Logo
    Search

    Security Weekly Podcast Network (Video)

    This feed includes all episodes of Paul's Security Weekly, Enterprise Security Weekly, Business Security Weekly, Application Security Weekly, and Security Weekly News! Your one-stop shop for all things Security Weekly!
    enSecurity Weekly Productions3956 Episodes

    Episodes (3956)

    More API Calls, More Problems: The State of API Security in 2024 - Lebin Cheng - ASW #276

    More API Calls, More Problems: The State of API Security in 2024 - Lebin Cheng - ASW #276

    A majority of internet traffic now originates from APIs, and cybercriminals are taking advantage. Increasingly, APIs are used as a common attack vector because they’re a direct pathway to access sensitive data. In this discussion, Lebin Cheng shares what API attack trends Imperva, a Thales Company has observed over the past year, and what steps organizations can take to protect their APIs.

    This segment is sponsored by Imperva. Visit https://www.securityweekly.com/imperva to learn more about them!

    Show Notes: https://securityweekly.com/asw-276

    Protecting Executives: Why The Home Is The New Battle Ground - Chris Pierson - BSW #341

    Protecting Executives: Why The Home Is The New Battle Ground - Chris Pierson - BSW #341

    When you think of executive protection, you think of work related activities such as security details, travel planning, and other physical security protections. But in the world of Artificial Intelligence and DeepFakes, the risk landscape for executives goes far beyond work and into their personal lives. The home is now the new battle field and family life will never be the same.

    Chris Pierson, CEO at BlackCloak, joins Business Security Weekly to discuss the changes in the risk landscape for executives, including Generative AI, and its impacts on social engineering, personal attacks, and family threats. Executive protection must now include digital protection, both at work and at home.

    This segment is sponsored by BlackCloak. Visit https://securityweekly.com/blackcloak to learn more about them!

    Show Notes: https://securityweekly.com/bsw-341

    Early stage startup M&A on fire, funding healthy, and attackers are like lawyers? - ESW #352

    Early stage startup M&A on fire, funding healthy, and attackers are like lawyers? - ESW #352

    In the enterprise security news,

    1. Axonius raises $200M and is doing $100M ARR!
    2. Claroty raises $100M and is doing $100M ARR!
    3. Crowdstrike picks up DSPM with Flow Security
    4. CyCode picks up Bearer
    5. Are attackers like lawyers?
    6. How a bank failed (with no help from a cyber attack)
    7. the FTC cracks down on customer data collection
    8. Apple’s car sadly won’t be a thing any time soon
    9. or maybe ever.

    All that and more, on this episode of Enterprise Security Weekly.

    Show Notes: https://securityweekly.com/esw-352

    What can we do today to prevent tomorrow's breach? - Michael Mumcuoglu - ESW #352

    What can we do today to prevent tomorrow's breach? - Michael Mumcuoglu - ESW #352

    Defenders spend a lot of time and money procuring and implementing security controls. At the heart of SecOps and the SOC are technologies like XDR, SIEM, and SOAR. How do we know these technologies are going to detect or prevent attacks?

    Wait for the annual pen test? Probably not a good idea.

    In this segment, we'll talk with Michael Mumcuoglu about how MITRE's ATT&CK framework can help defenders better prepare for inevitable attack TTPs they'll have knocking on their doors.

    Segment Resources:

    Show Notes: https://securityweekly.com/esw-352

    DCNextGen, Memory Safety And More! - PSW #819

    DCNextGen, Memory Safety And More! - PSW #819

    BiaSciLab from DEF CON joins us to discuss DCNextGen! In the security News: MouseJacking still works, CISA recommends a complete rebuild, memory safety and re-writing code, not all doorbells are created equal, putting a firewall in front of your LLM, rugged gear and vulnerabilities, PLCs are not safe, neither are Windows kernels..

    Segment Resources: https://www.defcon.kids https://www.BiaSciLab.com https://www.GirlsWhoHack.com https://www.SecureOpenVote.com

    Show Notes: https://securityweekly.com/psw-819

    Facing the Reality of Risk Prioritization - Dan DeCloss - PSW #819

    Facing the Reality of Risk Prioritization - Dan DeCloss - PSW #819

    Public information about exploits and vulnerabilities alone is not enough to inform prioritization, especially with the growing rate and variety of CVEs. Dan DeCloss, founder and CTO of PlexTrac, joins the show to discuss solving the challenges of risk prioritization to drive faster, more strategic assessment cycles. Spoiler: The key is adding context and prioritization to risk-scoring equations.

    Segment Resources: https://plextrac.com/get-ready-to-prioritize-risk-with-our-new-contextual-scoring-engine/?utmmedium=techptr&utmsource=securityweekly

    https://plextrac.com/video/priorities/?utmmedium=techptr&utmsource=securityweekly

    This segment is sponsored by PlexTrac. Visit https://securityweekly.com/plextrac to learn more about them!

    Show Notes: https://securityweekly.com/psw-819

    The Simple Mistakes and Complex Seeds of a Vulnerability Management Program - Emily Fox - ASW #275

    The Simple Mistakes and Complex Seeds of a Vulnerability Management Program - Emily Fox - ASW #275

    The need for vuln management programs has been around since the first bugs -- but lots of programs remain stuck in the past. We talk about the traps to avoid in VM programs, the easy-to-say yet hard-to-do foundations that VM programs need, and smarter ways to approach vulns based in modern app development. We also explore the ecosystem of acronyms around vulns and figure out what's useful (if anything) in CVSS, SSVC, EPSS, and more.

    Segment resources:

    Show Notes: https://securityweekly.com/asw-275

    The Convergence of Security, Compliance, and Risk - Igor Volovich - BSW #340

    The Convergence of Security, Compliance, and Risk - Igor Volovich - BSW #340

    The SEC's new cyber reporting requirements are forcing organizations to rethink their compliance and risk programs. No longer can compliance and risk be static, point in time assessments. Instead they need to match the speed of security which is dynamic and real-time. Couple the difference in speeds with whistleblowers and attack groups reporting non-compliance with the new SEC rules and organizations find themselves in a regulatory nightmare.

    Igor Volovich, VP of Compliance Strategy for Cyber Compliance at Qmulos, joins BSW to share his "Notes from the battlefield" on how automation is the only way to effectively converge security, risk, and compliance into a dynamic, real-time discipline.

    Show Notes: https://securityweekly.com/bsw-340

    Funding goes quiet while M&A makes some noise! - ESW #351

    Funding goes quiet while M&A makes some noise! - ESW #351

    In this week's news segment, we discuss the lack of funding announcements, and the potential effect RSA could have on the timing of all sorts of press releases. We also discuss 1Password's potential future with its sizable customer base and the $620M it raised a few years back.

    Some other topics we discuss:

    • NIST CSF 2.0
    • insider threats
    • Ivanti Pulse Secure's appliance software found to be running positively ancient software (11 year old Linux distro, 5-20+ year old libraries & components)
    • Nevada AG trying to get messaging decrypted for children, to "protect them"
    • Kelly Shortridge's response to CISA's secure development RFI
    • OpenAI's new GenAI video product, Sora and the potential impact it could have on cybersecurity
    • Instacart spews out crappy AI recipes and photos

    Show Notes: https://securityweekly.com/esw-351

    Hacktivism Unveiled: Insights into the Footprints of Hacktivists - Pascal Geenens - ESW #351

    Hacktivism Unveiled: Insights into the Footprints of Hacktivists - Pascal Geenens - ESW #351

    Pascal Geenens from Radware joins us to discuss the latest research findings relating to hacktivists an other actors using volumetric and other network-based attacks. We'll discuss everything from the current state of DDoS attacks to use in the military and even the impact of cyberattacks on popular culture!

    You can find the report Pascal mentions here, on Radware's website: https://www.radware.com/threat-analysis-report/

    Show Notes: https://securityweekly.com/esw-351

    Malware In Strange Places, Overheating, LockBit - PSW #818

    Malware In Strange Places, Overheating, LockBit - PSW #818

    The latest attacks against WiFi, its illegal to break encryption, BLE Padlocks are as secure as you think, when command not found attacks, how did your vibrator get infected...with malware, the OT jackpot, the backdoor in a random CSRF library, it’s a vulnerability but there is no CVE, car theft and Canada, Glubteba, and settings things on fire!

    Show Notes: https://securityweekly.com/psw-818

    Social Engineering: AI & Living Off The Land - Jayson E. Street - PSW #818

    Social Engineering: AI & Living Off The Land - Jayson E. Street - PSW #818

    Jayson joins us to discuss how he is using, and social engineering, AI to help with his security engagements. We also talk about the low-tech tools he employs to get the job done, some tech tools that are in play, and the most important part of any security testing: Talking to people, creating awareness, and great reporting.

    Show Notes: https://securityweekly.com/psw-818