
Sign up to save your podcasts
Or


Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss significant developments in cybersecurity, including Microsoft's new AI vulnerability scanner, the long-awaited fix for Intune's sync button, and the implications of the Hugging Face and OpenAI incident. They explore the operationalization of AI in vulnerability discovery, the technical nuances of Intune's functionality, and the autonomy of AI agents in cyber operations, emphasizing the need for a balanced understanding of AI capabilities and limitations. In this conversation, Adam Brewer and Andy Jaw discuss the limitations of AI, the importance of cybersecurity in innovation, and the implications of recent incidents involving AI models. They emphasize the need for better security practices, the geopolitical aspects of AI development, and the future of AI models in various applications. The discussion highlights the balance between innovation and security, as well as the evolving landscape of AI technologies.
----------------------------------------------------
YouTube Video Link: https://youtu.be/FrhlHhjHtAQ
----------------------------------------------------
Documentation:
https://huggingface.co/blog/security-incident-july-2026
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.techrepublic.com/article/news-microsoft-july-2026-patch-tuesday/
https://patchmypc.com/blog/inside-the-improved-on-demand-sync-for-windows-devices/
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the upcoming transition to passkeys as the default method for multi-factor authentication (MFA) in Microsoft Entra ID. They explore the implications of this change, the importance of moving away from SMS and voice authentication, and best practices for organizations to prepare for this shift. The conversation also covers the challenges of transferring MFA codes and passkeys when upgrading phones, and introduces the YubiKey Locker, a new tool that enhances security by automatically locking devices when the YubiKey is removed. The hosts emphasize the need for organizations to modernize their identity infrastructure and adopt more secure authentication methods.
----------------------------------------------------
YouTube Video Link: https://youtu.be/eXqW3FAY_hE
----------------------------------------------------
Documentation:
https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/
https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-transfer-authenticator-new-phone
https://support.okta.com/help/s/article/migrating-all-existing-mfa-codes-to-okta-verify?language=en_US
https://www.sciber.io/sciber-blog/sciber-launches-yubikey-locker-to-defend-against-physical-attacks/
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, host Andy Jaw delves into the alarming rise of North Korean IT worker scams, exploring their historical context, operational tactics, and the financial implications for both the regime and unsuspecting American companies. The discussion highlights the vulnerabilities in the hiring process and offers practical mitigation strategies for organizations to protect themselves against these sophisticated cyber threats.
----------------------------------------------------
YouTube Video Link: https://youtu.be/wBZz3WEMG54
----------------------------------------------------
Documentation:
https://www.fbi.gov/wanted/cyber/dprk-it-fraud
https://www.csoonline.com/article/3481659/north-korean-group-infiltrated-100-plus-companies-with-imposter-it-pros.html
https://fortune.com/2025/07/24/north-korean-it-workers-chapman-nike/
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss Andy's career transition from Microsoft to Zscaler, the return of the AI model Fable and its user experience, and a critical SharePoint vulnerability that has caught CISA's attention. They delve into the implications of these topics for security professionals and the importance of staying updated on actively exploited vulnerabilities.
----------------------------------------------------
YouTube Video Link: https://youtu.be/3VbR22krL-w
----------------------------------------------------
Documentation:
https://www.bleepingcomputer.com/news/artificial-intelligence/claude-fable-relaunch-disappoints-users-with-nerfed-performance/
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer engage in a deep discussion about the implications of AI on society and the security industry. They explore whether AI is ultimately helping or hurting us, particularly in the context of job displacement and creation. The conversation delves into corporate strategies regarding AI investments, the financial implications of these technologies, and the broader backlash against the tech industry. They also analyze the economic landscape surrounding AI, emphasizing the need for a nuanced understanding of its impact. In this conversation, Adam Brewer and Andy Jaw delve into the complexities of AI investment, the competitive landscape posed by Chinese AI advancements, the implications of AI sycophancy, and the rising security risks associated with AI in social engineering. They also discuss the challenges of code security in AI development, emphasizing the need for robust security measures as AI-generated code becomes more prevalent.
----------------------------------------------------
YouTube Video Link: https://youtu.be/HzoyyLLpo7Y
----------------------------------------------------
Documentation:
https://blogs.microsoft.com/on-the-issues/2026/06/10/ai-jobs-and-the-next-generation/
https://markets.financialcontent.com/stocks/article/marketminute-2026-1-26-the-fragile-fifty-percent-jp-morgan-warns-of-systemic-tipping-point-as-s-and-p-500-concentration-hits-record-highs
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into the critical topic of Mobile Device Management (MDM) and the associated administrative rights. They discuss the risks posed by MDM admins, who often have significant control over organizational devices, and the need for robust security measures to protect against potential breaches. The conversation highlights the importance of understanding the roles within MDM, identifying risks, and implementing effective security controls to mitigate threats. The hosts provide actionable steps for organizations to enhance their security posture regarding MDM and administrative access.
----------------------------------------------------
YouTube Video Link: https://youtu.be/HzoyyLLpo7Y
----------------------------------------------------
Documentation:
https://trustedsec.com/blog/the-privileged-roles-nobody-talks-about
https://trustedsec.com/blog/hardening-intune-the-implementation-guide
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer celebrate their 300th episode by discussing the recent developments surrounding Anthropic and its AI model, Fable Five. They delve into the historical context of export controls, the implications of government regulations on technology, and the ongoing legal challenges faced by Anthropic. The conversation highlights the complexities of AI regulation, national security concerns, and the competitive landscape between the US and China in the AI sector.
----------------------------------------------------
YouTube Video Link: https://youtu.be/gsDOiDVBoIM
----------------------------------------------------
Documentation:
https://www.anthropic.com/news/fable-mythos-access
https://www.securityweek.com/anthropic-disputes-fable-5-ai-jailbreak/
https://www.csis.org/analysis/understanding-biden-administrations-updated-export-controls
https://www.cnbc.com/2025/11/20/us-approves-ai-chip-exports-to-gulf-after-saudi-crown-prince-visit.html
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss significant updates in Microsoft's security landscape, including the shift to passwordless authentication, cross-tenant synchronization, and the convergence of sensitivity labels with security groups. They also delve into Azure role governance and the implications of Facebook's new camera roll settings on user privacy.
----------------------------------------------------
YouTube Video Link: https://youtu.be/WFs6S42SCDs
----------------------------------------------------
Documentation:
https://www.bighatgroup.com/blog/entra-id-passwordless-default-governance-convergence-may-2026/
https://proton.me/blog/meta-ai-facebook-camera-roll
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss critical cybersecurity topics, including newly discovered Windows Zero Days, insights from Verizon's latest Data Breach Investigations Report, and a significant credential leak at CISA. They emphasize the importance of vulnerability management, the evolving threat landscape, and best practices for securing sensitive data. The conversation highlights the need for organizations to adapt quickly to emerging threats and implement robust security measures to protect against breaches.
----------------------------------------------------
YouTube Video Link: https://youtu.be/DtPgg2jQCyM
----------------------------------------------------
Documentation:
https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html?m=1
https://www.verizon.com/business/resources/T158/reports/2026-dbir-data-breach-investigations-report.pdf
https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss two significant topics: Agent 365, a new dashboard for monitoring AI agents in the Microsoft ecosystem, and MDash, a multi-model vulnerability scanner. They explore the importance of visibility and control over AI agents, the innovative licensing model for Agent 365, and the multi-model approach of MDash that enhances vulnerability detection. The conversation emphasizes the evolving landscape of cybersecurity and the need for organizations to adapt to new technologies and methodologies.
----------------------------------------------------
YouTube Video Link: https://youtu.be/BIqPhIkRFwg
----------------------------------------------------
Documentation:
https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/
https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/
https://www.microsoft.com/en-us/msrc/blog/2026/05/a-note-on-patch-tuesday
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
From the publisher's feed

4,837 Listeners

9,616 Listeners

2,010 Listeners

1,645 Listeners

373 Listeners

374 Listeners

651 Listeners

1,028 Listeners

317 Listeners

65 Listeners

179 Listeners

73 Listeners

25 Listeners

138 Listeners

5 Listeners