The Defensive Line

The Defensive Line Podcast

The Defensive Line Weekly delivers actionable cybersecurity intelligence every week, translating the latest threats, vulnerabilities, and breaches into practical defensive advice for blue teamers. Subscribe for prioritised security recommendations that work for organisations of all sizes—curated and analysed by experienced security practitioners. thedefensiveline.substack.com

Author

The Defensive Line

Category

Technology

Latest episode

Jul 8, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

The Defensive Line Weekly Podcast 025 08.07.2026

The Defensive Line Weekly — Episode 25 (28 June – 5 July 2026). A new CitrixBleed exploited in 24 hours; FortiBleed theft turns to ransomware; device-code phishing goes pro; AI runs ransomware end-to-end. 🤖 Voices are AI-generated. Story curation and analysis is human. A new CitrixBleed (CVE-2026-8451) * Citrix Security Bulletin CTX696604 — fixed builds * watchTowr Labs — CitrixBleed to Infinity...

The Defensive Line Weekly Podcast 024 01.07.2026

The Defensive Line Weekly — Episode 24 , covering 21–28 June 2026. A weekly briefing for blue teamers and security leaders: the biggest stories of the week, why they matter, and what to do next. 🤖 Voices are AI-generated. Story curation and analysis is human. Sources Cisco Catalyst SD-WAN zero-day exploited for months * Mandiant / Google Cloud — zero-day exploitation of Cisco Catalyst SD-WAN Mana...

The Defensive Line Weekly Podcast 023 24.06.2026

The Defensive Line Weekly podcast is the audio version of the weekly Defensive Line Substack intelligence summary. Written by humans but read by AI. It turns the week’s key cyber stories into a practical conversation between Carter and Lizzie. FortiBleed and edge credential exposure * CISA — CISA urges hardening Fortinet devices after reports of credential exposure * NCSC — Advice following global...

The Defensive Line Weekly Podcast 022 17.06.2026

The Defensive Line Weekly podcast is the audio version of the weekly Defensive Line Substack intelligence summary — the same curated briefing for blue teamers and security leaders, in a format you can listen to on the move. This week: PeopleSoft zero-day hits universities; AUR packages hijacked; AI agents turn ordinary inputs into code paths. ShinyHunters / Oracle PeopleSoft Oracle Security Alert...

The Defensive Line Weekly Podcast 021 11.06.2026

The Defensive Line Weekly podcast is the audio version of our weekly Defensive Line Substack intelligence summary — the same curated briefing for blue teamers and security leaders, in a format you can listen to on the move. This week: A self-spreading supply chain worm hits npm, PyPI and GitHub; AI turns up as both an attacker’s tool and an attack surface; and a five-month email espionage campaign...

The Defensive Line Weekly Podcast 020 03.06.2026

Gogs unpatched remote code execution * Rapid7 * BleepingComputer * SecurityWeek ShinyHunters: Charter and Carnival * BleepingComputer — Charter * BleepingComputer — Carnival * The Record * Carnival Corporation notice FBI warning: Silent Ransom Group * FBI IC3 Advisory * The Record * SecurityWeek * CyberScoop Honourable mentions * Palo Alto GlobalProtect: Rapid7 , Palo Alto Networks advisory , CISA...

The Defensive Line Weekly Podcast 019 27.05.2026

Story 1: Developer Supply Chains Under Sustained Assault * OX Security — TeamPCP / GitHub breach * StepSecurity — Nx Console VS Code extension * GitHub Security Blog — Investigating unauthorised access * SafeDep — Megalodon mass GitHub repo backdooring * StepSecurity — Megalodon CI/CD secrets exfiltration * Aikido Security — Laravel-Lang supply chain attack * Snyk — Laravel-Lang supply chain advis...

The Defensive Line Weekly Podcast 018 20.05.2026

The Defensive Line Weekly is a weekly intelligence briefing for blue teamers and security leaders — the stories that matter most, with clear implications and practical defensive actions. This podcast is the audio version of the weekly Defensive Line Substack newsletter, bringing the same curated analysis to your ears. Voices are AI generated, but the analysis and script is human curated. Topic 1:...

The Defensive Line Weekly Podcast 017 13.05.2026

The Defensive Line Weekly is a weekly intelligence briefing for blue teamers and security leaders — the stories that matter most, with clear implications and practical defensive actions. This podcast is the audio version of the weekly Defensive Line Substack newsletter, bringing the same curated analysis to your ears. Voices are AI generated, but the analysis and script is human curated. ShinyHunt...

The Defensive Line Weekly Podcast 016 06.05.2026

The Defensive Line Weekly is a podcast version of our weekly Substack intelligence summary — the security stories that matter most for blue teamers and security leaders, with clear implications and practical defensive actions. AI voices are used, but the content is human curated and written with the support of AI. Topic 1: Helpdesk Impersonation Continues to Succeed * CrowdStrike — Cordial Spider...

The Defensive Line Weekly Podcast 015 29.04.2026

Story 1: Vercel Breached via AI Tool OAuth Token Sprawl * Vercel Security Bulletin * Hudson Rock / InfoStealers * The Register * Push Security * Varonis Story 2: BlackFile Extortion Targets Retail and Hospitality * RH-ISAC / Unit 42 Joint Report * BleepingComputer Story 3: The Gentlemen Ransomware Scales Fast * Check Point Research * BleepingComputer * The Hacker News Honourable Mentions Bitwarden...

The Defensive Line Weekly Podcast 014 22.04.2026

The Defensive Line Weekly is a curated weekly intelligence briefing for blue teamers and security leaders — produced as both a written Substack newsletter and this podcast. Each week we cut through the noise to the stories that actually matter for defenders, with clear implications and practical defensive actions. Topic 1: QEMU Virtual Machines Weaponised to Blind EDR * Sophos X-Ops — QEMU abused...

The Defensive Line Weekly Podcast 013 15.04.2026

The Defensive Line Weekly is a curated weekly intelligence briefing for blue teamers and security leaders — delivered as both a Substack newsletter and this podcast. Each week, Carter and Lizzie go deep on the stories that matter, with clear context and practical defensive actions. Topic 1 — APT28 Hijacks Home Routers to Steal Microsoft 365 Tokens * Microsoft Security Blog — SOHO Router Compromise...

The Defensive Line Weekly Podcast 012 08.04.2026

The Defensive Line Weekly is a podcast version of the weekly Defensive Line Substack intelligence summary — covering the biggest cybersecurity stories of the week, what they mean for defenders, and what to do next. Each episode features AI voices with Carter (intelligence analyst) and Lizzie (blue teamer) in conversation. Story 1: Supply Chain — TeamPCP & Axios/DPRK * CERT-EU: European Commission...

The Defensive Line Weekly Podcast 011 01.04.2026

Main Stories TeamPCP PyPI Supply Chain — LiteLLM & Telnyx * Wiz Research disclosure (LiteLLM): https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign * BleepingComputer (Telnyx): https://www.bleepingcomputer.com/news/security/backdoored-telnyx-pypi-package-pushes-malware-hidden-in-wav-audio/ * Telnyx security notice: https://telnyx.com/resources/telnyx-python...

The Defensive Line Weekly Podcast 010 25.03.2026

The Defensive Line Weekly podcast is the audio version of the weekly Defensive Line Substack intelligence summary — the same stories, the same analysis, built for blue teamers and security leaders who want actionable intelligence on the go. Story 1: Trivy Compromised, CanisterWorm Spreads * Wiz Research — Trivy Compromised: TeamPCP Supply Chain Attack * BleepingComputer — Trivy Vulnerability Scann...

The Defensive Line Weekly Podcast 009 18.03.2026

A podcast version of the weekly Defensive Line Substack Intelligence Summary — focused on what matters, why it matters, and what defenders should do next. Handala wipes Stryker (management plane) * https://www.bleepingcomputer.com/news/security/medtech-giant-stryker-offline-after-iran-linked-wiper-malware-attack/ * https://therecord.media/stryker-tells-sec-unknown-timeline-recovery * https://unit4...

The Defensive Line Weekly Podcast 008 11.03.2026

Episode Summary: Episode 8 of The Defensive Line Weekly covers a week dominated by the cyber dimension of the Iran conflict, with MuddyWater pre-positioned in U.S. critical infrastructure and physical drone strikes on A.W.S data centres. We also examine InstallFix — a ClickFix evolution targeting developers via cloned tool installation pages — and a Microsoft oh-auth protocol abuse that turns legi...

The Defensive Line Weekly Podcast 007 04.03.2026

Cisco Catalyst S.D-WAN (CVE-2026-20127) * NCSC-UK Advisory — Exploitation of Cisco Catalyst SD-WANs — https://www.ncsc.gov.uk/news/exploitation-cisco-catalyst-sd-wans * BleepingComputer — Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023 — https://www.bleepingcomputer.com/news/security/critical-cisco-sd-wan-bug-exploited-in-zero-day-attacks-since-2023/ * The Hacker News — Cisco SD...

The Defensive Line Weekly Podcast 006 25.02.2026

Episode 6 of The Defensive Line Weekly examines how attackers are increasingly exploiting legitimate infrastructure to bypass defences: a Russian-aligned threat actor abuses Microsoft’s real authentication pages to harvest SSO credentials, China-nexus espionage actors exploit hardcoded credentials in Dell’s backup platform after eighteen months of silent access, and a financially motivated group u...

The Defensive Line Weekly Podcast 005 18.02.2026

Episode summary This episode looks at a shift in initial access: attackers increasingly win by exploiting trust relationships rather than pure exploit chains. We cover how A-I platforms, messaging and meeting workflows, software updates, and browser extensions are becoming a new perimeter—and what to do about it. Topics and sources Adversarial A-I moving from experimentation to operational tooling...

The Defensive Line Weekly Podcast 004 11.02.2026

This week covers five stories showing attackers exploiting well-understood defensive gaps. Shadow Campaigns breached 70+ organisations across 155 countries using conventional techniques. DKnife framework compromises edge devices for persistent traffic interception. A real-world attack used a decade-old forensic driver to disable 59 security products. Critical Google Looker vulnerabilities enable R...

The Defensive Line Weekly Podcast 003 04.02.2026

Coverage period: 27 January–2 February 2026 Episode summary: This episode covers four critical security stories including industrialised vishing campaigns targeting approximately 100 organisations, a vendor-managed SSO zero-day demonstrating dependency risk, wiper attacks on Polish energy infrastructure, and critical SolarWinds Web Help Desk vulnerabilities. Stories Covered 1. Match Group Breach V...

The Defensive Line Weekly Podcast 002 28.01.2026

20–26 January 2026 Episode Overview This week’s episode covers five critical security stories: industrialised voice phishing targeting SSO credentials, GitLab MFA bypass creating supply chain risk, AWS CodeBuild misconfiguration exposing the AWS Console supply chain, email threat research confirming the shift from malware to identity compromise, and sobering findings from Bank of England red team...

The Defensive Line Weekly Podcast 001 21.01.2026

Episode Overview This week’s episode covers five critical security stories: authentication failures in enterprise platforms, regulatory enforcement driving security improvements, supply chain attacks on automation tools, Russian hacktivist DDoS campaigns, and browser extension malware campaigns. Hosts: * Carter – Intelligence Analyst covering threat landscape and attacker behaviour * Lizzie – Blue...

Listen to the The Defensive Line Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.