Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401

    Prompt injection demonstrates one of the major challenges in securing LLMs and agents -- how do you ensure an agent ignores attackers and only does what you instructed it to do. The flaw highlights how LLMs mix inputs, context, and outputs without any strict boundaries between them. Julie Brunias joins us to talk through examples of injections, why their consequences can go beyond information leaks, and why trying to mitigate them with other LLMs is insufficient.

    Segment resources:

    • https://llmgateway.io/open-source
    • https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-401

    1 hr 1 min
  • Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477
    Interview with Rob Sadowsky from Cohesity

    Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment

    Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be understood, dependencies mapped, recovery could follow a predictable sequence, and decision-makers would have enough information to act.

    In practice, major cyber incidents unravel those assumptions. AI and autonomous agents are creating new paths to compromise, while cloud and SaaS expansion increases the systems, services, and dependencies involved in recovery. Vulnerabilities are discovered and weaponized faster than ever, and AI is accelerating that cycle. As incidents unfold, scope expands, dependencies appear only when they break, and recovery plans no longer match reality.

    With assumptions under greater strain, confidence is beginning to erode. This year, the percentage of survey respondents reporting complete confidence in their cyber resilience strategy fell.

    To understand how recovery unfolds today, Cohesity commissioned Vanson Bourne to survey 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries.

    This report examines where recovery becomes more difficult than expected, the obstacles organizations encounter, how they define and test a Minimum Viable Company (MVC), and how AI is reshaping cyber threats and cyber resilience.

    https://www.cohesity.com/dm/global-cyber-resilience-report/

    This segment is sponsored by Cohesity. Visit https://securityweekly.com/cohesity to learn more about them!

    Topic: When should we use AI for writing and when should we avoid it?

    I've had an essay in draft form for a month now, trying to get my feelings across on why AI writing drives me so crazy. I struggled to put it into words.

    Fortunately, Charity Majors figured out how to put it into words and I think she nailed not just how I feel about AI, but the reasons why I feel so strongly about it. She uses a scale to help explain this, with "personal" at one end and "functional" at the other.

    https://charity.wtf/p/confessions-of-an-unrepentant-slop

    When I ask AI to create a company profile for me, 10 minutes before I meet with them, I don't need poetry - just facts. But when I read something that is supposedly someone's opinions and analysis on a topic, and it's clearly 100% AI-generated, I angrily dismiss it.

    I love that this writeup isn't just an "I hate slop" rant - it actually quantifies why a personal touch matters and how to gauge when it is necessary and when outsourcing the task to AI is totally fine.

    In both cases, Charity notes that quality matters. My most recent complaints come from cases where things are not only clearly written by AI, but where quality went out the window and they're unrecognizable as a human-readable language.

    And yes, I brought an example: https://dispatch.cybersecurityhq.com/p/escalation-voided-on-construct-failure-timing-condition-placed-under-review

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We check the vibes, funding, and acquisitions
    2. Tenable now has Mythos built-in???
    3. We check in on how vulnerability remediation is going
    4. Microsoft is creating a code of conduct for AI
    5. OpenAI just got called to the principal’s office
    6. Booz Allen created new cybersecurity AI benchmarks
    7. 50% of CISOs see Mythos as a sign to resign???
    8. Ayman read the latest Anthropic AI misuse report
    9. MIT explains the 12 possible AI outcomes (very ominous)
    10. a 9-year old decided to promote his YouTube account… with his dad’s corporate card

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-477

    1 hr 38 min
  • AI hates CAPTCHAs - PSW #944

    In the security news this week:

    • UK government rolls out passkeys to 20 million users
    • Phishing-resistant authentication and replay resistance
    • Passkey adoption, device security, and user acceptance
    • EU Cyber Resilience Act guidance, scope, and compliance
    • CRA vulnerability disclosure and reporting requirements
    • The real cost of cyberattacks and cybersecurity spending
    • Cyber insurance and improving organizational security
    • Nightmare Eclipse and the release of Windows zero-days
    • Check Point VPN vulnerabilities and perimeter security
    • GitLab security updates and shadow IT
    • Discovering unmanaged GitLab instances
    • Cyberattacks against oil tankers and insider threats
    • VPN patching and implied rules
    • Zero-downtime GitLab updates and version management
    • Running Windows ARM on Apple Silicon with VMware and Parallels

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-944

    2 hr 5 min
  • Followership, CyberSecurity Leadership, and Judgement as a Defining Skill - Kenyada Meadows - BSW #465

    The overwhelming majority of people, across the full span of their professional lives, operate without formal authority over the domains in which they work (i.e., leadership). Yet followership has almost no sustained literature, no targeted development, and no rigorous framework of its own. If you're not a leader, what does a follower look like?

    Kenyada Meadows, CEO & Founder at The Executive Parent Company, joins Business Security Weekly to discuss his book, The PASSENGER Seat, which outlines a framework for followership. Kenyada will outline the nine disciplines of the framework across three dimensions, including:

    • (P) Principled Anchoring — Holds values explicitly and specifically enough to guide behavior under pressure; knows the limit line before reaching it.
    • (A) Accountability — Communicates upward honestly, documents concerns before decisions are made, and owns errors without deflection.
    • (S) Self-Mastery — Invests deliberately in work, home, and inner domains, so identity — and ethical agency — isn't hostage to institutional threat.
    • (S) Systems Thinking — Reads the institution analytically — what produces the patterns observed, and where honest information is being filtered.
    • (E) Emerging Risk Management — Functions as an early-warning system for risks that formal frameworks haven't yet named.
    • (N) Negotiation — Translates insight and values into institutional impact through credibility, framing, coalition, and timing. -(G) Guardianship — Protects what the institution stands for over time, especially when no one is watching.
    • (E) Enablement — Ensures influence strengthens collective capacity rather than merely advancing individual position.
    • (R) Results-Driven Influence — Binds the other eight disciplines toward outcomes that are genuinely better — not merely visible.

    In the leadership and communications segment, Stop playing with the CISO role. Fix cybersecurity leadership, What CIO-CISO alignment looks like when it's working, Why judgment is emerging as cybersecurity’s defining skill, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-465

    58 min
  • The AI Threat Multiplier: Securing Mobile Apps in the Automated Era - Ryan Lloyd, Jason Cortlund - ASW #400

    While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jason Cortlund break down how threat actors leverage LLMs as a force multiplier to accelerate mobile app attacks. Then we discuss actionable defense strategies, from viewing agents as an active adversary to leveraging server-side threat telemetry, attestation, and layered defense strategies combined with polymorphic code releases.

    This segment is sponsored by Guardsquare. Visit https://securityweekly.com/guardsquare to learn more about them!

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-400

    53 min
  • Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. - Snehal Antani - ESW #476
    Interview with Snehal Antani

    Snehal Antani, CEO and co-founder of Horizon3 joins us to talk about how automated validation can help with exposure management. As vulnerability counts spike, security teams are looking for a way to prioritize. Automated penetration testing offers a way to quickly separate exploitable vulnerabilities from the rest.

    This segment is sponsored by Horizon3. Visit https://securityweekly.com/horizon3 to learn more about them!

    Topic Segment - SmartTVs and Privacy

    For this week's topic segment, we explore privacy and TVs. LG has been in the news for allegedly collecting data from its customers, but the facts are unclear.

    We share our recent experiences and dive into some of the primary concerns and theories about what's going on here.

    If you want to opt out of some of your TV's data collection, Consumer Reports has a collection of instructions for a variety of TV platforms.

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We check the vibes
    2. We check finding and acquisitions
    3. Nightmare Eclipse or Good Night of Sleep Eclipse?
    4. Update on Anthropic’s Glasswing project
    5. How long would it take for a mobile phone worm to spread?
    6. Don’t expose SSH to the public Internet
    7. Massive amounts of cryptocurrency continue to get stolen
    8. Did you actually read your third party’s SOC 2?
    9. Your boss may be reading your AI chat history

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-476

    1 hr 41 min
  • 9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615

    Twenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on.

    Then we get to work.

    Shift-left didn't fail. The starting line moved. AI coding agents now read the issue, write the code, pick the dependencies and open the pull request — so the earliest trust boundary isn't your first commit any more, it's the moment an agent gets context and authority. Most of us haven't moved our controls with it.

    Unit 42 pull the lid off a pay-per-install operation running out of eleven gaming YouTube channels, with over ten thousand loader samples underneath it. Every layer built to look too boring to escalate. When your analyst closes that alert as adware, they may have just closed three separate compromises.

    Google's threat tracker: a credential-harvesting campaign built and run in under six hours, with Markdown files as attacker playbooks. And malware carrying prompt-injection text designed to make your LLM scanner refuse to look at it — because a refusal that reads as "clean" is a free pass.

    A CVSS 10 in Gemini CLI that never touched the model. No prompt, no injection, no tool call. The attacker just turned up before the sandbox did.

    The first ever Take It Down Act sentencing — handled carefully, with what you actually do if someone tells you something, and a proper shout-out to Dale, the Cyber Safety Guy, whose work every parent with a teenager online should have bookmarked.

    Two hundred and sixty-three million dollars walks out of a Bitcoin sidechain and then walks back in. Nobody stole the keys. They just convinced the system to sign a lie.

    Anthropic's 154-page threat report. And an alignment lead who puts extinction odds above ten percent.

    All that, plus Josh Marpet's take, on Security Weekly News #615.

    Visit https://www.securityweekly.com/swn for all the latest episodes!

    Show Notes: https://securityweekly.com/swn-615

    35 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,056 Listeners

Planet Money by NPR

Planet Money

30,692 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,626 Listeners

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,062 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

960 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners