SafeBreach

The Cyber Resilience Brief: A SafeBreach Podcast

The Cyber Resilience Brief is your 15-minute pulse on how organizations can build stronger defenses and achieve true cyber resilience. Each episode dives into the practical realities of Breach and Attack Simulation (BAS), adversarial exposure validation, and the evolving strategies that keep modern enterprises secure. Hosted by Tova Dvorin and brought to you by SafeBreach — the leader in Adversarial Exposure Validation — this podcast features insights from cybersecurity leaders, integration partners, CISOs, technical experts, and forward-thinking customers. Whether you’re in the EU navigating...

Author

SafeBreach

Category

Technology

Latest episode

Jul 8, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance 08.07.2026

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational — the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour z...

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools 05.07.2026

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud"...

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program 01.07.2026

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn'...

Ep. 64 - The Mythos Hype Index: What AI Really Did to the Zero-Day Curve 24.06.2026

Every CISO is asking it: now that frontier models like Claude Mythos and ChatGPT 5.5 have real offensive cyber capability, are zero days surging? Host Tova Dvorin and SafeBreach offensive engineer Adrian Culley dig into the mid-2026 data — GTIG, Mandiant M-Trends, Rapid7, AISI — and find the curve moved in shape, not volume. Inside: the two AI "firsts" (Big Sleep and a 2FA-bypass exploit), why com...

Ep. 63 - Mythos and ChatGPT 5.5: Why AI Now Finds Decades-Old Zero Days 17.06.2026

How is AI suddenly finding zero days that survived decades of human fuzzing? In April 2026, Anthropic's Claude Mythos and OpenAI's ChatGPT 5.5 rewrote what's possible with a keyboard. Host Tova Dvorin and offensive security expert Adrian Culley unpack the UK AISI's verdict — genuine step changes — through decades-old bugs in OpenBSD and FFmpeg, the 32-step autonomous attack chain, the Cyberstrike...

Ep. 62 - Zero Trust Breaks Against MCP: Why "Verified" No Longer Means Safe 10.06.2026

Most enterprises assume their zero trust architecture covers their AI agents. It doesn't. Hosts Tova Dvorin and Adrian Culley break down why zero trust breaks against the Model Context Protocol (MCP) — and why "verified" no longer means "safe." They unpack trust decay, the WhatsApp and GitHub MCP exploits, rug-pull tool poisoning, CVE-2025-49596, and the rise of "zero standing trust," then close w...

Ep. 61 - Blind With Scissors: The NSA's MCP Warning for Every Agentic AI Deployment 03.06.2026

The NSA just published a rare advisory on the Model Context Protocol (MCP)—the plumbing under nearly every agentic AI deployment of the last 18 months—and the verdict is stark: optional authentication, no token lifecycle, silent behavior changes, and no logging to catch any of it. Host Tova Dvorin sits down with defensive cybersecurity expert Adrian Culley to unpack the eight risk categories, the...

Ep. 60 - The Puppet Masters: Mustang Panda's Long Con Against ASEAN Diplomats 27.05.2026

When a tired EU diplomat clicks "connect" on an airport Wi-Fi portal, his briefing — and his government's secrets — end up in Chengdu. Hosts Tova Dvorin and Adrian Culley unpack Mustang Panda (APT27 / Bronze President), the Chinese threat group running the long con against NGOs, ASEAN ministries, and Tibetan and Uyghur activists. Inside: captive-portal Wi-Fi Pineapples that bypass MFA, PlugX side-...

Ep. 59 - Russia's Cyber Arsenal Exposed: Defeating the FSB, GRU, and BlackCat Before They Strike 20.05.2026

In the finale of our Russian intelligence and proxy threat series, SafeBreach engineer Adrian Culley joins host Tova Dvorin to turn five episodes of analysis into concrete, actionable defense. The threat is real — now here's how you stop it. Adrian and Tova walk through five critical mitigation layers your organization needs to implement today: hardening the human firewall through Continuous Autom...

Ep. 58 - Double Dragon: How China's APT 41 Works for the State by Day — and Itself by Night 13.05.2026

China's cyber shadow has already reached your software. APT 41 — known as Double Dragon — isn't just stealing state secrets. They've pioneered a new generation of supply chain attacks, trojanizing the shared code libraries that thousands of organizations trust without question. And their latest splinter unit, UAT 7290, has been inside North American developer environments for over a year — not tri...

Ep. 57 - Russia's Proxy Bridge: BlackCat, Scattered Spider, and the Kremlin 06.05.2026

In Part 4 of our Russian intelligence series, host Tova Dvorin and Adrian Culley map the proxy bridge between Western teenage hackers and Moscow. BlackCat (ALPHV) ransomware-as-a-service is the operational hinge: Scattered Spider breaks in, BlackCat encrypts, and the FSB watches the dashboard. Hear how the Kremlin earns plausible deniability, why a $115M extortion stream self-funds Russian intelli...

Ep. 56 - 10,000 Bugs, 12 That Matter: Using AI to Cut Through Exposure Noise with CTEM 29.04.2026

Are you still stuck on the vulnerability hamster wheel? In this episode of the Cyber Resilience Brief, host Tova Dvorin is joined by SafeBreach VP of Product Koby Bar and offensive security expert Adrian Culley to unpack a major shift in how enterprises approach proactive security — and to announce the launch of SafeBreach Helm, the AI validation layer built for Continuous Threat Exposure Manageme...

Ep. 55 - The ‘Typhoon’ Hack: How China Hid Inside Your Home Router 22.04.2026

Your home router isn’t just sitting there. It might already be part of a global cyberattack. In Part 2 of our deep dive into Chinese cyber operations, Tova Dvorin and Adrian Culley unpack the “Typhoon” threat groups —Volt Typhoon, Salt Typhoon, and Flax Typhoon—and how they’re quietly reshaping modern cyber warfare. This isn’t about stealing data. It’s about staying hidden, pre-positioning, and be...

Ep. 54 - EU Cyber Resilience Act (CRA) Explained: What Every Security Leader Must Do Now 15.04.2026

The EU Cyber Resilience Act (CRA) is set to transform cybersecurity—from a best practice into a legal requirement. But what does that actually mean for security teams, product leaders, and CISOs? In this episode of The Cyber Resilience Brief , host Tova Dvorin and cybersecurity expert Adrian Culley break down the CRA in plain terms—and explain why the shift to continuous security validation is una...

Ep. 53 - The Dragon’s Shadow: China’s Silent Cyber War Has Already Begun 08.04.2026

What if the next cyberattack doesn’t steal your data… but quietly prepares to break your infrastructure? In this premiere episode of our series on Chinese threat actors, we uncover how China transformed from noisy, smash-and-grab hackers into the world’s most sophisticated cyber power—one focused not just on espionage, but on pre-positioning inside critical infrastructure . Through a chilling real...

Ep. 52 - The Russian Cyber Triad: GRU, SVR, FSB Explained 01.04.2026

In this episode of the Cyber Resilience Brief , we shift from chaotic cybercriminals to the calculated world of Russian nation-state threat actors—breaking down the three agencies that dominate Russia’s cyber operations: the GRU, SVR, and FSB . What many organizations mistakenly treat as a single “Russian threat” is actually a complex ecosystem of competing intelligence agencies—each with distinct...

Ep. 51 - 2026 Cyber War Update: Handala, MuddyWater, and the Rise of Destructive Attacks 25.03.2026

Iranian cyber attacks are escalating—shifting from espionage to destructive, large-scale operations. In this episode, we break down what CISOs need to know. Host Tova Dvorin and offensive security expert Adrian Culley analyze the latest Iranian cyber threat activity, including groups like Handala (Void Manticore) and MuddyWater (Mango Sandstorm), and how their tactics are evolving. You’ll learn ho...

Ep. 50 - Inside Trump’s 2026 Cyber Strategy: Why “Check-the-Box Security” Is Dead 18.03.2026

The U.S. just made its boldest move in cybersecurity in decades. In this episode of the Cyber Resilience Brief , Tova Dvorin and Adrian break down President Trump’s 2026 Cyber Strategy —and why it signals a massive shift from reactive defense to proactive, offensive cybersecurity . What does this mean for CISOs, security leaders, and the private sector? We unpack the strategy’s most critical pilla...

Ep. 49 - Iran’s AI-Powered Cyber Warfare: The Next Phase of the Global Cyber Threat 11.03.2026

Iranian cyber operations are entering a new era. In this final episode of our Iran cyber series, we explore how Iranian APT groups are evolving — leveraging AI, targeting supply chains, and bypassing the billion-dollar security stacks built to stop them. Hosts Tova Dvorin and Adrian Culley break down the emerging threats shaping 2026, including: • Autonomous malware powered by localized LLMs • “Sk...

Ep. 48 - Iran's 12 Days of Cyber War: How Missiles Triggered a Global OT Hacking Campaign 04.03.2026

June 2025 marked a turning point in cyber warfare. In this episode of The Cyber Resilience Brief , Tova Dvorin and offensive engineer Adrian Cully break down the cyber escalation that followed Operation Rising Lion — what some analysts now describe as Iran’s 12 days of cyber war . As missiles struck Iranian strategic targets, coordinated hacktivist groups like Cyber Avengers and Handala launched p...

Ep. 47 - APT42 & Iran’s AI Social Engineering: Deepfakes, Phishing & Hack-and-Leak 25.02.2026

Iran’s APT42 — also known as Charming Kitten or Mint Sandstorm — is redefining social engineering with generative AI, deepfake voice cloning, and long-term phishing campaigns. In this episode of the Cyber Resilience Brief, we break down how Iranian state-sponsored threat actors are using AI-powered phishing, MFA fatigue attacks, credential harvesting, and hack-and-leak operations to target journal...

Ep. 46 - Blueprint Thieves: Inside Iran’s Industrial Espionage Machine 18.02.2026

In this episode of The Cyber Resilience Brief , we break down the modern reality of Iranian cyber warfare and industrial espionage . Host Tova Dvorin and offensive security engineer Adrian Culley analyze the tactics, techniques, and procedures (TTPs) of APT33, OilRig (APT34), and MuddyWater — three of the most active Iranian state-sponsored threat actors targeting energy, aviation, manufacturing,...

Ep. 45 - Teen Hackers, SIM Swaps & Russian Ransomware 11.02.2026

In Part 2 of our Russia cyber threat series, we unpack the Western cybercrime ecosystem powering Russian ransomware operations. We examine Scattered Spider, LAPSUS$, and Shiny Hunters , and how social engineering, SIM swapping, MFA bypass, and AI-driven voice spoofing are breaching Fortune 100 companies — without zero-days. Learn how access brokers commoditize breaches, why help desks are prime ta...

Ep. 44 - DynoWiper: A Nation-State Wiper Targeting Poland’s Energy Sector 08.02.2026

In this special bonus episode of The Cyber Resilience Brief , host Tova Dvorin is joined by SafeBreach threat research expert Adrian Culley to examine DynoWiper, a destructive nation-state wiper malware observed targeting Poland’s energy sector. First detected in late December 2025, DynoWiper has been linked to attacks on Polish wind farms and combined heat and power (CHP) plants, signaling a shif...

Ep. 43 - Russian Threat Actors: Useful Fools and Proxy Power 04.02.2026

In this episode, Tova Dvorin and Adrian Culley break down the realities of Russian intelligence and cyber security , separating myth from fact. They explore how Russian state actors rely on proxy actors and cybercriminal marketplaces rather than direct operations, and why attribution challenges make cyber attacks so difficult to trace. The discussion highlights the difference between state-sponsor...

Listen to the The Cyber Resilience Brief: A SafeBreach Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.