The Gate 15 Podcast Channel

The Gate 15 Podcast Channel

By Gate 15Business
Download on the App Store

The Gate 15 Podcast Channel episodes

  • Weekly Security Sprint EP 176. Marching toward election day with hostile events and MDM

    On this week's Security Sprint, Dave and Andy covered the following topics:


    Opening:

    • We’re making some changes to the SUN video edition and will briefly pause video delivery. We look forward to returning soon with a new and improved format highlighting the SUN’s top stories in a way that’s easy to share with your team!

    • The Value of InfraGard: A Board Member’s Perspective — Gate 15 — 30 Sep 2026

    • (TLP:CLEAR) WaterISAC Partners with Cyware to Strengthen Threat Intelligence Sharing for the Water Sector

    • Insider Threats in the Water Sector: A Growing and Underestimated Risk — Sam Houston State University Institute for Homeland Security — Sep 2026. Gate 15’s Alec Davison and David Pounder developed a new report examining insider threats as a growing and often underestimated risk to the water and wastewater sector, emphasizing that the threat extends beyond malicious employees to negligent users, contractors, vendors, and other trusted individuals with authorized access.

    • (TLP:CLEAR) WaterISAC’s Quarterly Water Sector Incident Summary, April to June 2026 – Executive Summary

    • Securing Water and Wastewater Operational Technology Environments — NIST — 01 Oct 2026


    Main Topics:


    Hate, Extremism & Terrorism: Three Arrested in Mobile for Alleged Threats Against the President — FBI — 02 Oct 2026. The FBI’s Mobile Division, working with the U.S. Secret Service and multiple federal, state, local, and university partners, arrested three individuals for allegedly making threatening communications directed toward the president of the United States.

    • Georgia man arrested for alleged threat to kill Hegseth, family if Pentagon chief didn’t kill Chabad Jews

    • Man arrested, accused in plot to attack Texas Capitol building, DPS says

    • Places of Worship are Increasingly Being Targeted by Far-Right Extremists

    • Iran hackers offer bounty for Americans: $15K if alive, $2.5K if dead

    • Two men charged with suspected terror plot targeting Jewish Community in Manchester

    • The 10 Priorities Every Church Security Team Should Have, and every security team should consider!

    • Full Senate Passes Measure to Reauthorize Federal Terrorism Insurance Backstop


    Russia! Hijacking Trusted Media Brands: Russia’s Favorite Disinformation Tactic Against the West Surged by 850 Percent in the Last Year — NewsGuard — Sep 2026. NewsGuard reports that Russian influence operations increasingly impersonate legitimate news organizations to lend credibility to fabricated stories, videos, websites, and social-media content.


    Quick Hits:

    • Measles! Flu! COVID! Ebola!

    • Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway — CISA

    • Disruptive cyber attacks – reducing their impact, reducing the risk — National Cyber Security Centre

    • 2026 Digital Defense Report — Microsoft

    • Threat Spotlight: What’s Trending? Top Cyber Attacker Techniques: June 2026–August 2026 — ReliaQuest

    21 min
  • Nerd Out EP 74. National Preparedness Month and the human behavior

    On the latest episode of Nerd Out, Dave and Alec are joined by Joe Levy (most favorite guest status) and Sharon Dye to talk about National Preparedness Month. Focusing on the human behavior, the discussion focuses on common pitfalls of where preparedness activities fail and ways that organizations can address that.


    Joe and Sharon founded The HX3 Advisory Group™

    Find out more at: thehxadvisorygroup.com

    44 min
  • Weekly Security Sprint EP 175. Anniversaries, School Shooting Analysis, and AI guardrails

    On this week's Security Sprint Dave and Andy covered the following topics:


    Opening:

    • 15 x 15 GRIP Alerts!!

    • 27th Annual TribalNet Conference & Tradeshow

    • Tribal-ISAC

    • CISA: 2026 Election Infrastructure Security Plan


    Main Topics:


    Terrorism and Targeted Violence (T2V) in the United States: Plots Targeting U.S. Schools — START — Sep 2026. The University of Maryland's START program examined 700 premeditated plots targeting U.S. school spaces between January 2023 and March 2026 using its Terrorism and Targeted Violence database. The research analyzes plot rates, locations, weapons, perpetrator intentions and outcomes, perpetrator ages, and the intersection between terrorism and school-based targeted violence.


    OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later — WIRED — 24 Sep 2026. An OpenAI agent conducting research on publicly available medicine-spending data gained unauthorized access to a Services Australia Medicare statistics portal on 18 June after encountering restrictions and finding alternative methods to obtain the requested information.

    • Scoop: Top AI companies probing tens of thousands of security incidents — Axios

    • The Hugging Face incident and other third-party impact from misaligned models — OpenAI

    • OpenAI pauses training on some models, says agents targeted government sites

    • OpenAI agents tried to bruteforce a UN website's API fields

    • OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

    • It was a matter of when, not if... — DIVD — 24 Sep 2026. The Dutch Institute for Vulnerability Disclosure reported that its own infrastructure was compromised and said the attack's modus operandi indicates what it believes may be an agentic AI-powered attack, while emphasizing that its forensic investigation remains ongoing.

    • Cyber Threat Report 2026: Leaders need to prepare now for the impact of AI — New Zealand National Cyber Security Centre — Sep 2026

    • Protect your organisation’s AI services — Australian Signals Directorate — Sep 2026.


    Quick Hits:

    • ENISA Threat Landscape 2026 — European Union Agency for Cybersecurity — 22 Sep 2026. ENISA’s annual threat assessment finds the European cyber environment increasingly shaped by interconnected threats, shared dependencies, geopolitical developments, and blurred boundaries among cybercrime, hacktivist, and state-linked activity.

    • ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate comment from FBI

    • FBI Statement on Compromise of fbijobs.gov Portal and Alleged Impact to FBI Employee PII

    • Military personnel data exposed in breach, agency warns

    • Gary Warner on LinkedIn: DMDC breach notification raises questions about notification timing and QR-code delivery

    • Special agents' blood and urine test results stolen in FBI hack

    • Russia! US-Based Digital Forensics Firm Hid its Russian Ownership from U.S. Government Customers

    • Russia! ‘United by chaos:’ Examining the Russian nexus to online networks of nihilistic violence

    • No Kings: Vote Early nationwide day of action planned for 17 October



    19 min
  • Weekly Security Sprint EP 174. Texas travel, weather, Russian interference, and more.

    On this week's Security Sprint, Dave and Andy covered the following topics:

    Opening:

    • CISA Hosts Cyber Storm X, Nationwide Cybersecurity Exercise to Strengthen Resilience — CISA — 18 Sep 2026.

    • New ASD Guidance: Network Segmentation & Segregation

    • UK NCSC: Don’t Assume Your Cyber Defenses Work. Test Them.

    • 27th Annual TribalNet Conference & Tradeshow


    Main Topics:


    Severe Weather’s Cascading Effects: Brutal heat, storms threaten football tailgates this weekend; This weekend's football tailgates face two threats: Extreme heat in the Southeast and rounds of rain and storms.

    • NWS: Thunderstorms and Heavy Rains in the Appalachians. Multiple rounds of moderate to locally heavy rain will impact portions of the Appalachians and Mid-Atlantic, which may lead to flash flooding concerns.

    • Rare September nor’easter could bring rain, wind and waves to East Coast


    Russia! Russia Fabricates Celebrity Attacks on Democrats as Midterms Approach — NewsGuard Reality Check — 18 Sep 2026. NewsGuard reports that a Russian influence campaign targeting the 2026 U.S. midterm elections is using manipulated celebrity content and fabricated news reports to attack Democratic candidates and amplify divisive social issues.

    • 'The rules have changed': has Russia begun to order assassinations on US soil?

    • Russia Escalates its External Operations Against the United States — The Soufan Center — 18 Sep 2026.

    • Russian hybrid attacks against Europe intensifying, says Macron

    • European Parliament adopts new report on foreign information manipulation and interference Russia Boosts the German Far Right — Again

    • Russia? Suspected sabotage causes major Netherlands rail disruption

    • Russia? Train derailment in France injures 44, police suspect sabotage


    North Korean "WaterPlum," commonly referred to as “Contagious Interview,” cyber actor group targeting IT professionals — Australian Signals Directorate’s Australian Cyber Security Centre — 18 Sep 2026. A multinational advisory warns that North Korean WaterPlum actors are targeting software developers and other IT professionals through fraudulent recruitment, technical interviews, and coding assignments designed to deliver malware and steal credentials, sensitive information, and cryptocurrency.

    • 98% of fraudulent hires have company credentials by the time they’re caught


    Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes — FBI Internet Crime Complaint Center — 17 Sep 2026. The FBI reiterated its warning about widespread scams in which criminals impersonate U.S. or foreign law enforcement and government officials to obtain money or personally identifiable information.


    Quick Hits:

    • Using Cyber Decoys to Strengthen Detection and Response — CISA — 16 Sep 2026. CISA released guidance to help organizations plan and implement cyber decoys to improve detection of adversaries using legitimate credentials, native tools, and living-off-the-land techniques.

    • Network segmentation and segregation – Overview — Australian Signals Directorate — 17 Sep 2026. 15 from 15 connection:

    • Network segmentation and segregation – Anti-patterns — Australian Signals Directorate — 17 Sep 2026.

    • Best practices for setting up a SOC (ITSAP.00.500) — Canadian Centre for Cyber Security — Sep 2026.

    • Cyber Adversary Simulation (CyAS): scheme documents now available — UK National Cyber Security Centre — 17 Sep 2026.



    20 min
  • Weekly Security Sprint EP 173. Information sharing, strategies, and AI

    On this week's Security Sprint, Dave and Andy covered the following topics:


    Opening:

    • 15 from 15: Blocking and Tackling Cybersecurity & Resilience — Gate 15 — 09 Sep 2026. Gate 15 released 15 from 15: Cybersecurity Mitigation & Resilience Fundamentals, emphasizing that rapidly evolving threats, artificial intelligence, ransomware, exploited vulnerabilities and nation-state activity do not eliminate the importance of consistently executing foundational security practices. The framework identifies 15 practical areas to help organizations “get a little better every day.”

    • What the FBI Phishing Warning Means for Event Planners — Skift Meetings — 08 Sep 2026. Gate 15 Vice President and Chief Resilience Officer Ben Taylor contributes perspective.

    • (TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin – Q3 2026 — WaterISAC — 10 Sep 2026

    • Cyberattacks on food and agriculture can turn disruptions into safety crises, threatening public health and supply chains — Industrial Cyber — 08 Sep 2026

    • 27th Annual TribalNet Conference & Tradeshow


    Main Topics:

    • FBI cyber chief worries private sector not sharing enough cyber threat information — CyberScoop — 09 Sep 2026. FBI Cyber Division Assistant Director Brett Leatherman said private-sector organizations are still not sharing enough cyber information with the Bureau, in part because some companies incorrectly believe information provided during an incident will be passed to regulators for regulatory purposes.
    • FBI Cyber Strategy — FBI — 09 Sep 2026. The FBI released its first agency-wide unclassified cyber strategy, organizing its approach around disrupting and imposing costs on adversaries, supporting victims, increasing impact through partnerships and strengthening internal cyber capabilities.
    • China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — CISA — 08 Sep 2026. CISA, NSA and the FBI warn that China-based AI companies are conducting industrial-scale campaigns to systematically extract proprietary capabilities from U.S. frontier AI models, describing malicious knowledge distillation as a core component rather than merely a supplement to their AI development strategies.
    • Insider Threat Mitigation Guide — CISA — 09 Sep 2026. During National Insider Threat Awareness Month, CISA is again highlighting its Insider Threat Mitigation Guide and related resources for organizations building or improving insider-risk programs.


    Quick Hits:

    • Congratulations! You Just Lived Through the Hottest Month Ever Recorded — WIRED — 10 Sep 2026.

    • NSA Highlights Cyber Hygiene Best Practices Effective Against AI-Enhanced Targeting — National Security Agency — 03 Sep 2026

    • Gateway security guidance package: Overview — Australian Signals Directorate’s Australian Cyber Security Centre — updated 04 Sep 2026

    • The hidden risks of shadow AI — UK National Cyber Security Centre — 07 Sep 2026

    • Iran hackers: Dissatisfaction with AT&T services drove decision to target telecom in Texas

    • Iran hackers, after denial of Texas AT&T claim: ‘Idiots don’t even know what we tampered with’

    • Iran hackers claim Texas AT&T outage, vow to ‘intensify’ attacks before 9/11




    24 min
  • The Gate 15 Interview EP 74: Adam Gruszcynski on tribes, ISACs, cybersecurity, celebrating people and bailing out The Rock!

    In this episode of The Gate 15 Interview, Andy Jabbour speaks with Adam Gruszcynski. Responsible for the day-to-day operations of the IT Department for Potawatomi Casino Hotel while ensuring all of the technology needs, whether current orfuture, of the organization are met. Adam joined Potawatomi Casino Hotel in 2008. During his time at PCH, Adam has gained an abundance of experience by taking on various roles including IT Security Manager, Senior Cybersecurity Engineer, Lead Network Administrator, Network Administrator, and ApplicationAdministrator. Prior to PCH, Adam was Network Engineer at the Milwaukee Journal Sentinel where he began his career as Help Desk Intern. 

    • In the podcast, Adam and Andy discuss:
    • Adam’s background and his path to his current role
    • Tribal infrastructure and sovereignty
    • Managing and mitigating risks, investing in people
    • Resilience
    • Tribal-ISAC and some of the great things ISACs do!Celebrating people, building teams
    • Adam’s advice
    • We play Three Questions and go deep on pro wrestling!


    34 min
  • Weekly Security Sprint EP 172. Alphabet soup month, cyber protections, leadership engagement and more!

    On this week's Security Sprint, Dave and Andy covered the following topics:


    Opening:

    • Celebrating 5 Years of the Tribal-ISAC: Mid-Year Executive Director Update — TribalHub

    • FB-ISAO Newsletter, v8, Issue 8 — Faith-Based ISAO

    • AI/Vishing: The Voice Is Not the Control — Crypto ISAC

    • National Insider Threat Awareness Month: Protect Our Potential


    Main Topics:


    Iran hackers: Minnesota ‘warning’ ignored, ‘critical events’ to hit 3 U.S. infrastructure sectors — Threat Beat — 31 Aug 2026. APT IRAN, which has claimed responsibility alongside CyberAv3ngers for recent attacks affecting U.S. municipal water systems, issued a new threat against multiple U.S. critical infrastructure sectors as military tensions with Iran continue. The group characterized its earlier Minnesota activity as a warning and has previously claimed the ability to affect electricity, telecommunications, and water infrastructure, although adversary claims regarding access and capabilities should not be accepted without independent verification.


    A Tale of Two SOCs: Insights From Two Red Team Assessments — CISA — 25 Aug 2026. CISA released findings from simultaneous red-team assessments of organizations in the Government Services and Facilities Sector and the Water and Wastewater Systems Sector. Both organizations experienced successful initial compromise, but the government organization failed to detect or effectively contain subsequent activity while water-sector defenders quickly identified compromised systems and isolated them. CISA attributed the differing outcomes in part to alert noise, organizational silos, cloud-security weaknesses, and differences in how defenders were empowered to respond.


    Institutional Wilful Blindness, NCSC Cyber Series — NCSC Cyber Series — 2026. The first installment of a two-part discussion examines why organizations can understand that cyber risks exist yet still fail to take meaningful action before incidents occur. Leadership expert Margaret Heffernan, Professor Genevieve Liveley of the Research Institute for Sociotechnical Cyber Security, and an NCSC social sciences leader discuss how organizational culture, leadership behavior, communication, and the narratives used to describe cybersecurity can create a gap between awareness and action. The discussion emphasizes that resilience depends on more than technical controls and requires leaders to challenge complacency, communicate uncertainty effectively, and create environments where uncomfortable risk information can influence decisions.


    Quick Hits:

    • Insights into Suspected DPRK Workers: Red Flags to Look Out For — Huntress

    • The Who and How of Ten Years of Russian Disinformation — NewsGuard


    21 min
  • Weekly Security Sprint EP 171. Cyber conflicts and critical infrastructure, new reports, and crime statistics

    On this week's Security Sprint, Dave and Andy covered the following topics:


    Opening:

    • Nerd Out EP 73: 5th Annual 2/3rd of the Year Awards with the Cybersecurity Evangelist

    • The Gate 15 Interview EP 73. The FBI’s Josh Obstfeld on Artificial Intelligence, Serving our Nation, and New York City!

    • Ice cream makers as ‘critical infrastructure’? EU’s new cybersecurity law suffers wobbly rollout

    • Healthcare finance trends for 2026: A mid-year update — Health-ISAC


    Main Topics


    Iran-linked hackers blamed for cyber-attack that shut down UK power plant — The Guardian — 23 Aug 2026. Hackers linked to Iran have been blamed for a cyberattack that temporarily shut down a small-scale power generator in the United Kingdom.

    • UK briefs energy chiefs after Iran-linked cyber attack reports

    • Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

    • "Not a single drop of oil" will be exported if US "economic" war continues: Iran's security chief

    • Defending Against an Active Threat to Siemens S7 Series PLCs — CISA


    Cyber Threats in Times of Conflict — Emsisoft — 17 Aug 2026. Emsisoft assesses that events in Ukraine, Venezuela, and the continuing Iran conflict demonstrate that cyber operations have become a routine component of modern conflict, but cautions against assuming every disruption represents a sophisticated state cyberattack or that cyber operations will replace conventional warfare.


    What if America Went Completely Dark? — The New York Times Magazine — 18 Aug 2026. The New York Times examines the potential consequences of a prolonged nationwide electric-grid failure and emphasizes how quickly an electricity crisis would cascade into communications, water and wastewater, fuel distribution, healthcare, transportation, food supply, finance, public safety, and other essential services.


    Quarterly Threat Report: Second Quarter, 2026 — Beazley Security — 18 Aug 2026. Beazley Security reports that vulnerability disclosures increased dramatically during the second quarter as agentic AI accelerated vulnerability research, yet confirmed exploitation grew at a substantially slower rate and the fundamental paths attackers used to enter organizations changed very little.


    CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomware.


    FBI: 2025 had biggest violent-crime drop in 90 years — Axios — 18 Aug 2026. FBI data shows that U.S. violent crime fell sharply in 2025, producing the largest annual decline since the bureau began publishing national estimates in 1936.


    Severe Weather: And Get Ready for Winter Weather!

    • At least six injured in Reno, Nevada, wildfire as 42,000 forced to evacuate

    • California’s coast under siege: A winter of flooding, big waves and erosion in the forecast

    • ‘Heat Dome’ to Bring Dangerous and Prolonged Heat Wave to Southern States


    Quick Hits:

    • Beware the Ransomware Rescuer: Ransom Busters — GuidePoint Security — 18 Aug 2026. GuidePoint Security reports that an entity calling itself Ransom Busters has contacted ransomware victims before incidents became publicly known and offered to recover data or delete stolen information for a fee.

    • NoName057(16) targets German government officials in “Tribunal project” — Real Hack History — 23 Aug 2026.

    • Protect yourself: Multi-factor authentication — Australian Signals Directorate’s Australian Cyber Security Centre

    • Logging Reference Architecture — CISA

    • Tip of the Week – August 20, 2026 — WaterISAC — 20 Aug 2026. WaterISAC urged water utilities to periodically review network segmentation between operational technology and business information technology environments.

    • Managing the cyber risk of agentic AI — UK National Cyber Security Centre

    • AI is changing the economics of vulnerability discovery. Defenders should adapt now — CERT-EU


    23 min
  • The Gate 15 Interview EP 73: The FBI’s Josh Obstfeld on Artificial Intelligence, Serving our Nation, and New York City!

    In this episode of The Gate 15 Interview, Andy Jabbour speaks with Joshua Obstfeld, FBI Counterintelligence Senior Executive for External Engagement. Joshua Obstfeld joined the FBI in 2005 and currently serves as the FBI Counterintelligence Senior Executive for External Engagement, with a focus on congressional and executive branch engagement to highlight strategic threats, FBI action, and potential policy responses. Josh has served separately as Senior National Intelligence Officer for both China and for Emerging and Disruptive Technologies, and from 2021-2024, he led the FBI Newark Division’s Intelligence Branch where he was responsible for analysis of all threats in the State of New Jersey. Josh holds an MA in International Relations from the Johns Hopkins University School of Advanced International Studies, and a BA from Johns Hopkins University.

    • Josh on LinkedIn


    In the podcast, Josh and Andy discuss:

    • AI, threats and opportunities

    • AI and cybercrime: from ransomware to insider threats, and the importance of the human element

    • AI Swarms

    • The Threats and Opportunities of Tomorrow

    • The race for AI dominance

    • Private Public Partnership

    • Josh’s call to action

    • We play Three Questions! and discuss New York’s finest food and sports, alternate careers, and some of the 80s and 90s greatest hits!

    • And more!!


    Relevant links to this podcast:

    • FBI

    • FBI Counterintelligence and Espionage Division

    • FBI Internet Crime Complaint Center

    • INTERPOL report finds AI linked to more than half of cybercrime in Africa, 03 Aug 2026

    • METR & the Frontier Risk Report (February to March 2026)

    • INTERPOL’s African Cyberthreat Assessment Report 2026 (PDF)

    • WIRED: AI-Powered Disinformation Swarms Are Coming for Democracy, 22 Jan 2026

    • SecurityWeek: Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms, 30 Jul 2206

    • Beazley Security: Quarterly Threat Report: Second Quarter, 2026, 18 Aug 2026


    50 min
  • Nerd Out EP 73: 5th Annual 2/3rd of the Year Awards with the Cybersecurity Evangelist

    On the latest episode of Nerd Out, Dave and Alec welcome in special guest Jennifer Lyn Walker, the Cybersecurity Evangelist, to go through the 2/3rd of the year awards. We review nominations for each award and discuss each.


    Awards:

    • MVP
    • The Cobra (Sly Stallone) Award - you are the disease and I’m the cure - what has been a great security process or procedure that can really help orgs.
    • The Dennis Green (Former Viking Coach - they are who we thought they are award. What is a threat or tactic that threats use that really showed their true colors.
    • The Aldus Snow (Infant Sorrow) - don’t forget about me. What is the security threat that remains always present.
    • Dumpster Fire award - what incident or threat will just make things a mess.
    • Scotty Doesn’t Know award (EuroTrip) - what threat is out there that orgs aren’t thinking about but should.
    • Avengers Team Up award - is there a great product or paper that involved multiple groups that orgs should know about.
    • Heath Ledger Joker award - what threat just takes it to another level - when you think last time was bad, the next time is worse.


    Some references made during the call include:

    • Cyber Readiness Institute https://cyberreadinessinstitute.org/
    • UnDisruptable27 https://securityandtechnology.org/undisruptable27/
    • National Council of ISACs https://www.nationalisacs.org/
    • Idaho National Laboratory | Cyber Informed Engineering https://inl.gov/national-security/cie/


    55 min

About The Gate 15 Podcast Channel

From the publisher's feed

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.