Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • State of the AI SOC, regulating AI, and can AI agents feel pain? - Aqsa Taylor - ESW #479
    Interview with Aqsa Taylor

    Exaforce's Chief Security Evangelist, Aqsa, joins us to discuss the current state of the AI SOC and why it covers so much more than it did over 2 years ago, when our podcast first started covering this market. Exaforce also recently released AI Security and its ExaGo mobile app - we're very excited about the possibility of analyzing incidents at the grocery store!

    This segment is sponsored by Exaforce. Visit https://securityweekly.com/exaforce to learn more about them!

    Topic Segment - Regulating AI

    The AI industry's sandbox escapes have had a big impact on everyone and unsurprisingly, there's a bill proposing to ban some AI products and pause the development of others.

    It seems that, increasingly, as pro-AI and anti-AI groups become more polarized and divided, you could start an entire podcast that does nothing but fact-check both sides. We're an emotional species and it seems the more heated debate gets, the more folks on both sides are willing to straight-up fabricate things to help argue their points.

    Today's focus is this YouTube video: https://www.youtube.com/watch?v=WXsTCJl7sU4

    It's the most on-the-nose type of propaganda - straight up claiming the government is going to break into your house and take your GPUs and LLMs. Could the bill proposed by Bernie Sanders and Greg Casar be characterized as extreme? Sure, but it's nowhere near as extreme as the title of the video, "They're Banning AI Servers at Home" suggests.

    The hardest things to swallow about the video:

    1. it characterizes Bernie Sanders as "the government", as if he's representative of most of the US government rather than an outlier that has little to no chance to get a bill like this passed
    2. it never mentions the fact that the bill establishes a model cutoff, measured in training effort (10^25 flops, which doesn't include the open weight models you're using at home, unless you have an 8x cluster of DGX Sparks - $40k+ worth of AI compute)
    Enterprise News

    Finally, in the enterprise security news,

    1. we check the vibes
    2. massive, connected funding
    3. NVIDIA OpenShell
    4. cars are still hackable
    5. a ransomware arrest turned into a murder investigation
    6. AI welfare

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-479

    1 hr 44 min
  • RAM, Muse, CloudSyncD, Springsteen, Software, Persistence, and Michael Jenkins - Michael Jenkins - SWN #621

    RAM, Muse, CloudSyncD, Springsteen, Who Owns Your Software?, Persistence, Michael Jenkins, CTO of ThreatLocker, and More on this episode of the Security Weekly News.

    Segment Resources: https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Visit https://www.securityweekly.com/swn for all the latest episodes!

    Show Notes: https://securityweekly.com/swn-621

    38 min
  • Hacking Without Boundaries - Michael Jenkins - PSW #946

    First up we talk with Threatlocker CTO Michael Jenkins about threat actors use of AI and keeping the bad things out with Zero Trust. Then in the security news:

    • Compiling spreadsheets, because that's why
    • Nvidia wants to put AI agents in timeout
    • Citrix NetScaler gets exploited again, and again
    • Spectre still refuses to die
    • Your SBOM is incomplete?
    • File notifications leak more than filenames
    • ENIAC had cables instead of a BIOS
    • Another Linux kernel root exploit lands
    • Containers share a kernel
    • ThinkNode M9 microSD card gets a virus notice
    • Google analyst infiltrates a supply-chain gang
    • Your phone speaker can transmit radio
    • Reconstructing firmware with a logic analyzer
    • Robot dogs learn cybersecurity
    • CISA warns about third-party ICS integrators
    • Dutch police arrest a ShinyHunters suspect
    • A soldier goes from telecom hacking to prison
    • AI companies discover their agents have opinions
    • Cloudflare containers accidentally share leftovers
    • OT networks are still mostly not isolated
    • Florida wants to pause ChatGPT

    The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-946

    2 hr 2 min
  • Defending at AI Speed as Quantum Threats and AI Policies Won't Save You - Nolan Karpinski - BSW #467

    At a time when the traditional approach to enterprise vulnerability management is no longer effective, security leaders are turning to AI agents to help identify, validate, and contain zero-day threats. Learn how Google Cloud Security is building autonomous detection engineering to help your organization close the remediation gap, establish compensating controls to protect business assets, and outpace AI-powered adversaries.

    Segment Resources:

    https://services.google.com/fh/files/misc/monitoringandstoppingaipowered_threats.pdf https://cloud.google.com/blog/products/identity-security/detecting-and-containing-powered-threats-with-google-security-operations-agents?e=48754805

    This segment is sponsored by Google Cloud. Visit https://securityweekly.com/googlecloud to learn more about them!

    In the leadership and communications segment, CISOs can no longer ignore the nation-state threat, AI Policies Won't Save You If You Can't See The Risk, The Invisible Work Draining Your Best Employees , and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-467

    55 min
  • Going From Bug Bounty Bugs to More Secure Systems - Shlomie Liberow - ASW #402

    Finding flaws with LLMs and agents is changing bug bounty programs. But it's not necessarily changing how orgs fix those flaws. Shlomie Liberow shares his experience across a decade of bounty programs and how they have changed for researchers and orgs. He explains why fixing the bug reported through a bug bounty is more about understanding interconnected systems than fixing a single piece of software. We discuss how orgs can be more effective at securing their environment and what role LLMs might have in evaluating controls. Plus, we look to the future of bug bounty programs and how researchers can still excel through curiosity and expertise on a topic rather than relying on scanners, prompts, and luck.

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-402

    1 hr 3 min
  • Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keeper - Kaushik Shanadi, Josh Davies, Tricia Howard, Christopher Crowley, Darren Guccione - ESW #478
    Interview with Christopher Crawley - The Value of SecOps

    This week, we talk to Chris Crawley about his new book, The Value of Cybersecurity Operations. Chris has been training teams on security operations for years, but found that students often struggled to justify the importance of secops training and even the need for secops in general. This book was written to more broadly arm practitioners with the information they need to communicate why security operations are necessary to leadership.

    The book is available in several forms: eBook, hardcover, softcover, and an audiobook read by Chris himself!

    You can pick all versions up here: https://shop.montance.com/collections/all and Security Weekly listeners get 50% off with code sw-50!

    The Evolving Exploitation of Trust with Josh Davies, Security Strategist at Fortra

    Fortra Intelligence and Research Experts (FIRE) is Fortra's emergent threat intelligence identity, created to unify research teams across multiple security disciplines and share intelligence with the wider threat intelligence community. FIRE co-ordinator and security strategist Josh Davies joins us to share insights from original FIRE research like Calphishing, Mirage2FA, RatPressto phishkit and heavily obfuscated campaigns that evade defences. While also digging into trends from big data analysis within phishing, fraud, social engineering and credential theft.

    Segment Resources:

    • Art of Security Podcast
    • Fortra Research

    This segment is sponsored by Fortra. Access FIRE Research here: https://securityweekly.com/fortrabh

    Why Agentic AI Security Requires a Defense-In-Depth Strategy with Kaushik Shanadi, CTO and Co-Founder of Helmet Security

    Many organizations are approaching agentic AI security by stitching together individual controls, assuming that identity, network, endpoint, or application security alone is enough. Each address only one part of the problem. As AI agents become more autonomous, move across systems, and take actions on behalf of users, organizations need a true defense-in-depth strategy that combines every layer of the security stack. Kaushik can discuss how each security layer provides a different piece of the puzzle and how individually, none of the controls are sufficient. But together, they create the layered governance needed to securely deploy agentic AI.

    For more information about Helmet Security, please visit https://securityweekly.com/helmetbh

    Above Security on Why Legacy Tools Don’t Cut It for Modern Insider Risk with Tricia Howard, Head of Marketing at Above Security

    As organizations rush to adopt agentic AI, agents are often given broad access to critical business systems and sensitive data. Legacy insider risk management tools weren't built for this, and organizations have spent years on insider risk posturing and investments that leave security teams inundated with false positives while the real risk slips through undetected. In this segment, Tricia Howard draws on her decade in cybersecurity, including years watching user and entity behavior analytics (UEBA) overpromise and underdeliver, to unpack why understanding human – and now AI – intent is the missing piece.

    Segment Resources:

    • Blog Post: Redefining Insider Threat
    • Blog Post: What I wanted UEBA to be, Years Ago

    To learn more about Above Security and insider risk management in the era of agentic AI, visit: https://securityweekly.com/abovebh

    The Identity Crisis Your Security Team Didn't See Coming: Governing AI Agents with Darren Guccione, CEO and Co-Founder of Keeper Security

    AI agents outnumber human identities in enterprise environments, and traditional security software was never built to govern them. 89% of cybersecurity decision-makers recently surveyed by Keeper Security said that AI adoption has made identity management harder.

    In this Black Hat USA conversation with Cyber Risk TV, Darren Guccione, CEO and Co-Founder of Keeper Security, shares a practical framework for extending identity governance to non-human identities and AI agents before the access gap becomes a breach.

    Segment Resources:

    • Privileged Access Management
    • Identity Security at Machine Speed

    To learn more about Keeper Security, visit: https://securityweekly.com/keeperbh

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-478

    1 hr 38 min
  • AI Will Save Us, or Not? - PSW #945

    In the security news this week:

    • Build your own router, or just buy one
    • What to patch first
    • But maybe don't buy D-Link
    • AI nearly starts a war
    • Flock cameras lose their keys
    • The AI slowdown won’t save bad security
    • Opus at home, just slower
    • Black Hat says fundamentals still work
    • Hacker gadgets, and my top pick
    • Gyazo screenshots
    • Fake job interviews, real malware
    • VINCE gets a new home
    • Munich university gets disconnected
    • LinkedIn fights the scraping machine
    • SolarWinds hard-codes another bad idea
    • Fake LastPass kills 145 security tools
    • Colorado water gets its settings changed
    • AI CEOs sell apocalypse and bonds
    • The AI safety cult gets audited
    • Ransomware recovery takes weeks, not hours
    • TeamPCP’s supply-chain tour continues
    • Zuckoff hunts smart glasses

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-945

    2 hr 4 min
  • Balancing AI Benefits and Risks as Your Next CISO Could be Artificial Intelligence - Evan McHenry - BSW #466

    As businesses race to embrace AI, security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. How do you balance the benefits of AI with the Risks of AI?

    Evan McHenry, Chief Information Security Officer at Robinhood Markets, joins Business Security Weekly to discuss how to practically implement and secure AI in the enterprise. Evan will share his lessons learned over the last 18 months, including how to communicate with the Board, why you should own Enterprise Architecture and embrace IT, and why you don't have time to argue with your CFO. If you're struggling to balance the benefits of AI with the Risks of AI, this interview is for you.

    In the leadership and communications segment, Security spending is growing — except for the typical CISO, What Leaders Need to Know About AI and Psychological Safety, The Cyber Gap, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-466

    58 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,056 Listeners

Planet Money by NPR

Planet Money

30,692 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,626 Listeners

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,062 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

960 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners