PodcastsTechnologyThe Cyber Threat Perspective

The Cyber Threat Perspective

SecurIT360
The Cyber Threat Perspective
Latest episode

221 episodes

  • The Cyber Threat Perspective

    Episode 184 | Active Directory Isn't Dead. It's Just Undefended.

    11/06/2026 | 28 mins.
    Think Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ years. In this episode, Brad and Spencer break down why AD attack paths remain one of the most critical threats in enterprise environments and what defenders can do about it right now.

    Spencer also previews his ContinuumCon workshop "Killing AD Attack Paths Once and For All" where he demonstrates how authentication policies and silos can eliminate an entire class of lateral movement attacks built into Windows and Active Directory.

    In this episode:

    - Why Active Directory is still alive, well, and heavily targeted
    - What an Active Directory attack path is and how attackers use them
    - The four prerequisites attackers need to abuse AD attack paths
    - Real-world examples: Kerberos ticket theft, SCCM abuse, certificate misconfigurations, and misconfigured permissions
    - Tools defenders should know: Bloodhound, PingCastle, Purple Knight, Locksmith, and ADelegator
    - How to prioritize remediations based on ease of exploitation vs. impact
    - Why retesting is the most overlooked step in any remediation cycle

    Resources mentioned:

    - Spencer's ContinuumCon Workshop (Fri. June 12, 10:30am PT / 1:30pm ET): https://continuumcon.com/schedule/
    - Hybrid Identity Protection Podcast (Semperis): https://www.semperis.com/hybrid-identity-protection-podcast/
    - Bloodhound CE: https://github.com/SpecterOps/BloodHound
    - PingCastle: https://www.pingcastle.com
    - Purple Knight: https://www.purple-knight.com
    - Locksmith: https://github.com/TrimarcJake/Locksmith
    - offsec.blog | securit360.com
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked

    05/06/2026 | 28 mins.
    Security misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Natter cover OWASP A05: Security Misconfiguration with real stories from recent engagements and practical takeaways for developers, security teams, and organizations of all sizes.
    In this episode:
    Hardcoded Active Directory credentials and API keys discovered in a public GitHub repo during a healthcare pen test
    Default credentials (admin/1234) found on a clinical research app storing PHI
    A rogue Apache basic auth panel that survived from dev into production
    How verbose error handling and stack traces hand attackers a roadmap to your app
    Why dev-to-production is the most dangerous transition in your app's lifecycle
    The shift-left mindset and DevSecOps — empowering devs to ship secure code
    How CIS lockdown guides can dramatically improve your security posture overnight
    Resources mentioned:
    OWASP Top 10: OWASP Top Ten Web Application Security Risks | OWASP Foundation
    CIS Benchmarks: https://www.cisecurity.org/cis-benchmarks
    Ep. 182 – OWASP Top 10 Part 1: https://youtu.be/BwYJ-kZ3XaY
    Need a web application pen test? Reach out: Offensive Security - SecurIT360
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR)

    27/05/2026 | 30 mins.
    Hosts Brad Causey and Spencer Alessi break down the 2026 Verizon Data Breach Investigations Report, focusing on the findings that actually matter for IT and security teams.
    The biggest surprise: vulnerability exploitation has overtaken stolen credentials as the top initial access vector, accounting for 31% of attacks, while credential abuse dropped to just 13%. This completely flips the script on years of "identity is the new perimeter" thinking.
    Topics covered include:
    Vulnerability explosion and remediation crisis: Why there are too many vulnerabilities and not enough time for patching, with only 26% of CISA KEV vulnerabilities fully remediated (down from 38%)
    The patching time paradox: Median remediation time increased from 32 days to 43 days despite organizations initially getting faster at patching from 2022-2024
    Web application sprawl: How the push to cloud and SaaS has created massive attack surfaces organizations don't own and can't patch
    The top 4 initial access vectors: Vulnerability exploitation, phishing, credential abuse, and pretexting
    Ransomware economics shifting: 48% of breaches involved ransomware, but 69% of victims didn't pay and median payments dropped to $139,875
    Mobile phishing success: Mobile-centric phishing had 40% higher success rates than email phishing as users get better at spotting email threats
    Social engineering evolution: The human element appeared in 62% of breaches, with pretexting requiring different countermeasures than traditional phishing
    Shadow AI explosion: 45% of employees are regular AI users on corporate devices (up from 15%), with 67% using non-corporate accounts
    AI data exfiltration: Shadow AI is now the third most common non-malicious insider risk, with source code being the top data type leaked
    MCP and IDE extension risks: Real-world examples including PocketOS having their entire production database deleted by Claude connected to a railway CLI MCP
    Brad and Spencer emphasize that while the threat landscape is shifting dramatically, the fundamentals still matter. Organizations need to get comfortable with not being able to patch everything and focus on what matters most.
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    [Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works

    20/05/2026 | 44 mins.
    We're re-releasing one of our most practical episodes this week — originally published November 2025, and still one of the best roadmap conversations we've had on the show.
    Brad and Spencer share no-fluff advice for breaking into cybersecurity, whether you're switching careers, starting from scratch, or leveling up from a general IT role. They cover what employers actually look for, the fastest paths in, and what to skip.
    If you're exploring a cybersecurity career, or know someone who is, this one's for you.
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
  • The Cyber Threat Perspective

    Episode 181: AI Zero Days (Google Threat Intelligence Report)

    12/05/2026 | 41 mins.
    Brad and Spencer break down Google Threat Intelligence Group's latest report on how adversaries are weaponizing AI across the entire attack lifecycle.
    The big takeaway isn't that AI has magically replaced attackers, but that it's making certain workflows faster, more scalable, and more repeatable. More importantly, AI platforms, agent skills, integrations, and dependencies are now becoming targets themselves.
    Topics covered include:
    AI for vulnerability discovery and exploit development: Google's first confirmed case of a zero-day exploit developed entirely with AI, including intentional prompts like "You are currently a network security expert specializing in embedded devices"
    Claude skills weaponization: A distilled knowledge base of over 85,000 real-world vulnerability cases integrated into AI research workflows
    Automation and scaled research: APT45 sending thousands of repetitive prompts to recursively analyze CVEs and validate proof-of-concept exploits
    AI-powered obfuscation techniques: Dynamic modification, evasive payload generation, and decoy logic using Gemini API for just-in-time VBScript obfuscation
    Autonomous attack orchestration: Moving beyond content generation into sophisticated malware command automation, including PromptSpy navigating Android UI for persistence
    AI-enhanced reconnaissance: Generating detailed organizational hierarchies and third-party relationships for high-value targets in finance, security, and HR departments
    Information operations and deepfakes: Taking legitimate journalist videos, editing in fabricated content, and adding AI-generated voiceovers
    Attacking AI dependencies: TeamPCP (UNC6780) targeting AI environments as initial access vectors, including March 2026 supply chain attacks on Trivy, Checkmarx, and LiteLLM
    The Mini Shai-Hulud worm: May 2026 attacks targeting AI infrastructure and dependencies
    Defensive fundamentals: Why inventory, zero trust principles, and behavioral monitoring matter more than ever
    Brad and Spencer emphasize that while the threat landscape is evolving rapidly, doubling down on foundational security practices remains the most effective defense strategy.
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
    Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
More Technology podcasts
About The Cyber Threat Perspective
Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.brad@securit360.com
Podcast website

Listen to The Cyber Threat Perspective, Lex Fridman Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features