CISO Series
Podcast Network
CISO Series is a media network for cybersecurity professionals, delivering the most fun you’ll have in cybersecurity. We publish 9-10 episodes every week across our network of five programs. Four of our programs are audio podcasts, and we also have two live streaming video events every week. Please check out our events page for upcoming virtual and in person events. Source
Actions
Media Outlet details
| Scope | National, Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesBetter business through smarter cybersecurity
Microsoft describes this attack, which has been observed since May 2026, as one that starts with identity-focused social engineering.
The Department of Know: Liquid drained, CISA urges change, agentic whistleblowers
This week’s Department of Know is hosted by Rich Stroffolino, with guests Alexandra Landegger, global head of cyber strategy & transformation, RTX, Mark Eggleston, CISO-at-large. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Better business through smarter cybersecurity
CISA is warning that this CVE numbered vulnerability (CVE-2026-19490) which has a CVSS score of 9.3, has been exploited, following an alert posted last week by Previdian founder and former WatchTowr head of threat intelligence Ryan Dewhurst. The defect affects all NetScaler ADC and NetScaler Gateway appliances configured as a gateway or an AAA virtual server. Citrix patched the flaw on August 19.
Building Resilience for Microsoft 365
Most disaster recovery plans treat Microsoft 365 like a single system you can back up and restore. That framing misses the point , since a compromised tenant is really about identity, trust, and configuration, not just data. If the files come back but the identities, policies, and trust relationships don’t, have you recovered anything?
Fortinet auth holes, China distills AI, Mythos human bottleneck
Fortinet patched ten product vulnerabilities, including two critical flaws that don’t require authentication. One lets an attacker forge or reuse a JSON Web Token to bypass the FortiMonitorOnSight web portal. The other can turn the Privileged Access Agent Chrome extension into a traffic proxy after a user visits a malicious site. Full remediation requires FortiPAM 1.9.1 or 1.8.4 and Chrome extension 8.0.1.123 or later. Fortinet says it hasn’t seen exploitation in the wild.
Automated Pentesting Is Impossible. Autonomous Pentesting Is Different.
I stumbled across a Reddit comment that makes a bold point, and one worthy of a response: “Fully automated pentesting is an oxymoron. Scaling testing is good, but fully automating it is nothing more than vulnerability scanning. You should focus on ways to better scale instead of offloading.” For most products that market themselves as “fully automated pentesting,” that criticism is accurate.
How Do You Give Secure Access to a Known Adversary in Your Environment?
What does it mean to secure someone you already know is an adversary? At Ping YOUniverse, David Spark sat down with Andre Durand, founder and CEO of Ping Identity, to unpack a scenario that’s no longer hypothetical: organizations have unknowingly hired hundreds of nation-state actors under false pretenses. When the threat is already inside, the old idea of a perimeter falls apart, and zero trust becomes the only sane operating assumption.
Better business through smarter cybersecurity
Threat intelligence firm SOCRadar says it found PEEP, a post-exploitation toolkit disguised as a Smart Bookmarks extension for Chrome and Edge. An attacker needs to already have administrator or code-execution access, then PEEP forges browser preference-integrity values so it can sideload without Web Store checks or prompts. From there, it steals cookies and browsing data and uses a native-messaging tool to run commands and manage files on the host.
Recommendations to Reboot the Security Vendor Pitch
When vendors are fortunate to get a meeting with a CISO, what’s the right format for engagement? And if there is a more attractive format, is there a way to promote it that will get more meetings? Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by David Spark, the producer of CISO Series, and Edward Contreras, senior evp and CISO, Frost Bank. Joining is Jill Rhodes, svp, CISO, Option Care Health.
Why a Flat Network Is an Open Door for Attackers with Zero Networks
Most networks are flat by default. Every door left open, so an attacker who gets in walks straight into every house. In this conversation with David Spark at Black Hat 2026, a longtime Zero Networks customer, Scott Ehrlich from wealth management firm BBR Partners explains how microsegmentation replaced a “Frankenstein” of RDP lockdowns and bolt-on MFA. Zero Networks stops lateral movement, limits blast radius, and strengthens cyber resilience after attackers gain a foothold.