Unspoken Security

Unspoken Security

Unspoken Security is a raw and gritty podcast for security professionals who are looking to understand the most important issues related to making the world a safer place, including intelligence-driven security, risks and threats in the digital and physical world, and discussions related to corporate culture, leadership, and how world events impact all of us on and off our keyboards.In each episode, host AJ Nash engages with a range of industry experts to dissect current trends, share practical insights, and address the blunt truths surrounding all aspects of the security industry.

  1. Sep 18

    How AI Is Rewriting the Rules of Offensive Security

    In this episode of Unspoken Security, host AJ Nash sits down with Snehal Antani, co-founder and CEO of Horizon3.ai and former first CTO of Joint Special Operations Command (JSOC), to dissect what AI is really doing to the economics of cyber attacks - and cyber defense. Snehal opens with a jaw-dropping data point: his team compromised a defense industrial base supplier and achieved full domain admin in 77 seconds. From there, the conversation moves into the surprising counter-strategy his team uncovered - that today's LLMs and agentic attackers are dramatically more gullible than human hackers, clicking on well-placed honey tokens up to 95% of the time. The two dig into why "train like you fight" - a principle Snehal absorbed at JSOC - is now essential for cyber teams, why compliance frameworks like CMMC are failing to produce real resilience, and why the future of cyber warfare is "AI versus AI with humans by exception." Snehal walks through Horizon3.ai's architectural bet on disposable models, persistent knowledge graphs, and constrained-action-space agents, and explains why the "haves and have-nots" of red teaming is finally being disrupted by autonomous pentesting that IT admins - not elite ethical hackers - can operate. The conversation closes with a candid look at the industry itself: the ChatGPT-driven sameness of vendor messaging, the Black Hat gimmick arms race, and Snehal's plea to return to technical authenticity. He ends with a deeply personal reflection on his late father - the electrical engineer who sabotaged toy robots so his six-year-old son would learn to troubleshoot them - and the weight of trying to pass that same gift on to his own kids. Send us Fan Mail Support the show

  2. Aug 27

    How Do We Know What’s Real in the Age of AI?

    AJ Nash sat down with Shai Gabay, co-founder and CEO of Trustmi, to talk about financial fraud in the age of AI. Gabay opened with the size of the problem: global fraud losses hit $450 billion last year. He explained why business-to-business payment fraud keeps growing. Attackers do not invent new relationships. They study the ones a company already has, then step into an existing conversation between a business and its vendor. Most of that conversation happens over email, and most companies still rely on people, not systems, to catch when something is wrong. The two traced how far that exploitation has evolved. Generative AI has erased the old tells: bad grammar, wrong context, unfamiliar phrasing. Gabay described attackers who forge invoices, bank letters, and void checks in minutes, and a rising pattern where criminals open fully legitimate bank accounts, complete with real KYC verification, under a stolen supplier identity. He walked through a real case where an attacker built a lookalike domain, cloned a supplier's website, and updated the fake site to appear first in search results, all to defeat a callback verification procedure before it ever started. Nash and Gabay closed on the harder question: what happens when video and voice can be faked too. They discussed a $25 million loss out of Hong Kong, where an employee was pulled into a Zoom call with deepfaked company leadership and instructed to wire funds. Gabay argued that no single tool fixes this. Organizations need to connect fragmented controls into one process and, above all, give the person who actually approves a payment the standing to ask questions and slow down. Asked the show's closing question, Gabay admitted that even as a CEO, he still gets pulled into incident response himself, just to understand exactly how an attack worked. Send us Fan Mail Support the show

5
out of 5
10 Ratings

About

Unspoken Security is a raw and gritty podcast for security professionals who are looking to understand the most important issues related to making the world a safer place, including intelligence-driven security, risks and threats in the digital and physical world, and discussions related to corporate culture, leadership, and how world events impact all of us on and off our keyboards.In each episode, host AJ Nash engages with a range of industry experts to dissect current trends, share practical insights, and address the blunt truths surrounding all aspects of the security industry.

You Might Also Like