Legitimate Cybersecurity Podcasts

LegitimateCybersecurity

Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.

  1. 4d ago

    Grok Build Uploaded Your Entire Codebase — Without Asking

    Grok Build reportedly uploaded entire Git repositories—including files it never opened, full Git history, and deleted secrets—to xAI-controlled cloud storage. In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer unpack what that means for anyone allowing an AI coding agent inside a real computer. Independent researcher CerebLab captured Grok Build packaging a complete repository into a Git bundle and sending it to cloud storage after being explicitly told not to read any files. Turning off “Improve the model” did not stop the transfer in the researcher’s test. That does not prove xAI trained on the code. It exposes a different problem: “don’t train,” “don’t transmit,” and “don’t retain” are three very different promises. Frank and Dustin discuss: • Why deleted passwords and API keys can survive in Git history • How AI coding agents gain broad access to your computer • Why developers keep treating security as something to add later • The difference between a breach, a leak, and a breach of trust • Why old code can be more dangerous than current code • What developers should do now: rotate secrets, isolate projects, restrict permissions, and monitor unexpected outbound data IMPORTANT UPDATE: CerebLab reports that whole-repository uploads later stopped after xAI enabled a server-side control. SpaceXAI also promised to delete previously retained coding data and subsequently open-sourced Grok Build. This episode examines the documented behavior before that change—and the trust problem it exposed. Research and updates: https://cereblab.com/ https://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123 Media/interview: mailto:admin@legitimatecybersecurity.com Audio podcast: https://legitimatecybersecurity.podbean.com/ CHAPTERS 00:00 — Grok Build reportedly uploaded whole repositories 01:20 — Why Git repositories are a gold mine 03:19 — Breach, leak, or breach of trust? 04:23 — What AI coding agents actually do 05:20 — Why old code still matters 08:56 — Deleted passwords can survive in Git history 10:41 — “Don’t train” vs. “don’t retain” 12:30 — When an AI codes its own connector badly 14:30 — What affected developers should do now 16:38 — AI agents are becoming highly privileged 19:31 — What system-level AI access can destroy 21:26 — The network anomaly that exposed the upload 22:19 — When bandwidth becomes a security signal 23:43 — Patch quickly—without becoming CrowdStrike 24:34 — The practical takeaway #Grok #GrokBuild #Cybersecurity #DataPrivacy #AICoding #VibeCoding #AIAgents #xAI #GitSecurity #SourceCode #ArtificialIntelligence #LegitimateCybersecurity

  2. Jul 13

    Your Password Isn’t the Weakest Link Anymore

    Hackers no longer need to steal your password. Software vulnerabilities have overtaken stolen credentials as the leading way attackers break into breached organizations. According to Verizon’s 2026 Data Breach Investigations Report, exploitation of software flaws now accounts for 31% of breach entry points. After years of companies concentrating on phishing, password security, and employee training, attackers may have found an easier target: the software itself. Frank Downs and Dr. Dustin Brewer examine why critical vulnerabilities remain exposed for months—even when patches already exist—and how artificial intelligence is changing the speed at which attackers can discover and exploit security flaws. In this episode: • Why software vulnerabilities have overtaken stolen credentials • How AI helps attackers find exploitable flaws faster • Why companies delay installing critical security patches • What the MOVEit breach revealed about patching failures • Why old printers, servers, and business applications remain dangerous • How organizations test patches without breaking production systems • Why network segmentation often becomes cybersecurity duct tape • What vulnerability scanners can—and cannot—detect • How threat intelligence, SOC teams, and vulnerability management should work together • Why the National Vulnerability Database is struggling to keep pace • What organizations can realistically do to reduce their exposure The warning is simple: your password can be perfectly secure, and an attacker may still find another way in. Media/interview: mailto:admin@legitimatecybersecurity.com Audio: https://legitimatecybersecurity.podbean.com/ CHAPTERS 00:00 Hackers don’t need your password 00:07 The new leading way attackers break in 01:09 AI is finding software exploits faster 02:19 MOVEit: The patch existed 02:38 Why critical vulnerabilities remain exposed 03:36 It is always the printer 04:17 Is segmentation just security duct tape? 05:00 Microsoft’s “keep an eye on it” solution 05:50 Testing security patches on Timmy 06:31 Making vulnerability management satisfying 07:10 Excel formatting becomes a professional sport 08:08 Scientists made brain cells play Doom 10:10 The vulnerability-management maturity model 11:38 Software is the weakest link again 13:26 Can AI find unknown vulnerabilities? 14:32 What AI can and cannot fix 15:41 Why vulnerability scanners miss emerging threats 18:14 Connecting SOC, threat intelligence, and vulnerability data 18:52 Why cybersecurity remains a cost center 20:01 The processes that can save an organization 21:16 A high CVSS score is not everything 21:40 Is the National Vulnerability Database falling behind? 24:27 Why old vulnerabilities remain useful to hackers 25:46 Your software is the new password #cybersecurity #hackers #databreach #SoftwareVulnerabilities #PasswordSecurity #ArtificialIntelligence #ZeroDay #PatchManagement #VulnerabilityManagement #VerizonDBIR

  3. Jul 9

    The Surveillance Pricing Trap Retailers Set at Checkout

    A $3 pair of kids’ shoes rang up for almost $19 at checkout. Mistake, dynamic pricing, or something much creepier? In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer break down a viral Walmart pricing story and ask the bigger question hiding behind it: what happens when stores, apps, location tracking, purchase history, and data brokers all meet at the register? This is not just about one pair of shoes. It is about whether the price you see is still the price everyone gets — or whether companies can quietly personalize what you pay based on where you are, what device you use, what you have bought before, and what they think you are willing to tolerate. Frank and Dustin discuss the difference between normal retail mistakes, dynamic pricing, surge pricing, geofenced pricing, and surveillance pricing. They also explain why this gets especially uncomfortable when the products involved are basic needs like food, clothing, and household goods. Main discussion threads: * The Walmart shoe price story * Why a $3 price becoming almost $19 gets people angry * Digital shelf tags and app-based prices * Dynamic pricing vs. surveillance pricing * How GPS, IP addresses, cookies, shopping apps, and data brokers can affect what companies know about you * Why VPNs may not solve the real problem * Why the person at the register is not the villain * What shoppers can do when prices change before checkout The key warning: the future of shopping may not be one price for everyone. It may be one price for you. Media/interview: mailto:admin@legitimatecybersecurity.com Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 The price changed before checkout 00:45 The $3 Walmart shoes story 02:24 The app said $3, checkout said almost $19 02:58 Retail mistake or something bigger? 04:04 Why people trust prices less now 04:50 Delivery apps and dynamic pricing 05:40 Walmart, digital tags, and checkout confusion 07:54 Are we already in the middle of surveillance pricing? 09:01 How location and devices can influence prices 10:49 Why phone GPS changes the game 11:16 Digital shelf tags and backend prices 12:12 The Sam’s Club checkout experiment 13:29 Why VPNs may not save you 14:30 Data brokers and behavioral pricing 17:00 Dynamic pricing vs. surveillance pricing 19:15 Privacy settings may not be enough 21:23 What shoppers can do 22:30 Don’t yell at the cashier 23:25 The price tag may not be the real price #Cybersecurity #Walmart #DynamicPricing #SurveillancePricing #ConsumerPrivacy #DataPrivacy #RetailTech #DataBrokers #LocationTracking #ShoppingApps #DigitalPrivacy #LegitimateCybersecurity

  4. Jul 7

    Your Job Is Training Its AI Replacement

    Your work laptop may be training the AI that eventually replaces you — and Meta just gave us a preview of how creepy that future could get. In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer discuss reports about Meta’s Model Capability Initiative, a program designed to collect employee computer activity such as mouse movements, clicks, keystrokes, and occasional screenshots to help train AI systems. This is not just another “employee monitoring” story. Traditional workplace monitoring was usually framed around security, compliance, or productivity. This is different: the purpose is AI training. That means your daily work behavior could become the dataset that helps AI agents learn how to navigate real software, real workflows, and real human messiness. Frank and Dustin break down why AI agents still struggle with ordinary computer tasks, why companies are desperate for human workflow data, and why “trust us” is not a privacy policy. They also discuss the reported data exposure concerns, the difference between “no indication of improper access” and actual assurance, and what this means for anyone using a corporate device for personal life. Main discussion threads: * Why Meta wanted real employee computer activity to train AI * How AI workplace monitoring differs from traditional enterprise monitoring * Why AI agents still struggle with menus, clicks, and normal workflows * The privacy problem with keystrokes, screenshots, prompts, and performance data * Why “no evidence of misuse” does not mean “nothing happened” * Whether this becomes normal as compute gets cheaper * Why you should stop using your work laptop for personal activity The big warning: if your employer owns the laptop, assume the laptop is not yours. And now, assume AI may be watching too. Media/interview: mailto:admin@legitimatecybersecurity.com Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 Is Meta showing us the future of work? 01:36 What Meta reportedly tracked 02:16 Normal monitoring vs AI training 04:50 Why AI agents need human workflow data 08:04 Is Meta building AI for users — or for extraction? 09:31 Employees, trust, and the 30-minute opt-out problem 15:36 The data exposure issue 17:17 “No indication of improper access” is not enough 20:15 Is workplace AI surveillance here to stay? 23:42 Stop using your work laptop for personal stuff 26:31 Final warning: AI is watching #AI #Cybersecurity #Meta #EmployeeMonitoring #WorkplaceSurveillance #ArtificialIntelligence #Privacy #DataPrivacy #AIAgents #FutureOfWork #TechNews #LegitimateCybersecurity

  5. Jun 29

    Why Cyber War Hasn’t Worked YET

    Most people think cyber war is about better hackers, better tools, and deeper access. But the real danger may be AI turning scattered attacks into coordinated campaigns. In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dustin Brewer talk with Dr. Charlie Harry about why cyber has often been powerful tactically but weak strategically — and why that may be changing fast. Charlie explains why cyber operations need more than individual hacks. They need timing, sequencing, terrain, and operational grammar. In other words: not just breaking into a system, but knowing how to turn cyber activity into campaign advantage. The conversation covers Ukraine, Russia’s cyber failures, logistics systems, ports, rail lines, AI agents, quantum computing, and why the next era of cyber conflict may look less like one big hack and more like coordinated pressure across many fragile systems. Media/interview: admin@legitimatecybersecurity.com Audio: https://legitimatecybersecurity.podbean.com/ Chapters: 00:00 Why cyber war may be misunderstood 01:06 What “cyber is present but peripheral” means 02:16 Cyber optimists vs. cyber skeptics 06:20 The missing grammar of cyber operations 09:05 Cyber effects vs. strategic impact 11:03 Ukraine as the first modern cyber war case study 13:18 Russia’s cyber operations at the start of the invasion 16:29 Why cyber resembles aircraft before World War II 19:46 Cyber terrain is not just a network map 23:35 Building cyber campaigns, not just hacks 25:21 When does cyber become war? 27:30 Cyber fires, effects, and tempo 29:51 How coordinated cyber attacks could disrupt logistics 31:58 Is Russia bad at cyber? 35:17 Could AI solve cyber’s coordination problem? 38:41 AI agents vs. AI defenders 40:10 Why Charlie says the genie is already out 42:55 Why humans still matter in AI-driven cyber 47:11 AI as a new layer on global infrastructure 51:19 Agentic AI, AGI, and what people confuse 54:51 Quantum computing may be closer than expected 57:19 Charlie Harry’s book and final advice #Cybersecurity #CyberWar #ArtificialIntelligence #AIsecurity #CyberOperations #NationalSecurity #CyberDefense #LegitimateCybersecurity #Podcast

  6. Jun 22

    MSG’s Hidden Face Database Just Leaked

    You may have gone to Madison Square Garden for a game or concert. But the bigger question is whether the venue was quietly building a file on you. In this episode of Legitimate Cybersecurity, Frank Downs and Dustin Brewer break down the alleged Madison Square Garden data leak, the ShinyHunters claims, facial recognition concerns, VIP dossiers, biometric surveillance, and why modern venues may be collecting far more information than ordinary fans realize. This is not just a story about hackers. It is a story about what happens when stadiums, arenas, and entertainment companies turn guests into data profiles — and then that data becomes someone else’s leverage. Frank and Dustin discuss: How biometric and facial recognition data changes the risk of attending public events Why “we met best practices” is not always good enough after a breach How extortion groups profit without traditional ransomware Why venues collect data they may not fully understand yet What ordinary people can actually do when opting out is barely realistic Media/interview: admin@legitimatecybersecurity.com Audio: https://legitimatecybersecurity.podbean.com/ Hosted by Frank Downs and Dustin Brewer. Chapters: 00:00 Should you still go to major sporting events? 01:07 What allegedly leaked from Madison Square Garden 02:00 Why venues collect more data than they need 04:19 “Best practices” after a breach 05:17 Oracle, vendors, and third-party risk 09:12 Who are ShinyHunters? 13:29 Token theft, MFA, and modern extortion 14:57 VIP dossiers, face scans, and SSNs 16:08 The privacy regulation problem 18:35 Why companies collect data before knowing its use 21:48 Consent is hard, so systems avoid asking 24:57 Preventable security failures 25:34 Why AI will not kill cybersecurity 28:44 How ordinary people can reduce exposure 30:20 Keep on cyberin’ #Cybersecurity #DataPrivacy #MadisonSquareGarden #FacialRecognition #Biometrics #DataBreach #ShinyHunters #Surveillance #Privacy

  7. Jun 15

    SpaceX IPO: Did You Just Fund a Spy Network?

    The SpaceX IPO is being sold as rockets, innovation, and the future of space. But investors may have also bought into a private network with battlefield, intelligence, and surveillance potential. In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer examine what the SpaceX IPO really means when you look beyond rockets and stock hype. Starlink has already proven how powerful satellite internet can be in remote regions and war zones. Starshield raises an even bigger question: what happens when the same company building consumer satellite internet also builds national-security infrastructure? This is not a claim that SpaceX is spying on Americans. It is a question about capability, incentives, oversight, and public-market funding. If Starlink can shape connectivity in Ukraine and Russia, and Starshield is built for government and intelligence use, what stops similar infrastructure from becoming part of domestic surveillance, border enforcement, emergency response, law enforcement, or classified government operations? And if that happens, would ordinary citizens or retail investors ever know? Frank and Dustin discuss: * Why the SpaceX IPO changes the public-interest question * The difference between Starlink and Starshield * How satellite internet became a war-zone capability * Why private infrastructure can become public power * Whether investors understand what they actually bought * Why regulation always arrives after someone sticks their finger in the pencil sharpener * The uncomfortable line between innovation, profit, warfare, and surveillance Media/interview: mailto:admin@legitimatecybersecurity.com Audio: https://legitimatecybersecurity.podbean.com/ Hosted by Frank Downs and Dr. Dustin Brewer. Chapters: 00:00 - Did SpaceX Just Become the Biggest IPO Ever? 01:06 - Why Everyone Loves Rockets 02:23 - Starlink vs. Starshield Explained 03:52 - Why Starlink Is Different From Old Satellite Internet 05:22 - The Good Side: Remote Access and Global Connectivity 06:41 - How Starlink Changed Modern War 07:21 - Drones, Jamming, Fiber Optics, and Satellite Links 08:44 - Should One Company Control Battlefield Connectivity? 10:46 - Is This Different From Traditional Arms Dealers? 13:22 - Why the IPO Changes the Question 14:45 - Lockheed, Palantir, Boeing, and Public Funding 16:59 - Did Investors Know What They Bought? 17:28 - The Elon Musk Factor and Private Decision-Making 18:52 - Rockets Are Cool — The Implications Are Harder 20:02 - The Hidden Cost of Powerful Technology 22:12 - Starshield and Government Intelligence Contracts 23:23 - When Safety Tools Become Tracking Tools 24:32 - Could Becomes Should: The Jurassic Park Problem 29:32 - Shareholder Value vs. Human Consequences 31:00 - Facebook, Terrorists, and “We Just Connect People” 35:32 - Why Regulation Exists 37:23 - Who Should Decide Who Gets the Network? 38:33 - Final Thoughts: Know What You Invest In #spacex #starlink #Starshield #cybersecurity #surveillance #ipo #privacymatters #nationalsecurity #techethics #legitimatecybersecurity #ai

Ratings & Reviews

5
out of 5
2 Ratings

About

Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.

You Might Also Like