Episodios

  • PP126: Trying (and Failing) the CCIE Security Exam
    Sep 15 2026
    Today we talk about trying and failing. More specifically, guest Keith Tokash wrote a pair of blogs on Packet Pushers about taking, but not passing, the CCIE Security written exam. Failure’s a hard thing to talk about, particularly in this age where every public utterance on LinkedIn feels like it has to document one’s ever-upward... Read more »
    Más Menos
    54 m
  • PP125: News Roundup—Cyberattack Impacts Pacemakers, OpenAI Publishes Eye-Opening Postmortem, and More
    Sep 8 2026
    If it feels like everything is on fire, today’s News Roundup will not dispel that feeling. We discuss consumer routers that ship with factory-installed backdoors, US law enforcement agencies shutting down hacking domains, and how a threat actor tied to China is targeting Cisco IOS-XR routers. Android-based auto infotainment systems are susceptible to malware, OpenAI... Read more »
    Más Menos
    1 h
  • PP124: How Coruna, DarkSword, and Other Exploits Slice Up Apple iPhones
    Sep 1 2026
    Coruna and DarkSword are exploit frameworks that have successfully targeted Apple iPhones to steal cryptocurrency and harvest data including messages, email, location data, and browsing history. On today’s show we trace the provenance of these exploits (Coruna was originally developed by a contractor for the US government), their rapid evolution in the cyber underworld, and... Read more »
    Más Menos
    57 m
  • PP123: Using Gridctl to Keep MCP Configs From Leaking Secrets
    Aug 25 2026
    If you’ve been spinning up AI tools — Claude Desktop, Cursor, Copilot, and so on — there’s a decent chance that API keys, credentials, and access tokens are sitting in plaintext on your laptop. With MCP, every quickstart guide tells you to paste your credentials right into a config file. That was a bad habit... Read more »
    Más Menos
    55 m
  • PP122: Using Burp Suite to Understand How Apps Collect and Share Our Data
    Aug 18 2026
    Zack Whittaker is a journalist for TechCrunch and author of the newsletter “This Week In Security.” He recently wrote a post describing how he uses Burp Suite, an open source penetration testing tool, to see what data apps are collecting from users, and what other sites those apps share that data with. Zack joins JJ... Read more »
    Más Menos
    1 h y 2 m
  • PP121: How CYBR.SEC.CON Builds Community for Learning and Professional Development
    Aug 11 2026
    Today we’re doing a crossover episode with the folks at Cybr.Sec.Media to talk about CYBR.SEC.CON, a community-driven security conference that JJ and Drew will be attending in Houston, TX September 15 and 16 2026. We talk with conference founders Michael Farnum and Sam Van Ryder about the origins of the event, and get into our... Read more »
    Más Menos
    37 m
  • PP120: News Roundup—AI Giants Praise Open Weight Models, Attackers Capture Captive Portals, a Tricky Mac Attack, and More
    Aug 4 2026
    Packet Protector uncorks another News Roundup! We talk about attackers capturing hotels’ captive portals to steal Microsoft credentials, and the OpenAI-attacking-Hugging Face story and how it ties into a broader industry effort to keep the US government from blocking access to open weight AI models from China. Nvidia and the Linux Foundation launch separate AI... Read more »
    Más Menos
    1 h y 2 m
  • PP119: Automating Firewall Ops To Stay Ahead of AI Threats (Sponsored)
    Jul 28 2026
    There’s always been a gap between the discovery of a security issue and the time it takes to remediate. Now AI models can autonomously find weak points and chain together actions to exploit them. How does AI change the notion of “fast enough” for network defense? On today’s sponsored episode we dig into how FireMon... Read more »
    Más Menos
    49 m