Secure Talk Podcast

Secure Talk Podcast

By Justin BealsNewsTechnologyTech News
Download on the App Store

Secure Talk Podcast episodes

  • How Russian Disinformation Networks Are Poisoning AI Chatbots | SecureTalk with NewsGuard Experts


    Episode Summary:
    In this eye-opening episode of Secure Talk, host Justin Beals investigates how foreign disinformation campaigns have evolved to target AI systems. NewsGuard researchers McKenzie Sadeghi and Isis Blachez reveal their groundbreaking investigation into the Moscow-based Pravda network that has successfully infiltrated Western AI chatbots, creating a new frontier in information warfare that bypasses human readers to directly corrupt the technology we rely on for information.

    Key Insights:

    • Leading AI chatbots repeated Russian disinformation 33% of the time when tested on key geopolitical topics
    • The Pravda network has expanded from 50 to over 150 websites specifically designed to influence AI training data
    • Modern disinformation operations now prioritize "LLM grooming" over targeting human readers
    • Even when AI systems attempt to debunk false claims, they often cite unreliable sources, further legitimizing them
    • Human oversight remains essential as these networks constantly evolve to evade automated detection

    Notable Quotes: "Bad actors are targeting AI models to get their information to appear in those responses, but they're also weaponizing AI to produce disinformation at scale." - McKenzie Sadeghi

    "What is changing is really the delivery of the disinformation... it's reaching a much larger audience and an audience that's not targeted as specifically because now practically anyone is using ChatGPT or other chatbots." - Isis Blachez

    "This network does not invest any money or resources into spreading its content online... It's sort of serving as a centralized hub. And as a result, it appears very high not only in search results but also in chatbot responses." - McKenzie Sadeghi


    Resources: 

    Sadeghi, M., & Blachez, I. (2025, March 6). A well-funded Moscow-based global disinformation network. NewsGuard Reality Check. https://www.newsguardrealitycheck.com/p/a-well-funded-moscow-based-global

    44 min
  • The Future of APIs in the Age of AI Agents A Conversation with Postman's Sam Chehab


    In this episode of SecureTalk, host Justin Beals explores the evolving world of API technology and security with Sam Chehab, Head of Security at Postman - the platform used by over 35 million developers and 90% of Fortune 500 companies.


    Episode Insights:

    • Postman's Strategic Position: Learn why Sam joined Postman in September 2024 and how they're positioned to be the connective tissue for the emerging AI agent ecosystem
    • APIs as Agent Infrastructure: Sam explains how Postman's catalog of hundreds of thousands of documented APIs creates the perfect foundation for AI agent interactions
    • Security by Design: Discover how Postman is embedding security throughout the API lifecycle - from conception to deployment
    • The Human Factor in Security: Why security remains a collaborative responsibility across organizations and how to foster a security-minded culture
    • Next-Gen Challenges: Sam's perspective on balancing innovation with fundamental security hygiene concerns like supply chain vulnerabilities


    "I see such a larger ecosystem that's really going to get built here beyond what's out in the market today," says Sam, discussing how Postman will facilitate human-agent collaboration in building the next generation of applications.


    Sam brings unique insights from his previous roles at technology giants like Palo Alto Networks and NVIDIA, where he once demonstrated an early chatbot prototype to Jensen Huang himself. His experience taking products through rigorous FedRAMP certification processes provides a valuable perspective on enterprise-grade security implementation.


    This episode offers essential insights for developers, security professionals, and technology leaders interested in the intersection of APIs, AI, and enterprise security in today's rapidly evolving digital landscape.


    47 min
  • Beyond the Blinky Lights: Why Security Governance Drives Technology with Bryant Tow


    In this eye-opening episode of SecureTalk, host Justin Beals welcomes Bryant Tow, Chief Security Officer at LeapFrog Services, to discuss why technology alone can't solve cybersecurity challenges. Bryant reveals how the "Ring of Security" concept shows that up to half of your attack surface lies outside of technology—in governance, policies, people, and processes. The conversation explores real-world examples like the Change Healthcare breach, why security frameworks often fall short, and how building a culture of security requires connecting protection of company assets to personal security concerns.

    Key Topics

    • The Change Healthcare breach: How a single oversight led to a $2.9 billion loss despite substantial technology investments
    • Why frameworks like CIS are great starting points but insufficient on their own
    • How the "Ring of Security" approach addresses the complete attack surface
    • Building a security culture that resonates with employees on a personal level
    • Why a business impact analysis is critical but often missing from frameworks
    • The importance of understanding your data before implementing AI solutions

    Notable Quotes


    "When you do the root cause analysis on headline breaches, nearly all of them started somewhere outside the technology." - Bryant Tow

    "Even if you do your technology perfectly, you're leaving half of your attack surface open." - Bryant Tow


    "Strategy drives governance. Governance drives operation." - Bryant Tow


    About the Guest


    Bryant Tow serves as Chief Security Officer at LeapFrog Services, where he assists clients with comprehensive security programs including strategy, governance, and operations. Previously, he owned Cyber Risk Solutions and served on the Department of Homeland Security Sector Coordinating Council. His "Ring of Security" concept emphasizes that cybersecurity is an organizational problem that uses technology as just one tool in the solution.


    Resources Mentioned

    • The "Ring of Security" concept
    • CIS Framework limitations
    • Business Impact Analysis
    • AI Readiness Assessment
    • Department of Homeland Security Sector Coordinating Council

    SecureTalk is hosted by Justin Beals, focusing on cybersecurity strategy, governance, and best practices for organizations of all sizes.


    47 min
  • From Burning Servers to Enterprise Resilience: The Evolution of Internet Security With Akamai


    In this eye-opening episode of SecureTalk, host Justin Beals welcomes Joe Gronemeyer, Solutions Engineer at Akamai Technologies, for a masterclass in how internet security has evolved from basic content delivery to sophisticated edge protection powering 30% of global web traffic. From stories of literally burning servers in 1999 to today's quantum-resistant cryptography, this conversation tracks the incredible journey of cybersecurity infrastructure.


    ### Key Highlights:

    - **The Birth of Edge Networks**: How Akamai transformed from emergency content delivery savior to cybersecurity powerhouse

    - **Massive Security Scale**: Processing 26 billion web attacks monthly and analyzing 7 trillion DNS queries daily


    - **Zero Trust Evolution**: Why identity-aware proxies are replacing traditional VPNs for enterprise security

    - **Micro-segmentation Explained**: Creating "mini-firewalls" at every endpoint to contain breaches and limit attack radius

    - **Bot Attack Revolution**: The evolution from simple DDoS to sophisticated credential abuse and account takeover attempts

    - **API Security Challenges**: Why APIs have become the new security frontier as other defenses improve


    - **Client-Side Security**: How PCI DSS v4 is forcing new approaches to JavaScript security monitoring


    - **Quantum-Resistant Future**: Akamai's implementation of NIST-approved quantum-resistant cryptography



    ### Notable Quotes:

    "If you had our auto rules applied during the Log4J incident, you wouldn't have had to take any action during Christmas - it would have been protecting you automatically." - Joe Gronemeyer


    "At some point I think it was in 2011-2012, is when we would start looking at the traffic coming in and protecting websites from attacks as well. So applying security at the edge, keeping the bad actors away from your servers." - Joe Gronemeyer


    ### About Our Guest:


    Joe Gronemeyer serves as a Solutions Engineer at Akamai Technologies with nearly a decade of experience. Previously, he spent 13 years at Accenture as a Senior Manager leading digital solutions for Fortune 500 companies across pharmaceuticals, consumer goods, and telecommunications industries. He holds a BS in Industrial and Systems Engineering from Georgia Tech and is CISSP certified.


    ### Resources Mentioned:

    - Web Application Firewall (WAF) technology


    - Zero Trust Network Access (ZTNA)

    - Enterprise Application Access


    - Client-Side Access and Compliance (formerly Page Integrity Manager)


    - OWASP Top 10 for web, API, and AI security

    - PCI DSS version 4 compliance requirements

    - NIST standards for quantum-resistant cryptography

    *Don't miss our next episode where we'll continue exploring cutting-edge cybersecurity approaches for enterprise organizations.*


    #EdgeSecurity #ZeroTrust #MicroSegmentation #APIProtection #WAF #PCICompliance #QuantumCryptography #CyberDefense


    46 min
  • "There's No Such Thing as Crypto Crime": Nick Furneaux on Blockchain Investigation, Digital Forensics, and the Future of Cryptocurrency


    In this eye-opening episode of SecureTalk, host Justin Beals sits down with Nick Furneaux, renowned cryptocurrency investigator and author of the provocatively titled book "There's No Such Thing as Crypto Crime." Furneaux shares his extensive expertise on blockchain technology, cryptocurrency investigations, and the evolving landscape of digital financial crimes.


    Key Topics Discussed:


    The meaning behind Furneaux's book title "There's No Such Thing as Crypto Crime" and why traditional investigation skills remain relevant

    • The fundamental differences between Bitcoin and newer cryptocurrencies like Ethereum and Solana
    • How blockchain technology actually helps investigators through its open ledger system
    • The mechanics behind "rug pulls" and other crypto-related scams
    • The role of mining in cryptocurrency ownership and value
    • How TRM Forensics tools help trace illicit cryptocurrency transactions
    • The concerning rise of human trafficking in crypto scam operations
    • How AI is transforming both criminal schemes and investigation techniques

    Notable Quotes:

    "There is no such thing as a crypto-only crime. There is no new criminal category. There is just a new payment mechanism." - Nick Furneaux


    "The Bitcoin source code is some of the most beautiful code ever written. It is extraordinary... and it's never been hacked." - Nick Furneaux


    "We're in a situation now where the victim is a victim, and the scammer is a victim." - Nick Furneaux on trafficking in scam compounds

    About Nick Furneaux:

    Nick Furneaux is a digital forensics expert, cryptocurrency investigator, and cybersecurity specialist. He has worked in digital forensics for many years and is known for his expertise in cryptocurrency investigations. He has served as a trainer and consultant for law enforcement agencies and private organizations on matters related to digital forensics and cryptocurrency tracing.


    He is the author of *There’s No Such Thing as Cryptocrime* (2024) and *Investigating Cryptocurrencies* (2018). He has trained thousands of investigators in the essential skills needed to track cryptocurrencies involved in criminal activities. Currently, he works as a Blockchain Intelligence Expert and Master Trainer at TRM Labs and serves as an advisor to the Board of Asset Reality.

    Resources Mentioned:


    Book: "There's No Such Thing as Crypto Crime" by Nick Furneaux (link)

    Book: "Investigating Cryptocurrencies" by Nick Furneaux (link)

    TRM Forensics Investigative Toolkit

    This episode provides invaluable insights for cybersecurity professionals, financial investigators, and anyone interested in understanding cryptocurrency's role in modern digital crime investigations.


    SecureTalk is hosted by Justin Beals, bringing you expert conversations with the leading minds in cybersecurity.


    #Cryptocurrency #BlockchainForensics #CryptoInvestigation #Cybersecurity #DigitalForensics #Bitcoin #Ethereum #CryptoScams #FinancialCrime


    49 min
  • Hijacking AI Memory: Inside Johann Rehberger's ChatGPT Security Breakthrough


    In this eye-opening episode of SecureTalk, host Justin Beals interviews Johann Rehberger, a seasoned cybersecurity expert and Red Team Director at Electronic Arts, about his groundbreaking discovery of a critical vulnerability in ChatGPT's memory system. 


    Johann shares how his security background and curiosity about AI led him to uncover the "SPAIWARE" attack - a persistent malicious instruction that can be injected into ChatGPT's long-term memory, potentially leading to data exfiltration and other security risks.

    Key Topics Covered

    • Johann's journey from Microsoft development consultant to becoming a leading red team expert specializing in AI security
    • The discovery of ChatGPT's memory system vulnerability and how it could be exploited
    • How traditional security concepts like the CIA security triad (Confidentiality, Integrity, Availability) apply to AI systems
    • The development of "SPAIWARE" - a persistent prompt injection attack that can leak user data
    • Command and control infrastructure using prompt injection techniques
    • The challenges of securing agentic AI systems that can control web browsers and execute tasks
    • The evolving relationship between security researchers and AI companies like OpenAI


    Notable Quotes

    "I think using this system is just so important because it can help you. They are so powerful. I started using it daily. But the security mindset of course too, because I use it for my productivity, but I always use it for trying to find the flaws and trying to understand how it works." - Johann Rehberger


    "What I did basically was use that technique and then insert that instruction in memory. So that whenever there's a conversation turn, the user has a question, ChatGPT responds. Every single conversation turn will be sent to the third-party server. So this is where the word spyware basically kind of came from." - Johann Rehberger


    "The better the models become, the better they follow instructions, including attacker instructions." - Johann Rehberger


    About Johann Rehberger

    Johann Rehberger is the Red Team Director at Electronic Arts with extensive experience in cybersecurity. His career includes roles at Microsoft, where he led the Red Team for Azure Data, and Uber, where he served as Red Team Lead. Johann is known for his pioneering work in AI security, specifically identifying and responsibly disclosing vulnerabilities in large language models like ChatGPT.


    Resources Mentioned

    • Johann's blog on machine learning security (https://embracethered.com/blog/index.html)
    • Black Hat Europe presentation on ChatGPT security vulnerabilities
    • LLM Owasp Top 10 vulnerability classifications

    Connect With Us

    Follow SecureTalk for more insights on cybersecurity trends and emerging threats. Visit our website at www.securetalkpodcast.com  for more episodes and resources.


    #AISecurityRisks #PromptInjection #ChatGPT #Cybersecurity #AIVulnerabilities #RedTeaming #SecureTalk


    47 min
  • Predicting Data Breach Risk: How Mathematical Privacy Is Revolutionizing Data Sharing with Simson Garfinkel

    What if there was a way to precisely predict the risk of a major data breach when sharing information? 

    In this illuminating episode of Secure Talk, Justin Beals sits down with Simson Garfinkel, renowned computer scientist, journalist, and author who helped implement differential privacy for the U.S. Census Bureau's 2020 census. As a fellow of the American Association for the Advancement of Science, the Association for Computing Machinery, and the IEEE, and with leadership positions at both the Department of Homeland Security and U.S. Census Bureau, Garfinkel offers unparalleled insights into how mathematics is creating an entirely new frontier in privacy protection in his new book “Differential Privacy”.


    Differential privacy is a reliable mathematical framework that quantifies privacy risk or the potential for a major breach. It can transform how organizations understand, measure, and control data exposure. Yet most security, compliance, and legal professionals haven't grasped its revolutionary implications for measuring and predicting a major privacy breach.


    Join Justin and Simson as they reveal:


    - How differential privacy allows organizations to calculate privacy risk with mathematical precision

    - Why this new field of privacy research eliminates guesswork when combining and distributing sensitive data

    - The revolutionary balance between data utility and privacy protection that was previously impossible

    - How forward-thinking organizations are using these mathematical formula to unlock data value safely


    This isn't abstract theory – it's a practical revolution in how we approach data sharing. Garfinkel, who literally wrote the book on "Differential Privacy," shares real-world examples from his work with the U.S. Census Bureau, where differential privacy enabled the release of valuable population data while mathematically predicting individual privacy. In his book, Simson breaks down complex mathematical concepts into clear, actionable insights for security leaders, compliance officers, and legal counsel.


    Listen now to discover how differential privacy is creating a future where data-sharing decisions are based on mathematical certainty rather than best guesses and crossed fingers.


    Link to Simson's book: https://mitpress.mit.edu/9780262551656/differential-privacy/

    49 min
  • The Future of CMMC: Surviving the new Federal Security Landscape with Former NRMC Director Bob Kolasky

    How do you secure a nation? Hint: look for the risks to the most critical infrastructure.


    In this critical episode of SecureTalk, host Justin Beals sits down with Robert Kolasky, former founding director of the National Risk Management Center at DHS and current Senior VP for Critical Infrastructure at Exiger. As the new administration implements sweeping changes to federal security requirements, Kolasky provides an insider's perspective on what these shifts mean for contractors, the Defense Industrial Base, and organizations managing critical infrastructure.


    Drawing from his experience protecting everything from elections to the electrical grid, Kolasky offers rare insights into:


    • The future of the Cybersecurity Maturity Model Certification (CMMC) program
    • How companies can prepare for evolving compliance standards
    • The relationship between FedRAMP and other security frameworks
    • Emerging hybrid threats to national security
    • Supply chain vulnerabilities and third-party risk management


    Whether you're a federal contractor navigating new requirements or a security professional concerned about critical infrastructure protection, this conversation provides essential guidance during a time of unprecedented change in the national security landscape.

    47 min
  • Redefining Personhood: The Legal and Ethical Challenges of an Advanced General Intelligence with James Boyle


    In a groundbreaking conversation on SecureTalk, legal scholar James Boyle explores the complex landscape of artificial intelligence and biological innovation, challenging our understanding of personhood and consciousness. Drawing from his recent book “The Line: Artificial Intelligence and the Future of Personhood”, Boyle dissects the potential future of artificial general intelligence and biological engineering through the lens of legal and ethical frameworks. We shine a light on how our current technological advancements are forcing us to reexamine fundamental questions about what constitutes a "person" – a journey that parallels historical shifts like human rights and the evolution of corporate personhood.


    Boyle also delves into the equally provocative realm of biological engineering, where technologies like CRISPR are blurring the lines between species and challenging our ethical boundaries. He warns that we're entering an era where genetic modifications could fundamentally alter human capabilities, raising critical questions about ownership, consent, and the rights of an invention. For cybersecurity professionals, AI researchers and corporate leaders, Boyle's legal insights offer a crucial roadmap for navigating the complex ethical terrain of emerging technologies, emphasizing the importance of proactive, critical thinking in shaping our technological future.

    You can find the book here: https://scholarship.law.duke.edu/faculty_books/9/

    49 min
  • How Do You Get 10,000 Developers To Write Secure Code? With Dimitry Shvartsman

    If you've ever found yourself frustrated watching deadlines slip by as your development team waits on yet another security review, you're not alone. In today's competitive landscape, companies are caught in a difficult balancing act: move quickly to deliver the features customers want or slow down to ensure those features don't introduce vulnerabilities that could lead to the next headline-making breach.


    Security reviews have become the speed bump on the road to innovation that everyone acknowledges is necessary, but few have figured out how to navigate efficiently. Development teams push for velocity while security teams pull the emergency brake, creating tension that reverberates throughout organizations.


    Today, we're joined by Dimitri Shvartsman, co-founder of Prime Security and prior Head of Cybersecurity at PayPal, to discuss how enterprise organizations are innovating security solutions to reduce the time to feature delivery. We'll explore how AI tools can actually enable rather than impede innovation and examine practical approaches to integrating AI security tools earlier in the development lifecycle.


    Whether you're a CISO trying to balance security with business needs, a developer tired of security roadblocks, or a product leader navigating these competing priorities, this conversation will give you actionable insights to transform security from a bottleneck into a business enabler.


    45 min

About Secure Talk Podcast

From the publisher's feed

Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance.

More shows like Secure Talk Podcast

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners