
Sign up to save your podcasts
Or


Have you ever wanted to know how to hack a bank? If so this is the episode for you (disclaimer, please don't hack banks).
In this special edition episode, we tracked down a few of the key thought leaders in cyber security around the RSA conference to ask them what they thought were the biggest security concerns for 2023 as well as some key recommendations for organizations to combat them. Their insights were fascinating.
This episode features:
Feross Aboukhadijeh - Founder and CEO of Socket
Steve Giguere - Organization London DevSecOps Community / Developer Advocate Bridge Crew
Joseph Carson -Chief Security Scientist (CSS) & Advisory CISO
Tony Loehr - Senior Product Manager
Joshua Kamdjou - Founder CEO Sublime Security
In this episode we sit down with legendary pen tester Adriel Disatel and Noah Tongate to discuss how modern cyber criminals are operating to deploy modern ransomware attacks. The conversation is full of real life hacking stories and to the point information on how you can protect yourselves against modern threats.
Links: Netragard Publications https://netragard.com/publications/
Adriel Desautels Bio: Adriel is the founder and CTO of Netragard, a company founded on the premise of delivering to its clients high-quality Realistic Threat Penetration Testing™ services, known today as Red Teaming. Adriel has over 20 years of professional experience with information security. In 1998, Adriel founded Secure Network Operations, Inc. which was home to the SNOsoft Research Team that gained worldwide recognition for its vulnerability research. While running SNOsoft, Adriel created the zeroday Exploit Acquisition Program (“EAP”), which was transferred to, and continued to operate underNetragard. Adriel also provided expert witness and testimony in US Federal court. You may know him from his many contributions to cyber security for companies such as Forbes, The Economist, Bloomberg and even was featured in the VICELAND Cyberwar documentary.
In this episode of the Security Repo we dive into intent-based access control. This is the concept of limiting access to just what is intended, it sounds simple enough, But how does one understand and define the intent? And more importantly, how to we enforce our intentions with access control? This week's guest is Uri Sarid, he is a man with a long list of credentials and walks us through exactly what is intent-based control and how we can implement it in our organizations.
APIs are what run the internet today, modern applications are no long monoliths, they are built upon hundreds of microservices and APIs are the glue that connects them. API security, however, is a massive blind spot for many organizations, from misconfigurations to leaked secrets, APIs give attackers ample opportunity to make intrusions into your systems. In this episode, we discuss how we can fundamentally change API security but add what Anusha Iyer, CEO of Corsha, calls multifactor authentication for APIs. In this episode, we dive deep into this topic with Anusha and discuss how we can make modern applications more secure.
Show links:
Corsha Website: https://corsha.com/
Corsha State of API Secrets Management Report, 2023: https://corsha.com/api-security-and-secrets-management-survey-report-2023
GitGuardian State of Secrets Sprawl Report: https://www.gitguardian.com/state-of-secrets-sprawl-report-2023
In this episode we are joined by Brendan O'Leary from ProjectDiscover we learn about the tools that hackers, bug bounty hunters, and red teams use to be able to map infrastructure and find vulnerabilities. Brendan is the head of community for ProjectDiscovery which is a company that builds open-source tools to help organizations find and discover their own vulnerabilities. We talk with Brendon about some of ProjectDiscovery's most popular tools but also take a look at their latest project, Chaos.
Please like and subscribe to this podcast it helps a lot for others to be able to discover us and helps us grow.
Show Links:
Have you ever wanted to threat model the death star from Star Wars? Well this is one of the many topics we discuss in the latest episode of the Security Repo podcast with our special guest Audrey Long. Audrey is a Senior Security Software Engineer at Microsoft in the Commercial Software Engineering team (CSE), which is a global engineering organization that works directly with the largest companies and not-for-profits in the world to tackle their most significant technical challenges.
Show Links:
Audrey on Linkedin - https://www.linkedin.com/in/audrey-long-53153a11b/
Stride Threat Model Framework - https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats#stride-model
Mitre Att&ck Framework - https://attack.mitre.org/
Threat Modelling at Microsoft - https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats
[Article] Why Threat Detection Should Always be Consideredhttps://www.linkedin.com/pulse/why-threat-detection-should-always-considered-audrey-long/?trk=pulse-article_more-articles_related-content-card
In this episode of The Security Repo we are joined again by Troy Santana from Critical Start to discuss how organizations can set up a Security Operations center regardless of their size. We explore exactly what a security operations center does and why you need one in the current security climate. For more information on Critical Start please check out their website at https://www.criticalstart.com/
Staff augmentation is the idea of augmenting your internal staff with consultants and tools to give you the collective knowledge of security experts for all teams. We sit down with security consultant Troy Santana to discuss exactly what staff augmentation looks like and how it can be implemented.
Troy Santana joins us as a Sales Engineer for Critical Start. After spending 6 years as part of their 24x7 SOC team in analyst, management, and supporting roles, he moved over to security consulting to provide technical depth and operations experience to the buying process. A veteran of the Marine Corps, he obtained an M.A. in Criminology/Criminal Justice and uses that experience and education to help his team and clients understand the importance of layered security and operational expertise in both tools and personnel.
Learn more about critical start at https://criticalstart.com
In this episode, we sit down with Laurent Balmelli, the CEO of Strong Network, to discuss why development environments are vulnerable to malicious actors and how we can move to a secure cloud IDE (Integrated Development Environment). A cloud IDE isn't entirely new but it also isn't changing how developers are working and more importantly how developers are keeping their environments secure. We ask Laurent what the issue is with cloud IDEs and discuss how we can leverage the concept to build better, more secure environments for our developers.
Breach of the week - This week we take a look at the Atlassian breach in which attackers were able to obtain employee credentials to gain access to a third-party HR system.
From the publisher's feed