214 episodes
Vulnerability Research, AI Slop, and Why Fundamentals Still Win with Stephen Sims
01/09/2026 | 35 mins.AI can now hand someone a working Linux kernel privilege escalation exploit, even if that person cannot explain a single line of how it works. Stephen Sims joined the show to talk about what that shift means for offensive security, and why the fundamentals matter more now, not less.Stephen is the curriculum lead for SANS Institute's Offensive Operations program, where he has spent more than 15 years as an author and instructor, and he is a co-founder of Off by One Security. He is a longtime exploit developer and vulnerability researcher who came up through game hacking, network engineering, and years of binary exploitation, reverse engineering, and weaponizing bugs in browsers and the kernel.In this episode, Stephen and Phillip get into how AI is reshaping vulnerability research and exploit development. Stephen explains why human validation is still doing the heavy lifting behind the big vulnerability-count headlines, how AI tends to overstate or understate severity, and why so many submissions are now AI slop or duplicates. He makes the case that logic bugs remain the hardest thing for AI to find, walks through his roadmap for anyone serious about learning exploit development, and shares why he tells students to do the work manually before letting AI do it for them. Stephen also offers grounded advice for breaking into the field, from building a real technology foundation first to staying curious and paying your dues, and gives his honest read on where the opportunity is heading.=========================Connect with Stephen Sims:LinkedIn: https://www.linkedin.com/in/stephen-sims-2788091/X: https://x.com/Steph3nSimsOff by One Security: https://offbyonesecurity.com/YouTube: https://www.youtube.com/@OffByOneSecurity=========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwyliePurple Teaming with Sarah Hume: Turning Threat Intelligence Into Actionable Testing
25/08/2026 | 29 mins.Penetration testing tells you where the vulnerabilities and misconfigurations are. Purple teaming asks a different question: when an attacker is actually operating inside your environment, what can your tools see, and what slips right past them? Sarah Hume has built her career around that second question.
Sarah leads the Purple Team program at Security Risk Advisors. Her path into cybersecurity started with a single week at a summer camp at Dakota State University, which her dad talked her into against her wishes and which ended up changing everything. She went on to study cybersecurity at Penn State and began her career in network, physical, and OT/ICS penetration testing before moving into purple teaming as a red operator and eventually leading the practice.
In this episode, Sarah breaks down how her team runs purple teams at scale, roughly 200 a year, working through TTPs across the full attack chain alongside a client's blue team. She explains why she favors smart automation over fully automated testing, how her team builds detections that hold up instead of breaking on a single command string or file hash, and why remediation only matters if it is actionable. She also covers living off the land binaries, her grounded take on AI in offensive testing, and real advice for breaking into the field, from home labs and certifications to taking down imposter syndrome and building the communication skills that separate a good tester from a useful one.
=========================
Connect with Sarah Hume:LinkedIn: https://www.linkedin.com/in/sarah-hume1 =========================
Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie
=========================
Sponsored by Suzu Labs
=========================
All the ways to connect with @Suzulabs
https://suzulabs.com
https://x.com/suzulabs
https://www.linkedin.com/company/suzu-labs/From English Teacher to OSINT Investigator: Lindsey Yagi-Hatake on Breaking Into Cybersecurity
18/08/2026 | 41 mins.In under a year, Lindsey Yagi-Hatake went from teaching English in a public school classroom to working as a professional OSINT investigator. Her path into cybersecurity did not start with a certification or a computer science degree. It started with survival.
Lindsey spent six years as a public school English teacher and holds a master's degree in education administration along with certifications in teaching English as a second language, where she specialized in helping immigrant students adjust to life in a new country. That background in language, culture, and patient instruction shapes how she approaches her work today as an OSINT investigator and privacy manager at Decisive Resources, where she works alongside Mishaal Khan.
In this episode, Lindsey shares the full story of how she broke into the field. After becoming a survivor of domestic violence in 2024, she found herself being digitally stalked and geolocated, and when the systems meant to protect her fell short, she taught herself open source intelligence to document what was happening. She talks about the gatekeeping she ran into early on, the moment she spent her last $500 on a DEF CON badge, and how the community at Noob Village and mentors like Mishaal Khan and Chadd Watson changed everything. She also shares hard-won advice for anyone trying to break in today.
This is a conversation about grit, community, digital safety advocacy, and what it really takes to get into cybersecurity in today's job market.
=========================
Connect with Lindsey Yagi-Hatake:
LinkedIn: https://www.linkedin.com/in/lindseyhatake/
=========================
Connect with your host, Phillip Wylie:
LinkedIn: https://linkedin.com/in/phillipwylie
X: https://x.com/PhillipWylie
Instagram: https://www.instagram.com/phillipwylie- How is AI changing penetration testing, bug bounty hunting, and offensive security?
In this episode of The Phillip Wylie Show, Phillip sits down with Herman Zubenko to explore how artificial intelligence and automation are transforming the way security professionals discover and validate vulnerabilities.
Herman shares his unconventional journey from quality assurance and software development into cybersecurity, including how having one of his own accounts compromised led him to investigate the incident with AI and eventually begin using AI for bug bounty research.
Phillip and Herman discuss AI-assisted penetration testing, continuous security testing, open and local models, the importance of keeping humans in the loop, and why AI is more likely to enhance penetration testers than replace them.
They also discuss how aspiring cybersecurity professionals can use AI to accelerate their learning while still developing the technical fundamentals needed to understand how systems, applications, and vulnerabilities actually work.
=========================
Connect with Herman Zubenko:
LinkedIn: https://www.linkedin.com/in/herman-zubenko/
Syntetisk Tech Limited website: https://syntetisk.tech/
=========================
Connect with your host, Phillip Wylie:
LinkedIn: https://linkedin.com/in/phillipwylie
X: https://x.com/PhillipWylie
Instagram: https://www.instagram.com/phillipwylie
=========================
Sponsored by Suzu Labs
=========================
All the ways to connect with @Suzulabs
https://suzulabs.com
https://x.com/suzulabs
https://www.linkedin.com/company/suzu-labs/ - In this episode of The Phillip Wylie Show, Phillip welcomes cybersecurity community member Moo for an inspiring conversation about breaking into cybersecurity, building a career through persistence, and giving back to others along the way.
Moo shares his unconventional hacker origin story, from being inspired by *The Matrix* and DEF CON videos as a teenager to eventually speaking at DEF CON and earning his first National Cyber League challenge coin. Along the way, he discusses the value of internships, apprenticeships, mentorship, and exploring different areas of cybersecurity before settling on a career path.
Phillip and Moo also discuss the importance of community, continuous learning, and why cybersecurity conferences like DEF CON can be life-changing for newcomers.
Whether you're a student, career changer, or experienced security professional, this episode offers practical advice and plenty of encouragement for anyone looking to grow in cybersecurity.
=========================
Connect with Moo:
LinkedIn: https://www.linkedin.com/in/munirmuhammad/
=========================
Connect with your host, Phillip Wylie:
LinkedIn: https://linkedin.com/in/phillipwylie
X: https://x.com/PhillipWylie
Instagram: https://www.instagram.com/phillipwylie
=========================
Sponsored by Suzu Labs
=========================
All the ways to connect with @SuzuLabs
https://suzulabs.com
https://x.com/suzulabs
https://www.linkedin.com/company/suzu-labs/
=========================
Podcast Music by Syntax976
=========================
LinkedIn: https://www.linkedin.com/in/brandon-prince-27a0ab51/
X: https://x.com/syntax976
More Business podcasts
Trending Business podcasts
About Phillip Wylie Show
The Phillip Wylie Show is a premier cybersecurity podcast and media source for offensive security professionals. Hosted by Phillip Wylie, globally recognized ethical hacking expert, keynote speaker, and co-author of The Pentester Blueprint, the show features elite red team operators, penetration testers, and security leaders sharing real-world tradecraft, advanced tactics, career strategy, and insights on AI-driven cyber threats.
Podcast websiteListen to Phillip Wylie Show, Money Talks and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Phillip Wylie Show
Scan code,
download the app,
start listening.
download the app,
start listening.































