The Security Repo

The Security Repo

By Mackenzie Jackson & Dwayne McDanielTechnology
Download on the App Store

The Security Repo episodes

  • The hacker in the board room: The journey from hacker to CISO with Jason Haddix

    Have you ever wanted to know how to hack a bank? If so this is the episode for you (disclaimer, please don't hack banks).

    Jason Haddix is someone that needs little introduction in the security world. In this Podcast, we were fortunate enough to sit down and discuss Jason's beginnings as a hacker through to how he made it all the way to the board room in some massive and truly awesome companies. We talk about how to hack banks, what happens when your a CISO during a security breach and what is the best advice for fellow and aspiring CISOs out there.
    Show Notes:
    Follow Jason on Twitter: https://twitter.com/Jhaddix
    Check out BuddoBot - Threat emulation testing https://buddobot.com/

    56 min
  • Security landscape in 2023 : Insights from the ground at RSA (Special Edition Episode)

    In this special edition episode, we tracked down a few of the key thought leaders in cyber security around the RSA conference to ask them what they thought were the biggest security concerns for 2023 as well as some key recommendations for organizations to combat them. Their insights were fascinating.

    This episode features:

    Feross Aboukhadijeh - Founder and CEO of Socket

    Steve Giguere - Organization London DevSecOps Community / Developer Advocate Bridge Crew

    Joseph Carson -Chief Security Scientist (CSS) & Advisory CISO

    Tony Loehr - Senior Product Manager

    Joshua Kamdjou - Founder CEO Sublime Security

    16 min
  • Modern ransomware: How hackers are targeting your organization with Adriel Disatel and Noah Tongate

    In this episode we sit down with legendary pen tester Adriel Disatel and Noah Tongate to discuss how modern cyber criminals are operating to deploy modern ransomware attacks. The conversation is full of real life hacking stories and to the point information on how you can protect yourselves against modern threats. 

    Links: Netragard Publications https://netragard.com/publications/

    Adriel Desautels Bio: Adriel is the founder and CTO of Netragard, a company founded on the premise of delivering to its clients high-quality Realistic Threat Penetration Testing™ services, known today as Red Teaming. Adriel has over 20 years of professional experience with information security. In 1998, Adriel founded Secure Network Operations, Inc. which was home to the SNOsoft Research Team that gained worldwide recognition for its vulnerability research. While running SNOsoft, Adriel created the zeroday Exploit Acquisition Program (“EAP”), which was transferred to, and continued to operate underNetragard. Adriel also provided expert witness and testimony in US Federal court. You may know him from his many contributions to cyber security for companies such as Forbes, The Economist, Bloomberg and even was featured in the VICELAND Cyberwar documentary.


    45 min
  • Understanding intent based access control with Uri Sarid

    In this episode of the Security Repo we dive into intent-based access control. This is the concept of limiting access to just what is intended, it sounds simple enough, But how does one understand and define the intent? And more importantly, how to we enforce our intentions with access control? This week's guest is Uri Sarid, he is a man with a long list of credentials and walks us through exactly what is intent-based control and how we can implement it in our organizations.

    About the guest - Uri Sarid
    Uri is responsible for products at Otterize. He is a recovering particle physicist with a 24-year career in high tech. He has co-founded or joined 6 early-stage software companies in the enterprise, consumer, and developer spaces, ran the Nook Cloud for Barnes & Noble, and most recently served as CTO for MuleSoft, where he led the vision, strategy, and architecture for the company. He is the co-creator of the RAML language for API specifications, a member of the OpenAPI Technical Steering Committee, and the holder of 26 patents, as well as a PhD in Theoretical Physics and Astrophysics from Harvard University.
    Show Notes
    Website: https://otterize.com/
    Blog Posts: https://otterize.com/blog
    About Otterize: https://tcrn.ch/3KXV4Im

    29 min
  • Multi Factor Authentication for APIs with Anusha Iyer

    APIs are what run the internet today, modern applications are no long monoliths, they are built upon hundreds of microservices and APIs are the glue that connects them. API security, however, is a massive blind spot for many organizations, from misconfigurations to leaked secrets, APIs give attackers ample opportunity to make intrusions into your systems. In this episode, we discuss how we can fundamentally change API security but add what Anusha Iyer, CEO of Corsha, calls multifactor authentication for APIs. In this episode, we dive deep into this topic with Anusha and discuss how we can make modern applications more secure.


    Show links:

    Corsha Website: https://corsha.com/

    Corsha State of API Secrets Management Report, 2023: https://corsha.com/api-security-and-secrets-management-survey-report-2023

    GitGuardian State of Secrets Sprawl Report: https://www.gitguardian.com/state-of-secrets-sprawl-report-2023


    31 min
  • Offensive security tools with Brendan O'Leary from ProjectDiscovery

    In this episode we are joined by Brendan O'Leary from ProjectDiscover we learn about the tools that hackers, bug bounty hunters, and red teams use to be able to map infrastructure and find vulnerabilities. Brendan is the head of community for ProjectDiscovery which is a company that builds open-source tools to help organizations find and discover their own vulnerabilities. We talk with Brendon about some of ProjectDiscovery's most popular tools but also take a look at their latest project, Chaos.


    Please like and subscribe to this podcast it helps a lot for others to be able to discover us and helps us grow.


    Show Links:

    Join the ProjectDiscovery community today https://projectdiscovery.io/#/communityMake sure you see their great articles on their blog at https://blog.projectdiscovery.io/

    32 min
  • Threat modeling in security with Audrey Long

    Have you ever wanted to threat model the death star from Star Wars? Well this is one of the many topics we discuss in the latest episode of the Security Repo podcast with our special guest Audrey Long. Audrey is a Senior Security Software Engineer at Microsoft in the Commercial Software Engineering team (CSE), which is a global engineering organization that works directly with the largest companies and not-for-profits in the world to tackle their most significant technical challenges.


    Show Links:

    Audrey on Linkedin - https://www.linkedin.com/in/audrey-long-53153a11b/

    Stride Threat Model Framework - https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats#stride-model

    Mitre Att&ck Framework - https://attack.mitre.org/

    Threat Modelling at Microsoft - https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats

    [Article] Why Threat Detection Should Always be Consideredhttps://www.linkedin.com/pulse/why-threat-detection-should-always-considered-audrey-long/?trk=pulse-article_more-articles_related-content-card

    39 min
  • Understanding and building the SOC (Security Operations Center) - With Troy Santana

    In this episode of The Security Repo we are joined again by Troy Santana from Critical Start to discuss how organizations can set up a Security Operations center regardless of their size. We explore exactly what a security operations center does and why you need one in the current security climate.   For more information on Critical Start please check out their website at https://www.criticalstart.com/

    22 min
  • Staff augmentation in security with Troy Santana

    Staff augmentation is the idea of augmenting your internal staff with consultants and tools to give you the collective knowledge of security experts for all teams. We sit down with security consultant Troy Santana to discuss exactly what staff augmentation looks like and how it can be implemented.

    Troy Santana joins us as a Sales Engineer for Critical Start. After spending 6 years as part of their 24x7 SOC team in analyst, management, and supporting roles, he moved over to security consulting to provide technical depth and operations experience to the buying process. A veteran of the Marine Corps, he obtained an M.A. in Criminology/Criminal Justice and uses that experience and education to help his team and clients understand the importance of layered security and operational expertise in both tools and personnel.

    Learn more about critical start at https://criticalstart.com

    36 min
  • Episode 6: Securing the development environment with Laurent Balmelli

    In this episode, we sit down with Laurent Balmelli, the CEO of Strong Network, to discuss why development environments are vulnerable to malicious actors and how we can move to a secure cloud IDE (Integrated Development Environment). A cloud IDE isn't entirely new but it also isn't changing how developers are working and more importantly how developers are keeping their environments secure. We ask Laurent what the issue is with cloud IDEs and discuss how we can leverage the concept to build better, more secure environments for our developers.

    Breach of the week - This week we take a look at the Atlassian breach in which attackers were able to obtain employee credentials to gain access to a third-party HR system. 

    36 min

About The Security Repo

From the publisher's feed

The security repo is a podcast that focuses on real world security issues we are all facing today. We will take deep dives into news events and have exclusive interviews with security leaders on the…