Rafal (Wh1t3Rabbit) Los
Down the Security Rabbithole Podcast (DtSR)
This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-securit...
Author
Rafal (Wh1t3Rabbit) Los
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
DtSR Episode 688 - Looking for Meaning in the Signal 13.01.2026 43:37
TL;DR: Grab your favorite note-taking thing, this week's pod features Julian Brownlow Davies of BugCrowd and it's chock full of things you'll want to look up. We tackle how red teaming and external 3rd party testing fits into a current security strategy, and how finding signal in the noise is just the beginning. YouTube video: https://youtube.com/live/aNz-qPmWf7g1 Have something to...
DtSR Episode 687 - Dan Geers Wisdom from 2014 06.01.2026 1:02:03
TL;DR: This week's episode is a special one. I (Rafal) revisit episode 100 with the one and only Dan Geer. Some shows are "in the moment", some are timeless. This show is timeless. Dan's wisdom and insights are as applicable today as they were 12 years ago. Crazy, right? Fun story - I ran into Dan at Black Hat conference a few years ago and asked him what he would say is &apos...
DtSR Episode 686 - An Unexpected Windows XP Conversation 30.12.2025 49:30
TL;DR: On today's pod, Rob Allen of ThreatLocker makes his triumphant return to derail us straight into a conversation about legacy systems and why he's still supporting WindowsXP. Right, you read that right. A great conversation ensued, and I'm glad we were able to record this one. Enjoy. From us to you, thank you for following along this year, and we wish you a happy new year, an...
DtSR Episode 685 - Weaponized AI is Real Now What Pt 1 23.12.2025 37:33
TL;DR: In part 1 of 2, Gadi Evron joins the show and chats with Jim and Rafal on the topic of the "AI Cataclysm". What does that even mean? Listen in - but it's part to do with how AI is changing the attacker model (level of effort, expertise required, timeline) and what defenders should start to think about. Part 2 is coming soon, standby. YouTube Video: https://youtube.com/live/i...
DtSR Episode 684 - AI Agents Gone Rogue 16.12.2025 50:04
TL;DR: This week's show features Aaron Costello, and is all about an analog from real-world attacks on humans, applied to AI "agents". I know what you're thinking - computers are supposed to be more difficult to trick, right? Right... no. Attacks such as this where computers try to be "helpful" (just like humans) are probably more common than we'd like to think....
DtSR Episode 683 - Sometimes You Have to Step Away 09.12.2025 37:37
TL;DR: On this episode, it's just Jim and Rafal talking about how sometimes you just need to take a big step back from your day job and touch some grass. Our chosen profession is, demanding, to say the least. So let's take a minute to acknowledge what we're really thinking. Unfiltered, raw, and straight from our heads to your ears, enjoy. YouTube video: https://youtube.com/live/ULT...
DtSR Episode 682 - A Third Opinion on Vulnerability Ranking 02.12.2025 48:48
TL;DR: This week's pod features a conversation with the Jay Jacobs , whom had previously been on the show talking about this very topic (vulnerability ranking/scoring) many, many years ago. If you missed Episode 297 check it out, it's crazy how far (or not) we've come since that conversation. YouTube Video: https://youtube.com/live/cpL9ZYbwkes Have something to say? Let's hear...
DtSR Episode 681 - AppSec Whack-a-Mole 25.11.2025 49:14
TL;DR: John Rafal & Jim as we welcome Dustin Lehr to talk about the state of AppSec and how we got here. We discuss vulnerabilities, accountability, culture, and a host of other things. It's a caffein-fueled episode, so buckle in! Youtube video: https://youtube.com/live/yoBIQ_sIawI Have something to say? Let's hear it. Support the show >>> Please consider clicking the link ab...
DtSR Episode 680 - Debating Patching and Vulnerability Scoring 18.11.2025 55:57
TL;DR: We heard RSnake's take on CVSS and CVEs and such, now let's hear Brian "Jericho" Martin's take. The gloves are off, and the opinions go native when we take this episode live. Brian doesn't pull any punches, and apparently I'm the only one without a pocket full of $2 bills? Sorry for the explicit rating, that's Brian's fault. YouTube Video: https...
DtSR Episode 679 - Wasting Time Patching 11.11.2025 55:29
TL;DR: Patching. Your least favorite thing. Well, it turns out that most of the work we have been doing in the last 20+ years has been for nothing. Robert "RSnake" Hansen's theory, backed by a lot of data, seems to point to a much bigger problem in cyber, and it's time we talk about it. Rob's Closing Keynote that started this conversation: https://youtu.be/80ZtAsuC4v4?si=...
DtSR Episode 678 - CyberSecurity Has Lost the Plot 04.11.2025 44:32
TL;DR: This week's pod features your favorite hosts reflecting on how security has lost its way. When everything is a catastrophe, nothing is. When every breach is world-ending, none of them matter. Have we completely lost the plot? Prepare to have a good think. YouTube Video: <coming soon> Have something to say? Let's hear it. Support the show >>> Please consider clicking...
DtSR Episode 677 - Is Cyber Insurance the Answer or A Question 28.10.2025 48:25
TL;DR: On this week's pod - Sean Scranton and Shawn Tuma make a return appearance to talk about Cyber (Security) Insurance. Some see it as the answer to cyber's problems, while others see it as just another question. Which is it? Is it just a matter of perspective? Listen in and find out! YouTube Video: https://youtube.com/live/GiuheFiFO78 Have something to say? Let's hear it. Suppo...
DtSR Episode 676 - Privacy and Healthcare Data at Crossroads 21.10.2025 43:58
TL;DR: This week's pod is all about healthcare-related data that is bought and sold the world over - and how you this data can be utilized while still preserving privacy. In this mind-blowing segment, John Kuhn of Integral joins Jim and I to talk about the vast quantities of data that's bought, sold, and aggregated for healthcare research - and how it can be used for good, while still p...
DtSR Episode 675 - Trey Ford on the Mind of CISOs 14.10.2025 46:16
TL;DR: If you've ever wondered what goes through the mind of a top-tier CISO, wonder no longer. This week's episode features Trey Ford talking a little nostalgia, and a little of what's on his mind as a CISO. Fantastic episode, shout out to BugCrowd for the episode. Youtube video: https://youtube.com/live/uFl45Tb93gY?feature=share Have something to say? Let's hear it. Support t...
DtSR Episode 674 - 3rd Party Risk is a Mess 07.10.2025 44:56
TL;DR: Let's talk, err, lament, Third Party Risk programs. Who has time for these, and is there any real value in identifying 3rd party risks? Or is it just all theater for the lawyers? Paul Farley joins Jim, James and Rafal to chop it up. Dive in with us, and see what you think. YouTube Video: https://youtube.com/live/Le23nkaybfE Have something to say? Let's hear it. Support the show &...
DtSR Episode 673 - Crash Out to Cash Out 30.09.2025 43:13
TL;DR: This week's episode is what happens when I go on vacation and have a little time to think. So here we go - let's talk about this Jaguar Land Rover was compromised and ransomware spread. The damage has been 'extensive' to the point where they stopped everything... are there any lessons here? Links https://www.theguardian.com/business/2025/sep/20/jaguar-land-rover-hack-f...
DtSR Episode 672 - DFARS CMMC Update Insights 23.09.2025 39:01
TL;DR: This podcast features our friend Bo Birdwell who sits down with us to explain the ins and outs of the new DFARS CMMS update. Jim and Bo cover a lot of ground, and James and I are along for the ride asking questions. Great episode if you're in the space, worrying about what this latest update means to you. YouTube Video: https://youtube.com/live/0cl1S4f3g8E Have something to say? Let...
DtSR Episode 671 - It's The End of the Internet As We Know It 16.09.2025 40:58
TL;DR: This week's returning guest is Doug Cavit , but this time he's here to talk about the Internet apocalypse. Partly driven by AI, but mostly we discuss automated content generation, bots, and consumption as we reach the conclusion that it's all coming crashing down... sooner than we'd like. YouTube Video: https://youtube.com/live/tUJgdrh3ws8 Have something to say? Let'...
DtSR Episode 670 - Ethics Equity and Rock Star CISOs 09.09.2025 40:57
TL;DR: Michael Reichstein joins the pod this week to talk about "rock star CISOs" and those who trade equity for their souls. It's an interesting discussion but this one comes with a warning label: If you're easily offended, do not listen to this. Michael's post that started this conversation: https://www.linkedin.com/posts/mreichstein_cybersecurity-leadership-businessethi...
DtSR Episode 669 - ADR Enters the SOC Chat 02.09.2025 43:26
TL;DR: This week's pod features our favorite former analyst Anton Chuvakin, and an AppSec OG Jeff Williams as we tackle the subject of AppSec's favorite new acronym - ADR. What is it? Why is it? Should it be? We answer all these questions and more, and laugh along the way a bit too. YouTube Video: https://youtube.com/live/69xeGDoDYbU Links Contrast's latest threat report (referenced...
DtSR Episode 668 - Actionable Crowd Sourced Defenses 26.08.2025 38:53
TL;DR: This week's returning guest is the man, the myth, the Alpaca farmer, Philippe Humeau of CrowdSec. Life comes at you fast, threats come at you faster. The good news is - defenses can keep up. Listen in, then go check out CrowdSec ! YouTube video: https://youtube.com/live/7Xc99bXCfwQ Have something to say? Let's hear it. Support the show >>> Please consider clicking the lin...
DtSR Episode 667 - Market Consolidation is Screwing the CISO 19.08.2025 49:59
TL;DR: This week's guest is Dr Sam Liles - who's been CISO'ing since most of us have been in the industry. Sam gets it, and he has some perspective on what's going on with all this market consolidation. What is it good for? He's got some things to say, and he's not shy about it. YouTube: https://youtube.com/live/ROEA6z5Q-sk Have something to say? Let's hear it. Su...
DtSR Episode 665 - From Black Hat 2025 with Exhaustion 12.08.2025 29:12
TL;DR: This week's show is a testament to surviving a week of Hacker Summer Camp out in Las Vegas. I have an interview with Ray Canzanese, Jr. (again, because y'all love him) and a bit of my take-away / rant from the week I spent out in the desert. Enjoy, I hope you made it home safe and learned something. Good God it was hot. YouTube Video: ( standby, waiting on me to edit ) Thanks a...
DtSR Episode 664 - Everything You Wanted to Know About RaffCon 04.08.2025 32:31
** Early release, due to Black Hat Conference and RaffCon XVIII. TL;DR: This episode is all about #RaffCon. Ever wanted to know what the heck it is? Well, Raffael Marty and I break it down, give you a little history, and reminisce. As we got into Black Hat week, this is the perfect precursor to #RaffCon XVIII. YouTube video: https://youtube.com/live/jwArV_EwuZc Have something to say? Let's he...
DtSR Episode 663 - The CISO and CIO Relationship 29.07.2025 40:14
TL;DR: This is one of the most important episodes we've done on this podcast. The CISO and CIO have a complicated, dynamic, and often ugly relationship - but what should it be like? How can the two work together and evolve their roles together, for the benefit of everyone in the business? Larry Whiteside, Jr. ( Co-Founder and President at Confide) and Dennis McDonald ( Chief Information &...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.