LimaCharlie
The Cybersecurity Defenders Podcast
An accessible but technical podcast about cybersecurity and the people who keep the internet safe. The podcast is built as a series of segments: we will be looking back at the last couple of weeks in cybersecurity news, talking to different people in the industry about areas of their expertise, we're going to break apart some of the TTPs being used by adversaries, and we will even cover a little bit of hacker history.
Koniecznie odwiedź stronę podcastu i wesprzyj twórcę: limacharlie.io
Gdzie słuchać?
Podcasty w aplikacji Replaio Radio Już wkrótcePodcasty trafią do aplikacji już wkrótce. Zainstaluj teraz i jako pierwszy zobacz nowe podejście do podcastów
Odcinki
Intel Chat: Dialogflow Rogue Agent, ghost phishing, CISA KEV deadline & HalluSquatting [338] 09.07.2026 34:26
Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: • Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltra...
Ransomware in the age of agentic AI with Behnaz Karimi [337] 08.07.2026 33:07
Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents. With more than 20 years of experience in cybersecurity, Behnaz is also a leader within the OWASP AI Exchang...
Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336] 03.07.2026 33:53
Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: • Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security audito...
Intel Chat: Cisco CUCM exploited, ransomware profiles, Gamaredon & AI agent phishing [335] 01.07.2026 30:01
Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: • Cisco CUCM (CVE-2026-20230) — a web-dialer SSRF that chains to root-level RCE, exploited in the wild less than 24 hours after the PoC and full exploit chain were published. • The latest Ransomware Tool Matrix (RTM) / Ransomware Vulnerability Matrix (RVM) update, profiling three act...
The evolving fraud landscape in the age of AI with Tamas Kadar [#334] 30.06.2026 42:38
Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it. Tamas' entrepreneurial path began at Corvinus University in Budapest, where the vision for SEON first took shape. Co-founding a cryptocurrency exchange opened his eyes to the s...
Anthropic restriction, ServiceNow incident, Fortinet credential harvesting & Ukraine accesses EU cyber reserve / Intel Chat [#333] 28.06.2026 34:44
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . Reports state that the US government issued an export control order restricting access to anthropic newly released cloud mythos five and fable five models for foreign nationals . ServiceNow disclosed a security incident involving an unauthenticated access for an API endpoint th...
Last call for Defenders - How we're actually using AI in the SOC with Eric Capuano / Defender Fridays [#332] 20.06.2026 37:05
Join us for the final episode of Defender Fridays as Eric Capuano, creator of Defender Fridays and co-founder of Digital Defense Institute, closes out the series with a candid conversation on how he's actually building and running agentic workflows in the SOC today. At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professional...
FFmpeg's 21 zero-days, Ruby cooldown feature, Microsoft disrupted by Shai-Hulud worm & Meta AI tool compromise / Intel Chat [#331] 15.06.2026 28:31
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . DepthFirst reported that it's autonomous security agent discovered 21 previously unknown vulnerabilities in FFmpeg, a widely deployed multimedia framework used across browsers, streaming infrastructure, and other systems that process media . Bundler, 4.0.13 introduces a new sec...
AI-assisted SOC training with Carlo Anez / Defender Fridays [#330] 12.06.2026 32:04
Join us for this week's Defender Fridays as Carlo Anez, Founder and Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down how to build practical blue team skills using open-source labs, MITRE ATTACK, and real-world defender workflows, and where AI fits into the picture without replacing the analyst. At Defender Fridays, we delve into the dynamic world of information se...
Building practical blue team skills using AI-assisted SOC training with Bobby Ford/ Defender Fridays [#329] 05.06.2026 30:31
Join us for this week's Defender Fridays as Bobby Ford, Chief Strategy and Experience Officer at Doppel, talks about open-source labs, MITRE ATT&CK, and real-world defender workflows. At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collab...
"Megalodon" Malware in GitHub, Malware-Slop steals from Claude AI, 7-Eleven breach & CISA cPanel vulnerability / Intel Chat [#328] 01.06.2026 29:05
Originally recorded: Friday May 29, 2026 In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . A large-scale software supply chain attack dubbed “Megalodon” infected thousands of GitHub repositories with credential-stealing malware in a highly automated campaign that unfolded over a six-hour period on May 18, 2026 . Researchers fr...
From PentestGPT to production: The state of AI-assisted offensive security with Charles Grandjean / Defender Fridays [#327] 30.05.2026 30:19
Join us for this week's Defender Fridays as Charles Grandjean, CTO and Co-founder at Hexiagon AI, breaks down where AI-assisted pen testing actually stands today and what it means for both red teams and defenders. At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet amb...
GitHub repositories compromised, Webworm targets Europe, fake Outlook & cybercriminal VPN / Intel Chat [#326] 29.05.2026 24:27
Originally recorded: Friday May 22, 2026 In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . GitHub has confirmed that roughly 3,800 internal repositories were accessed in a supply chain compromise tied to the hacking group TeamPCP . China-aligned threat actor Webworm has shifted its targeting focus from Asia to Europe, accordin...
How analysts use cognitive reasoning in investigations with Chris Sanders / Defender Fridays [#325] 22.05.2026 32:43
Join us for this week's Defender Fridays as Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, breaks down how analysts actually think through investigations and what separates high performers from the rest. At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. O...
"Dirty Frag", Canvas ransomware attack, “Mini Shai-Hulud” malware campaign & AI-developed zero-day exploit / Intel Chat [#324] 18.05.2026 28:49
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . Researchers have disclosed a new Linux local privilege escalation technique called “Dirty Frag,” which chains together two kernel vulnerabilities: CVE-2026-43284 in xfrm-ESP handling and CVE-2026-43500 in RxRPC . The breach affecting educational technology provider Instructure...
How to handle increasing vulnerabilities with AI-assistants? With Shane Warden from ActiveState / Defender Fridays [#323]] 15.05.2026 31:07
Join us for this week's Defender Fridays as Shane Warden, Principal Architect at ActiveState, shares what it's actually like to be on the receiving end of AI-assisted vulnerability reporting and what open source maintainers are already dealing with that the rest of the industry will face soon. At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive sid...
Does the rise of AI mean human-led SOCs are obsolete? With Dr. Adeel Shaikh Muhammad [#322] 13.05.2026 25:18
Dr. Adeel Shaikh Muhammad, a cybersecurity strategist and global speaker with over 16 years of experience across information security, networks, and systems. Adeel brings a practical perspective on how organizations can adapt to evolving cyber threats and the growing role of AI in cybersecurity. Adeel, with an extraordinary portfolio of 40+ industry certifications, including CISSP, CISM, CISA, CCI...
Daily breach attempts target UAE, fake ransomware attack, PAN-OS vulnerability & Microsoft’s Phone Link attack / Intel Chat [#321] 12.05.2026 27:28
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . The cyber threat environment in the Middle East has intensified sharply following military operations involving Israel, the United States, and Iran . An intrusion campaign attributed with moderate confidence to the Iranian state-linked group MuddyWater was disguised as a Chaos...
AI: The Hero's Journey with Ken Westin from LimaCharlie / Defender Fridays [#320] 08.05.2026 31:50
In this episode, Ken Westin maps AI adoption onto the hero's journey framework, drawing on two decades of security experience to explore how practitioners can move past early resistance, build real fluency with AI tools, and find a working model where humans and AI operate together. Key Topics: Why early AI tools left security teams skeptical and what has genuinely changed since then How Ken used...
Power systems under threat, Claude Mythos, suspicious KICS activity & JFrog / Intel Chat [#319] 06.05.2026 31:14
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . Researchers are raising concerns about a new cybersecurity risk emerging from the systems that regulate electrical power inside modern electronics and infrastructure . Japan’s financial sector is responding to concerns around Anthropic’s new AI model, Claude Mythos, which some...
How AI adoption in enterprise infrastructure has expanded the attack surface with Katherine McNamara from Cisco / Defender Fridays [#318] 04.05.2026 36:15
Today on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems. She'll walk through the security challenges unique to generative AI and ML-based architectures, and cover the four critical components: Model, Data, Application, and System...
Cybersecurity is a core leadership issue & opportunity with David Chernitzky from Armour Cybersecurity [#317] 29.04.2026 35:30
Today David Chernitzky, Co-Founder and CEO of Armour Cybersecurity, breaks down the challenges small and mid-sized businesses face in the new blink-and-you-miss-it cybersecurity landscape. Don't be left behind and open yourself to AI-driven attacks from threat actors. David Chernitzky brings over 25 years of deep cybersecurity and military cyber intelligence experience, with a career rooted in str...
Millions in crypto stolen, Vercel breach, Mastodon DDoS attack, North Korean IT workers at 100s of U.S. companies & ransomware negotiator pleads guilty / Intel Chat [#316] 27.04.2026 31:57
In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community . North Korea-linked hackers are believed to be responsible for a $290 million cryptocurrency theft targeting the Kelp DAO decentralized finance protocol . Vercel, the company behind the popular Next.js web framework and a frontend cloud platform for deploying and hosting web app...
Real examples of AI-powered code scanning with Jeff McJunkin from Rogue Valley Information Security / Defender Fridays [#315] 27.04.2026 32:41
Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. Jeff walks through real examples including using AI to find privilege escalation bugs in the Linux kernel. Jeff McJunkin is the founder of Rogue Valley Information Security, a consulting firm specializing in penetration testing and red team engagements. Jeff fou...
How can we improve global security? With J. Michael Daniel from Cyber Threat Alliance [#314] 22.04.2026 40:27
J. Michael Daniel, President and CEO of Cyber Threat Alliance (CTA), gives us a peek behind the U.S. Government cybersecurity curtain and how he has helped improve the nation's security through the CTA. Michael leads the CTA team and oversees the organization's operations. Prior to joining the CTA in February 2017, Michael served from June 2012 to January 2017 as Special Assistant to President Oba...
Podobne podcasty
Replaio nie jest wydawcą podcastów; nazwy audycji, okładki i audio należą do ich autorów i są rozpowszechniane przez publiczne kanały RSS