John Strand
Bio
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.Appears in 24 Episodes
OpenClaw Cancels a Stranger's Gym Reservation - 2026-08-10
This episode explores an AI agent that canceled someone else’s gym reservation, the growing offensive and defensive roles of AI, and a sharp rise in ransomware attacks...
OpenAI accidentally Hacked Hugging Face - 2026-07-27
This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment du...
Initiative Gold Eagle - 2026-07-20
This week, the team discusses the White House's Initiative Gold Eagle and its implications for cybersecurity information sharing, an unexpectedly positive development ...
OnlyFans Models Are Accidental Blue Team Defenders - 2026-07-13
This week, the team unpacks a wide range of cybersecurity news, including a fraudulent offensive security startup tied to cybercriminals, how leaked OnlyFans content i...
Apple's Hide My Email ... Doesn't! – 2026-07-06
This episode of BHIS - Talkin' Bout [infosec] News covers the latest cybersecurity headlines, including debate over the economics of AI infrastructure, updates on the ...
Polymarket's Bad Bet with Third-Party Vendors - 2026-06-29
This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of hig...
Rickrolling the FIFA World Cup - 2026-06-22
This week’s episode covers a series of cybersecurity stories, including a researcher’s discovery of vulnerabilities in FIFA’s World Cup platform that could have enable...
U.S. Government Effectively Bans Fable 5 and Mythos 5 - 2026-06-15
This episode dives into the fallout from new restrictions on Anthropic’s cybersecurity-focused AI models, Mythos and Fable, and the debate over whether government pres...
Breach Disclosure Lag is Worse Than Ever – 2026-06-08
This episode covers the rising costs and restrictions surrounding AI agents, including token consumption, model access policies, and the growing dependence on AI tools...
Mythos finds a curl vulnerability - 2026-05-18
This episode covers Mythos uncovering a vulnerability in cURL, a recent Google Threat Intelligence report on a zero-day exploit, and the growing impact of AI on captur...
The Canvas / Instructure Breach – 2026-05-11
Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community ne...
NASA Gets Phished by Chinese - 2026-04-27
This episode dives into the economics and competitive dynamics of the AI industry, including discussions on profitability, pricing strategies, monopolization, and the ...
Anthropic’s Project Glasswing is an Infosec Turning Point – 2026-04-13
This episode dives into Anthropic’s “Project Glasswing” and the broader implications of AI-driven offensive security, including models autonomously discovering vulnera...
Pentagon Plans to Train AI With Classified Data – 2026-03-23
This episode covers a range of cybersecurity and AI-related news, including how Pokémon Go players may have unknowingly helped train delivery robots using massive imag...
Iranian Hackers Claim Responsibility for Stryker Attack - 2026-03-16
This episode covers multiple cybersecurity news stories, including Iranian hackers claiming responsibility for a cyberattack on Stryker, ongoing challenges in attribut...
A Nightmare of Vibeware - 2026-03-09
Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community ne...
Pentagon Declares Anthropic a Supply Chain Risk — 2026-03-02
Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community ne...
The Coming SAAS Apocalypse - 2026-02-23
In this episode:Agentic AI tools that can autonomously perform tasks like researching and booking flights, raising concerns about automated purchases, fraud, guardrail...