Sign in

CISO Series

@cisoseries.com
220 followers 172 following 390 posts

CISO Series is a media network for cybersecurity professionals, delivering the most fun you’ll have in cybersecurity. Home of the podcasts Defense in Depth, Cyber Security Headlines, and the CISO Series Podcast. cisoseries.com

PostsRepliesMedia
CISO Series @cisoseries.com · 2h
Department of Know: October 16, 2026 www.youtube.com/watch?v=O5isRkel7Bg
youtube.com
Department of Know: October 16, 2026
Join us next time, at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you've already been having at work all week long. This week, we're joined by Dennis Pickett, vp, CISO, RTI International and David Cross, CISO, Atlassian. Big thanks to our sponsor, Guardsquare! #news #cybersecuritynews #cybersecurity #infosec #informationsecurity
000
CISO Series @cisoseries.com · 7h
Will data centers force a protocol shift? www.youtube.com/watch?v=oQHzTdNsiMc
youtube.com
Will data centers force a protocol shift?
Stanford Professor John Ousterhout is advocating for Homa, an alternative transport protocol to TCP, arguing it is better suited for AI-era data centers. Unlike TCP's streaming model, Homa is message-based, places congestion management on the receiver side, and claims latency reductions of up to 13 times compared to TCP. The protocol is still in early stages, with IETF standardization not yet under review, though back ports are beginning to appear in some Linux distributions. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Vanta.
000
CISO Series @cisoseries.com · 7h
Why File Permissions and ACL Inheritance Still Break Data Security with ThreatLocker www.youtube.com/watch?v=b5ZPH7OsNFQ
youtube.com
Why File Permissions and ACL Inheritance Still Break Data Security with ThreatLocker
Granting a visitor access to just one or two folders shouldn't mean hours of rewriting ACLs across every file in your environment. Avi Solomon, a ThreatLocker customer who works closely with law firms, explains how ThreatLocker's storage control lets him lock a guest down to exactly what they need with two simple rules, without touching file-level permissions. He also shares how the unified audit log speeds up troubleshooting, and how two years in, he's using features he never planned for when he first deployed. A practical look at file security management and data access control for organizations handling sensitive information. Presented by CISO Series. An AI-generated attack may be new, but it still needs to execute, access data, and move through your environment. ThreatLocker applies enforceable controls at each of those points, limiting what attackers can do regardless of how their code was created. Book a demo at threatlocker.com/ciso.
000
CISO Series @cisoseries.com · 12h
Data Is the New Oil, in That It's Useless Until You Refine It www.youtube.com/watch?v=7ZVwVYljtpg
youtube.com
Data Is the New Oil, in That It's Useless Until You Refine It
All links and images can be found on CISO Series (https://cisoseries.com/data-is-the-new-oil-in-that-its-useless-until-you-refine-it/) This week's episode is hosted by me, David Spark (https://www.linkedin.com/in/davidspark/) , producer of CISO Series and Andy Ellis (https://www.linkedin.com/in/csoandy/) , principal of Duha. Joining us is Jake Lorz (https://www.linkedin.com/in/jacob-lorz/) , vp information technology and CISO, Cintas (https://www.cintas.com/) . In this episode: • Security's identity crisis • The AI that never has a bad day • Your permissions have secrets • Nobody wrote it down A huge thanks to our sponsor, ThreatLocker (https://www.threatlocker.com/ciso?utm_source=ciso-series&utm_medium=sponsor&utm_campaign=ai-cant-stop-ai_q3_26&utm_content=ai-cant-stop-ai-&utm_term=podcast) An AI-generated attack may be new, but it still needs to execute, access data, and move through your environment. ThreatLocker applies enforceable controls at each of those points, limiting what attackers can do regardless of how their code was created. Book a demo at threatlocker.com/ciso (http://threatlocker.com/ciso) .
010
CISO Series @cisoseries.com · 12h
Google pauses bug bounties, ATB faces extortion, Exchange flaw exposes mailboxes www.youtube.com/watch?v=rPPaXSR7V0I
youtube.com
Google pauses bug bounties, ATB faces extortion, Exchange flaw exposes mailboxes
Google pauses open-source bug bounties amid AI spam Ukraine's largest grocery chain hit by extortion attack Exchange flaw exposes other users' mailboxes Get the show notes here: https://cisoseries.com/cybersecurity-news-october-6-2026/ Huge thanks to our sponsor, Vanta (http://vanta.com/ciso) Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's (http://vanta.com/ciso) automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso (http://vanta.com/ciso) .
000
CISO Series @cisoseries.com · 05/10/2026
Journalistic sources exposed in breach www.youtube.com/watch?v=gQKopqU7HIo
youtube.com
Journalistic sources exposed in breach
Japanese media giant Nikkei, owner of the Financial Times, disclosed two email breaches over the weekend. A compromised Google Workspace account accessed since July exposed information on roughly 1,600 business partners and employees, while a separate Microsoft 365 account compromise was used to send over 9,000 phishing messages to recipients inside and outside the company, including journalistic sources. Nikkei reset the affected account and contacted recipients of the phishing messages. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Vanta.
