<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Thu, 16 Apr 2026 22:03:56 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>Three Buddy Problem - Episodes Tagged with “Venture Capital”</title>
    <link>https://securityconversations.fireside.fm/tags/venture%20capital</link>
    <pubDate>Thu, 28 Nov 2024 07:00:00 -0700</pubDate>
    <description>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A Security Conversations podcast</itunes:subtitle>
    <itunes:author>Security Conversations</itunes:author>
    <itunes:summary>The Three Buddy Problem is a popular Security Conversations podcast that goes beyond industry talking points to discuss what others won’t -- nation-state malware, attribution, cyberwar, ethics, privacy, and the messy realities of securing computers and corporate networks. 
Hosted by three veteran security pros -- journalist Ryan Naraine and malware paleontologists Costin Raiu and Juan Andres Guerrero-Saade -- the weekly show attracts a highly engaged audience of security researchers, corporate defenders, CISOs, and policymakers.
&lt;a href="https://twitter.com/ryanaraine"&gt;Connect with Ryan on Twitter&lt;/a&gt; (Open DMs).
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/cover.jpg?v=15"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>cybersecurity, ciso, infosec, security, hacking, information security, research</itunes:keywords>
    <itunes:owner>
      <itunes:name>Security Conversations</itunes:name>
      <itunes:email>naraine@gmail.com</itunes:email>
    </itunes:owner>
<itunes:category text="Technology"/>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Technology"/>
<item>
  <title>Sid Trivedi on the RSA Innovation Sandbox $5 million investment gambit</title>
  <link>http://securityconversations.fireside.fm/sid-trivedi-foundation-capital-rsa-sandbox</link>
  <guid isPermaLink="false">9a555cb5-87d5-444f-b6c3-56ce4cf24bde</guid>
  <pubDate>Thu, 28 Nov 2024 07:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/9a555cb5-87d5-444f-b6c3-56ce4cf24bde.mp3" length="52339389" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly, the firmware security experts (https://binarly.io)
- Binary Risk Hunt (https://risk.binarly.io)

In this reboot of the Security Conversations interview series, Foundation Capital partner Sid Trivedi weighs in on major changes to the RSA Innovation Sandbox, the mandatory $5M uncapped SAFE investment for all 10 finalists, and red-flag concerns around discounts and pro-rata rights.

Also discussed: controversial pay-for-play dynamics involving CISOs and venture capital firms,  ethical implications of CISOs taking advisory positions in startups, and the challenges of investing in seed-stage startups amidst a trend towards platformization.  </itunes:subtitle>
  <itunes:duration>1:01:12</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/9/9a555cb5-87d5-444f-b6c3-56ce4cf24bde/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
Binary Risk Hunt (https://risk.binarly.io)
In this reboot of the Security Conversations interview series, Foundation Capital partner Sid Trivedi weighs in on major changes to the RSA Innovation Sandbox, the mandatory $5M uncapped SAFE investment for all 10 finalists, and red-flag concerns around discounts and pro-rata rights.
Also discussed: controversial pay-for-play dynamics involving CISOs and venture capital firms,  ethical implications of CISOs taking advisory positions in startups, and the challenges of investing in seed-stage startups amidst a trend towards platformization.  
</description>
  <itunes:keywords>Foundation Capital, Sid Trivedi, RSA Innovation Sandbox, venture capital, SAFE, pro rata rights, pay-for-play, advisory boards, CISO ethics</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>Binary Risk Hunt (<a href="https://risk.binarly.io" rel="nofollow">https://risk.binarly.io</a>)</li>
</ul>

<p>In this reboot of the Security Conversations interview series, Foundation Capital partner Sid Trivedi weighs in on major changes to the RSA Innovation Sandbox, the mandatory $5M uncapped SAFE investment for all 10 finalists, and red-flag concerns around discounts and pro-rata rights.</p>

<p>Also discussed: controversial pay-for-play dynamics involving CISOs and venture capital firms,  ethical implications of CISOs taking advisory positions in startups, and the challenges of investing in seed-stage startups amidst a trend towards platformization.  </p><p>Links:</p><ul><li><a title="RSA’s Innovation Sandbox: Cybersecurity Startups Must Accept $5 Million Investment" rel="nofollow" href="https://www.securityweek.com/rsa-conference-will-take-equity-in-innovation-sandbox-startup-finalists/">RSA’s Innovation Sandbox: Cybersecurity Startups Must Accept $5 Million Investment</a></li><li><a title="RSA Innovation Sandbox: $50 Million Annual Investment Program for Top 10 Finalists" rel="nofollow" href="https://www.rsaconference.com/library/press-release/rsa-conference-2025-innovation-sandbox-contest-celebrates-20th-anniversary">RSA Innovation Sandbox: $50 Million Annual Investment Program for Top 10 Finalists</a></li><li><a title="RSA Conference - How do SAFEs work?" rel="nofollow" href="https://www.rsaconference.com/usa/programs/innovation-sandbox/safe">RSA Conference - How do SAFEs work?</a></li><li><a title="This VC Built A Cybersecurity Unicorn Machine. Then Came A Conflict Of Interest Mess." rel="nofollow" href="https://archive.ph/RRHHE">This VC Built A Cybersecurity Unicorn Machine. Then Came A Conflict Of Interest Mess.</a></li><li><a title="The Gili Ra’anan model: CISOs and VCs controversy" rel="nofollow" href="https://www.calcalistech.com/ctechnews/article/b1a1jn00hc">The Gili Ra’anan model: CISOs and VCs controversy</a></li><li><a title="Sid Trivedi bio" rel="nofollow" href="https://foundationcapital.com/member/sid-trivedi/">Sid Trivedi bio</a></li><li><a title="Foundation Capital" rel="nofollow" href="https://foundationcapital.com/">Foundation Capital</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>Binary Risk Hunt (<a href="https://risk.binarly.io" rel="nofollow">https://risk.binarly.io</a>)</li>
</ul>

<p>In this reboot of the Security Conversations interview series, Foundation Capital partner Sid Trivedi weighs in on major changes to the RSA Innovation Sandbox, the mandatory $5M uncapped SAFE investment for all 10 finalists, and red-flag concerns around discounts and pro-rata rights.</p>

<p>Also discussed: controversial pay-for-play dynamics involving CISOs and venture capital firms,  ethical implications of CISOs taking advisory positions in startups, and the challenges of investing in seed-stage startups amidst a trend towards platformization.  </p><p>Links:</p><ul><li><a title="RSA’s Innovation Sandbox: Cybersecurity Startups Must Accept $5 Million Investment" rel="nofollow" href="https://www.securityweek.com/rsa-conference-will-take-equity-in-innovation-sandbox-startup-finalists/">RSA’s Innovation Sandbox: Cybersecurity Startups Must Accept $5 Million Investment</a></li><li><a title="RSA Innovation Sandbox: $50 Million Annual Investment Program for Top 10 Finalists" rel="nofollow" href="https://www.rsaconference.com/library/press-release/rsa-conference-2025-innovation-sandbox-contest-celebrates-20th-anniversary">RSA Innovation Sandbox: $50 Million Annual Investment Program for Top 10 Finalists</a></li><li><a title="RSA Conference - How do SAFEs work?" rel="nofollow" href="https://www.rsaconference.com/usa/programs/innovation-sandbox/safe">RSA Conference - How do SAFEs work?</a></li><li><a title="This VC Built A Cybersecurity Unicorn Machine. Then Came A Conflict Of Interest Mess." rel="nofollow" href="https://archive.ph/RRHHE">This VC Built A Cybersecurity Unicorn Machine. Then Came A Conflict Of Interest Mess.</a></li><li><a title="The Gili Ra’anan model: CISOs and VCs controversy" rel="nofollow" href="https://www.calcalistech.com/ctechnews/article/b1a1jn00hc">The Gili Ra’anan model: CISOs and VCs controversy</a></li><li><a title="Sid Trivedi bio" rel="nofollow" href="https://foundationcapital.com/member/sid-trivedi/">Sid Trivedi bio</a></li><li><a title="Foundation Capital" rel="nofollow" href="https://foundationcapital.com/">Foundation Capital</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Ep13: The Consolation of Threat Intel (JAG-S LABScon keynote)</title>
  <link>http://securityconversations.fireside.fm/tbp-ep13</link>
  <guid isPermaLink="false">6ceedb7b-2400-45e2-8798-027400574c18</guid>
  <pubDate>Sat, 21 Sep 2024 12:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/6ceedb7b-2400-45e2-8798-027400574c18.mp3" length="30869148" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Three Buddy Problem Episode 13:  This is a special edition of the show, featuring Juan Andres Guerrero-Saade's full keynote day remarks at LABScon2024.  In this talk, Juanito addresses the current state of the threat intelligence industry, expressing a need for a difficult conversation about its direction and purpose. He discusses feelings of disenfranchisement among professionals, the void in meaningful work, and the importance of reclaiming control and value in cybersecurity. Juan emphasizes the need for researchers, journalists, and even VCs, to be the change to reinvigorate the industry and ensure its relevance and impact.

Cast: Juan Andres Guerrero-Saade (SentinelLabs).  Costin Raiu and Ryan Naraine are listening to this episode.</itunes:subtitle>
  <itunes:duration>31:41</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/6/6ceedb7b-2400-45e2-8798-027400574c18/cover.jpg?v=1"/>
  <description>Three Buddy Problem - Episode 13:  This is a special edition of the show, featuring Juan Andres Guerrero-Saade's full keynote day remarks at LABScon2024.  In this talk, Juanito addresses the current state of the threat intelligence industry, expressing a need for a difficult conversation about its direction and purpose. He discusses feelings of disenfranchisement among professionals, the void in meaningful work, and the importance of reclaiming control and value in cybersecurity. Juan emphasizes the need for researchers, journalists, and even VCs, to be the change to reinvigorate the industry and ensure its relevance and impact.
Cast: Juan Andres Guerrero-Saade (SentinelLabs).  Costin Raiu and Ryan Naraine are listening to this episode.
</description>
  <itunes:keywords>threat intel, APT, nation-state, balkanization, journalism, research, venture capital</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 13</strong>:  This is a special edition of the show, featuring Juan Andres Guerrero-Saade&#39;s full keynote day remarks at LABScon2024.  In this talk, Juanito addresses the current state of the threat intelligence industry, expressing a need for a difficult conversation about its direction and purpose. He discusses feelings of disenfranchisement among professionals, the void in meaningful work, and the importance of reclaiming control and value in cybersecurity. Juan emphasizes the need for researchers, journalists, and even VCs, to be the change to reinvigorate the industry and ensure its relevance and impact.</p>

<p><strong>Cast:</strong> Juan Andres Guerrero-Saade (SentinelLabs).  Costin Raiu and Ryan Naraine are listening to this episode.</p><p>Links:</p><ul><li><a title="LABScon 2024" rel="nofollow" href="https://www.labscon.io/">LABScon 2024</a></li><li><a title="J. A. Guerrero-Saade on Twitter" rel="nofollow" href="https://x.com/juanandres_gs">J. A. Guerrero-Saade on Twitter</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Three Buddy Problem - Episode 13</strong>:  This is a special edition of the show, featuring Juan Andres Guerrero-Saade&#39;s full keynote day remarks at LABScon2024.  In this talk, Juanito addresses the current state of the threat intelligence industry, expressing a need for a difficult conversation about its direction and purpose. He discusses feelings of disenfranchisement among professionals, the void in meaningful work, and the importance of reclaiming control and value in cybersecurity. Juan emphasizes the need for researchers, journalists, and even VCs, to be the change to reinvigorate the industry and ensure its relevance and impact.</p>

<p><strong>Cast:</strong> Juan Andres Guerrero-Saade (SentinelLabs).  Costin Raiu and Ryan Naraine are listening to this episode.</p><p>Links:</p><ul><li><a title="LABScon 2024" rel="nofollow" href="https://www.labscon.io/">LABScon 2024</a></li><li><a title="J. A. Guerrero-Saade on Twitter" rel="nofollow" href="https://x.com/juanandres_gs">J. A. Guerrero-Saade on Twitter</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Cris Neckar on the early days of securing Chrome, chasing browser exploits</title>
  <link>http://securityconversations.fireside.fm/cris-neckar-chrome-security-stories</link>
  <guid isPermaLink="false">8151cb78-e91b-4526-95cc-6ea1dd6ddec5</guid>
  <pubDate>Thu, 11 Apr 2024 10:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/8151cb78-e91b-4526-95cc-6ea1dd6ddec5.mp3" length="52672988" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly, the supply chain security experts (https://binarly.io)
- XZ.fail backdoor detector  (https://xz.fail)

Cris Neckar is a veteran security researcher now working as a partner at Two Bear Capital.  In this episode, he reminisces on the early days of hacking at Neohapsis, his time on the Google Chrome security team, shenanigans at Pwn2Own/Pwnium and the cat-and-mouse battle for browser exploit chains. We also discuss the zero-day exploit marketplace, the hype and promise of AI, and his mission to help highly technical founders bring products to market.</itunes:subtitle>
  <itunes:duration>54:36</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/8/8151cb78-e91b-4526-95cc-6ea1dd6ddec5/cover.jpg?v=4"/>
  <description>Episode sponsors:
Binarly, the supply chain security experts (https://binarly.io)
XZ.fail backdoor detector  (https://xz.fail)
Cris Neckar is a veteran security researcher now working as a partner at Two Bear Capital.  In this episode, he reminisces on the early days of hacking at Neohapsis, his time on the Google Chrome security team, shenanigans at Pwn2Own/Pwnium, and the cat-and-mouse battle for browser exploit chains. We also discuss the zero-day exploit marketplace, the hype and promise of AI, and his mission to help highly technical founders bring products to market. 
</description>
  <itunes:keywords>venture capital, investments, supply chain, Chrome, Pwn2Own</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly, the supply chain security experts (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>XZ.fail backdoor detector  (<a href="https://xz.fail" rel="nofollow">https://xz.fail</a>)</li>
</ul>

<p>Cris Neckar is a veteran security researcher now working as a partner at Two Bear Capital.  In this episode, he reminisces on the early days of hacking at Neohapsis, his time on the Google Chrome security team, shenanigans at Pwn2Own/Pwnium, and the cat-and-mouse battle for browser exploit chains. We also discuss the zero-day exploit marketplace, the hype and promise of AI, and his mission to help highly technical founders bring products to market.</p><p>Links:</p><ul><li><a title="Unedited transcript (AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Xhf2pVxE4Trb9TVbK2VEBP6zDDe25MAbPdiAeh501h0/edit#heading=h.ulpyi4qqiq06">Unedited transcript (AI-generated)</a></li><li><a title="Cris Neckar on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/crisneckar/">Cris Neckar on LinkedIn</a></li><li><a title="Cris Neckar Bio (Two Bear Capital)" rel="nofollow" href="https://www.twobearcapital.com/team/cris-neckar">Cris Neckar Bio (Two Bear Capital)</a></li><li><a title="Teenager hacks Google Chrome with three 0days" rel="nofollow" href="https://www.zdnet.com/article/teenager-hacks-google-chrome-with-three-0day-vulnerabilities/">Teenager hacks Google Chrome with three 0days</a></li><li><a title="Research on Trident zero-day flaws" rel="nofollow" href="https://www.lookout.com/threat-intelligence/article/trident-pegasus-technical-details">Research on Trident zero-day flaws</a></li><li><a title="Cris Neckar podcast transcript (Unedited)" rel="nofollow" href="https://docs.google.com/document/d/1Xhf2pVxE4Trb9TVbK2VEBP6zDDe25MAbPdiAeh501h0/edit#heading">Cris Neckar podcast transcript (Unedited)</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly, the supply chain security experts (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>XZ.fail backdoor detector  (<a href="https://xz.fail" rel="nofollow">https://xz.fail</a>)</li>
</ul>

<p>Cris Neckar is a veteran security researcher now working as a partner at Two Bear Capital.  In this episode, he reminisces on the early days of hacking at Neohapsis, his time on the Google Chrome security team, shenanigans at Pwn2Own/Pwnium, and the cat-and-mouse battle for browser exploit chains. We also discuss the zero-day exploit marketplace, the hype and promise of AI, and his mission to help highly technical founders bring products to market.</p><p>Links:</p><ul><li><a title="Unedited transcript (AI-generated)" rel="nofollow" href="https://docs.google.com/document/d/1Xhf2pVxE4Trb9TVbK2VEBP6zDDe25MAbPdiAeh501h0/edit#heading=h.ulpyi4qqiq06">Unedited transcript (AI-generated)</a></li><li><a title="Cris Neckar on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/crisneckar/">Cris Neckar on LinkedIn</a></li><li><a title="Cris Neckar Bio (Two Bear Capital)" rel="nofollow" href="https://www.twobearcapital.com/team/cris-neckar">Cris Neckar Bio (Two Bear Capital)</a></li><li><a title="Teenager hacks Google Chrome with three 0days" rel="nofollow" href="https://www.zdnet.com/article/teenager-hacks-google-chrome-with-three-0day-vulnerabilities/">Teenager hacks Google Chrome with three 0days</a></li><li><a title="Research on Trident zero-day flaws" rel="nofollow" href="https://www.lookout.com/threat-intelligence/article/trident-pegasus-technical-details">Research on Trident zero-day flaws</a></li><li><a title="Cris Neckar podcast transcript (Unedited)" rel="nofollow" href="https://docs.google.com/document/d/1Xhf2pVxE4Trb9TVbK2VEBP6zDDe25MAbPdiAeh501h0/edit#heading">Cris Neckar podcast transcript (Unedited)</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Seth Spergel on venture capital bets in cybersecurity</title>
  <link>http://securityconversations.fireside.fm/seth-spergel-merlin-ventures</link>
  <guid isPermaLink="false">1f02640b-edf7-4549-8012-6764dcca018d</guid>
  <pubDate>Tue, 21 Nov 2023 10:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/1f02640b-edf7-4549-8012-6764dcca018d.mp3" length="17151625" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly, the firmware security experts (https://binarly.io)
- FwHunt (https://fwhunt.run)

Seth Spergel is managing partner at Merlin Ventures, where he is responsible for identifying cutting-edge companies for Merlin to partner with and invest in. In this episode, Seth talks about helping startups target US federal markets, the current state of deal sizes and valuations, and the red-hot sectors in cybersecurity ripe for venture investment.</itunes:subtitle>
  <itunes:duration>28:56</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/1/1f02640b-edf7-4549-8012-6764dcca018d/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
Seth Spergel is managing partner at Merlin Ventures, where he is responsible for identifying cutting-edge companies for Merlin to partner with and invest in. In this episode, Seth talks about helping startups target US federal markets, the current state of deal sizes and valuations, and the red-hot sectors in cybersecurity ripe for venture investment.
</description>
  <itunes:keywords>Venture capital, Merlin Ventures, investments, Artifical Intelligence</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Seth Spergel is managing partner at Merlin Ventures, where he is responsible for identifying cutting-edge companies for Merlin to partner with and invest in. In this episode, Seth talks about helping startups target US federal markets, the current state of deal sizes and valuations, and the red-hot sectors in cybersecurity ripe for venture investment.</p><p>Links:</p><ul><li><a title="Seth Spergel bio" rel="nofollow" href="https://merlin.vc/team/seth-spergel/">Seth Spergel bio</a> &mdash; Seth has more than 20 years of experience building, selling, and investing in software and startups. Prior to Merlin Ventures, Seth was VP for Infrastructure Technologies at In-Q-Tel, a strategic investment firm that invests in startups that meet the mission needs of government customers. </li><li><a title="Merlin Ventures portfolio" rel="nofollow" href="https://merlin.vc/portfolio/">Merlin Ventures portfolio</a></li><li><a title="Palo Alto buys Talon, Dig Security" rel="nofollow" href="https://www.securityweek.com/palo-alto-to-acquire-talon-intensifying-competition-in-cloud-data-security/">Palo Alto buys Talon, Dig Security</a> &mdash; Technology powerhouse Palo Alto Networks is officially on a billion-dollar shopping spree in the cloud data security space.</li><li><a title="Episode Sponsor: Binarly" rel="nofollow" href="https://binarly.io/capabilities/index.html">Episode Sponsor: Binarly</a> &mdash; The Binarly REsearch team leads the industry in firmware vulnerability disclosure and advisories</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Seth Spergel is managing partner at Merlin Ventures, where he is responsible for identifying cutting-edge companies for Merlin to partner with and invest in. In this episode, Seth talks about helping startups target US federal markets, the current state of deal sizes and valuations, and the red-hot sectors in cybersecurity ripe for venture investment.</p><p>Links:</p><ul><li><a title="Seth Spergel bio" rel="nofollow" href="https://merlin.vc/team/seth-spergel/">Seth Spergel bio</a> &mdash; Seth has more than 20 years of experience building, selling, and investing in software and startups. Prior to Merlin Ventures, Seth was VP for Infrastructure Technologies at In-Q-Tel, a strategic investment firm that invests in startups that meet the mission needs of government customers. </li><li><a title="Merlin Ventures portfolio" rel="nofollow" href="https://merlin.vc/portfolio/">Merlin Ventures portfolio</a></li><li><a title="Palo Alto buys Talon, Dig Security" rel="nofollow" href="https://www.securityweek.com/palo-alto-to-acquire-talon-intensifying-competition-in-cloud-data-security/">Palo Alto buys Talon, Dig Security</a> &mdash; Technology powerhouse Palo Alto Networks is officially on a billion-dollar shopping spree in the cloud data security space.</li><li><a title="Episode Sponsor: Binarly" rel="nofollow" href="https://binarly.io/capabilities/index.html">Episode Sponsor: Binarly</a> &mdash; The Binarly REsearch team leads the industry in firmware vulnerability disclosure and advisories</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Dan Lorenc on fixing the 'crappy' CVE ecosystem </title>
  <link>http://securityconversations.fireside.fm/dan-lorenc-deciphers-cve-cvss-sbom-supply-chains</link>
  <guid isPermaLink="false">aa617e3f-5689-4e88-a3ea-69bf50679c6e</guid>
  <pubDate>Tue, 14 Nov 2023 06:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/aa617e3f-5689-4e88-a3ea-69bf50679c6e.mp3" length="40642471" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly, the firmware security experts (https://binarly.io)
- FwHunt (https://fwhunt.run)

Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a "growth mode" startup, massive funding rounds and VC expectations, fixing the "crappy" CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.</itunes:subtitle>
  <itunes:duration>41:45</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/a/aa617e3f-5689-4e88-a3ea-69bf50679c6e/cover.jpg?v=1"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a "growth mode" startup, massive funding rounds and VC expectations, fixing the "crappy" CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.
</description>
  <itunes:keywords>Chainguard, supply chain, SBOMs, CVE, Venture Capital</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a &quot;growth mode&quot; startup, massive funding rounds and VC expectations, fixing the &quot;crappy&quot; CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.</p><p>Links:</p><ul><li><a title="SBOMs - All the right ingredients, but something is still missing" rel="nofollow" href="https://p72.vc/perspectives/software-bills-of-material-sboms/">SBOMs - All the right ingredients, but something is still missing</a></li><li><a title="Open Source Development Threatened in Europe" rel="nofollow" href="https://thenewstack.io/open-source-development-threatened-in-europe/">Open Source Development Threatened in Europe</a></li><li><a title="Chainguard Images: Reduce your attack surface" rel="nofollow" href="https://www.chainguard.dev/chainguard-images">Chainguard Images: Reduce your attack surface</a></li><li><a title="Dan Lorenc on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/danlorenc/">Dan Lorenc on LinkedIn</a></li><li><a title="Dan Lorenc on Twitter/X" rel="nofollow" href="https://twitter.com/lorenc_dan">Dan Lorenc on Twitter/X</a></li><li><a title="Chainguard Raises $61 Million Series B" rel="nofollow" href="https://www.chainguard.dev/unchained/series-b-funding">Chainguard Raises $61 Million Series B</a></li><li><a title="Binarly -- Firmware Supply Chain Security Platform" rel="nofollow" href="https://binarly.io/">Binarly -- Firmware Supply Chain Security Platform</a> &mdash; Binarly is the world's first automated firmware supply chain security platform. Using cutting-edge techniques, Binarly identifies both known and unknown vulnerabilities, misconfigurations, and malicious code in firmware and hardware components.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Dan Lorenc is CEO and co-founder of Chainguard, a company that raised $116 million in less than two years to tackle open source supply chain security problems.  In this episode, Dan joins Ryan to chat about the demands of building a &quot;growth mode&quot; startup, massive funding rounds and VC expectations, fixing the &quot;crappy&quot; CVE and CVSS ecosystems, managing expectations around SBOMs, and how politicians and lobbyists are framing cybersecurity issues in strange ways.</p><p>Links:</p><ul><li><a title="SBOMs - All the right ingredients, but something is still missing" rel="nofollow" href="https://p72.vc/perspectives/software-bills-of-material-sboms/">SBOMs - All the right ingredients, but something is still missing</a></li><li><a title="Open Source Development Threatened in Europe" rel="nofollow" href="https://thenewstack.io/open-source-development-threatened-in-europe/">Open Source Development Threatened in Europe</a></li><li><a title="Chainguard Images: Reduce your attack surface" rel="nofollow" href="https://www.chainguard.dev/chainguard-images">Chainguard Images: Reduce your attack surface</a></li><li><a title="Dan Lorenc on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/danlorenc/">Dan Lorenc on LinkedIn</a></li><li><a title="Dan Lorenc on Twitter/X" rel="nofollow" href="https://twitter.com/lorenc_dan">Dan Lorenc on Twitter/X</a></li><li><a title="Chainguard Raises $61 Million Series B" rel="nofollow" href="https://www.chainguard.dev/unchained/series-b-funding">Chainguard Raises $61 Million Series B</a></li><li><a title="Binarly -- Firmware Supply Chain Security Platform" rel="nofollow" href="https://binarly.io/">Binarly -- Firmware Supply Chain Security Platform</a> &mdash; Binarly is the world's first automated firmware supply chain security platform. Using cutting-edge techniques, Binarly identifies both known and unknown vulnerabilities, misconfigurations, and malicious code in firmware and hardware components.</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Sidra Ahmed Lefort dishes on VC investments and cyber uncertainties</title>
  <link>http://securityconversations.fireside.fm/sidra-ahmed-lefort-munich-re-ventures</link>
  <guid isPermaLink="false">517e5949-6bfd-4225-9a75-c3d75ebf7d4c</guid>
  <pubDate>Wed, 15 Feb 2023 08:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/517e5949-6bfd-4225-9a75-c3d75ebf7d4c.mp3" length="27740001" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Episode sponsors: 

- Binarly (https://binarly.io)
- FwHunt (https://fwhunt.run)

Munich Re Ventures investment principal Sidra Ahmed Lefort joins Ryan for a frank discussion on the state of VC funding in cybersecurity, the rise (and coming fall?) of 'unicorns', the massive early-stage funding rounds and what they mean, layoffs and contractions, and the areas in security still ripe for innovation.</itunes:subtitle>
  <itunes:duration>31:00</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/5/517e5949-6bfd-4225-9a75-c3d75ebf7d4c/cover.jpg?v=2"/>
  <description>Episode sponsors:
Binarly (https://binarly.io)
FwHunt (https://fwhunt.run)
Munich Re Ventures investment principal Sidra Ahmed Lefort joins Ryan Naraine for a frank discussion on the state of VC funding in cybersecurity, the rise (and coming correction) in the land of security 'unicorns', the massive early-stage funding rounds and what they mean, layoffs and contractions, and the places in security still ripe for innovation. 
</description>
  <itunes:keywords>venture capital, investments, data security</itunes:keywords>
  <content:encoded>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Munich Re Ventures investment principal Sidra Ahmed Lefort joins Ryan Naraine for a frank discussion on the state of VC funding in cybersecurity, the rise (and coming correction) in the land of security &#39;unicorns&#39;, the massive early-stage funding rounds and what they mean, layoffs and contractions, and the places in security still ripe for innovation.</p><p>Links:</p><ul><li><a title="Sidra Ahmed Lefort on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/sidra-ahmed-lefort/">Sidra Ahmed Lefort on LinkedIn</a></li><li><a title="Portfolio | Munich Re Ventures" rel="nofollow" href="https://www.munichre.com/mrv/en/portfolio.html">Portfolio | Munich Re Ventures</a></li><li><a title="What&#39;s Going on With Cybersecurity VC Investments?" rel="nofollow" href="https://www.securityweek.com/whats-going-cybersecurity-vc-investments/">What's Going on With Cybersecurity VC Investments?</a></li><li><a title="Video: VC View - Trends in Cybersecurity Innovation" rel="nofollow" href="https://vimeo.com/755174743">Video: VC View - Trends in Cybersecurity Innovation</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p><strong>Episode sponsors:</strong></p>

<ul>
<li>Binarly (<a href="https://binarly.io" rel="nofollow">https://binarly.io</a>)</li>
<li>FwHunt (<a href="https://fwhunt.run" rel="nofollow">https://fwhunt.run</a>)</li>
</ul>

<p>Munich Re Ventures investment principal Sidra Ahmed Lefort joins Ryan Naraine for a frank discussion on the state of VC funding in cybersecurity, the rise (and coming correction) in the land of security &#39;unicorns&#39;, the massive early-stage funding rounds and what they mean, layoffs and contractions, and the places in security still ripe for innovation.</p><p>Links:</p><ul><li><a title="Sidra Ahmed Lefort on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/sidra-ahmed-lefort/">Sidra Ahmed Lefort on LinkedIn</a></li><li><a title="Portfolio | Munich Re Ventures" rel="nofollow" href="https://www.munichre.com/mrv/en/portfolio.html">Portfolio | Munich Re Ventures</a></li><li><a title="What&#39;s Going on With Cybersecurity VC Investments?" rel="nofollow" href="https://www.securityweek.com/whats-going-cybersecurity-vc-investments/">What's Going on With Cybersecurity VC Investments?</a></li><li><a title="Video: VC View - Trends in Cybersecurity Innovation" rel="nofollow" href="https://vimeo.com/755174743">Video: VC View - Trends in Cybersecurity Innovation</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Haroon Meer on the business of cybersecurity </title>
  <link>http://securityconversations.fireside.fm/haroon-meer-thinkst</link>
  <guid isPermaLink="false">1e1458ae-78d3-445a-8b8a-42cee0397f6c</guid>
  <pubDate>Sat, 19 Mar 2022 10:00:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/1e1458ae-78d3-445a-8b8a-42cee0397f6c.mp3" length="58885756" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Thinkst founder and CEO Haroon Meer joins Ryan Naraine on the show to talk about building a successful cybersecurity company without venture capital investment, fast-moving attack surfaces and the never-ending battle to mitigate memory corruption issues.</itunes:subtitle>
  <itunes:duration>1:15:12</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/1/1e1458ae-78d3-445a-8b8a-42cee0397f6c/cover.jpg?v=1"/>
  <description>Thinkst founder and CEO Haroon Meer joins Ryan Naraine on the show to talk about building a successful cybersecurity company without venture capital investment, fast-moving attack surfaces and the never-ending battle to mitigate memory corruption issues. 
</description>
  <itunes:keywords>thinkst, canaries, breach detection, startup, venture capital, entrepreneurship, memory corruption, ransomware, attack surfaces</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Thinkst founder and CEO Haroon Meer joins Ryan Naraine on the show to talk about building a successful cybersecurity company without venture capital investment, fast-moving attack surfaces and the never-ending battle to mitigate memory corruption issues.</p><p>Links:</p><ul><li><a title="Haroon Meer on Twitter" rel="nofollow" href="https://twitter.com/haroonmeer">Haroon Meer on Twitter</a></li><li><a title="Thinkst: We bootstrapped to $11 million in ARR" rel="nofollow" href="https://blog.thinkst.com/2021/03/we-bootstrapped-to-11-million-in-arr.html">Thinkst: We bootstrapped to $11 million in ARR</a></li><li><a title="Memory Corruption and Hacker Folklore" rel="nofollow" href="https://blog.thinkst.com/2010/05/memory-corruption-and-hacker-folklore.html">Memory Corruption and Hacker Folklore</a></li><li><a title="Thinkst Canary" rel="nofollow" href="https://canary.tools/">Thinkst Canary</a></li><li><a title="Podcast: Haroon Meer, Thinkst Applied Research" rel="nofollow" href="https://securityconversations.com/episode/haroon-meer-ceo-thinkst-applied-research/">Podcast: Haroon Meer, Thinkst Applied Research</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Thinkst founder and CEO Haroon Meer joins Ryan Naraine on the show to talk about building a successful cybersecurity company without venture capital investment, fast-moving attack surfaces and the never-ending battle to mitigate memory corruption issues.</p><p>Links:</p><ul><li><a title="Haroon Meer on Twitter" rel="nofollow" href="https://twitter.com/haroonmeer">Haroon Meer on Twitter</a></li><li><a title="Thinkst: We bootstrapped to $11 million in ARR" rel="nofollow" href="https://blog.thinkst.com/2021/03/we-bootstrapped-to-11-million-in-arr.html">Thinkst: We bootstrapped to $11 million in ARR</a></li><li><a title="Memory Corruption and Hacker Folklore" rel="nofollow" href="https://blog.thinkst.com/2010/05/memory-corruption-and-hacker-folklore.html">Memory Corruption and Hacker Folklore</a></li><li><a title="Thinkst Canary" rel="nofollow" href="https://canary.tools/">Thinkst Canary</a></li><li><a title="Podcast: Haroon Meer, Thinkst Applied Research" rel="nofollow" href="https://securityconversations.com/episode/haroon-meer-ceo-thinkst-applied-research/">Podcast: Haroon Meer, Thinkst Applied Research</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Fahmida Rashid, Executive Editor, VentureBeat</title>
  <link>http://securityconversations.fireside.fm/fahmida-rashid-venturebeat</link>
  <guid isPermaLink="false">e3d22755-cc83-43aa-b67d-8003ad468a6b</guid>
  <pubDate>Fri, 09 Apr 2021 10:30:00 -0700</pubDate>
  <author>Security Conversations</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/e3d22755-cc83-43aa-b67d-8003ad468a6b.mp3" length="31693302" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Security Conversations</itunes:author>
  <itunes:subtitle>Newly appointed Executive Editor at VentureBeat Fahmida Rashid joins the show to talk about her introduction to computer networking in school, her winding path into cybersecurity journalism, the security stories worth telling, the venture capital ecosystem, and the surge in unicorn cybersecurity startups.</itunes:subtitle>
  <itunes:duration>37:02</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/5/5f0c01ff-49f1-4c51-a8f8-f14c0d9bc72e/episodes/e/e3d22755-cc83-43aa-b67d-8003ad468a6b/cover.jpg?v=1"/>
  <description>Newly appointed Executive Editor at VentureBeat Fahmida Rashid joins the show to talk about her introduction to computer networking in school, her winding path into cybersecurity journalism, the security stories worth telling, the venture capital ecosystem, and the surge in unicorn cybersecurity startups. 
</description>
  <itunes:keywords>journalism, story-telling, writing, news gathering, venture capital, investments</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Newly appointed Executive Editor at VentureBeat Fahmida Rashid joins the show to talk about her introduction to computer networking in school, her winding path into cybersecurity journalism, the security stories worth telling, the venture capital ecosystem, and the surge in unicorn cybersecurity startups.</p><p>Links:</p><ul><li><a title="Follow Fahmida on Twitter" rel="nofollow" href="https://twitter.com/FYRashid">Follow Fahmida on Twitter</a></li><li><a title="Fahmida Rashid on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/fyrashid/">Fahmida Rashid on LinkedIn</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Newly appointed Executive Editor at VentureBeat Fahmida Rashid joins the show to talk about her introduction to computer networking in school, her winding path into cybersecurity journalism, the security stories worth telling, the venture capital ecosystem, and the surge in unicorn cybersecurity startups.</p><p>Links:</p><ul><li><a title="Follow Fahmida on Twitter" rel="nofollow" href="https://twitter.com/FYRashid">Follow Fahmida on Twitter</a></li><li><a title="Fahmida Rashid on LinkedIn" rel="nofollow" href="https://www.linkedin.com/in/fyrashid/">Fahmida Rashid on LinkedIn</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
