Breach Please

Breach Please Team

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.

  1. Sep 11

    S0:E31 — They Did Everything Right, and Still Got Burned

    Trezor disclosed a breach affecting roughly 67,000 US customers, data from orders placed between November 2019 and August 2021. The twist: Trezor had repeatedly requested and received written assurance that this data was deleted, in line with their contract and data policy. It wasn't. Jess and Jake use this as a real-world case study in third-party risk management, why "right to audit" is often a paper tiger control nobody budgets to actually use, and why this is the exact kind of story to proactively brief leadership on before it happens to you. Second half: a wave of CVEs in PaperCut, the managed print service used heavily in schools and enterprises, letting attackers remotely take over print servers running as SYSTEM. Jess and Jake talk through why that's a bigger deal than it sounds (credential theft, lateral movement, and every sensitive document that crosses the print queue), why these servers so often end up exposed to the internet, and how to actually think about vulnerability risk beyond raw CVE counts. In this episode: Trezor's breach: third-party vendor data that should have been deleted years ago, wasn'tWhy "right to audit" contract language rarely gets used, and what to do insteadReducing blast radius: don't retain data you don't need, and if you must, wall it off behind a jump boxHow to brief leadership proactively: "we can do everything right and still get burned"PaperCut's remote takeover CVEs: SYSTEM-level access, credential theft, and lateral movementWhy print servers end up internet-exposed (BYOD, guest Wi-Fi, mobile printing)CVE count vs. actual risk: reading vulnerability history like an engineer, not a scorecardA tone-deaf vendor sales pitch that used their own vulnerability disclosures as a selling point Breach Please is a production of JWJH Media LLC. The opinions of our hosts are their own. Nothing in this episode is legal, financial, or security advice. Do your homework before pointing anything we said at prod.

  2. Sep 8

    S0:E29 — The GRE Tunnel That Wasn't in the Config

    Sygnia published new research on Fire Ant, a threat actor they first tracked in 2025 around hypervisor espionage against vCenter and ESXi. The new report covers something rarer: live compromise of Cisco IOS XR network devices, discovered because a responder noticed a GRE tunnel in network monitoring that didn't exist in the running config and left no trace in the logs. Jess and Jake walk through what that means for defenders, why IOS XR being Linux-based changes the economics of building a backdoor, and why "compromised network devices" remains one of the most underappreciated categories of incident today. They also get into the ongoing mess of threat actor naming conventions (why one group can have a dozen different names across vendors, and why that's not just marketing), and revisit an earlier debate: is network device security part of zero trust, or a separate problem? Jake asked the internet. The internet had opinions. In this episode: Why one threat actor group ends up with a different name at every vendor, and why that's harder to fix than it soundsFire Ant: Sygnia's research on Cisco IOS XR compromise and a GRE tunnel that left no trace in logs or saved configWhy IOS XR being Linux-based lowers the cost of building a persistent backdoor from six figures to a scripting problemThe running-config-vs-saved-config trap during incident responseWhy unencrypted internal traffic means a compromised network device gets credentials, not just topologyMan-in-the-middle terminology, RC4, Kerberoasting, and why alerting on SPN enumeration breaks down for an on-path attackerWhy network device security has to be part of zero trust, not an asterisk on it Breach Please is a production of JWJH Media LLC. The opinions of our hosts are their own. Nothing in this episode is legal, financial, or security advice. Do your homework before pointing anything we said at prod.

About

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.