Paul's Security Weekly (Video)

Paul's Security Weekly (Video)

By Paul AsadoorianTechnologyEducationHow To
Download on the App Store

Paul's Security Weekly (Video) episodes

  • Updating & Protecting Linux Systems - PSW #877

    Two parts to this episode:

    • Tech Segment: Updating Linux Systems - Beyond apt-get upgrade * Custom scripts for ensuring your Linux systems are up-to-date * topgrade - tutorial for using topgrade to update Linux systems on various Linux distributions

    • Discussion Topic: Anti-Malware and/or EDR on Linux Platforms * PCI calls for scanning Linux systems * What tools exist for analyzing Linux systems? (AIDE, uac, chkrootkit) * Best Anti-Malware for Linux - Commercial tools, open-source, both, none? * ClamAV - fa-notify and the dangers

    Show Notes: https://securityweekly.com/psw-877

    1 hr 6 min
  • It's A Trap! - PSW #876

    In the security news:

    • Vicious Trap - The malware hiding in your router
    • Hacking your car
    • WSL is open-source, but why?
    • Using AI to find vulnerabilities - a case study
    • Why you should not build your own password manager
    • The inside scoop behind Lumma Infostealer
    • Hacking a smart grill
    • Hardcoded credentials on end of life routers and "Alphanetworks"
    • SIM swapping is still happening
    • LoRa for C2
    • Russian drones use Telegram
    • Flipper Zero mod for the LOLZ
    • Signal blocks Recall
    • CISA loses more people

    Show Notes: https://securityweekly.com/psw-876

    2 hr 3 min
  • Malware Laced Printer Drivers - PSW #875

    This week in the security news:

    • Malware-laced printer drivers
    • Unicode steganography
    • Rhode Island may sue Deloitte for breach. They may even win.
    • Japan's active cyber defense law
    • Stop with the ping
    • LLMs replace Stack Overflow - ya don't say?
    • Aggravated identity theft is aggravating
    • Ivanti DSM and why you shouldn't use it
    • EDR is still playing cat and mouse with malware
    • There's a cellular modem in your solar gear
    • Don't slack on securing Slack
    • XSS in your mail
    • SIM swapping and the SEC
    • Ivanti and libraries
    • Supercomputers in space!

    Show Notes: https://securityweekly.com/psw-875

    2 hr 2 min
  • Ransomware in your CPU - PSW #874

    This week in the security news:

    • Android catches up to iOS with its own lockdown mode
    • Just in case, there is a new CVE foundation
    • Branch privilege injection attacks
    • My screen is vulnerable
    • The return of embedded devices to take over the world - 15 years later
    • Attackers are going after MagicINFO
    • Hacking Starlink
    • Mitel SIP phones can be hacked
    • Reversing with Hopper
    • Supercharge your Ghidra with AI
    • Pretending to be an anti-virus to bypass anti-virus
    • macOS RCE - perfect colors
    • End of life routers are a hackers dream, and how info sharing sucks
    • Ransomware in your CPU
    • Disable ASUS DriverHub
    • Age verification and privacy concerns

    Show Notes: https://securityweekly.com/psw-874

    1 hr 59 min
  • Are You Down With RDP? - PSW #873

    Security news for this week:

    • RDP and credentials that are not really revoked, and some RDP bitmap caching fun
    • Some magic info on MagicINFO
    • Vulnerability Management Zombies
    • There is a backdoor in your e-commerce
    • Airborne: vulnerabilities in AirPlay
    • Bring your own installer - crafty EDR bypass
    • The Signal clone used by US government officials: shocker: has been hacked
    • AI slop vulnerability reporting
    • Bricking iPhones with a single line of code
    • Hacking planet technology
    • Vibe hacking for the win?
    • Cybersecurity CEO arrested for deploying malware
    • Hello my perverted friend
    • FastCGI - fast, but vulnerable

    Chapters:

    0:00 Opening and introductions 2:43 Panel introductions and conference recaps 4:46 Conference announcements and Corncon discussion 8:05 RSAC 2025 recap and vulnerability management trends 15:44 RDP credential revocation flaw in Windows 11 34:57 Apple AirPlay "wormable" vulnerabilities and third-party device risks 44:10 Signal clone breach used by US officials (TeleMessage incident) 55:38 Supply chain attack: Magento extensions backdoor 66:12 "Hello my perverted friend": Sextortion scam analysis 72:10 Security culture and phishing awareness at home 75:25 Digital signage vulnerabilities: Samsung MagicInfo 81:41 Threat hunting tradecraft and blue team operations 88:38 AI slop in vulnerability reporting and vibe hacking 98:59 Apple notification DoS and sandbox bypass 101:24 VMware licensing controversy and alternatives 107:14 CEO arrested for planting malware in hospital systems 116:06 FastCGI vulnerabilities in embedded/IoT systems 122:12 Rooting Android phones and device locking 124:08 Closing and outro

    Show Notes: https://securityweekly.com/psw-873

    2 hr 5 min
  • AI Tips, Tricks, and Traps! - PSW #872

    The PSW crew discusses tips, tricks, and traps for using AI and LLMs. We discuss a wide range of AI-related topics, including how to utilize AI tools for writing, coding, data analysis, website design, and more! Some key takeaways include:

    • AI has rapidly shifted from novelty to an essential tool in security and other fields.
    • Paid AI versions offer significant advantages for professionals.
    • Legal, ethical, and copyright questions around AI-generated content remain unresolved.
    • Human skills, critical thinking, communication, and adaptability are more important than ever.
    • AI is a powerful assistant, but not a replacement for expertise, creativity, or judgment.
    • Fact-checking AI outputs and understanding bias are critical in the age of generative AI.

    This episode offers a comprehensive, practical, and philosophical look at how AI is reshaping security, education, and society, providing both optimism and caution for the future.

    Show Notes: https://securityweekly.com/psw-872

    1 hr 38 min
  • Hacking Crosswalks and Attacking Boilers - PSW #871

    The crosswalk is talking to me man!, don't block my website without due process, Florida is demanding encryption backdoors, attacking boilers and banning HackRF Ones, time to update your flipper zero, using AI to create working exploits, what happens when you combine an RP2350 and an ESP32? Hopefully good hackery things!, more evidence that patching is not enough, auditing the PHP source code, reading the MEGA advisories, threat actors lie about data breaches (you don't say?), the data breach that Hertz, CISA warns of ransomware, some can't get Ahold of data breaches, please don't let people take control of your PC over Zoom and Paul's hot takes on: 4chan hack, the CVE program, and Microsoft Recall!

    Show Notes: https://securityweekly.com/psw-871

    2 hr 5 min
  • You Should Just Patch - PSW #869

    In the security news this week: You should really just patch things, the NVD backlog, Android phones with malware pre-installed, so convenient, keyloggers and a creepy pharmacist, snooping on federal workers, someone stole your browser history, NSA director fired, deputy director of NSA also fired, CrushFTP the saga continues, only steal the valid credit cards, another post that vanished from the Internet, hiding in NVRAM, protecting the Linux kernel, you down with MCP?, more EOL IoT, bypassing kernel protections, when are you ready for a pen test, red team and bug bounty, what EDR is really missing, and based on this story you should just patch everything all the time!

    Show Notes: https://securityweekly.com/psw-869

    2 hr 6 min
  • Not-So-Secure Boot - Rob Allen - PSW #868

    Rob Allen, Chief Product Officer at Threatlocker joins us for an interview segment on using AI in security products: What works and what's not fully baked! Then in the security news, There are more holes in your boot...loader according to Microsoft, related: Secure Boot is in danger and no one is really talking about it (still), Dear Microsoft: I don't want to send you my data, I don't grant you remote access, and I don't want to create a MS account, CrushFTP has to crush some bugs, bypassing unprivileged user namespace restrictions, FBI raids, attackers using your GPU, Find My anything, protecting GlobalProtect, the exploits will continue until things improve, your call records were not protected, good vs. bad drivers, AI is hacking AI, time traveling attacks, and a bizarre call for security researchers.

    This segment is sponsored by ThreatLocker. Visit https://www.securityweekly.com/threatlocker to learn more about them!

    Show Notes: https://securityweekly.com/psw-868

    2 hr 13 min

About Paul's Security Weekly (Video)

From the publisher's feed

Where security veterans unpack the latest IT security news, vulnerabilities, and research through a historical and technical lens that can cut through even the thickest cigar smoke. Hosted by Paul…

More shows like Paul's Security Weekly (Video)

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

MacBreak Weekly (Video) by TWiT

MacBreak Weekly (Video)

363 Listeners

Security Now (Video) by TWiT

Security Now (Video)

148 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

Windows Weekly (Video) by TWiT

Windows Weekly (Video)

79 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,061 Listeners

First Ring Daily by Paul Thurrott and Brad Sams

First Ring Daily

51 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

93 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners