Paul's Security Weekly (Video)

Paul's Security Weekly (Video)

By Paul AsadoorianTechnologyEducationHow To
Download on the App Store

Paul's Security Weekly (Video) episodes

  • Vulnerability Mis-Management - PSW #917

    In the security news this week:

    • The XZ backdoor documentary
    • Zero days - the clock isn't ticking
    • Vulnerability Mis-Management
    • Reversing traffic light controllers
    • Reversing with Claude
    • Don't curl to bash!
    • Reading CVEs makes my head hurt
    • Dumping browser secrets
    • I open-sourced a new(ish) tool
    • D-LINK exploits
    • There is no password
    • I control the building
    • When old vulnerabilities become new
    • Tile is for stalkers
    • Hacking AI
    • Iran War: What cybersecurity needs to know
    • National cyber strategy
    • Coruna
    • I got phished and I want a refund

    Show Notes: https://securityweekly.com/psw-917

    2 hr 4 min
  • Airsnitch, Claude, Hacking Firewalls - PSW #916

    In the security news this week:

    • Remembering "FX"
    • Finding and analyzing Windows drivers
    • Network monitoring with Gibson
    • the backdoor in your PAM
    • The edge is fraying - and attackers have the advantage
    • Age verification for Linux?
    • Banning AI
    • TPMS tracking
    • BLE tracking
    • weird strings
    • Airsnitch
    • RESURGE in and on Ivanti
    • Attackers using Claude
    • Government iPhone hacking kits
    • Cisco SD-WAN, Linux, and 2023
    • Leakbase leaks
    • and Bro, upgrade your solar panel!

    Show Notes: https://securityweekly.com/psw-916

    2 hr 4 min
  • AI Is Taking Over Cybersecurity - PSW #915

    First up is a technical segment called "Paul's Linux Hacks". I finally got around to releasing a bunch of scripts and tutorials for Linux that I've created over the years. We'll go over scripts that can give you a supply chain security report and help you update your Arch-based Linux systems and the tutorial for using Linux KVM/Qemu/Libvirt. Repo is here: https://github.com/pasadoorian/Linux_Hacks

    Next up is the security news:

    • Controlling 7,000 robot vacuums
    • Curl finds not all AI is bad
    • Palo Alto says "These are not the ties to China you were looking for"
    • Bloomberg writes an article that sheds light on Ivanti
    • Looking for BLE is a trend
    • Don't use AI to generate you passwords
    • New research on hacking Samsung TVs
    • Its not all about gadgets
    • Ring's new bug bounty
    • Paul will be voted in as Prime Minister of Denmark?
    • Hacking AI, AI does some hacking, and hackers are talking about AI

    Show Notes: https://securityweekly.com/psw-915

    2 hr 2 min
  • Firmware Backdoors Be Spying On You - PSW #914

    AI says that this is the show where we turn coffee into threat intelligence and cigar smoke into packet captures. This week:

    • a firmware backdoor living its best life inside Android tablets
    • a fresh BeyondTrust RCE that already has scanners circling like seagulls over a french fry.
    • Lenovo Vantage reminds us that "preinstalled convenience" is just another way to spell "attack surface."
    • Texas is taking a swing at TP-Link
    • supercomputers with a 20-year-old Munge bug that still has teeth.
    • Your AI coding assistant might be quietly squirreling away secrets
    • macOS gets a visit from an infostealer delivered as helpful add-ons
    • Chrome extensions allegedly spy on millions
    • open source maintainers drowning in AI-generated nonsense
    • Windows flirting with smartphone-style permission prompts.

    Put your passwords in a vault, not in a repo, and stay tuned for Paul's Security Weekly!

    Show Notes: https://securityweekly.com/psw-914

    2 hr 7 min
  • AI Vulnerability Hunting - PSW #913

    In the security news:

    • Viral AI prompts
    • Things to do in your home security lab
    • I can open your garage door
    • They call me DKnife
    • Beyondtrust RCE
    • Cool AI device
    • Robots need your body
    • Meta is just full of scams, phishing, and malware
    • Claude Opus 4.6 found more than 500 high-severity vulnerabilities
    • Arista next gen firewalls and command injection
    • Secure Boot updates
    • The RCE AMD won't fix and why the article went away
    • End of support means get it off the network
    • Accidentally giving away $44 billion of Bitcoin

    Show Notes: https://securityweekly.com/psw-913

    2 hr 5 min
  • AI: No One Is Safe - PSW #912

    In the security news this week:

