Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • Celebrity investors, creator metrics, and Chrome extension compromise - ESW #389

    In this latest Enterprise Security Weekly episode, we explored some significant cybersecurity developments, starting with Veracode's acquisition of Phylum, a company specializing in detecting malicious code in open-source libraries. The acquisition sparked speculation that it might be more about Veracode staying relevant in a rapidly evolving market rather than a strategic growth move, especially given the rising influence of AI-driven code analysis tools. We also covered One Password's acquisition of a UK-based shadow IT detection firm, raising interesting questions about their expansion into access management. Notably, the deal involved celebrity investors like Matthew McConaughey and Ashton Kutcher, suggesting a trend where Hollywood influence intersects with cybersecurity branding.

    A major highlight was the Cyber Haven breach, where a compromised Chrome extension update led to stolen credentials. The attack was executed through a phishing campaign disguised as a Google policy violation warning. To their credit, Cyber Haven responded swiftly, pulling the extension within two hours and maintaining transparency throughout. This incident underscored broader concerns around the poor security of browser extensions, an issue that continues to be exploited due to lax marketplace oversight.

    We also reflected on Corey Doctorow's concept of "Enshittification," critiquing platforms that prioritize profit and engagement metrics over genuine user experiences. His decision to disable vanity metrics resonated, especially considering how often engagement numbers are inflated in corporate settings. The episode wrapped with a thoughtful discussion on how CISOs can say "no" more effectively, emphasizing "yes, but" strategies and the importance of consistency. We also debated the usability frustrations of "magic links" for authentication, arguing that simpler alternatives like passkeys or multi-factor codes could offer a better balance between security and convenience.

    Show Notes: https://securityweekly.com/esw-389

    55 min
  • Building a map of hacker history, one conversation at a time - Nathan Sportsman - ESW #389

    We're a fan of hacker lore and history here at Security Weekly. In fact, Paul's Security Weekly has interviewed some of the most notable (and notorious) personalities from both the business side of the industry and the hacker community.

    We're very excited to share this new effort to document hacker history through in-person interviews. The series is called "Where Warlocks Stay Up Late", and is the creation of Nathan Sportsman and other folks at Praetorian. The timing is crucial, as a lot of the original hackers and tech innovators are getting older, and we've already lost a few.

    References:

    • Check out the Where the Warlocks Stay Up Late website and subscribe to get notified of each episode as it is released
    • Check out the anthropological hacker map and relive your misspent youth!

    Show Notes: https://securityweekly.com/esw-389

    32 min
  • How threat-informed defense benefits each security team member - Frank Duff - ESW #389

    We're thrilled to have Frank Duff on to discuss threat-informed defense. As one of the MITRE folks that helped create MITRE ATT&CK and ATT&CK evaluations, Frank has been working on how best to define and communicate attack language for many years now. The company he founded, Tidal Cyber is in a unique position to both leverage what MITRE has built with ATT&CK and help enterprises operationalize it.

    Segment Resources:

    • Tidal Cyber website
    • Tidal Cyber Community Edition

    Show Notes: https://securityweekly.com/esw-389

    35 min
  • 2024 End-of-Year News and Wrapup - ESW #388

    As we wrap up the year, we have an honest discussion about how important security really is to the business. We discuss some of Katie's predictions for AppSec in 2025, as well as "what sucks" in security!

    Show Notes: https://securityweekly.com/esw-388

    31 min
  • D3FEND 1.0: A Milestone in Cyber Ontology - Peter Kaloroumakis - ESW #388

    Since D3FEND was founded to fill a gap created by the MITRE ATT&CK Matrix, it has come a long way. We discuss the details of the 1.0 release of D3FEND with Peter in this episode, along with some of the new tools they've built to go along with this milestone.

    To use MITRE's own words to describe the gap this project fills:

    "it is necessary that practitioners know not only what threats a capability claims to address, but specifically how those threats are addressed from an engineering perspective, and under what circumstances the solution would work"

    Segment Resources:

    • https://d3fend.mitre.org

    Show Notes: https://securityweekly.com/esw-388

    40 min
  • AWS does IR, credit card canarytokens, shared responsibility, phishing tests do harm - ESW #387

    This week, in the enterprise security news,

    NOTE: We didn't get to 2, 3, 5, or 7 due to some technical difficulties and time constraints, but we'll hit them next week! The show notes have been updated to reflect what we actually discussed this week: https://www.scworld.com/podcast-segment/13370-enterprise-security-weekly-387

    1. Snowflake takes security more seriously
    2. Microsoft takes security more seriously
    3. US Government takes telecom security more seriously
    4. Cleo Capital takes security more seriously
    5. EU's DORA takes effect soon
    6. Is phishing and security awareness training worthless?
    7. CISOs need financial literacy
    8. Supply chain firewall is basic but useful

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-387

    37 min
  • Pondering Portable Passwordless Passkeys in 2025 - Rew Islam - ESW #387

    In this segment, we discuss two new FIDO Alliance standards focused on credential portability. Specifically, if passwordless is going to catch on, we need to minimize friction and maximize usability. In practice, this means that passkeys must be portable!

    Rew Islam of Dashlane joins us to discuss the new standards and how they'll help us enter a new age of secure authentication, both for consumers and the enterprise.

    Segment Resources:

    • Elevating Passwordless Security With AWS Nitro
    • Synced Passkeys Will Be Portable
    • FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys

    Show Notes: https://securityweekly.com/esw-387

    36 min
  • The 2024 Cybersecurity Market Review - Mike Privette - ESW #387

    For our second year now, Mike Privette, from Return on Security and the Security, Funded newsletter joins us to discuss the year's highlights and what's to come in the next 12 months.

    In some ways, it has been a return to form for funding, though some casualties of a tough market likely had to seek acquisition when they might have otherwise raised another round and stayed independent a while longer. We'll cover some stats, talk 2025 IPO market, and discuss the likelihood of (already) being in another bubble, particularly with regards to the already saturated AI security market.

    It won't be all financial trends though, we'll discuss some of the technical market trends, whether they're finding market fit, and how ~50ish AI SOC startups could possibly survive in such a crowded space.

    Show Notes: https://securityweekly.com/esw-387

    37 min
  • Cybersecurity from Santa, office surveillance, Apple work/life balance issues, & more - ESW #386

    This week, in the enterprise security news,

    1. Funding and acquisition news slows down as we get into the "I'm more focused on holiday shopping season"
    2. North Pole Security picked an appropriate time to raise some seed funding
    3. Breaking news, it's still super easy to exfiltrate data
    4. The Nearest Neighbor Attack
    5. Agentic Security is the next buzzword you're going to be tired of soon
    6. Frustrations with separating work from personal in the Apple device ecosystem
    7. We check in on the AI SOC and see how it's going
    8. Office surveillance technology gives us the creeps

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-386

    50 min
  • Stopping 0day Exploits Doesn't Require AI or Superhuman Speed - Rob Allen - ESW #386

    When focused on cybersecurity through a vulnerability management lens, it's tempting to see the problem as a race between exploit development and patching speed. This is a false narrative, however. While there are hundreds of thousands of vulnerabilities, each requiring unique exploits, the number of post-exploit actions is finite. Small, even.

    Although Log4j was seemingly ubiquitous and easy to exploit, we discovered the Log4Shell attack wasn't particularly useful when organizations had strong outbound filters in place.

    Today, we'll discuss an often overlooked advantage defenders have: mitigating controls like traffic filtering and application control that can prevent a wide range of attack techniques.

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Show Notes: https://securityweekly.com/esw-386

    33 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…