Shared Security Podcast

Shared Security Podcast

By Tom Eston, Scott Wright, Kevin TackettNewsTechnologyTech News
Download on the App Store

Shared Security Podcast episodes

  • iOS 17 NameDrop Debunking, Real World QR Code Attacks, Impact of Ransomware on Hospitals
    In episode 307, Tom and Scott debunk misinformation circulating about the iOS 17 NameDrop feature by law enforcement and others on social media. Next, they discuss the potential risks of QR code scams, detailing a real-life incident where a woman lost a significant amount of money due to a QR code scam. Finally, the episode concludes with a discussion on a ransomware attack on a large US healthcare provider, examining potential repercussions and stressing the need for increased security for critical infrastructure. Co-host Scott Wright also presents an overview of the Click Armor platform, an innovative gamified security awareness training platform.
    17 min
  • Application Security Trends & Challenges with Tanya Janca
    In episode 306, noteworthy guest Tanya Janca returns to discuss her recent ventures and her vision for the future of AppSec. She reflects on the significant changes she has observed since her career at Microsoft, before discussing her new role at Semgrep that recently acquired WeHackPurple. Tanya sheds light on her decision to partner with Semgrep, a company that aligns with her vision of providing free resources in the AppSec community. Despite facing a failed acquisition process the previous year, WeHackPurple received multiple acquisition offers, leading to a bidding war.
    In addition, Tanya shares her optimism about the maturity of AppSec programs, presents her concerns about consolidation in the industry, and highlights the importance of role-based, tailored training. She also reveals her ongoing work on the sequel to her book titled 'Alice and Bob Learn Secure Coding' and hints at the launch of the Semgrep Academy.
    For our Patreon supporters, don't miss our bonus episode where Tanya shares her biggest career accomplishment and failure, offering invaluable lessons for all!
    28 min
  • Apple Finally Adopts RCS, AI Powered Scams Targeting the Elderly
    In this episode, Tom shows off AI generated images of a "Lonely and Sad Security Awareness Manager in a Dog Pound" and the humorous outcomes. The conversation shifts to Apple's upcoming support for Rich Communication Services (RCS) and the potential security implications. Lastly, Tom and Kevin reflect on reports of AI-powered voice cloning scams targeting elderly Americans, and argue that the true issue lies with social engineering rather than the involvement of AI.
    27 min
  • Paying Big Tech for Privacy, New Privacy Policy Study, Biden’s Executive Order on AI
    In this week's episode of the Shared Security Podcast, hosts Tom Eston, Scott Wright and Kevin Johnson tackle a number of topics related to AI, privacy and security. They begin with an amusing discussion about their respective roles on the podcast, before shifting to big tech's use of user data and whether subscribers should pay to not have their data used. The focus then turns to a recent move by Meta to charge European users who wish to use Instagram and Facebook without ads.
    Next, they touch on new research from NordVPN about the burdensome length and complexity of privacy policies on popular websites, and offer alternatives for consumers to navigate them.
    Lastly, the hosts discuss a new executive order by the Biden administration directed towards AI companies, calling for a watermark system to alert consumers when they interact with an AI-enabled product. They express concerns about businesses benefiting from the new AI rules while potentially stifling competition and highlight the need for stronger, enforceable laws to truly protect users' data and privacy.
    25 min
  • SEC vs. SolarWinds CISO, Classiscam Scam-as-a-Service
    In this episode we discuss the SEC's charges against SolarWinds' CISO for misleading investors about a major cyberattack. Plus don't miss our discussion about the shady world of "Classiscam Scam-as-a-Service," a very popular cyber criminal service that creates fake user accounts, posts fraudulent reviews, and boosts the reputation of dishonest sellers while defrauding e-commerce platforms.
    23 min
  • Okta Hacked Again, Quishing Is The New Phishing, Google Play Protect Real-Time Scanning
    In this episode, we explore the recent Okta breach where hackers obtained sensitive customer data via unauthorized access to the Okta support system. Next, we discuss the emerging threat of "quishing," a combination of voice calls and phishing that preys on unsuspecting victims. Finally, we discuss Google Play Protect's new feature, "Real-time App Analysis," which enhances Android device security by helping prevent malware from being installed.
    18 min
  • How to Opt Out of CPNI Data Sharing
    Did you know that your mobile phone provider can give data like phone numbers you've called and received, the time and date of those calls, and even your location data to their parent companies, affiliates, and agents? In this episode we show you how to opt out so you can stop your data from being being shared!
    8 min
  • Special Guest Jayson E. Street, Phantom Hacker Scams, 23andMe User Data For Sale
    In milestone episode 300, Jayson E. Street (a renowned hacker, helper, and human who has successfully robbed banks, hotels, government facilities, and Biochemical companies on five continents) joins us to share what he's been up to recently and to talk about his new role at Secure Yeti.
    Next, we explore the alarming rise of 'phantom hacker' scams targeting the elderly. The FBI issues a stern warning about these evolving tech support scams that are draining the savings of unsuspecting seniors. We uncover the extent of the issue, with staggering victim losses and disturbing trends.
    Finally, we unravel the unsettling revelation that private user data from 23andMe has been scraped and is up for sale, raising concerns about credential stuffing attacks, user privacy, and data security.
    For our Patreon supporters, check out this week's bonus episode where Jayson shares his recent gaming adventures in Starfield and No Man's Sky! If you're not a supporter yet, head to https://patreon.com/sharedsecurity to discover how you can access this exclusive content.
    26 min
  • Educating the Next Cybersecurity Generation with Tib3rius
    In this episode, we explore the remarkable journey of Tib3rius, a web application hacking expert and content creator. In this engaging conversation, we discuss:
    - Tib3rius' passion for community education and content creation. What fuels his desire to empower the next generation of cybersecurity professionals?
    - His expertise and enthusiasm for web application hacking, and we explore the transformative shifts in Application Security over recent years.
    - If you're new to the industry and aspire to be a web application pentester, don't miss the valuable insights Tib3rius has to offer.
    - Get the inside scoop on Tib3rius' latest move to TCM Security and his courses, with a spotlight on his upcoming web application security pentesting course!
    For our Patreon supporters, an extraordinary bonus episode awaits, where Tib3rius unveils two of his most astonishing hacks! This is a discussion you won't want to miss. If you're not a supporter yet, head to patreon.com/sharedsecurity to discover how you can access this exclusive content.
    18 min
  • Your Car is a Privacy Nightmare, Password Creation Best Practices, Sony Hacked Again
    In this episode, we discuss the Mozilla Foundation's alarming report that reveals why cars are the top privacy concern. Modern vehicles, equipped with data-collecting tech, pose significant risks to consumers' privacy, with data sharing even extending to law enforcement. Listen in to our discussion as we explore the urgent need for transparency and *gasp* regulations in the automotive industry.
    Next, we explore the best practices around password creation and why password requirements are so different between organizations and applications you use every day.
    Lastly, Sony has suffered two security breaches in the past four months. In their latest breach, we discuss how a zero-day vulnerability led to unauthorized access and the Clop ransomware gang's involvement, affecting thousands of individuals.
    28 min

About Shared Security Podcast

From the publisher's feed

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy…

More shows like Shared Security Podcast

Hacked by Hacked

Hacked

191 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners