

Shared Security Podcast
Tom Eston, Scott Wright, Kevin Johnson
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Episodes
Mentioned books

Dec 15, 2025 • 19min
The Hidden Threat in Your Holiday Emails: Tracking Pixels and Privacy Concerns
Join us in the midst of the holiday shopping season as we discuss a growing privacy problem: tracking pixels embedded in marketing emails. According to Proton’s latest Spam Watch 2025 report, nearly 80% of promotional emails now contain trackers that report back your email activity. We discuss how these trackers work, why they become more aggressive during the holidays, the data being collected by marketers, and how you can protect yourself. We are joined by Scott Wright to explore Proton’s comprehensive study, identify the worst offenders in email tracking, and share tips on maintaining your online privacy. Tune in and stay informed about the invisible surveillance in your emails this holiday season!
** Links mentioned on the show **
Spam Watch 2025: The hidden trackers and inbox overload behind holiday marketing
https://proton.me/blog/spam-watch-2025
Inbox full of promo emails? 80% are tracking you, new report warns
https://www.zdnet.com/article/inbox-promo-emails-tracking-you-proton-mail-warns/
AnnonAddy
https://addy.io/
SimpleLogin
https://simplelogin.io/
Apple Hide My Email (required iCloud+ subscription)
https://support.apple.com/guide/iphone/create-and-manage-hide-my-email-addresses-iphcb02e76f7/ios
** Watch this episode on YouTube **
https://youtu.be/sSFvCkiTmNc
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post The Hidden Threat in Your Holiday Emails: Tracking Pixels and Privacy Concerns appeared first on Shared Security Podcast.

Dec 8, 2025 • 17min
Seeing Is Not Believing: How to Spot AI-Generated Video
In this episode we discuss the rising challenge of AI-generated videos, including deepfakes and synthetic clips that can deceive even a skeptical viewer. Once the gold standard of proof, video content is now increasingly manipulated through advanced AI tools like Sora 2 and Google’s Nano Banana, making it harder to separate reality from fiction. Tom and Scott discuss the differences between malicious deepfakes and poorly-made AI-generated content, identify key indicators that reveal a video might be AI-generated, and explain how these videos are used in social engineering attacks. Practical advice is offered on how to protect yourself and your organization from this emerging threat.
** Links mentioned on the show **
Is that an AI video? 6 telltale signs it’s a fake
https://www.zdnet.com/article/is-that-video-ai-6-tell-tale-signs-its-a-deepfake/
** Watch this episode on YouTube **
https://youtu.be/7Zq4Jxli3vQ
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Seeing Is Not Believing: How to Spot AI-Generated Video appeared first on Shared Security Podcast.

10 snips
Dec 1, 2025 • 31min
So You Want to Be a CISO? With vCISO and Security Justice Alum Chris Clymer
In this engaging discussion, Chris Clymer, an experienced fractional CISO and former co-host of the Security Justice podcast, shares insights on the evolving CISO role. He explains the fractional CISO model and its benefits for businesses of all sizes. Chris highlights the essential balance of technical skills and soft skills needed for success, the challenges of resource constraints, and emphasizes the importance of understanding a company's mission. He offers valuable advice for aspiring CISOs, including skills development and the significance of effective people management.

7 snips
Nov 24, 2025 • 18min
AI Agent Does the Hacking: First Documented AI-Orchestrated Cyber Espionage
Explore the groundbreaking report of an AI-driven cyber espionage campaign targeting 30 global organizations. Discover the misuse of the Claude Code tool by a state-sponsored attacker, and how familiar open-source tools were leveraged for rapid exploitation. The discussion highlights the implications for cybersecurity risk and how AI might shift threat landscapes. Concerns about details shared in disclosures also arise, raising questions about defender preparedness. Join the analysis of AI's impact on both offensive and defensive strategies in cybersecurity.

Nov 17, 2025 • 19min
OWASP Top 10 for 2025: What’s New and Why It Matters
In this episode, we discuss the newly released OWASP Top 10 for 2025. Join hosts Tom Eston, Scott Wright, and Kevin Johnson as they explore the changes, the continuity, and the significance of the update for application security. Learn about the importance of getting involved with the release candidate to provide feedback and suggestions. The conversation touches on the history of the OWASP Top 10, its release cycle, the evolution from specific vulnerabilities to broader categories, and the impact on vulnerability assessment and compliance.
** Links mentioned on the show **
OWASP Top 10:2025 RC1
https://owasp.org/Top10/2025/0x00_2025-Introduction/
** Watch this episode on YouTube **
https://youtu.be/L3nMwFng8ek
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post OWASP Top 10 for 2025: What’s New and Why It Matters appeared first on Shared Security Podcast.

Nov 10, 2025 • 15min
Meet NEO 1X: The Robot That Does Chores and Spies on You?
The future of home robotics is here — and it’s a little awkward. Meet the NEO 1X humanoid robot, designed to help with chores but raising huge cybersecurity and privacy questions. We discuss what it can actually do, the risks of having an always-connected humanoid in your home, and why it’s definitely not the “Robot Rosie” we were promised.
** Links mentioned on the show **
NEO launched by 1X: What to know about the humanoid robot that will do your chores
https://www.yahoo.com/news/article/neo-launched-by-1x-what-to-know-about-the-humanoid-robot-that-will-do-your-chores-215410885.html
FULL EPISODE : Rosey The Robot | The Jetsons | Cartoon Cartoons
https://www.youtube.com/watch?v=-rVeOh1I-uY
** Watch this episode on YouTube **
https://youtu.be/DT44_tmMl3s
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Meet NEO 1X: The Robot That Does Chores and Spies on You? appeared first on Shared Security Podcast.

Nov 3, 2025 • 15min
OpenAI’s ChatGPT Atlas: What It Means for Cybersecurity and Privacy
In this episode, we explore OpenAI’s groundbreaking release GPT Atlas, the AI-powered browser that remembers your activities and acts on your behalf. Discover its features, implications for enterprise security, and the risks it poses to privacy. Join hosts Tom Eston and Scott Wright as they discuss everything from the browser’s memory function to vulnerabilities like indirect prompt injection. Stay informed on how AI browsers could reshape web browsing and cybersecurity.
** Links mentioned on the show **
OpenAI launches ChatGPT-powered web browser. What to know before downloading.
https://www.usatoday.com/story/tech/2025/10/22/open-ai-launches-chatgpt-atlas-web-browser/86833766007/
OpenAI’s Atlas shrugs off inevitability of prompt injection, releases AI browser anyway
https://www.theregister.com/2025/10/22/openai_defends_atlas_as_prompt/
** Watch this episode on YouTube **
https://youtu.be/P3TUW3Qv1MY
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post OpenAI’s ChatGPT Atlas: What It Means for Cybersecurity and Privacy appeared first on Shared Security Podcast.

Oct 27, 2025 • 19min
It’s Always DNS: Lessons from the AWS Outage
In episode 404 (no pun intended!) we discuss the recurring issue of DNS outages, the recent Amazon AWS disruption, and what this reveals about our dependency on cloud services. The conversation touches on the need for tested business continuity plans, the implications of DNS failures, and the misconceptions around cloud infrastructure’s automatic failover capabilities.
** Links mentioned on the show **
An AWS failure took down the internet Monday morning – and the aftershocks continue
https://www.zdnet.com/home-and-office/networking/an-aws-failure-took-down-the-internet-monday-morning-and-the-aftershocks-continue/
What the Huge AWS Outage Reveals About the Internet
https://www.wired.com/story/what-that-huge-aws-outage-reveals-about-the-internet/
** Watch this episode on YouTube **
https://youtu.be/Y2rhmkPhe78
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post It’s Always DNS: Lessons from the AWS Outage appeared first on Shared Security Podcast.

Oct 20, 2025 • 23min
Is Sora 2 the Future of Video? AI, Copyright, and Privacy Issues
OpenAI’s Sora 2 is here — and it’s not just another AI toy. This episode explores how Sora 2 works, how users can insert almost anything into generated content, and why that’s raising alarms about privacy, identity, and copyright. We walk you through the initial opt-out copyright controversy, the backlash from studios and creators, and how OpenAI is scrambling to offer more control. Tune in to understand what rights you might lose — or want to protect — in this new media era.
** Links mentioned on the show **
Tilly Norwood “AI Generated Actor”
https://www.tillynorwood.com/
Emily Blunt and Sag-Aftra join film industry condemnation of ‘AI actor’ Tilly Norwood
https://www.theguardian.com/film/2025/sep/30/emily-blunt-sag-aftra-film-industry-condemnation-ai-actor-tilly-norwood
Sora, Not Sorry: OpenAI Backtracks on Opt-Out Copyright Policy
https://copyrightlately.com/openai-backtracks-sora-opt-out-copyright-policy/
I tried the new Sora 2 to generate AI videos – and the results were pure sorcery
https://www.zdnet.com/article/i-tried-the-new-sora-2-to-generate-ai-videos-and-the-results-were-pure-sorcery/
** Watch this episode on YouTube **
https://youtu.be/MPY-OmTifPI
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Is Sora 2 the Future of Video? AI, Copyright, and Privacy Issues appeared first on Shared Security Podcast.

Oct 13, 2025 • 21min
Age Verification Laws: A Privacy Disaster in the Making
In this episode, we discuss the surge of age verification laws spreading across the US, including the recent implementation in Ohio. These laws intend to shield children but come at a significant cost to privacy and cybersecurity. We’ll explore how third-party ID verification companies operate, the risks associated with these systems, and the broader definition of adult content beyond pornography. We also question the effectiveness and security of these measures as we share insights into the ease of bypassing verification systems. Are we protecting kids, or building a privacy nightmare?
** Links mentioned on the show **
Bluesky to verify ages under Ohio pornography ID law. Here’s when the law takes effect
https://www.dispatch.com/story/news/2025/09/30/bluesky-verify-ages-ohio-pornography-id-law/86423200007/
How to get around age verification checks
https://gist.github.com/mary-ext/6e27b24a83838202908808ad528b3318
Age verification service that Bluesky is using
https://www.kidswebservices.com/en-US/services/age-verification
** Watch this episode on YouTube **
https://youtu.be/Pc3zjOWNthY
** Become a Shared Security Supporter **
Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Age Verification Laws: A Privacy Disaster in the Making appeared first on Shared Security Podcast.


