
Sign up to save your podcasts
Or


This week, Adam and Andy talk about cloud application security brokers (CASB). The podcast is focused more around Microsoft Cloud App Security but the concepts and use cases can be applied to any CASB solution.
----------------------------------------------
Youtube Video Link: https://youtu.be/j43MFpxMsqE
----------------------------------------------
Documentation
MCAS Ninja Training:
https://techcommunity.microsoft.com/t5/microsoft-security-and/the-microsoft-cloud-app-security-mcas-ninja-training-is-here/ba-p/1877343
----------------------------------------------
Contact: Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
----------------------------------------------
Andy Jaw Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------
Adam Brewer Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week, Adam and Andy talk about password managers. They discuss on password managers can protect you from phishing attacks, pros/cons of storing your TOTP key within your vault, and compare three different popular password managers on the market: Lastpass, 1Password, and BitWarden.
----------------------------------------------
Youtube Video Link: https://youtu.be/op9TGKlRZDY
----------------------------------------------
Documentation
https://blog.1password.com/totp-and-1password/
https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-more-from-your.html
https://www.ghacks.net/2013/09/17/can-now-use-email-aliases-outlook-com/
----------------------------------------------
Contact: Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
----------------------------------------------
Andy Jaw Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------
Adam Brewer Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week, Adam and Andy talk about a Red Team/Pentesting tool called EvilGinx. They explain how this tool works and how cyber-criminals can use it to bypass MFA enabled accounts. Most importantly, they provide several ways to mitigate against this using enterprise driven phishing education campaigns, security awareness training, and device-based conditional access.
This week, Adam and Andy go over modern device management. They discuss how to use device based conditional access to make access decisions on corporate or personal devices spanning different operating systems in the modern "work from home" and post-COVID world.
----------------------------------------------
YouTube Video Link:
https://youtu.be/s46ZhXnngjg
----------------------------------------------
Documentation:
Windows Autopilot
https://docs.microsoft.com/en-us/mem/autopilot/windows-autopilot
Apple Business Manager
https://support.apple.com/guide/apple-business-manager/what-is-apple-business-manager-apdd344cdd9d/web
Android Enterprise Enrollment
https://www.android.com/enterprise/enrollment/
Android Device Manager Deprecation
https://www.blog.google/products/android-enterprise/da-migration/
JAMF Apple Device Management
https://www.jamf.com
----------------------------------------------
Contact:
Website: http://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Instagram: https://www.instagram.com/bluesecuritypodcast/
Facebook: https://www.facebook.com/bluesecpod
----------------------------------------------
Andy Jaw
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
This week, Adam and Andy speak with Stealthbits security strategist, Gavin Aston. Gavin wrote the blog "Maersk, me & notPetya" and brings a unique percepective to information security defense as someone who's survived a ransomware attack.
Youtube Video Link
Documentation:
Maersk, me & notPetya
Protecting Microsoft 365 from on-premises attacks
Contact:
Gavin Aston
Twitter: @gvnshtn
Andy Jaw
Twitter: @ajawzero
LinkedIn: andyjaw
Email: [email protected]
Adam Brewer
Twitter: @ajbrewer
LinkedIn: adambrewer
Email: [email protected]
----------------------------------------------
Twitter: @bluesecuritypod
Instagram: @bluesecuritypodcast
Facebook: @bluesecpod
This week, Adam and Andy speak with application security guru, Tanya Janca, author of Alice and Bob learn Application Security. It was an amazing conversation where they touched on secure app design practices, password requirements, and infosec industry mentorship and education.
Youtube Video Link
Documentation:
Alice and Bob learn Application Security
We Hack Purple Academy
We Hack Purple Youtube/Podcast
Contact:
Tanya Janca
Twitter: @shehackspurple
LinkedIn: tanya-janca
Andy Jaw
Twitter: @ajawzero
LinkedIn: andyjaw
Email: [email protected]
Adam Brewer
Twitter: @ajbrewer
LinkedIn: adambrewer
Email: [email protected]
----------------------------------------------
Twitter: @bluesecuritypod
Instagram: @bluesecuritypodcast
Facebook: @bluesecpod
This week, Adam and Andy go over some news about Microsoft Defender for Identity and Intel's new CPU ransomware protection. There was also some news about Whatsapp's new privacy policy. Adam and Andy dive into a comparison of the most popular secure messaging apps including an exploit that would affect all secure messengers.
Documentation:
Whatsapp's Updated Privacy Policy
Signal Messenger
Threem Messenger
Secure Messaging Apps Comparison
Contact:
Twitter: @bluesecuritypod
Instagram: @bluesecuritypodcast
Andy Jaw
Twitter: @ajawzero
LinkedIn: andyjaw
Email: [email protected]
Adam Brewer
Twitter: @ajbrewer
LinkedIn: adambrewer
Email: [email protected]
This week, Adam and Andy revisit some more guidance that has come out about Sunburst/Solarigate since the initial breach. Additionally, they share some thoughts about this week's insurrection at the US Capitol and the cybersecurity implications. Finally, with a Biden administration and a Democratic controlled government, Andy and Adam speculate on what might be taken up as priority when it comes to tech policy.
Documentation:
Microsoft Solarigate Resource Center
Using Splunk to Detect Sunburst Backdoor
Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers
Using Microsoft 365 Defender to protect against Solorigate
M365 advanced hunting queries
Understanding "Solorigate"'s Identity IOCs - for Identity Vendors and their customers
Protecting Microsoft 365 from on-premises attacks
Contact:
Twitter: @bluesecuritypod
Instagram: @bluesecuritypodcast
Andy Jaw
Twitter: @ajawzero
LinkedIn: andyjaw
Email: [email protected]
Adam Brewer
Twitter: @ajbrewer
LinkedIn: adambrewer
Email: [email protected]
Happy New Year! To ring in the new year, this week's episode focuses on parents who are working from home while having to help home school their kids as well. Adam and Andy go through a lot of tips and tricks that will help secure home networks, devices, and cloud accounts.
Documentation:
Setup OpenDNS
Quad9
Disney Circle
Eero Wifi
How to change your wireless router's admin password
3-router method (Stacking routers for security)
Ubiquiti Unifi
Apple's Data Access when personal safety is at risk
Microsoft Families
Apple Families
Google Families
Contact:
Twitter: @bluesecuritypod
Instagram: @bluesecuritypodcast
Andy Jaw
Twitter: @ajawzero
LinkedIn: andyjaw
Email: [email protected]
Adam Brewer
Twitter: @ajbrewer
LinkedIn: adambrewer
Email: [email protected]
This holiday week, Adam and Andy give you some advice on how to spin up your own virtual machine lab and dev environment. They go through SaaS applications that have free dev environments as well as tools to use to manage VM's. They also give tips on what you can do with that lab environment from testing policies to managing devices in Intune and even learning about tools like Mimikatz and John the Ripper.
Documentation:
Lab Building Guide: Virtual Active Directory
Script to spin up AD controllers quickly
Microsoft Developer Subscription
Android Images
Andy Jaw
Twitter: @ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Adam Brewer
Twitter: @ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
From the publisher's feed

4,836 Listeners

9,613 Listeners

2,011 Listeners

1,644 Listeners

373 Listeners

374 Listeners

650 Listeners

1,027 Listeners

317 Listeners

65 Listeners

179 Listeners

73 Listeners

25 Listeners

137 Listeners

6 Listeners