Threat Talks - Your Gateway to Cybersecurity Insights
Threat Talks
0
Threat Talks is a cybersecurity podcast that explores the latest threats and industry trends. Each episode features experts breaking down complex topics to make them accessible to both IT professionals and everyday internet users. The show provides in-depth, first-hand experiences from leading cybersecurity professionals. New episodes are released monthly, helping listeners stay informed and secure.
Episódios
-
Lapsus$:Teenagers Hacked Microsoft. 21.09.2026 19minA group of teenagers walked into Microsoft, NVIDIA and Okta. No zero-days. No custom malware. No command and control infrastructure. They bought leaked credentials, or they called the service desk and asked for a password reset.Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with threat researcher Yuri Wit and Field CTO Rob Maas to take Lapsus$ apart step by step: bought credentials, MFA fatigue, over-permissioned accounts, and the extortion payday at the end.The uncomfortable part is not how clever the attack was. It is how basic it was. If your help desk resets passwords without proof of identity, if your MFA is a tap-to-approve prompt, if your users carry permissions from two jobs ago, Lapsus$ did not need to be good. They only needed to try.Yuri and Rob also cover what actually stops this: password resets that require physical identification, hardware tokens for sensitive Protect Surfaces, privileged access management with a human in the loop, and why AI is both the fastest way to audit your permissions and the fastest way to recreate the same over-permissioning problem all over again.Timestamps00:00:00 Hacking the largest companies on earth is super easy 00:01:19 Who Lapsus$ were, and why they are in jail 00:02:25 Step one: bought credentials and a phone call to the service desk 00:03:36 Password resets should be a hurdle, not a link 00:06:16 Not all MFA is equal: push fatigue, SMS and SIM swapping 00:09:03 Why your second factor does not belong in your password manager 00:11:09 Inside the network: privilege escalation, exfiltration, extortion 00:13:29 The fix: least privilege, PAM and a human in the loop 00:16:05 AI as auditor, and the agentic over-permissioning problemKey Topics CoveredHow Lapsus$ obtained initial access without a single novel technique: dark web credentials and social engineering of the help deskWhy MFA type matters more than MFA presence, and where push approval, SMS and TOTP each breakPrivilege escalation as the real bottleneck for attackers, and what least privilege plus PAM changesZero Trust Protect Surface thinking as the way to decide which control is appropriate for which dataThe AI double edge: faster permission audits on one side, over-permissioned agent service accounts on the other -
How a 19-Year-Old Hacked the NEWS Without Breaking In 15.09.2026 21minYour Outlook account recovery will accept an authenticator code on its own. No password, no inbox, no phone number. Anyone holding that TOTP secret owns the account, and the second factor you bought to survive credential theft becomes the only thing in the way.Koen Kandelaars found one sitting in a PDF on a public help page at the NOS, the largest news organization in the Netherlands. He scanned a QR code out of an onboarding manual and had a real employee's second factor on his phone. Rob Maas, Field CTO at ON2IT, walks the full chain with the attacker himself: eleven vulnerabilities in the first responsible disclosure, a twelfth Koen estimates at 1 to 5 million euros, and the recovery flow nobody tested.Timestamps(00:00) - MFA was on. He got in anyway. (02:04) - Why the biggest news organization became the target (03:24) - Mapping the attack surface before touching anything (04:54) - Eleven findings in the first responsible disclosure (08:50) - The Media Cloud help page and the live TOTP QR code (11:19) - How the password reset removes your second factor (14:29) - The 1 to 5 million euro estimate, and what to fix Key Topics CoveredAttack surface discovery against a large public broadcasterResponsible disclosure done well: response time, remediation, and recognitionWhere the next generation of defenders comes from, and how they choose a sideRelated ON2IT Content & Referenced Resources:Threat Talks: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams -
The End of Reactive Security 08.09.2026 12minYou already had the threat intel. The IP was on your blocklist, the file hash was known bad. So why did your MDR only raise an alert instead of blocking it? Lieuwe Jan Koning, Co-founder & CTO at ON2IT, and colleague Nicholai Piagentini, Technical Enablement Engineer at ON2IT, make the case for preemptive cybersecurity: the shift from detect-and-clean-up to block-first, and what it means for the future of MDR.Timestamps:(00:00) - Preemptive cybersecurity: what it means for MDR (00:59) - Why detect-and-clean-up is not enough (the leaking tap) (01:42) - You knew the threat: block first (03:34) - Fusing the SOC and operations teams (05:57) - Speed, seconds, and AI versus AI (08:15) - Data freedom and vendor lock-in (10:33) - Dynamic policy without breaking change control Key Topics Covered:Preemptive cybersecurity as the Gartner-flagged direction, and why MDR has to move past detect-and-respondTurning known indicators of compromise into automated blocks at the endpoint, network, and cloudCollapsing the SOC and operational teams so detection and enforcement act as oneSub-second response, AI-driven attacks, and why MTTD and MTTR need to convergeData freedom and data sovereignty, and avoiding vendor cloud lock-inRelated ON2IT Content & Referenced Resources:Threat Talks website: https://threat-talks.com/ ON2IT (Zero Trust as a Service): https://on2it.net/ AMS-IX: https://www.ams-ix.net/ams -
NIST CSF 2.0: No CISO, No Excuse 01.09.2026 23minThe new NIST Cybersecurity Framework 2.0 is out, and most teams still ask the same question: what do I do tomorrow? Lieuwe Jan Koning sits down with NIST's Amy Mahn and Daniel Elliott to turn the framework into a concrete next step. Governance is now its own function. Profiles tell you where you are and where you need to be. And the Quick Start Guides give a 15-page answer to a problem most people think needs 300 pages.If you run security with limited resources, this episode shows you where to start and why the whole thing is free.Timestamps00:00:00 The framework changed. What do you do tomorrow? 00:02:00 Why Govern became its own function 00:05:49 Profiles: current state, target state, gap analysis 00:08:08 Community profiles: sharing across a sector 00:10:29 Quick Start Guides and mappings to ISO 27001, SOC 2, HIPAA 00:14:24 No CISO? Where small businesses start 00:17:50 The future of CSF and how to contributeKey Topics CoveredWhy governance moved out of "Identify" and became its own function in CSF 2.0, and what that signals about cyber risk at board level.How organizational and community profiles turn the framework into a current-state, target-state, and gap analysis you can act on.Why CSF 2.0 stopped being a single PDF and became guides, spreadsheets, mappings, and search tools.How CSF maps to ISO 27001, SOC 2, and HIPAA so you report once instead of many times.Where a small business or an IT manager wearing every hat should actually begin.Related ON2IT Content & Referenced Resources: NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework NIST CSF Quick Start Guides: https://www.nist.gov/cyberframework/quick-start-guides National Cybersecurity Center of Excellence (NCCoE): https://www.nccoe.nist.gov/ NIST CSF contact: [email protected] Threat Talks website: https://threat-talks.com/ -
Your SOC Won't Survive AI Attackers Without This Shift 25.08.2026 28minRunning a SOC was always hard. With AI in attackers' hands, hard becomes impossible, unless you change how you work. Rob Maas, Field CTO at ON2IT, sits down with Lieuwe Jan Koning, Co-founder & CTO at ON2IT, on why detection and response no longer buys you time. Open-source AI now finds a way into a portal in about 15 minutes, no pentester required. The fix is preemptive cybersecurity: prevention first, automated countermeasures, and a zero trust culture that turns your SOC from analyst-driven to software-driven, with the analyst still in the driver's seat.Timestamps: 00:00:00 When hard becomes impossible 00:01:37 The biggest change in SOC history 00:05:16 What attackers can now do with AI 00:08:13 Why patching can't be your core defense 00:11:58 The analyst becomes the quality gate 00:13:11 Preemptive cybersecurity, explained 00:24:33 Advice for SOC managers -
