ZeroSum

Aaron Mog

ZeroSum is a new cybersecurity podcast that aims to talk honestly about the state of the cybersecurity industry. The show rejects standard "threat of the week" news breakdowns and instead focuses on the reality of the market. Viewing the industry through the lens of game theory, the podcast explores how the current cyber market is no longer a rising tide that lifts all boats; for massive VC gambles to win, the burnt-out practitioners on the ground are often the ones losing. The show features guests from all perspectives, including vendors, investors, workers, and CISOs.

  1. 5d ago ·  Video

    AI Attacks That Take Six Months, Not Six Minutes - with Jackson Reed

    Jackson Reed built the red team at the US Army Corps of Engineers and took it through certification, then spent four years rebuilding and leading Target's. He isn't worried about swarms of agents overwhelming your SOC — defenders are good at bursty and anomalous. What concerns him is the operator with ten thousand actions a day of compute budget who spends ten of them, in each of a thousand environments, for a year. We get into what a six-month timeline does to log retention and correlation windows, the two opposite ways red teams fail, why the frontier labs stopped measuring what matters in their system cards, and the Bronze Age analogy that explains most of the AI tooling being built right now. TIMESTAMPS 0:00 Cold Open 1:14 Meet Jackson Reed 6:29 Are You Hopeful or Upset? 12:33 Patience Beats Zero-Days 21:21 Agents Criminals Don't Have to Trust 24:01 Red Teaming in a Hall of Mirrors 29:46 Can AI Clone a World-Class Red Team? 33:35 What's Actually Scalable with AI 38:05 One Frontier Model, or Ten Thousand Custom? 40:58 AI Overkill: When Less Is More 44:58 YOLO Security 46:08 Chinese Models and Who Has Your Data 52:05 Barding: Can You Handle an Intrusion? 53:32 What System Cards Stopped Measuring 1:02:35 AI's Bronze Age 1:07:34 Holding an Industry Hostage 1:10:44 Where to Find Jackson ABOUT JACKSON Jackson Reed studied international affairs before moving into computer science through the CyberCorps Scholarship for Service. He did think tank and SOC analyst work, then threat attribution and intelligence analysis at CrowdStrike, built and led the red team at the US Army Corps of Engineers through certification, and rebuilt and led Target's. He launched Barding Defense in March and works with BT6 on assessments and jailbreaking for frontier labs. Blog: twelvetables.blog Barding Defense: bardingdefense.com #cybersecurity #redteam #aisecurity #threatintel #infosec #aiagents

  2. Sep 28 ·  Video

    AI Doom, and Why We Can Still Unplug the Servers - with Greg Ose

    Everyone's quitting a lab to warn us about the end of the world. Greg Ose, who has spent his career building product security programs from the inside and now does it at GitHub, isn't buying the hysteria — and his reason is boring in the best way. We built this. We can explain, step by step, how every one of these incidents actually happened, including the recent one the industry summarized as "our AI model hacked the company." Nothing mysterious is going on. And if it really came to it, we can still unplug the servers. What Greg thinks is actually worth worrying about isn't the technology getting away from us. It's whether anyone is funding the safety work at the same rate they're funding the growth. That's the last stretch of the conversation. The rest is the specifics of living with it right now: why AppSec is suddenly sucking all the oxygen out of security, whether developer security training was ever really working, why a paved path is a tier-zero product and not something one engineer writes in a week, what prompt injection looks like once you treat the agent as the most socially engineerable employee on your payroll, and why Greg thinks we should all just assume a dependency is going to be compromised and design for blast radius instead. Also: the Uber problem with AI pricing, the trust-pocalypse, and what Greg tells a 22-year-old who walks up at a con and asks how to get into security. CHAPTERS 0:00 Cold Open 0:53 Intro 1:01 Meet Greg Ose 2:33 AI hit AppSec all at once 5:51 What do you do with infinite vulnerabilities? 7:57 The supply chain was always fragile 12:53 Why AppSec money came roaring back 18:01 The people setting the fires 20:52 Does a pull request still mean anything? 25:54 Teaching security wisdom to models 28:59 Paved paths and who pays for them 33:27 "From scratch" and the token economy 36:21 Why Greg is still optimistic 42:42 Trust in a hall of mirrors 44:56 Reduce the blast radius, not the trust 50:19 Assume a dependency is compromised 53:40 Is AI going to end the world? 58:37 How to get into security now GUEST Greg Ose — GitHub https://www.linkedin.com/in/gregose/ ZEROSUM Hosted by Aaron Mog https://yellowteam.ai

  3. Sep 21 ·  Video

    EDR Gives Attackers Up to a 10-Minute Head Start - with Tim MalcolmVetter

    Tim MalcomVetter says every major EDR runs a two-to-ten-minute ingestion delay, and that it hands attackers a head start no AI SOC can close. The fix, he argues, isn't more AI. Tim ran a red team at Walmart, co-founded Wirespeed, and now runs incident response at Coalition, the cyber insurer that acquired it. That's a rare seat. He can tell you what a vulnerability actually costs, because his employer writes the check. We get into why the most expensive way to do security is people, the second most expensive is AI, and the cheapest is the deterministic code nobody wants to build. Why Wirespeed, an "AI SOC," uses AI in fewer than 2% of its verdicts. The vendor that burned $5 in tokens deciding to look up an IP address, a job deterministic code does in 20 to 30 milliseconds. Why most CISOs couldn't name their cyber insurance carrier a year ago. And the week Coalition scanned more than 100,000 companies for React2Shell, found 20 web shells, and didn't see a single claim. CHAPTERS 0:00 Cold open 0:50 Intro 2:27 Blue team first: how a defender became a red teamer 4:27 "We're not solving problems, we're just spending money" 6:57 The AI hype cycle is just relational databases again 8:52 People, AI, deterministic: the real cost hierarchy 10:17 "AI is not hard work. AI is cheating" 11:49 Founding Wirespeed and the race to the autonomous SOC 17:26 "I have to feel the shell": automating the red team 24:30 Mach 2.5 vs Mach 5: the air defense analogy 26:00 Usain Bolt's two-to-ten-minute head start 27:24 The Mexican government breach: one operator, one AI agent 33:12 $5 in tokens to decide it needed an IP enrichment 34:19 "Bring your own Claude license" and other red flags 37:06 Why a security founder ended up in insurance 39:52 Do you know who your cyber carrier is? 43:49 Brown bananas: how underwriting actually works 46:40 CrowdStrike's million-dollar policy 49:30 The IR retainer trap 53:22 React2Shell: 100,000 companies, zero claims 56:52 Custom code isn't where breaches come from 1:00:12 Identity, BEC and the $25M inbox 1:01:47 What's the next fad after AI? ABOUT TIM Tim MalcomVetter started his career on defense before moving into offensive work, including running a corporate red team at Walmart. He co-founded Wirespeed, an automated detection and response platform that Coalition acquired in November 2025. Incident response at Coalition, roughly 1,500 cases a year, now rolls up to him. Wirespeed: https://wirespeed.co Coalition: https://www.coalitioninc.com Find Tim on LinkedIn. ZeroSum is a podcast about what's actually happening in cybersecurity, not what the vendors say is happening. Practitioners, founders and operators, talking honestly about the work.

  4. Sep 14 ·  Video

    AI, Ransomware, & The Security Poverty Line - with Randy Rose

    Is AI closing the cybersecurity gap between big cities and small towns — or leaving under-resourced communities even further behind? In this episode of ZeroSum, Aaron sits down with Randy Rose, Vice President of Security Operations & Intelligence at the Center for Internet Security (CIS), to expose what's actually happening on the front lines of state and local government cybersecurity. Randy leads the operational missions of the MS-ISAC (Multi-State Information Sharing & Analysis Center). We dive into how ransomware crews are targeting rural school districts, why threat actors are using AI to clone writing styles for phishing, and why treating AI as a "prediction engine" rather than intelligence fundamentally changes your defense strategy. If you are a security practitioner, local government leader, or trying to break into the industry, this episode breaks down the realities of the security poverty line and what happens when a threat actor picks a small town for a payday. 🎯 What we cover: The security poverty line — and why AI might not fix itHow threat actors use generative AI for highly convincing phishing and BEC emailsThe real human cost when ransomware hits a rural hospital or school districtWhy "it's just a prediction engine" matters more than you thinkActionable advice for people trying to break into cybersecurity right now ⏱️ Chapters: 00:00 Cold Open 01:21 Introduction to the Cybersecurity Landscape 03:21 State vs Local Government Cybersecurity 06:13 Understanding the Multi-State ISAC 10:20 The Role of ISACs in Cybersecurity 12:00 Challenges Faced by Local Governments 14:50 AI's Impact on Cybersecurity 20:04 Ransomware and Business Email Compromise 24:35 Operational Technology and Municipal Challenges 25:51 Generative AI: The Great Democratizer? 32:26 Leveraging AI for Cybersecurity Skills 32:58 The Complexity of AI in Cybersecurity 35:52 Wisdom vs. Intelligence in Cybersecurity 40:11 The Growing Challenge of Cybersecurity 46:16 Building a Strong Cybersecurity Foundation 53:18 Advice for Aspiring Cybersecurity Professionals 🎙️ ZeroSum is a cybersecurity and AI podcast hosted by Aaron and Randy, digging into the real conversations security practitioners are having about AI, risk, and the future of the industry. #Cybersecurity #ArtificialIntelligence #Ransomware #InfoSec #ZeroSumPodcast

  5. Sep 7 ·  Video

    The AI Hacker Myth - with Silas Cutler

    Is artificial intelligence actually creating a new breed of super-hackers, or is the industry just selling panic? In this episode of the Zero Sum Podcast, Aaron sits down with Silas Cutler, one of the top security researchers in the industry and a Principal Reverse Engineer at Censys. Silas strips away the corporate marketing hype to reveal what threat actors are actually doing in the wild. They dive deep into the economic realities of cybercrime, how Russian military intelligence (APT28) hijacks criminal botnets, and the deadly, real-world risks of private companies legally "hacking back" against ransomware cartels. Whether you are a seasoned threat intel analyst, a security leader trying to understand the AI landscape, or an aspiring researcher looking to break into the field, this conversation provides a rare, unfiltered look into the trenches of cybersecurity. Timestamps / Chapters: 00:00 - Intro: Welcoming Silas Cutler to Zero Sum 01:36 - The State of Security Research Today 04:15 - Why Research is Underfunded (And Why That's Okay) 07:44 - Debunking the AI "Vulnerpocalypse" Hype 13:54 - How Threat Actors Actually Scale Their Operations 18:24 - Team PCP & The Rise of Supply Chain Attacks 22:00 - Google's "Beautiful Paranoia" vs. Unprepared AI Startups 29:12 - Is Ransomware a "Solved Problem"? 32:01 - Unmasking Russian APT28 and the Moobot Hijack 38:30 - Red on Red: When Cybercriminals Hack Each Other 39:53 - Letters of Marque & The Deadly Reality of "Hacking Back" 50:40 - Career Advice: How to Break Into Threat Research Follow Zero Sum & Our Guest: Subscribe to the Zero Sum Podcast: https://www.youtube.com/@zerosumpodcastFollow Silas Cutler on X / LinkedIn / MastodonHosted by Aaron Mog

  6. Aug 31 ·  Video

    What AI Just Exposed About Your Data - with Ward Balcerzak

    An employee typed his own name into Copilot and found out he was on the layoff list. Nobody hacked anything. Years earlier someone had used "share with all" in SharePoint, back when nobody could realistically guess the link. Then AI made everything trivially findable. Ward Balcerzak is Field CISO at Sentra with nearly two decades in data security across Accenture, Allstate, Carbon Black, and Fidelity National Financial, where he led data protection and insider risk programs. He also hosts the Guardians of the Data podcast. Aaron and Ward get into what data security looks like now that every employee is pasting company data into tools nobody approved. Ward's argument: the work organizations skipped for years — data discovery, classification, access hygiene — is exactly what AI is now dragging into the light. He also makes a contrarian case for protecting less. Nine times out of ten, the data companies are frantic about isn't special at all. Figure out what actually makes you different, find out who really has access to it, and start there. They cover why DLP earned its bad reputation, what to do when your tools hand you a million findings and no way to act on them, why regulators always arrive last, and why networking is now non-negotiable even for people who got into this field specifically to avoid people. Guest: Ward Balcerzak, Field CISO at Sentra. Find him on LinkedIn, at wardbalcerzak.com, or on the Guardians of the Data podcast. ⏱️ CHAPTERS 00:00 Intro 01:25 Twenty years of being wrong about what catches on 04:39 Can AI actually save data security? 09:30 The era of YOLO security 12:00 "AI readiness" and why nobody's ready 14:43 Sins of the past, now with petabytes 17:06 Are companies building their own models? 26:30 It's not a cat anymore, it's a mountain lion 28:16 The rigged casino of AI watermarking 29:24 Where are the actual wins? 30:59 Nine times out of ten, your data isn't special 33:48 Who actually has access? 35:09 The Copilot layoff list story 37:06 A million findings and no idea what to do 45:33 Forcing the conversations nobody wants to have 47:21 What to tell a 22-year-old today 50:26 Network, even if you got into this to avoid people 54:47 Pitch slapping and the value of being real 56:03 Where to find Ward #cybersecurity #datasecurity #AI #infosec #CISO

  7. Aug 24 ·  Video

    Why Every Cyber Company Sounds the Same - with Joel Benge

    Every CISO or engineer who's ever been told no by a board should watch this. Joel Benge spent years as the communications lead for the Department of Homeland Security's CISO office before writing "Be a Nerd That Talks Good." He's spent his career on one problem: getting technical people the budget, the headcount, and the buy-in they deserve — and figuring out why they so often don't get it. Aaron and Joel get into why most board decks fail before slide three, the "blank stare moment" that happens when you overload your audience, and the reframe that changes everything: you're not the hero of your pitch — you're Obi-Wan, and the person you're asking is Luke. Plus why the stories you least want to tell (the failures, the things you tried that didn't work) are the ones that actually build trust. They also get into why every vendor booth at Black Hat says the exact same thing, why "we prevent hacks" is a Gartner category and not a big idea, and how to align a security ask to something the business already cares about — instead of another slide full of blocked-attack metrics nobody reads. If you've ever needed a million dollars for a program and walked out with nothing, this is the episode. Guest: Joel Benge, author of "Be a Nerd That Talks Good." Find him at nerdthattalksgood.com or on LinkedIn — the intro and first chapter are free, no email required. ⏱️ CHAPTERS 00:00 Intro 02:09 Where the community is right now 06:13 Standing out in the sea of sameness 12:00 Stop copying each other's homework 13:10 "I can tell your content is AI" 15:08 "Live, laugh, love" and the Gartner-category trap 17:30 Mind, gut, heart 25:53 The stories founders refuse to tell 30:12 Why heart is what cyber gets worst 32:22 Finding the real big idea 34:09 Second- and third-order benefits 38:11 CISOs, boards, and getting budget 39:04 The blank stare moment 48:24 You're Obi-Wan, not the hero 52:35 We made CEOs the heroes and forgot customers 55:00 Aligning security to what the business values 56:06 "More scared of their company than the bad guys" 57:18 Where to find Joel #cybersecurity #CISO #infosec #leadership

  8. Aug 18 ·  Video

    I'm Not AGI Pilled. I'm Human Pilled - with Casey Ellis

    "You know who will be hiring juniors again? Bad guys." Casey Ellis founded Bugcrowd and launched the first bug bounty programs on it back in 2012, pioneering crowdsourced security as a service. He co-founded disclose.io, sits on the Black Hat and DEF CON Policy review boards, and now runs Tall Poppy Group, angel investing and advising the next generation of security startups. Fresh off a week at Black Hat, B-Sides, and DEF CON, Casey joins Aaron for a wide-ranging conversation about what he actually heard on the ground — and why the mood at each of those three conferences was completely different. We get into the "slopdemic" (Casey's term for AI-generated vulnerability reports drowning the ecosystem), why he's "human pilled" rather than AGI pilled, and his read on the White House memorandum he's calling the privateering order — what it actually authorizes, and who's really going to use it. Plus: why pen test firms are about to have a very hard time defending their value, why every company already has a vulnerability disclosure program whether they know it or not, and the hygiene fundamentals that still contain the blast radius when everything else fails. The last stretch is the one worth staying for — a genuinely urgent case for why the industry's "we're never hiring juniors again" moment is a gift to the people recruiting them instead. Guest: Casey Ellis, founder of Bugcrowd and disclose.io, principal of Tall Poppy Group. Find him on LinkedIn. ⏱️ CHAPTERS 00:00 Intro 02:35 Coming out of Black Hat, B-Sides, and DEF CON 06:33 Why DEF CON was allergic to the AI hype 09:35 Hybrid conflict is already here 10:53 Royalty in the palace, villagers at the gate 12:16 Security below the poverty line 13:14 "I'm not AGI pilled. I'm human pilled." 14:51 Do stupid things faster with more energy 19:04 What people get wrong about AI and exploitation 21:43 The slopdemic and the vulnpocalypse 25:07 What it takes before anything actually changes 28:48 Nobody is coming to save you 33:02 What actually works if you start from scratch today 37:34 Why pen test is in for a ride 39:13 Hygiene, blast radius, and the boring basics 43:31 The privateering memorandum 48:26 Who's actually waiting to hack back? 51:24 What to tell a 22-year-old today 53:21 It's really easy to do crime 55:08 Community, disclose.io, and knowledge transfer 58:01 The industry needs to give back 60:45 "Who will be hiring juniors again? Bad guys." 61:11 Tall Poppy Group and where to find Casey #cybersecurity #infosec #AI #bugbounty #DEFCON

Ratings & Reviews

5
out of 5
4 Ratings

About

ZeroSum is a new cybersecurity podcast that aims to talk honestly about the state of the cybersecurity industry. The show rejects standard "threat of the week" news breakdowns and instead focuses on the reality of the market. Viewing the industry through the lens of game theory, the podcast explores how the current cyber market is no longer a rising tide that lifts all boats; for massive VC gambles to win, the burnt-out practitioners on the ground are often the ones losing. The show features guests from all perspectives, including vendors, investors, workers, and CISOs.