The Payload Podcast #001 with Jonny Johnson & Max Harley

The Payload Podcast #001 with Jonny Johnson & Max Harley

Source: YouTube · John Hammond · published Feb 6, 2026 · 56:53

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The Payload podcast pilot features hosts Johnny Johnson and John Hammond with guest Max from Dreadnode, exploring the evolution of AI in cybersecurity, technical research on Windows internals, and recent security incidents.

Key Takeaways:
• Max explains his shift from red teaming to AI security, catalyzed by the "Ghost in the Node" talk which demonstrated LLMs' potential in offensive security 0:50.
• The group discusses Max's research on AMZY providers, where a red AI agent attempts privilege escalation while a blue AI agent classifies the activity, creating valuable training data 11:12.
• Johnny expresses skepticism about current blue team AI applications, arguing that while red teaming benefits from verifiable rewards, blue teaming lacks clear success metrics and often suffers from shallow understanding 19:12.
• The hosts discuss the Windows Projected File System, a mini-filter that allows dynamic file projection, highlighting its potential for deception and defensive canarying 40:35.
• They touch on recent security incidents, including the Notepad++ supply chain attack using Microsoft Warbird obfuscation and a Telnet privilege escalation bug 47:25.

The podcast aims to provide a relaxed, informal look at security tools and research, with plans for bi-weekly episodes featuring live demos and guest interviews.

Sources:

  • 0:10 Introduction to the Payload podcast and hosts
  • 0:50 Max's transition to AI security
  • 11:12 AMZY provider research details
  • 19:12 Skepticism on blue team A

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Oh, what's up everybody? Hello. Hello. Hello. >> Welcome. >> I think we're live. I think we're doing it. Look. Hey everybody. Thank you for coming to hang out with us for I guess the pilot episode, first show, first trial run really of uh the Payload podcast. And I think we have some sweet lore to dig into perhaps. But look, it's me. Hey. Hi. Hello. I'm John Hammond. I've got sweet esteemed co-host with me, Johnny Johnson. and a sweet special guest that I think you might see more of as sort of like our sweet third wheel. But Johnny, I'm sorry. I'm gonna let you take the floor, my friend. [laughter] >> No, I appreciate it. Everybody, first before we start, I have a good mic today, so no one roasts me. I'm not also not on that skddy Wi-Fi, so I shouldn't be in and out like like last night. U…