ZeroSum

ZeroSum

Aaron Mog
Land USA
Språk EN
Episoder 4
Siste 14.09.2026

ZeroSum is a cybersecurity podcast that discusses the state of the industry honestly, rejecting typical threat-of-the-week news. It uses game theory to examine how the cyber market often leaves practitioners losing while VC gambles win. The show features guests from various perspectives, including vendors, investors, workers, and CISOs.

Episoder

  • AI, Ransomware, & The Security Poverty Line - with Randy Rose 14.09.2026 59min
    Is AI closing the cybersecurity gap between big cities and small towns — or leaving under-resourced communities even further behind?In this episode of ZeroSum, Aaron sits down with Randy Rose, Vice President of Security Operations & Intelligence at the Center for Internet Security (CIS), to expose what's actually happening on the front lines of state and local government cybersecurity.Randy leads the operational missions of the MS-ISAC (Multi-State Information Sharing & Analysis Center). We dive into how ransomware crews are targeting rural school districts, why threat actors are using AI to clone writing styles for phishing, and why treating AI as a "prediction engine" rather than intelligence fundamentally changes your defense strategy.If you are a security practitioner, local government leader, or trying to break into the industry, this episode breaks down the realities of the security poverty line and what happens when a threat actor picks a small town for a payday.🎯 What we cover:The security poverty line — and why AI might not fix itHow threat actors use generative AI for highly convincing phishing and BEC emailsThe real human cost when ransomware hits a rural hospital or school districtWhy "it's just a prediction engine" matters more than you thinkActionable advice for people trying to break into cybersecurity right now⏱️ Chapters:00:00 Cold Open01:21 Introduction to the Cybersecurity Landscape03:21 State vs Local Government Cybersecurity06:13 Understanding the Multi-State ISAC10:20 The Role of ISACs in Cybersecurity12:00 Challenges Faced by Local Governments14:50 AI's Impact on Cybersecurity20:04 Ransomware and Business Email Compromise24:35 Operational Technology and Municipal Challenges25:51 Generative AI: The Great Democratizer?32:26 Leveraging AI for Cybersecurity Skills32:58 The Complexity of AI in Cybersecurity35:52 Wisdom vs. Intelligence in Cybersecurity40:11 The Growing Challenge of Cybersecurity46:16 Building a Strong Cybersecurity Foundation53:18 Advice for Aspiring Cybersecurity Professionals🎙️ ZeroSum is a cybersecurity and AI podcast hosted by Aaron and Randy, digging into the real conversations security practitioners are having about AI, risk, and the future of the industry.#Cybersecurity #ArtificialIntelligence #Ransomware #InfoSec #ZeroSumPodcast
  • The AI Hacker Myth - with Silas Cutler 07.09.2026 58min
    Is artificial intelligence actually creating a new breed of super-hackers, or is the industry just selling panic?In this episode of the Zero Sum Podcast, Aaron sits down with Silas Cutler, one of the top security researchers in the industry and a Principal Reverse Engineer at Censys. Silas strips away the corporate marketing hype to reveal what threat actors are actually doing in the wild. They dive deep into the economic realities of cybercrime, how Russian military intelligence (APT28) hijacks criminal botnets, and the deadly, real-world risks of private companies legally "hacking back" against ransomware cartels.Whether you are a seasoned threat intel analyst, a security leader trying to understand the AI landscape, or an aspiring researcher looking to break into the field, this conversation provides a rare, unfiltered look into the trenches of cybersecurity.Timestamps / Chapters:00:00 - Intro: Welcoming Silas Cutler to Zero Sum01:36 - The State of Security Research Today04:15 - Why Research is Underfunded (And Why That's Okay)07:44 - Debunking the AI "Vulnerpocalypse" Hype13:54 - How Threat Actors Actually Scale Their Operations18:24 - Team PCP & The Rise of Supply Chain Attacks22:00 - Google's "Beautiful Paranoia" vs. Unprepared AI Startups29:12 - Is Ransomware a "Solved Problem"?32:01 - Unmasking Russian APT28 and the Moobot Hijack38:30 - Red on Red: When Cybercriminals Hack Each Other39:53 - Letters of Marque & The Deadly Reality of "Hacking Back"50:40 - Career Advice: How to Break Into Threat ResearchFollow Zero Sum & Our Guest:Subscribe to the Zero Sum Podcast: https://www.youtube.com/@zerosumpodcastFollow Silas Cutler on X / LinkedIn / MastodonHosted by Aaron Mog
  • What AI Just Exposed About Your Data - with Ward Balcerzak 31.08.2026 58min
    An employee typed his own name into Copilot and found out he was on the layoff list.Nobody hacked anything. Years earlier someone had used "share with all" in SharePoint, back when nobody could realistically guess the link. Then AI made everything trivially findable.Ward Balcerzak is Field CISO at Sentra with nearly two decades in data security across Accenture, Allstate, Carbon Black, and Fidelity National Financial, where he led data protection and insider risk programs. He also hosts the Guardians of the Data podcast.Aaron and Ward get into what data security looks like now that every employee is pasting company data into tools nobody approved. Ward's argument: the work organizations skipped for years — data discovery, classification, access hygiene — is exactly what AI is now dragging into the light.He also makes a contrarian case for protecting less. Nine times out of ten, the data companies are frantic about isn't special at all. Figure out what actually makes you different, find out who really has access to it, and start there.They cover why DLP earned its bad reputation, what to do when your tools hand you a million findings and no way to act on them, why regulators always arrive last, and why networking is now non-negotiable even for people who got into this field specifically to avoid people.Guest: Ward Balcerzak, Field CISO at Sentra. Find him on LinkedIn, at wardbalcerzak.com, or on the Guardians of the Data podcast.⏱️ CHAPTERS00:00 Intro01:25 Twenty years of being wrong about what catches on04:39 Can AI actually save data security?09:30 The era of YOLO security12:00 "AI readiness" and why nobody's ready14:43 Sins of the past, now with petabytes17:06 Are companies building their own models?26:30 It's not a cat anymore, it's a mountain lion28:16 The rigged casino of AI watermarking29:24 Where are the actual wins?30:59 Nine times out of ten, your data isn't special33:48 Who actually has access?35:09 The Copilot layoff list story37:06 A million findings and no idea what to do45:33 Forcing the conversations nobody wants to have47:21 What to tell a 22-year-old today50:26 Network, even if you got into this to avoid people54:47 Pitch slapping and the value of being real56:03 Where to find Ward#cybersecurity #datasecurity #AI #infosec #CISO
  • Why Every Cyber Company Sounds the Same - with Joel Benge 24.08.2026 1t 1min
    Every CISO or engineer who's ever been told no by a board should watch this.Joel Benge spent years as the communications lead for the Department of Homeland Security's CISO office before writing "Be a Nerd That Talks Good." He's spent his career on one problem: getting technical people the budget, the headcount, and the buy-in they deserve — and figuring out why they so often don't get it.Aaron and Joel get into why most board decks fail before slide three, the "blank stare moment" that happens when you overload your audience, and the reframe that changes everything: you're not the hero of your pitch — you're Obi-Wan, and the person you're asking is Luke. Plus why the stories you least want to tell (the failures, the things you tried that didn't work) are the ones that actually build trust.They also get into why every vendor booth at Black Hat says the exact same thing, why "we prevent hacks" is a Gartner category and not a big idea, and how to align a security ask to something the business already cares about — instead of another slide full of blocked-attack metrics nobody reads.If you've ever needed a million dollars for a program and walked out with nothing, this is the episode.Guest: Joel Benge, author of "Be a Nerd That Talks Good." Find him at nerdthattalksgood.com or on LinkedIn — the intro and first chapter are free, no email required.⏱️ CHAPTERS00:00 Intro02:09 Where the community is right now06:13 Standing out in the sea of sameness12:00 Stop copying each other's homework13:10 "I can tell your content is AI"15:08 "Live, laugh, love" and the Gartner-category trap17:30 Mind, gut, heart25:53 The stories founders refuse to tell30:12 Why heart is what cyber gets worst32:22 Finding the real big idea34:09 Second- and third-order benefits38:11 CISOs, boards, and getting budget39:04 The blank stare moment48:24 You're Obi-Wan, not the hero52:35 We made CEOs the heroes and forgot customers55:00 Aligning security to what the business values56:06 "More scared of their company than the bad guys"57:18 Where to find Joel#cybersecurity #CISO #infosec #leadership
  • I'm Not AGI Pilled. I'm Human Pilled - with Casey Ellis 18.08.2026 1t 3min
    "You know who will be hiring juniors again? Bad guys."Casey Ellis founded Bugcrowd and launched the first bug bounty programs on it back in 2012, pioneering crowdsourced security as a service. He co-founded disclose.io, sits on the Black Hat and DEF CON Policy review boards, and now runs Tall Poppy Group, angel investing and advising the next generation of security startups.Fresh off a week at Black Hat, B-Sides, and DEF CON, Casey joins Aaron for a wide-ranging conversation about what he actually heard on the ground — and why the mood at each of those three conferences was completely different.We get into the "slopdemic" (Casey's term for AI-generated vulnerability reports drowning the ecosystem), why he's "human pilled" rather than AGI pilled, and his read on the White House memorandum he's calling the privateering order — what it actually authorizes, and who's really going to use it. Plus: why pen test firms are about to have a very hard time defending their value, why every company already has a vulnerability disclosure program whether they know it or not, and the hygiene fundamentals that still contain the blast radius when everything else fails.The last stretch is the one worth staying for — a genuinely urgent case for why the industry's "we're never hiring juniors again" moment is a gift to the people recruiting them instead.Guest: Casey Ellis, founder of Bugcrowd and disclose.io, principal of Tall Poppy Group. Find him on LinkedIn.⏱️ CHAPTERS00:00 Intro02:35 Coming out of Black Hat, B-Sides, and DEF CON06:33 Why DEF CON was allergic to the AI hype09:35 Hybrid conflict is already here10:53 Royalty in the palace, villagers at the gate12:16 Security below the poverty line13:14 "I'm not AGI pilled. I'm human pilled."14:51 Do stupid things faster with more energy19:04 What people get wrong about AI and exploitation21:43 The slopdemic and the vulnpocalypse25:07 What it takes before anything actually changes28:48 Nobody is coming to save you33:02 What actually works if you start from scratch today37:34 Why pen test is in for a ride39:13 Hygiene, blast radius, and the boring basics43:31 The privateering memorandum48:26 Who's actually waiting to hack back?51:24 What to tell a 22-year-old today53:21 It's really easy to do crime55:08 Community, disclose.io, and knowledge transfer58:01 The industry needs to give back60:45 "Who will be hiring juniors again? Bad guys."61:11 Tall Poppy Group and where to find Casey#cybersecurity #infosec #AI #bugbounty #DEFCON
  • Top 5 BlackHat Takes - with Aaron Mog 12.08.2026 25min
    I've been going to BlackHat since 2001. This year, the scariest thing on the floor was a booth almost nobody was crowding.Fresh off plane from Vegas, this is a solo ZeroSum episode — no guest, just my top 5 takes from the week. The throughline: the industry is running on hype and extraction, while the one real capability shift sat in plain sight.We get into build vs. buy flipping, the "ask me about Mythos" cargo cult, how transactional the show floor has become, the total absence of anything new, and the modest OpenAI booth that quietly made the case it could eat half the vendors in the hall.Chapters:00:00 Intro — 25 years of Black Hat, from 200102:24 Take 1: "We'll just build it ourselves"04:48 Take 2: Ask me about Mythos06:52 Take 3: Everyone's selling the same thing17:00 Take 4: 400 booths, zero controversial statements18:58 Take 5: The Amazon-in-the-corner boothListen anywhere — search "ZeroSum" on Spotify and Apple.What did you take away from Black Hat this year? Drop it in the comments.#BlackHat #Cybersecurity #AI #InfoSec #ZeroSum
  • Malware Moves in 27 Seconds. Humans Can't Keep Up - with Graham Westbrook 04.08.2026 1t 1min
    Malware used to take 18 minutes to move through your network. Now it takes 27 seconds. Humans can't respond fast enough anymore.Graham Westbrook is VP of International Markets at SimSpace — the "AI Proving Grounds" for cybersecurity — with a background spanning DoD/DISA, CrowdStrike, Flashpoint, and a postgrad in AI from Oxford. Aaron sits down with him for a genuinely global, big-picture conversation about where AI security is actually heading — not from Silicon Valley, but from the ministries of defense, critical infrastructure operators, and enterprises he works with around the world.We get into why "legacy SOC is no longer sufficient" and the shift from human-in-the-loop to AI-first defense, why governments and banks will build their own models on their own data instead of renting from OpenAI or Anthropic, and the case for preemptive defense — forecasting and patching attacks before they happen, the way Google forecasts weather. Plus: the "zero day clock" racing toward minutes, why finding more vulnerabilities is a dead end, whether AI's benefits will ever reach smaller organizations or just the giants, and why Graham thinks an AI market crash is coming — and what that means for anyone entering the field.Guest: Graham Westbrook, VP International Markets at SimSpace. Find him on LinkedIn @ https://www.linkedin.com/in/graham-westbrook/⏱️ CHAPTERS00:00 Intro01:57 Where the world actually is on AI (hint: behind)04:06 Battlefield AI and preemptive cyber defense06:23 Why every nation will need its own model09:48 AI, layoffs, and the "data shepherd" future11:12 What enterprises are actually doing today14:14 The 27-second breakout and why humans can't keep up16:09 The zero day clock and forecasting attacks like weather24:58 Building a digital replica of your organization29:33 Will AI's benefits ever reach the little guy?32:49 The arms race with China55:37 Getting high on your own supply — the coming crash56:42 Advice for anyone entering cybersecurity
  • AI Is Better at Hacking Than He Is, and He's Not Worried - with Scott Behrens 29.07.2026 58min
    He's an L8 Principal Engineer at Netflix — the kind of technical leader the company puts on the problems that decide whether it wins or loses. And he just watched AI out-hack him.Scott Behrens is an L8 Principal Security Engineer at Netflix, where over 11 years he's watched the security team grow from a handful of people to over a hundred. Today he's the technical lead for Netflix's Live product security, its Attack Emulation Red Team, and its DDoS research. He joins Aaron for one of the most honest, forward-looking conversations we've had about what AI actually does to security work, and to the people who do it.Scott doesn't sugarcoat it: he sat down with the latest models and quickly concluded they're better at finding and exploiting vulnerabilities than he is. But instead of doom, he lays out why that's an opportunity and where humans still hold the irreplaceable edge.We get into why the model matters less than the "harness" you build around it, the idea that human intention and hard-won wisdom are the most valuable resources in the AI race, and what actually happens when your discovery tools start surfacing thousands of real vulnerabilities you now have to fix. Plus: how AI is quietly making security the easiest story he's ever had to tell, the one-line trick that cuts vulnerabilities in AI-written code, and why the best security engineers are becoming systems thinkers, not bug-finders.Guest: Scott Behrens, L8 Principal Security Engineer at Netflix. Find him on LinkedIn and read his newsletter, The Engineer Setlist, on Substack.⏱️ CHAPTERS00:00 Intro01:57 Excited, worried, and humbled all at once04:16 Don't just do the old things faster07:30 Should security teams fix the bugs, not just find them?09:30 Human intention is the most valuable resource in the AI race10:16 The "wisdom" AI doesn't have12:22 Systems thinking as the human edge18:14 Why the harness matters more than the model20:25 Codifying 20 years of expertise into a harness23:41 You built the harness — now what do you do with the findings?25:32 What small and mid-size businesses should actually do27:35 The one-line trick that cuts vulnerabilities in AI code30:41 Rethinking the front end, WAFs, and detection32:45 The "isadmin=false" honeypot trick51:50 The era of YOLO security53:09 Security as an enablement function55:04 "The easiest story I've ever had to tell"56:34 Where to find Scott#cybersecurity #infosec #AI #Netflix #appsec
  • Why Security Always Failed and What Finally Changes That - with Justin Somaini 27.07.2026 59min
    For 30 years, the security industry could never fully win. Justin Somaini explains what finally changes that.Justin Somaini is one of the people who helped define the modern CISO role — former CISO of Symantec, Yahoo, SAP, and Box, and now a Partner at YL Ventures. In this episode, Aaron sits down with him for a genuinely optimistic conversation about why security has always fallen short, and why he believes we're at the most exciting inflection point in the industry's history.Justin lays out his core thesis: security has never truly succeeded because of two structural problems — you can never hire enough people to review everything, and the industry never solved the "shared accountability" gap with engineering and IT. For the first time, he argues, AI can absorb the enormous amount of pattern-matching work that's always overwhelmed security teams — letting them finally operate at the scale the business actually demands.We also get into how he learned to separate real founders from the hype (and the belief he had to unlearn), why "drop the first slide" is his number one pitch advice, how CISOs actually make buying decisions versus what they claim, and his honest take on where the funding market is heading. Plus: the first CISO ever, why word-of-mouth beats every marketing tactic, and what makes a startup worth betting on.Guest: Justin Somaini, Partner at YL Ventures. Find him on LinkedIn or on his podcast, Somaini Trust Issues.⏱️ CHAPTERS00:00 Intro01:38 Learning from Steve Katz, the first CISO ever04:03 Why a 30-year veteran is optimistic right now05:23 Why security has always failed — the two real reasons07:42 How AI absorbs the work that overwhelms security teams10:03 How to separate real founders from the hype13:13 Salesperson, or a product engineer faking it?16:15 "Drop the first slide" — fixing the founder pitch18:20 Why first-time founders are like teenagers22:10 The funding market and where it's headed28:12 Need-to-have vs. nice-to-have36:42 How CISOs actually make buying decisions52:00 How to get anyone to care about what you're building57:04 Where to find Justin
  • The Haystack Got Bigger. The Needles Didn't - with Ed Bellis 22.07.2026 50min
    The haystack got bigger. The needles didn't. Ed Bellis on why the vulnerability problem stopped being human-scale.Ed built Kenna Security, sold it to Cisco, and is now back with Empirical Security, building custom AI models that predict which vulnerabilities will actually get exploited in your environment — not just which ones score high on a generic global list. He joins Aaron for a candid conversation about what AI is really doing to the vulnerability landscape, the security talent pipeline, and the funding environment.We cover why AI is producing more code than ever and more vulnerable code than ever, what Anthropic told him about not hiring junior devs anymore ("what happens when the seniors time out?"), why every organization needs a model trained on its own environment, and where startups still win against Microsoft and Google. Plus: why raising $180M in a seed round quietly kills your optionality, the "fast no," and the Chicago startup problem.Guest: Ed Bellis, CEO of Empirical Security → empiricalsecurity.com⏱️ CHAPTERS00:00 Intro01:20 Coming off a raise — what it actually changes03:22 What money doesn't fix05:02 The mistakes he won't repeat from Kenna07:47 Why a huge seed round kills your optionality09:03 Is private equity coming for cyber?12:48 Why every company needs its own model17:22 Is it just YOLO security now?18:28 The haystack got bigger, the needles didn't20:25 AI, remediation, and operational risk23:45 Anthropic doesn't hire junior devs anymore26:19 If you take the bottom rung out of a ladder30:42 Advice for a 22-year-old entering cyber32:57 Cutting through the noise at Black Hat36:47 Why he loves a "fast no"37:26 The Chicago startup problem39:22 Where startups fit against Microsoft and Google43:47 Build vs. buy: should you train your own models?49:02 Where to find Ed#cybersecurity #infosec #AI #vulnerabilitymanagement #startups
  • We Don't Need to Throw Out Security, We Need to Update It. - with Diana Kelley 14.07.2026 1t
    "We don't need to throw out what we've been doing all of our careers. We just need to be AI-aware in how we apply it."Diana Kelley — CISO at Noma Security, formerly CISO at Protect AI, and a 25+ year veteran of Microsoft, IBM, and Symantec — joins Aaron for a grounded conversation on what actually changes, and what doesn't, when AI enters security.We cover why trust boundaries and identity are still the job even as AI reshapes the attack surface, why the LLM itself can't function as a trust boundary, the shadow AI sprawl most CISOs haven't gotten a handle on, and the identity mess created by agents inheriting permissions from whoever spins them up. Plus: does AI actually level the playing field for builders, or just make the biggest players bigger?Guest: Diana Kelley, CISO at Noma Security.⏱️ CHAPTERS00:00 Intro01:34 Nearly four decades in security — where are we right now13:23 The labs stole the data to begin with22:19 Shadow AI sprawl and the identity problem28:21 First principles: trust boundaries, not a full rewrite39:18 Are the frontier labs going to crush every startup?42:52 AI, equality, and who gets left behind55:56 Where to find Diana and get involved#cybersecurity #CISO #AI #infosec
  • Is Anybody Safe? Adaptability in the Age of AI Disruption - with Mark Carney 07.07.2026 1t
    Is any security company safe from AI disruption? Evolve Security CEO Mark Carney's answer: no and that's the wrong question anyway.Aaron talks with Mark Carney, CEO of Evolve Security and one of the OG figures in security services, about where the industry sits at a genuine inflection point. Mark breaks down why tech-enabled services are hotter than ever while human-only services are a dying breed, and how private equity now runs "AI disruption due diligence" before writing big checks.We get into:Why finding vulnerabilities became a commodity — and where the real value lives nowWhy Evolve deliberately isn't using AI for autonomous exploitation yetThe 50% false-positive problem with autonomous pen testing toolsAttack chains, business logic, and prioritizing high-impact exposuresChartering an "autonomous enterprise" across every business functionThe death of tasteful outbound and the abuse of the CISO relationshipCareer advice for a tough market: deliver outcomes, not activityGuest: Mark Carney, CEO of Evolve Security. Find him at evolvesecurity.com or on LinkedIn.
  • The Scariest Story a CISO Has Ever Told the Board - with Jason Loomis 07.07.2026 58min
    "This is the scariest story I've ever had to tell my board."CISO Jason Loomis on what AI is really doing to security teams.Aaron sits down with Jason Loomis for a raw, funny, unfiltered conversation about AI's impact on security teams, careers, and the humans caught in the middle. Jason lays out his "farm team" problem: the tier-one SOC, GRC, and help desk roles that grow new talent are being automated away and he's brutally honest with his own team about it.We get into:Why the security fundamentals haven't changed in 20 years, even as velocity explodesThe hype gap between vendor promises and enterprise realityVulnerability chaining in the era of frontier modelsWhy AppSec is the problem actually worth solvingThe build-vs-buy debate for security toolingA myth-busting rant on AI data paranoia and security theaterWhy "security is a revenue generator" is a line CISOs need to stop repeatingGuest: Jason Loomis, CISO at Freshworks and co-host of the new "Gen and Tonic" podcast. Find him on LinkedIn (no pitch-slapping, please).
  • The Cyber Industry Is Moving Fast but Chasing the Wrong Things - with Cris Neckar 07.07.2026 59min
    The cyber industry is moving faster than ever and Cris Neckar thinks it's chasing the wrong things.In the debut episode of Zero Sum, host Aaron Mog sits down with Cris Neckar, security researcher turned entrepreneur turned VC at Two Bears Capital in Whitefish, Montana. Cris traces his unusual path from hardcore offensive work to venture capital, and explains why the biggest roadblocks in security aren't technical but structural: broken incentives, revenue-first boards, and founders who fall in love with cool tech instead of customer problems.We get into:The "scientist vs. salesman" failure mode that kills early-stage security startupsWhy Cris's first diligence question is always "let me talk to your customers"How the Cursor playbook rewrote the rules of company-buildingHow elite hackers use AI as a force-multiplier, not a replacementWhy "nobody wants to buy more red on a dashboard"FinOps for AI spend, compliance-as-collateral, and betting on power and data centersGuest: Cris Neckar, Partner at Two Bears Capital. Connect on LinkedIn or pitch via the Two Bears website.Cris is a Partner at Two Bear Capital.  The views he expresses are his own and do not necessarily reflect the views of TBC or its partners.
  • Breaking In, Standing Out, and Becoming a "Data Shepherd" — with Wade Wells 07.07.2026 53min
    Entry-level security jobs are vanishing so how does anyone break in now? Detection engineer and educator Wade Wells has thoughts.Detection engineer, educator, and B-Sides San Diego organizer Wade Wells joins Aaron for a practical, honest look at entering and surviving in security today. Wade, who teaches cybersecurity students across all levels, admits the field moves so fast he can no longer confidently tell students what to do, since even the old advice can now be faked with AI.We get into:Why networking and a genuine community footprint beat a perfect résuméThe collapse of entry-level roles and the patience the job market now demandsThe "AI slop" problem: people submitting work they never readWhy everyone is becoming a developer — or a "data shepherd" who validates what AI buildsThe reckless reality of businesses uploading confidential data to AIThe coming "AI living off the land" attack and the yes-but approach to securityGuest: Wade Wells, detection engineer and B-Sides San Diego organizer. Catch him at DEFCON or on LinkedIn and Twitter — just mention where you found him.

Populær i

Denne podkasten finnes også i podkast-listene til disse landene.