Hackers to Founders

Chris Magistrado

I'm Chris (REal0day) Magistrado, hacker who interviews hackers, entrepreneurs, community builders, and investors. https://HackersToFounders.com

  1. Sep 23

    Jeremiah Grossman: The 1% of CVEs That Actually Matter

    Only about 1% of all CVEs have ever been exploited, and closer to 0.2% have caused real financial loss. Jeremiah Grossman, founder of WhiteHat Security and Bit Discovery and now CEO of Root Evidence, explains why finding vulnerabilities was never the hard part, and what security teams should focus on instead. We talk about what Anthropic's Mythos findings in OpenBSD and Firefox actually mean, why companies don't just "patch everything," and how breaches really happen today. Then we get into founding companies, how Grossman Ventures picks investments, and jiu-jitsu. In this episode:- Why most AI-found vulnerabilities will never be weaponized- The real reason companies don't patch everything- How breaches actually happen: edge devices, credential stuffing, and BEC- Why he calls compliance-driven security "actually evil"- A 90-day security plan for a Series A startup: scanning, MFA everywhere, and canaries- "Kamikaze" vs. "optionality": two ways to build a startup- The daily habit he uses to find problems worth solving- Why he never doubted he could be a founder, only an employee 0:00 Intro1:33 AI vuln discovery: finding vs. exploiting3:50 Mythos, the remediation gap, and the 1% of CVEs that matter6:21 Why companies don't patch everything8:35 How breaches actually happen today9:16 Is the annual pen test dead? Compliance vs. security10:58 Software liability12:07 CVSS: keep, kill, or ignore?13:34 How much of security sells more findings14:49 MSPs, SMBs, and how insurers scan16:59 SOC 2 and pen tests for a Series A founder17:52 The most common mistake: inconsistent MFA20:03 Security vendor warranties21:14 A 90-day security plan for a new fintech22:57 Lightning round25:27 Hacking Yahoo at 1926:26 What he wishes he knew before WhiteHat28:25 Kamikaze vs. optionality startups29:07 Bootstrap or raise? Talk to a customer every day31:18 Technical founders who hate selling32:40 The 3 people founders should talk to daily35:32 How Grossman Ventures picks investments39:29 Security problems he'd start a company around41:10 What Grossman Ventures wants to fund42:34 Why some security firms stall and others scale44:19 AI startups and the moat problem45:34 ToyBox Car Club and moving to Boise47:39 Jiu-jitsu and the Black Hat BJJ event57:00 Book recommendations1:01:06 What's next: Root Evidence and competing at Worlds1:08:32 Where to find Jeremiah and who should be on next1:09:36 How he met his co-founders1:10:52 Did he ever doubt he could be a founder?1:11:57 Wrap-up1:12:55 Outro Watch the full video on YouTube: https://youtu.be/fp3F6nc2pcQ Links:Jeremiah Grossman on LinkedIn: https://www.linkedin.com/in/grossmanjeremiah/Root Evidence: https://rootevidence.com/Grossman Ventures: https://www.grossman.vc/Chris Magistrado on LinkedIn: https://www.linkedin.com/in/cmagistrado/ Hackers to Founders features the hackers and security practitioners who went on to build companies. Subscribe wherever you listen.

    Jeremiah Grossman: The 1% of CVEs That Actually Matter
  2. Sep 3

    Winning DEF CON CTF, Failing at Consulting, and Building an All-Senior Hacker Firm — Erik Cabetas (Include Security)

    Erik Cabetas won DEF CON CTF his first year, failed at running a consulting shop, then came back five years later and built Include Security into an all-senior application security firm serving billion-dollar software companies. Erik Cabetas is the founder and "head hacker herder" of Include Security, an application security firm he's run for nearly 15 years. His path there was anything but linear. He was a materials engineering major who dropped an entire semester two months before graduation to switch to computer science. He learned to hack from zines and FTP servers before Google existed, after a college roommate put Back Orifice on his machine in 1998. He got his first security job by cold-emailing, at 4am, a guy he'd seen on a documentary that aired at 3am. He won DEFCON CTF in 2003 on a team that was in dead last when he asked to join — and his contribution wasn't the two exploits he wrote, it was reorganizing who on the team did what. Then he tried to start a company, and it didn't work. He went solo for five quarters, took four clients, hit his revenue target almost exactly to the dollar — and quit anyway, because he'd worked himself into the ground to get there and couldn't see it getting easier. Five years later he tried again. Include Security launched in January 2011 with three clients already signed. This is a full start-to-finish conversation. Erik walks through the Ernst & Young Advanced Security Center team that spawned Bishop Fox, Gotham Digital Science, and his own company. Burning out on the road at Fortify Software. Running security, fraud, and trust & safety at The Ladders through the 2008 crash — including being handed the layoffs after HR was laid off. And what it actually took to build a firm that deliberately has no junior hackers on it, in an industry where nearly everyone runs a 70%-junior pyramid. He's unusually candid about the parts founders normally skip: what his rent was, what number he set for himself, why sales and legal were harder than any technical work he'd ever done, why refusing to use his own network was a mistake, why it took him five years to find one salesperson he trusted, and why the real driver of pen testing demand is B2B contract language rather than compliance. Some of what we get into: Learning security in 1998, and why Erik thinks it's harder now, not easierThe Honeynet Project forensics challenges, and writing for 2600 at 20Getting hired at E&Y off a cold email, and being 22 telling a Fortune 500 you have rootWhy he left a job the moment they promoted himInclude Security "version zero" — the attempt that failed, and exactly whyReading an entire commercial product's source code in a week to survive a customer siteCutting seven-figure credit card fraud by 98% with a few hundred lines of T-SQLThe bad RFP responses that convinced him the industry could be done betterThe all-senior model vs. the pyramid model, and what clients actually notice54 programming languages, and what they found in the largest production Rust app they've assessedHow paid research time works, and the blog posts that turned into DEF CON talksConcrete advice for starting a consulting firm today — including why he lets future competitors subcontract off his companyDrum & bass, the Spawn soundtrack, and searching Napster by random nounsLinks Include Security: https://includesecurity.comInclude Security research blog: https://blog.includesecurity.comBooks Erik recommends Security Engineering — Ross AndersonThe Ghidra Book — Chris Eagle & Kara NanceNever Split the Difference — Chris VossThe Trusted Advisor — David Maister

    Winning DEF CON CTF, Failing at Consulting, and Building an All-Senior Hacker Firm — Erik Cabetas (Include Security)
  3. 03/21/2025

    Ep. 18 - Eliminating Human Errors w/ Patrick Thomas

    What if AI-powered security could eliminate human errors in cybersecurity? Meet the founder making it happen. In this episode of Hackers to Founders, I sit down with Patrick Ben Thomas, the founder of NullZec and its advanced malware development division, Shadow Mask. Patrick shares his journey from early cybersecurity research to building a solution designed to eliminate human errors and prevent malware from spreading. We discuss how his team integrates sandboxing, zero-trust architecture, and in-house malware analysis to isolate and detect threats before they reach end users. He also dives into the offensive research behind Shadow Mask, where they develop real-world exploits to strengthen defenses. Tune in to learn how Patrick is blending adversary simulation with next-gen defense strategies to reshape cybersecurity. People Patrick Ben Thomas (Guest, Founder of NullZec & Shadow Mask)Kevin Mitnick (Famous hacker, cybersecurity expert)Companies & Organizations NullZec (Parent company founded by Patrick Ben Thomas)Shadow Mask (Malware development & adversary simulation division under NullSec)Products & Technologies HackRF (Software-defined radio device used for security research)BladeRF (Full-duplex SDR used for radio frequency security research)Proxmark 3 (RFID/NFC security tool for cloning and emulation)Flipper Zero (Multi-tool for hardware and RF hacking)NFC Kill (Device used to destroy NFC-enabled cards by electromagnetic pulse)Cybersecurity Events & Conferences DEFCON (Hacker conference)Black Hat (Cybersecurity conference)BSides (Security conference, mentioned as besides)RSA Conference (Cybersecurity event)Cybersecurity Services & Platforms VirusTotal (Malware analysis service, mentioned as insufficient for zero-day threats)

    Ep. 18 - Eliminating Human Errors w/ Patrick Thomas
  4. 02/21/2025

    Ep. 17 - How AI is Changing OSINT, Dark Web Investigations, and Fraud Detection w/ Zara Perumal

    What if AI could predict and prevent cyber fraud before it happens? Meet the founder making it possible " On this episode of Hackers to Founders, we feature Zara Perumal, the CTO and co-founder of Overwatch Data. The episode explores Zara’s journey from an early fascination with computer science, influenced by her software developer father, to her evolution into a cybersecurity and AI entrepreneur. Zara recounts her first steps into coding, beginning with HTML at age 11 and later developing iOS apps, which sparked her passion for building technology. She reflects on her experiences at MIT, where she explored bioinformatics, machine learning, and eventually cybersecurity, which became a turning point in her career. Her work at Google’s Threat Analysis Group further deepened her understanding of digital threats, leading her to the realization that she wanted to create a company addressing cybersecurity challenges at scale. The episode then shifts focus to Overwatch Data, where Zara details the company's mission to harness AI to process OSINT (open-source intelligence) and provide actionable insights for businesses. She describes the challenges of collecting and analyzing data from the dark web and fraudulent networks, explaining how Overwatch leverages automation and investigative techniques to detect threats and fraud. She also discusses the business side of the startup, from finding the right market fit to the importance of customer feedback in shaping their solutions. Throughout the conversation, Zara and host Chris Magistrado delve into the complexities of cybercrime, the evolving threat landscape, and the role of AI in modern threat intelligence, offering listeners a fascinating look into the intersection of security, AI, and entrepreneurship. People Zara Perumal – CTO and Co-founder of Overwatch Data, specializing in AI-driven cybersecurity.Chris Magistrado – Host of Hackers to Founders, interviewing tech and security entrepreneurs.Arjun Bisen – CEO and Co-founder of Overwatch Data who initially had the idea for the company.Ron Rivest – Renowned cryptographer and MIT professor who influenced Zara’s interest in cybersecurity.Michael (YC Advisor) – Advisor at Y Combinator who guided Overwatch Data through its early stages.Companies & Organizations Overwatch Data – A cybersecurity startup leveraging AI to process OSINT and detect fraud.MIT CSAIL – MIT’s Computer Science and Artificial Intelligence Laboratory where Zara conducted research.Harvard Belfer Center – A research institute focused on security, where Zara contributed to digital democracy defense.Akamai – A cloud and cybersecurity company where Zara gained experience in software and data analytics.NASDAQ – A major stock exchange where Zara worked in technology roles.Apple – Technology company where Zara developed software.Y Combinator – Startup accelerator that backed Overwatch Data.Corellium – A company providing a virtualization platform for mobile security research.Technologies & Tools Objective-C – Programming language used for iOS app development before Swift.Swift – Modern programming language for Apple’s ecosystem.React Native – A framework for building cross-platform mobile applications.Flutter – Google’s UI toolkit for natively compiled mobile apps.JADX – A tool for reverse-engineering Android applications.Telegram – Messaging platform heavily used by cybercriminals for fraud and illicit activities.GPT (ChatGPT) – AI tool used for scripting and automating analysis tasks.DeepSeek – An AI tool discussed for its open-source implications.Magic Eye – A bot used for detecting duplicate images on Reddit.Corellium – A mobile security research platform used for analyzing malware.Cybersecurity & Hacking OSINT (Open-Source Intelligence) – Intelligence gathered from publicly available sources.Dark Web – A hidden part of the internet where illicit cyber activities and fraud take place.SIM Swapping – A fraud technique where hackers take over phone numbers to gain access to accounts.Credential Stuffing – A hacking technique using stolen username-password combinations.PDF Malware – Malicious software hidden in PDFs, which Zara researched in academia and at Google.Null Market (Nulled) – A recently taken-down dark web forum used for cybercrime.DNM (Dark Net Marketplaces) – Online platforms for buying and selling illicit goods.Grams – A dark web search engine that indexed darknet marketplaces.MD5 Hashing – A cryptographic technique used to verify digital signatures.

    Ep. 17 - How AI is Changing OSINT, Dark Web Investigations, and Fraud Detection w/ Zara Perumal
  5. 01/29/2025

    Ep. 16 - The Birth of the CVE System, created by Adam Shostack

    Who created the CVE system? That's Adam! In this insightful episode of "Hackers to Founders," host Chris REal0day Magistrado welcomes Adam Shostack, a renowned cybersecurity expert and co-creator of the Common Vulnerabilities and Exposures (CVE) system. Adam recounts his journey from a curious and geeky childhood, engaging in activities like D&D and building with Legos, to his influential career in cybersecurity. He delves into his early experiences at Brigham and Women's Hospital, where he first encountered the importance of security and privacy in medical systems. Adam shares his entrepreneurial ventures, including his pivotal roles in startups like Net Tech and Zero Knowledge Systems, highlighting the challenges and rewards of building security-focused businesses during the nascent stages of the cybersecurity industry. His passion for threat modeling is evident as he discusses his work at Microsoft, where he developed user-friendly threat modeling tools and authored influential books to make security practices more accessible. Beyond his technical achievements, Adam emphasizes the significance of education, training, and mentorship in advancing cybersecurity. He explains his transition from product development to focusing on training and creating scalable educational programs, ensuring that essential security skills are widely disseminated. Adam also explores his collaboration with Cyber Green to establish cyber public health, aiming to apply public health methodologies to measure and mitigate cyber impacts effectively. Throughout the conversation, Adam underscores the importance of diversity in fostering innovative solutions and the need for adaptable strategies in an ever-evolving threat landscape. His dedication to making cybersecurity more inclusive and his visionary approach to integrating interdisciplinary techniques position him as a key thought leader committed to enhancing global security practices. People Adam Shostack: Renowned cybersecurity expert, co-creator of the Common Vulnerabilities and Exposures (CVE) system, author of several influential books on threat modeling and security design.Frank Abagnale: Subject of the book "Catch Me If You Can," which influenced Adam's childhood interest in security and deception techniques.Leonardo DiCaprio: Actor who portrayed Frank Abagnale in the movie adaptation of "Catch Me If You Can."Mike Howard: Worked alongside Adam on the Secure Development Lifecycle team.Steve Lipner: Collaborated with Adam on threat modeling initiatives.Rob Kinnaki: Worked with Adam on the cyber public health project, contributing to the development of new cybersecurity disciplines.Tara Wheeler: Partnered with Adam in establishing cyber public health methodologies.Heidi Trust: Recommended by Adam as a notable figure intersecting usability and security.Gene Spafford: Part of Adam's professional network, contributing to cybersecurity discourse.Steve Belvin: Known to Adam, part of his network of cybersecurity professionals.Bruce Schneier: Part of Adam's extensive network within the cybersecurity community.Marcus Ranham: Known to Adam, contributing to his professional relationships.Mudge: Met by Adam during his time at BBN, part of his influential network.Weld Pond: Met by Adam at BBN, contributing to his professional connections.Prerit Garg: Contributor to threat modeling methodologies.Lance Cottrell: Influenced Adam's work on anonymized networks at Zero Knowledge Systems.Paul Syverson: Co-inventor of onion routing. His work influenced the development of anonymized network systems like Tor and Zero Knowledge Systems.Steve Christie: Involved in the development of the CVE system.Dave Mann: Collaborated with Adam on creating the CVE system.Andre Fresh: Worked with Adam on developing the CVE system.Tony Sager: Helped secure funding for the CVE system through collaboration with MITRE.Stephen Savage: Involved in ransomware detection research, mentioned in relation to cyber public health.Organizations CVE (Common Vulnerabilities and Exposures): A standardized system for identifying and categorizing cybersecurity vulnerabilities. Co-created by Adam Shostack to provide a common reference for vulnerabilities across different platforms and organizations.Net TechStartup focused on developing vulnerability scanners. Adam played a pivotal role in this successful startup, contributing to the creation of security tools.Zero Knowledge Systems: Startup aimed at creating anonymized network solutions similar to Tor. Adam joined this company to work on privacy-focused technologies.MITRE: Not-for-profit organization that manages various federally funded research and development centers. Collaborated with Adam to develop and support the CVE system.Secure ID: Company that produced authentication tokens. Adam conducted security and privacy reviews of their products early in his career.BBN (Bolt Beranek and Newman Inc.) Technology company known for its work on ARPANET and early internet infrastructure. Adam worked here and met key figures like Mudge and Weld Pond.DEF CON: One of the world's largest and most notable hacker conventions. Adam attended DEF CON, sharing experiences and networking with other security professionals.2600: Hacker community magazine and associated meetings. Part of the hacker culture Adam was involved with during his early career.ShmooCon: Annual East Coast hacker convention. Adam attended and interacted with the hacker community here.CISA (Cybersecurity and Infrastructure Security Agency): U.S. federal agency responsible for cybersecurity and infrastructure protection. Mentioned in the context of cybersecurity research and vulnerability management.Products and Tools CVE System (Common Vulnerabilities and Exposures): A standardized system for identifying and cataloging cybersecurity vulnerabilities. Co-created by Adam Shostack to provide a common reference across the cybersecurity industry.Hacker Shield: Vulnerability scanner developed by Adam's company. Used by organizations to identify and remediate security vulnerabilities.Stride: A mnemonic framework for threat modeling (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege). Developed by Prerit Garg and others to help structure threat analysis.Tor: An anonymity network that directs internet traffic through a free, worldwide, volunteer overlay network. Influenced the development of Zero Knowledge Systems' anonymized network products.Mixmaster: Asynchronous email router designed for anonymizing email traffic. Developed by Lance Cottrell, influencing Adam's work on privacy-focused networking.Log4j: Java-based logging utility with significant vulnerabilities exploited in cybersecurity attacks. Discussed by Adam in the context of vulnerability management and public health approaches to cybersecurity.

    Ep. 16 - The Birth of the CVE System, created by Adam Shostack
  6. 01/20/2025

    Ep. 15 - CISO Lessons from Fox News, Point72, and Phosphorus with John Terrill

    How do you defend Fox News, hedge funds, and global networks while building groundbreaking startups? John Terrill shares his journey. In this episode of Hackers for Founders, cybersecurity executive John Terrill shares his fascinating journey from a curious 12-year-old attending 2600 meetings in Atlanta to becoming a seasoned CISO and co-founder of Drawbridge Networks. He delves into the formative experiences that shaped his career, including his early exposure to security research at Internet Security Systems and his role in founding and developing innovative security technologies. Terrill highlights his learnings about product-market fit, timing, and the challenges of building technology ahead of its time, such as with Drawbridge Networks' pioneering work in micro-segmentation. The conversation also explores Terrill’s tenure as CISO at Fox News during a transformative period, including its sale to Disney, and at Point72, where he tackled challenges like the rise of ransomware, executive protection, and the pivot to remote work during the pandemic. Throughout the episode, Terrill emphasizes the importance of aligning cybersecurity efforts with business objectives, explaining the delicate "yin and yang" balance between offensive and defensive security strategies. He also critiques current board-level approaches to cybersecurity, advocating for more nuanced discussions around practical solutions, recovery planning, and metrics to assess whether organizations are genuinely improving security posture. Companies and Organizations Phosphorus Cybersecurity Inc: A cybersecurity company specializing in xIoT security solutions.Point72: A global hedge fund focused on investment and asset management.Fox News Media: A major American media company known for its news and television broadcasting.OPĀQ Networks: A network security company acquired by Fortinet.Drawbridge Networks: A cybersecurity startup co-founded by John Terrill, focusing on network microsegmentation.NYU Tandon School of Engineering: The engineering school of New York University, where John Terrill was an adjunct professor.BlackRock: A global investment management corporation, where John led application security efforts.NASDAQ OMX: A global financial services corporation operating stock exchanges, where John worked as a consultant.IBM (Internet Security Systems): A technology and cybersecurity company where John started as an X-Force researcher.Zettaset: A cybersecurity startup focusing on big data security, co-founded by John.Events and Concepts 2600 Meetings: Monthly hacker meetings where cybersecurity enthusiasts and professionals share knowledge.Microsegmentation: A network security strategy for isolating workloads and preventing lateral movement.Zero Trust: A cybersecurity framework emphasizing the elimination of implicit trust in networks.MITRE ATT&CK Framework: A globally accessible knowledge base of adversary tactics and techniques.

    Ep. 15 - CISO Lessons from Fox News, Point72, and Phosphorus with John Terrill
  7. 01/07/2025

    Ep 13 - Finding Your Passion in Cybersecurity with Dave Chronister

    From crimping cables to advising the French Minister of Defense—Dave Chronister’s journey is unreal! Step into the world of cybersecurity with Dave Chronister, a trailblazer whose career spans decades of groundbreaking achievements. As the founder of Parameter Security, Dave has helped organizations across heavily regulated industries protect their technology, data, and reputation through cutting-edge strategies. He also launched ShowMeCon, a premier InfoSec conference known for its hands-on training and top-tier speakers. From building one of the largest exchange server deployments to advising global leaders, Dave has been featured on CNN and CNBC for his expertise. Join us as he shares his journey from a small-town IT tech to a global cybersecurity icon, blending technical mastery with insights on business, AI, and creating impactful conferences. You won’t want to miss this! 1. People and Speakers Dave Chronister: Cybersecurity expert, founder of Parameter Security, creator of ShowMeCon.Chris REal0day: Co-interviewer or participant in the conversation with Dave Chronister.French Minister of Defense - Mentioned as a speaker at a conference where Dave Chronister was a keynote speaker.2. Companies and Organizations Parameter Security: Cybersecurity firm founded by Dave Chronister.ECCouncil: Organization offering certifications like CEH and facilitating cybersecurity training.EuroPol: European Union's law enforcement agency, involved in cybersecurity collaborations.FBI: U.S. federal law enforcement agency, referenced in cybersecurity operations.Fortinet: Cybersecurity company mentioned in the context of speaker quality.3. Conferences ShowMeCon: InfoSec conference organized by Dave Chronister.Def Camp: Cybersecurity conference held in Bucharest, Romania.Positive Hack Days (PHDays): Cybersecurity conference held in Moscow, Russia.Black Hat: Leading business-focused cybersecurity conference.DEF CON: Grassroots hacking conference focused on InfoSec enthusiasts.RSA Conference: Government-focused cybersecurity conference.4. Certifications and Courses CISSP: Certified Information Systems Security Professional, taught by Dave Chronister.CEH: Certified Ethical Hacker certification, taught by Dave Chronister.Security Plus: Foundational cybersecurity certification taught by Dave.5. Pop Culture References Animal House: Mentioned as the basis for Mizzou's party reputation.6. Books Find Your Why by Simon Sinek - A book that helps individuals and organizations discover their purpose and align their actions accordingly​Traction by Gino Wickman - Focused on the Entrepreneurial Operating System (EOS) framework, helping businesses gain clarity and improve execution​Rocket Fuel by Gino Wickman and Mark C. Winters - Explores the relationship between visionaries and integrators in business, emphasizing the need for complementary roles to drive success​Value-Based Fees by Alan Weiss - A guide for service-based businesses on pricing based on value delivered rather than hours worked​Vivid Vision by Cameron Herold - A book on creating a clear and compelling vision for businesses and teams to rally around​Who Not How by Dan Sullivan - A book on delegating effectively and focusing on what you do best by surrounding yourself with the right people​Living the Best Year Ever - A book with worksheets and tools for setting and achieving personal and professional goalsThe Home MBA - A curated list of books for learning business fundamentals

    Ep 13 - Finding Your Passion in Cybersecurity with Dave Chronister

About

I'm Chris (REal0day) Magistrado, hacker who interviews hackers, entrepreneurs, community builders, and investors. https://HackersToFounders.com

You Might Also Like