The Security Swarm Podcast

The Security Swarm Podcast

By HornetsecurityNewsTechnologyTech News
Download on the App Store

The Security Swarm Podcast episodes

  • EP 10: Tips and Tricks for Working with CISOs

    We’re back for another episode with Lia Fey, Customer Success Lead at Hornetsecurity. In today’s episode, Lia brings her wealth of experience working closely with CISOs on a daily basis to share valuable insights and strategies for effectively collaborating with them.  

    CISOs face a unique set of challenges as they operate in high-pressure environments and navigate the intersection of compliance requirements as well as the security needs of an organization.  

    Join us as we explore the multifaceted nature of working with CISOs on security awareness and discover tips and tricks for fostering effective partnerships in the ever-evolving security and compliance landscape. 

    Timestamps:

    3:25 – Initial Impressions and responsibilities of CISOs? 

    5:47 – CISOs and Interactions with the Rest of the Organization 

    8:47 – Responsibilities of CISOs 

    15:59 – What is the Most Effective Way to Communicate with CISOs 

    21:40 – How can we help CISOs solve difficult business challenges? 

    Episode Resources:

    EP09: Real World Guidance on Security Awareness Service

    Security Awareness Service

    Andy on LinkedIn, Twitter or Mastodon 

    Lia on LinkedIn 

    27 min
  • EP09: Real-World Guidance on Security Awareness Service

    In today’s episode, our host Andy sits down with Lia Fey, Customer Success Lead at Hornetsecurity, to discuss why employees need to be trained on security awareness and what type of training works best. In addition, they explore the challenges businesses face when trying to train their employees in today’s digital landscape.  

    Lia Fey brings her expertise to the table and sheds light on real-world scenarios where organizations have successfully prevented attacks because an end user possessed the knowledge and ability to react appropriately. 

    Timestamps:

    2:32 – What is a security awareness service? 

    9:38 – Why is security awareness training so effective? 

    12:45 – Measuring end-user success and right-sizing training 

    20:11 – What is the right kind of end-user security training? 

    24:22 – Some real-world scenarios 

    28:35 – Do security awareness services help spot threats outside of email? 

    Episode Resources:

    Security Awareness Service

    Cyber Security Report 2023

    Andy on LinkedIn, Twitter or Mastodon 

    Lia on LinkedIn 

    33 min
  • EP08: Advanced Threat Protection: A Must Have in Today’s Ecosystem?

    We’re back for another episode with Umut Alemdar - Head of Security Lab here at Hornetsecurity. Today, we’re discussing Advanced Threat Protection (ATP) and its crucial role in detecting, preventing, and responding to increasingly sophisticated cyber threats. 

    Throughout the episode, Andy and Umut discuss common ATP techniques such as sandboxing, time of click protection, and spam filters, all of which are critical in fortifying defenses against malicious actors. Furthermore, they emphasize the vital function of the natural language understanding module in ATP in detecting sophisticated social engineering attacks.  

    While this episode focuses on ATP in general, Andy and Umut draw concrete examples from our own ATP scanning methods here at Hornetsecurity.  

    Timestamps:

    2:05 – What is Advanced Threat Protection 

    5:50 – What are common scanning techniques used by ATP technologies 

    10:35 – How does Sandboxing work in ATP scanning techniques? 

    13:07 – What is the role of AI within ATP scanning? 

    18:09 – Concrete example of where ATP saves the day 

    20:11 – Scanning for malicious QR codes 

    Episode Resources: 

    Advanced Threat Protection

    We used ChatGPT to Create Ransomware

    Bit.ly QR Code Index

    Andy on LinkedIn, Twitter or Mastodon 

    Umut on LinkedIn 

    29 min
  • EP07: A Discussion and Analysis of Qakbot

    In today’s episode, Andy and Umut Alemdar explore one of the most malicious botnets in today’s digital threat landscape: Qakbot. What makes Qakbot so dangerous? 

    Qakbot originally started out as an information stealer back in 2007. Over the years, it has undergone significant transformations, evolving into a multi-modular malware that poses a severe threat to businesses. In our discussion and analysis, we uncover its attack chain from infecting a system to downloading malicious payload. 

    Timestamps:

    3:24 – What is Qakbot? 

    5:18 – An overview of Qakbot’s attack chain and capabilities 

    14:38 – Mitigation and defence strategies for Qakbot  

    19:48 – What does the future look like for Qakbot? 

    Episode Resources:

    The Reemergence of Emotet and Why Botnets Continue to Return

    Security Awareness Service

    Advanced Threat Protection

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Umut on LinkedIn 

    26 min
  • EP06: How Secure is Microsoft 365?

    In this episode, Andy and Paul Schnackenburg, Microsoft Certified Trainer, investigate the burning question on everyone's mind: Is Microsoft 365 a secure platform? As we discuss the intricate details and inner workings of Microsoft 365 security, we leave no stone unturned.  

    Tune in to learn valuable insights and expert analysis on the subject, as well as how Microsoft 365 holds up in today's ever-changing threat landscape. 

    Timestamps:

    2:30 – Is Microsoft 365 secure? 

    6:32 – Management portal and configuration creep in M365 

    13:28 – Does file sharing in M365 create a security problem? 

    20:07 – Lack of transparency in regards to internal cloud infrastructure CVEs 

    25:36 – The mentality of security – just because it’s in “the cloud” 

    29:38 – Ultimately it’s the “customer’s” responsibility to stay safe 

    Episode Resources:

    Microsoft 365 Security Checklist

    365 Total Protection Compliance & Awareness - Free Trial

    Azure Blunder left Bing Results Editable 

    365 Permission Manager Free Trial 

    Find Andy on LinkedIn, Twitter or Mastadon

    Find Paul on LinkedIn or Twitter

    34 min
  • EP05: What is Immutability and Why Do Ransomware Gangs Hate it?

    In today’s episode, we welcome Philip Galea, an esteemed expert in immutability and backups at Hornetscurity. With ransomware being one of the most pervasive issues in the industry today, immutability emerges as a powerful weapon against ransomware gangs.  

    The term immutability is thrown around a lot in the cybersecurity community, but what does it mean, and why do ransomware gangs hate it?  This episode provides a fascinating insight into immutability and its vital role in the fight against ransomware. 

    Timestamps:

    4:25 – What is immutability?

    9:34 – How ransomware drove the need for immutability

    12:30 – Ransomware creation via ChatGPT

    18:12 – Are there benefits and use cases for immutability outside of backup?

    21:30 – How does immutability really work?

    24:57 – What’s to stop a rogue admin from “Tinkering” with immutable storage?

    Episode resources:

    EP01: We used ChatGPT to Create Ransomware

    MITRE ATT&CK DK

    Hornetsecurity VM Backup

    34 min
  • EP04: The Modern Take on Social Engineering in Email

    In this episode, we delve into the world of social engineering, phishing, and spam campaigns, exploring modern techniques threat actors are using to trick users into divulging sensitive information through email. Security Evangelist Andy and guest expert Umut Alemdar, head of the Security Lab here at Hornetsecurity, explain how phishing remains the top method of attack for many cybercriminals due to its cost-effectiveness and ability to exploit human vulnerability. 

    Attackers use excellent context and timing to create convincing email messages that trick even the most savvy users into divulging sensitive information. Despite the prevalence of anti-spam solutions, phishing continues to rise as attackers adapt and evolve their techniques. 

    Tune in to gain a better understanding of social engineering and how to protect your organization in the modern age. 

    Timestamps:

    1:47 – Social engineering, phishing, and spam campaigns: still a problem in the modern era 

    6:30 – Why is phishing so effective, even today? 

    11:43 – What other types of attacks does phishing enable for end users? 

    16:48 – How does the industry ultimately solve the problem of phishing?

    Episode resources: 

    Cyber Security Report 2023        

    Security Awareness Services   

    Google and Facebook Accounts Payable Fraud   

    Find Andy on LinkedIn , Twitter , Mastodon 

    Find Umut on LinkedIn 

     

     

    22 min
  • EP03: The Reemergence of Emotet and Why Botnets Continue to Return

    Welcome back to the Security Swarm Podcast! In this episode, our host Andy Syrewicze talks with Umut Alemdar, Head of Security Lab here at Hornetsecurity, about the reemergence of Emotet and the pervasiveness of botnets. Why do they keep coming back? 

    Emotet, a well-known botnet for spreading malware and stealing personal information, had been dormant since December before reappearing in March 2023 with new tactics and capabilities. The Botnet has a modular architecture that allows threat actors to include any kind of payload that gets executed on the victim’s device. 

    Tune in to hear Andy and Umut discuss the attack chain of Emotet, how it has evolved and the risks it may pose to your organization. They also explore why botnets such as Emotet persist despite efforts to shut them down. 

    Timestamps:

    1:58 – What is Emotet? 

    6:25 – Emotet’s Attack Chain 

    12:20 – How do Botnets continue to return? 

    14:44 – How can organizations guard against botnets like Emotet? 

    Episode resources:

    Hornetsecurity Article Regarding Emotet

    Hornetsecurity CyberSecurity Roundtable Discussion

    Advanced Threat Protection

    Security Awareness Services

    Andy on LinkedIn, Twitter, Mastadon

    Umut on LinkedIn

    22 min
  • EP02: How Tech Pros Handle Security News

    Welcome back for another episode of the Security Swarm Podcast, the podcast that brings you the insights and expertise straight from the Security Lab here at Hornetsecurity. In this episode, we’ll be diving into recent security disclosures with Eric Siron, Microsoft MVP, and discussing how organizations should respond when vulnerabilities are discovered. 

    We’ll focus on two major incidents as examples throughout this episode; the Outlook Vulnerability CVE-2023-23397, and the re-emergence of Emotet. 

    In today’s digital landscape, threats are constantly evolving and becoming more sophisticated, making it critical to respond quickly and efficiently minimize the impact of such incidents. Whether you’re a SysAdmin working in a small organization or the CISO of a large business, you have to be more vigilant, and have a plan. 

    Tune in to learn valuable insights into how tech professionals should handle security news.  

    Timestamps:

    3:16 – A baseline example of a busy security news-cycle 

    8:00 – Keeping an eye on the security news-cycle and has it always been this way? 

    17:45 – What should organizations be doing to keep tabs on the security news-cycle? 

    23:21 – What can vendors be doing better to help SysAdmins handle security news? 

    Episode resources:

    CVE-2023-23397

    The Re-Emergence of Emotet

    Hornetsecurity July 2022 Threat Review with Talk of Qakbot

    White House to Shift Cybersecurity Burden

    Andy on LinkedIn , Twitter , Mastodon

    Eric on Twitter

    30 min
  • EP01: We Used ChatGPT to Create Ransomware

    In our very first episode we welcome Yvonne Bernard to the show for an in depth discussion into the security implications of ChatGPT. There is no doubting that ChatGPT and other recent AI models have brought some very positive change to a number of industries. However, did you know that there is potentially a darker side to AI? Can it be used for malicious purposes? The short answer is yes! In fact, we were able to use ChatGPT here at Hornetsecurity to essentially create ransomware! 

    In today’s episode we discuss the particulars of that process, the implications as well as other methods threat-actors can use to get ChatGPT to help them with illicit activities! 

    Timestamps: 

    5:51 - What are the cybersecurity benefits of ChatGPT? 

    10:05 - How is ChatGPT used for malicious use by threat-actors? 

    17:15 - Does OpenAI have controls in place to prevent malicious use? 

    20:48 - What are the legal implications that ChatGPT brings to the industry? 

    23:40 - What does the industry do about the potential security implications of ChatGPT? 

    Episode Resources: 

    The DAN Method on Reddit

    Hornetsecurity Webinar on the Security Implications of ChatGPT 

    Andy on LinkedIn, Twitter, Mastadon 

    Yvonne on LinkedIn 

    Security Awareness Service from Hornetsecurity 

    28 min

About The Security Swarm Podcast

From the publisher's feed

Welcome to The Security Swarm Podcast – a weekly conversation of the most critical issues facing the world of cybersecurity today, hosted by Andy Syrewicze, Security Evangelist at Hornetsecurity.