Find partners
The Defender's Advantage Podcast

The Defender's Advantage Podcast

Hosted by Mandiant

Episodes

181

Latest episode

Aug 2026

Language

EN-US

About the show

Learn about the latest threat and cybersecurity trends on The Defender’s Advantage Podcast! Hear from experts in the field as Host Luke McNamara, from Google Threat Intelligence Group, interviews analysts, researchers and other guests on the frontlines of the latest attacks. Episodes dive deep into various topics, including nation-state activity, cybercrime, malware and tradecraft, incident response, defensive guidance, and more. Don't forget to subscribe!

Listen to episodes

60 recent
August 10, 202633 min

The New Frontline of Supply Chain Attacks

In this episode of Mandiant’s Defender’s Advantage Podcast, host Luke McNamara sits down with Ben Read, Head of Strategic Threat Intelligence at Wiz, to explore the rapidly shifting landscape of software supply chain compromises. While historic, nation-state operations like SolarWinds focused on compromising closed-source software, modern adversaries have expanded their playbook to target widely used open-source ecosystems, repositories, and automated CI/CD pipelines. Ben discusses how differing tactics in these campaigns play out in the current threat landscape. For more on Wiz's research: https://www.wiz.io/blog/tag/research

July 22, 202635 min

Shadow LLMs, Agentic Identities, and Securely Integrating AI

Host Luke McNamara sits down with Muhammad Muneer, Technical Manager on Mandiant's Incident Response team, to unpack the stark realities of enterprise AI adoption. They explore why securing AI starts with resolving legacy security debt (specifically around IAM, supply chain, and secrets management) and dissect the critical differences between "governance for AI" and "governance of AI." Muhammad details real-world frontline findings—from developers bypassing API gateways to the financial costs of leaked LLM API keys—and outlines the emerging threat of adversaries leveraging LLM-enabled command-line tools for living-off-the-land attacks.

July 13, 202638 min

Human-Machine Teaming: Applying AI to Frontline Threat Intelligence Workflows

Host Luke McNamara is joined by Jake Nicastro, who leads the AI function for the Frontline Intelligence Operations team within the Google Threat Intelligence Group (GTIG). Jake details how his team is shifting from simple prompt engineering to more advanced agentic workflows, focusing on a model of "human-machine teaming." He shares practical use cases for AI in CTI—including automated script decoding, hunting query creation, and streamlining repetitive metadata-labeling tasks. Jake also discusses the concept of "judge agents" for quality control, the implementation of structured analytic techniques, and how real-time AI assistants can accelerate on-boarding and domain transitions for frontline threat analysts.

April 27, 202629 min

Google's Disruption Mission

Host Luke McNamara is joined by Charley Snyder, Head of Disruption Operations at Google Threat Intelligence Group, to delve into how Google is crafting a more coordinate approach to disrupting adversary cyber operations. Charley describes how this disruption focus is not hacking back, how it builds on existing work across Google security teams, and some of the recent wins such as the IPIDEA and GRIDTIDE takedowns.

April 15, 202627 min

Takeaways from the 2026 M-Trends Report

Host Luke McNamara is joined by Chris Linklater, Practice Leader at Mandiant, to discuss the 2026 edition of Mandiant's M-Trends Report. Chris dives into the latest trends observed in breached throughout 2025 and into this year, noting some of the key aspects organizations should focus on in applying these insights into today's threat landscape. https://cloud.google.com/security/resources/m-trends

March 23, 202630 min

Using GTI to Hunt Adversaries on the Dark Web

In this episode of the Defenders Advantage Podcast, host Luke McNamara sits down with Google Threat Intelligence experts Jose Nazario and Brandon Wood. They dive into the rollout of new dark web and underground monitoring capabilities, explaining how AI is fundamentally changing the way defenders track adversaries. https://cloud.google.com/blog/products/identity-security/bringing-dark-web-intelligence-into-the-ai-era\

January 16, 202631 min

How Android Combats Mobile Scams

Host Luke McNamara is joined by Eugene Liderman, Senior Director in Android's Security and Privacy Group, to discuss the evolving world of mobile-targeting scams. Eugene details some of the unique aspects to mobile scams, regional variations in tactics by scammers, and the steps Android has taken to combat this problem.

October 22, 202526 min

UNC5221 and the BRICKSTORM Campaign

Sarah Yoder (Manager, Mandiant Consulting) and Ashley Pearson (Senior Analyst, Advanced Practices on Google Threat Intelligence Group) join host Luke McNamara to discuss UNC5221 and their operations involving BRICKSTORM backdoor. This highly sophisticated, suspected China-nexus cyber-espionage threat group is known for aggressively targeting internet-facing network appliances (like VPNs and firewalls) to establish long-term, stealthy access for espionage. Read our blog post for more: https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign

September 15, 202539 min

How vSphere Became a Target for Adversaries

Stuart Carrera (Senior Consultant, Mandiant Consulting) joins host Luke McNamara to discuss how threat actors are increasingly targeting the VMware vSphere estate, and leveraging in this environment to conduct extortion and data theft. Stuart details why this has become an attractive target, and ways organizations can better engineer detections to respond to this activity. https://cloud.google.com/blog/topics/threat-intelligence/defending-vsphere-from-unc3944 https://cloud.google.com/blog/topics/threat-intelligence/vsphere-active-directory-integration-risks

August 18, 202525 min

AI Tools and Sentiment Within the Underground Cyber Crime Community

Michelle Cantos (Senior Analyst, Google Threat Intelligence Group) joins host Luke McNamara to discuss some of the recent trends in underground marketplaces around the selling of illicit AI tools and services. Michelle discusses GTIG's research into this space, how threat actors are seeking to leverage these models, use cases being discussed, and more.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts