Episodios

  • Cloud Detection Engineering, AI in the SOC and Parallel Parking with Alex Hurtado
    Nov 14 2025

    Detection engineering just got real!Eden Naftali and Amitai sit down with detection engineering powerhouse Alex Hurtado - and it's a must-listen for anyone in cloud security. 👇🔍 What's inside:1. The evolution of detection engineering in the cloud — and why traditional rules no longer apply2. Why DIY detections > vendor defaults3. How AI is reshaping detection and threat hunting (and why the human in the loop still wins)

    Más Menos
    26 m
  • VSCode Extension Secrets, RediShell, & Living-off-the-LLM
    Nov 7 2025

    🔍 From discovering VS Code supply chain risks → to uncovering Redis Shell vulnerabilities.

    Eden Naftali and Amitai sat down to unpack: 👇

    • How VS Code extensions became a critical supply chain risk (w/ Rami McCarthy)

    • What RediShell reveals about attacker innovation

    • Where AI is being weaponized in modern malware

    🎙️ Listen now to our NEW Crying Out Cloud episode

    Más Menos
    30 m
  • eBPF, Fishy Book Covers, and Open Source Security with Liz Rice
    Sep 16 2025

    🚨 The kernel-level security revolution you can't ignore — a must-listen with Liz Rice

    Eden Naftali and Amitai sit down with Liz Rice, Chief Open Source Officer at Isovalent (Cisco), and a global expert in eBPF, containers, and Kubernetes security.

    🎙️ In this episode:

    • How eBPF is reshaping cloud security from the ground up

    • Practical strategies to tackle open source supply chain attacks (a hot topic given today’s events)

    A must-listen for anyone building or securing cloud infrastructure in an era of AI coding and supply chain attacks.

    Más Menos
    33 m
  • Security Metrics, Detection & Response & Paintball with Erik Bloch
    Aug 18 2025

    🔐 Erik Bloch on his path from military hacker to Illumio security leader.

    Eden Naftali and Amitai sat down with Erik Bloch & here's what they covered 👇


    1. How starting in the military shaped Erik's approach to security

    2. Building and scaling cloud detection & response teams

    3. Converting security metrics into actionable business KPIs

    Más Menos
    28 m
  • Adversary Emulation, Cyber Education & Community Building with Day Johnson
    Aug 1 2025

    🚨 How do you build a 4,000+ strong student-tech community from scratch?Eden Naftali and Amitai sat down with Day Johnson, Security Engineer at @amazon , ex-Datadog, founder of CyberWox Academy.What they covered 👇- Detection engineering that works at scale- What breaks IR processes (and how to fix them)- Real talk on breaking into security without shortcutsAlso: why being the "tech kid" in your neighborhood might just launch your whole career.

    Más Menos
    29 m
  • Live Talk: Security Minds from Riot Games, Microsoft & Wiz
    Jul 15 2025

    - 💡 From cloud chaos to career confessions: live with security minds from RiotGames & Microsoft.Eden Naftali went live, and got personal, with 3 leaders shaping the future of cloud and cybersecurity:- Nicole Dove, Head of Security Engineering at @Riot Games- Sherrod DeGrippo, Director of Threat Intelligence Strategy at Microsoft- Alon Schindel, VP of AI & Threat Research at WizWhat they unpacked? 👇The heart of threat intel, building trust over tools, and how hobbies reflect how they lead.This Crying Out Cloud episode from RSA just hits different.⏱ Chapters00:05:02 – What it means to be a threat intelligence leader00:10:08 – How threat intelligence should really look00:15:48 – Skirting the tough questions in cybersecurity00:21:07 – Working with third-party vendors in the cloud00:26:17 – What the security industry is getting wrong00:31:20 – The special skill of deep research00:36:20 – A real-world story about leading with trust#CyberSecurity #CloudSecurity #ThreatIntelligence #Infosec #CloudComputing

    Más Menos
    40 m
  • AI Double Agents to Blame, Scattered Spider Pivots to Planes
    Jul 9 2025

    🎙️ Scattered Spider's new target? Airlines.Eden Koby Naftali & Amitai Cohen break down the latest in the cloud:1️⃣ A connectivity tool vuln & Open WebUI misconfig putting orgs at risk2️⃣ Why attackers are still tricking help desks (and how!)3️⃣ The "lethal trifecta" of AI agent danger, explained 🧠🤖0:25 – Scattered Spider targets the aviation industry1:38 – Help desk hacks: impersonation & real-world stories4:52 – Teleport vulnerability explained9:48 – AI’s “lethal trifecta” and why it matters#CloudSecurity #ScatteredSpider #AIThreats #HelpDeskAttacks #CryingOutCloud #CybersecurityPodcast

    Más Menos
    18 m
  • Pyramid of Pain, PEAK, and Bagpipes with David Bianco
    Jun 25 2025

    🎙️ New ep: David Bianco from Splunk with 🔥 insights from a lifetime of threat hunting.Eden Koby Naftali & Amitai Cohen sat down with David Bianco, creator of some of the most influential models in cyber detection.What they got into ⬇️1) How a threat intel milestone led to the Pyramid of Pain2) Why detection isn't just about indicators3) What good threat hunting teams actually do#CryingOutCloud #CyberSecurity #ThreatHunting #PyramidOfPain #DavidBianco #Splunk #Infosec #CloudSecurity #DetectionEngineering #BlueTeam #SecurityPodcast #SOC #ThreatIntel #IncidentResponse

    Más Menos
    27 m