The Gate 15 Podcast Channel

Gate 15

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

  1. 17h ago

    Weekly Security Sprint EP 173. Information sharing, strategies, and AI

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • 15 from 15: Blocking and Tackling Cybersecurity & Resilience — Gate 15 — 09 Sep 2026. Gate 15 released 15 from 15: Cybersecurity Mitigation & Resilience Fundamentals, emphasizing that rapidly evolving threats, artificial intelligence, ransomware, exploited vulnerabilities and nation-state activity do not eliminate the importance of consistently executing foundational security practices. The framework identifies 15 practical areas to help organizations “get a little better every day.” • What the FBI Phishing Warning Means for Event Planners — Skift Meetings — 08 Sep 2026. Gate 15 Vice President and Chief Resilience Officer Ben Taylor contributes perspective. • (TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin – Q3 2026 — WaterISAC — 10 Sep 2026 • Cyberattacks on food and agriculture can turn disruptions into safety crises, threatening public health and supply chains — Industrial Cyber — 08 Sep 2026 • 27th Annual TribalNet Conference & Tradeshow Main Topics: FBI cyber chief worries private sector not sharing enough cyber threat information — CyberScoop — 09 Sep 2026. FBI Cyber Division Assistant Director Brett Leatherman said private-sector organizations are still not sharing enough cyber information with the Bureau, in part because some companies incorrectly believe information provided during an incident will be passed to regulators for regulatory purposes. FBI Cyber Strategy — FBI — 09 Sep 2026. The FBI released its first agency-wide unclassified cyber strategy, organizing its approach around disrupting and imposing costs on adversaries, supporting victims, increasing impact through partnerships and strengthening internal cyber capabilities. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — CISA — 08 Sep 2026. CISA, NSA and the FBI warn that China-based AI companies are conducting industrial-scale campaigns to systematically extract proprietary capabilities from U.S. frontier AI models, describing malicious knowledge distillation as a core component rather than merely a supplement to their AI development strategies. Insider Threat Mitigation Guide — CISA — 09 Sep 2026. During National Insider Threat Awareness Month, CISA is again highlighting its Insider Threat Mitigation Guide and related resources for organizations building or improving insider-risk programs. Quick Hits: • Congratulations! You Just Lived Through the Hottest Month Ever Recorded — WIRED — 10 Sep 2026. • NSA Highlights Cyber Hygiene Best Practices Effective Against AI-Enhanced Targeting — National Security Agency — 03 Sep 2026 • Gateway security guidance package: Overview — Australian Signals Directorate’s Australian Cyber Security Centre — updated 04 Sep 2026 • The hidden risks of shadow AI — UK National Cyber Security Centre — 07 Sep 2026 • Iran hackers: Dissatisfaction with AT&T services drove decision to target telecom in Texas • Iran hackers, after denial of Texas AT&T claim: ‘Idiots don’t even know what we tampered with’ • Iran hackers claim Texas AT&T outage, vow to ‘intensify’ attacks before 9/11

    Weekly Security Sprint EP 173. Information sharing, strategies, and AI
  2. Sep 1

    Weekly Security Sprint EP 172. Alphabet soup month, cyber protections, leadership engagement and more!

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • Celebrating 5 Years of the Tribal-ISAC: Mid-Year Executive Director Update — TribalHub • FB-ISAO Newsletter, v8, Issue 8 — Faith-Based ISAO • AI/Vishing: The Voice Is Not the Control — Crypto ISAC • National Insider Threat Awareness Month: Protect Our Potential Main Topics: Iran hackers: Minnesota ‘warning’ ignored, ‘critical events’ to hit 3 U.S. infrastructure sectors — Threat Beat — 31 Aug 2026. APT IRAN, which has claimed responsibility alongside CyberAv3ngers for recent attacks affecting U.S. municipal water systems, issued a new threat against multiple U.S. critical infrastructure sectors as military tensions with Iran continue. The group characterized its earlier Minnesota activity as a warning and has previously claimed the ability to affect electricity, telecommunications, and water infrastructure, although adversary claims regarding access and capabilities should not be accepted without independent verification. A Tale of Two SOCs: Insights From Two Red Team Assessments — CISA — 25 Aug 2026. CISA released findings from simultaneous red-team assessments of organizations in the Government Services and Facilities Sector and the Water and Wastewater Systems Sector. Both organizations experienced successful initial compromise, but the government organization failed to detect or effectively contain subsequent activity while water-sector defenders quickly identified compromised systems and isolated them. CISA attributed the differing outcomes in part to alert noise, organizational silos, cloud-security weaknesses, and differences in how defenders were empowered to respond. Institutional Wilful Blindness, NCSC Cyber Series — NCSC Cyber Series — 2026. The first installment of a two-part discussion examines why organizations can understand that cyber risks exist yet still fail to take meaningful action before incidents occur. Leadership expert Margaret Heffernan, Professor Genevieve Liveley of the Research Institute for Sociotechnical Cyber Security, and an NCSC social sciences leader discuss how organizational culture, leadership behavior, communication, and the narratives used to describe cybersecurity can create a gap between awareness and action. The discussion emphasizes that resilience depends on more than technical controls and requires leaders to challenge complacency, communicate uncertainty effectively, and create environments where uncomfortable risk information can influence decisions. Quick Hits: • Insights into Suspected DPRK Workers: Red Flags to Look Out For — Huntress • The Who and How of Ten Years of Russian Disinformation — NewsGuard

