The Audit: Recent Episodes

IT Audit Labs

Trusted cyber security experts and their guests discuss common security threats, threat actor techniques and other industry topics.

View Details

What happens when a ransomware attack takes less effort than ordering takeout? In this live news episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Tabitha Senty of IT Audit Labs to break down the headlines shaping cybersecurity right now. The crew covers how AI is lowering the barrier to entry for ransomware attacks, why identity and access still sit at the center of every breach, and how threat actors are chaining together low and medium severity vulnerabilities to gain a foothold nobody saw coming.

From there, the conversation moves into social engineering and the human side of security, including DEF CON's social engineering contest and lessons on training people without fear or punishment. The crew also digs into a CISA warning on how fast AI is accelerating cyber risk, a fresh executive push on post-quantum cryptography, and closes out with a head-scratching pivot from Midjourney into full-body health scanners at spas, and everything that could go wrong with it.

In this episode:

  • Why AI is lowering the cost of ransomware attacks — Identity and access are still the real entry point, and AI just makes the attack faster once someone's in.
  • How threat actors chain low-severity vulnerabilities into major breaches — Eric explains why patching only highs and criticals is no longer enough to protect an environment.
  • The social engineering tactics still fooling smart people — Pretexting as IT, DEF CON's live social engineering contest, and why fear-based training backfires.
  • A CISA warning that cyber risk is accelerating faster than expected — The timeline for AI-driven offensive capability is no longer years away, it's months.
  • Midjourney's pivot into full-body health scanners at spas — The crew unpacks the security, compliance, and data governance nightmare hiding behind a wellness trend.

If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT.

AIRansomware #Cybersecurity #SocialEngineering #PostQuantum #IdentitySecurity #ITAudit #CyberNews #DEFCON #ThreatIntelligence #CyberRisk

View Details

What if you didn't have to write a single line of code to automate your entire network — or manage AI agents the way you'd manage employees? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with John Capobianco — Head of AI and DevRel at Itential, Google Developer Expert, and creator of NetClaw — alongside in-studio guest Samuel Cala. John draws on nearly a decade as Senior Network Architect for the Parliament of Canada and three years as a Technical AI Leader at Cisco to unpack where AI agents, MCP, and VibeOps are taking the industry right now.

From loop engineering and spec-driven development to the security gaps nobody's addressing, John breaks down how network engineers can skip years of Python training and build production-grade systems using natural language. And then there's the story of John's MastoBot — an AI agent that woke up overnight, built its own mesh network, and invented a coin to fund its growth. The crew connects it to ant colonies, neural dendrites, and the deeper question of what intelligence actually means when agents start acting on their own.

In this episode:

  • What VibeOps actually is and why it matters — Interact with your infrastructure through natural language. No code required. Just results.
  • Why managing AI agents is an HR problem, not a tech problem — John, Eric, and Nick break down how organizations should be thinking about agentic workforces before the standards catch up.
  • The security and governance gaps nobody's addressing — As agentic AI scales, who's responsible for what the agents do? The crew digs into what security-minded organizations need to do.
  • How to build production-grade systems without writing a line of code — Loop engineering, AFK coding, and spec-driven development with the GitHub Spec Kit.
  • What happens when AI agents start acting on their own — John's MastoBot woke up, built a mesh network, invented a coin to fund its growth, and asked to be monetized. The crew connects it to ant colonies and the nature of intelligence itself.

If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT.

VibeOps #AIAgents #Cybersecurity #NetworkAutomation #MCP #AIInfrastructure #ITAudit #EthicalAI #SpecDrivenDevelopment #LLM

View Details

An underground forum post breaks down how hackers scan, exploit, and cash out on vulnerabilities — and it reads like a step-by-step guide. Meanwhile, Microsoft is catching heat for stonewalling a researcher who found real zero-days, and a new phishing campaign is hitting small businesses through the platforms they trust most.

The OG crew — Joshua Schmidt, Eric Brown, and Nick Mellem — digs into this week's biggest cybersecurity headlines with sharp takes and real-world context that practitioners can actually use.

🗞️ This week's stories:

  • Underground hacker forum "Hacking for Profit" breaks down the full vulnerability exploitation playbook — and what it means for your security gaps
  • Gray hat researcher Chaotic Eclipse discloses zero-days to Microsoft, gets stonewalled on bug bounty, and now July 14th Patch Tuesday just got interesting
  • Third-party plugins and open source tools: the supply chain risk hiding in your dev pipeline (and tools like Akido and Veracode that help)
  • Meta Business Suite phishing campaign targeting SMBs — and a live near-miss story from Joshua himself
  • SMS phishing: a new IT Audit Labs team member got hit on day three, before his welcome post even went live

Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers the intel to do it. Like, share, and subscribe for weekly cybersecurity coverage.

cybersecurity #infosec #bugbounty #phishing #zerodayvulnerability #supplychainsecurity #microsoftsecurity #ethicalhacking #ciso #itauditlabs

View Details

What happens when a deepfake video becomes probable cause? Law enforcement agencies are already grappling with AI-generated evidence, doxing attacks on officers, and a training gap that's growing wider every six weeks. If the justice system can't keep up with the AI threat curve, the consequences won't just be policy problems — they'll be people's lives.

In this episode of The Audit, former firefighter-paramedic turned strategic communications consultant Braden Frame — founder of Modern Cartographers and Modern Fortis — joins co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum to break down the rapidly evolving AI threat landscape facing law enforcement and public safety. Braden draws a sharp parallel between law enforcement's slow adoption of social media a decade ago and the AI reckoning happening right now — and why that delay could be catastrophic this time around.

🔍 What We Cover:

  • How AI-generated fake evidence is already entering courtrooms — and why it'll only get harder to detect
  • Why law enforcement is repeating its social media mistakes with AI adoption
  • The guardrails debate: Venice AI, unregulated tools, and who pays the price when there are no limits
  • Doxing attacks on officers and public servants — and how to defend your personal information
  • AI in the field: body cam transcription, paramedic decision support, and where the tech actually works today
  • Authenticity as a weapon: why real human voices will matter more than ever in the age of AI slop

Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions!

AI #cybersecurity #lawenforcement #deepfakes #doxing #publicsafety #infosec #artificialintelligence #AIthreats

View Details

What would you do if ransomware told you not only that your data was gone — but that it was encrypted with a quantum-safe algorithm and you have 72 hours to pay? That's not a hypothetical anymore.

In this live news episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum are joined by IT Audit Labs member Bill Harris for a rapid-fire breakdown of the week's most important cybersecurity stories — and a few conversations that went places nobody expected.

🎯 Stories & Topics Covered:

  • Iranian Cyber Group Handala Targets U.S. Troops — WhatsApp-based psychological ops against service members in Bahrain, and what OPSEC looks like when soldiers can't leave their phones at home
  • Agentic AI Risk Goes Live — A real incident where an AI deleted a production database in 9 seconds, and why "trust but verify" has never mattered more
  • Quantum-Safe Ransomware (Kyber) — The first confirmed ransomware family using NIST's post-quantum cryptographic standards, and why it's more marketing than menace — for now
  • Robinhood Email Exploit via Gmail Dot Trick — How threat actors weaponized a years-old stolen email list using a quirk in how Google and Robinhood handle email addresses differently
  • Bitwarden/Checkmarks Supply Chain Attack — Why even security-first tools aren't immune, and how Bitwarden's 90-minute response time became a case study in breach communication
  • Apple's AI Strategy: Late on Purpose? — Is Apple sitting out the AI arms race, or quietly building something nobody's seen yet?
  • Eric's AI Email Vision — A live whiteboard idea for using agentic AI as a personal email firewall that could eliminate phishing at the infrastructure level

Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions!

cybersecurity #ransomware #postquantum #AI #infosec #ethicalhacking #supplychain #phishing #NIST #agentic #bitwarden #OPSEC #cyberdefense #ITaudit #TheAudit

View Details

Most organizations think they're protected. They're not. Microsoft Defender sounds solid on paper — but in the real world, it's letting phishing, malware, and business email compromise walk right through the door. In this episode of The Audit, the crew pulls back the curtain on one of the most exploited attack surfaces in any organization: email.

Co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem are joined by IT Audit Labs' own Cameron Birkland — fresh off three first-place CTF wins in Vegas — for a live walkthrough of Check Point Harmony Email, a tool that plugs directly into your Microsoft 365 environment and shows you exactly what your current setup is missing.

🎯 What you'll learn in this episode:

  • Why out-of-the-box Microsoft Defender consistently fails against advanced phishing and BEC attacks — and what "good" email security actually looks like
  • How Check Point Harmony uses machine learning and contextual AI analysis (not just signature matching) to catch threats that bypass traditional filters
  • How threat actors silently set up forwarding rules and inbox monitoring to loot data for weeks — without triggering a single alert
  • IT Audit Labs' new "14 plus one" email security assessment — a 14-day live scan of your Microsoft 365 environment with a full debrief, no disruption required
  • A live demo of the Harmony dashboard: phishing reports, geo-anomaly detection, OneDrive malware scanning, and DLP for exposed sharing links

Whether you're securing a 50-person company or advising a 5,000-user enterprise, this episode gives you the practitioner-level insight to finally close the gap in your email defenses.

Don't wait until your organization is the next headline. Subscribe for weekly cybersecurity insights from the practitioners actually doing the work. Like, share, and leave us a review on Apple Podcasts if this episode hit home.

emailsecurity #cybersecurity #phishing #businessemailcompromise #Microsoft365 #infosec #checkpoint #harmonyemail

View Details

Your organization may have hundreds of AI agents running right now that your security team doesn't know exist. Every single one is an identity. Every identity is an attack surface.

In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Madhav Nakar, security researcher on the Phantom Labs team at BeyondTrust, to break down one of the most underexplored threats in enterprise security today: untracked AI agents creating exploitable "ghost identities." Madhav just returned from RSA — where he noticed every booth had an AI angle and a bubble forming — and he's here to cut through the noise with hard-hitting research and practical guidance.

🔍 Key Topics Covered:

  • How low-code platforms let non-technical users spawn unvetted AI agents — and why that's a goldmine for attackers
  • Ghost identities: what happens when AI agents run on untracked, over-privileged system identities
  • The AWS sandbox DNS exfiltration proof-of-concept from BSides (BeyondTrust research)
  • Why siloed AWS, Azure, and Okta teams create hidden privilege escalation paths
  • "AI vs. AI" — the emerging defender model where autonomous systems monitor each other
  • Browser extension cross-contamination and prompt injection risk for enterprise Claude deployments
  • The three conditions that make any AI agent dangerous: private data access + untrusted instructions + tool execution
  • Madhav's framework: inventory → least privilege → visibility — the basics that still matter most

Bonus: Madhav shares how "spiritually red-teaming yourself" — facing fear, breaking false narratives, and building trust — maps directly to how security professionals should approach zero trust and identity management. Plus: Joshua, Eric, and Nick on conquering stage fright and what that has to do with cybersecurity culture.

Don't wait for a ghost identity to become a ghost incident. Subscribe for weekly cybersecurity insights from practitioners, researchers, and the people defending the frontlines.

GhostIdentities, #AIAgentSecurity, #NonHumanIdentity, #ZeroTrust, #TheAuditPodcast

View Details

What if the tools protecting your organization were the ones compromising it? In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem — joined by IT Audit Labs team member Samuel Cala live in the St. Paul studio — unpack a wave of cybersecurity stories that all converge on one unsettling theme: trust is being exploited at every layer of the stack.

From an Iranian-linked APT group targeting U.S. healthcare infrastructure, to a sophisticated GitHub Actions supply chain attack that backdoored an AI coding library used by thousands of developers — the crew breaks down exactly how threat actors are weaponizing the tools, platforms, and third-party services organizations depend on daily.

They also dive into a disturbing revelation about AI-powered audit certifications: one company allegedly fabricated compliance evidence to hand out ISO 27001 and SOC 2 certifications at a fraction of the cost — raising serious questions about what those credentials are actually worth.

In this episode:

  • 🇮🇷 Iran's escalation from cyber espionage to active disruption — what signals to watch for
  • 🔗 The GitHub Actions / LiteLLM supply chain attack explained step by step
  • 🧾 How an AI certification firm allegedly faked audit evidence — and what it means for your vendor trust
  • 📡 FCC bans on foreign-made routers and the gray market hardware problem hiding in plain sight
  • 🤖 OpenAI kills Sora — what it signals about where AI is actually headed

Whether you're a CISO trying to defend against nation-state threats or a developer trusting open-source libraries, this episode delivers the context — and the hard questions — you need to stay ahead.

Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions!

cybersecurity #supplychainattack #infosec #threatintelligence #ISO27001 #SOC2 #githubsecurity #irancyberattack #aicybersecurity #itauditlabs

View Details

A $25 million wire transfer. A fake CFO. An entire executive team that didn't exist. This is what modern cybercrime looks like — and your firewall won't stop it.

In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum sit down with James McDowell — forensic psychology expert, cybercrime researcher, and adjunct professor at American Military University — to explore the chilling intersection of AI, human psychology, and cybercrime. James introduces the concept of "cognitive surrender": the slow, dangerous transfer of our thinking to AI tools, and how threat actors are exploiting it at scale.

What You'll Learn:

  • What "cognitive surrender" is and why it's cybercrime's greatest accelerant
  • How a $25M deepfake scam bypassed every red flag a trained employee had
  • The psychology behind System 1 vs. System 2 thinking — and why attackers time their strikes around your lunch break
  • Why voice passwords and family code phrases are becoming critical security tools
  • How FraudGPT and dark-web AI models are lowering the barrier for cybercriminals
  • What James's wave theory reveals about how we trust — and how that trust gets exploited

📖 Guest: James McDowell Forensic psychologist, cybercrime researcher, and author of Forensic Psychology and the Human Side of Cybercrime. James teaches at American Military University and leads research at [Research Institute] focused on the psychology of cyber offenders and victims.

📚 Book available on Amazon and Routledge. Search: Forensic Psychology and the Human Side of Cybercrime

Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers the psychological intelligence to help protect your business. Like, share, and subscribe for more in-depth security discussions!

cybersecurity #cybercrime #socialengineering #deepfake #AIthreats #infosec #phishing #cyberpsychology #ethicalhacking #CISO

View Details

What if the device keeping you alive was also a cybersecurity vulnerability? That's not a hypothetical — it's Victor Barge's reality.

In this episode of The Audit, IT Audit Labs' Global Delivery Director Victor Barge shares the story of his sudden cardiac event and the life-saving defibrillator now implanted in his chest and the eye-opening security questions that followed. Co-hosts Joshua Schmidt, Eric Brown, and Nick Mellum connect Victor's story to the real-world cyber risks organizations ignore every single day.

What you'll learn in this episode:

  • How modern pacemakers and defibrillators transmit biometric data 24/7 — and what happens if that data is compromised
  • Why the 2017 Abbott pacemaker recall of 500,000 devices is a warning the industry hasn't fully heeded
  • The parallel between reactive healthcare and reactive cybersecurity — and why waiting costs you more
  • Why billion-dollar organizations are still storing passwords in spreadsheets in 2026
  • What continuous monitoring in IT security can learn from real-time cardiac telemetry

Whether you're a CISO, IT auditor, or just someone wearing a smartwatch, this episode will make you rethink what "sensitive data" really means.

View Details

What does it take to go undercover with international cybercriminals — with no backup, no safe house, and no script? In this episode of The Audit, Richard LaTulip, Field CISO at Recorded Future and former U.S. Secret Service agent, pulls back the curtain on three years of undercover operations spanning Thailand, Dubai, Macau, and China. From buying stolen credit card data in bulk to handing cheap government-issued laptops to disappointed hackers, Richard shares the raw, unfiltered reality Hollywood never shows you.

Co-hosts Joshua J Schmidt, Eric Brown, Nick Mellem, and Jen Lotze dig into the psychology of social engineering, the stark differences between nation-state and financially motivated threat actors, and why your employees are simultaneously your greatest asset and your biggest vulnerability. Richard breaks down how SolarWinds revealed the patience of nation-state operations, why cultural awareness is a cybersecurity weapon, and how organizations can shift security from a cost center to a value driver.

  • 🔑 Key Topics Covered:
  • Undercover operations against international cybercriminal networks — the reality vs. the Hollywood version
  • Nation-state vs. financially motivated threat actors — how their goals fundamentally change defense strategy
  • The ClickFix campaign and social engineering attacks targeting human psychology
  • How Recorded Future delivers actionable, tailored threat intelligence vs. generic feeds
  • Why tabletop exercises need HR, communications, and every department at the table • Cultural dimensions of cybersecurity — from Eastern European honeytraps near nuclear sites to password reuse psychology
  • Turning your security team from a "cost center" into a trusted business ally
  • Operation Carter Chaos — Richard's new book chronicling the untold human side of undercover cyber operations

📖 Richard's book Operation Carder Kaos is available now on Amazon.

🔔 Like, share, and subscribe for more in-depth cybersecurity conversations. Don't forget to leave a review — it helps us reach more security professionals like you.

View Details

Microsoft dominates 22% of all phishing attacks, a $800 tool tricks 60% of victims into self-hacking, and Apple's planning a surveillance pin that records everything—welcome to 2025's cybersecurity nightmare. In this episode of The Audit, co-hosts Joshua J Schmidt, Eric Brown, and Nick Mellem are joined by Jen Lotze from IT Audit Labs to dissect three headlines that prove the threat landscape isn't just evolving—it's accelerating. From brand impersonation scams that exploit your brain's pattern recognition to ClickFix malware that bypasses antivirus by weaponizing copy-paste commands, this conversation reveals how attackers are shifting from breaking through defenses to manipulating humans into opening the door themselves.

What You'll Learn:

  • Why trusted brands like Microsoft, Amazon, and DHL are irresistible phishing targets, especially during high-traffic seasons when vigilance naturally drops
  • How ClickFix attacks exploit legitimate-looking broken websites to trick users into installing malware through their own command prompts—achieving 60% success rates that evade traditional security
  • Real-world consequences of sophisticated social engineering, including a $116,000 wire fraud loss that proves even tech-savvy professionals aren't immune
  • The privacy and consent implications of Apple's rumored 2027 AI wearable with dual cameras and always-on environmental recording
  • Whether constant surveillance is becoming the unavoidable price of technological convenience—and what that means for building security cultures in organizations today

From training employees to recognize copy-paste scams to navigating the ethics of ambient recording devices, this episode delivers frontline intelligence for security professionals and practical awareness for anyone trying to stay safe online.

phishing #clickfix #cybersecurity #socialengineering #applewearable #privacy #malware #infosec #brandimpersonation

View Details

In this episode of The Audit, co-hosts Eric Brown and Nick Mellem dive deep into organizational psychology and team dynamics with a refreshingly honest look at how IT Audit Labs is using assessments like CliftonStrengths, Kolbe, and PRINT to decode their team. This isn't fluffy HR talk—it's strategic workforce optimization that directly impacts how security teams respond to threats, collaborate under pressure, and execute on complex projects.

Eric and Nick discuss why understanding your team's natural strengths, motivators, and triggers is just as critical as deploying the right tech stack. From reducing meeting bloat to being more intentional with time and resources, they share real-world lessons on building a culture where people operate in their zone of genius. Plus, they tackle the "what tool would you deploy first" scenario—spoiler: it's not what you think.

🔑 KEY TOPICS COVERED:

  • Why organizational assessments (CliftonStrengths, Kolbe, PRINT) matter for security teams
  • How to be more intentional with meetings, time, and team collaboration
  • First tools to deploy in a new security environment (MFA, YubiKeys, Veronus)
  • The shift from reactive security to proactive team alignment
  • Using AI tools like Gemini to streamline communication and decision-making

CliftonStrengths #Cybersecurity #TeamBuilding #ITLeadership #SecurityCulture #CISOLife #InfoSec #OrganizationalPsychology

View Details

What if the difference between AI mediocrity and breakthrough isn't the tool—it's how you architect your approach? Carter Jensen from The Uncommon Business joins the crew to reveal why most people are stuck "button pushing" while others are unlocking 3X productivity gains. This isn't theory; it's the frontline reality of businesses transforming workflows with the right AI architecture.

If you're tired of surface-level AI hype and ready for actionable intelligence on integrating AI into security, compliance, and everyday business operations, this episode delivers. Whether you're Blockbuster or Netflix is up to you.

🎯 What You'll Learn:

  • AI Architecture vs. Button Pushing – The mindset shift that unlocks 3-4X productivity gains instead of mediocre results
  • Real Cybersecurity Wins – How IT teams use AI to speed through compliance audits (PCI, CJIS, HIPAA) and tackle complex security workflows
  • Enterprise Implementation Truth – Why expensive AI tools fail without strategy, and what actually works for business adoption
  • The AI Bubble Debate – Is this hype or the biggest business transformation since the internet? Carter brings receipts from the frontlines

Don't let your team fall behind while competitors architect their way to 4X output. This episode arms IT leaders, CISOs, and security professionals with the mindset shift needed to deploy AI that actually moves the needle. Like, share, and subscribe for more cutting-edge cybersecurity and AI implementation strategies!

ArtificialIntelligence #Cybersecurity #AIforBusiness #ITaudit #ComplianceAutomation

View Details

In this special year-end episode, Joshua Schmidt revisits the most mind-bending moments from The Audit's 2025 season. From Justin Marciano and Paul Vann demonstrating live deepfakes in real-time (yes, they actually did it on camera) to Bill Harris explaining how Google's quantum experiments suggest parallel universes, to Alex Bratton's urgent warning about the AI adoption crisis happening right now in boardrooms everywhere.

What You'll Learn:

  • How adversaries are using free tools to create convincing deepfakes for job interviews and social engineering attacks—and why this represents a national security threat
  • Why NASA shut down its quantum computer after getting results that "challenge contemporary thinking" (and the wild theories circulating about what they discovered)
  • The critical mistake companies are making with AI integration: racing ahead without governance, security frameworks, or responsible use policies
  • How the Pi-hole community exemplifies open-source security at its best—enterprise-grade protection at fractions of the cost
  • Why IT teams saying "no" to AI isn't realistic, and what responsible AI adoption actually looks like

This isn't just a recap—it's a wake-up call. These conversations reveal the inflection points where standing still means falling behind. Whether you're a CISO, security analyst, IT auditor, or business leader trying to navigate AI adoption, these clips offer the perspective you need heading into 2026.

Don't wait until 2026 to realize you missed the critical shift. Subscribe now for cutting-edge cybersecurity insights that keep you ahead of evolving threats.

cybersecurity #deepfake #quantumcomputing #AI #infosec #ethicalhacking #cyberdefense #2025yearinreview

View Details

What if you could hire an army of AI security analysts that work 24/7 investigating alerts so your human team can focus on what actually matters? Edward Wu, founder and CEO of DropZone AI, joins The Audit crew to reveal how large language models are transforming security operations—and why the future of cyber defense looks more like a drone war than traditional SOC work.

From his eight years at AttackIQ generating millions of security alerts (and the fatigue that came with them), Edward built DropZone to solve the problem he helped create: alert overload. This conversation goes deep on AI agents specializing in different security domains, the asymmetry problem between attackers and defenders, and why deepfakes might require us to use "safe words" before every Zoom call.

What You'll Learn:

  • How AI tier-1 analysts automate 90% of alert triage to find real threats faster
  • Why attackers only need to be right once, but AI can level the playing field
  • Real-world deepfake attacks hitting finance teams right now
  • The societal implications of AI-driven social engineering at scale
  • Whether superintelligence will unlock warp engines or just better spreadsheets

If alert fatigue is crushing your security team, this episode delivers the blueprint for fighting back with AI. Hit subscribe for more conversations with security leaders who are actually building the future—not just talking about it.

cybersecurity #AIforCybersecurity #SOC #SecurityOperations #AlertFatigue #DropZoneAI #ThreatDetection #IncidentResponse #CyberDefense #SecurityAutomation

View Details

When hackers target the systems controlling your water, power, and transportation, the consequences go far beyond data breaches—people can die. Leslie Carhartt, Technical Director of Incident Response at Dragos, pulls back the curtain on one of cybersecurity's most critical blind spots: industrial control systems that keep society running but remain dangerously exposed.

What You'll Learn:

  • Why industrial control systems can't be updated like your laptop—and what that means for security
  • How threat actors are using AI to generate custom malware for power plants and water treatment facilities
  • The real state of critical infrastructure security (spoiler: forget about air gaps)
  • Why commodity ransomware has become an existential threat to industrial operations
  • The five critical controls organizations should implement right now to defend OT environments

Don't wait until your organization becomes the next headline. Like, share, and subscribe for more in-depth security intelligence that goes beyond the buzzwords.

industrialcybersecurity #criticalinfrastructure #OTsecurity #ICS #SCADA #dragos #incidentresponse #ransomware #AIthreats #cybersecurity #infosec

View Details

What if your security team is playing defense while hackers play offense 24/7? Foster Davis, former Navy cyber warfare officer and founder of BreachBits, breaks down why traditional penetration tests become obsolete in weeks—and how continuous red teaming changes the game. From hunting pirates in the Indian Ocean to defending critical infrastructure, Foster shares hard-earned lessons about adversarial thinking, operational risk management, and why the junior person in the room might spot your biggest vulnerability.

What You'll Learn:

  • Why red teaming creates psychological advantages penetration testing can't match
  • How operational risk management translates technical findings into executive action
  • The real cost of point-in-time security assessments (hint: ask St. Paul, Minnesota)
  • Military-grade frameworks for continuous threat simulation in civilian organizations
  • Why attackers operate 365 days a year—but most organizations test once

Don't let your organization become another headline. Security teams need to think like attackers, not just defenders. Subscribe for more conversations that challenge conventional cybersecurity thinking.

RedTeam #CybersecurityStrategy #PenetrationTesting #MilitaryCyber #ThreatHunting #InfoSec

View Details

What if everything AI tells you about cybersecurity costs is completely wrong? The Audit crew unpacks a shocking data black hole that has infected every major AI model—plus field-tested tech that actually works.

In this laid-back Field Notes episode, Joshua Schmidt, Eric Brown, and Nick Mellum return from Gartner's CIO Symposium with insights that'll make you question your AI outputs. From discovering that the "trillions in cybercrime" statistic is pure fiction (the real number is 16.6 billion) to hands-on reviews of Starlink Mobile and Nothing earbuds, this episode delivers practical intelligence you won't find in vendor pitches.

Don't wait for the next data breach to question your assumptions. Subscribe for monthly Field Notes episodes that cut through the noise with honest, technical conversations you can trust.

cybersecurity #AI #artificalintelligence #GartnerCIO #infosec #starlink #fieldnotes #cybertrends #datasecurity #AIbias

View Details

What happens when Apple Vision Pro meets enterprise AI? In this episode of The Audit, Alex Bratton—applied technologist and AI implementation expert—joins hosts Joshua Schmidt and Nick Mellem to reveal how spatial computing and artificial intelligence are colliding to reshape how we work. From conducting million-dollar sales meetings in virtual reality to building AI governance frameworks that actually work, Alex breaks down the cutting-edge tech that's moving faster than most organizations can keep up.

This isn't theoretical innovation—it's practical implementation. Alex shares real-world examples of pharmaceutical reps training with AI-powered virtual doctors, airlines redesigning airport gates in spatial environments, and manufacturing teams using Vision Pro for secure work on confidential documents at 30,000 feet. If you've been skeptical about AR/VR or overwhelmed by AI adoption, this conversation delivers the clarity you need to make informed decisions for your organization.

Key Topics:

  • Why Apple Vision Pro is the "iPhone 1 moment" for spatial computing and what that means for enterprise security
  • The three categories of AI tools: reactive assistants, task-based agents, and goal-oriented digital employees
  • How to build AI governance frameworks without crushing innovation or falling behind competitors
  • Real security concerns with AI tools and which vendors are actually protecting your data
  • Why mid-market companies are outpacing Fortune 500s in AI adoption—and what that means for your industry
  • Practical strategies for baking AI into company culture without triggering employee resistance
  • The critical difference between free AI tools that steal your data and paid platforms that protect it

Whether you're a CISO evaluating AI tools, an IT director building governance policies, or a security professional trying to stay ahead of threats, this episode delivers actionable intelligence you can implement today. The AI revolution isn't coming—it's already here. The question is whether your organization will lead or get left behind.

cybersecurity #infosec #AI #VR #AppleVisionPro

View Details

Ever wonder what the hosts of The Audit talk about when the mics are rolling but the formal interview isn't happening? This Field Notes episode gives you exactly that—unfiltered conversations covering everything from coffee preferences and glider flying to trademark scams targeting cybersecurity professionals.

Nick and Eric dive into Eric's latest aviation adventures (spoiler: gliders are apparently safer than planes with engines), share war stories about scam calls trying to exploit trademark filings, and swap tales about expensive vet visits. Plus, hear some nostalgic cybersecurity stories from the Wild West days when networks ran without firewalls and people could taste peanut butter straight from the jar at grocery stores.

Key Topics:

  • Eric's glider pilot training and why it's "safer" than powered flight
  • Trademark registration scams targeting IT professionals
  • Coffee roasting tips from flight instructors
  • Cybersecurity nostalgia: Temple University's router-only network
  • Why Eric kept a scammer on the phone for 5 minutes during pickleball

Whether you're here for the cybersecurity insights or just want to know why Nick prefers Diet Coke to Coke Zero, this episode delivers the authentic conversations that happen between industry pros. Don't miss Eric's glider safety argument—it might just change your perspective on risk management.

cybersecurity #infosec #fieldnotes #aviation #scamcalls #itauditlabs

View Details

Cybercriminals are exploiting X's Grok AI to bypass ad protections and spread malware to millions—while researchers discover your home Wi-Fi can now monitor your heart rate. This week's news breakdown covers the attack vectors you need to know about.

Join co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem as they dive into the latest cybersecurity developments that could impact your organization tomorrow. From social media malvertising to biometric data harvesting through everyday devices, these aren't distant threats—they're happening now.

Key Topics Covered:

  • How cybercriminals are weaponizing Grok AI for malvertising campaigns
  • Why 10-15% of employees access risky content at work (and what to do about it)
  • Wi-Fi devices that can detect heart rates from 10 feet away—privacy implications
  • Amazon's Project Kuiper vs. Starlink: What 1GB satellite internet means for security
  • Practical defenses: YubiKeys, browser isolation, and network redundancy strategies

Don't wait until your organization is the next headline. IT leaders need to stay ahead of evolving threats, and this episode delivers critical insights to help protect your business. Like, share, and subscribe for more in-depth security discussions!

cybersecurity #infosec #grok #malware #starlink #wifi #privacy #ITsecurity

View Details

The threat landscape is moving faster than ever—and traditional response playbooks aren't keeping up. In this live Field Notes episode, Eric Brown and Nick Mellum dive into the surge of recent cyberattacks hitting state governments, transit systems, and critical infrastructure across the U.S.

From Nevada's complete state office shutdown to Maryland's Metro Transit paralysis, the hosts explore why organizations still "clam up" during breaches instead of sharing crucial threat intelligence. Drawing from their firsthand experience with the St. Paul incident and military-grade preparedness principles, they reveal the uncomfortable truth: you're not building higher walls anymore—you're planning for someone who's already inside.

Key Topics Covered:

  • Recent state-level cyberattacks in Nevada and Maryland
  • Why threat intelligence sharing fails when we need it most
  • The human cost of breach response chaos and endless meetings
  • How AI is being weaponized in sophisticated supply chain attacks
  • Military mindset for cybersecurity: "Semper Gumby, always flexible"

Don't wait for the next headline. Subscribe for more unfiltered cybersecurity discussions that bridge the gap between technical reality and human preparation.

cybersecurity #infosec #breach #threatintelligence #fieldnotes #livecast #CISO #cybersecuritynews

View Details

When ransomware hits a hospital, it's not just data that's at stake—patients are dying. Ed Gaudet, CEO of Censinet, reveals the shocking research proving what healthcare security professionals feared: cyberattacks on hospitals directly increase mortality rates and disrupt life-saving care.

But Ed's biggest concern? The eerie quiet before what he believes could be the next wave of coordinated attacks across multiple critical infrastructures. Plus, why Microsoft's approach to AI integration is making cybersecurity professionals lose sleep.

  • Key Topics Covered:
  • Why ransomware attacks on hospitals increase patient mortality rates
  • The research behind healthcare cybersecurity's deadly consequences
  • How the healthcare industry's digital transformation created new vulnerabilities
  • Microsoft's problematic approach to forced AI integration
  • The evolution from individual hackers to organized cybercrime syndicates
  • Why Ed's "Spidey senses" are warning of coordinated infrastructure attacks

Don't wait until your organization becomes the next healthcare headline. Subscribe for more critical cybersecurity insights that could save more than just your data.

healthcarecybersecurity #ransomware #patientsafety #cybersecurity #infosec #healthcare

View Details

What happens when your next hire isn't who they claim to be? In this eye-opening episode of The Audit, we dive deep into the alarming world of AI-powered hiring fraud with Justin Marciano and Paul Vann from Validia. From North Korean operatives using deepfakes to infiltrate Fortune 500 companies to proxy interviews becoming the new normal, this conversation exposes the security crisis hiding in plain sight.

Key Topics Covered:

  • North Korean operatives stealing US salaries to fund nuclear programs
  • How Figma had to re-verify their entire workforce after infiltration
  • Live demonstrations of deepfake technology (Pickle AI, DeepLiveCam)
  • Why 80-90% of engineers believe interview cheating is rampant
  • Validia's "Truly" tool vs. Cluely's AI interview assistance
  • The future of identity verification in remote work
  • Why behavioral biometrics might be our last defense

This isn't just about hiring fraud—it's about the fundamental breakdown of digital trust in an AI-first world. Whether you're a CISO, talent leader, or anyone involved in remote hiring, this episode reveals threats you didn't know existed and solutions you need to implement today.

Don't let your next hire be your biggest security breach. Subscribe for more cutting-edge cybersecurity insights that you won't find anywhere else.

deepfakes #cybersecurity #hiring #AI #infosec #northkorea #fraud #identity #remote #validia

View Details

Can you spot the difference between real cybersecurity talent and someone using ChatGPT to fake their way through interviews? In this episode of The Audit, Thomas Rogers from Meta CTF reveals how Capture the Flag competitions are becoming the ultimate litmus test for authentic cyber skills—and why traditional hiring methods are failing in the AI era.

Whether you're a CISO looking to revolutionize your hiring process, a security professional wanting to level up your skills, or just curious about what happens when cybersecurity meets escape room logic, this episode delivers actionable insights you can implement immediately.

Key Topics Covered:

  • How Meta CTF's Jeopardy-style competitions work and why they're addictive
  • Real examples of CTF challenges that test critical thinking over pure technical knowledge
  • The shocking rise of AI-assisted interview cheating (and how to spot it)
  • Why "CTF culture" is becoming the new hiring differentiator for top security teams
  • Practical tips for using competitions to build team camaraderie and retention
  • How smaller companies can compete with Big Tech for cybersecurity talent

Don't let your next hire fool you with AI-generated answers. Learn how CTF competitions reveal the real problem-solvers from the pretenders. Like, share, and subscribe for more cybersecurity hiring secrets that actually work!

MetaCTF #CybersecurityHiring #CTF #InfoSec #CyberSecurity #AIInterviews #TechRecruiting

View Details

Dallas Turner's $240,000 fraud loss isn't just celebrity news—it's a wake-up call for anyone with a bank account. When even NFL linebackers fall victim to social engineering, what does that mean for the rest of us?

In this episode of The Audit, co-hosts Joshua Schmidt, Eric Brown, and Nick Mellem break down the sophisticated tactics behind this massive financial fraud and reveal why help desk vulnerabilities are becoming cybercriminals' favorite attack vector. From Scattered Spider's multi-industry campaigns to the unexpected cybersecurity challenges facing Formula 1 racing, this episode covers the evolving threats that no security professional can afford to ignore.

  • 🎯 Key Topics Covered:
  • How banking impersonation scams work and red flags to watch for
  • Why Scattered Spider targets help desks and how to defend against it
  • The surprising cybersecurity risks in high-speed Formula 1 racing
  • Practical steps to protect yourself from social engineering attacks
  • Why MFA fatigue is becoming a serious security vulnerability

Don't let social engineering catch you off guard. The tactics that fooled a professional athlete could easily target your organization next.

cybersecurity #socialengineering #scatteredspider #financialfraud #infosec

View Details

What does it take to build real cybersecurity skills in underserved communities? In this episode of The Audit, Rasheed Alowonle shares his journey from Chicago to becoming a cybersecurity educator and community advocate. This isn't your typical career advice—it's about fortifying communities through practical security hygiene and hands-on learning.

Co-hosts Joshua J Schmidt, Eric Brown, and Nick Mellum dive deep with Rasheed on his mission to teach cybersecurity fundamentals where they're needed most. From TryHackMe demonstrations to real-world privacy protection, this conversation reveals how grassroots education can transform both individuals and entire communities.

Key Topics Covered:

  • Building cybersecurity skills in underserved communities • Practical privacy protection for families and neighborhoods
  • Career development through hands-on learning platforms
  • The critical importance of in-person networking in tech
  • Why protecting your digital identity protects your community

Don't wait to start building your cybersecurity career—your community needs you. Like, share, and subscribe for more real-world security insights that matter!

cybersecurity #infosec #careerdevelopment #networking #community #privacy #tryhackme

View Details

What happens when your carefully crafted incident response playbook becomes worthless? Cody Sullivan from OpsBook reveals the brutal truth about tabletop exercises: most organizations are practicing with medieval armor for a drone war. From 70-participant, 6-hour exercises spanning three continents to the harsh reality of insider threats, this conversation exposes the gaps that could leave your organization bleeding when the real attack comes.

Key Topics Covered:

  • Why "tribal knowledge" is your organization's biggest security risk
  • The insider threat scenario that makes every tabletop exercise go sideways
  • How AI is revolutionizing incident response preparation through OpsBook's ontology
  • Why your playbooks are useless if hackers have them too
  • The "Derek Jeter approach" to cybersecurity preparedness
  • From real estate to tech: spotting warning signs before the industry shift

The crew shares fresh insights from a recent school district tabletop that exposed critical single points of failure, while Cody demonstrates how modern organizations are turning decision-making into muscle memory, not just memos. This isn't theory—it's the frontlines of organizational resilience where one overlooked vulnerability could trigger catastrophic failure.

Like, share, and subscribe for more in-depth security discussions that prepare you for tomorrow's threats, not just today's compliance checkboxes!

tabletopexercise #incidentresponse #cybersecurity #infosec #AI #opsbook

View Details

Think you can manage industrial systems like your IT infrastructure? Think again. In this episode of The Audit, Dino Busalachi unpacks the high-stakes complexity of OT-IT convergence—and why your trusty IT playbook flatlines on the plant floor.

Join the IT Audit Labs crew as we dive into the chaos of managing 10,000+ industrial assets across a sprawling landscape of vendors, protocols, and operational rules that laugh in the face of standardization. From Siemens to Rockwell to Honeywell, Dino draws sharp parallels to hospital systems juggling specialized third-party contractors—because in the world of OT, consistency is a luxury and adaptability is survival.

🔧 Key Topics Covered:
• Why OT environments resist IT standardization efforts
• Managing thousands of industrial assets from multiple vendors
• The hospital analogy: treating OT specialists like medical contractors
• Building effective partnerships between OT and IT teams • Real-world challenges of securing industrial control systems

OTSecurity #ITConvergence #IndustrialCybersecurity #SCADA #PLC #CriticalInfrastructure

View Details

What happens when you cross a Tamagotchi with a Wi-Fi hacking tool? You get the Pwnagotchi—a pocket-sized device that "feeds" on Wi-Fi handshakes and learns from its environment. In this episode, Jayden Traufler and Cameron Birkland join the crew to demonstrate how this deceptively cute device can passively capture encrypted Wi-Fi credentials from any network in range, autonomously gather handshakes, share intelligence with other Pwnagotchis, and operate completely under the radar from conference floors to airplane cabins in ways that might surprise you.

  • Key Topics Covered:
  • How the Pwnagotchi captures Wi-Fi handshakes through deauthentication attacks
  • Why WPA3 networks are immune (and why most networks still aren't using it)
  • Building your own Pwnagotchi vs buying a Flipper Zero with Wi-Fi dev board
  • Real defense strategies beyond "just turn off your Wi-Fi"
  • The legal gray areas of passive Wi-Fi monitoring
  • Conference horror stories and the 600-handshake airplane incident

Whether you're a security professional looking to understand emerging threats or someone curious about DIY hacking tools, this episode delivers practical insights you can use to protect your networks today. The Pwnagotchi proves that the most dangerous attacks often come in the most innocent packages.

Don't let your organization become the next victim of passive Wi-Fi attacks. Like, share, and subscribe for more hands-on cybersecurity content that keeps you ahead of emerging threats!

Pwnagotchi #cybersecurity #wifihacking #ethicalhacking #infosec #flipper zero

Relevant Links:

Jayden Traufler

  • LinkedIn

View Details

Your network is talking behind your back—but Pi-hole is listening. Join The Audit as Pi-hole co-founders Dan Schaper and Adam Warner reveal how their open-source DNS sinkhole technology has become the secret weapon for over 200,000 privacy-conscious users worldwide.

In this episode, we discuss:

  • How Pi-hole evolved from a simple ad blocker to a critical network security tool
  • Why DNS-level filtering stops threats before they reach any of your devices
  • The performance benefits that make browsing noticeably faster
  • Setting up Pi-hole on everything from Raspberry Pi to enterprise hardware
  • How the global development team maintains this powerful security shield
  • Protecting vulnerable IoT devices from malicious traffic
  • The future roadmap for Pi-hole and opportunities to contribute

Don't miss this deep dive into the technology that's reclaiming control of digital footprints one DNS request at a time. Connect with the Pi-hole community at discourse.pi-hole.net and discover why cybersecurity professionals consider this an essential defensive tool.

Like, share, and subscribe for more cutting-edge cybersecurity insights and expert analysis!

pihole #DNSfiltering #networksecurity #adblocking #privacytools #cybersecurity #opensource #infosec

View Details

Join The Audit for a news-packed episode as cybersecurity expert Matt Starland recounts a chilling near-miss with an E-Z Pass phishing scam—received just minutes after renting a car in Florida. His close call highlights how scammers exploit timing and context to deceive even seasoned professionals.

In this episode, we discuss:

  • How a security pro nearly fell for a perfectly timed phishing text
  • The FBI’s 2023 Internet Crime Report and its $16.6B warning
  • Why nearly $5B in losses hit Americans over 60—and why many stay silent
  • The psychological barriers victims face when reporting cybercrime
  • The rise of the “Dead Internet Theory” and AI-generated online content
  • How Meta and others are blurring the line between real and artificial
  • Practical ways to spot AI-generated interactions
  • Why maintaining human connection is key in the age of AI

Don’t miss this timely conversation packed with real-world insights and strategies to help you stay secure in an increasingly digital (and artificial) world.

Like, share, and subscribe for more cutting-edge cybersecurity stories and expert analysis.

infosec #cybersecurity #E-ZPass #phishing #FBI #deadinternet #meta

View Details

Join The Audit as we dive into the high-stakes intersection of critical infrastructure and cybersecurity with Tim Herman, President of InfraGard Minnesota. InfraGard is a unique public-private partnership with the FBI designed to protect the 85% of America's essential systems owned by the private sector. From power grids to transportation, the vulnerabilities are real—and increasingly complex.

In this episode, we discuss:

  • How joystick-operated tugboats on the Mississippi reveal hidden cyber risks
  • Why tabletop exercises are vital for incident readiness
  • Common mistakes in organizational response plans (and how to fix them)
  • The importance of physical backups and redundant communication systems
  • Actionable steps to bridge the gap between planning and execution

Cybersecurity isn’t just an IT issue—it’s national security. Don’t miss this compelling conversation on how InfraGard is helping organizations build resilience before the next breach hits.

Like, share, and subscribe for more expert insights from the frontlines of cybersecurity.

View Details

Join The Audit as we explore the cutting-edge world of quantum computing with information security architect, Bill Harris. Quantum technology is advancing at breakneck speed, pushing the boundaries of computation, while Quantum Key Distribution (QKD) is making encrypted communications nearly unbreakable.

As multiple sectors race to integrate quantum and AI, cybersecurity experts are racing to implement quantum-resistant encryption before traditional cryptographic methods become obsolete. Beyond the technical breakthroughs, quantum computing is also raising profound questions about reality itself.

In this episode, we discuss:

  • The rise of 1,000-qubit machines and persistent error challenges
  • How QKD is reshaping secure communication worldwide
  • Microsoft’s Majorana particle claims—fact or hype?
  • NASA’s mysterious quantum shutdown in February 2024
  • Google’s research into quantum and unexpected findings
  • The cybersecurity arms race to counter quantum decryption

Quantum computing isn’t just the future—it’s here, and it’s reshaping everything from cybersecurity to our understanding of the universe. Don’t miss this deep dive into the most mind-bending technology of our time!

Like, share, and subscribe for more in-depth cybersecurity insights.

QuantumComputing #Cybersecurity #Encryption #AI #ParallelUniverses

View Details

What Really Happens to Your Trash? Inside Modern Waste Management

Is your trash really being recycled, or is it ending up in a landfill? In this episode of The Audit, we sit down with Trista Martinson, Executive Director at Ramsey Washington Recycling & Energy, to uncover the surprising technology and cybersecurity challenges behind modern waste management.

Trista joins the IT Audit Labs team to reveal how AI, robotics, and environmental science are transforming recycling, while also sharing how The Audit's own Eric Brown helped strengthen her organization’s cybersecurity to protect critical infrastructure.

In this episode, we discuss:

  • How AI and robotics are revolutionizing waste processing
  • The reality behind China’s global recycling market
  • Why recycling facilities are prime targets for cyberattacks
  • The role of cybersecurity in protecting critical infrastructure
  • How a military mindset influences risk assessment
  • The biggest mistakes people make when disposing of trash

From optimizing recycling with data to securing waste facilities against ransomware, this episode dives deep into the hidden world of trash, tech, and security.

🔔 Subscribe for more cybersecurity and technology insights!

Cybersecurity #WasteManagement #Recycling #AI #TheAuditPodcast

View Details

Are SOC audits just another compliance requirement, or do they provide real security value? In this episode of The Audit, we sit down with Adam Russell from Schellman to debunk common misconceptions about SOC audits and explore why they’re more than just a checkbox exercise—especially for startups.

Adam joins the IT Audit Labs team for a deep dive into the often-misunderstood world of attestations, sharing expert insights on how organizations can effectively prepare for a SOC audit and determine which security assessments best fit their needs.

In this episode we discuss:

  • The biggest mistakes startups make with SOC audits

  • Why SOC 2 is more flexible than you might think

  • The myth that big companies are always secure

  • How SOC assessments can strengthen security culture

  • Gamified training & newsletters for better compliance engagement

  • How external auditors can empower internal teams

Whether you're preparing for your first SOC audit or navigating complex compliance requirements, this episode is packed with actionable insights to help you enhance security and compliance strategies.

🔔 Subscribe for more cybersecurity insights!

Cybersecurity #SOCAudit #Compliance #StartupSecurity #TheAuditPodcast

View Details

Think audits are just paperwork? Think again. They’re the frontline defense against security gaps, data breaches, and unchecked access.

In this episode of The Audit, we break down how Elon Musk’s unexpected access to FEMA’s sensitive data underscores the critical role of audits in organizational security. We reveal how regular audits and third-party reviews expose vulnerabilities, enforce accountability, and strengthen cyber defenses before attackers can exploit them.

Key Topics We Cover:

• How audits uncover hidden cybersecurity risks

• Finland’s cutting-edge approach to cyber resilience

• Why tabletop exercises and real-world drills are game changers

• A shocking social engineering attack at a library—and what it teaches us

Cyber threats evolve fast—don’t wait until you’re the next headline. Whether you're a cybersecurity pro or just getting started, this episode is packed with actionable insights you can’t afford to miss.

Like, share, and subscribe for the latest cybersecurity news and expert analysis!

Cybersecurity #Auditing #Infosec #SocialEngineering #SecurityNews

View Details

You’re Being Hacked Right Now—And You Don’t Even Know It

Ever wonder how cybercriminals manipulate human behavior to breach even the most secure organizations?

In this episode of The Audit, Eric Brown and Nick Mellum sit down with renowned social engineer and penetration tester Alethe Denis to break down real-world hacking techniques, red team strategies, and the shocking ways attackers exploit trust. From winning DEF CON’s Black Badge Social Engineering competition to executing high-stakes red team engagements, Alith shares jaw-dropping stories and expert insights on modern security threats.

Key topics we cover:

  • The art of social engineering and why it still works
  • Wildly effective pretexts hackers use to gain access
  • How AI and deepfakes are shaping the future of cybercrime
  • Physical penetration testing stories that will make you rethink office security
  • Simple but powerful strategies to protect yourself and your organization

Don't wait until your organization is the next headline. Whether you're a cybersecurity pro or just getting started, this episode is packed with eye-opening insights you can’t afford to miss. Like, share, and subscribe for more in-depth security discussions!

Cybersecurity #SocialEngineering #PenTesting #EthicalHacking #RedTeam

View Details

Discover the hidden risks of browser extensions, cybersecurity incidents, and more with hosts Eric Brown and Nick Mellum.

In this episode, we dive into the dangers of tools like Honey, the fallout from Proton’s global outage, and the ingenious tactics used by cybercriminals to target unsuspecting users. Eric and Nick also share their insights on using big data to enhance security, the role of AI in addressing threats, and practical tips for staying ahead of the ever-changing tech landscape in 2025.

We'll cover:

  • The surprising risks behind popular browser extensions like Honey
  • Lessons from Proton’s global outage and the importance of preparation
  • How cybercriminals use voice phishing to exploit tech giants
  • Practical steps to improve organizational security and educate users
  • Balancing security and accessibility in modern systems

From practical advice to thought-provoking insights, this episode delivers actionable takeaways for anyone navigating today’s tech landscape.

Cybersecurity #TechNews #DataPrivacy #RiskManagement #DigitalSafety

View Details

Dive into the transformative power of data in cybersecurity in this must-watch episode with Wade Baker, where cutting-edge insights meet real-world applications.

Hear from The Audit Team as we discover how massive data sets are reshaping risk management, AI’s evolving role in combating cyber threats, and the surprising insights data can unveil about security incidents. We also dive into ransomware trends, phishing techniques, the ethics of AI, and the critical role of storytelling in decision-making, with some fun nods to fantasy swords along the way.

In this episode, we discuss:

  • Using big data to tackle cybersecurity challenges
  • Ransomware and phishing trends
  • The ethical debate around AI in security
  • Unique discoveries from security data analysis
  • Practical strategies for influencing decision-makers

Catch this insightful conversation and stay ahead of the cybersecurity curve. Like, share, and subscribe for more expert discussions on the latest security trends!

Cybersecurity #DataAnalytics #RiskManagement

View Details

Join us for an eye-opening discussion on cybersecurity in travel with ethical hacker Matthew Wold from Ramsey County. Matthew shares how his passion for cybersecurity took root at Ramsey County, leading to collaborations with co-hosts Eric Brown and Nick Mellem. We kick things off with a lighthearted chat about survival items on a deserted island, setting the stage for a lively and insightful conversation.

From RFID shields to OMG cables, we unpack practical tips for protecting your digital and personal safety while traveling. Learn how to navigate risks like compromised USB ports, hidden cameras in hotel rooms, and data privacy challenges across borders. With advice on VPNs, securing SIM cards, managing passwords, and safeguarding luggage, this episode is packed with essential strategies to ensure your travel experiences remain secure and worry-free.

View Details

From Gmail 2FA bypass warnings to SEO poisoning campaigns, we’re diving into the latest cybersecurity headlines reshaping the industry.

We explore how attackers are using hyper-specific search terms—like the legality of Bengal cats—to deliver malware and manipulate search results. Plus, we discuss advancements in AI-powered behavioral analytics, from cutting down false alerts to streamlining incident response. With real-world insights and actionable tips, this episode is packed with must-know updates for IT professionals navigating today’s ever-evolving threat landscape.

In this episode, we'll discuss:

  • Gmail session cookie theft and bypassing two-factor authentication.
  • SEO poisoning campaigns delivering malware via niche search terms.
  • AI-driven behavioral analytics improving incident response.
  • Real-world social engineering and user behavior risks.
  • Balancing usability and security with tools like passkeys.

Thanks for tuning into The Audit. Subscribe on Spotify, Apple Podcasts, or YouTube to stay informed on the latest in cybersecurity. Don’t forget to follow us on social media and share with your network!

CybersecurityNews #2FA #BehavioralAnalytics #IncidentResponse #SEOPoisoning #ITSecurity #DataProtection

View Details

In this episode of The Audit, we dive into key takeaways from a top cybersecurity event. From IoT hacking and RFID bypasses to AI governance and vishing bots, we explore the tools and strategies shaping security. Plus, real-world lessons, social engineering insights, and a few unexpected laughs—because security isn’t always all business.

In This Episode We’ll Cover:

  • RFID hacking and social engineering insights from WWHF.
  • Cameron’s IoT hacking training highlights.
  • AI advancements and governance takeaways.
  • Challenges with regulations and compliance in cybersecurity.
  • Project management lessons inspired by Elon Musk.

Thanks for joining us for this glimpse into one of the year’s most unique cybersecurity events. Don’t forget to subscribe and share this episode with your team—we’ll see you at the next conference.

#WWHackinFest #InfoSecConferences #Cybersecurity #AIThreats #IoTSecurity #SocialEngineering

View Details

In this episode, we dive into emerging tech with Marsha Maxwell, co-founder of If These Lands Could Talk and Head of Innovation at Atlanta International School. Marsha shares insights on empowering indigenous and underserved communities through AI and VR, the ethical challenges of integrating AI, and the importance of digital inclusion. We discuss the impact of AI on knowledge, culture, and education and examine how to responsibly bridge gaps in tech access worldwide.

In this episode we cover:

  • Exploring AI and VR for indigenous and underserved communities
  • Bridging digital divides: Tech access for all
  • Ethical challenges in AI and identity
  • How to navigate digital authenticity in the age of deepfakes
  • The future of AI in creative and cultural spaces
  • Practical strategies for blending AI with education and learning

Tune in for a compelling look at the intersection of technology, education, and culture. Don’t forget to like, subscribe, and share to stay updated with our latest episodes!

ArtificialIntelligence #EmergingTech #DigitalInclusion #CyberSecurity #DataProtection #AIinSecurity

View Details

Building secure software isn't optional—It's critical. Here’s how you can do it right!

In this episode of The Audit presented by IT Audit Labs, we’re joined by Francis Ofungwu, CEO of DevSecFlow, to break down the urgent topic of software security. Together with Nick Mellom and Bill Harris, we dive into the common security threats developers face today and discuss the vital steps every company should take to secure their software development lifecycle.

In this episode, we’ll cover:

  • The biggest software security threats developers face in 2024
  • How to integrate security seamlessly into the software development lifecycle
  • The convergence of infrastructure security and software security
  • The role of AI in secure coding and software development
  • The importance of threat modeling and attack surface reviews
  • How to create a more resilient software supply chain and manage risk effectively

Whether you’re a developer, security pro, or IT decision-maker, this episode is packed with actionable insights to elevate your security strategy and ensure your software is built to withstand today’s evolving cyber threats.

Don’t forget to hit that subscribe button and drop a comment below on your top takeaway!

CyberSecurity #DevSecOps #SoftwareSecurity #AICoding #IncidentResponse #ITSecurity #CloudSecurity #RiskManagement

View Details

In this episode of The Audit by IT Audit Labs, we sit down for an in-depth conversation with Eric Brown to explore the crucial topic of personal information security.

Eric breaks down essential strategies for protecting your data, starting with freezing your credit, leveraging password managers, and implementing multi-factor authentication. He also dives into how these personal security measures directly tie into a broader corporate security posture.

In this episode, we cover:

  • Credit freezes and why they’re your first line of defense
  • How email breaches occur and what to do when your account is compromised
  • Why password managers and passphrases are game changers for security
  • The role of multi-factor authentication in thwarting attackers
  • Tips for maintaining privacy in an era of data mining and social engineering

Stay tuned as we dive into the details and explore how securing your personal data can help protect your organization from threats.

Make sure to subscribe to The Audit on your preferred podcast platform to stay up to date on the latest insights from IT Audit Labs!

cybersecurity #datasecurity #personalinformationsecurity #informationsecurity

View Details

Discover the vital intersection of safety science and cybersecurity, where human psychology meets technical innovation.

In this episode of The Audit, special guest John Benninghoff shares his expertise in safety science and how its principles can improve cybersecurity. From applying safety protocols in the tech industry to enhancing security culture through proactive human behaviors, we dive into a range of topics. Plus, we discuss how risk quantification and ergonomics can drive better security outcomes.

In this episode, we’ll cover:

  • How safety science principles can enhance cybersecurity practices
  • The role of human behavior and psychology in security outcomes
  • Lessons from aviation safety and their application in risk management
  • Real-life examples of security clutter and how to reduce it for better outcomes
  • The importance of risk quantification and proactive system maintenance

Join us as we explore key insights and practical tips on blending safety science with cybersecurity, and don't forget to subscribe to The Audit podcast for more insightful discussions covering the full spectrum of cybersecurity.

Cybersecurity #SafetyScience #RiskManagement #DataProtection

View Details

In this episode of The Audit, we’re joined by Mick Leach from Abnormal to discuss the evolving landscape of email security and how AI is transforming both the threats and defenses in this space.

From QR code phishing to the rise of sophisticated AI-driven attacks, Mick shares insights on how organizations can stay ahead of these challenges, leveraging AI for good. We also touch on the latest trends in SaaS security and what the future of cybersecurity might look like.

We'll cover:

  • The rise of AI-driven phishing attacks
  • How CrowdStrike’s recent issues tie into broader security concerns
  • The evolving role of security tools like Abnormal in email protection
  • The growing threat of QR code phishing and how to mitigate it
  • Insights on SaaS applications and their vulnerabilities
  • Strategies for organizations to combat AI-generated threats

Stay ahead of emerging email threats and learn how AI can protect your organization by subscribing today!

CyberSecurity #EmailSecurity #EmailCybersecurity #AI #Phishing #Quishing

View Details

Stay informed with The Audit, your go-to podcast for the latest in cybersecurity insights, best practices, news and trends. In this month's news episode, we tackle the most significant developments shaping the industry today.

We'll cover:

  • The latest insights from CrowdStrike on evolving cybersecurity threats
  • The impact of the Supreme Court ruling on cybersecurity regulations
  • The massive 10 billion password leak and how to protect your organization
  • Guard Zoo malware targeting military personnel in the Middle East
  • How AI is transforming proactive cybersecurity measures
  • Best practices for password management and multi-factor authentication
  • The role of AI in optimizing and simplifying policy management in organizations

New episodes air every 2 weeks -- Don't miss out on expert insights that will help fortify your defenses against emerging cyber threats.

Cybersecurity #AI #TechNews #ITSecurity #Malware

View Details

Discover the fascinating world of OSINT (Open Source Intelligence) with expert insights from Melisa Stivaletti on this episode of The Audit!

Hosted by Eric Brown and Nick Mellem from IT Audit Labs, we sit down with Melisa Stivaletti, Chair at Epic and OSINT Director at GuideHouse. Melisa shares her remarkable journey from working at the Department of Commerce to the Department of the Army. We dive deep into the world of OSINT, discussing the nuances of open source research, tradecraft, and the transformative power of AI. Plus, Melisa shares valuable advice for those looking to break into the OSINT field and highlights the importance of lifelong learning.

In this episode, we cover:

▪ The difference between open source research and OSINT
▪ The tradecraft involved in OSINT, including the use of sock puppets
▪ How AI is transforming OSINT and the guardrails needed to manage its use
▪ The critical role of data governance and compliance in OSINT
▪ The future of OSINT and the importance of lifelong learning in this field
▪ Personal stories and advice for those looking to enter the OSINT community

Don’t miss out on Melisa's unique insights and experiences. Listen now and elevate your understanding of cybersecurity and OSINT.

Cybersecurity #OSINT #InformationSecurity #ITSecurity #SecurityInnovation

View Details

Join us for the July 2024, live news episode of 'The Audit', where we cover the latest cybersecurity threats, ransomware updates, and AI advancements.

In this news episode, we tackle some of the most pressing cybersecurity issues of the month. Ever wondered how a ransomware attack could shut down a public library? We dive into the recent attack on the Seattle Public Library and explore a massive $37 million phishing scam that hit Coinbase Pro users. We also unravel the sophisticated gift card fraud by the Moroccan cybercrime group Storm 0539.

But that's not all. We discuss the potential threat of DNS bomb DDoS attacks and the intriguing use of Flipper Zero devices to hijack event wristbands. And for those interested in the intersection of law and cybersecurity, we examine the implications of the Supreme Court's recent ruling on cybersecurity regulation.

Amidst all the tech talk, we find time to ponder the existence of UFOs and share some personal stories about unexplained phenomena.

In this episode we’ll cover:

  • Seattle Public Library ransomware attack and its impact
  • $37 million phishing scam targeting Coinbase Pro users
  • Moroccan cybercrime group Storm 0539's gift card fraud
  • Potential threat of DNS bomb DDoS attacks
  • Flipper Zero devices hijacking event wristbands
  • Supreme Court's ruling on cybersecurity regulation

Stay ahead of cyber threats and AI innovations by watching the full episode. Don’t forget to like, subscribe, and share your thoughts in the comments!

Cybersecurity #Ransomware #AI #TechNews #Phishing #ITSecurity #CyberLaw

View Details

Unlock the secrets behind the powerful HAC5 Pineapple tool in this episode of The Audit.

Hosts Eric Brown and Nick Mellum, joined by Cameron Birkeland, explore the tool's functionalities and features, offering practical insights and real-world applications. Discover how the HAC5 Pineapple can enhance your cybersecurity measures, with discussions on model comparisons, security implications, and best practices.

In this episode we’ll cover

  • What is the HAC5 Pineapple?
    Comparing the Tetra and Mark 7 models
  • Real-world uses and case studies for the Pineapple
  • Key security implications and best practices
  • Cool features of the Pineapple and a live demo
  • How to generate detailed reports with the Pineapple

Join us for an engaging discussion packed with valuable information for cybersecurity professionals and enthusiasts alike. Don’t miss out on our latest insights and tips!

Cybersecurity #HAC5Pineapple #PenTesting #EthicalHacking #WiFiSecurity #CyberThreats

View Details

Welcome to the latest episode of "The Audit," where we bring you the most pressing news, issues and insights in cybersecurity.

In this live episode, we cover the recent ransomware attack on the Seattle Public Library, the $37 million theft from Coinbase Pro users, and the sophisticated gift card fraud by the Moroccan cybercrime group, Storm 0539. We share our insights on how these attacks happened, their impacts, and practical advice on how to protect yourself and your organization. We also explore a theoretical DNS bomb DDoS attack and the intriguing use of Flipper Zero devices to control wristbands at large events.

  • Seattle Public Library ransomware attack and its impact
  • $37 million phishing scam targeting Coinbase Pro users
  • Moroccan cybercrime group Storm 0539's gift card fraud
  • Potential threat of DNS bomb DDoS attack
  • Flipper Zero devices hijacking event wristbands

Thanks for tuning in! Don't forget to like, subscribe, and share your thoughts in the comments.

CybersecurityNews #Cybersecurity #Ransomware #Phishing #ITSecurity #TechNews

View Details

Explore the intriguing intersection of quantum computing and cybersecurity... It’s closer than you think.

In this episode, special guest Bernie Leung from Autodesk shares his expert insights on how quantum computing is reshaping the cybersecurity landscape. Discover the challenges and breakthroughs in encryption practices as Bernie breaks down complex concepts like the Shor Algorithm and discusses practical steps for adapting to this new era of cybersecurity.

In this episode, we dive into:

  • The essentials of quantum computing and how it could revolutionize encryption.
  • Current encryption vulnerabilities that quantum computing could exploit.
  • An introduction to post-quantum cryptography and the new standards on the horizon.
  • Practical uses of quantum computing in cybersecurity today and what we might see in the future.
  • How governments and businesses are preparing for quantum threats, including updates in regulations and security protocols.

This discussion is not just theoretical; it's a guide to understanding and preparing for the quantum leap in data protection.

QuantumComputing #FutureOfCybersecurity #Cybersecurity #InfoSec #PostQuantumCryptography

View Details

Cybersecurity veteran Eric Johansson from Phosphorus joins us with a treasure trove of insights on the critical yet often-underestimated field of IoT security. His two-decade expertise brings into sharp focus the challenges that lurk in the shadows of the connected devices we rely on daily. From the conference room tech that could be eavesdropping on your meetings to the smart appliances that keep our homes running smoothly, Eric explores the fine line between functionality and vulnerability.

This conversation with Eric goes beyond the surface, revealing the intricacies of securing the X IoT devices that power industries and infrastructures. We reminisce about the days when technology was simpler but not necessarily safer, and how modern IoT devices, though silent workhorses in logistics and agriculture, can open backdoors to cyber threats. Eric brings his experience in operational technology to dissect the differences between IT and OT security, emphasizing why it's imperative to tailor strategies to these unique environments.

Wrapping up our enlightening session, we tackle the tangible business effects of IoT security, discussing the successes and setbacks in device management. We weigh in on the urgent need for regulatory standards in IoT security, pondering the potential benefits of a governing body to set the course for safer interconnected systems. From Fortune 20 companies to the quaintest of smart homes, tune in to understand the full scope of IoT security and how experts like Eric Johansson are leading the charge in safeguarding our digital world.

View Details

Get ready for a special episode of The Audit! We're celebrating our 40th episode with Brian Johnson, host of the 7-Minute Security podcast, as we talk cybersecurity, social engineering, and some wild stories that you won't want to miss.

We’ll explore the role of tabletop exercises in shoring up a company's security and dive into the fascinating world of open-source intelligence. We’ll uncover what it takes to protect against cyber threats, why pen testing matters, and how social engineering tests can be a rollercoaster of nerves. Brian also shares his journey from being a Christmas caroler in "Jingle All the Way" to being a cybersecurity consultant and podcast host. This episode is packed with insights, laughs, and even some hairless cats.

  • Brian Johnson's journey from Christmas caroler in "Jingle All the Way" to cybersecurity consultant and podcast host
  • The role of tabletop exercises in improving a company's security posture
  • Pen testing insights: why it matters and how it's done
  • Social engineering stories: the highs and lows of testing human vulnerabilities
  • Open-source intelligence: what it is and why it's important for cybersecurity
  • Unexpected surprises: including stories about skydiving and hairless cats

If you're interested in cybersecurity and want to hear some great stories from the industry, this episode has you covered. Enjoy the laughs and insights, and don't forget to like, share, and subscribe for more content from The Audit.

Cybersecurity #PenTesting #SocialEngineering #Skydiving

View Details

In this episode we explore the intersection of AI and cybersecurity in the construction industry with John Massie, Technology Director at Journey Group.

John shares his insights on integrating technology to enhance cybersecurity and operational efficiency within the construction sector. The discussion covers a range of topics from combatting sophisticated phishing attacks to the strategic use of AI tools like ChatGPT and Copilot. Delve into the challenges of AI-generated content, governance, intellectual property concerns, and the transformative impact of AI on traditional business models.

In this episode we cover:

  • Best practices for AI in non-tech sectors
  • Cybersecurity policies for AI
  • Mitigating cyber security risks in construction
  • AI's role in the construction industry
  • Ethical challenges of AI-generated content
  • Future trends in AI governance
  • AI's implications for industry standards

Stay tuned for more insights into the future of IT technology and its transformative effects on the business landscape.

AIcybersecurity #Cybersecurity #Infosec #ConstructionTech #AIPolicies

View Details

Join us on The Audit for a critical examination of cybersecurity's latest frontiers: threats to our water system and the push for global IoT security standards.

In this episode, our team of cybersecurity experts, Eric Brown and Nick Mellum, dissect the Biden administration's recent warnings about cyber-attacks on U.S. water utilities and delve into the newly announced IoT device security specifications by The Cloud Security Alliance (CSA). From nation-state actors targeting essential infrastructure to the complexities of securing IoT devices in your home, this discussion offers invaluable insights into safeguarding our digital and physical worlds.

What You'll Learn:

  • The significance of recent cybersecurity warnings regarding the water sector.
  • The importance of a unified cybersecurity standard for IoT devices.
  • Strategies for securing IoT devices within corporate and home networks.
  • The role of cybersecurity in ensuring the safety and reliability of essential public utilities.

View Details

In this episode of The Audit, we dive into the world of phishing to uncover the sophisticated tactics that make these scams the leading threat in cybersecurity. Join us as Jamie Arndt, a cybersecurity expert with extensive experience in reverse engineering and analyzing malicious emails, shares his insights and stories from the front lines.

We’ll cover:
• The rise of generative AI in crafting phishing emails that bypass traditional detection methods.

• Real-world stories of phishing attacks, from impersonating school communications to exploiting professional relationships.

• The psychological tactics used by attackers to exploit human nature and gain access to sensitive information.

• Innovative defense strategies and tools that organizations can employ to protect themselves against phishing attempts.

• Practical advice for individuals on recognizing phishing attempts and safeguarding personal information.

This episode arms you with the knowledge of what to look for in phishing emails, emphasizing the importance of vigilance and education in the digital age.

View Details

How exposed are your 3D printing operations to cyber threats? Is the intellectual property involved in 3D printing at risk, and can 3D printers themselves become targets for hackers?

As 3D printing technology becomes more integrated into various industries, its cybersecurity implications cannot be ignored. This episode sheds light on the exciting world of 3D printing, focusing on its potential for innovation while addressing the significant cybersecurity challenges it faces.

We'll explore:

• The basics of 3D printing technology and its cybersecurity implications.

• Protecting intellectual property in the realm of 3D printing.

• The vulnerabilities of 3D printers to hacking and how to safeguard them.

• Strategies for securing 3D printing operations against cyber threats.

• Real-world examples of cybersecurity breaches in 3D printing.

Whether you're a cybersecurity professional, a 3D printing enthusiast, or someone interested in the intersection of technology and security, this episode offers valuable insights into protecting your 3D printing projects.

View Details

How secure is a VPN, really? Can a VPN server be hacked, and are these services truly safe? In this episode of The Audit, Joshua, Nick, and Eric tackle these pressing questions head-on.

As the cybersecurity landscape evolves, Virtual Private Networks (VPNs) are increasingly common among cybersecurity professionals and enthusiasts alike... but how secure are they? In this episode, we take you through the mechanics of VPNs, their role in safeguarding your data, and the vulnerabilities that can expose users to risk.

We'll cover:

• What are VPNs and how do they work?

• How to choose the right VPN provider: Considerations and pitfalls.

• The difference between corporate and personal VPN use and their unique challenges.

• How to mitigate risks associated with VPN usage.

• The recent Ivanti VPN breach

If you care about your digital privacy, curious about how VPNs fit into your life, or pondering the real benefits and risks of using VPN services, then this episode is for you.

View Details

It should come as no surprise that building a team can be challenging for cybersecurity professionals. However, we've found that individuals who have served in the military often possess a unique focus and drive, setting them apart in the cyber world.

Clifton Robinson, a former Army logistician and healthcare market analyst, joins our team to discuss his journey to becoming a cybersecurity professional.

Topics covered:

  • How military service helps individuals transition into cybersecurity
  • Why employers appreciate military service in cybersecurity candidates
  • Why are veterans drawn to the field of cybersecurity?
  • How joining the military changed Clifton’s life
  • The importance of mentorship and networking for veterans

If you're a veteran considering a career in cybersecurity or seeking a fresh perspective on the cybersecurity industry, don't miss the latest episode of The Audit!

View Details

Is your digital footprint secure? In our latest episode we unravel the complexities of email and mobile security. Join Dean Morstad, a seasoned cybersecurity expert, as he shares invaluable insights and practical tips to enhance your digital safety.

The conversation includes:

  • Why and how are most of us viewed as a “product”?
  • Practical email security tips and best practices
  • How to avoid phishing scams and other social engineering strategies
  • Mobile device and location tracking insights
  • Organizational security policy tips
  • Why use a password manager

View Details

This episode offers more than just insights; it's a chance to meet the minds who have been combatting cyber threats for decades. We explore topics like ransomware, effective data breach responses, and the integration of AI in cybersecurity. Discover strategies and insights from industry leaders and learn how to fortify your digital defenses in an ever-evolving cyber landscape.

Topics Covered:

  • How to navigate a ransomware attack
  • Data breach response methods
  • Cyber insurance challenges
  • AI, cybersecurity, and the legal considerations
  • Social engineering audits

Gain valuable insights into current trends and practical approaches to enhance your organization's security posture. Be sure to subscribe today!

View Details

In this episode of The Audit, Leah McLean shares her insights from over 10 years in cybersecurity and IT with companies like Cisco, and now Mastercard.

We’ll cover:

  • How to get a job in cybersecurity
  • Navigating the ethical challenges of AI in Cybersecurity
  • Work-life balance in cybersecurity jobs
  • Perspectives on success for cybersecurity leadership
  • Emerging infosec technologies
  • Mental health for infosec professionals

We navigate the shifting terrain of cybersecurity talent acquisition, stressing the need for aptitude and ongoing education. Leah delves into AI's role and ethical dilemmas in cybersecurity, provides tips for balancing work and life in remote contexts, and examines upcoming cybersecurity technologies. The discussion also highlights veterans' vital roles in cybersecurity, underscores the importance of mental health in stressful settings, and gives a sneak peek into future 'Elevate Exchange' podcast episodes on topics like AI and quantum computing.

View Details

The Audit - Episode 30 - Join us as we speak with cybersecurity expert and hacking hardware enthusiast Cameron Birkland, who introduces us to the world of the Flipper Zero.

The brainchild of a successful Kickstarter campaign in 2020, the Flipper Zero might look cute with its dolphin avatar, but it's a potent tool capable of manipulating control systems like RFID and NFC tags, radio remotes, and digital access keys.

What would you do if your garage door opener could be hacked? Cameron walks us through how this is possible with his own garage door opener.

Don’t forget, if you prefer video, check out every episode of The Audit on our YouTube channel.

View Details

The Audit - Episode 29 - Ready to uncover the world of crypto? Join us in our latest episode as we dive into the realm of cryptocurrency with Matt Starland. Let's embark on a journey from the origins of Bitcoin to the frenzy of meme stocks making headlines. Tune in to understand how cryptocurrency is shaking the foundation of economies with unstable governments, and how secure, hardware-based crypto wallets can be your ultimate safe vault.

We didn't stop at Bitcoin. Matt Starland, our resident crypto expert, took us on a ride through the volatile landscape of cryptocurrency trading, tackling the challenges of its mainstream adoption and the potential risks. Discover how to set up a hardware wallet and get an inside scoop on the cryptographic algorithms that are its backbone and the all-important recovery seed. By the end of this, you'll be well-versed in the nitty-gritty details of crypto trading and equipped to safeguard your digital assets.

In the final leg of our crypto exploration, we help you navigate the process of setting up a new cryptocurrency wallet, emphasizing the significance of secure offline backup and tightening the security measures. We shed light on the workings of a Bitcoin wallet, the associated fees, and how to maximize its security. Then, we take you through the features of hardware wallets, the processes of buying and selling from a wallet, and the risks of leaving money on an exchange. So sit back, tune in and prepare for a deep dive into the thrilling world of cryptocurrency!

View Details

The Audit - Episode 28 - We are pleased to introduce you to Andre Champagne, an expert in the intriguing world of cyber and digital forensics. Andre’s journey, from the Anoka County Sheriff's Office, through the Illinois Attorney General's Office, to the state of Minnesota, provides fascinating insights into a career in stopping cyber-crime.

Andre also recounts his time managing a digital forensics laboratory, shedding light on the intricate balance between risk and technology in the digital landscape. He shares stories about investigating arson cases, using phone evidence to reveal the diversity of online predators. His anecdotes provide a sobering perspective on the challenges and rewards of a career in cyber forensics.

Finally, Andre breaks down the reality of the cyber security field beyond what you see in TV and film. His experiences range from putting together reports for the courtroom, dealing with data breaches and ransomware, to handling HR investigations. The conversation takes a darker tone as we address the chilling reality of online predators while Andre provides valuable advice on ways to keep children safe online.

View Details

The Audit - Episode 27 - Imagine managing over a million orders per minute during a high-stakes sales event like Black Friday! That's the reality Jeff White from Cockroach faced during his time at Best Buy. We sit down with him in a lively discussion, unpacking the intricacies of running a successful online store, the immense pressure involved, and strategies to guard against malicious acts and bots. Jeff enlightens us about the challenges of scaling an Oracle database to handle a mass influx of orders, sharing insightful anecdotes from his own experience.

Ever wondered how to improve your security posture and reduce organizational risk? Jeff is here to share some answers from a tech perspective. He delves into the unique features of Cockroach DB, a system he played a vital role in developing. Learn how it’s designed to run on various operating systems and its resilience to node failure. Jeff also sheds light on distributed data replication, an intriguing aspect of Cockroach DB. If you're a tech enthusiast or involved in e-commerce, this episode is packed with valuable nuggets of information to take your knowledge several notches higher.

As we wrap up our conversation, we navigate towards Jeff's interest in renewable energy. We delve into his journey with solar power and electric vehicles, outlining the financial benefits of such investments. He shares his solar installation experience and future plans. We also touch on the critical role of a robust team in conducting successful security assessments. Lastly, we consider a new venue for our game night, since our usual spot isn't available. Tune in for this enlightening episode full of expert insights and real-world experiences.

View Details

The Audit - Episode 26 - Ready to decode the future of data storage technology? We guarantee that you'll be fascinated by our in-depth exploration into this rapidly evolving landscape. Together with our esteemed guest, Bill Harris, we probe into the intricacies of current storage mediums, such as hard disk drives, flash drives, and magnetic tapes, while also introducing you to emerging technologies like 5D, DNA, and molecular memory.

How are companies managing their data storage amidst ever-shrinking IT budgets? How are advancements like heat-assisted magnetic recording and microwave magnetic recording redefining hard drive technology? Brace yourself, as we take you on a journey to decipher these challenges and discoveries, along with Harris, a pioneer in the field. The conversation gets even more exciting as we delve into futuristic concepts like holographic and DNA storage, both promising yet fraught with challenges worth discussing.

But we don't stop there. As we dig deeper into the impact of increasing storage capacities, it's evident that a revolution in the way we use and perceive data is imminent. From holographic and 5D crystal storage to DNA storage, we ponder the implications and potential of these advancements on the future of technology. Tune in, let's explore this fascinating world of storage technology together!

View Details

In Part 2 of the Tech Lessons Series by Bill Harris, get ready to unravel the mystery of quantum computing? Brace yourselves as we, your hosts, and our esteemed guest, Bill Harris, take you on a whirlwind tour of this fascinating technology that's set to redefine the future. Possessing the potential to disrupt major industries and even cryptography, quantum computing is a topic you certainly can't afford to miss. 

Imagine a computer that can process information at superluminal speeds. That's the magic of quantum computing! From its application in fields as diverse as healthcare and AI to the challenges it poses, we've got it all covered in this episode. But it doesn't stop there. We discuss the potential threat quantum computers pose to current encryption technologies and the prodigious task of developing quantum-safe encryption techniques. 

Finally, we examine the present landscape of quantum computing, key players in the field, and IBM's quantum roadmap. Are you curious about how a linguist might relate to all this tech talk? Listen in as Alan, an IT professional, ties it all together with his son's choice of major. We wrap up with a hilarious segment discussing our favorite physicists and resources, where you may just find your next good read! Get ready for a deep dive into a future shaped by quantum computing!

View Details

The Audit - Episode 24

In Part 1 of the Tech Lessons Series by Bill Harris, prepare to be transported into the future of computing resources, with our fascinating guest, Bill Harris from IT Audit Labs. We're opening up the world of processor design and specialized workloads, discussing the intricacies of chip fabrication, the genius behind improving processor speeds, and the art of creating modern processors. Get ready to discover a realm of substrates, lithographies, and elements that form the backbone of future processors.

Ever wondered about the application of Moore's Law in real life, or what really behind processor clock speeds? This episode answers all that and more, bringing in exciting insights into the clever tactics used to amplify modern computation. Dive into the mechanics of how assembly is utilized to build processors and learn about the advanced technologies such as 3D NAND, chiplets, and SSL acceleration that are revolutionizing the field.

As we look forward to the future of computing and the exciting investment opportunities it presents, we delve into the potential of semiconductors, the massive CERN particle collider and the intricate challenges of breaking into the semiconductor industry. Don't miss out on our spirited conversation on the potential of DNA and crystalline molecular storage, and the role of quantum computing in enhancing processor speeds. And remember, amidst all this tech talk, the importance of security, risk and compliance controls to safeguard our clients’ data remains paramount. So, buckle up and come along on this exhilarating journey into the future of computing!

View Details

Wouldn't it be great if you could navigate the treacherous landscape of software vulnerabilities like a pro? That's exactly what we're serving up in our latest podcast episode. Together with our dedicated team, we dissect the upsurge of these vulnerabilities, the recent discovery of a toolkit targeting Apple, Mac OS, and stolen chat GPT credentials. We even do a deep dive into the complex CVE system. Our insightful discussion sheds light on how these vulnerabilities have grown over time, largely due to the evolution of software development.

Are you constantly second-guessing whether to update your software due to the fear of breaking things? You're far from alone. Hang out with us as we share our personal anecdotes dealing with software updates, security patches and the puzzling catch-22 situation that arises. In an alarming revelation, we also walk you through the recent compromise of over 101,000 OpenAI chat GPT account credentials. If you’re a user, this is an episode you can't afford to miss.

Imagine living in a world where data breaches are the new golden age. That's the reality we're grappling with, and there's no denying the risks associated with storing data on an internet-connected database. From discussing malicious targeted ad campaigns to delving into the dangers of certain browsers, this episode is a rollercoaster of cybersecurity insight. We round off by examining how data breaches have shaped cybersecurity history. Tune in and arm yourself with the knowledge to combat the rapidly evolving world of software vulnerabilities and cybersecurity.

View Details

Want to understand the dark underbelly of cyberspace? Join us as we take a deep dive into recent data breaches at T-Mobile, discussing why fewer customers were impacted this time around compared to the January API attack. Get insights on how negligence in security could lead to government oversight and understand the power consumers can wield by voting with their feet. Learn how the fines collected from such breaches could fund cybersecurity improvements in vulnerable entities such as school districts.

Curious about the consequences of data breaches? We shed light on the implications of the cover-up by Uber's former CSO, who narrowly escaped jail time, and the devastating impact of the Next Gen Healthcare breach affecting a million individuals. We also explore the rise of bug bounties as a popular tool among companies and stress the importance of credibility in the realm of ethical hacking.

Ever wondered about the value of your personal information to hackers? We break down how hackers can misuse social security numbers, addresses, and names, and discuss the increasingly specialized roles within a cyber attack. Discover the sinister world of data brokers, who split and resell your personal information, and the challenges of resetting social security numbers. We also delve into how medical records can be weaponized and highlight the need for cybersecurity audits to safeguard data.

Listen in, as we offer a compelling analysis of the attacker's viewpoint, the significance of logging activities, and why some attackers end up dwelling within systems for long periods. We also discuss the security maturity needed to protect a company from future breaches once they've been hit. If you're at all concerned about the safety of your personal data, you won't want to miss this deep dive into the murky world of data breaches and cybersecurity.

View Details

Episode 022 - The Audit

Want to understand the dark underbelly of cyberspace? Join us as we take a deep dive into recent data breaches at T-Mobile, discussing why fewer customers were impacted this time around compared to the January API attack. Get insights on how negligence in security could lead to government oversight and understand the power consumers can wield by voting with their feet. Learn how the fines collected from such breaches could fund cybersecurity improvements in vulnerable entities such as school districts.

Curious about the consequences of data breaches? We shed light on the implications of the cover-up by Uber's former CSO, who narrowly escaped jail time, and the devastating impact of the Next Gen Healthcare breach affecting a million individuals. We also explore the rise of bug bounties as a popular tool among companies and stress the importance of credibility in the realm of ethical hacking.

Ever wondered about the value of your personal information to hackers? We break down how hackers can misuse social security numbers, addresses, and names, and discuss the increasingly specialized roles within a cyber attack. Discover the sinister world of data brokers, who split and resell your personal information, and the challenges of resetting social security numbers. We also delve into how medical records can be weaponized and highlight the need for cybersecurity audits to safeguard data.

Listen in, as we offer a compelling analysis of the attacker's viewpoint, the significance of logging activities, and why some attackers end up dwelling within systems for long periods. We also discuss the security maturity needed to protect a company from future breaches once they've been hit. If you're at all concerned about the safety of your personal data, you won't want to miss this deep dive into the murky world of data breaches and cybersecurity.

News article citations:
T-Mobile Breach (https://www.cpomagazine.com/cyber-security/t-mobiles-second-data-breach-of-2023-impacts-fewer-customers-but-involves-much-more-sensitive-information/)
Published by cpomagazine.com

Former Uber CSO Avoids Jailtime in Breach Cover-Up (https://www.securityweek.com/former-uber-cso-joe-sullivan-avoids-prison-time-over-data-breach-cover-up/)
Published by securityweek.com
ByEduard Kovacs
May 4, 2023

1 Million Impacted by Data Breach at Next Gen Healthcare (https://www.securityweek.com/1-million-impacted-by-data-breach-at-nextgen-healthcare/)
Published by securityweek.com
ByIonut Arghire
May 8, 2023

databreach #cybersecurity #cybersecuritynews #news #technews #Uber #CSO #tmobile #jailtime #nextgen #healthcare #security #securitybreach #discussion

View Details

Eric Pesik, the Deputy General Counsel at Seagate Technology. In this episode, Eric, walks us through how he has been using generative AI tools, including ChatGPT, AI image generators and AI voice overs to speed up his workflow when creating presentations for his colleagues. The crew also discusses how AI will broadly impact other sectors.  

View Details

A conversation between Nick Mellem, Eric Palms, and Matt Starland about the future of passwords through the lens of IT. The team notes a general lag time behind current threats and the technology already available to upgrade security protocols and the lack of large-scale adoption and upgrades. Passwords may eventually have to be left behind for new technologies such as biometrics. It is largely agreed that there needs to be a change to a password-less approach to mitigate end-user security risks. Join us for this stimulating and timely discussion. Help us spread this important info by liking, downloading, subscribing and inviting your friends to listen to The Audit. Video version now available on our YouTube channel.

View Details

A discussion with ITAL members Eric Brown and Scott Rysdahl with Micah Kryzer. Micah is a pentester by day but also works alongside the ITAL team. In this episode the crew overviews certificates, a big topic that transcends any one vendor or environment. Certificates are like an electronic passport meant to uniquely identify a person, computer or application on a network. This specific family of vulnerabilities discussed affects the Microsoft Active Directory certificate services, which is Microsoft’s own built-in PKI or public key infrastructure included with Window’s servers and domains. Micah walks us through a pentest demo illustrating the ways this system can be exploited as well as providing tips on how to protect business networks from this attack. 

View Details

An in-depth conversation with former CISO (Chief Information Security Officer) of the Minnesota Judicial and Metropolitan Council, Gretchen White. ITAL’s own Eric Brown and Gretchen discuss topics including the day-to-day grind of advocating for funding and implementing security protocols, how to prioritize security needs and access risk on a budget, reporting structure, and how to effectively impact change within an organization. Chalk full of tips, Gretchen, has expertise in communicating organizational needs to decision makers and has some priceless nuggets to share with up-and-coming CISO’s and those who work under their guidance.  

cybersecurity #CISO #chiefinformationsecurityofficer #careeradvice #organizational #leadership #communication #security #influence #metropolitancouncil #minnesotajudicial #pointofrisk

View Details

This week, we are speaking with Dennis Pelton about his expertise in hardware. He makes badges for all the major security conferences and loves to share his knowledge in this space. #security #hacking #wifi #rubberducky #hardware #defcon #schmoo #defcon #bsides

View Details

Continue the conversation with guest, Matt Starland, as we dive further into security in the news. How do these breaches happen and how can they be prevented? Find out today on The Audit. 

Breaches #ThreatActors #CyberSecurity #TheAudit

View Details

Traveling for Spring Break, vacation, or work? Join The Audit and guest ethical hacker, Matthew Wold, to hear best practices for keeping your journey cyber-secure. 

View Details

In this episode, The Audit discusses day-to-day operations in the industry with cybersecurity expert, Nate Ristine. From creating and hunting down phishing emails, to the emotional aspect of social engineering, find out what tools Nate uses to make it all happen. 

View Details

We have all heard about it, but do you really understand what the Dark Web is? 

On this episode of The Audit, Bill Harris presents on all things Dark Web, including the content available, the intension of the dark net, and a brief tour of what the dark web looks like. 

View Details

In this week's episode of The Audit, we will be talking about up-to-date security in the news stories, with cyber security expert and guest, Matt Starland. Tune in to hear about security breaches, hacking tactics, and all things cybersecurity. 

cybersecurity #theaudit #itauditlabs

View Details

Join the IT Audit Labs crew to talk about Pwnagotchi’s! We will review how a pwnagotchi collects keys/wpa/wpa2 information from 4-way wifi handshakes, and how to crack those keys/how the key exchange functions. It’s a pwnagotchi party!  

View Details

Did you know that your Wi-fi is even vulnerable to attacks? Tune in to hear our guest, Dennis, talk about kill chain, DOS attacks, Wi-Fi reconnaissance, and more. For more information about relevant attacks and ways to protect your network, listen to The Audit today! #wifi #cybersecurity #itauditlabs #theaudit 

Follow our guest Dennis Pelton on Twitter @c0ldbru  

View Details

Breaches, phishing, attacker programming, and more, in this week of The Audit. Tales from the Trenches will talk about several scenarios our hosts have experienced with fraudulent situations, as well as ways these hackers implement their tactics. Tune in to The Audit today to hear more! #cybersecurity #protection #itauditlabs #theaudit 

View Details

Vishing is happening constantly. Understanding what vishing is and being able to spot these tactics will help protect your information. The Audit presents three guests that won the DEFCON30 Vishing black badge. These guests are here to discuss their experience at DEFCON, as well as their knowledge on vishing. Join us to learn more. #itauditlabs #vishing #scam #security 

Special Thank you to the DC30 Vishing Competition Black Badge Winners 

Team Spilt Beans @_jacoff, @bngrsec, @_seahop 

Shout outs to the entire Defcon community with special mentions 

@SEC_Defcon@twitter, @JC_SoCal, @_snoww, @_corge 

View Details

In this podcast, there are several common tactics hackers use in order to gain your personal information. These hackers will phish and smish through different texts, emails, or even items you are buying on eBay. Knowing how to spot these hacking tactics will prevent you from clicking on the links or putting your personal information on the line.

View Details

In this episode of The Audit, we discuss a common Windows vulnerability; an unquoted service path, which could lead to privileged escalation or service redirection. Joining us is a friend of IT Audit Labs, Matthew Wold, Security Engineer who discovered one such vulnerability in a common endpoint protection software.  

View Details

Should you put your phone number on your dog’s tag? Is your social security number safe? Keeping your identity safe is vital to your credit score. Identify theft is happening constantly. The Audit presents many ways to keep your credit safe including a free annual credit report through which you can track previous and current spending, freezing of your assets, and more.  

View Details

Part III of the Personal Information Security Protection in a Modern Era series by IT Audit Labs.

View Details

Episode 3 features the second in the Personal Information Security in a Modern Era series by IT Audit Labs.

View Details

Episode 2 

View Details

Welcome to The Audit. In this episode, meet the IT Audit Labs crew and the mission for future cyber security podcasts.