Dirty South Security Podcast

Dirty South Security Podcast

By VerSprite CybersecurityBusinessNewsTechnology
Download on the App Store

Dirty South Security Podcast episodes

  • Ep.17 - Strong Drink – Hard Hitting Truths in Entrepreneurial Success in Cyber, Tech as an Investor & Entrepreneur

    Building a cybersecurity company has never been easier. Building one that lasts may be harder than ever.

    In Episode 17 of the Dirty South Security Podcast, host Tony UV sits down with cybersecurity entrepreneur, investor, and longtime application security leader Dan Cornell for an honest conversation about building companies, raising capital, creating defensible products, and preparing for an eventual exit.

    Dan shares lessons from launching his first company during the dotcom era, building Denim Group, working in the OWASP community, navigating investment and acquisition discussions, and adjusting to life after selling a business.

    The conversation also looks at how generative AI is changing entrepreneurship. AI coding tools can help founders create prototypes faster and with fewer resources, but a working product is no longer enough to create a sustainable company.

    Tony and Dan discuss why founders need more than an idea, what investors look for in AI startups, and how proprietary data, distribution, customer relationships, network effects, and audience growth can create a genuine competitive advantage.

    Topics covered in this episode include:

    • Lessons from building a company during the dotcom era
    • How AI is lowering the barrier to creating software
    • The difference between building a prototype and operating a real product
    • Why technical knowledge still matters in the age of AI coding tools
    • What investors look for in cybersecurity and AI startups
    • Why an easily copied product does not have a defensible moat
    • How proprietary data, distribution, and audiences create long-term value
    • The risks of building a company around an AI feature that may become obsolete
    • How entrepreneurs can build an audience around a new product
    • Why founders need self-accountability, resilience, and persistence
    • What founders should understand before accepting venture capital
    • Why business exits take longer and change more often than expected
    • Preparing for legal, financial, and technical due diligence
    • The emotional and professional identity shift that can follow an acquisition

    Dan also explains why founders need to understand their personal goals before pursuing aggressive valuations or venture-backed growth. A large valuation may sound attractive, but it can place the company on a path that does not match what the founder actually wants.

    This episode is a practical and candid discussion for cybersecurity founders, startup operators, investors, technical leaders, and anyone considering building a company in the AI era.

    The Dirty South Security Podcast is hosted by Tony UV and sponsored by VerSprite.

    Subscribe for more direct conversations about cybersecurity, application security, entrepreneurship, offensive security, AI, investing, and the realities of building technology companies.

    #Cybersecurity #Entrepreneurship #AIStartups #AppSec #StartupInvesting #CybersecurityPodcast

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    37 min
  • Ep.16 - Unhackable AI Is a Myth: Why Companies Need AI Red Teaming with Marek Zmysłowski

    There is no such thing as unhackable AI.

    As organizations move faster to integrate large language models, AI agents, MCP servers, and automated workflows, attackers are gaining new ways to exploit excessive permissions, trusted data sources, prompt injection vulnerabilities, and weak security controls.

    In this episode of the Dirty South Security Podcast, we sit down with Marek Zmysłowski, Senior Security Engineer at Microsoft and AI security expert, to examine why offensive AI security and AI red teaming are becoming essential for any organization deploying AI.

    The conversation explores how artificial intelligence is changing penetration testing, cybercrime, social engineering, malware development, reconnaissance, and large-scale influence operations. Marek also explains why AI does not replace skilled attackers or penetration testers. Instead, it gives experienced operators the ability to work faster, automate more tasks, and scale attacks that previously required considerably more time and technical knowledge.

    Topics covered in this episode include:

    • Why the idea of unhackable AI is a dangerous myth
    • How attackers are using AI to accelerate reconnaissance and exploitation
    • The growing risk of indirect prompt injection and RAG poisoning
    • Security concerns surrounding AI agents and MCP servers
    • Why excessive permissions create serious agentic AI risks
    • How AI is changing penetration testing and exploit development
    • The role of human judgment in AI-assisted security testing
    • Deepfakes, voice cloning, phishing, and AI-enabled social engineering
    • Data poisoning, propaganda, bias, and geopolitical manipulation
    • Why business logic vulnerabilities still require human expertise
    • The importance of threat modeling and continuous adversarial testing
    • What organizations should know before deploying AI into production

    Marek also previews concepts connected to his AI model penetration testing training at DEF CON 2026 in Las Vegas.

