Home Podcasts Breach Please
Breach Please

Breach Please

Breach Please Team 36 Episodes Sep 17, 2026

Breach Please is a cybersecurity podcast hosted by Jake Williams and Jess Hebenstreit. It covers cybersecurity news, analysis, and commentary, calling out vendor hype and fear-mongering. The hosts bring real incident response and offensive security experience to break down stories that matter. Episodes aim to translate industry chaos into practical insights for people in SOCs, boardrooms, and everywhere in between.

Episodes

S0:E36 - Jake Talks to Exaforce about Data vs APIs in AI-enabled SOC
S0:E36 - Jake Talks to Exaforce about Data vs APIs in AI-enabled SOC Sep 17, 2026 19:56 In this episode, Jake sits down with one of Exaforce's co-founders and a long time user to discuss AI-enabled SOC. One of the big things we talk about is why API-based solutions miss a lot of context that is only really possible to generate with an underlying data model. We also talk about dogs and cats at the end for some fun personal discussions. Jess will be back tomorrow for more fun security
S0:E35. Update Yo Firewall Rules and Digital Escorts (totally SFW)
S0:E35. Update Yo Firewall Rules and Digital Escorts (totally SFW) Sep 16, 2026 30:56 In this episode, Jake and Jess talk about an upcoming critical change to domains for M365 and Teams that are ironically going to disproportionately impact those with the best security the most. We conclude this is busy work that MSFT is causing. Then we take a hard right into talking about Microsoft's Digital Escort (sounds dirty, but somehow is totally SFW) program, revealed by ProPublica. It's o
S0:E34. Jake and Stel talk zero-trust and validating network edge devices.
S0:E34. Jake and Stel talk zero-trust and validating network edge devices. Sep 15, 2026 13:43 Jake and Jess will be back tomorrow for more content together. In this episode of Breach Please, Jake sits down with Stel Valavanis, co-founder of Blue Team Con. They discuss how for too long, we've known that network edge devices needed to be part of the zero trust equation, but put them in the "too hard" bucket of security because we didn't have tools to monitor them. Stel talks about the format
S0:E33 - (re-record) The EU CRA and You (even if you aren't an EU company)
S0:E33 - (re-record) The EU CRA and You (even if you aren't an EU company) Sep 14, 2026 49:30 Folks, our apologies. We didn't realize how bad the audio was with a given microphone/computer setup was for Riverside (our recording platform). We re-recorded and honestly, not only is the audio better, but it's a MUCH better episode overall.On September 11, 2026, reporting requirements baked into the EU Cyber Resiliency Act came into force. The requirements apply to any vendor that sells or make
S0:E32 - Where Traditional EDR Has Visibility Gaps with Golan Myers from Bloom Security
S0:E32 - Where Traditional EDR Has Visibility Gaps with Golan Myers from Bloom Security Sep 13, 2026 15:56 In this episode, I sit down with Golan Myers with Bloom Security and discuss what EDR is missing in its visibility. We then discuss some of the findings from his research and Bloom Security and what they're doing to solve the problem.https://www.linkedin.com/in/golan-myers/https://bloom.security/
S0:E31 — They Did Everything Right, and Still Got Burned
S0:E31 — They Did Everything Right, and Still Got Burned Sep 11, 2026 36:07 Trezor disclosed a breach affecting roughly 67,000 US customers, data from orders placed between November 2019 and August 2021. The twist: Trezor had repeatedly requested and received written assurance that this data was deleted, in line with their contract and data policy. It wasn't. Jess and Jake use this as a real-world case study in third-party risk management, why "right to audit" is often a
S0:E30 — WeChat's Zero-Click Worm Didn't Need AI to Be Scary
S0:E30 — WeChat's Zero-Click Worm Didn't Need AI to Be Scary Sep 9, 2026 23:47 Researchers at security firm Calif found a zero-click exploit chain in WeChat: place a call, the target doesn't even have to answer, and you get code execution on their phone. Chain it with other bugs and you get full device control, on both iOS and Android. Tencent patched it. The bigger problem started after, when the New York Times ran a headline blaming an AI model for building a computer worm
S0:E29 — The GRE Tunnel That Wasn't in the Config
S0:E29 — The GRE Tunnel That Wasn't in the Config Sep 8, 2026 38:32 Sygnia published new research on Fire Ant, a threat actor they first tracked in 2025 around hypervisor espionage against vCenter and ESXi. The new report covers something rarer: live compromise of Cisco IOS XR network devices, discovered because a responder noticed a GRE tunnel in network monitoring that didn't exist in the running config and left no trace in the logs. Jess and Jake walk through w
S0:E28 — When "Unique Experiences" Means Everyone Looks the Same
S0:E28 — When "Unique Experiences" Means Everyone Looks the Same Sep 5, 2026 23:35 Jess opened LinkedIn to a CISO certificate program announcement featuring its full guest lecturer roster. Every single one looked the same. Tarah Wheeler joins Jess and Jake for their first-ever guest episode to talk through why this particular miss is worse than a one-hour conference "manel," what accountability actually looks like when it happens (spoiler: it's not calling out names), and the re
S0:E27 — The Agentic Ransomware Story That Wasn't
S0:E27 — The Agentic Ransomware Story That Wasn't Sep 4, 2026 33:45 Palo Alto's Unit 42 published a report describing a fully automated, agentic AI ransomware attack, complete with an 80-page lessons-learned document the attackers supposedly left behind for the victim. It got picked up and ran with by outlets looking for the AI-apocalypse angle. Jess and Jake go through what the report actually says versus what got exaggerated in the retelling, and call out the pa
S0:E26. IDScan.net suspected data breach, toxic data, and TPRM in general.
S0:E26. IDScan.net suspected data breach, toxic data, and TPRM in general. Sep 3, 2026 46:04 In this episode of Breach Please, Jake and Jess talk about the suspected IDScan.net breach. We discuss whether a situation like this is a data breach for your org if you "only" use a third party processor to verify identity. We decide this is a question best left for external counsel (with the cover of their malpractice insurance). We discuss the difficulties of saying "third party risk management
S0:E25 — The Exchange Bug That's Worse Than Its Score
S0:E25 — The Exchange Bug That's Worse Than Its Score Sep 2, 2026 31:02 A CVSS 8 elevation-of-privilege bug in on-prem Exchange looks unassuming until you dig into what it actually grants an attacker. Jess and Jake break down the proxy flaw, why "authorized attacker" is doing a lot of quiet work in that description, and why this is one of the rare moments defenders get a head start before exploitation goes wide.Jake's course at Wild West Hackin' Fest: https://www.anti

Recommended