Paul's Security Weekly (Video)

Paul's Security Weekly (Video)

By Paul AsadoorianTechnologyEducationHow To
Download on the App Store

Paul's Security Weekly (Video) episodes

  • Sandwich Hats - PSW #937

    In the security news:

    • 2.2 million cars, one shared Bluetooth key
    • JFrog tries to spin an AI 0-day into a win
    • Sextortion scammers recycling ShinyHunters' leaks
    • The first hack ever, from 1966
    • Prompt injection as a service, $150 a month
    • Cisco's mystery "static credential"
    • BMCs still on the internet, still handing out hashes
    • Scattered Spider duo sentenced over the TfL hack
    • Air-gapped data sneaking out over the video cable
    • A ghost in the network
    • DNS poisoning checks into hotel WiFi
    • Microsoft's cut-rate cybersecurity AI
    • Learning to trust USB drives again
    • Agentic pentesting shows up just in time for Black Hat
    • Microsoft rethinks security for the AI age, again

    Show Notes: https://securityweekly.com/psw-937

    2 hr 6 min
  • Fixing Vulns Is Harder Than Finding Them - PSW #936

    In the news this week:

    • InfraTrust and knowing what to patch
    • Adversary in the middle triggered command injection
    • Exploitarium again
    • FreeRDP comes with free vulnerabilities
    • AI breaking out of sandboxes on its own
    • Wordpress RCE
    • DMA dangers
    • Nightmware eclypse is at it again
    • Fortisandbox
    • Turning AI to the dark side
    • more prompt injection
    • Secure boot is broken, still and again...

    Show Notes: https://securityweekly.com/psw-936

    2 hr 3 min
  • 1999 Called and It Wants It's Exploits Back - PSW #935

    This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously discussed! Then in the security news:

    • The GodDamn Ransomware
    • CMMC suspended
    • Holy Microsoft Tuesday!
    • Lessons learned
    • Without the Internet, do we still get water?
    • The forgotten shims
    • More than two BIOS passwords
    • Cracking firmware encryption with Claude
    • 1999 called, and it wants its "Exploits" back
    • Prompt injection for defenders
    • Grok has your repo
    • You're not going to outpatch AI

    Show Notes: https://securityweekly.com/psw-935

    2 hr 12 min
  • AI Is Annoying & IoT Devices Still Get Hacked - PSW #934

    In the security news:

    • Son of Anton strikes again!
    • HalluSquatting and using Claude to defend itself
    • CISA KEV's Revolving Door
    • LLM's hallucinate and companies get sued
    • Additionally - GitLost
    • Yet even more Linux vulnerabilities
    • Citrix just keeps bleeding
    • Old hardware is new again
    • A sneak peak into next week's tech segment
    • Tenda hidden backdoors
    • We're still talking about Mirai
    • Today was not a good day for Roundcube
    • Canada is hacking criminals
    • AI safeguards are still annnoying
    • All cars will spy on you
    • The FatFs unpatched vulnerability in millions of embedded devices
    • Windows OS market share drops below 60% (Paul uses Arch)
    • 'We Cannot Choose to Become Idiots' - or can we?

    Show Notes: https://securityweekly.com/psw-934

    2 hr 6 min
  • Linux Tech Segment & Vulnerabilities Galore - PSW #933

    This week we have a technical segment based on the response to "Atomic Arch", an updated open-source tool to help you catch malicious packages. In the security news:

    • Exploitarium
    • A hot messy summer of vulnerabilities
    • AI Squatting
    • Linux LPE - no shortage of those
    • Fingerprinting Favicons
    • Windows 10 extended
    • Can Clothes Make You Invisible to Facial Recognition?
    • Fable and Mythos for All
    • Do we care about Quantum?
    • Execs have AI risk under control
    • Biological warefare in Spyware
    • The scripts in-scope for PCI
    • We don't have privacy, but we may get age restrictions

    Show Notes: https://securityweekly.com/psw-933

    2 hr 10 min
  • Cloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #932

    First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure!

    This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them!

    Next up in the security news:

    • Help, I am Fortibleeding
    • Cisco SD-WAN needs help
    • The secret life of probe requests
    • Help, I am Squidbleeding
    • XSS to RCE and why CVSS isn't the full picture
    • TVs spy on you
    • Foundational security practices
    • Cybersecurity costs money
    • Happy "Its too late to update your KEK key" day
    • You don't have security flaws if no one can report them
    • Rickrolling FIFA
    • Domain takeovers
    • End of life, out of luck
    • The key to Encryption...

    Show Notes: https://securityweekly.com/psw-932

    2 hr 14 min
  • GPS, PCI, ARCH, OH MY! - PSW #931

    In the security news this week:

    • GPS spoofing and satellite jamming are getting way too accessible
    • Rekeying satellites in orbit sounds terrifying
    • Cyber extortion and whether criminals still have ethics
    • AI helping cybersecurity research... and drug discovery
    • Data centers eating regional power grids
    • Nuclear, solar, natural gas, and the future of AI infrastructure
    • What happens when GPS stops being trustworthy?
    • Satellite constellations as the next critical infrastructure target
    • AI guardrails and why sci-fi warned us first
    • Cyber ranges that don't simulate reality anymore
    • The weird morality line between hackers, scammers, and criminals
    • Future satellite warfare without calling it warfare
    • Security standards for infrastructure nobody thought would be online
    • Historical cybersecurity stories that suddenly feel very current
    • Why AI changes both offense and defense simultaneously
    • And how much of modern cyber defense is just educated guessing

    Show Notes: https://securityweekly.com/psw-931

    2 hr 6 min
  • Trolling Microsoft With Vulnerabilities - PSW #930

    In the security news:

    • Trolling Microsoft With Vulnerabilities
    • Fable 5 loves guardrails
    • Binwalk vulnerability
    • EMBA and local models
    • EDRChoker
    • AI worms
    • Interesting Arista vulnerability added to KEV
    • BOD 26-04 and stakeholder specific vulnerability categorization
    • Bring your own execution environment
    • Homelab tips
    • MikroTik routers as interceptors
    • Ivanti Sentry and irony
    • Smart TV botnets
    • Privacy laws
    • Solarwinds Serv-U lives on
    • More Cisco SD-WAN fun!
    • Russia can jam GPS
    • No nudes for you says UK Government
    • "Why would someone want to learn code when AI does it better and faster?"

    Show Notes: https://securityweekly.com/psw-930

    2 hr 3 min
  • Security Researchers Are Threat Actors - PSW #929

    This week in the security news:

    • Security Researchers Are Threat Actors according to Microsoft
    • Hands-free malicious firmware
    • If you've ever typed "ls" in Windows, this is for you
    • Cisco makes more patches, wants you to pay
    • Ambiguous Secure Boot bypass
    • Threat actors love network edge devices, and I have the chat logs and leaks to prove it
    • The downside of chip sanctions
    • Your VoIP phone is hacked
    • Vulnerability disclosure and incentives
    • Claude reccovers Bitcoin wallet
    • an Instagram "Exploit"
    • Turn the plane around
    • The worms will continue
    • PAN-OS global protect vulnerability
    • The 1-Click Github token stealer
    • Data-nuking prompt injection
    • Turning Buses into spies
    • SymJack
    • NIST NVD mistakes, and how CNAs need to up their game

    Show Notes: https://securityweekly.com/psw-929

    2 hr 2 min
  • Linux Supply Chain How-To - PSW #928

    This week we have a technical segment focused on Linux! Paul released a script that helps you get a handle on Linux supply chain security, and new features allow you to assess the state of Secure Boot on your Linux systems (that also use MS certificates, ironically). The script is in his Git repo: https://github.com/pasadoorian/Linux_Hacks.

    In the security news:

    • The CVE chase
    • The new security basics
    • Enterprises are lacking more than AI
    • Detections are falling behind
    • Why DOOM!?!
    • Chromium vulnerability
    • The ambitious Flipper One
    • I'm still curious who was behind these leaks
    • Mitre moves Caldera to Apache foundation
    • Wind cybersecurity
    • PQC updates
    • YellowKey Bitlocker Bypass updates
    • The software supply chain is in deep trouble

    Show Notes: https://securityweekly.com/psw-928

    2 hr 5 min

About Paul's Security Weekly (Video)

From the publisher's feed

Where security veterans unpack the latest IT security news, vulnerabilities, and research through a historical and technical lens that can cut through even the thickest cigar smoke. Hosted by Paul…

More shows like Paul's Security Weekly (Video)

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

MacBreak Weekly (Video) by TWiT

MacBreak Weekly (Video)

363 Listeners

Security Now (Video) by TWiT

Security Now (Video)

148 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

Windows Weekly (Video) by TWiT

Windows Weekly (Video)

79 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

First Ring Daily by Paul Thurrott and Brad Sams

First Ring Daily

51 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

93 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners