

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
Jerry Bell and Andrew Kalat
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
Episodes
Mentioned books

Sep 15, 2025 • 58min
Defensive Security Podcast Episode 321
Listen and Watch Defensive Security Episodes a week early by becoming a Patreon donor: https://www.patreon.com/defensivesec
Please subscribe to our YouTube channel: Defensive Podcasts – Cyber Security & Infosec. – YouTube
Links:
https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/
https://www.bleepingcomputer.com/news/security/ai-powered-malware-hit-2-180-github-accounts-in-s1ngularity-attack/
https://www.cbc.ca/news/canada/hamilton/cybersecurity-breach-1.7597713
https://www.bleepingcomputer.com/news/security/6-browser-based-attacks-all-security-teams-should-be-ready-for-in-2025/
https://www.bleepingcomputer.com/news/security/hackers-use-new-hexstrike-ai-tool-to-rapidly-exploit-n-day-flaws/

Sep 8, 2025 • 47min
Defensive Security Podcast Episode 320
Links to stories:
https://securityaffairs.com/181430/security/after-sharepoint-attacks-microsoft-stops-sharing-poc-exploit-code-with-china.html
https://www.cybersecuritydive.com/news/software-vulnerabilities-breaches-checkmarx-report/757793/
https://www.securityinfowatch.com/cybersecurity/article/55309774/even-security-leaders-are-breaking-ai-rules-calypsoai-report
https://www.darkreading.com/cyber-risk/cyber-insurers-may-limit-payments-breaches-unpatched-cve
https://www.darkreading.com/cyberattacks-data-breaches/fake-employees-pose-real-security-risks

Aug 26, 2025 • 1h 16min
Defensive Security Podcast Episode 318
This installment dives into the latest cybersecurity threats, including a downgrade attack that circumvents FIDO authentication in Microsoft Entra ID. There's a deep exploration of vulnerabilities in Docker Hub and the rising danger of ransomware such as Charon. The concept of vibe coding is introduced, discussing how AI can assist novice coders while also raising security concerns. Additionally, the podcast highlights the market for initial access brokers, revealing how compromised access is sold on the dark web. Tune in for practical security tips and a fun teaser about an upcoming live event!

Aug 12, 2025 • 1h 17min
Defensive Security Podcast Episode 317
The hosts dive into the intriguing world of AI and its impact on cybersecurity. They discuss the rise of malicious activities leading to new vulnerabilities and emphasize proactive defense strategies. A shocking case involving ATM networks reveals risks from poor security practices. Special attention is given to a critical flaw in the T app, threatening user privacy. The conversation wraps up with insights on the future of AI in security roles, raising questions about job security for professionals in an evolving landscape.

Aug 4, 2025 • 1h 8min
Defensive Security Podcast Episode 316
Want to support our show? Want to get access to episodes a week before everyone else? Become a patreon sponsor here: https://www.patreon.com/defensivesec
If you’re in Atlanta on August 20, you can join us for a LIVE episode at Mission 25. Register here: MCS Mission: Security’25
Our new merch store is live: DefSec Store
We’ve added a lot of new items and will continue to do so over time.
On to the show. Here are the links for this week’s episode:
https://www.theregister.com/2025/07/26/microsoft_sharepoint_attacks_leak/
https://mashable.com/article/google-gemini-deletes-users-code
https://arstechnica.com/security/2025/07/open-source-repositories-are-seeing-a-rash-of-supply-chain-attacks/
https://www.theregister.com/2025/07/23/lawsuit_clorox_vs_cognizant/
https://www.bleepingcomputer.com/news/security/allianz-life-confirms-data-breach-impacts-majority-of-14-million-customers/

Jul 28, 2025 • 43min
Defensive Security Podcast Episode 315
If you’re in Atlanta on August 20, you can join us for a LIVE episode at Mission 25. Register here: MCS Mission: Security’25
Our new merch store is live(ish): DefSec Store – We’ll be adding more items as time goes on. This is managed through Printify, which has a quite expansive range of products to logo up.
Also, some of you may know that Jerry is into photography and contemplating creating a calendar with images he’s taken. Let us know if that sounds interesting. Possible themes are: beach sunsets, flowers, or jet fighters, because that’s about all he’s good at taking pictures of.
On to the show. Here are the links for this week’s episode:
https://www.bleepingcomputer.com/news/security/lamehug-malware-uses-ai-llm-to-craft-windows-data-theft-commands-in-real-time/
https://arstechnica.com/security/2025/07/hackers-exploit-a-blind-spot-by-hiding-malware-inside-dns-records/
https://www.darkreading.com/remote-workforce/fully-patched-sonicwall-gear-zero-day-attack
https://www.bleepingcomputer.com/news/security/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers/ (for patreon listeners only)
https://thehackernews.com/2025/07/malware-injected-into-6-npm-packages.html?m=1(for patreon listeners only)

Jul 22, 2025 • 47sec
Defensive Security Podcast Episode 314.5
Episode 315 is available for our patreon donors and will be posted for everyone else on Monday, July 28. Going forward, episodes will be released to our patreon donors shortly after recording and will be released to everyone else a week later. If you want to become a patreon donor, you can do so here: https://www.patreon.com/defensivesec
Also, our new merch store is live and available here: https://store.defensivesecurity.org
It’s a work in progress and please let me know if you have any issued with it. Thank you all and we’ll talk on Monday!

Jul 14, 2025 • 37min
Defensive Security Podcast Episode 314
Want to support us? Want even MORE DefSec? Starting this week, we are providing more DefSec for our Patreon donors. Sign up to be a Patreon donor today: https://www.patreon.com/defensivesec
Links:
https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/
https://www.axios.com/2025/07/08/scattered-spider-cybercrime-hackers
https://www.bleepingcomputer.com/news/security/employee-gets-920-for-credentials-used-in-140-million-bank-heist/
Additional links for Patreon donors:
https://www.theregister.com/2025/07/13/fake_it_worker_problem/
https://www.theregister.com/2025/07/09/chatgpt_jailbreak_windows_keys/

Jul 9, 2025 • 44min
Defensive Security Podcast Episode 313
The hosts reflect on personal memories while blending humor with security insights. They introduce an AI bot, Expo, that's revolutionizing vulnerability identification. The chat turns to advanced application security tools and the growing role of AI in this field. Cyber threats are evolving, with new tactics like callback phishing emerging. There's an urgent call for organizations to step up their vulnerability management. Fans can look forward to exciting merchandise updates and exclusive content opportunities.

Jun 30, 2025 • 42min
Defensive Security Podcast Episode 312
The hosts humorously discuss Patreon support and introduce new exclusive content for donors. They reveal a critical vulnerability in MegaRack systems that could allow hackers unauthorized access. The episode also highlights the importance of professionalism in cybersecurity marketing and the challenges new hires face regarding phishing risks, tying in historical malware stories. Engaging anecdotes about email overload during orientations blend with discussions on combating social engineering, making for an entertaining and informative listen.