

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
Jerry Bell and Andrew Kalat
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
Episodes
Mentioned books

Oct 27, 2025 • 1h
Defensive Security Podcast Episode 327
Want to be the first to hear our episodes each week? Become a Patreon donor here.
Links to this week’s stories:
https://www.cybersecurity-insiders.com/how-ai-will-shape-the-future-of-cyber-defense-a-one-three-and-five-year-outlook/
https://www.helpnetsecurity.com/2025/10/15/f5-big-ip-data-breach/
https://www.bleepingcomputer.com/news/security/fake-lastpass-bitwarden-breach-alerts-lead-to-pc-hijacks/
https://blogs.microsoft.com/on-the-issues/2025/10/16/mddr-2025/
https://www.theguardian.com/technology/2025/oct/19/global-cyber-attack-russian-hack-solarwinds-stress-health

Oct 21, 2025 • 1h 7min
Defensive Security Podcast Episode 326
Want to be the first to hear our episodes each week? Become a Patreon donor here.
Here are the stories we discuss this week:
https://cybersecuritynews.com/hackers-actively-compromising-databases/
https://www.bleepingcomputer.com/news/security/hackers-target-university-hr-employees-in-payroll-pirate-attacks/
https://securityaffairs.com/183154/security/threat-actors-steal-firewall-configs-impacting-all-sonicwall-cloud-backup-users.html
https://www.theregister.com/2025/10/07/gen_ai_shadow_it_secrets/
https://thehackernews.com/2025/10/from-phishing-to-malware-ai-becomes.html?m=1
https://databreaches.net/2025/10/12/from-sizzle-to-drizzle-to-fizzle-the-massive-data-leak-that-wasnt/

Oct 13, 2025 • 1h 3min
Defensive Security Podcast Episode 325
Want to be the first to hear our episodes each week? Become a Patreon donor here.
Here are links to the stories we discuss this week:
https://www.theregister.com/2025/09/29/postmark_mcp_server_code_hijacked/
https://www.bleepingcomputer.com/news/security/oracle-patches-ebs-zero-day-exploited-in-clop-data-theft-attacks/
https://www.bleepingcomputer.com/news/security/westjet-data-breach-exposes-travel-details-of-12-million-customers/
https://www.cybersecuritydive.com/news/material-cybersecurity-breaches-unreported/760892/
https://www.securityweek.com/red-hat-confirms-gitlab-instance-hack-data-theft/
https://www.securityweek.com/hackers-extorting-salesforce-after-stealing-data-from-dozens-of-customers/
https://databreaches.net/2025/10/04/just-days-before-its-data-might-be-leaked-qantas-airways-obtained-a-permanent-injunction/

Oct 6, 2025 • 1h 20min
Defensive Security Podcast Episode 324
Here are links to the stories we discuss this week:
https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign
https://thehackernews.com/2025/09/github-mandates-2fa-and-short-lived.html
https://www.theregister.com/2025/09/23/gartner_ai_attack/
https://www.bleepingcomputer.com/news/security/sonicwall-releases-sma100-firmware-update-to-wipe-rootkit-malware/
https://www.zdnet.com/article/battered-by-cyberattacks-salesforce-faces-a-trust-problem-and-a-potential-class-action-lawsuit/

Sep 29, 2025 • 51min
Defensive Security Podcast Episode 323
Please follow us on YouTube!
Want episodes a week early? Consider becoming a Patreon sponsor of the DefSec podcast here.
Here are links to the stories we talked about this week:
https://krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages
https://cybersecuritynews.com/finwise-insider-breach/
https://arstechnica.com/security/2025/09/how-weak-passwords-and-other-failings-led-to-catastrophic-breach-of-ascension/

Sep 22, 2025 • 53min
Defensive Security Podcast Episode 322
In a riveting discussion, hosts explore Qantas handing down executive pay cuts post-cyber incident. They delve into the alarming rise of ransomware losses exacerbated by AI-driven phishing tactics. The conversation shifts to a significant NPM supply-chain compromise, raising concerns about dependency risks. LunaLock ransomware’s unique extortion method using stolen data for AI training models is a game changer. Finally, the FBI warns about impending Salesforce attacks, prompting vital talks on security measures like MFA.

Sep 15, 2025 • 58min
Defensive Security Podcast Episode 321
Listen and Watch Defensive Security Episodes a week early by becoming a Patreon donor: https://www.patreon.com/defensivesec
Please subscribe to our YouTube channel: Defensive Podcasts – Cyber Security & Infosec. – YouTube
Links:
https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/
https://www.bleepingcomputer.com/news/security/ai-powered-malware-hit-2-180-github-accounts-in-s1ngularity-attack/
https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713
https://www.bleepingcomputer.com/news/security/6-browser-based-attacks-all-security-teams-should-be-ready-for-in-2025/
https://www.bleepingcomputer.com/news/security/hackers-use-new-hexstrike-ai-tool-to-rapidly-exploit-n-day-flaws/

Sep 8, 2025 • 47min
Defensive Security Podcast Episode 320
Links to stories:
https://securityaffairs.com/181430/security/after-sharepoint-attacks-microsoft-stops-sharing-poc-exploit-code-with-china.html
https://www.cybersecuritydive.com/news/software-vulnerabilities-breaches-checkmarx-report/757793/
https://www.securityinfowatch.com/cybersecurity/article/55309774/even-security-leaders-are-breaking-ai-rules-calypsoai-report
https://www.darkreading.com/cyber-risk/cyber-insurers-may-limit-payments-breaches-unpatched-cve
https://www.darkreading.com/cyberattacks-data-breaches/fake-employees-pose-real-security-risks

Aug 26, 2025 • 1h 16min
Defensive Security Podcast Episode 318
This installment dives into the latest cybersecurity threats, including a downgrade attack that circumvents FIDO authentication in Microsoft Entra ID. There's a deep exploration of vulnerabilities in Docker Hub and the rising danger of ransomware such as Charon. The concept of vibe coding is introduced, discussing how AI can assist novice coders while also raising security concerns. Additionally, the podcast highlights the market for initial access brokers, revealing how compromised access is sold on the dark web. Tune in for practical security tips and a fun teaser about an upcoming live event!

Aug 12, 2025 • 1h 17min
Defensive Security Podcast Episode 317
The hosts dive into the intriguing world of AI and its impact on cybersecurity. They discuss the rise of malicious activities leading to new vulnerabilities and emphasize proactive defense strategies. A shocking case involving ATM networks reveals risks from poor security practices. Special attention is given to a critical flaw in the T app, threatening user privacy. The conversation wraps up with insights on the future of AI in security roles, raising questions about job security for professionals in an evolving landscape.


