Safe Mode Podcast cover art

Safe Mode Podcast

Safe Mode Podcast

Written by: Safe Mode Podcast
Listen for free

Podcast by Safe Mode PodcastAll rights reserved Politics & Government
Episodes
  • ClickFix and the social engineering of routine
    Sep 17 2026
    It starts with a fake error message. It ends with a pasted command. ClickFix has become one of the most reliable ways for attackers to get an initial foothold — first adopted by criminal groups, now used by state-linked actors like APT28 and Lazarus Group. This week, Greg is joined by John Hammond, Principal Security Researcher at Huntress, who helped identify and name the technique and has tracked its evolution for the past three years. They dig into why ClickFix still drives an estimated 20+ incidents a day at Huntress even after law enforcement disrupted major infostealer infrastructure like LumaStealer, how the technique has splintered into variants like FileFix and "consent fix" targeting Microsoft 365 and browser-stored credentials, and how attackers are now smuggling payloads inside images to slip past endpoint defenses. John walks through a real incident where a single pasted command led to 11 compromised devices, explains why he still believes security awareness training — not just tooling — is the best defense, and makes the case that the browser itself has become the blurriest and most under-protected boundary between endpoint and identity security. The conversation also turns to the npm/Axios supply chain attacks, where operators built fake Slack communities and fabricated employee personas to earn open-source maintainers' trust before compromising their packages — and what, if anything, can technically guard against a threat that's fundamentally social. In our reporter chat, Greg talks with Derek Johnson about the Supreme Court deciding against the Trump administration’s push for changes to mail-in ballots. Follow John on Youtube: https://www.youtube.com/@_JohnHammond
    Show More Show Less
    36 mins
  • Defending in the middle of the vulnpocalypse
    Sep 3 2026
    CyberScoop editor-in-chief Greg Otto talks with WatchTowr founder and CEO Ben Harris about how cybersecurity teams are adapting as AI accelerates vulnerability discovery, public proof-of-concepts, and exploitation timelines. They discuss the WordPress-to-shell case study, why mitigation has become essential when patching cannot happen instantly, and why Harris argues that traditional vulnerability management is “effectively dead.” Also in this episode, senior reporter Tim Starks explains Project Watershed 250, a new effort involving Texas, the private sector, and the water industry to strengthen critical-infrastructure cybersecurity.
    Show More Show Less
    31 mins
  • The Vulnpocalypse arrived early
    Aug 27 2026
    NEA partner Aaron Jacobson put $250 million behind autonomous pen testing company Horizon3.ai on the bet that cybersecurity has entered an AI-versus-AI era — and he argues the "vulnpocalypse" defenders were warned about has already arrived, with AI-discovered vulnerabilities now the primary way attackers get into enterprises. He explains why overprovisioned AI agents are the new phishing target, since an agent with a user's credentials and no common sense can be prompt-injected into exfiltrating data a human would never touch. Jacobson also separates the open weights debate from the open source one, makes the case that cheap open competition ultimately favors defenders, and closes with the thing he got most wrong 18 months ago. In our reporter segment, Greg talks with Matt Kapko about the cybersecurity implications of the GTA VI leaks.
    Show More Show Less
    35 mins
adbl_web_anon_alc_button_suppression_t1
No reviews yet