Episodios

  • NPM Package Compromises, Sen. Wyden's Ransomware Letter, and Apple's Memory Safety Advance
    Sep 11 2025

    Dennis and Lindsey discuss the targeted compromises of NPM packages (1:00) and the pointed letter that Sen. Ron Wyden sent to the FTC chairman asking for Microsoft to be held liable for the Ascension ransomware attack last year (11:45) before finally touching on Apple's new memory safety technology for new iPhones (20:43).


    NPM compromise: https://decipher.sc/2025/09/08/targeted-attack-compromises-popular-npm-packages/
    Wyden and Microsoft: https://decipher.sc/2025/09/10/senator-flags-microsofts-role-in-the-ascension-ransomware-hack/
    Apple memory safety: https://security.apple.com/blog/memory-integrity-enforcement/

    Más Menos
    31 m
  • The Salesloft Drift Fallout and SBOM Guidance From CISA and NSA
    Sep 5 2025

    Dennis and Lindsey talk through the continuing fallout of the Salesloft Drift incident (2:05) in light of the disclosure of several new companies that are involved, including Cloudflare, which published an excellent post-mortem on the intrusion. Then they discuss the new Shared Vision of SBOM for Cybersecurity published by CISA, NSA, and many foreign government cybersecurity agencies, and talk about why this is coming out now (17:54).

    Más Menos
    29 m
  • Decipher Lives!
    Sep 2 2025

    We are so back! After a bit of a hiatus, we're very excited to be back with new Decipher content for you in all of the old familiar places. And also some new ones. Join Decipher editors Dennis Fisher and Lindsey O'Donnell-Welch as we start our new, independent phase, talk about what we've been up to, and discuss our plans for what fun stuff we have in store.

    Decipher website: https://decipher.sc/

    YouTube: https://www.youtube.com/@DecipherSec

    Bluesky: https://bsky.app/profile/deciphersec.bsky.social

    X: https://x.com/DecipherSec

    Más Menos
    44 m
  • The Sony Hack Ten Years Later With Brian Raftery
    Sep 3 2024

    The Sony Pictures hack in 2014 by the North Korean Lazarus Group was a seminal event both in Hollywood and in the security community, bringing to light the capabilities and ambitions of North Korean attackers and showing the damage a leak of sensitive data can be. Brian Raftery joins Dennis Fisher to discuss his new Ringer podcast, The Hollywood Hack, that digs deep into the incident, its repercussions in Hollywood, and how it helped set the tone for how companies handle public data leaks.


    Más Menos
    45 m
  • Zero Day Reuse and A Busy Week for Iranian APTs
    Aug 30 2024

    The focus was on Iranian APTs this week, both from private threat intelligence teams and CISA, exposing new operations from UNC757 and other groups targeting government, higher education, and private industry. We also check in on a new report from Google's Threat Analysis Group on APTs using the same exploits for zero days that were developed by private commercial surveillance vendors NSO Group and Intellexa.

    Más Menos
    19 m
  • Reddit's Matt Johansen on Identity Attacks, Enterprise Security, and Burnout
    Aug 27 2024

    Reddit's head of software security Matt Johansen joins Dennis Fisher to talk about the highlights of Black Hat USA, the challenges of sorting security priorities in a large enterprise, and how he's learned to take care of his mental health after many years in the security industry.

    Más Menos
    32 m
  • Rebekah Brown and John Scott-Railton on COLDRIVER and Russian Cyberespionage
    Aug 19 2024

    Rebekah Brown and John Scott-Railton of the Citizen Lab join Dennis Fisher to dive into their group's new report on highly targeted spear phishing campaigns by the Russian threat actor COLDRIVER and then discuss the emergence of a new, possibly related group called COLDWASTREL.

    Más Menos
    23 m
  • Back Hat USA 2024 Recap
    Aug 12 2024

    Dennis Fisher and Lindsey O'Donnell-Welch reflect on their week in Las Vegas at Black Hat and discuss the talks they liked, including Moxie Marlinspike's keynote and the Google Project Zero retrospective, and the other topics they found interesting, including vulnerability exploitation versus social engineering and the AI ecosystem.

    Más Menos
    20 m