Couverture de The CISO Signal: True Cybercrime Podcast

The CISO Signal: True Cybercrime Podcast

The CISO Signal: True Cybercrime Podcast

De : Jeremy Ladner
Écouter gratuitement

Offres de saison | 0,99 € par mois pendant les 3 premiers mois

5,99 €/mois par la suite. Des conditions s’appliquent. Annulation mensuelle possible.
The CISO Signal is a true cybercrime podcast investigating the most consequential breaches, insider threats, takedowns, and nation-state hacks shaping today’s digital world. Each episode combines gripping, cinematic storytelling with exclusive interviews from top CISOs and cybersecurity leaders. Together, we break down how the world’s most dangerous cyberattacks unfolded and what today’s security professionals must learn from them. Whether you’re a Chief Information Security Officer, a security team member, or a fan of true crime and high-stakes digital espionage, this show pulls you behind the curtain of real-world cyber warfare. 🎧 Educational. Entertaining. Essential. The CISO Signal delivers expert insights and battlefield-tested lessons that every security leader and true cybercrime fan should hear.© 2026 Jeremy Ladner
Épisodes
  • ALL ACCESS ATTACK | One Chatbot Hacked. 700+ Companies Hit. – EP 20 The CISO Signal
    Oct 2 2026

    It was just a little chat window in the corner of the screen.

    The kind you see on thousands of websites every day. But behind it was a web of trusted connections reaching deep inside the enterprise.

    In August 2025, attackers tracked as UNC6395 compromised OAuth tokens associated with Salesloft’s Drift integration, turning trusted connections to customer Salesforce environments into an attack path reaching hundreds of companies, including some of the world’s most sophisticated technology and cybersecurity organizations.

    Instead of breaching those companies one by one, the attackers compromised trust upstream and inherited access downstream.

    Then they went looking for more.

    Inside stolen Salesforce data, the attackers reportedly searched for passwords, API keys, cloud credentials, and other secrets that could potentially open the next system, cloud environment, or application.

    The Drift breach exposed a much larger problem.

    Modern enterprises depend on thousands of connections between SaaS platforms, APIs, cloud services, applications, and third parties. Every connection creates business value, but it also extends trust and expands the attack surface.

    What happens when something you trust becomes the attacker’s way in?

    In this episode of The CISO Signal | True Cybercrime Podcast, host Jeremy Ladner is joined by Volker Rath, Field CISO APAC at Cloudflare, the sponsor of this episode, to investigate the Drift breach and what it reveals about the changing enterprise attack surface.

    Together they explore:

    • How UNC6395 turned compromised OAuth tokens into an attack path reaching hundreds of companies
    • Why compromising one trusted integration can create a massive downstream blast radius
    • What the attackers were searching for inside stolen Salesforce data
    • How security teams detect malicious behavior hiding behind legitimate access
    • Why even sophisticated cybersecurity companies can inherit risk from trusted connections
    • Whether traditional third-party risk programs adequately measure that risk
    • Why revoking compromised tokens may only be the beginning of incident response
    • How AI could help attackers learn, adapt, and operate at machine speed
    • Which assumptions about trusted applications and authorized connections CISOs may need to rethink

    Your attack surface no longer ends at the edge of your network.

    It extends through everything you trust.

    🎙 This episode is sponsored by Cloudflare.

    Cloudflare helps organizations connect and protect their people, applications, infrastructure, and networks across an increasingly distributed digital environment.

    🌐 https://www.cloudflare.com

    🎙 Guest Co-Host

    Volker Rath
    Field CISO APAC | Cloudflare

    Volker works with security leaders and executives across the Asia-Pacific region on the changing realities of enterprise cybersecurity. In this episode, he joins Jeremy to examine what the Drift breach can teach CISOs about inherited trust, third-party risk, and protecting an enterprise increasingly connected to systems outside its direct control.

    🔎 Episode Topics:

    • Salesloft Drift breach
    • UNC6395
    • Salesforce security
    • OAuth token compromise
    • SaaS security
    • Third-party risk
    • Supply chain attacks
    • API and cloud security
    • Identity security
    • Zero Trust
    • Enterprise attack surface
    • AI-powered cyberattacks
    • Cloudflare
    • CISO leadership

    🧩 The CISO Signal links:

    ▶️ / @thecisosignal
    💼 / the-ciso-signal
    🌐 https://www.thecisosignal.com

    👥 Join the Conversation:

    If one of your organization’s trusted applications were compromised tomorrow, would your security team recognize when legitimate access had become malicious access?

    Let us know what you think in the comments.

    #CISOSignal #DriftBreach #Salesloft #Salesforce #UNC6395 #OAuth #SaaSSecurity #ThirdPartyRisk #CloudSecurity #IdentitySecurity #ZeroTrust #CyberSecurity #Cloudflare #CISO #TrueCybercrime

    Afficher plus Afficher moins
    44 min
  • The Enemy Inside: How North Korea’s Phantom Employees Hack the Hiring Process – The CISO Signal EP19
    Sep 4 2026
    One of the most sophisticated nation-state cyber campaigns ever uncovered didn’t begin with ransomware.Or phishing.Or a zero-day vulnerability.It began with a job interview.Using stolen identities, fabricated résumés, U.S.-based laptop farms, and an international network of facilitators, North Korean operatives secured remote technology jobs inside hundreds of legitimate companies.They attended interviews.Passed technical assessments.Joined engineering teams.Collected salaries.And gained trusted access to the systems, source code, cloud environments, and intellectual property of some of the world’s most valuable organizations.One Arizona woman, Christina Chapman, helped North Korean workers obtain jobs at more than 300 American companies and generate over $17 million. But she wasn’t the mastermind.She was one visible part of a much larger machine.Now, artificial intelligence is making that machine even more powerful. Deepfake interviews, cloned voices, AI-generated résumés, synthetic identities, and real-time interview assistance are making it increasingly difficult to answer one of cybersecurity’s most fundamental questions:Is the person on the other side really who they claim to be?In this episode of The CISO Signal | True Cybercrime Podcast, host Jeremy Ladner is joined by Vijay Balasubramaniyan, CEO and co-founder of Pindrop, the sponsor of this episode, to investigate how North Korea transformed the hiring process into a cyber weapon.Together they explore:• Why North Korea pursued legitimate employment instead of simply breaking into companies• How stolen identities and laptop farms sustained the deception• Why remote software engineering roles became the perfect target• What North Korea gained beyond employee salaries• How trusted insiders can bypass traditional security assumptions• Why MFA, endpoint security, and Zero Trust may begin too late• How deepfakes and generative AI are accelerating the threat• Why identity verification must begin before onboarding• What CISOs, security teams, and HR leaders can do to rebuild trust• How the phantom workforce is continuing to evolveBecause the next cyberattack may not begin with someone trying to break into your network...It may begin with someone applying for a job.________________________________________🎙 This episode is sponsored by Pindrop.Pindrop is an identity trust platform for the AI era, helping enterprises detect deepfakes and continuously verify identity across voice, video, and digital interactions.Powered by models trained on more than 5 billion real-world interactions and protected by more than 300 patents, Pindrop helps many of the world’s leading banks, insurers, healthcare providers, and other enterprises defend against AI-generated deception, identity fraud, and emerging threats to digital trust.🌐 https://www.pindrop.com________________________________________🎙 Guest Co-HostVijay BalasubramaniyanCEO & Co-Founder | PindropFor more than two decades, Vijay has focused on one of cybersecurity’s most important challenges: determining whether the person on the other end of an interaction is truly who they claim to be.As CEO and co-founder of Pindrop, Vijay leads the development of technology designed to detect AI-generated deception and establish identity across voice, video, and digital interactions. In 2026, TIME named Pindrop one of the world’s 10 Most Influential Software Companies.________________________________________🔎 Episode Topics:• North Korean IT workers• Phantom workforce• Fake remote employees• Christina Chapman• Laptop farms• Insider threats• Nation-state cyber operations• Deepfake job interviews• AI-generated identities• Voice cloning• Employment fraud• Identity verification• Remote hiring security• Zero Trust• Human identity assurance• CISO leadership• Artificial intelligence and cybersecurity• North Korean cybercrime• DPRK IT worker scheme• Enterprise identity security________________________________________ 🧩 The CISO Signal links:▶️ / @thecisosignal 💼 / the-ciso-signal 🌐 https://www.thecisosignal.com ________________________________________ 👥 Join the Conversation:Could a North Korean operative make it through your organization’s hiring process? And should identity verification continue after the interview and onboarding? Let us know what you think in the comments.________________________________________ #CISOSignal#NorthKorea #DPRK #PhantomWorkforce #InsiderThreat #IdentitySecurity #Deepfake #ArtificialIntelligence #RemoteWork #CyberSecurity #ZeroTrust#Pindrop #CISO #TrueCybercrime
    Afficher plus Afficher moins
    36 min
  • CDK Under Siege | The Cyberattack That Brought Car Sales to a Halt - The CISO Signal Episode 18
    Jul 30 2026

    On June 19, 2024, thousands of car dealerships across North America opened for what looked like an ordinary business day.
    The vehicles were on the lot.
    The sales teams were ready.
    The service bays were full.
    Then the software stopped working.
    Within hours, more than 15,000 dealerships lost access to the systems that powered nearly every part of their business: vehicle sales, financing, inventory, repair orders, customer records, payroll, and parts management.
    The target wasn't the dealerships.
    It was the company almost nobody had heard of...
    CDK Global.
    What followed wasn't simply another ransomware attack.
    It became a real-world demonstration of what happens when an entire industry becomes dependent on a single technology platform—and what happens when that platform suddenly disappears.

    In this episode of The CISO Signal | True Cybercrime Podcast, host Jeremy Ladner is joined by Benjamin Lipczynski, Director of Cybersecurity & Regulatory Services at Origina, the sponsor of this episode, and Christopher Russell, Chief Information Security Officer at tZERO Group, to investigate one of the largest supply-chain ransomware incidents ever to impact North American commerce.

    Together they explore:
    • Who BlackSuit really is and how modern ransomware groups operate
    • Why CDK became such an attractive target
    • How a single software platform became a single point of failure for an entire industry
    • Why attackers seek persistence long before they demand payment
    • The difficult decisions defenders face when shutting down critical systems
    • Why recovery is often far more difficult than the attack itself
    • The cybersecurity lessons every CISO should take from the CDK incident

    Because sometimes the biggest cyber attacks don't target thousands of companies...
    They target the one company that thousands of businesses depend on.
    ________________________________________
    🎙 This episode is sponsored by Origina.

    Modern enterprises often depend on mission-critical IBM, HCL, and VMware environments that simply can't afford unnecessary disruption. Origina helps organizations extend the life of these critical platforms through independent third-party software support and cybersecurity expertise, giving customers greater control over their infrastructure, reducing unnecessary vendor-driven upgrades, and helping IT and security leaders build resilient, long-term technology strategies.
    🌐 https://www.origina.com
    ________________________________________

    🎙 Guest Co-Hosts
    Benjamin Lipczynski
    Director, Cybersecurity & Regulatory Services | Origina
    Benjamin has more than 20 years of experience across defense, critical infrastructure, incident response, and cybersecurity strategy. At Origina, he works with enterprise security and IT leaders to reduce operational risk, strengthen resilience, and protect the mission-critical environments organizations depend on every day.

    Christopher Russell
    Chief Information Security Officer | tZERO Group
    Chris has spent more than two decades leading cybersecurity, intelligence, cloud security, and security operations across both military and commercial environments.
    ________________________________________
    🔎 Episode Topics
    • CDK Global ransomware attack
    • BlackSuit ransomware
    • Supply chain cyber attacks
    • Third-party risk
    • Single points of failure
    • Incident response
    • Business continuity
    • Disaster recovery
    • Enterprise resilience
    • Critical infrastructure
    • CISO leadership
    • Cyber resilience
    ________________________________________
    🧩 About The CISO Signal
    True cybercrime storytelling with real CISO lessons.
    ▶️ https://www.youtube.com/@TheCISOSignal
    💼 https://www.linkedin.com/company/the-ciso-signal
    🌐 https://www.thecisosignal.com
    ________________________________________
    👥 Join the Conversation
    At what point does operational efficiency become operational dependency?
    Can any organization justify relying on a single platform to run every critical business function?
    Let us know what you think in the comments.
    ________________________________________
    #CISOSignal #CDK #CDKGlobal #BlackSuit #Ransomware #CyberSecurity #SupplyChain #ThirdPartyRisk #IncidentResponse #BusinessContinuity #CyberResilience #CISO #TrueCybercrime

    Afficher plus Afficher moins
    42 min
adbl_web_anon_alc_button_suppression_t1
Aucun commentaire pour le moment