ZeroSum

Aaron Mog

ZeroSum is a new cybersecurity podcast that aims to talk honestly about the state of the cybersecurity industry. The show rejects standard "threat of the week" news breakdowns and instead focuses on the reality of the market. Viewing the industry through the lens of game theory, the podcast explores how the current cyber market is no longer a rising tide that lifts all boats; for massive VC gambles to win, the burnt-out practitioners on the ground are often the ones losing. The show features guests from all perspectives, including vendors, investors, workers, and CISOs.

  1. 5 days ago ·  Video

    The AI Hacker Myth - with Silas Cutler

    Is artificial intelligence actually creating a new breed of super-hackers, or is the industry just selling panic? In this episode of the Zero Sum Podcast, Aaron sits down with Silas Cutler, one of the top security researchers in the industry and a Principal Reverse Engineer at Censys. Silas strips away the corporate marketing hype to reveal what threat actors are actually doing in the wild. They dive deep into the economic realities of cybercrime, how Russian military intelligence (APT28) hijacks criminal botnets, and the deadly, real-world risks of private companies legally "hacking back" against ransomware cartels. Whether you are a seasoned threat intel analyst, a security leader trying to understand the AI landscape, or an aspiring researcher looking to break into the field, this conversation provides a rare, unfiltered look into the trenches of cybersecurity. Timestamps / Chapters: 00:00 - Intro: Welcoming Silas Cutler to Zero Sum 01:36 - The State of Security Research Today 04:15 - Why Research is Underfunded (And Why That's Okay) 07:44 - Debunking the AI "Vulnerpocalypse" Hype 13:54 - How Threat Actors Actually Scale Their Operations 18:24 - Team PCP & The Rise of Supply Chain Attacks 22:00 - Google's "Beautiful Paranoia" vs. Unprepared AI Startups 29:12 - Is Ransomware a "Solved Problem"? 32:01 - Unmasking Russian APT28 and the Moobot Hijack 38:30 - Red on Red: When Cybercriminals Hack Each Other 39:53 - Letters of Marque & The Deadly Reality of "Hacking Back" 50:40 - Career Advice: How to Break Into Threat Research Follow Zero Sum & Our Guest: Subscribe to the Zero Sum Podcast: https://www.youtube.com/@zerosumpodcastFollow Silas Cutler on X / LinkedIn / MastodonHosted by Aaron Mog

  2. 31 Aug ·  Video

    What AI Just Exposed About Your Data - with Ward Balcerzak

    An employee typed his own name into Copilot and found out he was on the layoff list. Nobody hacked anything. Years earlier someone had used "share with all" in SharePoint, back when nobody could realistically guess the link. Then AI made everything trivially findable. Ward Balcerzak is Field CISO at Sentra with nearly two decades in data security across Accenture, Allstate, Carbon Black, and Fidelity National Financial, where he led data protection and insider risk programs. He also hosts the Guardians of the Data podcast. Aaron and Ward get into what data security looks like now that every employee is pasting company data into tools nobody approved. Ward's argument: the work organizations skipped for years — data discovery, classification, access hygiene — is exactly what AI is now dragging into the light. He also makes a contrarian case for protecting less. Nine times out of ten, the data companies are frantic about isn't special at all. Figure out what actually makes you different, find out who really has access to it, and start there. They cover why DLP earned its bad reputation, what to do when your tools hand you a million findings and no way to act on them, why regulators always arrive last, and why networking is now non-negotiable even for people who got into this field specifically to avoid people. Guest: Ward Balcerzak, Field CISO at Sentra. Find him on LinkedIn, at wardbalcerzak.com, or on the Guardians of the Data podcast. ⏱️ CHAPTERS 00:00 Intro 01:25 Twenty years of being wrong about what catches on 04:39 Can AI actually save data security? 09:30 The era of YOLO security 12:00 "AI readiness" and why nobody's ready 14:43 Sins of the past, now with petabytes 17:06 Are companies building their own models? 26:30 It's not a cat anymore, it's a mountain lion 28:16 The rigged casino of AI watermarking 29:24 Where are the actual wins? 30:59 Nine times out of ten, your data isn't special 33:48 Who actually has access? 35:09 The Copilot layoff list story 37:06 A million findings and no idea what to do 45:33 Forcing the conversations nobody wants to have 47:21 What to tell a 22-year-old today 50:26 Network, even if you got into this to avoid people 54:47 Pitch slapping and the value of being real 56:03 Where to find Ward #cybersecurity #datasecurity #AI #infosec #CISO

  3. 24 Aug ·  Video

    Why Every Cyber Company Sounds the Same - with Joel Benge

    Every CISO or engineer who's ever been told no by a board should watch this. Joel Benge spent years as the communications lead for the Department of Homeland Security's CISO office before writing "Be a Nerd That Talks Good." He's spent his career on one problem: getting technical people the budget, the headcount, and the buy-in they deserve — and figuring out why they so often don't get it. Aaron and Joel get into why most board decks fail before slide three, the "blank stare moment" that happens when you overload your audience, and the reframe that changes everything: you're not the hero of your pitch — you're Obi-Wan, and the person you're asking is Luke. Plus why the stories you least want to tell (the failures, the things you tried that didn't work) are the ones that actually build trust. They also get into why every vendor booth at Black Hat says the exact same thing, why "we prevent hacks" is a Gartner category and not a big idea, and how to align a security ask to something the business already cares about — instead of another slide full of blocked-attack metrics nobody reads. If you've ever needed a million dollars for a program and walked out with nothing, this is the episode. Guest: Joel Benge, author of "Be a Nerd That Talks Good." Find him at nerdthattalksgood.com or on LinkedIn — the intro and first chapter are free, no email required. ⏱️ CHAPTERS 00:00 Intro 02:09 Where the community is right now 06:13 Standing out in the sea of sameness 12:00 Stop copying each other's homework 13:10 "I can tell your content is AI" 15:08 "Live, laugh, love" and the Gartner-category trap 17:30 Mind, gut, heart 25:53 The stories founders refuse to tell 30:12 Why heart is what cyber gets worst 32:22 Finding the real big idea 34:09 Second- and third-order benefits 38:11 CISOs, boards, and getting budget 39:04 The blank stare moment 48:24 You're Obi-Wan, not the hero 52:35 We made CEOs the heroes and forgot customers 55:00 Aligning security to what the business values 56:06 "More scared of their company than the bad guys" 57:18 Where to find Joel #cybersecurity #CISO #infosec #leadership

  4. 18 Aug ·  Video

    I'm Not AGI Pilled. I'm Human Pilled - with Casey Ellis

    "You know who will be hiring juniors again? Bad guys." Casey Ellis founded Bugcrowd and launched the first bug bounty programs on it back in 2012, pioneering crowdsourced security as a service. He co-founded disclose.io, sits on the Black Hat and DEF CON Policy review boards, and now runs Tall Poppy Group, angel investing and advising the next generation of security startups. Fresh off a week at Black Hat, B-Sides, and DEF CON, Casey joins Aaron for a wide-ranging conversation about what he actually heard on the ground — and why the mood at each of those three conferences was completely different. We get into the "slopdemic" (Casey's term for AI-generated vulnerability reports drowning the ecosystem), why he's "human pilled" rather than AGI pilled, and his read on the White House memorandum he's calling the privateering order — what it actually authorizes, and who's really going to use it. Plus: why pen test firms are about to have a very hard time defending their value, why every company already has a vulnerability disclosure program whether they know it or not, and the hygiene fundamentals that still contain the blast radius when everything else fails. The last stretch is the one worth staying for — a genuinely urgent case for why the industry's "we're never hiring juniors again" moment is a gift to the people recruiting them instead. Guest: Casey Ellis, founder of Bugcrowd and disclose.io, principal of Tall Poppy Group. Find him on LinkedIn. ⏱️ CHAPTERS 00:00 Intro 02:35 Coming out of Black Hat, B-Sides, and DEF CON 06:33 Why DEF CON was allergic to the AI hype 09:35 Hybrid conflict is already here 10:53 Royalty in the palace, villagers at the gate 12:16 Security below the poverty line 13:14 "I'm not AGI pilled. I'm human pilled." 14:51 Do stupid things faster with more energy 19:04 What people get wrong about AI and exploitation 21:43 The slopdemic and the vulnpocalypse 25:07 What it takes before anything actually changes 28:48 Nobody is coming to save you 33:02 What actually works if you start from scratch today 37:34 Why pen test is in for a ride 39:13 Hygiene, blast radius, and the boring basics 43:31 The privateering memorandum 48:26 Who's actually waiting to hack back? 51:24 What to tell a 22-year-old today 53:21 It's really easy to do crime 55:08 Community, disclose.io, and knowledge transfer 58:01 The industry needs to give back 60:45 "Who will be hiring juniors again? Bad guys." 61:11 Tall Poppy Group and where to find Casey #cybersecurity #infosec #AI #bugbounty #DEFCON

  5. 4 Aug ·  Video

    Malware Moves in 27 Seconds. Humans Can't Keep Up - with Graham Westbrook

    Malware used to take 18 minutes to move through your network. Now it takes 27 seconds. Humans can't respond fast enough anymore. Graham Westbrook is VP of International Markets at SimSpace — the "AI Proving Grounds" for cybersecurity — with a background spanning DoD/DISA, CrowdStrike, Flashpoint, and a postgrad in AI from Oxford. Aaron sits down with him for a genuinely global, big-picture conversation about where AI security is actually heading — not from Silicon Valley, but from the ministries of defense, critical infrastructure operators, and enterprises he works with around the world. We get into why "legacy SOC is no longer sufficient" and the shift from human-in-the-loop to AI-first defense, why governments and banks will build their own models on their own data instead of renting from OpenAI or Anthropic, and the case for preemptive defense — forecasting and patching attacks before they happen, the way Google forecasts weather. Plus: the "zero day clock" racing toward minutes, why finding more vulnerabilities is a dead end, whether AI's benefits will ever reach smaller organizations or just the giants, and why Graham thinks an AI market crash is coming — and what that means for anyone entering the field. Guest: Graham Westbrook, VP International Markets at SimSpace. Find him on LinkedIn @ https://www.linkedin.com/in/graham-westbrook/ ⏱️ CHAPTERS 00:00 Intro 01:57 Where the world actually is on AI (hint: behind) 04:06 Battlefield AI and preemptive cyber defense 06:23 Why every nation will need its own model 09:48 AI, layoffs, and the "data shepherd" future 11:12 What enterprises are actually doing today 14:14 The 27-second breakout and why humans can't keep up 16:09 The zero day clock and forecasting attacks like weather 24:58 Building a digital replica of your organization 29:33 Will AI's benefits ever reach the little guy? 32:49 The arms race with China 55:37 Getting high on your own supply — the coming crash 56:42 Advice for anyone entering cybersecurity

  6. 29 Jul ·  Video

    AI Is Better at Hacking Than He Is, and He's Not Worried - with Scott Behrens

    He's an L8 Principal Engineer at Netflix — the kind of technical leader the company puts on the problems that decide whether it wins or loses. And he just watched AI out-hack him. Scott Behrens is an L8 Principal Security Engineer at Netflix, where over 11 years he's watched the security team grow from a handful of people to over a hundred. Today he's the technical lead for Netflix's Live product security, its Attack Emulation Red Team, and its DDoS research. He joins Aaron for one of the most honest, forward-looking conversations we've had about what AI actually does to security work, and to the people who do it. Scott doesn't sugarcoat it: he sat down with the latest models and quickly concluded they're better at finding and exploiting vulnerabilities than he is. But instead of doom, he lays out why that's an opportunity and where humans still hold the irreplaceable edge. We get into why the model matters less than the "harness" you build around it, the idea that human intention and hard-won wisdom are the most valuable resources in the AI race, and what actually happens when your discovery tools start surfacing thousands of real vulnerabilities you now have to fix. Plus: how AI is quietly making security the easiest story he's ever had to tell, the one-line trick that cuts vulnerabilities in AI-written code, and why the best security engineers are becoming systems thinkers, not bug-finders. Guest: Scott Behrens, L8 Principal Security Engineer at Netflix. Find him on LinkedIn and read his newsletter, The Engineer Setlist, on Substack. ⏱️ CHAPTERS 00:00 Intro 01:57 Excited, worried, and humbled all at once 04:16 Don't just do the old things faster 07:30 Should security teams fix the bugs, not just find them? 09:30 Human intention is the most valuable resource in the AI race 10:16 The "wisdom" AI doesn't have 12:22 Systems thinking as the human edge 18:14 Why the harness matters more than the model 20:25 Codifying 20 years of expertise into a harness 23:41 You built the harness — now what do you do with the findings? 25:32 What small and mid-size businesses should actually do 27:35 The one-line trick that cuts vulnerabilities in AI code 30:41 Rethinking the front end, WAFs, and detection 32:45 The "isadmin=false" honeypot trick 51:50 The era of YOLO security 53:09 Security as an enablement function 55:04 "The easiest story I've ever had to tell" 56:34 Where to find Scott #cybersecurity #infosec #AI #Netflix #appsec

  7. 27 Jul ·  Video

    Why Security Always Failed and What Finally Changes That - with Justin Somaini

    For 30 years, the security industry could never fully win. Justin Somaini explains what finally changes that. Justin Somaini is one of the people who helped define the modern CISO role — former CISO of Symantec, Yahoo, SAP, and Box, and now a Partner at YL Ventures. In this episode, Aaron sits down with him for a genuinely optimistic conversation about why security has always fallen short, and why he believes we're at the most exciting inflection point in the industry's history. Justin lays out his core thesis: security has never truly succeeded because of two structural problems — you can never hire enough people to review everything, and the industry never solved the "shared accountability" gap with engineering and IT. For the first time, he argues, AI can absorb the enormous amount of pattern-matching work that's always overwhelmed security teams — letting them finally operate at the scale the business actually demands. We also get into how he learned to separate real founders from the hype (and the belief he had to unlearn), why "drop the first slide" is his number one pitch advice, how CISOs actually make buying decisions versus what they claim, and his honest take on where the funding market is heading. Plus: the first CISO ever, why word-of-mouth beats every marketing tactic, and what makes a startup worth betting on. Guest: Justin Somaini, Partner at YL Ventures. Find him on LinkedIn or on his podcast, Somaini Trust Issues. ⏱️ CHAPTERS 00:00 Intro 01:38 Learning from Steve Katz, the first CISO ever 04:03 Why a 30-year veteran is optimistic right now 05:23 Why security has always failed — the two real reasons 07:42 How AI absorbs the work that overwhelms security teams 10:03 How to separate real founders from the hype 13:13 Salesperson, or a product engineer faking it? 16:15 "Drop the first slide" — fixing the founder pitch 18:20 Why first-time founders are like teenagers 22:10 The funding market and where it's headed 28:12 Need-to-have vs. nice-to-have 36:42 How CISOs actually make buying decisions 52:00 How to get anyone to care about what you're building 57:04 Where to find Justin

About

ZeroSum is a new cybersecurity podcast that aims to talk honestly about the state of the cybersecurity industry. The show rejects standard "threat of the week" news breakdowns and instead focuses on the reality of the market. Viewing the industry through the lens of game theory, the podcast explores how the current cyber market is no longer a rising tide that lifts all boats; for massive VC gambles to win, the burnt-out practitioners on the ground are often the ones losing. The show features guests from all perspectives, including vendors, investors, workers, and CISOs.