
Secure AF - A Cybersecurity Podcast
Secure AF is a cybersecurity podcast hosted by industry veterans Donovan Farrow and Jonathan Kimmitt. It covers real-world infosec challenges, red team tactics, blue team strategies, and the latest tools in cybersecurity. The show features expert interviews and unfiltered discussions with Alias team members and guests. It aims to provide actionable insights for pentesters, SOC analysts, and newcomers to the field.
Episodes

Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders
Got a question or comment? Message us here!Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes.Support

Windows BlueHammer Flaw Now Actively Exploited by Ransomware Gangs
Got a question or comment? Message us here!Ransomware operators are leveraging the BlueHammer privilege escalation flaw to gain SYSTEM-level access and disable security controls. Get the latest insights and response recommendations. Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

FortiBleed Attacks: Turning Fortinet Firewalls into Credential Stealers
Got a question or comment? Message us here!FortiBleed is turning perimeter defenses into attack infrastructure. In this episode, we unpack how adversaries exploit FortiOS vulnerabilities, harvest credentials directly from firewalls, and pivot deeper into networks, plus detection strategies, threat hunting tips, and mitigation guidance for SOC teams.Support the showWatch full episodes at youtube.co

Arch Linux AUR Compromise – Supply Chain Risks in the Open Source World
Got a question or comment? Message us here!This #SOCBrief episode explores a recent Arch Linux AUR supply chain compromise, where malicious community packages were used to steal credentials and gain persistence. It highlights the risks of third-party repositories and offers key detection and mitigation strategies for security teams to better protect against similar attacks. Support the showWatch f

Qilin Ransomware Exploiting VPN Zero-Days: What SOCs Need to Do Now
Got a question or comment? Message us here!A single unpatched VPN could be all it takes. Qilin ransomware is actively exploiting VPN zero-days to breach networks and accelerate ransomware deployment. We walk through the tactics, the real risk to your organization, and actionable SOC strategies to stay ahead.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podc

You're Probably Not Hacked, You're Being Tracked
Got a question or comment? Message us here!You probably haven’t been hacked, you’ve been tracked. This episode breaks down how ad tech, mobile apps, and data brokers create massive behavioral profiles without ever touching your phone’s security. Learn how tracking really works, why it matters, and what you can actually do about it. 📱👁️📡Support the showWatch full episodes at youtube.com/@aliascyber

The SOC Brief Turns One 🎂 Insights, Stories & Lessons Learned
Got a question or comment? Message us here!It’s our 1-year anniversary! 🎂 From bite-sized cyber insights to growing a passionate listener base, this episode reflects on the journey, the challenges, and the wins along the way. Expect laughs, lessons, and behind-the-scenes stories you won’t want to miss. 🚀Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts

Kali365 Phishing-as-a-Service: FBI Warns of New M365 Credential Theft Tool
Got a question or comment? Message us here!The FBI is warning about Kali365, a new phishing‑as‑a‑service tool designed to steal Microsoft 365 credentials and enable account takeovers at scale. In this episode, we break down how it works, why it’s so effective, and what your SOC can do right now to detect and defend against it. 🎧 Tune in now at secureafpodcast.comSupport the showWatch full episodes

Incident Response 101: What to Do When You’re Under Attack
Got a question or comment? Message us here!What actually happens when a company gets hacked?In this episode, we break down real-world incident response, from initial access and ransomware tactics to forensic investigation and common mistakes that make things worse. If your organization had an incident tomorrow, would you know what to do?Support the showWatch full episodes at youtube.com/@aliascybe

First Known AI-Powered Zero-Day Exploit: What SOCs Need to Know 🤖
Got a question or comment? Message us here!In this episode of the #SOCBrief, we dive into the first confirmed case of an AI-powered zero-day exploit. With attackers leveraging AI to discover vulnerabilities, generate exploit code, and bypass defenses faster than ever, this marks a major shift in how threats are developed and deployed. We break down how the attack worked, what made the exploit uniq

ShinyHunters Breach of Instructure Canvas LMS 📚✏️: Lessons for SOCs on Third-Party Vendor Risks
Got a question or comment? Message us here!In this episode of the #SOCBrief, we break down the ShinyHunters breach of Instructure’s Canvas LMS and what it means for security teams everywhere. From exploiting a lesser-monitored service to exfiltrating millions of records, this attack highlights the growing risk of third-party vendors and supply chain exposure. We walk through how the breach unfolde

Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS Risk
Got a question or comment? Message us here!When the Canvas LMS went down, thousands of institutions came to a halt, right in the middle of finals. In this episode, we break down what really happened, what data may have been exposed, and why this incident is a wake-up call for every organization relying on SaaS platforms.From vendor risk and contract blind spots to business continuity failures, we

MuddyWater’s Ransomware Decoy: Iranian APTs Hiding Espionage in Plain Sight
Got a question or comment? Message us here!MuddyWater is blurring the line between ransomware and espionage... using Chaos ransomware as a decoy to distract defenders while quietly stealing data and maintaining persistence. In this episode, we break down how this tactic works, what SOC teams should watch for, and how to detect the hidden activity beneath the noise.Support the showWatch full episod

Qilin Ransomware’s EDR Killer DLL – How Attackers Are Subverting Defenses
Got a question or comment? Message us here!Qilin ransomware is deploying a malicious DLL to disable EDR tools before encryption begins. In this #SOCBrief, we break down how the attack works, what to look for, and how defenders can respond. Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

AI’s Inflection Point: From Productivity Tool to Existential Risk
Got a question or comment? Message us here!Artificial intelligence is evolving faster than most organizations, and regulators, are prepared for. In this episode of the #SecureAFPodcast, we sit down with Chris Hood, a veteran technologist and financial industry leader, to explore how AI has evolved from early computing to today’s large language models and agentic systems.We discuss real‑world AI us

Axios NPM Supply Chain Compromise – Lessons for SOCs on Third-Party Risks
Got a question or comment? Message us here!A malicious Axios NPM package highlights how quickly supply chain compromises can spread through trusted dependencies. In this #SOCBrief, we break down what happened, the risks to downstream applications, and what SOC teams should be monitoring to catch similar attacks early. Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on

Black Shrantac Ransomware – LOTL Tactics and Double Extortion on the Rise
Got a question or comment? Message us here!A new ransomware group is blending in with legitimate tools. This #SOCBrief breaks down Black Shrantac and how to detect it early.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

Think Fast or Get Pwned: How Esports Is Forging Elite Cyber Defenders
Got a question or comment? Message us here!Cybersecurity success increasingly hinges on cognitive readiness, the ability to spot patterns fast, make the right calls under pressure, and perform amid chaos. On this episode of the SECURE AF PODCAST, Will Arnett sits down with Jessica Gulick, Founder and Commissioner of the U.S. Cyber Games, to discuss why cognitive training is critical, how esports p

Iranian APTs Targeting U.S. PLCs: OT Wake-Up Call for SOCs
Got a question or comment? Message us here!Iranian-affiliated APT actors are actively targeting U.S. critical infrastructure, specifically PLCs powering essential operations across water, energy, and manufacturing.This #SOCBrief breaks down the latest CISA alert, how attackers are exploiting OT environments, and what security teams need to be watching for right now. From key indicators to practica

Google Chrome Zero-Days Under Active Attack – What SOCs Need to Do Now
Got a question or comment? Message us here!Chrome just became the attack surface of the week.We’re breaking down the latest zero-day exploits, what attackers are doing with them, and how SOC teams can respond before it turns into something bigger. Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

Beyond the Network: The Rise of Medical Device Security
Got a question or comment? Message us here!Healthcare security isn’t just about networks anymore. In this episode, we dive into the complex world of connected medical devices, the challenges of securing them, and why organizations need a more holistic approach to cybersecurity.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you

Interlock Ransomware Hits Cisco FMC Zero-Day: Lessons for SOCs on Edge Device Security
Got a question or comment? Message us here!Your firewall could be the entry point. A critical Cisco FMC zero-day is being used in real-world ransomware attacks, turning security tools into launchpads. In this episode, we cover what’s happening, how attackers are exploiting edge devices, and how SOC teams can stay ahead.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen o

Chinese Hackers Breach FBI Surveillance Network: Supply-Chain Lessons for SOCs
Got a question or comment? Message us here!Suspected Chinese state-linked hackers breached an FBI surveillance network ... not by breaking through the front door, but through a third-party provider.In this episode of the #SOCBrief, we break down how the attack happened, why supply chain vulnerabilities are one of the biggest risks facing SOC teams today, and what this means for organizations of al

Ransomware as a Business: Inside Qilin’s Rise
Got a question or comment? Message us here!Qilin is quickly becoming one of the most dominant ransomware groups in the world, and it’s not because of groundbreaking tactics. It’s because of their business model.In this episode, we break down how Qilin operates as a ransomware-as-a-service group, why affiliates are flocking to them (hint: 80–85% payouts), and how that’s fueling explosive growth acr

MuddyWater's New BugSleep Malware – Iran's Cyber Retaliation Ramps Up
Got a question or comment? Message us here!In this episode of the #SOCBrief, we break down BugSleep, a new backdoor malware tied to the Iranian threat group MuddyWater, and how it’s being used in targeted spear-phishing campaigns against organizations. Learn how the malware works, what indicators SOC teams should watch for, and practical steps to detect and defend against these evolving attacks. S

🚨 The Telus Hack – ShinyHunters Strikes a Telecom Giant 🚨
Got a question or comment? Message us here!A massive breach has shaken the telecom world. In this episode of the #SOCBrief, we break down the alleged TELUS hack claimed by the ShinyHunters threat group, what data may have been stolen, and why the potential exfiltration of massive datasets could have far-reaching consequences for organizations worldwide. From OAuth tokens and API keys to customer P

A.I. as a Multiplier: Introducing Vector Pulse A.I.
Got a question or comment? Message us here!A.I. conversations are everywhere ... but how can businesses realistically use it today? In this episode of Secure AF, we introduce Vector Pulse A.I. and discuss how A.I. can help organizations automate workflows, improve operational efficiency, and support smarter decision-making. We also dive into the growing excitement (and concerns) around A.I., commo

Heightened Cyber Threats Amid U.S.-Iran Conflict Escalation
Got a question or comment? Message us here!Geopolitical tensions are rising ... and cyber threats aren’t far behind. In this episode of the #SOCBrief, we break down the escalating U.S.-Iran conflict, the potential cyber retaliation from Iranian threat actors, and the steps SOC teams can take now to stay ahead of attacks and protect critical systems.Support the showWatch full episodes at youtube.co

OSINT Essentials – Unlocking Not So Hidden Insights for Your SOC
Got a question or comment? Message us here!Open-source intelligence (OSINT) isn’t just for threat actors ... it’s a powerful advantage for SOC teams too. In this episode, we break down how publicly available data can help you uncover exposed assets, detect vulnerabilities early, and shrink your attack surface before attackers do.Support the showWatch full episodes at youtube.com/@aliascybersecurit

Talking SOC Shop: How SOCs Show Value to Leadership 📈
Got a question or comment? Message us here!This episode of the #SOCBrief goes beyond day-to-day cybersecurity news and dives into what SOC success actually looks like from the leadership side. Andrew and CISO Jonathan Kimmitt discuss how SOC teams can communicate risk, create meaningful deliverables, use metrics effectively, and gain leadership buy-in for security decisions.From risk profiles to r

Keeping AI Human-Centered in Digital Forensics 🧑💻⚖️
Got a question or comment? Message us here!AI can categorize images, analyze logs, and surface patterns faster than any human ever could, but it doesn’t understand context, legality, or nuance. In this episode, we discuss how AI is transforming criminal forensics and SOC investigations while examining the ethical, legal, and operational guardrails that must stay in place. As organizations adopt mo

SmarterMail RCE Flaw – Ransomware's New Favorite Door
Got a question or comment? Message us here!No phishing. No user interaction. Just exposed services and a missing authentication check. In this episode of the #SOCBrief, we dive into the SmarterMail RCE flaw already being exploited in the wild and why mail servers continue to be prime ransomware targets. We cover indicators to hunt for, detection tips, and practical steps SOC teams can take to redu

MSI Mayhem – RATs Hiding in Phishing Installers to Evade Detection 🧠
Got a question or comment? Message us here!Attackers are hiding remote access trojans (RATs) inside malicious MSI installers disguised as legit software, and it’s surging in early 2026. We break down how these phishing attacks bypass EDR, what to look for, and how SOC teams can stop them before they turn into full-blown breaches. Support the showWatch full episodes at youtube.com/@aliascybersecuri

Love as an Attack Vector 💌
Got a question or comment? Message us here!Romance scams spike around Valentine’s Day ... and they’re more dangerous than you think. In this episode, we break down how scammers build emotional trust, isolate victims, and turn relationships into financial and emotional traps. Learn the warning signs, the psychology behind the scams, and how to protect yourself and the people you love 💞.Support the

Double Trouble: Microsoft Office and Fortinet FortiCloud Flaws Under Attack 💥
Got a question or comment? Message us here!This week’s #SOCBrief covers a dangerous double-hit: a Microsoft Office security bypass and a Fortinet FortiCloud authentication flaw, both exploited in the wild. Andrew walks through what the CVEs mean, how attackers are abusing trusted tools, and the patching and hunting steps SOC teams should take immediately.Support the showWatch full episodes at yout

Top Ransomware Threats Dominating Early 2026
Got a question or comment? Message us here!Ransomware is kicking off 2026 at full speed. We break down the top active groups right now, how they’re getting in, what infrastructure they’re targeting, and the key indicators your SOC should be watching to stay ahead. 🔐⚠️Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your p

📂 Inside the Breaches: Real Insider Threat Case Files
Got a question or comment? Message us here!Insider threats don’t start with malware ... they start with access. From disgruntled employees to overlooked contractors, this episode breaks down real-world cases, common patterns, and how organizations can better protect what matters most. 🎧🛡️Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and an

CISA Retires 10 Emergency Directives – Progress for Feds, Wake-Up for the Rest of Us
Got a question or comment? Message us here!CISA has officially retired 10 emergency directives ... marking real progress for federal cybersecurity 🚀 But for the private sector, these “old” vulnerabilities are still very much in play ⚠️ In this #SOCBrief, we break down what was retired, why it matters, and what your SOC should do next.Support the showWatch full episodes at youtube.com/@aliascyberse

New Year SOC Reset: New Year, New You(r Security Posture) 🔒
Got a question or comment? Message us here!Kick off 2026 by hitting reset on your SOC 📊. In this episode of the #SOCBrief, we break down key January priorities, from annual security posture reviews and rule tuning to training refreshers and forward planning, so your team starts the year resilient, aligned, and ready for what’s next. Support the showWatch full episodes at youtube.com/@aliascybersec

Trusted Access, Malicious Intent: Insider Threats Explained
Got a question or comment? Message us here!When the threat isn’t external, it’s personal. This episode breaks down insider threats and corporate espionage: how trusted access turns into real risk, what warning signs to watch for, and how organizations can protect themselves. 🔐⚠️Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you

🔐 Holiday Cyber Threats & What’s Coming Next
Got a question or comment? Message us here!🎙️ In this episode, CISO Jonathan Kimmitt steps in to break down the latest cybersecurity threats impacting organizations during the holiday season and beyond. From ransomware spikes during understaffed weekends to holiday-themed phishing, critical Patch Tuesday vulnerabilities, and emerging AI-powered social engineering, Kimmitt covers what security lead

End-of-Year Wrap: 2025 Threat Trends and Bold Predictions for 2026 🎆
Got a question or comment? Message us here!In this special end-of-year SOC Brief, Andrew breaks down the biggest threat-actor and ransomware trends that shaped 2025, and what cybersecurity teams should be preparing for in 2026. From AI-powered ransomware and supply-chain attacks to the growing blur between nation-state operations and cybercrime, this episode connects the data, the patterns, and t

🎄 Holiday Season Security: Preparing Your SOC for the Festive Chaos
Got a question or comment? Message us here!This week’s SOC Brief dives into why the holidays are prime time for cyberattacks 🎄 from surging phishing attempts to sloppy vendor configs, alert fatigue, staffing gaps, and the seasonal spike in ransomware activity. Andrew and Dylan break down what SOCs should be watching for, how to prep, and how to stay covered even when headcount is low. Stay ahead o

Episode 100: Retrospective AF!
Got a question or comment? Message us here!🎉🎙️ EPISODE 100 IS LIVE! We’re celebrating 100 episodes of the Secure AF Podcast!This special edition features CEO Donovan Farrow and CISO Jonathan Kimmitt as they look back on the history of Alias Cybersecurity, the growth of this show, and the journey that brought us here. And we wouldn’t be here without you, the listeners who made this possible. 💜Addit

The Reality of Stalking in a Digital Age 🕵️♂️⚠️
Got a question or comment? Message us here!This episode dives into one of the darkest issues cybersecurity intersects with: stalking. Kimmitt and Peters discuss real cases, modern cyberstalking tactics, privacy failures, the challenges of protective orders, and what victims can do to stay safe. If you've ever wondered how digital footprints turn into real-world danger, or how to protect yours

Special Episode: Inside Weekly Threat-Intel Briefings with a vCISO 💼
Got a question or comment? Message us here!Get an inside look at how weekly threat-intel briefings really work in a mature security program. 🔍⚡ In this special episode, vCISO Jonathan Kimmitt breaks down how raw intel turns into real risk decisions, what trends are hitting organizations right now, and how SOC teams can brief leadership in a way that actually drives action. Stay sharp, stay informe

⚠️ React2Shell Zero-Day ⚠️: Chinese Hackers Strike Within Hours
Got a question or comment? Message us here!A new zero-day is already under active exploitation. This week’s SOC Brief breaks down the React2Shell vulnerability (CVE-2025-55182), how attackers moved within hours of disclosure, and what SOC teams need to do now to reduce exposure and stay ahead of fast-moving threats. 🔐🚨Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on

Tis the Season for Cybercrime: How Hackers Target Holidays 🎄
Got a question or comment? Message us here!In this #SecureAF episode, Tanner and Dylan share real-world IR stories, common attack vectors, SOC fatigue during holiday PTO, and the #1 thing every organization should do before stepping away for the season. If you’ve ever wondered why cyber incidents always seem to hit when everyone is off work, this one explains it. 🎁💻Support the showWatch full episo

U.S.-Venezuela Tensions: Cyber Risks for American SOCs
Got a question or comment? Message us here!In this episode of the #SOCBrief, we dig into how world events can trigger cyber fallout that lands directly on the desks of security teams. From ransomware crews capitalizing on instability to hacktivists launching DDoS attacks and opportunistic actors going after vulnerable sectors, we talk through why geopolitical tension often leads to increased cyber

When People Think They’ve Been Hacked
Got a question or comment? Message us here!📱 This #SecureAF episode covers the everyday questions and concerns people have when they think something unusual is happening with their devices or accounts. Hickman and Peters talk through typical scenarios, common misunderstandings, and the foundational steps that help people regain control of their accounts.Support the showWatch full episodes at youtu

FortiWeb Zero-Day: Silent Patch and Firewall Wake-Up Call 🔥
Got a question or comment? Message us here!This week’s #SOCBrief dives into the FortiWeb zero-day that’s letting attackers create admin accounts with a single unauthenticated HTTP request. With exploitation spiking and Fortinet pushing out a quiet fix, SOC teams are under pressure to lock down configs, audit firewalls, and patch fast. We break down what happened, who’s affected, and how to defend

The Halls: 2025 Hacker Gift Guide 🎁💻
Got a question or comment? Message us here!We’re back with the Hacker Holiday Gift Guide, and this year’s lineup is stacked with RF gadgets, Wi-Fi tools, red-team essentials, and quirky cyber gifts Tanner swears by. Whether you’re shopping for a pentester, a tinkerer, or someone who just loves breaking things (legally), these picks won’t miss. Get ready to level up your holiday shopping.Read here

Patch Tuesday: Zero-Day Alert and Patching Must-Dos ✅
Got a question or comment? Message us here!A new zero-day. 63 flaws. Endless patching chaos. This week’s #SOCBrief breaks down Microsoft’s November Patch Tuesday and what it means for your SOC. We’ll cover the top critical CVEs, patching priorities, and how to keep your systems resilient before attackers strike.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple

⚠️ Insider Threats ⚠️: Ransomware Negotiators Gone Rogue
Got a question or comment? Message us here!This week, we’re digging into a case where ransomware negotiators allegedly became the attackers themselves, leveraging insider access to hit organizations they were supposed to help. This one raises real questions about trust, vendor oversight, and the human element in incident response. We break down what happened and what SOC teams can take away from i

The Art Of The Con (Cyber Edition) 🔐
Got a question or comment? Message us here!In this episode, we break down the real mechanics of social engineering, from phishing emails and text scams to vishing calls and full-on physical pen tests. We share stories from the field, including how attackers build trust, why confidence is often more effective than technical skill, and what happens when social engineering meets the physical world. I

Atroposia RAT: The Malware That Scans for Its Own Exploits
Got a question or comment? Message us here!🎙️ A new threat is making waves ... Atroposia RAT, a remote access trojan that doesn’t just infiltrate systems but scans them for vulnerabilities to exploit further. In this episode, we break down how this modular malware operates, how it hides, and why its built-in scanner is a game-changer for attackers. Learn the detection cues, patching priorities, an

CAPTCHA Con: Hackers' Evolving ClickFix Malware Trap
Got a question or comment? Message us here!“I’m not a robot.” 🤖Hackers are exploiting fake “I’m not a robot” CAPTCHA pages to deliver malware. Host Andrew Hickman breaks down how this ClickFix attack uses social engineering to steal data and evade detection. Tune in to learn key defense tactics and how to keep your team protected.Support the showWatch full episodes at youtube.com/@aliascybersecuri

RondoDox Botnet Expansion: The Shotgun Approach to IoT Exploitation
Got a question or comment? Message us here!This week on the #SOCBrief, Andrew breaks down RondoDox, a rapidly growing botnet campaign taking aim at routers, DVRs, and IoT devices worldwide. With over 50 vulnerabilities across 30+ vendors, this “shotgun” exploitation strategy is fueling massive DDoS and crypto-mining attacks.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Lis

Obscura Ransomware: Unmasking a Stealthy New Threat ⚠️
Got a question or comment? Message us here!In this week’s #SOCBrief, Hickman and Peters break down Obscura ... a new ransomware variant making waves with aggressive evasion tactics, process terminations, and domain controller targeting. We cover what’s known so far, the risks it poses to businesses, and the key defenses every SOC should prioritize.Support the showWatch full episodes at youtube.com

🛡️ Pen Test Potential: How Organizations Are Missing Out on Fortifying the SOC 🛡️
Got a question or comment? Message us here!What’s the real difference between a penetration test and a red team engagement, and how can each benefit your SOC? In this episode, Andrew is joined by Tanner, to unpack how pentests uncover vulnerabilities, how red teams stress-test defenders, and why every organization should be leveraging these exercises.Support the showWatch full episodes at youtube.

2025 SECCON Debrief
Got a question or comment? Message us here!This week on #SecureAFPodcast, we’re recapping #SECCON 2025. From the keynote to the villages and everything in between, join us for a look back at the highlights, takeaways, and community moments that made this year’s conference our best yet.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywh

🚨 Ransomware Rising: Variants, Tactics, and Defenses in 2025 🚨
Got a question or comment? Message us here!Ransomware is evolving faster than ever, from double extortion tactics to lightning-fast attack chains. In this episode, we break down how these threats work, why every organization is a target, and the layered defenses SOCs can use to detect and stop attacks early. Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Pod

💢 FileFix Fiasco 💢 Steganography's Stealthy StealC Drop
Got a question or comment? Message us here!In this episode of The #SOCBrief, we break down the rising FileFix attack, a new social engineering technique using steganography to deliver info-stealing malware. Learn how attackers disguise malicious PowerShell commands, the risks this poses for browsers, messengers, and crypto wallets, and the proactive defenses SOCs can use to detect and contain thes

Monitoring the Dark Web for Leaked Data in DFIR
Got a question or comment? Message us here!🔎 This episode of The #SOCBrief dives into the world of dark web monitoring in digital forensics and incident response. Learn why leaked credentials are a top threat, how to safely detect exposures, and what steps SOC teams can take to stay proactive.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify a

Mastering Incident Response: Essential for SOC Success
Got a question or comment? Message us here!💡 This week on The SOC Brief, we’re breaking down incident response (IR) ... why it’s essential, how to build a strong plan, and what SOC teams can do to turn chaos into control. From preparation and containment to recovery and lessons learned, learn how a solid IR strategy saves time, money, and reputation. 👉 Tune in now at secureafpodcast.comSupport the

DEF CON 33 Debrief
Got a question or comment? Message us here!Fresh off the chaos of DEF CON 33, Tanner, Hickman, and Will break down the four-day hacker conference, from the eye-opening hacker villages and mind-bending talks to Hickman’s clutch CTF victory and Will’s bold dive into the Social Engineering Community’s Vishing Competition. No sleep, all signal.Support the showWatch full episodes at youtube.com/@aliasc

⚠️ Crypto24 ⚠️ Ransomware: Bypassing EDR and Bolstering Defenses
Got a question or comment? Message us here!In this episode, we break down the emerging Crypto24 ransomware attacks that use living-off-the-land techniques to bypass EDR. We’ll explore how these attacks unfold and the defensive strategies SOCs and organizations can use, like layered security, enhanced monitoring, and rapid response, to stay ahead of evolving threats.Support the showWatch full episo

🚨 Gone Vishing: The Recent Surge of Vishing Attacks
Got a question or comment? Message us here!This week, we’re unpacking the phishing wave hitting SaaS platforms ... from social engineering to OAuth abuse and AI voice spoofing. Learn why people remain the #1 attack vector and how to stay one step ahead.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

🚨 SonicWall Firewall Ransomware Breakdown
Got a question or comment? Message us here!On this episode of the #SOCBrief, we break down attacks on SonicWall firewalls. A wave of ransomware, possibly exploiting zero-day vulnerabilities, is compromising even fully patched systems. Learn how SOCs can respond fast and stay ahead.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere

Spilling the Tea: What Happens When Apps Launch Without Locking Down Security ☕
Got a question or comment? Message us here!This week’s SOC Brief unpacks how a misconfigured cloud bucket exposed 72,000+ user images from the Tea app, complete with geolocation metadata and real IDs. From national security risks to doxxing fallout, we break down what went wrong and what your security team must do to avoid the same mistakes.Support the showWatch full episodes at youtube.com/@alias

🚨⚠️ A Critical ZERO-DAY (CVE-2025-53770)
Got a question or comment? Message us here!A critical zero-day (CVE-2025-53770) is actively targeting on-premises SharePoint servers AND it’s already been used to compromise over 100 organizations. In this #SOCBrief, Andrew and Tanner break down how the exploit works and what steps your team should take now. If your SharePoint instance is public-facing and unpatched ... assume compromise.🎧 Tune in

🚪 Offboarding isn't just HR's job …
Got a question or comment? Message us here!In this week’s #SOCBrief, we break down why offboarding policies are ABSOLUTELY critical for security teams. Overlooked items from abandoned accounts to old VPN access can leave backdoors wide open. Learn how SOCs monitor, contain, and shut down lingering access, and why communication between HR, IT, and cybersecurity is essential.🎙️ Tune in. secureafpodc

Aligned by Design: CISO x Legal in Practice - Episode 92
Got a question or comment? Message us here!🎙️ NEW! Aligned by Design: CISO x LegalIntroducing! A fresh new series that explores the intersection of cybersecurity and legal strategy. Join Alias CISO Jonathan Kimmitt and privacy attorney Tom Vincent as they unpack what happens when technology, compliance, risk, and law collide. From real-world experiences to the nuances of the term "breach"

🚨 Record-Shattering DDoS Attack Alert 🚨
Got a question or comment? Message us here!Hackers just unleashed the largest DDoS attack in history, peaking at 7.3 Tbps and 4.8 billion packets per second. In just 45 seconds, it pummeled its target with the data equivalent of over 9,000 HD movies, a powerful reminder of how far attack capabilities have evolved.🎧 Tune in to today’s SOC Brief for insights on DDoS attacks and how to up your defens

Secure AF SOC Brief #5 - Chrome CVE-2025-6554
Got a question or comment? Message us here!In this episode of The SOC Brief, the team unpacks a critical zero-day vulnerability in Google Chrome (CVE-2025-6554) that’s being actively exploited. Learn how attackers use type confusion bugs to hijack browser memory, what makes this exploit so dangerous, and why it’s targeting high-value organizations. Discover actionable steps for updating Chrome, se

Ep 91: The Engineers React to Breach News
Got a question or comment? Message us here!In this episode, our security engineers break down the latest cybersecurity headlines, from the real scoop behind the “16 billion password” leak to the rise of hacker groups like Scattered Spider. 🕷️We discuss how attackers bypass MFA, why exploited data keeps resurfacing, and what organizations can do to protect sensitive data. Plus, we dive into industr

Secure AF SOC Brief #4 - False Positives
Got a question or comment? Message us here!In this episode of The SOC Brief, Andrew and Dax dive into the world of false positives – those misleading alerts that flood security teams with noise. They discuss how misconfigurations, lack of context, and overly sensitive rules can lead to alert fatigue. With practical tips on investigation, tuning tools, and understanding your environment, they highl

Secure AF SOC Brief #3 - IOCs
Got a question or comment? Message us here!🔐 New SOC Brief Episode: Tracing the BreadcrumbsCybercriminals always leave a trail, if you know where to look. In this episode, we break down Indicators of Compromise (IOCs) and how they help security teams detect and respond to threats faster.🎯 What we cover:• Real-world incident reports & proof of concept examples• Threat actor aliases & ransom

Episode 90: Global Wars - Cyber Strikes Back
Got a question or comment? Message us here!🎙️ New Secure AF Episode: Global Wars: Cyber Strikes Back 🌐⚔️How does global news shape cybersecurity operations? In this episode, we dig into how real-world events influence the threats we track, the way we respond, and the tools we use for social engineering/pentesting.🔍 We talk threat intel, evolving attack methods, and what teams should be looking out

Secure AF SOC Brief #2 - SafePay
Got a question or comment? Message us here!🎙️ This Week on the SOC Brief:Join Andrew and Dax as they dive into the emergence of a new threat actor known as SafePay 🕵️♂️💻. They break down the latest tactics, techniques, and procedures observed from this group, offering insights into how organizations can stay vigilant. From detection strategies 🔍 to proactive defense measures 🛡️, this episode is p
Recommended

Lighting the Legal Career Path

High Performance Mindset | Learn from World-Class Leaders, Consultants, Athletes & Coaches about Mindset

Pintastic® Pinterest Podcast

Learn 50 English Phrases While You Sleep | Everyday English Phrases & Vocabulary

The Daily

The Joe Rogan Experience

World News Tonight with David Muir

Talk About Talk - Executive & Leadership Communication Skills

This Past Weekend w/ Theo Von

Stand In The Circle

Conspiracy Files with Paige Carter

Learn English B1 with Daily News | English Listening Practice