Paul's Security Weekly (Video)

Paul's Security Weekly (Video)

By Paul AsadoorianTechnologyEducationHow To
Download on the App Store

Paul's Security Weekly (Video) episodes

  • Routers on Trial, AI Found More Bugs - PSW #947

    In the security news this week:

    • BPFDoor
    • OpenSSH compresses a little too much
    • AI can find bugs. Who gets them fixed?
    • TP-Link and the courts
    • Cisco NX-API
    • ClingSTUN
    • LineageOS, Android TV, and a Raspberry PI
    • Dell's updater has a privilege problem
    • SonicWall SSRF
    • U-Boot's LogoFAIL like
    • Exploit-DB isn't dead
    • MFA passes. The attacker still gets in.
    • LakeShark and cool gadgets
    • Kasa cameras and an exposed debug interface
    • SharePoint hardening is back on the checklist
    • Google pauses open-source bug bounty submissions
    • NetScaler's latest vulnerability needs a closer look
    • Kiteworks tells customers to shut it down
    • Exchange gets an unexpected security update
    • Do LLMs actually reason?
    • disagree on AI risk?
    • Anthropic, AI consciousness and the Vatican
    • Grok gets involved in foreign policy
    • WordPress malware that survives cleanup
    • Can spyware vendors stop their own tools?
    • When an AI chatbot conversation reaches the police
    • Open-weight AI models enter the cyber debate
    • AI agents take their attacks shopping

    Show Notes: https://securityweekly.com/psw-947

    2 hr 2 min
  • Hacking Without Boundaries - Michael Jenkins - PSW #946

    First up we talk with Threatlocker CTO Michael Jenkins about threat actors use of AI and keeping the bad things out with Zero Trust. Then in the security news:

    • Compiling spreadsheets, because that's why
    • Nvidia wants to put AI agents in timeout
    • Citrix NetScaler gets exploited again, and again
    • Spectre still refuses to die
    • Your SBOM is incomplete?
    • File notifications leak more than filenames
    • ENIAC had cables instead of a BIOS
    • Another Linux kernel root exploit lands
    • Containers share a kernel
    • ThinkNode M9 microSD card gets a virus notice
    • Google analyst infiltrates a supply-chain gang
    • Your phone speaker can transmit radio
    • Reconstructing firmware with a logic analyzer
    • Robot dogs learn cybersecurity
    • CISA warns about third-party ICS integrators
    • Dutch police arrest a ShinyHunters suspect
    • A soldier goes from telecom hacking to prison
    • AI companies discover their agents have opinions
    • Cloudflare containers accidentally share leftovers
    • OT networks are still mostly not isolated
    • Florida wants to pause ChatGPT

    The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Show Notes: https://securityweekly.com/psw-946

    2 hr 2 min
  • AI Will Save Us, or Not? - PSW #945

    In the security news this week:

    • Build your own router, or just buy one
    • What to patch first
    • But maybe don't buy D-Link
    • AI nearly starts a war
    • Flock cameras lose their keys
    • The AI slowdown won't save bad security
    • Opus at home, just slower
    • Black Hat says fundamentals still work
    • Hacker gadgets, and my top pick
    • Gyazo screenshots
    • Fake job interviews, real malware
    • VINCE gets a new home
    • Munich university gets disconnected
    • LinkedIn fights the scraping machine
    • SolarWinds hard-codes another bad idea
    • Fake LastPass kills 145 security tools
    • Colorado water gets its settings changed
    • AI CEOs sell apocalypse and bonds
    • The AI safety cult gets audited
    • Ransomware recovery takes weeks, not hours
    • TeamPCP's supply-chain tour continues
    • Zuckoff hunts smart glasses

    Show Notes: https://securityweekly.com/psw-945

    2 hr 4 min
  • AI hates CAPTCHAs - PSW #944

    In the security news this week:

    • UK government rolls out passkeys to 20 million users
    • Phishing-resistant authentication and replay resistance
    • Passkey adoption, device security, and user acceptance
    • EU Cyber Resilience Act guidance, scope, and compliance
    • CRA vulnerability disclosure and reporting requirements
    • The real cost of cyberattacks and cybersecurity spending
    • Cyber insurance and improving organizational security
    • Nightmare Eclipse and the release of Windows zero-days
    • Check Point VPN vulnerabilities and perimeter security
    • GitLab security updates and shadow IT
    • Discovering unmanaged GitLab instances
    • Cyberattacks against oil tankers and insider threats
    • VPN patching and implied rules
    • Zero-downtime GitLab updates and version management
    • Running Windows ARM on Apple Silicon with VMware and Parallels

    Show Notes: https://securityweekly.com/psw-944

    2 hr 5 min
  • It's More Secure When It's Disabled - PSW #943

    In the security news this week:

    • Microsoft patches all the things
    • Commissary freezers enter cyberwar
    • Fake AV, real Defender nap
    • Rowhammer comes for the GPU
    • BIOS updates are no longer optional
    • CVSS is not a crystal ball
    • Kworker, but make it malware
    • FortiGate gets a post-exploitation RAT
    • CERN goes Debian underground
    • UEFI shells strike again
    • Australia loses the plot, and phones
    • Cisco routers become covert gateways
    • MikroTik patches the takeover chain
    • WeWorm wriggles through mobile
    • The year of Linux television
    • Browsers become backdoors
    • Fake IT calls, real data theft
    • CVE attribution gets weird
    • Boston Scientific keeps talking
    • Security tools misconfigure themselves
    • AI circuit breakers for rogue agents
    • Passkeys meet the real world
    • Vibe coding, vibe vulnerabilities
    • AI loss of control keeps climbing
    • AI agents report themselves to Schneier

    Show Notes: https://securityweekly.com/psw-943

    2 hr 3 min
  • Linux Threat Hunting - PSW #942

    First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week:

    • SonicWall zero-days, again
    • AI finds a pile of Cisco bugs, and a root RCE
    • Claude Code Auto Mode dangers
    • BGP hijacks your unsigned software update
    • California, Linux and age verification
    • Free movies, complimentary malware
    • Citrix puts Linux alongside Windows
    • Signal's "secure" enclave
    • An expired domain answers military phone calls
    • MORE Cheap Android TV boxes arrive pre-pwned
    • CISA red teams meet critical infrastructure
    • PaperCut vulnerability cuts both ways
    • Big Tech asks everyone to secure its AI future
    • Pacemaker monitoring
    • DOJ files on a criminal leak site
    • Water utility security, right after the breaches

    Show Notes: https://securityweekly.com/psw-942

    2 hr 13 min
  • Hacking All The Devices, with AI? - Rob Allen - PSW #941

    Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do.

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    In the security news this week:

    • Sixteen-year-old Linux LPEs still work
    • Ubiquiti UniFi, patch it, also light on details
    • If you remember magicJack, you too are old
    • Slovakia doesn't trust its own speed cameras
    • More homework on NIST's vulnerability database
    • Your webcam, mic, and key light, all owned
    • Printer moonlights as Minecraft server
    • Zombie credit cards
    • Your car's infotainment system fuels botnets
    • Feds warn about AI-powered PLC attacks
    • Can an AI actually reverse engineer its way out?
    • Denver International's security breach, volume six
    • Charlotte's breach and a parking company
    • Why your ancient tech might be the safe one
    • Microsoft counts billions of phishing emails
    • A password vault that leaked to any website
    • Australia sells password books at the post office
    • Another perfect ten, this time in Entra ID
    • Cisco's bug scores read like Olympic gymnastics

    Show Notes: https://securityweekly.com/psw-941

    2 hr 7 min
  • Rejoice In The Nostalgia - PSW #940

    In the security news this week:

    • Cursor opens your repo, the repo opens you
    • If you want the good model I'm going to need to see your ID
    • Flock's a Flocking mess
    • Defender was supposed to be the chosen one
    • Side stepping Secure boot - twice
    • SonicWall: a LAMP stack in a fancy case
    • Macs don't get viruses, part infinity
    • Flipper One, but why not Nix?
    • NetScaler is back in the room
    • Borrowing phone's good reputation
    • USB and how to make Windows download stuff
    • A KVM with the expensive letters removed
    • Five steps to stop the webcam creeps
    • PlexTrac acquired
    • NIST asks the internet to fix the NVD
    • Poland's health software has a very bad week
    • If Apple pings you about spyware, believe it
    • A macOS stealer that drives your browser for you
    • T-Mobile's incident response tool of choice may suprise you, or not...

    Show Notes: https://securityweekly.com/psw-940

    2 hr 9 min
  • The Breached WiFi AI Ports... What? - PSW #939

    In the security news this week:

    • North Carolina ports and contingency plans • Back to paper and pencils • Midnight Blizzard compromises hotel Wi-Fi • DNS strikes again • Captive portals, stolen credentials, and nation-state scale • Phishing-resistant MFA • Goodbye SMS and voice authentication • Cornflake RAT and Chaco Shell • The NPM worm • Hundreds of compromised packages • AI lowers the barrier to mass exploitation • Rethinking "secure enough" • Back to basics: know what's on your network • Get off my PCI lawn

    Show Notes: https://securityweekly.com/psw-939

    2 hr 5 min
  • When AI Commits Felonies - PSW #938

    This week:

    • When you are not at summer camp you can't read about it
    • The Fettle continues
    • Using the CFAA against AI
    • Social contracts are not security models
    • VSCode extentions, again
    • Bugtraq is back!
    • NVIDA, LVFS, and unraveling AI infrastructure
    • More routers that come with backdoors
    • Do we care about LPE?
    • Even more AI that finds vulnerabilities
    • When AI breaks its own guardtails

    Show Notes: https://securityweekly.com/psw-938

    1 hr 59 min

About Paul's Security Weekly (Video)

From the publisher's feed

Where security veterans unpack the latest IT security news, vulnerabilities, and research through a historical and technical lens that can cut through even the thickest cigar smoke. Hosted by Paul…

More shows like Paul's Security Weekly (Video)

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

MacBreak Weekly (Video) by TWiT

MacBreak Weekly (Video)

363 Listeners

Security Now (Video) by TWiT

Security Now (Video)

148 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

Windows Weekly (Video) by TWiT

Windows Weekly (Video)

79 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

First Ring Daily by Paul Thurrott and Brad Sams

First Ring Daily

51 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

93 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners