
Sign up to save your podcasts
Or


Jim Manico is full of opinions. The founder of Manicode Security has advice on how to use the OWASP Top 10, on secure coding and especially on the OWASP Application Security Verification Standard (ASVS). He has advice for people starting out in security and all around thoughts on what it means to be a decent person. Jim is definitely one of those! He's also an educator, author, investor and entrepreneur. There are so many reasons to listen to this episode. Here are just a few:
* Hear from one of the leading educators focused on helping developers code securely.
* Learn more about all the important projects and initiatives happening at OWASP.
* Get Jim's perspective on how organizations can best implement DevSecOps.
Key quotes:
* "Honestly, you shouldn't be basing a security program on the OWASP Top 10. The Top 10 is meant for one purpose only: awareness. This is not just my opinion. This is actually codified in the introduction of the Top 10."
* "Being a decent human being, being a community supporter, trying to help people out, giving free talks: you can call it being a decent person, but it's also a good life and business strategy."
* "Learn how to f-ing code. And you don't have to be an expert at it. You don't have to be a software engineer, but if you're an IT professional and you don't even understand the basics of coding, it's going to limit your capability because the best pentesters I know write scripts."
Related links:
* https://manicode.com/
* https://owasp.org/www-project-top-ten/
* https://owasp.org/www-project-application-security-verification-standard/
* https://www.synack.com/
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Alex Holden has a knack for tracking Russian cyber criminals. The Ukrainian-born cybersecurity expert understands what it takes to infiltrate ransomware outfits, learn their secrets and help organizations protect themselves against their tactics. Beyond that, his firm is responsible for detecting some of the biggest breaches in recent history. In this episode, Alex talks about his approach to tracking the world's most notorious criminal hackers, the current cyber threat in Eastern Europe and his own journey from Kyiv to the American midwest.
Why should listen:
* Get the inside story of how the Conti ransomware gang and other Eastern European cybercrime syndicates operate.
* Hear about how the current Ukrainian War could shift the cyber threat landscape.
* Discover how one of the leading threat intelligence researchers uncovered some of the biggest data breaches in history.
Key quotes:
* "Russia knows how to wage cyber warfare. And they continuously keep showing us that they can ... So I think Russia is in [a] very powerful position to flex their cyber muscle to do damage."
* "We are watching a huge change in the cybersecurity threat landscape in Eastern Europe. Ukrainian cybercrime is not dead. They're still doing certain things in the western part of Ukraine. Some of them are moving into Eastern Europe ... The same is happening in Russia. Cyber criminals are afraid that the recent crackdown of the Russian government against them will continue."
* "If you are at all interested in threat intelligence or in cybersecurity, I would recommend sitting down and reading [the Conti leaks] because you're going to see how the real criminals work, how they think, how they evolve and how the everyday gang works."
Links:
* https://holdsecurity.com/
* https://www.synack.com/
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
There's a flood of cybersecurity news as a result of the Ukraine War as well as Washington's recent efforts to compel organizations to report cyberattacks to federal officials. In this episode, Trey Herr and Emma Schroeder of the Atlantic Council’s Cyber Statecraft Initiative break it all down. They explore the consequences of an escalating digital battlefield in Europe, whether a hack could bring NATO into the war and strategies for creating more consensus within the tangled and complicated realm of cyber policy.
Why you should listen:
* Understand what's at stake as cyber warriors do battle on both sides of the the Ukraine War.
* Lean about some potential consequences of a destructive hack in Europe and whether that could even draw NATO into the war.
* Hear what Washington is doing to obtain better insights and actionable intelligence that could improve cybersecurity defenses.
Key quotes:
* "Cybersecurity generally is not a good state of affairs. So I think we are going to see some regulatory changes that make it much harder for certain classes of companies to operate because they've grown up around this inefficient system."
* "The physical military invasion [into Ukraine] has not necessitated sophisticated cyber support from the Russians. What's been more important in the information space is misinformation [and] disinformation."
* "You've got a lot of [outside hackers] tripping over systems to try to find some kind of way in to do something. And the challenge is that's not really strategic. You don't have any of these groups plugged into the target selection and intelligence collection processes that Western agencies have."
Links:
* https://www.atlanticcouncil.org/
* https://www.atlanticcouncil.org/programs/scowcroft-center-for-strategy-and-security/cyber-statecraft-initiative/
* https://www.atlanticcouncil.org/thecybermoonshot/
* https://www.synack.com/
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Gabriella Coleman, a Harvard University anthropology professor, describes how she immersed herself in hacker culture and eventually became embedded in the shadowy and mercurial world of Anonymous, the hacktivist collective she chronicled in her 2015 book, "Hacker, Hoaxer, Whistleblower, Spy: The Many Faces of Anonymous." This is such a fascinating episode that explores the often misunderstood history of hacking and how many in this community went from outside agitators to mainstream security researchers.
-------
Why you should listen:
* Get a better understanding of the history of Anonymous and the role it played in shaping online protests and whistleblowing.
* Hear about some of the earliest hacking communities such as the free software hackers and efforts to archive their early writings and magazines.
* Get an anthropological perspective on how hackers have evolved from the fringes of the tech world to among the most influential voices in cybersecurity.
-------
Key quotes:
* "There's now a new narrative that there was a single founder of Anonymous, the trolls and the early hacktivists. And that's just wrong in terms of historical record."
* "I'm not surprised that hackers were at the forefront of establishing the protocols for the security industry."
* "The moment you cower, the moment you're not willing to speak up, that's the minute that I think ... the hacker spirit is dead and can't be effective in initiating change."
-------
Links:
* https://www.synack.com/
* https://gabriellacoleman.org/
* https://datasociety.net/library/wearing-many-hats-the-rise-of-the-professional-security-hacker/
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
In this episode, Micah Hoffman talks about his career in Open Source Intelligence (OSINT) and the value it has for investigations, cybersecurity and understanding how information is weaponized. He also gets into strategies for safeguarding personal privacy in the face of increasing digital surveillance. This episode will have you thinking twice about what you post on social media!
Why you should listen:
* Hear from one of the leading Open Source Intelligence researchers working today.
* Learn about the value of OSINT for offensive and defensive cybersecurity.
* Get a better understanding of all the privacy risks from fitness trackers, apps, shopping online and social media.
Key quotes:
* "OSINT is a reconnaissance skill. It's all about that preparation work that needs to be done before you do anything in cyber, whether it's attacking or defending."
* "Once things are on the internet -- or once things are even collected, not necessarily on the internet -- you've lost control of it."
* "The reality is that we give up our privacy every single time we use an app, every single time we choose to purchase something."
Links:
* https://www.spotlight-infosec.com/
* https://osintcurio.us/
* https://www.synack.com/
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Nicolas Chaillan, former Air Force Chief Software Officer, resigned from the DoD over frustrations with what he called a lack of innovation, collaboration and agility. He gets into those issues and talks about how the U.S. can invest more in technology to compete with China in artificial intelligence and cybersecurity.
---------
Why you should listen:
* Nicolas offers a candid and controversial view of the military's approach to the growing technological threat from China.
* He outlines his view for a Pentagon that is more agile, collaborative and competitive.
* Hear from a former DoD insider about some of the institutional barriers that can hinder innovation and software advancements.
---------
Key quotes:
* "In 10, 15, 20 years from now, America as we know it and the value we have and the freedom we enjoy will be at risk of going away if China dominates in AI like they are doing now."
* "TikTok is effectively an intelligence weapon of China on US citizens right now."
* "We don't see a lot of training and implementation of Agile at all in the DoD, which really leads to the inability to move at the pace of relevance and tremendous waste of taxpayer money."
---------
* https://www.synack.com/
* https://www.linkedin.com/in/nicolaschaillan/
* https://www.linkedin.com/pulse/time-say-goodbye-nicolas-m-chaillan/
* https://ama.preventbreach.com/register
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
In this episode, Phillip Wylie talks about his journey from pro wrestling to pentesting and what motivated him to start teaching, mentoring and giving back to the infosec community. It's an inspirational story for veterans in the field and newbies alike. Phillip not only talks about his work helping others get started in ethical hacking, but the value of truly understanding the mind of the adversary.
-------
Why you should listen:
* Phllip's story is both educational and inspirational -- worthwhile for anyone interested or involved in cybersecurity.
* Learn something from one of the most prolific cybersecurity speakers and educators.
* Get a better understanding of ethical hacking and the value of offensive security testing.
-------
Key quotes:
* "Once you learn how to pentest, your whole world changes."
* "For people that have been in the industry for a while, listen to the new folks. I learned a lot from my students."
* "If you can help people succeed, that's even more rewarding than personal success."
-------
Links:
* www.synack.com
* https://twitter.com/PhillipWylie
* https://www.youtube.com/c/ThePwnSchoolProject
* https://www.itspmagazine.com/the-hacker-factory-podcast
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Kim Zetter is a former staff writer at WIRED and author of the seminal cybersecurity book “Countdown to Zero Day: Stuxnet and the Launch of the World’s First Digital Weapon.” Her work has appeared in The New York Times, POLITICO, The Washington Post and regularly in her Substack newsletter, “Zero Day.” In this episode, Kim talks about her approach to reporting, what sparked her Stuxnet investigation and how the discovery of that malware fundamentally altered our global cybersecurity conversation.
Why you should listen:
* Hear from one of the most influential and knowledgeable journalists writing about cybersecurity today.
* Get her take on some of the biggest security stories of 2021 such as Colonial Pipeline and the Pegasus Project.
* Learn more about the key policy debates around election security and critical infrastructure protections.
Key Quotes:
* “Stuxnet really helped shine a light on industrial control systems as a target.”
* “We focus too much on the stuff that makes the headlines and completely ignore the innocuous things that you’re downloading onto your phone .... Those things are spying on you, as well.”
* “The Obama administration was the first administration to [make] cyber a priority, but they didn't really put critical infrastructure as a priority in the sense of using the government's weight to force security on critical infrastructure. We're actually only seeing that in this last year … in the wake of Colonial Pipeline.”
* “When we saw Russia trying to interfere in 2016, that woke up DHS that someone, somewhere needed to have some kind of influence over election officials.”
Links:
* www.synack.com
* https://zetter.substack.com/
* https://www.nytimes.com/2018/09/26/magazine/election-security-crisis-midterms.html
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Defense Digital Service Acting Director Katie Olson heads up a team of about 80 technologists working on some of the toughest challenges facing the U.S. Department of Defense. Since Katie started leading the team, often called the Pentagon’s “SWAT team of nerds," it has increasingly focused on the threat from drones, cybersecurity risks in space and the consequences of climate change. In this episode, Katie talks about this cutting-edge work, how DDS helped the Pentagon reduce the impact of COVID-19 and what big issues her team will tackle next.
-------
Why you should listen:
* Learn about some of the most cutting-edge work going on inside the Pentagon.
* Better understand emerging threats such as drones and risks associated with climate change.
* Hear how DDS helped the military rapidly deploy technology to reduce the spread of COVID-19.
-------
Key Quotes:
* "What I've seen shifting in my time here is making security researchers the good guys."
* “Facilitated by the pandemic, we are seeing just increased awareness and attention to cybersecurity.”
* “It would be better for us to check our defenses first before we have some kind of major breach.”
* “For those white hat hackers who want to contribute to national security, [there’s] a huge opportunity.”
-------
Related Links:
www.synack.com
https://www.dds.mil/
https://www.synack.com/blog/3-years-of-hack-the-pentagon/
https://www.usds.gov/projects/hack-the-pentagon
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Earlier this year, the Electronic Frontier Foundation named Matt Mitchell, founder of CryptoHarlem, one of its 2021 Pioneer Award winners for his groundbreaking work to protect Black communities from surveillance. In this episode, Matt talks about what led him to apply his hacking skills to social justice causes and how that led to his role today as a Technology Fellow for the BUILD program at the Ford Foundation. Matt also discusses what Twitch can do to safeguard creators and the steps anyone can take to better protect themselves online.
--------
Why you should listen:
* Hear from a hacker working on the frontlines of today’s most important racial justice issues.
* Better understand the state of digital surveillance in Black communities.
* Hear about what steps platforms such as Twitch can take to better protect creators.
* Learn the three things everyone online should do to better protect themselves on the internet.
* Discover where “Mr. Robot” placed an elusive CryptoHarlem Easter egg.
--------
Key Quotes:
* “It's really about taking the skill that we have and applying it toward something bigger than yourself.”
* “Under the lens of a surveyor, who’s always looking for wrongs, you’ll find what you’re looking for all the time.”
* “We sometimes confuse public safety with surveillance.”
* “I'm pretty realistic. If you look at the number of cyberattacks that came from sticky notes on personal computers, it’s zero. But don’t put a sticky note on the nuclear codes.”
--------
Related Links:
* Synack.com
* https://www.cryptoharlem.com/
* https://www.fordfoundation.org/
* https://calyxinstitute.org/
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
From the publisher's feed

421 Listeners

8,054 Listeners