
Sign up to save your podcasts
Or


This week's episode, Adam and Andy have a great time chatting with fellow cybersecurity professionals Nate Gardner and Gavin Ashton walking through tabletop scenarios. This is something security defenders should do to test their incident response plan.
-------------------------------------------
Youtube Video Link: https://youtu.be/kwxSCd40gWQ
-------------------------------------------
Documentation:
Nate Gardner:
https://www.linkedin.com/in/nate-gardner-infosec/
Gavin Ashton:
https://twitter.com/gvnshtn
https://www.linkedin.com/in/gvnshtn/
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week's episode, Adam and Andy talk catch up on some infosec news including BadUSB, President Biden's memorandum for National Security Systems, iOS/MacOS vulnerablities, and new hardware with Microsoft's Pluton Security Processor.
-------------------------------------------
Youtube Video Link: https://youtu.be/yQebJcb2j3E
-------------------------------------------
Documentation:
https://www.darkreading.com/vulnerabilities-threats/more-security-flaws-found-in-apple-s-OS-technologies
https://www.whitehouse.gov/briefing-room/presidential-actions/2022/01/19/memorandum-on-improving-the-cybersecurity-of-national-security-department-of-defense-and-intelligence-community-systems/
https://www.csoonline.com/article/3647173/badusb-explained-how-rogue-usbs-threaten-your-organization.html#tk.rss_all
https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-excel-40-macros-by-default-to-block-malware/
https://www.csoonline.com/article/3647170/microsofts-pluton-security-processor-tackles-hardware-firmware-vulnerabilities.html#tk.rss_all
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week's episode, Adam and Andy talk with special guest Shannon Fritz on Windows Device Management. If you haven't listened to Shannon's episode on Device Identity, we encourage you to listen to it! Following up the conversation on device identity, Shannon talks all about managing devices using co-management and how device identity is related to management but mainly where the device lives does not affect how it is managed. Listen in on what it means to co-manage your Windows devices!
-------------------------------------------
Youtube Video Link: https://youtu.be/LtkPvqLvG9Y
-------------------------------------------
Documentation:
Windows 10 Device Management vs Device Identity
https://mrshannon.wordpress.com/2020/06/24/windows-10-device-management-vs-device-identity/
https://anchor.fm/blue-security-podcast/episodes/Say-Goodbye-to-Domain-Join-with-Special-Guest-Shannon-Fritz-erudur
Shannon Fritz: https://twitter.com/mrshannonfritz
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week's episode, Adam and Andy talk about the importance of the nomenclature we use in information security. They also talk about the perception of information security to those who are not in the field and how that can affect safety when it comes to red teaming.
-------------------------------------------
Youtube Video Link: https://youtu.be/nMQC5D_P4qY
-------------------------------------------
Documentation:
https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-governor-threatens-to-prosecute-local-journalist-for-finding-exposed-state-data/
https://boingboing.net/2021/12/30/reporter-likely-to-be-charged-for-using-view-source-feature-on-web-browser.html
https://arstechnica.com/information-technology/2019/09/iowa-officials-claim-confusion-over-scope-led-to-arrest-of-pen-testers/
https://abcnews.go.com/US/wireStory/charges-dropped-men-broke-iowa-courthouses-68651855
https://www.darkreading.com/edge-articles/why-red-teaming-while-black-can-be-risky
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week's episode, Adam and Andy talk about a fundamental important program for security defenders: asset management. It may not be the most exciting aspect of security but knowing what you have makes it a lot easier to protect and response to attacks.
-------------------------------------------
Youtube Video Link: https://youtu.be/Kui8x_lCYOk
-------------------------------------------
Documentation:
https://danielmiessler.com/blog/continuous-asset-management-security/
https://www.darkreading.com/vulnerabilities-threats/log4j-reveals-cybersecurity-s-dirty-little-secret
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week's episode, Adam and Andy give an update on Log4j/Log4Shell insights from the Google Security Team. They also look back on some of the vulnerabilities and cyberattacks from 2021 and discuss what's to come in 2022 for defenders.
-------------------------------------------
Youtube Video Link: https://youtu.be/3XLwP8GFS3M
-------------------------------------------
Documentation:
https://security.googleblog.com/
https://www.av-comparatives.org/tests/business-security-test-2021-august-november/#management-summary
https://news.microsoft.com/on-the-issues/tools-and-weapons/
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week's episode, Adam and Andy talk all about a healthy work life balance. With the pandemic still on-going and working from home or hybrid work environments looking like they are not going away, it's time to re-evaluate your boundaries and enforce them. Listen on what's worked for Adam and Andy as they put their mental health ahead of the hustle culture.
-------------------------------------------
Youtube Video Link: https://youtu.be/lK147aYqt4k
-------------------------------------------
Documentation:
https://hbr.org/2021/12/hybrid-tanked-work-life-balance-heres-how-microsoft-is-trying-to-fix-it
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week, Adam and Andy talk all about how to start and run a threat and vulnerability program at your company. From asset management, scanning, remediation, and validation, they go over what is involved and how to orchestrate the effort cross-function to avoid down time. A TVM program is a key pillar of your defense so if you do not have one or want to improve your current one, listen in!
-------------------------------------------
Youtube Video Link: https://youtu.be/qTvtvfY3CaQ
-------------------------------------------
Documentation:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-devices?view=o365-worldwide
https://www.tenable.com/products/nessus
https://www.qualys.com/
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week, Adam and Andy talk all about the Log4Shell vulnerability affecting the log4j Java library. They give an overview on how it works and how you as a security defender can secure your environment against it.
-------------------------------------------
Youtube Video Link: https://youtu.be/D9KBcIHOQzI
-------------------------------------------
Documentation:
https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
https://github.com/Neo23x0/log4shell-detector
https://twitter.com/shehackspurple/status/1469742868952584194
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week, Adam and Andy talk about a security champions program. This is a way to bolster the security culture and develop representatives in each business group to understand security initiatives and evangelize them for you at your company. It's also a way to have a inner ring of testers and even possible a talent pipeline. There's a lot to discuss so listen in!
-------------------------------------------
Youtube Video Link: https://youtu.be/sbnppJR-eMo
-------------------------------------------
Documentation:
https://www.darkreading.com/careers-and-people/how-to-implement-a-security-champions-program
-------------------------------------------
Contact Us:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
Twitch: https://www.twitch.tv/bluesecuritypod
-------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
-------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
From the publisher's feed

4,836 Listeners

9,613 Listeners

2,011 Listeners

1,644 Listeners

373 Listeners

374 Listeners

650 Listeners

1,027 Listeners

317 Listeners

65 Listeners

179 Listeners

73 Listeners

25 Listeners

137 Listeners

6 Listeners