Best podcast episodes on identity attacks
Phishing, MFA bypass, SIM swaps, stolen session tokens and OAuth abuse: how attackers take over accounts today, and why phishing-resistant credentials change the picture.
12 episodes from 12 shows. Dates and lengths are from each show's own feed.
- 01
You Should Be Afraid of SIM Swaps
· 33 min · Beginner
Why a phone number is a weak identity anchor, and how SIM swappers turn that into account takeover.
- 02
· 13 min · Beginner
The story of the phishing toolkit built to prove MFA was not foolproof, in 13 minutes.
- 03
This clever scam nearly hijacked a tech CEO's Apple ID
· 55 min · Beginner
MFA fatigue, real Apple alerts and a fake support call aimed at Matt Mullenweg, broken down step by step.
- 04
The Defender's Advantage Podcast
How Threat Actors Bypass Multi-Factor Authentication
· 27 min · Beginner
The MFA bypass techniques Mandiant keeps seeing, with the controls that hold up.
- 05
Blueprint: Build the Best in Cyber Defense
How Phishing Resistant Credentials Work with Mark Morowczynski and Tarek Dawoud
· 54 min · Practitioner
The clearest explanation here of why FIDO2 and passkeys stop credential phishing and MFA relay.
- 06
#373 - Going Passkey Phishing with Nishant Kaushik
· 58 min · Practitioner
FIDO Alliance's CTO on where passkeys stop phishing and the objections raised against them.
- 07
Microsoft Threat Intelligence Podcast
Eviltokens: A Conversation with Huntress on an AI‑Enabled Device Code Phishing Campaign
· 42 min · Practitioner
Device code phishing explained by the teams that tracked it, a growing token theft vector.
- 08
Risky Business #795 -- How The Com is hacking Salesforce tenants
· 68 min · Practitioner
Weekly news led by how The Com was getting into Salesforce tenants.
- 09
Cloud Security Podcast by Google
EP268 Weaponizing the Administrative Fabric: Cloud Identity and SaaS Compromise in M Trends 2026
· 34 min · Practitioner
Mandiant analysts and responders on how attackers now take over cloud identity and SaaS admin planes.
- 10
· 24 min · Expert
Semperis on full account takeover of Entra cross-tenant SaaS apps through an OAuth flaw.
- 11
Dirk-Jan Mollema Walks Us Through the Entra ID Cross-Tenant Vulnerability Discovery
· 60 min · Expert
The researcher who found it explains how one Entra ID token flaw could have crossed every tenant boundary.
- 12
Critical Thinking - Bug Bounty Podcast
Episode 110: Oauth Gadget Correlation and Common Attacks
· 50 min · Expert
Bounty hunters on the OAuth flaws they chain into account takeover in real programs.