Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • It's More Secure When It's Disabled - PSW #943

    In the security news this week:

    • Microsoft patches all the things
    • Commissary freezers enter cyberwar
    • Fake AV, real Defender nap
    • Rowhammer comes for the GPU
    • BIOS updates are no longer optional
    • CVSS is not a crystal ball
    • Kworker, but make it malware
    • FortiGate gets a post-exploitation RAT
    • CERN goes Debian underground
    • UEFI shells strike again
    • Australia loses the plot, and phones
    • Cisco routers become covert gateways
    • MikroTik patches the takeover chain
    • WeWorm wriggles through mobile
    • The year of Linux television
    • Browsers become backdoors
    • Fake IT calls, real data theft
    • CVE attribution gets weird
    • Boston Scientific keeps talking
    • Security tools misconfigure themselves
    • AI circuit breakers for rogue agents
    • Passkeys meet the real world
    • Vibe coding, vibe vulnerabilities
    • AI loss of control keeps climbing
    • AI agents report themselves to Schneier

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-943

    2 hr 3 min
  • Security Money: The Index Explodes, as the History of AI Teaches Us About Investments - John Willis - BSW #464

    AI is all the hype, but we're currently stuck at the bottom of the 'J' curve. Wild enthusiasm has given way to the reality of costs, benefits, and risks. What's next for AI and companies looking to capitalize on the AI trends?

    John Willis, author, researcher, and technology industry veteran, joins Business Security Weekly to discuss AI's impact on fundraising. John explores what the history of AI can teach us about the current moment, including how to separate genuine technological transformation from hype and better understand where AI may take us next.

    Next, it’s time for Security Money. The Index is exploding upwards as the markets continue to climb. Both the Index and the NASDAQ, hit all time highs. The Business Security Weekly crew breaks down funding, acquisitions, and performance of both the public and private markets.

    The Security Weekly 24 Index is made up of the following pure play public security companies:

    SAIL Sailpoint Inc PANW Palo Alto Networks Inc CHKP Check Point Software Technologies Ltd RBRK Rubrik Inc GEN Gen Digital Inc FTNT Fortinet Inc AKAM Akamai Technologies Inc FFIV F5 Inc ZS Zscaler Inc OSPN Onespan Inc LDOS Leidos Holdings Inc QLYS Qualys Inc NTSK Netskope Inc TENB Tenable Holdings Inc OKTA Okta Inc S SentinelOne Inc NET Cloudflare Inc CRWD Crowdstrike Holdings Inc NTCT NetScout Systems Inc VRNS Varonis Systems Inc RPD Rapid7 Inc FSLY Fastly Inc RDWR Radware Ltd ATEN A10 Networks Inc

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-464

    54 min
  • Security Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - Michael Leland, Ido Geffen, Sean Murphy, Idan Plotnik - ASW #399

    We showcase recordings from this year's Black Hat.

    The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island

    Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of the trust and security controls applied to traditional software. Michael Leland discusses Island's research uncovering thousands of malicious repositories, widespread security flaws across MCP servers, and a new attack technique called “AgentBaiting,” in which attackers manipulate agents into finding and recommending malware to users. The conversation explains how enterprises can govern AI capabilities without slowing adoption.

    Segment Resources:

    • https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware

    For more information about Island's research, please visit https://securityweekly.com/islandbh

    After Mythos: Securing Frontier AI as Attack and Defense Accelerate - Black Hat interview with Sean Murphy, Field CISO - North America of F5

    Frontier AI is compressing the time between discovering and exploiting vulnerabilities, forcing enterprises to rethink how they secure modern applications and AI systems. Sean Murphy shares how security teams can prepare for the next generation of AI-powered threats, why known vulnerabilities may become a bigger risk than zero-days, and what it takes to secure AI at scale from shadow AI and governance to agent and API protection.

    This segment is sponsored by F5. Visit https://securityweekly.com/f5bh to learn more about them!

    The Perfect Storm: When AI Writes the Code and Sharpens the Attacks - Black Hat interview with Idan Plotnik, Co-Founder and CEO of Apiiro

    Two storms are converging on how software gets built. The first: AI coding assistants are generating far more code than any security team can review, and with it, far more risk. The second: AI is sharpening the tools attackers use to find and exploit weaknesses faster than ever. Idan Plotnik explains why this convergence has moved the security perimeter to the coding agent itself, and makes the case for a prevention-first model where an AI AppSec agent guards coding agents in real time, governed by the principle that the agent writing the code cannot be the one to secure it.

    This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirobh to learn more about them!

    Model, Harness, Gym: Why Novee Owns the Full AI Pentesting Stack - Black Hat interview with Ido Geffen, Founder & CEO of Novee Security

    Most AI security tools are thin wrappers around a general-purpose frontier LLM — reasoning capability rented from someone else, applied to a generic scanning workflow. In this interview, Ido Geffen breaks down what it means to own the full AI pentesting stack — the proprietary offensive reasoning model, the harness that coordinates specialized agents, and the training gym where those agents are continuously benchmarked, post-trained on real attacker tradecraft, and promoted into production.

    Ido explains why owning each layer matters: it's how Novee's model consistently outperforms frontier LLMs at live browser exploitation, how the platform improves at a rate the customer feels every cycle, how Novee keeps security testing cost-efficient rather than relying on tokenized pricing models, and how new attacker techniques get injected into agent memory the moment Novee's research team observes them in the wild. He then makes the case that owning the model is only half the story. The other half is the Asset Intelligence Model — a living understanding of each customer's environment, workflows, permissions, APIs, and business logic. That's what turns a generalist AI hacker into a bespoke one: not just an attacker that reasons well, but one that reasons well about your specific business. He closes with how this advantage leads to findings that get more targeted every cycle, remediation tailored to an organization's tech stack, and a platform whose ceiling rises as attackers get faster.

    This segment is sponsored by Novee Security. Visit https://securityweekly.com/noveebh to learn more about them!

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-399

    1 hr 10 min
  • Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News - Amit Assaraf - ESW #475
    Interview - Amit Assaraf

    As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary software, leaving critical blind spots for prompt injection and data exfiltration. Discover how Cortex Agentic Endpoint Security (AES) uses LLM-based classifiers and an AI powered risk engine to surface shadow AI and protect the modern workspace without stalling innovation.

    This segment is sponsored by Palo Alto Networks. Visit https://securityweekly.com/paloalto to learn more about them!

    Topic - The British Library Cyber-Attack

    For this week’s topic segment, we’re discussing the British Library cyber-attack.

    In October 2023, the British Library, one of the largest libraries in the world, was breached by the Rhysida ransomware group. The attack encrypted systems across the organization, led to over 500,000 files being leaked, and set off a recovery effort that consumed a significant portion of the Library’s £17.5 million cash reserves. With no clear end date, this is a story of what could happen when all of an organization’s tech debt comes due at once.

    Resources

    • https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library
    The Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We check the vibes
    2. the funding
    3. the acquisitions
    4. and the closures
    5. is the vulnpocalypse real, or not?
    6. TeamPCP finds out why being perpetually online isn’t great if you’re doing cybercrimes
    7. millions of IDs get leaked online
    8. What’s the bigger story: Huggingface and NVIDIA or Microduck?
    9. Dyson enters a new product category. Try to guess what it is without cheating and looking it up before the end of the episode!

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-475

    1 hr 46 min
  • Linux Threat Hunting - PSW #942

    First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week:

    • SonicWall zero-days, again
    • AI finds a pile of Cisco bugs, and a root RCE
    • Claude Code Auto Mode dangers
    • BGP hijacks your unsigned software update
    • California, Linux and age verification
    • Free movies, complimentary malware
    • Citrix puts Linux alongside Windows
    • Signal's "secure" enclave
    • An expired domain answers military phone calls
    • MORE Cheap Android TV boxes arrive pre-pwned
    • CISA red teams meet critical infrastructure
    • PaperCut vulnerability cuts both ways
    • Big Tech asks everyone to secure its AI future
    • Pacemaker monitoring
    • DOJ files on a criminal leak site
    • Water utility security, right after the breaches

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-942

    2 hr 13 min
  • Preventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and Kai - Galina Antova, Todd Sorrel, John Hurley - BSW #463

    Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn’t end with sound investment decisions — it must extend to operational best practices that protect every capital event. But how?

    Todd Sorrel, CEO & Co-Founder at 6lock, joins Business Security Weekly to discuss how ever evolving AI attacks are increasing the chances of wire fraud. From voice cloning to deep fakes to impersonation, trust-based, high-touch controls for money transfer processes are inadequate. Todd will share how Zero Trust and verify principles are the only way to defend against these sophisticated wire fraud attacks.

    Optiv: The One Partner to Advise, Deploy and Operate. That’s Cybersecurity Simplified - Black Hat interview with John Hurley, Chief Revenue Officer of Optiv

    This segment will focus on Optiv's unmatched ability to advise, deploy and operate complete cybersecurity programs. With more than 6,000 clients and 450 technology partners, Optiv is the one clients trust to handle real-world cyber complexity, reduce risk and deliver real results.

    Learn why Optiv is the most trusted brand in cyber at https://securityweekly.com/optivbh.

    The Shift to Machine-Led Security: What's Next for Cyber Defense - Black Hat interview with Galina Antova, CEO and Co-Founder of Kai

    Artificial intelligence is fundamentally changing cybersecurity- not only by making attacks faster and more sophisticated, but also by forcing defenders to rethink how security operations are built. In this conversation, Kai CEO and co-founder Galina Antova discusses why the industry is moving toward machine-led security, what is preventing organizations from trusting autonomous AI, and what recent survey data from hundreds of CISOs reveals about where cybersecurity is headed next.

    To learn more about Kai, please visit: https://securityweekly.com/kaibh

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-463

    1 hr 1 min
  • Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398

    AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable.

    Segment Resources

    • https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt

    Vulnerability discovery and remediation gap in the AI era

    AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn’t necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice.

    Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security

    AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation.

    Segment Resources:

    • https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/
    • https://orca.security/platform/ai-appgen-security/

    This segment is sponsored by Orca Security. Visit https://securityweekly.com/orcabh to learn more about them!

    Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd

    Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch.

    Segment Resources:

    • https://www.bugcrowd.com/products/pathseeker/
    • https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/
    • https://www.bugcrowd.com/products/platform
    • https://www.bugcrowd.com/products/ai-powered-security-intelligence/

    Apply for early access at https://securityweekly.com/bugcrowdbh

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-398

    1 hr 9 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,056 Listeners

Planet Money by NPR

Planet Money

30,692 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,626 Listeners

Hacked by Hacked

Hacked

193 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,062 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

960 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners