Paul's Security Weekly (Video)

Paul's Security Weekly (Video)

By Paul AsadoorianTechnologyEducationHow To
Download on the App Store

Paul's Security Weekly (Video) episodes

  • FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927

    In the security news this week:

    • FCC router bans and the hidden firmware update problem
    • Why extending support timelines actually improves security
    • Github supply chain concerns and the evolving SBOM ecosystem
    • CRA and NIS2 compliance deadlines are getting very real
    • The EU Cyber Resilience Act's 24-hour vulnerability disclosure requirement
    • Security regulation: vertical vs horizontal compliance models
    • Vehicle-to-load EV systems powering homes during outages
    • Solar, batteries, AI farms, and the future economics of electricity
    • Data centers consuming regional power grids
    • BitLocker "Yellow Key" fallout and large-scale remediation challenges
    • AI-generated PowerShell fixes and the rise of vibe scripting
    • Linux kernel exploits, module jail, and default deny strategies
    • Medical biometric data theft and why fingerprints are terrible passwords
    • Interpol cybercrime operations across the MENA region
    • OT security, connected vehicles, and accepting real-world risk

    The crew also discusses threat intelligence obligations under the CRA, the operational realities of patching at enterprise scale, the economics of secure-by-default systems, and why making security cheaper than insecurity might finally move the industry forward.

    Show Notes: https://securityweekly.com/psw-927

    2 hr 3 min
  • You're not going to patch your way out of this - PSW #926

    This week:

    • New Yellowkey bitlocker bypass and what it means for you
    • Hackers can run you over with a robot lawnmower
    • FCC says new things about routers, again
    • Glitching with AI
    • almost no false positives
    • AI thought it was evil
    • DirtyFrag and the sad state of Linux LPEs
    • You can buy better tools, perfect security, and other lies
    • The Canvas breach
    • Hackers can still take over trains
    • Baby monitors, on the Internet!
    • dnsmasq flaws I am now paying attention to
    • Swordfish
    • A neat vulnerability for ransomware
    • Mythos, Curl, and how to do secure software
    • Various ways to use AI to find bugs, spoiler, you don't need Mythos

    Show Notes: https://securityweekly.com/psw-926

    2 hr 3 min
  • Getting Rid of Your VPN - Rob Allen - PSW #925

    Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them!

    In the Security News:

    • Less details about the FCC router ban
    • Canary traps that work
    • Hacking trains and getting arrested
    • You can be an adult if you have a mustache
    • cPanel is being exploited
    • Pro-Iran group takes down Ubuntu
    • Anthropic's new security solution
    • Safe AI Agents and other lies
    • People still use screensavers?
    • CISA and operating for weeks or months in isolation
    • Paramiko issues fixes
    • Find security research
    • Copy/Fail and AI slop debate
    • ESP32 simulator
    • Spotting vibe coded malware
    • Fast16 - Stuxnet before Stuxnet

    Show Notes: https://securityweekly.com/psw-925

    2 hr 5 min
  • FIRESTARTER - PSW #924

    This week in the security news:

    • Are you a FIRESTARTER?
    • Eavesdropping via fiber-optic cables
    • Copy Fail - more Linux LPE
    • Github RCE
    • Running Linux on a PS5
    • BadUSB tricks
    • SilentGlass and HDMI threats
    • Sonicwall and vague details
    • Universities are for porn?
    • The Banshee
    • Before CVEs comes scanning
    • Vendor addresses AirSnitch
    • GitHub and not serious work
    • Routers have country-specific backdoors
    • Phones with Hotspot are fine

    Show Notes: https://securityweekly.com/psw-924

    2 hr 3 min
  • Back to (or Start) Fundamentals? - Rajesh Khazanchi - PSW #923

    This week:

    Larry's in the host seat and chaos ensues. We dig into:

    • A very questionable story about tracking a warship with a $5 Bluetooth tracker
    • Serial-to-IP devices quietly sitting in critical infrastructure… and full of holes
    • New York regulators mandating MFA and asset inventory—aka CIS Control #1 is now breaking news
    • A ransomware negotiator who decided to double-dip (and landed in prison)
    • "Brand new" hard drives that come preloaded… with someone else's data
    • The Vercel breach: no zero-day, just shadow IT, stolen tokens, and bad decisions
    • AI-driven vulnerability discovery and the looming "vulnpocalypse"
    • Quantum crypto debates: real threat or just another security boogeyman?
    • Mirai is STILL alive—because apparently we still don't patch routers
    • And yes… Flipper Zero makes an appearance (no, you're not hacking airplanes… calm down)

    Then, we rebroadcast an interview from RSAC.

    Breach Readiness for Measurable Risk Reduction in the Age of AI Cyber leaders no longer debate whether a breach will occur. What has changed is the speed and scale at which AI now enables those breaches. The real question is how far an attacker can move once inside. In this conversation, Rajesh Khazanchi explores why breach readiness, including AI-assisted containment, measurable blast radius reduction, and pervasive microsegmentation, has become mission-critical for business continuity in 2026.

    This segment is sponsored by ColorTokens. Visit https://securityweekly.com/colortokensrsac to learn more about them!

    Show Notes: https://securityweekly.com/psw-923

    2 hr 4 min
  • The AI "Vulnpocolypse" Is Real? - PSW #922

    This week:

    • CSA issues guidance to CISOs on Mythos
    • Vuln management woes
    • Windows tells you about Secure Boot
    • AI-assisted firmware vuln hunting
    • The dumbest hack
    • Edge decay and the failing perimeter
    • Mac OS X on a Wii
    • Little snitch comes to Linux
    • CPUID served malware
    • Buying plugins to backdoor them
    • Addicted to hacking
    • Is Mythos just a sales pitch?
    • We are still talking about Adobe Acrobat vulns
    • A single line AI jailbreak
    • Hacking Apple Intelligence
    • Don't leave your ICS device or RDP exposed to the Internet!

    Show Notes: https://securityweekly.com/psw-922

    2 hr 5 min
  • AI Makes All Bug Shallow? - PSW #921

    This week:

    • Rage dropping 0-Day
    • Claude Mythos, things are different now
    • From UART to root, on a device made in China, where's the FCC?
    • More CUPS vulnerabilities
    • Russians are hacking routers, FCC ban doesn't stop them
    • Mongoose vulnerabilities, and FCC still does nothing
    • Renting virtual phones
    • Iran's cyber attacks
    • SHA-256 almost broken?
    • Catching Axios
    • New Rowhammer, dubbed GPUBreach, gives you root
    • Windows 11 has sudo! (And SSH...)
    • And Inside a Kubernetes Scanning Fleet

    Show Notes: https://securityweekly.com/psw-921

    2 hr 5 min
  • What Is A Router? (And all things AI) - PSW #920

    In the Security News:

    • Claude leaks source code and new models
    • Two really smart people say AI is finding vulnerabilities better than ever
    • Windows is using your internet to send updates to strangers
    • BIG-IP APM vulnerability - all you need to know
    • Linux KVM for the win
    • The bus factor and open source
    • Axios supply chain breach
    • Trimming Grub
    • Depotting and hacking e-Motorcycles
    • Trivy and Cisco source code leaks
    • The FCC ban and What is a router?

    Show Notes: https://securityweekly.com/psw-920

    2 hr 6 min
  • Scanning The Internet with Linux Tools - PSW #919

    In this segment, we will explore some pretty awesome tools for scanning the Internet, with a focus on network edge devices. We'll bring it all together with Claude Code and look at some sample results. Tools include:

    • Shodan | Passive recon — query existing scan data for exposed devices, services, and vulns | Passive (API) | Instant (no packets sent)
    • ZMap | Host discovery — find live hosts with open ports | L4 (TCP SYN, UDP, ICMP) | Millions of packets/sec
    • ZGrab2 | Application-layer handshakes — grab banners, certs, headers | L7 (30+ protocol modules) | Thousands of hosts/sec
    • Nerva | Service fingerprinting — identify 140+ protocols with metadata, CPEs, technology stacks | L7 (TCP, UDP, SCTP) | Fast, concurrent
    • Nuclei | Template-based vulnerability scanning — default creds, exposed panels, known CVEs | L7 (HTTP, network) | Hundreds of targets/min
    • Shannon | Vulnerability exploitation — AI-powered whitebox pentesting of web apps | Application | ~1-1.5 hrs per target
    • edgescan.py | Automated pipeline — orchestrates all tools above into a single command | Orchestration | End-to-end

    Show Notes: https://securityweekly.com/psw-919

    1 hr 4 min
  • Hacking IP KVMs & Reversing with Radare2 - Sergi Àlvarez - PSW #918

    In this episode, we sit down with the Radare community leader, Pancake, the creator of the Radare2 reverse engineering framework. Whether you've never heard of Radare, already use it daily, or are thinking about contributing to its development, this conversation will demystify what makes Radare unique, why thousands of engineers rely on it, and how you can step into the community.

    This segment is sponsored by NowSecure. Discover how AI-powered mobile app security testing finds hidden vulns and leaks at https://securityweekly.com/nowsecure.

    In the security news:

    • The US national cyber strategy
    • in the category of dumb laws and 3d printing guns
    • Iranian threat analysis
    • ESP32 Bus Pirate gets some amazing updates
    • I can reset the admin password
    • Rick-rolling yourself
    • Chrome 0days
    • Re-purposing those old Ubiquiti cloud keys
    • The new TLS certificate lifecycle
    • A Flipper Zero add-on and news on the FlipperOne
    • glassword malware
    • Do you care about exploits or patching?
    • attacking nuclear research centers
    • how we uncovered 9 vulnerabilities in IP KVMs
    • and hacking your laundry card with Claude

    Show Notes: https://securityweekly.com/psw-918

    2 hr 11 min

About Paul's Security Weekly (Video)

From the publisher's feed

Where security veterans unpack the latest IT security news, vulnerabilities, and research through a historical and technical lens that can cut through even the thickest cigar smoke. Hosted by Paul…

More shows like Paul's Security Weekly (Video)

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

MacBreak Weekly (Video) by TWiT

MacBreak Weekly (Video)

363 Listeners

Security Now (Video) by TWiT

Security Now (Video)

148 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

Windows Weekly (Video) by TWiT

Windows Weekly (Video)

79 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

First Ring Daily by Paul Thurrott and Brad Sams

First Ring Daily

51 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

93 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners