Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • Applying Usability and Transparency to Security - Hannah Sutor - ASW #311

    Practices around identity and managing credentials have improved greatly since the days of infosec mandating 90-day password rotations. But those improvements didn't arise from a narrow security view. Hannah Sutor talks about the importance of balancing security with usability, the importance of engaging with users when determining defaults, and setting an example for transparency in security disclosures.

    Segment resources

    • https://youtu.be/ydg95R2QKwM

    Curl's oldest bug yet, RCPs (and more!) from AWS re:Invent, possible controls for NPM's malware proliferation, insights and next steps on protecting top 500 packages from the Census III report, the flawed design choice that made Microsoft's OTP (successfully) brute-forceable, and more!

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    00:00 Welcome to Application Security Weekly! 01:49 Meet the Experts 03:28 What Are Non-Human Identities? 06:17 Balancing Security & Usability 08:24 MFA Challenges & Admin Security 12:09 Navigating Breaking Changes 16:05 Security by Design in Action 18:42 Identity Management for Startups 20:18 Secure by Design: Real Impact 24:03 Transparency After a Critical Vulnerability 31:39 Looking Ahead to 2025 32:45 Application Security in Three Words 34:10 - Intro & Cyber Resilience Insights 35:30 - The 25-Year-Old Curl Bug Story 38:27 - Fuzzing for Security: A Missed Opportunity? 42:56 - AWS re:Invent Security Highlights 46:04 - NPM Malware Surge 50:43 - Small Packages, Big Risks in NPM 54:05 - Open Source Security Trends 58:37 - Microsoft MFA Vulnerability Explained 62:38 - Hardware Hacking & DMA Exploits 65:05 - Auditing Ruby’s Package Ecosystem 68:12 - Looking Ahead to 2025

    Show Notes: https://securityweekly.com/asw-311

    1 hr 10 min
  • The 2024 Cybersecurity Market Review - Mike Privette, Rew Islam - ESW #387

    For our second year now, Mike Privette, from Return on Security and the Security, Funded newsletter joins us to discuss the year's highlights and what's to come in the next 12 months.

    In some ways, it has been a return to form for funding, though some casualties of a tough market likely had to seek acquisition when they might have otherwise raised another round and stayed independent a while longer. We'll cover some stats, talk 2025 IPO market, and discuss the likelihood of (already) being in another bubble, particularly with regards to the already saturated AI security market.

    It won't be all financial trends though, we'll discuss some of the technical market trends, whether they're finding market fit, and how ~50ish AI SOC startups could possibly survive in such a crowded space.

    In this segment, we discuss two new FIDO Alliance standards focused on credential portability. Specifically, if passwordless is going to catch on, we need to minimize friction and maximize usability. In practice, this means that passkeys must be portable!

    Rew Islam of Dashlane joins us to discuss the new standards and how they'll help us enter a new age of secure authentication, both for consumers and the enterprise.

    Segment Resources:

    • Elevating Passwordless Security With AWS Nitro
    • Synced Passkeys Will Be Portable
    • FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys

    This week, in the enterprise security news,

    NOTE: We didn't get to 2, 3, 5, or 7 due to some technical difficulties and time constraints, but we'll hit them next week! The show notes have been updated to reflect what we actually discussed this week: https://www.scworld.com/podcast-segment/13370-enterprise-security-weekly-387

    1. Snowflake takes security more seriously
    2. Microsoft takes security more seriously
    3. US Government takes telecom security more seriously
    4. Cleo Capital takes security more seriously
    5. EU’s DORA takes effect soon
    6. Is phishing and security awareness training worthless?
    7. CISOs need financial literacy
    8. Supply chain firewall is basic but useful

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-387

    1 hr 48 min
  • Navigating Regulations in Supply Chain Security - Eric Greenwald - PSW #854

    Join us for this segment as we discuss government regulations and certifications as they apply to supply chain security and vulnerability management, and how understanding the mumbo jumbo can enable organizations to improve their cyber security.

    In the security news, the crew, (minus Paul) get to gather to discus hacks causing disruptions, in healthcare, donuts and vodka, router and OpenWRT hacks (and the two are not related), Salt/Volt Typhoon means no more texting and 10 year old vulnerabilities and more!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-854

    2 hr 44 min
  • Okta Secure Sign-In Trends Report Shows Companies are Getting Smarter about MFA - Chris Niggel - BSW #375

    For over 15 years, Okta has led the charge in securing digital identities through more sophisticated sign-in solutions. Our latest 2024 Secure Sign-In Trends Report offers insights into the rapidly evolving world of identity security, specifically on how organizations across industries are embracing modern, phishing-resistant methods like Multi-Factor Authentication (MFA) and passwordless sign-ins.

    In this year's report, we explore: - The surge in MFA adoption across industries, and what it means for the future of secure authentication. - Phishing-resistant authentication methods gaining traction, signaling that the passwordless future is possible. - Why a seamless user experience and strong security are no longer in opposition. - How industries compare in their adoption of modern authentication, and who's setting the pace.

    Segment Resources: Secure Sign-In Trends Full Report: https://www.okta.com/resources/whitepaper-the-secure-sign-in-trends-report/

    Todd McKinnon Blog on the Secure Sign-In Trends Report: https://www.okta.com/blog/2024/10/phishing-resistant-mfa-shows-great-momentum/

    This segment is sponsored by Okta. Visit https://www.securityweekly.com/okta to learn more about them!

