THREATCON1 PODCAST

The THREATCON1 podcast features live recordings from the event floor alongside in-depth conversations with the leaders shaping cybersecurity. Listen to keynotes, spotlight discussions, and exclusive interviews — hosted by Christine Fignar.

Season 2026 will feature live recordings from the Flagship event, including keynote content from Gen. Paul Nakasone, and featured episodes with Jen Easterly and Andrew Boyd.

RECENT EPISODES

How Cyber Threat Hunters Think | Joe Slowik on Threat Intel, Detection Engineering & Cyber Warfare

Recorded live at the RSA Conference, this episode of the THREATCON1 Podcast features a deep-dive conversation with Joe Slowik — one of the cybersecurity industry’s leading voices in cyber threat intelligence, detection engineering, and adversary operations.

Hosted by Patrick Garrity and Kimber Duke from VulnCheck, the discussion explores how modern threat actors operate, why most organizations still struggle with cybersecurity fundamentals, and how defenders can build stronger, intelligence-driven security programs.

ABOUT OUR GUEST:

Before joining Dataminr, Joe held cybersecurity and threat intelligence roles across government and industry, including work with Dragos, Gigamon, Huntress, and MITRE. His background spans Navy cyber warfare operations, incident response, threat hunting, intrusion analysis, and large-scale detection engineering.

In this episode, the conversation covers:

  • How cyber threat intelligence actually supports real security outcomes
  • Why detection engineering is becoming essential for modern security teams
  • The mindset defenders need to think like attackers
  • Lessons from the Black Basta ransomware chat leaks
  • Threat hunting methodologies and operational security practices
  • VPN abuse, proxy infrastructure, and telecom compromise risks
  • Why healthcare and manufacturing continue to be high-risk targets
  • How attackers prioritize targets using sales and marketing-style tactics
  • The future of cybersecurity talent, hacker culture, and defensive operations
  • Why strong cybersecurity still comes down to fundamentals and operational discipline

Whether you work in a SOC, lead a security team, build detection content, hunt threats, or simply want to better understand how modern cyber adversaries operate, this episode delivers practical insights from leaders working on the front lines of cybersecurity.

Dataminr uses AI and real-time event discovery to help organizations detect emerging risks, cyber threats, geopolitical events, and breaking incidents faster — enabling security teams to respond before threats escalate.

VulnCheck provides exploit and vulnerability intelligence designed to help organizations prioritize real-world threats, understand exploitation activity, and stay ahead of emerging vulnerabilities before attackers weaponize them.

May 19, 2026
Learn More

From ‘Hackers Are Criminals’ to Industry Leaders — What Changed? | Casey Ellis of Bugcrowd

Recorded live at the RSA Conference, this episode of THREATCON1 features a deep dive into the evolving world of cybersecurity with Casey Ellis, Founder of Bugcrowd.

Joined by Patrick Garrity (Security Researcher) and Kimber Duke (Director of Product at VulnCheck), the conversation explores how the industry is changing—and why many of the core problems remain the same.

From the rise of AI-powered capabilities to the growing importance of vulnerability disclosure programs, this episode unpacks the tension between speed, innovation, and security.

🔍 What You’ll Learn

- Why cybersecurity today feels “faster, louder, and more chaotic”

- How AI is expanding both opportunity and risk in hacking

- The evolution of bug bounty programs and ethical hacking

- Why most software is built without security as a priority

- The reality of vulnerability disclosure—and why it’s still broken

- The importance of empathy between researchers and organizations

- How community plays a critical role in modern security

- The legal risks hackers face—and how initiatives like the Security Research Legal Defense Fund are changing that

⚡ Key Insights

- “We’re solving the same problems—just faster and louder.”

- Security often comes second to shipping products quickly

- Ethical hackers are now gaining a seat at the leadership table

- Clear vulnerability disclosure processes can prevent real-world damage

- The future of cybersecurity depends on collaboration, not silos

👤 About the Guest

Casey Ellis is the Founder of Bugcrowd, a pioneer in crowdsourced cybersecurity and bug bounty programs. With over a decade of experience shaping how organizations work with ethical hackers, Casey has played a key role in advancing vulnerability disclosure practices globally.

🔗 Resources & Projects Mentioned

Disclose.io — Improving vulnerability disclosure standards https://disclose.io

Security Research Legal Defense Fund — Supporting ethical hackers facing legal challenges https://srldf.org

🎙️ About THREATCON1

THREATCON1 brings together leading voices in cybersecurity to explore the biggest challenges, ideas, and innovations shaping the industry today. https://threatcon1.org

May 5, 2026
Learn More

about

This is some text inside of a div block.
VENUE

Meet the Hosts

Tom Bain is the Chief Marketing Officer at VulnCheck. He’s a frequent presenter at the biggest cybersecurity events including RSAC Innovation Sandbox and Black Hat, as well as investor and Marketing events globally. He was the host of Cyware’s Cybercast podcast, and is also a frequent contributor to the RSA Innovation network.

Tom has held Marketing lead roles at multiple cybersecurity startups including Finite State, Cyware, RiskRecon, (acquired by Mastercard) Morphisec, GoSecure, Q1 Labs (acquired by IBM) and AppSecInc. (acquired by Trustwave). He has experience in building go-to-market strategies focused on growth and solving complex challenges.

Patrick Garrity is a security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors. Patrick has spent the last decade helping building Cybersecurity companies including Duo Security, Censys, Blumira, Nucleus Security and VulnCheck. In his role, he is a frequent contributor to the VulnCheck blog, the Marketing and Product teams, as well as a regular presenter on webinars and at industry events worldwide.