
Sign up to save your podcasts
Or


In this susceptible edition of the Exploring Information Security podcast, Samy Kamkar joins me to discuss how to find vulnerabilities. This is a RERELEASE EPISODE.
Samy (@samykamkar) shouldn't need too much of an introduction to most people. He's been in the news for hacking garage doors, credit cards, cars, and much much more. Samy likes to hack things and has a knack for finding vulnerabilities in everything from locked machines to wireless doorbells. His site has the full list of vulnerabilities as well as videos and press appearances. Which made him the perfect guess for talking about how to find vulnerabilities.
In this episode we discuss:
What got him started in looking for vulnerabilities
What is a vulnerability
What skills are necessary for finding vulnerabilities
How he decides his next project
The steps to finding vulnerabilities
What he does when he discovers a vulnerability
How long the process takes
[RSS Feed] [iTunes]
Patrick Gray, the host of the Risky Business podcast, shares how he transitioned from a tech journalist to a leading voice in cybersecurity podcasting. Patrick discusses the origins of his podcast, the evolution of his content, and how he maintains integrity with sponsors. He also offers advice for aspiring podcasters on focusing on the audience and using the right tools.
Key Topics:
The unexpected inspiration behind Risky Business.
Moving from general tech journalism to focused security content.
The importance of understanding technical details in reporting.
The growth of the Risky Business team and their venture into video content.
Navigating sponsorships while maintaining editorial independence.
Advice for new podcasters: prioritize your audience and use the right tools.
Resources:
Risky Business Podcast
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this episode, Timothy De Block sits down with Ralph Collum, a cybersecurity educator with over a decade of experience in the field. They delve into Ralph's career journey, discussing his transition from a chemist to a cybersecurity professional and the various roles he's taken on, including server administration, auditing, and penetration testing. Ralph shares insights on the importance of soft skills, continuous learning, and the evolving landscape of cybersecurity.
Key Topics Discussed:Ralph’s Career Journey
The Impact of the Pandemic on Cybersecurity Groups
Getting Into Cybersecurity
The Role of Soft Skills in Cybersecurity
The Impact of AI on Cybersecurity Careers
Resources and Recommendations
Books:
The Code to the Dead Cow Joseph Menn
Spam Nation by Brian Krebs
The Art of Invisibility by Kevin Mitnick
Social Engineering: The Science of Human Hacking by Christopher Hadnagy
Websites:
Help Net Security
Bleeping Computer
Hacker News
Dark Reading
Tools:
Feedly for organizing cybersecurity news
TryHackMe and Hack The Box for practical labs
Website: Training Concepts
Social Media: Instagram, TikTok
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Episode Summary: In this exchanged episode, Timothy De Block chats with Mubix about the intricacies of SIM swapping, an attack vector that has seen significant attention. They discuss the current state of SIM swapping, how attackers exploit this technique, and the measures carriers have implemented to mitigate these risks. Mubix highlights the importance of understanding your risk profile and the practical steps organizations and individuals can take to protect themselves.
Key Topics:
The evolution and difficulty of executing SIM swapping attacks.
Real-world examples and the misclassification of SIM swapping incidents.
The impact of enhanced carrier protections and the role of user awareness.
The distinction between SIM swapping and other forms of social engineering.
Practical advice for businesses and high-risk individuals to safeguard against SIM swapping.
Discussion Points:
SIM swapping detection and reporting procedures.
The role of eSIMs and potential security concerns.
The importance of proactive security measures and user empowerment.
Leave a comment below or reach out via the contact form on the site, email timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
In this engaging episode, Timothy De Block speaks with Steve Orrin Federal CTO at Intel about the intersection of artificial intelligence and cybersecurity. The conversation delves into the challenges and opportunities that AI presents in the cybersecurity landscape, exploring topics such as deep fakes, disinformation, and the implementation of AI in security practices.
Key Discussion Points:
AI in Cybersecurity:
The rise of AI in both defensive and offensive cybersecurity strategies.
How AI is being used to enhance security measures and identify threats.
Deep Fakes and Disinformation:
The challenges posed by deep fakes in the current digital landscape.
Techniques to detect and counteract deep fakes.
The implications of deep fake technology on public opinion and security.
Practical AI Applications:
Real-world examples of AI in action within cybersecurity frameworks.
The role of AI in threat detection and response.
Implementing AI to automate routine security tasks, freeing up human resources for more complex issues.
Policy and Ethical Considerations:
The importance of developing policies for the responsible use of AI.
Ethical considerations in deploying AI for cybersecurity purposes.
Balancing innovation with security in AI development.
Future of AI and Cybersecurity:
Upcoming trends in AI and their potential impact on cybersecurity.
The evolving nature of cyber threats and how AI can adapt to these changes.
The need for continuous learning and adaptation in the face of rapidly advancing technology.
Resources Mentioned:
OWASP
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
In this automatic episode of Exploring Information Security, Timothy De Block talks with Mark Baggett about automating information security tasks using Python. They delve into the SANS SEC573 and SEC673 courses, which cover Python basics, advanced automation techniques, and real-world applications. Mark shares insights on using AI for coding, highlights his YouTube series "Infosec Tool Shed," and discusses upcoming workshops and conferences. The conversation also touches on the importance of Python in information security and practical experiences in automating security tasks.
Key Discussion Points:Mark's journey in automating security tasks with Python.
Overview of SANS SEC573 and SEC673 courses.
Practical applications of Python in information security.
Using AI for coding and debugging.
Mark’s YouTube series "Infosec Tool Shed."
Upcoming workshops and conferences.
SANS SEC573 Course: https://www.sans.org/cyber-security-courses/automating-information-security-with-python/
SANS SEC673 Course: https://www.sans.org/cyber-security-courses/advanced-information-security-automation-with-python/
Infosec Tool Shed YouTube Series: https://www.youtube.com/@markbaggett/videos
Upcoming Workshop Registration 31 July, 2024: https://www.sans.org/webcasts/advanced-python-automation-hands-on-workshop-2024/
B-Sides Augusta Conference: https://bsidesaugusta.org/
Cyber Security Training at SANS Network Security Las Vegas 2024: https://www.sans.org/cyber-security-training-events/network-security-2024/
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
In this off-the-cuff episode, Timothy De Block brings a mic to the floor of ShowMeCon for the first-ever HallwayCon podcast episode. He walks around with a mic and recorder, engaging in spontaneous conversations with random attendees. Timothy highlights the immense value of attending security conferences, emphasizing that these real, impromptu conversations with professionals are crucial for expanding knowledge and building relationships within the industry. This unique approach captures some just some of the many conversations going on at security conferences.
Key Topics Discussed:
Importance of Networking:
Knowing your target employers and daily tasks.
Overcoming the fear of talking to strangers.
Effective Techniques:
Asking engaging questions.
Volunteering and getting involved.
Conference Culture:
Evolution of conference attire.
Balancing business and casual environments.
Career Challenges:
Job market difficulties for younger and older professionals.
Role of networking in career advancement.
Humorous Stories:
Conference experiences and unique attire.
Creative uses of business cards.
Management Insights:
Effective management and hiring practices.
Importance of structured onboarding.
Impact of AI:
AI’s role in security and deepfake technology.
Future relevance in cybersecurity.
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
In this episode, we sit down with Geoff Hill from Tutamantic_Sec to explore the innovative approach of Rapid Threat Model Prototyping (RTMP). Geoff shares his journey from being a C++ developer to becoming a threat modeling expert, highlighting the challenges and successes he encountered along the way. This episode dives deep into how RTMP can help streamline threat modeling processes, making them more efficient and scalable.
Key Discussion Points:
Introduction to RTMP:
Geoff explains the origins and the need for a new threat modeling approach.
Discussion on traditional threat modeling challenges and how RTMP addresses them.
Implementation and Benefits:
Detailed walkthrough of RTMP’s implementation in various organizations.
How RTMP integrates with existing development workflows like Agile and DevOps.
Benefits of using RTMP, including reduced workload on security teams and improved security posture.
RTMP Methodology:
Explanation of the stages and numerical ranking system in RTMP.
How RTMP utilizes open-source frameworks and tools.
The role of security champions within development teams.
Practical Applications and Case Studies:
Real-world examples of RTMP in action.
Success stories and lessons learned from implementing RTMP in different industries.
Future of Threat Modeling:
Geoff’s insights on the evolution of threat modeling.
Upcoming trends and the importance of being proactive in security.
Resources Mentioned:
Tutamantic
GitHub Repository for RTMP
OWASP Top 10
Connect with Geoff Hill:
Twitter: @Tutamantic_Sec
LinkedIn: Geoff Hill
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
In this episode, Timothy De Block sits down with Ed Rojas to discuss the origins and development of the Ransomware Defense Initiative (RDI). They explore Ed’s motivation behind creating RDI, its evolution, and how it aids organizations in proactively combating ransomware threats.
Key Topics Discussed:
Origins of RDI: Ed explains his drive to identify effective controls against ransomware, focusing on proactive measures rather than reactive strategies.
Research Findings: Insights from extensive research on ransomware techniques and the identification of key controls.
Implementation: How RDI assists organizations in assessing their maturity and readiness against ransomware attacks.
Use Cases: Examples of how companies and new CISOs can utilize RDI for rapid assessment and strategic planning.
Future Developments: Upcoming features and improvements in RDI to enhance its utility and accessibility.
Quotes:
“I wanted to identify a set of controls that everyone should have implemented to be okay against ransomware.”
“Most recommendations focus on recovery. I wanted to focus on how we detect and mitigate ransomware attacks as early as possible.”
Resources Mentioned:
RDI Shield
Contact Information:
Ed Rojas: Connect with Ed on LinkedIn.
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
Summary:
In this dynamic episode, host Timothy De Block engages in a lively conversation with Joey Smith, Tim McLaren, and Ben Miller live from the floor of Show Me Con 2024. They discuss various topics including the importance of trust in vendor relationships, the evolution of security roles, and the innovative approaches being adopted in the food industry.
Episode Highlights:Conversations with Industry Experts:
Spontaneous discussions about the importance of genuine interactions at conferences.
Joey's perspective on the value of treating vendors with respect and professionalism.
Insights from Tim McLaren:
Tim shares his experience transitioning from a vendor-specific role to a broader consultancy position.
Discussion on the importance of having diverse solutions and the role of trust in customer relationships.
Ben Miller's Take:
Ben emphasizes the need for critical thinking and continuous learning in security roles.
Reflections on how past experiences shape current practices in cybersecurity.
Vendor Relationships and Trust:
The group discusses the significance of building long-term, trust-based relationships with vendors.
Examples of how trust influences decision-making and security practices.
Innovations in Security:
Conversations on how emerging technologies and innovative solutions are reshaping the cybersecurity landscape.
Joey's insights on the latest advancements and their implications for the industry.
Key Quotes:
"Trust is between two people. I don't trust the business or a line of questioning; I trust the individuals behind it." - Joey Smith
"Critical thinking and adaptability are essential in the ever-evolving field of cybersecurity." - Ben Miller
Recommended Resources:
ShowMeCon
GuidePoint Security
Contact Information:
Leave a comment below or reach out via the contact form on the site, email [timothy.deblock[@]exploresec[.]com, or reach out on LinkedIn.
Check out our services page and reach out if you see any services that fit your needs.
Social Media Links:
[RSS Feed] [iTunes] [LinkedIn]
Sign up with your email address to receive news and updates.
We respect your privacy.
From the publisher's feed

373 Listeners

1,029 Listeners

8,059 Listeners