Security Unfiltered

Joe South

Cyber Security can be a difficult field to not only understand but to also navigate. Joe South is here to help with over a decade of experience across several domains of security. With this podcast I hope to help more people get into IT and Cyber Security as well as discussing modern day Cyber Security topics you may find in the daily news. Come join us as we learn and grow together!

  1. 14 Sept

    100,000 OAuth Grants Later, Security Teams Still Can’t See the Risk

    Joe and Danielle discuss how AI has accelerated an already messy SaaS security problem, especially as employees connect more tools, more agents, and more data without centralized oversight. The conversation focuses on why traditional block or allow controls are breaking down, and how security teams can use agentic automation to reduce risk without slowing the business 00:00 - Why AI adoption is moving faster than cloud and SaaS ever did 01:20 - The professional pressure to skill up on AI now 03:19 - How cloud security and SaaS security lagged behind adoption 06:13 - Why organizations can’t simply say no to AI tools 08:30 - The difference between cloud-era experimentation and today’s browser-based AI 10:37 - Why AI security and SaaS security are becoming the same problem 12:31 - Why traditional onboarding and vendor review processes don’t scale 14:43 - The Salesforce example that exposed hidden risk in a large enterprise 17:00 - Why most third-party risk programs only cover part of the estate 19:07 - How decentralized tech adoption bypasses security workflows 20:31 - Why OAuth grants and third-party integrations are a major attack path 22:25 - Why attackers usually go after credentials and tokens, not zero days 23:19 - How AI lowers the barrier to entry for attackers 26:55 - Why defenders need agentic capabilities too 28:16 - The scale of unmanaged OAuth grants inside enterprises 30:26 - Why no one can hire enough people to review every grant manually 31:53 - How agents can analyze risk and recommend revocation at scale 33:33 - The reality check from customer conversations about AI visibility 35:24 - How security people think when told they can’t do something 38:16 - Reactance theory and why employees work around controls 40:25 - Incentives matter more than policy slogans 41:48 - Why binary block or allow controls create shadow IT 43:30 - How Nudge Security approaches SaaS and AI as one workforce problem 46:14 - Why a workforce edge model matters more than network or identity alone 48:26 - What just-in-time policy decisions could look like in the browser 50:10 - Why policy experience is as important as policy enforcement 52:08 - Danielle on Nudge Security’s free trial and LinkedIn presence Affiliates ➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh ➡️ OffGrid Coupon Code: JOE ➡️ Unplugged Phone: https://unplugged.com/ Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout *See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions. Tesla Referral Code: https://ts.la/joseph675128 Follow the Podcast on Social Media! Instagram: https://www.instagram.com/secunfpodcast/ Twitter: https://twitter.com/SecUnfPodcast

  2. 31 Aug

    The Real Innovation Wasn't Face Recognition - It Was Liveness

    Joe talks with Andrew Bud, founder of iProov, about how an engineer’s career across mobile communications, payments, and identity led to one of the early liveness technologies for secure remote authentication. The conversation ranges from entrepreneurship and resilience to deepfakes, digital identity wallets, and why proving a real human is present is becoming central to cybersecurity. 00:00 The Importance of Family and Presence 03:44 Andrew Bud's Journey in Technology 09:40 The Entrepreneurial Mindset and Necessity 15:28 Conviction vs. Delusion in Entrepreneurship 23:11 Innovating Trust: The Birth of iProve 27:55 Discovering the Core Problem 29:17 The Rise of Authentication Technology 30:26 Deepfakes and the Evolution of Threats 35:19 The Challenge of Deepfake Detection 38:56 Attribution and Accountability in the Digital Age 44:51 Identity as a Defense Mechanism 49:22 Cybersecurity and National Defense Affiliates ➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh ➡️ OffGrid Coupon Code: JOE ➡️ Unplugged Phone: https://unplugged.com/ Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout *See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions. Tesla Referral Code: https://ts.la/joseph675128 Follow the Podcast on Social Media! Instagram: https://www.instagram.com/secunfpodcast/ Twitter: https://twitter.com/SecUnfPodcast

  3. 24 Aug

    The Real Reason Iran, Iraq, and America Keep Colliding

    The conversation covers Mark's journey to the CIA, his language training, overseas assignments, and the challenges and unpredictability of his career. Mark shares insights into the preparation, language proficiency, and stress associated with overseas assignments, as well as the different roles and responsibilities within the CIA. The conversation delves into the impact of language training on CIA officers, the challenges of post-9/11 operations, the Iraq war and WMDs, and the historical context of Iran's relations with global powers. The discussion provides insights into the complexities of intelligence operations and geopolitical dynamics. The conversation delves into the history of Iran, focusing on the rise and fall of the Shahs and the country's pursuit of nuclear weapons. It explores the Shah's attempts to modernize Iran, the overthrow of Mossadegh, and the impact of the Iran-Iraq war. Additionally, it discusses the development of Iran's nuclear program and the decision-making process behind Iran's nuclear ambitions. Takeaways Language training is a crucial part of CIA preparationOverseas assignments require extensive preparation and adaptation to real-time language use Language training is crucial for CIA officersPost-9/11 operations reshaped CIA priorities and focusThe Iraq war and WMDs had significant intelligence implicationsIran's historical context shapes its relations with global powers The complex history of Iran's political landscape and the role of the Shahs in modernizing the country.The motivations and implications of Iran's pursuit of nuclear weapons and the challenges it presents to global security. Chapters 00:00 Introduction and Background01:00 Journey to the Agency03:10 Applying to the Agency04:04 Joining the Agency05:16 Challenges and Qualifications06:09 Language Training and Assignments07:26 Specializing in Farsi08:36 Roles in the CIA09:23 Senior Roles and Responsibilities10:20 Career Impact and Unpredictability11:08 Preparation for Overseas Assignments12:05 Language Training and Deployment13:45 Preparation for Denied Areas14:14 Cover and Role Preparation16:00 Language Learning and Proficiency17:17 Adapting to Real-Time Language Use18:14 Language Training and Stress19:30 Preparation for Overseas Assignments21:16 Language Training and Deployment22:50 Language Requirements for Different Countries24:26 Preparation for Overseas Assignments25:43 Language Training for Denied Areas26:58 Preparation for Overseas Assignments28:17 Language Proficiency and Role29:07 Adapting to Real-Time Language Use30:39 Language Learning and Proficiency31:57 Language Training and Adaptation36:00 Post 9/11 Operations and Iraq40:21 Impact of 9/11 on Operations47:36 Iraq and WMDs01:03:59 Iran's Historical Context01:08:13 The History of Iran01:18:28 Iran's Pursuit of Nuclear Weapons

  4. 30 Jul

    The Future of Digital Identity: How Suremark Makes Verifying People Seamless at Scale

    Explore how AI, neural networks, and technological scaling are transforming industries, security, and business operations today. Scott Stornetta shares insights from his pioneering work in AI, the evolution of neural networks, and the strategic advancements by companies like Elon Musk’s ventures — all through the lens of future-proofing and responsible innovation. Perfect for entrepreneurs, tech enthusiasts, and security professionals aiming to understand the next wave of digital evolution. 00:00 - Intro: The unpredictable nature of AI progress and technological breakthroughs 02:00 - The hardware arms race: Scaling compute power in AI industries 05:00 - Elon Musk’s space ventures: Pushing the limits of orbital compute and AI scalability 08:00 - The evolution of neural networks: From thousand-parameter models to trillion-parameter systems 12:00 - How large language models learn: The mechanics of training and generalization 16:00 - The slowdown in innovation: Is more data the key or are new models needed? 20:00 - Leveraging AI tools to overcome writer's block and improve research productivity 24:00 - The importance of responsibility and accountability when using AI-generated content 28:00 - Blockchain-style identity verification and combating deepfake fraud 32:00 - The business perspective: Scaling rapidly and managing organizational change like a sports team 36:00 - The role of profitability versus mission-driven entrepreneurship 40:00 - AI in security: Protecting digital identities and verifying online interactions with Shermark 44:00 - The future of content authenticity: Using blockchain to prevent fakes and deepfakes 48:00 - Final thoughts: Embracing responsible AI innovation and strategic scaling

  5. 6 Jul

    AI Agents Are Quietly Destroying Organizations—Here's Why

    Send us Fan Mail Eve Security: https://eve.security/ LinkedIn: https://www.linkedin.com/in/nadav-cornberg/ The Future of Cybersecurity in an AI-Driven World BOLD, FEELING THE PULSE, AND MAKING YOU THINK: Nadav Cornberg reveals the seismic shifts coming to cybersecurity due to AI. From threat evolution to governance of intelligent agents, this episode is a wake-up call for every security professional. Are you ready to adapt, or will you get left behind? Timestamps: 00:00 - Introducing Nadav Cornberg: tech journey from Israel to AI security 02:30 - Over 20 years fighting evolving cyber threats 05:00 - How AI adoption accelerates security risks 07:15 - Navigating the new governance of autonomous AI agents 09:40 - The danger of prompt injections and malicious exploits 11:50 - Transition from permission-based to behavior-based security 14:10 - Classic security paradigms challenged by AI behaviors 16:35 - The future attack landscape in an agentic AI world 19:10 - Managing unintended actions and the importance of real-time governance 21:50 - The shift in cybersecurity roles due to AI tools 24:20 - Cost efficiency, model local deployment, and tokens 27:00 - Strategic considerations: investments, startups, and geopolitical factors 30:15 - Long-term future: local models, digital waste, and workforce evolution 34:00 - The importance of proactive innovation in security 37:15 - Eve Security’s approach to managing AI behaviors and risk 39:30 - Protecting organizations without limiting AI’s potential 41:50 - Final thoughts: Future-proofing your security strategies Support the show Follow the Podcast on Social Media! Tesla Referral Code: https://ts.la/joseph675128 YouTube: https://www.youtube.com/@securityunfilteredpodcast Instagram: https://www.instagram.com/secunfpodcast/ Twitter: https://twitter.com/SecUnfPodcast Affiliates ➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh ➡️ OffGrid Coupon Code: JOE ➡️ Unplugged Phone: https://unplugged.com/ Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout *See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

  6. 8 Jun

    The Scary Future of AI-Driven Social Engineering — Are You Ready?

    Send us Fan Mail Bobby Ford, a seasoned cybersecurity leader and CISO turned strategist, joins us for a powerhouse discussion on how AI is reshaping social engineering threats and what organizations need to do now to stay protected. From militaristic origins to startup innovation, Bobby’s insights are both visionary and urgent. This episode is a must-listen for anyone serious about defending against tomorrow’s cyber threats. Timestamps: 00:00 - Why social engineering AI threats are now more relevant than ever 02:12 - The importance of transparency about what you don't know in cybersecurity 04:25 - The ‘third why’ technique to test real expertise in security conversations 06:40 - How a podcast episode led to a future leadership role at Doppel 08:08 - Bobby's journey from military cybersecurity to startup strategy 09:52 - The early days of Pentagon incident response teams and military innovation 11:45 - De-gaussing hard drives in the 1980s and the evolution of data destruction 13:09 - The FBI's updated wiping standards and data recovery advances 14:16 - The challenge of data forensics and how little data is enough to piece together activity 14:53 - How social engineering tests can be made more realistic and effective 15:49 - The importance of testing controls, not just user awareness 16:46 - Building resilient organizations with layered digital and human defenses 18:46 - Why preventing attacks before they land is critical in AI-driven threats 19:37 - External versus internal controls and the threat from outside-in protections 22:23 - Social engineering as an effort to engineer humans for good or bad 23:42 - How generative AI makes it impossible for users to tell real from fake 24:17 - The alarming rise in convincing, AI-generated phishing emails and calls 25:54 - The necessity of shifting accountability from users to technology 27:19 - AI-to-AI attack scenarios and the future of autonomous cyber conflict 29:34 - Mirroring military AI strategies in digital cyber warfare 31:08 - The role of internet localization and firewalls in a future of AI-enabled conflict 33:41 - How security controls will evolve in an AI-powered world 36:49 - Why security is a business enabler, not just a gatekeeper 41:29 - The history of security’s “catch-up” game and embracing digital transformation 44:47 - The mindset of a cyber mercenary—focusing on outcomes and results 46:45 - The rapid evolution toward zero-day, AI-enabled breaches 49:57 - The four pillars of AI-fueled attacks: hyper-personalization, multi-channel, speed, and volume 51:13 - How a simple online search can make attack success egregiously easy 52:05 - Demonstration of AI-based social engineering at scale, terrifying yet promising defenses 56:41 - Bobby’s closing thoughts: security as outcome-driven and resilient Doppel:  https://www.doppel.com/ LinkedIn: https://www.linkedin.com/in/bobbyjford/ Support the show Follow the Podcast on Social Media! Tesla Referral Code: https://ts.la/joseph675128 YouTube: https://www.youtube.com/@securityunfilteredpodcast Instagram: https://www.instagram.com/secunfpodcast/ Twitter: https://twitter.com/SecUnfPodcast Affiliates ➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh ➡️ OffGrid Coupon Code: JOE ➡️ Unplugged Phone: https://unplugged.com/ Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout *See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

About

Cyber Security can be a difficult field to not only understand but to also navigate. Joe South is here to help with over a decade of experience across several domains of security. With this podcast I hope to help more people get into IT and Cyber Security as well as discussing modern day Cyber Security topics you may find in the daily news. Come join us as we learn and grow together!

You Might Also Like