    In the leadership and communications segment, How Good Leaders Become Great By Never Leading Alone, How Leaders Can Prepare Their Teams For 2025, Nervous About Public Speaking? Here’s How to Use Notes Like a Pro, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-375

    1 hr
  • Looking Back on 2024 - ASW #310

    We do our usual end of year look back on the topics, news, and trends that caught our attention. We covered some OWASP projects, the ongoing attention and promises of generative AI, and big events from the XZ Utils backdoor to Microsoft's Recall to Crowdstrike's outage.

    Segment resources

    • https://prods.ec
    • https://owasp.org/www-project-spvs/
    • https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
    • https://securitychampions.owasp.org/
    • https://deadliestwebattacks.com/appsec/2024/11/14/ai-and-llms-asw-topic-recap
    • https://www.scworld.com/podcast-episode/3017-infosec-myths-mistakes-and-misconceptions-adrian-sanabria-asw-279

    Curl and Python (and others) deal with bad vuln reports generated by LLMs, supply chain attack on Solana, comparing 5 genAI mistakes to OWASP's Top Ten for LLM Applications, a Rust survey, and more!

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-310

    1 hr
  • Tackling Barriers on the Road To Cyber Resilience - Rob Allen, Theresa Lanowitz - ESW #386

    In this final installment of a trio of discussions with Theresa Lanowitz about Cyber Resilience, we put it all together and attempt to figure out what the road to cyber resilience looks like, and what barriers security leaders will have to tackle along the way. We'll discuss:

    • How to identify these barriers to cyber resilience
    • Be secure by design
    • Align cybersecurity investments with the business

    Also, be sure to check out the first two installments of this series!

    • Episode 380: Cybersecurity Success is Business Success
    • Episode 383: Cybersecurity Budgets: The Journey from Reactive to Proactive

    This segment is sponsored by LevelBlue. Visit https://securityweekly.com/levelblue to learn more about them!

    When focused on cybersecurity through a vulnerability management lens, it's tempting to see the problem as a race between exploit development and patching speed. This is a false narrative, however. While there are hundreds of thousands of vulnerabilities, each requiring unique exploits, the number of post-exploit actions is finite. Small, even.

    Although Log4j was seemingly ubiquitous and easy to exploit, we discovered the Log4Shell attack wasn't particularly useful when organizations had strong outbound filters in place.

    Today, we'll discuss an often overlooked advantage defenders have: mitigating controls like traffic filtering and application control that can prevent a wide range of attack techniques.

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    This week, in the enterprise security news,

    1. Funding and acquisition news slows down as we get into the “I’m more focused on holiday shopping season”
    2. North Pole Security picked an appropriate time to raise some seed funding
    3. Breaking news, it’s still super easy to exfiltrate data
    4. The Nearest Neighbor Attack
    5. Agentic Security is the next buzzword you’re going to be tired of soon
    6. Frustrations with separating work from personal in the Apple device ecosystem
    7. We check in on the AI SOC and see how it’s going
    8. Office surveillance technology gives us the creeps

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-386

    2 hr
  • Hacker Gadgets - PSW #853

    The hosts discuss hacker gadgets! We'll cover what we've been hacking on lately and discuss gadgets we want to work on in the future and other gadgets we want to get our hands on.

    • Paul has been working with some M5Stack devices, a guide can be found here: https://securitypodcaster.com/m5stack-hacking-guide/
    • We will cover the Clockwork PI "uConsole" (RPI CM4) - https://www.clockworkpi.com/uconsole
    • We want the RPI Pico 2 W and the RPI CM5 (https://www.raspberrypi.com/products/)
    • Paul upgraded one of his Flipper Zeros with Momentum Firmware (https://momentum-fw.dev/)
    • Paul and Larry have the new Crowview Note (https://www.kickstarter.com/projects/elecrow/crowview-note-empowering-your-device-as-a-laptop?ref=20bm9i)

    Larry's List: Cheap Yellow Display - https://github.com/witnessmenow/ESP32-Cheap-Yellow-Display KV4P HT - https://www.kv4p.com/ Lilygo T-Deck - https://lilygo.cc/products/t-deck Helltec LoRa32 https://heltec.org/project/wifi-lora-32-v3/ NRF52840-DK - https://www.mouser.com/ProductDetail/Nordic-Semiconductor/nRF52840-DK?qs=F5EMLAvA7IA76ZLjlwrwMw%3D%3D NRF52840 Dongle - https://www.mouser.com/ProductDetail/Nordic-Semiconductor/nRF52840-Dongle?qs=gTYE2QTfZfTbdrOaMHWEZg%3D%3D&mgh=1 MakerDialry NRF52840 - https://wiki.makerdiary.com/nrf52840-mdk-usb-dongle/ Radioberry - https://www.amazon.com/dp/B0CKN1PW4J

    Bootkitties and Linux bootkits, Canada realizes banning Flippers is silly, null bytes matter, CVE samples, how dark web marketplaces do security, Perl code from 2014 and vulnerabilities in needrestart, malware in gaming engines, the nearby neighbor attack, this week in security appliances featuring Sonicwall and Fortinet, footguns, and get it off the freakin public Internet!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-853

    2 hr 43 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,046 Listeners

Planet Money by NPR

Planet Money

30,701 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,625 Listeners

Hacked by Hacked

Hacked

191 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

959 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners