

Safe Mode Podcast
Safe Mode Podcast
Podcast by Safe Mode Podcast
Episodes
Mentioned books

Sep 25, 2025 • 27min
Censys’ Silas Cutler on how adversaries chain vulns together for big attacks
In this episode of Safe Mode, Greg talks with Silas Cutler, principal security researcher at Census, how ransomware attackers chain together overlooked vulnerabilities, especially in platforms like SharePoint, and why patch fatigue leaves defenders at risk. Silas breaks down advanced ways criminals maintain access even after patches, and explains what makes government and critical sectors prime targets. We discuss the real challenges of incident response, threat intelligence, and preventing long-term damage—especially in complex cloud and hybrid environments.
In our reporter chat, Greg talks with Tim Starks about two marquee stories this week: a look at how the government information sharing law renewal has sputtered, and a new China-linked espionage campaign has researchers sounding the alarms.
https://cyberscoop.com/cyber-threat-information-law-hurtles-toward-expiration-with-poor-prospects-for-renewal/

Sep 18, 2025 • 32min
Veracode’s Chris Wysopal on the security issues with AI code development
On this episode of Safe Mode, we’re joined by a renowned cybersecurity expert and CyberScoop 50 winner, Veracode co-founder and CTO Chris Wysopal, to discuss the fast-evolving landscape of AI-assisted software development. Chris shares insights from a recent study examining over 100 large language models and their tendency to introduce security vulnerabilities in generated code. The conversation delves into why a staggering 45% of AI-generated code samples contained vulnerabilities and why improvements in AI reasoning haven’t translated to more secure outputs. Chris emphasizes the critical need for enhanced security testing and better quality training data, discussing both the challenges and opportunities ahead as AI adoption accelerates. Tune in for a thoughtful exploration of the intersection between AI, secure coding, and what the future holds for developers and enterprises alike.
In our reporter chat, Greg talks with Derek Johnson about work that OpenAI and Anthropic have done with the U.S. and U.K. government to secure their models.

Sep 11, 2025 • 24min
Phosphorus’ Sonu Shankar on IoT Vulnerabilities and Salt Typhoon Tactics
In this episode, Greg Otto talks with Sonu Shankar, President at Phosphorus, to discuss the unique security challenges facing today’s rapidly expanding Internet of Things landscape, where traditional endpoint protections are ineffective. The episode explores how everyday devices with default passwords and outdated firmware open organizations up to significant risk. Shankar highlights the tactics of groups like Salt Typhoon, who exploit these weak spots to infiltrate and persist within networks. The conversation underscores the pressing need for deeper asset inventory and active discovery in critical environments.
In our reporter chat, Greg talks with Matt Kapko about a supply-chain attack on npm that turned out to be pretty close to a false alarm.

Sep 4, 2025 • 29min
Halcyon’s Cynthia Kaiser on the state of ransomware
In this episode, Greg Otto talks with Cynthia Kaiser Sr. Vice President of Halcyon’s Ransomware Research Center, discussing the latest ransomware operations and exploring the latest shifts in the cyber threat landscape. Greg and Cynthia discuss the rise of new groups like DragonForce, SafePay, and Fog, and the decline of once-dominant names such as LockBit and BlackBasta. They also discuss unique tactics and tools employed by emerging players, discuss the impact of law enforcement and internal group dynamics, and examine why certain industries are now prime targets. Learn how attackers choose their victims, the early warning signs organizations should watch for, and the most frequent pitfalls in ransomware defense.
In our reporter chat, Greg talks with Matt Kapko about the deep drive into an accused ransomware affiliate that has been given a long leash by law enforcement while he awaits trial.

Aug 28, 2025 • 25min
What happens if CISA 2015 lapses?
In this episode of Safe Mode, host Greg Otto talks with Tim Starks about what would happen if the nation’s information sharing law – known as CISA 2015 – expires at the end of September.
In our interview segment, Greg talks with Kevin Hanes, CEO of Reveal Security, exploring the critical and often overlooked world of machine identity security. From the blind spots in privileged access management that focus too heavily on human users while machines hold increasingly sensitive roles, to the operational challenges of securing identities in cloud-native, containerized, and AI-powered environments, Kevin shares practical insights on scaling visibility and maintaining accountability across fragmented teams.

Aug 21, 2025 • 31min
Dave DeWalt on how to get a board to buy in on cybersecurity
In this episode of Safe Mode, host Greg Otto talks with Dave DeWalt, founder and CEO of NightDragon, about advising boards and portfolio companies on making cyber a first-order business issue, not an afterthought. We’ll explore how emerging technologies and remote work reshape risk profiles, when a CISO belongs in the board conversation—or even in a board seat—and what training and metrics actually move the needle across non-technical teams. We’ll also unpack how to motivate leaders outside of IT to own cyber risk, the structures that drive enterprise-wide accountability, and what information boards should demand to ensure the right risks are being prioritized. From calibrating cyber risk appetite in shifting threat environments to staying ahead of evolving regulations across sectors like power and aviation, we’ll get practical on governance and disclosure.
In our reporter chat, Greg talks with Derek Johnson about the president’s possible push to end mail-in voting, and why the efforts are dead on arrival.

Aug 14, 2025 • 46min
Are enterprises having the right AI security conversations?
In this episode of Safe Mode, host Greg Otto sits down with Chris Sestito, CEO of HiddenLayer Technologies, to discuss the evolving landscape of AI security and where current protection strategies are falling short. Sestito shares insights on how leading enterprises are rethinking their approach to AI asset protection, reveals real-world examples where traditional security measures failed against AI-specific threats, and explains the unique vulnerabilities that conventional cybersecurity tools struggle to address. The conversation explores the tension between rapid AI innovation and regulatory frameworks, with Sestito offering his perspective on what smarter, more adaptive AI regulation should look like and how policymakers can balance innovation with robust security protections. Don't miss this deep dive into the future of AI security, insider threats in AI-driven workplaces, and Sestito's top recommendations for government regulators crafting new AI security laws
In our reporter chat, Greg talks with Tim Starks about what the federal government is doing to meet the demands put forth in President Trump’s cybersecurity executive order.

Aug 7, 2025 • 34min
What is CISA’s focus moving forward
On this episode of Safe Mode, Greg Otto sits with two CISA leaders, Chris Butera, Acting Executive Assistant Director for CISA’s Cybersecurity Division, and Bob Costello, CIO of CISA, at the 2025 Black Hat USA Conference to discuss numerous different topics: the recent Microsoft Sharepoint vulnerability, the upcoming CIRCIA rulemaking, the future of the JCDC, state and local cyber grants, and the emphasis they are placing to strengthening public-private partnerships.
In our reporter chat, Greg talks with Matt Kapko about what they both heard during their conversations at the Black Hat conference.

Jul 31, 2025 • 33min
Inside the AI Action Plan with Dreadnode’s Daria Bahrami
On this episode of Safe Mode, host Greg Otto sits down with Daria Bahrami, Head of Policy at Dreadnode, for an in-depth exploration of the new AI Action Plan and its sweeping implications for critical infrastructure security. From the technical hurdles in securing vital systems to the growing need for “secure-by-design” technology standards, Daria breaks down what’s at stake as artificial intelligence becomes both a linchpin and a potential liability in our national cyber defenses.
In our reporter chat, Greg talks with Tim Starks about the motion on Capitol Hill to confirm CISA Director nominee Sean Plankey.

Jul 24, 2025 • 31min
NetRise’s Tom Pace on why telecom’s Salt Typhoon problem may never go away
In this episode of Safe Mode, Greg talks with Tom Pace, CEO of Netrise, about the recent Salt Typhoon cyberattack against U.S. telecom networks and how the government is responding. Tom explains why it’s so hard to fully protect or fix these giant, complex systems, even when officials say they have stopped the threat. He points out the tough choices telecom companies face—like keeping service running, following regulations, and fixing security gaps—which don’t always work together. The conversation also covers problems with current rules and why spending more money isn’t always the answer. Listen for a straightforward discussion about what it will really take to keep our communication networks safe.