
Breach Please
Breach Please is a cybersecurity podcast hosted by Jake Williams and Jess Hebenstreit. It covers cybersecurity news, analysis, and commentary, calling out vendor hype and fear-mongering. The hosts bring real incident response and offensive security experience to break down stories that matter. Episodes aim to translate industry chaos into practical insights for people in SOCs, boardrooms, and everywhere in between.
Episodes

S0:E36 - Jake Talks to Exaforce about Data vs APIs in AI-enabled SOC
In this episode, Jake sits down with one of Exaforce's co-founders and a long time user to discuss AI-enabled SOC. One of the big things we talk about is why API-based solutions miss a lot of context that is only really possible to generate with an underlying data model. We also talk about dogs and cats at the end for some fun personal discussions. Jess will be back tomorrow for more fun security

S0:E35. Update Yo Firewall Rules and Digital Escorts (totally SFW)
In this episode, Jake and Jess talk about an upcoming critical change to domains for M365 and Teams that are ironically going to disproportionately impact those with the best security the most. We conclude this is busy work that MSFT is causing. Then we take a hard right into talking about Microsoft's Digital Escort (sounds dirty, but somehow is totally SFW) program, revealed by ProPublica. It's o

S0:E34. Jake and Stel talk zero-trust and validating network edge devices.
Jake and Jess will be back tomorrow for more content together. In this episode of Breach Please, Jake sits down with Stel Valavanis, co-founder of Blue Team Con. They discuss how for too long, we've known that network edge devices needed to be part of the zero trust equation, but put them in the "too hard" bucket of security because we didn't have tools to monitor them. Stel talks about the format

S0:E33 - (re-record) The EU CRA and You (even if you aren't an EU company)
Folks, our apologies. We didn't realize how bad the audio was with a given microphone/computer setup was for Riverside (our recording platform). We re-recorded and honestly, not only is the audio better, but it's a MUCH better episode overall.On September 11, 2026, reporting requirements baked into the EU Cyber Resiliency Act came into force. The requirements apply to any vendor that sells or make

S0:E32 - Where Traditional EDR Has Visibility Gaps with Golan Myers from Bloom Security
In this episode, I sit down with Golan Myers with Bloom Security and discuss what EDR is missing in its visibility. We then discuss some of the findings from his research and Bloom Security and what they're doing to solve the problem.https://www.linkedin.com/in/golan-myers/https://bloom.security/

S0:E31 — They Did Everything Right, and Still Got Burned
Trezor disclosed a breach affecting roughly 67,000 US customers, data from orders placed between November 2019 and August 2021. The twist: Trezor had repeatedly requested and received written assurance that this data was deleted, in line with their contract and data policy. It wasn't. Jess and Jake use this as a real-world case study in third-party risk management, why "right to audit" is often a

S0:E30 — WeChat's Zero-Click Worm Didn't Need AI to Be Scary
Researchers at security firm Calif found a zero-click exploit chain in WeChat: place a call, the target doesn't even have to answer, and you get code execution on their phone. Chain it with other bugs and you get full device control, on both iOS and Android. Tencent patched it. The bigger problem started after, when the New York Times ran a headline blaming an AI model for building a computer worm

S0:E29 — The GRE Tunnel That Wasn't in the Config
Sygnia published new research on Fire Ant, a threat actor they first tracked in 2025 around hypervisor espionage against vCenter and ESXi. The new report covers something rarer: live compromise of Cisco IOS XR network devices, discovered because a responder noticed a GRE tunnel in network monitoring that didn't exist in the running config and left no trace in the logs. Jess and Jake walk through w

S0:E28 — When "Unique Experiences" Means Everyone Looks the Same
Jess opened LinkedIn to a CISO certificate program announcement featuring its full guest lecturer roster. Every single one looked the same. Tarah Wheeler joins Jess and Jake for their first-ever guest episode to talk through why this particular miss is worse than a one-hour conference "manel," what accountability actually looks like when it happens (spoiler: it's not calling out names), and the re

S0:E27 — The Agentic Ransomware Story That Wasn't
Palo Alto's Unit 42 published a report describing a fully automated, agentic AI ransomware attack, complete with an 80-page lessons-learned document the attackers supposedly left behind for the victim. It got picked up and ran with by outlets looking for the AI-apocalypse angle. Jess and Jake go through what the report actually says versus what got exaggerated in the retelling, and call out the pa

S0:E26. IDScan.net suspected data breach, toxic data, and TPRM in general.
In this episode of Breach Please, Jake and Jess talk about the suspected IDScan.net breach. We discuss whether a situation like this is a data breach for your org if you "only" use a third party processor to verify identity. We decide this is a question best left for external counsel (with the cover of their malpractice insurance). We discuss the difficulties of saying "third party risk management

S0:E25 — The Exchange Bug That's Worse Than Its Score
A CVSS 8 elevation-of-privilege bug in on-prem Exchange looks unassuming until you dig into what it actually grants an attacker. Jess and Jake break down the proxy flaw, why "authorized attacker" is doing a lot of quiet work in that description, and why this is one of the rare moments defenders get a head start before exploitation goes wide.Jake's course at Wild West Hackin' Fest: https://www.anti

S0:E24. We talk about the attack on Boston Scientific and ransomware in general.
In this episode, Jake and Jess talk about the IT availability issue occurring at Boston Scientific (be real, it's almost certainly ransomware). Then we talk about ransomware response, immutable backups (and specifically what they DON'T get you), and rabbit hole in the ransomware discussion several times.Jake also reps #SAINTCON - you should go if you get the opportunity (tickets for this year are

S0E23. The LA County Museum of Art breach that took a year to unravel
LACMA’s year-long breach disclosure delay and what it says about incident responseJess Hebenstreit and Jake Williams break down a Los Angeles County Museum of Art data security incident that raises big questions about breach timelines, notification delays, and response ownership. They focus on what the disclosure says, what it leaves unsaid, and why the cleanup process may have taken far longer th

S0:E22. We go a little long discussing the OpenAI post-mortem on Hugging Face.
In today's episode of Breach Please, Jake and Jess talk through the OpenAI post-mortem on the Hugging Face hack. It's a doozy. There's little doubt in either of our minds that the facts as presented don't exonerate OpenAI - they make it look far worse. We cut through the hype and conclude that there's no way OpenAI was following even the most basic of security best practices, even accounting for h

S0E21: Alabama Comes for OpenAI, WebLogic Comes for Everyone
Fifteen state attorneys general, led by Alabama, just subpoenaed OpenAI over the Hugging Face breach, demanding the company preserve all evidence related to the intrusion. Jess and Jake break down what that legal hold actually requires, why "mark it ACP" doesn't make a Slack channel privileged, and why the discovery list's question about internal safety concerns might be the part that burns OpenAI

S0:E20 Multi-Agent AI Systems Turn Into Turf Wars
AI just became a cybersecurity governance problem in public. Jess Hebenstreit and Jake Williams break down Anthropic’s multi-agent research, where AI agents with conflicting goals start negotiating, forcing, or trucing their way through “collaboration.”What does it mean when one model settles by force and another settles by truce? Jess and Jake unpack what that means for real-world agent deploymen

S0:E19: Cloud Platform Vulnerabilities and Vendor Transparency
In this episode, Jake and Jess talk about vulnerabilities in cloud platforms and how vulnerabilities should be disclosed. We discussed this in the context of recent Microsoft vulnerabilities in Entra, Azure Arc, Exchange Online, and Managed Apache Casandra. All of these had vulnerabilities with minimal details from Microsoft. We generally agree that this isn't what transparency looks like. We also

S0:E18. Student stops AI supply chain attack and prompt injection is still a thing...
In this episode of Breach Please, we talk about the details that emerged about the Anthropic agent that tried to social engineer a college student into committing a supply chain attack. The whole thing feels very xz-utils 'esque, only with an agent - and a malfunctioning one at that.Then we cover some interesting reporting by Dan Goodin showing how Grok's guardrails can be bypassed through passing

S0E17: Amazon vs Perplexity Reveals the First Big AI Agent Liability Test
AI agents are about to test the limits of who gets blamed when they act on your behalf. A new Ninth Circuit ruling in the Amazon vs. Perplexity fight could reshape how enterprises think about autonomous tools, non-human identities, and legal exposure - and the takeaway is more unsettling than most vendors will admit. Jake Williams and Jess Hebenstreit break down what happened when Amazon pushed ba

S0:E16. OpenAI Highlights Security Basics and Hopes We Won't Notice
In this episode of Breach Please, Jake and Jess talk through OpenAI's recent blog on "pacing model development." The blog reads pretty poorly and really just covers security best practices, apparently hoping readers won't notice that OpenAI is just recommending basics it should have been doing all along (monitoring, sandboxing, etc.). One significant takeaway is that OpenAI has probably raised the

S0E15 Faking out Famous Chollima and is in-car infotainment advertising a threat?
In this episode of Breach Please Jake and Jess talk about Famous Chollima getting faked out and tricked into revealing TTPs. We discuss our own experience with DPRK workers and share actionable tips for not hiring them or discovering them after they've been hired. Jake may or may not have gone on a rant about cryptocurrency more generally and how it facilitates lots of crime (inspired by talking a

S0:E14 - CTI and Geopolitical Events
In this episode of Breach Please, we talk about whether CTI analysts can use changes in dwell times, cyber targeting, etc. as a leading indicator of impending geopolitical events. We generally think there's to much noise to be generally effective (especially for Taiwan). Then we talk about a Mac vuln that's being exploited in the wild, with a CVSS score of 9.8. Somehow it isn't in CISA's KEV, but

S0E13 - We talk about private companies conducting cyber ops and another AI oopsie.
In today's episode of Breach Please, Jake and Jess talk about cyber companies conducting cyber ops against transnational-criminal organizations, per the new Presidential directive. We also talk about a bug in how major AI platform providers encrypted their chain of thought traces for their frontier models. The vulnerability, when combined with jailbreaking of less powerful models, allowed the trac

