Adversarial Podcast S4E06 – F5 Breach, AWS Outage, Risk Management vs. Security Engineering [ZQhQ7WROuUp]
00:00 Intro 00:50 AWS Outage 20:48 F5 Breach 41:06 Risk Management vs. Security Engineering 58:19 Moving the Needle Part 3 F5 Hack Blamed on China Chinese state-backed hackers allegedly breached U.S. cybersecurity firm F5, gaining year-long access to its systems and BIG-IP source code, prompting security fears and causing the company to warn of revenue impacts and falling shares. Reference: AWS Outage A race condition in Amazon DynamoDB’s DNS management system caused widespread outages across the US-EAST-1 region on October 19–20, 2025, disrupting DynamoDB, EC2, NLB, and multiple dependent AWS services until recovery was completed the next afternoon. Reference: The CISO Dilemma: Risk Management vs. Security Engineering This post argues that quantitative risk management (QRM) in cybersecurity is a deceptive comfort mechanism that lets executives rationalize insecurity, urging CISOs to reject financialized “risk buy-downs” and instead demand true security engineering and systemic architectural integrity. Reference: Hosts: Jerry Perullo (Founder, Sounil Yu (Founder, Mario Duarte (Founder, stealth startup) Producer: Tillson Galloway (Founder,