Podcast charts
Published by Lou Covey
Unraveling the technology that affects us all but that few of us understand, in a format to give you a basic understanding in the time it takes to drive to and from the grocery store.
On the charts
Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.
From the feed
The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.
Back in May the coding world reeled to the news that a hacking group, using customized AI agents, had breached Github and stolen 3,800 of its internal repositories by a threat actor group tracked as TeamPCP. The attack was designed to stay under the radar: it ran entirely within normal user permissions and explicitly avoided privilege escalation, so it looked like ordinary developer/AI-assisted activity rather than an attack. The question that comes out of this is, are AI agents fundamentally changing the trust model in collaborative software development? So today I’m talking with Matan Bar-Efrat, the Rein Security, CEO, who’s company is one of the latest in a growing group of companies specializing in enterprise generative AI governance and data security companies. His answer to that question was refeshingly candid.
Flock has been in the news recently in a backlash against municipal surveillance, but this technology has been in use for half a century. Why the problem now? We sat down to talk with a city commissioner from Del Ray Beach, Florida, Tom Markert, who also consults with the FBI on cybersecurity. He's something of a rennaissance man wh, in addition to his corporate and civic work, also writes thrillers and screenplay related to technology and government. He had some insight into the controversy and it is more than surveillance. It's about competence.
A few months ago the tech world went into a tizzy over Anthropic's announcement that it's latest fronter AI incarnation was finding zero-day vulnerabilities. My BS meter started pinging immediately. A zero-day attack requires finding a system vulnerability that no one knows about. It is about as creative a process that a blackhatter can pull off. But AIs can't do anything new or creative. It's output is always based on something a human has already done and shared on the internet. Then I got a pitch from a Swiss academic and tech CEO Ilia Kolochenko titled, 'The illusion of AI Zero-day attacks". this is someone who knows how to get my attention.
It seems the entire cybersecurity industry went on vacation after Blackhat USA last week because every interview I scheduled for this podcast went belly up with cancellations. So at our Monday staff meeting, my EU partner Patrick Boch and I decided to fill the gap this week regarding Anthropic's AI watermark tech. We decided it's not that big a deal. The are a regulatory response (EU), not a choice designed protect publishers from uncopyrightable AI-generated content, and prevent plagiarism. Amazingly enough, one of the stories that popped up this wee was about how Ne Yorker writer Ross Barkum lost a bood deal because most of his content was plagiarized. For us watermarks simplifies content vetting. We can find AI content faster than current AI checkers. The bottom line is human originality has value. As AI floods the internet with "lowest common denominator" content, unique human work will become a premium, potentially reversing the decline in journalistic value. There is a lot more and you can find the transcript on Cyber Protection Magazine next week.
In a world of employment upheaval, job seekers are freely sending out millions of documents containing significant personal information. Whether called CVs or resumes, these documents can be used to impersonate and defraud employers and the job seekers alike. Chris Els, founder of P3 Audit, a data compliance and supply chain risk company, is developing a technology to help get that massive amount of information back under control of those who own it. We talked with him about its importance.
We've been getting an influx of announcements regarding shoulder surfing and technology that protects against it. However, we haven't found a single incident that actually, involved breaking into a device by looking over someone's shoulder. Instead, every report involves stealing someone's phone that hasn't been properly protected by biometrics or MFA. So we put out a call to ask experts about the validity of the problem and Stephanie Schneider from LastPass stepped into the breach. As we thought, you don't really need much to stop it, if it even happens. This podcast is sponsored by Haven , from Mirrortab
Cybersecurity is never more crucial than when it hits home. This past week, my daughter, who runs a small event planning business, was targeted by a phishing exploit known as a Click-Fix, designed to get her to go to a fake website to harvest her Google log-in credentials. She didn't fall for it and we had a lovely discussion about how she recognized it and stopped it in it's tracks. But I thought it would be a good case study for our sponsor, Haven , from Mirrortab, so I got Colin Britton, COO of Mirrortab on the horn and talked about how their free browser extension could have aided the defense. Luckily, my daughter had enough security awareness that precluded the need, but she has it installed now, just in case. And Colin revealed that the Haven service is expanding to a business application.
It has been a while since we talked with Ian Thorton-Trump, CISO and prognosticator at Inversion6 , so we were happy when he dropped us a note and reminded us of that lack. Boy, was this one a barn burner. Across the world, pessimism reigns in geopolitics with cybersecurity at the dead center of it. Asymmetric warfare is less about kinetic attacks by terrorists and more about nation-states using the internet to attack and disrupt enemies, and sometimes friends, all over the world. That has resulted in distrust, broken relations, and dysfunctional governments. But from his vantage point in the UK, Ian sees a brighter future ahead and the US will be in the lead, once again. So grab a coffee and a danish and get ready to put a smile on the day.
The idea that humans can be excluded from technology operations has been an aspiration in the AI industry, and that interest is NOT going away. But companies are pushing the idea less and redefining how important humans are in the process, described as humans in the loop, at the helm and in the middle depending on whom you are talking to, A lot of the aspirational efforts have been in automating security operations centers (SOCs), but, like much of the threat that AI will eventually replace all humanity, is being tempered by reality. Many companies are pushing the idea autonomous response in SOCs tempered with human involvement. The latest is Blackpoint Cyber who have announced their first offering in the area. We are talking with Chief Security and Trust Officer Wil Santiago about how human involvement in security is still a requirement now and for the foreseeable future. This episode is sponsored by Haven
Meta is like Hotel California. You can enter but you can't leave. That's the story I hear over and over. It isn't true. I did and have never looked back. The claims that Meta platforms can improve your business, keep relationships alive, inform the electorate and make a better society have been disproven again and again, but the thing keeps growing. It does that by suppressing the belief that there are alternatives. This podcast talks about how you, your group, your business and your friends can leave the toxic cesspit and find success and mental health in the decentralized world. Sponsored by Haven. Most security tools only know how to shout. Haven doesn't. It's a Chrome browser extension that spots phishing links and attempts before you click, and stays quiet the rest of the time. Free for individual use, at starthaven.com.
This week I talked to the good folks at the Digital Citizens Alliance about a report on residential proxies. Say what? Residential proxies? What the heck are those? They are the apps and hardware products people use to connect to the internet, and they are as secure as a sieve is water tight. The Wall Street Journal published a report on them June 15 and. Back in March the FBI issued an alert abut the dangers they pose. The DCA produced their own report that was, frankly, more informative about the problem. The podcast is sponsored by Haven , a free internet browser extension that protects you from phishing links and malicious sites before you ever click.
Back in April, Microsoft released an advisory about phishing gang infiltrating Microsoft Teams meetings. In stunning turn of events, it wasn't a weakness in the Microsoft product but in users turning off or bypassing multiple security controls for external users, and then forgetting to turn them back on. This is what is known as configuration drift. We talked with Reach Security's CEO Garrett Hamilton.
The data broker market is worth half a trillion dollars and growing at a rate of 7.3 percent annually through 2033. That means they don’t care that you want your privacy. They are making too much money selling your personal information to care. That lack of concern doesn’t just affect an individual’s privacy. It threatens their security and that of nation states. There is a technology niche dedicated to fixing that problem: the personal data removal and online privacy market. The problem is it’s worth a 10th of the data broker market so it doesn’t have the political clout of data brokers. And nowhere is the problem bigger than the healthcare industry, according to Rob Shavell, CEO of Deleteme . This episode is sponsored by Haven , a free browser extension that protects you from phishing links and malicious sites before you ever click.
A public relations firm in the United Kingdom, Whiteoaks International, said the quiet part out loud about cybersecurity marketing: that much of it is fiction if not outright fraudulent. I sat down with the rest of the Cyber Protection Magazine team, Patrick Boch and Joe Basques to have a frank discussion about this issue. Frankly, any journalist knew this to be true but to hear it come from a practicing agency was rather surprising.
Just to prove that even the most secure practitioners, like your truly, can fall for the “free lunch” offer, I inadvertently signed up for a shady but completely legal “cash back” offer. Not only did I not get any cash back I got charged for it, had to cancel a debit card and walked through the process (which I described in Cyber Protection Magazine this week. But I also called up Brian Silverstein, CEO of MirrorTab (whom we talked with a couple of weeks ago) about how to be aware when these things pop up unexpectedly and his company's plans to deal with not just scams, but scammy deals.
AT the RSAC Conference this year a new marketing buzzword appeared in several interviews, most particularly DataKrypto and Cy4Data Labs . They are doing important work, but my interviews with them indicate they need to lift their heads up now and then and look around. Their competitive field is bigger than they think. More on Cyber Protection Magazine next week.
I talk about the nature of truth in an Ai world with documentarian Steven Rosenbaum in advance of the release next week of his book The Future of Truth , not to be mistaken by the 2025 book of the same name by film maker Werner Herzog.
The dirty secret of digital media for the past two decades has been that it doesn't really work. It's just a lot cheaper and easier than actual marketing. Lou Covey and Joe Basques of Cyber Protection Magazine have watched it in its genesis to where it is today and talk about how AI has totally flipped the script, how it changes the metrics and purpose of content and how to make it work for your company.
The great conundrum of business is how rare it is for a company to find markets they can dominate. Oh, they all say that’s what they want to do, but when asked about their business they respond, “Some of our customers are in the Fortune 100/500/1000.” That response always leaves us cold. The biggest companies will always buy one of everything just to make sure they don’t miss out. Cybersecurity is not immune to this case of tunnel vision. 90 percent of companies in the industry target 10 percent of the available market in the form of medium to large enterprises. Meanwhile, small to medium businesses (SMBs) can’t get cybersecurity companies to answer the phone unless they are will to spend six figures on tools and services. We don’t think that a very good idea. SMBs make up the backbone of any supply chain and without effective security, they become massive holes for the large companies that contract with them. We’ve been playing around with the idea of how much it really costs to make your SMB network secure and we’ve determined that it can be done for less than $500 a month. No, it’s not comprehensive, but even companies with million-dollar security budgets get hacked. Our idea is to plug the most obvious holes. Sure enough, we are finding companies that do just that. We are launching this campaign today with two interviews of security providers that have competint/overlapping services: MirrorTab and it’s new product Haven , and an old-guard company, DNSFilter . The services these companies offer will alert users to questionable websites or emails. Considering that represents 95% of all breaches, that pretty much covers your business like a blanket. The cost? Free to $5 a month. We suggest you call one or both of them today, but before you do, listen to our itnerviews with Mikey Pruitt, head of AI labs at DNS Filter, and MirrorTab CEO Brian Silverstein. You will learn some valuable information.
Back in January I had a chat with Doug Kersten, CISO for Appfire , that had soemwise words about the intersection of Ai and security. He said AI amplifies existing weaknesses. It doesn't create new threats . AI-driven attacks (phishing, deepfakes) succeed by exploiting poor security fundamentals like weak training and monitoring. And that's what we have to worry about most. This conversation was about rational response to the use of AI in security. Seems timely.
Ranking source
Apple Podcasts rankings via the Mato Topic Intelligence Platform.
Observed September 20, 2026.
Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.
Pairs with
Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.