Skip to content
PodcastsNewsAdversary Universe Podcast

Adversary Universe Podcast

CrowdStrike
Adversary Universe Podcast
Latest episode

80 episodes

  • Adversary Universe Podcast

    Preparing for an AI-Powered Future with Amazon CSO Steve Schmidt

    09/10/2026 | 37 mins.
    Steve Schmidt, SVP and CSO at Amazon, sees firsthand how both defenders and adversaries are using AI to their advantage. In this episode, he joins Adam and Cristian to discuss modern AI models, evolving adversary behavior, and how Amazon is responding to shifts in the threat landscape.

    “The big change we’ve seen recently is the ability of models to chain things together to produce something interesting,” Steve says. As AI models grow more adept at automatically chaining and acting, he adds, the time to respond has dramatically decreased.

    Defenders must now measure and respond in seconds or minutes, when they used to have hours or days. In using AI to fight AI-driven attacks, they must also consider which AI models they’re using. Using the right model is essential. If the business is building defenses for Mythos or Fable, and the adversary is using a different technology, the threat model changes.

    While adversarial use of AI is a primary concern, right alongside it is employees’ use of AI. As Steve puts it, to build a good AI governance program, defenders need strong identity governance and data governance programs. The identity component is key. Many organizations over-permission agents; others are so restrictive they defeat the purpose of having agents at all.

    How did Amazon handle this? Steve shares how the company built its own authentication framework that treats agents as a third type of identity. The agent temporarily inherits permissions through session-based delegation from the human who deployed it; it can only access what that person can access. It can’t do what they can’t do, even if a malicious prompt tries to trick it.

    Tune in to hear more details about AI-driven defense, and the evolution of AI-powered offense, in this episode of the Adversary Universe podcast.
  • Adversary Universe Podcast

    AI as a Weapon, Target, and Enterprise Reality with CoreWeave’s Natasha Eastman

    08/13/2026 | 42 mins.
    “What are these AI systems attached to that make them such a huge risk?”

    “Everything.”

    Today, the Adversary Universe podcast welcomes Natasha Eastman, head of threat intelligence at CoreWeave, to share her perspective on how AI is used in the modern enterprise, the infrastructure needed to support it, and how she sees adversaries both using and attacking it.

    AI hasn’t necessarily given adversaries wholly new capabilities, Natasha explains. It enables them to do things faster, more capably, and with a lower barrier to entry. AI is seen in phishing scams, recon, coding and tooling support, fraud, and language and persona operations. It’s allowing threat actors to refine their content and make phishing even harder to detect.

    When it comes to attacks on AI, supply chain compromise and identity targeting are top of mind. Depending on how agents are configured and who configured them, they can have a phenomenal amount of access to internal and external resources. An attacker who gains control of an employee or agent identity could have unrestricted access to company systems and resources without the right guardrails in place. Our hosts and guest agree: It’s the new insider risk.

    “Everyone’s infrastructure that has access to AI capability is a target,” Natasha says.

    Tune in to hear Adam, Cristian, and Natasha pool their observations on AI threats, share what concerns them most, and offer their advice on what makes a strong AI governance program.
  • Adversary Universe Podcast

    Unpacking the CrowdStrike 2026 Threat Hunting Report with CrowdStrike’s Katie Blankenship

    08/03/2026 | 32 mins.
    The CrowdStrike 2026 Threat Hunting Report is now live! The report sheds light on how our threat hunters and analysts hunt and defend against the world’s most sophisticated adversaries. It’s packed with stories from the front lines and trends that define the modern threat landscape.

    Joining Adam to dig into its findings is Katie Blankenship, Sr. Director of the Global Threat Analysis Cell for the CrowdStrike Counter Adversary Operations team. Katie, who leads the charge for our major intelligence reports, explains the herculean effort that goes into distilling a year’s worth of events into a single report. The CrowdStrike 2026 Threat Hunting Report is the product of seven trillion events analyzed, 14 million daily detection leads, and 36,000 annual customer alerts and notifications.

    So what did they tell us? These are some key takeaways covered in this episode:

    The window between vulnerability disclosure and exploitation is collapsing. From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public proof of concept (PoC) was conducted within 48 hours of the PoC’s release. China-nexus adversaries VAULT PANDA and GENESIS PANDA, both highly active in the last six months, are monitoring vulnerability disclosures so they can quickly weaponize them.

    Adversaries are targeting the developer ecosystem. Software supply chain attacks aren’t new, but adversaries are seeing opportunities to exploit trust relationships in this pipeline. ALTERED SPIDER is one of them — this adversary compromised 300+ software dependencies in one day, harvested credentials, and pivoted into cloud environments.

    Technology and finance are in the crosshairs. Technology was the most targeted sector for the ninth year running. DPRK-nexus adversary FAMOUS CHOLLIMA’s operations accounted for 55% of all state-sponsored intrusions targeting this sector. The financial services sector saw an 11% year-over-year increase in targeting, with FAMOUS CHOLLIMA driving activity there as well.

    Tune in to hear Adam and Katie discuss the CrowdStrike 2026 Threat Hunting Report’s most interesting stories, stats, and adversaries in an episode that Adam calls “the podcast for those who didn’t want to read the 48-page report.”

    Methodology & Source: All information provided is based on the CrowdStrike Counter Adversary Operations team’s proprietary threat intelligence gathered between July 1, 2025, and June 30, 2026. Stats may include data from the entire period surveyed or excerpts of data from specific date ranges within the period.
  • Adversary Universe Podcast

    SaaS Security Threats to Worry About, with Salesforce’s Kelly McCracken

    07/09/2026 | 36 mins.
    Kelly McCracken, SVP of the Cyber Security Operations Center at Salesforce, leads one of the most complex and high-scale cyber operation environments on the planet. Today, she joins Adam and Cristian to discuss how adversaries are targeting SaaS vendors, the most underappreciated SaaS misconfigurations, and what the future of the shared responsibility model looks like.

    SaaS is a continuously growing target, but who is taking aim? eCrime adversaries such as SNARKY SPIDER and CORDIAL SPIDER are ones to watch, Adam says. They take advantage of poorly secured identities that make for lucrative targets. If a threat actor can log in as a legitimate user and gain access to a SaaS environment, they can reach any range of applications with poor security configurations — and exfiltrate their sensitive data.

    The shared responsibility model is essential to defense. Businesses must understand what their vendors are responsible for securing and what they’re responsible for securing. A lack of configurations and policies opens the door to both external adversaries and insider threats.

    “I feel like most security teams are flying blind when it comes to what’s going on with some of the most precious data for their company,” Kelly says.

    Tune in for a deep-dive conversation on one of the most prominent threats facing businesses today and stick around to hear about Cristian’s latest culinary fail and Kelly’s elite Latin skills.
  • Adversary Universe Podcast

    Examining the Glassworm Takeover with Tillmann "Bot Slayer" Werner

    06/25/2026 | 38 mins.
    He’s back, and he’s ready to talk botnet takeovers.

    Tillmann Werner, VP of Intelligence Production at CrowdStrike, returns to the podcast to discuss CrowdStrike’s coordinated takeover of the Glassworm botnet. Glassworm was a global threat targeting software developers through the open-source supply chain. This infection vector stood out — open-source ecosystems are based on trust, and adversaries are learning they can reach a vast pool of victims by compromising the supply chain. Some open-source libraries get 100 million downloads per week.

    Glassworm was described as an “unkillable” botnet. Resilience was built into its design, which relied on four different command-and-control channels. This made the takeover complicated because a botnet can’t be taken over until all command-and-control mechanisms are suppressed.

    “Once it’s down, you gotta make sure it’s down,” said Adam, who calls Tillmann the “bot slayer.”

    In this episode, they get into the details: what Glassworm was after, how its unknown operators strengthened its infrastructure, and the planning and execution behind the takeover. Tillmann and his team facilitated the process by conducting extensive technical analysis, understanding Glassworm’s evolution, and spotting the opportunity to disrupt it. They worked with partners across the private and public sectors, as well as internally at CrowdStrike, to do it safely and avoid disrupting critical systems.

    Come for the behind-the-scenes details, and stay for the debate around baking the perfect pizza in this episode of the Adversary Universe podcast.

    Learn more in our blog: https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/.
More News podcasts
About Adversary Universe Podcast
Modern adversaries are relentless. Today’s threat actors target organizations around the world with sophisticated cyberattacks. Who are they? What are they after? And most importantly, how can you defend against them? Welcome to the Adversary Universe podcast, where CrowdStrike answers all of these questions — and more. Join our hosts, a pioneer in adversary intelligence and a specialist in cybersecurity technology, as they unmask the threat actors targeting your organization.
Podcast website

Listen to Adversary Universe Podcast, Pod Save America and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features