Skip to content
PodcastsTechnologyThe Audit - Cybersecurity Podcast

The Audit - Cybersecurity Podcast

IT Audit Labs
The Audit - Cybersecurity Podcast
Latest episode

103 episodes

  • The Audit - Cybersecurity Podcast

    Pineapple Pager: Wi-Fi Hacking, Spying Smart TVs and a $118K Ad Bill

    05/10/2026 | 30 mins.
    What does a device shaped like a 90s pager have to do with the Wi-Fi network your laptop joined at Starbucks last month? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem are joined by IT Audit Labs' own Cameron Birkland to get hands-on with the Hak5 Wi-Fi Pineapple Pager, the newest tool in the Pineapple lineup. Before the gear comes out, the crew unpacks a nine-year-old who ran up $118,000 in YouTube ads on his dad's saved work credit card, how Chrome sync quietly blends work and personal accounts, and new research showing LG smart TVs listening and collecting data even when they appear to be off. 
    Cameron walks through what the Pineapple Pager does right out of the box, from passive recon and handshake capture to Wi-Fi 6E support and the reality that WPA3 has made many classic attacks far harder to pull off. Eric explains how probe requests let a rogue device impersonate your home or office network to set up a man-in-the-middle attack, shares what he captured at the Minnesota State Fair, and the team talks through war driving with GPS and WiGLE and how these demos land in security awareness training. The episode wraps with the debut of a new segment, Eric Reacts, featuring a pilot's breakdown of a gnarly crosswind landing. 
    In this episode: 
    • The Wi-Fi Pineapple Pager runs recon by default and supports Wi-Fi 6E, though WPA3 networks remain out of reach for today's Wi-Fi pen testing tools. 
    • Eric explains how your devices call out for saved networks and how a rogue access point answers back to launch evil twin and man-in-the-middle attacks. 
    • War driving in 2026 comes to life with GPS modules, WiGLE integration, and everything a pocket-sized device picked up in one afternoon at the state fair. 
    • New findings show LG smart TVs listening and collecting data through automatic content recognition, which helps explain why TV prices stay so low. 
    • A $118,000 ad bill shows what happens when Chrome sync blends work and personal accounts and kids share a browser with a company credit card.
    If you've ever connected to public Wi-Fi without a second thought, this one is worth sharing with your team. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. 
    #PineapplePager #Hak5 #WiFiHacking #Cybersecurity #EthicalHacking #WarDriving #WPA3 #SmartTVPrivacy #InfoSec #PenTesting
  • The Audit - Cybersecurity Podcast

    Cybersecurity News: PaperCut Breach, AGI Hype and Patch Tuesday

    21/09/2026 | 37 mins.
    Nation states are paying top dollar for zero day vulnerabilities, hackers went from an empty lab to domain admin in under four hours, and Nvidia's CEO says we just crossed into AGI. On this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the cybersecurity stories shaping the week and dig into a debate that has no clean answer. 
    The crew opens with news that Eric Brown has a book on the way, built around lessons learned managing technology for clients over the years, before moving into Patch Tuesday, a PaperCut vulnerability that AI agents used to hack hundreds of organizations in seconds, and Nvidia CEO Jensen Huang's claim that artificial intelligence has already crossed into AGI territory. The conversation closes with an ancient parable about a fireman, and what it teaches modern IT teams about the habits they reward. 
    In this episode: 
    Eric Brown's upcoming book workshops potential titles for his book on fixing the managed service provider model. 
    Patch Tuesday and zero days explained, covering what Microsoft's monthly patch cycle fixes and why a zero day can be worth a fortune to a nation state. 
    The PaperCut breach and printer security, where an AI powered attack hit 395 organizations through a PaperCut flaw, echoing printer security nightmares the crew has seen during audits and pen tests. 
    Have we already reached AGI, with Jensen Huang saying yes and Sam Altman calling the term meaningless, as the crew works through the paperclip dilemma and an AI sandbox experiment. 
    The Fireman's Paradox, a centuries old parable about ignoring good advice and what it says about why organizations keep rewarding firefighting instead of prevention. 
    If this episode gave you something to think about, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. 
    #PatchTuesday #ZeroDay #Cybersecurity #AGI #PaperCut #ITAudit #InfoSec #AIThreats #Podcast #ITAuditLabs
  • The Audit - Cybersecurity Podcast

    Building the Future: AI Coding, Agentic Advisors and Custom Tools

    07/09/2026 | 1h 15 mins.
    What if your company didn't need a single line of code to build its own CRM, or a board of directors made up entirely of AI agents? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Loren Horsager, founder of Model Mind AI, who has been working in AI since 1993 and now spends his days coaching businesses and CEOs on how to actually put it to work. Loren has helped organizations trade their bloated software stacks, their expensive middleware, and their old habits for AI-driven processes that get built in days instead of quarters. 
    The crew digs into vibe coding, AI councils, and the death of the traditional user interface, then pivots into the harder questions: what happens to developers, where security has to fit into the process, and why voice AI still hasn't earned people's trust. Along the way there's talk of AI trading bots, a QuickBooks security scare, a routing engine that hit 100 percent on-time delivery, and a debate about whether vinyl records and iPods still have a place in an AI-driven world. 
    In this episode: 
    Why vibe coding terrifies developers who ignore it 
    The AI council approach to strategic thinking 
    Why nobody loves their CRM anymore 
    Where security has to sit in AI adoption 
    Why voice AI works for productivity but not yet for trust 
    If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. 
    #AI #VibeCoding #Cybersecurity #ITAudit #AIAgents #Automation #BusinessAI #TechLeadership #DigitalTransformation #TheAuditPodcast
  • The Audit - Cybersecurity Podcast

    Cyber Warfare on Tap: Water Utility Hacks, Nation-State APTs and Secure Browsers

    24/08/2026 | 47 mins.
    What happens when nation-state hackers target the water coming out of your tap? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the recent wave of attacks on water utilities across Minnesota and 27 other states, where threat actors got their hands on administrative passwords to programmable logic controllers. The crew is joined for the first time by Kelly Venzke, Director of Business Operations at IT Audit Labs, who brings a business leadership perspective to a conversation that quickly turns technical. 
    From there, Eric and Nick trace how these attacks echo the Stuxnet playbook used against Iran's nuclear program, explain how threat actors are impersonating help desk staff over Microsoft Teams to gain remote access, and dig into a blockchain-based command and control technique that hides inside paid search ads. The conversation wraps with practical advice on browser security, including why isolating AI browser extensions and ditching saved passwords in the browser matters more than most people realize. 
    In this episode: 
    Nation-state hackers breach US water utilities across 27 states. How Iranian threat actors obtained administrative access to programmable logic controllers and why Minnesota may have been ground zero. 
    The Stuxnet connection. Eric breaks down how the historic attack on Iran's nuclear centrifuges bridged an air-gapped network, and why today's "air-gapped" systems often aren't as isolated as they seem. 
    Help desk impersonation over Microsoft Teams. Why blocking external Teams-to-Teams calls has become a critical defense against social engineering attacks targeting employees. 
    EtherHiding: blockchain-backed command and control. How attackers use paid search ads and blockchain infrastructure to maintain persistent, hard-to-detect access to compromised environments. 
    Practical browser security tips. Kelly, Eric, and Nick talk through password managers, isolating LLM browser extensions, and why saving passwords in your browser is a bad habit worth breaking. 
    Don't wait until your organization is the next headline. Like, share, and subscribe for more conversations on the threats shaping cybersecurity and IT today. 
    #Cybersecurity #InfoSec #NationStateThreat #CriticalInfrastructure #WaterSecurity #APT #EtherHiding #BrowserSecurity #ITAudit #Stuxnet
  • The Audit - Cybersecurity Podcast

    Decode Your Team: The Kolbe Index, Conative Strengths and Hiring Smarter

    10/08/2026 | 44 mins.
    What if the way you solve problems has nothing to do with how smart you are or how you feel, and everything to do with instinct? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem are joined by Jen Lotze from SipCyber and guest David Kolbe of Kolbe Corp, whose company built the Kolbe Index to measure the instinctive way people take action. After the whole team takes the assessment live, David breaks down what their scores actually mean and why the crew's mix of Fact Finder, Follow Thru, Quick Start, and Implementor strengths shapes the way they operate under pressure. 
    The conversation moves from the Johari Window and personal blind spots to why teams that clone each other's strengths tend to stall out, and why hiring people unlike yourself is one of the best things a leader can do. David also shares stories from decades of client work, from a CFO who built a physical model of a financing plan to a security engineer who cannot walk past an unsecured cable, before turning to what comes next for Kolbe Corp as they build AI tools around decades of behavioral data while trying to keep that data private and secure. 
    In this episode: 
    What the Kolbe Index actually measures, and why it's different from personality or IQ tests. 
    Conative strengths describe how you instinctively take action, not what you think or how you feel, and they do not change over time. 
    Why balanced teams outperform teams that clone each other. 
    A team full of people with the same instincts feels comfortable right up until deadlines start slipping and nobody notices the blind spot. 
    How opposite strengths cause friction, at work and at home. 
    If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT. 
    #KolbeIndex #TeamDynamics #Cybersecurity #Leadership #HiringSmart #ITAudit #WorkplacePsychology #TeamBuilding #Podcast #ITAuditLabs
More Technology podcasts
About The Audit - Cybersecurity Podcast
The Audit - Cybersecurity Podcast from IT Audit Labs features trusted security experts, industry leaders, and practitioners who unpack the threats, tactics, and trends shaping today’s risk landscape.With 90+ episodes and a top 10% global ranking on Listen Notes, The Audit goes beyond surface-level security talk. Each episode explores real-world threats, attacker techniques, compliance challenges, cyber risk, and the decisions security teams face before, during, and after an incident.IT Audit Labs helps organizations identify risk before attackers exploit it. Through threat assessments, security control reviews, compliance expertise, and a trusted network of partners and specialists, we help teams find their soft spots, strengthen their defenses, and make smarter security decisions.Listen in for sharp conversations, practical insight, and a clearer view of what’s coming next in cybersecurity.
Podcast website

Listen to The Audit - Cybersecurity Podcast, Power On with Mark Gurman and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
The Audit - Cybersecurity Podcast: Podcasts in Family