Welcome to Vulnerable U, a podcast where we explore the intersection of vulnerability and cyber security. Each episode, we explore how vulnerability can drive growth and foster community resilience within our industry. Get ready for thought-provoking conversations, real-life stories, and curated news that inspire you to embrace discomfort on the road to a more vulnerable you.
…
continue reading
Matt Johansen Podcasts
Join HOU.SEC.CON Cofounders Michael and Sam each week as they chat with conference speakers about the latest topics and trends in the cybersecurity space.
…
continue reading
The editors of Decipher talk with a rotating cast of security practitioners, researchers, and executives about a variety of topics in the security and privacy fields.
…
continue reading

1
Get in Loser, We’re Going to ShmooCon with Matt Johansen
36:50
36:50
Play later
Play later
Lists
Like
Liked
36:50In this episode, Michael and Sam are joined by Matt Johansen, founder of Vulnerable U, to discuss his journey in cybersecurity, the importance of networking, and the evolution of technical content creation in the industry. Things Mentioned: · Vulnerable U - https://www.vulnu.com/ · Spain under fire for contracting Huawei to store judicial wiretaps …
…
continue reading

1
It’s not magic – it’s just AI with Daniel Miessler
38:00
38:00
Play later
Play later
Lists
Like
Liked
38:00In this episode, Michael and Sam sit down with Daniel Miessler, founder of Unsupervised Learning, for a thought-provoking conversation that spans the future of cybersecurity and Daniel’s unique personal journey. They dive into the escalating arms race between attackers and defenders, explore how Daniel’s path shifted from pre-med to cybersecurity t…
…
continue reading
We are so back! After a bit of a hiatus, we're very excited to be back with new Decipher content for you in all of the old familiar places. And also some new ones. Join Decipher editors Dennis Fisher and Lindsey O'Donnell-Welch as we start our new, independent phase, talk about what we've been up to, and discuss our plans for what fun stuff we have…
…
continue reading

1
Watching Each Other’s Backs with Sean Jones & Kaloyan Ivanov
37:55
37:55
Play later
Play later
Lists
Like
Liked
37:55Michael and Sam chat with HOU.SEC.CON 2025 speakers Sean Jones and Kaloyan Ivanov! In this episode, they explore how pathways into the cybersecurity industry have evolved across generations, what it takes to go undercover in cybercriminal communities, and why accountability is crucial when engaging in such high-risk work. Things Mentioned: DarkForu…
…
continue reading

1
Preserving Hacker History with Emily Crose
33:33
33:33
Play later
Play later
Lists
Like
Liked
33:33In this episode Michael and Sam sit down with Emily Crose - cybersecurity professional, speaker, and author of “Hack to the Future”. Emily shares her journey into the field, the project that sparked the idea for her debut novel, and her candid thoughts on hacker culture. Emily will be a featured speaker and author at HOU.SEC.CON. 2025, so be sure t…
…
continue reading
We’re chatting with another fantastic HOU.SEC.CON. author and speaker, Doug Landoll! In this episode Michael and Sam talk to Doug about his book “Security Risk Assessment Handbook”, how he transitioned from traditional IT to cybersecurity, and why others should consider a similar path before moving into a GRC role. Things Mentioned: · HSC User Grou…
…
continue reading
We’re back with another keynote speaker, Robert “RSnake” Hansen! He chats with Michael and Sam about his new book, AI’s Best Friend (and how to get a free copy!), how he started hacking, and his upcoming HOU.SEC.CON. presentation around his research on the CVSS framework. Things Mentioned: · HSC User Group on June 26, 2025 – https://www.hscusergrou…
…
continue reading

1
The Never-Ending Cat and Mouse Game with Dmitri Alperovitch
36:12
36:12
Play later
Play later
Lists
Like
Liked
36:12Michael and Sam are back with another HOU.SEC.CON. keynote speaker – Dmitri Alperovitch! In this episode they talk about his new book, what he’s been up to since CrowdStrike, and what will be covered in his opening keynote. Things Mentioned: HSC User Group on June 26, 2025 – https://www.hscusergroup.com TAB Cyber Foundation Scholarship Closing July…
…
continue reading

1
Forcing Innovation with Jeremiah Grossman
43:19
43:19
Play later
Play later
Lists
Like
Liked
43:19HOU.SEC.CON.'s first keynote speaker is returning for our 15-year anniversary! This week Michael and Sam are talking to cybersecurity legend Jeremiah Grossman about his start in cyber at just 19 years old, what we can learn from cybersecurity insurance companies, and what to expect at HOU.SEC.CON. 2025! Things Mentioned: · What Works in Cybersecuri…
…
continue reading

1
OT Security with Watch Mr. Wizard Star Sean Curry
32:13
32:13
Play later
Play later
Lists
Like
Liked
32:13Michael and Sam are catching up with Principal Consultant and Co-Founder at Cavalry Solutions, Sean Curry! Sean talks about his transition from the military to the private sector, the importance of standards like IEC 62443 for OT security, and the best way to align IT and OT teams. Things Mentioned: · New study reveals 92% of industrial sites at ri…
…
continue reading

1
Predicting the Future of Malware with Dr. Marcus Botacin
35:21
35:21
Play later
Play later
Lists
Like
Liked
35:21In this episode Michael and Sam are talking to malware researcher Dr. Marcus Botacin. Dr. Botacin discusses his journey from early work in sandboxing to advanced malware detection through machine learning, his recent efforts combining LLMs with GANs to create an iterative malware generation system that enhances evasion capabilities, and the importa…
…
continue reading
Today’s episode looks a little different as Michael and Sam are talking to the entire YOUTH.SEC.CON. team! Arthi Vasudevan, Reynaldo Gonzalez, and Mary DiFiore-Smith joined the podcast to discuss all aspects of our first event focused on 9th – 12th grade students. Listen now to learn about the talks and activities, eligibility, registration, safety…
…
continue reading

1
Definitions of Pen Testing with Darin Fredde
35:33
35:33
Play later
Play later
Lists
Like
Liked
35:33Sam and Michael are joined by Offensive Security Advisor, Darin Fredde! They discuss the need to move beyond compliance checkboxes, the importance of continuous pen testing, and the disconnect between marketing claims and real-world security implementations. Things Mentioned: Having trouble with your OT.SEC.CON. or EXEC.SEC.CON. ticket? Reach out t…
…
continue reading

1
AppSec Fish in a Barrel with Steven Schmidt
36:28
36:28
Play later
Play later
Lists
Like
Liked
36:28Michael and Sam are joined by Field CTO, Steven Schmidt! They discuss the early days of application security, the evolution of AppSec tools and processes, and challenges in balancing developer speed with security requirements. Thank you to Snyk for sponsoring this episode! Learn more about building secure applications at https://snyk.io and chat wi…
…
continue reading

1
Network Monitoring in OT/ICS Environments with Stuart Bailey
31:05
31:05
Play later
Play later
Lists
Like
Liked
31:05In today’s episode Michael and Sam are catching up with Security Consulting Manager, ICS/OT at Accenture, Stuart Bailey! Stuart shares his journey from a career in social work to cybersecurity, the challenges of working on OT environments, and the importance of network monitoring for critical infrastructure. Things Mentioned: · Romanian energy supp…
…
continue reading
This week Michael and Sam are catching up with Bugcrowd CISO, Trey Ford. They chat about his evolution from consulting to the C-Suite, how to know if the CISO role is right for you, and what alignment between security leadership and the board should look like. Things Mentioned: · Key strategies to Enhance Cyber Resilience - https://www.csoonline.co…
…
continue reading

1
Special, Special, Special Guest – Marco Ayala
31:01
31:01
Play later
Play later
Lists
Like
Liked
31:01Michael and Sam are gearing up for OT.SEC.CON. with keynote speaker, Marco Ayala! Marco is an ISA Fellow, and President of InfraGard Houston with over 30 years of experience in industrial automation controls and OT/IT security. They chat about some exciting OT Cybersecurity initiatives in Texas, the incident that led him to cybersecurity, and what …
…
continue reading

1
HIPAA with Two A’s with Stephen Alexander
34:32
34:32
Play later
Play later
Lists
Like
Liked
34:32Hosts Michael and Sam are covering another HOU.SEC.CON. 2024 presentation, this time with Security Architect Stephen Alexander! They discuss how audits, while annoying, can provide significant value by offering insights for organizational improvement, help ensure compliance, and educate companies on how to strengthen their security operations. Thin…
…
continue reading
We’re kicking off season 3 with our good friend Len Noe! Len wears many hats, including whitehat hacker, technical evangelist, international speaker, podcast host, and most recently, author. In this episode, Michael and Sam chat with him about his new book, transhumanism, and his upcoming projects. Things Mentioned: · Google's AI-Powered OSS-Fuzz T…
…
continue reading
Michael and Sam are on their own for our last episode of the year. They chat about all of the growth HOU.SEC.CON. saw over 2024, highlight the countless sponsors, volunteers, and speakers that make all of our initiatives happen, and discuss what to expect in 2025! Things Mentioned: · Submit an abstract for our monthly user group: https://www.hscuse…
…
continue reading
On our latest episode Michael and Sam are talking to the Security Fairy Godmother herself, Dawn Cappelli! They discuss her transition from programming to security, her passion helping SMB’s, and how that passion pulled her out of retirement to create free resources for the OT community. Things Mentioned: · OT Cert Link - https://www.dragos.com/comm…
…
continue reading
In this episode, Jason Haddix, CEO & Hacker & Trainer at Arcanum Information Security, joins the podcast to discuss his HOU.SEC.CON. 2024 talk, “Tales from the Breach.” In his conversation with Michael and Sam, Jason shares his unconventional introduction to hacking, his journey from CISO to Founder, and how companies can apply what he learned from…
…
continue reading

1
Sprinting Ahead of Quantum Computing with Marian Zaki
34:47
34:47
Play later
Play later
Lists
Like
Liked
34:47Dr. Marian Zaki, Assistant Professor of Computer Science and Cybersecurity at Houston Christian University, joined Michael and Sam on this week’s episode of HOU.SEC.CAST! They discuss how Marian’s career pivoted from working for the Egyptian Armed Forces to education, the growing threat of quantum computing, and the cybersecurity programs she’s dev…
…
continue reading
Hosts Michal and Sam catch up with EXEC.SEC.CON./HOU.SEC.CON. speaker and Cyber Point Advisory Founder Dd Budiharto! They talk about how she (accidentally!) ended up in her first cybersecurity role, her personal experience as a whistleblower, and the need for integrity in the industry, particularly as organizations grapple with ethical dilemmas in …
…
continue reading

1
Releasing Angry Pixies with Dennis Maldonado
43:22
43:22
Play later
Play later
Lists
Like
Liked
43:22In this episode, hosts Sam and Michael are chatting with Harris Fort-Bend County ESD #100 Director of Technology, and HOU.SEC.CON. Speaker, Dennis Maldonado! They discuss their first meeting at HOU.SEC.CON. 2012, how Dennis found himself working in cybersecurity while still in school, how he built WestCom, and his 2024 talk. Things Mentioned: AT&T,…
…
continue reading

1
101 Definitions of Cybersecurity with Gene Spafford
33:26
33:26
Play later
Play later
Lists
Like
Liked
33:26We have a very special guest on this week’s show, opening keynote speaker Gene Spafford! Hosts Michael and Sam chat with him about his start in cybersecurity and academia, his new book, and what to expect during his talk. Things Mentioned: · CTF Link (Opens September 14, 2024) - https://www.cisa.gov · Cybersecurity Myths and Misconceptions: Avoidin…
…
continue reading

1
The Sony Hack Ten Years Later With Brian Raftery
45:17
45:17
Play later
Play later
Lists
Like
Liked
45:17The Sony Pictures hack in 2014 by the North Korean Lazarus Group was a seminal event both in Hollywood and in the security community, bringing to light the capabilities and ambitions of North Korean attackers and showing the damage a leak of sensitive data can be. Brian Raftery joins Dennis Fisher to discuss his new Ringer podcast, The Hollywood Ha…
…
continue reading

1
Zero Day Reuse and A Busy Week for Iranian APTs
18:32
18:32
Play later
Play later
Lists
Like
Liked
18:32The focus was on Iranian APTs this week, both from private threat intelligence teams and CISA, exposing new operations from UNC757 and other groups targeting government, higher education, and private industry. We also check in on a new report from Google's Threat Analysis Group on APTs using the same exploits for zero days that were developed by pr…
…
continue reading

1
Learn Something New Today with Andy Ellis
34:26
34:26
Play later
Play later
Lists
Like
Liked
34:26This week hosts Michael and Sam are joined by our day one closing keynote speaker, Andy Ellis! In this episode they discuss an article authored by Andy that covers the growing issue of admin access and its role in cybersecurity vulnerabilities. They also get into Andy’s transition from the Air Force to 21+ years at Akamai, his book, 1% leadership, …
…
continue reading

1
Reddit's Matt Johansen on Identity Attacks, Enterprise Security, and Burnout
31:42
31:42
Play later
Play later
Lists
Like
Liked
31:42Reddit's head of software security Matt Johansen joins Dennis Fisher to talk about the highlights of Black Hat USA, the challenges of sorting security priorities in a large enterprise, and how he's learned to take care of his mental health after many years in the security industry.By Decipher
…
continue reading

1
Rebekah Brown and John Scott-Railton on COLDRIVER and Russian Cyberespionage
23:12
23:12
Play later
Play later
Lists
Like
Liked
23:12Rebekah Brown and John Scott-Railton of the Citizen Lab join Dennis Fisher to dive into their group's new report on highly targeted spear phishing campaigns by the Russian threat actor COLDRIVER and then discuss the emergence of a new, possibly related group called COLDWASTREL.By Decipher
…
continue reading

1
Protecting the Cheese and Chocolate with John Kindervag
39:51
39:51
Play later
Play later
Lists
Like
Liked
39:51About this episode: HOU.SEC.CAST. Is back after a short summer break and we’re kicking things off with the one and only John Kindervag! In this episode the guys discuss the importance of securing ALL technology, John’s journey into cybersecurity, and his top secret HOU.SEC.CON. keynote presentation. Things Mentioned: · Swiss cow and calf dead after…
…
continue reading
Dennis Fisher and Lindsey O'Donnell-Welch reflect on their week in Las Vegas at Black Hat and discuss the talks they liked, including Moxie Marlinspike's keynote and the Google Project Zero retrospective, and the other topics they found interesting, including vulnerability exploitation versus social engineering and the AI ecosystem.…
…
continue reading

1
Black Hat Podcast: Josh Harguess and Chris Ward
26:52
26:52
Play later
Play later
Lists
Like
Liked
26:52At Black Hat USA this year, Josh Harguess and Chris Ward, with Cranium AI, talk about the security challenges that organizations are experiencing while implementing AI in their environments, what AI red teaming consists of and the backstory of how MITRE Labs’ AI Red Team came to be.By Decipher
…
continue reading
AI and machine learning security expert Gary McGraw joins Dennis Fisher to discuss the concept of data feudalism in LLM foundation models, what the security implications of it are, and whether narrowly focused models may help address these issues.By Decipher
…
continue reading

1
Black Hat USA 2024 Preview: AI, AI, and More AI
46:46
46:46
Play later
Play later
Lists
Like
Liked
46:46Decipher editors Dennis Fisher and Lindsey O"Donnell-Welch are joined by Brian Donohue to dissect the Black Hat talks they're looking forward to, including sessions with H D Moore, Sherrod DeGrippo, and Moxie Marlinspike, and some talks they can't quite figure out from the titles.By Decipher
…
continue reading
The fallout from the CrowdStrike outage continues more than a week after the faulty update, so Huntress security researcher John Hammond joins Dennis Fisher to talk about the lessons learned from the incident, our fragile software ecosystem, and what cybersecurity practitioners can do differently next time.…
…
continue reading
Tyler Healy, CISO of Digital Ocean, joins Dennis Fisher to discuss the unique challenges of defending a huge platform, how AI is changing things for defenders, and what new challenges AI might bring in the near future.By Decipher
…
continue reading

1
What Happened With the CrowdStrike Update and Azure Outage
11:47
11:47
Play later
Play later
Lists
Like
Liked
11:47CrowdStrike said a problem with an update the company pushed to Falcon sensors on Windows hosts on July 18 caused a blue screen of death, an issue that coincided with a Microsoft Azure outage and widespread outages across airlines, banks, hospitals, and other services. Our story on this incident: https://duo.com/decipher/crowdstrike-windows-update-…
…
continue reading
FIN7 is a highly active and capable cybercrime group also known as Carbanak that has been evolving and using its own tools such as AVNeutralizer for many years. SentinelOne researchers Antonio Cocomazzi helps us dig into the group's tactics and tools. Read Antonio's new research here: https://www.sentinelone.com/labs/fin7-reboot-cybercrime-gang-enh…
…
continue reading
Former NSA Deputy Director George Barnes joins Dennis Fisher to talk about his 35-year career at the agency, how he came to be intrigued by the cybersecurity world, the emergence of Cyber Command as a force inside the government, and what he sees as the priorities for defenders now.By Decipher
…
continue reading
Chris Hughes, co-founder of Aquia and a Cyber Innovation Fellow at the Cybersecurity and Infrastructure Security Agency, joins Dennis Fisher to talk about the challenges of supply chain security, working with the government to address systemic issues, and the importance of collaboration.By Decipher
…
continue reading
Today Michael and Sam are catching up with DevSecOps manager and 2023 HOU.SEC.CON. speaker, Christopher Pope. They discuss the importance of integrating security from the beginning of the development process, the need for building relationships and understanding between developers and security professionals to create secure applications, and the si…
…
continue reading

1
The TeamViewer Breach and a Busy Week for APT29
10:07
10:07
Play later
Play later
Lists
Like
Liked
10:07Dennis Fisher and Lindsey O'Donnell-Welch dig into the news of the TeamViewer corporate breach, attributed to APT29/Midnight Blizzard, and news of more victims from the Microsoft intrusion by the same group earlier this year.By Decipher
…
continue reading

1
Cisco Talos: How Threat Actors Target MFA
15:42
15:42
Play later
Play later
Lists
Like
Liked
15:42Multi-factor authentication (MFA) is a critical form of defense for organizations, and threat actors are recognizing that: According to the latest Cisco Talos Incident Response Quarterly Trends report, instances related to MFA were involved in some capacity in half of all security incidents that the Talos team responded to in the first quarter of 2…
…
continue reading
Metin Kortak, CISO with Rhymetec, talks about how organizations are approaching data privacy and security compliance, and thinking about risk management policies, when it comes to generative AI in the workplace.By Decipher
…
continue reading
Every year HOU.SEC.CON. partners with local universities to involve cybersecurity students at the conference. Today Michael and Sam are sitting down with Samir Saber, Dean of Digital & Information Technology at Houston Community College and long-time champion of HOU.SEC.CON. They discuss Samir's journey in cybersecurity education, the importance of…
…
continue reading
Michael Mann's 1995 thriller Heat is considered by many people to be the best crime movie ever made. And hidden inside the intricate plot is a story of a lone hacker with a background at DARPA who uses his skills to set up scores for the crews in LA's underworld. Meg Gardiner, the co-author of Heat 2, and Casey Ellis, cofounder of Bugcrowd, join De…
…
continue reading
Amy Bogac, a longtime security executive with a deep background in systems administration and networking, joins Dennis Fisher to talk about how she came to security, how her background in communications informed her career choices, and the difficult conversations that need to occur before someone has to push the button during an incident.…
…
continue reading
A few days after Microsoft announced the new AI-enabled Recall feature--generating tremendous concerns and pushback from the security and privacy communities--the company had decided to disable it by default, but many concerns still remain. A month after the company's CEO proclaimed that it would be "prioritizing security above all else", how did t…
…
continue reading