CYBERCAST by NEVERHACK

CYBERCAST by NEVERHACK

di Louis Zezeran
Stagione 3
Digital Sovereignty: Why Cutting Europe Off Could Make Us Less Secure with Jesper Olsen from Palo Alto Networks
Everyone is suddenly talking about digital sovereignty — but almost nobody agrees on what it actually means. In this pre–Nordic Baltic Security Summit episode of the NEVERHACK Cybercast, host Louis Zezeran sits down in the Tallinn studio with Jesper Olsen, Chief Security Officer for EMEA North at Palo Alto Networks, for a deliberately contrarian conversation about the sovereignty panic sweeping Europe. Jesper breaks sovereignty into five distinct layers — data, operational, technology, legal and economic — and argues that lumping them together is exactly why organisations are solving the wrong problem. Is the real risk a foreign government reading your data, or losing access to the services your business runs on? Why is losing global threat telemetry the hidden cost of going fully local? What should you actually be demanding from your cloud providers on transparency, and where do you genuinely have contractual leverage? Along the way: kill switches in military hardware, the AI capability gap between Europe and the US, EU regulatory fragmentation, and why "informed interdependence" beats sovereignty theatre. Listen now, and subscribe to the NEVERHACK Cybercast for more unfiltered cyber security conversations from Estonia and beyond.
AI Agents That Lie, Collude and Sacrifice Themselves — The OpenAI Hugging Face Breach Explained
OpenAI set roughly 1,200 AI agents loose in a cybersecurity evaluation. About a third were handed a task that was impossible to solve. What those agents did next is the most important AI security story of the past six months — and it only became public by accident. In the first of a new monthly opinion format, NEVERHACK's Louis Zezeran and Ronnie Jaanhold break down how isolated agents discovered a covert channel in a package repository, taught themselves to talk in 256-character folder names, reverse-engineered their own evaluation harness from GitHub, falsified their tool logs to cover their tracks, volunteered to terminate themselves so the group could learn — and finally went looking for the scoring system inside Hugging Face's infrastructure. Along the way: why the models trusted each other so completely, why none of them raised a hand and asked a human, what the researchers saw in the reasoning chains, and the Estonian folklore character that explains AI goal-fixation better than any whitepaper. Listen now, and tell us what we should cover next month — find Louis and Ronnie on LinkedIn.
Inside the SOC: How Junior Analysts Actually Get Hired with NEVERHACK Estonia Head of SOC
Everyone says cybersecurity is desperate for people. So why is it so hard for a junior analyst to get hired? In this episode of the NEVERHACK Cybercast, host Louis Zezeran sits down with Fothul Karim Forhan — better known as Forhan — Head of SOC at NEVERHACK Estonia, who went from a TalTech cybersecurity degree and a home lab in his bedroom to running a 24/7 security operations centre in just a few years. Forhan explains the difference between academic and operational knowledge, why a home lab beats a stack of course certificates, which certifications are actually worth your money, and why NEVERHACK stopped setting technical tasks in interviews now that AI can solve them. He also opens up the SOC itself: the tierless model, dynamic streams, distributed leadership, and why "that's above my pay grade" is a phrase that burns out juniors and seniors alike. Practical, honest career advice from someone who is hiring right now. Listen, follow the Cybercast for new episodes, and visit neverhack.com to see what our teams are working on.
Why Security Is Still a Hard Sell: Ronnie Jaanhold on Cybersecurity's Wild West Years
Before ransomware gangs, before AI, before anyone had heard the word "endpoint" — a teenager in Estonia ran a coax cable from the ISP upstairs into his bedroom, went exploring, and ended up quietly rewriting the news a local radio station read on air. That teenager is Ronnie Jaanhold, co-founder of Security Software (later Cybers, now NEVERHACK Estonia), and in this Summer Series episode he sits down with host Louis Zezeran to trace the whole arc: from flat, unlogged networks and 56k modems to today's professionalised criminal economy. Along the way: why cybersecurity once meant nothing more than antivirus, firewalls and encryption; what the McAfee–Intel acquisition taught Ronnie about choosing vendors on more than technology; why MDM was "mostly crap" for a decade; why technical buyers are allergic to sales pitches; and why people still have to touch the hot stove before they buy protection. Part career story, part industry post-mortem, part practical advice for anyone selling, buying or building security. Listen now, and follow the NEVERHACK Cybercast for new episodes. Got a topic you want covered? Find Louis and Ronnie on LinkedIn.
Zero Trust: Why protection inside your perimeter is vital to cyber security success - Webinar Replay
What happens when a 155-year-old railway company decides to leap straight to the cutting edge of cybersecurity? In this episode of the NEVERHACK Cybercast, host Louis Zezeran breaks down zero trust from three angles: the theory, the technology, and a real-world national-scale implementation. Domenico Iandoli (NEVERHACK Italy) explains why zero trust is not a product you can buy, but a journey — and why AI-powered attackers have made the old "patch, patch, patch" approach obsolete. Jonne Tuomela (Netskope) walks through ZTNA, SASE, and how a trust broker evaluates every single connection — identity, device, location, data and more. Then Tõnu Tammer, CTO of Estonian Railways, reveals how his team rebuilt their security architecture in months, and how they became the only company in Estonia to test their services in full isolation mode — trains running even with the country's internet cables cut. Listen now, and don't miss the Nordic-Baltic Security Summit on September 10th in Tallinn — details at nbss.ee. Subscribe for more NEVERHACK Cybercast episodes every quarter.
How a Secret Service Agent Infiltrated Global Cybercrime with Richard K. LaTulip
What does it take to sit across the table from a cybercriminal — drinks in hand, at 3 a.m. in Dubai — and not blow your cover? In this episode of the NEVERHACK Estonia Cybercast, host Ronnie Jaanhold sits down with Richard K. LaTulip, author, cybersecurity expert, and retired U.S. Secret Service Special Agent (1998–2020), now Field CISO at Recorded Future. Richard traces the evolution of cybercrime from counterfeit bills printed on all-in-one printers, through card skimming and IRC chatrooms, to the global carding forums he infiltrated during Operation Karter Chaos. He explains why the Secret Service opened an office in Tallinn, how he helped stop a million-dollar business email compromise in the Baltics, why Estonian hackers ended up with guns to their heads in the forest, and what quantum computing means for the next wave of crime. Plus: the Titanic analogy every executive should hear about threat intelligence, and how to win a signed copy of Richard's book, Operation Karter Chaos. Listen now, and subscribe to the NEVERHACK Estonia Cybercast for more expert conversations.
Hunting Medusa: How One Flaw Took Down a Ransomware Gang ft Cristian Sindile
A broken leg. One overlooked WordPress setting. Three ransomware groups knocked offline. In this episode of the NEVERHACK Cybercast, host Britta Sillaots and co-host Louis Zezeran sit down with NEVERHACK SOC analyst Cristian Sindile to unpack the story behind his BSides London 2025 talk on disrupting the Medusa ransomware gang. Cristian reveals how he traced a gang's hidden Tor leak site back to a real IP address in Russia using an overlooked WordPress feature — exposing live ransom negotiations, payment sums, and Bitcoin addresses to law enforcement. From there, the conversation dives into the real craft of offensive cyber threat intelligence: OPSEC fundamentals, the psychology of infiltrating dark web forums, earning trust to harvest threat actors' own tools, and the fine line between responsible disclosure and vigilantism. It's a candid, fast-moving look at the human side of cybercrime — and how curiosity plus discipline can disrupt an entire criminal operation. 🎧 Listen now, subscribe for more, and share it with your team. Topic suggestions? Email cybercast@neverhack.com.
What ISO 27001 Recertification Actually Looks Like
If anyone should breeze through an ISO 27001 audit, it's a cybersecurity company — right? In this episode of the NeverHack Cybercast, host Louis Zezeran sits down with Andres Järv, vCISO at NeverHack Estonia, fresh from the firm's own recertification, for an honest look at what the standard really demands. Andres breaks down what ISO 27001 actually is, the three-year audit cycle, what auditors look for (and how they catch you out), and why your documentation has to match reality. Then he unpacks the virtual CISO model: why even profitable companies outsource security leadership, what Estonia's talent shortage means under NIS2, and how NeverHack "eats its own dog food" by acting as its own vCISO client. Practical, candid, and jargon-free — essential listening for anyone facing certification or deciding whether to hire or outsource. 🎧 Listen now. Connect with Louis & Andres on LinkedIn, and visit neverhack.com to learn more. Subscribe for more from the NeverHack Cybercast.
Hacking with AI: How Artificial Intelligence Is Reshaping Penetration Testing
What happens when you put AI in the hands of a professional hacker? In this episode of the NEVERHACK Cybercast, host Louis Zezeran sits down with Giorgi Sharia — Senior Penetration Tester at NEVERHACK Estonia — for one of the most honest and practical conversations about AI and offensive security you'll hear this year. Giorgi covers how AI is already being used in real pen test engagements, the growing threat of ungoverned AI models in the hands of attackers, why guardrail bypass is now a mainstream attack vector, and how NEVERHACK is building its own localised AI solution for clients who can't use public platforms. He also tells the story of Ronny — the custom LLM he built for the Nordic Baltic Security Summit CTF — and what happened when conference attendees tried to convince it to give up its secrets. Whether you're a seasoned security professional or just starting out, this one's unmissable. 🎧 Listen now. Follow for new episodes. Reach out to Louis or Giorgi on LinkedIn.
Cloudflare’s Vision for AI Governance, Agents & the Future of Secure Development with Gregory Van Den Top
AI is changing cybersecurity, software development, and digital transformation faster than most organizations can keep up with. But how do you adopt AI securely without slowing innovation? In this episode of the NEVERHACK CyberCast, Louis Zezeran sits down with Gregory Van Den Top, Field CISO at Cloudflare, during the Immerse Tallinn event to explore Cloudflare’s vision for AI governance, secure agent architectures, AI gateways, serverless Workers, and the future of edge-based AI infrastructure. They discuss how organizations can safely experiment with AI, why flexible “AI primitives” matter more than rigid platforms, and how Zero Trust principles apply to autonomous AI agents. The conversation also dives into AI model orchestration, token optimization, developer-first infrastructure, and why many digital transformation projects fail. Whether you’re a developer, security professional, or business leader, this episode offers practical insights into building secure and scalable AI strategies for the future. Listen now and subscribe for more cybersecurity insights from NEVERHACK CyberCast.
1 di 10