This week on the podcast we welcome back Ryan Estes from the WatchGuard Endpoint Security attestation team to discuss a recent deep dive analysis of NoisyS0cks. After that, we give an update on the latest trends in Ransomware targeting SMBs.
In this episode, host Richard Bejtlich sits down with Corelight Senior Sales Engineers Adam Donadeo and Nico Roosenboom to unpack their firsthand experiences at Locked Shields, the world’s largest international live-fire cyber defense exercise. The conversation dives deep into the chaotic, real-world friction of defending a massive virtualized network alongside 4,000 global experts against aggressive red team waves.
Learn how to back up a Proxmox VE VM to tape using a backup copy job, and how to recover a Proxmox VE VM directly from tape to a Proxmox host with NAKIVO Backup & Replication. Learn more.
Watch the seventh episode of CISO Global's podcast, "You've Been Owned," with host CISO Gary Perkins. In this episode, Gary sits down with Steve Quartarone, Partnerships Director at Prove.
CMMC Phase 2 enforcement lands in November 2026, and C3PAOs are already warning about assessment capacity. If your configuration management domain isn't audit-ready, this is the walkthrough to fix that. Roy Ludmir breaks down what changed in enforced CMMC as of November 2025, what auditors actually test versus what they just ask about, and where most organizations get stuck below full compliance — plus which security baselines to standardize on and how to build an evidence package that holds up under a real assessment.
AI agents and AI coding are creating a new software supply chain risk inside development teams. When coding agents pull code, prompts, skills and open source packages straight from GitHub, insecure code and malicious dependencies get much closer to production.
The Five Eyes intelligence alliance—NSA, CISA, GCHQ, Australia's ASD, Canada's Cyber Centre, and New Zealand's GCSB—just issued a joint warning: AI has compressed the window between vulnerability discovery and exploitation from years to months. Adrian breaks down what the "AI Shift in Cyber Risk" statement actually means for patching timelines and attacker sophistication—and why most organizations aren't moving fast enough to keep up.