    AI is increasing the speed of software development, but speed without security creates a larger and more interconnected attack surface. Building securely is important. Testing continuously is equally important.

    Subscribe to the Dirty South Security Podcast for candid conversations about cybersecurity, hacking, cybercrime, offensive security, artificial intelligence, and the evolving threat landscape.

    #AISecurity #AIRedTeaming #Cybersecurity #OffensiveSecurity #PenetrationTesting #DEFCON

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    33 min
  • Ep. 15 - We Replicated the Anthropic AI Espionage Report… and Claude Code Lied

    Did Anthropic’s November AI espionage report tell the full story?

    In this episode of the Dirty South Security Podcast, host Tony UV sits down with returning guest Dan Tentler, Executive Founder at Phobos, to replicate and mythbust Anthropic’s claims that Claude Code autonomously executed a large-scale cyber espionage campaign.

    Over the course of three days of live testing, we attempted to reproduce the behavior described in the report. What we discovered raises serious questions about AI autonomy, model behavior, safety guardrails, and something even more concerning — Claude Code presenting false information during testing.

    In this episode we break down:

    • What the Anthropic November report claimed
     • How we attempted to replicate the AI-orchestrated attack scenario
     • Where Claude Code failed
     • Evidence of deceptive or fabricated responses
     • The difference between AI hallucination and intentional-seeming behavior
     • What this means for cybersecurity professionals
     • Implications for AI governance and enterprise adoption

    This is not a hot take. This is hands-on testing.

    If you work in cybersecurity, AI safety, red teaming, or enterprise security strategy, this episode is essential listening.

    Watch until the end for the full breakdown of what happened during our three-day replication attempt.

    Subscribe for more deep technical security discussions and mythbusting.

    #DirtySouthSecurity #Anthropic #ClaudeCode #AISecurity #CyberSecurity #DanTentler #TonyUV #AIHallucinations #AITransparency #RedTeam #Infosec #AIResearch

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    2 hr 19 min
  • Ep. 14 – Leadership in the AI Era

    Episode 14 – Leadership in the AI Era with Ruby Agarwal (VP Cloud Platform & Operations @ Avaya)

    The game has permanently changed. AI isn’t coming for your job tomorrow; it’s already rewriting the operating system of every security and technology organization today. In this no-BS episode, Tony UV sits down with Ruby Agarwal to separate leadership theater from what actually works when LLMs, automation, and agentic workflows are collapsing timelines that used to take years into weeks.

    We get real about:

    • Why the old ā€œI’ve got all the answersā€ CISO/CIO playbook is now a liability
    • Moving from control-freak management to radical curiosity and productive discomfort
    • How to build actual AI fluency in your teams without turning everyone into a prompt engineer
    • Redefining performance when AI eats 70% of the repetitive work SecOps used to own
    • Why ethical guardrails aren’t a ā€œnice-to-haveā€ compliance checkbox; they’re your last line of defense against career-ending mistakes
    • The hard conversations leaders must have when roles inevitably morph or disappear
    • Three dead-simple moves you can execute this week to stop lagging and start leading the AI wave

    If you’re a security leader who’s tired of generic ā€œembrace changeā€ platitudes and wants battle-tested tactics for thriving in the chaos, this is the episode you’ve been waiting for.

    #Cybersecurity #InfoSec #AILeadership #SecurityLeadership #ArtificialIntelligence #CISO #CloudSecurity #SecOps #Leadership #AISecurity #DirtySouthSecurity

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    48 min
  • Ep. 13 - Small Firms, Big Impact - Why Offensive Security Matters More Than Ever

    šŸ”„ Nobody Got Fired for Hiring IBM... But Maybe They Should Have

    In this episode of Dirty South Security, we're pulling back the curtain on the security industrial complex. Tony UV sits down with Dan Tentler to discuss why small boutique security firms are running circles around the big consulting giants, and why that matters more than ever in the age of AI.

