
Free Daily Podcast Summary
by Justin Leapline, Joe Wynn, and Rick Yocum
Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you're a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained.
The most recent episodes — sign up to get AI-powered summaries of each one.
In Episode 27, we recap BSides Pittsburgh 2026 (914 attendees, best turnout yet), then dive into AI models breaking out of sandboxes and hacking Hugging Face, the EU AI Act transparency rules now in effect, the CMMC Phase 2 pause and what it doesn't change, and the precedent, setting case of a US citizen criminally charged for using a phone duress code at the border. Plus Wayne Gretzky No. 99 Whisky. 🥃⏱️ Timestamps00:00 – Intro 01:28 – BSides Pittsburgh 2025 Recap & Numbers 05:33 – Villages, Sponsors & Planning for Next Year 10:46 – The After-After Party at The Lion 🍸 20:43 – AI Hacking AI: The Hugging Face Incident 25:46 – What CISOs Should Do Now 33:54 – Agentic IR Teams & Kill Switch Governance 45:00 – AI Patching & Configuration Management 57:04 – EU AI Act: The Deadline That Wasn't 1:04:33 – AI Inventory & Third-Party SaaS Risk 1:23:56 – 🥃 Spirit: Wayne Gretzky No. 99 Whisky 1:28:37 – CMMC Phase 2 Pause: What It Means 1:44:15 – Duress Code Case & Corporate Travel Policy 2:04:00 – Digital Privacy at the Border & Employee Training 2:15:37 – Wrap-Up🎙️ HostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum📬 Send Us Your Questions!ask@distilledsecuritypodcast.com🌐 Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodEmail: hello@distilledsecuritypodcast.com👍 Like, comment, and subscribe for monthly security and compliance insights.
In this episode, we're joined by Jon Buhagiar, Director of Information Technology at RareMed Solutions; a published Sybex/Wiley author of Cisco and Microsoft certification guides; and a longtime amateur radio enthusiast. We get into what it actually takes to run a security conference from the ground up, why so many penetration tests end up wasting everyone's money, and how compliance and cyber insurance keep reshaping the way organizations work. Plus, as always, a bourbon. 🎤 Jon's world — rare-disease specialty pharmacy, patient assistance programs, book writing, and ham radio🏗️ Running BSides Pittsburgh: revenue, expenses, marketing, volunteers, speakers, and sponsors🎟️ The real economics of ticket pricing, free tickets, and the venue/affordability squeeze🧑🤝🧑 Dividing responsibilities and appointing workstream leads as an event grows🎯 Scoping as the make-or-break of a good pen test — and the human element that tooling misses🔗 Chaining vulnerabilities and what separates a checkbox test from a real one💸 Why pen testing so often becomes an ineffective use of resources📋 Compliance and contractual drivers vs. genuine risk reduction🛡️ A risk-based, scenario-driven approach focused on resilience and continuous improvement🤝 Engaging pen testers as partners and maturing the process over time🔄 Security as a constant state of change — compliance, cyber insurance, and government scoring🏥 HIPAA compliance, risk analysis, and the ransomware reckoning facing healthcare🥃 Bourbon tasting and discussion⏱️ Timestamps00:00 Intro01:26 Guest introduction & background02:18 RareMed Solutions & patient assistance programs05:01 Book writing & amateur radio08:11 BSides Pittsburgh overview15:04 Running a conference: planning & organization22:05 Marketing & audience engagement25:07 Dividing responsibilities as you grow27:59 The value of ticket pricing31:50 BSides & the conference model46:11 Penetration testing & scoping57:28 The purpose of pen testing58:23 When pen testing goes wrong01:00:16 Reasons for pen testing & compliance drivers01:03:04 Continuous monitoring, testing & detection01:06:19 Is your company ready for a pen test?01:07:07 A risk-based approach01:13:58 Scenario-based testing & resilience01:17:31 Evaluating the value of pen testing01:29:01 The constant state of change01:31:01 Compliance & cyber insurance01:32:19 Bourbon tasting01:36:32 Government scoring & risk analysis01:50:36 HIPAA compliance & ransomware01:55:01 Wrap-up & call to action🎧 Distilled Security PodcastCybersecurity, GRC, and leadership, one pour at a time.🎙️ HostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum🎤 GuestJon Buhagiar linkedin.com/in/jonbuhagiar📬 Send Us Your Questions!ask@distilledsecuritypodcast.com🌐 Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodYouTube: @distilledsecurityEmail: hello@distilledsecuritypodcast.com👍 Like, comment, and subscribe for monthlysecurity and compliance insights.
