• Ep47: Why AI Risks Are Different
    Sep 19 2026
    Episode Summary:Someone told Marc that AI panic is nothing new — just the printing press or nuclear weapons all over again. He disagreed, and it turns out there was a report to back it up. In this episode he breaks down why AI collapses the cost of dangerous capability in a way the printing press, the internet, and even nuclear weapons never did, what Anthropic's brand-new September 2026 threat intelligence report documents, where his own "$200 expert" framing overstated the case, and the four guardrails that would close the gap.Key Topics Covered:The argument that started this episode — a debate about whether AI panic is history repeating, and the report Marc found three days later making his case for himWhy the printing press comparison breaks down — institutions had a century (and decades, for the internet) to catch up; AI's capability curve moves in monthsWhat's actually different about nuclear weapons — nuclear risk lives behind physical choke points: materials, facilities, expertise. AI risk lives in a skill, and skills can't be fenced offAnthropic's report: the receipts — three disrupted operations, walked through case by case, that turn the argument from speculative to documentedDoes AI make anyone an expert? Not exactly — Marc's own "$200 subscription = expert" line, and the more defensible version of the claimAttackers, defenders, and who adapts faster — the same models cutting attacker costs are cutting defender costs too, and why that race mattersWhat real AI guardrails would look like — four concrete guardrails: pre/post-release capability testing, enforceable standards, international coordination, and risk-scaled accessMain Takeaways:AI doesn't need generations to reach scale like the printing press or the internet did — model capability jumps happen every few months, not every few decadesNuclear risk is contained by physical choke points (fissile material, facilities, expertise); AI risk lives in a skill, and skills don't have a border to fenceAnthropic's September 2026 report documents real, disrupted operations — including a breach that went from one stolen developer token to full cloud admin control in roughly three hours"$200 subscription = expert" overstates it: AI doesn't manufacture expertise, it lowers the skill required to attempt tasks whose consequences the operator isn't trained to handleDefenders get the same acceleration attackers do — the organizations lagging on AI-assisted defense are the ones absorbing the most riskClosing the gap takes four things: pre/post-release capability testing, enforceable (not voluntary) standards, international coordination, and access that scales with risk instead of priceTimestamps:[0:00] The argument behind this episode[1:03] Why the printing press comparison breaks down[1:53] What's different about nuclear weapons[2:55] Anthropic's report: the receipts[4:46] Does AI make anyone an expert? Not exactly[5:45] Attackers, defenders, and who adapts faster[6:16] What real AI guardrails would look likeTools & Resources Mentioned:Anthropic: Detecting and Countering Misuse of AI (September 2026)NIST AI Risk Management FrameworkEU AI Act (European Commission)Full written guide: Why AI Risks Are DifferentAI is fueling the cybersecurity career boomWhy an AI agent shouldn't inherit your permissionsNot legal advice. Figures reflect Anthropic's report as published on September 10, 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
    Show More Show Less
    9 mins
  • Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited
    Sep 10 2026

    Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview.

    In this episode:

    • (00:00) The scan report that isn't as urgent as it looks
    • (01:03) The 98.5% number and the mechanic analogy
    • (02:01) Why the industry defaulted to patch everything
    • (03:00) The 36-hour outage from a perfect-10 patch
    • (03:48) CVSS score vs. exploitation evidence vs. insurance-claims data
    • (05:08) What it sounds like when someone understands this in an interview
    • (06:15) Why the industry has no brakes, and the AI-hype myth
    • (07:49) Your homework

    Links:

    • Down the Rabbit Hole, episode 722, "Vulnerability Math Ain't Mathing"
    • CISA's Known Exploited Vulnerabilities (KEV) catalog
    • FIRST.org, the CVSS specification
    • Full written breakdown
    • Our cybersecurity career guide
    • Breaking into cybersecurity with no experience
    • Third-party risk and the AI bug-report flood

    Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode.

    I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

    --

    Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

    Listen to Byte Sized Security

    --

    Support this Podcast with a Tip:

    Support Byte Sized Security

    --

    If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

    Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    Show More Show Less
    10 mins
  • Ep45: Fired for Failing a Phishing Test? What Binance Actually Does
    Jul 28 2026
    Episode Summary:Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.Key Topics Covered:What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who failsCan you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offenseHow corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)"Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc landsAccountability without a blame culture — four principles for getting Binance's seriousness without the fearThe boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patternsMain Takeaways:You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone ownedPunishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incidentThe metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudlyHumans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the personFair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or reportTimestamps:[0:00] The gotcha that shows up on your performance review[1:03] What Binance's red team is actually doing[2:23] Can you really get fired? Three strikes and the Krebs debate[3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder[5:03] "Weakest link"? The industry split, and where we land[6:55] Accountability without a blame culture: four principles[8:19] The boring middle thing that actually worksTools & Resources Mentioned:Binance runs monthly phishing tests (crypto.news)Repeated failures may lead to dismissal (WEEX)Addressing the repeat phishing offender (IT Brew)"Should Failing Phish Tests Be a Fireable Offense?" (Krebs on Security, 2019)What to do (and not do) when employees click (Hook Security)What's a good phishing failure rate? (Hoxhunt benchmarks)KnowBe4 phishing security testProofpoint phishing simulationMicrosoft Defender attack simulation trainingFull written article: Fired for failing a phishing test?Why modern phishing beats smart peopleWhy employee security awareness training mattersGeneral education, not legal or HR advice. Reporting reflects coverage as of July 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
    Show More Show Less
    11 mins
  • Ep44: California's DROP Tool: Delete Yourself From Data Brokers in One Free Request
    Jul 22 2026
    Episode Summary:California just made deleting yourself from data brokers a single free request. In this episode Marc breaks down the state's new DROP tool: what it deletes, how to file it in a few minutes, why August 1, 2026 is the date that matters, and the three things it won't fix. If you're a California resident, this is a free privacy win you shouldn't skip. If you're not, he covers what to do instead.Key Topics Covered:What DROP is — California's Delete Request and Opt-out Platform, and where the 614 data broker number comes fromHow it works — one free request, and what it actually deletes across registered brokersFiling it step by step — a few minutes of work, plus the scam to watch out forThe August 1, 2026 deadline — why that's the date brokers have to start honoring requestsThe honest limits — what DROP won't fix: Google, Meta, and brokers that re-collect your dataNot in California? — the moves that get you similar protection without DROPMain Takeaways:DROP lets California residents delete themselves from every registered data broker (614 and counting) with a single free request — no per-broker opt-outsAugust 1, 2026 is the date that matters: that's when brokers must start honoring DROP deletion requestsIt's not a silver bullet — it won't remove you from Google or Meta, and brokers can re-collect your data over time, so treat it as maintenance, not a one-and-doneWatch for the scam: the only official place to file is the state's own site — don't pay a third party to do what's freeNot a California resident? Freeze your credit and use manual opt-outs or a removal service to get similar coverageTimestamps:[0:00] The 12-broker breaking point[1:10] What DROP is and where the 614 number comes from[2:05] How it works and what it actually deletes[3:40] Filing it step by step, plus the scam to avoid[4:46] Why August 1, 2026 is the deadline[5:19] The honest limits: Google, Meta, and recurring brokers[6:51] Not in California? Do this insteadTools & Resources Mentioned:File a DROP request (official)California Privacy Protection AgencyCalifornia Delete Act (SB 362)EFF: What You Need to Know About California's DROP ToolFull written guide: California's DROP tool & data broker opt-outHow consent laundering moves your dataRemove your personal info from the internetCredit freezes & identity protectionNot legal advice. Details reflect the tool as of July 2026; enforcement begins August 1, 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
    Show More Show Less
    10 mins
  • Ep43: The Best Personality Traits for Working in Cybersecurity
    Jun 1 2026

    Episode Summary:

    A Reddit thread on r/cybersecurity asked a simple question: what's the best personality trait for working in cyber? The answers — with hundreds of upvotes — weren't about hacking or certifications. They were about curiosity, patience, humility, staying calm under pressure, and empathy. Marc walks through each trait with personal stories from 8+ years of building teams, hiring, and working incidents at 2 AM.

    Key Topics Covered:

    • Curiosity — the #1 answer by a wide margin; the trait that makes you dig into a log line everyone else shrugs off
    • Patience — explaining technical risk to non-technical people without making them feel stupid, because if you do, they stop reporting incidents
    • Humility — saying "I don't know, but I'll figure it out" beats bluffing every time; ego is the worst trait in the field
    • Calm under pressure — incident response at 2 AM, zero-days on Friday afternoons, breaches that keep growing; staying focused when everything is on fire matters more than any cert
    • Empathy and kindness — cybersecurity is a people problem wrapped in a technology problem; being technically right doesn't matter if nobody wants to work with you
    • The uncomfortable truth — ADHD, burnout, trauma-induced hypervigilance; the always-on mindset is a strength until it isn't

    Main Takeaways:

    • Technical skills are trainable — tools, frameworks, scripting languages, detection logic are all learnable, especially with AI
    • Soft traits like curiosity, patience, and empathy are harder to develop and are what separate people everyone wants on their team from people nobody wants to work with
    • If you're thinking about getting into cybersecurity, don't ask "am I technical enough?" — ask "am I curious enough to keep learning?"
    • The best cybersecurity professionals aren't the ones who sprint the hardest — they're the ones still there in five years

    Timestamps:

    • [0:00] Introduction — the Reddit thread that started it all
    • [0:58] Curiosity — the #1 answer and why it matters
    • [2:41] Patience — the art of explaining things without condescension
    • [3:58] Humility — why "I don't know" is a superpower
    • [5:15] Calm under pressure — the difference between a skill and a warning sign
    • [6:28] Empathy and kindness — the most surprising and important trait
    • [7:49] The uncomfortable part — burnout, ADHD, and mental health in cyber
    • [9:11] Final thoughts — what really separates the best from the rest

    Tools & Resources Mentioned:

    • Reddit Thread: Best Personality Type/Traits for Working in Cyber

    ---

    I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

    --

    Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

    Listen to Byte Sized Security

    --

    Support this Podcast with a Tip:

    Support Byte Sized Security

    --

    If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

    Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    Show More Show Less
    12 mins
  • Ep42: Three Privacy Actions You Need Today
    Jul 5 2025

    # Byte Sized Security Show Notes

    ## Episode Title:

    3 Immediate Actions to Protect Your Privacy Today

    ## Episode Summary:

    In this episode of Byte Sized Security, host Marc David outlines three practical, actionable steps to enhance your privacy protection immediately. With data breaches nearly doubling in 2024 and companies like AT&T and Ticketmaster experiencing massive exposures, these privacy protection measures aren't just theoretical—they're essential defenses against real threats.

    ## Key Discussion Points:

    * The alarming state of data breaches in 2024: 10,626 confirmed breaches, nearly double from previous year

    * Major breaches highlighted: AT&T (73M records), Ticketmaster (560M users), National Public Data (2.9B records)

    * The average breach costs $4.88 million, or $165 per stolen record

    * **Step 1**: Enable two-factor authentication everywhere

    * 2FA stops 99.9% of automated attacks

    * Use authentication apps instead of SMS

    * Save backup codes in a safe place

    * **Step 2**: Audit your privacy settings

    * Detailed walkthrough for Facebook, Instagram, Twitter/X, and LinkedIn

    * Phone settings review for both iOS and Android

    * Revoking unnecessary app permissions

    * **Step 3**: Protect your connection and digital footprint

    * Using a VPN to encrypt connections and mask browsing

    * Reviewing and cleaning your digital footprint

    * Opting out of data broker sites

    * Deleting old, unused accounts

    * The importance of ongoing privacy maintenance


    ## Tools and Resources Mentioned:

    * **Authentication Apps:**

    * [Google Authenticator](https://googleauthenticator.net/)

    * [Authy](https://authy.com/)

    * **Recommended VPN Services:**

    * [NordVPN](https://nordvpn.com/)

    * [ExpressVPN](https://www.expressvpn.com/)

    * [Surfshark](https://surfshark.com/)

    * **Data Broker Removal Services:**

    * [DeleteMe](https://joindeleteme.com/)

    * [Privacy Bee](https://privacybee.com/)

    * [Optery](https://optery.com/)

    * **Data Broker Sites to Opt Out From:**

    * [Whitepages](https://www.whitepages.com/)

    * [PeopleFinder](https://www.peoplefinder.com/)

    * [Spokeo](https://www.spokeo.com/)

    Show More Show Less
    7 mins
  • Ep:41 Beware: Your Top VPN App May Be a Chinese Government Spy
    Jul 3 2025

    Episode Summary:

    In this episode, we explore the alarming discovery that many of the top-rated VPN apps on the App Store and Google Play are secretly owned by Chinese companies. These VPNs pose a serious risk to user privacy and security, as Chinese law requires them to hand over all user data to the government without justification.

    Key Topics Covered:

    - Chinese-owned VPN apps masquerading as legitimate services

    - Lack of transparency and disclosure around company ownership

    - Risks of user data being accessed by the Chinese government

    - Failure of app stores to properly vet and regulate these VPN apps

    - Importance of researching VPN providers before using them

    Main Takeaways:

    - Many popular VPN apps are secretly owned by Chinese companies, creating a significant risk to user privacy and security.

    - App stores like the App Store and Google Play are not properly vetting and regulating these potentially compromised VPN apps.

    - Users must do their own research to ensure the VPN they are using is trustworthy and not owned by a company with ties to the Chinese government.

    Timestamps for Major Topics:

    - 0:00 - Introduction to the issue of Chinese-owned VPN apps

    - 1:30 - Examples of top-ranked VPN apps with hidden Chinese ownership

    - 3:00 - Explanation of the legal requirements for Chinese companies to hand over user data

    - 4:30 - Lack of action by app stores to remove or label these problematic VPN apps

    - 6:00 - Importance of user research and caution when selecting a VPN provider

    ---

    I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode.

    --

    --

    Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

    Listen to Byte Sized Security

    --

    Support this Podcast with a Tip:

    Support Byte Sized Security

    --

    If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

    Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    Show More Show Less
    3 mins
  • Ep40: The AI Layoff Apocalypse Has Already Started — And You’re Next
    May 30 2025

    The Imminent AI Job Crisis: Are You Prepared?

    This episode highlights the alarming prediction by Dario Amodei, CEO of Anthropic, that AI could eliminate half of all entry-level white-collar jobs within the next one to five years, potentially raising U.S. unemployment to 20%. While major companies are quietly adopting advanced AI systems, the public and lawmakers remain largely unaware or in disbelief. The episode discusses the impacts of AI on various industries and jobs, stressing the need for urgent action such as an AI 'token tax,' real-time job replacement tracking, legislative briefings, and worker reskilling programs. The message is clear: the AI job crash is imminent, and proactive measures are essential to mitigate its effects.


    00:00 The Impending Disappearance of White-Collar Jobs

    00:37 Real-World Examples of AI-Induced Job Cuts

    01:03 The Rise of AI Agents in the Workplace

    01:30 The Alarming Capabilities of Advanced AI

    01:48 Public Response and the Threat to Democracy

    02:32 Proposed Solutions to the AI Job Crisis

    02:57 The Urgency of Immediate Action

    03:06 Conclusion: Preparing for the AI Job Crash

    ---

    I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode.

    --

    Sites Mentioned in this Episode

    • Behind the Curtain: A white-collar bloodbath

    --

    Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

    Listen to Byte Sized Security

    --

    Support this Podcast with a Tip:

    Support Byte Sized Security

    --

    If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

    Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    Show More Show Less
    5 mins