
Sign up to save your podcasts
Or


We’re back for another episode with Lia Fey, Customer Success Lead at Hornetsecurity. In today’s episode, Lia brings her wealth of experience working closely with CISOs on a daily basis to share valuable insights and strategies for effectively collaborating with them.
CISOs face a unique set of challenges as they operate in high-pressure environments and navigate the intersection of compliance requirements as well as the security needs of an organization.
Join us as we explore the multifaceted nature of working with CISOs on security awareness and discover tips and tricks for fostering effective partnerships in the ever-evolving security and compliance landscape.
Timestamps:
3:25 – Initial Impressions and responsibilities of CISOs?
5:47 – CISOs and Interactions with the Rest of the Organization
8:47 – Responsibilities of CISOs
15:59 – What is the Most Effective Way to Communicate with CISOs
21:40 – How can we help CISOs solve difficult business challenges?
Episode Resources:
EP09: Real World Guidance on Security Awareness Service
Security Awareness Service
Andy on LinkedIn, Twitter or Mastodon
Lia on LinkedIn
In today’s episode, our host Andy sits down with Lia Fey, Customer Success Lead at Hornetsecurity, to discuss why employees need to be trained on security awareness and what type of training works best. In addition, they explore the challenges businesses face when trying to train their employees in today’s digital landscape.
Lia Fey brings her expertise to the table and sheds light on real-world scenarios where organizations have successfully prevented attacks because an end user possessed the knowledge and ability to react appropriately.
Timestamps:
2:32 – What is a security awareness service?
9:38 – Why is security awareness training so effective?
12:45 – Measuring end-user success and right-sizing training
20:11 – What is the right kind of end-user security training?
24:22 – Some real-world scenarios
28:35 – Do security awareness services help spot threats outside of email?
Episode Resources:
Security Awareness Service
Cyber Security Report 2023
Andy on LinkedIn, Twitter or Mastodon
Lia on LinkedIn
We’re back for another episode with Umut Alemdar - Head of Security Lab here at Hornetsecurity. Today, we’re discussing Advanced Threat Protection (ATP) and its crucial role in detecting, preventing, and responding to increasingly sophisticated cyber threats.
Throughout the episode, Andy and Umut discuss common ATP techniques such as sandboxing, time of click protection, and spam filters, all of which are critical in fortifying defenses against malicious actors. Furthermore, they emphasize the vital function of the natural language understanding module in ATP in detecting sophisticated social engineering attacks.
While this episode focuses on ATP in general, Andy and Umut draw concrete examples from our own ATP scanning methods here at Hornetsecurity.
Timestamps:
2:05 – What is Advanced Threat Protection
5:50 – What are common scanning techniques used by ATP technologies
10:35 – How does Sandboxing work in ATP scanning techniques?
13:07 – What is the role of AI within ATP scanning?
18:09 – Concrete example of where ATP saves the day
20:11 – Scanning for malicious QR codes
Episode Resources:
Advanced Threat Protection
We used ChatGPT to Create Ransomware
Bit.ly QR Code Index
Andy on LinkedIn, Twitter or Mastodon
Umut on LinkedIn
In today’s episode, Andy and Umut Alemdar explore one of the most malicious botnets in today’s digital threat landscape: Qakbot. What makes Qakbot so dangerous?
Qakbot originally started out as an information stealer back in 2007. Over the years, it has undergone significant transformations, evolving into a multi-modular malware that poses a severe threat to businesses. In our discussion and analysis, we uncover its attack chain from infecting a system to downloading malicious payload.
Timestamps:
3:24 – What is Qakbot?
5:18 – An overview of Qakbot’s attack chain and capabilities
14:38 – Mitigation and defence strategies for Qakbot
19:48 – What does the future look like for Qakbot?
Episode Resources:
The Reemergence of Emotet and Why Botnets Continue to Return
Security Awareness Service
Advanced Threat Protection
Find Andy on LinkedIn, Twitter or Mastadon
Find Umut on LinkedIn
In this episode, Andy and Paul Schnackenburg, Microsoft Certified Trainer, investigate the burning question on everyone's mind: Is Microsoft 365 a secure platform? As we discuss the intricate details and inner workings of Microsoft 365 security, we leave no stone unturned.
Tune in to learn valuable insights and expert analysis on the subject, as well as how Microsoft 365 holds up in today's ever-changing threat landscape.
Timestamps:
2:30 – Is Microsoft 365 secure?
6:32 – Management portal and configuration creep in M365
13:28 – Does file sharing in M365 create a security problem?
20:07 – Lack of transparency in regards to internal cloud infrastructure CVEs
25:36 – The mentality of security – just because it’s in “the cloud”
29:38 – Ultimately it’s the “customer’s” responsibility to stay safe
Episode Resources:
Microsoft 365 Security Checklist
365 Total Protection Compliance & Awareness - Free Trial
Azure Blunder left Bing Results Editable
365 Permission Manager Free Trial
Find Andy on LinkedIn, Twitter or Mastadon
Find Paul on LinkedIn or Twitter
In today’s episode, we welcome Philip Galea, an esteemed expert in immutability and backups at Hornetscurity. With ransomware being one of the most pervasive issues in the industry today, immutability emerges as a powerful weapon against ransomware gangs.
The term immutability is thrown around a lot in the cybersecurity community, but what does it mean, and why do ransomware gangs hate it? This episode provides a fascinating insight into immutability and its vital role in the fight against ransomware.
Timestamps:
4:25 – What is immutability?
9:34 – How ransomware drove the need for immutability
12:30 – Ransomware creation via ChatGPT
18:12 – Are there benefits and use cases for immutability outside of backup?
21:30 – How does immutability really work?
24:57 – What’s to stop a rogue admin from “Tinkering” with immutable storage?
Episode resources:
EP01: We used ChatGPT to Create Ransomware
MITRE ATT&CK DK
Hornetsecurity VM Backup
In this episode, we delve into the world of social engineering, phishing, and spam campaigns, exploring modern techniques threat actors are using to trick users into divulging sensitive information through email. Security Evangelist Andy and guest expert Umut Alemdar, head of the Security Lab here at Hornetsecurity, explain how phishing remains the top method of attack for many cybercriminals due to its cost-effectiveness and ability to exploit human vulnerability.
Attackers use excellent context and timing to create convincing email messages that trick even the most savvy users into divulging sensitive information. Despite the prevalence of anti-spam solutions, phishing continues to rise as attackers adapt and evolve their techniques.
Tune in to gain a better understanding of social engineering and how to protect your organization in the modern age.
Timestamps:
1:47 – Social engineering, phishing, and spam campaigns: still a problem in the modern era
6:30 – Why is phishing so effective, even today?
11:43 – What other types of attacks does phishing enable for end users?
16:48 – How does the industry ultimately solve the problem of phishing?
Episode resources:
Cyber Security Report 2023
Security Awareness Services
Google and Facebook Accounts Payable Fraud
Find Andy on LinkedIn , Twitter , Mastodon
Find Umut on LinkedIn
Welcome back to the Security Swarm Podcast! In this episode, our host Andy Syrewicze talks with Umut Alemdar, Head of Security Lab here at Hornetsecurity, about the reemergence of Emotet and the pervasiveness of botnets. Why do they keep coming back?
Emotet, a well-known botnet for spreading malware and stealing personal information, had been dormant since December before reappearing in March 2023 with new tactics and capabilities. The Botnet has a modular architecture that allows threat actors to include any kind of payload that gets executed on the victim’s device.
Tune in to hear Andy and Umut discuss the attack chain of Emotet, how it has evolved and the risks it may pose to your organization. They also explore why botnets such as Emotet persist despite efforts to shut them down.
Timestamps:
1:58 – What is Emotet?
6:25 – Emotet’s Attack Chain
12:20 – How do Botnets continue to return?
14:44 – How can organizations guard against botnets like Emotet?
Episode resources:
Hornetsecurity Article Regarding Emotet
Hornetsecurity CyberSecurity Roundtable Discussion
Advanced Threat Protection
Security Awareness Services
Andy on LinkedIn, Twitter, Mastadon
Umut on LinkedIn
Welcome back for another episode of the Security Swarm Podcast, the podcast that brings you the insights and expertise straight from the Security Lab here at Hornetsecurity. In this episode, we’ll be diving into recent security disclosures with Eric Siron, Microsoft MVP, and discussing how organizations should respond when vulnerabilities are discovered.
We’ll focus on two major incidents as examples throughout this episode; the Outlook Vulnerability CVE-2023-23397, and the re-emergence of Emotet.
In today’s digital landscape, threats are constantly evolving and becoming more sophisticated, making it critical to respond quickly and efficiently minimize the impact of such incidents. Whether you’re a SysAdmin working in a small organization or the CISO of a large business, you have to be more vigilant, and have a plan.
Tune in to learn valuable insights into how tech professionals should handle security news.
Timestamps:
3:16 – A baseline example of a busy security news-cycle
8:00 – Keeping an eye on the security news-cycle and has it always been this way?
17:45 – What should organizations be doing to keep tabs on the security news-cycle?
23:21 – What can vendors be doing better to help SysAdmins handle security news?
Episode resources:
CVE-2023-23397
The Re-Emergence of Emotet
Hornetsecurity July 2022 Threat Review with Talk of Qakbot
White House to Shift Cybersecurity Burden
Andy on LinkedIn , Twitter , Mastodon
Eric on Twitter
In our very first episode we welcome Yvonne Bernard to the show for an in depth discussion into the security implications of ChatGPT. There is no doubting that ChatGPT and other recent AI models have brought some very positive change to a number of industries. However, did you know that there is potentially a darker side to AI? Can it be used for malicious purposes? The short answer is yes! In fact, we were able to use ChatGPT here at Hornetsecurity to essentially create ransomware!
In today’s episode we discuss the particulars of that process, the implications as well as other methods threat-actors can use to get ChatGPT to help them with illicit activities!
Timestamps:
5:51 - What are the cybersecurity benefits of ChatGPT?
10:05 - How is ChatGPT used for malicious use by threat-actors?
17:15 - Does OpenAI have controls in place to prevent malicious use?
20:48 - What are the legal implications that ChatGPT brings to the industry?
23:40 - What does the industry do about the potential security implications of ChatGPT?
Episode Resources:
The DAN Method on Reddit
Hornetsecurity Webinar on the Security Implications of ChatGPT
Andy on LinkedIn, Twitter, Mastadon
Yvonne on LinkedIn
Security Awareness Service from Hornetsecurity
From the publisher's feed