Decipher Security Podcast

Decipher Security Podcast

By DecipherTechnology
Download on the App Store

Decipher Security Podcast episodes

  • Fighting Cybercrime With Global Intelligence | Will Dixon

    Will Dixon has seen the evolution of cybercrime as both a GCHQ intelligence officer and a private sector executive and analyst, and has seen the way these groups operate up close. He joins Dennis to talk about the ongoing threat from ransomware gangs, how organizations are managing their responses, and what he expects to come next.

    45 min
  • The fast16 Mystery, Stuxnet, and the History of Cyber Espionage | Juan Andres Guerrero-Saade

    JAGS joins Dennis Fisher to unpack the complex history of fast16, a highly targeted cyber espionage platform that goes back as far as 2005, many years before Stuxnet, and was deployed against targets in Iran. JAGS has been in the APT hunting game for a long time, and brings his historical perspective and context around the Shadow Brokers leak, Stuxnet ties, and how this discovery changes what we know about the use of these tools.
    LinksSentinelLabs report: https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/

    1 hr 9 min
  • cPanel Exploits, Copy Fail, and the History of Branded Bugs

    The security news was out of hand this week, so we had to pick our spots. We start with the nasty cPanel/WHM vulnerability that affects tens of millions of domains in shared hosting environments, then we discuss the Copy Fail Linux bug and its effects before seguing into the delightful history of branded bugs, logos, and parodies.


    Links

    Branded bugs and logos: https://io.netgarage.org/logo/

    43 min
  • The Vercel Intrusion and What is Happening at CISA

    This week we dig deep into the Vercel intrusion that emerged last weekend, how it happened, what the response was, and what the downstream effects may be for defenders. Then we talk about CISA's bizarre delayed response to the Axios npm compromise and what it signals about the agency's capabilities going forward.

    40 min
  • Claude Mythos, Automated Bug Hunting, and AI Eating Everything

    It's been A WEEK. Security news never sleeps, and neither does AI, so Dennis and Lindsey dive into all of the storylines coming from the Claude Mythos and Project Glasswing announcements, how organizations will deal with the coming flood of CVEs and patches, NIST's decision to only enrich specific CVEs going forward, and what could possibly be next on the horizon.

    33 min
  • The Era of AI-Led Vulnerability Research With Tom Ptacek

    Dennis sits down with Tom Ptacek of Fly.io, a veteran security researcher, founder, and observer of the vulnerability landscape, to talk about the recent wave of AI-assisted vulnerability discovery and exploit development, specifically from the use of frontier models such as Claude Mythos. Tom has strong opinions on what's coming and how human researchers and defenders need to respond.


    Tom's post: https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/

    56 min
  • Mapping the Cybercrime Ecosystem With Andrew Northern of Censys

    The internet is dark and full of terrors, but thanks to folks such as Andrew Northern, a principal security researcher at internet-mapping pioneer Censys, it doesn't have to be, Andrew joins Dennis to talk about the cybercrime ecosystem, getting his start in security on a tiny team with huge responsibilities, and the value of a strong mentor.

    34 min
  • The Rapid Rise of AI Exploit Development and More Axios Compromise Effects

    It's been quite a week in security news, and Dennis and Lindsey dig into the continued effects of the axios supply chain attack, the incredibly fast adoption of AI tools for vulnerability research and what that means for software makers and defenders, and what the future holds for vulnerability research and exploit development.

    Security Theater in Austin: https://material.security/theater-2026#theater-live-event

    52 min
  • Axios NPM Supply Chain Attack

    Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer's account, the window of exposure for the malicious packages, the behavior of the RAT that's installed on victims' machines, and what the downstream effects may be.


    Links

    Huntress post: https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package

    Socket analysis: https://socket.dev/blog/axios-npm-package-compromised

    26 min

About Decipher Security Podcast

From the publisher's feed

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp…

More shows like Decipher Security Podcast

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,641 Listeners