
Sign up to save your podcasts
Or


Building a cybersecurity company has never been easier. Building one that lasts may be harder than ever.
In Episode 17 of the Dirty South Security Podcast, host Tony UV sits down with cybersecurity entrepreneur, investor, and longtime application security leader Dan Cornell for an honest conversation about building companies, raising capital, creating defensible products, and preparing for an eventual exit.
Dan shares lessons from launching his first company during the dotcom era, building Denim Group, working in the OWASP community, navigating investment and acquisition discussions, and adjusting to life after selling a business.
The conversation also looks at how generative AI is changing entrepreneurship. AI coding tools can help founders create prototypes faster and with fewer resources, but a working product is no longer enough to create a sustainable company.
Tony and Dan discuss why founders need more than an idea, what investors look for in AI startups, and how proprietary data, distribution, customer relationships, network effects, and audience growth can create a genuine competitive advantage.
Topics covered in this episode include:
⢠Lessons from building a company during the dotcom era
⢠How AI is lowering the barrier to creating software
⢠The difference between building a prototype and operating a real product
⢠Why technical knowledge still matters in the age of AI coding tools
⢠What investors look for in cybersecurity and AI startups
⢠Why an easily copied product does not have a defensible moat
⢠How proprietary data, distribution, and audiences create long-term value
⢠The risks of building a company around an AI feature that may become obsolete
⢠How entrepreneurs can build an audience around a new product
⢠Why founders need self-accountability, resilience, and persistence
⢠What founders should understand before accepting venture capital
⢠Why business exits take longer and change more often than expected
⢠Preparing for legal, financial, and technical due diligence
⢠The emotional and professional identity shift that can follow an acquisition
Dan also explains why founders need to understand their personal goals before pursuing aggressive valuations or venture-backed growth. A large valuation may sound attractive, but it can place the company on a path that does not match what the founder actually wants.
This episode is a practical and candid discussion for cybersecurity founders, startup operators, investors, technical leaders, and anyone considering building a company in the AI era.
The Dirty South Security Podcast is hosted by Tony UV and sponsored by VerSprite.
Subscribe for more direct conversations about cybersecurity, application security, entrepreneurship, offensive security, AI, investing, and the realities of building technology companies.
#Cybersecurity #Entrepreneurship #AIStartups #AppSec #StartupInvesting #CybersecurityPodcast
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
There is no such thing as unhackable AI.
As organizations move faster to integrate large language models, AI agents, MCP servers, and automated workflows, attackers are gaining new ways to exploit excessive permissions, trusted data sources, prompt injection vulnerabilities, and weak security controls.
In this episode of the Dirty South Security Podcast, we sit down with Marek ZmysÅowski, Senior Security Engineer at Microsoft and AI security expert, to examine why offensive AI security and AI red teaming are becoming essential for any organization deploying AI.
The conversation explores how artificial intelligence is changing penetration testing, cybercrime, social engineering, malware development, reconnaissance, and large-scale influence operations. Marek also explains why AI does not replace skilled attackers or penetration testers. Instead, it gives experienced operators the ability to work faster, automate more tasks, and scale attacks that previously required considerably more time and technical knowledge.
Topics covered in this episode include:
⢠Why the idea of unhackable AI is a dangerous myth
⢠How attackers are using AI to accelerate reconnaissance and exploitation
⢠The growing risk of indirect prompt injection and RAG poisoning
⢠Security concerns surrounding AI agents and MCP servers
⢠Why excessive permissions create serious agentic AI risks
⢠How AI is changing penetration testing and exploit development
⢠The role of human judgment in AI-assisted security testing
⢠Deepfakes, voice cloning, phishing, and AI-enabled social engineering
⢠Data poisoning, propaganda, bias, and geopolitical manipulation
⢠Why business logic vulnerabilities still require human expertise
⢠The importance of threat modeling and continuous adversarial testing
⢠What organizations should know before deploying AI into production
Marek also previews concepts connected to his AI model penetration testing training at DEF CON 2026 in Las Vegas.
AI is increasing the speed of software development, but speed without security creates a larger and more interconnected attack surface. Building securely is important. Testing continuously is equally important.
Subscribe to the Dirty South Security Podcast for candid conversations about cybersecurity, hacking, cybercrime, offensive security, artificial intelligence, and the evolving threat landscape.
#AISecurity #AIRedTeaming #Cybersecurity #OffensiveSecurity #PenetrationTesting #DEFCON
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
Did Anthropicās November AI espionage report tell the full story?
