
Sign up to save your podcasts
Or


Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam delve into a significant surge in external ID charges experienced by a customer, leading to the discovery of an international revenue share fraud attack. They discuss the mechanics of this fraud, how it exploits telecommunication systems, and the importance of monitoring and mitigating such attacks. The conversation emphasizes the need for organizations to implement security measures, including web application firewalls and billing alerts, to prevent financial losses from similar attacks. The episode concludes with key takeaways and recommendations for enhancing security in external identity management.
----------------------------------------------------
YouTube Video Link: https://youtu.be/6jXBULGx5aA
----------------------------------------------------
Documentation:
https://learn.microsoft.com/en-us/entra/architecture/deployment-external-operations
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mfa-telephony-fraud
https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-region-code-opt-in
https://learn.microsoft.com/en-us/entra/external-id/customers/concept-multifactor-authentication-customers#sms-pricing-tiers-by-countryregion
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam delve into a significant surge in external ID charges experienced by a customer, leading to the discovery of an international revenue share fraud attack. They discuss the mechanics of this fraud, how it exploits telecommunication systems, and the importance of monitoring and mitigating such attacks. The conversation emphasizes the need for organizations to implement security measures, including web application firewalls and billing alerts, to prevent financial losses from similar attacks. The episode concludes with key takeaways and recommendations for enhancing security in external identity management.
----------------------------------------------------
YouTube Video Link: https://youtu.be/6jXBULGx5aA
----------------------------------------------------
Documentation:
https://learn.microsoft.com/en-us/entra/architecture/deployment-external-operations
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mfa-telephony-fraud
https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-region-code-opt-in
https://learn.microsoft.com/en-us/entra/external-id/customers/concept-multifactor-authentication-customers#sms-pricing-tiers-by-countryregion
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam delve into the recent tensions between the U.S. government and the private tech sector regarding artificial intelligence. They discuss the clash between Anthropic and the Department of Defense over AI safety guardrails, the implications of designating Anthropic as a supply chain risk, and the broader impact on the defense sector. The conversation also touches on the importance of AI guardrails, the dangers of autonomous AI systems, and the ethical considerations surrounding AI in mental health. The hosts conclude by exploring the competitive landscape of AI and the potential for multiple winners in the field.
----------------------------------------------------
YouTube Video Link: https://youtu.be/rnUsvQbQkQQ
----------------------------------------------------
Documentation:
https://www.npr.org/2026/02/27/nx-s1-5729118/trump-anthropic-pentagon-openai-ai-weapons-ban
https://www.theverge.com/ai-artificial-intelligence/882005/amazon-blames-human-employees-for-an-ai-coding-agents-mistake
https://www.newsweek.com/ai-chooses-nuclear-option-in-95-of-war-simulations-11589197
https://www.fastcompany.com/91497841/meta-superintelligence-lab-ai-safety-alignment-director-lost-control-of-agent-deleted-her-emails
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam delve into the recent tensions between the U.S. government and the private tech sector regarding artificial intelligence. They discuss the clash between Anthropic and the Department of Defense over AI safety guardrails, the implications of designating Anthropic as a supply chain risk, and the broader impact on the defense sector. The conversation also touches on the importance of AI guardrails, the dangers of autonomous AI systems, and the ethical considerations surrounding AI in mental health. The hosts conclude by exploring the competitive landscape of AI and the potential for multiple winners in the field.
----------------------------------------------------
YouTube Video Link: https://youtu.be/rnUsvQbQkQQ
----------------------------------------------------
Documentation:
https://www.npr.org/2026/02/27/nx-s1-5729118/trump-anthropic-pentagon-openai-ai-weapons-ban
https://www.theverge.com/ai-artificial-intelligence/882005/amazon-blames-human-employees-for-an-ai-coding-agents-mistake
https://www.newsweek.com/ai-chooses-nuclear-option-in-95-of-war-simulations-11589197
https://www.fastcompany.com/91497841/meta-superintelligence-lab-ai-safety-alignment-director-lost-control-of-agent-deleted-her-emails
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode, Adam and Andy explore the security challenges and risks associated with OpenClaw, an AI assistant with extensive system access, highlighting recent incidents, vulnerabilities, and best practices for security in AI development.
----------------------------------------------------
YouTube Video Link: https://youtu.be/TGAbhPQa9iw
----------------------------------------------------
Documentation:
https://www.zdnet.com/article/openclaw-moltbot-clawdbot-5-reasons-viral-ai-agent-security-nightmare/
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode, Adam and Andy explore the security challenges and risks associated with OpenClaw, an AI assistant with extensive system access, highlighting recent incidents, vulnerabilities, and best practices for security in AI development.
----------------------------------------------------
YouTube Video Link: https://youtu.be/TGAbhPQa9iw
----------------------------------------------------
Documentation:
https://www.zdnet.com/article/openclaw-moltbot-clawdbot-5-reasons-viral-ai-agent-security-nightmare/
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam discuss significant cybersecurity incidents involving Notepad++ and 7-Zip, highlighting the vulnerabilities in open-source software and the importance of enterprise software management. They emphasize the need for ad blockers, the challenges of identifying legitimate software downloads, and the necessity of implementing robust security measures in organizations.
----------------------------------------------------
YouTube Video Link: https://youtu.be/t6ERCYqFHFU
----------------------------------------------------
Documentation:
https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/
https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
https://msendpointmgr.com/2025/10/04/taming-browser-extensions-with-intune/
https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam discuss significant cybersecurity incidents involving Notepad++ and 7-Zip, highlighting the vulnerabilities in open-source software and the importance of enterprise software management. They emphasize the need for ad blockers, the challenges of identifying legitimate software downloads, and the necessity of implementing robust security measures in organizations.
----------------------------------------------------
YouTube Video Link: https://youtu.be/t6ERCYqFHFU
----------------------------------------------------
Documentation:
https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/
https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
https://msendpointmgr.com/2025/10/04/taming-browser-extensions-with-intune/
https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam discuss the evolving landscape of cybersecurity training, particularly in light of generative AI and the limitations of traditional phishing simulations. They argue that expecting employees to outsmart sophisticated cybercriminals is unrealistic and emphasize the need for a robust security architecture that assumes clicks will happen. The conversation then shifts to recent updates regarding Microsoft Intune Suite, including pricing changes and new features, highlighting the importance of adapting to the changing cybersecurity environment.
----------------------------------------------------
YouTube Video Link: https://youtu.be/KzT_wOyC4-w
----------------------------------------------------
Documentation:
https://www.linkedin.com/posts/james-haynes_im-going-to-say-something-that-might-get-activity-7417944035304079360-s1D_/
https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam discuss the evolving landscape of cybersecurity training, particularly in light of generative AI and the limitations of traditional phishing simulations. They argue that expecting employees to outsmart sophisticated cybercriminals is unrealistic and emphasize the need for a robust security architecture that assumes clicks will happen. The conversation then shifts to recent updates regarding Microsoft Intune Suite, including pricing changes and new features, highlighting the importance of adapting to the changing cybersecurity environment.
----------------------------------------------------
YouTube Video Link: https://youtu.be/KzT_wOyC4-w
----------------------------------------------------
Documentation:
https://www.linkedin.com/posts/james-haynes_im-going-to-say-something-that-might-get-activity-7417944035304079360-s1D_/
https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: [email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: [email protected]
From the publisher's feed

4,837 Listeners

9,616 Listeners

2,010 Listeners

1,645 Listeners

373 Listeners

374 Listeners

651 Listeners

1,028 Listeners

317 Listeners

65 Listeners

179 Listeners

73 Listeners

25 Listeners

138 Listeners

5 Listeners