The Adversarial Podcast

The Adversarial Podcast

By Jerry Perullo, Sounil Yu, Mario DuarteBusinessTechnology
Download on the App Store

The Adversarial Podcast episodes

  • The Adversarial Podcast Ep. 4 - CrowdStrike Lawsuits, Overhyped Exploits, and Fake Remote Employees

    Join former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu as they discuss upcoming lawsuits related to the recent CrowdStrike outage, switching costs, overhyped security vulnerabilities and their effect on practitioners' responsibilities, fake employees from North Korea, the information stealers and the state of password managers, and the increasing threat of deepfakes.

    Stories

    • “CrowdStrike is sued by shareholders over huge software outage” - https://www.reuters.com/legal/crowdstrike-is-sued-by-shareholders-over-huge-software-outage-2024-07-31/
    • “Delta CEO says CrowdStrike-Microsoft outage cost the airline $500 million” - https://www.cnbc.com/2024/07/31/delta-ceo-crowdstrike-microsoft-outage-cost-the-airline-500-million.html
    • “Microsoft And AWS Outages: A Wake-Up Call For Cloud Dependency“ - https://www.forbes.com/sites/emilsayegh/2024/07/31/microsoft-and-aws-outages-a-wake-up-call-for-cloud-dependency/
    • “Microsoft confirms Azure, 365 outage linked to DDoS attack” - https://www.cybersecuritydive.com/news/microsoft-azure-365-outage-ddos/722920/
    • “Millions of Devices Vulnerable to 'PKFail' Secure Boot Bypass Issue” - https://www.darkreading.com/endpoint-security/millions-of-devices-vulnerable-to-pkfail-secure-boot-bypass-issue
    • “Who Knew? Domain Hijacking Is So Easy” - https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/
    • “Security Firm Alarmed to Discover Their Remote Employee Is a North Korean Hacker” - https://futurism.com/the-byte/security-firm-remote-employee-north-korean-hacker
    • “The Evolution and Rise of Stealer Malware” (Josh Lefowitz/Flashpoint) https://www.linkedin.com/posts/activity-7209733860715098114-ZgYQ / https://flashpoint.io/blog/evolution-stealer-malware/
    • ‘I Need to Identify You': How One Question Saved Ferrari From a Deepfake Scam - https://www.bloomberg.com/news/articles/2024-07-26/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo
    • “AI-Powered Deepfake Tools Becoming More Accessible Than Ever” - https://www.trendmicro.com/en_us/research/24/g/ai-deepfake-cybercrime.html
    1 hr 27 min
  • The Adversarial Podcast Ep. 3 - CrowdStrike, Wiz Acquisition Rumors, and SolarWinds

    In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss the recent Crowdstrike outages, PR in the recent Wiz acquisition rumors, stakeholder value in Rapid7, and the SEC dropping charges in the SolarWinds case.

    Stories:

    - Activist Jana has a stake in Rapid7. There are two paths to bolster value at the cybersecurity company: https://www.cnbc.com/2024/06/29/two-paths-for-jana-to-bolster-shareholder-value-at-rapid7.html

    - Google Near $23 Billion Deal for Cybersecurity Startup Wiz: https://www.wsj.com/business/deals/google-near-23-billion-deal-for-cybersecurity-startup-wiz-622edf1a

    - Most SEC charges dismissed in SolarWinds hack case: https://www.axios.com/2024/07/18/sec-solarwinds-cyberattack-case-dismissal

    Hosts:

    Jerry Perullo: https://www.linkedin.com/in/perullo/

    Mario Duarte: https://www.linkedin.com/in/mario-duarte-7855237/

    Sounil Yu: https://www.linkedin.com/in/sounil/

    1 hr 16 min
  • The Adversarial Podcast Pilot – Cybersecurity Investments, Secure Configurations vs. Code, and Risk Management

    Join former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu as they reflect on the state of cybersecurity investments in 2024, debate the importance of configuration vs. code security, and discuss the importance of governance in risk management.

    Stories:

    • ‘There’s A Lot Of Noise’ — VCs Trying To Find Clarity In Cluttered Cyber AI Landscape: https://news.crunchbase.com/cybersecurity/venture-funding-ai-wiz-ma-rsa/
    • Wiz raises $1B at a $12B valuation to expand its cloud security platform through acquisitions: https://techcrunch.com/2024/05/07/wiz-raises-1b-at-12b-valuation-expanding-through-acquisitions/
    • CyberArk Signs Definitive Agreement to Acquire Machine Identity Management Leader Venafi from Thoma Bravo: https://www.cyberark.com/press/cyberark-signs-definitive-agreement-to-acquire-machine-identity-management-leader-venafi-from-thoma-bravo/
    • A review of zero-day in-the-wild exploits in 2023: https://blog.google/technology/safety-security/a-review-of-zero-day-in-the-wild-exploits-in-2023/

    Hosts:

    Jerry Perullo: https://www.linkedin.com/in/perullo/

    Mario Duarte: https://www.linkedin.com/in/mario-duarte-7855237/

    Sounil Yu: https://www.linkedin.com/in/sounil/

    49 min
  • The Adversarial Podcast Ep. 2 - Chrome Extension Vulns, Cyber Job Market, Mouse Jigglers, and the Ransomware Plague

    In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss malicious Chrome extensions, the cybersecurity job market, mouse jigglers and security policy, and the impact of the recent ransomware wave. They share insights from their experiences, exploring the challenges of managing browser security policies, job burnout, and banning ransom payments.

    Stories:

    • Millions under threat from malicious browser extensions — what to do: https://www.tomsguide.com/news/millions-under-threat-from-malicious-browser-extensions-what-to-do

    • Demand for better cybersecurity fuels a booming job market: https://www.washingtonpost.com/business/2024/06/21/cybersecurity-job-demand-boot-camps/

    • Wells Fargo Fires Over a Dozen for ‘Simulation of Keyboard Activity’: https://www.bloomberg.com/news/articles/2024-06-13/wells-fires-over-a-dozen-for-simulation-of-keyboard-activity

    • London hospitals cancel nearly 1,600 operations and appointments in one week due to hack: https://www.theguardian.com/technology/article/2024/jun/14/london-hospitals-cancelled-nearly-1600-operations-and-appointments-in-one-week-due-to-hack

    • Cyberattacks crippled thousands of car dealers. Here's what to know. https://www.washingtonpost.com/business/2024/06/21/car-dealers-cyberattack-cdk-global/

    • Ticketmaster hackers send death threats to cybercrime investigators: https://www.thetimes.com/uk/technology-uk/article/ticketmaster-hackers-death-threats-cybercrime-unc5537-msjgqw92w

    • CVE-2024-5806: Progress MOVEit Transfer Authentication Bypass Vulnerability: https://www.tenable.com/blog/cve-2024-5806-progress-moveit-transfer-authentication-bypass-vulnerability

    Hosts:

    Jerry Perullo: https://www.linkedin.com/in/perullo/

    Mario Duarte: https://www.linkedin.com/in/mario-duarte-7855237/

    Sounil Yu: https://www.linkedin.com/in/sounil/

    1 hr 3 min
  • The Adversarial Podcast Ep. 1 - Snowflake, Shared Fate, and the Gili Ra’anan Model

    In this episode, former CISOs-turned-founders Jerry Perullo, Mario Duarte, and Sounil Yu discuss the recent wave of cyber-attacks using Snowflake and the model of shared fate. They debate the effectiveness of banning ransom payments and explore the complexities of cybersecurity regulation, using recent events involving UnitedHealth and Jerry's former employer as case studies. The conversation also touches on the ethical dilemmas CISOs face when interacting with venture capital, highlighting personal experiences and the fine line between advisory roles and conflicts of interest.

    Stories:

    • UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion
    • SEC Charges Intercontinental Exchange and Nine Affiliates Including the New York Stock Exchange with Failing to Inform the Commission of a Cyber Intrusion: https://www.sec.gov/news/press-release/2024-63
    • Why cybercriminals are targeting small businesses: https://www.marketplace.org/2024/05/30/why-cybercriminals-are-targeting-small-businesses/
    • UnitedHealth leaders 'should be held responsible' for installing inexperienced CISO, senator says: https://therecord.media/unitedhealth-ciso-wyden-letter-sec-ftc
    • The Gili Ra’anan model: Questions emerging from Cyberstarts' remarkable success: https://www.calcalistech.com/ctechnews/article/b1a1jn00hc

    Hosts:

    Jerry Perullo: https://www.linkedin.com/in/perullo/

    Mario Duarte: https://www.linkedin.com/in/mario-duarte-7855237/

    Sounil Yu: https://www.linkedin.com/in/sounil/

    1 hr 13 min
  • Season 02 Episode 02 - The Interim CISO

    Joined by fellow Interim CISO veterans Yael Nagler of Yass Partners and Aurobindo Sundaram of RELX, host Jerry Perullo reflects on his experience as the Interim CISO of Silicon Valley Bank and explores the challenges of the role from hiring manager and candidate perspectives.

    Yael Nagler: https://www.linkedin.com/in/yaelnagler/

    Aurobindo Sundaram: https://www.linkedin.com/in/aurobindosundaram/

    57 min
  • Season 01 Episode 07 - Bug Bounties with guest Casey Ellis

    Bugcrowd founder Casey Ellis joins #lifeafterCISO to talk about bug bounty programs in the wake of the Joe Sullivan Uber trial. Whether you've been running bounty programs for years or just learned of them last week, this conversation will take you from basics straight into the most interesting and controversial bits.

    59 min
  • Season 01 Episode 06 - Retire Many Times with guest Sounil Yu

    Sounil Yu joins the #lifeafterCISO podcast and shares the idea of "retiring many times". Sounil is the renowned author of the Cyber Defense Matrix and lauded by the CISO community for his ability to step back and view problems in a new light. Host Jerry Perullo and Sounil go on to look at the Equifax breach from a new angle, talk about CISO accountability, and finally offer up their early thoughts on the Twitter whistleblower report.

    01:43 Returning to work as a CISO

    10:30 Do CISOs spend too much time on tech?

    11:38 CDM and the Equifax breach

    15:00 CISO accountability

    19:45 The Twitter whistleblower complaint

    Learn more about Sounil and his work at https://www.cyberdefensematrix.com/

    36 min
  • Season 01 Episode 05 - Deciding When It's Time to Go with guest Jason Chan

    An essential part of moving on from a long tech career is just figuring out when the time is right. Join host Jerry Perullo and retired Netflix CISO Jason Chan for a discussion about picking your time, "Identity Management" after retirement, and the Psychology of Happiness.

    Links to the material discussed by Jason Chan include:

    https://arthurbrooks.com/podcast_show/the-art-of-happiness-with-arthur-brooks/

    https://www.coursera.org/learn/the-science-of-well-being

    39 min

About The Adversarial Podcast

From the publisher's feed

Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the…

More shows like The Adversarial Podcast

Risky Business by Risky Business Media

Risky Business

375 Listeners