The Cyber Threat Perspective
SecurIT360
0
Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. The podcast brings fresh content from their journeys into penetration testing, threat research, and various other interesting topics. It is hosted by Brad, who can be reached at [email protected].
Jaksot
-
[Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers 11.09.2026 31minReplay of Episode 178, originally published April 22, 2026. We are re-running this one because it is the question we get asked most on internal pen test debriefs: of everything on the list, what actually slows an attacker down? Spencer and Tyler answer it from the attacker side, using what has and has not stopped them on real engagements. What's covered: - Application control done right, including where ThreatLocker and WDAC actually block a payload and where they get bypassed - MFA... -
Every IT Team Has a Joe | Ep 195 04.09.2026 27minInterested in a pen test? Visit securit360.com. Every organization has a Joe. He is the long tenured engineer or admin who built half the environment, maintains the other half, and keeps most of it in his head. Everybody depends on him and nobody wants to challenge him. Spencer and Tyler break down key man risk in IT, drawing on hundreds of internal pen tests across law firms, banks, credit unions, manufacturing, municipalities, and SaaS organizations. In this episode: Why tribal knowledge is... -
Service Accounts: The Shortest Path to Domain Admin | Ep 194 27.08.2026 32minService accounts are one of the easiest paths to domain admin on an internal pen test, and one of the most neglected accounts in Active Directory. In this episode, Spencer and Tyler break down why service accounts keep falling: Kerberoasting every service account (not just the privileged ones), cracking the hashes offline, and spraying what cracks across the environment. Tyler shares a recent engagement where a non-administrative service account shared its password with a domain admin. Same ... -
Your IT Job Doubled. Nobody Told Your Boss. | Ep 193 20.08.2026 39minIn July 2026, Microsoft alone released 622 CVEs. In the 2010s, the monthly average was about a dozen. Nobody handed IT teams more time, budget, or headcount to match, and that gap is what burnout is actually made of. Somewhere in the last five to ten years, "keeping the lights on" became "and also prevent cyberattacks." Spencer Alessi and Brad Causey talk through how security landed on IT's plate, why capable admins end up feeling like they're failing, and what to do about it when hiring a de... -
Subtractive Security: Stop Adding Tools and Start Deleting Attack Paths | Ep 192 14.08.2026 38minWork with us --> https://www.securit360.com/#contact-anchor The OWASP Subtractive Security Top 10 Project --> https://github.com/OWASP/OWASP-Subtractive-Hardening-Top-10 The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spen... -
The CrowdStrike Settings That Actually Stop Us | Ep 191 06.08.2026 38minTwo pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned. In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire lef... -
Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures 31.07.2026 22minMost cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them? In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compro... -
Episode 189 | OWASP Top 10 Part 3: Software Supply Chain Failures — From SolarWinds to Vibe Coding 24.07.2026 27minAlmost no one writes an application from scratch anymore, and that's exactly the problem. In Part 3 of our OWASP Top 10 series, Brad Causey and Jordan Natter break down A03: Software Supply Chain Failures, the category that climbed to #3 and topped OWASP's own community survey as the vulnerability organizations worry about most. If your team pulls in third-party libraries, buys SaaS, or lets anyone "vibe code" a project, this episode is for you. Brad and Jordan cover both sides of supply chai... -
Guaranteed way to catch threat actors | Ep 188 17.07.2026 31minIn this episode, Spencer and Tyler discuss why deception is one of the best ways to catch threat actors. Resources Spencer's Cyber Deception WebinarSpencer's X posts on the topic of cyber deceptionhttps://thinkst.com/, https://canary.tools/@_subtee on X, @haroonmeer on Xhttps://tracebit.com/Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https:/... -
Avoid this cyber leadership trap | Ep 187 10.07.2026 16minNeed a pentest or vCISO? Work with us! https://www.securit360.com/ A major leadership failure in Cybersecurity is l buying tools first then figuring out where they fit and how to use them. That’s super backwards. Here’s what I would do instead. Plan first, buy & implement second. I’m going to cover just the planning part this week. Next week we will talk about buying and implementing. Because honestly, implementation is where a lot of security teams go wrong. Blog: https://offsec.... -
Episode 186: Real Life Active Directory Attack Paths 03.07.2026 35minIn this episode Spencer and Tyler discuss real life Active Directory attack paths, taken from real internal pentest engagements over the last several years. Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here. -
[Replay] Episode 172: The Biggest Security Blind Spots in Midsized Companies 25.06.2026 33minSome of the most dangerous security gaps aren't sophisticated — they're the ones hiding in plain sight. In this replay, Brad and Spencer break down the biggest blind spots they see over and over in mid-size companies: poor asset inventory, flat networks, flat identities, overconfidence in security tools, credential reuse, and the emerging risks with AI. If any of these hit home, go to our website, fill out the form, and see if we're a fit for you. Blog: https://offsec.blog/ Youtube: https://w... -
Episode 185 | A Toddler with a Bazooka: The Real Risk of AI Agents 18.06.2026 45minAI agents can search the web, manipulate files, run commands, make API requests, access cloud platforms, and operate fully autonomously. They are powerful, they are here, and most organizations have no security controls around them whatsoever. In this episode, Brad and Spencer break down the five major AI agent risk categories security teams need to understand right now, using Simon Willison's "lethal trifecta" as a framework and building on it with two additional risk areas they see in the f... -
Episode 184 | Active Directory Isn't Dead. It's Just Undefended. 11.06.2026 28minThink Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ years. In this episode, Brad and Spencer break down why AD attack paths remain one of the most critical threats in enterprise environments and what defenders can do about it right now. Spencer also previews his ContinuumCon workshop "Killing AD Attack Paths Once and For All" wher... -
Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked 05.06.2026 28minSecurity misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Natter cover OWASP A05: Security Misconfiguration with real stories from recent engagements and practical takeaways for developers, security teams, and organizations of all sizes. In this episode: Hardcoded Active Directory credentials and API keys discovered in a public GitHub r... -
Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR) 27.05.2026 30minHosts Brad Causey and Spencer Alessi break down the 2026 Verizon Data Breach Investigations Report, focusing on the findings that actually matter for IT and security teams. The biggest surprise: vulnerability exploitation has overtaken stolen credentials as the top initial access vector, accounting for 31% of attacks, while credential abuse dropped to just 13%. This completely flips the script on years of "identity is the new perimeter" thinking. Topics covered include: Vulnerability explosio... -
[Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works 20.05.2026 44minWe're re-releasing one of our most practical episodes this week — originally published November 2025, and still one of the best roadmap conversations we've had on the show. Brad and Spencer share no-fluff advice for breaking into cybersecurity, whether you're switching careers, starting from scratch, or leveling up from a general IT role. They cover what employers actually look for, the fastest paths in, and what to skip. If you're exploring a cybersecurity career, or know someone who is, thi... -
Episode 181: AI Zero Days (Google Threat Intelligence Report) 12.05.2026 41minBrad and Spencer break down Google Threat Intelligence Group's latest report on how adversaries are weaponizing AI across the entire attack lifecycle. The big takeaway isn't that AI has magically replaced attackers, but that it's making certain workflows faster, more scalable, and more repeatable. More importantly, AI platforms, agent skills, integrations, and dependencies are now becoming targets themselves. Topics covered include: AI for vulnerability discovery and exploit development: Goog... -
Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry 07.05.2026 29minIn Episode 180, hosts Brad Causey and Spencer Alessi tackle a critical but often overlooked issue in cybersecurity: the echo chambers that can undermine critical thinking and effective security programs. Inspired by recent experiences at the ILTA Evolve conference, Spencer and Brad explore how cybersecurity professionals, from practitioners to executives, can fall into bubbles where everyone reinforces the same ideas without questioning underlying assumptions. Topics covered include: What cyb... -
Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained 30.04.2026 28minIn Episode 179 of the Cyber Threat Perspective podcast, host Brad Causey and web app pen tester Jordan Natter kick off a multi-part series on the OWASP Top 10, the newly updated list of the most common and critical web application security risks, with a fresh version released in 2025. Before diving in, Brad sets the record straight on something that's been bugging him for 20 years: the OWASP Top 10 is an awareness document, not a compliance framework, not a pen test checklist, and not a compr...
Suosittu maassa
Tämä podcast esiintyy myös näiden maiden podcast-listoilla.