Enterprise Security Weekly (Video)

Enterprise Security Weekly (Video)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store

Enterprise Security Weekly (Video) episodes

  • AI and Ransomware dominate the news cycles - ESW #341

    Nine out of the ten funding articles mention AI - they're either using it in their products, or protecting AI use cases (particularly GenAI and LLM use).

    We discuss Broadcom's closing of the VMware acquisition, how they operate similarly to private equity firms, and how it's mostly bad news for VMware employees and customers.

    Some weird legal cases this week: Binance's founder and CEO pleads guilty to money laundering charges, a cybersecurity company's COO pleads guilty to attacking hospitals to generate sales leads, and Hacking Team's founder is arrested for attempted murder!

    We devote a chunk of time to discussing the huge rise in ransomware activity, and close out the show with a squirrel story on the tiny Pacific island nation of Tokelau, and how the .tk domain has destroyed its reputation, and nearly the nation itself.

    Show Notes: https://securityweekly.com/esw-341

    45 min
  • Cybercrime is booming: understanding why and what we can do about it - Keith Jarvis - ESW #341

    As with any category of trends, the success rate of cybercrime ebbs and flows. As Russia seems be a safe haven for cybercriminals, it seemed for a while that the war in Ukraine might disrupt this activity. It did, but only for a short while.

    Keith Jarvis walks us through the latest types, tactics, and trends in cybercrime. Secureworks' latest State of the Threat report reveals a disturbing dichotomy: how is it we understand our adversaries' so well, but continue to fail to stop them? In this interview, we aim to understand what needs to happen to tilt the odds a bit back in our favor.

    Segment Resources:

    • Secureworks State of the Threat Report
    • Press Release

    Show Notes: https://securityweekly.com/esw-341

    42 min
  • Non-profits need security too - Kelley Misata - ESW #341

    While non-profit doesn't mean "no budget" when it comes to cybersecurity, a lot of smaller to mid-sized non-profits operate on a shoestring, with little to no money for cybersecurity talent or spending. This is where Sightline Security steps in. Sightline's founder and CEO, Kelley Misata joins us today to explain how her own non-profit helps other non-profits improve their cybersecurity posture.

    Show Notes: https://securityweekly.com/esw-341

    43 min
  • New security startups, Stamos and Krebs go to SentinelOne, NY takes cyber seriously - ESW #340

    Finally, in the enterprise security news,

    1. Lots of new security startups with early stage funding
    2. SentinelOne picks up Chris Krebs and Alex Stamos's consulting firm
    3. PE firm picks up ActiveState - a company I haven't thought about since I last downloaded ActiveState Perl 1000 years ago
    4. Microsoft announces the limited release of Security Copilot
    5. Semgrep releases a secrets scanner
    6. AGI predicted to come much sooner than you might expect
    7. NY State doubles down on cybersecurity regulations to protect its hospitals
    8. the young hackers behind Mirai, one of the biggest botnets ever
    9. Ransomware groups snitch on businesses to the SEC

    Show Notes: https://securityweekly.com/esw-340

    38 min
  • Five Lessons Learned From Okta's Customer Support System Breach - ESW #340

    We regularly cover significant breaches on this podcast, but it is rare that we have enough information about a major breach to cover in enough detail to devote an entire segment to. Today, we dive into lessons learned from the breach of Okta's customer support system that targeted some other major security vendors.

    This is part of a troubling trend, where the target of an attack only serves as a jumping off point to other organizations. China's 2023 attack of Microsoft is an example of this. It was easier to attack Microsoft 365, one of the world's largest business SaaS platforms, than to go after each of the 25 individual targets these Chinese actors needed access to.

    Traditionally, we've thought of lateral movement as something that happens within a network segment, or even within a single organization. Now, we're seeing lateral movement between SaaS platforms, between clouds, from third party vendors to customer, and even from open source project to open source adopters.

    In this segment, we'll cover five key lessons learned from Okta's breach, from information shared by Okta and three of its customers: 1Password, Cloudflare, and BeyondTrust.

    1. Protect Your Session Tokens
    2. Monitor for Unusual Behavior
    3. SaaS Vendors Are Common Targets
    4. Zero Trust Principles Work
    5. MFA Isn't a Binary (on or off) Control

    Segment Resources

    • https://www.valencesecurity.com/resources/blogs/five-lessons-learned-from-oktas-support-site-breach

    Show Notes: https://securityweekly.com/esw-340

    48 min
  • Exploring the Intersection of Security for Edge Computing and Endpoint - Theresa Lanowitz, Mani Keerthi Nagothu - ESW #340

    Once again, Theresa Lanowitz joins us to discuss Edge Computing, but with a twist this time, as Mani Keerthi Nagotu from SentinelOne joins us as well! As a field CISO, Mani knows all too well the struggles security leaders are going through, given the current market and threat landscape:

    • Maybe not less budget, but more pressure to produce results and justify spending
    • Security leaders being held personally accountable for performance
    • Potential layoffs, and the need to achieve the same goals with less labor and tool overhead

    Segment Resources

    • https://cybersecurity.att.com/insights-report

    This segment is sponsored by AT&T Cybersecurity. Visit https://securityweekly.com/attcybersecurity to learn more about them!

    Show Notes: https://securityweekly.com/esw-340

    46 min
  • Palo Alto buys Talon, the changing world of security exits, 6 Qs to ask your CISO - ESW #339

    During the news today, we went deep down the rabbithole of discussing security product efficacy. Adrian still doesn't believe in enterprise browsers beyond Google Chrome, but can't deny that Talon got a pretty favorable exit considering the state of the market. We see the first major exit for cybersecurity insuretechs, and discuss a few notable funding rounds.

    We discuss Kelly Shortridge's essay on the origins and nature of the term "security" and what it means. Stephen Schmidt suggests 6 questions every board should ask their CISO, we explore Cyentia Labs' meta analysis of MITRE ATT&CK techniques, and Phil Venables shares some hilarious takes on infosec stereotypes.

    Show Notes: https://securityweekly.com/esw-339

    1 hr 10 min
  • Security Chaos Engineering: Realigning the Security Industry - Kelly Shortridge - ESW #339

    We've reached an inflection point in security. There are a handful of organizations regularly and successfully stopping cyber attacks. Most companies haven't gotten there, however. What separates these two groups? Why does it seem like we're still failing as an industry, despite seeming to collectively have all the tools, intel, and budget we've asked for?

    Kelly Shortridge has studied this problem in depth. She has created tools (https://www.deciduous.app/), and written books (https://www.securitychaoseng.com/) to help the community approach security challenges in a more logical and structured way. We'll discuss what hasn't worked for infosec in the past, and what Kelly thinks might work as we go into the future.

    Show Notes: https://securityweekly.com/esw-339

    48 min
  • The State of Internet Attack Surface - Aidan Holland - ESW #339

    Today, we discuss the state of attack surface across the Internet. We've known for decades now that putting an insecure service on the public Internet is a recipe for disaster, often within minutes. How has this knowledge changed the publicly accessible Internet? We find out when we talk to Censys's Aidan Holland today.

    Show Notes: https://securityweekly.com/esw-339

    44 min

About Enterprise Security Weekly (Video)

From the publisher's feed

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts:…