Security Weekly Podcast Network (Audio)

Security Weekly Podcast Network (Audio)

By Security Weekly ProductionsNewsTechnologyTech News
Download on the App Store
  • Favorites

    79

    Followers

  • Typical duration

    36 min

    per episode

Based on Podcast App listening data

Security Weekly Podcast Network (Audio) episodes

  • Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - Jeremiah Grossman, O'Shea Bowens - ESW #469
    Segment 1 - Interview with O'Shea Bowens

    What do we really know about "AI Network Protocols"? Network security is about to get popular all over again.

    Generative AI caused a disruptive explosion across all of tech and every company’s roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other?

    Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O’Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling.

    Segment Resources:

    1. https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D
    2. https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/
    3. https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth
    Segment 2 - Interview with Jeremiah Grossman

    Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years

    After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up.

    Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat

    Segment 3 - Weekly Enterprise News

    Finally, in the enterprise security news,

    1. We vibe check the AI model situation
    2. hidden devices in California cars causes concerns
    3. OpenAI’s models escape sandboxes and breaches another AI company, totally by accident, they promise!
    4. Grok Build uploads all your files, totally by accident, they promise!
    5. Eclipsium debuts a firmware version of patch tuesday!
    6. HTTP gets a new method
    7. common problems with incident response
    8. Which one of the security weekly hosts would consider switching to a “dumb phone”?

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-469

    1 hr 51 min
  • Fixing Vulns Is Harder Than Finding Them - PSW #936

    In the news this week:

    • InfraTrust and knowing what to patch
    • Adversary in the middle triggered command injection
    • Exploitarium again
    • FreeRDP comes with free vulnerabilities
    • AI breaking out of sandboxes on its own
    • Wordpress RCE
    • DMA dangers
    • Nightmware eclypse is at it again
    • Fortisandbox
    • Turning AI to the dark side
    • more prompt injection
    • Secure boot is broken, still and again...

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-936

    2 hr 3 min
  • AI's Disruption as Cybersecurity’s Economics Are Broken, Compounding Security Debt - Ben Gilliland - BSW #457

    America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American history?

    Ben Gilliland, author of the upcoming book Breaking the Compact, joins Business Security Weekly to discuss why business leaders need to be prepared for the upcoming AI disruption. The impact of AI, which has not fully materialized, goes far beyond security and job displacement. It will impact our economy, our privacy, and our way of life. The closest recent warning is the "China shock," the period of rapidly increasing import competition that followed China's integration into the global trading system. AI will dwarf that. Ben will discuss the human advantage and how we can prepare now.

    In the leadership and communications segment, Cybersecurity’s Economics Are Broken. Automation Alone Won’t Fix It, The business case for burning down security debt: A practical approach for CISOs, The last human relationship in cybersecurity, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-457

    59 min
  • LegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - Kieran Human - SWN #600

    Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More.

    Segment Resources:

    Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Visit https://www.securityweekly.com/swn for all the latest episodes!

    Show Notes: https://securityweekly.com/swn-600

    37 min
  • MacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392

    Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's aggressive stance on deprecation benefits security, and the areas of the OS where he still sees plenty of opportunity for more security research. We discuss how developers make defensible design choices, why privacy needs security, and some security principles that any app developer should keep in mind regardless of their programming language or operating system.

    Resources:

    • https://objective-see.org/blog/blog_0x86.html
    • https://objective-see.org/products/lulu.html
    • https://objectivebythesea.org/v9/index.html

    Visit https://www.securityweekly.com/asw for all the latest episodes!

    Show Notes: https://securityweekly.com/asw-392

    1 hr 13 min
  • AI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - Keith Hollender - ESW #468
    Interview with Keith Hollender, CEO and Co-Founder of Arcova

    Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem

    As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introducing unmanaged risk. The challenge is no longer whether organizations should pursue AI, but how they can govern it, secure it, and operationalize it in ways that stand up to real-world business and threat conditions.

    In this conversation, Keith Hollender discusses what Arcova is seeing across enterprise environments as organizations work to connect cybersecurity, AI governance, resilience, and broader transformation priorities. He explores where companies are getting stuck, why traditional siloed approaches are falling short, and what it takes to move from strategy decks to secure execution.

    Keith also shares how Arcova’s practitioner-led, relationship-driven model helps organizations turn complexity into clarity by embedding with client teams, solving urgent problems hands-on, and building capabilities designed to last. The conversation also covers Arcova’s continued growth, including expansion into the Middle East, and what global demand signals reveal about the next phase of cybersecurity and AI consulting.

    Segment Resources:

    • https://arcova.com/sectors/
    • https://arcova.com/category/blog/

    For more information about Arcova and how they can help your enterprise shape what's next, please visit:

    https://securityweekly.com/arcova

    Topic: CMMC Pause creating chaos among federal contractors

    This one sent some shockwaves through the CMMC community, particularly the hundreds or thousands of folks gearing up to assist with the validation that phase 2 aimed to provide. The TL;DR - defense contractors have been required to comply with CMMC controls for years, but self-attestation means that many probably haven't been meeting the requirements. Perhaps, rather than have tons of defense contractors fail the test, they just suspended the requirement for the test itself.

    I think Howard Holton nails it here when he says:

    "100,000 defense contractors needed third-party assessments. Roughly 100 authorized assessors exist. That's 1,000 assessments each, with the deadline in November."

    PCI already created a model that works for a scenario like this. If you're small, you self-assess. If you're big enough, an independent auditor comes to check you out once a year. I'm sure they were probably aware of this and chose not to go down that path for some reasons. I'm not aware of those reasons.

    What this means:

    • Phase II is paused
    • Phase I self-assessments still in place (note, however, that phase II existed, because self-attestation didn't work)
    • NIST SP 800-171 Rev 2 and DFARS 252.204-7012 compliance still required
    • 60-day review aims to reform CMMC
    • DoW opened an RFI for industry perspectives on what they should do
    • CMMC characterized as a "compliance burden" and "red tape"
    • False Claims Act and DOJ's cyber-fraud enforcement are still on the table

    More resources:

    • CIO Davies' post on Twitter
    • Administrator of the Small Business Administration, Kelly Loeffler's post
    • A useful LinkedIn post that breaks down a lot of what this really means (and doesn't)
    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. will AI eliminate more cybersecurity jobs than it creates?
    2. Linus’s law, amended
    3. the biggest patch Tuesday ever
    4. AI context bombs
    5. AI workflows are a security disaster
    6. people using AI in areas they don’t understand
    7. ransomware crews are hitting legal firms hard
    8. lessons learned from CISA’s recent github leak
    9. demystify your USB cables!

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-468

    1 hr 43 min
  • 1999 Called and It Wants It's Exploits Back - PSW #935

    This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously discussed! Then in the security news:

    • The GodDamn Ransomware
    • CMMC suspended
    • Holy Microsoft Tuesday!
    • Lessons learned
    • Without the Internet, do we still get water?
    • The forgotten shims
    • More than two BIOS passwords
    • Cracking firmware encryption with Claude
    • 1999 called, and it wants its "Exploits" back
    • Prompt injection for defenders
    • Grok has your repo
    • You're not going to outpatch AI

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-935

    2 hr 12 min
  • Take Back Control as Enterprises Struggle to Incorporate Risks They Don't Understand - Ben Lipczynski - BSW #456

    More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited. However, you’re expected to mitigate all vulnerabilities, or at least critical and high. But what if there is no patch to fix the vulnerability or the software is unsupported?

    Ben Lipcynski, Director Security and Regulatory Services at Optima, joins Business Security Weekly to discuss how organizations can take back control of your enterprise software. OPTAS — Origina Proactive Threat Assurance Service — predicts, validates, prioritizes, and mitigates threats specific to your environment. Unlike AI vulnerability tools that flag everything without context or mitigation guidance, OPTAS cuts through the noise. OPTAS helps security teams focus on the risks that matter instead of chasing the 99% that do not.

    Segment Resources: - https://www.origina.com/optas#optas-overview

    This segment is sponsored by Origina. Visit https://securityweekly.com/origina to request a consultation.

    In the leadership and communications segment, US enterprises incorporate cyber risk into larger strategic focus, 75% of CISOs Fear Executives Don’t Understand Cybersecurity Risks, AI agents are not your “coworkers”, and more!

    Visit https://www.securityweekly.com/bsw for all the latest episodes!

    Show Notes: https://securityweekly.com/bsw-456

    56 min

About Security Weekly Podcast Network (Audio)

From the publisher's feed

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Best of Security Weekly Podcast Network (Audio)

Ranked by our users in the last 21 days

More shows like Security Weekly Podcast Network (Audio)

Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,053 Listeners

Planet Money by NPR

Planet Money

30,689 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,624 Listeners

Hacked by Hacked

Hacked

192 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

504 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Paul's Security Weekly (Audio) by Paul Asadoorian

Paul's Security Weekly (Audio)

17 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,059 Listeners

Tech Brew Ride Home by Morning Brew

Tech Brew Ride Home

959 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners