Paul's Security Weekly (Video)

Paul's Security Weekly (Video)

By Paul AsadoorianTechnologyEducationHow To
Download on the App Store

Paul's Security Weekly (Video) episodes

  • Everything is Overrated - PSW #847

    Air gaps are still not air gapped, making old exploits new again, chaining exploits for full compromise, patching is overrated, SBOMs are overrated, VPNs are overrated, getting root with a cigarette lighter, you can be any user you want to be, in-memory Linux malware, the Internet Archive is back, we still don't know who created Bitcoin, unhackable phones, and There's No Security Backdoor That's Only For The "Good Guys" !

    Show Notes: https://securityweekly.com/psw-847

    2 hr 2 min
  • Effective Operational Outcomes - Ken Dunham - PSW #847

    New security and vulnerability research is published every day. How can security teams get ahead of the curve and build architecture to combat modern threats and threat actors? Tune-in to a lively discussion about the threat landscape and tips on how to stay ahead of the curve.

    Segment Resources: https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server

    Show Notes: https://securityweekly.com/psw-847

    57 min
  • The Saga Continues - PSW #846

    Get ready for a wild ride in this week's podcast episode, where we dive into the latest security shenanigans!

    • Default Credentials Gone Wild: We'll kick things off with a look at how default credential scanners are like that friend who shows up to the party but never brings snacks. They're everywhere, but good luck finding one that actually works!
    • Critical Vulnerabilities in Tank Gauges: Next, we'll discuss how automated tank gauges are now the new playground for hackers. With vulnerabilities that could lead to environmental disasters, it's like giving a toddler a box of matches—what could possibly go wrong?
    • Cisco Routers: The Forgotten Gear: Cisco's small business routers are like that old car in your driveway—still running but definitely not roadworthy. We'll explore why you should check your network before it becomes a digital junkyard.
    • Firmware Updates: A Love Story: Richard Hughes has dropped some juicy updates on fwupd 2.0.0, making firmware updates as easy as ordering takeout. But let's be real, how many of us actually do it?
    • Stealthy Linux Malware: We'll also uncover Perfctl, the stealthy malware that's been creeping around Linux systems since 2021. It's like that one relative who overstays their welcome—hard to get rid of and always looking to borrow money!
    • PrintNightmare Continues: And yes, the PrintNightmare saga is still haunting Windows users. It's like a horror movie that just won't end—grab your popcorn!
    • Cyber Shenanigans at Comcast and Truist: We'll wrap up with a juicy breach involving Comcast and Truist Bank that compromised data for millions. Spoiler alert: they didn't have a great plan for cleaning up the mess.

    Tune in for all this and more as we navigate the wild world of security news with a wink and a nudge!

    Show Notes: https://securityweekly.com/psw-846

    1 hr 21 min
  • The Code of Honor: Embracing Ethics in Cybersecurity - Ed Skoudis - PSW #846

    "Code of Honor: Embracing Ethics in Cybersecurity" by Ed Skoudis is a book that explores the ethical challenges faced by cybersecurity professionals in today's digital landscape. The book delves into the complex moral dilemmas that arise in the field of cybersecurity, offering guidance on how to navigate these issues while maintaining integrity. The authors provide practical advice and real-world examples to help readers develop a strong ethical framework for decision-making in their cybersecurity careers.

    Segment Resources:

    • Code of Honor: https://www.montreat.edu/cybersecurity-code/
    • Purchase Ed's book here: https://a.co/d/gb3yRxU

    Show Notes: https://securityweekly.com/psw-846

    55 min
  • Nothing Is Safe - PSW #845

    Automated tank gauges are leaking more than just fuel, while CUPS is serving up a steaming hot brew of vulnerabilities. Meanwhile, Supermicro's BMC firmware is giving away root access like it's going out of style. If you thought your Kia was safe, think again - all it takes is a license plate and 30 seconds to turn your car into a hacker's joyride. China's been busy building a massive IoT botnet called Raptor Train. It's been chugging along undetected for four years. NIST has decided that your password doesn't need to be a cryptographic masterpiece anymore. No more special characters or arbitrary changes - just make it long and don't use "password123". A Texas hospital is playing a game of "hot potato" with ambulances thanks to a ransomware attack. More thoughts on known exploited vulnerabilities, firmware unpacking tools lowdown, Aruba, Bahama, come-on command injection, and kids changing the name of their school!

    Show Notes: https://securityweekly.com/psw-845

    2 hr 6 min
  • Analyzing Malware at Scale - John Hammond - PSW #845

    This episode of Paul Security Weekly features John Hammond, a senior security researcher from Huntress, discussing malware analysis. Hammond dives into the analysis of Ocean Lotus attacks, highlighting the use of stealthy techniques like alternate data streams and DLL side-loading. The conversation also touches on the challenges of combating attackers who leverage 'bring your own vulnerable driver' techniques to gain kernel-level privileges. The hosts discuss the need for secure-by-default configurations and the ongoing struggle to combat attackers who exploit vulnerabilities. The episode concludes with a discussion on how to improve the security of the industry.

    Segment Resources:

    • https://www.huntress.com/blog/the-hackers-in-the-arena-the-huntress-ctf-retrospective
    • https://www.huntress.com/blog/fake-browser-updates-lead-to-boinc-volunteer-computing-software

    Show Notes: https://securityweekly.com/psw-845

    1 hr 4 min
  • AI in Cyber & Addressing Analyst Burnout - Kayla Williams - PSW #844

    Kayla Williams, Chief Security Information Officer at Devo, discussed the role of AI in cybersecurity and the ongoing issue of burnout for SOC analysts. Working with Wakefield Research, Devo discovered that 83% of IT professionals feel burnt out due to stress, lack of sleep, and anxiety. Many also report that their burnout leads to breaches.

    This segment is sponsored by Devo . Visit https://securityweekly.com/devo to learn more about them!

    Segment Resources: SOC Analyst Appreciation Day: https://www.socanalystday.com/ Kayla's LinkedIn: https://www.linkedin.com/in/kaylamwilliams1/

    Show Notes: https://securityweekly.com/psw-844

    56 min
  • Unsophisticated Methods - PSW #844

    This week in the security news, Dr. Doug and Larry explore various technological advancements and their implications with a healthy dose of nostalgia, particularly focusing on health monitoring through Wi-Fi signals, the misconceptions surrounding 5G connectivity, the importance of understanding internet speed needs, and the cybersecurity threats facing water systems. They also discuss the potential chaos that could arise from infrastructure failures and the vulnerabilities present in automated tank gauges, emphasizing the need for better asset management and security measures.

    Show Notes: https://securityweekly.com/psw-844

    2 hr 4 min
  • Exploding Pagers - PSW #843

    Apple drops a lawsuit to avoid exposing secrets, what does it mean for the security industry if MS locks down the kernel?, exploding pagers, more things from the past: Adobe Flash exploits, robots get rid of your data, PKFail is still a thing, Android TV malware is back: now with conspiracy theories, DMA attacks, gamers are not nation-state attackers, the story of a .MOBI Whois server, a better bettercap, and when not to trust video baby monitors.

    Show Notes: https://securityweekly.com/psw-843

    1 hr 58 min

About Paul's Security Weekly (Video)

From the publisher's feed

Where security veterans unpack the latest IT security news, vulnerabilities, and research through a historical and technical lens that can cut through even the thickest cigar smoke. Hosted by Paul…

More shows like Paul's Security Weekly (Video)

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

MacBreak Weekly (Video) by TWiT

MacBreak Weekly (Video)

363 Listeners

Security Now (Video) by TWiT

Security Now (Video)

148 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

Windows Weekly (Video) by TWiT

Windows Weekly (Video)

79 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

First Ring Daily by Paul Thurrott and Brad Sams

First Ring Daily

51 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

93 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners