Shared Security Podcast

Shared Security Podcast

By Tom Eston, Scott Wright, Kevin TackettNewsTechnologyTech News
Download on the App Store

Shared Security Podcast episodes

  • Private Tweets Exposed, Unauthorized Tracking Collaboration, AI Risks and Regulation
    In this episode we discuss a recent Twitter security incident that caused private tweets sent to Twitter Circles to become visible to unintended recipients.
    Next, we discuss the collaboration between Apple and Google to develop a specification for detecting and alerting users of unauthorized tracking using devices like AirTags.
    Finally, we explore the US government's engagement with major technology companies and AI experts to address the risks associated with generative artificial intelligence (AI). We analyze the White House initiatives and the call for increased regulatory measures in the AI field.
    19 min
  • Juice Jacking Debunked, Photographer vs. AI Dataset, Google Authenticator Risks
    In this episode we debunk the fearmongering surrounding "juice jacking," a cyber attack where attackers steal data from devices that are charging via USB ports.
    Next, we dive into a case where a photographer tried to get his photos removed from an AI dataset, only to receive an invoice instead of having his photos taken down.
    Finally, we examine the security risks of using Google Authenticator's cloud sync feature for two-factor authentication. We explain why this feature may not provide adequate protection and offer recommendations for more secure alternatives.
    25 min
  • Building a Healthy Security Culture: Insights from Kai Roer
    In this episode we speak with Kai Roer, a renowned author, security culture coach, and CEO of Praxis Security Labs. Kai shares his career journey in cybersecurity and emphasizes the importance of building a strong security culture within organizations. He identifies the biggest impediments to a good security culture and offers actionable steps that organizations can take to improve their culture. Kai also discusses some of the biggest surprises he's encountered in his work and provides insights for security awareness professionals and executives to learn about the most critical aspects of security culture. Finally, Kai shares his vision for the future of cybersecurity and his current projects.
    30 min
  • Arkansas Social Media Consent Law, Android Malware Invasion, New Method of Keyless Car Theft
    Is Arkansas taking the right step to protect children online? A new law passed in the state makes it illegal for minors to use social media without their parent or guardian's consent.
    Over 60 Android apps on the Google Play Store with more than 100 million downloads have been infiltrated by the new "Tekya" malware. The malware can commit ad fraud and steal Facebook credentials.
    Criminals are stealing keyless cars in under two minutes with a previously unknown method involving intercepting the signal between the car key and the car.
    27 min
  • Genesis Market Crackdown, Life360 App Misuse, Tesla Customer Privacy Concerns
    Law enforcement agencies across 17 countries have cracked down on Genesis Market, one of the largest criminal marketplaces, resulting in the arrests of 120 people globally.
    Popular family safety app, Life360, has been used by sex traffickers to monitor and control their victims, highlighting the increasing use of GPS technology by criminals.
    A recent news report reveals that groups of Tesla employees shared highly invasive videos and images recorded by customers’ car cameras, including embarrassing and vulnerable situations. The leaked footage was shared via an internal messaging system, potentially compromising customer privacy.
    29 min
  • Clearview AI Facial Recognition Fallout, Hacked and Helpless, Is AI Armageddon Upon Us?
    Clearview AI provided police with 30 billion scraped images from Facebook, raising concerns over privacy and the potential misuse of facial recognition technology.
    A victim of a phone hack shares their story of how their credit card was stolen, highlighting the vulnerability of personal information and the chain of events that happen when someone's identity is stolen.
    Our discussion about an open letter calling for the regulation of AI development due to potential dangers and misuse has become a source of controversy within the tech community. We also discuss an extreme proposal of using the threat of nuclear war to prevent the rise of artificial intelligence.
    30 min
  • The TikTok CEO Testimony, ChatGPT’s Privacy Risks, Inaudible Ultrasound Attacks
    The CEO of TikTok was criticized by Congress for his "worthless" assurances regarding the app's privacy and security. But what is the real motivation for Congress attempting to ban TikTok?
    Should we be concerned that AI language models like ChatGPT are a privacy nightmare? Not just for businesses but for anyone using it?
    Researchers have found a way to use inaudible ultrasonic waves to attack smartphones, smart speakers, and other devices by taking control of their voice assistants, opening browser windows, and performing other malicious actions. Is this the next generation of attacks we need to be worried about?
    31 min
  • Samsung Chipset Zero-Day Vulnerabilities, AI-Assisted Social Engineering, ATM Fraud with a Twist
    In this episode we discuss Google's discovery of 18 zero-day vulnerabilities in Samsung's Exynos chipsets.
    We examine an AI-assisted social engineering campaign that combines emerging technologies with classic techniques.
    Finally, we look at a new method of ATM fraud where thieves use glue to disable card readers and trick customers into using the tap function on their debit cards.
    22 min
  • Exploring the Role of Empathy in Cybersecurity with Andra Zaharia
    On this episode, Tom Eston discusses empathy in cybersecurity with Andra Zaharia, host of the Cyber Empathy Podcast.
    We talk about finding her passion for contributing to the industry and the importance of empathy in cybersecurity. We cover how empathy relates to cybersecurity in the industry, the importance of being empathetic in our roles as cybersecurity professionals, and why the phrase "users are the weakest link in security" is nothing more than victim blaming.
    We also discuss the long term implications of new technology and how we can help educate people on how to build and use technology with kindness and how even impacting one person can make a difference.
    30 min
  • Biden’s National Cybersecurity Strategy, BetterHelp’s FTC Fine, Chick-fil-A Data Breach
    What you need to know about Biden's new National Cybersecurity Strategy, which aims to provide a framework of what the current administration wants the US federal government, critical infrastructure organizations, and private companies to do to work together to improve national cybersecurity.
    BetterHelp, a direct-to-consumer mental health app, has been asked to pay $7.8m by the Federal Trade Commission (FTC) for allegedly passing on users' mental health information to Facebook, Snapchat and others.
    Fast food chain Chick-fil-A has confirmed a credential stuffing attack that allowed cybercriminals (who apparently really love chicken sandwiches) to access 71,473 customer accounts and sell access to them online.
    14 min

About Shared Security Podcast

From the publisher's feed

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy…

More shows like Shared Security Podcast

Hacked by Hacked

Hacked

191 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners