
Hosted by Joe Patti and Adam Roth · EN
Security veterans Joe Patti and Adam Roth welcome a diverse lineup of cybersecurity and information security experts to share their insights at the virtual bar. From cutting edge topics like AI and Operational Technology (OT) to the realities of careers and mental health, you'll get the inside view of what's happening across the industry and what it's really like to work in these fields, from the people who do it every day.
Reach us at feedback@securitycocktailhour.com or @SecCocktailHour on Twitter.

Eva Galperin explains how stalkerware, ordinary phone access, coercion, and weak privacy defaults can let someone close create devastating real-world harm.In this episode, we cover:What stalkerware is and why hiding from the user mattersWhy intimate-partner abuse changes the cybersecurity threat modelPrivacy as consent and control, not isolationWhy end-to-end encryption is not magic if the endpoint is compromisedPassword managers, VPN myths, patching, and backupsWhat security teams miss when they only focus on exotic adversariesGuest: Eva Galperin, Director of Cybersecurity at the Electronic Frontier Foundation and co-founder of the Coalition Against Stalkerware.Resources:EFF Surveillance Self-Defense: https://ssd.eff.org/Coalition Against Stalkerware: https://stopstalkerware.org/

This is the full interview version of our conversation with Chad Butler.Chad previously worked in product security at Amazon and was involved with Prime Air, Amazon's drone delivery program. He joins Joe Patti and Adam Roth to talk about drone delivery, FAA rules, GPS spoofing, detect-and-avoid, ADS-B, autonomous vehicles, AI agents, and the engineering culture needed when software failures can become physical-world safety failures.Topics include:Prime Air and product securitycommercial drone delivery riskPart 107 and Part 108beyond visual line of sight operationsGPS spoofing and drone capturedetect-and-avoid vs right of wayADS-B tradeoffswhy pilots may not reliably see dronesautonomous vehicles and AI agentsadversarial inputs and edge casespublic trust after catastrophic failuresChallenger, Feynman, and ignored engineering warnings

Autonomous systems are already moving into the physical world. Drones can fly themselves, robot taxis are carrying passengers, and AI systems are taking more action without direct human control.Chad Butler joins the Security Cocktail Hour to explain why that changes the risk model.The issue is what happens when autonomous systems make real-world decisions from sensor data, routing logic, and AI-driven judgment that may be wrong, spoofed, or manipulated.In this feature version, Chad talks with Joe Patti and Adam Roth about:GPS spoofing and drone capturebeyond visual line of sight drone operationstrusted and untrusted sensor dataAI agents and autonomous vehicleswhy optimal-environment testing is not enoughwhy "nobody will do that" is not a defensehow cyber failures can become safety failureswhat Challenger and Feynman still teach us about launch pressure and ignored warningsThis is a feature cut of the conversation. Th full interview will be released soon.

This time we’re revisiting our conversation with Luke Canfield and focusing on how drones are becoming a cybersecurity problem.Luke walks through war-flying, drone-mounted Wi-Fi Pineapples, rogue access points, cartel drone operations, prison contraband drops, hybrid warfare, and why most security teams are still thinking too flat. The core takeaway: security exists in three dimensions now, and defenders need to start looking up.Full original episode with Luke Canfield: https://open.spotify.com/episode/18TYWLjiLpqGX995iDmqdL?si=67c757474cc84d33Security Cocktail Hour:https://securitycocktailhour.com

Former NASA Administrator and astronaut Charles Bolden joins the Security Cocktail Hour to explain why space is not as isolated as people assume.We cover:Why mission control still sits in the middleWhy messages get routed, reviewed, and filtered before reaching a vehicleHow consumer devices expand the attack surface in spaceWhat cooperation in orbit teaches about security and civicsWhy he does not buy the hype about easy moon or Mars colonizationOrganizations mentioned in this episode:Intrepid Museum: https://intrepidmuseum.org/Astronauts for America: https://www.astronautsforamerica.org/

Modern cars are phones with wheels: GPS, telematics, connected apps, and data streams that can expose privacy risks, but also help recover a stolen vehicle before it disappears across jurisdictions.Maria Santos and Eugene Giordani, co-founders of Autoscope, join the Security Cocktail Hour to explain how law enforcement can use consent-based access to connected-car data after a theft. We talk about relay attacks, key cloning, license plate reader limits, built-in GPS, jurisdiction problems, AirTags, immobilizers, Faraday bags, dash cams, and the practical steps car owners can take before something happens.If you care about cybersecurity, connected vehicles, public safety, privacy, or just keeping your car in your driveway, this one is for you.Website: https://securitycocktailhour.comLinkedIn: https://www.linkedin.com/company/security-cocktail-hourTwitter/X: @SecCocktailHourEnjoyed this episode? Follow us and share it with a colleague or friend who owns a connected car.

In this episode, Ché Bolden joins us to talk about drone security, uncrewed systems, satellite security, GPS, autonomy, counter-drone defense, and the growing cyber risks around space-based infrastructure. We get into how drones were originally secured, why unencrypted links were such a problem, how command-and-control attacks can work, and why space is now part of the security conversation.This conversation sits at the intersection of cyber security, drone warfare, satellite security, space security, and the future of connected systems. If you care about drones, satellites, GPS, cyber risk, or the security of critical infrastructure, this episode is worth a listen.GuestChé BoldenLearn more:bolden.groupinterastra.institute

Joe South joins the Security Cocktail Hour to discuss the state of communication satellite security and the doctoral research he is doing to change it. Joe is Director of Cloud & AI Security at Abira Security and hosts the Security Unfiltered podcast, one of the larger independent cybersecurity podcasts. The conversation covers what satellite defense actually looks like today: why most of the security is at the ground station rather than on the satellite itself, what happens when CubeSats stay in orbit for 10 to 12 years without meaningful patching, and how a zero trust framework could be made to work on hardware that operates on less than three watts of power. Joe walks through his proposed approach, which combines TPM-based component authentication with a distributed trust ring across satellite orbits.We also get into cyber warfare and the attribution problem, the strategic implications of a compromised satellite fleet, and Joe's personal story about building self-sufficiency. If you work in cloud, infrastructure, or national security and have never had space in your threat model, this is a good place to start. Guest: Joe South, Director of Cloud & AI Security at Abira Security, host of Security Unfiltered (securityunfiltered.com), doctoral candidate at Capital Technology University.Subscribe to the Security Cocktail Hour newsletter at securitycocktailhour.com for a biweekly read on cybersecurity news and upcoming episodes.

Matt Sloane has spent 13 years in the drone industry, working with over 1,000 public safety agencies to build and operate drone programs. As Co-Founder and Chief Strategy Officer of SkyfireAI, he's at the intersection of drone operations, AI-enabled autonomy, and national security policy.In this conversation, Matt covers how drone first response (DFR) programs are changing 911 operations, why the FAA's upcoming Part 108 framework will prioritize autonomy over human pilots, how counter-UAS mitigation actually works (with memorable stories from the Super Bowl and World Cup preparations), and what he told the White House about the Chinese drone ban's impact on American public safety agencies.Supply chain risk from Chinese-made drones mirrors the Hikvision and Huawei debates. Counter-UAS involves signal jamming and RF detection. Autonomous drone systems are expanding the attack surface in ways most security programs haven't accounted for yet.

Amanda King was a Senior Director of Breakthrough Technology at an aerospace and defense company when she learned she was on a list of 77 people specifically targeted by Iran's Charming Kitten APT group. In this episode, she tells the full story: how the Associated Press tried to reach her three times, what the attackers accessed, how a US government agency got involved, and what she changed in her personal and professional life afterward.The conversation covers the real-world experience of being targeted by a nation-state actor, the gap between corporate and personal security, what it's like when a three-letter agency asks for access to your life, and how the experience shaped Amanda's approach as she moved into executive roles. Amanda also shares her perspective on resilience, including her cancer journey, and a practical framework for processing difficult experiences.Hosts: Joe Patti and Adam Roth. Recorded March 14, 2026.