In this episode of the Dirty South Security Podcast, host Tony UV sits down with returning guest Dan Tentler, Executive Founder at Phobos, to replicate and mythbust Anthropicās claims that Claude Code autonomously executed a large-scale cyber espionage campaign.
Over the course of three days of live testing, we attempted to reproduce the behavior described in the report. What we discovered raises serious questions about AI autonomy, model behavior, safety guardrails, and something even more concerning ā Claude Code presenting false information during testing.
In this episode we break down:
⢠What the Anthropic November report claimed
 ⢠How we attempted to replicate the AI-orchestrated attack scenario
 ⢠Where Claude Code failed
 ⢠Evidence of deceptive or fabricated responses
 ⢠The difference between AI hallucination and intentional-seeming behavior
 ⢠What this means for cybersecurity professionals
 ⢠Implications for AI governance and enterprise adoption
This is not a hot take. This is hands-on testing.
If you work in cybersecurity, AI safety, red teaming, or enterprise security strategy, this episode is essential listening.
Watch until the end for the full breakdown of what happened during our three-day replication attempt.
Subscribe for more deep technical security discussions and mythbusting.
#DirtySouthSecurity #Anthropic #ClaudeCode #AISecurity #CyberSecurity #DanTentler #TonyUV #AIHallucinations #AITransparency #RedTeam #Infosec #AIResearch
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
Episode 14 ā Leadership in the AI Era with Ruby Agarwal (VP Cloud Platform & Operations @ Avaya)
The game has permanently changed. AI isnāt coming for your job tomorrow; itās already rewriting the operating system of every security and technology organization today. In this no-BS episode, Tony UV sits down with Ruby Agarwal to separate leadership theater from what actually works when LLMs, automation, and agentic workflows are collapsing timelines that used to take years into weeks.
We get real about:
If youāre a security leader whoās tired of generic āembrace changeā platitudes and wants battle-tested tactics for thriving in the chaos, this is the episode youāve been waiting for.
#Cybersecurity #InfoSec #AILeadership #SecurityLeadership #ArtificialIntelligence #CISO #CloudSecurity #SecOps #Leadership #AISecurity #DirtySouthSecurity
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
š„ Nobody Got Fired for Hiring IBM... But Maybe They Should Have
In this episode of Dirty South Security, we're pulling back the curtain on the security industrial complex. Tony UV sits down with Dan Tentler to discuss why small boutique security firms are running circles around the big consulting giants, and why that matters more than ever in the age of AI.
Host: Tony UV
Guest: Dan Tentler
What We Cover:
The Boutique Advantage We break down why procurement processes favor mediocrity, the difference between checkbox security and actual security, and why small firms' "unfair advantages" (speed, skin in the game, and actually giving a damn) are reshaping the industry.
Real Offensive Security Most pentests are security theater. We discuss what adversary emulation actually looks like, the attack techniques keeping security professionals up at night (supply chain attacks, LOLBins, modern C2 frameworks), and the massive gap between what vendors sell and what attackers actually do.
AI: The Offensive Security Inflection Point When everyone has AI, attack surface becomes intelligence surface. We explore how LLMs are being weaponized for polymorphic malware, why prompt injection is the new SQL injection, and why companies building AI without offensive security expertise are sitting ducks.
The Business of Staying Small and Deadly Why we don't want to be a 500-person firm, the scaling trap that kills quality, and how to build sustainable boutique practices through high-value, low-volume models.
Hot Takes & Hard Truths We tackle controversial topics: Are most cybersecurity certifications worthless? Is MITRE ATT&CK just intimidating wallpaper? Zero trust products vs. real zero trust. Bug bounties: innovation or race to the bottom? The ethics of red teaming and where we draw the line.
Key Takeaway:
If your security team can't think like attackers, you're already compromised.
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
Episode 12 - AI in Offensive Security: Cutting Through the HypeĀ
Host: Tony UV - https://www.linkedin.com/in/tonyuv/
Guest: Andrew Wilson - https://www.linkedin.com/in/awilsonaz/
Is AI revolutionizing offensive security, or simply accelerating what humans already do? In this episode, we cut through the hype and get real about how AI is reshaping vulnerability discovery, exploit development, and red team operations.
š Topics Covered:
1. AI-Powered Vulnerability Discovery
- Static analysis vs LLMs
- AI-guided fuzzing performance
- Signal-to-noise improvements
- Case study: AI vs human researcher
- Scaling AI across enterprise vs startup teams
2. Exploit Development Automation
- Can AI reliably build working exploits?
- Adaptability to target environments
- Evasion techniques vs modern defenses
- What red teams are actually using
3. Large-Scale Offensive Operations
- AI orchestration across thousands of assets
- Prioritization and continuous assessment
- Managing AI-generated data
- Measuring ROI of AI-enhanced testing
4. The AI Arms Race
- Offensive vs defensive AI
- Behavioral mimicry and detection evasion
- Speed, scale, and resource asymmetry
- Autonomous threat modeling
5. Implementation Reality Check
- Where to start with AI in OffSec
- Tool integration and team training
- Budgeting and vendor evaluation
- Compliance and regulatory concerns
š” Whether you're a security leader, red teamer, or just trying to separate signal from noise, this episode delivers practical insights and strategic foresight.
šŗ Watch, subscribe, and join the conversation.Ā
#AIinSecurity #OffensiveSecurity #RedTeamOps #ThreatModeling #CybersecurityPodcast #DirtySouthSecurity #VerSprite #TonyUV #AndrewWilson
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
In this episode, weāre flipping the script on traditional security thinking. As security champions, we know that resiliency isnāt just a buzzwordāitās the backbone of modern cybersecurity strategy.
Join us as we unpack:
š From Security to Resiliency ā Were we too confident in the early days of CISO-ship? We reflect on the evolution of security leadership and what it means to lead with resilience today.
š”ļø Is Product Resiliency Subjective? ā What really defines a āresilientā product? We challenge assumptions and explore how context, threat models, and business goals shape the answer.
āļø Top 3 Fundamentals for CISOs ā We break down the core pillars every CISO should build from to create sustainable, secure, and resilient programs or products.
š„ CISO Hot Takes ā No fluff, just real talk. We share bold opinions on whatās working, whatās not, and where the industry needs to level up.
Whether you're a CISO, security engineer, or just passionate about building better defenses, this episode is packed with insights to help you lead with clarity and confidence.
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
Welcome to Episode 10 of our Dirty South Security podcast series, where we dive deep into the world of marketing within the cybersecurity industry, especially in the context of RSA 2025. In this episode, we tackle some of the most pressing and controversial topics in the field:
Topics Covered:
AI Misrepresentations at RSA and Beyond
Explore the practice of misrepresenting AI solutions in today's industry. We discuss how these misrepresentations impact trust and the overall landscape of cybersecurity.
Marketing Investments: What Works, What Doesn't
Get insights into foundational marketing strategies. We share hot takes on what marketing investments yield the best returns and which ones fall flat.
Pay-to-Play Models
Uncover the dubious paid models that taint the integrity and authenticity of products, people, or services in cybersecurity. We examine how these models affect the industry's credibility.
Join us for an honest and insightful discussion that aims to shed light on the truths and myths of marketing in cybersecurity.Ā
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
In this episode, Tony UV and Q0PHI are joined by Rafal Lo, a seasoned InfoSec professional, to discuss the intersection of business and information security.Ā
Tune in as they explore:
1. Aligning InfoSec programs with business objectives
2. Key metrics for measuring InfoSec success
3. The benefits and challenges of leveraging managed services
Don't miss this insightful conversation packed with practical advice and expert insights!
Subscribe to our channel for more episodes and follow us on social media for the latest updates.
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
Welcome to another episode of The Dirty South Security Podcast! In this episode, we are joined by Billy Hoffman as we dive deep into the chaotic world of vulnerability management and explore ways to future-proof your organization's resiliency. Here's what we cover:
I. Vuln Mgt Sucks
II. End of Life Software: The Story of Our Lives
III. 1980 - Is it the Complacent Vulnerability Scoring System?
IV. Autopatching - Did it Ever Arrive? Why Not?
V. AI to the Rescue?
VI. Final Thoughts
Join us as we navigate these critical topics and share insights to help you stay ahead in the ever-evolving cybersecurity landscape. Don't forget to like, comment, and subscribe for more episodes
// FIND VERSPRITEāS CYBERSECURITY TEAM ONLINE //
// ABOUT VERSPRITE //
VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organizationās cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organizationās assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.
From the publisher's feed
Welcome to the Dirty South Security Podcast! šš
Join us as we dive into the hottest takes and latest trends in cybersecurity from around the globe. Whether you're a seasoned professionalā¦