Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318

    We're getting close to two full decades of celebrating web hacking techniques. James Kettle shares which was his favorite, why the list is important to the web hacking community, and what inspires the kind of research that makes it onto the list. We discuss why we keep seeing eternal flaws like XSS and SQL injection making these lists year after year and how clever research is still finding new attack surfaces in old technologies. But there's a lot of new web technology still to be examined, from HTTP/2 and HTTP/3 to WebAssembly.

    Segment Resources:

    • Top 10, 2024: https://portswigger.net/research/top-10-web-hacking-techniques-of-2024
    • Full nomination list: https://portswigger.net/research/top-10-web-hacking-techniques-of-2024-nominations-open
    • Project overview: https://portswigger.net/research/top-10-web-hacking-techniques

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-318

    45 min
  • Evolving the SOC: Automating Manual Work while Maintaining Quality at Scale - Allie Mellen, Tim MalcomVetter - ESW #394

    We've got a few compelling topics to discuss within SecOps today. First, Tim insists it's possible to automate a large amount of SecOps work, without the use of generative AI. Not only that, but he intends to back it up by tracking the quality of this automated work with an ISO standard unknown to cybersecurity.

    I've often found useful lessons and wisdom outside security, so I get excited when someone borrows from another, more mature industry to help solve problems in cyber. In this case, we'll be talking about Acceptable Quality Limits (AQL), an ISO standard quality assurance framework that's never been used in cyber.

    Segment Resources:

    • Introducing AQL for cyber.
    • AQL - How we do it
    • An AQL 'calculator' you can play around with

    We couldn't decide what to talk to Allie about, so we're going with a bit of everything. Don't worry - it's all related and ties together nicely.

    • First, we'll discuss AI and automation in the SOC - Allie is covering this trend closely, and we want to know if she's seeing any results yet here.
    • Next, we'll discover SecOps data management - the blood that delivers oxygen to the SOC muscles.
    • Finally, we'll discuss MITRE's recent EDR evaluations - there was some contention around some vendors claiming to ace the test and we're going to get the tea on what's really going on here!

    For each of these three topics, these are the blog posts they correspond with if you want to learn more:

    1. Generative AI Will Not Fulfill Your Autonomous SOC Hopes (Or Even Your Demo Dreams)
    2. If You’re Not Using Data Pipeline Management For Security And IT, You Need To
    3. Go Beyond The MITRE ATT&CK Evaluation To The True Cost Of Alert Volumes

    In this week's enterprise security news, we've got

    1. 5 acquisitions
    2. Tines gets funding
    3. new tools and DFIR reports to check out
    4. A legal precedent that could hurt AI companies
    5. AI garbage is in your code repos
    6. the dark side of security leadership
    7. HIPAA fines are broken
    8. Salt Typhoon is having a great time
    9. Don't use ChatGPT for legal advice!!!!!

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-394

    1 hr 56 min
  • Prompt Injection, CISA, Patch Tuesday - PSW #861

    You can install Linux in your PDF, just upload everything to AI, hackers behind the forum, TP-Link's taking security seriously, patche Tuesday for everyone including Intel, AMD, Microsoft, Fortinet, and Ivanti, hacking your space heater for fun and fire, Cybertrucks on fire (or not), if you could just go ahead and get rid of the buffer overflows, steam deck hacking and not what you think, Prompt Injection and Delayed Tool Invocation, new to me Ludus, Contec patient monitors are just insecure, Badbox carries on, the compiler saved me, and Telnet command injection!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-861

    2 hr 6 min
  • Speak the Same Language, as Cybersecurity is Everyone's Responsibility - BSW #382

    This week, we tackle a ton of leadership and communications articles: Why CISOs and Boards Must Speak the Same Language on Cybersecurity, The Hidden Costs of Not Having a Strong Cybersecurity Leader, Why Cybersecurity Is Everyone’s Responsibility, Leadership is an Action, not a Position, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-382

    55 min
  • Code Scanning That Works With Your Code - Scott Norberg - ASW #317

    Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shares his experience with encountering code scanners that didn't find the .NET vuln classes he needed to find and why that led him to creating a scanner from scratch. We talk about some challenges in testing tools, making smart investments in engineering time, and why working with .NET's compiler made his decisions easier.

    Segment Resources:

    -https://github.com/ScottNorberg-NCG/CodeSheriff.NET

    Identifying and eradicating unforgivable vulns, an unforgivable flaw (and a few others) in DeepSeek's iOS app, academics and industry looking to standardize principles and practices for memory safety, and more!

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-317

    1 hr 13 min
  • The groundbreaking technology addressing employment scams and deepfakes - John Dwyer, Aaron Painter - ESW #393

    Spoiler: it's probably in your pocket or sitting on the table in front of you, right now!

    Modern smartphones are conveniently well-suited for identity verification. They have microphones, cameras, depth sensors, and fingerprint readers in some cases. With face scanning quickly becoming the de facto technology used for identity verification, it was a no-brainer for Nametag to build a solution around mobile devices to address employment scams.

    Segment Resources:

    • Company website
    • Aaron's book, Loyal

    Listeners of the show are probably aware (possibly painfully aware) that I spend a lot of time analyzing breaches to understand how failures occurred. Every breach story contains lessons organizations can learn from to avoid suffering the same fate. A few details make today's breach story particularly interesting:

    • It was a Chinese APT
    • Maybe the B or C team? They seemed to be having a hard time
    • Their target was a blind spot for both the defender AND the attacker

    Segment Resources:

    • https://www.binarydefense.com/resources/blog/shining-a-light-in-the-dark-how-binary-defense-uncovered-an-apt-lurking-in-shadows-of-it/
    • https://www.theregister.com/2024/09/18/chinesespiesfoundonushqfirm_network/

    This week, in the enterprise security news,

    1. Semgrep raises a lotta money
    2. CYE acquires Solvo
    3. Sophos completes the Secureworks acquisition
    4. SailPoint prepares for IPO
    5. Summarizing the 2024 cybersecurity market
    6. Lawyers that specialize in keeping breach details secret
    7. Scientists torture AI
    8. Make sure to offboard your S3 buckets
    9. extinguish fires with bass

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-393

    1 hr 50 min
  • Deepseek, AMD, and Forgotten Buckets - PSW #860

    Deepseek troubles, AI models explained, AMD CPU microcode signature validation, what happens when you leave an AWS S3 bucket laying around, 3D printing tips, and the malware that never was on Ethernet to USB adapters.

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-860

    2 hr 7 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,046 Listeners

Planet Money by NPR

Planet Money

30,701 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,625 Listeners

Hacked by Hacked

Hacked

191 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

959 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners