Unspoken Security

Unspoken Security

Download on the App Store

Unspoken Security episodes

  • How AI Is Rewriting the Rules of Offensive Security

    In this episode of Unspoken Security, host AJ Nash sits down with Snehal Antani, co-founder and CEO of Horizon3.ai and former first CTO of Joint Special Operations Command (JSOC), to dissect what AI is really doing to the economics of cyber attacks - and cyber defense. Snehal opens with a jaw-dropping data point: his team compromised a defense industrial base supplier and achieved full domain admin in 77 seconds. From there, the conversation moves into the surprising counter-strategy his team uncovered - that today's LLMs and agentic attackers are dramatically more gullible than human hackers, clicking on well-placed honey tokens up to 95% of the time.

    The two dig into why "train like you fight" - a principle Snehal absorbed at JSOC - is now essential for cyber teams, why compliance frameworks like CMMC are failing to produce real resilience, and why the future of cyber warfare is "AI versus AI with humans by exception." Snehal walks through Horizon3.ai's architectural bet on disposable models, persistent knowledge graphs, and constrained-action-space agents, and explains why the "haves and have-nots" of red teaming is finally being disrupted by autonomous pentesting that IT admins - not elite ethical hackers - can operate.

    The conversation closes with a candid look at the industry itself: the ChatGPT-driven sameness of vendor messaging, the Black Hat gimmick arms race, and Snehal's plea to return to technical authenticity. He ends with a deeply personal reflection on his late father - the electrical engineer who sabotaged toy robots so his six-year-old son would learn to troubleshoot them - and the weight of trying to pass that same gift on to his own kids.

    Send us Fan Mail

    Support the show

    54 min
  • How Do We Know What’s Real in the Age of AI?

    AJ Nash sat down with Shai Gabay, co-founder and CEO of Trustmi, to talk about financial fraud in the age of AI. Gabay opened with the size of the problem: global fraud losses hit $450 billion last year. He explained why business-to-business payment fraud keeps growing. Attackers do not invent new relationships. They study the ones a company already has, then step into an existing conversation between a business and its vendor. Most of that conversation happens over email, and most companies still rely on people, not systems, to catch when something is wrong.

    The two traced how far that exploitation has evolved. Generative AI has erased the old tells: bad grammar, wrong context, unfamiliar phrasing. Gabay described attackers who forge invoices, bank letters, and void checks in minutes, and a rising pattern where criminals open fully legitimate bank accounts, complete with real KYC verification, under a stolen supplier identity. He walked through a real case where an attacker built a lookalike domain, cloned a supplier's website, and updated the fake site to appear first in search results, all to defeat a callback verification procedure before it ever started.

    Nash and Gabay closed on the harder question: what happens when video and voice can be faked too. They discussed a $25 million loss out of Hong Kong, where an employee was pulled into a Zoom call with deepfaked company leadership and instructed to wire funds. Gabay argued that no single tool fixes this. Organizations need to connect fragmented controls into one process and, above all, give the person who actually approves a payment the standing to ask questions and slow down. Asked the show's closing question, Gabay admitted that even as a CEO, he still gets pulled into incident response himself, just to understand exactly how an attack worked.

    Send us Fan Mail

    Support the show

    43 min
  • Should We Be Afraid of Artificial Intelligence (AI)?

    In this episode of Unspoken Security, host AJ Nash sits down with Heath Mullins, Chief Evangelist at ExtraHop and former senior analyst at Forrester. The two dig into the question everyone in tech keeps circling back to right now: should we be afraid of AI?

    Mullins argues that today's AI is best understood as a recalcitrant four-year-old handed the keys to everything, powerful, unpredictable, and rewriting itself faster than anyone can fully audit. AJ and Heath trace that unpredictability through self-driving cars that can't tell a yawn from drunk driving, medical offices where AI now transcribes and recommends diagnoses, and the accountability gap that opens up when something goes wrong and nobody, the automaker, the AI vendor, or a third party, wants to own it.

    The conversation closes on Unspoken Security's signature question, and Heath shares something he's never said publicly before: his son was murdered in 2020, and the same AI tools that can recreate a voice or a likeness from old recordings and social media now make it possible to build an avatar of someone who's gone. Heath draws a hard line on where that technology should stop, and AJ and Heath talk through the psychology of grief, denial, and why loss makes that temptation so powerful.

    Send us Fan Mail

    Support the show

    51 min
  • Why Are We Trusting AI with Intelligence?

    In this episode of Unspoken Security, AJ Nash and Faith MacGregor tackle the private sector's sloppy relationship with the word "intelligence" — the gap between raw data, contextual information, and verified, actionable intelligence — and how vendors, circular reporting, and fragmented disciplines like "cyber threat intelligence" have eroded that discipline. From there they turn to AI, weighing real utility against real danger: hallucinations that persist even with vetted sources, analysts pulled toward premature conclusions under time pressure, and the EY finding that roughly 40% of AI-generated conclusions had to be recalled. Nash's sharpest line - if a human analyst behaved this way, you'd fire them - sets up a back half that's cautiously optimistic, pointing to Recorded Future's human-curated, AI-assisted model as a template, while widening the lens to AI in government targeting decisions and the quiet brain drain hollowing out the intelligence profession. 

    Send us Fan Mail

    Support the show

    52 min
  • Is All Social Engineering Malicious?

    Social engineering has a reputation problem. Most people hear the term and think phishing, scams, and threat actors. AJ Nash and guest Ashley Stryker push back on that framing in this episode of Unspoken Security. The conversation opens by defining social engineering on its own terms: the act of understanding how people work and using that knowledge to get them to take a specific action. The technique itself is neutral. What determines whether it crosses a line is motive and outcome.

    From there, the conversation moves into the mechanics. Urgency is one of the most effective social engineering tools threat actors use because time pressure cuts off critical thinking. Stryker argues that the real defense is not training people to recognize a specific type of phish. It is training them to pause before acting on anything that creates pressure around money or security. She also makes a pointed case against security awareness programs that raise awareness without giving employees something concrete to do. Information alone does not change behavior. Action does.

    The episode closes with the show's signature "unspoken" segment, where Stryker shares the full story behind why she goes by her last name. It turns out there are several reasons, including a divorce, an ex-husband with the same first name, and a deliberate operational security strategy she has used since entering the cybersecurity field.

    Send us Fan Mail

    Support the show

    1 hr 6 min
  • Stolen Credentials, Fake Hires, and the New Insider Threat

    In this episode of Unspoken Security, host AJ Nash sits down with Dan O'Day, Senior Consulting Director at Unit 42 by Palo Alto Networks. Dan shares key findings from the 2026 Global Incident Response Report, built from over 750 real-world cyber incidents, covering four major threat trends reshaping the security landscape.

    Dan breaks down how AI is compressing attack timelines at a dramatic rate. The fastest incidents now move from access to full impact in just 72 minutes, down from 285 minutes the year prior. Attackers are no longer breaking in. They are logging in, using stolen credentials, tokens, and API keys to move laterally and avoid detection. Identity is now the dominant attack surface, playing a material role in nearly 90% of Unit 42's investigations.

    The conversation closes on a note of cautious optimism. Dan argues that over 90% of breaches stem from preventable gaps, meaning security is solvable. He outlines three priorities for defenders: empowering the SOC to act at machine speed, treating identity as the new perimeter, and securing the entire software supply chain from the first line of code to cloud runtime.

    Download the Unit 42 Global Incident Response Report 2026 here: https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report?utm_source=linkedin&utm_medium=social&utm_campaign=na&utm_content=pa001134 

    Send us Fan Mail

    Support the show

    50 min
  • AI, Deepfakes, & the New Ransomware Playbook

    In this episode of Unspoken Security, host A.J. Nash sits down with Cynthia Kaiser, SVP at Halcyon’s Ransomware Research Center. They explore how ransomware grew from a niche crime into a business, and why security teams now face faster attacks, extortion, and a threat landscape that blurs crime and state activity.

    Cynthia traces the shift from early encryption schemes to double and triple extortion, then explains how professional crews use access brokers, deepfakes, and AI-assisted phishing to move in hours, not weeks. She also breaks down how Russian-speaking groups, Iranian actors, and state-linked operations use cybercrime for profit, cover, and pressure.


    She argues that defenders still need the basics: harden identity, patch fast, assume breach, and build response plans that include PR. Cynthia closes with a blunt point: ransomware and fraud are not side issues. They hit hospitals, businesses, and families every day in ways nation-state threats often do not.

    Send us Fan Mail

    Support the show

    39 min
  • The Multi-Billion Dollar Crime Nobody Talks About

    In this episode of Unspoken Security, host A.J. Nash sits down with Erin West, Founder at Operation Shamrock. They explore the “scamdemic” and the scams draining wealth at industrial scale. Erin explains why business email compromise, government impersonation, and romance scams work so well: they use fear, trust, urgency, and loneliness.

    She then breaks down pig butchering, a long con that starts with a stray text and grows into a fake relationship and a fake crypto investment. Victims think they are building love and wealth at the same time. Instead, scammers push them to empty savings, tap retirement accounts, and borrow more.

    Erin also exposes the system behind the fraud. Many scammers are trafficking victims forced to work inside compounds in Cambodia, Myanmar, and beyond. She argues this is both a financial crime and a human rights crisis, and she calls for stronger reporting, public awareness, and international pressure.

    Send us Fan Mail

    Support the show

    57 min
  • The Dangers of Performative Leadership in Tech

    In this episode of Unspoken Security, host AJ Nash sits down with Bob Fabien “BZ” Zinga, a cybersecurity executive and Naval Information Warfare Commander in the U.S. Navy Reserve. They explore how performative leadership shows up in security teams, and why values on a wall fail when pressure hits.

    BZ argues that optics without accountability kills trust. When leaders bend with politics or budgets, engaged employees go quiet. That silence hides risk. He shares how breaches often trace back to human choices, including a W-2 phishing scam that exposed employees’ data and changed his own life. He also pushes blameless postmortems and clear escalation paths.

    From there, the conversation moves to AI. BZ warns that teams can automate bias and outsource judgment. He calls for guardrails, regulation, and human oversight, especially in high-stakes decisions. He closes with a simple standard: speak up for fairness, even when silence would feel safer.

    Send us Fan Mail

    Support the show

    1 hr 7 min
  • The Future is Human

    In this episode of Unspoken Security, host AJ Nash sits down with Galya Westler, Co-Founder and CEO at HumanBeam. They explore how advances in AI, digital identity, and holographic technology are reshaping the way organizations interact with people—while raising tough questions about privacy, ownership, and trust.

    Galya shares how her work began in health technology, connecting patients to care during pandemics, and evolved into building secure, lifelike AI avatars for real-world use. She explains why protecting personal likeness and voice matters more than ever, especially as AI tools become more convincing and accessible. Galya stresses the need for consent, encryption, and clear boundaries to keep digital identities safe and organizations accountable.

    Together, AJ and Galya dig into the risks and rewards of merging human presence with AI. They discuss how thoughtful design and strong security practices can support experts instead of replacing them, and why education and authenticity are key as we build a future where technology and humanity work side by side.

    Send us Fan Mail

    Support the show

    1 hr 7 min

About Unspoken Security

From the publisher's feed

Unspoken Security is a raw and gritty podcast for security professionals who are looking to understand the most important issues related to making the world a safer place, including…