25 Security Podcast Episodes Every Beginner Should Hear
Twenty-five episodes for students and career changers starting from zero, ordered as a learning path: real attack stories first, then core concepts with a strong identity thread, then how defenders and the industry work, then careers. Lengths run from 7 minutes to over an hour, and some shows run long. Dates and lengths come from each show's feed.
25 episodes from 16 shows. Dates and lengths are from each show's own feed.
- 01
· 41 min · Beginner
One 2009 breach of 32 million plaintext passwords explains why password reuse and weak storage still matter.
- 02
· 34 min · Beginner
A retail giant breached through its HVAC contractor: the clearest first lesson in how third-party access becomes a way in.
- 03
160. Anatomy of a fall: One rural hospital’s ransomware story
· 31 min · Beginner
Ransomware told from inside a small rural hospital, so the cost lands on patients and staff, not abstractions.
- 04
· 66 min · Beginner
A convicted SIM swapper explains how carrier agents were talked into moving phone numbers, and why that unlocks accounts.
- 05
· 61 min · Beginner
A hired tester poses as a new employee for a week: what a sanctioned attack looks like and how it goes wrong.
- 06
This clever scam nearly hijacked a tech CEO's Apple ID
· 55 min · Beginner
MFA fatigue, real Apple alerts and a fake support call combine against Matt Mullenweg: a near-miss account takeover, step by step.
- 07
How the World Got Owned Episode 1: The 1980s
· 64 min · Beginner
A documentary on 1980s hacking, the Morris Worm included, that shows where today's problems started.
- 08
Certified: The CompTIA Security+ Audio Course
CIA and AAA: The Core Security Models (1.1)
· 13 min · Beginner
Thirteen minutes on confidentiality, integrity, availability and authentication, authorization, accounting: the vocabulary every later episode assumes.
- 09
Certified: The CompTIA Security+ Audio Course
Threats vs. Vulnerabilities: Likelihood, Impact, and Life Cycle (2.1)
· 15 min · Beginner
Separates threat, vulnerability and risk cleanly, the distinction beginners blur most often.
- 10
Threat Vector by Palo Alto Networks
From Bytes to Bait: Navigating Phishing, Smishing, and Vishing with Sama Manchanda
· 8 min · Beginner
An eight-minute primer from a Unit 42 consultant on phishing, smishing and vishing, the most common way in.
- 11
Hacking Multi-Factor Authentication
· 26 min · Beginner
Roger Grimes argues MFA is not the finish line, which is the right frame before you meet MFA bypass in the wild.
- 12
MFA prompt bombing (noun) [Word Notes]
· 7 min · Beginner
Seven minutes on one attack: flooding a user with login prompts until they tap approve.
- 13
Passkeys: consumer-friendly password killers?
· 47 min · Beginner
A plain-language take on passkeys, the phishing-resistant login that is replacing passwords on consumer accounts.
- 14
Our Help Desk Plaque Reads "Over 100,000 Threat Actors Served"
· 36 min · Practitioner
Three security leaders debate the help desk as an attack path, a short route into the social engineering behind account takeover.
- 15
#450 - New to Identity with Alexis Bernthal
· 84 min · Beginner
A newcomer and a veteran host talk through what identity and access management is and how someone new learns it.
- 16
A "Night" In The Life of a SOC Analyst (Real Truths)
· 62 min · Beginner
An honest look at SOC shift work, the most common first security job, including the night shifts.
- 17
Active Ransomware Incident Response Day in the Life
· 63 min · Practitioner
An incident responder who works live ransomware cases walks through what the first days of a response involve.
- 18
Microsoft Threat Intelligence Podcast
Incident Response with Empathy
· 43 min · Practitioner
A Microsoft responder on building free forensics resources for entry-level analysts, and the case for empathy when helping a breached team.
- 19
The Defender's Advantage Podcast
How to Run an Effective Tabletop Exercise
· 29 min · Practitioner
How organizations rehearse a breach before it happens, explained by a Mandiant consultant who runs these exercises.
- 20
Threat Vector by Palo Alto Networks
Inside 750 Breaches with Unit 42
· 42 min · Practitioner
Unit 42's incident response lead on patterns across 750 breaches in one year: where defenses actually fail.
- 21
Microsoft Threat Intelligence Podcast
Inside Microsoft’s Global Operation to Disrupt Lumma Stealer’s 2,300-Domain Malware Network
· 45 min · Beginner
How a legal and technical takedown of a password-stealing malware network actually works, from Microsoft's Digital Crimes Unit.
- 22
#76 - IAM as a Career with IDPro Ian Glazer
· 74 min · Beginner
IDPro co-founder Ian Glazer on identity as a career path, a specialty most beginners never hear about.
- 23
Hospitality to Cyber Pivot | Anthony Merlas | Breaking Into Cybersecurity
· 17 min · Beginner
A hotel general manager who moved into security with no tech background: 17 minutes on which skills carried over.
- 24
I Failed Over 300 Times Trying To Get Into Security ft. Joe South
· 40 min · Beginner
Rejection is normal when breaking in; this is the episode to hear before the applications start.
- 25
Episode 88 - Tips & Tricks For Breaking Into Security
· 55 min · Beginner
Practical advice on getting the first security role from someone who coaches new professionals through it.