Dirty South Security Podcast

VerSprite Cybersecurity

Welcome to the Dirty South Security Podcast! 🌍🔒Join us as we dive into the hottest takes and latest trends in cybersecurity from around the globe. Whether you're a seasoned professional or just curious about the digital world's inner workings, our podcast offers insightful discussions, expert interviews, and thought-provoking analysis on the most pressing security issues today.Stay ahead of the curve with our no-nonsense approach to all things cybersecurity. Subscribe now and never miss an episode!

  1. Jul 28

    Ep.17 - Strong Drink – Hard Hitting Truths in Entrepreneurial Success in Cyber, Tech as an Investor & Entrepreneur

    Building a cybersecurity company has never been easier. Building one that lasts may be harder than ever. In Episode 17 of the Dirty South Security Podcast, host Tony UV sits down with cybersecurity entrepreneur, investor, and longtime application security leader Dan Cornell for an honest conversation about building companies, raising capital, creating defensible products, and preparing for an eventual exit. Dan shares lessons from launching his first company during the dotcom era, building Denim Group, working in the OWASP community, navigating investment and acquisition discussions, and adjusting to life after selling a business. The conversation also looks at how generative AI is changing entrepreneurship. AI coding tools can help founders create prototypes faster and with fewer resources, but a working product is no longer enough to create a sustainable company. Tony and Dan discuss why founders need more than an idea, what investors look for in AI startups, and how proprietary data, distribution, customer relationships, network effects, and audience growth can create a genuine competitive advantage. Topics covered in this episode include: • Lessons from building a company during the dotcom era • How AI is lowering the barrier to creating software • The difference between building a prototype and operating a real product • Why technical knowledge still matters in the age of AI coding tools • What investors look for in cybersecurity and AI startups • Why an easily copied product does not have a defensible moat • How proprietary data, distribution, and audiences create long-term value • The risks of building a company around an AI feature that may become obsolete • How entrepreneurs can build an audience around a new product • Why founders need self-accountability, resilience, and persistence • What founders should understand before accepting venture capital • Why business exits take longer and change more often than expected • Preparing for legal, financial, and technical due diligence • The emotional and professional identity shift that can follow an acquisition Dan also explains why founders need to understand their personal goals before pursuing aggressive valuations or venture-backed growth. A large valuation may sound attractive, but it can place the company on a path that does not match what the founder actually wants. This episode is a practical and candid discussion for cybersecurity founders, startup operators, investors, technical leaders, and anyone considering building a company in the AI era. The Dirty South Security Podcast is hosted by Tony UV and sponsored by VerSprite. Subscribe for more direct conversations about cybersecurity, application security, entrepreneurship, offensive security, AI, investing, and the realities of building technology companies. #Cybersecurity #Entrepreneurship #AIStartups #AppSec #StartupInvesting #CybersecurityPodcast // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

  2. Jul 20

    Ep.16 - Unhackable AI Is a Myth: Why Companies Need AI Red Teaming with Marek Zmysłowski

    There is no such thing as unhackable AI. As organizations move faster to integrate large language models, AI agents, MCP servers, and automated workflows, attackers are gaining new ways to exploit excessive permissions, trusted data sources, prompt injection vulnerabilities, and weak security controls. In this episode of the Dirty South Security Podcast, we sit down with Marek Zmysłowski, Senior Security Engineer at Microsoft and AI security expert, to examine why offensive AI security and AI red teaming are becoming essential for any organization deploying AI. The conversation explores how artificial intelligence is changing penetration testing, cybercrime, social engineering, malware development, reconnaissance, and large-scale influence operations. Marek also explains why AI does not replace skilled attackers or penetration testers. Instead, it gives experienced operators the ability to work faster, automate more tasks, and scale attacks that previously required considerably more time and technical knowledge. Topics covered in this episode include: • Why the idea of unhackable AI is a dangerous myth • How attackers are using AI to accelerate reconnaissance and exploitation • The growing risk of indirect prompt injection and RAG poisoning • Security concerns surrounding AI agents and MCP servers • Why excessive permissions create serious agentic AI risks • How AI is changing penetration testing and exploit development • The role of human judgment in AI-assisted security testing • Deepfakes, voice cloning, phishing, and AI-enabled social engineering • Data poisoning, propaganda, bias, and geopolitical manipulation • Why business logic vulnerabilities still require human expertise • The importance of threat modeling and continuous adversarial testing • What organizations should know before deploying AI into production Marek also previews concepts connected to his AI model penetration testing training at DEF CON 2026 in Las Vegas. AI is increasing the speed of software development, but speed without security creates a larger and more interconnected attack surface. Building securely is important. Testing continuously is equally important. Subscribe to the Dirty South Security Podcast for candid conversations about cybersecurity, hacking, cybercrime, offensive security, artificial intelligence, and the evolving threat landscape. #AISecurity #AIRedTeaming #Cybersecurity #OffensiveSecurity #PenetrationTesting #DEFCON // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

  3. Feb 26

    Ep. 15 - We Replicated the Anthropic AI Espionage Report… and Claude Code Lied

    Did Anthropic’s November AI espionage report tell the full story? In this episode of the Dirty South Security Podcast, host Tony UV sits down with returning guest Dan Tentler, Executive Founder at Phobos, to replicate and mythbust Anthropic’s claims that Claude Code autonomously executed a large-scale cyber espionage campaign. Over the course of three days of live testing, we attempted to reproduce the behavior described in the report. What we discovered raises serious questions about AI autonomy, model behavior, safety guardrails, and something even more concerning — Claude Code presenting false information during testing. In this episode we break down: • What the Anthropic November report claimed  • How we attempted to replicate the AI-orchestrated attack scenario  • Where Claude Code failed  • Evidence of deceptive or fabricated responses  • The difference between AI hallucination and intentional-seeming behavior  • What this means for cybersecurity professionals  • Implications for AI governance and enterprise adoption This is not a hot take. This is hands-on testing. If you work in cybersecurity, AI safety, red teaming, or enterprise security strategy, this episode is essential listening. Watch until the end for the full breakdown of what happened during our three-day replication attempt. Subscribe for more deep technical security discussions and mythbusting. #DirtySouthSecurity #Anthropic #ClaudeCode #AISecurity #CyberSecurity #DanTentler #TonyUV #AIHallucinations #AITransparency #RedTeam #Infosec #AIResearch // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

  4. 12/08/2025

    Ep. 14 – Leadership in the AI Era

    Episode 14 – Leadership in the AI Era with Ruby Agarwal (VP Cloud Platform & Operations @ Avaya) The game has permanently changed. AI isn’t coming for your job tomorrow; it’s already rewriting the operating system of every security and technology organization today. In this no-BS episode, Tony UV sits down with Ruby Agarwal to separate leadership theater from what actually works when LLMs, automation, and agentic workflows are collapsing timelines that used to take years into weeks. We get real about: Why the old “I’ve got all the answers” CISO/CIO playbook is now a liabilityMoving from control-freak management to radical curiosity and productive discomfortHow to build actual AI fluency in your teams without turning everyone into a prompt engineerRedefining performance when AI eats 70% of the repetitive work SecOps used to ownWhy ethical guardrails aren’t a “nice-to-have” compliance checkbox; they’re your last line of defense against career-ending mistakesThe hard conversations leaders must have when roles inevitably morph or disappearThree dead-simple moves you can execute this week to stop lagging and start leading the AI waveIf you’re a security leader who’s tired of generic “embrace change” platitudes and wants battle-tested tactics for thriving in the chaos, this is the episode you’ve been waiting for. #Cybersecurity #InfoSec #AILeadership #SecurityLeadership #ArtificialIntelligence #CISO #CloudSecurity #SecOps #Leadership #AISecurity #DirtySouthSecurity // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

  5. 11/10/2025

    Ep. 13 - Small Firms, Big Impact - Why Offensive Security Matters More Than Ever

    🔥 Nobody Got Fired for Hiring IBM... But Maybe They Should Have In this episode of Dirty South Security, we're pulling back the curtain on the security industrial complex. Tony UV sits down with Dan Tentler to discuss why small boutique security firms are running circles around the big consulting giants, and why that matters more than ever in the age of AI. Host: Tony UV Guest: Dan Tentler What We Cover: The Boutique Advantage We break down why procurement processes favor mediocrity, the difference between checkbox security and actual security, and why small firms' "unfair advantages" (speed, skin in the game, and actually giving a damn) are reshaping the industry. Real Offensive Security Most pentests are security theater. We discuss what adversary emulation actually looks like, the attack techniques keeping security professionals up at night (supply chain attacks, LOLBins, modern C2 frameworks), and the massive gap between what vendors sell and what attackers actually do. AI: The Offensive Security Inflection Point When everyone has AI, attack surface becomes intelligence surface. We explore how LLMs are being weaponized for polymorphic malware, why prompt injection is the new SQL injection, and why companies building AI without offensive security expertise are sitting ducks. The Business of Staying Small and Deadly Why we don't want to be a 500-person firm, the scaling trap that kills quality, and how to build sustainable boutique practices through high-value, low-volume models. Hot Takes & Hard Truths We tackle controversial topics: Are most cybersecurity certifications worthless? Is MITRE ATT&CK just intimidating wallpaper? Zero trust products vs. real zero trust. Bug bounties: innovation or race to the bottom? The ethics of red teaming and where we draw the line. Key Takeaway: If your security team can't think like attackers, you're already compromised. // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

  6. 08/08/2025

    Ep. 12 - AI in Offensive Security - Cutting Through the Hype

    Episode 12 - AI in Offensive Security: Cutting Through the Hype  Host: Tony UV - https://www.linkedin.com/in/tonyuv/ Guest: Andrew Wilson - https://www.linkedin.com/in/awilsonaz/ Is AI revolutionizing offensive security, or simply accelerating what humans already do? In this episode, we cut through the hype and get real about how AI is reshaping vulnerability discovery, exploit development, and red team operations. 🔍 Topics Covered: 1. AI-Powered Vulnerability Discovery - Static analysis vs LLMs - AI-guided fuzzing performance - Signal-to-noise improvements - Case study: AI vs human researcher - Scaling AI across enterprise vs startup teams 2. Exploit Development Automation - Can AI reliably build working exploits? - Adaptability to target environments - Evasion techniques vs modern defenses - What red teams are actually using 3. Large-Scale Offensive Operations - AI orchestration across thousands of assets - Prioritization and continuous assessment - Managing AI-generated data - Measuring ROI of AI-enhanced testing 4. The AI Arms Race - Offensive vs defensive AI - Behavioral mimicry and detection evasion - Speed, scale, and resource asymmetry - Autonomous threat modeling 5. Implementation Reality Check - Where to start with AI in OffSec - Tool integration and team training - Budgeting and vendor evaluation - Compliance and regulatory concerns 💡 Whether you're a security leader, red teamer, or just trying to separate signal from noise, this episode delivers practical insights and strategic foresight. 📺 Watch, subscribe, and join the conversation.  #AIinSecurity #OffensiveSecurity #RedTeamOps #ThreatModeling #CybersecurityPodcast #DirtySouthSecurity #VerSprite #TonyUV #AndrewWilson // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

  7. 06/12/2025

    Ep. 11 - Building Resiliency: The New Paradigm in Security Leadership

    In this episode, we’re flipping the script on traditional security thinking. As security champions, we know that resiliency isn’t just a buzzword—it’s the backbone of modern cybersecurity strategy. Join us as we unpack: 🔐 From Security to Resiliency – Were we too confident in the early days of CISO-ship? We reflect on the evolution of security leadership and what it means to lead with resilience today. 🛡️ Is Product Resiliency Subjective? – What really defines a “resilient” product? We challenge assumptions and explore how context, threat models, and business goals shape the answer. ⚙️ Top 3 Fundamentals for CISOs – We break down the core pillars every CISO should build from to create sustainable, secure, and resilient programs or products. 🔥 CISO Hot Takes – No fluff, just real talk. We share bold opinions on what’s working, what’s not, and where the industry needs to level up. Whether you're a CISO, security engineer, or just passionate about building better defenses, this episode is packed with insights to help you lead with clarity and confidence. // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

  8. 05/08/2025

    Ep.10 - Truth in Marketing An Honest Regard on Marketing Cybersecurity RSA 2025

    Welcome to Episode 10 of our Dirty South Security podcast series, where we dive deep into the world of marketing within the cybersecurity industry, especially in the context of RSA 2025. In this episode, we tackle some of the most pressing and controversial topics in the field: Topics Covered: AI Misrepresentations at RSA and Beyond Explore the practice of misrepresenting AI solutions in today's industry. We discuss how these misrepresentations impact trust and the overall landscape of cybersecurity. Marketing Investments: What Works, What Doesn't Get insights into foundational marketing strategies. We share hot takes on what marketing investments yield the best returns and which ones fall flat. Pay-to-Play Models Uncover the dubious paid models that taint the integrity and authenticity of products, people, or services in cybersecurity. We examine how these models affect the industry's credibility. Join us for an honest and insightful discussion that aims to shed light on the truths and myths of marketing in cybersecurity.  // FIND VERSPRITE’S CYBERSECURITY TEAM ONLINE //  VerSprite: https://versprite.com/LinkedIn: https://www.linkedin.com/versprite-llc/Twitter: https://twitter.com/versprite/YouTube: https://www.youtube.com/c/VerSprite // ABOUT VERSPRITE // VerSprite is a leader in risk-based cybersecurity services and PASTA threat modeling, enabling businesses to improve the protection of critical assets, ensure compliance, and manage risk. Our mission is to help you understand and improve your organization’s cybersecurity posture. With cyberattacks increasing in number and sophistication daily, it is crucial to protect your organization’s assets, protect your clients, and maintain the same, excellent reputation and trust you have worked hard to build. We believe that an integrated approach will result in better and more cost-effective security practices and business outcomes.

About

Welcome to the Dirty South Security Podcast! 🌍🔒Join us as we dive into the hottest takes and latest trends in cybersecurity from around the globe. Whether you're a seasoned professional or just curious about the digital world's inner workings, our podcast offers insightful discussions, expert interviews, and thought-provoking analysis on the most pressing security issues today.Stay ahead of the curve with our no-nonsense approach to all things cybersecurity. Subscribe now and never miss an episode!