S0E12 - Vulnerable edge devices, Fortinet exploitation, and whether firewalls belong in zero trust
This episode tackles why internet-facing edge devices keep showing up in major incidents and why that creates more than just patching work. Jess Hebenstreit and Jake Williams also dig into the real operational cost of keeping vulnerable gear in place, from constant incident response to the challenge of proving a device is actually clean. We discuss Fortinet exploitation tied to Gunra ransomware, w

S0E11 - Using AI for patching and inflight shenanigans.
In this episode of Breach Please, Jake and Jess talk about new research showing that AI isn't actually that good at generating patches, highlighting objective rates of failure. Turns out, frontier models only generate the correct patch without introducing issues in about 25% of cases. In almost 5% of cases, the AI introduces new vulnerabilities. We also talk about some shenanigans on a Delta fligh

S0E10 - Commonalities in AI lab escapes and How to govern smart devices.
In this episode of Breach Please, Jake and Jess talk about governing smart devices in the enterprise, pivoting off some outstanding research work that Andy Greenberg covered (and was a subject in himself). Then we talk about a common player whose name keeps popping up in these "AI lab escape" disclosures (and who we saw *again* with the Meta disclosure). We bat around some actionable advice for th

S0E9 - AI social engineering & operational concerns with AI workflows.
In this episode, Jake and Jess talk about more issues with AI agents escaping containment, this time actively using social engineering to compromise victims. We pose ethical questions about whether you have a duty to investigate your logs for agent breakouts. Then, we discuss how Grokipedia can serve as a cautionary tale in AI workflows silently breaking down.Show links: https://www.bleepingcomput

S0E8 - Anthropic ruins Jake's best laid plans, BMC controller vulns, and SentinelOne vs HJ
In this episode of Breach Please, Jake and Jess talk about Anthropic announcing they have lost control of their agents too (not to be outdone by OpenAI). OpenAI is in good company though, since Anthropic ALSO failed to notice their agents breaking out of their sandbox environments. Jake mentions CUSTODY, a framework he'd been planning to present on later this year until these irresponsible agentic

S0E7 - HuggingFace Post Mortem Breakdown
Jake and Jess discuss the excellent post mortem Hugging Face released as a follow on to the OpenAI agent attack. We cover everything from should we call an Autonomous Agent a Threat Actor, to API Security, other lessons learned.

S0E6 - Hacker Summer Camp Survival Guide
In this episode, Jake and Jess share their tips for doing Hacker Summer Camp (Black Hat, DEF CON, B-Sides, and SO MANY side conferences) the right way. If you've never been, things can be overwhelming and it's easy to overdo it. Even if you're an old hat, there's probably learnings here - plus Jess shows off some of the Breach Please swag we'll have with us.

S0E5 - Probable alert fatigue endangers DHS collaborators and duress passwords.
In this episode, Jake and Jess talk DHS (twice). First, we talk about DHS dismissing real alarms as false positives in what Jake assesses was a probable watering hole attack nobody seems to be acknowledging. Then we talk about a #stopCopCity activist being charged for giving CBP a duress password that wiped his device. While I think we should all agree that's not a chargeable offense, are duress p

S0E4 - Google indexes AI chats (again) and dump of PoC exploits
In this episode of Breach Please, Jake and Jess talk about how the story (again) about AI chats being indexed by search engines isn't really an AI story. This is a data security problem and a misalignment with enterprise tooling. We then talk about a relatively new GitHub repo with lots of zero day exploits. We agree it's academically interesting, but doesn't change anything for how we do enterpri

S0E3 - OpenAI Lost Control of its Agents
In this episode, we talk a lot (too much, we went over on time) about the reports that OpenAI lost control of its agents and apparently only realized it after Hugging Face posted and someone said "yeah, that sounds a bit like us." Reuters article: https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/ Jake mentioned training. Her

S0E2 SNow vs researchers and destructive cyberattacks.
In this episode, Jake and Jess talk about lessons we can take away from the alleged exploitation of ServiceNow (likely CVE-2026-6875) and the destructive attack on Romania's Land Registry Database. Join us as we discuss the stories, but more importantly what they mean for you and your security team.

S0E1 OpenAI hacked Hugging Face? Oh noes!
Jake and Jess talk through the story (and there's a LOT missing here) where OpenAI's agent allegedly hacked Hugging Face. There's so much meat missing in OpenAI's account of what happened that their PR people are clearly advocating we go vegetarian...

S0E0 - Is This Thing On?
In this episode, we discuss our mission statement. What are we even doing with Breach Please? What can you expect? Does the industry even need more talking heads? We think so - but only if they tell it like it is...
Recommended

This Past Weekend w/ Theo Von

Learn 50 English Phrases While You Sleep | Everyday English Phrases & Vocabulary

پلی لیست | PlayList

English with Olivia | Slow Conversations & Vocabulary

Conspiracy Files with Paige Carter

Learn English A2 with Daily News | Simple English Listening Practice

Bible Tea

Bad Friends

Fantasy Flex

Solved Murders - True Crime Stories

紐約鳥|New York Aperture

The Swerve Podcast: Obscure Topics | Conspiracy Theories