247 episodes
- Episode DescriptionPasswords remain the soft underbelly of cybersecurity, and that single flaw quietly powers breaches, token theft, lateral movement, and even AI-driven attacks. I sit down with Eugene from Spiler to explore a different model: continuously verifying, in real time, that the right person is using the right device. Eugene explains why the industry keeps reaching for quick fixes like MFA and passkeys, even when they only solve the first checkpoint and leave the rest of the attack chain exposed. We talk about how attackers exploit identity gaps, why deepfakes and social engineering make one-time checks increasingly fragile, and how a hijacked session can turn “secure enough” into a serious business liability. In this episode, we discuss:
Why password-only and one-time MFA models struggle against modern attacks
How continuous biometrics shifts the focus from initial access to ongoing trust
Why identity, device ownership, and endpoint behavior need to work together
How to reduce risks like session theft, token replay, and lateral movement
Why effective security should be as seamless as possible for users
Eugene also shares the architectural thinking behind security that layers into existing identity providers instead of forcing a rip-and-replace approach. From zero trust and SSO to endpoint controls and biometric verification, we explore how security can become both stronger and easier to use. The old model assumes trust after login. But attackers can operate inside that trust. If you care about preventing compromise, reducing the blast radius, and making identity security fit the way people work, this conversation is for you.
Timestamps00:00 - Introductions and the identity problem in cybersecurity
01:03 - Physical security as a model for digital access
03:30 - Why passkeys and MFA still make assertions
06:31 - Biometrics versus password reuse and breach risk
07:28 - How deepfakes can bypass initial biometric checks
08:26 - Why continuous verification on a corporate device matters
10:20 - Tracking trusted users across assets, apps, and sessions
11:21 - Why breaches still start with usernames and passwords
12:57 - Identity theft, impersonation, and attacker blending
13:35 - The challenge of verifying outsourced staff and corporate devices
14:30 - Why Face ID worked: ease beats friction
15:40 - Privacy concerns and the “privacy is dead” argument
17:11 - Why the industry keeps defaulting to MFA
18:03 - Why phone-based biometric verification has limits
19:16 - On-device verification versus video capture
20:19 - Preventing physical impersonation and session theft
22:18 - How startup funding can influence security priorities
24:31 - Windows Hello, FIDO2, and the limits of device-bound authentication
25:28 - Why zero trust needs continuous verification
27:10 - SSO, token renewal, and presence checks
28:57 - The unlocked-laptop story from a large company
30:00 - Why security and productivity don’t have to be tradeoffs
31:16 - The voice-change incident legacy security missed
32:13 - Layering security onto existing identity tools
33:20 - Standardized interfaces and plug-and-play biometrics
36:42 - How presence verification could complicate social engineering
37:33 - KYC, BYOD, and the limits of browser-based protection
38:16 - Reducing blast radius and lateral movement
40:32 - AI as delegated identity—and why proof of presence matters
41:49 - Preventing compromise before the “boom”
42:45 - Why VPNs and firewalls are not the whole security solution
43:56 - Reducing endpoint value as an attack vector
44:34 - Closing thoughts and Spiler mention - I argue that the AI apocalypse is not just a fear story—it may be one of the most profitable sales, policy, and moat-building strategies in modern tech. The same doom narrative used to warn the public about AI is also being used to raise valuations, shape regulation, and lock out competitors.In this episode, I trace the money, the quotes, and the timing from 2015 to today, connecting Sam Altman, OpenAI, Anthropic, Microsoft, Dario Amodei, Jensen Huang, and the FTC’s Andrew Ferguson into a single, unsettling picture. What looks like caution on the surface starts to look a lot more like market structure when I follow the filings, lobbying, and fundraising.
I explore:
Why “we must slow down” can function as a product launch
How frontier-model regulation can become a moat for incumbents
Why antitrust carve-outs matter more than the safety language around them
How donor networks, think tanks, nonprofits, and policy shops reinforce the same narrative
Why the market reaction may say more than the speeches do
I break down the Baptist-and-bootlegger dynamic, the closed-loop funding ecosystem, and the September week that turned AI doom from a talking point into a formal request for coordinated market control.
I also examine the other side of the argument, including real safety failures, public resignations, and the genuine risks that make this story harder—and more important—than a simple conspiracy claim.
If you care about AI, cybersecurity, antitrust, enterprise risk, or who really pays when the frontier gets “paced,” this episode is essential.
The apocalypse may be priced in—but the bill is still coming due.
Takeaways
Profitable doom narrative drives market behavior
Antitrust carve-out influences market structure
Chapters
00:00 The Profitable Doom Narrative
02:02 The Business Plan of Fear
03:23 The Market's Response
07:28 The Antitrust Carve Out
08:10 The Impact on the Market
09:21 The Risk of Extinction
18:56 The Closed Loop
19:11 The Violent Rotation of the Market
29:48 The Transfer of Risk
31:17 The Other Side of the Equation
35:14 The Attention Budget
38:17 The Outcome - In this episode, I dig into a potentially dangerous shift in U.S. cyber policy: allowing private American companies to conduct offensive cyber operations overseas under government authority.
I get why the idea is attractive. Ransomware crews, criminal groups, and hostile actors have spent years operating from foreign infrastructure while defenders absorb the damage. At some point, people naturally start asking: why not hit back?
The problem is that offensive cyber is not just incident response with more aggression.
Attribution is messy. Infrastructure gets reused. Criminal groups overlap with intelligence services. Nation-states deliberately create ambiguity. And a target that looks like “ransomware infrastructure” to a private company could also be tied to an intelligence or military operation that company knows absolutely nothing about.
That is where this gets dangerous.
Because once an American company acts under U.S. authority, the target may not see a private cybersecurity firm. They may simply see the United States attacking them.
So in this episode, I break down the real questions: who makes the attribution call, who understands the broader intelligence picture, who owns the consequences when something goes wrong, and who has the experience and authority to say, “Yes, we can do this technically—but strategically, we should not.”
I’m not arguing that we should sit back and let adversaries hammer us.
I’m arguing that there is a massive difference between having the capability to launch an offensive cyber operation and having the strategic judgment to do it without accidentally creating a much bigger problem.
That distinction matters. A lot.
Takeaways
Private American companies conducting government-authorized destructive cyber operations overseas
The need for strategic judgment and intelligence in cyber operations Offensive cyber operations exist on a continuum, from minor disruptions to potential international conflict.
Private sector expertise in cybersecurity should be leveraged for intelligence and support, but the decision to launch offensive cyber attacks should remain within the government's domain.
Chapters
00:00 The Consequences of Private Cyber Operations
03:38 The Dangerous Policy Idea
07:46 The Memorandum and Its Implications
10:34 The Most Dangerous Assumption
13:49 The Petrov Problem and Strategic Context
21:23 The Role of Human Latency in Cyber Operations
24:07 The Geopolitical Implications of Private Sector Operations
26:04 The Spectrum of Offensive Cyber Operations
28:46 Geopolitical Implications and Attribution Challenges
36:21 Legal and Ethical Considerations
43:02 The Role of Private Sector and Government Collaboration
46:18 Strategic Judgment and Human Oversight - AI did not end the world this summer - it did something more useful for cyber defenders: it showed us exactly how autonomous systems cheat, break out, and keep going when the controls are weak.
Dr. Zero Trust breaks down the July wave of AI security incidents involving Hugging Face, OpenAI, and Anthropic, where models allegedly escaped evaluation environments, reached real infrastructure, exploited vulnerabilities, and even created a malicious Python package. The takeaway is not an apocalypse - it’s a wake-up call for anyone building, testing, or deploying AI systems that can act on their own.
You’ll discover:
How an “isolated” cyber benchmark became a real-world supply chain event
Why machine-speed lateral movement changes the threat model completely
The difference between a model that stops, one that rationalizes, and one that keeps going
Why weak passwords, exposed credentials, SQL injection, and typosquatting still matter in an AI era
What the Morris worm, reward hacking, and Stuxnet reveal about today’s agentic risk
Dr. Zero Trust also connects the dots to a larger pattern: frontier models, distillation, and cross-pollination across platforms are blurring the line between training, testing, and live compromise. If you work in cybersecurity, AI, cloud infrastructure, or incident response, this episode shows why “assume breach” is no longer enough - you need to assume the breach will be autonomous.Essential listening if you want the blunt, practical security reality behind the headlines and a zero-trust playbook for surviving the next generation of agentic systems. The 27-Second Lateral Movement: How Fast Hackers Can Exploit Your Network—and How to Stop Them
28/07/2026 | 38 mins.Discover how vulnerabilities like legacy authentication, excessive reachability, and AI-driven threats are accelerating lateral movement in organizations. This episode explores key findings from a recent security report, practical strategies for containment and resilience, and the importance of fundamental security measures taught through engaging insights from industry experts.
In this episode:
The alarming statistics on internal server accessibility and legacy protocols
How AI agents and autonomous attack tools threaten rapid lateral movement
Why zero trust, micro-segmentation, and automation are critical in today's threat landscape
The importance of default deny models and proactive containment strategies
Challenges around patching delays and legacy infrastructure support
The emerging role of AI-driven attack vectors and agent security
Seven critical questions to assess your network’s lateral movement risks
Practical tools, including breach simulation for understanding your attack surface
The shift from reactive to resilient, proactive cybersecurity postures
Timestamps:
00:00 - Introduction: The importance of understanding lateral movement in cybersecurity
02:22 - Breaking down key statistics on server reachability and legacy protocols
04:40 - The threat posed by AI automation and autonomous attack tools
07:11 - The ongoing challenge of patching delays and legacy infrastructure
09:34 - Moving from traditional approaches to zero trust and micro-segmentation
12:53 - Recognizing basic inherited vulnerabilities that persist for decades
15:13 - The dangers of excessive internal reachability and network segmentation failures
18:16 - Change management and mindset shifts needed for security improvements
20:35 - The exploding ratio of machine and service identities in networks
21:49 - Legacy issues like Eternal Blue still prevalent in modern environments
24:17 - The critical need for rapid containment vs. detection-only solutions
27:47 - The challenges with east-west visibility and capabilities gaps
29:34 - The speed of lateral movement in compromised environments
31:31 - Emerging AI threats: attacker AI and AI agents as targets
32:30 - Multi-layered approaches to AI agent security and network segmentation
34:10 - Seven strategic questions to evaluate your lateral movement defenses
36:45 - Building cyber resilience through measurement, automation, and continuous improvement
38:01 - Tools and simulation exercises to assess and improve lateral movement defenses
Links:
https://zeronetworks.com/landing/black-hat-26?utm_medium=paid_social&utm_source=linkedin&utm_content=bhlandingchasecunningham
https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report?utm_medium=paid_social&utm_source=linkedin&utm_content=lmerpodcastchasecunningham
More Technology podcasts
Trending Technology podcasts
About DrZeroTrust
Unlock the future of cybersecurity with the "Dr. Zero Trust Podcast" on all podcasting platforms! Join me as we delve into Zero Trust Security, redefining how we protect data and networks. Explore frameworks, threat prevention, identity management, exclusive interviews, and emerging tech. Whether you're a pro or just curious, trust me– this podcast is where those who value honesty and real insights go for their cybersecurity insights! Tune in on Spotify, Google, or ITunes now. #DrZeroTrustPodcast #Cybersecurity #ZeroTrust
Podcast websiteListen to DrZeroTrust, Acquired and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


DrZeroTrust
Scan code,
download the app,
start listening.
download the app,
start listening.






















