Inside the Box
Cybersecurity is broken down, not dumbed down.
Hosted by Peter Bassill — CEO of Hedgehog Security, CISSP, Chartered Fellow of the BCS, and veteran of over 25 years defending networks, building SOCs, and breaking into systems so the bad guys can't — alongside his AI co-host Emily, who brings the data, the research, and the awkward questions.
Each episode is 15 minutes or under. One topic, covered properly. Real threats, real defences, real stories from the front line — no vendor pitches, no fear-mongering, and no jargon without an explanation.
Whether you're a security professional, an IT manager holding the fort, or a business owner who's just realised cyber risk is business risk, Inside the Box gives you something practical you can act on. Every episode.
New episodes weekly. Stay safe. Stay patched.
Episodes

Apr 4, 2026
Apr 4, 2026
10 min
Episode 1 — "Hello, World": Introducing Inside the Box
Meet your hosts. Peter Bassill has spent over 25 years in cybersecurity — from network engineering in the mid-nineties, through defensive operations at Microsoft and beyond, to founding Hedgehog Security and running a 24/7 Security Operations Centre. His co-host Emily is an AI, and she's not shy about saying so.
In this opening episode, Peter and Emily explain what Inside the Box is, why it exists, and what you can expect from the series. They set the scene with a frank look at the current threat landscape: the industrialisation of cybercrime, the quiet devastation of business email compromise, and why the next attack on your organisation might come through software you already trust.
No jargon without an explanation. No sales pitches. Just fifteen minutes of honest, practical cybersecurity insight.

Apr 4, 2026
Apr 4, 2026
12 min
This week's threat landscape is dominated by supply chain compromise at industrial scale. The TeamPCP campaign has claimed its first named victim in Mercor, while Mandiant estimates thousands more are affected. North Korean hackers poisoned the axios npm package — downloaded over 100 million times per week. A new malware strain called DeepLoad uses AI-generated obfuscation and survives being removed from infected machines. Hasbro and Stryker are both dealing with operational disruption from cyberattacks. And yes, a coffee machine really did cause a corporate data breach.
Peter and Emily cover it all, with practical takeaways for businesses of every size.
In this episode:
LiteLLM supply chain attack cascades to thousands of organisations
Axios npm package compromised by North Korean threat actor
Trojanised Claude Code repositories spreading malware on GitHub
DeepLoad: AI-powered malware with ClickFix delivery and WMI persistence
Hasbro and Stryker cyberattack operational impact
The coffee machine that brought down a corporate network
RSAC 2026: Attribution risks and AI budget warnings
User behaviour as the primary entry point for attacks
Outro and action items
Episode tags: supply chain attack, LiteLLM, Trivy, axios, North Korea, Claude Code, DeepLoad, ClickFix, Hasbro, Stryker, IoT security, RSAC 2026
You'll want to adjust the chapter timestamps once the audio is produced to match the actual recording, but this gives you the structure to work from.