    Host: Tony UV
    Guest: Dan Tentler


    What We Cover:

    The Boutique Advantage We break down why procurement processes favor mediocrity, the difference between checkbox security and actual security, and why small firms' "unfair advantages" (speed, skin in the game, and actually giving a damn) are reshaping the industry.

    Real Offensive Security Most pentests are security theater. We discuss what adversary emulation actually looks like, the attack techniques keeping security professionals up at night (supply chain attacks, LOLBins, modern C2 frameworks), and the massive gap between what vendors sell and what attackers actually do.

    AI: The Offensive Security Inflection Point When everyone has AI, attack surface becomes intelligence surface. We explore how LLMs are being weaponized for polymorphic malware, why prompt injection is the new SQL injection, and why companies building AI without offensive security expertise are sitting ducks.

    The Business of Staying Small and Deadly Why we don't want to be a 500-person firm, the scaling trap that kills quality, and how to build sustainable boutique practices through high-value, low-volume models.

    Hot Takes & Hard Truths We tackle controversial topics: Are most cybersecurity certifications worthless? Is MITRE ATT&CK just intimidating wallpaper? Zero trust products vs. real zero trust. Bug bounties: innovation or race to the bottom? The ethics of red teaming and where we draw the line.


    Key Takeaway:

    If your security team can't think like attackers, you're already compromised.

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    1 hr 13 min
  • Ep. 12 - AI in Offensive Security - Cutting Through the Hype

    Episode 12 - AI in Offensive Security: Cutting Through the HypeĀ 

    Host: Tony UV - https://www.linkedin.com/in/tonyuv/

    Guest: Andrew Wilson - https://www.linkedin.com/in/awilsonaz/

    Is AI revolutionizing offensive security, or simply accelerating what humans already do? In this episode, we cut through the hype and get real about how AI is reshaping vulnerability discovery, exploit development, and red team operations.

    šŸ” Topics Covered:

    1. AI-Powered Vulnerability Discovery

    - Static analysis vs LLMs
    - AI-guided fuzzing performance
    - Signal-to-noise improvements
    - Case study: AI vs human researcher
    - Scaling AI across enterprise vs startup teams

    2. Exploit Development Automation

    - Can AI reliably build working exploits?
    - Adaptability to target environments
    - Evasion techniques vs modern defenses
    - What red teams are actually using

    3. Large-Scale Offensive Operations

    - AI orchestration across thousands of assets
    - Prioritization and continuous assessment
    - Managing AI-generated data
    - Measuring ROI of AI-enhanced testing

    4. The AI Arms Race

    - Offensive vs defensive AI
    - Behavioral mimicry and detection evasion
    - Speed, scale, and resource asymmetry
    - Autonomous threat modeling

    5. Implementation Reality Check

    - Where to start with AI in OffSec
    - Tool integration and team training
    - Budgeting and vendor evaluation
    - Compliance and regulatory concerns

    šŸ’” Whether you're a security leader, red teamer, or just trying to separate signal from noise, this episode delivers practical insights and strategic foresight.

    šŸ“ŗ Watch, subscribe, and join the conversation.Ā 

    #AIinSecurity #OffensiveSecurity #RedTeamOps #ThreatModeling #CybersecurityPodcast #DirtySouthSecurity #VerSprite #TonyUV #AndrewWilson

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    58 min
  • Ep. 11 - Building Resiliency: The New Paradigm in Security Leadership

    In this episode, we’re flipping the script on traditional security thinking. As security champions, we know that resiliency isn’t just a buzzword—it’s the backbone of modern cybersecurity strategy.

    Join us as we unpack:

    šŸ” From Security to Resiliency – Were we too confident in the early days of CISO-ship? We reflect on the evolution of security leadership and what it means to lead with resilience today.

    šŸ›”ļø Is Product Resiliency Subjective? – What really defines a ā€œresilientā€ product? We challenge assumptions and explore how context, threat models, and business goals shape the answer.

    āš™ļø Top 3 Fundamentals for CISOs – We break down the core pillars every CISO should build from to create sustainable, secure, and resilient programs or products.

    šŸ”„ CISO Hot Takes – No fluff, just real talk. We share bold opinions on what’s working, what’s not, and where the industry needs to level up.

    Whether you're a CISO, security engineer, or just passionate about building better defenses, this episode is packed with insights to help you lead with clarity and confidence.

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    39 min
  • Ep.10 - Truth in Marketing An Honest Regard on Marketing Cybersecurity RSA 2025

    Welcome to Episode 10 of our Dirty South Security podcast series, where we dive deep into the world of marketing within the cybersecurity industry, especially in the context of RSA 2025. In this episode, we tackle some of the most pressing and controversial topics in the field:

    Topics Covered:

    AI Misrepresentations at RSA and Beyond
    Explore the practice of misrepresenting AI solutions in today's industry. We discuss how these misrepresentations impact trust and the overall landscape of cybersecurity.

    Marketing Investments: What Works, What Doesn't
    Get insights into foundational marketing strategies. We share hot takes on what marketing investments yield the best returns and which ones fall flat.

    Pay-to-Play Models
    Uncover the dubious paid models that taint the integrity and authenticity of products, people, or services in cybersecurity. We examine how these models affect the industry's credibility.

    Join us for an honest and insightful discussion that aims to shed light on the truths and myths of marketing in cybersecurity.Ā 


    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    32 min
  • Ep.09 - Business Takes on InfoSec - Program Alignment, Metrics, Leveraging Managed Services

    In this episode, Tony UV and Q0PHI are joined by Rafal Lo, a seasoned InfoSec professional, to discuss the intersection of business and information security.Ā 

    Tune in as they explore:

    1. Aligning InfoSec programs with business objectives
    2. Key metrics for measuring InfoSec success
    3. The benefits and challenges of leveraging managed services

    Don't miss this insightful conversation packed with practical advice and expert insights!

    Subscribe to our channel for more episodes and follow us on social media for the latest updates.

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    49 min
  • Ep.08 - Vuln Mgt Meltdowns, Revisiting Autopatching, & Future Proofing Resiliency

    Welcome to another episode of The Dirty South Security Podcast! In this episode, we are joined by Billy Hoffman as we dive deep into the chaotic world of vulnerability management and explore ways to future-proof your organization's resiliency. Here's what we cover:

    I. Vuln Mgt Sucks

    • Ā - We break down the stereotypical vulnerability management process and its pitfalls.
    • Ā - Can CVSS 4.0 (link) save the day?
    • Exploring EPSS & KEV and their roles in vulnerability management.


    II. End of Life Software: The Story of Our Lives

    • Ā - Discussing the decade-old Cisco ASA vulnerability (CVE-2014-2120) that'sĀ  - still being actively exploited.
    • Ā - The mentality around patching, acceptable vulnerability levels, and the ongoing struggle with EOL assets.


    III. 1980 - Is it the Complacent Vulnerability Scoring System?

    • Ā - Examining the medium severity CVEs and how most organizations handle them.
    • Ā - Why do many security teams overlook medium-severity vulnerabilities and their impact on overall security?


    IV. Autopatching - Did it Ever Arrive? Why Not?

    • Ā - Understanding the complexities of 1:many relationships in patching.
    • Ā - The implications of downtime and why auto patching hasn't become the norm.


    V. AI to the Rescue?

    • Ā - Debunking the marketing hype around AI in vulnerability management (link).
    • Ā - Discussing the rise of AI-generated compliance solutions and their effectiveness.


    VI. Final Thoughts

    • How can we move beyond the outdated 2005 enterprise vulnerability management practices?


    Join us as we navigate these critical topics and share insights to help you stay ahead in the ever-evolving cybersecurity landscape. Don't forget to like, comment, and subscribe for more episodes

    // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //

    • Ā VerSprite: https://versprite.com/
    • LinkedIn: https://www.linkedin.com/versprite-llc/
    • Twitter: https://twitter.com/versprite/
    • YouTube: https://www.youtube.com/c/VerSprite


    // ABOUT VERSPRITE //
    VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

    37 min

About Dirty South Security Podcast

From the publisher's feed

Welcome to the Dirty South Security Podcast! šŸŒšŸ”’

Join us as we dive into the hottest takes and latest trends in cybersecurity from around the globe. Whether you're a seasoned professional…