

The Defender's Advantage Podcast
Mandiant
Learn about the latest threat and cybersecurity trends on The Defender’s Advantage Podcast! Hear from experts in the field as Host Luke McNamara, from Google Threat Intelligence Group, interviews analysts, researchers and other guests on the frontlines of the latest attacks. Episodes dive deep into various topics, including nation-state activity, cybercrime, malware and tradecraft, incident response, defensive guidance, and more. Don't forget to subscribe!
Episodes
Mentioned books

Aug 10, 2026 • 33min
The New Frontline of Supply Chain Attacks
In this episode of Mandiant’s Defender’s Advantage Podcast, host Luke McNamara sits down with Ben Read, Head of Strategic Threat Intelligence at Wiz, to explore the rapidly shifting landscape of software supply chain compromises. While historic, nation-state operations like SolarWinds focused on compromising closed-source software, modern adversaries have expanded their playbook to target widely used open-source ecosystems, repositories, and automated CI/CD pipelines. Ben discusses how differing tactics in these campaigns play out in the current threat landscape. For more on Wiz's research: https://www.wiz.io/blog/tag/research

Jul 22, 2026 • 36min
Shadow LLMs, Agentic Identities, and Securely Integrating AI
Host Luke McNamara sits down with Muhammad Muneer, Technical Manager on Mandiant's Incident Response team, to unpack the stark realities of enterprise AI adoption. They explore why securing AI starts with resolving legacy security debt (specifically around IAM, supply chain, and secrets management) and dissect the critical differences between "governance for AI" and "governance of AI." Muhammad details real-world frontline findings—from developers bypassing API gateways to the financial costs of leaked LLM API keys—and outlines the emerging threat of adversaries leveraging LLM-enabled command-line tools for living-off-the-land attacks.

Jul 13, 2026 • 39min
Human-Machine Teaming: Applying AI to Frontline Threat Intelligence Workflows
Host Luke McNamara is joined by Jake Nicastro, who leads the AI function for the Frontline Intelligence Operations team within the Google Threat Intelligence Group (GTIG). Jake details how his team is shifting from simple prompt engineering to more advanced agentic workflows, focusing on a model of "human-machine teaming." He shares practical use cases for AI in CTI—including automated script decoding, hunting query creation, and streamlining repetitive metadata-labeling tasks. Jake also discusses the concept of "judge agents" for quality control, the implementation of structured analytic techniques, and how real-time AI assistants can accelerate on-boarding and domain transitions for frontline threat analysts.

Apr 27, 2026 • 29min
Google's Disruption Mission
Host Luke McNamara is joined by Charley Snyder, Head of Disruption Operations at Google Threat Intelligence Group, to delve into how Google is crafting a more coordinate approach to disrupting adversary cyber operations. Charley describes how this disruption focus is not hacking back, how it builds on existing work across Google security teams, and some of the recent wins such as the IPIDEA and GRIDTIDE takedowns.

Apr 15, 2026 • 28min
Takeaways from the 2026 M-Trends Report
Host Luke McNamara is joined by Chris Linklater, Practice Leader at Mandiant, to discuss the 2026 edition of Mandiant's M-Trends Report. Chris dives into the latest trends observed in breached throughout 2025 and into this year, noting some of the key aspects organizations should focus on in applying these insights into today's threat landscape. https://cloud.google.com/security/resources/m-trends

Mar 23, 2026 • 30min
Using GTI to Hunt Adversaries on the Dark Web
In this episode of the Defenders Advantage Podcast, host Luke McNamara sits down with Google Threat Intelligence experts Jose Nazario and Brandon Wood. They dive into the rollout of new dark web and underground monitoring capabilities, explaining how AI is fundamentally changing the way defenders track adversaries.https://cloud.google.com/blog/products/identity-security/bringing-dark-web-intelligence-into-the-ai-era\

Jan 16, 2026 • 32min
How Android Combats Mobile Scams
Host Luke McNamara is joined by Eugene Liderman, Senior Director in Android's Security and Privacy Group, to discuss the evolving world of mobile-targeting scams. Eugene details some of the unique aspects to mobile scams, regional variations in tactics by scammers, and the steps Android has taken to combat this problem.

Oct 22, 2025 • 26min
UNC5221 and the BRICKSTORM Campaign
Sarah Yoder (Manager, Mandiant Consulting) and Ashley Pearson (Senior Analyst, Advanced Practices on Google Threat Intelligence Group) join host Luke McNamara to discuss UNC5221 and their operations involving BRICKSTORM backdoor. This highly sophisticated, suspected China-nexus cyber-espionage threat group is known for aggressively targeting internet-facing network appliances (like VPNs and firewalls) to establish long-term, stealthy access for espionage.Read our blog post for more: https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign

17 snips
Sep 15, 2025 • 39min
How vSphere Became a Target for Adversaries
In this discussion, Stuart Carrera, a Senior Consultant at Mandiant with deep expertise in vSphere security, reveals why threat actors are now targeting VMware environments. He highlights how vSphere's unique features, like AD integrations and the absence of effective detection tools, make it appealing for ransomware and espionage. Stuart shares tactics used in attacks, including backdoors and rapid ransomware execution. He also offers practical hardening tips, urging organizations to treat vSphere as a crucial asset to mitigate risks effectively.

5 snips
Aug 18, 2025 • 26min
AI Tools and Sentiment Within the Underground Cyber Crime Community
Michelle Cantos, a Senior Analyst at Google Threat Intelligence Group, dives into the dark world of underground cybercrime. She reveals how deepfake technology is exploited for creation and monetization, shedding light on the complex landscape of illicit AI tools. The podcast discusses how threat actors leverage customized AI models, transforming conventional crime into sophisticated operations. Additionally, Cantos explores customer reviews in these marketplaces, highlighting the duality of satisfaction and deception among cybercriminals.


