#cybersecurity
65 episodes
#5463: What Happens When You Click "Connect" on an AI Plugin
You click accept, the tool runs, and a credential you never saw is doing the work. Here's who actually owns it.
#5450: Heat, Fans, and the Limits of Air-Gapped Security
Dozens of ways to leak data from air-gapped machines exist — but every real breach still used a USB stick.
#5404: Gemini Broke Out of Its Sandbox. Sort Of.
A Gemini agent reached three real companies during a capture-the-flag test. The containment failure, the seven-week silence, and what "broke out" a...
#5380: Zero-Click: When Your OS Opens Files For You
Your file manager parses downloads before you touch them. Here's what that means for your security — and what you can actually do about it.
#5379: Hashing, Sandboxes, and YARA: The Free Forensics Nobody Uses
VirusTotal, MalwareBazaar, and YARA do far more than most people realize — and they're free. Here's how to actually use them.
#5314: Private Cyber Skills vs. Government Ops
What actually changes when a cybersecurity operator crosses from protecting a company to protecting a state?
#5220: Malware vs. Virus: What's Actually Attacking Your Machine
Every virus is malware, but not every malware is a virus — and that distinction explains why your antivirus keeps missing things.
#5202: What Happens to Breached Data After the Breach
Once a dataset leaks, it never stops moving. A look at the bots, combolists, and USB drives that make breached data impossible to recall.
#4776: Wi-Fi Monitor Mode Hardware Guide
From $40 Alfa adapters to $3,000 spectrum analyzers — the hardware that listens to your network.
#4751: AI Agents vs Anti-Bot Systems
Why AI agents get blocked by anti-bot systems and what actually works to get through.
#4375: How to Audit 47 Stale Sessions Without Breaking Everything
A systematic method for identifying and cleaning up forgotten sessions without locking yourself out of critical services.
#4321: Reverse Engineering Android APKs in 2026
From Ghidra to Frida: the modern toolkit for analyzing bundled Android apps.
#4153: The Corporate Org Chart of Cybercrime
Stop picturing a lone hacker. Today's cybercrime looks like a consulting firm with a really unethical business plan.
#4152: How Your SSN Became the Master Key to Everything
When a data breach and a mail scam combine to hijack your Social Security benefits — and what to do about it.
#3804: Stateful Firewalls vs. Modern Threats
Is a basic firewall still enough in 2026? We break down what each security layer actually catches—and misses.
#3644: What Criminologists Actually Do (It's Not CSI)
Criminology isn't detective training. It's a social science that studies why crime happens—and whether the system works.
#3216: EFF's 36-Year Fight for Digital Rights
How the Electronic Frontier Foundation has fought for internet freedom since 1990 — from the Crypto Wars to border phone searches.
#2834: The Deep Ocean Trench of Authentication
PIN + smart card + biometric + behavioral checks. The real security stack behind federal authentication.
#2827: Why People Still Pay for SSL Certificates
Free DV certificates are everywhere, yet paid SSL still thrives. Here’s what commercial CAs actually provide that free ones don’t.
#2698: How Hackers Hide C2 Servers in Plain Sight
Bulletproof hosts, hijacked routers, and Discord channels — how command and control infrastructure stays up despite takedown attempts.
#2696: How Pegasus Silently Hijacks Your Phone's Microphone
How NSO's Pegasus achieves silent mic access on Android through zero-click exploits, kernel privilege escalation, and DMA buffer reading.
#2508: Why CORS Doesn't Protect Your Server
Why browsers block cross-origin requests, how CORS actually works, and the common pitfalls that trip up developers.
#2500: What Actually Counts as Hacking?
The CFAA, web scraping, and the messy line between curious URL-poking and federal crime.
#2481: How to Ask Cloud Vendors About Security (Without Sounding Clueless)
What to ask cloud vendors about security practices — and the technical red flags that actually matter.