000
CISO Series @cisoseries.com · 05/10/2026
Proving Readiness with TryHackMe www.youtube.com/watch?v=bU39VVJFWJ4
youtube.com
Proving Readiness with TryHackMe
In this episode, Ashu Savani (https://www.linkedin.com/in/ashu-savani/) , co-founder of TryHackMe (https://tryhackme.com/) , explains how the company's Live Breach product puts teams inside fully-executed, realistic breach simulations built around the threat actors and tech stacks they face, building the reflexes and reporting security leaders need before a real incident hits. Joining him are Roland Toussaint (https://www.linkedin.com/in/roland-t-b7171511/) , Senior Director of Incident Response and Security Engineering at ChenMed (https://www.chenmed.com/) , and Heather Hinton (https://www.linkedin.com/in/heather-hinton-9731911/) , CISO at Sitecore (https://www.sitecore.com/) . Want to know: • How can a simulated environment realistically reflect a security team's actual tech stack and the threat actors they care about? • Can TryHackMe's reporting help security leaders prove upskilling progress to auditors and cyber insurance carriers? • How does TryHackMe help teams train for incidents caused by their own people, not just outside attackers? • How granular can training get: can a team run a meaningful exercise in just 15 to 20 minutes? • How are TryHackMe's custom exercises tiered and packaged across its plans? • What's TryHackMe's track record getting cyber insurance carriers to accept its exercises as sufficient proof of readiness? • Does TryHackMe offer anything built specifically around HIPAA for healthcare organizations? • Why is crisis communication often more under-rehearsed than technical response, and how does TryHackMe help teams practice it? Check out the episode for the answers you need. Huge thanks to our sponsor, TryHackMe
010
CISO Series @cisoseries.com · 05/10/2026
Warlock continues SharePoint exploits, ShinyHunters member flips China's AI espionage www.youtube.com/watch?v=ZNB8EM5zRPE
youtube.com
Warlock continues SharePoint exploits, ShinyHunters member flips China's AI espionage
Warlock ransomware continues to exploit year-old SharePoint flaws ShinyHunters member detained in Jordan China-aligned espionage group targets American AI policy experts Get the show notes here: https://cisoseries.com/cybersecurity-news-warlock-continues-sharepoint-exploits-shinyhunters-member-flips-chinas-ai-espionage/ Huge thanks to our sponsor, Vanta (http://vanta.com/ciso) Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's (http://vanta.com/ciso) automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso (http://vanta.com/ciso) .
100
CISO Series @cisoseries.com · 03/10/2026
The Department of Know: ShinyHunters vs FBI, Kiteworks shutdown, and hundreds of orgs hit by rogu... www.youtube.com/watch?v=Iay3FpLCLXI
youtube.com
The Department of Know: ShinyHunters vs FBI, Kiteworks shutdown, and hundreds of orgs hit by rogu...
Read all the stories at CISOSeries.com (https://cisoseries.com/the-department-of-know-shinyhunters-vs-fbi-kiteworks-shutdown-and-hundreds-of-orgs-hit-by-rogue-ai/) . This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon (https://www.linkedin.com/in/brettconlon/) , CISO, American Century Investments (https://www.americancentury.com/home/) , and Nick Espinosa (https://www.linkedin.com/in/nickespinosa/) , host, Deep Dive Radio Show (https://podcasts.apple.com/us/podcast/the-deep-dive-radio-show-and-nicks-nerd-news/id1262505658) . Missed the live show? Check it out on YouTube. (https://youtube.com/live/nYDGmB7Luvs?feature=share) The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com (https://cisoseries.com/) . Big thanks to our sponsor, Intezer. (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) If you caught our tips this week, they pointed one direction: investigate everything, and keep the evidence. That's a hard promise to make with people. It's an easy one to make with forensics that run in under a minute. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines (http://intezer.com/headlines) .
000
CISO Series @cisoseries.com · 02/10/2026
OpenAI agents hacked hundreds www.youtube.com/watch?v=wCBunrMlJT4
youtube.com
OpenAI agents hacked hundreds
OpenAI has reportedly contacted more than one hundred organizations about unauthorized access tied to rogue agent activity, according to sources cited by Reuters. The company said it is working through roughly fifty petabytes of data to determine the full extent of the agent behavior and its impact. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Intezer.
000
CISO Series @cisoseries.com · 02/10/2026
"Hacking Your Career Growth Mistakes" - Super Cyber Friday www.youtube.com/watch?v=qsqt2Cp4CjA
youtube.com
"Hacking Your Career Growth Mistakes" - Super Cyber Friday
Join us live on Crowdcast: https://www.crowdcast.io/c/hacking-your-career-growth-mistakes
000
CISO Series @cisoseries.com · 02/10/2026
AI readiness reports, KillSec takedown, OpenAI website scraping www.youtube.com/watch?v=4iY0LTHC-jc
youtube.com
AI readiness reports, KillSec takedown, OpenAI website scraping
Report suggests AI and quantum threat preparedness is lacking Authorities seize KillSec extortion group arrest leader Dozens more prominent websites scraped by OpenAI software Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-readiness-reports-killsec-takedown-openai-website-scraping/ Huge thanks to our episode sponsor, Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) Today's tip: treat every false positive like a bug report against a detection rule. Fix the rule, and that noise stops coming back. Intezer does that for you, so your SOC gets quieter over time instead of louder. Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) . The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) .
010
CISO Series @cisoseries.com · 01/10/2026
Chinese AI catching up on bad behavior www.youtube.com/watch?v=lcQd48wJr8U
youtube.com
Chinese AI catching up on bad behavior
Research reviewed by Reuters found that Chinese open-weight AI models, including DeepSeek and Moonshot, exhibited deceptive and guardrail-challenging behaviors across at least 20 evaluations since 2025. In one case, agents lied about their capabilities during a simulated business bid and persisted in the deception when retested. The observed behaviors were confined to simulations and testing environments, with no evidence of the models escaping to the open internet or evading shutdown. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Intezer.
000
CISO Series @cisoseries.com · 01/10/2026
Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware www.youtube.com/watch?v=vcRsbcYCMNc
youtube.com
Gemini 4 enters the ring, MI5 flags research ties, Custom GPTs deliver malware
Gemini 4 starts with cybersecurity MI5 flags Chinese research funding Custom GPTs steer users into ClickFix attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-october-1-2026/ Huge thanks to our episode sponsor, Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) Today's tip: add up the hours your tier-one analysts spent closing alerts that turned out to be nothing. That's your real triage cost. At a hundred and fifty enterprises, that work isn't done by hand. Intezer investigates every alert. Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) . The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) .
