Alias Cybersecurity
Secure AF - A Cybersecurity Podcast
Think like a hacker. Defend like a pro. Welcome to the Secure AF Cybersecurity Podcast — your tactical edge in the ever-evolving cyber battlefield. Hosted by industry veterans including Donovan Farrow and Jonathan Kimmitt , this podcast dives deep into real-world infosec challenges, red team tactics, blue team strategies, and the latest tools shaping the cybersecurity landscape. Whether you're a seasoned pentester, a SOC analyst, or just breaking into the field, you'll find actionable insights, expert interviews, and unfiltered discussions with Alias team members and top-tier guests from acro...
Author
Alias Cybersecurity
Category
Podcast website
Latest episode
Jul 8, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
The Halls: 2025 Hacker Gift Guide 🎁💻 25.11.2025 26:17
Got a question or comment? Message us here! We’re back with the Hacker Holiday Gift Guide , and this year’s lineup is stacked with RF gadgets, Wi-Fi tools, red-team essentials, and quirky cyber gifts Tanner swears by. Whether you’re shopping for a pentester, a tinkerer, or someone who just loves breaking things (legally), these picks won’t miss. Get ready to level up your holiday shopping. Read he...
Patch Tuesday: Zero-Day Alert and Patching Must-Dos ✅ 19.11.2025 7:11
Got a question or comment? Message us here! A new zero-day. 63 flaws. Endless patching chaos. This week’s #SOCBrief breaks down Microsoft’s November Patch Tuesday and what it means for your SOC. We’ll cover the top critical CVEs, patching priorities, and how to keep your systems resilient before attackers strike. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Ap...
⚠️ Insider Threats ⚠️: Ransomware Negotiators Gone Rogue 12.11.2025 6:12
Got a question or comment? Message us here! This week, we’re digging into a case where ransomware negotiators allegedly became the attackers themselves, leveraging insider access to hit organizations they were supposed to help. This one raises real questions about trust, vendor oversight, and the human element in incident response. We break down what happened and what SOC teams can take away from...
The Art Of The Con (Cyber Edition) 🔐 11.11.2025 46:44
Got a question or comment? Message us here! In this episode, we break down the real mechanics of social engineering, from phishing emails and text scams to vishing calls and full-on physical pen tests. We share stories from the field, including how attackers build trust, why confidence is often more effective than technical skill, and what happens when social engineering meets the physical world. ...
Atroposia RAT: The Malware That Scans for Its Own Exploits 05.11.2025 6:11
Got a question or comment? Message us here! 🎙️ A new threat is making waves ... Atroposia RAT , a remote access trojan that doesn’t just infiltrate systems but scans them for vulnerabilities to exploit further. In this episode, we break down how this modular malware operates, how it hides, and why its built-in scanner is a game-changer for attackers. Learn the detection cues, patching priorities,...
CAPTCHA Con: Hackers' Evolving ClickFix Malware Trap 29.10.2025 7:50
Got a question or comment? Message us here! “I’m not a robot.” 🤖 Hackers are exploiting fake “ I’m not a robot ” CAPTCHA pages to deliver malware. Host Andrew Hickman breaks down how this ClickFix attack uses social engineering to steal data and evade detection. Tune in to learn key defense tactics and how to keep your team protected. Support the show Watch full episodes at youtube.com/@aliascybe...
RondoDox Botnet Expansion: The Shotgun Approach to IoT Exploitation 22.10.2025 7:19
Got a question or comment? Message us here! This week on the # SOCBrief , Andrew breaks down RondoDox, a rapidly growing botnet campaign taking aim at routers, DVRs, and IoT devices worldwide. With over 50 vulnerabilities across 30+ vendors , this “shotgun” exploitation strategy is fueling massive DDoS and crypto-mining attacks. Support the show Watch full episodes at youtube.com/@aliascybersecuri...
Obscura Ransomware: Unmasking a Stealthy New Threat ⚠️ 15.10.2025 12:25
Got a question or comment? Message us here! In this week’s #SOCBrief, Hickman and Peters break down Obscura ... a new ransomware variant making waves with aggressive evasion tactics, process terminations, and domain controller targeting. We cover what’s known so far, the risks it poses to businesses, and the key defenses every SOC should prioritize. Support the show Watch full episodes at youtube...
🛡️ Pen Test Potential: How Organizations Are Missing Out on Fortifying the SOC 🛡️ 08.10.2025 20:08
Got a question or comment? Message us here! What’s the real difference between a penetration test and a red team engagement, and how can each benefit your SOC? In this episode, Andrew is joined by Tanner, to unpack how pentests uncover vulnerabilities, how red teams stress-test defenders, and why every organization should be leveraging these exercises. Support the show Watch full episodes at youtu...
2025 SECCON Debrief 07.10.2025 25:33
Got a question or comment? Message us here! This week on #SecureAFPodcast, we’re recapping # SECCON 2025 . From the keynote to the villages and everything in between, join us for a look back at the highlights, takeaways, and community moments that made this year’s conference our best yet. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and...
🚨 Ransomware Rising: Variants, Tactics, and Defenses in 2025 🚨 01.10.2025 7:29
Got a question or comment? Message us here! Ransomware is evolving faster than ever, from double extortion tactics to lightning-fast attack chains. In this episode, we break down how these threats work, why every organization is a target, and the layered defenses SOCs can use to detect and stop attacks early. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple...
💢 FileFix Fiasco 💢 Steganography's Stealthy StealC Drop 24.09.2025 5:53
Got a question or comment? Message us here! In this episode of The #SOCBrief , we break down the rising FileFix attack , a new social engineering technique using steganography to deliver info-stealing malware. Learn how attackers disguise malicious PowerShell commands, the risks this poses for browsers, messengers, and crypto wallets, and the proactive defenses SOCs can use to detect and contain t...
Monitoring the Dark Web for Leaked Data in DFIR 17.09.2025 6:28
Got a question or comment? Message us here! 🔎 This episode of The #SOCBrief dives into the world of dark web monitoring in digital forensics and incident response. Learn why leaked credentials are a top threat, how to safely detect exposures, and what steps SOC teams can take to stay proactive. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spot...
Mastering Incident Response: Essential for SOC Success 10.09.2025 8:41
Got a question or comment? Message us here! 💡 This week on The SOC Brief , we’re breaking down incident response (IR) ... why it’s essential, how to build a strong plan, and what SOC teams can do to turn chaos into control. From preparation and containment to recovery and lessons learned, learn how a solid IR strategy saves time, money, and reputation. 👉 Tune in now at secureafpodcast.com Suppo...
DEF CON 33 Debrief 26.08.2025 48:45
Got a question or comment? Message us here! Fresh off the chaos of DEF CON 33 , Tanner, Hickman, and Will break down the four-day hacker conference, from the eye-opening hacker villages and mind-bending talks to Hickman’s clutch CTF victory and Will’s bold dive into the Social Engineering Community’s Vishing Competition. No sleep, all signal. Support the show Watch full episodes at youtube.com/@al...
⚠️ Crypto24 ⚠️ Ransomware: Bypassing EDR and Bolstering Defenses 20.08.2025 8:22
Got a question or comment? Message us here! In this episode, we break down the emerging Crypto24 ransomware attacks that use living-off-the-land techniques to bypass EDR. We’ll explore how these attacks unfold and the defensive strategies SOCs and organizations can use, like layered security, enhanced monitoring, and rapid response, to stay ahead of evolving threats. Support the show Watch full ep...
🚨 Gone Vishing: The Recent Surge of Vishing Attacks 13.08.2025 10:50
Got a question or comment? Message us here! This week, we’re unpacking the phishing wave hitting SaaS platforms ... from social engineering to OAuth abuse and AI voice spoofing. Learn why people remain the #1 attack vector and how to stay one step ahead. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.
🚨 SonicWall Firewall Ransomware Breakdown 06.08.2025 9:19
Got a question or comment? Message us here! On this episode of the #SOCBrief, we break down attacks on SonicWall firewalls. A wave of ransomware, possibly exploiting zero-day vulnerabilities, is compromising even fully patched systems. Learn how SOCs can respond fast and stay ahead. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywh...
Spilling the Tea: What Happens When Apps Launch Without Locking Down Security ☕ 30.07.2025 13:23
Got a question or comment? Message us here! This week’s SOC Brief unpacks how a misconfigured cloud bucket exposed 72,000+ user images from the Tea app, complete with geolocation metadata and real IDs. From national security risks to doxxing fallout, we break down what went wrong and what your security team must do to avoid the same mistakes. Support the show Watch full episodes at youtube.com/@al...
🚨⚠️ A Critical ZERO-DAY (CVE-2025-53770) 25.07.2025 17:54
Got a question or comment? Message us here! A critical zero-day (CVE-2025-53770) is actively targeting on-premises SharePoint servers AND it’s already been used to compromise over 100 organizations. In this #SOCBrief, Andrew and Tanner break down how the exploit works and what steps your team should take now. If your SharePoint instance is public-facing and unpatched ... assume compromise. 🎧 Tune...
🚪 Offboarding isn't just HR's job … 23.07.2025 15:47
Got a question or comment? Message us here! In this week’s #SOCBrief, we break down why offboarding policies are ABSOLUTELY critical for security teams. Overlooked items from abandoned accounts to old VPN access can leave backdoors wide open. Learn how SOCs monitor, contain, and shut down lingering access, and why communication between HR, IT, and cybersecurity is essential . 🎙️ Tune in. secureafp...
Aligned by Design: CISO x Legal in Practice - Episode 92 22.07.2025 54:40
Got a question or comment? Message us here! 🎙️ NEW! Aligned by Design: CISO x Legal Introducing! A fresh new series that explores the intersection of cybersecurity and legal strategy. Join Alias CISO Jonathan Kimmitt and privacy attorney Tom Vincent as they unpack what happens when technology, compliance, risk, and law collide. From real-world experiences to the nuances of the term "breach&q...
🚨 Record-Shattering DDoS Attack Alert 🚨 16.07.2025 11:41
Got a question or comment? Message us here! Hackers just unleashed the largest DDoS attack in history , peaking at 7.3 Tbps and 4.8 billion packets per second . In just 45 seconds , it pummeled its target with the data equivalent of over 9,000 HD movies, a powerful reminder of how far attack capabilities have evolved. 🎧 Tune in to today’s SOC Brief for insights on DDoS attacks and how to up your...
Secure AF SOC Brief #5 - Chrome CVE-2025-6554 09.07.2025 9:04
Got a question or comment? Message us here! In this episode of The SOC Brief , the team unpacks a critical zero-day vulnerability in Google Chrome (CVE-2025-6554) that’s being actively exploited. Learn how attackers use type confusion bugs to hijack browser memory, what makes this exploit so dangerous, and why it’s targeting high-value organizations. Discover actionable steps for updating Chrome,...
Ep 91: The Engineers React to Breach News 08.07.2025 45:27
Got a question or comment? Message us here! In this episode, our security engineers break down the latest cybersecurity headlines, from the real scoop behind the “16 billion password” leak to the rise of hacker groups like Scattered Spider. 🕷️ We discuss how attackers bypass MFA, why exploited data keeps resurfacing, and what organizations can do to protect sensitive data. Plus, we dive into indus...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.