Decipher
Decipher Security Podcast
Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.
Kde poslouchat?
Podcasty v aplikaci Replaio Radio Už brzyPodcasty míří do aplikace už brzy. Nainstaluj si ji teď a jako první uvidíš úplně nový pohled na podcasty
Epizody
Axios NPM Supply Chain Attack 31.03.2026 25:41
Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer's account, the window of exposure for the malicious packages, the behavior of the RAT that's installed on victims' machines, and what the downstream effects may be. Links Huntress post : https://www.huntress.com/blog/supply-c...
RSA Recap: Dancing Robots, AI Everywhere, and the Future of Security 27.03.2026 51:00
Fresh off the plane from RSA, Dennis fills Lindsey in on everything she missed (and didn't miss) at this year's conference (0:23), from the insanity of the expo floor (4:06) to the appearance of a line of synchronized robots or spacemen or something (8:18), to some very interesting conversations about the hyper speed of AI malware development and what's coming next for defenders (27:25...
RSA 2026 Preview 20.03.2026 43:06
With the RSA Conference on the horizon, Dennis and Lindsey are here with a preview of the conference's more interesting sessions and keynotes, a discussion of the recent and ancient history of the conference, and a quick game: Is this a security vendor or a prescription drug name?
Mark Watney Is a Space Hacker in The Martian 18.03.2026 52:37
Sure, space pirate is a cool title, but what about space hacker? Way cooler! With the imminent release of Project Hail Mary, Wendy Nather joins Dennis Fisher to dig into the nutrient-rich narrative soil that produced a modern classic that truly epitomizes the hacker ethos. We are the greatest podcasters on Mars!
Fancy Tools From Fancy Bear, Another Proxy Network Takedown, and A Look Ahead 13.03.2026 15:50
This week's news includes a reappearance by an old favorite, APT28, aka Fancy Bear, which is back with some nasty new implants and tools it is deploying against targets in Ukraine (2:10), and we also have another law enforcement disruption of a residential proxy network, this one known as SocksEscort, which had victims all over the globe (7:45). Lastly, we talk about some of the upcoming episo...
The Wild, Wild World of Exploits With Caitlin Condon 10.03.2026 46:05
The process of developing and deploying exploits is a complex and controversial one and it's often a black box to outside observers. To help shine a light on how this all works, Caitlin Condon of VulnCheck joins Dennis Fisher for a deep dive into the zero day exploit landscape, what goes into exploit development, and what actually qualifies as a functional exploit.
The Zero Day Landscape, Tycoon 2FA Disruption, and KEVology 06.03.2026 19:14
Every day is zero day, and this week we talked about the new Google Threat Intelligence Group report on the zero day exploit landscape in 2025 (2:22) and who's exploiting what, then we discuss Microsoft's disruption of the Tycoon 2FA cybercrime operation (9:51), and finally we talk about the KEVology report from runZero and our new podcast with Tod Beardsley (13:25).
We Need to Talk About KEV With Tod Beardsley 02.03.2026 47:09
Tod Beardsley, VP of security research at runZero and former KEV section chief at CISA, joins Dennis Fisher to talk about the evolution of the Known Exploited Vulnerabilities catalog, how much value defenders should place on a specific bug being in the KEV, and his new KEVology report that breaks down all of the data in the KEV and sifts through it for specific insights for defenders.
Cisco SD-WAN Zero Day, Google Disrupts Chinese Campaign, and More Cyber on The Pitt 27.02.2026 31:56
This week Lindsey rejoins Dennis to talk about the attacks targeting a zero day in Cisco's Catalyst SD-WAN Controller (2:17), Google's disruption of a China-linked cyber espionage campaign targeting telecom infrastructure (6:30), and the new cyber developments on everyone's favorite tech show, The Pitt (13:13)!
China Targets Dell Flaw, New Ivanti Exploitation, and Cyber Shenanigans on The Pitt! 20.02.2026 18:58
It's a light news week, but we have some fun content for you! This week, we talk about our latest hacker movie episode-- STAR WARS --which is up on the site and all of our feeds now (0:25), then we dig into a nasty hard-coded. credential bug in Dell RecoverPoint for Virtual Machines that Chinese threat actors are exploiting (4:20), and then we move on to an active campaign targeting two vulne...
The Hacker Movie Canon: Star Wars 18.02.2026 1:04:35
STAR WARS isn't just one of the more successful and iconic movies of all time and the basis for a worldwide sci-fi empire, it's also a true hacker story. Wade Baker and Rich Mogull, two Star Wars scholars, join Dennis Fisher to break down the Empire's pathetic perimeter defenses, R2D2's arc as a wily hacker, and how the movie hinges on a data breach. Support the show
Six Zero Days From Microsoft, One From Apple, and a CSI: Cyber Throwback 13.02.2026 17:59
This week was a cornucopia of zero days. We talk about the six (!) actively exploited vulnerabilities that Microsoft patched this week in its February update (2:46), then we discuss the one that Apple fixed in iOS 26.3 , a vulnerability that has been used in what the company calls an "extremely sophisticated attack" against a few individuals (7:24). That's a clear indication that t...
How to Stay Ahead of Attackers With watchTowr's Ryan Dewhurst 09.02.2026 49:17
Attackers are moving faster and faster every day, and the challenge of keeping pace is a daunting one. But it's not impossible. watchTowr's Ryan Dewhurst joins Dennis Fisher to talk about how the "magic" of computers first captured his imagination when he was young, how defenders can learn from attackers' tactics and adapt, and how the AI revolution is accelerating vulner...
Dumping Edge Security Devices, the SystemBC Botnet, and the Joy of Joybubbles 06.02.2026 16:56
This week we talk about the new CISA Binding Operational Directive that sets a deadline for removing end of support edge security devices from federal government networks (1:15), then we discuss the new research from Silent Push on the new variant of the SystemBC botnet (6:45), and finally we have a movie recommendation for you: Joybubbles , the fascinating new documentary about phone phreaker Joe...
Fortinet and WinRAR Exploitation, Google's IPIDEA Disruption, and Our Favorite Cybersecurity Creators 30.01.2026 20:55
It was a busy week in the cybers! Today we start with the targeted exploitation of another Fortinet vulnerability (CVE-2026-24858) that enables simple authentication bypass (1:15), then we discuss Google's disruption of a large residential proxy network called IPIDEA that has been abused by hundreds of threat actors (5:40), then we talk about the continued attacks on an older WinRAR bug by bo...
The RedVDS Takedown, Yet Another Chinese APT Emerges, and the StackWarp AMD Bug 16.01.2026 16:41
This week, we talk about how Microsoft disrupted a long-running, large-scale cybercrime-as-a-service platform called RedVDS that has been active since 2019 and was used in high-volume phishing and BEC scams (1:00), then we discuss the research from Cisco Talos on another (!) Chinese APT called UAT-8837 that is targeting critical infrastructure organizations in North America (6:06), and finally the...
The Future of Vulnerability Management With Jeremiah Grossman and Robert "RSnake" Hansen 13.01.2026 1:04:32
Jeremiah Grossman and Robert Hansen, two of the more influential and accomplished leaders and entrepreneurs in the cybersecurity community, have seen and done it all in their careers. From their roles as the driving forces behind pioneering web appsec firm WhiteHat Security to building out enterprise security programs to breaking large portions of the web (on purpose), Jeremiah and Robert have uni...
A New Chinese APT Debuts and React2Shell Attacks Spike 09.01.2026 14:06
The new year is here! And so are the attacks. The first full week of 2026 brought us new research from Cisco Talos on a China-nexus APT group called UAT-7290 that is expanding its targeting and serving as an initial access group as well as a cyber espionage team (3:02). There is also some great data from GreyNoise on the attack volume from actors trying to exploit the React2Shell vulnerability fro...
The Hacker Movie Canon: Home Alone 22.12.2025 58:46
There may not be any computers in Home Alone, but few movie characters embody the old-school hacker ethos like Kevin McCallister does. Resourceful, clever, determined, and creative, Kevin uses all of the tools and talents at his disposal to repel a pair of relentless adversaries. Merry Christmas ya filthy animals! Support the show
Russian Targeting of Edge Devices. Cisco AsyncOS Zero Day, and React2Shell Won't Go Away 19.12.2025 21:25
As we ease into the holidays, the security news doesn't stop coming. This week we discuss the research from AWS threat intelligence on Russian adversaries targeting a variety of network edge devices for opportunistic exploitation, then we break down attacks by a Chinese threat actor that target a new zero day in Cisco's AsyncOS, and finally we discuss the continued exploitation of the Re...
The Hacker Movie Canon: Die Hard 17.12.2025 1:04:25
Pete Baker and Zoe Lindsey join Dennis Fisher on the roof of Nakatomi Plaza to discuss one of the great action classics* and a beloved movie in the hacker community: Die Hard. Yippee ki-yay! *NOT a Christmas movie Support the show
More React Bugs Reaction, the Challenge of Vulnerability Management, and CI Attacks 12.12.2025 26:34
This week gave us the gift of some more React Server Components vulnerabilities and further exploitation of the previously disclosed bugs by a variety of threat groups. There were also a long list of vulnerabilities disclosed by Microsoft, Adobe, and others, which we discuss in the context of how difficult vulnerability management is right now. Finally, we discuss CISA's warning about contin...
From CIA Officer to a Career in Cybersecurity With Erin Whitmore 10.12.2025 1:21:42
Coming from a military family, Erin Whitmore was prepared for a career of service. But her path took her not into the military, but the intelligence community, first in the private sector supporting the DIA and NGA, and later as a cybersecurty program manager in the Office of the Director of National Intelligence. She eventually joined CIA as an operations officer and served in locations around th...
React2Shell, Typhoon Attacks, and Why Our Infrastructure is So Vulnerable 05.12.2025 33:33
Dennis and Lindsey react (!) to the React2Shell vulnerability disclosure and the quick exploitation of it by Chinese threat actors, then discuss the continues intrusions into critical infrastructure by the Salt Typhoon actors and this week's congressional hearing on telecom network security . Finally, we talk about some upcoming hacker movie episodes, including Die Hard and maybe Home Alone!...
Jeff Gothelf on Designing for Users, Enterprise Agility, and the AI Conundrum 02.12.2025 40:51
Jeff Gothelf, a renowned author and product strategist and co-founder of Sense and Respond Learning , joins Dennis to discuss the need to design products with users in mind, how critical thinking can help teams succeed, and what the AI revolution means for security teams and other groups. Support the show
Podobné podcasty
Replaio není vydavatelem podcastů; názvy pořadů, obálky a audio patří jejich autorům a šíří se přes veřejné RSS kanály