Exploring Information Security - Exploring Information Security

Exploring Information Security - Exploring Information Security

By Timothy De BlockTechnology
Download on the App Store

Exploring Information Security - Exploring Information Security episodes

  • [RERELEASE] How to find vulnerabilites

    In this susceptible edition of the Exploring Information Security podcast, Samy Kamkar joins me to discuss how to find vulnerabilities. This is a RERELEASE EPISODE.

    Samy (@samykamkar) shouldn't need too much of an introduction to most people. He's been in the news for hacking garage doors, credit cards, cars, and much much more. Samy likes to hack things and has a knack for finding vulnerabilities in everything from locked machines to wireless doorbells. His site has the full list of vulnerabilities as well as videos and press appearances. Which made him the perfect guess for talking about how to find vulnerabilities.

    In this episode we discuss:

    • What got him started in looking for vulnerabilities

    • What is a vulnerability

    • What skills are necessary for finding vulnerabilities

    • How he decides his next project

    • The steps to finding vulnerabilities

    • What he does when he discovers a vulnerability

    • How long the process takes

    How to find vulnerabilties
    With Samy Kamkar
    Download

    [RSS Feed] [iTunes]

    28 min
  • The Origins of Risky Business with Patrick Gray
    Summary:

    Patrick Gray, the host of the Risky Business podcast, shares how he transitioned from a tech journalist to a leading voice in cybersecurity podcasting. Patrick discusses the origins of his podcast, the evolution of his content, and how he maintains integrity with sponsors. He also offers advice for aspiring podcasters on focusing on the audience and using the right tools.

    Key Topics:

    • The unexpected inspiration behind Risky Business.

    • Moving from general tech journalism to focused security content.

    • The importance of understanding technical details in reporting.

    • The growth of the Risky Business team and their venture into video content.

    • Navigating sponsorships while maintaining editorial independence.

    • Advice for new podcasters: prioritize your audience and use the right tools.

    Resources:

    • Risky Business Podcast

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    The Origins of Risky Business
    with Patrick Gray
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    47 min
  • How to Navigate a Career in Cybersecurity
    Summary:

    In this episode, Timothy De Block sits down with Ralph Collum, a cybersecurity educator with over a decade of experience in the field. They delve into Ralph's career journey, discussing his transition from a chemist to a cybersecurity professional and the various roles he's taken on, including server administration, auditing, and penetration testing. Ralph shares insights on the importance of soft skills, continuous learning, and the evolving landscape of cybersecurity.

    Key Topics Discussed:
    • Ralph’s Career Journey

    • The Impact of the Pandemic on Cybersecurity Groups

    • Getting Into Cybersecurity

    • The Role of Soft Skills in Cybersecurity

    • The Impact of AI on Cybersecurity Careers

    • Resources and Recommendations

    Resources Mentioned:
    • Books:

      • The Code to the Dead Cow Joseph Menn

      • Spam Nation by Brian Krebs

      • The Art of Invisibility by Kevin Mitnick

      • Social Engineering: The Science of Human Hacking by Christopher Hadnagy

    • Websites:

      • Help Net Security

      • Bleeping Computer

      • Hacker News

      • Dark Reading

    • Tools:

      • Feedly for organizing cybersecurity news

      • TryHackMe and Hack The Box for practical labs

    Connect with Ralph Collum:
    • Website: Training Concepts

    • Social Media: Instagram, TikTok

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    How to Navigate a Career in Cybersecurity
    With Ralph Collum
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    42 min
  • SIM Swapping: How Worrying is it in 2024?
    Summary:

    Episode Summary: In this exchanged episode, Timothy De Block chats with Mubix about the intricacies of SIM swapping, an attack vector that has seen significant attention. They discuss the current state of SIM swapping, how attackers exploit this technique, and the measures carriers have implemented to mitigate these risks. Mubix highlights the importance of understanding your risk profile and the practical steps organizations and individuals can take to protect themselves.

    Key Topics:

    • The evolution and difficulty of executing SIM swapping attacks.

    • Real-world examples and the misclassification of SIM swapping incidents.

    • The impact of enhanced carrier protections and the role of user awareness.

    • The distinction between SIM swapping and other forms of social engineering.

    • Practical advice for businesses and high-risk individuals to safeguard against SIM swapping.

    Discussion Points:

    • SIM swapping detection and reporting procedures.

    • The role of eSIMs and potential security concerns.

    • The importance of proactive security measures and user empowerment.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    How Worrying is SIM Swapping in 2024?
    With Rob Fuller AKA Mubix
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    32 min
  • How Artificial Intelligence is impacting Cybersecurity with Steve Orrin

    Summary:

    In this engaging episode, Timothy De Block speaks with Steve Orrin Federal CTO at Intel about the intersection of artificial intelligence and cybersecurity. The conversation delves into the challenges and opportunities that AI presents in the cybersecurity landscape, exploring topics such as deep fakes, disinformation, and the implementation of AI in security practices.

    Key Discussion Points:

    1. AI in Cybersecurity:

      • The rise of AI in both defensive and offensive cybersecurity strategies.

      • How AI is being used to enhance security measures and identify threats.

    2. Deep Fakes and Disinformation:

      • The challenges posed by deep fakes in the current digital landscape.

      • Techniques to detect and counteract deep fakes.

      • The implications of deep fake technology on public opinion and security.

    3. Practical AI Applications:

      • Real-world examples of AI in action within cybersecurity frameworks.

      • The role of AI in threat detection and response.

      • Implementing AI to automate routine security tasks, freeing up human resources for more complex issues.

    4. Policy and Ethical Considerations:

      • The importance of developing policies for the responsible use of AI.

      • Ethical considerations in deploying AI for cybersecurity purposes.

      • Balancing innovation with security in AI development.

    5. Future of AI and Cybersecurity:

      • Upcoming trends in AI and their potential impact on cybersecurity.

      • The evolving nature of cyber threats and how AI can adapt to these changes.

      • The need for continuous learning and adaptation in the face of rapidly advancing technology.

    Resources Mentioned:

    • OWASP

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    How AI is impacting Cybersecurity
    With Steve Orrin
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    40 min
  • How to Automate Information Security with Python
    Summary:

    In this automatic episode of Exploring Information Security, Timothy De Block talks with Mark Baggett about automating information security tasks using Python. They delve into the SANS SEC573 and SEC673 courses, which cover Python basics, advanced automation techniques, and real-world applications. Mark shares insights on using AI for coding, highlights his YouTube series "Infosec Tool Shed," and discusses upcoming workshops and conferences. The conversation also touches on the importance of Python in information security and practical experiences in automating security tasks.

    Key Discussion Points:
    • Mark's journey in automating security tasks with Python.

    • Overview of SANS SEC573 and SEC673 courses.

    • Practical applications of Python in information security.

    • Using AI for coding and debugging.

    • Mark’s YouTube series "Infosec Tool Shed."

    • Upcoming workshops and conferences.

    Links and Resources:
    • SANS SEC573 Course: https://www.sans.org/cyber-security-courses/automating-information-security-with-python/

    • SANS SEC673 Course: https://www.sans.org/cyber-security-courses/advanced-information-security-automation-with-python/

    • Infosec Tool Shed YouTube Series: https://www.youtube.com/@markbaggett/videos

    • Upcoming Workshop Registration 31 July, 2024: https://www.sans.org/webcasts/advanced-python-automation-hands-on-workshop-2024/

    • B-Sides Augusta Conference: https://bsidesaugusta.org/

    • Cyber Security Training at SANS Network Security Las Vegas 2024: https://www.sans.org/cyber-security-training-events/network-security-2024/

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    How to Automate Information Security with Python
    Mark Baggett
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    1 hr
  • HallwayCon from the floor of ShowMeCon 2024

    Summary:

    In this off-the-cuff episode, Timothy De Block brings a mic to the floor of ShowMeCon for the first-ever HallwayCon podcast episode. He walks around with a mic and recorder, engaging in spontaneous conversations with random attendees. Timothy highlights the immense value of attending security conferences, emphasizing that these real, impromptu conversations with professionals are crucial for expanding knowledge and building relationships within the industry. This unique approach captures some just some of the many conversations going on at security conferences.

    Key Topics Discussed:

    1. Importance of Networking:

      • Knowing your target employers and daily tasks.

      • Overcoming the fear of talking to strangers.

    2. Effective Techniques:

      • Asking engaging questions.

      • Volunteering and getting involved.

    3. Conference Culture:

      • Evolution of conference attire.

      • Balancing business and casual environments.

    4. Career Challenges:

      • Job market difficulties for younger and older professionals.

      • Role of networking in career advancement.

    5. Humorous Stories:

      • Conference experiences and unique attire.

      • Creative uses of business cards.

    6. Management Insights:

      • Effective management and hiring practices.

      • Importance of structured onboarding.

    7. Impact of AI:

      • AI’s role in security and deepfake technology.

      • Future relevance in cybersecurity.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    HallwayCon from the floor of ShowMeCon 2024
    With ShowMeCon Attendees
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    38 min
  • What is Rapid Threat Model Prototyping?

    Summary:

    In this episode, we sit down with Geoff Hill from Tutamantic_Sec to explore the innovative approach of Rapid Threat Model Prototyping (RTMP). Geoff shares his journey from being a C++ developer to becoming a threat modeling expert, highlighting the challenges and successes he encountered along the way. This episode dives deep into how RTMP can help streamline threat modeling processes, making them more efficient and scalable.

    Key Discussion Points:

    1. Introduction to RTMP:

      • Geoff explains the origins and the need for a new threat modeling approach.

      • Discussion on traditional threat modeling challenges and how RTMP addresses them.

    2. Implementation and Benefits:

      • Detailed walkthrough of RTMP’s implementation in various organizations.

      • How RTMP integrates with existing development workflows like Agile and DevOps.

      • Benefits of using RTMP, including reduced workload on security teams and improved security posture.

    3. RTMP Methodology:

      • Explanation of the stages and numerical ranking system in RTMP.

      • How RTMP utilizes open-source frameworks and tools.

      • The role of security champions within development teams.

    4. Practical Applications and Case Studies:

      • Real-world examples of RTMP in action.

      • Success stories and lessons learned from implementing RTMP in different industries.

    5. Future of Threat Modeling:

      • Geoff’s insights on the evolution of threat modeling.

      • Upcoming trends and the importance of being proactive in security.

    Resources Mentioned:

    • Tutamantic

    • GitHub Repository for RTMP

    • OWASP Top 10

    Connect with Geoff Hill:

    • Twitter: @Tutamantic_Sec

    • LinkedIn: Geoff Hill

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    What is Rapid Threat Model Prototyping?
    With Geoff Hill
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    47 min
  • What is the Ransomware Defense Initiative (RDI)?

    Summary:

    In this episode, Timothy De Block sits down with Ed Rojas to discuss the origins and development of the Ransomware Defense Initiative (RDI). They explore Ed’s motivation behind creating RDI, its evolution, and how it aids organizations in proactively combating ransomware threats.

    Key Topics Discussed:

    • Origins of RDI: Ed explains his drive to identify effective controls against ransomware, focusing on proactive measures rather than reactive strategies.

    • Research Findings: Insights from extensive research on ransomware techniques and the identification of key controls.

    • Implementation: How RDI assists organizations in assessing their maturity and readiness against ransomware attacks.

    • Use Cases: Examples of how companies and new CISOs can utilize RDI for rapid assessment and strategic planning.

    • Future Developments: Upcoming features and improvements in RDI to enhance its utility and accessibility.

    Quotes:

    • “I wanted to identify a set of controls that everyone should have implemented to be okay against ransomware.”

    • “Most recommendations focus on recovery. I wanted to focus on how we detect and mitigate ransomware attacks as early as possible.”

    Resources Mentioned:

    • RDI Shield

    Contact Information:

    • Ed Rojas: Connect with Ed on LinkedIn.

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    What is the Ransomware Defense Initiative (RDI)
    With Ed Rojas
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    57 min
  • What's Happening at ShowMeCon 2024?

    Summary:

    In this dynamic episode, host Timothy De Block engages in a lively conversation with Joey Smith, Tim McLaren, and Ben Miller live from the floor of Show Me Con 2024. They discuss various topics including the importance of trust in vendor relationships, the evolution of security roles, and the innovative approaches being adopted in the food industry.

    Episode Highlights:

    Conversations with Industry Experts:

    • Spontaneous discussions about the importance of genuine interactions at conferences.

    • Joey's perspective on the value of treating vendors with respect and professionalism.

    Insights from Tim McLaren:

    • Tim shares his experience transitioning from a vendor-specific role to a broader consultancy position.

    • Discussion on the importance of having diverse solutions and the role of trust in customer relationships.

    Ben Miller's Take:

    • Ben emphasizes the need for critical thinking and continuous learning in security roles.

    • Reflections on how past experiences shape current practices in cybersecurity.

    Vendor Relationships and Trust:

    • The group discusses the significance of building long-term, trust-based relationships with vendors.

    • Examples of how trust influences decision-making and security practices.

    Innovations in Security:

    • Conversations on how emerging technologies and innovative solutions are reshaping the cybersecurity landscape.

    • Joey's insights on the latest advancements and their implications for the industry.

    Key Quotes:

    • "Trust is between two people. I don't trust the business or a line of questioning; I trust the individuals behind it." - Joey Smith

    • "Critical thinking and adaptability are essential in the ever-evolving field of cybersecurity." - Ben Miller

    Recommended Resources:

    • ShowMeCon

    • GuidePoint Security

    Contact Information:

    Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.

    Check out our services page and reach out if you see any services that fit your needs.

    Social Media Links:

    [RSS Feed] [iTunes] [LinkedIn]

    What's Happening at ShowMeCon 2024
    With Joey Smith, Tim McLaren, and Ben Miller
    Newsletter Block
    This newsletter signup form needs a storage option. Edit the block and enter a storage location via the Storage tab.
    Subscribe

    Sign up with your email address to receive news and updates.

    Email Address
    Sign Up

    We respect your privacy.

    Thank you!


    54 min

About Exploring Information Security - Exploring Information Security

From the publisher's feed

The Exploring Information Security podcast interviews a different professional each week exploring topics, ideas, and disciplines within information security. Prepare to learn, explore, and grow your…

More shows like Exploring Information Security - Exploring Information Security

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners