Podcast thumbnail for Security Bros

Security Bros

Claim This Podcast

by Security Bros

8 episodes
Updated Daily
Accepts GuestsHas Sponsors

Podcast Overview

<p>John and Rocky Giglio, brothers from the same mother share insights from their combined 50+ years of experience in the trenches of cyber, infrastructure, and consulting.</p>

Language

🇺🇲

Publishing Since

12/16/2025

1 verified contact email on file for Security Bros

Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.

Recent Episodes

Episode thumbnail for The Attacker Has 150 AI Agents. Your SOC Has...

June 19, 2026

The Attacker Has 150 AI Agents. Your SOC Has...

<p>The numbers don't lie: attackers can operationalize a zero-day exploit in 12 seconds. The average enterprise took 12 weeks to patch Log4Shell. That gap is the whole problem — and it's getting worse.</p><p></p><p>Rocky sits down with Nicolas Popp, a 30-year cybersecurity veteran who built WebObjects at Apple, launched MFA-as-a-service at VeriSign, and now backs the next generation of security companies at Crosspoint Capital. Nico has seen every major wave in this industry. His read on where we are right now: the asymmetry between AI-powered attackers and human-speed defenders has crossed a line that can't be uncrossed.</p><p></p><p>In this episode, they get into the mechanics of what an agentic SOC actually looks like — not the marketing version, the operational one. What does it mean to train AI on 10 years of SOC history? How do you govern agents that are making decisions at machine speed? What happens when your load balancer has a zero-day and there's no patch? And how should MSSPs rethink their entire service model before agents eat them alive?</p><p></p><p>This one gets into the weeds in the best way. If you're building, managing, or investing in security operations, this conversation is required listening.</p><p></p><p><b>Chapters:</b></p><pre><code>00:00 - Intro: Where's John? Meet Nico Popp 01:45 - 30 years in cyber: from Apple's WebObjects to building MFA-as-a-service 05:10 - The Google AI zero-day moment that changed everything 06:16 - Speed, scale, sophistication: the three vectors of AI-powered attacks 06:34 - Log4Shell took 12 weeks to patch. LLMs generate exploits in 12 seconds. 07:10 - "Joe the Hacker now looks like the Chinese net army" 09:02 - Why the SOC alert backlog problem just became an existential threat 10:57 - Agentic SOC in practice: what the orchestration layer actually does 12:50 - The trust problem: how you start the agentic transformation 13:24 - "We're trading salaries for tokens" — the real budget shift 14:29 - When attackers burn your AI budget on purpose 15:09 - Honeypots never worked. But the digital twin cyber gym might. 16:36 - Vekna and the idea of training your agents in a cyber gym before battle 18:41 - Agent orchestration: the general, the units, and who owns the layer 21:45 - Why operational memory makes agents 10x more valuable over time 23:13 - Advice for legacy vendors: you don't need to own the agentic layer 25:00 - VulnOps: the three-layer framework for closing the patch gap 26:38 - Where Nico would build a startup right now (DLP, CSPM, AppSec) 28:49 - AI, wealth concentration, and the social question nobody wants to answer 30:28 - The one-person unicorn: how many years until it happens? 33:13 - Identity Action Management: the governance problem nobody has solved 36:38 - Why the "governance harness" is replacing "sandbox" as the right frame 38:09 - Agentic VulnOps in action: patching, control reconfiguration, detection rules 43:59 - Third-party and legacy software: the attack surface you can't fix 46:22 - Zest Security: AI that generates the WAF rule and the Terraform code 49:12 - Slack as the audit trail for what your agents are doing 51:00 - How professional services firms need to become software companies 54:50 - Wrap-up and where to follow Nico on LinkedIn</code></pre>

Episode thumbnail for 62% of Cloud Breaches Are From Bugs You Already Know About (Here's the Fix)

June 1, 2026

62% of Cloud Breaches Are From Bugs You Already Know About (Here's the Fix)

<p>62% of cloud security incidents come from vulnerabilities your team already knew about. The problem isn't visibility. It's remediation. AI is changing that -- fast.</p><p>This week, Rocky and John sit down with Snir Ben Shimol, CEO of Zest Security, to break down why cloud vulnerability remediation is still one of the biggest unsolved problems in security and how autonomous AI agents are finally making it solvable. We cover the 30-to-90-day remediation window, why only 1-2% of vulnerabilities are actually exploitable in your environment, and how Zest's platform shrinks a backlog of 100,000 vulnerabilities by 70% in the first week -- without a single human in the loop.</p><p>If you're running a CSPM, drowning in vulnerability backlogs, or wondering what practical AI in security actually looks like (not just marketing slides), this episode is for you.</p><p></p><pre><code>Chapters 00:00 - Introduction and recording setup 02:00 - The 62%: cloud incidents from known, unfixed vulnerabilities 03:32 - Snir's background: Israeli intelligence, Cybereason CISO, acquisition by Palo Alto 03:41 - Setting the stage: CSPM, Wiz, Orca, Tenable, Qualys 04:23 - Visibility is solved. Remediation is the new bottleneck. 06:49 - The math doesn't work: 30-90 days to remediate vs. 24 hours to exploit 07:23 - SANS and CSA call for a VulnOps practice (end of 2024) 08:34 - What Zest's Cloud Risk Exposure Impact Report actually found 11:25 - Why remediation takes so long: CABs, testing cycles, approvals 13:05 - Is this a process problem, a tooling problem, or an architecture problem? 15:28 - Only 1-2% of vulnerabilities are actually exploitable in your environment 16:36 - Mythos, AI-powered zero-day discovery, and the changing threat landscape 19:08 - Will AI make the exploitable percentage grow? 21:53 - How Zest uses AI agents to attack the remediation gap 23:16 - Shrinking a 100,000-vulnerability backlog by 70% in one week 24:37 - Remediation simulation with digital twin technology 26:41 - 15 fixes to close 80-90% of your critical exposure 29:49 - Mitigating controls: what to do when you can't patch right now 35:24 - Real story: a supply chain attack (Aqua/Trivy) contained in under 6 hours 37:40 - Autonomous agents: what Zest announced at RSA 41:47 - The future: zero humans in the loop, self-healing production environments 45:43 - Measuring what matters: mean time to remediation, not mean time to ticket 46:02 - Where to find Zest Security and request a demo</code></pre><p>Links and Resources</p><pre><code>Zest Security (request a demo): https://zestsecurity.io Snir Ben Shimol on LinkedIn: https://www.linkedin.com/in/snirsbs/ Zest Cloud Risk Exposure Impact Report (the source of the 62% stat): https://zestsecurity.io Verizon Data Breach Investigations Report 2025: https://www.verizon.com/business/resources/reports/dbir/ Mandiant M-Trends 2025 Report: https://cloud.google.com/security/resources/m-trends SANS/CSA VulnOps guidance: https://www.sans.org Subscribe for new episodes every month covering cloud security, AI, and the tools actually being used in the field.</code></pre>

Episode thumbnail for AI Is a Weapon You Might Be Pointing at Yourself | OWASP Top 10 LLMs

May 12, 2026

AI Is a Weapon You Might Be Pointing at Yourself | OWASP Top 10 LLMs

<p>A lawyer submitted six court cases to a federal judge in New York.</p><p>ChatGPT wrote every single one of them. None of them existed.</p><p>When opposing counsel said they couldn't find the cases, the lawyer went back to ChatGPT to verify whether the cases were real. ChatGPT said yes. Absolutely. You can find them on Westlaw and LexisNexis.</p><p>He submitted them anyway — under oath.</p><p>That's hallucination. That's number nine on the OWASP Top 10 for LLM Applications. And it cost him $5,000, a formal apology to every federal judge whose name appeared in the fake rulings, and probably a lot more in embarrassment.</p><p>This week on Security Bros, Rocky and John Giglio go deep on the OWASP Top 10 for LLM Applications — the 2025 edition, built by 600+ researchers across 18 countries. If you're building with AI, deploying AI, or just using it every day at work, this list is the closest thing the security world has to a peer-reviewed warning label.</p><p>They break down all 10 vulnerabilities in plain English, connect each one to real stories, and don't sugarcoat any of it:</p><ul><li>A world-famous white hat hacker who jailbreaks ChatGPT to write his own attack tools</li><li>Samsung engineers who handed proprietary source code to ChatGPT — and how long it took after the ban was lifted for it to happen again (spoiler: 20 days, three incidents)</li><li>Air Canada's chatbot that gave a grieving customer wrong information about bereavement fares — and the company's legal defense that the chatbot was "a separate legal entity"</li><li>How DeepSeek may have reverse-engineered Claude's reasoning by querying it at scale — and what Anthropic is doing about it</li><li>The invisible text on a webpage that hijacks your AI agent without you ever knowing</li></ul><p>The lesson running through all of it: your security policy will never beat convenience without technical controls. You have to make the secure path the easy path.</p><p></p><p><b>Subscribe</b> so you don't miss the follow-up deep dives on Claude Cowork security, AI-ready DLP, and the excessive agency problem that's about to blow up as agentic AI goes mainstream.</p><hr /><p><b>Resources mentioned:</b></p><ul><li>OWASP Top 10 for LLM Applications: <a rel="noopener noreferrer nofollow" href="https://owasp.org/www-project-top-10-for-large-language-model-applications/" target="_blank">https://owasp.org/www-project-top-10-for-large-language-model-applications/</a></li><li>Previous episode: OWASP Top 10 for Web Applications<p><a rel="noopener noreferrer nofollow" href="https://youtu.be/oCuYgphY6iY" target="_blank">https://youtu.be/oCuYgphY6iY</a></p></li></ul><p></p><p>00:00 The Lawyer Who Asked AI If AI Was Lying to Him</p><p>00:33 Meet the Security Bros + What We're Covering Today</p><p>01:41 What Is OWASP? (600 Researchers, 18 Countries, One List)</p><p>04:38 #1 Prompt Injection — The Attack That's Everywhere Right Now</p><p>07:28 #2 Sensitive Information Disclosure — You Think It's Private. It's Not.</p><p>08:29 #3 Supply Chain Risk — What's Really Inside That Open Source Model?</p><p>10:27 #4 Data &amp; Model Poisoning — The Sleeper Agent Attack</p><p>13:31 #5 Output Handling — Nobody Reviews AI Code. Nobody.</p><p>14:05 #6 Excessive Agency — When Your AI Has Too Much Power</p><p>18:12 #7 System Prompt Leakage — Stop Putting Secrets in the Instructions</p><p>20:37 #8 Vector &amp; Embedding Weaknesses — How RAG Gets Poisoned</p><p>23:30 #9 Hallucination — AI Makes Things Up. Confidently.</p><p>25:58 #10 Unbounded Consumption — How DeepSeek May Have Stolen Claude's Brain</p><p>29:59 Real Story: Samsung's 3 Data Leaks in 20 Days</p><p>36:03 Real Story: Air Canada's "Separate Legal Entity" Defense</p><p>40:30 Real Story: The $5K Fine &amp; Apology Letters to Federal Judges</p><p>45:09 Key Takeaways — Make the Secure Path the Easy Path</p>

8 total episodes available

Deep-dive analytics for Security Bros

Frequently asked questions

Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.

What is Security Bros?
<p>John and Rocky Giglio, brothers from the same mother share insights from their combined 50+ years of experience in the trenches of cyber, infrastructure, and consulting.</p>
How often does this podcast release new episodes?

This podcast updates daily.

Where can I listen to this podcast?

This podcast is available on 4 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.

Does this podcast accept guests?

Yes, this podcast regularly features guests.

Legal Disclaimer

Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.

All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.

We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.

While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.

By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.