Threat Vector by Palo Alto Networks
Hosted by David Moulton
Unit 42 incident responders and threat researchers explain what they saw on real engagements, in 35 minutes a week.
- Level
- Practitioner, assumes you work in or study security
- Status
- Slowing, last episode
- Who's behind it
- Vendor-run, Palo Alto Networks sourceProduced with N2K Networks.
- Last verified
- Transcripts for every episode
Listed underThreat intel and newsCISO and leadership
Editorial take
Threat Vector is strongest when Unit 42 people are at the mic. Episodes with incident responders, ransomware negotiators, and the DPRK fake-worker team carry evidence from hundreds of real engagements, and that is hard to get anywhere else for free. David Moulton runs a tidy 30 to 45 minute interview with clear takeaways. The honest limitation: Palo Alto Networks owns the show, and a fair share of guests are its own product and marketing leaders, so some weeks feel like a product briefing about AI runtime defense or platformization. Pick episodes by guest. Unit 42 consultants and outside CISOs are the reason to subscribe. Note the cadence: the last new episode aired in May 2026, followed by two months of encores and then silence.
Last hand-checked 2026-09-30, Last new episode 2026-05-21; encores ran weekly to 2026-07-30 and nothing has aired since.
Listen if you …
- want breach lessons from people who answer the incident response call
- track North Korean IT worker schemes, ransomware negotiation, or China-nexus activity
- brief executives and need plain-language framing of current threats
Skip if you …
- you want vendor-neutral commentary, the owner's products and executives appear often
- you need a reliable weekly habit right now, new episodes paused after May 2026
Start with these 3 episodes
- 01
Inside 750 Breaches with Unit 42
· 42 min · Beginner
The show at its most useful: aggregate breach data from Unit 42's IR practice, turned into where defenses actually fail.
- 02
The Billion Dollar Hiring Scam Funding North Korea
· 38 min · Practitioner
Concrete detail on DPRK fake IT workers from the team that investigates them, with hiring controls you can apply.
- 03
Inside Ransomware Negotiations: Trust Criminals or Walk Away?
· 30 min · Practitioner
A rare look at the negotiation table, the part of ransomware response most teams never see until it is too late.
About the show
Threat Vector is the podcast of Palo Alto Networks, produced with N2K Networks and distributed on the CyberWire network. It launched in July 2023 as a Unit 42 show and is hosted by David Moulton, who leads thought leadership for Unit 42.
Most episodes are a single interview of 30 to 45 minutes with a Unit 42 researcher or consultant, a Palo Alto Networks executive, or an outside security leader. Topics run from incident response statistics and ransomware negotiation to AI agent security and board communication. Special editions cover new Unit 42 threat research, and encores fill breaks.
Notable guests
- Wendi Whitmore
- Nikesh Arora
- Allie Mellen
- Keith Mularski
- Thomas P. Bossert
- Michael Daniel
- Lisa Plaggemier
- Ryan Chapman
Pairs with
If Threat Vector by Palo Alto Networks works for you, these likely will too.
The Defender's Advantage Podcast
Luke McNamara
Mandiant and Google Threat Intelligence Group analysts on the intrusions they responded to, in 30 tight minutes.
Listen if you do incident response or threat hunting and want lessons from Mandiant engagements.
interviewirregular30–60mMicrosoft Threat Intelligence Podcast
Elliot Volkman
Microsoft's own threat hunters on the Blizzards, Typhoons, and crime crews they track, plus the takedowns they run.
Listen if you work in a SOC or CTI team and want the analyst story behind Microsoft's threat reports.
interviewbiweekly30–60mCyberWire Daily
PickDave Bittner
Daily 25-minute briefing on the cybersecurity news that actually moved markets, regulators, or attackers.
Listen if you work in or sell to cybersecurity and need the daily news pulse.
narrativedaily<30m