
Sign up to save your podcasts
Or


Flashpoint's Ian Gray and Max Aliapoulios discuss trends happening inside illicit underground online markets where everything from credit cards and personal information, to drugs and other physical goods, are sold. Ian and Max help characterize these markets, the impact of law enforcement and self-imposed shutdowns on the overall landscape, the ecosystem supporting these markets, as well as trends we can expect to see formulating in the coming months.
Chris Cochran, threat intelligence lead at a media services company, shares his personal and professional journey to a career in information security and intelligence. Cochran, who co-hosts the secdevops.ai podcast, shares his unique career path, one that spans the military, public service, a startup, and now a major enterprise. He's an innovator in developing a culture inside the enterprise that embraces security, doing so by introducing unstructured play into the environment with a large degree of success. In the podcast, he describes how play helps train teammates, increase visibility, and remediate security gaps.
Longtime Fortune 100 CISO and current managing partner at DelveRisk Anthony Johnson discusses what it takes to drive information security culturally inside the enterprise and smaller organizations. Anthony explains the trends that helped to elevate security to a C-suite and board-level discussion, how employees must be an extension of the security operation, and the consequences of current security skill shortage in the industry.
In this episode of the Collective Intelligence Podcast, recorded during the recent Black Hat conference in Las Vegas, Alexander Klimburg of the The Hague Centre for Strategic Studies discusses how the East—Russia and China specifically—don't view cyber conflict and cyberwar as a battle for critical infrastructure, as the West might. Instead, regime change is the nightmare scenario in these regions, Klimburg said, adding that Russia is attempting to extend to the internet the Communist tradition of the information sphere being the dominant sphere of decision making. By changing the multistakeholder governance model to a multilateral one, Russia believes it would have more stable control over cyber.
Jeffrey Smith, managing partner of Cyber Risk Underwriters, explains why the adoption of cyber insurance is turning a corner and becoming a constant fixture inside enterprises, smaller companies, and even managed security service providers. Smith discusses how cyber insurance products options are improving, with input from a number of prominent security researchers and managers. He also discusses what current cyber insurance products look like, what industries are gravitating toward adoption, and why he believes it will someday soon be on par with standard insurance businesses currently buy as a baseline.
Security researcher Mathy Vanhoef discusses two new vulnerabilities he and colleague Eyal Ronen discovered in the Dragonfly cryptographic handshake in the WPA3 WiFi protocol. The vulnerabilities, nicknamed Dragonblood, are the continuation of research and additional security flaws in the protocol the two disclosed in April.
The bugs include side-channel timing attacks and downgrade attacks that allow a hacker to leak memory from a client connection to a wireless access point and decrypt passwords in offline dictionary attacks. The Dragonblood attacks bypass mitigations in WPA3 designed to blunt these types of offline attacks.
The vulnerabilities are design and implementation flaws that are being addressed by the WiFi Alliance. Vanhoef discusses his and Ronen's interactions with the group. He also looks back at the KRACK attack he developed three years ago against WPA2.
LAS VEGAS—Akamai Director of Security Strategy Tony Lauro table-sets the annual Black Hat hacker conference with a wide-ranging discussion about some of the threats facing private- and public-sector organizations.
Lauro discusses the changing motivations of threat actors, and describes the challenges facing defenders stuck between hackers seeking profit, social change, or those motivated by espionage.
He also digs into the shifting trend of targeted ransomware attacks, how attackers are leveraging bots to carry out credential-stuffing attacks at scale to perform account takeover attacks, and how sharing of threat data across industries needs to move beyond only industry-specific groups.
Eric Lackey of Flashpoint discusses the risk to businesses and the public sector posed by privileged insiders. The insider threat—characterized by a rogue or disgruntled employee, or an accidental disclosure by an employee—requires a mix of technology and understanding of human nature to properly mitigate the risk to the bottom line. Lackey covers common risks posed by insiders, mistakes made by defenders trying to mitigate insider threats, and what it takes to successfully develop and implement an insider threat program.
Digita Security Chief Research Officer Patrick Wardle discusses a macOS Mojave vulnerability he recently disclosed whereby an attacker can abuse synthetic clicks allowed by the OS to spy on users, access private data, or install additional malicious code.
Wardle disclosed the vulnerability during the Objective By The Sea conference in Monte Carlo earlier this month. He previously had privately disclosed the issue to Apple, which has yet to patch it, but has introduced a temporary mitigation.
The bug bypasses additional security protections Apple introduced in Mojave that specifically ban synthetic clicks without the user physically clicking through and permitting this action.
Flashpoint Director of Security Research Allison Nixon discusses SIM swap, a lucrative form of fraud that is turning profits for criminals and quickly gaining more attention from the security research community and law enforcement alike.
In this podcast, Allison describes the machinations of a SIM swap scheme, starting with the criminals who cook up these capers and often recruit insiders at a telecommunications company to take part in these scams, to the places where the industry is coming up short in defending against it.
From the publisher's feed