Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • What We’ve Learned from LockBit and Black Basta Leaks (and News) - Ian Gray - PSW #888

    This segment is sponsored by Flashpoint. Visit https://securityweekly.com/flashpoint to learn more about them!

    Recent leaks tied to LockBit and Black Basta have exposed the inner workings of two of the most notorious ransomware groups—revealing their tactics, negotiation strategies, and operational infrastructure. For defenders, this rare window into adversary behavior offers critical intelligence to strengthen incident response and prevention strategies. In this interview, we'll break down what these leaks reveal and how security teams can use this intelligence to proactively harden their defenses, including:

    • Key takeaways from the LockBit and Black Basta leaks—and what they confirm about ransomware operations
    • How leaked playbooks, chats, and toolkits can inform detection and response
    • Practical steps to defend against modern ransomware tactics in 2025

    In the security news:

    • Practical exploit code
    • Old vulnerabilities, new attackers
    • AI and web scraping - the battle continues
    • 0-Days: You gotta prove it
    • WinRAR 0-Day
    • LLM patch diffing
    • $20 million bug bounty
    • Your APT is showing
    • Hacking from the routers
    • Its that easy eh?
    • NIST guidance on AI
    • Words have meaning
    • Developers knowingly push vulnerable code
    • My Hackberry PI post is live: https://eclypsium.com/blog/build-the-ultimate-cyberdeck-hackberry-pi/

    Resources:

    • Inside the LockBit Leak: Rare Insights Into Their Operations: https://flashpoint.io/blog/inside-the-lockbit-leak/?utmcampaign=WBHostedSCMedia2025&utmsource=SCMedia&utmmedium=email&sfcampaign_id=701Rc00000S48bZIAR
    • 2025 Ransomware Survival Guide: https://flashpoint.io/resources/e-book/2025-ransomware-survival-guide/?utmcampaign=WBHostedSCMedia2025&utmsource=SCMedia&utmmedium=email&sfcampaign_id=701Rc00000S48bZIAR
    • AI and Threat Intelligence: The Defenders’ Guide https://go.flashpoint.io/ai-and-threat-intelligence-guide?utmcampaign=WBHostedSCMedia2025&utmsource=SCMedia&utmmedium=email&sfcampaign_id=701Rc00000S48bZIAR

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-888

    2 hr 16 min
  • Misconfiguration, The Forgotten Vulnerability and the Power and Failure of "Yes" - Danny Jenkins - BSW #409

    The industry is obsessed with vulnerabilities. From vulnerability assessment to vulnerability management to exposure management and even zero days, we love to talk about vulnerabilities. But what about misconfiguration? By definition it's a vulnerability or weakness, but it doesn't have a CVE (common vulnerability enumeration). Should we ignore it?

    Danny Jenkins, CEO and Founder at ThreatLocker, joins BSW to discuss why misconfigurations matter. Simply, you can prevent many cyberattacks by eliminating your misconfigurations. That's why ThreatLocker released Defense Against Configurations (DAC). Danny will discuss the benefits of DAC, including:

    • Immediate visibility into system misconfigurations before they become vulnerabilities
    • Compliance transparency, showing exactly where systems fall short of industry standards
    • One unified view, with filters by criticality, system, and framework
    • Actionable insights, updated weekly and delivered straight to customers’ inboxes

    Segment Resources:

    • https://www.threatlocker.com/press-release/threatlocker-launches-dac-empowering-organizations-with-real-time-visibility-into-configuration-risks-and-compliance-gaps
    • https://www.threatlocker.com/platform/defense-against-configurations

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    In the leadership and communications segment, CEO Blind Spots That Put Your Company at Risk, The CISO Mindset Shift: From Risk Defender to Business Accelerator in the Age of AI, When “Yes, and…” Backfires, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-409

    54 min
  • Managing the Minimization of a Container Attack Surface - Neil Carpenter - ASW #344

    A smaller attack surface should lead to a smaller list of CVEs to track, which in turn should lead to a smaller set of vulns that you should care about. But in practice, keeping something like a container image small has a lot of challenges in terms of what should be considered minimal. Neil Carpenter shares advice and anecdotes on what it takes to refine a container image and to change an org's expectations that every CVE needs to be fixed.

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-344

    1 hr 9 min
  • Rethinking risk based vulnerability management, Black Hat expo insights, and the news - Snehal Antani - ESW #420
    Interview with Snehal Antani - Rethinking Risk-Based Vulnerability Management

    Vulnerability management is broken. Organizations basically use math to turn a crappy list into a slightly less crappy list, and the hardest part of the job as a CIO is deciding what NOT to fix. There has to be a better way, and there is...

    Segment Resources:

    • https://horizon3.ai/intelligence/blogs/vulnerability-management-is-broken-there-is-a-better-way/

    This segment is sponsored by Horizon3.ai. Visit https://securityweekly.com/horizon3 to learn more about them!

    Topic - Andy Ellis's Black Hat Expo Experience

    Andy Ellis visited every booth at Black Hat. Every. Single. One. He wrote up what he learned and we discuss his findings!

    https://www.duha.co/state-of-security-vendors-blackhat-2025/

    News

    Finally, in the enterprise security news,

    1. Tons of handy new and free tools!
    2. is cybersecurity really at the latter stages of consolidation?
    3. new books
    4. is our obsession with risk quantification hurting our credibility?
    5. AI trends
    6. is there an impending AI layoff-pocalypse?
    7. we explain the kids’ favorite new term: Clanker

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-420

    1 hr 56 min
  • Hackberry PIs and Other Hacker Things - PSW #887

    We kick things off with a deep dive into the Hackberry PI and how to build one. Then in the security news:

    • Will Perplexity buy Chrome?
    • ESP32 Bus Pirates
    • Poisoned telemetry
    • Docker image security
    • Fully Open Source Quantum Sensors
    • Securing your car, Flippers, and show me the money
    • Bringing your printer and desktop to Starbucks
    • Paying a ransom? You need approval
    • AI: Shield or Spear?
    • No authentication? That's a problem
    • Transient Bugs: A realistic threat?
    • You can run Linux
    • And who still uses AOL dial-up?

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-887

    2 hr 9 min
  • Defending Trust & Reputation as CISOs and Leaders Prepare Their AI Strategy - Santosh Nair - BSW #408

    As brands grow more digital, the threats grow more personal. Attackers impersonate executives, spin up fake websites, and leak sensitive data — hurting business reputations and breaking customer trust. How do you defend your organization's reputation and customers' trust?

    Santosh Nair, Co-Founder and CTO at Styx Intelligence, joins Business Security Weekly to discuss how to defend trust and reputation in the age of AI. Santosh will cover both the company and executive challenges of defending against the latest AI attacks, including:

    • Impersonations and Deepfakes
    • Employee Scams
    • Financial Fraud

    Segment Resources: - https://styxintel.com/blog/what-is-brand-protection/ - https://styxintel.com/blog/brand-impersonation-hurts-business/ - https://styxintel.com/blog/social-engineering-tactics/

    In the leadership and communications section, Mind the overconfidence gap: CISOs and staff don’t see eye to eye on security posture, Your AI Strategy Needs More Than a Single Leader, Avoid These Communication Breakdowns When Launching Strategic Initiatives, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-408

    51 min
  • The Future of Supply Chain Security - Janet Worthington - ASW #343

    Open source software is a massive contribution that provides everything from foundational frameworks to tiny single-purpose libraries. We walk through the dimensions of trust and provenance in the software supply chain with Janet Worthington. And we discuss how even with new code generated by LLMs and new terms like slopsquatting, a lot of the most effective solutions are old techniques.

    Resources

    • https://www.forrester.com/blogs/make-no-mistake-software-is-a-supply-chain-and-its-under-attack/
    • https://www.forrester.com/report/the-future-of-software-supply-chain-security/RES184050

    Show Notes: https://securityweekly.com/asw-343

    43 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,053 Listeners

Planet Money by NPR

Planet Money

30,689 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,624 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

959 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners