181 episodes
- In this episode of Mandiant’s Defender’s Advantage Podcast, host Luke McNamara sits down with Ben Read, Head of Strategic Threat Intelligence at Wiz, to explore the rapidly shifting landscape of software supply chain compromises. While historic, nation-state operations like SolarWinds focused on compromising closed-source software, modern adversaries have expanded their playbook to target widely used open-source ecosystems, repositories, and automated CI/CD pipelines. Ben discusses how differing tactics in these campaigns play out in the current threat landscape.
For more on Wiz's research: https://www.wiz.io/blog/tag/research - Host Luke McNamara sits down with Muhammad Muneer, Technical Manager on Mandiant's Incident Response team, to unpack the stark realities of enterprise AI adoption. They explore why securing AI starts with resolving legacy security debt (specifically around IAM, supply chain, and secrets management) and dissect the critical differences between "governance for AI" and "governance of AI." Muhammad details real-world frontline findings—from developers bypassing API gateways to the financial costs of leaked LLM API keys—and outlines the emerging threat of adversaries leveraging LLM-enabled command-line tools for living-off-the-land attacks.
- Host Luke McNamara is joined by Jake Nicastro, who leads the AI function for the Frontline Intelligence Operations team within the Google Threat Intelligence Group (GTIG). Jake details how his team is shifting from simple prompt engineering to more advanced agentic workflows, focusing on a model of "human-machine teaming." He shares practical use cases for AI in CTI—including automated script decoding, hunting query creation, and streamlining repetitive metadata-labeling tasks. Jake also discusses the concept of "judge agents" for quality control, the implementation of structured analytic techniques, and how real-time AI assistants can accelerate on-boarding and domain transitions for frontline threat analysts.
- Host Luke McNamara is joined by Charley Snyder, Head of Disruption Operations at Google Threat Intelligence Group, to delve into how Google is crafting a more coordinate approach to disrupting adversary cyber operations. Charley describes how this disruption focus is not hacking back, how it builds on existing work across Google security teams, and some of the recent wins such as the IPIDEA and GRIDTIDE takedowns.
- Host Luke McNamara is joined by Chris Linklater, Practice Leader at Mandiant, to discuss the 2026 edition of Mandiant's M-Trends Report. Chris dives into the latest trends observed in breached throughout 2025 and into this year, noting some of the key aspects organizations should focus on in applying these insights into today's threat landscape.
https://cloud.google.com/security/resources/m-trends
More Technology podcasts
Trending Technology podcasts
About The Defender's Advantage Podcast
Learn about the latest threat and cybersecurity trends on The Defender’s Advantage Podcast! Hear from experts in the field as Host Luke McNamara, from Google Threat Intelligence Group, interviews analysts, researchers and other guests on the frontlines of the latest attacks. Episodes dive deep into various topics, including nation-state activity, cybercrime, malware and tradecraft, incident response, defensive guidance, and more. Don't forget to subscribe!
Podcast websiteListen to The Defender's Advantage Podcast, Darknet Diaries and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Defender's Advantage Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.






