In this episode, we celebrate our 2nd anniversary and Episode 24 of Distilled Security! We cover the Vercel breach, how a Roblox script led to compromised Google Workspace credentials via an unauthorized OAuth connection. Then we dive into HackerOne, pausing their own bug bounty program, overwhelmed by low-quality, AI-generated submissions. And we close out with the State of Vibe-Coded Security—4,783 AI-assisted apps scanned, 727 critical issues found, and the real question: are you vibe coding or vibe deploying? Plus, a quick look at Claude for Security dropping into public beta and what that means for the industry. All of that, and we crack open a Peerless Double Oak to toast two years of Distilled Security. 🥃⏱️ TIMESTAMPS:00:00 – Intro & 2-Year Anniversary 🎉01:26 – Behind the Scenes & Favorite Moments08:26 – Podcast Metrics & Global Reach24:20 – BSides Pittsburgh 2025 Update 🛡️34:31 – The Vercel Breach & OAuth Risk58:57 – HackerOne Pauses Bug Bounty1:16:05 – Spirit: Peerless Double Oak 🥃1:20:27 – Vibe Coding vs. Vibe Deploying1:26:46 – Claude for Security & AI News1:41:27 – Cheers to Two Years! 🥃🎙️ HostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum📬 Send Us Your Questions!ask@distilledsecuritypodcast.com🌐 Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodEmail: hello@distilledsecuritypodcast.com👍 Like, comment, and subscribe for monthly security and compliance insights
In this episode of the Distilled Security Podcast, we break down the Delve scandal—flawed SOC 2 reports, copy-pasted content, and oversight failures that expose deeper issues in compliance-as-a-service. Joined by Matthew J. Schiavone, we examine auditor accountability, quality review gaps, and key differences between SOC 2 and ISO 27001.We also cover what companies should demand from auditors, the role of automation, and whether this scandal will drive real change in the industry. Topics CoveredThe Delve scandal—leaked reports, copy-pasted audits & pervasive deficienciesThe AICPA peer review process & AC Corp's adverse findingsSOC 2 vs ISO 27001—oversight models, witness audits & accreditationThe incentive structure driving compliance to the bottomCompliance automation — what works, what doesn't & AI's real roleWhat to ask your auditor before signing anythingTrust centers — done right vs. compliance theaterIs SOC 2 dead? What needs to change & who has to change itHostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocumHostsMatthew J. Schiavone - (Sikich) Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodEmail: hello@distilledsecuritypodcast.com
In this episode of the Distilled Security Podcast, we tackle four topics shaping the cybersecurity landscape — from AI's real impact on defense to a wave of regulatory and market changes every security team needs to be tracking.🔹 Is AI Good for Security? — Anthropic's model finding hundreds of zero days, stock market panic after Claude Code's launch (CrowdStrike down 11%), the "hard things easy, easy things hard" reality of AI, why human-out-of-the-loop isn't ready yet, the coming spike in vulnerability disclosures, and how defenders should be using AI for better hygiene🔹 CIRCIA Final Rule (May 2026) — The federal incident reporting law hitting critical infrastructure, 72-hour incident and 24-hour ransom payment notification clocks, how "substantial cyber incident" triggers differ from materiality, mid-market companies falling in scope, overlapping timelines with HIPAA/SEC/state breach laws, and building your incident response playbook now🔹 Protecting Yourself Against a Changing Compliance Landscape — CMMC Phase 2, HIPAA overhaul, CCPA audits all converging, why a unified security program beats framework-by-framework chasing, evidence over policy in audits, engineering continuous compliance through automation, and the reality of doing this without dedicated staff🔹 Cybersecurity M&A / Consolidation Problem — Google acquiring Wiz for $32B, 10% of the cybersecurity industry changing hands, operational benefits of fewer vendors vs. pricing pressure and talent drain, the OneTrust "sticker on the side" integration warning, Cisco's Startup Studios model, and why consolidation only works if they don't break what made the acquisition special🥃 Spirit Review: WhistlePig 12 Year Old World RyePA Fine Wine & Good Spirits Select — Finished in Madeira, Sauternes & Port barrels, 86 proofhttps://www.whistlepigwhiskey.com/📬 Send Us Your Questions!ask@distilledsecuritypodcast.com🎙️ HostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum🌐 Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodEmail: hello@distilledsecuritypodcast.com👍 Like, comment, and subscribe for weekly security and compliance insights.
In this episode of the Distilled Security Podcast, we break down three converging forces reshaping how organizations manage AI risk — and what you need to do about it now.🔹 BIPA + AI Notetakers — A class action lawsuit exposes unauthorized biometric data collection, why a single Illinois meeting participant creates liability, the Shopify wiretapping dismissal, and the steps you should take today to audit your AI tools🔹 GRC Engineering Meets AI — Real AI compliance tools vs. vaporware, using LLMs for policy drafting and control mapping, the hallucination accountability problem, building AI guardrails as code, and the NIST RFI on AI Agent Security (comments due March 9, 2026)🔹 ISO 42001 Deep Dive — The first AI Management System standard, how it differs from ISO 27001, AI Impact Assessments vs. traditional risk assessments, stakeholder engagement requirements, and why certification is becoming essential for EU AI Act compliance🥃 Spirit Review: Redbreast 12 Cask Strengthhttps://www.redbreastwhiskey.com/en-us/whiskey-collections/redbreast-cask-strength-whiskey/⏱️ Timestamps0:00 Intro & Episode Overview2:04 BIPA & AI Notetakers25:08 GRC Engineering Meets AI1:07:15 🥃 Spirit Review: Redbreast 12 Cask Strength (Irish Whiskey)1:11:17 ISO 420011:49:30 Outro & wrap-up🎙️ HostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum🌐 Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodEmail: hello@distilledsecuritypodcast.com👍 Like, comment, and subscribe for weekly security and compliance insights.
In the first episode of 2026, the Distilled Security team kicks off the year with a practical discussion on security priorities, key compliance dates to watch in 2026, and why misleading the government on cybersecurity compliance can have serious consequences.The conversation focuses on simplifying security programs, returning to core fundamentals, and learning from real-world enforcement and regulatory cases. The episode closes with a holiday pour and a preview of format changes coming next.⏱️ Timestamps0:00 Intro & episode overview0:33 2026 security resolutions: simplify & back to basics5:45 “Science projects”: removing emotion from decisions8:36 Justin’s goals: family, travel, business & AI workflows17:52 EOS + Atomic Habits workbook (goal planning)23:54 Key compliance dates to watch in 202631:45 California privacy updates & risk assessments (CCPA)35:39 EU AI Act + NIS2 enforcement ramp-up42:48 Drink break: High West “A Midwinter Night’s Dram.”45:04 Don’t mislead the feds: FedRAMP, SolarWinds, CMMC—wrap-up to 1:20:12 🎙️ HostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocum🌐 Connect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodEmail: hello@distilledsecuritypodcast.com🥃 Drink of the episode: High West A Midwinter Night’s Dram
In this episode, we break down a major Cloudflare outage, explore how a nation-state used AI agents to automate a cyberattack, and discuss the growing risks around MCP integrations. We also highlight why GRC Engineering is becoming essential to modern security programs and wrap up with key regulatory updates, including CMMC changes affecting thousands of contractors.Topics covered: • Cloudflare outage impact and root cause• Nation-state attack using AI agents to automate intrusion steps• MCP (Model Context Protocol): power, risks, and examples• Why GRC Engineering is the future of compliance and automation• Updates on GDPR, ISO 27701, California AB 5866, and SEC rules• CMMC assessor shortages and what organizations must prepare forSpirit of the Episode• Knob Creek 21-Year Limited Release, rich caramel notes, heavy char, smooth for 100 proofTimestamps0:02—Cloudflare Outage Stories & Global Impact3:07—Root Cause, Not a Cyberattack & Third-Party Risk Reality10:38 - China Uses Anthropic’s Claude + MCP for Automated Cyberattacks14:17 - Full AI Attack Lifecycle Explained27:18 - MCP: The API for AI & Its Security Risks44:05 - Bourbon Break: Knob Creek 21-Year Review50:02 - GRC Engineering Deep Dive: Automation & Controls-as-Code1:24:13 - Regulatory Roundup: GDPR, ISO 27701, California AB 566, SEC SP1:44:27 - CMMC 2.0 Crisis: Auditor Shortages & DoD Contract Impact2:11:20 - Closing Thoughts & Episode Wrap-UpHostsJustin Leapline – @justinleaplineJoe Wynn – @wynnjoeRick Yocum – @rickyocumGuestMatthew J. Schiavone - @SikitchConnect with UsWebsite: distilledsecuritypodcast.comX: @DisSecPodEmail: hello@distilledsecuritypodcast.com
Free AI-powered daily recaps. Key takeaways, quotes, and mentions — in a 5-minute read.
Get Free Summaries →Free forever for up to 3 podcasts. No credit card required.
Listeners also like.

Security Now (Audio)
A weekly deep dive into cybersecurity news, hacking trends, and digital defense strategies for professionals and individuals.

The Dark Web Diaries
Explores cybersecurity topics, hacker motivations, and weekly cyber news to demystify online safety and the dark web.

Cybersecurity Today
Latest cybersecurity threats, data breaches, and practical steps to protect businesses in high-risk environments.

Whiskey Web and Whatnot
Developers discuss web technologies, AI coding tools, and software careers alongside casual talk about the human side of programming.

The Lawfare Podcast
Discussions with experts on national security, law, and policy covering foreign policy, intelligence, cybersecurity, and governance.

The Just Security Podcast
Expert analysis of national security, foreign policy, and rights from practitioners, academics, and affected individuals.

Daily Tech News Show
A daily briefing covering the latest developments in technology news from an independent and trustworthy source.

Primary Technology
Tech news covering consumer gadgets, AI, and major industry stories explained for a general audience.

The Lawfare Podcast: Patreon Edition
Experts and policymakers discuss national security, law, and policy issues including foreign policy, intelligence, and cybersecurity.

All-In with Chamath, Jason, Sacks & Friedberg
Four tech investors discuss technology, markets, politics, and poker with candid, in-depth analysis.

The AI in Business Podcast
Executives discuss practical AI adoption in business through interviews focused on strategy, use-cases, and ROI.

The Most Interesting Thing in AI
Conversations with leading thinkers exploring the ethical, economic, and social impact of artificial intelligence.
Join us on Distilled Security as we delve into the fascinating world of cybersecurity. Each episode, we break down intriguing topics, analyze the latest news, and engage in in-depth conversations with our hosts and invited guests. Whether you're a seasoned professional or just curious about cybersecurity, our podcast offers valuable insights and thought-provoking discussions to keep you informed and entertained.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from Distilled Security Podcast in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of Distilled Security Podcast as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by Justin Leapline, Joe Wynn, and Rick Yocum.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
Distilled Security Podcast publishes monthly. Our AI generates a summary within hours of each new episode.
Distilled Security Podcast covers topics including Technology, Business. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.