    Weekly Security Sprint EP 172. Alphabet soup month, cyber protections, leadership engagement and more!
  3. Aug 25

    Weekly Security Sprint EP 171. Cyber conflicts and critical infrastructure, new reports, and crime statistics

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • Nerd Out EP 73: 5th Annual 2/3rd of the Year Awards with the Cybersecurity Evangelist • The Gate 15 Interview EP 73. The FBI’s Josh Obstfeld on Artificial Intelligence, Serving our Nation, and New York City! • Ice cream makers as ‘critical infrastructure’? EU’s new cybersecurity law suffers wobbly rollout • Healthcare finance trends for 2026: A mid-year update — Health-ISAC Main Topics Iran-linked hackers blamed for cyber-attack that shut down UK power plant — The Guardian — 23 Aug 2026. Hackers linked to Iran have been blamed for a cyberattack that temporarily shut down a small-scale power generator in the United Kingdom. • UK briefs energy chiefs after Iran-linked cyber attack reports • Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant • "Not a single drop of oil" will be exported if US "economic" war continues: Iran's security chief • Defending Against an Active Threat to Siemens S7 Series PLCs — CISA Cyber Threats in Times of Conflict — Emsisoft — 17 Aug 2026. Emsisoft assesses that events in Ukraine, Venezuela, and the continuing Iran conflict demonstrate that cyber operations have become a routine component of modern conflict, but cautions against assuming every disruption represents a sophisticated state cyberattack or that cyber operations will replace conventional warfare. What if America Went Completely Dark? — The New York Times Magazine — 18 Aug 2026. The New York Times examines the potential consequences of a prolonged nationwide electric-grid failure and emphasizes how quickly an electricity crisis would cascade into communications, water and wastewater, fuel distribution, healthcare, transportation, food supply, finance, public safety, and other essential services. Quarterly Threat Report: Second Quarter, 2026 — Beazley Security — 18 Aug 2026. Beazley Security reports that vulnerability disclosures increased dramatically during the second quarter as agentic AI accelerated vulnerability research, yet confirmed exploitation grew at a substantially slower rate and the fundamental paths attackers used to enter organizations changed very little. CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomware. FBI: 2025 had biggest violent-crime drop in 90 years — Axios — 18 Aug 2026. FBI data shows that U.S. violent crime fell sharply in 2025, producing the largest annual decline since the bureau began publishing national estimates in 1936. Severe Weather: And Get Ready for Winter Weather! • At least six injured in Reno, Nevada, wildfire as 42,000 forced to evacuate • California’s coast under siege: A winter of flooding, big waves and erosion in the forecast • ‘Heat Dome’ to Bring Dangerous and Prolonged Heat Wave to Southern States Quick Hits: • Beware the Ransomware Rescuer: Ransom Busters — GuidePoint Security — 18 Aug 2026. GuidePoint Security reports that an entity calling itself Ransom Busters has contacted ransomware victims before incidents became publicly known and offered to recover data or delete stolen information for a fee. • NoName057(16) targets German government officials in “Tribunal project” — Real Hack History — 23 Aug 2026. • Protect yourself: Multi-factor authentication — Australian Signals Directorate’s Australian Cyber Security Centre • Logging Reference Architecture — CISA • Tip of the Week – August 20, 2026 — WaterISAC — 20 Aug 2026. WaterISAC urged water utilities to periodically review network segmentation between operational technology and business information technology environments. • Managing the cyber risk of agentic AI — UK National Cyber Security Centre • AI is changing the economics of vulnerability discovery. Defenders should adapt now — CERT-EU

    Weekly Security Sprint EP 171. Cyber conflicts and critical infrastructure, new reports, and crime statistics
  4. Aug 24

    The Gate 15 Interview EP 73: The FBI’s Josh Obstfeld on Artificial Intelligence, Serving our Nation, and New York City!