    • Residential proxy abuse is everywhere this week: from Google's takedown of IPIDEA to massive Citrix NetScaler scanning and the Badbox 2.0 botnet
    • Supply chain fun time: Notepad++ updates were hijacked
    • Attackers set their sights on: Ivanti EPMM, Dell Unity storage, Fortinet VPNs/firewalls, and ASUSTOR NAS devices
    • Russian state hackers went after Poland's grid
    • Is ICE on a surveillance shopping spree and into hacking anti-ICE apps?
    • Ukraine's war-time Starlink problem is turning into a policy and controls experiment
    • The AI security theme is alive and well with exposed LLM endpoints, OpenClaw/Moltbot/Moltbook fiasco, and letting anyone hijack agents
    • Signed forensic driver for Windows is still an EDR killer
    • The Trump administration's rollback of software security attestation
    • National Cyber Director Sean Cairncross says: "less regulation, more cooperation."
    • Finally, there are some "only in infosec" human stories: * pen testers arrested in Iowa now getting a settlement, * a Google engineer convicted over stolen AI IP, * Booz Allen losing Treasury work over intentional insider leaks, * and an "AI psychosis" saga at an adult-content platform.

    Show Notes: https://securityweekly.com/psw-912

    2 hr 6 min
  • To curmudgeon or not to curmudgeon, that is the question. - PSW #911

    This week, we get un-curmudgeoned by Mandy, spending a bunch of time talking about regulations, compliance, and even the US federal government's commitment to cybersecurity internally and with the community at large. We even dive into some Microsoft patches, hacking defunct eScooters, and a lively discussion on ADS-B spoofing!

    Show Notes: https://securityweekly.com/psw-911

    2 hr 5 min
  • We Left It Vulnerable On Purpose - Rob Allen - PSW #910

    In the security news:

    • Rainbow tables for everyone
    • Lilygo releases a new T-Display that looks awesome
    • AI generated malware for real
    • Detecting BadUSB when its not a dongle
    • A telnetd vulnerability
    • Google Fast Pair and how I took control of your headset
    • Should we make CVE noise?
    • Exploiting the Fortinet patch
    • DIY data diode
    • Bambu NFC reader for your Flipper
    • Payloads in PNG files
    • Don't leave the lab door open - amazing research and new tool release
    • Fixing your breadboards
    • Finding vulnerabilities in AI using AI

    Then, Rob Allen from ThreatLocker joins us to discuss default allow, and why that is still a really bad idea.

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Show Notes: https://securityweekly.com/psw-910

    2 hr 17 min
  • Digging For Vulnerability Gold - PSW #909

    In the security news:

    • KVMs are a hacker's dream
    • Hacking an e-scooter
    • Flipper Zero alternatives
    • The best authentication bypass
    • Pwning Claude Code
    • ForiSIEM, vulnerabilities, and exploits
    • Microsoft patches and Secure Boot fun
    • Making Windows great, again?
    • Breaching the Breach Forum
    • Congressional Emails
    • unsolicited Instagram password reset requests - Is Meta doing enough to secure the platform?
    • LLMs are HIPAA compliant?
    • Threat actors target LLM honeypots

    Show Notes: https://securityweekly.com/psw-909

    2 hr 8 min
  • No FlipperZeros Allowed - PSW #908

    This week in the security news:

    • Supply chain attacks and XSS
    • PS5 leaked keys
    • Claude tips for security pros
    • No Flipper Zeros allowed, or Raspberry PIs for that matter
    • Kimwolf and your local network
    • Linux is good now
    • Removing unremovable apps without root
    • Detecting lag catches infiltrators
    • Defending your KVM
    • Fixing some of the oldest code
    • Deleting websites live on stage in costume
    • It was a honeypot
    • FCC is letting telecoms off easy
    • Don't buy a Haribo power bank
    • Ransomeware scum
    • Fortinet vulns
    • CISA warns about NVRs
    • Patching MongoDB

    Show Notes: https://securityweekly.com/psw-908

    2 hr 6 min

About Paul's Security Weekly (Video)

From the publisher's feed

Where security veterans unpack the latest IT security news, vulnerabilities, and research through a historical and technical lens that can cut through even the thickest cigar smoke. Hosted by Paul…

More shows like Paul's Security Weekly (Video)

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

MacBreak Weekly (Video) by TWiT

MacBreak Weekly (Video)

363 Listeners

Security Now (Video) by TWiT

Security Now (Video)

148 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

Windows Weekly (Video) by TWiT

Windows Weekly (Video)

79 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

First Ring Daily by Paul Thurrott and Brad Sams

First Ring Daily

51 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

93 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners