Home Podcasts The Cyber Threat Perspective
The Cyber Threat Perspective

The Cyber Threat Perspective

SecurIT360 220 episodes Latest Jun 5, 2026

Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. The podcast brings fresh content from their journeys into penetration testing, threat research, and various other interesting topics. It is hosted by Brad, who can be reached at brad@securit360.com.

Episodes

Episode 184 | Active Directory Isn't Dead. It's Just Undefended. Jun 11, 2026 1732 Think Active Directory is dead? Think again. According to Microsoft data, 86% of organizational workloads still touch Active Directory, and nearly 20% of organizations don't expect to reach a hybrid state for 10-20+ years. In this episode, Brad and Spencer break down why AD attack paths remain one of the most critical threats in enterprise environments and what defenders can do about it right
Episode 183 | OWASP Top 10 Part 2: Security Misconfigurations That Get You Hacked Jun 5, 2026 1728 Security misconfiguration is one of the most frequently found vulnerabilities in web application pen testing — and most of the fixes are just a checkbox. In Part 2 of their OWASP Top 10 series, Brad Causey and Jordan Natter cover OWASP A05: Security Misconfiguration with real stories from recent engagements and practical takeaways for developers, security teams, and organizations of all sizes.In t
Episode 182: Patching Crisis — Vulns Now #1 Attack Vector (2026 Verizon DBIR) May 27, 2026 1854 Hosts Brad Causey and Spencer Alessi break down the 2026 Verizon Data Breach Investigations Report, focusing on the findings that actually matter for IT and security teams.The biggest surprise: vulnerability exploitation has overtaken stolen credentials as the top initial access vector, accounting for 31% of attacks, while credential abuse dropped to just 13%. This completely flips the script on y
[Replay] Episode 159: How to Break Into Cybersecurity — What Actually Works May 20, 2026 2696 We're re-releasing one of our most practical episodes this week — originally published November 2025, and still one of the best roadmap conversations we've had on the show.Brad and Spencer share no-fluff advice for breaking into cybersecurity, whether you're switching careers, starting from scratch, or leveling up from a general IT role. They cover what employers actually look for,
Episode 181: AI Zero Days (Google Threat Intelligence Report) May 12, 2026 2469 Brad and Spencer break down Google Threat Intelligence Group's latest report on how adversaries are weaponizing AI across the entire attack lifecycle.The big takeaway isn't that AI has magically replaced attackers, but that it's making certain workflows faster, more scalable, and more repeatable. More importantly, AI platforms, agent skills, integrations, and dependencies are now be
Episode 180: Cybersecurity Echo Chambers — How to Think Critically in a Hype-Driven Industry May 7, 2026 1753 In Episode 180, hosts Brad Causey and Spencer Alessi tackle a critical but often overlooked issue in cybersecurity: the echo chambers that can undermine critical thinking and effective security programs.Inspired by recent experiences at the ILTA Evolve conference, Spencer and Brad explore how cybersecurity professionals, from practitioners to executives, can fall into bubbles where everyone reinfo
Episode 179: OWASP Top 10 Part 1 - Broken Access Control, IDOR, and CORS Explained Apr 30, 2026 1728 In Episode 179 of the Cyber Threat Perspective podcast, host Brad Causey and web app pen tester Jordan Natter kick off a multi-part series on the OWASP Top 10, the newly updated list of the most common and critical web application security risks, with a fresh version released in 2025.Before diving in, Brad sets the record straight on something that's been bugging him for 20 years: the OWASP T
Episode 178: Internal Security Controls That Actually Frustrate Attackers Apr 22, 2026 1862 In Episode 178 of the Cyber Threat Perspective podcast, hosts Spencer and Tyler take a practitioner-first look at the internal security controls that genuinely make attackers' lives difficult, drawing directly from their experience conducting hundreds of internal penetration tests every year.This isn't a vendor comparison or a theoretical framework. It's an honest account of what wo
Episode 177: Claude Mythos — What It Actually Does, What It Doesn't, and What Your Organization Should Do Now Apr 14, 2026 2493 In Episode 177 of the Cyber Threat Perspective podcast, host Brad Causey and virtual CISO Daniel Perkins take a clear-eyed look at Claude Mythos — Anthropic's AI model that's generating serious buzz in the cybersecurity world for its ability to analyze source code, identify vulnerabilities at scale, build working exploits, and surface flaws that have sat undetected for decades.The cybers
Episode 176: Cybersecurity Advice That Sounds Smart But Fails in Practice Apr 9, 2026 2303 In Episode 176 of the Cyber Threat Perspective podcast, Brad and Spencer break down some of the most repeated cybersecurity best practices in the industry and explain why, despite sounding solid on paper, they consistently fall short in real IT environments.This isn't about dismissing good security principles. It's about closing the gap between advice that looks great in a framework and
Episode 175: NetTools - The Free Active Directory Swiss Army Knife for IT Admins & Pen Testers Apr 2, 2026 1465 In Episode 175, Spencer and Tyler break down NetTools — a free, self-contained Active Directory management and troubleshooting tool that’s become a go-to for their internal penetration testing engagements.They start with the backstory: years of relying on AD Explorer from Microsoft Sysinternals, and the growing need to evade EDR detections. At one point, that meant manually obfuscating binaries wi
Episode 174: Web Application Penetration Testing Tools & Techniques with Jordan Mar 26, 2026 1726 In Episode 174, host Brad Causey is joined by guest Jordan Natter for a practical, tool-focused conversation on web application penetration testing. Together they break down the essential tools and Burp Suite Pro extensions that make up a modern web app pen testing toolkit.Topics covered include:Burp Suite Pro vs. OWASP ZAP — comparing capabilities, extensions, and use casesCSP Auditor — identifyi

Recommended

Playing