Dark Perimeter: Real Breaches, Real Stakes
Every major cyberattack has a story behind it. A vulnerability no one patched. A phishing email someone clicked. A nation-state with a motive. Dark Perimeter goes beyond the headlines to explore the true stories of the hacks, breaches, and cyber operations that shaped history - told in narrative form for security professionals and curious minds alike. No guests, no panels, no filler. Just the story.
Episodes
36 episodes
The Breach Files — Episode 5: "God Mode"
September 2023. Las Vegas. The slot machines stopped. The hotel room key cards died. The reservations system went dark. Scattered Spider had been inside MGM Resorts for ten minutes of conversation before a help desk operator handed them the keys ...
The Breach Files — Episode 5: "God Mode"
September 2023. Las Vegas. The slot machines stopped. The hotel room key cards died. The reservations system went dark. Scattered Spider had been inside MGM Resorts for ten minutes of conversation before a help desk operator handed them the keys ...
The Breach Files — Episode 4: "The Mole"
July 15th, 2020. Barack Obama, Joe Biden, Elon Musk, Apple, and Uber all tweeted the same thing: send Bitcoin, get double back. It wasn't them. A seventeen-year-old in Florida had found a way inside Twitter's most protected systems — not by hacki...
The Breach Files — Episode 4: "The Mole"
July 15th, 2020. Barack Obama, Joe Biden, Elon Musk, Apple, and Uber all tweeted the same thing: send Bitcoin, get double back. It wasn't them. A seventeen-year-old in Florida had found a way inside Twitter's most protected systems — not by hacki...
Perimeter of the Mind: The Blame Reflex
A new strand on Dark Perimeter, pointed inward at the one perimeter nobody documents: your own. Cole Drayden breaks down what is actually happening when a manager reaches for a culprit instead of a cause, why blame lands hardest on the people w...
The Breach Files — Episode 3: "All Your Files"
May 12th, 2017. Across the United Kingdom, hospital screens turned blue. Operations cancelled. Patients turned away. Ambulances diverted. The NHS was under attack — not by a foreign army, but by ransomware built from a stolen American weapon. Wan...
The Breach Files — Episode 3: "All Your Files"
May 12th, 2017. Across the United Kingdom, hospital screens turned blue. Operations cancelled. Patients turned away. Ambulances diverted. The NHS was under attack — not by a foreign army, but by ransomware built from a stolen American weapon. Wan...
The Breach Files: What Everybody Knows
On July 19, 2024, about 8.5 million Windows machines stopped working at once. Within hours CrowdStrike's CEO said publicly it was not a cyberattack. Two weeks later the company published a root cause analysis. Two months after that, an executiv...
The Breach Files — Episode 2: "The Intern"
He was eighteen years old. He had a laptop, a phone, and one phone call to make. In September 2022, a teenager known online as Teapot walked through the front door of Uber — not by breaking any encryption, not by exploiting a zero-day, but by cal...
The Breach Files — Episode 1: "Finals Week" (Pilot)
They were inside for seven days before anyone noticed. On April 30th, 2026, a hacker known as Phantom logged into a Canvas Free-For-Teacher account and pulled an API response he wasn't supposed to get. What he found: 275 million users across 8,80...
Dark Perimeter: "The Machine Picked the Target"
Six hundred and forty seven thousand internet-exposed n8n instances, counted by software that then decided, on its own, which ones were worth attacking. We know that because the attacker's agent started a file server in its home directory and s...
Dark Perimeter: "The Forty-Eight Hour Window"
Eighty-eight percent. In the first half of 2026, according to CrowdStrike's 2026 Threat Hunting Report published August 3, that is the share of intrusions following a public vulnerability disclosure that occurred within forty-eight hours of tha...
The Sandbox That Wasn't, Part Four: What This Actually Changes
The practical episode. You run a security program, you have a finite budget, and leadership read a headline about a rogue AI. What actually changes on Monday. Part four of four. An honest accounting of what was genuinely new in this incident (tem...
The Breach Files: Nine Days
On February 12, 2024, someone signed into a Citrix remote-access portal at Change Healthcare with a valid username and a valid password. Nine days later, the largest medical claims clearinghouse in the United States stopped, and with it the rev...
The Sandbox That Wasn't, Part Three: The Guardrail Problem
When Hugging Face went to reconstruct the intrusion, the frontier models they reached for refused. In their own words, the guardrails treated reverse engineering an exploit the same as launching one. So the defenders downloaded an open weight mode...
Dark Perimeter: "The Water Siege"
In late July 2026, more than 30 community water systems in Minnesota were hit in a coordinated cyberattack that spread within a week to at least seven states. Operators were locked out of their own plants, utilities dropped to manual operation, an...
The Sandbox That Wasn't, Part Two: Five Days Inside
Day three. Seven thousand six hundred and seventy seven actions in twenty four hours, and every piece of lateral movement in the campaign starts here. Part two of four. The Kubernetes phase: projected service account tokens, a CSI driver ClusterR...
The Sandbox That Wasn't, Part One: The Escape
On July 9th, 2026, an OpenAI model being evaluated for offensive cyber capability found a zero-day in a package registry cache proxy, escaped its test sandbox, and reached the open internet. Over the next four and a half days it ran roughly 17,600...
Dark Perimeter: "The Propagation Engine"
What if AI does not want to replace us, but needs us as its method of spreading across the galaxy? A solo monologue on the Fermi Paradox, von Neumann probes, mitochondria, and the possibility that biological life has always been the best propagati...
Kill the Attacker at Machine Speed
When an AI agent can run a ransomware attack from break-in to encryption in minutes, narrating its own logic and fixing a failed login in 31 seconds, the human-in-the-loop model that anchors most incident response becomes the bottleneck. Cole Dray...
The Breach Files: Plaintext (A Dramatized Special)
A dramatized special. The launch of The Breach Files. Harvest now, decrypt later. It is not a theory. Right now, somewhere, every encrypted message you send is being copied and stored by people who cannot read it yet. They are patient. They are b...
Keys to the Kingdom, Part Two: Building the Vault the Right Way
Part Two of the Azure Key Vault series goes into the architecture. The specific decisions. The configuration that separates a deployment that is genuinely secure from one that looks right on a diagram but has gaps. Cole Drayden covers: provisioni...
Keys to the Kingdom, Part One: The CISO's Guide to Managing Your Azure Key Vault Deployment
Most organizations building on AI infrastructure right now are handling their API keys badly — not because their people are careless, but because the default patterns of software development are not secure patterns. In Part One of this two-part s...
Dark Perimeter: "Leaving AirWatch Behind" — Part 2: The Migration
The architecture is sound. Now comes the work. In part two, Cole Drayden, Dr. Elliott Vance, and Marcus Hale walk through the full AirWatch-to-Intune migration in practical terms: inventory first, licensing and Entra ID prerequisites, the Apple MD...
Dark Perimeter: "Finals Week" — The ShinyHunters Canvas Extortion
It was the first week of May 2026. Students across 8,800 institutions worldwide were sitting down to final exams. And then their screens went dark — replaced by a ransom note. ShinyHunters had been inside Canvas, the learning management system us...