Decipher Security Podcast

Decipher Security Podcast

By DecipherTechnology
Download on the App Store

Decipher Security Podcast episodes

  • How The Conversation Predicted Our Surveillance Society 50 Years Ago

    Perhaps no film captures the paranoia and anxiety of the 1970s better than The Conversation, Francis Ford Copolla's masterpiece about reclusive surveillance expert Harry Caul, a man who it's safe to say has some demons. Decades before we all agreed to carry tracking and recording devices in our pockets, The Conversation shows us just how invasive and damaging technology can be.

    59 min
  • Shai Hulud Returns, How Attackers are Using AI, and More Weird MSRC Behavior

    We regret to inform you that there are more npm supply chain attacks this week, and a new variant of the Shai Hulud worm is involved. We also talk about the new analysis from Anthropic on a year of data relating to how attackers are using AI in their operations, and the continuing adventures of Microsoft's relationship with security researchers.

    37 min
  • Microsoft Has Forgotten Its Vulnerability Disclosure History

    The recent Nightmare-Eclipse zero day drop and attendant drama has stirred up all kinds of trouble and unfortunately spurred Microsoft to publish a post scolding security researchers for not using the "proper channels" to disclose bugs, threatening legal action, and generally dredging up every hobby horse from the threadbare disclosure debate.


    Links

    MSRC post: https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

    Decipher story: https://decipher.sc/2026/05/28/the-past-is-always-present-in-vulnerability-disclosure/

    Expel event: https://info.expel.com/event-mythos-unhappy-hour.html

    46 min
  • Lessons in Resilience, Perseverance, and Leadership With Matt Eversmann

    After being caught in one of the more notorious battles in modern American history, Matt Eversmann's military career has become the stuff of legend. The Battle of Mogadishu, immortalized in the book and movie Black Hawk Down, was a pivotal event in U.S. history and in the lives of Matt and his fellow soldiers. Now retired from the army and focusing on training the next generation of leaders, Matt joins Dennis Fisher to talk about his career, what he's learned from his failures and successes, and how vital resilience and perseverance are for success in any field.

    Matt's biography: https://thayerleadership.com/team-member/first-sergeant-matt-eversmann/

    1 hr 19 min
  • Chain Chain Chain of Compromises

    In the spring, a young attacker's fancy turns to supply chain compromises, and this season's crop includes the GitHub breach and the Grafana intrusion, which are connected and trace back to the TanStack supply chain attack and...TeamPCP.


    Links

    Grafana attack: https://decipher.sc/2026/05/17/grafana-investigating-token-compromise-and-extortion-attempt/

    GitHub breach: https://decipher.sc/2026/05/20/github-confirms-internal-breach/

    23 min
  • What the Data Tells Us About Claude Mythos and Bug Exploitability | Jay Jacobs and Michael Roytman

    Finding a huge pile of bugs with Claude Mythos is great, but the logical next step is figuring out how many of those vulnerabilities are likely to be exploited in the near future. Jay Jacobs and Michael Roytman of Empirical Security join Dennis to talk about how the Exploit Prediction Scoring System can help teams make informed decisions and prioritize patching the most important vulnerabilities. Jay and Michael are pioneers in the data-driven security field and help steer the EPSS effort.


    44 min
  • Solving Hard Security Problems With an Outsider's Perspective | Sravish Sridhar

    Unlike a lot of founders in the industry, Sravish Sridhar hasn't spent his career in the security world. He comes from a background in distributed computing and advanced math, and is a successful entrepreneur who's now bringing that experience to bear at TrustCloud, where he's helping CISOs automate and streamline their compliance programs.

    54 min
  • AI Has a Security Measurement Problem | Gary McGraw

    Few people (if any) have spent more time thinking about and working on the hard problems in security and software than Gary McGraw, and he also happens to have a PhD in cognitive science and computer science and has been studying neural nets and AI systems for 30+ years. Gary joins Dennis to talk about his team's new research into AI security benchmarks, measurement, and bringing a software security approach to LLMs and AI systems.


    Links

    BIML report: https://berryvilleiml.com/results/no-security-meter-ai.pdf

    39 min
  • Inside the $285M Drift Protocol Heist | Ari Redbord

    Ari Redbord, Global Head of Policy at TRM Labs, talks about the insane background behind the $285 million Drift Protocol crypto heist, how law enforcement agencies are investigating ransomware-linked cryptocurrency wallets, and how effective sanctions are on cybercrime.



    35 min
  • The Canvas Attack, Ivanti and Palo Alto Exploits, and Dirty Frag

    If we needed any more evidence that the internet was a mistake, this week provided it. We kick things off with a discussion of the Canvas breach that has affected thousands of schools worldwide, then we dig into the disclosure of two new vulnerabilities in Ivanti and Palo Alto Networks products that are actively exploited, and then we talk about a new branded Linux bug called Dirty Frag. Finally, we wrap up with some comic relief from the Everything App.


    Links

    Ivanti bug: https://decipher.sc/2026/05/07/ivanti-warns-of-exploited-epmm-flaw-cve-2026-6973/

    Palo Alto bug: https://decipher.sc/2026/05/06/845/

    Dirty Frag: https://decipher.sc/2026/05/07/new-dirty-frag-linux-bug-emerges/

    The viral tweet: https://x.com/DennisF/status/2050682024587845690

    42 min

About Decipher Security Podcast

From the publisher's feed

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp…

More shows like Decipher Security Podcast

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,641 Listeners