AI Summary
5 min readChris Griffin, a 22-year contributor to the open-source security testing methodology manual (OSSTMM), argues that the cybersecurity industry’s most popular frameworks—Zero Trust and defense in depth—contain dangerous blind spots. Drawing on his experience as a penetration tester, Griffin explains that organizations often check compliance boxes while missing the actual gaps attackers exploit. The conversation uses the recent Nike breach as a case in point: attackers bypassed customer data and credit cards entirely, going straight for intellectual property. The episode is a practical walkthrough of why standard approaches fail and what to do instead.
The Blind Trust in Zero Trust
Griffin defines Zero Trust with its common slogan: "never trust, always verify." But he argues the framework itself contains "a lot of blind trust." His primary example is patching. Organizations rush to apply Microsoft patches within Zero Trust’s urgent timelines, but those patches often reset Active Directory group policies without alerting anyone. The result: a patch intended to close one vulnerability silently opens others. "I've never seen anyone fully lab test patches and updates," Griffin says. Testing usually checks only whether the system keeps running, not whether it has created new vulnerabilities. He also points to a Microsoft update that broke SMB, forcing companies to roll back to SMB
Continue reading the full summary in the app — free to try.
Read Full Summary →Free • No credit card required
Never miss an episode of Cyber Crime Junkies
Get every new episode summarized in your inbox — free, ~5 minutes to read.
No spam. Unsubscribe anytime.
What you'll learn
- 1 (00:12) **Nike Breach as a Case Study** - Attackers bypassed credit cards and customer data to steal intellectual property, showing where the real money is today.
- 2 (01:02) **Introducing Chris Griffin** - 22-year contributor to the OSTM (Open Source Security Testing Methodology Manual) and founder of Griffin Security.
- 3 (03:37) **Chris's Origin Story** - How a friend's move to become a pen tester in NYC led Chris to discover the OSTM and eventually become a contributor to the manual itself.
- 4 (10:20) **The Blind Trust in Zero Trust** - Defining "never trust, always verify" and exposing the assumptions that undermine it.
- 5 (15:32) **IPv6: A Hidden Attack Surface** - A remote code execution vulnerability in IPv6 can bypass firewalls and ZTNA if IPv6 is enabled but unused.
- 6 (18:48) **Mobius Defense vs. Defense in Depth** - Why the military concept of "defense in depth" fails in networks, and the alternative "Mobius defense" (no inside/outside, secure the whole organism).
- 7 (25:58) **The Business Mindset Problem** - Leadership's risk appetite and checkbox mentality are the biggest detractors in security.
+ Full timestamped outline available in the app
Show Notes
New Episode🔥The Cybercrime Junkies interviews cybersecurity expert Chris Griffin offering insights for cybersecurity for beginners and seasoned pros alike. This episode explores the critical role of PCI in network security and emphasizes the importance of compliance to protect against threats. Stay informed and protect yourself from cyber crime.
CHAPTERS
00:00 Meet Chris Griffin: From Help Desk to Penetration Testing Pioneer
08:10 Zero Trust Architecture: The Blind Trust Problem Nobody Talks About
16:30 Why Patching Without Testing Creates Hidden Vulnerabilities
24:15 The Mobius Defense: Rethinking Internal vs External Security
32:00 Chrome Extensions and InfoStealer Dumps: Your Biggest Browser Risks
40:15 AI Security Gaps: Why Vibe Coding Is Destroying Network Security
48:20 Building Your Own Private AI: Protecting Intellectual Property
56:00 Griffin Security Platform Demo and Future of Quantum Testing
Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out online at www.NETGAINIT.com
🔥New Exclusive Offers for our Listeners! 🔥
- 1. Remove Your Data Online Today! Try OPTERY Risk Free. Sign up here https://get.optery.com/DMauro-CyberCrimeJunkies
- 2. Or Turn it over to the Pros at DELETE ME and get 20% Off! Remove your data with 24/7 data broker monitoring. 🔥Sign up here and Get 20% off DELETE ME
- 3. 🔥Experience The Best AI Translation, Audio Reader & Voice Cloning! Try Eleven Labs Today risk free: https://try.elevenlabs.io/gla58o32c6hq
Dive Deeper:
🔗 Website: https://cybercrimejunkies.com
📰 Chaos Newsletter: https://open.substack.com/pub/chaosbrief
✅ LinkedIn: https://www.linkedin.com/in/daviddmauro/
📸 Instagram: https://www.instagram.com/cybercrimejunkies/
===========================================================
More from this podcast
Cyber Crime Junkies →