Cyber Crime Junkies
Cyber Crime Junkies

Your Zero Trust Approach Has a Blind Trust Problem?

March 13, 2026

AI Summary

5 min read

Chris Griffin, a 22-year contributor to the open-source security testing methodology manual (OSSTMM), argues that the cybersecurity industry’s most popular frameworks—Zero Trust and defense in depth—contain dangerous blind spots. Drawing on his experience as a penetration tester, Griffin explains that organizations often check compliance boxes while missing the actual gaps attackers exploit. The conversation uses the recent Nike breach as a case in point: attackers bypassed customer data and credit cards entirely, going straight for intellectual property. The episode is a practical walkthrough of why standard approaches fail and what to do instead.

The Blind Trust in Zero Trust

Griffin defines Zero Trust with its common slogan: "never trust, always verify." But he argues the framework itself contains "a lot of blind trust." His primary example is patching. Organizations rush to apply Microsoft patches within Zero Trust’s urgent timelines, but those patches often reset Active Directory group policies without alerting anyone. The result: a patch intended to close one vulnerability silently opens others. "I've never seen anyone fully lab test patches and updates," Griffin says. Testing usually checks only whether the system keeps running, not whether it has created new vulnerabilities. He also points to a Microsoft update that broke SMB, forcing companies to roll back to SMB

Continue reading the full summary in the app — free to try.

Read Full Summary →

Free • No credit card required

What you'll learn

  • 1 (00:12) **Nike Breach as a Case Study** - Attackers bypassed credit cards and customer data to steal intellectual property, showing where the real money is today.
  • 2 (01:02) **Introducing Chris Griffin** - 22-year contributor to the OSTM (Open Source Security Testing Methodology Manual) and founder of Griffin Security.
  • 3 (03:37) **Chris's Origin Story** - How a friend's move to become a pen tester in NYC led Chris to discover the OSTM and eventually become a contributor to the manual itself.
  • 4 (10:20) **The Blind Trust in Zero Trust** - Defining "never trust, always verify" and exposing the assumptions that undermine it.
  • 5 (15:32) **IPv6: A Hidden Attack Surface** - A remote code execution vulnerability in IPv6 can bypass firewalls and ZTNA if IPv6 is enabled but unused.
  • 6 (18:48) **Mobius Defense vs. Defense in Depth** - Why the military concept of "defense in depth" fails in networks, and the alternative "Mobius defense" (no inside/outside, secure the whole organism).
  • 7 (25:58) **The Business Mindset Problem** - Leadership's risk appetite and checkbox mentality are the biggest detractors in security.

+ Full timestamped outline available in the app

Show Notes

New Episode🔥The Cybercrime Junkies interviews  cybersecurity expert Chris Griffin offering insights for cybersecurity for beginners and seasoned pros alike. This episode explores the critical role of PCI in network security and emphasizes the importance of compliance to protect against threats. Stay informed and protect yourself from cyber crime.

CHAPTERS
00:00 Meet Chris Griffin: From Help Desk to Penetration Testing Pioneer
08:10 Zero Trust Architecture: The Blind Trust Problem Nobody Talks About
16:30 Why Patching Without Testing Creates Hidden Vulnerabilities
24:15 The Mobius Defense: Rethinking Internal vs External Security
32:00 Chrome Extensions and InfoStealer Dumps: Your Biggest Browser Risks
40:15 AI Security Gaps: Why Vibe Coding Is Destroying Network Security
48:20 Building Your Own Private AI: Protecting Intellectual Property
56:00 Griffin Security Platform Demo and Future of Quantum Testing

Questions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us.

Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out online at www.NETGAINIT.com  
 

Support the show

🔥New Exclusive Offers for our Listeners! 🔥

Dive Deeper:
🔗 Website: https://cybercrimejunkies.com

📰 Chaos Newsletter: https://open.substack.com/pub/chaosbrief

✅ LinkedIn: https://www.linkedin.com/in/daviddmauro/
📸 Instagram: https://www.instagram.com/cybercrimejunkies/

===========================================================

Cyber Crime Junkies

More from this podcast

Cyber Crime Junkies →