DiscoverDown the Security Rabbithole Podcast (DtSR)
Down the Security Rabbithole Podcast (DtSR)
Claim Ownership

Down the Security Rabbithole Podcast (DtSR)

Author: Rafal (Wh1t3Rabbit) Los

Subscribed: 2,963Played: 68,164
Share

Description

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show.

On Twitter/X: https://twitter.com/@DtSR_Podcast
On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
On LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/


710 Episodes
Reverse
TL;DR: This week's episode is what happens when I go on vacation and have a little time to think. So here we go - let's talk about this Jaguar Land Rover was compromised and ransomware spread. The damage has been 'extensive' to the point where they stopped everything... are there any lessons here? Links https://www.theguardian.com/business/2025/sep/20/jaguar-land-rover-hack-factories-cybersecurity-jlrhttps://www.theguardian.com/business/2025/sep/20/jaguar-land-rover-hack-factories-...
TL;DR: This podcast features our friend Bo Birdwell who sits down with us to explain the ins and outs of the new DFARS CMMS update. Jim and Bo cover a lot of ground, and James and I are along for the ride asking questions. Great episode if you're in the space, worrying about what this latest update means to you. YouTube Video: https://youtube.com/live/0cl1S4f3g8E Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=...
TL;DR: This week's returning guest is Doug Cavit, but this time he's here to talk about the Internet apocalypse. Partly driven by AI, but mostly we discuss automated content generation, bots, and consumption as we reach the conclusion that it's all coming crashing down... sooner than we'd like. YouTube Video: https://youtube.com/live/tUJgdrh3ws8 Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-...
TL;DR: Michael Reichstein joins the pod this week to talk about "rock star CISOs" and those who trade equity for their souls. It's an interesting discussion but this one comes with a warning label: If you're easily offended, do not listen to this. Michael's post that started this conversation: https://www.linkedin.com/posts/mreichstein_cybersecurity-leadership-businessethics-activity-7361753110983135233-YSct YouTube video: https://youtube.com/live/N1mD_HLYDxU Have something to say? Let's he...
TL;DR: This week's pod features our favorite former analyst Anton Chuvakin, and an AppSec OG Jeff Williams as we tackle the subject of AppSec's favorite new acronym - ADR. What is it? Why is it? Should it be? We answer all these questions and more, and laugh along the way a bit too. YouTube Video: https://youtube.com/live/69xeGDoDYbU Links Contrast's latest threat report (referenced in the show)An in-depth ADR Explainer (helpful!)Run-Time Security Explained (for those wanting to learn more)Ha...
TL;DR: This week's returning guest is the man, the myth, the Alpaca farmer, Philippe Humeau of CrowdSec. Life comes at you fast, threats come at you faster. The good news is - defenses can keep up. Listen in, then go check out CrowdSec! YouTube video: https://youtube.com/live/7Xc99bXCfwQ Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Y...
TL;DR: This week's guest is Dr Sam Liles - who's been CISO'ing since most of us have been in the industry. Sam gets it, and he has some perspective on what's going on with all this market consolidation. What is it good for? He's got some things to say, and he's not shy about it. YouTube: https://youtube.com/live/ROEA6z5Q-sk Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=...
TL;DR: This week's show is a testament to surviving a week of Hacker Summer Camp out in Las Vegas. I have an interview with Ray Canzanese, Jr. (again, because y'all love him) and a bit of my take-away / rant from the week I spent out in the desert. Enjoy, I hope you made it home safe and learned something. Good God it was hot. YouTube Video: ( standby, waiting on me to edit ) Thanks again to my friends at Netskope! Have something to say? Let's hear it. Support the show >>&gt...
** Early release, due to Black Hat Conference and RaffCon XVIII. TL;DR: This episode is all about #RaffCon. Ever wanted to know what the heck it is? Well, Raffael Marty and I break it down, give you a little history, and reminisce. As we got into Black Hat week, this is the perfect precursor to #RaffCon XVIII. YouTube video: https://youtube.com/live/jwArV_EwuZc Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the sho...
TL;DR: This is one of the most important episodes we've done on this podcast. The CISO and CIO have a complicated, dynamic, and often ugly relationship - but what should it be like? How can the two work together and evolve their roles together, for the benefit of everyone in the business? Larry Whiteside, Jr. ( Co-Founder and President at Confide) and Dennis McDonald ( Chief Information & Security Officer at Jack Henry ) lay down a conversation that's worth a repeated listen. YouTube...
TL;DR: This week's conversation is all about the Customer Success team featuring Nick Puetz and Steve Dakhe. These guys have significant seat time building, operating, and perfecting the CSM role - and we're here to talk about it. What is a CSM? Why do they exist? And what is their role in customer engagement? Listen in, find out! YouTube: https://youtube.com/live/lCen-1Vt_K8 Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to su...
TL;DR: This week we took a sit-down with serial entrepreneur, Will Gragido. Will has been a part of several innovative start-ups, and is now onto his next one. He's a product innovator with a pragmatic sense of what customers need, and he's here to give you the run-down of what drives him, what got him here, and things you should think about if you're thinking of setting off on your own. YouTube video: https://youtube.com/live/qkAi6Nj8kII Have something to say? Let's hear it. Show Sponso...
TL;DR: Did you miss us? Yes, we're back with Sam Masiello and we're talking about whatever is on his mind. Well ...there's geopolitics and Iranian hackers and frankly we need to talk about what it means for your security program. Thanks for joining us, Sam! YouTube Video: https://youtube.com/live/H-4ZktBIUDE Have something to say? Let's hear it. Show Sponsor: ThreatLockerAllow what you need, block everything else... Including ransomware.Disclaimer: This post contains affiliate links. If ...
TL;DR: This week's episode came from my (Rafal) brain. I've been reading far too much LinkedIn, and the "influencer" postings have been making me crazy. So, here we are. We talk through some of these posts, many of which are AI generated I think, and have a little fun with it. Call it...therapy. YouTube Video: https://youtube.com/live/uZVfkge8bQE Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=...
TL;DR: On this episode, part 4 of our AI series, we are once again joined by Raja Mukerji, Jeff Collins, and John Dickson to discuss what it means to think about security for AI. Is it something completely different? Is it something same-'ol? Or - is it a bit of both. And what aren't we thinking about when it comes to securing AI? YouTube video: https://youtube.com/live/vUJIOrX0kHc Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above...
TL;DR: This week I bring John Dickson back to join Jeff Collins and Raja Mukerji as we talk through the following: What can AI do, for cyber security, that we can't do with current tools?What is the model for incorporating AI into cybersecurity - are we replacing people? augmenting people? both? neither?Where is AI the strongest in these use-cases today, and where is the promise for 12 - 36 months out?What are the LIMITATIONS for AI in cybersecurity? Are these short-term limitations, or long-...
TL;DR: This week John Dickson returns to go deeper down the AI rabbit hole with special guest Erik Bloch as we dive into a more technical explanation of AI, how this innovation differs from other similar concepts, previous tech innovations, and some of the commercial vs consumer use-cases where AI is best suited. It's a deeper discussion, and we will for sure have a part 3, and likely 4 coming soon. YouTube video: https://youtube.com/live/QXi6ed2NKhc Have something to say? Let's hear it. Supp...
TL;DR: So - Artificial Intelligence (AI)...incomprehensible good, or catastrophic evil? Both? And what does that depend on? This episode is the start of a series wherein we explore the potential good or bad of AI, what the dependencies are. and what kinds of branches of discussion there could be. Join us as we discuss a generational topic, with some of our best guests starting with John Dickson. Required listening: Episode 654 w/Sounil Yu ( https://dtsr.buzzsprout.com/2153215/episod...
TL;DR: This week's episode asks the question - is it possible to give AI "discretion" (which feels like a uniquely human concept)? And if so - what would that look like, and how can this help a society that's hurling headlong into an AI future from destroying secrecy as we know it? Sounil Yu from Knostic joins Rafal & James to think through the problem - complete with visuals! If that sounds a little dramatic, you'll enjoy the episode, because this problem is very real and those outside s...
TL;DR: On this "live on the scene" episode from Zero Trust World 2025 sponsored by Threat Locker - I have the distinct pleasure to speak with Rich Latayan about his career leading big-company security programs as CISO and his current endeavor. YouTube: <coming soon> Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://...
loading
Comments (5)

David Hortsch

Worst episode ever... (Okay I haven't listened to all 400), but..

Jul 14th
Reply

mrmr

You're talking about "hacker summer camp" but you don't go. That feels off.

Aug 6th
Reply (1)

mrmr

wow you guys need to visit defcon again. Your impressions are off

Aug 6th
Reply (1)