Skip to content
PodcastsTechnologyThe Cyber Threat Perspective

The Cyber Threat Perspective

SecurIT360
The Cyber Threat Perspective
Latest episode

237 episodes

  • The Cyber Threat Perspective

    Your Employee Got Hacked. Now What? | Ep 198

    02/10/2026 | 27 mins.
    Users will get compromised. Someone will click the link, and credentials will get stolen. The question that really matters is what happens next.
    In this episode, Spencer and Brad walk through the Post-Compromise Risk Framework (PRID), a simple, repeatable way for IT and security teams to judge how exposed their environment is once an attacker gets in. Using a real-world-style ClickFix scenario involving "Susie in accounting," they trace how one compromised account can lead to lateral movement, credential dumping and sensitive data exposure. They also cover why so many of those steps go undetected.
    In this episode:
    Why the assume breach mindset is the best way to measure your security
    Privileges: what can a compromised user actually do?
    Reach: where can they go with that access?
    Impact: how bad would it be?
    Detection: would you even know it happened?
    How least privilege and network segmentation map to each step
    Why PS Remoting to a domain controller goes undetected nine times out of 10
    Why "that couldn't happen here" is not proof, and how to verify your controls
    "Inspect what you expect": testing your EDR instead of trusting it
    Pick a user, assume they're compromised, and walk the path. You'll learn more about your environment, and you'll likely find issues you didn't know were there.
    Work with Us: https://securit360.com
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
  • The Cyber Threat Perspective

    The Basics Still Win: What GreyNoise's PaperCut Report Shows | Ep 197

    25/09/2026 | 24 mins.
    One threat actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, using AI to run the same playbook at scale. The fastest path to domain admin took five minutes. But out of hundreds of organizations hit, the attacker only got domain admin at 12 of them.
    Spencer and Tyler use GreyNoise's recent PaperCut report to make the case that the basics matter more now than they ever have. The attack itself was not novel. It used a known vulnerability, a lab environment built to test exploits, an internet scanning service, and familiar offensive tools. AI (Codex and DeepSeek) is what took it from one target to hundreds.
    In this episode:
    How the attacker built a PaperCut and Active Directory lab to test exploits before going wide
    Why five minutes to domain admin is fast but not unheard of, and how certificate abuse makes it possible
    The Conti playbook comparison, and how LLMs are turning attack playbooks into automated campaigns
    The toolkit: Certify, Rubeus, SpoolSample, Impacket, NetExec, BloodHound, Mimikatz, and AMSI bypasses
    Why letting hosts reach GitHub directly is a red flag, and how DNS and category filtering slow attackers down
    The one case where Cloudflare's WAF stopped the attack
    Why the 12 domain admin compromises are a hopeful sign that hardening works
    Where to start with AD hardening: tier zero permissions, dangerous rights on broad groups, service accounts, and certificate templates
    Moving past EDR alone with application control, NDR, and identity-based detections
    Comparing what a security tool costs to what a compromise costs
    Spencer and Tyler are penetration testers at SecurIT360.
    If you get something out of the show, subscribe and leave a rating or review. It helps more than you would think.
    Work with Us: https://securit360.com
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
  • The Cyber Threat Perspective

    One Hacker, 42 Targets: Inside Anthropic's AI Threat Report | Ep 196

    18/09/2026 | 52 mins.
    One French-speaking hacktivist targeted 42 organizations and got internal access to 14 of them, working alone. That is the kind of detail Anthropic's September 2026 threat intelligence report put on the record, with data spanning December 2025 through August 2026. Spencer and Tyler walk through all six generative threat groups named in it and what actually changes for defenders.
    Their read: the attacks themselves are familiar. Stolen credentials, unpatched edge devices, exposed services, phishing, SQL injection. What AI changed is speed, automation, and scale, and that is enough to matter.
    In this episode:
    The skill floor for hacking has dropped, and solo operators are now running campaigns that used to take a team
    Threat actors vibe coding phishing kits, credential dashboards, and custom tooling
    Automated vulnerability discovery and exploit development, including one workflow that produced more than a dozen potential zero-day findings in a month
    Why older models with looser guardrails are showing up in operations while frontier models refuse the same requests
    Custom harnesses and multi-agent pen testing frameworks that chain traditional offensive tools under an LLM
    Stolen AI credentials and API keys as a high-priority target, plus resellers advertising discounted access to frontier models
    On-the-fly obfuscation and retooling that breaks signature-based detection
    Why baselining, behavioral detection, application control, and external attack surface hygiene matter more than they did a year ago
    Groups covered: GTG-2006, GTG-50014, GTG-10007, GTG-50020, GTG-50021, and GTG-50029.
    Spencer and Tyler are penetration testers at SecurIT360. 
    If you get something out of the show, subscribe and leave a rating or review. It helps more than you would think.
    Work with Us: https://securit360.com
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
  • The Cyber Threat Perspective

    [Replay] Episode 178: Internal Security Controls That Actually Frustrate Attackers

    11/09/2026 | 31 mins.
    Replay of Episode 178, originally published April 22, 2026.

    We are re-running this one because it is the question we get asked most
    on internal pen test debriefs: of everything on the list, what actually
    slows an attacker down? Spencer and Tyler answer it from the attacker
    side, using what has and has not stopped them on real engagements.

    What's covered:

    - Application control done right, including where ThreatLocker and WDAC
      actually block a payload and where they get bypassed
    - MFA, the Protected Users group, and least privilege as attacker-facing
      controls rather than compliance checkboxes
    - Why mismanaged admin privileges and service accounts remain the fastest
      route from foothold to domain admin
    - Network segmentation and zero trust, and what separates a real
      implementation from a diagram
    - Deception techniques and EDR baselining for catching activity that
      looks legitimate

    If you are deciding where the next dollar of your security budget goes,
    this is the episode that tells you what attackers hope you skip.
    Work with Us: https://securit360.com
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
  • The Cyber Threat Perspective

    Every IT Team Has a Joe | Ep 195

    04/09/2026 | 27 mins.
    Interested in a pen test? Visit securit360.com.
    Every organization has a Joe. He is the long tenured engineer or admin who built half the environment, maintains the other half, and keeps most of it in his head. Everybody depends on him and nobody wants to challenge him.
    Spencer and Tyler break down key man risk in IT, drawing on hundreds of internal pen tests across law firms, banks, credit unions, manufacturing, municipalities, and SaaS organizations.
    In this episode:
    Why tribal knowledge is a security risk, not just an operations problem
    How word of mouth process handoffs turn into a game of telephone
    The reason remediations stall for an extra 30 days
    Shadow IT that originates inside the IT team
    Privilege creep and the single account that owns the environment
    When Joe's resistance to change is the correct call
    Cross training that does not add more work to Joe's plate
    Incentives, clear ownership, and update deadlines that actually stick
    Separating fact gathering from decision making so seniority does not win by default
    This is not a knock on senior admins. It is a look at the risk that accumulates when one person carries everything, and what IT leaders can do about it.
    All of our content can be found at Offsec.blog. Interested in a pen test? Visit securit360.com.
    Work with Us: https://securit360.com
    Blog: https://offsec.blog/
    Youtube: https://www.youtube.com/@cyberthreatpov
    Twitter: https://x.com/cyberthreatpov
    Follow Spencer on social ⬇
    Spencer's Links: https://spenceralessi.com
More Technology podcasts
About The Cyber Threat Perspective
Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.brad@securit360.com
Podcast website

Listen to The Cyber Threat Perspective, Power On with Mark Gurman and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features