Discover
Safe Mode Podcast
150 Episodes
Reverse
It starts with a fake error message. It ends with a pasted command. ClickFix has become one of the most reliable ways for attackers to get an initial foothold — first adopted by criminal groups, now used by state-linked actors like APT28 and Lazarus Group.
This week, Greg is joined by John Hammond, Principal Security Researcher at Huntress, who helped identify and name the technique and has tracked its evolution for the past three years. They dig into why ClickFix still drives an estimated 20+ incidents a day at Huntress even after law enforcement disrupted major infostealer infrastructure like LumaStealer, how the technique has splintered into variants like FileFix and "consent fix" targeting Microsoft 365 and browser-stored credentials, and how attackers are now smuggling payloads inside images to slip past endpoint defenses. John walks through a real incident where a single pasted command led to 11 compromised devices, explains why he still believes security awareness training — not just tooling — is the best defense, and makes the case that the browser itself has become the blurriest and most under-protected boundary between endpoint and identity security.
The conversation also turns to the npm/Axios supply chain attacks, where operators built fake Slack communities and fabricated employee personas to earn open-source maintainers' trust before compromising their packages — and what, if anything, can technically guard against a threat that's fundamentally social.
In our reporter chat, Greg talks with Derek Johnson about the Supreme Court deciding against the Trump administration’s push for changes to mail-in ballots.
Follow John on Youtube: https://www.youtube.com/@_JohnHammond
CyberScoop editor-in-chief Greg Otto talks with WatchTowr founder and CEO Ben Harris about how cybersecurity teams are adapting as AI accelerates vulnerability discovery, public proof-of-concepts, and exploitation timelines. They discuss the WordPress-to-shell case study, why mitigation has become essential when patching cannot happen instantly, and why Harris argues that traditional vulnerability management is “effectively dead.”
Also in this episode, senior reporter Tim Starks explains Project Watershed 250, a new effort involving Texas, the private sector, and the water industry to strengthen critical-infrastructure cybersecurity.
NEA partner Aaron Jacobson put $250 million behind autonomous pen testing company Horizon3.ai on the bet that cybersecurity has entered an AI-versus-AI era — and he argues the "vulnpocalypse" defenders were warned about has already arrived, with AI-discovered vulnerabilities now the primary way attackers get into enterprises. He explains why overprovisioned AI agents are the new phishing target, since an agent with a user's credentials and no common sense can be prompt-injected into exfiltrating data a human would never touch. Jacobson also separates the open weights debate from the open source one, makes the case that cheap open competition ultimately favors defenders, and closes with the thing he got most wrong 18 months ago. In our reporter segment, Greg talks with Matt Kapko about the cybersecurity implications of the GTA VI leaks.
The federal government can't reliably say how many cybersecurity workers it has or what they cost — and that uncertainty sits at the heart of a much bigger question: is federal cyber training working, and can it keep pace with a field that's changing by the month?
On this episode of Safe Mode, host Greg Otto talks with Christopher Bloor, Defense Director at the SANS Institute, about the state of the federal cyber workforce. The conversation moves through the real gap agencies face between filling job openings and actually assessing the skills their people already have, what 1,100 National Guard members revealed about morale and readiness during the CyberGuard critical infrastructure exercise, and why certifications and "qualifications" get treated as interchangeable when they shouldn't be.
They also dig into some of the harder tensions in the space: whether federal training amounts to an unintentional subsidy for private-sector salaries, since the government will never be able to out-pay industry; how much of the workforce shortage is actually a skills problem versus a security-clearance bottleneck; and how AI has already flipped the day-to-day workflow for defenders, from checking AI-assisted code a year ago to now checking code AI has written itself.
In this week's reporter chat, Greg talks with Tim Starks about the future of CORCA, a bill designated to fight organized retail crime that privacy experts say would create new mass surveillance capabilities for DHS.
Kat Sommer, head of government affairs at NCC Group, joins Safe Mode to unpack the DEF CON talk she gave on how governments around the world are — and mostly aren't — protecting security researchers.
Of the roughly 195 jurisdictions on the planet, Sommer found only about 15 have enacted any form of legal safe harbor for vulnerability research, and just one, Portugal, has what she'd call a proper one on the statute book. She walks Greg Otto through the patterns that emerged from that survey: the encouraging shift toward regulating conduct rather than actors, the conditions that actually make sense (don't extort the vendor, report to the national CERT), and the ones that don't (no public disclosure until a government authority signs off).
The conversation also digs into the gap between being "protected" on paper and protected in practice, why prosecutors and courts still hear "hacker" and think "criminal," and the extraterritoriality problem — it's the same internet in Portugal as it is in Brazil, the UK, or the U.S., but the legal exposure changes the moment you cross a border.




