Podcast thumbnail for Inside Cyber Minds

Inside Cyber Minds

Claim This Podcast

by Luciano Ferrari

14 episodes
Updated Daily
Accepts GuestsHas Sponsors

Podcast Overview

Step inside the minds of cybersecurity leaders. Hosted by Luciano Ferrari, Inside Cyber Minds explores how professionals in security think, lead, and keep learning in an industry that never slows down. Each episode dives into honest conversations about growth, imposter syndrome, leadership, and the human side of cybersecurity — reminding us that even the experts are still figuring it out. 🎙️ Part of the Lufsec Podcast series. 🧠 Conversations that shape security.

Language

🇺🇲

Publishing Since

11/5/2025

1 verified contact email on file for Inside Cyber Minds

Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.

Recent Episodes

Episode thumbnail for Inside Cyber Minds S2E8 — Katie Moussouris: Bug Bounties, Vulnerability Disclosure, Hacker Economics

July 30, 2026

Inside Cyber Minds S2E8 — Katie Moussouris: Bug Bounties, Vulnerability Disclosure, Hacker Economics

<p>🛡️ This episode is all about vulnerability disclosure, bug bounty programs, and working effectively with security researchers. To build practical offensive security skills, explore LufSec’s cybersecurity courses and hands-on training:👉 https://www.lufsec.com/courses/?utm_source=youtube&amp;utm_medium=onramp&amp;utm_campaign=career-guide-funnel&amp;utm_content=s2e8-course━━━━━━━━━━━━━━━━━━━━Season 2 of Inside Cyber Minds continues with Katie Moussouris — founder and CEO of Luta Security and one of the most influential leaders in vulnerability disclosure, bug bounty programs, and hacker economics.Katie has helped shape how major technology companies, governments, and global organizations work with security researchers. Her career includes launching vulnerability programs at Microsoft, contributing to the creation of Hack the Pentagon, and helping develop international standards for vulnerability disclosure and handling.Her core argument: launching a bug bounty program is not the same as building a mature vulnerability management capability. Organizations must first create the internal processes, resources, ownership, and remediation capacity required to receive and act on vulnerability reports.We discuss how organizations should work with hackers, why some bug bounty programs fail, and how leaders can determine whether their security teams are ready to engage with external researchers.Katie also explains the economics behind vulnerability research, how incentives influence researcher behavior, and why paying for vulnerabilities without fixing the underlying process can create more problems than value.We explore coordinated vulnerability disclosure, researcher relationships, government programs, liability protections, security maturity, and the difference between generating more vulnerability reports and actually reducing organizational risk.Katie also shares her perspective on the future of vulnerability research, how AI may affect bug discovery and exploitation, and what security leaders must understand before scaling a disclosure or bounty program.Topics CoveredKatie’s path into cybersecurity and vulnerability researchThe origins of modern bug bounty programsBuilding vulnerability disclosure programs at MicrosoftThe creation and impact of Hack the PentagonWhy bug bounty programs are not a shortcut to security maturityVulnerability disclosure versus vulnerability managementHow organizations should work with security researchersThe economics of vulnerabilities and hacker incentivesMeasuring the ROI of bug bounty programsCommon mistakes organizations make when launching programsCoordinated vulnerability disclosure and safe harborGovernment collaboration with ethical hackersPreparing internal teams to receive vulnerability reportsHow AI may change vulnerability discovery and exploitationThe future of bug bounties and security researchAbout Inside Cyber MindsA LufSec cybersecurity podcast featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, authors, and industry leaders about mindset, decisions, emerging threats, and the human side of cybersecurity.LinkedIn: https://www.linkedin.com/company/lufsec/Katie Moussouris and Luta SecurityWebsite:https://www.lutasecurity.com/X:https://x.com/LutaSecurityhttps://x.com/k8em0Bluesky:https://bsky.app/profile/lutasecurity.bsky.socialhttps://bsky.app/profile/k8em0.bsky.social#Cybersecurity #BugBounty #VulnerabilityDisclosure #EthicalHacking #HackerEconomics #KatieMoussouris #LutaSecurity #InsideCyberMinds</p>

Episode thumbnail for Inside Cyber Minds S2E7 — David Girvin: AI Agent Security, Runtime Governance & Future Attacks

July 22, 2026

Inside Cyber Minds S2E7 — David Girvin: AI Agent Security, Runtime Governance & Future Attacks

<p>Season 2 of Inside Cyber Minds continues with David Girvin — offensive security expert, cybersecurity leader, and founder of Honey Badger, focused on securing AI agents at the execution layer.After an injury forced him to leave welding, David discovered hacking and bug bounty programs. That curiosity became a career spanning offensive security, threat modeling, detection engineering, MDR, startup leadership, and AI security.His core argument: AI governance cannot stop at policies, model evaluations, or prompt filtering. As agents gain access to tools, credentials, data, and business processes, organizations need controls that govern what they can actually execute.We discuss adaptive agent governance, runtime enforcement, deterministic controls, and why securing thousands of autonomous agents requires a different security architecture.David also shares lessons from BitDiscovery, 1Password, Red Canary, and Sumo Logic, and explains how offensive security, leadership, detection engineering, and threat modeling shaped his approach.We explore how attackers may target AI agents, why prompt injection is not going away, how attacks could evolve, and which AI security failures may emerge over the next two years.David also predicts that by 2028, AI will handle more repetitive SOC analysis while humans focus on judgment, investigation, and complex decisions.Topics CoveredDavid’s journey from welding to offensive cybersecurityBug bounty programs and early hacksThreat modeling for AI agentsWhy traditional AI governance is not enoughAdaptive agent governance at the execution layerRuntime governance and deterministic controlsSecuring agents with access to tools, systems, and dataPrompt injection and future AI attack techniquesManaging thousands of autonomous agentsHow AI may reshape SOC roles by 2028Expected AI security failures over the next two yearsChapters00:00 Introduction to David Girvin and his background01:14 Early security experiences and breaking into cars02:04 Transition from welding to cybersecurity03:32 Discovering hacking and bug bounty programs04:28 Offensive security work and early hacks06:38 Understanding the defender’s perspective08:42 The impact of AI on cybersecurity10:41 Startup GTM lessons from BitDiscovery12:32 Leadership challenges at 1Password14:00 Threat modeling inside a large organization15:42 Detection engineering and MDR operations18:25 Lessons from Red Canary and Sumo Logic20:00 Founding Honey Badger and focusing on AI security22:15 Hacking agents and securing agent environments25:43 Adaptive agent governance explained36:14 AI governance and deterministic controls40:37 Scaling security across thousands of AI agents45:53 Future agent attack techniques and AI risks51:29 Why prompt injection remains a major threat53:33 Runtime governance and platform integrations58:24 How SOC analyst roles may evolve by 202801:02:46 Expected AI security failures over the next two years01:04:23 Closing remarksAbout Inside Cyber MindsA LufSec cybersecurity podcast featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, authors, and industry leaders about mindset, decisions, emerging threats, and the human side of cybersecurity.Watch &amp; Listen🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🍎 Apple: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640🎤 Amazon: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1LinkedIn: https://www.linkedin.com/company/lufsec/David Girvin: https://assury.ai/#Cybersecurity #AISecurity #AgentSecurity #PromptInjection #AIGovernance #OffensiveSecurity #DavidGirvin #InsideCyberMinds</p>

Episode thumbnail for Inside Cyber Minds S2E6 — Marcio Cots: AI Overtrust, Digital Governance & the $1 Car a Chatbot Sold

July 17, 2026

Inside Cyber Minds S2E6 — Marcio Cots: AI Overtrust, Digital Governance & the $1 Car a Chatbot Sold

🎯 Free Cyber Security Career GuideBreak into cybersecurity without wasting years on the wrong path — the roles, skills, certs, and the shortest route in:👉 https://www.lufsec.com/products/digital_downloads/cyber-security-career-guide?utm_source=youtube&amp;utm_medium=onramp&amp;utm_campaign=career-guide-funnel&amp;utm_content=s2e6🎓 Bonus: download the guide and unlock a free lesson from the LufSec course library.🤖 In this episode, Marcio tells the story of a chatbot that sold a car for $1 through prompt injection. Want to learn how those attacks actually work — and how to defend against them? My new course, Introduction to Prompt Hacking for LLMs, has 2 free lessons — no card, no signup:👉 https://www.lufsec.com/enroll/3577077?et=free_trial&amp;utm_source=youtube&amp;utm_medium=onramp&amp;utm_campaign=career-guide-funnel&amp;utm_content=s2e6-course━━━━━━━━━━━━━━━━━━━━Season 2 of Inside Cyber Minds continues with Marcio Cots — international technology and privacy lawyer, digital governance consultant at GetGlobal International / ethosfy, and professor of AI ethics at Atlantis University. Marcio took Harvard Law School&#39;s cyber law program in 2005 — before &quot;cyber law&quot; was even a category — and has spent two decades building privacy and AI governance programs across the US, Europe, and Latin America.His core warning: the biggest AI risk most organizations are underestimating isn&#39;t poor performance — it&#39;s OVERTRUST. As AI gets more accurate, oversight gets quieter. His analogy: using AI is like riding a motorcycle — useful and reliable, until you get confident enough to skip the procedures.We discuss the three dimensions of AI governance every company must manage (how you use AI, how you buy it, how you develop it), why governance starts with assessment rather than policy, pentest-style testing for privacy programs, and the global regulatory chessboard — the EU AI Act, Brazil&#39;s LGPD, the US patchwork, and China&#39;s pragmatic approach.We also talk about the AI Risk Inspector — the AI risk assessment tool built as a joint venture between LufSec and ethosfy, running 1,400+ automated tests to catch AI risks before production. LufSec leads technical development; ethosfy leads sales and marketing.And near the end, the story that says it all: a company&#39;s chatbot sold a brand-new car for one dollar — because of a prompt injection attack.Topics CoveredWhy AI overtrust is the most underestimated riskThe three dimensions of AI governance: use, procurement, development&quot;Privacy Proof&quot; — pentest-style testing for privacy programsAI Risk Inspector — the LufSec × ethosfy tool (1,400+ tests)EU AI Act, LGPD, US patchwork, and China&#39;s approachThe one rule Marcio would mandate: human supervisionThe $1 car — prompt injection in the wildAbout Inside Cyber MindsA cybersecurity podcast by LufSec featuring deep, unscripted conversations with hackers, CISOs, researchers, founders, authors, and industry leaders — mindset, decision-making, emerging threats, and the human side of cybersecurity.Watch &amp; Listen🎙️ Spotify: https://open.spotify.com/show/6hWg94SxRjHUMCMXoKutlc🍎 Apple: https://podcasts.apple.com/us/podcast/inside-cyber-minds/id1851011640🎤 Amazon: https://music.amazon.com/podcasts/87069409-9772-4c83-821a-d5607e52be51/inside-cyber-minds🎧 Audible: https://www.audible.com/podcast/Inside-Cyber-Minds/B0G15CT6R1LinkedIn: https://www.linkedin.com/company/lufsec/#Cybersecurity #AIGovernance #DataPrivacy #PromptInjection #ArtificialIntelligence #CyberLaw #MarcioCots #InsideCyberMinds</p>

14 total episodes available

Deep-dive analytics for Inside Cyber Minds

Frequently asked questions

Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.

What is Inside Cyber Minds?

Step inside the minds of cybersecurity leaders. Hosted by Luciano Ferrari, Inside Cyber Minds explores how professionals in security think, lead, and keep learning in an industry that never slows down.

Each episode dives into honest conversations about growth, imposter syndrome, leadership, and the human side of cybersecurity — reminding us that even the experts are still figuring it out.

🎙️ Part of the Lufsec Podcast series. 🧠 Conversations that shape security.

How often does this podcast release new episodes?

This podcast updates daily.

Where can I listen to this podcast?

This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.

Does this podcast accept guests?

Yes, this podcast regularly features guests.

Legal Disclaimer

Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.

All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.

We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.

While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.

By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.