True Stories From the Hacker Underworld

Episode 05   Published October 29, 2025 36 minute watch

Summary

It is the attacker's job to know your network better than you do, so the defender's job is to know it better still. Automox CTO and CISO Jason Kikta, a 20-year Marine Corps veteran who spent seven years running the National Counter-Cyber Mission at U.S. Cyber Command, walks through how breaches actually unfold. Log4j (CVE-2021-44228) anchors the discussion: a Java logging library buried millions of dependencies deep, whose JNDI lookup feature let a crafted log string run remote code with no authentication. From there Kikta explains the five stages of a vulnerability, how the initial access method narrows down who is attacking you, and why a company with immutable offsite backups still paid a ransom. His prescription comes down to three fundamentals: inventory what you have, keep patching and configuration tight, and protect identity.