Phillip Wylie Show
Phillip Wylie Show
Phillip Wylie
The Phillip Wylie Show is a premier cybersecurity podcast and media source for offensive security professionals. Hosted by Phillip Wylie, globally recognized ethical hacking expert, keynote speaker, and co-author of The Pentester Blueprint, the show features elite red team operators, penetration testers, and security leaders sharing real-world tradecraft, advanced tactics, career strategy, and insights on AI-driven cyber threats.
Drones, RF, and the Hacker Mindset with Luke Canfield
Luke Canfield came up the way a lot of hardware hackers do, the geeky kid in high school everyone came to when the school's computers broke, tinkering with Windows XP and war driving with homemade Yagi antennas built out of Pringles cans. That fascination with the hardware side never left him, and today he runs Reconnaissance Drone Consulting, teaching people about a threat surface most of the security world still isn't looking at.Phillip and Luke met at KernelCon, and this conversation is a wide tour through the corners of security that live outside the usual enterprise conversation. They get into the resurgence of war driving and how a headless Kali Pi has replaced a car full of gear, why AI is reshaping RF and CTF competitions and what that means for people who still want to learn things manually, and Luke's real focus, drones as a multi-domain problem spanning the cyber, operational, and physical.From there it opens up into the stuff that makes you rethink physical security entirely, the six-week drone iteration cycle coming out of Ukraine and how much of it ends up freely available online, why the cartels have run in-house drone design teams for over a decade, prison contraband as the biggest domestic misuse case, and the simple reason nobody looks up - as Luke puts it, humans evolved to avoid being eaten by big cats, not big birds. He also shares his current build, an open source unmanned ground vehicle named Tortuga, made from two donated power wheelchairs, that's headed into Texas cattle pastures to spot parasite outbreaks with thermal imaging.=========================Connect with Luke Canfield:LinkedIn: https://www.linkedin.com/in/luke-a-canfield/ =========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie
Sep 29
31 min
From Law Degree to AI Cyber Defense with Zack Korman
Zack Korman came into cybersecurity from about as far outside the field as you can get, a UK law degree and a master's in law and finance, and he now spends his days on the AI defense problems most of the industry is still catching up to. His outsider path is exactly what makes his take on the current AI moment worth hearing.Based in Norway, Zack got into code to win an argument with a professor, worked his way up to running a media company's tech department, then spent four and a half years as CTO of an Oslo cybersecurity startup building AI phishing simulations and AI insider threat detection. That work pulled him deep into the defensive side of security and into a conviction that detection is one of the most underserved areas of the field.Phillip and Zack get into why the "thousand crap alerts" model of detection is broken, the blind spots that let obvious insider threats slip past a SOC that was never even receiving the data, and Zack's work on AI agent security, including the malicious MCP server he built to prove how completely an agent can exfiltrate a company. From there the conversation turns to the thing Zack has become known for online, pushing back on inflated AI risk claims, the fallout from the Hugging Face incident, and why so many of the loudest warnings about AI in cybersecurity are coming from people who have never worked in security. They also cover frontier versus local models, why smaller models could reshape defensive work, model guardrails and offensive testing, and Zack's straightforward advice for anyone trying to fold AI into their day to day.=========================Connect with Zack Korman:LinkedIn: https://www.linkedin.com/in/zacharyakorman/X: https://x.com/ZackKorman=========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with Suzu Labshttps://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/
Sep 22
31 min
Cloud Security, Shadow IT, and Breaking Into the Field with rekdt
Most advice about breaking into cybersecurity tells you to follow the path. rekdt makes the opposite case: the path is exactly what makes you look like everyone else. In this episode he shares a candid, sometimes contrarian view of the field, shaped by nearly two decades in it.rekdt runs a cloud security tower for a large enterprise operating across multiple clouds, and he came up through the professional cloud world during his time at AWS. He is also a longtime fixture in the hacker community, volunteering with the DEF CON Social Engineering Community and helping out at Red Team Village. His start in tech goes back to a teenage fascination with dial-up, the piracy and IRC scene, and picking apart malicious code on early MySpace pages, before a winding route through bartending and help desk work led him into engineering and eventually security.In this episode, rekdt and Phillip get into why the most interesting security conversations happen at cloud and developer conferences rather than security echo chambers, how cloud and containers upended traditional defenses, and why shadow IT and vibe coding are making things harder. rekdt explains why cybersecurity is really a people problem, what actually makes a candidate stand out when everyone has the same resume, and why he sometimes asks people why they want to get into security at all. He closes with honest, practical advice on building a career with an actual plan instead of just chasing the title.=========================Connect with rekdt:https://x.com/rekdt=========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with Suzu Labshttps://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/
Sep 15
42 min
From Cyber Warfare to AI-Powered Defense with Dave Kennedy
Dave Kennedy was a skeptic. After 28 years in the field, he had heard every claim about the next technology that was going to change cybersecurity, and he assumed AI was more of the same. Then it changed his mind, and now he is building some of the most advanced defensive AI in the industry.Dave is the founder of TrustedSec and Binary Defense. He got his start on the military intelligence side as a U.S. Marine in cyber warfare. He is a well-known name in the cybersecurity community through his work on BackTrack Linux, the Social-Engineer Toolkit, and Metasploit. Dave is also, by his own description, obsessed with cybersecurity as both a career and a hobby - he can't get enough of it.In this episode, Dave breaks down how AI has re-energized his work and, in his words, made this feel like the early 2000s all over again. He walks through Night Beacon, the AI system his team built to transform the security operations center, and explains why they train their own models instead of relying on frontier models, how they keep a human in the loop for every final determination, and why his teams now ship more than a million lines of code a week. Phillip and Dave get into what AI means for offensive work at TrustedSec and Binary Defense, concerns about autonomous hacking and cheaper zero days, and why Dave believes AI will create more work in cybersecurity rather than eliminate it.=========================Connect with Dave Kennedy:https://www.linkedin.com/in/davidkennedy4https://x.com/HackingDavehttps://binarydefense.comhttps://trustedsec.com=========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with Suzu Labshttps://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/
Sep 8
33 min
Vulnerability Research, AI Slop, and Why Fundamentals Still Win with Stephen Sims
AI can now hand someone a working Linux kernel privilege escalation exploit, even if that person cannot explain a single line of how it works. Stephen Sims joined the show to talk about what that shift means for offensive security, and why the fundamentals matter more now, not less.Stephen is the curriculum lead for SANS Institute's Offensive Operations program, where he has spent more than 15 years as an author and instructor, and he is a co-founder of Off by One Security. He is a longtime exploit developer and vulnerability researcher who came up through game hacking, network engineering, and years of binary exploitation, reverse engineering, and weaponizing bugs in browsers and the kernel.In this episode, Stephen and Phillip get into how AI is reshaping vulnerability research and exploit development. Stephen explains why human validation is still doing the heavy lifting behind the big vulnerability-count headlines, how AI tends to overstate or understate severity, and why so many submissions are now AI slop or duplicates. He makes the case that logic bugs remain the hardest thing for AI to find, walks through his roadmap for anyone serious about learning exploit development, and shares why he tells students to do the work manually before letting AI do it for them. Stephen also offers grounded advice for breaking into the field, from building a real technology foundation first to staying curious and paying your dues, and gives his honest read on where the opportunity is heading.=========================Connect with Stephen Sims:LinkedIn: https://www.linkedin.com/in/stephen-sims-2788091/X: https://x.com/Steph3nSimsOff by One Security: https://offbyonesecurity.com/YouTube: https://www.youtube.com/@OffByOneSecurity=========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with Suzu Labshttps://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/
Sep 1
35 min
Purple Teaming with Sarah Hume: Turning Threat Intelligence Into Actionable Testing
Penetration testing tells you where the vulnerabilities and misconfigurations are. Purple teaming asks a different question: when an attacker is actually operating inside your environment, what can your tools see, and what slips right past them? Sarah Hume has built her career around that second question.Sarah leads the Purple Team program at Security Risk Advisors. Her path into cybersecurity started with a single week at a summer camp at Dakota State University, which her dad talked her into against her wishes and which ended up changing everything. She went on to study cybersecurity at Penn State and began her career in network, physical, and OT/ICS penetration testing before moving into purple teaming as a red operator and eventually leading the practice.In this episode, Sarah breaks down how her team runs purple teams at scale, roughly 200 a year, working through TTPs across the full attack chain alongside a client's blue team. She explains why she favors smart automation over fully automated testing, how her team builds detections that hold up instead of breaking on a single command string or file hash, and why remediation only matters if it is actionable. She also covers living off the land binaries, her grounded take on AI in offensive testing, and real advice for breaking into the field, from home labs and certifications to taking down imposter syndrome and building the communication skills that separate a good tester from a useful one.=========================Connect with Sarah Hume:LinkedIn: https://www.linkedin.com/in/sarah-hume1 =========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with @Suzulabshttps://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/
Aug 25
29 min
From English Teacher to OSINT Investigator: Lindsey Yagi-Hatake on Breaking Into Cybersecurity
In under a year, Lindsey Yagi-Hatake went from teaching English in a public school classroom to working as a professional OSINT investigator. Her path into cybersecurity did not start with a certification or a computer science degree. It started with survival.Lindsey spent six years as a public school English teacher and holds a master's degree in education administration along with certifications in teaching English as a second language, where she specialized in helping immigrant students adjust to life in a new country. That background in language, culture, and patient instruction shapes how she approaches her work today as an OSINT investigator and privacy manager at Decisive Resources, where she works alongside Mishaal Khan.In this episode, Lindsey shares the full story of how she broke into the field. After becoming a survivor of domestic violence in 2024, she found herself being digitally stalked and geolocated, and when the systems meant to protect her fell short, she taught herself open source intelligence to document what was happening. She talks about the gatekeeping she ran into early on, the moment she spent her last $500 on a DEF CON badge, and how the community at Noob Village and mentors like Mishaal Khan and Chadd Watson changed everything. She also shares hard-won advice for anyone trying to break in today.This is a conversation about grit, community, digital safety advocacy, and what it really takes to get into cybersecurity in today's job market.=========================Connect with Lindsey Yagi-Hatake:LinkedIn: https://www.linkedin.com/in/lindseyhatake/=========================Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with Suzu Labshttps://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/
Aug 18
41 min
AI, Automation, and the Future of Penetration Testing with Herman Zubenko
How is AI changing penetration testing, bug bounty hunting, and offensive security?In this episode of The Phillip Wylie Show, Phillip sits down with Herman Zubenko to explore how artificial intelligence and automation are transforming the way security professionals discover and validate vulnerabilities.Herman shares his unconventional journey from quality assurance and software development into cybersecurity, including how having one of his own accounts compromised led him to investigate the incident with AI and eventually begin using AI for bug bounty research.Phillip and Herman discuss AI-assisted penetration testing, continuous security testing, open and local models, the importance of keeping humans in the loop, and why AI is more likely to enhance penetration testers than replace them.They also discuss how aspiring cybersecurity professionals can use AI to accelerate their learning while still developing the technical fundamentals needed to understand how systems, applications, and vulnerabilities actually work.========================= Connect with Herman Zubenko:LinkedIn: https://www.linkedin.com/in/herman-zubenko/Syntetisk Tech Limited website: https://syntetisk.tech/========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with @Suzulabshttps://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/
Aug 11
23 min
From First-Generation Graduate to DEF CON Speaker: Moo's Cybersecurity Journey
In this episode of The Phillip Wylie Show, Phillip welcomes cybersecurity community member Moo for an inspiring conversation about breaking into cybersecurity, building a career through persistence, and giving back to others along the way.Moo shares his unconventional hacker origin story, from being inspired by *The Matrix* and DEF CON videos as a teenager to eventually speaking at DEF CON and earning his first National Cyber League challenge coin. Along the way, he discusses the value of internships, apprenticeships, mentorship, and exploring different areas of cybersecurity before settling on a career path.Phillip and Moo also discuss the importance of community, continuous learning, and why cybersecurity conferences like DEF CON can be life-changing for newcomers.Whether you're a student, career changer, or experienced security professional, this episode offers practical advice and plenty of encouragement for anyone looking to grow in cybersecurity.========================= Connect with Moo:LinkedIn: https://www.linkedin.com/in/munirmuhammad/========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with @SuzuLabs https://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/========================= Podcast Music by Syntax976=========================LinkedIn: https://www.linkedin.com/in/brandon-prince-27a0ab51/X: https://x.com/syntax976
Aug 4
27 min
Casey Smith (SubTee): Living Off the Land, Deception Technology, and the Evolution of Offensive Security
In this episode of The Phillip Wylie Show, Phillip Wylie sits down with offensive security researcher, educator, and entrepreneur Casey Smith (SubTee) to discuss his journey into cybersecurity, the evolution of offensive tradecraft, and why deception technology is becoming one of the most effective defensive strategies in today's threat landscape.Casey shares how he transitioned from systems administration into security through application testing and enterprise security projects before becoming widely recognized for his pioneering research into Living Off the Land Binaries (LOLBins). The conversation also explores how Windows security has evolved over the years, the impact of application whitelisting, and why modern defenders should be thinking differently about detection.The discussion wraps up with Casey's latest venture, where he is helping organizations leverage deception technologies while mentoring the next generation of cybersecurity professionals.========================= Connect with Casey Smith:X: https://x.com/_subTeeGitHub: https://github.com/AlloySecureGroup========================= Connect with your host, Phillip Wylie: LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie========================= Sponsored by Suzu Labs=========================All the ways to connect with @SuzuLabs https://suzulabs.comhttps://x.com/suzulabshttps://www.linkedin.com/company/suzu-labs/========================= Podcast Music by Syntax976=========================LinkedIn: https://www.linkedin.com/in/brandon-prince-27a0ab51/X: https://x.com/syntax976
Jul 28
27 min
Load more