The Cybersecurity Defenders Podcast

LimaCharlie
undefined
Nov 17, 2025 • 42min

#268 - Intel Chat: LLM integration in malware, Android spyware family LandFall, Windows kernel zero-day flaw & Ex-L3Harris executive sells trade secrets

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.Google’s Threat Intelligence Group has observed a significant shift in 2025, threat actors are no longer using AI to just speed up operations, they are now integrating LLMs directly into the malware.Unit 42 has identified a previously undocumented Android spyware family, named LandFall, discovered during an investigation into iOS exploit chains involving malicious DNG images.Microsoft’s November Patch Tuesday rollout includes fixes for over 60 vulnerabilities, one of which is a zero-day privilege escalation flaw in the Windows kernel that has already been exploited in the wild.Former executive at L3Harris Trenchant, Peter Williams, has pleaded guilty in U.S. federal court to selling 8 trade secrets valued at over 1.3 million to a Russian-based software broker involved in the zero-day exploit market.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
undefined
Nov 14, 2025 • 32min

#267 - Defender Fridays: AI in SecOps - what's real vs. what's hype? With Alec Fenton from Foresite Cybersecurity

In this episode of Defender Fridays, we talk to Alec Fenton, VP Security Operations at Foresite Cybersecurity, practical career advice for defenders, SOC metrics that actually matter and AI in security operations.Join the Defender Fridays community, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.Alec is a seasoned Cyber Security professional with over 15 years of extensive experience across many IT domains. With a career spanning more than a decade, Alec has honed his expertise in addressing a broad spectrum of cybersecurity challenges, leveraging his analytical prowess and hands-on approach to leadership.Throughout his career, Alec has navigated the intricate landscape of IT security, working across various sectors including managed service providers and private companies. His tenure as an analyst in the cybersecurity space has not only equipped him with a deep understanding of emerging threats and vulnerabilities but has also shaped his leadership philosophy of "lead from the front."Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
undefined
Nov 12, 2025 • 31min

#266 - Preparing for Out-of-Band Communication in Incident Response with Navroop Mitter from ArmorText

On this episode of The Cybersecurity Defenders Podcast we speak with Navroop Mitter, CEO of ArmorText, about the role of Out-of-Band (OOB) communication in cyber incident response.ArmorText Named a Leader in The Forrester Wave™: Secure Communications Solutions, Q3 2024Cyber Resilience: Incident Response Tabletop ExercisesNavroop Mitter is the CEO of ArmorText, a mobile security and privacy company based in the Washington, D.C. area.Before founding ArmorText, Navroop was a Senior Manager in Accenture’s North American Security Practice, where he built and led information security programs across multiple regions. He helped double Accenture’s Scandinavian security practice within a year and established the firm’s first near-shore security delivery center in Argentina, hiring and training over 30 practitioners in under 30 days.Navroop has led large-scale international security engagements, working across cultures and time zones to strengthen teams in the U.S., India, and abroad. Recognized for his entrepreneurial mindset and expertise in identity and access management, he became one of Accenture’s most sought-after leaders for complex, multi-country security initiatives.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
undefined
Nov 10, 2025 • 31min

#265 - Intel Chat: AWS TruffleNet exploit, React Native vulnerability, SesameOp OpenAI Assistants API C2 channel & Operation SkyCloak

Explore a newly discovered threat exploiting AWS Simple Email Service with stolen credentials to launch Business Email Compromise scams. Discover a critical vulnerability in the React Native Community CLI that requires immediate attention. Learn about SesameOp, a novel backdoor using OpenAI’s Assistants API for command and control. Uncover Operation SkyCloak, a sophisticated malware campaign targeting defense organizations through clever phishing tactics. Dive into the future of cloud security and attack vectors!
undefined
Nov 7, 2025 • 33min

#264 - Defender Fridays: Dive into SaaS Intrusion Trends with Julie Agnes Sparks from Datadog

Julie Agnes Sparks, a security engineer at Datadog, brings her expertise in detection engineering and SaaS threat hunting to the table. She discusses the rising incidence of SaaS breaches and the critical need for effective audit logging. The conversation dives into the challenges of inconsistent vendor logs and typical incident workflows that hinder visibility. Julie also highlights notable attack patterns like identity provider pivoting and the role of AI in enhancing detection strategies, making a case for clearer audit log quality to combat evolving threats.
undefined
Nov 3, 2025 • 41min

#263 - Intel Chat: BlackBasta, BlueNoroff, Operation ForumTroll & Aisuru

The podcast explores the chilling details of the BlackBasta ransomware attack on Capita and its operational failures. North Korea's BlueNoroff campaigns utilize social engineering and AI-assisted malware for nefarious gains. A zero-day vulnerability tied to Operation ForumTroll raises alarms over cyber-espionage efforts targeting Russian entities. There's a deep dive into the newly emerged Aisuru IoT botnet responsible for massive DDoS attacks, highlighting the urgent need for better home IoT security and proactive protective measures.
undefined
9 snips
Oct 31, 2025 • 35min

#262 - Defender Fridays: What does "AI-ready SOC" actually mean? With Dr. Anton Chuvakin from CISO, Google Cloud

Dr. Anton Chuvakin, a Security Advisor at Google Cloud and a leading expert in SIEM and log management, delves into the essentials of an AI-ready security operations center (SOC). He discusses the risks of adopting technology prematurely and highlights key pillars for effective AI integration, including data quality and process maturity. Anton stresses the importance of cultural readiness for balancing human roles with AI capabilities and shares insights on using AI to enhance threat detection and operational efficiency. A must-listen for cybersecurity enthusiasts!
undefined
Oct 29, 2025 • 60min

#261 - Scaling MSP & MSSP Services with Hannah Lloyd, Co-Founder / CRO of enhanced.io

Hannah Lloyd, Co-Founder and CRO of enhanced.io, brings over a decade of channel sales expertise to the conversation. She recounts her journey from English major to cybersecurity leader and discusses how MSPs can ethically monetize security solutions. Key topics include the rising demand from insurance and compliance, successful MSP strategies, and effective marketing in the age of AI. She also highlights future opportunities in co-managed services and urges listeners to stay curious and engaged in the cybersecurity community.
undefined
Oct 27, 2025 • 40min

#260 - Intel Chat: Kansas City National Security Campus breach, COLDRIVER, new KEV catalog additions & AWS outage

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community.A breach at the Kansas City National Security Campus (KCNSC), a facility responsible for manufacturing roughly 80% of the non-nuclear components for U.S. nuclear weapons, was enabled by two critical Microsoft SharePoint vulnerabilities.COLDRIVER, a Russian state-sponsored group also tracked as UNC4057, Callisto, or Star Blizzard, has shifted rapidly toward new malware development following the public exposure of its previous malware, LOSTKEYS, in May 2025.CISA has officially added three newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging swift remediation efforts across federal environments. Newer article link.Amazon Web Services (AWS) experienced a major outage on October 20th that impacted thousands of applications globally, disrupting operations for companies and end-users alike.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform.This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.
undefined
Oct 24, 2025 • 34min

#259 - Defender Fridays: Breaking Down Microsoft Defender for Endpoint with Ken Westin from LimaCharlie

Ken, Senior Solutions Engineer at LimaCharlie, dives into the incredibly confusing licensing tiers, pricing models and feature sets for Microsoft Defender for Endpoint. Today we discuss: The difference between tiersWays to solve Defender visibility issues and increase operational transparencyHow its capabilities can be customized and expanded for better flexibility and scalability for service providersJoin the Defender Fridays community, live every Friday, to discuss the dynamic world of information security in a collaborative space with seasoned professionals.A big picture thinker, Ken ferrets out trends, seeking to understand what happens when businesses are breached and the methods behind the attacks. Then he figures out how to protect customers before they’re hit.Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastruture for SecOps where everything is built API first. Scale with confidence as your business grows. Start today for free at limacharlie.io.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app