The Cyber Threat Perspective

SecurIT360
undefined
Jul 24, 2026 • 28min

Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding

Almost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you.Brad and Jordan cover both sides of supply chain risk: the trusted third-party applications you deploy (SolarWinds being the case that put this category on the map) and the open-source components you pull into your own code without always knowing what's inside. They explain why AI and vibe coding are accelerating the problem, why jQuery is the modern-day Flash, and why "just upgrade the package" is rarely that simple.From there it gets practical:What a Software Bill of Materials (SBOM) is and why you need oneTransitive dependencies — the packages hiding beneath your packagesBuilding security checks into your CI/CD pipeline and shifting leftWhy a flaw caught in static analysis can cost ~$200, while the same flaw found in a pen test can cost $20,000+Why a pen test should validate your controls, not be your first line of defenseHow SecurIT360's Project Lantern and ChainGarde automate SBOM analysis against known and actively-exploited vulnerabilitiesA playbook for vetting vendors, writing accountability into contracts, and holding third parties responsible for actually fixing findingsThe takeaway: whether you're writing software or buying it, you need a way to inventory your components, check them against known vulnerabilities, and hold your vendors accountable — and most of it you can do with tools and teams you already have.Part 1 — Broken Access Control, IDOR & CORS: https://youtu.be/BwYJ-kZ3XaYPart 2 — Security Misconfigurations: https://youtu.be/Po8H140BijENeed a web app pen test? SecurIT360 | Cybersecurity From Every Angle More content: https://offsec.blogWork with Us: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.com
undefined
Jul 17, 2026 • 31min

Guaranteed way to catch threat actors | Ep 188

They dig into deception as an early-warning tactic that lures intruders into predictable traps. Listeners hear practical bait ideas like fake file shares, misconfigurations, certificate and account honeypots. The conversation covers building realistic campaign-style decoys, scaling from simple DIY lures to commercial tools, and using deception to slow attackers and boost detection opportunities.
undefined
Jul 10, 2026 • 16min

Avoid this cyber leadership trap | Ep 187

Need a pentest or vCISO? Work with us! https://www.securit360.com/A major leadership failure in Cybersecurity is l buying tools first then figuring out where they fit and how to use them. That’s super backwards. Here’s what I would do instead. Plan first, buy & implement second. I’m going to cover just the planning part this week. Next week we will talk about buying and implementing. Because honestly, implementation is where a lot of security teams go wrong. Work with Us: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.com
undefined
Jul 3, 2026 • 36min

Episode 186: Real Life Active Directory Attack Paths

In this episode Spencer and Tyler discuss real life Active Directory attack paths, taken from real internal pentest engagements over the last several years.Work with Us: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.com
undefined
Jun 25, 2026 • 34min

[Replay] Episode 172: The Biggest Security Blind Spots in Midsized Companies

They unpack the most common security blind spots in midsized companies: missing asset inventories, forgotten internet-facing hosts, and risky MSP misconfigurations. They discuss flat networks and over-permissive identities that enable lateral movement. They highlight credential reuse, developer systems acting like domain admin keys, and fast-growing AI-related risks from agent identities and unchecked integrations.
undefined
Jun 18, 2026 • 46min

Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents

AI agents can search the web, manipulate files, run commands, make API requests, access cloud platforms, and operate fully autonomously. They are powerful, they are here, and most organizations have no security controls around them whatsoever.In this episode, Brad and Spencer break down the five major AI agent risk categories security teams need to understand right now, using Simon Willison's "lethal trifecta" as a framework and building on it with two additional risk areas they see in the field.In this episode:- What an AI agent actually is and why the definition matters before you can secure it - What AI agents are capable of: files, commands, APIs, memory, cloud access, and autonomous execution - The lethal trifecta: access to private data, exposure to untrusted content, and external communication - Risk category 1: Access to private data - why agents inherit your permissions and why that is dangerous - Risk category 2: Exposure to untrusted content and prompt injection attacks - Risk category 3: External communication and data exfiltration (including a real canary token experiment) - Risk category 4: Privileged access and limiting blast radius with least privilege identities - Risk category 5: Autonomous actions, approval gates, rate limits, and kill switches - Why backups, rollback plans, and recovery playbooks are more important than ever in an AI agent worldResources mentioned:- Simon Willison's lethal trifecta post (June 2025): https://simonwillison.net - Zach Korman's ContinuumCon sandbox escape workshop: https://continuumcon.com/schedule/ - offsec.blog | securit360.comNeed a pen test before end of year? Q3 slots are filling up fast. Work with Us: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.com
undefined
Jun 11, 2026 • 29min

Episode 184 | Active Directory Isn't Dead. It's Just Undefended.

Think Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ years. In this episode, Brad and Spencer break down why AD attack paths remain one of the most critical threats in enterprise environments and what defenders can do about it right now.Spencer also previews his ContinuumCon workshop "Killing AD Attack Paths Once and For All" where he demonstrates how authentication policies and silos can eliminate an entire class of lateral movement attacks built into Windows and Active Directory.In this episode:- Why Active Directory is still alive, well, and heavily targeted- What an Active Directory attack path is and how attackers use them- The four prerequisites attackers need to abuse AD attack paths- Real-world examples: Kerberos ticket theft, SCCM abuse, certificate misconfigurations, and misconfigured permissions- Tools defenders should know: Bloodhound, PingCastle, Purple Knight, Locksmith, and ADelegator- How to prioritize remediations based on ease of exploitation vs. impact- Why retesting is the most overlooked step in any remediation cycleResources mentioned:- Spencer's ContinuumCon Workshop (Fri. June 12, 10:30am PT / 1:30pm ET): https://continuumcon.com/schedule/- Hybrid Identity Protection Podcast (Semperis): https://www.semperis.com/hybrid-identity-protection-podcast/- Bloodhound CE: https://github.com/SpecterOps/BloodHound- PingCastle: https://www.pingcastle.com- Purple Knight: https://www.purple-knight.com- Locksmith: https://github.com/TrimarcJake/Locksmith- offsec.blog | securit360.comWork with Us: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.com
undefined
Jun 5, 2026 • 29min

Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked

Security misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Natter cover OWASP A05: Security Misconfiguration with real stories from recent engagements and practical takeaways for developers, security teams, and organizations of all sizes.In this episode:Hardcoded Active Directory credentials and API keys discovered in a public GitHub repo during a healthcare pen testDefault credentials (admin/1234) found on a clinical research app storing PHIA rogue Apache basic auth panel that survived from dev into productionHow verbose error handling and stack traces hand attackers a roadmap to your appWhy dev-to-production is the most dangerous transition in your app's lifecycleThe shift-left mindset and DevSecOps — empowering devs to ship secure codeHow CIS lockdown guides can dramatically improve your security posture overnightResources mentioned:OWASP Top 10: OWASP Top Ten Web Application Security Risks | OWASP FoundationCIS Benchmarks: https://www.cisecurity.org/cis-benchmarksEp. 182 – OWASP Top 10 Part 1: https://youtu.be/BwYJ-kZ3XaYNeed a web application pen test? Reach out: Offensive Security - SecurIT360Work with Us: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.com
undefined
May 27, 2026 • 31min

Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR)

They unpack Verizon's finding that software vulnerabilities have become the top initial access vector. They cover the remediation crisis and why patching is falling behind. They discuss web application sprawl from cloud and SaaS. They highlight shifting ransomware economics and rising mobile phishing and pretexting threats. They examine shadow AI risks, IDE/extension dangers, and real-world incidents tied to coding agents.
undefined
May 20, 2026 • 45min

[Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works

We're re-releasing one of our most practical episodes this week — originally published November 2025, and still one of the best roadmap conversations we've had on the show.Brad and Spencer share no-fluff advice for breaking into cybersecurity, whether you're switching careers, starting from scratch, or leveling up from a general IT role. They cover what employers actually look for, the fastest paths in, and what to skip.If you're exploring a cybersecurity career, or know someone who is, this one's for you.Work with Us: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.com

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app