100 episodes
Cyber Warfare on Tap: Water Utility Hacks, Nation-State APTs and Secure Browsers
24/08/2026 | 47 mins.What happens when nation-state hackers target the water coming out of your tap? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem break down the recent wave of attacks on water utilities across Minnesota and 27 other states, where threat actors got their hands on administrative passwords to programmable logic controllers. The crew is joined for the first time by Kelly Venzke, Director of Business Operations at IT Audit Labs, who brings a business leadership perspective to a conversation that quickly turns technical.
From there, Eric and Nick trace how these attacks echo the Stuxnet playbook used against Iran's nuclear program, explain how threat actors are impersonating help desk staff over Microsoft Teams to gain remote access, and dig into a blockchain-based command and control technique that hides inside paid search ads. The conversation wraps with practical advice on browser security, including why isolating AI browser extensions and ditching saved passwords in the browser matters more than most people realize.
In this episode:
Nation-state hackers breach US water utilities across 27 states. How Iranian threat actors obtained administrative access to programmable logic controllers and why Minnesota may have been ground zero.
The Stuxnet connection. Eric breaks down how the historic attack on Iran's nuclear centrifuges bridged an air-gapped network, and why today's "air-gapped" systems often aren't as isolated as they seem.
Help desk impersonation over Microsoft Teams. Why blocking external Teams-to-Teams calls has become a critical defense against social engineering attacks targeting employees.
EtherHiding: blockchain-backed command and control. How attackers use paid search ads and blockchain infrastructure to maintain persistent, hard-to-detect access to compromised environments.
Practical browser security tips. Kelly, Eric, and Nick talk through password managers, isolating LLM browser extensions, and why saving passwords in your browser is a bad habit worth breaking.
Don't wait until your organization is the next headline. Like, share, and subscribe for more conversations on the threats shaping cybersecurity and IT today.
#Cybersecurity #InfoSec #NationStateThreat #CriticalInfrastructure #WaterSecurity #APT #EtherHiding #BrowserSecurity #ITAudit #Stuxnet- What if the way you solve problems has nothing to do with how smart you are or how you feel, and everything to do with instinct? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem are joined by Jen Lotze from SipCyber and guest David Kolbe of Kolbe Corp, whose company built the Kolbe Index to measure the instinctive way people take action. After the whole team takes the assessment live, David breaks down what their scores actually mean and why the crew's mix of Fact Finder, Follow Thru, Quick Start, and Implementor strengths shapes the way they operate under pressure.
The conversation moves from the Johari Window and personal blind spots to why teams that clone each other's strengths tend to stall out, and why hiring people unlike yourself is one of the best things a leader can do. David also shares stories from decades of client work, from a CFO who built a physical model of a financing plan to a security engineer who cannot walk past an unsecured cable, before turning to what comes next for Kolbe Corp as they build AI tools around decades of behavioral data while trying to keep that data private and secure.
In this episode:
What the Kolbe Index actually measures, and why it's different from personality or IQ tests.
Conative strengths describe how you instinctively take action, not what you think or how you feel, and they do not change over time.
Why balanced teams outperform teams that clone each other.
A team full of people with the same instincts feels comfortable right up until deadlines start slipping and nobody notices the blind spot.
How opposite strengths cause friction, at work and at home.
If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT.
#KolbeIndex #TeamDynamics #Cybersecurity #Leadership #HiringSmart #ITAudit #WorkplacePsychology #TeamBuilding #Podcast #ITAuditLabs - Can a $35 padlock from a hardware store really keep anyone out? In this episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Eric Osterberg of Grey Duck Locks for a live lock picking demo, a deep dive into how modern car keys get cloned, and a wide-ranging conversation about vibe coding, AI agents, and 3D printing. Eric brings decades of hands-on locksmithing and automotive security experience, along with a builder's instinct that has him constantly shipping his own tools, from a computer-aided dispatch app for emergency management volunteers to a searchable database for ham radio operators.
The crew gets into how pin tumbler locks are actually picked, why European vehicles like Audi and Volvo are harder to clone than most domestic trucks, and how devices like the Softdrill can manipulate a safe's dial by listening to its own internal mechanics. From there the conversation turns to AI, covering Eric's use of large language models to streamline his business, the rise of vibe coding for non-programmers, and a heated but even-handed debate over new federal rules pushing automakers toward built-in driver monitoring systems.
In this episode:
Live lock picking demo and how pin tumbler locks actually work
How car key cloning really works, and why some brands resist it better
Safe manipulation tools like the Softdrill and TL2000
Vibe coding, AI agents, and building your own tools without a dev team
The driver monitoring debate — A new federal mandate pushes automakers toward built-in impairment detection
Whether you're curious about lock picking as a hobby or trying to understand how exposed your car key really is, this episode has something for you. Like, share, and subscribe for more conversations at the intersection of security, hardware, and AI.
#LockPicking #Locksmith #Cybersecurity #CarKeySecurity #VibeOps #AIAgents #ITAudit #Podcast #3DPrinting #InfoSec - What happens when a ransomware attack takes less effort than ordering takeout? In this live news episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Tabitha Senty of IT Audit Labs to break down the headlines shaping cybersecurity right now. The crew covers how AI is lowering the barrier to entry for ransomware attacks, why identity and access still sit at the center of every breach, and how threat actors are chaining together low and medium severity vulnerabilities to gain a foothold nobody saw coming.
From there, the conversation moves into social engineering and the human side of security, including DEF CON's social engineering contest and lessons on training people without fear or punishment. The crew also digs into a CISA warning on how fast AI is accelerating cyber risk, a fresh executive push on post-quantum cryptography, and closes out with a head-scratching pivot from Midjourney into full-body health scanners at spas, and everything that could go wrong with it.
In this episode:
Why AI is lowering the cost of ransomware attacks — Identity and access are still the real entry point, and AI just makes the attack faster once someone's in.
How threat actors chain low-severity vulnerabilities into major breaches — Eric explains why patching only highs and criticals is no longer enough to protect an environment.
The social engineering tactics still fooling smart people — Pretexting as IT, DEF CON's live social engineering contest, and why fear-based training backfires.
A CISA warning that cyber risk is accelerating faster than expected — The timeline for AI-driven offensive capability is no longer years away, it's months.
Midjourney's pivot into full-body health scanners at spas — The crew unpacks the security, compliance, and data governance nightmare hiding behind a wellness trend.
If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT.
#AIRansomware #Cybersecurity #SocialEngineering #PostQuantum #IdentitySecurity #ITAudit #CyberNews #DEFCON #ThreatIntelligence #CyberRisk - What happens when a ransomware attack takes less effort than ordering takeout? In this live news episode of The Audit, Joshua Schmidt, Eric Brown, and Nick Mellem sit down with Tabitha Senty of IT Audit Labs to break down the headlines shaping cybersecurity right now. The crew covers how AI is lowering the barrier to entry for ransomware attacks, why identity and access still sit at the center of every breach, and how threat actors are chaining together low and medium severity vulnerabilities to gain a foothold nobody saw coming.
From there, the conversation moves into social engineering and the human side of security, including DEF CON's social engineering contest and lessons on training people without fear or punishment. The crew also digs into a CISA warning on how fast AI is accelerating cyber risk, a fresh executive push on post-quantum cryptography, and closes out with a head-scratching pivot from Midjourney into full-body health scanners at spas, and everything that could go wrong with it.
In this episode:
Why AI is lowering the cost of ransomware attacks — Identity and access are still the real entry point, and AI just makes the attack faster once someone's in.
How threat actors chain low-severity vulnerabilities into major breaches — Eric explains why patching only highs and criticals is no longer enough to protect an environment.
The social engineering tactics still fooling smart people — Pretexting as IT, DEF CON's live social engineering contest, and why fear-based training backfires.
A CISA warning that cyber risk is accelerating faster than expected — The timeline for AI-driven offensive capability is no longer years away, it's months.
Midjourney's pivot into full-body health scanners at spas — The crew unpacks the security, compliance, and data governance nightmare hiding behind a wellness trend.
If this conversation sparked something, share it with someone who needs to hear it. Like, share, and subscribe for more of the discussions shaping the future of cybersecurity and IT.
#AIRansomware #Cybersecurity #SocialEngineering #PostQuantum #IdentitySecurity #ITAudit #CyberNews #DEFCON #ThreatIntelligence #CyberRisk
More Technology podcasts
Trending Technology podcasts
About The Audit - Cybersecurity Podcast
The Audit - Cybersecurity Podcast from IT Audit Labs features trusted security experts, industry leaders, and practitioners who unpack the threats, tactics, and trends shaping today’s risk landscape.With 90+ episodes and a top 10% global ranking on Listen Notes, The Audit goes beyond surface-level security talk. Each episode explores real-world threats, attacker techniques, compliance challenges, cyber risk, and the decisions security teams face before, during, and after an incident.IT Audit Labs helps organizations identify risk before attackers exploit it. Through threat assessments, security control reviews, compliance expertise, and a trusted network of partners and specialists, we help teams find their soft spots, strengthen their defenses, and make smarter security decisions.Listen in for sharp conversations, practical insight, and a clearer view of what’s coming next in cybersecurity.
Podcast websiteListen to The Audit - Cybersecurity Podcast, The Vergecast and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Audit - Cybersecurity Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.
The Audit - Cybersecurity Podcast: Podcasts in Family

























