Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • Budget Planning Guide 2025: Security And Risk - Jeff Pollard - BSW #368

    In today’s uncertain macroeconomic environment, security and risk leaders need practical guidance on managing existing spending and new budgetary requests. Jeff Pollard, Vice-President, Principal Analyst on the Security and Risk Team at Forrester Research, joins Business Security Weekly to review Forrester's Budget Planning Guide 2025: Security And Risk. This data-driven report provides spending benchmarks, insights, and recommendations that will keep you on budget while still mitigating the most critical risks facing your organization. Jeff will cover which areas to invest, divest, and experiment, but you'll have to listen to get the details.

    In the leadership and communications segment, The CEO’s Role in Setting Tone at the Top, CISOs, C-suite remain at odds over corporate cyber resilience, Warren Buffett's Secret To Success? Run It 'Like A Small Family Business,' Says One Of His CEOs, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-368

    1 hr
  • Community Knowledge Sharing with CyberNest - Ben Siegel, Aaron Costello - ESW #379

    For this interview, Ben from CyberNest joins us to talk about one of my favorite subjects: information sharing in infosec. There are so many amazing skills, tips, techniques, and intel that security professionals have to share. Sadly, a natural corporate reluctance to share information viewed as privileged and private has historically had a chilling effect on information sharing.

    We'll discuss how to build such a community, how to clear the historical hurdles with information sharing, and how to monetize it without introducing bias and compromising the integrity of the information shared.

    Aaron was already a skilled bug hunter and working at HackerOne as a triage analyst at the time. What he discovered can't even be described as a software bug or a vulnerability. This type of finding has probably resulted in more security incidents and breaches than any other category: the unintentional misconfiguration.

    There's a lot of conversation right now about the grey space around 'shared responsibility'. In our news segment later, we'll also be discussing the difference between secure design and secure defaults. The recent incidents revolving around Snowflake customers getting compromised via credential stuffing attacks is a great example of this. Open AWS S3 buckets are probably the best known example of this problem. At what point is the service provider responsible for customer mistakes? When 80% of customers are making expensive, critical mistakes? Doesn't the service provider have a responsibility to protect its customers (even if it's from themselves)?

    These are the kinds of issues that led to Aaron getting his current job as Chief of SaaS Security Research at AppOmni, and also led to him recently finding another common misconfiguration - this time in ServiceNow's products. Finally, we'll discuss the value of a good bug report, and how it can be a killer addition to your resume if you're interested in this kind of work!

    Segment Resources:

    • Aaron's blog about the ServiceNow data exposure.
    • The ServiceNow blog, thanking AppOmni for its support in uncovering the issue.

    In the enterprise security news,

    1. Eon, Resolve AI, Harmonic and more raise funding
    2. Dragos acquires Network Perception
    3. Prevalent acquires Miratech
    4. The latest DFIR reports
    5. A spicy security product review
    6. Secure by Whatever
    7. New threats
    8. Hot takes

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-379

    1 hr 54 min
  • The Code of Honor: Embracing Ethics in Cybersecurity - Ed Skoudis - PSW #846

    "Code of Honor: Embracing Ethics in Cybersecurity" by Ed Skoudis is a book that explores the ethical challenges faced by cybersecurity professionals in today's digital landscape. The book delves into the complex moral dilemmas that arise in the field of cybersecurity, offering guidance on how to navigate these issues while maintaining integrity. The authors provide practical advice and real-world examples to help readers develop a strong ethical framework for decision-making in their cybersecurity careers.

    Segment Resources:

    • Code of Honor: https://www.montreat.edu/cybersecurity-code/
    • Purchase Ed's book here: https://a.co/d/gb3yRxU

    Get ready for a wild ride in this week's podcast episode, where we dive into the latest security shenanigans!

    • Default Credentials Gone Wild: We’ll kick things off with a look at how default credential scanners are like that friend who shows up to the party but never brings snacks. They're everywhere, but good luck finding one that actually works!
    • Critical Vulnerabilities in Tank Gauges: Next, we’ll discuss how automated tank gauges are now the new playground for hackers. With vulnerabilities that could lead to environmental disasters, it’s like giving a toddler a box of matches—what could possibly go wrong?
    • Cisco Routers: The Forgotten Gear: Cisco's small business routers are like that old car in your driveway—still running but definitely not roadworthy. We’ll explore why you should check your network before it becomes a digital junkyard.
    • Firmware Updates: A Love Story: Richard Hughes has dropped some juicy updates on fwupd 2.0.0, making firmware updates as easy as ordering takeout. But let’s be real, how many of us actually do it?
    • Stealthy Linux Malware: We’ll also uncover Perfctl, the stealthy malware that’s been creeping around Linux systems since 2021. It’s like that one relative who overstays their welcome—hard to get rid of and always looking to borrow money!
    • PrintNightmare Continues: And yes, the PrintNightmare saga is still haunting Windows users. It’s like a horror movie that just won’t end—grab your popcorn!
    • Cyber Shenanigans at Comcast and Truist: We'll wrap up with a juicy breach involving Comcast and Truist Bank that compromised data for millions. Spoiler alert: they didn’t have a great plan for cleaning up the mess.

    Tune in for all this and more as we navigate the wild world of security news with a wink and a nudge!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-846

    2 hr 15 min
  • The Future of Zed Attack Proxy - Simon Bennetts, Ori Bendet - ASW #302

    Zed Attack Proxy has been a crucial web app testing tool for decades. It's also had a struggle throughout 2024 to obtain funding that would enable the tool to add more features while remaining true to its open source history. Simon Bennetts, founder of ZAP, and Ori Bendet from Checkmarx update us on that journey, share some exploration of LLM fuzzing that ZAP has been working on, and what the future looks like for this well-loved project.

    Segment Resources:

    • https://www.zaproxy.org/blog/2024-09-24-zap-has-joined-forces-with-checkmarx/
    • https://www.zaproxy.org/blog/2024-09-30-improving-fuzzing-payloads-for-llms-with-fuzzai/
    • https://checkmarx.com/press-releases/checkmarx-joins-forces-with-zap-to-supercharge-dynamic-application-security-testing-dast-for-the-enterprise-and-enhance-community-growth/
    • KICS: https://github.com/Checkmarx/kics
    • 2MS: https://github.com/Checkmarx/2ms

    The many lessons to take away from a 24-year old flaw in glibc and the mastery in crafting an exploit in PHP, changing a fuzzer's configuration to find more flaws, fuzzing LLMs for prompt injection and jailbreaks, security hardening of baseband code, revisiting the threat models in Microsoft's Recall, and more!

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-302

    1 hr 13 min
  • Run Your Security Program Like an Election Campaign - Kush Sharma - BSW #367

    Does the CISO need to act like a politician? Negotiating budgets, communicating risks, and selling your strategy across the organization does sound a little like a politician. And if that's the case, are you hiring the right campaign staff?

    Kush Sharma, former CISO for CPR, City of Toronto, and Saputo, joins Business Security Weekly to discuss why you should run your security program like an election campaign. Kush will discuss the other positions you need to hire, not just the technical positions, to help you budget, communicate, and sell your strategy. A politician can't do it all by themself, so why should a CISO?

    In the leadership and communications segment, PwC Urges Boards to Give CISOs a Seat at the Table, CISO Salary Surge: Fewer Job Changes, Bigger Paychecks for Experienced Cybersecurity Leaders, Fostering a cybersecurity-first culture: Key leadership insights for building resilient businesses, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-367

    1 hr 6 min
  • Cybersecurity Career Paths: from touring musician to purple teaming at Meta - Neko Papez, Brian Contos, Jayson Grace - ESW #378

    Our latest in a series of interviews discussing cybersecurity career paths, today we talk to Jayson Grace his path into cybersecurity and his experience building red teams at national labs and purple teams at Meta. We also talk about his community impact, giving talks and building open source tools. Jayson just left Meta for an AI safety startup named Dreadnode, which we'll discuss as well.

    Segment Resources:

    • CyberSecEval 3: Advancing the Evaluation of Cybersecurity Risks and Capabilities in Large Language Models
    • The [TTPForge] (https://github.com/facebookincubator/TTPForge) is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).
    • ForgeArmory provides TTPs that can be used with the TTPForge
    • Wired, by Lily Hay Newman: Facebook's ‘Red Team X’ Hunts Bugs Beyond the Social Network's Walls
    • MOSE (Master Of SErvers) is a post exploitation tool for configuration management servers.
    • BSides SF 2024 - Beyond Quick Cash: Rethinking Bug Bounties for Greater Impact
    • BSides LV 2023 - [GF - Enemy Within: Leveraging Purple Teams for Advanced Threat Detection & Prevention - https://www.youtube.com/watch?v=-MT0tNi2vvc

    This week in the enterprise security news, we've got:

    1. Torq, Tamnoon, and Defect Dojo raise funding
    2. Checkmarx acquires ZAP
    3. Commvault acquires Clumio
    4. Would you believe San Francisco is NOT the most funded metro area for cybersecurity?
    5. Auto-doxxing Smart glasses are now possible
    6. Meta gets fined $100M for storing plaintext passwords
    7. AI coding assistants might not be living up to expectations
    8. Worst Practices
    9. Dumpster fires and truth bombs

    All that and more, on this episode of Enterprise Security Weekly!

    The way we use browsers has changed, so has the way we need to secure them. Using a secure enterprise browser to execute content away from the endpoint, inside a secure cloud browser is a dramatically more effective and cost-effective approach to protect users and secure access.

    This segment is sponsored by Menlo Security. Visit https://securityweekly.com/menloisw to learn more about them!

    Sevco is a cloud-native vulnerability and exposure management platform built atop asset intelligence to enable rapid risk prioritization, mitigation, validation, and metrics.

    Segment Resources: Customer Testimonials: https://www.sevcosecurity.com/testimonials/ Product Videos: https://www.sevcosecurity.com/sevcoshorts/

    This segment is sponsored by Sevco Security. Visit https://securityweekly.com/sevcoisw to learn more about them!

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-378

    2 hr 15 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,046 Listeners

Planet Money by NPR

Planet Money

30,701 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,625 Listeners

Hacked by Hacked

Hacked

191 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

959 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners