-3b728d0fba9f</guid>
      <link>https://share.transistor.fm/s/2e4fe360</link>
      <description>
        <![CDATA[<p>Dr. Adeel Shaikh Muhammad, a cybersecurity strategist and global speaker with over 16 years of experience across information security, networks, and systems. Adeel brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity. </p><p>Adeel, with an extraordinary portfolio of 40+ industry certifications, including CISSP, CISM, CISA, CCISO, PMP, CEH, ISO 27001 Lead Implementer &amp; Auditor, and a robust suite of advanced Cisco, Microsoft, Fortinet, Barracuda, ITIL, PRINCE2, and AI-related credentials, he is a benchmark of technical mastery and visionary execution. His academic excellence includes a Master’s in Cybersecurity and a current Doctorate in Business Administration (DBA) focused on the impact of AI in Security Operations Centers (SOCs) in the Gulf region.</p><p>Adeel is the author of two acclaimed books—“AI-Driven Transformation of Security Operations Center (SOC)” and “AI and Us: The Ethical Choices”—bridging the critical intersection of AI innovation and ethical leadership.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dr. Adeel Shaikh Muhammad, a cybersecurity strategist and global speaker with over 16 years of experience across information security, networks, and systems. Adeel brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity. </p><p>Adeel, with an extraordinary portfolio of 40+ industry certifications, including CISSP, CISM, CISA, CCISO, PMP, CEH, ISO 27001 Lead Implementer &amp; Auditor, and a robust suite of advanced Cisco, Microsoft, Fortinet, Barracuda, ITIL, PRINCE2, and AI-related credentials, he is a benchmark of technical mastery and visionary execution. His academic excellence includes a Master’s in Cybersecurity and a current Doctorate in Business Administration (DBA) focused on the impact of AI in Security Operations Centers (SOCs) in the Gulf region.</p><p>Adeel is the author of two acclaimed books—“AI-Driven Transformation of Security Operations Center (SOC)” and “AI and Us: The Ethical Choices”—bridging the critical intersection of AI innovation and ethical leadership.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 13 May 2026 13:00:22 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2e4fe360/d08cd9bd.mp3" length="36588321" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1519</itunes:duration>
      <itunes:summary>Dr. Adeel Shaikh Muhammad brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity.</itunes:summary>
      <itunes:subtitle>Dr. Adeel Shaikh Muhammad brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Daily breach attempts target UAE, fake ransomware attack, PAN-OS vulnerability &amp; Microsoft’s Phone Link attack / Intel Chat [#321]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>321</itunes:episode>
      <podcast:episode>321</podcast:episode>
      <itunes:title>Daily breach attempts target UAE, fake ransomware attack, PAN-OS vulnerability &amp; Microsoft’s Phone Link attack / Intel Chat [#321]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0ee2ca8a-1718-447d-bc2a-9d8e9342bd2e</guid>
      <link>https://share.transistor.fm/s/5f68fe13</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The cyber threat environment in the Middle East has intensified sharply following military operations involving Israel, <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/middle-east-cyber-battle-field-broadens-uae">the United States, and Iran</a>. </li><li>An intrusion campaign attributed with moderate confidence to the Iranian state-linked group MuddyWater was disguised as a Chaos ransomware attack, <a rel="noreferrer noopener" href="https://www.securityweek.com/iranian-apt-intrusion-masquerades-as-chaos-ransomware-attack/">according to research from Rapid7</a>.</li><li>Palo Alto Networks has warned customers that a critical remote code execution vulnerability in PAN-OS is being <a rel="noreferrer noopener" href="https://thehackernews.com/2026/05/palo-alto-pan-os-flaw-under-active.html">actively exploited in the wild</a>.</li><li>Attackers are abusing Microsoft’s Phone Link application in a campaign that Cisco Talos says has <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/attacks-abuse-windows-phone-link-texts-bypass-2fa">been active since January</a>. <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/cloudz-pheno-infostealer/">Report here.</a></li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The cyber threat environment in the Middle East has intensified sharply following military operations involving Israel, <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/middle-east-cyber-battle-field-broadens-uae">the United States, and Iran</a>. </li><li>An intrusion campaign attributed with moderate confidence to the Iranian state-linked group MuddyWater was disguised as a Chaos ransomware attack, <a rel="noreferrer noopener" href="https://www.securityweek.com/iranian-apt-intrusion-masquerades-as-chaos-ransomware-attack/">according to research from Rapid7</a>.</li><li>Palo Alto Networks has warned customers that a critical remote code execution vulnerability in PAN-OS is being <a rel="noreferrer noopener" href="https://thehackernews.com/2026/05/palo-alto-pan-os-flaw-under-active.html">actively exploited in the wild</a>.</li><li>Attackers are abusing Microsoft’s Phone Link application in a campaign that Cisco Talos says has <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/attacks-abuse-windows-phone-link-texts-bypass-2fa">been active since January</a>. <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/cloudz-pheno-infostealer/">Report here.</a></li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 12 May 2026 17:35:43 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5f68fe13/51b9d35d.mp3" length="39708589" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/fkmJPPYMdMfGFDZK1OQBkfFqKjQ1BfiqwhU9MO0A-gg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85ZmFl/MGJmNmQ4NDBjMjk3/OGM4MzU4YmJiNzY3/YmU1NC5wbmc.jpg"/>
      <itunes:duration>1648</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI: The Hero's Journey with Ken Westin from LimaCharlie / Defender Fridays [#320]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>320</itunes:episode>
      <podcast:episode>320</podcast:episode>
      <itunes:title>AI: The Hero's Journey with Ken Westin from LimaCharlie / Defender Fridays [#320]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">cfdc63c9-296b-4bb9-ae50-f2d5ebefe0dc</guid>
      <link>https://share.transistor.fm/s/6340dc9b</link>
      <description>
        <![CDATA[<p>In this episode, Ken Westin maps AI adoption onto the hero's journey framework, drawing on two decades of security experience to explore how practitioners can move past early resistance, build real fluency with AI tools, and find a working model where humans and AI operate together.</p><p>Key Topics:</p><ul><li>Why early AI tools left security teams skeptical and what has genuinely changed since then</li><li>How Ken used AI to accelerate detection engineering without sacrificing analyst oversight</li><li>Why AI is best understood as an eager, overconfident intern that still needs supervision</li><li>The importance of hands-on experimentation over passive observation when learning AI</li><li>How collaboration and shared prompting practices are shaping how practitioners learn</li><li>Why security analysts who engage with AI now will not be left behind as the field evolves</li><li>The case for AI as a tool of empowerment, not replacement</li></ul><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>About Our Guest</p><p>Ken Westin is a Senior Solutions Engineer at LimaCharlie with nearly two decades in the cybersecurity industry. A former startup founder who built tools to track criminal activity, Ken has worked across SIEM, EDR, and detection engineering throughout his career. He also teaches at the college level, where AI and cybersecurity are increasingly intertwined disciplines.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Ken Westin - Senior Solutions Engineer at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, Ken Westin maps AI adoption onto the hero's journey framework, drawing on two decades of security experience to explore how practitioners can move past early resistance, build real fluency with AI tools, and find a working model where humans and AI operate together.</p><p>Key Topics:</p><ul><li>Why early AI tools left security teams skeptical and what has genuinely changed since then</li><li>How Ken used AI to accelerate detection engineering without sacrificing analyst oversight</li><li>Why AI is best understood as an eager, overconfident intern that still needs supervision</li><li>The importance of hands-on experimentation over passive observation when learning AI</li><li>How collaboration and shared prompting practices are shaping how practitioners learn</li><li>Why security analysts who engage with AI now will not be left behind as the field evolves</li><li>The case for AI as a tool of empowerment, not replacement</li></ul><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>About Our Guest</p><p>Ken Westin is a Senior Solutions Engineer at LimaCharlie with nearly two decades in the cybersecurity industry. A former startup founder who built tools to track criminal activity, Ken has worked across SIEM, EDR, and detection engineering throughout his career. He also teaches at the college level, where AI and cybersecurity are increasingly intertwined disciplines.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.</p><p>Why LimaCharlie?</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Accelerate response with agentic AI that acts directly within predefined workflows</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn: / limacharlieio</p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p><p>Guest: Ken Westin - Senior Solutions Engineer at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 08 May 2026 07:51:15 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6340dc9b/86392b94.mp3" length="45888026" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/KvwkRkyoov_eMb1JEvA6BSHV7JvrxGXxzOVQG-w8PV0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80NTBj/N2I2ODE5YTZlZjBl/OTQ3YjZmZjE0YWI1/YmI0OC5wbmc.jpg"/>
      <itunes:duration>1911</itunes:duration>
      <itunes:summary>Ken Westin draws on two decades of security experience to explore how practitioners can move past early resistance when building with AI.</itunes:summary>
      <itunes:subtitle>Ken Westin draws on two decades of security experience to explore how practitioners can move past early resistance when building with AI.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Power systems under threat, Claude Mythos, suspicious KICS activity &amp; JFrog  / Intel Chat [#319]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>319</itunes:episode>
      <podcast:episode>319</podcast:episode>
      <itunes:title>Power systems under threat, Claude Mythos, suspicious KICS activity &amp; JFrog  / Intel Chat [#319]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">00cd7c9b-c986-47ca-a91e-d54d84923823</guid>
      <link>https://share.transistor.fm/s/2ef7239b</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers are raising concerns about a new cybersecurity risk emerging from the systems that regulate electrical power inside modern <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/electricity-growing-area-cyber-risk">electronics and infrastructure</a>.</li><li>Japan’s financial sector is responding to concerns around Anthropic’s new AI model, Claude Mythos, which some officials believe could <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/claude-mythos-startle-japans-financial-sector">significantly impact cybersecurity</a>.</li><li>Docker and Socket researchers discovered that malicious images were pushed to the official checkmarx/kics Docker Hub repository, indicating a supply chain compromise affecting the KICS <a rel="noreferrer noopener" href="https://socket.dev/blog/checkmarx-supply-chain-compromise">infrastructure-as-code scanning tool</a>.</li><li>JFrog security researchers identified a malicious npm package published as @bitwarden/cli version 2026.4.0 that impersonates the legitimate <a rel="noreferrer noopener" href="https://research.jfrog.com/post/bitwarden-cli-hijack/">Bitwarden command-line client</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers are raising concerns about a new cybersecurity risk emerging from the systems that regulate electrical power inside modern <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/electricity-growing-area-cyber-risk">electronics and infrastructure</a>.</li><li>Japan’s financial sector is responding to concerns around Anthropic’s new AI model, Claude Mythos, which some officials believe could <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/claude-mythos-startle-japans-financial-sector">significantly impact cybersecurity</a>.</li><li>Docker and Socket researchers discovered that malicious images were pushed to the official checkmarx/kics Docker Hub repository, indicating a supply chain compromise affecting the KICS <a rel="noreferrer noopener" href="https://socket.dev/blog/checkmarx-supply-chain-compromise">infrastructure-as-code scanning tool</a>.</li><li>JFrog security researchers identified a malicious npm package published as @bitwarden/cli version 2026.4.0 that impersonates the legitimate <a rel="noreferrer noopener" href="https://research.jfrog.com/post/bitwarden-cli-hijack/">Bitwarden command-line client</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 06 May 2026 21:22:25 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2ef7239b/16807265.mp3" length="45102903" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/wjVlyZW5Tr6M2kAf93w0SRsTHAsyLMXIH2AZF0hxXQ8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mZjhk/ZTFlYTkwZGExYmJl/MTE4ZmQ0OWY4ZTQz/ODFiOC5wbmc.jpg"/>
      <itunes:duration>1874</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>318</itunes:episode>
      <podcast:episode>318</podcast:episode>
      <itunes:title>How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">085300c8-b208-495e-a792-7048c98244ce</guid>
      <link>https://share.transistor.fm/s/0999ce9a</link>
      <description>
        <![CDATA[<p>Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.</p><p>She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.</p><p>Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting her hands into the CLI or trying something new. She holds a Bachelors of Science and Masters of Information Security and Assurance from Western Governors University as well as several industry certifications. </p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.</p><p>She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System, that organizations need to secure to maintain integrity.</p><p>Katherine works for Cisco as a Cybersecurity Systems Engineer by day and by night, she's labbing and trying new things with the resources she has available. Katherine loves technology and getting her hands into the CLI or trying something new. She holds a Bachelors of Science and Masters of Information Security and Assurance from Western Governors University as well as several industry certifications. </p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Mon, 04 May 2026 10:00:19 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0999ce9a/cd53c92d.mp3" length="52240343" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/2sDyos8jvN7pGvf5aFqUHpebW42kzsV8L1tjDUgMHGY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iZDlh/ODcxNTc1MWVlYTUx/YjkxZDMxMDFkM2Mw/OWQ0Yy5wbmc.jpg"/>
      <itunes:duration>2176</itunes:duration>
      <itunes:summary>Katherine McNamara joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.</itunes:summary>
      <itunes:subtitle>Katherine McNamara joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Cybersecurity is a core leadership issue &amp; opportunity with David Chernitzky from Armour Cybersecurity [#317]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>317</itunes:episode>
      <podcast:episode>317</podcast:episode>
      <itunes:title>Cybersecurity is a core leadership issue &amp; opportunity with David Chernitzky from Armour Cybersecurity [#317]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">da6d00b3-2329-435c-9de1-088650ef5994</guid>
      <link>https://share.transistor.fm/s/ec14191e</link>
      <description>
        <![CDATA[<p>Today David Chernitzky, Co-Founder and CEO of Armour Cybersecurity, breaks down the challenges small and mid-sized businesses face in the new blink-and-you-miss-it cybersecurity landscape. Don't be left behind and open yourself to AI-driven attacks from threat actors.</p><p>David Chernitzky brings over 25 years of deep cybersecurity and military cyber intelligence experience, with a career rooted in strategic risk management and protecting critical systems against advanced threats. As the driving force behind Armour Cybersecurity, he has guided the company’s growth into a trusted global security partner for enterprises and small-to-midsized organizations. David combines strategic vision with hands-on expertise to deliver practical, high-impact cyber defence solutions. Learn more here: <a rel="noreferrer noopener" href="https://armourcyber.io/">https://armourcyber.io/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today David Chernitzky, Co-Founder and CEO of Armour Cybersecurity, breaks down the challenges small and mid-sized businesses face in the new blink-and-you-miss-it cybersecurity landscape. Don't be left behind and open yourself to AI-driven attacks from threat actors.</p><p>David Chernitzky brings over 25 years of deep cybersecurity and military cyber intelligence experience, with a career rooted in strategic risk management and protecting critical systems against advanced threats. As the driving force behind Armour Cybersecurity, he has guided the company’s growth into a trusted global security partner for enterprises and small-to-midsized organizations. David combines strategic vision with hands-on expertise to deliver practical, high-impact cyber defence solutions. Learn more here: <a rel="noreferrer noopener" href="https://armourcyber.io/">https://armourcyber.io/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Apr 2026 13:56:15 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ec14191e/9ebbf0ae.mp3" length="51327208" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2130</itunes:duration>
      <itunes:summary>Today David Chernitzky, Co-Founder and CEO of Armour Cybersecurity, breaks down the challenges small and mid-sized businesses face in the new AI-driven cybersecurity landscape.</itunes:summary>
      <itunes:subtitle>Today David Chernitzky, Co-Founder and CEO of Armour Cybersecurity, breaks down the challenges small and mid-sized businesses face in the new AI-driven cybersecurity landscape.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Millions in crypto stolen, Vercel breach, Mastodon DDoS attack, North Korean IT workers at 100s of U.S. companies &amp; ransomware negotiator pleads guilty / Intel Chat [#316]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>316</itunes:episode>
      <podcast:episode>316</podcast:episode>
      <itunes:title>Millions in crypto stolen, Vercel breach, Mastodon DDoS attack, North Korean IT workers at 100s of U.S. companies &amp; ransomware negotiator pleads guilty / Intel Chat [#316]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e71f7da2-d9ed-46a9-9e15-03cde50cf8cd</guid>
      <link>https://share.transistor.fm/s/c59f19a0</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>North Korea-linked hackers are believed to be responsible for a $290 million cryptocurrency theft targeting the Kelp DAO <a rel="noreferrer noopener" href="https://www.securityweek.com/290-million-kelp-dao-crypto-heist-blamed-on-north-korea/">decentralized finance protocol</a>.</li><li>Vercel, the company behind the popular Next.js web framework and a frontend cloud platform for deploying and hosting web applications, has confirmed that it suffered a security breach involving unauthorized <a rel="noreferrer noopener" href="https://www.securityweek.com/next-js-creator-vercel-hacked">access to internal systems</a>.</li><li>The decentralized social media platform Mastodon experienced a major distributed denial-of-service attack that caused a significant outage on its <a rel="noreferrer noopener" href="https://www.securityweek.com/after-bluesky-mastodon-targeted-in-ddos-attack/">flagship server, Mastodon.social</a>.</li><li>Two U.S. nationals have been sentenced for helping North Korean remote IT workers fraudulently obtain jobs at more than 100 U.S. companies using <a rel="noreferrer noopener" href="https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker">stolen American identities</a>.</li><li>A former ransomware negotiator has pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group to conduct attacks against <a rel="noreferrer noopener" href="https://www.darkreading.com/insider-threats/ransomware-negotiator-pleads-guilty-blackcat-scheme">U.S. organizations in 2023</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>North Korea-linked hackers are believed to be responsible for a $290 million cryptocurrency theft targeting the Kelp DAO <a rel="noreferrer noopener" href="https://www.securityweek.com/290-million-kelp-dao-crypto-heist-blamed-on-north-korea/">decentralized finance protocol</a>.</li><li>Vercel, the company behind the popular Next.js web framework and a frontend cloud platform for deploying and hosting web applications, has confirmed that it suffered a security breach involving unauthorized <a rel="noreferrer noopener" href="https://www.securityweek.com/next-js-creator-vercel-hacked">access to internal systems</a>.</li><li>The decentralized social media platform Mastodon experienced a major distributed denial-of-service attack that caused a significant outage on its <a rel="noreferrer noopener" href="https://www.securityweek.com/after-bluesky-mastodon-targeted-in-ddos-attack/">flagship server, Mastodon.social</a>.</li><li>Two U.S. nationals have been sentenced for helping North Korean remote IT workers fraudulently obtain jobs at more than 100 U.S. companies using <a rel="noreferrer noopener" href="https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker">stolen American identities</a>.</li><li>A former ransomware negotiator has pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group to conduct attacks against <a rel="noreferrer noopener" href="https://www.darkreading.com/insider-threats/ransomware-negotiator-pleads-guilty-blackcat-scheme">U.S. organizations in 2023</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 27 Apr 2026 12:45:13 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c59f19a0/f3b98800.mp3" length="46176537" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/i81vY-KLvt4qE_rxx6mKRmeAlupOHDWBFlOcYNpJ6KY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80ZDZk/M2FiZWU4YmMzZjFh/ZjgxZTc0NTQxZGQ3/OWE5YS5wbmc.jpg"/>
      <itunes:duration>1917</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>315</itunes:episode>
      <podcast:episode>315</podcast:episode>
      <itunes:title>Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1591f767-a9ec-4dd9-a0f1-90bd319961a8</guid>
      <link>https://share.transistor.fm/s/d5ab0a16</link>
      <description>
        <![CDATA[<p>Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.</p><p>Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding events that are likely to cause alerts, it was all very exciting. The challenge of successfully accomplishing the goal of that pen test, using essentially only native tools, was addictive for Jeff. He was hooked. Since those first penetration tests, Jeff has gone on to become an expert in the field, doing assessments for Fortune 100 companies, architecting two major versions of Core NetWars Experience, and contributing a vast amount of material to SANS Penetration Testing.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.</p><p>Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff found the offensive side of cyber security very alluring during one the first penetration tests of his career. Feeling the challenge of host defenses like AV and centralized logging, and, at the time, knowing nothing about AV evasion or avoiding events that are likely to cause alerts, it was all very exciting. The challenge of successfully accomplishing the goal of that pen test, using essentially only native tools, was addictive for Jeff. He was hooked. Since those first penetration tests, Jeff has gone on to become an expert in the field, doing assessments for Fortune 100 companies, architecting two major versions of Core NetWars Experience, and contributing a vast amount of material to SANS Penetration Testing.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Mon, 27 Apr 2026 04:56:19 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d5ab0a16/3543ea42.mp3" length="47109264" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tHXeV_EUIiDMZRW_jNlhnTZbHxI0NWJFfpiiH4HWz2w/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80ZmNi/ZWYwNzNlN2ZmMWFl/Y2ExZTg1NjE4NGI2/NTAwZS5wbmc.jpg"/>
      <itunes:duration>1961</itunes:duration>
      <itunes:summary>Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.</itunes:summary>
      <itunes:subtitle>Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How can we improve global security? With J. Michael Daniel from Cyber Threat Alliance [#314]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>314</itunes:episode>
      <podcast:episode>314</podcast:episode>
      <itunes:title>How can we improve global security? With J. Michael Daniel from Cyber Threat Alliance [#314]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">57e5663e-785f-49ff-a4c0-cb873c3a9bce</guid>
      <link>https://share.transistor.fm/s/c1458cd2</link>
      <description>
        <![CDATA[<p>J. Michael Daniel, President and CEO of Cyber Threat Alliance (CTA), gives us a peek behind the U.S. Government cybersecurity curtain and how he has helped improve the nation's security through the CTA.</p><p>Michael leads the CTA team and oversees the organization's operations. Prior to joining the CTA in February 2017, Michael served from June 2012 to January 2017 as Special Assistant to President Obama and Cybersecurity Coordinator on the National Security Council Staff. In this role, Michael led the development of national cybersecurity strategy and policy, and ensured that the US government effectively partnered with the private sector, non-governmental organizations, and other nations. Learn more at: <a rel="noreferrer noopener" href="https://www.cyberthreatalliance.org/">https://www.cyberthreatalliance.org/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>J. Michael Daniel, President and CEO of Cyber Threat Alliance (CTA), gives us a peek behind the U.S. Government cybersecurity curtain and how he has helped improve the nation's security through the CTA.</p><p>Michael leads the CTA team and oversees the organization's operations. Prior to joining the CTA in February 2017, Michael served from June 2012 to January 2017 as Special Assistant to President Obama and Cybersecurity Coordinator on the National Security Council Staff. In this role, Michael led the development of national cybersecurity strategy and policy, and ensured that the US government effectively partnered with the private sector, non-governmental organizations, and other nations. Learn more at: <a rel="noreferrer noopener" href="https://www.cyberthreatalliance.org/">https://www.cyberthreatalliance.org/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 22 Apr 2026 13:35:20 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c1458cd2/ee8cc3b4.mp3" length="58417053" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2427</itunes:duration>
      <itunes:summary>J. Michael Daniel, President and CEO of Cyber Threat Alliance , gives us a peek behind the U.S. Government cybersecurity curtain.</itunes:summary>
      <itunes:subtitle>J. Michael Daniel, President and CEO of Cyber Threat Alliance , gives us a peek behind the U.S. Government cybersecurity curtain.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>China-linked group targets cloud workflows, Russian cyber espionage, agentic AI systems flaw &amp; Nginx vulnerability / Intel Chat [#313]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>313</itunes:episode>
      <podcast:episode>313</podcast:episode>
      <itunes:title>China-linked group targets cloud workflows, Russian cyber espionage, agentic AI systems flaw &amp; Nginx vulnerability / Intel Chat [#313]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ff921c65-b90b-4ec8-9186-6aef995a3d33</guid>
      <link>https://share.transistor.fm/s/639228a9</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>Intercept and control AI agent activity with Viberails by LimaCharlie: <a rel="noreferrer noopener" href="https://www.viberails.io/">viberails.io</a></p><ul><li>APT41, a China-linked threat group is deploying a previously undetected backdoor targeting <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/apt41-zero-detection-backdoor-harvest-cloud-credentials">Linux based cloud workflows</a>.</li><li>Fancy bear, also known as APT28 or Forest Blizzard, is a Russian cyber espionage group believed to operate on behalf of the country's military <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/russias-fancy-bear-apt-continues-global-onslaught">intelligence services, the GRU</a>. Trend Micro research <a rel="noreferrer noopener" href="https://www.trendmicro.com/en_us/research/26/c/pawn-storm-targets-govt-infra.html">here</a>.</li><li>Anthropic’s Model Control Protocol widely used in agentic AI systems to connect AI agents with data sources, contains a design flaw that would enable <a rel="noreferrer noopener" href="https://www.securityweek.com/by-design-flaw-in-mcp-could-enable-widespread-ai-supply-chain-attacks/">large-scale supply chain attacks</a>. Report <a rel="noreferrer noopener" href="https://20204725.hs-sites.com/the-mother-of-all-ai-supply-chains">here</a>.</li><li>There's a critical vulnerability in nginx-UI, a web-based management interface for Nginx servers, which is being actively exploited and could allow attackers to take <a rel="noreferrer noopener" href="https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html">full control affected systems</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>Intercept and control AI agent activity with Viberails by LimaCharlie: <a rel="noreferrer noopener" href="https://www.viberails.io/">viberails.io</a></p><ul><li>APT41, a China-linked threat group is deploying a previously undetected backdoor targeting <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/apt41-zero-detection-backdoor-harvest-cloud-credentials">Linux based cloud workflows</a>.</li><li>Fancy bear, also known as APT28 or Forest Blizzard, is a Russian cyber espionage group believed to operate on behalf of the country's military <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/russias-fancy-bear-apt-continues-global-onslaught">intelligence services, the GRU</a>. Trend Micro research <a rel="noreferrer noopener" href="https://www.trendmicro.com/en_us/research/26/c/pawn-storm-targets-govt-infra.html">here</a>.</li><li>Anthropic’s Model Control Protocol widely used in agentic AI systems to connect AI agents with data sources, contains a design flaw that would enable <a rel="noreferrer noopener" href="https://www.securityweek.com/by-design-flaw-in-mcp-could-enable-widespread-ai-supply-chain-attacks/">large-scale supply chain attacks</a>. Report <a rel="noreferrer noopener" href="https://20204725.hs-sites.com/the-mother-of-all-ai-supply-chains">here</a>.</li><li>There's a critical vulnerability in nginx-UI, a web-based management interface for Nginx servers, which is being actively exploited and could allow attackers to take <a rel="noreferrer noopener" href="https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html">full control affected systems</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 20 Apr 2026 13:00:20 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/639228a9/3c28785f.mp3" length="45034143" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/aWkKWPDop0KOZOokH4o3SQznRkbC3burk1qx-G03yxs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMjZl/YzhmNDEwOWI2Mzll/NDU4MTZlM2M2NmU2/YmVkMS5wbmc.jpg"/>
      <itunes:duration>1869</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How do you know your AI agents are actually correct? With Dylan Williams from Spectrum Security / Defender Fridays [#312]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>312</itunes:episode>
      <podcast:episode>312</podcast:episode>
      <itunes:title>How do you know your AI agents are actually correct? With Dylan Williams from Spectrum Security / Defender Fridays [#312]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b5f5abf9-b74a-4d90-b4f7-b78e9dcbf786</guid>
      <link>https://share.transistor.fm/s/b503dfa0</link>
      <description>
        <![CDATA[<p>Today, Dylan Williams, Co-Founder and Chief Research Officer at Spectrum Security, joins Defender Fridays to dig into that exact problem: self-evaluating agents, trajectory analysis, and what improvement looks like in production.</p><p>Learn more at <a rel="noreferrer noopener" href="https://www.spectrum.security/">https://www.spectrum.security/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today, Dylan Williams, Co-Founder and Chief Research Officer at Spectrum Security, joins Defender Fridays to dig into that exact problem: self-evaluating agents, trajectory analysis, and what improvement looks like in production.</p><p>Learn more at <a rel="noreferrer noopener" href="https://www.spectrum.security/">https://www.spectrum.security/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 17 Apr 2026 13:16:04 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b503dfa0/65dd4587.mp3" length="48180286" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/VPhTuxm6GLSoWdVTuI4Kyufp3nh1PGow7yr5Ni3J77w/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNmJm/NWY3YWYwOWMwOWY1/NmM3ZDNlNzY1YTdk/NTI1Mi5wbmc.jpg"/>
      <itunes:duration>2006</itunes:duration>
      <itunes:summary>Dylan Williams, Spectrum Security, joins Defender Fridays to dig into self-evaluating agents, trajectory analysis, and what improvement looks like in production.</itunes:summary>
      <itunes:subtitle>Dylan Williams, Spectrum Security, joins Defender Fridays to dig into self-evaluating agents, trajectory analysis, and what improvement looks like in production.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Understanding how attackers think &amp; helping you avoid threats with Terry Bradley from Mile High Cyber [#311]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>311</itunes:episode>
      <podcast:episode>311</podcast:episode>
      <itunes:title>Understanding how attackers think &amp; helping you avoid threats with Terry Bradley from Mile High Cyber [#311]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0a556b06-1784-4030-b786-43247148c5b7</guid>
      <link>https://share.transistor.fm/s/d996042d</link>
      <description>
        <![CDATA[<p>Terry Bradley, Founder and President of Mile High Cyber, shares how you can uncover vulnerabilities and strengthen your organization's defenses with expert penetration testing and security assessments.</p><p>Terry is a former hacker for the NSA and uses those same skills at Mile High Club, the firm he founded, to help businesses stay one step ahead of cybercriminals. After a lifelong passion for security, starting with his time as a 1990 graduate of the U.S. Air Force Academy, Terry has spent his career understanding how attackers exploit weaknesses and helping businesses stay ahead of threats. From penetration testing to enterprise risk management, he's worked with organizations of all sizes to uncover vulnerabilities, enhance security resilience, and protect what matters most. Learn more at <a rel="noreferrer noopener" href="https://www.milehighcyber.com/">https://www.milehighcyber.com/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Terry Bradley, Founder and President of Mile High Cyber, shares how you can uncover vulnerabilities and strengthen your organization's defenses with expert penetration testing and security assessments.</p><p>Terry is a former hacker for the NSA and uses those same skills at Mile High Club, the firm he founded, to help businesses stay one step ahead of cybercriminals. After a lifelong passion for security, starting with his time as a 1990 graduate of the U.S. Air Force Academy, Terry has spent his career understanding how attackers exploit weaknesses and helping businesses stay ahead of threats. From penetration testing to enterprise risk management, he's worked with organizations of all sizes to uncover vulnerabilities, enhance security resilience, and protect what matters most. Learn more at <a rel="noreferrer noopener" href="https://www.milehighcyber.com/">https://www.milehighcyber.com/</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 15 Apr 2026 13:00:21 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d996042d/0545ae78.mp3" length="56331051" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2337</itunes:duration>
      <itunes:summary>Terry Bradley, Founder and President of Mile High Cyber, shares how you can uncover vulnerabilities and strengthen your organization's defenses with expert penetration testing and security assessments.</itunes:summary>
      <itunes:subtitle>Terry Bradley, Founder and President of Mile High Cyber, shares how you can uncover vulnerabilities and strengthen your organization's defenses with expert penetration testing and security assessments.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Iran-linked cyber attacks U.S. critical infrastructure, FlamingChina, Node.js targeted &amp; Storm-1175 / Intel Chat [#310]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>310</itunes:episode>
      <podcast:episode>310</podcast:episode>
      <itunes:title>Iran-linked cyber attacks U.S. critical infrastructure, FlamingChina, Node.js targeted &amp; Storm-1175 / Intel Chat [#310]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">073e26f4-32fb-40dd-aef6-ef51041d6c39</guid>
      <link>https://share.transistor.fm/s/f7dface5</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Federal cybersecurity agencies have issued an urgent warning about Iran-linked cyberattacks targeting operational technology (OT) systems across <a rel="noreferrer noopener" href="https://www.securityweek.com/iran-linked-hackers-disrupt-us-critical-infrastructure-via-plc-attacks/">U.S. critical infrastructure</a>.</li><li>A hacker operating under the alias “FlamingChina” claims to have breached a Chinese state-run supercomputing facility and stolen a large dataset that may exceed <a rel="noreferrer noopener" href="https://www.cnn.com/2026/04/08/china/china-supercomputer-hackers-hnk-intl">10 petabytes of information</a>.</li><li>Multiple high-profile maintainers in the Node.js ecosystem report being targeted in a coordinated social-engineering campaign aimed at compromising widely used <a rel="noreferrer noopener" href="https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers">open-source packages</a>.</li><li>Microsoft Threat Intelligence reports that the cybercrime group Storm-1175 is conducting rapid ransomware campaigns deploying the <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/storm-1175-medusa-ransomware-high-velocity">Medusa ransomware family</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Federal cybersecurity agencies have issued an urgent warning about Iran-linked cyberattacks targeting operational technology (OT) systems across <a rel="noreferrer noopener" href="https://www.securityweek.com/iran-linked-hackers-disrupt-us-critical-infrastructure-via-plc-attacks/">U.S. critical infrastructure</a>.</li><li>A hacker operating under the alias “FlamingChina” claims to have breached a Chinese state-run supercomputing facility and stolen a large dataset that may exceed <a rel="noreferrer noopener" href="https://www.cnn.com/2026/04/08/china/china-supercomputer-hackers-hnk-intl">10 petabytes of information</a>.</li><li>Multiple high-profile maintainers in the Node.js ecosystem report being targeted in a coordinated social-engineering campaign aimed at compromising widely used <a rel="noreferrer noopener" href="https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers">open-source packages</a>.</li><li>Microsoft Threat Intelligence reports that the cybercrime group Storm-1175 is conducting rapid ransomware campaigns deploying the <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/storm-1175-medusa-ransomware-high-velocity">Medusa ransomware family</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 13 Apr 2026 13:00:21 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f7dface5/492f91bd.mp3" length="56685921" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/EdRSDxLBq29ZHvRwcGZww3oTx9404gdC_M0gRcqel0g/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mMjMz/MzA3MGMyOGRhYjZh/OWU2MzQ4NmJiNmRl/YzM2Ny5wbmc.jpg"/>
      <itunes:duration>2355</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Levelling up your AI SOC with Joshua Neil from Alpha Level / Defender Fridays [#309]</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>309</itunes:episode>
      <podcast:episode>309</podcast:episode>
      <itunes:title>Levelling up your AI SOC with Joshua Neil from Alpha Level / Defender Fridays [#309]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4720e675-d2af-4b75-b671-e57735faa794</guid>
      <link>https://share.transistor.fm/s/bfd83327</link>
      <description>
        <![CDATA[<p>Joshua Neil, Co-Founder of Alpha Level, dives into a more sophisticated understanding of AI SOCs. Join the conversation about this industry change on Defender Fridays.</p><p>Dr. Joshua Neil, has been a pioneer in applying machine learning to cybersecurity since 2000, starting his journey at Los Alamos National Laboratory. There, he co-developed Pathscan, a network anomaly detection system capable of spotting attacks that slip past traditional defenses. In 2014, he and CEO Mike Pozmantier took that innovation to market by licensing Pathscan to Ernst &amp; Young (EY), turning deep research into enterprise impact.</p><p>That experience exposed a hard truth: anomaly detection is powerful at catching unknown threats - but on its own, it creates too much noise. Josh went on to tackle the other half of the problem, alert overload, through leadership roles at Microsoft and Securonix, gaining firsthand insight into the real-world struggles of security teams.</p><p>In 2023, Josh and Mike launched Alpha Level to bring both worlds together: pairing the depth of anomaly detection with the precision of behavioral threat signals. The result? A platform that reduces false positives, adapts to your environment, and lets teams focus on real threats—before they become breaches. Learn more here: <a rel="noreferrer noopener" href="https://alphalevel.ai/">https://alphalevel.ai/</a></p><p>Learn more at <a rel="noreferrer noopener" href="https://www.reconinfosec.com/">reconinfosec.com</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Joshua Neil, Co-Founder of Alpha Level, dives into a more sophisticated understanding of AI SOCs. Join the conversation about this industry change on Defender Fridays.</p><p>Dr. Joshua Neil, has been a pioneer in applying machine learning to cybersecurity since 2000, starting his journey at Los Alamos National Laboratory. There, he co-developed Pathscan, a network anomaly detection system capable of spotting attacks that slip past traditional defenses. In 2014, he and CEO Mike Pozmantier took that innovation to market by licensing Pathscan to Ernst &amp; Young (EY), turning deep research into enterprise impact.</p><p>That experience exposed a hard truth: anomaly detection is powerful at catching unknown threats - but on its own, it creates too much noise. Josh went on to tackle the other half of the problem, alert overload, through leadership roles at Microsoft and Securonix, gaining firsthand insight into the real-world struggles of security teams.</p><p>In 2023, Josh and Mike launched Alpha Level to bring both worlds together: pairing the depth of anomaly detection with the precision of behavioral threat signals. The result? A platform that reduces false positives, adapts to your environment, and lets teams focus on real threats—before they become breaches. Learn more here: <a rel="noreferrer noopener" href="https://alphalevel.ai/">https://alphalevel.ai/</a></p><p>Learn more at <a rel="noreferrer noopener" href="https://www.reconinfosec.com/">reconinfosec.com</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 10 Apr 2026 13:36:59 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/bfd83327/d42d03e1.mp3" length="49429210" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/-_6DrKpawRz8516T2O8nhksYurr0XTmrVpolaAxrIAM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82ODgy/YmQ2ZDdmNmY1ZmNj/NzNhODExZmU4MTVj/YTlkOC5wbmc.jpg"/>
      <itunes:duration>2058</itunes:duration>
      <itunes:summary>Joshua Neil, Co-Founder of Alpha Level, dives into a more sophisticated understanding of AI SOCs. Join the conversation about this industry change on Defender Fridays.</itunes:summary>
      <itunes:subtitle>Joshua Neil, Co-Founder of Alpha Level, dives into a more sophisticated understanding of AI SOCs. Join the conversation about this industry change on Defender Fridays.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Why cyber analysts are crucial in protecting public infrastructure with Michael Hamilton from PISCES International [#308]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>308</itunes:episode>
      <podcast:episode>308</podcast:episode>
      <itunes:title>Why cyber analysts are crucial in protecting public infrastructure with Michael Hamilton from PISCES International [#308]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">269ee65d-40be-4e87-80f7-38fb24059fea</guid>
      <link>https://share.transistor.fm/s/fd249997</link>
      <description>
        <![CDATA[<p>Michael Hamilton, Chief Technology Officer at PISCES International, joins us to discuss the benefits of providing real world experience to students while they protect existing public infrastructure. The resilient future of local government security rests in our ability to adapt to changing threats and adopt new technologies, including AI.</p><p>Learn more at <a rel="noreferrer noopener" href="https://pisces-intl.org/">https://pisces-intl.org/</a></p><p>30 years in Information Security as a practitioner, entrepreneur, consultant, and in executive management. Direct experience in retail, manufacturing, government, defense, academic, semiconductor, energy, law enforcement, transportation, publishing and financial sectors - from Fortune 1 to small nonprofits. </p><p>Formerly: Policy Advisor to Washington State, Chief Information Security Officer for the City of Seattle, and Managing Consultant for VeriSign Global Security Consulting. Former Vice-Chair of the DHS State, Local, Tribal and Territorial Government Coordinating Council.</p><p>Currently: Field CISO, Lumifi Cyber</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Michael Hamilton, Chief Technology Officer at PISCES International, joins us to discuss the benefits of providing real world experience to students while they protect existing public infrastructure. The resilient future of local government security rests in our ability to adapt to changing threats and adopt new technologies, including AI.</p><p>Learn more at <a rel="noreferrer noopener" href="https://pisces-intl.org/">https://pisces-intl.org/</a></p><p>30 years in Information Security as a practitioner, entrepreneur, consultant, and in executive management. Direct experience in retail, manufacturing, government, defense, academic, semiconductor, energy, law enforcement, transportation, publishing and financial sectors - from Fortune 1 to small nonprofits. </p><p>Formerly: Policy Advisor to Washington State, Chief Information Security Officer for the City of Seattle, and Managing Consultant for VeriSign Global Security Consulting. Former Vice-Chair of the DHS State, Local, Tribal and Territorial Government Coordinating Council.</p><p>Currently: Field CISO, Lumifi Cyber</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 08 Apr 2026 13:00:20 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fd249997/7cb33633.mp3" length="65377168" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2714</itunes:duration>
      <itunes:summary>Michael Hamilton, Chief Technology Officer at PISCES International, joins us to discuss the benefits of providing real world experience to students while they protect existing public infrastructure.</itunes:summary>
      <itunes:subtitle>Michael Hamilton, Chief Technology Officer at PISCES International, joins us to discuss the benefits of providing real world experience to students while they protect existing public infrastructure.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Iran’s IRGC threatens U.S. tech companies, FBI Director hacked, Venom Stealer &amp; Hasbro cyber attack / Intel Chat [#307]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>307</itunes:episode>
      <podcast:episode>307</podcast:episode>
      <itunes:title>Iran’s IRGC threatens U.S. tech companies, FBI Director hacked, Venom Stealer &amp; Hasbro cyber attack / Intel Chat [#307]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">26ce72dd-1d22-48bf-a929-d12b38430f7c</guid>
      <link>https://share.transistor.fm/s/89fdb521</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Iran’s Islamic Revolutionary Guard Core, or the IRGC, announced that it plans to begin attacks on more than a dozen American technology companies operating across the middle east, starting after 8pm <a rel="noreferrer noopener" href="https://www.wired.com/story/iran-threatens-to-start-attacking-major-us-tech-firms-on-april-1/">Tiran time on April 1st</a>.</li><li>A pro-Iranian hacking group, known as Hendala, has claimed responsibility for breaching a personal account belonging to <a rel="noreferrer noopener" href="https://www.securityweek.com/pro-iranian-hacking-group-claims-credit-for-hack-of-fbi-director-kash-patels-personal-account/">FBI Director, Kash Patel</a>.</li><li>A newly discovered malware-as-a-service platform called Venom Stealer is automating the creation and deployment of quick-fix social engineering attacks, significantly lowering the <a rel="noreferrer noopener" href="https://www.darkreading.com/endpoint-security/venom-stealer-maas-commoditizes-clickfix-attacks">barrier for cyber criminals</a>.</li><li>Toy and entertainment company, Hasbro, disclosed that it experienced a cyber attack that disrupted some of its internal operations, in a filing with the <a rel="noreferrer noopener" href="https://www.securityweek.com/toy-giant-hasbro-hit-by-cyberattack/">U.S. Securities and Exchange Commission</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Iran’s Islamic Revolutionary Guard Core, or the IRGC, announced that it plans to begin attacks on more than a dozen American technology companies operating across the middle east, starting after 8pm <a rel="noreferrer noopener" href="https://www.wired.com/story/iran-threatens-to-start-attacking-major-us-tech-firms-on-april-1/">Tiran time on April 1st</a>.</li><li>A pro-Iranian hacking group, known as Hendala, has claimed responsibility for breaching a personal account belonging to <a rel="noreferrer noopener" href="https://www.securityweek.com/pro-iranian-hacking-group-claims-credit-for-hack-of-fbi-director-kash-patels-personal-account/">FBI Director, Kash Patel</a>.</li><li>A newly discovered malware-as-a-service platform called Venom Stealer is automating the creation and deployment of quick-fix social engineering attacks, significantly lowering the <a rel="noreferrer noopener" href="https://www.darkreading.com/endpoint-security/venom-stealer-maas-commoditizes-clickfix-attacks">barrier for cyber criminals</a>.</li><li>Toy and entertainment company, Hasbro, disclosed that it experienced a cyber attack that disrupted some of its internal operations, in a filing with the <a rel="noreferrer noopener" href="https://www.securityweek.com/toy-giant-hasbro-hit-by-cyberattack/">U.S. Securities and Exchange Commission</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 06 Apr 2026 13:00:28 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/89fdb521/2d779d4f.mp3" length="33671116" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Aa6x7EwAl7bjqn83FxTkLcjO0mViCsTuay_3XvDhok0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wMWM5/YTI2ZjIyMjIzZDY3/N2Y3ZTI2NzJlYzkw/M2UyNC5wbmc.jpg"/>
      <itunes:duration>1397</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Malicious geopolitical cyber activity, cyberattacks tied to conflict in Iran, open source supply chain attack &amp; AI autonomous espionage / Intel Chat [#306]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>306</itunes:episode>
      <podcast:episode>306</podcast:episode>
      <itunes:title>Malicious geopolitical cyber activity, cyberattacks tied to conflict in Iran, open source supply chain attack &amp; AI autonomous espionage / Intel Chat [#306]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bd63eb1a-f860-44a3-90bf-67b27cc794e2</guid>
      <link>https://share.transistor.fm/s/30c4bad8</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Since the onset of the conflict in the Gulf region, cybersecurity researchers have observed a noticeable rise in malicious cyber activity <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/iran-hacktivists-impact-on-war">tied to geopolitical events</a>.</li><li>Unit 42 researchers are warning about an increased risk of destructive cyberattacks tied to the <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/">conflict involving Iran</a>.</li><li>The hacking group known as TeamPCP has expanded a large-scale supply chain campaign targeting widely used <a rel="noreferrer noopener" href="https://www.securityweek.com/from-trivy-to-broad-oss-compromise-teampcp-hits-docker-hub-vs-code-pypi/">open source software ecosystems</a>.</li><li>In September 2025, Anthropic disclosed an incident in which a state-sponsored threat actor used an AI coding agent to conduct an autonomous cyber espionage campaign targeting <a rel="noreferrer noopener" href="https://thehackernews.com/2026/03/the-kill-chain-is-obsolete-when-your-ai.html">30 organizations worldwide</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Since the onset of the conflict in the Gulf region, cybersecurity researchers have observed a noticeable rise in malicious cyber activity <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/iran-hacktivists-impact-on-war">tied to geopolitical events</a>.</li><li>Unit 42 researchers are warning about an increased risk of destructive cyberattacks tied to the <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/">conflict involving Iran</a>.</li><li>The hacking group known as TeamPCP has expanded a large-scale supply chain campaign targeting widely used <a rel="noreferrer noopener" href="https://www.securityweek.com/from-trivy-to-broad-oss-compromise-teampcp-hits-docker-hub-vs-code-pypi/">open source software ecosystems</a>.</li><li>In September 2025, Anthropic disclosed an incident in which a state-sponsored threat actor used an AI coding agent to conduct an autonomous cyber espionage campaign targeting <a rel="noreferrer noopener" href="https://thehackernews.com/2026/03/the-kill-chain-is-obsolete-when-your-ai.html">30 organizations worldwide</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 30 Mar 2026 13:00:13 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/30c4bad8/e3f96a5b.mp3" length="51455724" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/540RMG-xrdFe3J0n7Ch_7Mofa9CVu6TaGXgtYnFOgok/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yMjQw/NWVlODdhZmYzNGU0/YTJmMzFlOGZlNGQ3/YjRkZi5wbmc.jpg"/>
      <itunes:duration>2136</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>What makes a strong security team? With Andrew Cook from Recon InfoSec / Defender Fridays [#305]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>305</itunes:episode>
      <podcast:episode>305</podcast:episode>
      <itunes:title>What makes a strong security team? With Andrew Cook from Recon InfoSec / Defender Fridays [#305]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1141b6d3-60d2-4c1e-baf8-b10388c3bec4</guid>
      <link>https://share.transistor.fm/s/b13ce9ae</link>
      <description>
        <![CDATA[<p>This week on Defender Friday we are joined by Andrew Cook, CTO of Recon InfoSec, to talk about what it means to build a strong security team and why hiring builders is always a good bet.</p><p>As the CTO of Recon InfoSec, a leading provider of managed security operations, Andrew oversees the technical vision, strategy, and execution of their services and solutions. He has more than a decade of experience in threat hunting, digital forensics, network defense, and capability development.</p><p>Andrew's mission is to provide customers with the expertise they need to confidently and effectively respond to incidents, protect their organizations, and enhance their resilience. He has a proven track record of delivering high-quality results, leading and mentoring teams, and collaborating with partners across the industry and the government. Andrew is also a former Air Force officer, with national-level contributions and a passion for technical leadership.</p><p>Learn more at <a rel="noreferrer noopener" href="https://www.reconinfosec.com/">reconinfosec.com</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This week on Defender Friday we are joined by Andrew Cook, CTO of Recon InfoSec, to talk about what it means to build a strong security team and why hiring builders is always a good bet.</p><p>As the CTO of Recon InfoSec, a leading provider of managed security operations, Andrew oversees the technical vision, strategy, and execution of their services and solutions. He has more than a decade of experience in threat hunting, digital forensics, network defense, and capability development.</p><p>Andrew's mission is to provide customers with the expertise they need to confidently and effectively respond to incidents, protect their organizations, and enhance their resilience. He has a proven track record of delivering high-quality results, leading and mentoring teams, and collaborating with partners across the industry and the government. Andrew is also a former Air Force officer, with national-level contributions and a passion for technical leadership.</p><p>Learn more at <a rel="noreferrer noopener" href="https://www.reconinfosec.com/">reconinfosec.com</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 27 Mar 2026 12:02:56 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b13ce9ae/d6bd68af.mp3" length="46163610" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ZZWDy4zPEFmYtCjvRzZmRH2rqqkTW8R25UXuoZPt-9I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNzQz/YTljYmNkMTc3MTE5/ZDMyYzRkMTdkOGJl/NGU2NS5wbmc.jpg"/>
      <itunes:duration>1922</itunes:duration>
      <itunes:summary>This week on Defender Friday we are joined by Andrew Cook, CTO of Recon InfoSec, to talk about what it means to build a strong security team and why hiring builders is always a good bet.</itunes:summary>
      <itunes:subtitle>This week on Defender Friday we are joined by Andrew Cook, CTO of Recon InfoSec, to talk about what it means to build a strong security team and why hiring builders is always a good bet.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Bringing 40+ year old industrial security systems into the 21st century with Justin Searle from InGuardians [#304]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>304</itunes:episode>
      <podcast:episode>304</podcast:episode>
      <itunes:title>Bringing 40+ year old industrial security systems into the 21st century with Justin Searle from InGuardians [#304]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9c25314d-2091-4542-b47f-67ea99a019bf</guid>
      <link>https://share.transistor.fm/s/e11abe8a</link>
      <description>
        <![CDATA[<p>Justin Searle, Director of ICS Security at InGuardians, joins us today to talk about the challenges facing industrial control system security. With increased attack surface areas and maintaining and updating decades-old systems, Justin's dedication to informing and educating newcomers and experts alike is more important now than ever before.</p><p>As the Director of ICS Security at InGuardians, Justin specializes in ICS security architecture design and penetration testing. He led the Smart Grid Security Architecture group in creating the NIST Interagency Report 7628 and has played key roles in the Advanced Security Acceleration Project for the Smart Grid (ASAP-SG), National Electric Sector Cybersecurity Organization Resources (NESCOR), and Smart Grid Interoperability Panel (SGIP). </p><p>Justin is the owner of ControlThings LLC, a member of the SANS faculty, and an instructor at BlackHat. He has authored and taught numerous courses such as ICS410: ICS/SCADA Security Essentials,  Assessing and Exploiting Control Systems and IIoT, Assessing and Exploiting Web Applications with SamuraiWTF, and SEC542: Web App Penetration Testing and Ethical Hacking. Justin also presents on a range of cybersecurity topics at leading security conferences across the globe.</p><p>Learn more at: <a rel="noreferrer noopener" href="https://www.controlthings.io/tools">controlthings.io</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Justin Searle, Director of ICS Security at InGuardians, joins us today to talk about the challenges facing industrial control system security. With increased attack surface areas and maintaining and updating decades-old systems, Justin's dedication to informing and educating newcomers and experts alike is more important now than ever before.</p><p>As the Director of ICS Security at InGuardians, Justin specializes in ICS security architecture design and penetration testing. He led the Smart Grid Security Architecture group in creating the NIST Interagency Report 7628 and has played key roles in the Advanced Security Acceleration Project for the Smart Grid (ASAP-SG), National Electric Sector Cybersecurity Organization Resources (NESCOR), and Smart Grid Interoperability Panel (SGIP). </p><p>Justin is the owner of ControlThings LLC, a member of the SANS faculty, and an instructor at BlackHat. He has authored and taught numerous courses such as ICS410: ICS/SCADA Security Essentials,  Assessing and Exploiting Control Systems and IIoT, Assessing and Exploiting Web Applications with SamuraiWTF, and SEC542: Web App Penetration Testing and Ethical Hacking. Justin also presents on a range of cybersecurity topics at leading security conferences across the globe.</p><p>Learn more at: <a rel="noreferrer noopener" href="https://www.controlthings.io/tools">controlthings.io</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 25 Mar 2026 15:03:27 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e11abe8a/d4c45590.mp3" length="44989578" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1868</itunes:duration>
      <itunes:summary>Justin Searle, Director of ICS Security at InGuardians, joins us today to talk about the challenges facing industrial control system security.</itunes:summary>
      <itunes:subtitle>Justin Searle, Director of ICS Security at InGuardians, joins us today to talk about the challenges facing industrial control system security.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Is it smart to have AI agents act as employees? With David Burkett from Corelight / Defender Fridays [#303]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>303</itunes:episode>
      <podcast:episode>303</podcast:episode>
      <itunes:title>Is it smart to have AI agents act as employees? With David Burkett from Corelight / Defender Fridays [#303]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ace330a1-6f9f-4e8d-9997-0c7837afaea5</guid>
      <link>https://share.transistor.fm/s/9b856307</link>
      <description>
        <![CDATA[<p>David Burkett, Cloud Security Researcher at Corelight, is back on Defender Fridays this week to discuss thinking in pipelines for AI agents.</p><p>As a dedicated and highly experienced Cloud Detection Engineer and Security Architect, David has the privilege of working at a Fortune 50 Company where he leverages his extensive background in cybersecurity to protect digital assets. With a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.</p><p>David's expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. He's proud to have been part of a large overall security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. Our security operations center was recognized as being among the top 1% of cybersecurity programs for all cleared facilities.</p><p>In addition to his hands-on experience, David has consulted for over 40 Fortune 500 Companies and Large Federal Organizations, helping them manage their SOAR platforms and playbooks. As a strong believer in knowledge sharing and collaboration, he's also an active contributor to the open-source detection security project known as Sigma. Learn more at <a rel="noreferrer noopener" href="https://corelight.com/">https://corelight.com/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>David Burkett, Cloud Security Researcher at Corelight, is back on Defender Fridays this week to discuss thinking in pipelines for AI agents.</p><p>As a dedicated and highly experienced Cloud Detection Engineer and Security Architect, David has the privilege of working at a Fortune 50 Company where he leverages his extensive background in cybersecurity to protect digital assets. With a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.</p><p>David's expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. He's proud to have been part of a large overall security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. Our security operations center was recognized as being among the top 1% of cybersecurity programs for all cleared facilities.</p><p>In addition to his hands-on experience, David has consulted for over 40 Fortune 500 Companies and Large Federal Organizations, helping them manage their SOAR platforms and playbooks. As a strong believer in knowledge sharing and collaboration, he's also an active contributor to the open-source detection security project known as Sigma. Learn more at <a rel="noreferrer noopener" href="https://corelight.com/">https://corelight.com/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 20 Mar 2026 13:56:44 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9b856307/02576cbf.mp3" length="51031658" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/_f3PdrJtEmtInXdP-3OQjNlOMDRVY3qRCUfT7yvaJZE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMGYw/NGZiMDAxOTkzNmQw/YjM4NDdjMDAwZmYy/YzMyYi5wbmc.jpg"/>
      <itunes:duration>2125</itunes:duration>
      <itunes:summary>David Burkett, Cloud Security Researcher at Corelight, is back on Defender Fridays this week to discuss thinking in pipelines for AI agents.</itunes:summary>
      <itunes:subtitle>David Burkett, Cloud Security Researcher at Corelight, is back on Defender Fridays this week to discuss thinking in pipelines for AI agents.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How to think long-term growth in an AI-dominated industry with Stel Valavanis from onShore Networks [#302]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>302</itunes:episode>
      <podcast:episode>302</podcast:episode>
      <itunes:title>How to think long-term growth in an AI-dominated industry with Stel Valavanis from onShore Networks [#302]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">dd563f3b-e053-4b83-8308-be9e04686d6f</guid>
      <link>https://share.transistor.fm/s/0f1a25aa</link>
      <description>
        <![CDATA[<p>Today we're speaking with Stel Valavanis, Founder and Chairman at onShore Networks and Co-Founder at The Gallery Building, about sustaining a security company over three decades of industry changes. We also dive into investing in start ups and how founders can think long term about governance and growth.</p><p>Stel has over 40 years of experience ranging from software development to network design and cybersecurity. He's founded 8 companies, invested in 10 more, and sit on various boards. His goal is to build the best tech stack for his  customers but also wants to pay forward and make investments in startups, leveraging his knowledge and resources. Stel is always open to board positions and speaking engagements on cybersecurity, media technology, startup investing, and entrepreneurship.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Today we're speaking with Stel Valavanis, Founder and Chairman at onShore Networks and Co-Founder at The Gallery Building, about sustaining a security company over three decades of industry changes. We also dive into investing in start ups and how founders can think long term about governance and growth.</p><p>Stel has over 40 years of experience ranging from software development to network design and cybersecurity. He's founded 8 companies, invested in 10 more, and sit on various boards. His goal is to build the best tech stack for his  customers but also wants to pay forward and make investments in startups, leveraging his knowledge and resources. Stel is always open to board positions and speaking engagements on cybersecurity, media technology, startup investing, and entrepreneurship.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 19 Mar 2026 12:00:29 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0f1a25aa/e94ea6af.mp3" length="56169356" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2331</itunes:duration>
      <itunes:summary>Today we're speaking with Stel Valavanis, Founder and Chairman at onShore Networks, about how founders can think long term about governance and growth.</itunes:summary>
      <itunes:subtitle>Today we're speaking with Stel Valavanis, Founder and Chairman at onShore Networks, about how founders can think long term about governance and growth.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Cyber Strategy for America, new targets in war in Iran, Camaro Dragon &amp; medical manufacturer Stryker attacked / Intel Chat [#301]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>301</itunes:episode>
      <podcast:episode>301</podcast:episode>
      <itunes:title>Cyber Strategy for America, new targets in war in Iran, Camaro Dragon &amp; medical manufacturer Stryker attacked / Intel Chat [#301]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b8920854-7668-4989-a1ad-8a8c43838d75</guid>
      <link>https://share.transistor.fm/s/a0981938</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The White House released President Trump’s Cyber Strategy for America, outlining a national framework to strengthen both defensive and <a rel="noreferrer noopener" href="https://www.securityweek.com/us-cyber-strategy-targets-adversaries-critical-infrastructure-and-emerging-technologies/">offensive cybersecurity capabilities</a>.</li><li>Iran has expanded the scope of potential targets in the ongoing conflict with Israel and the United States by identifying infrastructure tied to major American technology companies in the <a rel="noreferrer noopener" href="https://www.financialexpress.com/world-news/us-linked-firms-in-middle-east-are-legitimate-targets-irans-new-warfront-puts-google-amazon-under-siege/4169694/">Middle East as “legitimate targets</a>.”</li><li>Chinese-linked threat actors have launched cyberattacks against organizations in Qatar shortly after the initial US-Israel strikes on Iran, indicating a <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/chinese-nexus-actors-shift-focus-qatar-iranian-conflict'">shift in regional targeting strategy</a>.</li><li>An Iranian-linked hacking group has claimed responsibility for a cyberattack on U.S.-based medical equipment manufacturer Stryker, which disrupted the company’s technology <a rel="noreferrer noopener" href="https://thehill.com/policy/technology/5779368-stryker-iran-hack-schoo-strike/">operations across its global offices</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The White House released President Trump’s Cyber Strategy for America, outlining a national framework to strengthen both defensive and <a rel="noreferrer noopener" href="https://www.securityweek.com/us-cyber-strategy-targets-adversaries-critical-infrastructure-and-emerging-technologies/">offensive cybersecurity capabilities</a>.</li><li>Iran has expanded the scope of potential targets in the ongoing conflict with Israel and the United States by identifying infrastructure tied to major American technology companies in the <a rel="noreferrer noopener" href="https://www.financialexpress.com/world-news/us-linked-firms-in-middle-east-are-legitimate-targets-irans-new-warfront-puts-google-amazon-under-siege/4169694/">Middle East as “legitimate targets</a>.”</li><li>Chinese-linked threat actors have launched cyberattacks against organizations in Qatar shortly after the initial US-Israel strikes on Iran, indicating a <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/chinese-nexus-actors-shift-focus-qatar-iranian-conflict'">shift in regional targeting strategy</a>.</li><li>An Iranian-linked hacking group has claimed responsibility for a cyberattack on U.S.-based medical equipment manufacturer Stryker, which disrupted the company’s technology <a rel="noreferrer noopener" href="https://thehill.com/policy/technology/5779368-stryker-iran-hack-schoo-strike/">operations across its global offices</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 17 Mar 2026 12:41:06 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a0981938/f5b63c14.mp3" length="47651524" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/w4qk_hoFWlG6O1c54QH_eizBNUWKY5m6A248dW-2CFs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lODM2/OTljOWY0YmVjZWUy/NzljOTc2ODg2ZDIw/OTcwMC5wbmc.jpg"/>
      <itunes:duration>1978</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Drones damage data centers, Iranian cyber retaliation, Sloppy Lemming &amp; Honeywell vulnerability / Intel Chat [#300]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>300</itunes:episode>
      <podcast:episode>300</podcast:episode>
      <itunes:title>Drones damage data centers, Iranian cyber retaliation, Sloppy Lemming &amp; Honeywell vulnerability / Intel Chat [#300]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bfdd9abf-e94d-42fb-9915-38bf68edae36</guid>
      <link>https://share.transistor.fm/s/c557bd01</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Iranian drone strikes damaged three Amazon Web Services data center facilities in the Middle East, highlighting the physical risks associated with <a rel="noreferrer noopener" href="https://www.theglobeandmail.com/investing/markets/indices/TTMT/pressreleases/540376/iranian-strikes-on-amazon-data-centers-highlight-industry-s-vulnerability-to-physical-disasters/">large-scale cloud infrastructure</a>.</li><li>Cyber activity linked to Iran and pro-Iranian actors has intensified following a joint US–Israeli military strike on Iran that killed Supreme Leader Ayatollah Ali Khamenei and <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/war-pro-iranian-actors-cyberattacks">several other government officials</a>.</li><li>The India-linked advanced persistent threat group known as “Sloppy Lemming” has significantly increased its cyber operations over the past year, targeting organizations in Pakistan, Bangladesh, and other <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/india-apt-sloppy-lemming-defense-critical-infrastructure">parts of South and Southeast Asia</a>.</li><li>A cybersecurity researcher has reported a potentially serious vulnerability in Honeywell’s IQ4 building management controller, though the vendor disputes both the severity and practical <a rel="noreferrer noopener" href="https://www.securityweek.com/honeywell-researcher-clash-over-impact-of-building-controller-vulnerability/">impact of the issue</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Iranian drone strikes damaged three Amazon Web Services data center facilities in the Middle East, highlighting the physical risks associated with <a rel="noreferrer noopener" href="https://www.theglobeandmail.com/investing/markets/indices/TTMT/pressreleases/540376/iranian-strikes-on-amazon-data-centers-highlight-industry-s-vulnerability-to-physical-disasters/">large-scale cloud infrastructure</a>.</li><li>Cyber activity linked to Iran and pro-Iranian actors has intensified following a joint US–Israeli military strike on Iran that killed Supreme Leader Ayatollah Ali Khamenei and <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/war-pro-iranian-actors-cyberattacks">several other government officials</a>.</li><li>The India-linked advanced persistent threat group known as “Sloppy Lemming” has significantly increased its cyber operations over the past year, targeting organizations in Pakistan, Bangladesh, and other <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/india-apt-sloppy-lemming-defense-critical-infrastructure">parts of South and Southeast Asia</a>.</li><li>A cybersecurity researcher has reported a potentially serious vulnerability in Honeywell’s IQ4 building management controller, though the vendor disputes both the severity and practical <a rel="noreferrer noopener" href="https://www.securityweek.com/honeywell-researcher-clash-over-impact-of-building-controller-vulnerability/">impact of the issue</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 09 Mar 2026 11:56:06 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c557bd01/e550e02f.mp3" length="51621151" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/U5YFD7RxgJcpxp7MLiXsdxCRSeaDuM8RPPb5JZiePxU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lMzFm/OGIyZjkxOGZiMzcz/NTQ2NDFhYTFlZDIy/NTRjMS5wbmc.jpg"/>
      <itunes:duration>2144</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Learning how to trust that AI is secure with Saurabh Shintre from Realm Labs / Defender Fridays [#299]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>299</itunes:episode>
      <podcast:episode>299</podcast:episode>
      <itunes:title>Learning how to trust that AI is secure with Saurabh Shintre from Realm Labs / Defender Fridays [#299]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f1a218bb-7c40-4ea2-b697-61b6cc4d0864</guid>
      <link>https://share.transistor.fm/s/30f7621d</link>
      <description>
        <![CDATA[<p>Saurabh Shintre, Founder and CEO of Realm Labs, is on Defender Fridays today to discuss securing AI from within.</p><p>Saurabh previously led the AI security research at Splunk and Symantec. He has been at the forefront of AI security research for nearly a decade with multiple publications and patents and regularly features on public forums on issues regarding security and AI. Saurabh holds a PhD from Carnegie Mellon. Learn more at <a rel="noreferrer noopener" href="https://www.realmlabs.ai/">https://www.realmlabs.ai/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Saurabh Shintre, Founder and CEO of Realm Labs, is on Defender Fridays today to discuss securing AI from within.</p><p>Saurabh previously led the AI security research at Splunk and Symantec. He has been at the forefront of AI security research for nearly a decade with multiple publications and patents and regularly features on public forums on issues regarding security and AI. Saurabh holds a PhD from Carnegie Mellon. Learn more at <a rel="noreferrer noopener" href="https://www.realmlabs.ai/">https://www.realmlabs.ai/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Learn more: <a rel="noreferrer noopener" href="https://docs.limacharlie.io/">https://docs.limacharlie.io/</a></p><p>Follow LimaCharlie</p><p>Sign up for free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p><p>LinkedIn:   / limacharlieio  </p><p>X: <a rel="noreferrer noopener" href="https://x.com/limacharlieio">https://x.com/limacharlieio</a></p><p>Community Discourse: <a rel="noreferrer noopener" href="https://community.limacharlie.com/">https://community.limacharlie.com/</a></p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Mon, 09 Mar 2026 10:02:48 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/30f7621d/019517b6.mp3" length="44029795" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/aw43dRF6AH0crH7PdVoID5YW8kurgkJ2HOriwF9USt4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hNzFm/Njk0MzJiNmViZTYz/NWNmMmI2YWVmNGQw/ZTM1Ny5wbmc.jpg"/>
      <itunes:duration>1833</itunes:duration>
      <itunes:summary>Saurabh Shintre, Founder and CEO of Realm Labs, is on Defender Fridays today to discuss securing AI from within.</itunes:summary>
      <itunes:subtitle>Saurabh Shintre, Founder and CEO of Realm Labs, is on Defender Fridays today to discuss securing AI from within.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>North Korean malware interviews, FortiGate firewall compromised, Cisco zero-day &amp; Citrini Research AI future / Intel Chat [#298]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>298</itunes:episode>
      <podcast:episode>298</podcast:episode>
      <itunes:title>North Korean malware interviews, FortiGate firewall compromised, Cisco zero-day &amp; Citrini Research AI future / Intel Chat [#298]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5560c8c2-9f56-48b9-aa72-016a39b55936</guid>
      <link>https://share.transistor.fm/s/b59ecb04</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>GitLab’s Threat Intelligence Team published detailed findings on North Korean activity associated with the Contagious Interview campaign and <a rel="noreferrer noopener" href="https://about.gitlab.com/blog/gitlab-threat-intelligence-reveals-north-korean-tradecraft/">broader IT worker operations</a>.</li><li>A financially motivated, Russian-speaking threat actor used generative AI tools to compromise more than 600 Fortinet FortiGate firewall instances between January and February, according to <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/600-fortigate-devices-hacked-ai-amateur">Amazon Web Services</a>.</li><li>Cisco has released emergency patches for a critical zero-day vulnerability in its Catalyst SD-WAN products that has been actively <a rel="noreferrer noopener" href="https://www.securityweek.com/cisco-patches-catalyst-sd-wan-zero-day-exploited-by-highly-sophisticated-hackers/">exploited in the wild</a>.</li><li>Citrini Research presents a forward-looking scenario framed as a June 2028 macro memo describing a “Global Intelligence Crisis” triggered by <a rel="noreferrer noopener" href="https://www.citriniresearch.com/p/2028gic">abundant AI-driven intelligence</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>GitLab’s Threat Intelligence Team published detailed findings on North Korean activity associated with the Contagious Interview campaign and <a rel="noreferrer noopener" href="https://about.gitlab.com/blog/gitlab-threat-intelligence-reveals-north-korean-tradecraft/">broader IT worker operations</a>.</li><li>A financially motivated, Russian-speaking threat actor used generative AI tools to compromise more than 600 Fortinet FortiGate firewall instances between January and February, according to <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/600-fortigate-devices-hacked-ai-amateur">Amazon Web Services</a>.</li><li>Cisco has released emergency patches for a critical zero-day vulnerability in its Catalyst SD-WAN products that has been actively <a rel="noreferrer noopener" href="https://www.securityweek.com/cisco-patches-catalyst-sd-wan-zero-day-exploited-by-highly-sophisticated-hackers/">exploited in the wild</a>.</li><li>Citrini Research presents a forward-looking scenario framed as a June 2028 macro memo describing a “Global Intelligence Crisis” triggered by <a rel="noreferrer noopener" href="https://www.citriniresearch.com/p/2028gic">abundant AI-driven intelligence</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 03 Mar 2026 13:57:35 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b59ecb04/1318dbd3.mp3" length="61399132" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ClQmL5VFVzbgpNKwqJZOqKQ8aK4WoJM5069jdiVl4lk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lYzMx/ZDJiYjhjMjZmZmFm/NzYxZjYzNGM4YzMy/MGYzOS5wbmc.jpg"/>
      <itunes:duration>2551</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI Red Teaming with John V from the Institute for Security and Technology / Defender Fridays [#297]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>297</itunes:episode>
      <podcast:episode>297</podcast:episode>
      <itunes:title>AI Red Teaming with John V from the Institute for Security and Technology / Defender Fridays [#297]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5f132ad4-f3f5-46c5-8057-d5f9050ec6b5</guid>
      <link>https://share.transistor.fm/s/713c4838</link>
      <description>
        <![CDATA[<p>John V, AI risk, safety, and security at the Institute for Security and Technology (IST), joins Defender Fridays today. </p><p>John's work spans AI red teaming, adversarial machine learning, AI evals and validation, and AI risk assessment, including policy work at the intersection of AGI and nuclear strategic stability. Learn more at <a rel="noreferrer noopener" href="https://securityandtechnology.org/">https://securityandtechnology.org/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>John V, AI risk, safety, and security at the Institute for Security and Technology (IST), joins Defender Fridays today. </p><p>John's work spans AI red teaming, adversarial machine learning, AI evals and validation, and AI risk assessment, including policy work at the intersection of AGI and nuclear strategic stability. Learn more at <a rel="noreferrer noopener" href="https://securityandtechnology.org/">https://securityandtechnology.org/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 27 Feb 2026 15:23:16 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/713c4838/b114ba52.mp3" length="44149533" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/j8a2ysJvtPFLxXscRkIMkOqQ-Wo77q77HqfbDnL_e9c/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85MDIx/MjkxZTM4NjVmMzRm/YzdhYzNkMWM3MjE2/ZDdjYi5wbmc.jpg"/>
      <itunes:duration>1838</itunes:duration>
      <itunes:summary>John V, AI risk, safety, and security at the Institute for Security and Technology (IST), joins Defender Fridays today.</itunes:summary>
      <itunes:subtitle>John V, AI risk, safety, and security at the Institute for Security and Technology (IST), joins Defender Fridays today.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How to Strengthen Cyber Resilience in an AI Era with Chris Cochran from SANS Institute [#296]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>296</itunes:episode>
      <podcast:episode>296</podcast:episode>
      <itunes:title>How to Strengthen Cyber Resilience in an AI Era with Chris Cochran from SANS Institute [#296]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f886f74a-be3e-4e8c-8d69-67f6ac986001</guid>
      <link>https://share.transistor.fm/s/be915862</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Chris Cochran, Field CISO &amp; Vice President of AI Security at <a rel="noreferrer noopener" href="https://www.sans.org/">SANS Institute</a>, about how to navigate the future of AI risk and security strategy</p><p>Chris works at the intersection of cyber defense, AI safety, and emerging risk, where the threats are converging and the playbooks are still being written. His career has taken him from the Marine Corps to NSA, U.S. Cyber Command, the U.S. House of Representatives, Mandiant, and Netflix. Across every role, one throughline: understanding adversaries, building high-trust teams, and translating complex problems into strategies leaders can act on.</p><p>Today, Chris advises organizations, governments, and research institutions on AI governance, agentic threat preparedness, and unifying safety and security into a single discipline. He contributes to global standards efforts including the EU AI Act (via OWASP AI) and leads executive education on cybersecurity and AI strategy at SANS.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Chris Cochran, Field CISO &amp; Vice President of AI Security at <a rel="noreferrer noopener" href="https://www.sans.org/">SANS Institute</a>, about how to navigate the future of AI risk and security strategy</p><p>Chris works at the intersection of cyber defense, AI safety, and emerging risk, where the threats are converging and the playbooks are still being written. His career has taken him from the Marine Corps to NSA, U.S. Cyber Command, the U.S. House of Representatives, Mandiant, and Netflix. Across every role, one throughline: understanding adversaries, building high-trust teams, and translating complex problems into strategies leaders can act on.</p><p>Today, Chris advises organizations, governments, and research institutions on AI governance, agentic threat preparedness, and unifying safety and security into a single discipline. He contributes to global standards efforts including the EU AI Act (via OWASP AI) and leads executive education on cybersecurity and AI strategy at SANS.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 25 Feb 2026 13:00:36 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/be915862/033517b7.mp3" length="45121499" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1875</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with Chris Cochran, Field CISO &amp;amp; Vice President of AI Security at SANS Institute, about how to navigate the future of AI risk and security strategy</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with Chris Cochran, Field CISO &amp;amp; Vice President of AI Security at SANS Institute, about how to navigate the future of AI risk and security strategy</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>DoppelBrand targets fortune 500s, Android malware Keenadu, attackers expand AI adoption &amp; endless AI-driven threats / Intel Chat [#295]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>295</itunes:episode>
      <podcast:episode>295</podcast:episode>
      <itunes:title>DoppelBrand targets fortune 500s, Android malware Keenadu, attackers expand AI adoption &amp; endless AI-driven threats / Intel Chat [#295]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8612192a-212b-4e13-bc67-1e18cda3aa1f</guid>
      <link>https://share.transistor.fm/s/c8c2dfeb</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A financially motivated threat actor known as GS7 is conducting a large-scale phishing campaign called Operation DoppelBrand, targeting Fortune 500 companies by impersonating <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/operation-doppelbrand-weaponizing-fortune-500-brands">their corporate login portals</a>.</li><li>Kaspersky researchers have analyzed a newly identified Android malware strain named Keenadu that provides attackers with remote <a rel="noreferrer noopener" href="https://www.securityweek.com/new-keenadu-android-malware-found-on-thousands-of-devices/">control over infected devices</a>.</li><li>Application Programming Interfaces continue to be a primary attack surface, and new research from Wallarm shows the problem is <a rel="noreferrer noopener" href="https://www.securityweek.com/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/">accelerating as AI adoption expands</a>.</li><li>Hacker News outlines cybersecurity technology priorities for 2026, framing the environment as one of continuous instability rather <a rel="noreferrer noopener" href="https://thehackernews.com/2026/02/cybersecurity-tech-predictions-for-2026.html">than periodic disruption</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A financially motivated threat actor known as GS7 is conducting a large-scale phishing campaign called Operation DoppelBrand, targeting Fortune 500 companies by impersonating <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/operation-doppelbrand-weaponizing-fortune-500-brands">their corporate login portals</a>.</li><li>Kaspersky researchers have analyzed a newly identified Android malware strain named Keenadu that provides attackers with remote <a rel="noreferrer noopener" href="https://www.securityweek.com/new-keenadu-android-malware-found-on-thousands-of-devices/">control over infected devices</a>.</li><li>Application Programming Interfaces continue to be a primary attack surface, and new research from Wallarm shows the problem is <a rel="noreferrer noopener" href="https://www.securityweek.com/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/">accelerating as AI adoption expands</a>.</li><li>Hacker News outlines cybersecurity technology priorities for 2026, framing the environment as one of continuous instability rather <a rel="noreferrer noopener" href="https://thehackernews.com/2026/02/cybersecurity-tech-predictions-for-2026.html">than periodic disruption</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 23 Feb 2026 13:00:35 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c8c2dfeb/47583042.mp3" length="57886922" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/QipanfV6bnVUj2LgZyb-QMRQmxqXNaUZ7VXkArGoQms/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MTll/ZTc4MDhjMjg3N2Uy/NjBhNmQ0ODMzMTI5/MDVmOC5wbmc.jpg"/>
      <itunes:duration>2405</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How is AI reshaping app security? With Farshad Abasi from Eureka DevSecOps / Defender Fridays [#294]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>294</itunes:episode>
      <podcast:episode>294</podcast:episode>
      <itunes:title>How is AI reshaping app security? With Farshad Abasi from Eureka DevSecOps / Defender Fridays [#294]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b66d7359-52ee-41d7-bb52-a5a0958a908e</guid>
      <link>https://share.transistor.fm/s/7b702df2</link>
      <description>
        <![CDATA[<p>This week on Defender Fridays, Farshad Abasi, Founder and CEO of Forward Security and Eureka DevSecOps, discusses how AI can help us set a new standard in app and cloud security. </p><p>Farshad brings over 27 years of industry experience to the forefront of cybersecurity innovation. His professional journey includes key technical roles at Intel and Motorola, evolving into senior security positions as the Principal Security Architect for HSBC Global, and Head of IT Security for the Canadian division. </p><p>Farshad's commitment to the field extends to his role as an instructor at BCIT, where he imparts his wealth of knowledge to the next generation of cybersecurity experts. His diverse experience, which spans startups to large enterprises, informs his approach to delivering adaptive and reliable solutions.</p><p>Engaged actively in the cybersecurity community through roles in BSides Vancouver/MARS, OWASP Vancouver/AppSec PNW, and as a CISSP designate, Farshad's vision and leadership continue to drive the industry forward. Under his guidance, Forward Security is setting new standards in application and cloud security. Learn more at <a rel="noreferrer noopener" href="https://www.eurekadevsecops.com/">https://www.eurekadevsecops.com/</a> and <a rel="noreferrer noopener" href="https://forwardsecurity.com/">https://forwardsecurity.com/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This week on Defender Fridays, Farshad Abasi, Founder and CEO of Forward Security and Eureka DevSecOps, discusses how AI can help us set a new standard in app and cloud security. </p><p>Farshad brings over 27 years of industry experience to the forefront of cybersecurity innovation. His professional journey includes key technical roles at Intel and Motorola, evolving into senior security positions as the Principal Security Architect for HSBC Global, and Head of IT Security for the Canadian division. </p><p>Farshad's commitment to the field extends to his role as an instructor at BCIT, where he imparts his wealth of knowledge to the next generation of cybersecurity experts. His diverse experience, which spans startups to large enterprises, informs his approach to delivering adaptive and reliable solutions.</p><p>Engaged actively in the cybersecurity community through roles in BSides Vancouver/MARS, OWASP Vancouver/AppSec PNW, and as a CISSP designate, Farshad's vision and leadership continue to drive the industry forward. Under his guidance, Forward Security is setting new standards in application and cloud security. Learn more at <a rel="noreferrer noopener" href="https://www.eurekadevsecops.com/">https://www.eurekadevsecops.com/</a> and <a rel="noreferrer noopener" href="https://forwardsecurity.com/">https://forwardsecurity.com/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 20 Feb 2026 14:30:09 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7b702df2/eef89b5f.mp3" length="44224774" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/efSx7HWAoaUQpUBPD3uvNrf0Rrk9JMZMs3EeOz08VkE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82MGRl/ZThiM2Y3ZDk3ZmZl/MDY1ZGZiMmI4OTJi/NTNkOS5wbmc.jpg"/>
      <itunes:duration>1842</itunes:duration>
      <itunes:summary>This week on Defender Fridays, Farshad Abasi, Founder and CEO of Forward Security and Eureka DevSecOps, discusses how AI can help us set a new standard in app and cloud security.</itunes:summary>
      <itunes:subtitle>This week on Defender Fridays, Farshad Abasi, Founder and CEO of Forward Security and Eureka DevSecOps, discusses how AI can help us set a new standard in app and cloud security.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Russian cyber ops, Sygnia, Ollama &amp; TeamPCP / Intel Chat [#293]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>293</itunes:episode>
      <podcast:episode>293</podcast:episode>
      <itunes:title>Russian cyber ops, Sygnia, Ollama &amp; TeamPCP / Intel Chat [#293]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c06980bc-64b8-45d9-8b69-04d29b27ace9</guid>
      <link>https://share.transistor.fm/s/6e53264f</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Russian cyber operations have maintained a consistent focus on exploiting both tactical and strategic targets within the defense industrial base, particularly in the context of the <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-base">war in Ukraine</a>.</li><li>Sygnia has disclosed a large-scale, AI-driven scam operation involving over 150 cloned <a rel="noreferrer noopener" href="https://www.securityweek.com/researchers-expose-network-of-150-cloned-law-firm-websites-in-ai-powered-scam-campaign/">websites impersonating law firms</a>.</li><li>A joint investigation by SentinelLabs and Censys has revealed a growing ecosystem of publicly exposed AI compute infrastructure, driven largely by deployments of Ollama - an open-source framework for running <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/researchers-find-175000-publicly.html">large language models locally</a>.</li><li>Flare has identified a widespread, ongoing campaign attributed to a threat actor group known as TeamPCP -also operating under aliases such as PCPcat and ShellForce - which has compromised over 60,000 servers <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/teampcp-cloud-infrastructure-crime-bots">worldwide since late December</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Russian cyber operations have maintained a consistent focus on exploiting both tactical and strategic targets within the defense industrial base, particularly in the context of the <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-base">war in Ukraine</a>.</li><li>Sygnia has disclosed a large-scale, AI-driven scam operation involving over 150 cloned <a rel="noreferrer noopener" href="https://www.securityweek.com/researchers-expose-network-of-150-cloned-law-firm-websites-in-ai-powered-scam-campaign/">websites impersonating law firms</a>.</li><li>A joint investigation by SentinelLabs and Censys has revealed a growing ecosystem of publicly exposed AI compute infrastructure, driven largely by deployments of Ollama - an open-source framework for running <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/researchers-find-175000-publicly.html">large language models locally</a>.</li><li>Flare has identified a widespread, ongoing campaign attributed to a threat actor group known as TeamPCP -also operating under aliases such as PCPcat and ShellForce - which has compromised over 60,000 servers <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/teampcp-cloud-infrastructure-crime-bots">worldwide since late December</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 16 Feb 2026 13:00:36 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6e53264f/5a4c249c.mp3" length="51781286" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/GI5L5U_NHrtshh0iKatOroGlhXUUZK-SokwdaMf5MHQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81ZjIx/NDk2Mjg5NmY2Zjcy/OGEwM2U4MTFjY2Rk/N2YxZS5wbmc.jpg"/>
      <itunes:duration>2149</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Are we overlooking our most precious resource - ourselves? With Brandon Min from Herd Security / Defender Fridays [#292]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>292</itunes:episode>
      <podcast:episode>292</podcast:episode>
      <itunes:title>Are we overlooking our most precious resource - ourselves? With Brandon Min from Herd Security / Defender Fridays [#292]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e4d39f13-a28a-4f0e-81b9-1aa12e0a0b72</guid>
      <link>https://share.transistor.fm/s/3507c013</link>
      <description>
        <![CDATA[<p>This week Brandon Min, Founder and CEO of Herd Security, joins Defender Fridays to discuss how human risk management needs to rebrand with empathy.</p><p>Brandon is the co-founder and CEO of Herd Security, where they help security teams drive employee engagement in security, making a more resilient organization. Humans have been the #1 target of organizational cyber attacks; however, security teams, organizations, vendors, and leaders have vilified them. </p><p>At Herd, they believe security should be led with empathy and care. Building trust amongst users that will drive their engagement in security. Building herd immunity from cyber attacks. Learn more at <a rel="noreferrer noopener" href="https://herdsecurity.io/">https://herdsecurity.io/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This week Brandon Min, Founder and CEO of Herd Security, joins Defender Fridays to discuss how human risk management needs to rebrand with empathy.</p><p>Brandon is the co-founder and CEO of Herd Security, where they help security teams drive employee engagement in security, making a more resilient organization. Humans have been the #1 target of organizational cyber attacks; however, security teams, organizations, vendors, and leaders have vilified them. </p><p>At Herd, they believe security should be led with empathy and care. Building trust amongst users that will drive their engagement in security. Building herd immunity from cyber attacks. Learn more at <a rel="noreferrer noopener" href="https://herdsecurity.io/">https://herdsecurity.io/</a></p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 13 Feb 2026 13:00:32 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3507c013/dfa9df33.mp3" length="46813415" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Oxiwjb0l0K5QBHpYnheLn2z2chH-rimwPlxJi6ist38/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNjUy/NzBmZjc2ZjZhZTQ1/NWYzODY4MTFjZjk0/ZmY5ZC5wbmc.jpg"/>
      <itunes:duration>1949</itunes:duration>
      <itunes:summary>This week on Defender Fridays, Brandon Min, Founder and CEO of Herd Security, discusses how human risk management needs to rebrand with empathy.</itunes:summary>
      <itunes:subtitle>This week on Defender Fridays, Brandon Min, Founder and CEO of Herd Security, discusses how human risk management needs to rebrand with empathy.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>OpenClaw saga continues, React Native Community vulnerability, Notepad++ &amp; GTIG targets IPIDEA proxy network / Intel Chat [#291]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>291</itunes:episode>
      <podcast:episode>291</podcast:episode>
      <itunes:title>OpenClaw saga continues, React Native Community vulnerability, Notepad++ &amp; GTIG targets IPIDEA proxy network / Intel Chat [#291]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9cf9ffd7-f7c8-4a0a-996d-05fc759b10e6</guid>
      <link>https://share.transistor.fm/s/d0943bd4</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>OpenClaw, an open source AI agent formerly known as MoltBot and ClawdBot, has rapidly become the fastest-growing project on GitHub, amassing over <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/openclaw-ai-runs-wild-business-environments">113,000 stars in under a week</a>.</li><li>A critical vulnerability in the React Native Community CLI NPM package, tracked as CVE-2025-11953 with a CVSS score of 9.8, has been actively exploited in the wild since late December 2025, according to <a rel="noreferrer noopener" href="https://www.securityweek.com/critical-react-native-vulnerability-exploited-in-the-wild/">new findings by VulnCheck</a>. <a rel="noreferrer noopener" href="https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability/">JFrog article.</a></li><li>Following the disclosure in the Notepad++ v8.8.9 release announcement, further investigation confirmed a sophisticated supply chain attack that targeted the <a rel="noreferrer noopener" href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/">application's update mechanism</a>.</li><li>Google, in coordination with multiple partners, has undertaken a large-scale disruption effort targeting the IPIDEA proxy network, which it identifies as one of the largest residential <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network">proxy networks globally</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>OpenClaw, an open source AI agent formerly known as MoltBot and ClawdBot, has rapidly become the fastest-growing project on GitHub, amassing over <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/openclaw-ai-runs-wild-business-environments">113,000 stars in under a week</a>.</li><li>A critical vulnerability in the React Native Community CLI NPM package, tracked as CVE-2025-11953 with a CVSS score of 9.8, has been actively exploited in the wild since late December 2025, according to <a rel="noreferrer noopener" href="https://www.securityweek.com/critical-react-native-vulnerability-exploited-in-the-wild/">new findings by VulnCheck</a>. <a rel="noreferrer noopener" href="https://jfrog.com/blog/cve-2025-11953-critical-react-native-community-cli-vulnerability/">JFrog article.</a></li><li>Following the disclosure in the Notepad++ v8.8.9 release announcement, further investigation confirmed a sophisticated supply chain attack that targeted the <a rel="noreferrer noopener" href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/">application's update mechanism</a>.</li><li>Google, in coordination with multiple partners, has undertaken a large-scale disruption effort targeting the IPIDEA proxy network, which it identifies as one of the largest residential <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network">proxy networks globally</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 09 Feb 2026 13:00:31 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d0943bd4/440627a5.mp3" length="41032575" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/m8iiuYKrsTiYS4Yw0Wq4rwNwuindYvrPzN72vdvHhR0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lYTM4/YjViYjJlZDU4MmE4/MzYyZjQxN2M0ZTMy/M2I4NS5wbmc.jpg"/>
      <itunes:duration>1703</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Do you have a browser blind spot? With Cody Pierce from Neon Cyber / Defender Fridays [#290]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>290</itunes:episode>
      <podcast:episode>290</podcast:episode>
      <itunes:title>Do you have a browser blind spot? With Cody Pierce from Neon Cyber / Defender Fridays [#290]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bb02268d-158b-423a-ab4c-95b1e7e117dc</guid>
      <link>https://share.transistor.fm/s/7cdbe23b</link>
      <description>
        <![CDATA[<p>Most orgs have a major blind spot: the browser.</p><p>This week on Defender Fridays, we're joined by Cody Pierce, Co-Founder and CEO at Neon Cyber, to discuss why browser security remains a critical gap, from sophisticated phishing campaigns that bypass traditional controls to shadow AI tools operating outside your security perimeter.</p><p>Cody began his career in the computer security industry twenty-five years ago. The first half of his journey was rooted in deep R&amp;D for offensive security, and he had the privilege of leading great teams working on elite problems. Over the last decade, Cody have moved into product and leadership roles that allowed him to focus on developing and delivering innovative and differentiated capabilities through product incubation, development, and GTM activities. Cody says he gets the most joy from building and delivering products that bring order to the chaos of cyber security while giving defenders the upper hand.</p><p>About This Session</p><p>This office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Most orgs have a major blind spot: the browser.</p><p>This week on Defender Fridays, we're joined by Cody Pierce, Co-Founder and CEO at Neon Cyber, to discuss why browser security remains a critical gap, from sophisticated phishing campaigns that bypass traditional controls to shadow AI tools operating outside your security perimeter.</p><p>Cody began his career in the computer security industry twenty-five years ago. The first half of his journey was rooted in deep R&amp;D for offensive security, and he had the privilege of leading great teams working on elite problems. Over the last decade, Cody have moved into product and leadership roles that allowed him to focus on developing and delivering innovative and differentiated capabilities through product incubation, development, and GTM activities. Cody says he gets the most joy from building and delivering products that bring order to the chaos of cyber security while giving defenders the upper hand.</p><p>About This Session</p><p>This office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 06 Feb 2026 13:00:35 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7cdbe23b/72b3c276.mp3" length="49067005" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/0QzEEdBctHzFsrEqlxAIyZwOYg9WPT_fZJiSU4W3_lM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZTEz/YTJkM2FmMzAxZGU5/NjMyZWEyMWMzOTJh/MGJmYy5wbmc.jpg"/>
      <itunes:duration>2043</itunes:duration>
      <itunes:summary>This week on Defender Fridays, we're joined by Cody Pierce, Co-Founder and CEO at Neon Cyber, to discuss why browser security remains a critical gap.</itunes:summary>
      <itunes:subtitle>This week on Defender Fridays, we're joined by Cody Pierce, Co-Founder and CEO at Neon Cyber, to discuss why browser security remains a critical gap.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>PeckBirdy, ShinyHunters, OpenClaw (former Moltbot) impersonation &amp; ELECTRUM / Intel Chat [#289]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>289</itunes:episode>
      <podcast:episode>289</podcast:episode>
      <itunes:title>PeckBirdy, ShinyHunters, OpenClaw (former Moltbot) impersonation &amp; ELECTRUM / Intel Chat [#289]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3fefd3bd-bec9-42b1-8904-8e80e3ba4ecb</guid>
      <link>https://share.transistor.fm/s/fd6f046f</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers at Trend Micro have uncovered continued activity from China-aligned threat actors leveraging a cross-platform JavaScript-based command-and-control <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/china-backed-peckbirdy-cross-platform-attacks">framework known as "PeckBirdy"</a>.</li><li>Silent Push has identified an extensive phishing campaign targeting over 100 organizations, attributed to the <a rel="noreferrer noopener" href="https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/">threat actor group ShinyHunters</a>.</li><li>A malicious Visual Studio Code extension impersonating an AI coding assistant for OpenClaw (former Moltbot) has been discovered distributing malware via the official VS <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/fake-moltbot-ai-coding-assistant-on-vs.html">Code Extension Marketplace</a>.</li><li>Dragos has attributed the December 2025 cyberattack on the Polish power grid to the Russian state-sponsored group known as ELECTRUM, <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/russian-electrum-tied-to-december-2025.html">with medium confidence</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers at Trend Micro have uncovered continued activity from China-aligned threat actors leveraging a cross-platform JavaScript-based command-and-control <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/china-backed-peckbirdy-cross-platform-attacks">framework known as "PeckBirdy"</a>.</li><li>Silent Push has identified an extensive phishing campaign targeting over 100 organizations, attributed to the <a rel="noreferrer noopener" href="https://www.securityweek.com/over-100-organizations-targeted-in-shinyhunters-phishing-campaign/">threat actor group ShinyHunters</a>.</li><li>A malicious Visual Studio Code extension impersonating an AI coding assistant for OpenClaw (former Moltbot) has been discovered distributing malware via the official VS <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/fake-moltbot-ai-coding-assistant-on-vs.html">Code Extension Marketplace</a>.</li><li>Dragos has attributed the December 2025 cyberattack on the Polish power grid to the Russian state-sponsored group known as ELECTRUM, <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/russian-electrum-tied-to-december-2025.html">with medium confidence</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 02 Feb 2026 15:07:20 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fd6f046f/66307980.mp3" length="42595990" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/GBZcfv--J2bFgNALQI0J1Gc_3Cqil0PZa-KtsL2UW4Q/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82MzJi/OGQ2MzdkOWZlZTRj/OTRiODU0M2M4MGU4/MWM1Zi5wbmc.jpg"/>
      <itunes:duration>1769</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Agentic SecOps Workspace (ASW) office hours with LimaCharlie / Defender Fridays [#288]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>288</itunes:episode>
      <podcast:episode>288</podcast:episode>
      <itunes:title>Agentic SecOps Workspace (ASW) office hours with LimaCharlie / Defender Fridays [#288]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d3f7a10f-0286-45de-b95a-04b023227221</guid>
      <link>https://share.transistor.fm/s/1c661596</link>
      <description>
        <![CDATA[<p>Join us for a special Defender Fridays Office Hours session where the LimaCharlie team demonstrates the new Agentic SecOps Workspace (ASW) and explores what's possible when AI agents operate security infrastructure directly.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this hands-on session, we showcase real working implementations of AI in cybersecurity operations. From reverse engineering malware to automated rule tuning and infrastructure management, we demonstrate how AI agents are transforming security workflows from concept to production-ready tools in hours instead of days.</p><p>Key Topics</p><ul><li>Automated malware analysis and decompilation without traditional manual reverse engineering workflows</li><li>Rule tuning at scale: Investigating noisy detections, writing false positive rules, and deploying them autonomously</li><li>Infrastructure automation: Setting up data sources, configuring tenants, and managing security operations through AI agents</li><li>The permission model: Balancing AI capability with human oversight and approval workflows</li><li>Real-world applications: Custom reporting, detection coverage analysis, and operational time savings</li></ul><p>About This Session</p><p>This office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for a special Defender Fridays Office Hours session where the LimaCharlie team demonstrates the new Agentic SecOps Workspace (ASW) and explores what's possible when AI agents operate security infrastructure directly.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>What We'll Discuss</p><p>In this hands-on session, we showcase real working implementations of AI in cybersecurity operations. From reverse engineering malware to automated rule tuning and infrastructure management, we demonstrate how AI agents are transforming security workflows from concept to production-ready tools in hours instead of days.</p><p>Key Topics</p><ul><li>Automated malware analysis and decompilation without traditional manual reverse engineering workflows</li><li>Rule tuning at scale: Investigating noisy detections, writing false positive rules, and deploying them autonomously</li><li>Infrastructure automation: Setting up data sources, configuring tenants, and managing security operations through AI agents</li><li>The permission model: Balancing AI capability with human oversight and approval workflows</li><li>Real-world applications: Custom reporting, detection coverage analysis, and operational time savings</li></ul><p>About This Session</p><p>This office hours format brings together the LimaCharlie team to share practical experiences with AI-powered security operations. Rather than theoretical discussions, we demonstrate working tools and invite the community to share their own AI security experiments. The session highlights the rapid evolution of AI capabilities in cybersecurity and explores the changing relationship between security practitioners and automation.</p><p>Register for Live Sessions</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience.</p><p>Register here: https://limacharlie.io/defender-fridays</p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes!</p><p>Sponsored by LimaCharlie</p><p>This episode is brought to you by LimaCharlie, a cloud-native SecOps platform where AI agents operate security infrastructure directly. Founded in 2018, LimaCharlie provides complete API coverage across detection, response, automation, and telemetry, with multi-tenant architecture designed for MSSPs and MDR providers managing thousands of unique client environments.</p><p>Why LimaCharlie?</p><ul><li>Transparency: Complete visibility into every action and decision. No black boxes, no vendor lock-in.</li><li>Scalability: Security operations that scale like infrastructure, not like procurement cycles. Move at cloud speed.</li><li>Unopinionated Design: Integrate the tools you need, not just those contracts allow. Build security on your terms.</li><li>Agentic SecOps Workspace (ASW): AI agents that operate alongside your team with observable, auditable actions through the same APIs human analysts use.</li><li>Security Primitives: Composable building blocks that endure as tools come and go. Build once, evolve continuously.</li></ul><p>Try the Agentic SecOps Workspace free: https://limacharlie.io</p><p>Learn more: https://docs.limacharlie.io</p><p>Follow LimaCharlie</p><p>Sign up for free: https://limacharlie.io</p><p>LinkedIn:   / limacharlieio  </p><p>X: https://x.com/limacharlieio</p><p>Community Discourse: https://community.limacharlie.com/</p><p>Host: Maxime Lamothe-Brassard - CEO / Co-founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 30 Jan 2026 12:56:58 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1c661596/fb0be431.mp3" length="42889293" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/zlGx4TeRc-uMvQwRB3P5gYrkDmfTv1EeKywlFg3kslk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85YmIx/NWM1ZDlhMjdiZmEy/Zjg5ZDNiOGEwMzVk/YTE0Yy5wbmc.jpg"/>
      <itunes:duration>1785</itunes:duration>
      <itunes:summary>This week on Defender Fridays Office Hours session where the LimaCharlie team demonstrates the new Agentic SecOps Workspace (ASW) and explores what's possible when AI agents operate security infrastructure directly.</itunes:summary>
      <itunes:subtitle>This week on Defender Fridays Office Hours session where the LimaCharlie team demonstrates the new Agentic SecOps Workspace (ASW) and explores what's possible when AI agents operate security infrastructure directly.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>No Going Back: AI Redefines SecOps for Service Providers (MSSP) with a panel of computer scientists and security practitioners [#287]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>287</itunes:episode>
      <podcast:episode>287</podcast:episode>
      <itunes:title>No Going Back: AI Redefines SecOps for Service Providers (MSSP) with a panel of computer scientists and security practitioners [#287]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3f3efe2a-6d26-4e3d-b043-c73c6144784e</guid>
      <link>https://share.transistor.fm/s/092f9ef4</link>
      <description>
        <![CDATA[<p>In this special episode of The Cybersecurity Defenders Podcast, a panel of cybersecurity experts discuss the irreversible changes AI has brought to the industry. This panel originally aired on January 20th, 2026.</p><p>The panel attendees include:</p><ul><li>Christopher Luft (host) - Co-Founder / CCO, LimaCharlie</li><li>Maxime Lamothe-Brassard - Founder / CEO, LimaCharlie</li><li>Eric Capuano - Co-Founder, Digital Defense Institute</li><li>Joshua Neil - Co-Founder, Alpha Level</li><li>Kris Merritt - Advisor</li><li>Daniel Lees - Sr Staff Cloud Security Architect, Google</li></ul><p>LimaCharlie has watched the AI SOC conversation unfold and stayed quiet. Until now.</p><p>Security vendors are racing to attach chatbots to legacy platforms and call it innovation. AI SOC startups have raised hundreds of millions to build better alert triage. Both approaches solve the same narrow problem: helping analysts click faster.</p><p>Service providers managing hundreds or thousands of tenants face a different reality. Alert triage matters, but so does deployment, configuration, detection engineering, reporting, and onboarding. The tedious work that eats margin and slows growth spans the entire operation.</p><p>What if AI could operate your entire security infrastructure with the same access as your best analyst?</p><p>We built LimaCharlie for complete programmatic access from day one. we were building for AI operators before AI operators existed. On January 20th, we'll show you what happens when AI agents can do everything in a security platform, across every tenant, through natural language.</p><p>No marketing theater. Just real conversations and a demonstration of AI-driven security operations where you stay in control.</p><p>Learn more at <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this special episode of The Cybersecurity Defenders Podcast, a panel of cybersecurity experts discuss the irreversible changes AI has brought to the industry. This panel originally aired on January 20th, 2026.</p><p>The panel attendees include:</p><ul><li>Christopher Luft (host) - Co-Founder / CCO, LimaCharlie</li><li>Maxime Lamothe-Brassard - Founder / CEO, LimaCharlie</li><li>Eric Capuano - Co-Founder, Digital Defense Institute</li><li>Joshua Neil - Co-Founder, Alpha Level</li><li>Kris Merritt - Advisor</li><li>Daniel Lees - Sr Staff Cloud Security Architect, Google</li></ul><p>LimaCharlie has watched the AI SOC conversation unfold and stayed quiet. Until now.</p><p>Security vendors are racing to attach chatbots to legacy platforms and call it innovation. AI SOC startups have raised hundreds of millions to build better alert triage. Both approaches solve the same narrow problem: helping analysts click faster.</p><p>Service providers managing hundreds or thousands of tenants face a different reality. Alert triage matters, but so does deployment, configuration, detection engineering, reporting, and onboarding. The tedious work that eats margin and slows growth spans the entire operation.</p><p>What if AI could operate your entire security infrastructure with the same access as your best analyst?</p><p>We built LimaCharlie for complete programmatic access from day one. we were building for AI operators before AI operators existed. On January 20th, we'll show you what happens when AI agents can do everything in a security platform, across every tenant, through natural language.</p><p>No marketing theater. Just real conversations and a demonstration of AI-driven security operations where you stay in control.</p><p>Learn more at <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 28 Jan 2026 13:00:30 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/092f9ef4/8ef013c0.mp3" length="103736138" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>4323</itunes:duration>
      <itunes:summary>In this special episode, Christopher Luft hosts a panel discussion about AI in SecOps with Maxime Lamothe-Brassard, Eric Capuano, Joshua Neil, Kris Merritt and Daniel Lees.</itunes:summary>
      <itunes:subtitle>In this special episode, Christopher Luft hosts a panel discussion about AI in SecOps with Maxime Lamothe-Brassard, Eric Capuano, Joshua Neil, Kris Merritt and Daniel Lees.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Visual Studio Code malware, Sinkholes reversal, Chinese pen-testing &amp; FortiSIEM zero-day / Intel Chat [#286]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>286</itunes:episode>
      <podcast:episode>286</podcast:episode>
      <itunes:title>Visual Studio Code malware, Sinkholes reversal, Chinese pen-testing &amp; FortiSIEM zero-day / Intel Chat [#286]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e18dfd73-0f89-4481-af98-b64bdd09cb12</guid>
      <link>https://share.transistor.fm/s/51dba3af</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>North Korean threat actors are targeting macOS software developers in a new malware campaign that abuses Visual Studio Code (VS Code) confi gurations to deliver JavaScript-based backdoors, <a rel="noreferrer noopener" href="https://www.securityweek.com/north-korean-hackers-target-macos-developers-via-malicious-vs-code-projects/">according to research from Jamf</a>.</li><li>Sinkholes are usually seen as the end of a malicious campaign - the point where domains are <a rel="noreferrer noopener" href="https://disclosing.observer/2026/01/14/excavating-abuse-infrastructure-dns-sinkholes.html">seized and abuse stops</a>.</li><li>China’s pen-testing and red-team ecosystem has always been hard to observe, especially since many teams stopped participating in international <a rel="noreferrer noopener" href="https://substack.com/inbox/post/184574472">CTFs post-2018</a>.</li><li>A critical zero-day vulnerability, CVE-2025-64155, has been discovered in Fortinet’s FortiSIEM platform by Horizon3.ai, allowing unauthenticated remote code execution and <a rel="noreferrer noopener" href="https://horizon3.ai/attack-research/vulnerabilities/cve-2025-64155-fortinet-fortisiem/">privilege escalation to root</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>North Korean threat actors are targeting macOS software developers in a new malware campaign that abuses Visual Studio Code (VS Code) confi gurations to deliver JavaScript-based backdoors, <a rel="noreferrer noopener" href="https://www.securityweek.com/north-korean-hackers-target-macos-developers-via-malicious-vs-code-projects/">according to research from Jamf</a>.</li><li>Sinkholes are usually seen as the end of a malicious campaign - the point where domains are <a rel="noreferrer noopener" href="https://disclosing.observer/2026/01/14/excavating-abuse-infrastructure-dns-sinkholes.html">seized and abuse stops</a>.</li><li>China’s pen-testing and red-team ecosystem has always been hard to observe, especially since many teams stopped participating in international <a rel="noreferrer noopener" href="https://substack.com/inbox/post/184574472">CTFs post-2018</a>.</li><li>A critical zero-day vulnerability, CVE-2025-64155, has been discovered in Fortinet’s FortiSIEM platform by Horizon3.ai, allowing unauthenticated remote code execution and <a rel="noreferrer noopener" href="https://horizon3.ai/attack-research/vulnerabilities/cve-2025-64155-fortinet-fortisiem/">privilege escalation to root</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 26 Jan 2026 14:14:29 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/51dba3af/d9144e31.mp3" length="46165756" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/idf8EPAfXUNAAX2eJVGOhtrlWB5o8sBTUk18_-hQwCI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xYzMw/ZTU5ZWVkZWZlMTJl/OWIxYzExZmZmYzY4/ZGY0MC5wbmc.jpg"/>
      <itunes:duration>1918</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>The future of SOC leadership with John Hubbard from SANS Institute / Defender Fridays [#285]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>285</itunes:episode>
      <podcast:episode>285</podcast:episode>
      <itunes:title>The future of SOC leadership with John Hubbard from SANS Institute / Defender Fridays [#285]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bf3bc5b7-b5a3-4f7b-92e9-7f3ec612714e</guid>
      <link>https://share.transistor.fm/s/07b8cff5</link>
      <description>
        <![CDATA[<p>This week on Defender Fridays, John Hubbard, SANS Institute Cyber Defense Curriculum Lead, discusses the future of security operations and what it means for SOC leaders today. </p><p>We'll be talking about:</p><ul><li>Building continuous improvement into SOC leadership</li><li>Current vendor and product trends shaping security operations</li><li>AI's real impact on SOC jobs and operations</li></ul><p>Few instructors combine real-world security operations center (SOC) leadership, curriculum design, and frontline defense experience like John Hubbard. As a Senior Instructor at the SANS Institute, author of SANS SEC450: SOC Analyst Training – Applied Skills for Cyber Defense Operations, and co-author of SANS LDR551: Building and Leading Security Operations Centers, John translates years of frontline SOC leadership into practical lessons students can immediately apply. His courses give participants more than technical knowledge—they build the skills and judgment that ensure professionals thrive in modern security operations.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This week on Defender Fridays, John Hubbard, SANS Institute Cyber Defense Curriculum Lead, discusses the future of security operations and what it means for SOC leaders today. </p><p>We'll be talking about:</p><ul><li>Building continuous improvement into SOC leadership</li><li>Current vendor and product trends shaping security operations</li><li>AI's real impact on SOC jobs and operations</li></ul><p>Few instructors combine real-world security operations center (SOC) leadership, curriculum design, and frontline defense experience like John Hubbard. As a Senior Instructor at the SANS Institute, author of SANS SEC450: SOC Analyst Training – Applied Skills for Cyber Defense Operations, and co-author of SANS LDR551: Building and Leading Security Operations Centers, John translates years of frontline SOC leadership into practical lessons students can immediately apply. His courses give participants more than technical knowledge—they build the skills and judgment that ensure professionals thrive in modern security operations.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 23 Jan 2026 16:59:44 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/07b8cff5/9042175e.mp3" length="46361566" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/10OAO8BjV37gWLEHe4n4-LTv45L69Gkchk4tygfD_wM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81NjE4/ZTZiOGNjZTg3M2Jj/YjVlMTc3NDJhY2Rm/YzUxYy5wbmc.jpg"/>
      <itunes:duration>1931</itunes:duration>
      <itunes:summary>This week on Defender Fridays, John Hubbard, SANS Institute Cyber Defense Curriculum Lead, discusses the future of security operations and what it means for SOC leaders today.</itunes:summary>
      <itunes:subtitle>This week on Defender Fridays, John Hubbard, SANS Institute Cyber Defense Curriculum Lead, discusses the future of security operations and what it means for SOC leaders today.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>From AI SOC to AI in the SOC (and beyond) Ft. Mike Privette from Return on Security with Maxime Lamothe-Brassard from LimaCharlie [#284]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>284</itunes:episode>
      <podcast:episode>284</podcast:episode>
      <itunes:title>From AI SOC to AI in the SOC (and beyond) Ft. Mike Privette from Return on Security with Maxime Lamothe-Brassard from LimaCharlie [#284]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e3323be2-2731-489f-938e-e4be3305c611</guid>
      <link>https://share.transistor.fm/s/f1babe9b</link>
      <description>
        <![CDATA[<p>In this special episode of The Cybersecurity Defenders Podcast, Mike Privette hosts a keynote discussion with LimaCharlie Founder and CEO, Maxime Lamothe-Brassard. </p><p>LimaCharlie has watched the AI SOC conversation unfold and stayed quiet. Until now.</p><p>Security vendors are racing to attach chatbots to legacy platforms and call it innovation. AI SOC startups have raised hundreds of millions to build better alert triage. Both approaches solve the same narrow problem: helping analysts click faster.</p><p>Service providers managing hundreds or thousands of tenants face a different reality. Alert triage matters, but so does deployment, configuration, detection engineering, reporting, and onboarding. The tedious work that eats margin and slows growth spans the entire operation.</p><p>What if AI could operate your entire security infrastructure with the same access as your best analyst?</p><p>We built LimaCharlie for complete programmatic access from day one. we were building for AI operators before AI operators existed. On January 20th, we'll show you what happens when AI agents can do everything in a security platform, across every tenant, through natural language.</p><p>No marketing theater. Just real conversations and a demonstration of AI-driven security operations where you stay in control.</p><p>Learn more at <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this special episode of The Cybersecurity Defenders Podcast, Mike Privette hosts a keynote discussion with LimaCharlie Founder and CEO, Maxime Lamothe-Brassard. </p><p>LimaCharlie has watched the AI SOC conversation unfold and stayed quiet. Until now.</p><p>Security vendors are racing to attach chatbots to legacy platforms and call it innovation. AI SOC startups have raised hundreds of millions to build better alert triage. Both approaches solve the same narrow problem: helping analysts click faster.</p><p>Service providers managing hundreds or thousands of tenants face a different reality. Alert triage matters, but so does deployment, configuration, detection engineering, reporting, and onboarding. The tedious work that eats margin and slows growth spans the entire operation.</p><p>What if AI could operate your entire security infrastructure with the same access as your best analyst?</p><p>We built LimaCharlie for complete programmatic access from day one. we were building for AI operators before AI operators existed. On January 20th, we'll show you what happens when AI agents can do everything in a security platform, across every tenant, through natural language.</p><p>No marketing theater. Just real conversations and a demonstration of AI-driven security operations where you stay in control.</p><p>Learn more at <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io/</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 22 Jan 2026 20:26:18 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f1babe9b/d36e9fc2.mp3" length="89092833" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>3519</itunes:duration>
      <itunes:summary>In this special episode, Mike Privette hosts a keynote discussion with LimaCharlie Founder and CEO, Maxime Lamothe-Brassard on the transformative powers of LimaCharlie and AI-driven SecOps.</itunes:summary>
      <itunes:subtitle>In this special episode, Mike Privette hosts a keynote discussion with LimaCharlie Founder and CEO, Maxime Lamothe-Brassard on the transformative powers of LimaCharlie and AI-driven SecOps.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>VoidLink, AsyncRat, Predator spyware &amp; AI agents pose risk to enterprises / Intel Chat [#283]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>282</itunes:episode>
      <podcast:episode>282</podcast:episode>
      <itunes:title>VoidLink, AsyncRat, Predator spyware &amp; AI agents pose risk to enterprises / Intel Chat [#283]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fa9ac3d3-d50b-484e-a384-59704e26e7c6</guid>
      <link>https://share.transistor.fm/s/da87f064</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Security researchers at Check Point have uncovered a previously unknown Linux malware framework named VoidLink, which stands out for its <a rel="noreferrer noopener" href="https://arstechnica.com/security/2026/01/never-before-seen-linux-malware-is-far-more-advanced-than-typical/">complexity and modular design</a>.</li><li>Researchers at Trend Micro have identified a new phishing campaign that combines legitimate services and open-source tools to distribute AsyncRAT, a <a rel="noreferrer noopener" href="https://www.trendmicro.com/en_us/research/26/a/analyzing-a-a-multi-stage-asyncrat-campaign-via-mdr.html">commodity-remote access trojan</a>.</li><li>New research into Predator spyware reveals a deeper level of sophistication and operational intelligence <a rel="noreferrer noopener" href="https://www.securityweek.com/predator-spywares-granular-anti-analysis-features-exposed/">than previously understood</a>.</li><li>The widespread adoption of AI agents in enterprise environments is creating a new class of identity and access control risks as highlighted in a <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/ai-agents-are-becoming-privilege.html">new report from The Hacker News</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Security researchers at Check Point have uncovered a previously unknown Linux malware framework named VoidLink, which stands out for its <a rel="noreferrer noopener" href="https://arstechnica.com/security/2026/01/never-before-seen-linux-malware-is-far-more-advanced-than-typical/">complexity and modular design</a>.</li><li>Researchers at Trend Micro have identified a new phishing campaign that combines legitimate services and open-source tools to distribute AsyncRAT, a <a rel="noreferrer noopener" href="https://www.trendmicro.com/en_us/research/26/a/analyzing-a-a-multi-stage-asyncrat-campaign-via-mdr.html">commodity-remote access trojan</a>.</li><li>New research into Predator spyware reveals a deeper level of sophistication and operational intelligence <a rel="noreferrer noopener" href="https://www.securityweek.com/predator-spywares-granular-anti-analysis-features-exposed/">than previously understood</a>.</li><li>The widespread adoption of AI agents in enterprise environments is creating a new class of identity and access control risks as highlighted in a <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/ai-agents-are-becoming-privilege.html">new report from The Hacker News</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 20 Jan 2026 17:23:12 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/da87f064/87da6e0c.mp3" length="45956721" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/H9eIHQB_Skj_Xz6kwCZ-Y1nQtAt9fO8tY5rAEoMu94w/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82YTFk/MGZkOGVhOGI1NzFl/ZmVmZWUxZDljM2Iz/Y2RjOC5wbmc.jpg"/>
      <itunes:duration>1909</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Hiring fraud and deepfake AI with Tom Cross from GetReal Security / Defender Fridays [#282]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>282</itunes:episode>
      <podcast:episode>282</podcast:episode>
      <itunes:title>Hiring fraud and deepfake AI with Tom Cross from GetReal Security / Defender Fridays [#282]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">53f45317-20bb-40be-b699-7952b3d77489</guid>
      <link>https://share.transistor.fm/s/4a3e112c</link>
      <description>
        <![CDATA[<p>This week on Defender Fridays, Tom Cross, Head of Threat Research at <a rel="noreferrer noopener" href="https://www.getrealsecurity.com/">GetReal Security</a>, joins us to talk hiring fraud and deepfakes on our first Defender Fridays session of 2026!</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This week on Defender Fridays, Tom Cross, Head of Threat Research at <a rel="noreferrer noopener" href="https://www.getrealsecurity.com/">GetReal Security</a>, joins us to talk hiring fraud and deepfakes on our first Defender Fridays session of 2026!</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 16 Jan 2026 16:09:26 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4a3e112c/d26e4299.mp3" length="46479190" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/fAivz2k7Oo4tx79tBi_RlTF4oZAeibxtEHOQ62jM5ak/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wOGYw/NTE2OTliNTM2ZDAz/ZTA4MmMxZDMyY2Yw/NDZmMS5wbmc.jpg"/>
      <itunes:duration>1935</itunes:duration>
      <itunes:summary>This week on Defender Fridays, Tom Cross, Head of Threat Research at GetReal Security, takes us into the world of deepfakes and what to look for to avoid hiring fraud.</itunes:summary>
      <itunes:subtitle>This week on Defender Fridays, Tom Cross, Head of Threat Research at GetReal Security, takes us into the world of deepfakes and what to look for to avoid hiring fraud.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Ni8mare CVSS 10.0, malicious AI extensions, Venezuela blackout &amp; guilty BlackCat insiders / Intel Chat [#281]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>281</itunes:episode>
      <podcast:episode>281</podcast:episode>
      <itunes:title>Ni8mare CVSS 10.0, malicious AI extensions, Venezuela blackout &amp; guilty BlackCat insiders / Intel Chat [#281]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5d1ae2ac-115c-4544-b4ab-9d1c9dc18818</guid>
      <link>https://share.transistor.fm/s/9002a643</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A newly disclosed vulnerability in the workflow automation platform n8n, tracked as CVE-2026-21858 and rated CVSS 10.0, allows unauthenticated remote attackers to fully <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/critical-n8n-vulnerability-cvss-100.html">compromise exposed instances</a>.</li><li>Two malicious Chrome extensions impersonating a legitimate product from AITOPIA were found exfiltrating sensitive user data, including full AI chat histories, according to <a rel="noreferrer noopener" href="https://www.securityweek.com/chrome-extensions-with-900000-downloads-caught-stealing-ai-chats/">a report from OX Security</a>.</li><li>The recent U.S. military operation in Venezuela that led to the capture of President Nicolás Maduro may have included cyber operations, but official confirmation of <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/cyberattacks-part-military-operation-venezuela">cyber’s role remains ambiguous</a>.</li><li>Two U.S. citizens with professional backgrounds in cybersecurity have pleaded guilty to acting as affiliates of the ALPHV/BlackCat ransomware group, a prominent <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/us-cyber-pros-plead-guilty-over-ransomware-activity">ransomware-as-a-service (RaaS) operation</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A newly disclosed vulnerability in the workflow automation platform n8n, tracked as CVE-2026-21858 and rated CVSS 10.0, allows unauthenticated remote attackers to fully <a rel="noreferrer noopener" href="https://thehackernews.com/2026/01/critical-n8n-vulnerability-cvss-100.html">compromise exposed instances</a>.</li><li>Two malicious Chrome extensions impersonating a legitimate product from AITOPIA were found exfiltrating sensitive user data, including full AI chat histories, according to <a rel="noreferrer noopener" href="https://www.securityweek.com/chrome-extensions-with-900000-downloads-caught-stealing-ai-chats/">a report from OX Security</a>.</li><li>The recent U.S. military operation in Venezuela that led to the capture of President Nicolás Maduro may have included cyber operations, but official confirmation of <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/cyberattacks-part-military-operation-venezuela">cyber’s role remains ambiguous</a>.</li><li>Two U.S. citizens with professional backgrounds in cybersecurity have pleaded guilty to acting as affiliates of the ALPHV/BlackCat ransomware group, a prominent <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/us-cyber-pros-plead-guilty-over-ransomware-activity">ransomware-as-a-service (RaaS) operation</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 14 Jan 2026 15:37:59 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9002a643/3fb7d3cd.mp3" length="45152579" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/qKa0-DN3z88Bo1JcZH3KK9W3zzWUeZrHsUB89jpCpkM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jZjE4/ZWZmNDA0MjY5ZmVh/NzMwYjliM2QzN2Q4/NmZjNC5wbmc.jpg"/>
      <itunes:duration>1874</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>How AI is Re-Building the Cybersecurity Landscape with Max Lamothe-Brassard from LimaCharlie [#280]</title>
      <itunes:season>5</itunes:season>
      <podcast:season>5</podcast:season>
      <itunes:episode>280</itunes:episode>
      <podcast:episode>280</podcast:episode>
      <itunes:title>How AI is Re-Building the Cybersecurity Landscape with Max Lamothe-Brassard from LimaCharlie [#280]</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0f4405ff-b4e9-4735-8043-ac19b7814d74</guid>
      <link>https://share.transistor.fm/s/4af2246f</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we're starting the new season off with the hottest topic of 2025: AI. </p><p>Sitting down with Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, we discuss the ways AI has rapidly changed how companies are building security tools.</p><p>Join an in-depth discussion January 20, 2026 and witness LimaCharlie's fundamentally different approach to AI-powered security operations. Your security operations will never be the same: <a rel="noreferrer noopener" href="https://www.linkedin.com/events/7401665070889545728/">https://www.linkedin.com/events/7401665070889545728/</a></p><p>Maxime Lamothe-Brassard began his cybersecurity career at the Canadian Department of National Defense before providing direct assistance to organizations facing cyber defense challenges. His career includes key roles at CrowdStrike and Google, as well as being part of Chronicle Security’s founding team, ultimately leading him to establish <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a> to revolutionize security operations infrastructure. </p><p>Support our show and share your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we're starting the new season off with the hottest topic of 2025: AI. </p><p>Sitting down with Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, we discuss the ways AI has rapidly changed how companies are building security tools.</p><p>Join an in-depth discussion January 20, 2026 and witness LimaCharlie's fundamentally different approach to AI-powered security operations. Your security operations will never be the same: <a rel="noreferrer noopener" href="https://www.linkedin.com/events/7401665070889545728/">https://www.linkedin.com/events/7401665070889545728/</a></p><p>Maxime Lamothe-Brassard began his cybersecurity career at the Canadian Department of National Defense before providing direct assistance to organizations facing cyber defense challenges. His career includes key roles at CrowdStrike and Google, as well as being part of Chronicle Security’s founding team, ultimately leading him to establish <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a> to revolutionize security operations infrastructure. </p><p>Support our show and share your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 12 Jan 2026 14:24:26 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4af2246f/bb462e33.mp3" length="63896632" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2657</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we're sitting down with LimaCharlie Founder and CEO, Maxime Lamothe-Brassard to discuss the hottest topic of 2025: AI.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we're sitting down with LimaCharlie Founder and CEO, Maxime Lamothe-Brassard to discuss the hottest topic of 2025: AI.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#279 - 2025 Predictions for the Future of Cybersecurity with all our guests</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>279</itunes:episode>
      <podcast:episode>279</podcast:episode>
      <itunes:title>#279 - 2025 Predictions for the Future of Cybersecurity with all our guests</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f9109b60-fc87-492c-8c5b-19dade32903d</guid>
      <link>https://share.transistor.fm/s/96ad8451</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we revisit the 2025 predictions shared by our guests throughout the year. </p><p>From attackers and defenders to AI and the broader security industry, these forecasts capture what experts expected was coming next. Rather than judging accuracy - which is still too early to assess -we're examining the predictions themselves: where they aligned, how they clustered, and what those patterns reveal about the industry’s mindset as this year came to a close. Free from hindsight bias, this episode explores what remained uncertain as we entered 2026.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we revisit the 2025 predictions shared by our guests throughout the year. </p><p>From attackers and defenders to AI and the broader security industry, these forecasts capture what experts expected was coming next. Rather than judging accuracy - which is still too early to assess -we're examining the predictions themselves: where they aligned, how they clustered, and what those patterns reveal about the industry’s mindset as this year came to a close. Free from hindsight bias, this episode explores what remained uncertain as we entered 2026.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 22 Dec 2025 15:26:04 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/96ad8451/94fa30c0.mp3" length="81052007" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>3355</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we revisit the 2025 predictions shared by our guests throughout the year.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we revisit the 2025 predictions shared by our guests throughout the year.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#278 - Defender Fridays: Bug bounties, disclosures and real-world response with Bryan Brake from Amazon</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>#278 - Defender Fridays: Bug bounties, disclosures and real-world response with Bryan Brake from Amazon</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b3311ba5-3a10-4dc2-81aa-7ea6af874b9a</guid>
      <link>https://share.transistor.fm/s/699b0e49</link>
      <description>
        <![CDATA[<p>This week on Defender Fridays, Bryan Brake, Senior Product Manager and Bug Bounty Team Lead at Amazon, joins us to discuss vulnerability remediation, bounty processes, and incident response workflows.</p><p>Bryan will share practical insights on managing disclosures and coordinating responses across security teams.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This week on Defender Fridays, Bryan Brake, Senior Product Manager and Bug Bounty Team Lead at Amazon, joins us to discuss vulnerability remediation, bounty processes, and incident response workflows.</p><p>Bryan will share practical insights on managing disclosures and coordinating responses across security teams.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 19 Dec 2025 14:01:37 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/699b0e49/c2f18d01.mp3" length="47072311" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/hOEU_7HTwfnR-QWPJJMfNRmWzL-ZefNLlvzm0Bhtfgg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lOWIw/MDUyYzhhNWY0YTM3/MTY0NjJkOGNlNmU0/MjA5Yi5wbmc.jpg"/>
      <itunes:duration>1960</itunes:duration>
      <itunes:summary>Join us for this week's Defender Fridays as Bryan Brake, Senior Product Manager and Bug Bounty Team Lead at Amazon, shares practical insights on managing disclosures and coordinating responses across security teams.</itunes:summary>
      <itunes:subtitle>Join us for this week's Defender Fridays as Bryan Brake, Senior Product Manager and Bug Bounty Team Lead at Amazon, shares practical insights on managing disclosures and coordinating responses across security teams.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#277 - BlackGirlsHack: Building a community and impactful legacy with Rebekah Skeete</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>277</itunes:episode>
      <podcast:episode>277</podcast:episode>
      <itunes:title>#277 - BlackGirlsHack: Building a community and impactful legacy with Rebekah Skeete</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">90817a6a-6400-4b68-add9-b18bb12011ba</guid>
      <link>https://share.transistor.fm/s/21ff9cf3</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Rebekah Skeete, Executive Director and CEO of <a rel="noreferrer noopener" href="https://www.blackgirlshack.org/">BlackGirlsHack Foundation</a>. Rebekah dives into how BGH is helping to increase diversity in cybersecurity by bridging the gap between what is taught in educational institutions and what is necessary for careers in cybersecurity.</p><p>For more information visit: <a rel="noreferrer noopener" href="https://www.blackgirlshack.org/Home">https://www.blackgirlshack.org/Home</a></p><p>Rebekah Skeete is a Security Engineer with Schellman based in Dallas, Texas. As a member of the Infrastructure and Security team, Rebekah is part of a collaborative group of technology professionals serving as the primary technical resource to safeguard the organization's computer networks and systems. In her role, she is responsible for planning and carrying out security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks. </p><p>Prior to joining Schellman in 2022, Rebekah worked for the Texas Rangers in a myriad of roles, including Cybersecurity Analyst and Manager of IT Applications and Operations. During the construction of the Rangers new state-of-the-art ballpark, Globe Life Field, Rebekah assisted the Rangers IT department’s efforts to transition over 200 front office employees to their new workspaces. </p><p>Outside baseball and IT, Rebekah is also interested in politics and started volunteering for campaigns in 2008. From 2013-2016, she served as a Campaign Manager in the Dallas-Fort Worth area. In 2015, she attended the Women’s Campaign School at Yale. </p><p>Rebekah is the COO of BlackGirlsHack, a nonprofit organization providing black women with resources, training, mentoring, and access to increase representation and diversity in the cybersecurity field. Committed to inclusion and belonging, she holds the firm belief that representation enhances the culture and community of an organization and seeks to amplify underserved voices at any table she has a seat.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Rebekah Skeete, Executive Director and CEO of <a rel="noreferrer noopener" href="https://www.blackgirlshack.org/">BlackGirlsHack Foundation</a>. Rebekah dives into how BGH is helping to increase diversity in cybersecurity by bridging the gap between what is taught in educational institutions and what is necessary for careers in cybersecurity.</p><p>For more information visit: <a rel="noreferrer noopener" href="https://www.blackgirlshack.org/Home">https://www.blackgirlshack.org/Home</a></p><p>Rebekah Skeete is a Security Engineer with Schellman based in Dallas, Texas. As a member of the Infrastructure and Security team, Rebekah is part of a collaborative group of technology professionals serving as the primary technical resource to safeguard the organization's computer networks and systems. In her role, she is responsible for planning and carrying out security measures to monitor and protect sensitive data and systems from infiltration and cyber-attacks. </p><p>Prior to joining Schellman in 2022, Rebekah worked for the Texas Rangers in a myriad of roles, including Cybersecurity Analyst and Manager of IT Applications and Operations. During the construction of the Rangers new state-of-the-art ballpark, Globe Life Field, Rebekah assisted the Rangers IT department’s efforts to transition over 200 front office employees to their new workspaces. </p><p>Outside baseball and IT, Rebekah is also interested in politics and started volunteering for campaigns in 2008. From 2013-2016, she served as a Campaign Manager in the Dallas-Fort Worth area. In 2015, she attended the Women’s Campaign School at Yale. </p><p>Rebekah is the COO of BlackGirlsHack, a nonprofit organization providing black women with resources, training, mentoring, and access to increase representation and diversity in the cybersecurity field. Committed to inclusion and belonging, she holds the firm belief that representation enhances the culture and community of an organization and seeks to amplify underserved voices at any table she has a seat.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 17 Dec 2025 15:08:47 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/21ff9cf3/73ac065d.mp3" length="66458073" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2761</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Rebekah Skeete, Executive Director and CEO of BlackGirlsHack Foundation about gaps in the cybersecurity industry.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Rebekah Skeete, Executive Director and CEO of BlackGirlsHack Foundation about gaps in the cybersecurity industry.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#276 - Intel Chat: React2Shell, GeminiJack vulnerability, pro‑Russia hacktivist arrested &amp; Warp Panda</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>276</itunes:episode>
      <podcast:episode>276</podcast:episode>
      <itunes:title>#276 - Intel Chat: React2Shell, GeminiJack vulnerability, pro‑Russia hacktivist arrested &amp; Warp Panda</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">32b16599-4ca7-4073-8ffe-eeff2b6da355</guid>
      <link>https://share.transistor.fm/s/a20e26a3</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>For for more information about Cybersecurity Cares, visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p><ul><li>React2Shell is the latest high-profile vulnerability in the web application landscape, scoring a critical CVSS 10.0 and drawing i<a rel="noreferrer noopener" href="https://www.detectionengineering.net/i/181124037/threat-landscape">mmediate comparisons to Log4Shell</a>.</li><li>Researchers at Noma Labs disclosed a critical vulnerability in Google's Gemini Enterprise AI assistant, dubbed GeminiJack, that allowed attackers to stealthily <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/gemini-enterprise-exposes-sensitive-data">exfiltrate sensitive enterprise data</a>.</li><li>U.S. prosecutors have charged Victoria Eduardovna Dubranova, a 33‑year‑old Ukrainian woman, in two separate indictments for her alleged involvement with pro‑Russia hacktivist groups <a rel="noreferrer noopener" href="https://www.securityweek.com/us-indicts-extradited-ukrainian-on-charges-of-aiding-russian-hacking-groups/">CyberArmyofRussia_Reborn and NoName057(16)</a>.</li><li>A China-aligned threat actor identified as Warp Panda has been linked to recent compromises of VMware vCenter environments at U.S.-based organizations, <a rel="noreferrer noopener" href="https://www.cybersecuritydive.com/news/china-actor-us-entities-brickstorm-malware/807166/">according to a new report from CrowdStrike</a>. <a rel="noreferrer noopener" href="https://www.crowdstrike.com/en-us/blog/warp-panda-cloud-threats/">Original CrowdStrike article</a>. <a rel="noreferrer noopener" href="https://www.cisa.gov/news-events/analysis-reports/ar25-338a">CISA BRICKSTORM Backdoor breakdown</a>. <a rel="noreferrer noopener" href="https://www.cisa.gov/sites/default/files/2025-12/malware-analysis-report-brickstorm-backdoor.pdf">Analysis report</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>For for more information about Cybersecurity Cares, visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p><ul><li>React2Shell is the latest high-profile vulnerability in the web application landscape, scoring a critical CVSS 10.0 and drawing i<a rel="noreferrer noopener" href="https://www.detectionengineering.net/i/181124037/threat-landscape">mmediate comparisons to Log4Shell</a>.</li><li>Researchers at Noma Labs disclosed a critical vulnerability in Google's Gemini Enterprise AI assistant, dubbed GeminiJack, that allowed attackers to stealthily <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/gemini-enterprise-exposes-sensitive-data">exfiltrate sensitive enterprise data</a>.</li><li>U.S. prosecutors have charged Victoria Eduardovna Dubranova, a 33‑year‑old Ukrainian woman, in two separate indictments for her alleged involvement with pro‑Russia hacktivist groups <a rel="noreferrer noopener" href="https://www.securityweek.com/us-indicts-extradited-ukrainian-on-charges-of-aiding-russian-hacking-groups/">CyberArmyofRussia_Reborn and NoName057(16)</a>.</li><li>A China-aligned threat actor identified as Warp Panda has been linked to recent compromises of VMware vCenter environments at U.S.-based organizations, <a rel="noreferrer noopener" href="https://www.cybersecuritydive.com/news/china-actor-us-entities-brickstorm-malware/807166/">according to a new report from CrowdStrike</a>. <a rel="noreferrer noopener" href="https://www.crowdstrike.com/en-us/blog/warp-panda-cloud-threats/">Original CrowdStrike article</a>. <a rel="noreferrer noopener" href="https://www.cisa.gov/news-events/analysis-reports/ar25-338a">CISA BRICKSTORM Backdoor breakdown</a>. <a rel="noreferrer noopener" href="https://www.cisa.gov/sites/default/files/2025-12/malware-analysis-report-brickstorm-backdoor.pdf">Analysis report</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 15 Dec 2025 14:44:05 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a20e26a3/6fc87046.mp3" length="53684706" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/igtpnUn9LZNutcvUKD-hWq9jftXIe3hoNeyWU1P7NKs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMDEz/YWUwNTdhODA2NWRh/MGI0M2I0ZDU0MmEz/YjExYi5wbmc.jpg"/>
      <itunes:duration>2228</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#275 - Defender Fridays: Polymorphic Panic - Debunking the AI Malware Myth with Randy Pargman from Proofpoint</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>275</itunes:episode>
      <podcast:episode>275</podcast:episode>
      <itunes:title>#275 - Defender Fridays: Polymorphic Panic - Debunking the AI Malware Myth with Randy Pargman from Proofpoint</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0eb7fea5-7f0d-4bd8-86b7-b4dad3faa81c</guid>
      <link>https://share.transistor.fm/s/ebf69a99</link>
      <description>
        <![CDATA[<p>Join us for this week's Defender Fridays as we explore the reality of AI-powered malware threats with Randy Pargman, Senior Director of Threat Detection at Proofpoint.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>In this episode, Randy challenges the hype around AI-powered polymorphic malware and examines how threat actors actually operate in practice. He discusses why defenders should focus on real-world threats rather than theoretical sophisticated attacks.</p><p>Key Topics:</p><ul><li>The gap between AI malware hype and practical reality</li><li>Why threat actors prefer simple, effective methods over sophisticated techniques</li><li>The prevalence of legitimate RMM tools in modern attacks</li><li>Building practical detection strategies for actual threats</li><li>Lessons from physical security that apply to cybersecurity defense</li></ul><p>Randy Pargman is Senior Director of Threat Detection at Proofpoint, where he leads detection engineering, sandbox development, and threat actor tracking initiatives. </p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us for this week's Defender Fridays as we explore the reality of AI-powered malware threats with Randy Pargman, Senior Director of Threat Detection at Proofpoint.</p><p>At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>In this episode, Randy challenges the hype around AI-powered polymorphic malware and examines how threat actors actually operate in practice. He discusses why defenders should focus on real-world threats rather than theoretical sophisticated attacks.</p><p>Key Topics:</p><ul><li>The gap between AI malware hype and practical reality</li><li>Why threat actors prefer simple, effective methods over sophisticated techniques</li><li>The prevalence of legitimate RMM tools in modern attacks</li><li>Building practical detection strategies for actual threats</li><li>Lessons from physical security that apply to cybersecurity defense</li></ul><p>Randy Pargman is Senior Director of Threat Detection at Proofpoint, where he leads detection engineering, sandbox development, and threat actor tracking initiatives. </p><p>Join us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you – our audience. Register here: <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">https://limacharlie.io/defender-fridays</a></p><p>Subscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!</p><p>This episode is brought to you by LimaCharlie, the world's first SecOps Cloud Platform (SCP). Build and customize your security stack like "lego blocks" with our flexible, API-first solution.</p><ul><li>Eliminate vendor sprawl and tool complexity</li><li>Deploy and scale effortlessly on native multi-tenant architecture</li><li>Reduce costs with intelligent data routing and free 1-year retention</li><li>Build custom solutions with 100+ security capabilities on-demand</li><li>Improve response times with automation and real-time capabilities</li></ul><p>Try the SecOps Cloud Platform free: <a rel="noreferrer noopener" href="https://limacharlie.io/">https://limacharlie.io</a></p><p>Host: Maxime Lamothe-Brassard - Founder at LimaCharlie</p>]]>
      </content:encoded>
      <pubDate>Fri, 12 Dec 2025 14:03:46 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ebf69a99/5ba2c5ae.mp3" length="46951079" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/A-aB6y7sHCp4eN6kAIjYEOiaUpdxMrkzEhDOgDSWOvg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMTM2/NzA2ZmI1MzY0ZGUx/ZjU2YjRhMGVkNDgw/NGQwMi5wbmc.jpg"/>
      <itunes:duration>1955</itunes:duration>
      <itunes:summary>Join us for this week's Defender Fridays as we explore the reality of AI-powered malware threats with Randy Pargman, Senior Director of Threat Detection at Proofpoint.</itunes:summary>
      <itunes:subtitle>Join us for this week's Defender Fridays as we explore the reality of AI-powered malware threats with Randy Pargman, Senior Director of Threat Detection at Proofpoint.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#274 - Why most SOCs are failing (and how to fix them) with Alec Fenton from Foresite Cybersecurity</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>274</itunes:episode>
      <podcast:episode>274</podcast:episode>
      <itunes:title>#274 - Why most SOCs are failing (and how to fix them) with Alec Fenton from Foresite Cybersecurity</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e2bfb4e5-7f4a-4156-a7d6-153db56109bb</guid>
      <link>https://share.transistor.fm/s/3dac9b6c</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Alec Fenton, VP of Security Operations at <a rel="noreferrer noopener" href="https://foresite.com/">Foresite Cybersecurity</a> about his journey from SOC analyst to security leader.</p><p>Alec Fenton is a seasoned Cyber Security professional with over 15 years of extensive experience across many IT domains. With a career spanning more than a decade, Alec has honed his expertise in addressing a broad spectrum of cybersecurity challenges, leveraging his analytical prowess and hands-on approach to leadership.</p><p>Throughout his career, Alec has navigated the intricate landscape of IT security, working across various sectors including managed service providers and private companies. His tenure as an analyst in the cybersecurity space has not only equipped him with a deep understanding of emerging threats and vulnerabilities but has also shaped his leadership philosophy of "lead from the front."</p><p>Alec's commitment to excellence and his unwavering dedication to staying ahead of the curve in the ever-evolving field of cybersecurity have earned him recognition as a trusted advisor and thought leader in the industry. When he's not immersed in the world of IT security, Alec enjoys spending time outdoors, and help coach his son's baseball/basketball teams.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Alec Fenton, VP of Security Operations at <a rel="noreferrer noopener" href="https://foresite.com/">Foresite Cybersecurity</a> about his journey from SOC analyst to security leader.</p><p>Alec Fenton is a seasoned Cyber Security professional with over 15 years of extensive experience across many IT domains. With a career spanning more than a decade, Alec has honed his expertise in addressing a broad spectrum of cybersecurity challenges, leveraging his analytical prowess and hands-on approach to leadership.</p><p>Throughout his career, Alec has navigated the intricate landscape of IT security, working across various sectors including managed service providers and private companies. His tenure as an analyst in the cybersecurity space has not only equipped him with a deep understanding of emerging threats and vulnerabilities but has also shaped his leadership philosophy of "lead from the front."</p><p>Alec's commitment to excellence and his unwavering dedication to staying ahead of the curve in the ever-evolving field of cybersecurity have earned him recognition as a trusted advisor and thought leader in the industry. When he's not immersed in the world of IT security, Alec enjoys spending time outdoors, and help coach his son's baseball/basketball teams.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 10 Dec 2025 13:00:33 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3dac9b6c/3a988110.mp3" length="59979560" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/R8H8K2FaYBmFznmmwYYc90-IXvzLhN9wAv0s7rgLSBo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82MWNk/N2IxYzc5ZDk4ZTI0/NDA4YjJmYzQ1MTNm/ZWY3Yi5wbmc.jpg"/>
      <itunes:duration>2493</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Alec Fenton, VP of Security Operations at Foresite Cybersecurity about his journey from SOC analyst to security leader.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Alec Fenton, VP of Security Operations at Foresite Cybersecurity about his journey from SOC analyst to security leader.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#273 - Intel Chat: Tomiris cyber-espionage group, OpenPLC ScadaBR flaw, NPM manipulating AI-driven scanners &amp; MuddyWater</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>273</itunes:episode>
      <podcast:episode>273</podcast:episode>
      <itunes:title>#273 - Intel Chat: Tomiris cyber-espionage group, OpenPLC ScadaBR flaw, NPM manipulating AI-driven scanners &amp; MuddyWater</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f2cf8ae0-f578-4679-b5a0-6db0381d38de</guid>
      <link>https://share.transistor.fm/s/dd437c43</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>For for more information about Cybersecurity Cares, visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p><ul><li>The Tomiris cyber-espionage group, which has been under Kaspersky's watch since 2021, has evolved its tactics in a new wave of attacks <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/tomiris-unleashes-havoc-new-tools-tactics">observed in early 2025</a>.  <a rel="noreferrer noopener" href="https://securelist.com/tomiris-new-tools/118143/">Article #2</a>.</li><li>CISA has recently added CVE-2021-26829 to its known exploited vulnerabilities, or KEV catalog, marking it as a confirmed threat based on <a rel="noreferrer noopener" href="https://www.securityweek.com/cisa-warns-of-scadabr-vulnerability-after-hacktivist-ics-attack/">real world exploitation</a>. </li><li>Researchers at KOI Security have identified a malicious NPM package, which not only performs typical credential stealing behavior, but also includes a new, subtle tactic attempting to manipulate AI-driven security scanners via <a rel="noreferrer noopener" href="https://thehackernews.com/2025/12/malicious-npm-package-uses-hidden.html">embedded prompt engineering</a>. <a rel="noreferrer noopener" href="https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners">Article #2</a>.</li><li>Iranian state sponsored threat group MuddyWater has launched a new wave of cyber espionage attacks targeting Israeli organizations across sectors including academia, civil infrastructure, <a rel="noreferrer noopener" href="https://thehackernews.com/2025/12/iran-linked-hackers-hits-israeli_2.html">engineering, technology and utilities</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>For for more information about Cybersecurity Cares, visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p><ul><li>The Tomiris cyber-espionage group, which has been under Kaspersky's watch since 2021, has evolved its tactics in a new wave of attacks <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/tomiris-unleashes-havoc-new-tools-tactics">observed in early 2025</a>.  <a rel="noreferrer noopener" href="https://securelist.com/tomiris-new-tools/118143/">Article #2</a>.</li><li>CISA has recently added CVE-2021-26829 to its known exploited vulnerabilities, or KEV catalog, marking it as a confirmed threat based on <a rel="noreferrer noopener" href="https://www.securityweek.com/cisa-warns-of-scadabr-vulnerability-after-hacktivist-ics-attack/">real world exploitation</a>. </li><li>Researchers at KOI Security have identified a malicious NPM package, which not only performs typical credential stealing behavior, but also includes a new, subtle tactic attempting to manipulate AI-driven security scanners via <a rel="noreferrer noopener" href="https://thehackernews.com/2025/12/malicious-npm-package-uses-hidden.html">embedded prompt engineering</a>. <a rel="noreferrer noopener" href="https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners">Article #2</a>.</li><li>Iranian state sponsored threat group MuddyWater has launched a new wave of cyber espionage attacks targeting Israeli organizations across sectors including academia, civil infrastructure, <a rel="noreferrer noopener" href="https://thehackernews.com/2025/12/iran-linked-hackers-hits-israeli_2.html">engineering, technology and utilities</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 09 Dec 2025 00:37:20 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/dd437c43/a3da311d.mp3" length="44588051" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/52ey1LF2zIG53_d1SVl9u-0Hzh6eVCPxgqjQAuQsxjU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wNGYz/OGY3YzRkMTNlYjIz/ZGZlMzRkYjE1ZTc5/ODI0OS5wbmc.jpg"/>
      <itunes:duration>1851</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#272 - Intel Chat: AI taking over low-skilled work, AI-orchestrated cyber espionage, JackFix &amp; weaponizing Blender files</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>272</itunes:episode>
      <podcast:episode>272</podcast:episode>
      <itunes:title>#272 - Intel Chat: AI taking over low-skilled work, AI-orchestrated cyber espionage, JackFix &amp; weaponizing Blender files</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4f30b781-5878-4124-a3a5-a660369467e1</guid>
      <link>https://share.transistor.fm/s/5009fffd</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>For for more information about Cyber Security Cares, visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p><ul><li>AI is now fulfilling a long-standing hope of security teams: it’s taking over repetitive, low-skill tasks like log reviews, <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-careers/with-ai-reshaping-entry-level-cyber-what-happens-to-the-security-talent-pipeline-">alert triage, and basic investigations</a>.</li><li>Anthropic has disclosed what it believes is the first documented case of a largely autonomous AI-orchestrated <a rel="noreferrer noopener" href="https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf">cyber espionage campaign</a>.</li><li>The new "JackFix" variant of the ClickFix attack is gaining traction, and unlike its predecessors, it combines both social engineering and technical evasion tactics to bypass<a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/jackfix-attack-clickfix-mitigations"> existing defenses more effectively</a>.</li><li>Researchers at Morphisec have uncovered a new six-month-long campaign weaponizing .blend files - native to Blender, the open-source 3D modeling software - to deliver a <a rel="noreferrer noopener" href="https://thehackernews.com/2025/11/hackers-hijack-blender-3d-assets-to.html">variant of the StealC information stealer</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>For for more information about Cyber Security Cares, visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p><ul><li>AI is now fulfilling a long-standing hope of security teams: it’s taking over repetitive, low-skill tasks like log reviews, <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-careers/with-ai-reshaping-entry-level-cyber-what-happens-to-the-security-talent-pipeline-">alert triage, and basic investigations</a>.</li><li>Anthropic has disclosed what it believes is the first documented case of a largely autonomous AI-orchestrated <a rel="noreferrer noopener" href="https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf">cyber espionage campaign</a>.</li><li>The new "JackFix" variant of the ClickFix attack is gaining traction, and unlike its predecessors, it combines both social engineering and technical evasion tactics to bypass<a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/jackfix-attack-clickfix-mitigations"> existing defenses more effectively</a>.</li><li>Researchers at Morphisec have uncovered a new six-month-long campaign weaponizing .blend files - native to Blender, the open-source 3D modeling software - to deliver a <a rel="noreferrer noopener" href="https://thehackernews.com/2025/11/hackers-hijack-blender-3d-assets-to.html">variant of the StealC information stealer</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 01 Dec 2025 15:55:59 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5009fffd/deb4280b.mp3" length="47661195" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/XVFg2zSrJ4Zl7cDAqX-GWrqTkg6wPQObywSAk8c1zp4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84ZTVl/ZTEwYmVjYzUxMmE5/NTM2ZDA0NWYxN2E0/ZGY1Zi5wbmc.jpg"/>
      <itunes:duration>1978</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#271 - AI hype &amp; the future of SecOps, what’s changed in 30 years? With Erik Bloch from Illumio</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>271</itunes:episode>
      <podcast:episode>271</podcast:episode>
      <itunes:title>#271 - AI hype &amp; the future of SecOps, what’s changed in 30 years? With Erik Bloch from Illumio</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8bc12a3d-b34d-4024-84ec-5578d186d874</guid>
      <link>https://share.transistor.fm/s/10b873e8</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Erik Bloch, VP of Security at <a rel="noreferrer noopener" href="https://www.illumio.com/">Illumio</a>, about better tools to combat burnout rate and discuss the reality of AI in security.</p><p>Erik Bloch has 30+ years of information and cyber security experience, both as an IC and as a leader of teams. “People first” has always been his approach. He has led entire security and IT functions at smaller companies, and been the CISOs leading big teams at larger orgs. </p><p>Erik also spent time on the product side, trying to make better tooling for people like him. With a mix of security, IT and product under his belt, Erik is at a place where connections, making meaningful change and driving impact in peoples lives, mean a lot to him. The smartest person he knows once said "Problems are really opportunities in disguise"​, and that's something Erik always tries to see.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Erik Bloch, VP of Security at <a rel="noreferrer noopener" href="https://www.illumio.com/">Illumio</a>, about better tools to combat burnout rate and discuss the reality of AI in security.</p><p>Erik Bloch has 30+ years of information and cyber security experience, both as an IC and as a leader of teams. “People first” has always been his approach. He has led entire security and IT functions at smaller companies, and been the CISOs leading big teams at larger orgs. </p><p>Erik also spent time on the product side, trying to make better tooling for people like him. With a mix of security, IT and product under his belt, Erik is at a place where connections, making meaningful change and driving impact in peoples lives, mean a lot to him. The smartest person he knows once said "Problems are really opportunities in disguise"​, and that's something Erik always tries to see.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 26 Nov 2025 16:09:04 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/10b873e8/d868f40a.mp3" length="75045913" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>3120</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Erik Bloch, VP of Security at Illumio, about better tools to combat burnout rate and discuss the reality of AI in security.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Erik Bloch, VP of Security at Illumio, about better tools to combat burnout rate and discuss the reality of AI in security.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#270 - Defender Fridays: Zero Trust with Dr. Chase Cunningham from Demo-Force</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>270</itunes:episode>
      <podcast:episode>270</podcast:episode>
      <itunes:title>#270 - Defender Fridays: Zero Trust with Dr. Chase Cunningham from Demo-Force</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fc55cc29-06be-4266-b350-5eb1f63c5022</guid>
      <link>https://share.transistor.fm/s/a950ccd4</link>
      <description>
        <![CDATA[<p>Dr. Cunningham created the influential Zero Trust Extended (ZTX) Framework at Forrester Research, playing a key role in accelerating global adoption of Zero Trust principles across industries and governments worldwide.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dr. Cunningham created the influential Zero Trust Extended (ZTX) Framework at Forrester Research, playing a key role in accelerating global adoption of Zero Trust principles across industries and governments worldwide.</p>]]>
      </content:encoded>
      <pubDate>Fri, 21 Nov 2025 15:58:36 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a950ccd4/7f712893.mp3" length="41799321" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/NaeGBfiSxoIwSt4JVkHcT9wGtdrad7ln_kXjUEQaFSE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xM2Q2/MWVlOTdmZDRhODA1/ODEwNTg5MjZlY2Zl/ODljOS5wbmc.jpg"/>
      <itunes:duration>1740</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Dr. Cunningham created the influential Zero Trust Extended (ZTX) Framework at Forrester Research, playing a key role in accelerating global adoption of Zero Trust principles across industries and governments worldwide.</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#269 - How AI offers defenders even more growth opportunities with Michael Baker from DXC Technology</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>269</itunes:episode>
      <podcast:episode>269</podcast:episode>
      <itunes:title>#269 - How AI offers defenders even more growth opportunities with Michael Baker from DXC Technology</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">15b045f9-8644-40b8-a46c-d32009ccb43d</guid>
      <link>https://share.transistor.fm/s/e781b680</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Michael Baker, VP, Global Chief Information Security Officer at DXC Technology, about his optimistic outlook on the impact of AI in cybersecurity.</p><p>Michael Baker is an accomplished cyber security executive with more than 24 years of experience in the field. He is passionate about building high-performing teams and transforming the way cyber risk is managed within businesses. Currently, Michael serves as the Global Chief Information Security Officer (CISO) for <a rel="noreferrer noopener" href="https://dxc.com/us/en">DXC Technology</a>. In this capacity, he is responsible for protecting the brand and reputation of DXC Technology, a $14 billion global technology enterprise with 130,000 employees located across 80+ territories.</p><p>Before joining DXC Technology, he held various leadership positions, including CISO, within the US government contracting and aerospace and defense industry, along with a long career serving clients as a cyber security and risk management consultant. Michael is known for his strategic vision, global program management, and ability to drive operational excellence across end-to end cyber services that provide measurable business value. Visit <a rel="noreferrer noopener" href="https://dxc.com/us/en">dxc.com</a> for more info.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Michael Baker, VP, Global Chief Information Security Officer at DXC Technology, about his optimistic outlook on the impact of AI in cybersecurity.</p><p>Michael Baker is an accomplished cyber security executive with more than 24 years of experience in the field. He is passionate about building high-performing teams and transforming the way cyber risk is managed within businesses. Currently, Michael serves as the Global Chief Information Security Officer (CISO) for <a rel="noreferrer noopener" href="https://dxc.com/us/en">DXC Technology</a>. In this capacity, he is responsible for protecting the brand and reputation of DXC Technology, a $14 billion global technology enterprise with 130,000 employees located across 80+ territories.</p><p>Before joining DXC Technology, he held various leadership positions, including CISO, within the US government contracting and aerospace and defense industry, along with a long career serving clients as a cyber security and risk management consultant. Michael is known for his strategic vision, global program management, and ability to drive operational excellence across end-to end cyber services that provide measurable business value. Visit <a rel="noreferrer noopener" href="https://dxc.com/us/en">dxc.com</a> for more info.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 19 Nov 2025 15:22:35 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e781b680/258cd755.mp3" length="54949134" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2285</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Michael Baker, VP, Global Chief Information Security Officer at DXC Technology, about his optimistic outlook on the impact of AI in cybersecurity.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Michael Baker, VP, Global Chief Information Security Officer at DXC Technology, about his optimistic outlook on the impact of AI in cybersecurity.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#268 - Intel Chat: LLM integration in malware, Android spyware family LandFall, Windows kernel zero-day flaw &amp; Ex-L3Harris executive sells trade secrets</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>268</itunes:episode>
      <podcast:episode>268</podcast:episode>
      <itunes:title>#268 - Intel Chat: LLM integration in malware, Android spyware family LandFall, Windows kernel zero-day flaw &amp; Ex-L3Harris executive sells trade secrets</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">337a25ab-01de-49df-a061-38eb8634e5fc</guid>
      <link>https://share.transistor.fm/s/54265dce</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Google’s Threat Intelligence Group has observed a significant shift in 2025, threat actors are no longer using AI to just speed up operations, they are now integrating <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools">LLMs directly into the malware</a>.</li><li>Unit 42 has identified a previously undocumented Android spyware family, named LandFall, discovered during an investigation into iOS exploit chains involving <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/">malicious DNG images</a>.</li><li>Microsoft’s November Patch Tuesday rollout includes fixes for over 60 vulnerabilities, one of which is a zero-day privilege escalation flaw in the Windows kernel that has <a rel="noreferrer noopener" href="https://www.securityweek.com/microsoft-patches-actively-exploited-windows-kernel-zero-day/">already been exploited in the wild</a>.</li><li>Former executive at L3Harris Trenchant, Peter Williams, has pleaded guilty in U.S. federal court to selling 8 trade secrets valued at over 1.3 million to a Russian-based software broker <a rel="noreferrer noopener" href="https://www.wired.com/story/peter-williams-trenchant-trade-secrets-theft-russian-firm/">involved in the zero-day exploit market</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Google’s Threat Intelligence Group has observed a significant shift in 2025, threat actors are no longer using AI to just speed up operations, they are now integrating <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools">LLMs directly into the malware</a>.</li><li>Unit 42 has identified a previously undocumented Android spyware family, named LandFall, discovered during an investigation into iOS exploit chains involving <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/">malicious DNG images</a>.</li><li>Microsoft’s November Patch Tuesday rollout includes fixes for over 60 vulnerabilities, one of which is a zero-day privilege escalation flaw in the Windows kernel that has <a rel="noreferrer noopener" href="https://www.securityweek.com/microsoft-patches-actively-exploited-windows-kernel-zero-day/">already been exploited in the wild</a>.</li><li>Former executive at L3Harris Trenchant, Peter Williams, has pleaded guilty in U.S. federal court to selling 8 trade secrets valued at over 1.3 million to a Russian-based software broker <a rel="noreferrer noopener" href="https://www.wired.com/story/peter-williams-trenchant-trade-secrets-theft-russian-firm/">involved in the zero-day exploit market</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 17 Nov 2025 13:13:03 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/54265dce/99bdee8d.mp3" length="60841490" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/I_UI0g1EWr1PP0XGwCHHwEUwns23BCrDnbsNe5aXBK8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yYzA1/NmY5M2ZlMmY3NmQx/OTQ2ZWQ1MTJkZTk1/YWVmZi5wbmc.jpg"/>
      <itunes:duration>2527</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#267 - Defender Fridays: AI in SecOps - what's real vs. what's hype? With Alec Fenton from Foresite Cybersecurity</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>267</itunes:episode>
      <podcast:episode>267</podcast:episode>
      <itunes:title>#267 - Defender Fridays: AI in SecOps - what's real vs. what's hype? With Alec Fenton from Foresite Cybersecurity</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">48fa33ae-c47d-43d9-a18e-7b5539c74a99</guid>
      <link>https://share.transistor.fm/s/d739438e</link>
      <description>
        <![CDATA[<p>In this episode of Defender Fridays, we talk to Alec Fenton, VP Security Operations at Foresite Cybersecurity, practical career advice for defenders, SOC metrics that actually matter and AI in security operations.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Alec is a seasoned Cyber Security professional with over 15 years of extensive experience across many IT domains. With a career spanning more than a decade, Alec has honed his expertise in addressing a broad spectrum of cybersecurity challenges, leveraging his analytical prowess and hands-on approach to leadership.</p><p>Throughout his career, Alec has navigated the intricate landscape of IT security, working across various sectors including managed service providers and private companies. His tenure as an analyst in the cybersecurity space has not only equipped him with a deep understanding of emerging threats and vulnerabilities but has also shaped his leadership philosophy of "lead from the front."</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of Defender Fridays, we talk to Alec Fenton, VP Security Operations at Foresite Cybersecurity, practical career advice for defenders, SOC metrics that actually matter and AI in security operations.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Alec is a seasoned Cyber Security professional with over 15 years of extensive experience across many IT domains. With a career spanning more than a decade, Alec has honed his expertise in addressing a broad spectrum of cybersecurity challenges, leveraging his analytical prowess and hands-on approach to leadership.</p><p>Throughout his career, Alec has navigated the intricate landscape of IT security, working across various sectors including managed service providers and private companies. His tenure as an analyst in the cybersecurity space has not only equipped him with a deep understanding of emerging threats and vulnerabilities but has also shaped his leadership philosophy of "lead from the front."</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 14 Nov 2025 14:11:40 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d739438e/f8bfc718.mp3" length="46535660" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/axEvGI9E7wA_c29ggaLCKaVEfEzdc45C6CkJ6l-Fddo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jNmIw/ZGQ0ZWFhMDdmZDE1/NzdkNTMyZjdjZDQ4/NzZmYS5wbmc.jpg"/>
      <itunes:duration>1938</itunes:duration>
      <itunes:summary>In this episode of Defender Fridays, we talk to Alec Fenton, VP Security Operations at Foresite Cybersecurity, practical career advice for defenders, SOC metrics that actually matter and AI in security operations.</itunes:summary>
      <itunes:subtitle>In this episode of Defender Fridays, we talk to Alec Fenton, VP Security Operations at Foresite Cybersecurity, practical career advice for defenders, SOC metrics that actually matter and AI in security operations.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#266 - Preparing for Out-of-Band Communication in Incident Response with Navroop Mitter from ArmorText</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>266</itunes:episode>
      <podcast:episode>266</podcast:episode>
      <itunes:title>#266 - Preparing for Out-of-Band Communication in Incident Response with Navroop Mitter from ArmorText</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">11332374-cae5-4047-a52d-cf694712e008</guid>
      <link>https://share.transistor.fm/s/21d78f91</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Navroop Mitter, CEO of ArmorText, about the role of Out-of-Band (OOB) communication in cyber incident response.</p><p><a rel="noreferrer noopener" href="https://armortext.com/forrester-2024/">ArmorText Named a Leader in The Forrester Wave</a>™: Secure Communications Solutions, Q3 2024</p><p>Cyber Resilience: <a rel="noreferrer noopener" href="https://armortext.com/cybertabletop/">Incident Response Tabletop Exercises</a></p><p>Navroop Mitter is the CEO of ArmorText, a mobile security and privacy company based in the Washington, D.C. area.</p><p>Before founding ArmorText, Navroop was a Senior Manager in Accenture’s North American Security Practice, where he built and led information security programs across multiple regions. He helped double Accenture’s Scandinavian security practice within a year and established the firm’s first near-shore security delivery center in Argentina, hiring and training over 30 practitioners in under 30 days.</p><p>Navroop has led large-scale international security engagements, working across cultures and time zones to strengthen teams in the U.S., India, and abroad. Recognized for his entrepreneurial mindset and expertise in identity and access management, he became one of Accenture’s most sought-after leaders for complex, multi-country security initiatives.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Navroop Mitter, CEO of ArmorText, about the role of Out-of-Band (OOB) communication in cyber incident response.</p><p><a rel="noreferrer noopener" href="https://armortext.com/forrester-2024/">ArmorText Named a Leader in The Forrester Wave</a>™: Secure Communications Solutions, Q3 2024</p><p>Cyber Resilience: <a rel="noreferrer noopener" href="https://armortext.com/cybertabletop/">Incident Response Tabletop Exercises</a></p><p>Navroop Mitter is the CEO of ArmorText, a mobile security and privacy company based in the Washington, D.C. area.</p><p>Before founding ArmorText, Navroop was a Senior Manager in Accenture’s North American Security Practice, where he built and led information security programs across multiple regions. He helped double Accenture’s Scandinavian security practice within a year and established the firm’s first near-shore security delivery center in Argentina, hiring and training over 30 practitioners in under 30 days.</p><p>Navroop has led large-scale international security engagements, working across cultures and time zones to strengthen teams in the U.S., India, and abroad. Recognized for his entrepreneurial mindset and expertise in identity and access management, he became one of Accenture’s most sought-after leaders for complex, multi-country security initiatives.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 12 Nov 2025 13:00:26 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/21d78f91/0f076ba5.mp3" length="44585058" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1851</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Navroop Mitter, CEO of ArmorText, about the role of Out-of-Band (OOB) communication in cyber incident response.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Navroop Mitter, CEO of ArmorText, about the role of Out-of-Band (OOB) communication in cyber incident response.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#265 - Intel Chat: AWS TruffleNet exploit, React Native vulnerability, SesameOp OpenAI Assistants API C2 channel &amp; Operation SkyCloak</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>265</itunes:episode>
      <podcast:episode>265</podcast:episode>
      <itunes:title>#265 - Intel Chat: AWS TruffleNet exploit, React Native vulnerability, SesameOp OpenAI Assistants API C2 channel &amp; Operation SkyCloak</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ca4c4976-c958-4454-a985-e6021d936109</guid>
      <link>https://share.transistor.fm/s/f159d25d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A newly observed threat campaign is exploiting Amazon Web Services' Simple Email Service using stolen credentials and open source tools to perform cloud reconnaissance and eventually launch <a rel="noreferrer noopener" href="https://www.darkreading.com/vulnerabilities-threats/trufflenet-attack-stolen-credentials-aws">Business Email Compromise scams</a>. </li><li>A critical vulnerability has been disclosed in the React Native Community CLI NPM package, a toolset widely used for building <a rel="noreferrer noopener" href="https://www.securityweek.com/critical-flaw-in-popular-react-native-npm-package-exposes-developers-to-attacks/">React Native applications</a>.</li><li>Microsoft's Detection and Response Team (DART) has discovered a novel backdoor, SesameOp, that uses the OpenAI Assistants API as a command-and-control (C2) channel, highlighting a new way <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/sesameop-backdoor-openai-api-covert-c2">attackers are misusing generative AI platforms</a>.</li><li>Researchers from Cyble and Seqrite Labs have disclosed a sophisticated malware campaign, dubbed Operation SkyCloak, targeting defense-related organizations in Russia and Belarus through weaponized <a rel="noreferrer noopener" href="https://thehackernews.com/2025/11/operation-skycloak-deploys-tor-enabled.html">attachments delivered via phishing emails</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A newly observed threat campaign is exploiting Amazon Web Services' Simple Email Service using stolen credentials and open source tools to perform cloud reconnaissance and eventually launch <a rel="noreferrer noopener" href="https://www.darkreading.com/vulnerabilities-threats/trufflenet-attack-stolen-credentials-aws">Business Email Compromise scams</a>. </li><li>A critical vulnerability has been disclosed in the React Native Community CLI NPM package, a toolset widely used for building <a rel="noreferrer noopener" href="https://www.securityweek.com/critical-flaw-in-popular-react-native-npm-package-exposes-developers-to-attacks/">React Native applications</a>.</li><li>Microsoft's Detection and Response Team (DART) has discovered a novel backdoor, SesameOp, that uses the OpenAI Assistants API as a command-and-control (C2) channel, highlighting a new way <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/sesameop-backdoor-openai-api-covert-c2">attackers are misusing generative AI platforms</a>.</li><li>Researchers from Cyble and Seqrite Labs have disclosed a sophisticated malware campaign, dubbed Operation SkyCloak, targeting defense-related organizations in Russia and Belarus through weaponized <a rel="noreferrer noopener" href="https://thehackernews.com/2025/11/operation-skycloak-deploys-tor-enabled.html">attachments delivered via phishing emails</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 10 Nov 2025 15:59:47 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f159d25d/5624d550.mp3" length="45362970" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/noN9BziDo1VYTahNzhzslVAnYNblp6lmDyLiiiKO3Xo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wM2U5/ZWZkNjk2MTY4ZjAw/M2IxYzBkZjM4OTMw/YzAzOC5wbmc.jpg"/>
      <itunes:duration>1884</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#264 - Defender Fridays: Dive into SaaS Intrusion Trends with Julie Agnes Sparks from Datadog</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>264</itunes:episode>
      <podcast:episode>264</podcast:episode>
      <itunes:title>#264 - Defender Fridays: Dive into SaaS Intrusion Trends with Julie Agnes Sparks from Datadog</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">db983f29-5ac5-4f31-983d-2de029b51f4e</guid>
      <link>https://share.transistor.fm/s/9962565e</link>
      <description>
        <![CDATA[<p>In this episode of Defender Fridays, LimaCharlie Founder Maxime Lamothe-Brassard talks to Julie Agnes Sparks, Security Engineer at Datadog, about how to maximize logging visibility for effective detection engineering.</p><p>Julie has a passion for continuous learning, proactively detecting significant security events, and responding effectively. Interests include: diversity &amp; inclusion, privacy, and making technology more accessible.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of Defender Fridays, LimaCharlie Founder Maxime Lamothe-Brassard talks to Julie Agnes Sparks, Security Engineer at Datadog, about how to maximize logging visibility for effective detection engineering.</p><p>Julie has a passion for continuous learning, proactively detecting significant security events, and responding effectively. Interests include: diversity &amp; inclusion, privacy, and making technology more accessible.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 07 Nov 2025 16:13:45 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9962565e/5a50a00e.mp3" length="47193231" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/mVLsyEjPaJCHMzXDmONJV84oOWvG0Xn1-gl658YAZKY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80NTE3/NjU2NzhhMzcwOTY3/YjhhZjQ0N2Y3MjY0/YWY0Mi5wbmc.jpg"/>
      <itunes:duration>1965</itunes:duration>
      <itunes:summary>Join us as Julie Agnes Sparks, Security Engineer at Datadog, talks about how to maximize logging visibility for effective detection engineering.</itunes:summary>
      <itunes:subtitle>Join us as Julie Agnes Sparks, Security Engineer at Datadog, talks about how to maximize logging visibility for effective detection engineering.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#263 - Intel Chat: BlackBasta, BlueNoroff, Operation ForumTroll &amp; Aisuru</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>263</itunes:episode>
      <podcast:episode>263</podcast:episode>
      <itunes:title>#263 - Intel Chat: BlackBasta, BlueNoroff, Operation ForumTroll &amp; Aisuru</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2ebf6e85-ec53-46cd-a763-6f138e4c6075</guid>
      <link>https://share.transistor.fm/s/14b10ab1</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The UK Information Commissioner's Office (ICO) recently released a comprehensive 136-page report detailing the BlackBasta ransomware attack on <a rel="noreferrer noopener" href="https://blog.bushidotoken.net/2025/10/lessons-from-blackbasta-ransomware.html">Capita in March 2023</a>.</li><li>Kaspersky researchers have detailed two active campaigns from North Korean APT group BlueNoroff, which continue the group’s long-running SnatchCrypto operation targeting individuals in <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/north-korea-bluenoroff-expands-crypto-heists">financial and tech sectors</a>.</li><li>The exploitation of the first Chrome zero-day of 2025 has been attributed to a state-sponsored threat actor involved in Operation ForumTroll, a cyber-espionage campaign targeting Russian entities across sectors like <a rel="noreferrer noopener" href="https://www.securityweek.com/chrome-zero-day-exploitation-linked-to-hacking-team-spyware/">education, finance, media, and government</a>.</li><li>Netscout has identified a newly emerging Internet of Things (IoT) botnet, Aisuru, which has already launched distributed denial-of-service (DDoS) attacks exceeding 20 Tbps, placing it among the most <a rel="noreferrer noopener" href="https://www.securityweek.com/turbomirai-class-aisuru-botnet-blamed-for-20-tbps-ddos-attacks/">powerful botnets observed to date</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The UK Information Commissioner's Office (ICO) recently released a comprehensive 136-page report detailing the BlackBasta ransomware attack on <a rel="noreferrer noopener" href="https://blog.bushidotoken.net/2025/10/lessons-from-blackbasta-ransomware.html">Capita in March 2023</a>.</li><li>Kaspersky researchers have detailed two active campaigns from North Korean APT group BlueNoroff, which continue the group’s long-running SnatchCrypto operation targeting individuals in <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/north-korea-bluenoroff-expands-crypto-heists">financial and tech sectors</a>.</li><li>The exploitation of the first Chrome zero-day of 2025 has been attributed to a state-sponsored threat actor involved in Operation ForumTroll, a cyber-espionage campaign targeting Russian entities across sectors like <a rel="noreferrer noopener" href="https://www.securityweek.com/chrome-zero-day-exploitation-linked-to-hacking-team-spyware/">education, finance, media, and government</a>.</li><li>Netscout has identified a newly emerging Internet of Things (IoT) botnet, Aisuru, which has already launched distributed denial-of-service (DDoS) attacks exceeding 20 Tbps, placing it among the most <a rel="noreferrer noopener" href="https://www.securityweek.com/turbomirai-class-aisuru-botnet-blamed-for-20-tbps-ddos-attacks/">powerful botnets observed to date</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 03 Nov 2025 16:30:23 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/14b10ab1/1c9ca314.mp3" length="59734003" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/m33sidEH8QBUqd85QVoeSbQrjf0XuVZb9asYsv6qLQI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85M2Qw/MDdkNGQzYmUwNWVi/Mjk1YWQxMWU0MzA1/MDYzZC5wbmc.jpg"/>
      <itunes:duration>2483</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#262 - Defender Fridays: What does "AI-ready SOC" actually mean? With Dr. Anton Chuvakin from CISO, Google Cloud</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>262</itunes:episode>
      <podcast:episode>262</podcast:episode>
      <itunes:title>#262 - Defender Fridays: What does "AI-ready SOC" actually mean? With Dr. Anton Chuvakin from CISO, Google Cloud</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8bca47d4-5983-4a40-a766-3bd38710f5c5</guid>
      <link>https://share.transistor.fm/s/81c6eb5d</link>
      <description>
        <![CDATA[<p>Dr. Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud and a recognized expert in SIEM, log management, and PCI DSS compliance, will help us cut through the buzzwords and discuss modern security operations.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Dr. Chuvakin is now involved with security solution strategy at Google Cloud, where he arrived via Chronicle Security (an Alphabet company) acquisition in July 2019. He is also a co-host of <a rel="noreferrer noopener" href="http://www.twitter.com/CloudSecPodcast">Cloud Security Podcast</a>.</p><p>Until June 2019, Dr. Anton Chuvakin was a Research VP and Distinguished Analyst at Gartner for Technical Professionals (GTP) Security and Risk Management Strategies (SRMS) team. At Gartner he covered a broad range of security operations and detection and response topics, and is credited with inventing the term "EDR." </p><p>He is a recognized security expert in the field of SIEM, log management and PCI DSS compliance. He is an author of books "Security Warrior", "PCI Compliance", "Logging and Log Management" and a contributor to "Know Your Enemy II", "Information Security Management Handbook" and others. Anton has published dozens of papers on log management, SIEM, correlation, security data analysis, PCI DSS, honeypots, etc. His blog securitywarrior.org was one of the most popular in the industry.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Dr. Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud and a recognized expert in SIEM, log management, and PCI DSS compliance, will help us cut through the buzzwords and discuss modern security operations.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Dr. Chuvakin is now involved with security solution strategy at Google Cloud, where he arrived via Chronicle Security (an Alphabet company) acquisition in July 2019. He is also a co-host of <a rel="noreferrer noopener" href="http://www.twitter.com/CloudSecPodcast">Cloud Security Podcast</a>.</p><p>Until June 2019, Dr. Anton Chuvakin was a Research VP and Distinguished Analyst at Gartner for Technical Professionals (GTP) Security and Risk Management Strategies (SRMS) team. At Gartner he covered a broad range of security operations and detection and response topics, and is credited with inventing the term "EDR." </p><p>He is a recognized security expert in the field of SIEM, log management and PCI DSS compliance. He is an author of books "Security Warrior", "PCI Compliance", "Logging and Log Management" and a contributor to "Know Your Enemy II", "Information Security Management Handbook" and others. Anton has published dozens of papers on log management, SIEM, correlation, security data analysis, PCI DSS, honeypots, etc. His blog securitywarrior.org was one of the most popular in the industry.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 31 Oct 2025 14:08:27 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/81c6eb5d/613fcaca.mp3" length="50755285" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/IekCkE_H08HPF9g-3J0N4EGh92grp7Pq0TAvtP4pJRs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xYTc1/NjYzNWE5MzM0MDli/NTVmZmZkZjAyZDZl/ZTBiMy5wbmc.jpg"/>
      <itunes:duration>2114</itunes:duration>
      <itunes:summary>Anton, Security Advisor at Office of the CISO, Google Cloud and a recognized expert in SIEM, log management, and PCI DSS compliance, will help us cut through the buzzwords and discuss modern security operations.</itunes:summary>
      <itunes:subtitle>Anton, Security Advisor at Office of the CISO, Google Cloud and a recognized expert in SIEM, log management, and PCI DSS compliance, will help us cut through the buzzwords and discuss modern security operations.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#261 - Scaling MSP &amp; MSSP Services with Hannah Lloyd, Co-Founder / CRO of enhanced.io</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>261</itunes:episode>
      <podcast:episode>261</podcast:episode>
      <itunes:title>#261 - Scaling MSP &amp; MSSP Services with Hannah Lloyd, Co-Founder / CRO of enhanced.io</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c40bf2ea-71f7-4826-8af4-095b12d24a8a</guid>
      <link>https://share.transistor.fm/s/5974ef17</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Hannah Lloyd, Co-Founder and CRO of enhanced.io, about how MSPs can launch, sell and scale security offerings.</p><p>With 10+ years of channel sales experience, Hannah leads global new business generation and account management to deliver innovative cybersecurity solutions to <a rel="noreferrer noopener" href="https://enhanced.io/">enhanced.io</a>’s MSP partners. As a GTIA EC member (2018) and Chair (2021), Hannah is actively involved in the MSP channel community. </p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Hannah Lloyd, Co-Founder and CRO of enhanced.io, about how MSPs can launch, sell and scale security offerings.</p><p>With 10+ years of channel sales experience, Hannah leads global new business generation and account management to deliver innovative cybersecurity solutions to <a rel="noreferrer noopener" href="https://enhanced.io/">enhanced.io</a>’s MSP partners. As a GTIA EC member (2018) and Chair (2021), Hannah is actively involved in the MSP channel community. </p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Oct 2025 09:00:28 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5974ef17/25b89144.mp3" length="86076218" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>3582</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Hannah Lloyd, Co-Founder and CRO of enhanced.io.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Hannah Lloyd, Co-Founder and CRO of enhanced.io.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#260 - Intel Chat: Kansas City National Security Campus breach, COLDRIVER, new KEV catalog additions &amp; AWS outage</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>260</itunes:episode>
      <podcast:episode>260</podcast:episode>
      <itunes:title>#260 - Intel Chat: Kansas City National Security Campus breach, COLDRIVER, new KEV catalog additions &amp; AWS outage</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">384d786e-b76d-465b-9ba0-c2aca67f7526</guid>
      <link>https://share.transistor.fm/s/a0db1d1b</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A breach at the Kansas City National Security Campus (KCNSC), a facility responsible for manufacturing roughly 80% of the non-nuclear components for U.S. nuclear weapons, was enabled by two critical <a rel="noreferrer noopener" href="https://www.csoonline.com/article/4074962/foreign-hackers-breached-a-us-nuclear-weapons-plant-via-sharepoint-flaws.html">Microsoft SharePoint vulnerabilities</a>.</li><li>COLDRIVER, a Russian state-sponsored group also tracked as UNC4057, Callisto, or Star Blizzard, has shifted rapidly toward new malware development following the public exposure of its <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/new-malware-russia-coldriver">previous malware, LOSTKEYS, in May 2025</a>.</li><li>CISA has officially added three newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging swift remediation efforts <a rel="noreferrer noopener" href="https://www.cisa.gov/news-events/alerts/2025/10/20/cisa-adds-five-known-exploited-vulnerabilities-catalog">across federal environments</a>. <a rel="noreferrer noopener" href="https://www.securityweek.com/cisa-confirms-exploitation-of-latest-oracle-ebs-vulnerability/">Newer article link</a>.</li><li>Amazon Web Services (AWS) experienced a major outage on October 20th that impacted thousands of applications globally, disrupting <a rel="noreferrer noopener" href="https://www.reuters.com/business/retail-consumer/amazons-cloud-unit-reports-outage-several-websites-down-2025-10-20/">operations for companies and end-users alike</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A breach at the Kansas City National Security Campus (KCNSC), a facility responsible for manufacturing roughly 80% of the non-nuclear components for U.S. nuclear weapons, was enabled by two critical <a rel="noreferrer noopener" href="https://www.csoonline.com/article/4074962/foreign-hackers-breached-a-us-nuclear-weapons-plant-via-sharepoint-flaws.html">Microsoft SharePoint vulnerabilities</a>.</li><li>COLDRIVER, a Russian state-sponsored group also tracked as UNC4057, Callisto, or Star Blizzard, has shifted rapidly toward new malware development following the public exposure of its <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/new-malware-russia-coldriver">previous malware, LOSTKEYS, in May 2025</a>.</li><li>CISA has officially added three newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging swift remediation efforts <a rel="noreferrer noopener" href="https://www.cisa.gov/news-events/alerts/2025/10/20/cisa-adds-five-known-exploited-vulnerabilities-catalog">across federal environments</a>. <a rel="noreferrer noopener" href="https://www.securityweek.com/cisa-confirms-exploitation-of-latest-oracle-ebs-vulnerability/">Newer article link</a>.</li><li>Amazon Web Services (AWS) experienced a major outage on October 20th that impacted thousands of applications globally, disrupting <a rel="noreferrer noopener" href="https://www.reuters.com/business/retail-consumer/amazons-cloud-unit-reports-outage-several-websites-down-2025-10-20/">operations for companies and end-users alike</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 27 Oct 2025 13:06:19 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a0db1d1b/925367f0.mp3" length="58440266" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Uuz3Jy7wCaGSTsoCvAoL1U2QMNdscxc2YOxN7IANG0w/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jOTJj/ZGE5OTA3ZGJmNWQ2/ODY4OTNjNDEyMGY1/NWU5YS5wbmc.jpg"/>
      <itunes:duration>2429</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#259 - Defender Fridays: Breaking Down Microsoft Defender for Endpoint with Ken Westin from LimaCharlie</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>259</itunes:episode>
      <podcast:episode>259</podcast:episode>
      <itunes:title>#259 - Defender Fridays: Breaking Down Microsoft Defender for Endpoint with Ken Westin from LimaCharlie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">870c3ba3-ce1f-457b-9e76-abbe9c9a475c</guid>
      <link>https://share.transistor.fm/s/be94e4e4</link>
      <description>
        <![CDATA[<p>Ken, Senior Solutions Engineer at LimaCharlie, dives into the incredibly confusing licensing tiers, pricing models and feature sets for Microsoft Defender for Endpoint. Today we discuss: </p><ul><li>The difference between tiers</li><li>Ways to solve Defender visibility issues and increase operational transparency</li><li>How its capabilities can be customized and expanded for better flexibility and scalability for service providers</li></ul><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>A big picture thinker, Ken ferrets out trends, seeking to understand what happens when businesses are breached and the methods behind the attacks. Then he figures out how to protect customers before they’re hit.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastruture for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Ken, Senior Solutions Engineer at LimaCharlie, dives into the incredibly confusing licensing tiers, pricing models and feature sets for Microsoft Defender for Endpoint. Today we discuss: </p><ul><li>The difference between tiers</li><li>Ways to solve Defender visibility issues and increase operational transparency</li><li>How its capabilities can be customized and expanded for better flexibility and scalability for service providers</li></ul><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>A big picture thinker, Ken ferrets out trends, seeking to understand what happens when businesses are breached and the methods behind the attacks. Then he figures out how to protect customers before they’re hit.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastruture for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 24 Oct 2025 16:33:59 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/be94e4e4/7bdd5a55.mp3" length="48720556" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Gvr_GnrNU8pm462RwCtX3ofzuCDiUhiEZHS8I1B5tic/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kOGI2/NjRhZTNjNzExMTJk/NDNhYmFhNGMwZjM4/MWZiZS5wbmc.jpg"/>
      <itunes:duration>2027</itunes:duration>
      <itunes:summary>Ken Westin, Senior Solutions Engineer at LimaCharlie, dives into the incredibly confusing licensing tiers, pricing models and feature sets for Microsoft Defender for Endpoint.</itunes:summary>
      <itunes:subtitle>Ken Westin, Senior Solutions Engineer at LimaCharlie, dives into the incredibly confusing licensing tiers, pricing models and feature sets for Microsoft Defender for Endpoint.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#258 - Intel Chat: Oracle EBS, Storm-2603, North Korean IT infiltration &amp; LLM poisoning study</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>258</itunes:episode>
      <podcast:episode>258</podcast:episode>
      <itunes:title>#258 - Intel Chat: Oracle EBS, Storm-2603, North Korean IT infiltration &amp; LLM poisoning study</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b9957af3-d58a-4e89-ba46-c7fec0e7483d</guid>
      <link>https://share.transistor.fm/s/3ebf128c</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>CrowdStrike is tracking a mass exploitation campaign leveraging a previously unknown vulnerability in <a rel="noreferrer noopener" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-identifies-campaign-targeting-oracle-e-business-suite-zero-day-CVE-2025-61882/">Oracle E-business suite or EBS</a>. </li><li>A threat group, tracked as Storm-2603, has been observed using the open source Velociraptor DFIR tool as part of it’s post-exploitation <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/chinese-hackers-velociraptor-ir-tool-ransomware-attacks">toolkit in recent ransomware attacks</a>.</li><li>North Korean IT workers, operating under state direction, continue to infiltrate international tech companies using false identities and anonymizing infrastructure to secure jobs and <a rel="noreferrer noopener" href="https://www.chainalysis.com/blog/dprk-it-workers-north-korea-crypto-laundering-networks/">route payments in cryptocurrency</a>. </li><li>Researchers from Anthropic, the UK AI Security Institute, and Alan Turing Institute have released the largest study to date on poisoning attacks during pre-training on large <a rel="noreferrer noopener" href="https://www.anthropic.com/research/small-samples-poison">language models or LLMs</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>CrowdStrike is tracking a mass exploitation campaign leveraging a previously unknown vulnerability in <a rel="noreferrer noopener" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-identifies-campaign-targeting-oracle-e-business-suite-zero-day-CVE-2025-61882/">Oracle E-business suite or EBS</a>. </li><li>A threat group, tracked as Storm-2603, has been observed using the open source Velociraptor DFIR tool as part of it’s post-exploitation <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/chinese-hackers-velociraptor-ir-tool-ransomware-attacks">toolkit in recent ransomware attacks</a>.</li><li>North Korean IT workers, operating under state direction, continue to infiltrate international tech companies using false identities and anonymizing infrastructure to secure jobs and <a rel="noreferrer noopener" href="https://www.chainalysis.com/blog/dprk-it-workers-north-korea-crypto-laundering-networks/">route payments in cryptocurrency</a>. </li><li>Researchers from Anthropic, the UK AI Security Institute, and Alan Turing Institute have released the largest study to date on poisoning attacks during pre-training on large <a rel="noreferrer noopener" href="https://www.anthropic.com/research/small-samples-poison">language models or LLMs</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 20 Oct 2025 13:00:25 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3ebf128c/0fc77050.mp3" length="57435509" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/2AbKvTqUE3VECT4S5WKUA6r5c72nOYN-yFL4gaKQ5z4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yYjA1/ODkyNWY0ZWJmYzhh/OTU5MDNiZTgzMmFk/NjVkOS5wbmc.jpg"/>
      <itunes:duration>2386</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#257 - Defender Fridays: Using Honeyfiles to Detect Adversaries with Zane Gittins from Meissner Filtration Products</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>257</itunes:episode>
      <podcast:episode>257</podcast:episode>
      <itunes:title>#257 - Defender Fridays: Using Honeyfiles to Detect Adversaries with Zane Gittins from Meissner Filtration Products</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">79ca8028-1f1c-4bdf-acbd-9545333462e5</guid>
      <link>https://share.transistor.fm/s/8664742a</link>
      <description>
        <![CDATA[<p>Zane demonstrates deploying honeyfiles via Velociraptor and discuss deception techniques for early detection of compromise. Learn how decoy files can serve as tripwires for infostealers and adversaries in your environment. Watch on YouTube for better visuals.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastruture for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Zane demonstrates deploying honeyfiles via Velociraptor and discuss deception techniques for early detection of compromise. Learn how decoy files can serve as tripwires for infostealers and adversaries in your environment. Watch on YouTube for better visuals.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastruture for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 20 Oct 2025 03:14:08 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8664742a/b0dac16b.mp3" length="45891550" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tFJSkVcYnDsC1_xVOGEfFcelfXts1JGVBBQVtnVKcdg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZGM1/YmYzNGJhYjFiMzc5/MjMyNzFiNzU3NzYz/ODA1ZC5wbmc.jpg"/>
      <itunes:duration>1907</itunes:duration>
      <itunes:summary>Matt, Chief Strategy Officer at Cerby, joins Defender Fridays to discuss how the autonomous AI agents create a demand for a fresh approach to identity security and shares practical insights on navigating these new challenges.</itunes:summary>
      <itunes:subtitle>Matt, Chief Strategy Officer at Cerby, joins Defender Fridays to discuss how the autonomous AI agents create a demand for a fresh approach to identity security and shares practical insights on navigating these new challenges.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#256 - Intel Chat: RediShell, Cisco zero-day vulnerability, AI voice cloning tech, Brickstorm &amp; pro-Russia teen hackers arrested</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>256</itunes:episode>
      <podcast:episode>256</podcast:episode>
      <itunes:title>#256 - Intel Chat: RediShell, Cisco zero-day vulnerability, AI voice cloning tech, Brickstorm &amp; pro-Russia teen hackers arrested</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">48df121b-46c8-48df-94a8-50386d035483</guid>
      <link>https://share.transistor.fm/s/d34b6035</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A newly disclosed vulnerability in Redis, dubbed RediShell and tracked as CVE-2025-49844, affects all Redis versions and carries a <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/patch-now-redishell-redis-rce">maximum CVSS score of 10.0</a>.</li></ul><ul><li>Cisco has disclosed a critical zero-day vulnerability—CVE-2025-20352—affecting its widely deployed IOS and IOS XE software, confirming active <a rel="noreferrer noopener" href="https://cybersecuritynews.com/cisco-ios-0-day-rce-vulnerability/#google_vignette">exploitation in the wild</a>.</li><li>Researchers at NCC Group have found that voice cloning technology has reached a level where just five minutes of recorded audio is enough to generate <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/ai-voice-cloning-vishing-risks">convincing voice clones in real time</a>.</li><li>A China-linked cyber-espionage group, tracked as UNC5221, has been systematically targeting network infrastructure appliances that lack standard endpoint <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-brickstorm-backdoors-edge-devices">detection and response (EDR) support</a>.</li><li>Dutch authorities have arrested two 17-year-old boys suspected of being recruited by pro-Russian hackers to <a rel="noreferrer noopener" href="https://www.securityweek.com/dutch-teens-arrested-for-allegedly-helping-russian-hackers/">carry out surveillance activities</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A newly disclosed vulnerability in Redis, dubbed RediShell and tracked as CVE-2025-49844, affects all Redis versions and carries a <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/patch-now-redishell-redis-rce">maximum CVSS score of 10.0</a>.</li></ul><ul><li>Cisco has disclosed a critical zero-day vulnerability—CVE-2025-20352—affecting its widely deployed IOS and IOS XE software, confirming active <a rel="noreferrer noopener" href="https://cybersecuritynews.com/cisco-ios-0-day-rce-vulnerability/#google_vignette">exploitation in the wild</a>.</li><li>Researchers at NCC Group have found that voice cloning technology has reached a level where just five minutes of recorded audio is enough to generate <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/ai-voice-cloning-vishing-risks">convincing voice clones in real time</a>.</li><li>A China-linked cyber-espionage group, tracked as UNC5221, has been systematically targeting network infrastructure appliances that lack standard endpoint <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-brickstorm-backdoors-edge-devices">detection and response (EDR) support</a>.</li><li>Dutch authorities have arrested two 17-year-old boys suspected of being recruited by pro-Russian hackers to <a rel="noreferrer noopener" href="https://www.securityweek.com/dutch-teens-arrested-for-allegedly-helping-russian-hackers/">carry out surveillance activities</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 13 Oct 2025 13:00:29 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d34b6035/eded4dfa.mp3" length="66988317" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tlpzUTZBlkKnEhUPNvCKg3l9A4ZcGFyvMU17jXTS5SI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iOTA4/MWMzZTc3NTNkOTkw/NTk4YzdjYmQ5NDE5/OWIxMi5wbmc.jpg"/>
      <itunes:duration>2783</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#255 - Defender Fridays: Identity Automation in the Age of Agentic AI with Matthew Chiodi from Cerby</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>255</itunes:episode>
      <podcast:episode>255</podcast:episode>
      <itunes:title>#255 - Defender Fridays: Identity Automation in the Age of Agentic AI with Matthew Chiodi from Cerby</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b725bc03-2b25-480e-a247-c999873e6891</guid>
      <link>https://share.transistor.fm/s/dd7ffc58</link>
      <description>
        <![CDATA[<p>Matt, Chief Strategy Officer at Cerby, discusses how the autonomous AI agents create a demand for a fresh approach to identity security and shares practical insights on navigating these new challenges.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Matt has spent 20+ years at the intersection of cybersecurity, strategy, and company building. His career began in the trenches as a practitioner and architect, grew into CISO and CSO roles, and today he helps scale <a rel="noreferrer noopener" href="https://www.cerby.com/">Cerby</a> as Chief Strategy Officer.</p><p>At Cerby, Matt has been part of the journey from pre-launch through significant enterprise adoption, serving first as Founding Advisor, then Chief Trust Officer, COO, and now CSO. Each role reflected a different stage of building the company: establishing trust and market credibility, creating the operations foundation, and shaping long-term strategy and growth.</p><p>Before Cerby, as part of the early RedLock team, Matt helped scale Prisma Cloud (formerly RedLock) from $4M to $500M+ ARR after Palo Alto Networks’ $235M acquisition. That experience taught him how to scale security businesses from the ground up while staying connected to practitioner needs.</p><p>Matt believes the best security leaders shouldn’t have to choose between protecting and growing the business; his work is helping organizations achieve both.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastruture for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Matt, Chief Strategy Officer at Cerby, discusses how the autonomous AI agents create a demand for a fresh approach to identity security and shares practical insights on navigating these new challenges.</p><p><a rel="noreferrer noopener" href="https://community.limacharlie.com/">Join the Defender Fridays community</a>, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</p><p>Matt has spent 20+ years at the intersection of cybersecurity, strategy, and company building. His career began in the trenches as a practitioner and architect, grew into CISO and CSO roles, and today he helps scale <a rel="noreferrer noopener" href="https://www.cerby.com/">Cerby</a> as Chief Strategy Officer.</p><p>At Cerby, Matt has been part of the journey from pre-launch through significant enterprise adoption, serving first as Founding Advisor, then Chief Trust Officer, COO, and now CSO. Each role reflected a different stage of building the company: establishing trust and market credibility, creating the operations foundation, and shaping long-term strategy and growth.</p><p>Before Cerby, as part of the early RedLock team, Matt helped scale Prisma Cloud (formerly RedLock) from $4M to $500M+ ARR after Palo Alto Networks’ $235M acquisition. That experience taught him how to scale security businesses from the ground up while staying connected to practitioner needs.</p><p>Matt believes the best security leaders shouldn’t have to choose between protecting and growing the business; his work is helping organizations achieve both.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastruture for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 10 Oct 2025 13:00:24 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/dd7ffc58/1e5ad5ff.mp3" length="48192155" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tt93grs43vfB83xJLKm4T76zoyN7jptqaehEseKwMcE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mZmZm/MjMwMzZjOTJlYThl/YzMwZDJjMGRiMWUy/N2JjZi5wbmc.jpg"/>
      <itunes:duration>2007</itunes:duration>
      <itunes:summary>Matt, Chief Strategy Officer at Cerby, joins Defender Fridays to discuss how the autonomous AI agents create a demand for a fresh approach to identity security and shares practical insights on navigating these new challenges.</itunes:summary>
      <itunes:subtitle>Matt, Chief Strategy Officer at Cerby, joins Defender Fridays to discuss how the autonomous AI agents create a demand for a fresh approach to identity security and shares practical insights on navigating these new challenges.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#254 - Roadmap to Community Cyber Defense with Sarah Powazek, Program Director of Public Interest Cybersecurity, UC Berkeley CLTC</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>254</itunes:episode>
      <podcast:episode>254</podcast:episode>
      <itunes:title>#254 - Roadmap to Community Cyber Defense with Sarah Powazek, Program Director of Public Interest Cybersecurity, UC Berkeley CLTC</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6c7fbda5-4850-48bd-a279-bc0419c73da4</guid>
      <link>https://share.transistor.fm/s/172fee1f</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Sarah Powazek about the Roadmap to Community Cyber Defense. Diving into the report, Sarah emphasizes the need for low-resource organizations and cyber experts to come together in a co-responsibility model for cyber defense. </p><p><a rel="noreferrer noopener" href="https://cltc.berkeley.edu/">Learn more</a> about the UC Berkeley Center for Long-Term Cybersecurity (CLTC).</p><p>Get help or join the <a rel="noreferrer noopener" href="https://www.cybervolunteers.us/en">Cyber Resilience Corps here</a>.</p><p><a rel="noreferrer noopener" href="https://cltc.berkeley.edu/program/cyber-resilience-corps/">Read the roadmap</a>.</p><p>Sarah leads flagship research on defending low-resource organizations like nonprofits, municipalities, and schools from cyber attacks. She serves as Co-Chair of the Cyber Resilience Corps and is also Senior Advisor for the Consortium of Cybersecurity Clinics, advocating for the expansion of clinical cyber education around the world. Sarah hosts the Cyber Civil Defense Summit, an annual mission-based gathering of cyber defenders to protect the nation’s most vulnerable public infrastructure. Sarah previously worked at CrowdStrike Strategic Advisory Services, and as the Program Manager of the Ransomware Task Force.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Sarah Powazek about the Roadmap to Community Cyber Defense. Diving into the report, Sarah emphasizes the need for low-resource organizations and cyber experts to come together in a co-responsibility model for cyber defense. </p><p><a rel="noreferrer noopener" href="https://cltc.berkeley.edu/">Learn more</a> about the UC Berkeley Center for Long-Term Cybersecurity (CLTC).</p><p>Get help or join the <a rel="noreferrer noopener" href="https://www.cybervolunteers.us/en">Cyber Resilience Corps here</a>.</p><p><a rel="noreferrer noopener" href="https://cltc.berkeley.edu/program/cyber-resilience-corps/">Read the roadmap</a>.</p><p>Sarah leads flagship research on defending low-resource organizations like nonprofits, municipalities, and schools from cyber attacks. She serves as Co-Chair of the Cyber Resilience Corps and is also Senior Advisor for the Consortium of Cybersecurity Clinics, advocating for the expansion of clinical cyber education around the world. Sarah hosts the Cyber Civil Defense Summit, an annual mission-based gathering of cyber defenders to protect the nation’s most vulnerable public infrastructure. Sarah previously worked at CrowdStrike Strategic Advisory Services, and as the Program Manager of the Ransomware Task Force.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 08 Oct 2025 10:00:24 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/172fee1f/e8be3b7e.mp3" length="54590733" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2267</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Sarah Powazek, Program Director of Public Interest Cybersecurity, UC Berkeley CLTC.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Sarah Powazek, Program Director of Public Interest Cybersecurity, UC Berkeley CLTC.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#253 - Defender Fridays: Building the Strelka File Scanning System with Josh Liburdi from DoorDash</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>253</itunes:episode>
      <podcast:episode>253</podcast:episode>
      <itunes:title>#253 - Defender Fridays: Building the Strelka File Scanning System with Josh Liburdi from DoorDash</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d70d881d-c079-4106-81a1-5949520d043f</guid>
      <link>https://share.transistor.fm/s/55cfe827</link>
      <description>
        <![CDATA[<p>Josh Liburdi, Principal Engineer of Security Operations at DoorDash, joins Maxime Lamothe-Brassard, LimaCharlie CEO / Founder, to talk about building the Strelka file scanning system.</p><p>As a security engineer who works in security operations (prevention, detection, and response), Josh has more than a decade of industry experience and has worked at several diverse organizations, including Brex, Target, and CrowdStrike.</p><p>He also presents at information security conferences (BSides NYC &amp; SF, SANS, fwd:cloudsec), is a published author (Bluenomicon from Splunk, Huntpedia from Sqrrl), and is active in the open source security community with contributions to many projects, including Substation at Brex (creator), Strelka at Target (creator), and the Zeek network analysis framework.</p><p>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals. Become part of the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie Community</a>. </p><p>Learn more about LimaCharlie at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Josh Liburdi, Principal Engineer of Security Operations at DoorDash, joins Maxime Lamothe-Brassard, LimaCharlie CEO / Founder, to talk about building the Strelka file scanning system.</p><p>As a security engineer who works in security operations (prevention, detection, and response), Josh has more than a decade of industry experience and has worked at several diverse organizations, including Brex, Target, and CrowdStrike.</p><p>He also presents at information security conferences (BSides NYC &amp; SF, SANS, fwd:cloudsec), is a published author (Bluenomicon from Splunk, Huntpedia from Sqrrl), and is active in the open source security community with contributions to many projects, including Substation at Brex (creator), Strelka at Target (creator), and the Zeek network analysis framework.</p><p>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals. Become part of the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie Community</a>. </p><p>Learn more about LimaCharlie at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 03 Oct 2025 16:25:21 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/55cfe827/f4fb069a.mp3" length="44412391" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ZdA_xRpqYtDghTHnxr55H-59_33SkkWnBNLhj3H4LF0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xMTE5/YjM3NmU2NjliZmYx/YWIyZjc1ZmMxZDM5/ZjkyNS5wbmc.jpg"/>
      <itunes:duration>1849</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals. Become part of the LimaCharlie Community.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals. Become part of the LimaCharlie Community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#252 - Intel Chat: Secret Service SWAT Infrastructure, Nimbus Manticore, malicious ads targeting macOS, SpamGPT &amp; GitHub NPM changes</title>
      <itunes:episode>252</itunes:episode>
      <podcast:episode>252</podcast:episode>
      <itunes:title>#252 - Intel Chat: Secret Service SWAT Infrastructure, Nimbus Manticore, malicious ads targeting macOS, SpamGPT &amp; GitHub NPM changes</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2f791593-b84a-4e57-a9db-4d0d39222c1d</guid>
      <link>https://share.transistor.fm/s/c2c42477</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A recent investigation by the U.S. Secret Service claims to have uncovered a massive swatting infrastructure <a rel="noreferrer noopener" href="https://www.cnn.com/2025/09/23/us/swatting-investigation-server-network-discovered">centered around New York City</a>.</li><li>Check Point researchers are tracking an Iran-linked cyber-espionage group known as Nimbus Manticore, which appears to be expanding its <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/iran-linked-hackers-europe-new-malware">operations into Western Europe</a>.</li><li>A new wave of malicious advertising is targeting macOS users by impersonating widely used software and services <a rel="noreferrer noopener" href="https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/">through search engine ads</a>.</li><li>A new tool called SpamGPT is drawing attention in the cybersecurity community for effectively lowering the barrier to entry for large-scale <a rel="noreferrer noopener" href="https://www.techradar.com/pro/security/a-crm-for-cybercriminals-spamgpt-makes-cybercriminals-wildest-dreams-come-true-with-business-grade-marketing-tools-and-features">spam and phishing campaigns</a>.</li><li>In light of increasing attacks on open source ecosystems, GitHub has disclosed recent security incidents affecting the npm registry, including the <a rel="noreferrer noopener" href="https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/">Shai-Hulud worm</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A recent investigation by the U.S. Secret Service claims to have uncovered a massive swatting infrastructure <a rel="noreferrer noopener" href="https://www.cnn.com/2025/09/23/us/swatting-investigation-server-network-discovered">centered around New York City</a>.</li><li>Check Point researchers are tracking an Iran-linked cyber-espionage group known as Nimbus Manticore, which appears to be expanding its <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/iran-linked-hackers-europe-new-malware">operations into Western Europe</a>.</li><li>A new wave of malicious advertising is targeting macOS users by impersonating widely used software and services <a rel="noreferrer noopener" href="https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/">through search engine ads</a>.</li><li>A new tool called SpamGPT is drawing attention in the cybersecurity community for effectively lowering the barrier to entry for large-scale <a rel="noreferrer noopener" href="https://www.techradar.com/pro/security/a-crm-for-cybercriminals-spamgpt-makes-cybercriminals-wildest-dreams-come-true-with-business-grade-marketing-tools-and-features">spam and phishing campaigns</a>.</li><li>In light of increasing attacks on open source ecosystems, GitHub has disclosed recent security incidents affecting the npm registry, including the <a rel="noreferrer noopener" href="https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/">Shai-Hulud worm</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 29 Sep 2025 20:53:58 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c2c42477/fda73a8c.mp3" length="49203147" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/7Zsdt7tNKoJi3A6As8lknZiGIr9iM86Js3qc1y1vRgw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xNjdj/YzgzMWVmMTEyYzU0/ZWRkMmE5ODE5ZmI0/YTY2NC5wbmc.jpg"/>
      <itunes:duration>2043</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#251 - Defender Fridays: Hunting Chinese State Actors with David Burkett from Corelight</title>
      <itunes:episode>251</itunes:episode>
      <podcast:episode>251</podcast:episode>
      <itunes:title>#251 - Defender Fridays: Hunting Chinese State Actors with David Burkett from Corelight</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b14238de-6469-4083-8226-39802cffeb53</guid>
      <link>https://share.transistor.fm/s/98c65d2c</link>
      <description>
        <![CDATA[<p>Maxime Lamothe-Brassard, LimaCharlie CEO / Founder, and our Defender Fridays community sat down with David Burkett to discuss hunting Chinese State Actors with the Latest CISA Joint Advisory.</p>
<p>As a dedicated and highly experienced Cloud Detection Engineer and Security Architect, David has the privilege of working at a Fortune 50 Company where he leverages his extensive background in cybersecurity to protect digital assets. With a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.</p>
<p>David’s expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. He is proud to have been part of a large overall security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. Their security operations center was recognized as being among the top 1% of cybersecurity programs for all cleared facilities.</p>
<p>In addition to his hands-on experience, David has consulted for over 40 Fortune 500 Companies and Large Federal Organizations, helping them manage their SOAR platforms and playbooks. As a strong believer in knowledge sharing and collaboration, he is also an active contributor to the open-source detection security project known as Sigma.</p>
<p>David is constantly seeking opportunities to grow and learn, and is eager to connect with like-minded professionals in the cybersecurity domain. Let's connect and build a safer digital world together.</p>
<p>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals. Become part of the LimaCharlie Community.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Maxime Lamothe-Brassard, LimaCharlie CEO / Founder, and our Defender Fridays community sat down with David Burkett to discuss hunting Chinese State Actors with the Latest CISA Joint Advisory.</p>
<p>As a dedicated and highly experienced Cloud Detection Engineer and Security Architect, David has the privilege of working at a Fortune 50 Company where he leverages his extensive background in cybersecurity to protect digital assets. With a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.</p>
<p>David’s expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. He is proud to have been part of a large overall security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. Their security operations center was recognized as being among the top 1% of cybersecurity programs for all cleared facilities.</p>
<p>In addition to his hands-on experience, David has consulted for over 40 Fortune 500 Companies and Large Federal Organizations, helping them manage their SOAR platforms and playbooks. As a strong believer in knowledge sharing and collaboration, he is also an active contributor to the open-source detection security project known as Sigma.</p>
<p>David is constantly seeking opportunities to grow and learn, and is eager to connect with like-minded professionals in the cybersecurity domain. Let's connect and build a safer digital world together.</p>
<p>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals. Become part of the LimaCharlie Community.</p>]]>
      </content:encoded>
      <pubDate>Fri, 26 Sep 2025 16:21:21 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/98c65d2c/1eaacbbf.mp3" length="47981493" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/0gRsvif3gFOZjB4C5PhQRLlumG9GRNuSobCDlcxkl-Q/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kY2Yx/MTE1ZTIyZTY1Mjhm/MzZhMDQxODQzZWZh/ODBkOC5wbmc.jpg"/>
      <itunes:duration>1998</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#250 - Intel Chat: PromptLock, "Shai-Hulud", EdisonWatch &amp; FileFix campaign</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>250</itunes:episode>
      <podcast:episode>250</podcast:episode>
      <itunes:title>#250 - Intel Chat: PromptLock, "Shai-Hulud", EdisonWatch &amp; FileFix campaign</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bd0260a0-0936-4d48-bd85-e42a6104af76</guid>
      <link>https://share.transistor.fm/s/cf163eea</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>ESET Research has uncovered what it believes to be the first documented case of AI-powered ransomware, <a rel="noreferrer noopener" href="https://bsky.app/profile/esetresearch.bsky.social/post/3lxctuaf4222t">dubbed PromptLock</a>.</li><li>Multiple CrowdStrike-branded npm packages were recently discovered to be compromised, marking a new wave in the ongoing “Shai-Hulud” <a rel="noreferrer noopener" href="https://socket.dev/blog/ongoing-supply-chain-attack-targets-crowdstrike-npm-packages">supply chain attack campaign</a>.</li><li>Researchers at AI security firm EdisonWatch have uncovered a new vulnerability in the ChatGPT calendar integration, revealing how it can be exploited to execute <a rel="noreferrer noopener" href="https://www.securityweek.com/chatgpts-new-calendar-integration-can-be-abused-to-steal-emails/">attacker-controlled commands</a>.</li><li>The most mature and globally distributed FileFix campaign observed to date is now active in the wild, according to <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/innovative-filefix-attack-potent">researchers at Acronis</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="http://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>ESET Research has uncovered what it believes to be the first documented case of AI-powered ransomware, <a rel="noreferrer noopener" href="https://bsky.app/profile/esetresearch.bsky.social/post/3lxctuaf4222t">dubbed PromptLock</a>.</li><li>Multiple CrowdStrike-branded npm packages were recently discovered to be compromised, marking a new wave in the ongoing “Shai-Hulud” <a rel="noreferrer noopener" href="https://socket.dev/blog/ongoing-supply-chain-attack-targets-crowdstrike-npm-packages">supply chain attack campaign</a>.</li><li>Researchers at AI security firm EdisonWatch have uncovered a new vulnerability in the ChatGPT calendar integration, revealing how it can be exploited to execute <a rel="noreferrer noopener" href="https://www.securityweek.com/chatgpts-new-calendar-integration-can-be-abused-to-steal-emails/">attacker-controlled commands</a>.</li><li>The most mature and globally distributed FileFix campaign observed to date is now active in the wild, according to <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/innovative-filefix-attack-potent">researchers at Acronis</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="http://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 22 Sep 2025 16:31:23 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/cf163eea/06bc97e7.mp3" length="52755744" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/JPK5-a-F9HZN6V_fkm_rYvTEniWoXW7o7-Kibgs9hdk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZThj/NGE4YTRiMDRhMjY3/NzUzMDM4MzlmMzRl/N2MzNS5wbmc.jpg"/>
      <itunes:duration>2191</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#249 - Defender Fridays: Security State of Affairs with Cliff Janzen, CISO and VP of Security Services at Arctiq</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>249</itunes:episode>
      <podcast:episode>249</podcast:episode>
      <itunes:title>#249 - Defender Fridays: Security State of Affairs with Cliff Janzen, CISO and VP of Security Services at Arctiq</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">612acd8b-e132-49a3-adcd-7b6318e17c4c</guid>
      <link>https://share.transistor.fm/s/7a7e00a3</link>
      <description>
        <![CDATA[<p>LimaCharlie CEO, Max Lamothe-Brassard welcome Cliff Janzen, CISO and VP of Security Services at Arctiq, for a special "Security Potpourri" session!</p><p>What's on the menu?</p><ul><li>SOC operations and optimization</li><li>Security automation strategies</li><li>Penetration testing insights</li></ul><p>All through Cliff's expert lens and real-world experience. Join us for an insightful discussion on the current security landscape!</p><p>Cliff is an experienced Vice President of Security with a demonstrated history of working in the computer and network security industry. Skilled in Security Architecture, Governance, Incident Management, Ethical Hacking, and Intrusion Detection. Currently working as CISO and VP of Security Services at Arctiq.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>LimaCharlie CEO, Max Lamothe-Brassard welcome Cliff Janzen, CISO and VP of Security Services at Arctiq, for a special "Security Potpourri" session!</p><p>What's on the menu?</p><ul><li>SOC operations and optimization</li><li>Security automation strategies</li><li>Penetration testing insights</li></ul><p>All through Cliff's expert lens and real-world experience. Join us for an insightful discussion on the current security landscape!</p><p>Cliff is an experienced Vice President of Security with a demonstrated history of working in the computer and network security industry. Skilled in Security Architecture, Governance, Incident Management, Ethical Hacking, and Intrusion Detection. Currently working as CISO and VP of Security Services at Arctiq.</p>]]>
      </content:encoded>
      <pubDate>Fri, 19 Sep 2025 17:00:26 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7a7e00a3/691a5d9a.mp3" length="46604957" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/DhppZrGYAkcEpFVRU3nLAnctJnHbCK8_Y89YNT4Cnfg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85OWFj/MTFlOTc1OGJkY2Yx/MmE1NGQyYzMzNDE2/MjNmOS5wbmc.jpg"/>
      <itunes:duration>1941</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#248 - Predictive vs. Reactive Cybersecurity with Robert Boles, Founder / CEO of BLOKWORX</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>248</itunes:episode>
      <podcast:episode>248</podcast:episode>
      <itunes:title>#248 - Predictive vs. Reactive Cybersecurity with Robert Boles, Founder / CEO of BLOKWORX</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">dc918088-38b3-4733-98c8-560518b291b0</guid>
      <link>https://share.transistor.fm/s/5b46803b</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Robert Boles, Founder / CEO of <a rel="noreferrer noopener" href="https://blokworx.com/">BLOKWORX</a>.</p><p>A veteran of the U.S. Marine Corps, Rob founded BLOKWORX in 2006 to further his passion for creating fast, secure networks. Since 1999 Rob was a core technical contributor and presenter on an Advanced IP Team, delivering bleeding edge WAN and Managed Security services to Small, Mid-level and Fortune 500 businesses around the world. </p><p>The experience led him back to the same conclusion, regardless of size and resources, every company struggled with the same uncertainty – multiple vendors with infinite solutions, and no real clarity how to make it all “work.” Rob focused BLOKWORX on security, reliability, and positive user experience. He has built a team that leverages their expertise with extensive research and testing, alignment with vendors, partners, and clients, and the experience of 1000’s of nodes managed and monitored, all supported by a mature delivery model built on years of operational experience. Rob is an avid outdoorsman and his favorite place to be is in a raft or a kayak with his son Jack.</p><p>Learn more at <a rel="noreferrer noopener" href="https://blokworx.com/">blokworx.com</a>.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Robert Boles, Founder / CEO of <a rel="noreferrer noopener" href="https://blokworx.com/">BLOKWORX</a>.</p><p>A veteran of the U.S. Marine Corps, Rob founded BLOKWORX in 2006 to further his passion for creating fast, secure networks. Since 1999 Rob was a core technical contributor and presenter on an Advanced IP Team, delivering bleeding edge WAN and Managed Security services to Small, Mid-level and Fortune 500 businesses around the world. </p><p>The experience led him back to the same conclusion, regardless of size and resources, every company struggled with the same uncertainty – multiple vendors with infinite solutions, and no real clarity how to make it all “work.” Rob focused BLOKWORX on security, reliability, and positive user experience. He has built a team that leverages their expertise with extensive research and testing, alignment with vendors, partners, and clients, and the experience of 1000’s of nodes managed and monitored, all supported by a mature delivery model built on years of operational experience. Rob is an avid outdoorsman and his favorite place to be is in a raft or a kayak with his son Jack.</p><p>Learn more at <a rel="noreferrer noopener" href="https://blokworx.com/">blokworx.com</a>.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 17 Sep 2025 16:00:26 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5b46803b/fb95ab12.mp3" length="56717551" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tOelvW6cniMjb7tE2YVx2yahiAHJL-i-_buNa8270As/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yY2Zj/OTc4ZTNlNGY1Yzli/MDkxNDRmN2RiMWRh/OTY5NS5wbmc.jpg"/>
      <itunes:duration>2352</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders Podcast we speak with Robert Boles, Founder / CEO of BLOKWORX.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders Podcast we speak with Robert Boles, Founder / CEO of BLOKWORX.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#247 - Intel Chat: JavaScript high-profile phishing, Red Sea cable cutting, Contagious Interview campaign &amp; Salty2FA</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>248</itunes:episode>
      <podcast:episode>248</podcast:episode>
      <itunes:title>#247 - Intel Chat: JavaScript high-profile phishing, Red Sea cable cutting, Contagious Interview campaign &amp; Salty2FA</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">cf7666af-8b94-45fa-8d67-950044907227</guid>
      <link>https://share.transistor.fm/s/9425a371</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A high-profile phishing incident has resulted in the compromise of several widely-used JavaScript packages on npm, after a developer known as "Qix" inadvertently clicked a malicious link from a <a rel="noreferrer noopener" href="https://news.ycombinator.com/item?id=45169657">fake support email</a>.</li><li>Multiple undersea cable cuts in the Red Sea have led to degraded internet connectivity across the Middle East and South Asia, affecting <a rel="noreferrer noopener" href="https://www.aljazeera.com/news/2025/9/7/internet-disruptions-in-middle-east-and-south-asia-after-red-sea-cable-cuts">key infrastructure and cloud services</a>.</li><li>North Korean-aligned threat actors operating under the Contagious Interview campaign have been systematically abusing cyber threat intelligence (CTI) platforms to monitor exposure of their own infrastructure and <a rel="noreferrer noopener" href="https://www.sentinelone.com/labs/contagious-interview-threat-actors-scout-cyber-intel-platforms-reveal-plans-and-ops/">scout for new assets</a>.</li><li>Researchers from Ontinue have detailed a sophisticated phishing campaign leveraging the Salty2FA phishing kit - a framework that reflects how cybercriminal tooling is increasingly mimicking enterprise-grade software in terms of design, <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/salty2fa-phishing-kits-enterprise-level">capability, and operational maturity</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A high-profile phishing incident has resulted in the compromise of several widely-used JavaScript packages on npm, after a developer known as "Qix" inadvertently clicked a malicious link from a <a rel="noreferrer noopener" href="https://news.ycombinator.com/item?id=45169657">fake support email</a>.</li><li>Multiple undersea cable cuts in the Red Sea have led to degraded internet connectivity across the Middle East and South Asia, affecting <a rel="noreferrer noopener" href="https://www.aljazeera.com/news/2025/9/7/internet-disruptions-in-middle-east-and-south-asia-after-red-sea-cable-cuts">key infrastructure and cloud services</a>.</li><li>North Korean-aligned threat actors operating under the Contagious Interview campaign have been systematically abusing cyber threat intelligence (CTI) platforms to monitor exposure of their own infrastructure and <a rel="noreferrer noopener" href="https://www.sentinelone.com/labs/contagious-interview-threat-actors-scout-cyber-intel-platforms-reveal-plans-and-ops/">scout for new assets</a>.</li><li>Researchers from Ontinue have detailed a sophisticated phishing campaign leveraging the Salty2FA phishing kit - a framework that reflects how cybercriminal tooling is increasingly mimicking enterprise-grade software in terms of design, <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/salty2fa-phishing-kits-enterprise-level">capability, and operational maturity</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 15 Sep 2025 18:08:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9425a371/6fa629b7.mp3" length="49386088" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/uoTw1IYy7HrKzVL-N2FK0TlH1f4UGAjCdt4iorJ2-9U/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mOTA3/N2RkMjI1MjlhZWUw/NmIzMWYwNzQxOTU2/YmMyMC5wbmc.jpg"/>
      <itunes:duration>2048</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#246 - Defender Fridays: AI in the SOC with Matt Bromiley from Prophet Security</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>246</itunes:episode>
      <podcast:episode>246</podcast:episode>
      <itunes:title>#246 - Defender Fridays: AI in the SOC with Matt Bromiley from Prophet Security</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6856693c-8dac-4a72-8d6f-0312c80cbed5</guid>
      <link>https://share.transistor.fm/s/0f1209e1</link>
      <description>
        <![CDATA[<p>Matt Bromiley breaks down how AI is transforming (and should be transforming) SOC workflows. Whether you're already using AI tools or wondering where to start, this is the conversation you don't want to miss. </p><p>Matt is a security engineer at Prophet Security, refining Prophet AI to enhance automated alert triage, investigation, and response. His work ensures that customers can cut through the noise and focus on real threats - without getting bogged down by manual analysis. Learn more at <a rel="noreferrer noopener" href="https://www.prophetsecurity.ai/">prophetsecurity.ai</a></p><p>Matt is a cybersecurity leader and educator with over 14 years of experience leading incident response efforts and advancing detection and response capabilities across enterprise environments. His career has spanned hands-on operations, high-pressure breach response, and the strategic development of scalable cybersecurity programs.</p><p>Matt also serves as an instructor with the SANS institute, delivering advanced training in incident management and host- and network-based incident response. </p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Matt Bromiley breaks down how AI is transforming (and should be transforming) SOC workflows. Whether you're already using AI tools or wondering where to start, this is the conversation you don't want to miss. </p><p>Matt is a security engineer at Prophet Security, refining Prophet AI to enhance automated alert triage, investigation, and response. His work ensures that customers can cut through the noise and focus on real threats - without getting bogged down by manual analysis. Learn more at <a rel="noreferrer noopener" href="https://www.prophetsecurity.ai/">prophetsecurity.ai</a></p><p>Matt is a cybersecurity leader and educator with over 14 years of experience leading incident response efforts and advancing detection and response capabilities across enterprise environments. His career has spanned hands-on operations, high-pressure breach response, and the strategic development of scalable cybersecurity programs.</p><p>Matt also serves as an instructor with the SANS institute, delivering advanced training in incident management and host- and network-based incident response. </p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 12 Sep 2025 21:09:37 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0f1209e1/a3a44acc.mp3" length="47204504" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ADMMkXH_iIOAlLjr1ySq3ewxE789n9ZeIZwjpCCIXf8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNjAz/Y2FjMTc4YWE1NmYw/MDljMDA5YTMxMTgz/Mjc0Ni5wbmc.jpg"/>
      <itunes:duration>1966</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#245 - Intel Chat: Salt Typhoon, Scattered LapSus Hunters, WhatsApp vulnerability &amp; AI-assisted compromise</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>245</itunes:episode>
      <podcast:episode>245</podcast:episode>
      <itunes:title>#245 - Intel Chat: Salt Typhoon, Scattered LapSus Hunters, WhatsApp vulnerability &amp; AI-assisted compromise</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4e416e96-d550-48c4-bcbe-fca04f2fda9d</guid>
      <link>https://share.transistor.fm/s/ee4959a4</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The Salt Typhoon cyber campaign, attributed to Chinese state-backed hackers, has been declared a national defense crisis by the FBI and <a rel="noreferrer noopener" href="https://www.forbes.com/sites/emilsayegh/2025/08/30/us-and-allies-declare-salt-typhoon-hack-a-national-defense-crisis/">allied intelligence agencies</a>.</li><li>A group identifying itself as “Scattered LapSus Hunters” has posted a threat on Telegram demanding that Google terminate <a rel="noreferrer noopener" href="https://www.newsweek.com/hackers-issue-ultimatum-data-breach-2122489">two of its employees</a>.</li><li>A newly discovered WhatsApp vulnerability, now tracked as CVE-2025-55177, has triggered urgent security advisories, <a rel="noreferrer noopener" href="https://nypost.com/2025/09/01/tech/sophisticated-whatsapp-attack-targets-iphone-users/">particularly for iPhone users</a>.</li><li>More than 1,000 developers were compromised in just over four hours on August 26 during an unprecedented, AI-assisted software supply chain attack <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/1000-devs-lose-secrets-ai-powered-stealer">targeting the npm ecosystem</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The Salt Typhoon cyber campaign, attributed to Chinese state-backed hackers, has been declared a national defense crisis by the FBI and <a rel="noreferrer noopener" href="https://www.forbes.com/sites/emilsayegh/2025/08/30/us-and-allies-declare-salt-typhoon-hack-a-national-defense-crisis/">allied intelligence agencies</a>.</li><li>A group identifying itself as “Scattered LapSus Hunters” has posted a threat on Telegram demanding that Google terminate <a rel="noreferrer noopener" href="https://www.newsweek.com/hackers-issue-ultimatum-data-breach-2122489">two of its employees</a>.</li><li>A newly discovered WhatsApp vulnerability, now tracked as CVE-2025-55177, has triggered urgent security advisories, <a rel="noreferrer noopener" href="https://nypost.com/2025/09/01/tech/sophisticated-whatsapp-attack-targets-iphone-users/">particularly for iPhone users</a>.</li><li>More than 1,000 developers were compromised in just over four hours on August 26 during an unprecedented, AI-assisted software supply chain attack <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/1000-devs-lose-secrets-ai-powered-stealer">targeting the npm ecosystem</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 08 Sep 2025 22:25:47 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ee4959a4/1d2ec464.mp3" length="50489691" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/QRVR9YAAOUgu53uxfiaEC7j2awTLfxzjvZfRry5gFT8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83YTM0/NjA4ZTUwOWI0MTY5/ODYyNTliNTFlZDY3/MTA4MS5wbmc.jpg"/>
      <itunes:duration>2097</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#244 - Intel Chat: Trend Micro Apex One, PyPI domains, RingReaper &amp; Openbaar Ministrie attack</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>244</itunes:episode>
      <podcast:episode>244</podcast:episode>
      <itunes:title>#244 - Intel Chat: Trend Micro Apex One, PyPI domains, RingReaper &amp; Openbaar Ministrie attack</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d8aa55b5-0e8f-408f-9045-8179f97de651</guid>
      <link>https://share.transistor.fm/s/99efd82e</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>CISA has added CVE-2025-54948, a critical vulnerability in Trend Micro Apex One, to its Known Exploited Vulnerabilities (KEV) catalog, signaling that the flaw has been actively <a rel="noreferrer noopener" href="https://securityaffairs.com/181283/hacking/u-s-cisa-adds-trend-micro-apex-one-flaw-to-its-known-exploited-vulnerabilities-catalog.html">exploited in the wild</a>.</li><li>PyPI has introduced new security measures to detect and respond to expired domains tied to user accounts, aiming to shut down a known supply chain attack vector: <a rel="noreferrer noopener" href="https://thehackernews.com/2025/08/pypi-blocks-1800-expired-domain-emails.html">domain resurrection.</a></li><li>A recently discovered post-exploitation tool named RingReaper is gaining attention for its sophisticated evasion strategy: abusing the Linux kernel’s io_uring interface to operate undetected by standard endpoint <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/ringreaper-sneaks-past-linux-edrs">detection and response (EDR) systems</a>.</li><li>A cyberattack on the Netherlands’ Openbaar Ministerie (OM), the Public Prosecution Service, has unexpectedly disrupted speed enforcement <a rel="noreferrer noopener" href="https://www.bitdefender.com/en-us/blog/hotforsecurity/speed-cameras-knocked-out-after-cyber-attack">across the country.</a></li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>CISA has added CVE-2025-54948, a critical vulnerability in Trend Micro Apex One, to its Known Exploited Vulnerabilities (KEV) catalog, signaling that the flaw has been actively <a rel="noreferrer noopener" href="https://securityaffairs.com/181283/hacking/u-s-cisa-adds-trend-micro-apex-one-flaw-to-its-known-exploited-vulnerabilities-catalog.html">exploited in the wild</a>.</li><li>PyPI has introduced new security measures to detect and respond to expired domains tied to user accounts, aiming to shut down a known supply chain attack vector: <a rel="noreferrer noopener" href="https://thehackernews.com/2025/08/pypi-blocks-1800-expired-domain-emails.html">domain resurrection.</a></li><li>A recently discovered post-exploitation tool named RingReaper is gaining attention for its sophisticated evasion strategy: abusing the Linux kernel’s io_uring interface to operate undetected by standard endpoint <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/ringreaper-sneaks-past-linux-edrs">detection and response (EDR) systems</a>.</li><li>A cyberattack on the Netherlands’ Openbaar Ministerie (OM), the Public Prosecution Service, has unexpectedly disrupted speed enforcement <a rel="noreferrer noopener" href="https://www.bitdefender.com/en-us/blog/hotforsecurity/speed-cameras-knocked-out-after-cyber-attack">across the country.</a></li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 01 Sep 2025 19:52:16 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/99efd82e/9df62ae4.mp3" length="43317620" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Wvxd5NqUR7qRJgVVrJlrGJmdRSdaIJDyskiiIotraas/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNGJk/ZDcwYjJhYzk0ZTNk/ZjQ0ZjdmY2UwMDFi/YmY2ZC5wbmc.jpg"/>
      <itunes:duration>1794</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#243 - Defender Fridays: Detection prioritization via the BloodHound attack graph with Jared Atkinson, CTO at SpecterOps</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>243</itunes:episode>
      <podcast:episode>243</podcast:episode>
      <itunes:title>#243 - Defender Fridays: Detection prioritization via the BloodHound attack graph with Jared Atkinson, CTO at SpecterOps</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3ed972cb-3289-418a-bac0-6afe5f62ae2c</guid>
      <link>https://share.transistor.fm/s/f455c65d</link>
      <description>
        <![CDATA[<p>Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, and the Defender Fridays community sit down with Jared Atkinson and dive into BloodHound.</p><p>Jared is a security researcher who specializes in Digital Forensics and Incident Response. Recently, he has been building and leading private sector Hunt Operations capabilities. In his previous life, Jared lead incident response missions for the U.S. Air Force Hunt Team, detecting and removing Advanced Persistent Threats on Air Force and DoD networks. Passionate about PowerShell and the open source community, Jared is the lead developer of PowerForensics, Uproot, and maintains a DFIR focused blog at www.invoke-ir.com.</p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at https://limacharlie.io/defender-fridays</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, and the Defender Fridays community sit down with Jared Atkinson and dive into BloodHound.</p><p>Jared is a security researcher who specializes in Digital Forensics and Incident Response. Recently, he has been building and leading private sector Hunt Operations capabilities. In his previous life, Jared lead incident response missions for the U.S. Air Force Hunt Team, detecting and removing Advanced Persistent Threats on Air Force and DoD networks. Passionate about PowerShell and the open source community, Jared is the lead developer of PowerForensics, Uproot, and maintains a DFIR focused blog at www.invoke-ir.com.</p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at https://limacharlie.io/defender-fridays</p>]]>
      </content:encoded>
      <pubDate>Fri, 29 Aug 2025 16:45:13 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f455c65d/0bd35d58.mp3" length="47951873" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/S2ZIgNs4OUaWXkSq2VpeZk_A3abyfg569CAwyde4bD4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZDU4/MWM3ZDJmMTliZGVk/OTM2MGM0YWU5ODgx/ZDAxZC5wbmc.jpg"/>
      <itunes:duration>1997</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#242 - Building human &amp; AI synergy with Peter Ruta, Founder / CEO of Arcanna.ai</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>242</itunes:episode>
      <podcast:episode>242</podcast:episode>
      <itunes:title>#242 - Building human &amp; AI synergy with Peter Ruta, Founder / CEO of Arcanna.ai</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">32204cb8-d30a-409b-b890-65e00882891f</guid>
      <link>https://share.transistor.fm/s/90017259</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Peter Ruta, Founder / CEO, Arcanna.ai.</p><p>Peter is a Romanian-born entrepreneur and technology expert with over 13 years of experience in the industry. His interest in technology was sparked after following a military path, and he went on to secure key jobs in prominent tech companies such as Cisco. In 2015, Peter decided to pursue his passion for entrepreneurship and founded Siscale AI INC. He then went on to develop Arcanna AI, a product that leverages the latest advancements in artificial intelligence to deliver cutting-edge solutions to clients. </p><p>Alongside his highly knowledgeable team, Peter has successfully grown Siscale AI into a thriving company with a strong reputation for innovation and excellence. Throughout his career, Peter has been recognized for his inquisitive, analytical mind and his ability to grasp complex situations quickly. He is known for his professionalism, results-oriented approach, and unwavering determination in the face of challenges. Peter is a natural leader who inspires his team to achieve their full potential and never loses sight of his goals.</p><p>Learn more at https://www.arcanna.ai/</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Peter Ruta, Founder / CEO, Arcanna.ai.</p><p>Peter is a Romanian-born entrepreneur and technology expert with over 13 years of experience in the industry. His interest in technology was sparked after following a military path, and he went on to secure key jobs in prominent tech companies such as Cisco. In 2015, Peter decided to pursue his passion for entrepreneurship and founded Siscale AI INC. He then went on to develop Arcanna AI, a product that leverages the latest advancements in artificial intelligence to deliver cutting-edge solutions to clients. </p><p>Alongside his highly knowledgeable team, Peter has successfully grown Siscale AI into a thriving company with a strong reputation for innovation and excellence. Throughout his career, Peter has been recognized for his inquisitive, analytical mind and his ability to grasp complex situations quickly. He is known for his professionalism, results-oriented approach, and unwavering determination in the face of challenges. Peter is a natural leader who inspires his team to achieve their full potential and never loses sight of his goals.</p><p>Learn more at https://www.arcanna.ai/</p>]]>
      </content:encoded>
      <pubDate>Wed, 27 Aug 2025 21:33:15 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/90017259/cb663606.mp3" length="45840215" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/WGhk9exQpg5ebkw2ZCuQqXXOcMXZ6gz0AliQQwE9t-g/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83ODI4/N2U3ZTA4OTE2NzNm/OGU4MzlkYjBmMzQz/YjNkNi5wbmc.jpg"/>
      <itunes:duration>1901</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders Podcast we speak with Peter Ruta, Founder / CEO, Arcanna.ai.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders Podcast we speak with Peter Ruta, Founder / CEO, Arcanna.ai.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#241 - Intel Chat:Apache ActiveMQ, Elastic EDR vulnerability, kernel-level EDR killers &amp; PipeMagic</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>244</itunes:episode>
      <podcast:episode>244</podcast:episode>
      <itunes:title>#241 - Intel Chat:Apache ActiveMQ, Elastic EDR vulnerability, kernel-level EDR killers &amp; PipeMagic</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c3cd2fd6-b2bd-42e1-8453-db6d13e8ec12</guid>
      <link>https://share.transistor.fm/s/5a126c76</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>• Attackers are actively exploiting CVE-2023-46604, a remote code execution vulnerability in Apache ActiveMQ first disclosed in October 2023, that is used to compromise <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/dripdropper-hackers-patch-own-exploit">cloud-hosted Linux servers</a>.</p><p>• AshES Cybersecurity has publicly disclosed a critical zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) platform, specifically in the Microsoft-signed kernel driver <a rel="noreferrer noopener" href="https://gbhackers.com/elastic-edr-0-day-flaw/amp/">elastic-endpoint-driver.sys</a>.</p><p>• At least a dozen ransomware groups are now deploying kernel-level EDR killers - tools designed specifically to disable endpoint detection and response solutions - as part of <a rel="noreferrer noopener" href="https://www.theregister.com/2025/08/14/edr_killers_ransomware/">their malware arsenal</a>.</p><p>• Microsoft has released an in-depth technical analysis of PipeMagic, a modular backdoor linked to ransomware operations carried out by Storm-2460, a financially motivated threat group <a rel="noreferrer noopener" href="https://www.securityweek.com/microsoft-dissects-pipemagic-modular-backdoor/">associated with RansomEXX</a>.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><p>• Attackers are actively exploiting CVE-2023-46604, a remote code execution vulnerability in Apache ActiveMQ first disclosed in October 2023, that is used to compromise <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/dripdropper-hackers-patch-own-exploit">cloud-hosted Linux servers</a>.</p><p>• AshES Cybersecurity has publicly disclosed a critical zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) platform, specifically in the Microsoft-signed kernel driver <a rel="noreferrer noopener" href="https://gbhackers.com/elastic-edr-0-day-flaw/amp/">elastic-endpoint-driver.sys</a>.</p><p>• At least a dozen ransomware groups are now deploying kernel-level EDR killers - tools designed specifically to disable endpoint detection and response solutions - as part of <a rel="noreferrer noopener" href="https://www.theregister.com/2025/08/14/edr_killers_ransomware/">their malware arsenal</a>.</p><p>• Microsoft has released an in-depth technical analysis of PipeMagic, a modular backdoor linked to ransomware operations carried out by Storm-2460, a financially motivated threat group <a rel="noreferrer noopener" href="https://www.securityweek.com/microsoft-dissects-pipemagic-modular-backdoor/">associated with RansomEXX</a>.</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 26 Aug 2025 01:25:08 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5a126c76/9ff9720c.mp3" length="53017964" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/rXUGk2obHDww1nWekA88-fl9L4SCuaXyWPvJymsxIBM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZTdi/ODRmYTY2MTczYmMw/MGM0NTI5MTc1MmE4/MDIxYy5wbmc.jpg"/>
      <itunes:duration>2201</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#240 - Defender Fridays: Remote Management Tool Abuse with Ezra Woods, Security Engineer at Grand Canyon Education</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>240</itunes:episode>
      <podcast:episode>240</podcast:episode>
      <itunes:title>#240 - Defender Fridays: Remote Management Tool Abuse with Ezra Woods, Security Engineer at Grand Canyon Education</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2d5cb702-6b06-4e80-88ac-4c5f099888ac</guid>
      <link>https://share.transistor.fm/s/53eec936</link>
      <description>
        <![CDATA[<p>Ezra Woods, Security Engineer at Grand Canyon Education, shares insights on current attack trends and practical defensive strategies you can use to protect your environment with Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, and the Defender Fridays community.</p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at https://limacharlie.io/defender-fridays</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Ezra Woods, Security Engineer at Grand Canyon Education, shares insights on current attack trends and practical defensive strategies you can use to protect your environment with Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, and the Defender Fridays community.</p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at https://limacharlie.io/defender-fridays</p>]]>
      </content:encoded>
      <pubDate>Sat, 23 Aug 2025 05:06:26 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/53eec936/6e2c9b1c.mp3" length="41918617" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/nXnFSDFDTuXaFDeDhCJhUhDdLKHe4H772CiqEbv3EyU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lMDM0/ZjYzNmZjY2M3YzQ3/ZjBjZDUxNDE3NWUw/MTliMC5wbmc.jpg"/>
      <itunes:duration>1746</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#239 - Intel Chat: Scattered Spider or ShinyHunters, Linux kernel’s eBPF subsystem, MAPP &amp; BlackSuit ransomware group</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>239</itunes:episode>
      <podcast:episode>239</podcast:episode>
      <itunes:title>#239 - Intel Chat: Scattered Spider or ShinyHunters, Linux kernel’s eBPF subsystem, MAPP &amp; BlackSuit ransomware group</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">cb68f6da-b4c2-49ef-8903-0df7f8ecda2b</guid>
      <link>https://share.transistor.fm/s/a6102ddc</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community. </p><p>• Recent reporting from DataBreaches has added yet another twist to the attribution puzzle between Scattered Spider and ShinyHunters. https://databreaches.net/2025/08/03/are-scattered-spider-and-shinyhunters-one-group-or-two-and-who-did-france-arrest/</p><p>• A recent disclosure on the oss-security mailing list detailed a set of 11 vulnerabilities in the Linux kernel’s eBPF subsystem, originally reported by security researcher “Van1sh” to both the kernel security team and the linux-distros list on July 19. https://www.openwall.com/lists/oss-security/2025/08/03/1</p><p>• Microsoft’s Microsoft Active Protections Program, or MAPP, is designed to shorten the time between vulnerability discovery and patch deployment by giving trusted security vendors early access to vulnerability details. https://nattothoughts.substack.com/p/when-privileged-access-falls-into</p><p>• US law enforcement, in coordination with multiple international partners, has taken action against the BlackSuit ransomware group — also known as Royal — resulting in the seizure of four servers, nine domains, and approximately $1 million in cryptocurrency. https://www.darkreading.com/vulnerabilities-threats/blacksuit-ransomware-infrastructure-law-enforcement</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community. </p><p>• Recent reporting from DataBreaches has added yet another twist to the attribution puzzle between Scattered Spider and ShinyHunters. https://databreaches.net/2025/08/03/are-scattered-spider-and-shinyhunters-one-group-or-two-and-who-did-france-arrest/</p><p>• A recent disclosure on the oss-security mailing list detailed a set of 11 vulnerabilities in the Linux kernel’s eBPF subsystem, originally reported by security researcher “Van1sh” to both the kernel security team and the linux-distros list on July 19. https://www.openwall.com/lists/oss-security/2025/08/03/1</p><p>• Microsoft’s Microsoft Active Protections Program, or MAPP, is designed to shorten the time between vulnerability discovery and patch deployment by giving trusted security vendors early access to vulnerability details. https://nattothoughts.substack.com/p/when-privileged-access-falls-into</p><p>• US law enforcement, in coordination with multiple international partners, has taken action against the BlackSuit ransomware group — also known as Royal — resulting in the seizure of four servers, nine domains, and approximately $1 million in cryptocurrency. https://www.darkreading.com/vulnerabilities-threats/blacksuit-ransomware-infrastructure-law-enforcement</p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. </p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.</p>]]>
      </content:encoded>
      <pubDate>Tue, 19 Aug 2025 22:15:31 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a6102ddc/8f143ad8.mp3" length="55048251" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/AnFPmUoHX9zPV2qmOPCO899JwBoKxhRiHaU7aykLjeg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hNWJl/MzQ1ZTliODNiYTQz/YzRjZjdkNTg4MGM4/ZjUyOS5wbmc.jpg"/>
      <itunes:duration>2284</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#238 - Defender Fridays: Building trusted ecosystems for incident response with Dr. Mike Saylor, CEO of Blackswan Cybersecurity</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>238</itunes:episode>
      <podcast:episode>238</podcast:episode>
      <itunes:title>#238 - Defender Fridays: Building trusted ecosystems for incident response with Dr. Mike Saylor, CEO of Blackswan Cybersecurity</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ceca97bc-6907-49a1-bc1d-bdda974a1d90</guid>
      <link>https://share.transistor.fm/s/effbad98</link>
      <description>
        <![CDATA[<p>Christopher Luft, Co-Founder and CCO of LimaCharlie, and Dr. Mike Saylor, CEO of Blackswan Cybersecurity, sat down with the Defender Fridays community for Black Hat week wrap up and a deep dive building secure environments for IR.</p><p>Dr. Mike Saylor is an accomplished, outcome-driven and solution-focused business professional and entrepreneur with 30+ years of Consulting, IT Audit &amp; Risk, Cyber Security &amp; Incident Response experience. Uniquely qualified as a leader with a solid knowledge of operations, strategy and management, Dr. Mike has enjoyed repeated success guiding highly skilled, cross functional teams in areas of intelligence, security, technology, and audit &amp; compliance. </p><p>Dr. Mike is an experienced public speaker, writer, and researcher on topics of technology, security, and cybercrime. He stays current with changes in the industry through professional affiliations and continuing professional development. Learn more about Blackswan Cybersecurity at <a rel="noreferrer noopener" href="https://www.blackswan-cybersecurity.com/">blackswan-cybersecurity.com</a></p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Christopher Luft, Co-Founder and CCO of LimaCharlie, and Dr. Mike Saylor, CEO of Blackswan Cybersecurity, sat down with the Defender Fridays community for Black Hat week wrap up and a deep dive building secure environments for IR.</p><p>Dr. Mike Saylor is an accomplished, outcome-driven and solution-focused business professional and entrepreneur with 30+ years of Consulting, IT Audit &amp; Risk, Cyber Security &amp; Incident Response experience. Uniquely qualified as a leader with a solid knowledge of operations, strategy and management, Dr. Mike has enjoyed repeated success guiding highly skilled, cross functional teams in areas of intelligence, security, technology, and audit &amp; compliance. </p><p>Dr. Mike is an experienced public speaker, writer, and researcher on topics of technology, security, and cybercrime. He stays current with changes in the industry through professional affiliations and continuing professional development. Learn more about Blackswan Cybersecurity at <a rel="noreferrer noopener" href="https://www.blackswan-cybersecurity.com/">blackswan-cybersecurity.com</a></p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 15 Aug 2025 16:00:32 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/effbad98/2f8b5768.mp3" length="45270508" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ZgSG8CblGXLyzLdvjdy_zTFD-3TXuXJt2UQPxgZh5L4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yMTUx/YWY4Mjc0ODFlMmI1/OWIyYjI3NWIyMzFm/Zjk1Zi5wbmc.jpg"/>
      <itunes:duration>1885</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#237 - Intel Chat: Black Hat roundup - Gemini AI, NeuralTrust &amp; SPLX, VisionSpace Tech, BCM5820X - &amp; CISA/FEMA grant funding</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>237</itunes:episode>
      <podcast:episode>237</podcast:episode>
      <itunes:title>#237 - Intel Chat: Black Hat roundup - Gemini AI, NeuralTrust &amp; SPLX, VisionSpace Tech, BCM5820X - &amp; CISA/FEMA grant funding</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">68a47955-4431-4cf9-993c-c59a0c201663</guid>
      <link>https://share.transistor.fm/s/fcd7d023</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>At Black Hat USA in Las Vegas, three security researchers demonstrated how Google's Gemini AI could be hijacked to take control of smart home devices using a novel form of <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/google-gemini-ai-bot-hijacks-smart-homes">indirect prompt injection</a>.</li><li>Two separate security teams - NeuralTrust and SPLX - have conducted red teaming evaluations of the newly released GPT-5, and both report serious deficiencies in the <a rel="noreferrer noopener" href="https://www.securityweek.com/red-teams-breach-gpt-5-with-ease-warn-its-nearly-unusable-for-enterprise/">model’s security posture</a>.</li><li>Another Black Hat story, security researchers Milenko Starcik and Andrzej Olchawa from VisionSpace Technologies presented a compelling case that hacking satellites is not only more cost-effective than deploying anti-satellite missiles, but alarmingly easy due to <a rel="noreferrer noopener" href="https://www.theregister.com/2025/08/07/balck_hat_satellites/">widespread software vulnerabilities</a>.</li><li>Our final Black Hat story, Cisco Talos researchers disclosed five critical vulnerabilities in Broadcom’s BCM5820X series chips, used in Dell’s ControlVault3 <a rel="noreferrer noopener" href="https://www.theregister.com/2025/08/05/millions_of_dell_pc_with/?td=keepreading">secure enclave hardware</a>.</li><li>CISA and FEMA have jointly announced over $100 million in cybersecurity grant funding for the 2025 fiscal year, targeting state, local, <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/cisa-fema-100m-cybersecurity-grants">and tribal governments</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>At Black Hat USA in Las Vegas, three security researchers demonstrated how Google's Gemini AI could be hijacked to take control of smart home devices using a novel form of <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/google-gemini-ai-bot-hijacks-smart-homes">indirect prompt injection</a>.</li><li>Two separate security teams - NeuralTrust and SPLX - have conducted red teaming evaluations of the newly released GPT-5, and both report serious deficiencies in the <a rel="noreferrer noopener" href="https://www.securityweek.com/red-teams-breach-gpt-5-with-ease-warn-its-nearly-unusable-for-enterprise/">model’s security posture</a>.</li><li>Another Black Hat story, security researchers Milenko Starcik and Andrzej Olchawa from VisionSpace Technologies presented a compelling case that hacking satellites is not only more cost-effective than deploying anti-satellite missiles, but alarmingly easy due to <a rel="noreferrer noopener" href="https://www.theregister.com/2025/08/07/balck_hat_satellites/">widespread software vulnerabilities</a>.</li><li>Our final Black Hat story, Cisco Talos researchers disclosed five critical vulnerabilities in Broadcom’s BCM5820X series chips, used in Dell’s ControlVault3 <a rel="noreferrer noopener" href="https://www.theregister.com/2025/08/05/millions_of_dell_pc_with/?td=keepreading">secure enclave hardware</a>.</li><li>CISA and FEMA have jointly announced over $100 million in cybersecurity grant funding for the 2025 fiscal year, targeting state, local, <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/cisa-fema-100m-cybersecurity-grants">and tribal governments</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 11 Aug 2025 20:36:28 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fcd7d023/8d4e6ff5.mp3" length="61546754" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/i_2ld-S8Ropti6ufMmbnzmTJ4dluKr6I3VGFR8RS1Ms/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80OGU1/OGRmMzZhZDFjODA5/ODg3ZGQ3ZDY2NGRk/MDdhMS5wbmc.jpg"/>
      <itunes:duration>2557</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#236 - Defender Fridays: Explore the Challenges of Securing AI Adoption with Jeremy Snyder, Founder and CEO of FireTail.ai</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>236</itunes:episode>
      <podcast:episode>236</podcast:episode>
      <itunes:title>#236 - Defender Fridays: Explore the Challenges of Securing AI Adoption with Jeremy Snyder, Founder and CEO of FireTail.ai</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e9c8e825-faf0-4364-8f0e-8d6462c7ac0e</guid>
      <link>https://share.transistor.fm/s/322869d0</link>
      <description>
        <![CDATA[<p>Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, and Jeremy Snyder, Founder and CEO of <a rel="noreferrer noopener" href="https://www.firetail.ai/">FireTail.ai</a>, sat down with the Defender Fridays community to discuss the hurdles of maintaining secure processes while adding AI to your workflow.</p><p>Jeremy is the founder and CEO of FireTail.ai. Jeremy was an IT and cybersecurity practitioner for over 10 years before transitioning into product and sales roles in cloud security and cyber. Jeremy once went three days without seeing another human, but saw lots of reindeer. Another time, Jeremy was kicked off a train in central Sweden. Find out more at <a rel="noreferrer noopener" href="https://www.firetail.ai/">FireTail.ai</a>.</p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays?wchannelid=1ezi1lkgs2">limacharlie.io/defender-fridays.</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Maxime Lamothe-Brassard, Founder and CEO of LimaCharlie, and Jeremy Snyder, Founder and CEO of <a rel="noreferrer noopener" href="https://www.firetail.ai/">FireTail.ai</a>, sat down with the Defender Fridays community to discuss the hurdles of maintaining secure processes while adding AI to your workflow.</p><p>Jeremy is the founder and CEO of FireTail.ai. Jeremy was an IT and cybersecurity practitioner for over 10 years before transitioning into product and sales roles in cloud security and cyber. Jeremy once went three days without seeing another human, but saw lots of reindeer. Another time, Jeremy was kicked off a train in central Sweden. Find out more at <a rel="noreferrer noopener" href="https://www.firetail.ai/">FireTail.ai</a>.</p><p>On Defender Fridays we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Join the live discussions by registering at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays?wchannelid=1ezi1lkgs2">limacharlie.io/defender-fridays.</a></p><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 08 Aug 2025 20:32:08 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/322869d0/e60798e9.mp3" length="43589053" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/nh95tyCWkaOXVSNIGQPRLDnOJWHGKKqxaz7uTTOpTDc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yODA0/YTkxZDVjMDU1NDJi/MmRiOTE4MDU2ZDM5/MGRkZS5wbmc.jpg"/>
      <itunes:duration>1815</itunes:duration>
      <itunes:summary>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:summary>
      <itunes:subtitle>Join Defender Fridays, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#237 - Intel Chat: Black Hat roundup - Gemini AI, NeuralTrust &amp; SPLX, VisionSpace Tech, BCM5820X - &amp; CISA/FEMA cyber grant funding</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>235</itunes:episode>
      <podcast:episode>235</podcast:episode>
      <itunes:title>#237 - Intel Chat: Black Hat roundup - Gemini AI, NeuralTrust &amp; SPLX, VisionSpace Tech, BCM5820X - &amp; CISA/FEMA cyber grant funding</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9c803d93-0e3d-4f75-ab12-9d0553ac8963</guid>
      <link>https://share.transistor.fm/s/45114c25</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>More than 90 state and local government organizations have been targeted in a recent wave of cyberattacks exploiting a vulnerability in Microsoft SharePoint, according to the <a rel="noreferrer noopener" href="https://www.reuters.com/technology/more-than-90-state-local-governments-targeted-using-microsoft-sharepoint-2025-07-29/">Center for Internet Security (CIS)</a>.</li><li>Traditional cyber attack methodologies - exploiting endpoints, moving laterally, escalating privileges - are increasingly outdated as enterprise IT shifts toward <a rel="noreferrer noopener" href="https://chatgpt.com/g/g-Otf6Ae2Im-intel-chat-summary-robot/c/6888f1c7-fb48-8323-a4d2-6bb24b5e5fe4">SaaS and browser-based access</a>.</li><li>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2023-2533 - a high-severity Cross-Site Request Forgery (CSRF) vulnerability in PaperCut NG/MF print management software - to its <a rel="noreferrer noopener" href="https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html">Known Exploited Vulnerabilities (KEV) catalog</a>.</li><li>Researchers at Nozomi Networks have disclosed over a dozen security flaws in Tridium’s Niagara Framework, a vendor-agnostic building management platform used in sectors ranging from industrial automation to <a rel="noreferrer noopener" href="https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html">energy and smart infrastructure</a>.</li><li>Between April 2024 and April 2025, ransomware attacks on the oil and gas industry increased by an unprecedented 935%, according to new research from <a rel="noreferrer noopener" href="https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html">cybersecurity firm Zscaler</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>More than 90 state and local government organizations have been targeted in a recent wave of cyberattacks exploiting a vulnerability in Microsoft SharePoint, according to the <a rel="noreferrer noopener" href="https://www.reuters.com/technology/more-than-90-state-local-governments-targeted-using-microsoft-sharepoint-2025-07-29/">Center for Internet Security (CIS)</a>.</li><li>Traditional cyber attack methodologies - exploiting endpoints, moving laterally, escalating privileges - are increasingly outdated as enterprise IT shifts toward <a rel="noreferrer noopener" href="https://chatgpt.com/g/g-Otf6Ae2Im-intel-chat-summary-robot/c/6888f1c7-fb48-8323-a4d2-6bb24b5e5fe4">SaaS and browser-based access</a>.</li><li>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2023-2533 - a high-severity Cross-Site Request Forgery (CSRF) vulnerability in PaperCut NG/MF print management software - to its <a rel="noreferrer noopener" href="https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html">Known Exploited Vulnerabilities (KEV) catalog</a>.</li><li>Researchers at Nozomi Networks have disclosed over a dozen security flaws in Tridium’s Niagara Framework, a vendor-agnostic building management platform used in sectors ranging from industrial automation to <a rel="noreferrer noopener" href="https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html">energy and smart infrastructure</a>.</li><li>Between April 2024 and April 2025, ransomware attacks on the oil and gas industry increased by an unprecedented 935%, according to new research from <a rel="noreferrer noopener" href="https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html">cybersecurity firm Zscaler</a>.</li></ul><p>Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.</p><p>This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 06 Aug 2025 23:12:03 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/45114c25/af465703.mp3" length="57246788" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/eI2pzxKfUq5XFc9npswuF5x88r0HmluYm6yo1nJBfiM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iNTEw/MzBmMzgyMThlYWRl/YjIzOTUzYmYzYTQz/MmEwOC5wbmc.jpg"/>
      <itunes:duration>2375</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#234 - Defender Fridays: Autonomous SOC, AI for cybersecurity, and security automation with Filip Stojkovski, Staff Security Engineer at Snyk</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>234</itunes:episode>
      <podcast:episode>234</podcast:episode>
      <itunes:title>#234 - Defender Fridays: Autonomous SOC, AI for cybersecurity, and security automation with Filip Stojkovski, Staff Security Engineer at Snyk</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ddf6dd33-2460-44cc-88c9-d002674ac4b0</guid>
      <link>https://share.transistor.fm/s/bb946149</link>
      <description>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </content:encoded>
      <pubDate>Sat, 02 Aug 2025 02:19:38 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/bb946149/316cd984.mp3" length="28112873" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/6IPj3m7qUW7JIQ0EDdo7WCsP71qLriY0quAHYHdlgEw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xMjVi/MzY3NTVmNmEwZDYz/ZGIxOGUzYWRhYzg0/NDUxMi5wbmc.jpg"/>
      <itunes:duration>1757</itunes:duration>
      <itunes:summary>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</itunes:summary>
      <itunes:subtitle>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, e</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#233 - Intel Chat: SharePoint, ToolShell, UK bans payment &amp; cryptojacking</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>233</itunes:episode>
      <podcast:episode>233</podcast:episode>
      <itunes:title>#233 - Intel Chat: SharePoint, ToolShell, UK bans payment &amp; cryptojacking</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7f185f3a-11fb-4741-a753-7e95cc250dfd</guid>
      <link>https://share.transistor.fm/s/68b25495</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A critical new SharePoint vulnerability is under mass exploitation, with attackers targeting on-premises SharePoint Server deployments to exfiltrate sensitive data, including <a rel="noreferrer noopener" href="https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/">authentication tokens</a>.</li><li>And then directly related to the first story, Microsoft has now confirmed that at least three China-linked threat actors—Linen Typhoon, Violet Typhoon, and Storm-2603—were actively exploiting CVE-2025-49706 and CVE-2025-49704 a day before the company <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/3-china-nation-state-actors-sharepoint-bugs">issued patches on July 8</a>.</li><li>The UK government announced on July 22, 2025, that it plans to make ransomware payments illegal for public sector bodies and operators of <a rel="noreferrer noopener" href="https://www.securityweek.com/uks-ransomware-payment-ban-bold-strategy-or-dangerous-gamble/">critical national infrastructure (CNI)</a>.</li><li>In-browser cryptocurrency mining, often called crypto jacking, originally gained notoriety in 2017 when Coinhive introduced <a rel="noreferrer noopener" href="https://cside.dev/blog/cryptojacking-is-dead-long-live-cryptojacking">JavaScript-based mining for Monero</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A critical new SharePoint vulnerability is under mass exploitation, with attackers targeting on-premises SharePoint Server deployments to exfiltrate sensitive data, including <a rel="noreferrer noopener" href="https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/">authentication tokens</a>.</li><li>And then directly related to the first story, Microsoft has now confirmed that at least three China-linked threat actors—Linen Typhoon, Violet Typhoon, and Storm-2603—were actively exploiting CVE-2025-49706 and CVE-2025-49704 a day before the company <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/3-china-nation-state-actors-sharepoint-bugs">issued patches on July 8</a>.</li><li>The UK government announced on July 22, 2025, that it plans to make ransomware payments illegal for public sector bodies and operators of <a rel="noreferrer noopener" href="https://www.securityweek.com/uks-ransomware-payment-ban-bold-strategy-or-dangerous-gamble/">critical national infrastructure (CNI)</a>.</li><li>In-browser cryptocurrency mining, often called crypto jacking, originally gained notoriety in 2017 when Coinhive introduced <a rel="noreferrer noopener" href="https://cside.dev/blog/cryptojacking-is-dead-long-live-cryptojacking">JavaScript-based mining for Monero</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 31 Jul 2025 20:39:44 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/68b25495/d8587dfc.mp3" length="26795493" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/kLgOaGAFo98HguOedCeLBG83sNatgy66ExKDdVH7tAg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lZmNh/ZTZkYTE4ODAxMTBm/Yzk4ZmE3ZDM1NjY2/ZTVkMy5wbmc.jpg"/>
      <itunes:duration>2233</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#232 - Defender Fridays: AI scarping and internal threat with Lera Leonteva, Founder of Leo AI</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>232</itunes:episode>
      <podcast:episode>232</podcast:episode>
      <itunes:title>#232 - Defender Fridays: AI scarping and internal threat with Lera Leonteva, Founder of Leo AI</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">629cf6f0-1a44-4e8b-87dc-e1c879b7f50c</guid>
      <link>https://share.transistor.fm/s/c8046097</link>
      <description>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </content:encoded>
      <pubDate>Fri, 25 Jul 2025 19:11:16 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c8046097/4f55f58f.mp3" length="44953216" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/UiNOF-bxRFOeHSelupCGo1XlWGotO92_NnjLO5l_rAs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83YWFk/ZDFlM2JlOWQ4MjQ3/ZjIwYjhkMjQ1MDk0/ZDU2Yi5wbmc.jpg"/>
      <itunes:duration>1873</itunes:duration>
      <itunes:summary>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</itunes:summary>
      <itunes:subtitle>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, e</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#231 - Intel Chat: CISCO CVE 10/10, Matanbuchus, Cambodian takedown &amp; Overstep</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>231</itunes:episode>
      <podcast:episode>231</podcast:episode>
      <itunes:title>#231 - Intel Chat: CISCO CVE 10/10, Matanbuchus, Cambodian takedown &amp; Overstep</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">91a880b5-0a0a-49e1-805d-31de319a2d87</guid>
      <link>https://share.transistor.fm/s/90ec68b6</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Cisco has disclosed a critical vulnerability—tracked as CVE-2025-20337 with a perfect score of 10—affecting its Identity Services Engine (ISE) and the <a rel="noreferrer noopener" href="https://cvefeed.io/vuln/detail/CVE-2025-20337">ISE Passive Identity Connector</a> (ISE-PIC). </li><li>A recently updated version of the malware-as-a-service (MaaS) loader Matanbuchus is being deployed in active spear-phishing campaigns that are ultimately aimed at high-value <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/matanbuchus-loader-ransomware-infections">ransomware infections</a>.</li><li>Cambodia has announced the arrest of over 1,000 individuals this week as part of a nationwide crackdown on cybercrime networks <a rel="noreferrer noopener" href="https://www.securityweek.com/cambodia-makes-1000-arrests-in-latest-crackdown-on-cybercrime/">operating within its borders</a>.</li><li>A threat actor linked to the Abyss ransomware campaign, tracked as UNC6148 by Google’s Threat Intelligence Group (GTIG), appears to be exploiting a zero-day vulnerability in SonicWall’s end-of-life Secure Mobile Access (SMA) <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/fully-patched-sonicwall-gear-zero-day-attack">100 series devices</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Cisco has disclosed a critical vulnerability—tracked as CVE-2025-20337 with a perfect score of 10—affecting its Identity Services Engine (ISE) and the <a rel="noreferrer noopener" href="https://cvefeed.io/vuln/detail/CVE-2025-20337">ISE Passive Identity Connector</a> (ISE-PIC). </li><li>A recently updated version of the malware-as-a-service (MaaS) loader Matanbuchus is being deployed in active spear-phishing campaigns that are ultimately aimed at high-value <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/matanbuchus-loader-ransomware-infections">ransomware infections</a>.</li><li>Cambodia has announced the arrest of over 1,000 individuals this week as part of a nationwide crackdown on cybercrime networks <a rel="noreferrer noopener" href="https://www.securityweek.com/cambodia-makes-1000-arrests-in-latest-crackdown-on-cybercrime/">operating within its borders</a>.</li><li>A threat actor linked to the Abyss ransomware campaign, tracked as UNC6148 by Google’s Threat Intelligence Group (GTIG), appears to be exploiting a zero-day vulnerability in SonicWall’s end-of-life Secure Mobile Access (SMA) <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/fully-patched-sonicwall-gear-zero-day-attack">100 series devices</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 22 Jul 2025 18:21:35 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/90ec68b6/3955e1b1.mp3" length="40727023" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/xPdFCHVS703kkeNcOkZrjaT99Y2jW3LfQ5XgYRz0Lq4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjZk/MjRjZGJkZDczMDJi/NjA2ZjJkYzMzMDdi/ZTNlYi5wbmc.jpg"/>
      <itunes:duration>1697</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#230 - Defender Fridays: Cyberphysical protection for high value assets with Lennart Koopman, Founder of</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>230</itunes:episode>
      <podcast:episode>230</podcast:episode>
      <itunes:title>#230 - Defender Fridays: Cyberphysical protection for high value assets with Lennart Koopman, Founder of</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">24bc4872-2c40-4948-9b09-d27cd519d948</guid>
      <link>https://share.transistor.fm/s/47099448</link>
      <description>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </content:encoded>
      <pubDate>Fri, 18 Jul 2025 18:13:22 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/47099448/70048d75.mp3" length="22278148" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/I2s7BW9KQeOmaYnJsCt0nCSL-PcX24yanq9S64VpCOI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84MmUy/NWIxNzczM2RkOWVk/NDgyMjk1MWY5ODI4/ZGFiOC5wbmc.jpg"/>
      <itunes:duration>1857</itunes:duration>
      <itunes:summary>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</itunes:summary>
      <itunes:subtitle>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, e</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#229 - Intel Chat: IntelBroker, Hunters International, Brazilian insider, Ruckus Networks &amp; Patch Tuesday</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>229</itunes:episode>
      <podcast:episode>229</podcast:episode>
      <itunes:title>#229 - Intel Chat: IntelBroker, Hunters International, Brazilian insider, Ruckus Networks &amp; Patch Tuesday</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b4d752c0-c840-4f4a-a3eb-0e5419d15041</guid>
      <link>https://share.transistor.fm/s/0a306a46</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Kai West, a 25-year-old British national, has been indicted by the U.S. Attorney’s Office for the Southern District of New York for allegedly operating under the online alias “<a rel="noreferrer noopener" href="https://www.justice.gov/usao-sdny/pr/serial-hacker-intelbroker-charged-causing-25-million-damages-victims">IntelBroker</a>.” </li><li>Hunters International, a ransomware group that surfaced in 2023 and is believed to have originated from the now-defunct Hive ransomware operation, has announced it is <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/hunters-international-raas-group-closes-doors">ceasing all activity</a>.</li><li>Hackers in Brazil managed to steal nearly $140 million USD from six banks by exploiting insider access at a financial technology firm called C&amp;M, which provides connectivity services to financial institutions and the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/employee-gets-920-for-credentials-used-in-140-million-bank-heist/">Brazilian Central Bank</a>. </li><li>Several critical vulnerabilities in Ruckus Networks' management products remain unpatched, leaving large-scale WiFi environments at risk of <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/ruckus-networks-leaves-severe-flaws-unpatched-in-management-devices/">complete compromise</a>.</li><li>Microsoft has released security updates addressing 130 vulnerabilities across its product line as part of its July 2025 <a rel="noreferrer noopener" href="https://www.securityweek.com/microsoft-patches-130-vulnerabilities-for-july-2025-patch-tuesday/">Patch Tuesday</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Kai West, a 25-year-old British national, has been indicted by the U.S. Attorney’s Office for the Southern District of New York for allegedly operating under the online alias “<a rel="noreferrer noopener" href="https://www.justice.gov/usao-sdny/pr/serial-hacker-intelbroker-charged-causing-25-million-damages-victims">IntelBroker</a>.” </li><li>Hunters International, a ransomware group that surfaced in 2023 and is believed to have originated from the now-defunct Hive ransomware operation, has announced it is <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/hunters-international-raas-group-closes-doors">ceasing all activity</a>.</li><li>Hackers in Brazil managed to steal nearly $140 million USD from six banks by exploiting insider access at a financial technology firm called C&amp;M, which provides connectivity services to financial institutions and the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/employee-gets-920-for-credentials-used-in-140-million-bank-heist/">Brazilian Central Bank</a>. </li><li>Several critical vulnerabilities in Ruckus Networks' management products remain unpatched, leaving large-scale WiFi environments at risk of <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/ruckus-networks-leaves-severe-flaws-unpatched-in-management-devices/">complete compromise</a>.</li><li>Microsoft has released security updates addressing 130 vulnerabilities across its product line as part of its July 2025 <a rel="noreferrer noopener" href="https://www.securityweek.com/microsoft-patches-130-vulnerabilities-for-july-2025-patch-tuesday/">Patch Tuesday</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 17 Jul 2025 21:54:03 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0a306a46/2300ba06.mp3" length="25589327" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/cUl15YTgVkRg-t_-3EIwXDx0QUJKDpn4pl00FWVL2v0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lYzdm/ODEwMzhkYjliM2E5/Yjk4MzgwZjQ1YzUz/ODZkYy5wbmc.jpg"/>
      <itunes:duration>2133</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#228 - Defender Fridays: Building detection and response processes that scale with Ryan Cox, Senior Security Engineer at Revinate</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>228</itunes:episode>
      <podcast:episode>228</podcast:episode>
      <itunes:title>#228 - Defender Fridays: Building detection and response processes that scale with Ryan Cox, Senior Security Engineer at Revinate</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">82db3455-007e-4360-b84d-f1fc1d54c1d6</guid>
      <link>https://share.transistor.fm/s/ce297407</link>
      <description>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 11 Jul 2025 18:11:34 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ce297407/7251ce38.mp3" length="41565274" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/kUS6Qfh7K3ZpXT7QZyw2GlaUSX-FabSeXftXteNjV3U/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84MWJj/YjFlOGVhNWRmOWNk/NmMwZjY5OTQ2N2E4/MTk1Yy5wbmc.jpg"/>
      <itunes:duration>1732</itunes:duration>
      <itunes:summary>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</itunes:summary>
      <itunes:subtitle>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, e</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#227 - Intel Chat: Sudo, browser vulns, Medusa &amp; Cloudflare blocks AI</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>227</itunes:episode>
      <podcast:episode>227</podcast:episode>
      <itunes:title>#227 - Intel Chat: Sudo, browser vulns, Medusa &amp; Cloudflare blocks AI</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">be16a088-e416-4d5f-843c-c1e4823ce126</guid>
      <link>https://share.transistor.fm/s/4b781578</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Two critical local privilege escalation vulnerabilities in the Sudo utility—CVE-2025-32462 and CVE-2025-32463—have been disclosed by the <a rel="noreferrer noopener" href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot">Stratascale Cyber Research Unit</a>.</li><li>Google Chrome and Mozilla Firefox are both facing distinct, serious threats this week—Chrome from a zero-day vulnerability under active exploitation and Firefox from a campaign of malicious browser extensions targeting <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/browsers-targeted-chrome-zero-day-malicious-firefox-extensions">cryptocurrency users</a>.</li><li>The Medusa ransomware group, active since late 2021, has maintained a consistent and aggressive operational <a rel="noreferrer noopener" href="https://www.bridewell.com/insights/blogs/detail/who-are-medusa-ransomware-group">tempo into 2025</a>. </li><li>Cloudflare has rolled out a significant change to how websites handle AI crawlers, positioning itself as the first internet infrastructure provider to block <a rel="noreferrer noopener" href="https://www.securityweek.com/cloudflare-puts-a-default-block-on-ai-web-scraping/">AI-driven scraping by default</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Two critical local privilege escalation vulnerabilities in the Sudo utility—CVE-2025-32462 and CVE-2025-32463—have been disclosed by the <a rel="noreferrer noopener" href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot">Stratascale Cyber Research Unit</a>.</li><li>Google Chrome and Mozilla Firefox are both facing distinct, serious threats this week—Chrome from a zero-day vulnerability under active exploitation and Firefox from a campaign of malicious browser extensions targeting <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/browsers-targeted-chrome-zero-day-malicious-firefox-extensions">cryptocurrency users</a>.</li><li>The Medusa ransomware group, active since late 2021, has maintained a consistent and aggressive operational <a rel="noreferrer noopener" href="https://www.bridewell.com/insights/blogs/detail/who-are-medusa-ransomware-group">tempo into 2025</a>. </li><li>Cloudflare has rolled out a significant change to how websites handle AI crawlers, positioning itself as the first internet infrastructure provider to block <a rel="noreferrer noopener" href="https://www.securityweek.com/cloudflare-puts-a-default-block-on-ai-web-scraping/">AI-driven scraping by default</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Jul 2025 16:20:35 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4b781578/c5fc39be.mp3" length="45695977" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/31Uxiijlue9_UEDYhaWqQxsnHcgs1mA6rPNdGf1WHLk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jNmRk/YjU0ZDM2ZjliMTVk/ZTBjM2QxMWVjM2M2/ZGQ4ZS5wbmc.jpg"/>
      <itunes:duration>1904</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#226 - Intel Chat: Thai takedown, Salt Typhoon, Iran &amp; BlueNoroff</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>226</itunes:episode>
      <podcast:episode>226</podcast:episode>
      <itunes:title>#226 - Intel Chat: Thai takedown, Salt Typhoon, Iran &amp; BlueNoroff</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8859933e-4f98-482a-ab66-22653fb4d16e</guid>
      <link>https://share.transistor.fm/s/43247408</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Thai police conducted a major raid on the Antai Holiday Hotel in central Pattaya late on Monday night, June 16th, uncovering a joint operation involving both ransomware distribution and <a rel="noreferrer noopener" href="https://www.bitdefender.com/en-us/blog/hotforsecurity/ransomware-gang-busted-in-thailand-hotel-raid">illegal gambling.</a></li><li>Canada’s national cybersecurity agency has confirmed that a Chinese state-sponsored group known as Salt Typhoon successfully targeted a Canadian telecommunications company earlier this year, exploiting a <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/canada-targeted-salt-typhoon-telecom">Cisco vulnerability</a>.</li><li>The Department of Homeland Security (DHS) has issued a National Terrorism Advisory System bulletin warning of an elevated risk of cyberattacks and potentially violent extremism in response to escalating geopolitical tensions between the <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/dhs-cyberattacks-iran-conflict">U.S. and Iran</a>.</li><li>Security researchers have confirmed that recent social engineering campaigns exploiting Zoom are the work of BlueNoroff, a North Korean state-sponsored APT group known for targeting financial entities, particularly in the <a rel="noreferrer noopener" href="https://www.securityweek.com/north-korean-hackers-take-over-victims-systems-using-zoom-meeting/">cryptocurrency and online gambling sectors</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Thai police conducted a major raid on the Antai Holiday Hotel in central Pattaya late on Monday night, June 16th, uncovering a joint operation involving both ransomware distribution and <a rel="noreferrer noopener" href="https://www.bitdefender.com/en-us/blog/hotforsecurity/ransomware-gang-busted-in-thailand-hotel-raid">illegal gambling.</a></li><li>Canada’s national cybersecurity agency has confirmed that a Chinese state-sponsored group known as Salt Typhoon successfully targeted a Canadian telecommunications company earlier this year, exploiting a <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/canada-targeted-salt-typhoon-telecom">Cisco vulnerability</a>.</li><li>The Department of Homeland Security (DHS) has issued a National Terrorism Advisory System bulletin warning of an elevated risk of cyberattacks and potentially violent extremism in response to escalating geopolitical tensions between the <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/dhs-cyberattacks-iran-conflict">U.S. and Iran</a>.</li><li>Security researchers have confirmed that recent social engineering campaigns exploiting Zoom are the work of BlueNoroff, a North Korean state-sponsored APT group known for targeting financial entities, particularly in the <a rel="noreferrer noopener" href="https://www.securityweek.com/north-korean-hackers-take-over-victims-systems-using-zoom-meeting/">cryptocurrency and online gambling sectors</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 01 Jul 2025 15:47:44 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/43247408/104e892e.mp3" length="19702919" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/TAubzRVfckdinCUak1GdlSctyMqrV9buZMp9EZ0O_Wg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZjM0/OWQ1OGNjYWEzMmI1/NzdlZmQ0YzM3NGQ2/NDJkNi5wbmc.jpg"/>
      <itunes:duration>1642</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#225 - Defender Fridays: EDR, DFIR &amp; endpoint triage with Brian Carrier, CEO of Sleauth Kit Labs</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>225</itunes:episode>
      <podcast:episode>225</podcast:episode>
      <itunes:title>#225 - Defender Fridays: EDR, DFIR &amp; endpoint triage with Brian Carrier, CEO of Sleauth Kit Labs</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fc8ced15-fa17-4cd7-be7f-81d287dde0c3</guid>
      <link>https://share.transistor.fm/s/a740b049</link>
      <description>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 27 Jun 2025 17:26:45 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a740b049/7d6a783d.mp3" length="22321704" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ph_7r33S5sPJalNqD3SzKQ-GMW_VkWBzQ01Yr1fyZ8g/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mMjkw/MTFmM2U1YWQ1YjI3/ZWUyNGEzYTVlOWFl/MDk2NS5wbmc.jpg"/>
      <itunes:duration>1860</itunes:duration>
      <itunes:summary>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</itunes:summary>
      <itunes:subtitle>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, e</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#224 - Intel Chat: OtterCookie, Flodrix, Water Curse &amp; Scattered Spider</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>224</itunes:episode>
      <podcast:episode>224</podcast:episode>
      <itunes:title>#224 - Intel Chat: OtterCookie, Flodrix, Water Curse &amp; Scattered Spider</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">81952807-77ab-4c62-a4ba-90bb6f3780e4</guid>
      <link>https://share.transistor.fm/s/88a58945</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A new malware strain known as OtterCookie, developed by the North Korean APT group Lazarus, has been dissected in a detailed technical analysis by offensive security expert <a rel="noreferrer noopener" href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/?utm_source=reddit">Mauro Eldritch</a>. </li><li>Attackers are currently exploiting a critical vulnerability in the Langflow platform — an open-source Python-based web app used to build AI workflows and agents — to deliver a new botnet called <a rel="noreferrer noopener" href="https://www.darkreading.com/vulnerabilities-threats/hackers-exploit-langflow-flaw-flodrix-botnet">Flodrix</a>.</li><li>A new campaign from an emerging threat group named Water Curse is targeting the software supply chain by leveraging GitHub repositories that masquerade as <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/water-curse-targets-cybersecurity-pros-github-repos">legitimate security tools</a>. </li><li>The threat actor known as Scattered Spider, also tracked as UNC3944 by Google and Mandiant, has apparently shifted its operational focus from the retail sector to the US insurance industry, according to a new alert from <a rel="noreferrer noopener" href="https://www.securityweek.com/us-insurance-industry-warned-of-scattered-spider-attacks/">Google’s Threat Intelligence Group</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A new malware strain known as OtterCookie, developed by the North Korean APT group Lazarus, has been dissected in a detailed technical analysis by offensive security expert <a rel="noreferrer noopener" href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/?utm_source=reddit">Mauro Eldritch</a>. </li><li>Attackers are currently exploiting a critical vulnerability in the Langflow platform — an open-source Python-based web app used to build AI workflows and agents — to deliver a new botnet called <a rel="noreferrer noopener" href="https://www.darkreading.com/vulnerabilities-threats/hackers-exploit-langflow-flaw-flodrix-botnet">Flodrix</a>.</li><li>A new campaign from an emerging threat group named Water Curse is targeting the software supply chain by leveraging GitHub repositories that masquerade as <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/water-curse-targets-cybersecurity-pros-github-repos">legitimate security tools</a>. </li><li>The threat actor known as Scattered Spider, also tracked as UNC3944 by Google and Mandiant, has apparently shifted its operational focus from the retail sector to the US insurance industry, according to a new alert from <a rel="noreferrer noopener" href="https://www.securityweek.com/us-insurance-industry-warned-of-scattered-spider-attacks/">Google’s Threat Intelligence Group</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 24 Jun 2025 19:27:46 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/88a58945/bf1892c7.mp3" length="22857687" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/klTPjeskuP4bvRsp6ZwUsr8t8IScfVTelfY7WPEqrpM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lNTM4/MmQ1Yzc5Mzc2YjIz/MTVlY2MxN2VlY2Zh/MTljZi5wbmc.jpg"/>
      <itunes:duration>1905</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#223 - Defender Fridays: Maintaining the human touch in security operations with Hayden Covington, SOC SecOps Lead at BHIS</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>223</itunes:episode>
      <podcast:episode>223</podcast:episode>
      <itunes:title>#223 - Defender Fridays: Maintaining the human touch in security operations with Hayden Covington, SOC SecOps Lead at BHIS</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">492314de-ce29-4ecf-bea3-6d385f79adac</guid>
      <link>https://share.transistor.fm/s/3f37c8b1</link>
      <description>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 20 Jun 2025 16:28:32 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3f37c8b1/8062a7f0.mp3" length="22174112" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/NZfjGVhzo7VpQ0m_oKd48bz_TPzKA8r3-D-jqn1ozeI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kM2Fm/OWYzMGNlYjZlM2Jh/MGVjYmJkYTIxNWMy/ZDY4Yi5wbmc.jpg"/>
      <itunes:duration>1848</itunes:duration>
      <itunes:summary>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</itunes:summary>
      <itunes:subtitle>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, e</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#222 - Intel Chat: PurpleHaze, KEV++, ChatGPT &amp; Mirai botnet</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>222</itunes:episode>
      <podcast:episode>222</podcast:episode>
      <itunes:title>#222 - Intel Chat: PurpleHaze, KEV++, ChatGPT &amp; Mirai botnet</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3147fccf-a66d-48b0-a6ce-958f87b7f2a4</guid>
      <link>https://share.transistor.fm/s/5e77c4eb</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Over an eight-month period beginning in July of last year, China-backed threat actors carried out a coordinated campaign that included attempts to breach <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/china-hackers-target-sentinelone-purplehaze-attack">cybersecurity vendor SentinelOne</a>.</li><li>CISA has added two newly confirmed exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of <a rel="noreferrer noopener" href="https://thehackernews.com/2025/06/cisa-adds-erlang-ssh-and-roundcube.html">active abuse in the wild</a>.</li><li>OpenAI has banned ChatGPT accounts linked to state-sponsored threat actors, including groups affiliated with governments in <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/openai-bans-chatgpt-accounts-nation-state-threat-actors">China, Russia, North Korea, Iran, and others</a>.</li><li>A critical vulnerability in Wazuh Server, CVE-2025-24016 (CVSS 9.9), is being actively exploited by threat actors to deliver multiple Mirai botnet variants for <a rel="noreferrer noopener" href="https://thehackernews.com/2025/06/botnet-wazuh-server-vulnerability.html">distributed denial-of-service (DDoS) operations</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Over an eight-month period beginning in July of last year, China-backed threat actors carried out a coordinated campaign that included attempts to breach <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/china-hackers-target-sentinelone-purplehaze-attack">cybersecurity vendor SentinelOne</a>.</li><li>CISA has added two newly confirmed exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of <a rel="noreferrer noopener" href="https://thehackernews.com/2025/06/cisa-adds-erlang-ssh-and-roundcube.html">active abuse in the wild</a>.</li><li>OpenAI has banned ChatGPT accounts linked to state-sponsored threat actors, including groups affiliated with governments in <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/openai-bans-chatgpt-accounts-nation-state-threat-actors">China, Russia, North Korea, Iran, and others</a>.</li><li>A critical vulnerability in Wazuh Server, CVE-2025-24016 (CVSS 9.9), is being actively exploited by threat actors to deliver multiple Mirai botnet variants for <a rel="noreferrer noopener" href="https://thehackernews.com/2025/06/botnet-wazuh-server-vulnerability.html">distributed denial-of-service (DDoS) operations</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 18 Jun 2025 17:28:42 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5e77c4eb/20442ce1.mp3" length="38560769" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/MYy59lmgb8nXZnW7C-MwyGtJNCpMUxMSzxc816rK_KU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83NDI1/NTI1OTRmMTU1N2Iz/MzhjMzgzOGQxY2M5/N2U4YS5wbmc.jpg"/>
      <itunes:duration>1607</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#221 - AI and Automation for security operations with Filip Stojkovski, Staff Security Engineer at Snyk</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>220</itunes:episode>
      <podcast:episode>220</podcast:episode>
      <itunes:title>#221 - AI and Automation for security operations with Filip Stojkovski, Staff Security Engineer at Snyk</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b7ae29a7-5bb3-46b4-acc2-d154aabc7531</guid>
      <link>https://share.transistor.fm/s/63b4b244</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Filip Stojkovski, Staff Security Engineer at <a rel="noreferrer noopener" href="https://snyk.io/">Snyk</a>.</p><p>Filip is a cybersecurity professional with over 15 years of experience. He began his career as a SOC analyst and now leads SecOps engineering at Snyk. Filip also advises organizations on SOAR, AI for SOC, and threat intelligence strategies. He holds multiple SANS certifications, including GSTRT, GCTI, and GCFA, and was recognized as “Threat Seeker of the Year.” He is the creator of the LEAD Threat Intelligence Framework and the Security Automation Development Life Cycle. </p><p>Filip regularly shares his expertise through industry talks and on his blog: <a rel="noreferrer noopener" href="https://www.cybersec-automation.com/">Cyber Security Automation and Orchestration</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Filip Stojkovski, Staff Security Engineer at <a rel="noreferrer noopener" href="https://snyk.io/">Snyk</a>.</p><p>Filip is a cybersecurity professional with over 15 years of experience. He began his career as a SOC analyst and now leads SecOps engineering at Snyk. Filip also advises organizations on SOAR, AI for SOC, and threat intelligence strategies. He holds multiple SANS certifications, including GSTRT, GCTI, and GCFA, and was recognized as “Threat Seeker of the Year.” He is the creator of the LEAD Threat Intelligence Framework and the Security Automation Development Life Cycle. </p><p>Filip regularly shares his expertise through industry talks and on his blog: <a rel="noreferrer noopener" href="https://www.cybersec-automation.com/">Cyber Security Automation and Orchestration</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 17 Jun 2025 14:00:24 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/63b4b244/a95a45d4.mp3" length="23533591" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1961</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders Podcast we speak with Filip Stojkovski, Staff Security Engineer at Snyk.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders Podcast we speak with Filip Stojkovski, Staff Security Engineer at Snyk.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#220 - Defender Fridays: AI on the edge with David (DWIZZLE) Weston, Corporate Vice President, Enterprise and OS Security at Microsoft</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>220</itunes:episode>
      <podcast:episode>220</podcast:episode>
      <itunes:title>#220 - Defender Fridays: AI on the edge with David (DWIZZLE) Weston, Corporate Vice President, Enterprise and OS Security at Microsoft</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">cada5398-eb2b-41e9-888f-c8072e134415</guid>
      <link>https://share.transistor.fm/s/88fa6087</link>
      <description>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p><p>Each week, we bring you a different expert guest who will share their invaluable insights on topics ranging from threat hunting and incident response to security operations and detection engineering. What makes these sessions special is their informal and interactive nature, allowing for an engaging dialogue between our guests, hosts, and the audience.</p><p>You can sign up to join us for the live sessions at <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">limacharlie.io/defender-fridays</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 13 Jun 2025 17:25:21 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/88fa6087/01d3b936.mp3" length="22539328" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/8p5x-Nx3mzPulT2zuwhyYXIMCTriTfYH_LTUa2jeiSU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MDdi/MWJmZGM4NDRlYjk0/MTMyZTBmMWI0OWRm/OGJjOC5wbmc.jpg"/>
      <itunes:duration>1879</itunes:duration>
      <itunes:summary>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry.</itunes:summary>
      <itunes:subtitle>Join us every Friday as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#219 - Intel Chat: MSFT-Crowdstrike, GangExposed, Fastlane &amp; HashiCorp Nomad servers</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>219</itunes:episode>
      <podcast:episode>219</podcast:episode>
      <itunes:title>#219 - Intel Chat: MSFT-Crowdstrike, GangExposed, Fastlane &amp; HashiCorp Nomad servers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d99a3b46-4d99-49f1-b960-6f31c759a5b9</guid>
      <link>https://share.transistor.fm/s/c23c32e3</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Microsoft and CrowdStrike have announced a strategic alliance aimed at deconflicting threat actor names <a rel="noreferrer noopener" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-and-microsoft-unite-to-deconflict-cyber-threat-attribution/">across their platforms</a>.</li><li>A new, anonymous figure calling himself GangExposed has surfaced in the cyber threat landscape, publishing a significant set of internal documents that reveal the identities of top leadership within the Conti and Trickbot <a rel="noreferrer noopener" href="https://www.theregister.com/2025/05/31/gangexposed_coni_ransomware_leaks/">ransomware crews</a>.</li><li>A new supply chain attack targeting the Ruby ecosystem has emerged, leveraging impersonated packages to exfiltrate sensitive data from <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/attackers-impersonate-ruby-packages-telegram-data">Telegram communications</a>. </li><li>Researchers at Wiz have published what appears to be the first confirmed case of active exploitation of misconfigured HashiCorp Nomad servers in the wild, used by attackers to mine <a rel="noreferrer noopener" href="https://www.securityweek.com/cryptojackers-caught-mining-monero-via-exposed-devops-infrastructure/">Monero cryptocurrency</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Microsoft and CrowdStrike have announced a strategic alliance aimed at deconflicting threat actor names <a rel="noreferrer noopener" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-and-microsoft-unite-to-deconflict-cyber-threat-attribution/">across their platforms</a>.</li><li>A new, anonymous figure calling himself GangExposed has surfaced in the cyber threat landscape, publishing a significant set of internal documents that reveal the identities of top leadership within the Conti and Trickbot <a rel="noreferrer noopener" href="https://www.theregister.com/2025/05/31/gangexposed_coni_ransomware_leaks/">ransomware crews</a>.</li><li>A new supply chain attack targeting the Ruby ecosystem has emerged, leveraging impersonated packages to exfiltrate sensitive data from <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/attackers-impersonate-ruby-packages-telegram-data">Telegram communications</a>. </li><li>Researchers at Wiz have published what appears to be the first confirmed case of active exploitation of misconfigured HashiCorp Nomad servers in the wild, used by attackers to mine <a rel="noreferrer noopener" href="https://www.securityweek.com/cryptojackers-caught-mining-monero-via-exposed-devops-infrastructure/">Monero cryptocurrency</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 11 Jun 2025 13:00:17 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c23c32e3/06844680.mp3" length="20818281" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/fMf8TrBufd9Qq0CvkuMS1OaqXI5NtuJXz8bwi0Kk2_g/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYTcw/YTU0MzRmZjI0MDkw/ZTMwNzJkY2Q5ZDAy/OTkzZi5wbmc.jpg"/>
      <itunes:duration>1735</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#218 - Coinbase + Cetus, Hazy Hawk, BadSuccesssor &amp; DCIS takedown</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>218</itunes:episode>
      <podcast:episode>218</podcast:episode>
      <itunes:title>#218 - Coinbase + Cetus, Hazy Hawk, BadSuccesssor &amp; DCIS takedown</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fee971f9-4493-42b2-b931-65168c6ba173</guid>
      <link>https://share.transistor.fm/s/09ed8ed8</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Two significant crypto security breaches occurred in close succession this month, affecting both decentralized and centralized platforms. On May 22, Cetus—a decentralized exchange built on the Sui Network—was exploited via a vulnerability in its <a rel="noreferrer noopener" href="https://bitcoinist.com/crypto-wallet-best-wallet-coinbase-cetus-hack/">automated market maker (AMM)</a>. Meanwhile, Coinbase confirmed what it called a “targeted insider threat operation” that compromised data from less than <a rel="noreferrer noopener" href="https://www.coinbase.com/en-ca/blog/protecting-our-customers-standing-up-to-extortionists">1% of its active monthly users</a>.</li><li>A threat group identified as “Hazy Hawk” has been systematically hijacking cloud-based DNS resources tied to well-known organizations, including the US Centers for Disease Control and Prevention (CDC), <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/hazy-hawk-cybercrime-gang-cloud-resources">since December 2023</a>.</li><li> A newly disclosed vulnerability in Windows Server 2025, dubbed BadSuccessor, has raised major concerns among enterprise administrators managing <a rel="noreferrer noopener" href="https://www.forbes.com/sites/daveywinder/2025/05/21/new-windows-server-2025-attack-compromises-any-active-directory-user/">Active Directory environments</a>.</li><li>Federal and international law enforcement, alongside a significant number of private-sector partners, have successfully dismantled the Danabot botnet in a multiyear operation aimed at neutralizing one of the more advanced malware-as-a-service (MaaS) <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/danabot-takedown-russian-cybercrime">platforms tied to Russian cybercriminal activity</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Two significant crypto security breaches occurred in close succession this month, affecting both decentralized and centralized platforms. On May 22, Cetus—a decentralized exchange built on the Sui Network—was exploited via a vulnerability in its <a rel="noreferrer noopener" href="https://bitcoinist.com/crypto-wallet-best-wallet-coinbase-cetus-hack/">automated market maker (AMM)</a>. Meanwhile, Coinbase confirmed what it called a “targeted insider threat operation” that compromised data from less than <a rel="noreferrer noopener" href="https://www.coinbase.com/en-ca/blog/protecting-our-customers-standing-up-to-extortionists">1% of its active monthly users</a>.</li><li>A threat group identified as “Hazy Hawk” has been systematically hijacking cloud-based DNS resources tied to well-known organizations, including the US Centers for Disease Control and Prevention (CDC), <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/hazy-hawk-cybercrime-gang-cloud-resources">since December 2023</a>.</li><li> A newly disclosed vulnerability in Windows Server 2025, dubbed BadSuccessor, has raised major concerns among enterprise administrators managing <a rel="noreferrer noopener" href="https://www.forbes.com/sites/daveywinder/2025/05/21/new-windows-server-2025-attack-compromises-any-active-directory-user/">Active Directory environments</a>.</li><li>Federal and international law enforcement, alongside a significant number of private-sector partners, have successfully dismantled the Danabot botnet in a multiyear operation aimed at neutralizing one of the more advanced malware-as-a-service (MaaS) <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/danabot-takedown-russian-cybercrime">platforms tied to Russian cybercriminal activity</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 03 Jun 2025 16:56:11 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/09ed8ed8/759f38c5.mp3" length="23622540" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/gYcSJlbKbUMjShFLb7TnrUcTLg2_V9N4JFcxejMAGCE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MmFh/YTE5Njc3YjM1MzI2/ZGMwZWEzYjU4MDM0/Y2I0YS5wbmc.jpg"/>
      <itunes:duration>1969</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#217 - Navigating compliance and risk with Joshua Hoffman, CRO at ControlCase</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>217</itunes:episode>
      <podcast:episode>217</podcast:episode>
      <itunes:title>#217 - Navigating compliance and risk with Joshua Hoffman, CRO at ControlCase</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5598138a-acad-4617-96c3-08b8c725ad01</guid>
      <link>https://share.transistor.fm/s/7511c786</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Joshua Hoffman, CRO at <a rel="noreferrer noopener" href="https://www.controlcase.com/">ControlCase</a>.</p><p>Josh brings a unique perspective to the cybersecurity conversation, shaped by years of building revenue strategies in fast-changing, highly regulated environments. At ControlCase, he's helping organizations navigate the growing complexity of compliance standards like CMMC, SOC, and PCI DSS, while driving adoption of tech-forward approaches to risk management. His background spans advisory roles and leadership positions across the cybersecurity ecosystem, making him a key voice on how businesses can move beyond checkbox compliance to a more strategic, scalable security posture.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Joshua Hoffman, CRO at <a rel="noreferrer noopener" href="https://www.controlcase.com/">ControlCase</a>.</p><p>Josh brings a unique perspective to the cybersecurity conversation, shaped by years of building revenue strategies in fast-changing, highly regulated environments. At ControlCase, he's helping organizations navigate the growing complexity of compliance standards like CMMC, SOC, and PCI DSS, while driving adoption of tech-forward approaches to risk management. His background spans advisory roles and leadership positions across the cybersecurity ecosystem, making him a key voice on how businesses can move beyond checkbox compliance to a more strategic, scalable security posture.</p>]]>
      </content:encoded>
      <pubDate>Tue, 27 May 2025 15:04:50 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7511c786/886cf9c9.mp3" length="23974590" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/yoSKRbCRCYEb7yBGv8lBVGg7sZkns1jgQH-lSXupKSE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xOTY3/OGNjOWU1YjQ0NmJk/ZmIxZWIzYTNiM2Q5/ZjdmMy5wbmc.jpg"/>
      <itunes:duration>1998</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders Podcast we speak with Joshua Hoffman, CRO at ControlCase.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders Podcast we speak with Joshua Hoffman, CRO at ControlCase.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#216 - Intel Chat: Scattered Spider, TA406, Oriental Gudgeon &amp; Apple patches</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>216</itunes:episode>
      <podcast:episode>216</podcast:episode>
      <itunes:title>#216 - Intel Chat: Scattered Spider, TA406, Oriental Gudgeon &amp; Apple patches</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8baffdc4-1a01-4d2c-8641-13dc7312347c</guid>
      <link>https://share.transistor.fm/s/2b811d02</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A report from Google on how to defend against UNC3944, better known as <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805">Scattered Spider</a>.</li><li>North Korea-backed threat actor TA406 has shifted its focus to targeting Ukrainian government agencies, according to new research <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/north-koreas-ta406-targets-ukraine">from Proofpoint</a>.</li><li>Since October 2024, urlscan.io has been tracking a phishing campaign known as Oriental Gudgeon, which is targeting over 40 Japanese commercial entities—mostly in the <a rel="noreferrer noopener" href="https://urlscan.io/blog/2025/05/06/oriental-gudgeon/">financial services sector</a>.</li><li>Apple has released a substantial batch of security updates across its software ecosystem, including iOS 18.5, iPadOS, and the <a rel="noreferrer noopener" href="https://www.securityweek.com/apple-patches-major-security-flaws-in-ios-macos-platforms/">latest versions of macOS</a>. </li></ul><p>And the article Matt mentions about CISA shifting their alert distribution strategy: <a rel="noreferrer noopener" href="https://www.infosecurity-magazine.com/news/cisa-alert-strategy-email-social/">https://www.infosecurity-magazine.com/news/cisa-alert-strategy-email-social/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>A report from Google on how to defend against UNC3944, better known as <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805">Scattered Spider</a>.</li><li>North Korea-backed threat actor TA406 has shifted its focus to targeting Ukrainian government agencies, according to new research <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/north-koreas-ta406-targets-ukraine">from Proofpoint</a>.</li><li>Since October 2024, urlscan.io has been tracking a phishing campaign known as Oriental Gudgeon, which is targeting over 40 Japanese commercial entities—mostly in the <a rel="noreferrer noopener" href="https://urlscan.io/blog/2025/05/06/oriental-gudgeon/">financial services sector</a>.</li><li>Apple has released a substantial batch of security updates across its software ecosystem, including iOS 18.5, iPadOS, and the <a rel="noreferrer noopener" href="https://www.securityweek.com/apple-patches-major-security-flaws-in-ios-macos-platforms/">latest versions of macOS</a>. </li></ul><p>And the article Matt mentions about CISA shifting their alert distribution strategy: <a rel="noreferrer noopener" href="https://www.infosecurity-magazine.com/news/cisa-alert-strategy-email-social/">https://www.infosecurity-magazine.com/news/cisa-alert-strategy-email-social/</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 21 May 2025 13:17:14 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2b811d02/481f4886.mp3" length="50255234" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/OvFprfRoCEvCZxTTiMJ6vNxIHabpK7DeEJD9syqmFXM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82ODhi/Nzc2YjI5ZmVkOTY4/NTBmYjJmZjNjODE1/NTQ3NC5wbmc.jpg"/>
      <itunes:duration>2094</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#215 - Inside cyber warfare, intelligence, and investment with Hank Thomas, Managing Partner and Founder at Strategic Cyber Ventures</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>215</itunes:episode>
      <podcast:episode>215</podcast:episode>
      <itunes:title>#215 - Inside cyber warfare, intelligence, and investment with Hank Thomas, Managing Partner and Founder at Strategic Cyber Ventures</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">231bbaf1-5dc2-4719-8ef1-6192ceba999e</guid>
      <link>https://share.transistor.fm/s/3cde19c2</link>
      <description>
        <![CDATA[<p>On episode 215 of the Cybersecurity Defenders Podcast, Hank Thomas, Managing Partner and Founder at <a rel="noreferrer noopener" href="https://www.scvgroup.com/">Strategic Cyber Ventures</a>, shares his journey from Army intelligence officer to cyber-focused venture capitalist. But the most pressing part of the conversation is his call for a structural overhaul in how the US military handles cyber operations.</p><p>Thomas argues that cyber is no longer a niche; it is the starting point for modern conflict. Yet cyber capability remains fragmented across service branches, leading to inefficiencies, talent drain, and even internal competition for resources. He makes the case for a separate, fully resourced cyber force, similar to the creation of the Air Force and Space Force, to truly secure the digital domain.</p><p>He also shares concerns about government overreliance on contractors in critical cyber roles, the need for agile decision-making authority during cyber operations, and why AI must be deployed responsibly to defend a fractured critical infrastructure landscape.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On episode 215 of the Cybersecurity Defenders Podcast, Hank Thomas, Managing Partner and Founder at <a rel="noreferrer noopener" href="https://www.scvgroup.com/">Strategic Cyber Ventures</a>, shares his journey from Army intelligence officer to cyber-focused venture capitalist. But the most pressing part of the conversation is his call for a structural overhaul in how the US military handles cyber operations.</p><p>Thomas argues that cyber is no longer a niche; it is the starting point for modern conflict. Yet cyber capability remains fragmented across service branches, leading to inefficiencies, talent drain, and even internal competition for resources. He makes the case for a separate, fully resourced cyber force, similar to the creation of the Air Force and Space Force, to truly secure the digital domain.</p><p>He also shares concerns about government overreliance on contractors in critical cyber roles, the need for agile decision-making authority during cyber operations, and why AI must be deployed responsibly to defend a fractured critical infrastructure landscape.</p>]]>
      </content:encoded>
      <pubDate>Thu, 15 May 2025 17:47:16 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3cde19c2/45b76167.mp3" length="22530234" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1878</itunes:duration>
      <itunes:summary>On episode 215 of the Cybersecurity Defenders Podcast, Hank Thomas, Managing Partner and Founder at Strategic Cyber Ventures, shares his journey from Army intelligence officer to cyber-focused venture capitalist.</itunes:summary>
      <itunes:subtitle>On episode 215 of the Cybersecurity Defenders Podcast, Hank Thomas, Managing Partner and Founder at Strategic Cyber Ventures, shares his journey from Army intelligence officer to cyber-focused venture capitalist.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#214 - Intel Chat: UTA0352/UTA0355, Commvault, Sonic wall &amp; Bot Traffic</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>214</itunes:episode>
      <podcast:episode>214</podcast:episode>
      <itunes:title>#214 - Intel Chat: UTA0352/UTA0355, Commvault, Sonic wall &amp; Bot Traffic</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">269669a8-1897-4201-907b-e347e1f3c5f7</guid>
      <link>https://share.transistor.fm/s/47fd38c9</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Since March 2025, Volexity has tracked an escalation in sophisticated phishing campaigns executed by two suspected Russian threat actors, UTA0352 and UTA0355, targeting the Microsoft 365 accounts of individuals connected to Ukraine and <a rel="noreferrer noopener" href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/">human rights organizations</a>.</li><li> A recent security assessment by watchTowr uncovered a pre-authenticated Remote Code Execution (RCE) vulnerability in Commvault’s on-premise Backup and Recovery solution (<a rel="noreferrer noopener" href="https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/">Innovation Release 11.38.20</a>). </li><li>CISA has added two SonicWall vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating an escalation in exploitation activity against the vendor’s SMA series of <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/two-sonicwall-vulnerabilities-under-exploitation">secure remote access appliances</a>. </li><li>Bot traffic has overtaken legitimate human use on the internet, with the latest data showing that automated traffic now accounts for 51% of all internet activity—of which 37% is <a rel="noreferrer noopener" href="https://www.securityweek.com/bot-traffic-surpasses-humans-online-driven-by-ai-and-criminal-innovation/">classified as malicious</a>. </li></ul><ul></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Since March 2025, Volexity has tracked an escalation in sophisticated phishing campaigns executed by two suspected Russian threat actors, UTA0352 and UTA0355, targeting the Microsoft 365 accounts of individuals connected to Ukraine and <a rel="noreferrer noopener" href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/">human rights organizations</a>.</li><li> A recent security assessment by watchTowr uncovered a pre-authenticated Remote Code Execution (RCE) vulnerability in Commvault’s on-premise Backup and Recovery solution (<a rel="noreferrer noopener" href="https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/">Innovation Release 11.38.20</a>). </li><li>CISA has added two SonicWall vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating an escalation in exploitation activity against the vendor’s SMA series of <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/two-sonicwall-vulnerabilities-under-exploitation">secure remote access appliances</a>. </li><li>Bot traffic has overtaken legitimate human use on the internet, with the latest data showing that automated traffic now accounts for 51% of all internet activity—of which 37% is <a rel="noreferrer noopener" href="https://www.securityweek.com/bot-traffic-surpasses-humans-online-driven-by-ai-and-criminal-innovation/">classified as malicious</a>. </li></ul><ul></ul>]]>
      </content:encoded>
      <pubDate>Wed, 14 May 2025 17:49:44 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/47fd38c9/a25936c0.mp3" length="45759436" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/_9u8fs9_8yKceCvxScGADZRWUJfGFAGiJi64bEWoZ74/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yYzAz/YmE2OWZjYjIzZmY2/NmFlNjIyNmZhMDc4/MzViNC5wbmc.jpg"/>
      <itunes:duration>1907</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#213 - Building cybersecurity products with Jonathan Haas, Product at Vanta</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>213</itunes:episode>
      <podcast:episode>213</podcast:episode>
      <itunes:title>#213 - Building cybersecurity products with Jonathan Haas, Product at Vanta</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7f92b28d-3bf6-4e78-acd0-2ba84fa80e9f</guid>
      <link>https://share.transistor.fm/s/fad68271</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Jonathan Haas, Product at <a rel="noreferrer noopener" href="https://www.vanta.com/">Vanta</a>, about building cybersecurity products.</p><p>Jonathan’s work focuses on making security compliance faster and more accessible, helping teams move from months-long processes to efficient workflows that take just days. Before Vanta, he was the co-founder and CEO of cybersecurity startup ThreatKey, and before that he held key roles at Snapchat, DoorDash, and Carta, where he built and refined compliance systems during times of rapid growth.</p><p>Outside of work, Jonathan explores San Francisco on foot, experiments with sourdough pizza recipes, and is cooking a dish from every country in the world. He brings a product philosophy rooted in solving real problems, blending data with user stories, and fostering inclusive teams.</p><p>You can read his blog, Haas on Saas, <a rel="noreferrer noopener" href="https://www.haasonsaas.com/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we speak with Jonathan Haas, Product at <a rel="noreferrer noopener" href="https://www.vanta.com/">Vanta</a>, about building cybersecurity products.</p><p>Jonathan’s work focuses on making security compliance faster and more accessible, helping teams move from months-long processes to efficient workflows that take just days. Before Vanta, he was the co-founder and CEO of cybersecurity startup ThreatKey, and before that he held key roles at Snapchat, DoorDash, and Carta, where he built and refined compliance systems during times of rapid growth.</p><p>Outside of work, Jonathan explores San Francisco on foot, experiments with sourdough pizza recipes, and is cooking a dish from every country in the world. He brings a product philosophy rooted in solving real problems, blending data with user stories, and fostering inclusive teams.</p><p>You can read his blog, Haas on Saas, <a rel="noreferrer noopener" href="https://www.haasonsaas.com/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 08 May 2025 16:47:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fad68271/909737f9.mp3" length="23173672" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1931</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders Podcast we speak with Jonathan Haas, Product at Vanta, about building cybersecurity products.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders Podcast we speak with Jonathan Haas, Product at Vanta, about building cybersecurity products.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#212 - Intel Chat: RSA 2025</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>212</itunes:episode>
      <podcast:episode>212</podcast:episode>
      <itunes:title>#212 - Intel Chat: RSA 2025</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">91f0f3ae-02bc-4f67-a544-a8c509d877b5</guid>
      <link>https://share.transistor.fm/s/d8dd90f3</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>During a talk at RSA, DHS Secretary Kristi Noem provided an update on the future direction of the Cybersecurity and Infrastructure Security Agency (CISA) under the new <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/dhs-secretary-noem-cisa-back-on-mission">Trump administration</a>.</li><li>During the panel discussion titled “AI and Cyber Defense: Protecting Critical Infrastructure” which brought together federal research leaders to talk about how AI and automation are being leveraged to address mounting cyber risks across the U.S. critical <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/darpa-highlights-critical-infrastructure-security-challenges">infrastructure landscape</a>. </li><li>A new report titled The Rise of State-Sponsored Hacktivism provides a detailed analysis of how hacktivist operations have become an increasingly prominent feature of <a rel="noreferrer noopener" href="https://www.forescout.com/resources/the-rise-of-state-sponsored-hacktivism/">geopolitical cyber conflict</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>During a talk at RSA, DHS Secretary Kristi Noem provided an update on the future direction of the Cybersecurity and Infrastructure Security Agency (CISA) under the new <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/dhs-secretary-noem-cisa-back-on-mission">Trump administration</a>.</li><li>During the panel discussion titled “AI and Cyber Defense: Protecting Critical Infrastructure” which brought together federal research leaders to talk about how AI and automation are being leveraged to address mounting cyber risks across the U.S. critical <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/darpa-highlights-critical-infrastructure-security-challenges">infrastructure landscape</a>. </li><li>A new report titled The Rise of State-Sponsored Hacktivism provides a detailed analysis of how hacktivist operations have become an increasingly prominent feature of <a rel="noreferrer noopener" href="https://www.forescout.com/resources/the-rise-of-state-sponsored-hacktivism/">geopolitical cyber conflict</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Mon, 05 May 2025 15:31:14 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d8dd90f3/68fc4e05.mp3" length="67334863" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/1AW5egJgwykxg8KkWx4eZaKXDcuH6GfcwM1BaFsfZkk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84ZjM3/ZTdhN2EwYzAxYjcw/NzNjMmUyN2FiOTg3/MWM3ZS5wbmc.jpg"/>
      <itunes:duration>2806</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#211 - Intel Chat: Fog, Operation Endgame, Mustang Panda &amp; Atomic macOS Stealer (AMOS)</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>211</itunes:episode>
      <podcast:episode>211</podcast:episode>
      <itunes:title>#211 - Intel Chat: Fog, Operation Endgame, Mustang Panda &amp; Atomic macOS Stealer (AMOS)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">89468910-18a1-48a2-a3f6-c20824fa3d1f</guid>
      <link>https://share.transistor.fm/s/4af3a366</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers at Trend Micro have uncovered a new campaign by the Fog ransomware group, notable for its use of DOGE-themed ransom notes aimed at mocking victims rather than <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/fog-hackers-doge-ransom-notes">just extorting them</a>.</li><li>In the wake of May 2024’s Operation Endgame, which dismantled some of the most prominent malware droppers such as IcedID, Pikabot, SystemBC, Smokeloader, and Bumblebee, law enforcement agencies across Europe and North America have moved into a new phase targeting end <a rel="noreferrer noopener" href="https://www.europol.europa.eu/media-press/newsroom/news/operation-endgame-follow-leads-to-five-detentions-and-interrogations-well-server-takedowns">users of these platforms</a>.</li><li>Zscaler researchers have recently observed Mustang Panda—also known by aliases like Bronze President, Stately Taurus, and TA416—upgrading its toolset as part of an ongoing espionage campaign, with a recent operation targeting an <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/chinese-apt-mustang-panda-4-attack-tools">organization in Myanmar</a>.</li><li> Atomic macOS Stealer (AMOS), identified as one of the most impactful macOS-targeting infostealers of 2024, leverages deceptive application installers and phishing tactics to gain <a rel="noreferrer noopener" href="https://www.picussecurity.com/resource/blog/atomic-stealer-amos-macos-threat-analysis">access to victim machines</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>Researchers at Trend Micro have uncovered a new campaign by the Fog ransomware group, notable for its use of DOGE-themed ransom notes aimed at mocking victims rather than <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/fog-hackers-doge-ransom-notes">just extorting them</a>.</li><li>In the wake of May 2024’s Operation Endgame, which dismantled some of the most prominent malware droppers such as IcedID, Pikabot, SystemBC, Smokeloader, and Bumblebee, law enforcement agencies across Europe and North America have moved into a new phase targeting end <a rel="noreferrer noopener" href="https://www.europol.europa.eu/media-press/newsroom/news/operation-endgame-follow-leads-to-five-detentions-and-interrogations-well-server-takedowns">users of these platforms</a>.</li><li>Zscaler researchers have recently observed Mustang Panda—also known by aliases like Bronze President, Stately Taurus, and TA416—upgrading its toolset as part of an ongoing espionage campaign, with a recent operation targeting an <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/chinese-apt-mustang-panda-4-attack-tools">organization in Myanmar</a>.</li><li> Atomic macOS Stealer (AMOS), identified as one of the most impactful macOS-targeting infostealers of 2024, leverages deceptive application installers and phishing tactics to gain <a rel="noreferrer noopener" href="https://www.picussecurity.com/resource/blog/atomic-stealer-amos-macos-threat-analysis">access to victim machines</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 29 Apr 2025 13:09:46 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4af3a366/871faa8f.mp3" length="21022981" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/zWDalXDoTJQKjdVOBWrZok38kJG2y0Yb6SEBXu6OWH0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xNzRi/MWEyZmM0MDgxNGI3/OWEyMTMzZTNjOWRh/YWRmMS5wbmc.jpg"/>
      <itunes:duration>1752</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#210 - The current cybersecurity landscape with Ian L. Paterson, CEO of Plurilock</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>210</itunes:episode>
      <podcast:episode>210</podcast:episode>
      <itunes:title>#210 - The current cybersecurity landscape with Ian L. Paterson, CEO of Plurilock</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">75662c78-3f96-489b-aa85-1fe7fdd10cfb</guid>
      <link>https://share.transistor.fm/s/6dbef92e</link>
      <description>
        <![CDATA[<p>On today’s episode of The Cybersecurity Defenders Podcast we speak with Ian L. Paterson, CEO of <a rel="noreferrer noopener" href="https://plurilock.com/">Plurilock</a>, about the current state of Cybersecurity.</p><p>Ian is a data entrepreneur with more than 15 years of experience in leading and commercializing technology companies in the fields of data analytics and cybersecurity. Ian is the CEO of Plurilock, where he led the company’s growth and its successful listing on the TSX Venture Exchange.</p><p>He previously founded and served as CEO of a data monetization platform that processed over a billion data events monthly before being acquired. Ian also held the role of Director of Insights at a venture backed analytics firm, where he managed half a trillion dollars in transaction data and helped generate eight-figure analytics sales before the company’s acquisition by eBay.</p><p>Ian has raised tens of millions of dollars in financing, completed four international M&amp;A deals, and is a co-inventor on three patents. He is an active angel investor, a frequent media commentator featured in publications like Forbes and the Wall Street Journal, and a volunteer contributor to national policy through organizations such as the Canadian Council of Innovators and the Centre for International Government Innovation.</p><p>You can listen to Ian's podcast, Code &amp; COuntry, here: <a rel="noreferrer noopener" href="https://plurilock.com/podcast/">https://plurilock.com/podcast/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today’s episode of The Cybersecurity Defenders Podcast we speak with Ian L. Paterson, CEO of <a rel="noreferrer noopener" href="https://plurilock.com/">Plurilock</a>, about the current state of Cybersecurity.</p><p>Ian is a data entrepreneur with more than 15 years of experience in leading and commercializing technology companies in the fields of data analytics and cybersecurity. Ian is the CEO of Plurilock, where he led the company’s growth and its successful listing on the TSX Venture Exchange.</p><p>He previously founded and served as CEO of a data monetization platform that processed over a billion data events monthly before being acquired. Ian also held the role of Director of Insights at a venture backed analytics firm, where he managed half a trillion dollars in transaction data and helped generate eight-figure analytics sales before the company’s acquisition by eBay.</p><p>Ian has raised tens of millions of dollars in financing, completed four international M&amp;A deals, and is a co-inventor on three patents. He is an active angel investor, a frequent media commentator featured in publications like Forbes and the Wall Street Journal, and a volunteer contributor to national policy through organizations such as the Canadian Council of Innovators and the Centre for International Government Innovation.</p><p>You can listen to Ian's podcast, Code &amp; COuntry, here: <a rel="noreferrer noopener" href="https://plurilock.com/podcast/">https://plurilock.com/podcast/</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 25 Apr 2025 19:26:49 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6dbef92e/f7aa78d7.mp3" length="24768616" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2064</itunes:duration>
      <itunes:summary>On today’s episode of The Cybersecurity Defenders Podcast we speak with Ian L. Paterson, CEO of Plurilock, about the current state of Cybersecurity.</itunes:summary>
      <itunes:subtitle>On today’s episode of The Cybersecurity Defenders Podcast we speak with Ian L. Paterson, CEO of Plurilock, about the current state of Cybersecurity.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#209 - Intel Chat: OCC, CentreStack, UNC5174 &amp; Oracle</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>209</itunes:episode>
      <podcast:episode>209</podcast:episode>
      <itunes:title>#209 - Intel Chat: OCC, CentreStack, UNC5174 &amp; Oracle</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">282f9f33-1129-4826-a5c6-1dbe94b2a750</guid>
      <link>https://share.transistor.fm/s/d6420186</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie's community</a>.</p><ul><li>The U.S. Treasury Department’s Office of the Comptroller of the Currency (OCC) has confirmed that emails belonging to its executives and staff were compromised in a cyber incident first <a rel="noreferrer noopener" href="https://www.reuters.com/technology/cybersecurity/us-regulator-occ-notifies-congress-major-security-breach-2025-04-08/">detected in February</a>.</li><li>A critical zero-day vulnerability, tracked as CVE-2025-30406, has been actively exploited since March in CentreStack, a file-sharing platform developed by Gladinet and widely used by <a rel="noreferrer noopener" href="https://community.limacharlie.com/t/vulnerability-zero-day-in-centrestack-file-sharing-platform-under-attack/265">managed services providers (MSPs)</a>.</li><li>UNC5174, a state-backed Chinese threat actor, has been observed using stealthy tactics and open source tooling in recent campaigns targeting Western and <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/china-threat-actor-unc5174-open-source-stealthy-attacks">Asia-Pacific organizations</a>.</li><li>Oracle is facing sustained criticism over its handling of a recent cybersecurity incident in which a hacker claimed to have breached its systems and obtained records linked to over <a rel="noreferrer noopener" href="https://www.securityweek.com/oracle-faces-mounting-criticism-as-it-notifies-customers-of-hack/">140,000 tenants</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie's community</a>.</p><ul><li>The U.S. Treasury Department’s Office of the Comptroller of the Currency (OCC) has confirmed that emails belonging to its executives and staff were compromised in a cyber incident first <a rel="noreferrer noopener" href="https://www.reuters.com/technology/cybersecurity/us-regulator-occ-notifies-congress-major-security-breach-2025-04-08/">detected in February</a>.</li><li>A critical zero-day vulnerability, tracked as CVE-2025-30406, has been actively exploited since March in CentreStack, a file-sharing platform developed by Gladinet and widely used by <a rel="noreferrer noopener" href="https://community.limacharlie.com/t/vulnerability-zero-day-in-centrestack-file-sharing-platform-under-attack/265">managed services providers (MSPs)</a>.</li><li>UNC5174, a state-backed Chinese threat actor, has been observed using stealthy tactics and open source tooling in recent campaigns targeting Western and <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/china-threat-actor-unc5174-open-source-stealthy-attacks">Asia-Pacific organizations</a>.</li><li>Oracle is facing sustained criticism over its handling of a recent cybersecurity incident in which a hacker claimed to have breached its systems and obtained records linked to over <a rel="noreferrer noopener" href="https://www.securityweek.com/oracle-faces-mounting-criticism-as-it-notifies-customers-of-hack/">140,000 tenants</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Mon, 21 Apr 2025 16:08:54 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d6420186/1e074114.mp3" length="23976737" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/_kBUVva5nbK3Hvnay-7OqFRSmUO36jpat18V5GZwtzA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mZWY0/NmFkM2ExMTg3ZmI1/MmU0MTY1NWZkMTc0/ZWM0YS5wbmc.jpg"/>
      <itunes:duration>1998</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#208 - Cybersecurity in space with Blake Hershey and Gabe Garrett from MORI Associates</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>208</itunes:episode>
      <podcast:episode>208</podcast:episode>
      <itunes:title>#208 - Cybersecurity in space with Blake Hershey and Gabe Garrett from MORI Associates</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">847c44ac-b376-498c-b044-b74a9f62c367</guid>
      <link>https://share.transistor.fm/s/9bde67b9</link>
      <description>
        <![CDATA[<p>On today’s episode of The Cybersecurity Defenders Podcast we are going to be speaking with a couple of team members from <a rel="noreferrer noopener" href="https://moriassociates.com/">MORI Associates</a>, a leading firm with over 25 years of experience in delivering comprehensive solutions across technology, communication, and space mission support. </p><p>Specializing in scalable, high-impact technologies, the company addresses current challenges while anticipating future needs, contributing to a more connected, efficient, and secure future. </p><p>MORI Associates has played pivotal roles in supporting missions to Earth orbit, the moon, and beyond, contributing to groundbreaking projects that advance both terrestrial applications and interstellar explorations.</p><p>Our first guest is Gabe Garrett, Senior Vice President of Space and Defense at MORI Associates. With nearly two decades of experience in the aerospace and defense industries, Gabe leads strategy, growth, and operations across key civil and defense accounts. Before joining MORI Associates, he served as Account Vice President at SAIC, overseeing the Human Space Exploration and Operations Solutions division. Gabe's extensive background includes leadership roles at Engility Corporation and engineering experience with spacecraft, launch vehicles, and mission systems at ARES Corporation.</p><p>Our other guest is Blake Hershey, Chief Growth Officer at MORI Associates. Blake is a visionary entrepreneur known for his passion for creating products that enhance lives and drive positive behavioral changes.</p><p>With a track record of transforming concepts into successful multi-million-dollar ventures, he brings extensive expertise in business development, including finance, operations, marketing, product innovation, and strategic planning. </p><p>His leadership has been instrumental in driving significant revenue growth at MORI Associates over the past several years. Blake has also been recognized by Forbes' Next 1000 for his entrepreneurial achievements.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today’s episode of The Cybersecurity Defenders Podcast we are going to be speaking with a couple of team members from <a rel="noreferrer noopener" href="https://moriassociates.com/">MORI Associates</a>, a leading firm with over 25 years of experience in delivering comprehensive solutions across technology, communication, and space mission support. </p><p>Specializing in scalable, high-impact technologies, the company addresses current challenges while anticipating future needs, contributing to a more connected, efficient, and secure future. </p><p>MORI Associates has played pivotal roles in supporting missions to Earth orbit, the moon, and beyond, contributing to groundbreaking projects that advance both terrestrial applications and interstellar explorations.</p><p>Our first guest is Gabe Garrett, Senior Vice President of Space and Defense at MORI Associates. With nearly two decades of experience in the aerospace and defense industries, Gabe leads strategy, growth, and operations across key civil and defense accounts. Before joining MORI Associates, he served as Account Vice President at SAIC, overseeing the Human Space Exploration and Operations Solutions division. Gabe's extensive background includes leadership roles at Engility Corporation and engineering experience with spacecraft, launch vehicles, and mission systems at ARES Corporation.</p><p>Our other guest is Blake Hershey, Chief Growth Officer at MORI Associates. Blake is a visionary entrepreneur known for his passion for creating products that enhance lives and drive positive behavioral changes.</p><p>With a track record of transforming concepts into successful multi-million-dollar ventures, he brings extensive expertise in business development, including finance, operations, marketing, product innovation, and strategic planning. </p><p>His leadership has been instrumental in driving significant revenue growth at MORI Associates over the past several years. Blake has also been recognized by Forbes' Next 1000 for his entrepreneurial achievements.</p>]]>
      </content:encoded>
      <pubDate>Tue, 15 Apr 2025 14:54:53 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9bde67b9/1cfaa5bb.mp3" length="20496979" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1708</itunes:duration>
      <itunes:summary>On today’s episode of The Cybersecurity Defenders Podcast we are going to be speaking with a couple of team members from MORI Associates, a leading firm with over 25 years of experience in delivering comprehensive solutions across technology, communication, and space mission support.</itunes:summary>
      <itunes:subtitle>On today’s episode of The Cybersecurity Defenders Podcast we are going to be speaking with a couple of team members from MORI Associates, a leading firm with over 25 years of experience in delivering comprehensive solutions across technology, communicatio</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#207 - Intel Chat: MirrorFace, Neptune, Sparrow door &amp; CrushFTP</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>207</itunes:episode>
      <podcast:episode>207</podcast:episode>
      <itunes:title>#207 - Intel Chat: MirrorFace, Neptune, Sparrow door &amp; CrushFTP</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e04a0a14-a83f-4877-80c7-4b4eb9e25e99</guid>
      <link>https://share.transistor.fm/s/0a3939b5</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie's community</a>.</p><ul><li>Japanese law enforcement has publicly linked a Chinese state-sponsored threat group known as MirrorFace to a series of cyberattacks that have targeted <a rel="noreferrer noopener" href="https://www.securityweek.com/japan-links-chinese-hacker-mirrorface-to-dozens-of-cyberattacks-targeting-security-and-tech-data/">Japan over the past five years</a>.</li><li>Researchers at Cyfirma have detailed a new campaign where attackers are using a Remote Access Trojan (RAT) dubbed Neptune to hijack <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/windows-hijacking-neptune-rat-telegram-youtube">Windows systems</a>.</li><li>Researchers have discovered new variants of a previously identified Linux backdoor known as SparrowDoor, believed to be the work of a North Korean state-sponsored group known as <a rel="noreferrer noopener" href="https://thehackernews.com/2025/03/new-sparrowdoor-backdoor-variants-found.html">Kimsuky</a>.</li><li>CISA has added a recently disclosed vulnerability in CrushFTP (tracked as CVE-2024-4040) to its <a rel="noreferrer noopener" href="https://thehackernews.com/2025/04/cisa-adds-crushftp-vulnerability-to-kev.html">Known Exploited Vulnerabilities (KEV) catalog</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie's community</a>.</p><ul><li>Japanese law enforcement has publicly linked a Chinese state-sponsored threat group known as MirrorFace to a series of cyberattacks that have targeted <a rel="noreferrer noopener" href="https://www.securityweek.com/japan-links-chinese-hacker-mirrorface-to-dozens-of-cyberattacks-targeting-security-and-tech-data/">Japan over the past five years</a>.</li><li>Researchers at Cyfirma have detailed a new campaign where attackers are using a Remote Access Trojan (RAT) dubbed Neptune to hijack <a rel="noreferrer noopener" href="https://www.darkreading.com/cloud-security/windows-hijacking-neptune-rat-telegram-youtube">Windows systems</a>.</li><li>Researchers have discovered new variants of a previously identified Linux backdoor known as SparrowDoor, believed to be the work of a North Korean state-sponsored group known as <a rel="noreferrer noopener" href="https://thehackernews.com/2025/03/new-sparrowdoor-backdoor-variants-found.html">Kimsuky</a>.</li><li>CISA has added a recently disclosed vulnerability in CrushFTP (tracked as CVE-2024-4040) to its <a rel="noreferrer noopener" href="https://thehackernews.com/2025/04/cisa-adds-crushftp-vulnerability-to-kev.html">Known Exploited Vulnerabilities (KEV) catalog</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 11 Apr 2025 16:14:51 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0a3939b5/4592a73f.mp3" length="21805354" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/b5icQnDYP0yWVQSBQS4oVZ9xi9ffL9sPf7Eweh-dU6I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iN2Uy/ZmIzZWVhZWMxZDg2/YWU2ODY4ZTJiZWMx/YmJkOC5wbmc.jpg"/>
      <itunes:duration>1817</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#206 - The AI Threat Landscape Report with Eoin Wickens, Director of Threat Intelligence at HiddenLayer</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>206</itunes:episode>
      <podcast:episode>206</podcast:episode>
      <itunes:title>#206 - The AI Threat Landscape Report with Eoin Wickens, Director of Threat Intelligence at HiddenLayer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7e748be6-eafe-46c8-bdab-5d8079a6bc8f</guid>
      <link>https://share.transistor.fm/s/a0e271bf</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we dive into the AI Threat Landscape report with Eoin Wickens, Director of Threat Intelligence at <a rel="noreferrer noopener" href="https://hiddenlayer.com/">HiddenLayer</a>.</p><p>Eoin specializes in AI security, threat research, and malware reverse engineering. Eoin has authored numerous articles on AI security, co-authored a book on cyber threat intelligence focusing on Cobalt Strike, and has spoken at conferences such as DEF CON AI Village, BSides San Francisco, LABScon, and 44CON. He also delivered the 2024 SCORED opening keynote.</p><p>You can get a copy of the report here: <a rel="noreferrer noopener" href="https://hiddenlayer.com/threatreport2025/">https://hiddenlayer.com/threatreport2025/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast we dive into the AI Threat Landscape report with Eoin Wickens, Director of Threat Intelligence at <a rel="noreferrer noopener" href="https://hiddenlayer.com/">HiddenLayer</a>.</p><p>Eoin specializes in AI security, threat research, and malware reverse engineering. Eoin has authored numerous articles on AI security, co-authored a book on cyber threat intelligence focusing on Cobalt Strike, and has spoken at conferences such as DEF CON AI Village, BSides San Francisco, LABScon, and 44CON. He also delivered the 2024 SCORED opening keynote.</p><p>You can get a copy of the report here: <a rel="noreferrer noopener" href="https://hiddenlayer.com/threatreport2025/">https://hiddenlayer.com/threatreport2025/</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 07 Apr 2025 15:48:09 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a0e271bf/d78a94ec.mp3" length="60094948" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2504</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders Podcast we dive into the AI Threat Landscape report with Eoin Wickens, Director of Threat Intelligence at HiddenLayer.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders Podcast we dive into the AI Threat Landscape report with Eoin Wickens, Director of Threat Intelligence at HiddenLayer.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#205 - Intel Chat: OPSEC FAIL, Manifest Confusion &amp; Github Actions</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>205</itunes:episode>
      <podcast:episode>205</podcast:episode>
      <itunes:title>#205 - Intel Chat: OPSEC FAIL, Manifest Confusion &amp; Github Actions</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bc13d8f1-0419-4933-95d8-7e72bcef60c4</guid>
      <link>https://share.transistor.fm/s/e0a96451</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie's community</a>.</p><ul><li>On March 24, The Atlantic’s editor-in-chief Jeffrey Goldberg reported a significant OPSEC failure involving U.S. Secretary of Defense Pete Hegseth, who allegedly sent him detailed U.S. military plans over Signal—an encrypted messaging app—on <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/opsec-nightmare-leaking-us-military-plans-reporter">March 15</a>.</li><li>A newly discovered supply chain attack on the npm ecosystem is targeting developers by backdooring local packages through a process known as <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/new-npm-attack-poisons-local-packages-with-backdoors/">“manifest confusion.”</a> </li><li>Unit 42 researchers at Palo Alto Networks have uncovered an ongoing software supply chain attack targeting GitHub repositories via malicious <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/">GitHub Actions workflows</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie's community</a>.</p><ul><li>On March 24, The Atlantic’s editor-in-chief Jeffrey Goldberg reported a significant OPSEC failure involving U.S. Secretary of Defense Pete Hegseth, who allegedly sent him detailed U.S. military plans over Signal—an encrypted messaging app—on <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/opsec-nightmare-leaking-us-military-plans-reporter">March 15</a>.</li><li>A newly discovered supply chain attack on the npm ecosystem is targeting developers by backdooring local packages through a process known as <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/new-npm-attack-poisons-local-packages-with-backdoors/">“manifest confusion.”</a> </li><li>Unit 42 researchers at Palo Alto Networks have uncovered an ongoing software supply chain attack targeting GitHub repositories via malicious <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/">GitHub Actions workflows</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 01 Apr 2025 14:48:32 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e0a96451/ff3c357e.mp3" length="21301928" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/GCPfJSjvFp-7S1HaIbb4xa6mq_Y-o39ZwUTT7YzalNU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZTdm/YTc3ZTA1Y2M4ODgy/ZmMzY2FkMDdlNGY4/NmZmNy5wbmc.jpg"/>
      <itunes:duration>1775</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#204 - Intel Chat: Wiz, Windows, SocGholish, WDAC &amp; BLE</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>204</itunes:episode>
      <podcast:episode>204</podcast:episode>
      <itunes:title>#204 - Intel Chat: Wiz, Windows, SocGholish, WDAC &amp; BLE</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">115271de-36a5-4c9a-97b6-1dbbe9c4f503</guid>
      <link>https://share.transistor.fm/s/f50b3e8a</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community<a rel="noreferrer noopener" href="https://slack.limacharlie.io/"> Slack channel</a>.</p><ul><li>Google has announced a $32 billion ALL CASH acquisition of the Israeli cybersecurity startup Wiz, making it one of the largest deals in the <a rel="noreferrer noopener" href="https://blog.google/inside-google/company-announcements/google-agreement-acquire-wiz/">company’s history</a>.</li><li>A newly discovered zero-day vulnerability in Windows allows attackers to escalate privileges, potentially granting them full control over<a rel="noreferrer noopener" href="https://thehackernews.com/2025/03/unpatched-windows-zero-day-flaw.html"> affected systems</a>.</li><li>Security researchers have identified new intrusion techniques used by the SocGholish malware framework, which is increasingly being leveraged to <a rel="noreferrer noopener" href="https://www.trendmicro.com/en_us/research/25/c/socgholishs-intrusion-techniques-facilitate-distribution-of-rans.html">distribute ransomware</a>.</li><li>Security researchers have uncovered a new technique that allows attackers to disable Endpoint Detection and Response (EDR) solutions using <a rel="noreferrer noopener" href="https://labs.beazley.security/articles/disabling-edr-with-wdac">Windows Defender Application Control (WDAC)</a>.</li><li>Security researchers have discovered undocumented commands in a widely used Bluetooth chip, potentially exposing over a billion devices to <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices/">security risks</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community<a rel="noreferrer noopener" href="https://slack.limacharlie.io/"> Slack channel</a>.</p><ul><li>Google has announced a $32 billion ALL CASH acquisition of the Israeli cybersecurity startup Wiz, making it one of the largest deals in the <a rel="noreferrer noopener" href="https://blog.google/inside-google/company-announcements/google-agreement-acquire-wiz/">company’s history</a>.</li><li>A newly discovered zero-day vulnerability in Windows allows attackers to escalate privileges, potentially granting them full control over<a rel="noreferrer noopener" href="https://thehackernews.com/2025/03/unpatched-windows-zero-day-flaw.html"> affected systems</a>.</li><li>Security researchers have identified new intrusion techniques used by the SocGholish malware framework, which is increasingly being leveraged to <a rel="noreferrer noopener" href="https://www.trendmicro.com/en_us/research/25/c/socgholishs-intrusion-techniques-facilitate-distribution-of-rans.html">distribute ransomware</a>.</li><li>Security researchers have uncovered a new technique that allows attackers to disable Endpoint Detection and Response (EDR) solutions using <a rel="noreferrer noopener" href="https://labs.beazley.security/articles/disabling-edr-with-wdac">Windows Defender Application Control (WDAC)</a>.</li><li>Security researchers have discovered undocumented commands in a widely used Bluetooth chip, potentially exposing over a billion devices to <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices/">security risks</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 21 Mar 2025 17:31:04 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f50b3e8a/97a135c3.mp3" length="25271337" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/GVrmbixWOAxvimhofYjSJcImGq7CJsuCj-lmXhRd4Zk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZWE2/OTdiMzlmNDgzODU2/OGNiYmE5OTY3ODYw/ZjQ3YS5wbmc.jpg"/>
      <itunes:duration>2090</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#203 - Breaking the stigma of addiction in cyber with Jen VanAntwerp, Founder of Sober in Cyber</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>203</itunes:episode>
      <podcast:episode>203</podcast:episode>
      <itunes:title>#203 - Breaking the stigma of addiction in cyber with Jen VanAntwerp, Founder of Sober in Cyber</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f2d3b2a9-d22e-41ea-adb5-8bff45317dab</guid>
      <link>https://share.transistor.fm/s/148a74a0</link>
      <description>
        <![CDATA[<p>On today's episode of the Cybersecurity Defenders Podcast, we speak with Jen VanAntwerp, the Founder of <a rel="noreferrer noopener" href="https://www.soberincyber.org/">Sober in Cyber</a>.</p><p>Jen is a cybersecurity marketing professional and the founder of Sober in Cyber, a nonprofit on a mission to provide alcohol-free events and community-building opportunities for sober and sober-curious individuals working in infosec. Jen is passionate about breaking the stigma of addiction recovery and is profoundly driven to increase the number of professional networking events that don’t revolve around alcohol. She is also the founder of JVAN Consulting, where she provides marketing consultation services to cybersecurity startups.</p><p>Sober in Cyber Discord can be found <a rel="noreferrer noopener" href="https://discord.com/invite/muaaTbWyvC">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today's episode of the Cybersecurity Defenders Podcast, we speak with Jen VanAntwerp, the Founder of <a rel="noreferrer noopener" href="https://www.soberincyber.org/">Sober in Cyber</a>.</p><p>Jen is a cybersecurity marketing professional and the founder of Sober in Cyber, a nonprofit on a mission to provide alcohol-free events and community-building opportunities for sober and sober-curious individuals working in infosec. Jen is passionate about breaking the stigma of addiction recovery and is profoundly driven to increase the number of professional networking events that don’t revolve around alcohol. She is also the founder of JVAN Consulting, where she provides marketing consultation services to cybersecurity startups.</p><p>Sober in Cyber Discord can be found <a rel="noreferrer noopener" href="https://discord.com/invite/muaaTbWyvC">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 20 Mar 2025 03:03:20 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/148a74a0/da7f68ca.mp3" length="24249193" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/V-FvLr15UapeeTw0bKiyfeqsE1mHweY7_tC74Pvo-uk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lYzQz/MzgyNmM0MmRkYmUz/YzA1MDUwMGM0ODJh/N2RkMi5wbmc.jpg"/>
      <itunes:duration>2005</itunes:duration>
      <itunes:summary>On today's episode of the Cybersecurity Defenders Podcast, we speak with Jen VanAntwerp, the Founder of Sober in Cyber.</itunes:summary>
      <itunes:subtitle>On today's episode of the Cybersecurity Defenders Podcast, we speak with Jen VanAntwerp, the Founder of Sober in Cyber.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#202 - Intel Chat: CISA, BianLian (not), Crafty Camel, Github malvertising &amp; SCADA</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>202</itunes:episode>
      <podcast:episode>202</podcast:episode>
      <itunes:title>#202 - Intel Chat: CISA, BianLian (not), Crafty Camel, Github malvertising &amp; SCADA</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e5430b84-efa9-4e9d-96b9-a35ca28c566f</guid>
      <link>https://share.transistor.fm/s/1622a9d1</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The Cybersecurity and Infrastructure Security Agency (CISA) is facing significant operational challenges as budget constraints force it to scale back key <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/cisa-cuts-dangerous-gamble-dangerous-world">cybersecurity programs</a>.</li><li>Scammers are taking a new approach to extortion by mailing physical ransom letters to victims, claiming to be the operators of the<a rel="noreferrer noopener" href="https://hackread.com/scammers-mailing-ransom-letters-bianlian-ransomware/"> BianLian ransomware group</a>.</li><li>A newly identified advanced persistent threat (APT) group, dubbed "Crafty Camel," has been targeting aviation operational technology (OT) systems using a sophisticated technique involving <a rel="noreferrer noopener" href="https://www.darkreading.com/ics-ot-security/crafty-camel-apt-aviation-ot-polygot-files">polyglot files</a>. </li><li>A new malvertising campaign is leveraging deceptive online ads to distribute information-stealing malware hosted on GitHub, highlighting an ongoing evolution in <a rel="noreferrer noopener" href="https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/">cybercriminal tactics</a>.</li><li>Security researchers have disclosed details of multiple vulnerabilities in Supervisory Control and Data Acquisition (SCADA) systems that could be exploited to facilitate attacks on <a rel="noreferrer noopener" href="https://www.securityweek.com/details-disclosed-for-scada-flaws-that-could-facilitate-industrial-attacks/">industrial environments</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of the <a rel="noreferrer noopener" href="https://community.limacharlie.com/">LimaCharlie community</a>.</p><ul><li>The Cybersecurity and Infrastructure Security Agency (CISA) is facing significant operational challenges as budget constraints force it to scale back key <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/cisa-cuts-dangerous-gamble-dangerous-world">cybersecurity programs</a>.</li><li>Scammers are taking a new approach to extortion by mailing physical ransom letters to victims, claiming to be the operators of the<a rel="noreferrer noopener" href="https://hackread.com/scammers-mailing-ransom-letters-bianlian-ransomware/"> BianLian ransomware group</a>.</li><li>A newly identified advanced persistent threat (APT) group, dubbed "Crafty Camel," has been targeting aviation operational technology (OT) systems using a sophisticated technique involving <a rel="noreferrer noopener" href="https://www.darkreading.com/ics-ot-security/crafty-camel-apt-aviation-ot-polygot-files">polyglot files</a>. </li><li>A new malvertising campaign is leveraging deceptive online ads to distribute information-stealing malware hosted on GitHub, highlighting an ongoing evolution in <a rel="noreferrer noopener" href="https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/">cybercriminal tactics</a>.</li><li>Security researchers have disclosed details of multiple vulnerabilities in Supervisory Control and Data Acquisition (SCADA) systems that could be exploited to facilitate attacks on <a rel="noreferrer noopener" href="https://www.securityweek.com/details-disclosed-for-scada-flaws-that-could-facilitate-industrial-attacks/">industrial environments</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 14 Mar 2025 15:14:34 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1622a9d1/c4c14eba.mp3" length="27894502" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Q2DZRhnQP9dxrigriAq0j5OfMNqZHWGxjDiaxVwINNs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MTYx/N2I3NDQ3MGJhNTY5/YjYyMjY3YjRjZWM1/NzE3Zi5wbmc.jpg"/>
      <itunes:duration>2308</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of the LimaCharlie community.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of the LimaCharlie community.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#201 - Scaling Managed Security Operations with Andrew Cook, CTO of Recon InfoSec</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>201</itunes:episode>
      <podcast:episode>201</podcast:episode>
      <itunes:title>#201 - Scaling Managed Security Operations with Andrew Cook, CTO of Recon InfoSec</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">882d951b-708d-4462-aaa5-6b26fc2462f8</guid>
      <link>https://share.transistor.fm/s/d83a3b34</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Andrew Cook, CTO of Recon InfoSec, about lessons learned scaling Managed Security Operations.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Andrew Cook, CTO of Recon InfoSec, about lessons learned scaling Managed Security Operations.</p>]]>
      </content:encoded>
      <pubDate>Wed, 12 Mar 2025 16:41:17 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d83a3b34/df5a88ce.mp3" length="24278318" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/iFCUtO45yCm2GAnUaUXJA2o5pMJSameAmt55ao4qqvw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jMjgz/YTVhNTJhMmM4NWNj/Mjg4ODc5ZTZjZjJk/OTIyMi5wbmc.jpg"/>
      <itunes:duration>2007</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Andrew Cook, CTO of Recon InfoSec, about lessons learned scaling Managed Security Operations.

Andrew is the Chief Technology Officer at Recon InfoSec, where he leads the technical vision, strategy, and execution of the company’s managed security operations. With over a decade of experience in threat hunting, digital forensics, and network defense, Andrew has built a career at the forefront of cybersecurity. Before joining Recon InfoSec, he held key leadership roles at Praetorian, Delta Risk, and the U.S. Air Force, where he contributed to national-level cyber defense initiatives. He has a strong background in incident response, capability development, and technical leadership. Andrew is also a frequent speaker and author in the cybersecurity community</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Andrew Cook, CTO of Recon InfoSec, about lessons learned scaling Managed Security Operations.

Andrew is the Chief Technology Officer at Recon InfoSec, where he leads the technical visio</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#200 - Multimodal Offensive Artificial Intelligence with Philippe Humeau, CEO of CrowdSec</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>200</itunes:episode>
      <podcast:episode>200</podcast:episode>
      <itunes:title>#200 - Multimodal Offensive Artificial Intelligence with Philippe Humeau, CEO of CrowdSec</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ee199466-4e59-4d58-8907-bced2cd7eeb2</guid>
      <link>https://share.transistor.fm/s/d9548d0c</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Philippe Humeau, CEO of <a rel="noreferrer noopener" href="https://www.crowdsec.net/">CrowdSec</a>, about Multimodal Offensive Artificial Intelligence (MOAI).</p><p>Philippe is a cybersecurity expert and seasoned entrepreneur with a deep passion for enhancing global internet security. He is the founder and CEO of CrowdSec, an innovative open-source platform that harnesses the power of community-driven threat intelligence to protect systems worldwide. Philippe's work focuses on collaborative approaches to cybersecurity, ensuring that organizations can stay ahead of evolving threats by pooling collective knowledge and resources. With years of experience building solutions that address complex security challenges, Philippe has made a significant impact on the field.</p><p>Before founding CrowdSec, Philippe successfully launched and led several companies within the cybersecurity space, further cementing his reputation as a thought leader and innovator. His journey reflects a commitment to addressing the most pressing challenges in the digital age, from fostering safer internet ecosystems to empowering businesses with the tools they need to defend against cyberattacks. Philippe is also an advocate for open-source technology and community-driven solutions, underscoring his belief that collaboration is key to combating global threats.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Philippe Humeau, CEO of <a rel="noreferrer noopener" href="https://www.crowdsec.net/">CrowdSec</a>, about Multimodal Offensive Artificial Intelligence (MOAI).</p><p>Philippe is a cybersecurity expert and seasoned entrepreneur with a deep passion for enhancing global internet security. He is the founder and CEO of CrowdSec, an innovative open-source platform that harnesses the power of community-driven threat intelligence to protect systems worldwide. Philippe's work focuses on collaborative approaches to cybersecurity, ensuring that organizations can stay ahead of evolving threats by pooling collective knowledge and resources. With years of experience building solutions that address complex security challenges, Philippe has made a significant impact on the field.</p><p>Before founding CrowdSec, Philippe successfully launched and led several companies within the cybersecurity space, further cementing his reputation as a thought leader and innovator. His journey reflects a commitment to addressing the most pressing challenges in the digital age, from fostering safer internet ecosystems to empowering businesses with the tools they need to defend against cyberattacks. Philippe is also an advocate for open-source technology and community-driven solutions, underscoring his belief that collaboration is key to combating global threats.</p>]]>
      </content:encoded>
      <pubDate>Tue, 11 Mar 2025 16:40:05 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d9548d0c/0a7bac9f.mp3" length="23853583" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/P_6DVzR2womGkE5Fo07BEoonkjmaGRe-1QNAYxorbHM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83Yzcz/MDU4ZjgzZmFjOTkz/YzY2N2U4Yzc2NTMx/YWMyYy5wbmc.jpg"/>
      <itunes:duration>1972</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Philippe Humeau, CEO of CrowdSec, about Multimodal Offensive Artificial Intelligence (MOAI).</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Philippe Humeau, CEO of CrowdSec, about Multimodal Offensive Artificial Intelligence (MOAI).</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#199 - Intel Chat: Lazarus Group, BadPilot, PAN-OS, emoji exfil, Kitty Stealer &amp;  PolarEdge</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>199</itunes:episode>
      <podcast:episode>199</podcast:episode>
      <itunes:title>#199 - Intel Chat: Lazarus Group, BadPilot, PAN-OS, emoji exfil, Kitty Stealer &amp;  PolarEdge</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8e282611-d405-4dd0-bc02-c5f8c803de50</guid>
      <link>https://share.transistor.fm/s/52b01351</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community<a rel="noreferrer noopener" href="https://slack.limacharlie.io/"> Slack channel</a>.</p><ul><li>North Korea’s state-backed Lazarus Group is believed to be responsible for the largest cryptocurrency heist ever recorded, stealing $1.5 billion from the <a rel="noreferrer noopener" href="https://www.businessinsider.com/north-korea-behind-bybit-crypto-hack-fbi-billion-dollar-heist-2025-2?utm_source=chatgpt.com">Bybit exchange</a>. </li><li>The "BadPilot" hacking campaign has been linked to Russia's Sandworm threat group, a unit of the GRU known for cyber espionage and <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/badpilot-network-hacking-campaign-fuels-russian-sandworm-attacks/">disruptive attacks</a>. </li><li>GreyNoise has observed active exploitation of CVE-2025-0108, a critical authentication bypass vulnerability in <a rel="noreferrer noopener" href="https://www.greynoise.io/blog/greynoise-observes-active-exploitation-of-pan-os-authentication-bypass-vulnerability-cve-2025-0108">Palo Alto Networks’ PAN-OS</a>. </li><li>Security researcher Paul Butler has demonstrated a novel technique for smuggling arbitrary data using emojis, leveraging the way modern text encoding and rendering systems handle <a rel="noreferrer noopener" href="https://paulbutler.org/2025/smuggling-arbitrary-data-through-an-emoji/">Unicode characters</a>.</li><li>Kitty Stealer is a newly identified malware targeting macOS systems, designed to steal sensitive user data such as credentials, browser cookies, and <a rel="noreferrer noopener" href="https://www.kandji.io/blog/kitty-stealer">cryptocurrency wallets</a>.</li><li>SEKOIA researchers have uncovered a previously unknown IoT botnet named PolarEdge, which has been operating covertly <a rel="noreferrer noopener" href="https://blog.sekoia.io/polaredge-unveiling-an-uncovered-iot-botnet/">for an extended period</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community<a rel="noreferrer noopener" href="https://slack.limacharlie.io/"> Slack channel</a>.</p><ul><li>North Korea’s state-backed Lazarus Group is believed to be responsible for the largest cryptocurrency heist ever recorded, stealing $1.5 billion from the <a rel="noreferrer noopener" href="https://www.businessinsider.com/north-korea-behind-bybit-crypto-hack-fbi-billion-dollar-heist-2025-2?utm_source=chatgpt.com">Bybit exchange</a>. </li><li>The "BadPilot" hacking campaign has been linked to Russia's Sandworm threat group, a unit of the GRU known for cyber espionage and <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/badpilot-network-hacking-campaign-fuels-russian-sandworm-attacks/">disruptive attacks</a>. </li><li>GreyNoise has observed active exploitation of CVE-2025-0108, a critical authentication bypass vulnerability in <a rel="noreferrer noopener" href="https://www.greynoise.io/blog/greynoise-observes-active-exploitation-of-pan-os-authentication-bypass-vulnerability-cve-2025-0108">Palo Alto Networks’ PAN-OS</a>. </li><li>Security researcher Paul Butler has demonstrated a novel technique for smuggling arbitrary data using emojis, leveraging the way modern text encoding and rendering systems handle <a rel="noreferrer noopener" href="https://paulbutler.org/2025/smuggling-arbitrary-data-through-an-emoji/">Unicode characters</a>.</li><li>Kitty Stealer is a newly identified malware targeting macOS systems, designed to steal sensitive user data such as credentials, browser cookies, and <a rel="noreferrer noopener" href="https://www.kandji.io/blog/kitty-stealer">cryptocurrency wallets</a>.</li><li>SEKOIA researchers have uncovered a previously unknown IoT botnet named PolarEdge, which has been operating covertly <a rel="noreferrer noopener" href="https://blog.sekoia.io/polaredge-unveiling-an-uncovered-iot-botnet/">for an extended period</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 07 Mar 2025 17:25:51 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/52b01351/af52203b.mp3" length="26276078" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/P1t4qOswKzDlH4ItVHioRJShxRWntWSp7yGmECwTVqo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83YmUz/YmJhNjZiMjc4ZWQz/OTI2NDJhYzFlZWRi/OTlhMC5wbmc.jpg"/>
      <itunes:duration>2174</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#198 - AI risk and safety with John Vaina, AI Researcher &amp; Red Teamer</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>198</itunes:episode>
      <podcast:episode>198</podcast:episode>
      <itunes:title>#198 - AI risk and safety with John Vaina, AI Researcher &amp; Red Teamer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a10091dd-dc4a-41e6-8582-fe859327d4a3</guid>
      <link>https://share.transistor.fm/s/6ffed456</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk with John Vaina, AI Researcher and Red Teamer, about AI risk and safety.</p><p>John is an expert in AI risk, safety, and security. John currently works as an AI red team operator, tackling some of the most complex challenges in the field. His work spans traditional cybersecurity concerns, such as identifying vulnerabilities in AI systems, to cutting-edge tasks like testing for emergent behaviors and conducting AI alignment and safety audits.</p><p>John’s expertise includes evaluating ethical and bias risks, ensuring model robustness, and running adversarial attack simulations to uncover potential weaknesses. Beyond these technical aspects, he also addresses broader safety issues, including scenarios involving CBRNE threats and other high-stakes risks.</p><p>John’s unique combination of technical skills, strategic thinking, and a focus on ethical considerations makes him a leading voice in ensuring that AI technologies are safe, secure, and aligned with human values.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk with John Vaina, AI Researcher and Red Teamer, about AI risk and safety.</p><p>John is an expert in AI risk, safety, and security. John currently works as an AI red team operator, tackling some of the most complex challenges in the field. His work spans traditional cybersecurity concerns, such as identifying vulnerabilities in AI systems, to cutting-edge tasks like testing for emergent behaviors and conducting AI alignment and safety audits.</p><p>John’s expertise includes evaluating ethical and bias risks, ensuring model robustness, and running adversarial attack simulations to uncover potential weaknesses. Beyond these technical aspects, he also addresses broader safety issues, including scenarios involving CBRNE threats and other high-stakes risks.</p><p>John’s unique combination of technical skills, strategic thinking, and a focus on ethical considerations makes him a leading voice in ensuring that AI technologies are safe, secure, and aligned with human values.</p>]]>
      </content:encoded>
      <pubDate>Thu, 06 Mar 2025 20:59:57 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6ffed456/7f629ded.mp3" length="69529875" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2897</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk with John Vaina, AI Researcher and Red Teamer, about AI risk and safety.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk with John Vaina, AI Researcher and Red Teamer, about AI risk and safety.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#197 - Avoiding burnout and a managing stress with Amanda Berlin, CEO of Mental Health Hackers</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>197</itunes:episode>
      <podcast:episode>197</podcast:episode>
      <itunes:title>#197 - Avoiding burnout and a managing stress with Amanda Berlin, CEO of Mental Health Hackers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e9e83caf-d2d5-4a78-b683-d46f0aee5974</guid>
      <link>https://share.transistor.fm/s/a1c2a15f</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss stress management and avoiding burnout with Amanda Berlin, CEO of <a rel="noreferrer noopener" href="https://www.mentalhealthhackers.org/">Mental Health Hackers</a>.</p><p>Amanda is the Senior Product Manager of Cybersecurity at Blumira, where she collaborates with a talented team to make security more accessible. With a career in IT spanning nearly her entire adult life, her expertise includes infrastructure security, network troubleshooting, purple teaming, and security awareness training.</p><p>Beyond her role at Blumira, Amanda leads Mental Health Hackers, an organization dedicated to addressing the unique mental health challenges faced by cybersecurity professionals and heavy technology users. Through education and advocacy, she helps shine a light on the critical intersection of mental health and the tech industry.</p><p>All of the links:</p><p><a rel="noreferrer noopener" href="https://www.donut.com/">Coffee bot: Donuts</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Fearless-Organization-Psychological-Workplace-Innovation/dp/1119477247/ref=sr_1_1?dib=eyJ2IjoiMSJ9.su7yBNVXvD-ttcz3_i5B6-BciiHH7awgpywJoyb_ft0mC2k5_TAYVcxoAfRlhYvzoPUwKP20mWdF0f5zmSgV8LbIEemn7uv8XHAtdjaYyUsQxZE7WYtqQeHOpiXNU0zAOhwaPDtXAM3gInmMlUjzDXs-snDia14Q7UQs0bXgPduZol9VYJo6r8fLcsahpOPaV9PJlbjf94jvHpmUdupgXPxScYho1qgKUIXnu1XNUEU.ejpuEj8bqeieaQRNrYGjNfNVNMaMF3mSLvMFCQ8fkh8&amp;dib_tag=se&amp;hvadid=555794818068&amp;hvdev=c&amp;hvlocphy=9001616&amp;hvnetw=g&amp;hvqmt=e&amp;hvrand=2098428560201712278&amp;hvtargid=kwd-492637128880&amp;hydadcr=3320_10311060&amp;keywords=the+fearless+organization&amp;qid=1740763294&amp;s=books&amp;sr=1-1">Book: The Fearless Organization</a></p><p><a rel="noreferrer noopener" href="https://www.apa.org/">American Psychological Association</a></p><p>Mental Health hackers next at:   Bsides Charm in Baltimore, Blue Team Con in Chicago... check social media for more</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss stress management and avoiding burnout with Amanda Berlin, CEO of <a rel="noreferrer noopener" href="https://www.mentalhealthhackers.org/">Mental Health Hackers</a>.</p><p>Amanda is the Senior Product Manager of Cybersecurity at Blumira, where she collaborates with a talented team to make security more accessible. With a career in IT spanning nearly her entire adult life, her expertise includes infrastructure security, network troubleshooting, purple teaming, and security awareness training.</p><p>Beyond her role at Blumira, Amanda leads Mental Health Hackers, an organization dedicated to addressing the unique mental health challenges faced by cybersecurity professionals and heavy technology users. Through education and advocacy, she helps shine a light on the critical intersection of mental health and the tech industry.</p><p>All of the links:</p><p><a rel="noreferrer noopener" href="https://www.donut.com/">Coffee bot: Donuts</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Fearless-Organization-Psychological-Workplace-Innovation/dp/1119477247/ref=sr_1_1?dib=eyJ2IjoiMSJ9.su7yBNVXvD-ttcz3_i5B6-BciiHH7awgpywJoyb_ft0mC2k5_TAYVcxoAfRlhYvzoPUwKP20mWdF0f5zmSgV8LbIEemn7uv8XHAtdjaYyUsQxZE7WYtqQeHOpiXNU0zAOhwaPDtXAM3gInmMlUjzDXs-snDia14Q7UQs0bXgPduZol9VYJo6r8fLcsahpOPaV9PJlbjf94jvHpmUdupgXPxScYho1qgKUIXnu1XNUEU.ejpuEj8bqeieaQRNrYGjNfNVNMaMF3mSLvMFCQ8fkh8&amp;dib_tag=se&amp;hvadid=555794818068&amp;hvdev=c&amp;hvlocphy=9001616&amp;hvnetw=g&amp;hvqmt=e&amp;hvrand=2098428560201712278&amp;hvtargid=kwd-492637128880&amp;hydadcr=3320_10311060&amp;keywords=the+fearless+organization&amp;qid=1740763294&amp;s=books&amp;sr=1-1">Book: The Fearless Organization</a></p><p><a rel="noreferrer noopener" href="https://www.apa.org/">American Psychological Association</a></p><p>Mental Health hackers next at:   Bsides Charm in Baltimore, Blue Team Con in Chicago... check social media for more</p>]]>
      </content:encoded>
      <pubDate>Fri, 28 Feb 2025 16:38:43 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a1c2a15f/58893482.mp3" length="20893501" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/PKtjjzFcYXOQbi7EPURs29YmGjD3OHmPM1jloUox3Vo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82Y2Nk/ZTZjMzY0YzM3MTM3/ZWVjOWE2YjM5YjZi/MTg2ZS5wbmc.jpg"/>
      <itunes:duration>1725</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss stress management and avoiding burnout with Amanda Berlin, CEO of Mental Health Hackers.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss stress management and avoiding burnout with Amanda Berlin, CEO of Mental Health Hackers.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#196 - Security challenges in the Arctic with Deepak Dutt, Founder of Zighra</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>196</itunes:episode>
      <podcast:episode>196</podcast:episode>
      <itunes:title>#196 - Security challenges in the Arctic with Deepak Dutt, Founder of Zighra</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0a006978-3613-43ab-ab71-8d0271e7d6ab</guid>
      <link>https://share.transistor.fm/s/c3e3714e</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk about security issues in the Arctic with Deepak Dutt, Founder of <a rel="noreferrer noopener" href="https://zighra.com/">Zighra.</a></p><p>Deepak is a technology leader and entrepreneur on a mission to secure the future against AI-powered threats and to inspire founders to transform their ideas from zero to meaningful impact.</p><p>Deepak’s career began in the software space, inspired by his father’s passion for technology. In his late teens, he founded his first company in the eLearning space, which he successfully led to an acquisition, relocating to Ottawa at the age of 21.</p><p>While in Ottawa, Deepak balanced graduate studies with roles at Newbridge Networks and Nortel, where he spent nearly a decade gaining expertise in product development, go-to-market strategy, and technological innovation. These experiences reinforced his drive to harness technology’s transformative potential.</p><p>In 2009, Deepak founded his second startup, a cloud-based cybersecurity company. Over the years, he has participated in leading accelerators worldwide, including Barclays/Techstars, Creative Destruction Labs, and the Canadian Technology Accelerator. Today, as Founder and CEO of Zighra, he is building an operating system designed to defend against AI-powered attacks, working with financial institutions and governments to deliver robust security solutions powered by explainable AI, behavioral biometrics, and contextual intelligence.</p><p>A passionate advocate of the Zero to Impact philosophy, Deepak is committed to inspiring tech founders to embrace big challenges and develop innovations that drive meaningful change.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk about security issues in the Arctic with Deepak Dutt, Founder of <a rel="noreferrer noopener" href="https://zighra.com/">Zighra.</a></p><p>Deepak is a technology leader and entrepreneur on a mission to secure the future against AI-powered threats and to inspire founders to transform their ideas from zero to meaningful impact.</p><p>Deepak’s career began in the software space, inspired by his father’s passion for technology. In his late teens, he founded his first company in the eLearning space, which he successfully led to an acquisition, relocating to Ottawa at the age of 21.</p><p>While in Ottawa, Deepak balanced graduate studies with roles at Newbridge Networks and Nortel, where he spent nearly a decade gaining expertise in product development, go-to-market strategy, and technological innovation. These experiences reinforced his drive to harness technology’s transformative potential.</p><p>In 2009, Deepak founded his second startup, a cloud-based cybersecurity company. Over the years, he has participated in leading accelerators worldwide, including Barclays/Techstars, Creative Destruction Labs, and the Canadian Technology Accelerator. Today, as Founder and CEO of Zighra, he is building an operating system designed to defend against AI-powered attacks, working with financial institutions and governments to deliver robust security solutions powered by explainable AI, behavioral biometrics, and contextual intelligence.</p><p>A passionate advocate of the Zero to Impact philosophy, Deepak is committed to inspiring tech founders to embrace big challenges and develop innovations that drive meaningful change.</p>]]>
      </content:encoded>
      <pubDate>Tue, 25 Feb 2025 16:40:13 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c3e3714e/5bd9448a.mp3" length="21621341" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/vXZtwafLzb9LXOnT4P2jUusgwirU6cOGeRFxQfD-eMo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNjNi/M2VmOTIyMmM0NWEy/N2QyYmFjZTlhZmRl/NTMyOC5wbmc.jpg"/>
      <itunes:duration>1786</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we talk about security issues in the Arctic with Deepak Dutt, Founder of Zighra.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we talk about security issues in the Arctic with Deepak Dutt, Founder of Zighra.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#195 - Intel Chat: APT tunnelling, BadPilot, CVE-2025-0108, emojis &amp; Kitty Stealer (take 2)</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>193</itunes:episode>
      <podcast:episode>193</podcast:episode>
      <itunes:title>#195 - Intel Chat: APT tunnelling, BadPilot, CVE-2025-0108, emojis &amp; Kitty Stealer (take 2)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">47f687bb-051d-4d1a-90f4-148c97308331</guid>
      <link>https://share.transistor.fm/s/9c4ee3d0</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community<a rel="noreferrer noopener" href="https://slack.limacharlie.io/"> Slack channel</a>.</p><p>Network traffic tunneling is a technique used by attackers to bypass security controls and exfiltrate data or establish covert communication channels. Threat actors use various tunneling methods, including DNS tunneling, HTTP/S tunneling, and ICMP tunneling, each with its own advantages depending on the target environment.</p><p>The "BadPilot" hacking campaign has been linked to Russia's Sandworm threat group, a unit of the GRU known for cyber espionage and disruptive attacks.</p><p>GreyNoise has observed active exploitation of CVE-2025-0108, a critical authentication bypass vulnerability in Palo Alto Networks’ PAN-OS. This vulnerability allows unauthenticated attackers to gain administrative access to affected firewall devices, posing a significant risk to organizations relying on PAN-OS for network security.</p><p>Security researcher Paul Butler has demonstrated a novel technique for smuggling arbitrary data using emojis, leveraging the way modern text encoding and rendering systems handle Unicode characters.</p><p>Kitty Stealer is a newly identified malware targeting macOS systems, designed to steal sensitive user data such as credentials, browser cookies, and cryptocurrency wallets.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community<a rel="noreferrer noopener" href="https://slack.limacharlie.io/"> Slack channel</a>.</p><p>Network traffic tunneling is a technique used by attackers to bypass security controls and exfiltrate data or establish covert communication channels. Threat actors use various tunneling methods, including DNS tunneling, HTTP/S tunneling, and ICMP tunneling, each with its own advantages depending on the target environment.</p><p>The "BadPilot" hacking campaign has been linked to Russia's Sandworm threat group, a unit of the GRU known for cyber espionage and disruptive attacks.</p><p>GreyNoise has observed active exploitation of CVE-2025-0108, a critical authentication bypass vulnerability in Palo Alto Networks’ PAN-OS. This vulnerability allows unauthenticated attackers to gain administrative access to affected firewall devices, posing a significant risk to organizations relying on PAN-OS for network security.</p><p>Security researcher Paul Butler has demonstrated a novel technique for smuggling arbitrary data using emojis, leveraging the way modern text encoding and rendering systems handle Unicode characters.</p><p>Kitty Stealer is a newly identified malware targeting macOS systems, designed to steal sensitive user data such as credentials, browser cookies, and cryptocurrency wallets.</p>]]>
      </content:encoded>
      <pubDate>Fri, 21 Feb 2025 15:17:23 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9c4ee3d0/08abe96f.mp3" length="25504630" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/X6wpqYyyT9omqjKwwPF3HGvwiRq-geR9A05Grzzg8ls/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iODkx/NzcwZTNkYjAxZmJm/OTQ2OWRlYzJmODE3/ZWJjYi5wbmc.jpg"/>
      <itunes:duration>2109</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#194 – Exploring MSSP partnerships and technology providers with Raffaele Mautone, CEO of Judy Security</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>194</itunes:episode>
      <podcast:episode>194</podcast:episode>
      <itunes:title>#194 – Exploring MSSP partnerships and technology providers with Raffaele Mautone, CEO of Judy Security</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">328bf186-bbc3-4c25-a9fa-fc29b9af0255</guid>
      <link>https://share.transistor.fm/s/c3db1622</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we explore MSSP partnerships and technology providers with Raffaele Mautone, CEO of <a rel="noreferrer noopener" href="https://www.judysecurity.ai/">Judy Security</a>.</p><p>Raffaele brings a strong background in IT, sales, and operations, with extensive experience in cybersecurity and IT shaping the foundation of Judy Security. He has a proven track record of leading teams through successful acquisitions, strategic planning, and large-scale program deployments.</p><p>Throughout his career, he has worked with major companies like Duo, FireEye, McAfee, and Dell, focusing on marketing and sales strategies, business process improvements, and go-to-market programs.</p><p>Judy Security delivers enterprise-grade cybersecurity tailored for SMBs and MSPs. Their AI-powered platform is affordable, intuitive, and designed to seamlessly integrate with MSP business models while addressing the unique security challenges of SMBs. With Judy Security, businesses can stay protected with advanced, easy-to-use cybersecurity solutions—because safeguarding data shouldn’t be complicated.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we explore MSSP partnerships and technology providers with Raffaele Mautone, CEO of <a rel="noreferrer noopener" href="https://www.judysecurity.ai/">Judy Security</a>.</p><p>Raffaele brings a strong background in IT, sales, and operations, with extensive experience in cybersecurity and IT shaping the foundation of Judy Security. He has a proven track record of leading teams through successful acquisitions, strategic planning, and large-scale program deployments.</p><p>Throughout his career, he has worked with major companies like Duo, FireEye, McAfee, and Dell, focusing on marketing and sales strategies, business process improvements, and go-to-market programs.</p><p>Judy Security delivers enterprise-grade cybersecurity tailored for SMBs and MSPs. Their AI-powered platform is affordable, intuitive, and designed to seamlessly integrate with MSP business models while addressing the unique security challenges of SMBs. With Judy Security, businesses can stay protected with advanced, easy-to-use cybersecurity solutions—because safeguarding data shouldn’t be complicated.</p>]]>
      </content:encoded>
      <pubDate>Wed, 19 Feb 2025 13:00:17 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c3db1622/01dc2373.mp3" length="22162757" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Ana4i4MhA6Gck8NWizQNVMQzlHv38cjxX-piI5Pp9aA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMjI4/ZjUwMDE5YThmNzEw/Yjg0NDEzNTliODM5/NzhjMi5wbmc.jpg"/>
      <itunes:duration>1831</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we explore MSSP partnerships and technology providers with Raffaele Mautone, CEO of Judy Security.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we explore MSSP partnerships and technology providers with Raffaele Mautone, CEO of Judy Security.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#193 - Intel Chat: Ransomware drops, 8Base, XE Group, SolarWinds-esque attack &amp; cyber-espionage in South Asia</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>193</itunes:episode>
      <podcast:episode>193</podcast:episode>
      <itunes:title>#193 - Intel Chat: Ransomware drops, 8Base, XE Group, SolarWinds-esque attack &amp; cyber-espionage in South Asia</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2e6414ae-a744-41fd-b0e0-616f8b9fc1af</guid>
      <link>https://share.transistor.fm/s/2253b52d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Ransomware payments saw a significant drop in 2024, falling by 35% compared to the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/ransomware-payments-fell-by-35-percent-in-2024-totalling-813-550-000/">previous year</a>. </li><li>Law enforcement agencies have arrested a suspected core member of the 8Base ransomware group, marking a significant development in efforts to <a rel="noreferrer noopener" href="https://www.theregister.com/2025/02/10/8base_police_arrrest/">combat cybercrime</a>. </li><li>The XE Group, a financially motivated cybercrime organization, has shifted its tactics from traditional card-skimming attacks to more sophisticated <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/xe-group-shifts-card-skimming-supply-chain-attacks">supply chain compromises</a>.</li><li>Security researchers at watchTowr have demonstrated a supply chain attack technique that surpasses the scale and stealth of the infamous <a rel="noreferrer noopener" href="https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/">SolarWinds breach</a>.</li><li>A newly discovered cyber-espionage campaign is targeting government and military entities in South Asia, according to <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/espionage-campaign-targets-south-asian-entities/">researchers at Unit 42</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Ransomware payments saw a significant drop in 2024, falling by 35% compared to the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/ransomware-payments-fell-by-35-percent-in-2024-totalling-813-550-000/">previous year</a>. </li><li>Law enforcement agencies have arrested a suspected core member of the 8Base ransomware group, marking a significant development in efforts to <a rel="noreferrer noopener" href="https://www.theregister.com/2025/02/10/8base_police_arrrest/">combat cybercrime</a>. </li><li>The XE Group, a financially motivated cybercrime organization, has shifted its tactics from traditional card-skimming attacks to more sophisticated <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/xe-group-shifts-card-skimming-supply-chain-attacks">supply chain compromises</a>.</li><li>Security researchers at watchTowr have demonstrated a supply chain attack technique that surpasses the scale and stealth of the infamous <a rel="noreferrer noopener" href="https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/">SolarWinds breach</a>.</li><li>A newly discovered cyber-espionage campaign is targeting government and military entities in South Asia, according to <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/espionage-campaign-targets-south-asian-entities/">researchers at Unit 42</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 13 Feb 2025 18:39:36 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2253b52d/137d2936.mp3" length="24036062" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/xF0M0fberpSdc3-j2sXsMo_GJSXDfndqKQc9lE4u8Mw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mYzZh/YWMyZmY0MDJmODVk/MTNiOGYwNDgxYzM4/NzhlZi5wbmc.jpg"/>
      <itunes:duration>1987</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#192 - Talent acquisition, training, and retention in the MSSP space with Paul Ihme, Cofounder &amp; Managing Principle at Soteria</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>192</itunes:episode>
      <podcast:episode>192</podcast:episode>
      <itunes:title>#192 - Talent acquisition, training, and retention in the MSSP space with Paul Ihme, Cofounder &amp; Managing Principle at Soteria</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d091959e-9c48-4780-bffb-0c27782de585</guid>
      <link>https://share.transistor.fm/s/31fdaf34</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about talent acquisition, training, and retention in the MSSP space with Paul Ihme, Cofounder &amp; Managing Principle at <a rel="noreferrer noopener" href="https://soteria.io/">Soteria</a>.</p><p>Paul is a cybersecurity professional with extensive experience in both federal and private sectors. He is the co-founder and managing principal of Soteria, a firm that provides tailored cybersecurity solutions and strategic advisory services to help businesses defend against cyber threats 24/7. Soteria specializes in managed detection and response, domain monitoring, and risk management for Microsoft 365 environments among other things. Prior to founding Soteria, Paul held key roles in cybersecurity, including Vice President of Active Network Defense at JPMorgan Chase and as a Cyber Warfare Operator in the U.S. Air Force. Today, we are going to be discussing what it takes to Build a Skilled Team and exploring his experience with Talent acquisition, training, and retention in the MSSP space.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about talent acquisition, training, and retention in the MSSP space with Paul Ihme, Cofounder &amp; Managing Principle at <a rel="noreferrer noopener" href="https://soteria.io/">Soteria</a>.</p><p>Paul is a cybersecurity professional with extensive experience in both federal and private sectors. He is the co-founder and managing principal of Soteria, a firm that provides tailored cybersecurity solutions and strategic advisory services to help businesses defend against cyber threats 24/7. Soteria specializes in managed detection and response, domain monitoring, and risk management for Microsoft 365 environments among other things. Prior to founding Soteria, Paul held key roles in cybersecurity, including Vice President of Active Network Defense at JPMorgan Chase and as a Cyber Warfare Operator in the U.S. Air Force. Today, we are going to be discussing what it takes to Build a Skilled Team and exploring his experience with Talent acquisition, training, and retention in the MSSP space.</p>]]>
      </content:encoded>
      <pubDate>Tue, 11 Feb 2025 14:41:49 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/31fdaf34/6de4c5a9.mp3" length="28867286" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/chZguQ2wF28yj--e3CMuwUOxTG82mbnREg6w0Jup2Vg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNTQ4/YTcyMGY1ODg2M2Jm/YTA5YTE2ZDhhYzUz/MTA3Yy5wbmc.jpg"/>
      <itunes:duration>2389</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk about talent acquisition, training, and retention in the MSSP space with Paul Ihme, Cofounder &amp;amp; Managing Principle at Soteria.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk about talent acquisition, training, and retention in the MSSP space with Paul Ihme, Cofounder &amp;amp; Managing Principle at Soteria.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#191 - Intel Chat: Lumma Stealer, xWorm, WSDOT &amp; FortiOS</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>191</itunes:episode>
      <podcast:episode>191</podcast:episode>
      <itunes:title>#191 - Intel Chat: Lumma Stealer, xWorm, WSDOT &amp; FortiOS</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f9a4e5d8-0ae6-450c-b865-55ecb0cc2e91</guid>
      <link>https://share.transistor.fm/s/c45760c1</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Lumma Stealer, an information-stealing malware, has been observed using new evasion techniques to <a rel="noreferrer noopener" href="https://www.netskope.com/blog/lumma-stealer-fake-captchas-new-techniques-to-evade-detection">avoid detection</a>.</li><li>Researchers at CloudSEK have uncovered a trojanized version of the xWorm Remote Access Trojan (RAT) builder that is being secretly <a rel="noreferrer noopener" href="https://www.cloudsek.com/blog/no-honour-among-thieves-uncovering-a-trojanized-xworm-rat-builder-propagated-by-threat-actors-and-disrupting-its-operations">distributed among cybercriminals</a>. </li><li>A recent disclosure by security researcher Zach Latta highlights how the Washington State Department of Transportation (WSDOT) inadvertently exposed sensitive server <a rel="noreferrer noopener" href="https://gist.github.com/zachlatta/f86317493654b550c689dc6509973aa4">credentials on its public website</a>.</li><li>A critical authentication bypass vulnerability (CVE-2024-21762) in Fortinet’s FortiOS has been actively exploited in the wild, allowing attackers to execute arbitrary code or gain unauthorized <a rel="noreferrer noopener" href="https://cybersecuritynews.com/fortios-auth-bypass-vulnerability-exploited/">access to affected systems</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Lumma Stealer, an information-stealing malware, has been observed using new evasion techniques to <a rel="noreferrer noopener" href="https://www.netskope.com/blog/lumma-stealer-fake-captchas-new-techniques-to-evade-detection">avoid detection</a>.</li><li>Researchers at CloudSEK have uncovered a trojanized version of the xWorm Remote Access Trojan (RAT) builder that is being secretly <a rel="noreferrer noopener" href="https://www.cloudsek.com/blog/no-honour-among-thieves-uncovering-a-trojanized-xworm-rat-builder-propagated-by-threat-actors-and-disrupting-its-operations">distributed among cybercriminals</a>. </li><li>A recent disclosure by security researcher Zach Latta highlights how the Washington State Department of Transportation (WSDOT) inadvertently exposed sensitive server <a rel="noreferrer noopener" href="https://gist.github.com/zachlatta/f86317493654b550c689dc6509973aa4">credentials on its public website</a>.</li><li>A critical authentication bypass vulnerability (CVE-2024-21762) in Fortinet’s FortiOS has been actively exploited in the wild, allowing attackers to execute arbitrary code or gain unauthorized <a rel="noreferrer noopener" href="https://cybersecuritynews.com/fortios-auth-bypass-vulnerability-exploited/">access to affected systems</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 04 Feb 2025 19:25:51 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c45760c1/d824823f.mp3" length="37105785" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/uC_TqXP9CEegd-K-14rnhuYgkdelXgwusxUZV_1sGKk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81M2Zi/MDg1YzZlODA1NDE5/MDk5ZmNlOGY4ODg0/OGQwOC5wbmc.jpg"/>
      <itunes:duration>1546</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#190 - How MSSPs can help clients meet regulatory requirements with Garret Grajek, CEO at YouAttest</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>190</itunes:episode>
      <podcast:episode>190</podcast:episode>
      <itunes:title>#190 - How MSSPs can help clients meet regulatory requirements with Garret Grajek, CEO at YouAttest</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">221010dc-a077-4560-8b64-c889db939945</guid>
      <link>https://share.transistor.fm/s/98744068</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Garret Grajek, CEO of <a rel="noreferrer noopener" href="https://youattest.com/">YouAttest</a>, about how MSSPs help clients meet regulatory requirements and what it means for the MSSP.</p><p>Garret is a certified security leader with nearly 30 years of experience in information security. Garret is widely recognized as a visionary in identity, access, and authentication, holding 13 patents in areas such as x.509, mobile security, single sign-on (SSO), federation, and multi-factor technologies. Over the course of his career, he has contributed to major security projects for prominent commercial clients like Dish Networks, Office Depot, TicketMaster, and E*Trade, as well as public sector organizations including the U.S. Navy and the EPA.</p><p>Garret began his career as a security programmer at Texas Instruments, IBM, and Tandem Computers, later advancing to key roles at RSA, Netegrity, and Cisco. He is also the founder and creator of SecureAuth IdP, a two-factor authentication and SSO platform. Known for his expertise in security architecture, product development, and leadership, Garret is a thought leader in modern IT architecture, including mobile deployments, cloud, hybrid environments, and advanced authentication technologies.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Garret Grajek, CEO of <a rel="noreferrer noopener" href="https://youattest.com/">YouAttest</a>, about how MSSPs help clients meet regulatory requirements and what it means for the MSSP.</p><p>Garret is a certified security leader with nearly 30 years of experience in information security. Garret is widely recognized as a visionary in identity, access, and authentication, holding 13 patents in areas such as x.509, mobile security, single sign-on (SSO), federation, and multi-factor technologies. Over the course of his career, he has contributed to major security projects for prominent commercial clients like Dish Networks, Office Depot, TicketMaster, and E*Trade, as well as public sector organizations including the U.S. Navy and the EPA.</p><p>Garret began his career as a security programmer at Texas Instruments, IBM, and Tandem Computers, later advancing to key roles at RSA, Netegrity, and Cisco. He is also the founder and creator of SecureAuth IdP, a two-factor authentication and SSO platform. Known for his expertise in security architecture, product development, and leadership, Garret is a thought leader in modern IT architecture, including mobile deployments, cloud, hybrid environments, and advanced authentication technologies.</p>]]>
      </content:encoded>
      <pubDate>Mon, 03 Feb 2025 18:04:03 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/98744068/6b86765d.mp3" length="27778866" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Fr2SmynCmkUe4pWoLB15BGAhSUuuE2WBu_DtJdKY3cI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jZWVi/MGFmMzk0MGY1NzM4/MjYxNjI3YzA3YWRj/NWMxNi5wbmc.jpg"/>
      <itunes:duration>2299</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Garret Grajek, CEO of YouAttest, about how MSSPs help clients meet regulatory requirements and what it means for the MSSP.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Garret Grajek, CEO of YouAttest, about how MSSPs help clients meet regulatory requirements and what it means for the MSSP.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#189 - Intel Chat: Docker, LDAPNightmare, Codefinger &amp; Fortinet FortiGate</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>189</itunes:episode>
      <podcast:episode>189</podcast:episode>
      <itunes:title>#189 - Intel Chat: Docker, LDAPNightmare, Codefinger &amp; Fortinet FortiGate</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9833733c-df6c-4b24-9765-a13317e37aa4</guid>
      <link>https://share.transistor.fm/s/32da777b</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>From earlier this week, The Docker Systems Status page reports an ongoing issue affecting Docker Desktop on macOS, where malware alerts are triggered by macOS identifying com.docker.vmnetd or com.docker.socket as <a rel="noreferrer noopener" href="https://www.dockerstatus.com/">potential threats</a>. </li><li>SafeBreach Labs has released a proof-of-concept (PoC) exploit for CVE-2024-49113, a critical vulnerability in the Lightweight Directory Access Protocol (LDAP) that impacts unpatched Windows Servers, including <a rel="noreferrer noopener" href="https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49112/">Active Directory Domain Controllers (DCs)</a>.</li><li>The Halcyon RISE team has uncovered a novel ransomware campaign targeting Amazon S3 buckets, exploiting AWS’s Server-Side Encryption with <a rel="noreferrer noopener" href="https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c">Customer-Provided Keys (SSE-C)</a>.</li><li>A recent campaign has been targeting Fortinet FortiGate firewalls with exposed management interfaces, likely exploiting a zero-day vulnerability to gain <a rel="noreferrer noopener" href="https://thehackernews.com/2025/01/zero-day-vulnerability-suspected-in.html?m=1">unauthorized administrative access</a>. </li><li>Sophos recently reported on two distinct ransomware campaigns utilizing unique techniques to pressure <a rel="noreferrer noopener" href="https://news.sophos.com/en-us/2025/01/21/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing/">victims and evade detection</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>From earlier this week, The Docker Systems Status page reports an ongoing issue affecting Docker Desktop on macOS, where malware alerts are triggered by macOS identifying com.docker.vmnetd or com.docker.socket as <a rel="noreferrer noopener" href="https://www.dockerstatus.com/">potential threats</a>. </li><li>SafeBreach Labs has released a proof-of-concept (PoC) exploit for CVE-2024-49113, a critical vulnerability in the Lightweight Directory Access Protocol (LDAP) that impacts unpatched Windows Servers, including <a rel="noreferrer noopener" href="https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49112/">Active Directory Domain Controllers (DCs)</a>.</li><li>The Halcyon RISE team has uncovered a novel ransomware campaign targeting Amazon S3 buckets, exploiting AWS’s Server-Side Encryption with <a rel="noreferrer noopener" href="https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c">Customer-Provided Keys (SSE-C)</a>.</li><li>A recent campaign has been targeting Fortinet FortiGate firewalls with exposed management interfaces, likely exploiting a zero-day vulnerability to gain <a rel="noreferrer noopener" href="https://thehackernews.com/2025/01/zero-day-vulnerability-suspected-in.html?m=1">unauthorized administrative access</a>. </li><li>Sophos recently reported on two distinct ransomware campaigns utilizing unique techniques to pressure <a rel="noreferrer noopener" href="https://news.sophos.com/en-us/2025/01/21/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing/">victims and evade detection</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 28 Jan 2025 15:09:42 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/32da777b/c2592858.mp3" length="25198334" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Rc21uF0kIOWGyQIcEL-bRxff3kjNBKtkRYEbWAhys60/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yMzIx/Y2E3MDFiZDIwZDYz/NmM2ZjFmMWM2ZDYw/YWU3Yy5wbmc.jpg"/>
      <itunes:duration>2084</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#188 - The MSSP Alert 2024 Pricing Benchmark Report with Sharon Florentine, Senior Managing Editor at CyberRisk Alliance</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>188</itunes:episode>
      <podcast:episode>188</podcast:episode>
      <itunes:title>#188 - The MSSP Alert 2024 Pricing Benchmark Report with Sharon Florentine, Senior Managing Editor at CyberRisk Alliance</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">483722a5-4317-4b0e-a66e-8453b24e6328</guid>
      <link>https://share.transistor.fm/s/8da9be3d</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Sharon Florentine, Senior Managing Editor at CyberRisk Alliance, about the MSSP Alert 2024 Pricing Benchmark Report.</p><p>Sharon is a master technology storyteller and editor with over two decades of experience in shaping the way we understand and engage with technology. Sharon's career spans an impressive range of platforms, from books and print magazines to podcasts, live events, and digital media. She's covered everything from AI and cybersecurity to career development and diversity in tech.</p><p>Currently, Sharon is the Senior Managing Editor for CyberRisk Alliance's channel brands, ChannelE2E and MSSP Alert, where she’s helping to expand the reach of these vital resources for the IT and cybersecurity communities. Sharon has a rich history of editorial leadership, including her previous role as Managing Editor at Techstrong Group, overseeing Cloud Native Now, DevOps.com, and Security Boulevard.</p><p>She joins us to discuss the inaugural 2024 MSSP Pricing Benchmark Report—a critical resource for understanding the evolving managed security services market. </p><p>You can get a copy of the report here: <a rel="noreferrer noopener" href="https://www.msspalert.com/whitepaper/mssp-alert-2024-pricing-benchmark">https://www.msspalert.com/whitepaper/mssp-alert-2024-pricing-benchmark</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Sharon Florentine, Senior Managing Editor at CyberRisk Alliance, about the MSSP Alert 2024 Pricing Benchmark Report.</p><p>Sharon is a master technology storyteller and editor with over two decades of experience in shaping the way we understand and engage with technology. Sharon's career spans an impressive range of platforms, from books and print magazines to podcasts, live events, and digital media. She's covered everything from AI and cybersecurity to career development and diversity in tech.</p><p>Currently, Sharon is the Senior Managing Editor for CyberRisk Alliance's channel brands, ChannelE2E and MSSP Alert, where she’s helping to expand the reach of these vital resources for the IT and cybersecurity communities. Sharon has a rich history of editorial leadership, including her previous role as Managing Editor at Techstrong Group, overseeing Cloud Native Now, DevOps.com, and Security Boulevard.</p><p>She joins us to discuss the inaugural 2024 MSSP Pricing Benchmark Report—a critical resource for understanding the evolving managed security services market. </p><p>You can get a copy of the report here: <a rel="noreferrer noopener" href="https://www.msspalert.com/whitepaper/mssp-alert-2024-pricing-benchmark">https://www.msspalert.com/whitepaper/mssp-alert-2024-pricing-benchmark</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 23 Jan 2025 14:25:32 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8da9be3d/aaef2282.mp3" length="18348495" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/wUjS6_C_0DbStEmx6cRctJgM73MC3i_VtOOzbZM_72U/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMWQ5/OTFmMWNmNTg1NjNh/N2U2OTUwZTE5YjQw/Njc2Mi5wbmc.jpg"/>
      <itunes:duration>1513</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Sharon Florentine, Senior Managing Editor at CyberRisk Alliance, about the MSSP Alert 2024 Pricing Benchmark Report.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Sharon Florentine, Senior Managing Editor at CyberRisk Alliance, about the MSSP Alert 2024 Pricing Benchmark Report.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#187 - Automation in MSSP Operations with David Burkett, Cloud Security Researcher at Corelight</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>187</itunes:episode>
      <podcast:episode>187</podcast:episode>
      <itunes:title>#187 - Automation in MSSP Operations with David Burkett, Cloud Security Researcher at Corelight</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5584f7f9-c8c9-4c1f-92b2-c8144893ab89</guid>
      <link>https://share.transistor.fm/s/d3b5f804</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about automation in MSSP operations with David Burkett, Cloud Security Researcher at Core light. </p><p>David has deep expertise in cloud threat detection and automation. Over the course of his career, David has built and optimized three different Cyber Security Operations Centers for MSSP and MDR providers, demonstrating his unparalleled skill in scaling security operations through automation and efficient processes.</p><p>David has consulted for over 40 Fortune 500 companies and large federal organizations, helping them design and implement SOAR platforms and playbooks that enhance detection and response capabilities. He also actively contributes to the open-source detection project Sigma, showcasing his dedication to advancing the cybersecurity community.</p><p>Among his many accolades, David was part of a team that received the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award, recognizing their SOC as one of the top 1% in cybersecurity programs for cleared facilities. He also holds a robust set of GIAC certifications, reinforcing his technical expertise in threat intelligence, cloud security, and playbook design.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about automation in MSSP operations with David Burkett, Cloud Security Researcher at Core light. </p><p>David has deep expertise in cloud threat detection and automation. Over the course of his career, David has built and optimized three different Cyber Security Operations Centers for MSSP and MDR providers, demonstrating his unparalleled skill in scaling security operations through automation and efficient processes.</p><p>David has consulted for over 40 Fortune 500 companies and large federal organizations, helping them design and implement SOAR platforms and playbooks that enhance detection and response capabilities. He also actively contributes to the open-source detection project Sigma, showcasing his dedication to advancing the cybersecurity community.</p><p>Among his many accolades, David was part of a team that received the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award, recognizing their SOC as one of the top 1% in cybersecurity programs for cleared facilities. He also holds a robust set of GIAC certifications, reinforcing his technical expertise in threat intelligence, cloud security, and playbook design.</p>]]>
      </content:encoded>
      <pubDate>Tue, 14 Jan 2025 16:56:36 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d3b5f804/4db4a133.mp3" length="18734953" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/OVX1NeA9RCT6U-AnhFot3EoodQLy_lOqTh8oJdMHPKo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iNDUy/OTAzOGM2MmZkZmM5/M2I4NDUzYjlhNjRh/N2RhMC5wbmc.jpg"/>
      <itunes:duration>1545</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk about automation in MSSP operations with David Burkett, Cloud Security Researcher at Core light.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk about automation in MSSP operations with David Burkett, Cloud Security Researcher at Core light.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#186 - Intel Chat: Amit Yoran, USDoD, BeyondTrust &amp; LDAPNightmare</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>186</itunes:episode>
      <podcast:episode>186</podcast:episode>
      <itunes:title>#186 - Intel Chat: Amit Yoran, USDoD, BeyondTrust &amp; LDAPNightmare</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f60eaa2c-2893-40c5-ab04-683b45cd2d4f</guid>
      <link>https://share.transistor.fm/s/63f29ec2</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>We pause to honor the life and legacy of Amit Yoran, a visionary leader in the world of cybersecurity who passed away on January 4, 2025, after battling cancer.</li><li>In April 2024, a threat actor known as "USDoD" advertised a massive database for sale on BreachForums, claiming it contained 2.9 billion records encompassing personal information of individuals from the<a rel="noreferrer noopener" href="https://x.com/vxunderground/status/1872492830553432311?s=46"> United States, United Kingdom, and Canada</a>. </li><li>In December 2024, the U.S. Treasury Department disclosed a significant cybersecurity breach attributed to <a rel="noreferrer noopener" href="https://apnews.com/article/china-hacking-treasury-department-8942106afabeac96010057e05c67c9d5">Chinese state-sponsored hackers</a>. </li><li>SafeBreach Labs has published a proof-of-concept (PoC) exploit for CVE-2024-49113, dubbed "LDAPNightmare." This vulnerability affects Windows Servers using the Lightweight Directory Access Protocol (LDAP) and enables attackers to crash <a rel="noreferrer noopener" href="https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49112/">unpatched systems</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>We pause to honor the life and legacy of Amit Yoran, a visionary leader in the world of cybersecurity who passed away on January 4, 2025, after battling cancer.</li><li>In April 2024, a threat actor known as "USDoD" advertised a massive database for sale on BreachForums, claiming it contained 2.9 billion records encompassing personal information of individuals from the<a rel="noreferrer noopener" href="https://x.com/vxunderground/status/1872492830553432311?s=46"> United States, United Kingdom, and Canada</a>. </li><li>In December 2024, the U.S. Treasury Department disclosed a significant cybersecurity breach attributed to <a rel="noreferrer noopener" href="https://apnews.com/article/china-hacking-treasury-department-8942106afabeac96010057e05c67c9d5">Chinese state-sponsored hackers</a>. </li><li>SafeBreach Labs has published a proof-of-concept (PoC) exploit for CVE-2024-49113, dubbed "LDAPNightmare." This vulnerability affects Windows Servers using the Lightweight Directory Access Protocol (LDAP) and enables attackers to crash <a rel="noreferrer noopener" href="https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49112/">unpatched systems</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 08 Jan 2025 06:49:09 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/63f29ec2/553bafc7.mp3" length="34334098" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/iv1yGVCLsOLtYCMFbFR6ZZKc9SThf35_RCx4HGgZ-q8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83NjQ2/OGI2MjRjYzFkNjRk/NzI0NjgzMGUwZjA1/MTlkMi5wbmc.jpg"/>
      <itunes:duration>1431</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#185 - Bootstrapping an MSSP with Nick Gipson, Founder &amp; CEO at Gipson Cyber</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>185</itunes:episode>
      <podcast:episode>185</podcast:episode>
      <itunes:title>#185 - Bootstrapping an MSSP with Nick Gipson, Founder &amp; CEO at Gipson Cyber</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">47070cb8-6f90-4034-8248-c29f32307d43</guid>
      <link>https://share.transistor.fm/s/f11ca98e</link>
      <description>
        <![CDATA[<p>MSSPs and other security service providers comprise the backbone of the cybersecurity industry. They are the organizations on the front line that keep the world running in the face of ever more sophisticated adversaries. </p><p>In this special series we are going to be exploring a variety of topics with seasoned experts around the ways they have learned to improve the effectiveness of their organizations.</p><p>Our guest today is Nick Gipson - the founder and CEO of <a rel="noreferrer noopener" href="https://gipsoncyber.com/">Gipson Cyber</a>.</p><p> Nick founded Gipson Cyber in February 2023 to provide affordable, subscription-based cybersecurity services to small businesses. With nearly a decade of experience as a digital forensics investigator for the Department of Defense and Fortune 100 companies, Nick recognized a gap in cybersecurity solutions for smaller organizations. Determined to address this, he built Gipson Cyber to deliver proffesional-grade protection to industries like accounting, finance, legal, and healthcare.</p><p>Nick’s company focuses on equipping small businesses with the tools to prevent cyber threats before they happen, backed by a team with over 20 years of expertise in the field. Today, we’ll explore not only the challenges small businesses face in cybersecurity but also the lessons Nick has learned in building a managed security service provider from the ground up.</p><p> Nick Gipson, the founder of Gipson Cyber, a company he launched in February 2023 to provide affordable, subscription-based cybersecurity services to small businesses. With nearly a decade of experience as a digital forensics investigator for the Department of Defense and Fortune 100 companies, Nick recognized a gap in cybersecurity solutions for smaller organizations. Determined to address this, he built Gipson Cyber to deliver proffesional-grade protection to industries like accounting, finance, legal, and healthcare.</p><p>Nick’s company focuses on equipping small businesses with the tools to prevent cyber threats before they happen, backed by a team with over 20 years of expertise in the field. Today, we’ll explore not only the challenges small businesses face in cybersecurity but also the lessons Nick has learned in building a managed security service provider from the ground up.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>MSSPs and other security service providers comprise the backbone of the cybersecurity industry. They are the organizations on the front line that keep the world running in the face of ever more sophisticated adversaries. </p><p>In this special series we are going to be exploring a variety of topics with seasoned experts around the ways they have learned to improve the effectiveness of their organizations.</p><p>Our guest today is Nick Gipson - the founder and CEO of <a rel="noreferrer noopener" href="https://gipsoncyber.com/">Gipson Cyber</a>.</p><p> Nick founded Gipson Cyber in February 2023 to provide affordable, subscription-based cybersecurity services to small businesses. With nearly a decade of experience as a digital forensics investigator for the Department of Defense and Fortune 100 companies, Nick recognized a gap in cybersecurity solutions for smaller organizations. Determined to address this, he built Gipson Cyber to deliver proffesional-grade protection to industries like accounting, finance, legal, and healthcare.</p><p>Nick’s company focuses on equipping small businesses with the tools to prevent cyber threats before they happen, backed by a team with over 20 years of expertise in the field. Today, we’ll explore not only the challenges small businesses face in cybersecurity but also the lessons Nick has learned in building a managed security service provider from the ground up.</p><p> Nick Gipson, the founder of Gipson Cyber, a company he launched in February 2023 to provide affordable, subscription-based cybersecurity services to small businesses. With nearly a decade of experience as a digital forensics investigator for the Department of Defense and Fortune 100 companies, Nick recognized a gap in cybersecurity solutions for smaller organizations. Determined to address this, he built Gipson Cyber to deliver proffesional-grade protection to industries like accounting, finance, legal, and healthcare.</p><p>Nick’s company focuses on equipping small businesses with the tools to prevent cyber threats before they happen, backed by a team with over 20 years of expertise in the field. Today, we’ll explore not only the challenges small businesses face in cybersecurity but also the lessons Nick has learned in building a managed security service provider from the ground up.</p>]]>
      </content:encoded>
      <pubDate>Tue, 07 Jan 2025 07:11:38 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f11ca98e/8eb218e5.mp3" length="34100888" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/fgfZDn1AgAH-BLBCTL5oNBLEglu96od0H27ZdOGPLdU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNTA1/ZDhkNGQyYTk4NDVh/MDZmOTI5YTczM2Fl/ZmMwOC5wbmc.jpg"/>
      <itunes:duration>1421</itunes:duration>
      <itunes:summary>MSSPs and other security service providers comprise the backbone of the cybersecurity industry. In this special series we are going to be exploring a variety of topics with seasoned experts around the ways they have learned to improve the effectiveness of their organizations.</itunes:summary>
      <itunes:subtitle>MSSPs and other security service providers comprise the backbone of the cybersecurity industry. In this special series we are going to be exploring a variety of topics with seasoned experts around the ways they have learned to improve the effectiveness of</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#184 - Hacker Holidays: The Colonial Pipeline</title>
      <itunes:season>4</itunes:season>
      <podcast:season>4</podcast:season>
      <itunes:episode>184</itunes:episode>
      <podcast:episode>184</podcast:episode>
      <itunes:title>#184 - Hacker Holidays: The Colonial Pipeline</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b81066d4-0ceb-4723-be11-b01bbdfab559</guid>
      <link>https://share.transistor.fm/s/c7662799</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at <a rel="noreferrer noopener" href="https://www.bugcrowd.com/">Bugcrowd</a>, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeline</p><p>On May 7, 2021, Colonial Pipeline, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a ransomware cyberattack that impacted computerized equipment managing the pipeline. The Colonial Pipeline Company halted all pipeline operations to contain the attack. Overseen by the FBI, the company paid the amount that was asked by the hacker group (75 bitcoin or $4.4 million USD) within several hours; upon receipt of the ransom, an IT tool was provided to the Colonial Pipeline Company by DarkSide to restore the system. However, the tool required a very long processing time to restore the system to a working state.</p><p>This episode was written by the talented <a rel="noreferrer noopener" href="https://www.linkedin.com/in/nate-nelson-75589611b/">Nathaniel Nelson</a>.</p><p>Casey Ellis can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/caseyjohnellis/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at <a rel="noreferrer noopener" href="https://www.bugcrowd.com/">Bugcrowd</a>, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeline</p><p>On May 7, 2021, Colonial Pipeline, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a ransomware cyberattack that impacted computerized equipment managing the pipeline. The Colonial Pipeline Company halted all pipeline operations to contain the attack. Overseen by the FBI, the company paid the amount that was asked by the hacker group (75 bitcoin or $4.4 million USD) within several hours; upon receipt of the ransom, an IT tool was provided to the Colonial Pipeline Company by DarkSide to restore the system. However, the tool required a very long processing time to restore the system to a working state.</p><p>This episode was written by the talented <a rel="noreferrer noopener" href="https://www.linkedin.com/in/nate-nelson-75589611b/">Nathaniel Nelson</a>.</p><p>Casey Ellis can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/caseyjohnellis/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 01 Jan 2025 19:48:33 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c7662799/72755bda.mp3" length="15928273" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Hva5pxxor_MffEKlDt3PRByna8G5FvTsnifipBfT-9I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YzRm/MTA5NDNhZTE5MjU4/YTFmZmI5MTg2MzRm/ZDFmZi5wbmc.jpg"/>
      <itunes:duration>1311</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at Bugcrowd, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeline</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at Bugcrowd, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeli</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#183 - Hacker Holidays: When the lights went out in Ukraine (Part 1 &amp; 2)</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>183</itunes:episode>
      <podcast:episode>183</podcast:episode>
      <itunes:title>#183 - Hacker Holidays: When the lights went out in Ukraine (Part 1 &amp; 2)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ea91872c-7b03-4393-bd2e-1e619251c13c</guid>
      <link>https://share.transistor.fm/s/6eac00df</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we share both parts of 'When the Lights Went Out in Ukraine.'</p><p>Beginning on January 13th, 2022, a Russian APT installed wiper malware on the IT networks of government, NGO, and IT companies across Ukraine. The malicious program was designed to appear like ransomware, but contained no recovery feature – it simply destroyed any computer it wished.

Just one day later, hackers from the intelligence service of Belarus – Russia’s close ally – took down 70 websites belonging to the Ukrainian government.

This was tilling – laying down the foundation for an all-out ground attack. Plastered on the 70 downed websites was a message from the attackers: “be afraid,” they wrote,
and expect the worst.”</p><p>This episode was written by the talented Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at LimaCharlie.</p><p>And a special thank you to Robert Lipovsky for sharing his first-hand knowledge.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we share both parts of 'When the Lights Went Out in Ukraine.'</p><p>Beginning on January 13th, 2022, a Russian APT installed wiper malware on the IT networks of government, NGO, and IT companies across Ukraine. The malicious program was designed to appear like ransomware, but contained no recovery feature – it simply destroyed any computer it wished.

Just one day later, hackers from the intelligence service of Belarus – Russia’s close ally – took down 70 websites belonging to the Ukrainian government.

This was tilling – laying down the foundation for an all-out ground attack. Plastered on the 70 downed websites was a message from the attackers: “be afraid,” they wrote,
and expect the worst.”</p><p>This episode was written by the talented Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at LimaCharlie.</p><p>And a special thank you to Robert Lipovsky for sharing his first-hand knowledge.</p>]]>
      </content:encoded>
      <pubDate>Tue, 31 Dec 2024 16:27:09 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6eac00df/d5c22cb0.mp3" length="54709796" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2280</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we share both parts of 'When the Lights Went Out in Ukraine.'</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we share both parts of 'When the Lights Went Out in Ukraine.'</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#182 - Hacker Holidays: Stuxnet (Part 1 &amp; 2)</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>182</itunes:episode>
      <podcast:episode>182</podcast:episode>
      <itunes:title>#182 - Hacker Holidays: Stuxnet (Part 1 &amp; 2)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bf1a6b18-aaa7-4476-bf36-9e528a6e58c8</guid>
      <link>https://share.transistor.fm/s/fbcde56b</link>
      <description>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet. 

Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.

Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.

This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet. 

Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.

Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.

This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 30 Dec 2024 18:20:28 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fbcde56b/59005fca.mp3" length="27466541" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/x539FsOxs6axZsQkB4ofZ2mDnNU5CGxiQcBveLAvZvM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lY2Yx/ZDAwZWRiYTgwNzli/ZDljN2IwYTRkMWY4/ZmVmYy5wbmc.jpg"/>
      <itunes:duration>2273</itunes:duration>
      <itunes:summary>This episode of the Cybersecurity Defenders podcast is a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet.</itunes:summary>
      <itunes:subtitle>This episode of the Cybersecurity Defenders podcast is a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#181 - Hacker Holidays: WannaCry</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>181</itunes:episode>
      <podcast:episode>181</podcast:episode>
      <itunes:title>#181 - Hacker Holidays: WannaCry</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">08f037a7-63d4-4cc5-9020-f16bc73458c1</guid>
      <link>https://share.transistor.fm/s/8bb28b15</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history, and with the help of Marcus Hutchins, tell the story of the WannaCry ransomware attack.

The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the Bitcoin cryptocurrency. It propagated by using EternalBlue, an exploit developed by the United States National Security Agency (NSA) for Windows systems. EternalBlue was stolen and leaked by a group called The Shadow Brokers a month prior to the attack. 

Researcher Marcus Hutchins discovered the kill switch domain hardcoded in the malware. Registering a domain name for a DNS sinkhole stopped the attack spreading as a worm, because the ransomware only encrypted the computer's files if it was unable to connect to that domain, which all computers infected with WannaCry before the website's registration had been unable to do. While this did not help already infected systems, it severely slowed the spread of the initial infection and gave time for defensive measures to be deployed worldwide, particularly in North America and Asia, which had not been attacked to the same extent as elsewhere.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history, and with the help of Marcus Hutchins, tell the story of the WannaCry ransomware attack.

The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the Bitcoin cryptocurrency. It propagated by using EternalBlue, an exploit developed by the United States National Security Agency (NSA) for Windows systems. EternalBlue was stolen and leaked by a group called The Shadow Brokers a month prior to the attack. 

Researcher Marcus Hutchins discovered the kill switch domain hardcoded in the malware. Registering a domain name for a DNS sinkhole stopped the attack spreading as a worm, because the ransomware only encrypted the computer's files if it was unable to connect to that domain, which all computers infected with WannaCry before the website's registration had been unable to do. While this did not help already infected systems, it severely slowed the spread of the initial infection and gave time for defensive measures to be deployed worldwide, particularly in North America and Asia, which had not been attacked to the same extent as elsewhere.</p>]]>
      </content:encoded>
      <pubDate>Sun, 29 Dec 2024 09:20:59 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8bb28b15/b530d978.mp3" length="14030278" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/gJ0hBJ1JF2RA7L8PzQIthCCVawImpS_8ahnFi6BcjGE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84ZmUz/ZjA1ZDE0OWFkYjc1/MTQxNWE4ZDFiYmIx/N2EzZC5wbmc.jpg"/>
      <itunes:duration>1153</itunes:duration>
      <itunes:summary>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history, and with the help of Marcus Hutchins, tell the story of the WannaCry ransomware attack.</itunes:summary>
      <itunes:subtitle>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history, and with the help of Marcus Hutchins, tell the story of the WannaCry ransomware attack.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#180 - Hacker Holidays: Titan Rain</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>180</itunes:episode>
      <podcast:episode>180</podcast:episode>
      <itunes:title>#180 - Hacker Holidays: Titan Rain</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ebf660b8-bf97-4630-8f0c-881d9b00ce7d</guid>
      <link>https://share.transistor.fm/s/a7ec1369</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Shawn Carpenter; a rogue cybersecurity defender who singlehandedly identified a Chinese APT. It is a phenomenal story that exemplifies the grit and moral fortitude that the best defenders among us have. 

Titan Rain was a series of coordinated attacks on computer systems in the United States since 2003; they were known to have been ongoing for at least three years. The attacks originated in Guangdong, China. The activity is believed to be associated with a state-sponsored advanced persistent threat. It was given the designation <em>Titan Rain</em> by the federal government of the United States.</p><p>Titan Rain hackers gained access to many United States defense contractor computer networks, which were targeted for their sensitive information, including those at Lockheed Martin, Sandia National Laboratories, Redstone Arsenal, and NASA.

This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Shawn Carpenter; a rogue cybersecurity defender who singlehandedly identified a Chinese APT. It is a phenomenal story that exemplifies the grit and moral fortitude that the best defenders among us have. 

Titan Rain was a series of coordinated attacks on computer systems in the United States since 2003; they were known to have been ongoing for at least three years. The attacks originated in Guangdong, China. The activity is believed to be associated with a state-sponsored advanced persistent threat. It was given the designation <em>Titan Rain</em> by the federal government of the United States.</p><p>Titan Rain hackers gained access to many United States defense contractor computer networks, which were targeted for their sensitive information, including those at Lockheed Martin, Sandia National Laboratories, Redstone Arsenal, and NASA.

This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.</p>]]>
      </content:encoded>
      <pubDate>Sat, 28 Dec 2024 06:28:29 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a7ec1369/c52128a6.mp3" length="14833704" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/NURvabay49-JHRngvU-BxtRP8JdYbBp60N9lgIAf06I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYjk0/ZDk4YzNjMmM4OWYy/NmU0NzhhOTNiMTcw/NTgxZC5wbmc.jpg"/>
      <itunes:duration>1220</itunes:duration>
      <itunes:summary>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Shawn Carpenter; a rogue cybersecurity defender who singlehandedly identified a Chinese APT. It is a phenomenal story that exemplifies the grit and moral fortitude that the best defenders among us have.</itunes:summary>
      <itunes:subtitle>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Shawn Carpenter; a rogue cybersecurity defender who singlehandedly identified a Chinese APT. It is a phenomenal story that exemplifies the grit an</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#179 - Hacker Holidays: Operation Flyhook</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>179</itunes:episode>
      <podcast:episode>179</podcast:episode>
      <itunes:title>#179 - Hacker Holidays: Operation Flyhook</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e373b90a-d99c-4b30-b854-bbe6c84e6c9c</guid>
      <link>https://share.transistor.fm/s/47db2717</link>
      <description>
        <![CDATA[<p>In this episode, we recount the story of Operation Flyhook - an FBI sting operation in 2000 that resulted in the arrest of two Russian hackers on American soil. It is quite the story and leaves us with some pretty heavy conclusions.

This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.

Any questions or feedback can be directed to <a rel="noreferrer noopener" href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, we recount the story of Operation Flyhook - an FBI sting operation in 2000 that resulted in the arrest of two Russian hackers on American soil. It is quite the story and leaves us with some pretty heavy conclusions.

This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.

Any questions or feedback can be directed to <a rel="noreferrer noopener" href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 27 Dec 2024 07:05:31 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/47db2717/7d5b69e0.mp3" length="26043342" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1086</itunes:duration>
      <itunes:summary>In this episode, we recount the story of Operation Flyhook - an FBI sting operation in 2000 that resulted in the arrest of two Russian hackers on American soil. It is quite the story and leaves us with some pretty heavy conclusions.</itunes:summary>
      <itunes:subtitle>In this episode, we recount the story of Operation Flyhook - an FBI sting operation in 2000 that resulted in the arrest of two Russian hackers on American soil. It is quite the story and leaves us with some pretty heavy conclusions.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#178 - Intel Chat: ptcpdump, Target adopts TLSH, Clop, XLoader &amp; HeartCrypt</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>178</itunes:episode>
      <podcast:episode>178</podcast:episode>
      <itunes:title>#178 - Intel Chat: ptcpdump, Target adopts TLSH, Clop, XLoader &amp; HeartCrypt</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c3e13a37-36d0-4202-9e02-8e3e1273acfc</guid>
      <link>https://share.transistor.fm/s/fc6428a8</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><p>ptcpdump is an eBPF-based version of tcpdump that adds process information to each packet. It supports filtering by p<a rel="noreferrer noopener" href="https://github.com/mozillazg/ptcpdump">rocess ID, process name, container ID, and Kubernetes pod name</a>. </p><p>In a recent implementation, Target's cybersecurity team adopted TLSH (Trend Micro Locality Sensitive Hash) to improve their <a rel="noreferrer noopener" href="https://tech.target.com/blog/implementing_TLSH_based_detection">malware detection capabilities</a>. </p><p>Huntress recently issued a threat advisory regarding active exploitation of a zero-day vulnerability affecting Cleo's file transfer software, specifically impacting <a rel="noreferrer noopener" href="https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild">LexiCom, VLTrader, and Harmony versions up to 5.8.0.21</a>. </p><p>Sublime Security recently analyzed a phishing campaign that impersonates Microsoft SharePoint to deliver the <a rel="noreferrer noopener" href="https://sublime.security/blog/xloader-deep-dive-link-based-malware-delivery-via-sharepoint-impersonation">XLoader malware</a>.</p><p>Palo Alto Networks' Unit 42 team has uncovered a new packer-as-a-service (PaaS) operation named HeartCrypt, which has been active since July 2023 and began sales in February 2024. HeartCrypt is designed to obfuscate malware, making detection by <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/packer-as-a-service-heartcrypt-malware/">security solutions more challenging</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><p>ptcpdump is an eBPF-based version of tcpdump that adds process information to each packet. It supports filtering by p<a rel="noreferrer noopener" href="https://github.com/mozillazg/ptcpdump">rocess ID, process name, container ID, and Kubernetes pod name</a>. </p><p>In a recent implementation, Target's cybersecurity team adopted TLSH (Trend Micro Locality Sensitive Hash) to improve their <a rel="noreferrer noopener" href="https://tech.target.com/blog/implementing_TLSH_based_detection">malware detection capabilities</a>. </p><p>Huntress recently issued a threat advisory regarding active exploitation of a zero-day vulnerability affecting Cleo's file transfer software, specifically impacting <a rel="noreferrer noopener" href="https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild">LexiCom, VLTrader, and Harmony versions up to 5.8.0.21</a>. </p><p>Sublime Security recently analyzed a phishing campaign that impersonates Microsoft SharePoint to deliver the <a rel="noreferrer noopener" href="https://sublime.security/blog/xloader-deep-dive-link-based-malware-delivery-via-sharepoint-impersonation">XLoader malware</a>.</p><p>Palo Alto Networks' Unit 42 team has uncovered a new packer-as-a-service (PaaS) operation named HeartCrypt, which has been active since July 2023 and began sales in February 2024. HeartCrypt is designed to obfuscate malware, making detection by <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/packer-as-a-service-heartcrypt-malware/">security solutions more challenging</a>.</p>]]>
      </content:encoded>
      <pubDate>Sat, 21 Dec 2024 02:17:03 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fc6428a8/70a794a4.mp3" length="44653497" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1861</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#177 - Intel Chat: Supply-Chain Firewall, Scattered Spider, Linux malware &amp; another NTLM exploit</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>177</itunes:episode>
      <podcast:episode>177</podcast:episode>
      <itunes:title>#177 - Intel Chat: Supply-Chain Firewall, Scattered Spider, Linux malware &amp; another NTLM exploit</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5a31c5a1-7ce7-4298-bab6-1e274dd654f2</guid>
      <link>https://share.transistor.fm/s/3134b139</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Datadog Security Labs has introduced the Supply-Chain Firewall, a new open-source tool designed to protect developers from malicious and vulnerable <a rel="noreferrer noopener" href="https://securitylabs.datadoghq.com/articles/introducing-supply-chain-firewall/">packages sourced from PyPI and npm repositories</a>.</li><li>U.S. authorities have arrested 19-year-old Remington Goy Ogletree, known online as "remi," for allegedly breaching a U.S. financial institution and <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/us-arrests-scattered-spider-suspect-linked-to-telecom-hacks/">two unnamed telecommunications firms</a>.</li><li> A recent study titled "A Study of Malware Prevention in Linux Distributions" examines the challenges of preventing and detecting malware within <a rel="noreferrer noopener" href="https://arxiv.org/abs/2411.11017">Linux distribution package repositories</a>. </li><li>A recently identified zero-day vulnerability affects all modern versions of Windows Workstation and Server operating systems, from <a rel="noreferrer noopener" href="https://cybernews.com/security/windows-zero-day-attackers-can-steal-ntlm-credentials/">Windows 7 and Server 2008 R2 up to the latest Windows 11 v24H2 and Server 2022</a>. </li></ul><p>And you can subscribe to Detection Engineering Weekly <a rel="noreferrer noopener" href="https://www.detectionengineering.net/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Datadog Security Labs has introduced the Supply-Chain Firewall, a new open-source tool designed to protect developers from malicious and vulnerable <a rel="noreferrer noopener" href="https://securitylabs.datadoghq.com/articles/introducing-supply-chain-firewall/">packages sourced from PyPI and npm repositories</a>.</li><li>U.S. authorities have arrested 19-year-old Remington Goy Ogletree, known online as "remi," for allegedly breaching a U.S. financial institution and <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/us-arrests-scattered-spider-suspect-linked-to-telecom-hacks/">two unnamed telecommunications firms</a>.</li><li> A recent study titled "A Study of Malware Prevention in Linux Distributions" examines the challenges of preventing and detecting malware within <a rel="noreferrer noopener" href="https://arxiv.org/abs/2411.11017">Linux distribution package repositories</a>. </li><li>A recently identified zero-day vulnerability affects all modern versions of Windows Workstation and Server operating systems, from <a rel="noreferrer noopener" href="https://cybernews.com/security/windows-zero-day-attackers-can-steal-ntlm-credentials/">Windows 7 and Server 2008 R2 up to the latest Windows 11 v24H2 and Server 2022</a>. </li></ul><p>And you can subscribe to Detection Engineering Weekly <a rel="noreferrer noopener" href="https://www.detectionengineering.net/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 12 Dec 2024 15:40:28 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3134b139/0ff19415.mp3" length="19864072" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/8MpH8SV4W9q8rQ-bs6FPnfarsqvVfY6SMZzKVqfnaCs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80YjYz/YzllYWNmZjk5ZWJk/ZmVlZTE3NzMwYjUy/OGRjMy5wbmc.jpg"/>
      <itunes:duration>1639</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#176 - The reality of modern browser threats with John Tuckner, Founder at Secure Annex</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>176</itunes:episode>
      <podcast:episode>176</podcast:episode>
      <itunes:title>#176 - The reality of modern browser threats with John Tuckner, Founder at Secure Annex</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">efcb1d86-374e-44a7-bdd4-e8d78533c580</guid>
      <link>https://share.transistor.fm/s/87d5ae1a</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we explore the reality of modern browser threats with John Tuckner, Founder at <a rel="noreferrer noopener" href="https://secureannex.com/">Secure Annex</a>.</p><p>John, the founder of Secure Annex, an innovative platform focused on helping organizations manage and secure browser extensions. With over a decade of experience in cybersecurity and technical program management, they have held key leadership roles at companies like Tines, Cyderes, and Optiv. At Tines, they spearheaded multiple initiatives, including the creation of Tines Labs, the development of a natural language AI workflow tool, and the expansion of the Tines Library of automation workflows.</p><p>John’s career also includes building customer success engineering teams, driving security automation research, and implementing cutting-edge network and security solutions. They bring a wealth of expertise in creating scalable frameworks, strategic tools, and impactful automation technologies.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we explore the reality of modern browser threats with John Tuckner, Founder at <a rel="noreferrer noopener" href="https://secureannex.com/">Secure Annex</a>.</p><p>John, the founder of Secure Annex, an innovative platform focused on helping organizations manage and secure browser extensions. With over a decade of experience in cybersecurity and technical program management, they have held key leadership roles at companies like Tines, Cyderes, and Optiv. At Tines, they spearheaded multiple initiatives, including the creation of Tines Labs, the development of a natural language AI workflow tool, and the expansion of the Tines Library of automation workflows.</p><p>John’s career also includes building customer success engineering teams, driving security automation research, and implementing cutting-edge network and security solutions. They bring a wealth of expertise in creating scalable frameworks, strategic tools, and impactful automation technologies.</p>]]>
      </content:encoded>
      <pubDate>Tue, 10 Dec 2024 15:16:45 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/87d5ae1a/025d635e.mp3" length="23090908" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/0840qy8K-ZgcgcUayZ3bV8WyG0SU__xbXY92oZLzd3Q/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iNDcz/YmJiZDYzOTY1OGEz/N2ExM2Y5ZGIzYjlm/MGQxOC5wbmc.jpg"/>
      <itunes:duration>1908</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we explore the reality of modern browser threats with John Tuckner, Founder at Secure Annex.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we explore the reality of modern browser threats with John Tuckner, Founder at Secure Annex.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#175 - Intel Chat: Hydra dark web, DOC entity list, Venom Spider &amp; flowbreaking,</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>175</itunes:episode>
      <podcast:episode>175</podcast:episode>
      <itunes:title>#175 - Intel Chat: Hydra dark web, DOC entity list, Venom Spider &amp; flowbreaking,</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">78ee77fd-38c4-4e28-9001-266056b91605</guid>
      <link>https://share.transistor.fm/s/72b9ab48</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><p>Russian courts have sentenced Stanislav Moiseyev, the leader of the Hydra dark web marketplace, <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/russia-sentences-hydra-dark-web-market-leader-to-life-in-prison/">to life imprisonment.</a></p><p>The U.S. Commerce Department has expanded its export controls, adding nearly 140 Chinese technology companies to its "entity list." This action primarily targets firms involved in the production of computer chips, chipmaking tools, and related software, including Chinese-owned entities operating in <a rel="noreferrer noopener" href="https://apnews.com/article/china-us-technology-chips-sanctions-bis-8f8ab1ab49b5bb57e5a290a3937fa939">Japan, South Korea, and Singapore.</a></p><p>Researchers have uncovered new malware strains, RevC2 and Venom Loader, tied to the sophisticated threat actor known as <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/unveiling-revc2-and-venom-loader">Venom Spider.</a> </p><p>Recent analyses have identified a critical vulnerability in generative AI systems, termed "flowbreaking" exploits, which can lead to <a rel="noreferrer noopener" href="https://www.forbes.com/sites/nizangpackin/2024/11/26/generative-ai-under-attack-flowbreaking-exploits-trigger-data-leaks/">unintended data leaks. </a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><p>Russian courts have sentenced Stanislav Moiseyev, the leader of the Hydra dark web marketplace, <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/russia-sentences-hydra-dark-web-market-leader-to-life-in-prison/">to life imprisonment.</a></p><p>The U.S. Commerce Department has expanded its export controls, adding nearly 140 Chinese technology companies to its "entity list." This action primarily targets firms involved in the production of computer chips, chipmaking tools, and related software, including Chinese-owned entities operating in <a rel="noreferrer noopener" href="https://apnews.com/article/china-us-technology-chips-sanctions-bis-8f8ab1ab49b5bb57e5a290a3937fa939">Japan, South Korea, and Singapore.</a></p><p>Researchers have uncovered new malware strains, RevC2 and Venom Loader, tied to the sophisticated threat actor known as <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/unveiling-revc2-and-venom-loader">Venom Spider.</a> </p><p>Recent analyses have identified a critical vulnerability in generative AI systems, termed "flowbreaking" exploits, which can lead to <a rel="noreferrer noopener" href="https://www.forbes.com/sites/nizangpackin/2024/11/26/generative-ai-under-attack-flowbreaking-exploits-trigger-data-leaks/">unintended data leaks. </a></p>]]>
      </content:encoded>
      <pubDate>Fri, 06 Dec 2024 15:50:19 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/72b9ab48/a5a9b809.mp3" length="21031713" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/AWqe1E-IiqKc8MAfkY0-O9zjXtzok3p-Kt0iDjkyoxI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85NTE0/MWIyYzJhMTVlNmY0/Nzc2MGUyOWY1MjNm/ZTIwYy5wbmc.jpg"/>
      <itunes:duration>1737</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#174 - Predictions for the future of cybersecurity from 2024</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>174</itunes:episode>
      <podcast:episode>174</podcast:episode>
      <itunes:title>#174 - Predictions for the future of cybersecurity from 2024</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">06a225de-f99e-4499-9d39-63f2df25b972</guid>
      <link>https://share.transistor.fm/s/b082da4e</link>
      <description>
        <![CDATA[<p>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2024, and bring together all of the predictions for the future of cybersecurity.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2024, and bring together all of the predictions for the future of cybersecurity.</p>]]>
      </content:encoded>
      <pubDate>Wed, 04 Dec 2024 19:33:19 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b082da4e/3ad77c49.mp3" length="62382360" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/EEQLNZsNQT1-kSgUlTwzH9YJnHLJKBLFZ_kAKeXFSJs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYzJh/MjEwMDFiZTQ5Y2I0/YTU0NjM1OWFjNThm/ZTBlMy5wbmc.jpg"/>
      <itunes:duration>5182</itunes:duration>
      <itunes:summary>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2024, and bring together all of the predictions for the future of cybersecurity.</itunes:summary>
      <itunes:subtitle>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2024, and bring together all of the predictions for the future of cybersecurity.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#173 - Intel Chat: ClickFix, Raspberry Robin, Gelsemium, Fancy Bear &amp; Salt Typhoon</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>173</itunes:episode>
      <podcast:episode>173</podcast:episode>
      <itunes:title>#173 - Intel Chat: ClickFix, Raspberry Robin, Gelsemium, Fancy Bear &amp; Salt Typhoon</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">012b2da5-47fa-4920-bc2d-20c14d3b160a</guid>
      <link>https://share.transistor.fm/s/b0586d3c</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>In recent months, cybersecurity researchers have observed a surge in the use of a social engineering technique known as "ClickFix." This method involves threat actors presenting users with deceptive error messages that prompt them to manually execute malicious commands, often by <a rel="noreferrer noopener" href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape">copying and pasting scripts into their systems.</a></li><li>Raspberry Robin, also known as Roshtyak, is a highly obfuscated malware first discovered in 2021, notable for its complex binary structure and advanced evasion techniques. It primarily spreads via infected USB devices and employs multi-layered <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/unraveling-raspberry-robin-s-layers-analyzing-obfuscation-techniques-and">execution to obscure its true purpose</a>. </li><li>A China-linked Advanced Persistent Threat (APT) group, Gelsemium, has been observed targeting Linux systems for the first time, deploying previously undocumented malware in an espionage campaign. Historically known for targeting Windows platforms, this new activity signifies a shift towards Linux, possibly driven by the <a rel="noreferrer noopener" href="https://therecord.media/china-hackers-linux-malware-target">increasing security of Windows systems.</a></li><li>Russia’s APT28 hacking group, also known as Fancy Bear or Unit 26165, has developed a novel technique dubbed the<a rel="noreferrer noopener" href="https://www.wired.com/story/russia-gru-apt28-wifi-daisy-chain-breach/"> “nearest neighbor attack” to exploit Wi-Fi networks remotely.</a></li><li>Hackers linked to the Chinese government, known as Salt Typhoon, have deeply infiltrated U.S. telecommunications infrastructure, gaining the ability to intercept unencrypted phone calls and text messages. The group exploited vulnerabilities in the wiretap systems used by U.S. authorities for lawful interception, marking what Senator Mark Warner has called <a rel="noreferrer noopener" href="https://gizmodo.com/china-wiretaps-americans-in-worst-hack-in-our-nations-history-2000528424">"the worst telecom hack in our nation's history." </a></li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>In recent months, cybersecurity researchers have observed a surge in the use of a social engineering technique known as "ClickFix." This method involves threat actors presenting users with deceptive error messages that prompt them to manually execute malicious commands, often by <a rel="noreferrer noopener" href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape">copying and pasting scripts into their systems.</a></li><li>Raspberry Robin, also known as Roshtyak, is a highly obfuscated malware first discovered in 2021, notable for its complex binary structure and advanced evasion techniques. It primarily spreads via infected USB devices and employs multi-layered <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/unraveling-raspberry-robin-s-layers-analyzing-obfuscation-techniques-and">execution to obscure its true purpose</a>. </li><li>A China-linked Advanced Persistent Threat (APT) group, Gelsemium, has been observed targeting Linux systems for the first time, deploying previously undocumented malware in an espionage campaign. Historically known for targeting Windows platforms, this new activity signifies a shift towards Linux, possibly driven by the <a rel="noreferrer noopener" href="https://therecord.media/china-hackers-linux-malware-target">increasing security of Windows systems.</a></li><li>Russia’s APT28 hacking group, also known as Fancy Bear or Unit 26165, has developed a novel technique dubbed the<a rel="noreferrer noopener" href="https://www.wired.com/story/russia-gru-apt28-wifi-daisy-chain-breach/"> “nearest neighbor attack” to exploit Wi-Fi networks remotely.</a></li><li>Hackers linked to the Chinese government, known as Salt Typhoon, have deeply infiltrated U.S. telecommunications infrastructure, gaining the ability to intercept unencrypted phone calls and text messages. The group exploited vulnerabilities in the wiretap systems used by U.S. authorities for lawful interception, marking what Senator Mark Warner has called <a rel="noreferrer noopener" href="https://gizmodo.com/china-wiretaps-americans-in-worst-hack-in-our-nations-history-2000528424">"the worst telecom hack in our nation's history." </a></li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 28 Nov 2024 14:43:48 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b0586d3c/e7553649.mp3" length="31375267" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/obVsnZCAC2YryNI1S2jeJhlNHF7r-zca05Oi6u5nvkI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mZTEw/Y2UzZjgwZjJhMjA5/Zjk0MDg5NGI2MDE2/MmYwNC5wbmc.jpg"/>
      <itunes:duration>2598</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#172 - Cybercrime cottage industries with Reed McGinley-Stempel, the Co-Founder and CEO of Stytch</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>172</itunes:episode>
      <podcast:episode>172</podcast:episode>
      <itunes:title>#172 - Cybercrime cottage industries with Reed McGinley-Stempel, the Co-Founder and CEO of Stytch</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4752a194-c91c-4781-b7df-22c902043323</guid>
      <link>https://share.transistor.fm/s/a193ea45</link>
      <description>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we talk about cybercrime cottage industries with Reed McGinley-Stempel, the Co-Founder and CEO of <a rel="noreferrer noopener" href="https://stytch.com/">Stytch</a></p><p>Stytch is a platform designed to streamline authentication, authorization, and fraud prevention in a way that enhances security while minimizing user friction. Stytch serves both consumer and B2B applications, offering a variety of authentication solutions, including features like Google One-Tap and Biometrics for consumer-facing applications, as well as SSO, Role-Based Access Control, and SCIM integrations for enterprise SaaS. Reed founded Stytch after witnessing the challenges teams face when building secure and user-friendly authentication solutions, a problem he first encountered while working at Plaid. He is also a proud duke alumni and was the recipient of the prestigious Fullbright Scholarship</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we talk about cybercrime cottage industries with Reed McGinley-Stempel, the Co-Founder and CEO of <a rel="noreferrer noopener" href="https://stytch.com/">Stytch</a></p><p>Stytch is a platform designed to streamline authentication, authorization, and fraud prevention in a way that enhances security while minimizing user friction. Stytch serves both consumer and B2B applications, offering a variety of authentication solutions, including features like Google One-Tap and Biometrics for consumer-facing applications, as well as SSO, Role-Based Access Control, and SCIM integrations for enterprise SaaS. Reed founded Stytch after witnessing the challenges teams face when building secure and user-friendly authentication solutions, a problem he first encountered while working at Plaid. He is also a proud duke alumni and was the recipient of the prestigious Fullbright Scholarship</p>]]>
      </content:encoded>
      <pubDate>Wed, 27 Nov 2024 07:30:13 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a193ea45/a554d94c.mp3" length="25738803" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/k6uuvHbCBQ5hnTJiQNK706ssNjxKI-c-a9vatpdcx8Q/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kYTNk/ODVlNmNiNDFjMDlh/MjI4MjZlMTM4MWRj/OWZhMi5wbmc.jpg"/>
      <itunes:duration>2129</itunes:duration>
      <itunes:summary>On today's episode of The Cybersecurity Defenders Podcast we talk about cybercrime cottage industries with Reed McGinley-Stempel, the Co-Founder and CEO of Stytch</itunes:summary>
      <itunes:subtitle>On today's episode of The Cybersecurity Defenders Podcast we talk about cybercrime cottage industries with Reed McGinley-Stempel, the Co-Founder and CEO of Stytch</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#171 - Intel Chat: Snowflake, Scattered Spider, CCP, Melofee backdoor, SilkSpecter &amp; Palo Alto Networks</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>171</itunes:episode>
      <podcast:episode>171</podcast:episode>
      <itunes:title>#171 - Intel Chat: Snowflake, Scattered Spider, CCP, Melofee backdoor, SilkSpecter &amp; Palo Alto Networks</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8fb0fbcc-839d-4452-9be9-bb45d99adb75</guid>
      <link>https://share.transistor.fm/s/676a6dc7</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>U.S. authorities have identified and charged individuals responsible for a significant data breach involving Snowflake Inc., a major cloud data warehousing company. The breach resulted in the theft of approximately 50 billion records from AT&amp;T, <a rel="noreferrer noopener" href="https://techcrunch.com/2024/11/12/snowflake-hackers-identified-and-charged-with-stealing-50-billion-att-records/">one of Snowflake's prominent clients</a>.</li><li>U.S. prosecutors have charged five individuals, including 22-year-old Scottish national Tyler Buchanan, for their alleged involvement in the cybercrime group Scattered Spider. This group is accused of executing sophisticated phishing attacks that compromised numerous U.S. companies and individuals, leading to the <a rel="noreferrer noopener" href="https://news.sky.com/story/scottish-man-linked-to-hacking-group-scattered-spider-among-five-charged-in-us-13257514?dcmp=snt-sf-twitter">theft of confidential information and cryptocurrency</a>. </li><li>The next one is an interesting breakdown on the evolving landscape of Chinese state-sponsored cyber threats that reveals a highly coordinated and multi-layered approach to achieving the strategic <a rel="noreferrer noopener" href="https://blog.sekoia.io/a-three-beats-waltz-the-ecosystem-behind-chinese-state-sponsored-cyber-threats/">objectives of the Chinese Communist Party (CCP)</a>.</li><li>In July 2024, cybersecurity researchers identified a new variant of the Melofee backdoor, a sophisticated malware associated with the Winnti Advanced Persistent Threat group. This variant specifically targets Red Hat Enterprise Linux 7.9 systems and demonstrates <a rel="noreferrer noopener" href="https://blog.xlab.qianxin.com/analysis_of_new_melofee_variant_en/">enhanced stealth and persistence mechanisms</a>. </li><li>In early October 2024, cybersecurity analysts identified a phishing campaign targeting e-commerce shoppers in Europe and the USA seeking Black Friday discounts. The campaign, attributed to a financially motivated Chinese threat actor dubbed "SilkSpecter," exploited the surge in online shopping during<a rel="noreferrer noopener" href="https://blog.eclecticiq.com/inside-intelligence-center-financially-motivated-chinese-threat-actor-silkspecter-targeting-black-friday-shoppers"> November's Black Friday season</a>. </li><li>Palo Alto Networks' Unit 42 has identified exploitation activities targeting two critical vulnerabilities in PAN-OS software: <a rel="noreferrer noopener" href="https://security.paloaltonetworks.com/PAN-SA-2024-0015">CVE-2024-0012 and CVE-2024-9474</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>U.S. authorities have identified and charged individuals responsible for a significant data breach involving Snowflake Inc., a major cloud data warehousing company. The breach resulted in the theft of approximately 50 billion records from AT&amp;T, <a rel="noreferrer noopener" href="https://techcrunch.com/2024/11/12/snowflake-hackers-identified-and-charged-with-stealing-50-billion-att-records/">one of Snowflake's prominent clients</a>.</li><li>U.S. prosecutors have charged five individuals, including 22-year-old Scottish national Tyler Buchanan, for their alleged involvement in the cybercrime group Scattered Spider. This group is accused of executing sophisticated phishing attacks that compromised numerous U.S. companies and individuals, leading to the <a rel="noreferrer noopener" href="https://news.sky.com/story/scottish-man-linked-to-hacking-group-scattered-spider-among-five-charged-in-us-13257514?dcmp=snt-sf-twitter">theft of confidential information and cryptocurrency</a>. </li><li>The next one is an interesting breakdown on the evolving landscape of Chinese state-sponsored cyber threats that reveals a highly coordinated and multi-layered approach to achieving the strategic <a rel="noreferrer noopener" href="https://blog.sekoia.io/a-three-beats-waltz-the-ecosystem-behind-chinese-state-sponsored-cyber-threats/">objectives of the Chinese Communist Party (CCP)</a>.</li><li>In July 2024, cybersecurity researchers identified a new variant of the Melofee backdoor, a sophisticated malware associated with the Winnti Advanced Persistent Threat group. This variant specifically targets Red Hat Enterprise Linux 7.9 systems and demonstrates <a rel="noreferrer noopener" href="https://blog.xlab.qianxin.com/analysis_of_new_melofee_variant_en/">enhanced stealth and persistence mechanisms</a>. </li><li>In early October 2024, cybersecurity analysts identified a phishing campaign targeting e-commerce shoppers in Europe and the USA seeking Black Friday discounts. The campaign, attributed to a financially motivated Chinese threat actor dubbed "SilkSpecter," exploited the surge in online shopping during<a rel="noreferrer noopener" href="https://blog.eclecticiq.com/inside-intelligence-center-financially-motivated-chinese-threat-actor-silkspecter-targeting-black-friday-shoppers"> November's Black Friday season</a>. </li><li>Palo Alto Networks' Unit 42 has identified exploitation activities targeting two critical vulnerabilities in PAN-OS software: <a rel="noreferrer noopener" href="https://security.paloaltonetworks.com/PAN-SA-2024-0015">CVE-2024-0012 and CVE-2024-9474</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Sat, 23 Nov 2024 20:22:31 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/676a6dc7/149c22e7.mp3" length="31508846" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/XUzMPGjhz3bVydEqhKRQJV1b3p-xSf06tseL8xaqNBI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNWM4/NWM2ZjQ4YzJhNzIz/ZTBiYzY4NWNlNWEw/ZWE0My5wbmc.jpg"/>
      <itunes:duration>2610</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#170 - A novel path into cybersecurity with Jibby Saetang, Security Researcher with Microsoft GHOST</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>170</itunes:episode>
      <podcast:episode>170</podcast:episode>
      <itunes:title>#170 - A novel path into cybersecurity with Jibby Saetang, Security Researcher with Microsoft GHOST</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8382427a-8be7-42b6-8c2e-56c835d71aba</guid>
      <link>https://share.transistor.fm/s/6e5ca869</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Jibby Saetang, Security Researcher with Microsoft GHOST, about his novel path to a career in cybersecurity.</p><p>With over a decade of experience in watch and jewelry repair, Jibby developed an impressive eye for detail and a knack for solving complex problems. These skills translated seamlessly into the world of cybersecurity, where Jibby found an unexpected yet perfect fit. Driven by a passion for learning, Jibby dove into the KC7 platform, an immersive cybersecurity training resource, which ultimately led to a role at Microsoft—all without taking the traditional certification route. Jibby’s story is a testament to the power of persistence, passion, and non-traditional paths in tech. Now, Jibby is focused on helping others break into cybersecurity by developing new KC7 training modules, aiming to inspire and equip the next generation of problem-solvers.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Jibby Saetang, Security Researcher with Microsoft GHOST, about his novel path to a career in cybersecurity.</p><p>With over a decade of experience in watch and jewelry repair, Jibby developed an impressive eye for detail and a knack for solving complex problems. These skills translated seamlessly into the world of cybersecurity, where Jibby found an unexpected yet perfect fit. Driven by a passion for learning, Jibby dove into the KC7 platform, an immersive cybersecurity training resource, which ultimately led to a role at Microsoft—all without taking the traditional certification route. Jibby’s story is a testament to the power of persistence, passion, and non-traditional paths in tech. Now, Jibby is focused on helping others break into cybersecurity by developing new KC7 training modules, aiming to inspire and equip the next generation of problem-solvers.</p>]]>
      </content:encoded>
      <pubDate>Tue, 19 Nov 2024 07:30:12 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6e5ca869/96b7fc6d.mp3" length="42094437" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1754</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Jibby Saetang, Security Researcher with Microsoft GHOST, about his novel path to a career in cybersecurity.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Jibby Saetang, Security Researcher with Microsoft GHOST, about his novel path to a career in cybersecurity.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#169 - Intel Chat: Tools, N. Korean IT workers, GootLoader,  FakeBat &amp; Pacific Rim</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>169</itunes:episode>
      <podcast:episode>169</podcast:episode>
      <itunes:title>#169 - Intel Chat: Tools, N. Korean IT workers, GootLoader,  FakeBat &amp; Pacific Rim</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e46eec07-583e-4e38-9031-2d187a66a65d</guid>
      <link>https://share.transistor.fm/s/f33a9d0d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>MFASweep is a PowerShell script that attempts to log in to various Microsoft services using a provided set of credentials and will attempt to identify if <a rel="noreferrer noopener" href="https://github.com/dafthack/MFASweep">MFA is enabled</a>. </li><li>CVE2CAPEC is a tool developed by Galeax that automates the process of mapping Common Vulnerabilities and Exposures (CVEs) to Common Weakness Enumerations (CWEs), Common Attack Pattern Enumeration and Classification (CAPEC), and <a rel="noreferrer noopener" href="https://github.com/Galeax/CVE2CAPEC">MITRE ATT&amp;CK Techniques</a>.</li><li>This tool helps security researchers identify vulnerabilities within macOS’s sandbox restrictions, particularly targeting XPC services in the PID domain marked as "Application" services, which <a rel="noreferrer noopener" href="https://jhftss.github.io/A-New-Era-of-macOS-Sandbox-Escapes/">often lack adequate protection</a>.</li><li>Zscaler's recent blog discusses how North Korean IT professionals are increasingly finding remote work in Western <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/pyongyang-your-payroll-rise-north-korean-remote-workers-west">companies, often under disguised identities</a>.</li><li>In a recent campaign, GootLoader malware has been targeting Bengal cat enthusiasts in Australia using <a rel="noreferrer noopener" href="https://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/">SEO poisoning tactics</a>.</li><li>After a multi-month absence, the malware loader FakeBat—also known as Eugenloader or PaykLoader—has resurfaced, distributing malware through Google Ads, with a recent campaign exploiting ads for the <a rel="noreferrer noopener" href="https://www.malwarebytes.com/blog/news/2024/11/hello-again-fakebat-popular-loader-returns-after-months-long-hiatus">popular app Notion</a>.</li><li>Over the past five years, Sophos has been engaged in a complex battle against Chinese state-sponsored cyber adversaries targeting its firewall products. This prolonged engagement, detailed in Sophos' "Pacific Rim" report, reveals a series of sophisticated attacks aimed at exploiting vulnerabilities in internet-facing devices, particularly those within critical infrastructure sectors <a rel="noreferrer noopener" href="https://www.sophos.com/en-us/content/pacific-rim">across South and Southeast Asia</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>MFASweep is a PowerShell script that attempts to log in to various Microsoft services using a provided set of credentials and will attempt to identify if <a rel="noreferrer noopener" href="https://github.com/dafthack/MFASweep">MFA is enabled</a>. </li><li>CVE2CAPEC is a tool developed by Galeax that automates the process of mapping Common Vulnerabilities and Exposures (CVEs) to Common Weakness Enumerations (CWEs), Common Attack Pattern Enumeration and Classification (CAPEC), and <a rel="noreferrer noopener" href="https://github.com/Galeax/CVE2CAPEC">MITRE ATT&amp;CK Techniques</a>.</li><li>This tool helps security researchers identify vulnerabilities within macOS’s sandbox restrictions, particularly targeting XPC services in the PID domain marked as "Application" services, which <a rel="noreferrer noopener" href="https://jhftss.github.io/A-New-Era-of-macOS-Sandbox-Escapes/">often lack adequate protection</a>.</li><li>Zscaler's recent blog discusses how North Korean IT professionals are increasingly finding remote work in Western <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/pyongyang-your-payroll-rise-north-korean-remote-workers-west">companies, often under disguised identities</a>.</li><li>In a recent campaign, GootLoader malware has been targeting Bengal cat enthusiasts in Australia using <a rel="noreferrer noopener" href="https://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/">SEO poisoning tactics</a>.</li><li>After a multi-month absence, the malware loader FakeBat—also known as Eugenloader or PaykLoader—has resurfaced, distributing malware through Google Ads, with a recent campaign exploiting ads for the <a rel="noreferrer noopener" href="https://www.malwarebytes.com/blog/news/2024/11/hello-again-fakebat-popular-loader-returns-after-months-long-hiatus">popular app Notion</a>.</li><li>Over the past five years, Sophos has been engaged in a complex battle against Chinese state-sponsored cyber adversaries targeting its firewall products. This prolonged engagement, detailed in Sophos' "Pacific Rim" report, reveals a series of sophisticated attacks aimed at exploiting vulnerabilities in internet-facing devices, particularly those within critical infrastructure sectors <a rel="noreferrer noopener" href="https://www.sophos.com/en-us/content/pacific-rim">across South and Southeast Asia</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 15 Nov 2024 07:30:12 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f33a9d0d/6134e1f8.mp3" length="27347185" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/MYvXpx8iphubyLu9IGApUcBAAjCrh8mYk80j8r_88_E/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNDBl/YjJjODYwNTFiMTNk/MjI3M2JhMjVmOWUz/NDljNC5wbmc.jpg"/>
      <itunes:duration>2263</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#168 - Intel Chat: Latrodectus, WarmCookie, FortiManager, EU's Product Liability Directive &amp; Linus Torvalds</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>168</itunes:episode>
      <podcast:episode>168</podcast:episode>
      <itunes:title>#168 - Intel Chat: Latrodectus, WarmCookie, FortiManager, EU's Product Liability Directive &amp; Linus Torvalds</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f3f1e896-4bdb-44ef-a869-a5e0b9f4b301</guid>
      <link>https://share.transistor.fm/s/f8cc1f50</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>VMRay's analysis on Latrodectus highlights the malware family’s development, detailing how it evolved from simple loaders to highly <a rel="noreferrer noopener" href="https://www.vmray.com/latrodectus-a-year-in-the-making/">evasive, sophisticated malware</a>.</li><li>The WarmCookie malware is a recent, persistent threat known for its self-updating capabilities, specifically designed to evade security tools and establish <a rel="noreferrer noopener" href="https://guardiansofcyber.com/threats-vulnerabilities/warmcookie-malware/">long-term presence in systems</a>. </li><li>Fortinet recently disclosed a critical zero-day vulnerability in its FortiManager product, assigned CVE-2024-47575, which has been <a rel="noreferrer noopener" href="https://arstechnica.com/security/2024/10/fortinet-stays-mum-on-critical-0-day-reportedly-under-active-exploitation/">actively exploited in the wild</a>.</li><li>The European Union (EU) recently updated its product liability framework to better address the challenges of the digital age and support the shift toward a <a rel="noreferrer noopener" href="https://www.consilium.europa.eu/en/press/press-releases/2024/10/10/eu-brings-product-liability-rules-in-line-with-digital-age-and-circular-economy/">circular economy</a>. </li><li>Linux creator Linus Torvalds recently reaffirmed the expulsion of Russian maintainers from the Linux MAINTAINERS file due to sanctions compliance, sparking discussion within the <a rel="noreferrer noopener" href="https://www.theregister.com/2024/10/23/linus_torvalds_affirms_expulsion_of/">open-source community</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>VMRay's analysis on Latrodectus highlights the malware family’s development, detailing how it evolved from simple loaders to highly <a rel="noreferrer noopener" href="https://www.vmray.com/latrodectus-a-year-in-the-making/">evasive, sophisticated malware</a>.</li><li>The WarmCookie malware is a recent, persistent threat known for its self-updating capabilities, specifically designed to evade security tools and establish <a rel="noreferrer noopener" href="https://guardiansofcyber.com/threats-vulnerabilities/warmcookie-malware/">long-term presence in systems</a>. </li><li>Fortinet recently disclosed a critical zero-day vulnerability in its FortiManager product, assigned CVE-2024-47575, which has been <a rel="noreferrer noopener" href="https://arstechnica.com/security/2024/10/fortinet-stays-mum-on-critical-0-day-reportedly-under-active-exploitation/">actively exploited in the wild</a>.</li><li>The European Union (EU) recently updated its product liability framework to better address the challenges of the digital age and support the shift toward a <a rel="noreferrer noopener" href="https://www.consilium.europa.eu/en/press/press-releases/2024/10/10/eu-brings-product-liability-rules-in-line-with-digital-age-and-circular-economy/">circular economy</a>. </li><li>Linux creator Linus Torvalds recently reaffirmed the expulsion of Russian maintainers from the Linux MAINTAINERS file due to sanctions compliance, sparking discussion within the <a rel="noreferrer noopener" href="https://www.theregister.com/2024/10/23/linus_torvalds_affirms_expulsion_of/">open-source community</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 31 Oct 2024 21:33:11 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f8cc1f50/62a14b5d.mp3" length="25683913" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/DjpxY7wUl2aEvjtCWXmLHo88ikhytfXiMvTcjxHCC94/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80YWYw/MmU4YTJhY2NiMDZm/NTM4MDg3Mjk5YTg0/NjY4YS5wbmc.jpg"/>
      <itunes:duration>2124</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#167 - Running and MDR company with Joshua Sitta, Co-Founder and CTO at Sittadel</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>167</itunes:episode>
      <podcast:episode>167</podcast:episode>
      <itunes:title>#167 - Running and MDR company with Joshua Sitta, Co-Founder and CTO at Sittadel</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4c171d60-4b4f-423b-9c70-102aa614db50</guid>
      <link>https://share.transistor.fm/s/7c66cc42</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about running and MDR company with Joshua Sitta, Co-Founder and CTO at <a rel="noreferrer noopener" href="https://sittadel.com/">Sittadel</a>.</p><p>My guest today is Joshua Sitta, the co-founder and CTO of Sittadel, a cybersecurity company specializing in 24/7/365 Managed Detection and Response services. With a focus on enterprise-grade EDR solutions, Sittadel provides comprehensive cybersecurity monitoring and incident response. Before founding Sittadel, Joshua served as the Director of Enterprise Security Architecture at SouthState Bank, where he built a robust in-house cybersecurity program that safeguarded billions in assets. He brings a deep expertise in protecting organizations from modern cyber threats.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about running and MDR company with Joshua Sitta, Co-Founder and CTO at <a rel="noreferrer noopener" href="https://sittadel.com/">Sittadel</a>.</p><p>My guest today is Joshua Sitta, the co-founder and CTO of Sittadel, a cybersecurity company specializing in 24/7/365 Managed Detection and Response services. With a focus on enterprise-grade EDR solutions, Sittadel provides comprehensive cybersecurity monitoring and incident response. Before founding Sittadel, Joshua served as the Director of Enterprise Security Architecture at SouthState Bank, where he built a robust in-house cybersecurity program that safeguarded billions in assets. He brings a deep expertise in protecting organizations from modern cyber threats.</p>]]>
      </content:encoded>
      <pubDate>Wed, 30 Oct 2024 18:13:18 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7c66cc42/6b87beb4.mp3" length="26971592" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/x99IsyRiK81BfLoFW19gwDPiSY9CuUcus7-RTWeVoCw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mZDcx/ZDk2NzViNTRhYWVj/Y2E3Njc5M2IyYjRh/NWQ3YS5wbmc.jpg"/>
      <itunes:duration>2232</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk about running and MDR company with Joshua Sitta, Co-Founder and CTO at Sittadel.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk about running and MDR company with Joshua Sitta, Co-Founder and CTO at Sittadel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#166 - Intel Chat: Microsoft logs, USDoD, SolarWinds WHD, &amp; CISA KEV</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>166</itunes:episode>
      <podcast:episode>166</podcast:episode>
      <itunes:title>#166 - Intel Chat: Microsoft logs, USDoD, SolarWinds WHD, &amp; CISA KEV</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">332f47dc-9e58-46d0-b6e1-ef9a91eb1f20</guid>
      <link>https://share.transistor.fm/s/d1fe546f</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Microsoft has recently confirmed that a software bug caused the loss of more than two weeks' worth of critical security logs from <a rel="noreferrer noopener" href="https://techcrunch.com/2024/10/17/microsoft-said-it-lost-weeks-of-security-logs-for-its-customers-cloud-products/">several of its cloud services</a>.</li><li>Brazil’s Federal Police have arrested a hacker suspected to be "USDoD," a notorious cybercriminal involved in several <a rel="noreferrer noopener" href="https://www.securityweek.com/brazilian-police-arrest-notorious-hacker-usdod/">high-profile data breaches</a>.</li><li>A critical vulnerability has been discovered in SolarWinds' Web Help Desk (WHD) software, involving hardcoded <a rel="noreferrer noopener" href="https://www.theregister.com/2024/10/16/solarwinds_critical_hardcoded_credential_bug/">credentials that could be exploited by attackers</a>. </li><li>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling that these flaws are being <a rel="noreferrer noopener" href="https://securityaffairs.com/169882/hacking/u-s-cisa-microsoft-windows-kernel-mozilla-firefox-solarwinds-web-help-desk-bugs-known-exploited-vulnerabilities-catalog.html">actively used in cyberattacks</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Microsoft has recently confirmed that a software bug caused the loss of more than two weeks' worth of critical security logs from <a rel="noreferrer noopener" href="https://techcrunch.com/2024/10/17/microsoft-said-it-lost-weeks-of-security-logs-for-its-customers-cloud-products/">several of its cloud services</a>.</li><li>Brazil’s Federal Police have arrested a hacker suspected to be "USDoD," a notorious cybercriminal involved in several <a rel="noreferrer noopener" href="https://www.securityweek.com/brazilian-police-arrest-notorious-hacker-usdod/">high-profile data breaches</a>.</li><li>A critical vulnerability has been discovered in SolarWinds' Web Help Desk (WHD) software, involving hardcoded <a rel="noreferrer noopener" href="https://www.theregister.com/2024/10/16/solarwinds_critical_hardcoded_credential_bug/">credentials that could be exploited by attackers</a>. </li><li>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling that these flaws are being <a rel="noreferrer noopener" href="https://securityaffairs.com/169882/hacking/u-s-cisa-microsoft-windows-kernel-mozilla-firefox-solarwinds-web-help-desk-bugs-known-exploited-vulnerabilities-catalog.html">actively used in cyberattacks</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 24 Oct 2024 08:08:04 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d1fe546f/86e84b4d.mp3" length="21776126" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/jS1AGWrv7Z8lExNo4009oraXnGikVIU5yUW0itSkcWE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hYzZi/NDRhZWE3Y2QyYWM3/ZTVkNjdjOTFhMDJl/YWM4Ny5wbmc.jpg"/>
      <itunes:duration>1799</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#165 - How AI is revolutionizing compliance with Dr. Gaurav Banga, CEO of Balbix</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>165</itunes:episode>
      <podcast:episode>165</podcast:episode>
      <itunes:title>#165 - How AI is revolutionizing compliance with Dr. Gaurav Banga, CEO of Balbix</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7739c1b4-b000-4d99-904c-d38aaf633c4b</guid>
      <link>https://share.transistor.fm/s/a2d6d9d1</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we examine how AI is revolutionizing compliance with Dr. Gaurav Banga, CEO of Balbix.</p><p>Gaurav Banga, the CEO and Founder of Balbix, an AI-powered cybersecurity risk management startup. Gaurav is an accomplished inventor with over 50 patents to his name, and he has a deep background in founding and leading multiple successful tech ventures. His journey into entrepreneurship is unique—it began over a decade ago when he was inspired by a book that eventually led him to leave academia and pursue his passion for deep tech.</p><p>Gaurav regularly speaks with CISOs, gaining firsthand insights into their biggest challenges as they navigate an increasingly complex cybersecurity landscape. As regulatory scrutiny around security disclosures intensifies, Gaurav offers a unique perspective on how AI can reshape the future of risk management, helping organizations strike the right balance between innovation and security.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we examine how AI is revolutionizing compliance with Dr. Gaurav Banga, CEO of Balbix.</p><p>Gaurav Banga, the CEO and Founder of Balbix, an AI-powered cybersecurity risk management startup. Gaurav is an accomplished inventor with over 50 patents to his name, and he has a deep background in founding and leading multiple successful tech ventures. His journey into entrepreneurship is unique—it began over a decade ago when he was inspired by a book that eventually led him to leave academia and pursue his passion for deep tech.</p><p>Gaurav regularly speaks with CISOs, gaining firsthand insights into their biggest challenges as they navigate an increasingly complex cybersecurity landscape. As regulatory scrutiny around security disclosures intensifies, Gaurav offers a unique perspective on how AI can reshape the future of risk management, helping organizations strike the right balance between innovation and security.</p>]]>
      </content:encoded>
      <pubDate>Wed, 23 Oct 2024 07:18:50 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a2d6d9d1/b137246c.mp3" length="21673959" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/f0mQi2p97vj9rMKCFcOr3699FtOX9qDhalilVLqz9IA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83MzEw/ZWU3MmU3NTVjY2Rk/ZTUxNDNiZmFmMTY4/MjgxMS5wbmc.jpg"/>
      <itunes:duration>1790</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we examine how AI is revolutionizing compliance with Dr. Gaurav Banga, CEO of Balbix.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we examine how AI is revolutionizing compliance with Dr. Gaurav Banga, CEO of Balbix.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#164 - Intel Chat: Wazuh, .io, AI, Discord, Palo Alto &amp; GoldenJackal</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>164</itunes:episode>
      <podcast:episode>164</podcast:episode>
      <itunes:title>#164 - Intel Chat: Wazuh, .io, AI, Discord, Palo Alto &amp; GoldenJackal</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">59e3c127-90c8-468f-8c82-67b073ad3ad7</guid>
      <link>https://share.transistor.fm/s/28f3a58d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A recent malware campaign has been discovered that exploits the open-source Wazuh SIEM agent to deliver a <a rel="noreferrer noopener" href="https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/">cryptomining payload</a>. </li><li>There is uncertainty surrounding the .io domain following the UK’s decision to return the Chagos Islands, including the <a rel="noreferrer noopener" href="https://every.to/p/the-disappearance-of-an-internet-domain">British Indian Ocean Territory, to Mauritius</a>.</li><li>The October 2024 report, "Influence and Cyber Operations," explores how AI is being leveraged by both state and non-state actors in cyber campaigns. Key findings show that AI tools are increasingly being used to enhance traditional cyberattacks, particularly in areas like vulnerability research, <a rel="noreferrer noopener" href="https://cdn.openai.com/threat-intelligence-reports/influence-and-cyber-operations-an-update_October-2024.pdf">malware debugging, and influence operations</a>. </li><li>Discord has recently been blocked in both Russia and Turkey due to claims of illegal activity on <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/government/discord-blocked-in-russia-and-turkey-for-spreading-illegal-content/">the platform</a>.</li><li>Palo Alto Networks recently patched several critical vulnerabilities in its Expedition tool, which could allow attackers to take control of firewall systems. The most severe flaw, CVE-2024-9463, allows unauthenticated attackers to execute arbitrary OS commands as root, exposing sensitive data like <a rel="noreferrer noopener" href="https://www.securityweek.com/palo-alto-patches-critical-firewall-takeover-vulnerabilities/">usernames, passwords, and API keys</a>.</li><li>The article from ESET highlights a cyberespionage campaign conducted by a group known as GoldenJackal, which is targeting government and diplomatic entities, focusing specifically on air-gapped systems in regions such as Europe, <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/">the Middle East, and South Asia</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A recent malware campaign has been discovered that exploits the open-source Wazuh SIEM agent to deliver a <a rel="noreferrer noopener" href="https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/">cryptomining payload</a>. </li><li>There is uncertainty surrounding the .io domain following the UK’s decision to return the Chagos Islands, including the <a rel="noreferrer noopener" href="https://every.to/p/the-disappearance-of-an-internet-domain">British Indian Ocean Territory, to Mauritius</a>.</li><li>The October 2024 report, "Influence and Cyber Operations," explores how AI is being leveraged by both state and non-state actors in cyber campaigns. Key findings show that AI tools are increasingly being used to enhance traditional cyberattacks, particularly in areas like vulnerability research, <a rel="noreferrer noopener" href="https://cdn.openai.com/threat-intelligence-reports/influence-and-cyber-operations-an-update_October-2024.pdf">malware debugging, and influence operations</a>. </li><li>Discord has recently been blocked in both Russia and Turkey due to claims of illegal activity on <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/government/discord-blocked-in-russia-and-turkey-for-spreading-illegal-content/">the platform</a>.</li><li>Palo Alto Networks recently patched several critical vulnerabilities in its Expedition tool, which could allow attackers to take control of firewall systems. The most severe flaw, CVE-2024-9463, allows unauthenticated attackers to execute arbitrary OS commands as root, exposing sensitive data like <a rel="noreferrer noopener" href="https://www.securityweek.com/palo-alto-patches-critical-firewall-takeover-vulnerabilities/">usernames, passwords, and API keys</a>.</li><li>The article from ESET highlights a cyberespionage campaign conducted by a group known as GoldenJackal, which is targeting government and diplomatic entities, focusing specifically on air-gapped systems in regions such as Europe, <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/">the Middle East, and South Asia</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Mon, 21 Oct 2024 14:04:38 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/28f3a58d/53f4bcb1.mp3" length="29426033" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/urkTlDLOGe-8jnatHUcEtrTpyCAR1y-qAl1oxHZ3cXk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85ZTUz/Y2ZhNWJhOWEyMjdk/Yjc4ZGY3YmU3OWIy/MmE5ZS5wbmc.jpg"/>
      <itunes:duration>2436</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#163 - Practical applications of AI in cybersecurity with Rich Heimann, AI researcher &amp; author</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>163</itunes:episode>
      <podcast:episode>163</podcast:episode>
      <itunes:title>#163 - Practical applications of AI in cybersecurity with Rich Heimann, AI researcher &amp; author</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b338738c-96f2-4d14-8266-d7adc1f394bf</guid>
      <link>https://share.transistor.fm/s/8397eb66</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Rich Heimann, AI researcher and author.</p><p>Rich is a visionary leader in artificial intelligence and business transformation. As a Chief Artificial Intelligence Officer, Rich has a proven track record of developing and deploying AI solutions that drive measurable impact across a range of industries. Known for his ability to blend technical expertise with strategic insight, he consistently helps organizations unlock the full potential of AI to achieve real business results. Rich is also committed to ethical AI practices and excels at building innovative, high-performing teams. He’s recently authored a new book titled <a rel="noreferrer noopener" href="https://www.amazon.ca/Generative-Artificial-Intelligence-Revealed-Understanding/dp/B0DH3MGR3V">Generative Artificial Intelligence Revealed</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Rich Heimann, AI researcher and author.</p><p>Rich is a visionary leader in artificial intelligence and business transformation. As a Chief Artificial Intelligence Officer, Rich has a proven track record of developing and deploying AI solutions that drive measurable impact across a range of industries. Known for his ability to blend technical expertise with strategic insight, he consistently helps organizations unlock the full potential of AI to achieve real business results. Rich is also committed to ethical AI practices and excels at building innovative, high-performing teams. He’s recently authored a new book titled <a rel="noreferrer noopener" href="https://www.amazon.ca/Generative-Artificial-Intelligence-Revealed-Understanding/dp/B0DH3MGR3V">Generative Artificial Intelligence Revealed</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 17 Oct 2024 15:27:50 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8397eb66/b7eb0da7.mp3" length="33548521" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/iuBA10QeNMGFtNRgOBy1tREbTbL67cCoFZTsuhqS_40/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83N2E2/NTViYzZmZmNkYTE3/MDNjMjFmN2I4MmIx/OWExZS5wbmc.jpg"/>
      <itunes:duration>2780</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Rich Heimann, AI researcher and author.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Rich Heimann, AI researcher and author.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#162 - Intel Chat: FIN7, COLDRIVER, perfectly, Comcast &amp; EKUwu</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>162</itunes:episode>
      <podcast:episode>162</podcast:episode>
      <itunes:title>#162 - Intel Chat: FIN7, COLDRIVER, perfectly, Comcast &amp; EKUwu</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4e9fd4b3-ee5c-4e09-a4e1-b35003566dc7</guid>
      <link>https://share.transistor.fm/s/49f524e5</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Silent Push's recent analysis reveals new tactics by the FIN7 cybercriminal group, which is leveraging AI-based “DeepNude Generators” as part of a phishing campaign to <a rel="noreferrer noopener" href="https://www.silentpush.com/blog/fin7-malware-deepfake-ai-honeypot/">spread malware</a>. </li><li>Microsoft's Digital Crimes Unit (DCU), in partnership with the U.S. Department of Justice, has taken steps to dismantle cyber operations by Star Blizzard, a Russian state-affiliated actor <a rel="noreferrer noopener" href="https://blogs.microsoft.com/on-the-issues/2024/10/03/protecting-democratic-institutions-from-cyber-threats/">also known as COLDRIVER</a>.</li><li>Aqua Security's detailed research on perfctl describes it as a highly stealthy malware that targets Linux servers using a range of <a rel="noreferrer noopener" href="https://www.aquasec.com/blog/perfctl-a-stealthy-malware-targeting-millions-of-linux-servers/">sophisticated methods</a>.</li><li>Comcast recently disclosed that over 237,000 customers had their personal data compromised due to a ransomware attack targeting a former debt collection agency, <a rel="noreferrer noopener" href="https://techcrunch.com/2024/10/07/comcast-says-customer-data-stolen-in-ransomware-attack-on-debt-collection-agency/">Financial Business and Consumer Solutions (FBCS)</a>.</li><li>TrustedSec's research on EKUwu sheds light on a significant Active Directory Certificate Services (AD CS) vulnerability that allows attackers to misuse version 1 <a rel="noreferrer noopener" href="https://trustedsec.com/blog/ekuwu-not-just-another-ad-cs-esc">certificate templates</a>. </li></ul><p><a rel="noreferrer noopener" href="https://www.linkedin.com/posts/resilientcyber_ciso-cyber-business-activity-7249760601151868928-fl0V">Stats on business outcomes after breaches referenced by Matt.</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Silent Push's recent analysis reveals new tactics by the FIN7 cybercriminal group, which is leveraging AI-based “DeepNude Generators” as part of a phishing campaign to <a rel="noreferrer noopener" href="https://www.silentpush.com/blog/fin7-malware-deepfake-ai-honeypot/">spread malware</a>. </li><li>Microsoft's Digital Crimes Unit (DCU), in partnership with the U.S. Department of Justice, has taken steps to dismantle cyber operations by Star Blizzard, a Russian state-affiliated actor <a rel="noreferrer noopener" href="https://blogs.microsoft.com/on-the-issues/2024/10/03/protecting-democratic-institutions-from-cyber-threats/">also known as COLDRIVER</a>.</li><li>Aqua Security's detailed research on perfctl describes it as a highly stealthy malware that targets Linux servers using a range of <a rel="noreferrer noopener" href="https://www.aquasec.com/blog/perfctl-a-stealthy-malware-targeting-millions-of-linux-servers/">sophisticated methods</a>.</li><li>Comcast recently disclosed that over 237,000 customers had their personal data compromised due to a ransomware attack targeting a former debt collection agency, <a rel="noreferrer noopener" href="https://techcrunch.com/2024/10/07/comcast-says-customer-data-stolen-in-ransomware-attack-on-debt-collection-agency/">Financial Business and Consumer Solutions (FBCS)</a>.</li><li>TrustedSec's research on EKUwu sheds light on a significant Active Directory Certificate Services (AD CS) vulnerability that allows attackers to misuse version 1 <a rel="noreferrer noopener" href="https://trustedsec.com/blog/ekuwu-not-just-another-ad-cs-esc">certificate templates</a>. </li></ul><p><a rel="noreferrer noopener" href="https://www.linkedin.com/posts/resilientcyber_ciso-cyber-business-activity-7249760601151868928-fl0V">Stats on business outcomes after breaches referenced by Matt.</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 10 Oct 2024 14:30:59 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/49f524e5/c1b5a9c1.mp3" length="21620320" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/sN1ZEMZAsczAwu0YFml4x9hcz3ce102KnRsM-zgc_Lo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMzRj/Y2VlZWEwNTNjMjk4/NWE3NjQ3Nzk1MDQx/M2YzMy5wbmc.jpg"/>
      <itunes:duration>1786</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#161 - Intel Chat: MSSN CTRL, CRI summit, Shadow AI, More_Eggs, Andariel hacking group &amp; DrayTek routers</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>161</itunes:episode>
      <podcast:episode>161</podcast:episode>
      <itunes:title>#161 - Intel Chat: MSSN CTRL, CRI summit, Shadow AI, More_Eggs, Andariel hacking group &amp; DrayTek routers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d3775d67-bdf7-4f8e-a613-8d87b6f85625</guid>
      <link>https://share.transistor.fm/s/0ed614a6</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>The White House recently hosted the International Counter Ransomware Initiative (CRI) summit, bringing together representatives from 68 countries to address the growing <a rel="noreferrer noopener" href="https://www.bankinfosecurity.com/white-house-pledges-major-deliverables-at-ransomware-summit-a-26418">global threat of ransomware</a>.</li><li>The rise of "Shadow AI," which refers to the unauthorized use of AI tools by employees without the oversight of IT departments, poses <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/shadow-ai-sensitive-data-exposure-workplace-chatbot-use">significant risks for organizations</a>. </li><li>A new wave of attacks leveraging the More_Eggs backdoor malware has been specifically targeting recruiters. TA4557, a financially motivated group linked to North Korea, has been distributing this <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/attackers-targeting-recruiters-more_eggs-backdoor">backdoor since late 2023</a>.</li><li>The Andariel hacking group, a subgroup of North Korea’s Lazarus Group, has turned its attention to financially motivated <a rel="noreferrer noopener" href="https://thehackernews.com/2024/10/andariel-hacker-group-shifts-focus-to.html">attacks against U.S. organizations</a>.</li><li>Forescout Vedere Labs has uncovered 14 vulnerabilities affecting over 700,000 DrayTek routers, with two critical flaws posing <a rel="noreferrer noopener" href="https://thehackernews.com/2024/10/alert-over-700000-draytek-routers.html">significant security risks</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>The White House recently hosted the International Counter Ransomware Initiative (CRI) summit, bringing together representatives from 68 countries to address the growing <a rel="noreferrer noopener" href="https://www.bankinfosecurity.com/white-house-pledges-major-deliverables-at-ransomware-summit-a-26418">global threat of ransomware</a>.</li><li>The rise of "Shadow AI," which refers to the unauthorized use of AI tools by employees without the oversight of IT departments, poses <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/shadow-ai-sensitive-data-exposure-workplace-chatbot-use">significant risks for organizations</a>. </li><li>A new wave of attacks leveraging the More_Eggs backdoor malware has been specifically targeting recruiters. TA4557, a financially motivated group linked to North Korea, has been distributing this <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/attackers-targeting-recruiters-more_eggs-backdoor">backdoor since late 2023</a>.</li><li>The Andariel hacking group, a subgroup of North Korea’s Lazarus Group, has turned its attention to financially motivated <a rel="noreferrer noopener" href="https://thehackernews.com/2024/10/andariel-hacker-group-shifts-focus-to.html">attacks against U.S. organizations</a>.</li><li>Forescout Vedere Labs has uncovered 14 vulnerabilities affecting over 700,000 DrayTek routers, with two critical flaws posing <a rel="noreferrer noopener" href="https://thehackernews.com/2024/10/alert-over-700000-draytek-routers.html">significant security risks</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Tue, 08 Oct 2024 17:50:25 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0ed614a6/ef88648d.mp3" length="29230500" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/p9dHab7TI5fvRQQ8J9b9ZvtK5arfxIy4ztvKpSz5LQY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zOTll/MzZiYTk1NjRjM2E2/YmMwZWE4ZTEzMDU5/OTgwNi5wbmc.jpg"/>
      <itunes:duration>2420</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#160 - Cryptocurrency and its role in money laundering with BBC journalist and author Geoff White</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>160</itunes:episode>
      <podcast:episode>160</podcast:episode>
      <itunes:title>#160 - Cryptocurrency and its role in money laundering with BBC journalist and author Geoff White</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">051799d7-fc93-417a-bc74-cc2e76f99ab8</guid>
      <link>https://share.transistor.fm/s/12784c37</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we dive into cryptocurrency and it’s role in money laundering with BBC journalist and author Geoff White.</p><p>Geoff is an accomplished author, speaker, investigative journalist, and podcast creator with over 20 years of experience, focusing on organized crime and technology. He has worked with major outlets including the BBC, Audible, Penguin, Sky News, and The Sunday Times, covering topics such as financial crime, money laundering, cryptocurrency, and cybercrime. His recently released book, Rinsed, dives into how technology is transforming the money laundering industry, and was published by Penguin back in June of 2024.</p><p>His previous book, The Lazarus Heist, followed the success of the hit BBC podcast series he co-hosted, which investigated North Korea’s cyber operations. He’s also the author of Crime Dot Com, which explores the global rise of hacking, and has created multiple podcast series for Audible, including The Dark Web and Artificial Intelligence: Friend or Foe?</p><p>In addition to writing, he is a sought-after public speaker who has given keynote talks for brands like Microsoft, MasterCard, and HSBC. He has also won numerous awards for his reporting, including his work on the Snowden leaks and his investigations into internet fraud.</p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Rinsed-Cartels-Crypto-Industry-Deadliest/dp/0241624835">Rinsed: From Cartels to Crypto How the Tech Industry Washes Money for the World's Deadliest Crooks</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we dive into cryptocurrency and it’s role in money laundering with BBC journalist and author Geoff White.</p><p>Geoff is an accomplished author, speaker, investigative journalist, and podcast creator with over 20 years of experience, focusing on organized crime and technology. He has worked with major outlets including the BBC, Audible, Penguin, Sky News, and The Sunday Times, covering topics such as financial crime, money laundering, cryptocurrency, and cybercrime. His recently released book, Rinsed, dives into how technology is transforming the money laundering industry, and was published by Penguin back in June of 2024.</p><p>His previous book, The Lazarus Heist, followed the success of the hit BBC podcast series he co-hosted, which investigated North Korea’s cyber operations. He’s also the author of Crime Dot Com, which explores the global rise of hacking, and has created multiple podcast series for Audible, including The Dark Web and Artificial Intelligence: Friend or Foe?</p><p>In addition to writing, he is a sought-after public speaker who has given keynote talks for brands like Microsoft, MasterCard, and HSBC. He has also won numerous awards for his reporting, including his work on the Snowden leaks and his investigations into internet fraud.</p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Rinsed-Cartels-Crypto-Industry-Deadliest/dp/0241624835">Rinsed: From Cartels to Crypto How the Tech Industry Washes Money for the World's Deadliest Crooks</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 03 Oct 2024 20:17:28 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/12784c37/133f6eb2.mp3" length="35251919" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/-Teq2Fgf1GvSIR6YsNQ0InxOSvbGy2BTytNrcbHgJhg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83NjMz/M2JkOTJmNjk4Mjkw/Zjg2MGRmOGMwOGVh/MjQwOS5wbmc.jpg"/>
      <itunes:duration>2922</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we dive into cryptocurrency and it’s role in money laundering with BBC journalist and author Geoff White.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we dive into cryptocurrency and it’s role in money laundering with BBC journalist and author Geoff White.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#159 - Intel Chat: Sequoia disruption, Github, Supershell, DPRK &amp; Telegram arrest</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>159</itunes:episode>
      <podcast:episode>159</podcast:episode>
      <itunes:title>#159 - Intel Chat: Sequoia disruption, Github, Supershell, DPRK &amp; Telegram arrest</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">24a7ab4f-2671-4992-8784-1af9be99d662</guid>
      <link>https://share.transistor.fm/s/6c49f9e3</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Apple’s release of macOS 15, or Sequoia, has caused significant disruptions for several security tools and software vendors, including CrowdStrike, SentinelOne, Microsoft, <a rel="noreferrer noopener" href="https://techcrunch.com/2024/09/19/apples-new-macos-sequoia-update-is-breaking-some-cybersecurity-tools/">and others</a>.</li><li>Attackers are exploiting GitHub notifications for phishing by sending legitimate-looking alerts with <a rel="noreferrer noopener" href="https://giomke.github.io/posts/githubphishing/post/">malicious URLs</a>.</li><li>Truffle Security's research exposes a significant issue in GitHub’s handling of deleted and private repository data via <a rel="noreferrer noopener" href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github">Cross Fork Object Reference (CFOR)</a>.</li><li>AhnLab’s report details Supershell, a malware targeting Linux SSH servers via <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/83232/">brute-force attacks</a>.</li><li>Since 2022, Mandiant has tracked DPRK IT workers infiltrating global organizations by posing as non-North Koreans to fund the regime's weapons programs and <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/mitigating-dprk-it-worker-threat?e=48754805">evade sanctions</a>.</li><li>In August 2024, Telegram CEO Pavel Durov was arrested in France, facing charges for allowing <a rel="noreferrer noopener" href="https://www.cnn.com/2024/09/23/tech/telegram-ceo-durov-arrest-user-data-changes/index.html">criminal activities to proliferate on the platform</a>, including the distribution of illegal content such as child sexual abuse material.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Apple’s release of macOS 15, or Sequoia, has caused significant disruptions for several security tools and software vendors, including CrowdStrike, SentinelOne, Microsoft, <a rel="noreferrer noopener" href="https://techcrunch.com/2024/09/19/apples-new-macos-sequoia-update-is-breaking-some-cybersecurity-tools/">and others</a>.</li><li>Attackers are exploiting GitHub notifications for phishing by sending legitimate-looking alerts with <a rel="noreferrer noopener" href="https://giomke.github.io/posts/githubphishing/post/">malicious URLs</a>.</li><li>Truffle Security's research exposes a significant issue in GitHub’s handling of deleted and private repository data via <a rel="noreferrer noopener" href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github">Cross Fork Object Reference (CFOR)</a>.</li><li>AhnLab’s report details Supershell, a malware targeting Linux SSH servers via <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/83232/">brute-force attacks</a>.</li><li>Since 2022, Mandiant has tracked DPRK IT workers infiltrating global organizations by posing as non-North Koreans to fund the regime's weapons programs and <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/mitigating-dprk-it-worker-threat?e=48754805">evade sanctions</a>.</li><li>In August 2024, Telegram CEO Pavel Durov was arrested in France, facing charges for allowing <a rel="noreferrer noopener" href="https://www.cnn.com/2024/09/23/tech/telegram-ceo-durov-arrest-user-data-changes/index.html">criminal activities to proliferate on the platform</a>, including the distribution of illegal content such as child sexual abuse material.</li></ul>]]>
      </content:encoded>
      <pubDate>Mon, 30 Sep 2024 07:30:12 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6c49f9e3/2d014b1b.mp3" length="28210425" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/3VOhgNNlpiAZDpAG7LcBO02lNYCSA8ZFF51kN2Nt15M/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iZDg4/NjJlMDIxMmUzNjFm/MDFlZjU2MTBiZjIx/NzVkNy5wbmc.jpg"/>
      <itunes:duration>2335</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#158 - Common pitfalls for founders with Andrew Plato, Founder &amp; CEO of Zenaciti</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>156</itunes:episode>
      <podcast:episode>156</podcast:episode>
      <itunes:title>#158 - Common pitfalls for founders with Andrew Plato, Founder &amp; CEO of Zenaciti</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e8cceecd-71ad-4fdc-80b7-5c82199b79c3</guid>
      <link>https://share.transistor.fm/s/15973f98</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about some of the common pitfalls faced by founders with Andrew Plato, Founder &amp; CEO of <a rel="noreferrer noopener" href="https://zenaciti.com/">Zenaciti</a>.</p><p>Andrew is an experienced CEO, founder, author, and cybersecurity expert. In 1995, Andrew founded Anitian, one of the earliest cybersecurity companies on record, where he pioneered innovations in intrusion detection, endpoint security, and cloud security. He led the development of a revolutionary automated platform for secure cloud environments, and under his leadership, Anitian formed strategic partnerships with major tech companies like AWS, Microsoft, and Trend Micro before he exited the company in 2022. Andrew also leads Zenaciti, providing business and security intelligence, and recently founded Screenopolis, focusing on media analysis. He is also the author of <a rel="noreferrer noopener" href="https://www.amazon.com/Founders-User-Manual-Practical-Strategies/dp/B0CZXP7TNF">The Founder’s User Manual: Practical Strategies for the Startup Leader.</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about some of the common pitfalls faced by founders with Andrew Plato, Founder &amp; CEO of <a rel="noreferrer noopener" href="https://zenaciti.com/">Zenaciti</a>.</p><p>Andrew is an experienced CEO, founder, author, and cybersecurity expert. In 1995, Andrew founded Anitian, one of the earliest cybersecurity companies on record, where he pioneered innovations in intrusion detection, endpoint security, and cloud security. He led the development of a revolutionary automated platform for secure cloud environments, and under his leadership, Anitian formed strategic partnerships with major tech companies like AWS, Microsoft, and Trend Micro before he exited the company in 2022. Andrew also leads Zenaciti, providing business and security intelligence, and recently founded Screenopolis, focusing on media analysis. He is also the author of <a rel="noreferrer noopener" href="https://www.amazon.com/Founders-User-Manual-Practical-Strategies/dp/B0CZXP7TNF">The Founder’s User Manual: Practical Strategies for the Startup Leader.</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 26 Sep 2024 19:31:34 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/15973f98/ffd7893a.mp3" length="36324264" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/JKpEHULPQp0_EgCyBgrRjzSWXCvmFBJXex4lw7AWQ8U/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yYzVj/NTZjYjgwYWMxYWY5/ZmQ2Y2RmMDJkYTFj/NjI2ZC5wbmc.jpg"/>
      <itunes:duration>3011</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk about some of the common pitfalls faced by founders with Andrew Plato, Founder &amp;amp; CEO of Zenaciti.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk about some of the common pitfalls faced by founders with Andrew Plato, Founder &amp;amp; CEO of Zenaciti.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#157 - Low noise threat detection with Joshua Neil, Founder at Alpha Level</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>157</itunes:episode>
      <podcast:episode>157</podcast:episode>
      <itunes:title>#157 - Low noise threat detection with Joshua Neil, Founder at Alpha Level</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8a143159-aae9-4ecb-a995-567f60113105</guid>
      <link>https://share.transistor.fm/s/1d37d35f</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about low noise threat detection with Joshua Neil, Founder at <a rel="noreferrer noopener" href="https://alphalevel.ai/">Alpha Level</a>.</p><p>Josh is a seasoned expert with over 20 years of experience in developing data-driven solutions to security challenges faced by both the U.S. Government and industry at large. With a deep understanding of enterprise security, they are focused on the fact that perimeter defenses alone aren't enough to prevent attackers from breaching systems. They emphasize the importance of visibility into enterprise behavior, the need for statistical methods in attack detection, and the interconnected nature of attacks across multiple endpoints. Their work revolves around quantifying security-relevant rare events and leveraging context to support analysts in distinguishing true breaches from false positives.</p><p><a rel="noreferrer noopener" href="https://www.amazon.ca/Statistical-Inference-George-Casella/dp/0534243126">Statistical Inference by George Casella and Roger Berger</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about low noise threat detection with Joshua Neil, Founder at <a rel="noreferrer noopener" href="https://alphalevel.ai/">Alpha Level</a>.</p><p>Josh is a seasoned expert with over 20 years of experience in developing data-driven solutions to security challenges faced by both the U.S. Government and industry at large. With a deep understanding of enterprise security, they are focused on the fact that perimeter defenses alone aren't enough to prevent attackers from breaching systems. They emphasize the importance of visibility into enterprise behavior, the need for statistical methods in attack detection, and the interconnected nature of attacks across multiple endpoints. Their work revolves around quantifying security-relevant rare events and leveraging context to support analysts in distinguishing true breaches from false positives.</p><p><a rel="noreferrer noopener" href="https://www.amazon.ca/Statistical-Inference-George-Casella/dp/0534243126">Statistical Inference by George Casella and Roger Berger</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 24 Sep 2024 11:59:28 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1d37d35f/0a9a1b0b.mp3" length="67345548" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2806</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk about low noise threat detection with Joshua Neil, Founder at Alpha Level.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk about low noise threat detection with Joshua Neil, Founder at Alpha Level.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#156 - Intel Chat: Fortibitch, Hadooken, Void Banshee &amp; CloudImposer</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>156</itunes:episode>
      <podcast:episode>156</podcast:episode>
      <itunes:title>#156 - Intel Chat: Fortibitch, Hadooken, Void Banshee &amp; CloudImposer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d60cec88-8fc7-4a2d-b2cc-e46f52546a9e</guid>
      <link>https://share.transistor.fm/s/285f6e7c</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Fortinet responded by confirming that the breach involved unauthorized access to files on a third-party cloud-based shared drive, affecting a <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/fortinet-confirms-data-breach-after-hacker-claims-to-steal-440gb-of-files/">small portion of customer data</a>.</li><li>Hackers are targeting Oracle WebLogic servers with a new Linux malware named "Hadooken," which is designed to deploy a cryptominer and facilitate <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/new-linux-malware-hadooken-targets-oracle-weblogic-servers/">distributed denial-of-service (DDoS) attacks</a>.  </li><li>Microsoft has reclassified a previously patched bug, CVE-2024-43461, as a zero-day vulnerability actively exploited by <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/void-banshee-exploits-second-microsoft-zero-day">the "Void Banshee" threat group.</a></li><li>Security researchers from Tenable revealed a critical remote code execution vulnerability in Google Cloud Platform that could have allowed attackers to run malicious code on <a rel="noreferrer noopener" href="https://cybersecuritynews.com/gcp-rce-flaw/">millions of Google’s servers.</a> </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Fortinet responded by confirming that the breach involved unauthorized access to files on a third-party cloud-based shared drive, affecting a <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/fortinet-confirms-data-breach-after-hacker-claims-to-steal-440gb-of-files/">small portion of customer data</a>.</li><li>Hackers are targeting Oracle WebLogic servers with a new Linux malware named "Hadooken," which is designed to deploy a cryptominer and facilitate <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/new-linux-malware-hadooken-targets-oracle-weblogic-servers/">distributed denial-of-service (DDoS) attacks</a>.  </li><li>Microsoft has reclassified a previously patched bug, CVE-2024-43461, as a zero-day vulnerability actively exploited by <a rel="noreferrer noopener" href="https://www.darkreading.com/application-security/void-banshee-exploits-second-microsoft-zero-day">the "Void Banshee" threat group.</a></li><li>Security researchers from Tenable revealed a critical remote code execution vulnerability in Google Cloud Platform that could have allowed attackers to run malicious code on <a rel="noreferrer noopener" href="https://cybersecuritynews.com/gcp-rce-flaw/">millions of Google’s servers.</a> </li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 20 Sep 2024 07:30:12 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/285f6e7c/07add4e7.mp3" length="23560707" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/cv-ialQ0XdAG7SiwEHnlqa9o6MaMWgNZPh7t1Q_hCj8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yY2Vj/ODhhNWRkZWZkMjI3/NzBlNmQwMjlhZTky/MTBiNS5wbmc.jpg"/>
      <itunes:duration>1947</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#155 - A look at quantum cryptography with David Carvalho, CEO &amp; Chief Scientist at Naoris Protocol</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>155</itunes:episode>
      <podcast:episode>155</podcast:episode>
      <itunes:title>#155 - A look at quantum cryptography with David Carvalho, CEO &amp; Chief Scientist at Naoris Protocol</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d876c795-0f33-4362-9580-b29cfcef3f83</guid>
      <link>https://share.transistor.fm/s/0668c17f</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a look at quantum cryptography with David Carvalho, CEO &amp; Chief Scientist at Naoris Protocol.</p><p>David is the founder, CEO, and Chief Scientist of Naoris Protocol, a decentralized cybersecurity mesh. David is an accomplished leader and innovator who advises nation-states and highly regulated sectors on critical issues such as cyber espionage, cyber warfare, and cyber terrorism. He is deeply involved in blockchain-based projects, digital currencies, and cybersecurity innovations. With over 20 years of experience in the field, David has worked as a Chief Information Security Officer in multi-billion-dollar companies and brings a forward-thinking approach to risk mitigation, automation, AI, and next-gen cybersecurity. He continues to advise a wide range of organizations, from startups to national-level projects, on transformative strategies for the future.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a look at quantum cryptography with David Carvalho, CEO &amp; Chief Scientist at Naoris Protocol.</p><p>David is the founder, CEO, and Chief Scientist of Naoris Protocol, a decentralized cybersecurity mesh. David is an accomplished leader and innovator who advises nation-states and highly regulated sectors on critical issues such as cyber espionage, cyber warfare, and cyber terrorism. He is deeply involved in blockchain-based projects, digital currencies, and cybersecurity innovations. With over 20 years of experience in the field, David has worked as a Chief Information Security Officer in multi-billion-dollar companies and brings a forward-thinking approach to risk mitigation, automation, AI, and next-gen cybersecurity. He continues to advise a wide range of organizations, from startups to national-level projects, on transformative strategies for the future.</p>]]>
      </content:encoded>
      <pubDate>Thu, 19 Sep 2024 07:30:12 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0668c17f/aea0a4e9.mp3" length="31684955" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/LXnQCncZfZGxAqpUBS9zVzUTuJLrIrrDe8OfveVxtrI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kOTQ0/ZmM0NWVjNjNjM2Ri/NWJmNGJiYWE1Yjdl/MTFmYS5wbmc.jpg"/>
      <itunes:duration>2624</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we take a look at quantum cryptography with David Carvalho, CEO &amp;amp; Chief Scientist at Naoris Protocol.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we take a look at quantum cryptography with David Carvalho, CEO &amp;amp; Chief Scientist at Naoris Protocol.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#154 - Intel Chat: Specula, Chromium, Mustang Panda &amp; Service for America</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>154</itunes:episode>
      <podcast:episode>154</podcast:episode>
      <itunes:title>#154 - Intel Chat: Specula, Chromium, Mustang Panda &amp; Service for America</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e68226c2-b969-4606-9dc8-f0fa543c3139</guid>
      <link>https://share.transistor.fm/s/9d37a982</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>The Specula C2 framework represents a sophisticated attack method that transforms Microsoft Outlook into a command-and-control system by <a rel="noreferrer noopener" href="https://blog.snapattack.com/hunting-specula-c2-framework-and-xll-execution-0e9165ba1058">exploiting its Home Page feature</a>. </li><li>Attackers exploit browser notifications in Chromium-based browsers by tricking users through <a rel="noreferrer noopener" href="https://blog.nviso.eu/2024/09/06/hunting-chromium-notifications/">CAPTCHA-like prompts to enable notifications</a>.</li><li>The Biden administration has launched an initiative aimed at addressing the growing cybersecurity talent shortage, which has reached <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/cybersecurity-talent-shortage-prompts-white-house-action">critical levels</a>. </li><li>Mustang Panda, a Chinese state-backed cyber-espionage group, has adapted its tactics by launching a USB-based attack campaign that leverages a worm for self-propagation <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/mustang-panda-worm-driven-usb-attack">across air-gapped networks</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>The Specula C2 framework represents a sophisticated attack method that transforms Microsoft Outlook into a command-and-control system by <a rel="noreferrer noopener" href="https://blog.snapattack.com/hunting-specula-c2-framework-and-xll-execution-0e9165ba1058">exploiting its Home Page feature</a>. </li><li>Attackers exploit browser notifications in Chromium-based browsers by tricking users through <a rel="noreferrer noopener" href="https://blog.nviso.eu/2024/09/06/hunting-chromium-notifications/">CAPTCHA-like prompts to enable notifications</a>.</li><li>The Biden administration has launched an initiative aimed at addressing the growing cybersecurity talent shortage, which has reached <a rel="noreferrer noopener" href="https://www.darkreading.com/cybersecurity-operations/cybersecurity-talent-shortage-prompts-white-house-action">critical levels</a>. </li><li>Mustang Panda, a Chinese state-backed cyber-espionage group, has adapted its tactics by launching a USB-based attack campaign that leverages a worm for self-propagation <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/mustang-panda-worm-driven-usb-attack">across air-gapped networks</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 12 Sep 2024 07:30:13 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9d37a982/9b902840.mp3" length="20817547" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/m_7ibGbURpouJrnrcRM4O3qfqGFL-xqCHxqaSJCtPfc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMWI2/ZWY3MWQ3NDgzMzA5/YWViYzMwZTJiOGFj/Zjc5NC5wbmc.jpg"/>
      <itunes:duration>1719</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#153 - Unpacking the hacker mindset with Ken Westin, Senior Solutions Engineer at LimaCharlie</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>151</itunes:episode>
      <podcast:episode>151</podcast:episode>
      <itunes:title>#153 - Unpacking the hacker mindset with Ken Westin, Senior Solutions Engineer at LimaCharlie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">63561622-a4be-492f-968c-f9c4b5edde07</guid>
      <link>https://share.transistor.fm/s/de10edc6</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we unpack the hacker mindset with Ken Westin, Senior Solutions Engineer at LimaCharlie.</p><p>Ken is a seasoned thought leader in cybersecurity who has spent years analyzing and understanding the intricacies of cyber threats and the methods behind them. Ken has a unique ability to identify emerging trends in the industry and for figuring out how businesses can protect themselves before they fall victim to attacks. </p><p>Previous to his current role, Ken was the Field CISO at Panther, where he developed workshops and delivered them around the world. His career also includes significant contributions at Cybereason, Elastic, and Splunk, where he drove security growth, developed innovative tools, and shaped industry conversations on cybersecurity. Ken has been a key spokesperson in the industry, frequently quoted in the media and featured at major conferences like Black Hat and DEF CON.</p><p>Ken recently joined the team at LimaCharlie as a Senior Solutions Engineer, with the intent to use his deep expertise to help organizations build robust security strategies.</p><p>Ken's reading list:</p><p><a rel="noreferrer noopener" href="https://www.amazon.com/DAEMON-Daemon-Daniel-Suarez/dp/0451228731">“Daemon” - Daniel Suarez</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0380788624/ref=sr_1_1?crid=3PIZ7J2M0E7K7&amp;dib=eyJ2IjoiMSJ9.zefEBDXIkLzS7eoUzBdcYwpVzrgRBDQ09Xrotd71__m2_N5WzsYgIefeCwpM2uuJcvv86vTZMYiFkzXIU9qGUfLD3iFEPbLdOl06n6ok6l-EIC2sL2Feptq2taNOSwvQ8uEgCGeAtl7Q8-4QVjghm6QywqB5bSeRPbPzTHYTx0gNxEpAmJUnUUf863DPvhhKlnTICgeoc2cw3XF16SMuzgu4YCRIfEzwoDs_wkwTxzE.yOMbIOC31lbUdB9crRf_uW_LvxnYYHIQNaRO4LzC8KA&amp;dib_tag=se&amp;keywords=%E2%80%9CCryptonomicon%E2%80%9D+-+Neal+Stephenson&amp;qid=1725945818&amp;s=books&amp;sprefix=cryptonomicon+-+neal+stephenson%2Cstripbooks%2C237&amp;sr=1-1">“Cryptonomicon” -  Neal Stephenson</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Myth-Normal-Illness-Healing-Culture/dp/0593083881/ref=sr_1_1?crid=37XI29QRJD56Z&amp;dib=eyJ2IjoiMSJ9.SNhv6R0yBm7q5giqshgLX0Q6UJxsY5TzMmnUGCioBxo.KiMXiXUEisJzdD9YxV5DDllXoJKEWiArdm44WlSfFkI&amp;dib_tag=se&amp;keywords=%E2%80%9CCryptonomicon%E2%80%9D+-+Nea%E2%80%9CThe+Myth+of+Normal%E2%80%9D+-+Gabor+Mat%C3%A9l+Stephenson&amp;qid=1725945848&amp;s=books&amp;sprefix=cryptonomicon+-+nea+the+myth+of+normal+-+gabor+mat%C3%A9l+stephenson%2Cstripbooks%2C263&amp;sr=1-1">“The Myth of Normal” - Gabor Maté</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Threats-Every-Engineer-Should-Learn/dp/1119895162/ref=sr_1_1?crid=3G8QF848TZ7YC&amp;dib=eyJ2IjoiMSJ9.aqeaHHF3mhnlBBzA1ZO7tw.W5y-w7LsR-izpBH1XDavEisjHkXvLvNklfCGpPwVtNs&amp;dib_tag=se&amp;keywords=%E2%80%9CThreats%3A+What+Every+Engineer+Should+Learn+From+Star+Wars%E2%80%9D+-+Adam+Shostack&amp;qid=1725945870&amp;s=books&amp;sprefix=threats+what+every+engineer+should+learn+from+star+wars+-+adam+shostack%2Cstripbooks%2C442&amp;sr=1-1">“Threats: What Every Engineer Should Learn From Star Wars” - Adam Shostack</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Mitrokhin-Archive-KGB-Europe-West/dp/0141989483/ref=sr_1_1?crid=NOWPYRX5XJ1F&amp;dib=eyJ2IjoiMSJ9.jswKTk0DMjqvHfjwgwbQHTlNlqlWdzByerX02hVuB8TCNGCZBacw--0FLAQzu4WUQHn8RHKs96vMk2_WNv9ug_qW_nJ3SG99vgYueNEUz1I.Ald9ZEw3O5nC3SyKOukVpFfx0HV2_KKS0HO5FtbZ1nQ&amp;dib_tag=se&amp;keywords=%E2%80%9CThe+Mitrokhin+Archive%E2%80%9D+Christopher+Andrew+%26+Vasili+Mitrokhin&amp;qid=1725945890&amp;s=books&amp;sprefix=the+mitrokhin+archive+christopher+andrew+%26+vasili+mitrokhin%2Cstripbooks%2C231&amp;sr=1-1">“The Mitrokhin Archive” Christopher Andrew &amp; Vasili Mitrokhin</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Road-Cormac-McCarthy/dp/0307387895/ref=sr_1_1?crid=2M122N9FQU824&amp;dib=eyJ2IjoiMSJ9.QeBwwxAerUi8TH8VHlQflPCS4ywLB7BlcaQzv6UAjtQSfXNetcq3-kAAZmCDc7kt6Yt53PhTY-b1Wj8aLAUh3eLs-pEx6Ugk0o1vEYfyTtMNg1N-c_UOwb__8Ts9TYaJg-gC-rhTvB6E3gXp8Yg8rArZvEgv0muA9yS0muGVDMo0Vzenf5svdjzCs89E9dPfq9xGg2GMVEUxY47SvYfZLBnYEzJkxYbdl03OWOr70C4.3rbRJ0NmGzqNPqFC39tXD2UXYDYetvp0E8j0Xaz5cN0&amp;dib_tag=se&amp;keywords=%E2%80%9CThe+Road%E2%80%9D+-+Cormac+McCarthy&amp;qid=1725945919&amp;s=books&amp;sprefix=the+road+-+cormac+mccarthy%2Cstripbooks%2C230&amp;sr=1-1">“The Road” - Cormac McCarthy</a></p><p>The song at the end of the podcast:</p><p>Decrypted Savant - Mercator Misconceptions</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we unpack the hacker mindset with Ken Westin, Senior Solutions Engineer at LimaCharlie.</p><p>Ken is a seasoned thought leader in cybersecurity who has spent years analyzing and understanding the intricacies of cyber threats and the methods behind them. Ken has a unique ability to identify emerging trends in the industry and for figuring out how businesses can protect themselves before they fall victim to attacks. </p><p>Previous to his current role, Ken was the Field CISO at Panther, where he developed workshops and delivered them around the world. His career also includes significant contributions at Cybereason, Elastic, and Splunk, where he drove security growth, developed innovative tools, and shaped industry conversations on cybersecurity. Ken has been a key spokesperson in the industry, frequently quoted in the media and featured at major conferences like Black Hat and DEF CON.</p><p>Ken recently joined the team at LimaCharlie as a Senior Solutions Engineer, with the intent to use his deep expertise to help organizations build robust security strategies.</p><p>Ken's reading list:</p><p><a rel="noreferrer noopener" href="https://www.amazon.com/DAEMON-Daemon-Daniel-Suarez/dp/0451228731">“Daemon” - Daniel Suarez</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0380788624/ref=sr_1_1?crid=3PIZ7J2M0E7K7&amp;dib=eyJ2IjoiMSJ9.zefEBDXIkLzS7eoUzBdcYwpVzrgRBDQ09Xrotd71__m2_N5WzsYgIefeCwpM2uuJcvv86vTZMYiFkzXIU9qGUfLD3iFEPbLdOl06n6ok6l-EIC2sL2Feptq2taNOSwvQ8uEgCGeAtl7Q8-4QVjghm6QywqB5bSeRPbPzTHYTx0gNxEpAmJUnUUf863DPvhhKlnTICgeoc2cw3XF16SMuzgu4YCRIfEzwoDs_wkwTxzE.yOMbIOC31lbUdB9crRf_uW_LvxnYYHIQNaRO4LzC8KA&amp;dib_tag=se&amp;keywords=%E2%80%9CCryptonomicon%E2%80%9D+-+Neal+Stephenson&amp;qid=1725945818&amp;s=books&amp;sprefix=cryptonomicon+-+neal+stephenson%2Cstripbooks%2C237&amp;sr=1-1">“Cryptonomicon” -  Neal Stephenson</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Myth-Normal-Illness-Healing-Culture/dp/0593083881/ref=sr_1_1?crid=37XI29QRJD56Z&amp;dib=eyJ2IjoiMSJ9.SNhv6R0yBm7q5giqshgLX0Q6UJxsY5TzMmnUGCioBxo.KiMXiXUEisJzdD9YxV5DDllXoJKEWiArdm44WlSfFkI&amp;dib_tag=se&amp;keywords=%E2%80%9CCryptonomicon%E2%80%9D+-+Nea%E2%80%9CThe+Myth+of+Normal%E2%80%9D+-+Gabor+Mat%C3%A9l+Stephenson&amp;qid=1725945848&amp;s=books&amp;sprefix=cryptonomicon+-+nea+the+myth+of+normal+-+gabor+mat%C3%A9l+stephenson%2Cstripbooks%2C263&amp;sr=1-1">“The Myth of Normal” - Gabor Maté</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Threats-Every-Engineer-Should-Learn/dp/1119895162/ref=sr_1_1?crid=3G8QF848TZ7YC&amp;dib=eyJ2IjoiMSJ9.aqeaHHF3mhnlBBzA1ZO7tw.W5y-w7LsR-izpBH1XDavEisjHkXvLvNklfCGpPwVtNs&amp;dib_tag=se&amp;keywords=%E2%80%9CThreats%3A+What+Every+Engineer+Should+Learn+From+Star+Wars%E2%80%9D+-+Adam+Shostack&amp;qid=1725945870&amp;s=books&amp;sprefix=threats+what+every+engineer+should+learn+from+star+wars+-+adam+shostack%2Cstripbooks%2C442&amp;sr=1-1">“Threats: What Every Engineer Should Learn From Star Wars” - Adam Shostack</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Mitrokhin-Archive-KGB-Europe-West/dp/0141989483/ref=sr_1_1?crid=NOWPYRX5XJ1F&amp;dib=eyJ2IjoiMSJ9.jswKTk0DMjqvHfjwgwbQHTlNlqlWdzByerX02hVuB8TCNGCZBacw--0FLAQzu4WUQHn8RHKs96vMk2_WNv9ug_qW_nJ3SG99vgYueNEUz1I.Ald9ZEw3O5nC3SyKOukVpFfx0HV2_KKS0HO5FtbZ1nQ&amp;dib_tag=se&amp;keywords=%E2%80%9CThe+Mitrokhin+Archive%E2%80%9D+Christopher+Andrew+%26+Vasili+Mitrokhin&amp;qid=1725945890&amp;s=books&amp;sprefix=the+mitrokhin+archive+christopher+andrew+%26+vasili+mitrokhin%2Cstripbooks%2C231&amp;sr=1-1">“The Mitrokhin Archive” Christopher Andrew &amp; Vasili Mitrokhin</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Road-Cormac-McCarthy/dp/0307387895/ref=sr_1_1?crid=2M122N9FQU824&amp;dib=eyJ2IjoiMSJ9.QeBwwxAerUi8TH8VHlQflPCS4ywLB7BlcaQzv6UAjtQSfXNetcq3-kAAZmCDc7kt6Yt53PhTY-b1Wj8aLAUh3eLs-pEx6Ugk0o1vEYfyTtMNg1N-c_UOwb__8Ts9TYaJg-gC-rhTvB6E3gXp8Yg8rArZvEgv0muA9yS0muGVDMo0Vzenf5svdjzCs89E9dPfq9xGg2GMVEUxY47SvYfZLBnYEzJkxYbdl03OWOr70C4.3rbRJ0NmGzqNPqFC39tXD2UXYDYetvp0E8j0Xaz5cN0&amp;dib_tag=se&amp;keywords=%E2%80%9CThe+Road%E2%80%9D+-+Cormac+McCarthy&amp;qid=1725945919&amp;s=books&amp;sprefix=the+road+-+cormac+mccarthy%2Cstripbooks%2C230&amp;sr=1-1">“The Road” - Cormac McCarthy</a></p><p>The song at the end of the podcast:</p><p>Decrypted Savant - Mercator Misconceptions</p>]]>
      </content:encoded>
      <pubDate>Tue, 10 Sep 2024 07:30:12 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/de10edc6/1c928afe.mp3" length="50575603" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2108</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we unpack the hacker mindset with Ken Westin, Senior Solutions Engineer at LimaCharlie.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we unpack the hacker mindset with Ken Westin, Senior Solutions Engineer at LimaCharlie.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#152 - Intel Chat: sedexp, Volt Typhoon, Citrine Sleet, Clearview AI &amp; RansomHub?</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>152</itunes:episode>
      <podcast:episode>152</podcast:episode>
      <itunes:title>#152 - Intel Chat: sedexp, Volt Typhoon, Citrine Sleet, Clearview AI &amp; RansomHub?</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">826f47d7-fe64-4ea8-9974-86b585bfe30b</guid>
      <link>https://share.transistor.fm/s/873313eb</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A stealthy Linux malware named 'sedexp' has been evading detection since 2022 by using a persistence technique not yet included in the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/stealthy-sedexp-linux-malware-evaded-detection-for-two-years/">MITRE ATT&amp;CK framework</a>.</li><li>The Black Lotus Labs team at Lumen Technologies have uncovered a group of hackers linked to the Chinese government which have exploited a previously unknown software vulnerability to <a rel="noreferrer noopener" href="https://blog.lumen.com/taking-the-crossroads-the-versa-director-zero-day-exploitation/">target U.S. internet service providers</a>.</li><li>Earlier in August, a North Korean hacking group exploited a previously unknown bug in Chrome-based browsers, aiming to steal cryptocurrency, which was <a rel="noreferrer noopener" href="https://techcrunch.com/2024/08/30/north-korean-hackers-exploited-chrome-zero-day-to-steal-crypto/">reported by Microsoft in a recent update</a>.</li><li>The Dutch Data Protection Authority, or Dutch DPA, has hit Clearview AI with a €30.5 million fine—about $33.7 million—for illegally collecting data using facial recognition, <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/legal/clearview-ai-fined-305-million-by-dutch-dpa-for-unlawful-data-collection/">including photos of Dutch citizens</a>.</li><li>Energy giant Halliburton has confirmed that its systems were hacked, and intruders were able to steal information following a <a rel="noreferrer noopener" href="https://techcrunch.com/2024/09/03/halliburton-confirms-data-was-stolen-in-ongoing-cyberattack/">cyberattack last week</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A stealthy Linux malware named 'sedexp' has been evading detection since 2022 by using a persistence technique not yet included in the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/stealthy-sedexp-linux-malware-evaded-detection-for-two-years/">MITRE ATT&amp;CK framework</a>.</li><li>The Black Lotus Labs team at Lumen Technologies have uncovered a group of hackers linked to the Chinese government which have exploited a previously unknown software vulnerability to <a rel="noreferrer noopener" href="https://blog.lumen.com/taking-the-crossroads-the-versa-director-zero-day-exploitation/">target U.S. internet service providers</a>.</li><li>Earlier in August, a North Korean hacking group exploited a previously unknown bug in Chrome-based browsers, aiming to steal cryptocurrency, which was <a rel="noreferrer noopener" href="https://techcrunch.com/2024/08/30/north-korean-hackers-exploited-chrome-zero-day-to-steal-crypto/">reported by Microsoft in a recent update</a>.</li><li>The Dutch Data Protection Authority, or Dutch DPA, has hit Clearview AI with a €30.5 million fine—about $33.7 million—for illegally collecting data using facial recognition, <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/legal/clearview-ai-fined-305-million-by-dutch-dpa-for-unlawful-data-collection/">including photos of Dutch citizens</a>.</li><li>Energy giant Halliburton has confirmed that its systems were hacked, and intruders were able to steal information following a <a rel="noreferrer noopener" href="https://techcrunch.com/2024/09/03/halliburton-confirms-data-was-stolen-in-ongoing-cyberattack/">cyberattack last week</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 05 Sep 2024 13:35:23 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/873313eb/4af4b3da.mp3" length="27372521" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/dysCc0JhTNpUKccCrxla6DR5ZUNP8j8gLWWd8x6WT-U/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZTIy/ZGYxYjgzNmU3NzY4/MzhhYWE3ODM1ODY5/ZDk0MC5wbmc.jpg"/>
      <itunes:duration>2265</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#151 - Exploring AI as it pertains to cybersecurity with George Gerchow, Head of Trust at MongoDB</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>151</itunes:episode>
      <podcast:episode>151</podcast:episode>
      <itunes:title>#151 - Exploring AI as it pertains to cybersecurity with George Gerchow, Head of Trust at MongoDB</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fa9d7d67-e94f-467f-bbc4-3f6882a7d6fc</guid>
      <link>https://share.transistor.fm/s/1209491f</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with George Gerchow, Head of Trust at MongoDB, about the current narrative surrounding AI in cybersecurity. George challenges the dominant focus on AI as a threat and instead highlights its potential as a powerful ally in defending against sophisticated cyberattacks. We explore how AI-driven defense strategies are reshaping the landscape of proactive threat detection and automated response mechanisms, offering a fresh perspective on balancing security innovation with risk management.</p><p>George is an experienced executive who has played a key role in guiding highly regulated organizations as they establish and develop agile security, privacy, and compliance programs in fast-paced environments. George’s strong focus on relationships and customer engagement shines through in every interaction, both within his teams and with external clients. He is adept at implementing risk-based security programs that align with overall business objectives, effectively balancing risk reduction with cost management. During his six years at Sumo Logic, George was integral to the team's success in taking the company public and achieving FedRAMP Authorization. Currently, he serves as the Head of Trust at MongoDB, where he continues to drive excellence in security and compliance.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with George Gerchow, Head of Trust at MongoDB, about the current narrative surrounding AI in cybersecurity. George challenges the dominant focus on AI as a threat and instead highlights its potential as a powerful ally in defending against sophisticated cyberattacks. We explore how AI-driven defense strategies are reshaping the landscape of proactive threat detection and automated response mechanisms, offering a fresh perspective on balancing security innovation with risk management.</p><p>George is an experienced executive who has played a key role in guiding highly regulated organizations as they establish and develop agile security, privacy, and compliance programs in fast-paced environments. George’s strong focus on relationships and customer engagement shines through in every interaction, both within his teams and with external clients. He is adept at implementing risk-based security programs that align with overall business objectives, effectively balancing risk reduction with cost management. During his six years at Sumo Logic, George was integral to the team's success in taking the company public and achieving FedRAMP Authorization. Currently, he serves as the Head of Trust at MongoDB, where he continues to drive excellence in security and compliance.</p>]]>
      </content:encoded>
      <pubDate>Wed, 28 Aug 2024 17:09:05 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1209491f/ffcddd7e.mp3" length="30596899" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/smWTzXFzhdwOo8JxuigxBOsHJQhp98aqHk3XsB58VtE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNmFm/NzcwM2YwYTFhZTIx/YjljMjY2Y2I2NWYw/ZjQ3MS5wbmc.jpg"/>
      <itunes:duration>2534</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with George Gerchow, Head of Trust at MongoDB, about the current narrative surrounding AI in cybersecurity. George challenges the dominant focus on AI as a threat and instead highlights its potential as a powerful ally in defending against sophisticated cyberattacks. We explore how AI-driven defense strategies are reshaping the landscape of proactive threat detection and automated response mechanisms, offering a fresh perspective on balancing security innovation with risk management.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with George Gerchow, Head of Trust at MongoDB, about the current narrative surrounding AI in cybersecurity. George challenges the dominant focus on AI as a threat and instead highlights its </itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#150 - Intel Chat: Azure MFA, 2.9b records leaked, CVE 9.8 &amp; ransomware record</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>148</itunes:episode>
      <podcast:episode>148</podcast:episode>
      <itunes:title>#150 - Intel Chat: Azure MFA, 2.9b records leaked, CVE 9.8 &amp; ransomware record</itunes:title>
      <itunes:episodeType>bonus</itunes:episodeType>
      <guid isPermaLink="false">ff8fcbf7-4aef-4218-8915-81c2325cd0b0</guid>
      <link>https://share.transistor.fm/s/fede0258</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Starting in October, all Microsoft Azure customers will be required to have multi-factor authentication (MFA) enabled on their accounts.</li><li>Documents from a lawsuit revealed that over 2.9 billion records are vulnerable after a massive hack of the Florida-based National Public Data network.</li><li>Microsoft recently advised of a critical TCP/IP Remote Code Execution Vulnerability dubbed CVE 2024-38063, which is a critical unauthenticated Remote Code Execution - or RCE - vulnerability within the Windows TCP/IP stack. </li><li>Ransomware victims have paid $459,800,000 to cybercriminals in the first half of 2024, setting the stage for a new record this year if ransom payments continue at this level.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Starting in October, all Microsoft Azure customers will be required to have multi-factor authentication (MFA) enabled on their accounts.</li><li>Documents from a lawsuit revealed that over 2.9 billion records are vulnerable after a massive hack of the Florida-based National Public Data network.</li><li>Microsoft recently advised of a critical TCP/IP Remote Code Execution Vulnerability dubbed CVE 2024-38063, which is a critical unauthenticated Remote Code Execution - or RCE - vulnerability within the Windows TCP/IP stack. </li><li>Ransomware victims have paid $459,800,000 to cybercriminals in the first half of 2024, setting the stage for a new record this year if ransom payments continue at this level.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 23 Aug 2024 16:47:52 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fede0258/10f11848.mp3" length="54611896" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2276</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#149 - Product security with Jacob Salassi, Co-Founder at stealth startup</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>149</itunes:episode>
      <podcast:episode>149</podcast:episode>
      <itunes:title>#149 - Product security with Jacob Salassi, Co-Founder at stealth startup</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1150f16b-de3c-479a-bd22-4f415ea54438</guid>
      <link>https://share.transistor.fm/s/1e450602</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Jacob Salassi, Co-Founder at stealth startup, about product security.</p><p>Jacob brings over 10 years of experience in software engineering and cybersecurity to the table. Until four months ago, Jacob was a Security Architect at Snowflake, where he ensured every developer was wildly successful in owning security. Since then, he’s been diving into something new and exciting, working on a stealth startup. Before Snowflake, Jacob was busy bootstrapping application security programs in healthcare and engineering secure distributed systems for a hybrid-cloud security platform. He’s passionate about creating a development security experience that not only measurably reduces risk but also earns the love of engineers. In his own words, Jacob solves problems.</p><p>Books mentioned in the podcast:</p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Engineering-Trustworthy-Systems-Cybersecurity-Design/dp/1260118177">Engineering Trustworthy Systems: Get Cybersecurity Design Right the First Time</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.ca/Security-Engineering-Building-Dependable-Distributed-dp-1119642787/dp/1119642787/ref=dp_ob_title_bk">Security Engineering: A Guide to Building Dependable Distributed Systems</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.ca/Measuring-Managing-Information-Risk-Approach/dp/0124202314">Measuring and Managing Information Risk: A FAIR Approach</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Jacob Salassi, Co-Founder at stealth startup, about product security.</p><p>Jacob brings over 10 years of experience in software engineering and cybersecurity to the table. Until four months ago, Jacob was a Security Architect at Snowflake, where he ensured every developer was wildly successful in owning security. Since then, he’s been diving into something new and exciting, working on a stealth startup. Before Snowflake, Jacob was busy bootstrapping application security programs in healthcare and engineering secure distributed systems for a hybrid-cloud security platform. He’s passionate about creating a development security experience that not only measurably reduces risk but also earns the love of engineers. In his own words, Jacob solves problems.</p><p>Books mentioned in the podcast:</p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Engineering-Trustworthy-Systems-Cybersecurity-Design/dp/1260118177">Engineering Trustworthy Systems: Get Cybersecurity Design Right the First Time</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.ca/Security-Engineering-Building-Dependable-Distributed-dp-1119642787/dp/1119642787/ref=dp_ob_title_bk">Security Engineering: A Guide to Building Dependable Distributed Systems</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.ca/Measuring-Managing-Information-Risk-Approach/dp/0124202314">Measuring and Managing Information Risk: A FAIR Approach</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 20 Aug 2024 15:16:40 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1e450602/caf1e39b.mp3" length="69519086" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2897</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Jacob Salassi, Co-Founder at stealth startup, about product security.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Jacob Salassi, Co-Founder at stealth startup, about product security.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#148 - Intel Chat: Hacker Summer Camp, N. Korea, Dispossessor, Proofpoint &amp; Sinkclose</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>148</itunes:episode>
      <podcast:episode>148</podcast:episode>
      <itunes:title>#148 - Intel Chat: Hacker Summer Camp, N. Korea, Dispossessor, Proofpoint &amp; Sinkclose</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3f847b42-0414-47bb-ae6f-16ef05e701d7</guid>
      <link>https://share.transistor.fm/s/2b326f38</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A heated dispute at DEF CON over the custom electronic badges this year turned physical, leading to an altercation between <a rel="noreferrer noopener" href="https://www.theregister.com/2024/08/13/defcon_badge_disagreement_gets_physical/">two attendees</a>.</li><li>The U.S. Department of Justice has charged Matthew Isaac Knoot, a 38-year-old Nashville resident, with multiple crimes for aiding North Korean IT workers in securing jobs with <a rel="noreferrer noopener" href="https://thehackernews.com/2024/08/doj-charges-nashville-man-for-helping.html">U.S. and U.K. companies</a>.</li><li>The FBI has dismantled the infrastructure of the Dispossessor ransomware group, also known as Radar, which had rapidly gained prominence since its <a rel="noreferrer noopener" href="https://thehackernews.com/2024/08/fbi-shuts-down-dispossessor-ransomware.html">inception in August 2023</a>.</li><li>A critical flaw in Proofpoint’s email filtering service was recently discovered, allowing cybercriminals to impersonate major brands and send phishing emails that bypassed <a rel="noreferrer noopener" href="https://www.pcmag.com/news/proofpoint-bug-allowed-scammers-to-pose-as-major-brands-send-phishing-emails">Proofpoint’s security</a>.</li><li>A newly discovered security flaw affects AMD processors dating back to 2006. The vulnerability, which impacts CPUs from the Athlon 64 to the Ryzen 7000 series, allows attackers to exploit speculative execution to <a rel="noreferrer noopener" href="https://www.fudzilla.com/news/59499-amd-processors-from-2006-affected-by-security-flaw">access sensitive data</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A heated dispute at DEF CON over the custom electronic badges this year turned physical, leading to an altercation between <a rel="noreferrer noopener" href="https://www.theregister.com/2024/08/13/defcon_badge_disagreement_gets_physical/">two attendees</a>.</li><li>The U.S. Department of Justice has charged Matthew Isaac Knoot, a 38-year-old Nashville resident, with multiple crimes for aiding North Korean IT workers in securing jobs with <a rel="noreferrer noopener" href="https://thehackernews.com/2024/08/doj-charges-nashville-man-for-helping.html">U.S. and U.K. companies</a>.</li><li>The FBI has dismantled the infrastructure of the Dispossessor ransomware group, also known as Radar, which had rapidly gained prominence since its <a rel="noreferrer noopener" href="https://thehackernews.com/2024/08/fbi-shuts-down-dispossessor-ransomware.html">inception in August 2023</a>.</li><li>A critical flaw in Proofpoint’s email filtering service was recently discovered, allowing cybercriminals to impersonate major brands and send phishing emails that bypassed <a rel="noreferrer noopener" href="https://www.pcmag.com/news/proofpoint-bug-allowed-scammers-to-pose-as-major-brands-send-phishing-emails">Proofpoint’s security</a>.</li><li>A newly discovered security flaw affects AMD processors dating back to 2006. The vulnerability, which impacts CPUs from the Athlon 64 to the Ryzen 7000 series, allows attackers to exploit speculative execution to <a rel="noreferrer noopener" href="https://www.fudzilla.com/news/59499-amd-processors-from-2006-affected-by-security-flaw">access sensitive data</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 14 Aug 2024 13:42:21 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2b326f38/fd744843.mp3" length="20979321" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ry-RLuOsjJh3aulczpx53c_V5wjdUcfjEeHS5b6E8oQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xZmZk/NjgxNTE1ZjhhMTk3/ZWZkZjRhMWUzOTA2/MjUxNi5wbmc.jpg"/>
      <itunes:duration>1732</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#147 - Cybersecurity product development with Vijay Pitchuman, Director of Product for Identity Management at Okta</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>147</itunes:episode>
      <podcast:episode>147</podcast:episode>
      <itunes:title>#147 - Cybersecurity product development with Vijay Pitchuman, Director of Product for Identity Management at Okta</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">064d5773-6c63-461a-ba1e-57e30e5f543b</guid>
      <link>https://share.transistor.fm/s/30d772e8</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about cybersecurity product development with Vijay Pitchuman, Director of Product for Identity Management at Okta.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk about cybersecurity product development with Vijay Pitchuman, Director of Product for Identity Management at Okta.</p>]]>
      </content:encoded>
      <pubDate>Wed, 07 Aug 2024 15:27:49 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/30d772e8/d94d705c.mp3" length="40968745" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1707</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk about cybersecurity product development with Vijay Pitchuman, Director of Product for Identity Management at Okta.

 Vijay is an accomplished product management leader. Vijay has a wealth of experience across a variety of roles, having been instrumental in driving technological innovation at various organizations. He is passionate about building high-performing teams and fostering a culture of continuous improvement and innovation. With a deep understanding of both the technical and business aspects of technology development, Vijay brings a unique perspective to the intersection of technology and business strategy.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk about cybersecurity product development with Vijay Pitchuman, Director of Product for Identity Management at Okta.

 Vijay is an accomplished product management leader. Vijay has a wealth of e</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#146 - Intel Chat: GhostEmperor, .top, PlugX &amp; Microsoft</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>146</itunes:episode>
      <podcast:episode>146</podcast:episode>
      <itunes:title>#146 - Intel Chat: GhostEmperor, .top, PlugX &amp; Microsoft</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">92752f88-fae7-4cce-aa27-1095b772712b</guid>
      <link>https://share.transistor.fm/s/1df5d73e</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>The Chinese hacker group GhostEmperor has re-emerged after a two-year hiatus, displaying new advanced capabilities and <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/notorious-chinese-hacker-gang-re-emerges-after-two-years">sophisticated evasion techniques</a>. </li><li>The Chinese company, Jiangsu Bangning Science &amp; Technology Co., in charge of handing out domain names ending in “.top” has been given until mid-August 2024 to show that it has put in place systems for managing phishing reports and suspending abusive domains, or else <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/07/phish-friendly-domain-registry-top-put-on-notice/">forfeit its license to sell domains</a>. </li><li>Following a report by the cybersecurity firm Sekoia.io, the Paris Public Prosecutor’s Office launched a preliminary investigation into a botnet involving millions of global victims, including <a rel="noreferrer noopener" href="https://securityaffairs.com/166213/cyber-crime/plugx-malware-disinfection-operation.html">thousands of machines in France</a>. </li><li>Microsoft has initiated significant changes to its Windows operating system following a critical incident involving <a rel="noreferrer noopener" href="https://www.theverge.com/2024/7/26/24206719/microsoft-windows-changes-crowdstrike-kernel-driver">CrowdStrike's kernel driver</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>The Chinese hacker group GhostEmperor has re-emerged after a two-year hiatus, displaying new advanced capabilities and <a rel="noreferrer noopener" href="https://www.darkreading.com/threat-intelligence/notorious-chinese-hacker-gang-re-emerges-after-two-years">sophisticated evasion techniques</a>. </li><li>The Chinese company, Jiangsu Bangning Science &amp; Technology Co., in charge of handing out domain names ending in “.top” has been given until mid-August 2024 to show that it has put in place systems for managing phishing reports and suspending abusive domains, or else <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/07/phish-friendly-domain-registry-top-put-on-notice/">forfeit its license to sell domains</a>. </li><li>Following a report by the cybersecurity firm Sekoia.io, the Paris Public Prosecutor’s Office launched a preliminary investigation into a botnet involving millions of global victims, including <a rel="noreferrer noopener" href="https://securityaffairs.com/166213/cyber-crime/plugx-malware-disinfection-operation.html">thousands of machines in France</a>. </li><li>Microsoft has initiated significant changes to its Windows operating system following a critical incident involving <a rel="noreferrer noopener" href="https://www.theverge.com/2024/7/26/24206719/microsoft-windows-changes-crowdstrike-kernel-driver">CrowdStrike's kernel driver</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 31 Jul 2024 11:47:35 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1df5d73e/c0d4b0c6.mp3" length="22982959" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Pb1uqTHPPlhi1E7nZiRxsjb0-N_sF4htOlsWbYXcy2I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjUw/NzEyODZjMGZkMTQ2/NDBkMDk1Y2Q0YzNm/MTVjMS5wbmc.jpg"/>
      <itunes:duration>1899</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#145 - Exploring threat intelligence with Jamie Williams, Threat Intelligence Researcher at Unit 42</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>145</itunes:episode>
      <podcast:episode>145</podcast:episode>
      <itunes:title>#145 - Exploring threat intelligence with Jamie Williams, Threat Intelligence Researcher at Unit 42</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4e8f84d7-d1b1-4528-a623-89182823fa7a</guid>
      <link>https://share.transistor.fm/s/baff06a1</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast, we explore threat intelligence with Jamie Williams, Threat Intelligence Researcher at Palo Alto Networks' Unit 42.</p><p>Jamie is a seasoned professional in the field of cybersecurity. Before joining Unit 42, he made significant contributions at the MITRE Corporation as a Senior Principal Cyber Operations Engineer. During his tenure at MITRE, Jamie led the development of MITRE ATT&amp;CK® for Enterprise, focusing on adversary emulation and behavior-based detections.</p><p>In addition to his full-time role, Jamie is also a member of the IANS Faculty, where he shares his extensive knowledge and experience with the cybersecurity community. With a rich background that includes time at the National Security Agency, Jamie brings a wealth of expertise to the podcast.</p><p>Katie Nickels blog can be found <a rel="noreferrer noopener" href="https://medium.com/@knickels_96700">here</a>.</p><p>Google Mandiant's article on requirement-driven intelligence can be found <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/requirements-driven-approach-cti">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast, we explore threat intelligence with Jamie Williams, Threat Intelligence Researcher at Palo Alto Networks' Unit 42.</p><p>Jamie is a seasoned professional in the field of cybersecurity. Before joining Unit 42, he made significant contributions at the MITRE Corporation as a Senior Principal Cyber Operations Engineer. During his tenure at MITRE, Jamie led the development of MITRE ATT&amp;CK® for Enterprise, focusing on adversary emulation and behavior-based detections.</p><p>In addition to his full-time role, Jamie is also a member of the IANS Faculty, where he shares his extensive knowledge and experience with the cybersecurity community. With a rich background that includes time at the National Security Agency, Jamie brings a wealth of expertise to the podcast.</p><p>Katie Nickels blog can be found <a rel="noreferrer noopener" href="https://medium.com/@knickels_96700">here</a>.</p><p>Google Mandiant's article on requirement-driven intelligence can be found <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/requirements-driven-approach-cti">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 30 Jul 2024 07:02:42 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/baff06a1/41a633fb.mp3" length="31009115" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/8FM9FUsoRz2YqpAeROab41d3R4X3_R3JOcVf_5dpuRE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jY2E2/NDk0MmQwOTM0NDZm/MzZkZGQ4ZTFiMmMw/NTlhMi5wbmc.jpg"/>
      <itunes:duration>2568</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders podcast, we explore threat intelligence with Jamie Williams, Threat Intelligence Researcher at Palo Alto Networks' Unit 42.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders podcast, we explore threat intelligence with Jamie Williams, Threat Intelligence Researcher at Palo Alto Networks' Unit 42.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#144 - How to think about IR with Lee Sult, Chief Investigator at Binalyze</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>144</itunes:episode>
      <podcast:episode>144</podcast:episode>
      <itunes:title>#144 - How to think about IR with Lee Sult, Chief Investigator at Binalyze</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bda8b0dd-c421-46ab-97c4-2a10f58c2447</guid>
      <link>https://share.transistor.fm/s/0e096615</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we sit down with Lee Sult, Chief Investigator at Binalyze, and talk about incident response (IR).</p><p>Lee is a seasoned cybersecurity expert and investigator with extensive experience in digital forensics and incident response. He is the Chief Investigator at Binalyze and has a strong track record at prestigious organizations like Trustwave-SpiderLabs and Palantir. Lee has supported the US Secret Service and managed complex cybersecurity incidents for Fortune 50 companies.</p><p>As the co-founder and former CTO of Horangi Cyber Security, Singapore's first cybersecurity startup, Lee's leadership and collaboration skills have significantly impacted the region's cybersecurity landscape. Passionate about mentoring, Lee actively contributes to cybersecurity communities and supports up-and-coming entrepreneurs.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we sit down with Lee Sult, Chief Investigator at Binalyze, and talk about incident response (IR).</p><p>Lee is a seasoned cybersecurity expert and investigator with extensive experience in digital forensics and incident response. He is the Chief Investigator at Binalyze and has a strong track record at prestigious organizations like Trustwave-SpiderLabs and Palantir. Lee has supported the US Secret Service and managed complex cybersecurity incidents for Fortune 50 companies.</p><p>As the co-founder and former CTO of Horangi Cyber Security, Singapore's first cybersecurity startup, Lee's leadership and collaboration skills have significantly impacted the region's cybersecurity landscape. Passionate about mentoring, Lee actively contributes to cybersecurity communities and supports up-and-coming entrepreneurs.</p>]]>
      </content:encoded>
      <pubDate>Fri, 26 Jul 2024 14:53:11 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0e096615/046cda9a.mp3" length="23782969" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/m_RJB9UID2LufjC2Zgmlf0TgLonINMBPdzVtu8kctY8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NzEz/OTIwYzJkN2ExYzg5/YmIzZTIzYTdiYTM4/YmU5OS5wbmc.jpg"/>
      <itunes:duration>1966</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we sit down with Lee Sult, Chief Investigator at Binalyze, and talk about incident response (IR).</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we sit down with Lee Sult, Chief Investigator at Binalyze, and talk about incident response (IR).</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#143 - Intel Chat: Blast-RADIUS, Chrome, AT&amp;T, Kaspersky &amp; Crowdstrike</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>143</itunes:episode>
      <podcast:episode>143</podcast:episode>
      <itunes:title>#143 - Intel Chat: Blast-RADIUS, Chrome, AT&amp;T, Kaspersky &amp; Crowdstrike</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b85cfde4-8070-4373-bca4-00b668ab36f2</guid>
      <link>https://share.transistor.fm/s/e78739ee</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Blast-RADIUS is a vulnerability in the RADIUS protocol that allows a man-in-the-middle attacker to forge valid protocol accept messages in response to failed <a rel="noreferrer noopener" href="https://www.blastradius.fail/">authentication requests</a>.</li><li>The blog post on <a rel="noreferrer noopener" href="https://syntax-err0r.github.io/Silently_Install_Chrome_Extension.html">Syntax-Err0r</a> details a technique for silently installing a Chrome extension to maintain persistence, bypassing typical detection methods.</li><li>American telecom service provider AT&amp;T has confirmed that threat actors managed to access data belonging to "nearly all" of its wireless customers as well as customers of mobile virtual network operators using <a rel="noreferrer noopener" href="https://thehackernews.com/2024/07/at-confirms-data-breach-affecting.html">AT&amp;T's wireless network</a>.</li><li>The U.S. Department of Commerce added Kaspersky to its Entity List, barring U.S. businesses from engaging with the company due to national security concerns related to the Russian government's influence over <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/kaspersky-is-shutting-down-its-business-in-the-united-states/">Kaspersky's operations</a>.</li><li>On July 19th Crowdstrike distributed a faulty update to its Falcon sensors that caused widespread problems with computers running Microsoft Windows. As a result, roughly 8.5 million systems crashed, bringing up the feared blue screen of death, in what is being called the <a rel="noreferrer noopener" href="https://arstechnica.com/information-technology/2024/07/microsoft-says-8-5m-systems-hit-by-crowdstrike-bsod-releases-usb-recovery-tool/">largest IT outage in history</a> (<a rel="noreferrer noopener" href="https://www.thestack.technology/crowdstrike-bug-maxes-out-100-of-cpu-requires-windows-reboots/">+outage 1-month ago</a>, <a rel="noreferrer noopener" href="https://www.neowin.net/news/crowdstrike-broke-debian-and-rocky-linux-months-ago-but-no-one-noticed/">+outage 3-months ago</a>).</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Blast-RADIUS is a vulnerability in the RADIUS protocol that allows a man-in-the-middle attacker to forge valid protocol accept messages in response to failed <a rel="noreferrer noopener" href="https://www.blastradius.fail/">authentication requests</a>.</li><li>The blog post on <a rel="noreferrer noopener" href="https://syntax-err0r.github.io/Silently_Install_Chrome_Extension.html">Syntax-Err0r</a> details a technique for silently installing a Chrome extension to maintain persistence, bypassing typical detection methods.</li><li>American telecom service provider AT&amp;T has confirmed that threat actors managed to access data belonging to "nearly all" of its wireless customers as well as customers of mobile virtual network operators using <a rel="noreferrer noopener" href="https://thehackernews.com/2024/07/at-confirms-data-breach-affecting.html">AT&amp;T's wireless network</a>.</li><li>The U.S. Department of Commerce added Kaspersky to its Entity List, barring U.S. businesses from engaging with the company due to national security concerns related to the Russian government's influence over <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/kaspersky-is-shutting-down-its-business-in-the-united-states/">Kaspersky's operations</a>.</li><li>On July 19th Crowdstrike distributed a faulty update to its Falcon sensors that caused widespread problems with computers running Microsoft Windows. As a result, roughly 8.5 million systems crashed, bringing up the feared blue screen of death, in what is being called the <a rel="noreferrer noopener" href="https://arstechnica.com/information-technology/2024/07/microsoft-says-8-5m-systems-hit-by-crowdstrike-bsod-releases-usb-recovery-tool/">largest IT outage in history</a> (<a rel="noreferrer noopener" href="https://www.thestack.technology/crowdstrike-bug-maxes-out-100-of-cpu-requires-windows-reboots/">+outage 1-month ago</a>, <a rel="noreferrer noopener" href="https://www.neowin.net/news/crowdstrike-broke-debian-and-rocky-linux-months-ago-but-no-one-noticed/">+outage 3-months ago</a>).</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 24 Jul 2024 07:30:11 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e78739ee/2e8e5f06.mp3" length="28323878" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/_-suSg7e6-GllhPeIodbcd-wjb-OxVprWkib_vfk-UE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yYjIw/YjU4MmFlZDBiZGEx/YmY5YWY3ZDBmNWQx/ZWYxMi5wbmc.jpg"/>
      <itunes:duration>2344</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#142 - Threat detection &amp; research with Zack Allen, Security Detection &amp; Research Leader at Datadog</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>142</itunes:episode>
      <podcast:episode>142</podcast:episode>
      <itunes:title>#142 - Threat detection &amp; research with Zack Allen, Security Detection &amp; Research Leader at Datadog</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">00961632-9af7-40b0-bd45-2a26eb8dfb14</guid>
      <link>https://share.transistor.fm/s/d86c0f0b</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk threat detection &amp; research with Zack Allen, Security Detection &amp; Research Leader at Datadog.</p><p>Zack is a seasoned security research, engineering, and product leader with over a decade of experience in building organizations that create impactful security for customers. Zack specializes in threat research and intelligence, cloud security, software engineering, and DevOps. His expertise has significantly contributed to advancing the field of cybersecurity. He is also the visionary behind Detection Engineering Weekly, a platform that provides insights and updates on the latest in detection engineering. </p><p>You can subscribe to Zack's newsletter <a rel="noreferrer noopener" href="https://www.detectionengineering.net/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we talk threat detection &amp; research with Zack Allen, Security Detection &amp; Research Leader at Datadog.</p><p>Zack is a seasoned security research, engineering, and product leader with over a decade of experience in building organizations that create impactful security for customers. Zack specializes in threat research and intelligence, cloud security, software engineering, and DevOps. His expertise has significantly contributed to advancing the field of cybersecurity. He is also the visionary behind Detection Engineering Weekly, a platform that provides insights and updates on the latest in detection engineering. </p><p>You can subscribe to Zack's newsletter <a rel="noreferrer noopener" href="https://www.detectionengineering.net/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 19 Jul 2024 13:34:21 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d86c0f0b/22f032b2.mp3" length="25165732" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/nEOMCrl9KX9U9riZxDpm-8Y-fcY9v9nTfrUxhkQ69WY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kMzBi/YTliYzY4NTdhODA3/ODQxZTM0ZWNjODM4/MzI4ZS5wbmc.jpg"/>
      <itunes:duration>2081</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we talk threat detection &amp;amp; research with Zack Allen, Security Detection &amp;amp; Research Leader at Datadog.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we talk threat detection &amp;amp; research with Zack Allen, Security Detection &amp;amp; Research Leader at Datadog.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#141 - The Rescue of Evelyn Chang by Gene Yu, Founder &amp; CEO of Blackpanda</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>141</itunes:episode>
      <podcast:episode>141</podcast:episode>
      <itunes:title>#141 - The Rescue of Evelyn Chang by Gene Yu, Founder &amp; CEO of Blackpanda</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">dd6b1829-a37f-44e7-859a-1fc8e439f425</guid>
      <link>https://share.transistor.fm/s/45734b8c</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Gene Yu, Founder &amp; CEO of <a rel="noreferrer noopener" href="https://www.blackpanda.com/">Blackpanda</a>.</p><p>Gene has a diverse background, with early roles at Palantir's Asia office and Credit Suisse on Wall Street. He also served as a team leader in the US Army Special Forces, completing four combat tours in Iraq and the Southern Philippines. Gene is an active angel investor, renowned for leading the successful rescue of Evelyn Chang from Abu Sayyaf terrorists in 2013. He graduated with top honors in computer science from West Point and has attended Johns Hopkins University and Stanford's Executive Program.</p><p>Gene’s book, about the incredible rescue of Evelyn Chang, can be purchased <a rel="noreferrer noopener" href="https://www.amazon.ca/Second-Shot-Green-Berets-Mission/dp/1662510543">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Gene Yu, Founder &amp; CEO of <a rel="noreferrer noopener" href="https://www.blackpanda.com/">Blackpanda</a>.</p><p>Gene has a diverse background, with early roles at Palantir's Asia office and Credit Suisse on Wall Street. He also served as a team leader in the US Army Special Forces, completing four combat tours in Iraq and the Southern Philippines. Gene is an active angel investor, renowned for leading the successful rescue of Evelyn Chang from Abu Sayyaf terrorists in 2013. He graduated with top honors in computer science from West Point and has attended Johns Hopkins University and Stanford's Executive Program.</p><p>Gene’s book, about the incredible rescue of Evelyn Chang, can be purchased <a rel="noreferrer noopener" href="https://www.amazon.ca/Second-Shot-Green-Berets-Mission/dp/1662510543">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 11 Jul 2024 08:32:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/45734b8c/3faebc04.mp3" length="117547615" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>4898</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Gene Yu, Founder &amp;amp; CEO of Blackpanda.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Gene Yu, Founder &amp;amp; CEO of Blackpanda.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#140 - Intel Chat: 10bn Pwds, Eldorado RaaS, 840Mpps DDoS, regreSSHion &amp; $1.4bn in stolen crypto</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>140</itunes:episode>
      <podcast:episode>140</podcast:episode>
      <itunes:title>#140 - Intel Chat: 10bn Pwds, Eldorado RaaS, 840Mpps DDoS, regreSSHion &amp; $1.4bn in stolen crypto</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">963478eb-993f-40fa-8ec8-b9a2adaf95ef</guid>
      <link>https://share.transistor.fm/s/1ec90c70</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Likely the biggest password leak ever: nearly 10 billion <a rel="noreferrer noopener" href="https://mashable.com/article/rockyou2024-leaked-password-database">credentials exposed</a>.</li><li>Eldorado is a newly discovered <a rel="noreferrer noopener" href="https://thehackernews.com/2024/07/new-ransomware-as-service-eldorado.html">ransomware-as-a-service</a> operation targeting both Windows and Linux systems. </li><li>OVHcloud has reported mitigating a record-breaking distributed denial-of-service attack that peaked at <a rel="noreferrer noopener" href="https://www.securityweek.com/ovhcloud-sees-record-840-mpps-ddos-attack/">840 million packets per second</a>.</li><li>Cisco has issued a warning about a critical remote code execution vulnerability named "regreSSHion," tracked as <a rel="noreferrer noopener" href="https://cybersecuritynews.com/cisco-warns-regresshion-rce/#google_vignette">CVE-2024-6387</a>, affecting OpenSSH on glibc-based Linux systems. </li><li>In the first half of 2024, cryptocurrency thefts amounted to $1.4 billion, significantly driven by rising crypto prices and a few<a rel="noreferrer noopener" href="https://www.nbcnews.com/tech/tech-news/hackers-steal-600-million-maker-axie-infinity-rcna22031"> large-scale attacks</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Likely the biggest password leak ever: nearly 10 billion <a rel="noreferrer noopener" href="https://mashable.com/article/rockyou2024-leaked-password-database">credentials exposed</a>.</li><li>Eldorado is a newly discovered <a rel="noreferrer noopener" href="https://thehackernews.com/2024/07/new-ransomware-as-service-eldorado.html">ransomware-as-a-service</a> operation targeting both Windows and Linux systems. </li><li>OVHcloud has reported mitigating a record-breaking distributed denial-of-service attack that peaked at <a rel="noreferrer noopener" href="https://www.securityweek.com/ovhcloud-sees-record-840-mpps-ddos-attack/">840 million packets per second</a>.</li><li>Cisco has issued a warning about a critical remote code execution vulnerability named "regreSSHion," tracked as <a rel="noreferrer noopener" href="https://cybersecuritynews.com/cisco-warns-regresshion-rce/#google_vignette">CVE-2024-6387</a>, affecting OpenSSH on glibc-based Linux systems. </li><li>In the first half of 2024, cryptocurrency thefts amounted to $1.4 billion, significantly driven by rising crypto prices and a few<a rel="noreferrer noopener" href="https://www.nbcnews.com/tech/tech-news/hackers-steal-600-million-maker-axie-infinity-rcna22031"> large-scale attacks</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 10 Jul 2024 15:03:05 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1ec90c70/8ebb6fb5.mp3" length="40202848" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/6-2H4zz27tXtbkoJwT0EWVMphkflOpBvz1MEqxNKqSo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hNDA2/MjU5NDMwODZlMDg3/NTAyMjgzZWI2NjY1/YzkxMi5wbmc.jpg"/>
      <itunes:duration>1676</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#139 - Intel Chat: MOVEit, P2PInfect, polyfill.io &amp; TeamViewer</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>139</itunes:episode>
      <podcast:episode>139</podcast:episode>
      <itunes:title>#139 - Intel Chat: MOVEit, P2PInfect, polyfill.io &amp; TeamViewer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5eba80e1-e17e-4d23-878c-744c5afa5c17</guid>
      <link>https://share.transistor.fm/s/d28622ad</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A high-severity security vulnerability in Progress Software's MOVEit Transfer software could allow cyberattackers to get around the platform's authentication mechanisms — and it's been spotted being actively exploited in the wild just hours <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/fresh-moveit-bug-under-attack-disclosure">after it was made public</a>.</li><li>A new version of the P2P worm, P2PInfect, that targets Redis servers running on both Linux and Windows systems, which is aimed at deploying both ransomware and cryptocurrency mining payloads, <a rel="noreferrer noopener" href="https://securityaffairs.com/164968/malware/p2pinfect-delivers-miners-ransomware-on-redis.html">is out in the wild</a>.</li><li>The polyfill.io domain, used for providing backward compatibility for older browsers, has been shut down amid accusations of malicious activity after recently being acquired by Chinese firm Funnull, and was allegedly redirecting users to malicious sites and <a rel="noreferrer noopener" href="https://www.securityweek.com/polyfill-domain-shut-down-as-owner-disputes-accusations-of-malicious-activity/">employing evasion techniques</a>. </li><li>The Germany-based company behind the world-famous remote desktop software TeamViewer has confirmed that in 2016 <a rel="noreferrer noopener" href="https://hackread.com/teamviewer-was-targeted-by-chinese-hackers-in-2016/">TeamViewer software was compromised</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>A high-severity security vulnerability in Progress Software's MOVEit Transfer software could allow cyberattackers to get around the platform's authentication mechanisms — and it's been spotted being actively exploited in the wild just hours <a rel="noreferrer noopener" href="https://www.darkreading.com/remote-workforce/fresh-moveit-bug-under-attack-disclosure">after it was made public</a>.</li><li>A new version of the P2P worm, P2PInfect, that targets Redis servers running on both Linux and Windows systems, which is aimed at deploying both ransomware and cryptocurrency mining payloads, <a rel="noreferrer noopener" href="https://securityaffairs.com/164968/malware/p2pinfect-delivers-miners-ransomware-on-redis.html">is out in the wild</a>.</li><li>The polyfill.io domain, used for providing backward compatibility for older browsers, has been shut down amid accusations of malicious activity after recently being acquired by Chinese firm Funnull, and was allegedly redirecting users to malicious sites and <a rel="noreferrer noopener" href="https://www.securityweek.com/polyfill-domain-shut-down-as-owner-disputes-accusations-of-malicious-activity/">employing evasion techniques</a>. </li><li>The Germany-based company behind the world-famous remote desktop software TeamViewer has confirmed that in 2016 <a rel="noreferrer noopener" href="https://hackread.com/teamviewer-was-targeted-by-chinese-hackers-in-2016/">TeamViewer software was compromised</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 04 Jul 2024 09:09:58 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d28622ad/813e1641.mp3" length="18680917" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/g6bF2HOv8H_XBUSoCn2Ftpai1iNO6ilXaIAtONfLQmU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YmRi/ZDFkZjRiYTcwZmU3/YWVmZmNmZjIxNWFm/MDJjZC5wbmc.jpg"/>
      <itunes:duration>1541</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#138 - Automating security detection engineering with Dennis Chow, Security Engineer at EY</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>138</itunes:episode>
      <podcast:episode>138</podcast:episode>
      <itunes:title>#138 - Automating security detection engineering with Dennis Chow, Security Engineer at EY</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fe5bffef-9896-4465-8566-d852713abb4f</guid>
      <link>https://share.transistor.fm/s/bc93a1a4</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk about automating security detection engineering with Dennis Chow, Security Engineer at EY.</p><p>Dennis is a multi-industry and seasoned cybersecurity operations leader. Using his experience, he helps organizations achieve their maximum security potential through hybrid training, sec ops management, engineering, and cross-disciplinary integration. He is also a published author, and a veteran of the armed forces. </p><p>Dennis Chow's book on Automating Security Detection Engineering can be purchased <a rel="noreferrer noopener" href="https://www.amazon.com/Automating-Security-Detection-Engineering-hands/dp/1837636419">here</a>.</p><p>Megan Rodie's book on Practical Threat Detection Engineering can be purchased <a rel="noreferrer noopener" href="https://www.amazon.com/Practical-Threat-Detection-Engineering-hands/dp/1801076715/ref=pd_sim_d_sccl_1_3/132-6453362-3758240?pd_rd_w=By1e7&amp;content-id=amzn1.sym.fc475966-e837-48fc-9ed0-f4ca6ae9337b&amp;pf_rd_p=fc475966-e837-48fc-9ed0-f4ca6ae9337b&amp;pf_rd_r=W8XKS19GVCNWV1KNYT0F&amp;pd_rd_wg=DaNlm&amp;pd_rd_r=cd03c3b8-8025-42e3-a634-d708805a5d13&amp;pd_rd_i=1801076715&amp;psc=1">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk about automating security detection engineering with Dennis Chow, Security Engineer at EY.</p><p>Dennis is a multi-industry and seasoned cybersecurity operations leader. Using his experience, he helps organizations achieve their maximum security potential through hybrid training, sec ops management, engineering, and cross-disciplinary integration. He is also a published author, and a veteran of the armed forces. </p><p>Dennis Chow's book on Automating Security Detection Engineering can be purchased <a rel="noreferrer noopener" href="https://www.amazon.com/Automating-Security-Detection-Engineering-hands/dp/1837636419">here</a>.</p><p>Megan Rodie's book on Practical Threat Detection Engineering can be purchased <a rel="noreferrer noopener" href="https://www.amazon.com/Practical-Threat-Detection-Engineering-hands/dp/1801076715/ref=pd_sim_d_sccl_1_3/132-6453362-3758240?pd_rd_w=By1e7&amp;content-id=amzn1.sym.fc475966-e837-48fc-9ed0-f4ca6ae9337b&amp;pf_rd_p=fc475966-e837-48fc-9ed0-f4ca6ae9337b&amp;pf_rd_r=W8XKS19GVCNWV1KNYT0F&amp;pd_rd_wg=DaNlm&amp;pd_rd_r=cd03c3b8-8025-42e3-a634-d708805a5d13&amp;pd_rd_i=1801076715&amp;psc=1">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 02 Jul 2024 07:07:49 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/bc93a1a4/61bc9799.mp3" length="24213081" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/KLwjBD3AvLnZC993Nv68M6v5Aer9ysTYWitd9mPLlOg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82NmNl/NDQ0NTQyNDczYjQ3/MWE1NjRkZjhiMTE0/NzRkYy5wbmc.jpg"/>
      <itunes:duration>2002</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we talk about automating security detection engineering with Dennis Chow, Security Engineer at EY.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we talk about automating security detection engineering with Dennis Chow, Security Engineer at EY.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#137 - Exploring AI-powered cybersecurity with Rodrigo Loureiro, CEO of Cyber Connective Corporation</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>137</itunes:episode>
      <podcast:episode>137</podcast:episode>
      <itunes:title>#137 - Exploring AI-powered cybersecurity with Rodrigo Loureiro, CEO of Cyber Connective Corporation</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">79ecf210-8415-4ab1-b13d-86ae6736639a</guid>
      <link>https://share.transistor.fm/s/d32c29d9</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk AI-powered cybersecurity with Rodrigo Loureiro, CEO of Cyber Connective Corporation.</p><p>Rodrigo's extensive experience includes roles as a global Chief Information Officer where he managed a $215M IT budget and oversaw a team of 1800 people, ensuring world-class infrastructure services around the clock.</p><p>In addition to his executive roles, Rodrigo is a bestselling author of 'Game On - Leaders Who Last', where he explores the necessity of adaptability and open-mindedness in leadership, particularly within the technology sector. He is also an Operational Partner at the Executive Enterprise Venture Fund, focusing on innovative cybersecurity and AI investments. A recognized keynote speaker and expert in aligning technology with business strategy, Rodrigo’s insights are invaluable to anyone interested in the future of tech and leadership.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk AI-powered cybersecurity with Rodrigo Loureiro, CEO of Cyber Connective Corporation.</p><p>Rodrigo's extensive experience includes roles as a global Chief Information Officer where he managed a $215M IT budget and oversaw a team of 1800 people, ensuring world-class infrastructure services around the clock.</p><p>In addition to his executive roles, Rodrigo is a bestselling author of 'Game On - Leaders Who Last', where he explores the necessity of adaptability and open-mindedness in leadership, particularly within the technology sector. He is also an Operational Partner at the Executive Enterprise Venture Fund, focusing on innovative cybersecurity and AI investments. A recognized keynote speaker and expert in aligning technology with business strategy, Rodrigo’s insights are invaluable to anyone interested in the future of tech and leadership.</p>]]>
      </content:encoded>
      <pubDate>Fri, 28 Jun 2024 17:10:34 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d32c29d9/27b792d6.mp3" length="27584778" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/yzDZhvv4YvrfsP6lCw10E3tOivv4TOOLqCUnPBDW1fA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80Y2I4/NDI4NDUwMWYxMzJm/NjE4M2Y1MGYzM2Qz/MzYwOC5wbmc.jpg"/>
      <itunes:duration>2283</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we talk AI-powered cybersecurity with Rodrigo Loureiro, CEO of Cyber Connective Corporation.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we talk AI-powered cybersecurity with Rodrigo Loureiro, CEO of Cyber Connective Corporation.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#136 - Special Episode: The ongoing CDK Global cybersecurity incident</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>136</itunes:episode>
      <podcast:episode>136</podcast:episode>
      <itunes:title>#136 - Special Episode: The ongoing CDK Global cybersecurity incident</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">28e681a2-ad89-46cd-b354-afe8c1b751c0</guid>
      <link>https://share.transistor.fm/s/127adfb5</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak MIke Pedrick and Adriano Carvalho about the ongoing CDK Global cybersecurity incident.</p><p>Mike Pedrick is an experienced cybersecurity practitioner with too many certs to list off. He makes his way through the world as a vCISO and happens to have a deep interest in the automobile sector.</p><p>Adriano Carvalho is consulting partner with the Reynolds and Reynolds company, who has spent over 10 years immersed in the automotive industry.</p><p>The incident: CDK Global experienced a significant cyberattack starting on June 18, 2024, which led to the shutdown of its systems affecting approximately 15,000 automotive dealerships across the United States. The company, which provides crucial software solutions for dealership management, had to proactively shut down most of its IT systems to prevent the spread of the attack. This resulted in a major disruption of dealership operations, forcing employees to revert to manual processes such as writing work orders by hand.</p><p>CDK Global has been working with third-party experts to investigate the incident and has started to restore some of its services, including the core dealer management system. However, the full resolution of the issue is expected to take several days, and the company is continuously updating its customers on the progress. The company has emphasized that its priority is the security of its customers and is taking extensive measures to ensure systems are safe before bringing them back online.</p><p>The impact of the cyberattack has left many dealerships unable to conduct regular business activities, significantly affecting their operations. CDK Global has not yet disclosed who was behind the attack or if any sensitive data was compromised, but further updates are expected as the investigation continues​.</p><p>Mike can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/mpedrick/">here</a>.</p><p>Adriano can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/adrianocarvalho92/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak MIke Pedrick and Adriano Carvalho about the ongoing CDK Global cybersecurity incident.</p><p>Mike Pedrick is an experienced cybersecurity practitioner with too many certs to list off. He makes his way through the world as a vCISO and happens to have a deep interest in the automobile sector.</p><p>Adriano Carvalho is consulting partner with the Reynolds and Reynolds company, who has spent over 10 years immersed in the automotive industry.</p><p>The incident: CDK Global experienced a significant cyberattack starting on June 18, 2024, which led to the shutdown of its systems affecting approximately 15,000 automotive dealerships across the United States. The company, which provides crucial software solutions for dealership management, had to proactively shut down most of its IT systems to prevent the spread of the attack. This resulted in a major disruption of dealership operations, forcing employees to revert to manual processes such as writing work orders by hand.</p><p>CDK Global has been working with third-party experts to investigate the incident and has started to restore some of its services, including the core dealer management system. However, the full resolution of the issue is expected to take several days, and the company is continuously updating its customers on the progress. The company has emphasized that its priority is the security of its customers and is taking extensive measures to ensure systems are safe before bringing them back online.</p><p>The impact of the cyberattack has left many dealerships unable to conduct regular business activities, significantly affecting their operations. CDK Global has not yet disclosed who was behind the attack or if any sensitive data was compromised, but further updates are expected as the investigation continues​.</p><p>Mike can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/mpedrick/">here</a>.</p><p>Adriano can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/adrianocarvalho92/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 26 Jun 2024 08:31:44 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/127adfb5/33f5e21f.mp3" length="27555563" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/xdzMw60rBOIlAdh84LYEFF-3aVGZmAluG4UVwcuEUYY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84MmI3/Y2E5NzdhNDU5MGVi/MTFkZTdlMjgyNmU2/M2YwNy5wbmc.jpg"/>
      <itunes:duration>2280</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak MIke Pedrick and Adriano Carvalho about the ongoing CDK Global cybersecurity incident.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak MIke Pedrick and Adriano Carvalho about the ongoing CDK Global cybersecurity incident.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#135 - Intel Chat: Sigma, Scattered Spider, Microsoft, Empire Market &amp; UNC3886</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>135</itunes:episode>
      <podcast:episode>135</podcast:episode>
      <itunes:title>#135 - Intel Chat: Sigma, Scattered Spider, Microsoft, Empire Market &amp; UNC3886</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">39753f24-0570-4d7a-a1c5-6879e37646d2</guid>
      <link>https://share.transistor.fm/s/21267bd4</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>SigmaHQ has introduced Sigma Correlations to enhance its rule-based detection capabilities, allowing for more sophisticated event correlation across multiple <a rel="noreferrer noopener" href="https://blog.sigmahq.io/introducing-sigma-correlations-52fe377f2527">Sigma rules</a>.</li><li>Tyler Buchanan, a 22-year-old from the UK and alleged leader of the Scattered Spider hacking group, was <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/06/alleged-boss-of-scattered-spider-hacking-group-arrested/">arrested in Spain</a>.</li><li>Microsoft has issued an urgent update for all supported versions of Windows to address a critical Wi-Fi vulnerability, <a rel="noreferrer noopener" href="https://www.forbes.com/sites/daveywinder/2024/06/14/new-wi-fi-takeover-attack-all-windows-users-warned-to-update-now/">CVE-2024-30078</a>.</li><li>Three individuals— Yousef Selassie, Ugochukwu Emmanuel Nwosu, and David Gil—have been charged with operating Empire Market, a dark web marketplace that facilitated over <a rel="noreferrer noopener" href="https://securityaffairs.com/164619/deep-web/empire-market-owners-charged.html">$430 million in illegal transactions</a>.</li><li>In September 2022, Mandiant began investigating several intrusions conducted by UNC3886, a China-linked cyber espionage group, after discovering malware in <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/uncovering-unc3886-espionage-operations">ESXi hypervisors</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>SigmaHQ has introduced Sigma Correlations to enhance its rule-based detection capabilities, allowing for more sophisticated event correlation across multiple <a rel="noreferrer noopener" href="https://blog.sigmahq.io/introducing-sigma-correlations-52fe377f2527">Sigma rules</a>.</li><li>Tyler Buchanan, a 22-year-old from the UK and alleged leader of the Scattered Spider hacking group, was <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/06/alleged-boss-of-scattered-spider-hacking-group-arrested/">arrested in Spain</a>.</li><li>Microsoft has issued an urgent update for all supported versions of Windows to address a critical Wi-Fi vulnerability, <a rel="noreferrer noopener" href="https://www.forbes.com/sites/daveywinder/2024/06/14/new-wi-fi-takeover-attack-all-windows-users-warned-to-update-now/">CVE-2024-30078</a>.</li><li>Three individuals— Yousef Selassie, Ugochukwu Emmanuel Nwosu, and David Gil—have been charged with operating Empire Market, a dark web marketplace that facilitated over <a rel="noreferrer noopener" href="https://securityaffairs.com/164619/deep-web/empire-market-owners-charged.html">$430 million in illegal transactions</a>.</li><li>In September 2022, Mandiant began investigating several intrusions conducted by UNC3886, a China-linked cyber espionage group, after discovering malware in <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/uncovering-unc3886-espionage-operations">ESXi hypervisors</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 21 Jun 2024 14:18:25 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/21267bd4/742041fd.mp3" length="26434614" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/zYJw0IdD6utVtEkgKYBThSmfI_956ifgADBjLDzmIAQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yYzhl/YzIzYzZkZTliNzhl/M2U1YjY1MjQwNjRi/ZTViZi5wbmc.jpg"/>
      <itunes:duration>2187</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#134 - Incident command with Gerard Johansen, Principal Security Solutions Specialist at Red Canary</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>134</itunes:episode>
      <podcast:episode>134</podcast:episode>
      <itunes:title>#134 - Incident command with Gerard Johansen, Principal Security Solutions Specialist at Red Canary</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">adc9236b-00aa-4f4a-b5ff-c6b8659521c1</guid>
      <link>https://share.transistor.fm/s/73d020ca</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Gerard Johansen, Principal Security Solutions Specialist at Red Canary.</p><p>Gerard is a seasoned expert in the field of cybersecurity. Gerard holds the prestigious Certified Information System Security Professional - or CISSP. His extensive career includes serving as a Special Deputy United States Marshal for the FBI's Connecticut Computer Crimes Task Force and working as a Certification and Accreditation Analyst for a federal inter-agency unit. Gerard has conducted numerous technical and non-technical vulnerability assessments for both financial and government organizations, demonstrating his deep expertise in digital forensics and incident response.</p><p>With a wealth of experience in risk assessment, cyber threat intelligence, and penetration testing, Gerard is frequently sought after for his knowledge in corporate counterintelligence, threat emulation, and cloud security challenges. He has developed and maintained crucial industry relationships through ongoing professional development and is a trusted resource for information security seminars and training programs. </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Gerard Johansen, Principal Security Solutions Specialist at Red Canary.</p><p>Gerard is a seasoned expert in the field of cybersecurity. Gerard holds the prestigious Certified Information System Security Professional - or CISSP. His extensive career includes serving as a Special Deputy United States Marshal for the FBI's Connecticut Computer Crimes Task Force and working as a Certification and Accreditation Analyst for a federal inter-agency unit. Gerard has conducted numerous technical and non-technical vulnerability assessments for both financial and government organizations, demonstrating his deep expertise in digital forensics and incident response.</p><p>With a wealth of experience in risk assessment, cyber threat intelligence, and penetration testing, Gerard is frequently sought after for his knowledge in corporate counterintelligence, threat emulation, and cloud security challenges. He has developed and maintained crucial industry relationships through ongoing professional development and is a trusted resource for information security seminars and training programs. </p>]]>
      </content:encoded>
      <pubDate>Tue, 18 Jun 2024 12:00:11 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/73d020ca/74fc57a4.mp3" length="17260803" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2158</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with Gerard Johansen, Principal Security Solutions Specialist at Red Canary.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with Gerard Johansen, Principal Security Solutions Specialist at Red Canary.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#133 - Intel Chat: Snowflake, Operation Endgame, Android spoof &amp; Operation Crimson Palace</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>133</itunes:episode>
      <podcast:episode>133</podcast:episode>
      <itunes:title>#133 - Intel Chat: Snowflake, Operation Endgame, Android spoof &amp; Operation Crimson Palace</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c89f01bf-7c2b-4073-803c-befe3e82b517</guid>
      <link>https://share.transistor.fm/s/4fed49cd</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Mandiant has linked a series of data breaches affecting hundreds of Snowflake instances to the use of infostealer malware, primarily targeting non-Snowflake systems to <a rel="noreferrer noopener" href="https://www.securityweek.com/snowflake-attacks-mandiant-links-data-breaches-to-infostealer-infections/">harvest credentials</a>.</li><li>Authorities have ramped up something they are calling Operation Endgame which is an effort to capture a fellow that goes by the handle "Odd," the alleged mastermind behind the <a rel="noreferrer noopener" href="https://thehackernews.com/2024/06/authorities-ramp-up-efforts-to-capture.html">Emotet botnet</a>.</li><li>McAfee has identified a fake Bahrain government Android app masquerading as the Labour Market Regulatory Authority app, and is designed to steal personal data for <a rel="noreferrer noopener" href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/">financial fraud</a>.</li><li>A technical deep-dive on Operation Crimson Palace performed by Sophos X-ops: the operation exposes a sophisticated cyberespionage campaign targeting a Southeast Asian government, attributed to <a rel="noreferrer noopener" href="https://news.sophos.com/en-us/2024/06/05/operation-crimson-palace-a-technical-deep-dive/">Chinese state interests</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Mandiant has linked a series of data breaches affecting hundreds of Snowflake instances to the use of infostealer malware, primarily targeting non-Snowflake systems to <a rel="noreferrer noopener" href="https://www.securityweek.com/snowflake-attacks-mandiant-links-data-breaches-to-infostealer-infections/">harvest credentials</a>.</li><li>Authorities have ramped up something they are calling Operation Endgame which is an effort to capture a fellow that goes by the handle "Odd," the alleged mastermind behind the <a rel="noreferrer noopener" href="https://thehackernews.com/2024/06/authorities-ramp-up-efforts-to-capture.html">Emotet botnet</a>.</li><li>McAfee has identified a fake Bahrain government Android app masquerading as the Labour Market Regulatory Authority app, and is designed to steal personal data for <a rel="noreferrer noopener" href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/">financial fraud</a>.</li><li>A technical deep-dive on Operation Crimson Palace performed by Sophos X-ops: the operation exposes a sophisticated cyberespionage campaign targeting a Southeast Asian government, attributed to <a rel="noreferrer noopener" href="https://news.sophos.com/en-us/2024/06/05/operation-crimson-palace-a-technical-deep-dive/">Chinese state interests</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 13 Jun 2024 18:29:04 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4fed49cd/e1c53e37.mp3" length="18638554" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/1GVZSyPT5etf1LXLAOB7sspPoNyvJ3fPg3FxxDB1X_M/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jNTll/YTZkZDgwNzUzMGJi/NmRlNGViM2M0MDM2/MDBiNy5wbmc.jpg"/>
      <itunes:duration>1537</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#132 - API security with Jeremy Snyder, Founder and CEO at FireTail.io</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>132</itunes:episode>
      <podcast:episode>132</podcast:episode>
      <itunes:title>#132 - API security with Jeremy Snyder, Founder and CEO at FireTail.io</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3fbfc2bf-2dd5-4b08-a135-bbfb21ee4926</guid>
      <link>https://share.transistor.fm/s/f398613a</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk API security with Jeremy Snyder, Founder and CEO at <a rel="noreferrer noopener" href="https://www.firetail.io/">FireTail.io.</a></p><p>FireTail.io is a pioneering company specializing in end-to-end API security. With APIs being the number one attack surface and a significant threat to data privacy and security, Jeremy and his team are at the forefront of protecting sensitive information in an increasingly interconnected world.</p><p>Jeremy brings a wealth of experience in cloud, cybersecurity, and data domains, coupled with a strong background in M&amp;A, international business, business development, strategy, and operations. Fluent in five languages and having lived in five different countries, he offers a unique global perspective on cybersecurity challenges and innovations.</p><p>FireTail.io's <a rel="noreferrer noopener" href="https://www.firetail.io/api-data-breach-tracker">data breach tracker</a>.</p><p><a rel="noreferrer noopener" href="https://github.com/daveshanley/vacuum">vacuum</a> - The world's fastest OpenAPI &amp; Swagger linter.</p><p><a rel="noreferrer noopener" href="https://github.com/projectdiscovery/nuclei">Nuclei</a> - Fast and customisable vulnerability scanner based on simple YAML based DSL.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk API security with Jeremy Snyder, Founder and CEO at <a rel="noreferrer noopener" href="https://www.firetail.io/">FireTail.io.</a></p><p>FireTail.io is a pioneering company specializing in end-to-end API security. With APIs being the number one attack surface and a significant threat to data privacy and security, Jeremy and his team are at the forefront of protecting sensitive information in an increasingly interconnected world.</p><p>Jeremy brings a wealth of experience in cloud, cybersecurity, and data domains, coupled with a strong background in M&amp;A, international business, business development, strategy, and operations. Fluent in five languages and having lived in five different countries, he offers a unique global perspective on cybersecurity challenges and innovations.</p><p>FireTail.io's <a rel="noreferrer noopener" href="https://www.firetail.io/api-data-breach-tracker">data breach tracker</a>.</p><p><a rel="noreferrer noopener" href="https://github.com/daveshanley/vacuum">vacuum</a> - The world's fastest OpenAPI &amp; Swagger linter.</p><p><a rel="noreferrer noopener" href="https://github.com/projectdiscovery/nuclei">Nuclei</a> - Fast and customisable vulnerability scanner based on simple YAML based DSL.</p>]]>
      </content:encoded>
      <pubDate>Wed, 12 Jun 2024 12:00:11 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f398613a/fb4a3759.mp3" length="26000031" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/M4Y8xQiqKKZolLeerMJXxJi4CMtSqYlMr_V01SpH2FQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZmIx/NDA0YWI3Y2VhMGM4/ZTBlN2UwZGYyNGQ5/OGVkMy5wbmc.jpg"/>
      <itunes:duration>2151</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we talk API security with Jeremy Snyder, Founder and CEO at FireTail.io.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we talk API security with Jeremy Snyder, Founder and CEO at FireTail.io.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#131 - Network threat hunting with Chris Brenton, COO at Active Countermeasures</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>131</itunes:episode>
      <podcast:episode>131</podcast:episode>
      <itunes:title>#131 - Network threat hunting with Chris Brenton, COO at Active Countermeasures</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">13790e25-559c-40dd-9684-d6b6ec45383c</guid>
      <link>https://share.transistor.fm/s/f184bf4b</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk network threat hunting with Chris Brenton, COO at Active Countermeasures.</p><p>Chris is a dedicated professional with a passion for simplifying the process of threat hunting. Chris is deeply committed to enhancing cybersecurity knowledge through delivering both free and affordable security training. Alongside this, he plays a crucial role in the development of both open-source and commercially accessible threat hunting tools. Whether you’re aiming to sharpen your threat hunting skills or are looking to establish a robust threat hunting program within your organization, Chris is the go-to expert. Stay tuned as we dive deeper into his journey, and feel free to reach out to him directly to learn more or get involved.</p><p>You can find Chris on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/chris-brenton/">here</a>.</p><p>And you can find Chris in Twitter <a rel="noreferrer noopener" href="https://twitter.com/Chris_Brenton">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk network threat hunting with Chris Brenton, COO at Active Countermeasures.</p><p>Chris is a dedicated professional with a passion for simplifying the process of threat hunting. Chris is deeply committed to enhancing cybersecurity knowledge through delivering both free and affordable security training. Alongside this, he plays a crucial role in the development of both open-source and commercially accessible threat hunting tools. Whether you’re aiming to sharpen your threat hunting skills or are looking to establish a robust threat hunting program within your organization, Chris is the go-to expert. Stay tuned as we dive deeper into his journey, and feel free to reach out to him directly to learn more or get involved.</p><p>You can find Chris on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/chris-brenton/">here</a>.</p><p>And you can find Chris in Twitter <a rel="noreferrer noopener" href="https://twitter.com/Chris_Brenton">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 06 Jun 2024 15:15:37 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f184bf4b/549334d9.mp3" length="28157659" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/1yJw5gwiSG7mMr6u3rVbIuyC8iqMF1VA7fLE7OCANP0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82Mzdi/YmMxYjdiNWJkN2Uw/MTkyMDgyZWNlZmVl/ZjNjYy5wbmc.jpg"/>
      <itunes:duration>2330</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we talk network threat hunting with Chris Brenton, COO at Active Countermeasures.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we talk network threat hunting with Chris Brenton, COO at Active Countermeasures.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#130 - The changing compliance landscape with Alexander Byrne, Director of Corporate IT Compliance at Thrive</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>131</itunes:episode>
      <podcast:episode>131</podcast:episode>
      <itunes:title>#130 - The changing compliance landscape with Alexander Byrne, Director of Corporate IT Compliance at Thrive</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3686a4d8-82a1-4df1-a121-aebbab27b794</guid>
      <link>https://share.transistor.fm/s/1ce8dc82</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Alexander Byrne, Director of Corporate IT Compliance at Thrive.</p><p>Alexander is a seasoned expert in crafting dynamic information security and IT compliance strategies tailored to meet the needs of businesses ranging from SMBs to large enterprises. With a solid decade of experience, Alexander has delivered solutions across various industries including information technology, fintech, real estate, e-commerce, energy, and healthcare. His approach not only solves business challenges but also ensures alignment with industry best practices and compliance with regulatory requirements, ultimately enabling sustainable value through the technology and cybersecurity investment cycle.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Alexander Byrne, Director of Corporate IT Compliance at Thrive.</p><p>Alexander is a seasoned expert in crafting dynamic information security and IT compliance strategies tailored to meet the needs of businesses ranging from SMBs to large enterprises. With a solid decade of experience, Alexander has delivered solutions across various industries including information technology, fintech, real estate, e-commerce, energy, and healthcare. His approach not only solves business challenges but also ensures alignment with industry best practices and compliance with regulatory requirements, ultimately enabling sustainable value through the technology and cybersecurity investment cycle.</p>]]>
      </content:encoded>
      <pubDate>Tue, 04 Jun 2024 12:30:09 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1ce8dc82/587996a4.mp3" length="30196835" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/lt87o5MmF_-GOc9jtrhhQz88dO1xWi164YVaohxJGw4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZjFi/Y2FlOTY1Y2RjMmEz/ODEyZThhNzY4NTMw/NzU3NC5wbmc.jpg"/>
      <itunes:duration>2500</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with Alexander Byrne, Director of Corporate IT Compliance at Thrive.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with Alexander Byrne, Director of Corporate IT Compliance at Thrive.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#129 - Intel Chat: MSSN CTRL, GhostEngine, MITRE &amp; BreachForums</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>129</itunes:episode>
      <podcast:episode>129</podcast:episode>
      <itunes:title>#129 - Intel Chat: MSSN CTRL, GhostEngine, MITRE &amp; BreachForums</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1f4a0ddc-d11b-4c9b-a87f-e657bcc657f0</guid>
      <link>https://share.transistor.fm/s/6353dc8f</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Researchers have identified a new malware, called"GhostEngine," which targets vulnerable drivers to disable <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/novel-edr-killing-ghostengine-malware-stealth">endpoint detection and response solutions</a>.</li><li> MITRE has released some more details on how Chinese state-sponsored hackers recently exploited VMware systems within <a rel="noreferrer noopener" href="https://www.securityweek.com/vmware-abused-in-recent-mitre-hack-for-persistence-evasion/">MITRE's NERVE environment</a> for persistence and evasion.</li><li>The FBI has once again seized control of <a rel="noreferrer noopener" href="https://thehackernews.com/2024/05/hackers-created-rogue-vms-to-evade.html">BreachForums</a>, a notorious site known for trading stolen data, marking the second such action within a year.</li></ul><p>Information on MSSN CTRL, the security automation and engineering conference, can be found <a rel="noreferrer noopener" href="https://www.mssnctrl.org/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Researchers have identified a new malware, called"GhostEngine," which targets vulnerable drivers to disable <a rel="noreferrer noopener" href="https://www.darkreading.com/cyberattacks-data-breaches/novel-edr-killing-ghostengine-malware-stealth">endpoint detection and response solutions</a>.</li><li> MITRE has released some more details on how Chinese state-sponsored hackers recently exploited VMware systems within <a rel="noreferrer noopener" href="https://www.securityweek.com/vmware-abused-in-recent-mitre-hack-for-persistence-evasion/">MITRE's NERVE environment</a> for persistence and evasion.</li><li>The FBI has once again seized control of <a rel="noreferrer noopener" href="https://thehackernews.com/2024/05/hackers-created-rogue-vms-to-evade.html">BreachForums</a>, a notorious site known for trading stolen data, marking the second such action within a year.</li></ul><p>Information on MSSN CTRL, the security automation and engineering conference, can be found <a rel="noreferrer noopener" href="https://www.mssnctrl.org/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 30 May 2024 13:17:20 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6353dc8f/693bc3ae.mp3" length="16714212" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/pQH0-nu4_WgdB3-KRc435pQmSlVjW7X6qZ3Cuhp4uP8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xZGU1/ZWE3NmUwOTNiMTRj/MTQ1MjZmMGIzNDEy/NWIwMC5wbmc.jpg"/>
      <itunes:duration>1377</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#128 - Exploring SOAR with Andrew Katz, Senior Information Security Engineer at Jamf</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>128</itunes:episode>
      <podcast:episode>128</podcast:episode>
      <itunes:title>#128 - Exploring SOAR with Andrew Katz, Senior Information Security Engineer at Jamf</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f95106cf-afca-45ee-81e9-d139cc0cac67</guid>
      <link>https://share.transistor.fm/s/a2041b2b</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Andrew Katz, Senior Information Security Engineer at Jamf.</p><p>Andrew is a seasoned security engineer with a sharp focus on security automation. Over the past nine years, Andrew has honed his expertise in Python, API development, AWS, and Docker to craft sophisticated automated security solutions. His journey includes leading the development of SOAR platforms at Jamf, which enhanced distributed alerting systems to help SOC analysts combat alert fatigue. At Tevora, he offered his skills as a consultant, conducting enterprise-level cybersecurity risk assessments. Andrew's earlier roles as a Systems Engineer at Falck and an Information Technologist at GHD laid the groundwork for his profound understanding of IT, which feeds into his current security prowess. A holder of a CISSP and a Bachelor of Science in Geographic Science and Community Planning, Andrew brings a unique blend of technical skill and strategic insight to the field of cybersecurity.</p><p>The Security Engineering Newsletter can be found here: <a rel="noreferrer noopener" href="https://akatz.org/tag/seceng/">SecEng Newsletter</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Andrew Katz, Senior Information Security Engineer at Jamf.</p><p>Andrew is a seasoned security engineer with a sharp focus on security automation. Over the past nine years, Andrew has honed his expertise in Python, API development, AWS, and Docker to craft sophisticated automated security solutions. His journey includes leading the development of SOAR platforms at Jamf, which enhanced distributed alerting systems to help SOC analysts combat alert fatigue. At Tevora, he offered his skills as a consultant, conducting enterprise-level cybersecurity risk assessments. Andrew's earlier roles as a Systems Engineer at Falck and an Information Technologist at GHD laid the groundwork for his profound understanding of IT, which feeds into his current security prowess. A holder of a CISSP and a Bachelor of Science in Geographic Science and Community Planning, Andrew brings a unique blend of technical skill and strategic insight to the field of cybersecurity.</p><p>The Security Engineering Newsletter can be found here: <a rel="noreferrer noopener" href="https://akatz.org/tag/seceng/">SecEng Newsletter</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 29 May 2024 13:06:44 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a2041b2b/970e6ffa.mp3" length="24667187" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/_uRSbKjEE7nqmluZfD9bVaK2HY_7n1olga082i4tznE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNGVh/NTE4NDc1YjFmNWZm/NTBhZjljZTQxNGEx/NTIzOS5wbmc.jpg"/>
      <itunes:duration>2039</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with Andrew Katz, Senior Information Security Engineer at Jamf.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with Andrew Katz, Senior Information Security Engineer at Jamf.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#127 - Intel Chat: Alabuga Leaks, LockBit, EBury, E2EE &amp; Dropbox</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>127</itunes:episode>
      <podcast:episode>127</podcast:episode>
      <itunes:title>#127 - Intel Chat: Alabuga Leaks, LockBit, EBury, E2EE &amp; Dropbox</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d0a90b76-704a-476e-8804-491f8d96e82a</guid>
      <link>https://share.transistor.fm/s/579a3e8d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Some of the findings that were revealed by this leak about the inner workings of the Russian company Albatross and its Albatross-M5 UAVs, now being used in the <a rel="noreferrer noopener" href="https://informnapalm.org/en/alabugaleaks-part-3/">war against Ukraine</a>. </li><li>The U.S. Department of Justice has charged Dmitry Yuryevich Khoroshev, a 31-year-old Russian national, as the leader of the <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/05/u-s-charges-russian-man-as-boss-of-lockbit-ransomware-group/">LockBit ransomware group</a>.</li><li>ESET reveals the persistent threat posed by the Ebury malware, which has compromised approximately <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/">400,000 Linux servers</a> since 2009, which was initially documented in 2014.</li><li>Zoom has announced the global rollout of post-quantum end-to-end encryption for its video meetings, a significant step forward in securing communications against future <a rel="noreferrer noopener" href="https://thehackernews.com/2024/05/zoom-adopts-nist-approved-post-quantum.html">quantum computing threats</a>.</li><li>Dropbox recently disclosed a security breach impacting its <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/dropbox-says-hackers-stole-customer-data-auth-secrets-from-esignature-service/">Dropbox Sign eSignature service</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Some of the findings that were revealed by this leak about the inner workings of the Russian company Albatross and its Albatross-M5 UAVs, now being used in the <a rel="noreferrer noopener" href="https://informnapalm.org/en/alabugaleaks-part-3/">war against Ukraine</a>. </li><li>The U.S. Department of Justice has charged Dmitry Yuryevich Khoroshev, a 31-year-old Russian national, as the leader of the <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/05/u-s-charges-russian-man-as-boss-of-lockbit-ransomware-group/">LockBit ransomware group</a>.</li><li>ESET reveals the persistent threat posed by the Ebury malware, which has compromised approximately <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/">400,000 Linux servers</a> since 2009, which was initially documented in 2014.</li><li>Zoom has announced the global rollout of post-quantum end-to-end encryption for its video meetings, a significant step forward in securing communications against future <a rel="noreferrer noopener" href="https://thehackernews.com/2024/05/zoom-adopts-nist-approved-post-quantum.html">quantum computing threats</a>.</li><li>Dropbox recently disclosed a security breach impacting its <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/dropbox-says-hackers-stole-customer-data-auth-secrets-from-esignature-service/">Dropbox Sign eSignature service</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 24 May 2024 06:12:08 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/579a3e8d/87d39d0a.mp3" length="19420610" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/HvUWhDA-rePFKvUXJgzQoxCmqcVudSz9D8WpuZ_R5vE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84Nzky/YWVkM2Y2MTk4Yjcx/N2ZmY2I5NTk2NGZh/ZmQyMC5wbmc.jpg"/>
      <itunes:duration>1602</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#126 - Zero Trust architecture with Kane Narraway, Head of Enterprise Security at Canva</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>126</itunes:episode>
      <podcast:episode>126</podcast:episode>
      <itunes:title>#126 - Zero Trust architecture with Kane Narraway, Head of Enterprise Security at Canva</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f8d99421-f28d-43d2-8c80-aaa4b3ada7bf</guid>
      <link>https://share.transistor.fm/s/0a65b643</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Kane Narraway, Head of Enterprise Security at Canva, about Zero Trust architecture.</p><p>Kane brings over a decade of experience to the table, specializing in enterprise security, cloud security, and risk management. He's known for his groundbreaking work in building zero trust architectures at some of the world’s largest tech companies, often from scratch during the early days of zero trust when solutions were not readily available.</p><p>Kane's career is marked by notable achievements, including integrating multi-billion dollar acquisitions and establishing robust security frameworks for regulations like SOC2, PCI-DSS, and HIPAA. He’s not only a director who has scaled technology companies from startup to enterprise level but also a passionate leader who has nurtured diverse teams, promoting autonomy and inclusivity. Outside of his direct work, Kane is dedicated to giving back to the community—whether it’s sharing cybersecurity insights, mentoring at boot camps, or volunteering at conferences. Join us as we gain insights from his extensive experience and innovative approaches to tackling some of the most complex challenges in cybersecurity today.</p><p>Kane's blog can be found <a rel="noreferrer noopener" href="https://kanenarraway.com/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Kane Narraway, Head of Enterprise Security at Canva, about Zero Trust architecture.</p><p>Kane brings over a decade of experience to the table, specializing in enterprise security, cloud security, and risk management. He's known for his groundbreaking work in building zero trust architectures at some of the world’s largest tech companies, often from scratch during the early days of zero trust when solutions were not readily available.</p><p>Kane's career is marked by notable achievements, including integrating multi-billion dollar acquisitions and establishing robust security frameworks for regulations like SOC2, PCI-DSS, and HIPAA. He’s not only a director who has scaled technology companies from startup to enterprise level but also a passionate leader who has nurtured diverse teams, promoting autonomy and inclusivity. Outside of his direct work, Kane is dedicated to giving back to the community—whether it’s sharing cybersecurity insights, mentoring at boot camps, or volunteering at conferences. Join us as we gain insights from his extensive experience and innovative approaches to tackling some of the most complex challenges in cybersecurity today.</p><p>Kane's blog can be found <a rel="noreferrer noopener" href="https://kanenarraway.com/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 21 May 2024 12:00:10 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0a65b643/ce1e7753.mp3" length="34838334" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/aUXBVTnnG__ztCO1CcboCRpu6opPFM-IyRez5nMLWaM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YWU1/YTU0YjM4Mjk0NTJh/NDBmZmIzMTkzNmY4/ZTJlOS5wbmc.jpg"/>
      <itunes:duration>2887</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with Kane Narraway, Head of Enterprise Security at Canva, about Zero Trust architecture.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with Kane Narraway, Head of Enterprise Security at Canva, about Zero Trust architecture.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#125 - Special Episode: The 2024 Verizon Data Breach Investigations Report</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>125</itunes:episode>
      <podcast:episode>125</podcast:episode>
      <itunes:title>#125 - Special Episode: The 2024 Verizon Data Breach Investigations Report</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a00e9809-28eb-436c-a4f5-3c76fa234f02</guid>
      <link>https://share.transistor.fm/s/8584e87b</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a close look at the 2024 Verizon Data Breach Investigations Report.</p><p>The Verizon 2024 Data Breach Investigations Report (DBIR) provides a comprehensive analysis of the current cybersecurity landscape, highlighting significant trends and emerging threats. This year's report, the 17th edition, examines 30,458 security incidents and 10,626 confirmed breaches, marking a two-fold increase from the previous year. A key finding is the dramatic surge in vulnerability exploitation, which nearly tripled, driven by attacks on unpatched systems and zero-day vulnerabilities. Ransomware and extortion continue to be major threats, comprising 32% of breaches, with a notable rise in pure extortion attacks where data is stolen but not encrypted​​.</p><p>The report also emphasizes the human element in cybersecurity breaches, with human errors contributing to 68% of incidents. Phishing remains a critical issue, with median times to click on malicious links and submit data being alarmingly short. Despite this, there is an encouraging increase in phishing awareness among users. Additionally, the report underscores the growing complexity of supply chain attacks, highlighting the vulnerabilities in third-party code and services. Interestingly, the impact of generative AI in cyberattacks remains minimal, with most uses being experimental rather than operational. The DBIR concludes with a call for improved vulnerability management and continued focus on human-centric security measures​.</p><p>You can download the <a rel="noreferrer noopener" href="https://www.verizon.com/business/resources/reports/dbir/">full report here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a close look at the 2024 Verizon Data Breach Investigations Report.</p><p>The Verizon 2024 Data Breach Investigations Report (DBIR) provides a comprehensive analysis of the current cybersecurity landscape, highlighting significant trends and emerging threats. This year's report, the 17th edition, examines 30,458 security incidents and 10,626 confirmed breaches, marking a two-fold increase from the previous year. A key finding is the dramatic surge in vulnerability exploitation, which nearly tripled, driven by attacks on unpatched systems and zero-day vulnerabilities. Ransomware and extortion continue to be major threats, comprising 32% of breaches, with a notable rise in pure extortion attacks where data is stolen but not encrypted​​.</p><p>The report also emphasizes the human element in cybersecurity breaches, with human errors contributing to 68% of incidents. Phishing remains a critical issue, with median times to click on malicious links and submit data being alarmingly short. Despite this, there is an encouraging increase in phishing awareness among users. Additionally, the report underscores the growing complexity of supply chain attacks, highlighting the vulnerabilities in third-party code and services. Interestingly, the impact of generative AI in cyberattacks remains minimal, with most uses being experimental rather than operational. The DBIR concludes with a call for improved vulnerability management and continued focus on human-centric security measures​.</p><p>You can download the <a rel="noreferrer noopener" href="https://www.verizon.com/business/resources/reports/dbir/">full report here</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 17 May 2024 22:31:07 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8584e87b/8fa52819.mp3" length="65847758" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2744</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we take a close look at the 2024 Verizon Data Breach Investigations Report.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we take a close look at the 2024 Verizon Data Breach Investigations Report.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#124 - The intersection of CTI &amp; Detection Engineering with Wade Wells, Lead Cybersecurity Threat Detection Engineer</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>124</itunes:episode>
      <podcast:episode>124</podcast:episode>
      <itunes:title>#124 - The intersection of CTI &amp; Detection Engineering with Wade Wells, Lead Cybersecurity Threat Detection Engineer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ce1d6296-af8d-4a68-a0ce-79a02b164f5c</guid>
      <link>https://share.transistor.fm/s/19938426</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the intersection of CTI &amp; Detection Engineering with Wade Wells, Lead Cybersecurity Threat Detection Engineer.</p><p>Wade Wells, a seasoned cyber security expert whose passion for technology was sparked at an early age. Growing up with a computer built from parts his dad found dumpster diving, Wade learned how to navigate MS-DOS before he could even spell 'windows'. His lifelong fascination with technology and rule-bending led him naturally into the world of cybersecurity. Today, Wade hunts for evil within networks, reveling in the continuous pursuit of knowledge and the thrill of uncovering deeper insights. Join us as we dive into his journey, explore the challenges of threat hunting, and discuss how his work contributes to a greater cause in cybersecurity.</p><p><a rel="noreferrer noopener" href="https://sublime.security/">Sublime Security: Email security that's not a black box</a></p><p><a rel="noreferrer noopener" href="https://www.salemcyber.com/">Salem Cyber: Find the alerts that actually matter</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Practical-Threat-Detection-Engineering-hands/dp/1801076715">Practical Threat Detection Engineering: A hands-on guide to planning, developing, and validating detection capabilities</a></p><p><a rel="noreferrer noopener" href="https://www.cia.gov/resources/csi/static/Pyschology-of-Intelligence-Analysis.pdf">Psychology of Intelligence Analysis</a></p><p>And the TV show <a rel="noreferrer noopener" href="https://en.wikipedia.org/wiki/Devs_(TV_series)">Devs.</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the intersection of CTI &amp; Detection Engineering with Wade Wells, Lead Cybersecurity Threat Detection Engineer.</p><p>Wade Wells, a seasoned cyber security expert whose passion for technology was sparked at an early age. Growing up with a computer built from parts his dad found dumpster diving, Wade learned how to navigate MS-DOS before he could even spell 'windows'. His lifelong fascination with technology and rule-bending led him naturally into the world of cybersecurity. Today, Wade hunts for evil within networks, reveling in the continuous pursuit of knowledge and the thrill of uncovering deeper insights. Join us as we dive into his journey, explore the challenges of threat hunting, and discuss how his work contributes to a greater cause in cybersecurity.</p><p><a rel="noreferrer noopener" href="https://sublime.security/">Sublime Security: Email security that's not a black box</a></p><p><a rel="noreferrer noopener" href="https://www.salemcyber.com/">Salem Cyber: Find the alerts that actually matter</a></p><p><a rel="noreferrer noopener" href="https://www.amazon.com/Practical-Threat-Detection-Engineering-hands/dp/1801076715">Practical Threat Detection Engineering: A hands-on guide to planning, developing, and validating detection capabilities</a></p><p><a rel="noreferrer noopener" href="https://www.cia.gov/resources/csi/static/Pyschology-of-Intelligence-Analysis.pdf">Psychology of Intelligence Analysis</a></p><p>And the TV show <a rel="noreferrer noopener" href="https://en.wikipedia.org/wiki/Devs_(TV_series)">Devs.</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 15 May 2024 14:55:42 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/19938426/e6fdffe9.mp3" length="25255947" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Zml1SMRtUvXrQ0zgnwgCfjHlD-q5OW2XSmQIzW44J3I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81YjUz/MWJmMzMwNWQ0NmUw/YjA3MjZjZDQzZWY2/Zjg2Ni5wbmc.jpg"/>
      <itunes:duration>2088</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the intersection of CTI &amp;amp; Detection Engineering with Wade Wells, Lead Cybersecurity Threat Detection Engineer.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the intersection of CTI &amp;amp; Detection Engineering with Wade Wells, Lead Cybersecurity Threat Detection Engineer.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#123 - The RSA Conference</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>124</itunes:episode>
      <podcast:episode>124</podcast:episode>
      <itunes:title>#123 - The RSA Conference</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">60c5d9c8-2f83-4d8d-a4a5-3b5e9955222f</guid>
      <link>https://share.transistor.fm/s/883499fa</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a closer look at the RSA Conference: past, present and future.</p><p>The RSA Conference is a series of IT security conferences. Approximately 45,000 people attend one of the conferences each year. It was founded in 1991 as a small cryptography conference. RSA conferences take place in the United States, Europe, Asia, and the United Arab Emirates each year. The conference also hosts educational, professional networking, and awards programs.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a closer look at the RSA Conference: past, present and future.</p><p>The RSA Conference is a series of IT security conferences. Approximately 45,000 people attend one of the conferences each year. It was founded in 1991 as a small cryptography conference. RSA conferences take place in the United States, Europe, Asia, and the United Arab Emirates each year. The conference also hosts educational, professional networking, and awards programs.</p>]]>
      </content:encoded>
      <pubDate>Sat, 11 May 2024 14:29:13 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/883499fa/aaf7edfa.mp3" length="11246504" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/5NK2aiWCJWZcDI5Q2OO6Da2gE-r9P_2lxAAKQ-pgrvc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82MjUw/MjNiMmYwNjY5MGY5/YTRiNjQ1N2MyNjEz/MTE0Zi5wbmc.jpg"/>
      <itunes:duration>921</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we take a closer look at the RSA Conference: past, present and future.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we take a closer look at the RSA Conference: past, present and future.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#122 - Platformization in cybersecurity with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>118</itunes:episode>
      <podcast:episode>118</podcast:episode>
      <itunes:title>#122 - Platformization in cybersecurity with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">80fa1f16-8995-4595-9765-9c6a9c6288c6</guid>
      <link>https://share.transistor.fm/s/1cc72584</link>
      <description>
        <![CDATA[<p>On this episode of The Cyebrsecurity Defenders Podcast, we talk platformization and the SecOps Cloud Platform with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie.</p><p>In a world where digital transformation has become the norm, cybersecurity professionals face unprecedented challenges. The traditional approach of managing dozens of disparate point solutions and siloed security tools, while attempting to control costs, is no longer sufficient.</p><p>It's time to embrace a new era of cybersecurity in the SecOps Cloud Platform – one that treats cybersecurity as a set of capabilities much like how cloud providers did for IT. We challenge you to question the status quo and to open your mind a new way of thinking about security operations.</p><p>You can get started for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cyebrsecurity Defenders Podcast, we talk platformization and the SecOps Cloud Platform with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie.</p><p>In a world where digital transformation has become the norm, cybersecurity professionals face unprecedented challenges. The traditional approach of managing dozens of disparate point solutions and siloed security tools, while attempting to control costs, is no longer sufficient.</p><p>It's time to embrace a new era of cybersecurity in the SecOps Cloud Platform – one that treats cybersecurity as a set of capabilities much like how cloud providers did for IT. We challenge you to question the status quo and to open your mind a new way of thinking about security operations.</p><p>You can get started for free at <a rel="noreferrer noopener" href="https://limacharlie.io/">limacharlie.io</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 06 May 2024 12:00:11 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1cc72584/15712f5c.mp3" length="16345230" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/YGxs29mVLhYGKEO4TmhDP9Kah9HrjCMu6Mnqny_IK0w/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81ZTQ0/ZWVjODU4N2I5MTkx/ZTRjMDE3NzMyMmFk/OTJkZC5wbmc.jpg"/>
      <itunes:duration>1346</itunes:duration>
      <itunes:summary>On this episode of The Cyebrsecurity Defenders Podcast, we talk platformization and the SecOps Cloud Platform with Maxime Lamothe-Brassard, Founder &amp;amp; CEO of LimaCharlie.</itunes:summary>
      <itunes:subtitle>On this episode of The Cyebrsecurity Defenders Podcast, we talk platformization and the SecOps Cloud Platform with Maxime Lamothe-Brassard, Founder &amp;amp; CEO of LimaCharlie.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#121 - Intel Chat: Albatross leak, Cerber ransomware, UAT4356 &amp; MITRE compromised</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>121</itunes:episode>
      <podcast:episode>121</podcast:episode>
      <itunes:title>#121 - Intel Chat: Albatross leak, Cerber ransomware, UAT4356 &amp; MITRE compromised</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9b3dd903-26eb-430f-aa69-1f8cc1fd4f70</guid>
      <link>https://share.transistor.fm/s/560e64c7</link>
      <description>
        <![CDATA[<ul><li>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</li><li>Ukrainian hackers claim to have breached the Russian drone developer Albatross, leaking 100 gigabytes of data, including internal documentation, technical data and drawings of various types of <a rel="noreferrer noopener" href="https://therecord.media/russia-albatross-drones-alleged-data-leak-ukraine-cyber-resistance">unmanned aerial vehicles</a>.</li><li>A critical vulnerability in Atlassian Confluence Data Center and Server was used to deploy a Linux variant of <a rel="noreferrer noopener" href="https://www.scmagazine.com/news/atlassian-confluence-linux-instances-targeted-with-cerber-ransomware">Cerber ransomware</a>.</li><li>Cisco Talos are actively monitoring a global increase in brute-force attacks against a variety of targets, including VPN services, <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/">web application authentication interfaces</a> and SSH services since at least March 18, 2024. </li><li>An emerging threat campaign named ArcaneDoor, orchestrated by a <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">previously unknown actor</a> identified as UAT4356, now also known as STORM-1849 by Microsoft.</li><li>The MITRE Corporation reported a significant security breach within one of its specialized networks, the Networked Experimentation, Research, and Virtualization Environment - or <a rel="noreferrer noopener" href="https://securityaffairs.com/162045/security/mitre-security-breach-ivanti-zero-days.html">NERVE</a>. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<ul><li>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</li><li>Ukrainian hackers claim to have breached the Russian drone developer Albatross, leaking 100 gigabytes of data, including internal documentation, technical data and drawings of various types of <a rel="noreferrer noopener" href="https://therecord.media/russia-albatross-drones-alleged-data-leak-ukraine-cyber-resistance">unmanned aerial vehicles</a>.</li><li>A critical vulnerability in Atlassian Confluence Data Center and Server was used to deploy a Linux variant of <a rel="noreferrer noopener" href="https://www.scmagazine.com/news/atlassian-confluence-linux-instances-targeted-with-cerber-ransomware">Cerber ransomware</a>.</li><li>Cisco Talos are actively monitoring a global increase in brute-force attacks against a variety of targets, including VPN services, <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/">web application authentication interfaces</a> and SSH services since at least March 18, 2024. </li><li>An emerging threat campaign named ArcaneDoor, orchestrated by a <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">previously unknown actor</a> identified as UAT4356, now also known as STORM-1849 by Microsoft.</li><li>The MITRE Corporation reported a significant security breach within one of its specialized networks, the Networked Experimentation, Research, and Virtualization Environment - or <a rel="noreferrer noopener" href="https://securityaffairs.com/162045/security/mitre-security-breach-ivanti-zero-days.html">NERVE</a>. </li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 01 May 2024 13:59:37 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/560e64c7/fdfbfe54.mp3" length="20731260" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Ev3ChDcpxFWfV9uurIV6tdg4Ev6t7vFNZcGf8wjKY-0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZmI2/MzgwZGI2MjEyNWRj/YWM0ZTYzODgzZTMz/NjdhZC5wbmc.jpg"/>
      <itunes:duration>1711</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#120 - Open Source Intelligence with Mishaal Khan, Cybersecurity Practice Lead at Mindsight</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>120</itunes:episode>
      <podcast:episode>120</podcast:episode>
      <itunes:title>#120 - Open Source Intelligence with Mishaal Khan, Cybersecurity Practice Lead at Mindsight</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">03f6205a-6380-4461-9327-50f03a454939</guid>
      <link>https://share.transistor.fm/s/bcde9e29</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Open Source Intelligence with Mishaal Khan, Cybersecurity Practice Lead at Mindsight.</p><p>Misshal is a jack of all trades and master of some! With a profound knack for thinking like the bad guys, Misshal harnesses his extensive knowledge—from the nitty-gritty of bits and bytes to intricate business processes. As a techie, Ethical Hacker, OSINT enthusiast, and Social Engineer, he leverages his diverse skillset to help organizations fortify their defenses and tackle real-world security challenges. </p><p>You can find out more about his book, The Phantom CISO, on his website, <a rel="noreferrer noopener" href="https://www.phantomciso.com/">here</a>.</p><p>And you can learn more about Operation Privacy <a rel="noreferrer noopener" href="https://www.operationprivacy.com/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Open Source Intelligence with Mishaal Khan, Cybersecurity Practice Lead at Mindsight.</p><p>Misshal is a jack of all trades and master of some! With a profound knack for thinking like the bad guys, Misshal harnesses his extensive knowledge—from the nitty-gritty of bits and bytes to intricate business processes. As a techie, Ethical Hacker, OSINT enthusiast, and Social Engineer, he leverages his diverse skillset to help organizations fortify their defenses and tackle real-world security challenges. </p><p>You can find out more about his book, The Phantom CISO, on his website, <a rel="noreferrer noopener" href="https://www.phantomciso.com/">here</a>.</p><p>And you can learn more about Operation Privacy <a rel="noreferrer noopener" href="https://www.operationprivacy.com/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 30 Apr 2024 12:00:10 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/bcde9e29/fa9a0241.mp3" length="28490587" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Fs83cJY47gSXpunNgR6zGRPyfrM4i3vJCNhNofGZEzc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mYmJh/NDJkOGFlMDNjMTc2/OTdhNTg5NDc5ZTk4/OWYxNC5wbmc.jpg"/>
      <itunes:duration>2358</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Open Source Intelligence with Mishaal Khan, Cybersecurity Practice Lead at Mindsight.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Open Source Intelligence with Mishaal Khan, Cybersecurity Practice Lead at Mindsight.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#119 - Special Episode: Sandworm is promoted to APT44</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>119</itunes:episode>
      <podcast:episode>119</podcast:episode>
      <itunes:title>#119 - Special Episode: Sandworm is promoted to APT44</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">55157407-ef9c-4cc7-8864-3f04e4ec39dd</guid>
      <link>https://share.transistor.fm/s/45b01fc9</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss the GRU-backed cyber unit Sandworm which was <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm">recently promoted to APT44 by Mandiant</a>.</p><p>Sandworm is a notorious hacking group, believed to be linked to Russia's military intelligence agency, the GRU. Known for its destructive cyberattacks, Sandworm has targeted various sectors worldwide, including energy, media, and election systems. Their activities are marked by the use of sophisticated malware and tactics that not only seek to steal information but also to disrupt critical infrastructure. The group gained international prominence with attacks like NotPetya in 2017, which caused billions of dollars in damage across multiple countries, emphasizing their capability to impact global cyber stability.</p><p>The name "Sandworm" is inspired by the monstrous creatures from Frank Herbert's science fiction novel "Dune," reflecting the group's elusive and destructive nature. Over the years, Sandworm's operations have evolved, showcasing their adaptability and the increasing complexity of their attacks. This evolution highlights the growing challenges in cybersecurity, making the understanding of such threat actors crucial for developing robust defense strategies against state-sponsored cyber warfare.</p><p>YouTube video showing Sandworm attacking a Ukrainian power plant <a rel="noreferrer noopener" href="https://www.youtube.com/watch?v=bV47gBsrDkc">here</a>.</p><p>Episode #56 - <a rel="noreferrer noopener" href="https://open.spotify.com/episode/6VdSqCsLrnHuVVTvZJ6XEJ?si=QstKefwxS5CM_U1oYN4jEA">When the lights went out in Ukraine (Part 1)</a></p><p>Episode #74 - <a rel="noreferrer noopener" href="https://open.spotify.com/episode/3HhRwHN35d1AEG2bxceVpJ?si=QQG7G3GnTfCZbvXvTsmlXQ">When the lights went out in Ukraine (Part 2)</a></p><p>Episode #16 - <a rel="noreferrer noopener" href="https://open.spotify.com/episode/6nUJgYJBbUBhvNbi7uN4ro?si=s6e6VLA5Sqeu23l7BC_vPA">NotPetya</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss the GRU-backed cyber unit Sandworm which was <a rel="noreferrer noopener" href="https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm">recently promoted to APT44 by Mandiant</a>.</p><p>Sandworm is a notorious hacking group, believed to be linked to Russia's military intelligence agency, the GRU. Known for its destructive cyberattacks, Sandworm has targeted various sectors worldwide, including energy, media, and election systems. Their activities are marked by the use of sophisticated malware and tactics that not only seek to steal information but also to disrupt critical infrastructure. The group gained international prominence with attacks like NotPetya in 2017, which caused billions of dollars in damage across multiple countries, emphasizing their capability to impact global cyber stability.</p><p>The name "Sandworm" is inspired by the monstrous creatures from Frank Herbert's science fiction novel "Dune," reflecting the group's elusive and destructive nature. Over the years, Sandworm's operations have evolved, showcasing their adaptability and the increasing complexity of their attacks. This evolution highlights the growing challenges in cybersecurity, making the understanding of such threat actors crucial for developing robust defense strategies against state-sponsored cyber warfare.</p><p>YouTube video showing Sandworm attacking a Ukrainian power plant <a rel="noreferrer noopener" href="https://www.youtube.com/watch?v=bV47gBsrDkc">here</a>.</p><p>Episode #56 - <a rel="noreferrer noopener" href="https://open.spotify.com/episode/6VdSqCsLrnHuVVTvZJ6XEJ?si=QstKefwxS5CM_U1oYN4jEA">When the lights went out in Ukraine (Part 1)</a></p><p>Episode #74 - <a rel="noreferrer noopener" href="https://open.spotify.com/episode/3HhRwHN35d1AEG2bxceVpJ?si=QQG7G3GnTfCZbvXvTsmlXQ">When the lights went out in Ukraine (Part 2)</a></p><p>Episode #16 - <a rel="noreferrer noopener" href="https://open.spotify.com/episode/6nUJgYJBbUBhvNbi7uN4ro?si=s6e6VLA5Sqeu23l7BC_vPA">NotPetya</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 25 Apr 2024 14:18:39 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/45b01fc9/a55b8ad3.mp3" length="55616198" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2318</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss the GRU-backed cyber unit Sandworm which was recently promoted to APT44 by Mandiant.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss the GRU-backed cyber unit Sandworm which was recently promoted to APT44 by Mandiant.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#118 - Intel Chat: FakeBat, Sisense, APT29 &amp; CVE of 10</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>118</itunes:episode>
      <podcast:episode>118</podcast:episode>
      <itunes:title>#118 - Intel Chat: FakeBat, Sisense, APT29 &amp; CVE of 10</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8453ac57-8b85-4efe-b27e-ff2d800fd0a2</guid>
      <link>https://share.transistor.fm/s/c254e770</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</p><ul><li>eSentire's Threat Response Unit has observed FakeBat loader being distributed via FakeUpdates, ultimately leading to a LummaC2 infection via a custom-written PaykRunPE provided by the <a rel="noreferrer noopener" href="https://www.malwarebytes.com/blog/threat-intelligence/2024/03/fakebat-delivered-via-several-active-malvertising-campaigns">FakeBat Threat Actors</a>.</li><li>CISA is investigating a breach at business intelligence company Sisense and urged all Sisense customers to reset any credentials and secrets that may have been <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/04/why-cisa-is-warning-cisos-about-a-breach-at-sisense/">shared with the company</a>.</li><li>CISA has confirmed that Russian government-backed hackers stole emails from several U.S. federal agencies as a result of an ongoing <a rel="noreferrer noopener" href="https://techcrunch.com/2024/04/11/us-cisa-russia-apt-29-government-email-theft-microsoft/">cyberattack at Microsoft.</a></li><li>Volexity identified a zero-day exploitation of a vulnerability found within the GlobalProtect feature of Palo Alto Networks PAN-OS at one of its network <a rel="noreferrer noopener" href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/">security monitoring customers</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</p><ul><li>eSentire's Threat Response Unit has observed FakeBat loader being distributed via FakeUpdates, ultimately leading to a LummaC2 infection via a custom-written PaykRunPE provided by the <a rel="noreferrer noopener" href="https://www.malwarebytes.com/blog/threat-intelligence/2024/03/fakebat-delivered-via-several-active-malvertising-campaigns">FakeBat Threat Actors</a>.</li><li>CISA is investigating a breach at business intelligence company Sisense and urged all Sisense customers to reset any credentials and secrets that may have been <a rel="noreferrer noopener" href="https://krebsonsecurity.com/2024/04/why-cisa-is-warning-cisos-about-a-breach-at-sisense/">shared with the company</a>.</li><li>CISA has confirmed that Russian government-backed hackers stole emails from several U.S. federal agencies as a result of an ongoing <a rel="noreferrer noopener" href="https://techcrunch.com/2024/04/11/us-cisa-russia-apt-29-government-email-theft-microsoft/">cyberattack at Microsoft.</a></li><li>Volexity identified a zero-day exploitation of a vulnerability found within the GlobalProtect feature of Palo Alto Networks PAN-OS at one of its network <a rel="noreferrer noopener" href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/">security monitoring customers</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 18 Apr 2024 12:30:07 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c254e770/91587c2d.mp3" length="28572015" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/yt3ABKZGJSc53jepOzU1yGFSL3JNi_chnHH7cUvp_3I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82NDVk/YzNmMWQzZmI5ZGRi/ZmIzM2U2ZjJkY2U2/YTYzOC5wbmc.jpg"/>
      <itunes:duration>2365</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#117 - Digital Forensics with Carlos Cajigas, CTO at Covert Bit</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>117</itunes:episode>
      <podcast:episode>117</podcast:episode>
      <itunes:title>#117 - Digital Forensics with Carlos Cajigas, CTO at Covert Bit</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1278f818-fafe-40bf-afb9-88d6608e2057</guid>
      <link>https://share.transistor.fm/s/d10026fe</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Digital Forensics with Carlos Cajigas, CTO of Covert Bit.</p><p>Carlos is a seasoned Incident Response professional hailing from San Juan, Puerto Rico. Carlos's journey in the field began after dedicating over a decade to law enforcement, specializing as a Digital Forensics Detective and Examiner in West Palm Beach, Florida. His extensive experience spans conducting detailed examinations on numerous digital devices, backed by hundreds of hours in specialized training from reputable institutions like EnCase, NW3C, Access Data, and SANS, to name a few. Carlos is not just an expert in the field; he's also a dedicated educator, holding instructor roles with both the Florida Department of Law Enforcement and SANS, where he teaches courses on Windows Forensic Analysis and Advanced Incident Response. With a solid academic foundation, Carlos brings a wealth of knowledge and insight into today's digital forensics and incident response landscape.</p><p>You can find Carlos on Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/Carlos_Cajigas">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Digital Forensics with Carlos Cajigas, CTO of Covert Bit.</p><p>Carlos is a seasoned Incident Response professional hailing from San Juan, Puerto Rico. Carlos's journey in the field began after dedicating over a decade to law enforcement, specializing as a Digital Forensics Detective and Examiner in West Palm Beach, Florida. His extensive experience spans conducting detailed examinations on numerous digital devices, backed by hundreds of hours in specialized training from reputable institutions like EnCase, NW3C, Access Data, and SANS, to name a few. Carlos is not just an expert in the field; he's also a dedicated educator, holding instructor roles with both the Florida Department of Law Enforcement and SANS, where he teaches courses on Windows Forensic Analysis and Advanced Incident Response. With a solid academic foundation, Carlos brings a wealth of knowledge and insight into today's digital forensics and incident response landscape.</p><p>You can find Carlos on Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/Carlos_Cajigas">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 16 Apr 2024 13:32:39 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d10026fe/f0bd7112.mp3" length="27933496" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/UnhHO7kmkjyZyi1XZyLny57WnnQgyIYkdY1EmlHKEqE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NDNm/OTgyMzA0MjUzMmQz/OTgxYjM5MTM1Yjg1/OTYwZS5wbmc.jpg"/>
      <itunes:duration>2312</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Digital Forensics with Carlos Cajigas, CTO of Covert Bit.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we take a close look at Digital Forensics with Carlos Cajigas, CTO of Covert Bit.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#116 - Intel Chat: XZ Utils</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>116</itunes:episode>
      <podcast:episode>116</podcast:episode>
      <itunes:title>#116 - Intel Chat: XZ Utils</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">010db9e8-8cfe-4974-b620-25522d48c829</guid>
      <link>https://share.transistor.fm/s/563a905c</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><p>On March 29, 2024 defenders became aware that  a backdoor was intentionally planted inside of XZ Utils an open source data compression utility available on many installations of Linux and other Unix-like operating systems. The threat actors behind this implant likely spent years on this operation and were very close to getting the backdoor merged into Debian and Redhat before it was discovered.</p><p>The original disclosure email can be found <a rel="noreferrer noopener" href="https://www.openwall.com/lists/oss-security/2024/03/29/4">here</a>.</p><p>A technical break down of the compromise can be found <a rel="noreferrer noopener" href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27">here</a>.</p><p>A Wired article covering the compromise in-depth can be found <a rel="noreferrer noopener" href="https://www.wired.com/story/xz-backdoor-everything-you-need-to-know/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><p>On March 29, 2024 defenders became aware that  a backdoor was intentionally planted inside of XZ Utils an open source data compression utility available on many installations of Linux and other Unix-like operating systems. The threat actors behind this implant likely spent years on this operation and were very close to getting the backdoor merged into Debian and Redhat before it was discovered.</p><p>The original disclosure email can be found <a rel="noreferrer noopener" href="https://www.openwall.com/lists/oss-security/2024/03/29/4">here</a>.</p><p>A technical break down of the compromise can be found <a rel="noreferrer noopener" href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27">here</a>.</p><p>A Wired article covering the compromise in-depth can be found <a rel="noreferrer noopener" href="https://www.wired.com/story/xz-backdoor-everything-you-need-to-know/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 04 Apr 2024 07:05:35 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/563a905c/1bec150b.mp3" length="29128067" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/rNGcdFop6E68YtshtDVVoOL9TJyPI551YJhmgcqruwY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iNDNl/ZGIyZTcyZTY5ZjA5/NDc1OGU0MjQ4NjQy/Zjg4NC5wbmc.jpg"/>
      <itunes:duration>2411</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#115 - The cyber threat from China, with Adam Kozy &amp; Daniel Velasquez</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>113</itunes:episode>
      <podcast:episode>113</podcast:episode>
      <itunes:title>#115 - The cyber threat from China, with Adam Kozy &amp; Daniel Velasquez</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c4f8dfeb-35c4-4f2a-83c0-28926a9134fc</guid>
      <link>https://share.transistor.fm/s/8f60ccf0</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast we have an in-depth talk about the cyber threat from China, with Adam Kozy and Daniel Velasquez.</p><p>Daniel started his career as a defender in the United States Marine Corps as an intelligence analyst where he served in Afghanistan - from there he went on to work with the Defense Intelligence Agency, Joint Special Operations Command and the CIA. After his service, he was a director at Mandiant and is now the Executive Vice President of <a rel="noreferrer noopener" href="https://www.op4.io/">OP[4]</a> - a company providing security for critical devices and embedded systems.</p><p>Adam began his career as an intelligence analyst working with the Federal Bureau of Investigation where he provided all-source analysis of Asia-Pacifc related cybersecurity issues. After the FBI, Adam was the principal intelligence analyst for the Asia cyber team at CrowdStrike. </p><p>Currently, he is the founder of <a rel="noreferrer noopener" href="https://sinacyber.com/">SinaCyber</a> which is a boutique consulting firm combining native Chinese language research and cyber intelligence expertise to create bespoke reports for government officials, technology firms, and financial institutions under threat from China's rampant cyber espionage campaigns.</p><p>The history of China and its people goes back to ancient times. It is a rich and beautiful culture that has given much to the world in the form of art, ideas and technology. When we talk about China or the Chinese in this podcast episode we are specifically talking about the Chinese Communist Party - or CCP - which are a group of elites offering an increasingly authoritarian world view and alternative model to Western ideals of democracy and freedom. </p><p>The Chinese people themselves are not your enemy. Current laws in China make it easy for the CCP to co-opt its citizenry for use in intelligence operations, wittingly and unwittingly. </p><p>Unnecessarily making this into a racial divide alienates the folks that can help us the most in the coming years and provides more ammunition for Beijing.</p><p>It was an incredible honor to speak with these two, and I hope you enjoy this conversation full of valuable information.</p><p>Adam's testimony before the U.S.-China Economic and Security Review Commission Hearing on, “China’s Cyber Capabilities: Warfare, Espionage, and Implications for the United States” <a rel="noreferrer noopener" href="https://www.uscc.gov/sites/default/files/2022-02/Adam_Kozy_Testimony.pdf">here.</a></p><p>The Mandiant report on APT1 can be found <a rel="noreferrer noopener" href="https://www.mandiant.com/resources/reports/apt1-exposing-one-chinas-cyber-espionage-units">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast we have an in-depth talk about the cyber threat from China, with Adam Kozy and Daniel Velasquez.</p><p>Daniel started his career as a defender in the United States Marine Corps as an intelligence analyst where he served in Afghanistan - from there he went on to work with the Defense Intelligence Agency, Joint Special Operations Command and the CIA. After his service, he was a director at Mandiant and is now the Executive Vice President of <a rel="noreferrer noopener" href="https://www.op4.io/">OP[4]</a> - a company providing security for critical devices and embedded systems.</p><p>Adam began his career as an intelligence analyst working with the Federal Bureau of Investigation where he provided all-source analysis of Asia-Pacifc related cybersecurity issues. After the FBI, Adam was the principal intelligence analyst for the Asia cyber team at CrowdStrike. </p><p>Currently, he is the founder of <a rel="noreferrer noopener" href="https://sinacyber.com/">SinaCyber</a> which is a boutique consulting firm combining native Chinese language research and cyber intelligence expertise to create bespoke reports for government officials, technology firms, and financial institutions under threat from China's rampant cyber espionage campaigns.</p><p>The history of China and its people goes back to ancient times. It is a rich and beautiful culture that has given much to the world in the form of art, ideas and technology. When we talk about China or the Chinese in this podcast episode we are specifically talking about the Chinese Communist Party - or CCP - which are a group of elites offering an increasingly authoritarian world view and alternative model to Western ideals of democracy and freedom. </p><p>The Chinese people themselves are not your enemy. Current laws in China make it easy for the CCP to co-opt its citizenry for use in intelligence operations, wittingly and unwittingly. </p><p>Unnecessarily making this into a racial divide alienates the folks that can help us the most in the coming years and provides more ammunition for Beijing.</p><p>It was an incredible honor to speak with these two, and I hope you enjoy this conversation full of valuable information.</p><p>Adam's testimony before the U.S.-China Economic and Security Review Commission Hearing on, “China’s Cyber Capabilities: Warfare, Espionage, and Implications for the United States” <a rel="noreferrer noopener" href="https://www.uscc.gov/sites/default/files/2022-02/Adam_Kozy_Testimony.pdf">here.</a></p><p>The Mandiant report on APT1 can be found <a rel="noreferrer noopener" href="https://www.mandiant.com/resources/reports/apt1-exposing-one-chinas-cyber-espionage-units">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 03 Apr 2024 07:01:06 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8f60ccf0/82aeeb83.mp3" length="45177783" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/6Ybszm49aMgEinKLxljcKYv-UsdrELYSLAyLYPJs5eU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mZWIz/ZTAwNmRjMGMwNDA0/ZWVjYThjNGMwMjQ5/MjYxNC5wbmc.jpg"/>
      <itunes:duration>3749</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast we have an in-depth talk about the cyber threat from China, with Adam Kozy and Daniel Velasquez.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast we have an in-depth talk about the cyber threat from China, with Adam Kozy and Daniel Velasquez.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#114 - The tokenization process of payment systems with Salvador Mendoza, Director of Research and Development at Metabase Q</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>114</itunes:episode>
      <podcast:episode>114</podcast:episode>
      <itunes:title>#114 - The tokenization process of payment systems with Salvador Mendoza, Director of Research and Development at Metabase Q</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9a3b4c74-7808-4f36-9aa2-bc68282161d5</guid>
      <link>https://share.transistor.fm/s/e529ae79</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast we speak with Salvador Mendoza, Director of Research and Development at Metabase Q, about the tokenization of payment systems.</p><p>Salvador is a prominent figure in the cybersecurity industry and holds the position of Director of Research and Development at Metabase Q. He is also an integral member of the Ocelot Offensive Security Team. His area of expertise lies in the intricate world of the tokenization process, payment systems, and the development of embedded prototypes. With a commendable history of presenting at high-profile security conferences including Black Hat, DEF CON, Hack in the Box, and Troopers, Salvador brings a wealth of knowledge and insight to our discussion. Furthermore, he is the author of the insightful book, "Show me the e-money. Hacking digital payment systems: NFC, RFID, MST and EMV Chips," where he delves into the vulnerabilities and security measures of digital payment technologies.</p><p>You can find his book for purchase <a rel="noreferrer noopener" href="https://0xword.com/es/libros/161-show-me-the-e-money-hacking-a-sistemas-de-pagos-digitales-nfc-rfid-mst-y-chips-emv.html">here</a>.</p><p>And you can find the PCI spec <a rel="noreferrer noopener" href="https://listings.pcisecuritystandards.org/documents/PCI_DSS-QRG-v3_2_1.pdf">here</a>.</p><p>You can follow Salvaador on Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/netxing?lang=en">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast we speak with Salvador Mendoza, Director of Research and Development at Metabase Q, about the tokenization of payment systems.</p><p>Salvador is a prominent figure in the cybersecurity industry and holds the position of Director of Research and Development at Metabase Q. He is also an integral member of the Ocelot Offensive Security Team. His area of expertise lies in the intricate world of the tokenization process, payment systems, and the development of embedded prototypes. With a commendable history of presenting at high-profile security conferences including Black Hat, DEF CON, Hack in the Box, and Troopers, Salvador brings a wealth of knowledge and insight to our discussion. Furthermore, he is the author of the insightful book, "Show me the e-money. Hacking digital payment systems: NFC, RFID, MST and EMV Chips," where he delves into the vulnerabilities and security measures of digital payment technologies.</p><p>You can find his book for purchase <a rel="noreferrer noopener" href="https://0xword.com/es/libros/161-show-me-the-e-money-hacking-a-sistemas-de-pagos-digitales-nfc-rfid-mst-y-chips-emv.html">here</a>.</p><p>And you can find the PCI spec <a rel="noreferrer noopener" href="https://listings.pcisecuritystandards.org/documents/PCI_DSS-QRG-v3_2_1.pdf">here</a>.</p><p>You can follow Salvaador on Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/netxing?lang=en">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 29 Mar 2024 19:26:25 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e529ae79/257acfa7.mp3" length="20150184" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/F0f5YH1m0T9aHXJVWI5TIiAYxy2QRLhVWr1jIqCg94Q/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jNzA3/NGI3MDNiN2EzODA5/YzkzY2QyZWU2NDFj/MDAzNi5wbmc.jpg"/>
      <itunes:duration>1663</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast we speak with Salvador Mendoza, Director of Research and Development at Metabase Q, about the tokenization of payment systems.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast we speak with Salvador Mendoza, Director of Research and Development at Metabase Q, about the tokenization of payment systems.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#113 - Intel Chat: StrelaStealer, APT29, Apple's M-series &amp; APT31</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>113</itunes:episode>
      <podcast:episode>113</podcast:episode>
      <itunes:title>#113 - Intel Chat: StrelaStealer, APT29, Apple's M-series &amp; APT31</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">67b72e7f-7c14-4a09-a0e8-f8f7792a0fb8</guid>
      <link>https://share.transistor.fm/s/4fe6f8e0</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Unit 42 have recently identified a wave of large-scale StrelaStealer campaigns impacting over 100 organizations <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/strelastealer-campaign/">across the EU and U.S</a>.</li><li>Researchers at Mandiant on Friday raised an alarm after discovering Russia’s APT29 hacking group targeting political parties in Germany, indicating a possible <a rel="noreferrer noopener" href="https://www.securityweek.com/russian-apt29-hackers-caught-targeting-german-political-parties/">new operational focus</a> beyond typical attacks on diplomatic figures.</li><li>The newly discovered vulnerability baked into Apple’s M-series of chips that allows attackers to extract secret keys from Macs when they perform <a rel="noreferrer noopener" href="https://mashable.com/article/apple-silicon-m-series-chip-vulnerability-hackers-encryption-keys">widely used cryptographic operations</a>.</li><li>The Department of Justice this week charged seven Chinese nationals, who are <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/chinese-state-hackers-slapped-with-us-charges-sanctions">affiliates of threat group APT31</a>, with widespread cyber espionage against US businesses and politicians.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Unit 42 have recently identified a wave of large-scale StrelaStealer campaigns impacting over 100 organizations <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/strelastealer-campaign/">across the EU and U.S</a>.</li><li>Researchers at Mandiant on Friday raised an alarm after discovering Russia’s APT29 hacking group targeting political parties in Germany, indicating a possible <a rel="noreferrer noopener" href="https://www.securityweek.com/russian-apt29-hackers-caught-targeting-german-political-parties/">new operational focus</a> beyond typical attacks on diplomatic figures.</li><li>The newly discovered vulnerability baked into Apple’s M-series of chips that allows attackers to extract secret keys from Macs when they perform <a rel="noreferrer noopener" href="https://mashable.com/article/apple-silicon-m-series-chip-vulnerability-hackers-encryption-keys">widely used cryptographic operations</a>.</li><li>The Department of Justice this week charged seven Chinese nationals, who are <a rel="noreferrer noopener" href="https://www.darkreading.com/cyber-risk/chinese-state-hackers-slapped-with-us-charges-sanctions">affiliates of threat group APT31</a>, with widespread cyber espionage against US businesses and politicians.</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 27 Mar 2024 19:27:11 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4fe6f8e0/de20c306.mp3" length="32743385" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/mwC9dSn-7S7YCRvh6ebdMgYx_zp1LHuRGkF3gJjPbe0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yN2Zm/OGQ4YmRmNjFhOTA2/OGE2ZTc3ZGI2Y2Nk/MjkwNy5wbmc.jpg"/>
      <itunes:duration>2713</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#112 - Cyber Threat Intelligence Networking with Grace Chi, CoFounder &amp; COO of Pulsedive Cyber Threat Intelligence</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>112</itunes:episode>
      <podcast:episode>112</podcast:episode>
      <itunes:title>#112 - Cyber Threat Intelligence Networking with Grace Chi, CoFounder &amp; COO of Pulsedive Cyber Threat Intelligence</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">14e2d19b-f847-42da-95a4-b00d8ad0a551</guid>
      <link>https://share.transistor.fm/s/61d788d4</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast we speak with Grace Chi, CoFounder &amp; COO of <a rel="noreferrer noopener" href="https://pulsedive.com/">Pulsedive Cyber Threat Intelligence</a> about a report she published on cyber threat intelligence networking.</p><p>Cyber Threat Intelligence (CTI) is an evolving field, with an industry-wide consensus that teams cannot effectively operate in an intelligence silo. This sentiment is shared across all stakeholder segments – public, private, vendor, and academic. In support of improved CTI sharing, stakeholders have invested in efforts around cross-boundary collaboration, technical standardization, managing trust, and reporting best practices. However, understanding the time and effort spent in CTI networking (i.e. connecting human-to-human for improved business outcomes) is often overlooked.</p><p>The report can be found here: <a rel="noreferrer noopener" href="https://blog.pulsedive.com/cti-networking-2024/">Sharing, Compared: A Study on the Changing Landscape of CTI Networking</a></p><p>The Op Ed mentioned in the show: <a rel="noreferrer noopener" href="https://blog.pulsedive.com/op-ed-stix/">Op-Ed: How tro Make STIX Stickie</a></p><p>And the subreddit mention on the show (possibly NSFW): <a rel="noreferrer noopener" href="https://www.reddit.com/r/LinkedInLunatics/">LinkedIn Lunatics</a></p><p>Pulsedive can be found on Twitter <a rel="noreferrer noopener" href="https://twitter.com/pulsedive">here</a>.</p><p>Grace can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/graceschi/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast we speak with Grace Chi, CoFounder &amp; COO of <a rel="noreferrer noopener" href="https://pulsedive.com/">Pulsedive Cyber Threat Intelligence</a> about a report she published on cyber threat intelligence networking.</p><p>Cyber Threat Intelligence (CTI) is an evolving field, with an industry-wide consensus that teams cannot effectively operate in an intelligence silo. This sentiment is shared across all stakeholder segments – public, private, vendor, and academic. In support of improved CTI sharing, stakeholders have invested in efforts around cross-boundary collaboration, technical standardization, managing trust, and reporting best practices. However, understanding the time and effort spent in CTI networking (i.e. connecting human-to-human for improved business outcomes) is often overlooked.</p><p>The report can be found here: <a rel="noreferrer noopener" href="https://blog.pulsedive.com/cti-networking-2024/">Sharing, Compared: A Study on the Changing Landscape of CTI Networking</a></p><p>The Op Ed mentioned in the show: <a rel="noreferrer noopener" href="https://blog.pulsedive.com/op-ed-stix/">Op-Ed: How tro Make STIX Stickie</a></p><p>And the subreddit mention on the show (possibly NSFW): <a rel="noreferrer noopener" href="https://www.reddit.com/r/LinkedInLunatics/">LinkedIn Lunatics</a></p><p>Pulsedive can be found on Twitter <a rel="noreferrer noopener" href="https://twitter.com/pulsedive">here</a>.</p><p>Grace can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/graceschi/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 22 Mar 2024 13:29:14 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/61d788d4/2837dde4.mp3" length="20466141" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tmaC7l1dNpFbQjHFOyF9T19Ev3NdNhSfkivpxI5bRzI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xODYz/NTc1NTg3MGNiZGI5/MjU1ZDRkOTJmZmE1/ODMxNy5wbmc.jpg"/>
      <itunes:duration>1690</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast we speak with Grace Chi, CoFounder &amp;amp; COO of Pulsedive Cyber Threat Intelligence about a report she published on cyber threat intelligence networking.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast we speak with Grace Chi, CoFounder &amp;amp; COO of Pulsedive Cyber Threat Intelligence about a report she published on cyber threat intelligence networking.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#111 - Intel Chat: Magnet Goblin, StopCrypt ransomware, aiohttp &amp; Midnight Blizzard</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>111</itunes:episode>
      <podcast:episode>111</podcast:episode>
      <itunes:title>#111 - Intel Chat: Magnet Goblin, StopCrypt ransomware, aiohttp &amp; Midnight Blizzard</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">45a36c49-5bfe-4ac5-8fec-d0376fedfdbb</guid>
      <link>https://share.transistor.fm/s/5c209c60</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><p>Threat actors have been actively targeting vulnerable Connect Secure VPN appliances after the disclosure of <a rel="noreferrer noopener" href="https://research.checkpoint.com/2024/magnet-goblin-targets-publicly-facing-servers-using-1-day-vulnerabilities/">CVE-2023-46805 and CVE-2023-21887</a>.</p><p>Threat researchers recently observed an interesting variant of <a rel="noreferrer noopener" href="https://blog.sonicwall.com/en-us/2024/03/new-multi-stage-stopcrypt-ransomware/">StopCrypt ransomware</a>. The ransomware executes its malicious activities by utilizing multi-stage shellcodes before launching a final payload that contains the file encryption code.</p><p>In the last week of January 2024, a patch was released to address a directory traversal vulnerability in the package that allows unauthenticated, remote attackers to access sensitive information from arbitrary <a rel="noreferrer noopener" href="https://cyble.com/blog/cgsi-probes-shadowsyndicate-groups-possible-exploitation-of-aiohttp-vulnerability-cve-2024-23334/">files on the server if exploited</a>. </p><p>On March 8th, Microsoft said that it’s still trying to evict the elite Russian government hackers who broke into the email accounts of senior company executives in November and who it said have been trying to breach customer <a rel="noreferrer noopener" href="https://www.msspalert.com/news/microsoft-admits-source-code-stolen-in-midnight-blizzard-email-attacks?nbd=bNTMO4gBmHFjV-KUeLre&amp;nbd_source=mrkto&amp;mkt_tok=MTg4LVVOWi02NjAAAAGR3HQa_YT-5Xyn9LKzhwsxKLdrPPRhM-6L7R-KTrHzbVPkqWpZUa9Igj7Rzj3Z8z4kJXXW4-To2pdtGVxCyvWDYwro9VjTW3PHAFVW_gnrEjFT">networks with stolen access data</a>. </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><p>Threat actors have been actively targeting vulnerable Connect Secure VPN appliances after the disclosure of <a rel="noreferrer noopener" href="https://research.checkpoint.com/2024/magnet-goblin-targets-publicly-facing-servers-using-1-day-vulnerabilities/">CVE-2023-46805 and CVE-2023-21887</a>.</p><p>Threat researchers recently observed an interesting variant of <a rel="noreferrer noopener" href="https://blog.sonicwall.com/en-us/2024/03/new-multi-stage-stopcrypt-ransomware/">StopCrypt ransomware</a>. The ransomware executes its malicious activities by utilizing multi-stage shellcodes before launching a final payload that contains the file encryption code.</p><p>In the last week of January 2024, a patch was released to address a directory traversal vulnerability in the package that allows unauthenticated, remote attackers to access sensitive information from arbitrary <a rel="noreferrer noopener" href="https://cyble.com/blog/cgsi-probes-shadowsyndicate-groups-possible-exploitation-of-aiohttp-vulnerability-cve-2024-23334/">files on the server if exploited</a>. </p><p>On March 8th, Microsoft said that it’s still trying to evict the elite Russian government hackers who broke into the email accounts of senior company executives in November and who it said have been trying to breach customer <a rel="noreferrer noopener" href="https://www.msspalert.com/news/microsoft-admits-source-code-stolen-in-midnight-blizzard-email-attacks?nbd=bNTMO4gBmHFjV-KUeLre&amp;nbd_source=mrkto&amp;mkt_tok=MTg4LVVOWi02NjAAAAGR3HQa_YT-5Xyn9LKzhwsxKLdrPPRhM-6L7R-KTrHzbVPkqWpZUa9Igj7Rzj3Z8z4kJXXW4-To2pdtGVxCyvWDYwro9VjTW3PHAFVW_gnrEjFT">networks with stolen access data</a>. </p>]]>
      </content:encoded>
      <pubDate>Wed, 20 Mar 2024 06:30:09 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5c209c60/81323f71.mp3" length="23281975" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/oWXuNKLEM6HZBBCtzwARlD_q5tV8YpFXorNDYpeuvkw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMTY2/YTFkYTM4MmJjMzI4/NTVjNWQ1YWI0Yzk0/MWEzOS5wbmc.jpg"/>
      <itunes:duration>1924</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#110 - Intel Chat: Lazarus Group, tunnelling with QEMU, ScreenConnect &amp; CISA breach</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>110</itunes:episode>
      <podcast:episode>110</podcast:episode>
      <itunes:title>#110 - Intel Chat: Lazarus Group, tunnelling with QEMU, ScreenConnect &amp; CISA breach</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f60418bf-236f-4510-bf29-6199de55af9f</guid>
      <link>https://share.transistor.fm/s/965792fa</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>North Korean threat actors known as the Lazarus Group exploited a zero-day in the Windows AppLocker driver to gain kernel-level access and turn off security tools, allowing them to bypass noisy <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-gain-kernel-privileges/">Bring Your Own Vulnerable Driver</a> techniques.</li><li>Researchers observed threat actors run the Angry IP Scanner, followed by some Mimikatz functions, and then the kicker, the open-source <a rel="noreferrer noopener" href="https://securelist.com/network-tunneling-with-qemu/111803/">QEMU hardware emulator and virtualizer</a>.</li><li>Threat actors have been observed installing RMM tools as a means of maintaining persistence within a <a rel="noreferrer noopener" href="https://www.huntress.com/blog/insights-rmm-tools">compromised organization</a>. </li><li>Hackers breached some of the systems belonging to CISA in February through some known vulnerabilities in <a rel="noreferrer noopener" href="https://therecord.media/cisa-takes-two-systems-offline-following-ivanti-compromise">Ivanti products</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>North Korean threat actors known as the Lazarus Group exploited a zero-day in the Windows AppLocker driver to gain kernel-level access and turn off security tools, allowing them to bypass noisy <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-gain-kernel-privileges/">Bring Your Own Vulnerable Driver</a> techniques.</li><li>Researchers observed threat actors run the Angry IP Scanner, followed by some Mimikatz functions, and then the kicker, the open-source <a rel="noreferrer noopener" href="https://securelist.com/network-tunneling-with-qemu/111803/">QEMU hardware emulator and virtualizer</a>.</li><li>Threat actors have been observed installing RMM tools as a means of maintaining persistence within a <a rel="noreferrer noopener" href="https://www.huntress.com/blog/insights-rmm-tools">compromised organization</a>. </li><li>Hackers breached some of the systems belonging to CISA in February through some known vulnerabilities in <a rel="noreferrer noopener" href="https://therecord.media/cisa-takes-two-systems-offline-following-ivanti-compromise">Ivanti products</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 15 Mar 2024 12:53:34 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/965792fa/be146de0.mp3" length="25189122" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/jaZge18HBGgpL3jyZkq5w3dtQYNwy9G_NDubEQ3jJ0c/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82NDA1/YjNhYWJmNjZhYzJk/M2VmYWY3MGUwNjdh/MGZhOS5wbmc.jpg"/>
      <itunes:duration>2083</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#109 - Hacker History: The MOVEit cyberattack</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>109</itunes:episode>
      <podcast:episode>109</podcast:episode>
      <itunes:title>#109 - Hacker History: The MOVEit cyberattack</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4ff209a0-8f3b-4bb5-bac8-21b5116855fd</guid>
      <link>https://share.transistor.fm/s/d5b81b25</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of <a rel="noreferrer noopener" href="https://www.linkedin.com/in/johnhammond010/">John Hammond</a>, Principal Security Researcher at <a rel="noreferrer noopener" href="https://www.linkedin.com/company/huntress-labs/">Huntress</a>, tell the story of the MOVEit cyberattack: the biggest data theft of 2023.</p><p>The MOVEit cyberbreach, was a far-reaching cyber attack that unfolded with significant implications worldwide. The breach initially came to light on June 3, when the Government of Nova Scotia disclosed that approximately 100,000 of its current and former employees had been affected, signaling the severity of the breach's impact.</p><p>The scope of the breach widened on June 5, as it became apparent that numerous organizations in the United Kingdom had also fallen victim. Among those affected were prominent entities such as the BBC, British Airways, Boots, Aer Lingus, and the payroll service provider Zellis. This phase of the breach underscored its indiscriminate nature, with targets spanning across various sectors.</p><p>Further developments were reported on June 12, with major organizations like Ernst &amp; Young, Transport for London, and Ofcom announcing their entanglement in the breach. Of particular concern was Ofcom's revelation that personal and confidential information had been compromised, highlighting the breach's capacity to infiltrate and extract sensitive data.</p><p>The United States felt the breach's ramifications by June 15, with reports confirming that the Department of Energy, among other federal entities, was impacted by the MOVEit vulnerability. The breach's reach extended further on June 16, affecting state-level organizations such as the Louisiana Office of Motor Vehicles and Oregon Driver and Motor Vehicle Services, thereby impacting millions of American residents.</p><p>By October 25, 2023, a report from the cybersecurity firm Emsisoft indicated that the MOVEit cyberbreach had affected over 2,500 organizations globally, with a significant 80% of these being based in the United States. This breach highlights the critical vulnerabilities within digital infrastructures and underscores the urgent need for enhanced security measures to protect against such widespread cyber threats.</p><p>This story was written by the talented <a rel="noreferrer noopener" href="https://www.linkedin.com/in/nate-nelson-75589611b/">Nathaniel Nelson</a> and produced by the team at LimaCharlie.</p><p>And a special thank you to John Hammond, Principal Security researcher at Huntress, for sharing his expertise and experience</p><p>If you have any feedback or ideas for future topics or guests, please send an email to defenders@limacharlie.io.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of <a rel="noreferrer noopener" href="https://www.linkedin.com/in/johnhammond010/">John Hammond</a>, Principal Security Researcher at <a rel="noreferrer noopener" href="https://www.linkedin.com/company/huntress-labs/">Huntress</a>, tell the story of the MOVEit cyberattack: the biggest data theft of 2023.</p><p>The MOVEit cyberbreach, was a far-reaching cyber attack that unfolded with significant implications worldwide. The breach initially came to light on June 3, when the Government of Nova Scotia disclosed that approximately 100,000 of its current and former employees had been affected, signaling the severity of the breach's impact.</p><p>The scope of the breach widened on June 5, as it became apparent that numerous organizations in the United Kingdom had also fallen victim. Among those affected were prominent entities such as the BBC, British Airways, Boots, Aer Lingus, and the payroll service provider Zellis. This phase of the breach underscored its indiscriminate nature, with targets spanning across various sectors.</p><p>Further developments were reported on June 12, with major organizations like Ernst &amp; Young, Transport for London, and Ofcom announcing their entanglement in the breach. Of particular concern was Ofcom's revelation that personal and confidential information had been compromised, highlighting the breach's capacity to infiltrate and extract sensitive data.</p><p>The United States felt the breach's ramifications by June 15, with reports confirming that the Department of Energy, among other federal entities, was impacted by the MOVEit vulnerability. The breach's reach extended further on June 16, affecting state-level organizations such as the Louisiana Office of Motor Vehicles and Oregon Driver and Motor Vehicle Services, thereby impacting millions of American residents.</p><p>By October 25, 2023, a report from the cybersecurity firm Emsisoft indicated that the MOVEit cyberbreach had affected over 2,500 organizations globally, with a significant 80% of these being based in the United States. This breach highlights the critical vulnerabilities within digital infrastructures and underscores the urgent need for enhanced security measures to protect against such widespread cyber threats.</p><p>This story was written by the talented <a rel="noreferrer noopener" href="https://www.linkedin.com/in/nate-nelson-75589611b/">Nathaniel Nelson</a> and produced by the team at LimaCharlie.</p><p>And a special thank you to John Hammond, Principal Security researcher at Huntress, for sharing his expertise and experience</p><p>If you have any feedback or ideas for future topics or guests, please send an email to defenders@limacharlie.io.</p>]]>
      </content:encoded>
      <pubDate>Wed, 13 Mar 2024 12:58:37 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d5b81b25/68dbec29.mp3" length="14070601" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/rg12uWYlSanN9uz7xc5jZTAUycYWz0SRyKAMsX-r67Y/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xZTM3/MWM4NWM4YjdjNjc3/YzRkNDAxNjVhMmE3/MThkOC5wbmc.jpg"/>
      <itunes:duration>1157</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of John Hammond, Principal Security Researcher at Huntress, tell the story of the MOVEit cyberattack: the biggest data theft of 2023.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of John Hammond, Principal Security Researcher at Huntress, tell the story of the MOVEit cyberattack: the biggest data theft of 2023.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#108 - Intel Chat: Nood RAT, GTPDOOR, Pikabot, Bifrost &amp; the Executive Order on Preventing Access to Americans</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>108</itunes:episode>
      <podcast:episode>108</podcast:episode>
      <itunes:title>#108 - Intel Chat: Nood RAT, GTPDOOR, Pikabot, Bifrost &amp; the Executive Order on Preventing Access to Americans</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fc9c44de-8458-4995-8ad1-342782074a0c</guid>
      <link>https://share.transistor.fm/s/5124e65e</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>AhnLab Security Intelligence Center published an article exploring Nood RAT. Nood RAT is a variant of Gh0st RAT that <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/62144/">works in Linux</a>.</li><li>GTPDOOR is the name of Linux-based malware that is intended to be deployed on systems in telco networks adjacent to the GRPS eXchange Network with the novel feature of communicating C2 traffic over <a rel="noreferrer noopener" href="https://doubleagent.net/telecommunications/backdoor/gtp/2024/02/27/GTPDOOR-COVERT-TELCO-BACKDOOR">GTP-C Control Plane signaling messages</a>.</li><li>Researchers reporting on Pikabot evasion techniques for Endpoint Detection and Response systems by employing an advanced technique to hide its malicious activities known as <a rel="noreferrer noopener" href="https://www.vmray.com/cyber-security-blog/why-your-edr-let-pikabot-jump-through/">“indirect system calls”</a>.</li><li>Nit 42 at Palo Alto Networks, they are reporting on a new Linux variant of Bifrost that is showcasing an <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/new-linux-variant-bifrost-malware/">innovative technique to evade detection</a>.</li><li>President Biden issued an Executive Order to protect Americans’ sensitive personal data from exploitation by <a rel="noreferrer noopener" href="https://www.whitehouse.gov/briefing-room/statements-releases/2024/02/28/fact-sheet-president-biden-issues-sweeping-executive-order-to-protect-americans-sensitive-personal-data/">countries of concern</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>AhnLab Security Intelligence Center published an article exploring Nood RAT. Nood RAT is a variant of Gh0st RAT that <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/62144/">works in Linux</a>.</li><li>GTPDOOR is the name of Linux-based malware that is intended to be deployed on systems in telco networks adjacent to the GRPS eXchange Network with the novel feature of communicating C2 traffic over <a rel="noreferrer noopener" href="https://doubleagent.net/telecommunications/backdoor/gtp/2024/02/27/GTPDOOR-COVERT-TELCO-BACKDOOR">GTP-C Control Plane signaling messages</a>.</li><li>Researchers reporting on Pikabot evasion techniques for Endpoint Detection and Response systems by employing an advanced technique to hide its malicious activities known as <a rel="noreferrer noopener" href="https://www.vmray.com/cyber-security-blog/why-your-edr-let-pikabot-jump-through/">“indirect system calls”</a>.</li><li>Nit 42 at Palo Alto Networks, they are reporting on a new Linux variant of Bifrost that is showcasing an <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/new-linux-variant-bifrost-malware/">innovative technique to evade detection</a>.</li><li>President Biden issued an Executive Order to protect Americans’ sensitive personal data from exploitation by <a rel="noreferrer noopener" href="https://www.whitehouse.gov/briefing-room/statements-releases/2024/02/28/fact-sheet-president-biden-issues-sweeping-executive-order-to-protect-americans-sensitive-personal-data/">countries of concern</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 08 Mar 2024 15:00:36 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5124e65e/cf5ddf64.mp3" length="27949901" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/08XleY1YrGPa7BPOvPmkanckX-dcjBALu5BuEeDD8ZA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kOTI3/ODE2YzIzMTVlNDJj/ZjYxZjI3YzA4ZDZl/MWNjMS5wbmc.jpg"/>
      <itunes:duration>2313</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#107 - Weaponizing ASCII escape sequences with Fredrik (STÖK) Alexandersson</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>107</itunes:episode>
      <podcast:episode>107</podcast:episode>
      <itunes:title>#107 - Weaponizing ASCII escape sequences with Fredrik (STÖK) Alexandersson</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">67fce8ff-a115-4dfe-b10c-23432bf58556</guid>
      <link>https://share.transistor.fm/s/277221c7</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at weaponizing ASCII escape sequences with Fredrik (STÖK) Alexandersson from <a rel="noreferrer noopener" href="https://www.truesec.com/">Truesec</a>.</p><p>Fredrik (STÖK) Alexandersson is a dynamic individual driven by a boundless curiosity and a passion for sharing knowledge. With over three decades of professional experience, he's hacked his way through realms ranging from computers and technology to marketing, fashion, communication, and even the human psyche. Renowned for his lightning-fast presentations and his knack for making complex technical subjects entertaining, STÖK is a prominent figure in the cybersecurity community. His meticulous attention to detail, insatiable curiosity, and "Good Vibes Only" attitude have inspired millions worldwide and earned him recognition from industry giants like Salesforce, Microsoft, and Verizon Media, among many others.  Currently, he working as a Hacker and Creative Director at TRUESEC.</p><p>You can follow him on Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/stokfredrik">here</a>.</p><p>And you can watch his talk on Weaponizing ASCII escape sequences <a rel="noreferrer noopener" href="https://www.youtube.com/watch?v=3T2Al3jdY38">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at weaponizing ASCII escape sequences with Fredrik (STÖK) Alexandersson from <a rel="noreferrer noopener" href="https://www.truesec.com/">Truesec</a>.</p><p>Fredrik (STÖK) Alexandersson is a dynamic individual driven by a boundless curiosity and a passion for sharing knowledge. With over three decades of professional experience, he's hacked his way through realms ranging from computers and technology to marketing, fashion, communication, and even the human psyche. Renowned for his lightning-fast presentations and his knack for making complex technical subjects entertaining, STÖK is a prominent figure in the cybersecurity community. His meticulous attention to detail, insatiable curiosity, and "Good Vibes Only" attitude have inspired millions worldwide and earned him recognition from industry giants like Salesforce, Microsoft, and Verizon Media, among many others.  Currently, he working as a Hacker and Creative Director at TRUESEC.</p><p>You can follow him on Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/stokfredrik">here</a>.</p><p>And you can watch his talk on Weaponizing ASCII escape sequences <a rel="noreferrer noopener" href="https://www.youtube.com/watch?v=3T2Al3jdY38">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 06 Mar 2024 17:56:54 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/277221c7/22f84d5d.mp3" length="18241998" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/RqPTtYDMOLsRYOrbxAAoCIBK6hDeSZUliexhqna-5_0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85NGU5/N2VkNTQ5ZTcyOWJj/MDBlZjQ3N2NkYmI0/OTY2Zi5wbmc.jpg"/>
      <itunes:duration>1504</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we take a close look at weaponizing ASCII escape sequences with Fredrik (STÖK) Alexandersson.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we take a close look at weaponizing ASCII escape sequences with Fredrik (STÖK) Alexandersson.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#106 - Intel Chat: LockBit, TicTacToe Dropper, Google Cloud Run &amp; I-Soon</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>106</itunes:episode>
      <podcast:episode>106</podcast:episode>
      <itunes:title>#106 - Intel Chat: LockBit, TicTacToe Dropper, Google Cloud Run &amp; I-Soon</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">31c6d5d8-27b7-40a5-9eab-a20d2ef189c2</guid>
      <link>https://share.transistor.fm/s/f375cf78</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Law enforcement from 10 countries - in a joint operation called ‘Operation Cronos’ - have disrupted the criminal operation of the <a rel="noreferrer noopener" href="https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-disrupt-worlds-biggest-ransomware-operation">LockBit ransomware group</a>.</li><li>FortiGuard has identified a grouping of malware droppers used to deliver various final-stage payloads through 2023 they are calling the <a rel="noreferrer noopener" href="https://www.fortinet.com/blog/threat-research/tictactoe-dropper">TicTacToe dropper</a>.</li><li>Cisco Talos researchers have observed a significant increase in the volume of malicious emails leveraging the <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/google-cloud-run-abuse/">Google Cloud Run</a> service to infect potential victims with banking trojans. </li><li>A massive leak from a Chinese Ministry of Public Security <a rel="noreferrer noopener" href="https://twitter.com/bushidotoken/status/1759376010804392441?s=46&amp;t=FLuA3okS_QhMXqjYayZqUg">contractor called I-Soon</a> shows that Bejing’s intelligence and military groups are attempting large-scale, systemic cyber intrusions against foreign governments, companies, and infrastructure.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Law enforcement from 10 countries - in a joint operation called ‘Operation Cronos’ - have disrupted the criminal operation of the <a rel="noreferrer noopener" href="https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-disrupt-worlds-biggest-ransomware-operation">LockBit ransomware group</a>.</li><li>FortiGuard has identified a grouping of malware droppers used to deliver various final-stage payloads through 2023 they are calling the <a rel="noreferrer noopener" href="https://www.fortinet.com/blog/threat-research/tictactoe-dropper">TicTacToe dropper</a>.</li><li>Cisco Talos researchers have observed a significant increase in the volume of malicious emails leveraging the <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/google-cloud-run-abuse/">Google Cloud Run</a> service to infect potential victims with banking trojans. </li><li>A massive leak from a Chinese Ministry of Public Security <a rel="noreferrer noopener" href="https://twitter.com/bushidotoken/status/1759376010804392441?s=46&amp;t=FLuA3okS_QhMXqjYayZqUg">contractor called I-Soon</a> shows that Bejing’s intelligence and military groups are attempting large-scale, systemic cyber intrusions against foreign governments, companies, and infrastructure.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 29 Feb 2024 07:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f375cf78/1564893c.mp3" length="20480477" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/As6-SJskQMSLYLS-3aHXqVkreyCmmSYn0b4sV7beNnA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lMTdi/MWMyOTcxM2Y5NzRi/YjZjNTYzYTg2Mjdl/MzRmZS5wbmc.jpg"/>
      <itunes:duration>1691</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#105 - Cybersecurity in space systems with Tim Fowler, Offensive Security Analyst at Black Hills Information Security</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>105</itunes:episode>
      <podcast:episode>105</podcast:episode>
      <itunes:title>#105 - Cybersecurity in space systems with Tim Fowler, Offensive Security Analyst at Black Hills Information Security</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ed54f4ca-6a2d-4389-940b-7a6b727ec9c8</guid>
      <link>https://share.transistor.fm/s/73f61a9e</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we talk about cybersecurity issues as they relate to the space industry with Tim Fowler, Offensive Security Analyst at Black Hills Information Security.</p><p>Tim's unique blend of curiosity, determination, and passion for problem-solving make him stand out in the cybersecurity world. As a frequent speaker on topics ranging from Information Security to Open Source software, Tim's mission is clear: to empower others to take control of their journey and make a positive impact in the world of cybersecurity. </p><p>Currently Tim is working as an offensive security analyst for Black Hills Information Security - and he is here today to talk to use about the research he has been doing around cybersecurity in space…. and yes, it is as awesome as it sounds.</p><p>Tim’s upcoming training: <a rel="noreferrer noopener" href="https://www.antisyphontraining.com/event/introduction-to-cybersecurity-in-space-systems/">Introduction to Cybersecurity in Space Systems</a></p><p>Resources mentioned in the show:</p><ul><li><a rel="noreferrer noopener" href="https://treksframework.org/">TREKS Cybersecurity Framework</a></li><li><a rel="noreferrer noopener" href="https://sparta.aerospace.org/">Space Attack Research &amp; Tactic Analysis (SPARTA)</a></li><li><a rel="noreferrer noopener" href="https://spaceshield.esa.int/">SPACE-SHIELD</a></li><li><a rel="noreferrer noopener" href="https://www.opensatkit.org/">OpenSatKit</a></li><li><a rel="noreferrer noopener" href="https://cfs.gsfc.nasa.gov/">NASA Core Flight System</a></li><li><a rel="noreferrer noopener" href="https://tinygs.com/">Tiny GS</a></li><li><a rel="noreferrer noopener" href="https://openc3.com/">OpenC3</a></li><li><a rel="noreferrer noopener" href="https://www.nasa.gov/nasa-operational-simulation-for-small-satellites/">NASA Operational Simulator for Small Satellites</a></li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we talk about cybersecurity issues as they relate to the space industry with Tim Fowler, Offensive Security Analyst at Black Hills Information Security.</p><p>Tim's unique blend of curiosity, determination, and passion for problem-solving make him stand out in the cybersecurity world. As a frequent speaker on topics ranging from Information Security to Open Source software, Tim's mission is clear: to empower others to take control of their journey and make a positive impact in the world of cybersecurity. </p><p>Currently Tim is working as an offensive security analyst for Black Hills Information Security - and he is here today to talk to use about the research he has been doing around cybersecurity in space…. and yes, it is as awesome as it sounds.</p><p>Tim’s upcoming training: <a rel="noreferrer noopener" href="https://www.antisyphontraining.com/event/introduction-to-cybersecurity-in-space-systems/">Introduction to Cybersecurity in Space Systems</a></p><p>Resources mentioned in the show:</p><ul><li><a rel="noreferrer noopener" href="https://treksframework.org/">TREKS Cybersecurity Framework</a></li><li><a rel="noreferrer noopener" href="https://sparta.aerospace.org/">Space Attack Research &amp; Tactic Analysis (SPARTA)</a></li><li><a rel="noreferrer noopener" href="https://spaceshield.esa.int/">SPACE-SHIELD</a></li><li><a rel="noreferrer noopener" href="https://www.opensatkit.org/">OpenSatKit</a></li><li><a rel="noreferrer noopener" href="https://cfs.gsfc.nasa.gov/">NASA Core Flight System</a></li><li><a rel="noreferrer noopener" href="https://tinygs.com/">Tiny GS</a></li><li><a rel="noreferrer noopener" href="https://openc3.com/">OpenC3</a></li><li><a rel="noreferrer noopener" href="https://www.nasa.gov/nasa-operational-simulation-for-small-satellites/">NASA Operational Simulator for Small Satellites</a></li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 28 Feb 2024 07:00:11 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/73f61a9e/fce7ab2a.mp3" length="52096776" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/AgGt5neppnA_e96qqejE9bl1cUCoRPu8yp1X4cNCyo4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85YjMx/ZGQ2MjQwZGEwNjVj/ZGEyMjMzNjc2Nzcx/NjNlMC5wbmc.jpg"/>
      <itunes:duration>4325</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we talk about cybersecurity issues as they relate to the space industry with Tim Fowler, Offensive Security Analyst at Black Hills Information Security.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we talk about cybersecurity issues as they relate to the space industry with Tim Fowler, Offensive Security Analyst at Black Hills Information Security.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#104 - Intel Chat: Pikabot, OpenAI boots APTs, GRU Military Unit 26165 &amp; the Akira ransomware group</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>104</itunes:episode>
      <podcast:episode>104</podcast:episode>
      <itunes:title>#104 - Intel Chat: Pikabot, OpenAI boots APTs, GRU Military Unit 26165 &amp; the Akira ransomware group</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">38fdaec7-63b9-4522-849e-a5ad5c511696</guid>
      <link>https://share.transistor.fm/s/80c85f12</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>ZScaler ThreatLabz are reporting on some recent campaigns, which started in February 2024, where they observed Pikabot reemerging with significant changes in its <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/d-evolution-pikabot">code base and structure</a>.</li><li>OpenAi is claiming that they have terminated accounts associated with <a rel="noreferrer noopener" href="https://openai.com/blog/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors">state-affiliated threat actors.</a></li><li>A January 2024 court-authorized operation has neutralized a network of hundreds of small office/home office (SOHO)  routers that were used to commit crimes by the <a rel="noreferrer noopener" href="https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-botnet-controlled-russian">GRU Military Unit 26165</a>.</li><li>SecurityWeek is reporting on the fine folks at CISA who are urging the patching of a Cisco ASA flaw that is being <a rel="noreferrer noopener" href="https://www.securityweek.com/cisa-urges-patching-of-cisco-asa-flaw-exploited-in-ransomware-attacks/">used in ransomware</a>.</li></ul><p>A document naming APT groups and operations can be <a rel="noreferrer noopener" href="https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit#gid=1864660085">found here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>ZScaler ThreatLabz are reporting on some recent campaigns, which started in February 2024, where they observed Pikabot reemerging with significant changes in its <a rel="noreferrer noopener" href="https://www.zscaler.com/blogs/security-research/d-evolution-pikabot">code base and structure</a>.</li><li>OpenAi is claiming that they have terminated accounts associated with <a rel="noreferrer noopener" href="https://openai.com/blog/disrupting-malicious-uses-of-ai-by-state-affiliated-threat-actors">state-affiliated threat actors.</a></li><li>A January 2024 court-authorized operation has neutralized a network of hundreds of small office/home office (SOHO)  routers that were used to commit crimes by the <a rel="noreferrer noopener" href="https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-botnet-controlled-russian">GRU Military Unit 26165</a>.</li><li>SecurityWeek is reporting on the fine folks at CISA who are urging the patching of a Cisco ASA flaw that is being <a rel="noreferrer noopener" href="https://www.securityweek.com/cisa-urges-patching-of-cisco-asa-flaw-exploited-in-ransomware-attacks/">used in ransomware</a>.</li></ul><p>A document naming APT groups and operations can be <a rel="noreferrer noopener" href="https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit#gid=1864660085">found here</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 23 Feb 2024 06:36:33 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/80c85f12/0c59010e.mp3" length="27822297" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/cENuJ_DMetCd_R45o1szCbKxAbVYtL0d5DpmRLJCmkc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lYjEz/ODhiNDM4YTg0YmQ1/ZjBiNjMwNzk5NTYy/MTJhNC5wbmc.jpg"/>
      <itunes:duration>2303</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#103 - A better way forward for cybersecurity with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>103</itunes:episode>
      <podcast:episode>103</podcast:episode>
      <itunes:title>#103 - A better way forward for cybersecurity with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0c16e472-688c-45a0-99f0-5456d05fedcf</guid>
      <link>https://share.transistor.fm/s/c557e768</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we delve into an innovative, engineering-centered perspective on cybersecurity with Maxime Lamothe-Brassard, the Founder &amp; CEO of <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.</p><p>As part of the Canadian Intelligence apparatus, Maxime worked in positions ranging from development of cyber defence technologies, Counter Computer Network Exploitation, and Counter Intelligence. Maxime led the creation of an advanced cyber security program for the Canadian government and received several Director’s awards for his service.</p><p>After leaving the government, Maxime provided direct help to private and public organizations in matters of cyber defence and worked for Crowdstrike, Google and Google X. Maxime left Google X - where he was a founding member of Chronicle Security - in 2018 to found LimaCharlie.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we delve into an innovative, engineering-centered perspective on cybersecurity with Maxime Lamothe-Brassard, the Founder &amp; CEO of <a rel="noreferrer noopener" href="https://limacharlie.io/">LimaCharlie</a>.</p><p>As part of the Canadian Intelligence apparatus, Maxime worked in positions ranging from development of cyber defence technologies, Counter Computer Network Exploitation, and Counter Intelligence. Maxime led the creation of an advanced cyber security program for the Canadian government and received several Director’s awards for his service.</p><p>After leaving the government, Maxime provided direct help to private and public organizations in matters of cyber defence and worked for Crowdstrike, Google and Google X. Maxime left Google X - where he was a founding member of Chronicle Security - in 2018 to found LimaCharlie.</p>]]>
      </content:encoded>
      <pubDate>Wed, 21 Feb 2024 14:36:46 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c557e768/c0e1d95c.mp3" length="38508792" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/V5zaTC3IXSBj7vN9S6YDMm0C_A-SSJh8-W2RD2-b12Y/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMjg0/NDU3MWFiYjMwYzE0/OWUzY2ZkZjkxNGRh/OWQ1Mi5wbmc.jpg"/>
      <itunes:duration>3193</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we delve into an innovative, engineering-centered perspective on cybersecurity with Maxime Lamothe-Brassard, the Founder &amp;amp; CEO of LimaCharlie.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we delve into an innovative, engineering-centered perspective on cybersecurity with Maxime Lamothe-Brassard, the Founder &amp;amp; CEO of LimaCharlie.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#102 - Intel Chat: toothbrush DDOS, TPM-based encryption bypass &amp; HijackLoader</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>102</itunes:episode>
      <podcast:episode>102</podcast:episode>
      <itunes:title>#102 - Intel Chat: toothbrush DDOS, TPM-based encryption bypass &amp; HijackLoader</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fea6a30b-b23a-4195-8395-830a23a764e4</guid>
      <link>https://share.transistor.fm/s/a404e80d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>The spectacular headline announcing a DDOS attack that involved 3-million electric <a rel="noreferrer noopener" href="https://grahamcluley.com/the-toothbrush-ddos-attack-how-misinformation-spreads-in-the-cybersecurity-world/">toothbrushes</a>.</li><li>A hardware attack to bypass TPM-based encryption which is used on most Microsoft <a rel="noreferrer noopener" href="https://youtu.be/wTl4vEednkQ?si=mNV47fZ9Xdl7W-Cd">Windows devices</a>.</li><li>CrowdStrike researchers have identified a HijackLoader sample that employs sophisticated evasion techniques to enhance the <a rel="noreferrer noopener" href="https://www.crowdstrike.com/blog/hijackloader-expands-techniques/">complexity of the threat</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>The spectacular headline announcing a DDOS attack that involved 3-million electric <a rel="noreferrer noopener" href="https://grahamcluley.com/the-toothbrush-ddos-attack-how-misinformation-spreads-in-the-cybersecurity-world/">toothbrushes</a>.</li><li>A hardware attack to bypass TPM-based encryption which is used on most Microsoft <a rel="noreferrer noopener" href="https://youtu.be/wTl4vEednkQ?si=mNV47fZ9Xdl7W-Cd">Windows devices</a>.</li><li>CrowdStrike researchers have identified a HijackLoader sample that employs sophisticated evasion techniques to enhance the <a rel="noreferrer noopener" href="https://www.crowdstrike.com/blog/hijackloader-expands-techniques/">complexity of the threat</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 15 Feb 2024 22:55:02 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a404e80d/73fd4ffb.mp3" length="24244943" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/gCNvD_PIXoQjfqSofC4jZQiMCkbv4GS3XGrx5o52mok/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yYmY2/YmEyOTk3MzU2YjIx/MDM3MmM3NmU2OGQw/NTA5Yy5wbmc.jpg"/>
      <itunes:duration>2005</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#101 - WiFi attacks and defense with Lennart Koopmann, Founder of the Nzyme Network Defense System</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>101</itunes:episode>
      <podcast:episode>101</podcast:episode>
      <itunes:title>#101 - WiFi attacks and defense with Lennart Koopmann, Founder of the Nzyme Network Defense System</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3600460d-5ff3-45e0-808f-751c3888db77</guid>
      <link>https://share.transistor.fm/s/70f47898</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at WiFi attack methods, and the defenses to them, with Lennart Koopmann, Founder of the Nzyme Network Defense System.</p><p>Lennart Koopman, a tech enthusiast originally from Germany, now calling Houston, TX home. He began coding at a young age and chose to forgo formal education, diving straight into the world of computers after high school.</p><p>Lennart's career path led him through various roles, from assisting in a hospital's IT helpdesk to web development and eventually joining a startup. In 2009, he launched the Graylog log management system as a side project, marking his entry into the tech scene.</p><p>Currently, Lennart is focused on his latest endeavor: The nzyme Network Defense System, demonstrating his ongoing commitment to technological advancement.</p><p>The WiFiPhisher Github account can be found <a rel="noreferrer noopener" href="https://github.com/wifiphisher">here</a>. </p><p>Lennart’s talk at MSS CTRL (LINK) can be found <a rel="noreferrer noopener" href="https://limacharlie.io/events/mssn-ctrl-2023?wchannelid=ior20bh59e&amp;wmediaid=ia51zmjo9q">here</a>.</p><p>The Nzyme Network Defense System website can be found <a rel="noreferrer noopener" href="https://www.nzyme.org/">here</a>. </p><p>Lennart can be found in Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/_lennart">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at WiFi attack methods, and the defenses to them, with Lennart Koopmann, Founder of the Nzyme Network Defense System.</p><p>Lennart Koopman, a tech enthusiast originally from Germany, now calling Houston, TX home. He began coding at a young age and chose to forgo formal education, diving straight into the world of computers after high school.</p><p>Lennart's career path led him through various roles, from assisting in a hospital's IT helpdesk to web development and eventually joining a startup. In 2009, he launched the Graylog log management system as a side project, marking his entry into the tech scene.</p><p>Currently, Lennart is focused on his latest endeavor: The nzyme Network Defense System, demonstrating his ongoing commitment to technological advancement.</p><p>The WiFiPhisher Github account can be found <a rel="noreferrer noopener" href="https://github.com/wifiphisher">here</a>. </p><p>Lennart’s talk at MSS CTRL (LINK) can be found <a rel="noreferrer noopener" href="https://limacharlie.io/events/mssn-ctrl-2023?wchannelid=ior20bh59e&amp;wmediaid=ia51zmjo9q">here</a>.</p><p>The Nzyme Network Defense System website can be found <a rel="noreferrer noopener" href="https://www.nzyme.org/">here</a>. </p><p>Lennart can be found in Twitter/X <a rel="noreferrer noopener" href="https://twitter.com/_lennart">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 13 Feb 2024 07:20:48 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/70f47898/0b3a60eb.mp3" length="42820552" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/G1m6VUrAE8j5tlGMUFXMsASm5bPaY9UBcis4hKWuHpY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zOWUy/ZDVhOGE3YTIzNDE3/M2MzNDJhNDBhYWQ1/NWQ1ZS5wbmc.jpg"/>
      <itunes:duration>3552</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we take a close look at WiFi attack methods, and the defenses to them, with Lennart Koopmann, Founder of the Nzyme Network Defense System.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we take a close look at WiFi attack methods, and the defenses to them, with Lennart Koopmann, Founder of the Nzyme Network Defense System.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#100 - A tale of two breaches: examining the AnyDesk &amp; Cloudflare incidents</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>96</itunes:episode>
      <podcast:episode>96</podcast:episode>
      <itunes:title>#100 - A tale of two breaches: examining the AnyDesk &amp; Cloudflare incidents</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">42290e0a-ff38-442c-928b-043a420e1580</guid>
      <link>https://share.transistor.fm/s/0c7a016c</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the AnyDesk and Cloudflare breaches that were both disclosed on February 2, 2024.</p><p>AnyDesk, a prominent remote desktop software provider, disclosed a cyberattack late on February 2nd, causing the company to enforce strict security measures for nearly a week. Adversaries breached AnyDesk's systems, compromising vital assets such as source code and private code signing keys, and gaining unauthorized access to production systems.</p><p>For more on AnyDesk's breach, see the following references:</p><p><a rel="noreferrer noopener" href="https://techcrunch.com/2024/02/05/remote-access-giant-anydesk-resets-passwords-and-revokes-certificates-after-hack/">https://techcrunch.com/2024/02/05/remote-access-giant-anydesk-resets-passwords-and-revokes-certificates-after-hack/</a></p><p><a rel="noreferrer noopener" href="https://anydesk.com/en/public-statement">https://anydesk.com/en/public-statement</a></p><p><a rel="noreferrer noopener" href="https://www.infosecurity-magazine.com/news/anydesk-hit-cyberattack-customer/">https://www.infosecurity-magazine.com/news/anydesk-hit-cyberattack-customer/</a></p><p><a rel="noreferrer noopener" href="https://www.helpnetsecurity.com/2024/02/05/anydesk-hacked/">https://www.helpnetsecurity.com/2024/02/05/anydesk-hacked/</a></p><p><a rel="noreferrer noopener" href="https://thehackernews.com/2024/02/anydesk-hacked-popular-remote-desktop.html">https://thehackernews.com/2024/02/anydesk-hacked-popular-remote-desktop.html</a></p><p>On the other front, Cloudflare disclosed that a nation-state actor infiltrated their self-hosted Atlassian server on November 14, 2023, utilizing stolen access tokens and service account credentials from the Okta breach. The threat actor conducted reconnaissance activities from November 14th to 17th, gaining access to Cloudflare's internal wiki and bug database. Additional access attempts on November 20th and 21st indicated the actor's persistence, culminating in establishing continuous access through ScriptRunner for Jira on November 22nd. Finally, they tried, unsuccessfully, to access a console server that had access to a data center that Cloudflare had not yet put into production in São Paulo, Brazil.</p><p>For more details on Cloudflare's breach, consult the following sources:</p><p><a rel="noreferrer noopener" href="https://www.csoonline.com/article/1303785/nation-state-actor-used-recent-okta-compromises-to-hack-into-cloudflare-systems.html">https://www.csoonline.com/article/1303785/nation-state-actor-used-recent-okta-compromises-to-hack-into-cloudflare-systems.html</a></p><p><a rel="noreferrer noopener" href="https://www.techtarget.com/searchsecurity/news/366568694/Cloudflare-discloses-breach-related-to-stolen-Okta-data">https://www.techtarget.com/searchsecurity/news/366568694/Cloudflare-discloses-breach-related-to-stolen-Okta-data</a></p><p><a rel="noreferrer noopener" href="https://www.computing.co.uk/news/4170126/cloudflare-server-breached-suspected-sponsored-threat-actors">https://www.computing.co.uk/news/4170126/cloudflare-server-breached-suspected-sponsored-threat-actors</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the AnyDesk and Cloudflare breaches that were both disclosed on February 2, 2024.</p><p>AnyDesk, a prominent remote desktop software provider, disclosed a cyberattack late on February 2nd, causing the company to enforce strict security measures for nearly a week. Adversaries breached AnyDesk's systems, compromising vital assets such as source code and private code signing keys, and gaining unauthorized access to production systems.</p><p>For more on AnyDesk's breach, see the following references:</p><p><a rel="noreferrer noopener" href="https://techcrunch.com/2024/02/05/remote-access-giant-anydesk-resets-passwords-and-revokes-certificates-after-hack/">https://techcrunch.com/2024/02/05/remote-access-giant-anydesk-resets-passwords-and-revokes-certificates-after-hack/</a></p><p><a rel="noreferrer noopener" href="https://anydesk.com/en/public-statement">https://anydesk.com/en/public-statement</a></p><p><a rel="noreferrer noopener" href="https://www.infosecurity-magazine.com/news/anydesk-hit-cyberattack-customer/">https://www.infosecurity-magazine.com/news/anydesk-hit-cyberattack-customer/</a></p><p><a rel="noreferrer noopener" href="https://www.helpnetsecurity.com/2024/02/05/anydesk-hacked/">https://www.helpnetsecurity.com/2024/02/05/anydesk-hacked/</a></p><p><a rel="noreferrer noopener" href="https://thehackernews.com/2024/02/anydesk-hacked-popular-remote-desktop.html">https://thehackernews.com/2024/02/anydesk-hacked-popular-remote-desktop.html</a></p><p>On the other front, Cloudflare disclosed that a nation-state actor infiltrated their self-hosted Atlassian server on November 14, 2023, utilizing stolen access tokens and service account credentials from the Okta breach. The threat actor conducted reconnaissance activities from November 14th to 17th, gaining access to Cloudflare's internal wiki and bug database. Additional access attempts on November 20th and 21st indicated the actor's persistence, culminating in establishing continuous access through ScriptRunner for Jira on November 22nd. Finally, they tried, unsuccessfully, to access a console server that had access to a data center that Cloudflare had not yet put into production in São Paulo, Brazil.</p><p>For more details on Cloudflare's breach, consult the following sources:</p><p><a rel="noreferrer noopener" href="https://www.csoonline.com/article/1303785/nation-state-actor-used-recent-okta-compromises-to-hack-into-cloudflare-systems.html">https://www.csoonline.com/article/1303785/nation-state-actor-used-recent-okta-compromises-to-hack-into-cloudflare-systems.html</a></p><p><a rel="noreferrer noopener" href="https://www.techtarget.com/searchsecurity/news/366568694/Cloudflare-discloses-breach-related-to-stolen-Okta-data">https://www.techtarget.com/searchsecurity/news/366568694/Cloudflare-discloses-breach-related-to-stolen-Okta-data</a></p><p><a rel="noreferrer noopener" href="https://www.computing.co.uk/news/4170126/cloudflare-server-breached-suspected-sponsored-threat-actors">https://www.computing.co.uk/news/4170126/cloudflare-server-breached-suspected-sponsored-threat-actors</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 09 Feb 2024 08:00:37 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0c7a016c/b7e559e0.mp3" length="26553011" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/fWxln_5HrgMfcBasLI5FZb-aqyQ2-uQapsdFd7jZPE8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZWM3/NWE0YWQ4OTZiMTc1/OGFhYWY5MTQ0OWY5/MTMzMi5wbmc.jpg"/>
      <itunes:duration>2197</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the AnyDesk and Cloudflare breaches that were both disclosed on February 2, 2024.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we take a close look at the AnyDesk and Cloudflare breaches that were both disclosed on February 2, 2024.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#99 - Ground truth realities with Yochai Greenberg, Frontline Cyber Defender</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>99</itunes:episode>
      <podcast:episode>99</podcast:episode>
      <itunes:title>#99 - Ground truth realities with Yochai Greenberg, Frontline Cyber Defender</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d41b0a9b-5d61-4a30-aad3-cec9e9394617</guid>
      <link>https://share.transistor.fm/s/c59baaf5</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we delve into the ground truth realities of cybersecurity with Yochai Greenberg, a frontline cyber defender.</p><p>Yochai Greenberg's expertise in cybersecurity is grounded in a lifetime of hands-on experience and military service. From an early age, he immersed himself in computer technology, gaining comprehensive knowledge of hardware and software through practical experimentation. Serving in the IDF further cultivated his understanding of protection and security protocols.</p><p>Transitioning into the security industry, Yochai applied his diverse skill set as an executive protection professional, bridging the gap between physical and digital security domains. His career is defined by a relentless pursuit of knowledge and innovation, driven by a commitment to integrating and enhancing security measures across various fronts.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we delve into the ground truth realities of cybersecurity with Yochai Greenberg, a frontline cyber defender.</p><p>Yochai Greenberg's expertise in cybersecurity is grounded in a lifetime of hands-on experience and military service. From an early age, he immersed himself in computer technology, gaining comprehensive knowledge of hardware and software through practical experimentation. Serving in the IDF further cultivated his understanding of protection and security protocols.</p><p>Transitioning into the security industry, Yochai applied his diverse skill set as an executive protection professional, bridging the gap between physical and digital security domains. His career is defined by a relentless pursuit of knowledge and innovation, driven by a commitment to integrating and enhancing security measures across various fronts.</p>]]>
      </content:encoded>
      <pubDate>Tue, 06 Feb 2024 13:10:46 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c59baaf5/53c0d40a.mp3" length="23148735" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/MMCYgxK9kbeEWEku9vkDkguZVU9LRIj9LKl_ykMVcGI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MWM3/Y2JkY2UwY2I2NTFm/ODg0NTMzMGRhMTdl/ZjZkMy5wbmc.jpg"/>
      <itunes:duration>1913</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we delve into the ground truth realities of cybersecurity with Yochai Greenberg, a frontline cyber defender.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we delve into the ground truth realities of cybersecurity with Yochai Greenberg, a frontline cyber defender.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#98 - Intel Chat: Midnight Blizzard, GKE vulnerability, NetSupport RAT &amp; Cactus ransomware</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>98</itunes:episode>
      <podcast:episode>98</podcast:episode>
      <itunes:title>#98 - Intel Chat: Midnight Blizzard, GKE vulnerability, NetSupport RAT &amp; Cactus ransomware</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">eebbcc04-c93b-433b-a16b-ad96fa514121</guid>
      <link>https://share.transistor.fm/s/1b5ddb95</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Microsoft updated the public on their findings - apparently, the threat actors were able to gain persistent access to the privileged email accounts by abusing the <a rel="noreferrer noopener" href="https://arstechnica.com/security/2024/01/in-major-gaffe-hacked-microsoft-test-account-was-assigned-admin-privileges/">OAuth authorization protocol</a>.</li><li>Cybersecurity researchers have discovered a loophole impacting Google Kubernetes Engine that could be potentially exploited by threat actors to take control of a <a rel="noreferrer noopener" href="https://thehackernews.com/2024/01/google-kubernetes-misconfig-lets-any.html">Kubernetes cluster</a>.</li><li>A new campaign is using phishing emails to distribute malware and legitimate services to bypass email protection systems to <a rel="noreferrer noopener" href="https://medium.com/@ad12347/netsupport-rat-hits-again-with-new-iocs-37318de44cfc">install NetSupport RAT</a>.</li><li>On January 20th the Cactus ransomware group attacked a number of <a rel="noreferrer noopener" href="https://www.shadowstackre.com/analysis/cactus">victims across varying industries</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Microsoft updated the public on their findings - apparently, the threat actors were able to gain persistent access to the privileged email accounts by abusing the <a rel="noreferrer noopener" href="https://arstechnica.com/security/2024/01/in-major-gaffe-hacked-microsoft-test-account-was-assigned-admin-privileges/">OAuth authorization protocol</a>.</li><li>Cybersecurity researchers have discovered a loophole impacting Google Kubernetes Engine that could be potentially exploited by threat actors to take control of a <a rel="noreferrer noopener" href="https://thehackernews.com/2024/01/google-kubernetes-misconfig-lets-any.html">Kubernetes cluster</a>.</li><li>A new campaign is using phishing emails to distribute malware and legitimate services to bypass email protection systems to <a rel="noreferrer noopener" href="https://medium.com/@ad12347/netsupport-rat-hits-again-with-new-iocs-37318de44cfc">install NetSupport RAT</a>.</li><li>On January 20th the Cactus ransomware group attacked a number of <a rel="noreferrer noopener" href="https://www.shadowstackre.com/analysis/cactus">victims across varying industries</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 01 Feb 2024 19:31:03 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1b5ddb95/ba1e1ede.mp3" length="26627960" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/r_UotSvXF0oUZUb34472bRYZ6fqLlUV1pkLWZL_D0vQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yMzM4/NzBjMmFlNGVhNzAw/NjBkODU4NDg3NmJm/YzJlYy5wbmc.jpg"/>
      <itunes:duration>2203</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#97 - Cybersecurity threats to electric vehicles with Mike Pedrick, VP of Cybersecurity Consulting at Nuspire</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>97</itunes:episode>
      <podcast:episode>97</podcast:episode>
      <itunes:title>#97 - Cybersecurity threats to electric vehicles with Mike Pedrick, VP of Cybersecurity Consulting at Nuspire</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6ef16d15-df7f-459c-9ec2-74b2bd230590</guid>
      <link>https://share.transistor.fm/s/f7f8aa88</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we discuss some of the cybersecurity threats to electric vehicles with Mike Pedrick, VP of Cybersecurity Consulting at <a rel="noreferrer noopener" href="https://www.nuspire.com/">Nuspire</a>.</p><p>Mike is currently serving as the Vice President of Cybersecurity Consulting at Nuspire. In his role over the past two years, Mike has focused on providing advisory services to mid-market clients in the areas of cybersecurity, governance, risk, and compliance with data security and privacy standards. His specialization lies in implementing mature cybersecurity programs tailored for small and medium-sized businesses. Mike is also actively involved with ISACA, where he currently serves as the Certification Coordinator for the Denver Chapter Board, managing certification-related activities.</p><p>Before joining Nuspire, Mike held positions such as Vice President of Consulting at Stealth - ISS Group Inc. and Director of Security Consulting at Synoptek. In these roles, he provided leadership and advisory services in the cybersecurity domain. With over a decade of self-employment as a Security, Compliance, and Risk Management Consultant, Mike has served as a trusted advisor to SMB/Midmarket organizations, offering guidance in cybersecurity, compliance, and risk management.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we discuss some of the cybersecurity threats to electric vehicles with Mike Pedrick, VP of Cybersecurity Consulting at <a rel="noreferrer noopener" href="https://www.nuspire.com/">Nuspire</a>.</p><p>Mike is currently serving as the Vice President of Cybersecurity Consulting at Nuspire. In his role over the past two years, Mike has focused on providing advisory services to mid-market clients in the areas of cybersecurity, governance, risk, and compliance with data security and privacy standards. His specialization lies in implementing mature cybersecurity programs tailored for small and medium-sized businesses. Mike is also actively involved with ISACA, where he currently serves as the Certification Coordinator for the Denver Chapter Board, managing certification-related activities.</p><p>Before joining Nuspire, Mike held positions such as Vice President of Consulting at Stealth - ISS Group Inc. and Director of Security Consulting at Synoptek. In these roles, he provided leadership and advisory services in the cybersecurity domain. With over a decade of self-employment as a Security, Compliance, and Risk Management Consultant, Mike has served as a trusted advisor to SMB/Midmarket organizations, offering guidance in cybersecurity, compliance, and risk management.</p>]]>
      </content:encoded>
      <pubDate>Tue, 30 Jan 2024 14:50:59 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f7f8aa88/e519722a.mp3" length="31619684" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/oQCtRtNytaEbLDSO5p9LDvhFq4FjOA7lQXDDqc3gv2I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZjdj/NmNhYzJkMzUzNzc5/MDM1ZGQ3N2RlZDc5/YTYzMy5wbmc.jpg"/>
      <itunes:duration>2619</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we discuss some of the cybersecurity threats to electric vehicles with Mike Pedrick, VP of Cybersecurity Consulting at Nuspire.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we discuss some of the cybersecurity threats to electric vehicles with Mike Pedrick, VP of Cybersecurity Consulting at Nuspire.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#96 - Intel Chat: iOS malware detection, credentials leaked, ColdRiver, &amp; Midnight Blizzard</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>96</itunes:episode>
      <podcast:episode>96</podcast:episode>
      <itunes:title>#96 - Intel Chat: iOS malware detection, credentials leaked, ColdRiver, &amp; Midnight Blizzard</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8365bbfb-f4e8-4232-bb72-e47e8640424b</guid>
      <link>https://share.transistor.fm/s/2de012eb</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>SecureList researchers from Kaspersky have come up with a lightweight method to detect <a rel="noreferrer noopener" href="https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/">iOS malware</a>.</li><li>Nearly 71 million unique credentials that were leaked from websites such as Facebook, Roblox, eBay, Yahoo, and Coinbase have been <a rel="noreferrer noopener" href="https://arstechnica.com/security/2024/01/71-million-passwords-for-facebook-coinbase-and-others-found-for-sale/#p3">circulating on the Internet</a>.</li><li>Russian threat group <a rel="noreferrer noopener" href="https://blog.google/threat-analysis-group/google-tag-coldriver-russian-phishing-malware/">COLDRIVER</a> has expanded its targeting of Western officials to include the use of malware.</li><li>The Microsoft security team is reporting that it detected a <a rel="noreferrer noopener" href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/">nation-state attack</a> on its corporate systems on January 12, 2024. </li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>SecureList researchers from Kaspersky have come up with a lightweight method to detect <a rel="noreferrer noopener" href="https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/">iOS malware</a>.</li><li>Nearly 71 million unique credentials that were leaked from websites such as Facebook, Roblox, eBay, Yahoo, and Coinbase have been <a rel="noreferrer noopener" href="https://arstechnica.com/security/2024/01/71-million-passwords-for-facebook-coinbase-and-others-found-for-sale/#p3">circulating on the Internet</a>.</li><li>Russian threat group <a rel="noreferrer noopener" href="https://blog.google/threat-analysis-group/google-tag-coldriver-russian-phishing-malware/">COLDRIVER</a> has expanded its targeting of Western officials to include the use of malware.</li><li>The Microsoft security team is reporting that it detected a <a rel="noreferrer noopener" href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/">nation-state attack</a> on its corporate systems on January 12, 2024. </li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 25 Jan 2024 14:07:26 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2de012eb/39906905.mp3" length="22380452" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ay5dXLUmBa_V2j2ifCUWsMa2LjtwIkbw0fbkBnYnrKU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84ODhj/ODVmZmY0NGQzZjRk/MThlOTFmMDRiODk5/YzcxNi5wbmc.jpg"/>
      <itunes:duration>1849</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#95 - The SaaS Cyber Kill Chain with Luke Jennings, VP Research &amp; Development at Push Security</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>95</itunes:episode>
      <podcast:episode>95</podcast:episode>
      <itunes:title>#95 - The SaaS Cyber Kill Chain with Luke Jennings, VP Research &amp; Development at Push Security</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">316d8e9d-3f7b-492a-82cd-830a0d021f63</guid>
      <link>https://share.transistor.fm/s/798fa3e2</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a conversation about the SaaS Cyber Kill Chain with Luke Jennings, VP of Research &amp; Development at Push Security.</p><p>In this interview, we explore the evolution of cyber attacks and the impact of the remote working and SaaS revolution on the cyber kill chain.</p><p>The SaaS Attack Matrix can be found <a rel="noreferrer noopener" href="https://github.com/pushsecurity/saas-attacks">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a conversation about the SaaS Cyber Kill Chain with Luke Jennings, VP of Research &amp; Development at Push Security.</p><p>In this interview, we explore the evolution of cyber attacks and the impact of the remote working and SaaS revolution on the cyber kill chain.</p><p>The SaaS Attack Matrix can be found <a rel="noreferrer noopener" href="https://github.com/pushsecurity/saas-attacks">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 23 Jan 2024 13:54:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/798fa3e2/09224675.mp3" length="33321793" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/2q6n0BmYh3wOdJSs36cIWM0GaXlhDdjzYQbhBg7Q86E/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jMmYz/ZWI0YWRkYTQ2ZWIw/MDUzZjA4NWMwNjE5/MGQ1Ni5wbmc.jpg"/>
      <itunes:duration>2761</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we have a conversation about the SaaS Cyber Kill Chain with Luke Jennings, VP of Research &amp;amp; Development at Push Security.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we have a conversation about the SaaS Cyber Kill Chain with Luke Jennings, VP of Research &amp;amp; Development at Push Security.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#94 - Intel Chat: Bandook, NoaBot, mandating 2FA &amp; POST SMTP</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>95</itunes:episode>
      <podcast:episode>95</podcast:episode>
      <itunes:title>#94 - Intel Chat: Bandook, NoaBot, mandating 2FA &amp; POST SMTP</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b6df415c-4bbb-4be1-afb4-f323e7eb807c</guid>
      <link>https://share.transistor.fm/s/d67ae451</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>A new <a rel="noreferrer noopener" href="https://www.fortinet.com/blog/threat-research/bandook-persistent-threat-that-keeps-evolving">Bandook variant</a> has been distributed via a PDF since this past October.</li><li>Akami researchers have uncovered a new <a rel="noreferrer noopener" href="https://www.akamai.com/blog/security-research/mirai-based-noabot-crypto-mining">crypto-mining campaign</a> that has been active since the start of 2023. </li><li>The Centres for Medicare and Medicaid Services will reportedly set out the proposed <a rel="noreferrer noopener" href="https://secalerts.co/news/no-federal-funding-for-us-healthcare-providers-lacking-cyber-security/4VFNjpb6oxtJyqRW2jFOyh">requirements</a> that include two-factor authentication and maintaining a vulnerability-fixing program.</li><li>Two vulnerabilities were uncovered that impact the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/over-150k-wordpress-sites-at-takeover-risk-via-vulnerable-plugin/">POST SMTP</a> Mailer WordPress plugin, an email delivery tool used by 300,000 websites.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>A new <a rel="noreferrer noopener" href="https://www.fortinet.com/blog/threat-research/bandook-persistent-threat-that-keeps-evolving">Bandook variant</a> has been distributed via a PDF since this past October.</li><li>Akami researchers have uncovered a new <a rel="noreferrer noopener" href="https://www.akamai.com/blog/security-research/mirai-based-noabot-crypto-mining">crypto-mining campaign</a> that has been active since the start of 2023. </li><li>The Centres for Medicare and Medicaid Services will reportedly set out the proposed <a rel="noreferrer noopener" href="https://secalerts.co/news/no-federal-funding-for-us-healthcare-providers-lacking-cyber-security/4VFNjpb6oxtJyqRW2jFOyh">requirements</a> that include two-factor authentication and maintaining a vulnerability-fixing program.</li><li>Two vulnerabilities were uncovered that impact the <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/over-150k-wordpress-sites-at-takeover-risk-via-vulnerable-plugin/">POST SMTP</a> Mailer WordPress plugin, an email delivery tool used by 300,000 websites.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 19 Jan 2024 07:42:49 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d67ae451/d6df6a8b.mp3" length="27109389" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/aZz-fe3iR91rr2rvyfTK7yD_3LPjWpAP2a05YqAunM0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wNDk2/Mzk3ZWQ3OGZiNWYx/ODFkNmUyMzU4NjZl/YWM1Zi5wbmc.jpg"/>
      <itunes:duration>2243</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#93 - Poisoning Github's runner images with Adnan Khan, Lead Security Engineer at Praetorian</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>93</itunes:episode>
      <podcast:episode>93</podcast:episode>
      <itunes:title>#93 - Poisoning Github's runner images with Adnan Khan, Lead Security Engineer at Praetorian</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1fd4266a-4f97-4881-874a-6f8caaddda10</guid>
      <link>https://share.transistor.fm/s/16dc5129</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Adnan Khan, Lead Security Engineer at <a rel="noreferrer noopener" href="https://www.praetorian.com/">Praetorian</a>, about a supply chain attack that was successful in poisoning Gihub’s runner images.</p><p>Adnan is an Offensive Security Engineer and Security Researcher with a strong development background and passion for CI/CD and supply chain security. </p><p>Adnan’s research can be found <a rel="noreferrer noopener" href="https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-to-rule-them-all/">here</a>.</p><p>The Github Attack TOolkit can be found <a rel="noreferrer noopener" href="https://github.com/praetorian-inc/gato">here</a>.</p><p>And Adnan can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/adnanekhan/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we speak with Adnan Khan, Lead Security Engineer at <a rel="noreferrer noopener" href="https://www.praetorian.com/">Praetorian</a>, about a supply chain attack that was successful in poisoning Gihub’s runner images.</p><p>Adnan is an Offensive Security Engineer and Security Researcher with a strong development background and passion for CI/CD and supply chain security. </p><p>Adnan’s research can be found <a rel="noreferrer noopener" href="https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-to-rule-them-all/">here</a>.</p><p>The Github Attack TOolkit can be found <a rel="noreferrer noopener" href="https://github.com/praetorian-inc/gato">here</a>.</p><p>And Adnan can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/adnanekhan/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Tue, 16 Jan 2024 15:03:58 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/16dc5129/95897b2d.mp3" length="21471706" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/KBSFJRsAJweH7yznO8MHHaVpaedIDLEVz6qeeEyTAOo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82MGIw/YzI4ODZjNzE1Nzkz/MTUyOGY0NTZlOTlj/Yzc4My5wbmc.jpg"/>
      <itunes:duration>1773</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast we speak with Adnan Khan, Lead Security Engineer at Praetorian, about a supply chain attack that was successful in poisoning Gihub’s runner images.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast we speak with Adnan Khan, Lead Security Engineer at Praetorian, about a supply chain attack that was successful in poisoning Gihub’s runner images.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#92 - Early cybersecurity career advice with Gerald Auger, Chief Content Creator at Simply Cyber</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>92</itunes:episode>
      <podcast:episode>92</podcast:episode>
      <itunes:title>#92 - Early cybersecurity career advice with Gerald Auger, Chief Content Creator at Simply Cyber</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7e76714e-095a-45ba-8e41-6b718a5ac809</guid>
      <link>https://share.transistor.fm/s/0de74429</link>
      <description>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast, we chat with Gerald Auger, Chief Content Creator at Simply Cyber.</p><p>Dr. Gerald Auger is deeply passionate about information security, holding a steadfast belief that there exists a bespoke information security program for every organization. This tailored approach, he contends, not only mitigates cybersecurity risks but also amplifies overall value, aligning harmoniously with the business mission. Through Coastal Information Security Group, Dr. Auger extends his consulting and advisory cybersecurity services to both large and small organizations. With a focus on guiding the implementation of robust information security programs, he strives to meet the unique needs of each client.</p><p>Gerald Auger's, 'Build an Elastic SIEM lab' <a rel="noreferrer noopener" href="https://www.youtube.com/watch?v=2XLzMb9oZBI">video</a></p><p>Eric Capuano's, 'So you want to be a SOC Analyst?' <a rel="noreferrer noopener" href="https://blog.ecapuano.com/p/so-you-want-to-be-a-soc-analyst-part">Part 1</a> &amp; <a rel="noreferrer noopener" href="https://blog.ecapuano.com/p/so-you-want-to-be-a-soc-analyst-20">Part 2</a></p><p>You can find Gerald on the various social media platforms as linked below.</p><p><a rel="noreferrer noopener" href="https://www.youtube.com/c/GeraldAuger">YouTube</a></p><p><a rel="noreferrer noopener" href="https://twitter.com/Gerald_Auger">Twitter</a></p><p><a rel="noreferrer noopener" href="https://www.linkedin.com/in/geraldauger/">LinkedIn</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast, we chat with Gerald Auger, Chief Content Creator at Simply Cyber.</p><p>Dr. Gerald Auger is deeply passionate about information security, holding a steadfast belief that there exists a bespoke information security program for every organization. This tailored approach, he contends, not only mitigates cybersecurity risks but also amplifies overall value, aligning harmoniously with the business mission. Through Coastal Information Security Group, Dr. Auger extends his consulting and advisory cybersecurity services to both large and small organizations. With a focus on guiding the implementation of robust information security programs, he strives to meet the unique needs of each client.</p><p>Gerald Auger's, 'Build an Elastic SIEM lab' <a rel="noreferrer noopener" href="https://www.youtube.com/watch?v=2XLzMb9oZBI">video</a></p><p>Eric Capuano's, 'So you want to be a SOC Analyst?' <a rel="noreferrer noopener" href="https://blog.ecapuano.com/p/so-you-want-to-be-a-soc-analyst-part">Part 1</a> &amp; <a rel="noreferrer noopener" href="https://blog.ecapuano.com/p/so-you-want-to-be-a-soc-analyst-20">Part 2</a></p><p>You can find Gerald on the various social media platforms as linked below.</p><p><a rel="noreferrer noopener" href="https://www.youtube.com/c/GeraldAuger">YouTube</a></p><p><a rel="noreferrer noopener" href="https://twitter.com/Gerald_Auger">Twitter</a></p><p><a rel="noreferrer noopener" href="https://www.linkedin.com/in/geraldauger/">LinkedIn</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 12 Jan 2024 14:38:57 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0de74429/2130fc7b.mp3" length="29827867" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/GZqiTw0IFyE36hrhAcd9oAxA168SCWKKdKE4kcVh12o/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZGVl/NDM0MmUxZmFjYTI4/NDZhODUyZDA1N2Zl/MGUzYS5wbmc.jpg"/>
      <itunes:duration>2470</itunes:duration>
      <itunes:summary>On today's episode of The Cybersecurity Defenders Podcast, we chat with Gerald Auger, Chief Content Creator at Simply Cyber.</itunes:summary>
      <itunes:subtitle>On today's episode of The Cybersecurity Defenders Podcast, we chat with Gerald Auger, Chief Content Creator at Simply Cyber.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#91 - Intel Chat: ALPHV, DanaBot?, Operation Triangulation, npm everything, &amp; Sandworm?</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>91</itunes:episode>
      <podcast:episode>91</podcast:episode>
      <itunes:title>#91 - Intel Chat: ALPHV, DanaBot?, Operation Triangulation, npm everything, &amp; Sandworm?</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6045bd46-97f4-43f6-81f3-2e762325510f</guid>
      <link>https://share.transistor.fm/s/714e4e70</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>An international group of law enforcement agencies has seized the dark web leak site of the notorious ransomware gang known as <a rel="noreferrer noopener" href="https://techcrunch.com/2023/12/19/alphv-blackcat-ransomware-seizure/">ALPHV</a>, or BlackCat.</li><li>IBM Security Trusteer uncovered a new malware campaign using JavaScript web injections with a possible connection to <a rel="noreferrer noopener" href="https://securityintelligence.com/posts/web-injections-back-on-rise-banks-affected-danabot-malware/">DanaBot</a>.</li><li>Kaspersky published some new research in which they have identified a vulnerability in Apple System on a chip - or SOC - that has played a critical role in the attacks they saw in <a rel="noreferrer noopener" href="https://www.kaspersky.com/about/press-releases/2023_kaspersky-discloses-iphone-hardware-feature-vital-in-operation-triangulation-case">Operation Triangulation</a>.</li><li>NPM package “everything” downloads millions of packages and prevents all authors on npmjs.com from removing their <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/">packages</a>.</li><li>Russian hackers were inside the Ukrainian telecom giant Kyivstar's system from at least May last year and recently caused a <a rel="noreferrer noopener" href="https://www.reuters.com/world/europe/russian-hackers-were-inside-ukraine-telecoms-giant-months-cyber-spy-chief-2024-01-04/">destructive outage</a>.</li></ul><p>And the Hacker History episodes, When the Lights Went Out in Ukraine <a rel="noreferrer noopener" href="https://limacharlie.wistia.com/medias/ntc58b66bd">Part 1</a> &amp; <a rel="noreferrer noopener" href="https://limacharlie.wistia.com/medias/gdblq02ovx">Part 2</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>An international group of law enforcement agencies has seized the dark web leak site of the notorious ransomware gang known as <a rel="noreferrer noopener" href="https://techcrunch.com/2023/12/19/alphv-blackcat-ransomware-seizure/">ALPHV</a>, or BlackCat.</li><li>IBM Security Trusteer uncovered a new malware campaign using JavaScript web injections with a possible connection to <a rel="noreferrer noopener" href="https://securityintelligence.com/posts/web-injections-back-on-rise-banks-affected-danabot-malware/">DanaBot</a>.</li><li>Kaspersky published some new research in which they have identified a vulnerability in Apple System on a chip - or SOC - that has played a critical role in the attacks they saw in <a rel="noreferrer noopener" href="https://www.kaspersky.com/about/press-releases/2023_kaspersky-discloses-iphone-hardware-feature-vital-in-operation-triangulation-case">Operation Triangulation</a>.</li><li>NPM package “everything” downloads millions of packages and prevents all authors on npmjs.com from removing their <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/">packages</a>.</li><li>Russian hackers were inside the Ukrainian telecom giant Kyivstar's system from at least May last year and recently caused a <a rel="noreferrer noopener" href="https://www.reuters.com/world/europe/russian-hackers-were-inside-ukraine-telecoms-giant-months-cyber-spy-chief-2024-01-04/">destructive outage</a>.</li></ul><p>And the Hacker History episodes, When the Lights Went Out in Ukraine <a rel="noreferrer noopener" href="https://limacharlie.wistia.com/medias/ntc58b66bd">Part 1</a> &amp; <a rel="noreferrer noopener" href="https://limacharlie.wistia.com/medias/gdblq02ovx">Part 2</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 10 Jan 2024 14:14:30 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/714e4e70/818a5374.mp3" length="23799206" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/BKFIxMGMcuJCXFkiafaI8fVc51ykggj-_6pehED8zqw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mM2Mx/ZDEzYjdmN2FmYjM5/OGE1ODU3MjFhZTUz/OTk0ZC5wbmc.jpg"/>
      <itunes:duration>1967</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#90 - The similarities between punk rock and cybersecurity with James McMurry, Founder &amp; CEO of ThreatHunter.ai</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>90</itunes:episode>
      <podcast:episode>90</podcast:episode>
      <itunes:title>#90 - The similarities between punk rock and cybersecurity with James McMurry, Founder &amp; CEO of ThreatHunter.ai</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d57ab661-c26b-4588-a300-c74e87d381f5</guid>
      <link>https://share.transistor.fm/s/381dfb00</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with James McMurry, Founder and CEO of <a rel="noreferrer noopener" href="https://threathunter.ai/">ThreatHunter.ai.</a></p><p>James is a cybersecurity veteran (and a veteran) with a career that spans over 30 years. </p><p>He's the problem-solver who sees complexity as a puzzle to unravel.</p><p>His approach goes beyond buzzwords; James transforms innovation into reality by blending AI, machine learning, and a team of human threat hunters into an effective cybersecurity strategy. </p><p>Beyond the office, James is a discerning whisk(e)y enthusiast, showcasing a refined taste that matches his coding finesse. He is also a philanthropist and the Founder of <a rel="noreferrer noopener" href="https://vetconactual.com/">VETCON</a>.</p><p>James can be found on Twitter <a rel="noreferrer noopener" href="https://twitter.com/jmcmurry">here</a>.</p><p>And on Instagram <a rel="noreferrer noopener" href="https://www.instagram.com/whiskeyhacker/?hl=en">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with James McMurry, Founder and CEO of <a rel="noreferrer noopener" href="https://threathunter.ai/">ThreatHunter.ai.</a></p><p>James is a cybersecurity veteran (and a veteran) with a career that spans over 30 years. </p><p>He's the problem-solver who sees complexity as a puzzle to unravel.</p><p>His approach goes beyond buzzwords; James transforms innovation into reality by blending AI, machine learning, and a team of human threat hunters into an effective cybersecurity strategy. </p><p>Beyond the office, James is a discerning whisk(e)y enthusiast, showcasing a refined taste that matches his coding finesse. He is also a philanthropist and the Founder of <a rel="noreferrer noopener" href="https://vetconactual.com/">VETCON</a>.</p><p>James can be found on Twitter <a rel="noreferrer noopener" href="https://twitter.com/jmcmurry">here</a>.</p><p>And on Instagram <a rel="noreferrer noopener" href="https://www.instagram.com/whiskeyhacker/?hl=en">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 05 Jan 2024 15:01:06 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/381dfb00/d274a864.mp3" length="22795212" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/1QMcEyJpQ4q5mneVULM7hUuKyMIOwULxp7rXlum-FU0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zOWQz/NDU5OGNkOGQzMGJl/MGFlZTE2YWNiZDk3/MTFlMS5wbmc.jpg"/>
      <itunes:duration>1884</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with James McMurry, Founder and CEO of ThreatHunter.ai</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with James McMurry, Founder and CEO of ThreatHunter.ai</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#89 - Hard-won entrepreneurial lessons with JP Bourget, Founder and President of Blue Cycle</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>#89 - Hard-won entrepreneurial lessons with JP Bourget, Founder and President of Blue Cycle</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3f895989-6b9a-42e4-b02e-a5d78d68bade</guid>
      <link>https://share.transistor.fm/s/53c435ae</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with JP Bourget, Founder and President of <a rel="noreferrer noopener" href="https://www.bluecycle.net/">Blue Cycle</a>, who shares some hard-won lessons from his entrepreneurial journey.</p><p>JP Bourget specializes in empowering Blue Teams and Security Operations Centers (SOCs) by implementing cutting-edge methodologies to enhance Cyber Maturity. His expertise spans automation, data engineering, API integration, and advocating security-as-code principles. Additionally, he holds the role of Entrepreneur in Residence (EIR) at <a rel="noreferrer noopener" href="https://www.lyticalventures.com/">Lytical Ventures</a>.</p><p>Previously, JP was the Founder and Chief Security Officer (CSO) of Syncurity, a company acquired by Swimlane and an early pioneer in the Security Orchestration, Automation, and Response (SOAR) landscape. Syncurity's flagship product, IR-Flow, revolutionized alert triage, allowing organizations to optimize their security efforts efficiently.</p><p>Before co-founding Syncurity, JP honed his skills as the Network Security Manager at Arnold Magnetic Technologies, a prominent global manufacturing enterprise valued at $250 million.</p><p>JP can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/jpbourget/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with JP Bourget, Founder and President of <a rel="noreferrer noopener" href="https://www.bluecycle.net/">Blue Cycle</a>, who shares some hard-won lessons from his entrepreneurial journey.</p><p>JP Bourget specializes in empowering Blue Teams and Security Operations Centers (SOCs) by implementing cutting-edge methodologies to enhance Cyber Maturity. His expertise spans automation, data engineering, API integration, and advocating security-as-code principles. Additionally, he holds the role of Entrepreneur in Residence (EIR) at <a rel="noreferrer noopener" href="https://www.lyticalventures.com/">Lytical Ventures</a>.</p><p>Previously, JP was the Founder and Chief Security Officer (CSO) of Syncurity, a company acquired by Swimlane and an early pioneer in the Security Orchestration, Automation, and Response (SOAR) landscape. Syncurity's flagship product, IR-Flow, revolutionized alert triage, allowing organizations to optimize their security efforts efficiently.</p><p>Before co-founding Syncurity, JP honed his skills as the Network Security Manager at Arnold Magnetic Technologies, a prominent global manufacturing enterprise valued at $250 million.</p><p>JP can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/jpbourget/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 03 Jan 2024 15:56:22 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/53c435ae/a9332a5c.mp3" length="23153780" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/349GHOz4tV_zIkNPdDx82gTzwld-mVMh__-0GgvTOlo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zMzJm/ZmM2MGJkMmYwNTBl/YmJkNGMzMDAzOWMz/NGJmNS5wbmc.jpg"/>
      <itunes:duration>1914</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with JP Bourget, Founder and President of Blue Cycle, who shares some hard-won lessons from his entrepreneurial journey.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we have a conversation with JP Bourget, Founder and President of Blue Cycle, who shares some hard-won lessons from his entrepreneurial journey.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Podcast trailer for 2024</title>
      <itunes:season>3</itunes:season>
      <podcast:season>3</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>Podcast trailer for 2024</itunes:title>
      <itunes:episodeType>trailer</itunes:episodeType>
      <guid isPermaLink="false">abb8a754-917e-463a-b3d9-4e4fbb389b8d</guid>
      <link>https://share.transistor.fm/s/ed29a09b</link>
      <description>
        <![CDATA[<p>Welcome to the Cybersecurity Defenders Podcast. My name is Christopher Luft, one of the founders of LimaCharlie and I am your host.</p><p>This podcast is set up as a series of segments in and around cybersecurity - with a focus on the defensive side.</p><ul><li>Tune in for weekly intelligence reports and discussions, as well as deep-dives into   major incidents like the MGM ransomware attack or the recent Okta breach with expert guests who can break down the events.</li><li>I also get the privilege of interviewing many information security experts to share their unique stories. Hear from security analysts, detection engineers, CISOs, and other high-profile public figures. </li><li>And my personal favourite, is a special segment called Hacker History where we narrate the true stories of infamous cybersecurity incidents with the help from those that were directly involved.</li></ul><p>The show is a constant work in progress and we would love for you to join us. We are always happy to hear from our listeners and encourage you to engage with us so that we can make this show the best it can be. So subscribe and follow along as we learn and grow together in this ever-evolving realm of cybersecurity.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Welcome to the Cybersecurity Defenders Podcast. My name is Christopher Luft, one of the founders of LimaCharlie and I am your host.</p><p>This podcast is set up as a series of segments in and around cybersecurity - with a focus on the defensive side.</p><ul><li>Tune in for weekly intelligence reports and discussions, as well as deep-dives into   major incidents like the MGM ransomware attack or the recent Okta breach with expert guests who can break down the events.</li><li>I also get the privilege of interviewing many information security experts to share their unique stories. Hear from security analysts, detection engineers, CISOs, and other high-profile public figures. </li><li>And my personal favourite, is a special segment called Hacker History where we narrate the true stories of infamous cybersecurity incidents with the help from those that were directly involved.</li></ul><p>The show is a constant work in progress and we would love for you to join us. We are always happy to hear from our listeners and encourage you to engage with us so that we can make this show the best it can be. So subscribe and follow along as we learn and grow together in this ever-evolving realm of cybersecurity.</p>]]>
      </content:encoded>
      <pubDate>Tue, 02 Jan 2024 14:58:57 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ed29a09b/78fe5a53.mp3" length="1770084" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>74</itunes:duration>
      <itunes:summary>Podcast trailer for 2024</itunes:summary>
      <itunes:subtitle>Podcast trailer for 2024</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#88 - Predictions for the future of cybersecurity from 2023</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>88</itunes:episode>
      <podcast:episode>88</podcast:episode>
      <itunes:title>#88 - Predictions for the future of cybersecurity from 2023</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5f8c67bd-d136-4ec1-b97f-f7d4bbf8c920</guid>
      <link>https://share.transistor.fm/s/70741b8e</link>
      <description>
        <![CDATA[<p>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2023, and bring together all of the predictions for the future of cybersecurity.</p><p>It is a fun episode, and we hope you enjoy listening to it. </p><p>And a Happy New Year to all our listeners! Wishing you security and success in 2024.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2023, and bring together all of the predictions for the future of cybersecurity.</p><p>It is a fun episode, and we hope you enjoy listening to it. </p><p>And a Happy New Year to all our listeners! Wishing you security and success in 2024.</p>]]>
      </content:encoded>
      <pubDate>Sun, 31 Dec 2023 19:30:07 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/70741b8e/d0d7e63e.mp3" length="48040678" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/kJrXC5BgdPDIfvMNWsvzs2vebkMPV2PWYL9aizDbvEE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82YTll/MzUwYjlkODVjNmIz/MTJmZGNhODcxMTZj/N2EzMC5wbmc.jpg"/>
      <itunes:duration>3987</itunes:duration>
      <itunes:summary>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2023, and bring together all of the predictions for the future of cybersecurity.</itunes:summary>
      <itunes:subtitle>A special episode of The Cybersecurity Defenders Podcast, where we look back at our conversations throughout 2023, and bring together all of the predictions for the future of cybersecurity.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#87 - Hacker History: The Colonial Pipeline</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>85</itunes:episode>
      <podcast:episode>85</podcast:episode>
      <itunes:title>#87 - Hacker History: The Colonial Pipeline</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">41184a9a-965e-4e68-899d-b036c39e34b4</guid>
      <link>https://share.transistor.fm/s/78c47a53</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at <a rel="noreferrer noopener" href="https://www.bugcrowd.com/">Bugcrowd</a>, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeline</p><p>On May 7, 2021, Colonial Pipeline, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a ransomware cyberattack that impacted computerized equipment managing the pipeline. The Colonial Pipeline Company halted all pipeline operations to contain the attack. Overseen by the FBI, the company paid the amount that was asked by the hacker group (75 bitcoin or $4.4 million USD) within several hours; upon receipt of the ransom, an IT tool was provided to the Colonial Pipeline Company by DarkSide to restore the system. However, the tool required a very long processing time to restore the system to a working state.</p><p>This episode was written by the talented <a rel="noreferrer noopener" href="https://www.linkedin.com/in/nate-nelson-75589611b/">Nathaniel Nelson</a>.</p><p>Casey Ellis can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/caseyjohnellis/">here</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at <a rel="noreferrer noopener" href="https://www.bugcrowd.com/">Bugcrowd</a>, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeline</p><p>On May 7, 2021, Colonial Pipeline, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a ransomware cyberattack that impacted computerized equipment managing the pipeline. The Colonial Pipeline Company halted all pipeline operations to contain the attack. Overseen by the FBI, the company paid the amount that was asked by the hacker group (75 bitcoin or $4.4 million USD) within several hours; upon receipt of the ransom, an IT tool was provided to the Colonial Pipeline Company by DarkSide to restore the system. However, the tool required a very long processing time to restore the system to a working state.</p><p>This episode was written by the talented <a rel="noreferrer noopener" href="https://www.linkedin.com/in/nate-nelson-75589611b/">Nathaniel Nelson</a>.</p><p>Casey Ellis can be found on LinkedIn <a rel="noreferrer noopener" href="https://www.linkedin.com/in/caseyjohnellis/">here</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 28 Dec 2023 14:08:25 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/78c47a53/2fe28387.mp3" length="15928215" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/-9HOvp1kV8KL7B2Wy-sn2hN5ZxPb2C44BA1CXDHA-HE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZGY5/ODg2N2U4YjJlYTI1/ZjllMzg3M2M3Zjg4/NjYwNi5wbmc.jpg"/>
      <itunes:duration>1311</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at Bugcrowd, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeline</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of Casey Ellis, Founder and CSO at Bugcrowd, tell the story of the largest critical infrastructure ransomware attacks in history: The Colonial Pipeli</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#86 - Intel Chat: pfSense vulnerability, Gootloader, OilRig &amp; the KV-botnet</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>85</itunes:episode>
      <podcast:episode>85</podcast:episode>
      <itunes:title>#86 - Intel Chat: pfSense vulnerability, Gootloader, OilRig &amp; the KV-botnet</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1d517edb-838f-49b7-8d3d-1056756b55a2</guid>
      <link>https://share.transistor.fm/s/590a857a</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Sonar Source are reporting on a few vulnerabilities they have found in <a rel="noreferrer noopener" href="https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/">pfSense</a>.</li><li>eSentire’s Threat Response Unit launched a multi-pronged offensive against the <a rel="noreferrer noopener" href="https://www.esentire.com/web-native-pages/gootloader-unloaded-researchers-launch-multi-pronged-offensive-against-gootloader">Gootloader</a> Initial Access-as-a-Service Operation. </li><li>ESET researchers documented a series of new <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/">OilRig downloaders</a>, all relying on legitimate cloud service providers for command and control communications.</li><li>The Black Lotus Labs team at Lumen Technologies is tracking a small or home <a rel="noreferrer noopener" href="https://blog.lumen.com/routers-roasting-on-an-open-firewall-the-kv-botnet-investigation/">office router botnet</a> that forms a covert data transfer network for advanced threat actors. </li></ul><p>You can make a donation in support of ending domestic violence through <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">Cybersecurity Cares</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Sonar Source are reporting on a few vulnerabilities they have found in <a rel="noreferrer noopener" href="https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/">pfSense</a>.</li><li>eSentire’s Threat Response Unit launched a multi-pronged offensive against the <a rel="noreferrer noopener" href="https://www.esentire.com/web-native-pages/gootloader-unloaded-researchers-launch-multi-pronged-offensive-against-gootloader">Gootloader</a> Initial Access-as-a-Service Operation. </li><li>ESET researchers documented a series of new <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/">OilRig downloaders</a>, all relying on legitimate cloud service providers for command and control communications.</li><li>The Black Lotus Labs team at Lumen Technologies is tracking a small or home <a rel="noreferrer noopener" href="https://blog.lumen.com/routers-roasting-on-an-open-firewall-the-kv-botnet-investigation/">office router botnet</a> that forms a covert data transfer network for advanced threat actors. </li></ul><p>You can make a donation in support of ending domestic violence through <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">Cybersecurity Cares</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 20 Dec 2023 22:44:30 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/590a857a/2192b1e3.mp3" length="43625346" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1818</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#85 - Going deep on Active Directory with James Potter, founder of DSE</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>85</itunes:episode>
      <podcast:episode>85</podcast:episode>
      <itunes:title>#85 - Going deep on Active Directory with James Potter, founder of DSE</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7ac59726-8805-48a0-9c48-e74c42bbb07a</guid>
      <link>https://share.transistor.fm/s/fc18749a</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a detailed conversation with James Potter, founder of <a rel="noreferrer noopener" href="https://www.dse.team/">DSE</a>, about Active Directory.</p><p>James boasts over two decades of expertise in Active Directory security, serving as a trusted consultant for major companies. His focus is on fortifying security measures and devising strategies to strengthen critical systems. He's collaborated with diverse teams, identifying vulnerabilities and implementing robust security measures while balancing cost, usability, and security for each client's specific needs.</p><p>Beyond consultancy, James proudly leads a team at DSE, providing cutting-edge security solutions to global corporations. Actively engaging in the security community, he shares insights through conferences, publications, and forums, emphasizing continuous learning and innovation to counter evolving threats.</p><p>His passion lies in aiding organizations to navigate the dynamic threat landscape, ensuring resilient security frameworks and efficient business objectives. Whether crafting secure Active Directory environments, conducting assessments, or delivering tailored training, James's dedication ensures exceptional results surpassing client expectations.</p><p>James can be found on LinkedIn here: <a rel="noreferrer noopener" href="https://www.linkedin.com/in/jamesthesecurityguy/">James Potter</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we have a detailed conversation with James Potter, founder of <a rel="noreferrer noopener" href="https://www.dse.team/">DSE</a>, about Active Directory.</p><p>James boasts over two decades of expertise in Active Directory security, serving as a trusted consultant for major companies. His focus is on fortifying security measures and devising strategies to strengthen critical systems. He's collaborated with diverse teams, identifying vulnerabilities and implementing robust security measures while balancing cost, usability, and security for each client's specific needs.</p><p>Beyond consultancy, James proudly leads a team at DSE, providing cutting-edge security solutions to global corporations. Actively engaging in the security community, he shares insights through conferences, publications, and forums, emphasizing continuous learning and innovation to counter evolving threats.</p><p>His passion lies in aiding organizations to navigate the dynamic threat landscape, ensuring resilient security frameworks and efficient business objectives. Whether crafting secure Active Directory environments, conducting assessments, or delivering tailored training, James's dedication ensures exceptional results surpassing client expectations.</p><p>James can be found on LinkedIn here: <a rel="noreferrer noopener" href="https://www.linkedin.com/in/jamesthesecurityguy/">James Potter</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 14 Dec 2023 14:49:48 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fc18749a/6083c70b.mp3" length="24074085" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/QIZsVVAEuAIMQGzxSpcNrIoYQTLnl07BoTimccmzVrw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jNWE5/MDVlYjhhZDQzNzA3/ZjcyNTQwOTYxMjgy/ZWM5Ny5wbmc.jpg"/>
      <itunes:duration>1990</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we have a detailed conversation with James Potter, founder of DSE, about Active Directory.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we have a detailed conversation with James Potter, founder of DSE, about Active Directory.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#84 - Intel Chat: Push notification surveillance, a RAT, a critical Bluetooth flaw &amp; 5Ghoul</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>84</itunes:episode>
      <podcast:episode>84</podcast:episode>
      <itunes:title>#84 - Intel Chat: Push notification surveillance, a RAT, a critical Bluetooth flaw &amp; 5Ghoul</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">eaef26f5-a12d-44b5-9019-187298e2862a</guid>
      <link>https://share.transistor.fm/s/e01528f9</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Unidentified governments are <a rel="noreferrer noopener" href="https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/">surveilling smartphone users</a> via their apps' push notifications, as reported by a US senator on December 6th.</li><li>Cyber.wtf reporting on an interesting piece of malware that turned out to be a <a rel="noreferrer noopener" href="https://cyber.wtf/2023/12/06/the-csharp-streamer-rat/">RAT written in C#</a>.</li><li>Israel’s critical infrastructure is under threat from an <a rel="noreferrer noopener" href="https://www.darkreading.com/ics-ot-security/iran-threatens-israel-critical-infrastructure-polonium-proxy">Iranian proxy hacking group</a> operating out of Lebanon.</li><li>Hacker News is reporting on a <a rel="noreferrer noopener" href="https://thehackernews.com/2023/12/new-bluetooth-flaw-let-hackers-take.html">critical Bluetooth security flaw</a> that could be exploited by threat actors to take control of Android, Linux, MacOS and iOS devices.</li><li>A collection of <a rel="noreferrer noopener" href="https://thehackernews.com/2023/12/new-5g-modems-flaws-affect-ios-devices.html">security flaws in the firmware</a> implementation of 5G mobile network modems from major chipset vendors such as MediaTek and Qualcomm impact USB and IoT modems as well as hundreds of smartphone models running Android and iOS.</li></ul><p>The Cybersecurity Cares Holiday Telethon is taking place on December 15th. More information can be found at <a rel="noreferrer noopener" href="https://cybersecurity-cares.com">cybersecurity-cares.com</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io">Slack channel</a>.</p><ul><li>Unidentified governments are <a rel="noreferrer noopener" href="https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/">surveilling smartphone users</a> via their apps' push notifications, as reported by a US senator on December 6th.</li><li>Cyber.wtf reporting on an interesting piece of malware that turned out to be a <a rel="noreferrer noopener" href="https://cyber.wtf/2023/12/06/the-csharp-streamer-rat/">RAT written in C#</a>.</li><li>Israel’s critical infrastructure is under threat from an <a rel="noreferrer noopener" href="https://www.darkreading.com/ics-ot-security/iran-threatens-israel-critical-infrastructure-polonium-proxy">Iranian proxy hacking group</a> operating out of Lebanon.</li><li>Hacker News is reporting on a <a rel="noreferrer noopener" href="https://thehackernews.com/2023/12/new-bluetooth-flaw-let-hackers-take.html">critical Bluetooth security flaw</a> that could be exploited by threat actors to take control of Android, Linux, MacOS and iOS devices.</li><li>A collection of <a rel="noreferrer noopener" href="https://thehackernews.com/2023/12/new-5g-modems-flaws-affect-ios-devices.html">security flaws in the firmware</a> implementation of 5G mobile network modems from major chipset vendors such as MediaTek and Qualcomm impact USB and IoT modems as well as hundreds of smartphone models running Android and iOS.</li></ul><p>The Cybersecurity Cares Holiday Telethon is taking place on December 15th. More information can be found at <a rel="noreferrer noopener" href="https://cybersecurity-cares.com">cybersecurity-cares.com</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 13 Dec 2023 22:56:41 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e01528f9/dfbb7ca3.mp3" length="20600572" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/2icaQTPaInRWBvJkEmePXWr0XT3fGHxZYeqDTxFwMt4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iZDcy/MmVhNDFhNWNhYzA0/M2JhN2JlZTRmM2Rh/Y2NkYS5wbmc.jpg"/>
      <itunes:duration>1701</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#83 - Intel Chat: Atomic Stealer, Okta breach grows, CrushFTP &amp; Danabot opens the door for Cactus ransomware</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>83</itunes:episode>
      <podcast:episode>83</podcast:episode>
      <itunes:title>#83 - Intel Chat: Atomic Stealer, Okta breach grows, CrushFTP &amp; Danabot opens the door for Cactus ransomware</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1b3612e6-10d5-41ca-af0c-28d41e0b85cf</guid>
      <link>https://share.transistor.fm/s/3720822b</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io">community Slack channel</a>.</p><ul><li>MalwareBytes is reporting on <a rel="noreferrer noopener" href="https://www.malwarebytes.com/blog/threat-intelligence/2023/11/atomic-stealer-distributed-to-mac-users-via-fake-browser-updates/amp">Atomic Stealer</a>, a popular information stealer for MacOS.</li><li>Identity services provider Okta has disclosed that it detected "<a rel="noreferrer noopener" href="https://thehackernews.com/2023/11/okta-discloses-additional-data-breach.html">additional threat actor activity</a>" in connection with the October 2023 breach of its support case management system.</li><li>Huntress is reporting that <a rel="noreferrer noopener" href="https://www.huntress.com/blog/mft-exploitation-and-adversary-operations">threat actors of varying types</a> continue to target managed file transfer applications for exploitation. </li><li>Microsoft has detected Danabot infections leading to hands-on-keyboard activity by ransomware operator Twisted Spider, culminating in the deployment of <a rel="noreferrer noopener" href="https://twitter.com/MsftSecIntel/status/1730383711437283757">Cactus ransomware</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io">community Slack channel</a>.</p><ul><li>MalwareBytes is reporting on <a rel="noreferrer noopener" href="https://www.malwarebytes.com/blog/threat-intelligence/2023/11/atomic-stealer-distributed-to-mac-users-via-fake-browser-updates/amp">Atomic Stealer</a>, a popular information stealer for MacOS.</li><li>Identity services provider Okta has disclosed that it detected "<a rel="noreferrer noopener" href="https://thehackernews.com/2023/11/okta-discloses-additional-data-breach.html">additional threat actor activity</a>" in connection with the October 2023 breach of its support case management system.</li><li>Huntress is reporting that <a rel="noreferrer noopener" href="https://www.huntress.com/blog/mft-exploitation-and-adversary-operations">threat actors of varying types</a> continue to target managed file transfer applications for exploitation. </li><li>Microsoft has detected Danabot infections leading to hands-on-keyboard activity by ransomware operator Twisted Spider, culminating in the deployment of <a rel="noreferrer noopener" href="https://twitter.com/MsftSecIntel/status/1730383711437283757">Cactus ransomware</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Fri, 08 Dec 2023 10:11:38 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3720822b/82da44c0.mp3" length="43997094" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/UVCHF5SERkUbNushK2NrgBOf7VRQZbaGoNwYA_yN3j0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hODc0/ZGY2OWU5ZjFjMTZh/MjUwMDA4ZjRiNGQ3/ZTY2Zi5wbmc.jpg"/>
      <itunes:duration>1834</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#82 - Decrypting Darknet Diaries: A Conversation with Jack Rhysider</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>80</itunes:episode>
      <podcast:episode>80</podcast:episode>
      <itunes:title>#82 - Decrypting Darknet Diaries: A Conversation with Jack Rhysider</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1c723bd8-c95a-4920-a151-2e4f32facda9</guid>
      <link>https://share.transistor.fm/s/aeca1eb1</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Jack Rhysider, the creator of Darknet Diaries.</p><p>Darknet Diaries is a captivating podcast that delves into the intriguing and often clandestine world of cybersecurity and hacking. Hosted by Jack Rhysider, each episode features gripping narratives that explore real-life cybercrime incidents, hacking escapades, security breaches, and the individuals involved. Rhysider skillfully combines storytelling with in-depth interviews, providing a unique and engaging perspective on the complex landscape of cybersecurity. The podcast not only highlights the darker aspects of the internet but also sheds light on the efforts of cybersecurity professionals, their challenges, and the measures taken to defend against cyber threats. With its compelling storytelling and insightful discussions, Darknet Diaries offers a fascinating glimpse into the ever-evolving world of digital security.</p><p>Learn more about the show, purchase swag, and listen to episodes at <a rel="noreferrer noopener" href="https://darknetdiaries.com/">https://darknetdiaries.com/</a></p><p>You can find Jack Rhysider on Twitter/X here: <a rel="noreferrer noopener" href="https://twitter.com/JackRhysider">@JackRhysider</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Jack Rhysider, the creator of Darknet Diaries.</p><p>Darknet Diaries is a captivating podcast that delves into the intriguing and often clandestine world of cybersecurity and hacking. Hosted by Jack Rhysider, each episode features gripping narratives that explore real-life cybercrime incidents, hacking escapades, security breaches, and the individuals involved. Rhysider skillfully combines storytelling with in-depth interviews, providing a unique and engaging perspective on the complex landscape of cybersecurity. The podcast not only highlights the darker aspects of the internet but also sheds light on the efforts of cybersecurity professionals, their challenges, and the measures taken to defend against cyber threats. With its compelling storytelling and insightful discussions, Darknet Diaries offers a fascinating glimpse into the ever-evolving world of digital security.</p><p>Learn more about the show, purchase swag, and listen to episodes at <a rel="noreferrer noopener" href="https://darknetdiaries.com/">https://darknetdiaries.com/</a></p><p>You can find Jack Rhysider on Twitter/X here: <a rel="noreferrer noopener" href="https://twitter.com/JackRhysider">@JackRhysider</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 07 Dec 2023 12:00:11 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/aeca1eb1/19adfc0d.mp3" length="29996456" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/RdFiF0Z5JR9Al1MJTgp7jt43e_LeNp5oz4HdYkh9Jq4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85MDNl/ZDA0NWVmYzM0Y2Iy/MGExODYzNWQ1OTA2/Y2Q4OS5wbmc.jpg"/>
      <itunes:duration>2484</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with Jack Rhysider, the creator of Darknet Diaries.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with Jack Rhysider, the creator of Darknet Diaries.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#81 - Intel Chat: DarkCasino, Agent Tesla, DarkGate, DiamonSleet &amp; Chimera</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>81</itunes:episode>
      <podcast:episode>81</podcast:episode>
      <itunes:title>#81 - Intel Chat: DarkCasino, Agent Tesla, DarkGate, DiamonSleet &amp; Chimera</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e8dcab72-b7f6-401a-903a-79450b4f4983</guid>
      <link>https://share.transistor.fm/s/276a2cb7</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io">community Slack channel</a>.</p><ul><li>NSFOCUS Research Labs about how the DarkCasino APT group has leveraged a recently disclosed <a rel="noreferrer noopener" href="https://securityaffairs.com/154414/apt/darkcasino-apt-exploiting-winrar-0day.html">WinRAR zero-day vulnerability</a>.</li><li>G DATA CyberDefense is reporting on a threat actor using the ZPAQ archive and .wav file extension to infect systems with <a rel="noreferrer noopener" href="https://www.gdatasoftware.com/blog/2023/11/37822-agent-tesla-zpaq">Agent Tesla</a>.</li><li>A technical analysis of DarkGate Malware-as-a-Service which is widely available on various <a rel="noreferrer noopener" href="https://blog.sekoia.io/darkgate-internals/">cybercrime forums</a> by the RastaFarEye persona.</li><li>The Micrososft Threat Intelligence team has uncovered a supply chain attack by the North Korea-based threat actor Diamond Sleet involving a <a rel="noreferrer noopener" href="https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/">malicious variant</a> of an application developed by CyberLink Corp.</li><li>The Chinese hacker group “Chimera” broke into NXP - <a rel="noreferrer noopener" href="https://nltimes.nl/2023/11/24/chinese-spies-acces-dutch-chip-maker-nxps-systems-two-years-report">a Dutch chip maker</a> - at the end of 2017 and had access to the manufacturer’s systems until the spring of 2020.</li></ul><p>To learn more about the community initiative to help end domestic violence please visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io">community Slack channel</a>.</p><ul><li>NSFOCUS Research Labs about how the DarkCasino APT group has leveraged a recently disclosed <a rel="noreferrer noopener" href="https://securityaffairs.com/154414/apt/darkcasino-apt-exploiting-winrar-0day.html">WinRAR zero-day vulnerability</a>.</li><li>G DATA CyberDefense is reporting on a threat actor using the ZPAQ archive and .wav file extension to infect systems with <a rel="noreferrer noopener" href="https://www.gdatasoftware.com/blog/2023/11/37822-agent-tesla-zpaq">Agent Tesla</a>.</li><li>A technical analysis of DarkGate Malware-as-a-Service which is widely available on various <a rel="noreferrer noopener" href="https://blog.sekoia.io/darkgate-internals/">cybercrime forums</a> by the RastaFarEye persona.</li><li>The Micrososft Threat Intelligence team has uncovered a supply chain attack by the North Korea-based threat actor Diamond Sleet involving a <a rel="noreferrer noopener" href="https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/">malicious variant</a> of an application developed by CyberLink Corp.</li><li>The Chinese hacker group “Chimera” broke into NXP - <a rel="noreferrer noopener" href="https://nltimes.nl/2023/11/24/chinese-spies-acces-dutch-chip-maker-nxps-systems-two-years-report">a Dutch chip maker</a> - at the end of 2017 and had access to the manufacturer’s systems until the spring of 2020.</li></ul><p>To learn more about the community initiative to help end domestic violence please visit <a rel="noreferrer noopener" href="https://www.cybersecurity-cares.com/">cybersecurity-cares.com</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 30 Nov 2023 15:06:50 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/276a2cb7/4e528b56.mp3" length="27975846" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/nGfxl4czMGwyn-SWG1ZB_rsk5JenL5_muZL_sqYRhS0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iNzQw/YmExMWJmNDczNzRi/YWEwMDk3YWNlZWY2/ZjViYS5wbmc.jpg"/>
      <itunes:duration>2315</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#80 - A look into the cybercriminal underworld with Jon DiMaggio, Chief Security Strategist at Analyst1</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>80</itunes:episode>
      <podcast:episode>80</podcast:episode>
      <itunes:title>#80 - A look into the cybercriminal underworld with Jon DiMaggio, Chief Security Strategist at Analyst1</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">85835d0c-2c62-4287-9dc7-6ce22674a7bf</guid>
      <link>https://share.transistor.fm/s/1ab46ca5</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a look into the cybercriminal underworld with Jon DiMaggio, Chief Security Strategist at Analyst1.</p><p>Jon DiMaggio is the chief security strategist at Analyst1 and has over 15 years of experience hunting, researching, and writing about advanced cyber threats. As a specialist in enterprise ransomware attacks and nation-state intrusions, such as”Ransom Mafia:Analysis of the World’s first Ransomware Cartel”,“Nation State Ransomware” and a “History of REvil”. He has exposed the criminal cartels behind major ransomware attacks, aided law enforcement agencies in federal indictments of nation-state attacks, and discussed his work with The New York Times, Bloomberg, Fox, CNN, Reuters, and Wired. You can find Jon speaking about his research at conferences such as RSA. Additionally, in 2022, Jon authored the book “The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime” published by No Starch Press.</p><p>You can buy “The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime” <a rel="noreferrer noopener" href="https://www.amazon.ca/Art-Cyberwarfare-Investigators-Ransomware-Cybercrime/dp/1718502141/ref=sr_1_1?hvadid=667740481140&amp;hvdev=c&amp;hvlocphy=9001616&amp;hvnetw=g&amp;hvqmt=e&amp;hvrand=4932679838120362334&amp;hvtargid=kwd-1676357932524&amp;hydadcr=5409_13351378&amp;keywords=art+of+cyberwarfare&amp;qid=1701275946&amp;sr=8-1">here</a>.</p><p>The Ransomware Diaries: <a rel="noreferrer noopener" href="https://analyst1.com/ransomware-diaries-volume-1/">Volume1</a> &amp; <a rel="noreferrer noopener" href="https://analyst1.com/ransomware-diaries-volume-2/">Volume2</a></p><p>Jon DiMaggio on <a rel="noreferrer noopener" href="https://www.linkedin.com/in/jondimaggio/">LinkedIn</a></p><p>Jon DiMaggio on <a rel="noreferrer noopener" href="https://twitter.com/Jon__DiMaggio">Twitter</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we take a look into the cybercriminal underworld with Jon DiMaggio, Chief Security Strategist at Analyst1.</p><p>Jon DiMaggio is the chief security strategist at Analyst1 and has over 15 years of experience hunting, researching, and writing about advanced cyber threats. As a specialist in enterprise ransomware attacks and nation-state intrusions, such as”Ransom Mafia:Analysis of the World’s first Ransomware Cartel”,“Nation State Ransomware” and a “History of REvil”. He has exposed the criminal cartels behind major ransomware attacks, aided law enforcement agencies in federal indictments of nation-state attacks, and discussed his work with The New York Times, Bloomberg, Fox, CNN, Reuters, and Wired. You can find Jon speaking about his research at conferences such as RSA. Additionally, in 2022, Jon authored the book “The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime” published by No Starch Press.</p><p>You can buy “The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime” <a rel="noreferrer noopener" href="https://www.amazon.ca/Art-Cyberwarfare-Investigators-Ransomware-Cybercrime/dp/1718502141/ref=sr_1_1?hvadid=667740481140&amp;hvdev=c&amp;hvlocphy=9001616&amp;hvnetw=g&amp;hvqmt=e&amp;hvrand=4932679838120362334&amp;hvtargid=kwd-1676357932524&amp;hydadcr=5409_13351378&amp;keywords=art+of+cyberwarfare&amp;qid=1701275946&amp;sr=8-1">here</a>.</p><p>The Ransomware Diaries: <a rel="noreferrer noopener" href="https://analyst1.com/ransomware-diaries-volume-1/">Volume1</a> &amp; <a rel="noreferrer noopener" href="https://analyst1.com/ransomware-diaries-volume-2/">Volume2</a></p><p>Jon DiMaggio on <a rel="noreferrer noopener" href="https://www.linkedin.com/in/jondimaggio/">LinkedIn</a></p><p>Jon DiMaggio on <a rel="noreferrer noopener" href="https://twitter.com/Jon__DiMaggio">Twitter</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Nov 2023 15:43:30 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1ab46ca5/36f10985.mp3" length="28681210" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/np3lWkiq0sHJs_fUu8RtEfL7Ej_kx6ZTUUOGlIO7NC0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85YTcw/YTEzZWI0MmJjY2Fk/MzA2MmU1NWU0N2E2/OWVhMi5wbmc.jpg"/>
      <itunes:duration>2374</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we take a look into the cybercriminal underworld with Jon DiMaggio, Chief Security Strategist at Analyst1.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we take a look into the cybercriminal underworld with Jon DiMaggio, Chief Security Strategist at Analyst1.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#79 - Intel Chat: SystemBC, Ddostf DDOS bot, ALPHV files with the SEC, &amp; LummaC2 v4.0</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>79</itunes:episode>
      <podcast:episode>79</podcast:episode>
      <itunes:title>#79 - Intel Chat: SystemBC, Ddostf DDOS bot, ALPHV files with the SEC, &amp; LummaC2 v4.0</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3e66bf98-63a6-4412-b6b7-12d77082fd9c</guid>
      <link>https://share.transistor.fm/s/917c93a0</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>A look at a versatile piece of malware that gets categorised as proxy malware, a bot, a backdoor, and even as a RAT, known as <a rel="noreferrer noopener" href="https://rexorvc0.com/2023/11/12/Swiss-Knife-SystemBC-Coroxy/">SystemBC</a>.</li><li>The AhnLab Security Emergency response Center’s analysis team has published an article outlining their recent discovery that the <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/58878/">Ddostf DDoS bot</a> is being installed on vulnerable MySQL servers.</li><li>The notorious ALPHV ransomware group has taken extortion to a new level by filing a U.S. Securities and Exchange Commission complaint against one of their alleged victims for <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/ransomware-gang-files-sec-complaint-over-victims-undisclosed-breach/">not complying with the four-day rule</a> to disclose a cyberattack.</li><li>A new Anti-Sandbox technique LummaC2 v4.0 stealer is <a rel="noreferrer noopener" href="https://outpost24.com/blog/lummac2-anti-sandbox-technique-trigonometry-human-detection/">using to avoid detonation</a> if no human mouse activity is detected, along with some other techniques being employed such as Control Flow Flattening.</li></ul><p>And you can sign up to participate in the Defender Fridays series <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">here</a>. Join us as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>A look at a versatile piece of malware that gets categorised as proxy malware, a bot, a backdoor, and even as a RAT, known as <a rel="noreferrer noopener" href="https://rexorvc0.com/2023/11/12/Swiss-Knife-SystemBC-Coroxy/">SystemBC</a>.</li><li>The AhnLab Security Emergency response Center’s analysis team has published an article outlining their recent discovery that the <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/58878/">Ddostf DDoS bot</a> is being installed on vulnerable MySQL servers.</li><li>The notorious ALPHV ransomware group has taken extortion to a new level by filing a U.S. Securities and Exchange Commission complaint against one of their alleged victims for <a rel="noreferrer noopener" href="https://www.bleepingcomputer.com/news/security/ransomware-gang-files-sec-complaint-over-victims-undisclosed-breach/">not complying with the four-day rule</a> to disclose a cyberattack.</li><li>A new Anti-Sandbox technique LummaC2 v4.0 stealer is <a rel="noreferrer noopener" href="https://outpost24.com/blog/lummac2-anti-sandbox-technique-trigonometry-human-detection/">using to avoid detonation</a> if no human mouse activity is detected, along with some other techniques being employed such as Control Flow Flattening.</li></ul><p>And you can sign up to participate in the Defender Fridays series <a rel="noreferrer noopener" href="https://limacharlie.io/defender-fridays">here</a>. Join us as we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.</p>]]>
      </content:encoded>
      <pubDate>Thu, 23 Nov 2023 14:40:43 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/917c93a0/da95de85.mp3" length="17912874" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/mF23eO3dlqCBcysXkFOOX9WlfKVdmB0yQeI3pSgpPYo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yZDVh/YWQ3NDBlYTIzNzNl/MTFkOWNkYWRkODJm/YTdjZi5wbmc.jpg"/>
      <itunes:duration>1477</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#78 - Brand and marketing for cybersecurity startups with Chris Cochran, VP &amp; Head of Marketing at AKA Identity</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>77</itunes:episode>
      <podcast:episode>77</podcast:episode>
      <itunes:title>#78 - Brand and marketing for cybersecurity startups with Chris Cochran, VP &amp; Head of Marketing at AKA Identity</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">470dc533-6cbd-4d01-9255-96e75d7a4a37</guid>
      <link>https://share.transistor.fm/s/950feab2</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk with Chris Cochran, VP &amp; Head of Marketing at <a rel="noreferrer noopener" href="https://www.akaidentity.io/">AKA Identity</a>, about brand and marketing for cybersecurity startups.</p><p>Chris Cochran is an entrepreneur who combines a wealth of experience in technology and innate creativity that has proven to be invaluable to both brands and individuals who work with him. As the Co-Founder and CEO of <a rel="noreferrer noopener" href="https://hackervalley.com/">Hacker Valley Media</a>, Chris has a unique perspective on how to craft compelling narratives that engage, inform, and entertain technical audiences. His experience in technology allows him to bring a rare depth of knowledge to any creative project, and his ability to communicate complex ideas equally clearly and entertainingly makes for a powerful combination for reaching everyone, from students to entrepreneurs.</p><p>As a US Marine veteran and former cybersecurity professional, Chris has been an intelligence analyst, incident responder, SOC analyst, threat intelligence leader, and security operations leader. On the creative side, Chris has been an award-winning podcaster, TV series showrunner, short film director, keynote speaker, event host, and writer. He is passionate about inspiring and empowering people to live out their personal and professional legend. </p><p>With his unique combination of industry knowledge and creative skills, Chris can connect with audiences in an authentic and relatable way, inspiring trust and loyalty, which are crucial elements to building a successful brand, whether personal or corporate. He has created many award-winning shows, including Hacker Valley Studio and Technically Divided, alongside his co-founder Ron Eddings; he is a highly sought-after keynote speaker in technology and helps technology brands stand out from the rest through impactful storytelling.</p><p>If you have a story to tell, an experience to create, or a community to reach, Chris can help.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk with Chris Cochran, VP &amp; Head of Marketing at <a rel="noreferrer noopener" href="https://www.akaidentity.io/">AKA Identity</a>, about brand and marketing for cybersecurity startups.</p><p>Chris Cochran is an entrepreneur who combines a wealth of experience in technology and innate creativity that has proven to be invaluable to both brands and individuals who work with him. As the Co-Founder and CEO of <a rel="noreferrer noopener" href="https://hackervalley.com/">Hacker Valley Media</a>, Chris has a unique perspective on how to craft compelling narratives that engage, inform, and entertain technical audiences. His experience in technology allows him to bring a rare depth of knowledge to any creative project, and his ability to communicate complex ideas equally clearly and entertainingly makes for a powerful combination for reaching everyone, from students to entrepreneurs.</p><p>As a US Marine veteran and former cybersecurity professional, Chris has been an intelligence analyst, incident responder, SOC analyst, threat intelligence leader, and security operations leader. On the creative side, Chris has been an award-winning podcaster, TV series showrunner, short film director, keynote speaker, event host, and writer. He is passionate about inspiring and empowering people to live out their personal and professional legend. </p><p>With his unique combination of industry knowledge and creative skills, Chris can connect with audiences in an authentic and relatable way, inspiring trust and loyalty, which are crucial elements to building a successful brand, whether personal or corporate. He has created many award-winning shows, including Hacker Valley Studio and Technically Divided, alongside his co-founder Ron Eddings; he is a highly sought-after keynote speaker in technology and helps technology brands stand out from the rest through impactful storytelling.</p><p>If you have a story to tell, an experience to create, or a community to reach, Chris can help.</p>]]>
      </content:encoded>
      <pubDate>Tue, 21 Nov 2023 15:47:12 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/950feab2/7bcec28e.mp3" length="16802617" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/b66ujMF4DhBMJnPI41PNWDoQIdb0k4191L8K7Kq8B7A/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85NTI0/MWMyNzA1MWFiZTZh/ZTk3NDE2MmM3MGM1/MDBiOC5wbmc.jpg"/>
      <itunes:duration>1384</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we talk with Chris Cochran, VP &amp;amp; Head of Marketing at AKA Identity, about brand and marketing for cybersecurity startups.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we talk with Chris Cochran, VP &amp;amp; Head of Marketing at AKA Identity, about brand and marketing for cybersecurity startups.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#77 - Intel Chat: Okta again, MuddyWater, Google Calendar Rat &amp; BiBi-Windows Wiper</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>77</itunes:episode>
      <podcast:episode>77</podcast:episode>
      <itunes:title>#77 - Intel Chat: Okta again, MuddyWater, Google Calendar Rat &amp; BiBi-Windows Wiper</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7bab0c40-6554-47ea-be61-e72ffa9799a9</guid>
      <link>https://share.transistor.fm/s/0b40cebb</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Arstechnica is reporting that identity and authentication management provider Okta has been hit by <a rel="noreferrer noopener" href="https://arstechnica.com/security/2023/11/okta-hit-by-another-breach-this-one-stealing-employee-data-from-3rd-party-vendor/">another breach</a>.</li><li>Deep Instinct’s Threat Research team has identified a new campaign from the “<a rel="noreferrer noopener" href="https://www.deepinstinct.com/blog/muddywater-en-able-spear-phishing-with-new-ttps">MuddyWater</a>” group.</li><li> Google is warning of multiple threat actors sharing a public proof-of-concept exploit that leverages its Calendar service to host <a rel="noreferrer noopener" href="https://thehackernews.com/2023/11/google-warns-of-hackers-absing-calendar.html">command-and-control infrastructure</a>.</li><li>BlackBerry Research and Intelligence Team has found a wiper variant that targets Windows systems being <a rel="noreferrer noopener" href="https://blogs.blackberry.com/en/2023/11/bibi-wiper-used-in-the-israel-hamas-war-now-runs-on-windows">deployed by hacktivists</a> in support of Hamas.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Arstechnica is reporting that identity and authentication management provider Okta has been hit by <a rel="noreferrer noopener" href="https://arstechnica.com/security/2023/11/okta-hit-by-another-breach-this-one-stealing-employee-data-from-3rd-party-vendor/">another breach</a>.</li><li>Deep Instinct’s Threat Research team has identified a new campaign from the “<a rel="noreferrer noopener" href="https://www.deepinstinct.com/blog/muddywater-en-able-spear-phishing-with-new-ttps">MuddyWater</a>” group.</li><li> Google is warning of multiple threat actors sharing a public proof-of-concept exploit that leverages its Calendar service to host <a rel="noreferrer noopener" href="https://thehackernews.com/2023/11/google-warns-of-hackers-absing-calendar.html">command-and-control infrastructure</a>.</li><li>BlackBerry Research and Intelligence Team has found a wiper variant that targets Windows systems being <a rel="noreferrer noopener" href="https://blogs.blackberry.com/en/2023/11/bibi-wiper-used-in-the-israel-hamas-war-now-runs-on-windows">deployed by hacktivists</a> in support of Hamas.</li></ul>]]>
      </content:encoded>
      <pubDate>Thu, 16 Nov 2023 07:02:20 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0b40cebb/3dc1de4d.mp3" length="42546466" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1773</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#76 - Reimagining the cyber kill chain with David Burkett</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>76</itunes:episode>
      <podcast:episode>76</podcast:episode>
      <itunes:title>#76 - Reimagining the cyber kill chain with David Burkett</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">496340d1-75c6-4d09-b98f-ac98a5480c23</guid>
      <link>https://share.transistor.fm/s/4456a854</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk with David Burkett, founder of <a rel="noreferrer noopener" href="https://www.signalblur.io/">Signalblur</a>, about reimagining the cyber kill chain from a defenders perspective.</p><p>David is a dedicated and highly experienced Cloud Detection Engineer and Security Architect, with a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.

His expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. David is proud to have been part of a security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. 

David is constantly seeking opportunities to grow and learn and is eager to connect with like-minded professionals in the cybersecurity domain. </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we talk with David Burkett, founder of <a rel="noreferrer noopener" href="https://www.signalblur.io/">Signalblur</a>, about reimagining the cyber kill chain from a defenders perspective.</p><p>David is a dedicated and highly experienced Cloud Detection Engineer and Security Architect, with a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.

His expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. David is proud to have been part of a security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. 

David is constantly seeking opportunities to grow and learn and is eager to connect with like-minded professionals in the cybersecurity domain. </p>]]>
      </content:encoded>
      <pubDate>Wed, 15 Nov 2023 14:46:34 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4456a854/3508ba80.mp3" length="32373501" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1349</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we talk with David Burkett, founder of Signalblur, about reimagining the cyber kill chain from a defenders perspective.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we talk with David Burkett, founder of Signalblur, about reimagining the cyber kill chain from a defenders perspective.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#75 - A close look at Okta's latest security breach</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>75</itunes:episode>
      <podcast:episode>75</podcast:episode>
      <itunes:title>#75 - A close look at Okta's latest security breach</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">251e3efb-58a0-4438-b068-4c41412186a0</guid>
      <link>https://share.transistor.fm/s/4f2bf185</link>
      <description>
        <![CDATA[<p>The Cybersecurity Defender's host, Christopher Luft, along with special guest Eric Capuano, walk through the available details of the most recent Okta security breach that affected 1Password, BeyondTrust, and CloudFlare.</p><p>On Friday, October 20th, Okta announced that it suffered an intrusion in its customer support system. The company confirmed that 'certain Okta customers' were affected and stated that it notified 'around 1 percent' of its 18,400 customers that they were impacted.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>The Cybersecurity Defender's host, Christopher Luft, along with special guest Eric Capuano, walk through the available details of the most recent Okta security breach that affected 1Password, BeyondTrust, and CloudFlare.</p><p>On Friday, October 20th, Okta announced that it suffered an intrusion in its customer support system. The company confirmed that 'certain Okta customers' were affected and stated that it notified 'around 1 percent' of its 18,400 customers that they were impacted.</p>]]>
      </content:encoded>
      <pubDate>Thu, 02 Nov 2023 06:04:35 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4f2bf185/136b847b.mp3" length="58893729" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2454</itunes:duration>
      <itunes:summary>The Cybersecurity Defender's host, Christopher Luft, along with special guest Eric Capuano,  walk through the available details of the most recent Okta security breach that affected 1Password, BeyondTrust, and CloudFlare.</itunes:summary>
      <itunes:subtitle>The Cybersecurity Defender's host, Christopher Luft, along with special guest Eric Capuano,  walk through the available details of the most recent Okta security breach that affected 1Password, BeyondTrust, and CloudFlare.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#74 - Hacker History: When the Lights Went Out in Ukraine (Part 2)</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>72</itunes:episode>
      <podcast:episode>72</podcast:episode>
      <itunes:title>#74 - Hacker History: When the Lights Went Out in Ukraine (Part 2)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">78a6534e-95bf-4e18-9ca1-ef9f5625cf43</guid>
      <link>https://share.transistor.fm/s/6929a32e</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we share the second part of 'When the Lights Went Out in Ukraine.'</p><p>If you haven’t already, I recommend going back now and listening to “<a rel="noreferrer noopener" href="https://limacharlie.wistia.com/medias/ntc58b66bd">When the Lights Went Out in Ukraine, Part 1</a>.”</p><p>Beginning on January 13th, 2022, a Russian APT installed wiper malware on the IT networks of government, NGO, and IT companies across Ukraine. The malicious program was designed to appear like ransomware, but contained no recovery feature – it simply destroyed any computer it wished.

Just one day later, hackers from the intelligence service of Belarus – Russia’s close ally – took down 70 websites belonging to the Ukrainian government.

This was tilling – laying down the foundation for an all-out ground attack. Plastered on the 70 downed websites was a message from the attackers: “be afraid,” they wrote,
and expect the worst.”</p><p>This episode was written by the talented Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at LimaCharlie.</p><p>And a special thank you to Robert Lipovsky for sharing his first-hand knowledge.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we share the second part of 'When the Lights Went Out in Ukraine.'</p><p>If you haven’t already, I recommend going back now and listening to “<a rel="noreferrer noopener" href="https://limacharlie.wistia.com/medias/ntc58b66bd">When the Lights Went Out in Ukraine, Part 1</a>.”</p><p>Beginning on January 13th, 2022, a Russian APT installed wiper malware on the IT networks of government, NGO, and IT companies across Ukraine. The malicious program was designed to appear like ransomware, but contained no recovery feature – it simply destroyed any computer it wished.

Just one day later, hackers from the intelligence service of Belarus – Russia’s close ally – took down 70 websites belonging to the Ukrainian government.

This was tilling – laying down the foundation for an all-out ground attack. Plastered on the 70 downed websites was a message from the attackers: “be afraid,” they wrote,
and expect the worst.”</p><p>This episode was written by the talented Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at LimaCharlie.</p><p>And a special thank you to Robert Lipovsky for sharing his first-hand knowledge.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </content:encoded>
      <pubDate>Mon, 30 Oct 2023 15:20:25 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6929a32e/2e126128.mp3" length="32142267" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1340</itunes:duration>
      <itunes:summary>This episode is the second half of a Hacker History story about Russia’s attacks on Ukraine’s power grid.</itunes:summary>
      <itunes:subtitle>This episode is the second half of a Hacker History story about Russia’s attacks on Ukraine’s power grid.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#73 - Intel Chat: macOS malware, BlackCat's Munchkin, Cisco zero-day, the Phantom Hacker, &amp; a WinRAR vuln.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>73</itunes:episode>
      <podcast:episode>73</podcast:episode>
      <itunes:title>#73 - Intel Chat: macOS malware, BlackCat's Munchkin, Cisco zero-day, the Phantom Hacker, &amp; a WinRAR vuln.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">90303c19-8789-4061-ac2f-1d81244235c5</guid>
      <link>https://share.transistor.fm/s/b5a08a92</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Sentinel One talking about emerging trends and evolving techniques for <a rel="noreferrer noopener" href="https://www.sentinelone.com/blog/macos-malware-2023-a-deep-dive-into-emerging-trends-and-evolving-techniques/">macOS malware in 2023</a></li><li>BlackCat operators recently announced new updates to their tooling, including a utility called <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/blackcat-ransomware-releases-new-utility-munchkin/">Munchkin</a></li><li>On October 16, Cisco released an advisory regarding a critical zero-day privilege escalation <a rel="noreferrer noopener" href="https://censys.com/cve-2023-20198-cisco-ios-xe-zeroday/">vulnerability in their IOS XE Web UI</a> software.</li><li>WithSecure Labs is reporting that Vietnamese cybercrime groups are using multiple different Malware as a Service infostealers and Remote Access Trojans to <a rel="noreferrer noopener" href="https://labs.withsecure.com/publications/darkgate-malware-campaign">target the digital marketing sector</a>.</li><li>The FBI in Phoenix is warning the public of a new scam dubbed “<a rel="noreferrer noopener" href="https://www.fbi.gov/contact-us/field-offices/phoenix/news/press-releases/the-phantom-hacker-fbi-phoenix-warns-public-of-new-financial-scam">The Phantom Hacker</a>.”</li><li>Google’s Threat Analysis Group has recently observed multiple government-backed hacking groups exploiting the known vulnerability, <a rel="noreferrer noopener" href="https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/">CVE-2023-38831</a>.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>Sentinel One talking about emerging trends and evolving techniques for <a rel="noreferrer noopener" href="https://www.sentinelone.com/blog/macos-malware-2023-a-deep-dive-into-emerging-trends-and-evolving-techniques/">macOS malware in 2023</a></li><li>BlackCat operators recently announced new updates to their tooling, including a utility called <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/blackcat-ransomware-releases-new-utility-munchkin/">Munchkin</a></li><li>On October 16, Cisco released an advisory regarding a critical zero-day privilege escalation <a rel="noreferrer noopener" href="https://censys.com/cve-2023-20198-cisco-ios-xe-zeroday/">vulnerability in their IOS XE Web UI</a> software.</li><li>WithSecure Labs is reporting that Vietnamese cybercrime groups are using multiple different Malware as a Service infostealers and Remote Access Trojans to <a rel="noreferrer noopener" href="https://labs.withsecure.com/publications/darkgate-malware-campaign">target the digital marketing sector</a>.</li><li>The FBI in Phoenix is warning the public of a new scam dubbed “<a rel="noreferrer noopener" href="https://www.fbi.gov/contact-us/field-offices/phoenix/news/press-releases/the-phantom-hacker-fbi-phoenix-warns-public-of-new-financial-scam">The Phantom Hacker</a>.”</li><li>Google’s Threat Analysis Group has recently observed multiple government-backed hacking groups exploiting the known vulnerability, <a rel="noreferrer noopener" href="https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/">CVE-2023-38831</a>.</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 25 Oct 2023 18:27:31 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b5a08a92/d61170ce.mp3" length="35708335" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1488</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#72 - LOLDrivers &amp; Sigma community-based detections with Nas Bencherchali, Detection Engineer &amp; Threat Researcher at Nextron Systems</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>72</itunes:episode>
      <podcast:episode>72</podcast:episode>
      <itunes:title>#72 - LOLDrivers &amp; Sigma community-based detections with Nas Bencherchali, Detection Engineer &amp; Threat Researcher at Nextron Systems</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">57a44400-42b4-43f5-9bb2-cf681e1cc1b8</guid>
      <link>https://share.transistor.fm/s/2cf57955</link>
      <description>
        <![CDATA[<p>On today’s episode, we going to be speaking with Nas Bencherchall, one of the community members behind the scenes of LOLDrivers and Sigma.</p><p>Nas is an avid learner who is passionate about all things detection, malware, DFIR, threat hunting, and Windows Internals.</p><p>Nas is one of the community members behind LOLDrivers and one of the maintainers of the SIGMA Rule Repository.</p><p>The newly re-imagined Sigma project website can be found here: <a rel="noreferrer noopener" href="https://sigmahq.io/">SigmaHQ</a></p><p>The LoLDrivers website can be found here: <a rel="noreferrer noopener" href="https://www.loldrivers.io/">LOLDrivers</a></p><p>The VS Code extension we talked about on the show can be found here: <a rel="noreferrer noopener" href="https://marketplace.visualstudio.com/items?itemName=humpalum.sigma">VSCOde Ext</a></p><p>Nas on Twitter: <a rel="noreferrer noopener" href="https://twitter.com/nas_bench">nas_bench</a> </p><p>Nas’ Blog: <a rel="noreferrer noopener" href="https://nasbench.medium.com/">nasbench</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today’s episode, we going to be speaking with Nas Bencherchall, one of the community members behind the scenes of LOLDrivers and Sigma.</p><p>Nas is an avid learner who is passionate about all things detection, malware, DFIR, threat hunting, and Windows Internals.</p><p>Nas is one of the community members behind LOLDrivers and one of the maintainers of the SIGMA Rule Repository.</p><p>The newly re-imagined Sigma project website can be found here: <a rel="noreferrer noopener" href="https://sigmahq.io/">SigmaHQ</a></p><p>The LoLDrivers website can be found here: <a rel="noreferrer noopener" href="https://www.loldrivers.io/">LOLDrivers</a></p><p>The VS Code extension we talked about on the show can be found here: <a rel="noreferrer noopener" href="https://marketplace.visualstudio.com/items?itemName=humpalum.sigma">VSCOde Ext</a></p><p>Nas on Twitter: <a rel="noreferrer noopener" href="https://twitter.com/nas_bench">nas_bench</a> </p><p>Nas’ Blog: <a rel="noreferrer noopener" href="https://nasbench.medium.com/">nasbench</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 20 Oct 2023 16:39:54 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2cf57955/f9443c05.mp3" length="34774222" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1449</itunes:duration>
      <itunes:summary>On today’s episode, we going to be speaking with Nas Bencherchall, one of the community members behind the scenes of LOLDrivers and Sigma.</itunes:summary>
      <itunes:subtitle>On today’s episode, we going to be speaking with Nas Bencherchall, one of the community members behind the scenes of LOLDrivers and Sigma.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#71 - Intel Chat: BlackTech, Lazarus, CL0P, Python supply chain, Android malware &amp; libcue 0-day</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>71</itunes:episode>
      <podcast:episode>71</podcast:episode>
      <itunes:title>#71 - Intel Chat: BlackTech, Lazarus, CL0P, Python supply chain, Android malware &amp; libcue 0-day</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7376363f-fe77-434b-a818-5b6d5d320d44</guid>
      <link>https://share.transistor.fm/s/7474ddd9</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>A <a rel="noreferrer noopener" href="https://media.defense.gov/2023/Sep/27/2003309107/-1/-1/0/CSA_BLACKTECH_HIDE_IN_ROUTERS_TLP-CLEAR.PDF">joint advisory</a> that was published by the NSA, the FBI and CISA, along with, the Japan National Police Agency and the Japan National Center of Incident Readiness and Strategy for Cybersecurity.</li><li>ESET researchers have uncovered a <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/">Lazarus attack</a> against an aerospace company in Spain.</li><li>Unit 42 at Palo Alto are reporting that the <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/cl0p-group-distributes-ransomware-data-with-torrents/">CL0P ransomware group</a> recently began using torrents to distribute victim data after a rather notorious campaign stealing data from thousands of companies.</li><li>Checkmarx is reporting on a persistent <a rel="noreferrer noopener" href="https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/">open-source supply chain attacker</a> targeting the Python ecosystem who has been active and evolving since April 2023.</li><li>Arstechnica is reporting the discovery of thousands of <a rel="noreferrer noopener" href="https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/#p3">Androids devices</a> infected with malware right out of the box.</li><li>Github Security Lab, in coordination with Ilya Lipnitskiy, has disclosed a 0-day <a rel="noreferrer noopener" href="https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/">memory corruption vulnerability</a> in libcue, noted as CVE-2023-43641. </li><li>Checkmarx reporting on a <a rel="noreferrer noopener" href="https://checkmarx.com/blog/users-of-telegram-aws-and-alibaba-cloud-targeted-in-latest-supply-chain-attack/">targeted campaign</a> that unfolded via Pypi, targeting developers utilizing Alibaba cloud services, AWS, and Telegram.</li></ul>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">Slack channel</a>.</p><ul><li>A <a rel="noreferrer noopener" href="https://media.defense.gov/2023/Sep/27/2003309107/-1/-1/0/CSA_BLACKTECH_HIDE_IN_ROUTERS_TLP-CLEAR.PDF">joint advisory</a> that was published by the NSA, the FBI and CISA, along with, the Japan National Police Agency and the Japan National Center of Incident Readiness and Strategy for Cybersecurity.</li><li>ESET researchers have uncovered a <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/">Lazarus attack</a> against an aerospace company in Spain.</li><li>Unit 42 at Palo Alto are reporting that the <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/cl0p-group-distributes-ransomware-data-with-torrents/">CL0P ransomware group</a> recently began using torrents to distribute victim data after a rather notorious campaign stealing data from thousands of companies.</li><li>Checkmarx is reporting on a persistent <a rel="noreferrer noopener" href="https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/">open-source supply chain attacker</a> targeting the Python ecosystem who has been active and evolving since April 2023.</li><li>Arstechnica is reporting the discovery of thousands of <a rel="noreferrer noopener" href="https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/#p3">Androids devices</a> infected with malware right out of the box.</li><li>Github Security Lab, in coordination with Ilya Lipnitskiy, has disclosed a 0-day <a rel="noreferrer noopener" href="https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/">memory corruption vulnerability</a> in libcue, noted as CVE-2023-43641. </li><li>Checkmarx reporting on a <a rel="noreferrer noopener" href="https://checkmarx.com/blog/users-of-telegram-aws-and-alibaba-cloud-targeted-in-latest-supply-chain-attack/">targeted campaign</a> that unfolded via Pypi, targeting developers utilizing Alibaba cloud services, AWS, and Telegram.</li></ul>]]>
      </content:encoded>
      <pubDate>Wed, 18 Oct 2023 07:20:48 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7474ddd9/3e7b2d2e.mp3" length="53658321" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>2236</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#70 - Navigating a career in cybersecurity with Sean Higgins, Co-founder of the Herjavec Group</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>70</itunes:episode>
      <podcast:episode>70</podcast:episode>
      <itunes:title>#70 - Navigating a career in cybersecurity with Sean Higgins, Co-founder of the Herjavec Group</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6c347721-ce02-44b2-a1c4-29d784229d3e</guid>
      <link>https://share.transistor.fm/s/37f46e84</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we speak with Sean Higgins, consultant, educator, and co-founder of the Herjavec Group.</p><p>Sean Higgins is a coach, speaker, author, and consultant with a specialization in cybersecurity program evaluation. With over 35 years of experience in information technology, he has dedicated nearly three decades to the field of cybersecurity. From 2003 to 2022, Sean served as the CTO and Co-founder of Herjavec Group. In his Canadian Best Selling book, "Driven," Robert Herjavec described Sean as "the smartest guy I ever met," a recognition that deeply touched him.</p><p>Today, organizations seek out Sean's expertise when they require guidance on resolving technical issues, evaluating technological solutions, or need assistance in shaping the direction of their company's security program. One of his notable strengths lies in helping Chief Information Security Officers (CISO) and senior management confidently evaluate and refine their security programs.</p><p>Sean is astounded by the rapid evolution of technology over the years. His career commenced in 1986 when he was writing programs to count light bulbs at General Electric. A few years later, he was instrumental in establishing the first computer network for the North York Public Library in Ontario, an endeavor that predates the widespread internet we know today. During those early days of the ARPANET, Sean used it to send emails to friends still at Purdue University. He also holds the distinction of being the first expert witness in a Canadian court regarding a cybersecurity incident.</p><p>Passionate about mentoring millennials in the tech industry to find balance between their professional and personal lives, Sean collaborates with various universities, including the University of York's Career Mentorship Program. Additionally, he is a member of the Case Alumni Association Scholarship Committee, where he has the honor of awarding millions of dollars in scholarships to junior and senior STEM students.</p><p>Sean's coaching approach combines elements of traditional life coaching, entrepreneurial business experience, and his ability to read energy. He has received training from the Quantum Success Coaching Academy, Enwaken Coaching, and Enwaken Apprentice programs.</p><p>Notably, Sean has self-published his first book on Amazon titled "Living Your Purposeful Life" and is currently working on his second book, "Balancing: How tech managers can avoid burnout, balance priorities, and come back to life," slated for release in January 2023.</p><p>Residing on picturesque Vancouver Island, Sean enjoys exploring the island's beauty with his faithful Golden Retriever, Rosie. He is an avid mountain biker and has recently discovered a passion for pickleball. His love for college athletics, particularly college basketball, is evident, and he especially cherishes watching his alma mater, Purdue University, during March Madness. So, reaching him during that time might prove a challenge, as he's likely to be glued to the games.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we speak with Sean Higgins, consultant, educator, and co-founder of the Herjavec Group.</p><p>Sean Higgins is a coach, speaker, author, and consultant with a specialization in cybersecurity program evaluation. With over 35 years of experience in information technology, he has dedicated nearly three decades to the field of cybersecurity. From 2003 to 2022, Sean served as the CTO and Co-founder of Herjavec Group. In his Canadian Best Selling book, "Driven," Robert Herjavec described Sean as "the smartest guy I ever met," a recognition that deeply touched him.</p><p>Today, organizations seek out Sean's expertise when they require guidance on resolving technical issues, evaluating technological solutions, or need assistance in shaping the direction of their company's security program. One of his notable strengths lies in helping Chief Information Security Officers (CISO) and senior management confidently evaluate and refine their security programs.</p><p>Sean is astounded by the rapid evolution of technology over the years. His career commenced in 1986 when he was writing programs to count light bulbs at General Electric. A few years later, he was instrumental in establishing the first computer network for the North York Public Library in Ontario, an endeavor that predates the widespread internet we know today. During those early days of the ARPANET, Sean used it to send emails to friends still at Purdue University. He also holds the distinction of being the first expert witness in a Canadian court regarding a cybersecurity incident.</p><p>Passionate about mentoring millennials in the tech industry to find balance between their professional and personal lives, Sean collaborates with various universities, including the University of York's Career Mentorship Program. Additionally, he is a member of the Case Alumni Association Scholarship Committee, where he has the honor of awarding millions of dollars in scholarships to junior and senior STEM students.</p><p>Sean's coaching approach combines elements of traditional life coaching, entrepreneurial business experience, and his ability to read energy. He has received training from the Quantum Success Coaching Academy, Enwaken Coaching, and Enwaken Apprentice programs.</p><p>Notably, Sean has self-published his first book on Amazon titled "Living Your Purposeful Life" and is currently working on his second book, "Balancing: How tech managers can avoid burnout, balance priorities, and come back to life," slated for release in January 2023.</p><p>Residing on picturesque Vancouver Island, Sean enjoys exploring the island's beauty with his faithful Golden Retriever, Rosie. He is an avid mountain biker and has recently discovered a passion for pickleball. His love for college athletics, particularly college basketball, is evident, and he especially cherishes watching his alma mater, Purdue University, during March Madness. So, reaching him during that time might prove a challenge, as he's likely to be glued to the games.</p>]]>
      </content:encoded>
      <pubDate>Fri, 13 Oct 2023 18:12:32 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/37f46e84/3b6d7ec5.mp3" length="30690305" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1279</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we speak with Sean Higgins, consultant, educator, and co-founder of the Herjavec Group.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we speak with Sean Higgins, consultant, educator, and co-founder of the Herjavec Group.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#69 - The SecOps Cloud Platform for Managed Security Service Providers</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>69</itunes:episode>
      <podcast:episode>69</podcast:episode>
      <itunes:title>#69 - The SecOps Cloud Platform for Managed Security Service Providers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">03cb7587-1840-46a2-b87a-b9808d30640b</guid>
      <link>https://share.transistor.fm/s/e3eabc12</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, a hosted panel discussion with industry leaders to explore what advantages the SecOps Cloud Platform confers for Managed Security Service Providers.</p><p>The panel is moderated by LimaCharlie Co-founder, Christopher Luft. The panel participants are:</p><p>Co-founder at Soteria, Paul Ihme</p><p>Co-founder/CTO at Horangi Security, Lee Sult</p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><p>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</p><p>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, a hosted panel discussion with industry leaders to explore what advantages the SecOps Cloud Platform confers for Managed Security Service Providers.</p><p>The panel is moderated by LimaCharlie Co-founder, Christopher Luft. The panel participants are:</p><p>Co-founder at Soteria, Paul Ihme</p><p>Co-founder/CTO at Horangi Security, Lee Sult</p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><p>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</p><p>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p>]]>
      </content:encoded>
      <pubDate>Tue, 10 Oct 2023 15:15:42 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e3eabc12/bcc9eb83.mp3" length="41898694" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:duration>1746</itunes:duration>
      <itunes:summary>On this episode of the Cybersecurity Defenders Podcast, a hosted panel discussion with industry leaders to explore what advantages the SecOps Cloud Platform confers for Managed Security Service Providers.</itunes:summary>
      <itunes:subtitle>On this episode of the Cybersecurity Defenders Podcast, a hosted panel discussion with industry leaders to explore what advantages the SecOps Cloud Platform confers for Managed Security Service Providers.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#68 - Intel Chat: Bumbebee, LockBit Gang, LUC-3, HTTPSnoop, DeadGlyph &amp; Stately Taurus + Alloy Taurus + Gelsemium</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>68</itunes:episode>
      <podcast:episode>68</podcast:episode>
      <itunes:title>#68 - Intel Chat: Bumbebee, LockBit Gang, LUC-3, HTTPSnoop, DeadGlyph &amp; Stately Taurus + Alloy Taurus + Gelsemium</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13678985</guid>
      <link>https://share.transistor.fm/s/efc2a07d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Intel471 are reporting on a campaign utilizing <a rel="noreferrer noopener" href="https://intel471.com/blog/bumblebee-loader-resurfaces-in-new-campaign">Bumblebee</a>, a type of a loader that has increasingly been used by threat actors affiliated with ransomware.</li><li>ESentire are reporting on several attacks conducted by the Russia-linked <a rel="noreferrer noopener" href="https://www.esentire.com/blog/russia-linked-lockbit-ransomware-gang-attacks-an-msp-and-two-manufacturers-using-the-targets-rmm-tools-to-infect-downstream-customers-and-employees-with-ransomware">LockBit Gang</a>.</li><li>Permiso reporting on<a rel="noreferrer noopener" href="https://permiso.io/blog/lucr-3-scattered-spider-getting-saas-y-in-the-cloud"> LUC-3</a> who overlaps with Scattered Spider.</li><li>Cisco Talos has discovered a new malware family they have dubbed HTTPSnoop being deployed against <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/introducing-shrouded-snooper/">telecommunication providers</a> in the Middle East.  </li><li>WeLiveSecurity have stumbled upon a previously unknown backdoor being deployed in the Middle East that they have named <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/stealth-falcon-preying-middle-eastern-skies-deadglyph/">DeadGlyph</a>. </li><li>Unit42 have started investigating a series of espionage attacks <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/analysis-of-three-attack-clusters-in-se-asia/">targeting a government </a>in Southeast Asia.</li></ul><p>LimaCharlie's Office Hours, where we break down some TTPs in-depth, take place every Friday at 9.00 AM PT / 12.00 PM ET. You can find more information here: <a rel="noreferrer noopener" href="https://limacharlie.io/office-hours">limacharlie.io/office-hours</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Intel471 are reporting on a campaign utilizing <a rel="noreferrer noopener" href="https://intel471.com/blog/bumblebee-loader-resurfaces-in-new-campaign">Bumblebee</a>, a type of a loader that has increasingly been used by threat actors affiliated with ransomware.</li><li>ESentire are reporting on several attacks conducted by the Russia-linked <a rel="noreferrer noopener" href="https://www.esentire.com/blog/russia-linked-lockbit-ransomware-gang-attacks-an-msp-and-two-manufacturers-using-the-targets-rmm-tools-to-infect-downstream-customers-and-employees-with-ransomware">LockBit Gang</a>.</li><li>Permiso reporting on<a rel="noreferrer noopener" href="https://permiso.io/blog/lucr-3-scattered-spider-getting-saas-y-in-the-cloud"> LUC-3</a> who overlaps with Scattered Spider.</li><li>Cisco Talos has discovered a new malware family they have dubbed HTTPSnoop being deployed against <a rel="noreferrer noopener" href="https://blog.talosintelligence.com/introducing-shrouded-snooper/">telecommunication providers</a> in the Middle East.  </li><li>WeLiveSecurity have stumbled upon a previously unknown backdoor being deployed in the Middle East that they have named <a rel="noreferrer noopener" href="https://www.welivesecurity.com/en/eset-research/stealth-falcon-preying-middle-eastern-skies-deadglyph/">DeadGlyph</a>. </li><li>Unit42 have started investigating a series of espionage attacks <a rel="noreferrer noopener" href="https://unit42.paloaltonetworks.com/analysis-of-three-attack-clusters-in-se-asia/">targeting a government </a>in Southeast Asia.</li></ul><p>LimaCharlie's Office Hours, where we break down some TTPs in-depth, take place every Friday at 9.00 AM PT / 12.00 PM ET. You can find more information here: <a rel="noreferrer noopener" href="https://limacharlie.io/office-hours">limacharlie.io/office-hours</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </content:encoded>
      <pubDate>Thu, 28 Sep 2023 13:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/efc2a07d/ba386d5b.mp3" length="34243399" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/xREOkhk_AtPyTTDEzJ1MdLndlsmHrmntOCAlFcZ2xf0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jNzY4/MjMyNDY0ZjA3YTgx/YWRhNTU2YmRmNDAx/ZDBiZC5wbmc.jpg"/>
      <itunes:duration>2838</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#67 - A close look at the MGM cyberattack</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>67</itunes:episode>
      <podcast:episode>67</podcast:episode>
      <itunes:title>#67 - A close look at the MGM cyberattack</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13638457</guid>
      <link>https://share.transistor.fm/s/bb082fae</link>
      <description>
        <![CDATA[<p>On the special episode of The Cybersecurity Defenders Podcast we take a close look at the MGM cyberattack that took place in September 2023.

On September 11 numerous MGM Resorts International properties in Las Vegas and throughout the United States were attacked by ransomware which shut down many aspects of its IT. Checking in and out, reservations, digital room keys, tickets, credit card systems, some slot machines, and even elevators at several MGM casino hotels became inoperative, forcing their staffs to use manual methods to serve their clientele, i.e. analog pen and paper. MGM filed a Form 8-K report with the SEC the next day. The relatively recent criminal hacking group Scattered Spider is believed to have used social engineering to bypass multi-factor authentication.

The published statement by Scattered Spider can be found <a rel="noreferrer noopener" href="https://gist.githubusercontent.com/BushidoUK/20b81335c6729dc8e0b5997ca83fa35f/raw/a0697117e905f5094e7a5feae928806b2ba65b20/gistfile1.txt">here</a>.

A list of APT groups/names can be found <a rel="noreferrer noopener" href="https://apt.threattracking.com/">here</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On the special episode of The Cybersecurity Defenders Podcast we take a close look at the MGM cyberattack that took place in September 2023.

On September 11 numerous MGM Resorts International properties in Las Vegas and throughout the United States were attacked by ransomware which shut down many aspects of its IT. Checking in and out, reservations, digital room keys, tickets, credit card systems, some slot machines, and even elevators at several MGM casino hotels became inoperative, forcing their staffs to use manual methods to serve their clientele, i.e. analog pen and paper. MGM filed a Form 8-K report with the SEC the next day. The relatively recent criminal hacking group Scattered Spider is believed to have used social engineering to bypass multi-factor authentication.

The published statement by Scattered Spider can be found <a rel="noreferrer noopener" href="https://gist.githubusercontent.com/BushidoUK/20b81335c6729dc8e0b5997ca83fa35f/raw/a0697117e905f5094e7a5feae928806b2ba65b20/gistfile1.txt">here</a>.

A list of APT groups/names can be found <a rel="noreferrer noopener" href="https://apt.threattracking.com/">here</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </content:encoded>
      <pubDate>Fri, 22 Sep 2023 06:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/bb082fae/75564d81.mp3" length="30915151" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/mnPwRsQlNainDDpOnd9HZoJxqujCJgLeglqO6cBwtF4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84ZWFk/MDUyMGM4MDk2YWQ3/NWJjMzliZGE0Njgw/MjQ5Mi5wbmc.jpg"/>
      <itunes:duration>2560</itunes:duration>
      <itunes:summary>On the special episode of The Cybersecurity Defenders Podcast we take a close look at the MGM cyberattack that took place in September 2023.</itunes:summary>
      <itunes:subtitle>On the special episode of The Cybersecurity Defenders Podcast we take a close look at the MGM cyberattack that took place in September 2023.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#66 - Go-to-market strategies in cybersecurity with Chad Loeven, VP Business Development at OPSWAT</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>66</itunes:episode>
      <podcast:episode>66</podcast:episode>
      <itunes:title>#66 - Go-to-market strategies in cybersecurity with Chad Loeven, VP Business Development at OPSWAT</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13628364</guid>
      <link>https://share.transistor.fm/s/c6fb1ed9</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Chad Loeven, VP Business Development at OPSWAT.

Chad Loeven is an experienced cybersecurity professional who leads OPSWAT's OEM technology licensing business and technology partners. OPSWAT technology helps secure over 150M endpoints by working with many of the world's largest technology vendors. They provide threat intelligence, malware analysis, vulnerability assessment, patch management, device compliance, and more.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Chad Loeven, VP Business Development at OPSWAT.

Chad Loeven is an experienced cybersecurity professional who leads OPSWAT's OEM technology licensing business and technology partners. OPSWAT technology helps secure over 150M endpoints by working with many of the world's largest technology vendors. They provide threat intelligence, malware analysis, vulnerability assessment, patch management, device compliance, and more.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </content:encoded>
      <pubDate>Wed, 20 Sep 2023 18:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c6fb1ed9/31f46888.mp3" length="18528835" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/RyuhKRHlsKZz6Pa4CBfXdKbxoUicrRHaa_1q35Ok2Z8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZDkw/MWQxNjZiZDFhNWQx/NjU2M2Y1ZmY5ZTkz/OTliZi5wbmc.jpg"/>
      <itunes:duration>1528</itunes:duration>
      <itunes:summary>On this episode of The Cybersecurity Defenders Podcast, we speak with Chad Loeven, VP Business Development at OPSWAT.</itunes:summary>
      <itunes:subtitle>On this episode of The Cybersecurity Defenders Podcast, we speak with Chad Loeven, VP Business Development at OPSWAT.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#65 - Intel Chat: DB#JAMMER, Chae$ malware, W3LL, APT34 deploy Side Twist Trojan and government-backed actors in North Korea target security researchers.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>65</itunes:episode>
      <podcast:episode>65</podcast:episode>
      <itunes:title>#65 - Intel Chat: DB#JAMMER, Chae$ malware, W3LL, APT34 deploy Side Twist Trojan and government-backed actors in North Korea target security researchers.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13591352</guid>
      <link>https://share.transistor.fm/s/e0e9b0ee</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Securonix Threat Labs are reporting that threat actors working as part of the <a rel="noreferrer noopener" href="https://www.securonix.com/blog/securonix-threat-labs-security-advisory-threat-actors-target-mssql-servers-in-dbjammer-to-deliver-freeworld-ransomware/">DB#JAMMER attack</a> campaigns are compromising exposed MSSQL databases using brute force attacks.</li><li> AhnLab’s Security Emergency Response Center are reporting on threat actors using phishing emails to distribute some <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/56512/">fileless malware</a>.</li><li>The researchers over at Group-IB have uncovered a covert business email compromise <a rel="noreferrer noopener" href="https://www.group-ib.com/media-center/press-releases/w3ll-phishing-report/">phishing campaign targeting Microsoft 365</a>.</li><li>NSFOCUS Security Labs captured a new APT34 phishing attack against enterprise targets that released a variant of the <a rel="noreferrer noopener" href="https://nsfocusglobal.com/apt34-unleashes-new-wave-of-phishing-attack-with-variant-of-sidetwist-trojan/">SideTwist Trojan</a> to achieve long-term control of the victim host.</li><li>Threat Analysis Group publicly disclosed a campaign from <a rel="noreferrer noopener" href="https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/">government-backed actors in North Korea</a> who used 0-day exploits to target security researchers working on vulnerability research and development. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a rel="noreferrer noopener" href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Securonix Threat Labs are reporting that threat actors working as part of the <a rel="noreferrer noopener" href="https://www.securonix.com/blog/securonix-threat-labs-security-advisory-threat-actors-target-mssql-servers-in-dbjammer-to-deliver-freeworld-ransomware/">DB#JAMMER attack</a> campaigns are compromising exposed MSSQL databases using brute force attacks.</li><li> AhnLab’s Security Emergency Response Center are reporting on threat actors using phishing emails to distribute some <a rel="noreferrer noopener" href="https://asec.ahnlab.com/en/56512/">fileless malware</a>.</li><li>The researchers over at Group-IB have uncovered a covert business email compromise <a rel="noreferrer noopener" href="https://www.group-ib.com/media-center/press-releases/w3ll-phishing-report/">phishing campaign targeting Microsoft 365</a>.</li><li>NSFOCUS Security Labs captured a new APT34 phishing attack against enterprise targets that released a variant of the <a rel="noreferrer noopener" href="https://nsfocusglobal.com/apt34-unleashes-new-wave-of-phishing-attack-with-variant-of-sidetwist-trojan/">SideTwist Trojan</a> to achieve long-term control of the victim host.</li><li>Threat Analysis Group publicly disclosed a campaign from <a rel="noreferrer noopener" href="https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/">government-backed actors in North Korea</a> who used 0-day exploits to target security researchers working on vulnerability research and development. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </content:encoded>
      <pubDate>Thu, 14 Sep 2023 14:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e0e9b0ee/5e6c0979.mp3" length="26852811" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/sHYcMlBczbFrjK-hsksCkT6TDDi9Zx-4J56FjxxCicU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81ZjVl/MTZkOGYxYjRlYTAy/ZDUyY2ZjZWE1OWZm/ZmFiNS5wbmc.jpg"/>
      <itunes:duration>2222</itunes:duration>
      <itunes:summary>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:summary>
      <itunes:subtitle>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.</itunes:subtitle>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#64 - A chat about enterprise security with Mathew Fulmer, Director of Cyber Threat Intelligence at BLOKWORX</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>64</itunes:episode>
      <podcast:episode>64</podcast:episode>
      <itunes:title>#64 - A chat about enterprise security with Mathew Fulmer, Director of Cyber Threat Intelligence at BLOKWORX</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13585128</guid>
      <link>https://share.transistor.fm/s/b99eb597</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Matthew Fulmer, Director of Cyber Threat Intelligence at <a href="https://www.blokworx.com/">BLOKWORX</a>.</p><p>With over 9 years of experience in the cyber security field, Matthew is a passionate and driven leader who strives to protect organizations from evolving and emerging threats. He has a strong background in threat intelligence, malware analysis, offensive security, and customer success, and he holds a Six Sigma Green Belt certification. As the Director of Cyber Threat Intelligence at BLOKWORX, Matthew integrates with internal teams to provide them with the latest knowledge and insights on the threat landscape and the best practices to prevent and deflect attacks.</p><p>In his previous role as the Manager of Cyber Intelligence Engineering at Deep Instinct, Matthew managed a growing team of cyber intelligence engineers who operated within the customer success organization. He was responsible for creating a new service offering, developing the professional skills of his team, analyzing threat vectors in various environments, communicating proactively with customers, creating technical articles and content, and assisting with security education. He also contributed to the malware analysis, the pre-load product, and the administrator certification course. Some of the skills that Matthew applied and enhanced in this role include network administration, information security, and technical support.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Matthew Fulmer, Director of Cyber Threat Intelligence at <a href="https://www.blokworx.com/">BLOKWORX</a>.</p><p>With over 9 years of experience in the cyber security field, Matthew is a passionate and driven leader who strives to protect organizations from evolving and emerging threats. He has a strong background in threat intelligence, malware analysis, offensive security, and customer success, and he holds a Six Sigma Green Belt certification. As the Director of Cyber Threat Intelligence at BLOKWORX, Matthew integrates with internal teams to provide them with the latest knowledge and insights on the threat landscape and the best practices to prevent and deflect attacks.</p><p>In his previous role as the Manager of Cyber Intelligence Engineering at Deep Instinct, Matthew managed a growing team of cyber intelligence engineers who operated within the customer success organization. He was responsible for creating a new service offering, developing the professional skills of his team, analyzing threat vectors in various environments, communicating proactively with customers, creating technical articles and content, and assisting with security education. He also contributed to the malware analysis, the pre-load product, and the administrator certification course. Some of the skills that Matthew applied and enhanced in this role include network administration, information security, and technical support.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 13 Sep 2023 16:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b99eb597/e957435a.mp3" length="29012839" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/MukjpV8ctI4ynfA2gN6wfYMpsXUJQMfcyGzNjh0MXIo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMTJm/M2QzZmM2YjU0MGFl/YjI2YWExMDIxZTY0/MjYwYS5wbmc.jpg"/>
      <itunes:duration>2402</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we speak with Matthew Fulmer, Director of Cyber Threat Intelligence at <a href="https://www.blokworx.com/">BLOKWORX</a>.</p><p>With over 9 years of experience in the cyber security field, Matthew is a passionate and driven leader who strives to protect organizations from evolving and emerging threats. He has a strong background in threat intelligence, malware analysis, offensive security, and customer success, and he holds a Six Sigma Green Belt certification. As the Director of Cyber Threat Intelligence at BLOKWORX, Matthew integrates with internal teams to provide them with the latest knowledge and insights on the threat landscape and the best practices to prevent and deflect attacks.</p><p>In his previous role as the Manager of Cyber Intelligence Engineering at Deep Instinct, Matthew managed a growing team of cyber intelligence engineers who operated within the customer success organization. He was responsible for creating a new service offering, developing the professional skills of his team, analyzing threat vectors in various environments, communicating proactively with customers, creating technical articles and content, and assisting with security education. He also contributed to the malware analysis, the pre-load product, and the administrator certification course. Some of the skills that Matthew applied and enhanced in this role include network administration, information security, and technical support.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#63 - The SecOps Cloud Platform for ecosystem builders</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>63</itunes:episode>
      <podcast:episode>63</podcast:episode>
      <itunes:title>#63 - The SecOps Cloud Platform for ecosystem builders</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13556310</guid>
      <link>https://share.transistor.fm/s/ba61d230</link>
      <description>
        <![CDATA[<p>A hosted panel discussion with industry leaders to explore what advantages the SecOps Cloud Platform confers for ecosystem builders.</p><p>The panel is moderated by LimaCharlie's Head of Product, Matt Bromiley. The panel participants are:</p><p>Senior Security Researcher at Thinkst, Casey Smith<br>Security Evangelist at RunZero, Huxley Barbee<br>Head of Tines Labs, John Tuckner</p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><p>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.<br>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>A hosted panel discussion with industry leaders to explore what advantages the SecOps Cloud Platform confers for ecosystem builders.</p><p>The panel is moderated by LimaCharlie's Head of Product, Matt Bromiley. The panel participants are:</p><p>Senior Security Researcher at Thinkst, Casey Smith<br>Security Evangelist at RunZero, Huxley Barbee<br>Head of Tines Labs, John Tuckner</p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><p>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.<br>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Fri, 08 Sep 2023 17:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ba61d230/5a003d48.mp3" length="19878233" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/-fvVuNrszZGAqKUHC_HASc7A03ho7NM67IUwTVU5Zaw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hY2Jh/YjQzNDU2MGJhYjVj/YjJhNTE2YzRiZWNm/MTU4MS5wbmc.jpg"/>
      <itunes:duration>1641</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>A hosted panel discussion with industry leaders to explore what advantages the SecOps Cloud Platform confers for ecosystem builders.</p><p>The panel is moderated by LimaCharlie's Head of Product, Matt Bromiley. The panel participants are:</p><p>Senior Security Researcher at Thinkst, Casey Smith<br>Security Evangelist at RunZero, Huxley Barbee<br>Head of Tines Labs, John Tuckner</p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><p>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.<br>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#62 - Cybersecurity industry trends with Ross Haleliuk, Co-Lead of the Venture in Security Angel Syndicate</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>62</itunes:episode>
      <podcast:episode>62</podcast:episode>
      <itunes:title>#62 - Cybersecurity industry trends with Ross Haleliuk, Co-Lead of the Venture in Security Angel Syndicate</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13551097</guid>
      <link>https://share.transistor.fm/s/60b5a065</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with <a href="https://www.linkedin.com/in/rosshaleliuk/">Ross Haleliuk</a>, Co-Lead of the <a href="https://www.visangels.com/">Venture in Security Angel Syndicate</a>, and Head of Product at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>Ross is a head of product at LimaCharlie - a startup that enables organisations to detect &amp; respond to threats, automate processes, and future-proof their security operations. His areas of expertise include go-to-market and product strategy, B2B product-led growth, strategic positioning, product-market fit expansion, and growth. Outside of work, Ross is a startup advisor, angel investor, frequent contributor to <a href="https://techcrunch.com/author/ross-haleliuk/">TechCrunch</a>, Forbes, and VentureBeat, and author of <a href="https://ventureinsecurity.substack.com/">VentureinSecurity</a>.net</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with <a href="https://www.linkedin.com/in/rosshaleliuk/">Ross Haleliuk</a>, Co-Lead of the <a href="https://www.visangels.com/">Venture in Security Angel Syndicate</a>, and Head of Product at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>Ross is a head of product at LimaCharlie - a startup that enables organisations to detect &amp; respond to threats, automate processes, and future-proof their security operations. His areas of expertise include go-to-market and product strategy, B2B product-led growth, strategic positioning, product-market fit expansion, and growth. Outside of work, Ross is a startup advisor, angel investor, frequent contributor to <a href="https://techcrunch.com/author/ross-haleliuk/">TechCrunch</a>, Forbes, and VentureBeat, and author of <a href="https://ventureinsecurity.substack.com/">VentureinSecurity</a>.net</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 07 Sep 2023 20:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/60b5a065/afabcddd.mp3" length="29694247" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/KSS5FNJGtBthKUo3A_eRlGTS8YFR8ClyhqL5SRNjjQg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mMzYy/MjI2NTA5M2UwMjEz/YTFlY2U2MDQ2MTc4/ZjViMS5wbmc.jpg"/>
      <itunes:duration>2459</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with <a href="https://www.linkedin.com/in/rosshaleliuk/">Ross Haleliuk</a>, Co-Lead of the <a href="https://www.visangels.com/">Venture in Security Angel Syndicate</a>, and Head of Product at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>Ross is a head of product at LimaCharlie - a startup that enables organisations to detect &amp; respond to threats, automate processes, and future-proof their security operations. His areas of expertise include go-to-market and product strategy, B2B product-led growth, strategic positioning, product-market fit expansion, and growth. Outside of work, Ross is a startup advisor, angel investor, frequent contributor to <a href="https://techcrunch.com/author/ross-haleliuk/">TechCrunch</a>, Forbes, and VentureBeat, and author of <a href="https://ventureinsecurity.substack.com/">VentureinSecurity</a>.net</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#61 - Intel Chat: QuiteRAT, CollectionRAT, Maldoc in PDF, DarkGate &amp; the FBI takes down Qakbot</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>61</itunes:episode>
      <podcast:episode>61</podcast:episode>
      <itunes:title>#61 - Intel Chat: QuiteRAT, CollectionRAT, Maldoc in PDF, DarkGate &amp; the FBI takes down Qakbot</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13510727</guid>
      <link>https://share.transistor.fm/s/6a72b2e4</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Cisco Talos reporting on both <a href="https://blog.talosintelligence.com/lazarus-quiterat/">QuiteRAT</a> and <a href="https://blog.talosintelligence.com/lazarus-collectionrat/">CollectionRAT</a> from the Lazarus Group.</li><li>JPCERT/CC has confirmed a new technique used in an attack that bypasses detection by embedding a <a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html">malicious Word file into a PDF file</a>. </li><li>Telekom Security was recently made aware via trust groups about a new malware campaign involving <a href="https://github.security.telekom.com/2023/08/darkgate-loader.html">DarkGate</a><b> .</b></li><li>The FBI and the Justice Department announced <a href="https://www.fbi.gov/news/stories/fbi-partners-dismantle-qakbot-infrastructure-in-multinational-cyber-takedown">a multinational operation</a> to disrupt and dismantle the malware and botnet known as Qakbot. </li></ul><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Cisco Talos reporting on both <a href="https://blog.talosintelligence.com/lazarus-quiterat/">QuiteRAT</a> and <a href="https://blog.talosintelligence.com/lazarus-collectionrat/">CollectionRAT</a> from the Lazarus Group.</li><li>JPCERT/CC has confirmed a new technique used in an attack that bypasses detection by embedding a <a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html">malicious Word file into a PDF file</a>. </li><li>Telekom Security was recently made aware via trust groups about a new malware campaign involving <a href="https://github.security.telekom.com/2023/08/darkgate-loader.html">DarkGate</a><b> .</b></li><li>The FBI and the Justice Department announced <a href="https://www.fbi.gov/news/stories/fbi-partners-dismantle-qakbot-infrastructure-in-multinational-cyber-takedown">a multinational operation</a> to disrupt and dismantle the malware and botnet known as Qakbot. </li></ul><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Fri, 01 Sep 2023 12:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6a72b2e4/be5dd485.mp3" length="15489527" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/am36NudPNTNN8cwG8IQE_17rdUHEyPkrK9xazsI8FPU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83MDM5/Zjg4ZmE3Yjg4ZTI5/NTY4M2NjNGRkNjE0/NWQyOC5wbmc.jpg"/>
      <itunes:duration>1275</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Cisco Talos reporting on both <a href="https://blog.talosintelligence.com/lazarus-quiterat/">QuiteRAT</a> and <a href="https://blog.talosintelligence.com/lazarus-collectionrat/">CollectionRAT</a> from the Lazarus Group.</li><li>JPCERT/CC has confirmed a new technique used in an attack that bypasses detection by embedding a <a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html">malicious Word file into a PDF file</a>. </li><li>Telekom Security was recently made aware via trust groups about a new malware campaign involving <a href="https://github.security.telekom.com/2023/08/darkgate-loader.html">DarkGate</a><b> .</b></li><li>The FBI and the Justice Department announced <a href="https://www.fbi.gov/news/stories/fbi-partners-dismantle-qakbot-infrastructure-in-multinational-cyber-takedown">a multinational operation</a> to disrupt and dismantle the malware and botnet known as Qakbot. </li></ul><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#60 - Building scalable security products quickly with the SecOps Cloud Platform</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>60</itunes:episode>
      <podcast:episode>60</podcast:episode>
      <itunes:title>#60 - Building scalable security products quickly with the SecOps Cloud Platform</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13474556</guid>
      <link>https://share.transistor.fm/s/620b8e55</link>
      <description>
        <![CDATA[<p>A hosted panel discussion with industry leaders to explore the advantages of the SecOps Cloud Platform for product builders.</p><p><br>The panel is moderated by LimaCharlie's Head of Product, <a href="https://www.linkedin.com/in/rosshaleliuk/">Ross Haleliuk</a>. The panel participants are:</p><p><br>Founder &amp; CTO of Recon InfoSec, <a href="https://www.linkedin.com/in/ecapuano/">Eric Capuano</a><br>Lead Incident Detection Engineer at Blumira, <a href="https://www.linkedin.com/in/amandaberlin/">Amanda Berlin</a></p><p><br>What is the SecOps Cloud Platform?</p><p><br>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p><br>The SecOps Cloud Platform is:</p><p><br>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.<br>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p><p><br>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>A hosted panel discussion with industry leaders to explore the advantages of the SecOps Cloud Platform for product builders.</p><p><br>The panel is moderated by LimaCharlie's Head of Product, <a href="https://www.linkedin.com/in/rosshaleliuk/">Ross Haleliuk</a>. The panel participants are:</p><p><br>Founder &amp; CTO of Recon InfoSec, <a href="https://www.linkedin.com/in/ecapuano/">Eric Capuano</a><br>Lead Incident Detection Engineer at Blumira, <a href="https://www.linkedin.com/in/amandaberlin/">Amanda Berlin</a></p><p><br>What is the SecOps Cloud Platform?</p><p><br>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p><br>The SecOps Cloud Platform is:</p><p><br>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.<br>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p><p><br>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Tue, 29 Aug 2023 10:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/620b8e55/b2dfca9a.mp3" length="18205612" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/A117FPdzseGPJc7bDtJNmrP6UROCHR87Y1LA_cbi7LM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kMjM3/ODE1ZTQzMDZmNGUx/ZjZmNWY4NTU1Nzdk/N2E4ZC5wbmc.jpg"/>
      <itunes:duration>1501</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>A hosted panel discussion with industry leaders to explore the advantages of the SecOps Cloud Platform for product builders.</p><p><br>The panel is moderated by LimaCharlie's Head of Product, <a href="https://www.linkedin.com/in/rosshaleliuk/">Ross Haleliuk</a>. The panel participants are:</p><p><br>Founder &amp; CTO of Recon InfoSec, <a href="https://www.linkedin.com/in/ecapuano/">Eric Capuano</a><br>Lead Incident Detection Engineer at Blumira, <a href="https://www.linkedin.com/in/amandaberlin/">Amanda Berlin</a></p><p><br>What is the SecOps Cloud Platform?</p><p><br>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p><br>The SecOps Cloud Platform is:</p><p><br>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.<br>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</p><p><br>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#59 - Intel Chat: Racoon stealer, Duke, WoofLocker, Cuba ransomware &amp; XLoader</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#59 - Intel Chat: Racoon stealer, Duke, WoofLocker, Cuba ransomware &amp; XLoader</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13468619</guid>
      <link>https://share.transistor.fm/s/a9cf7933</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>The return of the <a href="https://twitter.com/vxunderground/status/1691175828607111171">Racoon Stealer</a> after temporarily being disrupted.</li><li>EclecticIQ, analysts have assessed with high-confidence <a href="https://blog.eclecticiq.com/german-embassy-lure-likely-part-of-campaign-against-nato-aligned-ministries-of-foreign-affairs">two observed PDF documents </a>that are part of an ongoing campaign targeting Ministries of Foreign Affairs of NATO aligned countries.</li><li>MalwareBytes is following up on a tech support scam campaign dubbed <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/08/wooflocker2">WoofLocker</a>.</li><li>The threat research team at BlackBerry has discovered and documented new tools used by the <a href="https://blogs.blackberry.com/en/2023/08/cuba-ransomware-deploys-new-tools-targets-critical-infrastructure-sector-in-the-usa-and-it-integrator-in-latin-america">Cuba ransomware threat group</a>.</li><li>SentinelOne are reporting a new iteration of the <a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/">XLoader</a> malware-as-a-service infostealer and botnet .</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>The return of the <a href="https://twitter.com/vxunderground/status/1691175828607111171">Racoon Stealer</a> after temporarily being disrupted.</li><li>EclecticIQ, analysts have assessed with high-confidence <a href="https://blog.eclecticiq.com/german-embassy-lure-likely-part-of-campaign-against-nato-aligned-ministries-of-foreign-affairs">two observed PDF documents </a>that are part of an ongoing campaign targeting Ministries of Foreign Affairs of NATO aligned countries.</li><li>MalwareBytes is following up on a tech support scam campaign dubbed <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/08/wooflocker2">WoofLocker</a>.</li><li>The threat research team at BlackBerry has discovered and documented new tools used by the <a href="https://blogs.blackberry.com/en/2023/08/cuba-ransomware-deploys-new-tools-targets-critical-infrastructure-sector-in-the-usa-and-it-integrator-in-latin-america">Cuba ransomware threat group</a>.</li><li>SentinelOne are reporting a new iteration of the <a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/">XLoader</a> malware-as-a-service infostealer and botnet .</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Fri, 25 Aug 2023 07:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/a9cf7933/ba7778d5.mp3" length="22699189" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/XMoVOAKlnxpEcZ3LtLuEFsf2ydweKURDAo910VQaRnc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81Y2U4/NThlZjRiNzkyY2Fk/YWNmZjc4OGY0NTVi/YzUzMC5wbmc.jpg"/>
      <itunes:duration>1876</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>The return of the <a href="https://twitter.com/vxunderground/status/1691175828607111171">Racoon Stealer</a> after temporarily being disrupted.</li><li>EclecticIQ, analysts have assessed with high-confidence <a href="https://blog.eclecticiq.com/german-embassy-lure-likely-part-of-campaign-against-nato-aligned-ministries-of-foreign-affairs">two observed PDF documents </a>that are part of an ongoing campaign targeting Ministries of Foreign Affairs of NATO aligned countries.</li><li>MalwareBytes is following up on a tech support scam campaign dubbed <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/08/wooflocker2">WoofLocker</a>.</li><li>The threat research team at BlackBerry has discovered and documented new tools used by the <a href="https://blogs.blackberry.com/en/2023/08/cuba-ransomware-deploys-new-tools-targets-critical-infrastructure-sector-in-the-usa-and-it-integrator-in-latin-america">Cuba ransomware threat group</a>.</li><li>SentinelOne are reporting a new iteration of the <a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/">XLoader</a> malware-as-a-service infostealer and botnet .</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#58 - An introduction to the SecOps Cloud Platform with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#58 - An introduction to the SecOps Cloud Platform with Maxime Lamothe-Brassard, Founder &amp; CEO of LimaCharlie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13435705</guid>
      <link>https://share.transistor.fm/s/33d7abd7</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with Maxime Lamothe-Brassard, Founder &amp; CEO of <a href="https://limacharlie.io/">LimaCharlie</a>, about the SecOps Cloud Platform.</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with Maxime Lamothe-Brassard, Founder &amp; CEO of <a href="https://limacharlie.io/">LimaCharlie</a>, about the SecOps Cloud Platform.</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Sun, 20 Aug 2023 06:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/33d7abd7/10db77c1.mp3" length="5162208" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/FgYaP21cpg5faQuttJGnKtHQiekapkhshe8aTzLlxMA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84OTAw/NGVmMGZiYTg1NWM4/ZGE1OGJiMzdmZDBm/NDg2Zi5wbmc.jpg"/>
      <itunes:duration>414</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with Maxime Lamothe-Brassard, Founder &amp; CEO of <a href="https://limacharlie.io/">LimaCharlie</a>, about the SecOps Cloud Platform.</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#57 - A discussion about security research with John Hammond, Principal Security Researcher at Huntress</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#57 - A discussion about security research with John Hammond, Principal Security Researcher at Huntress</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13435686</guid>
      <link>https://share.transistor.fm/s/512b1af4</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with John Hammond, Principal Security Researcher at <a href="https://www.huntress.com/">Huntress</a>, about security research.</p><p>John Hammond is a cybersecurity researcher, educator and content creator. As part of the Threat Operations team at Huntress, John spends his days making hackers earn their access and helping tell the story. Previously, as a Department of Defense Cyber Training Academy instructor, he taught the Cyber Threat Emulation course, educating both civilian and military members on offensive Python, PowerShell, other scripting languages and the adversarial mindset. He has developed training material and information security challenges for events such as PicoCTF and competitions at DEFCON US. John speaks at security conferences such as BsidesNoVA, to students at colleges such as the US Naval Academy, and other online events including the SANS Holiday Hack Challenge/KringleCon. He is an online YouTube personality showcasing programming tutorials, CTF video walkthroughs and other cyber security content. John currently holds the following certifications: Security+, CEH, LFS, eJPT, eCPPT, PNPT, PCAP, OSWP, OSCP, OSCE, OSWE, OSEP, and OSED (OSCE(3)).</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with John Hammond, Principal Security Researcher at <a href="https://www.huntress.com/">Huntress</a>, about security research.</p><p>John Hammond is a cybersecurity researcher, educator and content creator. As part of the Threat Operations team at Huntress, John spends his days making hackers earn their access and helping tell the story. Previously, as a Department of Defense Cyber Training Academy instructor, he taught the Cyber Threat Emulation course, educating both civilian and military members on offensive Python, PowerShell, other scripting languages and the adversarial mindset. He has developed training material and information security challenges for events such as PicoCTF and competitions at DEFCON US. John speaks at security conferences such as BsidesNoVA, to students at colleges such as the US Naval Academy, and other online events including the SANS Holiday Hack Challenge/KringleCon. He is an online YouTube personality showcasing programming tutorials, CTF video walkthroughs and other cyber security content. John currently holds the following certifications: Security+, CEH, LFS, eJPT, eCPPT, PNPT, PCAP, OSWP, OSCP, OSCE, OSWE, OSEP, and OSED (OSCE(3)).</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Sun, 20 Aug 2023 06:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/512b1af4/4a53c330.mp3" length="19547620" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/EVoPSUFr6TUTtTT7rO2cdcNatlkk6nLQQhyyWsPK9pc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lNGUz/YjI1OGM3NmFmN2M3/MzE4NmU2ZGIyOTdh/NTc1YS5wbmc.jpg"/>
      <itunes:duration>1613</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with John Hammond, Principal Security Researcher at <a href="https://www.huntress.com/">Huntress</a>, about security research.</p><p>John Hammond is a cybersecurity researcher, educator and content creator. As part of the Threat Operations team at Huntress, John spends his days making hackers earn their access and helping tell the story. Previously, as a Department of Defense Cyber Training Academy instructor, he taught the Cyber Threat Emulation course, educating both civilian and military members on offensive Python, PowerShell, other scripting languages and the adversarial mindset. He has developed training material and information security challenges for events such as PicoCTF and competitions at DEFCON US. John speaks at security conferences such as BsidesNoVA, to students at colleges such as the US Naval Academy, and other online events including the SANS Holiday Hack Challenge/KringleCon. He is an online YouTube personality showcasing programming tutorials, CTF video walkthroughs and other cyber security content. John currently holds the following certifications: Security+, CEH, LFS, eJPT, eCPPT, PNPT, PCAP, OSWP, OSCP, OSCE, OSWE, OSEP, and OSED (OSCE(3)).</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#56 - Hacker History: When the Lights Went Out in Ukraine (Part 1)</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>52</itunes:episode>
      <podcast:episode>52</podcast:episode>
      <itunes:title>#56 - Hacker History: When the Lights Went Out in Ukraine (Part 1)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13427641</guid>
      <link>https://share.transistor.fm/s/1c4d9744</link>
      <description>
        <![CDATA[<p>Beginning on January 13th, 2022, a Russian APT installed wiper malware on the IT networks of government, NGO, and IT companies across Ukraine. The malicious program was designed to appear like ransomware, but contained no recovery feature – it simply destroyed any computer it wished.

Just one day later, hackers from the intelligence service of Belarus – Russia’s close ally – took down 70 websites belonging to the Ukrainian government.

This was tilling – laying down the foundation for an all-out ground attack. Plastered on the 70 downed websites was a message from the attackers: “be afraid,” they wrote,
and expect the worst.”</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Beginning on January 13th, 2022, a Russian APT installed wiper malware on the IT networks of government, NGO, and IT companies across Ukraine. The malicious program was designed to appear like ransomware, but contained no recovery feature – it simply destroyed any computer it wished.

Just one day later, hackers from the intelligence service of Belarus – Russia’s close ally – took down 70 websites belonging to the Ukrainian government.

This was tilling – laying down the foundation for an all-out ground attack. Plastered on the 70 downed websites was a message from the attackers: “be afraid,” they wrote,
and expect the worst.”</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </content:encoded>
      <pubDate>Fri, 18 Aug 2023 09:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1c4d9744/fe9de76d.mp3" length="13097877" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/BlSpVhoh9DSdTyvF5yYSMNccP7ir8jbQvcknRKCeup0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNjAx/ZDRlMWY0NzY2YWI5/NjVlYTZjY2RmZDBm/MjFiYi5wbmc.jpg"/>
      <itunes:duration>1076</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Beginning on January 13th, 2022, a Russian APT installed wiper malware on the IT networks of government, NGO, and IT companies across Ukraine. The malicious program was designed to appear like ransomware, but contained no recovery feature – it simply destroyed any computer it wished.

Just one day later, hackers from the intelligence service of Belarus – Russia’s close ally – took down 70 websites belonging to the Ukrainian government.

This was tilling – laying down the foundation for an all-out ground attack. Plastered on the 70 downed websites was a message from the attackers: “be afraid,” they wrote,
and expect the worst.”</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#55 - Intel Chat: XWorm, SugarCRM zero-day, Statc Stealer, Background Task Manager fail, Seaspy &amp; Whirlpool</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#55 - Intel Chat: XWorm, SugarCRM zero-day, Statc Stealer, Background Task Manager fail, Seaspy &amp; Whirlpool</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13414794</guid>
      <link>https://share.transistor.fm/s/f3a10021</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>A new injector written in Rust is used to inject shellcode and introduce <a href="https://www.fortinet.com/blog/threat-research/malware-distributed-via-freezers-and-syk-crypter">XWorm into a victim’s environment</a>.</li><li>Multiple cases where the SugarCRM was the initial attack vector and allowed threat actors to <a href="https://unit42.paloaltonetworks.com/sugarcrm-cloud-incident-black-hat/">gain access to AWS accounts</a>.</li><li>Statc Stealer is a sophisticated malware that infects devices powered by Windows, gains access to computer systems and <a href="https://www.zscaler.com/blogs/security-research/statc-stealer-decoding-elusive-malware-threat">steals sensitive information</a>.</li><li>Patrick Wardle's research says that macOS's Background Task Manager can be easily bypassed and that Apple failed to act on <a href="https://9to5mac.com/2023/08/14/mac-malware-background-task-manager/">his recommendations to fix it</a>.</li><li>CISA are reporting on the Seaspy and Whirlpool backdoors after obtaining <a href="https://www.cisa.gov/news-events/analysis-reports/ar23-221a">malware samples from a compromised device</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>A new injector written in Rust is used to inject shellcode and introduce <a href="https://www.fortinet.com/blog/threat-research/malware-distributed-via-freezers-and-syk-crypter">XWorm into a victim’s environment</a>.</li><li>Multiple cases where the SugarCRM was the initial attack vector and allowed threat actors to <a href="https://unit42.paloaltonetworks.com/sugarcrm-cloud-incident-black-hat/">gain access to AWS accounts</a>.</li><li>Statc Stealer is a sophisticated malware that infects devices powered by Windows, gains access to computer systems and <a href="https://www.zscaler.com/blogs/security-research/statc-stealer-decoding-elusive-malware-threat">steals sensitive information</a>.</li><li>Patrick Wardle's research says that macOS's Background Task Manager can be easily bypassed and that Apple failed to act on <a href="https://9to5mac.com/2023/08/14/mac-malware-background-task-manager/">his recommendations to fix it</a>.</li><li>CISA are reporting on the Seaspy and Whirlpool backdoors after obtaining <a href="https://www.cisa.gov/news-events/analysis-reports/ar23-221a">malware samples from a compromised device</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 16 Aug 2023 07:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/f3a10021/b0862b04.mp3" length="27796674" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/qr1kkB2DtkMvStOLyOZUXvoLk7PshLyk9LttmnhlNXM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82Nzlm/Y2M1YWExNzU4ZWQ3/OWY4MjNlMmNjYTFl/ODc5Yi5wbmc.jpg"/>
      <itunes:duration>2301</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>A new injector written in Rust is used to inject shellcode and introduce <a href="https://www.fortinet.com/blog/threat-research/malware-distributed-via-freezers-and-syk-crypter">XWorm into a victim’s environment</a>.</li><li>Multiple cases where the SugarCRM was the initial attack vector and allowed threat actors to <a href="https://unit42.paloaltonetworks.com/sugarcrm-cloud-incident-black-hat/">gain access to AWS accounts</a>.</li><li>Statc Stealer is a sophisticated malware that infects devices powered by Windows, gains access to computer systems and <a href="https://www.zscaler.com/blogs/security-research/statc-stealer-decoding-elusive-malware-threat">steals sensitive information</a>.</li><li>Patrick Wardle's research says that macOS's Background Task Manager can be easily bypassed and that Apple failed to act on <a href="https://9to5mac.com/2023/08/14/mac-malware-background-task-manager/">his recommendations to fix it</a>.</li><li>CISA are reporting on the Seaspy and Whirlpool backdoors after obtaining <a href="https://www.cisa.gov/news-events/analysis-reports/ar23-221a">malware samples from a compromised device</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#54 - A discussion about Linux ransomware with David Burkett, founder of Signalblur</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#54 - A discussion about Linux ransomware with David Burkett, founder of Signalblur</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13382581</guid>
      <link>https://share.transistor.fm/s/80b89419</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with David Burkett, Founder of <a href="https://www.signalblur.io/">Signalblur</a>, about the growing threat of Linux ransomware.</p><p>David is a dedicated and highly experienced Cloud Detection Engineer and Security Architect, with a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.</p><p>His expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. David is proud to have been part of a security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. </p><p>David is constantly seeking opportunities to grow and learn and is eager to connect with like-minded professionals in the cybersecurity domain. </p><p>The article on Linux ransomware referenced in the podcast can be found here: <a href="https://www.signalblur.io/through-the-looking-glass">A Deep Dive into Linux Ransomware Research</a></p><p>And David's previous appearance on the show can be found here: <a href="https://cybersecuritydefenderspodcast.buzzsprout.com/2050721/11705957-6-simply-cyber-report-for-nov-16-and-david-burkett-cloud-detection-engineer">Episode #6</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with David Burkett, Founder of <a href="https://www.signalblur.io/">Signalblur</a>, about the growing threat of Linux ransomware.</p><p>David is a dedicated and highly experienced Cloud Detection Engineer and Security Architect, with a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.</p><p>His expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. David is proud to have been part of a security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. </p><p>David is constantly seeking opportunities to grow and learn and is eager to connect with like-minded professionals in the cybersecurity domain. </p><p>The article on Linux ransomware referenced in the podcast can be found here: <a href="https://www.signalblur.io/through-the-looking-glass">A Deep Dive into Linux Ransomware Research</a></p><p>And David's previous appearance on the show can be found here: <a href="https://cybersecuritydefenderspodcast.buzzsprout.com/2050721/11705957-6-simply-cyber-report-for-nov-16-and-david-burkett-cloud-detection-engineer">Episode #6</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 10 Aug 2023 12:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/80b89419/30087ee8.mp3" length="12855107" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/2PNWl-3mhTjIRlRc9u-md4OBOwTwiUATCI1OZzSYgxY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zY2Y1/YWI5MjRiNGFkYmMw/NDBlYjEzMDdmMGY1/ZWE0NC5wbmc.jpg"/>
      <itunes:duration>1055</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with David Burkett, Founder of <a href="https://www.signalblur.io/">Signalblur</a>, about the growing threat of Linux ransomware.</p><p>David is a dedicated and highly experienced Cloud Detection Engineer and Security Architect, with a proven track record of building three different Cyber Security Operations Centers for multiple MSSP/MDR providers.</p><p>His expertise is backed by a strong set of GIAC certifications, including GCTI, GCIA, GPYC, and GCED... among others. David is proud to have been part of a security team that won the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Counterintelligence and Security Agency. </p><p>David is constantly seeking opportunities to grow and learn and is eager to connect with like-minded professionals in the cybersecurity domain. </p><p>The article on Linux ransomware referenced in the podcast can be found here: <a href="https://www.signalblur.io/through-the-looking-glass">A Deep Dive into Linux Ransomware Research</a></p><p>And David's previous appearance on the show can be found here: <a href="https://cybersecuritydefenderspodcast.buzzsprout.com/2050721/11705957-6-simply-cyber-report-for-nov-16-and-david-burkett-cloud-detection-engineer">Episode #6</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#53 - The future of enterprise SecOps: a panel discussion with industry leaders</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#53 - The future of enterprise SecOps: a panel discussion with industry leaders</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13340357</guid>
      <link>https://share.transistor.fm/s/ce39a8af</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we host a panel discussion with industry leaders and explore the advantages of the <a href="https://limacharlie.io/secops-cloud-platform">SecOps Cloud Platform</a> for securing enterprise organizations.</p><p>The panel is moderated by LimaCharlie's Chief Revenue Officer, Jessica Crytzer. The panel participants are:</p><p>Founder &amp; CEO of <a href="https://limacharlie.io/">LimaCharlie</a>, Maxime Lamothe-Brassard<br>Founder &amp; CEO of <a href="https://turngate.io/">Turngate</a>, Bruce Potter <br>Head of Product, <a href="https://interpressecurity.com/">Interpres Security</a>, Fred Wilmot<br>Principal Consultant at Higgins Cybersecurity Consulting, <a href="https://seanchiggins.com/">Sean Higgins</a></p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we host a panel discussion with industry leaders and explore the advantages of the <a href="https://limacharlie.io/secops-cloud-platform">SecOps Cloud Platform</a> for securing enterprise organizations.</p><p>The panel is moderated by LimaCharlie's Chief Revenue Officer, Jessica Crytzer. The panel participants are:</p><p>Founder &amp; CEO of <a href="https://limacharlie.io/">LimaCharlie</a>, Maxime Lamothe-Brassard<br>Founder &amp; CEO of <a href="https://turngate.io/">Turngate</a>, Bruce Potter <br>Head of Product, <a href="https://interpressecurity.com/">Interpres Security</a>, Fred Wilmot<br>Principal Consultant at Higgins Cybersecurity Consulting, <a href="https://seanchiggins.com/">Sean Higgins</a></p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 03 Aug 2023 14:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/ce39a8af/497c8109.mp3" length="23048398" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/306xyWkqfVFakOXK1hGiVzWtKIKLf2_urTrBV5SlTFs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZDBj/NjYwZDQwMGVhNWNj/OGYzZTA4MWEwOTAy/MjYzMi5wbmc.jpg"/>
      <itunes:duration>1905</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast we host a panel discussion with industry leaders and explore the advantages of the <a href="https://limacharlie.io/secops-cloud-platform">SecOps Cloud Platform</a> for securing enterprise organizations.</p><p>The panel is moderated by LimaCharlie's Chief Revenue Officer, Jessica Crytzer. The panel participants are:</p><p>Founder &amp; CEO of <a href="https://limacharlie.io/">LimaCharlie</a>, Maxime Lamothe-Brassard<br>Founder &amp; CEO of <a href="https://turngate.io/">Turngate</a>, Bruce Potter <br>Head of Product, <a href="https://interpressecurity.com/">Interpres Security</a>, Fred Wilmot<br>Principal Consultant at Higgins Cybersecurity Consulting, <a href="https://seanchiggins.com/">Sean Higgins</a></p><p>What is the SecOps Cloud Platform?</p><p>The SecOps Cloud Platform is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#52 - Intel Chat: Mallox, Decoy Dog, Casbaneiro, Nitrogen, search-ms exploit, &amp; the BlackLotus</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#52 - Intel Chat: Mallox, Decoy Dog, Casbaneiro, Nitrogen, search-ms exploit, &amp; the BlackLotus</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13335128</guid>
      <link>https://share.transistor.fm/s/6c909530</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Decoy Dog is a malware toolkit that <a href="https://insights.infoblox.com/resources-whitepaper/infoblox-whitepaper-decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns">cleverly uses DNS </a>to perform command and control.</li><li>Breaking down the infection chain for Casbaneiro, <a href="https://blog.sygnia.co/breaking-down-casbaneiro-infection-chain-part2">another banking trojan</a> targeting Latin America.</li><li>An initial-access malware campaign that leverages malicious advertising - or malvertising - to impersonate legitimate software and <a href="https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/">compromise business networks</a>.</li><li>The VirusTotal Malware Trends Report: <a href="https://blog.virustotal.com/2023/07/virustotal-malware-trends-report.html?m=1">Emerging Formats and Delivery Techniques</a>.</li><li>Trellix Advanced Research Center who have identified a novel method for <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html">exploiting the ‘search-ms” protocol handler</a>.</li><li>The source code of the BlackLotus Unified Extensible Firmware Interface - or UEFI - <a href="https://securityaffairs.com/148482/malware/source-code-blacklotus-uefi-bootkit-leaked.html?amp=1">rootkit was leaked on GitHub</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Decoy Dog is a malware toolkit that <a href="https://insights.infoblox.com/resources-whitepaper/infoblox-whitepaper-decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns">cleverly uses DNS </a>to perform command and control.</li><li>Breaking down the infection chain for Casbaneiro, <a href="https://blog.sygnia.co/breaking-down-casbaneiro-infection-chain-part2">another banking trojan</a> targeting Latin America.</li><li>An initial-access malware campaign that leverages malicious advertising - or malvertising - to impersonate legitimate software and <a href="https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/">compromise business networks</a>.</li><li>The VirusTotal Malware Trends Report: <a href="https://blog.virustotal.com/2023/07/virustotal-malware-trends-report.html?m=1">Emerging Formats and Delivery Techniques</a>.</li><li>Trellix Advanced Research Center who have identified a novel method for <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html">exploiting the ‘search-ms” protocol handler</a>.</li><li>The source code of the BlackLotus Unified Extensible Firmware Interface - or UEFI - <a href="https://securityaffairs.com/148482/malware/source-code-blacklotus-uefi-bootkit-leaked.html?amp=1">rootkit was leaked on GitHub</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 02 Aug 2023 05:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6c909530/159bc431.mp3" length="28898394" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/7c53Yg10-CWkammr3X_orj0zPeGFKEQCue8dyrms4oY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81NDhj/NmNlYmY2NWM1NWYz/MWQwMGFmMzc3Y2Y1/ZmMyMi5wbmc.jpg"/>
      <itunes:duration>2392</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Decoy Dog is a malware toolkit that <a href="https://insights.infoblox.com/resources-whitepaper/infoblox-whitepaper-decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns">cleverly uses DNS </a>to perform command and control.</li><li>Breaking down the infection chain for Casbaneiro, <a href="https://blog.sygnia.co/breaking-down-casbaneiro-infection-chain-part2">another banking trojan</a> targeting Latin America.</li><li>An initial-access malware campaign that leverages malicious advertising - or malvertising - to impersonate legitimate software and <a href="https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/">compromise business networks</a>.</li><li>The VirusTotal Malware Trends Report: <a href="https://blog.virustotal.com/2023/07/virustotal-malware-trends-report.html?m=1">Emerging Formats and Delivery Techniques</a>.</li><li>Trellix Advanced Research Center who have identified a novel method for <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html">exploiting the ‘search-ms” protocol handler</a>.</li><li>The source code of the BlackLotus Unified Extensible Firmware Interface - or UEFI - <a href="https://securityaffairs.com/148482/malware/source-code-blacklotus-uefi-bootkit-leaked.html?amp=1">rootkit was leaked on GitHub</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#51 - Building high-performance cybersecurity teams: a chat with David Seidman, Head of Detection &amp; Response at Robinhood</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>38</itunes:episode>
      <podcast:episode>38</podcast:episode>
      <itunes:title>#51 - Building high-performance cybersecurity teams: a chat with David Seidman, Head of Detection &amp; Response at Robinhood</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13301841</guid>
      <link>https://share.transistor.fm/s/1ba34db9</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with David Seidman, Head of Detection &amp; Response at <a href="https://robinhood.com/us/en/">Robinhood</a>, about building high-performance teams.</p><p>David manages the Detection &amp; Response team at Robinhood,  and is responsible for detection, incident response, and D&amp;R infrastructure. Robinhood's Platform team develops the "pipes and engines": log ETL, transport, data lake, Splunk, SIEM, SOAR, experimental tech, etc. Robinhood emphasizes engineering excellence and agility - they are moving fast and getting a lot done. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with David Seidman, Head of Detection &amp; Response at <a href="https://robinhood.com/us/en/">Robinhood</a>, about building high-performance teams.</p><p>David manages the Detection &amp; Response team at Robinhood,  and is responsible for detection, incident response, and D&amp;R infrastructure. Robinhood's Platform team develops the "pipes and engines": log ETL, transport, data lake, Splunk, SIEM, SOAR, experimental tech, etc. Robinhood emphasizes engineering excellence and agility - they are moving fast and getting a lot done. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 27 Jul 2023 17:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1ba34db9/cdda9101.mp3" length="21554488" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/slpuubMQQyI4f1F64OPjbNlolYgk4yNAzRZznt2_o40/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kYWRm/MWI5NmVjNzdjYWRk/ZmNlMzJlMjE5ZTI5/MjcwMy5wbmc.jpg"/>
      <itunes:duration>1780</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we chat with David Seidman, Head of Detection &amp; Response at <a href="https://robinhood.com/us/en/">Robinhood</a>, about building high-performance teams.</p><p>David manages the Detection &amp; Response team at Robinhood,  and is responsible for detection, incident response, and D&amp;R infrastructure. Robinhood's Platform team develops the "pipes and engines": log ETL, transport, data lake, Splunk, SIEM, SOAR, experimental tech, etc. Robinhood emphasizes engineering excellence and agility - they are moving fast and getting a lot done. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#50 - Intel Chat: AgentTesla, Cobalt Strike, njRAT, LokiBot, SophosEncrypt, BundleBot, and targetted OSS supply chain attacks</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>37</itunes:episode>
      <podcast:episode>37</podcast:episode>
      <itunes:title>#50 - Intel Chat: AgentTesla, Cobalt Strike, njRAT, LokiBot, SophosEncrypt, BundleBot, and targetted OSS supply chain attacks</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13291635</guid>
      <link>https://share.transistor.fm/s/2ae2b741</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Cisco Talos has discovered a <a href="https://blog.talosintelligence.com/malicious-campaigns-target-entities-in-ukraine-poland/">threat actor conducting several campaigns</a> against government entities, military organizations, and civilian users in Ukraine and Poland.</li><li>FortiGuard Labs investigation the researchers came across several Malicious Office documents <a href="https://www.fortinet.com/blog/threat-research/lokibot-targets-microsoft-office-document-using-vulnerabilities-and-macros">designed to exploit known vulnerabilities</a>.</li><li>Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called <a href="https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/">SophosEncrypt</a>.</li><li>CheckMarx is reporting the first known targeted OSS supply chain <a href="https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/">attacks against the banking sector</a>.</li></ul><p>The LimaCharlie SecOps Cloud Platform provides organizations with comprehensive enterprise protection that brings together critical cybersecurity capabilities and eliminates integration challenges and security gaps for more effective protection against today’s threats.</p><p>Watch the SecOps Cloud Platform panel discussions here: <a href="https://www.youtube.com/watch?v=-WcrcgYF_q0">Introducing the SecOps Cloud Platform</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Cisco Talos has discovered a <a href="https://blog.talosintelligence.com/malicious-campaigns-target-entities-in-ukraine-poland/">threat actor conducting several campaigns</a> against government entities, military organizations, and civilian users in Ukraine and Poland.</li><li>FortiGuard Labs investigation the researchers came across several Malicious Office documents <a href="https://www.fortinet.com/blog/threat-research/lokibot-targets-microsoft-office-document-using-vulnerabilities-and-macros">designed to exploit known vulnerabilities</a>.</li><li>Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called <a href="https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/">SophosEncrypt</a>.</li><li>CheckMarx is reporting the first known targeted OSS supply chain <a href="https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/">attacks against the banking sector</a>.</li></ul><p>The LimaCharlie SecOps Cloud Platform provides organizations with comprehensive enterprise protection that brings together critical cybersecurity capabilities and eliminates integration challenges and security gaps for more effective protection against today’s threats.</p><p>Watch the SecOps Cloud Platform panel discussions here: <a href="https://www.youtube.com/watch?v=-WcrcgYF_q0">Introducing the SecOps Cloud Platform</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 26 Jul 2023 07:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2ae2b741/38d46b93.mp3" length="18940161" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/9GuopwXMrzG9UJArw7ONLYxqIU5jphFg2_zOLSC6ca4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNDBm/ZDQwYzQ3NGU4YmI2/ZTdlMjhiMzU3YWU1/ZGU5Yi5wbmc.jpg"/>
      <itunes:duration>1562</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>Cisco Talos has discovered a <a href="https://blog.talosintelligence.com/malicious-campaigns-target-entities-in-ukraine-poland/">threat actor conducting several campaigns</a> against government entities, military organizations, and civilian users in Ukraine and Poland.</li><li>FortiGuard Labs investigation the researchers came across several Malicious Office documents <a href="https://www.fortinet.com/blog/threat-research/lokibot-targets-microsoft-office-document-using-vulnerabilities-and-macros">designed to exploit known vulnerabilities</a>.</li><li>Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called <a href="https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/">SophosEncrypt</a>.</li><li>CheckMarx is reporting the first known targeted OSS supply chain <a href="https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/">attacks against the banking sector</a>.</li></ul><p>The LimaCharlie SecOps Cloud Platform provides organizations with comprehensive enterprise protection that brings together critical cybersecurity capabilities and eliminates integration challenges and security gaps for more effective protection against today’s threats.</p><p>Watch the SecOps Cloud Platform panel discussions here: <a href="https://www.youtube.com/watch?v=-WcrcgYF_q0">Introducing the SecOps Cloud Platform</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#49 - The history of LimaCharlie with Founder &amp; CEO, Maxime Lamothe-Brassard</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>36</itunes:episode>
      <podcast:episode>36</podcast:episode>
      <itunes:title>#49 - The history of LimaCharlie with Founder &amp; CEO, Maxime Lamothe-Brassard</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13262241</guid>
      <link>https://share.transistor.fm/s/7a35a90d</link>
      <description>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we sit down with <a href="https://limacharlie.io">LimaCharlie</a> Founder &amp; CEO, Maxime Lamothe-Brassard, and talk about the history and vision of the SecOps Cloud Platform.</p><p><b>About the SecOps Cloud Platform:</b></p><p><a href="https://limacharlie.io/secops-cloud-platform">The SecOps Cloud Platform</a> is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p><b>About Maxime:<br></b><br>After graduating from the University of Victoria with a degree in Computer Science Maxime began his career in cybersecurity working for the Canadian Government as part of the Communications Security Establishment (CSE). CSE is Canada's national cryptologic agency, providing the Government of Canada with information technology security and foreign signals intelligence. As part of the Canadian Intelligence apparatus, Maxime worked in positions ranging from the development of cyber defense technologies, Counter Computer Network Exploitation and Counter Intelligence.</p><p>After leaving the government, Maxime provided direct help to private and public organizations in matters of cyber defense. He was an early employee at Crowdstrike, then worked for Google where he eventually landed in Google X. Maxime left Google X - where he was a founding member of Chronicle Security - in 2018 to found <a href="https://limacharlie.io">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we sit down with <a href="https://limacharlie.io">LimaCharlie</a> Founder &amp; CEO, Maxime Lamothe-Brassard, and talk about the history and vision of the SecOps Cloud Platform.</p><p><b>About the SecOps Cloud Platform:</b></p><p><a href="https://limacharlie.io/secops-cloud-platform">The SecOps Cloud Platform</a> is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p><b>About Maxime:<br></b><br>After graduating from the University of Victoria with a degree in Computer Science Maxime began his career in cybersecurity working for the Canadian Government as part of the Communications Security Establishment (CSE). CSE is Canada's national cryptologic agency, providing the Government of Canada with information technology security and foreign signals intelligence. As part of the Canadian Intelligence apparatus, Maxime worked in positions ranging from the development of cyber defense technologies, Counter Computer Network Exploitation and Counter Intelligence.</p><p>After leaving the government, Maxime provided direct help to private and public organizations in matters of cyber defense. He was an early employee at Crowdstrike, then worked for Google where he eventually landed in Google X. Maxime left Google X - where he was a founding member of Chronicle Security - in 2018 to found <a href="https://limacharlie.io">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Fri, 21 Jul 2023 09:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7a35a90d/5d072b9f.mp3" length="28640060" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/NOk7OC-MZ4hO94KdscReh_7IL0lP80FIxDXLIQTK6Os/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82N2M5/ZjAzMzE3YTBmOGMw/MGE1NTg5ZDg2N2M2/NjdkNC5wbmc.jpg"/>
      <itunes:duration>2371</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of The Cybersecurity Defenders Podcast, we sit down with <a href="https://limacharlie.io">LimaCharlie</a> Founder &amp; CEO, Maxime Lamothe-Brassard, and talk about the history and vision of the SecOps Cloud Platform.</p><p><b>About the SecOps Cloud Platform:</b></p><p><a href="https://limacharlie.io/secops-cloud-platform">The SecOps Cloud Platform</a> is a construct for delivering the core components needed to secure and monitor any given organization: things like, deploying endpoint capabilities through a single agent regardless of the technology, alerting and correlating from logs regardless of the source, automating analysis and response regardless of the environment.</p><p>The SecOps Cloud Platform is:</p><ul><li>An environment where many solutions can exist, not as a collection of random tools, but as a series of cybersecurity solutions designed to interoperate in an un-opinionated way, from the ground up; where powerful systems can be put in place at incredible speeds.</li><li>An environment fundamentally open through APIs, documentation, integrability, affordability; making it a neutral space for all cybersecurity professionals, whether they’re in enterprise, services or vendors to build appropriate solutions.</li></ul><p>The SecOps Cloud Platform is not where data goes to die—it’s a fabric, a sandbox ready for you to use, but also ready to disseminate data and insights to other systems as needed in cost-effective ways.</p><p><b>About Maxime:<br></b><br>After graduating from the University of Victoria with a degree in Computer Science Maxime began his career in cybersecurity working for the Canadian Government as part of the Communications Security Establishment (CSE). CSE is Canada's national cryptologic agency, providing the Government of Canada with information technology security and foreign signals intelligence. As part of the Canadian Intelligence apparatus, Maxime worked in positions ranging from the development of cyber defense technologies, Counter Computer Network Exploitation and Counter Intelligence.</p><p>After leaving the government, Maxime provided direct help to private and public organizations in matters of cyber defense. He was an early employee at Crowdstrike, then worked for Google where he eventually landed in Google X. Maxime left Google X - where he was a founding member of Chronicle Security - in 2018 to found <a href="https://limacharlie.io">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#48 - Intel Chat: Rust Bucket, RedEnergy, Charming Kitten, Truebot variants, Big Head &amp; TOITOIN</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>35</itunes:episode>
      <podcast:episode>35</podcast:episode>
      <itunes:title>#48 - Intel Chat: Rust Bucket, RedEnergy, Charming Kitten, Truebot variants, Big Head &amp; TOITOIN</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13215708</guid>
      <link>https://share.transistor.fm/s/5505f8ff</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>The <a href="https://securityaffairs.com/148042/malware/rustbucket-macos-malware.html?amp=1">RustBucket malware</a> allows operators to download and execute various payloads. </li><li>Zscaler ThreatLabz researchers discovered a new <a href="https://securityaffairs.com/148193/malware/redenergy-stealer-as-a-ransomware.html?amp=1">Stealer-as-a-Ransomware named RedEnergy</a> used in attacks against energy utilities, oil, gas, telecom, and machinery sectors.</li><li>Charming Kitten sends a lure <a href="https://www.proofpoint.com/us/blog/threat-insight/welcome-new-york-exploring-ta453s-foray-lnks-and-mac-malware">masquerading as a senior fellow </a>with the Royal United Services Institute to a public media contact for a nuclear security expert at a US-based think tank focused on foreign affairs. </li><li>New Truebot malware variants deployed on networks compromised using a critical <a href="https://www.bleepingcomputer.com/news/security/cisa-netwrix-auditor-rce-bug-exploited-in-truebot-malware-attacks/">remote code execution</a> vulnerability in the Netwrix Auditor software.</li><li>TrendMicro is reporting <a href="https://www.trendmicro.com/en_us/research/23/g/tailing-big-head-ransomware-variants-tactics-and-impact.html">a new ransomware family</a> and its variant named Big Head.</li><li>Zscaler ThreatLabz has recently uncovered a <a href="https://www.zscaler.com/blogs/security-research/toitoin-trojan-analyzing-new-multi-stage-attack-targeting-latam-region">new targeted attack campaign</a> striking businesses in the Latin American region.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>The <a href="https://securityaffairs.com/148042/malware/rustbucket-macos-malware.html?amp=1">RustBucket malware</a> allows operators to download and execute various payloads. </li><li>Zscaler ThreatLabz researchers discovered a new <a href="https://securityaffairs.com/148193/malware/redenergy-stealer-as-a-ransomware.html?amp=1">Stealer-as-a-Ransomware named RedEnergy</a> used in attacks against energy utilities, oil, gas, telecom, and machinery sectors.</li><li>Charming Kitten sends a lure <a href="https://www.proofpoint.com/us/blog/threat-insight/welcome-new-york-exploring-ta453s-foray-lnks-and-mac-malware">masquerading as a senior fellow </a>with the Royal United Services Institute to a public media contact for a nuclear security expert at a US-based think tank focused on foreign affairs. </li><li>New Truebot malware variants deployed on networks compromised using a critical <a href="https://www.bleepingcomputer.com/news/security/cisa-netwrix-auditor-rce-bug-exploited-in-truebot-malware-attacks/">remote code execution</a> vulnerability in the Netwrix Auditor software.</li><li>TrendMicro is reporting <a href="https://www.trendmicro.com/en_us/research/23/g/tailing-big-head-ransomware-variants-tactics-and-impact.html">a new ransomware family</a> and its variant named Big Head.</li><li>Zscaler ThreatLabz has recently uncovered a <a href="https://www.zscaler.com/blogs/security-research/toitoin-trojan-analyzing-new-multi-stage-attack-targeting-latam-region">new targeted attack campaign</a> striking businesses in the Latin American region.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 13 Jul 2023 07:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/5505f8ff/c733007e.mp3" length="21384465" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/FTSD7I-BJ-uewzRW8soN2RqJLKsGV2S4CKOryBO6TLI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lMzg1/NTg0NGZlYjg0M2U5/OTQ4N2ZjYjc4MDU3/YmNmYS5wbmc.jpg"/>
      <itunes:duration>1766</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>The <a href="https://securityaffairs.com/148042/malware/rustbucket-macos-malware.html?amp=1">RustBucket malware</a> allows operators to download and execute various payloads. </li><li>Zscaler ThreatLabz researchers discovered a new <a href="https://securityaffairs.com/148193/malware/redenergy-stealer-as-a-ransomware.html?amp=1">Stealer-as-a-Ransomware named RedEnergy</a> used in attacks against energy utilities, oil, gas, telecom, and machinery sectors.</li><li>Charming Kitten sends a lure <a href="https://www.proofpoint.com/us/blog/threat-insight/welcome-new-york-exploring-ta453s-foray-lnks-and-mac-malware">masquerading as a senior fellow </a>with the Royal United Services Institute to a public media contact for a nuclear security expert at a US-based think tank focused on foreign affairs. </li><li>New Truebot malware variants deployed on networks compromised using a critical <a href="https://www.bleepingcomputer.com/news/security/cisa-netwrix-auditor-rce-bug-exploited-in-truebot-malware-attacks/">remote code execution</a> vulnerability in the Netwrix Auditor software.</li><li>TrendMicro is reporting <a href="https://www.trendmicro.com/en_us/research/23/g/tailing-big-head-ransomware-variants-tactics-and-impact.html">a new ransomware family</a> and its variant named Big Head.</li><li>Zscaler ThreatLabz has recently uncovered a <a href="https://www.zscaler.com/blogs/security-research/toitoin-trojan-analyzing-new-multi-stage-attack-targeting-latam-region">new targeted attack campaign</a> striking businesses in the Latin American region.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#47 - Tips for submitting papers to conferences with Huxley Barbee, organiser at BSidesNYC</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>34</itunes:episode>
      <podcast:episode>34</podcast:episode>
      <itunes:title>#47 - Tips for submitting papers to conferences with Huxley Barbee, organiser at BSidesNYC</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13172097</guid>
      <link>https://share.transistor.fm/s/c05f0755</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation around best practices for submitting papers to conferences with Huxley Barbee, Security Evangelist at runZero &amp; organizer of BSidesNYC.</p><p>Throughout Huxley's career, he has held key positions at Cisco, Datadog and now runZero. He is passionate about cybersecurity and supporting the community in order to create a better security posture for all. </p><p>Huxley encourages our listeners to connect with him on various platforms as linked below.</p><ul><li><a href="https://linktr.ee/huxley_barbee">Linktree</a></li><li><a href="https://www.linkedin.com/in/jhbarbee/">LinkedIn</a></li><li><a href="https://infosec.exchange/@huxley">Mastadon</a></li><li><a href="https://twitter.com/huxley_barbee">Twitter</a></li></ul><p>Some resources for finding conferences to submit papers to are linked below.</p><p><a href="https://infosec-conferences.com/">Infosec Conferences</a><br><a href="https://www.cfptime.org/home">CFP Time<br></a><a href="http://www.securitybsides.com/w/page/12194156/FrontPage">Security BSides<br></a><a href="https://blog.pulsedive.com/the-biggest-best-cti-events/">Pulesdive's list of threat intel conferences</a></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation around best practices for submitting papers to conferences with Huxley Barbee, Security Evangelist at runZero &amp; organizer of BSidesNYC.</p><p>Throughout Huxley's career, he has held key positions at Cisco, Datadog and now runZero. He is passionate about cybersecurity and supporting the community in order to create a better security posture for all. </p><p>Huxley encourages our listeners to connect with him on various platforms as linked below.</p><ul><li><a href="https://linktr.ee/huxley_barbee">Linktree</a></li><li><a href="https://www.linkedin.com/in/jhbarbee/">LinkedIn</a></li><li><a href="https://infosec.exchange/@huxley">Mastadon</a></li><li><a href="https://twitter.com/huxley_barbee">Twitter</a></li></ul><p>Some resources for finding conferences to submit papers to are linked below.</p><p><a href="https://infosec-conferences.com/">Infosec Conferences</a><br><a href="https://www.cfptime.org/home">CFP Time<br></a><a href="http://www.securitybsides.com/w/page/12194156/FrontPage">Security BSides<br></a><a href="https://blog.pulsedive.com/the-biggest-best-cti-events/">Pulesdive's list of threat intel conferences</a></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 06 Jul 2023 15:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c05f0755/7464f724.mp3" length="24600094" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/NZaMNO67s5yY4G-C570lR2c_XO3XXbbfmPgoN8-8urk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jOTVj/MTUyNmZhYjRiNDUw/YWQzMmFjOWEzZjIy/ZDIyOC5wbmc.jpg"/>
      <itunes:duration>2034</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation around best practices for submitting papers to conferences with Huxley Barbee, Security Evangelist at runZero &amp; organizer of BSidesNYC.</p><p>Throughout Huxley's career, he has held key positions at Cisco, Datadog and now runZero. He is passionate about cybersecurity and supporting the community in order to create a better security posture for all. </p><p>Huxley encourages our listeners to connect with him on various platforms as linked below.</p><ul><li><a href="https://linktr.ee/huxley_barbee">Linktree</a></li><li><a href="https://www.linkedin.com/in/jhbarbee/">LinkedIn</a></li><li><a href="https://infosec.exchange/@huxley">Mastadon</a></li><li><a href="https://twitter.com/huxley_barbee">Twitter</a></li></ul><p>Some resources for finding conferences to submit papers to are linked below.</p><p><a href="https://infosec-conferences.com/">Infosec Conferences</a><br><a href="https://www.cfptime.org/home">CFP Time<br></a><a href="http://www.securitybsides.com/w/page/12194156/FrontPage">Security BSides<br></a><a href="https://blog.pulsedive.com/the-biggest-best-cti-events/">Pulesdive's list of threat intel conferences</a></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#46 - Intel Chat: RedEyes, The Flea, JS dropper delivering Bumblebee &amp; IcedID, and free smartwatches</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>33</itunes:episode>
      <podcast:episode>33</podcast:episode>
      <itunes:title>#46 - Intel Chat: RedEyes, The Flea, JS dropper delivering Bumblebee &amp; IcedID, and free smartwatches</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13132552</guid>
      <link>https://share.transistor.fm/s/48ba6759</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>ASEC discovered that RedEyes is distributing and using an <a href="https://asec.ahnlab.com/en/54349/">infostealer with wiretapping features</a>. </li><li>Symantex is reporting that The Flea has continued to focus on foreign ministries in a <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/flea-backdoor-microsoft-graph-apt15">recent attack campaign</a> that ran from late 2022 into early 2023. </li><li>Deep Instinct’s Threat Research Lab recently noticed a new strain of a <a href="https://www.deepinstinct.com/blog/pindos-new-javascript-dropper-delivering-bumblebee-and-icedid">JavaScript-based dropper</a> that is delivering Bumblebee and IcedID </li><li>Rapid7 researchers recently undertook a project to analyze managed file transfer applications, due to the number of <a href="https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/">recent vulnerabilities discovered</a>.</li><li> Members across the military have reported receiving <a href="https://www.cid.army.mil/Media/Press-Center/Article-Display/Article/3429159/cid-lookout-unsolicited-smartwatches-received-by-mail/">smartwatches unsolicited in the mail</a>. </li></ul><p>And you can register here to attend the LinkedIn Live Event, <a href="https://www.linkedin.com/events/7079452470560616448/comments/">An Invitation to Change: Introducing the SecOps Cloud Platform</a> </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>ASEC discovered that RedEyes is distributing and using an <a href="https://asec.ahnlab.com/en/54349/">infostealer with wiretapping features</a>. </li><li>Symantex is reporting that The Flea has continued to focus on foreign ministries in a <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/flea-backdoor-microsoft-graph-apt15">recent attack campaign</a> that ran from late 2022 into early 2023. </li><li>Deep Instinct’s Threat Research Lab recently noticed a new strain of a <a href="https://www.deepinstinct.com/blog/pindos-new-javascript-dropper-delivering-bumblebee-and-icedid">JavaScript-based dropper</a> that is delivering Bumblebee and IcedID </li><li>Rapid7 researchers recently undertook a project to analyze managed file transfer applications, due to the number of <a href="https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/">recent vulnerabilities discovered</a>.</li><li> Members across the military have reported receiving <a href="https://www.cid.army.mil/Media/Press-Center/Article-Display/Article/3429159/cid-lookout-unsolicited-smartwatches-received-by-mail/">smartwatches unsolicited in the mail</a>. </li></ul><p>And you can register here to attend the LinkedIn Live Event, <a href="https://www.linkedin.com/events/7079452470560616448/comments/">An Invitation to Change: Introducing the SecOps Cloud Platform</a> </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 29 Jun 2023 15:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/48ba6759/b2ab5513.mp3" length="22198312" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/P29FAVTSv5y_kRHZ_NBbnIqJQ6O6Mfqm1iankiFCPYk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84ODEz/NmEwMGQxZDgzOWE4/NDQ2ZjUwYWIyOGI2/Y2FlYS5wbmc.jpg"/>
      <itunes:duration>1834</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>. </p><ul><li>ASEC discovered that RedEyes is distributing and using an <a href="https://asec.ahnlab.com/en/54349/">infostealer with wiretapping features</a>. </li><li>Symantex is reporting that The Flea has continued to focus on foreign ministries in a <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/flea-backdoor-microsoft-graph-apt15">recent attack campaign</a> that ran from late 2022 into early 2023. </li><li>Deep Instinct’s Threat Research Lab recently noticed a new strain of a <a href="https://www.deepinstinct.com/blog/pindos-new-javascript-dropper-delivering-bumblebee-and-icedid">JavaScript-based dropper</a> that is delivering Bumblebee and IcedID </li><li>Rapid7 researchers recently undertook a project to analyze managed file transfer applications, due to the number of <a href="https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/">recent vulnerabilities discovered</a>.</li><li> Members across the military have reported receiving <a href="https://www.cid.army.mil/Media/Press-Center/Article-Display/Article/3429159/cid-lookout-unsolicited-smartwatches-received-by-mail/">smartwatches unsolicited in the mail</a>. </li></ul><p>And you can register here to attend the LinkedIn Live Event, <a href="https://www.linkedin.com/events/7079452470560616448/comments/">An Invitation to Change: Introducing the SecOps Cloud Platform</a> </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#45 - Hacker History: SolarWinds</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>32</itunes:episode>
      <podcast:episode>32</podcast:episode>
      <itunes:title>#45 - Hacker History: SolarWinds</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13124019</guid>
      <link>https://share.transistor.fm/s/35c62581</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of John Bambenek, tell the story of one of the largest and most complicated supply chain attacks in history: SolarWinds </p><p>On December 13, 2020, <a href="https://www.wikipedia.org/wiki/The%20Washington%20Post"><em>The Washington Post</em></a><em> </em>reported that multiple government agencies were breached through SolarWinds's Orion software.</p><p>Victims of this attack include the cybersecurity firm <a href="https://handwiki.org/wiki/Company:FireEye">FireEye</a>, the US Treasury Department, the US Department of Commerce's National Telecommunications and Information Administration, as well as the US Department of Homeland Security.Prominent international SolarWinds customers investigating whether they were impacted include the North Atlantic Treaty Organization (NATO), the European Parliament, UK <a href="https://handwiki.org/wiki/Organization:GCHQ">Government Communications Headquarters</a>, the UK Ministry of Defence, the UK National Health Service (NHS), the UK Home Office, and <a href="https://handwiki.org/wiki/Company:AstraZeneca">AstraZeneca</a>. FireEye reported the hackers inserted "malicious code into legitimate software updates for the Orion software that allow an attacker remote access into the victim's environment" and that they have found "indications of compromise dating back to the spring of 2020". FireEye named the malware SUNBURST. Microsoft called it Solorigate.</p><p>The attack used a <a href="https://handwiki.org/wiki/Backdoor_(computing)">backdoor</a> in a SolarWinds <a href="https://handwiki.org/wiki/Library_(computing)">library</a>; when an update to SolarWinds occurred, the malicious attack would go unnoticed due to the trusted certificate.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of John Bambenek, tell the story of one of the largest and most complicated supply chain attacks in history: SolarWinds </p><p>On December 13, 2020, <a href="https://www.wikipedia.org/wiki/The%20Washington%20Post"><em>The Washington Post</em></a><em> </em>reported that multiple government agencies were breached through SolarWinds's Orion software.</p><p>Victims of this attack include the cybersecurity firm <a href="https://handwiki.org/wiki/Company:FireEye">FireEye</a>, the US Treasury Department, the US Department of Commerce's National Telecommunications and Information Administration, as well as the US Department of Homeland Security.Prominent international SolarWinds customers investigating whether they were impacted include the North Atlantic Treaty Organization (NATO), the European Parliament, UK <a href="https://handwiki.org/wiki/Organization:GCHQ">Government Communications Headquarters</a>, the UK Ministry of Defence, the UK National Health Service (NHS), the UK Home Office, and <a href="https://handwiki.org/wiki/Company:AstraZeneca">AstraZeneca</a>. FireEye reported the hackers inserted "malicious code into legitimate software updates for the Orion software that allow an attacker remote access into the victim's environment" and that they have found "indications of compromise dating back to the spring of 2020". FireEye named the malware SUNBURST. Microsoft called it Solorigate.</p><p>The attack used a <a href="https://handwiki.org/wiki/Backdoor_(computing)">backdoor</a> in a SolarWinds <a href="https://handwiki.org/wiki/Library_(computing)">library</a>; when an update to SolarWinds occurred, the malicious attack would go unnoticed due to the trusted certificate.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 28 Jun 2023 14:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/35c62581/5a5cd205.mp3" length="14768011" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/vyXvy3CKNXJ__ZzcnL4azAHX-aJRxwc3t-aHB7v5K0M/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85MDY3/MjQyNThiYTE4N2E2/MmU4YWU3NDc4OWFi/ZjFhYS5wbmc.jpg"/>
      <itunes:duration>1215</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we recount some hacker history, and with the help of John Bambenek, tell the story of one of the largest and most complicated supply chain attacks in history: SolarWinds </p><p>On December 13, 2020, <a href="https://www.wikipedia.org/wiki/The%20Washington%20Post"><em>The Washington Post</em></a><em> </em>reported that multiple government agencies were breached through SolarWinds's Orion software.</p><p>Victims of this attack include the cybersecurity firm <a href="https://handwiki.org/wiki/Company:FireEye">FireEye</a>, the US Treasury Department, the US Department of Commerce's National Telecommunications and Information Administration, as well as the US Department of Homeland Security.Prominent international SolarWinds customers investigating whether they were impacted include the North Atlantic Treaty Organization (NATO), the European Parliament, UK <a href="https://handwiki.org/wiki/Organization:GCHQ">Government Communications Headquarters</a>, the UK Ministry of Defence, the UK National Health Service (NHS), the UK Home Office, and <a href="https://handwiki.org/wiki/Company:AstraZeneca">AstraZeneca</a>. FireEye reported the hackers inserted "malicious code into legitimate software updates for the Orion software that allow an attacker remote access into the victim's environment" and that they have found "indications of compromise dating back to the spring of 2020". FireEye named the malware SUNBURST. Microsoft called it Solorigate.</p><p>The attack used a <a href="https://handwiki.org/wiki/Backdoor_(computing)">backdoor</a> in a SolarWinds <a href="https://handwiki.org/wiki/Library_(computing)">library</a>; when an update to SolarWinds occurred, the malicious attack would go unnoticed due to the trusted certificate.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#44 - Intel Chat: Fake GitHub repos, NPM poison, Vidar, Mac malware, Tsunami DDOS, Cl0p reward, and the EDR killer: Spyboy</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>31</itunes:episode>
      <podcast:episode>31</podcast:episode>
      <itunes:title>#44 - Intel Chat: Fake GitHub repos, NPM poison, Vidar, Mac malware, Tsunami DDOS, Cl0p reward, and the EDR killer: Spyboy</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13099344</guid>
      <link>https://share.transistor.fm/s/2a35b73d</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>VulnCheck comes across a malicious GitHub repository that is claimed to be <a href="https://vulncheck.com/blog/fake-repos-deliver-malicious-implant">a Signal 0-day</a>.</li><li>CheckMarx are reporting that Without altering a single line of code, attackers <a href="https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers/">poisoned the NPM package</a> “bignum” by hijacking a S3 bucket.</li><li>Team CYMRU has released a <a href="https://www.team-cymru.com/post/darth-vidar-the-aesir-strike-back">detailed publication on Vidar</a> infrastructure which encompasses both the primary administrative aspects and the underlying backend. </li><li>Bit Defender Mac researchers stumbled upon a small set of files with backdoor capabilities that seem to form part of a more <a href="https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/">complex malware toolkit</a>. </li><li>Researchers have found an <a href="https://blog.sandworm.dev/security-alert-dont-npm-install-https">unofficial package called 'https'</a> that exists on NPM with over 1600 other packages that depend on it.</li><li>An attack campaign that consists of the Tsunami DDoS Bot being installed on <a href="https://asec.ahnlab.com/en/54647/">inadequately managed Linux SSH servers</a>.</li><li>Cl0p rewards of up to <a href="https://www.scmagazine.com/brief/ransomware/us-puts-up-10m-reward-to-disrupt-clop-ransomware-gang">$10 million are being offered</a> by the U.S. State Department's Rewards for Justice program.</li><li>SentinelOne is reporting on the Terminator <a href="https://www.sentinelone.com/blog/terminator-edr-killer-spyboy-detecting-and-preventing-a-windows-byovd-attack/">EDR killer - Spyboy</a>. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>VulnCheck comes across a malicious GitHub repository that is claimed to be <a href="https://vulncheck.com/blog/fake-repos-deliver-malicious-implant">a Signal 0-day</a>.</li><li>CheckMarx are reporting that Without altering a single line of code, attackers <a href="https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers/">poisoned the NPM package</a> “bignum” by hijacking a S3 bucket.</li><li>Team CYMRU has released a <a href="https://www.team-cymru.com/post/darth-vidar-the-aesir-strike-back">detailed publication on Vidar</a> infrastructure which encompasses both the primary administrative aspects and the underlying backend. </li><li>Bit Defender Mac researchers stumbled upon a small set of files with backdoor capabilities that seem to form part of a more <a href="https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/">complex malware toolkit</a>. </li><li>Researchers have found an <a href="https://blog.sandworm.dev/security-alert-dont-npm-install-https">unofficial package called 'https'</a> that exists on NPM with over 1600 other packages that depend on it.</li><li>An attack campaign that consists of the Tsunami DDoS Bot being installed on <a href="https://asec.ahnlab.com/en/54647/">inadequately managed Linux SSH servers</a>.</li><li>Cl0p rewards of up to <a href="https://www.scmagazine.com/brief/ransomware/us-puts-up-10m-reward-to-disrupt-clop-ransomware-gang">$10 million are being offered</a> by the U.S. State Department's Rewards for Justice program.</li><li>SentinelOne is reporting on the Terminator <a href="https://www.sentinelone.com/blog/terminator-edr-killer-spyboy-detecting-and-preventing-a-windows-byovd-attack/">EDR killer - Spyboy</a>. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Sat, 24 Jun 2023 16:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2a35b73d/367bf754.mp3" length="31509024" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/hL_tyPCD50LAVleQb1YW7o2LKD3aoSTzDnvfoUORUsM/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84Y2Mz/YjQyNWY1N2I3MTE4/NTU2OTc0YWZiYzE1/OWNkNC5wbmc.jpg"/>
      <itunes:duration>2610</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>VulnCheck comes across a malicious GitHub repository that is claimed to be <a href="https://vulncheck.com/blog/fake-repos-deliver-malicious-implant">a Signal 0-day</a>.</li><li>CheckMarx are reporting that Without altering a single line of code, attackers <a href="https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers/">poisoned the NPM package</a> “bignum” by hijacking a S3 bucket.</li><li>Team CYMRU has released a <a href="https://www.team-cymru.com/post/darth-vidar-the-aesir-strike-back">detailed publication on Vidar</a> infrastructure which encompasses both the primary administrative aspects and the underlying backend. </li><li>Bit Defender Mac researchers stumbled upon a small set of files with backdoor capabilities that seem to form part of a more <a href="https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/">complex malware toolkit</a>. </li><li>Researchers have found an <a href="https://blog.sandworm.dev/security-alert-dont-npm-install-https">unofficial package called 'https'</a> that exists on NPM with over 1600 other packages that depend on it.</li><li>An attack campaign that consists of the Tsunami DDoS Bot being installed on <a href="https://asec.ahnlab.com/en/54647/">inadequately managed Linux SSH servers</a>.</li><li>Cl0p rewards of up to <a href="https://www.scmagazine.com/brief/ransomware/us-puts-up-10m-reward-to-disrupt-clop-ransomware-gang">$10 million are being offered</a> by the U.S. State Department's Rewards for Justice program.</li><li>SentinelOne is reporting on the Terminator <a href="https://www.sentinelone.com/blog/terminator-edr-killer-spyboy-detecting-and-preventing-a-windows-byovd-attack/">EDR killer - Spyboy</a>. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#43 - A conversation about AI in cybersecurity with Jon Bagg, Founder &amp; CEO of Salem Cyber</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>30</itunes:episode>
      <podcast:episode>30</podcast:episode>
      <itunes:title>#43 - A conversation about AI in cybersecurity with Jon Bagg, Founder &amp; CEO of Salem Cyber</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13082164</guid>
      <link>https://share.transistor.fm/s/6ea46653</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about AI in cybersecurity with Jon Bagg, Founder &amp; CEO of Salem Cyber.</p><p>Jon Bagg is the creator of Salem Cyber, an innovative cyber analysis technology that helps scale their alert investigation capacity so they can find threats in the noise. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about AI in cybersecurity with Jon Bagg, Founder &amp; CEO of Salem Cyber.</p><p>Jon Bagg is the creator of Salem Cyber, an innovative cyber analysis technology that helps scale their alert investigation capacity so they can find threats in the noise. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 21 Jun 2023 14:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/6ea46653/5d1e2008.mp3" length="28320036" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/kkYjttMugIKm8h7TSC7uVaFjW5AugE1bf_zi9rF92nE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jYzAw/MDFmYjMzOTBjOWE1/Nzk4NTNkMjdkY2U0/MGVlNi5wbmc.jpg"/>
      <itunes:duration>2344</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about AI in cybersecurity with Jon Bagg, Founder &amp; CEO of Salem Cyber.</p><p>Jon Bagg is the creator of Salem Cyber, an innovative cyber analysis technology that helps scale their alert investigation capacity so they can find threats in the noise. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#42 - Intel Chat: Atomic Wallet, Azure goes down, BEC justice, FortiOS SSL VPN and the BatCloak</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>29</itunes:episode>
      <podcast:episode>29</podcast:episode>
      <itunes:title>#42 - Intel Chat: Atomic Wallet, Azure goes down, BEC justice, FortiOS SSL VPN and the BatCloak</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13044834</guid>
      <link>https://share.transistor.fm/s/47b201b7</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li> $35 million has reportedly been stolen from users of <a href="https://hub.elliptic.co/analysis/north-korea-s-lazarus-group-likely-responsible-for-35-million-atomic-crypto-theft/">Atomic Wallet</a>.</li><li>On June 9th the Microsoft Azure Portal was down on the web as a result of <a href="https://www.bleepingcomputer.com/news/microsoft/microsofts-azure-portal-down-following-new-claims-of-ddos-attacks/">suspected DDOS</a>.</li><li>The US Department of Justice has indicted 6 people for their involvement in a $6 million dollar <a href="https://www.databreachtoday.com/us-doj-indicts-6-for-6m-business-email-compromise-scam-a-22259">business email compromise scam</a>.</li><li>CVE-2023-27997 was <a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign">reported by Fortinet</a> on June 13th (<a href="https://docs.fortinet.com/document/fortigate/7.2.0/best-practices/555436/hardening">Fortinet hardening guide</a>).</li><li>Trend Micro recently discovered the use of heavily obfuscated batch files utilizing the advanced <a href="https://www.trendmicro.com/en_us/research/23/f/analyzing-the-fud-malware-obfuscation-engine-batcloak.html">BatCloak engine</a>.</li><li>And a really cool PDF - <a href="https://www.orangecyberdefense.com/be/white-papers/cy-xplorer-2023">the Cy-Xplorer 2023 report</a> put out by Orange Cyberdefense.</li></ul><p><br></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li> $35 million has reportedly been stolen from users of <a href="https://hub.elliptic.co/analysis/north-korea-s-lazarus-group-likely-responsible-for-35-million-atomic-crypto-theft/">Atomic Wallet</a>.</li><li>On June 9th the Microsoft Azure Portal was down on the web as a result of <a href="https://www.bleepingcomputer.com/news/microsoft/microsofts-azure-portal-down-following-new-claims-of-ddos-attacks/">suspected DDOS</a>.</li><li>The US Department of Justice has indicted 6 people for their involvement in a $6 million dollar <a href="https://www.databreachtoday.com/us-doj-indicts-6-for-6m-business-email-compromise-scam-a-22259">business email compromise scam</a>.</li><li>CVE-2023-27997 was <a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign">reported by Fortinet</a> on June 13th (<a href="https://docs.fortinet.com/document/fortigate/7.2.0/best-practices/555436/hardening">Fortinet hardening guide</a>).</li><li>Trend Micro recently discovered the use of heavily obfuscated batch files utilizing the advanced <a href="https://www.trendmicro.com/en_us/research/23/f/analyzing-the-fud-malware-obfuscation-engine-batcloak.html">BatCloak engine</a>.</li><li>And a really cool PDF - <a href="https://www.orangecyberdefense.com/be/white-papers/cy-xplorer-2023">the Cy-Xplorer 2023 report</a> put out by Orange Cyberdefense.</li></ul><p><br></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 15 Jun 2023 11:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/47b201b7/f571ccd5.mp3" length="25637375" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/z2GmYsXC22jdHX6GgoZQ11JG-W9aC_C25xbZgbtp-Y4/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84ZDI1/ODk1ODE3YmE0NDdl/YjI2ZjQ3OGQwZTE2/Y2I1MS5wbmc.jpg"/>
      <itunes:duration>2121</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li> $35 million has reportedly been stolen from users of <a href="https://hub.elliptic.co/analysis/north-korea-s-lazarus-group-likely-responsible-for-35-million-atomic-crypto-theft/">Atomic Wallet</a>.</li><li>On June 9th the Microsoft Azure Portal was down on the web as a result of <a href="https://www.bleepingcomputer.com/news/microsoft/microsofts-azure-portal-down-following-new-claims-of-ddos-attacks/">suspected DDOS</a>.</li><li>The US Department of Justice has indicted 6 people for their involvement in a $6 million dollar <a href="https://www.databreachtoday.com/us-doj-indicts-6-for-6m-business-email-compromise-scam-a-22259">business email compromise scam</a>.</li><li>CVE-2023-27997 was <a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign">reported by Fortinet</a> on June 13th (<a href="https://docs.fortinet.com/document/fortigate/7.2.0/best-practices/555436/hardening">Fortinet hardening guide</a>).</li><li>Trend Micro recently discovered the use of heavily obfuscated batch files utilizing the advanced <a href="https://www.trendmicro.com/en_us/research/23/f/analyzing-the-fud-malware-obfuscation-engine-batcloak.html">BatCloak engine</a>.</li><li>And a really cool PDF - <a href="https://www.orangecyberdefense.com/be/white-papers/cy-xplorer-2023">the Cy-Xplorer 2023 report</a> put out by Orange Cyberdefense.</li></ul><p><br></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#41 - A conversation about edge computing with Theresa Lanowitz, Head of Evangelism and Portfolio Marketing at AT&amp;T Cybersecurity</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>28</itunes:episode>
      <podcast:episode>28</podcast:episode>
      <itunes:title>#41 - A conversation about edge computing with Theresa Lanowitz, Head of Evangelism and Portfolio Marketing at AT&amp;T Cybersecurity</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13030854</guid>
      <link>https://share.transistor.fm/s/989aee07</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about edge computing with Theresa Lanowitz, Head of Evangelism and Portfolio Marketing at AT&amp;T Cybersecurity.</p><p>Theresa Lanowitz is a proven global influencer and speaks on trends and emerging technology poised to help today’s enterprise organizations flourish. Theresa is currently the head of evangelism at AT&amp;T Business - Cybersecurity.</p><p>Prior to joining AT&amp;T, Theresa was an industry analyst with boutique analyst firm voke and Gartner. While at Gartner, Theresa spearheaded the application quality ecosystem, championed application security technology, and created the successful Application Development conference.</p><p>As a product manager at Borland International Software, Theresa launched the iconic Java integrated development environment, JBuilder. While at Sun Microsystems, Theresa led strategic marketing for the Jini project – a precursor to IoT (Internet of Things).</p><p>Theresa’s professional career began with McDonnell Douglas where she was a software developer on the C-17 military transport plane and held a US Department of Defense Top Secret security clearance.</p><p>Theresa holds a Bachelor of Science in Computer Science from the University of Pittsburgh, Pittsburgh, PA.</p><p>The report referenced in the podcast can be acquired here: <a href="https://cybersecurity.att.com/resource-center/insights-reports/cybersecurity-insights-report-edge-ecosystem">2023 AT&amp;T Cybersecurity Insight Report: Edge Ecosystem </a></p><p>The open-source Genie Framework referenced in the podcast can be viewed here: <a href="https://genie-framework.sourceforge.net/">Genie Framework</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about edge computing with Theresa Lanowitz, Head of Evangelism and Portfolio Marketing at AT&amp;T Cybersecurity.</p><p>Theresa Lanowitz is a proven global influencer and speaks on trends and emerging technology poised to help today’s enterprise organizations flourish. Theresa is currently the head of evangelism at AT&amp;T Business - Cybersecurity.</p><p>Prior to joining AT&amp;T, Theresa was an industry analyst with boutique analyst firm voke and Gartner. While at Gartner, Theresa spearheaded the application quality ecosystem, championed application security technology, and created the successful Application Development conference.</p><p>As a product manager at Borland International Software, Theresa launched the iconic Java integrated development environment, JBuilder. While at Sun Microsystems, Theresa led strategic marketing for the Jini project – a precursor to IoT (Internet of Things).</p><p>Theresa’s professional career began with McDonnell Douglas where she was a software developer on the C-17 military transport plane and held a US Department of Defense Top Secret security clearance.</p><p>Theresa holds a Bachelor of Science in Computer Science from the University of Pittsburgh, Pittsburgh, PA.</p><p>The report referenced in the podcast can be acquired here: <a href="https://cybersecurity.att.com/resource-center/insights-reports/cybersecurity-insights-report-edge-ecosystem">2023 AT&amp;T Cybersecurity Insight Report: Edge Ecosystem </a></p><p>The open-source Genie Framework referenced in the podcast can be viewed here: <a href="https://genie-framework.sourceforge.net/">Genie Framework</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Tue, 13 Jun 2023 14:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/989aee07/e2f7ccce.mp3" length="29176297" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/NlRWATmZ6vSeP7r7hHqHpU6LMQoGyq7k5_I2JzZUgww/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NjMx/MDFiOWViOTdjZDlk/MTg2N2Q1OTFmMmQx/MTRmYi5wbmc.jpg"/>
      <itunes:duration>2415</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about edge computing with Theresa Lanowitz, Head of Evangelism and Portfolio Marketing at AT&amp;T Cybersecurity.</p><p>Theresa Lanowitz is a proven global influencer and speaks on trends and emerging technology poised to help today’s enterprise organizations flourish. Theresa is currently the head of evangelism at AT&amp;T Business - Cybersecurity.</p><p>Prior to joining AT&amp;T, Theresa was an industry analyst with boutique analyst firm voke and Gartner. While at Gartner, Theresa spearheaded the application quality ecosystem, championed application security technology, and created the successful Application Development conference.</p><p>As a product manager at Borland International Software, Theresa launched the iconic Java integrated development environment, JBuilder. While at Sun Microsystems, Theresa led strategic marketing for the Jini project – a precursor to IoT (Internet of Things).</p><p>Theresa’s professional career began with McDonnell Douglas where she was a software developer on the C-17 military transport plane and held a US Department of Defense Top Secret security clearance.</p><p>Theresa holds a Bachelor of Science in Computer Science from the University of Pittsburgh, Pittsburgh, PA.</p><p>The report referenced in the podcast can be acquired here: <a href="https://cybersecurity.att.com/resource-center/insights-reports/cybersecurity-insights-report-edge-ecosystem">2023 AT&amp;T Cybersecurity Insight Report: Edge Ecosystem </a></p><p>The open-source Genie Framework referenced in the podcast can be viewed here: <a href="https://genie-framework.sourceforge.net/">Genie Framework</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#40 - Intel Chat: BlackCat, RaidForums Exposed, MOVEit Transfer, Camaro Dragon, mystery iOS malware, TrueBot and the Cyclops Ransomware &amp; Stealer combo</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>27</itunes:episode>
      <podcast:episode>27</podcast:episode>
      <itunes:title>#40 - Intel Chat: BlackCat, RaidForums Exposed, MOVEit Transfer, Camaro Dragon, mystery iOS malware, TrueBot and the Cyclops Ransomware &amp; Stealer combo</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-13003242</guid>
      <link>https://share.transistor.fm/s/97be4740</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>BlackCat makes some changes geared towards improving its tradecraft and increasing the likelihood of <a href="https://securityintelligence.com/posts/blackcat-ransomware-levels-up-stealth-speed-exfiltration/">data theft and encryption</a>. </li><li>A<b> </b>new hacking forum called Exposed has <a href="https://www.bitdefender.com/blog/hotforsecurity/new-hacking-forum-exposed-unveils-database-of-over-478-000-raidforums-members/">publicly leaked</a> a substantial database from the infamous RaidForums.</li><li>A <a href="https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023">critical vulnerability</a> in the MOVEit Transfer software.</li><li>Camaro Dragon <a href="https://research.checkpoint.com/2023/malware-spotlight-camaro-dragons-tinynote-backdoor/">targets European foreign affairs</a> entities linked to Southeast and East Asia.</li><li>Kaspersky is reporting on some <a href="https://securelist.com/operation-triangulation/109842/">unknown malware</a> targeting iOS devices.</li><li>The Hacker News is reporting a <a href="https://thehackernews.com/2023/06/alarming-surge-in-truebot-activity.html">surge in TrueBot activity</a> that was observed starting in May 2023.</li><li>Uptycs is reporting on the threat group behind the Cyclops <a href="https://www.uptycs.com/blog/cyclops-ransomware-stealer-combo">ransomware and stealer combo</a>. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>BlackCat makes some changes geared towards improving its tradecraft and increasing the likelihood of <a href="https://securityintelligence.com/posts/blackcat-ransomware-levels-up-stealth-speed-exfiltration/">data theft and encryption</a>. </li><li>A<b> </b>new hacking forum called Exposed has <a href="https://www.bitdefender.com/blog/hotforsecurity/new-hacking-forum-exposed-unveils-database-of-over-478-000-raidforums-members/">publicly leaked</a> a substantial database from the infamous RaidForums.</li><li>A <a href="https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023">critical vulnerability</a> in the MOVEit Transfer software.</li><li>Camaro Dragon <a href="https://research.checkpoint.com/2023/malware-spotlight-camaro-dragons-tinynote-backdoor/">targets European foreign affairs</a> entities linked to Southeast and East Asia.</li><li>Kaspersky is reporting on some <a href="https://securelist.com/operation-triangulation/109842/">unknown malware</a> targeting iOS devices.</li><li>The Hacker News is reporting a <a href="https://thehackernews.com/2023/06/alarming-surge-in-truebot-activity.html">surge in TrueBot activity</a> that was observed starting in May 2023.</li><li>Uptycs is reporting on the threat group behind the Cyclops <a href="https://www.uptycs.com/blog/cyclops-ransomware-stealer-combo">ransomware and stealer combo</a>. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 08 Jun 2023 16:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/97be4740/a174c330.mp3" length="8505758" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/0Ku2aBownpPhpJhbcGY4u3lNz0PC59platRYyhafr-0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xZjNj/ZmM4ZGJkY2FhODYx/ZjFkMGQ3YWM0MTQ4/YjE5YS5wbmc.jpg"/>
      <itunes:duration>693</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>BlackCat makes some changes geared towards improving its tradecraft and increasing the likelihood of <a href="https://securityintelligence.com/posts/blackcat-ransomware-levels-up-stealth-speed-exfiltration/">data theft and encryption</a>. </li><li>A<b> </b>new hacking forum called Exposed has <a href="https://www.bitdefender.com/blog/hotforsecurity/new-hacking-forum-exposed-unveils-database-of-over-478-000-raidforums-members/">publicly leaked</a> a substantial database from the infamous RaidForums.</li><li>A <a href="https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023">critical vulnerability</a> in the MOVEit Transfer software.</li><li>Camaro Dragon <a href="https://research.checkpoint.com/2023/malware-spotlight-camaro-dragons-tinynote-backdoor/">targets European foreign affairs</a> entities linked to Southeast and East Asia.</li><li>Kaspersky is reporting on some <a href="https://securelist.com/operation-triangulation/109842/">unknown malware</a> targeting iOS devices.</li><li>The Hacker News is reporting a <a href="https://thehackernews.com/2023/06/alarming-surge-in-truebot-activity.html">surge in TrueBot activity</a> that was observed starting in May 2023.</li><li>Uptycs is reporting on the threat group behind the Cyclops <a href="https://www.uptycs.com/blog/cyclops-ransomware-stealer-combo">ransomware and stealer combo</a>. </li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#39 - A conversation about DFIR with Devon Ackerman, Global Service Line Leader for Digital Forensics and Incident Response Kroll</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>26</itunes:episode>
      <podcast:episode>26</podcast:episode>
      <itunes:title>#39 - A conversation about DFIR with Devon Ackerman, Global Service Line Leader for Digital Forensics and Incident Response Kroll</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12986540</guid>
      <link>https://share.transistor.fm/s/05553586</link>
      <description>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we are joined Devon Ackerman, Global Service Line Leader for Digital Forensics and Incident Response (DFIR) services at Kroll Cyber.</p><p>Prior to Kroll, Devon served as a Supervisory Special Agent at the FBI's Operational Technology Division in the CART Field Operations Unit. He navigated digital forensic issues, managed 56 FBI Division executive management relationships, organized team deployments during mass incident response events such as the San Bernardino Domestic Terrorism shooting (Apple iPhones), and served as a senior certified Forensic Examiner (CART) for on-scene collections and forensic analysis.</p><p>As mentioned in the show, an excellent resource for all things DFIR: <a href="https://aboutdfir.com/">aboutDFIR.com</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we are joined Devon Ackerman, Global Service Line Leader for Digital Forensics and Incident Response (DFIR) services at Kroll Cyber.</p><p>Prior to Kroll, Devon served as a Supervisory Special Agent at the FBI's Operational Technology Division in the CART Field Operations Unit. He navigated digital forensic issues, managed 56 FBI Division executive management relationships, organized team deployments during mass incident response events such as the San Bernardino Domestic Terrorism shooting (Apple iPhones), and served as a senior certified Forensic Examiner (CART) for on-scene collections and forensic analysis.</p><p>As mentioned in the show, an excellent resource for all things DFIR: <a href="https://aboutdfir.com/">aboutDFIR.com</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Tue, 06 Jun 2023 05:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/05553586/970bf3b4.mp3" length="21057440" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/fB1uxtWXlDOAg75AhkdEoeGwv0JmsIDhpIoDLjToI0w/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82YmI2/NWFmZjg2ZWMyM2Ni/ODA2ZGVlMDg4MzVh/ZWU4NC5wbmc.jpg"/>
      <itunes:duration>1739</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we are joined Devon Ackerman, Global Service Line Leader for Digital Forensics and Incident Response (DFIR) services at Kroll Cyber.</p><p>Prior to Kroll, Devon served as a Supervisory Special Agent at the FBI's Operational Technology Division in the CART Field Operations Unit. He navigated digital forensic issues, managed 56 FBI Division executive management relationships, organized team deployments during mass incident response events such as the San Bernardino Domestic Terrorism shooting (Apple iPhones), and served as a senior certified Forensic Examiner (CART) for on-scene collections and forensic analysis.</p><p>As mentioned in the show, an excellent resource for all things DFIR: <a href="https://aboutdfir.com/">aboutDFIR.com</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#38 - Intel Chat: Donut, Agrius, Kimsuky, Pikabot, QBot &amp; the Gootloader Initial Access-as-a-Service Operation.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>25</itunes:episode>
      <podcast:episode>25</podcast:episode>
      <itunes:title>#38 - Intel Chat: Donut, Agrius, Kimsuky, Pikabot, QBot &amp; the Gootloader Initial Access-as-a-Service Operation.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12958820</guid>
      <link>https://share.transistor.fm/s/77b2f13a</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>FortiGaurd Labs encounters <a href="https://www.fortinet.com/blog/threat-research/wintapix-kernal-driver-middle-east-countries">a kernel driver</a> that makes use of the open-source donut tool.</li><li>Checkpoint researchers observe <a href="https://research.checkpoint.com/2023/agrius-deploys-moneybird-in-targeted-attacks-against-israeli-organizations/">Iranian threat actor Agrius</a> operating against Israeli targets.</li><li>SentielOne notes changes in the <a href="https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/">ongoing campaign by Kimsuky</a>.</li><li>Microsoft uncovers stealthy malicious activity <a href="https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/">aimed at critical infrastructure </a>in the United States.</li><li>ZScaler Threatlabz reporting on Pikabot, a <a href="https://www.zscaler.com/blogs/security-research/technical-analysis-pikabot">new malware trojan</a>.</li><li>Bleeping Computer reporting that the <a href="https://www.bleepingcomputer.com/news/security/qbot-malware-abuses-windows-wordpad-exe-to-infect-devices/">QBot malware operation</a> has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program.</li><li>eSentire launches a multi-pronged offensive against a growing cyberthreat: the <a href="https://www.esentire.com/web-native-pages/gootloader-unloaded">Gootloader Initial Access-as-a-Service Operation</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>FortiGaurd Labs encounters <a href="https://www.fortinet.com/blog/threat-research/wintapix-kernal-driver-middle-east-countries">a kernel driver</a> that makes use of the open-source donut tool.</li><li>Checkpoint researchers observe <a href="https://research.checkpoint.com/2023/agrius-deploys-moneybird-in-targeted-attacks-against-israeli-organizations/">Iranian threat actor Agrius</a> operating against Israeli targets.</li><li>SentielOne notes changes in the <a href="https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/">ongoing campaign by Kimsuky</a>.</li><li>Microsoft uncovers stealthy malicious activity <a href="https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/">aimed at critical infrastructure </a>in the United States.</li><li>ZScaler Threatlabz reporting on Pikabot, a <a href="https://www.zscaler.com/blogs/security-research/technical-analysis-pikabot">new malware trojan</a>.</li><li>Bleeping Computer reporting that the <a href="https://www.bleepingcomputer.com/news/security/qbot-malware-abuses-windows-wordpad-exe-to-infect-devices/">QBot malware operation</a> has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program.</li><li>eSentire launches a multi-pronged offensive against a growing cyberthreat: the <a href="https://www.esentire.com/web-native-pages/gootloader-unloaded">Gootloader Initial Access-as-a-Service Operation</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 01 Jun 2023 14:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/77b2f13a/ad1eb3f2.mp3" length="32639471" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/-cmgN-Syfsk7xRUTlPna8HqSEr6CHriTxlGzu3WxfEA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84OTRm/MTFmYmVhZGUzZDFm/ZDAxNDYwOWRiOTY2/MzJhOS5wbmc.jpg"/>
      <itunes:duration>2704</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>FortiGaurd Labs encounters <a href="https://www.fortinet.com/blog/threat-research/wintapix-kernal-driver-middle-east-countries">a kernel driver</a> that makes use of the open-source donut tool.</li><li>Checkpoint researchers observe <a href="https://research.checkpoint.com/2023/agrius-deploys-moneybird-in-targeted-attacks-against-israeli-organizations/">Iranian threat actor Agrius</a> operating against Israeli targets.</li><li>SentielOne notes changes in the <a href="https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/">ongoing campaign by Kimsuky</a>.</li><li>Microsoft uncovers stealthy malicious activity <a href="https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/">aimed at critical infrastructure </a>in the United States.</li><li>ZScaler Threatlabz reporting on Pikabot, a <a href="https://www.zscaler.com/blogs/security-research/technical-analysis-pikabot">new malware trojan</a>.</li><li>Bleeping Computer reporting that the <a href="https://www.bleepingcomputer.com/news/security/qbot-malware-abuses-windows-wordpad-exe-to-infect-devices/">QBot malware operation</a> has started to abuse a DLL hijacking flaw in the Windows 10 WordPad program.</li><li>eSentire launches a multi-pronged offensive against a growing cyberthreat: the <a href="https://www.esentire.com/web-native-pages/gootloader-unloaded">Gootloader Initial Access-as-a-Service Operation</a>.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#37 - A conversation about securing the build pipeline with Adnan Khan, Lead Security Engineer at Praetorian</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>24</itunes:episode>
      <podcast:episode>24</podcast:episode>
      <itunes:title>#37 - A conversation about securing the build pipeline with Adnan Khan, Lead Security Engineer at Praetorian</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12943072</guid>
      <link>https://share.transistor.fm/s/9ad9e63c</link>
      <description>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we are joined by security engineer Adnan Khan to talk about securing the build pipeline and explore some common vulnerabilities in enterprise Github configurations.<b><br></b><br>Organizations using GitHub Actions with self-hosted runners are at risk of attackers gaining an internal network foothold from the Internet if they compromise one developer’s personal GitHub access token. Key configuration adjustments can secure these pipelines and limit the damage from a breach.</p><p>Adnan's talk at BSidesSF: <a href="https://www.youtube.com/watch?v=FVK-ssWqVEM">Securing the Pipeline: Protecting Self-Hosted HitHub Runners</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we are joined by security engineer Adnan Khan to talk about securing the build pipeline and explore some common vulnerabilities in enterprise Github configurations.<b><br></b><br>Organizations using GitHub Actions with self-hosted runners are at risk of attackers gaining an internal network foothold from the Internet if they compromise one developer’s personal GitHub access token. Key configuration adjustments can secure these pipelines and limit the damage from a breach.</p><p>Adnan's talk at BSidesSF: <a href="https://www.youtube.com/watch?v=FVK-ssWqVEM">Securing the Pipeline: Protecting Self-Hosted HitHub Runners</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Tue, 30 May 2023 06:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9ad9e63c/5a9691d4.mp3" length="18721325" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/DcN11t4_qsbDrTQpP61P7AysjVEEZxvIKWhrvc6j04k/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85ZmU0/YTY1NDAzOTVjZGZk/NzYwM2M5OTYwNDY4/MGM5Yy5wbmc.jpg"/>
      <itunes:duration>1544</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On today's episode of The Cybersecurity Defenders Podcast we are joined by security engineer Adnan Khan to talk about securing the build pipeline and explore some common vulnerabilities in enterprise Github configurations.<b><br></b><br>Organizations using GitHub Actions with self-hosted runners are at risk of attackers gaining an internal network foothold from the Internet if they compromise one developer’s personal GitHub access token. Key configuration adjustments can secure these pipelines and limit the damage from a breach.</p><p>Adnan's talk at BSidesSF: <a href="https://www.youtube.com/watch?v=FVK-ssWqVEM">Securing the Pipeline: Protecting Self-Hosted HitHub Runners</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#36 - Intel Chat: Red Stinger, 3 new Apple Zero Days, the GuLoader, BlackCat and the Golden Jackal</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>23</itunes:episode>
      <podcast:episode>23</podcast:episode>
      <itunes:title>#36 - Intel Chat: Red Stinger, 3 new Apple Zero Days, the GuLoader, BlackCat and the Golden Jackal</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12917015</guid>
      <link>https://share.transistor.fm/s/3bd305c4</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Malware Bytes researchers reporting on the <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/05/redstinger">Red Stinger group</a> which has targeted entities in Ukraine.</li><li>Apple is reporting <a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-three-new-zero-days-exploited-to-hack-iphones-macs/">three new zero</a> days affecting iPhones, iPads, Macs and even Apple watches and TVs. </li><li>The folks over at CISCO Talos have recently identified <a href="https://blog.talosintelligence.com/ra-group-ransomware/">a new RA group</a> that has been operating since at least April 22, 2023.</li><li>Check Point researchers<b> </b>have uncovered <a href="https://research.checkpoint.com/2023/cloud-based-malware-delivery-the-evolution-of-guloader/">the GuLoader</a> that has been used in a large number of attacks.</li><li>Trend Micro is reporting on <a href="https://www.trendmicro.com/en_us/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver.html">a new capability</a> seen in a BlackCat ransomware incident.</li><li>Kaspersky is introducing the world to <a href="https://securelist.com/goldenjackal-apt-group/109677/">a new APT group</a> they are calling GoldenJackal.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Malware Bytes researchers reporting on the <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/05/redstinger">Red Stinger group</a> which has targeted entities in Ukraine.</li><li>Apple is reporting <a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-three-new-zero-days-exploited-to-hack-iphones-macs/">three new zero</a> days affecting iPhones, iPads, Macs and even Apple watches and TVs. </li><li>The folks over at CISCO Talos have recently identified <a href="https://blog.talosintelligence.com/ra-group-ransomware/">a new RA group</a> that has been operating since at least April 22, 2023.</li><li>Check Point researchers<b> </b>have uncovered <a href="https://research.checkpoint.com/2023/cloud-based-malware-delivery-the-evolution-of-guloader/">the GuLoader</a> that has been used in a large number of attacks.</li><li>Trend Micro is reporting on <a href="https://www.trendmicro.com/en_us/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver.html">a new capability</a> seen in a BlackCat ransomware incident.</li><li>Kaspersky is introducing the world to <a href="https://securelist.com/goldenjackal-apt-group/109677/">a new APT group</a> they are calling GoldenJackal.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 25 May 2023 04:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3bd305c4/0b5662b5.mp3" length="28426945" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/IRTyXlb8uZsBzekmkTxSUO1f0PxNwealOvjGof2PErs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zOGNj/ZjEyODA2MWU3OGUy/M2YwOTljNzA1ZGI5/YjI4OC5wbmc.jpg"/>
      <itunes:duration>2353</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Malware Bytes researchers reporting on the <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/05/redstinger">Red Stinger group</a> which has targeted entities in Ukraine.</li><li>Apple is reporting <a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-three-new-zero-days-exploited-to-hack-iphones-macs/">three new zero</a> days affecting iPhones, iPads, Macs and even Apple watches and TVs. </li><li>The folks over at CISCO Talos have recently identified <a href="https://blog.talosintelligence.com/ra-group-ransomware/">a new RA group</a> that has been operating since at least April 22, 2023.</li><li>Check Point researchers<b> </b>have uncovered <a href="https://research.checkpoint.com/2023/cloud-based-malware-delivery-the-evolution-of-guloader/">the GuLoader</a> that has been used in a large number of attacks.</li><li>Trend Micro is reporting on <a href="https://www.trendmicro.com/en_us/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver.html">a new capability</a> seen in a BlackCat ransomware incident.</li><li>Kaspersky is introducing the world to <a href="https://securelist.com/goldenjackal-apt-group/109677/">a new APT group</a> they are calling GoldenJackal.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#35 - A conversation about mental health in cybersecurity with Amanda Berlin, CEO of Mental Health Hackers</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>22</itunes:episode>
      <podcast:episode>22</podcast:episode>
      <itunes:title>#35 - A conversation about mental health in cybersecurity with Amanda Berlin, CEO of Mental Health Hackers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12908479</guid>
      <link>https://share.transistor.fm/s/cbe31d48</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about mental health in cybersecurity with Amanda Berlin, CEO of Mental Health Hackers.</p><p>Mental Health Hackers' stated mission is to <em>educate</em> tech professionals about the unique mental health risks faced by those in our field – and often by the people who we share our lives with – and <em>provide guidance</em> on reducing their effects and better manage the triggering causes.</p><p>They also aim at <em>providing support services</em> to those who may be susceptible to related mental health issues such as anxiety, depression, social isolation, eating disorders, etc.</p><p>If you are struggling please know that there are a lot of people in your community that care, as well as resources that you can access. </p><ul><li><a href="https://www.mentalhealthfirstaid.org/">Mental Health First Aid</a></li><li><a href="https://workplacementalhealth.org/">Workplace Mental Health</a></li><li><a href="https://drive.google.com/drive/folders/1qL07CCbpiyG5HTf4xIdTi2yZHzuaW2eh">A list of resources from Mental Health Hackers</a></li><li><a href="https://drive.google.com/file/d/1VLMf4_U1Hj4ih9CSjUdV0bPtkvyCgrbI/view">Mental Health: Know the Warning Signs</a></li><li> <a href="https://drive.google.com/file/d/1pIJJxokjvdQnp6osL7rx0Y6YdPpvE25j/view">Mental Health: How to find help </a></li><li> <a href="https://drive.google.com/file/d/1_cpaLG5k5ZZWviVSPWO87Y13niJc3KX4/view">Mental Health: Maintaining a Healthy Lifestyle</a></li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about mental health in cybersecurity with Amanda Berlin, CEO of Mental Health Hackers.</p><p>Mental Health Hackers' stated mission is to <em>educate</em> tech professionals about the unique mental health risks faced by those in our field – and often by the people who we share our lives with – and <em>provide guidance</em> on reducing their effects and better manage the triggering causes.</p><p>They also aim at <em>providing support services</em> to those who may be susceptible to related mental health issues such as anxiety, depression, social isolation, eating disorders, etc.</p><p>If you are struggling please know that there are a lot of people in your community that care, as well as resources that you can access. </p><ul><li><a href="https://www.mentalhealthfirstaid.org/">Mental Health First Aid</a></li><li><a href="https://workplacementalhealth.org/">Workplace Mental Health</a></li><li><a href="https://drive.google.com/drive/folders/1qL07CCbpiyG5HTf4xIdTi2yZHzuaW2eh">A list of resources from Mental Health Hackers</a></li><li><a href="https://drive.google.com/file/d/1VLMf4_U1Hj4ih9CSjUdV0bPtkvyCgrbI/view">Mental Health: Know the Warning Signs</a></li><li> <a href="https://drive.google.com/file/d/1pIJJxokjvdQnp6osL7rx0Y6YdPpvE25j/view">Mental Health: How to find help </a></li><li> <a href="https://drive.google.com/file/d/1_cpaLG5k5ZZWviVSPWO87Y13niJc3KX4/view">Mental Health: Maintaining a Healthy Lifestyle</a></li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 24 May 2023 05:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/cbe31d48/15b9c4c2.mp3" length="15998213" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/jFYJRetZybxTpybSRVROZSPwWGJFC_6trDRiVzN6TQk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jYjI3/ZmFkMDVjYmMyYmRj/MDQ3MjhmYTdhN2I4/Y2Y4MC5wbmc.jpg"/>
      <itunes:duration>1317</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders Podcast, we have a conversation about mental health in cybersecurity with Amanda Berlin, CEO of Mental Health Hackers.</p><p>Mental Health Hackers' stated mission is to <em>educate</em> tech professionals about the unique mental health risks faced by those in our field – and often by the people who we share our lives with – and <em>provide guidance</em> on reducing their effects and better manage the triggering causes.</p><p>They also aim at <em>providing support services</em> to those who may be susceptible to related mental health issues such as anxiety, depression, social isolation, eating disorders, etc.</p><p>If you are struggling please know that there are a lot of people in your community that care, as well as resources that you can access. </p><ul><li><a href="https://www.mentalhealthfirstaid.org/">Mental Health First Aid</a></li><li><a href="https://workplacementalhealth.org/">Workplace Mental Health</a></li><li><a href="https://drive.google.com/drive/folders/1qL07CCbpiyG5HTf4xIdTi2yZHzuaW2eh">A list of resources from Mental Health Hackers</a></li><li><a href="https://drive.google.com/file/d/1VLMf4_U1Hj4ih9CSjUdV0bPtkvyCgrbI/view">Mental Health: Know the Warning Signs</a></li><li> <a href="https://drive.google.com/file/d/1pIJJxokjvdQnp6osL7rx0Y6YdPpvE25j/view">Mental Health: How to find help </a></li><li> <a href="https://drive.google.com/file/d/1_cpaLG5k5ZZWviVSPWO87Y13niJc3KX4/view">Mental Health: Maintaining a Healthy Lifestyle</a></li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#34 - Special Episode: Operation Medusa cuts the head off of the Snake using PEGASUS software</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>21</itunes:episode>
      <podcast:episode>21</podcast:episode>
      <itunes:title>#34 - Special Episode: Operation Medusa cuts the head off of the Snake using PEGASUS software</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12876611</guid>
      <link>https://share.transistor.fm/s/b8e59441</link>
      <description>
        <![CDATA[<p>On this special episode of the Cybersecurity Defenders Podcast, we have a longer-form discussion about the recent FBI takedown of the Russian malware known as Snake. The FBI dismantled the global peer-to-peer network of Snake-infected computers with Operation MEDUSA in coordination with multiple cybersecurity agencies.</p><p>Resources referenced in this show:</p><ul><li>Press release from the <a href="https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-snake-malware-network-controlled">Department of Justice</a></li><li>CISA's <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a">cybersecurity advisory</a></li><li>CISA breakdown of the <a href="https://www.cisa.gov/sites/default/files/2023-05/aa23-129a_snake_malware_2.pdf">Snake malware</a></li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this special episode of the Cybersecurity Defenders Podcast, we have a longer-form discussion about the recent FBI takedown of the Russian malware known as Snake. The FBI dismantled the global peer-to-peer network of Snake-infected computers with Operation MEDUSA in coordination with multiple cybersecurity agencies.</p><p>Resources referenced in this show:</p><ul><li>Press release from the <a href="https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-snake-malware-network-controlled">Department of Justice</a></li><li>CISA's <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a">cybersecurity advisory</a></li><li>CISA breakdown of the <a href="https://www.cisa.gov/sites/default/files/2023-05/aa23-129a_snake_malware_2.pdf">Snake malware</a></li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 18 May 2023 19:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b8e59441/5013bf4c.mp3" length="38526918" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/E07ruT6VU94hpsAY_LxqTSbaaDcrNyFZa9s3nbQ1RTE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80M2Jl/ZDJmZDRjY2U5YzVi/MDEzYzkwYzBjOGM0/NTBhZi5wbmc.jpg"/>
      <itunes:duration>3195</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this special episode of the Cybersecurity Defenders Podcast, we have a longer-form discussion about the recent FBI takedown of the Russian malware known as Snake. The FBI dismantled the global peer-to-peer network of Snake-infected computers with Operation MEDUSA in coordination with multiple cybersecurity agencies.</p><p>Resources referenced in this show:</p><ul><li>Press release from the <a href="https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-snake-malware-network-controlled">Department of Justice</a></li><li>CISA's <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a">cybersecurity advisory</a></li><li>CISA breakdown of the <a href="https://www.cisa.gov/sites/default/files/2023-05/aa23-129a_snake_malware_2.pdf">Snake malware</a></li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#33 - Hacker History: Stuxnet (Part 2)</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>20</itunes:episode>
      <podcast:episode>20</podcast:episode>
      <itunes:title>#33 - Hacker History: Stuxnet (Part 2)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12857505</guid>
      <link>https://share.transistor.fm/s/9fdc1bf6</link>
      <description>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is the second part in a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet.</p><p>Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.</p><p>If you have not heard the first episode it is recommended that you do so before listening to this one. You can listen to the first episode here: <a href="https://cybersecuritydefenderspodcast.buzzsprout.com/2050721/12539776-hacker-history-stuxnet-part-1">Stuxnet (Part 1)</a></p><p>Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is the second part in a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet.</p><p>Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.</p><p>If you have not heard the first episode it is recommended that you do so before listening to this one. You can listen to the first episode here: <a href="https://cybersecuritydefenderspodcast.buzzsprout.com/2050721/12539776-hacker-history-stuxnet-part-1">Stuxnet (Part 1)</a></p><p>Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Tue, 16 May 2023 07:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9fdc1bf6/be4871c3.mp3" length="13617590" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/4kFhDn1NkRRf6NcWY6QNUmL_Bt2-geHXWGfKBPQMK2o/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZTdm/ZDJjNGNkNTE3M2Fi/NWRjYjgwYWU4Yjc4/MzIxYi5wbmc.jpg"/>
      <itunes:duration>1119</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is the second part in a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet.</p><p>Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.</p><p>If you have not heard the first episode it is recommended that you do so before listening to this one. You can listen to the first episode here: <a href="https://cybersecuritydefenderspodcast.buzzsprout.com/2050721/12539776-hacker-history-stuxnet-part-1">Stuxnet (Part 1)</a></p><p>Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#32 - Intel Chat: APT41, Sidewinder &amp; Operation Medusa cuts the head off of Snake</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>19</itunes:episode>
      <podcast:episode>19</podcast:episode>
      <itunes:title>#32 - Intel Chat: APT41, Sidewinder &amp; Operation Medusa cuts the head off of Snake</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12828501</guid>
      <link>https://share.transistor.fm/s/34aae43d</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Threatmmon have uncovered a <a href="https://cybersecuritynews.com/apt41s-powershell-backdoor/?amp">targeted PowerShell backdoor</a> malware attack that bypasses normal detection methodology.</li><li>Researchers have uncovered an attack that is based on a classic <a href="https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/">sideloading technique with a twist</a> in which a first-stage clean application sideloads a second clean application and auto-executes it.</li><li>US authorities have announced the seizure of <a href="https://www.securityweek.com/us-seizes-domains-of-13-ddos-for-hire-services/">13 internet domains</a>.</li><li>The Blackberry Threat Research and Intelligence team has discovered a new campaign from the <a href="https://blogs.blackberry.com/en/2023/05/sidewinder-uses-server-side-polymorphism-to-target-pakistan">Sidewinder APT group</a> against Pakistani government organizations.</li><li>CISA has issued an advisory letting the public know that the FBI has used a court order to take down a <a href="https://www.darkreading.com/attacks-breaches/fbi-disarms-russian-fsb-snake-malware-network">Russian government-controlled malware</a> network.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Threatmmon have uncovered a <a href="https://cybersecuritynews.com/apt41s-powershell-backdoor/?amp">targeted PowerShell backdoor</a> malware attack that bypasses normal detection methodology.</li><li>Researchers have uncovered an attack that is based on a classic <a href="https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/">sideloading technique with a twist</a> in which a first-stage clean application sideloads a second clean application and auto-executes it.</li><li>US authorities have announced the seizure of <a href="https://www.securityweek.com/us-seizes-domains-of-13-ddos-for-hire-services/">13 internet domains</a>.</li><li>The Blackberry Threat Research and Intelligence team has discovered a new campaign from the <a href="https://blogs.blackberry.com/en/2023/05/sidewinder-uses-server-side-polymorphism-to-target-pakistan">Sidewinder APT group</a> against Pakistani government organizations.</li><li>CISA has issued an advisory letting the public know that the FBI has used a court order to take down a <a href="https://www.darkreading.com/attacks-breaches/fbi-disarms-russian-fsb-snake-malware-network">Russian government-controlled malware</a> network.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 11 May 2023 10:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/34aae43d/5d17393e.mp3" length="20920573" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/nD08xrKbSXNQ8xQv7a4Wj7y4J1CLOkjg3iSpXhDvexw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83ODcz/ZGViYzYyYjhlODNi/YWRkM2U1MjhhZGI5/ZDQxMi5wbmc.jpg"/>
      <itunes:duration>1727</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Threatmmon have uncovered a <a href="https://cybersecuritynews.com/apt41s-powershell-backdoor/?amp">targeted PowerShell backdoor</a> malware attack that bypasses normal detection methodology.</li><li>Researchers have uncovered an attack that is based on a classic <a href="https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/">sideloading technique with a twist</a> in which a first-stage clean application sideloads a second clean application and auto-executes it.</li><li>US authorities have announced the seizure of <a href="https://www.securityweek.com/us-seizes-domains-of-13-ddos-for-hire-services/">13 internet domains</a>.</li><li>The Blackberry Threat Research and Intelligence team has discovered a new campaign from the <a href="https://blogs.blackberry.com/en/2023/05/sidewinder-uses-server-side-polymorphism-to-target-pakistan">Sidewinder APT group</a> against Pakistani government organizations.</li><li>CISA has issued an advisory letting the public know that the FBI has used a court order to take down a <a href="https://www.darkreading.com/attacks-breaches/fbi-disarms-russian-fsb-snake-malware-network">Russian government-controlled malware</a> network.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#31 - Intel Chat: 3CX Inception, QuaDream goes down, APTs targeting for destruction, AMOS &amp; AuKill</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>18</itunes:episode>
      <podcast:episode>18</podcast:episode>
      <itunes:title>#31 - Intel Chat: 3CX Inception, QuaDream goes down, APTs targeting for destruction, AMOS &amp; AuKill</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12782141</guid>
      <link>https://share.transistor.fm/s/528cc37e</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>The <a href="https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise">initial  attack vector</a> of 3CX’s network was via malicious software downloaded from Trading Technologies website</li><li>QuaDream has allegedly <a href="https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html">fired all of its staff</a> and is shutting down its operations in the coming days</li><li>State-sponsored campaigns targeting global infrastructure: looks like <a href="https://blog.talosintelligence.com/state-sponsored-campaigns-target-global-network-infrastructure/">obvious targeting</a> to support future destructive attacks</li><li>A new information-stealing malware called Atomic macOS Stealer (<a href="https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/">AMOS</a>)</li><li>Attackers have been observed attempting to disable EDR clients with a new defensive evasion tool we’ve dubbed <a href="https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/">AuKill</a></li></ul><p>A new report put out by the National Cyber Security Centre is meant to help defenders understand selected malware threats in more technical depth, and provide indicators and TTPs to support threat hunting or modeling: <a href="https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports">View the Report</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>The <a href="https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise">initial  attack vector</a> of 3CX’s network was via malicious software downloaded from Trading Technologies website</li><li>QuaDream has allegedly <a href="https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html">fired all of its staff</a> and is shutting down its operations in the coming days</li><li>State-sponsored campaigns targeting global infrastructure: looks like <a href="https://blog.talosintelligence.com/state-sponsored-campaigns-target-global-network-infrastructure/">obvious targeting</a> to support future destructive attacks</li><li>A new information-stealing malware called Atomic macOS Stealer (<a href="https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/">AMOS</a>)</li><li>Attackers have been observed attempting to disable EDR clients with a new defensive evasion tool we’ve dubbed <a href="https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/">AuKill</a></li></ul><p>A new report put out by the National Cyber Security Centre is meant to help defenders understand selected malware threats in more technical depth, and provide indicators and TTPs to support threat hunting or modeling: <a href="https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports">View the Report</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 04 May 2023 07:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/528cc37e/7fbd2c65.mp3" length="22442814" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/5MQuEEgNgCWaSItDbbJBQDxzy1HFmWcLaldc6_oH__s/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZjdk/MGE5OTRiY2ZhNzU2/OTQ0YmFmNDIyMGI3/MmViNS5wbmc.jpg"/>
      <itunes:duration>1854</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>The <a href="https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise">initial  attack vector</a> of 3CX’s network was via malicious software downloaded from Trading Technologies website</li><li>QuaDream has allegedly <a href="https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html">fired all of its staff</a> and is shutting down its operations in the coming days</li><li>State-sponsored campaigns targeting global infrastructure: looks like <a href="https://blog.talosintelligence.com/state-sponsored-campaigns-target-global-network-infrastructure/">obvious targeting</a> to support future destructive attacks</li><li>A new information-stealing malware called Atomic macOS Stealer (<a href="https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/">AMOS</a>)</li><li>Attackers have been observed attempting to disable EDR clients with a new defensive evasion tool we’ve dubbed <a href="https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/">AuKill</a></li></ul><p>A new report put out by the National Cyber Security Centre is meant to help defenders understand selected malware threats in more technical depth, and provide indicators and TTPs to support threat hunting or modeling: <a href="https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports">View the Report</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#30 - A conversation on the history of security tooling with Dr. Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>17</itunes:episode>
      <podcast:episode>17</podcast:episode>
      <itunes:title>#30 - A conversation on the history of security tooling with Dr. Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12769487</guid>
      <link>https://share.transistor.fm/s/d087a602</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast we have a conversation around the history of security tooling with Dr. Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud.</p><p>Dr. Anton Chuvakin is currently involved with security solution strategy at Google Cloud, where he arrived via Chronicle Security (an Alphabet company) acquisition in July 2019. He is also a co-host of Cloud Security Podcast http://www.twitter.com/CloudSecPodcast</p><p>Until June 2019, Dr. Anton Chuvakin was a Research VP and Distinguished Analyst at Gartner for Technical Professionals (GTP) Security and Risk Management Strategies (SRMS) team. At Gartner he covered a broad range of security operations and detection and response topics, and is credited with inventing the term "EDR." </p><p>He is a recognized security expert in the field of SIEM, log management and PCI DSS compliance. He is an author of books "Security Warrior", "PCI Compliance", "Logging and Log Management" and a contributor to "Know Your Enemy II", "Information Security Management Handbook" and others. Anton has published dozens of papers on log management, SIEM, correlation, security data analysis, PCI DSS, honeypots, etc. His blog securitywarrior.org was one of the most popular in the industry. </p><p>In addition, Anton taught classes (including his own SANS SEC434 class on log management) and presented at many security conferences across the world; he recently addressed audiences in United States, UK, Singapore, Spain, Russia and other countries. He worked on emerging security standards and served on the advisory boards of several security start-ups.</p><p>Before joining Gartner in 2011, Anton was running his own security consulting practice www.securitywarriorconsulting.com, focusing on SIEM, logging and PCI DSS compliance for security vendors and Fortune 500 organizations. Anton earned his Ph.D. degree from Stony Brook University.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast we have a conversation around the history of security tooling with Dr. Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud.</p><p>Dr. Anton Chuvakin is currently involved with security solution strategy at Google Cloud, where he arrived via Chronicle Security (an Alphabet company) acquisition in July 2019. He is also a co-host of Cloud Security Podcast http://www.twitter.com/CloudSecPodcast</p><p>Until June 2019, Dr. Anton Chuvakin was a Research VP and Distinguished Analyst at Gartner for Technical Professionals (GTP) Security and Risk Management Strategies (SRMS) team. At Gartner he covered a broad range of security operations and detection and response topics, and is credited with inventing the term "EDR." </p><p>He is a recognized security expert in the field of SIEM, log management and PCI DSS compliance. He is an author of books "Security Warrior", "PCI Compliance", "Logging and Log Management" and a contributor to "Know Your Enemy II", "Information Security Management Handbook" and others. Anton has published dozens of papers on log management, SIEM, correlation, security data analysis, PCI DSS, honeypots, etc. His blog securitywarrior.org was one of the most popular in the industry. </p><p>In addition, Anton taught classes (including his own SANS SEC434 class on log management) and presented at many security conferences across the world; he recently addressed audiences in United States, UK, Singapore, Spain, Russia and other countries. He worked on emerging security standards and served on the advisory boards of several security start-ups.</p><p>Before joining Gartner in 2011, Anton was running his own security consulting practice www.securitywarriorconsulting.com, focusing on SIEM, logging and PCI DSS compliance for security vendors and Fortune 500 organizations. Anton earned his Ph.D. degree from Stony Brook University.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Tue, 02 May 2023 16:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d087a602/fde8c1dc.mp3" length="21442533" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/lt46iFiGnvlt563bbcKTyBQrr3idhruI2kkkMYFefjI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MmM3/NWYzNzBiZmQ2Nzdm/ZDRjYTVjYWJlMGU0/ZDVkYi5wbmc.jpg"/>
      <itunes:duration>1771</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast we have a conversation around the history of security tooling with Dr. Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud.</p><p>Dr. Anton Chuvakin is currently involved with security solution strategy at Google Cloud, where he arrived via Chronicle Security (an Alphabet company) acquisition in July 2019. He is also a co-host of Cloud Security Podcast http://www.twitter.com/CloudSecPodcast</p><p>Until June 2019, Dr. Anton Chuvakin was a Research VP and Distinguished Analyst at Gartner for Technical Professionals (GTP) Security and Risk Management Strategies (SRMS) team. At Gartner he covered a broad range of security operations and detection and response topics, and is credited with inventing the term "EDR." </p><p>He is a recognized security expert in the field of SIEM, log management and PCI DSS compliance. He is an author of books "Security Warrior", "PCI Compliance", "Logging and Log Management" and a contributor to "Know Your Enemy II", "Information Security Management Handbook" and others. Anton has published dozens of papers on log management, SIEM, correlation, security data analysis, PCI DSS, honeypots, etc. His blog securitywarrior.org was one of the most popular in the industry. </p><p>In addition, Anton taught classes (including his own SANS SEC434 class on log management) and presented at many security conferences across the world; he recently addressed audiences in United States, UK, Singapore, Spain, Russia and other countries. He worked on emerging security standards and served on the advisory boards of several security start-ups.</p><p>Before joining Gartner in 2011, Anton was running his own security consulting practice www.securitywarriorconsulting.com, focusing on SIEM, logging and PCI DSS compliance for security vendors and Fortune 500 organizations. Anton earned his Ph.D. degree from Stony Brook University.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#29 - A focused discussion on ransomware with Paul Ihme, Co-Founder and Managing Principle at Soteria Security Solutions and Advisory</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>16</itunes:episode>
      <podcast:episode>16</podcast:episode>
      <itunes:title>#29 - A focused discussion on ransomware with Paul Ihme, Co-Founder and Managing Principle at Soteria Security Solutions and Advisory</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12721801</guid>
      <link>https://share.transistor.fm/s/e6120fc2</link>
      <description>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast we have a focused discussion on ransomware with Paul Ihme, Co-Founder and Managing Principle at Soteria Security Solutions and Advisory.</p><p>Paul is a cybersecurity professional with experience in federal and private environments. Wide array of expertise in multiple information technology domains, specializing in penetration testing, vulnerability assessments, and security incident response.</p><p>The blog article, "Ransomware Is Irrelevant (Wait WHAT?!)" written by Adrian Sanabria that is referenced in the podcast can be <a href="https://thecyberwhy.substack.com/p/ransomware-is-irrelevant-wait-what">viewed here</a>. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast we have a focused discussion on ransomware with Paul Ihme, Co-Founder and Managing Principle at Soteria Security Solutions and Advisory.</p><p>Paul is a cybersecurity professional with experience in federal and private environments. Wide array of expertise in multiple information technology domains, specializing in penetration testing, vulnerability assessments, and security incident response.</p><p>The blog article, "Ransomware Is Irrelevant (Wait WHAT?!)" written by Adrian Sanabria that is referenced in the podcast can be <a href="https://thecyberwhy.substack.com/p/ransomware-is-irrelevant-wait-what">viewed here</a>. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Tue, 25 Apr 2023 18:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/e6120fc2/c497a0c8.mp3" length="22437242" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tnJedBJCzh2wU8L_UNAQo24mMZm1-TagAdfyMHsEdDI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83OWFh/NjMzMDRjMjA5YTUy/YTUwODkyYzk1OWEy/MWU1Ni5wbmc.jpg"/>
      <itunes:duration>1854</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>On this episode of the Cybersecurity Defenders podcast we have a focused discussion on ransomware with Paul Ihme, Co-Founder and Managing Principle at Soteria Security Solutions and Advisory.</p><p>Paul is a cybersecurity professional with experience in federal and private environments. Wide array of expertise in multiple information technology domains, specializing in penetration testing, vulnerability assessments, and security incident response.</p><p>The blog article, "Ransomware Is Irrelevant (Wait WHAT?!)" written by Adrian Sanabria that is referenced in the podcast can be <a href="https://thecyberwhy.substack.com/p/ransomware-is-irrelevant-wait-what">viewed here</a>. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#28 - Intel Chat: Balada injector, Lockbit, the Legion hacktool, Nokoyawa ransomware, Domino malware and more.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>15</itunes:episode>
      <podcast:episode>15</podcast:episode>
      <itunes:title>#28 - Intel Chat: Balada injector, Lockbit, the Legion hacktool, Nokoyawa ransomware, Domino malware and more.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12680013</guid>
      <link>https://share.transistor.fm/s/769f6dcc</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Over 1 million Wordpress sites have been infected by the <a href="https://twitter.com/unix_root/status/1645406020934725634">Balada Injector malware</a></li><li>Nokoyawa ransomware attacks are being seen in the wild <a href="https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/">exploiting a Windows zero-day</a></li><li>An emerging Python-based credential harvester and hacktool, named <a href="https://www.cadosecurity.com/legion-an-aws-credential-harvester-and-smtp-hijacker/">Legion</a></li><li>A recently discovered malware family being called <a href="https://securityintelligence.com/posts/ex-conti-fin7-actors-collaborate-new-domino-backdoor/">“Domino”</a></li><li> Care increasingly using the Action1 remote access software for <a href="https://www.bleepingcomputer.com/news/security/hackers-start-abusing-action1-rmm-in-ransomware-attacks/">persistence on compromised networks</a></li><li>A ransomware group has created encryptors <a href="https://www.bleepingcomputer.com/news/security/lockbit-ransomware-encryptors-found-targeting-mac-devices/">targeting Macs</a> for the first time</li><li>And a <a href="https://thehackernews.com/2023/04/google-releases-urgent-chrome-update-to.html">Chrome type confusion issue</a> in the V8 Javascript engine</li></ul><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Over 1 million Wordpress sites have been infected by the <a href="https://twitter.com/unix_root/status/1645406020934725634">Balada Injector malware</a></li><li>Nokoyawa ransomware attacks are being seen in the wild <a href="https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/">exploiting a Windows zero-day</a></li><li>An emerging Python-based credential harvester and hacktool, named <a href="https://www.cadosecurity.com/legion-an-aws-credential-harvester-and-smtp-hijacker/">Legion</a></li><li>A recently discovered malware family being called <a href="https://securityintelligence.com/posts/ex-conti-fin7-actors-collaborate-new-domino-backdoor/">“Domino”</a></li><li> Care increasingly using the Action1 remote access software for <a href="https://www.bleepingcomputer.com/news/security/hackers-start-abusing-action1-rmm-in-ransomware-attacks/">persistence on compromised networks</a></li><li>A ransomware group has created encryptors <a href="https://www.bleepingcomputer.com/news/security/lockbit-ransomware-encryptors-found-targeting-mac-devices/">targeting Macs</a> for the first time</li><li>And a <a href="https://thehackernews.com/2023/04/google-releases-urgent-chrome-update-to.html">Chrome type confusion issue</a> in the V8 Javascript engine</li></ul><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 19 Apr 2023 03:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/769f6dcc/f6fc877a.mp3" length="28705956" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/KClHXZEnHnAi1c9rph9dihck6bxmOD_Qjfmc5L7K560/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xMmNl/MzJlMzdmNjQyNWQx/ZTNhOWEwZDA1NTA3/MjFjYS5wbmc.jpg"/>
      <itunes:duration>2376</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Over 1 million Wordpress sites have been infected by the <a href="https://twitter.com/unix_root/status/1645406020934725634">Balada Injector malware</a></li><li>Nokoyawa ransomware attacks are being seen in the wild <a href="https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/">exploiting a Windows zero-day</a></li><li>An emerging Python-based credential harvester and hacktool, named <a href="https://www.cadosecurity.com/legion-an-aws-credential-harvester-and-smtp-hijacker/">Legion</a></li><li>A recently discovered malware family being called <a href="https://securityintelligence.com/posts/ex-conti-fin7-actors-collaborate-new-domino-backdoor/">“Domino”</a></li><li> Care increasingly using the Action1 remote access software for <a href="https://www.bleepingcomputer.com/news/security/hackers-start-abusing-action1-rmm-in-ransomware-attacks/">persistence on compromised networks</a></li><li>A ransomware group has created encryptors <a href="https://www.bleepingcomputer.com/news/security/lockbit-ransomware-encryptors-found-targeting-mac-devices/">targeting Macs</a> for the first time</li><li>And a <a href="https://thehackernews.com/2023/04/google-releases-urgent-chrome-update-to.html">Chrome type confusion issue</a> in the V8 Javascript engine</li></ul><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#27 - Intel Chat: Apple zero-days to the end of the Genesis Market. And a dive into OT security with Dave Cullen, Field CTO of OTORIO</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>14</itunes:episode>
      <podcast:episode>14</podcast:episode>
      <itunes:title>#27 - Intel Chat: Apple zero-days to the end of the Genesis Market. And a dive into OT security with Dave Cullen, Field CTO of OTORIO</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12635222</guid>
      <link>https://share.transistor.fm/s/eff4079c</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Emergency security updates <a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-two-zero-days-exploited-to-hack-iphones-and-macs/">issued by Apple</a>: CVE-2023-28206 &amp; CVE-2023-28205 .</li><li>Check Point researchers have unveiled a new sophisticated and <a href="https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/">fast acting ransomware</a>.</li><li>eFile.com, an IRS-authorized e-file software service provider used by many for filing their tax returns, has been caught serving <a href="https://www.bleepingcomputer.com/news/security/irs-authorized-efilecom-tax-return-software-caught-serving-js-malware/">JavaScript malware</a>.</li><li>The CrowdStrike Falcon OverWatch team recently observed <a href="https://www.crowdstrike.com/blog/self-extracting-archives-decoy-files-and-their-hidden-payloads/">threat actors exploit WinRAR </a>self-extracting archives.</li><li>FBI, Europol and the Dutch Police have disrupted the infamous browser cookie market known as <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/genesis-market-no-longer-feeds-the-evil-cookie-monster.html">Genesis Market</a>.</li><li> Microsoft’s Digital Crimes Unit along with a cybersecurity software company <a href="https://www.fortra.com/">Fortra</a> and Health Information Sharing and Analysis Center are taking technical and legal action to disrupt cracked, <a href="https://blogs.microsoft.com/on-the-issues/2023/04/06/stopping-cybercriminals-from-abusing-security-tools/">legacy copies of Cobalt Strike</a>.</li></ul><p>And then we dive into OT security with Dave Cullen, Field CTO for OTORIO.</p><p>As mentioned in the podcast, <a href="https://blog.ecapuano.com/p/so-you-want-to-be-a-soc-analyst-intro">here is a link</a> to the “So you want to be a SOC Analyst?” by <a href="https://www.linkedin.com/in/ecapuano/">Eric Capuano</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Emergency security updates <a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-two-zero-days-exploited-to-hack-iphones-and-macs/">issued by Apple</a>: CVE-2023-28206 &amp; CVE-2023-28205 .</li><li>Check Point researchers have unveiled a new sophisticated and <a href="https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/">fast acting ransomware</a>.</li><li>eFile.com, an IRS-authorized e-file software service provider used by many for filing their tax returns, has been caught serving <a href="https://www.bleepingcomputer.com/news/security/irs-authorized-efilecom-tax-return-software-caught-serving-js-malware/">JavaScript malware</a>.</li><li>The CrowdStrike Falcon OverWatch team recently observed <a href="https://www.crowdstrike.com/blog/self-extracting-archives-decoy-files-and-their-hidden-payloads/">threat actors exploit WinRAR </a>self-extracting archives.</li><li>FBI, Europol and the Dutch Police have disrupted the infamous browser cookie market known as <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/genesis-market-no-longer-feeds-the-evil-cookie-monster.html">Genesis Market</a>.</li><li> Microsoft’s Digital Crimes Unit along with a cybersecurity software company <a href="https://www.fortra.com/">Fortra</a> and Health Information Sharing and Analysis Center are taking technical and legal action to disrupt cracked, <a href="https://blogs.microsoft.com/on-the-issues/2023/04/06/stopping-cybercriminals-from-abusing-security-tools/">legacy copies of Cobalt Strike</a>.</li></ul><p>And then we dive into OT security with Dave Cullen, Field CTO for OTORIO.</p><p>As mentioned in the podcast, <a href="https://blog.ecapuano.com/p/so-you-want-to-be-a-soc-analyst-intro">here is a link</a> to the “So you want to be a SOC Analyst?” by <a href="https://www.linkedin.com/in/ecapuano/">Eric Capuano</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 12 Apr 2023 07:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/eff4079c/52eaa4d6.mp3" length="52712672" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/n5K65V7yNLUeGPiwDcMw8_nuS6TDRIeAhkSi1FEz3sg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lMDI1/OTJlYjJlNTk2NDE3/MTJhNWY1NTFiZDhi/NDkzNi5wbmc.jpg"/>
      <itunes:duration>4377</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io/">community Slack channel</a>.</p><ul><li>Emergency security updates <a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-two-zero-days-exploited-to-hack-iphones-and-macs/">issued by Apple</a>: CVE-2023-28206 &amp; CVE-2023-28205 .</li><li>Check Point researchers have unveiled a new sophisticated and <a href="https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/">fast acting ransomware</a>.</li><li>eFile.com, an IRS-authorized e-file software service provider used by many for filing their tax returns, has been caught serving <a href="https://www.bleepingcomputer.com/news/security/irs-authorized-efilecom-tax-return-software-caught-serving-js-malware/">JavaScript malware</a>.</li><li>The CrowdStrike Falcon OverWatch team recently observed <a href="https://www.crowdstrike.com/blog/self-extracting-archives-decoy-files-and-their-hidden-payloads/">threat actors exploit WinRAR </a>self-extracting archives.</li><li>FBI, Europol and the Dutch Police have disrupted the infamous browser cookie market known as <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/genesis-market-no-longer-feeds-the-evil-cookie-monster.html">Genesis Market</a>.</li><li> Microsoft’s Digital Crimes Unit along with a cybersecurity software company <a href="https://www.fortra.com/">Fortra</a> and Health Information Sharing and Analysis Center are taking technical and legal action to disrupt cracked, <a href="https://blogs.microsoft.com/on-the-issues/2023/04/06/stopping-cybercriminals-from-abusing-security-tools/">legacy copies of Cobalt Strike</a>.</li></ul><p>And then we dive into OT security with Dave Cullen, Field CTO for OTORIO.</p><p>As mentioned in the podcast, <a href="https://blog.ecapuano.com/p/so-you-want-to-be-a-soc-analyst-intro">here is a link</a> to the “So you want to be a SOC Analyst?” by <a href="https://www.linkedin.com/in/ecapuano/">Eric Capuano</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#26 - Intel Chat: 3CX to APT43. And a deep dive on the Capital One breach with Cloud Threat Detection Engineer, Day Johnson</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <itunes:title>#26 - Intel Chat: 3CX to APT43. And a deep dive on the Capital One breach with Cloud Threat Detection Engineer, Day Johnson</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12597412</guid>
      <link>https://share.transistor.fm/s/37bb106e</link>
      <description>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io">community Slack channel</a>.</p><ul><li>Crowdstrike reports the <a href="https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/">3CX supply chain attack</a>.</li><li>Agents arrested Conor <a href="https://flashpoint.io/blog/usa-vs-conor-brian-fitzpatrick/">Brian Fitzpatrick</a> on a charge of conspiracy to commit access device fraud.</li><li>SentinelOne reporting on the <a href="https://www.sentinelone.com/blog/decrypting-catb-ransomware-analyzing-their-latest-attack-methods/">CatB ransomware family</a> which is sometimes referred to as CatB99 or Baxtoy.</li><li>A new everything infostealer on the dark market called <a href="https://research.checkpoint.com/2023/rhadamanthys-the-everything-bagel-infostealer/">Radamanthys</a>.</li><li>Mandiant has assessed with high confidence they identified a new APT: <a href="https://www.mandiant.com/resources/reports/apt43-north-korea-cybercrime-espionage">APT43</a>.</li></ul><p>And then we deep dive the Capital One data breach discovered on July 19, 2019, with DataDog Cloud Threat Detection Engineer, Day Johnson.</p><p>As mentioned in the podcast, Day's cybersecurity education-focused YouTube channel can be found here: <a href="https://www.youtube.com/daycyberwox">@daycyberwox</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io">community Slack channel</a>.</p><ul><li>Crowdstrike reports the <a href="https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/">3CX supply chain attack</a>.</li><li>Agents arrested Conor <a href="https://flashpoint.io/blog/usa-vs-conor-brian-fitzpatrick/">Brian Fitzpatrick</a> on a charge of conspiracy to commit access device fraud.</li><li>SentinelOne reporting on the <a href="https://www.sentinelone.com/blog/decrypting-catb-ransomware-analyzing-their-latest-attack-methods/">CatB ransomware family</a> which is sometimes referred to as CatB99 or Baxtoy.</li><li>A new everything infostealer on the dark market called <a href="https://research.checkpoint.com/2023/rhadamanthys-the-everything-bagel-infostealer/">Radamanthys</a>.</li><li>Mandiant has assessed with high confidence they identified a new APT: <a href="https://www.mandiant.com/resources/reports/apt43-north-korea-cybercrime-espionage">APT43</a>.</li></ul><p>And then we deep dive the Capital One data breach discovered on July 19, 2019, with DataDog Cloud Threat Detection Engineer, Day Johnson.</p><p>As mentioned in the podcast, Day's cybersecurity education-focused YouTube channel can be found here: <a href="https://www.youtube.com/daycyberwox">@daycyberwox</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 05 Apr 2023 23:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/37bb106e/921ee264.mp3" length="42940000" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/L-DKp3GtcUtqyFzRZrQHipqcyCRknxakRYvEU1mHpxs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80YjM3/MzVmMDRiNjYyOGIz/NTg2YWFkNjk1ZGMx/NDRkNi5wbmc.jpg"/>
      <itunes:duration>3562</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's <a href="https://slack.limacharlie.io">community Slack channel</a>.</p><ul><li>Crowdstrike reports the <a href="https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/">3CX supply chain attack</a>.</li><li>Agents arrested Conor <a href="https://flashpoint.io/blog/usa-vs-conor-brian-fitzpatrick/">Brian Fitzpatrick</a> on a charge of conspiracy to commit access device fraud.</li><li>SentinelOne reporting on the <a href="https://www.sentinelone.com/blog/decrypting-catb-ransomware-analyzing-their-latest-attack-methods/">CatB ransomware family</a> which is sometimes referred to as CatB99 or Baxtoy.</li><li>A new everything infostealer on the dark market called <a href="https://research.checkpoint.com/2023/rhadamanthys-the-everything-bagel-infostealer/">Radamanthys</a>.</li><li>Mandiant has assessed with high confidence they identified a new APT: <a href="https://www.mandiant.com/resources/reports/apt43-north-korea-cybercrime-espionage">APT43</a>.</li></ul><p>And then we deep dive the Capital One data breach discovered on July 19, 2019, with DataDog Cloud Threat Detection Engineer, Day Johnson.</p><p>As mentioned in the podcast, Day's cybersecurity education-focused YouTube channel can be found here: <a href="https://www.youtube.com/daycyberwox">@daycyberwox</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#25 - Hacker History: Stuxnet (Part 1)</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:title>#25 - Hacker History: Stuxnet (Part 1)</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12539776</guid>
      <link>https://share.transistor.fm/s/3e0f6ba8</link>
      <description>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is the first part in a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet. </p><p>Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.</p><p>Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is the first part in a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet. </p><p>Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.</p><p>Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Mar 2023 09:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/3e0f6ba8/390d197e.mp3" length="14712852" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/RgXIoqWXfSaG4Z1Gnc28rPy00H6wEvbjna2dft56Ih8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNmIw/MWZmNTFiMzQxOWJl/MTYyMzU3MmY1MWNj/Y2U1MS5wbmc.jpg"/>
      <itunes:duration>1210</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This episode of the Cybersecurity Defenders podcast is the first part in a two-part mini-series about the greatest cyber attack ever conceived: Stuxnet. </p><p>Joining to help us tell the story is Kim Zetter, Journalist and Author - Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon.</p><p>Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as Operation Olympic Games. The program, started during the Bush administration, was rapidly expanded within the first months of Barack Obama's presidency.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#24 - Intel Chat: MS Outlook exploit. And ShmooCon organizers, Heidi and Bruce Potter.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <itunes:title>#24 - Intel Chat: MS Outlook exploit. And ShmooCon organizers, Heidi and Bruce Potter.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12491943</guid>
      <link>https://share.transistor.fm/s/b7d75e18</link>
      <description>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the <a href="https://slack.limacharlie.io/">LimaCharlie community Slack channel</a>:</p><ul><li><a href="https://twitter.com/cyb3rops/status/1636492182210199555"> CVE-2023-23397</a>: A zero-touch exploit that affects all versions of Windows Outlook. (<a href="https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_webdav_client_susp_execution.yml">Sigma rule</a>)</li><li><a href="https://blog.google/threat-analysis-group/magniber-ransomware-actors-used-a-variant-of-microsoft-smartscreen-bypass/"> CVE-2023-24880</a>: An unpatched security bypass in Microsoft’s SmartScreen security feature.</li><li><a href="https://www.mandiant.com/resources/blog/fortinet-malware-ecosystem">Mandiant</a> observes China-nexus threat actors targeting technologies that do not normally support endpoint detection and response solutions.</li><li>Kaspersky recently conducted an analysis of 155 dark web forums from January 2020 to June 2022. Threat groups are offering $240k salaries to tech jobseekers.</li></ul><p>And an interview with Heidi and Bruce Potter, <a href="https://www.shmoocon.org/">ShmooCon</a> organizers.</p><p> ShmooCon is an annual east coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software, and hardware solutions, and open discussions of critical infosec issues.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the <a href="https://slack.limacharlie.io/">LimaCharlie community Slack channel</a>:</p><ul><li><a href="https://twitter.com/cyb3rops/status/1636492182210199555"> CVE-2023-23397</a>: A zero-touch exploit that affects all versions of Windows Outlook. (<a href="https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_webdav_client_susp_execution.yml">Sigma rule</a>)</li><li><a href="https://blog.google/threat-analysis-group/magniber-ransomware-actors-used-a-variant-of-microsoft-smartscreen-bypass/"> CVE-2023-24880</a>: An unpatched security bypass in Microsoft’s SmartScreen security feature.</li><li><a href="https://www.mandiant.com/resources/blog/fortinet-malware-ecosystem">Mandiant</a> observes China-nexus threat actors targeting technologies that do not normally support endpoint detection and response solutions.</li><li>Kaspersky recently conducted an analysis of 155 dark web forums from January 2020 to June 2022. Threat groups are offering $240k salaries to tech jobseekers.</li></ul><p>And an interview with Heidi and Bruce Potter, <a href="https://www.shmoocon.org/">ShmooCon</a> organizers.</p><p> ShmooCon is an annual east coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software, and hardware solutions, and open discussions of critical infosec issues.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 22 Mar 2023 07:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b7d75e18/cb66b2b2.mp3" length="48439433" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/U7Vb1F7nltnVyXKBow0ZYRmNl21iHbosd81ZyYLfLCs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZGZl/NzY1Yjg3OWY1ODM4/NGI1YTRmMWE4YWNj/ZDhhNy5wbmc.jpg"/>
      <itunes:duration>4021</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the <a href="https://slack.limacharlie.io/">LimaCharlie community Slack channel</a>:</p><ul><li><a href="https://twitter.com/cyb3rops/status/1636492182210199555"> CVE-2023-23397</a>: A zero-touch exploit that affects all versions of Windows Outlook. (<a href="https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_webdav_client_susp_execution.yml">Sigma rule</a>)</li><li><a href="https://blog.google/threat-analysis-group/magniber-ransomware-actors-used-a-variant-of-microsoft-smartscreen-bypass/"> CVE-2023-24880</a>: An unpatched security bypass in Microsoft’s SmartScreen security feature.</li><li><a href="https://www.mandiant.com/resources/blog/fortinet-malware-ecosystem">Mandiant</a> observes China-nexus threat actors targeting technologies that do not normally support endpoint detection and response solutions.</li><li>Kaspersky recently conducted an analysis of 155 dark web forums from January 2020 to June 2022. Threat groups are offering $240k salaries to tech jobseekers.</li></ul><p>And an interview with Heidi and Bruce Potter, <a href="https://www.shmoocon.org/">ShmooCon</a> organizers.</p><p> ShmooCon is an annual east coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software, and hardware solutions, and open discussions of critical infosec issues.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#23 - Intel chat with Matt Bromiley and an interview with Joe Schreiber, Co-founder &amp; CEO of appNovi.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:title>#23 - Intel chat with Matt Bromiley and an interview with Joe Schreiber, Co-founder &amp; CEO of appNovi.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12450494</guid>
      <link>https://share.transistor.fm/s/011e027b</link>
      <description>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel:</p><ul><li>A new Microsoft Word Vulnerability: CVE-2023-21716. </li><li>The Emotet botnet is back spamming again.</li><li>A previously undisclosed toolset used by Sharp Panda, a long-running Chinese cyber-espionage operation targeting Southeast Asian government entities.</li><li>A SpaceX vendor has been compromised by a LockBit affiliate.</li><li>Ring LLC, the home security and smart home company owned by Amazon, has been ransomed by ALPHV ransomware group.</li></ul><p>And an interview with Joe Schreiber, Co-founder and CEO of <a href="https://appnovi.com/">appNovi</a>.</p><p>Joe has been doing IT security since dial-up. He utilizes his knowledge and experience as a practitioner, software developer, and business developer to build highly functional, scalable, usable and quality software.</p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel:</p><ul><li>A new Microsoft Word Vulnerability: CVE-2023-21716. </li><li>The Emotet botnet is back spamming again.</li><li>A previously undisclosed toolset used by Sharp Panda, a long-running Chinese cyber-espionage operation targeting Southeast Asian government entities.</li><li>A SpaceX vendor has been compromised by a LockBit affiliate.</li><li>Ring LLC, the home security and smart home company owned by Amazon, has been ransomed by ALPHV ransomware group.</li></ul><p>And an interview with Joe Schreiber, Co-founder and CEO of <a href="https://appnovi.com/">appNovi</a>.</p><p>Joe has been doing IT security since dial-up. He utilizes his knowledge and experience as a practitioner, software developer, and business developer to build highly functional, scalable, usable and quality software.</p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 15 Mar 2023 22:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/011e027b/efa83299.mp3" length="43075375" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/HRKkHEZgw5J9-J55HOekcTT6uY2MNNk1Sc6Za9DbqA8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kMjdj/ZmZhZDViMTk0ZDA1/MjFhNWQ3YzQwNzcx/ODg4NC5wbmc.jpg"/>
      <itunes:duration>3574</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel:</p><ul><li>A new Microsoft Word Vulnerability: CVE-2023-21716. </li><li>The Emotet botnet is back spamming again.</li><li>A previously undisclosed toolset used by Sharp Panda, a long-running Chinese cyber-espionage operation targeting Southeast Asian government entities.</li><li>A SpaceX vendor has been compromised by a LockBit affiliate.</li><li>Ring LLC, the home security and smart home company owned by Amazon, has been ransomed by ALPHV ransomware group.</li></ul><p>And an interview with Joe Schreiber, Co-founder and CEO of <a href="https://appnovi.com/">appNovi</a>.</p><p>Joe has been doing IT security since dial-up. He utilizes his knowledge and experience as a practitioner, software developer, and business developer to build highly functional, scalable, usable and quality software.</p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#22 - An intel chat with Matt Bromiley and an interview with Rich Heimann, Chief AI Officer at SilverSky.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:title>#22 - An intel chat with Matt Bromiley and an interview with Rich Heimann, Chief AI Officer at SilverSky.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12398572</guid>
      <link>https://share.transistor.fm/s/fc6f3cbd</link>
      <description>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel:</p><ul><li>Menlo Labs has uncovered an unknown threat actor that’s running an evasive threat campaign which is being distributed via Discord and is targeting government entities.</li><li>TA569 is a prolific threat actor who has been deploying website injections that run a Javascript payload known as SocGholish.</li><li>The risk to business from burned-out analysts.</li><li>The emerging post-explotation framework, EXFILTRATOR-22 or EX-22.</li></ul><p>And an interview with Rich Heimann, Chief AI Officer at SilverSky, where we talk about Machine Learning and Artificial Intelligence as they relate to cybersecurity.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel:</p><ul><li>Menlo Labs has uncovered an unknown threat actor that’s running an evasive threat campaign which is being distributed via Discord and is targeting government entities.</li><li>TA569 is a prolific threat actor who has been deploying website injections that run a Javascript payload known as SocGholish.</li><li>The risk to business from burned-out analysts.</li><li>The emerging post-explotation framework, EXFILTRATOR-22 or EX-22.</li></ul><p>And an interview with Rich Heimann, Chief AI Officer at SilverSky, where we talk about Machine Learning and Artificial Intelligence as they relate to cybersecurity.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 08 Mar 2023 06:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/fc6f3cbd/c320f198.mp3" length="44637714" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/fZjlmoZyeR8GFuww9pjcnkc8KIieZQPTpvYECFhrFuo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NmEz/ZWEwMjU3OGM4Y2I0/OWUzYzUzYzE2ODhl/ZGUzYi5wbmc.jpg"/>
      <itunes:duration>3704</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel:</p><ul><li>Menlo Labs has uncovered an unknown threat actor that’s running an evasive threat campaign which is being distributed via Discord and is targeting government entities.</li><li>TA569 is a prolific threat actor who has been deploying website injections that run a Javascript payload known as SocGholish.</li><li>The risk to business from burned-out analysts.</li><li>The emerging post-explotation framework, EXFILTRATOR-22 or EX-22.</li></ul><p>And an interview with Rich Heimann, Chief AI Officer at SilverSky, where we talk about Machine Learning and Artificial Intelligence as they relate to cybersecurity.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#21 - A intel chat with Matt Bromiley and an interview with Nick Gipson, Director of Cyber Operations at Pareto Cyber.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>#21 - A intel chat with Matt Bromiley and an interview with Nick Gipson, Director of Cyber Operations at Pareto Cyber.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12352144</guid>
      <link>https://share.transistor.fm/s/01e5781d</link>
      <description>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel. After that, an interview with Nick Gipson, Director of Cyber Operations at Pareto Cyber.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel. After that, an interview with Nick Gipson, Director of Cyber Operations at Pareto Cyber.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 01 Mar 2023 07:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/01e5781d/b7c7576b.mp3" length="22921521" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/SSCl7OgpxNvzjCsk0SZ_W00-gAet7MG3t2LiE39LU9c/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iNmQ2/NjNlNTc0OTk2MDY4/ZjJiMDY3ODRmMDI3/NDAyYS5wbmc.jpg"/>
      <itunes:duration>1894</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, we sit down with Matt Bromiley to talk about some of the latest intel coming out of the LimaCharlie community Slack channel. After that, an interview with Nick Gipson, Director of Cyber Operations at Pareto Cyber.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#20 - Hacker History: WannaCry</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>#20 - Hacker History: WannaCry</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12303300</guid>
      <link>https://share.transistor.fm/s/2aeb250c</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history, and with the help of Marcus Hutchins, tell the story of the WannaCry ransomware attack.</p><p>The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the Bitcoin cryptocurrency. It propagated by using EternalBlue, an exploit developed by the United States National Security Agency (NSA) for Windows systems. EternalBlue was stolen and leaked by a group called The Shadow Brokers a month prior to the attack. </p><p>Researcher Marcus Hutchins discovered the kill switch domain hardcoded in the malware. Registering a domain name for a DNS sinkhole stopped the attack spreading as a worm, because the ransomware only encrypted the computer's files if it was unable to connect to that domain, which all computers infected with WannaCry before the website's registration had been unable to do. While this did not help already infected systems, it severely slowed the spread of the initial infection and gave time for defensive measures to be deployed worldwide, particularly in North America and Asia, which had not been attacked to the same extent as elsewhere.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history, and with the help of Marcus Hutchins, tell the story of the WannaCry ransomware attack.</p><p>The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the Bitcoin cryptocurrency. It propagated by using EternalBlue, an exploit developed by the United States National Security Agency (NSA) for Windows systems. EternalBlue was stolen and leaked by a group called The Shadow Brokers a month prior to the attack. </p><p>Researcher Marcus Hutchins discovered the kill switch domain hardcoded in the malware. Registering a domain name for a DNS sinkhole stopped the attack spreading as a worm, because the ransomware only encrypted the computer's files if it was unable to connect to that domain, which all computers infected with WannaCry before the website's registration had been unable to do. While this did not help already infected systems, it severely slowed the spread of the initial infection and gave time for defensive measures to be deployed worldwide, particularly in North America and Asia, which had not been attacked to the same extent as elsewhere.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 22 Feb 2023 06:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2aeb250c/de5db65b.mp3" length="13535444" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/oixMR_RW0wRNVnjWLZam_h2JpiR7OBsv76spRfQL4BA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS85NmMw/YmRmMGYwZmUyZGE2/N2JhMzk0MjkxNWM1/YTgyNy5wbmc.jpg"/>
      <itunes:duration>1112</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history, and with the help of Marcus Hutchins, tell the story of the WannaCry ransomware attack.</p><p>The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the Bitcoin cryptocurrency. It propagated by using EternalBlue, an exploit developed by the United States National Security Agency (NSA) for Windows systems. EternalBlue was stolen and leaked by a group called The Shadow Brokers a month prior to the attack. </p><p>Researcher Marcus Hutchins discovered the kill switch domain hardcoded in the malware. Registering a domain name for a DNS sinkhole stopped the attack spreading as a worm, because the ransomware only encrypted the computer's files if it was unable to connect to that domain, which all computers infected with WannaCry before the website's registration had been unable to do. While this did not help already infected systems, it severely slowed the spread of the initial infection and gave time for defensive measures to be deployed worldwide, particularly in North America and Asia, which had not been attacked to the same extent as elsewhere.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#19 - Simply Cyber Report for February 15. Plus a conversation with Ira Winkler, Field CISO and Vice President of CYE</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>#19 - Simply Cyber Report for February 15. Plus a conversation with Ira Winkler, Field CISO and Vice President of CYE</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12256939</guid>
      <link>https://share.transistor.fm/s/8a9d7dd6</link>
      <description>
        <![CDATA[<p>This week on the Simply Cyber Report:</p><ul><li>Scores of Redis servers infested by sophisticated custom-built malware.</li><li>Oktapus hackers are back and targeting tech and gaming companies.</li><li>Russian hackers using new Graphiron information stealer in Ukraine.</li><li>New QakNote attacks push QBot malware via Microsoft OneNote files.</li><li>Fresh, buggy Clop ransomware variant targets Linux systems.</li></ul><p>We also sit down with Ira Winkler, Field CISO and Vice President of <a href="https://www.linkedin.com/company/cyesec/">CYE</a>. Ira shares a wide range of thoughts and experiences garnered from an exceptional career. </p><p>You can find the various books that Ira has written, which are mentioned in the podcast, at the  following links:</p><p><a href="https://www.amazon.com/You-CAN-Stop-Stupid-Accidental/dp/1119621984">You CAN Stop Stupid</a><br><a href="https://www.amazon.com/Advanced-Persistent-Security-Cyberwarfare-Implementing/dp/0128093161">Advanced Persistent Security</a><br><a href="https://www.amazon.com/Security-Awareness-Dummies-Ira-Winkler/dp/1119720923">Security Awareness for Dummies</a><br><a href="https://www.amazon.com/Cybersecurity-All-Dummies-Joseph-Steinberg/dp/139415285X">Cybersecurity All-in-one For Dummies</a></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>This week on the Simply Cyber Report:</p><ul><li>Scores of Redis servers infested by sophisticated custom-built malware.</li><li>Oktapus hackers are back and targeting tech and gaming companies.</li><li>Russian hackers using new Graphiron information stealer in Ukraine.</li><li>New QakNote attacks push QBot malware via Microsoft OneNote files.</li><li>Fresh, buggy Clop ransomware variant targets Linux systems.</li></ul><p>We also sit down with Ira Winkler, Field CISO and Vice President of <a href="https://www.linkedin.com/company/cyesec/">CYE</a>. Ira shares a wide range of thoughts and experiences garnered from an exceptional career. </p><p>You can find the various books that Ira has written, which are mentioned in the podcast, at the  following links:</p><p><a href="https://www.amazon.com/You-CAN-Stop-Stupid-Accidental/dp/1119621984">You CAN Stop Stupid</a><br><a href="https://www.amazon.com/Advanced-Persistent-Security-Cyberwarfare-Implementing/dp/0128093161">Advanced Persistent Security</a><br><a href="https://www.amazon.com/Security-Awareness-Dummies-Ira-Winkler/dp/1119720923">Security Awareness for Dummies</a><br><a href="https://www.amazon.com/Cybersecurity-All-Dummies-Joseph-Steinberg/dp/139415285X">Cybersecurity All-in-one For Dummies</a></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 15 Feb 2023 05:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8a9d7dd6/7f4d7286.mp3" length="31722485" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/I2WYcbquqnX-2ejtcmdcwpLix2Eu3_Xmwhlsa1dOB90/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNGQx/OTdjNjFhZWI2NjNh/NDA1ODVhNDRjNmUz/MjA2MC5wbmc.jpg"/>
      <itunes:duration>2628</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>This week on the Simply Cyber Report:</p><ul><li>Scores of Redis servers infested by sophisticated custom-built malware.</li><li>Oktapus hackers are back and targeting tech and gaming companies.</li><li>Russian hackers using new Graphiron information stealer in Ukraine.</li><li>New QakNote attacks push QBot malware via Microsoft OneNote files.</li><li>Fresh, buggy Clop ransomware variant targets Linux systems.</li></ul><p>We also sit down with Ira Winkler, Field CISO and Vice President of <a href="https://www.linkedin.com/company/cyesec/">CYE</a>. Ira shares a wide range of thoughts and experiences garnered from an exceptional career. </p><p>You can find the various books that Ira has written, which are mentioned in the podcast, at the  following links:</p><p><a href="https://www.amazon.com/You-CAN-Stop-Stupid-Accidental/dp/1119621984">You CAN Stop Stupid</a><br><a href="https://www.amazon.com/Advanced-Persistent-Security-Cyberwarfare-Implementing/dp/0128093161">Advanced Persistent Security</a><br><a href="https://www.amazon.com/Security-Awareness-Dummies-Ira-Winkler/dp/1119720923">Security Awareness for Dummies</a><br><a href="https://www.amazon.com/Cybersecurity-All-Dummies-Joseph-Steinberg/dp/139415285X">Cybersecurity All-in-one For Dummies</a></p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#18 - The Adversary Toolbox: BITS jobs. Plus an interview with Tyler Shields, entrepreneur and angel investor.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>#18 - The Adversary Toolbox: BITS jobs. Plus an interview with Tyler Shields, entrepreneur and angel investor.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12209587</guid>
      <link>https://share.transistor.fm/s/8a6f5a89</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about BITS jobs.</p><p>We also sit down with Tyler Shields: a cybersecurity veteran, entrepreneur, and angel investor. In our conversation, we talk about the economic conditions driving the tech sector layoffs we are seeing, what zombie companies are, and speculate on the future of AI.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about BITS jobs.</p><p>We also sit down with Tyler Shields: a cybersecurity veteran, entrepreneur, and angel investor. In our conversation, we talk about the economic conditions driving the tech sector layoffs we are seeing, what zombie companies are, and speculate on the future of AI.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 08 Feb 2023 07:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8a6f5a89/763173b1.mp3" length="18512871" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/StlhbDqgoQ4RTVYg0KjdPET6AMJ5haHXxmoVAv-DrjQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84NWI5/NmRhOWQyN2UyMGI2/NDRlNTgwNjgxNzIy/OTVhYi5wbmc.jpg"/>
      <itunes:duration>1527</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about BITS jobs.</p><p>We also sit down with Tyler Shields: a cybersecurity veteran, entrepreneur, and angel investor. In our conversation, we talk about the economic conditions driving the tech sector layoffs we are seeing, what zombie companies are, and speculate on the future of AI.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#17 - Simply Cyber Report for Feb 1. Plus a conversation with Michael Argast, Co-founder &amp; CEO of Kobalt.io</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>#17 - Simply Cyber Report for Feb 1. Plus a conversation with Michael Argast, Co-founder &amp; CEO of Kobalt.io</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12160869</guid>
      <link>https://share.transistor.fm/s/4d1936f2</link>
      <description>
        <![CDATA[<p>Microsoft has started blocking the execution of XLL add-ins downloaded from the Internet. The hacking group DragonSpark is leveraging Golang source code interpretation to evade detection. Threat actors are turning to Sliver to replace more popular frameworks Cobalt Strike and Metasploit. Over 4,500 WordPress sites have been hacked and Emote malware makes a comeback. Emotet is back with new evasion techniques in MS Excel.</p><p>We also sit down with <a href="https://www.linkedin.com/in/michaelargast/">Michael Argast</a>, Co-founder and CEO of <a href="https://kobalt.io/">Kobalt.io</a>. We learn about Kobalt's approach to scaling cybersecurity services for small and medium-sized businesses, and also some great advice on what it takes to build services for this part of the market. A great conversation that is full of tidbits of wisdom for anybody looking to start a security services company.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Microsoft has started blocking the execution of XLL add-ins downloaded from the Internet. The hacking group DragonSpark is leveraging Golang source code interpretation to evade detection. Threat actors are turning to Sliver to replace more popular frameworks Cobalt Strike and Metasploit. Over 4,500 WordPress sites have been hacked and Emote malware makes a comeback. Emotet is back with new evasion techniques in MS Excel.</p><p>We also sit down with <a href="https://www.linkedin.com/in/michaelargast/">Michael Argast</a>, Co-founder and CEO of <a href="https://kobalt.io/">Kobalt.io</a>. We learn about Kobalt's approach to scaling cybersecurity services for small and medium-sized businesses, and also some great advice on what it takes to build services for this part of the market. A great conversation that is full of tidbits of wisdom for anybody looking to start a security services company.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 01 Feb 2023 06:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/4d1936f2/e2b5f636.mp3" length="25172209" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/YYhpDy2fcA0yniMTYndb2MUYhoSWcyK0Oc0gw4GXyBA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wZjZj/ZTNmNmRkNGFjYTc3/ZDE1YmM1MmVmM2Qw/ODI3Zi5wbmc.jpg"/>
      <itunes:duration>2082</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Microsoft has started blocking the execution of XLL add-ins downloaded from the Internet. The hacking group DragonSpark is leveraging Golang source code interpretation to evade detection. Threat actors are turning to Sliver to replace more popular frameworks Cobalt Strike and Metasploit. Over 4,500 WordPress sites have been hacked and Emote malware makes a comeback. Emotet is back with new evasion techniques in MS Excel.</p><p>We also sit down with <a href="https://www.linkedin.com/in/michaelargast/">Michael Argast</a>, Co-founder and CEO of <a href="https://kobalt.io/">Kobalt.io</a>. We learn about Kobalt's approach to scaling cybersecurity services for small and medium-sized businesses, and also some great advice on what it takes to build services for this part of the market. A great conversation that is full of tidbits of wisdom for anybody looking to start a security services company.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#16 - Hacker History: NotPetya</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>#16 - Hacker History: NotPetya</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12122226</guid>
      <link>https://share.transistor.fm/s/d72d377b</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Amit Serper, a hacker and reverse engineer, who was instrumental in stopping the most devastating cyber attack in history: NotPetya.</p><p>On 27 June 2017, a major global cyberattack began (Ukrainian companies were among the first to state they were being attacked), utilizing a new variant of Petya. On that day, Kaspersky Lab reported infections in France, Germany, Italy, Poland, the United Kingdom, and the United States, but that the majority of infections targeted Russia and Ukraine, where more than 80 companies were initially attacked, including the National Bank of Ukraine. ESET estimated on 28 June 2017 that 80% of all infections were in Ukraine, with Germany second hardest hit with about 9%.Russian president Vladimir Putin's press secretary, Dmitry Peskov, stated that the attack had caused no serious damage in Russia. Experts believed this was a politically-motivated attack against Ukraine, since it occurred on the eve of the Ukrainian holiday Constitution Day.</p><p>Kaspersky dubbed this variant "NotPetya", as it has major differences in its operations in comparison to earlier variants. McAfee engineer Christiaan Beek stated that this variant was designed to spread quickly, and that it had been targeting "complete energy companies, the power grid, bus stations, gas stations, the airport, and banks".</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Amit Serper, a hacker and reverse engineer, who was instrumental in stopping the most devastating cyber attack in history: NotPetya.</p><p>On 27 June 2017, a major global cyberattack began (Ukrainian companies were among the first to state they were being attacked), utilizing a new variant of Petya. On that day, Kaspersky Lab reported infections in France, Germany, Italy, Poland, the United Kingdom, and the United States, but that the majority of infections targeted Russia and Ukraine, where more than 80 companies were initially attacked, including the National Bank of Ukraine. ESET estimated on 28 June 2017 that 80% of all infections were in Ukraine, with Germany second hardest hit with about 9%.Russian president Vladimir Putin's press secretary, Dmitry Peskov, stated that the attack had caused no serious damage in Russia. Experts believed this was a politically-motivated attack against Ukraine, since it occurred on the eve of the Ukrainian holiday Constitution Day.</p><p>Kaspersky dubbed this variant "NotPetya", as it has major differences in its operations in comparison to earlier variants. McAfee engineer Christiaan Beek stated that this variant was designed to spread quickly, and that it had been targeting "complete energy companies, the power grid, bus stations, gas stations, the airport, and banks".</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 26 Jan 2023 06:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/d72d377b/c95a33de.mp3" length="14141694" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/y65PeO-nXj279yd28B3D4Z1nGR4j2QDtrQMMVkth33E/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82MWU0/NjNiMzY5Nzc2YWI4/Y2U1YTI1ZTg0MGU2/N2I0Yy5wbmc.jpg"/>
      <itunes:duration>1163</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Amit Serper, a hacker and reverse engineer, who was instrumental in stopping the most devastating cyber attack in history: NotPetya.</p><p>On 27 June 2017, a major global cyberattack began (Ukrainian companies were among the first to state they were being attacked), utilizing a new variant of Petya. On that day, Kaspersky Lab reported infections in France, Germany, Italy, Poland, the United Kingdom, and the United States, but that the majority of infections targeted Russia and Ukraine, where more than 80 companies were initially attacked, including the National Bank of Ukraine. ESET estimated on 28 June 2017 that 80% of all infections were in Ukraine, with Germany second hardest hit with about 9%.Russian president Vladimir Putin's press secretary, Dmitry Peskov, stated that the attack had caused no serious damage in Russia. Experts believed this was a politically-motivated attack against Ukraine, since it occurred on the eve of the Ukrainian holiday Constitution Day.</p><p>Kaspersky dubbed this variant "NotPetya", as it has major differences in its operations in comparison to earlier variants. McAfee engineer Christiaan Beek stated that this variant was designed to spread quickly, and that it had been targeting "complete energy companies, the power grid, bus stations, gas stations, the airport, and banks".</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#15 - The Adversary Toolbox: RDP. Plus an interview with Michael Laudenslager, VP of Cybersecurity at Churchill Mortgage</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>#15 - The Adversary Toolbox: RDP. Plus an interview with Michael Laudenslager, VP of Cybersecurity at Churchill Mortgage</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12069545</guid>
      <link>https://share.transistor.fm/s/2272f69b</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about RDP.</p><p>We also sit down with Michael Laudenslager, VP of Cybersecurity at Churchill Mortgage and talk about security in the cloud.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about RDP.</p><p>We also sit down with Michael Laudenslager, VP of Cybersecurity at Churchill Mortgage and talk about security in the cloud.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 18 Jan 2023 15:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/2272f69b/ceac583e.mp3" length="33743961" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/V3vDmBkYBmgNz6fHs_fBmVWKHaJ7biN7RKh-JfmdLyk/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80YWEx/Mjk3OTdiNzllMmU1/YTgyNjYyOTZhYmU5/MWQwMi5wbmc.jpg"/>
      <itunes:duration>2795</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about RDP.</p><p>We also sit down with Michael Laudenslager, VP of Cybersecurity at Churchill Mortgage and talk about security in the cloud.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#14 - Simply Cyber Report for Jan 12. Plus a conversation with Walter Haydock, Founder and CEO of StackAware.</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#14 - Simply Cyber Report for Jan 12. Plus a conversation with Walter Haydock, Founder and CEO of StackAware.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-12031139</guid>
      <link>https://share.transistor.fm/s/09ed203d</link>
      <description>
        <![CDATA[<p>Unknown threat actors have been observed hiding malware execution behind a legitimate Windows support binary. S3 buckets are now encrypted by default. A powerful Android malware has been tuned to target banking applications. And it is the end of life for Windows Server 2008.</p><p>We also sit down with Walter Haydock, Founder and CEO of StackAware. We learn about StackAware and their approach to vulnerability management, and also how Walter got his company off of the ground using low-code tooling. A fascinating conversation for anyone looking to start their own cybersecurity company.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Unknown threat actors have been observed hiding malware execution behind a legitimate Windows support binary. S3 buckets are now encrypted by default. A powerful Android malware has been tuned to target banking applications. And it is the end of life for Windows Server 2008.</p><p>We also sit down with Walter Haydock, Founder and CEO of StackAware. We learn about StackAware and their approach to vulnerability management, and also how Walter got his company off of the ground using low-code tooling. A fascinating conversation for anyone looking to start their own cybersecurity company.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Thu, 12 Jan 2023 16:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/09ed203d/afb5ec71.mp3" length="38783879" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/EaSCXv8VswUn3YmYBBj5gWnchfRYxIijFLIEW2LsOMc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zMTM0/NTExNzg1ZDU2NzYy/NTkwNDI1OTdlZWY4/ZTEzYy5wbmc.jpg"/>
      <itunes:duration>2411</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>Unknown threat actors have been observed hiding malware execution behind a legitimate Windows support binary. S3 buckets are now encrypted by default. A powerful Android malware has been tuned to target banking applications. And it is the end of life for Windows Server 2008.</p><p>We also sit down with Walter Haydock, Founder and CEO of StackAware. We learn about StackAware and their approach to vulnerability management, and also how Walter got his company off of the ground using low-code tooling. A fascinating conversation for anyone looking to start their own cybersecurity company.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#13 - Hacker History: Titan Rain</title>
      <itunes:season>2</itunes:season>
      <podcast:season>2</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>#13 - Hacker History: Titan Rain</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11979184</guid>
      <link>https://share.transistor.fm/s/35aab90f</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Shawn Carpenter; a rogue cybersecurity defender who singlehandedly identified a Chinese APT. It is a phenomenal story that exemplifies the grit and moral fortitude that the best defenders among us have. </p><p><b>Titan Rain</b> was a series of coordinated attacks on computer systems in the United States since 2003; they were known to have been ongoing for at least three years. The attacks originated in Guangdong, China. The activity is believed to be associated with a state-sponsored advanced persistent threat. It was given the designation <em>Titan Rain</em> by the federal government of the United States.</p><p>Titan Rain hackers gained access to many United States defense contractor computer networks, which were targeted for their sensitive information, including those at Lockheed Martin, Sandia National Laboratories, Redstone Arsenal, and NASA.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Shawn Carpenter; a rogue cybersecurity defender who singlehandedly identified a Chinese APT. It is a phenomenal story that exemplifies the grit and moral fortitude that the best defenders among us have. </p><p><b>Titan Rain</b> was a series of coordinated attacks on computer systems in the United States since 2003; they were known to have been ongoing for at least three years. The attacks originated in Guangdong, China. The activity is believed to be associated with a state-sponsored advanced persistent threat. It was given the designation <em>Titan Rain</em> by the federal government of the United States.</p><p>Titan Rain hackers gained access to many United States defense contractor computer networks, which were targeted for their sensitive information, including those at Lockheed Martin, Sandia National Laboratories, Redstone Arsenal, and NASA.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 04 Jan 2023 17:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/35aab90f/d1b03ad8.mp3" length="28370711" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/TjVLTVc-2ueK9BVI9o6fV8VW7xbKRvAf2oeD4o60qsw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80MzM3/ZmEzOWI3N2Y5NzQ2/ZWVlZDM4ZmYzOTdj/Y2IyMC5wbmc.jpg"/>
      <itunes:duration>1174</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders podcast, we recount some hacker history and tell the story of Shawn Carpenter; a rogue cybersecurity defender who singlehandedly identified a Chinese APT. It is a phenomenal story that exemplifies the grit and moral fortitude that the best defenders among us have. </p><p><b>Titan Rain</b> was a series of coordinated attacks on computer systems in the United States since 2003; they were known to have been ongoing for at least three years. The attacks originated in Guangdong, China. The activity is believed to be associated with a state-sponsored advanced persistent threat. It was given the designation <em>Titan Rain</em> by the federal government of the United States.</p><p>Titan Rain hackers gained access to many United States defense contractor computer networks, which were targeted for their sensitive information, including those at Lockheed Martin, Sandia National Laboratories, Redstone Arsenal, and NASA.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#12 - Simply Cyber Report for December 28. Plus an interview with Jason Chan, former VP of Security at Netflix.</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:title>#12 - Simply Cyber Report for December 28. Plus an interview with Jason Chan, former VP of Security at Netflix.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11941479</guid>
      <link>https://share.transistor.fm/s/727e6a72</link>
      <description>
        <![CDATA[<p>New vulnerability found in WooCommerece Gift Cards Premium Wordpress plugin with CVSS score of 9.8.</p><p>Fin7 has developed an AI-powered automated attacking tool called Checkmarks. Checkmarks is designed to auto-attack ms exchange systems, perform post exploitation actions, and grab enough data to allow FIN7 to understand their victim.</p><p>Raspberry Robin has a new feature. This version of Raspberry Robin has two payloads, one designed to be discovered if the malware believes it's being analyzed in a sandbox. This fake payload look legit including looking at the registry on start up to check for infection, pulling down an adware named 'browserassist'. This payload has shellcode and a PE file with the MZ magic bytes removed to hide its not a PE file.</p><p>Plus an interview with Jason Chan, former VP of Information Security at Netflix <b> </b>about how he helped build their security program from the ground up.</p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>New vulnerability found in WooCommerece Gift Cards Premium Wordpress plugin with CVSS score of 9.8.</p><p>Fin7 has developed an AI-powered automated attacking tool called Checkmarks. Checkmarks is designed to auto-attack ms exchange systems, perform post exploitation actions, and grab enough data to allow FIN7 to understand their victim.</p><p>Raspberry Robin has a new feature. This version of Raspberry Robin has two payloads, one designed to be discovered if the malware believes it's being analyzed in a sandbox. This fake payload look legit including looking at the registry on start up to check for infection, pulling down an adware named 'browserassist'. This payload has shellcode and a PE file with the MZ magic bytes removed to hide its not a PE file.</p><p>Plus an interview with Jason Chan, former VP of Information Security at Netflix <b> </b>about how he helped build their security program from the ground up.</p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 28 Dec 2022 12:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/727e6a72/313e7dcf.mp3" length="34129307" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/7Ty0v-wv_dGK54Hu07s5mBckRU99qNjeu96tfEiBrhY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lNjFl/YzEzMDc1NTRlYzE0/NDNmYzFlYmVhZWI3/YTVlMC5wbmc.jpg"/>
      <itunes:duration>2121</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>New vulnerability found in WooCommerece Gift Cards Premium Wordpress plugin with CVSS score of 9.8.</p><p>Fin7 has developed an AI-powered automated attacking tool called Checkmarks. Checkmarks is designed to auto-attack ms exchange systems, perform post exploitation actions, and grab enough data to allow FIN7 to understand their victim.</p><p>Raspberry Robin has a new feature. This version of Raspberry Robin has two payloads, one designed to be discovered if the malware believes it's being analyzed in a sandbox. This fake payload look legit including looking at the registry on start up to check for infection, pulling down an adware named 'browserassist'. This payload has shellcode and a PE file with the MZ magic bytes removed to hide its not a PE file.</p><p>Plus an interview with Jason Chan, former VP of Information Security at Netflix <b> </b>about how he helped build their security program from the ground up.</p><p><br></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#11 - The Adversary Toolbox: WinRM + PowerShell Remoting. Plus Zack Allen, Director of Security Detection &amp; Research at Datadog.</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <itunes:title>#11 - The Adversary Toolbox: WinRM + PowerShell Remoting. Plus Zack Allen, Director of Security Detection &amp; Research at Datadog.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11911701</guid>
      <link>https://share.transistor.fm/s/912a83fa</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about WinRM + PowerShell Remoting.</p><p>We also sit down with Zack Allen, Director of Security Detection &amp; Research at Datadog, about managing uncertainty, some of his favorite tools, and building quality detections.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about WinRM + PowerShell Remoting.</p><p>We also sit down with Zack Allen, Director of Security Detection &amp; Research at Datadog, about managing uncertainty, some of his favorite tools, and building quality detections.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 21 Dec 2022 15:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/912a83fa/d3c93302.mp3" length="32951016" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/q-gojk9GhxMXYwaV3GH9wKgBiu3CUYA6jixCFsBIvio/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83ZTg4/MWNlY2EzZDUzYzBl/ZGU5MTQwMGVkNTky/YThiZi5wbmc.jpg"/>
      <itunes:duration>2047</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox to tell us all about WinRM + PowerShell Remoting.</p><p>We also sit down with Zack Allen, Director of Security Detection &amp; Research at Datadog, about managing uncertainty, some of his favorite tools, and building quality detections.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#10 - Simply Cyber Report for December 14. Plus a conversation with several Open Source cybersecurity founders.</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:title>#10 - Simply Cyber Report for December 14. Plus a conversation with several Open Source cybersecurity founders.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11871982</guid>
      <link>https://share.transistor.fm/s/b825ad37</link>
      <description>
        <![CDATA[<p>The Simply Cyber Report for December 14, 2022.</p><p>Go-based malware named Zerobot in the wild. Android malware dubbed "Zombinder" a Just-in-time Trojan style malware. Iranian based APT, has been pushing hard with remote administration tooling.</p><p>A roundtable conversation with several Open Source cybersecurity founders. During the conversation we discuss the complexities of open-source as it relates to cybersecurity, the effects it has on the industry, funding models, what inspired these projects, how they came to be, how they are trying to grow, and any lessons - good or bad - they have learned along the way.</p><p>The panelist include:</p><p>Zach Wasserman from <a href="https://www.osquery.io/">osquery</a><br>Lennart Koopmann from <a href="https://www.graylog.org/">Graylog, Inc.</a><br>Peter Manev from <a href="https://suricata.io/">Suricata</a></p><p>And we acknowledge some heavy audio compression during the roundtable conversation. We will be employing some new recording technology for future group conversations.</p><p>As always, we would love to hear from you. Questions, feedback and ideas can be directed to <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>The Simply Cyber Report for December 14, 2022.</p><p>Go-based malware named Zerobot in the wild. Android malware dubbed "Zombinder" a Just-in-time Trojan style malware. Iranian based APT, has been pushing hard with remote administration tooling.</p><p>A roundtable conversation with several Open Source cybersecurity founders. During the conversation we discuss the complexities of open-source as it relates to cybersecurity, the effects it has on the industry, funding models, what inspired these projects, how they came to be, how they are trying to grow, and any lessons - good or bad - they have learned along the way.</p><p>The panelist include:</p><p>Zach Wasserman from <a href="https://www.osquery.io/">osquery</a><br>Lennart Koopmann from <a href="https://www.graylog.org/">Graylog, Inc.</a><br>Peter Manev from <a href="https://suricata.io/">Suricata</a></p><p>And we acknowledge some heavy audio compression during the roundtable conversation. We will be employing some new recording technology for future group conversations.</p><p>As always, we would love to hear from you. Questions, feedback and ideas can be directed to <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 14 Dec 2022 16:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/b825ad37/92d9d4e9.mp3" length="44145472" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/vQCDWaHkLwimvn8JiHg2x2QYL2WzAyUOgaI5xvXGltA/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mN2Y4/Zjk2NDMyZTY4YTRk/NGI4Yjk5OTIzNTUw/ZDIwYy5wbmc.jpg"/>
      <itunes:duration>3663</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>The Simply Cyber Report for December 14, 2022.</p><p>Go-based malware named Zerobot in the wild. Android malware dubbed "Zombinder" a Just-in-time Trojan style malware. Iranian based APT, has been pushing hard with remote administration tooling.</p><p>A roundtable conversation with several Open Source cybersecurity founders. During the conversation we discuss the complexities of open-source as it relates to cybersecurity, the effects it has on the industry, funding models, what inspired these projects, how they came to be, how they are trying to grow, and any lessons - good or bad - they have learned along the way.</p><p>The panelist include:</p><p>Zach Wasserman from <a href="https://www.osquery.io/">osquery</a><br>Lennart Koopmann from <a href="https://www.graylog.org/">Graylog, Inc.</a><br>Peter Manev from <a href="https://suricata.io/">Suricata</a></p><p>And we acknowledge some heavy audio compression during the roundtable conversation. We will be employing some new recording technology for future group conversations.</p><p>As always, we would love to hear from you. Questions, feedback and ideas can be directed to <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#9 - Predictions for the future from 2022</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:title>#9 - Predictions for the future from 2022</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11831372</guid>
      <link>https://share.transistor.fm/s/9a9288cc</link>
      <description>
        <![CDATA[<p>As we get ready to say goodbye to 2022 the team at the Cybersecurity Defenders podcast thought it would be nice to review all the predictions for the future made by guests on this show so far.</p><p>It is a fun episode and will be interesting to circle back on next year at the same time.</p><p>In the show, we talk about Dr. Joseph Burt-Miller Jr's study hall group on Discord - here is the link for anybody interested in checking it out: <a href="https://discord.gg/Z8gaAvnS4m">https://discord.gg/Z8gaAvnS4m</a></p><p>As always, your feedback is always welcome. If you have any criticisms or ideas for the show, please don't hesitate to reach out to us at <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>As we get ready to say goodbye to 2022 the team at the Cybersecurity Defenders podcast thought it would be nice to review all the predictions for the future made by guests on this show so far.</p><p>It is a fun episode and will be interesting to circle back on next year at the same time.</p><p>In the show, we talk about Dr. Joseph Burt-Miller Jr's study hall group on Discord - here is the link for anybody interested in checking it out: <a href="https://discord.gg/Z8gaAvnS4m">https://discord.gg/Z8gaAvnS4m</a></p><p>As always, your feedback is always welcome. If you have any criticisms or ideas for the show, please don't hesitate to reach out to us at <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 07 Dec 2022 16:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/9a9288cc/33a80eca.mp3" length="15404371" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/NQM98FLmbUUGJYuYxfvQLEdZ6JIzsEvFd6VkdwI0Hwo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jYTEz/MzgzYzgxOWY2MDYw/M2YzZWFjYTU2MDM4/ZDQxMC5wbmc.jpg"/>
      <itunes:duration>1268</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>As we get ready to say goodbye to 2022 the team at the Cybersecurity Defenders podcast thought it would be nice to review all the predictions for the future made by guests on this show so far.</p><p>It is a fun episode and will be interesting to circle back on next year at the same time.</p><p>In the show, we talk about Dr. Joseph Burt-Miller Jr's study hall group on Discord - here is the link for anybody interested in checking it out: <a href="https://discord.gg/Z8gaAvnS4m">https://discord.gg/Z8gaAvnS4m</a></p><p>As always, your feedback is always welcome. If you have any criticisms or ideas for the show, please don't hesitate to reach out to us at <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#8 - Simply Cyber Report for Nov 30 and Daniel Velasquez of Ground Truth Connections</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>#8 - Simply Cyber Report for Nov 30 and Daniel Velasquez of Ground Truth Connections</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11788991</guid>
      <link>https://share.transistor.fm/s/dbbd24e9</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report.</p><p>We also sit down with Daniel Velasquez, founder of <a href="https://www.linkedin.com/company/ground-truth-connections/">Ground Truth Connections</a>.</p><p>Daniel has had a very interesting career. He has been a drone pilot inside of a war zone, worked in signals intelligence, been a CIA Targeter and risen through the ranks at Mandiant. Daniel is now the CEO and Founder of Ground Truth Connections who are operating on the ground in Ukraine with a humanitarian mission.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report.</p><p>We also sit down with Daniel Velasquez, founder of <a href="https://www.linkedin.com/company/ground-truth-connections/">Ground Truth Connections</a>.</p><p>Daniel has had a very interesting career. He has been a drone pilot inside of a war zone, worked in signals intelligence, been a CIA Targeter and risen through the ranks at Mandiant. Daniel is now the CEO and Founder of Ground Truth Connections who are operating on the ground in Ukraine with a humanitarian mission.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 30 Nov 2022 15:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/dbbd24e9/1b4cf272.mp3" length="24587543" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/tnf_RefXae47wPNQItX4VdFVAJg0CN4ANBicRS-cTzw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kNWM1/ODZhMTQwODEzMTM5/NWM4Yjk5ZDgyNjU1/MGRlNS5wbmc.jpg"/>
      <itunes:duration>2033</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report.</p><p>We also sit down with Daniel Velasquez, founder of <a href="https://www.linkedin.com/company/ground-truth-connections/">Ground Truth Connections</a>.</p><p>Daniel has had a very interesting career. He has been a drone pilot inside of a war zone, worked in signals intelligence, been a CIA Targeter and risen through the ranks at Mandiant. Daniel is now the CEO and Founder of Ground Truth Connections who are operating on the ground in Ukraine with a humanitarian mission.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#7 - Hacker History: Operation Flyhook</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>#7 - Hacker History: Operation Flyhook</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11752561</guid>
      <link>https://share.transistor.fm/s/1ec4fe00</link>
      <description>
        <![CDATA[<p>In this episode, we recount the story of Operation Flyhook - an FBI sting operation in 2000 that resulted in the arrest of two Russian hackers on American soil. It is quite the story and leaves us with some pretty heavy conclusions.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>Any questions or feedback can be directed to <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, we recount the story of Operation Flyhook - an FBI sting operation in 2000 that resulted in the arrest of two Russian hackers on American soil. It is quite the story and leaves us with some pretty heavy conclusions.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>Any questions or feedback can be directed to <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 23 Nov 2022 17:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/1ec4fe00/dad3496c.mp3" length="13192211" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ATpVIm739j_Z6PNjJ3EXlFAMjvwXSY3wlKnc8xpzN4M/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYjBi/NzU0MGNiZTg2YTg1/OWY5YTYzYmM4MzM3/MzdmMi5wbmc.jpg"/>
      <itunes:duration>1083</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, we recount the story of Operation Flyhook - an FBI sting operation in 2000 that resulted in the arrest of two Russian hackers on American soil. It is quite the story and leaves us with some pretty heavy conclusions.</p><p>This episode was written by Nathaniel Nelson, narrated by Christopher Luft, and produced by the team at <a href="https://limacharlie.io/">LimaCharlie</a>.</p><p>Any questions or feedback can be directed to <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#6 - Simply Cyber Report for Nov. 16 and David Burkett, Cloud Detection Engineer</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>#6 - Simply Cyber Report for Nov. 16 and David Burkett, Cloud Detection Engineer</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11705957</guid>
      <link>https://share.transistor.fm/s/0ad59d4d</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report.</p><p>We also sit down with David Burkett, co-author of <a href="https://soteria.io/detectors-as-code/">Detectors as Code</a>.</p><p>David is an experienced Information Security Architect with a demonstrated history of working in the security industry in both Government and the Telecommunications / Service Provider Industries. He is skilled in Security Information and Event Management, Security Monitoring, Python, and Digital Forensics among other things.</p><p>IN our talk with David about UAPs he references this video: <a href="https://youtu.be/ZBtMbBPzqHY">Navy pilot describes encounter with UFOs</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report.</p><p>We also sit down with David Burkett, co-author of <a href="https://soteria.io/detectors-as-code/">Detectors as Code</a>.</p><p>David is an experienced Information Security Architect with a demonstrated history of working in the security industry in both Government and the Telecommunications / Service Provider Industries. He is skilled in Security Information and Event Management, Security Monitoring, Python, and Digital Forensics among other things.</p><p>IN our talk with David about UAPs he references this video: <a href="https://youtu.be/ZBtMbBPzqHY">Navy pilot describes encounter with UFOs</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 16 Nov 2022 15:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/0ad59d4d/633e5fa2.mp3" length="36374924" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/wJ4jVjlgaNSnB5-PZq6_tgLY7tSPe-2z_0R3VQmYR30/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iOGJm/ZjA4YWRiMjNkYzJl/Y2E3ZGMyZDY5NDBk/OTkxZi5wbmc.jpg"/>
      <itunes:duration>3015</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report.</p><p>We also sit down with David Burkett, co-author of <a href="https://soteria.io/detectors-as-code/">Detectors as Code</a>.</p><p>David is an experienced Information Security Architect with a demonstrated history of working in the security industry in both Government and the Telecommunications / Service Provider Industries. He is skilled in Security Information and Event Management, Security Monitoring, Python, and Digital Forensics among other things.</p><p>IN our talk with David about UAPs he references this video: <a href="https://youtu.be/ZBtMbBPzqHY">Navy pilot describes encounter with UFOs</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#5 - The Adversary Toolbox: PaExec. Plus Eric Capuano, Founder &amp; CEO of Recon Infosec</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>#5 - The Adversary Toolbox: PaExec. Plus Eric Capuano, Founder &amp; CEO of Recon Infosec</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11662912</guid>
      <link>https://share.transistor.fm/s/7eff748f</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox and tells us all about PaExec.</p><p>We also sit down to chat with Eric Capuano, Founder and CEO of <a href="https://www.reconinfosec.com/">Recon Infosec</a>.</p><p>During the conversation with Eric, we talk about many different things including the <a href="https://opensoc.io/">OpenSoc Network Defense Range</a> and their new <a href="https://www.reconinfosec.com/thursday-defensive/">Thursday Defensive</a> webcast.</p><p>If you have any suggestions or feedback please don't hesitate to reach out to us: <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox and tells us all about PaExec.</p><p>We also sit down to chat with Eric Capuano, Founder and CEO of <a href="https://www.reconinfosec.com/">Recon Infosec</a>.</p><p>During the conversation with Eric, we talk about many different things including the <a href="https://opensoc.io/">OpenSoc Network Defense Range</a> and their new <a href="https://www.reconinfosec.com/thursday-defensive/">Thursday Defensive</a> webcast.</p><p>If you have any suggestions or feedback please don't hesitate to reach out to us: <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 09 Nov 2022 14:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/7eff748f/727d44d1.mp3" length="30061974" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/UqRtXHNgpAuPWWZ2kFnsvAwPptU3qjpYVBT18iNOEK8/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MGVm/OGU2MTIwYWEwMjM3/ZWJiMTE1NjFlNDlm/ODRkNS5wbmc.jpg"/>
      <itunes:duration>2489</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley opens up the Adversary Toolbox and tells us all about PaExec.</p><p>We also sit down to chat with Eric Capuano, Founder and CEO of <a href="https://www.reconinfosec.com/">Recon Infosec</a>.</p><p>During the conversation with Eric, we talk about many different things including the <a href="https://opensoc.io/">OpenSoc Network Defense Range</a> and their new <a href="https://www.reconinfosec.com/thursday-defensive/">Thursday Defensive</a> webcast.</p><p>If you have any suggestions or feedback please don't hesitate to reach out to us: <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#4 - Simply Cyber Report for Nov. 2 and Paul Caiazzo of SnapAttack</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>#4 - Simply Cyber Report for Nov. 2 and Paul Caiazzo of SnapAttack</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11617104</guid>
      <link>https://share.transistor.fm/s/8aff70d3</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report</p><p>We also sit down with Paul Caiazzo: cybersecurity expert, entrepreneur and strategist, CISO and CPO.</p><p>Paul has dedicated his career to advancing the field of global cyber security. In his current role as Chief Growth Officer at SnapAttack, Paul focuses on product/market fit, strategic partnerships, and business development.</p><p>Paul continues to support Avertium as an Advisory Board Member, focused on brand ambassadorship, adversary intelligence, and security industry trends. Prior to Avertium, Paul was the Co-Founder and CEO of TruShield Security Solutions, which was acquired by Sunstone Partners as one of the founding companies of Avertium </p><p>His foundation in the finance industry gave him first-hand experience in how crippling cybersecurity issues can be for individuals, businesses, and even the Federal Government. This sparked his interest in building a company where he could help clients not just understand the risks they face, but to combat them with effective mitigation strategies. </p><p>Under Paul’s leadership, TruShield earned a distinguished reputation as one of the fastest growing companies in the cybersecurity industry. Paul also serves as the Cybersecurity Advisor to the Science and Technology Policy Center for Development, where he utilizes his expertise to help the nonprofit achieve their goal of advancing ICT in developing countries. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report</p><p>We also sit down with Paul Caiazzo: cybersecurity expert, entrepreneur and strategist, CISO and CPO.</p><p>Paul has dedicated his career to advancing the field of global cyber security. In his current role as Chief Growth Officer at SnapAttack, Paul focuses on product/market fit, strategic partnerships, and business development.</p><p>Paul continues to support Avertium as an Advisory Board Member, focused on brand ambassadorship, adversary intelligence, and security industry trends. Prior to Avertium, Paul was the Co-Founder and CEO of TruShield Security Solutions, which was acquired by Sunstone Partners as one of the founding companies of Avertium </p><p>His foundation in the finance industry gave him first-hand experience in how crippling cybersecurity issues can be for individuals, businesses, and even the Federal Government. This sparked his interest in building a company where he could help clients not just understand the risks they face, but to combat them with effective mitigation strategies. </p><p>Under Paul’s leadership, TruShield earned a distinguished reputation as one of the fastest growing companies in the cybersecurity industry. Paul also serves as the Cybersecurity Advisor to the Science and Technology Policy Center for Development, where he utilizes his expertise to help the nonprofit achieve their goal of advancing ICT in developing countries. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 02 Nov 2022 14:00:00 -0100</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/8aff70d3/b515c618.mp3" length="39107722" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/t010bSa9B2szjWnnWr-wmjEhHHuJ1V9I_gLnDcDrZrc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mMTk4/YjY4NzcwNTQ1NWUw/MjAwNzBkMDQzYjAy/NGY5ZS5wbmc.jpg"/>
      <itunes:duration>3243</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Dr. Gerald Auger takes us through the last couple of weeks in cybersecurity news via the Simply Cyber Report</p><p>We also sit down with Paul Caiazzo: cybersecurity expert, entrepreneur and strategist, CISO and CPO.</p><p>Paul has dedicated his career to advancing the field of global cyber security. In his current role as Chief Growth Officer at SnapAttack, Paul focuses on product/market fit, strategic partnerships, and business development.</p><p>Paul continues to support Avertium as an Advisory Board Member, focused on brand ambassadorship, adversary intelligence, and security industry trends. Prior to Avertium, Paul was the Co-Founder and CEO of TruShield Security Solutions, which was acquired by Sunstone Partners as one of the founding companies of Avertium </p><p>His foundation in the finance industry gave him first-hand experience in how crippling cybersecurity issues can be for individuals, businesses, and even the Federal Government. This sparked his interest in building a company where he could help clients not just understand the risks they face, but to combat them with effective mitigation strategies. </p><p>Under Paul’s leadership, TruShield earned a distinguished reputation as one of the fastest growing companies in the cybersecurity industry. Paul also serves as the Cybersecurity Advisor to the Science and Technology Policy Center for Development, where he utilizes his expertise to help the nonprofit achieve their goal of advancing ICT in developing countries. </p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#3 - Introducing The Adversary Toolbox: PsExec. Plus cybersecurity startup founders roundtable.</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>#3 - Introducing The Adversary Toolbox: PsExec. Plus cybersecurity startup founders roundtable.</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11571731</guid>
      <link>https://share.transistor.fm/s/091caf83</link>
      <description>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley introduces the Adversary Toolbox and discusses Microsoft Windows remote execution tool, PsExec.</p><p>We also sit down to chat with several cybersecurity startup founders about the lessons that they learned along the way and the things they wished they had known starting out.</p><p>The panelists for this informative discussion are:</p><p>Roselle Safran, Founder and CEO of <a href="https://keycaliber.com/">KeyCaliber</a><br>Corey White, Founder and CEO of <a href="https://cyvatar.ai/">Cyvatar</a><br>Maxime Lamothe-Brassard, Founder and CEO of <a href="https://limacharlie.io/">LimaCharlie</a></p><p>If you have any suggestions or feedback please don't hesitate to reach out to us: <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley introduces the Adversary Toolbox and discusses Microsoft Windows remote execution tool, PsExec.</p><p>We also sit down to chat with several cybersecurity startup founders about the lessons that they learned along the way and the things they wished they had known starting out.</p><p>The panelists for this informative discussion are:</p><p>Roselle Safran, Founder and CEO of <a href="https://keycaliber.com/">KeyCaliber</a><br>Corey White, Founder and CEO of <a href="https://cyvatar.ai/">Cyvatar</a><br>Maxime Lamothe-Brassard, Founder and CEO of <a href="https://limacharlie.io/">LimaCharlie</a></p><p>If you have any suggestions or feedback please don't hesitate to reach out to us: <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 26 Oct 2022 12:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/091caf83/270253c8.mp3" length="36762818" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/dCxezUTSCGcMsKGFCKwB400FSlsD0e4fORgRUW47VJo/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS80NThm/N2UxYzYxNjVkMmVi/ZjgxZDk3MjQ4MmUx/OGY5ZS5wbmc.jpg"/>
      <itunes:duration>3048</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode of the Cybersecurity Defenders Podcast, Matt Bromiley introduces the Adversary Toolbox and discusses Microsoft Windows remote execution tool, PsExec.</p><p>We also sit down to chat with several cybersecurity startup founders about the lessons that they learned along the way and the things they wished they had known starting out.</p><p>The panelists for this informative discussion are:</p><p>Roselle Safran, Founder and CEO of <a href="https://keycaliber.com/">KeyCaliber</a><br>Corey White, Founder and CEO of <a href="https://cyvatar.ai/">Cyvatar</a><br>Maxime Lamothe-Brassard, Founder and CEO of <a href="https://limacharlie.io/">LimaCharlie</a></p><p>If you have any suggestions or feedback please don't hesitate to reach out to us: <a href="mailto:defenders@limacharlie.io">defenders@limacharlie.io</a></p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#2 - Hacker History: Clifford Stoll</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>#2 - Hacker History: Clifford Stoll</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11542577</guid>
      <link>https://share.transistor.fm/s/feb87735</link>
      <description>
        <![CDATA[<p>In this episode, we are going to be recounting the Story of Clifford Stoll, who made a pretty big discovery in 1986 while working as a sys admin for the Lawrence Berkeley National Laboratory. It is a story that involves a suspected murder, international espionage, and the type of relentless curiosity that makes a great defender.</p><p>This episode was written by Nathaniel Nelson, narrated and produced by Christopher Luft.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>In this episode, we are going to be recounting the Story of Clifford Stoll, who made a pretty big discovery in 1986 while working as a sys admin for the Lawrence Berkeley National Laboratory. It is a story that involves a suspected murder, international espionage, and the type of relentless curiosity that makes a great defender.</p><p>This episode was written by Nathaniel Nelson, narrated and produced by Christopher Luft.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Fri, 21 Oct 2022 14:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/feb87735/01561e35.mp3" length="15617896" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/FRkMCFubYYsPysAcQKQJAG4m6X71oSjbb13lSKu9rek/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9jOTAw/Nzg5YWQ3Mjg4YzRm/NmVjMDBjYjBmM2Rl/ZDAzNi5wbmc.jpg"/>
      <itunes:duration>1286</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>In this episode, we are going to be recounting the Story of Clifford Stoll, who made a pretty big discovery in 1986 while working as a sys admin for the Lawrence Berkeley National Laboratory. It is a story that involves a suspected murder, international espionage, and the type of relentless curiosity that makes a great defender.</p><p>This episode was written by Nathaniel Nelson, narrated and produced by Christopher Luft.</p><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>#1 - Introducing The Cybersecurity Defenders Podcast</title>
      <itunes:season>1</itunes:season>
      <podcast:season>1</podcast:season>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>#1 - Introducing The Cybersecurity Defenders Podcast</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">Buzzsprout-11528828</guid>
      <link>https://share.transistor.fm/s/c2d9fae0</link>
      <description>
        <![CDATA[<p>The first episode of The Cybersecurity Defenders Podcast. A show about cybersecurity and the people that defend the internet. </p><p>This weekly show is put together as a series of segments. This episode includes the following:</p><ul><li>A cybersecurity news update by Dr. Gerald Auger of Simply Cyber.</li><li>An interview with the CISO of Synoptek, Chris Gebhardt.</li><li>A product update from LimaCharlie founder Maxime Lamothe-Brassard.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>The first episode of The Cybersecurity Defenders Podcast. A show about cybersecurity and the people that defend the internet. </p><p>This weekly show is put together as a series of segments. This episode includes the following:</p><ul><li>A cybersecurity news update by Dr. Gerald Auger of Simply Cyber.</li><li>An interview with the CISO of Synoptek, Chris Gebhardt.</li><li>A product update from LimaCharlie founder Maxime Lamothe-Brassard.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </content:encoded>
      <pubDate>Wed, 19 Oct 2022 12:00:00 +0000</pubDate>
      <author>LimaCharlie</author>
      <enclosure url="https://media.transistor.fm/c2d9fae0/ce3f8ce8.mp3" length="39083557" type="audio/mpeg"/>
      <itunes:author>LimaCharlie</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/aHiXbS5TSRdfMTRB6fsVCWCpMSgi0tkSnWkbgkYDlmQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMGY0/OThlMWVlMzM0YjM2/Y2Q1ODg2YjkzMjI5/ZTlmNi5wbmc.jpg"/>
      <itunes:duration>3241</itunes:duration>
      <itunes:summary>
        <![CDATA[<p>The first episode of The Cybersecurity Defenders Podcast. A show about cybersecurity and the people that defend the internet. </p><p>This weekly show is put together as a series of segments. This episode includes the following:</p><ul><li>A cybersecurity news update by Dr. Gerald Auger of Simply Cyber.</li><li>An interview with the CISO of Synoptek, Chris Gebhardt.</li><li>A product update from LimaCharlie founder Maxime Lamothe-Brassard.</li></ul><p>The Cybersecurity Defenders Podcast: a show about cybersecurity and the people that defend the internet.</p> <p><br></p>]]>
      </itunes:summary>
      <itunes:keywords></itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
  </channel>
</rss>
