Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • Discovering a common Salesforce mistake launched this security professional's career - Aaron Costello - ESW #379

    Aaron was already a skilled bug hunter and working at HackerOne as a triage analyst at the time. What he discovered can't even be described as a software bug or a vulnerability. This type of finding has probably resulted in more security incidents and breaches than any other category: the unintentional misconfiguration.

    There's a lot of conversation right now about the grey space around 'shared responsibility'. In our news segment later, we'll also be discussing the difference between secure design and secure defaults. The recent incidents revolving around Snowflake customers getting compromised via credential stuffing attacks is a great example of this. Open AWS S3 buckets are probably the best known example of this problem. At what point is the service provider responsible for customer mistakes? When 80% of customers are making expensive, critical mistakes? Doesn't the service provider have a responsibility to protect its customers (even if it's from themselves)?

    These are the kinds of issues that led to Aaron getting his current job as Chief of SaaS Security Research at AppOmni, and also led to him recently finding another common misconfiguration - this time in ServiceNow's products. Finally, we'll discuss the value of a good bug report, and how it can be a killer addition to your resume if you're interested in this kind of work!

    Segment Resources:

    • Aaron's blog about the ServiceNow data exposure.
    • The ServiceNow blog, thanking AppOmni for its support in uncovering the issue.

    Show Notes: https://securityweekly.com/esw-379

    32 min
  • Community Knowledge Sharing with CyberNest - Ben Siegel - ESW #379

    For this interview, Ben from CyberNest joins us to talk about one of my favorite subjects: information sharing in infosec. There are so many amazing skills, tips, techniques, and intel that security professionals have to share. Sadly, a natural corporate reluctance to share information viewed as privileged and private has historically had a chilling effect on information sharing.

    We'll discuss how to build such a community, how to clear the historical hurdles with information sharing, and how to monetize it without introducing bias and compromising the integrity of the information shared.

    Show Notes: https://securityweekly.com/esw-379

    29 min
  • Secure the Browser & Vulnerability and Exposure Management - Brian Contos, Neko Papez - ESW #378

    The way we use browsers has changed, so has the way we need to secure them. Using a secure enterprise browser to execute content away from the endpoint, inside a secure cloud browser is a dramatically more effective and cost-effective approach to protect users and secure access.

    This segment is sponsored by Menlo Security. Visit https://securityweekly.com/menloisw to learn more about them!

    Sevco is a cloud-native vulnerability and exposure management platform built atop asset intelligence to enable rapid risk prioritization, mitigation, validation, and metrics.

    Segment Resources: Customer Testimonials: https://www.sevcosecurity.com/testimonials/ Product Videos: https://www.sevcosecurity.com/sevcoshorts/

    This segment is sponsored by Sevco Security. Visit https://securityweekly.com/sevcoisw to learn more about them!

    Show Notes: https://securityweekly.com/esw-378

    32 min
  • Cybersecurity Career Paths: from touring musician to purple teaming at Meta - Jayson Grace - ESW #378

    Our latest in a series of interviews discussing cybersecurity career paths, today we talk to Jayson Grace his path into cybersecurity and his experience building red teams at national labs and purple teams at Meta. We also talk about his community impact, giving talks and building open source tools. Jayson just left Meta for an AI safety startup named Dreadnode, which we'll discuss as well.

    Segment Resources:

    • CyberSecEval 3: Advancing the Evaluation of Cybersecurity Risks and Capabilities in Large Language Models
    • The [TTPForge] (https://github.com/facebookincubator/TTPForge) is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).
    • ForgeArmory provides TTPs that can be used with the TTPForge
    • Wired, by Lily Hay Newman: Facebook's 'Red Team X' Hunts Bugs Beyond the Social Network's Walls
    • MOSE (Master Of SErvers) is a post exploitation tool for configuration management servers.
    • BSides SF 2024 - Beyond Quick Cash: Rethinking Bug Bounties for Greater Impact
    • BSides LV 2023 - [GF - Enemy Within: Leveraging Purple Teams for Advanced Threat Detection & Prevention - https://www.youtube.com/watch?v=-MT0tNi2vvc

    Show Notes: https://securityweekly.com/esw-378

    36 min
  • Cybersecurity best practices are the worst, AI indegestion, real time doxxing - ESW #378

    This week in the enterprise security news, we've got:

    1. Torq, Tamnoon, and Defect Dojo raise funding
    2. Checkmarx acquires ZAP
    3. Commvault acquires Clumio
    4. Would you believe San Francisco is NOT the most funded metro area for cybersecurity?
    5. Auto-doxxing Smart glasses are now possible
    6. Meta gets fined $100M for storing plaintext passwords
    7. AI coding assistants might not be living up to expectations
    8. Worst Practices
    9. Dumpster fires and truth bombs

    All that and more, on this episode of Enterprise Security Weekly!

    Show Notes: https://securityweekly.com/esw-378

    1 hr 8 min
  • Quantum threats, SOC automation, funding trends - ESW #377

    In the Enterprise News, the hosts discuss various trends and challenges in the cybersecurity landscape, including the evolution of terminology, funding trends, the emergence of new startups, and the impact of AI on security practices. They also explore the challenges faced by CISOs, the importance of humor in the industry, and the future of quantum readiness. The conversation highlights the need for clarity in cybersecurity messaging and the potential for consolidation in the market.

    Show Notes: https://securityweekly.com/esw-377

    45 min
  • Oh the Places You'll Go (in Cybersecurity) - Jason Shockey - ESW #377

    We've been hearing a lot lately about how the talent gap in cybersecurity is much more complex than some folks have been making it out to be. While making six figures after going through a six week boot camp might be overselling the cybersecurity job market a bit, it is definitely a complex space with lots of opportunities.

    Fortunately, we have folks building passion projects like My Cyber Path. When Jason transitioned into cyber from the military, he took note of the path he took. He also noticed how different the path was for many of his peers. Inspired by NIST NICE and other programs designed to help folks get a start in cyber, he created My Cyber Path.

    My Cyber Path has a very organized approach. There are 12 paths outlined, which fall into 4 main areas. After taking a personality test, this tool suggests the best paths for you. Hmmm, this sounds a lot like the sorting hat in Harry Potter, and there are 4 "houses" you could get put into... coincidence?

    Segment Resources: My Cyber Path has a free account where people can get matched to a cybersecurity work role based on their interests and personality traits and get access to free areas in the platform without having to save a credit card.

    • https://www.mycyberpath.com/
    • https://www.mycyberpath.com/auth/register

    Show Notes: https://securityweekly.com/esw-377

    34 min
  • SIEM: Shakeup in Event Management - What's Happening in the SIEM market today? - Seth Goldhammer - ESW #377

    The SIEM market has undergone some significant changes this summer. This is a great opportunity to talk about the current state of SIEM! In this conversation, we'll discuss:

    • market changes and terminology: security analytics, data lakes, SIEM
    • what is SOAR's role in the current SIEM market?
    • machine learning and generative AI's role
    • strategies for implementing a SIEM
    • common mistakes that still lead to SIEMs becoming shelfware
    • and much more!

    Both Seth and Adrian have a long history when it comes to SIEMs, so this conversation will be packed with anecdotes, stories, and lessons learned!

    This segment is sponsored by Graylog. Visit https://securityweekly.com/graylog to learn more about them!

    Show Notes: https://securityweekly.com/esw-377

    43 min
  • Cybersecurity: is the talent gap a myth? Is the industry delusional? - ESW #376

    This week, the cybersecurity industry's most basic assumptions under scrutiny. Following up our conversation with Wolfgang Goerlich, where he questions the value of phishing simulations, we discuss essays that call into question:

    • the maturity of the industry
    • the supposed "talent gap" with millions of open jobs despite complaints that this industry is difficult to break into
    • cybersecurity's 'delusion' problem

    Also some whoopsies:

    • researchers accidentally take over a TLD
    • When nearly all your customers make the same insecure configuration mistakes, maybe it's not all their fault, ServiceNow finds out

    Fortinet has a breach, but is it really accurate to call it that?

    Some Coalfire pentesters that were arrested in Iowa 5 years ago share some unheard details about the event, and how it is still impacting their lives on a daily basis five years later.

    The news this week isn't all negative though! We discuss an insightful essay on detection engineering for managers from Ryan McGeehan is a must read for secops managers.

    Finally, we discuss a fun and excellent writeup on what happens when you ignore the integrity of your data at the beginning of a 20 year research project that resulted in several bestselling books and a Netflix series!

    Show Notes: https://securityweekly.com/esw-376

    46 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…