Podcast thumbnail for Legitimate Cybersecurity Podcasts

Legitimate Cybersecurity Podcasts

Claim This Podcast

by LegitimateCybersecurity

5.0(2 reviews)
65 episodes
Updated Daily
Accepts GuestsHas SponsorsLocation 🇺🇸

Podcast Overview

Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.

Language

🇺🇲

Publishing Since

5/13/2025

Reach the team behind Legitimate Cybersecurity Podcasts

Verified contact details for this show aren't on file yet — sign up to get notified when they land.

Recent Episodes

Episode thumbnail for How Flock Cameras Track You (Even Without LAPD)

July 27, 2026

How Flock Cameras Track You (Even Without LAPD)

<p></p>

Episode thumbnail for Grok Build Uploaded Your Entire Codebase — Without Asking

July 20, 2026

Grok Build Uploaded Your Entire Codebase — Without Asking

Grok Build reportedly uploaded entire Git repositories—including files it never opened, full Git history, and deleted secrets—to xAI-controlled cloud storage.In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer unpack what that means for anyone allowing an AI coding agent inside a real computer.Independent researcher CerebLab captured Grok Build packaging a complete repository into a Git bundle and sending it to cloud storage after being explicitly told not to read any files. Turning off “Improve the model” did not stop the transfer in the researcher’s test.That does not prove xAI trained on the code. It exposes a different problem: “don’t train,” “don’t transmit,” and “don’t retain” are three very different promises.Frank and Dustin discuss:• Why deleted passwords and API keys can survive in Git history• How AI coding agents gain broad access to your computer• Why developers keep treating security as something to add later• The difference between a breach, a leak, and a breach of trust• Why old code can be more dangerous than current code• What developers should do now: rotate secrets, isolate projects, restrict permissions, and monitor unexpected outbound dataIMPORTANT UPDATE: CerebLab reports that whole-repository uploads later stopped after xAI enabled a server-side control. SpaceXAI also promised to delete previously retained coding data and subsequently open-sourced Grok Build. This episode examines the documented behavior before that change—and the trust problem it exposed.Research and updates:https://cereblab.com/https://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123Media/interview: mailto:admin@legitimatecybersecurity.comAudio podcast: https://legitimatecybersecurity.podbean.com/CHAPTERS00:00 — Grok Build reportedly uploaded whole repositories01:20 — Why Git repositories are a gold mine03:19 — Breach, leak, or breach of trust?04:23 — What AI coding agents actually do05:20 — Why old code still matters08:56 — Deleted passwords can survive in Git history10:41 — “Don’t train” vs. “don’t retain”12:30 — When an AI codes its own connector badly14:30 — What affected developers should do now16:38 — AI agents are becoming highly privileged19:31 — What system-level AI access can destroy21:26 — The network anomaly that exposed the upload22:19 — When bandwidth becomes a security signal23:43 — Patch quickly—without becoming CrowdStrike24:34 — The practical takeaway#Grok #GrokBuild #Cybersecurity #DataPrivacy #AICoding #VibeCoding #AIAgents #xAI #GitSecurity #SourceCode #ArtificialIntelligence #LegitimateCybersecurity

Episode thumbnail for Your Password Isn’t the Weakest Link Anymore

July 13, 2026

Your Password Isn’t the Weakest Link Anymore

Hackers no longer need to steal your password. Software vulnerabilities have overtaken stolen credentials as the leading way attackers break into breached organizations.According to Verizon’s 2026 Data Breach Investigations Report, exploitation of software flaws now accounts for 31% of breach entry points. After years of companies concentrating on phishing, password security, and employee training, attackers may have found an easier target: the software itself.Frank Downs and Dr. Dustin Brewer examine why critical vulnerabilities remain exposed for months—even when patches already exist—and how artificial intelligence is changing the speed at which attackers can discover and exploit security flaws.In this episode:• Why software vulnerabilities have overtaken stolen credentials• How AI helps attackers find exploitable flaws faster• Why companies delay installing critical security patches• What the MOVEit breach revealed about patching failures• Why old printers, servers, and business applications remain dangerous• How organizations test patches without breaking production systems• Why network segmentation often becomes cybersecurity duct tape• What vulnerability scanners can—and cannot—detect• How threat intelligence, SOC teams, and vulnerability management should work together• Why the National Vulnerability Database is struggling to keep pace• What organizations can realistically do to reduce their exposureThe warning is simple: your password can be perfectly secure, and an attacker may still find another way in.Media/interview: mailto:admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/CHAPTERS00:00 Hackers don’t need your password00:07 The new leading way attackers break in01:09 AI is finding software exploits faster02:19 MOVEit: The patch existed02:38 Why critical vulnerabilities remain exposed03:36 It is always the printer04:17 Is segmentation just security duct tape?05:00 Microsoft’s “keep an eye on it” solution05:50 Testing security patches on Timmy06:31 Making vulnerability management satisfying07:10 Excel formatting becomes a professional sport08:08 Scientists made brain cells play Doom10:10 The vulnerability-management maturity model11:38 Software is the weakest link again13:26 Can AI find unknown vulnerabilities?14:32 What AI can and cannot fix15:41 Why vulnerability scanners miss emerging threats18:14 Connecting SOC, threat intelligence, and vulnerability data18:52 Why cybersecurity remains a cost center20:01 The processes that can save an organization21:16 A high CVSS score is not everything21:40 Is the National Vulnerability Database falling behind?24:27 Why old vulnerabilities remain useful to hackers25:46 Your software is the new password#cybersecurity #hackers #databreach #SoftwareVulnerabilities #PasswordSecurity #ArtificialIntelligence #ZeroDay #PatchManagement #VulnerabilityManagement #VerizonDBIR

65 total episodes available

Deep-dive analytics for Legitimate Cybersecurity Podcasts

Frequently asked questions

Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.

What is Legitimate Cybersecurity Podcasts?

Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.

How often does this podcast release new episodes?

This podcast updates daily.

Where can I listen to this podcast?

This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.

Does this podcast accept guests?

Yes, this podcast regularly features guests.

Legal Disclaimer

Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.

All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.

We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.

While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.

By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.