000
CISO Series @cisoseries.com · 01/10/2026
Why Do We Keep Complaining About the Same Issues in Cybersecurity? www.youtube.com/watch?v=F3XW87vWX30
youtube.com
Why Do We Keep Complaining About the Same Issues in Cybersecurity?
All links and images can be found on CISO Series (https://cisoseries.com/why-do-we-keep-complaining-about-the-same-things/) LinkedIn used to have a decent reputation among cybersecurity professionals. But lately, it feels like our feeds are relitigating the same debates every day, just with different faces. Has the situation changed? Check out this post (https://www.linkedin.com/feed/update/urn:li:activity:7441840456977711105/) by Allan Alford of NTT Global Data Centers for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark (https://www.linkedin.com/in/davidspark/) , the producer of CISO Series (https://cisoseries.com/) , and Geoff Belknap (https://www.linkedin.com/in/geoffbelknap/) . Joining us is Howard Holton (https://www.linkedin.com/in/howardholton/) , founder, Phronia Counsel (https://www.phronia.co/) . In this episode: • The clichés that say nothing • A discipline without shared answers • Old topics, new lenses • A people problem, not a security problem A huge thanks to our sponsor, Teleskope (https://www.teleskope.ai/?utm_source=defense_in_depth&utm_medium=podcast&utm_campaign=ceo_podcast_june2026) Most DSPMs stop at finding the risk. Teleskope fixes this: it automatically finds sensitive data, including IP documents or board decks, and remediates exposure across cloud, SaaS, and AI environments natively, with human-in-the-loop controls, improving your team's efficiency tenfold. Trusted by Ramp, Polymarket, and Chevron Phillips, and more. teleskope.ai (http://teleskope.ai/)
000
CISO Series @cisoseries.com · 01/10/2026
GitLab's Email Is a Skeleton Key? www.youtube.com/watch?v=sS1mgU1INgg
youtube.com
GitLab's Email Is a Skeleton Key?
GitLab's private issue-email address hides a non-expiring, account-wide token that bypasses IP restrictions and two-factor authentication, as discovered by Aikido Security. The panel does not hold back in their response. Dmitriy Sokolovskiy makes the case for treating it as part of your non-human identity program while Christian Frösch flags the configuration drift risk, and Rich lands the perfect "secure by design" punchline. Is there a token like this lurking in your environment right now? Big thanks to our sponsor, Nudge Security! Join us next time — LIVE every Friday at 4 PM ET / 1 PM PT: https://youtube.com/live/nYDGmB7Luvs?feature=share #cybersecurity #cybersecuritynews #infosec #news #informationsecurity
011
CISO Series @cisoseries.com · 01/10/2026
ShinyHunters backs off of the FBI www.youtube.com/watch?v=qe9HL2JE6Y4
youtube.com
ShinyHunters backs off of the FBI
The threat group ShinyHunters circulated a list of approximately 5,000 FBI employees, presenting it as proof of a larger multi-terabyte theft of agency data. The move appeared to be an extortion attempt aimed at pressuring the FBI to rescind a report stating the group had exaggerated its data theft claims to victims in order to encourage payment. A ShinyHunters representative later walked back the rhetoric in comments to 404 Media, claiming the group never intended to release the data and describing the effort as a marketing campaign rather than extortion. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Intezer.
000
CISO Series @cisoseries.com · 30/09/2026
What's a Red Flag When Evaluating a Security Vendor? www.youtube.com/watch?v=_Q62fnpvW_Y
youtube.com
What's a Red Flag When Evaluating a Security Vendor?
Red flag: A company nobody has heard of says it is the world's leading something. At Black Hat 2026, David Spark asked security practitioners a simple question: what's a red flag when you're evaluating a security vendor? Answers included salespeople who can't explain their own technology, the "technical guy" who never follows up, reps who stick to a script instead of listening, and absolute promises like "we take care of everything." It's a candid look at what earns trust from buyers, and what gets you shown the door. Thanks to our sponsor, ThreatDown. ThreatDown delivers elite Managed Detection and Response purpose-built for resource-constrained teams with high-efficacy protection without complexity. Combining artificial intelligence and expert analyst judgment, ThreatDown intercepts sophisticated attacks with speed and accuracy, scaling security effortlessly. Recognized by MRG Effitas, AVLab, and G2, ditch fragmented tools for fast, 24/7 protection without overhead.
000
CISO Series @cisoseries.com · 30/09/2026
Star Blizzard, Cloudflare CA, GPT-6.1 scuttled www.youtube.com/watch?v=g8yneCRQG8A
youtube.com
Star Blizzard, Cloudflare CA, GPT-6.1 scuttled
Microsoft details new Star Blizzard and NeedyMantis activity Cloudflare to become a public certificate authority Safety concerns scuttle GPT-6.1 Get the show notes here: https://cisoseries.com/cybersecurity-news-star-blizzard-cloudflare-ca-gpt-6-1-scuttled/ Huge thanks to our episode sponsor, Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) Today's tip: when an AI calls an alert benign, ask for the evidence. The file, the memory, the command line. If it can't show its work, it's guessing. Intezer shows its work, and your team can argue with it. Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) . The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) .
000
CISO Series @cisoseries.com · 30/09/2026
What's a Red Flag When Evaluating a Security Vendor? www.youtube.com/watch?v=Ejkv9IkGr0w
youtube.com
What's a Red Flag When Evaluating a Security Vendor?
Red flag: A company nobody has heard of says it is the world's leading something. At Black Hat 2026, David Spark asked security practitioners a simple question: what's a red flag when you're evaluating a security vendor? Answers included salespeople who can't explain their own technology, the "technical guy" who never follows up, reps who stick to a script instead of listening, and absolute promises like "we take care of everything." It's a candid look at what earns trust from buyers, and what gets you shown the door. Thanks to our sponsor, ThreatDown. https://www.threatdown.com/products/managed-detection-and-response/?utm_medium=referral&utm_source=ciso&utm_content=independent_video ThreatDown delivers elite Managed Detection and Response purpose-built for resource-constrained teams with high-efficacy protection without complexity. Combining artificial intelligence and expert analyst judgment, ThreatDown intercepts sophisticated attacks with speed and accuracy, scaling security effortlessly. Recognized by MRG Effitas, AVLab, and G2, ditch fragmented tools for fast, 24/7 protection without overhead.
000
CISO Series @cisoseries.com · 30/09/2026
Entertaining enough that I learn www.youtube.com/watch?v=WtBvT_cfiV8
youtube.com
Entertaining enough that I learn
Amy Tom, community manager, at D3 Security, values CISO Series for the unfiltered practitioner perspective that pulls back the curtain on parts of cybersecurity beyond her day to day. Whether you are deep in the weeds or expanding your view, hearing directly from the people facing new attack vectors is how you stay sharp on what is actually happening in the field. Subscribe and stay ahead on the latest in cybersecurity with CISO Series: cisoseries.com/subscribe #CISOSeries #CISO #Cybersecurity #InfoSec #SecurityPractitioners
000
CISO Series @cisoseries.com · 29/09/2026
OpenAI's New AI Went Rogue in Hacking Tests www.youtube.com/watch?v=sfwd1RyYB6w
youtube.com
OpenAI's New AI Went Rogue in Hacking Tests
Testing by the AI Security Institute found that OpenAI's GPT-6 Astra was three to six times more likely than earlier GPT models to develop attacks, create fake identities, and deliver payloads against targets outside its sanctioned scope. The tests ran with Astra's cyber classifiers disabled in a simulated environment. Even with explicit scope limits in its prompts, the model still carried out an unsanctioned supply chain attack on an out-of-scope target. Subscribe for more cybersecurity news and stay up to date: CISOseries.com/subscribe Thanks to our video sponsor, Intezer. #cybersecurity #AIsecurity #OpenAI #infosec #AIsafety #cybersecuritynews
000
CISO Series @cisoseries.com · 29/09/2026
Mirror, Mirror on the Wall, Who Has the Best Infrastructure of Them All? www.youtube.com/watch?v=gDcSGtHyJGU
youtube.com
Mirror, Mirror on the Wall, Who Has the Best Infrastructure of Them All?
All links and images can be found on CISO Series (https://cisoseries.com/mirror-mirror-on-the-wall-who-has-the-best-infrastructure-of-them-all/) This week's episode is hosted by me, David Spark (https://www.linkedin.com/in/davidspark/) , the producer of CISO Series (https://cisoseries.com/) , and Geoff Belknap (https://www.linkedin.com/in/geoffbelknap/) . Joining us is our sponsored guest Ryan Lloyd (https://www.linkedin.com/in/ryanlloyd/) , chief product officer, GuardSquare (https://hubs.la/Q03_0XJK0) . In this episode: • Determinism was never the point • Every MCP server is an uncontracted vendor • Mobile security, the version everyone's tired of hearing • Architectural vanity A huge thanks to our sponsor, Guardsquare (https://hubs.la/Q03_0XJK0) Guardsquare delivers mobile app security without compromise, providing advanced protections for both Android and iOS apps. From app security testing to code hardening to real-time visibility into the threat landscape, Guardsquare solutions provide enhanced mobile application security from early in the development process through publication. Learn more about how to protect your app at Guardsquare.com (http://Guardsquare.com) .
010
CISO Series @cisoseries.com · 29/09/2026
GPT-6 Astra goes off script, ShinyHunters suspect arrested, Nvidia corrals rogue AI agents www.youtube.com/watch?v=V-zwKM97xeI
youtube.com
GPT-6 Astra goes off script, ShinyHunters suspect arrested, Nvidia corrals rogue AI agents
GPT-6 Astra goes off script in attack simulations Dutch police arrest "reformed" hacker in ShinyHunters probe Nvidia builds a browser for AI agents Get the show notes here: https://cisoseries.com/cybersecurity-news-september-29-2026/ Huge thanks to our episode sponsor, Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) Today's tip: time how long an employee-reported phish waits for a verdict. If it's a day, someone already clicked. Salesforce's incident response team got that down to minutes with Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) . At their size, one click is plenty. Intezer. The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) .
001
CISO Series @cisoseries.com · 28/09/2026
Department of Know: October 9, 2026 www.youtube.com/watch?v=t9nL7j8GXKs
youtube.com
Department of Know: October 9, 2026
Join us next time, at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you've already been having at work all week long. This week, we're joined by Julie Myerholtz, CISO, Brunswick Corporation and Derek Fisher, director of the cyber defense and information assurance program, Temple University. Big thanks to our sponsor, Vanta! #news #cybersecuritynews #cybersecurity #infosec #informationsecurity
000
CISO Series @cisoseries.com · 28/09/2026
Nvidia announces Open Agent Safety Platform www.youtube.com/watch?v=IZoorFYwFqM
youtube.com
Nvidia announces Open Agent Safety Platform
NVIDIA announced its Open Agent Safety Platform, a containment layer designed to restrict AI agents to only the tasks required for a given job, following a rise in incidents involving agents escaping testing sandboxes and reaching production systems. The platform includes NVIDIA Open Shell, which runs on CPUs to set limits on agentic capabilities, and Sentry, which runs on networking hardware to monitor agents. Launch partners include Cisco, Microsoft, Oracle, CoreWeave, Dell, HPE, Lenovo, Arm, and Intel. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Intezer.
000
CISO Series @cisoseries.com · 28/09/2026
New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage www.youtube.com/watch?v=ej-crqhJrxA
youtube.com
New SharePoint exploit, Australian OpenAI hack developments, Kiteworks urges stoppage
Another Microsoft SharePoint flaw now exploited Details and doubts emerge regarding OpenAI hack of Australian Health portal Kiteworks urges customers to stop using platform Get the show notes here: https://cisoseries.com/cybersecurity-news-new-sharepoint-exploit-australian-openai-hack-developments-kiteworks-urges-stoppage/ Huge thanks to our episode sponsor, Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) Today's tip: pull your low-severity alerts and count how many got opened. That's where attackers hide. Intezer investigates every alert, boring ones included, in under a minute. MGM Resorts' CTO has talked about nation-state threats turning up right there. Intezer (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) . The AI SOC trusted by Salesforce, MGM Resorts and Nvidia. See it yourself at intezer.com/headlines (https://intezer.com/headlines?utm_source=ciso+series&utm_medium=social) .
000
CISO Series @cisoseries.com · 28/09/2026
Bringing Privacy to AI Models with TrustedRouter www.youtube.com/watch?v=nN9nBuYsVbc
youtube.com
Bringing Privacy to AI Models with TrustedRouter
In this episode, Joseph Perla (https://www.linkedin.com/in/josephperla/) , founder and CEO at TrustedRouter (https://trustedrouter.com/?utm_source=creator&utm_medium=sponsorship&utm_campaign=ciso_series_202609&utm_content=ciso_series_privacy_with_proof) , explains how his company's confidential-computing-based LLM router lets teams send prompts to hundreds of AI models while cryptographically verifying, rather than simply trusting, that no one, including TrustedRouter itself, can see the data passing through. Joining him are TC Niedzialkowski (https://www.linkedin.com/in/tc-niedzialkowski/) , former head of IT & security at Opendoor, and Keith McCartney, (https://www.linkedin.com/in/keithmccartney/) svp of security and IT at DNAnexus (https://www.dnanexus.com/) . Want to know: • Why hasn't the AI privacy problem already been solved, given how many tools and architectures already exist? • What's wrong with the "zero data retention" promises most AI providers offer today? • How does a confidential virtual machine let a company verify, instead of just trust, that its own router isn't looking at its prompts? • For a use case like HIPAA-covered medical data, does TrustedRouter provide one complete, auditable path from a user's machine to the model and back? • How does remote attestation confirm end-to-end encryption down to the chip level? • Does TrustedRouter's SOC 2 Type 2 attestation cover the AI workload itself, or just its own SaaS interface? • Can customers restrict which data centers or jurisdictions their AI workloads run in? • What happens to a company's existing AI usage monitoring once it starts routing through TrustedRouter? Check out the episode for the answers you need. Huge thanks to our sponsor, TrustedRouter TrustedRouter (https://trustedrouter.com/?utm_source=creator&utm_medium=sponsorship&utm_campaign=ciso_series_202609&utm_content=ciso_series_privacy_with_proof) is the open-source AI gateway for teams that need privacy with proof. It routes hundreds of models through attested confidential compute, keeps prompts and outputs out of logs, verifies the code handling each request, and adds provider failover, spend controls, and OpenAI-compatible APIs for production AI systems.
001
CISO Series @cisoseries.com · 26/09/2026
The Department of Know: NCSC's AI "inconvenient truth," automated payment skimming, CISA's CVE plan www.youtube.com/watch?v=raxlMCh5BUs
youtube.com
The Department of Know: NCSC's AI "inconvenient truth," automated payment skimming, CISA's CVE plan
Read all the stories at CISOSeries.com (https://cisoseries.com/the-department-of-know-ncscs-ai-inconvenient-truth-automated-payment-skimming-cisas-cve-plan/) . This week's Department of Know is hosted by Rich Stroffolino, with guests Dmitriy Sokolovskiy (https://www.linkedin.com/in/dmitriy-sokolovskiy/) , senior vice president, information security, Semrush (https://www.semrush.com/) , and Christian Frösch (https://www.linkedin.com/in/christianfroesch/) , CISO, CH Media (https://chmedia.ch/) . Missed the live show? Check it out on YouTube. (https://youtube.com/live/k1Or1n1H0jQ?feature=share) The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com (https://cisoseries.com/) . Big thanks to our sponsor, Nudge Security. (https://www.nudgesecurity.com/try-nudge/lp-ai-agent-security?utm_medium=sponsored&utm_source=cisoseries&utm_content=podcast&utm_campaign=ai_security&utm_term=free-trial_ai-agent-discovery)) Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who created it, what it's connected to, and risks like destructive permissions. And, smart automation helps you engage the right person to fix the risk.
000
CISO Series @cisoseries.com · 25/09/2026
Can You Airgap an LLM? www.youtube.com/watch?v=H7AFU9A48DE
youtube.com
Can You Airgap an LLM?
Researchers are examining how to safely test AI systems and agents, including the use of air gaps to isolate them from networks. Experts note that air gapping reduces the realism of testing, since it does not resemble real networked environments, and warn that decades of research into defeating air gaps through lights, sounds, and electromagnetic emissions is data an LLM may have been trained on, potentially enabling an agent to bypass such isolation. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Nudge Security.
000
CISO Series @cisoseries.com · 25/09/2026
"Hacking Microsegmentation for Machine Workloads" - Super Cyber Friday www.youtube.com/watch?v=rmw6yHhx_-g
youtube.com
"Hacking Microsegmentation for Machine Workloads" - Super Cyber Friday
Join us live on Crowdcast: https://www.crowdcast.io/c/hacking-microsegmentation-for-machine-workloads
000
CISO Series @cisoseries.com · 25/09/2026
OpenAI hacks Australia health, Astrana Health breached, TeamCity flaw exploited www.youtube.com/watch?v=QDRz1oW7TVU
youtube.com
OpenAI hacks Australia health, Astrana Health breached, TeamCity flaw exploited
OpenAI program hacks Australia's government health portal Astrana Health suffers data breach Ransomware gangs exploiting TeamCity flaw Get the show notes here: https://cisoseries.com/cybersecurity-news-september-25-2026/ (https://cisoseries.com/cybersecurity-news-openai-hacks-australia-health-astrana-health-breached-teamcity-flaw-exploited/) Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries (http://nudgesecurity.com/cisoseries)
000
CISO Series @cisoseries.com · 24/09/2026
How ActiveState Is Taking Steps to Secure Software in the Age of AI www.youtube.com/watch?v=YpsHZxLnODM
youtube.com
How ActiveState Is Taking Steps to Secure Software in the Age of AI
ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time.
010
CISO Series @cisoseries.com · 24/09/2026
LLMs trained on ancient Greek www.youtube.com/watch?v=8Vt-b5Hwcio
youtube.com
LLMs trained on ancient Greek
The Austrian Academy of Sciences and AI lab Minstrel are developing a "vintage" large language model trained on roughly 600 million historical Greek words drawn from ancient inscriptions, manuscripts, and papyri. The model, which will be made freely available to academics through a chatbot, aims to speed the restoration of partial manuscripts by understanding historical Greek context and suggesting statistically probable words for missing text fragments. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Nudge Security.
000
CISO Series @cisoseries.com · 24/09/2026
Compliant But Still Insecure? www.youtube.com/watch?v=vUktw48RoaA
youtube.com
Compliant But Still Insecure?
A new Department of Transportation rule lets airlines skip meal vouchers and hotels if a cyberattack grounds you, as long as they were compliant with cybersecurity regulations. Big thanks to our sponsor, Vanta! Join us next time — LIVE every Friday at 4 PM ET / 1 PM PT: https://youtube.com/live/k1Or1n1H0jQ?feature=share #cybersecurity #cybersecuritynews #infosec #news #informationsecurity
000
CISO Series @cisoseries.com · 24/09/2026
ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon's cyber appetite g... www.youtube.com/watch?v=KBXnEZeaLq8
youtube.com
ShinyHunters peeks at FBI assignments, WordPress flaw wastes no time, Pentagon's cyber appetite g...
ShinyHunters peeks at FBI assignments WordPress flaw wastes no time Pentagon's cyber appetite grows Get the show notes here: https://cisoseries.com/cybersecurity-news-september-24-2026/ Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries (http://nudgesecurity.com/cisoseries)
000
CISO Series @cisoseries.com · 24/09/2026
Securing AI-Generated Open Source Code www.youtube.com/watch?v=Y9dY1vxHX0g
youtube.com
Securing AI-Generated Open Source Code
All links and images can be found on CISO Series (https://cisoseries.com/securing-ai-generated-open-source-code/) Check out this post (https://www.linkedin.com/posts/szalewski_looking-for-some-input-from-my-security-community-share-7483673156793290752-b2_b/?utm_source=share&utm_medium=member_desktop&rcm=ACoAABTPPZ4B1qQYPSxiaKsxlD-DogPwH6La93s) for the discussion that is the basis of our conversation on this week's episode co-hosted by me, David Spark (https://www.linkedin.com/in/davidspark/) , the producer of CISO Series (https://cisoseries.com/) , and Steve Zalewski (https://www.linkedin.com/in/szalewski/) . Joining us is our sponsored guest, Abby Kearns (https://www.linkedin.com/in/abbykearns/) , CEO, ActiveState (https://go.activestate.com/free-oss-health-check-ai-risk?utm_source=ciso%20series&utm_medium=banner_ad&utm_campaign=fy26_q2_comms&utm_content=paid_campaign) . In this episode: • Trust, but nobody verifies • The economics of trust just changed • Implicit trust doesn't scale anymore • Rethinking what "open" even means A huge thanks to our sponsor, ActiveState (https://go.activestate.com/free-oss-health-check-ai-risk?utm_source=ciso%20series&utm_medium=banner_ad&utm_campaign=fy26_q2_comms&utm_content=paid_campaign) ActiveState gives security and engineering teams a single governed source for open source software. With 79 million components built from source, continuously remediated, and delivered directly into the tools teams already use, ActiveState eliminates the CVE backlog and the developer toil that comes with it. Companies see a 60 to 99% reduction in CVEs and reclaim up to 30% of developer time. Learn more at activestate.com (https://go.activestate.com/free-oss-health-check-ai-risk?utm_source=ciso%20series&utm_medium=banner_ad&utm_campaign=fy26_q2_comms&utm_content=paid_campaign) .
000
CISO Series @cisoseries.com · 23/09/2026
Department of Know: October 2, 2026 www.youtube.com/watch?v=nYDGmB7Luvs
youtube.com
Department of Know: October 2, 2026
Join us next time, at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you've already been having at work all week long.   This week, we're joined by Brett Conlon, CISO, American Century Investments, and Dan Holden, CISO, Commerce. Big thanks to our sponsor, Intezer!   #news #cybersecuritynews #cybersecurity #infosec #informationsecurity
000
CISO Series @cisoseries.com · 23/09/2026
Patch Tuesday breaks Always On VPN www.youtube.com/watch?v=0GjOuNLaD5o
youtube.com
Patch Tuesday breaks Always On VPN
Microsoft's September 2026 Patch Tuesday introduced more than 1,000 bug fixes but failed to address its Always On VPN remote access service, with the update reportedly causing connectivity issues. Microsoft has notified administrators of the disruption, and a fix is expected within days. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Nudge Security.
000
CISO Series @cisoseries.com · 23/09/2026
How Would You Get a Job in Cybersecurity Today? www.youtube.com/watch?v=AxQXT0Na0NQ
youtube.com
How Would You Get a Job in Cybersecurity Today?
Breaking into cybersecurity used to have a clear first step. At Black Hat 2026, David Spark asked a range of seasoned professionals a simple question: if you had to break in today, how would you do it? Answers varied from building a home lab and attacking it, breaking things and then fixing them, working the help desk, finding mentors, and building a public portfolio. It’s great career advice for anyone trying to start or restart in security in the AI era. Do you have questions about leveling up your career? Coming up on the CISO Series, we'll be hosting an AMA (Ask me anything), on Reddit's r/cybersecurity, on exactly this topic: "I’m a CISO who’s built many security teams. I want to help you level up your career. Ask me anything." Bring questions for our panel of expert guests starting Sunday September 27th. Then, join us LIVE for Super Cyber Friday, on October 2nd. The topic is "Hacking Your Career Growth Mistakes: An hour of critical thinking about learning from the past to build your cybersecurity future." Presented by CISO Series. Thanks to our sponsor, Zero Networks.
000
CISO Series @cisoseries.com · 23/09/2026
How Would You Get a Job in Cybersecurity Today? www.youtube.com/watch?v=YwG0WmK6Tv4
youtube.com
How Would You Get a Job in Cybersecurity Today?
Breaking into cybersecurity used to have a clear first step. AI is eating up the entry-level jobs that used to be the way in. At Black Hat 2026, David Spark asked a range of seasoned professionals a deceptively simple question: if you had to break in today, how would you do it? Build a home lab and attack it, learn how things break and not just how they work, work the help desk, find mentors, and build a portfolio in public. Career advice for anyone trying to start or restart in security in the AI era. Presented by CISO Series. Thanks to our sponsor, Zero Networks.
000
CISO Series @cisoseries.com · 23/09/2026
CAIRN framework, Muse zero-day, BigDiskBuster www.youtube.com/watch?v=CmR0CBLPy5w
youtube.com
CAIRN framework, Muse zero-day, BigDiskBuster
Cisco releases open-source CAIRN framework Muse zero-day opens the door to account takeovers Microsoft can't wake up from Nightmare Eclipse Get the show notes here: https://cisoseries.com/cybersecurity-news-cairn-framework-muse-zero-day-bigdiskbuster/ Huge thanks to our episode sponsor, Nudge Security Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries (http://nudgesecurity.com/cisoseries)
000
CISO Series @cisoseries.com · 22/09/2026
AI breaks encryption... from WWI www.youtube.com/watch?v=Tk6pZYcBTLE
youtube.com
AI breaks encryption... from WWI
OpenAI's newly released GPT-6 Astra model reportedly cracked a German radio message from World War I that had been encoded using the ADFGVX cipher. The AI identified the keyword used for the encryption and produced a translation that naval logs from the period appear to corroborate. While large language models have found flaws in encryption schemes before, those cases were largely academic rather than involving production ciphers. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Nudge Security.
000
CISO Series @cisoseries.com · 22/09/2026
ShinyHunters hijacks Clop, fake LastPass kills security tools, trusted npm release carries malware www.youtube.com/watch?v=n9xY-KkaWMY
youtube.com
ShinyHunters hijacks Clop, fake LastPass kills security tools, trusted npm release carries malware
ShinyHunters hijacks Clop's own leak site Fake LastPass installers kill security tools Trusted npm release carries GHAPPIER malware Huge thanks to our episode sponsor, Nudge Security (http://nudgesecurity.com/cisoseries) Here's a question that might make you sweat…how many AI agents are running in your org right now? Not sure? You're not alone. But, we have good news. Nudge Security now includes AI Agent Discovery, in addition to Day One discovery of every other AI and SaaS app. For each agent, you'll see who built it, what it's connected to, and risks like destructive permissions. And, Nudge gives you smart automation to engage the right person to fix the risk. No chasing people down for answers. Give it a try for free at nudgesecurity.com/cisoseries (http://nudgesecurity.com/cisoseries) Get the show notes here: https://cisoseries.com/cybersecurity-news-september-22-2026/
000
CISO Series @cisoseries.com · 22/09/2026
Our AI Agents Are So Safe and Reliable You Can't Buy Insurance for Them www.youtube.com/watch?v=fwvhOuTTgLI
youtube.com
Our AI Agents Are So Safe and Reliable You Can't Buy Insurance for Them
All links and images can be found on CISO Series (https://cisoseries.com/our-ai-agents-are-so-safe-and-reliable-you-cant-buy-insurance-for-them/) This week's episode is hosted by me, David Spark (https://www.linkedin.com/in/davidspark/) , producer of CISO Series and Andy Ellis (https://www.linkedin.com/in/csoandy/) , principal of Duha. Joining us is Aaron Stanley (https://www.linkedin.com/in/aastanley/) , former vp of security, DBT Labs. In this episode: • Saying no just hides the agent • Communication is not a side project • Even OpenAI can't buy enough coverage • Identity governance beats the illusion of control A huge thanks to our sponsor, Arctic Wolf (http://arcticwolf.com/CISO) Security leaders need to reduce complexity, strengthen resilience, and prove value. Arctic Wolf's Security Operations ROI Calculator helps estimate operational value, potential risk exposure reduction, and projected payback based on your environment. See what a modern, AI-powered security operations model could mean for your business at arcticwolf.com/CISO (http://arcticwolf.com/CISO) today, right now.
000
CISO Series @cisoseries.com · 21/09/2026
cl0p site hacked by ShinyHunters www.youtube.com/watch?v=AQn1t8Td6WE
youtube.com
cl0p site hacked by ShinyHunters
The extortion group ShinyHunters has reportedly hijacked the leak site of the cl0p ransomware gang, demanding 2.333% of cl0p's net worth, estimated to be at least eight figures in US dollars, to return control. ShinyHunters is threatening to publish the names of cl0p victims who paid, along with amounts paid and Bitcoin addresses, and claims the action is a response to unauthorized use of the Oracle e-business suite vulnerability against one of its members. Subscribe for daily cybersecurity news: CISOseries.com/subscribe Thanks to our video sponsor, Nudge Security.
010
CISO Series @cisoseries.com · 21/09/2026
How to Re-Verify Your Entire Workforce Without Locking Them Out with Ping Identity www.youtube.com/watch?v=uOwtporzr4A
youtube.com
How to Re-Verify Your Entire Workforce Without Locking Them Out with Ping Identity
How do you re-verify thousands of employees are who they say they are, without freezing the whole company out of its own systems? At Ping YOUniverse, David Spark sat down with John Cannava, chief information officer of Ping Identity, to walk through a workforce-wide re-verification rollout and the choice at the heart of it: lock users out until they prove themselves, or run a "sidecar" verification alongside their normal work so access continues while identity gets confirmed. Big thanks to the sponsor of this video, Ping Identity At Ping Identity, we help organizations secure and manage digital identities across customers, employees, partners, and non-human entities. Whether securing millions of users, fighting fraud, simplifying third-party access, or enabling passwordless experiences, establishing trust in every digital moment shouldn't slow you down. Our enterprise identity platform is designed for scale, flexibility, and integration across cloud, hybrid, and on-prem environments. With our Runtime Identity capabilities, Ping enables organizations to adopt AI and automation by continuously verifying identity, context, and intent at every interaction, helping secure and govern AI agents in real time.
000
CISO Series @cisoseries.com · 21/09/2026
Simplifying MDR for SMBs with ThreatDown www.youtube.com/watch?v=bOgCSHapJ4E
youtube.com
Simplifying MDR for SMBs with ThreatDown
In this episode, Dean Shroll (https://www.linkedin.com/in/deanshroll/) , senior director of sales engineering at ThreatDown (https://threatdown.com) , explains how the company's Nebula and OneView consoles simplify protection across Mac, Linux, and Windows endpoints while its managed detection and response team absorbs the 24/7 monitoring that resource-constrained teams can't staff on their own. Joining him are Jonathan Waldrop (https://www.linkedin.com/in/jonathanwaldrop/) , CISO at Acoustic (https://www.acoustic.com/) , and Arif Hameed (https://www.linkedin.com/in/arif-hameed/) , CISO at C&R Software (https://www.crsoftware.com/) . Want to know: • Why is managing security for resource-constrained organizations suddenly getting more attention? • How does ThreatDown keep its console simple without sacrificing depth across Windows, Mac, Linux, and cloud environments? • Where does ThreatDown draw the line between what it automates and what still needs a human analyst? • How does the platform distinguish suspicious behavior from normal DevOps activity without drowning teams in false positives? • What guardrails exist to stop overly broad exclusions from opening up a device? • Who owns what when an MDR provider is involved, and where does that responsibility actually end? • How should a CISO justify an MDR investment to the board when nothing bad happens? Check out the episode for the answers you need. Huge thanks to our sponsor, ThreatDown ThreatDown (https://www.threatdown.com/products/managed-detection-and-response/?utm_medium=referral&utm_source=ciso&utm_content=security_you_should_know) delivers elite Managed Detection and Response purpose-built for resource-constrained teams with high-efficacy protection without complexity. Combining artificial intelligence and expert analyst judgment, ThreatDown intercepts sophisticated attacks with speed and accuracy, scaling security effortlessly. Recognized by MRG Effitas, AVLab, and G2, ditch fragmented tools for fast, 24/7 protection without overhead.
010
CISO Series @cisoseries.com · 21/09/2026
BONUS EPISODE: Super Cyber Friday Express - Hacking Vendor Selection www.youtube.com/watch?v=VrIe1c2IPyM
youtube.com
BONUS EPISODE: Super Cyber Friday Express - Hacking Vendor Selection
All links and images can be found on CISO Series (https://cisoseries.com/join-us-on-9-11-26-for-hacking-vendor-selection-super-cyber-friday/) This is a bonus episode of our brand new podcast, Super Cyber Friday Express — a 20-minute highlight version of our live one-hour show we do every available Friday at 1 p.m. Eastern. In this episode, David Spark is joined by Karl Mattson (https://www.linkedin.com/in/karlmattson1/) , founder and managing director of Squared Circle Ventures, and Howard Holton (https://www.linkedin.com/in/howardholton/) , founder and principal analyst at Phronia Counsel LLC, to discuss how your existing environment shapes what you buy next — and whether that's a strategy or just inertia. Watch the full one-hour show at Crowdcast (https://www.crowdcast.io/c/hacking-vendor-selection) . Subscribe to Super Cyber Friday Express, or any show on CISO Series, at CISOseries.com/subscribe (http://cisoseries.com/subscribe) .
000
CISO Series @cisoseries.com · 21/09/2026
BONUS EPISODE: Super Cyber Friday Express - Hacking Vendor Selection www.youtube.com/watch?v=H0rZ7OTtX4c
youtube.com
BONUS EPISODE: Super Cyber Friday Express - Hacking Vendor Selection
All links and images can be found on CISO Series (https://cisoseries.com/join-us-on-9-11-26-for-hacking-vendor-selection-super-cyber-friday/) This is a bonus episode of our brand new podcast, Super Cyber Friday Express — a 20-minute highlight version of our live one-hour show we do every available Friday at 1 p.m. Eastern. In this episode, David Spark is joined by Karl Mattson (https://www.linkedin.com/in/karlmattson1/) , founder and managing director of Squared Circle Ventures, and Howard Holton (https://www.linkedin.com/in/howardholton/) , founder and principal analyst at Phronia Counsel LLC, to discuss how your existing environment shapes what you buy next — and whether that's a strategy or just inertia. Watch the full one-hour show at Crowdcast (https://www.crowdcast.io/c/hacking-vendor-selection) . Subscribe to Super Cyber Friday Express, or any show on CISO Series, at CISOseries.com/subscribe (http://cisoseries.com/subscribe) .
000