Learn about the latest threat and cybersecurity trends on The Defender’s Advantage Podcast! Hear from experts in the field as Host Luke McNamara, from Google Threat Intelligence Group, interviews analysts, researchers and other guests on the frontlines of the latest attacks. Episodes dive deep into various topics, including nation-state activity, cybercrime, malware and tradecraft, incident response, defensive guidance, and more. Don't forget to subscribe!
Saves to your Listen queue, to pick up on another day or another device.
The New Frontline of Supply Chain Attacks
In this episode of Mandiant’s Defender’s Advantage Podcast, host Luke McNamara sits down with Ben Read, Head of Strategic Threat Intelligence at Wiz, to explore the rapidly shifting landscape of software supply chain compromises. While historic, nation-state operations like SolarWinds focused on compromising closed-source software, modern adversaries have expanded their playbook to target widely…
Shadow LLMs, Agentic Identities, and Securely Integrating AI
Host Luke McNamara sits down with Muhammad Muneer, Technical Manager on Mandiant's Incident Response team, to unpack the stark realities of enterprise AI adoption. They explore why securing AI starts with resolving legacy security debt (specifically around IAM, supply chain, and secrets management) and dissect the critical differences between "governance for AI" and "governance of AI." Muhammad…
Human-Machine Teaming: Applying AI to Frontline Threat Intelligence Workflows
Host Luke McNamara is joined by Jake Nicastro, who leads the AI function for the Frontline Intelligence Operations team within the Google Threat Intelligence Group (GTIG). Jake details how his team is shifting from simple prompt engineering to more advanced agentic workflows, focusing on a model of "human-machine teaming." He shares practical use cases for AI in CTI—including automated script…
Host Luke McNamara is joined by Charley Snyder, Head of Disruption Operations at Google Threat Intelligence Group, to delve into how Google is crafting a more coordinate approach to disrupting adversary cyber operations. Charley describes how this disruption focus is not hacking back, how it builds on existing work across Google security teams, and some of the recent wins such as the IPIDEA and…
Host Luke McNamara is joined by Chris Linklater, Practice Leader at Mandiant, to discuss the 2026 edition of Mandiant's M-Trends Report. Chris dives into the latest trends observed in breached throughout 2025 and into this year, noting some of the key aspects organizations should focus on in applying these insights into today's threat landscape. https://cloud.google.com/security/resources/m-trends
In this episode of the Defenders Advantage Podcast, host Luke McNamara sits down with Google Threat Intelligence experts Jose Nazario and Brandon Wood. They dive into the rollout of new dark web and underground monitoring capabilities, explaining how AI is fundamentally changing the way defenders track adversaries.…
Host Luke McNamara is joined by Eugene Liderman, Senior Director in Android's Security and Privacy Group, to discuss the evolving world of mobile-targeting scams. Eugene details some of the unique aspects to mobile scams, regional variations in tactics by scammers, and the steps Android has taken to combat this problem.
Sarah Yoder (Manager, Mandiant Consulting) and Ashley Pearson (Senior Analyst, Advanced Practices on Google Threat Intelligence Group) join host Luke McNamara to discuss UNC5221 and their operations involving BRICKSTORM backdoor. This highly sophisticated, suspected China-nexus cyber-espionage threat group is known for aggressively targeting internet-facing network appliances (like VPNs and…
Stuart Carrera (Senior Consultant, Mandiant Consulting) joins host Luke McNamara to discuss how threat actors are increasingly targeting the VMware vSphere estate, and leveraging in this environment to conduct extortion and data theft. Stuart details why this has become an attractive target, and ways organizations can better engineer detections to respond to this activity.…
AI Tools and Sentiment Within the Underground Cyber Crime Community
Michelle Cantos (Senior Analyst, Google Threat Intelligence Group) joins host Luke McNamara to discuss some of the recent trends in underground marketplaces around the selling of illicit AI tools and services. Michelle discusses GTIG's research into this space, how threat actors are seeking to leverage these models, use cases being discussed, and more.