Blue Security

Blue Security

By Andy Jaw & Adam BrewerTechnology
Download on the App Store

Blue Security episodes

  • VPNs vs SDPs

    Adam and Andy talk about VPN's versus Software Defined Perimeters (SDP) this week. They break down why companies still use VPN's and why they pose an infosec security risk. They present SDP's as a different way of thinking about how to access internal applications and some vendors in the space already.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/N8CxB84f50A

    -------------------------------------------

    Documentation:

    https://www.blastwave.io/posts/house-of-cards-your-guide-to-getting-hacked-using-vpns

    https://docs.microsoft.com/en-us/azure/active-directory/app-proxy/what-is-application-proxy

    https://www.microsoft.com/security/blog/2020/01/23/microsoft-zscaler-help-organizations-implement-zero-trust-model/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    32 min
  • Okta Says Sorry, Fake Warrants, New PCI Reqs

    This week's episode, Adam and Andy talk about some interesting infosec news including Okta's apology and how that affected their stock prices. They also talk about the latest Apple zero days and an interesting tactic cybercriminals are using to get sensitive data out of organizations. Finally, they chat about the new PCI 4.0 standard and what's different from the current standard.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/Dja0bWaARQU

    -------------------------------------------

    Documentation:

    https://www.bleepingcomputer.com/news/security/okta-we-made-a-mistake-delaying-the-lapsus-hack-disclosure/

    https://krebsonsecurity.com/2022/03/fake-emergency-search-warrants-draw-scrutiny-from-capitol-hill/

    https://www.darkreading.com/edge-articles/what-s-new-in-pci-dss-4-0-for-authentication-requirements

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    34 min
  • LAPSUS$

    This week's episode, Adam and Andy talk about the hacker group LAPSUS$. They go over what makes this group unique in the cybercriminal world and a breakdown of the latest high value targets.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/w-7RPcOl8HE

    -------------------------------------------

    Documentation:

    https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/

    https://www.linkedin.com/pulse/open-letter-okta-amit-yoran/

    https://sec.okta.com/articles/2022/03/official-okta-statement-lapsus-claims

    https://support.okta.com/help/s/article/Frequently-Asked-Questions-Regarding-January-2022-Compromise?language=en_US

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    42 min
  • Infosec News Catch Up

    This week's episode, Adam and Andy catch up on some infosec news including the new Cyber Incident Reporting Act signed into law last week and other reporting policies on the horizon. They also talk about CISA's advisory on misconfigured MFA and Russia's new root certificate.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/igcF6dLvq4E

    -------------------------------------------

    Documentation:

    https://www.cisa.gov/uscert/ncas/alerts/aa22-074a

    https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/workbook-conditional-access-gap-analyzer

    https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-insights-reporting

    https://www.eff.org/deeplinks/2022/03/you-should-not-trust-russias-new-trusted-root-ca

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    30 min
  • Helpdesk Security

    This week's episode, Adam and Andy talk about helpdesk security. Enterprise helpdesks are often a popular target for cybercriminals because they have access to sensitive information and accounts. Listen in as they talk about things to think about when driving towards a zero trust model for helpdesk security.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/6WPDH9W8UOQ

    -------------------------------------------

    Documentation:

    https://www.linkedin.com/pulse/password-tickets-consume-31-40-help-desks-time-roy-verberne/?articleId=6627845881985146880

    https://specopssoft.com/product/secure-service-desk/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    30 min
  • War in the Digital Age

    This week's episode, Adam and Andy talk about the Russian invasion of Ukraine and the information war that is happening behind the scenes. They go over some specific takeaways on what to focus on in this heightened state of cybersecurity risk.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/a2452Yd0--g

    -------------------------------------------

    Documentation:

    SANS Webcast: Russian Cyber Attack Escalation in Ukraine - What You Need To Know! https://www.youtube.com/watch?v=bZoHePqoBtM

    https://blogs.microsoft.com/on-the-issues/2022/02/28/ukraine-russia-digital-war-cyberattacks/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Linkedin: https://www.linkedin.com/company/bluesecpod

    Youtube: https://www.youtube.com/c/BlueSecurityPodcast

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    32 min
  • Windows Hello for Business Revisited

    This week's episode, Adam and Andy talk about the new cloud key trust deployment model for Windows Hello for Business in hybrid environments. Cloud key trust greatly simplifies the deployment of Windows Hello for Business by removing the requirement for any PKI infrastructure. If you've been waiting to try this passwordless solution to authenticate to Windows PC's, now is the time. There are benefits even if you are using Azure AD Joined devices. Listen in on how to get started today!

    -------------------------------------------

    Youtube Video Link: https://youtu.be/9e7XyVWIPk8

    -------------------------------------------

    Documentation:

    https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trust

    https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-how-it-works-authentication#hybrid-azure-ad-join-authentication-using-azure-ad-kerberos-cloud-trust-preview

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    27 min
  • Password Cracking

    This week's episode, Adam and Andy talk about the basics of password cracking. Understanding how passwords are cracked by offensive security and cybercriminals can help defenders scope and make better password policies.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/f2IniyS8Le4

    -------------------------------------------

    Documentation:

    https://techcommunity.microsoft.com/t5/azure-active-directory-identity/your-pa-word-doesn-t-matter/ba-p/731984

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    21 min
  • Geopolitical Crises and Cybersecurity

    This week's episode, Adam and Andy talk about some of the geopolitical crises happening around the world with Russia and China and how that affects cybersecurity defenders.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/LATDlvH6h90

    -------------------------------------------

    Documentation:

    https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    24 min
  • Windows Defender Application Control

    This week's episode, Adam and Andy continue their Windows Security series and talk about Defender Application Control. This is a great feature built into Windows Enterprise that can help reduce the attack surface in many use cases. Listen in on how it works and how to test and implement it.

    -------------------------------------------

    Youtube Video Link: https://youtu.be/A0LXCsIIFBM

    -------------------------------------------

    Documentation:

    https://call4cloud.nl/2021/06/wdac-or-the-unexpected-virtue-of-ignorance/

    https://webapp-wdac-wizard.azurewebsites.net/

    -------------------------------------------

    Contact Us:

    Website: http://bluesecuritypod.com

    Twitter: https://twitter.com/bluesecuritypod

    Instagram: https://www.instagram.com/bluesecuritypodcast/

    Facebook: https://www.facebook.com/bluesecpod

    Twitch: https://www.twitch.tv/bluesecuritypod

    -------------------------------------------

    Andy Jaw

    Twitter: https://twitter.com/ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    -------------------------------------------

    Adam Brewer

    Twitter: https://twitter.com/ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    23 min

About Blue Security

From the publisher's feed

A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.

More shows like Blue Security

Acquired by Ben Gilbert and David Rosenthal

Acquired

4,836 Listeners

Pivot by New York Magazine

Pivot

9,613 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

65 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

25 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Entra.Chat by Merill Fernando

Entra.Chat

6 Listeners