Scinary Information Nexus

Scinary Cybersecurity

Scinary Cybersecurity is here to "Serve and defend those who serve and defend others". To help us "serve and defend" we pull from many different sources - experts, colleagues, industry standards, etc... We hit every subject from all angles making it easy to understand while also letting us go in depth. Making this podcast perfect for cybersecurity beginners and experts alike. Come join us on our journey to constantly educate ourselves and explore the amazing things that are happening in our industry.

  1. 6d ago

    Episode 56: Untitled Episode

    Welcome back to the Scinary Information Nexus! This week, Brazos and Joseph hold down the fort for a two-man episode. We review the new executive order pushing for "free" cybersecurity for critical infrastructure and question how it will actually be funded. We also debate the controversial authorization of private companies launching offensive cyber "hack-backs." Allowing private entities to retaliate against attackers could cause massive collateral damage on shared infrastructure like AWS and Cloudflare. For the main topic, we answer a viewer question: What do you do if you inherit an organization with no cybersecurity? Brazos explains the governance side with a 5-step foundational plan starting with risk analysis. Joseph offers the technical approach, advocating for immediate network segmentation to stop the bleeding. From locking down firewalls to dodging the "bystander effect," we outline how to build a security program that continuously improves. What we cover: The new executive order providing "free" cybersecurity to critical infrastructure The unintended consequences of legalizing corporate "hack-backs" Why risk analysis and strict asset inventory must happen first Governance vs. Action: When to educate leadership vs. when to lock down the firewall Why delegated authority is crucial for enforcing technical controls Deploying critical controls like MFA and backing them up with written policies Avoiding "deferred maintenance" and keeping your security program alive What is the very first thing you would do if you inherited an unsecured network? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 06:45 Free Cyber for Critical Infrastructure 10:15 The Dangers of Offensive Hack-Backs 15:30 Step 1: Risk Analysis & Asset Inventory 25:00 Step 2: Leadership vs Immediate Action 31:30 Step 3: Delegated Authority & IT Roles 51:30 Steps 4 & 5: Controls & Written Policies 59:30 The Final Step: Continuous Improvement Cybersecurity #InfoSec #HackBack #CriticalInfrastructure #NetworkSecurity #RiskManagement #MFA #CISA #AccessControl

  2. Aug 28

    Episode 55: ClickFix & Phishing Attacks: The Back-to-School Surge

    Welcome back to the Scinary Information Nexus! While Richard is away enjoying his August hiatus, Brazos, Joseph, and Mario are holding down the fort. With the back-to-school season in full swing, the SOC team has been battling an absolute blazing inferno of cyber threats. The guys debrief on two major attacks currently hammering networks: highly evasive "ClickFix" malware campaigns and relentless Business Email Compromise (BEC) attacks. Threat actors are getting clever, injecting fake CAPTCHAs into legitimate websites to trick users into running malicious PowerShell scripts. Meanwhile, credential harvesters are using trusted services like Google Docs to bypass email filtering and build massive databases of compromised accounts. Ultimately, these attacks expose a real problem: modern cybersecurity education is failing. Because end-users have become overly trusting of automated security tools, they've let their guard down. The crew debates how to fix this broken system, joking about the ineffective "D.A.R.E. program" style of current compliance training. In this episode, we discuss: The massive back-to-school surge in SOC alerts and incidents. How ClickFix uses fake CAPTCHAs to trick users into executing malware. Why threat actors use trusted sites like Canva and Google Docs to bypass filters. The rise of Initial Access Brokers and credential harvesting through BEC. Why traditional compliance-based cybersecurity training is failing end-users. How to modernize user education with real-world, local examples. The debate over implementing consequences for "habitual clickers." Do you think employees should face real consequences for continuously failing phishing tests? Let's discuss in the comments. Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 04:30 The ClickFix Epidemic & Fake CAPTCHAs 19:30 BEC & Google Forms Credential Harvesting 31:00 Why Cybersecurity Education is Failing 41:00 Rethinking Training & User Consequences Cybersecurity #InfoSec #ClickFix #Malware #Phishing #SecurityAwareness

  3. Aug 14

    Episode 54: The Consumer Cybersecurity Gap: Botnets, Gamers & ClickFix

    Welcome back to the Scinary Information Nexus! Brazos, Joseph, and Mario are holding down the fort. After reviewing this week's beer selections (and swearing off Jeppson's Malort forever), the guys tackle the grim realities of critical infrastructure attacks. With water treatment facilities and power grids being targeted by nation-state actors, why is the general public left with survival-level advice like "learn how to boil water"? The team then breaks down the consumer cybersecurity gap and explains why the industry naturally chases enterprise money, leaving everyday users with weak, fragmented protections. Relying on built-in tools like Windows Defender or forced bloatware like McAfee creates a dangerous false sense of security. Since government guidance from agencies like CISA is hopelessly outdated, you need to understand the actual threats hitting your home network. In this episode, we discuss: Why critical infrastructure prioritizes availability over security, leaving utilities vulnerable to nation-state actors. The consumer cybersecurity gap and why everyday users are ignored by enterprise security vendors. How "free" antivirus and forced bloatware like McAfee create a false sense of security. Social engineering on Steam forums and how gamers are tricked into installing ClickFix and XMRig. Why modern malware doesn't slow down your computer, but quietly drafts you into botnets instead. The alarming rise in DDoS attacks fueled by compromised residential proxies. A debate on who is really responsible for security: the user or the software developer. Are you relying too heavily on built-in protections, or have you upgraded your home security setup? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 05:45 Critical Infrastructure Attacks 15:15 The Consumer Cybersecurity Gap 32:15 Gamers in the Crosshairs: ClickFix 38:15 Outdated Advice & The McAfee Problem 46:00 Botnets, DDoS & The Blame Game Cybersecurity #InfoSec #Privacy #Malware #Botnets #Hacking

  4. Aug 7

    Episode 53: Cybersecurity Tool Overload: Are You Wasting Money?

    Welcome back to the Scinary Information Nexus! Brazos takes the director's chair this week (filling in for Richard) and brings a highly structured and highly debated topic to the table: Defense in Depth. Joined by Joseph, Pierre, and Alexandra, the crew unpacks the reality of layered security and whether having more tools actually makes you safer. We kick things off by debating classic cybersecurity analogies (is your network a Swiss cheese model, a Jenga tower, or Shrek's onion?) before getting into a core industry problem: alert fatigue. The discussion highlights how complexity is the true enemy of security. Pierre and Joseph share horror stories of default firewall configurations erasing gigabytes of log memory and tool alerts spamming admins into creating dangerous auto-delete rules. The takeaway? A few well-configured foundational tools are better than a massive stack of redundant solutions. We also run through a fun thought experiment: what would the team build with an infinite budget versus a shoestring budget? In this episode, we discuss: The "Swiss Cheese" and "Onion" models of Defense in Depth. Why adding too many security tools can actually become a liability. Logging nightmares: How default firewall configs can erase vital data. Alert fatigue and why admins ignore critical security warnings. The Shoestring Budget: Top priorities when you can only afford one tool. Why attackers target basic misconfigurations over expensive zero-days. The Infinite Budget: TSA checkpoints, air-gapped networks, and pen-and-paper security. Have you ever dealt with serious alert fatigue in your environment? Let's discuss in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/

  5. Jul 24

    Episode 52: K-12 Cybersecurity & Third-Party Risks with Matt Wilkin

    Welcome back to the Scinary Information Nexus! After a quick laugh about a temporary face tattoo prank (sorry, Richard), we sit down with Matt Wilkin, who manages the network and technology infrastructure for Godley ISD. This week, Richard, Joseph, and Brazos chat with Matt about his 17 years in K-12 IT. They cover everything from turning a four-story football stadium into classrooms to the time a squirrel and a lightning strike took down the school's entire network. We also look at the growing threat of third-party and fourth-party vendor breaches, including a recent Clever report showing that third-party breaches now account for 32% of all K-12 incidents. We then discuss a major problem in incident response: 71% of education organizations hit by ransomware have their backups compromised. The crew talks about the pros and cons of tools like ChatGPT and Claude, and why foundational networking knowledge is critical before relying on modern AI shortcuts. Finally, Matt shares some great advice on how IT professionals can securely "pave the road" for staff instead of just being the "minister of no." In this episode, we discuss: A hilarious meme folder and Richard's face tattoo prank Matt's wild K-12 IT stories, including a squirrel-induced network outage Why third-party breaches in education now make up 32% of incidents The hidden risks of fourth-party vendors like Snowflake Why 71% of education ransomware backups fail and how to test restores How AI tools like Claude are eroding foundational IT skills Strategies for IT admins to support staff without being the "minister of no" How often does your organization actively test its backup restore process? Let us know in the comments below! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 03:45 Matt Wilkin's K-12 IT Journey 18:00 AI Tools vs. Foundational IT Skills 29:30 Third-Party Risks & Decentralized Data 37:30 Why 71% of Ransomware Backups Fail 44:30 Hard Truths & Advice for IT Admins Cybersecurity #InfoSec #Ransomware #EdTech #ThirdPartyRisk

  6. Jul 17

    Episode 51: Anthropic Lawsuit & Broken CVEs

    Welcome back to the Scinary Information Nexus! Mario kicks things off in a cowboy hat to mourn a Mexico soccer loss, and the team tries a mysterious Spanish "potion of prosperity" courtesy of Thet. We jump into the trademark fight between Anthropic and email security platform Abnormal AI over a slanted "A" logo. Is this a PR stunt from Abnormal AI or a real warning shot? We also talk about the risks of "vibe coding" and what happens when your entire startup is built on someone else's AI model without a defensive moat. Later, we play a round of "Hot Take or Hard Truth" regarding the broken CVE system. The industry is staring down a projected 66,000 vulnerabilities in 2026, and NIST's NVD is barely keeping up. We explain why panic-patching is no longer a viable strategy, how to set up a risk-based patching plan, and why defense in depth matters when the vulnerability count gets this high. In this episode, we cover: Mario's cowboy hat and Thet's "potion of prosperity" Anthropic suing Abnormal AI over a slanted letter, plus the irony of disgorged profits The real dangers of AI dependency and lacking a defensive moat Why the traditional CVE system is breaking under 66,000 projected vulnerabilities NIST's NVD failing to enrich new vulnerability submissions Shifting from CVSS 10 panic-patching to risk-based security Relying on defense in depth when you fall behind on patching Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 05:00 Anthropic Sues Abnormal 15:30 The AI Dependency Problem 27:30 Hot Take: The CVE System is Broken 36:00 Risk-Based Patching 44:00 Upcoming Guests & Live Announcement Cybersecurity #InfoSec #Hacking

  7. Jul 3

    Episode 50: From Blackberries to Wiretaps: Presidents and Tech History

    Welcome back to the Scinary Information Nexus! After a funny mishap where the crew "pre-gamed" a little too hard and had to scrap Friday's recording, we're back on track with a special Tuesday episode. With the 250th American Independence Day coming up, we're taking a break from heavy cyber news to play a game of presidential tech trivia. This week, Richard challenges Joseph, Mario, and Brazos to test their knowledge on the history of technology in the Oval Office. We talk about Obama's battle with the NSA to keep his BlackBerry, and how the first televised debates changed politics. We also look at wild historical rumors, like Civil War soldiers supposedly wiretapping telegraph lines using their tongues to feel the electrical pulses - a theory the guys jokingly threaten to have the SOC analysts test. To close out the episode, we cover some serious industry news regarding the FCC reviewing USAC and the potential defunding of the E-rate program, which could severely impact school tech funding. Plus, we share updates about our July 30th live stream and where you can catch the Scinary team at regional conferences! In this episode, we discuss: The reason we had to scrap our original recording. Why Barack Obama fought the NSA and Secret Service to keep his BlackBerry. How the 1960 Nixon-Kennedy debates shifted political focus to visual optics. Wild Civil War espionage: cracking the Vicksburg cipher and "tongue" wiretaps. The history of the White House telephone and why it wasn't private until 1993. Security lessons behind Hillary Clinton's private email server. Updates on the FCC reviewing USAC, the E-rate program, and what it means for schools. Which piece of presidential tech history surprised you the most? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 04:30 Presidential Tech Trivia & Security Standards 09:15 TV Presidents & The Importance of Optics 12:45 Civil War Ciphers & White House Telephones 18:15 Stripped Blackberries & Presidential Emails 22:15 Radio Debuts & Civil War Tongue Wiretaps 28:45 Secure by Design & Political Photos 34:15 E-Rate Defunding Concerns & Nerd Lore Cybersecurity #InfoSec #Privacy

  8. Jun 19

    Episode 49: Breach or BS: Testing our Cyber Knowledge

    This week on the Scinary Information Nexus, the crew takes a much-needed break from the endless AI chatter to play a game of Breach or BS. Join Richard, Joseph, Hunter, and newly promoted team member Thet for some office banter before we get down to business. We test our knowledge on some of the wildest cyber attacks in recent history. Can you guess which bizarre incidents are real and which are total fiction? From ransomware demands printed directly on a victim's hardware to cartel-orchestrated insider threats, we cover it all. We also talk about how vulnerable IoT devices put critical infrastructure at risk. We revisit the classic story of a casino breached through a fish tank thermometer, along with traffic light hacks and remote attacks on municipal water plants. Plus, Richard shares a funny vendor negotiation story where a simple CC vs. BCC email mistake gave him the upper hand. In this episode, we cover: Ransomware gangs printing extortion letters on a victim's own printers The dangers of insider threats and cartel infiltration How a simple email CC/BCC mistake can ruin a vendor negotiation The infamous casino hacked through an internet-connected fish tank Hackers targeting traffic light systems and municipal water plants Taking down North Korea's slant 24s in retaliation What is the craziest cyber attack you've ever heard of? Let us know in the comments! Connect with Scinary Cybersecurity: https://www.scinary.com https://x.com/scinarycyber https://www.linkedin.com/company/scinarycyber/ 00:00 Intro 03:30 AI Fatigue & SpaceX Wealth 05:15 Ransomware by Mail & Insiders 13:45 Fish Tank Hacks & Traffic Cams Cybersecurity #InfoSec #Ransomware #InternetOfThings #IoTSecurity #InsiderThreats #DataBreach #Hacking #CyberAttacks

5
out of 5
5 Ratings

About

Scinary Cybersecurity is here to "Serve and defend those who serve and defend others". To help us "serve and defend" we pull from many different sources - experts, colleagues, industry standards, etc... We hit every subject from all angles making it easy to understand while also letting us go in depth. Making this podcast perfect for cybersecurity beginners and experts alike. Come join us on our journey to constantly educate ourselves and explore the amazing things that are happening in our industry.

You Might Also Like