Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • Developing Open Source Skills for Maintaining Projects - Kat Cosgrove - ASW #361

    Open source projects benefit from support that takes many shapes. Kat Cosgrove shares her experience across the Kubernetes project and the different ways people can make meaningful contributions to it. One of the underlying themes is that code is written for other people. That means PRs need to be understandable, discussions need to be enlightening, documentation needs to be clear, and collaboration needs to cross all sorts of boundaries.

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-361

    1 hr 4 min
  • Illuminating Data Blind Spots, Topic, Enterprise News - Tony Kelly - ESW #437
    Interview Segment: Tony Kelly

    Illuminating Data Blind Spots

    As data sprawls across clouds and collaboration tools, shadow data and fragmented controls have become some of the biggest blind spots in enterprise security. In this segment, we’ll unpack how Data Security Posture Management (DSPM) helps organizations regain visibility and control over their most sensitive assets.

    Our guest will break down how DSPM differs from adjacent technologies like DLP, CSPM, and DSP, and how it integrates into broader Zero Trust and cloud security strategies. We’ll also explore how compliance and regulatory pressures are shaping the next evolution of the DSPM market—and what security leaders should be doing now to prepare.

    Segment Resources:

    https://static.fortra.com/corporate/pdfs/brochure/fta-corp-fortra-dspm-br.pdf

    This segment is sponsored by Fortra. Visit https://securityweekly.com/fortra to learn more about them!

    Topic Segment: We've got passkeys, now what?

    Over this year on this podcast, we've talked a lot about infostealers. Passkeys are a clear solution to implementing phishing and theft-resistant authentication, but what about all these infostealers stealing OAuth keys and refresh tokens? As long as session hijacking is as simple as moving a cookie from one machine to another, securing authentication seems like solving only half the problem. Locking the front door, but leaving a side door unlocked.

    After doing some research, it appears that there has been some work on this front, including a few standards that have been introduced:

    1. DBSC (Device Bound Session Credentials) for browsers
    2. DPoP (Demonstrating Proof of Possession) for OAuth applications

    We'll address a few key questions in this segment: 1. how do these new standards help stop token theft? 2. how broadly have they been adopted?

    Segment Resources:

    • FIDO Alliance White Paper: DBSC/DPOP as Complementary Technologies to FIDO Authentication
    News Segment

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-437

    1 hr 50 min
  • Tech Segment: MITM Automation + Security News - Josh Bressers - PSW #904

    This week in our technical segment, you will learn how to build a MITM proxy device using Kali Linux, some custom scripts, and a Raspberry PI! In the security news:

    • Hacking Smart BBQ Probes
    • China uses us as a proxy
    • LOLPROX and living off the Hypervisor
    • Are we overreating to React4Shell?
    • Prolific Spyware vendors
    • EDR evaluations and tin foil hats
    • Compiling to Bash!
    • How e-waste became a conference badge
    • Overflows via underflows and reporting to CERT
    • Users are using AI to complete mandatory infosec training!
    • AI in your IDE is not a good idea
    • Cybercrime is on the rise, and its the kids
    • AI can replace humans in power plants
    • Will AI prompt injection ever go away?
    • To use a VPN or to not use a VPN, that is the question

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-904

    2 hr 8 min
  • Salesforce Security Risks, Boards Duty of Care, and Managing CISO Risks - Justin Hazard - BSW #425

    Organizations rely heavily on Salesforce to manage vasts amounts of sensitive data, but hidden security risks lurk beneath the surface. Misconfigurations, excessive user permissions, and unmonitored third party integrations can expose this data to attackers. How do I secure this data?

    Justin Hazard, Principal Security Architect at AutoRABIT, joins Business Security Weekly to discuss the security challenges of Salesforce. Justin will discuss how proactive oversight and a strong security posture in Salesforce requires additional capabilities, including:

    • Continuous monitoring of your Salesforce environment,
    • Strict access controls of Salesforce users, and
    • Automated backup of sensitive data.

    Think your data in Salesforce is safe and secure, think again.

    This segment is sponsored by AutoRABIT. Visit https://securityweekly.com/autorabit to learn more about them!

    In the leadership and communications segment, Boards Have a Digital Duty of Care, The CISO’s greatest risk? Department leaders quitting, The 15 Habits of Highly Empathetic People, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-425

    53 min
  • Making OAuth Scale Securely for MCPs - Aaron Parecki - ASW #360

    The MCP standard gave rise to dreams of interconnected agents and nightmares of what those interconnected agents would do with unfettered access to APIs, data, and local systems. Aaron Parecki explains how OAuth's new Client ID Metadata Documents spec provides more security for MCPs and the reasons why the behavior and design of MCPs required a new spec like this.

    Segment resources:

    • https://aaronparecki.com/2025/11/25/1/mcp-authorization-spec-update
    • https://www.ietf.org/archive/id/draft-ietf-oauth-client-id-metadata-document-00.html
    • https://oauth.net/cross-app-access/
    • https://oauth.net/2/oauth-best-practice/

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-360

    1 hr 8 min
  • Fix your dumb misconfigurations, AI isn't people, and the weekly news - Wendy Nather, Danny Jenkins - ESW #436
    Interview with Danny Jenkins: How badly configured are your endpoints?

    Misconfigurations are one of the most overlooked areas in terms of security program quick wins. Everyone freaks out about vulnerabilities, patching, and exploits.

    Meanwhile, security tools are misconfigured. Thousands of unused software packages increase remediation effort and attack surface. The most basic misconfigurations lead to breaches. Threatlocker spotted this opportunity and have extended their agent-based product to increase attention on these common issues.

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more!

    Interview with Wendy Nather: Recalibrating how we think about AI

    AI and the case for toxic anthropomorphism. When Wendy coined this phrase on Mastodon a few weeks ago, I knew that she had hit on something important and that we needed to discuss it on this podcast.

    We were lucky to find some time for Wendy to come on the show!

    Quick note: while this was not a sponsored segment, 1Password IS currently a sponsor of this podcast. That doesn’t really change the conversation any, except that I have to be nice to Wendy. But why would anyone ever be mean to Wendy???

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. Dozens of funding rounds over the past two weeks
    2. Windows is becoming an Agentic OS? We talk about what that actually means.
    3. Some great free tools
    4. the latest cyber insurance trends
    5. we analyze some recent breaches
    6. the stop hacklore campaign
    7. some essays worth reading
    8. and a how a whole country dropped off the internet, because someone forgot to pay a GoDaddy invoice

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-436

    1 hr 35 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,053 Listeners

Planet Money by NPR

Planet Money

30,689 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,624 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

959 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners