Home Podcasts Secure AF - A Cybersecurity Podcast
Secure AF - A Cybersecurity Podcast

Secure AF - A Cybersecurity Podcast

Alias Cybersecurity 168 Episodes Aug 20, 2026

Secure AF is a cybersecurity podcast hosted by industry veterans Donovan Farrow and Jonathan Kimmitt. It covers real-world infosec challenges, red team tactics, blue team strategies, and the latest tools in cybersecurity. The show features expert interviews and unfiltered discussions with Alias team members and guests. It aims to provide actionable insights for pentesters, SOC analysts, and newcomers to the field.

Episodes

Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders
Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders Aug 20, 2026 343 Got a question or comment? Message us here!Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes.Support
Windows BlueHammer Flaw Now Actively Exploited by Ransomware Gangs
Windows BlueHammer Flaw Now Actively Exploited by Ransomware Gangs Jul 8, 2026 288 Got a question or comment? Message us here!Ransomware operators are leveraging the BlueHammer privilege escalation flaw to gain SYSTEM-level access and disable security controls. Get the latest insights and response recommendations. Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.
FortiBleed Attacks: Turning Fortinet Firewalls into Credential Stealers
FortiBleed Attacks: Turning Fortinet Firewalls into Credential Stealers Jul 1, 2026 293 Got a question or comment? Message us here!FortiBleed is turning perimeter defenses into attack infrastructure. In this episode, we unpack how adversaries exploit FortiOS vulnerabilities, harvest credentials directly from firewalls, and pivot deeper into networks, plus detection strategies, threat hunting tips, and mitigation guidance for SOC teams.Support the showWatch full episodes at youtube.co
Arch Linux AUR Compromise – Supply Chain Risks in the Open Source World
Arch Linux AUR Compromise – Supply Chain Risks in the Open Source World Jun 24, 2026 344 Got a question or comment? Message us here!This #SOCBrief episode explores a recent Arch Linux AUR supply chain compromise, where malicious community packages were used to steal credentials and gain persistence. It highlights the risks of third-party repositories and offers key detection and mitigation strategies for security teams to better protect against similar attacks. Support the showWatch f
Qilin Ransomware Exploiting VPN Zero-Days: What SOCs Need to Do Now
Qilin Ransomware Exploiting VPN Zero-Days: What SOCs Need to Do Now Jun 17, 2026 292 Got a question or comment? Message us here!A single unpatched VPN could be all it takes. Qilin ransomware is actively exploiting VPN zero-days to breach networks and accelerate ransomware deployment. We walk through the tactics, the real risk to your organization, and actionable SOC strategies to stay ahead.Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podc
You're Probably Not Hacked, You're Being Tracked
You're Probably Not Hacked, You're Being Tracked Jun 16, 2026 2633 Got a question or comment? Message us here!You probably haven’t been hacked, you’ve been tracked. This episode breaks down how ad tech, mobile apps, and data brokers create massive behavioral profiles without ever touching your phone’s security. Learn how tracking really works, why it matters, and what you can actually do about it. 📱👁️📡Support the showWatch full episodes at youtube.com/@aliascyber
The SOC Brief Turns One 🎂 Insights, Stories & Lessons Learned
The SOC Brief Turns One 🎂 Insights, Stories & Lessons Learned Jun 10, 2026 830 Got a question or comment? Message us here!It’s our 1-year anniversary! 🎂 From bite-sized cyber insights to growing a passionate listener base, this episode reflects on the journey, the challenges, and the wins along the way. Expect laughs, lessons, and behind-the-scenes stories you won’t want to miss. 🚀Support the showWatch full episodes at youtube.com/@aliascybersecurity.Listen on Apple Podcasts
Kali365 Phishing-as-a-Service: FBI Warns of New M365 Credential Theft Tool
Kali365 Phishing-as-a-Service: FBI Warns of New M365 Credential Theft Tool Jun 3, 2026 339 Got a question or comment? Message us here!The FBI is warning about Kali365, a new phishing‑as‑a‑service tool designed to steal Microsoft 365 credentials and enable account takeovers at scale. In this episode, we break down how it works, why it’s so effective, and what your SOC can do right now to detect and defend against it. 🎧 Tune in now at secureafpodcast.comSupport the showWatch full episodes
Incident Response 101: What to Do When You’re Under Attack
Incident Response 101: What to Do When You’re Under Attack Jun 2, 2026 2252 Got a question or comment? Message us here!What actually happens when a company gets hacked?In this episode, we break down real-world incident response, from initial access and ransomware tactics to forensic investigation and common mistakes that make things worse. If your organization had an incident tomorrow, would you know what to do?Support the showWatch full episodes at youtube.com/@aliascybe
First Known AI-Powered Zero-Day Exploit: What SOCs Need to Know 🤖
First Known AI-Powered Zero-Day Exploit: What SOCs Need to Know 🤖 May 27, 2026 288 Got a question or comment? Message us here!In this episode of the #SOCBrief, we dive into the first confirmed case of an AI-powered zero-day exploit. With attackers leveraging AI to discover vulnerabilities, generate exploit code, and bypass defenses faster than ever, this marks a major shift in how threats are developed and deployed. We break down how the attack worked, what made the exploit uniq
ShinyHunters Breach of Instructure Canvas LMS 📚✏️: Lessons for SOCs on Third-Party Vendor Risks
ShinyHunters Breach of Instructure Canvas LMS 📚✏️: Lessons for SOCs on Third-Party Vendor Risks May 20, 2026 321 Got a question or comment? Message us here!In this episode of the #SOCBrief, we break down the ShinyHunters breach of Instructure’s Canvas LMS and what it means for security teams everywhere. From exploiting a lesser-monitored service to exfiltrating millions of records, this attack highlights the growing risk of third-party vendors and supply chain exposure. We walk through how the breach unfolde
Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS Risk
Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS Risk May 19, 2026 3312 Got a question or comment? Message us here!When the Canvas LMS went down, thousands of institutions came to a halt, right in the middle of finals. In this episode, we break down what really happened, what data may have been exposed, and why this incident is a wake-up call for every organization relying on SaaS platforms.From vendor risk and contract blind spots to business continuity failures, we

Recommended