Page de couverture de The Adversarial Podcast

The Adversarial Podcast

The Adversarial Podcast

Auteur(s): Jerry Perullo Sounil Yu Mario Duarte
Écouter gratuitement

À propos de cet audio

Join former ICE:NYSE CISO Jerry Perullo, former Snowflake CISO Mario Duarte, and former JupiterOne CISO and Bank of America leader Sounil Yu as they dive into the good, the bad, and the ugly in the latest cybersecurity news. Each week, we discuss the most pressing headlines, offer candid commentary, and share unique insights from our extensive experience in the field.

Adversarial Risk Management
Économie
Épisodes
  • Adversarial Podcast S4E08 – Shai-Hulud worm strikes again, critical React vuln, CrowdStrike insider threat
    Dec 9 2025

    00:00 Intro

    02:33 Shai Hulud 2.0

    17:12 Max severity React vulnerability

    29:23 CrowdStrike catches insider feeding information to hackers

    46:24 Anthropic disruptes AI-orchestrated cyber campaign

    52:35 Uncertain economy takes effect on cyber teams

    Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact

    Researchers report that Shai-Hulud 2.0 is an ongoing npm supply-chain worm that has compromised hundreds of packages and tens of thousands of GitHub repositories and siphoned secrets through CI/CD pipelines.

    Critical React Server Components Vulnerability CVE-2025-55182

    React vulnerability React Server Components (RSC) — tracked as CVE-2025-55182 — is a critical (CVSS 10.0) flaw that allows unauthenticated attackers to execute arbitrary code on servers just by sending a crafted HTTP request to vulnerable packages.

    CrowdStrike catches insider feeding information to hackers

    CrowdStrike caught an insider who had secretly shared screenshots of internal systems with hackers linked to Scattered Lapsus$ Hunters — though the company says no breach of its infrastructure occurred and no customer data was compromised.

    Comcast's 2025 Cybersecurity Threat Report

    Comcast Business’s 2025 Cybersecurity Threat Report finds that over the 12-month period ending May 31, 2025 the company recorded 34.6 billion cyber events — including 4.7 billion phishing attempts, 9.7 billion “drive-by” compromise attacks, 44,000 DDoS attacks, and 19.5 billion resource-development activities.

    Disrupting the first reported AI-orchestrated cyber espionage campaign

    Anthropic reports disrupting what it assesses to be the first large-scale, AI-orchestrated cyber espionage campaign, in which a Chinese state-linked group jailbroke Claude Code to autonomously conduct reconnaissance, exploit vulnerabilities, and exfiltrate data across dozens of global targets with minimal human involvement.

    Uncertain Economy Takes Toll on Cybersecurity Teams

    Economic uncertainty has hit corporate cyber operations: Artico Search and IANS Research report that cybersecurity budgets rose just 4% in 2025 (a five-year low), hiring growth slowed to 7% (down from 12% in 2024), and many security-teams are grappling with tighter budgets, fewer hires, and slower wage growth.

    Hosts:

    Jerry Perullo (Founder, https://adversarial.com/)

    Sounil Yu (Founder, https://www.knostic.ai/)

    Mario Duarte (Founder, stealth startup)

    Producer: Tillson Galloway (Founder, http://githoundexplore.com/)

    Voir plus Voir moins
    1 h et 2 min
  • Adversarial Podcast S4E07 – The password is "Louvre", AI ransomware, Nevada stands up to ransomware
    Nov 11 2025

    00:00 Intro

    01:50 Louvre password

    08:54 Trump budget cuts

    20:35 Google AI threat report

    36:56 Nevada didn’t pay ransom

    48:25 Moved the needle

    58:38 L3Harris Trenchant boss stole exploits, sold to Russia

    62:00 Ransomware remediation firm employees go rogue

    63:40 Cybersecurity Is A Digital Identity Problem And We Must Deal With It

    The password for the Louvre’s video surveillance system was “Louvre”

    The Louvre Museum reportedly had a video-surveillance server password of simply “LOUVRE” as early as 2014..

    Trump budget cuts, agency gutting, leave Americans and economy at greater risk of being hacked, experts warn

    Budget cuts under Donald Trump’s administration are slashing funding and staff at key federal cybersecurity agencies like CISA, increasing the risk of U.S. vulnerability to cyberattacks.

    GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog

    Adversaries are now deploying AI-enabled malware (such as self-modifying code) and exploiting underground AI tool markets across the full attack lifecycle.

    Nevada didn’t pay ransom in statewide cyberattack, spent $1.5M on response

    The State of Nevada did not pay the ransom after a statewide cyberattack, opting instead to spend approximately $1.5 million on response efforts.

    How an ex-L3Harris boss stole and sold cyber exploits to Russia

    A former L3Harris division boss admitted to stealing eight zero-day exploits from network and selling them to a Russian cyber-tool broker.

    Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says

    A Chicago-based ransomware response firm is under indictment after employees allegedly conducted five ransomware attacks of their own.

    Cybersecurity Is A Digital Identity Problem And We Must Deal With It

    Cybersecurity failures increasingly stem from weak or mis-managed digital identities, and organizations must shift their focus from endpoints to identity-first strategies.

    Hosts:

    Jerry Perullo (Founder, https://adversarial.com/)

    Sounil Yu (Founder, https://www.knostic.ai/)

    Mario Duarte (Founder, stealth startup)

    Producer: Tillson Galloway (Founder, http://githoundexplore.com/)

    Voir plus Voir moins
    1 h et 14 min
  • Adversarial Podcast S4E06 – F5 Breach, AWS Outage, Risk Management vs. Security Engineering
    Oct 28 2025

    00:00 Intro

    00:50 AWS Outage

    20:48 F5 Breach

    41:06 Risk Management vs. Security Engineering

    58:19 Moving the Needle Part 3

    F5 Hack Blamed on China

    Chinese state-backed hackers allegedly breached U.S. cybersecurity firm F5, gaining year-long access to its systems and BIG-IP source code, prompting security fears and causing the company to warn of revenue impacts and falling shares.

    AWS Outage

    A race condition in Amazon DynamoDB’s DNS management system caused widespread outages across the US-EAST-1 region on October 19–20, 2025, disrupting DynamoDB, EC2, NLB, and multiple dependent AWS services until recovery was completed the next afternoon.

    The CISO Dilemma: Risk Management vs. Security Engineering

    This post argues that quantitative risk management (QRM) in cybersecurity is a deceptive comfort mechanism that lets executives rationalize insecurity, urging CISOs to reject financialized “risk buy-downs” and instead demand true security engineering and systemic architectural integrity.

    Hosts:

    Jerry Perullo (Founder, https://adversarial.com/)

    Sounil Yu (Founder, https://www.knostic.ai/)

    Mario Duarte (Founder, stealth startup)

    Producer: Tillson Galloway (Founder, http://githoundexplore.com/)

    Voir plus Voir moins
    1 h et 12 min
Pas encore de commentaire