Shiny Hunters: One Name Behind a Dozen Mega-Breaches 18.08.2026 14minSalesforce, Google, Okta, Louis Vuitton, Allianz, Odido: all breached under the same name. Shiny Hunters may not even be one group. It is a brand that different criminal crews borrow to extort their victims, because the reputation does half the work.The uncomfortable part is how simple it is. No fancy malware, no zero-days. Almost every documented breach started with a phishing call to the help desk, over-permissive credentials, and data copied straight out of a SaaS platform. Host Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Field CTO Rob Maas and ON2IT researcher Yuri Witt to trace how these attacks land, why the attacker's name never matters to your defense, and the basic controls that stop them: multi-factor authentication, IP access control on your SaaS tenants, no over-permissive accounts, and deleting the toxic data you no longer need.If you run SaaS at scale, treat this as a checklist for the controls most teams still have not switched on.Charpters:00:00:00 One name behind a dozen mega-breaches00:01:06 Shiny Hunters: a group, or a brand?00:04:16 The leak site: extortion as a marketplace00:05:37 How they get in: phishing the help desk00:07:54 Basic defenses: MFA, no admin rights, block downloads00:09:36 Pay up or we leak: the Odido case00:11:24 Lock down SaaS, delete toxic data, and Zero Trust -
HackShield: Raising the Next Generation of Cyber Heroes 11.08.2026 19minThe hacker who will attack your organization in five years is in school right now, and nobody is teaching that kid what to do online. HackShield is trying to change that. Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Tim Murck, co-founder of HackShield, on why security awareness training for adults keeps failing, and what a game built for seven to twelve year olds can teach every CISO about human risk. If your plan is to train 2,000 people to never click the wrong link, this is the episode that explains why you have already lost, and what to do instead. -
The Hacker Who'll Hit You in 5 Years Is in School 04.08.2026 22minThe hacker who will attack your organization in five years is in primary school right now, and nobody is teaching them anything. Tim Murck, Co-founder & Chief Product Officer at HackShield, joins Lieuwe Jan Koning, Co-founder & CTO at ON2IT, to explain how a game turns kids aged 7 to 12 into junior cyber agents instead of future attackers. The method is not fear. It is teaching kids to ask one question: how are they going to trick me?🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: https://threat-talks.com/the-hacker-wholl-hit-you-in-5-years-is-in-school/🎙️ Subscribe on Spotify and Apple Podcasts, links below.Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday.#ThreatTalks #ZeroTrust #cybersecurity #hackshield #securityawareness #cybereducation #kidsonlinesafetyCharpters:00:00:00 The hacker who will attack you is in school now00:00:27 From actor to HackShield: meet Tim Murck00:02:00 The mission: digital scouting for kids 7 to 1200:03:53 Junior cyber agents and the Dutch police00:05:26 Inside the HackShield universe00:10:02 Adversarial thinking and the grooming theme00:13:35 Why age 7 to 12, and the school system's blind spot00:14:53 Ban phones, or teach kids to swim?00:18:42 The numbers: half a million Dutch kids, 850,000 worldwide -
JADEPUFFER: The AI Malware With No Human in the loop 28.07.2026 21minWhat if AI stopped being the assistant to cybercriminals and became the attacker itself? That's no longer hypothetical. JADEPUFFER is the first documented case of ransomware run entirely by an AI agent: it broke into a production database, hit a wall mid-attack, then found another way in within 31 seconds, faster than most human penetration testers can react. Rob Maas, Field CTO at ON2IT, sits down with Yuri Wit, SOC DevOps Engineer at ON2IT, to trace how agentic malware evolved out of AI-assisted attacks into a threat that plans, executes, and pivots entirely on its own.🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: 🎙️ Subscribe on Spotify and Apple Podcasts, links below.Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday.#ThreatTalks #ZeroTrust #firewallsecurity #NetworkSecurity #CyberSecurity #infosec Charpters: 00:00:00 Cold open: can AI become the attacker?00:01:42 PromptLock and PromptSteal: proof of concept to real world00:04:24 The agentic malware trend and the local LLM question00:07:24 JADEPUFFER: ransomware run entirely by an AI agent00:09:58 Proof of concept, or a live-fire test?00:11:30 Intent-driven attacks and shrinking detection windows00:16:34 Zero Trust: what to do about it starting now🔔 Follow and Support our channel! 🔔=== ► YOUTUBE: https://youtube.com/@ThreatTalks► SPOTIFY: https://open.spotify.com/show/1SXUyUEndOeKYREvlAeD7E► APPLE: https://podcasts.apple.com/us/podcast/threat-talks-your-gateway-to-cybersecurity-insights/id1725776520👕 Receive your Threat Talks T-shirthttps://threat-talks.com/🗺️ Explore the Hack's Route in Detail 🗺️https://threat-talks.com🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX -
Four Firewall Mistakes Still Wrecking Networks in 2026 21.07.2026 14minThree out of four firewall rule sets ON2IT’s SOC inherits from new customers share the same blind spots, and none of the fixes cost extra licensing.In this episode, Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Jelle Konings, security optimization specialist in ON2IT’s Security Operations Center, to walk through the mistakes his team finds on almost every inherited network: no logging enabled, no identity tied to traffic, no default deny rule at the bottom of the rule base, and port-based rules standing in for real application control. Most environments he inherits sit around 30 to 40 percent application-based policy coverage against a 60 to 80 percent target.You will hear what to check first when you inherit a firewall, how long a realistic clean-up takes (weeks, months, sometimes over a year), and why an encrypted VPN tunnel riding on port 443 can move data out the door without a single alert firing.🔗 Episode resources, transcript and show notes: https://threat-talks.com 📝 Read the companion blog post: https://threat-talks.com/blog/four-firewall-mistakes-still-wrecking-networks-in-2026/🎙️ Subscribe on Spotify and Apple Podcasts, links below.Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday.#ThreatTalks #ZeroTrust #FirewallSecurity #NetworkSecurity #CyberSecurity #InfoSecChapters: 00:00 Cold open: the top firewall mistakes of 202500:21 Meet Jelle Konings, security optimization specialist01:16 Mistake 1: No visibility into your network03:36 Mistake 2: Skipping User-ID mapping06:01 Mistake 3: No default deny rule07:44 Fixing it: from logs to default deny09:09 Bonus mistake: port-based vs. application-based rules13:20 Will 2026 be any different? -
Would Your Boss Read Your Prompts? Private AI, Explained 14.07.2026 19minWould you still use ChatGPT if your boss, or the AI provider, could read every single prompt you typed in? Most of us type something we would never share publicly into an AI tool every day.In this Threat Talks Deep Dive, Field CTO Rob Maas sits down with ON2IT senior developer Derk Bell to unpack the privacy problem hiding inside everyday AI use, and a genuinely clever way to solve it.The problem is bigger than a single prompt. An AI request carries far more context than a Google search: your conversation history, your files, and (with agents and MCP) automatic, autonomous access to your CRM, your email, your calendar and your codebase. A lot of that data is shipped off to a remote provider, often without you realizing it. Today we just trust those providers not to misuse it. As Derk points out, “trust us” is the exact opposite of Zero Trust: never trust, always verify.So how do you verify? Derk walks through Confer, the privacy-first AI service from Signal Protocol co-creator Moxie Marlinspike. Using the analogy of a tamper-proof, locked calculator box for an “anonymous” employee survey, he explains how Confer lets you actually check the wiring: a hardware Trusted Execution Environment that isolates and encrypts the running program, remote attestation that lets you verify the exact open-source code handling your prompt, a Signal-style encrypted channel to talk to it, and hardware-bound keys that are thrown away the moment your session ends, so even the operator can never read your data.We close on who needs this most (developers protecting trade secrets, executives working on M&A or strategy, and anyone bound by GDPR) and whether the big AI labs will adopt this the way the whole industry adopted Signal.The takeaway: privacy and powerful AI do not have to be a trade-off. “Trust us” was never a security strategy.🔗 Episode resources, transcript and show notes: https://threat-talks.com📊 Grab the infographic referenced in the episode in the show notes to follow the technical steps. 🎙️ Subscribe to the podcast on Spotify, Apple Podcasts, or your podcast app of choice.Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday.Chapters:00:00 Would you still use ChatGPT if your boss read every prompt?01:00 Why AI is different from a Google search: context02:08 "Trust us" and why that is the opposite of Zero Trust03:22 It gets worse: AI agents, MCP and autonomous access05:52 Enter Moxie Marlinspike, Signal, and Confer06:30 The analogy: an "anonymous" employee survey in a locked box10:16 Inside Confer: the TEE, attestation and the encrypted channel14:21 End the session, throw away the keys16:08 Who needs this? Developers, executives, GDPR-bound teams18:29 Wrap-up: privacy and powerful AI can coexist -
Framework Fatigue: Why NIST Rebuilt the Cybersecurity Framework 07.07.2026 28minTen years after its first release, the NIST Cybersecurity Framework got a full rebuild. Not because it failed, but because everyone started using it, and it was never built for everyone.In this episode, host Lieuwe Jan Koning talks with Amy Mahn, IT Standards Advisor at NIST, and Daniel Eliot, Lead for Small Business Engagement at NIST’s Applied Cybersecurity Division, about what CSF 2.0 actually changes and why it took a multi-year public process to get there.The original framework was written with critical infrastructure operators in mind. A decade later, hospitals, school districts, and small businesses were all using it too, often without the staff or budget the framework quietly assumed they had. NIST collected more than 4,000 comments from organizations across over 100 countries to find out what was missing.The result includes a new Govern function that puts cybersecurity risk decisions in front of leadership and the board, a deliberately technology agnostic and vendor agnostic design that keeps the framework useful no matter which tools an organization runs, a Quick Start Guide aimed at organizations without a dedicated security team, and a sharper focus on supply chain risk.Amy and Daniel also explain why “vendor agnostic” is a feature, not a gap: it’s what lets an organization decide for itself who or what is best suited to close a given risk, instead of a framework quietly picking winners.Part 2, “CSF 2.0: Beyond the Framework,” continues the conversation and covers implementation in practice.Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. New episode every Tuesday. Follow Threat Talks to stay up to date on the topic of cybersecurity.Chapters:00:00 Framework fatigue, the problem NIST heard01:12 Welcome to Threat Talks02:05 Meet Amy Mahn and Daniel Eliot (NIST)03:40 What the original CSF got right, and where it broke down07:15 Four thousand comments, one framework10:30 The new Govern function14:05 Why CSF 2.0 is technology agnostic and vendor agnostic17:20 The Quick Start Guide for teams without a security team20:10 Supply chain risk gets its own seat at the table22:45 What Part 2 will cover24:48 Closing thoughts -
Why Do You Trust Your AI Agent? 30.06.2026 24minAgentic AI is powerful, and someone recently found that out the hard way when an AI tool, given free rein with a user’s own permissions, deleted her entire mailbox. That cautionary tale opens this Threat Talks Deep Dive, where host Lieuwe Jan Koning talks with Rob Maas, Field CTO of ON2IT, about what Zero Trust looks like when the thing you’re securing is an AI agent.Drawing on Rob’s recent blog post (and the Zero Trust pillars shared by CISA and Forrester’s Zero Trust eXtended framework), they work through each pillar in turn. The recurring theme is “just-in-case” privileges: the broad access we hand humans on the assumption they’ll use judgment. Agents have no such judgment. Give one an intent and it will use everything it has to reach the goal, and it can spin up parallel instances to get there faster.Across Identity, Devices, Network, Applications & Workloads, and Data, Rob makes the case for:Non-human identities with just-in-time, quickly-rotated privileges, so a leaked token can’t be reused forever.Tightly constrained execution environments (VM, container, serverless) that only touch what the agent truly needs.Identity-based network segmentation, so an agent working with CRM data can never reach the financial system.Allow-listed MCP tooling, because tool sprawl is the new shadow IT.New data controls for a world where everything (prompts, retrieval, documents) is data flowing to and from a model.He’s candid about the gaps, too: there’s no generic “AI firewall” yet, prompt injection has no guaranteed fix, and the hardest control points now live in the details of how individual developers configure their tools. The optimistic note: because agent-to-model and agent-to-agent calls can be logged, you can actually see what an agent is doing, an advantage over the opacity of the human mind. The episode closes on what’s still missing and a clear first step for any organization: get an overview of every agent and MCP server in use, and the access each one has.Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. New episode every Tuesday. Follow Threat Talks to stay up to date on the topic of cybersecurity. -
Mythos is not the AI Apocalypse 23.06.2026 22minMythos found a 23-year-old vulnerability in FreeBSD that no human team had caught. Your 30-day patch cycle assumes years before it gets weaponized. Today that window is one day. Next year it will be one hour.Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Rob Maas, Field CTO at ON2IT, to break down what Anthropic's Mythos actually found, why the public release (Fable) still frustrates security professionals, and whether the FABLE framework gives defenders a realistic path forward.Rob's verdict: there is truth in what Anthropic claims. It is not as catastrophic as the marketing suggests. But if your fundamentals are not in place, the time to fix that is now.00:00:00 Introduction00:00:46 What is Mythos? From Project Glasswing to Fable00:03:13 What Mythos actually found: FreeBSD, Palo Alto, real patches00:05:57 The zero-day clock: from years to one hour00:09:00 The FABLE framework and the CSA "Mythos Ready" paper00:15:24 Authentication, segmentation, and egress filtering00:20:51 Myth or reality: Rob's verdictSubscribe to Threat Talks and turn on notifications for deep dives into the world's most active cyber threats and hands-on exploitation techniques.🔔 Follow and Support our channel! 🔔===► YOUTUBE: / @threattalks► SPOTIFY: https://open.spotify.com/show/1SXUyUE...► APPLE: https://podcasts.apple.com/us/podcast...👕 Receive your Threat Talks T-shirthttps://threat-talks.com/🗺️ Explore the Hack's Route in Detail 🗺️https://threat-talks.com🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX -
What about Iran? One Word Document, Three Backdoors 16.06.2026 22minEvery big nation state has a cyber army: China, Russia, the US, Europe. But what about Iran? Meet Boggy Serpens, a group tied to Iran’s civilian intelligence service whose entire business is breaking in and staying in, then handing the keys to whoever strikes next. Their playbook, Operation OLALAMPO, needs just one booby-trapped Word document to plant three separate backdoors on your network.A Telegram-bot command channel that hides inside everyday encrypted chat traffic, a Rust “Ghost” backdoor built to defeat analysis, and a legitimate AnyDesk install quietly turned against you.The layered defense for every stage: email and file controls, behavioral EDR, egress policy, threat intel, and Zero Trust segmentation.The twist: why this operation mostly failed, plus the tells that the malware was partly written with AI.Filmed live at the ON2IT SOC, host Lieuwe Jan Koning runs a red team vs blue team session with analysts Yuri Wit, the “proxy Iranian” attacker, and Rob Maas on defense. Watch the full episode to see each move, and the exact control that stops it.🔗 Episode resources, transcript and show notes: https://threat-talks.com 🎙️ Subscribe to the podcast on Spotify, Apple Podcasts, or your podcast app of choice.Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday.Chapters (paste into YouTube description)00:00 Every nation state has a cyber army: what about Iran?00:21 Meet the guests: Yuri (red team) and Rob (blue team)01:17 Boggy Serpens and Operation OLALAMPO: Iran's access brokers04:20 Infection via Office macros, and the social-engineering layer07:18 You opened the document: three payloads08:06 Backdoor 1: Telegram-bot command and control12:55 Backdoor 2: the Rust "Ghost" backdoor, and why it's so hard to analyze16:03 Backdoor 3: legitimate AnyDesk, pre-loaded for the attacker17:59 Zero Trust and network segmentation18:59 Did it work? AI tells, and staying vigilant -
Europe Is Losing the Sea Cable Race 09.06.2026 35minIn 2026, 40 new submarine cables go live. Most won't land in Europe. Europe is losing the sea cable race, and most people haven't noticed yet.In this second part of our sea cables conversation, host Peter Ernst sits down with Ernst Noorman, the Netherlands' Cyber Ambassador-at-Large and a member of the ITU Advisory Body on Submarine Cable Resilience, to move from the “how” of sea cables to the “why it matters.”We compare two places that were once called the two hardest spots in the world to build digital infrastructure, Amsterdam and Singapore, and unpack how Singapore solved its crunch with 32 cable landings, five years of zero cable faults, and a green-energy-first tender process, while the Netherlands risks resting on a 30-year-old head start.Along the way: the difference between sovereignty and autonomy, why “always the cheapest option” no longer works, the EU Cyber Resilience Act and security by design, what NIS2 means for boards and CEOs personally, and why Europe needs to stop being modest about Airbus-sized wins.Chapters00:00 — 40 new cables, most skip Europe00:30 — Meet Ernst Noorman & the ITU advisory body02:00 — The sea cable map is being redrawn04:08 — Why the Netherlands risks losing its head start06:26 — How Singapore solved it: 32 landings, zero faults08:09 — Tax cuts for digital, would Europe ever?08:59 — Sovereignty vs autonomy: it's about choice15:02 — You can't own the whole stack (ASML, Nokia, Ericsson)15:53 — Why “always the cheapest” stops working17:47 — The Cyber Resilience Act & security by design18:51 — The water-from-the-tap analogy19:51 — What boards and CEOs must actually ask25:30 — Back to Singapore: government-led, by design29:39 — The good news: Europe's real strengths36:15 — What needs to happen in the next 3–5 yearsThreat Talks is a podcast by ON2IT and AMS-IX. Subscribe for more on Zero Trust, cyber resilience, and the infrastructure behind the internet. -
Russia Cutting Cables? 02.06.2026 32minThe headlines say Russia’s shadow fleet is cutting cables. The experts say most faults come from clumsy ship anchors. Ninety-nine percent of global internet traffic runs across the ocean floor, and the conversation about what threatens it is mostly wrong.In this episode of Threat Talks, Peter van Burgel, CEO of AMS-IX, sits down with Ernst Noorman, Cyber Ambassador at Large for the Netherlands and member of the ITU Advisory Board on Submarine Cable Resilience, to separate geopolitical noise from engineering reality, and explain what actually puts global internet connectivity at risk.Timestamps00:00:00 Introduction 00:00:55 The ITU Advisory Board on Submarine Cable Resilience 00:05:04 Shadow Fleets, Geopolitics, and the Sabotage Myth 00:10:30 Shunts, Faults, and What Actually Breaks Cables 00:15:47 Why Satellite Cannot Replace Submarine Cables 00:17:06 Digital Sovereignty and the Big Tech Cable Takeover 00:28:16 What Every CEO Should Put on the AgendaKey Topics Covered• Why most submarine cable faults come from anchors, fishing nets, and natural events, not state actors• How aging repair ships and bureaucratic permitting barriers make restoration slow in most of the world• Why satellite (including Starlink) cannot replace subsea fiber at any meaningful scale• How big tech dominance over new cable investment creates digital sovereignty risks for governments and large organizations• What NIS2 means for CEO accountability on digital infrastructure resilienceRelated ON2IT Content & Referenced ResourcesITU Advisory Board on Submarine Cable Resilience: https://www.itu.int/digital-resilience/submarine-cables/advisory-body/ ICPC (International Cable Protection Committee): https://www.iscpc.org Dutch Cybersecurity Council / CEO manual on NIS2: https://www.cybersecuritycouncil.nl Dutch Cybersecurity Act (NIS2 implementation): https://www.dutchncca.nl/the-cybersecurity-actThreat Talks: https://threat-talks.com/russia-cutting-cables-whos-protecting-it/ ON2IT (Zero Trust as a Service): https://on2it.net AMS-IX: https://www.ams-ix.net/amsSubscribe to Threat Talks and turn on notifications for deep dives into the world’s most active cyber threats and hands-on exploitation techniques.🔔 Follow and Support our channel! 🔔► YOUTUBE: / @threattalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUE… ► APPLE: https://podcasts.apple.com/us/podcast…👕 Receive your Threat Talks T-shirt https://threat-talks.com/🗺️ Explore the Hack’s Route in Detail 🗺️ https://threat-talks.com🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX -
Hero Culture and a $1 Million Mistake 26.05.2026 20minA company skips a security check two days before Black Friday and loses $1 million when transactions land in the wrong bank accounts. A machine learning team is told no on production data access, gets it via SharePoint anyway, and a year later the data is on contractor laptops nobody can account for. Two stories, one pattern: when security blocks, the risky work doesn’t stop – it just happens without you.Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Sina Yazdanmehr, Founder and Managing Director of Aplite GmbH, on the prevention paradox, why a “no” from the CISO is an illusion of control, and how a technical security team turns into a business partner instead of a roadblock. Timestamps00:00:00 Introduction 00:01:55 The $1 million Black Friday story 00:04:14 Hero culture rewards shipping, not prevention 00:06:55 The prevention paradox 00:08:00 NIS2 and executive accountability 00:09:00 Avoiding the Department of No 00:12:18 Production data on contractor laptops 00:16:13 The technical CISO as business partnerKey Topics CoveredWhy hero culture quietly trains organizations to bypass security under deadline pressureThe prevention paradox: why the person who avoids a loss never gets the creditWhat happens after a CISO says no: shadow workflows, friendly handovers, and data on laptops nobody ownsWhat a counter-proposal in risk-based language gets you that a flat refusal does notRelated ON2IT Content & Referenced ResourcesAplite GmbH: https://aplite.dePrevious Threat Talks with Sina Yazdanmehr (Security Culture part 1): https://youtu.be/1JnAsXDCKzM?si=qFlMxC617E30U1dWPrevious Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=wBodTl_nY1wPrevious Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=fBwdGXf-0dYThreat Talks: https://threat-talks.com/ON2IT (Zero Trust as a Service): https://on2it.net/AMS-IX: https://www.ams-ix.net/amsSubscribe to Threat Talks and turn on notifications for deep dives into the world's most active cyber threats and hands-on exploitation techniques. 🔔 Follow and Support our channel! 🔔 === ► YOUTUBE: / @threattalks ► SPOTIFY: https://open.spotify.com/show/1SXUyUE... ► APPLE: https://podcasts.apple.com/us/podcast... 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX -
When Compliance Replaces Security 19.05.2026 23minA SaaS company buys enterprise ChatGPT for 800 staff and strangely only uses 30 seats. A corporate signs annual risk exemptions for five years until the exception list itself is mistaken for a working security process. Same root cause, two symptoms.Compliance is not security. Security culture is company culture. If your employees do not trust their managers, no policy you write will save you.Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Sina Yazdanmehr, Founder and Managing Director of Aplite GmbH, on why security policy depends on trust, why a signed risk acceptance is a legal act, and what a leadership cadence on security communication actually looks like.Timestamps00:00:00 Introduction00:02:20 When risk exceptions become culture00:07:50 Turning a five-year exemption list around00:09:07 Working with auditors instead of around them00:13:14 The trust gap: enterprise tools and personal accounts00:19:27 Security culture is company culture00:22:21 Wrap and what is nextKey Topics CoveredWhy employee trust in management determines whether any security policy landsHow sanctioned enterprise tools, AI included, quietly fail when context and trust are missingThe legal weight of a signed risk acceptance, and why most managers treat it as paperworkWhat a working leadership cadence on security communication actually looks likeRelated ON2IT Content & Referenced ResourcesAplite GmbH: https://aplite.dePrevious Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=wBodTl_nY1wPrevious Threat Talks with Sina Yazdanmehr: https://www.youtube.com/watch?v=fBwdGXf-0dYThreat Talks: https://threat-talks.com/ON2IT (Zero Trust as a Service): https://on2it.net/AMS-IX: https://www.ams-ix.net/amsSubscribe to Threat Talks and turn on notifications for deep dives into the world's most active cyber threats and hands-on exploitation techniques. 👕 Receive your Threat Talks T-shirt https://threat-talks.com/ 🗺️ Explore the Hack's Route in Detail 🗺️ https://threat-talks.com 🕵️ Threat Talks is a collaboration between @ON2IT and @AMS-IX -
The Agent Problem 12.05.2026 21minYour AI agents are users now. They have your permissions. They read your email. They send messages. And they act on instructions that anyone with an internet connection can drop into your inbox.In this episode of Threat Talks, Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, sits down with Jack Cable, CEO and Co-founder of Corridor and former lead of Secure by Design at CISA, to walk through the “lethal triangle” (the three conditions that turn helpful AI into a breach vector) and what CISOs should be doing right now, before the technology runs further ahead of the controls.Timestamps00:00 – 01:36 Cold Open: The User Inside Your Software 01:36 – 04:23 What Agentic AI Actually Is 04:23 – 07:20 The Lethal Triangle: Three Conditions for a Breach 07:20 – 10:05 Why Prompt Injection Has No Fix Today 10:05 – 14:09 Sanctioning Agents Without “Allow Fatigue” 14:09 – 18:45 OpenClaw: Should Your CISO Authorize It? 18:45 – 21:17 Sandboxing, Sub-Agents, and What to Do Right NowKey Topics CoveredThe “lethal triangle” – sensitive access, untrusted input, and the ability to take unapproved actions – and why every basic email agent already breaks all three rulesWhy prompt injection cannot be reliably solved by another LLM, and why deterministic guardrails (sandboxing, allow-lists, human-in-the-loop) are the only durable answer todayWhy “allow, allow, allow” fatigue makes per-action approvals largely theatrical, and why routing approvals through a separate model is a real, if partial, improvementWhy Jack Cable’s CISO answer on OpenClaw and similar general-purpose agents today is short: don’t authorize (and what to deploy in its place)
Popular em
Este podcast também aparece nas paradas de podcasts destes países.