Scinary Information Nexus

Scinary Cybersecurity

Scinary Cybersecurity is here to "Serve and defend those who serve and defend others". To help us "serve and defend" we pull from many different sources - experts, colleagues, industry standards, etc... We hit every subject from all angles making it easy to understand while also letting us go in depth. Making this podcast perfect for cybersecurity beginners and experts alike. Come join us on our journey to constantly educate ourselves and explore the amazing things that are happening in our industry.

  1. 1d ago

    Episode 52: K-12 Cybersecurity & Third-Party Risks with Matt Wilkin

    Welcome back to the Scinary Information Nexus! After a quick laugh about a temporary face tattoo prank (sorry, Richard), we sit down with Matt Wilkin, who manages the network and technology infrastructure for Godley ISD. This week, Richard, Joseph, and Brazos chat with Matt about his 17 years in K-12 IT. They cover everything from turning a four-story football stadium into classrooms to the time a squirrel and a lightning strike took down the school's entire network. We also look at the growing threat of third-party and fourth-party vendor breaches, including a recent Clever report showing that third-party breaches now account for 32% of all K-12 incidents. We then discuss a major problem in incident response: 71% of education organizations hit by ransomware have their backups compromised. The crew talks about the pros and cons of tools like ChatGPT and Claude, and why foundational networking knowledge is critical before relying on modern AI shortcuts. Finally, Matt shares some great advice on how IT professionals can securely "pave the road" for staff instead of just being the "minister of no." In this episode, we discuss: A hilarious meme folder and Richard's face tattoo prank Matt's wild K-12 IT stories, including a squirrel-induced network outage Why third-party breaches in education now make up 32% of incidents The hidden risks of fourth-party vendors like Snowflake Why 71% of education ransomware backups fail and how to test restores How AI tools like Claude are eroding foundational IT skills Strategies for IT admins to support staff without being the "minister of no" How often does your organization actively test its backup restore process? Let us know in the comments below! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 03:45 Matt Wilkin's K-12 IT Journey 18:00 AI Tools vs. Foundational IT Skills 29:30 Third-Party Risks & Decentralized Data 37:30 Why 71% of Ransomware Backups Fail 44:30 Hard Truths & Advice for IT Admins Cybersecurity #InfoSec #Ransomware #EdTech #ThirdPartyRisk

  2. Jul 17

    Episode 51: Anthropic Lawsuit & Broken CVEs

    Welcome back to the Scinary Information Nexus! Mario kicks things off in a cowboy hat to mourn a Mexico soccer loss, and the team tries a mysterious Spanish "potion of prosperity" courtesy of Thet. We jump into the trademark fight between Anthropic and email security platform Abnormal AI over a slanted "A" logo. Is this a PR stunt from Abnormal AI or a real warning shot? We also talk about the risks of "vibe coding" and what happens when your entire startup is built on someone else's AI model without a defensive moat. Later, we play a round of "Hot Take or Hard Truth" regarding the broken CVE system. The industry is staring down a projected 66,000 vulnerabilities in 2026, and NIST's NVD is barely keeping up. We explain why panic-patching is no longer a viable strategy, how to set up a risk-based patching plan, and why defense in depth matters when the vulnerability count gets this high. In this episode, we cover: Mario's cowboy hat and Thet's "potion of prosperity" Anthropic suing Abnormal AI over a slanted letter, plus the irony of disgorged profits The real dangers of AI dependency and lacking a defensive moat Why the traditional CVE system is breaking under 66,000 projected vulnerabilities NIST's NVD failing to enrich new vulnerability submissions Shifting from CVSS 10 panic-patching to risk-based security Relying on defense in depth when you fall behind on patching Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 05:00 Anthropic Sues Abnormal 15:30 The AI Dependency Problem 27:30 Hot Take: The CVE System is Broken 36:00 Risk-Based Patching 44:00 Upcoming Guests & Live Announcement Cybersecurity #InfoSec #Hacking

  3. Jul 3

    Episode 50: From Blackberries to Wiretaps: Presidents and Tech History

    Welcome back to the Scinary Information Nexus! After a funny mishap where the crew "pre-gamed" a little too hard and had to scrap Friday's recording, we're back on track with a special Tuesday episode. With the 250th American Independence Day coming up, we're taking a break from heavy cyber news to play a game of presidential tech trivia. This week, Richard challenges Joseph, Mario, and Brazos to test their knowledge on the history of technology in the Oval Office. We talk about Obama's battle with the NSA to keep his BlackBerry, and how the first televised debates changed politics. We also look at wild historical rumors, like Civil War soldiers supposedly wiretapping telegraph lines using their tongues to feel the electrical pulses - a theory the guys jokingly threaten to have the SOC analysts test. To close out the episode, we cover some serious industry news regarding the FCC reviewing USAC and the potential defunding of the E-rate program, which could severely impact school tech funding. Plus, we share updates about our July 30th live stream and where you can catch the Scinary team at regional conferences! In this episode, we discuss: The reason we had to scrap our original recording. Why Barack Obama fought the NSA and Secret Service to keep his BlackBerry. How the 1960 Nixon-Kennedy debates shifted political focus to visual optics. Wild Civil War espionage: cracking the Vicksburg cipher and "tongue" wiretaps. The history of the White House telephone and why it wasn't private until 1993. Security lessons behind Hillary Clinton's private email server. Updates on the FCC reviewing USAC, the E-rate program, and what it means for schools. Which piece of presidential tech history surprised you the most? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 04:30 Presidential Tech Trivia & Security Standards 09:15 TV Presidents & The Importance of Optics 12:45 Civil War Ciphers & White House Telephones 18:15 Stripped Blackberries & Presidential Emails 22:15 Radio Debuts & Civil War Tongue Wiretaps 28:45 Secure by Design & Political Photos 34:15 E-Rate Defunding Concerns & Nerd Lore Cybersecurity #InfoSec #Privacy

  4. Jun 19

    Episode 49: Breach or BS: Testing our Cyber Knowledge

    This week on the Scinary Information Nexus, the crew takes a much-needed break from the endless AI chatter to play a game of Breach or BS. Join Richard, Joseph, Hunter, and newly promoted team member Thet for some office banter before we get down to business. We test our knowledge on some of the wildest cyber attacks in recent history. Can you guess which bizarre incidents are real and which are total fiction? From ransomware demands printed directly on a victim's hardware to cartel-orchestrated insider threats, we cover it all. We also talk about how vulnerable IoT devices put critical infrastructure at risk. We revisit the classic story of a casino breached through a fish tank thermometer, along with traffic light hacks and remote attacks on municipal water plants. Plus, Richard shares a funny vendor negotiation story where a simple CC vs. BCC email mistake gave him the upper hand. In this episode, we cover: Ransomware gangs printing extortion letters on a victim's own printers The dangers of insider threats and cartel infiltration How a simple email CC/BCC mistake can ruin a vendor negotiation The infamous casino hacked through an internet-connected fish tank Hackers targeting traffic light systems and municipal water plants Taking down North Korea's slant 24s in retaliation What is the craziest cyber attack you've ever heard of? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 03:30 AI Fatigue & SpaceX Wealth 05:15 Ransomware by Mail & Insiders 13:45 Fish Tank Hacks & Traffic Cams Cybersecurity #InfoSec #Ransomware #InternetOfThings #IoTSecurity #InsiderThreats #DataBreach #Hacking #CyberAttacks

  5. Jun 12

    Episode 48: Is AI Replacing Your Job or Just Burning Billions?

    Welcome back to the Scinary Information Nexus! After a slightly chaotic start involving rescue farm animals and Mario's battle to open a bottle of raspberry melomel, the guys sit down to talk about what's really happening behind Silicon Valley's biggest promises. This week, Richard, Joseph, Mario, and Brazos look at the current state of AI in the enterprise. Are companies actually replacing workers with AI, or are we just seeing an "automation paradox" where these tools need even more human oversight? They compare today's massive AI infrastructure spending to the historical railroad expansion, while pointing out the real risks of "model death" and feeding your company's data into third-party systems. The conversation also covers the financial side of the tech industry right now. We talk about the intertwined upcoming IPOs of SpaceX and Anthropic, and question the massive $1.77 trillion valuation SpaceX is eyeing. From index fund rule changes forcing passive investments to AI hallucinations claiming there are "three fish in the days of the week" (shoutout to Kevin Beaumont for finding that one), we cut through the latest tech hype. In this episode, we discuss: The "Automation Paradox" and why AI actually requires more human oversight. Real-world AI failures and why companies are hiring humans back. What "model death" is and why training AI on its own data ruins the output. The risks of feeding your proprietary data into third-party AI models. The financial engineering behind the SpaceX and Anthropic IPOs. How index fund rule changes force you to invest in inflated tech stocks. A post-credits guide on the proper white-glove technique for opening wine. Is the current AI boom a true industrial revolution, or just modern snake oil? Let us know what you think in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 18:30 The AI Labor Replacement Reality 33:15 Is AI the New Snake Oil? 44:30 SpaceX & Anthropic IPO Bubbles 59:30 Post-Credits: Opening Wine Correctly Cybersecurity #InfoSec #TechBubble #MachineLearning #Investing

  6. Jun 5

    Episode 47: K-12 Cybersecurity: Student Shadow IT & Vendor Breaches

    Welcome back to the Scinary Information Nexus! This week, we're taking a field trip into the wild world of K-12 IT. Richard sits down with Jack, Alice, and Tom - a trio of IT professionals from a rural Texas school district - to swap stories from the educational trenches. They kick things off by proving you don't need a traditional IT background to thrive in cybersecurity, sharing how past careers in teaching and culinary arts shaped their problem-solving skills. We also get into the daily battle of securing educational networks without disrupting the learning process. From students building hidden "shadow IT" on Google Sites to bypass web filters, to managing third-party risks like the Instructure breach, keeping a school online takes serious work. The team wraps up by debating AI in the classroom. We break down whether tools like ChatGPT and Gemini act as a crutch for students or a hammer for building deeper knowledge. In this episode, we discuss: Unconventional paths into tech and the value of STEAM. How kids are creating "shadow IT" to bypass CIPA web filters. The recent Instructure breach and third-party vendor risks. Why compliance tags like FedRAMP and TX-RAMP don't guarantee security. Navigating cloud data sprawl across Google Drive and Office 365. The "hammer vs. crutch" debate on AI in education. Why the future of school IT relies on biometric MFA and passphrases. Do you think AI in the classroom is a helpful tool or a shortcut to skip learning? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 22:00 Battling Student Shadow IT 32:45 Third-Party Vendor Breaches 41:30 AI in Education: Hammer vs. Crutch 51:15 The Future of Passphrases & MFA Cybersecurity #InfoSec #K12Cybersecurity #EdTech #ShadowIT #ArtificialIntelligence #DataPrivacy #ThreatIntel #SchoolIT #EducationTech

  7. May 29

    Episode 46: Verizon DBIR 2026: Why Vibe Coding is Fueling Exploits

    Welcome back to the Scinary Information Nexus! While Richard Martin is away, Brazos Wortham, Joseph Hamilton, and Mario Ortiz take the helm. They crack open some Texas Meadworks blackberry melomel to break down the 2026 Verizon Data Breach Investigations Report (DBIR). The crew talks about a massive shift in the industry: vulnerability exploitation has officially overtaken credential abuse. We also talk about "vibe coding" -- developers using AI to write code they don't fully understand. This trend causes up to 62% of AI-generated code to ship with vulnerabilities. Plus, we debunk Hollywood myths about polymorphic AI malware and see how threat actors actually use AI to draft phishing emails and speed up attacks. We review the surprising drop in ransomware payments, noting that 69% of victims now refuse to pay. What happens when the money dries up? The guys predict a pivot toward public website defacement and data destruction from groups like Shiny Hunters. They also share practical advice on risk-based vulnerability management. In this episode, we discuss: What the 2026 Verizon DBIR reveals about initial access vectors. A disastrous DIY absinthe experiment involving wormwood and gin. How "vibe coding" is flooding code repositories with vulnerabilities. The truth about AI malware and how attackers actually weaponize it. The patching ceiling: why organizations tap out at fixing just 30-40% of vulnerabilities in the first week. Why 69% of ransomware victims refuse to pay. A pro-tip for reading the DBIR without giving up your personal data. What's your biggest takeaway from this year's DBIR? Let us know in the comments below! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 05:15 Blackberry Melomel & DIY Gin 09:45 Exploits Overtake Credential Abuse 15:30 Vibe Coding & AI Threats 33:00 The Limits of Patching 58:30 Declining Ransomware Payments Cybersecurity #InfoSec #VibeCoding #Ransomware #DBIR #Malware #ArtificialIntelligence #DataBreach #ShinyHunters #Vulnerability

  8. May 22

    Episode 45: Is Your School's Tech Now Illegal In Texas?

    Welcome back to the Scinary Information Nexus! Pour yourself some mead (or a Texas ale) and join the crew as we tackle some heavy cybersecurity news hitting the K-12 and higher-ed worlds. This week, Richard Martin, Brazos Wortham, Joseph Hamilton, and Mario Ortiz break down the fallout from the Instructure (Canvas) breach. Threat group Shiny Hunters reportedly exploited a cross-site scripting vulnerability, leading to a massive, undisclosed ransom payment. Now, school districts are stuck in a regulatory nightmare: how do you report a breach when you don't even know what student data was compromised? We also talk about the debate over state bans on Chinese-owned technology like Lenovo. While Texas Cyber Command maintains a strict Prohibited Technologies list for state agencies, Lenovo currently remains unbanned despite federal security warnings. We look at the reality of outright hardware bans versus just blocking network traffic. Plus, we clear up the dangerous confusion between Lenovo-owned Motorola Mobility and American-owned Motorola Solutions (which emergency services use). Expanding these state mandates could be a devastating financial hit to public schools already dealing with budget deficits. In this episode, we discuss: How Shiny Hunters breached Instructure via a "Free for Teacher" account The regulatory nightmare of reporting K-12 data breaches Why easily guessable passwords make brute-forcing simple Texas Cyber Command's recent updates to the Prohibited Technologies list The danger of banning network domains instead of replacing vulnerable hardware Why confusing Motorola Mobility with Motorola Solutions could panic police and emergency services How state mandates impact independent school districts that are already struggling Does the state's approach to cybersecurity actually make schools less secure? Let us know your thoughts in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 02:15 The Canvas Ransomware Breach 34:15 Texas Cyber Command's Lenovo Ban Cybersecurity #InfoSec #Ransomware #EdTech #TxRamp

5
out of 5
5 Ratings

About

Scinary Cybersecurity is here to "Serve and defend those who serve and defend others". To help us "serve and defend" we pull from many different sources - experts, colleagues, industry standards, etc... We hit every subject from all angles making it easy to understand while also letting us go in depth. Making this podcast perfect for cybersecurity beginners and experts alike. Come join us on our journey to constantly educate ourselves and explore the amazing things that are happening in our industry.

You Might Also Like