Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • ESW #297 - Tony Karam, Dan Frechtling

    Infrastructure-as-code (IaC) allows for quick and consistent configuration and deployment of infrastructure components because it’s defined through code. It also enables repeatable deployments across environments. IaC is seeing significant attention in the cloud security space, but why now? This conversation will dig into how Infrastructure-as-code is enabling faster innovation on application development with security built in.

    Segment Resources:

    - https://www.lacework.com/solutions/infrastructure-as-code/

    - https://www.lacework.com/blog/introducing-secure-automated-iac-deployments-with-terraform/ 

    - https://info.lacework.com/cloud-threat-report.html 

     

    We catch up on 2 weeks of news, starting with 18 funding rounds and several new products! Splunk acquires Twinwave Another ASM vendor, Templarbit, gets acquired into the Cyberinsurance industry, InfoSec Layoffs continue in a big way alongside huge cuts at Facebook, Twitter, and Amazon, Microsoft sued for stealing code to train GitHub Copilot, Google sued for tracking when users asked them not to, Apple sued for violating privacy when users asked them not to, Taking away kids’ smartphones, Stealing passwords from Mastodon, Should Cryptocurrency die in a fire? All that and more, on this episode of Enterprise Security Weekly.

     

    This segment will focus on (1) Why Did Sephora Get Fined $1.2M and Why Are They on Probation? (2) Why Data Privacy is Being Overhauled in 2023 (and How You Can Be Ready)

    Segment Resources:

    - https://www.consumerreports.org/electronics-computers/privacy/i-said-no-to-online-cookies-websites-tracked-me-anyway-a8480554809/

    - https://www.geekwire.com/2022/the-bittersweet-serendipity-that-gave-these-two-startup-leaders-a-shared-mission-in-online-privacy/

    - https://www.boltive.com/blog/why-having-a-consent-management-platform-is-not-enough

    - https://www.boltive.com/blog/bracing-for-2023-privacy-laws

    - https://ceoworld.biz/2022/07/03/three-ways-your-data

     

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/esw297

    2 hr 26 min
  • PSW #764 - Jesse Michael

    In the Security News: Stealing Mastodon passwords, reporting vulnerabilities in open-source privately, labeling does not solve problems, or does it? will it every get patched? geolocating people from photos, no meta-data required, update your firmware on Linux, hacking flow computers, when a driver isn't really a driver, well, its a driver, but not the one you may be thinking of, oops I leaked it again, misconfiguration leads to compromise, harden runner, guard dog and hacking spacecraft via Ethernet! Navigating the UEFI waters is treacherous. While UEFI has become the standard on most PCs, servers, and laptops, replacing legacy BIOS, it is a complex set of standards and protocols. Jesse joins us to help explain how some of this works and describe how vulnerabilities, specifically with SMM, can manifest and be exploited.

    Segment Resources:

    [CHIPSEC GitHub] https://github.com/chipsec/chipsec 

     

    Visit https://www.securityweekly.com/psw for all the latest episodes!

     

    Visit https://securityweekly.com/acm to sign up for a demo or buy our AI Hunter!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/psw764

    3 hr 36 min
  • ASW #220 - Daniel Krivelevich

    CosMiss in Azure, $70k bounty for a Pixel Lock Screen bypass, finding path traversal with Raspberry Pi-based emulators, NSA guidance on moving to memory safe languages, implementing phishing-resistant MFA, egress filtering, and how to approach code reviews

     

    Cider Security’s recently published research of the Top 10 CI/CD Security Risks acts to identify vulnerabilities to help defenders focus on areas to secure their CI/CD ecosystem. They created a free learning tool with a deliberately vulnerable environment to demonstrate these flaws -- “CI/CD Goat”. Like similar tools, this helps appsec and devops teams gain a better understanding of major CI/CD security risks and, importantly, their appropriate countermeasures.

    Segment Resources:

    - https://www.cidersecurity.io/top-10-cicd-security-risks/

    - https://github.com/cider-security-research/top-10-cicd-security-risks

    - https://www.cidersecurity.io/blog/research/ci-cd-goat/

    - https://github.com/cider-security-research/cicd-goat

     

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/secweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/asw220

    1 hr 28 min
  • SWN #256 - Billbug, Pushwoosh, Github, FTX, Eli Lilly, & Peter Klimek

    This week Dr. Doug talks: Billbug, Pushwoosh, GitHub, FTX, K-12 schools without security, say it isn't so, Eli Lilly, and is joined by Peter Klimek for Expert Commentary! All that and more on the Security Weekly News!

    This segment is sponsored by Imperva. Visit https://securityweekly.com/imperva to learn more about them!

     

    Visit https://www.securityweekly.com/swn for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/swn256

    32 min
  • BSW #285 - John Grancarich, Mike Devine

    In the leadership and communications section, Is Your Board Prepared for New Cybersecurity Regulations?, 32% of cybersecurity leaders considering quitting their jobs, 40 Jargon Words to Eliminate from Your Workplace Today, and more!

     

    Positive change is coming to cybersecurity. In this segment, Mike Devine (CMO) and John Grancarich (EVP of Strategy) at Fortra discuss the business of leading a cybersecurity company, the reasons behind our recent rebrand, and our plans for continuing as a people-first company that collaborates with our customers to combat the threat landscape with confidence.

    This segment is sponsored by Fortra. Visit https://securityweekly.com/fortra to learn more about them!

     

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/bsw285

    1 hr 6 min
  • SWN #255 - Twitlegit, Liability, Venus, Stego , C++ Death Knell, & Cisa - Wrap Up

    This week in the Security News: Twitlegit, Liability, Venus, Steganography, C++ death knell, the EU, CISA, and show Wrap-Ups on this edition of the Security weekly News!

     

    Visit https://www.securityweekly.com/swn for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/swn255

    30 min
  • ESW #296 - Travis Spencer, Sounil Yu, Brian Markham, Robert Graham, Rich Friedberg

    Don’t leave the door open. Modern systems are complex and require you to consider many aspects. Here are some aspects we consider critical:

    - APIs are the dominant software development direction/trend. Traditional/legacy ways to grant access is not fit for purpose of protecting this new way of delivering products and services.

    - Customers are demanding better digital experiences. To maintain a competitive edge and drive brand loyalty businesses need to provide great online experiences.

    - Standards (such as OAuth and OpenID Connect) are important to ensure high-security levels. Also enables scalability and helps future-proof your infrastructure. For example in the financial sector, these standards play a key role in the drive toward open banking.

    - A modern architecture is a zero trust architecture. In a zero trust architecture, the new perimeter hinges on identity.

     

    Segment Resources:

    https://thenewstack.io/zero-trust-time-to-get-rid-of-your-vpn/

    This segment is sponsored by Curity. Visit https://securityweekly.com/curity to learn more about them!

     

    In this panel discussion, we'll discuss the polarizing case of Joe Sullivan that has rattled the CISO community. Was the Sullivan case a rare anomaly? Were his actions in this scenario typical or unconscionable for the average CISO? Is it okay for Sullivan to take the fall while the rest of Uber and involved parties plead out with little to no punishment?

    We'll tackle all these questions and more with our excellent panel, comprised of:

    Sounil Yu, CISO and Head of Research at JupiterOne

    Brian Markham, CISO at EAB

    Rich Friedburg, CISO at Live Oak Bank

    Robert Graham, Owner at Errata Security 

     

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/esw296

    2 hr 11 min
  • PSW #763 - Dan DeCloss

    Every penetration test should have specific goals. Coverage of the MITRE ATT&CK framework or the OWASP Top Ten is great, but what other value can a pentest provide by shifting your mindset further left or with a more strategic approach? How often do you focus on the overall ROI of your penetration testing program? This talk will explore what it means to “shift left” with your penetration testing by working on a threat informed test plan. Using a threat informed test plan will provide more value from your pentesting program and gain efficiency in your security testing pipeline. This talk applies to both consultants and internal security teams.

    Segment Resources:

    Hack Your Pentesting Routine WP: https://plextrac.com/resources/white-papers/hack-your-pentesting-routine/

    Effective Purple Teaming WP: https://plextrac.com/effective-purple-teaming/

    This segment is sponsored by PlexTrac. Visit https://securityweekly.com/plextrac to learn more about them!

     

    In the Security News: submerged under blankets in a popcorn tin is where they found it, Indirect Branch Tracking, don't hack me bro, we're here from the government to scan your systems, Fizzling out security, static and dynamic analysis for the win, BYODC, Bring your own domain controller, application context matters, if you want an update better have an Intel CPU, one-time programs, urlscan is leaking, hacking load balancers, and its all about the company you keep.

     

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Visit https://securityweekly.com/acm to sign up for a demo or buy our AI Hunter!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/psw763

    3 hr 28 min
  • BSW #284 - Meritt Maxim, Rafal Los

    Threat actors use automation and technology to do evil at scale. Yet, even with cutting edge technology available to them, smaller organizations feel overwhelmed. Analysts struggle from the “alt-tab, swivel-chair” problem, and security products just don’t feel… powerful. So how does a SOC maximize its most valuable asset–the humans–in combination with technology to overachieve? This talk will teach you a new way to model out your team's resources, assets, and capabilities to defend against various levels of adversaries to determine where you have operational capability, where you have gaps, and how to tell the difference.

    This segment is sponsored by ExtraHop Networks. Visit https://securityweekly.com/extrahop to learn more about them!

     

    After years of increases, security budgets are coming under scrutiny. Cybersecurity professionals need practical guidance on how to manage existing budget allocations and new requests for funding. This segment provides Forrester's spending benchmarks, insights, and recommendations to future-proof your security investments in ways that keep you on budget while simultaneously mitigating the risks facing your organization.

    Segment Resources:

    https://www.forrester.com/blogs/new-security-risk-planning-guide-helps-cisos-set-2023-priorities/

     

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/bsw284

    1 hr 6 min
  • SWN #254 - Exploding Heads, Mastodon, Azov Wiper, Zlibrary, & Nervegear Irl

    This week Dr. Doug talks: Exploding heads, Mastodon, James Zhong, Azov, Zlibrary, Siemens and Schneider, Chinese AI, Jason Wood, and more on the Security Weekly News!

    Visit https://www.securityweekly.com/swn for all the latest episodes!

    Follow us on Twitter: https://www.twitter.com/securityweekly

    Like us on Facebook: https://www.facebook.com/secweekly

     

    Show Notes: https://securityweekly.com/swn254

    30 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

31,996 Listeners

Planet Money by NPR

Planet Money

30,703 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,608 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

506 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

652 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

420 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,058 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

959 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners