Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
History
TV & Film
Technology
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/d8/66/f2/d866f218-5024-7a0d-c398-213df97fcac1/mza_7229373592020833672.jpg/600x600bb.jpg
Decipher Security Podcast
Decipher
318 episodes
4 days ago
This week gave us the gift of some more React Server Components vulnerabilities and further exploitation of the previously disclosed bugs by a variety of threat groups. There were also a long list of vulnerabilities disclosed by Microsoft, Adobe, and others, which we discuss in the context of how difficult vulnerability management is right now. Finally, we discuss CISA's warning about continued Russian targeting of US critical infrastructure. GreyNoise report: https://info.greynoise.io/...
Show more...
Technology
TV & Film,
News,
Tech News,
Film Reviews
RSS
All content for Decipher Security Podcast is the property of Decipher and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
This week gave us the gift of some more React Server Components vulnerabilities and further exploitation of the previously disclosed bugs by a variety of threat groups. There were also a long list of vulnerabilities disclosed by Microsoft, Adobe, and others, which we discuss in the context of how difficult vulnerability management is right now. Finally, we discuss CISA's warning about continued Russian targeting of US critical infrastructure. GreyNoise report: https://info.greynoise.io/...
Show more...
Technology
TV & Film,
News,
Tech News,
Film Reviews
Episodes (20/318)
Decipher Security Podcast
More React Bugs Reaction, the Challenge of Vulnerability Management, and CI Attacks
This week gave us the gift of some more React Server Components vulnerabilities and further exploitation of the previously disclosed bugs by a variety of threat groups. There were also a long list of vulnerabilities disclosed by Microsoft, Adobe, and others, which we discuss in the context of how difficult vulnerability management is right now. Finally, we discuss CISA's warning about continued Russian targeting of US critical infrastructure. GreyNoise report: https://info.greynoise.io/...
Show more...
5 days ago
24 minutes

Decipher Security Podcast
From CIA Officer to a Career in Cybersecurity With Erin Whitmore
Coming from a military family, Erin Whitmore was prepared for a career of service. But her path took her not into the military, but the intelligence community, first in the private sector supporting the DIA and NGA, and later as a cybersecurty program manager in the Office of the Director of National Intelligence. She eventually joined CIA as an operations officer and served in locations around the world before moving back to the private sector where she now focuses on executive risk and stra...
Show more...
1 week ago
1 hour 21 minutes

Decipher Security Podcast
React2Shell, Typhoon Attacks, and Why Our Infrastructure is So Vulnerable
Dennis and Lindsey react (!) to the React2Shell vulnerability disclosure and the quick exploitation of it by Chinese threat actors, then discuss the continues intrusions into critical infrastructure by the Salt Typhoon actors and this week's congressional hearing on telecom network security. Finally, we talk about some upcoming hacker movie episodes, including Die Hard and maybe Home Alone! Support the show
Show more...
1 week ago
33 minutes

Decipher Security Podcast
Jeff Gothelf on Designing for Users, Enterprise Agility, and the AI Conundrum
Jeff Gothelf, a renowned author and product strategist and co-founder of Sense and Respond Learning, joins Dennis to discuss the need to design products with users in mind, how critical thinking can help teams succeed, and what the AI revolution means for security teams and other groups. Support the show
Show more...
2 weeks ago
41 minutes

Decipher Security Podcast
DoJ Sanctions, the SEC Abandons the SolarWinds Action, and the FCC Reverses Course on Telecom Security
It's an acronym-filled, government-only bonanza this week! We discuss the DoJ sanctioning Russian bulletproof hosting provider Media Land (0:53), the SEC dropping its enforcement action against SolarWinds and its CISO (13:25), and the FCC reversing course on a longstanding security rule for telecom providers (26:00). Support the show
Show more...
3 weeks ago
36 minutes

Decipher Security Podcast
Rich Mogull on the Cloudflare Outage, Resilience, and Single Points of Failure
Dennis is joined by Rich Mogull, chief analyst at the Cloud Security Alliance, cloud security trainer, and all around good guy to talk about the Cloudflare outage, why the internet is now just six companies, and what, if anything, organizations can do to improve their resilience in the current environment. Support the show
Show more...
4 weeks ago
24 minutes

Decipher Security Podcast
Lighthouse Phishing Kit Takedown, Zero Day Mysteries, and Measuring Cyber Attack Costs
This week was a bit of a throwback to olden times, with the disclosure by Amazon threat intelligence of zero days in Cisco and Citrix products that were exploited by an unnamed APT, and Google using legal action to disrupt the Lighthouse phishing service operation. We dig into those two stories, plus we discuss the challenge of trying to quantify the financial and other effects of a major cyber attack. Related stories: https://decipher.sc/2025/11/12/apt-targets-cisco-and-citrix-ze...
Show more...
1 month ago
46 minutes

Decipher Security Podcast
The Hacker Movie Canon: The Social Network
"You know, you really don't need a forensics team to get to the bottom of this. If you guys were the inventors of Facebook, you'd have invented Facebook." Melanie Ensign joins Dennis Fisher and Lindsey O'Donnell-Welch to discuss David Fincher's massively successful 2010 film, The Social Network, a movie that opens a window into the dark side of Silicon Valley and the lengths that some people will go to in order to win. Support the show
Show more...
1 month ago
1 hour 13 minutes

Decipher Security Podcast
Yahoo's Sean Zadig on How to Raise a Hacker Safely and How Maybe AI Isn't Changing Everything
Yahoo CISO and Chief Paranoid Sean Zadig returns to the podcast for a discussion with Dennis Fisher about how to go about getting kids interested in technology and teaching them about hacking (in the broad, classical sense) safely (9:10). Then they talk about how rapidly the cybersecurity industry is changing and what effects AI is and is not having on offense, defense, and the job market (45:00). Support the show
Show more...
1 month ago
51 minutes

Decipher Security Podcast
Shadow AI Is Eating the World, the Return of Hacking Team, and the Commercial Spyware Landscape
We don't do holiday themed episodes in this house, so no tricks, but we have some treats for you. First we discuss the problem of shadow AI (1:00) and how it seems like we're just repeating the mistakes of previous tech waves in ignoring security until it's too late. Then we dig into a new report from Kaspersky about a crazy exploit they discovered for a Chrome sandbox escape that led them to identify the new version of Hacking Team's spyware called Dante (23:00). Finally, we provide some imp...
Show more...
1 month ago
41 minutes

Decipher Security Podcast
US Cybersecurity Going in Reverse, the AWS Outage, and is CISA Okay
This week saw a blessed lack of major vulnerabilities, but there was plenty of other news to dig into. We discuss the fallout from the AWS outage (0:36), the conclusions from the latest Cyberspace Solarium Commission report (4:37), and the effects of CISA's shakeup on the private sector (14:07), and the continued effects of the F5 incident (21:21). Finally, we have some extremely important updates on whether Dennis has a dog yet and a WILD story about woodland creatures in Lindsey's house tha...
Show more...
1 month ago
43 minutes

Decipher Security Podcast
The Hacker Movie Canon: Real Genius
Mitch, there's something you need to know. Compared to you, most people have the IQ of a carrot. Real Genius has it all: '80s movie icon Val Kilmer at his coolest, a brilliant hacker named Laszlo living in a closet, a giant space laser, and the absolute embodiment of the hacker ethos. Join us as we dig into this classic with our pal Wendy Nather. It's a moral imperative. Slate article on the inspiration for Jordan: https://slate.com/technology/2015/08/real-genius-30th-anniversary-how-i-helped...
Show more...
1 month ago
53 minutes

Decipher Security Podcast
Breaking Down the F5 Breach
In the wake of the disclosure of a serious intrusion at F5 that reportedly lasted about a year, we talk about the details of the disclosure, the potential link to Chinese state actors, the fallout from the attackers' access to source code and bug reports, and what this could mean in the long term.
Show more...
2 months ago
27 minutes

Decipher Security Podcast
AI Attack and Defense With Adam Meyers and Elia Zaitsev of CrowdStrike
Have you heard about this AI thing? It's wild. Turns out, attackers are using it for all kinds of things we'd rather not have them doing. Dennis Fisher is joined by two experts from CrowdStrike--Adam Meyers, head of counter adversary operations, and Elia Zaitsev, CTO--to talk about how both defenders and attackers are leveraging AI and where things might be going in the next few years.
Show more...
2 months ago
57 minutes

Decipher Security Podcast
More Cl0p Clues and Huge Apple Bug Bounty Changes
This week brings some new insights into the origins and length of the Cl0p extortion attacks tied to the Oracle E-Business Suite vulnerability, big surges in scanning for Cisco ASA, Palo Alto, and Fortinet devices, and a huge upgrade to Apple bug bounty payouts. Plus: Does Dennis have a dog yet? https://security.apple.com/blog/apple-security-bounty-evolved/ https://decipher.sc/2025/10/08/data-connects-scanning-surges-for-cisco-fortinet-pan-devices/ https://decipher.sc/2025/10/09/oracle-...
Show more...
2 months ago
14 minutes

Decipher Security Podcast
The Hacker Movie Canon: WARGAMES
What you see on these screens up here is a fantasy; a computer-enhanced hallucination. WarGames may be 42 years old (!) but its prescience about our current technocracy and race to take humans out of the loop is as clear as ever. Dennis Fisher, Lindsey O-Donnell-Welch, Zoe Lindsey, and Pete Baker sit down in front of an IMSAI 8080 with some raw corn on the cob and a can of Tab to talk about this brilliant hacker movie classic. Support the show
Show more...
2 months ago
1 hour 4 minutes

Decipher Security Podcast
The Cl0p-Oracle Extortion Emails, Red Hat Breach, and Sad Government News
Dennis and Lindsey dissect a busy week in security news, starting with the Cl0p group's extortion campaign against Oracle customers (3:24), then moving into the Crimson Collective's claimed breach of some of Red Hat GitLab's repos (12:41), and finally the consequences of the expiration of th CISA legislation and de-funding of the MS-ISAC (22:46). PLUS! An exciting announcement about our partnership with Material Security for their Security Theater event in NYC! Support the show
Show more...
2 months ago
35 minutes

Decipher Security Podcast
The Hacker Movie Canon: SNEAKERS
The world isn't run by weapons anymore, or energy, or money. It's run by little ones and zeroes, little bits of data. It's all just electrons. Daniel Cuthbert joins Dennis Fisher to dive into an all-tiime, undisputed hacker movie classic, the 1992 masterpiece, Sneakers. We dissect the movie's genesis, its technical accuracy and prescience, and discuss its lasting influence on the hacker community more than 30 years after its release. Support the show
Show more...
2 months ago
58 minutes

Decipher Security Podcast
New Targeted Phishing Attack Trends With Adam Bateman of Push Security
Adam Bateman, co-founder and CEO of Push Security, joins Dennis Fisher to talk about a new, highly targeted phishing campaign the company uncovered that uses compromised LinkedIn accounts in order to harvest victims' Google or Microsoft credentials through a fake investment, then discuss trends in browser-based attacks and defensive challenges. Support the show
Show more...
2 months ago
31 minutes

Decipher Security Podcast
NPM Package Compromises, Sen. Wyden's Ransomware Letter, and Apple's Memory Safety Advance
Dennis and Lindsey discuss the targeted compromises of NPM packages (1:00) and the pointed letter that Sen. Ron Wyden sent to the FTC chairman asking for Microsoft to be held liable for the Ascension ransomware attack last year (11:45) before finally touching on Apple's new memory safety technology for new iPhones (20:43). NPM compromise: https://decipher.sc/2025/09/08/targeted-attack-compromises-popular-npm-packages/ Wyden and Microsoft: https://decipher.sc/2025/09/10/senator-flags-microso...
Show more...
3 months ago
30 minutes

Decipher Security Podcast
This week gave us the gift of some more React Server Components vulnerabilities and further exploitation of the previously disclosed bugs by a variety of threat groups. There were also a long list of vulnerabilities disclosed by Microsoft, Adobe, and others, which we discuss in the context of how difficult vulnerability management is right now. Finally, we discuss CISA's warning about continued Russian targeting of US critical infrastructure. GreyNoise report: https://info.greynoise.io/...