    In this episode of The Gate 15 Interview, Andy Jabbour speaks with Joshua Obstfeld, FBI Counterintelligence Senior Executive for External Engagement. Joshua Obstfeld joined the FBI in 2005 and currently serves as the FBI Counterintelligence Senior Executive for External Engagement, with a focus on congressional and executive branch engagement to highlight strategic threats, FBI action, and potential policy responses. Josh has served separately as Senior National Intelligence Officer for both China and for Emerging and Disruptive Technologies, and from 2021-2024, he led the FBI Newark Division’s Intelligence Branch where he was responsible for analysis of all threats in the State of New Jersey. Josh holds an MA in International Relations from the Johns Hopkins University School of Advanced International Studies, and a BA from Johns Hopkins University. • Josh on LinkedIn In the podcast, Josh and Andy discuss: • AI, threats and opportunities • AI and cybercrime: from ransomware to insider threats, and the importance of the human element • AI Swarms • The Threats and Opportunities of Tomorrow • The race for AI dominance • Private Public Partnership • Josh’s call to action • We play Three Questions! and discuss New York’s finest food and sports, alternate careers, and some of the 80s and 90s greatest hits! • And more!! Relevant links to this podcast: • FBI • FBI Counterintelligence and Espionage Division • FBI Internet Crime Complaint Center • INTERPOL report finds AI linked to more than half of cybercrime in Africa, 03 Aug 2026 • METR & the Frontier Risk Report (February to March 2026) • INTERPOL’s African Cyberthreat Assessment Report 2026 (PDF) • WIRED: AI-Powered Disinformation Swarms Are Coming for Democracy, 22 Jan 2026 • SecurityWeek: Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms, 30 Jul 2206 • Beazley Security: Quarterly Threat Report: Second Quarter, 2026, 18 Aug 2026

  5. Aug 19

    Nerd Out EP 73: 5th Annual 2/3rd of the Year Awards with the Cybersecurity Evangelist

    On the latest episode of Nerd Out, Dave and Alec welcome in special guest Jennifer Lyn Walker, the Cybersecurity Evangelist, to go through the 2/3rd of the year awards. We review nominations for each award and discuss each. Awards: MVP The Cobra (Sly Stallone) Award - you are the disease and I’m the cure - what has been a great security process or procedure that can really help orgs.The Dennis Green (Former Viking Coach - they are who we thought they are award. What is a threat or tactic that threats use that really showed their true colors.The Aldus Snow (Infant Sorrow) - don’t forget about me. What is the security threat that remains always present.Dumpster Fire award - what incident or threat will just make things a mess.Scotty Doesn’t Know award (EuroTrip) - what threat is out there that orgs aren’t thinking about but should.Avengers Team Up award - is there a great product or paper that involved multiple groups that orgs should know about.Heath Ledger Joker award - what threat just takes it to another level - when you think last time was bad, the next time is worse. Some references made during the call include: Cyber Readiness Institute https://cyberreadinessinstitute.org/UnDisruptable27 https://securityandtechnology.org/undisruptable27/National Council of ISACs https://www.nationalisacs.org/Idaho National Laboratory | Cyber Informed Engineering https://inl.gov/national-security/cie/

  6. Aug 18

    Weekly Security Sprint EP 170. NK IT worker scams, blended attacks, and the weatherman!

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • Operation Vital Signs: First-of-its-kind exercise stress tests health sector cyber resilience — Health-ISAC — 11 Aug 2026. Health-ISAC and the Health Sector Coordinating Council Cybersecurity Working Group conducted the inaugural Operation Vital Signs national tabletop exercise to test healthcare's collective response to major cyber disruption. The exercise brought together organizations spanning hospitals, pharmaceutical companies, medical device manufacturers, payers, health IT, laboratories, pharmacies, and other components of the healthcare ecosystem. • Testimonial: “Over the past two years, our company has implemented several technology and security enhancements and has worked closely with Gate 15 to conduct a series of executive-level exercises, a post-mortem of a cyber event, and a cybersecurity assessment. Through these initiatives, we achieved a 34% reduction in our cyber insurance costs.” - Director Cybersecurity & Infrastructure for a leading U.S. solar and energy manufacturer. Main Topics : North Korea IT Worker Threat: FBI investigating North Korean remote IT staffer working for US agency — Federal News Network — 10 Aug 2026. The FBI is investigating how an unidentified federal agency became involved in the longstanding North Korean scheme in which operatives fraudulently obtain remote IT employment. The development represents an escalation from documented infiltration of private-sector organizations into a reported federal government environment. Experts cited by Federal News Network warned that contractors and support personnel can create pathways into government environments even when their positions are not directly associated with government contracts. • Inside North Korea’s Operation to Conquer the American Job Market • The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In Blended Threats: Ransomware Attack disrupts Hospital Doors, Elevators, Ventilation and Air Conditioning in Canada — Cybersecurity Insiders — 11 Aug 2026. A ransomware attack affecting Health Sciences Centre in Winnipeg disrupted facility-management systems controlling doors, elevators, heating, ventilation, and air conditioning, demonstrating a direct physical consequence from a cyberattack. The hospital reported that patient care and clinical operations continued, but the incident interfered with maintenance and operation of building services. The event is significant because compromise was not confined to data or conventional business systems and instead affected infrastructure required to operate the physical hospital environment. • When Ransomware Turns Off the HVAC: Lessons from the Winnipeg Hospital Incident Severe Weather: Contiguous US breaks its record for hottest month ever, NOAA says — Associated Press — 11 Aug 2026. NOAA reported that July 2026 was the hottest month recorded across the contiguous United States since national records began in 1895. The nationwide average exceeded the previous July record set during the Dust Bowl era, with above-average temperatures recorded across all 48 contiguous states. Scientists cited by AP identify human-caused climate change as the primary driver of the long-term warming trend, with unusually warm nighttime temperatures contributing significantly to the record. Quick Hits: • Victim Decision-Making During Ransomware — Gate 15 — 13 Aug 2026 • Opportunities for AI in cyber defence — Australian Signals Directorate — 27 May 2026 • Expanding Capabilities to Combat Transnational Cyber-Enabled Crime — The White House • Russia pushes narratives aimed at reviving divisions between eastern and western Germany — NewsGuard Reality Check

    Weekly Security Sprint EP 170. NK IT worker scams, blended attacks, and the weatherman!
  7. Aug 4

    Weekly Security Sprint EP 169. Water ISAC review with Chase Snow

    On this week's Security Sprint, Dave and Andy are joined by Chase Snow to talk about the latest cyber incident involving water facilities. They covered some of these topics: Opening: • Crypto security breaches surpass $1B in H1 2026, hit record high — Crypto Briefing • CISA, ASD’s ACSC, and Partners Release Joint Guidance on Isolating Vital Operational Technology and Enabling Systems During Crisis. The Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation (FBI) and international partners, published joint guidance CI Fortify – Advice for isolating vital systems. • CI Fortify – Advice for isolating vital systems — Australian Signals Directorate • When cyber attacks happen: helping organisations recover — United Kingdom National Cyber Security Centre Water Sector Cyberattacks: • Iran’s CyberAv3ngers claim ‘attacks on U.S. infrastructure,’ vow more in first statement since Minnesota water hacks • Trump rejects Iran blame for Minnesota cyberattack, points finger at 'corrupt' political foe • Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world — CyberScoop — 31 Jul 2026. With commentary from Gate 15 and WaterISAC. • Several states report cyberattacks as spy agencies suspect Iran is targeting water — The Washington Post — 01 Aug 2026. WaterISAC analyst Alec Davison said attackers used relatively unsophisticated methods against internet-connected programmable logic controllers, then changed passwords, locked out operators, and disconnected controllers, resulting in boil-water notices and sustained manual operations. • (TLP:CLEAR) CISA Issues Alert Urging Water and Wastewater Utilities to Protect OT Against Activity Targeting PLCs — WaterISAC • Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control

    Weekly Security Sprint EP 169. Water ISAC review with Chase Snow

Ratings & Reviews

5
out of 5
4 Ratings

About

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

You Might Also Like