Legitimate Cybersecurity Podcasts

Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.
Legitimate Cybersecurity Podcast - designed to empower you with real-world cybersecurity information, stories, and advice.
Episodes
Episodes



Jun 15, 2026
SpaceX IPO: Did You Just Fund a Spy Network?
Jun 15, 2026
Jun 15, 2026
38 min
The SpaceX IPO is being sold as rockets, innovation, and the future of space.But investors may have also bought into a private network with battlefield, intelligence, and surveillance potential.In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer examine what the SpaceX IPO really means when you look beyond rockets and stock hype. Starlink has already proven how powerful satellite internet can be in remote regions and war zones. Starshield raises an even bigger question: what happens when the same company building consumer satellite internet also builds national-security infrastructure?This is not a claim that SpaceX is spying on Americans. It is a question about capability, incentives, oversight, and public-market funding.If Starlink can shape connectivity in Ukraine and Russia, and Starshield is built for government and intelligence use, what stops similar infrastructure from becoming part of domestic surveillance, border enforcement, emergency response, law enforcement, or classified government operations?And if that happens, would ordinary citizens or retail investors ever know?Frank and Dustin discuss:* Why the SpaceX IPO changes the public-interest question* The difference between Starlink and Starshield* How satellite internet became a war-zone capability* Why private infrastructure can become public power* Whether investors understand what they actually bought* Why regulation always arrives after someone sticks their finger in the pencil sharpener* The uncomfortable line between innovation, profit, warfare, and surveillanceMedia/interview: mailto:admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Hosted by Frank Downs and Dr. Dustin Brewer.Chapters:00:00 - Did SpaceX Just Become the Biggest IPO Ever?01:06 - Why Everyone Loves Rockets02:23 - Starlink vs. Starshield Explained03:52 - Why Starlink Is Different From Old Satellite Internet05:22 - The Good Side: Remote Access and Global Connectivity06:41 - How Starlink Changed Modern War07:21 - Drones, Jamming, Fiber Optics, and Satellite Links08:44 - Should One Company Control Battlefield Connectivity?10:46 - Is This Different From Traditional Arms Dealers?13:22 - Why the IPO Changes the Question14:45 - Lockheed, Palantir, Boeing, and Public Funding16:59 - Did Investors Know What They Bought?17:28 - The Elon Musk Factor and Private Decision-Making18:52 - Rockets Are Cool — The Implications Are Harder20:02 - The Hidden Cost of Powerful Technology22:12 - Starshield and Government Intelligence Contracts23:23 - When Safety Tools Become Tracking Tools24:32 - Could Becomes Should: The Jurassic Park Problem29:32 - Shareholder Value vs. Human Consequences31:00 - Facebook, Terrorists, and “We Just Connect People”35:32 - Why Regulation Exists37:23 - Who Should Decide Who Gets the Network?38:33 - Final Thoughts: Know What You Invest In#spacex #starlink #Starshield#cybersecurity #surveillance #ipo #privacymatters #nationalsecurity #techethics #legitimatecybersecurity #ai
Jun 15, 2026
38 min



Jun 8, 2026
They Send a Fake IT Guy to Hack Your Office
Jun 8, 2026
Jun 8, 2026
33 min
The hacker isn't a thousand miles away in a hoodie. He's standing at your desk in a polo shirt, holding a clipboard, asking to plug something into your computer. And law firms are the target.Frank Downs and Dustin Brewer break down the Silent Ransom Group — the crew skipping the phishing email and walking straight through the front door.In this episode of Legitimate Cybersecurity, Frank and Dustin dig into SRG (aka Luna Moth, aka Chatty Spider), a Conti offshoot now assessed — and corroborated by an FBI FLASH alert — to be running physical IT-impersonation attacks against law firms and other data-rich targets.They discuss why physical social engineering is suddenly back from the 1990s, the cyber-psychology that makes us trust a stranger with a lanyard, Dustin's casino fake-badge pen test, why law firms are such a rich target (trade secrets, M&A, criminal defense, HIPAA data), and the brutally simple fix most companies skip: trust but verify.The conversation also covers why "keyboard Frank" is a different person, the hospital HIPAA nightmares you've personally witnessed, and AI's role on both sides of the kill chain. The one thing to leave with: if an IT person shows up unannounced, it costs you nothing to call IT and confirm before you let Steven in.Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Chapters:00:00 — The hacker shows up at your door00:36 — Mandiant + FBI: who Silent Ransom Group really is02:39 — The cyber-psychology of "why physical works"06:00 — War story: the student who ran from the front desk08:00 — Cutouts, proxies, and unwitting accomplices11:53 — Why physical access does damage instantly12:09 — Law firms: the richest target set there is15:46 — Mar-a-Lago, thumb drives, and the history of in-person hacks19:08 — Tailgating past security (Dustin's seventh-floor proof)20:58 — Trust but verify: the fix that actually works26:26 — The societal norms bad guys exploit27:02 — The casino badge: getting your face "known"28:00 — The human is always the weakest link29:41 — AI is only as smart (and hackable) as we are32:12 — Keep on cybering#Cybersecurity #SocialEngineering #Hacking #InfoSec #DataPrivacy #LawFirms #PenTesting #AI #CyberAwareness #SilentRansomGroup #LunaMoth #PhysicalSecurity
Jun 8, 2026
33 min



Jun 2, 2026
Jun 2, 2026
42 min
Researchers just found thousands of AI-built apps leaking medical records, financial data, and customer PII straight to the open internet. The scary part isn't that AI writes code — it's that it writes code just well enough that nobody asks questions.Frank Downs and Dustin Brewer break down the hidden cost of vibe coding: insecure-by-default software shipped to production, AI tools replacing the junior developers who'd grow into the people who fix it, and AI quietly wired into services you never consented to — including a dentist's chair that records every cleaning and sends it to an insurance-linked system.AI learned security from us. And we were never good at it.🎙️ Listen: https://legitimatecybersecurity.podbean.com/📩 Media/interview: admin@legitimatecybersecurity.comHosted by Frank Downs and Dustin Brewer.Chapters:00:00 The code works — that's the problem01:24 "Do you consider yourself a coder?"03:15 What AI actually learned to copy (us)04:58 Vibe-coded tools running in production05:19 3,380 exposed apps, 5,000 data leaks07:56 Who fixes it when the cyber team finds holes?08:26 The $1.5M QA cut that cost $6M09:35 AI talking to AI: nobody reads the code15:21 "Your password is God" — security never changed16:27 Should AI touch the live service?17:48 The dentist chair that records everything21:00 Where the line actually is (help desk vs. prod)24:20 AI monitoring employees & the gold-standard trap28:23 Always-on "streaming AI" is 5 years out29:25 The coming AI caste system30:34 Adversaries already use it (the Lego propaganda)33:14 We're about to lose every junior analyst40:15 The Twitter "efficiency" parallel41:35 Keep on cybering#vibecoding #cybersecurity #aisecurity #dataprivacy #shadowit #infosec #aitools #privacy #devsecops #surveillance
Jun 2, 2026
42 min



May 26, 2026
AI Pioneer Warns: AI Wants Your Private Files
May 26, 2026
May 26, 2026
1 hr 4 min
AI companies are running out of easy data — and the next target may be your private files, calendars, medical records, photos, and desktop activity.AI pioneer Dr. Jonathan Schaeffer joins Frank Downs and Dustin Brewer to explain why today’s AI tools are powerful, flawed, and increasingly hungry for personal data.In this episode of Legitimate Cybersecurity, Frank and Dustin talk with Dr. Jonathan Schaeffer, University of Alberta Professor Emeritus, AI pioneer, AAAI Fellow, entrepreneur, and founder of Synsara.They discuss why today’s chatbot boom is not the AI future many researchers imagined, why “hallucination” is the wrong word for AI errors, how AI companies depend on more and more data, and why desktop AI tools may create a new privacy boundary problem.The conversation also covers AI bias, manipulation, private data, local AI, regulation, data centers, environmental costs, and why solving AI’s safety and privacy problems should matter before the race to AGI gets even faster. Dr. Schaeffer’s key warning is that current AI systems do not understand the consequences of their answers, yet people increasingly treat them like trusted authorities.Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Chapters:00:00 — AI’s privacy problem is getting bigger01:27 — Jonathan Schaeffer’s AI origin story03:29 — Beating humans at checkers before Deep Blue05:48 — Why modern AI feels like the wrong future07:50 — Why “hallucination” is the wrong word09:01 — How “chat” created false trust10:32 — AI does not understand consequences13:52 — Why AI companies are desperate for data15:12 — Your private files are the real gold mine16:32 — The hidden cost of “free” AI tools20:44 — AI wants access to your desktop22:50 — The safety, security, and privacy problem24:05 — The AGI race is moving faster than safeguards27:07 — Why Jonathan built private local AI tools30:59 — The security risk nobody talks about32:31 — Why AI systems need audits34:21 — When AI answers become manipulation39:13 — Influence, rage content, and algorithmic persuasion42:21 — Why AI regulation cannot keep up46:05 — Canada’s failed attempt to regulate AI50:40 — Is it already too late?55:16 — What polar exploration teaches us about AI risk59:39 — Data centers, power, water, and responsibility1:03:18 — Jonathan’s life advice: fun beats money#ArtificialIntelligence#AIPrivacy#Cybersecurity#DataPrivacy#ChatGPT#AISafety#Privacy#TechPolicy#LegitimateCybersecurity#Synsara
May 26, 2026
1 hr 4 min



May 18, 2026
Your Ex May Still Have Access to Your Phone
May 18, 2026
May 18, 2026
35 min
Your ex may still have access to your accounts, your phone, or your private life — even after you changed your password.This episode explains how cyberstalking hides inside logged-in devices, shared biometrics, old account access, and security questions people close to you already know.On this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer break down real cyberstalking cases involving toxic exes, stolen images, account impersonation, hidden device access, and the overlooked settings that keep people exposed.Most people think the danger is “getting hacked.”But in toxic relationships, the real danger is often simpler: someone close to you already had the key.Frank and Dustin explain:Why changing your password may not log someone outHow old devices can stay connected to your accountsWhy shared phones, laptops, and biometrics create riskHow security questions can be abused by people who know youWhat warning signs suggest someone may be monitoring youWhere to get professional help if this is happening to youThis episode is part of our cyber safety series for people dealing with toxic relationships, stalking, harassment, and digital abuse.Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Chapters:00:00 — Your Ex, Walmart, or the State Agency Problem00:51 — Why Cyberstalking Is Now Everyday Life01:27 — Case 1: She Changed Her Password, But He Stayed Logged In03:39 — Why “Logged-In Devices” Are So Hard to Read05:20 — Don’t Share Accounts in Relationships07:28 — The Netflix / Hotel TV Problem08:20 — Why Access Tokens Keep People Logged In10:21 — Marriott, Hotel TVs, and Automatic Logouts11:41 — Case 2: Private Images Posted for 14 Years13:36 — The Law Slowly Caught Up14:41 — Photos, Trust, and Digital Leverage16:32 — Treat Your Phone Like a Toothbrush17:43 — Red Flags: When They Know Things They Shouldn’t20:20 — Case 3: He Added His Thumbprint to Her Phone22:28 — Why Biometrics Can Become Relationship Risk23:31 — Used Phones, Forensics, and Hidden Data28:27 — Don’t Let Someone Else Use Your AI Either30:49 — Security Questions Are Broken32:08 — Personal Cyber Hygiene Checklist34:18 — One Year of Legitimate Cybersecurity34:53 — Where to Get Real Help35:46 — Keep on Cyberin’#cyberstalking #cybersafety #digitalsafety #toxicrelationships #onlineprivacy #phonesecurity #cybersecurity #domesticabuseawareness #dataprivacy #legitimatecybersecurity
May 18, 2026
35 min



May 8, 2026
May 8, 2026
41 min
One could be hidden in your car, purse, luggage, or jacket — and it may cost less than dinner.Bluetooth trackers were built to find lost keys, but they can also turn nearby phones into a surveillance network.In this episode of Legitimate Cybersecurity, hosts Frank Downs and Dr. Dustin Brewer break down how AirTags, Tile trackers, Samsung SmartTags, Find My-compatible devices, and other Bluetooth beacons can be abused for stalking, theft, and surveillance.They explain why these devices do not “call home” like GPS trackers, how nearby phones quietly report their location, why some safety alerts can fail, and what to do if you suspect someone is tracking you.This episode also covers real-world cases involving hidden trackers, vehicle sweeps, modded AirTags, stalkerware, smart clothing, and the broader problem of everyday devices becoming personal surveillance infrastructure.If you think you may be in danger, contact professionals who can help:National Domestic Violence Hotline: 1-800-799-7233Coalition Against Stalkerware: StopStalkerware.orgOperation Safe Escape: SafeEscape.orgMedia/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Chapters:0:00 — A $29 tracker could be on you0:46 — Why Bluetooth trackers changed personal safety2:55 — How AirTags actually track location5:18 — Why abusers use trackers instead of GPS7:18 — AirTags, Find My, and Apple’s safety alerts10:04 — Tile trackers and the limits of smaller networks11:38 — Samsung SmartTags and smart home tracking13:07 — Modded trackers and the speaker loophole14:31 — The ethics of tiny surveillance devices18:48 — Cars, phones, and surveillance double standards22:33 — Real cases where trackers led to violence24:27 — Pattern-of-life tracking in the real world26:48 — Flipper Zero, Bluetooth footprints, and NFC risks33:12 — What to do if you think you’re being tracked34:00 — Where to search your car for hidden trackers35:37 — Behavioral signs someone may be monitoring you37:23 — Smart clothing and Bluetooth tracking risks39:41 — Resources for stalking and domestic violence help41:09 — Final thoughts#cybersecurity #airtag #BluetoothTracking#digitalprivacy #Stalkerware#personalsafety #surveillance #smartdevices #legitimatecybersecurity
May 8, 2026
41 min



May 4, 2026
May 4, 2026
30 min
Gloria Globman — CTO of Acclaimed Technical Services, former Senior Cyber Advisor at the US Embassy in Tokyo, US Navy veteran, and Presidential Rank Award recipient — joins Frank Downs and Dustin Brewer to translate what's really happening on your home network. Every smart device is a tiny computer with a camera, a microphone, and an internet connection, constantly talking to its manufacturer, the cloud, and other devices on your Wi-Fi. Many of them will never be patched again. Some of the manufacturers don't even exist anymore.In this episode we cover why mid-sized companies keep underfunding security until it's too late, how AI tools like Mythos and Zealot are compressing the patch window to almost nothing, why the upcoming TP-Link ban probably won't save you, and the simple home-router moves that actually do.If you've ever brought a personal phone onto the work Wi-Fi, set up a smart camera you've stopped thinking about, or assumed "the cloud" means it's somebody else's problem — this one is for you.🎙 Listen to the audio version: https://legitimatecybersecurity.podbean.com/📩 Media / interview requests: admin@legitimatecybersecurity.com👥 Hosts: Frank Downs and Dustin Brewer🎤 Guest: Gloria Globman, CTO, Acclaimed Technical ServicesChapters:00:00 The IoT problem nobody locks down00:36 Meet Gloria Globman — Tokyo, the IC, and 20 years of cyber02:10 Your smart devices are unlocked front doors03:51 Cognitive offloading: convenience until it isn't04:42 The aquarium that hacked a casino (MGM)05:17 Are IoT devices just printers 2.0?06:14 When personal phones meet corporate Wi-Fi08:35 Work moved home — security posture didn't09:19 Mid-sized companies and the 15–20% rule10:16 Why "not sexy" budgets keep getting cut11:24 Highest-impact moves: zero trust, segmentation, encryption12:16 Patch, patch, patch — and why AI changed the timer12:39 Mythos vs. Zealot: orchestrated AI attacks16:09 Microsegmentation for your actual house17:39 Why companies embrace BYOD anyway18:48 Why VDI never quite won22:18 Risk transference dysmorphia: "it's the cloud's problem"22:53 Botnets, dead routers, and the FBI cleanup23:24 Goodbye TP-Link — security move or theater?26:25 What the average person should actually do tonight28:21 Password managers, quantum, and MFA29:44 Gloria's one piece of life advice#cybersecurity #iotsecurity #smarthome #zerotrust #byod #HomeNetworkSecurity #infosec #dataprivacy #patchtuesday #legitimatecybersecurity
May 4, 2026
30 min



Apr 27, 2026
AI Is Now Faking Loved Ones and Setting Prices
Apr 27, 2026
Apr 27, 2026
34 min
AI is no longer just answering prompts — it is imitating dead relatives, profiling shoppers, and helping companies decide what people pay.That matters because the same hidden data systems behind convenience can reshape grief, prices, privacy, work, and trust without clear consent.In this episode of Legitimate Cybersecurity, Frank Downs and Dr. Dustin Brewer break down a disturbing wave of AI and surveillance stories: AI avatars of deceased loved ones, Maryland’s move against surveillance pricing, Washington’s restrictions around public access to ALPR data, Virginia’s precise geolocation data ban, deepfake CEO scams, remote hiring impersonation, and employee webcam monitoring.The big question: When AI can imitate people, price you individually, and watch you at work, what does consent even mean anymore?Media/interview: admin@legitimatecybersecurity.comAudio: https://legitimatecybersecurity.podbean.com/Chapters:00:00 — AI avatars of dead loved ones01:19 — Grief, deception, and consent02:48 — When an AI “person” is not really a person04:00 — Frank’s Afghanistan story and withheld grief07:14 — The problem with resurrecting people through AI09:16 — AI ghosts, Benjamin Franklin, and Disney presidents10:58 — Maryland moves against surveillance pricing12:37 — When dynamic pricing becomes predatory14:38 — Market pricing vs. personal profiling15:35 — Washington limits access to ALPR data18:10 — Virginia bans precise geolocation data sales21:30 — Location data, pricing, and individual targeting22:56 — Deepfake CEO scams and wire-transfer fraud24:17 — The “three-finger test” for deepfakes26:04 — Remote hiring scams and AI impersonation28:23 — Laptop farms, proxies, and scam infrastructure29:56 — Employee webcam and microphone monitoring34:30 — Final thoughts: stay dressed at work#ai #cybersecurity #privacy #surveillance #dataprivacy #Deepfakes#geolocation #SurveillancePricing#remotework #legitimatecybersecurity
Apr 27, 2026
34 min






