Podcasts by Pauls Security Weekly TV

Paul's Security Weekly TV

Security news, interviews, how-to technical segments. For security professionals by security professionals. We Hack Naked.

Further podcasts by Security Weekly

Podcast on the topic Technologie

All episodes

Paul's Security Weekly TV
The DIY AppSec Lab - ASW #185 from 2022-02-21T22:00

Lots of web hacking can be done directly from the browser. Throw in a proxy like Burp plus the browser's developer tools window and you've got a nearly complete toolkit. But nearly complete mean...

Listen
Paul's Security Weekly TV
Cisco/Splunk Rumors, Canonic Security, Unhelpful Legislation, & Securonix Round - ESW #261 from 2022-02-19T22:00

Finally, in the Enterprise Security News, Securonix raises $1B in Vista-led round (it’s like they ate a unicorn!), Salt Security becomes a Unicorn, has not been eaten (yet), Legit Security raise...

Listen
Paul's Security Weekly TV
Pixelating Info, Pilfer Or Report, Digital Credit Unions, & Airtag Abuse - PSW #728 from 2022-02-19T10:00

This week in the Security News: To steal or collect a bug bounty, print bombing an NFL team, Webkit strikes again, hackers be framing, TIPC Linux kernels, is that an Airtag in your pocket or?, I...

Listen
Paul's Security Weekly TV
Cassandra RCE, Pixelation Is Poor Redaction, Rust's Useful Errors, & Hardening Edge - ASW #185 from 2022-02-18T22:27:35

This week in the Application Security News: RCE in Cassandra, why pixelization isn't good redaction, Rust's compiler is friendly, Edge adds arbitrary code guard to its WASM interpreter, & the di...

Listen
Paul's Security Weekly TV
Running Windows Inside Containers On Linux - PSW #728 from 2022-02-18T22:00

Yes, this is possible! We have incoporated into our vulhub-lab project a way to run Windows inside a Docker Container that is running on Linux. We didn't invent this technique but we will show y...

Listen
Paul's Security Weekly TV
0patch - Security Patching That Doesn't Make Your Life Miserable - Mitja Kolsek - ESW #261 from 2022-02-18T22:00

0patch is a simple but powerful service that provides tiny targeted security patches to Windows computers, eliminating the most critical vulnerabilities without restarting the computer or relaun...

Listen
Paul's Security Weekly TV
Cybersecurity Coordinator Under President Obama - Michael Daniel - PSW #728 from 2022-02-18T10:00

Michael joins us to discuss the importance of information sharing, how to convey cybersecurity practice and topics to senior leaders, cybersecurity regulation, myths surrounding militarizing cyb...

Listen
Paul's Security Weekly TV
Changing the TPCRM Game W/ Cyber Risk Intelligence Tools - Vikram Asnani - ESW #261 from 2022-02-18T10:00

Definitions of the word intelligence include a collection of information of military or political value as well as the ability to acquire and apply knowledge or skills. In cybersecurity, when we...

Listen
Paul's Security Weekly TV
5 Leadership Lessons, 6 Steps to Success, & 6 Tips to Say No - BSW #250 from 2022-02-17T15:57:24

In the Leadership and Communications section, 5 Leadership Lessons General Marshall can Teach Us, Cybersecurity incident response: The 6 steps to success, 6 Effective Tips to Politely Say No (th...

Listen
Paul's Security Weekly TV
Time To Move Away From "G - little R - Big C" (GRC) - John Wheeler, Padraic O'Reilly - BSW #250 from 2022-02-15T22:00

How to move from legacy GRC processes and systems to a more automated approach that promotes visibility, agility, and alignment from assessment to Boardroom.

 

This segment is spon...

Listen
Paul's Security Weekly TV
Docker Boundaries, Google Bounties, 2021's Top Web Hacks, Apple AirTags, AI vs. RFCs - ASW #184 from 2022-02-15T10:00

In the AppSec News: Docker and security boundaries, Google's year in vuln awards, 2021's year in web hacks, Apple AirTags and privacy, turning AIs onto RFCs for security, & facial recognition re...

Listen
Paul's Security Weekly TV
The Modern Developer Must be Security Minded, Too - Doug Kersten - ASW #184 from 2022-02-14T22:00

In light of the far-reaching Log4j vulnerability, it’s become increasingly clear that the modern developer can’t operate without a solid level of security expertise. Vulnerability management is ...

Listen
Paul's Security Weekly TV
Glyptodons, Mandiant Rumors, Virtual CISOs, Log4j Testimony, & A Cyber Safety Board - ESW #260 from 2022-02-12T22:00

Finally, in the Enterprise Security News, Security automation startup Cerby raises $12M, Virtual CISO startup Cynomi raises 3.5M to help SMBs automate cybersecurity, Keeper Security acquires Gly...

Listen
Paul's Security Weekly TV
Uncovering a Major Linux PolicyKit Security Vulnerability: Pwnkit - Wheel - PSW #727 from 2022-02-12T10:00

Qualys researcher, Wheel, will discuss the discovery of the 12 year old Linux vulnerability in PolicyKit - which Qualys had dubbed, PwnKit. Wheel will provide an overview of the vulnerability an...

Listen
Paul's Security Weekly TV
The State of Identity in the Enterprise - Branden Williams - ESW #260 from 2022-02-12T10:00

We discuss the current state of identity challenges in the enterprise with Branden Williams.

 

Visit https://www.securityweekly.com/es...

Listen
Paul's Security Weekly TV
AR vs. VR, Hacking Mazdas, Risqué Latte Art, Crypto Wormholes, & Carding Forum Seized - PSW #727 from 2022-02-11T22:00

In the Security News for this week: Microsoft to block VBA macros by default (in some Office applications), Russia arrests it’s 3rd hacking group, The ‘Metaverse’ of security challenges, $323 Mi...

Listen
Paul's Security Weekly TV
To Err Is Human, but the Blockchain Is Forever - ESW #260 from 2022-02-11T22:00

One of the key features of cryptocurrency, NFTs, and other blockchain-based technologies is the immutable ledger. Put another way, there's no clear way to implement an 'undo' button when it come...

Listen
Paul's Security Weekly TV
Cybersecurity Is Not Just a Technical Problem - Brian Honan - PSW #727 from 2022-02-11T10:00

We have spent decades tackling security threats with technology, and we are failing badly. We need to look and learn from other industries and see how they have improved their industry. In parti...

Listen
Paul's Security Weekly TV
Cybersecurity Policy Creation, Champions Program, & the War for Talent - BSW #249 from 2022-02-09T10:00

In the leadership and communications section, Cybersecurity Policy Creation: Priority One, 5 steps to run a successful cybersecurity champions program, The war for cloud and cybersecurity talent...

Listen
Paul's Security Weekly TV
Effective Communications During & After a Cyber Attack - Ann Marie van den Hurk - BSW #249 from 2022-02-08T22:00

A cyber attack is a catastrophic event for any organization. Therefore, effective cyber crisis communication is crucial but often overlooked and an internal concern. In this conversation, we wil...

Listen
Paul's Security Weekly TV
HTTP/3 Streams, Argo CD Paths, Log4j Devs, Cyber Safety Review Board, OSSF Projects - ASW #183 from 2022-02-08T10:00

Vulns in an HTTP/3 server, path traversal in Argo CD, Log4Shell from the perspective of Log4j devs, DHS launches Cyber Safety Review Board, OSSF launches Alpha and Omega projects, resources for ...

Listen
Paul's Security Weekly TV
Policy Momentum in Coordinated Vulnerability Disclosure - Amit Elazari - ASW #183 from 2022-02-07T22:00

Security is one of the most evolving and impactful landscapes in the regulatory sphere. Proposed initiatives in the areas of Incident Response, Software and Product Assurance, Coordinated Vulner...

Listen
Paul's Security Weekly TV
Securing Olympians, Hiding in UEFI, 'Fingerprinting GPUs', & P4x vs. North Korea - PSW #726 from 2022-02-05T10:00

This week in the Security News: Temporary phones, webcam hacks that are so much more, bags of cash, patch Wordpress plugins and patch them some more, crowd-sourced-government-funded vulnerabilit...

Listen
Paul's Security Weekly TV
A Look at Microsoft's Cloud-Native SIEM - Darwin Salazar - ESW #259 from 2022-02-05T10:00

In late 2019, Microsoft released their cloud-native SIEM, Sentinel. A lot in the world has changed since then so we'll be looking at Sentinel's progression, talking about it's features and what ...

Listen
Paul's Security Weekly TV
Linux Post Exploitation - PSW #726 from 2022-02-04T22:00

In this Technical Segment, Paul walks through Linux Post Exploitation!

Github: https://github.com/SecurityWeekly/vulhub-lab

...

Listen
Paul's Security Weekly TV
How Zapier’s Attila Török Manages Security for a 100% Remote Organization - Attila Török - ESW #259 from 2022-02-04T22:00

Imagine having 500+ employees across the world — all working remotely. Now imagine making sure they can all do their work securely. This is exactly what Zapier’s Head of Security, Attila Török d...

Listen
Paul's Security Weekly TV
Covert EDC & Physical Pen Tests - Brent White - PSW #726 from 2022-02-04T10:00

Discussing every-day-carry items that are utilized during covert entry assessments. Also discussing the concealment of these tools, and which tools we use for various assessment types.

Se...

Listen
Paul's Security Weekly TV
The 1000th Unicorn, Island Browser, Optiv For Sale, & Polar Bear Takeover - ESW #259 from 2022-02-04T10:00

Finally, in the Enterprise Security News, Island raises $100M to introduce a new Chromium-based web browser, designed for the enterprise, Plextrac rasies a $70M Series B, HackerOne raises a $49M...

Listen
Paul's Security Weekly TV
Cybersecurity & Audit, CIO Involvement Grows, & Poor Security Culture - BSW #248 from 2022-02-02T10:00

In the leadership and communications section, Cybersecurity increasingly on audit committee agendas, CIO involvement in security grows as CEOs target risk reduction, How Poor Security Culture Le...

Listen
Paul's Security Weekly TV
Digital Risk Protection - Dan Mathews - BSW #248 from 2022-02-01T22:00

Your information is everywhere. Executive, employee, and corporate data are contained in breach data, social media, and the dark web. How do you protect your organization from impersonation and ...

Listen
Paul's Security Weekly TV
PwnKit, Qubit Hack, Multichain Hack, Safari Bounty, & Python NaN - ASW #182 from 2022-02-01T10:00

PwnKit LPE in Linux, two different smart contract logic flaws in two different hacks, a $100K bounty for Safari, Python NaN coercion, appsec games

 

Visit Listen

Paul's Security Weekly TV
Shift Left, NOT S#!T LEFT - Larry Maccherone - ASW #182 from 2022-01-31T22:00

If you attempt to shift security left without adaptation, it'll feel a lot more like S#!T LEFT to the development teams but most security groups lack the mindset and skills to do it in a way tha...

Listen
Paul's Security Weekly TV
Continuous Red Teaming Trends - Bikash Barai - ESW #258 from 2022-01-29T22:00

Why is continuous security here to stay? How is Red Teaming getting automated and moving towards continuous?

 

Visit https://www.secur...

Listen
Paul's Security Weekly TV
12 Year Linux Bug, Recovering Bitcoin, Lulzsec's Impact, & Pimp My Cubicle - PSW #725 from 2022-01-29T10:00

This week in the Security News: More QR codes you shouldn't trust, race conditions in Rust, encrypting railways, Pwnkit - the latest Linux exploit, tricking researchers into crashing, cybersecur...

Listen
Paul's Security Weekly TV
New Startups From Stealth, It's Not Matt Damon's Fault, Merck Wins, & Pearson Fined - ESW #258 from 2022-01-29T10:00

This week, in the Enterprise Security News, Hunters raises a series C to continue building XDR, Anitian raises a $55M Series B, Four new startups emerge from stealth with seed funding, BugAlert ...

Listen
Paul's Security Weekly TV
Securing Ubiquiti WiFi Systems - PSW #725 from 2022-01-28T22:00

Ubiquiti has become a crown favorite for WiFi (and many other solutions). Learn how to do some basic security, update the software, change passwords and more!

 

Visit Listen

Paul's Security Weekly TV
Log4Shell: Impact & Lessons Learned - Jamie Moles - ESW #258 from 2022-01-28T22:00

If 2021 taught us anything, it’s that our supply chain–especially our technical supply chain–hangs in the balance of a very fragile system. In this interview, ExtraHop's Jamie Moles examines the...

Listen
Paul's Security Weekly TV
Cracks in the Castle - Jimmy Sanders - PSW #725 from 2022-01-28T10:00

Enterprises today has an ever expanding attack surface. Jimmy Sanders, Head of Security for DVD.com, joins to discuss how Organizations are constantly trying to stay ahead of the latest known an...

Listen
Paul's Security Weekly TV
Mastering Art and Science, Stakeholder Trust, and Trustworthy Computing - BSW #247 from 2022-01-26T10:00

In the leadership and communications section, Mastering Art and Science Is Imperative for CISOs to Be Successful, Seven Ways to Ensure Successful Cross-Team Security Initiatives, 2 Key Cybersecu...

Listen
Paul's Security Weekly TV
Securing the Digital Value Chain - Mark Fernandes - BSW #247 from 2022-01-25T22:00

Enabling the business requires a nuanced view of verticalization and what it means to an enterprise. Why is this important as CISO’s think about how to apply cyber to enterprise resiliency? Mark...

Listen
Paul's Security Weekly TV
IndexedDB Leak, Linux Kernel Bug, Zoom Security, SSRF & Allow Lists, Security Courses - ASW #181 from 2022-01-25T10:00

In the AppSec News, Safari fixes a privacy leak in IndexedDB, integer arithmetic flaw leads to Linux kernel bug, a look back on Zoom security, SSRF from an URL allow list bypass, a security engi...

Listen
Paul's Security Weekly TV
API Security (Shadow APIs) - Himanshu Dwivedi - ASW #181 from 2022-01-24T22:00

It is hard, if not impossible, to secure something you don’t know exists. While security professionals spend countless hours on complex yet interesting issues that *may* be exploitable in the fu...

Listen
Paul's Security Weekly TV
McAfee MVISION XDR, Microsoft Acquires Activision Blizzard, & Tom Brady NFTs - ESW #257 from 2022-01-22T22:00

In the Enterprise Security News: 1Password plans to do some shopping with their massive Series C, Devo announces a $250M round, Permiso Security and Tromzo emerge backed by both traditional VCs ...

Listen
Paul's Security Weekly TV
REvil Gang Arrested, 5G & Airplanes, Zoom Zero-Click, & Stolen Brownies - PSW #724 from 2022-01-22T10:00

In the Security News: Malware targets Ukraine, I wonder where that's coming from?, evil Google Docs comments, Russia grabs REvil, funding a dictatorship, Zoom zero clicks, When 9-year old's laun...

Listen
Paul's Security Weekly TV
Architecture & Security from the Trenches - Will Clark - ESW #257 from 2022-01-22T10:00

An open discussion of challenges facing software and system architects in small and medium sized businesses.

 

Visit https://www.secur...

Listen
Paul's Security Weekly TV
Using WPScan To Find WordPress Vulnerabilities - PSW #724 from 2022-01-21T22:00

wpscan is a free tool for scanning WordPress, and let's face it, there are many vulnerabilities to be found in Wordpress! This segment will walk you through installing, configuring and using wps...

Listen
Paul's Security Weekly TV
Vulnerability Management is Dead! - Rickard Carlsson - ESW #257 from 2022-01-21T22:00

Modern tech stacks are becoming increasingly complex puzzles of components built in-house and sourced from third-party vendors. With DNS at the center of the infrastructure, and staging and prod...

Listen
Paul's Security Weekly TV
Cyber Resilience - Cybersecurity Mental Health - Neal O'Farrell - PSW #724 from 2022-01-21T10:00

What can we do to raise awareness on issues of mental health for cybersecurity professionals? Neal walks us through some of the issues and ways to deal with them. Neil has also put together trai...

Listen
Paul's Security Weekly TV
Scams and Security in Web3*, URL Parsing Problems, AWS Glue, CI/CD Compromises - ASW #180 from 2022-01-19T10:00

Scams and security flaws in (so-called) web3 and when decentralization looks centralized, SSRF from a URL parsing problem, vuln in AWS Glue, 10 vulns used for CI/CD compromises

 

V...

Listen
Paul's Security Weekly TV
Investing in Open Source Security - ASW #180 from 2022-01-18T22:00

This isn't a story about NPM even though it's inspired by NPM. Twice. The maintainer of the "colors" NPM library intentionally changed the library's behavior from its expected functionality to p...

Listen
Paul's Security Weekly TV
Arming CISOs, The 'Great Resignation', & Deciding Your Next Career Move - BSW #246 from 2022-01-16T10:00

In the leadership and communications segment, Arming CISOs With the Skills to Combat Disinformation, Is the 'Great Resignation' Impacting Cybersecurity?, Ask These 5 Questions to Decide Your Nex...

Listen
Paul's Security Weekly TV
Israeli CyberSec Drama, Microsoft's Security Chip, Best Job of 2022, & "YAU"s - ESW #256 from 2022-01-15T22:00

In the Enterprise Security News for this week: Pentera announces a $150m Series C - YAU (Yet Another Unicorn), Herjavec Group merges with Fishtech, Google acquires SOAR vendor SIEMplify, A Europ...

Listen
Paul's Security Weekly TV
Security Money - The Index Has Cooled Off - BSW #246 from 2022-01-15T22:00

The Security Weekly 25 index has finally cooled off, closing at 2226.93 on January 13th, 2022, which is an increase of 122.69% (down from last Q) since inception. The NASDAQ Index closed at 14,8...

Listen
Paul's Security Weekly TV
CanSecWest, PacSec, & PWN2OWN - Dragos Ruiu - PSW #723 from 2022-01-15T10:00

Dragos is the Organizer of CanSecWest, PACSEC, originator of PWN2OWN, and does security auditing, and virtual engagement/training.

 

Visit Listen

Paul's Security Weekly TV
A Look Back at the Most Active Year in Federal Cybersecurity Ever - Derek Johnson - ESW #256 from 2022-01-15T10:00

2021 was the most active year in federal cybersecurity policy. Ever. The Biden administration used executive orders, new regulations, public/private partnerships and novel law enforcement strate...

Listen
Paul's Security Weekly TV
Mailing USBs, DoS in DoorLock, Moxie Resigns, QR Code Mystery, & Jarring Revelations - PSW #723 from 2022-01-14T22:00

This week in the Security News: Attacking RDP (from the inside), NetUSB exposed, the old mailing USB drives trick, a persistent DoS in your doorLock, Signal gets a new CEO, attacking the patchin...

Listen
Paul's Security Weekly TV
New Year, Same Security Problems - Kris Lahiri - ESW #256 from 2022-01-14T22:00

It’s a new year and a time when we make resolutions…which often drop off by the start of February. To keep your security resolutions for 2022, today’s show will be about enterprise security pitf...

Listen
Paul's Security Weekly TV
Log4j Exploit Step-By-Step - PSW #723 from 2022-01-14T10:00

The log4j vulnerability still exists in many environments. Learn how to exploit this vulnerability in our step-by-step guide. Please only use this information for research and testing purposes, ...

Listen
Paul's Security Weekly TV
No Log4j, 2021 Recaps, or 2022 Resolutions! - BSW #245 from 2022-01-12T10:00

In the leadership and communications section, no, we're not discussing log4j, 2021 recaps or lessons learned, or 2022 new year's resolutions or predictions!

 

Visit Listen

Paul's Security Weekly TV
Zero Trust Access To, From and Within the Cloud - Colby Dyess - BSW #245 from 2022-01-11T22:00

How cloud resources are architected and utilized is different for every organization, but whether cloud native or cloud traditionalist – security risk and complexity are problems. Concerns over ...

Listen
Paul's Security Weekly TV
Broadening What We Call AppSec - Christien Rioux - ASW #179 from 2022-01-11T10:00

There's an understandable focus on "shift left" in modern DevOps and appsec discussions. So what does it take to broaden what we call appsec into something effective for modern apps, whether the...

Listen
Paul's Security Weekly TV
Log4j for FTC, More JNDI, Cache Poisoning, Improving Default Configs, ThinkstScapes - ASW #179 from 2022-01-10T22:00

The FTC issues a warning about taking log4j seriously, JNDI is elsewhere, cache poisoning shows challenges in normalizing strings, semgrep for refactoring configs with security in mind, the Q4 2...

Listen
Paul's Security Weekly TV
ESW End-of-Year Wrap Up - ESW #255 from 2021-12-25T22:00

In our final security weekly segment of the year, we're wrapping up by reminiscing about 2021's biggest, craziest, and most interesting stories. We'll chat about our favorite interviews of the y...

Listen
Paul's Security Weekly TV
Zip Tie Pick, Wifi/Bluetooth Bugs, Domain Controllers, & Beetle Behavior - PSW #722 from 2021-12-25T10:00

The greatest exploit in the world, throw some more logs on the log4j fire, lock picking with a zip tie, hacking metal detectors, please disclose your vulnerabilities here, bugs in Wifi and Bluet...

Listen
Paul's Security Weekly TV
Dragons & Unicorns, Phishing Training, GreyNoise, & Becoming Domain Admin - ESW #255 from 2021-12-25T10:00

In the Enterprise Security News for this week, ZeroFox has a $1.4 billion dollar blank check, Corellium raises a $25m series A, GreyNoise makes its data free to help out Log4j sufferers, AWS suf...

Listen
Paul's Security Weekly TV
The State Of Internet Exposed Services - John Matherly - PSW #722 from 2021-12-24T22:00

John joins us to talk about what its like to run scans of the Internet on a regular basis. We'll talk about some trends, such as what is more exposed, what is less exposed, and how select segmen...

Listen
Paul's Security Weekly TV
Bringing Autonomy to AppSec - Dr. David Brumley - ESW #255 from 2021-12-24T22:00

Log4j, solar winds, tesla hacks, and the wave of high profile appsec problems aren’t going to go away with current approaches like SAST and SCA. Why? They are: -40 years old, with little innovat...

Listen
Paul's Security Weekly TV
Lock Picking & Physical Security - Deviant Ollam - PSW #722 from 2021-12-24T10:00

Many of us, myself included, learned lock picking techniques from Deviant. He comes on the show to talk about physical security in a pandemic, how to train for lock picking and physical security...

Listen
Paul's Security Weekly TV
The Security Hippie, Part 2 - Barak Engel - SCW #99 from 2021-12-23T10:00

Author of "Why CISOs Fail" is joining us today to tell us about the success of his first book as well as introduce us to his forthcoming book, "Security Hippie. Barak is best known for pioneerin...

Listen
Paul's Security Weekly TV
The Security Hippie, Part 1 - Barak Engel - SCW #99 from 2021-12-22T22:00

Author of "Why CISOs Fail" is joining us today to tell us about the success of his first book as well as introduce us to his forthcoming book, "Security Hippie. Barak is best known for pioneerin...

Listen
Paul's Security Weekly TV
Office of the CISO, The Fearless CISO, and America's Cyber Reckoning - BSW #244 from 2021-12-22T10:00

In the leadership and communications section, The Office of the CISO: A Framework for the CISO, America’s Cyber-Reckoning, How to Include Cybersecurity Training in Employee Onboarding, and more!...

Listen
Paul's Security Weekly TV
Security Maturity: From Hostage Negotiator to Business Leader - Sandy Dunn - BSW #244 from 2021-12-21T22:00

Throughout her career, Sandy Dunn has continued to mature and refine her skills. In the early days, she describes her job as a "hostage negotiator", constantly negotiating between the business t...

Listen
Paul's Security Weekly TV
Latest Log4j, Outages & Availability, FPGA Security Concepts, & Bug Bounty Awards - ASW #178 from 2021-12-21T10:00

Log4j has more updates and more vulns (but probably not more heartburn...), revisiting outages and whether availability has made it into your threat models, deep dive into hardware security, ano...

Listen
Paul's Security Weekly TV
Evolving Security Testing - Dan Guido - ASW #178 from 2021-12-20T22:00

What does a collaborative approach to security testing look like? What does it take to tackle an entire attack class as opposed to fixing a bunch of bugs? If we can shift from vulnerability miti...

Listen
Paul's Security Weekly TV
Cyber-Loaded Bills, Dazz CSPM, Janky Tech, VC Startup Valuations, & Keanu Reeves Talk - ESW #254 from 2021-12-18T22:00

This week in the Enterprise News: Is the art of VC valuations a lie?, Noname Security hits unicorn status, Dazz sounds like an 80's cartoon character and is the latest to join the CSPM category ...

Listen
Paul's Security Weekly TV
Printing Shellz, Block Chain For C2, Wordpress Theft, & Log4j Who? - PSW #721 from 2021-12-18T10:00

This week in the Security News: Printing Shellz, the exploit is in the link, 42 CVEs, time to update all of your browsers again, Microsoft App spoofing vulnerability, stealing credit cards in Wo...

Listen
Paul's Security Weekly TV
The Evolution & Future of XDR & the SOC - Scott Crawford - ESW #254 from 2021-12-18T10:00

Like our interview with Allie Mellen last week (episode 253, check it out also), we have another analyst roundtable here (all ESW hosts are former analysts), discussing one of the hottest new cy...

Listen
Paul's Security Weekly TV
What to Expect in 2022 - Sinan Eren - PSW #721 from 2021-12-17T22:00

Since it is Dec 15 - might make sense to have a discussion on what might be coming in 2022 in terms of security - topics could span Ransomware, and other threats as well as technology segments l...

Listen
Paul's Security Weekly TV
Morale Is a Safety Control - Shoshana Gourdin - ESW #254 from 2021-12-17T22:00

Not all security is complicated--many aspects boil down to noticing that something is off. Attentive and curious employees are an overlooked safety mechanism, as is handling problems in a constr...

Listen
Paul's Security Weekly TV
All Your Holiday Hack Challenge Belong To Us - Ed Skoudis - PSW #721 from 2021-12-17T10:00

Let's talk about the 2021 SANS Holiday Hack Challenge. Lotsa great new stuff this year, with a focus on hardware hacking in a virtual world... plus TWO cons at the North Pole.

 

Se...

Listen
Paul's Security Weekly TV
Everything You Wanted to Know About CISOs But Were Afraid to Ask, Part 2 - Ben Carr - SCW #98 from 2021-12-16T10:00

Ben Carr will lead us in a discussion about the origins of the role of CISO, roles/responsibilities, and what it's like to be a CISO. We'll touch on qualifications, organizational structure, its...

Listen
Paul's Security Weekly TV
Everything You Wanted to Know About CISOs But Were Afraid to Ask, Part 1 - Ben Carr - SCW #98 from 2021-12-15T22:00

Ben Carr will lead us in a discussion about the origins of the role of CISO, roles/responsibilities, and what it's like to be a CISO. We'll touch on qualifications, organizational structure, its...

Listen
Paul's Security Weekly TV
(13 Traits + 7 Strategies)/2 = 10 Effective Ways to Improve Communication - BSW #243 from 2021-12-15T10:00

In the Leadership and Communications section: 13 traits of a security-conscious board of directors, 7 Strategies for CSO Cybersecurity Survival, 10 Effective Ways You Can Improve Your Communicat...

Listen
Paul's Security Weekly TV
Why Hospitals Face Unique Security Challenges - Mike Murray - BSW #243 from 2021-12-14T22:00

-More than 25% of US hospitals have suffered at least one ransomware attack in the last two years. -Clearly, hospital IT teams, for the first time, the power to see and stop ransomware and other...

Listen
Paul's Security Weekly TV
Log4Shell, Mozilla's BigFix & New Sandbox, Rust in Linux Kernel, Path Traversal in Go - ASW #177 from 2021-12-14T10:00

This week in the AppSec News, Mike & John talk: All about Log4Shell, Mozilla's BigFix bug and new sandbox, Rust in the Linux kernel, path traversals, reflections on the security profession, & mo...

Listen
Paul's Security Weekly TV
DevSecOps, Compliance GRC, and the Future of Application Security - Francesco Cipollone - ASW #177 from 2021-12-13T22:00

DevSecOps has been traditionally very people centric. It is hard to measure software security and the landscape is becoming increasingly more complex with container, cloud, and infrastructure. D...

Listen
Paul's Security Weekly TV
Unicorns Galore, Selling Text Messages, Spicy Takes, & Treacherous Devs - ESW #253 from 2021-12-11T22:00

Finally, in the enterprise security news: At least a dozen cybersecurity companies announced raises totaling more than $900m - just in the past week!, Permira proposes to take Mimecast private f...

Listen
Paul's Security Weekly TV
Securing the Invisible: Holes in Your Visibility Fabric & Where Hackers Hide - Vincent Berk - ESW #253 from 2021-12-11T10:00

Riverbed’s Network Security Solutions provide the full-fidelity network visibility organizations need to see everything. The rise of cloud and user mobility has increased the complexity and the ...

Listen
Paul's Security Weekly TV
Digging Into XDR - Allie Mellen - ESW #253 from 2021-12-10T22:00

XDR is the buzzword practitioners can't seem to escape. Or is it? Allie Mellen, Forrester Analyst, will cover her research on what XDR is and what it isn't to help practitioners understand what ...

Listen
Paul's Security Weekly TV
Killing the SOC, Burger King Runes, ReliaQuest Valuation, & StrongDM - ESW #252 from 2021-12-04T22:00

This week in the enterprise security news: ReliaQuest crests a $1bn valuation, CyCognito raises a $100m Series C, AWS enhances cloud vulnerability management, StrongDM automates access to infras...

Listen
Paul's Security Weekly TV
The 2021 Security Landscape & What Lies Ahead - Shailesh Athalye - PSW #720 from 2021-12-04T10:00

What are the key security challenges that customers faced this year? What did attackers do differently in 2021, and why are they succeeding more often? What can we expect in 2022? Shailesh will ...

Listen
Paul's Security Weekly TV
Authentication Vulnerabilities - PSW #720 from 2021-12-04T10:00

Sven will present common vulnerabilities and issues that arise when implementing authentication and authorization in web applications.

 

This segment is sponsored by Invicti. Visit...

Listen
Paul's Security Weekly TV
First Look: Is Passwordless Really Killing the Password? - ESW #252 from 2021-12-04T10:00

Passwordless is everywhere these days, but like most new security markets, it's shrouded in confusion. There are already dozens of vendors promising to kill the password, but they don't all seem...

Listen
Paul's Security Weekly TV
Bypassing Biometrics, Hiding in Plain Sight, Hacker Cinema, & High Aspirations - PSW #720 from 2021-12-03T22:00

In the Security News for this week: Stop hiding your secrets in plain sight, Detecting Wildcard DNS Abuse, $5 setup that hacks biometrics, Managing passwords with pen and paper, Windows 10 Zero ...

Listen
Paul's Security Weekly TV
Are We Ever Going to Get Information Sharing Right? - Edna Conway - ESW #252 from 2021-12-03T22:00

In this interview, we discuss defenders sharing information, how Edna deals with Azure's supply chain challenges, ransomware trends, and some future predictions. Edna has been in security as lon...

Listen
Paul's Security Weekly TV
Hacker Situational Awareness, Part 2 - John Threat - SCW #97 from 2021-12-02T10:00

There’s something happening here – and what it is ain’t exactly clear to O.G hackers like John Threat or our own Mr. Jeff Man. We’re going to devote an episode talking about how things used to b...

Listen
Paul's Security Weekly TV
Hacker Situational Awareness, Part 1 - John Threat - SCW #97 from 2021-12-01T22:00

There’s something happening here – and what it is ain’t exactly clear to O.G hackers like John Threat or our own Mr. Jeff Man. We’re going to devote an episode talking about how things used to b...

Listen
Paul's Security Weekly TV
Leadership Triad, Awesome CISO Tips, & CISO Demands - BSW #242 from 2021-12-01T10:00

This week in the Leadership & Communications section, 'They Said a CISO Does What?', 5 Tips to be an awesome CISO, 9 tips for an effective ransomware negotiation, and more!

 

Visit...

Listen
Paul's Security Weekly TV
CISO Transition: A CISO's Perspective - BSW #242 from 2021-11-30T22:00

We cover a lot of articles about CISO leadership, communications, skills, and yes, transition. This week we discuss the CISO transition from a CISO's perspective. I will interview my co-hosts on...

Listen
Paul's Security Weekly TV
Bug Bounties in Windows/WebKit, Edge Hardening, OAuth Hardening, & GoDaddy Breach - ASW #176 from 2021-11-30T10:00

This week in the AppSec News: Bug bounty payout practices, Edge goes super duper secure mode, WebKit CSP flaw has consequences for OAuth, GoDaddy breach, vuln in MediaTek audio DSP, & more!

...

Listen
Paul's Security Weekly TV
Solving Systemic Risk in Software Development - Chris Wysopal - ASW #176 from 2021-11-29T22:00

In today’s session Chris Wysopal will address a number of topics with Mike, including systemic risk in software development and how developers and security teams can work together to meet common...

Listen
Paul's Security Weekly TV
Security & Compliance Thru the Lens of a Technology Journalist, Part 2 - Evan Schuman - SCW #96 from 2021-11-25T10:00

In the early days of PCI there was an online column called StorefrontBacktalk which focused on retail and technology issues. The column provided valuable insights from various specialists on the...

Listen
Paul's Security Weekly TV
Security & Compliance Thru the Lens of a Technology Journalist, Part 1 - Evan Schuman - SCW #96 from 2021-11-24T22:00

In the early days of PCI there was an online column called StorefrontBacktalk which focused on retail and technology issues. The column provided valuable insights from various specialists on the...

Listen
Paul's Security Weekly TV
4 Things Boards Should Know, 4 in 10 Orgs Don't Have a CISO, & Creating Culture - BSW #241 from 2021-11-24T10:00

In the Leadership & Communications section for this week: Four Things Your CISO Wants Your Board to Know, 4 in 10 Organizations Do Not Employ a CISO, Creating a Culture of Cybersecurity, & more!...

Listen
Paul's Security Weekly TV
Preventing Attacks Through Risk Management & Governance - Kevin Powers, Padraic O'Reilly - BSW #241 from 2021-11-23T22:00

As a CISO tasked to present to the Board or other executives, communicating cybersecurity in business context is critical to success. Hear from Kevin Powers, who has taught hundreds of CISOs in ...

Listen
Paul's Security Weekly TV
CVEs 4 CSPs, Malicious PyPi, Bounty Programs, Shared Responsibility, & Breach Costs - ASW #175 from 2021-11-23T10:00

This week in the AppSec News: What would CVEs for CSPs look like, clever C2 in malicious Python packages, diversity in bounty programs, shared responsibility and secure defaults, breach costs to...

Listen
Paul's Security Weekly TV
wasmCloud - Distributed Computing With WebAssembly - Liam Randall - ASW #175 from 2021-11-22T22:00

CNCF wasmCloud helps developers to build distributed microservices in WebAssembly that they can run across clouds, browsers, and everywhere securely.

 

Segment Resources:

- ...

Listen
Paul's Security Weekly TV
Congress Goes Cyber-Crazy, Emotet Returns, SnapAttack, & Netography - ESW #251 from 2021-11-20T22:00

This week in the Enterprise Security News: NDR startup Netography raises a $45m Series A with Martin Roesch at the helm! Data Security startup Laminar comes out of stealth with a $32m Series A T...

Listen
Paul's Security Weekly TV
Suing Satoshi, Trojans in IDA, FBI Spam, Beg Bounties, & UPNP Strikes Again - PSW #719 from 2021-11-20T10:00

This week in the Security News: The FBI is spamming you, hacking exists in the mind, Beg Bounties, nasty top-level domains, MosesStaff, why own one npm package when you can own them all, how muc...

Listen
Paul's Security Weekly TV
Skill Building: CTFs & Computer Fundamentals - Derek Rook - PSW #719 from 2021-11-19T22:00

Derek and the hosts will discuss technologies to build CTFs as well as what types of things to consider while doing so. They will also talk about the computer fundamentals that are often underva...

Listen
Paul's Security Weekly TV
The Real Costs of Ransomware in 2021, 2022, & Beyond - Mike Campfield - ESW #251 from 2021-11-19T22:00

Ransomware: the problem that everyone is talking about, yet somehow continues to get worse with each passing year. In 2021, the cost of ransomware to global businesses is estimated to reach a wh...

Listen
Paul's Security Weekly TV
Understanding Cyber Insurance Trends & Changes - ESW #251 from 2021-11-19T22:00

Jeffrey joins us today to guide us through the rapidly changing world of Cyber Insurance! We solicited some questions from our audience and look forward to picking his brain in this segment.

...

Listen
Paul's Security Weekly TV
Building Vulnerable Docker Containers (On Purpose) - PSW #719 from 2021-11-19T10:00

I needed to create some vulnerable targets for testing exploits and my default password finder I wrote in Python (featured in previous episodes). I found a few useful projects, including Vulhub,...

Listen
Paul's Security Weekly TV
CISA Guidance for MSPs and SMBs, Part 2 - Chris Loehr - SCW #95 from 2021-11-18T10:00

CISA recently published guidance for how managed service providers (MSPs) should approach security for their operations based on the premise that cyber threat actors are known to target MSPs to ...

Listen
Paul's Security Weekly TV
CISA Guidance for MSPs and SMBs, Part 1 - Chris Loehr - SCW #95 from 2021-11-17T22:00

CISA recently published guidance for how managed service providers (MSPs) should approach security for their operations based on the premise that cyber threat actors are known to target MSPs to ...

Listen
Paul's Security Weekly TV
4 Attributes of a Great Leader & 5 Myths About Management & Cybersecurity - BSW #240 from 2021-11-17T10:00

In the Leadership and Communications section, The Gardener: Four Attributes Of A Great Leader, Unpacking 5 Myths About Management, 5 Cybersecurity Myths That Make You More Vulnerable to Attacks,...

Listen
Paul's Security Weekly TV
Protecting Identity Services - Tony Cole - BSW #240 from 2021-11-16T22:00

Identity Services such as Active Directory is an area that is almost always utilized by the attacker after the initial endpoint is compromised. This is an area lacking critical focus by defender...

Listen
Paul's Security Weekly TV
PAN-OS Vuln, ChaosDB, Fuzzing BusyBox, Refactoring in Rust, HTML Smuggling - ASW #174 from 2021-11-16T10:00

In the AppSec news: Disclosure decisions and CVE-2021-3064, technical details behind ChaosDB in Azure, fuzzing BusyBox, Prossimo and Rust, vulns in Nucleus RTOS, & HTML smuggling!

 

<...

Listen
Paul's Security Weekly TV
Mobile Application Security - Ryan Lloyd - ASW #174 from 2021-11-15T22:00

Mobile applications have a unique attack surface. The tools and techniques being used to compromise these environments are constantly evolving. We'll talk about how to harden mobile apps against...

Listen
Paul's Security Weekly TV
Record Unicorns, SCYTHE Series A, SPAC Fails, McAfee Worth $14B, & Hashicorp IPO - ESW #250 from 2021-11-13T22:00

In the Enterprise Security News for this week: Drata reaches unicorn status in record time with a $100m Series B, SCYTHE announces a $10m Series A, McAfee Consumer business acquired for $14b, WP...

Listen
Paul's Security Weekly TV
Building a Risk Based Security Program That Actually Works - Nick Leghorn - ESW #250 from 2021-11-13T10:00

Risk based security programs are all the rage, from managers looking to "trim" the security budget to regulatory bodies looking for excuses to fine your company. Nick is a security pro who has s...

Listen
Paul's Security Weekly TV
MAVSH - Sachin Mahajan - PSW #718 from 2021-11-12T22:00

Over the course of 2020 and 2021 new UAV regulations and restrictions, such as Remote Identification, have threatened UAV hobbyist's ability to fly freely. These new regulations did leave hobbyi...

Listen
Paul's Security Weekly TV
MegatronAL on Kicking in the Door to Cybersecurity - Angela Marafino - ESW #250 from 2021-11-12T22:00

I once told my college advisor that I wanted to double major in computer science and jazz performance. She laughed at me. Instead, I jumped into a career in IT and played jazz - without a degree...

Listen
Paul's Security Weekly TV
Stalkerware Capabilities in the Real World - Lodrina Cherne, Martijn Grooten - PSW #718 from 2021-11-12T10:00

Can using technology risk your personal safety? Tracking information can be shared with attackers and facilitate cyberstalking in multiple ways including key logging and screen sharing. Explorat...

Listen
Paul's Security Weekly TV
TIPC Kernel Vulns, SBDCs, Truckloads of GPUs, & Hardcoded SSH Keys - PSW #718 from 2021-11-12T10:00

This week in the Security News: NPM hijacked again, hardcoding your keys, PAN-ODay, more Nmap in your python or python in your nmap, put your Docker API to rest, Busybox will own your box, Micro...

Listen
Paul's Security Weekly TV
Governance, Risk, & Compliance...so What? - Part 2 - Allan Alford - SCW #94 from 2021-11-11T10:00

Join us on this episode of SCW for a general discussion about how to do this whole security/compliance thing better; how compliance really needs to come first; how it's all risk-based or should ...

Listen
Paul's Security Weekly TV
Governance, Risk, & Compliance...so What? - Part 1 - Allan Alford - SCW #94 from 2021-11-10T22:00

Join us on this episode of SCW for a general discussion about how to do this whole security/compliance thing better; how compliance really needs to come first; how it's all risk-based or should ...

Listen
Paul's Security Weekly TV
A CISO's Life, FOMO Is Real, & Cybersecurity's Hiring Problem - BSW #239 from 2021-11-10T10:00

In the Leadership and Communications section, The First 100 Days in A CISO’s Life — Biggest Mistakes and Best Quick Wins, Hybrid work woes: FOMO is real, employees feel disconnected, Breaking Do...

Listen
Paul's Security Weekly TV
Reinvigorating Cybersecurity Teams - Sara Griffith, Suresh Balasubramanian - BSW #239 from 2021-11-09T22:00

The rise in cyberattacks and the switch to remote work has kept security teams busy, but it has also left them isolated by halting their ability to meet with peers and network with industry frie...

Listen
Paul's Security Weekly TV
Linux Kernel TIPC RCE, NPM Malware, OTP 2FA Bots, & Security Labels - ASW #173 from 2021-11-09T10:00

This week in the AppSec News, Mike and John talk: Excel gains support for JavaScript data types and functions, arbitrary code execution in Linux kernel TIPC, more malware in npm packages, threat...

Listen
Paul's Security Weekly TV
A Standardized Approach to SBOM - Dan McKinney - ASW #173 from 2021-11-08T22:00

In this segment, Mike and Dan McKinney from Cloudsmith will be discussing SBOM and what that looks like for your applications. Other topics include: cloud-native tooling for your software supply...

Listen
Paul's Security Weekly TV
Facebook Gets Meta, Crazy Valuations, IBM XDR, & Analysts V.S Darktrace - ESW #249 from 2021-11-06T21:00

In the Enterprise Security News for this week: Laika raises $35m in the growing compliance-as-a-service segment, IBM launches XDR, CrowdStrike acquires SecureCircle and moves into the data layer...

Listen
Paul's Security Weekly TV
Shrootless Bug, Statistic Stats, Trojan Source, Fake Students, & Clippy Returns - PSW #717 from 2021-11-06T09:00

This week in the Security News: LOLbins that make you LOL, over exposing your medical records, Shrootless gets past SIP, 73.6% of statistics are made up and other such lies, we love Signal, if a...

Listen
Paul's Security Weekly TV
Building Up the Blue Team - Frank McGovern - ESW #249 from 2021-11-06T09:00

Traditionally, the red team has been seen as "fun and interesting", with blue team characterized as "all work, no play" in terms of cybersecurity career paths. Today we talk with Frank McGovern ...

Listen
Paul's Security Weekly TV
Peel Back the Layers of Your Enterprise with Security Onion 2 - Doug Burks - PSW #717 from 2021-11-05T21:00

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. We've got a new container-based platform that is more flexible, more powerful, ...

Listen
Paul's Security Weekly TV
Detecting the Next Breach: How to Win the War With NSX NDR - Chad Skipper - ESW #249 from 2021-11-05T21:00

When it comes to detecting the next cyber breach, would your organization pass the test? Of course, in real life, you not only need to ace the practice exam – you need to test against the real t...

Listen
Paul's Security Weekly TV
Part 2: Scanning For Default Creds With Python - PSW #717 from 2021-11-05T09:00

We've updated our script with all sorts of new features. The latest version uses the TOML configuration file format to store the vendor information and the credentials to test with. We'll focus ...

Listen
Paul's Security Weekly TV
Security Industry Burnout, Part 2 - Rick McElroy - SCW #93 from 2021-11-04T09:00

With cybersecurity skills already in short supply, the prospect of losing what little workforce there is to pull from to resignations (especially in the context of the ‘Great Resignation’), is a...

Listen
Paul's Security Weekly TV
Easy Ways for Businesses to Become More Resilient - Kyle McNulty - BSW #238 from 2021-11-03T21:00

More and more, start-ups and small companies have to consider cybersecurity earlier in their growth cycle. Whether for a VC investment or revolutionary customer, cybersecurity can make or break ...

Listen
Paul's Security Weekly TV
Security Industry Burnout, Part 1 - Rick McElroy - SCW #93 from 2021-11-03T21:00

With cybersecurity skills already in short supply, the prospect of losing what little workforce there is to pull from to resignations (especially in the context of the ‘Great Resignation’), is a...

Listen
Paul's Security Weekly TV
10 Questions, 5 Personality Traits, & 3 Security Priorities - BSW #238 from 2021-11-03T09:00

This week, in the Leadership and Communications section, 10 Questions Great Bosses Ask Themselves, 5 cybersecurity personality traits for a successful career, 3 Security Priorities to Support th...

Listen
Paul's Security Weekly TV
Discourse RCE, Trojan Source, WhatsApp Security, & Privacy Engineering - ASW #172 from 2021-11-02T09:00

This week in the AppSec News, Mike & John talk: Discourse SNS webhook RCE, a checklist for a Minimum Viable Secure Product, WhatsApp security assessment, privacy engineering specialties, & DevOp...

Listen
Paul's Security Weekly TV
Untangling API Security in 2022 - Peter Klimek - ASW #172 from 2021-11-01T21:00

Peter will talk to the challenges he's hearing from customers and partners about managing the security of APIs and what considerations organizations need to make in 2022 to better protect these ...

Listen
Paul's Security Weekly TV
Market Analysis With a VC - Introducing Will Lin - ESW #248 from 2021-10-30T21:00

In our news segments, we often discuss and explore the ever-expanding vendor landscape. Funding rounds are getting huge, we're seeing upwards of 40 acquisitions each month - there's a lot of mon...

Listen
Paul's Security Weekly TV
Iranian Gas, Smelly Towns, View Source Legality, EBCDIC & GDPR, & Unlocking Oculus Go - PSW #716 from 2021-10-30T09:00

This week in the Security News we talk: Its still not illegal to look at HTML source code, Nobelium strikes again, npm infections, gas is cheap in Iran, if you can get it, Google Tensor, going b...

Listen
Paul's Security Weekly TV
Piiano, Scanning Your Eyes, Rainbow Unicorns, Netflix Execs, & Yeast Milk - ESW #248 from 2021-10-30T09:00

In the Enterprise Security News, Devo, Dragos, Cato Networks and Aura have all announced $200m or larger funding rounds, TransUnion acquires Sontiq for $638m, Summit Partners acquires Invicti fo...

Listen
Paul's Security Weekly TV
What Exactly Is an Incident Commander, Anyway - Matt Linton - PSW #716 from 2021-10-29T21:00

You may have seen the term "Incident Commander" in discussions about incident response, but do you know where that term came from and what it means? How can professionalizing your incident respo...

Listen
Paul's Security Weekly TV
Decrypt As If Your Security Depends On It - Jamie Moles - ESW #248 from 2021-10-29T21:00

Use of encryption is on the rise: both by cyber defenders and the attackers they’re tasked to defend against. Encryption has reached near-full adoption by internal teams hoping to implement stro...

Listen
Paul's Security Weekly TV
Focusing on Preventing Ransomware - Roger Grimes - PSW #716 from 2021-10-29T09:00

A good backup is not prevention. Its recovery. Roger A. Grimes, author of the just released Ransomware Protection Playbook (Wiley), and author of 12 other books and over 1100 articles on compute...

Listen
Paul's Security Weekly TV
Mapping Across an Ocean of Security Frameworks, Part 2 - Thomas Sager, Tony Sager - SCW #92 from 2021-10-28T09:00

Tony and Thomas will discuss the importance, value, and challenge of cross-mapping security frameworks, and the rationale and process used by CIS to create end support mapping, some real-world e...

Listen
Paul's Security Weekly TV
Mapping Across an Ocean of Security Frameworks, Part 1 - Thomas Sager, Tony Sager - SCW #92 from 2021-10-27T21:00

Tony and Thomas will discuss the importance, value, and challenge of cross-mapping security frameworks, and the rationale and process used by CIS to create end support mapping, some real-world e...

Listen
Paul's Security Weekly TV
Board Tips & Tricks, Security Culture, & Zero Trust Myths - BSW #237 from 2021-10-27T09:00

In the Leadership and Communications section for this week: CISOs: Approach the board with precision, simplicity, Layoffs Taught Me To Never Make 3 Powerful Leadership Mistakes, 6 zero trust myt...

Listen
Paul's Security Weekly TV
Fight Fire With Fire: Proactive CyberSec Strategies for Security Leaders - Renee Tarun - BSW #237 from 2021-10-26T21:00

With today’s expanding attack surface, constantly evolving threat landscape, and growing cyber skills gap, cybersecurity leaders need actionable advice from seasoned peers more than ever. Renee ...

Listen
Paul's Security Weekly TV
UAParser.js Malware in NPM, Squirrel Sandbox Escape, Securing CI/CD, & AppSec Videos - ASW #171 from 2021-10-26T09:00

This week in the AppSec News: Malware in the UAParser.js npm package, security vuln in Squirrel scripting language, a blueprint for securing software development, L0phtCrack now open source, app...

Listen
Paul's Security Weekly TV
Security Champions in an Online First World - Ashish Rajan - ASW #171 from 2021-10-25T21:00

Ashish will talk about building a security champion in an online world and how SAST as it stands today will die in the world of DevOps and Cloud.

 

Segment Resources:

Listen

Paul's Security Weekly TV
Wild Hippos, Chrome FTP, L0phtCrack Is Open-Source, Win 11 Pentium, & Legacy Systems - PSW #715 from 2021-10-24T09:00

This week in the Security News: More security advice for non-profits, faster 0-day exploits, ban all the things, you are still phishable, how to treat security researchers, what the heck is cybe...

Listen
Paul's Security Weekly TV
Scanning For Default Credentials With Python - PSW #715 from 2021-10-23T21:00

We've been working on this Python project that will use the Nmap Python library to scan the local network, enumerate select systems and devices, try to login with default or known credentials, a...

Listen
Paul's Security Weekly TV
Evolution & Maturity of the Cybersecurity Industry - Maxime Lamothe-Brassard - PSW #715 from 2021-10-23T09:00

The business of Security is gaining in maturity, from being an obscure corner of IT to becoming a core part of the C-Suite. How is this transformation happening and what can we learn from the si...

Listen
Paul's Security Weekly TV
What We've Learned From Interviewing Cybercriminals - Adam Janofsky - ESW #247 from 2021-10-22T21:00

Over the last year, The Record has published several interviews between security analysts and cybercriminals. This includes representatives from REvil, BlackMatter, and Marketo. The interviews h...

Listen
Paul's Security Weekly TV
Query.AI, Tenchi Security, HelpSystems, CrowdStrike, & Snowcat Scanner for Istio - ESW #247 from 2021-10-22T09:00

This Week in the Enterprise Security News: HelpSystems Acquires PhishLabs, Elastic and Optimyze, The Leading Indicators of a Great Info/Cybersecurity Program, & more!

 

Visit Listen

Paul's Security Weekly TV
First Jobs in Cybersecurity: The Analyst Role - Joshua Copeland - ESW #247 from 2021-10-21T21:00

There are tons of cybersecurity job openings for folks with 3-5 years of experience, but where are the junior roles? How are people getting their initial 3-5 years in? Josh and the ESW hosts dis...

Listen
Paul's Security Weekly TV
Excited About PCI DSS 4.0? What to Expect & How to Prepare, Part 2 - Chris Pin - SCW #91 from 2021-10-21T09:00

We’re getting closer to the Q1 2022 release of PCI DSS 4.0, which is expected to differ from the current PCI DSS 3.2.1 version in a few key ways. This includes giving organizations more options ...

Listen
Paul's Security Weekly TV
Excited about PCI DSS 4.0? What to Expect & How to Prepare, Part 1 - Chris Pin - SCW #91 from 2021-10-20T21:00

We’re getting closer to the Q1 2022 release of PCI DSS 4.0, which is expected to differ from the current PCI DSS 3.2.1 version in a few key ways. This includes giving organizations more options ...

Listen
Paul's Security Weekly TV
Building Your Zero Trust Architecture: Stronger, Simpler Access Controls - Jason Garbis - BSW #236 from 2021-10-20T09:00

Zero Trust has quickly become a cybersecurity mandate and also the most abused term in the industry. The core tenants of Zero Trust are rooted in the ability to deliver secure access, which is a...

Listen
Paul's Security Weekly TV
Security Money - The Index Hits a Turkey (3 Records in a Row) - BSW #236 from 2021-10-19T21:00

The Security Weekly 25 Index hits an all-time high for the third straight quarter! In this segment, Matt, Jason, and Ben break down the cybersecurity market winners and losers, in both the publi...

Listen
Paul's Security Weekly TV
View Source, Bindiff for Vuln Analysis, Bypass with GitHub Actions, & NIST DevSecOps - ASW #170 from 2021-10-19T09:00

This Week in the AppSec News: View source good / vuln bad, IoT bad / rick-roll good, analyzing the iOS 15.0.2 patch to develop an exploit, bypassing reviews with GitHub Actions, & more NIST DevS...

Listen
Paul's Security Weekly TV
Dev(Sec)Ops Scanning Challenges & Tips - Nuno Loureiro, Tiago Mendo - ASW #170 from 2021-10-18T21:00

There's a plenitude of ways to do Dev(Sec)Ops, and each organization or even each team uses a different approach. Questions such as how many environments you have and the frequency of deployment...

Listen
Paul's Security Weekly TV
IoT Rickroll, Suing Over Disclosures, K-12 Cybersecurity Act, & SS7 Signaling - PSW #714 from 2021-10-17T09:00

This week in the Security News: Following the ransomware money, the Mystery Snail, school cybersecurity is the law, sue anyone, just not security researchers, "hacking" a flight school, refusing...

Listen
Paul's Security Weekly TV
GraphQL - Sven Morgenroth - PSW #714 from 2021-10-16T21:00

Sven will talk about GraphQL APIs. He is going to show common issues that arise from its usage and how to attack GraphQL applications.

 

This segment is sponsored by Invicti. Visit...

Listen
Paul's Security Weekly TV
Open Source Endpoint Security with Osquery & Fleet - Zach Wasserman - PSW #714 from 2021-10-16T09:00

The world's top tech organizations are pursuing an open-source endpoint security strategy using osquery. We will dig into how osquery and Fleet can enable observation, collection, and investigat...

Listen
Paul's Security Weekly TV
Wiz Valuation, Facebook OSS Tools, Gretel.ai, & Yubico Biometric Keys - ESW #246 from 2021-10-15T21:00

In the Enterprise Security News: Wiz raises $250 million at a staggering $6 billion valuation, Gretel.ai, another privacy engineering startup, raises $50 million, Forcepoint acquires Bitglass, Y...

Listen
Paul's Security Weekly TV
Why Less Is More for Static Application Scanning - Surag Patel - ESW #246 from 2021-10-15T09:00

Seeking to capitalize on the full potential of digital transformation, organizations are turning to serverless applications to accelerate development cycles, reduce operational complexities, and...

Listen
Paul's Security Weekly TV
A Plea for Better Press Releases - ESW #246 from 2021-10-14T21:00

A big part of preparing for Security Weekly news segments is reading press releases. Most of us also get emails whenever a cybersecurity vendor sends out a press release. Too many are frivolous,...

Listen
Paul's Security Weekly TV
Social Engineering Deep Dive, Part 2 - Perry Carpenter - SCW #90 from 2021-10-14T09:00

Tune in for this discussion on social engineering and its merits on being recognized as a legitimate component of cyber security. We'll also dive into the whole notion of motive and intent as it...

Listen
Paul's Security Weekly TV
Social Engineering Deep Dive, Part 1 - Perry Carpenter - SCW #90 from 2021-10-13T21:00

Tune in for this discussion on social engineering and its merits on being recognized as a legitimate component of cyber security. We'll also dive into the whole notion of motive and intent as it...

Listen
Paul's Security Weekly TV
Top Cybersecurity Statistics/Trends/Facts, Zero Trust, & Hiring Strategies - BSW #235 from 2021-10-13T09:00

In the Leadership and Communications section for this week: How to strive and thrive [in a meeting], 5 steps toward real zero trust security, Seven strategies for building a great security team,...

Listen
Paul's Security Weekly TV
The Human Element of Security Awareness - Brian Reed - BSW #235 from 2021-10-12T21:00

It is Cybersecurity Awareness Month, but security awareness is a lot tougher than just dedicating a month to awareness activities. Security awareness is a journey, requiring motivation along the...

Listen
Paul's Security Weekly TV
Twitch Breach, HTTPd Path Traversal, Disabling Macros, & Great Cybersecurity Programs - ASW #169 from 2021-10-12T09:00

This week in the AppSec News, Mike and John talk: The Twitch breach, a path traversal in Apache httpd, Microsoft disables macros by default after almost 30 years, factors in a great cybersecurit...

Listen
Paul's Security Weekly TV
Modernizing the Management of Your Software Supply Chain - Tom Gibson - ASW #169 from 2021-10-11T21:00

SBOM: What does it really tell you and the importance of having one for your organization.

- Finding and fixing known vulnerabilities in dependencies and container images

- Buildin...

Listen
Paul's Security Weekly TV
LANtennas, ESXi & Python, Twitch Leaks, Facebook BGP, & iPhone Is Always On - PSW #713 from 2021-10-10T09:00

This week in the Security Weekly News: Brushing that data breach under the rug? Get sued by the US Government!, all your text messages belong to someone else, beware of the Python in your ESXi, ...

Listen
Paul's Security Weekly TV
Up & Running With Security Onion - PSW #713 from 2021-10-09T21:00

There are many options to choose from when setting up The Security Onion. The use cases are vast, including a NIDS (Zeek, Suricata), HIDS (Beats, Wazuh, osquery) and standalone instances for a S...

Listen
Paul's Security Weekly TV
Survey Says: Improve Your Security Posture by Purple Teaming - Dan DeCloss - PSW #713 from 2021-10-09T09:00

Today Dan DeCloss, CEO of PlexTrac, joins the panel to share results from a CyberRisk Alliance survey of 315 security practitioners in the U.S. and Canada. This research, sponsored by PlexTrac, ...

Listen
Paul's Security Weekly TV
Privacy Engineering Firms, Facebook Outages, Orca Series C, & Gravwell - ESW #245 from 2021-10-08T21:00

In the Enterprise Security News for this week: Orca Security raises all the money, Privacy engineering firms hit their funding stride, McAfee and FireEye merge, but where's RSA's dance partner? ...

Listen
Paul's Security Weekly TV
Shifty Adversaries, Shifting Tactics - Ryan Kalember - ESW #245 from 2021-10-08T09:00

Once again, it is Cybersecurity awareness month and we'll be talking with Ryan Kalember about the latest threats and other activities he and Proofpoint have going on this month. When it comes to...

Listen
Paul's Security Weekly TV
Better Sales, Worse Relationships? - Richard Reinders - ESW #245 from 2021-10-07T21:00

Sales teams are under more pressure than ever to locate and bring in new customers. The methods they use can range from clever to questionable. While some of the more ethically questionable meth...

Listen
Paul's Security Weekly TV
ISO27001, Part 2 - Wim Remes - SCW #89 from 2021-10-07T09:00

This week we're talking all things ISO27001 with Wim Remes! We're starting with what it is, the who, what, where, when, why etc. then we'll talk about the bad and the good. Tune in for this spec...

Listen
Paul's Security Weekly TV
ISO27001, Part 1 - Wim Remes - SCW #89 from 2021-10-06T21:00

This week we're talking all things ISO27001 with Wim Remes! We're starting with what it is, the who, what, where, when, why etc. then we'll talk about the bad and the good. Tune in for this spec...

Listen
Paul's Security Weekly TV
CISA's Initiatives, Partnerships, and Cybersecurity Awareness Month - Alaina Clark - BSW #234 from 2021-10-06T09:00

We kick-off Cybersecurity Awareness Month with Alaina Clark, Assistant Director for Stakeholder Engagement at the Cybersecurity and Infrastructure Security Agency (CISA). Jill Aitoro, Editor in ...

Listen
Paul's Security Weekly TV
Medical Device Security - Dan Purvis - BSW #234 from 2021-10-05T21:00

With the first recorded death from a Ransomware attack during the Pandemic, it's time to take medical device security seriously. Dan Purvis, CEO at Velentium, joins Business Security Weekly to d...

Listen
Paul's Security Weekly TV
Prototype Pollution, Funding Open Source Security, Expiring Root CA, Mariana Trench - ASW #168 from 2021-10-05T09:00

In the AppSec News, John and Mike discuss Prototype pollution vulns, funding open source project hardening, Let's Encrypt root CA expires, and Marian Trench scanner for Android and Java!

...

Listen
Paul's Security Weekly TV
The Power of Developer-First Security - Hillary Benson - ASW #168 from 2021-10-04T21:00

Developers want to write good code. Secure code. Security tools that optimize developer workflows for handling security issues can take a large burden off security practitioners and make triagin...

Listen
Paul's Security Weekly TV
Pickpocketing Apple Pay, Mandatory Breach Reporting, Huawei Fears, & Cyber Criminals - PSW #712 from 2021-10-02T21:00

In the Security News, Microsoft adds automated mitigations for Exchange servers, Senior US cyber officials support mandatory breach reporting, 2021 has broken the record for 0days, but maybe tha...

Listen
Paul's Security Weekly TV
Defense Strategies to Combat Sophisticated Ransomware - Mehul Revankar - PSW #712 from 2021-10-02T09:00

To defend themselves, companies need to detect ransomware attacks early, gather the intelligence to understand the attack, and prevent the attacks from occurring in the future. Qualys’ Mehul Rev...

Listen
Paul's Security Weekly TV
Startup Post Mortems, Live Security Statuses, LG Acquires Cybellum, & Coalition - ESW #244 from 2021-10-01T21:00

In the Enterprise Security News: Cyber insurance firm Coalition lands a $205m Series E with a $3.5bn valuation, Risk management platform Panorays nabs $42m, Jscrambler raises a $15m Series A to ...

Listen
Paul's Security Weekly TV
The Importance of Identity Detection and Response (IDR) - Joseph Salazar - ESW #244 from 2021-10-01T09:00

Identity Detection and Response (IDR) is a new security category that focuses on protecting credentials, privileges, cloud entitlements, and the systems that manage them across endpoints, Active...

Listen
Paul's Security Weekly TV
How Good CISOs Build Bad Security Programs - Juliet Okafor - ESW #244 from 2021-09-30T21:00

No Man is an Island. Neither can a security program exist without interconnections and strong relationships to the rest of the business. Yet, over and over again I meet Security Leaders that thr...

Listen
Paul's Security Weekly TV
Compliance and “The Crowd”, Part 2 - Casey Ellis - SCW #88 from 2021-09-30T09:00

Crowdsourcing and multi-sourcing focus on risk identification and reduction, and they seem to be effective... but my auditor doesn't understand what it is yet - Will it meet the requirements of ...

Listen
Paul's Security Weekly TV
Compliance and “The Crowd”, Part 1 - Casey Ellis - SCW #88 from 2021-09-29T21:00

Crowdsourcing and multi-sourcing focus on risk identification and reduction, and they seem to be effective... but my auditor doesn't understand what it is yet - Will it meet the requirements of ...

Listen
Paul's Security Weekly TV
CISO vs. CIO, CISO & the C-Suite, & How the CISO Works With the CPO - BSW #233 from 2021-09-29T09:00

This week in the Leadership and Communications section, Who actually owns cyber security: CISO vs. CIO, How to Say “No” After Saying “Yes”, Decode different types of business interruption insura...

Listen
Paul's Security Weekly TV
Building Security from Scratch: One Year as CISO at a Start-up - Guillaume Ross - BSW #233 from 2021-09-28T21:00

We often think "this would be so much better if done properly from the beginning", but the reality is, doing things from scratch comes with different challenges. Managing priorities, deciding wh...

Listen
Paul's Security Weekly TV
Exchange's Great Leak, RCE in VMware, IoT Bug in MQTT, & Chrome's Memory Safety Nets - ASW #167 from 2021-09-28T14:04:30

This week in the AppSec News: The Great Leak flaw in Exchange's auto discover feature, common flaws in VMware and Nagios, memory issues and SSRF in Apache's HTTP server, Chrome's plans for memor...

Listen
Paul's Security Weekly TV
AppSec Orchestration/Correlation & DevSecOps Efficiency - Anita D'Amico, Patrick Carey - ASW #167 from 2021-09-28T13:14:02

In its 2019 Hype Cycle for Application Security report, Gartner revealed a new, “high-priority” category called Application Security Orchestration and Correlation (ASOC). ASOC delivers three pri...

Listen
Paul's Security Weekly TV
Renting Your Phone, Public-Key Explained, Toilet Identification, & AutoDiscover Bug - PSW #711 from 2021-09-26T09:00

This week in the Security News: What to do with your old hardware, renting your phone, "persistently execute system software in the context of Windows", sensational headline: ransomware could ca...

Listen
Paul's Security Weekly TV
Nzyme - Paul Asadoorian & Larry Pesce - PSW #711 from 2021-09-25T21:00

In this segment Paul and Larry attempt to confirm or deny that Nzyme performs intelligent device fingerprinting and behavioral analytics to detect rogue actors. Classic signature-based detection...

Listen
Paul's Security Weekly TV
Velociraptor - Digging Deeper - Mike Cohen, Wes Lambert - PSW #711 from 2021-09-25T09:00

Velociraptor is a multi-platform, open-source, endpoint forensics, monitoring, and response platform that allows security professionals to quickly and easily dig through host artifacts and perfo...

Listen
Paul's Security Weekly TV
The Color White, Forgerock IPO, Ditching Your Microsoft Password, & Neosec - ESW #243 from 2021-09-24T21:00

This week in the Enterprise Security News: Funders Fund Values Identity Startup Persona at $1.5 billion, Neosec Emerges from Stealth With $20.7 million in funding, F5 acquires threat stack, Forg...

Listen
Paul's Security Weekly TV
Threat Intelligence & Threat Hunting - Chris Cochran - ESW #243 from 2021-09-24T09:00

Chris will discuss the relevance of intelligence and threat hunting today and how they work together. He will also talk about his EASY framework for creating impactful intelligence and its relat...

Listen
Paul's Security Weekly TV
Scaling Application Security - Joe Gillespie, Nuno Loureiro - ESW #243 from 2021-09-23T21:00

A common ratio between Appsec and development teams is 1:100 (1 Security Engineer for every 100 developers). Scaling Appsec teams, especially when it comes to security testing, becomes challengi...

Listen
Paul's Security Weekly TV
Activism v. Hacktivism, Part 2 - Johanna Baum - SCW #87 from 2021-09-23T09:00

"Hacktivism" is a controversial term with several meanings. The word was coined to characterize electronic direct action as working toward social change by combining programming skills with crit...

Listen
Paul's Security Weekly TV
Activism v. Hacktivism, Part 1 - Johanna Baum - SCW #87 from 2021-09-22T21:00

"Hacktivism" is a controversial term with several meanings. The word was coined to characterize electronic direct action as working toward social change by combining programming skills with crit...

Listen
Paul's Security Weekly TV
Boards Rethink Incident Response, CISOs & CIOs Share, & Stay True to Ethics - BSW #232 from 2021-09-22T09:00

This Week, in the Leadership and Communications section: Boards rethink incident response playbook as ransomware surges, How CISOs and CIOs should share cybersecurity ownership, How CISOs are Bu...

Listen
Paul's Security Weekly TV
Accelerate 0-Trust Adoption W/ End2End Visibility & Increased Collaboration - Tom Roeh - BSW #232 from 2021-09-21T21:00

It's no surprise that Zero Trust initiatives are increasing in importance in both the public and private sectors. New cybersecurity mandates and a boom in remote work due to COVID-19 are just tw...

Listen
Paul's Security Weekly TV
OMIGOD, FORCEDENTRY, Code Ownership, Security as a Product, & IoT Device Criteria - ASW #166 from 2021-09-21T09:00

This week in the AppSec News, Mike and John talk: RCE in Azure OMI, punching a hole in iMessage BlastDoor, Travis CI exposes sensitive environment variables, keeping code ownership accurate, dep...

Listen
Paul's Security Weekly TV
Transforming Modern Software Development with Developer-First AppSec - Jeff Williams - ASW #166 from 2021-09-20T21:30

Modern software development demands a different approach to application security. Contrast’s developer-first Application Security Platform empowers developers to accelerate the release of secure...

Listen
Paul's Security Weekly TV
Dubious Drones, NSO Group, Apple's Bug Bounties, Ghostscript 0-Day, & IBM Server Bugs - PSW #710 from 2021-09-19T09:00

This week in the Security News: Anonymous hacks Epik (with a K), Fuzzing Close-Source Javascript Engines, ForcedEntry, 8 Websites that can replace computer software, REvil decryptor key released...

Listen
Paul's Security Weekly TV
Brakeman - Justin Collins - PSW #710 from 2021-09-18T21:00

Brakeman is a free static analysis security tool specifically designed for Ruby on Rails applications. It analyzes Rails application code to find security issues at any stage of development. Jus...

Listen
Paul's Security Weekly TV
The State of Network Security in 2021 - Sinan Eren - PSW #710 from 2021-09-18T09:00

Network breaches, ransomware attacks, and remote-work challenges highlight the need for cloud-native Secure Access Service Edge (SASE) deployments.

 

Show Notes: Listen

Paul's Security Weekly TV
Palo Alto Goes IoT, Numbers Lose Their Meaning, BitSight, & Colossal Mammoths - ESW #242 from 2021-09-17T21:00

This week in the Enterprise News: Adrian's first Enterprise News in the Captain's Seat, BitSight raises $250m on a $2.4bn valuation, Palo Alto Networks enters the consumer IoT market, Martin Roe...

Listen
Paul's Security Weekly TV
The Device Security Divide - John Loucaides - ESW #242 from 2021-09-17T09:00

Organizations are divided. Some will be able to lean into mitigations against catastrophic and cascading failures. Others will not. In this discussion, we will explore the risk tradeoffs in firm...

Listen
Paul's Security Weekly TV
Web Asset Discovery in Application Security - Tolga Kayas - ESW #242 from 2021-09-16T21:00

Large organizations develop hundreds of new web applications every year. Some of those deployments are lost in time, and others go wild with high severity vulnerabilities. Forgotten and outdated...

Listen
Paul's Security Weekly TV
Insider Threats Overview - Going Beyond The Norm, Part 2 - Jim Henderson - SCW #86 from 2021-09-16T09:00

Defining Insider Threats / Going Beyond Traditional Definitions (What Is Really Happening Behind Firewalls) How Damaging And Costly An Insider Threat Incident Can Be? (Eye Opening Examples From ...

Listen
Paul's Security Weekly TV
Insider Threats Overview - Going Beyond The Norm, Part 1 - Jim Henderson - SCW #86 from 2021-09-15T21:00

Defining Insider Threats / Going Beyond Traditional Definitions (What Is Really Happening Behind Firewalls) How Damaging And Costly An Insider Threat Incident Can Be? (Eye Opening Examples From ...

Listen
Paul's Security Weekly TV
SEC Is Serious, CISA's Bad Practices, & What Tech Workers Really Want - BSW #231 from 2021-09-15T09:00

This Week, in the Leadership and Communications section, The SEC Is Serious About Cybersecurity. Is Your Company?, CISA Urges Organizations to Avoid Bad Security Practices, IT leaders facing bac...

Listen
Paul's Security Weekly TV
Cyber Education Is the Key to Solving the Skills Gap - Kevin Nolten - BSW #231 from 2021-09-14T21:00

Kevin Nolten, Director of Academic Outreach from Cyber.org, joins Business Security Weekly to discuss how cyber education is the key to solving the skills gap and developing the next generation ...

Listen
Paul's Security Weekly TV
OWASP Top 10, CISA Bad Practices, Azurescape, Confluence RCE, & API Security Tokens - ASW #165 from 2021-09-14T09:00

This week in the AppSec News, Mike and John talk: OWASP Top 10 draft for 2021, bad practices noted by CISA, Azurescape cross-account takeover, Confluence RCE, WhatsApp image handling, API securi...

Listen
Paul's Security Weekly TV
Findings From the 2021 AppSec Shift Left Progress Report - Manish Gupta - ASW #165 from 2021-09-13T21:00

Data from the ShiftLeft customer report shows that companies that have rebuilt their core testing processes around faster and more accurate static analysis are able to release more secure code a...

Listen
Paul's Security Weekly TV
Iframe Security - Benjamin Daniel Mussler - PSW #709 from 2021-09-05T09:00

Benjamin will discuss securing iframes with the sandbox attribute. This segment is sponsored by Acunetix.

 

Visit https://securitywee...

Listen
Paul's Security Weekly TV
Hacking Honda, Insider Threat Galore, ChaosDB, USB File Weight, & Linux 5.14 - PSW #709 from 2021-09-04T21:00

This week in the Security News: Hacking Honda, a fact about single-factor, disarming your home and alarming vulnerability disclosure response, btw, you have a Sudo vulnerability, NSO under inves...

Listen
Paul's Security Weekly TV
Nmap Vulnerability Scanning/Flan Scan - PSW #709 from 2021-09-04T09:00

Paul presents a Technical Segment that walks through Nmap, Vulners scripts, & Flan Scan!

 

Visit https://www.securityweekly.com/psw Listen

Paul's Security Weekly TV
"Lift & Drag", BeyondTrust, Absolute DataExplorer, & RDP Exploits - ESW #241 from 2021-09-03T21:00

This week in the Enterprise News, "inertia in cybersecurity strategy", Check Point acquires Avanan, Absolute DataExplorer, BreachQuest Launches with $4.4m in seed funding, Acronym Bingo, & More!...

Listen
Paul's Security Weekly TV
Putting the "R" in the NDR - John Smith - ESW #241 from 2021-09-03T09:00

It's time to think more broadly about the R in NDR. Incident responders need a full spectrum of response–from hunting and investigations to remediation–not just another alert cannon. While block...

Listen
Paul's Security Weekly TV
Transparency in Large Supply Chains - Philippe Lafoucrière - ESW #241 from 2021-09-02T21:00

GitLab is unique in many ways, but our transparency value is pushing us to mature our Security posture faster than attackers. Discover how GitLab iterates quickly to adapt to a world where every...

Listen
Paul's Security Weekly TV
The Truth Behind the Payments, Part 2 - Christopher Bulin - SCW #85 from 2021-09-02T09:00

SMB needs to understand the importance of being PCI compliant and that just because the verbiage on a website says the vendor is compliant, doesn't make the merchant compliant. Just because it s...

Listen
Paul's Security Weekly TV
The Truth Behind the Payments, Part 1 - Christopher Bulin - SCW #85 from 2021-09-01T21:00

SMB needs to understand the importance of being PCI compliant and that just because the verbiage on a website says the vendor is compliant, doesn't make the merchant compliant. Just because it s...

Listen
Paul's Security Weekly TV
State of Cyber Threats: Tenfold Increase in Ransomware - Derek Manky - BSW #230 from 2021-09-01T09:00

Looking into the first half of 2021, there are important indicators of what cyber adversaries are planning next. This will be a conversation about cyberthreat trends and looking into takeaways f...

Listen
Paul's Security Weekly TV
Staff Attrition Is Rising, Retaining Women in Tech, & Growing Privacy Concerns - BSW #230 from 2021-08-31T21:00

In the Leadership and Communications section, Executives in tech say staff attrition is rising, 7 in 10 Facility Managers Consider OT Cybersecurity a Major Concern, Consumers Concerned About Per...

Listen
Paul's Security Weekly TV
ChaosDB, OpenSSL String Bugs, Revealing Locations, & More Top 15 Vulns - ASW #164 from 2021-08-31T09:00

This week in the Application Security News, Mike and John talk: Flaws in Azure's CosmosDB, OpenSSL vulns in string handling, dating app location security, cloud security orienteering, detailed S...

Listen
Paul's Security Weekly TV
A DevOps Perspective on Risk Tolerance & Risk Transfer - Caroline Wong - ASW #164 from 2021-08-30T21:00

In the segment Mike and Caroline will discuss Risk Tolerance and Risk Transfer. They'll touch on the following: risk ranking, risk transfer in supply chain, how to diversify security controls, t...

Listen
Paul's Security Weekly TV
Yard Sales, Bitcoin Thief Charged, Mouse Privilege Escalation, & LED Eavesdropping - PSW #708 from 2021-08-29T09:00

This week in the Security News: Some describe T-Mobile security as not good, if kids steal bitcoin just sue the parents, newsflash: unpatched vulnerabilities are exploited, insiders planting mal...

Listen
Paul's Security Weekly TV
Trends in Mac Malware & Apple Security - Patrick Wardle - PSW #708 from 2021-08-28T21:00

Apple's new M1 systems offer a myriad of benefits for both macOS users, and unfortunately, to malware authors as well. In this talk Patrick details the first malicious programs compiled to nativ...

Listen
Paul's Security Weekly TV
Working With OpenVAS - PSW #708 from 2021-08-28T09:00

Gain some insights into the OpenVAS project, why you might want to use it and some of the best implementations. This segment will dive right into the extended setup by compiling OpenVAS, and all...

Listen
Paul's Security Weekly TV
Cloudflare Saves the Day, Sumo Logic SOAR, Tenable Risk Management, & Drones - ESW #240 from 2021-08-27T21:00

This week, In the Enterprise News, Guardicore Centra lets teams stop ransomware and lateral movement, Netskope streamlines procedures with improved attribution models and collaboration, Cloudfla...

Listen
Paul's Security Weekly TV
Penning a Cyber Thriller - Deb Radcliff - ESW #240 from 2021-08-27T09:00

Deb has written a thriller series about an evil corporation called GlobeCom that takes over the world through human chip implants and the hackers who rise up against it to break its backbones an...

Listen
Paul's Security Weekly TV
Deciduous / Decision trees + Security Chaos Engineering - Kelly Shortridge - ESW #240 from 2021-08-26T21:00

Deciduous is an app Kelly built with Ryan Petrich that simplifies the process of creating security decision trees. Security decision trees are valuable aids in threat modeling and prioritizing m...

Listen
Paul's Security Weekly TV
From Compliance to Resiliency: The Evolution of InfoSec, Part 2 - Tim Callahan - SCW #84 from 2021-08-26T09:00

Because only maintaining compliance is not enough to protect your business from the ever-evolving threat landscape, in this session, we will consider the intersection and codependence of complia...

Listen
Paul's Security Weekly TV
From Compliance to Resiliency: The Evolution of InfoSec, Part 1 - Tim Callahan - SCW #84 from 2021-08-25T21:00

Because only maintaining compliance is not enough to protect your business from the ever-evolving threat landscape, in this session, we will consider the intersection and codependence of complia...

Listen
Paul's Security Weekly TV
10 Years Later... 15 Priorities, 8 Weeks, & 7 Steps - BSW #229 from 2021-08-25T09:00

This Week, In the Leadership and Communications section:10 years later, software really did eat the world, CISOs’ 15 top strategic priorities for 2021, 7 steps to protect against ransomware-rela...

Listen
Paul's Security Weekly TV
What Type of CISO Are You & Does It Align to Your Company’s Needs? - Ben Carr - BSW #229 from 2021-08-24T21:00

Ben Carr, Qualys CISO, joins Business Security Weekly to share his views on the evolving role of the CISO. He’ll dive into the ever changing risks and how CISOs need to understand those risks to...

Listen
Paul's Security Weekly TV
BlackBerry's BadAlloc, Glibc's NULL, Backtick Command Injection, & ProxyLogon Details - ASW #163 from 2021-08-24T09:00

This week Mike & John discuss: BlackBerry addresses BadAlloc bugs, glibc fixes a fix, more snprintf misuse that leads to command injection, ProxyLogon technical details, & more in the AppSec New...

Listen
Paul's Security Weekly TV
Challenges in Open Source Application Security - Shubhra Kar - ASW #163 from 2021-08-23T21:00

Open Source is the new mainstream of software development. However not much attention is paid on security in the upstream community for creating robust and secure software. At the LF, we are wor...

Listen
Paul's Security Weekly TV
Shifting Left Probably Left You Vulnerable, Here’s How To Make it Right - Sonali Shah - PSW #707 from 2021-08-22T09:00

Shifting security left is good - but it’s an incomplete strategy that often leads to a false sense of security. In this segment, Sonali will discuss how organizations can reduce their risk of br...

Listen
Paul's Security Weekly TV
Sequoia: A Local Privilege Escalation Vulnerability in Linux’s Filesystem Layer - Wheel - PSW #707 from 2021-08-21T21:00

The Qualys Research Team discovered a size_t-to-int type conversion vulnerability in the Linux Kernel’s filesystem layer affecting most Linux operating systems. Any unprivileged user can gain ro...

Listen
Paul's Security Weekly TV
Tractorload of John Deere Vulns, T-Mobile Breach, Kalay IoT Hack, & HolesWarm - PSW #707 from 2021-08-21T09:00

In the Security News for this week: Buffer overflows galore, how not to do Kerberos, no patches, no problem, all your IoTs belong to Kalay, the old pen test vs. vulnerability scan, application s...

Listen
Paul's Security Weekly TV
New iboss Features, CVSS Scores, Praetorian GoKart, & Anti Anti-Money Laundering - ESW #239 from 2021-08-20T21:00

This week In the Enterprise News, iboss adds features to its Cloud Platform for visibility and control, SailPoint Workflows enable customers to automate security tasks, Digital Shadows launches ...

Listen
Paul's Security Weekly TV
Cybersecurity Tips & Challenges in the Hybrid Work Era - Darren Guccione - ESW #239 from 2021-08-20T09:00

As organizations shift to respond to an ever-changing landscape of cybersecurity challenges, cybercriminals are trying to stay one step ahead. The last two years have brought an explosion of ran...

Listen
Paul's Security Weekly TV
Humanizing Security Operations - Allie Mellen - ESW #239 from 2021-08-19T21:00

The security industry spends a lot of time talking about the tools of the SOC, especially around making the SOC more 'autonomous'. But is this really what we need? Allie is also presenting "How ...

Listen
Paul's Security Weekly TV
Gatekeeping in Cybersecurity, Part 2 - Naomi Buckwalter - SCW #83 from 2021-08-19T09:00

The “cybersecurity skills gap” is a myth. There is no skills gap. There are tens of thousands of amazing, highly intelligent, passionate people around the world looking to break into cybersecuri...

Listen
Paul's Security Weekly TV
Gatekeeping in Cybersecurity, Part 1 - Naomi Buckwalter - SCW #83 from 2021-08-18T21:00

The “cybersecurity skills gap” is a myth. There is no skills gap. There are tens of thousands of amazing, highly intelligent, passionate people around the world looking to break into cybersecuri...

Listen
Paul's Security Weekly TV
7 Tips, 5 Simple Tips, & 3 Strategies for CISOs - BSW #228 from 2021-08-18T09:00

This week, in the Leadership and Communications section, 7 tips for better CISO-CFO relationships, 5 Simple Tips to Help You Write a Powerful Email That Gets Read, 3 Strategies to Secure Your Di...

Listen
Paul's Security Weekly TV
Ransomware Trends 2021 - Fleming Shi - BSW #228 from 2021-08-17T21:00

Ransomware attacks have surged in 2021, with the number of attacks increasing dramatically and ransom amounts continuing to skyrocket. Cybercriminals are also expanding their targets, shifting t...

Listen
Paul's Security Weekly TV
Cracked Concatenation, Injection Against DNS, Allstar GitHub, & DEF CON Highlights - ASW #162 from 2021-08-17T15:07:33

This week in the AppSec News: Bug bounty report that cleverly manipulates a hash for profit, Allstar GitHub app to enforce security policies, choosing a programming language, what an app should ...

Listen
Paul's Security Weekly TV
DevSecOps - Making It Real - Mike Rothman - ASW #162 from 2021-08-16T21:00

DevSecOps is an aspirational vision for many teams. With a number of macro changes occurring in modern application development, this segment will explore what tangible, practical things can be d...

Listen
Paul's Security Weekly TV
Cyber-Symposiums, Apple Backdoor, Crypto Theft, & "Quadruple Extortion" - PSW #706 from 2021-08-15T09:00

This week in the Security News: Accenture gets Lockbit, $600 million in cryptocurrency is stolen, and they've started returning it, Lee and Jeff's data is leaked (among other senior citizens), a...

Listen
Paul's Security Weekly TV
Offensive Operations With Mythic - Kyle Avery - PSW #706 from 2021-08-14T21:00

Mythic is an open-source, multi-platform framework for conducting red team engagements. This talk will cover the automated deployment of a Mythic server, developing new "wrappers" to extend the ...

Listen
Paul's Security Weekly TV
OSINT & Social Engineering - Joe Gray - PSW #706 from 2021-08-14T09:00

Joe will discuss his upcoming Book, "Practical Social Engineering" in addition to OSINT. He is primarily passionate about OSINT and adjacent forms of Intelligence, but will need to discuss some ...

Listen
Paul's Security Weekly TV
Automate Hacker Knowledge & Community in Learning InfoSec - Carolin Solskär, TJ Null - ESW #238 from 2021-08-13T21:00

The reason our founder started Detectify is that they wanted to automate hacker knowledge and make it scalable. This is very different from how most hackers work today and what we believe will r...

Listen
Paul's Security Weekly TV
Zombie APIs, Morphisec IR Service, "New Product Jeopardy", & Risk Scoring - ESW #238 from 2021-08-13T09:00

This week in the Enterprise News: Latent AI, Optiv Security Launches Next-Gen Managed XDR, An Intriguing Update to Mandiant Advantage, ReversingLabs raises $56M to combat software supply chain, ...

Listen
Paul's Security Weekly TV
The Different Approaches To Vulnerability Management - ESW #238 from 2021-08-12T21:00

As we dig into vulnerability management we uncover both old and new challenges. We still struggle with developing and maintaining an accurate asset inventory. We also, still, struggle to priorit...

Listen
Paul's Security Weekly TV
Protecting Comm. & Collaboration in Contested Environments, Pt 2 - Matthew Erickson - SCW #82 from 2021-08-12T09:00

Protecting digital communication and collaboration is critical to both our military and private sector industries in driving mission success. Our ability to secure the local and remote systems w...

Listen
Paul's Security Weekly TV
Protecting Comm. & Collaboration in Contested Environments, Pt 1 - Matthew Erickson - SCW #82 from 2021-08-11T21:00

Protecting digital communication and collaboration is critical to both our military and private sector industries in driving mission success. Our ability to secure the local and remote systems w...

Listen
Paul's Security Weekly TV
New Fines Making Business Case for Security, & Improving Security as a Team - BSW #227 from 2021-08-11T09:00

In the Leadership and Communications section for this week, A Chief Executive Officer's Guide to Cybersecurity, Zoom Settlement: An $85M Business Case for Security Investment, CISOs: Do you know...

Listen
Paul's Security Weekly TV
The 3 Mistakes All First Time CISOs Make That No One Tells You - Jim Routh - BSW #227 from 2021-08-10T21:00

Listen in for a discussion with Jim Routh, former CISO at Aetna, CVS Healthcare, and Mass Mutual, to discuss the 3 mistakes all first time CISOs make. Jim will share the lessons he learned throu...

Listen
Paul's Security Weekly TV
Router Auth Bypass, Weak IoT RNG, HTTP/2 Request Smuggling, & Kindle Fuzzing - ASW #161 from 2021-08-10T09:00

This week in the AppSec News: Hardware hacking for authn bypass and analyzing IoT RNG, Request Smuggling in HTTP/2, Kindle Fuzzing, Kubernetes Hardening, Countering Dependency Confusion, ATO Che...

Listen
Paul's Security Weekly TV
Securing Modern Web Apps: Development Techniques are Changing - Tom Hudson - ASW #161 from 2021-08-09T21:36:57

The use of web apps, SPAs, and APIs are growing steadily and traditional scanning methods don't provide enough coverage. The appsec tools need to innovate and become smarter and more contextual ...

Listen
Paul's Security Weekly TV
'Master Faces', Ship Hijacked, Windows Container Escape, & DNS Loopholes - PSW #705 from 2021-08-08T09:00

This week in the Security News: PwnedPiper and vulnerabilities that suck, assless chaps, how non-techy people use ARP, how to and how not to explain the history of crypto, they are still calling...

Listen
Paul's Security Weekly TV
The Stakes Are Raised When Protecting the Foundation of Computing - Scott Scheferman - PSW #705 from 2021-08-07T21:00

With Eclypsium researchers' discovery of BIOSDisconnect and their upcoming talk and demo at DefCon 29 upon us, the stakes have never been higher when it comes to protecting the foundation of com...

Listen
Paul's Security Weekly TV
Corelight Smart PCAPs, Shifting Left, Tenable AD Security, & Tube Vulns - ESW #237 from 2021-08-07T09:00

In the Enterprise News, Armis Identifies Nine Vulnerabilities in pneumatic tubes, Corelight Introduces Smart PCAPs, SolarWinds disputes lawsuit, Code42 and Rapid7 Partner, and more news from thi...

Listen
Paul's Security Weekly TV
RF Village at DefCon - Rick Farina, Rick Mellendick - PSW #705 from 2021-08-07T09:00

The RF Hackers Sanctuary is a group of experts in the areas of Information, Wifi, and Radio Frequency Security with the common purpose to teach the exploration of these technologies with a focus...

Listen
Paul's Security Weekly TV
The State of CyberSecurity Ops in a Ransomware Filled Hybrid Work World - David Finger - ESW #237 from 2021-08-06T21:00

Ransomware is flourishing and our endpoints are scattered outside the corporate network. Visibility is a challenge in this age of decentralized corporate assets. Our discussion today will explor...

Listen
Paul's Security Weekly TV
Cyber Hat Trick: How Ransomware Gangs Exfiltrate, Encrypt & Exploit - Matt Cauthorn - ESW #237 from 2021-08-06T09:00

Exfiltrate. Encrypt. Exploit. In 2021, ransomware attackers moved beyond exfiltrating and encrypting data to extract a ransom, working to compromise the victim’s build server to introduce an exp...

Listen
Paul's Security Weekly TV
The State of Cybersecurity & Destigmatizing Reporting Security Vulnerabilities - BSW #226 from 2021-08-05T01:00:27

In the Leadership and Communications section for this week: 10 security tools all remote employees should have, 1 in 4 security teams report to CIOs, but would benefit from CISO leadership, stat...

Listen
Paul's Security Weekly TV
OT Security for Critical Infrastructure and Why It Is Not “Intuitive” - Edward Liebig - BSW #226 from 2021-08-03T21:00

The IT and operational technologies of critical infrastructure are under attack. The "general expectation" from the public and lawmakers is "fix it already" but we will discuss why this expectat...

Listen
Paul's Security Weekly TV
PunkSpider, Bug Bounties, RCE in PyPI, Kernel Pwning With eBPF, & Top Vulns From CISA - ASW #160 from 2021-08-03T09:00

This week in the AppSec News: PunkSpider coming to DEF CON, Google matures its VRP, $50K bounty for an access token, RCE in PyPI, kernel vuln via eBPF, top vulns reported by CISA, & the importan...

Listen
Paul's Security Weekly TV
Platform Firmware Security - Maggie Jauregui - ASW #160 from 2021-08-02T21:00

Firmware security is complex and continues to be an industry challenge. In this podcast we'll talk about the reasons firmware security remains a challenge and some best practices around platform...

Listen
Paul's Security Weekly TV
PetitPotam Attack, History of RickRolling, & Foxit PDF Vulns - PSW #704 from 2021-08-01T09:00

This week in the Security News: From a stolen laptop to inside the company network, the essential tool for hackers called "Discord", fixin' your highs, hacking DEF CON, an 11-year-old can show y...

Listen
Paul's Security Weekly TV
Cyber-Physical Attacks - Michael Welch - PSW #704 from 2021-07-31T21:00

Join Michael Welch for a discussion on the ramifications a cyber-physical attack can have on ill prepared organizations. As a third-party expert, Michael can speak to: • The importance of being ...

Listen
Paul's Security Weekly TV
The B Is for Business - Alyssa Miller - PSW #704 from 2021-07-31T09:00

Alyssa will discuss the growing trend of organizations implementing Business Information Security Officers. We'll talk about how the BISO builds bridges between the security and business organiz...

Listen
Paul's Security Weekly TV
Aqua Security, Clearview AI, Threat Stack EKS Support, & Security Summit 2021 - ESW #236 from 2021-07-30T21:00

This week in the Enterprise News: Aqua Security Introduces new Aqua Platform, Decryption Tools, Security Summit 2021: Google expands Trusted Cloud, Clearview AI raises $30M to accelerate growth ...

Listen
Paul's Security Weekly TV
Tanium for Incidents: How the Best Defense Gets Better: Part 2 - Stephanie Aceves - ESW #236 from 2021-07-30T09:00

Security starts before detection, it starts before investigations. Mature security teams understand the importance of good hygiene and take proactive measures to secure themselves against the ev...

Listen
Paul's Security Weekly TV
Need for CyberSecurity Training Programs/Role Cyber Professionals Play - Da-Wyone Haynes - ESW #236 from 2021-07-29T21:00

Brief chat around the rise in Ransomware attacks, campaigns against our Infrastructure, the deficit in Cyber Talent, and how we could address the issue by extending Corporate Cyber Training prog...

Listen
Paul's Security Weekly TV
Catching Up W/Priya on Recent Litigation and Proposed Legislation: Part 2 - SCW #81 from 2021-07-29T09:00

Priya Chaudhry joins us today as co-host and we are eager to catch up with her and get her legal perspective on recent litigations and proposed legislation that impacts our world of security and...

Listen
Paul's Security Weekly TV
Catching Up w/Priya on Recent Litigation & Proposed Legislation: Part 1 - SCW #81 from 2021-07-28T21:00

Priya Chaudhry joins us today as co-host and we are eager to catch up with her and get her legal perspective on recent litigations and proposed legislation that impacts our world of security and...

Listen
Paul's Security Weekly TV
Security Is a Barrier & Incentive, Theatrical Meetings, & Cybersecurity Salaries - BSW #225 from 2021-07-28T09:00

In the Leadership and Communications section for this week: In modernization, security is a barrier and an incentive, Federal CISO DeRusha Maps FISMA Reform Priorities, Cybersecurity salaries: W...

Listen
Paul's Security Weekly TV
Security Money - The Index Hits Another All Time High - BSW #225 from 2021-07-27T21:00

Both the Security Weekly 25 Index and the NASDAQ close at record highs on 7/23/2021. See how the security market continues to stay hot. The current companies in the Security Weekly 25 Index: SCW...

Listen
Paul's Security Weekly TV
CWE Top 25, Bugs in Inconstancies, Sequoia Vuln, Twitter Transparency, & Cloud Risks - ASW #159 from 2021-07-27T17:04:14

This week in the AppSec News: CWE releases the top 25 vulns for 2021, findings bugs in similar code, Sequoia vuln in the Linux kernel, Twitter transparency for account security, a future for clo...

Listen
Paul's Security Weekly TV
Navigating the Seas of Security in Serverless Functions - Peter Klimek - ASW #159 from 2021-07-27T17:03:18

Adoption of serverless functions is rapidly growing, which means security teams will be challenged to deliver protection for data and applications in these complex environments in the coming mon...

Listen
Paul's Security Weekly TV
Windows Vulns Galore, Homoglyph Domains, Pegasus, & "Trust No One"! - PSW #703 from 2021-07-25T09:00

This week in the Security News: Trust no one, its all about the information, so many Windows vulnerabilities and exploits, so. many., Saudi Aramco data for sale, Sequoia, a perfectly named Linux...

Listen
Paul's Security Weekly TV
CyberMarket & Democratisation/Globalisation of CyberSecurity Consulting - Gordon Draper - PSW #703 from 2021-07-24T21:00

CyberMarket.com is a marketplace where CyberSecurity Consultancies and clients can find each other. There is a growing trend where CyberSecurity Consultants recognize the gap between what they a...

Listen
Paul's Security Weekly TV
Online Safety & Security: Dating Apps & Online Marketplaces - Jeff Tinsley - PSW #703 from 2021-07-24T09:00

Safety in online dating spaces is an issue the dating industry has grappled with for some time; with the surge of dating app usage during the pandemic, the demand for dating apps to take respons...

Listen
Paul's Security Weekly TV
Why Transparency Matters & Web Application Prioritization - Mark Ralls, Wayne Haber - ESW #235 from 2021-07-23T21:00

The shift away from web application security, caused by the pandemic and the focus on remote workforces, resulted in an increased number of web vulnerabilities. In this segment, Mark talks about...

Listen
Paul's Security Weekly TV
Rapid7 Acquires Intsights, Intezer Refines Malware Analysis, & Funding News - ESW #235 from 2021-07-23T09:00

In the Enterprise News, SafeBreach adds support for new advanced attacks to the Microsoft Defender for Endpoint evaluation lab, Stellar Cyber XDR Kill Chain allows security analyst teams to disr...

Listen
Paul's Security Weekly TV
Reinventing Asset Inventory for Security - Ed Rossi - ESW #235 from 2021-07-22T21:00

Security teams relying on asset inventory from their IT counterparts can be a challenge due to a lack of security context for assets. This gap can lead to missed opportunities to identify and fi...

Listen
Paul's Security Weekly TV
Your Security Is ALWAYS in Scope, Part 2 - Joseph Kirkpatrick - SCW #80 from 2021-07-22T09:00

Our client was using a hosted service to perform remote monitoring and management and resisted its inclusion in the audit scope. The vendor's external scans revealed critical vulnerabilities. Pr...

Listen
Paul's Security Weekly TV
Your Security Is ALWAYS in Scope, Part 1 - Joseph Kirkpatrick - SCW #80 from 2021-07-21T21:00

Our client was using a hosted service to perform remote monitoring and management and resisted its inclusion in the audit scope. The vendor's external scans revealed critical vulnerabilities. Pr...

Listen
Paul's Security Weekly TV
Know Cybersecurity & Drive Innovation Through Operational Excellence - BSW #224 from 2021-07-21T09:00

This week in the Leadership and Communications section, How much does a CEO or business leader need to know about cybersecurity, How businesses can drive innovation while delivering operational ...

Listen
Paul's Security Weekly TV
Aligning Cyber Risk to Business Risk Through Automation - Padraic O'Reilly - BSW #224 from 2021-07-20T21:00

In light of recent events and the pressures of the digital world, the landscape is finally shifting towards risk. The opportunity for cyber risk profiling, standardization, and seamless collabor...

Listen
Paul's Security Weekly TV
Code Comments, Decision Trees, Windows Hello, Telegram Analysis, & Cloud Risks - ASW #158 from 2021-07-20T09:00

This week in the AppSec News: Security from code comments, visualizing decision trees, bypassing Windows Hello, security analysis of Telegram, paying for patient bug bounty programs, cloud risks...

Listen
Paul's Security Weekly TV
The Role of Open Source in DevSecOps - David DeSanto - ASW #158 from 2021-07-19T21:00

In the wake of events such as the Solarwinds breach, there has been a lot of misinformation about the role of open source in DevSecOps. GitLab believes everyone benefits when everyone can contri...

Listen
Paul's Security Weekly TV
Ransomware Task Force, Year of the Linux Desktop?, & Ring Doorbell Encryption - PSW #702 from 2021-07-18T09:00

The White House announces a Ransomware Task Force, how much money Microsoft has paid out to security researchers last year, Amazon rolls out encryption for Ring doorbells, how a backdoor in popu...

Listen
Paul's Security Weekly TV
The Journey from Network Security Engineer to Podcast Host - Jack Rhysider - PSW #702 from 2021-07-17T21:00

In this segment of Paul's Security Weekly, Paul and crew interview Jack Rhysider about how he got his start in Information Security, the projects and careers he worked on over the years, and how...

Listen
Paul's Security Weekly TV
The BIOS Disconnect - Scott Scheferman - PSW #702 from 2021-07-17T09:00

Eclypsium researchers identified vulnerabilities affecting the BIOSConnect feature within Dell Client BIOS. This disconnect impacted 129 Dell models of consumer and business laptops, desktops, a...

Listen
Paul's Security Weekly TV
All Our Devices and Privacy on the Web - Deepika Gajaria, Scott Scheferman - ESW #234 from 2021-07-16T21:00

Against the ubiquitous backdrop of Zero Trust initiatives, we have all come to accept the motto of "Verify, then trust". Yet, here we are building an entire stack of Zero Trust enabled technolog...

Listen
Paul's Security Weekly TV
Microsoft Acquires RiskIQ, Rapid7 InsightCloudSec, & Bitdefender eXtended EDR - ESW #234 from 2021-07-16T09:00

In the Enterprise News, Contrast Security partners with Secure Code Warrior, Bandura releases the Cyber Intelligence Marketplace, Illumio beefs up zero-trust security with automated policy enfor...

Listen
Paul's Security Weekly TV
Gas South and ExtraHop- A Journey of Security Partnership - Rajiv Thomas - ESW #234 from 2021-07-15T21:00

Gas South and Extrahop have partnered to give Gas South visibility in areas of the network that are normally invisible or dark to the regular network team.

To learn more about ExtraHop, v...

Listen
Paul's Security Weekly TV
HIP, HIP, HIPAA, Part 2 - Jordan Wiseman - SCW #79 from 2021-07-15T09:00

We'll start with a brief discussion of what HIPAA and is not (e.g., it's doesn't prevent your employer from ask you about your health). Then discuss recent developments like ongoing how ransomwa...

Listen
Paul's Security Weekly TV
HIP, HIP, HIPAA, Part 1 - Jordan Wiseman - SCW #79 from 2021-07-14T21:00

We'll start with a brief discussion of what HIPAA and is not (e.g., it's doesn't prevent your employer from ask you about your health). Then discuss recent developments like ongoing how ransomwa...

Listen
Paul's Security Weekly TV
Can XDR Solve Ransomware? - Maurice Stebila - BSW #223 from 2021-07-14T09:00

Every day brings news of more breaches and ransomware attacks. Why are organizations failing to protect themselves, and what can we do to combat these cybersecurity threats? Technological advanc...

Listen
Paul's Security Weekly TV
CISO Wishes and Initiatives, Risk of Disconnect, and Cyber Insurance Rises - BSW #223 from 2021-07-13T21:00

In the Leadership and Communications section, 3 Things Every CISO Wishes You Understood, What is the BISO role and is it necessary?, Cyber insurance costs up by a third, and more!

 

<...

Listen
Paul's Security Weekly TV
Web App and API Security Needs to Be Modernized: Here’s How - Sean Leach - ASW #157 from 2021-07-13T18:17:50

The truth is, most web app and API security tools were designed for a very different era. A time before developers and security practitioners worked together, before applications were globally d...

Listen
Paul's Security Weekly TV
Password Mismanager, Trusted Types vs. DOM XSS, PrintNightmare, & Fault Injections - ASW #157 from 2021-07-13T18:17:19

In the AppSec news, a password manager makes predictable mistakes, Trusted Types terminate DOM XSS, waking up from PrintNightmare, understanding hardware fault injections.

 

Visit ...

Listen
Paul's Security Weekly TV
LinkedIn Breach, Bitcoin From Banks, PrintNightmare, & NFC Flaws in ATMs - PSW #701 from 2021-07-04T09:00

This week in the Security News: LinkedIn breach exposes user data, Why MTTR is Bad for SecOps, 3 Things Every CISO Wishes You Understood, USA as a Cyber Power, is ignorance bliss for hackers, fl...

Listen
Paul's Security Weekly TV
The Rise of Sim Swapping - Haseeb Awan - PSW #701 from 2021-07-03T21:00

80% of SIM-Swap attacks are successful. This could lead to greater financial loss and loss of social status since this is where hackers latch onto. The statistics are true and spreading like a w...

Listen
Paul's Security Weekly TV
New Security Threats Stemming from PII Online - Rob Shavell - PSW #701 from 2021-07-03T09:00

Deep dive on the data broker industry, and how new threats are stemming from the widespread availability of employee/personal information publicly for sale at data broker websites.

 

...

Listen
Paul's Security Weekly TV
MalWare Labs and Why You Should Challenge Shift-Left Testing - Mario Vuksan, Rickard Carlsson - ESW #233 from 2021-07-02T21:00

Threat hunters are under increased pressure to rapidly analyze, classify, detect and respond to malicious files. ReversingLabs is stepping forward to address these needs with its new Malware Lab...

Listen
Paul's Security Weekly TV
Noname Security, JFrog Acquires Vdoo, Micro Segmentation, & AWS Buys Wickr - ESW #233 from 2021-07-02T09:00

This week, In the Enterprise News, Atos launches thinkAI, AWS welcomes Wickr to the team, U.S. DoD approves two (ISC)² certifications as requirements for staff, JFrog to acquire Vdoo, & more! Listen

Paul's Security Weekly TV
Why DAST - from Project Management Perspective - Suha Akyuz - ESW #233 from 2021-07-01T21:00

More than 96% of software development projects fail across the globe because too many businesses rely on the legacy DevOps process which allows us to run security testing right before going to p...

Listen
Paul's Security Weekly TV
CARES Act Fraud, Paying People & Fraudsters, Part 2 - Steve Lenderman - SCW #78 from 2021-07-01T09:00

We will review how synthetics are being utilized to perpetrate pandemic related frauds in the Payroll Protection Program and Unemployment Insurance. An overview of the government programs will t...

Listen
Paul's Security Weekly TV
CARES Act Fraud, Paying People & Fraudsters, Part 1 - Steve Lenderman - SCW #78 from 2021-06-30T21:00

We will review how synthetics are being utilized to perpetrate pandemic related frauds in the Payroll Protection Program and Unemployment Insurance. An overview of the government programs will t...

Listen
Paul's Security Weekly TV
Boardroom Perspectives, Greater Business Understanding, & Preventing Burnout - BSW #222 from 2021-06-30T09:00

In the Leadership and Communications section: Cybersecurity today requires greater digital and business understanding, 12 skills business continuity managers need to succeed, SOC burnout is real...

Listen
Paul's Security Weekly TV
The Year of Hybrid - Jim Richberg - BSW #222 from 2021-06-29T21:00

For the private sector and government alike, 2021 is proving to be a year of transition and refocused activity. A year of hybrid activity - from cyber threats to IT approaches.

Segment Re...

Listen
Paul's Security Weekly TV
Semgrep, Microsoft Signs With Rootkits, ATT&CK/D3FEND, & Injured Android - ASW #156 from 2021-06-29T09:00

This week in the AppSec News: Visual Studio Code's Workplace Trust, Injured Android an insecure mobile app, Microsoft accidentally signed driver with rootkits, The NSA funds a new sister Matrix ...

Listen
Paul's Security Weekly TV
Scaling Your Application Security Program - Clint Gibler - ASW #156 from 2021-06-28T21:00

In this segment with Clint Gibler, learn:

* Why secure defaults are higher ROI than finding vulnerabilities

* How modern AppSec teams are working with their engineering counterpart...

Listen
Paul's Security Weekly TV
Thermostat Hijacking, MA Androids, Windows 11, Hacking Pelotons, & John McAfee - PSW #700 from 2021-06-27T09:00

In the Security News for this week Paul and the crew talk: Windows 11, Drive-by RCE, Cookies for sale, McAfee has passed away, 30 Million Dell Devices at risk, & more!

 

Visit Listen

Paul's Security Weekly TV
CFAA: Recent US Supreme Court Case Van Buren v. US - Thomas Lonardo - PSW #700 from 2021-06-26T21:00

Brief history and purpose of the CFAA. Discussion of the majority and dissenting "Van Buren" opinion. Implications for the computer forensic and security profession.

Segment Resources: Listen

Paul's Security Weekly TV
Career Pathing and Advice From Offensive Security - Jim O'Gorman - PSW #700 from 2021-06-26T09:00

Offensive Security expert Jim O'Gorman talks through his own career progression and training, revealing what it takes to be successful in infosec. He also covers key learning tracks and gives co...

Listen
Paul's Security Weekly TV
SentinelOne IPO, Cloudflare Integrations, D3FEND, & Rumble Network Discovery - ESW #232 from 2021-06-25T21:00

This week In the Enterprise News: Smoothwall Acquires eSafe Global, LookingGlass Cyber Announces Acquisition of AlphaWave, Vectra Launches Detect for AWS, SentinelOne announces IPO, & Building a...

Listen
Paul's Security Weekly TV
How Teams Can Reduce the Visibility Gap - Brendon Macaraeg - ESW #232 from 2021-06-25T09:00

Security is a shared responsibility, but teams need to know what’s really going on in production with their web apps and APIs, as it’s happening, in order to achieve the reliable security that c...

Listen
Paul's Security Weekly TV
How Criminals Use Cloud Apps to Inject Chaos Into Work Environments - Doni Brass - ESW #232 from 2021-06-24T21:00

In 2020, cyber criminals used cloud apps, the cover of a pandemic, and a newly embraced work-from-home culture to serve up ransomware, steal data, and disrupt how companies do business. The year...

Listen
Paul's Security Weekly TV
Value & Importance of Cybersecurity Certification for Professionals, Part 2 - Casey Marks - SCW #77 from 2021-06-24T09:00

Join Dr. Casey Marks' discussion of the merits of cybersecurity certification and learn whether and how it provides training or proves experience or both, the pros and cons, how to start or appr...

Listen
Paul's Security Weekly TV
Value & Importance of Cybersecurity Certification for Professionals, Part 1 - Casey Marks - SCW #77 from 2021-06-23T21:00

Join Dr. Casey Marks' discussion of the merits of cybersecurity certification and learn whether and how it provides training or proves experience or both, the pros and cons, how to start or appr...

Listen
Paul's Security Weekly TV
CIO Succession, Hidden Costs, 10 Leadership Habits, & 5 Key Ingredients - BSW #221 from 2021-06-23T09:00

This week, In the Leadership and Communications section, What is the hidden cost of maintaining legacy systems?, 10 Leadership Habits of Highly Effective Leaders, 5 Key Ingredients to Finding Sa...

Listen
Paul's Security Weekly TV
Making the Case for Supply Chain Behavior Transparency - Ben Higgins, Ted Driggs - BSW #221 from 2021-06-22T21:00

The Biden Cyber Executive Order includes a Software Bill of Materials that is a critical and necessary first measure for protecting the software supply chain. To defend against cyber attacks, su...

Listen
Paul's Security Weekly TV
Supply Chain Integrity, Format Strings, Systemd Bug, Instagram Bounty, & Refactoring - ASW #155 from 2021-06-22T09:00

This week in the AppSec Weekly News John and Mike discuss: SLSA framework for supply chain integrity, Wi-Fi network of doom for iPhones, seven-year old systemd privesc, $30K for an API call, Cod...

Listen
Paul's Security Weekly TV
Challenges of DAST Scanners / Adoption by Developers - Nuno Loureiro, Tiago Mendo - ASW #155 from 2021-06-21T21:00

What are some of the DAST scanners challenges, like coverage of modern apps, point & shoot, scan time, partial scans, or scanning at scale? What do developers look for in a DAST scanner?

...

Listen
Paul's Security Weekly TV
Web Cache Poisoning - Timur Guvenkaya - PSW #699 from 2021-06-21T16:53:26

This presentation will cover how incorrect implementation of caching mechanism within web application might lead to the Web Cache Poisoning vulnerability that can potentially affect all the user...

Listen
Paul's Security Weekly TV
"Eavesdropping Cameras", Ransomware Poll Results, Windows 11, & CVS Records Leak - PSW #699 from 2021-06-19T21:00

This week in the Security News: Jeff, Larry, & Doug adjust to our Adrian Overlord! Ransomware galore, Ransomware Poll Results, Windows 11 & Windows 10's End-Of-Life, Drones that hunt for human s...

Listen
Paul's Security Weekly TV
Avoiding the Silo: Bridging the Divide Between Security + Dev Teams - Brian Joe - PSW #699 from 2021-06-19T09:00

Too often, developers and security teams have a siloed relationship. That separation can lead to inefficiencies and gaps in security across software development, ultimately leading to anything f...

Listen
Paul's Security Weekly TV
Tanium for Incidents. How the Best Defense Gets Better: Part 1 - ESW #231 from 2021-06-18T21:00

Security starts before detection, it starts before investigations. Mature security teams understand the importance of good hygiene and take proactive measures to secure themselves against the ev...

Listen
Paul's Security Weekly TV
RSA Outseer, Elisity Zero Trust, Contrast Scan, & SOAR Soup - ESW #231 from 2021-06-18T09:00

This week, In the Enterprise News Paul and the crew talk: Zero trust networking startup Elisity raises $26M , Contrast Security Launches Contrast Scan, Vectra Launches Detect for AWS, SOAR Is an...

Listen
Paul's Security Weekly TV
Open Source Enterprise Communication Security - Ian Tien - ESW #231 from 2021-06-17T21:00

Data security is more important than ever for enterprise organizations -- but in a time where data breaches have become common, it's also more challenging than ever. Mattermost co-founder and CE...

Listen
Paul's Security Weekly TV
Security Training, Evangelism, & Community Building, Part 2 - Danny Akacki - SCW #76 from 2021-06-17T09:00

Join this segment with Danny Akacki to learn about educating both practitioners and executives on security topics of the day and helping to build community initiatives like trust groups and comm...

Listen
Paul's Security Weekly TV
Security Training, Evangelism, & Community Building, Part 1 - Danny Akacki - SCW #76 from 2021-06-16T21:00

Join this segment with Danny Akacki to learn about educating both practitioners and executives on security topics of the day and helping to build community initiatives like trust groups and comm...

Listen
Paul's Security Weekly TV
Cliché Self-Help, RockYou2021, "Productive Procrastinators", & Attracting Talent - BSW #220 from 2021-06-16T09:00

This week, In the Leadership & Communications articles: Attracting Talent During a Worker Shortage, CISOs Say Application Security is Broken, Three Steps to Harden Your Active Directory in Light...

Listen
Paul's Security Weekly TV
Securing User Connections to Applications - Jonny Noble - BSW #220 from 2021-06-15T21:00

Are Secure Web Gateways doing their job to keep businesses safe in 2021? Recent survey results from ESG reveal 1 in 10 are not happy with their secure web gateway (SWG) and/or web security. Yet ...

Listen
Paul's Security Weekly TV
ALPACA, EA Breach, sprintf Lives, Go Fuzzing, K8s Goat, & OT Basics - ASW #154 from 2021-06-15T09:00

This week in the AppSec News, Mike and John talk: ALPACA surveys protocol confusion, lessons from the EA breach, forgotten lessons about sprintf, Go fuzzing goes beta, security lessons from Kube...

Listen
Paul's Security Weekly TV
OWASP SAMM - Software Assurance Maturity Model - Sebastian Deleersnyder - ASW #154 from 2021-06-14T21:00

We will provide a short introduction to OWASP SAMM, which is a flagship OWASP project allowing organizations to bootstrap and iteratively improve their secure software practice in a measurable w...

Listen
Paul's Security Weekly TV
ANOM Bust, Ransomware Solutions, NAC, & A PCI Deathmatch! - PSW #698 from 2021-06-13T09:00

This week, In the Security News Paul & the crew discuss: Microsoft Patches 6 Zero-Days Under Active Attack, US seizes $2.3 million Colonial Pipeline paid to ransomware attackers, the largest pas...

Listen
Paul's Security Weekly TV
Protecting the Attack Surface - Rob Gurzeev - PSW #698 from 2021-06-12T21:00

What does it mean to protect the attack surface? What's the difference between attack surface protection vs. attack surface management? Rob Gurzeev, CEO and Founder at Cycognito, joins us to dis...

Listen
Paul's Security Weekly TV
OpenWRT for Enterprise and Labs - Gene Erik - PSW #698 from 2021-06-12T09:00

OpenWRT is a mature and well supported project. It is supported on many hardware platforms and available as production-level products. OpenWRT has developed into a platform that is filled with e...

Listen
Paul's Security Weekly TV
BTS of the Cyber Fight and Building a Resilient Web App Security Program - ESW #230 from 2021-06-11T21:00

“Behind the scenes of the cyber fight” – talking about the good on the defender side, taking down cyber criminal supply chains, partnerships, taking down ransomware gangs.

This segment is...

Listen
Paul's Security Weekly TV
FireEye 'Fire Sale', Panaseer Security Guidance, & Infoblox 3.0 - ESW #230 from 2021-06-11T09:00

This week in the Enterprise News: Proofpoint unveils people-centric innovations across its three platforms, Citrix Secure Internet Access Simplifies Hybrid Workforce Challenges, CyberArk : Advan...

Listen
Paul's Security Weekly TV
Redefining SaaS Security so SOC/IR Teams Aren’t in the Dark - Stephen Newman - ESW #230 from 2021-06-10T21:00

Traditional options of acquiring network detection and response (NDR) solutions have their individual pros and cons. SaaS or On-Premises NDR solutions allow you to customize it to your environme...

Listen
Paul's Security Weekly TV
CMMC Program and the DIB Preparation, Part 2 - Doug Landoll - SCW #75 from 2021-06-10T09:00

Doing business with the Federal government has always had its share of requirements and regulations, especially when it comes to storing, processing, or transmitting any sensitive data. In fact,...

Listen
Paul's Security Weekly TV
CMMC Program and the DIB Preparation, Part 1 - Doug Landoll - SCW #75 from 2021-06-09T21:00

Doing business with the Federal government has always had its share of requirements and regulations, especially when it comes to storing, processing, or transmitting any sensitive data. In fact,...

Listen
Paul's Security Weekly TV
3 Ways + 4 Measures + 5 Approaches + 5 Myths = 17 Questions - BSW #219 from 2021-06-09T09:00

In the Leadership and Communications section, 3 Effective Ways To Improve Your Internal Communication To Boost Employee Engagement, 4 Immediate Measures to Execute After a Cyberattack, 17 cyber ...

Listen
Paul's Security Weekly TV
Optimize Buying Criteria to Ensure Success of Your New Security Tools - Travis Isaacson - BSW #219 from 2021-06-08T21:00

CISOs know the power of security as a driver of business, but other stakeholders often equate security with compliance. Security shouldn’t be viewed as a controlling organ - then it will stall i...

Listen
Paul's Security Weekly TV
HTTP Goes QUIC, Security & Humans, Amazon Sidewalk Privacy, & Product Abuse - ASW #153 from 2021-06-08T09:00

This week in the AppSec News, Tyler Robinson joins Mike & John to discuss: HTTP/3 and QUIC, bounties for product abuse, Amazon Sidewalk security & privacy, security & human behavior, authenticat...

Listen
Paul's Security Weekly TV
API Security: Understanding Threats to Better Protect Your Organization - Daniel Hampton - ASW #153 from 2021-06-07T21:00

While web application security is a highly researched topic with a lot of subject familiarity among security professionals, it’s still not easy for security and development teams to navigate mod...

Listen
Paul's Security Weekly TV
CFAA Ruling, Amazon Sidewalk, Agile Security Testing, & WordPress Plugins - PSW #697 from 2021-06-06T09:00

This week In the Security News, Paul and the Crew talk: Establishing Confidence in IoT Device Security: How do we get there?, JBS hack latest escalation of Russia-based aggression ahead of June ...

Listen
Paul's Security Weekly TV
Digital Transformation's Impact On IT Asset Visibility - Sumedh Thakar - PSW #697 from 2021-06-05T21:00

Over the past year, organizations have rapidly accelerated their digital transformation by leveraging technologies such as cloud and container that support the shift to IoT and a remote workforc...

Listen
Paul's Security Weekly TV
Attack Surface Discovery and Enumeration - Dan Tentler - PSW #697 from 2021-06-05T09:00

We've let the compliance world drive security for so long there are folks that literally have no idea what 'reasonably secure' looks or feels like because they've never seen it before.

 <...

Listen
Paul's Security Weekly TV
M1 Chip Flaw, Boeing 747 Hacking, Don't Blame the Intern, & John Deere - PSW #696 from 2021-05-30T09:00

This week in the Security Weekly News, Paul and the Crew Talk: Nagios exploits, hacking a Boeing 747, bypass container image scanning, unpatchable new vulnerability in Apple M1 chips, stop blami...

Listen
Paul's Security Weekly TV
Cybersecurity Canon - Rick Howard - PSW #696 from 2021-05-29T21:00

Rick Howard joins to talk about his Cybersecurity Canon project, the rock and roll hall of fame for Cybersecurity literature! The Cybersecurity Canon Committee has announced it's hall of winners...

Listen
Paul's Security Weekly TV
Polarity’s Power-up Sessions, Add an Ability in 15 Minutes - Paul Battista - PSW #696 from 2021-05-29T09:00

Training is critical but it is tough to break away from the day to day. Polarity is running free 15 minute training sessions that leverage our community edition to leave you with a new ability t...

Listen
Paul's Security Weekly TV
Metrics, Training, Culture & Cloud Security Resilience - Drew Rose, Ganesh Pai - ESW #229 from 2021-05-28T21:00

Metrics, Training, Culture – Why Your Phishing Program Isn’t Working - Drew Rose, Living Security Phishing reports have become the standard for measuring security awareness, and yet breaches kee...

Listen
Paul's Security Weekly TV
AWS Lambda New Features, ServiceNow Integration, & Zscaler Acquires Smokescreen - ESW #229 from 2021-05-28T09:00

This week in the Enterprise News, Paul and the Crew talk: Secure and monitor AWS Lamba with new, not related, features from Datadog and Imperva, ServiceNow integrates with Microsoft solutions, S...

Listen
Paul's Security Weekly TV
Down With SIEM, Long Live SOAR! - Nathan Hunstad - ESW #229 from 2021-05-27T21:00

SIEM tools have been the bedrock of Security Operation Centers, or SOCs, for much of the history of modern security. That does not mean that they are loved: most SIEM tools are overwrought, comp...

Listen
Paul's Security Weekly TV
SBOM, Part 2 - Allan Friedman - SCW #74 from 2021-05-27T09:00

What is SBOM? Who needs to think about this? Is this required today, and what might the future of compliance look like? What is in the recent EO?

Segment Resources:

ntia.gov/SBOM Listen

Paul's Security Weekly TV
SBOM, Part 1 - Allan Friedman - SCW #74 from 2021-05-26T21:00

What is SBOM? Who needs to think about this? Is this required today, and what might the future of compliance look like? What is in the recent EO?

Segment Resources:

ntia.gov/SBOM Listen

Paul's Security Weekly TV
CISOs Struggle to Cope, Cybersecurity Metrics, & Security by Design - BSW #218 from 2021-05-26T09:00

This week, in the Leadership and Communications section, CISOs Struggle to Cope with Mounting Job Stress, Corporate Compliance Strategies to Protect Data, Cybersecurity Metrics That Matter, and ...

Listen
Paul's Security Weekly TV
Simplify & Accelerate Patch Management - Chris Hallenbeck - BSW #218 from 2021-05-25T21:00

Most people focus on the patch, check that box but they forget the other side of the coin. How do they make sure a bad actor isn't still in their network?

Segment Resources:

Listen

Paul's Security Weekly TV
IIS Bug, Browsers & Androids & Supply Chains Oh My! - ASW #152 from 2021-05-25T09:00

This week in the AppSec News segment, Mike and John talk: HTTP bug bothers IIS, Android platform security, supply chain security (new and old), brief (very brief) history of browser security, & ...

Listen
Paul's Security Weekly TV
Bringing AppSec to a Modern CI Pipeline - Manish Gupta - ASW #152 from 2021-05-24T21:00

Appsec in a modern CI pipeline needs a combination of tools, collaboration, and processes to be successful. Importantly, it also needs to scale. We can't just shift responsibility left and assum...

Listen
Paul's Security Weekly TV
21 Nails: Behind the Scenes Discussion of Qualys Exim Vulnerability Discovery - Wheel - PSW #695 from 2021-05-22T09:00

Join Qualys researcher Wheel for a discussion on the team's recent discovery and disclosure of multiple critical vulnerabilities in the Exim mail server. This includes discussion of the vulnerab...

Listen
Paul's Security Weekly TV
Five by Five: Why the Cyber Defense Matrix Gets Great Reception - PSW #695 from 2021-05-21T21:00

Five years after Sounil Yu originally introduced the Cyber Defense Matrix at the 2016 RSA conference, he just wrapped up the third workshop based on the framework. CDM has its own website, is an...

Listen
Paul's Security Weekly TV
Building a Response Strategy to Advanced Threats - Mark Bowling - ESW #228 from 2021-05-21T09:00

SolarWinds SUNBURST was a rude awakening for many security teams, and it won't be the last time security leaders face tough questions about how an adversary evaded defenses and stayed hidden. Wi...

Listen
Paul's Security Weekly TV
Unplugging the Internet, Diversity, Cyber NTSB, & Best Practices - PSW #695 from 2021-05-21T09:00

This week in the Security News: Is the cyber NTSB a good thing?, Russian virtual keyboard for the win, information should be free, hang on while I unplug the Internet, security MUST be taken ser...

Listen
Paul's Security Weekly TV
All the News From RSA Conference 2021 - ESW #228 from 2021-05-20T21:00

The Enterprise Security Weekly crew summarizes all the news from RSA Conference 2021, including product announcement, acquisitions, funding, and more!

 

Visit Listen

Paul's Security Weekly TV
Identity Management as a Foundation for Future-Proofing your Security - John Masserini - ESW #228 from 2021-05-20T09:00

The perimeter is dissolving. Employees are using any device from any location for work. With limited visibility from our traditional networking and endpoint security controls, how do we protect ...

Listen
Paul's Security Weekly TV
Building a Unified Security Fabric - Johnathan Nguyen-Duy - BSW #217 from 2021-05-19T21:00

What is top of mind for CISOs in a year where cyber threats are getting sophisticated? Cross platform and cross domain visibility across LAN, WAN, Cloud, and Edge. Jonathan Nguyen-Duy, Vice Pres...

Listen
Paul's Security Weekly TV
Unified BCDR: Why Backup Alone is No Longer Enough - Joseph Noonan - BSW #217 from 2021-05-19T09:00

Data is the lifeblood of business, but now lives in more places than ever before (data centers, endpoints of remote workers, in multiple clouds, and SaaS applications), is time-consuming to mana...

Listen
Paul's Security Weekly TV
Third Party Software Risk on the Web - Aanand Krishnan - ASW #151 from 2021-05-18T09:00

Web applications are highly dependent on third party content and JavaScript. This creates a significant set of vulnerabilities that attackers are exploiting. How do you prevent a Solarwinds type...

Listen
Paul's Security Weekly TV
CNCF Supply Chain, Frag Attacks, Securing Webhooks, & Complexity vs. Security - ASW #151 from 2021-05-18T09:00

CNCF releases a whitepaper on supply chain security, Frag attacks against WiFi devices, security webhooks, trusting terraform plans, shared credentials and app access, complexity vs. security vs...

Listen
Paul's Security Weekly TV
Executive Order, New & Old Wifi Vulns, Pipeline Hack, & Distro-Less Linux - PSW #694 from 2021-05-16T09:00

This week in the Security News: President Biden issues a 34-page executive order on Cybersecurity, Did you hear about the pipeline hack?, New/Old Wifi vulnerabilities, get this Apple didn't want...

Listen
Paul's Security Weekly TV
Attack Surface Mapping w/ AMASS - PSW #694 from 2021-05-15T21:00

Learn how to use Amass to collect information about your Internet exposed assets. We'll cover usage of the configuration file (heavily), then put it altogether by integrating Nmap and a screensh...

Listen
Paul's Security Weekly TV
How Hacking Naked Changed My Life - Alex Chaveriat - PSW #694 from 2021-05-15T09:00

"I hack naked" - Not my best choice of a phrase to use with a prospective client though, now that it is done, might as well go through with this terrible idea... This is the story of a kick-off ...

Listen
Paul's Security Weekly TV
Accurics Terrascan, Sophos XDR Solution, & API Security Need to Know - ESW #227 from 2021-05-14T21:00

This week in the Enterprise News: XM Cyber Announces Integration with Palo Alto Network's Cortex XSOAR, API Security Lessons Learned, Cycode Raises $20 Million, HelpSystems Acquires Beyond Secur...

Listen
Paul's Security Weekly TV
Chart Topping Threats – How Attacks will Rage in 2021 - Artsiom Holub, Austin McBride - ESW #227 from 2021-05-14T09:00

Cyberattackers have not been slowed down by the worldwide pandemic. Phishing, cryptojacking, and trojans all continue to dominate the cybersecurity threat charts. It’s critical to know what secu...

Listen
Paul's Security Weekly TV
Florida Water Treatment Facility Hack, and the Convergence of OT & IT - Damon Small - ESW #227 from 2021-05-13T21:00

What lessons can others still learn from the attack on the Florida water treatment facility? How does this incident shine a light on cybersecurity risks associated with the convergence of OT and...

Listen
Paul's Security Weekly TV
Hot Legal Topics in Privacy and Cybersecurity, Part 2 - Erik Weinick - SCW #73 from 2021-05-13T09:00

A flurry of legislative and legal activity is re-shaping the way privacy and cybersecurity professionals conduct business. As a result, in addition to actually carrying out their protection resp...

Listen
Paul's Security Weekly TV
Hot Legal Topics in Privacy and Cybersecurity, Part 1 - Erik Weinick - SCW #73 from 2021-05-12T21:00

A flurry of legislative and legal activity is re-shaping the way privacy and cybersecurity professionals conduct business. As a result, in addition to actually carrying out their protection resp...

Listen
Paul's Security Weekly TV
6 Ways to Engage, 5 Key Qualities of CISOs, & 4 Actions Leader Take - BSW #216 from 2021-05-12T09:00

In the Leadership and Communications section, 6 ways to spur cybersecurity board engagement, 5 key qualities of successful CISOs, and how to develop them, 4 Actions Transformational Leaders Take...

Listen
Paul's Security Weekly TV
The Lost Year: The Impact of the Pandemic on Web App Security - Ryan Bergquist - BSW #216 from 2021-05-11T21:00

The shift away from web application security, caused by the pandemic and the focus on remote workforces, resulted in an increased number of web vulnerabilities, as shown in the latest Acunetix b...

Listen
Paul's Security Weekly TV
AirTags & Threat Models, Qualcomm Modem Vuln, Exim RCE(s), & Binary Hardening - ASW #150 from 2021-05-11T09:00

This Week in the AppSec News, Mike and John talk: "Find My threat model" with AirTags, Qualcomm modem vuln hits lots of Android, an Exim update patches lots of vulns, measuring hardened binaries...

Listen
Paul's Security Weekly TV
Delivering On the Promise of Application Security - Ankur Shah - ASW #150 from 2021-05-10T21:00

While the vision for app security is relatively clear, executing on that vision is still somewhat of a work in progress. Fast-moving, interdependent pieces—custom code and open source packages, ...

Listen
Paul's Security Weekly TV
Job Expectations, Pi Password Thief, Python Masscan, & Pingback - PSW #693 from 2021-05-09T09:00

This week in the Security Weekly News the crew talks: Pingback is back, was it ever really gone?, damn QNAP ransomeware, anti-anti-porn software, Qualcomm vulnerabilities, spreading pandas on Di...

Listen
Paul's Security Weekly TV
Biden Administration EO on Cyber - Jim Langevin - PSW #693 from 2021-05-08T21:00

US Congressman Jim Langevin joins to talk about Executive Orders, International Interest in Cyber, & more in this gripping interview!

 

Visit Listen

Paul's Security Weekly TV
Building a Risk-Based Vulnerability Management Program - Bob Erdman - PSW #693 from 2021-05-08T09:00

Risk-based vulnerability management is more than just a vulnerability scan or assessment. It incorporates relevant risk context and analysis to prioritize the vulnerabilities that pose the great...

Listen
Paul's Security Weekly TV
JupiterOne, Signal Ad Banned, Series F Funding, & Imperva Acquires CloudVector - ESW #226 from 2021-05-07T21:00

This week in the Enterprise Security News: Code42 enhances Incydr to help identify insider risk related to file uploads to unsanctioned websites, Imperva acquires CloudVector to provide visibili...

Listen
Paul's Security Weekly TV
The Rise of the SBOM - Steve Springett - ESW #226 from 2021-05-06T21:00

Software Bill of Materials (SBOM) are used to describe the list of ingredients for the software that organizations create or acquire. There's a rapidly expanding community of adopters, implement...

Listen
Paul's Security Weekly TV
Applications Are Your Lifeblood - Carlos Morales - ESW #226 from 2021-05-06T21:00

Web applications have never been more critical to your business. Yet, the everchanging threat landscape, from the move towards the cloud, to the explosion of devices on the internet, to the effe...

Listen
Paul's Security Weekly TV
Data Security Compliance & Virginia’s New Privacy Law, Part 2 - Chris Pin - SCW #72 from 2021-05-06T09:00

Just last month, Virginia became the second state in the U.S. to pass a privacy law – the Consumer Data Protection Act (CDPA). While this doesn’t take effect until 2023, it’s important for busin...

Listen
Paul's Security Weekly TV
Security Money - The Index is Still Going Strong - BSW #215 from 2021-05-05T21:00

This week, it's my favorite segment, Security Money, where we update you on the latest security funding and performance of the public market. The Security Weekly 25 index is still going strong.<...

Listen
Paul's Security Weekly TV
Data Security Compliance & Virginia’s New Privacy Law, Part 1 - Chris Pin - SCW #72 from 2021-05-05T21:00

Just last month, Virginia became the second state in the U.S. to pass a privacy law – the Consumer Data Protection Act (CDPA). While this doesn’t take effect until 2023, it’s important for busin...

Listen
Paul's Security Weekly TV
The Benefits of CISO Peer-to-Peer Networks - Graham Keavney - BSW #215 from 2021-05-04T21:00

Graham Keavney, President at Cybersecurity Collaboration Forum, joins us to provide an overview of the Cybersecurity Collaboration Forum and the benefits of CISO peer-to-peer networks.

 <...

Listen
Paul's Security Weekly TV
BadAlloc Vulns, Gatekeeper Bypass, & More Spectre in Micro-Op Caches - ASW #149 from 2021-05-04T09:00

This week in the AppSec News: Microsoft discloses "BadAlloc" bugs, macOS Gatekeeper logic falters, authentication issues in KDCs and ADs, Spectre gains another vector, followup on the UMN Linux ...

Listen
Paul's Security Weekly TV
Why Developers Need to Think Differently About Software Security - Rey Bango - ASW #149 from 2021-05-03T21:00

Rey will be digging into the developer security training conundrum based on his own experiences with secure coding and security training. He'll cover:

• The types of security training tha...

Listen
Paul's Security Weekly TV
AirDrop Vulns, Linux Hypocrite Commits, Wi-Fi Code Execution, & We'll Miss You Dan - PSW #692 from 2021-05-02T09:00

This week in the Security News, Penetration testing leaving organizations with too many blind spots, A New PHP Composer Bug Could Enable Widespread Supply-Chain Attacks, Apple AirDrop Vulnerabil...

Listen
Paul's Security Weekly TV
Smart Building Control System Cybersecurity - The Real World - Fred Gordy - PSW #692 from 2021-05-01T21:00

Currently, in the United States, there are over 87 billion square feet of commercial real estate. Smart Building control systems pervasive throughout these buildings and helped increase efficien...

Listen
Paul's Security Weekly TV
Protecting the Hybrid Workforce - Fleming Shi - PSW #692 from 2021-05-01T09:00

Fleming will cover the vulnerabilities of a hybrid workforce and how employees are now working from anywhere, not just their homes. Zero trust will play a large part in securing workforces in th...

Listen
Paul's Security Weekly TV
Authentication vs. Authorization: Why Privileged Access Matters - Joseph Carson - ESW #225 from 2021-04-30T21:00

Authentication and authorization might sound similar, but they are two distinct security processes. Joe Carson, Chief Security Scientist at Thycotic, joins us to discuss why privileges, not iden...

Listen
Paul's Security Weekly TV
HackerOne Enhances Platform, PANW Expands Unit 42, & More Funding - ESW #225 from 2021-04-30T09:00

In the Enterprise News for this week: HackerOne Enhances Security Testing Platform, Palo Alto Networks Expands Unit 42 Cybersecurity Consulting Group, Thoma Bravo to take cyber security firm Pro...

Listen
Paul's Security Weekly TV
Collaboration Rules! Challenging Transparency in Modern App Sec - Rickard Carlsson - ESW #225 from 2021-04-29T21:00

Rickard Carlsson, CEO at Detectify, joins us to talk about collaboration as the modern approach application security. During the discussion, we'll cover: - why organizations should challenge tra...

Listen
Paul's Security Weekly TV
ATT&CK and CTID, Part 2 - Richard Struse - SCW #71 from 2021-04-29T09:00

Richard Struse, Director of The Center for Threat-Informed Defense from MITRE Engenuity joins the SCW crew for a two part interview! -What is threat-informed defense and how does it relate to ot...

Listen
Paul's Security Weekly TV
ATT&CK & CTID, Part 1 - Richard Struse - SCW #71 from 2021-04-28T21:00

Richard Struse, Director of The Center for Threat-Informed Defense from MITRE Engenuity joins the SCW crew for a two part interview! -What is threat-informed defense and how does it relate to ot...

Listen
Paul's Security Weekly TV
Outgunned CISOs, Cyberthreat Reports, & Effective Cyber Security Strategy - BSW #214 from 2021-04-28T09:00

In the Leadership and Communications section, Outgunned CISOs navigate complex obstacles to keep rising attacks from turning into breaches, How to write a cyberthreat report executives can reall...

Listen
Paul's Security Weekly TV
Cyber Accountability - Mathieu Gorge - BSW #214 from 2021-04-27T21:00

Cyber accountability is often overlooked by Board of Directors and the C-Suite. They tend to turn a blind eye to their cyber security mandates or avoid the issue. But as Solarwinds, MS Exchange ...

Listen
Paul's Security Weekly TV
Signal Aesthetics, AirDrop Privacy, Safety vs. Security, & Data Ordering Attacks - ASW #148 from 2021-04-27T09:00

This week in the AppSec News: Signal points out parsing problems, privacy preserving improvements to AirDrop, Homebrew disclosure, WhatsApp workflows, adversarial data ordering for ML, & more! Listen

Paul's Security Weekly TV
Deceptive Diffs From Subversive Submitters - ASW #148 from 2021-04-26T21:00

We start with the article about "Researchers Secretly Tried To Add Vulnerabilities to Linux Kernel, Ended Up Getting Banned" and explore its range of issues from ethics to securing huge, distrib...

Listen
Paul's Security Weekly TV
Feds Have a Busy Two Weeks, British Tween Takes On TikTok, & More Facebook Woes... - PSW #691 from 2021-04-25T09:00

This week in the Security News, U.S Formally Attributes SolarWinds Attack to Russian Intelligence Agency, FBI Clears ProxyLogon Web Shells from Hundreds of Orgs, Justice Dept. Creates Task Force...

Listen
Paul's Security Weekly TV
Encrypted Collaboration & Communication - Joel Wallenstrom - PSW #691 from 2021-04-24T21:00

This conversation will introduce Wickr to the PSW listeners. Joel Wallenstrom will discuss the importance of end-to-end encrypted collaboration and communication as it relates to enterprise and ...

Listen
Paul's Security Weekly TV
Why Now is the Time for K-12 Cybersecurity Education - Kevin Nolten - PSW #691 from 2021-04-24T09:00

With the U.S. facing a shortage of roughly 314,000 cybersecurity professionals in the workforce, according to CSIS, there is an urgent need to build cybersecurity skills and fill the workforce p...

Listen
Paul's Security Weekly TV
Darktrace & Knowbe4 IPOs, Dell Spins Off VMWare, & Zscaler Keeps Growing - ESW #224 from 2021-04-23T21:00

In the Enterprise News for this week, Darktrace targets listing for early May, KKR-backed cybersecurity firm KnowBe4 aims for $3 Billion valuation in U.S. IPO, Dell spins off VMware to fuel post...

Listen
Paul's Security Weekly TV
Stopping Phishing Breaches at the Point of Click - Chris Cleveland - ESW #224 from 2021-04-23T09:00

Phishing links are getting past existing protections and clicked. How do you prevent these attacks? In this segment, Chris Cleveland, CEO at Pixm, will demonstrate how computer vision protection...

Listen
Paul's Security Weekly TV
How Cloud Defenders Thwart Attacks Against Resilient Services - Jeff Deininger - ESW #224 from 2021-04-22T21:00

In cybersecurity attackers have a structural advantage over defenders: they can succeed with a staggeringly high failure-rate (not caring that most attacks get blocked at the perimeter). Meanwhi...

Listen
Paul's Security Weekly TV
Compliance Innovations in the Cloud, Part 2 - Chris Hughes - SCW #70 from 2021-04-22T09:00

Cloud has and continues to disrupt many traditional business processes, activities and IT paradigms. Compliance will also be revolutionized by cloud computing. In this session we will dive into ...

Listen
Paul's Security Weekly TV
Compliance Innovations in the Cloud, Part 1 - Chris Hughes - SCW #70 from 2021-04-21T21:00

Cloud has and continues to disrupt many traditional business processes, activities and IT paradigms. Compliance will also be revolutionized by cloud computing. In this session we will dive into ...

Listen
Paul's Security Weekly TV
Rust in Android, Vuln Disclosure, Postmortems, & BootHole Follow-Up - ASW #147 from 2021-04-20T09:00

This week in the AppSec News, Mike and John discuss Rust in Android and the Linux kernel, vuln disclosure policy changes from Project Zero, security and DevOps collaboration, XSS with NULL, & a ...

Listen
Paul's Security Weekly TV
Cyber-Risk Threat, 4 Steps to Better Security Hygiene, & 10 Rules for Work-Life - BSW #213 from 2021-04-20T09:00

In the Leadership and Communications section, Federal Reserve Chairman Says Cyber-Risk a Top Threat to National Economy, What Good Leaders Do When Replacing Bad Leaders, My Ten Rules for Work-Li...

Listen
Paul's Security Weekly TV
Supply Chain Management - Doug Barbin - ASW #147 from 2021-04-19T21:00

Supply chain security isn't new, despite the renewed attention from the Solar Winds attack. It has old challenges, like having an accurate asset or app inventory, and new opportunities, like Sof...

Listen
Paul's Security Weekly TV
The Hybrid Workforce: Addressing the Challenges of Work from Anywhere - Fleming Shi - BSW #213 from 2021-04-19T21:00

When the world went fully remote a year ago, many systems had to migrate from on-premise to the cloud. Now that we're starting to re-open offices, do we move these system back to on-premise or i...

Listen
Paul's Security Weekly TV
Security Awareness Culture Change, Part 2 - Kelley Bray, Stephanie Pratt - SCW #69 from 2021-04-15T09:00

We continue the discussion about the importance of effective security awareness programs and what that would actually look like. We'll also examine how to move beyond "bare minimum" check-box me...

Listen
Paul's Security Weekly TV
Security Awareness Culture Change, Part 1 - Kelley Bray, Stephanie Pratt - SCW #69 from 2021-04-14T21:00

Today we are going to take a look at security awareness training programs in organizations. We are joined to day by Kelley Bray and Stephanie Pratt who will help facilitate the discussion. We'll...

Listen
Paul's Security Weekly TV
Facebook Dump, Hacking Your Dishwasher, Zoom 0-Click Exploit, & Ubiquity Response - PSW #690 from 2021-04-11T09:00

This week in the Security News, Polish blogger sued after revealing security issue in encrypted messenger, The Facebook dump and Have I Been Pwned, LinkedIn and more_eggs, APTs targeting Fortine...

Listen
Paul's Security Weekly TV
Lessons Learned When Migrating from On Prem to Cloud - Dutch Schwartz - PSW #690 from 2021-04-10T21:00

Less than 15% of enterprise customers are primarily cloud native. With so many companies still in early stages of cloud migration, what are the key lessons learned from early adopters as well as...

Listen
Paul's Security Weekly TV
nzyme - Free & Open WiFi Defense System - Lennart Koopmann - PSW #690 from 2021-04-10T09:00

Nzyme is a new kind of WiFi IDS (WIDS) that detects adversaries by looking at hard to spoof characteristics of an attacker. Existing WIDS tend to look at extremely easy to spoof metadata like ch...

Listen
Paul's Security Weekly TV
Cybersecurity Unicorns, LogRhythm Version 7.7, Rapid7 Kubernetes Beta, & Cisco SASE - ESW #223 from 2021-04-09T21:00

This week in the Enterprise News, Cyble raises $4M, ThreatQuotient raises $22.5M, OneTrust acquires Convercent, Digital Shadows announces new threat intelligence capabilities, Rapid7 Announces K...

Listen
Paul's Security Weekly TV
Hackers Are Targeting Your Firmware. Are You Ready? - John Loucaides - ESW #223 from 2021-04-09T09:00

83% of businesses have experienced at least one firmware attack in the past two years - and yet most organizations lack visibility into this attack surface. We'll discuss why hackers are increas...

Listen
Paul's Security Weekly TV
Inbox: Zero Trust - Ryan Noon - ESW #223 from 2021-04-08T21:00

Ryan Noon joins ESW team this week to chat through the significance of recent hacks (namely: SolarWinds and Hafnium), unpack growing enterprise demand for a “digital seatbelt,” and illuminate wh...

Listen
Paul's Security Weekly TV
Information Sharing - A 360 Degree View, Part 2 - Errol Weiss - SCW #68 from 2021-04-08T09:00

Errol will talk about his experiences with information sharing and building the world's first Information Sharing & Analysis Center in 1999. Errol brings unique perspective to the table as he wa...

Listen
Paul's Security Weekly TV
Information Sharing - A 360 Degree View, Part 1 - Errol Weiss - SCW #68 from 2021-04-07T21:00

Errol will talk about his experiences with information sharing and building the world's first Information Sharing & Analysis Center in 1999. Errol brings unique perspective to the table as he wa...

Listen
Paul's Security Weekly TV
Risk Management Approach, Automation, & the Problem With Cyber Insurance - BSW #212 from 2021-04-07T09:00

In the Leadership and Communications section, Developing a Risk Management Approach to Cybersecurity, How Automation Can Protect Against Data Breaches, The Problem with Cyber Insurance: Outdated...

Listen
Paul's Security Weekly TV
Accelerating Security with Security Automation - John McClure - BSW #212 from 2021-04-06T21:00

Are you struggling with Alert Overload, Manual Processes, Multiple/Disparate Tools, Talent Shortage, and/or Budget Constraints? Of course you are! John McClure, Chief Information Security Office...

Listen
Paul's Security Weekly TV
Malicious PHP Commits, OAuth Attacks & XML Injection, & Zines For DevSecOps - ASW #146 from 2021-04-06T09:00

PHP deals with two malicious commits, SSO and OAuth attack vectors to remember for your threat models, zines for your DevSecOps education!

 

Visit Listen

Paul's Security Weekly TV
Shifting Right: What Security Engineers Can Learn From DevSecOps - Leif Dreizler - ASW #146 from 2021-04-05T21:00

The security industry generally agrees on the value of enabling developers in an agile environment—although we don't agree on what to call it… “Shifting Left,” “Creating a Paved Path,” “DevSecOp...

Listen
Paul's Security Weekly TV
Ubiquiti Breach, Tesla, PHP, & More Sagas - PSW #689 from 2021-04-04T09:00

npm netmask library has a critical bug, when AI attacks, firmware attacks on the rise, Microsoft Hololens and order 66, a real executive order 13694, The Ubiquity breach saga, the FreeBSD and wi...

Listen
Paul's Security Weekly TV
Cybersecurity Journalist - Robert Lemos - PSW #689 from 2021-04-03T21:00

Paul, and the rest of the PSW Hosts, will talk to Robert about how he got his start in InfoSec.

 

Visit https://www.securityweekly.com...

Listen
Paul's Security Weekly TV
The Intersection of Cybersecurity & Cryptocurrency - Nick Percoco - PSW #689 from 2021-04-03T09:00

With an uptick in malware scams and email compromises, the best thing we can do is educate the cryptocurrency community about risks and security best practices. Listen

Paul's Security Weekly TV
Tyler's "Deathpool", Astadia, Gigamon, & GRIMM - ESW #222 from 2021-04-02T21:00

This week in the Enterprise News: Funding announcements from Clearsense, Morphisec, Feedzai, Jumio, Ketch, Living Security, Productiv and Socure. ServiceNow acquires Intellibot, Accenture acquir...

Listen
Paul's Security Weekly TV
Why User Adoption in Enterprise Security is Low - Juliet Okafor - ESW #222 from 2021-04-02T09:00

Security technology roll-outs often fail because of the following: 1) Weak Security Culture - users don't see value or understand the importance of taking action. 2) Security teams often fail to...

Listen
Paul's Security Weekly TV
Rise of Insider Threat Post-C19 - Zack Moody - ESW #222 from 2021-04-01T21:00

Is there an emerging threat to your data post-C19 with disgruntled employees having to come back to an office? How do we protect our data and keep employees happy that have access to data from w...

Listen
Paul's Security Weekly TV
Vulnerability Management is Still a Mess - Part 2 - Rafal Los - SCW #67 from 2021-04-01T09:00

In the second segment, the SCW hosts will continue the discussion with Raf and hopefully come up with some guidance on what can be done to make vulnerability management work better.

 

...

Listen
Paul's Security Weekly TV
Vulnerability Management is Still a Mess - Part 1 - Rafal Los - SCW #67 from 2021-03-31T21:00

The SCW hosts discuss Rafal Los' recent blog post "Vulnerability Management is Still a Mess" (...

Listen
Paul's Security Weekly TV
Business Leader, CISO Skills, & Building Your Cybersecurity A-Team - BSW #211 from 2021-03-31T09:00

In the Leadership and Communications section, Being a CISO in 2021: How to Be a Business Leader in the Boardroom, Skills CISOs Need to Have in 2021, Build your cybersecurity A-team: 7 recruiting...

Listen
Paul's Security Weekly TV
How NDR Technology Helps Manage Cybersecurity Challenges - Nemi George - BSW #211 from 2021-03-30T21:00

NDR technologies such as ExtraHop are the latest tools in the CISO toolbox for combating cybersecurity threats. It enables previously unattainable speed and efficacy in detecting, identifying an...

Listen
Paul's Security Weekly TV
TikTok Analysis, Patching Patches, CI/CD Integrity, Faster Fuzzing, & Slack Safety - ASW #145 from 2021-03-30T09:00

Security and privacy technical analysis of TikTok, subtle parsing problems, chain of trust through a CI/CD pipeline, faster fuzzing even without source code, interplay of application security an...

Listen
Paul's Security Weekly TV
OWASP Top 10 of 2021 - Andrew van der Stock - ASW #145 from 2021-03-29T21:00

The OWASP Top 10 2021 is in development. A public survey has just been released. We have finished collecting data. I would like to discuss what the plans are for the OWASP Top 10 2021, and when ...

Listen
Paul's Security Weekly TV
Open Redirects - An Underestimated Vulnerability - PSW #688 from 2021-03-28T09:00

Learn what redirects are, the different types, how they work and how they are exploited by attackers. Oh, also learn how to defend against redirect attacks!

Sven's Slide Deck - Open Redir...

Listen
Paul's Security Weekly TV
DOOM Exploit, iPhone Deep Fakes, & 11 0-Days Infect Devices - PSW #688 from 2021-03-27T21:00

This week in the Security News: Doom exploit wins an award, a puzzle honors Alan Turing, anyone can create a deepfake, Jabber bugs, unquoted service paths, Nim malware, Deadly sins of secure cod...

Listen
Paul's Security Weekly TV
Taming Vulnerability Overload - Mehul Revankar - PSW #688 from 2021-03-27T09:00

Almost weekly, hackers discover and exploit vulnerabilities in popular programs like SolarWinds and Microsoft Exchange Server, impacting thousands. While it would be great to eradicate these vul...

Listen
Paul's Security Weekly TV
Axis Security, Qualys, VMware, NFTs, & Linksys/Fortinet - ESW #221 from 2021-03-26T21:00

This week in the Enterprise News, Funding announcements from Security Scorecard, Secureframe, Axis Security, Orca, Cylera, and Vulcan Cyber. A non-funding announcement from Thinkst. Fortinet aqu...

Listen
Paul's Security Weekly TV
"Jump-Start Your SOC Analyst Career" - Jarrett Rodrick - ESW #221 from 2021-03-26T09:00

Jarrett Rodrick and Tyler Wall's new book, "Jump-start Your SOC Analyst Career," is meant to serve as a roadmap for those who wish to take their first steps into cyber security/SOC analyst. We d...

Listen
Paul's Security Weekly TV
Platform Security - PaaS & Hosting - Trey Ford - ESW #221 from 2021-03-25T21:00

- What security features does Heroku offer that the customer can control and how have these evolved over time? - How do you balance the security of the application, with the security of the depl...

Listen
Paul's Security Weekly TV
PlexTrac Talks PCI, Part 2 - Dan DeCloss, Shawn Scott - SCW #66 from 2021-03-25T09:00

The conversation continues as the PlexTrac team, Dan DeCloss & Shawn Scott, demonstrate how PlexTrac can tackle compliance (among other things)!

 

Visit Listen

Paul's Security Weekly TV
PlexTrac Talks PCI, Part 1 - Dan DeCloss, Shawn Scott - SCW #66 from 2021-03-24T21:00

This week, Jeff, Liam Downward, Scott, & Josh talk PCI with Dan DeCloss and Shawn Scott from PlexTrac!

 

Visit https://www.securitywee...

Listen
Paul's Security Weekly TV
Dictionary Attacks, SASE Misinformation, & 3 Key Tasks - BSW #210 from 2021-03-24T09:00

In the Leadership and Communication Segment, 5 Reasons Why Cybersecurity Should Be A Priority While Planning Your Business, 3 Key Tasks That Help Me Work Way Less and Accomplish More, Everything...

Listen
Paul's Security Weekly TV
Medical Device Secure Development Lifecycle - Christopher Gates - BSW #210 from 2021-03-23T21:00

How to incorporate security into your existing medical device development process, What artifacts need to be created, & Security activities that are new.

 

Visit Listen

Paul's Security Weekly TV
Supply Chains in Azure SDK/Xcode, GitHub Sessions, & GCP VRP - ASW #144 from 2021-03-23T09:00

In the AppSec News: Supply chain security in Azure SDK and macOS Xcode, GitHub's postmortem on a session handling flaw, six GCP vulns from 2020, & information resources for hacking the cloud! Listen

Paul's Security Weekly TV
Approaching AppSec Like a Hacker - Johanna Ydergard, Roberto Giachetta - ASW #144 from 2021-03-22T21:00

Security is struggling to keep up with securing modern web applications and the fast pace of wild web hacks. Detectify is building automated app scanners that can think like a hacker and shorten...

Listen
Paul's Security Weekly TV
Plextrac Mini-Series Episode 1: Purple Teaming - Bryson Bort - PSW #687 from 2021-03-21T09:00

The first episode of Security Weekly's podcast mini-series with PlexTrac "Getting the Real Work Done in Cybersecurity" starts with PlexTrac's bread and butter, Purple Teaming! The group - along ...

Listen
Paul's Security Weekly TV
Security Grades, Mirai, Quantum Cryptography, & Hacking "Beer" - PSW #687 from 2021-03-20T21:00

In the Security News, If software got a security grade, most would get an F, SolarWinds hackers got some source code, new old bugs in the Linux kernel, hack stuff and get blown up, stop hacking ...

Listen
Paul's Security Weekly TV
Getting The Real Work Done With Plextrac - Dan DeCloss - PSW #687 from 2021-03-20T09:00

Dan will run through some customer testimonials on how they are using Plextrac effectively to get the real work done in security! This segment is sponsored by PlexTrac.

 

Visit Listen

Paul's Security Weekly TV
Attack Surface - What are we Missing? - Ilia Kolochenko - ESW #220 from 2021-03-19T21:00

Ilia Kolochenko, founder of ImmuniWeb, joins Paul and Adrian to discuss the challenge of discovering and handling exposed data and vulnerabilities before the bad guys do.

 

Visit <...

Listen
Paul's Security Weekly TV
ARM Support, Cyber "SPAC", Cyber Fusion, Docker, & Beer Outage - ESW #220 from 2021-03-19T09:00

This week in the Enterprise Security News: funding announcements from Coalition, HeraSoft, Cowbell Cyber, Argon, Cynet, Docker, and Cyware. Sonatype Acquires MuseDev, Sumologic Acquires DF Labs,...

Listen
Paul's Security Weekly TV
Investing In Cybersecurity - Ron Gula - ESW #220 from 2021-03-18T21:00

Ron joins us to cover various aspects of investing, including how to give the right pitch, what enterprises should be looking for in new technologies, are you 5% or amazing tech? Ron is also cha...

Listen
Paul's Security Weekly TV
Security & Compliance Legal Highlights - Part Deux - SCW #65 from 2021-03-18T09:00

We're letting Priya have the bulk of the time to discuss what's on her mind in terms of legal implications of security & compliance news and events.

 

Visit Listen

Paul's Security Weekly TV
Security & Compliance Legal Highlights - SCW #65 from 2021-03-17T21:00

We're excited to have Priya Chaudry with us today, so we are going to focus our discussion on news and events with legal implications (or the legal implications of news and events)! For starters...

Listen
Paul's Security Weekly TV
Importance of Culture, Engaging The Board, & 8 New Roles! - BSW #209 from 2021-03-17T09:00

This week, in the Leadership and Communications section, The importance of culture in digital transformation, 4 ways to keep the cybersecurity conversation going after the crisis has passed, 8 n...

Listen
Paul's Security Weekly TV
The Nine Cybersecurity Habits - George Finney - BSW #209 from 2021-03-16T21:00

In 1989, Stephen Covey first published "The 7 Habits of Highly Effective People," empowering and inspiring leaders for over 25 years. Is there an equivalent or new set of habits for CISOs? Georg...

Listen
Paul's Security Weekly TV
Unauth'd RCE, "Regexploits", Post-Spectre Web, & SigStore Signing - ASW #143 from 2021-03-16T09:00

Software safety to mitigate the impact of unauthenticated RCEs, exploding regex patterns, web and browser security in the face of Spectre side-channels, signing software artifacts, 8 roles for t...

Listen
Paul's Security Weekly TV
Cloud Native Security Platforms - John Morello - ASW #143 from 2021-03-15T21:25:33

Modern appsec demonstrates the importance of a cloud native strategy for enterprise security and how much that strategy must integrate with DevOps tools and workflows. Security solutions need to...

Listen
Paul's Security Weekly TV
Ransomware Research, Threats, and Futures - Assaf Dahan - PSW #686 from 2021-03-14T10:00

Assaf Dahan, Sr Director, Head of Threat Research at Cybereason, discusses current trends in ransomware research. What happens when we're not watching or watching the wrong indicators? And threa...

Listen
Paul's Security Weekly TV
Russian regex, John McAfee, Verkada Hack, & Microsoft Exchange - PSW #686 from 2021-03-13T22:00

Microsoft Exchange had some vulnerabilities, how could you not hear about them?, Russians try to throttle Twitter, silicon valley security camera company has been breached and we get to see what...

Listen
Paul's Security Weekly TV
How Illicit Markets Really Operate - David Hétu - PSW #686 from 2021-03-13T10:00

David has been studying the structure, size and scope of illicit markets for over 10 years. He has come to realize just how fragmented illicit markets are, how a few select vendors often control...

Listen
Paul's Security Weekly TV
CrowdStrike Falcon, Gigamon Hawk, Awake's NDR, & Acquisitions - ESW #219 from 2021-03-12T22:00

This Week, In the Enterprise Security News: Okta acquires Auth0, KnowBe4 Acquires MediaPRO, PayPal to acquire Curv, and Dropbox to acquire DocSend Aqua Security raises $135M, Privacera Secures a...

Listen
Paul's Security Weekly TV
Attack Surface Management, Monitoring, & Mapping - Jeff Foley - ESW #219 from 2021-03-12T10:00

The OWASP Amass Project has developed a tool to help information security professionals perform network mapping of attack surfaces and perform external asset discovery using open source informat...

Listen
Paul's Security Weekly TV
Using Computer Vision to Combat Phishing - Chris Cleveland - ESW #219 from 2021-03-11T22:00

Email security and phishing protection has many gaps that are exploited by attackers. Learn how computer vision can help prevent malicious URLs and websites from doing bad things to your users. ...

Listen
Paul's Security Weekly TV
ICS/OT Regulation, Part 2 - Jim Gilsinn - SCW #64 from 2021-03-11T10:00

Industrial Control Systems (ICS) and Operational Technology (OT) have risks and consequences in the real world, such as the health and safety of people, but how those industries handle the poten...

Listen
Paul's Security Weekly TV
ICS/OT Regulation - Jim Gilsinn - SCW #64 from 2021-03-10T22:00

Industrial Control Systems (ICS) and Operational Technology (OT) have risks and consequences in the real world, such as the health and safety of people, but how those industries handle the poten...

Listen
Paul's Security Weekly TV
Risky Business (With Less Resources), Or: Know the CISO Job Search - BSW #208 from 2021-03-10T10:00

In the leadership and communications section, Risky business: 3 timeless approaches to reduce security risk in 2021, Why Less Can Be More When It Comes to Cybersecurity, CISO job search: What to...

Listen
Paul's Security Weekly TV
Security Leadership in Times of Transition - Gerald Beuchelt - BSW #208 from 2021-03-09T22:00

In 2020, we interviewed Gerald Beuchelt on Enterprise Security Weekly. At that time, he was the CISO at LogMeIn. Now he's the CISO at Sprinklr. What's it like to transition jobs in the middle of...

Listen
Paul's Security Weekly TV
Security Engineering, Evil Packages, Exchange SSRF, & Observability - ASW #142 from 2021-03-09T10:00

Making security engineering successful, Go's supply chain, mitigating JSON interoperability flaws, automating the hunt for deserialization flaws, the importance of observability, and what to do ...

Listen
Paul's Security Weekly TV
Privacy, Data Security & Compliance - Cynthia Burke - ASW #142 from 2021-03-08T22:00

In most IT shops, privacy, data security and compliance often resided under the same umbrella of ownership. While all 50 States in the US have data breach notification laws, we are seeing a shif...

Listen
Paul's Security Weekly TV
Patching Exchange Servers, Book Reviews, Rockwell, & Forgotten AM Broadcasts - PSW #685 from 2021-03-07T10:00

This week, In the Security News, Calling all people who know how to patch MS Exchange servers, we need you, Rockwell Automation PLC flaws and what you can't do about it, a book review I agree wi...

Listen
Paul's Security Weekly TV
How To Build A Kick-Ass PC - PSW #685 from 2021-03-06T22:00

Paul recently built a new PC for daily work and security-related tasks. It's a monster PC! The build was researched heavily, and in this segment, Paul will share all the tips and tricks to you c...

Listen
Paul's Security Weekly TV
Offensive Cybersecurity Education and Getting Started in Pentesting - Phillip Wylie - PSW #685 from 2021-03-06T10:00

Phillip will discuss his passion for offensive cybersecurity education, mentoring, and getting started in pentesting. He co-authored a book based on his conference talk "The Pentester Blueprint:...

Listen
Paul's Security Weekly TV
Thycotic & Centrify, Geography, YubiKey, & K7 Antivirus - ESW #218 from 2021-03-05T22:00

This week, In the Enterprise Security News Thycotic and Centrify join forces, Netwrix acquires Strongpoint, SentinelOne plans for IPO, Qomplx plans to go public, and funding announcements from A...

Listen
Paul's Security Weekly TV
The New Cybercrime Landscape - Kimberly Sutherland - ESW #218 from 2021-03-05T10:00

LexisNexis Risk Solutions recently released its biannual Cybercrime Report covering July 2020 through December 2020, which details how the evolving threat landscape created new opportunities for...

Listen
Paul's Security Weekly TV
Traditional IDS is Dead - Matt Cauthorn, Sri Sundaralingam - ESW #218 from 2021-03-04T22:00

Many security teams have accepted their Intrusion Detection Systems (IDS) as little more than a compliance check-off. IDS reliance on bi-modal signatures is brittle, easily evaded by attackers, ...

Listen
Paul's Security Weekly TV
Tips and Advice: Practical Steps When Considering Cyber Insurance - Albert "Nickel" Lietzau, V, Mike Volk - SCW #63 from 2021-03-04T10:00

Assuming Nickel and Mike survived the first segment, we're asking them for practical advice in this segment on how to consider and ultimately select the right cyber insurance program for you. We...

Listen
Paul's Security Weekly TV
Cyber Insurance: Debunking Myths - Albert "Nickel" Lietzau, V, Mike Volk - SCW #63 from 2021-03-03T22:00

Nickel Lietzau and Mike Volk have heard that we are not huge fans of cyber insurance on SCW, and they have graciously agreed to subject themselves to our scrutiny. In the first segment we'll tou...

Listen
Paul's Security Weekly TV
Cyberinsurance, Breaches, Business Continuity, & Beyond! - BSW #207 from 2021-03-03T10:00

In the leadership and communications section, Financial Targets Don’t Motivate Employees, Texas power outage flags need to revisit business continuity, Security job candidate background checks: ...

Listen
Paul's Security Weekly TV
Security Incidents: Simple Responses That Make All The Difference - David Chamberlin - BSW #207 from 2021-03-02T22:00

What are some best practices for preparing for a security incident? David Chamberlin, Managing Director at CRA, Inc., joins Business Security Weekly to discuss preparation for a security inciden...

Listen
Paul's Security Weekly TV
JSON, OpenSSL, Educational Resources, & Flaws in CodeQL - ASW #141 from 2021-03-02T10:00

This week on the Application Security News, Implementation pitfalls in parsing JSON, finding all forms of a flaw with CodeQL, more educational resources for hacking apps, engineering and product...

Listen
Paul's Security Weekly TV
Hackable; How to do Application Security Right - Ted Harrington - ASW #141 from 2021-03-01T22:00

In looking at how to do application security right we talk about understanding the difference between defining types of security testing and the goals that security testing should be aiming for....

Listen
Paul's Security Weekly TV
TV Hacking, Nvidia, Nation States, NASA, & WMware - PSW #684 from 2021-02-28T10:00

This week In the Security News, Nvidia tries to throttle cryptocurrency mining, Digging deeper into the SolarWinds breach, now with executive orders, NASA's secret message on Mars, vulnerabiliti...

Listen
Paul's Security Weekly TV
Wait, You Did What? How To Be A Cybersecurity Hero... - Bryan Seely - PSW #684 from 2021-02-27T22:00

Bryan will talk about how and why he wire-tapped the US Secret Service and FBI, how he used his Marine Corps training, cyber abilities, social engineering, and OSINT to rescue his foster daughte...

Listen
Paul's Security Weekly TV
"Confessions of a CIA Spy - The Art of Human Hacking" Book Release - Peter Warmka - PSW #684 from 2021-02-27T10:00

Peter will tell the story behind the story of his new book "Confessions of a CIA Spy - The Art of Human Hacking" including key highlights from the book regarding data protection. Peter's new boo...

Listen
Paul's Security Weekly TV
Evaluating the MITRE ATT&CK Evaluations in their Third Year - ESW #217 from 2021-02-26T22:00

The latest MITRE ATT&CK vendor evaluations are due out soon. In advance of the new round, Uptycs' Ganesh Pai and Amit Malik explore the MITRE ATT&CK framework, its ongoing value for analysts AND...

Listen
Paul's Security Weekly TV
2020 Security Operations Survey - Christopher Crowley - ESW #217 from 2021-02-26T10:00

The 2020 SOC Survey results are in and the author, Chris Crowley, will discuss the detailed results in the report and how they can help individuals and organizations reduce the drag on our globa...

Listen
Paul's Security Weekly TV
Red Canary, Imperva Sonar, Data Breaches & Share Prices, & TrendMicro XDR - ESW #217 from 2021-02-25T22:00

This week in the Enterprise News: LasPass is no longer free, Tenable helps with dynamic assets, Security Scorecard and the Score Planner, Trend Micro XDR, & Imperva launches sonar! Funding annou...

Listen
Paul's Security Weekly TV
The Journey Of An Inner City Street Hacker, Part 2 - Chris Cochran, John Threat, Ronald Eddings - SCW #62 from 2021-02-25T10:00

The world of hacking and the threat actors that do that sort of thing. What are the implications on comp sec in 2021 for persons, corporations, nation states and maybe even your cat?

  Listen

Paul's Security Weekly TV
The Journey Of An Inner City Street Hacker, Part 1 - John Threat - SCW #62 from 2021-02-24T22:00

Jeff, Flee, & Scott talk to John Threat about his background and what led him to becoming a hacker.

 

Visit https://www.securityweekly...

Listen
Paul's Security Weekly TV
Risk, Security Initiatives, Business Outcomes, & Aligning Budgets - BSW #206 from 2021-02-24T10:00

In the Leadership and Communications section, Are businesses underinvesting in cybersecurity?, 4 tips to help CISOs get more C-Suite cybersecurity buy-in, New CISO Priorities of 2021, and more!<...

Listen
Paul's Security Weekly TV
The Cloud's Influence on the Evolving Culture of Security - Dutch Schwartz - BSW #206 from 2021-02-23T22:00

Dutch Schwartz, Cloud Security Strategist at AWS, discusses cloud's influence on the evolving culture of security. Having worked with many Fortune 500 CISOs and CIOs, Dutch will share his though...

Listen
Paul's Security Weekly TV
Dependency Confusion, Suspender Falls, Web Shells, & AppSec Scale - ASW #140 from 2021-02-23T10:00

This week on the Application Security News, Dependency confusion for internal packages, Chrome pulls down the Great Suspender, Microsoft highlights web shells, some strategies on scaling AppSec,...

Listen
Paul's Security Weekly TV
Targeting, Exploiting, & Defending Linux - Brandon Edwards - ASW #140 from 2021-02-22T22:00

Linux is all over the place (sometimes surprising), why is targeting it different? What types of attacks are used? How can we defend against attacks on Linux? We can incorporate recent attacks a...

Listen
Paul's Security Weekly TV
Unearthing a 10-Year Old SUDO Vulnerability - . Wheel - PSW #683 from 2021-02-14T10:00

“Wheel” was part of the team that discovered the heap overflow vulnerability in SUDO, Baron Samedit (CVE-2021-3156), that impacted major Unix-like operating systems included Linux, macOS, AIX an...

Listen
Paul's Security Weekly TV
CD Projekt Ransomwared, Ciphers, Water Supply Hacked, & Clubhouse Security Risks - PSW #683 from 2021-02-13T22:00

This week in the Security News, Police Playing copyrighted music to stop video of them being posted online, Border agents can search phones freely under new circuit court ruling, Microsoft warns...

Listen
Paul's Security Weekly TV
What Does Zero Trust Mean To You? - Peter Smith - PSW #683 from 2021-02-13T10:00

In this segment we'll unpack "Zero Trust", what does it mean and how can it be applied as a concept to information security today? It certainly begs the question what and who do you trust? Often...

Listen
Paul's Security Weekly TV
Work-Bench Ventures - Kelley Mak - ESW #216 from 2021-02-12T22:00

Kelley will discuss his investment thesis in security, his opinions on the cybersecurity investment market in general. He will also review some good and bad investments, stories from the real wo...

Listen
Paul's Security Weekly TV
Network Discovery & IT Asset Inventory - HD Moore - ESW #216 from 2021-02-12T10:00

HD has been focused on research related to network discovery and IT asset inventory for the past three years. This work has led to new techniques for device fingerprinting and topology mapping t...

Listen
Paul's Security Weekly TV
'Selfie Biometrics', NetWitness, Okta, & Jetstack Secure - ESW #216 from 2021-02-11T22:00

A new Open-source tool helps discover public Azure blobs, A New Eclypsium Integration with Kenna.VM, Armis Raises $125 Million, Okta launches its new open-source design system, Enterprise selfie...

Listen
Paul's Security Weekly TV
Security & Compliance Legal Highlights - SCW #61 from 2021-02-11T10:00

Our co-host, Priya Chaudry will enlighten us on several other topics of interest to our community. There might be a mention of Solarwinds, Southwest Airlines, HIQ Labs, and more.

 

Listen
Paul's Security Weekly TV
Update on CFAA - SCW #61 from 2021-02-10T22:00

We welcome our resident legal expert and co-host Priya Chaudry to catch us up on the status of the Supreme Court case concerning the Computer Fraud and Abuse Act (CFAA) and some other legal topi...

Listen
Paul's Security Weekly TV
9 Steps, the Big 8, & 7 Super Bowl Rings! - BSW #205 from 2021-02-10T10:00

In the leadership and communications section, 9 Steps for Effective Cybersecurity Risk Management, The Big 8: How to heighten cybersecurity governance, 7 Super Bowl rings for Tom Brady, and more...

Listen
Paul's Security Weekly TV
Evolution of the CISO Role - Ben Carr - BSW #205 from 2021-02-09T22:00

Ben Carr, Global Chief Information Security Officer at Qualys, steps in last minute to talk about his transition from Aristocrat to Qualys and the evolution of the CISO role.

 

Vis...

Listen
Paul's Security Weekly TV
BBPLR, API Security Trends, Memory Unsafety, & Patching 0-Days - ASW #139 from 2021-02-09T10:00

Funding bounties or finding bugs, how should we invest? Talks from Enigma Conference on memory unsafety and 0-days. Coming trends in API security and a review of research from 2020.

 

...

Listen
Paul's Security Weekly TV
Being a Serial Entrepreneur, Business Leader, & Hacker - Alissa Knight - ASW #139 from 2021-02-08T22:00

Alissa Knight has spent her career going against industry and social norms as both a Transgendered and Lesbian business leader and hacker. Learn more about her, her achievements as a published a...

Listen
Paul's Security Weekly TV
Vending Machine Hack, Chucky's Amber Alert, HarmonyOS, & Realtek Vulns - PSW #682 from 2021-02-07T10:00

Security in a Complex World, Huawei’s HarmonyOS embodies “Fake it till you make it”, Hackers Infiltrating the World of Online Gaming, Sloppy patches breed zero-day exploits, Dutch researcher hac...

Listen
Paul's Security Weekly TV
Quantum Computing & Finding the Truth - Bill DeLisi - PSW #682 from 2021-02-06T22:00

Bill will provide insight on best practices for internet safety, for work from home, family friendly internet habits which leads to the conversation of secure chats/files, & more!

 

<...

Listen
Paul's Security Weekly TV
Starting A Non-Profit To Help Small Companies With CMMC - Josh Marpet - PSW #682 from 2021-02-06T10:00

Small federal contractors are being required to become compliant with a new standard, CMMC. They've never had to do the level of security and compliance maturity that it requires! What do they d...

Listen
Paul's Security Weekly TV
The Cyber Defense Matrix, the DIE Triad, and Cybersecurity Startups - Sounil Yu - ESW #215 from 2021-02-05T22:00

The Cyber Defense Matrix is a framework to help systematically organize the many things that we buy and do in cybersecurity. The DIE Triad offers a new way of thinking about resiliency, how we s...

Listen
Paul's Security Weekly TV
Attack Surface Management - Jonathan Cran - ESW #215 from 2021-02-05T10:00

Attack Surface Management is an important and growing field within Information Security. In this segment, we discuss how security teams can frame the problem and what can be done to get a handle...

Listen
Paul's Security Weekly TV
Imperva Updates WAAP, SonicWall Confirms 0-Day, & Arista Zero Trust - ESW #215 from 2021-02-04T22:00

This week in the Enterprise News, Mission Secure Announces Series B, Akamai Technologies Acquires Inverse, for Microsoft, Security is a $10 Billion Business, Sontiq acquires Cyberscout, IRONSCAL...

Listen
Paul's Security Weekly TV
The Security Poverty Line, Part 2 - Wendy Nather - SCW #60 from 2021-02-04T10:00

Securing an organization means more than just spending money. For those that fall below the "security poverty line," many other dynamics come into play that make it harder for them to accomplish...

Listen
Paul's Security Weekly TV
The Security Poverty Line, Part 1 - Wendy Nather - SCW #60 from 2021-02-03T22:00

Securing an organization means more than just spending money. For those that fall below the "security poverty line," many other dynamics come into play that make it harder for them to accomplish...

Listen
Paul's Security Weekly TV
WallStreetBets - Hacking the Hedge Funds - BSW #204 from 2021-02-03T10:00

Everyone has heard the GameStop frenzy by now, but what's it all about. How did a group of Reddit users hack the financial system and squeeze the hedge funds? We're going to discuss the details ...

Listen
Paul's Security Weekly TV
Security Money - The Index is on the Rise - BSW #204 from 2021-02-02T22:00

It's time for our quarterly segment to review the money of security, including public companies, IPOs, funding rounds and acquisitions from Q4 2020. We'll also update you on our own index that t...

Listen
Paul's Security Weekly TV
Sudo Vuln, Libgcrypt, BlastDoor on iMessage, & AWS Lambda security - ASW #138 from 2021-02-02T10:00

This week in the Application Security News, Sudo sure does, Libgcrypt flaw, iMessage demonstrates security by design, AWS Lambda shares a message on its design security, & more!

 

...

Listen
Paul's Security Weekly TV
Groundhog Day - It's Time to Reset the Script on Vulnerabilities - John Delaroderie - ASW #138 from 2021-02-01T22:00

In honor of the movie Groundhog Day, John will take a look at the top 10 most routinely exploited vulnerabilities through a web app security lens.

 

This segment is sponsored by Qu...

Listen
Paul's Security Weekly TV
Ghostcat, Apache, Networks, Starliner - ASW #98 from 2021-01-31T22:10:42.023393

CVE-2020-1938: Ghostcat vulnerability in the Tomcat Apache JServ Protocol. IMP4GT: IMPersonation Attacks in 4G NeTworks demonstrates a proven insecurity on a layer above provably secure protocol...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #31 from 2021-01-31T22:10:42.023393

Machine learning from an investor’s perspective, 5 skills entrepreneurs need to succeed, AdEspresso joins Hootsuite, and more in this week’s Startup News!

Full Show Notes: Listen

Paul's Security Weekly TV
Hack Naked TV - June 9, 2016 from 2021-01-31T22:10:42.023393

Welcome to another episode of Hack Naked TV recorded June 9th 2016. I’m your host Aaron Lyons and today I’ll be talking about Ransomare, Angler, and the Swift Network.

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #37 from 2021-01-31T22:10:42.023393

LookingGlass debuts a new partner portal, F-Secure acquires Inverse Path, Skyhigh Networks has new CASB patents, and more in this week’s Enterprise News!

Full Show Notes: Listen

Paul's Security Weekly TV
Recorded Future and Virsec - PSW #617 from 2021-01-31T22:10:42.023393

We interview Roman Sannikov, the Director and Analyst on Demand at Recorded Future. We also interview Ray DeMeo, the Chief Operating Officer at Virsec.

\Full Show Notes: Listen

Paul's Security Weekly TV
Hack Naked TV - June 2, 2016 from 2021-01-31T22:10:42.023393

Hack Naked News covers Team Viewer, Myspace gets hacked, Infoblox, Ransomware, and Darkode! Here on Hack Naked TV!

Listen
Paul's Security Weekly TV
FireFox, Windows 10, DevOps, and BitHubLab - Application Security Weekly #19 from 2021-01-31T22:10:42.023393

Application news, DevOps food for thought, learning & tools from BitHubLab, and bugs, breaches, and more!

Full Show Notes: https:/...

Listen
Paul's Security Weekly TV
Hack Naked TV - May 31, 2016 from 2021-01-31T22:10:42.023393

Hack Naked TV, hosted by yours truly, Aaron Lyons! This week he will bring up the Bangladesh Heist, the battle between Google VS Oracle, Rob Graham's Port Scanning, and he'll rant on Ransomware!...

Listen
Paul's Security Weekly TV
Coresecurity, Endgame, & Edgewise - ESW #150 from 2021-01-31T22:10:42.023393

We interview Steve Laubenstein from CoreSecurity, Ian McShane from Endgame, and Peter Smith from Edgewise!

Full Show Notes: https:...

Listen
Paul's Security Weekly TV
Hack Naked TV - May 26, 2016 from 2021-01-31T22:10:42.023393

Do you know who Guccifer is? He could hack your email! Aaron Lyons talks about Guccifer, the Bangladesh Heist, and $12 million was stolen from an Ecuadorean bank.

Listen
Paul's Security Weekly TV
Hack Naked TV - May 24, 2016 from 2021-01-31T22:10:42.023393

This week on Hack Naked TV, Aaron talks about Ransomware, Bangladesh, and US Cyber Tech!

Listen
Paul's Security Weekly TV
Ping Identity, Cequence, & NowSecure - ASW #73 from 2021-01-31T22:10:42.023393

At Black Hat 2019, we interviewed: Ameya Talwalker from Cequence, Mark Batchelor from PING Identity, and Michael Krueger from NowSecure!

Full Show Notes: Listen

Paul's Security Weekly TV
Hack Naked TV - May 19, 2016 from 2021-01-31T22:10:42.023393

Ransomware again? I think so! Hear other great news stories and he will give some special advice! Here on Hack Naked TV!

Listen
Paul's Security Weekly TV
Hack Naked TV - Beau Bullock from 2021-01-31T22:10:42.023393

Need the Security News for Week? Here's an in-depth update with Beau Bullock about Critical 7-zip Vulns, Symantec BSOD, Facebook CTF Platform, and EmPyre.

Listen
Paul's Security Weekly TV
Hack Naked TV - May 12, 2016 from 2021-01-31T22:10:42.023393

Need the Security News for the Week? Here on Hack Naked TV, Aaron Lyons gives the top news for the week in Security and Hacking!

Listen
Paul's Security Weekly TV
Hack Naked TV - May 5, 2016 from 2021-01-31T22:10:42.023393

Ever wonder what Image Magick is? We don't know either! That's why Aaron is here to inform you about Image Magick among other more interesting topics! Stay tuned here on Hack Naked TV!

Listen
Paul's Security Weekly TV
Hack Naked TV - May 3, 2016 from 2021-01-31T22:10:42.023393

Do you know what Cyber warfare? Hear what Aaron Lyons has to say about Cyber warfare! He rants on this Hack Naked TV.

Listen
Paul's Security Weekly TV
Kobe's Quotes To Live and Other Leadership News - BSW #161 from 2021-01-31T22:10:42.023393

This week in the leadership articles segment, Matt, Paul and Jason cover the following articles: Tech Isn't the Problem or Solution for Better Productivity. Instead, Look to Your Own Leadership,...

Listen
Paul's Security Weekly TV
Hack Naked TV - April 28, 2016 from 2021-01-31T22:10:42.023393

Welcome to another episode of Hack Naked TV recorded April 28th 2016. Aaron covers Cyberbombs, the next scan from Robert Graham, professional cyclists hacking their bikes, and more.

Listen
Paul's Security Weekly TV
Hack Naked TV - April 14, 2016 from 2021-01-31T22:10:42.023393

This week on Hack Naked TV, Aaron Lyons talks about Badlock, Ransomware, Russian Prison for Hackers, and Ransomware. Check out Beau Bullock's Hack Naked for more in depth detail on Badlock.

Listen
Paul's Security Weekly TV
Fighting IoT Insecurities - Terry Dunlap - PSW #657 from 2021-01-31T22:10:42.023393

Arrested at 17 while hacking with a Commodore 64, Terry went on to work for the US National Security Agency help track terrorists. He left the NSA in 2007 to bootstrap Tactical Network Solutions...

Listen
Paul's Security Weekly TV
MITRE ATT&CK: Katie Nickels, MITRE - Paul's Security Weekly #612 from 2021-01-31T22:10:42.023393

Katie Nickels is the ATT&CK Threat Intelligence Lead at MITRE Corporation. MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observatio...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #364 - Security News from 2021-01-31T22:10:42.023393

Listen
Paul's Security Weekly TV
Paul's Security Weekly #363 - Security News from 2021-01-31T22:10:42.023393


Embedded device fail, WeMo, and more!

Listen
Paul's Security Weekly TV
Guacamole RCE, PAN-OS Flaw, & A Culture of Resilience - ASW #113 from 2021-01-31T22:10:42.023393

Would you like some RCE with your Guacamole?, Attackers Will Target Critical PAN-OS Flaw, Security Experts Warn, Microsoft releases emergency security update to fix two bugs in Windows codecs, T...

Listen
Paul's Security Weekly TV
Biometric Authentication, Jumio - Paul's Security Weekly #611 from 2021-01-31T22:10:42.023393

Growth of account takeover and how to prevent it Data breaches continue to threaten organizations and expose usernames and passwords on the Dark Web, enabling fraudsters to use stolen data to ac...

Listen
Paul's Security Weekly TV
Security Weekly #448 - The Vulnerability Management Maturity Curve from 2021-01-31T22:10:42.023393

Organizations tend to fall somewhere on a scale of 0 through 100 (with 100 being the best) when it comes to the maturity of their vulnerability management program. Starting at 0 for those who do...

Listen
Paul's Security Weekly TV
AttackDefense Labs Platform - Paul's Security Weekly #609 from 2021-01-31T22:10:42.023393

We interview Vivek Ramachandranis the Founder & CEO of Pentester Academy. Pentester Academy, our AttackDefense Labs platform and other topics. Vivek will show a demo of their AttackDefense labs....

Listen
Paul's Security Weekly TV
Hack Naked TV: OSCP Review from 2021-01-31T22:10:42.023393

Aaron reviews the Penetration Testing with Kali Linux course and OSCP test.

Listen
Paul's Security Weekly TV
Startup Security Weekly #20 - Chad Boeckmann, Secure Digital Solutions from 2021-01-31T22:10:42.023393

Chad founded Secure Digital Solutions in 2005 with a vision to provide clients vendor-neutral information security services aligned with business goals and objectives. He has over 17 years of in...

Listen
Paul's Security Weekly TV
Security Weekly #443 - Security News from 2021-01-31T22:10:42.023393

The Security Weekly crew discusses software security, how to create more secure code, legacy code, IoT devices and more!

Security Weekly Web Site: http://securityweekly.com

Hack Na...

Listen
Paul's Security Weekly TV
SambaCry, FBI Warnings, and Hacking Segways - Paul's Security Weekly #523 from 2021-01-31T22:10:42.023393

Exploiting SambaCry, a warning from the FBI, hacks versus hurricanes, hacking segways, and more security news!

Full Show Notes: https...

Listen
Paul's Security Weekly TV
Security Weekly #438 - Interview with Ron Gula from 2021-01-31T22:10:42.023393

We interview Ron Gula, one of the first interviews conducted on Security Weekly. Ron is a leading cybersecurity thinker, innovator, and visionary in the information security industry.

Listen

Paul's Security Weekly TV
Security Weekly #436 – Security News: IoT and Nest from 2021-01-31T22:10:42.023393

Today in the news, Kevin recaps the T-Mobile breach. Do we now let the fox watch the henhouse? Larry dives into a Nest (TM) of IoT (drink) devices. Paul tries to keep it together with a blog pos...

Listen
Paul's Security Weekly TV
The Pillars Of The Enterprise, Gravwell - Enterprise Security Weekly #138 from 2021-01-31T22:10:42.023393

Corey Thuen is the Co-Founder at Gravwell. Corey covers the topics: Framework for discussion: the pillars of the SOC and the 80/20 principle, Wire data, Log/Application Data, Endpoint protection...

Listen
Paul's Security Weekly TV
Security Weekly #434 Security News - Deep Thoughts with Jack Daniel from 2021-01-31T22:10:42.023393

Jack goes full-rant on Windows 10 touch screen changes. If you are still using Yahoo! messenger, you should stop. Also, vote for McAfee bumper stickers and t-shirts will likely surface after his...

Listen
Paul's Security Weekly TV
Security Weekly #434 - Interview with Micah Hoffman from 2021-01-31T22:10:42.023393

In our feature interview SANS instructor Micah Hoffman discusses everything from bug bounty programs to better security for your SaaS. Micah is an active member in the NoVAHackers community, wri...

Listen
Paul's Security Weekly TV
Zane Lackey, Signal Sciences - Application Security Weekly #31 from 2021-01-31T22:10:42.023393

Zane Lackey is the Founder/Chief Security Officer at Signal Sciences. Zane Lackey explains how we the security industry needs to shift left when it comes to applications and patching.

Ful...

Listen
Paul's Security Weekly TV
Startup Smart and Trade Secrets - Startup Security Weekly #43 from 2021-01-31T22:10:42.023393

Wall Street Journal Best-Selling Author Shares 6 Secrets to Starting Smart [Book Excerpt] - Note the role of emotion to get traction/results Why Entrepreneurs Need To Keep Their Business Focused...

Listen
Paul's Security Weekly TV
Hack Naked News #96 - October 11, 2016 from 2021-01-31T22:10:42.023393

Tons and tons of Ransomware and Cisco! All that and more with Aaron Lyons on Hack Naked News!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Hack_Naked_TV_October_11_2016<...

Listen
Paul's Security Weekly TV
OneLogin Woes, Shadow Brokers Identity, oAuth Nightmares - Paul's Security Weekly #516 from 2021-01-31T22:10:42.023393

Chipotle and OneLogin suffer breaches, Windows XP Too Unstable To Spread WannaCry, Patches Available for Linux Sudo Vulnerability, Cisco, Netgear Readying Patches For Samba Vulnerability, oAuth ...

Listen
Paul's Security Weekly TV
Adam Fletcher, Blackstone - Business Security Weekly #125 from 2021-01-31T22:10:42.023393

Adam Fletcher is the Chief Information Security Officer for Blackstone. As a security professional with over 18 years of experience, Adam has worked with global security organizations large and ...

Listen
Paul's Security Weekly TV
Exploiting Client-Side Node.js with Moses Hernandez - Paul's Security Weekly #516 from 2021-01-31T22:10:42.023393

I know what you're thinking, Node.js is server-side right? Not exactly. It turns out many client-side applications have embedded Node.js. And its not always updated to the latest version. And, i...

Listen
Paul's Security Weekly TV
Security Vendor Response to WannaCry Makes Me Want to Cry - Enterprise Security Weekly #45 from 2021-01-31T22:10:42.023393

Identropy and Exabeam team up, five pitfalls to avoid during a CASB evaluation, FirstWave partners with Fortinet, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
ICS - Enterprise Security Weekly #102 from 2021-01-31T22:10:42.023393

Paul and Matt review the ICS security landscape, discussing the problems and potential solutions to secure critical infrastructure. We used several on-site interviews and briefings with solution...

Listen
Paul's Security Weekly TV
Larry Pesce, Getting Started with FL2k - Paul's Security Weekly #570 from 2021-01-31T22:10:42.023393

An introduction to FL2K: Software Defined Radio is all the rage for detecting unknown signals and transmitters. We'll show you how to set up and use a surreptitious transmitter to start your jou...

Listen
Paul's Security Weekly TV
Hack Naked TV - August 11, 2016 from 2021-01-31T22:10:42.023393

This week on Hack Naked TV, Aaron Lyons discusses all the news during Hacker Summer Camp. So stay tuned!

Listen
Paul's Security Weekly TV
John Moran, DFLabs - Enterprise Security Weekly #99 from 2021-01-31T22:10:42.023393

John is a Senior Product Manager at DFLabs, where he performs a wide variety of tasks from product management to content development and partner management. John Moran talks about DFLabs Incman ...

Listen
Paul's Security Weekly TV
Accenture and Heaphones - Startup Security Weekly #66 from 2021-01-31T22:10:42.023393

Paul and Michael talk about headphones, Accenture, and the startup companies that influence the security industry.

Full Show Notes: Listen

Paul's Security Weekly TV
Hack Naked TV - July 28, 2016 from 2021-01-31T22:10:42.023393

Aaron Lyons discusses Lastpass, Malicious Insider, and Hacker Summer Camp! Watch all the latest security news every week, here on Hack Naked TV!

Visit http://hacknaked.tv to get all the l...

Listen
Paul's Security Weekly TV
Hack Naked TV - July 26, 2016 from 2021-01-31T22:10:42.023393

This week Aaron Lyons talks about Powerware, no more Ransomware, and HIPAA! All that and more on Hack Naked TV!

Listen
Paul's Security Weekly TV
Hack Naked TV - July 21, 2016 from 2021-01-31T22:10:42.023393

This week on Hack Naked TV, Aaron Lyons talks about httpoxy, Neutrino Exploit Kit, and Ubuntu. All that and more, so stay tuned!

Listen
Paul's Security Weekly TV
Hack Naked TV - July 14, 2016 from 2021-01-31T22:10:42.023393

This week on Hack Naked TV, Aaron Lyons talks about Sundown exploit kit, Store Communications Act, and FDIC Hacked. All that and more, so stay tuned!

Listen
Paul's Security Weekly TV
EMOTET Disrupted, "Ghost" Hackers, & Why Privacy is 'Like Bubblewrap' - PSW #681 from 2021-01-31T10:00

In the Security News, why privacy is like bubble wrap, South African government releases its own browser just to re-enable flash support, former Lulzsec hacker releases VPN zero-day used to hack...

Listen
Paul's Security Weekly TV
How Tall Do You Have to Be to Ride the Ride? - Dan DeCloss - PSW #681 from 2021-01-30T22:00

Today’s segment will discuss effective assessments, the maturity of your security posture, and the composition of your team. Specific topics in the episode include the what, when, and how of con...

Listen
Paul's Security Weekly TV
XDR and Vitamins - Michael Roytman - PSW #681 from 2021-01-30T10:00

What is XDR? How do we know the security protections we're investing in are working? All this and Paul's CBD Pineapple Pizza Drink on this week's show.

 

This segment is sponsored ...

Listen
Paul's Security Weekly TV
Supply Chain Security in the Face of Solarwinds - Allan Alford - ESW #214 from 2021-01-29T22:00

Do we really need to be freaking out? What could we and should we be doing in general regardless of SolarWinds?

 

Visit https://www.se...

Listen
Paul's Security Weekly TV
DNS Hijacking - Fredrik Nordberg Almroth - ESW #214 from 2021-01-29T10:00

Fredrik Nordberg Almroth, Security Researcher at Detectify, tells the story of how he managed to claim the top-level domain of an entire country - the Congo (DRC), .cd - before any bad actors co...

Listen
Paul's Security Weekly TV
Platform9, Swimlane, SonicWall 0-Days, & Fortinet - ESW #214 from 2021-01-28T22:00

This week, in the Enterprise Security News, Platform9 unburdens users from the complexities of Kubernetes, Swimlane Raises $40 Million, SonicWall hacked by zero-days in its own products, Deloitt...

Listen
Paul's Security Weekly TV
How to Build an Insider Threat Program in 10 Steps - Part 2 - Anthony Palmeri - SCW #59 from 2021-01-28T10:00

The conversation continues on mitigating insider threats and building an insider threat program!

 

This segment is sponsored by Ekran System. Visit Listen

Paul's Security Weekly TV
How to Build an Insider Threat Program in 10 Steps - Part 1 - Anthony Palmeri - SCW #59 from 2021-01-27T22:00

Mitigating insider threats is a key cybersecurity priority for any organization that works with sensitive data. And to do that, you need an insider threat program. Such a program not only is req...

Listen
Paul's Security Weekly TV
Cybersecurity Failure, Reboot Security Strategy, & Solving the Skills Gap - BSW #203 from 2021-01-27T10:00

In the Leadership and Communications section, Cybersecurity Failure among Highest Risks, warns World Economic Forum, How to reboot a broken or outdated security strategy, A 21st Century Solution...

Listen
Paul's Security Weekly TV
Everyone missed SUNBURST... or did they? - Matt Cauthorn - BSW #203 from 2021-01-26T22:00

When the SolarWinds Orion SUNBURST attack hit the national newscycle, businesses far-and-wide scrambled to determine whether or not they were affected–unfortunately, many found they couldn't say...

Listen
Paul's Security Weekly TV
KindleDrip, State of Messaging State Machines, DoH, & Data Security Strategies - ASW #137 from 2021-01-26T10:00

An overflow and a flawed regex paint an RCE picture for Kindle, messaging apps miss the message on secure state machines, three pillars of a data security strategy for the cloud, where DoH might...

Listen
Paul's Security Weekly TV
Reading Industry Analyst Tea Leaves To Predict The Future - Taylor McCaslin - ASW #137 from 2021-01-25T22:00

It's analyst season with the new Forrester Wave on SAST recently published as well as Gartner's Application Security Testing Magic Quadrant publishing in April. We'll talk about what are analyst...

Listen
Paul's Security Weekly TV
WRT54G Hacking History, 70 Unpatched Cisco Vulns, & Bypassing MFA - PSW #680 from 2021-01-17T10:00

In the Security News, How two authors became part of WRT54G hacking history, European police and German law enforcement have taken down the illegal "DarkMarket" online marketplace, 70 unpatched ...

Listen
Paul's Security Weekly TV
Hacking Ubiquiti Devices - Jon Gorenflo - PSW #680 from 2021-01-16T22:00

Ubiquiti network gear has become a favorite among tech enthusiasts, but various Ubiquiti products have had some serious vulnerabilities in recent history. Listen in as we discuss hack, secure, a...

Listen
Paul's Security Weekly TV
Beyond Phishing Blockers - Ryan Noon - PSW #680 from 2021-01-16T10:00

Ryan Noon joins Paul, and the rest of the PSW team, this week to chat through the importance of resilience in everything companies do to protect cloud-stored data and IP, unpack growing enterpri...

Listen
Paul's Security Weekly TV
The DBoM Consortium - Chris Blask - ESW #213 from 2021-01-15T22:00

The DBoM consortium is a Linux Foundation project to be able to share information with third parties safely, securely, and with control over the information, even after handing it over! Unisys h...

Listen
Paul's Security Weekly TV
It's 2021, Do You Know Where Your Assets Are? - ESW #213 from 2021-01-15T10:00

We all know asset management is one of the basics. In fact, it's literally the first two items on the Center for Internet Security's list of top 20 critical security controls. https://www.cisecu...

Listen
Paul's Security Weekly TV
Amazon's Parler Removal, Beyond Security & Vicarius Partner, & More SolarWinds! - ESW #213 from 2021-01-14T22:00

This week, Beyond Security partners with Vicarius, Amazon’s Parler removal and what it means for Cloud onfidence, Kount sold to Equifax, McAfee vs Crowdstrike, JumpCloud raises some funds, Red H...

Listen
Paul's Security Weekly TV
Sunburst: The Cleanup - SCW #58 from 2021-01-14T10:00

We will shift focus of the discussion from understanding to action - that is, what to do about this and similar types of attacks that might be perpetrated agains your organization. Or is there a...

Listen
Paul's Security Weekly TV
Sunburst: Down the Rabbit Hole - SCW #58 from 2021-01-13T22:00

We're going to dissect what we know about the Sunburst/SolarWinds hack to this point - SCW style! We'll touch on the things that keep coming up in the news - attribution, conspiracy theories, im...

Listen
Paul's Security Weekly TV
BISOs Bridge the Gap, Lots of Questions, & Use Negative Feedback to Improve - BSW #202 from 2021-01-13T10:00

In the Leadership and Communications section, How BISOs bridge the gap between corporate boards and cybersecurity, 5 questions CISOs should ask prospective corporate lawyers, Good Leadership Is ...

Listen
Paul's Security Weekly TV
Why deepwatch Chose Splunk to Secure Customer Networks - Patrick Orzechowski - BSW #202 from 2021-01-12T22:00

Learn why deepwatch chose Splunk as it’s one and only SIEM solution to deliver its Managed Detection & Response services to Fortune 2000 customers. Hear how deepwatch is leveraging a variety of ...

Listen
Paul's Security Weekly TV
Google 2FA Cloning, Speed vs. Security, & "Hack The Army" Bug Bounty 3.0 - ASW #136 from 2021-01-12T10:00

Significant source code leak from misconfigured repo, side-channel attack on hardware authentication keys, a third bug bounty for the U.S. Army, the cost of poor software quality, the benefits o...

Listen
Paul's Security Weekly TV
Fuzz Testing - Andrei Serban - ASW #136 from 2021-01-11T22:00

Fuzzing can be successful appsec strategy for finding software bugs. And deploying a fuzzer no longer needs to be a cumbersome process. Find out how fuzzing can help secure software beyond just ...

Listen
Paul's Security Weekly TV
Custom Python Encryption, Shady 0-Days, & The Great iPwn - PSW #679 from 2021-01-10T10:00

In the Security News, Nissan Source code leaked, how the shady 0-Day sales game is evolving, Hack the Army 3.0 announced, creating your own custom encryption in python, FBI warns of swatting att...

Listen
Paul's Security Weekly TV
What Has Changed (or Not) Since Our Last Visit? - Ming Chow - PSW #679 from 2021-01-09T22:00

-What are we seeing from infosec graduates as they come into the enterprise to begin their careers? -How has data privacy changed since 2014? -Is the cloud a solution, or creates more problems? ...

Listen
Paul's Security Weekly TV
Automated Vulnerability Remediation - The Good, the Bad and the Ugly - PSW #679 from 2021-01-09T10:00

The way we identify, prioritize, and mitigate software vulnerabilities was built in the reverse order. Why did it happen? Could a new remediation strategy finally form an alliance between IT and...

Listen
Paul's Security Weekly TV
SolarWinds, FireEye, Microsoft, Oh My! - Sean Metcalf, Tyler Robinson - ESW #212 from 2021-01-08T22:00

The current ransomware, breaches, and nation state attacks have defenders feeling overwhelmed and under resourced. Can defensive teams really have defended against this type of supply chain atta...

Listen
Paul's Security Weekly TV
The State of Data Security - Chris Brown - ESW #212 from 2021-01-08T10:00

A casual and candid conversation on database security. Talking through the current data trends including the transition to the cloud and what this means for the database security practitioner. W...

Listen
Paul's Security Weekly TV
Veracode in AWS Marketplace, ZScaler SUNBURST Assessment, & SolarWinds Fallout - ESW #212 from 2021-01-07T22:00

This week, Tyler Shields joins us for his first episode as Co-Host, and John Strand returns! In the Enterprise News, Two data security companies merge, Veracode's products are now available in t...

Listen
Paul's Security Weekly TV
Looking Forward - SCW #57 from 2021-01-07T10:00

We don't want to have the typical "predictions" episode, but do want to chat about what we might expect in the coming year; what is changing? what is coming back? and when? (if at all)? Looking ...

Listen
Paul's Security Weekly TV
Looking Back - SCW #57 from 2021-01-06T22:00

We have a roundtable discussion amongst the hosts looking back on the highs and lows of 2020! Looking back: -Solarwinds (not in depth but just as part of the year) -Covid-19 -Working from home -...

Listen
Paul's Security Weekly TV
6 Security Concerns, 3 Steps, & 10 Skills - BSW #201 from 2021-01-06T10:00

In the leadership and communications section, 6 board of directors security concerns every CISO should be prepared to address, Four ways to improve the relationship between security and IT, CISO...

Listen
Paul's Security Weekly TV
CISO Stories - Cybersecurity Leadership 2021 - Todd Fitzgerald - BSW #201 from 2021-01-05T22:00

Up Your game with the CISO STORIES Podcast! If anything this past year has taught us is that we can not go on our own, and leveraging the experiences from other CISOs is critical to our success....

Listen
Paul's Security Weekly TV
Kubernetes Clusters, Microsoft Solarigate, & Apple's Security DIY - ASW #135 from 2021-01-05T10:00

Microsoft purges malicious SolarWinds presence and highlights a threat model around their source code, the tl;drsec crew provides a hardening guide for Kubernetes, Apples provides a user guide f...

Listen
Paul's Security Weekly TV
Security By Design - ASW #135 from 2021-01-04T22:00

A premise of adding security to DevOps is we can "shift left" AppSec responsibilities, one of which is building apps so they're secure by design. Yet what resources does the AppSec community pro...

Listen
Paul's Security Weekly TV
SolarWinds Attack, AIR-FI Technique, & Zodiac Cypher Decoded - PSW #678 from 2020-12-20T10:00

In the Security News, How suspected Russian hackers outed their massive cyberattack, Millions of Unpatched IoT, OT Devices Threaten Critical Infrastructure, Zodiac Killer Cipher Solved, a Securi...

Listen
Paul's Security Weekly TV
Securing The Enterprise Software Supply Chain - Harry Sverdlove - PSW #678 from 2020-12-19T22:00

SolarWinds is just the latest example of how the enterprise software supply chain, when compromised, can be used successfully by attackers. These coordinated and well-managed attacks prey on tru...

Listen
Paul's Security Weekly TV
Generating Threat Insights Using Data Science - Roi Cohen, Shani Dodge - PSW #678 from 2020-12-19T10:00

In this world of countless vulnerabilities, we need to find a way to identify threats. Prioritizing known vulnerabilities is a step in the right direction but definitely not enough. There is a n...

Listen
Paul's Security Weekly TV
Mimecast Awareness Training Philosophy - Emily Huynh, Mandy McKenzie - ESW #211 from 2020-12-18T22:00

When you roll-out the Mimecast Awareness Training best practices to your organization and embrace your employees, you will achieve something magical - employees who become an extension of your s...

Listen
Paul's Security Weekly TV
Visibility Is Critical in Uncertain Times - Martyn Crew - ESW #211 from 2020-12-18T10:00

As organizations come to terms with continued uncertainty in 2021, Martyn will discuss the importance of hybrid network visibility in building an IT infrastructure that can meet the needs of thi...

Listen
Paul's Security Weekly TV
42Crunch IDE OpenAPI Editing, DigiCert IoT Device Manager, & More SolarWinds - ESW #211 from 2020-12-17T22:00

This week in the Enterprise security News, A Hack brought unwanted attention to SolarWinds, Datadog and Snyk unveil GitHub integration to automate software development workflow, Thoma Bravo Inve...

Listen
Paul's Security Weekly TV
Pen Testing, Part 2 w/ Dmitry Zagadsky - SCW #56 from 2020-12-17T10:00

We'll continue our discussion of penetration testing. In this segment, we'll talk about the right reasons to have a penetration test performed, the impact (for better or worse) of the PCI requir...

Listen
Paul's Security Weekly TV
Pen Testing, Part 1 w/ Dmitry Zagadsky - SCW #56 from 2020-12-16T22:00

The penetration testing mythology as it applies to information security is all screwed up. If nothing else, we're going to attempt to define a penetration test, focus on the goals, and what shou...

Listen
Paul's Security Weekly TV
Leadership & Communications: Lessons Learned in 2020 - BSW #200 from 2020-12-16T10:00

For this final segment of 2020, why pull more articles to review when we all lived it? Instead, let's recap some of the leadership and communications lessons we have learned in a very difficult ...

Listen
Paul's Security Weekly TV
Transforming Cyber Risk/Compliance Through Automation - Padraic O'Reilly - BSW #200 from 2020-12-15T22:00

How are CISOs of the Global 500 automating risk and compliance assessments by 90%, saving millions of dollars per year, and creating a unified strategy around cyber risk in the wake of Digital T...

Listen
Paul's Security Weekly TV
Atheris Python Fuzzer, Bronze Bit Attack, & FireEye Highlights - ASW #134 from 2020-12-15T10:00

FireEye shares supply chain subterfuge, researchers show repeated mistakes in TCP/IP stacks, Google open sources Python fuzzing, Cisco and Microsoft patch their patches for vulns in Jabber and p...

Listen
Paul's Security Weekly TV
Freedom From Computing Environments - Ev Kontsevoy - ASW #134 from 2020-12-14T22:45:59

We built OSS Teleport to provide a Unified Access Plane that consolidates access controls and auditing across all environments - infrastructure, applications, and data.

 

This segm...

Listen
Paul's Security Weekly TV
Hacking Matters Panel - PSW #677 from 2020-12-13T10:00

Hacking matters. The term hacking has gotten away from us over the years. I believe we've reclaimed it, to a certain extent. The goal of this panel is to discuss all things hacking culture. What...

Listen
Paul's Security Weekly TV
Innovative Blue Team Techniques Panel - PSW #677 from 2020-12-12T22:00

We often hear that offensive security techniques are "sexier" than defensive blue team techniques. In this panel discussion, we attempt to level the playing field (on so many levels...) between ...

Listen
Paul's Security Weekly TV
The State Of Penetration Testing Panel - PSW #677 from 2020-12-12T10:00

Join us for a lively discussion surrounding the topic of penetration testing. Sure, we've called out differences between vulnerability scanning and penetration testing. Moving past this particul...

Listen
Paul's Security Weekly TV
Every Analyst Struggles to Balance Thoroughness & Speed - Joe Rivela - ESW #210 from 2020-12-11T22:00

Polarity uses computer vision that works like augmented reality for your data. It's not a new dashboard to search or a new portal to manage. Polarity augments your existing workflows, enriching ...

Listen
Paul's Security Weekly TV
How Can We Vaccinate Our Networks? - Mike Lloyd - ESW #210 from 2020-12-11T10:00

These days, we're all learning about human immunology from the headlines. What are the equivalent defenses for our networks? How do we achieve resilience at scale, when we don't really have a ne...

Listen
Paul's Security Weekly TV
Kali Linux & Pentesting, FireEye Compromised, & Qualys UAE Cloud - ESW #210 from 2020-12-10T22:00

This week in the Enterprise News, How Kali Linux creators plan to handle the future of penetration testing, Tenable founders launch cybersecurity foundation to hand out grants, FireEye cybersecu...

Listen
Paul's Security Weekly TV
Getting To Know Flee - SCW #55 from 2020-12-10T10:00

We want to take the time in the segment to formally introduce you to one of our new co-hosts, Mr. Fredrick "Flee" Lee. Flee is currently the Chief Security Officer for a company called Gusto and...

Listen
Paul's Security Weekly TV
The Cyber Risk/Compliance Transformation Solution - Padraic O'Reilly - SCW #55 from 2020-12-09T22:00

In this segment, we discuss how COVID-19 and rapid Digitalization have pushed risk and compliance teams to innovate internally, and how they’re doing so with real-life examples. How is it even p...

Listen
Paul's Security Weekly TV
Darth Vader Week - Leadership from the Dark Side - BSW #199 from 2020-12-09T10:00

In the leadership and communications section, Darth Vader Week - Leadership from the Dark Side, Compassionate Leadership Is Necessary — but Not Sufficient, 3 Steps to Run Better and More Effecti...

Listen
Paul's Security Weekly TV
Securing the Hybrid Workforce in 2021 and Beyond - Sri Sundaralingam - BSW #199 from 2020-12-08T22:00

When the COVID-19 pandemic suddenly forced the global workforce into remote work, many wondered if we’d ever go back to the office. While some businesses have announced the option for 100% remot...

Listen
Paul's Security Weekly TV
Google Play Bug, GitHub, iPhone Radio Reboots, & Docker Hub Vulns - ASW #133 from 2020-12-08T10:00

An old security bug in the Play library still affects 8% of apps in Google Play, Project Zero researcher spends six months to reboot an iPhone (in an epic manner), GitHub looks at the security o...

Listen
Paul's Security Weekly TV
Security Web Applications Against Modern Threats - John Delaroderie, Mike Manrod - ASW #133 from 2020-12-07T22:15:12

Mike Manrod, CISO of Grand Canyon University, joined by John Delaroderie, Security Solutions Architect at Qualys, will discuss his approach to web application security with an emphasis on improv...

Listen
Paul's Security Weekly TV
Security News w/ Ed Skoudis - PSW #676 from 2020-12-06T10:00

Ed Skoudis returns to talk to us about the Holiday Hack Challenge! Then, in the Security News, Thousands of unsecured medical records were exposed online, Advanced Persistent Threat Actors Targe...

Listen
Paul's Security Weekly TV
Zero Trust Data Security - Jeff Capone - PSW #676 from 2020-12-05T22:00

Ensure all your data is secure, without impacting the business.

 

This segment is sponsored by SecureCircle. Visit https://securi...

Listen
Paul's Security Weekly TV
From Chaos to Topia - Vicarius - PSW #676 from 2020-12-05T10:00

More computers, more software, and faster development cycles lead to more vulnerabilities. The security and IT teams are put under immense pressure to tackle the growing number of vulnerabilitie...

Listen
Paul's Security Weekly TV
Cybersecurity & Diversity - Jackie Abrams, Gabe Gumbs, Mandy Logan, Susan Bosco - ESW #209 from 2020-12-04T22:00

How bad is the diversity problem in the Cybersecurity industry? Have we made any progress or is it all talk? In this special Enterprise Security Weekly segment, we are joined by industry profess...

Listen
Paul's Security Weekly TV
The Road To Secure Your Organization - Ferruh Mavituna - ESW #209 from 2020-12-04T10:00

Before you go picking technologies, you have to have a plan. How does one create that plan? Ferruh will focus on some concrete steps to create an AppSec plan using Netsparker's simple framework....

Listen
Paul's Security Weekly TV
Amazon EKS, DFLabs Cloud Package, & CyberMDX Healthcare Security Suite - ESW #209 from 2020-12-03T22:00

This week in the Enterprise Security News, securing Amazon EKS, Attivo Networks announces a new integration, a cloud security mapping startup comes out of Stealth, recent funding announcements f...

Listen
Paul's Security Weekly TV
AJ Yawn, NABCRMP - Part 2 - SCW #54 from 2020-12-03T10:00

We're taking on a different aspect of the cybersecurity skills gaps in this episode. Namely, the lack of diversity in our industry when it comes to African Americans and what can we all do about...

Listen
Paul's Security Weekly TV
AJ Yawn, NABCRMP - Part 1 - SCW #54 from 2020-12-02T22:00

We're going to take on a different aspect of the cybersecurity skills gaps in this episode. Namely, the lack of diversity in our industry when it comes to African Americans and what can we all d...

Listen
Paul's Security Weekly TV
Your Title Doesn't Make You a Leader, The New 9 to 5, & Say "Thanks" - BSW #198 from 2020-12-02T10:00

In the leadership and communications section, Your Title Doesn't Make You a Leader, The New Nine to Five: How Traditional Hours Are Holding Your Business Back, Building a Better Workplace Starts...

Listen
Paul's Security Weekly TV
Where's your data? Who Cares! - Jeff Capone - BSW #198 from 2020-12-01T22:00

App, User, and Data, but it's all about the data! Discovering and classifying data to protect it is tough. What if you can protect all of your data? Jeff Capone, CEO and Co-founder at SecureCirc...

Listen
Paul's Security Weekly TV
Top CyberSec Skills for 2021, Xbox Gamertag Bug, & MobileIron RCE Flaw - ASW #132 from 2020-12-01T10:00

Xbox bug exposed email identities, focusing on prevention for your cloud security strategies, Amazon looking to hire more Rust developers, KubeCon continues push for security, and a DevOps readi...

Listen
Paul's Security Weekly TV
Security Decisions During Application Development - Tim Mackey - ASW #132 from 2020-11-30T22:00

The security of any application is a function of the decisions made during development. Measuring the risk of those decisions isn't something contained within a single tool, but instead requires...

Listen
Paul's Security Weekly TV
Beyond Subjectivity: Sharpening CVSS with Asset Context - Clayton Fields, Michael Assraf - ESW #208 from 2020-11-27T22:00

Vulnerability prioritization has traditionally relied on CVSS scores and other subjective measurements (e.g. asset tagging) that don't factor in internal context. A new approach integrates asset...

Listen
Paul's Security Weekly TV
Which Multifactor Authentication is the Right One? - Matt Barnett - ESW #208 from 2020-11-27T10:00

It's widely-accepted that multifactor is a best practice for authentication, but there are a variety of implementations (e.g., smart cards, push notifications, OTPs). We'll talk through the bene...

Listen
Paul's Security Weekly TV
Drupal Vulnerability, Sectigo DevOps Integrations, & Vulnerable Fortinet VPNs - ESW #208 from 2020-11-26T22:00

This week, Why Companies Should Outsource Cybersecurity During COVID and Beyond, Sectigo Adds Five PKI DevOps Integrations, a Drupal vulnerability press statement from ExtraHop, Palo Alto Networ...

Listen
Paul's Security Weekly TV
Compliance Topic: Cyber Credit Score Industry - SCW #53 from 2020-11-26T10:00

Someone made an offhand comment about the Cyber Credit Score Industry on one of our shows a couple weeks ago, so we thought we'd bring it up as a compliance topic. We'll define what we're talkin...

Listen
Paul's Security Weekly TV
Zero Trust Intersects XDR in Today’s Digital Era - Zulfikar Ramzan, Ph.D. - SCW #53 from 2020-11-25T22:00

The rapid shift to distributed work, along with radical changes in human behavior, is expanding digital risk for organizations and creating new opportunities for malicious actors. As such, organ...

Listen
Paul's Security Weekly TV
Creative Mindsets, Reaching Goals, & Encouraging Accountability - BSW #197 from 2020-11-25T10:00

In the Leadership and Communications segment, we discuss the creative mindset, CMMC challenges, work from home security is still lacking security, you may not get it right the first time, reachi...

Listen
Paul's Security Weekly TV
Cybersecurity & Integrated Risk Management - Top 10 for Trend 2021 - M. James Gomez - BSW #197 from 2020-11-24T22:00

Key Points:

  • Being Strategic is vital and relevant to a successful Cybersecurity Program
  • Understanding Organization Status of controls in real-time is a competitive advantag...

    Listen
Paul's Security Weekly TV
Drupal Flaws, DevSecOps Implementation, & Cloud Native Security White Paper - ASW #131 from 2020-11-24T10:00

In the Application Security News, a manifesto highlights principles and values for threat modeling, the CNCF releases a Cloud Native Security Whitepaper, Microsoft put security in the CPU with P...

Listen
Paul's Security Weekly TV
Threat Modeling Deep Dive - ASW #131 from 2020-11-23T22:00

We threat model every day without realizing it. And, of course, we often threat model with systems and products within our organizations. So how formal does our approach need to be? How do we be...

Listen
Paul's Security Weekly TV
IoT Cybersecurity Improvement Act, TCL Smart TV Flaw, & Popping Reverse Shells - PSW #675 from 2020-11-22T10:00

In the Security News, Verizon has suggestions on how to make DNS more secure, Microsoft is trying to fix another Kerberos vulnerability, Bumble made some security blunders, why trying to write a...

Listen
Paul's Security Weekly TV
Understanding How Data Science Applies to Infosec - Michael Roytman - PSW #675 from 2020-11-21T22:00

Michael takes us through some of the common AI and ML methods of data science and how they apply to our InfoSec problems.

 

This segment is sponsored by Kenna Security. Visit Listen

Paul's Security Weekly TV
Threat Actors & Recent Trends - Jamie Fernandes, Karsten Chearis - PSW #675 from 2020-11-21T10:00

Jamie and Karsten join us for a discussion about recent attack trends, threat actors, and campaigns carried out by malicious threat actors. Everything from gift card scams to the latest techniqu...

Listen
Paul's Security Weekly TV
The Future of Osquery - Ganesh Pai, Julian Wayte - ESW #207 from 2020-11-20T22:00

Osquery has grown in popularity because of its broad applicability in enterprise environments. In this tech segment, Ganesh Pai and Julian Wayte from Uptycs will talk about how organizations are...

Listen
Paul's Security Weekly TV
How Network Detection Helps Fill The Gaps - Steve Porcello - ESW #207 from 2020-11-20T10:00

The recent surge of ransomware attacks has highlighted a shift in tactics employed by threat actors looking to extort organizations. Their methodology has changed from a quick, opportunistic att...

Listen
Paul's Security Weekly TV
AlgoSec CloudFlow, AWS Network Firewall, & Sysdig Zero Trust - ESW #207 from 2020-11-19T22:00

In the Enterprise News, the all new AWS Network Firewall, Zero Trust for kubernetes, interactive coding simulations, DNS monitoring, and Twitter appoints a new head of security! The latest acqui...

Listen
Paul's Security Weekly TV
What's in It for Us? - Adrian Sanabria - SCW #52 from 2020-11-19T10:00

We're continuing the discussion with Adrian Sanabria and exploring if and how the plans for CRA/Security Weekly will impact the Security & Compliance Weekly audience!

 

Visit Listen

Paul's Security Weekly TV
Who Are You? - Adrian Sanabria - SCW #52 from 2020-11-18T22:00

An Interview with the newest member of the CRA/Security Weekly family, Adrian Sanabria! What is his role at Security Weekly, and what is the plan for rolling things out over the next 12-18 month...

Listen
Paul's Security Weekly TV
The CISO's Dilemma, 7 Cybersecurity Predictions, & 5 Cloud Considerations - BSW #196 from 2020-11-18T10:00

In the Leadership and Communications section, The CISO’s Dilemma: Balancing Security, Productivity With a Housebound Workforce, Seven cybersecurity predictions for 2021, Avoiding cloud sprawl: 5...

Listen
Paul's Security Weekly TV
The C-Suite's Risk Mitigation Strategy - Kevin O'Brien - BSW #196 from 2020-11-17T22:00

Email security is transitioning into being one of the top security pillars within the C-Suite’s risk mitigation strategy. Given that it’s the largest attack vector – not only based on the quanti...

Listen
Paul's Security Weekly TV
'Platypus' Attack, IDOR DOD Bug, & 2 More Chrome 0-Days - ASW #130 from 2020-11-17T10:00

In the Application Security News, The Platypus Attack Threatens Intel SGX, a Revitalized Attack Makes for Sad DNS, Bug Hunter Hits DOD With an IDOR, Steps for Devops, Testing in Prod, Two More C...

Listen
Paul's Security Weekly TV
Automated Hacker Knowledge - Rickard Carlsson - ASW #130 from 2020-11-16T22:00

In a fast-paced tech environment, keeping up with security research can be overwhelming for companies. Automation is a must to keep up - but you also need human ingenuity to make sure automation...

Listen
Paul's Security Weekly TV
Cobalt Strike Leak, DNS Cache Poisoning, & Decrypting Open SSH - PSW #674 from 2020-11-15T10:00

In the Security News, not all cyberattacks are created equal, Google patches two more Chrome zero days, What does threat intelligence really mean, Cobalt Strike leaked source code, DNS cache poi...

Listen
Paul's Security Weekly TV
Challenges With Securing Container Environments - Badri Raghunathan, Sumedh Thakar - PSW #674 from 2020-11-14T22:00

Sumedh and Badri discuss challenges associated with container Security & DevOps need for visibility into containers. Qualys' new approach to runtime security.

 

This segment is spo...

Listen
Paul's Security Weekly TV
Disrupt Attacks at the Endpoint with Attivo Networks - Joseph Salazar - PSW #674 from 2020-11-14T10:00

Attackers have repeatedly demonstrated that they can evade perimeter defenses to compromise a system inside the network. Once they get in, they must break out from that beachhead, conduct discov...

Listen
Paul's Security Weekly TV
SWVHSC Micro Interviews: Secure Circle & Vicarius - Jeff Capone, Roi Cohen - ESW #206 from 2020-11-13T22:00

Secure Circle: For a true Zero-Trust environment, it isn’t enough to think about data in cloud services and SaaS applications, we also must protect, control and audit data that egresses form the...

Listen
Paul's Security Weekly TV
BotRx Widgets, New Kasada API, & White Ops Bot Protection - ESW #206 from 2020-11-13T10:00

In the Enterprise News, BotRx widgets provide analytical context on how attacks impact business operations, New Kasada API protects from botnet attacks and targeted fraud, White Ops Offers Expan...

Listen
Paul's Security Weekly TV
Getting Google Scale Threat Detection With Chronicle Detect - Trevor Welsh - ESW #206 from 2020-11-12T22:00

Chronicle brings Google-scale threat detection to enterprises with the debut of its threat detection solution, Chronicle Detect. It includes a rules engine that operates at the speed of search, ...

Listen
Paul's Security Weekly TV
Data, Data, Data - Part 2 - Liam Downward - SCW #51 from 2020-11-12T10:00

The conversation continues about data classification!

 

This segment is sponsored by CYRISMA. Visit https://securityweekly.com/cyrisma...

Listen
Paul's Security Weekly TV
Data, Data, Data - Part 1 - Liam Downward - SCW #51 from 2020-11-11T22:00

You've scanned your data to uncover risks and vulnerabilities and assigned accountability through mitigation plans to meet compliance mandates. Now you must classify, rank, prioritize and score ...

Listen
Paul's Security Weekly TV
5 Mistakes, 5 Best Practices, & CEOs Focus for 2021 - BSW #195 from 2020-11-11T10:00

In the Leadership and Communications section, How to Be a Visionary Leader and Still Have a Personal Life, 5 Mistakes CISOs Make in Their Board Presentations, What are CEOs focused on for next y...

Listen
Paul's Security Weekly TV
Cybersecurity Forecast: Cloudy With a Chance of Turbulence - Mike Lloyd - BSW #195 from 2020-11-10T22:00

All our networks are hybrid now. Some old security challenges were solved by cloud migration, but we've just swapped them for some new ways to get things wrong. What's the best way forward?

...

Listen
Paul's Security Weekly TV
Security Is a Feature - Keith Hoodlet - ASW #129 from 2020-11-10T10:00

What does it take to manage security teams and security initiatives? Find out the importance of people in security, whether it's keeping a team engaged or encouraging a team to rethink how they ...

Listen
Paul's Security Weekly TV
China's Top Hacking Contest, GitHub Actions, & Vulnonym - ASW #129 from 2020-11-09T22:00

China's top hacking contest turns months of effort into 15 minutes of exploits, an injection flaw in GitHub Actions, understanding post-compromise activity in exploits targeting Solaris and VoIP...

Listen
Paul's Security Weekly TV
Multiple iOS 0-Days, Intel Malware Defense, & Windows 0-Day Under Attack - PSW #673 from 2020-11-08T10:00

In the Security News, Deception Technology: No Longer Only A Fortune 2000 Solution, Windows 10 zero-day could allow hackers to seize control of your computer, A Nameless Hiker and the Case the I...

Listen
Paul's Security Weekly TV
Proactive Security Using Runbooks - Dan DeCloss - PSW #673 from 2020-11-07T22:00

Runbooks can be a game changer when it comes to executing proactive security assessments and tabletop exercises. This segment will highlight how to use runbooks to enhance your proactive securit...

Listen
Paul's Security Weekly TV
Abusing JWT (JSON Web Tokens) - Sven Morgenroth - PSW #673 from 2020-11-07T10:00

Learn how JWTs are implemented, both the correct way and the insecure way. Spoiler alert, most implement them insecurely. Sven will also show you some of the common attacks against JWTs, for use...

Listen
Paul's Security Weekly TV
Why Network Detection/Response Belongs In Your 2021 Strategy - Mike Campfield - ESW #205 from 2020-11-06T22:00

The sudden shift to remote work rocked IT teams around the world–disrupting systems that had been carefully designed to keep the business secure almost overnight. As remote work continues, IT te...

Listen
Paul's Security Weekly TV
Massive Cyberattack Spreading Across 68% of Organizations - Kevin O'Brien - ESW #205 from 2020-11-06T10:00

A current and active cyberattack is spreading rapidly across organizations, propagating via open redirector domains and subsidiary domains belonging to multiple global brands. The comprehensive ...

Listen
Paul's Security Weekly TV
The Benefits of Online, On-Demand Training For Teams - Mike Gruen - ESW #205 from 2020-11-05T22:00

Offsite-training is expensive and inefficient. It takes key resources away from their jobs and then demands even more time from them by requiring that they then train the rest of the team on wha...

Listen
Paul's Security Weekly TV
Cloud Computing Compliance: Intelligent vs Basic Automations, Part 2 - Frank Macreery - SCW #50 from 2020-11-05T10:00

The conversation continues on how intelligent automations can simplify cloud computing compliance.

 

This segment is sponsored by Aptible. Visit Listen

Paul's Security Weekly TV
Cloud Computing Compliance: Intelligent vs Basic Automations, Part 1 - Frank Macreery - SCW #50 from 2020-11-04T22:00

Cloud computing services have become the norm for companies — even on-prem die-hards are using hybrid models. This leads to an increased need for compliance evidence. There are more controls in ...

Listen
Paul's Security Weekly TV
The Dark Side, CISO Transition, & Communicate in Bursts - BSW #194 from 2020-11-04T10:00

In the Leadership and Communications section, The Dark Side Of Authentic Leadership, Why CISOs must be students of the business, Top IT certifications and degrees to help you advance your career...

Listen
Paul's Security Weekly TV
How to Develop Your Cybersecurity Skills - Marie Ketner - BSW #194 from 2020-11-03T22:00

Marie Ketner from Cybrary joins BSW to discuss how to develop your cybersecurity skills to address your key use cases, including: 1. Skills Development 2. On-boarding 3. Industry Certifications ...

Listen
Paul's Security Weekly TV
Lax IoT, Adobe Flash Croaks, Link Preview Vulns, & Security Theatre! - ASW #128 from 2020-11-03T10:00

Lax IoT security exposes smart-irrigation systems, Adobe Flash goes truly end of line in one last update, confidential computing gets a turbo boost with Nitro, link previews show security and pr...

Listen
Paul's Security Weekly TV
Azure App Service & Cloud-Native Signal Sciences Deployments - Alfred Chung - ASW #128 from 2020-11-02T22:00

Discussing what enterprises have to do while adapting legacy apps in to Azure, while doing in a secure, steady way without leaving any gaps. Signal Sciences site extension makes sure your apps a...

Listen
Paul's Security Weekly TV
JavaScript Web Tokens, NVIDIA GeForce Experience Vulns, & Hacking Coffee Pots - PSW #672 from 2020-11-01T09:00

In the Security News, the KashmirBlack botnet is behind attacks on CMSs such as WordPress, Joomla, and Drupal, Cybercriminals are Coming After Your Coffee, irrigation systems and door openers ar...

Listen
Paul's Security Weekly TV
How Computer Vision Balances Thoroughness & Speed - PSW #672 from 2020-10-31T21:00

Polarity uses computer vision that works like augmented reality for your data. It's not a new dashboard to search or a new portal to manage. Polarity augments your existing workflows, enriching ...

Listen
Paul's Security Weekly TV
Determining Vulnerability Exploitation With Real Software Activity - PSW #672 from 2020-10-31T09:00

Only integrating vulnerability characteristics to determine risk leaves half the prioritization canvas empty. Observing and analyzing user interaction and other surrounding software characterist...

Listen
Paul's Security Weekly TV
Attacking & Defending Cloud Infrastructure - Alexi Papaleonardos - ESW #204 from 2020-10-30T21:00

CrowdStrike's broad visibility into incidents at organizations from every sector, around the globe has yielded insights into current trends in security incidents related to public clouds such as...

Listen
Paul's Security Weekly TV
Conditional Data Access for Endpoints - Jeff Capone - ESW #204 from 2020-10-30T09:00

Most folks think about using Conditional access for SaaS applications or access to specific data sources. However, once that data is accessed how do you continuously enforce conditional access "...

Listen
Paul's Security Weekly TV
Blackpoint RISK, GrammaTech CodeSentry, & Fortinet Secure SD-WAN - ESW #204 from 2020-10-29T21:00

Blackpoint Cyber introduces insurance for customers and MSPs, Qualys Extends Integration with Microsoft Azure Defender, GrammaTech CodeSentry now identifies third party code vulnerabilities, Att...

Listen
Paul's Security Weekly TV
Logging, Monitoring, and SIEM, Oh My! - Alain Espinosa - SCW #49 from 2020-10-29T09:00

Security monitoring tends to be a topic that companies either avoid, because it sounds too complicated or they tried it and were inundated with data. With proper tuning and asset clarification, ...

Listen
Paul's Security Weekly TV
Third Party Risk Assessment: What's in Your Supply Chain? - Frank Price - SCW #49 from 2020-10-28T21:00

An introduction to CyberGRX and how to get companies working together safely and efficiently. Topics: - Third-party risk management and importance for your organization - The nature of bilateral...

Listen
Paul's Security Weekly TV
Board Risks, Selling Lemons, & 4 Critical Strategies - BSW #193 from 2020-10-28T09:00

In the leadership and communications section, Cybersecurity, a risk to all board of directors , Is The Cybersecurity Industry Selling Lemons? Apparently Lots Of Important CISOs Think it Is, 4 cr...

Listen
Paul's Security Weekly TV
Scale Your SOC: Protecting Against Browser-Based Threats - Matt Ashburn - BSW #193 from 2020-10-27T21:00

Silo is a cloud-based web isolation platform that separates the things you care about from the things you cannot trust. In this segment, former CIA cyber security officer Matt Ashburn will demon...

Listen
Paul's Security Weekly TV
Cyber Risk in Industrial IoT, Firefox 'Site Isolation', & Chrome 0-Day Bug - ASW #127 from 2020-10-27T09:00

NSA publishes list of top vulnerabilities currently targeted by Chinese hackers, Nvidia Warns Gamers of Severe GeForce Experience Flaws, Addressing cybersecurity risk in industrial IoT and OT, F...

Listen
Paul's Security Weekly TV
Cyber Resiliency Through Self-Healing Cloud Infrastructure - Cesar Rodriguez - ASW #127 from 2020-10-26T21:00

With the increased development velocity in cloud environments, cyber resilience is now more important than ever. To achieve cyber resiliency, security needs to be codified through the developmen...

Listen
Paul's Security Weekly TV
Discord Vulnerabilities, Chrome 0-Day, & Severe WordPress Flaw - PSW #671 from 2020-10-25T09:00

In the Security News, Testing firm NSS Labs closes up shop, stringing vulnerabilities together to pwn the Discord desktop app, a Wordpress plugin aimed at protecting Wordpress does the opposite,...

Listen
Paul's Security Weekly TV
Hackers Hitting Below The Belt - Scott Scheferman - PSW #671 from 2020-10-24T21:00

In 2020 attackers are increasingly targeting firmware and hardware - going below the operating system to hide from traditional security solutions and gain persistence. Both nation state actors a...

Listen
Paul's Security Weekly TV
Sysmon Endpoint Monitoring, Now w/ Clipboard Voyeurism - Corey Thuen - PSW #671 from 2020-10-24T09:00

Sysmon is a free endpoint monitoring tool published by Microsoft in their sysinternals suite. It generates process creations, network connections, file creations, DNS, and now clipboard monitori...

Listen
Paul's Security Weekly TV
deepwatch Lens Score & Series B - Corey Bodzin - ESW #203 from 2020-10-23T21:00

deepwatch formally launched its Lens Score app on October 20th. Corey joins us to discuss the app, its future, and how it helps CISOs achieve their security outcomes. Corey will also discuss the...

Listen
Paul's Security Weekly TV
Prioritization to Prediction Vulnerability Research Series - Ed Bellis - ESW #203 from 2020-10-23T09:00

Organizations have millions of vulnerabilities. And our research has shown that those same organizations, large or small, on average, can only fix about one in ten of those vulnerabilities. But ...

Listen
Paul's Security Weekly TV
Prisma Cloud 2.0, Blackpoint RISK, & Tenable Lumin - ESW #203 from 2020-10-22T21:00

Palo Alto Networks announces cloud native security platform, Akamai launches new API security tool, SentinelOne secures patent for unique approach to uncovering exploits in their initial payload...

Listen
Paul's Security Weekly TV
How Backdoors Lead To Breaches & GRC Compliance Issues - David Mundhenk, Ivan Tsarynny - SCW #48 from 2020-10-22T09:00

The client-side or the front end of web applications, aka ‘digital user experience’, actively ingests customer/user information via forms. As the web app's front-end code runs on unmonitored dev...

Listen
Paul's Security Weekly TV
Integrated Risk Management & Operational Resiliency - Steve Schlarman - SCW #48 from 2020-10-21T21:00

2020 has been the perfect storm for risk management planners and practitioners. Steve Schlarman, Director of Product Marketing and GRC Strategist for RSA Archer will provide anecdotes and lesson...

Listen
Paul's Security Weekly TV
CISO Stressbusters, Infosec Hiring, & Narrowing Communication Gaps - BSW #192 from 2020-10-21T09:00

In the Leadership and Communications segment, 96% of Cybersecurity Professionals are Happy With Their Roles, 4 Tips for Effective Virtual Collaboration, What’s Really Happening in Infosec Hiring...

Listen
Paul's Security Weekly TV
Security Money - BSW #192 from 2020-10-20T21:00

This week we update you on the Security Weekly 25 Index... Here's the companies we're tracking: Symbol Company Name SCWX Secureworks Corp PANW Palo Alto Networks Inc CHKP Check Point Software Te...

Listen
Paul's Security Weekly TV
Windows "Ping of Death", SonicWall VPN RCE , & MediaTek BootROM Glitch - ASW #126 from 2020-10-20T09:00

Patch Your Windows - “Ping of Death” bug revealed, 800,000 SonicWall VPNs vulnerable to remote code execution bug, T2 Exploit Team Creates Cable That Hacks Mac, Zoom Rolling Out End-to-End Encry...

Listen
Paul's Security Weekly TV
The Future of Application Security Testing (AST) - Taylor McCaslin - ASW #126 from 2020-10-19T21:00

Join Taylor McCaslin, Security Product Manager at GitLab to discuss current trends in the application security testing industry. We'll chat about where the industry is at today and discuss advan...

Listen
Paul's Security Weekly TV
'BleedingTooth' Vulnerability, Zoom Rolls Out E2EE, & 50,000 Cameras Compromised - PSW #670 from 2020-10-18T09:00

In the Security News, Microsoft Uses Trademark Law to Disrupt Trickbot Botnet, Barnes & Noble cyber incident could expose customer shipping addresses and order history, Zoom Rolls Out End-to-End...

Listen
Paul's Security Weekly TV
Democratizing & Saasifying Security Operations - Patrick Garrity - PSW #670 from 2020-10-17T21:00

Threats are no longer only a concern of large sophisticated organizations and there is a continued need to democratize security operations and controls so they are accessible to organizations of...

Listen
Paul's Security Weekly TV
Prioritize This, Prioritize That, Prioritize With Context! - Roi Cohen, Shani Dodge - PSW #670 from 2020-10-17T09:00

Software vulnerabilities are exploding in growth at an unprecedented rate, and security teams are struggling to stay afloat. Lifebuoys (i.e. CVSS base scores) aren’t doing much to save them, eit...

Listen
Paul's Security Weekly TV
SWVHSC Micro Interviews: CYRISMA & Mimecast - Liam Downward, Matthew Gardiner - ESW #202 from 2020-10-16T21:00

Simplifying The Process Of Identifying, Assessing & Mitigating Risks: Liam Downward, CEO of CYRISMA, talks about burdensome technologies that generate bloat within any organization, high licensi...

Listen
Paul's Security Weekly TV
Social Engineering Attacks Through Vishing & Phishing - Whitney Maxwell - ESW #202 from 2020-10-16T09:00

Learn about some of the latest techniques attackers are using when phishing and vishing, including how to protect your users!

 

This segment is sponsored by Rapid7. Visit Listen

Paul's Security Weekly TV
Datadog Deployment Tracking, 'Bad Neighbor' Vulnerability, & Aqua's Trivy - ESW #202 from 2020-10-15T21:00

Bad Neighbor Vulnerability, FireEye Announced ‘Mandiant Advantage: Threat Intelligence’ SaaS-based Offering, Aqua’s Trivy Now Available as a GitHub Action, Datadog adds Deployment Tracking to it...

Listen
Paul's Security Weekly TV
CMMC - SCW #47 from 2020-10-15T09:00

While we're on the topic of doing business with the federal government, we'll provide an update on the goings on of Cybersecurity Maturity Model Certification (CMMC). We've invited Mike Brooks t...

Listen
Paul's Security Weekly TV
Turning Cybersecurity Challenges Into a Competitive Advantage - Mike Brooks - SCW #47 from 2020-10-14T21:00

Mike Brooks will talk to us about his transition from cybersecurity roles in the DoD to roles in the private sector. He currently works as vCISO for Abacode, a company that is providing a next-g...

Listen
Paul's Security Weekly TV
The 4 C's of Leadership with Michael Santarcangelo - BSW #191 from 2020-10-14T09:00

In the Leadership and Communications section, we go off script. Michael Santarcangelo joins me for a discussion on leadership. I want to review the 4 C's of Leadership: 1. Culture 2. Collaborati...

Listen
Paul's Security Weekly TV
Navigating Complexity: Orienting Your Security Solutions - Mike Lloyd - BSW #191 from 2020-10-13T21:00

Typical security teams have 20-50 technologies, and enough staff to be expert in about 3 of them. This makes taming complexity very challenging - the short staffing is showing no signs of lettin...

Listen
Paul's Security Weekly TV
Fortinet SIEM RCE, Facebook Bug Bounty, & Anti-Virus Vulnerabilities - ASW #125 from 2020-10-13T09:00

Redefining Impossible: XSS without arbitrary JavaScript, API flaws in an "unconventional" smart device, Facebook Bug Bounty Announces "Hacker Plus", Anti-Virus Vulnerabilities, and Chrome Introd...

Listen
Paul's Security Weekly TV
Application Security Best Practices - James Manico - ASW #125 from 2020-10-12T21:00

Managing passwords is a critical developer task. Developers tasked with building or augmenting legacy authentication systems have a daunting task when facing modern adversaries. This session wil...

Listen
Paul's Security Weekly TV
10 Years Since Stuxnet, Rare Bootkit Discovered, & Thin Client Vulnerabilities - PSW #669 from 2020-10-11T09:00

US Air Force slaps Googly container tech on yet another war machine to 'run advanced ML algorithms', Rare Firmware Rootkit Discovered Targeting Diplomats, NGOs, Hackers exploit Windows Error Rep...

Listen
Paul's Security Weekly TV
Assembling Your First Infosec Home Lab - Tony "tjnull" Punturiero - PSW #669 from 2020-10-10T21:00

Assembling an infosec home lab is great way to learn more about the ever-changing programs and systems in the cyber world. However, it can get complicated to figure out what you really need to g...

Listen
Paul's Security Weekly TV
Fast And Secure Web - Alexander Krizhanovsky - PSW #669 from 2020-10-10T09:00

Tempesta FW is an open source hybrid of an HTTPS accelerator and a firewall aiming to accelerate web resources and protect them against DDoS and web attacks. The project is built into the Linux ...

Listen
Paul's Security Weekly TV
2020 Threat Hunting Report: Insights From the CrowdStrike OverWatch Team - Jen Ayers - ESW #201 from 2020-10-09T21:00

Falcon OverWatch, the CrowdStrike® elite team of threat hunters, has the unparalleled ability to see and stop the most sophisticated threats, leaving adversaries with nowhere to hide. In this se...

Listen
Paul's Security Weekly TV
Trading Least Privilege for Security Theater - Cris Neckar - ESW #201 from 2020-10-09T09:00

The appearance of safety and actual security often do not align as closely as we would like to think. As enterprise security products get "smarter", the access that they require to your most sen...

Listen
Paul's Security Weekly TV
PingOne Services, Digital Shadows Key Alerts, & Azure Implements Datadog - ESW #201 from 2020-10-08T21:00

Anchore Rolls Out Open Source DevOps Tools, Rapid7 Cloud Identity and Access Management Governance Module for DivvyCloud, Digital Shadows launches access key alerts, Microsoft Azure customers ca...

Listen
Paul's Security Weekly TV
Ransomware Attacks - SCW #46 from 2020-10-08T09:00

How Security & Compliance fails and what to do about it.

Visit https://www.securityweekly.com/scw for all the latest episodes!

Sho...

Listen
Paul's Security Weekly TV
SCW's First Anniversary/Recap - SCW #46 from 2020-10-07T21:00

We're going to look back on our favorite episodes of the first year, reflect on how we are doing, solicit feedback from listeners, look ahead to the future/coming year - what to expect.

 ...

Listen
Paul's Security Weekly TV
The Power of True Peer-to-Peer Collaboration - Parham Eftekhari - BSW #190 from 2020-10-07T09:00

Parham Eftekhari provides an overview of the Cybersecurity Collaborative and why the nation's top CISOs are rediscovering the power of true peer-to-peer collaboration.

 

Visit Listen

Paul's Security Weekly TV
Transformational CISO, Metrics, & 5 Simple Ways to Make Better Decisions - BSW #190 from 2020-10-06T21:00

In the Leadership and Communications section, What it takes to be a transformational CISO, Put Your Metrics Where Your Mouth Is, 5 Simple Ways to Make Better Decisions, and more!

 

Listen
Paul's Security Weekly TV
DOMOS 5.8 OS Command Injection, API Shield, & TRB245 Vulnerabilities - ASW #124 from 2020-10-06T09:00

DOMOS 5.8 - OS Command Injection, 4G, 5G networks could be vulnerable to exploit due to ‘mishmash’ of old technologies, Google sets up research grant for finding bugs in browser JavaScript engin...

Listen
Paul's Security Weekly TV
Things Every Developer Should Know About Security - Chris Romeo - ASW #124 from 2020-10-05T21:00

Developers are at the center of properly securing applications. A large number of security issues bury developers. We must understand the things every developer must know about security in order...

Listen
Paul's Security Weekly TV
Ryuk Ransomware Attack, Windows XP Server Leak, & Potential Return to 'Hackers' - PSW #668 from 2020-10-03T09:00

In the Security News, Rumored Windows XP Source Code Leaked Online, Hospitals hit by countrywide ransomware attack, China-linked 'BlackTech' hackers start targeting U.S, a 13-year-old student wa...

Listen
Paul's Security Weekly TV
Intrusion Detection Honeypots: Detection Through Deception - Chris Sanders - PSW #668 from 2020-10-02T21:00

Intrusion Detection Honeypots are fake services, data, and tokens placed inside the network to lure attackers into interacting with them to give away their presence. If you can control what the ...

Listen
Paul's Security Weekly TV
NGINX As An RTMP Proxy - PSW #668 from 2020-10-02T09:00

Paul will discuss his process for creating a docker container for running NGINX as an RTMP proxy for streaming video to multiple services; complete with SSL and authentication.

 

V...

Listen
Paul's Security Weekly TV
Vulnerability Management & the Art of Prioritization of Risk - SCW #45 from 2020-10-01T09:00

There was a pretty extensive discussion on the Discord server during last week's show that we thought was appropriate to discuss on air. Josh kicked off the discussion by asking, "Anybody know a...

Listen
Paul's Security Weekly TV
Data Centric Security - Liam Downward - SCW #45 from 2020-09-30T21:00

Do we know where our sensitive data is located? Is the system that hosts this data free from vulnerabilities, and is it securely configured? How do we assign accountability through mitigation pl...

Listen
Paul's Security Weekly TV
6 Types of CISO, Habits of Highly Effective CISOs, 10 Key Security Projects - BSW #189 from 2020-09-30T09:00

In the Leadership and Communications section, 6 types of CISO and the companies they thrive in, What are the habits of highly effective CISOs, Cybersecurity is Not a Four-Letter Word, and more!<...

Listen
Paul's Security Weekly TV
State of the Managed Detection & Response Market - Ryan Benson - BSW #189 from 2020-09-29T21:00

What makes MDR different from MSSP? What makes a good MDR provider? How do you decide to build your own capabilities, hire an MSSP or ally with an MDR?

 

This segment is sponsored ...

Listen
Paul's Security Weekly TV
Bypassing TikTok's MFA, Instragram RCE, & Chrome Security Updates - ASW #123 from 2020-09-29T09:00

6 Things to Know About the Microsoft 'Zerologon' Flaw, You can bypass TikTok's MFA by logging in via a browser, Instagram RCE: Code Execution Vulnerability in Instagram App for Android and iOS, ...

Listen
Paul's Security Weekly TV
The Difference Between Finding Vulns & Securing Apps - ASW #123 from 2020-09-28T21:00

There's a big difference between finding vulns and securing apps. When we hear the phrase "shift left", what are we actually shifting? Maybe there's something more that security can learn when w...

Listen
Paul's Security Weekly TV
ZeroTrust Data Security - Jeff Capone, Peter Levett - ESW #200 from 2020-09-25T21:00

Data breaches and insider threats are happening, even with costly and complex data protection programs in place. A reimagined approach to data security needs to be taken.

 

This se...

Listen
Paul's Security Weekly TV
Demystifying AI/ML for Cybersecurity - Edward Wu, Ted Driggs - ESW #200 from 2020-09-25T09:00

As attackers grow increasingly sophisticated, artificial intelligence (AI) and machine learning (ML) applications in cybersecurity are no longer a “nice to have.” But after years of being tossed...

Listen
Paul's Security Weekly TV
Code42 Incydr, Microsoft 365 Defender, & Qualys Multi-Vector EDR - ESW #200 from 2020-09-24T21:00

ExaGrid releases version 6.0 with Time-Lock for Ransonware Recovery Feature, Microsoft overhauls 'Patch Tuesday', Palantir to begin New York trading on September 30th, Accenture acquires SALT So...

Listen
Paul's Security Weekly TV
Legal Review of CFAA Supreme Court Case - Priya Chaudhry - SCW #44 from 2020-09-24T09:00

Priya and the SCW hosts take a look at the upcoming Supreme Court case that could potentially redefine or redirect the scope of the Computer Fraud and Abuse Act (CFAA).

 

Visit Listen

Paul's Security Weekly TV
Reducing the Headache of Audit Prep With Automation - Chas Ballew - SCW #44 from 2020-09-23T21:00

Tax season happens once a year but audit preparation can happen multiple times per year for most companies dealing with SOC 2, HIPAA, ISO 27001, PCI, and more. Manual evidence collection, user a...

Listen
Paul's Security Weekly TV
The Anatomy of an Acquisition - BSW #188 from 2020-09-23T09:00

Michael Santarcangelo and Sam Estrella join us for this special segment to discuss the anatomy of an acquisition. A listener request, Michael will walk us through the Security Weekly acquisition...

Listen
Paul's Security Weekly TV
The Power of Context & Collaboration in a Data Driven World - Corey Thuen - BSW #188 from 2020-09-22T21:00

Corey Thuen, the founder of Gravwell, will join us to discuss how to drive better decision making. Context and collaboration are key, but only if you have the data. Gravwell allows the collectio...

Listen
Paul's Security Weekly TV
Project OneFuzz, Bluetooth Spoofing Bug, & Safeguarding Secrets - ASW #122 from 2020-09-22T09:00

Microsoft announces new Project OneFuzz framework, an open source developer tool to find and fix bugs at scale, Bluetooth Spoofing Bug Affects Billions of IoT Devices, Firefox bug lets you hijac...

Listen
Paul's Security Weekly TV
Visualizing & Detecting Threats For Your Custom Application - Justin Massey - ASW #122 from 2020-09-21T21:00

Application logs are critical to DevOps teams for monitoring the performance and health of their apps. Those same logs are just as critical to understanding the security of apps, whether detecti...

Listen
Paul's Security Weekly TV
Zerologon Attack, CrimeOps, & BLESA Bluetooth Flaw - PSW #667 from 2020-09-20T09:00

Three Cybersecurity Lessons from a 1970s KGB Key Logger, MFA Bypass Bugs Opened Microsoft 365 to Attack, How Hackers Can Pick Your LocksJust By Listening, U.S. House Passes IoT Cybersecurity Bil...

Listen
Paul's Security Weekly TV
Elastic Security Opens Public Detections Rules Repo - James Spiteri - PSW #667 from 2020-09-19T21:00

Following the release of our detection engine, Elastic opened up a new GitHub repo of our public detection rules. See: https://github.com/elastic/detection-rules. This is where our security inte...

Listen
Paul's Security Weekly TV
Key Findings From The Newly Released BSIMM11 Report - Mike Ware - PSW #667 from 2020-09-19T09:00

BSIMM11, the latest version of the Building Security In Maturity Model (BSIMM), was created to help organizations plan, execute, measure, and improve their Application Security program/initiativ...

Listen
Paul's Security Weekly TV
Securing Enterprise Digital Transformations - Jimmy Mesta - ESW #199 from 2020-09-18T21:00

The drivers behind transformation, or roadbloacks, come in different forms. Mergers and acquisitions present both security challenges and opportunities for growth. Legacy technology always prese...

Listen
Paul's Security Weekly TV
Current Security Needs Of Modern Enterprise Companies - Ferruh Mavituna - ESW #199 from 2020-09-18T09:00

As organizations grow and get more mature, they are looking for ways to achieve more with less. Join this ESW segment to learn how mature organizations approach web application security at scale...

Listen
Paul's Security Weekly TV
Zscaler Zero Trust Exchange, Gravwell Data Fusion, & CrowdStrike Falcon - ESW #199 from 2020-09-17T21:00

Acunetix new data retention policies, 5 Things to Ask Your Web App Pen Test Provider, Microsoft's open source tool for sniffing out Windows 10 bugs, Datadog unveils support for distributed traci...

Listen
Paul's Security Weekly TV
How We Lost the Cybersecurity War (and What Happens Next) - Part 2 - David King - SCW #43 from 2020-09-17T09:00

David asserts that, from a consumer data and SMB perspective, we've already lost the Cybersecurity War on 2 major fronts. 1) Cybercriminals already have our unalterable PII, yet we're still driv...

Listen
Paul's Security Weekly TV
How We Lost the Cybersecurity War (and What Happens Next) - Part 1 - David King - SCW #43 from 2020-09-16T21:00

David asserts that, from a consumer data and SMB perspective, we've already lost the Cybersecurity War on 2 major fronts. 1) Cybercriminals already have our unalterable PII, yet we're still driv...

Listen
Paul's Security Weekly TV
Cyber Risks, C-Suite Supporting CISOs, & Cybersecurity Spending - BSW #187 from 2020-09-16T09:00

In the Leadership and Communications section, we're playing 3 questions - Does Your Board Really Understand Your Cyber Risks?, How can the C-suite support CISOs in improving cybersecurity?, Thin...

Listen
Paul's Security Weekly TV
Cracks in the Foundation: Understanding the New Endpoint Challenge - John Loucaides - BSW #187 from 2020-09-15T21:00

Cyber adversaries have mastered the art of staying one step ahead of our controls. As endpoint protections grow stronger, attackers have adapted by going further down the stack - targeting firmw...

Listen
Paul's Security Weekly TV
RCE via BACKBLAZE, Microsoft Patch Tuesday, & CRYLOGGER - ASW #121 from 2020-09-15T09:00

BLURtooth vulnerability lets attackers overwrite Bluetooth authentication keys, Microsoft Patch Tuesday, Sept. 2020 Edition, XSS->Fix->Bypass: 10000$ bounty in Google Maps, Academics find crypto...

Listen
Paul's Security Weekly TV
The People & Process of DevOps - Frank Catucci - ASW #121 from 2020-09-14T21:00

Developer friendly appsec; the people, process and culture of DevSecOps. The basics for some and struggles for others.

 

Visit https:/...

Listen
Paul's Security Weekly TV
Chrome Sandbox Exploit, Cisco Jabber CVE, & Lea Snyder w/ BSides Boston - PSW #666 from 2020-09-12T09:00

We welcome special guest Lea Snyder, BSides Boston Organizer, to talk all things BSides Boston 2020 for its 10 year anniversary! In the Security News, Cisco Patches Critical Vulnerability in Jab...

Listen
Paul's Security Weekly TV
Building Security Into the DevOps Lifecycle - Sumedh Thakar - PSW #666 from 2020-09-11T21:00

DevOps has gained momentum over the years as its methods have been used by teams worldwide to accelerate application delivery. But where we continue to struggle is in integrating security into t...

Listen
Paul's Security Weekly TV
The Patchless Horseman - Roi Cohen & David Asraf - PSW #666 from 2020-09-11T09:00

Every time you deploy a patch nothing has ever gone wrong, right? Most of us have been burned by deploying a patch, causing downtime in your environment, getting in trouble with users and manage...

Listen
Paul's Security Weekly TV
Cloud Based Cyber Resiliency - Bradon Rogers - ESW #198 from 2020-09-10T21:00

Bradon describes Mimecast's "cloud-based resilience platform." What problem(s) they are solving. How they solve it in a unique/differentiated way and the value to the customers.

 

...

Listen
Paul's Security Weekly TV
Exploring Identity Security & Its Role in the Modern Enterprise - Corey Williams - ESW #198 from 2020-09-10T09:00

In today’s modern enterprise, where traditional security boundaries have all but disappeared, Identity has become the new security perimeter. In this episode, CyberArk Identity Security expert C...

Listen
Paul's Security Weekly TV
Cynet 360 4.0, YubiKey 5C NFC, & Netskope Cloud Threat Exchange - ESW #198 from 2020-09-09T21:00

Yubico Delivers New Security Key the YubiKey 5C NFC, ManageEngine ADSelfService Plus now supports MFA for VPNs to protect remote workforce, Sysdig partners with VulnDB to strengthen vulnerabilit...

Listen
Paul's Security Weekly TV
Ekran System & Universal Insider Threat Protection - Part 2 - Oleg Shomonko - SCW #42 from 2020-09-09T09:00

Ekran System is a PCI DSS compliance solution that helps you comply with key industry rules and requirements and protect your company from insider threats.

 

This segment is sponso...

Listen
Paul's Security Weekly TV
Ekran System & Universal Insider Threat Protection - Part 1 - Oleg Shomonko - SCW #42 from 2020-09-08T21:00

Ekran System is a universal insider threat protection platform that combines three essential insider security controls: activity monitoring, access management, and identity management. Functiona...

Listen
Paul's Security Weekly TV
Slack RCE, Tesla Dodges Ransomware, & Cisco Router 0-Day - PSW #665 from 2020-09-06T09:00

The NSA Makes Its Powerful Cybersecurity Tool Open Source, The bizarre reason Amazon drivers are hanging phones in trees near Whole Foods, Elon Musk Confirms Serious Russian Bitcoin Ransomware A...

Listen
Paul's Security Weekly TV
Cybersecurity & Patient Safety - Justin Armstrong - PSW #665 from 2020-09-05T21:00

Successful attacks on healthcare entities are steadily increasing. Sophisticated criminals and nation states are focusing more attention on healthcare than ever before. The main goals are to ste...

Listen
Paul's Security Weekly TV
Lovable Security: Be a Data Custodian, Not a Data Owner - Fredrick "Flee" Lee - PSW #665 from 2020-09-05T09:00

Loveable Security: Flee's approach to cybersecurity is that is should be "loveable." He thinks cybersecurity perpetuates a myth of an elite, isolated team of stealth insiders who are seen as enf...

Listen
Paul's Security Weekly TV
SWVHSC Micro Interviews: CrowdStrike & Synopsys - Ian McShane, Michael Borohovski - ESW #197 from 2020-09-04T21:00

This year we’ve seen organizations accelerate their so-called digital transformation almost overnight. Now we’re getting to the point where security leaders and business owners need to stop and ...

Listen
Paul's Security Weekly TV
SWVHSC Micro Interviews: deepwatch & ExtraHop - Corey Bodzin, Michael Sanders - ESW #197 from 2020-09-04T09:00

deepwatch Lens Score - The first SecOps maturity benchmarking and planning app. Answers CISO Questions: How mature is my Security Program? How do I compare to my peers? What one thing should I d...

Listen
Paul's Security Weekly TV
Anchore Enterprise 2.4, Auth0 Bot Detection, & Bitdefender MDR - ESW #197 from 2020-09-03T21:00

Proofpoint's $300 Million buyback program, LogRhythmn Power Users share their use cases, Bitdefender Enhances MDR Service to Increase Proactive Protection and Advanced Detection, Anchore Unveils...

Listen
Paul's Security Weekly TV
Uber Indictments, Part 2 - Priya Chaudhry - SCW #41 from 2020-09-03T09:00

Recent criminal charges against the CSO and CEO of Uber.

 

Visit https://www.securityweekly.com/scw for all the latest episodes! Listen

Paul's Security Weekly TV
Uber Indictments, Part 1 - Priya Chaudhry - SCW #41 from 2020-09-02T21:00

Recent criminal charges against the CSO and CEO of Uber.

 

Visit https://www.securityweekly.com/scw for all the latest episodes! Listen

Paul's Security Weekly TV
7 Keys, 7 Elements, & 7 Quotes - BSW #186 from 2020-09-02T09:00

In the Leadership and Communications section, the lucky 7's have it: 7 Keys to Effective Leadership in Our New Normal, The 7 elements of an enterprise cybersecurity culture, 7 Quotes from Milita...

Listen
Paul's Security Weekly TV
CISO Interview: Role of the CISO, Why Do You Need a vCISO? - Carlos Becerra - BSW #186 from 2020-09-01T21:00

Organizations need a highly skilled security chief to drive fundamental initiatives and align activities to address pressing enterprise needs. Proven CISOs (Chief Information Security Officers) ...

Listen
Paul's Security Weekly TV
GitHub to Ruby 2.7, CISO Success, & Lessons From Uber - ASW #120 from 2020-09-01T09:00

A Tale of Escaping a Hardened Docker container, Four More Bugs Patched in Microsoft’s Azure Sphere IoT Platform, Upgrading GitHub to Ruby 2.7, Upgrading GitHub to Ruby 2.7, Redefining What CISO ...

Listen
Paul's Security Weekly TV
Detecting Threats & Avoiding Misconfigs In The Cloud-Age - Marc Tremsal - ASW #120 from 2020-08-31T21:00

What are challenges for companies moving to the cloud in forms of security? Marc Tremsal, Director of Product Management - Security at Datadog, will discuss these challenges and how he helps sec...

Listen
Paul's Security Weekly TV
Predicting Vulnerabilities In Compiled Code - Roi Cohen & Shani Dodge - PSW #664 from 2020-08-30T09:00

The growth in software vulnerability exploitation creates a need for better prediction capabilities. Over time, there have been shifts in the ways of discovering vulnerabilities in binary code. ...

Listen
Paul's Security Weekly TV
SWVHSC Micro Interviews: Polarity & Netsparker - Ferruh Mavituna, Paul Battista - PSW #664 from 2020-08-29T21:00

Most analysts will tell you that they balance between being thorough and getting the job done quickly. Paul Battista asked the security community to weigh in on this debate. He’ll share what the...

Listen
Paul's Security Weekly TV
Hacking Tesla's Model 3, 28,000 Printers Hijacked, & iOS 14 Privacy Changes - PSW #664 from 2020-08-29T09:00

Google Researcher Reported 3 Flaws in Apache Web Server Software, Medical Data Leaked on GitHub Due to Developer Errors, Experts hacked 28,000 unsecured printers to raise awareness of printer se...

Listen
Paul's Security Weekly TV
Under Pressure - Building Security Into Application Development - Patrick Carey - ESW #196 from 2020-08-28T21:00

A recent study by Enterprise Strategy Group, commissioned by Synopsys, revealed that nearly half of the cybersecurity and development professionals surveyed indicate that their organization know...

Listen
Paul's Security Weekly TV
"Under the Hoodie:" Rapid7's 2020 Pen Testing Report - Kwan Lin - ESW #196 from 2020-08-28T09:00

Penetration testing is the practice of simulating a criminal breach of a sensitive area in order to uncover and fix defensive failures. Rapid7 just released it's 2020 "Under the Hoodie" report w...

Listen
Paul's Security Weekly TV
Elastic Security 7.9, Sumo Logic, & Attivo Networks - ESW #196 from 2020-08-27T21:00

Checkmarx Announces GitLab Integration, Panaseer Automates IRM with Archer Integration, How Attivo Networks Strengthens Active Directory Defense, Elastic Security 7.9 delivers a major milestone ...

Listen
Paul's Security Weekly TV
Pragmatic Approaches to Cybersecurity Maturity, Part 2 - SCW #40 from 2020-08-27T09:00

The SCW Hosts continue the conversation about how to create pragmatic approaches to maturing your cybersecurity program.

 

Reference Slides: Listen

Paul's Security Weekly TV
Pragmatic Approaches to Cybersecurity Maturity, Part 1 - SCW #40 from 2020-08-26T21:00

There are a lot of ways to measure/assess the level of organizational maturity of security programs. But, how do you mature your organization? We will discuss practical steps, like prioritizing ...

Listen
Paul's Security Weekly TV
Disrupting Traditional Security Research & Advisory - Edward Amoroso - BSW #185 from 2020-08-26T09:00

Ed Amoroso spent over 30 years with AT&T and was frustrated with the security research and advisory firms. We all have our stories, but Ed decided to do something about it. He created TAG Cyber ...

Listen
Paul's Security Weekly TV
Employees Resist New Tech, Safer Cloud, & Lowest Data Breaches in 5 Years - BSW #185 from 2020-08-25T21:00

In the Leadership and Communications section, Why Do Your Employees Resist New Tech?, Who’s Responsible for a Safer Cloud?, Publicly Reported Data Breaches Stand at its Lowest Point in 5 Years, ...

Listen
Paul's Security Weekly TV
ATM Attacks, gcploit, & ClusterFuzz - ASW #119 from 2020-08-25T09:00

The Confused Mailman: Sending SPF and DMARC passing mail as any Gmail or G Suite customer, ATM makers Diebold and NCR deploy fixes for 'deposit forgery' attacks, Control Flow Guard for Clang/LLV...

Listen
Paul's Security Weekly TV
DevOps-First Application Security For Mid-Markets - Sundar Krish - ASW #119 from 2020-08-24T21:00

Mid-markets do have AppSec expertise, the current AppSec products are focused on large enterprises and require AppSec expertise. Sken.ai is the new and the only AppSec scan tool, focused on mid-...

Listen
Paul's Security Weekly TV
SWVHSC Micro Interviews: Gravwell & Rapid7 - Corey Thuen, Deral Heiland - PSW #663 from 2020-08-23T09:00

What use cases are addressed by Threat Hunting Platforms and SIEMs? Where is the overlap and where are the differences? Corey Thuen, Founder of Gravwell, covers the high level and low-level tech...

Listen
Paul's Security Weekly TV
Voice Phishers, 'SpiKey' Lock Picking, & Coffee Cup Hackers - PSW #663 from 2020-08-22T21:00

New Microsoft Defender ATP Capability Blocks Malicious Behaviors, Voice Phishers Targeting Corporate VPNs, IBM finds vulnerability in IoT chips present in billions of devices, The Sounds a Key M...

Listen
Paul's Security Weekly TV
Protecting Critical Infrastructure In Hybrid Clouds - Dan Perkins, Harry Sverdlove - PSW #663 from 2020-08-22T09:00

Customers are concerned about protecting critical services such as Active Directory from compromise. It's game over if AD is compromised. AD environments can be heterogeneous; public cloud, on-p...

Listen
Paul's Security Weekly TV
SWVHSC: Micro-Interview - Plextrac & Spirion - Dan DeCloss, Gabe Gumbs - ESW #195 from 2020-08-21T21:00

The concept of purple teaming needs to be expanded to incorporate a culture of collaboration across all proactive and reactive activities within enterprise cybersecurity programs. Learn how Plex...

Listen
Paul's Security Weekly TV
SWVHSC: Micro-Interview - Tanium & Vectra - Anton Chuvakin, Chris Morales, Matt Hastings - ESW #195 from 2020-08-21T09:00

Matt and Anton will discuss the new integration between Tanium and Chronicle, designed for distributed IT in a remote-work world. The two will explore some of the unique challenges that security...

Listen
Paul's Security Weekly TV
ThreatConnect, Auth0 Bot Detection, & Thycotic Identity Bridge - ESW #195 from 2020-08-20T21:00

ThreatConnect Integrates with Microsoft Graph Security API to Strengthen Security Automation, Sectigo unveils Sectigo Quantum Labs to help orgs prepare for quantum computers, Trend Micro to offe...

Listen
Paul's Security Weekly TV
The Principle of Least Privilege & Regulatory Compliance - Matt Tarr - SCW #39 from 2020-08-20T09:00

In this episode we will discuss the overarching importance of securing privileged access throughout the organization as it relates to the overall security posture and compliance requirements. Cy...

Listen
Paul's Security Weekly TV
Matt Tarr, CyberArk - SCW #39 from 2020-08-19T21:00

Matt discusses his position on the Solutions Engineering team at CyberArk. He talks about how his 15 years in Systems and Sales Engineering roles adds a layer of experience at CyberArk. Matt wil...

Listen
Paul's Security Weekly TV
New Problem Solving Strategies, New Priorities, & Jobs With a Future - BSW #184 from 2020-08-19T09:00

In the Leadership and Communications section, CISOs say new problem solving strategies required, How Remote Work is Reshuffling Your Security Priorities and Investments, Security Jobs With a Fut...

Listen
Paul's Security Weekly TV
Ripple20: Finding Vulnerable Devices & Detecting Attacks - Jeff Costlow - BSW #184 from 2020-08-18T21:00

Jeff Costlow, Deputy CISO at ExtraHop, will discuss the challenges of detecting and patching Ripple20. Ripple 20 is a series of zero-day vulnerabilities in a widely used low-level TCP/IP softwar...

Listen
Paul's Security Weekly TV
AWS S3 Crypto SDK, ReVoLTE Attack, & Microsoft Bug Bounties - ASW #118 from 2020-08-18T09:00

Microsoft Bug Bounty Programs Year in Review: $13.7M in Rewards, In-band key negotiation issue in AWS S3 Crypto SDK for golang, Re­VoL­TE attack can decrypt 4G (LTE) calls to eavesdrop on conver...

Listen
Paul's Security Weekly TV
Immutable Security For Immutable Infrastructure - Cesar Rodriguez - ASW #118 from 2020-08-17T21:00

Cesar will demonstrate breach path prediction as well as other features.

 

This segment is sponsored by Accurics. Visit https://secur...

Listen
Paul's Security Weekly TV
Vulnerability Rich - Contextually Blind! - Michael Assraf - PSW #662 from 2020-08-16T09:00

It s not uncommon to find the traditional vulnerability assessment report buried under the CISO family picture, compliance books, and his latest blood pressure test. These reports highlight the ...

Listen
Paul's Security Weekly TV
Adobe RCEs, Amazon Alexa Vulns, & TeamViewer Flaw - PSW #662 from 2020-08-15T21:00

This week, Amazon Alexa One-Click Attack Can Divulge Personal Data, Adobe tackles critical code execution vulnerabilities in Acrobat, Reader, Threat actors managed to control 23% of Tor Exit nod...

Listen
Paul's Security Weekly TV
Why Elastic Is Making Endpoint Security 'Free And Open' - Mike Nichols - PSW #662 from 2020-08-15T09:00

Elastic believes that transparency and collaboration must be the new norm for the greater infosec community to succeed in stopping threats at scale. With many individuals now working from home, ...

Listen
Paul's Security Weekly TV
SWVHSC: Micro-Interview - Bitsight & Threatlocker - Danny Jenkins, Stephen Boyer - ESW #194 from 2020-08-14T21:00

Security professionals need to be thinking of the next evolution of the approach from working from home, specifically focusing on the security of the home network for both employees and third pa...

Listen
Paul's Security Weekly TV
SWVHSC: Micro-Interview - ReversingLabs & Veracode - Chris Wysopal, Mario Vuksan - ESW #194 from 2020-08-14T09:00

Mario Vuksan, CEO and Co-Founder of ReversingLabs discusses modern digital objects, made up of layers of structured code and data, are central to the exchange or storage of information and are b...

Listen
Paul's Security Weekly TV
GreatHorn, JumpCloud App, & Elite Intelligence - ESW #194 from 2020-08-13T21:00

Attivo Networks Announces New Integration with IBM Security Resilient, GreatHorn improves email security with better visibility and intelligent protection, Elite Intelligence Ascends to the Clou...

Listen
Paul's Security Weekly TV
Compliance Without Compromise - Part 2 - Jeanette Manfra - SCW #38 from 2020-08-13T09:00

The discussion continues with Jeanette Manfra.

 

Visit https://www.securityweekly.com/scw for all the latest episodes!

Show...

Listen
Paul's Security Weekly TV
Compliance Without Compromise - Part 1 - Jeanette Manfra - SCW #38 from 2020-08-12T21:00

Government agencies are running in antiquated, fortress-based government clouds under the guise this is the only option for superior security and compliance. However, security and compliance don...

Listen
Paul's Security Weekly TV
Automating Your Vulnerability Management Program - Mehul Revankar, Sumedh Thakar - PSW #661 from 2020-08-08T21:00

In this segment, we discuss the importance of automating the Vulnerability Management Program and discuss Qualys VMDR which takes vulnerability management to the next level bringing detection an...

Listen
Paul's Security Weekly TV
SWVHSC: Netgear Flaws, Satellite Spying, & Stealing UltraLoq Keys - PSW #661 from 2020-08-08T09:00

How hackers could spy on satellite internet traffic with just $300 of home TV equipment, Smart locks opened with nothing more than a MAC address, 17-Year-Old 'Mastermind' and 2 Others Behind the...

Listen
Paul's Security Weekly TV
SWVHSC: Observing Disinformation Campaigns - Chad Anderson - PSW #661 from 2020-08-07T21:00

Chad talks about the DomainTools COVID research (and how they stumbled on the CovidLock Android ransomware), mapping the Reopen Campaigns in more detail. He will then touch on some of the work h...

Listen
Paul's Security Weekly TV
SWVHSC: Mapping MITRE ATT&CK to PCI DSS - Jeff Man - ESW #193 from 2020-08-07T09:00

MITRE ATT&CK seems to be the “next big thing”. Every time I hear about it I can’t help but wonder, “how do you prevent all these attacks in the first place? Shouldn’t that be the end game?” To t...

Listen
Paul's Security Weekly TV
DigiCert Automation Gateway, Veracode Security Labs, & CyberArk Shadow Admin - ESW #193 from 2020-08-06T21:00

Tanium offering new cybersecurity service through a partnership with Google Cloud, CyberArk launches open-source Shadow Admin identification tool for Azure and AWS, Threat Stack Cloud Security P...

Listen
Paul's Security Weekly TV
SWVHSC: Put Zero Trust in Your Devices - John Loucaides - ESW #193 from 2020-08-06T09:00

The recent shift to a remote work environment has created new challenges for many businesses and government institutions with profound impacts on organizational security models. Users are no lon...

Listen
Paul's Security Weekly TV
SWVHSC: "The Failure of Risk Management" - Doug Hubbard - BSW #183 from 2020-08-06T01:15:32

A ground shaking exposé on the failure of popular cyber risk management methods. This book is the first of a series of spinoffs from Douglas Hubbard’s successful first book, How To Measure Anyth...

Listen
Paul's Security Weekly TV
SWVHSC: How Security Spending Overlooks the Biggest Risk of All - Matt Ashburn - BSW #183 from 2020-08-05T09:00

Global spending on cyber security totals over $100 billion per year, with no upper limit in sight as adversaries remain successful at compromising even well-resourced organizations. Why do adver...

Listen
Paul's Security Weekly TV
SWVHSC: Amazon GuardDuty, Sandboxing & Workload Isolation, & No More SHA-1 - ASW #117 from 2020-08-04T21:00

Using Amazon GuardDuty to Protect Your S3, OkCupid Security Flaw Threatens Intimate Dater Details, Florida teen charged as “mastermind” in Twitter hack hitting Biden, Bezos, and others, Sandboxi...

Listen
Paul's Security Weekly TV
SWVHSC: How Does Sec Live In A DevOps World? - Mike Rothman - ASW #117 from 2020-08-04T18:28:08

As you go full DevSecOps, where does that leave security operations? Who makes changes that are required? How do you empower (or deputize) app folks or ops folks (DevOps) to make those operation...

Listen
Paul's Security Weekly TV
GNU GRUB2 Vulnerability, 'BootHole' Secure Boot Threat, & Garmin Ransomware Hack - PSW #660 from 2020-08-01T21:00

A Vulnerability that Allowed Brute-Forcing Passwords of Private Zoom Meetings, Russia's GRU Hackers Hit US Government and Energy Targets, a New tool that detects shadow admin accounts in AWS and...

Listen
Paul's Security Weekly TV
MIDAS - Siddharth Bhatia - PSW #660 from 2020-08-01T09:00

MIDAS uses unsupervised learning to detect anomalies in a streaming manner in real-time and has become a new baseline. It was designed keeping in mind the way recent sophisticated attacks occur....

Listen
Paul's Security Weekly TV
Gravwell Big Bang Release - Corey Thuen - PSW #660 from 2020-07-31T21:00

The Gravwell Data Fusion platform is releasing a major update this week. New features make analyzing logs and network data much easier for new users while still keeping the raw power of a unix-l...

Listen
Paul's Security Weekly TV
Compliance & Fraud Prevention in FinTech - Neira Jones - ESW #192 from 2020-07-31T09:00

Neira Jones discusses how financial services deals with PCI-DSS, other compliance standards, fraud and cyber crime.

 

Visit https://ww...

Listen
Paul's Security Weekly TV
A New Paradigm: Immutable Security - Om Moolchandani - ESW #192 from 2020-07-30T21:00

Learn about a new paradigm dubbed immutable security. What is immutable security? Why has it become more important than before? Infrastructure is being build and deployed with code, hence we can...

Listen
Paul's Security Weekly TV
CloudPassage, VMware Cloud, & Portshift K8SHIELD - ESW #192 from 2020-07-30T09:00

Attivo Networks EDN enhancements prevent attackers from fingerprinting an endpoint, CloudPassage Expands Cloud Security Capabilities for Docker, Kubernetes, and Container-related Services on AWS...

Listen
Paul's Security Weekly TV
Legal Implications of Security & Compliance - Part 2 - SCW #37 from 2020-07-29T21:00

Continuing our discussion with John Snyder, our new co-host. Peppering him with questions about the law, hacking, security, compliance, and we might throw in a few of our favorite lawyer movie q...

Listen
Paul's Security Weekly TV
Marketing & Selling to the CISO - BSW #182 from 2020-07-29T09:00

Marketing to today’s CISO is no easy task. CISOs have an unprecedented amount of work on their plates with constantly shifting technology, vast amounts of data in motion, regulatory requirements...

Listen
Paul's Security Weekly TV
Legal Implications of Security & Compliance - Part 1 - SCW #37 from 2020-07-29T09:00

John Snyder will lead the discussion about the legal implications of Security and Compliance.

 

Visit https://www.securityweekly.com/s...

Listen
Paul's Security Weekly TV
Cybersecurity Challenges in a Teleworking World - Drew Cohen - BSW #182 from 2020-07-28T21:00

Drew Cohen discusses the cybersecurity challenges that have risen with many businesses shifting to WFH environments during the pandemic. We'll review some of the top cybersecurity issues/threats...

Listen
Paul's Security Weekly TV
TaskRouter JS SDK, EL1/EL3 Vulnerability, & 234 Alexa Skills Store Violations - ASW #116 from 2020-07-28T09:00

TaskRouter JS SDK Security Incident, Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability, An EL1/EL3 coldboot vul...

Listen
Paul's Security Weekly TV
Fixing Vulnerabilities Effectively & Efficiently - John Matherly - ASW #116 from 2020-07-27T21:00

What does it take to fix vulns effectively and efficiently? There's no lack of vulns identified from bug bounties and vuln reporting programs, but not every vuln needs the same attention and not...

Listen
Paul's Security Weekly TV
Cisco Security Flaw, Million Dollar Bounties, & Jackpotting ATMs - PSW #659 from 2020-07-26T09:00

Vulnerable Cellular Routers Targeted in Latest Attacks on Israel Water Facilities, Fugitive Wirecard Executive Jan Marsalek Was Involved In Attempt to Purchase Hacking Team Spyware, 8 Cybersecur...

Listen
Paul's Security Weekly TV
The Power of the Cloud Platform: One Single Agent, One Global View - Sumedh Thakar - PSW #659 from 2020-07-25T21:00

Leveraging the unifying power of a cloud-based security platform to provide full context and comprehensive visibility into the entire attack chain for a complete, accurate risk-based analysis an...

Listen
Paul's Security Weekly TV
Affects of COVID-19 on Web Applications - Zane Lackey - PSW #659 from 2020-07-25T09:00

Zane Lackey joins us once again to talk about Zero Trust, Cloud Security, and the impact of COVID-19 on Digital Transformation! This segment is sponsored by Signal Sciences.

 

Visi...

Listen
Paul's Security Weekly TV
An Overview of Black Hat USA 2020 - Steve Wylie - ESW #191 from 2020-07-24T21:00

Tune-in to get the inside scoop on Blackhat 2020! Steve Wylie, Black Hat General Manager, joins us to talk about to what attendees can expect from this year's virtual Blackhat event. Steve discu...

Listen
Paul's Security Weekly TV
Secretless & the End of Application Secrets as We Know Them - Brian Kelly - ESW #191 from 2020-07-24T09:00

Passwords, keys, and other secrets are becoming an outdated technique for applications to use. They are usually over-privileged, easy to steal, and very hard to handle securely. Developers frequ...

Listen
Paul's Security Weekly TV
The Evolution of Enterprise Web Apps & Its Impact on Web Security - Mark Ralls - ESW #191 from 2020-07-23T21:00

Over the last 15 years the web application landscape has changed more dramatically than many might realize, including the exponential growth in the number of web sites, the rise of complex web a...

Listen
Paul's Security Weekly TV
PCI Dream Team - Part 2 - Arthur Cooper, Ben Rothke, David Mundhenk, Jeff Hall - SCW #36 from 2020-07-23T09:00

PCI Dream Team: Ben Rothke, Jeff Hall, David Mundhenk, Art Cooper answer all of the toughest PCI questions, Part 2!

 

Show Notes: h...

Listen
Paul's Security Weekly TV
PCI Dream Team - Part 1 - Arthur Cooper, Ben Rothke, David Mundhenk, Jeff Hall - SCW #36 from 2020-07-22T21:00

PCI Dream Team: Ben Rothke, Jeff Hall, David Mundhenk, Art Cooper answer all of the toughest PCI questions.

 

Show Notes: ht...

Listen
Paul's Security Weekly TV
New CISOs, Overworked CISOs, and 10 Worst Cybersecurity Strategies - BSW #181 from 2020-07-22T09:00

In the Leadership and Communications section, CISOs undervalued, overworked, burning out, warns CIISec, The 10 Worst Cybersecurity Strategies, AppSec Becomes A Priority For New CISOs/CSOs, and m...

Listen
Paul's Security Weekly TV
Zero Trust Execution as Part of Your Cloud Workload Protection Strategy - Justin Bradley - BSW #181 from 2020-07-21T21:00

The use of Application Control - commonly referred to as whitelisting or Zero Trust Execution - is considered to be a robust and essential Cloud Workload Protection strategy, largely due to the ...

Listen
Paul's Security Weekly TV
SIGRed RCE, Google Cloud 'Confidential VMs', & Twitter Hack Crypto Scam - ASW #115 from 2020-07-21T09:00

This week, SIGRed – Resolving Your Way into Domain Admin: Exploiting a 17 Year-old Bug in Windows DNS Servers, Introducing Google Cloud Confidential Computing with Confidential VMs, Internet of ...

Listen
Paul's Security Weekly TV
Cloud Security Posture Management & Governance - Bhasker Nallapothula, Kris Rajana - ASW #115 from 2020-07-20T21:30

Digital transformation is taking the IT industry by storm. As the pace of adoption of public cloud increases, security posture management and governance is usually not top of the mind of cloud e...

Listen
Paul's Security Weekly TV
Twitter Mega Hack, 3rd Party IoT Vulns, & Windows DNS SIGRed RCE - PSW #658 from 2020-07-18T21:00

Microsoft fixes critical wormable RCE SigRed in Windows DNS servers, Zoom Addresses Vanity URL Zero-Day, Docker attackers devise clever technique to avoid detection,a massive DDoS Attack Launche...

Listen
Paul's Security Weekly TV
Welcome Our Newest Host! - John Snyder - PSW #658 from 2020-07-18T09:00

The guys welcome our newest host to the family. John Snyder will replace Matt Alderman on Security and Compliance Weekly. Tune in to hear about how John made the jump from being a trial lawyer i...

Listen
Paul's Security Weekly TV
Artificial Intelligence and Machine Learning in Cybersecurity - Ankur Chowdhary - PSW #658 from 2020-07-17T21:00

With advent of Internet of Things (IoT) and emerging cloud technologies, ensuring continued cybersecurity at scale is a challenging task. An ever growing increase in demand of cybersecurity work...

Listen
Paul's Security Weekly TV
Auditor Meets Security Pt. 2 - SCW #35 - Brian Tremblay - SCW #35 from 2020-07-16T09:00

We continue the discussion with Brian Tremblay, a former auditor who "got religion" when he began to understand the complexities of security and how compliance could help or hinder security prog...

Listen
Paul's Security Weekly TV
Auditor Meets Security Pt. 1 - Brian Tremblay - SCW #35 from 2020-07-15T21:00

Auditor turned security professional joins Security & Compliance Weekly to talk about how security misconfigurations and vulnerabilities can lead to compliance problems and the need for organiza...

Listen
Paul's Security Weekly TV
What's Next, Board Discussions, and New Cybersecurity Priorities for 2020 - BSW #180 from 2020-07-15T09:00

In the Leadership and Communications section, I'm a CISO, what's next?, The Upside of Virtual Board Meetings, The new cybersecurity priorities of 2020, and more!

 

Visit Listen

Paul's Security Weekly TV
Security Money - BSW #180 from 2020-07-14T21:00

This week, it's our quarterly Security Money update of the Security Weekly 25 Index and the Nasdaq. At the close on July 10th, 2020: - SW25 Index is 1,437.23, which is an increase of 43.72% - NA...

Listen
Paul's Security Weekly TV
Top Bug Bounty Rankings, Zoom 0-Day, & Firefox Send Malware - ASW #114 from 2020-07-14T09:00

Microsoft OneDrive client for Windows Qt QML module hijack, Zero-day flaw found in Zoom for Windows 7, Protecting your remote workforce from application-based attacks like consent phishing, Veri...

Listen
Paul's Security Weekly TV
DevSecOps - Judy Ngure - ASW #114 from 2020-07-13T21:00

DevSecOps helps build secure applications and part of that approach means security testing. It takes more than knowing the OWASP Top 10 to make bug bounties successful. From techniques for findi...

Listen
Paul's Security Weekly TV
RCE Chaos, Zoom 0-Day, & Banning TikTok - PSW #657 from 2020-07-12T09:00

Hackers Are Exploiting a 5-Alarm Bug in Networking Equipment, Cisco Talos discloses technical details of Chrome and Firefox flaws, Palo Alto Networks Patches Command Injection Vulnerabilities in...

Listen
Paul's Security Weekly TV
IPv6 Tunneling - Joff Thyer - PSW #657 from 2020-07-11T09:00

In this technical demo, Joff will show how you can bring up an IPv6 tunnel to learn and play with IPv6 connectivity and basic concepts. This tech segment will largely be a demo on a Debian based...

Listen
Paul's Security Weekly TV
Trends In Enterprise Identity - Robb Reck - ESW #190 from 2020-07-10T21:00

Robb Reck, CISO at Ping Identity, joins ESW to discuss the current focus for some companies including , passwordless authentication, focus on customer identity, and zero trust acceleration durin...

Listen
Paul's Security Weekly TV
Living Through a Ransomware Attack - Scott DeLong - ESW #190 from 2020-07-10T09:00

Having helped organizations identify, assess, remediate and recover from a significant ransomware attack, Scott describes the step by step process of events organizations will experience living ...

Listen
Paul's Security Weekly TV
Signal Sciences, Recorded Future, & CipherCloud - ESW #190 from 2020-07-09T21:00

Why You Need Recorded Futures Ultimate Security Intelligence Kit, Securing the Multi-Cloud Environment through CSPM and SSPM, CyberKnight joins forces with Armis to bring agentless EDR to OT, Io...

Listen
Paul's Security Weekly TV
A Hacker's View of Security vs. Compliance - @mzbat - SCW #34 from 2020-07-09T09:00

@mzbat is a frequent speaker at hacker conferences, and likes to help folks prepare for job searches by performing mock interviews and resume reviews.

 

Visit Listen

Paul's Security Weekly TV
A Professional's View of Security vs. Compliance - Kimber Dowsett - SCW #34 from 2020-07-08T21:00

Director of Security Engineering at Truss.

 

Visit https://www.securityweekly.com/scw for all the latest episodes!

Show Not...

Listen
Paul's Security Weekly TV
Post-Pandemic CISO, 5 Threats to Resilience, and Time to Rethink Cyber Security - BSW #179 from 2020-07-08T09:00

In the Leadership and Communications section, Profile of the Post-Pandemic CISO, Time to rethink business continuity and cyber security, Protecting Remote Workers’ Productivity and Performance, ...

Listen
Paul's Security Weekly TV
An Honest Conversation About "Response" - Juan Canales, Matt Cauthorn - BSW #179 from 2020-07-07T21:00

It's time to come out and say it: "response" means something different to every category in cybersecurity. Yet, it's broadly used with little industry definition. In endpoint detection and respo...

Listen
Paul's Security Weekly TV
Protecting Mobile Applications - Catherine Chambers, Will Hickie - ASW #113 from 2020-07-06T21:00

What do you do if your ambition is to provide security for all the mobile apps in the world? You hire a data scientist! Machine Learning is more than just a buzz word, it is the science behind m...

Listen
Paul's Security Weekly TV
Netgear RCE, Guacamole Flaws, & 'Lucifer' DDoS Botnet - PSW #656 from 2020-07-05T09:00

Cisco Releases Security Advisory for Telnet Vulnerability in IOS XE Software, Firefox 78 is out with a mysteriously empty list of security fixes, Python Arbitrary File Write Prevention: The Tarb...

Listen
Paul's Security Weekly TV
OSINT Scraping with Python - Ryan Hays - PSW #656 from 2020-07-04T21:00

With bug bounties becoming more and more main stream for organizations. The bounty hunters are turning to more and more automation. Open source intelligence gathering can be automated with the u...

Listen
Paul's Security Weekly TV
Work From Home Cyber Security - Jerry Chen - PSW #656 from 2020-07-04T09:00

Hackers know that more people are working from home now and accessing/ sending/ sharing sensitive company data through their home networks. How can businesses help employees secure their home ne...

Listen
Paul's Security Weekly TV
Cybersecurity Hiring - Franz Payer - ESW #189 from 2020-07-03T21:00

Given the huge demand for cybersecurity professionals, how can we improve the hiring process to find those who are talented, but may not have an extensive resume? Let's discuss how CTF-style exe...

Listen
Paul's Security Weekly TV
HITRUST Compliance vs. Security & Diversity in InfoSec - Greg Thomas - ESW #189 from 2020-07-03T09:00

Discussing HITRUST compliance in small and medium environments and how to use automation and scalable practices in the cloud to be both compliant and secure.

 

Visit Listen

Paul's Security Weekly TV
SaltStack Enterprise 6.3, Semperis, & SafeGuard 7.6 - ESW #189 from 2020-07-02T21:00

Semperis adds vulnerability assessment, security reporting, and auto-remediation to its DSP, AWS launches Amazon Honeycode to help quickly build mobile and web apps without programming, Attivo N...

Listen
Paul's Security Weekly TV
Cloud Security & Compliance News - SCW #33 from 2020-07-02T09:00

Cloud Security for a Dynamic Environment, Why identity-based, distributed controls are better suited to address cloud-era threats, Top Cloud Security Challenges in 2020, Exposed Cloud Databases ...

Listen
Paul's Security Weekly TV
PCI Workloads in the Cloud - Matt Springfield - SCW #33 from 2020-07-01T21:00

Taking a deeper look into moving PCI related resources into cloud platforms. Public cloud, private cloud, do's, don'ts and can'ts! We will explore key considerations and impacts to security comp...

Listen
Paul's Security Weekly TV
Cybersecurity is a Business Problem,6 Reasons Strategy Fails, 5 Cities for Tech - BSW #178 from 2020-07-01T09:00

In the leadership and communications section, Why Cybersecurity Is Really A Business Problem, 6 Reasons Your Strategy Isn’t Working, 5 cities with the highest tech salaries, and more!

  Listen

Paul's Security Weekly TV
Cybersecurity Challenges in Growth Organizations - Graeme Park - BSW #178 from 2020-06-30T21:00

As part of our CISO interview series, we'll ask Graeme our standard questions, including: How did you get started in security?, What security problems do you face on a daily basis?, How have you...

Listen
Paul's Security Weekly TV
DLL Hijacking, Trust Through Privacy, & Adobe EOL Data - ASW #112 from 2020-06-30T09:00

DLL Hijacking at the Trend Micro Password Manager, Adobe Prompts Users to Uninstall Flash Player As EOL Date Looms, The State of Open Source Security 2020, Microservices vs. Monoliths: Which is ...

Listen
Paul's Security Weekly TV
Using IaC to Establish & Analyze Secure Environments - Cesar Rodriguez - ASW #112 from 2020-06-29T21:00

Teams building Infrastructure as Code still need to ensure that the infrastructure deployed matches the code they created. Not only can IaC help establish secure environments, analyzing that cod...

Listen
Paul's Security Weekly TV
Emerging Security Threats to Your Digital Supply Chain - Jason Fruge - ESW #188 from 2020-06-19T21:00

Despite running the mission-critical applications that power your business, ERP applications, such as SAP and Oracle E-Business Suite, and their custom code are often a cybersecurity blind spot....

Listen
Paul's Security Weekly TV
Debunking DAST Myths & Short-Term Strategies to Fixing Vulnerablities - Ferruh Mavituna - ESW #188 from 2020-06-19T09:00

Paul, Matt, and Ferruh discuss the differences between DAST and other approaches such as SAST and IAST! They will debunk some common DAST myths and then follow-up on their last conversation and ...

Listen
Paul's Security Weekly TV
STELKS 6, CyberArk Alero, & CheckPoint CloudGuard - ESW #188 from 2020-06-18T21:00

BeyondTrust Announces Integration with the SailPoint Predictive Identity Platform, Check Point Launches CloudGuard Cloud Native Security, CyberArk Alero enhancements provide secure privileged ac...

Listen
Paul's Security Weekly TV
How to Become an InfoSec Professional With Limited Resources - SCW #32 from 2020-06-18T09:00

Jeff, Matt, Scott, and Josh continue the conversation and talk "How to Become an InfoSec Professional With Limited Resources"!

 

Visit Listen

Paul's Security Weekly TV
What Is an InfoSec Professional? - SCW #32 from 2020-06-17T21:00

Jeff, Matt, Scott, and Josh talk "What Is An InfoSec Professional?"!

 

Visit https://www.securityweekly.com/scw for all the latest...

Listen
Paul's Security Weekly TV
Virtual CISO, How to Negotiate Virtually, & Endpoint Security - BSW #177 from 2020-06-17T09:00

In the Leadership and Communications section, Five signs a virtual CISO makes sense for your organization, How to Negotiate — Virtually, Why Securing Endpoints Is The Future Of Cybersecurity, an...

Listen
Paul's Security Weekly TV
How CISOs Can Best Prioritize Security With a Decreased Budget - Lewie Dunsworth - BSW #177 from 2020-06-16T21:00

The recent pandemic has been a financial burden across the country while also forcing businesses to transition to a work from home environment where IT and security departments were tasked with ...

Listen
Paul's Security Weekly TV
CallStranger, SMBleedingGhost, & Misconfigured Kubeflow - ASW #111 from 2020-06-16T09:00

CallStranger hits the horror trope where the call is coming from inside the house, SMBleedingGhost Writeup expands on prior SMB flaws that exposed kernel memory, Misconfigured Kubeflow workloads...

Listen
Paul's Security Weekly TV
Data Mapping & Data Value Journey - Michelle Dennedy - ASW #111 from 2020-06-15T21:00

Data management can transform a company. This digital transformation is about more than changing the way users relate to their data. It is about revolutionizing how we work with and think about ...

Listen
Paul's Security Weekly TV
New Web Technology & Impact on Automated Security Testing - Benjamin Daniel Mussler - PSW #655 from 2020-06-14T09:00

As web applications have evolved from static HTML pages into fully-fledged applications with a native feel to them, web browsers continue to provide developers with truly novel functionality. Th...

Listen
Paul's Security Weekly TV
OSS Vulnerabilities, UPnP Flaws, & 0-Days for Bad People - PSW #655 from 2020-06-13T21:00

Hospital-busting hacker crew may be behind ransomware attack that made Honda halt car factories, 3 common misconceptions about PCI compliance, SMBleed could allow a remote attacker to leak kerne...

Listen
Paul's Security Weekly TV
Enhancing Vulnerability Management By Including Penetration Testing Results - Dan DeCloss - PSW #655 from 2020-06-13T09:00

We’ll discuss how organizations can improve their vulnerability management life cycle and demo some quick ways to get started with vulnerability management and combining penetration test results...

Listen
Paul's Security Weekly TV
Building Secure & Reliable Systems - Heather Adkins - ESW #187 from 2020-06-12T21:00

Heather will discuss a new book detailing best practices for designing scalable and reliable systems that are fundamentally secure.

 

Visit Listen

Paul's Security Weekly TV
Vulnerability Management - Scott Kuffer - ESW #187 from 2020-06-12T09:00

In this episode of Enterprise Security Weekly, Nucleus co-founder Scott Kuffer talks about the problems teams face in doing the process of vulnerability management effectively and how Nucleus is...

Listen
Paul's Security Weekly TV
F-Secure, Checkmarx SCA, & Sonatype Nexus - ESW #187 from 2020-06-11T21:00

Morpheus Announces Zero-Trust Cloud Management Platform, Thycotic Releases New Version of DevOps Secrets Vault, Qualys Remote Endpoint Protection gets malware detection, F-Secure launches ID PRO...

Listen
Paul's Security Weekly TV
Compliance News - SCW #31 from 2020-06-11T09:00

Security and Compliance news of the week (or longer - it's our show).

 

Visit https://www.securityweekly.com/scw for all the lates...

Listen
Paul's Security Weekly TV
Navigating the Risks Associated With the Return to "Normal" - Chris Patteson, Robert Carey - SCW #31 from 2020-06-10T21:00

Around the U.S., economies are re-opening and employees are beginning to return to the office. Rob and "C-Pat" will provide perspective on what new compliance and security challenges the public ...

Listen
Paul's Security Weekly TV
Challenges of a New CISO, Security Culture, & Business Communication - BSW #176 from 2020-06-10T09:00

In the Leadership and Communications section, Challenges of a New CISO: The First Year, Why a robust security culture begins with people, How Cybersecurity Leaders Can Chart the Seas of Business...

Listen
Paul's Security Weekly TV
Career Ladders in Information Security - Marc French - BSW #176 from 2020-06-09T21:00

Marc French has more than 25 years of technology experience in engineering, operations, product management, and security. Prior to his current role at CISO at Product Security Group, Marc was th...

Listen
Paul's Security Weekly TV
Zoom Vulns, Apple 0-Days, & Abandoned Domains - ASW #110 from 2020-06-09T09:00

Two vulnerabilities in Zoom could lead to code execution, Zero-day in Sign in with Apple, Focus on Speed Doesn’t Mean Focus on Automation, Apple pushes fix across ALL devices for “unc0ver” jailb...

Listen
Paul's Security Weekly TV
The Future State of AppSec - Phillip Maddux - ASW #110 from 2020-06-08T21:00

Application Security is changing rapidly, and with changes to automation and tooling will look vastly different 5 years from now than it does today. Discuss what those changes will look like, in...

Listen
Paul's Security Weekly TV
Root Cert Chaos, Octopus Scanner, & RobbinHood & the Merry Men - PSW #654 from 2020-06-07T09:00

Octopus Scanner Sinks Tentacles into GitHub Repositories, RobbinHood and the Merry Men, Zoom Restricts End-to-End Encryption to Paid Users, Hackers steal secrets from US nuclear missile contract...

Listen
Paul's Security Weekly TV
PCAPS Or It Didn't Happen- Corey Thuen - PSW #654 from 2020-06-06T21:00

Threat hunting activities often require packet capture analysis but capturing and storing PCAP at scale is rough. This segment covers open source tools for collecting packet captures on demand w...

Listen
Paul's Security Weekly TV
Lightweight Vulnerability Management Using NMAP - PSW #654 from 2020-06-06T09:00

Paul delivers a Technical Segment on Lightweight Vulnerability Management using NMAP!

 

Visit https://www.securityweekly.com/psw f...

Listen
Paul's Security Weekly TV
Security Chaos Engineering - Aaron Rinehart, Casey Rosenthal - ESW #186 from 2020-06-05T21:00

Co-Founder and CEO Casey Rosenthal and Co-Founder and CTO Aaron Rinehart of Verica join us today to talk Chaos Engineering and Security, Continuous Integration, Delivery, Verification, and more!...

Listen
Paul's Security Weekly TV
Unraveling Your Software Bill of Materials - Alyssa Miller - ESW #186 from 2020-06-05T09:00

Whether you are deploying your own software or someone else's software, there are a chain of dependencies that likely includes vulnerabilities. From the base OS image, to utilities, to framework...

Listen
Paul's Security Weekly TV
Dragos, AttackIQ, Cortex XSOAR, & SureCloud - ESW #186 from 2020-06-04T21:00

SureCloud Launches Cyber Resilience Assessment Solution, Blackpoint Cyber launches 365 Defense - a Microsoft 365 security add-on for its MDR service, Endace and Palo Alto Networks Cortex XSOAR e...

Listen
Paul's Security Weekly TV
Regulations, PCI, and IoT Safety - Part 2 - Josh Corman - SCW #30 from 2020-06-04T09:00

Jeff loves PCI DSS. Josh has been a fierce critic of it... and... Josh has been working with public policy... We'll dig into the nuances and offer better ways to tell good from bad policy incent...

Listen
Paul's Security Weekly TV
Regulations, PCI, and IoT Safety - Part 1 - Josh Corman - SCW #30 from 2020-06-03T21:00

Jeff loves PCI DSS. Josh has been a fierce critic of it... and... Josh has been working with public policy... We'll dig into the nuances and offer better ways to tell good from bad policy incent...

Listen
Paul's Security Weekly TV
How to Truly Disrupt Cybercrime - Jen Ellis - BSW #175 from 2020-06-03T09:00

Jen Ellis focuses on cybersecurity policy for Rapid7. Working with governments, manufacturers, and operators, Jen strategizes on policies and practices that will actually disrupt cybercrime at s...

Listen
Paul's Security Weekly TV
CISO vs. CEO, Security Is Not a Technical Problem, How to Be a Great Listener - BSW #175 from 2020-06-02T21:00

In the Leadership and Communications section, CISO vs. CEO: How executives rate their security posture, 3 Reasons Why Cybersecurity Is Not A Technical Problem, How to Be a Great Listener in Remo...

Listen
Paul's Security Weekly TV
Apps Are the New Endpoint - Catherine Chambers - ASW #109 from 2020-06-02T09:00

Apps are everywhere. Increasingly apps are the main entry point for daily services such as banking, home security or even unlocking a car. But mobile devices are untrustworthy: a place where hac...

Listen
Paul's Security Weekly TV
How to Prevent Account Takeover Attacks - John Chirhart - ASW #109 from 2020-06-01T21:00

Attackers are using methods such as password spraying and credential theft to commit fraud against websites at an alarming rate. Automated bots are aiding the attacker to conduct these operation...

Listen
Paul's Security Weekly TV
Ed Skoudis & Security News - PSW #653 from 2020-05-30T09:00

In this week's Security News, NSA warns Russia-linked APT group is exploiting Exim flaw since 2019, Hackers Compromise Cisco Servers Via SaltStack Flaws, OpenSSH to deprecate SHA-1 logins due to...

Listen
Paul's Security Weekly TV
"Burn-In: A Novel of the Real Robotic Revolution" - Peter Singer - PSW #653 from 2020-05-29T21:00

"Burn-In: A Novel of the Real Robotic Revolution" (May 26 release) is a new kind of novel+nonfiction. It uses the technothriller format as a way to share real research on the ways that AI+automa...

Listen
Paul's Security Weekly TV
2020 MITRE ATT&CK Malware Trends - Greg Foss - PSW #653 from 2020-05-29T09:00

The MITRE ATT&CK framework has had a major impact on the cybersecurity industry and has given a defenders a haystack in which to focus their defensive efforts. What’s most interesting, perhaps, ...

Listen
Paul's Security Weekly TV
Cybersecurity Is a Mindset That Cannot Be Taught - Zack Moody - ESW #185 from 2020-05-28T21:00

Security Leadership, Accountability in Security Leadership, and Enforcing Buy-in From the Top!

 

Visit https://www.securityweekly.com/...

Listen
Paul's Security Weekly TV
The Real Value of Identity in a Multi-Vendor IT Environment - Adam Bosnian - ESW #185 from 2020-05-28T09:00

What is the value of identity in a larger security conversation? Why does CyberArk partner with so many technology vendors? What’s the value to you, the customer? It’s an opportunity to talk abo...

Listen
Paul's Security Weekly TV
BeyondTrust, MITRE ATT&CK for ICS, & ThreatConnect - ESW #185 from 2020-05-27T21:00

This week, MITRE ATT&CK for ICS: A Technical Deep Dive, Tufin Expands Security Automation Capabilities, Strengthen Business and Security Alignment with ThreatConnect, BeyondTrust Privilege Manag...

Listen
Paul's Security Weekly TV
Stuxnet, RCE's Everywhere, & Breach Chaos - PSW #652 from 2020-05-24T09:00

In the Security News, Hackers target the air-gapped networks of the Taiwanese and Philippine military, Stored XSS in WP Product Review Lite plugin allows for automated takeovers, Remote Code Exe...

Listen
Paul's Security Weekly TV
HTTP Security Headers In Action - Sven Morgenroth - PSW #652 from 2020-05-23T21:00

HTTP security headers are an easy and effective way to harden your application against all kinds of client side attacks. We'll discuss which security headers there are, what functions they have ...

Listen
Paul's Security Weekly TV
Building An InfoSec Career - Jason Nickola - PSW #652 from 2020-05-23T09:00

The guests on Trust Me I'm Certified have dropped some real knowledge and I'd like to distill that down as well as talk about building technical skills, looking at your career as a 'thing' that ...

Listen
Paul's Security Weekly TV
Dealing With Phishing Attacks Outside of Email - DJ Sampath - ESW #184 from 2020-05-22T21:00

In this segment we'll discuss why email security is still not a solved problem and how now that people are increasingly working from home, it poses an increased risk. We'll also share some inter...

Listen
Paul's Security Weekly TV
Managing Enterprise Security Assessments - Dan DeCloss - ESW #184 from 2020-05-22T09:00

Whether it's an external red team, internal red team, vulnerability scanning data, or a self-assessment questionnaire, results from all of these different types of assessments must be tracked an...

Listen
Paul's Security Weekly TV
Acquisition-Mania, SaltStack Breaches, & RSAC 2021 - ESW #184 from 2020-05-21T21:00

RSA Conference 2021 Changes Date from February to May 2021, Docker partners with Snyk on container image vulnerability scanning, Venafi acquires Jetstack to bring together developer speed and en...

Listen
Paul's Security Weekly TV
The Center for Long-Term Cybersecurity - Part 2 - Ann Cleaveland - SCW #29 from 2020-05-21T09:00

Meet Ann Cleaveland, the Executive Director of the Center for Long-Term Cybersecurity, a research and collaboration think tank housed within the University of California, Berkeley School of Info...

Listen
Paul's Security Weekly TV
The Center for Long-Term Cybersecurity - Part 1 - Ann Cleaveland - SCW #29 from 2020-05-20T21:00

Meet Ann Cleaveland, the Executive Director of the Center for Long-Term Cybersecurity, a research and collaboration think tank housed within the University of California, Berkeley School of Info...

Listen
Paul's Security Weekly TV
Burnt Out CISOS, Build Strategy, and 50+ Security Products - BSW #174 from 2020-05-20T09:00

In the leadership and communications section, Burnt out CISOs are a huge cyber risk, to build strategy, start with the future, 78% of Organizations Use More than 50 Cybersecurity Products to Add...

Listen
Paul's Security Weekly TV
Is the Virtual SOC Our "New Normal"? - Mike Adler - BSW #174 from 2020-05-19T21:00

As many organizations look to their "new normal," remote work will likely be a large piece of that strategy. Adler will dive into the impact this has on the SOC and why EDR should be top-of-mind...

Listen
Paul's Security Weekly TV
Highlights From the New Open Source Security and Risk Analysis Report - Tim Mackey - ASW #108 from 2020-05-19T09:00

The 2020 OSSRA report shows that 91% of commercial applications contain outdated or abandoned open source components. The report, produced by the Synopsys Cybersecurity Research Center (CyRC), e...

Listen
Paul's Security Weekly TV
Using Rate Limiting to Protect Web Apps and APIs - Jack Zarris - ASW #108 from 2020-05-18T21:00

Rate limiting can be used to protect against a number of modern web application and API attacks. We’ll discuss some of those attacks, including Object ID enumeration, in detail, will demo an att...

Listen
Paul's Security Weekly TV
Ramsay Malware, Top 10 CVE's, & Reverse RDP Attacks - PSW #651 from 2020-05-17T09:00

In the Security News, Palo Alto Networks Patches Many Vulnerabilities in PAN-OS, Zerodium will no longer acquire certain types of iOS exploits due to surplus, New Ramsay Malware Can Steal Sensit...

Listen
Paul's Security Weekly TV
Securing Remote Access: Quarantines & Security - Harry Sverdlove - PSW #651 from 2020-05-16T21:00

We use terms such as Social Distancing, Quarantine, and Contact Tracing on a regular basis amid the current crisis. How do these apply to Information and Network Security?

 

To lea...

Listen
Paul's Security Weekly TV
MITRE ATT&CK & Security Visibility: Looking Beyond Endpoint Data - Mike Nichols - PSW #651 from 2020-05-16T09:00

In this episode of Paul's Security Weekly, we will dive into the recently published MITRE ATT&CK second-round evaluation based on APT29. While MITRE does not declare a "winner," stressing that t...

Listen
Paul's Security Weekly TV
Using the Network to Reduce Remediation Costs - Sid Nanda - ESW #183 from 2020-05-15T21:00

Many companies hire external consultants to conduct incident response and remediation, which can add up quickly in cost. By providing these security consultants with network data in seconds as o...

Listen
Paul's Security Weekly TV
Qualys VMDR: A Customer Perspective - Georges Bellefontaine - ESW #183 from 2020-05-15T09:00

Discuss approach to vulnerability management at Toyota Financials and benefits of a full life-cycle approach to vulnerability management.

 

To learn more about Qualys VMDR, visit: ...

Listen
Paul's Security Weekly TV
Cortex XSOAR, Fortinet, & YubiEnterprise - ESW #183 from 2020-05-14T21:00

In the Enterprise Security News, how GitHub Code Scanning aims to prevent vulnerabilities in open source software, SlashNext Integrates with Palo Alto Networks Cortex XSOAR to Deliver Automated ...

Listen
Paul's Security Weekly TV
What Does "Security" Really Mean? - Part 2 - Jake Williams - SCW #28 from 2020-05-14T09:00

Security vs. Compliance: Where are the overlaps? Where are the differences?

 

Visit https://www.securityweekly.com/scw for all the...

Listen
Paul's Security Weekly TV
What Does "Security" Really Mean? - Part 1 - Jake Williams - SCW #28 from 2020-05-13T21:00

Security vs. Compliance: Where are the overlaps? Where are the differences?

 

Visit https://www.securityweekly.com/scw for all the...

Listen
Paul's Security Weekly TV
5 Tactical Steps, 5 CISO Priorities, and Communicating "Why" - BSW #173 from 2020-05-13T09:00

In the leadership and communications section, Top 5 Tactical Steps for a New CISO, Good Leadership Is About Communicating “Why”, 5, ok maybe only 4, CISO Priorities During the COVID-19 Response,...

Listen
Paul's Security Weekly TV
Lessons for Cybersecurity From a Pandemic - Mike Lloyd - BSW #173 from 2020-05-12T21:00

The coronavirus has focused the world’s attention on disease spread like never before. This discussion will draw out some of the parallels that can inform how we do our work in cybersecurity, an...

Listen
Paul's Security Weekly TV
Samsung RCE 0-Click, Whispers, & Compromising Pluton - ASW #107 from 2020-05-12T09:00

In the Application Security News, Cloud servers hacked via critical SaltStack vulnerabilities, Samsung Confirms Critical Security Issue For Millions: Every Galaxy After 2014 Affected, Mitigating...

Listen
Paul's Security Weekly TV
How Can Security Work TOGETHER, Not Against, Developers - Joe Garcia - ASW #107 from 2020-05-11T21:00

DevOps and Agile IT practices have been around for a while. However, security teams are just now catching up. We will discuss how security teams can stop being “showstoppers” for the developers ...

Listen
Paul's Security Weekly TV
Vulnerability Madness, IoT Botnets, & Breach Chaos - PSW #650 from 2020-05-11T16:25:37

In the Security News, Naikon APT Hid Five-Year Espionage Attack Under Radar, PoC Exploit Released for DoS Vulnerability in OpenSSL, 900,000 WordPress sites attacked via XSS vulnerabilities, Kaij...

Listen
Paul's Security Weekly TV
Project Fantastic - Bringing The CLI to GUI Users - PSW #650 from 2020-05-09T21:00

Lots of IT and security professionals do not want to use the CLI, which has set them back. Fantastic exposes the same power as the CLI in an easy to use GUI that is more consistent and hopefully...

Listen
Paul's Security Weekly TV
Public Utility Security and National Guard Support - Chris Elgee, Jim McPherson - PSW #650 from 2020-05-09T09:00

Public utilities are under fire from malicious actors now, more than ever. At the same time, authorities for National Guard units are expanding, allowing greater levels of support. However, this...

Listen
Paul's Security Weekly TV
Effective Goal Setting and Tracking - ESW #182 from 2020-05-08T21:00

Executing on a successful program and proving its efficacy is an impossibility for many security teams. Tune in as we discuss what steps you can take immediately to set more effective goals, tra...

Listen
Paul's Security Weekly TV
Why the Cloud Stall Is Now the Cloud Surge - ESW #182 from 2020-05-08T09:00

Broad shifts to remote access plus increased strain on budgets and resources make it a business imperative to accelerate cloud adoption, and do it securely. Network detection and response bridge...

Listen
Paul's Security Weekly TV
WordPress Attacks, IoT Device Shifts, & Splunk Cloud - ESW #182 from 2020-05-07T21:00

Microsoft is to buy Israeli cybersecurity startup CyberX, ExtraHop Data Shows Shifts in IoT Device Usage During COVID-19 Have Broad Security Implications, Immuta and Snowflake help customers sha...

Listen
Paul's Security Weekly TV
PCI: A New Hope - SCW #27 from 2020-05-07T09:00

Security, Compliance, and Breach News!

 

Visit https://www.securityweekly.com/scw for all the latest episodes!

Show Notes: ...

Listen
Paul's Security Weekly TV
The Rise of PCI - SCW #27 from 2020-05-06T21:00

Today we will discuss the PCI DSS and some of its myths, misunderstandings, and misconceptions, including: Why most vendors don't understand how their products fit within PCI, The six overall go...

Listen
Paul's Security Weekly TV
CISO Burnout, 7 Rules to Stay Productive, and Hire Great Talent Now! - BSW #172 from 2020-05-06T09:00

In the leadership and communications section, CISO position burnout causes high churn rate, 7 Rules for Staying Productive Long-Term, Now Is an Unprecedented Opportunity to Hire Great Talent, an...

Listen
Paul's Security Weekly TV
Lessons Learned from a Data Breach - Graeme Payne - BSW #172 from 2020-05-05T21:00

During the Equifax 2017 Data Breach, Graeme Payne was Senior Vice President and CIO of Global Corporate Platforms. He was fired the day before the former Chairman and CEO of Equifax testified to...

Listen
Paul's Security Weekly TV
Psychic Paper, Salt RCE, & Love Bugs - ASW #106 from 2020-05-05T09:00

This week in the Application Security News, “Psychic Paper” demonstrates why a lack of safe and consistent parsing of XML is disturbing, Beware of the GIF: Account Takeover Vulnerability in Micr...

Listen
Paul's Security Weekly TV
Modern Application Security & Container Security - Gareth Rushgrove - ASW #106 from 2020-05-04T21:00

This week, we welcome Gareth Rushgrove, Director of Product Management at Snyk, to talk about Modern Application Security and Container Security! They also discuss Configuration Management, how ...

Listen
Paul's Security Weekly TV
Defensive Strategies and Qualys VMDR - PSW #649 from 2020-05-03T09:00

The crew talks about how to accomplish asset management, vulnerability management, prioritization of remediation, and the actual remediation steps! No small task! Then check out a deep dive demo...

Listen
Paul's Security Weekly TV
Python Pickling, Sophos 0-Day, & AWS RDS MySQL - PSW #649 from 2020-05-02T21:00

In the Security News, Half a Million Zoom Accounts Compromised by Credential Stuffing, Sold on Dark Web, Scammers pounce as stimulus checks start flowing, NSA shares list of vulnerabilities comm...

Listen
Paul's Security Weekly TV
Fighting the Cyber War With Battlefield Tactics - Jeremy Miller, Philip Niedermair - PSW #649 from 2020-05-02T09:00

Jeremy Miller, a former Green Beret and current CEO of Lionfish Cyber Security, will discuss how mission set tactics used by Special Forces can be applied directly to the cyber war being waged t...

Listen
Paul's Security Weekly TV
Building an Enterprise Security Team - Wim Remes - ESW #181 from 2020-05-01T21:00

This week, we welcome Wim Remes, CEO and Principal Consultant at Wire Security, to discuss learning how to build an Enterprise Security Team, including how to find the right people!

 

...

Listen
Paul's Security Weekly TV
Security Challenges When Working Remotely - Gerald Beuchelt - ESW #181 from 2020-05-01T09:00

Unfortunately, the pandemic has been used as the subject in an aggressive spike of malicious cyber attacks attempting to monopolize the situation. Knowing how and where to focus your security ef...

Listen
Paul's Security Weekly TV
Trustwave, F-Secure, & Obsidian Security - ESW #181 from 2020-04-30T21:00

This week in the Enterprise Security News, Obsidian Security lets security teams monitor Zoom usage, Guardicore Infection Monkey now maps its actions to MITRE ATT&CK knowledge base, Trustwave Se...

Listen
Paul's Security Weekly TV
Cyber and Disabilities Pt.2 - Joe Brinkley - SCW #26 from 2020-04-30T09:00

We continue the discussion with TheBlindHacker, Joe Brinkley. The Blind Hacker is an InfoSec enthusiast, hacker, mentor, pen tester, red team member, and much more. Among these many roles, the r...

Listen
Paul's Security Weekly TV
Cyber and Disabilities Pt.1 - Joe Brinkley - SCW #26 from 2020-04-29T21:00

This week, we welcome Joe Brinkley, Director Offensive Security at ACTIVECYBER, to discuss Cyber and Disabilities! We're taking a different angle on compliance today; talking to Joe Brinkley, th...

Listen
Paul's Security Weekly TV
Avoid These Missteps and Strategize a Return to the Office - BSW #171 from 2020-04-29T09:00

In the Leadership and Communications section, Executives and Boards, Avoid These Missteps in a Crisis, Strategizing a return to the office, How to Answer an Unanswerable Question, and more!

...

Listen
Paul's Security Weekly TV
Relations Between Buyers and Sellers of Security Products - David Spark - BSW #171 from 2020-04-28T21:00

The concept of the CISO/Security Vendor Relationship Series started more than two years ago when relations between security vendors and practitioners appeared very strained. Since we started pro...

Listen
Paul's Security Weekly TV
Nintendo Breach, NSA Advisory, & Security of IoMT - ASW #105 from 2020-04-28T09:00

This week, in the Application Security News, Nintendo Confirms Breach of 160,000 Accounts via a legacy endpoint, NSA shares list of vulnerabilities commonly exploited to plant web shells, Code P...

Listen
Paul's Security Weekly TV
Threat Modeling in AppSec - Avi Douglen - ASW #105 from 2020-04-27T21:00

This week, we welcome Avi Douglen, Founder and CEO of Bounce Security, to talk about Threat Modeling in Application Security, DevSecOps, and how Application Security is mapping Security culture!...

Listen
Paul's Security Weekly TV
iOS Mail Hijack, Hacking Satellites, & 0-Days for Days - PSW #648 from 2020-04-26T09:00

In the Security News, Legions of cybersecurity volunteers rally to protect hospitals during COVID-19 crisis, Wanna hack a Satellite? The Navy will let you…, IBM 0-day released for days after not...

Listen
Paul's Security Weekly TV
Layer8 Conference & WorkshopCon - Ori Zigindere, Patrick Laverty - PSW #648 from 2020-04-25T21:00

Patrick Laverty created and co-organizes the Layer 8 Conference with Lea Snyder. This year will be the 3rd annual conference that solely focuses on social engineering and OSINT topics. Ori Zigin...

Listen
Paul's Security Weekly TV
The Insider Threat - Steven Bay - PSW #648 from 2020-04-25T09:00

Steven Bay has over 16 years of cybersecurity experience, spanning the military, government, consulting, and enterprise security. For 10 of those years, he supported the National Security Agency...

Listen
Paul's Security Weekly TV
Threats of Social Engineering Go Beyond Phishing - Peter Warmka - ESW #180 from 2020-04-24T21:00

Peter will discuss this article and put it into even greater perspective: https:...

Listen
Paul's Security Weekly TV
Work from Home - Business Impacts & Security Risks - Mark Orsi - ESW #180 from 2020-04-24T09:00

As we quickly pivot to remote work, what are the business impacts and security risks? What have we learned and how quickly can organizations adapt to this new paradigm? What activities should we...

Listen
Paul's Security Weekly TV
ThunderScan, F-Secure Countercept, & ZeroFOX AI - ESW #180 from 2020-04-23T21:00

This week in the Enterprise Security News, Breach-and-Attack Simulation Firm SafeBreach Raises $19 Million, F-Secure launches protection and response service to protect remote workers, Swimlane ...

Listen
Paul's Security Weekly TV
Compliance News - SCW #25 from 2020-04-23T09:00

This week in the Security and Compliance News, Back to basics: The GDPR and PCI DSS, Why Compliance is for Guidance, Not a Security Strategy, Cognizant hit by 'Maze' ransomware attack, Audits Do...

Listen
Paul's Security Weekly TV
State of the Union - Paul Asadoorian - SCW #25 from 2020-04-22T21:00

We're talking to our host and benefactor about his vision for Security Weekly Productions and how Security & Compliance Weekly fits into the mix.

 

Visit Listen

Paul's Security Weekly TV
Clear Vision, 3 Recession Scenarios, and Transparency - BSW #170 from 2020-04-22T09:00

In the leadership and communications section, Leaders, Do You Have a Clear Vision for the Post-Crisis Future?, 3 recession scenarios and their impact on tech spend, Supply chain transparency: Te...

Listen
Paul's Security Weekly TV
InfoSec World Conference 2020 - Summer Fowler - BSW #170 from 2020-04-21T21:00

As the Co-Chair of the Leadership Board for InfoSec World Conference in Orlando, FL this June 2020, Summer will discuss how this is an excellent opportunity for Executive, Management, and Techni...

Listen
Paul's Security Weekly TV
Malicious Ruby Gems & JSON Web Token Bypass - ASW #104 from 2020-04-21T09:00

This week in the Application Security News, JSON Web Token Validation Bypass in Auth0 Authentication API, Mining for malicious Ruby gems, A Brief History of a Rootable Docker Image, Privacy In T...

Listen
Paul's Security Weekly TV
Building an AppSec Ecosystem - Rebecca Deck - ASW #104 from 2020-04-20T21:00

It's possible to check the boxes and have an AppSec program that looks great on paper, but still not have positive results. We will cover using continuous feedback from AppSec testing activities...

Listen
Paul's Security Weekly TV
Hospital Hackers, $500K Zoom 0day, & SFO Windows Hackers - PSW #647 from 2020-04-19T09:00

This week in the Security News, How to teach your iPhone to recognize you while wearing a mask, Hackers Targeting Critical Healthcare Facilities With Ransomware During Coronavirus Pandemic, VMwa...

Listen
Paul's Security Weekly TV
Pen Testing to Validate Vulnerability Scanners - Magno Gomes - PSW #647 from 2020-04-18T21:00

Many people inaccurately use vulnerability scans or vulnerability assessments as terms that are synonymous with penetration tests. Those that do know the difference often think you have to choos...

Listen
Paul's Security Weekly TV
Threat Intel Program Strategies - Wade Woolwine - PSW #647 from 2020-04-18T09:00

Defining key areas of investment that organizations need to consider in their programs. Within the areas of investment, we talk about functional areas and defining capabilities within each funct...

Listen
Paul's Security Weekly TV
The Missing Link for Protecting Against Ransomware - Tim Williams - ESW #179 from 2020-04-17T21:00

Tim Williams, Founder and CEO of Index Engines, joins us to discuss the cyber security software market and how it's focused on preventing ransomware attacks. How do you know if that line of defe...

Listen
Paul's Security Weekly TV
Phishing's Effect on Corporate Culture - Terry McCorkle - ESW #179 from 2020-04-17T09:00

Many organizations today know about phishing and have taken steps to educate users, followed by phishing simulations. What comes next? This discussion will revolve around what many organizations...

Listen
Paul's Security Weekly TV
Patch Tuesday, Sysdig, & AttackIQ - ESW #179 from 2020-04-16T21:00

This week in the Enterprise Security News, NeuVector adds to container security platform and automates end-to-end vulnerability management, Sysdig Expands Unified Monitoring Across IBM Cloud Ser...

Listen
Paul's Security Weekly TV
Cyber Insurance News - SCW #24 from 2020-04-16T09:00

Jeffrey Smith joins us in looking at how cyber insurance is playing out in the real world - or at least how it's showing up in the news.

 

Visit Listen

Paul's Security Weekly TV
Cyber Insurance - Jeffrey Smith - SCW #24 from 2020-04-15T21:00

This week, we welcome Jeffrey Smith, Managing Partner at Cyber Risk Underwriters, to sell us Cyber Insurance, and how he wants to take on the skeptics (e.g. the SCW hosts) about the role that Cy...

Listen
Paul's Security Weekly TV
Start, Stop, Defer; Adapting to a Crisis; and Building a Culture - BSW #169 from 2020-04-15T09:00

In the leadership and communications section, the 3 stages of adapting to a crisis, build a culture that aligns to people's values, stop, start, defer: how companies are navigating technology sp...

Listen
Paul's Security Weekly TV
Security Money - BSW #169 from 2020-04-14T21:00

It's our Security Money show, where we'll review the Security Weekly 25 Index and all the financial updates for both the public and private security markets.

 

Visit Listen

Paul's Security Weekly TV
Zooming Alex Stamos & Building Security TestOps - ASW #103 from 2020-04-14T09:00

This week in the Application Security News, Zoom Taps Ex-Facebook CISO Amid Security Snafus, Lawsuit, How we abused Slack's TURN servers to gain access to internal services, Moving from reCAPTCH...

Listen
Paul's Security Weekly TV
Making Kubernetes a Hostile Place for Attackers - Brad Geesaman - ASW #103 from 2020-04-13T21:00

Kubernetes is conceptually simple, but in practical terms, a highly complex distributed system with thousands of interdependent settings that drive behavior and security posture. That said, focu...

Listen
Paul's Security Weekly TV
Zoom, Kubernetes, and Hacking - PSW #646 from 2020-04-12T09:00

A little about Zoom vulnerabilities and data leaks and Cisco Webex vulnerabilities. We talk about security Kubernetes and how the same security principals apply, vulnerabilities in ICS systems a...

Listen
Paul's Security Weekly TV
Tales From The Crypt...Analyst - Part 2 - Jeff Man - PSW #646 from 2020-04-11T21:00

In the second part of our interview series with the legend Jeff Man, he continues his discussion with Paul, Matt, and Lee, about the many myths, legends and fables in hacker history. One of the ...

Listen
Paul's Security Weekly TV
To Hunt or Not To Hunt; This is Never a !=? - Tyler Robinson - PSW #646 from 2020-04-11T09:00

We welcome Security Weekly's own Tyler Robinson for a Technical Segment, to talk about how individuals are tracked and then demonstrates different TTPs Nisos uses to hunt and track people of int...

Listen
Paul's Security Weekly TV
Moving Towards Modern Vulnerability Management - Ed Bellis - ESW #178 from 2020-04-10T21:00

What are the practical ways to get that time to value in app security? How can we utilize devs in the process without creating massive SAST integration projects and training them on false positi...

Listen
Paul's Security Weekly TV
Time to Measure Security Improvement in AppSec - Ferruh Mavituna - ESW #178 from 2020-04-10T09:00

What are the practical ways to get that time to value in app security? How can we utilize devs in the process without creating massive SAST integration projects and training them on false positi...

Listen
Paul's Security Weekly TV
CrowdStrike, Automox, & Ixia - ESW #178 from 2020-04-09T21:00

New from BitDam, Ping, CrowsdStrike, Automox, Ixia, Recorded Future, CyberArk, AlgoSec, Tufin, Unisys. Redis servers found exposed to the Internet and vulnerable!

 

Visit Listen

Paul's Security Weekly TV
CMMC - Part 2 - Chris Golden - SCW #23 from 2020-04-09T09:00

Chris Golden, Board Member for the Accreditation Body, continues the conversation surrounding the DOD's release of the CMMC program to keep the amount of false information to a minimum.

 ...

Listen
Paul's Security Weekly TV
CMMC - Part 1 - Chris Golden - SCW #23 from 2020-04-08T21:00

Chris Golden, Board Member for the Accreditation Body, will answer questions surrounding the DOD's release of the CMMC program to keep the amount of false information to a minimum.

 

...

Listen
Paul's Security Weekly TV
3 Tips, 4 Behaviors, and 15 Steps for Remote Work - BSW #168 from 2020-04-08T09:00

In the leadership and communications section, 4 Behaviors That Help Leaders Manage a Crisis, The Right Way to Keep Your Remote Team Accountable, 15 Steps to Take Before Your Next Video Call, and...

Listen
Paul's Security Weekly TV
Cyber Resilience - Richard Clarke - BSW #168 from 2020-04-07T21:00

This week, we welcome Dick Clarke to discuss his new book, The Fifth Domain, and the need for cyber resilience, especially these days. Significant risks are still manageable, but what are the co...

Listen
Paul's Security Weekly TV
Zoom Flaws, 'Zombie' win32k Bug, & Inputscope - ASW #102 from 2020-04-07T09:00

This week in the Application Security News, Zoom is gaining lots of attention for flaws and serves as a good exercise in threat modeling and communicating security trade-offs, Popular Digital Wa...

Listen
Paul's Security Weekly TV
You're (probably) Doing AppSec Wrong - Grant Ongers - ASW #102 from 2020-04-06T21:00

Most security programs generally get in the way of delivery (if they don't, to all intents and purposes, prevent it altogether) and are probably also failing to provide the required level of act...

Listen
Paul's Security Weekly TV
Security News - To Zoom or Not to Zoom - PSW #645 from 2020-04-04T21:00

This segment will largely focus on the recent Zoom vulnerabilities and the responses from security researchers, the security community and enterprises. Should you stop using Zoom? Tune in to fin...

Listen
Paul's Security Weekly TV
IoT Devices: Security and Privacy Labels Research - Lorrie Cranor - PSW #645 from 2020-04-04T09:00

At Carnegie Mellon University we are designing a usable security and privacy label for smart devices to help consumers make informed choices about Internet of Things device purchases and encoura...

Listen
Paul's Security Weekly TV
Collaboration Between NetOps and SecOps in Today's World - Matt Allen - PSW #645 from 2020-04-03T21:00

Matt and the Security Weekly crew will discuss how the interaction between network engineers and security operations has changed over the years, as well as the value of the network when identify...

Listen
Paul's Security Weekly TV
Windows Exploits, Re-Training Your Security Solutions - Tod Beardsley - ESW #177 from 2020-03-27T21:00

Tod Beardsley, research director, will discuss some of the trends in Internet scanning and attacker behavior given there are new Windows vulnerabilities and the workforce working from home. Shou...

Listen
Paul's Security Weekly TV
Keeping Systems Secure...From Home - Sumedh Thakar - ESW #177 from 2020-03-27T09:00

The cybersecurity challenges created by remote workforces and what it takes to deliver security to remote workers while avoiding impacting business operations. How do you continue vulnerability ...

Listen
Paul's Security Weekly TV
Threat Stack, Qualys, StackRox, Sysdig - ESW #177 from 2020-03-26T21:00

How to Write an Automated Test Framework in a Million Little Steps, Qualys remote endpoint protection solution helps enterprises secure remote workforces, Sysdig Provides the First Cloud-Scale P...

Listen
Paul's Security Weekly TV
Nemours Use Of RSA Archer To Manage Compliance Risk - Kevin Haynes - SCW #22 from 2020-03-26T09:00

Customer perspective on the three topics discussed with RSA in first segment Also: -What is your view of security vs. compliance vs. risk? -What drives your security program initiatives? -What a...

Listen
Paul's Security Weekly TV
Compliance Risk Challenges - David Walter - SCW #22 from 2020-03-25T21:00

David Walter from RSA will join us to discuss the following:
-The shift in the enterprise from compliance-based focused initiatives to risk-based ones
-Regulatory changes that are im...

Listen
Paul's Security Weekly TV
Real Leaders, Social Distancing, and Vendor Relationships - BSW #167 from 2020-03-25T09:00

In the leadership and communications section, Real Leaders: Abraham Lincoln and the Power of Emotional Discipline, Social Distancing: 15 Ideas for How to Stay Sane, Rethink Your Relationship wit...

Listen
Paul's Security Weekly TV
Protect Your Assets According to Their Value - Jeff Costlow - BSW #167 from 2020-03-24T21:00

How do you protect your assets commensurate with their value if you lack situational awareness of everything communicating on your network thanks to IoT, rogue cloud instances, and shadow IT? If...

Listen
Paul's Security Weekly TV
The Benefits of SAST and SCA in Your IDE - Utsav Sanghani - ASW #101 from 2020-03-24T09:00

Static application security testing (SAST) is critical for uncovering and eliminating issues in proprietary code. However, over 60% of the code in an average application today is composed of ope...

Listen
Paul's Security Weekly TV
Singularity: A Different Take on Container Security - Adam Hughes - ASW #101 from 2020-03-23T21:28:16

Singularity is a container runtime that was built from the ground up to live in multi-user environments where POSIX permissions must be respected. In addition to a novel runtime approach, the Si...

Listen
Paul's Security Weekly TV
Drobo Exploit, Docker Escape, SMBv3.11 - PSW #644 from 2020-03-21T21:00

SANS Penetration Testing | Microsoft SMBv3.11 Vulnerability and Patch CVE-20200796 Explained, Drobo 5N2 4.1.1 - Remote Command Injection, $100K Paid Out for Google Cloud Shell Root Compromise, W...

Listen
Paul's Security Weekly TV
RSAC Micro Interview: Acunetix and Netsparker - Kevin Gallagher, Mark Ralls - ESW #176 from 2020-03-21T09:00

Acunetix: Automation as a Solution for Web Application Security - Mark Ralls - RSAC 2020 Mark Ralls, President and Chief Operating Officer at Acunetix, discusses web security challenges in small...

Listen
Paul's Security Weekly TV
Zen And The Art Of Logs In The Cloud - Corey Thuen - PSW #644 from 2020-03-20T21:00

Struggling with how to get your logs from the cloud? Have no fear, Corey and the Security Weekly crew talk about how to configure your logs in the cloud, use cloud-native services to handle the ...

Listen
Paul's Security Weekly TV
RSAC Micro Interview - SaltStack and Synopsys - ESW #176 from 2020-03-20T09:00

SaltStack: Managing Configuration & Patches with SaltStack - Mehul Revankar - RSAC 2020 Offering open-source and commercial solutions for configuration, patch, and vulnerability management, Salt...

Listen
Paul's Security Weekly TV
Work from home securely - PSW #644 from 2020-03-20T09:00

The challenges and differentiated values of desktop and laptop protection and administrative tool control (e.g., Powershell, SSH) for remote users and administrators to work securely. Visit http...

Listen
Paul's Security Weekly TV
A holistic view of meeting compliance requirements - Part 2 - Matt Allen - SCW #21 from 2020-03-19T09:00

Compliance requirements and SecOps frameworks like NIST - checking boxes rather than a ‘holistic’ view? The vendor eco-system feeding on checking boxes (of which we are one, we HAVE to be.) RSA’...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #176 from 2020-03-19T09:00

Fortinet Introduces Self-Learning AI Appliance for Sub-Second Threat Detection Enterprise IT World, GreatHorn Offers Free Email Protection for 60 Days, ZeroNorth raises $10M to further expand en...

Listen
Paul's Security Weekly TV
A holistic view of meeting compliance requirements - Part 1 - Matt Allen - SCW #21 from 2020-03-17T20:47:43

Compliance requirements and SecOps frameworks like NIST - checking boxes rather than a ‘holistic’ view? The vendor eco-system feeding on checking boxes (of which we are one, we HAVE to be.) RSA’...

Listen
Paul's Security Weekly TV
Where the Law Thinks Your Data Lives - Steve Black - BSW #166 from 2020-03-17T15:53:51

What data compliance regulations apply to a Las Vegas hospital with California patients? One major compliance fine can lead to a big financial hit and a complete loss of customer trust, so under...

Listen
Paul's Security Weekly TV
Bottlerocket, Supply Chain Casualty, DevOps Sweet Spot - ASW #100 from 2020-03-17T15:43:38

Data of millions of eBay and Amazon shoppers exposed as another supply chain casualty, Announcing Bottlerocket, a new open source Linux-based operating system purpose-built to run containers, an...

Listen
Paul's Security Weekly TV
DevSecOps / Scaling Security - Clint Gibler - ASW #100 from 2020-03-17T15:17:01

Due to a combination of a) development teams embracing Agile and DevOps and b) that security teams are often outnumbered by developers 100:1 or more in many companies, there's been a fundamental...

Listen
Paul's Security Weekly TV
Drowning in a Sea of Alerts, CIO News, and More! - BSW #166 from 2020-03-17T09:00

In the leadership and communications segment, Drowning in a Sea of Alerts, Boeing taps Qantas exec Susan Doniz as CIO, CIO interview: Ian Cohen, chief product and technology officer, at Addison ...

Listen
Paul's Security Weekly TV
Connected devices security - Dorit Naparstek - PSW #643 from 2020-03-15T09:00

Hacks performed on connected & IoT devices, such as routers, security cameras, smart meters, etc. are increasingly common, and revealing major vulnerabilities in existing security measure. This ...

Listen
Paul's Security Weekly TV
Protecting Data on Employee 0wned PCs - Gabe Gumbs - PSW #643 from 2020-03-15T09:00

COVID-19, among other things, has deemed it necessary for many to work from home. There are several security concerns that need to be raised, such as those who work from home still require acces...

Listen
Paul's Security Weekly TV
Girls Who Hack and Secure Open Vote - Bianca Lewis - PSW #643 from 2020-03-14T09:00

Girls Who Hack teaches classes primarily to middle school girls on hacking and making. Secure Open Vote is an end to end, open source election system that is in the design stages. www.BiaSciLab....

Listen
Paul's Security Weekly TV
RSAC Micro Interviews - ExtraHop and Bandura - Corey Bodzin, Todd Weller - ESW #175 from 2020-03-13T08:30

ExtraHop - Agents and logs don't play well in an IoT environment, however the network doesn't lie. Looking at the behaviors of IoT devices through the lens of the network traffic can help build ...

Listen
Paul's Security Weekly TV
Drink all the booze, log all the things. - Corey Thuen - ESW #175 from 2020-03-12T16:00

The pain caused by bad pricing models in cybersecurity and analytics tools Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/ESWEp...

Listen
Paul's Security Weekly TV
Neustar, Fortinet, WatchGuard, Panda Security - ESW #175 from 2020-03-11T17:41:49

Neustar's enhanced UltraDNS capabilities boast greater capacity, global reach and security, WatchGuard acquires Panda Security to expand endpoint capabilities, Ping Identity launches two hybrid ...

Listen
Paul's Security Weekly TV
Categorization of Information Security - BSW #165 from 2020-03-11T16:00

How we breakdown the categories in information security. We look at the major areas of infosec and how they relate to your security programs and the vendors/technologies in each category. Our ca...

Listen
Paul's Security Weekly TV
Where do you Stand? Part 2 - Winn Schwartau - SCW #20 from 2020-03-10T20:40:12

The goal of the show is to explore all the attitudes and impressions between security and compliance regardless of where you stand. for security folks - how to navigate compliance to promote sec...

Listen
Paul's Security Weekly TV
Where do you Stand? - Winn Schwartau - SCW #20 from 2020-03-10T17:42:02

The goal of the show is to explore all the attitudes and impressions between security and compliance regardless of where you stand. for security folks - how to navigate compliance to promote sec...

Listen
Paul's Security Weekly TV
CISOs, CVE, DevOps, Gandalf - ASW #99 from 2020-03-10T09:00

CVE-2020-0688 Losing the keys to your kingdom, which is why Multiple nation-state groups are hacking Microsoft Exchange servers, Revoking certain certificates on March 4 and Why 3 million Let’s ...

Listen
Paul's Security Weekly TV
CISOs ready to move, How CISOs manage stress, and more! - BSW #165 from 2020-03-09T21:09:40

In the leadership and communications section, CISOs who leave after 2 years may not finish what they start, Most CISOs ready to move jobs if something better comes along, A New Framework for Exe...

Listen
Paul's Security Weekly TV
Guy Podjarny, Snyk - Guy Podjarny - ASW #99 from 2020-03-09T20:25:35

Guy Podjarny (@guypod) is Snyk's Founder and President, focusing on using open source and staying secure. Guy was previously CTO at Akamai following their acquisition of his startup, Blaze.io, a...

Listen
Paul's Security Weekly TV
Tomcat, AWS Malware, Hacker Movies - PSW #642 from 2020-03-09T16:09:42

Apache Tomcat AJP exploit, malware in AWS, hacker movies and more! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/PSWEpisode642...

Listen
Paul's Security Weekly TV
Mark Cooper, PKI Solutions - Mark Cooper - PSW #642 from 2020-03-08T00:46:50

How SHAKEN/STIR and PKI will end the global robocall problem Link to an article Mark wrote for Dark Reading: https://www.darkreading.com/endpoint/shaken-stir-finally!-a-solution-to-caller-id-spo...

Listen
Paul's Security Weekly TV
Active Directory, Azure and Windows Security - Sean Metcalf - PSW #642 from 2020-03-08T00:42:07

Active Directory & Microsoft Cloud (Azure AD & Office 365) Security, including a breakdown of Microsoft's security offerings and recommendations for cloud migrations for Active Directory.

Listen
Paul's Security Weekly TV
RSAC Micro Interview - Plextrac & Gravwell - Corey Thuen, Daniel DeCloss - ESW #174 from 2020-03-04T21:52:34

Dashboards are a great way to enable junior security analysts to be more effective when trying to discover security events. Cory Thuen is the Founder and CEO of Gravwell, and they want to your l...

Listen
Paul's Security Weekly TV
RSAC Micro Interview - Elastic & Rapid7 - Mike Nichols, Tod Beardsley - ESW #174 from 2020-03-04T21:37:24

It is no secret that elections are under constant attack. Attacks take many shapes and forms, from dis-information to malware to denial of service, its all in play as adversaries look to disrupt...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #174 from 2020-03-04T21:35:21

News from Nozomi Networks, Code42, CrowdStrike, SCYTHE, Palo Alto Networks, Gurucul, SentinelOne and more! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https...

Listen
Paul's Security Weekly TV
Compliance News - SCW #19 from 2020-03-03T20:57:04

Health compliance measures to improve pandemic recovery and reduce issues, World Bank pandemic awareness, Is coronavirus not a flu?, Dear passwords: Forget you. Here's what is going to protect u...

Listen
Paul's Security Weekly TV
Reflections On RSAC - SCW #19 from 2020-03-03T20:55:38

Reflections on RSAC! Let's talk about the grand festival of infosec consumerism that is RSA Conference! Was it worth catching the Coronavirus? And if so, did you use a lime!?

Visit Listen

Paul's Security Weekly TV
InfoSec World Workshop: DevSecOps and Cultural Transformation - Dan Petit - ASW #98 from 2020-03-02T20:24:59

Dan discusses his upcoming 2-day workshop at InfoSec World. The workshop is a "deep survey" into all things DevSecOps. Visit https://www.securitywee...

Listen
Paul's Security Weekly TV
Cool Things We Found At RSAC 2020 - PSW #641 from 2020-03-02T01:33:19

We found some cool stuff at RSAC 2020! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: Listen

Paul's Security Weekly TV
Protect Ya Data - Gabe Gumbs - PSW #641 from 2020-03-01T23:58:52

Gabriel Gumbs and the Security Weekly crew discuss strategies for protecting your data. We will explore practical use-cases for needing to manage access and protect your data as it pertains to s...

Listen
Paul's Security Weekly TV
Tales From The Crypt...Analyst - Jeff Man - PSW #641 from 2020-03-01T23:30

There are many myths, legends and fables in hacker history. One of the themes of these legends surrounds some of the first red team hackers working for the US Government out of NSA. The building...

Listen
Paul's Security Weekly TV
Shadow Risk Elimination - Rob Gurzeev - BSW #164 from 2020-03-01T23:07:29

This interview will cover the idea of Shadow Risk and why it's something your organization can’t ignore. Specifically, we'll talk about why your security efforts have to start with mapping and m...

Listen
Paul's Security Weekly TV
Jinan Budge, Forrester - CISO Leadership, Culture, and the Evolving Role - Jinan Budge - BSW #164 from 2020-03-01T23:07:05

Jinan Budge, Principal Analyst at Forrester, discusses CISO Leadership, Security Culture, and the Evolving Role of the CISO.

 

Visit h...

Listen
Paul's Security Weekly TV
Application News - RSA Conference News and Activities - ASW #97 from 2020-02-26T10:00

6 of the 10 vendors at Innovation Sandbox are application security companies, F5 Empowers Customers with End-to-End App Security, Checkmarx Simplifies Automation of Application Security Testing ...

Listen
Paul's Security Weekly TV
Chris Eng Interview - What's New with Veracode - Chris Eng - ASW #97 from 2020-02-25T13:38:15

Chris Eng, Chief Research Officer at Veracode, provides an update on Veracode including 2019 growth, new product announcements, Veracode Security Labs, and booth activities at RSA Conference 202...

Listen
Paul's Security Weekly TV
Tesla Sensors, Israeli Soldiers Phished, Machine Learning - PSW #640 from 2020-02-24T10:00

Nedbank Says 1.7 Million Customers Impacted by Breach at Third-Party Provider, 500 Chrome Extensions Caught Stealing Private Data of 1.7 Million Users, 5 inch piece of electrical tape can fool T...

Listen
Paul's Security Weekly TV
Kubernetes/Container Security - Ian Coldwater - PSW #640 from 2020-02-23T10:00

Ian Coldwater is the Lead Platform Security Engineer at Heroku. Ian will discuss Kubernetes and container security!

Visit https://www.securit...

Listen
Paul's Security Weekly TV
ExtraHop Customer Interview - Ben Budge, Lyle Beck - ESW #173 from 2020-02-22T10:00

Ben Budge and Lyle Beck will discuss the problems they faced at Litehouse in regards to network and system monitoring and troubleshooting and how that ultimately took them to Extrahop. They will...

Listen
Paul's Security Weekly TV
Unifying SIEM And Endpoint Security - PSW #640 from 2020-02-22T10:00

Elastic recently released Elastic Security 7.6 - the culmination of months of work by the security team and a monumental leap forward toward delivering a unified threat protection and security a...

Listen
Paul's Security Weekly TV
IBM announces RSA Conference withdrawal, Dell Offloads RSA, 12 hottest new cybersecurity startups at RSA 2020 - ESW #173 from 2020-02-21T09:30

his week, in the enterprise news segment, IBM announces RSA Conference withdrawal, Dell Offloads RSA, 12 hottest new cybersecurity startups at RSA 2020, and lots of funding announcements.

Listen
Paul's Security Weekly TV
Red Lion is running the CTF at Infosec World 2020 - ESW #173 from 2020-02-20T15:08:51

Scott Lyons will provide an overview of their CTF at InfoSec World 2020, including their training class, CTF 101.

Visit https://www.securityw...

Listen
Paul's Security Weekly TV
SweynTooth, OWASP, CRXcavator, DevSecOps - ASW #96 from 2020-02-20T10:00

SweynTooth: Unleashing Mayhem over Bluetooth Low Energy, OWASP SAMM version 2, Understanding Trusted Execution Environments and Arm TrustZone, Security Researchers Partner With Chrome To Take Do...

Listen
Paul's Security Weekly TV
Zero to Sixty: Making Security Programmatic and Cultural - David Sherry, Tara Schaufler - BSW #163 from 2020-02-19T10:00

Our presentation in Orlando will be the rapid cultural change of security on the Princeton campus.

Visit https://www.securityweekly.com/bsw Listen

Paul's Security Weekly TV
Integrated Risk Management is the New GRC - Part 2 - Jeff Recor - SCW #18 from 2020-02-19T10:00

Continuation of the discussion with Jeff Recor about integrated risk management.

Visit https://www.securityweekly.com/scw for all the lat...

Listen
Paul's Security Weekly TV
Integrated Risk Management is the New GRC - Part 1 - Jeff Recor - SCW #18 from 2020-02-18T18:46:30

Jeff was scheduled to be part of the 'Security vs. Compliance' Roundtable (https://securityweekly.com/shows/security-vs-compliance-psw-632-2/) recorded on Dec. 19, 2019 but got snowed out. He fi...

Listen
Paul's Security Weekly TV
Companies Can't Sustain Privacy, Old School Paper Planner, Attracting Top Talent - BSW #163 from 2020-02-18T16:00:42

In the leadership and communications section, Why 67% of companies fear they can't sustain privacy compliance, How Using An Old School Paper Planner Changed My Life, How to attract top talent in...

Listen
Paul's Security Weekly TV
Lessons Learned From The DevSecOps Trenches - Doug DePerry - ASW #96 from 2020-02-18T10:00

Doug DePerry has held multiple positions in his three years at Datadog, including Director of Product Security and currently, Director of...

Listen
Paul's Security Weekly TV
Docker, 42 Vulnerabilities, Backdoors, Spying on 100+ Foreign Govs. - PSW #639 from 2020-02-16T10:00

In the Security News, Misconfigured Docker Registries Expose Thousands of Repositories, a Forgotten motherboard driver turns out to be perfect for slipping Windows ransomware past antivirus chec...

Listen
Paul's Security Weekly TV
The Unprotected Attack Surface of the Enterprise - John Loucaides - PSW #639 from 2020-02-15T10:30

Hackers are using firmware implants and backdoors to compromise enterprise security with attacks that are stealthy and persistent. It’s time for information security specialists to learn how to ...

Listen
Paul's Security Weekly TV
Living in Blue Team Land and Skicon - O'Shea Bowens - PSW #639 from 2020-02-14T09:30

O'Shea Bowens is the CEO of Null Hat Security. O'Shea will discuss why I think blue teaming is as essential now as our red brothers. Mistakenly calling out APT's. A new type of security conferen...

Listen
Paul's Security Weekly TV
RSA NetWitness, MDR+, CASB+, ZeroFox, Elastic Stack, Tufin SecureCloud - ESW #172 from 2020-02-13T16:00:24

This week in the Enterprise News, Paul and Matt cover the following stories: Insight Completes Venture Acquisition of Armis, Salt Security API Protection Explained, RSA NetWitness Platform Bolst...

Listen
Paul's Security Weekly TV
Secure Cloud Workloads & Reduce Friction With ExtraHop - Jeff Deininger - ESW #172 from 2020-02-13T11:30

Migrating to the cloud is increasingly a business imperative, but there are pressing security challenges unique to cloud environments that can slow, halt, or even reverse progress. Here's how cl...

Listen
Paul's Security Weekly TV
Building a Great Culture, Excelling at Failure, and Leadership Book Suggestions - BSW #162 from 2020-02-13T10:00

This week in the leadership articles segment, Paul and Jason cover the following articles: The Answer is Yes! Now, What Was Your Question?, When You Lead A Company Or Startup, You Are Creating T...

Listen
Paul's Security Weekly TV
Endpoint Security, Facebook Lawsuit, Hanna Andersson/Salesforce Breach - SCW #17 from 2020-02-13T10:00

This week in the Security & Compliance News Segment, Jeff, Scott, Josh and Matt cover the following news stories: IT, Legal, Compliance: We Need to Talk. Corollary: You need to listen, Back to t...

Listen
Paul's Security Weekly TV
Cyber Safety & Security in K-12 Schools - David Waugh - ESW #172 from 2020-02-12T19:20:44

As K-12 schools and students move into a digital world, the traditionally separate areas of campus safety and cybersecurity are converging. Cyberbullying, the increase in violence on campus, hac...

Listen
Paul's Security Weekly TV
WhatsApp Flaw, Dropbox Bug Bounty Program, Investigating Web Shell Attacks - ASW #95 from 2020-02-12T10:00

This week in the Application Security News, Mike and John cover the following news stories: Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read From The File S...

Listen
Paul's Security Weekly TV
The Critical Role of Basic Cyber Hygiene - Mike Lloyd - BSW #162 from 2020-02-12T10:00

Doing simple things consistently and at scale is hard. Today's short staffing doesn't help. Automation is the answer. To find out more and try Redseal, please visit: Listen

Paul's Security Weekly TV
The Spirit of the Law - Risk-Based Security - SCW #17 from 2020-02-12T10:00

What is Risk-Based Security? How does compliance and/or security programs/points-of-view help or hinder risk-based security efforts? How can we change this? Is there a more apparent path forward...

Listen
Paul's Security Weekly TV
Mitigating at Design Time - Shaun Lamb - ASW #95 from 2020-02-11T10:00

In this interview segment, Mike and John interview Shaun Lamb about strategies for how best to design applications so they are "secure by default" and have fewer incidents and vulnerabilities, H...

Listen
Paul's Security Weekly TV
Security News - PSW #638 from 2020-02-09T10:00

In the Security News, Twitter fixes API bug that can reveal users, Microsoft patches flaws in Azure stack, 8 cities that have been crippled by cyber attacks and how they fought against it, and s...

Listen
Paul's Security Weekly TV
Security Orchestration Is Not About Tools - Wilson Bautista - ESW #171 from 2020-02-08T10:00

We interview Wilson Bautista is the Founder of Jun Cyber. Wilson will talk about leadership, DevOps and Secrity working together to provide security for the business, how does that work? Buildin...

Listen
Paul's Security Weekly TV
Adventures In AWS Computing - PSW #638 from 2020-02-08T10:00

Paul shows you how to create secure Docker containers and begin to deploy them to Amazon ECS. This segment focuses on the security aspects of taking a legacy/non-contanerized application to the ...

Listen
Paul's Security Weekly TV
The Rise of the Cyber Industrial Complex - Malcolm Harkins - ESW #171 from 2020-02-07T10:00

Malcolm Harkins is the Chief Security & Trust Officer at Cymatic. Malcolm will discuss the security profits from the insecurity of computing thus at a macro economic level has no real economic i...

Listen
Paul's Security Weekly TV
BADASS Army - The Fight Against Revenge Porn - Katelyn Bowden - PSW #638 from 2020-02-07T10:00

After finding her own intimate photos online without her consent, Katelyn Bowden discovered that there weren't many resources for those who find themselves victims of this sort of abuse. In resp...

Listen
Paul's Security Weekly TV
The Big Lie - Part 2 - SCW #16 from 2020-02-06T10:00

You are hedging your bets, hoping that someone else get's breached first, don't believe it's as big as an issue as people make out, keeping your insurance companies happy, telling your board "we...

Listen
Paul's Security Weekly TV
Threat Detection, Risk Analytics, Threat Intelligence, Vulnerability Management - ESW #171 from 2020-02-05T18:41:03

This week in the Enterprise Security News segment, Paul, Jeff, and Matt cover the following news stories: Preempt Security Becomes First in Industry to do Real-Time Threat Detection for Encrypte...

Listen
Paul's Security Weekly TV
The Big Lie - Part 1 - Chris Roberts - SCW #16 from 2020-02-05T10:00

You are hedging your bets, hoping that someone else get's breached first, don't believe it's as big as an issue as people make out, keeping your insurance companies happy, telling your board "we...

Listen
Paul's Security Weekly TV
Network Communications in the World of IoT - David Starobinski - BSW #161 from 2020-02-04T15:04:07

In this interview, David Starobinksi discusses the changes in network communications in both the wireless and IoT world, including cascading attacks, network outages, and the impact on the econo...

Listen
Paul's Security Weekly TV
Scaling an AppSec Program - ASW #94 from 2020-02-03T19:48:43

Mike, John, and Matt review the presentation given by Clint Gilber at AppSec Cali, An Opinionated Guide to Scaling Your Company's Security.

Visit Listen

Paul's Security Weekly TV
Xbox Bounty Program, Magento Patch, RCE in OpenSMTPD - ASW #94 from 2020-02-03T19:10:40

This week in the Application Security News, Mike, John, and Matt cover the following news stories: Xbox Bounty Program, Magento 2.3.4 Patches Critical Code Execution Vulnerabilities, Remote Clou...

Listen
Paul's Security Weekly TV
Wawa Breach, Citrix ADC, Magecart Hackers, Ragnarok Ransomware - PSW #637 from 2020-02-03T10:00

In the Security News, NHS alerted to severe bulbs in GE health equipment, Ragnarok Ransomware targets Citrix ADC & disables Windows Defender, suspected Magecart hackers arrested in Indonesia, Wa...

Listen
Paul's Security Weekly TV
Stopping Python Backdoor Attacks - Peter Smith - PSW #637 from 2020-02-02T10:00

The recent MechaFlounder was a backdoor attack linked to Iranian threat actors who targeted Turkish entities. Similar Python-based backdoor attacks have managed to evade traditional network secu...

Listen
Paul's Security Weekly TV
The Unicorn Project and The Five Ideals - Gene Kim - PSW #637 from 2020-02-01T10:00

In this week's episode of Paul's Security Weekly, Paul and the guys welcome back Gene Kim to interview him about his newest book "The Unicorn Project". Gene shares with us his goals and aspirati...

Listen
Paul's Security Weekly TV
Cybereason, Swimlane, Citrix Scanner - ESW #170 from 2020-01-31T10:00

This week in the Enterprise Security News, Paul and Matt cover the following stories: Cequence CQ botDefense, Optimizing Your IT Spend as You Move to the Cloud, Cybereason Launches Free Emotet-L...

Listen
Paul's Security Weekly TV
Trust, Community, Competitive Advantage, Employee Appreciation - BSW #160 from 2020-01-30T10:00

This week in the leadership articles segment, Matt and Paul cover the following topics: Board members find cybersecurity risk an existential threat - According to a study from UC Berkeley's Cent...

Listen
Paul's Security Weekly TV
Cyber Insurance, Ransomware, and More Cowbell - SCW #15 from 2020-01-30T10:00

This week in the Security and Compliance Weekly News, Jeff, Matt, Scott, and Josh cover the following stories: Cyber insurance policies evolving to meet emerging risks - and premiums reflect it,...

Listen
Paul's Security Weekly TV
Edward Snowden and the Insider Threat - Steven Bay - ESW #170 from 2020-01-29T22:21:33

Edward Snowden is a prime example of an Insider Threat. Steven Bay was his manager at the time as says: "My missing employee, Edward Snowden, revealed himself to be the person behind the Top Sec...

Listen
Paul's Security Weekly TV
Migrating Legacy Apps to the Cloud Pt. 1 - ESW #170 from 2020-01-29T22:10:17

Whether you're trying to migrate a "homegrown" application or an open-source tool, getting into containers and to the cloud can be challenging. There are many ways to achieve the same goal, and ...

Listen
Paul's Security Weekly TV
Pwn2Own In Miami, Cloud Vuln., Deconstructing Web Cache Deception Attacks - ASW #93 from 2020-01-29T10:00

Pwn2Own Miami -- Schedule and Live Results show just how profitable deserialization, information leaks, and out-of-bounds flaws are, Insecure configurations expose GE Healthcare devices to attac...

Listen
Paul's Security Weekly TV
CISO Challenges in a Changing World - Michael Figueroa - BSW #160 from 2020-01-29T10:00

Michael discusses the challenges of CISOs and the differences between large enterprises and small businesses. As the role of the CISO continues to change, so do the requirements for both large e...

Listen
Paul's Security Weekly TV
Cyber Insurance - SCW #15 from 2020-01-29T10:00

Cyber Insurance. Cyberinsurance points to ponder: Relationship and dilution of responsibility between brokers, underwriters, and reinsurance companies, Cost of cyberinsurance, Actuarial tables f...

Listen
Paul's Security Weekly TV
Dynamically Protecting Mobile Applications With RASP - John Butler - ASW #93 from 2020-01-28T10:00

Mobile applications are a rapidly growing attack surface and the tools and techniques being used to compromise these environments are constantly evolving. As the provider in mobile application p...

Listen
Paul's Security Weekly TV
Tomatoes, Jeff Bezo, Vuln. In AMD ATI Radeon, 'The Rise of Skywalker' - PSW #636 from 2020-01-27T09:00

In the Security News, Microsoft Security Shocker As 250 Million Customer Records Exposed Online, the NSA Offers Guidance on Mitigating Cloud Flaws, Multiple Vulnerabilities Found in AMD ATI Rade...

Listen
Paul's Security Weekly TV
Electronic Frontier Foundation (EFF), Godwin's Law, Freedom of Speech - Mike Godwin - PSW #636 from 2020-01-26T10:00

Paul, Doug and Tyler interview Mike Godwin about the creation of the EFF, why it was created and how he became involved, some of the first cases taken on by the EFF, Godwin's Law, the right to r...

Listen
Paul's Security Weekly TV
Compelling People to Care About Security - Robert Siciliano - ESW #169 from 2020-01-25T10:00

Security goes against our core beliefs, therefore security awareness training often falls flat because employees don't care about security. By showing employees the "why" and how it benefits the...

Listen
Paul's Security Weekly TV
Dug Song - Engineer to Entrepreneur - Dug Song - PSW #636 from 2020-01-25T10:00

Paul, Doug and Tyler interview Dug Song about how he got his start in Information Security, what prompted him to begin work for dsniff, his transition from engineer to entrepreneur, what he lear...

Listen
Paul's Security Weekly TV
SAP Vulnerabilities - Alex Horan, Juan Pablo Perez Etchegoyen - ESW #169 from 2020-01-24T10:00

Alex Horan is the Director of Product Management at Onapsis and JP Perez is the CTO at Onapsis. Today they discuss the current state as it relates to SAP Vulnerabilities and security.

Vis...

Listen
Paul's Security Weekly TV
IE Zero-Day, Flashpoint, Malware Sandboxes - ESW #169 from 2020-01-24T10:00

In the Enterprise News, Paul and Matt cover new InfoSec products of the week, CyberArk's new JIT access capabilities, a Micro patch that simulates a workaround for the recent zero-day IE flaw, e...

Listen
Paul's Security Weekly TV
The State of the Financial Markets - Chase Robertson - BSW #159 from 2020-01-23T10:00

Chase Robertson, the CEO at Robertson Wealth Management, joins us to discuss the state of the financial markets in 2020 and beyond.

Visit https://www.securityweekly.com/bsw for all the la...

Listen
Paul's Security Weekly TV
The Role of Compliance in the Federal Gov. - How Security Works - Trevor Bryant - SCW #14 from 2020-01-23T10:00

In this segment, we interview Trevor about his role, his experience and his thoughts on the role of compliance in the Federal Government.

Visit Listen

Paul's Security Weekly TV
Security Money - BSW #159 from 2020-01-22T10:00

This week we provide our quarterly Security Money update. This segment tracks the top 25 public security vendors, known as the Security Weekly 25 Index, and the private funding.

Visit htt...

Listen
Paul's Security Weekly TV
The Role of Compliance in the Federal Gov. - How Compliance Works - Trevor Bryant - SCW #14 from 2020-01-22T10:00

In this segment, we continue the discussion with Trevor on the role of compliance in the Federal Government.

Visit https://www.securityweekly...

Listen
Paul's Security Weekly TV
Crypto Bugs, IoT Planes and Application Inspectors, Oh My! - ASW #92 from 2020-01-21T16:28:10

PoC Exploits Published For Microsoft Crypto Bug disclosed by NSA, Pratt & Whitney Expects GTF Engine Software Update on A220 Jet in Spring, Building a more private web: A path towards making thi...

Listen
Paul's Security Weekly TV
Protecting Data in Apps and Protecting Apps from Data - ASW #92 from 2020-01-21T10:00

Apps must protect the data they collect. How can DevOps teams apply effective controls like strong authentication and authorization? How do cloud services help or hinder encrypting data? Envelop...

Listen
Paul's Security Weekly TV
CVE-2020-0601, Netscaler RCE, npm - PSW #635 from 2020-01-19T10:00

We discuss the details and impact of the latest flaw, disclosed by NSA, in Windows 10 that allows attackers to pass off malware as signed applications and so much more. The Citric Netscaler vuln...

Listen
Paul's Security Weekly TV
VISA Security Alerts - What We Can Learn & What We Can Do - Ward Cobleigh - ESW #168 from 2020-01-18T10:00

This week on Enterprise Security Weekly, Paul Asadoorian and Matt Alderman interview Ward Cobleigh about the recent VISA security alerts highlighting the need for ongoing network monitoring and ...

Listen
Paul's Security Weekly TV
Hacking IoT Devices - Jeff Spielberg, Ryan Speers - PSW #635 from 2020-01-18T10:00

The world continues to see a proliferation of highly insecure IoT/embedded products. How can companies making embedded products design security in from the start, and why don t they do it today?...

Listen
Paul's Security Weekly TV
What Does It Mean To Be A Hacker? - PSW #635 from 2020-01-17T21:42:41

This is the Hacker Culture Roundtable discussion from the Security Weekly Christmas podcast marathon and features almost all of our hosts and special guests. Hacking is a term used to describe t...

Listen
Paul's Security Weekly TV
Outdated Defense Approaches - Mark Orlando - ESW #168 from 2020-01-17T10:00

This week on Enterprise Security Weekly, Paul Asadoorian and Matt Alderman interview Mark Orlando on outdated defense approaches and the need to revisit traditional thinking about security opera...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #158 from 2020-01-16T10:00

This week in the Leadership Articles segment of Business Security Weekly, Matt Alderman, Paul Asadoorian and Jason Albuquerque cover the following articles: Unexpected Companies Produce Some of ...

Listen
Paul's Security Weekly TV
Security and Compliance News - SCW #13 from 2020-01-16T10:00

This week in the Security and Compliance news, Matt Alderman, Scott Lyons, and Josh Marpet cover the following stories: A Risk Assessment Path to Real-Time Assurance, Culture, Integrity and the ...

Listen
Paul's Security Weekly TV
Tenable, VMRay, Tinfoil - ESW #168 from 2020-01-16T10:00

This week on the Enterprise Security News segment, Paul Asadoorian, John Strand, and Matt Alderman cover the following stories: Up Your Vulnerability Prioritization Game with Tenable Lumin for T...

Listen
Paul's Security Weekly TV
Application News - ASW #91 from 2020-01-15T10:00

This week on the Application Security News, Mike Shema, Matt Alderman and John Kinsella cover the following news stories: Policy and Disclosure: 2020 Edition, A look back & forward for bug bount...

Listen
Paul's Security Weekly TV
Startup Security - It's Everyone's Business - Al Ghous - BSW #158 from 2020-01-15T10:00

With the growing number of Security startups, often times the need for a quick go to market supersedes developing basic Security hygiene. However, the enterprise customers that startups want to ...

Listen
Paul's Security Weekly TV
The Multiple Personalities In Compliance & Audit Engagements - Ben Rothke - SCW #13 from 2020-01-15T10:00

This week on Security and Compliance Weekly, Matt Alderman, Scott Lyons, and Josh Marpet interview Ben Rothke about the multiple personalities we encounter during compliance and audit engagement...

Listen
Paul's Security Weekly TV
The Evolution of DevSecOps and AppSec Trends in 2020 - Hillel Solow - ASW #91 from 2020-01-14T10:00

Hillel Solow is the CTO at Check Point. Much has evolved in a few short years with DevSecOps and application development and security. But just when we think we see everything clearly and have i...

Listen
Paul's Security Weekly TV
Security News: January 9, 2020 - PSW #634 from 2020-01-13T10:00

In the security news, Car hacking hits the streets, 4 Ring employees fired for spying on customers, MITRE presents ATT&CK for ICS, and Las Vegas suffers cyberattack on the first day of CES!

...

Listen
Paul's Security Weekly TV
The Keys to Your Kingdom: Protecting Data in Hybrid and Multiple Public Clouds - Ambuj Kumar - PSW #634 from 2020-01-12T10:00

According to Gartner, 70% of businesses are adopting a hybrid cloud and multi-cloud strategy to augment their internal data centers. The challenges of protecting data and using encryption for mu...

Listen
Paul's Security Weekly TV
Improve Pen Testing Outcomes With Purple Teaming - PSW #634 from 2020-01-11T10:00

Purple teaming reduces the lifespan of vulnerabilities found from pentests by facilitating knowledge transfer between red and blue teams in the remediation phase. PlexTrac provides a single inte...

Listen
Paul's Security Weekly TV
RSA Conference 2020 - Britta Glade, Linda Gray Martin - ESW #167 from 2020-01-10T10:00

This week on Enterprise Security Weekly Paul Asadoorian and Matt Alderman interview Britta Glade and Linda Gray Martin about RSA Conference 2020! This segment will give listeners a high-level ov...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #157 from 2020-01-09T10:00

This week, in the Leadership Articles segment of Business Security Weekly, Matt Alderman, Paul Asadoorian and Jason Albuquerque discuss the following articles: 5 CIO and IT leadership trends for...

Listen
Paul's Security Weekly TV
Quantifiable Risk Metrics - Bringing Value to Your Security Program Part 2 - Ian Amit - SCW #12 from 2020-01-09T10:00

Utilizing quantitative (vs qualitative) metrics in a security program is the first step in maturing it from a technical novelty to something a business can align with and see value from. Underst...

Listen
Paul's Security Weekly TV
Docker Container Security - Vulnerable Upon Inception - ESW #167 from 2020-01-09T10:00

The Internet gives bad advice sometimes, especially when you are trying to figure out how to build container images. While you may get it to work, typically security will be left out completely....

Listen
Paul's Security Weekly TV
Enterprise News - ESW #167 from 2020-01-08T21:20:45

This week in the Enterprise News segment, Paul Asadoorian, John Strand and Matt Alderman cover the following news stories: Pulse Secure and SecureWave Partnership, BigID raised $50 million to ac...

Listen
Paul's Security Weekly TV
Application News - ASW #90 from 2020-01-08T10:00

This week, on the Application Security News, Mike Shema and Matt Alderman discuss Featured Flaws and Big Breaches (Cisco kicks off 2020 with 12 CVEs in Cisco Data Center Network Manager), Cloud,...

Listen
Paul's Security Weekly TV
The Best and Worst of 2019 - BSW #157 from 2020-01-08T10:00

This week on Business Security Weekly, Matt Alderman, Paul Asadoorian and Jason Albuquerque discuss the best and worst of 2019! The best companies and performance of 2019 include Amazon, Apple, ...

Listen
Paul's Security Weekly TV
Quantifiable Risk Metrics - Bringing Value to Your Security Program Part 1 - Ian Amit - SCW #12 from 2020-01-08T10:00

Utilizing quantitative (vs qualitative) metrics in a security program is the first step in maturing it from a technical novelty to something a business can align with and see value from. Underst...

Listen
Paul's Security Weekly TV
Privacy by Design - ASW #90 from 2020-01-07T10:00

This week on Application Security Weekly, Mike Shema and Matt Alderman discuss Privacy by Design - The 7 Foundational Principles. This discussion includes these topics: Proactive not Reactive; P...

Listen
Paul's Security Weekly TV
Security News: January 2, 2020 - PSW #633 from 2020-01-05T10:00

In the security news, mysterious Drones are Flying over Colorado (watchout Mr. Alderman), 7 Tips for Maximizing Your SOC, The Most Dangerous People on the Internet This Decade, North Korean Hack...

Listen
Paul's Security Weekly TV
Diplomacy, Norms and Deterrence in Cyberspace - Chris Painter - PSW #633 from 2020-01-04T10:00

Global conversations around acceptable norms of behavior in cyberspace (particularly for states), attribution, accountability, and deterrence (though we have not done well on the last one), rece...

Listen
Paul's Security Weekly TV
Who is Going to Protect the Brave New Virtual Worlds and HOW? - Kavya Pearlman - PSW #633 from 2020-01-03T15:01:03

Emerging technologies such as Virtual, Augmented and Mixed Reality are inevitably gaining momentum and helping businesses gain competitive advantage. These technological advancements are giving ...

Listen
Paul's Security Weekly TV
Security History - Lessons from the past - PSW #632 from 2020-01-02T16:19:35

The history of security can be traced back to a variety of different sources. The amount of articles on the topic is dizzying. Most will cite names of early phone phreaks, Kevin Mitnick, Kevin P...

Listen
Paul's Security Weekly TV
Security vs. Compliance - PSW #632 from 2019-12-28T10:00

It was once said that if Security and Compliance were in a relationship the status would be "It's Complicated". This discussion will aim to help you understand this relationship and how it can b...

Listen
Paul's Security Weekly TV
Holiday Hack Challenge - PSW #631 from 2019-12-26T10:00

Each year the team at Counterhack Challenges makes available the Holiday Hack Challenge. Led by Ed Skoudis, and created by some of the most talented security professionals in the industry, it is...

Listen
Paul's Security Weekly TV
The State of Penetration Testing - PSW #631 from 2019-12-24T10:00

Penetration testing has evolved quite a bit in the past year. As defenses shift, and in some cases get much better, attack techniques and landscapes have changed as well. - What has changed in t...

Listen
Paul's Security Weekly TV
DevOps and Securing Applications - PSW #632 from 2019-12-23T19:15:56

- Given that DevOps is a process and its execution requires many different tools, how do we get started "doing DevOps"? - What about DevOps allows us to produce more secure applications? - What ...

Listen
Paul's Security Weekly TV
Blue Team Tactics and Techniques - PSW #631 from 2019-12-23T16:28:52

It's often said that attackers need only to get it right once, where defenders have to be right all of the time. Those of us who have worked in a security role as a defender know we don't always...

Listen
Paul's Security Weekly TV
Risk-Based Vuln. Mgmt/Threat & Vuln. Mgmt - Jason Rolleston, Michael Roytman - ESW #166 from 2019-12-21T19:30

Jason Rolleston, Chief Product Officer at Kenna Security & Michael Roytman, Chief Data Scientist at Kenna Security join Paul, Matt, and Jeff on this week's episode of ESW to discuss how risk-bas...

Listen
Paul's Security Weekly TV
Unify DevOps and SecOps - ESW #166 from 2019-12-21T10:00

DevSecOps is all the rage, but what does it really mean? How do you achieve the integration of Security into DevOps? This segment explores the people and process challenges of DevSecOps and wher...

Listen
Paul's Security Weekly TV
The Joys Of Scoping pt. 2 - Steve Levinson - SCW #11 from 2019-12-20T10:00

Steve Levinsonis the Vice President - Risk, Security & Privacy at Online Business Systems. Steve’s strong technical and client management skills combined with his holistic approach to risk manag...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #166 from 2019-12-20T10:00

In the Enterprise News, we talk about how MITRE updates ATT&CK for the cloud, Ping Identity builds and matures Zero Trust Infrastructures, SaltStack integrates with ServiceNow to deliver Closed-...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #156 from 2019-12-19T10:00

Why Crowdsourcing Often Leads to Bad Ideas, Transforming operations for successful cloud adoption, Do You Need Charisma to Be a Great Public Speaker?, 20 Tools for More Productive Email, and Fig...

Listen
Paul's Security Weekly TV
The Joys Of Scoping - Steve Levinson - SCW #11 from 2019-12-18T23:17:44

Steve Levinsonis the Vice President - Risk, Security & Privacy at Online Business Systems. Steve’s strong technical and client management skills combined with his holistic approach to risk manag...

Listen
Paul's Security Weekly TV
Securing the OT - Martin Bally - BSW #156 from 2019-12-18T21:38:11

Martin Bally is a highly accomplished senior global information security officer with more than 20 years of experience in multiple industries. Currently, he is the Chief Information Security Off...

Listen
Paul's Security Weekly TV
Binary Planting, GitLab, and DevOps Pipelines - ASW #89 from 2019-12-18T10:00

Binary Planting with the npm CLI is another way to describe one of our favorite attacks, GitLab Doles Out Half a Million Bucks to White Hats, Speculation & leakage: Timing side channels & multi-...

Listen
Paul's Security Weekly TV
API Security - Dave Ferguson - ASW #89 from 2019-12-17T10:00

Dave Ferguson is the Director of Product Management, WAS at Qualys. Dave will discuss the issue of latent vulnerabilities and how they may linger in your custom-coded web applications and APIs, ...

Listen
Paul's Security Weekly TV
Risks, Ransomware, Data Leaks, Oh My! - PSW #630 from 2019-12-15T10:00

In the Security News, Reveton ransomware schemer stripped of six years of freedom, £270,000, and Rolex, Web-hosting firm 1&1 hit by almost €10 million GDPR fine over poor security at call centre...

Listen
Paul's Security Weekly TV
Improving Security Requires Reducing Complexity - Jamie Butler - ESW #165 from 2019-12-14T10:00

Jamie Butler is the Tech Lead at Elastic. The vast majority of breaches are not launched by nation states or foreign militaries, but individuals and cyber crime groups with varying degrees of ex...

Listen
Paul's Security Weekly TV
Backdoors & Breaches - The Card Game - PSW #630 from 2019-12-14T10:00

John Strand is a Security Analyst, Founder of Black Hills Information Security, and CTO of Offensive Countermeasures. John will be talking about Backdoors & Breaches, the Incident Response card ...

Listen
Paul's Security Weekly TV
Measuring And Maturing Security Operations Maturity - James Carder - ESW #165 from 2019-12-13T10:00

James Carder is the Chief Security Officer (CSO) and Vice President at LogRhythm. Overview of our security operations maturity model (SOMM), discussion around measurement and road-map to advanci...

Listen
Paul's Security Weekly TV
Runtime Protection for Containers - Jorge Salamero - PSW #630 from 2019-12-13T10:00

Jorge Salamero is the Director of Technical Marketing at Sysdig. Jorge enjoys playing with containers and Kubernetes, home automation and DIY projects. Currently, he is part of the Sysdig team, ...

Listen
Paul's Security Weekly TV
Equifax, Data Security, & A Compliance Carol - SCW #10 from 2019-12-12T23:00

Equifax nears 'historic' data breach settlement that could cost up to $3.5B, Maryland Again Amends its Data Breach Notification Law, Hidden Complexity is Biggest Threat to Compliance , Data Secu...

Listen
Paul's Security Weekly TV
Booz Allen, Barracuda, & Accenture - ESW #165 from 2019-12-12T10:00

Barracuda launches Cloud Security Guardian integration with Amazon Detective, Booz Allen Hamilton announces support for AWS Outposts, 10 Notable Cybersecurity Acquisitions of 2019, Part 2, Sopho...

Listen
Paul's Security Weekly TV
Orienting Younger Children to Cyber and Tech - Laura Jones - SCW #10 from 2019-12-11T22:00

Laura Jones is the author of a children’s book titled Cyber Ky & Tekkie Guy Manage the Risk of Being Online. She focuses on children being as 'appropriately informed' as they are comfortable wit...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #155 from 2019-12-11T16:00

In-depth protection is a matter of basic hygiene, 4 strategies to find time for yourself, Enterprises muddled over cloud security responsibilities, and Screw Productivity Hacks: My morning routi...

Listen
Paul's Security Weekly TV
The World Runs On Open-Source, But Who's Paying For Gas? - ASW #88 from 2019-12-11T10:00

In the Application Security News, GitHub Seeks Security Dominance With Developers, IoT and Agile Framework Partners in Efficacy, WhiteSource acquires & open sources Renovate dependency update to...

Listen
Paul's Security Weekly TV
Software Bill of Materials (SBOM) - Allan Friedman - ASW #88 from 2019-12-10T10:00

Allan Friedman is the Director of Cybersecurity Initiatives of NTIA (National Telecommunication and Information Administration) US Dept of Commerce. The problem: unknown software supply chain. F...

Listen
Paul's Security Weekly TV
Defecting Chinese, IoT Smartwatch, and Malicious SDKs - PSW #629 from 2019-12-09T10:00

Netflix: BPF is a new type of software we use to run Linux apps securely in the kernel, Automated security tests with OWASP ZAP, HackerOne Breach Leads to $20,000 Bounty Reward, US-CERT AA19-339...

Listen
Paul's Security Weekly TV
Open Source Intelligence (OSINT) in Cyber - PSW #629 from 2019-12-08T10:00

Micah Hoffman is the Principle Investigator at Spotlight Infosec. Looking to increase the publicity of using Open Source Intelligence (OSINT) in traditional cyber fields like pentest, DFIR, and ...

Listen
Paul's Security Weekly TV
Untangle's Upcoming SD-WAN Router release - Heather Paunet - ESW #164 from 2019-12-07T10:00

Heather Paunet is the VP of Product at Untangle. Untangle is releasing an SD-WAN Router, which has advanced routing capabilities and provides the ability for a business to build a comprehensive,...

Listen
Paul's Security Weekly TV
Outlook on Phishing in 2020 - Eric Brown - PSW #629 from 2019-12-07T10:00

Eric Brown is the Sr. Security Analyst at LogRhythm. Eric will cover topics including: Phishing Trends, 2020 Outlook, Top 4 Types Eric is seeing: Exec Phish / Legit websites (Box/sites.google/On...

Listen
Paul's Security Weekly TV
Web Security Program and A Realistic Approach for Enterprises - Ferruh Mavituna - ESW #164 from 2019-12-06T10:00

Ferruh Mavituna is the CEO at Netsparker. Ferruh will be talking about How to start building a web security program and a realistic approach to starting a web security security program in enterp...

Listen
Paul's Security Weekly TV
Why You Should Be Sending More Video Emails - BSW #154 from 2019-12-05T10:00

Companies Need to Rethink What Cybersecurity Leadership Is, What Companies That Are Good at Innovation Get Right, Staff in smaller businesses bogged down by poor communications, Why You Should B...

Listen
Paul's Security Weekly TV
Hong Kong, Sentara Hospitals, & Global Cops - SCW #9 from 2019-12-05T10:00

Sale of 4 Million Stolen Cards Tied to Breaches at 4 Restaurant Chains, Sentara Hospitals to pay $2.2M HIPAA settlement for undisclosed data breaches, Privacy Regs Changing the Face of Cybersecu...

Listen
Paul's Security Weekly TV
NSS Labs, CloudKnox, & Kratikal - ESW #164 from 2019-12-05T10:00

In the news, Mimecast Challenges Shadow IT for Cloud App Usage on Mobile and Desktop Devices, CloudKnox Security Announces Integration with AWS IAM Access Analyzer, Morphisec Achieves AWS Securi...

Listen
Paul's Security Weekly TV
Integrated Risk Management for CEOs - Mathieu Gorge - SCW #9 from 2019-12-04T22:00

Mathieu Gorge is the CEO at Vigitrust. The approach that business leaders need to take in developing payment risk strategies, linking, PCI, ISO, GDPR, CCPA, SCA.

Visit Listen

Paul's Security Weekly TV
Facebook, Twitter, & Firefox - ASW #87 from 2019-12-04T10:00

Analysis of Jira Bug Stresses Impact of SSRF in Public Cloud, DevSecOps Adoption and the Web Security Myth, Facebook, Twitter profiles slurped by mobile apps using malicious SDKs, Firefox gets t...

Listen
Paul's Security Weekly TV
Bringing NetOps Into The Threat Hunt - Ward Cobleigh - BSW #154 from 2019-12-04T10:00

Ward Cobleigh is the Sr. Product Manager at VIAVI Solutions. In a very recent study, 65% of responding organizations reported a shortage of cybersecurity staff, with a lack of skilled or experie...

Listen
Paul's Security Weekly TV
Bot Management - Sandy Carielli - ASW #87 from 2019-12-03T10:00

Sandy Carielli is the Principal Analyst at Forrester Research. Discuss the impact of good and bad bots on enterprises and how it is both a security and customer experience problem. Review how th...

Listen
Paul's Security Weekly TV
Patch Management - Brendan O'Connor - ESW #163 from 2019-12-01T10:00

From Fortune 500 to Education, from startup to running a consulting firm, Brendan's experience in information security has served him well. It all started with his boss speaking outloud about ho...

Listen
Paul's Security Weekly TV
Cloudflare, Qulays, and Palo Alto - ESW #163 from 2019-12-01T10:00

Cloudflare Open-Sources its Network Vulnerability Scanner, Qualys brings its Market Leading Vulnerability Management Solution to the next level, and some acquisition and funding updates from Pal...

Listen
Paul's Security Weekly TV
IoT Crusher - Ken Belva - ESW #163 from 2019-12-01T10:00

Kenneth F. Belva, CISSP, CEH is a cyber security expert practicing in the field since 1998 serving in both technical and non-technical roles. Ken joins Matt and Paul today to talk about Why scan...

Listen
Paul's Security Weekly TV
Discussion and Q&A - Jim Nitterauer, Russell Mosley - SCW #8 from 2019-11-30T10:00

Russell and Jim will discuss security and compliance specifically for small businesses where they have been involved with audit and compliance including NIST 800-171, 800-53 (FISMA) and SOC, and...

Listen
Paul's Security Weekly TV
Security & Compliance at Small and Medium Sized Businesses - Jim Nitterauer, Russell Mosley - SCW #8 from 2019-11-30T10:00

Russell and Jim will discuss security and compliance specifically for small businesses where they have been involved with audit and compliance including NIST 800-171, 800-53 (FISMA) and SOC, and...

Listen
Paul's Security Weekly TV
Elastic Security Update and Organizational Cybersecurity - Nate Fick - BSW #153 from 2019-11-29T10:00

Nate Fick is the GM of Elastic Security. Earlier this month, Elastic announced a radical change to how endpoint protection is offered, doing away with per-endpoint pricing. We'd like to spend 5-...

Listen
Paul's Security Weekly TV
Maersk, Digital Detox, and The Tech Job Market - BSW #153 from 2019-11-29T10:00

Maersk CISO on NotPetya recovery, workforce harmony and what makes a security chief, Why Business Leaders Need to Understand Their Algorithms, How to Do a Digital Detox: 3 Easy Steps for Success...

Listen
Paul's Security Weekly TV
Development Decisions Affect The Security Of Any Application - Tim Mackey - ASW #86 from 2019-11-28T10:00

Tim Mackey is the Principal Security Strategist at Synopsys. Measuring the risk of those decisions isn't something contained within a single tool, but instead requires a set of perspectives on h...

Listen
Paul's Security Weekly TV
The Marvel Universe - PSW #628 from 2019-11-27T10:00

In the Security News, Disney Plus Blames Past Hacks for User Accounts Sold Online, Why Multifactor Authentication Is Now a Hacker Target, How the Linux kernel balances the risks of public bug di...

Listen
Paul's Security Weekly TV
Application News - ASW #86 from 2019-11-27T10:00

$1M Google Hacking Prize, 1.2B Records Exposed in Massive Server Leak, How Attackers Could Hijack Your Android Camera to Spy on You, XSS in GMail’s AMP4Email via DOM Clobbering, and much more! Listen

Paul's Security Weekly TV
Coalfire Incident & DerbyCon Communities - PSW #628 from 2019-11-26T10:00

Dave Kennedy is the Founder & CEO of TrustedSec. Dave comes on the show to talk about the Coalfire incident and DerbyCon communities.

Visit h...

Listen
Paul's Security Weekly TV
The Next Generation of SOCs - Peter Liebert - PSW #628 from 2019-11-25T18:19:48

Peter Liebert is the CEO at Liebert Security. After working in and with SOCs for the majority of my career, as well as building one from the ground up for the State of California, there are some...

Listen
Paul's Security Weekly TV
Kubernetes and Project Falco - Jorge Salamero - ESW #162 from 2019-11-23T10:00

Jorge Salamero is the Director of Product Marketing at Sysdig. Jorge joins us on the show to talk about Kubernetes, Project Falco, vulnerability pre-deployment, and containers.

To learn m...

Listen
Paul's Security Weekly TV
Kubernetes, CyberCube, and Illusive - ESW #162 from 2019-11-22T10:00

In the enterprise news, discussing how Sysdig supports Google Cloud Run for Anthos to secure serverless workloads in production, StackRox Kubernetes Security Platform 3.0 Introduces Advanced Fea...

Listen
Paul's Security Weekly TV
Cloud, Containers, and Microservices - Reuven Harrison - ESW #162 from 2019-11-22T10:00

Reuven Harrison is the Chief Technology Officer at Tufin. Reuven brings more than 20 years of software development experience, holding two key senior developer positions at Check Point Software,...

Listen
Paul's Security Weekly TV
Mirantis' Docker, CISOs, & End of Life Dates - ASW #85 from 2019-11-21T10:00

This site maintains quick links for checking End Of Life dates for various tools and technologies, Mirantis' Docker Enterprise acquisition a lifeline as industry shifts to Kubernetes, Website, K...

Listen
Paul's Security Weekly TV
Challenges in the Browser & Securing Web Sessions - Scott Petry - BSW #152 from 2019-11-21T10:00

Scott Petry is the CEO of Authentic8. Scott Petry has been using the cloud to disrupt the information security market for nearly 20 years. He founded Postini in 1999, which pioneered the cloud-d...

Listen
Paul's Security Weekly TV
The Highest Performing Teams Have These 4 Mindsets - BSW #152 from 2019-11-21T10:00

CISOs left in compromising position as organisations tout cyber robustness, Why Your Organization Needs an Innovation Ecosystem, How businesses can accelerate innovation, The Highest Performing ...

Listen
Paul's Security Weekly TV
CCPA, GDPR, Uber, PCI, and You Can't Find Me! - SCW #7 from 2019-11-21T10:00

Verizon finds payment security declines for 2nd consecutive year, Is My PCI Compliance Good Enough to Serve as a Network Cybersecurity Audit?, Getting Prepared for New York’s Expanded Security B...

Listen
Paul's Security Weekly TV
2019 Verizon Payment Security Report - SCW #7 from 2019-11-20T22:00

On SCW this week, we talk about the 2019 Verizon Payment Security Report. We discuss Why is PCI Compliance Decreasing?, why is it decreasing?, what's missing?, and what needs to change?

V...

Listen
Paul's Security Weekly TV
Sysdig Secure 3.0 - Pawan Shankar - ASW #85 from 2019-11-20T10:00

Pawan Shankar is the Senior Product Marketing Manager of Sysdig. Sysdig is very excited to announce the launch of Sysdig Secure 3.0! Listen

Paul's Security Weekly TV
Security and Compliance News - SCW #6 from 2019-11-18T22:00

Payment Security Compliance Declines - 1 in 3 Companies Make the Grade, RMC Agrees to $3M HIPAA Settlement Over Mobile Device Encryption, How Emerging Technologies Are Disrupting the Banking Com...

Listen
Paul's Security Weekly TV
Building A Security and Compliance Program - SCW #6 from 2019-11-18T10:00

They answer questions like what is a security program and what is a compliance program?, Aren't they the same thing?, What are some differences?, Where do they overlap or how should they work to...

Listen
Paul's Security Weekly TV
Humans vs. Machines - PSW #627 from 2019-11-18T10:00

Two security researchers earned $60,000 for hacking an Amazon Echo, Amazon Kindle, Embedded devices Open to Code-Execution, This App Will Tell You if Your iPhone Gets Hacked, Two New Carding Bot...

Listen
Paul's Security Weekly TV
Simulating Ransomware Attacks with SCYTHE - PSW #627 from 2019-11-17T10:00

Bryson Bort (Founder and CEO of SCYTHE) will demonstrate how to safely simulate ransomware and a multi-staged APT with lateral movement in your production environment! How would your organizatio...

Listen
Paul's Security Weekly TV
The Ethics of Surveillance - Dr. Kevin Harris - PSW #627 from 2019-11-16T10:00

As advancements have been made in technologies new surveillance tools have been designed giving those charged with protecting citizen’s additional opportunities to prevent crimes or identify tho...

Listen
Paul's Security Weekly TV
Threat Detection: The Network Scavenger Hunt - Ward Cobleigh - ESW #161 from 2019-11-15T22:00

Ward Cobleigh is the Sr. Product Manager at VIAVI Solutions. There's an abundance of potential data sources that can be found within you network. Where should you look? Which data sources offer ...

Listen
Paul's Security Weekly TV
Bridging Compliance pt 2 - Ron Ross - SCW #4 from 2019-11-15T10:00

Ron Ross is a Fellow at the National Institute of Standards and Technology. His focus areas include cybersecurity, systems security engineering, and risk management. Dr. Ross leads the Federal I...

Listen
Paul's Security Weekly TV
Zero Trust Architecture - Baber Amin - ESW #161 from 2019-11-15T10:00

Baber Amin is the CTO West at Ping Identity. Security has always been perimeter centric with an "US" vs "THEM" approach. Multiple factors are forcing a change to this design pattern, and exposin...

Listen
Paul's Security Weekly TV
STEALTHbits, Tenable, Aqua Security - ESW #161 from 2019-11-14T16:58:04

STEALTHbits releases StealthDEFEND 2.2, its real-time threat detection and response platform, Tenable to Secure Enterprise Cloud Environments with Microsoft Azure Integration, Aqua Security buys...

Listen
Paul's Security Weekly TV
Security and Compliance News - SCW #5 from 2019-11-14T16:57:07

What does your business need to know about the California Consumer Privacy Act (CCPA)?, California AG: No CCPA Safe Harbor for GDPR Compliance, Canada data breach tally soars since new privacy l...

Listen
Paul's Security Weekly TV
Bridging Compliance pt 1 - Ron Ross - SCW #4 from 2019-11-14T10:00

Ron Ross is a Fellow at the National Institute of Standards and Technology. His focus areas include cybersecurity, systems security engineering, and risk management. Dr. Ross leads the Federal I...

Listen
Paul's Security Weekly TV
Application News - ASW #84 from 2019-11-14T10:00

Pwn2Own Tokyo Roundup: Amazon Echo, Routers, Smart TVs Fall to Hackers, Robinhood Traders Discovered a Glitch That Gave Them 'Infinite Leverage', Bugcrowd Pays Out Over $500K in Bounties in One ...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #151 from 2019-11-13T11:00

5 questions with Cisco's CISO, The CIO role, from IT operator to business strategist, Making the case for integrated risk management, Gartner's strategic tech trends for 2020: Part 1, augmenting...

Listen
Paul's Security Weekly TV
Security Testing - ASW #84 from 2019-11-13T11:00

Mike, Matt, and John talk about security testing.

Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: Listen

Paul's Security Weekly TV
2019 NACD Blue Ribbon Commission Initiative - SCW #3 from 2019-11-12T22:51:05

Josh Marpet and Scott Lyons perform interviews at 2019 NACD Blue Ribbon Commission Initiative.

Visit https://www.securityweekly.com/scw f...

Listen
Paul's Security Weekly TV
Developing an Effective AppSec Security Program - Brendon Macaraeg - BSW #151 from 2019-11-12T10:00

Brendon Macaraeg is the Sr. Director of Product Marketing of Signal Sciences. Focus on the people, processes and tools a dev team needs to put an effective security program in place. Discuss how...

Listen
Paul's Security Weekly TV
Artificial Intelligence and Compliance, Part 1 - SCW #5 from 2019-11-12T10:00

This week, we discuss part 1 on how Artificial Intelligence and Machine Learning can be used for Compliance, including:
- What is Artificial Intelligence (AI) and Machine Learning (ML)? Listen

Paul's Security Weekly TV
Security and Compliance News - SCW #3 from 2019-11-11T15:52:56

PwC's 2019 Annual Corporate Directors Survey, What is the Board's Role in Effective Risk Management?, CEOs could get jail time for violating privacy bill, California Amends Breach Notification L...

Listen
Paul's Security Weekly TV
Security News: November 7, 2019 - PSW #626 from 2019-11-11T10:00

In the Security News, Who is responsible for Active Directory security within your organization?, Apple publishes new technical details on privacy features, How to ensure online safety with DNS ...

Listen
Paul's Security Weekly TV
Arcade Hustle - PSW #626 from 2019-11-10T10:00

Kevin Finisterre is a Co-founder of Arcade Hustle. Josh Valentine is a Co-founder of Arcade Hustle. Josh and Kevin have spent the last year immersing ourselves in arcade platforms, games, and ca...

Listen
Paul's Security Weekly TV
Quantum Computing and IT - Tim Callan - ESW #160 from 2019-11-09T10:00

Tim Callan is the Senior Fellow at Sectigo. Quantum computing and what its arrival means for IT, traditional computing and infosecurity. TC expects that both architectures will live side by side...

Listen
Paul's Security Weekly TV
Stopping Linux Malware - Peter Smith - PSW #626 from 2019-11-09T10:00

Peter Smith is the Founder & CEO of Edgewise.

Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: Listen

Paul's Security Weekly TV
Enterprise Deception - Adrian Sanabria - ESW #160 from 2019-11-08T10:00

Adrian is an Advocate at Thinkst, the company behind the awesome and much loved Thinkst Canary. A former practitioner, PCI QSA, penetration tester, industry analyst and entrepreneur, he has expl...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #150 from 2019-11-07T10:00

Balancing the Company’s Needs and Employee Satisfaction, Why Successful People Wear The Same Thing Every Day, What industry gets wrong about cyber insurance, and much more!

Visit Listen

Paul's Security Weekly TV
Enterprise News - ESW #160 from 2019-11-07T10:00

In the news, talking about how Trustwave offers threat detection and response for Microsoft Azure, LogRhythm offers migration service to Splunk customers to address security challenges, CrowdStr...

Listen
Paul's Security Weekly TV
Security and Compliance News - SCW #2 from 2019-11-07T10:00

New York’s Breach Law Amendments and New Security Requirements, Cybersecurity, The C-Suite, & The Boardroom: The Rising Specter Of Director & Officer Liability, Kaiser says data breach exposed i...

Listen
Paul's Security Weekly TV
PCI: State of the Union - SCW #1 from 2019-11-06T21:18:53

Jeff Man, Scott Lyons, Josh Marpet, and Matt Alderman talk about PCI and how it affects the state of the union.

Visit https://www.securitywee...

Listen
Paul's Security Weekly TV
Application News - ASW #83 from 2019-11-06T10:00

Stable Channel Update for Desktop Chrome users should upgrade to, Overcoming the container security conundrum: What enterprises need to know, Security Think Tank: In the cloud, the buck stops wi...

Listen
Paul's Security Weekly TV
What is Hardsec? - Henry Harrison - BSW #150 from 2019-11-06T10:00

Henry Harrison is the CTO of Garrison. A contrarian in the security industry, Henry Harrison of Garrison believes the only way forward is to implement security on the foundational level through ...

Listen
Paul's Security Weekly TV
Cybersecurity Talent Initiative - Alexander Niejelow - SCW #2 from 2019-11-06T10:00

Alexander Niejelow is the Senior Vice President, Cybersecurity Coordination and Advocacy at Mastercard. The Cybersecurity Talent Initiative is the first-of-its-kind public-private partnership ai...

Listen
Paul's Security Weekly TV
Teaching Security In Software Development - Daniel Lowrie, Justin Dennison - ASW #83 from 2019-11-05T10:00

We interview Daniel Lowrie, who is an Edutainer at ITProTV and Justin Dennison, who is also an Edutainer at ITProTV. Dan and Justin talk about how to bridge the gap between a developer and secur...

Listen
Paul's Security Weekly TV
Security and Compliance News - SCW #1 from 2019-11-05T10:00

Important security notice about your DoorDash account, How PCI DSS compliance milestones can be a GDPR measuring stick, Companies vastly overestimating their GDPR readiness, only 28% achieving c...

Listen
Paul's Security Weekly TV
Security Weekly RoundTable, Cyberwire - PSW #625 from 2019-11-03T11:00

Paul and Matt sit down with Dave Bittner from Cyberwire to discuss the state of security podcasts, the latest security trends, and the security community.

Visit Listen

Paul's Security Weekly TV
Format String Vulnerabilities - PSW #625 from 2019-11-02T09:00

Sven Morgenroth is the Security Researcher at Netsparker. Sven joins us again to talk about Formatting string vulnerabilities.

To learn more about Netsparker, visit: Listen

Paul's Security Weekly TV
IT/OT Convergence In The Power/Utilities Space - Carter Manucy - ESW #159 from 2019-11-01T09:00

Carter Manucy is the Cybersecurity Manager at Municipal Power Agency. Fireside chat around the differences in IT and OT cybersecurity, challenges finding the right folks, challenges facing secur...

Listen
Paul's Security Weekly TV
A New Prescription for Security - Philippe Courtot, Sumedh Thakar - PSW #625 from 2019-11-01T09:00

Philippe Courtot is the Chairman and CEO of Qualys. Sumedh Thakar is the Chief Product Officer Qualys. Philippe Courtot, chairman and CEO of Qualys will examine the impact of today's complex and...

Listen
Paul's Security Weekly TV
Vulnerability Management Evaluation Guide - ESW #159 from 2019-11-01T05:00

Paul and Matt talk about Deployment, Practice, and Reporting concerning Vulnerability Management.

Visit https://www.securityweekly.com/esw Listen

Paul's Security Weekly TV
Leadership Articles - BSW #149 from 2019-10-31T09:00

In the leadership and communications section, Of the 4 manager types, only 1 boosts employee performance 26%, How to Look and Sound Confident During a Presentation, 2020 IT spending priorities —...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #159 from 2019-10-31T09:00

In the Enterprise News, discussing how IaaS cloud vulnerabilities are expected to increase 50% over 2018 figures, examining security process maturity in 400 organizations, Snow Software Unveils ...

Listen
Paul's Security Weekly TV
Application News - ASW #82 from 2019-10-30T09:00

Top cloud security controls you should be using, State of Software Security X, Developers: The Cause of and Solution to Security's Biggest Problems, and much more!

Visit Listen

Paul's Security Weekly TV
Email Security - Kevin O'Brien - BSW #149 from 2019-10-30T09:00

This week, we welcome Kevin O'Brien, Co-founder and CEO at GreatHorn, to discuss email security.

Visit https://www.securityweekly.com/bsw...

Listen
Paul's Security Weekly TV
Bug Bounties, Pentesting, & Scanners - ASW #82 from 2019-10-29T09:00

Mike Shema, Matt Alderman, and John Kinsella, talk about Bug Bounties, Pentesting, & Scanners.

Visit https://www.securityweekly.com/asw f...

Listen
Paul's Security Weekly TV
Endgame To Elastic Endpoint Security - Mark Dufresne - PSW #624 from 2019-10-27T09:00

Last week, Elastic and Endgame announced that they have formally joined forces to introduce Elastic Endpoint Security. Together, they combine Elastic’s free and open SIEM with Endgame's endpoint...

Listen
Paul's Security Weekly TV
Pentesters and Phishing- Kevin O'Brien, GreatHorn - ESW #158 from 2019-10-26T09:00

Kevin O'Brien is the CEO & Co-Founder at GreatHorn. Kevin will be talking about Pen testers and phishing, Social engineering and why user training isn't the answer
In moments of stress, yo...

Listen
Paul's Security Weekly TV
Security News: October 24, 2019 - PSW #624 from 2019-10-26T09:00

In the news, we talk Security News, discussing how Amazon Echo and Kindle devices were affected by a WiFi bug, Ransomware and data breaches linked to uptick in fatal heart attacks, a woman was o...

Listen
Paul's Security Weekly TV
Insider Threat (Whistleblowers) - Erich Anderson, ObserveIT - ESW #158 from 2019-10-25T09:00

Erich Anderson is the Insider Threat Principal at ObserveIT. Erich will be covering: Authorities, Processes, Staff and Operations, Exploring the types of protections employees have in an organiz...

Listen
Paul's Security Weekly TV
Mental Health Hackers & Veterans - Tom Williams - PSW #624 from 2019-10-25T09:00

Tom Williams is the Director of Veterans Operations of Veterans MHH. Speaking about the challenges that veterans face and how MHH is looking to address those.

Visit Listen

Paul's Security Weekly TV
Enterprise News - ESW #158 from 2019-10-24T09:00

This week, In our first segment, we talk Enterprise News, discussing how ManageEngine launched a holistic take on privileged access security, Avast faced a security breach aimed at messing up it...

Listen
Paul's Security Weekly TV
Application News - ASW #81 from 2019-10-23T09:00

From Stackoverflow to CVE, with some laughs along the way, Four-Year-Old Critical Linux Wi-Fi Bug Allows System Compromise, Recent Site Isolation improvements in Chrome, policy_sentry is an IAM ...

Listen
Paul's Security Weekly TV
CISO Role and Experience - Merlin Namuth - BSW #148 from 2019-10-23T09:00

Merlin Namuth is a former CISO. Namuth has over 24 years of IT experience with the last 21 years focused in security. His experience includes building and running numerous security programs, pro...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #148 from 2019-10-23T09:00

In the leadership and communications section, Two Big Reasons that Digital Transformations Fail, DevSecOps model requires security get out of its comfort zone, 3 things CIOs should discuss with ...

Listen
Paul's Security Weekly TV
Cybercrime, Threat Hunting, & APT - PSW #623 from 2019-10-22T09:00

Peter Kruse is the Founder of CSIS Security Group. "Nothing specific but a Google search will provide numerous research I have been involved with and conferences I have spoken at including Kaspe...

Listen
Paul's Security Weekly TV
Doug Coburn, Signal Sciences - Doug Coburn - ASW #81 from 2019-10-22T09:00

Doug Coburn is the Director, Professional Services at Signal Sciences. Doug will be discussing Containers, Layer 7, and application security. Visit ...

Listen
Paul's Security Weekly TV
Security News: October 17, 2019 - PSW #623 from 2019-10-21T09:00

Cybercrime Tool Prices Bump Up in Dark Web Markets, Pen testers find mystery black box connected to ships engines, Using Machine Learning to Detect IP Hijacking - Schneier on Security, and much ...

Listen
Paul's Security Weekly TV
Hacker Halted Interviews - ESW #157 from 2019-10-19T09:00

We air three pre-recorded interviews from Hacker Halted with Cathy Ullman, Joe Gray, and Jenny Radcliffe!

Visit https://www.securityweekly.co...

Listen
Paul's Security Weekly TV
What Makes A Good Pentest Report? - Daniel DeCloss - PSW #623 from 2019-10-19T09:00

DeCloss is the President and CEO of PlexTrac. The segment will focus on the importance of a high-quality report and what red and blue teamers should recognize goes into a good report. Often time...

Listen
Paul's Security Weekly TV
Tactics For Understanding Security Vendor Products - ESW #157 from 2019-10-18T09:00

In our second segment, we talk Tactics for Understanding Security Vendor Products!

Visit https://www.securityweekly.com/esw for all the l...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #157 from 2019-10-17T15:14:15

In the news, we discuss how Okta is launching offerings for threat detection and remediation, Tenable extends Lumin to all platform customers, Signal Sciences announces integration with Pivotal ...

Listen
Paul's Security Weekly TV
Security Money - BSW #147 from 2019-10-17T09:00

It's our quarterly security money segment and we'll review the Security Weekly 25 index.

Visit https://www.securityweekly.com/bsw for all...

Listen
Paul's Security Weekly TV
Survey Results - BSW #147 from 2019-10-15T09:00

In this segment, we'll share the results of our Security Weekly 25 Index Survey, which we completed earlier this year.

Visit https://www.secu...

Listen
Paul's Security Weekly TV
Application News - ASW #80 from 2019-10-14T19:23:19

In the Application Security News, Key takeaways from Imperva breach, From Automated Cloud Deployment to Progressive Delivery, Designing Your First App in Kubernetes: An Overview Food for Thought...

Listen
Paul's Security Weekly TV
Francois Lascelles, Ping Identity - - Francois Lascelles - ASW #80 from 2019-10-14T18:41:15

Francois is a member of the Ping Identity Office of the CTO. He provides product and strategic direction to customers and partners with a focus on API infrastructures security and API cybersecur...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #146 from 2019-10-10T09:00

In the leadership and communications section, The 5 Enemies of Trustworthy Leadership, 5 Things Leaders Do That Stifle Innovation, 'What's Your Purpose'? Big Tech's 7 Favorite Interview Question...

Listen
Paul's Security Weekly TV
Application News - ASW #79 from 2019-10-09T09:00

Ex-Yahoo Engineer Abused Access to Hack 6,000 User Accounts, American Express Insider Breaches Cardholder Information, How a double-free bug in, WhatsApp turns to RCE, Flare-on 6 2019 Writeups, ...

Listen
Paul's Security Weekly TV
Ty Sbano, Sisense - Ty Sbano - BSW #146 from 2019-10-09T09:00

Ty Sbano is the Cloud Chief Information Security Officer of Sisense. Ty graduated from Penn State University with a B.S. in Information Science & Technology and from Norwich University with a M....

Listen
Paul's Security Weekly TV
Cloud Security for Small Teams - ASW #79 from 2019-10-08T09:00

How to step in and help with small cloud security teams.

Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes...

Listen
Paul's Security Weekly TV
Security News: October 3, 2019 - PSW #622 from 2019-10-07T09:00

This week, we talk Security News, how Turkey fines Facebook $282,000 over privacy breach, why the FBI is encouraging not to pay ransomware demands, the top 10 cybersecurity myths that criminals ...

Listen
Paul's Security Weekly TV
Data Privacy and The Journey to Code - Stewart Room - PSW #622 from 2019-10-06T09:30

Stewart Room is a Partner of PwC. Security Professionals have long understood the need to deliver security outcomes in technology and data, but is the privacy community on the same page? Data Pr...

Listen
Paul's Security Weekly TV
Security & Compliance Introduction - PSW #622 from 2019-10-04T09:00

It’s the show, that bridges the requirements of regulations, compliance, and privacy with those of security. Your trusted source for complying with various mandates, building effective programs,...

Listen
Paul's Security Weekly TV
Cyber Security Threats - Paul Claxton - ESW #156 from 2019-10-03T15:32:54

Paul Claxton is the CEO at Elite Holding, Co.. Discussing the top cyber security threats for chief operations officers and chief marketing officer/chief information security officers. With regar...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #145 from 2019-10-03T09:00

In the articles, they cover Why New Leaders Should Make Decisions Slowly, The Missing Ingredient in Kraft Heinz’s Restructuring, Shift to digital business is booming, but are CEOs ignoring assoc...

Listen
Paul's Security Weekly TV
Supply Chain Security In The IoT Era - Matt Wyckhouse - ESW #156 from 2019-10-02T20:04:40

Matt Wyckhouse is the Co Founder & CEO at Finite State. More than 15 years of experience developing advanced software to support offensive and defensive cyber operations led Matt Wyckhouse to co...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #156 from 2019-10-02T19:34:51

In the news, we discuss how ripwire unveils new version of Tripwire Connect, Infrastructure management at scale with Netshield, Five Trends Shaping the Future of Container Security, and some fun...

Listen
Paul's Security Weekly TV
Application News - ASW #78 from 2019-10-02T09:00

Threat Actors Use Percentage-Based URL Encoding to Bypass Email Gateways, Intelligent Tracking Prevention 2.3 and a discussion to Limit the length of the Referer header with some background on B...

Listen
Paul's Security Weekly TV
SOC Visibility and SIEM Tools - Jeff Costlow - BSW #145 from 2019-10-02T09:00

Jeff Costlow is the Head of Security at ExtraHop. Organizations looking to embrace the speed and flexibility of the cloud need to shift gears in security as well, moving towards a cloud-first ap...

Listen
Paul's Security Weekly TV
Information Disclosure Vulnerabilities - Ryan Kelso - ASW #78 from 2019-10-01T13:59:37

Ryan Kelso is the Application Security Engineer at 10-Sec, Inc. Former developer turned application security engineer with a passion for giving back to the security community that has helped me ...

Listen
Paul's Security Weekly TV
Security News: September 26, 2019 - PSW #621 from 2019-09-30T09:00

How a hacker took over a smart home with vulgar music and rising temperatures, a security warning for 23 million YouTube creators following a crazy hack attack, Vimeo sued for storing faceprints...

Listen
Paul's Security Weekly TV
Perry Carpenter and Chris Edwards - PSW #621 from 2019-09-29T09:00

We interview Perry Carpenter and Chris Pritchard at DEF CON SE Village. Perry Carpenter talks about how (as someone on the autism spectrum) has used various social-engineering related skills to ...

Listen
Paul's Security Weekly TV
Billy Boatright, Edward Miro, & Jayson Street - PSW #621 from 2019-09-28T09:00

We interview Billy Boatright, Edward Miro, and Jayson Street at DEF CON SE Village. Billy talks about Impostor Syndrome. Edward Miro talks about Rideshare OSINT – Car Based SE For Fun & Profit. ...

Listen
Paul's Security Weekly TV
Building An Engineering Team With Company Growth - Tony Meehan - ESW #155 from 2019-09-28T09:00

Tony Meehan is the Vice President of Engineering at Endgame. Tony will be talking about building an engineering team for every stage of company growth. In the fast-paced startup world, there’s o...

Listen
Paul's Security Weekly TV
qqqqqqqqqqqqqqqqqqqqqq - PSW #22222 from 2019-09-27T19:48:28

gsgdfsgfd Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/PSWEpisode22222

Listen
Paul's Security Weekly TV
Path To Threat Hunting Through Great Network Data, Brian Dye - ESW #155 from 2019-09-27T09:00

Brian Dye is the CEO of Corelight. Brian will be discussing the Path To Threat Hunting Is Paved With Great Network Data. Tune in for a lively discussion about the role of network evidence in thr...

Listen
Paul's Security Weekly TV
Big Tech VS Big Tobacco - Brian Lamoureux - BSW #144 from 2019-09-26T09:00

Brian Lamoureux is a Partner at Pannone Lopes Devereaux & O'Gara LLC. Is Big Tech heading down the same road of Big Tobacco?

Full Show Notes: Listen

Paul's Security Weekly TV
Enterprise News - ESW #155 from 2019-09-26T09:00

In the news, Akamai acquires MFA specialist KryptCo, HP acquires Bromium to enhance its security platform, Cyber Insurance firm Cowbell emerges from stealth with $3.3M in seed funding, and more....

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #144 from 2019-09-25T09:00

In the leadership and communications section, Troublesome Teammates, Email challenges and how to set boundaries, Cybersecurity confidence rattled by continued investments, small results, and mor...

Listen
Paul's Security Weekly TV
Application News - ASW #77 from 2019-09-25T08:30

BSIMM10 Emphasizes DevOps' Role in Software Security and the BSIMM10 report, Crowdsourced Security & the Gig Economy, Lessons learned through 15 years of SDL at work, Software eats the world, jo...

Listen
Paul's Security Weekly TV
Training For Developers - Nicolas Valcarcel - ASW #77 from 2019-09-24T09:00

Nicolas Valcárcel is the Security Engineer at AdRoll. Nicolas Developers and security professional have vastly different views of the world, so it's not uncommon that trainings created by the la...

Listen
Paul's Security Weekly TV
iOS, Equifax Is Back, & phpMyAdmin CSRF Zero-Day - PSW #620 from 2019-09-23T09:00

In the Security News, how an iOS 13 flaw could provide access to contacts with passcode, Equifax demands more information before making payouts, confidential data of 24.3 million patients were d...

Listen
Paul's Security Weekly TV
Audio Security - PSW #620 from 2019-09-22T09:00

Wes Widner is the Cloud Engineering Manager at CrowdStrike. Wes will be talking about personal voice assistants are the wave of the future. So naturally we should wonder about the unique attack ...

Listen
Paul's Security Weekly TV
Attacking AWS: Elastic Map to Reduce Clusters - ESW #154 from 2019-09-21T09:00

John Strand gives a teaser about his upcoming webcast: Attacking AWS: Elastic Map to Reduce Clusters. John will talk about the intro to cloud security research.

Full Show Notes: Listen

Paul's Security Weekly TV
Anything Red/Purple Teaming - Jason Lang - PSW #620 from 2019-09-21T09:00

Jason Lang is the Sr. Security Consultant of TrustedSec. Modern day red teaming against some of the largest company's in the US. Current passion is Ansible for red teamers (i.e. fast infrastruct...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #154 from 2019-09-20T09:00

In the Enterprise News, hundreds of laid off by Symantec as part of restructuring plan, Infection Monkey Industries first Zero Trust Assesment Tool, Shape Security eyes IPO after raising 51 mill...

Listen
Paul's Security Weekly TV
Cloud Security - ESW #154 from 2019-09-19T09:00

Matt gives a demo on Cloud Security covering IaaS, PaaS, FaaS, SaaS, and the components concerning the User and the provider.

Full Show Notes: Listen

Paul's Security Weekly TV
Bugs, Breaches, & More - ASW #76 from 2019-09-18T09:00

Simjacker – Next Generation Spying Over Mobile, Intel CPUs Vulnerable to Sensitive Data Leakage in NetCAT Attack and NetCAT: Practical Cache Attacks from the Network, What is PSD2? And how it wi...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #143 from 2019-09-17T16:21:38

Why So Many Companies Fail at Strategy and How to Fix It, 8 Things Leaders Do That Make Employees Quit, The changing role of the CIO, How to Rehearse for an Important Presentation, and 10 Steps ...

Listen
Paul's Security Weekly TV
Investigating the Insider Threat - Chris Bush - BSW #143 from 2019-09-17T14:55:07

Chris Bush is the Head of Security at ObserveIT. He will be discussing: Investigating the Insider Threat.

To learn more about ObserveIT, visit: Listen

Paul's Security Weekly TV
OWASP Application Security Verification Standard - ASW #76 from 2019-09-17T13:49:35

The OWASP Application Security Verification Standard (ASVS) Project provides a basis for testing web application technical security controls and also provides developers with a list of requireme...

Listen
Paul's Security Weekly TV
SE Village Interviews: Chris Kirsch & Micah Zenko - PSW #619 from 2019-09-16T09:00

At DEF CON 2019, we interview Chris Kirsch on Getting Psychic: Cold Reading Techniques for Fortune Tellers and Social Engineers Cold reading is a technique to make others believe that you have p...

Listen
Paul's Security Weekly TV
Capital One Breach, Edgewise - Peter Smith - PSW #619 from 2019-09-15T09:00

Peter Smith is the Founder & CEO of Edgewise. Peter will be covering the Capital One breach and the AWS metadata service with request forgery. He will explain how to solve this problem with Edge...

Listen
Paul's Security Weekly TV
Black Hat Interviews: DenimGroup, SCYTHE, & Eclypsium - ESW #153 from 2019-09-14T09:00

We interview Dan Cornell, the Founder & CTO the at DenimGroup.Next, Bryson Bort, the Founder & CEO at SCYTHE. Last, Yuriy Bulygin, the Founder & CEO at Eclypsium.

Full Show Notes: Listen

Paul's Security Weekly TV
Security News: September 12, 2019 - PSW #619 from 2019-09-14T09:00

This week, we present the Security News, to discuss New ransomware grows 118% as cybercriminals adopt fresh tactics and code innovations, Period Tracker Apps share data with Facebook, U.S. Cyber...

Listen
Paul's Security Weekly TV
Elements of an Effective Penetration Testing Program - Steve Laubenstein - ESW #153 from 2019-09-13T09:00

Steve Laubenstein is the VP - Cyber Threat Products Group at Core Security - a HelpSystems Company. Steve will be discussing the need to understand your system's resilience to attacks, and your ...

Listen
Paul's Security Weekly TV
Mobile App Security At Scale: Brian Reed, NowSecure - Brian Reed - BSW #142 from 2019-09-12T09:00

Brian Reed is the Chief Mobility Officer at NowSecure. Brian discusses mobile-app traffic now outpaces mobile web traffic, yet for many organizations mobile security drags behind web leaving bus...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #153 from 2019-09-12T09:00

This week, in the Enterprise News, Splunk buys SaaS startup Omnition, Stage Fund buys Israeli cybersecurity co Cymmetria, Trustwave platform brings more visibility and control cloud security, an...

Listen
Paul's Security Weekly TV
Bugs, Breaches, & More - ASW #75 from 2019-09-11T09:00

A very deep dive into iOS Exploit chains found in the wild followed by Heap Exploit Development, Twitter turns off SMS texting after @Jack hijacking, CVE-2019-15846: Unauthenticated Remote Comma...

Listen
Paul's Security Weekly TV
David X Martin, DavidXMartin, LLC - David X Martin - BSW #142 from 2019-09-11T09:00

David X Martin is the CEO at DavidXMartin, LLC. He is passionate about helping business leaders sleep better at night – by equipping them with critical cyber risk management tools that protect t...

Listen
Paul's Security Weekly TV
Tools in the DevOps Pipeline: Ty Sbano, Sisense - ASW #75 from 2019-09-10T09:00

Ty Sbano is the Cloud Chief Information Security Officer of Sisense. Ty will be discussing Tools in the DevOps Pipeline, Component Analysis, and Anything Application Security!

Full Show N...

Listen
Paul's Security Weekly TV
Black Hat Interviews: Attivo Networks and Infoblox - ESW #152 from 2019-09-06T09:00

We interview Carolyn Crandall, the Chief Deception Officer at Attivo Networks. Carolyn will discussing the deception technology fabric, which interweaves "wolves in sheep's clothing" throughout ...

Listen
Paul's Security Weekly TV
Black Hat Interviews: NSS Labs and SaltStack - ESW #152 from 2019-09-05T09:00

We interview Jason Brvenik, the Chief Executive Officer at NSS Labs. Jason will cover The Importance of Independent, Third-Party Testing. We interview Mehul Revankar, the Senior Product Manager ...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #152 from 2019-09-05T09:00

Privilege Escalation Vulnerability that existed in Check Point Software, Untangle survey finds SMBs continue to struggle with IT Security, Tufin delivers enhanced Visibility and Topology modelin...

Listen
Paul's Security Weekly TV
SE Village 2020 and Innocent Lives Foundation - Christopher Hadnagy - PSW #618 from 2019-09-01T09:00

Christopher Hadnagy is the Chief Human Hacker of Social-Engineer, LLC. Chris will be giving an overview of inaugural SEVillage Orlando 2020. Brief description of the training workshops provided....

Listen
Paul's Security Weekly TV
Analyzing Custom Log Sources - Corey Thuen - PSW #618 from 2019-08-31T09:00

Corey Thuen is the Co-Founder at Gravwell. Security analytics using the new Sysmon DNS logging and Sysmon DNS logging dropped this week.

Full Show Notes: Listen

Paul's Security Weekly TV
Respond Software, Morphisec, and Sophos - ESW #151 from 2019-08-30T19:00

We interview Brett Wahlin, the VP of Security & Trust at Respond Software, Andrew Homer, the VP of Business Development at Morphisec, and Mat Gangwer, the Director of Managed Threat Response at ...

Listen
Paul's Security Weekly TV
AttackIQ, BlueHexagon, and Coalfire - ESW #151 from 2019-08-30T09:00

We interview Chris Kennedy, the CISO & VP and Customer Success at AttackIQ, Balaji Prasad, the VP of Product Management at BlueHexagon, and Mike Weber, the VP of Product Management at Coalfire.<...

Listen
Paul's Security Weekly TV
Security News: August 28, 2019 - PSW #618 from 2019-08-30T09:00

In the news, we discuss how AT&T employees took bribes to plant malware on the company’s network, how hackers could decrypt your GSM calls, 80 suspects charged with massive BEC scam, and how the...

Listen
Paul's Security Weekly TV
Imperva, Cofense, & VMware - ESW #151 from 2019-08-29T09:00

In the news, we discuss 5 tips on how testers can collaborate with software developers, Imperva discloses a data breach affecting some firewall users, VMware unveils security enhancements in Vir...

Listen
Paul's Security Weekly TV
Black Hat Interviews - WhiteSource and Venafi - ASW #74 from 2019-08-28T09:00

We interview Azi Cohen the Co-founder of WhiteSource. He will be talking about Application security has undergone a transition in recent years, as information security teams testing products bef...

Listen
Paul's Security Weekly TV
Managing 3rd Party Risk, SecureLink - Tony Howlett - BSW #141 from 2019-08-28T09:00

IT and data breaches are going up every year and a large portion of them involve vendors or other third parties with access to enterprise networks and systems. Mr. Howlett will review the curren...

Listen
Paul's Security Weekly TV
Container Security With Sysdig Secure 2.4 - Pawan Shankar - ASW #74 from 2019-08-27T15:06:28

Pawan Shankar is the Senior Product Marketing Manager of Sysdig. Sysdig is very excited to announce the launch of Sysdig Secure 2.4! With this release, Sysdig adds runtime profiling to enhance a...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #141 from 2019-08-27T09:00

In the Leadership and Communications segment, The elements of a good company apology, 8 ways leaders delegate successfully, there's no shame in working on vacation and more!

Full Show Not...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #150 from 2019-08-24T09:30

In the news, ThreatConnect released Enhanced Integration with Flashpoint, ObserveIT unveils crowdsourced insider threat analytics solution, Thycotic launches automated solution for managing serv...

Listen
Paul's Security Weekly TV
Critical Patches, Automox - Richard Melick - PSW #617 from 2019-08-24T09:00

Waiting to deploy critical patches makes you a bigger target - Cybercriminals Have Seven-Day Advantage to Weaponize Vulnerabilities, According to New Research from Tenable- Cyber Criminals have ...

Listen
Paul's Security Weekly TV
Deobfuscating JavaScript to Investigate Phishing Domains - PSW #617 from 2019-08-23T13:59:12

Paul gives a technical segment on deobfuscating JavaScript to investigate phishing domains.

To learn more about DomainTools, visit: https...

Listen
Paul's Security Weekly TV
VMRay and Blue Voyant - ESW #150 from 2019-08-23T09:00

We interview Carsten Willems from VMRay and David Etue from BlueVoyant!

Full Show Notes: https://wiki.securityweekly.com/ES_Episod...

Listen
Paul's Security Weekly TV
Bugs, Breaches, and More! - ASW #73 from 2019-08-21T09:00

CVE-2019-1162 showcases elevation of privilege in an ancient Windows component. HTTP/2 Denial of Service Advisory with seven vulns that affects the protocol implemented by several vendors, SSH c...

Listen
Paul's Security Weekly TV
Jessica Johnson & Amber Pedroncelli, Hacker Halted - BSW #140 from 2019-08-21T09:00

Hacker Halted is EC-Council's premier IT Security Conference held in Atlanta annually. Hacker Halted gathers 1400+ Information Security Professionals in two days of Exhibiting, Breakout Sessions...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW #140 from 2019-08-20T14:42:43

In the Leadership and Communications segment, 3 Traits Of Successful Entrepreneurs, 4 Ways To Gain Power And Use It For Good, 5 Reasons to Never Compromise on Punctuality, and more!

Full ...

Listen
Paul's Security Weekly TV
DEF CON 27 Interviews - PSW #616 from 2019-08-19T09:00

In this segment, we interview O'Shea Bowens from Null Hat Security and Tyler Robinson from Nisos, Inc., from the Blue Team Village. Then we interview Aaran Leyland in the Social Engineering Vill...

Listen
Paul's Security Weekly TV
Security News: August 15, 2019 - PSW #616 from 2019-08-18T09:00

The Huawei shenanigans get deeper and more broad. - This is why I have issues with supply chain, CapitalOne hacker may have stolen from 30 more companies, New Data Breach Has Exposed Millions Of...

Listen
Paul's Security Weekly TV
Blue Team To Red Team, Offensive Security - Tony Punturiero - PSW #616 from 2019-08-17T09:00

Tony Punturiero is the Community Manager at Offensive Security. Discussing about my adventure transferring from being on the blue side to becoming a pentester/red teamer full time. Created an in...

Listen
Paul's Security Weekly TV
Black Hat 2019 Interviews - ESW #149 from 2019-08-16T21:00

We interviewed NetScout, Remediant, and BitDefender at Black Hat 2019!

 

Full Show Notes: https://wiki.securityweekly.com/E...

Listen
Paul's Security Weekly TV
Brandon Edwards, Capsule8 - ESW #148 from 2019-08-16T09:00

Containers are a hot topic because of the simplicity they bring to the process of software development, shipping, and deployment. It is important to understand the security properties of contain...

Listen
Paul's Security Weekly TV
Joe Gillespie, Netsparker - ESW #148 from 2019-08-16T09:00

Managing vulnerabilities the Enterprise is more than how many assets can you scan but how do you manage the issues that you discover. They will cover usability, easy to use tool, fast deployment...

Listen
Paul's Security Weekly TV
Enterprise News - ESW #149 from 2019-08-16T09:00

Signal Sciences Rolls New Application Security Product, A10 Networks brings zero-day automated protection to DDoS defense, and we have some acquisition and funding updates from Symantec, McAfee,...

Listen
Paul's Security Weekly TV
Leadership Articles - BSW - News #139 from 2019-08-15T09:00

In the Leadership and Communications segment, How our brains decide when to trust, Warren Buffet's "2 List strategy, Lack of IT leadership fuels IoT trial failures, and more!

Full Show No...

Listen
Paul's Security Weekly TV
Joshua Douglas, Mimecast - PSW #615 from 2019-08-15T09:00

During this discussion, Joshua and Paul will speak about the threats facing organizations today and how they are evolving. Josh will also discuss how IT and security teams need to understand the...

Listen
Paul's Security Weekly TV
Network Detection & Response, ExtraHop - John Smith - ESW - Interview #148 from 2019-08-15T09:00

Network Detection & Response (NDR) as a critical component of cloud-first security, both because of the need for east-west visibility across cloud and on-premises assets, and because combining b...

Listen
Paul's Security Weekly TV
The Sec & Ops Challenge, Mehul Revankar - ESW #149 from 2019-08-15T09:00

IT operations and security teams are very different, but at a high level they both work to create a highly available digital infrastructure that s secure and compliant with regulatory standards....

Listen
Paul's Security Weekly TV
Application News - ASW - News #72 from 2019-08-14T09:00

From Equifax to Capital One: The problem with web application security, Upcoming Change to Chrome's Identity Indicators means the EV UI Moving to Page Info, Apple extends its bug bounty program ...

Listen
Paul's Security Weekly TV
Vanessa Van Edwards, Science of People - Vanessa Van Edwards - BSW - Interview #139 from 2019-08-14T09:00

Outline of Interview: Leaders want to be successful, what are the "6 Secrets of Success" As a leader, what's my body language and how do I improve it: "Body Language of Leaders" "Myths About Bod...

Listen
Paul's Security Weekly TV
Security Do's and Don'ts - PSW #615 from 2019-08-14T09:00

Paul, Larry, Doug, and Gabe talk about Software Development: Security Do's & Don'ts.

?Visit our website: https://www.securityweekly.com
...

Listen
Paul's Security Weekly TV
Gabriel Gumbs, Spirion - PSW #615 from 2019-08-13T18:41:07

Gabriel Gumbs is the VP of Product Management at Spirion where his focus is on the strategy and technology propelling Spirion’s rapidly-growing security platform.

?Visit our website: Listen

Paul's Security Weekly TV
Hacker Summer Camp Round-UP - ASW - Topic #72 from 2019-08-12T18:23:24

Mike Shema and Matt Alderman discuss Hacker Summer Camp as the Security Weekly team has returned from Las Vegas.

Full Show Notes: ...

Listen
Paul's Security Weekly TV
Security News - PSW #614 from 2019-08-05T09:00

In the Security News, the US government issues a light aircraft cyber alert, thieves steal a laptop with 30 years of Data from University of Western Australia, RCE is possible by exploiting flaw...

Listen
Paul's Security Weekly TV
Signal Sciences Kubernetes, Doug Coburn - PSW #614 from 2019-08-04T09:00

Talk about the way Signal Sciences is implemented, especially in the container world. Where we sit in the stack for protection of the web apps in those containers and common first things identif...

Listen
Paul's Security Weekly TV
LogRhythm To The Cloud, Sam Straka - PSW #614 from 2019-08-03T09:00

Sam Straka is the Technical Product Manager at LogRhythm, and he will be talking about the movement of their market to the Cloud, how LogRhythm is innovating in that area, and why total cost of ...

Listen
Paul's Security Weekly TV
News - ESW #147 from 2019-08-02T09:00

Paul, Matt, and John Strand to discuss how Microsoft acquires BlueTalon to bolster data governance offerings, Arduino selects Auth0 as standardized login for open source ecosystem, new code-sign...

Listen
Paul's Security Weekly TV
Threat Hunting - ESW #147 from 2019-08-02T09:00

Charles Thompson, Sr. Director of Product Management at VIAVI Solutions, has a career spanning 20 years in the IT space specializing in using wire-data to assist SecOps and NetOps teams with man...

Listen
Paul's Security Weekly TV
Evaluating Vendors - ESW #147 from 2019-08-01T09:00

To prepare for DEF CON and Black Hat, Paul and Matt talk about Evaluating Security Vendors!

Full Show Notes: https://wiki.security...

Listen
Paul's Security Weekly TV
Container Security Today - Application Security Weekly #71 from 2019-07-31T09:00

Murray Goldschmidt is the COO & Co-founder of Sense of Security. Murray talks about The state of container security in the enterprise. Full Show Notes: Listen

Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #138 from 2019-07-31T09:00

In the Leadership and Communications segment, Leading with Trust, Portrait of a CISO, roles and responsibilities, Cybersecurity Risk: What does a "reasonable" posture entail and who says so?, an...

Listen
Paul's Security Weekly TV
CISO COMPASS, Todd Fitzgerald - Business Security Weekly #138 from 2019-07-31T09:00

Todd Fitzgerald is the Managing Director/CISO/Cybersecurity Leadership Author at CISO SPOTLIGHT, LLC. Todd will be discussing his book, the CISO COMPASS: Navigating Cybersecurity Leadership Chal...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #71 from 2019-07-30T09:00

Rare Steganography Hack Can Compromise Fully Patched Websites, Bug Bounties Continue to Rise as Google Boosts its Payouts, Snyk Acquires DevSecCon to Boost DevSecOps Community, and much more! Listen

Paul's Security Weekly TV
Security News - Paul's Security Weekly #613 from 2019-07-26T17:25:08

In the Security News, a phishing scheme that targets AMEX cardholders, the list of labs affected by the American Medical Collection Agency data breach continues to grow, a Silk Road drug dealer ...

Listen
Paul's Security Weekly TV
Integrity Through Prevention, WEforum - Paul's Security Weekly #613 from 2019-07-26T01:26:01

Troels Oerting is the Head of the Global Centre for Cybersecurity established by World Economic Forum in 2018. Troels talks about Security, Privacy, Integrity through Prevention, Protection and ...

Listen
Paul's Security Weekly TV
DDoS, Murray Goldschmidt - Paul's Security Weekly #613 from 2019-07-26T01:11:40

Murray Goldschmidt is the COO & Co-founder of Sense of Security. Murray talks about the Intro to Sense of Security, DDoS in 2019, New trends, and How to address these issues! Full Show Notes: https...

Listen
Paul's Security Weekly TV
Michael Aiello, Google - Enterprise Security Weekly #146 from 2019-07-25T21:00:32

Mike is the Director of Product Management for Google Cloud Security.The concept of shared responsibility between provider and customer is core to managing security and risk as organizations mov...

Listen
Paul's Security Weekly TV
Enterprise News - Enterprise Security Weekly #146 from 2019-07-25T20:46:02

Riverbed launches Aternity to improve digital experiences, Synopsys and Ixia, a Keysight Business, Announce Collaboration to Enable Scalable Networking SoC Validation Solution, CyberArk unveils ...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #137 from 2019-07-25T09:00

In the Leadership and Communications segment, 8 Sales Skills You Need to Learn, The Trust Crisis, Five Management Lessons From the Apollo Moon Landing, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Luis Giraldo, Kaseya - Enterprise Security Weekly #146 from 2019-07-24T19:35:43

Luis is IT Glue s VP, Product. In his native Colombia, he was in the music business, once playing keyboards on tour with Shakira. Luis will be talking about Unified IT, and the Capabilities of K...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #70 from 2019-07-24T09:00

SupPy Chain Malware - Detecting malware in package manager repositories, Attacking SSL VPN, Solving Digital Transformation Cybersecurity Concerns With DevSecOps, How I Could Have Hacked Any Inst...

Listen
Paul's Security Weekly TV
Securing Identity With Conditional Access - Business Security Weekly #137 from 2019-07-24T09:00

Ajit Sancheti is the CEO at Preempt. Ajit will be discussing Securing Identity with Conditional Access.

Full Show Notes: https://w...

Listen
Paul's Security Weekly TV
Secure App Deployment With Unikernels - Application Security Weekly #70 from 2019-07-23T09:00

Ian Eyber is the CEO of NanoVMs. Unikernels are an emerging trend in software deployment because of their isolation, performance and size. However they are still very much new so it's good to le...

Listen
Paul's Security Weekly TV
Security News: July 18, 2019 - Paul's Security Weekly #612 from 2019-07-22T09:00

Slack Resets User Passwords After 2015 Data Breach, Hacker Breached Sprint Customer Accounts Through Samsung Website, Why 72% of people still recycle passwords Why 100% of Security Weekly hosts ...

Listen
Paul's Security Weekly TV
Topic Segment: Security Roundtable - Paul's Security Weekly #612 from 2019-07-21T09:00

They will be covering: Vulnerability Management, Patching, Asset Management, and System Hardening.

Full Show Notes: https://wiki.secu...

Listen
Paul's Security Weekly TV
IT Industry, Jared Haggerty - Enterprise Security Weekly #145 from 2019-07-20T09:00

Jared Haggerty is the Director, Content and Curation for Databerry. Jarred comes on the show to talk about an overview of security in business where it is now and where it is headed and the use ...

Listen
Paul's Security Weekly TV
Identity Authentication, David Harding - Enterprise Security Weekly #145 from 2019-07-19T09:00

David Harding is the SVP & Chief Technology Officer at ImageWare Systems, Inc. Identity authentication is more important now than at any other time in history. Today's methods such as 2-factor a...

Listen
Paul's Security Weekly TV
Eric McAlpine, Momentum Cyber - Business Security Weekly #136 from 2019-07-18T09:00

Eric McAlpine is the Co-founder and Managing Partner at Momentum Cyber. Eric is a Founder & Managing Partner at Momentum Cyber a firm he co-founded in 2018 along with Dave DeWalt and Michael Ted...

Listen
Paul's Security Weekly TV
Security Money: July 15, 2019 - Business Security Weekly #136 from 2019-07-18T09:00

This week we have our quarterly segment to review the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. We also update the Security ...

Listen
Paul's Security Weekly TV
Enterprise News: July 17, 2019 - Enterprise Security Weekly #145 from 2019-07-18T09:00

Vade Secure's Auto-Remediate adds automated protection for Office 365 environments, Aqua Security deepens strategic relationship with Microsoft to accelerate Azure deployments, Trend Micro's Dee...

Listen
Paul's Security Weekly TV
Securing Multi-Cloud Environments - Application Security Weekly #69 from 2019-07-16T09:00

Gururaj Pandurangi is a founder and CEO of Cloudneeti, a software-as-a-service company focused on continuous cloud security, data privacy and compliance assurance. Gururaj is coming on the show ...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #69 from 2019-07-16T09:00

Yes, the zoom thing, 50 Ways to Leak Your Data in 1,300 Popular Android Apps Access Data, Without Proper Permissions, GE Aviation exposed internal configs via open Jenkins instance, Preparing yo...

Listen
Paul's Security Weekly TV
Porn Pirating, Zoom RCE, & Huawei - Paul's Security Weekly #611 from 2019-07-15T09:00

In the Security News, Zoom's RCE Vulnerability is affecting over 700,000 companies, how YouTube is trying to ban hacking videos, 1TB of police body cam footage is available online, and how the U...

Listen
Paul's Security Weekly TV
Cloud-Based Training Solutions - Enterprise Security Weekly #144 from 2019-07-13T09:00

Employees are the weakest link in Cybersecurity and because of this 80% of businesses will adopt a Cloud-based training solution by 2020. Small to Medium sized businesses are being left behind b...

Listen
Paul's Security Weekly TV
Blue/Purple Teaming (defense) - Paul's Security Weekly #611 from 2019-07-13T08:30

Ben has been working in technology and development for over 20 years. He spent 13 years doing defense in the medical industry before moving over to the offense. He uses his knowledge of defense ...

Listen
Paul's Security Weekly TV
PinID, Infoblox, & BeyondTrust - Enterprise Security Weekly #144 from 2019-07-12T09:00

In the news segment, Is Broadcom buying Symantec?, Chronicle will join Google Cloud, PingID to Support FIDO-Compliant Biometric Authentication and Security Keys, and BeyondTrust Simplifies Endpo...

Listen
Paul's Security Weekly TV
Threat Hunting - Enterprise Security Weekly #144 from 2019-07-11T15:01:29

John Strand and Matt Alderman will discuss Threat Hunting.

Full Show Notes: https://wiki.securityweekly.com/ES_Episode144

...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #68 from 2019-07-11T09:00

WordPress Plugin WP Statistics Patches XSS Flaw, Three RCEs in Android's Media framework, Nine Best Practices For Integrating Application Security Testing Into DevOps, 6 Traits That Define DevSe...

Listen
Paul's Security Weekly TV
Science, Ben Franklin, & Lessons - Business Security Weekly #135 from 2019-07-11T09:00

In the Leadership and Communications segment, Life Lessons of Ben Franklin, A Lesson in Leadership, How to Start a Speech: The Best (and Worst) Speech Openers, and more!

Full Show Notes: ...

Listen
Paul's Security Weekly TV
Cloud Native - Application Security Weekly #68 from 2019-07-10T09:00

Mike Shema, John Kinsella, and Matt Alderman talk cloud native from an application perspective.

Full Show Notes: https://wiki.secu...

Listen
Paul's Security Weekly TV
ANSI's Subscription-Based Model - Business Security Weekly #135 from 2019-07-10T09:00

Mark Brown, Senior Director of Standards Connect, from ANSI. ANSI is a nonprofit that supports U.S. voluntary standards and conformity assessment and protects the integrity of these processes. O...

Listen
Paul's Security Weekly TV
Mastercard, Gen Z, & Leadership - Business Security Weekly #134 from 2019-07-04T09:00

In the Leadership and Communications segment, Mastercard CTO reveals must-have executive leadership traits, 10 Presentation Ideas That Will Radically Improve Your Presentation Skills, 7 tech ski...

Listen
Paul's Security Weekly TV
Security Training for Devs - Application Security Weekly #67 from 2019-07-03T09:00

Mike Shema, John Kinsella, & Matt Alderman discuss security training for Devs!

Full Show Notes: https://wiki.securityweekly.com/AS...

Listen
Paul's Security Weekly TV
Security Challenges in the Global Value Chain - Business Security Weekly #134 from 2019-07-03T09:00

Edna Conway is the Chief Security Officer, Global Value Chain at CISCO. Edna will be discussing Global Value Chain at Cisco.

Full Show Notes: Listen

Paul's Security Weekly TV
GKE, AWS, & S3 Buckets - Application Security Weekly #67 from 2019-07-02T09:00

GKE improves authentication with Workload Identity, AWS reinforce reveals traffic tools and security solutions that improve support for DevOps, Brief history of Trusted Execution Environments, F...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #610 from 2019-07-01T09:00

Nearly 100 drivers following Google Maps detour get stuck in muddy field, Breach at Cloud Solution Provider PCM Inc., Inside the West s failed fight against China s Cloud Hopper hackers, Mozilla...

Listen
Paul's Security Weekly TV
CySA+ & PenTest+ Certs, ITProTV - Paul's Security Weekly #610 from 2019-06-30T09:00

Don Pezet will be discussing the new CySA+ and PenTest+ certs that ITProTV has to offer! Don has been working in the IT industry for more than 18 years and in training for more than 12 years. He...

Listen
Paul's Security Weekly TV
Tools to Hack Your Career, CyberSecJobs - Paul's Security Weekly #610 from 2019-06-30T09:00

Kathleen Smith is the CMO at CyberSecJobs.Com/ClearedJobs.Net. We all have cool tools, but not necessarily the best ones for career search or professional development. Why is it so hard? Many of...

Listen
Paul's Security Weekly TV
Enterprise News - Enterprise Security Weekly #143 from 2019-06-28T09:00

CyberArk opens integration ecosystem to community contributions, ExtraHop Announces Reveal(x) Cloud, McAfee announced updates to McAfee MVISION Cloud for Amazon Web Services, and Elastic expands...

Listen
Paul's Security Weekly TV
Email Data Exfiltration, ObserveIT - Enterprise Security Weekly #143 from 2019-06-28T09:00

In our second segment, we welcome Sai Chavali, Security Strategist at ObserveIT. Most companies have preventative controls on email today, however, they are still finding that users exfiltrating...

Listen
Paul's Security Weekly TV
Don't Ignore APIs - Application Security Weekly #66 from 2019-06-27T09:00

API are now over 80% of the HTTP traffic and enterprise application breaches through compromised APIs are mounting!. A guide to API Security. They also discuss Public VS Private APIs and if the ...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #133 from 2019-06-27T09:00

In the Leadership and Communications segment, CEOs Share Their Most Helpful (and Unconventional) Career Advice, 3 Lessons From Emerging Leaders On The Power of Differing Perspectives, New breed ...

Listen
Paul's Security Weekly TV
RSAC Asia Pacific & Japan 2019 - Enterprise Security Weekly #143 from 2019-06-26T20:02:56

In our final segment, we welcome Britta Glade, Director of Content and Curation of RSA Conference, and Linda Gray, Director and Chief of Operations for RSAC APJ, to discuss what's coming new thi...

Listen
Paul's Security Weekly TV
Osquery, Netflix, & Mozilla - Application Security Weekly #66 from 2019-06-26T09:00

Mozilla pushes a patch onto an Array, Netflix shares a stream of patches, Breach to bankruptcy for healthcare company, Osquery becomes a foundational tool, Avoiding DevOps dangers, and Assigning...

Listen
Paul's Security Weekly TV
Third Party Vendor Management - Business Security Weekly #133 from 2019-06-26T09:00

Tom Garrubba is Senior Director/CISO at Santa Fe Group/Shared Assessments. He is an internationally recognized thought leader, lecturer, and blogger on third party risk, and is the head instruct...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #609 from 2019-06-24T09:00

In the Security News, how not to prevent a cyberwar with Russia, the case against knee-jerk installation of Windows patches, U.S. customs and Border Protection data breach is the result of a sup...

Listen
Paul's Security Weekly TV
Purple Teaming, SCYTHE - Paul's Security Weekly #609 from 2019-06-23T09:00

We welcome back Bryson Bort, who is the Founder/CEO of GRIMM. Bryson will be talking about Purple Teaming, Top Attack Simulation Scenarios, and Testing Command & Control Channels.

To lear...

Listen
Paul's Security Weekly TV
Inheriting Someone Else's Code - Enterprise Security Weekly #142 from 2019-06-21T21:00

Paul will talk about the challenges of inheriting someone else's code. Paul will discuss 5 tips: Use an IDE, Variable Usage, Jump To Implementation and Declaration, Global Search, and Inspection...

Listen
Paul's Security Weekly TV
Enterprise News - Enterprise Security Weekly #142 from 2019-06-21T09:00

In the Enterprise News, Docker desktop for Windows 10 will soon switch to WSL 2, Netskope introduces Zero-Trust secure access to private enterprise applications, 10 notable security acquisitions...

Listen
Paul's Security Weekly TV
Challenges of Healthcare Security - Enterprise Security Weekly #142 from 2019-06-20T15:13:02

Security in a healthcare environment takes on many unusual aspects that other industries do not typically deal with. From patient restraints to drug diversion to the highest workplace violence r...

Listen
Paul's Security Weekly TV
3 Shocking Ways To Show Up - Business Security Weekly #132 from 2019-06-20T09:00

In the Leadership and Communications Segment, the trust crisis in business, employee engagement and successful change, and 3 shocking ways to show up today!

Full Show Notes: Listen

Paul's Security Weekly TV
Shannon Lietz, Intuit - Application Security Weekly #65 from 2019-06-19T09:00

Mike Shema and John Kinsella interview Shannon Lietz, the Director Information Security at Intuit about DevOps.

Full Show Notes: h...

Listen
Paul's Security Weekly TV
Azure & Cloud Migration For CISOs - Business Security Weekly #132 from 2019-06-19T09:00

Jeremy Winter is the Director, Azure Management at Microsoft Azure. He joins us to talk about what CSOs & CISOs need to know about Azure + Cloud migration Tips + Mythbusting cloud security issue...

Listen
Paul's Security Weekly TV
Grim, Vim, & Neovim - Paul's Security Weekly #608 from 2019-06-18T09:00

In the Security News, the rise of purple teaming, the World's largest beer brewer sets up a Cyber-security team, a mystery signal shutting down key fobs in an Ohio neighborhood, why hackers igno...

Listen
Paul's Security Weekly TV
Bugs, Breaches, and More! - Application Security Weekly #65 from 2019-06-18T09:00

There's no escape that will save you..., the privilege of running a Chrome extension, and Four practices towards DevSecOps!

Full Show Notes: Listen

Paul's Security Weekly TV
Sysmon DNS Logging, Gravwell - Paul's Security Weekly #608 from 2019-06-17T13:13:50

We welcome back Corey Thuen, Founder and CEO of Gravwell, to talk about security analytics using the new Sysmon DNS logging that dropped this week!

To get involved with Gravwell, visit: <...

Listen
Paul's Security Weekly TV
Seed Rounds, Equity Rounds, Debt Rounds - Enterprise Security Weekly #141 from 2019-06-15T09:00

Matt and Paul talk about Seed Rounds, Equity Rounds, Debt Rounds! Discussing how to invest, how investors operate, and how to get involved with preferred stocks.

Full Show Notes: Listen

Paul's Security Weekly TV
1 Click Microsegmentation, Edgewise - Paul's Security Weekly #608 from 2019-06-15T09:00

Peter Smith, Edgewise Founder and CEO, is a serial entrepreneur who built and deployed Harvard University’s first NAC system before it became a security category. Peter comes on the show to talk...

Listen
Paul's Security Weekly TV
Container Services In Azure, ITProTV - Enterprise Security Weekly #141 from 2019-06-14T09:00

Do you wonder how your team can save costs by lifting and shifting your existing applications to containers, and build micro-services applications to deliver value to your users faster? Use end-...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #131 from 2019-06-13T09:00

In the Leadership and Communications segment, 7 subconscious habits that sabotage your ability to listen - and lead, the power of writing stuff down, what really helps employees improve, and mor...

Listen
Paul's Security Weekly TV
Rapid7, Ixia, & CNA - Enterprise Security Weekly #141 from 2019-06-13T09:00

Rapid7 is integrating access to Insight Platform Applications, Ixia releases a new Scalable, modular packet broker, Sonatype's Nexus user conference to bring 2000 DevSecOps leaders together for ...

Listen
Paul's Security Weekly TV
Privacy: One Year After GDPR - Business Security Weekly #131 from 2019-06-12T09:00

Unfortunately, our scheduled interview was cancelled this week, but we are working to get Brian rescheduled. Instead, we're going to discuss the state of privacy one year after GDPR. Yes, GDPR i...

Listen
Paul's Security Weekly TV
MacOS Catalina, OpenShift, & Pink Floyd - Application Security Weekly #64 from 2019-06-11T13:17:52

"Waiting for the worms to come." -- Pink Floyd and RDP's CVE-2019-0708. Even the NSA warns about the population of exposed systems, A patch commands attention for mail servers, In macOS Catalina...

Listen
Paul's Security Weekly TV
DevSecOps & Software Supply Chains, Microsoft - Application Security Weekly #64 from 2019-06-10T18:03:17

Tanya Janca, also known as SheHacksPurple, is a senior cloud advocate for Microsoft, specializing in application, cloud security, and more! Tanya is joining us on the show to talk about DevSecOp...

Listen
Paul's Security Weekly TV
SalesForce, iPhones, & Old Androids - Paul's Security Weekly #607 from 2019-06-10T09:00

In the Security News, SalesForce bans customers from gun sales, what is your iPhone talking to overnight, Office retires support for old Android versions, and really how likely are weaponized ca...

Listen
Paul's Security Weekly TV
Mental Health & Wellness - Paul's Security Weekly #607 from 2019-06-09T09:00

We welcome back Amanda Berlin, CEO of Mental Health Hackers to talk about why its important to educate technology professionals about unique mental health risks faced by people in the field, and...

Listen
Paul's Security Weekly TV
Imperva, Securonix, & ThreatConnect - Enterprise Security Weekly #140 from 2019-06-08T09:00

Flexera Acquires RISC Networks, Security stays hot as Imperva grabs Distil Networks, EnSilo is raising a series B to monitor and remediate cyber threats, SentinelOne lands $120 mln Series D, Sec...

Listen
Paul's Security Weekly TV
Detection & Response, Endgame - Paul's Security Weekly #607 from 2019-06-08T09:00

In this episode of Paul's Security Weekly, we will talk with Paul Ewing of Endgame about how to close the 'breakout window' between detection and response, and hear about Endgame's recently anno...

Listen
Paul's Security Weekly TV
Importance Of Remediation, Viavi - Enterprise Security Weekly #140 from 2019-06-07T09:00

Charles Thompson is the Senior Director of Product Management at Viavi. Charles will discuss the importance of response/remediation in a strong security strategy and the role wire-data plays in ...

Listen
Paul's Security Weekly TV
The Effectiveness Of Your SOC, LogRhythm - Business Security Weekly #130 from 2019-06-06T09:00

Andrew Hollister is the Chief Architect & Product Manager at LogRhythm. Andrew will talk about the Security Operations Maturity Model: How to Measure the effectiveness of your SOC.

To lea...

Listen
Paul's Security Weekly TV
Defending Against Microsoft Vulnerabilities - Enterprise Security Weekly #140 from 2019-06-06T09:00

Paul will be giving a technical segment on Defending Your Environment Against Major Microsoft Vulnerabilities. Discussion points will consist of: Discovery, Temporary Countermeasures, Be Resilie...

Listen
Paul's Security Weekly TV
Cybersecurity Workforce Gap - Business Security Weekly #130 from 2019-06-05T11:00

John McCumber is the Director, Cybersecurity Advocacy at (ISC)2. John will cover the statistics behind the cybersecurity workforce gap, and explain why what we perceive anecdotally isn't what we...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #63 from 2019-06-05T09:00

This week, Duo reveals a path from a Docker container to its host, Google fumbles some password functionality, GitHub makes dependency tracking more dependable, and more!

Full Show Notes:...

Listen
Paul's Security Weekly TV
Major Identities & Micro Services - Application Security Weekly #63 from 2019-06-04T09:00

Mike and John delve into some DevSecOps topics. They discuss good design patterns that emerged from cloud native environments, Kubernetes and containers, and building blocks of unique services i...

Listen
Paul's Security Weekly TV
Gatekeeper, WannaCry, and BlueKeep- Paul's Security Weekly #606 from 2019-06-03T09:00

In the security news, giving you the latest on thousands of infected servers from a cryptojacking campaign, an open letter to the GCHQ calling out spy agencies, and a new vulnerability that make...

Listen
Paul's Security Weekly TV
Automate IT, SaltStack - Paul's Security Weekly #606 from 2019-06-02T09:00

David Boucha is a Sr. Engineer at SaltStack. David will be talking about how Salt Open and SaltStack Enterprise can help you automate your infrastructure including servers (cloud, on-prem, virtu...

Listen
Paul's Security Weekly TV
Network-Wide Security Policy, Tufin - Enterprise Security Weekly #139 from 2019-06-01T09:00

Ruvi Kitov, CEO and Co-Founder of Tufin, talks about the importance of having a network-wide security policy! The discussion will be on the importance of having a network-wide security policy, t...

Listen
Paul's Security Weekly TV
BlueKeep Vulnerability, Robert Graham - Paul's Security Weekly #606 from 2019-06-01T09:00

Paul Asadoorian and Robert Graham from Errata Security show you how to search for the BlueKeep vulnerability, or CVE-2019-0708, that has been affecting hundreds of thousands of systems!

F...

Listen
Paul's Security Weekly TV
Digital Hygiene & The School System - Paul's Security Weekly #606 from 2019-05-31T13:53:22

Eric Butash and Mike Klein from Highlander Institute, join us on the show to talk about, what schools are doing to protect Student Data?, how do we teach our student the importance of good digit...

Listen
Paul's Security Weekly TV
Verodin, Palo Alto, & Okta - Enterprise Security Weekly #139 from 2019-05-31T09:00

John Strand and Paul Asadoorian discuss how Okta joins forces with Secret Double Octopus, Tenable unveils new innovations for Cyber Exposure analytics, Barracuda launches bot protection feature ...

Listen
Paul's Security Weekly TV
Understanding & Quantifying Cyber Risk, RiskLens - Enterprise Security Weekly #139 from 2019-05-29T20:37:21

We interview Jack Jones, Chief Risk Scientist at RiskLens to talk about Understanding and quantifying cyber risk using FAIR!

Full Show Notes: Listen

Paul's Security Weekly TV
Google, Huawei, & Windows 0-Day - Paul's Security Weekly #605 from 2019-05-27T09:00

In our final segment, Doug, Jeff, Patrick, and Lee give you the latest security news to talk about a Zero Day for Windows, the battle over Huawei with the US and Google, & unpatched hardware and...

Listen
Paul's Security Weekly TV
Does DNS Fit Into A Secure Architecture - Paul's Security Weekly #605 from 2019-05-26T09:00

In our second segment, we welcome Justin Murphy, Cloud Security Engineer at Cisco, to talk about DNS in the Security Architecture!

Full Show Notes: Listen

Paul's Security Weekly TV
KnowBE4, Autho0, & Guardicore - Enterprise Security Weekly #138 from 2019-05-25T15:30

In the Enterprise News, ThreatQuotient expands integration with MITRE ATT&CK Framework, JASK launches a new Heads Up Display for security operations centers, and we have some acquisition and fun...

Listen
Paul's Security Weekly TV
Candy Alexander, ISSA - Enterprise Security Weekly #138 from 2019-05-25T09:00

Candy Alexander is the President of Information Systems Security Association. Ms. Alexander has 30 years of information security experience working for various high-tech companies. She has held ...

Listen
Paul's Security Weekly TV
Matthew McMahon, Salve Regina University - Paul's Security Weekly #605 from 2019-05-25T09:00

We welcome Matthew McMahon, Head of Security Analytics at Salve Regina University, to talk about Medical devices, Cybersecurity and Resilience, and Cybersecurity Training!

Full Show Notes...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #62 from 2019-05-23T09:00

Cisco Expressway goes off path and a Cisco IOS XE vuln goes for emojis, More erosion of CPU data boundaries, RDP patches a pre-auth problem and even resuscitates a patch process for XP, Microsof...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #129 from 2019-05-22T09:00

In the Leadership and Communications segment, don't let your expertise narrow your perspective, don't be blinded by your own expertise, and the smartest cities in the future of urban development...

Listen
Paul's Security Weekly TV
Cody Wood, Signal Sciences - Application Security Weekly #62 from 2019-05-22T09:00

Mike Shema and John Kinsella interview Cody Wood. Cody Wood is the AppSec Product Support Engineer at Signal Sciences.

To get involved with Signal Sciences, visit: Listen

Paul's Security Weekly TV
Discovering Applications, Netsparker - Business Security Weekly #129 from 2019-05-21T09:00

We welcome Ferruh Mavituna, Founder and CEO of Netsparker! They will be discussing the discover and scan perspective of applications, how to handle in-house written applications vs. ones that ar...

Listen
Paul's Security Weekly TV
Singapore, Cisco, and Israeli Spyware - Paul's Security Weekly #604 from 2019-05-20T09:00

In the Security News, Singapore passes an anti-fake news law, WhatsApp Vulnerability Exploited to Infect Phones with Israeli Spyware, major security issues found in Cisco routers, and Microsoft ...

Listen
Paul's Security Weekly TV
Fixing Identity and Access Management - Paul's Security Weekly #604 from 2019-05-19T09:00

Federico Simonetti is the CTO of Xiid Corporation. Federico comes on the show to discuss How To Fix Identity & Access Management.

Full Show Notes: Listen

Paul's Security Weekly TV
Julian Zottl, Raytheon - Paul's Security Weekly #604 from 2019-05-18T09:00

Julian Zottl is the Cyber and Information Operations SME at Raytheon. Julian joins us on the show to talk about side-channel attacks!

Full Show Notes: Listen

Paul's Security Weekly TV
Centralization of Web Security, Netsparker - Enterprise Security Weekly #137 from 2019-05-17T09:00

Ferruh Mavituna is the Founder & Product Manager at Netsparker. Centralization vs. Decentralization of security is an interesting topic. Decentralization in web app penetration testing is popula...

Listen
Paul's Security Weekly TV
SysDig, In-Q-Tel, NextGen, & SIEM - Enterprise Security Weekly #137 from 2019-05-17T09:00

In the news, Atos launches a new unified cloud identity and access management solution, ExtraHop announces new panorama partner program, SysDig and In-Q-Tel partnership to provide U.S. governmen...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #128 from 2019-05-16T09:00

In the Leadership and Communications segment, Transformational leadership style inspires 'moonshot goals', How to Deal With Information Overload, The surprising secret of success: it's not about...

Listen
Paul's Security Weekly TV
Firewalls, Paul Asadoorian - Enterprise Security Weekly #137 from 2019-05-16T09:00

Paul will be giving a technical segment on firewalls. Paul talks about an enterprise open-source firewalls?

Full Show Notes: https...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #61 from 2019-05-15T09:00

In the Application News, Chrome constrains the cookies and Edge pushes privacy, Windows builds a sandbox for Linux, Android Q for more quarantined code with more LLVM features, Steve Singh stepp...

Listen
Paul's Security Weekly TV
Jon Fredrickson, BCBSRI - Business Security Weekly #128 from 2019-05-14T13:47:20

This week, we welcome Jon Fredrickson, Information Security Officer at Blue Cross & Blue Shield of Rhode Island.

Full Show Notes: ...

Listen
Paul's Security Weekly TV
Securing Software Supply Chains - Application Security Weekly #61 from 2019-05-14T09:00

This week, Derek Weeks joins us to talk about DevSecOps and Securing Software Supply Chains. Derek is the VP and DevOps Advocate at Sonatype. Derek is the world's foremost researcher on the topi...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #603 from 2019-05-13T09:00

The top 5 mistakes that create field days for hackers, WordPress 5.2 brings new security features, a discontinued Insulin pump with security a security flaw in high demand, and how to communicat...

Listen
Paul's Security Weekly TV
Chris Sanders, AND & RTF - Paul's Security Weekly #603 from 2019-05-12T09:00

Chris Sanders is the Founder of Applied Network Defense & Rural Technology Fund. He is also the Director of the Rural Technology Fund, a non-profit that donates scholarships and equipment to pub...

Listen
Paul's Security Weekly TV
Security Industry Briefings Update - Enterprise Security Weekly #136 from 2019-05-11T19:00

We have a Security Industry Briefings Update, where we talk about 42Crunch, Viridium, Whitecanyon, and Eclypsium!

Full Show Notes: Listen

Paul's Security Weekly TV
Enterprise News - Enterprise Security Weekly #136 from 2019-05-11T09:00

In the Enterprise news, Secureworks launches new cybersecurity analytics app, StackRox Kubernetes Security Platform Receives Red Hat Container Certification, SIEM Solutions Firm Exabeam Raises $...

Listen
Paul's Security Weekly TV
From IT to OT Security, Lesley Carhart - Paul's Security Weekly #603 from 2019-05-11T09:00

Lesley Carhart is the Principal Threat Analyst at Dragos Inc.. Lesley has been performing digital forensics and incident response on unconventional systems and advanced adversary attacks for ove...

Listen
Paul's Security Weekly TV
Continuous Controls Monitoring, Panaseer - Enterprise Security Weekly #136 from 2019-05-10T09:00

Nik Whitfield is the CEO at Panaseer. He joins us to talk about Continuous Controls Monitoring!

Full Show Notes: https://wiki.secu...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #60 from 2019-05-09T09:00

Firefox gives more scrutiny to add-ons but Firefox also forgot to give more scrutiny to a cert, Path traversals trampled by ransomware, Secure Software Design: The Next Frontier In Cybersecurity...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #127 from 2019-05-08T09:00

In the Leadership and Communications segment, How to build a startup, You Don't Have To Be Nice To Be Respected. Boeing and the Importance of Encouraging Employees to Speak Up, and more!

...

Listen
Paul's Security Weekly TV
Sven Morgenroth, Netsparker - Application Security Weekly #60 from 2019-05-08T09:00

Sven joins us to talk about securing our applications, how confident can we be about the security of web applications, and how we can make it easier to build applications that we don't need to w...

Listen
Paul's Security Weekly TV
Global Cyber Innovation Summit Recap - Business Security Weekly #127 from 2019-05-07T14:18:33

Matt, Jason, and Paul do a recap on the Global Cyber Innovation Summit that was held in Baltimore last week!

Full Show Notes: http...

Listen
Paul's Security Weekly TV
Philip Niedermair, National Cyber Group - Paul's Security Weekly #602 from 2019-05-06T15:28:18

We welcome Philip Niedermair from National Cyber Group. Philip is the CEO at National Cyber Group and he joins us to discuss the National Cyber Education Program!

Full Show Notes: Listen

Paul's Security Weekly TV
Joshua Abraham, Praetorian - Paul's Security Weekly #602 from 2019-05-05T09:00

Josh Abraham is in studio! He is a Staff Engineer at Praetorian, and he is going to talk about the MITRE attack framework for attackers!

Full Show Notes: Listen

Paul's Security Weekly TV
ThreatConnect, HALO, & SolarWinds - Enterprise Security Weekly #135 from 2019-05-04T09:00

In the Enterprise news, ThreatConnects new features make creating security playbooks easier, SolarWinds adds password management to security portfolio, Checkpoint Systems announces HALO IoT plat...

Listen
Paul's Security Weekly TV
Nokia 9, Julian Assange, & Tenable - Paul's Security Weekly #602 from 2019-05-04T09:00

In the Security News, how Tenable experts found 15 flaws in wireless penetration systems, Julian Assange refused exfiltration to the US, PoC exploits for old SAP config flaws increase risk of at...

Listen
Paul's Security Weekly TV
Joshua Abraham, Praetorian - Enterprise Security Weekly #135 from 2019-05-03T09:00

Josh Abraham is in studio! He is a Staff Engineer at Praetorian, and he is going to talk about the MITRE attack framework for defenders!

Why Praetorian Benchmarks to MITRE ATT&CK: Listen

Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #126 from 2019-05-02T09:00

In the Leadership and Communications segment, 5 Myths about Strategy, The making of a technology leader, Want Fewer Employees to Quit? Listen to Them, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Patch Management Struggles, Automox - Enterprise Security Weekly #135 from 2019-05-02T09:00

A self-described "Nerd with a big mouth" Jay is an 18-year startup veteran specialized in pre-IPO, hyper-competitive environments with a focus on new technology introduction, partner/customer ac...

Listen
Paul's Security Weekly TV
Security Awareness, Education, & Training - Business Security Weekly #126 from 2019-05-01T21:04:08

Craig Sandman is the President and Co Founder of Symbol Security, a Cyber Security SaaS company with a mission to reduce corporate risk through Security Awareness Education. Craig will discuss S...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #59 from 2019-05-01T09:00

In the Application Security News, Software update gums up fingerprints, a counterproductive security practice expires thanks to well-considered guidelines, Docker Hub breach response, a path to ...

Listen
Paul's Security Weekly TV
Larry Maccherone, Comcast - Application Security Weekly #59 from 2019-04-30T17:31:15

This week, we welcome Larry Maccherone, Senior Director of Comcast, to talk about the world of SecOps vs. DevSecOps!

Full Show Notes: Listen

Paul's Security Weekly TV
Fujifilm, Facebook, & Black Holes - Paul's Security Weekly #601 from 2019-04-29T09:00

Serious vulnerabilities found in Fujifilm x-ray devices, Facebook could be fined 5 billion over privacy violations, preinstalled malware on bootleg streaming devices, hackers using SIM swapping ...

Listen
Paul's Security Weekly TV
SaaS Product, Cloudneeti - Paul's Security Weekly #601 from 2019-04-28T09:00

Guru Pandurangi is the CEO and Founder of Cloudneeti, to talk about how their SaaS product is delivering continuous cloud security and compliance assurance to businesses migrating or using cloud...

Listen
Paul's Security Weekly TV
Dave Kennedy, Binary Defense - Enterprise Security Weekly #134 from 2019-04-27T09:00

Security Legend Dave Kennedy sits down with our Founder and CTO Paul Asadoorian at InfoSec World 2019 to discuss his company Binary Defense and how they're helping the Security community! A grea...

Listen
Paul's Security Weekly TV
The Canary Tool, Thinkst - Paul's Security Weekly #601 from 2019-04-27T09:00

Haroon Meer is the CEO and Researcher at Thinkst. He is coming on the show to talk about why hackers should create companies, and some of the technical details behind Thinkst' tool Canary!

<...

Listen
Paul's Security Weekly TV
ShieldX, Tenable, & Capsule8 - Enterprise Security Weekly #134 from 2019-04-26T09:00

In the Enterprise news, ShieldX adds lateral movement prevention to the Elastic Security Platform for AWS, Tenable Integrates with Google Cloud Security Command Center, Capsule8 to help Google C...

Listen
Paul's Security Weekly TV
Francis Dinha, OpenVPN - Enterprise Security Weekly #134 from 2019-04-25T09:00

This week, Paul Asadoorian is joined by Matt Alderman, as we interview Francis Dinha, the CEO of OpenVPN. Francis Dinha is the CEO of OpenVPN.

Full Show Notes: Listen

Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #125 from 2019-04-24T21:00

In the Leadership and Communications segment, 5 Ways to Find Natural Leaders for Your Team, Business Wisdom Learned From Bomb Squad Experts And Their Commanders, Why Rest Is Essential To High Pe...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #58 from 2019-04-23T21:00

In the Application Security News, Breach at IT outsourcer Wipro, SCP serves the file it wants, Confluence Path traverses to RCE, another Local PrivEsc on Windows, easier sandboxing for C and C++...

Listen
Paul's Security Weekly TV
Thomas Hatch, SaltStack - Application Security Weekly #58 from 2019-04-23T09:00

Thomas is the creator of the Salt open source software project and the CTO of SaltStack, the company behind Salt. He has spent his career writing software to orchestrate and automate the work of...

Listen
Paul's Security Weekly TV
Patrick Tierney, Endgame - Enterprise Security Weekly #133 from 2019-04-20T09:00

We interview Patrick Tierney, the Sales Engineer at Endgame.

To get involved with Endgame, visit: https://securityweekly.com/endgame

...

Listen
Paul's Security Weekly TV
Tufin, OpenVPN, & NYSE IPO - Enterprise Security Weekly #133 from 2019-04-19T09:00

In the news, OpenVPN and JumpCloud Partner to Bring Secure Cloud-based Authentication and User Management to VPN, IdenTrust and Device Authority Collaborate to Deliver Secure Lifecycle Managemen...

Listen
Paul's Security Weekly TV
SOC Intel: Wire, Logs, & Endpoint - Enterprise Security Weekly #133 from 2019-04-18T13:51:14

Matt Cauthorn is the VP of Cyber Security Engineering at ExtraHop. Matt Cauthorn leads a team of technical security engineers who work directly with customers and prospects. Matt uses his expert...

Listen
Paul's Security Weekly TV
How To Think Like An Investor, Will Lin - Business Security Weekly #124 from 2019-04-18T09:00

Will is a Partner and a Founding Investor at ForgePoint Capital. He has been an avid technology enthusiast for decades: building his first computer in elementary school and starting online busin...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #57 from 2019-04-17T09:00

3D fingerprints and unlocking Android, Ticking off another command injection, Alexa, audio, and annotations, STS no longer just for HTTP, and Hardenize goes beyond TLS.

Full Show Notes: <...

Listen
Paul's Security Weekly TV
Security Money - Business Security Weekly #124 from 2019-04-17T09:00

This week we have our quarterly segment to review the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. We also update the Security ...

Listen
Paul's Security Weekly TV
Containers and Kubernetes - Application Security Weekly #57 from 2019-04-16T14:20:39

This last week was pretty busy with announcements and presentations from the Google Next Conference. In 2018 they previewed some security tools and this year many of them are now GA along with a...

Listen
Paul's Security Weekly TV
Bitcoin, WikiLeaks, & Julian Assange - Paul's Security Weekly #600 from 2019-04-16T09:00

In the news, Bitcoin mining ban considered by China's economic planner, Yahoo strikes $117.5 million data breach settlement, Serious flaws leave WPA3 vulnerable to hacks that steal Wi-Fi passwor...

Listen
Paul's Security Weekly TV
Merissa & Jessica, WSC - Paul's Security Weekly #600 from 2019-04-15T09:00

Merissa Villalobos is the North America Talent Acquisition Leader for NCC Group, a global security consulting firm and has been recruiting in security for 10 years. She got her start in Virginia...

Listen
Paul's Security Weekly TV
Gabriel Gumbs, Spirion - Paul's Security Weekly #600 from 2019-04-14T09:00

Gabriel Gumbs is the VP of Product Management at Spirion where his focus is on the strategy and technology propelling Spirion’s rapidly-growing security platform. A cybersecurity industry vetera...

Listen
Paul's Security Weekly TV
Coalfire ASV Scanning - Enterprise Security Weekly #132 from 2019-04-13T09:00

Mike Weber is the Vice President of Coalfire and Rebecca Larson is the Director, Vulnerability Assessment Operations of Coalfire.

Coalfire ASV Scanning:

- ASV program (love, praise...

Listen
Paul's Security Weekly TV
Vendor Briefing - Enterprise Security Weekly #132 from 2019-04-13T09:00

In the last segment, we air the Security Briefing from Secure World Boston! Paul and Matt review the vendors at SecureWorld Boston 2019!

Full Show Notes: Listen

Paul's Security Weekly TV
Cloud Security, Bitglass, & Funding - Enterprise Security Weekly #132 from 2019-04-12T09:00

In the news, Cloud security company Bitglass raises $70M in late-stage round, Lockpath Announces Significant Updates to Keylight Platform, TrustBuilder Identity Hub introduces simple and scalabl...

Listen
Paul's Security Weekly TV
Calendars, Work-Life, & Balance - Business Security Weekly #123 from 2019-04-10T09:00

In the Leadership and Communications segment, 94% of CIOs, CISOs have to make protection compromises, Accelerating Business Through Customer Centricity, 5 states dominating tech employment, and ...

Listen
Paul's Security Weekly TV
Docker, ARM, & "Selfie" - Application Security Weekly #56 from 2019-04-10T09:00

In the News segment, The Matrix turns 20, Containers are Weakest Security Leak Again, The Evolution of Application Security in the Serverless World, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Falco, Sysdig - Application Security Weekly #56 from 2019-04-10T09:00

This week, we welcome Loris Degioanni from Sysdig to discuss their open source container native runtime security project called Falco!

To learn more about Sysdig, visit: Listen

Paul's Security Weekly TV
Post-Perimeter Security , Lookout - Business Security Weekly #123 from 2019-04-09T09:00

Michael Murray is the Chief Security Officer at Lookout. Michael joins us today to talk about Post-perimeter Security.

Full Show Notes: Listen

Paul's Security Weekly TV
OceanLotus, Russia, & Google - Paul's Security Weekly #599 from 2019-04-01T09:00

In the Security News, Attackers exploiting IMAP to bypass MFA on O365 and G-Suite accounts, Vietnam's OceanLotus Group Ramps up hacking car companies, UC Browser violates Google Play Store Rules...

Listen
Paul's Security Weekly TV
Threat Hunting & AI Hunter, ACM - Paul's Security Weekly #599 from 2019-03-31T09:00

In the Technical Segment, we welcome back our friend Chris Brenton, Chief Operating Officer at Active Countermeasures, to discuss why threat hunting is the missing link between our protection to...

Listen
Paul's Security Weekly TV
Illusive Networks - Enterprise Security Weekly #131 from 2019-03-30T21:00

Paul sits down with Wade Lance and Nir Greenberg of Illusive Networks at the RSA Conference 2019!

 

Full Show Notes: https:...

Listen
Paul's Security Weekly TV
Mary Beth Borgwing, Cyber Social Club - Paul's Security Weekly #599 from 2019-03-30T09:00

This week, we welcome back Mary Beth Borgwing, President and Founder of of the Cyber Social Club, to talk about Uniting Women in Cyber!

Full Show Notes: Listen

Paul's Security Weekly TV
Branden Williams, Union Bank - Enterprise Security Weekly #131 from 2019-03-29T09:00

Dr. Branden R. Williams has more than twenty years of experience in business, technology, and information security as a consultant, leader, and an executive. His specialty is navigating complex ...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #122 from 2019-03-28T20:34:31

In the Leadership and Communications segment, even CEOs should clean their own bathrooms sometimes, building an effective cybersecurity program, how to get booked as a podcast guest, and more! Listen

Paul's Security Weekly TV
Bugs, Breaches, and More! - Application Security Weekly #55 from 2019-03-28T20:34:14

XSS Vulnerability in Abandoned Cart Plugin Leads to WordPress Site Takeover, The RedMonk Programming Language Rankings: January 2019, I Deleted Facebook Last Year; Here's What Changed (and What ...

Listen
Paul's Security Weekly TV
Security ROI, Endgame - Business Security Weekly #122 from 2019-03-28T17:00

Ian McShane, the VP, Product Marketing at Endgame, joins us on Business Security Weekly to talk about security ROI and how to align goals, skills, and budgets to reduce risk.

 

To ...

Listen
Paul's Security Weekly TV
Android Q, Sirens, & Korean Hotels - Paul's Security Weekly #598 from 2019-03-26T09:00

In the Security News, how Android Q will come with improved privacy protections, hacked tornado sirens taken offline ahead of a major storm, and how Putty released an update that fixed 8 new sec...

Listen
Paul's Security Weekly TV
Iris, DomainTools - Paul's Security Weekly #598 from 2019-03-25T09:00

In this segment, we run a Technical Demo with our sponsor DomainTools, all about Domain Investigation with DomainTools Iris!

To learn more about DomainTools, visit: Listen

Paul's Security Weekly TV
Marcus Carey, Tribe of Hackers - Paul's Security Weekly #598 from 2019-03-24T09:00

Marcus Carey is the Founder & CEO at Threatcare. Navy Cryptologist turned cybersecurity entrepreneur, Marcus Carey is Currently working as founder and CEO of cybersecurity company Threatcare. He...

Listen
Paul's Security Weekly TV
NexDefense, 42Crunch, & ExtraHop - Enterprise Security Weekly #130 from 2019-03-22T09:00

Stackpath released new edge computing VMs, ExtraHop hires former Tenable and HPE leaders to support growth in cyber, Security professionals want to return fire to Venafi, Dragos acquires NexDefe...

Listen
Paul's Security Weekly TV
Endgame, Virsec, & SCYTHE - Enterprise Security Weekly #130 from 2019-03-21T09:00

Paul Asadoorian and Matt Alderman recorded interviews with the following vendors at RSA Conference 2019: Endgame, Virsec, and SCYTHE

Full Show Notes: Listen

Paul's Security Weekly TV
DARPA, Yelp, & FBI - Application Security Weekly #54 from 2019-03-21T08:30

Owner of MAGA-Friendly Yelp Knockoff Threatens to Call FBI After Researcher Exposes Security Holes, Chinese Data Breach Exposes 'Breed Ready' Status Of Almost 2 Million Women, Dozens of companie...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #121 from 2019-03-20T09:00

In the Leadership and Communications segment, How Boeing Should Have Responded to the 737 Max Safety Crisis, Digital Transformation is Not About Technology, Gartner's Top 10 Security Projects fo...

Listen
Paul's Security Weekly TV
Jamie Duncan, Red Hat - Application Security Weekly #54 from 2019-03-20T09:00

Jamie Duncan is a recovering history major who has been at Red Hat for just over 7 years. Beginning with his role as a TAM, his focus has increasingly centered on the operations-oriented feature...

Listen
Paul's Security Weekly TV
Intersection of Development & Security - Business Security Weekly #121 from 2019-03-19T15:01:11

Nick Galbreath, Co-founder and Chief Technology Officer at Signal Sciences, to discuss the Intersection of Development and Security!

To learn more about Signal Sciences, visit: Listen

Paul's Security Weekly TV
Malware Sandboxing, VMRay - Paul's Security Weekly #597 from 2019-03-18T09:00

We interview Carsten Williams, Co-Founder and CEO at VMRay, discussing malware sandboxing! Carsten is the original developer of CWSandbox, a commercial malware analysis suite that was later rena...

Listen
Paul's Security Weekly TV
Tesla, YouTube, & Sexy Selfies - Paul's Security Weekly #597 from 2019-03-17T09:00

New WordPress flaw lets unauthenticated remote attackers hack sites, Tesla allegedly spied on and ran a smear campaign on a whistleblower, Facebook and Instagram suffer most severe outage ever, ...

Listen
Paul's Security Weekly TV
RSAC 2019 Recap - Enterprise Security Weekly #129 from 2019-03-16T09:00

Paul Asadoorian and Matt Alderman recap RSA Conference 2019, including their briefings with: - 42Crunch - Baffle - CyberInt - Eclypsium - Ericom Software - Lacework - Radware - RiskRecon and Mor...

Listen
Paul's Security Weekly TV
Evolution of Zero Trust, Edgewise - Paul's Security Weekly #597 from 2019-03-16T09:00

We welcome Peter Smith, Founder and CEO of Edgewise to talk about the evolution of Zero Trust! Smith, Edgewise Founder and CEO, is a serial entrepreneur who built and deployed Harvard University...

Listen
Paul's Security Weekly TV
Continuous Cloud Assurance, Cloudneeti - Enterprise Security Weekly #129 from 2019-03-15T09:00

This week, we interview Gururaj Pandurangi, Founder and CEO at Cloudneeti, to discuss Continuous Cloud Assurance! Gururaj Pandurangi is a founder and CEO of Cloudneeti, a software-as-a-service c...

Listen
Paul's Security Weekly TV
RSAC 2019 Interviews Enterprise Security Weekly #129 from 2019-03-14T18:06:23

Paul Asadoorian and Matt Alderman recorded interviews with the following vendors at RSA Conference 2019:

- Venafi

- XM Cyber

- Onapsis

Full Show Notes: Listen

Paul's Security Weekly TV
Application News - Application Security Weekly #53 from 2019-03-14T09:00

WordPress accounted for 90 percent of all hacked CMS sites in 2018, Japanese police charge 13-year-old for sharing 'unclosable popup' prank online, Facebook exploit – Confirm website visitor ide...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #120 from 2019-03-13T09:00

In the Leadership and Communications segment, How to Make Sure Your Board Sets a Good Example for Your Company, Cybersecurity is Putting Customer Trust at the Center of Competition, 6 Reasons Yo...

Listen
Paul's Security Weekly TV
RSA 2019 Recap - Application Security Weekly #53 from 2019-03-13T09:00

Keith and Paul discuss the structure and experiences of 2019's RSA Conference.

Full Show Notes: https://wiki.securityweekly.com/AS...

Listen
Paul's Security Weekly TV
Ben Carr, Aristocrat - Business Security Weekly #120 from 2019-03-12T16:32:34

Ben Carr is the Chief Information Security Officer at Aristocrat. Prior to Aristocrat, we was VP of Strategy for Cyberbit and North America's Technical Director for Tenable. Prior to Tenable, he...

Listen
Paul's Security Weekly TV
YouTube Censorship & Vulnerabilities- Paul's Security Weekly #596 from 2019-03-04T10:00

YouTube controversy on ALL fronts, Cisco SOHO wireless VPN firewalls and routers open to attack, Ring doorbell flaw opens door to spying, bot plagues, free hacking toolkits, and everything you n...

Listen
Paul's Security Weekly TV
David Marble, OSHEAN - Paul's Security Weekly #596 from 2019-03-03T10:00

David Marble is the President & CEO at OSHEAN. David joins us to talk about what to expect at at this years Rhode Island Cybersecurity Exchange Day! This conference will be held on March 13th 20...

Listen
Paul's Security Weekly TV
PCI, Capsule8, & Polaris - Enterprise Security Weekly #128 from 2019-03-02T10:00

Capsule8 expands threat detection platform for PCI DSS, BitSight unveils peer analytics for more effective security performance management, Imperva advances autonomous application protection cap...

Listen
Paul's Security Weekly TV
Threat Intelligence, Recorded Future - Paul's Security Weekly #596 from 2019-03-02T10:00

Allan Liska is the Senior Solutions Architect at Recorded Future. Allan talks about threat intelligence – no longer just for the secret squirrels among us. While the term can elicit reactions ra...

Listen
Paul's Security Weekly TV
Funding and M&A News - Enterprise Security Weekly #128 from 2019-03-01T10:00

Paul and Matt discuss some Funding and M&A, such as Elevate Security announces an $8 million series A to alter employee security behavior, Armorblox raises 16.5 million in series A, Bandura Cybe...

Listen
Paul's Security Weekly TV
Matt Springfield, 12Feet, Inc. - Application Security Weekly #52 from 2019-02-28T10:00

Matt Springfield is the founder of 12Feet, Inc. an information security consulting firm based in the Dallas area. Matt has more than 23 years of information security experience spanning operatio...

Listen
Paul's Security Weekly TV
Bruce Sussman, SecureWorld - Business Security Weekly #119 from 2019-02-27T10:00

Bruce Sussman is the Media-Development Director at SecureWorld. Bruce will give us a preview of SecureWorld Boston 2019 and the upcoming events.

Full Show Notes: Listen

Paul's Security Weekly TV
Securing the Human Layer, Armorblox - Business Security Weekly #119 from 2019-02-27T10:00

DJ Sampath is the Co-Founder and Chief Executive Officer at Armorblox. DJ comes on the show to discuss "Securing the Human Layer"!

Full Show Notes: Listen

Paul's Security Weekly TV
Bugs, Breaches, and More! - Application Security Weekly #52 from 2019-02-27T10:00

Many websites threatened by highly critical code-execution bug in Drupal, UK parliament calls for antitrust, data abuse probe of Facebook, CommitStrip: Get rich quick, Google says the built-in m...

Listen
Paul's Security Weekly TV
Passwords, Splunk, & Nest Microphones - Paul's Security Weekly #595 from 2019-02-25T10:00

In the Security News, password managers leaking data in memory, security analysts are only human, Splunk changes position of Russian customers, Google admits error over hidden microphone, and a ...

Listen
Paul's Security Weekly TV
Steve Brown, SecureWorld Keynote - Paul's Security Weekly #595 from 2019-02-24T10:00

Steve Brown, Keynote Speaker at SecureWorld Boston 2019 to discuss his talk about Building Your Strategic Roadmap for the Next Wave of Digital Transformation!

Full Show Notes: Listen

Paul's Security Weekly TV
Product Launches and Announcements - Enterprise Security Weekly #127 from 2019-02-23T10:00

CylancePROTECT now available on AWS marketplace, Attivo Networks enhances deception platform with Forensic Collection, Cyber Security market will reach $365.26B by 2026, and Elevate Security rai...

Listen
Paul's Security Weekly TV
SILENTRINITY Updates, BHIS - Paul's Security Weekly #595 from 2019-02-23T10:00

Marcello Salvati, Security Analyst at our sponsor Black Hills Information Security, to give some updates on his Post Exploitation Tool SILENTRINITY! Sign up for the BHIS Mailing List to receive ...

Listen
Paul's Security Weekly TV
SOAR, Cody Cornell - Enterprise Security Weekly #127 from 2019-02-22T10:00

Cody Cornell is the CEO of Swimlane. Matt Alderman and Joff Thyer interview Cody, to discuss Security Orchestration, Automation, and Response!

Full Show Notes: Listen

Paul's Security Weekly TV
Leadership & Communication - Business Security Weekly #118 from 2019-02-21T10:00

In the Leadership and Communications segment, are boards of directors responsible for cybersecurity, cybersecurity mental health warning, how to cope with a Mid-Career Crisis, and more!

F...

Listen
Paul's Security Weekly TV
Android, Dark Web, & Development - Application Security Weekly #51 from 2019-02-20T10:00

A PNG Android Vulnerability, 620 Million Stolen Accounts for Sale on the Dark Web, How Shifting Security Left Speeds Development and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Cyber Insurance, Brendan Goodwin - Business Security Weekly #118 from 2019-02-20T10:00

Brendan Goodwin is the Regional Cyber Director – Northeast & Mid-Atlantic at Alfred J. Gallagher Co. Brendan comes on the show to talk about "How Cyber Insurance can Augment Your Cyber Security ...

Listen
Paul's Security Weekly TV
DEFCON, Windows 10, & Linux vs Mac - Paul's Security Weekly #594 from 2019-02-19T10:00

Why it's way too easy to sell counterfeit goods on amazon, how to defend against the runC container vulnerability, creating a dream team for the new age of cyber security, how you can get a wind...

Listen
Paul's Security Weekly TV
Integrating Security into DevOps, Altran - Application Security Weekly #51 from 2019-02-19T10:00

Gurpreet S. Sachdeva is the Assistant Vice President of Technology for Altran. Gurpreet Sachdeva will be discussing "Integrating Security into DevOps"!

Full Show Notes: Listen

Paul's Security Weekly TV
Enterprise-ish Network Security: Pt. 1 - Paul's Security Weekly #594 from 2019-02-18T10:00

There are quite a few choices for selecting open-source and inexpensive hardware to build your network and provide tools to monitor for security events. In this segment we'll discuss some of the...

Listen
Paul's Security Weekly TV
Harry Sverdlove, Edgewise - Paul's Security Weekly #594 from 2019-02-17T10:00

Harry Sverdlove, Chief Technology Officer of Edgewise for an interview, to talk about The Future of Firewalls!

To learn more about Edgewise, visit: Listen

Paul's Security Weekly TV
The Evolution Of Vulnerability Management - Enterprise Security Weekly #126 from 2019-02-16T10:00

Where do we stand today in the following 3 areas when it comes to vulnerability management: 1. Applications - DevOps, containers and applications in general (desktop and SaaS) - What are the new...

Listen
Paul's Security Weekly TV
Qualys, Lacework, & Multicloud - Enterprise Security Weekly #126 from 2019-02-15T10:00

Cisco unlocks IoT potential with Intent-Based Networking, Qualys extends cloud platform with patch management, Tenable announces general availability of Predictive Prioritization, and Lacework a...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #50 from 2019-02-14T10:00

In the Application Security News, Many popular iPhone apps secretly record your screen without asking, MongoDB databases still being held for ransom, Most of the Fortune 100 still use flawed sof...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #117 from 2019-02-13T10:00

In the Leadership and Communications segment, Keep your employees and you'll keep your customers, Why leadership development is superficial and how to fix it, simple techniques to overcome negat...

Listen
Paul's Security Weekly TV
Basic Flow of Problem, Solution, and Value - Application Security Weekly #50 from 2019-02-13T10:00

Tim Eades is the CEO at vArmour. Tim joins us on the show to talk about the basic flow of problems, the solutions, and the value.

Full Show Notes: Listen

Paul's Security Weekly TV
Connie Mastovich, InfoSec World 2019 - Paul's Security Weekly #593 from 2019-02-12T10:00

Connie Mastovich is the Sr. Security Compliance Analyst at Reclamere and she will be speaking at InfoSec World 2019. Connie's talk will be about "The Dark Web 2.0: How It Is Evolving, and How Ca...

Listen
Paul's Security Weekly TV
Ed Moyle, InfoSec World 2019 - Business Security Weekly #117 from 2019-02-12T10:00

Ed Moyle is on the Advisory Board for InfoSec World and he joins us on the show to talk about InfoSec World 2019 and its upcoming plans. Ed Moyle is also giving a talk on "Cryptocurrency Lessons...

Listen
Paul's Security Weekly TV
5G, Zero-Days, & National Museum - Paul's Security Weekly #593 from 2019-02-11T10:00

5G networks must be secured from hackers and bad actors, zero-day vulnerability highlights the responsible disclosure dilemma, a flaw in multiple airline systems exposes passenger data, security...

Listen
Paul's Security Weekly TV
DetectionLab, Chris Long - Paul's Security Weekly #593 from 2019-02-10T10:00

DetectionLab is a collection of Vagrant and Packer scripts that allows you to automate the creation of a small active directory network that is pre-loaded with endpoint security tooling and logg...

Listen
Paul's Security Weekly TV
RSA, DigiCert, and Signal Sciences - Enterprise Security Weekly #125 from 2019-02-09T10:00

RSA Conference announces finalists for Innovation Sandbox Contest 2019, DigiCert announces all-in-one digital certificate management solution, Google's new Chrome extension warns you about stole...

Listen
Paul's Security Weekly TV
Randall Trzeciak, CERT - Enterprise Security Weekly #125 from 2019-02-08T10:00

Randall Trzeciak, the Director of the CERT Insider Threat Center at Carnegie Mellon University's Software Engineering Institute! Randall will be speaking at InfoSec World 2019 about "An Effectiv...

Listen
Paul's Security Weekly TV
Application News - Application Security Weekly #49 from 2019-02-07T10:00

Three UK customer details exposed in homepage blunder, Microsoft cloud services see global authentication outage, the age of surveillance capitalism, the rise of DevXOps, and much more!

F...

Listen
Paul's Security Weekly TV
Privacy & Software Development - Application Security Weekly #49 from 2019-02-07T09:30

Keith and Paul discuss the current state of privacy and software development.

- Facebook reveals news feed experiment to control emotions

- Facebook pays teens to install VPN that ...

Listen
Paul's Security Weekly TV
Sandra Toms & Britta Glade, RSA Conference - Business Security Weekly #116 from 2019-02-06T10:00

Sandra Toms is Vice President and Curator at RSA Conference. In 1998, her vision was to establish RSA Conference as a global cybersecurity forum where technology vendors and businesses unite. We...

Listen
Paul's Security Weekly TV
Dave Kennedy, TrustedSec - Business Security Weekly #116 from 2019-02-05T16:39:44

We welcome David Kennedy, founder and CEO, at TrustedSec to discuss "Investing in the right technology and resources"!

To learn more about TrustedSec, visit: Listen

Paul's Security Weekly TV
The Future Of Security - Paul's Security Weekly #592 from 2019-02-04T10:00

In our second segment, the Security Weekly hosts will discuss the Future of Security, such as major changes, evolving threats, and security culture!

Full Show notes: Listen

Paul's Security Weekly TV
Web App Scanning w/ Authentication, Acunetix - Paul's Security Weekly #592 from 2019-02-03T10:00

Benjamin Daniel Mussleris the Senior Security Researcher at Acunetix. Benjamin will come on the show to talk about Web App Scanning with authentication.

To learn more about Acunetix, visi...

Listen
Paul's Security Weekly TV
Yubico, Symantec, & Sophos - Enterprise Security Weekly #124 from 2019-02-02T10:00

In the Enterprise Security News, we will discuss how Cynets Platform approach tames cyber security issues, Salt Security launches API protection platform, Yubicos 2019 state of password and auth...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #115 from 2019-02-02T10:00

In the Leadership and Communications segment, cybersecurity isn't just for tech people anymore, the weird approach to leadership, 4 things to do before a tough conversation, and more!

Ful...

Listen
Paul's Security Weekly TV
Japan, Imperva, & DDoS - Paul's Security Weekly #592 from 2019-02-02T10:00

In the Security News, 5 tips for access control from an ethical hacker, Japan is to hunt down Citizens insecure IoT devices, kid tracking watches allow attackers to monitor real time location da...

Listen
Paul's Security Weekly TV
Andrew Peterson, Signal Sciences - Enterprise Security Weekly #124 from 2019-02-01T10:00

Andrew Peterson is the Founder & CEO of Signal Sciences, and an O’Reilly author of "Cracking Security Misconceptions". He joins the show today to talk about prioritizing bugs, if certain bugs at...

Listen
Paul's Security Weekly TV
Advanced Bot Protection, Cequence Security - Business Security Weekly #115 from 2019-02-01T10:00

Shreyans Mehta is the CTO at Cequence Security. Shreyans joins us to talk about advanced bot protection and how Cequence is involved.

Full Show Notes: Listen

Paul's Security Weekly TV
Jing Xie, Venafi - Application Security Weekly #48 from 2019-01-31T10:00

Dr. Jing Xie is the senior threat intelligence researcher for Venafi, the market leading cybersecurity company in machine identity protection. As a member of the Venafi thought leadership group,...

Listen
Paul's Security Weekly TV
Bugs, Breaches, and More! - Application Security Weekly #48 from 2019-01-30T10:00

Concerns about WordPress' new "White Screen of Death", Google Chrome changes could 'destroy' ad-blockers, Mozilla is adding and ad-blocker to Firefox Focus 9.0, Websites can steal browser data v...

Listen
Paul's Security Weekly TV
Android, Nest, & Linux Malware - Paul's Security Weekly #591 from 2019-01-29T10:00

Cellular carriers are implementing services to identify cell scam leveraging, New Android Malware uses motion sensor to avoid detection, Linux Malware disables security software to mine cryptocu...

Listen
Paul's Security Weekly TV
Topics & Questions - Paul's Security Weekly #591 from 2019-01-28T10:00

In our second segment, the Security Weekly hosts talks about some of our favorite hacker movies, influencers in the community, and what software and devices make appearances in our labs!

...

Listen
Paul's Security Weekly TV
Chris Morales, Vectra - Paul's Security Weekly #591 from 2019-01-27T10:00

Christopher Morales is Head of Security Analytics at Vectra, where he advises and designs incident response and threat management programs for Fortune 500 enterprise clients. Christopher is a wi...

Listen
Paul's Security Weekly TV
Ping, API, & eSentire - Enterprise Security Weekly #123 from 2019-01-26T10:00

Jeff Man joins Paul to talk about Ping Identity offering advanced API cyber protection, AppDynamics keeps expanding monitoring vision, eSentire announces managed endpoint defense powered by Carb...

Listen
Paul's Security Weekly TV
Open-Source & Free Collaboration Security Tools - Enterprise Security Weekly #123 from 2019-01-24T22:19:24

Paul and Jeff Man talk about Open-Source and free collaboration security tools.

1. Project Planning - OrangeScrum

2. Ticketing - Mantis Bug Tracker

3. Documentation - MediaW...

Listen
Paul's Security Weekly TV
The Human Element of Application Security - Application Security Weekly #47 from 2019-01-24T10:00

This week on Application Security Weekly, Matt Alderman is joined by James Wickett, who is the Head of Research at Signal Sciences. They talk about the human element of application security trai...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #114 from 2019-01-23T10:00

In the Leadership and Communications segment, customer surveys are no substitute for actually talking to customers, CEOs most concerned about Cybersecurity in 2019, the open workspace, doesn't w...

Listen
Paul's Security Weekly TV
Zane Lackey, Signal Sciences - Business Security Weekly #114 from 2019-01-23T10:00

Zane Lackey is the Chief Security Officer at Signal Sciences. Zane comes on the show to talk about advising!

Full Show Notes: http...

Listen
Paul's Security Weekly TV
Bugs, Breaches, and More - Application Security Weekly #47 from 2019-01-23T10:00

In the News segment, Oracle patches 284 vulnerabilities, bug in Twitter Android app exposed protected tweets, 4 tips for better API Security in 2019, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
DerbyCon, Flaws, & Azure DevOps - Paul's Security Weekly #590 from 2019-01-22T10:00

Two code execution flaws patched in Drupal, 773 million records exposed in massive data breach, prices for zero-day exploits are rising, new attacks target recent PHP framework vulnerability, an...

Listen
Paul's Security Weekly TV
PowerShell for Fun and Profit - Paul's Security Weekly #590 from 2019-01-21T10:00

Joff will demonstrate some syntax with PowerShell useful for transferring data into a network while pen testing. The technical segment assumes that the pen testing is able to directly use PowerS...

Listen
Paul's Security Weekly TV
Dr. Eric Cole, Secure Anchor Consulting - Paul's Security Weekly #590 from 2019-01-20T10:00

Dr. Eric Cole is the leading cybersecurity expert in the world, known as the go-to for major political and business power players.

Full Show Notes: Listen

Paul's Security Weekly TV
Security Product Launches, and Announcements - Enterprise Security Weekly #122 from 2019-01-19T10:00

In this segment, we will discuss some security product launches & announcements from Trustwave, NopSec, ConnectGuard, Pulse Secure, and Synopsys!

Full Show Notes: Listen

Paul's Security Weekly TV
Security Mergers, Acquisitions, and Partnerships - Enterprise Security Weekly #122 from 2019-01-18T10:00

In this segment, they discuss some mergers, acquisitions, and partnerships, such as TokenEx partnering with SureCloud, Check Point acquires ForceNock, Zix agrees to acquire AppRiver for $275 mil...

Listen
Paul's Security Weekly TV
CRLF, NASA, & GitHub - Application Security Weekly #46 from 2019-01-17T10:00

Another server security lapse at NASA exposed staff and project data, CRLF Injection Into PHP’s cURL Options, System Down: A systemd-journald exploit, GitHub now gives free users unlimited priva...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #113 from 2019-01-16T10:00

In business articles they discuss, how to be present, manage time, and avoid distractions, why your gut instinct is usually wrong, the 5 most efficient ways to get your work done, the creative d...

Listen
Paul's Security Weekly TV
Rey Bango, Microsoft - Application Security Weekly #46 from 2019-01-16T10:00

Rey is a security advocate at Microsoft focused on helping the community build secure systems & being a voice for researchers within MS. After a long career in software development, he developed...

Listen
Paul's Security Weekly TV
Security Money - Business Security Weekly #113 from 2019-01-15T10:00

This week we introduce a new quarterly segment to review the money of security, including public companies, IPOs, funding rounds and acquisitions from the previous quarter. We also created our o...

Listen
Paul's Security Weekly TV
Tim Callahan, Aflac - Business Security Weekly #112 from 2019-01-14T20:14:29

Tim Callahan joined Aflac in 2014, bringing more than 30 years of experience in information and physical security, business resiliency and risk management. They talk about communicating threat i...

Listen
Paul's Security Weekly TV
Hyatt, El Chapo's IT, and Amazon Key - Paul's Security Weekly #589 from 2019-01-14T10:00

Why Hyatt Is Launching a Public Bug Bounty Program, Amazon Key partners with myQ, Web vulnerabilities up, IoT flaws down, enterprise iPhones will soon be able to use security dongles, and how El...

Listen
Paul's Security Weekly TV
pktrecon, Kory Findley - Paul's Security Weekly #589 from 2019-01-13T10:00

Kory Findley talks about his Github project pktrecon. Internal network segment reconnaissance using packets captured from broadcast and service discovery protocol traffic. pktrecon is a tool for...

Listen
Paul's Security Weekly TV
Bryson Bort, SCYTHE- Paul's Security Weekly #589 from 2019-01-12T10:00

Bryson is the Founder and CEO of SCYTHE and Founder of GRIMM. He comes on the show to talk about Attack Simulation.

To learn more about SCYTHE.io, go to: Listen

Paul's Security Weekly TV
Neustar, BlackBerry, and ShieldSquare - Enterprise Security Weekly #121 from 2019-01-11T10:00

Neustar bolsters fraud detection capabilities with Trustid, almost half of containers in production have vulnerabilities, BlackBerry offers its security technology to IoT device makers, and Radw...

Listen
Paul's Security Weekly TV
Cyber Deception Today: Tony Cole - Enterprise Security Weekly #121 from 2019-01-10T10:00

Tony Cole is the Chief Technology Officer at Attivo Networks and is a cybersecurity expert with more than 30 years’ experience, a bachelor’s degree in computer networking and is a CISSP. Tony di...

Listen
Paul's Security Weekly TV
Ken Johnson, GitHub - Application Security Weekly #45 from 2019-01-09T10:00

Ken Johnson has been hacking web applications professionally for 10 years and giving security training for 7 of those years. Ken is both a breaker and builder who currently works on the GitHub a...

Listen
Paul's Security Weekly TV
WordPress, Silicon Valley, and Hijacking - Application Security Weekly #45 from 2019-01-08T17:01:19

Wormable stored XSS on WordPress.org, a security lapse revealed private complaints from Silicon Valley employees, hackers hijack thousands of Chromecasts to warn of latest security bug, a lintin...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #112 from 2019-01-08T10:00

This week how to moderate a panel discussion, the secret to leading organizational change is empathy, DevOps explained, 5 cloud computing predictions for 2019, and the top 3 things CIOs lose sle...

Listen
Paul's Security Weekly TV
PewDiePie, DOOM Roomba, and 9/11 - Paul's Security Weekly #588 from 2019-01-07T10:00

Hijacking smart TV's to promote PewDiePie, hackers attempt to sell stolen 9/11 documents, turning your house into a DOOM level with a Roomba, and hopefully you're over that New Year's hangover, ...

Listen
Paul's Security Weekly TV
Breaches, Privacy, Compliance and More! - Paul's Security Weekly #588 from 2019-01-06T10:00

The Security Weekly crew has a lively topic discussion on the following: Security Breaches, Privacy, Vulnerability Disclosure, Evaluating Security Solutions, and Compliance.

Full Show Not...

Listen
Paul's Security Weekly TV
Helping People In The Security Community - Paul's Security Weekly #588 from 2019-01-05T10:00

"Phoneboy" has been helping the security community for over 15 years. We fondly remember Phoneboy as a resource that helped us configure our Check Point firewalls back in the day! Phoneboy comes...

Listen
Paul's Security Weekly TV
Hacking the Brainstem, Mandy Logan - Paul's Security Weekly #587 from 2018-12-24T10:00

Following a series of 5 strokes and major head injuries, Mandy is no longer in the construction engineering industry. Instead, she is pursuing all things InfoSec with an emphasis on Incident Res...

Listen
Paul's Security Weekly TV
What The Heck Are "Security Basics"? - Paul's Security Weekly #587 from 2018-12-23T10:00

The question comes up quite often, what should organizations be doing to meet the basic security requirements? We often hear the terms "Security Basics", "Minimum Security Standards" or dear lor...

Listen
Paul's Security Weekly TV
Detecting Attacker Behavior, LogRhythm - Paul's Security Weekly #587 from 2018-12-22T10:00

Vaughn will discuss using freely available tools and logs you are already collecting to detect attacker behavior. Vaughn has a cookbook that will allow you to configure and analyze logs to detec...

Listen
Paul's Security Weekly TV
Top Ten List for 2018 - Enterprise Security Weekly #120 from 2018-12-21T19:47:42

Paul, Matt Alderman, and John Strand talk Paul’s Top Ten List of 2018! They talk about Paul’s personal favorite acquisitions, breaches, vulnerabilities, interviews, attack tools, news articles, ...

Listen
Paul's Security Weekly TV
Bitdefender, Symantec, & Untangle - Enterprise Security Weekly #120 from 2018-12-21T10:00

Bitdefender offers new managed threat monitoring service, Symantec and Fortinet partner to deliver robust and comprehensive cloud security service, Untangle partners with Malwarebytes to bring l...

Listen
Paul's Security Weekly TV
Signal App, Jenkins Servers, & WordPress - Application Security Weekly #44 from 2018-12-20T10:00

Facebook bug exposed private photos of 6.8 million users, thousands of Jenkins servers will let anonymous users become admins, Signal app can't include a backdoor for the Australian government, ...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #111 from 2018-12-19T10:00

Matt and Paul discuss how to be productive during the holiday season, how to work from home without losing your mind, how to talk to your boss when you’re underperforming, selling your product a...

Listen
Paul's Security Weekly TV
Harry Sverdlove, Edgewise - Application Security Weekly #44 from 2018-12-19T09:30

Harry Sverdlove is the CTO of Edgewise. Harry joins Keith and Paul to discuss what Edgewise does in the AppSec world, segmentation, cloud migration, trying different architectures, and more!

...

Listen
Paul's Security Weekly TV
Bob Ackerman, AllegisCyber - Business Security Weekly #111 from 2018-12-18T10:00

Bob Ackerman is a legend in venture capital investing and is referred to as one of "Cyber's Money Men". Bob is the Founder and Managing Director of venture capital firm AllegisCyber, Co-Founder ...

Listen
Paul's Security Weekly TV
Taylor Swift, KringleCon, & 3D Head - Paul's Security Weekly #586 from 2018-12-17T10:00

How Taylor Swift used Facial Recognition to Thwart Stalkers, unlocking android phones with a 3D printed head, Ticketmaster fails to take responsibility for malware, and it's December of 2018, To...

Listen
Paul's Security Weekly TV
Ed Skoudis, Counter Hack Challenge - Paul's Security Weekly #586 from 2018-12-16T10:00

Ed Skoudis, Founder of the Counter Hack Challenge and Kringle Con 2018, joins us on the show to talk about this years challenge and what's in store! "Welcome to Counter Hack Challenges, an organ...

Listen
Paul's Security Weekly TV
Minerva, Rapid7, & Venafi - Enterprise Security Weekly #119 from 2018-12-15T10:00

NopSec announces the latest release of its flagship product, Minerva Labs Anti-Evasion Platform achieves VMware ready status, SecurityScorecard announces partnership with cybernance to drive hol...

Listen
Paul's Security Weekly TV
Don Murdoch, Regent University Cyber Range - Paul's Security Weekly #586 from 2018-12-15T10:00

Don Murdoch is the Assistant Director at Regent University Cyber Range. Don discusses his book "Blue Team Handbook Incident Response Edition".

Full Show Notes: Listen

Paul's Security Weekly TV
John Bradshaw, Acalvio - Enterprise Security Weekly #119 from 2018-12-14T10:00

This segment is sponsored by Acalvio. Check out their deception technologies by visiting https://securityweekly.com/acalvio. And remember, all [...

Listen
Paul's Security Weekly TV
Kubernetes, Firefox, & WordPress - Application Security Weekly #43 from 2018-12-13T10:00

Kubernetes instances are being hijacked worldwide, malicious sites abuse 11-year old Firefox bug that Mozilla failed to fix, Google is on a Witch Hunt for Internal Leakers, a botnet of over 20,0...

Listen
Paul's Security Weekly TV
Chris Elgee, Counter Hack Challenge - Application Security Weekly #43 from 2018-12-12T10:00

Chris Elgee is a full time husband, father of four, and technical engineer at Counter Hack Challenges. Chris joins Keith and Paul this week to talk about the Counter Hack Challenge, how it's bee...

Listen
Paul's Security Weekly TV
Leadership & Communication - Business Security Weekly #110 from 2018-12-12T09:30

How to collaborate with people you don't like, the right way to solve complex business problems, what the habits are of successful people, three things to know before you land a tech job, a CISO...

Listen
Paul's Security Weekly TV
Brian Carey, Rapid7 - Business Security Weekly #110 from 2018-12-11T10:00

Brian Carey is a Senior Security Consultant at Rapid7, specializing in: Security Program Assessments, Security Program Development, Vulnerability Management Program Development, Security Awarene...

Listen
Paul's Security Weekly TV
Marriott Breach, Lame Printer Hack, and Docker - Paul's Security Weekly #585 from 2018-12-10T10:00

This week, how Docker containers can be exploited to mine for cryptocurrency, WordPress sites attacking other WordPress sites, why the Marriott Breach is a valuable IT lesson, malicious Chrome e...

Listen
Paul's Security Weekly TV
Marcello Salvati, BHIS - Paul's Security Weekly #585 from 2018-12-09T10:00

Marcello Salvati is a security consultant at BHIS, and is giving a technical segment on SilentTrinity. Marcello will solve the red team tradecraft problem of gaining dynamic access to the .net a...

Listen
Paul's Security Weekly TV
Ixia, Yubico, Fortinet, and ZeroStack - Enterprise Security Weekly #118 from 2018-12-08T10:00

Ixia extends collaboration with ProtectWise, Ping Identity brings in New Customer Identity as a service solution, Fortinet introduces new security automation capabilities on AWS, and Yubico anno...

Listen
Paul's Security Weekly TV
Lenny Zeltser, Minerva Labs - Paul's Security Weekly #585 from 2018-12-08T10:00

Lenny Zeltser the VP of Products at Minerva, will be giving a technical segment on Evasion Tactics in Malware from the Inside Out. He will explain the tactics malware authors use to evade detect...

Listen
Paul's Security Weekly TV
Mike Nichols, Endgame - Enterprise Security Weekly #118 from 2018-12-07T10:00

Mike Nichols, the VP of Product for Endgame, joins us for an interview to talk about MITRE evaluation of Endgame, Open-Source Query Language EQL, and Storytime with Mike!

To learn more ab...

Listen
Paul's Security Weekly TV
NSA Malware, AFL Fuzzer, & Firecracker - Application Security Weekly #42 from 2018-12-06T09:30

Hackers are opening SMB ports on routers to infect PCs with NSA malware, bug detectives whip up smarter version of classic AFL fuzzer to hunt code vulnerabilities, malware & rogue users can spy ...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #109 from 2018-12-05T17:00

Paul and Jason Alburquerque discuss The new math of leadership, How pragmatic leaders can transform stuck organizations, and Why building a work community is critical!

Full Show Notes: Listen

Paul's Security Weekly TV
Aleksei Tiurin, Acunetix - Application Security Weekly #42 from 2018-12-05T10:00

Aleksei Tiurin is the Senior Security Researcher for Acunetix. He is performing a technical segment on reverse proxies using weblogic, Tomcat, and Nginx.

To learn more about Acunetix, go ...

Listen
Paul's Security Weekly TV
Jay Prassl, Automox - Business Security Weekly #109 from 2018-12-04T15:01:31

Matt Alderman interviews Jay Prassl, the CEO of Automox. Jay Prassl explains what Automox does, how Automox bridges the gap between ITOps and SecOps use case, and how Automox defines the way to ...

Listen
Paul's Security Weekly TV
"Dunkin" Donuts, Microsoft, & Marijuana - Paul's Security Weekly #584 from 2018-12-03T10:00

Hackers breach Dunkin Donuts, how insiders are serious threats to security in an organization, the return of email flooding, Microsoft helps police shut down fake tech support in India, and how ...

Listen
Paul's Security Weekly TV
Wietse Venema & Dan Farmer, SATAN - Paul's Security Weekly #584 from 2018-12-02T10:00

Wietse Venema and Dan Farmer, the Developers of Security Administrator Tool for Analyzing Networks (SATAN), talk about their experience as developers, their journey to creating SATAN and their d...

Listen
Paul's Security Weekly TV
Sven Morgenroth, Netsparker - Paul's Security Weekly #584 from 2018-12-01T10:00

Sven will talk about PHP Object injection vulnerabilities and explain the dangers of PHP's unserialize function. He will show the format of serialized PHP Objects, explain PHP's magic methods an...

Listen
Paul's Security Weekly TV
EdgeEngine, Cloud-Native, and Orkus - Enterprise Security Weekly #117 from 2018-11-29T20:36:17

tackPath launches EdgeEngine Serverless Computing, Alcide advances Cloud-Native security Firewall platform, Orkus launches Access Governance platform for Cloud Security, Tufin announces a new Cl...

Listen
Paul's Security Weekly TV
Drupalgeddon, USPS, & JavaScript - Application Security Weekly #41 from 2018-11-29T10:00

Hackers use Drupalgeddon 2 and Dirty COW exploits to take over web servers, second WordPress hacking campaign underway, USPS took a year to fix a vulnerability that exposed all 60 million users'...

Listen
Paul's Security Weekly TV
Jeremy Winter, Microsoft - Enterprise Security Weekly #117 from 2018-11-28T22:40:59

Jeremy Winter is Director of Azure Management, responsible for areas such as Azure Governance, Policy, Configuration, PowerShell, Disaster Recovery, Azure Migrate and the Azure Portal Experience...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #108 from 2018-11-28T10:00

The million-dollar question of cyber-risk, risk assessments essential to secure third-party vendor management, how digital tech is transforming business ecosystem, and more!

Full Show Not...

Listen
Paul's Security Weekly TV
Brent Dukes - Application Security Weekly #41 from 2018-11-28T10:00

Brent Dukes is a hacker, and Director of Information Security for an established manufacturing company. He joins Keith and Paul this week to talk about WAF’s, Pentesting, Burp Suite, and more! Listen

Paul's Security Weekly TV
Richard Seiersen, President of M-Cubed - Business Security Weekly #108 from 2018-11-27T10:00

Richard Seiersen a CISO with experience ranging from small technology companies to multi-national conglomerates. He joins Matt and Paul this week to talk about Richard’s CISO experience and expe...

Listen
Paul's Security Weekly TV
Mimecast, Endpoint Security, & Tufin - Enterprise Security Weekly #16 from 2018-11-24T10:00

Israeli cybersecurity company Tufin plans NASDAQ IPO, F-Secure boosts endpoint detection and response, Mimecast joins IBM Security app exchange community, and Awake Security debuts Network Traff...

Listen
Paul's Security Weekly TV
Rick Fernandez, LogRhythm - Enterprise Security Weekly #16 from 2018-11-23T10:00

Rick Fernandez is the Sr. Sales Engineer focused on Sales Integrators at LogRhythm. The discussion is about what Sis want isn’t that different from the Enterprise. They discuss automating the hu...

Listen
Paul's Security Weekly TV
Interviews: Venafi, Irdeto, and HP - Enterprise Security Weekly #16 from 2018-11-22T10:00

Our interviews with Jeff Hudson the CEO of Venafi, Dr. Kimberlee A. Brannock and Michael Howard from HP, and Ben Bennett and Mark Hearn from Irdeto.

For Full DefCon18 Playlist, go to: Listen

Paul's Security Weekly TV
Goals, Leadership, & Don't Set Limits - Business Security Weekly #107 from 2018-11-21T10:00

Jason Alburquerque and Paul discuss six ways you can establish which goals are important, how to diversify your professional network, the impact of perception and bias on leadership, and more! Listen

Paul's Security Weekly TV
Michael Pleasant, Open Security - Business Security Weekly #107 from 2018-11-20T10:00

Michael Pleasant is the Chief Executive Officer at Open Security. Michael talks about how his transferring from Marine training to a business environment, brought a different perspective/techniq...

Listen
Paul's Security Weekly TV
Instagram, Kraken, GitMiner - Application Security Weekly #40 from 2018-11-20T10:00

Instagram leaks passwords to the public, Clickjacking on Google MyAccount Worth $7,500, James Wickett's thread on Open Source SAST options, an advanced search tool for sensitive information stor...

Listen
Paul's Security Weekly TV
John Kinsella, Layered Insight - Application Security Weekly #40 from 2018-11-19T22:04:42

Previously co-founder and head of product at Layered Insight, John now leads container security engineering at Qualys after it's acquisition of Layered Insight. John talks about Qualys' Containe...

Listen
Paul's Security Weekly TV
Spectre, ATMs, and Japan's Minister - Paul's Security Weekly #583 from 2018-11-19T10:00

7 new Spectre/Meltdown attacks, Hacking ATM's for free cash is easier than Windows XP, AI can now fake fingerprints fooling ID scanners, and Japan's cybersecurity minister admits he's never used...

Listen
Paul's Security Weekly TV
John Moran, DFLabs - Paul's Security Weekly #583 from 2018-11-18T10:00

John is a Senior Product Manager at DFLabs, where he performs a wide variety of tasks from product management to content development and partner management. John Moran talks about IncMan SOAR an...

Listen
Paul's Security Weekly TV
Jon Buhagiar, Sybex - Paul's Security Weekly #583 from 2018-11-17T17:00

Jon Buhagiar is responsible for Network Operations at Pittsburgh Technical College for the past 19 years. Jon is currently a Network+ Review Course Instructor at Sybex, and he joins us to talk a...

Listen
Paul's Security Weekly TV
Dragos, BlackBerry, & ForeScout - Enterprise Security Weekly #115 from 2018-11-16T10:00

AlgoSec delivers Native Cloud Security Management for Azure, HP Reinvents customer experience with Ping Identity, what mid market security budgets will look like in 2019, and we have some acquis...

Listen
Paul's Security Weekly TV
Brian Kelly, CyberArk - Application Security Weekly #39 from 2018-11-15T10:00

Brian Kelly is Head of Conjur Engineering at CyberArk, where he focuses on creating products that add much-needed security and identity management to the landscape of DevOps tools and cloud syst...

Listen
Paul's Security Weekly TV
James Wickett, Signal Sciences - Enterprise Security Weekly #115 from 2018-11-15T10:00

James Wickett is the Head of Research at Signal Sciences. James talks about how security is moving to the application space and web applications. WAFs may seem tedious but they are necessary to ...

Listen
Paul's Security Weekly TV
Dario Forte, DFLabs - Business Security Weekly #106 from 2018-11-14T10:00

Dario Forte the CEO & Founder of DFLabs, explains his journey to the position he is in now. Dario talks about DFLabs and their platform tools. Dario also explains...

Listen
Paul's Security Weekly TV
ColdFusion, Destroying Logs, & Tracing Meme's - Application Security Weekly #39 from 2018-11-14T10:00

DJI Drone Vulnerability, Hackers are increasingly destroying logs to hide attacks, Adobe ColdFusion servers under attack from APT group, understanding Open Source Code use in your business, and ...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #106 from 2018-11-13T10:00

In the Article Discussion, Matt and Paul talk the key to better focus and higher productivity, living your life on purpose, why people are willing to do more meaningful work for less money, the ...

Listen
Paul's Security Weekly TV
Eyal Neemany, Javelin Networks - Paul's Security Weekly #582 from 2018-11-12T10:00

Former Head of Israeli Air Force CERT & Forensics Team, Senior Security Researcher at Javelin Networks. Eyal will be discussing securing remote administration, remote credentials, explains that ...

Listen
Paul's Security Weekly TV
Corin Imai, DomainTools - Paul's Security Weekly #582 from 2018-11-11T10:00

Corin Imai is Sr. Security Advisor for DomainTools. Corin began her career working on desktop virtualization, networking, and cloud computing technologies before delving into security. This inte...

Listen
Paul's Security Weekly TV
Symantec, Veracode, & Thoma Bravo - Enterprise Security Weekly #114 from 2018-11-10T10:30

Symantec boosts security with Javelin Networks, ThreatQuotient integrates Verified Breach Intelligence from Visa, FireMon delivers hybrid cloud security with new visibility and orchestration, St...

Listen
Paul's Security Weekly TV
Harry Sverdlove, Edgewise - Enterprise Security Weekly #114 from 2018-11-09T10:00

Harry Sverdlove is currently the CTO and Founder at Edgewise. He joins Matt and Paul this week to talk about Zero Trust Segmentation, what Edgewise does, and how it’s helping the community in ne...

Listen
Paul's Security Weekly TV
'Stalkerware', DHCPv6 Packets , & Python - Application Security Weekly #38 from 2018-11-08T10:00

In the Application Security News, a nasty DHCPv6 packet can Pwn vulnerable Linux Boxes, 'Stalkerware' website let anyone intercept texts of tens of thousands of people, twelve malicious Python l...

Listen
Paul's Security Weekly TV
Leadership Articles - Business Security Weekly #105 from 2018-11-07T10:00

In the Leadership Articles, Matt and Paul talk how getting fired can be good for your career, a powerful planning routine that puts you in control, how to get better with sales execution, and mo...

Listen
Paul's Security Weekly TV
Daniel Cuthbert, Banco Santander - Application Security Weekly #38 from 2018-11-07T09:30

Daniel Cuthbert is the Global Head of Security Research for Banco Santander. He joins Keith and Paul this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Alex Wood, CISO - Business Security Weekly #105 from 2018-11-06T10:00

Matt Alderman's good friend Alex Wood comes on the show to talk about the business mind set, how to be an effective CISO, and the vulnerabilities in the business that you have to watch out for.<...

Listen
Paul's Security Weekly TV
Apache, Dirty Cow, & Edge - Paul's Security Weekly #582 from 2018-11-06T10:00

Cisco accidentally released Dirty Cow exploit code, Apache Struts Vulnerabilities, Zero Day exploit published for VM Escape flaw, Spam spewing IoT botnet infects 100,000 routers, and some of the...

Listen
Paul's Security Weekly TV
AWS Lambda, Bleedingbit, and Cisco - Paul's Security Weekly #581 from 2018-11-05T13:00

AWS Security Best Practices, Masscan and massive address lists, Bleedingbit vulnerabilities, and Cisco Zero-Day exploited in the wild, ! All that and more, on this episode of Paul's Security Wee...

Listen
Paul's Security Weekly TV
Matt Toussain, BHIS - Paul's Security Weekly #581 from 2018-11-05T10:00

Matt Toussain a Security Analyst at Black Hills Information Security, will be giving a tech segment on remote access tools (RAS).

To learn more about BHIS, go to: Listen

Paul's Security Weekly TV
Aleksei Tiurin, Acunetix - Paul's Security Weekly #581 from 2018-11-04T09:00

Aleksei Tiurin is the Senior Security Researcher for Acunetix. Aleksei is giving a technical segment on insecure deserialization in Java/JVM and explains what polymorphism is. Aleksei Tiurin is ...

Listen
Paul's Security Weekly TV
LogRhythm, SOAR, and A Huge Acquisition - Enterprise Security Weekly #113 from 2018-11-03T09:00

LogRhythm advances NextGen SIEM security platform with SOAR, Ping Identity launches a Quickstart private sandbox, McAfee takes a big step in the cloud, Endgame improves Endpoint Security with To...

Listen
Paul's Security Weekly TV
Ian McShane, Endgame - Enterprise Security Weekly #113 from 2018-11-02T08:30

Ian McShane has nearly two decades of experience in operational IT and security and risk planning for enterprises, service providers and software vendors. Paul, Matt, and Ian talk about the futu...

Listen
Paul's Security Weekly TV
Airline Hacks, MicroTik Bug, & WordPress - Application Security Weekly #37 from 2018-11-01T09:00

Millions of passengers affected by Cathay Pacific Airline Hack, China has been hijacking the internet backbone of Western countries, how proficient are developers at fixing Application Security ...

Listen
Paul's Security Weekly TV
Johnny Xmas, Kasada.io - Application Security Weekly #37 from 2018-10-31T09:00

Keith, Paul, and Johnny Xmas discuss airport security, penetration testing, the top 5 payment apps, and DevOps infused conversation!

Full Show Notes: Listen

Paul's Security Weekly TV
AI Fear, FDA, Tesla, and D-Link - Paul's Security Weekly #580 from 2018-10-29T09:00

Fear of AI attacks, the FDA releases cybersecurity guidance, watch hackers steal a Tesla, serious D-Link router security flaw may never be patched, and California addresses default passwords! Al...

Listen
Paul's Security Weekly TV
Yossi Sassi, Javelin Networks - Paul's Security Weekly #580 from 2018-10-28T09:00

Yossi Sassi is the Co-Founder and Cybersecurity Researcher at CyberArtSecurity.com. Yossi joins us for a tech segment to talk about using windows powershell, discussing DCSync, DCShadow, creativ...

Listen
Paul's Security Weekly TV
Veronica Schmitt, DFIRLABS - Paul's Security Weekly #580 from 2018-10-27T09:00

Veronica Schmitt is the Sr. Digital Forensic Scientist for DFIRLABS. Veronica explains what SRUM is in WIndows 10. She explains how SRUM can be a valuable tool in Digital Forensics.

Full ...

Listen
Paul's Security Weekly TV
Security Solutions, Acquisitions, and IPOs - Enterprise Security Weekly #112 from 2018-10-27T08:30

Netscout takes internet scale Threat Protection to the EDGE, Splunk addresses several vulnerabilities in Enterprise and Light products, Ping Identity launches a Quickstart Private Sandbox, and w...

Listen
Paul's Security Weekly TV
Jonathan Sander, Snowflake - Enterprise Security Weekly #112 from 2018-10-26T09:00

Jonathan Sander explains how he came to work for Snowflake and what Snowflake does in the enterprise security space. Jonathan explains how Snowflake contains their data and protect from breaches...

Listen
Paul's Security Weekly TV
Cryptocurrency, Disney, and Adobe - Application Security Weekly #36 from 2018-10-25T09:00

Hackers hide Cryptocurrency malware in Adobe flash updates, the government is finally rolling out 2 Factor Authentication for Federal Agency Domains, and Disney is helping women from across thei...

Listen
Paul's Security Weekly TV
Leadership, Communication, and Innovation - Business Security Weekly #103 from 2018-10-24T09:00

In the Article Discussion, Michael and Paul talk about the root cause of workplace drama, how to make the most of meetings between IT and your business partners, how to stop procrastinating on y...

Listen
Paul's Security Weekly TV
Bugs, Breaches, and More! - Application Security Weekly #36 from 2018-10-24T09:00

Paul and April Wright discuss a jQuery Plugin that has been exploited for years is finally getting patched, a flaw in LibSSH leaves thousands of servers at risk, and a remote code implantation f...

Listen
Paul's Security Weekly TV
Michael McKee, ObserveIT - Business Security Weekly #103 from 2018-10-23T09:00

Mike McKee, CEO of ObserveIT, joins us to talk about the importance of focussing on people, and you do that to experience growth.

Full Show Notes: Listen

Paul's Security Weekly TV
Shodan, Apache, ICS, and Controllers - Paul's Security Weekly #579 from 2018-10-22T09:00

How to use the Shodan search engine to secure an enterprise's internet presence, Apache access vulnerability could affect thousands of applications, vulnerable controllers could allow attackers ...

Listen
Paul's Security Weekly TV
John Walsh, CyberArk - Paul's Security Weekly #579 from 2018-10-21T09:00

John Walsh the DevOps Evangelist for CyberArk joins us on the show. John talks about the articles he wrote for CyberArk about Kubernetes, DevSecOps, and how to strengthen your container authenti...

Listen
Paul's Security Weekly TV
Mark Dufresne, Endgame - Paul's Security Weekly #579 from 2018-10-20T09:00

Mark Dufresne explains why MITRE created their tool and what the MITRE attack framework is.

Full Show Notes: https://wiki.securitywee...

Listen
Paul's Security Weekly TV
BlackBerry, Imperva, & CyberArk - Enterprise Security Weekly #111 from 2018-10-19T09:00

In the Enterprise Security News, Avast launches AI-based software for phishing attacks, Carbon Black and Secureworks apply Red Cloak Analytics to Carbon Blacks Cloud, ShieldX integrates intentio...

Listen
Paul's Security Weekly TV
Briefings Summary - Enterprise Security Weekly #111 from 2018-10-18T09:00

In a special segment for this week, John Strand and Paul discuss some companies that Paul had a chance to sit down for briefings with! They discuss GuardiCore and their Application Segmentation,...

Listen
Paul's Security Weekly TV
Garrett Gross, Rapid7 - Application Security Weekly #35 from 2018-10-16T15:10:18

Garrett Gross received his first modem at age six and has been plugged in ever since. Today, Garrett is a Senior Solutions Engineer with a specialization in application security at Rapid7. He se...

Listen
Paul's Security Weekly TV
Git Project, Google+, & Facebook - Application Security Weekly #35 from 2018-10-16T15:09:13

In the Application Security News, Git Project patches Remote Code Execution Vulnerability, Google is Shutting Down Google+ after 500k accounts potentially affected by a data breach, Facebook wan...

Listen
Paul's Security Weekly TV
Article Discussion - Business Security Weekly #102 from 2018-10-16T09:00

This week, Michael and Paul talk about the Article Discussion on Leadership, Communication, and Innovation! They discuss how to automate habits and never think about them again, why it’s importa...

Listen
Paul's Security Weekly TV
DerbyCon, Russians, and Next Story - Paul's Security Weekly #578 from 2018-10-15T09:00

New Apple and Microsoft security flaws at Black Hat Europe, CCTV makers leaves at least 9 million cameras public, upset Google+ users are sueing Google, US weapons systems apparently can be easi...

Listen
Paul's Security Weekly TV
Lee Neely, Lawrence Livermore National Lab - Paul's Security Weekly #578 from 2018-10-14T09:00

Lee Neely is a senior IT and security professional at LLNL with over 25 years of extensive experience with a wide variety of technology and applications from point implementations to enterprise ...

Listen
Paul's Security Weekly TV
Omer Yair, Javelin - Paul's Security Weekly #578 from 2018-10-13T09:00

Omer is End-Point team lead at Javelin Networks. The team focuses on methods to covertly manipulate OS internals. Before Javelin Networks, he was a malware researcher at IBM Trusteer for two yea...

Listen
Paul's Security Weekly TV
Mark Russinovich, Microsoft Azure - Enterprise Security Weekly #110 from 2018-10-12T09:00

Doug White interviews Mark Russinovich at Microsoft Ignite. Doug and Mark talk about Azure Confidential Computing, Mark's book Zero Day, and Azure security.

Full Show Notes: Listen

Paul's Security Weekly TV
Splunk, White Hat, and Palo Alto - Enterprise Security Weekly #110 from 2018-10-11T16:06:40

Splunk unveils first IoT platform for customers, Palo Alto Networks acquires RedLock to build out Cloud Security Tech, KnowBe4 boosts security awareness training with Virtual Risk Officer, Syman...

Listen
Paul's Security Weekly TV
Mimecast, LogRhythm, & Tanium - Enterprise Security Weekly #109 from 2018-10-06T09:00

Mimecast offers free training kit as part of Cybersecurity Awareness Month, Microsoft will finally kill off the old Skype client (for real this time), Security startup Tanium raises another $200...

Listen
Paul's Security Weekly TV
Michael Gordover, ObserveIT - Enterprise Security Weekly #109 from 2018-10-05T09:00

Mike Gordover is a Pre-Sales manager and solutions architect at ObserveIT. He has been at ObserveIT consulting on insider threat management for 5 years, working hands on with over 300 deployment...

Listen
Paul's Security Weekly TV
Bugs, Breaches, and More - Application Security Weekly #34 from 2018-10-04T09:00

Facebook discloses the loss of at least 50M Access Tokens also covered by Motherboard Formjacking is on the rise, Google admits to allowing hundreds of companies read your email, FireFox Monitor...

Listen
Paul's Security Weekly TV
Leadership, Communication, and Innovation - Business Security Weekly #101 from 2018-10-03T09:00

Michael, Paul, and Jason discuss how to develop empathy for someone who annoys you, separating the quality of the outcome and quality of the decision, and much more!

Full Show Notes: Listen

Paul's Security Weekly TV
Landing a Job in Application Security - Application Security Weekly #34 from 2018-10-03T09:00

Attend local meetups and conferences, practice your coding skills, get educated by World Class security researchers, do your homework, there's no substitute for Practice, OWASP Juice Shop, and m...

Listen
Paul's Security Weekly TV
Jason Albuquerque, Carousel Industries - Business Security Weekly #101 from 2018-10-02T09:00

Michael and Paul ask Jason how to become a better business. Jason explains how to run your security team as in a 'fish bowl', and how to apply this technique to your clients and their business.<...

Listen
Paul's Security Weekly TV
Business Tips and Tricks - Business Security Weekly #104 from 2018-10-02T09:00

Michael and Paul discuss the tools that have helped them in their business. They talk about the books they've read, the interviews that helped them the most, and the journey from Startup Securit...

Listen
Paul's Security Weekly TV
Linux Bugs, macOS Zero-Day, & Twitter Exposed - Paul's Security Weekly #577 from 2018-10-01T09:00

In the security news, Russian Hackers use Malware that can survive OS reinstalls, Facebook’s 2-Factor authentication With a phone number isn’t only for security, it’s used for ads ,FBI warns com...

Listen
Paul's Security Weekly TV
Offensive Operating Against SysMon, Carlos Perez - Paul's Security Weekly #577 from 2018-09-30T09:00

Carlos Perez delivers the Technical Segment on How to Operate Offensively Against Sysmon. He talks about how SysMon allows him to create rules, and track specific types of tradecraft, around pro...

Listen
Paul's Security Weekly TV
Mike Nichols, Keith McCammon, & Shawn Smith - Paul's Security Weekly #577 from 2018-09-29T09:00

Mike Nichols is the VP of Product Management at Endgame, and he manages the Endgame endpoint protection platform. Keith McCammon is the Chief Security Officer and Co-Founder of Red Canary, and h...

Listen
Paul's Security Weekly TV
BeyondTrust, Rapid7, & Symantec - Enterprise Security Weekly #108 from 2018-09-28T09:00

In the Enterprise News this week, Bomgar to be renamed BeyondTrust after acquisition from PAM vendor, Rapid7 looks to SOAR with InsightConnect Automation Platform, DigiCert, Gemalto, and ISARA P...

Listen
Paul's Security Weekly TV
Threat & Vulnerability Management - Enterprise Security Weekly #108 from 2018-09-27T21:00

Paul and Matt sit down this week to discuss Threat and Vulnerability Management, the value it has, and the different players that deal with it in the Enterprise. They delve into Cloud and Applic...

Listen
Paul's Security Weekly TV
Newegg, Ticketmaster, & iOS 12 - Application Security Weekly #33 from 2018-09-27T09:00

In the Application Security News, Hackers stole customer credit cards in Newegg data breach, John Hancock now requires monitoring bracelets to buy insurance, the man who broke Ticketmaster, new ...

Listen
Paul's Security Weekly TV
Ron Gula, Gula Tech Adventures - Application Security Weekly #33 from 2018-09-26T21:00

Ron started his cybersecurity career as a network penetration tester for the NSA, and is the Founder of Tenable and Gula Tech Adventures. He joins Keith and April for an interview to talk about ...

Listen
Paul's Security Weekly TV
Scott King, Rapid7 Pt. 2 - Business Security Weekly #100 from 2018-09-26T09:00

In the second part of Scott’s interview, Michael and April talk with him about ICS security, communication, and building relationships! They discuss the best practices to understand how these sy...

Listen
Paul's Security Weekly TV
Scott King, Rapid7 Pt. 1 - Business Security Weekly #100 from 2018-09-25T09:00

Scott brings a unique mixture of hands-on experience in incident response, penetration testing, forensics, operations, architecture, engineering, and executive leadership as a former Chief Infor...

Listen
Paul's Security Weekly TV
GovPayNow.com, AmazonBasics, and FBI - Paul's Security Weekly #576 from 2018-09-24T21:00

Senate can't protect senators staff from Cyber Attacks, Equifax fined by ICO over data breach that hit Britons, US Military given the power to hack back and defend forward,and AmazonBasics Micro...

Listen
Paul's Security Weekly TV
Threat Hunting in the Cloud, Apollo Clark - Paul's Security Weekly #576 from 2018-09-24T09:00

Apollo Clark goes through inventory management, access management, config management, patch management, automated remediation, logging and monitoring, and deployment tools.

Full Show Note...

Listen
Paul's Security Weekly TV
Mike Ahmadi, DigiCert - Paul's Security Weekly #576 from 2018-09-23T09:00

Mike Ahmadi oversees IoT security solutions and technical implementations for DigiCert customers across various verticals that include industrial, transportation, smart city, consumer devices an...

Listen
Paul's Security Weekly TV
Cisco, Fidelis, Crossmatch, and DigitalPersona - Enterprise Security Weekly #107 from 2018-09-22T09:00

Cisco aims to make security foundational throughout its business, Fidelis looks to grow cyber-security platform, How artificial intelligence can improve human decision-making in IoT apps, Crossm...

Listen
Paul's Security Weekly TV
Audit Mistakes - Enterprise Security Weekly #107 from 2018-09-21T09:00

Doug White and Matt Alderman talk about audit mistakes. Don't get into the mindset of ticking the box to satisfy audit. - What is this control and why are using it? - What does it control?

<...

Listen
Paul's Security Weekly TV
Bluebox-ng, Stock Data Breaches, and CommitStrip- Application Security Weekly #32 from 2018-09-20T09:00

Alpine Linux hit with bug that can lead to Poisoned Containers, data breaches affect stock performance in the long run, Bluebox-ng, a Node.js VoIP pentesting framework, and CommitStrip: It's Not...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #99 from 2018-09-19T09:00

Michael Santarcangelo joined by special guest Ron Gula from Gula Tech Adventures, talk with Chris Brenton about how do you take someone with a basic level certification and give them access to t...

Listen
Paul's Security Weekly TV
April Wright, ArchitectSecurity.org - Application Security Weekly #32 from 2018-09-19T09:00

Keith Hoodlet and Paul Asadoorian interview April Wright. They discuss people connected by apps, workplace reward systems, and the importance of building/practicing the process before documentin...

Listen
Paul's Security Weekly TV
Microsoft, Elon Musk, Kernel and Powershell - Paul's Security Weekly #575 from 2018-09-18T09:00

Microsoft accidentally lets encrypted Windows 10 out the the world, Kernel exploit discovered in macOS, PowerShell obfuscation ups the anty on anti virus, Google outlines incident response proce...

Listen
Paul's Security Weekly TV
Chris Brenton, ACM - Business Security Weekly #99 from 2018-09-18T09:00

Michael Santarcangelo returns! Michael is joined by Matt Alderman and Ron Gula to interview Chris Brenton. They discuss what is threat hunting, what does this actually mean, is there a level of ...

Listen
Paul's Security Weekly TV
Bypassing PAM, Eyal Neemany - Paul's Security Weekly #575 from 2018-09-17T09:00

Eyal Neemany describes how to bypass Linux Pluggable Authentication Modules provide dynamic authentication support for applications and services in a Linux or GNU/kFreeBSD system. Eyal Neemany i...

Listen
Paul's Security Weekly TV
Brian Coulson, LogRhythm - Paul's Security Weekly #575 from 2018-09-16T09:00

Brian Coulson is a Senior Security Research Engineer in the Threat Research Group of LogRhythm Labs in Boulder, CO. His primary focus is the Threat Detection Modules such as UEBA, and NTBA.

...

Listen
Paul's Security Weekly TV
CLEAR, Demisto, OneLogin & Netskope - Enterprise Security Weekly #106 from 2018-09-15T09:00

Proofpoint automates email security with CLEAR, Demisto releases state of SOAR 2018 report, OneLogin and Netskope partner to expand cloud security for enterprises, RedSeal launches remote admini...

Listen
Paul's Security Weekly TV
Dave Maestas, Bandura - Enterprise Security Weekly #106 from 2018-09-14T09:00

David Maestas, also known as Dave, is the Co-Founder and Chief Technology Officer at Bandura Systems. David talks about how to phase out the bad tools and companies in the enterprise.

Ful...

Listen
Paul's Security Weekly TV
Microsoft, Equifax, MacOS, and Bug Bounties - Application Security Weekly #31 from 2018-09-13T09:00

U.S. Government releases post-mortem on Equifax, MacOS security baseline script by Jerry Gamblin, Equifax mega-breach and nothing has changed, Docker hacking challenge, and Bug Bounties and ment...

Listen
Paul's Security Weekly TV
Imperva, Allstate, & Sonatype - Business Security Weekly #98 from 2018-09-12T09:00

Imperva acquires app security firm Prevoty in $140 million deal, Allstate accelerates expansion into Identity Protection with acquisition of InfoArmor, Sonatype receives $80 million investment f...

Listen
Paul's Security Weekly TV
Supermicro, Apache Struts, & HTTPS - Paul's Security Weekly #574 from 2018-09-11T09:00

In the security news, Spanish driver tests positive for every drug test, vulnerabilities found in the remote management interface of Supermicro servers, Apache Struts 2 flaw in the wild, HTTPS c...

Listen
Paul's Security Weekly TV
Gabriel Gumbs, STEALTHbits - Business Security Weekly #98 from 2018-09-11T08:30

Michael and Paul interview Gabriel Gumbs from STEALTHbits. They talk about moving from detection to prevention, and protecting your data!

Full Show Notes: Listen

Paul's Security Weekly TV
Beacon Analysis, Chris Brenton - Paul's Security Weekly #574 from 2018-09-10T09:00

Beacon analysis is an integral part of threat hunting. If you are not looking for beacons you take the chance of missing compromised IoT devices or anything that does not have a threat mitigatio...

Listen
Paul's Security Weekly TV
Wim Remes, Wire Security bvba - Paul's Security Weekly #574 from 2018-09-09T09:00

Wim Remes from Wire Security bvba comes on the show to talk about pentesting, SDLC, the state of security, life of a (virtual) CISO, and certifications.

Full Show Notes: Listen

Paul's Security Weekly TV
Black Hat Dual Interview pt. 2- Enterprise Security Weekly #105 from 2018-09-08T09:00

Paul talks with Bret Settle, the CEO of ThreatX about shifting the focus to the hacker. Check out this interview and learn about innovative endpoint defenses and how attackers use covert signali...

Listen
Paul's Security Weekly TV
Black Hat Dual Interview pt.1- Enterprise Security Weekly #105 from 2018-09-07T09:00

Paul interviews Marc French the SVP Chief Trust Officer of Mimecast. He also interviews Ofer Maor the Director of Solutions for Synopsys. Ofer talks about the problem Synopsys solves, the deploy...

Listen
Paul's Security Weekly TV
BitSight, SentinelOne, and McAfee - Enterprise Security Weekly #105 from 2018-09-06T09:00

How the Department of Defense is using Open Source, BitSight launches forecasting capability, SentinelOne teams up with Sumo Logic, Swimlane supports McAfee's advanced security operation, Fortin...

Listen
Paul's Security Weekly TV
Texas, T-Mobile, and Jack Daniel - Paul's Security Weekly #573 from 2018-09-04T09:00

In the Security News this week, Zero-Day Windows exploits, How to hide sensitive files in encrypted containers, Misfortune Cookie vulnerability returns, and bank robbers faked Cosmos backend to ...

Listen
Paul's Security Weekly TV
No-Script Automation Tool, John Moran - Paul's Security Weekly #573 from 2018-09-03T09:00

John is a Senior Product Manager at DFLabs, where he performs a wide variety of tasks from product management to content development and partner management. Prior to joining DFLabs John worked f...

Listen
Paul's Security Weekly TV
Jayson Street, SphereNY - Paul's Security Weekly #573 from 2018-09-02T09:00

Jayson E. Street is an author of the "Dissecting the hack: Series". Also the DEF CON Groups Global Ambassador. Plus the VP of InfoSec for SphereNY. He has also spoken at DEF CON, DerbyCon, GRRCo...

Listen
Paul's Security Weekly TV
Minerva Labs, CrowdStrike, & VMware - Enterprise Security Weekly #104 from 2018-09-01T09:00

In the Enterprise News this week, VMWare launches Blockchain project, lacework raises new funds to extend Cloud Security capabilites, Minerva Labs achieves certified integration with McAfee ePO,...

Listen
Paul's Security Weekly TV
Office 365 User Behavior Analytics - Enterprise Security Weekly #104 from 2018-08-31T09:00

John Strand delivers the Technical Segment this week on Office 365 User Behavior Analytics. The idea is if you have a user account simultaneously logged in to multiple computer systems, that may...

Listen
Paul's Security Weekly TV
Fortnite, Netflix, & Black Hat - Application Security Weekly #30 from 2018-08-30T09:00

In the Application security news, 'Fortnite' developer had sharp words for Google after an Exploit was discovered, PHP flaw puts WordPress sites at risk, Oracle will charge for Java starting in ...

Listen
Paul's Security Weekly TV
Rick Holland, Digital Shadows - Enterprise Security Weekly #104 from 2018-08-30T09:00

Rick Holland has more than 15 years' experience working in information security. Paul and John talk to Rick about vulnerability management, WAFs, and advice to enterprise marketing.

Full ...

Listen
Paul's Security Weekly TV
Cloudera, AlienVault, and CA - Business Security Weekly #97 from 2018-08-29T09:00

Join Paul, Doug White, and Todd to talk about Security Innovation that includes: AlienVault, Cloudera, Splunk, Fortinet, CA and more!

Full Show Notes: Listen

Paul's Security Weekly TV
The Apache Struts2 RCE Vulnerability - Application Security Weekly #30 from 2018-08-29T09:00

Keith Hoodlet and Paul Asadoorian talk about The Apache Struts2 RCE Vulnerability. They cover:

- CVE-2018-11776

- How the 3 Ways of DevOps can guide us toward better security pract...

Listen
Paul's Security Weekly TV
Burp Suite 2.0, DNC, and NotPetya - Paul's Security Weekly #572 from 2018-08-28T09:00

The Untold story of NotPetya, New Apache Struts RCE Flaw, How door cameras are creating dilemmas for police, Google gets sued for tracking you even when your location history is off, and Artific...

Listen
Paul's Security Weekly TV
Todd Weller, Bandura Systems - Business Security Weekly #97 from 2018-08-28T09:00

Todd talks about his journey in the security industry. Todd also explains what Bandura Systems does for the security industry and how they sell their solution to companies.

Full Show Note...

Listen
Paul's Security Weekly TV
PHP Type Juggling Vulnerabilities, Netsparker - Paul's Security Weekly #572 from 2018-08-27T09:00

Sven Morgenroth is a security researcher at Netsparker. He found filter bypasses for Chrome's XSS auditor and several web application firewalls. He comes on the show to discuss PHP Type Juggling...

Listen
Paul's Security Weekly TV
Tod Beardsley, Rapid7 - Paul's Security Weekly #572 from 2018-08-26T09:00

Tod Beardsley is the Director of Research at Rapid7. Paul talks to Tod about his recent projects Sonar and Heisenberg. They also discuss Tod's Under the Hoodie pentest report.

Full Show N...

Listen
Paul's Security Weekly TV
Mike Jones, DomainTools - Enterprise Security Weekly #103 from 2018-08-25T09:00

Mike leads the Product Management, Product Marketing, UX, and Business Development efforts at DomainTools. He brings over 20 years of experience in the security industry, and has a real passion ...

Listen
Paul's Security Weekly TV
DEF CON 2018: Enterprise Vendors pt. 2 - Enterprise Security Weekly #103 from 2018-08-24T09:00

Paul Asadoorian and Matt Alderman compare and contrast the enterprise security vendors that were at Black Hat and DEF CON 2018.

Full Show Notes: Listen

Paul's Security Weekly TV
Matt Alderman & Paul Asadoorian, Def Con 2018 - Application Security Weekly #29 from 2018-08-23T09:00

Matt Alderman and Paul sat down at DEF CON to talk all of the AppSec vendors that they held briefings with at our Pool Cabana. They sat down with companies like Synopsis, Signal Sciences, and di...

Listen
Paul's Security Weekly TV
DEF CON 2018: Enterprise Vendors pt.1 - Enterprise Security Weekly #103 from 2018-08-23T09:00

Paul Asadoorian and Matt Alderman talk about and discuss the enterprise security vendors that attended DEF CON 2018.

Full Show Notes: Listen

Paul's Security Weekly TV
Matt Alderman & Paul, Def Con 2018 - Business Security Weekly #96 from 2018-08-22T09:00

Matt Alderman sits down with Paul this year at DEF CON to talk about the processes that they go through to hold briefings. Founders, CEO’s, and Business Execs of many different companies sat dow...

Listen
Paul's Security Weekly TV
Tom McLaughlin, ServerlessOps - Application Security Weekly #29 from 2018-08-22T09:00

Tom is the founder of ServerlessOps (https://www.serverlessops.io/) and an experienced operations engineer. He started ServerlessOps after he asked the question, what would he do if servers went...

Listen
Paul's Security Weekly TV
Cigars and Security - Paul's Security Weekly #571 from 2018-08-21T09:00

Paul and Matt Alderman had the chance at DEF CON to sit down and talk about Cigars and Security. In our very first episode, Paul asks Matt questions on how he got started in Security, who some o...

Listen
Paul's Security Weekly TV
Sharon Goldberg, Commonwealth Crypto - Business Security Weekly #96 from 2018-08-21T09:00

Sharon Goldberg is the CEO/Co-Founder of Commonwealth Crypto, a Boston blockchain startup that is making cryptocurrency trading more secure. She is also an associate professor in the Computer Sc...

Listen
Paul's Security Weekly TV
Spoofing GPS with a hackRF, Larry Pesce - Paul's Security Weekly #571 from 2018-08-20T17:23:36

Our very own Larry Pesce delivers the Technical Segment this week on Spoofing GPS with a hackRF.

Full Show Notes: https://wiki.securi...

Listen
Paul's Security Weekly TV
ThinkPenguin, Hacking Bodycams, & Adobe Flaws - Paul's Security Weekly #571 from 2018-08-20T09:00

In the Security News this week, Hacking Police Bodycams, Adobe fixes critical code execution flaws in latest patch update, Researchers develop device to aid in hunt for stealthy ATM card skimmer...

Listen
Paul's Security Weekly TV
Attack Simulation - Enterprise Security Weekly #102 from 2018-08-18T09:00

Paul and Matt discuss all of the vendors providing attack simulation solutions, including why you want (or need) this type of solution, the problem(s) they solve, and differentiators. This is an...

Listen
Paul's Security Weekly TV
Al Ghous, GE Digital - Enterprise Security Weekly #102 from 2018-08-16T09:00

Al Ghous is the Sr Director of Cyber Security for GE Digital. In this capacity Al is responsible for GE Digital’s Cloud Platform and Product Cyber Security where he is focused on building secure...

Listen
Paul's Security Weekly TV
Secure Coding Practices - Application Security Weekly #28 from 2018-08-15T09:00

After arriving back from Black Hat and DEF CON 2018, Doug joins Keith to share some of his stories about attending the world famous security conferences. They discuss, secure coding practices. Listen

Paul's Security Weekly TV
Alibaba Cloud Security, Comcast, and Facebook - Application Security Weekly #28 from 2018-08-14T14:27:21

Alibaba Cloud Security team discovers Apache spark rest API remote code execution exploit, Comcast security flaws exposed partial address, Hacker finds hidden 'God Mode' in old x86 CPUs, and mor...

Listen
Paul's Security Weekly TV
Resources, Bugs, Breaches, and Learning Tools - Application Security Weekly #27 from 2018-08-09T09:00

Hardware-based Root of Trust, Small Trusted Computing Base, React v16.4.2, GitHub shows best practices for account security and recoverability, and the cost of JavaScript, and Food for Thought!<...

Listen
Paul's Security Weekly TV
Katie Stebbins, UMASS - Business Security Weekly #95 from 2018-08-08T09:00

Katie Stebbins is the Vice President for economic development for the University of Massachusetts, a five-campus, 75,000-student public research university system. She serves as a liaison to the...

Listen
Paul's Security Weekly TV
Galen Hunt, Microsoft - Application Security Weekly #27 from 2018-08-08T09:00

Galen founded and lead the team building the Azure Sphere, announced at RSA Conference 2018. Our goal is to make IoT safe for society. Azure Sphere provides an end-to-end solution that enables a...

Listen
Paul's Security Weekly TV
Yale University, Spam's Revival, and SDR - Paul's Security Weekly #570 from 2018-08-07T09:00

Reddit breached after hackers bypass 2FA, Yale University discloses old school data breach, and 5 steps to fight unauthorized cryptomining. All that and more, here on security weekly!

Ful...

Listen
Paul's Security Weekly TV
Eric Bednash, RackTop - Business Security Weekly #95 from 2018-08-07T09:00

Eric Bednash is the CEO and co-founder of RackTop Systems. He has spent the past 19 years as an innovator and entrepreneur, designing products and solutions to solve challenging Extreme Data pro...

Listen
Paul's Security Weekly TV
Joshua Abraham, Praetorian - Paul's Security Weekly #570 from 2018-08-05T09:00

Josh is a key member of the technical execution team. In this capacity, he is responsible for leading, directing, and executing client-facing engagements that include Praetorian’s tactical and s...

Listen
Paul's Security Weekly TV
Oracle, FireEye, & Mimecast - Enterprise Security Weekly #101 from 2018-08-04T09:00

This week, Endace and Ixia partner to secure and monitor networks, Oracle brings autonomous security to identity with Trust Fabric, NetSpectre attack could enable remote CPU exploitation, FireEy...

Listen
Paul's Security Weekly TV
Evaluating Security Vendors At Trade Shows - Enterprise Security Weekly #101 from 2018-08-03T09:00

Paul and Jeff talk about the mentality you need to talk to vendors at a Trade Show. Concerning the upcoming conferences, Black Hat and Def Con, Paul and Jeff explain the best tactics to meet the...

Listen
Paul's Security Weekly TV
Spectre, OWASP, and iGoat - Application Security Weekly #26 from 2018-08-02T09:00

New Spectre attack can remotely steal secrets, Microsoft discovers supply chain attack at unnamed maker of PDF Software, XSS filter in edge, OWASP iGoat is a vulnerable swift application for iOS...

Listen
Paul's Security Weekly TV
Tenable, Imperva, & Proofpoint - Business Security Weekly #94 from 2018-08-01T09:00

This week, Imperva to acquire DevOps security leader prevoty, Carbon Black announces second quarter results, Sophos group upgraded to add at Numis Securities, Tenable jumps 31% by end of trading...

Listen
Paul's Security Weekly TV
Jessica Rozhin, Marqueta - Application Security Weekly #26 from 2018-08-01T09:00

Jessica Rozhin is currently a Security Engineer at an Oakland Financial Tech startup called Marqeta. This is her first role in the security space, but she is no stranger to technical operations ...

Listen
Paul's Security Weekly TV
Bluetooth Bug, Tenable, and Cosco - Paul's Security Weekly #569 from 2018-07-31T09:00

Bluetooth bug allows man-in-the-middle attacks on phones and laptops, serial killer electrocutes himself in jail cell sex act, Google launches its own USB-based FIDO U2F keys, and GhostPack.

...

Listen
Paul's Security Weekly TV
Article Discussion - Business Security Weekly #94 from 2018-07-31T09:00

This week, the show must go on. Paul and Matt Alderman talk about how leaders should stop avoiding the hard decisions, making smart people move in motion vs taking action, 10 things successful e...

Listen
Paul's Security Weekly TV
Chris Dale, Netsecurity - Paul's Security Weekly #569 from 2018-07-30T09:00

Chris Dale is the Head of the Penetration Testing & Incident Handling groups at Netsecurity, a mid-sized company based out of Norway. Along with significant security expertise, Chris has a backg...

Listen
Paul's Security Weekly TV
Dean Coclin, DigiCert - Paul's Security Weekly #569 from 2018-07-29T09:30

Dean Coclin is the Senior Director of Business Development at DigiCert. Dean brings more than 30 years of business development and product management experience in software, security, and teleco...

Listen
Paul's Security Weekly TV
Pulse, CloudHealth, and Barracuda - Enterprise Security Weekly #100 from 2018-07-28T09:00

Secure SAP Interfaces with the new Virtual Forge InterfaceProfiler, Sumo Logic unveils massive support for Google Cloud Platform, Barracuda's CloudGen WAF lands on Google Compute Platform.

<...

Listen
Paul's Security Weekly TV
Rip & Replace Your Antivirus Software? - Enterprise Security Weekly #99 from 2018-07-27T09:00

John Strand discusses whether your enterprise should replace your antivirus software and replace it with a new generation security software. Or, should the enterprises stick with your current ve...

Listen
Paul's Security Weekly TV
Joe Garcia, CyberArk - Application Security Weekly #25 from 2018-07-26T09:00

As a Global Corporate Solutions Engineer, Joe Garcia has a strong background in DevOps, Cloud and Security and is currently focused on helping customers implement and scale effective secrets man...

Listen
Paul's Security Weekly TV
Corey Thuen, Gravwell - Enterprise Security Weekly #100 from 2018-07-26T09:00

Corey Thuen is a founder of Gravwell and has spent over a decade in ICS (OT), IT, and IoT security. That experience is now driving development of a full-stack analytics platform built to solve m...

Listen
Paul's Security Weekly TV
Article Discussion - Business Security Weekly #93 from 2018-07-25T09:00

This week, Michael and Paul discuss the power of leaders who focus on solving problems, always waiting for and trusting the question, what someone learned from 5 years at Gartner, & how "Urgency...

Listen
Paul's Security Weekly TV
Venmo, Oracle, & Linux - Application Security Weekly #25 from 2018-07-25T09:00

Venmo caught publishing all transactions publicly, Oracle releases critical patches, Microsoft releases PowerShell Core for Linux, Health insurers are vacuuming up details about you, changing yo...

Listen
Paul's Security Weekly TV
Pen Testing, SIM Hijackers, & Mining Bitcoin - Paul's Security Weekly #568 from 2018-07-24T09:00

In the Security News this week, the evolutionary waves of the penetration testing, the SIM Hijackers, Roblox blames virtual "gang rape" on hack, thousands of Mega logins dumped online, Facebook ...

Listen
Paul's Security Weekly TV
Gary Berman, Cyberman Security - Business Security Weekly #93 from 2018-07-24T09:00

Gary is the CEO of Cyberman Security and refers to himself as, "the most reluctant cyber security person in the world" given that his 25-year career has been as a thought leader in marketing com...

Listen
Paul's Security Weekly TV
Chris Spehn, Mandiant's Red Team - Paul's Security Weekly #568 from 2018-07-23T09:00

Chris 'Lopi' Spehn is a consultant on Mandiant's red team. Chris was formerly a penetration tester for major credit card companies and retailers. Chris is also the founder of Illinois State Univ...

Listen
Paul's Security Weekly TV
Davi Ottenheimer, MongoDB - Paul's Security Weekly #568 from 2018-07-22T09:00

Davi Ottenheimer is a strategist and author focused on cultural disruptions and defense ethics in emerging data platforms and intelligent machines; for more than twenty years’ he has led global ...

Listen
Paul's Security Weekly TV
ThreatConnect, Optiv, & StackRox - Enterprise Security Weekly #99 from 2018-07-21T09:00

Alert Logic transforms Container Security, McAfee announces new enterprise security portfolio, ThreatConnect updates its Playbooks, Optiv Security launches new managed identity service, CA Techn...

Listen
Paul's Security Weekly TV
AppSec Solutions in a DevOps World - Application Security Weekly #24 from 2018-07-19T09:00

Application Security solutions in a DevOps world.

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode24 Follow us on ...

Listen
Paul's Security Weekly TV
Mayank Varia, Boston University pt. 2 - Business Security Weekly #92 from 2018-07-18T09:00

Mayank Varia is a research associate professor of computer science at Boston University and the co-director of BU's Center for Reliable Information Systems & Cyber Security. He holds a bachelor'...

Listen
Paul's Security Weekly TV
iOS Bugs, Burp Suite, & DevSecOps - Application Security Weekly #24 from 2018-07-18T09:00

In the news, compromised JavaScript package caught stealing npm credentials, remote iOS bugs, a $39 device that can defeat iOS USB Restricted mode, Broadcom buys CA Technologies, Burp Suite Auto...

Listen
Paul's Security Weekly TV
Chris Brenton, Active Countermeasures - Enterprise Security Weekly #95 from 2018-07-18T09:00

Chris has been a leader in IT and security for over 20 years. He has written multiple books on networking and security including "Mastering Cisco Routers" and "Mastering Network Security".

<...

Listen
Paul's Security Weekly TV
Airport Security, Dark Web, and Apple - Paul's Security Weekly #567 from 2018-07-17T09:00

In the Security News this week, Hackers put Airport Security system Access on the Dark Web, Arch Linux PDF reader package poisoned,Chrome defends Spectre, & Cisco patches bug in VoIP phones.

...

Listen
Paul's Security Weekly TV
Mayank Varia, Boston University pt. 1 - Business Security Weekly #92 from 2018-07-17T09:00

Mayank Varia is a research associate professor of computer science at Boston University and the co-director of BU's Center for Reliable Information Systems & Cyber Security. He holds a bachelor'...

Listen
Paul's Security Weekly TV
Limor Elbaz, Peerlyst - Paul's Security Weekly #567 from 2018-07-16T09:30

Limor is an entrepreneur, product evangelist, security expert, and a business development executive. She is the Founder of Peerlyst, the largest community of security professionals, serving more...

Listen
Paul's Security Weekly TV
SolarWinds, Mimecast, & AT&T - Enterprise Security Weekly #98 from 2018-07-15T09:00

This week, Thoma Bravo to buy majority stake in cybersecurity firm Centrify, SolarWinds acquires real-time threat-monitoring service Trusted Metrics, Mimecast acquires Ataata, AT&T to acquire Al...

Listen
Paul's Security Weekly TV
Zane Lackey, Signal Sciences - Paul's Security Weekly #567 from 2018-07-15T09:00

Zane Lackey is the Founder/Chief Security Officer at Signal Sciences and serves on the Advisory Boards of the Internet Bug Bounty Program and the US State Department-backed Open Technology Fund....

Listen
Paul's Security Weekly TV
Joe McManus, Automox - Enterprise Security Weekly #98 from 2018-07-14T09:00

Joe McManus is an expert and industry advisor in the field of information security. He currently serves as the CISO of Automox, provider of cloud-based, cross-platform patching software. He is a...

Listen
Paul's Security Weekly TV
Ferruh Mavituna, Netsparker - Enterprise Security Weekly #98 from 2018-07-13T09:00

Ferruh Mavituna is the Founder and Product Manager of Netsparker. He developed the first and only proof-based web security scanner with state-of-the-art, accurate vulnerability detection and exp...

Listen
Paul's Security Weekly TV
The Hardest Problem in Application Security - Application Security Weekly #23 from 2018-07-12T09:00

One of the hardest problems that Application Security practitioners need to solve is the problem of visibility. Not only do they need to uncover all of the different projects under development -...

Listen
Paul's Security Weekly TV
Intellectual Property, Edna Conway - Business Security Weekly #91 from 2018-07-11T09:00

CSO of Cisco Systems, Inc. Edna Conway, makes her return to discuss Intellectual Property with Paul, and more on this episode of Business Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
Facebook, Google, & GitLab - Application Security Weekly #23 from 2018-07-11T09:00

In the news, Google patches critical remote code execution bugs in Android OS, A new data breach may have exposed personal information of almost every American adult, Facebook acknowledges it sh...

Listen
Paul's Security Weekly TV
Articles, News, & Discussion - Business Security Weekly #91 from 2018-07-10T09:00

Technical experts need to get better at telling stories, How to get the upper hand in any "Take It Or Leave It" offer, How and when to inform your team of major developments in your business, wh...

Listen
Paul's Security Weekly TV
PHPMyAdmin, GitHub, and VS Code - Application Security Weekly #22 from 2018-07-05T09:00

'GDPR-Lite', Testing Firefox, refactoring in VS Code, sniff network traffic from our iOS device, Gentoo GitHub organization is hacked, and what does it mean to experience fulfillment? All that a...

Listen
Paul's Security Weekly TV
WPA3, Ticketmaster, and Don't Wipe So Hard - Paul's Security Weekly #566 from 2018-07-03T09:00

Terrible passwords outlawed in Microsoft's new Azure tool, Ticketmaster suffers security breach in personal and payment data, stop wiping your butt so hard, Toronto cops in big trouble for eatin...

Listen
Paul's Security Weekly TV
Thomas GX, Yelda - Application Security Weekly #22 from 2018-07-03T09:00

Thomas GX is a French entrepreneur specialized in Automation, AI, Assistants & Bots, handling creation and development as well as project management processes.

Full Show Notes: Listen

Paul's Security Weekly TV
Fun with Android APK's, Joff Thyer - Paul's Security Weekly #566 from 2018-07-02T09:00

Ever wonder how to get started pen testing Android Apps? This tech segment will demonstrate a few basic techniques and tools to give you a taste of mobile app assessments with the Android platfo...

Listen
Paul's Security Weekly TV
Tom Brennan & Gary Berman - Paul's Security Weekly #566 from 2018-07-01T09:00

Tom Brennan from Proactive Risk and Gary Berman from Cyberman Security, come on the show and talk about their journey up till their comic. They give us the inside scoop on their comic book, "The...

Listen
Paul's Security Weekly TV
Duo, CyberArk, & Demisto - Enterprise Security Weekly #97 from 2018-06-30T09:00

This week, Duo integrates with Sophos to address BYOD Security, SkyHigh not the limit of McAfee's ambition; IPO an option, CyberArk's new offering to mitigate privileged access risk, Ping Identi...

Listen
Paul's Security Weekly TV
Gabriel Gumbs, STEALTHbits - Enterprise Security Weekly #97 from 2018-06-29T09:00

Gabriel Gumbs is the VP of Product Strategy at STEALTHbits Technologies. With a 16 year tenure in CyberSecurity, he has spent more than a decade of that as a security practitioner at companies l...

Listen
Paul's Security Weekly TV
Microsoft, JavaScript, AI Can Fire - Application Security Weekly #21 from 2018-06-28T09:00

Apple comments on erroneous reports of iPhone brute force passcode hack, XSS, in Google Colaboratory + CSP bypass, how to deploy to Azure with Docker & VS Code, and debugging JavaScript in Googl...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #90 from 2018-06-27T09:00

Tron Foundation acquired BitTorrent, PayPal acquired Simility, Panaseer raised $10M Series A, and Agari raised $40M Series E.

Full Show Notes: Listen

Paul's Security Weekly TV
Dan Kuykendall, Rapid7 - Application Security Weekly #21 from 2018-06-27T09:00

Dan Kuykendall is the Senior Director of Application Security Products at Rapid7 where he directs the strategic vision, research and product development for the company’s application security so...

Listen
Paul's Security Weekly TV
Golden Tickets, 911 Callers, and Hacking Therapy - Paul's Security Weekly #565 from 2018-06-26T09:00

In the Security News this week, shutting down the Internet to prevent cheating, Yubico claims a bug bounty and upsets researchers, patching MRI scanners, getting your money back after being scam...

Listen
Paul's Security Weekly TV
Topic: How to Conduct a Time Audit - Business Security Weekly #90 from 2018-06-26T09:00

Struggling with unplanned work and finding the time to make change? Worry no more, my friends... I’ll share the strategy I introduce to the team I work with. Then Paul and I break down the big e...

Listen
Paul's Security Weekly TV
NMAP Scripts With LUA and NSE - Paul's Security Weekly #565 from 2018-06-25T09:00

Jason Wood delivers this technical segment on NMAP. Everyone loves using Nmap and the Nmap Scripting Engine. We don't always write NSE scripts though. Writing scripts for can be a bit intimidati...

Listen
Paul's Security Weekly TV
Galen Hunt, Microsoft Azure - Paul's Security Weekly #565 from 2018-06-24T09:00

Founder of Microsoft Azure Sphere, Galen Hunt is a Distinguished Engineer at Microsoft. Azure Sphere provides an end-to-end solution that enables any device manufacturer to create highly-secured...

Listen
Paul's Security Weekly TV
Topic: IPFIX - Enterprise Security Weekly #96 from 2018-06-22T09:00

IPFIX stands for Internet Protocol Flow Information Export. It was created due to a need for common, universal standard of export for Internet Protocol flow information from routers, probes, and...

Listen
Paul's Security Weekly TV
Windows, Smart Lock, & iPhone Hackers - Application Security Weekly #20 from 2018-06-21T09:00

In the news, Microsoft Windows remote kernel crash vulnerability, another flaw hits Tapplock smart locks, cops aren't confident iPhone hackers found a workaround to Apple's new security feature ...

Listen
Paul's Security Weekly TV
ForeScout, SafeBreach, & ExtraHop - Enterprise Security Weekly #96 from 2018-06-21T09:00

ForeScout deepens visibility into OT networks with industrial system integrations, Trend Micro extends container security for DevOps, Sophos adds AI to improve Its email security solution, Forti...

Listen
Paul's Security Weekly TV
Splunk, VictorOps, & Claroty - Business Security Weekly #89 from 2018-06-20T09:00

In Tracking Security Innovation, Splunk acquired VictorOps for $120M, Claroty raised $60 in Series B, "MIT's Mind-Blowing Solutions to the 9 Hardest Startup Problems", "Two Techniques for Helpin...

Listen
Paul's Security Weekly TV
Ron Gula, Gula Tech Adventures - Application Security Weekly #20 from 2018-06-20T09:00

Ron started his cybersecurity career as a network penetration tester for the NSA. at BBN, he developed network honeypots to lure hackers and he ran US Internetworking's team of penetration teste...

Listen
Paul's Security Weekly TV
Pennsylvania, Equifax, and US Senators - Paul's Security Weekly #564 from 2018-06-19T09:00

In the Security News this week, Smart lock can be hacked in seconds, librarian sues Equifax over 2017 data breach wins $600, Neighbors of Cold War Air Force deserter knew him as 'Tim'. In the ra...

Listen
Paul's Security Weekly TV
Sandy Dunn, CISO - Business Security Weekly #89 from 2018-06-19T09:00

Sandra (Sandy) Dunn has over 24 years in the software and hardware industry. Initially starting out in software and hardware sales she worked with NASA, JPL, Secret Service, IRS, and other Feder...

Listen
Paul's Security Weekly TV
Keith Hoodlet: Bug Bounty Hunting - Paul's Security Weekly #564 from 2018-06-18T09:00

Keith will be talking through some of the tools, techniques, and procedures he uses to perform recon, identify targets of interest, and report findings faster and easier.

Full Show Notes:...

Listen
Paul's Security Weekly TV
Jason Haddix, Bugcrowd - Paul's Security Weekly #564 from 2018-06-17T09:00

As the Vice President of Trust & Security, Jason works with clients and security researchers to create high value, sustainable, and impactful bug bounty programs.

Full Show Notes: Listen

Paul's Security Weekly TV
Riverbed, Tufin, & Splunk - Enterprise Security Weekly #95 from 2018-06-15T09:00

In the Enterprise News, Riverbed announced the latest release of Riverbed SteelCentral, Tufin advances automation capabilities with Tufin Orchestration Suite R18-1, ServiceNow announces new conv...

Listen
Paul's Security Weekly TV
Fortinet, Qualys, & CounterTack - Business Security Weekly #88 from 2018-06-14T09:00

In Tracking Security Innovation, Fortinet acquires Bradford Networks, Qualys acquires Second Front Systems, CounterTack acquires GoSecure, Panorays raised $5 million in an unattributed round, On...

Listen
Paul's Security Weekly TV
Peter Chestna, Veracode - Application Security Weekly #19 from 2018-06-14T09:00

Peter Chestna is the Director of Developer Engagement Veracode. He comes on the show to talk about the article he wrote called "The 3 Ways of DevSecOps".

Full Show Notes: Listen

Paul's Security Weekly TV
Article Discussion - Business Security Weekly #88 from 2018-06-13T09:00

Dr. Laurence J. Peter's paradox, do senior executives have the wisdom and discipline to get enough sleep, the changing face of B2B Marketing, and the questions the best mentors ask.

Full ...

Listen
Paul's Security Weekly TV
Masha Sedova, Elevate Security - Business Security Weekly #88 from 2018-06-12T14:20:33

Masha Sedova is an industry-recognized people-security expert, speaker and trainer focused on engaging people to be key elements of secure organizations. She is the co-founder of Elevate Securit...

Listen
Paul's Security Weekly TV
John Kinsella, Layered Insight - Paul's Security Weekly #563 from 2018-06-12T09:00

John Kinsella is a co-founder and head of product for Layered Insight, a container security startup based in San Francisco, California. His 20-year background includes security and network consu...

Listen
Paul's Security Weekly TV
CounterTack, Phishing Attacks, and Who Uses Flash? - Paul's Security Weekly #563 from 2018-06-11T09:00

In the Security News this week, Google Chrome has a critical vulnerability, Flash has another zero-day exploit, Colorado passes “most stringent” breach notification law, hackers hack a plane fro...

Listen
Paul's Security Weekly TV
Jake Reynolds, LogRhythm - Paul's Security Weekly #563 from 2018-06-10T09:00

Jake Reynolds is the Technology Alliances Engineer at LogRhythm, where he is responsible for supporting the development and management of the company’s integrations with third-party technology p...

Listen
Paul's Security Weekly TV
Qualys, Twistlock, & Tenable - Enterprise Security Weekly #94 from 2018-06-08T09:00

In the news, Infoblox research finds explosion of personal and IoT devices, Qualys announces letter of intent to acquire second front systems, Fortinet acquires Bradford Networks, Tenable extend...

Listen
Paul's Security Weekly TV
Microsoft, KnowBe4, & Signifyd - Business Security Weekly #87 from 2018-06-07T09:00

In Tracking Security Innovation, Microsoft to acquire GitHub for $7.5B, Thoma Bravo acquired LogRhythm for undisclosed, KnowBe4 acquired exploqii for undisclosed, Signifyd raised $100M Series D,...

Listen
Paul's Security Weekly TV
GitHub, Oracle, & GDPR - Application Security Weekly #18 from 2018-06-07T09:00

In the news, how other companies are responding to GDPR, Oracle plans to drop Java Serialization Port, Microsoft acquires GitHub, the percentage of open source code in proprietary apps is rising...

Listen
Paul's Security Weekly TV
Group Discussion: Penetration Testing - Enterprise Security Weekly #94 from 2018-06-07T09:00

Paul and John welcome Adrian Sanabria, Director of Research for Savage Security; Dave Kennedy, Founder of TrustedSec, Binary Defense, and DerbyCon; and Security Weekly's very own Jeff Man! Paul ...

Listen
Paul's Security Weekly TV
Jonathan Pritchard, Like A Mind Reader Training - Business Security Weekly #87 from 2018-06-06T09:00

Jonathan Pritchard is a business consultant specializing in the psychology of communication, negotiation, influence, and sales. Previously he spent 15 years traveling the world as a mentalist, a...

Listen
Paul's Security Weekly TV
Agile vs. DevOps - Application Security Weekly #18 from 2018-06-06T09:00

This week, Keith and Paul discuss what the difference is between Agile, CI/CD, and DevOps! Agile is focused on processed, highlighting change, all while accelerating delivery. CI/CD focuses on s...

Listen
Paul's Security Weekly TV
Acoustic Attacks, Bromium, and New GDPR Law - Paul's Security Weekly #562 from 2018-06-05T09:00

Dozens of vulnerabilities discovered in DoD's enterprise travel system, what Apple hiding with iOS 11.4, Git repository vulnerability leds to remote code execution attacks, and feeling for Kaspe...

Listen
Paul's Security Weekly TV
Christian Hamer, Harvard University - Business Security Weekly #87 from 2018-06-05T09:00

Christian Hamer is the Chief Information Security Officer at Harvard University. Christian leads the University's information security program, which includes oversight of the University-wide in...

Listen
Paul's Security Weekly TV
Chris Elgee & Lee Ford, Mass. Army National Guard G-6 - Paul's Security Weekly #562 from 2018-06-04T09:00

Chris is a full time husband, father of four, and pen tester; he's a part time Army officer, an aspiring SANS instructor, and the back-up church bass player. Lee Ford spent 2yrs in Information s...

Listen
Paul's Security Weekly TV
Ronnie Flathers, Uptake Technologies - Paul's Security Weekly #562 from 2018-06-03T09:00

Ronnie Flathers is an experienced pentester and security consultant who is equally addicted to both netsec and appsec and splits his time appropriately. He currently is the AppSec Pentest Lead a...

Listen
Paul's Security Weekly TV
DuoSec, Varonis, & InAuth - Enterprise Security Weekly #93 from 2018-06-01T09:00

In the news, Malwarebytes completes deal to acquire Binisoft, Lastline tackles advanced malware threats, Duo Security names Veteran marketing Leader, Neville Letzerich as Chief Marketing Officer...

Listen
Paul's Security Weekly TV
Eric Bednash and Jonathan Halstuch, RackTop - Enterprise Security Weekly #93 from 2018-05-31T09:00

Eric Bednash is the CEO and co-founder of RackTop Systems. Jonathan Halstuch is the Chief Technology Officer and co-founder of RackTop Systems. Eric and Jonathan joins Paul and John this week fo...

Listen
Paul's Security Weekly TV
GDPR, DOJ Sinkholes, & PornHub - Paul's Security Weekly #561 from 2018-05-29T09:00

In the news, what will GDPR's impact be on U.S. consumer privacy, DOJ Sinkholes VPNfilter control servers found in U.S., the most important characteristics of a successful DevOps engineer, FBI s...

Listen
Paul's Security Weekly TV
Bypassing Chrome's XSS Auditor - Paul's Security Weekly #561 from 2018-05-28T09:00

Sven Morgenroth is a security researcher at Netsparker. He found filter bypasses for Chrome's XSS auditor and several web application firewalls. He likes to exploit vulnerabilities in creative w...

Listen
Paul's Security Weekly TV
Steven Bellovin, Columbia University - Paul's Security Weekly #561 from 2018-05-27T09:00

Steven M. Bellovin is the Percy K. and Vidal L. W. Hudson Professor of Computer Science at Columbia University, member of the Cybersecurity and Privacy Center of the university's Data Science In...

Listen
Paul's Security Weekly TV
Skybox, McAfee, & Thales - Enterprise Security Weekly #92 from 2018-05-26T09:00

In the news,Blueliv boosts its cyber-threat intelligence platform, Skybox partners with Exclusive Networks, Global Scheduling and Automation Software Market 2018 IBM, BMC Software, CA Technologi...

Listen
Paul's Security Weekly TV
Building Your Purple Team - Enterprise Security Weekly #92 from 2018-05-25T09:00

John gives a Technical Segment this week entitled "Building A Purple Team". He talks about different MITRE Tools.

Full Show Notes: ...

Listen
Paul's Security Weekly TV
Capital One, TransUnion, & Tanium Business Security Weekly #86 from 2018-05-24T09:00

In Tracking Security Innovation, Capital One acquired Confyrm, TransUnion acquired Iovation, Auth0 raised $55M Series D, Tanium raised $175M in equity, Cisco forming New Venture Fund, and more!<...

Listen
Paul's Security Weekly TV
Nest, Node.js, & F.Secure - Application Security Weekly #None from 2018-05-24T09:00

In the news, the entire Nest ecosystem of smart home devices goes offline, how Alphabet plans to keep hackers away from this year's election, the Node.js Ecosystem is chaotic and insecure, open-...

Listen
Paul's Security Weekly TV
Terry Mason, Head of Information Risk & Technology Governance - Business Security Weekly #86 from 2018-05-23T09:00

Terry Mason is the Head of Information Risk & Technology Governance at a global multi-strategy hedge fund with 15+ years of experience in information security, technology governance, technology ...

Listen
Paul's Security Weekly TV
James Wickett, Signal Sciences - Application Security Weekly #17 from 2018-05-23T09:00

James is the creator and founder of the Lonestar Application Security Conference which is the largest annual security conference in Austin, TX. He also runs DevOps Days Austin and is on the glob...

Listen
Paul's Security Weekly TV
Project Zero, Securus, and CIA's "Vault 7" Mega-Leak - Paul's Security Weekly #560 from 2018-05-22T09:00

Google Project Zero call Windows 10 Edge Defense ACG flawed, Wapiti Web Application vulnerability scanner 3.0.1 packet storm, CIA's "Vault 7" Mega-Leak, and Trump eliminates national cyber-coord...

Listen
Paul's Security Weekly TV
Corey Thuen and Kristopher Watts, Gravwell - Business Security Weekly #86 from 2018-05-22T09:00

Corey Thuen is a founder of Gravwell and has spent over a decade in ICS (OT), IT, and IoT security. Kristopher Watts is a founder of Gravwell and has spent over a decade in large scale Emulytics...

Listen
Paul's Security Weekly TV
Configuring Your Own Travel Router with OpenVPN - Paul's Security Weekly #560 from 2018-05-21T09:00

Sometimes you just need a router handy when traveling. This allows you to connect multiple devices, use a VPN for all of them, and allow you to connect to a network via Wifi, Ethernet or USB 4G ...

Listen
Paul's Security Weekly TV
Matthew Silva, RWU - Paul's Security Weekly #560 from 2018-05-20T09:00

This week we interview Matthew Silva, an Undergraduate student attending Roger Williams University, and is the President and Founder of the Cybersecurity and Intel Club!

Full Show Notes: ...

Listen
Paul's Security Weekly TV
ServiceNow, Gurucul Fraud, and Shadow Devices - Enterprise Security Weekly #91 from 2018-05-19T09:00

ServiceNow introduces virtual agent, Red Hat to integrate CoreOS with OpenShift, Thycotic announces IBM Security, and Gurucul Fraud Analytics Solution monitors users.

Full Show Notes: Listen

Paul's Security Weekly TV
Ron Gula, Gula Tech Adventures - Enterprise Security Weekly #91 from 2018-05-18T09:00

Paul is joined by his good friend Ron Gula to talk about attack simulation and threat detection SIM.

Full Show Notes: https://wiki....

Listen
Paul's Security Weekly TV
Article Discussion - Business Security Weekly #85 from 2018-05-17T09:00

In the Article Discussion on Leadership, Communication, and Innovation, "Why People Really Quit Their Jobs", "How To Motivate Greater Ambition In Teams", "Why You Need an Untouchable Day Every W...

Listen
Paul's Security Weekly TV
Adam Gordon, ITProTV - Application Security Weekly #16 from 2018-05-17T09:00

Adam Gordon comes on the show to talk about DevOps, SecOps, and DevSecOps. He explains how DevOps, as a solution, is the framework for defining software, the nature of automation, and the nature...

Listen
Paul's Security Weekly TV
Michael Santarcangelo, Security Catalyst - Enterprise Security Weekly #90 from 2018-05-16T09:00

Michael Santarcangelo joins Paul Asadoorian at Source Boston 2018 for an Enterprise Security Weekly interview. Michael Santarcangelo is the Founder of Security Catalyst, author of "Into the Brea...

Listen
Paul's Security Weekly TV
PhishLabs, SafeBreach, & Red Canary - Business Security Weekly #85 from 2018-05-16T09:00

In Tracking Security Innovation, PhishLabs-BrandProtect merger, Avast cuts proposed IPO range, SafeBreach raised $15M Series B, Red Canary raised $6.3M in Equity, and more!

Full Show Note...

Listen
Paul's Security Weekly TV
Text Bombs, Black Dots of Death, and Azure - Application Security Weekly #16 from 2018-05-16T09:00

A remote code execution vulnerability is discovered in Electron, the Azure CTO reveals details about Azure confidential computing, and part 1 of 3 on the ways of DevSecOps.

Full Show Note...

Listen
Paul's Security Weekly TV
Microsoft Zero-Day, Mirai DDoS Attack, and GDPR - Paul's Security Weekly #559 from 2018-05-15T09:00

"Microsoft Patches Two Zero-Day Flaws Under Active Attack", "5 Powerful Botnets Found Exploiting Unpatched GPON Router Flaws", "Mirai DDoS attack against KrebsOnSecurity cost device owners $300,...

Listen
Paul's Security Weekly TV
Apollo Clark, Consultant - Enterprise Security Weekly #90 from 2018-05-15T09:00

Apollo Clark, a well-known name on the Security Weekly network, joins us at Source Boston to discuss his talk on Malicious User Stories. Visit http://sec...

Listen
Paul's Security Weekly TV
George Finney, Southern Methodist University - Business Security Weekly #85 from 2018-05-15T09:00

George Finney, is the Chief Security Officer for Southern Methodist University and is the author of No More Magic Wands: Transformative Cybersecurity Change for Everyone. He has also taught in t...

Listen
Paul's Security Weekly TV
Thomas Fischer, Security Advocator - Enterprise Security Weekly #90 from 2018-05-14T22:24:50

Thomas Fischer joins us at Source Boston 2018. Thomas Fischer tells Paul about his talk at Source Boston on "GDPR: Why it Matters Now!". Visit http://sec...

Listen
Paul's Security Weekly TV
Docker Security Incident: Lessons Learned - Paul's Security Weekly #559 from 2018-05-14T09:00

Paul delivers the Technical Segment this week entitled "Docker Security Incident: Lessons Learned"!

Full Show Notes: https://wiki.sec...

Listen
Paul's Security Weekly TV
Joe Gray, Advanced Persistent Security - Paul's Security Weekly #559 from 2018-05-13T09:00

Joe Gray is a native of East Tennessee. He joined the U.S. Navy directly out of High School and served for 7 years as a Submarine Navigation Electronics Technician. He joins Paul and the crew th...

Listen
Paul's Security Weekly TV
Building Your AppSec Program - Application Security Weekly #15 from 2018-05-10T10:00

Keith and Paul talk more about building your own AppSec program. They discuss working with developers as part of building your appsec program, and giving developers the tools to be able to move ...

Listen
Paul's Security Weekly TV
Article Discussion - Business Security Weekly #84 from 2018-05-10T09:00

The work required to have an opinion, why email is so stressful, even though it’s not actually that time-consuming, how great leaders simplify decision-making, and more on this episode on Busine...

Listen
Paul's Security Weekly TV
Twitter, Meltdown, & RSAC - Application Security Weekly #15 from 2018-05-09T12:30

In the news, A Boeing 757 was hacked remotely while it sat on the runway, Twitter says all 336 million users should change their passwords, Meltdown patches return kernel page table directory to...

Listen
Paul's Security Weekly TV
Carbon Black, Trusted Key, & IronNet - Business Security Weekly #84 from 2018-05-09T09:00

In tracking security innovation, PE's US cybersecurity push resumes in 2018 after last year's lull, Carbon Black IPO Success, Trusted Key raised $3M in "Seed", Namogoo raised $15M Series B, Iron...

Listen
Paul's Security Weekly TV
Elizabeth Wharton, Senior Attorney - Business Security Weekly #84 from 2018-05-08T09:00

Ms. Wharton is a policy and transaction attorney specializing in the development and scale of drone, smart city, autonomous vehicle, and other emerging technologies. She serves as a Senior Assis...

Listen
Paul's Security Weekly TV
Drupal, Twitter, iLo Ransomware, and Cambridge Analytica - Paul's Security Weekly #558 from 2018-05-07T09:00

Firms running Cisco WebEx are told to update their software, Medical devices vulnerable to KRACK Wi-Fi attacks, Kitty Cryptomining Malware Cashes in on Drupalgeddon 2.0, Facebook fires engineer ...

Listen
Paul's Security Weekly TV
Leonard Rose, Principal Security Architect at Limelight Networks - Paul's Security Weekly #558 from 2018-05-06T09:00

Leonard Rose, Principal Security Architect at Limelight Networks, joins Paul and the crew this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Jeff Man, RSA Vendor Wrap-up - Enterprise Security Weekly #89 from 2018-05-05T21:00

Jeff Man joins Paul to talk about different vendors at the RSA Conference from this year, (recapping his experiences out at RSA 2 weeks ago, putting it in the enterprise podcast, what was exciti...

Listen
Paul's Security Weekly TV
Adam Gordon, ITProTV - Enterprise Security Weekly #89 from 2018-05-05T09:00

Holding 160 certifications and counting, Adam's encyclopedia of knowledge is only rivaled by his massive, and quite ridiculous collection of socks. Adam's 30+ years as an IT instructor in the pr...

Listen
Paul's Security Weekly TV
Cisco, LogRhythm, & ServiceNow - Enterprise Security Weekly #89 from 2018-05-04T09:00

Cisco sets a new standard for production grade Kubernetes, LogRhythm & Mimecast fuse email security & next-gen SIEM, ServiceNow snaps up VendorHawk to help its customers manage their SaaS spendi...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #83 from 2018-05-03T16:00

Carbon Black looking for $1B valuation in IPO, Avast looking for $4.5B valuation in IPO, Scality, Minim raised $2.5M in Seed Funding, a Cybersecurity Pledge, and more on this episode on Business...

Listen
Paul's Security Weekly TV
Drupal, RSAC, & Facebook - Application Security Weekly #13 from 2018-05-03T09:00

In the news, Drupal 7 and 8 core critical releases, Irony of Leaky App at #RSAC Not Lost on Attendees, US FDA seeking Congressional Authority for new requirements, Facebook fuels broad privacy d...

Listen
Paul's Security Weekly TV
FDA, Microsoft, & Android - Application Security Weekly #14 from 2018-05-03T09:00

In the news, SEC fines Yahoo $35 million for not reporting cyber breach, hackers found using a new code injection technique to evade detection, Microsoft dismantles it's Windows Development Grou...

Listen
Paul's Security Weekly TV
Building Your AppSec Program: Getting Started - Application Security Weekly #14 from 2018-05-03T09:00

Keith and Paul talk about building your application security program!

Full Show Notes: https://wiki.securityweekly.com/ASW_Episode...

Listen
Paul's Security Weekly TV
Programming Update & Discussion - Business Security Weekly #83 from 2018-05-02T16:00

Michael and Paul give you a programming update and discussion on the value prop scorecard, a Monthly Book Club Segment, regular segments on improving performance, regular audience-driven segment...

Listen
Paul's Security Weekly TV
Rami Sass, CEO & Co-Founder of WhiteSource - Application Security Weekly #13 from 2018-05-02T09:00

Rami Sass is CEO and Co-Founder of WhiteSource. Rami is an experienced entrepreneur and executive with vast experience in defining innovative products, leading technology groups and growing comp...

Listen
Paul's Security Weekly TV
Equifax, Amazon, & Hacking Hotels - Paul's Security Weekly #557 from 2018-05-01T09:00

In the news, Western Digital My Cloud EX2 NAS device leaks files, Equifax has spent $242.7 million on its data breach so far, New Skill let Amazon Alexa Spy on Users, Hackers find devious way to...

Listen
Paul's Security Weekly TV
Tim Chen, DomainTools - Business Security Weekly #83 from 2018-04-30T21:53:07

Tim joined as CEO of DomainTools in 2009 and has spent 9 years leading the transformation of the company from an advertising based consumer service to a profitable and growing Enterprise SaaS se...

Listen
Paul's Security Weekly TV
Jeff Man, Recap of RSAC - Paul's Security Weekly #557 from 2018-04-30T09:00

This week in the Topic Segment, our very own Jeff Man gives us a recap on the 2018 RSA Conference! He discusses HackerOne CEO talking Bug Bounty programs, DevSecOps day at RSA demonstrates how t...

Listen
Paul's Security Weekly TV
Ferruh Mavituna, Founder of Netsparker - Paul's Security Weekly #557 from 2018-04-29T09:00

Ferruh Mavituna is the Founder and Product Manager of Netsparker. He developed the first and only proof-based web security scanner with state-of-the-art, accurate vulnerability detection and exp...

Listen
Paul's Security Weekly TV
RSA, Fortinet, SANS, & Twitter - Enterprise Security Weekly #88 from 2018-04-28T21:00

In the news, RSA Spotlight: VMware and Sophos discuss latest innovations, Fortinet receives recommended rating in NSS Labs latest advanced endpoint protection test report, Twitter bans Kaspersky...

Listen
Paul's Security Weekly TV
Eyal Neemany, AD Domain Trusts and Forest Trusts - Enterprise Security Weekly #88 from 2018-04-28T09:00

Eyal is the Former Head of Israeli Air Force CERT & Forensics Team & currently the Senior Security Researcher at Javelin Networks. Eyal will describe and explain how AD Domain Trusts and Forest ...

Listen
Paul's Security Weekly TV
Lenny Zeltser and Eddy Bobritsky, Minerva Labs - Enterprise Security Weekly #88 from 2018-04-27T09:00

Cyber and Information Security Expert with 13+ years of experience. After 7 years in different cyber units at the Israeli Defense Forces (IDF), Eddy was self-employed, senior consultant for the ...

Listen
Paul's Security Weekly TV
Ron Gula, Gula Tech Adventures - Business Security Weekly #82 from 2018-04-26T09:00

Serial Cyber Security Entrepreneur, Ron Gula Founded Tenable Network Security and Network Security Wizards. Ron has 15+ years experience as CEO in cyber security industry. He joins Michael and P...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #82 from 2018-04-25T09:00

In the NYC enterprise startup scene, security is job one, In the wake of RSA, Value Prop Scorecard; An Invitation to Engage, and more on this episode on Business Security Weekly!

Full Sho...

Listen
Paul's Security Weekly TV
Drupal, Microsoft, & NSA - Paul's Security Weekly #556 from 2018-04-24T09:00

In the news, Microsoft built its own custom Linux OS to secure IoT devices, another critical flaw found in Drupal CorePatch your sites immediately, Facebook plans to build its own chips for hard...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership, Communication, and Innovation - Business Security Weekly #82 from 2018-04-24T09:00

In the Article Discussion on Leadership, Communication, and Innovation, Michael and Paul discuss 4 ways to improve your content marketing, to everyone who asks for 'Just A Little' of your time: ...

Listen
Paul's Security Weekly TV
Long Live Penetration Testing - Paul's Security Weekly #556 from 2018-04-23T09:00

We've spent time defining the value of penetration testing, how we can do them better and how organizations can make the most out of this activity. The question today is, "Do we still need penet...

Listen
Paul's Security Weekly TV
Adrian Sanabria, Savage Security - Paul's Security Weekly #556 from 2018-04-22T09:00

Adrian is the Research Director and Co-Founder of Savage Security. He spent a decade building security programs and defending large financial firms. He also spent many years as a consultant, per...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #81 from 2018-04-20T09:00

Carbon Black files for IPO (worth $100M?), Bomgar acquired by Francisco Partners for undisclosed, SecDo acquired by Palo Alto Networks for undisclosed, SpyCloud raised $5M Series A, and more on ...

Listen
Paul's Security Weekly TV
Attorney-Client Privilege & Security - Business Security Weekly #81 from 2018-04-19T21:00

Shawn Tuma sticks around to sort the good advice from the misinformation surrounding attorney-client privilege in security.

Full Show Notes: Listen

Paul's Security Weekly TV
Shawn Tuma, Scheef & Stone, LLP - Business Security Weekly #81 from 2018-04-19T09:00

Shawn Tuma is an experienced cybersecurity and data privacy attorney and partner at Scheef & Stone. He joins Michael this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Open Source Software - Application Security Weekly #12 from 2018-04-18T09:00

With GitHub's 10-year Anniversary, it's about time we talk Open Source! Visit: https://github.com/ten to read about their anniversary!

Full Show Notes: Listen

Paul's Security Weekly TV
RTF Bugs, Attacking Accountants, & Trollcave - Paul's Security Weekly #555 from 2018-04-17T09:00

In the news, RTF bug finally gets patched, so many ways to bridge an air gap, attacking accountants, spoofing all the ports and Trollcave, and more on this episode of Paul’s Security Weekly!

...

Listen
Paul's Security Weekly TV
Windows, MacOS, & Javascript - Application Security Weekly #12 from 2018-04-17T09:00

In the news, Attacking an FTP Client: MGETting more than you bargained for, Warning: Your Windows PC can get hacked by just visiting a site, new MacOS backdoor linked to OceanLotus, & more on th...

Listen
Paul's Security Weekly TV
Got Privs? Extract and Crack the Creds - Paul's Security Weekly #555 from 2018-04-16T16:00

In the bad old days we used to exploit LSASS memory to dump hashed credentials from memory. When dealing with a domain controller, and a large environment this is dangerous. This segment will ad...

Listen
Paul's Security Weekly TV
Ron Gula, Gula Tech Adventures - Paul's Security Weekly #555 from 2018-04-15T09:00

Ron is a Serial Cyber Security Entrepreneur. He founded Tenable Network Security and Network Security Wizards, and has 15+ years experience as CEO in cyber security industry. He joins Paul and t...

Listen
Paul's Security Weekly TV
Kevin Donovan, ObserveIT - Enterprise Security Weekly #87 from 2018-04-13T09:30

Paul is joined by the long lost John Strand, for this interview with Kevin Donovan. Kevin is one of ObserveIT’s insider threat experts and a Senior Solutions Architect.

Full Show Notes: <...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership, Communication, and Innovation - Business Security Weekly #80 from 2018-04-12T09:00

BetterCloud closes 60M funding round, Fyde raises $3M in seed funding, WAF security startup Threat X Raises $8.2 Million, RSA acquires Fortscale, expands NetWitness SIEM Platform, and more on th...

Listen
Paul's Security Weekly TV
Cisco, Tufin, Infocyte, & ObserveIT - Enterprise Security Weekly #87 from 2018-04-12T09:00

In the news this week, Product announcements from Infoblox, Infocyte, ObserveIT, ThreatQuotient, Cisco and Tufin. Symantec could be in hot water, and CA and Palo Alto both made a recent acquisit...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #80 from 2018-04-11T09:00

Five techniques to nail the marketing aspect of your investor pitch, GFI Software launches different type of subscription model, Spotify says 2 million people figured out how to block ads for fr...

Listen
Paul's Security Weekly TV
One Language to Rule Them All - Application Security Weekly #11 from 2018-04-10T21:00

Everything you want to build, anywhere you want to build it, can be done with JavaScript. This week Paul and Keith discuss One Language to Rule Them All: Node-based Operating System, NodeOS!

...

Listen
Paul's Security Weekly TV
Intel, Cisco, Facebook, & Twitter - Paul's Security Weekly #554 from 2018-04-10T09:00

In the news, Intel drops plans to develop Spectre microcode for ancient chips, Critical flaw leaves thousands of Cisco Switches vulnerable to remote hacking, VirusTotal launches 'Droidy' sandbox...

Listen
Paul's Security Weekly TV
Intel, Slack, Spectre, & NASA - Application Security Weekly #11 from 2018-04-09T21:00

In the news, Microsoft rushes out fix for major hole caused by previous Meltdown patch, Intel admits a load of its CPUs have Spectre v2 flaw that can't be fixed, Slack’s new policy lets bosses r...

Listen
Paul's Security Weekly TV
Masha Sedova, Elevate Security - Paul's Security Weekly #554 from 2018-04-09T09:00

Masha Sedova is an industry-recognized people-security expert, speaker and trainer focused on engaging people to be key elements of secure organizations. She is the co-founder of Elevate Securit...

Listen
Paul's Security Weekly TV
Katherine Teitler, MISTI - Paul's Security Weekly #554 from 2018-04-08T09:00

Katherine Teitler is the Director of Content for MISTI, where she is responsible for programming information security conferences, workshops, and summits. Katherine also writes on a variety of s...

Listen
Paul's Security Weekly TV
Topic: Security Threats from Virtual Machines - Enterprise Security Weekly #86 from 2018-04-07T09:00

Doug White, host of Secure Digital Life, comes on the show to talk about five, no six security threats from virtual machines!

Full Show Notes: Listen

Paul's Security Weekly TV
SolarWinds, Qualys, and NGINX - Enterprise Security Weekly #86 from 2018-04-06T09:00

This week on Enterprise News, SolarWinds unveils cloud-first backup service for dedicated servers and virtual servers, VMware acquires E8 Security, NGINX simplifies the journey to microservices,...

Listen
Paul's Security Weekly TV
Cloudflare, Facebook, & Red Team Wisdom - Application Security Weekly #10 from 2018-04-05T09:00

In the news, uncovering a bug in Cloudflare's Minification Service, how security alerts are keeping your code safer, Red Team wisdom, Facebook scraped call, text message data for years from Andr...

Listen
Paul's Security Weekly TV
DevOps or DevSecOps? - Application Security Weekly #10 from 2018-04-04T09:00

Does DevOps handle security, or does it need to be DevSecOps? Maybe your not doing DevOps if you’re not doing security. This week Paul and Keith discuss the debate between the two! Full Show Not...

Listen
Paul's Security Weekly TV
Apple, Meltdown, & Atlanta Hackers - Paul's Security Weekly #553 from 2018-04-03T09:00

In the news, Apple macOS Bug Reveals Passwords for APFS Encrypted Volumes in Plaintext, Windows 7 Meltdown patch opens worse vulnerability, Atlanta Hit by Ransomware Attack Impacting Multiple Se...

Listen
Paul's Security Weekly TV
Cutting The Cord: The Ideal Home Network Setup - Paul's Security Weekly #553 from 2018-04-02T09:00

In this weeks Technical Segment, Paul delivers his segment entitled Cutting The Cord: The Ideal Home Network Setup. Paul and the crew discuss Nvidia Shield, Firewalls, Parental Control, and othe...

Listen
Paul's Security Weekly TV
Rob Cheyne, SourceBoston - Paul's Security Weekly #553 from 2018-04-01T09:00

Rob Cheyne is a highly regarded technologist, trainer, security expert and serial entrepreneur. He has 25 years of experience in the information technology field and has been working in informat...

Listen
Paul's Security Weekly TV
Cisco, SensorNet, Wombat, and Google - Enterprise Security Weekly #85 from 2018-03-31T09:00

In the news, Cisco commits $50 million to end homelessness in Silicon Valley, Distil Networks' annual bad bot report finds one in five companies now block Russian traffic, Alex Stamos' original ...

Listen
Paul's Security Weekly TV
The Phoenix Project - Enterprise Security Weekly #85 from 2018-03-30T09:00

Paul and Keith Hoodlet discuss The Phoenix Project: A Novel about IT, DevOps, and Helping Your Business Win!

Full Show Notes: https...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership, Communication, and Innovation - Business Security Weekly #79 from 2018-03-29T09:30

A look at the importance of evidence-driven marketing, making the most of second chances, how to talk to strangers, and the latest in innovation, including the company preparing for an IPO.

...

Listen
Paul's Security Weekly TV
Dan Wheatley, StraightTalk - Business Security Weekly #79 from 2018-03-28T09:00

Dan Wheatley, Partner and CEO at Straight Talk Agency, joins us for the interview this week.

Full Show Notes: https://wiki.security...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #79 from 2018-03-27T09:00

Tenable hires Morgan Stanley, Sift Science raised $53M Series D, and Virsec raised $24M Series B. This segment is about the companies making news with founding rounds, exits, and other impacts y...

Listen
Paul's Security Weekly TV
Alex Stamos, Facebook, Uber, and The Cuban Sonic Weapon - Paul's Security Weekly #552 from 2018-03-26T09:00

The Scarlett Johansson PostgreSQL Malware Attack, Alex Stamos might be leaving Facebook, is Mark Zuckerburg in trouble with the law again?, Uber self-driving car hits and kills pedestrian, and C...

Listen
Paul's Security Weekly TV
How To Find The Most Innovative Tech At A Security Show - Paul's Security Weekly #552 from 2018-03-25T09:00

Paul and Jeff express their likes and dislikes of vendor booths. Discover how to be a good sales-rep for your company, how to make yourself stand out in the vendor space, and how to be loose in ...

Listen
Paul's Security Weekly TV
Brian Honan, BH Consulting - Enterprise Security Weekly #84 from 2018-03-24T09:00

John Strand holds down the fort and interviews Brian Honan who is recognised internationally as an expert on cybersecurity! Full Show Notes: https://wiki.securityweekly.com/ES_Episode84 Visit ht...

Listen
Paul's Security Weekly TV
Enterprise Tools to Defend Against Attacks - Enterprise Security Weekly #84 from 2018-03-23T09:00

John Strand is off the hook! John discusses what works for enterprises when it comes to attacks.

Full Show Notes: https://wiki.secu...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership - Business Security Weekly #78 from 2018-03-22T21:00

If we all hate business jargon, why do we use it? Great products align with existing behaviors, how to give swag your customers actually want to keep, and more on this episode of Business Securi...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #78 from 2018-03-22T09:00

Palo Alto Networks acquired Evident.IO for $300M, Experian acquires ClearScore for $384M, CyberArk acquires Vaultive for undisclosed, Netsparker raised $40M, and more on this episode on Business...

Listen
Paul's Security Weekly TV
Fred Scholl, Monarch Information Networks - Business Security Weekly #78 from 2018-03-21T09:00

Frederick Scholl is a highly accomplished Global Senior Information Security Risk Manager. He joins Michael & Paul this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
AMD, MailChimp, & Equifax - Application Security Weekly #9 from 2018-03-20T21:00

In the news, researchers say AMD processors have serious vulnerabilities and backdoors, hijacked MailChimp accounts used to distribute malware banking, Voodoo Kali, for Equifax executive charged...

Listen
Paul's Security Weekly TV
Dick Wilkins, Phoenix Technologies - Paul's Security Weekly #551 from 2018-03-20T09:00

Dick Wilkins is an Associate Professor of Computer Science at Thomas College in central Maine and is Principal Technology Liaison for Phoenix Technologies, a USA based system boot firmware devel...

Listen
Paul's Security Weekly TV
Personal Development in Application Security - Application Security Weekly #9 from 2018-03-19T21:00

This week, Introducing Metta: Uber's open source tool for adversarial simulation, probable wordlists, & AttackDeploy gets dockerized!

Full Show Notes: Listen

Paul's Security Weekly TV
Flash, Pwn2Own, & VMware - Paul's Security Weekly #551 from 2018-03-19T09:00

In the news, Memcrashed Memcached DDoS exploit tool, Flash, Windows Users: It's Time to Patch, VMware releases security updates, what happens when Bitcoin miners take over your town, and more on...

Listen
Paul's Security Weekly TV
Patrick Laverty, Rapid7 - Paul's Security Weekly #551 from 2018-03-18T09:00

Patrick is a pentester for Rapid7, has done SIRT work for Akamai and was a web application developer at Brown University. He joins Paul and the crew this week for an interview!

Full Show ...

Listen
Paul's Security Weekly TV
Rami Essaid, Distil Networks - Enterprise Security Weekly #83 from 2018-03-17T09:00

Founder of Distil Networks, Rami Essaid is a passionate entrepreneur who has been building companies for over a decade. Disrupting industries with technological innovations is a personal mission...

Listen
Paul's Security Weekly TV
Rapid7, CyberArk, & Tenable - Enterprise Security Weekly #83 from 2018-03-16T21:00

In the news, CyberArk buy Vaultive to enrich cloud security solutions, Tenable expands its research team, Rapid7 announces pricing of public offering, and more on this episode of Enterprise Secu...

Listen
Paul's Security Weekly TV
Thornton May, Futurist - Business Security Weekly #77 from 2018-03-16T09:00

Thornton is one of America’s premier "executive educators" designing and delivering high impact curricula at UCLA, UC-Berkeley, Arizona State University, THE Ohio State University, the Universit...

Listen
Paul's Security Weekly TV
KnowBe4, Snyk, & McAfee - Business Security Weekly #77 from 2018-03-15T21:00

KnowBe4 acquired Popcorn Training for undisclosed, Snyk raises $7M Series A, McAfee acquired TunnelBear for undisclosed, and more on this episode of Business Security Weekly!

Full Show No...

Listen
Paul's Security Weekly TV
Edna Conway, Cisco Systems, Inc. - Business Security Weekly #77 from 2018-03-15T09:00

Edna Conway currently serves as Cisco's Chief Security Officer, Global Value Chain, creating clear strategies to deliver secure operating models for the digital economy. She joins Michael and Pa...

Listen
Paul's Security Weekly TV
Ethereum, Kali Linux, & Creepy Alexa - Application Security Weekly #8 from 2018-03-14T21:00

In the news, Amazon admits Alexa is creepily laughing at people and is working on a fix, Ethereum fixes serious 'eclipse' flaw that could be exploited by any kid, Kali Linux is now an app in the...

Listen
Paul's Security Weekly TV
AppSec/Development Partnership - Application Security Weekly #8 from 2018-03-14T09:00

This week, Paul and Keith talk about "The Phoenix Project: A Novel about IT, DevOps, and Helping Your Business Win!"

Full Show Notes: Listen

Paul's Security Weekly TV
Cisco, Kali, Equifax, & Facebook - Paul's Security Weekly #550 from 2018-03-13T09:00

In the news, Cisco hardcoded passwords, Kali on Windows, Equifax recovers $114 million on $26.5 million in expenses from breach, and more on this episode of Paul's Security Weekly!

Full S...

Listen
Paul's Security Weekly TV
Sven Morgenroth, Netsparker - Paul's Security Weekly #550 from 2018-03-12T09:00

Sven Morgenroth is a security researcher at Netsparker. He found filter bypasses for Chrome's XSS auditor and several web application firewalls.

Full Show Notes: Listen

Paul's Security Weekly TV
Stefano Righi, UEFI - Paul's Security Weekly #550 from 2018-03-11T10:00

Stefano has over 35 years of experience in research and development. Stefano is representing AMI on the UEFI Forum Board of Directors and serves on the UEFI Security Response Team. He joins Larr...

Listen
Paul's Security Weekly TV
PhishMe, Splunk, & CyberX - Business Security Weekly #76 from 2018-03-10T10:00

In the news, PhishMe acquired for $400M, Splunk acquires Phantom Cybersecurity for $350M, CyberX raised $18M Series B, and more on this episode of Business Security Weekly!

Full Show Note...

Listen
Paul's Security Weekly TV
Eyal Neemany, Domain Exploitation and Malware in the Olympics Hack - Enterprise Security Weekly #82 from 2018-03-09T22:00

Former Head of Israeli Air Force CERT & Forensics Team, Senior Security Researcher at Javelin Networks, Eyal Neemany joins Paul and John for a Technical Segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Articles of Discussion - Business Security Weekly #76 from 2018-03-09T10:00

This week, Michael and Paul talk how to build trust with colleagues, simple concepts to free up innovation, how to avoid 'Death by Committee', and more business security news!

Full Show N...

Listen
Paul's Security Weekly TV
AlgoSec, SolarWinds, & Martin Shkreli - Enterprise Security Weekly #82 from 2018-03-08T22:00

In the news, Duo Security launches media site, SolarWinds Democratizes Network Path Analysis with Release of Traceroute NG Free Tool, Martin Shkreli has to forfeit the Wu-Tang album because just...

Listen
Paul's Security Weekly TV
Shawn Tuma, Scheef & Stone, LLP - Business Security Weekly #76 from 2018-03-08T10:00

Shawn Tuma is an experienced cybersecurity and data privacy attorney and partner at Scheef & Stone. He joins Michael & Paul this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
DigiCert, GitHub, & Black Panther - Application Security Weekly #7 from 2018-03-07T22:00

In the news, DigiCert statement on Trustico certificate renovation, GitHub survived the biggest DDoS attack ever recorded, Black Panther inspired Disney to fund a STEM center in Oakland, & more ...

Listen
Paul's Security Weekly TV
Facebook Malware Scan - Application Security Weekly #7 from 2018-03-06T22:00

This week, Paul and Keith discuss Facebook's mandatory malware scan and how they lost daily users for the first time ever in the U.S. and Canada!

Full Show Notes: Listen

Paul's Security Weekly TV
Quickjack, Olympics, Largest DDoS Attack, and Bad AI is Still Bad AI - Paul's Security Weekly #549 from 2018-03-06T10:00

In the news, Quickjack advanced Clickjacking & frame slicing attack tool, how to fight mobile number port-out scams, the Russians hacked the Olympics, top 5 ways security vulnerabilities hide in...

Listen
Paul's Security Weekly TV
Bruce Sussman, SecureWorld Boston - Paul's Security Weekly #549 from 2018-03-05T10:00

Bruce Sussman spent more than 20 years on TV screens in Portland, Oregon. He joins Paul and crew this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Mary Beth Borgwing, Mach37 - Paul's Security Weekly #549 from 2018-03-04T10:00

Mary Beth Borgwing is an Advisor to MACH 37 and Center for Innovation (CIT). She joins Paul and team this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Red Hat, OpenShift, Atos, and Trustwave - Enterprise Security Weekly #81 from 2018-03-03T10:00

In the news, Atos unveils new managed service built on Red Hat OpenShift platform, Trustwave launches proactive Threat Hunting service, Phantom Cyber fetches $350 million in acquisition by Splun...

Listen
Paul's Security Weekly TV
Ferruh Mavituna, Netsparker - Enterprise Security Weekly #81 from 2018-03-02T10:00

Ferruh Mavituna is the Founder and Product Manager of Netsparker. He joins Paul and Doug this week for the interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Sean D'souza, "The Brain Audit", Pt. 2 - Business Security Weekly #75 from 2018-03-01T10:00

Author of "The Brain Audit", Sean D'souza runs Psychotactics.com. It's a site which explores why customers buy (and why they don't). He joins Michael and Paul for part two interview on this epis...

Listen
Paul's Security Weekly TV
Will Lin, Trident Capital - Business Security Weekly #75 from 2018-02-28T10:00

Will has invested more than $100 million across 15+ cybersecurity companies to date. He is currently a Principal and Founding Investor at Trident Capital. He joins Michael & Matt Alderman for an...

Listen
Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #75 from 2018-02-27T10:00

This week, Apptio raised $4.6M in Equity, Vectra raised $36M in Series D, Morphisec raised $12M in Series B, and more Business Security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tracking Security Innovation - Business Security Weekly #74 from 2018-02-23T10:00

This week, IdentityMind Global raised $10M Series C, DataVisor raised $40M Series C, Infocyte raised $5.2 series B, and more business security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Sean D'Souza, Psychotactics.com - Business Security Weekly #74 from 2018-02-22T10:00

Author of "The Brain Audit", Sean D’souza runs Psychotactics.com. It's a site which explores why customers buy (and why they don't). He joins Michael and Paul for an interview on this episode of...

Listen
Paul's Security Weekly TV
Bitcoin, Salon, Oxford Comma Dispute, and Amazon - Application Security Weekly #6 from 2018-02-21T10:00

In the news, Lenovo warns of critical Wifi vulnerability, Russian nuclear scientists arrest for Bitcoin mining plot, remote workers are outperforming office workers, & more on this episode of Ap...

Listen
Paul's Security Weekly TV
Joe Kay, Enswarm Business Security Weekly #74 from 2018-02-21T10:00

Joe Kay is the Founder & CEO of Enswarm, a technology business who are transforming the way people work together with a team intelligence tool that kills meetings. He joins Michael & Paul for an...

Listen
Paul's Security Weekly TV
Topic: Bug Bounties - Application Security Weekly #6 from 2018-02-20T22:00

This week, Keith and Paul discuss Data Security and Bug Bounty programs! They mention the lessons learned from the Uber breach and why Google paid 2.9 million in Bug Bounties in 2017!

Ful...

Listen
Paul's Security Weekly TV
DoubleDoor, NSA, & Google - Paul's Security Weekly #548 from 2018-02-20T10:00

In the news, DoubleDoor IoT botnet abuses two vulnerabilities to circumvent firewalls, cyber-attackers continue to be financially motivated, Internet security threats at the 2018 Olympics, and m...

Listen
Paul's Security Weekly TV
Michael Bazzell, OSINT & Privacy Consultant - Paul's Security Weekly #548 from 2018-02-19T10:00

Michael Bazzell spent 18 years as a government computer crime investigator. He joins Paul and crew this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Steve Tcherchian, XYPRO Technology - Paul's Security Weekly #548 from 2018-02-18T10:00

Steve Tcherchian, CISSP, PCI-ISA, PCIP is the Chief Information Security Officer and the Director of Product Management for XYPRO Technology. He joins Paul and team this week for an interview! Listen

Paul's Security Weekly TV
Domain Persistence, Javelin Networks - Enterprise Security Weekly #80 from 2018-02-17T10:00

Guy Franco is a highly experienced Security Researcher & Developer, and Security Consultant at Javelin Networks. He joins Paul and John this week for the Technical Segment!

Full Show Note...

Listen
Paul's Security Weekly TV
Startup & Security News You Need to Know - Business Security Weekly #73 from 2018-02-16T10:00

In the Startup News, APERIO Systems, Proofpoint, J2 Global acquired VIPRE, LogMeIn acquired Jive Communications, and Owl.

Full Show Notes: Listen

Paul's Security Weekly TV
NopSec, Palo Alto, & Microsoft - Enterprise Security Weekly #80 from 2018-02-16T10:00

In the news, ServerSide exploits dominate threat landscape & OT vulnerabilities rise, Palo Alto extends security to all major cloud providers, NopSec awarded most innovative cybersecurity compan...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership, Communication, and Innovation - Business Security Weekly #73 from 2018-02-15T22:00

Michael and Paul cover security concerns pushing IT to channel services, hard skills plus social skills, they describe what really drives sales growth, and best practices are dead! Here on Busin...

Listen
Paul's Security Weekly TV
Dawn-Marie Hutchinson, Optiv - Business Security Weekly #73 from 2018-02-14T22:00

Michael and Paul interview Dawn-Marie Hutchinson from Optiv. She brings 15 years of enterprise information technology experience to her role as an as executive director, executive advisory at Op...

Listen
Paul's Security Weekly TV
NSA, Google, & Microsoft - Application Security Weekly #05 from 2018-02-14T10:00

In the news, NSA Exploits Ported to Work on All Windows Versions Released Since Windows 2000, beware the looming Google Chrome HTTPS certificate apocalypse, Microsoft open sources a new Kubernet...

Listen
Paul's Security Weekly TV
OWASP ASVS pt. 2 - Application Security Weekly #05 from 2018-02-13T22:00

This week, Paul and Keith continue to discuss OWASP Application Security Verification Standards!

Full Show Notes: https://wiki.sec...

Listen
Paul's Security Weekly TV
Bitcoin, NSA, and Facebook - Paul's Security Weekly #547 from 2018-02-13T10:00

In the news, multiple vulnerabilities in 7-Zip, how getting granular improves network security, NSA exploit use on rise for cryptocurrency mining,and more on this episode of Paul’s Security Week...

Listen
Paul's Security Weekly TV
ESP8266 SoC0, Larry Pesce - Paul's Security Weekly #547 from 2018-02-12T10:00

Larry Pesce delivers the Technical Segment on an intro to the ESP8266 SoC!

Full Show Notes: https://wiki.securityweekly.com/Episode54...

Listen
Paul's Security Weekly TV
Zane Lackey, Signal Sciences Paul's Security Weekly #547 from 2018-02-11T10:00

Zane Lackey is the Founder/Chief Security Officer at Signal Sciences and serves on the Advisory Boards of the Internet Bug Bounty Program and the US State Department-backed Open Technology Fund....

Listen
Paul's Security Weekly TV
BehavioSec, DISCO, & Logikcull - Business Security Weekly #72 from 2018-02-09T10:00

In the news, BehavioSec raised $17.5M Series B, RELX acquires ThreatMetrix for $817M, Logickull raised $25M Series B, and more on this episode of Business Security Weekly!

Full Show Notes...

Listen
Paul's Security Weekly TV
Asif Awan & Matt Alderman, Layered Insight - Business Security Weekly #72 from 2018-02-08T10:00

This week, Matt Alderman, Chief Strategy Marketing Officer at Layered Insight, & Asif Awan, Co-founder & CTO of Layered Insight join Michael & Paul for an interview!

Full Show Notes: Listen

Paul's Security Weekly TV
Vik Desai, Accenture - Business Security Weekly #72 from 2018-02-07T22:00

Vik leads Accenture Security's global Products Operating Group, with responsibility for the creation and delivery of comprehensive strategies and solutions for Retail, Industrial, Travel, Consum...

Listen
Paul's Security Weekly TV
Summer Fowler, InfoSecWorld 2018 Speaker - Enterprise Security Weekly #79 from 2018-02-07T20:55:48

Summer has 17 years of experience in software engineering, cybersecurity, and technical management. She joins Paul and Doug this week for an interview! Full Show Notes: https://wiki.securityweekly....

Listen
Paul's Security Weekly TV
CISCO, SANS, APIS, and Mastering Security in the Zettabyte Era - Enterprise Security Weekly #79 from 2018-02-07T20:54:23

Paul and Doug discuss a new variant of Scarab, a remote code execution vulnerability in the XML parser, APIS post mushrooming security risk, and mastering security in the Zettabyte era. Full Show N...

Listen
Paul's Security Weekly TV
Intel, CloudFair, & Lenovo - Application Security Weekly #04 from 2018-02-07T10:00

In the news, Intel warned Chinese companies of chip flaw before U.S. government, $530 million cryptocurrency heist may be the biggest ever, Fitness tracking app Strava gives away location of sec...

Listen
Paul's Security Weekly TV
OWASP Application Security Verification Standard - Application Security Weekly #04 from 2018-02-06T22:00

This week, Paul and Keith discuss OWASP Application Security Verification Standards!

Full Show Notes: https://wiki.securityweekly....

Listen
Paul's Security Weekly TV
AI Celebrity Porn, NSA Exploit, and Bitcoin Exchange - Paul's Security Weekly #546 from 2018-02-06T10:00

Bitcoin exchange robbed, Deepfakes AI celebrity porn channel shut down by Discord, NSA Exploit Use On Rise For Crypto Currency Mining, First Jackpotting Attacks Hit U.S. ATMs, and more!

F...

Listen
Paul's Security Weekly TV
MITRE, John Strand - Paul's Security Weekly #546 from 2018-02-05T10:00

John Strand, Managing Intern of Black Hills Information Security, delivers the Technical Segment on MITRE!

Full Show Notes: https://w...

Listen
Paul's Security Weekly TV
Mark Arnold & Will Gragido, InfoSecWorld 2018 - Paul's Security Weekly #546 from 2018-02-04T10:00

Will Gragido is an internationally recognized information security specialist. Mark Arnold brings more than 20 years of technical and leadership experience to his role as a Senior Director of Se...

Listen
Paul's Security Weekly TV
John Moran, DFLabs - Enterprise Security Weekly #78 from 2018-02-03T22:00

John is a Senior Product Manager at DFLabs, where he performs a wide variety of tasks from product management to content development and partner management. He joins John and Paul for an intervi...

Listen
Paul's Security Weekly TV
Brendan O'Connor, ServiceNow - Enterprise Security Weekly #78 from 2018-02-03T10:00

Brendan O'Connor is the Security CTO at ServiceNow. He joins Paul and John this week for an interview!

Full Show Notes: https://wik...

Listen
Paul's Security Weekly TV
Sqrrl, Microsoft, & BeyondTrust - Enterprise Security Weekly #78 from 2018-02-02T22:00

In the news, AWS beefs up threat detection with Sqrrl acquisition, Microsoft partners Cisco, BeyondTrust now seamlessly integrated with McAfee ePO, and more enterprise security news!

Full...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership - Business Security Weekly #71 from 2018-02-02T10:00

This week, Michael and Doug White discuss how to design addictive products, yearning for the vast and endless sea, and five soft skills recruiters want most!

Full Show Notes: Listen

Paul's Security Weekly TV
Security Literacy in the Digital Age - Business Security Weekly #71 from 2018-02-01T22:00

Michael and Doug discuss the increasing challenge for security and business leaders to develop the security literacy necessary in the digital age.

Full Show Notes: Listen

Paul's Security Weekly TV
Facebook, RedHat, & Russian Twitterbots - Application Security Weekly #03 from 2018-02-01T10:00

This week, Doug and Keith discuss the last of the top ten most critical web application security risks! They discuss security misconfiguration, insecure deserialization, insufficient logging and...

Listen
Paul's Security Weekly TV
Matias Madou, Secure Code Warrior - Application Security Weekly #03 from 2018-01-31T10:00

Matias Madou is the CTO of Secure Code Warrior where he is responsible for leading the company’s technology vision and overseeing the engineering team. He joins Keith this week for the feature i...

Listen
Paul's Security Weekly TV
BIND, Intel, and Brickerbot - Paul's Security Weekly #545 from 2018-01-30T10:00

In the news, Intel warns "Don’t install our patch!", what you need to know about hash length extension attacks, Meltdown and Spectre patching has been a total train wreck,and more on this episod...

Listen
Paul's Security Weekly TV
Critical Security Control Resources, John Strand - Paul's Security Weekly #545 from 2018-01-29T10:00

John Strand delivers the Technical Segment on Critical Security Control Resources!

Full Show Notes: https://wiki.securityweekly.com/E...

Listen
Paul's Security Weekly TV
Kevin Donovan, ObserveIT - Paul's Security Weekly #545 from 2018-01-28T10:00

Kevin is one of ObserveIT's insider threat experts and a Senior Solutions Architect. He joins Larry and team this week for an interview on Paul's Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
ThreatMetrix, Palo Alto, and CrowdStrike - Enterprise Security Weekly #77 from 2018-01-27T10:00

In the news, ThreatMetrix teams up with GlobalOnePay, CrowdStrike walks away from Cloud distribution, SmartBear announces new API testing and documentation tool, and more enterprise security new...

Listen
Paul's Security Weekly TV
Lenny Zeltser, Minerva Labs - Enterprise Security Weekly #77 from 2018-01-26T10:00

Lenny Zeltser, VP of Products at Minerva Labs, is a seasoned business and tech leader with extensive information security expertise. He joins Paul and John for an interview!

Full Show Not...

Listen
Paul's Security Weekly TV
FireEye, WatchGuard, and First Alert - Business Security Weekly #70 from 2018-01-25T10:00

In the article discussion, three time management tips that actually work, confident speakers tell stories, and how to let go the need to be perfect! In the news, we have updates from FireEye, Wa...

Listen
Paul's Security Weekly TV
Jennifer Minella, Carolina Advanced Digital, Inc. - Business Security Weekly #70 from 2018-01-24T10:00

Jennifer Minella is VP of Engineering with Carolina Advanced Digital, Inc. She joins Paul and Michael for an interview on this week’s episode of Business Security Weekly!

Full Show Notes:...

Listen
Paul's Security Weekly TV
Top 10 OWASP pt.2 - Application Security Weekly #02 from 2018-01-23T22:00

This week, Paul and Keith discuss the last of the top ten most critical web application security risks! They discuss security misconfiguration, insecure deserialization, insufficient logging and...

Listen
Paul's Security Weekly TV
BIND, Intel, and Brickerbot - Paul's Security Weekly #544 from 2018-01-23T10:00

In the news, BIND comes apart thanks to ancient denial of service vuln, Brickerbot taking out your IoT one device at a time, Intel fix causes reboots and slowdowns, WiFi alliance announces WPA3 ...

Listen
Paul's Security Weekly TV
Google, Oracle, and Apple - Application Security Weekly #02 from 2018-01-22T22:00

In the Application Security News, Paul and Keith discuss Google Chromecast and Google Chrome, ballistic missile alerts, Intel AMT security issues, and the stress of remote working! All that and ...

Listen
Paul's Security Weekly TV
Rebekah Brown, Rapid7 - Paul's Security Weekly #544 from 2018-01-22T10:00

Rebekah Brown has spent more than a decade working in intelligence and information security. Today, Rebekah leads the threat intelligence programs at Rapid7, where her responsibilities include p...

Listen
Paul's Security Weekly TV
Adam Gordon, ItPro.TV - Paul's Security Weekly #544 from 2018-01-21T10:00

With over 30 years of experience as both an educator and IT professional, Adam holds numerous Professional IT Certifications. He joins Paul and team this week for an interview on Paul’s Security...

Listen
Paul's Security Weekly TV
VIVOTEK, Moneris, and AlgoSec - Enterprise Security Weekly #76 from 2018-01-20T10:00

In the news, privileged account management into the hybrid cloud, VIVOTEK and Trend Micro announce strategic partnership, Moneris partners with Kount to expand fraud protection services for Cana...

Listen
Paul's Security Weekly TV
Clayton Fields, Javelin Networks - Enterprise Security Weekly #76 from 2018-01-19T10:00

As a security specialist, Clayton has helped clients improve security programs across the world. A thorough understanding of business drivers coupled with the ability to diagnose risk has allowe...

Listen
Paul's Security Weekly TV
SolarWinds, Verizon, Cyxtera, and Arctic Wolf - Business Security Weekly #69 from 2018-01-18T10:00

In the Security News, Paul and Michael discuss SolarWinds acquiring LOGGLY (undisclosed), Verizon acquires Niddel, Cyxtera Technologies acquires Immunity (undisclosed), and Arctic Wolf raised $1...

Listen
Paul's Security Weekly TV
Curiosity Is the Key To Getting Answers - Business Security Weekly #69 from 2018-01-17T10:00

This week, Paul and Michael talk about how to be more productive without burning out, what it takes to become a great product manager, what cybersecurity chiefs can learn from Warren Buffett, an...

Listen
Paul's Security Weekly TV
Google, Intel, Oracle, and Meltdown-Spectre - Hack Naked News #157 from 2018-01-16T20:38:21

This week, Paul reports on malicious Google Chrome extensions affecting 500K users, configuration errors in Intel workstations being labeled a security hole, VMware releases security updates for...

Listen
Paul's Security Weekly TV
Skype, Apple, and Wi-Fi Alliance - Paul's Security Weekly #543 from 2018-01-16T10:00

In the news, prosecutors say Mac Spyware stole millions of user images over 13 years, Skype finally getting end-to-end encryption, Apple set to patch yet another macOS password security flaw, 14...

Listen
Paul's Security Weekly TV
OWASP Top 10 (2017) Overview - Application Security Weekly #1 from 2018-01-15T22:00

This week, Paul and Keith discuss the ten most critical web application security risks! They discuss broken authentication, sensible data exposure, XML external entities (XXE), broken access con...

Listen
Paul's Security Weekly TV
Jake Williams, SANS - Paul's Security Weekly #543 from 2018-01-15T10:00

Jake Williams is the founder of Rendition Infosec and is a Senior Instructor at the SANS Institute. MalwareJake clears last weeks news story with the latest news on Meltdown and Spectre. He join...

Listen
Paul's Security Weekly TV
NVIDIA, Oracle, Coinbase, and Bitcoin - Application Security Weekly #1 from 2018-01-14T22:00

In the Application Security News, Paul and Keith discuss how malicious NPM packages could harvest credit card numbers and passwords from your site, NVIDIA updates video drivers to help address C...

Listen
Paul's Security Weekly TV
Diana Kelley & Ed Moyle, Security Curve - Paul's Security Weekly #543 from 2018-01-14T10:00

Diana Kelley is the Cybersecurity Field CTO at Microsoft and a cybersecurity thought leader, practitioner, executive advisor, speaker, author and co-founder of SecurityCurve. Ed Moyle is current...

Listen
Paul's Security Weekly TV
Container Security - Enterprise Security Weekly #75 from 2018-01-13T10:00

Matt Alderman talks about container security with Paul! They analyze Docker, static analysis tools, and image build processes!

Full Show Notes: Listen

Paul's Security Weekly TV
CASB Bitglass, WhiteHat, and Twistlock - Enterprise Security Weekly #75 from 2018-01-12T10:00

CASB Bitglass, WhiteHat, and Twistlock - Enterprise Security Weekly #75 In the news, CASB Bitglass announces zero-day cloud app indexing with machine learning, WhiteHat combats code vulnerabilit...

Listen
Paul's Security Weekly TV
Marci McCarthy, CEO and President of T.E.N. - Enterprise Security Weekly #75 from 2018-01-11T22:00

This week, Matt Alderman joins Paul to interview Marci McCarthy, CEO and President of T.E.N. & CEO and Chairman of ISE®! Marci has over 20 years of business management and entrepreneurial experi...

Listen
Paul's Security Weekly TV
Article Discussion and Security News - Startup Security Weekly #68 from 2018-01-11T10:00

In our article discussion and security news, we talk about how managers are insane for brainstorming in groups, the real reasons companies are so focused on the short term, how to break bad busi...

Listen
Paul's Security Weekly TV
Google, Intel, Mozilla, and Starbucks - Application Security Weekly #00 from 2018-01-09T22:00

In the Application Security News, Paul and Keith talk about impatient employers designing their own courses, measurable CPU differences in AWS from Intel CPU vulnerabilities, the CEO of Intel se...

Listen
Paul's Security Weekly TV
VMWare, Meltdown, Spectre, and Chip Hacks That Work - Paul's Security Weekly #542 from 2018-01-09T10:00

10 things in cybersecurity that you might have missed in 2017, a flaw in major browsers, a critical flaw in phpMyAdmin, beware of a VMWare VDP remote root issue, how to protect your home router,...

Listen
Paul's Security Weekly TV
Rise of Application Security - Application Security Weekly #00 from 2018-01-08T22:00

Paul and Keith host the first show of Application Security Weekly! Today, they discuss the brief history of application security, software, and software security! With application security on th...

Listen
Paul's Security Weekly TV
Mimikatz Event Log Clearing Feature with John Strand - Paul's Security Weekly #542 from 2018-01-08T10:00

John will be talking about the new mimikatz event log clearing feature.

Full Show Notes: https://wiki.securityweekly.com/Episode542 Listen

Paul's Security Weekly TV
Marcello Salvati, Coalfire Labs - Paul's Security Weekly #542 from 2018-01-07T10:00

Marcello Salvati is a senior security consultant at Coalfire Labs by day and by night a tool developer who discovered a novel technique to turn tea, sushi and dank memes into somewhat functionin...

Listen
Paul's Security Weekly TV
Bam Azizi, NoPassword - Startup Security Weekly #68 from 2018-01-05T21:54:43

Bam Azizi is the CTO and co-founder of WiActs Inc., a cybersecurity startup and the company behind NoPassword.com. Prior to joining NoPassword, he was working on his PhD at Technical University ...

Listen
Paul's Security Weekly TV
Patching Intel Vulnerabilities In The Enterprise - Enterprise Security Weekly #74 from 2018-01-05T10:00

Our topic segment today will discuss Patching Intel Vulnerabilities In The Enterprise. All that and more on Enterprise Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
Coalfire, Swimlane, Shift in Security Solutions, and Twistlock 2.3 - Enterprise Security Weekly #74 from 2018-01-04T10:00

Doctors make the best rappers, 3 innovative security companies, DevOps will be a thing, integrate products swimmingly, AI and Machine Learning in the hands of bad actors, and serverless security...

Listen
Paul's Security Weekly TV
Rich Walchuck and Rick Olesek, CryptoniteNXT - Startup Security Weekly #67 from 2018-01-04T10:00

Rick brings nearly 20 years of experience working in both technical and business aspects of Cybersecurity and startups. He began his career in cybersecurity as a network security analyst working...

Listen
Paul's Security Weekly TV
Fake Bitecoin, North Korea, and Wordpress - Paul's Security Weekly #541 from 2017-12-27T10:00

In the news, we discuss Uber paying hacker to keep quiet, flaw in Intel processors, banking apps found vulnerable to MITM attacks, Apple patching all other High Sierra security holes,and more on...

Listen
Paul's Security Weekly TV
Kevin Finisterre, Department 13 - Paul's Security Weekly #541 from 2017-12-26T10:00

Kevin Finisterre is a principal of the security consultancy Digitalmunition, he enjoys testing the limits and is constantly dedicated to thinking outside the box. Kevin’s primary focus has alway...

Listen
Paul's Security Weekly TV
Bob Hillery, InGuardians - Paul's Security Weekly #541 from 2017-12-25T10:00

Bob Hillery join us on Security Weekly and is an experienced consultant in Information Systems Security Management. He is a founder and Chief Research Officer with InGuardians, Inc. and has an e...

Listen
Paul's Security Weekly TV
All I Want for Christmas is A Secure Active Directory - Enterprise Security Weekly #73 from 2017-12-23T10:00

Many roads lead to Active Directory insecurity, such as e-mail phishing, letting go of your foothold, and all of that can be done without getting caught. These problems can be solved with Endpoi...

Listen
Paul's Security Weekly TV
Flexera, Amazon, and ExtraHop - Enterprise Security Weekly #73 from 2017-12-22T10:00

It’s the most hackable time of the year! In the news, Paul and John discuss Flexera reimaging open source vulnerability detection, dispelling cybersecurity myths, Amazon to acquire cybersecurity...

Listen
Paul's Security Weekly TV
ShieldX, Menlo, Gemalto, and Accenture - Startup Security Weekly #66 from 2017-12-20T10:00

In the news, the best way to manage risk, creating defining moments for your customers, Upstream raised $9 million, ShieldX, Menlo, Atos offers to buy Gemalto, and the implosion of early-stage V...

Listen
Paul's Security Weekly TV
North Korea, Kaspersky, and France to Facebook - Hack Naked News #154 from 2017-12-19T21:29:33

Michael reports on a suspected North Korea Ransomware attack, Kaspersky federal software ban, compelled passwords, and 1 in 3 IT professionals looking for new jobs! Jason Wood of Paladin Securit...

Listen
Paul's Security Weekly TV
On-Demand Webcasts, Net Neutrality, and Pentesting - Paul's Security Weekly #540 from 2017-12-19T10:00

In the news, we talk about pentesting, On-Demand webcasts, net neutrality, Vegemite, and more on this episode of Paul’s Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
Ed Skoudis, Holiday Hack Challenge - Paul's Security Weekly #540 from 2017-12-18T10:00

Ed Skoudis has taught cyber incident response and advanced penetration testing techniques to more than 12,000 cybersecurity professionals. He is a SANS Faculty Fellow and the lead for the SANS P...

Listen
Paul's Security Weekly TV
Joe Gray, Advanced Persistent Security - Paul's Security Weekly #540 from 2017-12-17T10:00

Joe Gray is a native of East Tennessee. He joined the U.S. Navy directly out of High School and served for 7 years as a Submarine Navigation Electronics Technician. He is also the owner of the A...

Listen
Paul's Security Weekly TV
Jeff Schilling, CSO of Armor - Enterprise Security Weekly #72 from 2017-12-16T10:00

Jeff Schilling, CSO of Armor transitioned after a 24-year career in the Army. Career experiences in running a multi-million dollar PnL, Jeff joins us to talk about Cloud based security, incident...

Listen
Paul's Security Weekly TV
LogRhythm, Fortinet, and RiskSense - Enterprise Security Weekly #72 from 2017-12-15T10:00

LogRhythm named leader in Gartner magic quadrant, new report from CA Veracode, Fortinet launches Operational Technology Security platform, things to focus on in 2018, and more enterprise securit...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership, Innovation, and Startup Success - Startup Security Weekly #65 from 2017-12-14T10:00

Driving cultural change, the ‘Seed Stage’ is now the ‘Seed Gradient’, Prevoty raised $13M Series B, Okta reports earnings, Riskonnect acquired Aruvio, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Todd O'Boyle, StrongArm - Startup Security Weekly #65 from 2017-12-13T10:00

Todd O'Boyle is a co-founder and CTO at StrongArm, an Allied Minds company. He also served as principal investigator for a project developing methods to improve how operators respond to adversar...

Listen
Paul's Security Weekly TV
Google Patches, Android Flaw, and Apple HomeKit - Hack Naked News #153 from 2017-12-12T20:02:12

Paul reports on Google patches, vulnerability in two keyless entry locks, Mozilla security updates, and 1.4 billion plain-text leaked passwords found online! Jason Wood of Paladin Security joins...

Listen
Paul's Security Weekly TV
Uber, Vulnerable Banking Apps, and Bluetooth - Paul's Security Weekly #539 from 2017-12-12T10:00

In the news, a new Windows evasion technique, naked rowers, undetectable malware, social engineering from your shed and banking apps vulnerable to MITM attacks.

?Full Show Notes: Listen

Paul's Security Weekly TV
Bypassing Two-Factor Authentication - Paul's Security Weekly #539 from 2017-12-11T10:00

Former Head of Israeli Air Force CERT & Forensics Team, Senior Security Researcher at Javelin Networks. Eyal Neemany talks about bypassing two-factor authentication on Active Directory.

?...

Listen
Paul's Security Weekly TV
Lisa O'Connor, Accenture - Paul's Security Weekly #539 from 2017-12-10T10:00

Lisa leads Global Security Research and Development at Accenture Labs. In this role, she curates and manages a portfolio of cyber research, including threat intelligence, advanced cyber hunting,...

Listen
Paul's Security Weekly TV
Word-of-Mouth, Growth, McAfee, and Bitdefender - Startup Security Weekly #64 from 2017-12-07T10:00

Winning arguments, turning insight into execution, avoiding the "Yes" dilemma, and updates from Bitdefender, McAfee, Barracuda Networks, Pwnie Express, ReversingLabs, and more!

Full Show ...

Listen
Paul's Security Weekly TV
Zach Schlumpf, IOActive - Startup Security Weekly #64 from 2017-12-06T10:00

Zach Schlumpf is the Recruiting Coordinator for IOActive. An Army Veteran, former Red Teamer, and Seattle Locksport volunteer, Zach joins us to discuss recruiting, social engineering, and the ba...

Listen
Paul's Security Weekly TV
Dirty COW, Apache, MailSploit, and Mac - Hack Naked News #152 from 2017-12-05T22:56:39

Paul reports on a flaw found in Dirty COW patch, Apache Software security updates, more hacks in 2018, and a MailSploit e-mail spoofing flaw! Jason Wood joins us to give expert commentary on a F...

Listen
Paul's Security Weekly TV
High Sierra, NSA, WordPress, and HP - Paul's Security Weekly #538 from 2017-12-05T10:00

More secure WordPress updates, paying attention to SD-WAN security, NSA's "Red Disk" data leak, why gets you root, HP bloatware, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Network Telemetry with Mick Douglas, SANS Institute - Paul's Security Weekly #538 from 2017-12-04T10:00

Our good friend Mick Douglas takes an excerpt from SANS 555 and demonstrates using network telemetry to find unauthorized hosts with ELK stacks!

Full Show Notes: Listen

Paul's Security Weekly TV
Allison Miller Paul's Security Weekly #538 from 2017-12-03T10:00

Allison Miller has been working in the intersection of cybersecurity, human behavior, and predictive analytics for almost two decades. She has pioneered the use of data-driven detection technolo...

Listen
Paul's Security Weekly TV
James Wilkinson - Enterprise Security Weekly #71 from 2017-12-01T10:00

GuardiCore simplifies micro-segmentation, the latest tools used to fight cyberattacks, and acquisition news from McAfee, Trend Micro, Barracuda Networks, and more enterprise security news!

<...

Listen
Paul's Security Weekly TV
GuardiCore, Docker, CloudPassage, and McAfee - Enterprise Security Weekly #71 from 2017-11-30T10:00

GuardiCore simplifies micro-segmentation, the latest tools used to fight cyberattacks, and acquisition news from McAfee, Trend Micro, Barracuda Networks, and more enterprise security news!

<...

Listen
Paul's Security Weekly TV
Imgur, Firefox, Uber, and Facebook - Hack Naked News #151 from 2017-11-28T21:45:17

Paul and Michael report on an Exim-ergency, why Uber's in hot water, Firefox's new pwnage warnings, 1.7 million breached Imgur accounts, bidding farewell to SMS authentication, voting and securi...

Listen
Paul's Security Weekly TV
Rapid7, Tenable, and HPE - Enterprise Security Weekly #70 from 2017-11-25T10:00

Rapid7 and Tenable announce new headquarters, HPE's CEO steps down, announcements for CA World '17, and more enterprise security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Ismael Valenzuela, SANS Institute - Enterprise Security Weekly #70 from 2017-11-24T10:00

Ismael Valenzuela is a SANS instructor and Principal Engineer at McAfee. Since founding one of the first IT Security consultancies in Spain, he has participated in numerous security projects acr...

Listen
Paul's Security Weekly TV
Darren Mar-Elia, Semperis - Startup Security Weekly #63 from 2017-11-23T10:00

Darren Mar-Elia of Semperis is the Head of Product for Semperis. Semperis focuses on Active Directive protection.

Full Show Notes: ...

Listen
Paul's Security Weekly TV
Article Discussion on Leadership, Innovation, and Startup Success - Startup Security Weekly #63 from 2017-11-22T10:00

In the news, deciding with speed and conviction, learning from unicorns, starting your social enterprise, and updates from ThreatQuotient, Symantec, Optiv, and more on this episode of Startup Se...

Listen
Paul's Security Weekly TV
Microsoft, Amazon Key, Intel, and HP - Hack Naked News #150 from 2017-11-21T20:00:03

Don Pezet of ITProTV joins Paul to discuss Amazon S3 buckets, Google collecting Android data, secret spyware in smartwatches, and patches for Microsoft, Intel, HP, and more on this episode of Ha...

Listen
Paul's Security Weekly TV
DoD, Oracle, Apple, and Boeing - Paul's Security Weekly #537 from 2017-11-21T10:00

Blaming Russia, compromising Apple’s facial recognition, books to give to your 30-year old self, malware on NSA employee computers, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Mike Roderick & Adam Gordon, ITProTV - Paul's Security Weekly #537 from 2017-11-20T10:00

Our good friends Mike Roderick and Adam Gordon, two of ITProTV’s many security ninjas, deliver a tech segment and demo on virtualization, TPM, VMware, and virtual desktop infrastructure (VDI) as...

Listen
Paul's Security Weekly TV
Kyle Wilhoit, DomainTools - Paul's Security Weekly #537 from 2017-11-19T10:00

Kyle Wilhoit, a Senior Security Researcher for DomainTools, discusses all things dark web, illegal internet trade, and more with Paul!

Full Show Notes: Listen

Paul's Security Weekly TV
Comodo, RiskIQ, Forcepoint, and CloudHealth - Enterprise Security Weekly #69 from 2017-11-18T10:00

Free tools to remove website malware, next-gen CASBs, helping financial services with security, 10 steps to stop lateral movement, and more enterprise security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tony Kirtley, SecureWorks - Enterprise Security Weekly #69 from 2017-11-17T10:00

Tony Kirtley is a Senior Incident Response Consultant at SecureWorks. Paul and John pick Tony’s brain in an in-depth discussion about incident response in the enterprise!

Full Show Notes:...

Listen
Paul's Security Weekly TV
OnePlus, Amazon Key, and ADT - Hack Naked News #149 from 2017-11-16T16:45:14

Michael Santarcangelo and Jason Wood discuss Amazon Key's launch, backdoors on phones, consumers distrusting businesses with data, IT professionals turning to cybersecurity, and more on this epi...

Listen
Paul's Security Weekly TV
Zscalers, Crowdstrike, MetricStream, and Skybox - Startup Security Weekly #62 from 2017-11-16T10:00

Michael and Paul discuss myths about successful founders, side hustle, and overwhelmed consumers. In the news, updates from CrowdStrike, Skybox, Zscaler, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Roi Abutbul, Javelin Networks - Startup Security Weekly #62 from 2017-11-15T10:00

Roi Abutbul is the Co-Founder and CEO of Javelin Networks, an Israel-based protection platform for corporate domain environments. Roi joins Michael and Paul to talk about active directory, entre...

Listen
Paul's Security Weekly TV
Ex-NSA, Microsoft, Vault 8, and Backdoor in SATNAV - Paul's Security Weekly #536 from 2017-11-14T10:00

Marissa Mayer testifies, starting wars by hacking back, hacking fingerprint biometrics, the halfway point of Mr. Robot, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tech Segment: Sven Morgenroth, Netsparker - Paul's Security Weekly #536 from 2017-11-13T10:00

We welcome Sven Morgenroth back to the show! Sven currently works as a Security Researcher at Netsparker. He rejoins us to deliver a technical segment on content security policies and cross-site...

Listen
Paul's Security Weekly TV
Amanda Berlin, NetWorks Group and Lee Brotherston, Wealthsimple - Paul's Security Weekly #536 from 2017-11-12T10:00

Amanda Berlin of NetGroup and Lee Brotherston of Wealthsimple join Paul, Michael, and Larry for a discussion on the Defensive Security Handbook and its implications in the world of security!

...

Listen
Paul's Security Weekly TV
Logan Harris, SpotterRF - Enterprise Security Weekly #68 from 2017-11-11T10:00

Logan Harris founded SpotterRF in 2009 to provide wide-area surveillance radar to security professionals and war fighters. Logan joins Paul and Michael for a discussion on drone and radar techno...

Listen
Paul's Security Weekly TV
Forecepoint, WatchGuard, and Flexera - Enterprise Security Weekly #68 from 2017-11-10T10:00

Juniper enhances their Contrail Cloud service, Microsoft LAPS headaches, Flexera embraces open-source, local market deception technology, and more enterprise security news!

Full Show Note...

Listen
Paul's Security Weekly TV
WatchGuard, Forescout, and Synopsys - Startup Security Weekly #61 from 2017-11-09T10:00

Paul and Michael deliver startup updates from SailPoint, WatchGuard, KnowBe4, Synopsys, ForeScout, and more!

Full Show Notes: https...

Listen
Paul's Security Weekly TV
Sales Lessons, Idea to Launch, and Contribution Margin - Startup Security Weekly #61 from 2017-11-08T10:00

Paul and Michael discuss why some companies are hiring before training, the science behind contribution margin, sales lessons from successful entrepreneurs, battling from idea to launch, and why...

Listen
Paul's Security Weekly TV
FERC, Fake WhatsApp, and Google Play Bug - Hack Naked News #148 from 2017-11-07T20:01:02

Doug White and Jason Wood discuss improvements to IoT, fooling millions of Android users, Google Play bug bounties, school boards being hacked by pro-ISIS groups, and more with Jason Wood on thi...

Listen
Paul's Security Weekly TV
Gadi Evron, Cymmetria - Paul's Security Weekly #535 from 2017-11-07T10:00

Gadi Evron founded Cymmetria in 2014 with a vision of revolutionizing security technology, strategy, and innovation. He joins Paul, Doug, and Jeff for an interview about honeypots, hacking back,...

Listen
Paul's Security Weekly TV
Tim Medin, SANS Institute - Paul's Security Weekly #535 from 2017-11-06T10:00

Tim Medin from SANS comes on the show and does a tech segment on Windows PowerShell using PowerShell Empire.

Full Show Notes: https:/...

Listen
Paul's Security Weekly TV
Richard Moulds, Whitewood Security - Paul's Security Weekly #535 from 2017-11-05T09:00

Richard Moulds, General Manager of Whitewood Security, makes his triumphant return to the show!

Full Show Notes: https://wiki.securit...

Listen
Paul's Security Weekly TV
Ixia, Lacework, and Francisco - Enterprise Security Weekly #67 from 2017-11-03T09:00

Security horror stories, making cloud native a reality, and updates from Ixia, Lacework, Francisco, and more on this episode of Enterprise Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
Bryan Patton, Quest Software - Enterprise Security Weekly #67 from 2017-11-02T09:00

Bryan Patton is a Principal Strategic Systems Consultant for Quest Software. Prior to Quest, he worked with International Networking Services performing migrations to Active Directory and Exchan...

Listen
Paul's Security Weekly TV
Kaspersky, McAfee, AIG, and ARM - Hack Naked News #147 from 2017-10-31T19:07:36

Michael Santarcangelo discusses platform security architecture, Kaspersky, the Cyber Peace Corps, and more with Jason Wood on this episode of Hack Naked News!

Full Show Notes: Listen

Paul's Security Weekly TV
Article Discussion on Leadership, Innovation, and Startup Success - Startup Security Weekly #60 from 2017-10-25T09:00

Ten sales rules you should break, how to pitch a venture capitalist, guiding employees towards mental health, and updates from Duo Security, Contrast Security, and more startup news!

Full...

Listen
Paul's Security Weekly TV
WHOIS, OSX Malware, NetBSD, and Kaspersky - Hack Naked News #146 from 2017-10-24T18:35:46

Kaspersky has “nothing to hide”, the internet wants YOU, OS X malware runs rampant, WHOIS database slip-ups, and more. Jason Wood discusses an attack on critical US infrastructure on this episod...

Listen
Paul's Security Weekly TV
Microsoft, KRACK, Docker, and Kubernetes - Paul's Security Weekly #534 from 2017-10-24T09:00

Microsoft mocks Google for failed security fix, 5 steps to building a vulnerability management program, Pornhub, and kids smartwatches are harbouring major security flaws.

Full Show Notes...

Listen
Paul's Security Weekly TV
Borrowing Data, Joe Vest and Andrew Chiles, MINIS - Paul's Security Weekly #534 from 2017-10-23T09:00

Joe Vest and Andrew Chiles from MINIS talk about Borrowing data to hide binaries. Joe Vest is the Co-Founder of the security consulting company MINIS LLC. He has over 17 years' experience with a...

Listen
Paul's Security Weekly TV
Wendy Nather, Duo Security - Paul's Security Weekly #534 from 2017-10-22T09:00

Wendy Nather is Principal Security Strategist at Duo Security. Wendy is also a good friend of the Security Weekly team! She speaks regularly on topics ranging from threat intelligence to identit...

Listen
Paul's Security Weekly TV
Tanium Expands, LogRhythm, CyberArk, and Carbon Black - Enterprise Security Weekly #66 from 2017-10-21T09:00

Tanium expands their security platform, Carbon Black and IBM team up, improved container threat detection from StackRox, Illusive Networks introduces new mainframe deception, and more enterprise...

Listen
Paul's Security Weekly TV
Richard Moulds, Whitewood Security - Enterprise Security Weekly #66 from 2017-10-20T09:00

Richard Moulds has more than 18 years experience in the security industry with a specific focus on cryptography. Richard joins us to discuss the ROCA crypto bug!

Full Show Notes: Listen

Paul's Security Weekly TV
Attivo Networks, CloudZero, and Akami - Startup Security Weekly #59 from 2017-10-19T09:00

Defining traits of leaders, the realities of stealth mode, and updates from Attivo Networks, CloudZero, Akami, and more on this episode of Startup Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
Don Pezet, ITProTV - Startup Security Weekly #59 from 2017-10-18T09:00

The one and only Don Pezet of ITProTV rejoins us to discuss his philosophies on solving problems and creating markets in the business world!

Full Show Notes: Listen

Paul's Security Weekly TV
Equifax, Google Chrome, KRACK, and Adobe - Hack Naked News #145 from 2017-10-17T18:54:38

Paul talks about Equifax, TPMs security flaw in Infineon smart cards, Google removes more malicious Chrome extensions from Web Store, a Linux Kernel Privilege Escalation bug discovered, and Equi...

Listen
Paul's Security Weekly TV
Windows, Disqus, Cyberattacks, and FBI Cyberstalker - Paul's Security Weekly #533 from 2017-10-17T09:00

Windows Phone is dead, Disqus gets hacked, malvertising on X rated websites, North Korea ups their cyberattack game, the FBI arrests a cyberstalker, and more security news!

Full Show Note...

Listen
Paul's Security Weekly TV
Matthew Toussain, SANS Institute - Paul's Security Weekly #533 from 2017-10-16T09:00

Matthew Toussain is an active-duty Air Force officer and the founder of Spectrum Information Security. He regularly hunts for vulnerabilities in computer systems and releases tools to demonstrat...

Listen
Paul's Security Weekly TV
Pausing Processes with PowerShell with Mick Douglas, SANS - Paul's Security Weekly #533 from 2017-10-15T09:00

Mick Douglas is a SANS instructor and the Managing Partner for InfoSec Innovations. He joins us to demonstrate pausing potentially malicious executables in PowerShell!

Full Show Notes: Listen

Paul's Security Weekly TV
Splunk, ForeScout, Carbon Black, and ManageEngine - Enterprise Security Weekly #65 from 2017-10-14T09:00

Splunk goes shopping, ForeScout joins forces with an endpoint vendor, Carbon Black makes an announcement, new ManageEngine integrations, new Microsoft security features, and more enterprise news...

Listen
Paul's Security Weekly TV
Cloud Security (SaaS) - Enterprise Security Weekly #65 from 2017-10-13T09:00

Securing the cloud is all the rage these days. So many vendors are now offering services in this area, and rightfully so, as getting a handle on the security of SaaS applications is no small cho...

Listen
Paul's Security Weekly TV
Social Capital, Slack, and Oracle - Startup Security Weekly #58 from 2017-10-12T09:00

Leveling the playing field for entrepreneurs, using storytelling to increase sales, online crowdfunding, and more. In the startup security news for the week, Slack and Oracle team up, ForeScout ...

Listen
Paul's Security Weekly TV
Elizabeth Lawler, CyberArk - Startup Security Weekly #58 from 2017-10-11T09:00

Elizabeth Lawler is the Vice President of DevOps Security at CyberArk. She co-founded Conjur, a devops security company, in 2011; it was acquired by CyberArk in May 2017. Elizabeth joins us for ...

Listen
Paul's Security Weekly TV
Kaspersky, White House, Russian Hackers, and Doug White - Hack Naked News #144 from 2017-10-10T21:15:52

Doug White and Jason Wood discuss Kaspersky, social security, Duqu 2.0, and the Equifax breach on this episode of Hack Naked News!

Full Show Notes: Listen

Paul's Security Weekly TV
Equifax, Google, Alex Stamos, and Kaspersky - Paul's Security Weekly #532 from 2017-10-10T09:00

New Gmail security, who to blame for the Equifax breach, three billion compromised Yahoo accounts, embarrassing encryption ignorance, and why is Alex Stamos hunting down Russian political ads on...

Listen
Paul's Security Weekly TV
Ran Levi, Podcast Israel Media - Paul's Security Weekly #532 from 2017-10-09T09:00

Ran Levi started Making History! Podcast in 2007, which has become the most successful podcast in Israel. He has authored three books on malware, science, and more.

Full Show Notes: Listen

Paul's Security Weekly TV
Don Pezet, ITProTV - Paul's Security Weekly #532 from 2017-10-08T09:00

Our good friend Don Pezet joins Paul, Doug, and Ran for a discussion on his background in security! Don is a Co-Founder and Host of ITProTV, a video IT training company based in central Florida....

Listen
Paul's Security Weekly TV
John McAfee, ShieldX, and Phishing Emails - Enterprise Security Weekly #64 from 2017-10-06T09:00

John McAfee finally reveals his hack-proof system, ShieldX and Webroot join forces, a biometrics company teams up with Honeywell, and what percentage of successful attacks are caused by phishing...

Listen
Paul's Security Weekly TV
Mary Chaney, ICMCP - Enterprise Security Weekly #64 from 2017-10-06T09:00

Mary Chaney is the CEO of MBS Information Security Consulting and the Vice President for the International Consortium of Minority Cybersecurity Professionals (ICMCP), working to achieve building...

Listen
Paul's Security Weekly TV
Leadership, Innovation, and Startup Success - Startup Security Weekly #57 from 2017-10-05T09:00

Paul and Michael talk about being a leader in the startup world. How to fund your business? They also enforce how important it is to take a sabbatical.

Full Show Notes: Listen

Paul's Security Weekly TV
Barrett Lyon, Neustar - Startup Security Weekly #57 from 2017-10-04T09:00

Barrett Lyon is the Vice President of Research and Development for the Neustar Security Solutions’ portfolio. He spearheads the development of innovative new products and solutions for the compa...

Listen
Paul's Security Weekly TV
ICANN, Duo Security, iPhone Hacking, and Whole Foods - Hack Naked News #143 from 2017-10-03T18:57:57

The internet isn’t ready for DNS sec, Netgear patches away, Whole Foods is the latest victim of a credit card breach, and more. Ferruh Mavituna and Sven Morgenroth of Netsparker join us to discu...

Listen
Paul's Security Weekly TV
#TrevorForget, PGP, Oracle, and Linux Kernel - Paul's Security Weekly #531 from 2017-10-03T09:00

Don't worry about PGP private key exposure, Signal taps up Intel's SGX for increased security, a two-year-old Linux Kernel issue resurfaces, Bill Gates's biggest mistake, Oracle patches away, an...

Listen
Paul's Security Weekly TV
Ed Skoudis, Counter Hack - Paul's Security Weekly #531 from 2017-10-02T04:00

Ed Skoudis is a SANS Faculty Fellow and the lead for the SANS Penetration Testing Curriculum. He has the rare ability to translate advanced technical knowledge into easy-to-master guidance. Ed r...

Listen
Paul's Security Weekly TV
Jim Nitterauer, AppRiver - Paul's Security Weekly #531 from 2017-10-01T09:00

Jim Nitterauer, CISSP is currently a Senior Security Specialist at AppRiver. He's well-versed in ethical hacking and penetration testing techniques. Jim joins us for a nostalgia-packed DNS discu...

Listen
Paul's Security Weekly TV
Topic: Network Security Architecture pt. 2 - Enterprise Security Weekly #63 from 2017-09-29T09:00

How do you control outbound egress filtering? What do you use NG firewalls for? Where do proxy servers fit into the mix? Paul and John discuss the ins and outs of network security architecture!<...

Listen
Paul's Security Weekly TV
Signal Sciences, Zscaler, and Google Cloud - Enterprise Security Weekly #63 from 2017-09-28T09:00

Google Cloud acquires Bitium, Ixia extends cloud visibility, Lacework announces Microsoft Windows Server support, Signal Sciences joins Splunk's Adaptive Response Initiative, and more enterprise...

Listen
Paul's Security Weekly TV
Equifax, iOS 11, Zero-day, and DDos threats - Hack Naked News #142 from 2017-09-26T19:34:49

Tracking cars, iOS 11 patches eight vulnerabilities, Equifax dumps their CEO, High Sierra gets slammed with a Zero-day, and more. Jason Wood of Paladin Security discusses an email DDos threat on...

Listen
Paul's Security Weekly TV
SecureAuth, Digital Shadows, and ThreatStack - Startup Security Weekly #56 from 2017-09-26T09:00

Building successful products, the most important startup question, and updates from McAfee, Slack, ThreatStack, JASK, and more startup security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Don Pezet and Tim Broom, ITProTV - Startup Security Weekly #56 from 2017-09-25T17:53:12

Michael talks with Don Pezet and Tim Broom of ITProTV about the art of learning and creating captivating educational and entertaining content!

Full Show Notes: Listen

Paul's Security Weekly TV
Equifax Breach Insights - Enterprise Security Weekly #62 from 2017-09-23T09:00

Paul and John discuss the Equifax breach and they make a lot of speculations about security risk and security leadership.

Full Show Notes: Listen

Paul's Security Weekly TV
CyberGRX, Riverbed, YARA Rules, and Palantir - Enterprise Security Weekly #62 from 2017-09-22T09:00

CyberGRX and BitSight join forces, Java vs. JavaScript, YARA rules explained, Riverbed teases an application networking offering, and more enterprise security news!

Full Show Notes: Listen

Paul's Security Weekly TV
CashShield, AppGuard, Securonix, and Startup Journeys - Startup Security Weekly #55 from 2017-09-21T09:00

Michael and Matt discuss attributes of a scalable business, founder struggles, how to grow your startup, and updates from AppGuard, Securonix, CashShield, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Jason Brvenik, NSS Labs - Startup Security Weekly #55 from 2017-09-20T09:00

Jason Brvenik of NSS Labs brings more than 20 years of experience in systems design, integration, and security for both commercial and open markets. He was most recently a Principal Engineer in ...

Listen
Paul's Security Weekly TV
Windows 10, Zerodium, Linus Torvalds, and Equifax - Paul's Security Weekly #530 from 2017-09-19T09:00

No excuses for Equifax, mixed reviews for Apple’s facial recognition, Adobe and Microsoft patch away, one MILLION dollars for Tor zero-days, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
VMware, CCleaner Malware, Equifax, and Rogue Wordpress - Hack Naked News #141 from 2017-09-18T18:48:24

CCleaner is distributing malware, rogue WordPress plugins, Equifax replaces key staff members, and more. Jason Wood of Paladin Security discusses malicious WordPress plugins on this episode of H...

Listen
Paul's Security Weekly TV
What It Takes To Attack an ICS with Mike Assante, SANS Institute - Paul's Security Weekly #530 from 2017-09-18T09:00

Mike Assante is the Director of Critical Infrastructure and ICS for the SANS Institute. He clears up the confusion of Dragonfly 2.0 and explains control systems and how those attacks work.

<...

Listen
Paul's Security Weekly TV
Ted Demopoulos, SANS Institute - Paul's Security Weekly #530 from 2017-09-17T09:00

Ted Demopoulos is a Senior SANS Instructor, a recipient of the Department of Defense Award of Excellence, and the author of Infosec Rock Star: How to Accelerate Your Career Because Geek Will Onl...

Listen
Paul's Security Weekly TV
Go Development Tools, ThreatQuotient, and Bay Dynamics - Enterprise Security Weekly #61 from 2017-09-16T09:00

Paul and Matt discuss Bay Dynamics and VMware joining forces, the confessions of an insecure coder, Flexera acquiring BDNA, and more enterprise security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tom Parker, Accenture - Enterprise Security Weekly #61 from 2017-09-15T09:00

Tom Parker is the Group Technology Officer of Accenture Security and a recognized thought leader in the security industry. He’s known for his research in adversary and threat profiling and softw...

Listen
Paul's Security Weekly TV
ForgeRock, Cybersecurity Investors, and Startup Journeys - Startup Security Weekly #54 from 2017-09-14T09:00

Paul and Michael talk about the startup stories and discuss their startup journeys.

Full Show Notes: https://wiki.securityweekly.co...

Listen
Paul's Security Weekly TV
Gary Golomb, Awake Security - Startup Security Weekly #54 from 2017-09-13T09:00

Gary is focused on helping Awake improve security craft as the company’s Chief SOC Whisperer. Prior to Awake, Gary was one of the first employees at Cylance. He was also a co-founder of Provents...

Listen
Paul's Security Weekly TV
September 12, 2017 - Hack Naked News #140 from 2017-09-12T19:03:16

Bypassing Windows 10 security software, Android is vulnerable (go figure), hacking syringe infusion pumps to deliver fatal doses, and more. Jason Wood of Paladin Security discusses iOS 11 on thi...

Listen
Paul's Security Weekly TV
Flaw in Apache, Wikileaks Unveils Project Protego, and Linux 4.13 - Paul's Security Weekly #529 from 2017-09-12T09:00

The nightmare that is patching IoT devices, essential bug bounty programs, controlling voice assistants, flaws in Apache Struts2, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Mobile Application Assessment with Chris Crowley, SANS Institute - Paul's Security Weekly #529 from 2017-09-11T09:00

Chris Crowley is a SANS instructor and independent consultant based in the Washington, D.C. area. Mr. Crowley overviews his approach to keeping mobile applications secure in this technical segme...

Listen
Paul's Security Weekly TV
Michele Jordan, Under the Oak Consulting - Paul's Security Weekly #529 from 2017-09-10T09:00

Michele Jordan is the Founder and Principal Consultant of Under the Oak Consulting. She has worked in IT and network security for over 35 years. Michele delves into her background in security, h...

Listen
Paul's Security Weekly TV
Topic: Network Security Architecture - Enterprise Security Weekly #60 from 2017-09-09T09:00

Don Pezet of ITProTV joins us to discuss network security architecture. How does it affect your enterprise? Secure networks closely depend on its performance, reliability, and security.

F...

Listen
Paul's Security Weekly TV
Threat Intelligence, Starting the Avalanche, and SealPath - Enterprise Security Weekly #60 from 2017-09-08T09:00

Threat Intelligence, starting the Avalanche, Sealpath and Boldon James partner on document security classification and protection, and Oracle injects AI into its IoT cloud portfolio.

Full...

Listen
Paul's Security Weekly TV
Matt Alderman, Startup Categories - Startup Security Weekly #53 from 2017-09-07T09:00

Paul, Michael, and Matt talk about categories in the startup industry. They differentiate the meaning of competition versus no competition and being stagnate in the startup world.

Full Sh...

Listen
Paul's Security Weekly TV
Facebook Watch Show, Qadium, and Forcepoint - Startup Security Weekly #52 from 2017-09-06T09:00

Changing your audience’s perceptions, improving sales efforts, letting your kids fail, and updates from Facebook, Juniper, Qadium, and more startup security news!

Full Show Notes: Listen

Paul's Security Weekly TV
September 5, 2017 - Hack Naked News #139 from 2017-09-05T19:12:29

AT&T customers at risk, WikiLeaks gets vandalized, catching hackers in the act, going to jail over VPNs, and more. Jason Wood of Paladin Security discusses wheeling and dealing malware on this e...

Listen
Paul's Security Weekly TV
FCC, The Fappening, and Boarding Passes - Paul's Security Weekly #528 from 2017-09-05T09:00

Are you sick of The Fappening yet? We're not! Larry and Dave have fun with boarding passes, hacking pacemakers, the FCC hosting your memes, and more information security news!

Full Show N...

Listen
Paul's Security Weekly TV
Dave Kennedy, DerbyCon 2017 Preview - Paul's Security Weekly #528 from 2017-09-04T09:00

Larry and Dave discuss the upcoming DerbyCon conference, shenanigans from past cons, and reiterate the mission that DerbyCon was founded around in the first place!

Full Show Notes: Listen

Paul's Security Weekly TV
Tech Segment: Kyle Wilhoit, DomainTools - Paul's Security Weekly #528 from 2017-09-03T09:00

Kyle Wilhoit is a Senior Security Researcher at DomainTools; he focuses on research DNS-related exploits, investigate current cyber threats, and exploration of attack origins and threat actors. ...

Listen
Paul's Security Weekly TV
Fortinet FortiGate, Tufin, Okta, and VMware - Enterprise Security Weekly #59 from 2017-09-02T21:00

Matt and Michael discuss JASK, Automox, and more vendors that have stood out to them in the realms of security operations and endpoint protection!

Full Show Notes: Listen

Paul's Security Weekly TV
Topic: Security Operations and Endpoint Protection - Enterprise Security Weekly #59 from 2017-09-02T09:00

Matt and Michael discuss JASK, Automox, and more vendors that have stood out to them in the realms of security operations and endpoint protection!

Full Show Notes: Listen

Paul's Security Weekly TV
Technical Segment: Enterprise Network Monitoring - Enterprise Security Weekly #59 from 2017-09-01T09:00

Paul asked our Twitter followers about their favorite open-source alternatives to Nagios for monitoring system and service availability, and we listened, of course! Hear Paul’s essential enterpr...

Listen
Paul's Security Weekly TV
Startup News - Startup Security Weekly #52 from 2017-08-31T09:00

In the startup and security notes of interest, 3 Cybersecurity Stocks to Buy Now. All that and more on this episode of Startup Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
De-Risking Risk - Startup Security Weekly #52 from 2017-08-30T09:00

Paul and Michael reiterate the message that Startup Security Weekly is about: innovation, business, and success in security. They explain the need to “de-risk risk” and how to differentiate the ...

Listen
Paul's Security Weekly TV
August 29, 2017 - Hack Naked News #138 from 2017-08-29T19:36:05

Sparring government agencies, Microsoft patches a patch of a patch, Intel chips and backdoors, SMS authentication begone, and more. Jason Wood of Paladin Security discusses scaling back data dem...

Listen
Paul's Security Weekly TV
Larry's Capture-the-Flag Scenario - Paul's Security Weekly #527 from 2017-08-29T09:00

Larry had a technical problem that he needed to solve. Larry demonstrates a new capture-the-flag scenario. Larry explains how to capture a particular wireless packet in the middle of all this no...

Listen
Paul's Security Weekly TV
Fappening 2017, Open AWS, Flipboard, and Bitcoin - Paul's Security Weekly #527 from 2017-08-28T09:00

More Celebrity Nude Photos Hacked and Leaked Online, A Company Offers $500,000 For Secure Messaging Apps Zero-Day Exploits, Beware of Windows/MacOS/Linux Virus Spreading Through Facebook Messeng...

Listen
Paul's Security Weekly TV
Richard Moulds, Whitewood Security - Paul's Security Weekly #527 from 2017-08-27T09:00

Richard Moulds is the General Manager of Whitewood Security. Whitewood aims to help its customers to take control of the generation of random numbers across their application infrastructure.

...

Listen
Paul's Security Weekly TV
Enterprise News - Enterprise Security Weekly #58 from 2017-08-26T21:00

Diving deep into threat intelligence, GeoGuard and Skyhook team up, securing mobile devices, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
Security Training: Developer Awareness - Enterprise Security Weekly #58 from 2017-08-26T09:00

John and Paul talk about low-hanging fruit, but try to determine if the enterprise is more secure because of your consulting on developer awareness. They help the enterprising company determine ...

Listen
Paul's Security Weekly TV
Technical Segment: Vulnerability Tracking & Reporting - Enterprise Security Weekly #58 from 2017-08-25T09:00

Paul and John talk about a program that would give you a feed on the vulnerabilities that were specific to the software that you were using. Do you think that is still viable to today? John and ...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #51 from 2017-08-24T09:00

How much your startup needs to raise, 6 steps to surviving 3 years, documenting failures, and updates from Dragos, Zingbox, and more startup news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tara Wheeler, Symantec - Startup Security Weekly #51 from 2017-08-23T09:00

Tarah Wheeler, entrepreneur and hacker extraordinaire, joins us to discuss her startup journey, some of the issues facing the security industry, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
August 22, 2017 - Hack Naked News #137 from 2017-08-22T19:39:58

Zero-days in PDF readers, updates to Debain Stretch, killer robots are coming, and more. Jason Wood of Paladin Security discusses sexually charged sonar-based attacks on this episode of Hack Nak...

Listen
Paul's Security Weekly TV
Airdrop, Rowhammer, and Profexor Goes Dark - Paul's Security Weekly #526 from 2017-08-22T09:00

More Chrome extensions have been compromised, disabling safety features in cars, being targeted via AirDrop, USB is less secure (go figure), and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Bypassing Input Filters with Sven Morgenroth, Netsparker - Paul's Security Weekly #526 from 2017-08-21T09:00

Your WAF is not safe! Sven Morgenroth, a Security Researcher at Netsparker, blows Paul’s mind with his ninja-esque input filter bypass skills in this technical segment!

Full Show Notes: <...

Listen
Paul's Security Weekly TV
Bryson Bort, GRIMM - Paul's Security Weekly #526 from 2017-08-20T09:00

Bryson Bort is the Founder and CEO of GRIMM, a Washington, D.C. based security engineering and consulting services company. Bryson delves in-depth into his entrepreneurship journey, the problems...

Listen
Paul's Security Weekly TV
Paul's IoC Enchanting Quadrants - Enterprise Security Weekly #57 from 2017-08-19T21:00

In an attempt to define some of the basic areas for collecting information relevant to potential attacks, Paul came up with 4 enchanted quadrants. They cover Endpoints, SIEM, Network and Threat ...

Listen
Paul's Security Weekly TV
Enterprise News - Enterprise Security Weekly #57 from 2017-08-19T09:00

Security in the public cloud, the pitfalls of formal education, advanced security for AWS, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
Mike Nichols, Endgame - Enterprise Security Weekly #57 from 2017-08-18T09:00

Mike Nichols, Director of Products at Endgame, joins us to discuss EDR, threat detection, and customer relations!

Full Show Notes: ...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #50 from 2017-08-17T09:00

How not to botch your pitch, why VCs love insurance, ten ways to preserve cash as a bootstrapped startup, and updates from OpenText, WatchGuard, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Black Hat Recap with Matt Alderman - Startup Security Weekly #50 from 2017-08-16T09:00

Matt joins Paul to recap the startups that caught their attention at the recent Black Hat conference in Las Vegas!

Startup Companies:

- Skyport Systems

- IntSights

- ...

Listen
Paul's Security Weekly TV
APT28, Gmail, Game of Thrones leak, and WannaCry - Hack Naked News #136 from 2017-08-15T21:23:08

Allowing terrible passwords, four arrested in Game of Thrones leak, using EternalBlue to attack hotel guests, and more. Don Pezet of ITProTV joins us to deliver expert commentary on this episode...

Listen
Paul's Security Weekly TV
Dropbox, BeyondTrust, Marcus Hutchins, and DEF CON - Paul's Security Weekly #525 from 2017-08-15T09:00

Mystery bug bounties, Marcus Hutchins pleads not guilty, a password guru regrets past advice, Dropbox and offline two-factor authentication, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Printer Hacking Adventures - Paul's Security Weekly #525 from 2017-08-14T09:00

Printer attacks have been around for some time. Paul describes some of the latest techniques and research into printer hacking, including capturing print jobs, manipulating print jobs and other ...

Listen
Paul's Security Weekly TV
Aram Jivanyan, BeSafe - Paul's Security Weekly #525 from 2017-08-13T09:00

Aram is the Founder and CEO of BeSafe (formerly Skycryptor), an encrypted cloud company that uses proxy re-encryption techniques to protect user data. He provides a demo on his techniques to ens...

Listen
Paul's Security Weekly TV
Security Policies and Procedures - Enterprise Security Weekly #56 from 2017-08-10T21:09:05

Paul and John talk about Security Policies and Procedures. They discuss the most fundamental parts of policies and procedures. It is the most difficult to implement, but the most important to st...

Listen
Paul's Security Weekly TV
Glenn Chisholm and Ben Johnson, Obsidian Security - Startup Security Weekly #49 from 2017-08-10T09:00

Glenn Chisholm and Ben Johnson are CEO and CTO of Obsidian Security, an enterprise hybrid-cloud security startup. As former founding team members of Cylance and Carbon Black, Glenn and Ben have ...

Listen
Paul's Security Weekly TV
WatchGuard, Riverbed Launches New Xirrus, and Cylance - Enterprise Security Weekly #56 from 2017-08-09T19:48:38

HashiCorp Vault brings disaster recover to security secrets management, Oracle joins SafeLogic to develop FIPS module for OpenSSL security, and Cylance bringing enterprise security platform tech...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #49 from 2017-08-09T09:00

How to keep your head without losing your heart, what aspiring founders need to know, supercharging sales, and how NOT to start a startup. Michael and Paul deliver updates from Callsign, Juvo, A...

Listen
Paul's Security Weekly TV
August 8, 2017 - Hack Naked News #135 from 2017-08-08T19:32:32

Shame on Disney, shooting down customer drones, flaws in solar panels, Chrome extensions spreading adware, and more. Doug White of Roger Williams University joins us to discuss hacking back on t...

Listen
Paul's Security Weekly TV
WannaCry, FBI Arrests Researcher, and Smart Guns - Paul's Security Weekly #524 from 2017-08-08T09:00

WannaCry's killswitch domain registrant is arrested, making infosec more inclusive, hacking 113-year-old subway signs, security standards for smart devices, and more security news!

Full S...

Listen
Paul's Security Weekly TV
VaporTrail with Larry Pesce and Galen Alderson, InGuardians - Paul's Security Weekly #524 from 2017-08-07T09:00

Larry and his intern, Galen Alderson, present a demo of their Vaportrail project! Galen shows us how to exfiltrate data from networks using broadcast FM radio and other inexpensive materials. Listen

Paul's Security Weekly TV
Danny Miller, Ericom Software - Paul's Security Weekly #524 from 2017-08-06T09:00

Danny Miller, the Director of Product Marketing at Ericom Software, joins us to discuss how enterprises can protect themselves by utilizing isolated browsing and other techniques!

Full Sh...

Listen
Paul's Security Weekly TV
Tech Segment: RITA, John Strand - Enterprise Security Weekly #55 from 2017-08-05T09:00

John Strand from Black Hills Information Security, does a tech segment on real intelligence threat analytics. How it works, how you can get it up and running, how easy it is to get started, and ...

Listen
Paul's Security Weekly TV
Ping Look, Optiv - Enterprise Security Weekly #55 from 2017-08-04T16:14:04

Ping Look serves as the Executive Advisor of security communications and awareness at Optiv. Ping joins us to discuss security awareness, business diversity, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Wandera, SOC, Qualys, and Forcepoint - Enterprise Security Weekly #55 from 2017-08-03T17:04:20

Building a SOC with limited resources, the top five barriers to implementation, Qualys is acquiring Nevis Networks, auditing your AWS security policies, and more enterprise news!

Full Sho...

Listen
Paul's Security Weekly TV
August 2, 2017 - Hack Naked News #134 from 2017-08-02T20:41:17

No more VPNs in Russia, hacking luxury cars, stolen Game of Thrones scripts, your Echo is spying on you, and more. Jason Wood of Paladin Security joins us to discuss Chrome plugin phishing attac...

Listen
Paul's Security Weekly TV
Ali Golshan, StackRox - Startup Security Weekly #48 from 2017-07-26T09:00

Learn about containers, Docker, CoreOS and more in this interview with Ali Golshan, the Co-founder & CTO of StackRox. We discuss security approaches to containers and microservices, real-world t...

Listen
Paul's Security Weekly TV
Bypassing Corporate Firewalls with Sven Morgenroth, Netsparker - Paul's Security Weekly #523 from 2017-07-24T09:00

Sven Morgenroth of Netsparker joins us to expound upon an original blog post on bypassing corporate firewalls and vulnerable web applications in this technical segment!

Full Show Notes: <...

Listen
Paul's Security Weekly TV
Javelin ADProtect vs. Microsoft ATA with Almog Ohayon - Paul's Security Weekly #523 from 2017-07-23T09:00

Almog Ohayon of Javelin Networks pits Javelin ADProtect against Microsoft ATA in an epic threat analytics showdown!

Full Show Notes: ...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #54 from 2017-07-22T21:00

Malwarebytes revamps their adware removal, Minerva Labs fights against ransomware, EdgeWave announces phishing detection and awareness, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tech Segment: Monitoring Infrastructure with Nagios - Enterprise Security Weekly #54 from 2017-07-22T09:00

Where do the lines blur between monitoring, configuration, and vulnerability management? What is the best way to monitor systems in an enterprise? How to you manage machine to machine trust? Ans...

Listen
Paul's Security Weekly TV
Thomas Fischer, Digital Guardian - Enterprise Security Weekly #54 from 2017-07-21T09:00

Get some in-depth information on GDPR from Thomas Fischer, a Global Security Advocate at Digital Guardian and Director of BSides London!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Startup Security Weekly #47 from 2017-07-20T09:00

ZeroFOX, Deep Instinct, Flashpoint, Symantec acquired Skycure for an undisclosed amount, RiskLens and Nok Nok Labs raised $8M series D.

Full Show Notes: Listen

Paul's Security Weekly TV
Ronnie Feldman, Learnings & Entertainments - Startup Security Weekly #47 from 2017-07-19T09:00

Ronnie Feldman is the President & Creative Director of Learnings & Entertainments, a network of comedians musicians, and writers that builds creative content to improve employee engagement, comm...

Listen
Paul's Security Weekly TV
July 18, 2017 - Hack Naked News #133 from 2017-07-19T09:00

Forgetting your Windows password, bidding farewell to SMS authentication, reviewing Black Hat USA 2017, Ubuntu Linux for Windows 10, and more. Jason Wood of Paladin Security joins us to discuss ...

Listen
Paul's Security Weekly TV
Windows Vulnerabilities, Dirty Radio Songs, and Prime Day - Paul's Security Weekly #522 from 2017-07-18T09:00

Russians on PornHub, dirty songs on the radio, Windows security protocol vulnerabilities, tomato plant security, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Hardening Software RNGs with Don Pezet, ITProTV - Paul's Security Weekly #522 from 2017-07-17T09:00

This is a random technical segment on implementing random number generators in Linux. Don shows us the ins and outs of the entropy pool, the different between /dev/random and /dev/urandom, and s...

Listen
Paul's Security Weekly TV
Joe Desimone, Endgame - Paul's Security Weekly #522 from 2017-07-16T09:00

Learn about "fileless" malware, threat actors, evading detection on the endpoint and more!

Joe Desimone is a Malware Researcher at Endgame. He focuses on tracking and countering APTs, rev...

Listen
Paul's Security Weekly TV
CI Level Automated Web Security - Enterprise Security Weekly #53 from 2017-07-15T09:00

Ferruh Mavituna of Netsparker joins us to discuss CI level automated web security!

Full Show Notes: https://wiki.securityweekly.com...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #53 from 2017-07-14T09:00

Suffering breaches from ex-employees, Tanium announces threat response, the SANS Institute's incident response survey results, and is cybersecurity getting harder?

Full Show Notes: Listen

Paul's Security Weekly TV
The Opportunity For Hardening Docker Containers - Enterprise Security Weekly #53 from 2017-07-13T09:00

If you are a security professional who has not taken the plunge into Docker, this segment is for you. Paul highlights some of the configuration options available for Docket containers and how yo...

Listen
Paul's Security Weekly TV
July 11, 2017 - Hack Naked News #132 from 2017-07-11T19:17:48

Solving artificial stupidity, Petya’s decryption key is released, sleeping with the enemy, burner laptops for DEF CON, and more. Jason Wood of Paladin Security joins us to discuss the FTC shutti...

Listen
Paul's Security Weekly TV
James Jardine, Jardine Software Inc. - Startup Security Weekly #46 from 2017-07-11T09:00

James Jardine is the CEO of Jardine Software and a former SANS Institute author and instructor. James possesses over 15 years of development and application security experience.

Full Show...

Listen
Paul's Security Weekly TV
Cloudflare, Upstream, and Symantec - Startup Security Weekly #46 from 2017-07-11T09:00

The hells of being a founder, killing projects before they kill you, intellectual property 101, and invisible unicorns. Michael and Paul give updates on Auth0, Upstream, Palo Alto Networks, Syma...

Listen
Paul's Security Weekly TV
Tim Helming, DomainTools - Paul's Security Weekly #521 from 2017-07-11T09:00

Tim Helming joins us to talk about all things related to domains, including luxury domain abuses, the security value of the whois database and more!

Full Show Notes: Listen

Paul's Security Weekly TV
Demystifying the Art of Hunting with Paul Ewing, Endgame - Paul's Security Weekly #521 from 2017-07-10T20:39:53

Paul Ewing from Endgame talks about the different types of threat hunting (network, host and logs) and the pros and cons of each!

Full Show Notes: Listen

Paul's Security Weekly TV
Google Patches, Wordpress, and GnuPG - Paul's Security Weekly #521 from 2017-07-10T09:00

How to hire infosec professionals, patching automation code, hijacked Android devices, Bitdefender support for Mac, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Network Hardening Using Egress Filtering - Enterprise Security Weekly #52 from 2017-07-07T09:00

Paul and Doug talk about the need for and the pitfalls of Egress Filtering in your enterprise network. And sweaty lawyers.

Full Show Notes: Listen

Paul's Security Weekly TV
News - Enterprise Security Weekly #52 from 2017-07-06T09:00

Fortinet preps for a next-gen firewall, Samsung no longer males printers, beware of Cisco training, using the right switches, Kubernetes, requirements and testing, to update or not to update and...

Listen
Paul's Security Weekly TV
Linux hacking, Petya, and Windows - Paul's Security Weekly #520 from 2017-07-04T09:00

Separating the hacked and the paranoid, remote Linux hacking, Petya goes postal at FedEx, today’s mainstream hacktivism tools, and why choosing Windows should get you fired!

Full Show Not...

Listen
Paul's Security Weekly TV
Domain Admin in Active Directory, Guy Franco - Paul's Security Weekly #520 from 2017-07-03T09:00

Guy came on the show and gave a live demo on how to become Domain Admin in an Active Directory environment, and keep those privileges for 20+ years. Guys shows us how to abuse service accounts t...

Listen
Paul's Security Weekly TV
Moses Hernandez, Cisco Systems - Paul's Security Weekly #520 from 2017-07-02T09:00

Moses returns to the show to discuss his background in technology and security (which is eerily similar to Paul's!). The crew then got into a deep discussion of the history of many different tec...

Listen
Paul's Security Weekly TV
Tech Segment: Managing AWS Cloud Resources, Apollo Clark - Enterprise Security Weekly #51 from 2017-07-01T21:00

Apollo Clark discusses the tools and techniques your team can use to manage, monitor and tune your enterprise AWS deployment.

Full Show Notes: Listen

Paul's Security Weekly TV
Docker Security In The Enterprise - Enterprise Security Weekly #51 from 2017-07-01T09:00

Love it or hate it, Docker (and containers) are here to stay. Embrace change in this segment where Paul and Apollo discuss using Docker in the enterprise. We cover security considerations, deplo...

Listen
Paul's Security Weekly TV
Microsoft, Carbon Black, and Office 365 - Enterprise Security Weekly #51 from 2017-06-30T09:00

Microsoft buys another company, to patch (or not), the shift in the cybersecurity battleground, Carbon Black’s Petya assessment, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
Amazon, Cybereason, and GreatHorn - Startup Security Weekly #45 from 2017-06-29T09:00

Why most startups fail, conference season tips, the question you need to ask before solving any problem, and when should you hit pause? Michael and Paul deliver updates from GreatHorn, Cybereaso...

Listen
Paul's Security Weekly TV
June 28, 2017 - Hack Naked News #131 from 2017-06-28T19:53:44

DoD networks have been compromised, the Shadow Brokers continue their exploits, a Pennsylvania healthcare system gets hit with Petya, and more. Jason Wood of Paladin Security joins us to discuss...

Listen
Paul's Security Weekly TV
Fred Kneip, CyberGRX - Startup Security Weekly #45 from 2017-06-28T09:00

Fred Kneip is the Chief Executive Officer for CyberGRX. Fred has served in several senior management roles, and has worked as an investor with two later-stage private equity investment firms. Fr...

Listen
Paul's Security Weekly TV
Bye Bye Chrome, GhostHook, and Cisco - Paul's Security Weekly #519 from 2017-06-27T09:00

Why Firefox is superior, spies in Mexico, WannaCry shuts down a car plant, Cisco patches critical vulnerabilities, hacking air-gapped networks, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Reverse Analyzing Attacks for Detection, Justin Henderson - Paul's Security Weekly #519 from 2017-06-26T09:00

Learn how to use Windows Event Logs to catch attackers in your network, including domain admin group enumeration and mimikatz attacks! Justin Henderson (@SecurityMapper) categorizes these techni...

Listen
Paul's Security Weekly TV
Eric Conrad, SANS - Paul's Security Weekly #519 from 2017-06-25T09:00

Eric Conrad comes into the studio to talk about a groundbreaking new CTF aimed at the defenders and how to become a SANS instructor. A healthy dose of UNIX/Linux nerd talk and how to give effect...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #50 from 2017-06-24T09:00

Five ways to maximize your IT training, pocket-sized printing, 30 years of evasion techniques, Ixia teases advanced visibility solutions, and more enterprise security news!

Full Show Note...

Listen
Paul's Security Weekly TV
Brian Ventura and Ted Gary - Enterprise Security Weekly #50 from 2017-06-23T09:00

Brian Ventura is a SANS Instructor and infosec architect, while Ted Gary serves as the Product Marketing Manager at Tenable.

Full Show Notes: Listen

Paul's Security Weekly TV
Sqrrl, Hexadite, and SafeBreach - Startup Security Weekly #44 from 2017-06-22T09:00

Negotiation mistakes that are hurting your deals, hiring re-founders, and does VC fund differentiation really matter? Michael and Matt deliver updates from Hexadite, Amazon, Sqrrl, SafeBreach, a...

Listen
Paul's Security Weekly TV
Tarun Desikan, Banyan - Startup Security Weekly #44 from 2017-06-21T09:00

Tarun Desikan is the Co-Founder and CEO of Banyan, a container and microservices security company based in San Francisco. Tarun Joins Michael and Matt to discuss Containerization, biometrics, ad...

Listen
Paul's Security Weekly TV
UPnP, WikiLeaks, and Microsoft to Removes SMBv1 Protocol - Hack Naked News #130 from 2017-06-20T21:00

Hacking military phone systems, IoT malware activity doubles, more WikiLeaks dumps, decade-old bugs, and more. Jason Wood of Paladin Security joins us to discuss the erosion of ISP privacy rules...

Listen
Paul's Security Weekly TV
Iot is broken and 1 Million Exposed Endpoints - Paul's Security Weekly #518 from 2017-06-20T09:00

One MILLION endpoints, WannaCry is linked to North Korea, IoT is broken (what's new?),inside a porn-pimping spam botnet, fixing Windows Defender, and more security news!

Full Show Notes: ...

Listen
Paul's Security Weekly TV
ProxyCannon with Carrie Roberts, Black Hills Information Security - Paul's Security Weekly #518 from 2017-06-19T10:00

Carrie Roberts of Black Hills Information Security joins us to show hot to use Burp and ProxyCannon to Prevent IP blacklisting while password spraying in this technical segment!

Full Show...

Listen
Paul's Security Weekly TV
Trey Forgety, NENA - Paul's Security Weekly #518 from 2017-06-18T10:00

Trey Forgety is the Director of Government Affairs and Information Security Issues at the National Emergency Number Association. He worked with the White House to develop policy for a nationwide...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #49 from 2017-06-17T09:00

Carbon Black releases Cb Response 6.1, what to ask yourself before committing to a cybersecurity vendor, Malwarebytes replaces antivirus with endpoint protection, and more enterprise security ne...

Listen
Paul's Security Weekly TV
Malware: Endpoint Defense - Enterprise Security Weekly #49 from 2017-06-16T09:00

*Should EDR be installed on every system? Servers too? All clients?

*How important is the configuration of EDR?

*What should your goals be for defense: know malware? unknown malwar...

Listen
Paul's Security Weekly TV
Yubikey, CybelAngel, and Netskope - Startup Security Weekly #43 from 2017-06-15T09:00

Fundraising updates from Yubikey, CybelAngel, Netskope, Illumio, Krypto.co, and more startup new and journey updates!

Full Show Notes: Listen

Paul's Security Weekly TV
June 13, 2017 - Hack Naked News #129 from 2017-06-13T19:41:53

How to delete an entire company, GameStop suffers a breach, Macs do get viruses, Docker released LinuxKit, and more. Jason Wood of Paladin Security joins us to discuss the military beefing up th...

Listen
Paul's Security Weekly TV
NSA Contractor Arrested, PPT Malware - Paul's Security Weekly #517 from 2017-06-13T09:00

• FBI Arrests NSA Contractor for Leaking Secrets
• getsploit: Search & Download Exploits!
• Some non-lessons from WannaCry
• IDG Contributor Network: Top 5 InfoSec concerns for...

Listen
Paul's Security Weekly TV
Detecting The Empire's Death Star Attack - Paul's Security Weekly #517 from 2017-06-12T21:00

byt3bl33d3r recently released "DeathStar", which use Powershell Empire's API to automatically obtain Domain Admin privileges in an Active Directory environment with the Click of a button. Some m...

Listen
Paul's Security Weekly TV
Graham Cluley - Paul's Security Weekly #517 from 2017-06-12T16:36:43

Graham Cluley is an award-winning security blogger, researcher and public speaker. In this interview, we discuss ransomware, stealing content, the motivations of attackers, IoT, and more!

Listen
Paul's Security Weekly TV
Building an Internal Penetration Testing Team - Enterprise Security Weekly #48 from 2017-06-10T09:00

What should we consider while building an internal penetration testing team? Would you still need external pen tests? Paul and John discuss the pros and cons!

Full Show Notes: Listen

Paul's Security Weekly TV
DUO New Zealand and McAfee join forces - Enterprise Security Weekly #48 from 2017-06-09T09:00

Automating all the things, Juniper Networks opens a software-defined security ecosystem, millions of devices are running out-of-date systems, DUO New Zealand and McAfee join forces, and more ent...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #42 from 2017-06-08T09:00

Why You Should Think Twice About Listening to Business Gurus (There's no one-size-fits-all approach to innovation), A tech investor analyzed his 5000 monthly emails and explained how startups ca...

Listen
Paul's Security Weekly TV
Startup Advice with Matt Alderman - Startup Security Weekly #42 from 2017-06-07T09:00

Matt is the former VP of Strategy for Tenable where hew was responsible for developing strategies to enter new markets, develop new products and improve existing products, including the new Tena...

Listen
Paul's Security Weekly TV
June 6, 2017 - Hack Naked News #128 from 2017-06-06T20:49:27

Exploiting Windows 10, mimicking Twitter users, vulnerabilities in Subarus, security issues surrounding virtual personal assistants, and more. Jason Wood of Paladin Security joins us to discuss ...

Listen
Paul's Security Weekly TV
Security For Small Business - Paul's Security Weekly #516 from 2017-06-04T09:00

Don Pezet from ITPro.TV joins us on the show to help us identify security challenges and solutions for small business/mid-market. Backups are key, as are ease of use and support. The most import...

Listen
Paul's Security Weekly TV
Exploit, Carbon Black, and IAM Best Practices - Enterprise Security Weekly #47 from 2017-06-03T09:00

The power of an exploit, Carbon Black's open letter to Cylance, Viavi Solutions Introduces Scalable RF Monitoring for Heterogeneous Networks, and 13 AWS IAM Best Practices for Security and Compl...

Listen
Paul's Security Weekly TV
Containers and Security - Enterprise Security Weekly #47 from 2017-06-02T09:00

Containers are here to stay. While there is some resistance to this movement, Devops can help improve efficiency and security. For the first time security has a seat at the table when discussing...

Listen
Paul's Security Weekly TV
Don Pezet and Tim Broom, ITPro.TV - Startup Security Weekly #41 from 2017-06-01T09:00

Don Pezet has been working in the IT industry for over 18 years. In addition to working with the technologies, he has also been training others for over 12 years. He is a certified trainer with ...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #515 from 2017-05-31T20:00

Gravityscan is keeping WordPress sites safe, WiFi to see through walls, Dodged a bullet and stepped in front of another one, Twitter Flaw Allowed You To Tweet From Any Account, and Latest Cb Def...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #41 from 2017-05-31T09:00

Find out what the key to growth is, Bain Capital Ventures to fund 'angel' investors, Tanium raised $100M, and find out where Michael and Paul are in their startup journeys!

Full Show Note...

Listen
Paul's Security Weekly TV
May 30, 2017 - Hack Naked News #127 from 2017-05-30T20:10:59

Thousands of known bugs found in pacemaker code, Chipotle's sale terminals get hacked, Microsoft patches another critical malware protection engine flaw, popular Radius server expoitable with TL...

Listen
Paul's Security Weekly TV
Tech Segment: How Compromise Happens: Active Directory is Vulnerable - Paul's Security Weekly #515 from 2017-05-30T16:46:26

Almog Ohayon from Javelin Networks gives a demo on how compromises happen and counteract them.

Full Show Notes: https://wiki.security...

Listen
Paul's Security Weekly TV
Branden Williams - Paul's Security Weekly #515 from 2017-05-28T09:00

Dr. Branden R. Williams has twenty years of experience in business, technology, and information security as a consultant, leader, and an executive. Branden has world for well known Information S...

Listen
Paul's Security Weekly TV
Atif Ghauri, Herjavec Group - Enterprise Security Weekly #46 from 2017-05-27T09:00

Atif Ghauri is the CTO for Herjavec Group USA and comes on the show to talk about SEIM, EUBA and how to build a relationship with your MSSP! Atif has over 15 years of experience in technology st...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #46 from 2017-05-26T09:00

Stopping insider threats with machine learning, the importance of inspecting encrypted traffic, performance and security relations, and what to do if you're SOC is overwhelmed with too many SEIM...

Listen
Paul's Security Weekly TV
Startup Articles and Discussion - Startup Security Weekly #40 from 2017-05-25T09:00

How to come up with worthy startup ideas, why your explainer video matters, and what does “Minimum Viable Product” actually mean, anyway?

Full Show Notes: Listen

Paul's Security Weekly TV
Startup Security Notes of Interest - Startup Security Weekly #40 from 2017-05-24T09:00

Paul and Michael give updates on their startup journeys and report on Karamba, Crowdstrike, Wandera, and more on this episode!

Full Show Notes: Listen

Paul's Security Weekly TV
May 23, 2017 - Hack Naked News #126 from 2017-05-23T20:09:21

Exploiting media players using subtitles, Netgear is recording your IP and MAC address, net neutrality is on the chopping block, Yahoobleed attack, and EternalRocks. Jason Wood of Paladin Securi...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #514 from 2017-05-23T09:00

WordPress announces a bug bounty program, stealing voice prints, hacking Mar-a-Lago, XP PCs dodge WannaCry’s ransom, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tech Segment: Disabling SMBv1 - Paul's Security Weekly #514 from 2017-05-22T09:00

Microsoft has advised that customers disable SMBv1. This tech segment walks you through the steps required to do so on all Windows platforms, the pitfalls, and scanning for non-domain computers ...

Listen
Paul's Security Weekly TV
Joel Scambray, NCC Group - Paul's Security Weekly #514 from 2017-05-21T09:00

Widely recognized as Co-Author of the Hacking Exposed book series, Joel has worked/consulted for companies like Foundstone (co-founder), Microsoft, Amazon, Costco, Softcard, and Ernst & Young. J...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #45 from 2017-05-19T09:00

Identropy and Exabeam team up, five pitfalls to avoid during a CASB evaluation, FirstWave partners with Fortinet, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Startup Security Weekly #39 from 2017-05-18T09:00

Why companies aren’t startups, how to be insanely well-connected, CyberArk acquires Conjur, and more startup news!

Full Show Notes: Listen

Paul's Security Weekly TV
May 16, 2017 - Hack Naked News #125 from 2017-05-17T21:00

Netflix blocks rooted devices, HP laptops are logging your keystrokes, Google Chrome is vulnerable, and more. Jason Wood of Paladin Security joins us to discuss a global tech support scheme on t...

Listen
Paul's Security Weekly TV
Bonnie Halper, StartupOneStop - Startup Security Weekly #39 from 2017-05-17T09:00

Bonnie Halper is an-award winning writer who has been involved in tech since 1994. In 2009, she founded StartupOneStop, an opinionated newsletter covering the tech industry.

Full Show Not...

Listen
Paul's Security Weekly TV
Amanda Rousseau, Endgame - Hack Naked News #124 from 2017-05-16T21:00

Amanda Rousseau of Endgame joins us to discuss ransomware and malware protection on this episode of Hack Naked News!

Full Show Notes: Listen

Paul's Security Weekly TV
Steve Lipner, SAFECode - Paul's Security Weekly #513 from 2017-05-16T09:00

Steve Lipner is the Executive Director of SAFECode, a non-profit organization dedicated to increasing trust in ICT products and services. He retired in 2015 as Partner Director of Software Secur...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #513 from 2017-05-15T09:00

Avast blocks the entire internet (again), over 120,000 cameras are vulnerable to a new botnet, WordPress malware, stronger authentication on government sites, and more security news!

Full...

Listen
Paul's Security Weekly TV
Tech Segment: Roi Abutbul and Guy Franco, Javelin Networks - Paul's Security Weekly #513 from 2017-05-14T21:00

Roi Abutbul and Guy Franco of Javelin Networks explain how to protect your active directory and deceive attackers in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Enterprise Security Weekly #44 from 2017-05-13T21:00

VMware falls out with Tanium, machine learning at Invincea, the war on legacy IT, Cisco Cloudlock releases an apps firewall, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
Ryan Hays, TBG Security - Enterprise Security Weekly #44 from 2017-05-13T09:00

Ryan Hays is the Director of Security Engineering at TBG Security. During his career, he has worked with a multitude of Fortune 500 and 1000 companies, along with various U.S. Government Intelli...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #38 from 2017-05-12T09:00

Why your startup doesn’t necessarily need early stage funding, Cisco acquires Viptela, the risks of startup debt, and why do chefs and soldiers make the best product managers?

Full Show N...

Listen
Paul's Security Weekly TV
Public File Metadata Analysis - Tradecraft Security Weekly #1 from 2017-05-11T13:18:02

Public File Metadata Analysis with PowerMeta - It is very common for organizations to post files (docx, pdf, xlsx, etc.) to publicly available websites on the Internet. Often times these organiz...

Listen
Paul's Security Weekly TV
Steven Grossman, Bay Dynamics - Startup Security Weekly #38 from 2017-05-11T09:00

Steven has over 20 years of management consulting and industry experience working with technology, security and business executives. At Bay Dynamics, Steven is responsible for driving strategy a...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #512 from 2017-05-10T09:00

Phishing attacks in Google Docs, GE fixes its Smart Grid, hackers remotely control robots, and who is publishing NSA and CIA secrets (and why)?

Full Show Notes: Listen

Paul's Security Weekly TV
May 9, 2017 - Hack Naked News #123 from 2017-05-09T20:05:13

Phishing in Google’s waters, HandBrake has been compromised, Dell releases patches galore, and more. Jason Wood of Paladin Security delivers expert commentary on how ultrasonic beacons can track...

Listen
Paul's Security Weekly TV
Tech Segment: Second Order Attacks with Ferruh Mavituna, Netsparker Paul's Security Weekly #512 from 2017-05-09T09:00

Ferruh Mavituna of Netsparker gives a demo on exploiting application vulnerabilities and second order attacks in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Javvad Malik, AlienVault - Paul's Security Weekly #512 from 2017-05-07T09:00

Javvad Malik is a Security Advocate at AlienVault, a blogger event speaker, and industry commentator. Prior to joining AlienVault, Javvad was a Senior Analyst at 451’s Enterprise Security Practi...

Listen
Paul's Security Weekly TV
Deception Technologies and Honeypots - Enterprise Security Weekly #43 from 2017-05-06T09:00

Don Pezet of ITPro.TV joins Paul and John to discuss deception technologies and honeypots in this episode of Enterprise Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Enterprise Security Weekly #43 from 2017-05-05T17:42:13

Duo launches its MSP program, Fortscale beefs up its partner programs, integrating threat intelligence into your operations, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Enterprise Security Weekly #42 from 2017-05-04T09:00

LockPath and SailPoint join forces, Skyhigh Networks announces a cloud security partnership, Acalvio is building deception farms, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
Building a Bug Bounty Program - Enterprise Security Weekly #42 from 2017-05-04T09:00

Paul, John, and Michael discuss the ins and outs of building a bug bounty program in this episode of Enterprise Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
Mike Simon, Cryptonite NXT - Startup Security Weekly #37 from 2017-05-03T09:00

Mike Simon is the President and CEO of Cryptonite NTX, a company that aims to give businesses the upper hand against attackers. Mike is described as “an entrepreneur that enjoys the opportunity ...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #37 from 2017-05-03T09:00

How to drive maximum performance in your business, 6 reasons your small business will fail, how McAfee is securing its future, and how well do you know the language of startups?

Full Show...

Listen
Paul's Security Weekly TV
May 2, 2017 - Hack Naked News #122 from 2017-05-02T20:03:20

Microsoft VB macro barriers have been penetrated, the website that doesn’t let you change your password, IBM flash drives have malware, and more. Jason Wood of Paladin Security joins us to deliv...

Listen
Paul's Security Weekly TV
Mimi Herrmann, Taylor and Francis - Paul's Security Weekly #511 from 2017-05-02T09:00

Mimi Herrmann is a Network Security Engineer based in the Washington, D.C. area. She is also a contributing author and peer reviewer for Taylor and Francis. Mimi has been in security for more th...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #511 from 2017-05-01T09:00

Advances in ad blocking, PGP hijacking, the lack of security talent in the healthcare industry, and more security news!

Show Notes: Listen

Paul's Security Weekly TV
Tech Segment: Staying Secure at Hacker Conferences, Part 2 - Paul's Security Weekly #511 from 2017-04-30T09:00

Back by popular demand, Paul drops more conference security knowledge in this technical segment!

Show Notes: http://wik...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #36 from 2017-04-29T09:00

The number one trait of successful entrepreneurs, SoftBank is investing, the “store of the future,” Jeff Bezos’s annual letter, and more startup news!

Full Show Notes: Listen

Paul's Security Weekly TV
Roger Courville, EventBuilder - Startup Security Weekly #36 from 2017-04-28T09:00

Roger Courville is the Chief Content Officer of EventBuilder, a professional services firm that specializes in webinars, webcasts, virtual classes, and virtual events. Roger has been involved in...

Listen
Paul's Security Weekly TV
April 27, 2017 - Hack Naked News #121 from 2017-04-27T19:43:57

Windows boxes are getting pwned, vulnerabilities in SugarCRM, Ashley Madison is back in the news, and more. Jason Wood of Paladin Security joins us to deliver expert commentary on hacking cars w...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #510 from 2017-04-27T09:00

Hacking SEIMs, hijacking routers, Oracle’s recent path, the FBI can finally find hackers that don’t smoke weed, and more security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Tech Segment: Staying Secure at Hacker Conferences - Paul's Security Weekly #510 from 2017-04-26T09:00

Paul gives his top 10 tips on keeping your devices safe at hacker cons in this technical segment!

Full Show Notes: http...

Listen
Paul's Security Weekly TV
Philip Zimmerman, Silent Circle - Paul's Security Weekly #510 from 2017-04-25T09:00

Phil Zimmermann is the creator of Pretty Good Privacy (PGP), the most widely used email encryption software in the world. Phil is also a Co-Founder of Silent Circle, a provider of secure communi...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #41 from 2017-04-24T09:00

In the news, evaluating endpoint protection, trouble at Tanium, micro-virtualization, spying on your users, NAC meets anti-malware, CASBs and Facebook.

Full Show Notes: Listen

Paul's Security Weekly TV
Rami Essaid, Distill Networks - Enterprise Security Weekly #41 from 2017-04-23T09:00

Rami Essaid is the CEO and Co-Founder of Distil Networks. With over 15 years of experience in telecommunications, network security, and cloud infrastructure management, Rami advises enterprise c...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #35 from 2017-04-22T09:00

How to close investors, launching startups in crowded markets, and more in this week’s Startup News!

Full Show Notes: Listen

Paul's Security Weekly TV
Jeff Man - Startup Security Weekly #35 from 2017-04-21T09:00

Jeff joins Paul in studio with Michael (on the beach) to talk about the buyer perspective in the startup ecosystem.

Full Show Notes: Listen

Paul's Security Weekly TV
Security News - Paul's Security Weekly #509 from 2017-04-20T09:00

Free health apps are selling your data, SAP’s TREX exposes HANA and NetWeaver, Microsoft patches another Word bug, your phone PIN is at risk, and more in this week’s security news!

Full S...

Listen
Paul's Security Weekly TV
Tech Segment: Basics of Abusing WMI Events - Paul's Security Weekly #509 from 2017-04-19T09:00

Our very own Carlos Perez demonstrates the basics of WMI events and how to abuse them in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly TV
April 18, 2017 - Hack Naked News #120 from 2017-04-18T21:18:16

Doug White and Jason Wood discuss Cyberpatriot, Shadow Brokers, and more on this episode of Hack Naked News!

Full Show Notes: Listen

Paul's Security Weekly TV
Alex Horan, Onapsis - Paul's Security Weekly #509 from 2017-04-18T09:00

We welcome Alex Horan back to the show! Alex is the Director of Product Management at Onapsis. He has experience in startup-based project management, meeting with customers, prospects, and analy...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #40 from 2017-04-17T09:00

Virtualization-based security, the road to Twistlock 2.0, Trend Micro embraces machine learning, and more enterprise news!

Full Show Notes: Listen

Paul's Security Weekly TV
Gabriel Gumbs, STEALTHbits - Enterprise Security Weekly #40 from 2017-04-16T09:00

Gabriel Gumbs is the VP of Product Strategy at STEALTHbits Technologies. With a 16-year tenure in cybersecurity, Gabriel spent more than a decade as a security practitioner at companies like Pfi...

Listen
Paul's Security Weekly TV
How to Handle a Breach: Public Disclosure - Enterprise Security Weekly #39 from 2017-04-15T09:00

Stepping inside the room, Dr. Doom, prepare for the boom, Bam! Its Dr. Doug White! Our topic for discussion today is how to handle public breach disclosure.

Full Show Notes: Listen

Paul's Security Weekly TV
News - Enterprise Security Weekly #39 from 2017-04-14T09:00

Cisco has new certs, 5 things to consider when building an SOC, CounterTack announces new data loss prevention measures, and more!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Startup Security Weekly #34 from 2017-04-13T09:00

5 reasons to slow or stop the growth of your business, Walmart is working with startups, Cloudera goes public, and more in this week’s Startup News!

Full Show Notes: Listen

Paul's Security Weekly TV
James Gellert, RapidRatings - Startup Security Weekly #34 from 2017-04-12T09:00

James Gellert is the Chairman & CEO of RapidRatings, a provider of quantitative financial health ratings and risk management solutions. He was previously the Managing Partner of Howland Partners...

Listen
Paul's Security Weekly TV
April 11, 2017 - Hack Naked News #119 from 2017-04-11T19:16:57

Signal patches vulnerabilities, hackers target tornado sirens in Texas, a Microsoft Word 0-day is being used to spread malware, and more. Don Pezet of ITPro.TV offers his expert commentary on th...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #508 from 2017-04-11T09:00

Android ransomware bypasses all AV programs, McAfee gets a fresh start, the CIA and WikiLeaks saga continues, and Wi-Fi sex toys are vulnerable (again) in this week’s Security News!

Full ...

Listen
Paul's Security Weekly TV
Tech Segment: Jeff's Trip to IBM InterConnect - Paul's Security Weekly #508 from 2017-04-10T09:00

Our very own Jeff Man made a trip to the IBM InterConnect Conference on behalf of Security Weekly. Learn about his experience in this segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Anna Manley, Manley Law Inc. - Paul's Security Weekly #508 from 2017-04-09T09:00

Anna Manley is an internet and privacy lawyer based in Nova Scotia, Canada. She is the principal of Manley Law Inc. and founder of Advocate Cognitive Technologies Inc. She also writes a blog cov...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #33 from 2017-04-06T09:00

How to hire remote employees effectively, the periodic table of security startups, why no business is bulletproof, and more in this week’s Startup News!

Full Show Notes: Listen

Paul's Security Weekly TV
Ira Winkler, Secure Mentem - Startup Security Weekly #33 from 2017-04-05T09:00

Ira Winkler is the Author and President of Secure Mentem, a company dedicated to the human aspects of security. He consults to some of the largest corporations in the world. Before joining the p...

Listen
Paul's Security Weekly TV
April 4, 2017 - Hack Naked News #118 from 2017-04-04T20:49:23

Doug White fills in in the studio while the awesome, shear naked power of Jason Wood. Jason fills the airwaves. Anonymous FTP, The Russians, Skynet Activates in Connecticut, and the return of Va...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #507 from 2017-04-04T09:00

The CIA hacks Cisco, Trump extends an executive order on cybersecurity, ISP privacy rules are being repealed, and why was 2016 a record year for vulnerabilities?

Full Show Notes: Listen

Paul's Security Weekly TV
Technical Segment: Blocking Ads and Malware With Pi-hole In The Cloud - Paul's Security Weekly #507 from 2017-04-03T09:00

Paul shows you how to use Raspberry Pi’s Pi-hole to block ads and malware in the cloud in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Brad Antoniewicz, OpenDNS/BSides NYC - Paul's Security Weekly #507 from 2017-04-02T09:00

Brad Antoniewicz works in Cisco Umbrella’s security research group. He founded the NYC branch of Security BSides. Brad is also a contributing author to both the Hacking Exposed and Hacking Expos...

Listen
Paul's Security Weekly TV
Configuration Management - Enterprise Security Weekly #38 from 2017-04-01T09:00

Paul and John discuss configuration management and why you probably don't need 0-day defenses, threat intelligence, or AI-powered SOCs!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Enterprise Security Weekly #38 from 2017-03-31T09:00

enSilo adds NGAV support, the cure for infectious malware, and what percentage of malware attacks are 0-days?

Full Show Notes: Listen

Paul's Security Weekly TV
March 28, 2017 - Hack Naked News #117 from 2017-03-28T19:09:36

LastPass fixes vulnerabilities, Instagram adds 2FA, scammers target iOS porn viewers, and more. Israel Barak of Cybereason joins us to deliver expert commentary. Stay tuned!

Full Show Not...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #32 from 2017-03-28T09:00

5 challenges most entrepreneurs don’t anticipate, 6 ways marketing can shrink the sales cycle, what you need to know about raising seed funding, and more in this week’s Startup News!

Full...

Listen
Paul's Security Weekly TV
Kevin O'Brien, GreatHorn - Startup Security Weekly #32 from 2017-03-27T21:18:01

Kevin is the CEO and Co-Founder of GreatHorn. He has an extensive background in the cybersecurity industry that began in the late 1990s with the seminal security firm @stake (now Symantec). Kevi...

Listen
Paul's Security Weekly TV
Tech Segment: Arlo Wireless Camera System Security - Paul's Security Weekly #506 from 2017-03-27T09:00

Paul lists the pros and cons of using Arlo wireless cameras to secure your home in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Tech Segment: Secure Online Backups, Don Pezet, ITProTV - Paul's Security Weekly #506 from 2017-03-26T09:00

Online backups are a double-edged sword. They provide fast, easy backups with inexpensive storage; however, by being online, they are able to be targeted by attackers. Don Pezet of ITPro.TV show...

Listen
Paul's Security Weekly TV
Ferruh Mavituna, NetSparker - Paul's Security Weekly #506 from 2017-03-25T09:00

Ferruh Mavituna is the Founder and Product Manager of Netsparker. He developed the first and only proof-based web security scanner with vulnerability detection and exploitation features. Ferruh ...

Listen
Paul's Security Weekly TV
Michael Figueroa, Advanced Cyber Security Center - Startup Security Weekly #31 from 2017-03-22T09:00

Michael Figueroa is the President and Executive Director of the Advanced Cyber Security Center, a non-profit organization that brings together industry, university, and government organizations ...

Listen
Paul's Security Weekly TV
March 21, 2017 - Hack Naked News #116 from 2017-03-21T19:44:33

The Fappening 2.0 is upon us, hackers escape VMware, thieves are caught using facial recognition software, and more. Don Pezet of ITPro.TV joins us to deliver expert commentary. Stay tuned!

...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #505 from 2017-03-21T09:00

The origin of threat hunting, your microwave is spying on you, 10 must-read books for infosec professionals, and why is IR automation and orchestration so hot?

Full Show Notes: Listen

Paul's Security Weekly TV
Brad Haines (a.k.a. Render Man) on Internet of Dongs - Paul's Security Weekly #505 from 2017-03-20T09:00

Brad Haines (aka Render Man) is security enthusiast with a focus on security threats of all sorts. He is the person your sysadmin warned you about. Brad spearheads the Internet of Dongs Project,...

Listen
Paul's Security Weekly TV
Andrew Whitaker, Rapid7 - Paul's Security Weekly #505 from 2017-03-19T09:00

Andrew Whitaker is the Director of Global Services at Rapid7. He leads Rapid7’s penetration testing services that help organizations around the world gain insight into real-world risk and remedi...

Listen
Paul's Security Weekly TV
Michael Dalgleish, LogRhythm - Enterprise Security Weekly #37 from 2017-03-17T09:00

Michael Dalgleish is an industry veteran, having spent the last 15 years deeply entrenched in the network and security worlds. Michael currently works with the Field Sales Engineering team on th...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #30 from 2017-03-16T09:00

AI startups are winning, 8 funding alternatives, CA Technologies acquires Veracode, and more in this week’s Startup News!

Full Show Notes: Listen

Paul's Security Weekly TV
March 15, 2017 - Hack Naked News #115 from 2017-03-15T20:26:05

Patch Tuesday returns, Android devices have malware, a government spyware maker doxes itself, and more. Jason Wood of Paladin Security delivers expert commentary on the Wikipedia for spies. Stay...

Listen
Paul's Security Weekly TV
Steve Tout & Stan Bounev, VeriClouds - Startup Security Weekly #30 from 2017-03-15T09:00

Steve Tout and Stan Bounev serve as the CEO and Head of Product Management at VeriClouds, respectively. VeriCloud focuses on the aggregation of compromised online data aimed at enhancing the sec...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #504 from 2017-03-14T09:00

Lots of news involving the CIA, Firefox 52 expands non-secure HTTP warnings, WiFi cameras are insecure, email is safer in Office 365, and who is joining the IoT Cybersecurity Alliance?

Fu...

Listen
Paul's Security Weekly TV
Keith Hoodlet, InfoSec Mentor Project - Paul's Security Weekly #504 from 2017-03-13T09:00

Keith Hoodlet works as an Engineer on the Customer Success team at Rapid7. He is currently rebooting the InfoSec Mentors Project, providing a platform for finding and connecting mentors and ment...

Listen
Paul's Security Weekly TV
Hyrum Anderson, Endgame - Paul's Security Weekly #504 from 2017-03-12T10:00

Hyrum Anderson is the Technical Director for Data Science at Endgame. He received his PhD in Electrical Engineering from the University of Washington and BS/MS degrees from Brigham Young Univers...

Listen
Paul's Security Weekly TV
Cloud and Virtual Infrastructure of Security, Don Pezet - Enterprise Security Weekly #36 from 2017-03-11T10:00

Our friend Don Pezet of ITProTV joins us on this week’s episode of Enterprise Security Weekly to discuss cloud and virtual infrastructure security!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Enterprise Security Weekly #36 from 2017-03-10T10:00

Arista containerizes itself, the CIA slams Wikileaks, Okta buys Stormpath to add identity control, and more in this week’s Enterprise News!

Full Show Notes: Listen

Paul's Security Weekly TV
News - Startup Security Weekly #29 from 2017-03-09T10:00

PowerPoint slides that will save you hours on your next deck, 5 of the biggest first-time founder struggles, Palo Alto acquires LightCyber, and when is less more?

Full Show Notes: Listen

Paul's Security Weekly TV
Frank Wang, Cybersecurity Factory - Startup Security Weekly #29 from 2017-03-08T10:00

Frank Wang is a PhD student at MIT, focusing on building secure systems. He currently runs a summer program for early stage security companies called Cybersecurity Factory. Frank has interned at...

Listen
Paul's Security Weekly TV
March 7, 2017 - Hack Naked News #114 from 2017-03-07T21:42:39

Google and Microsoft announce bug bounty programs, HackerOne releases open source projects, less spam for all of us, and more. Jason Wood of Paladin Security delivers expert commentary on ransom...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #503 from 2017-03-07T10:00

The risks of using an Android password manager, another WordPress plugin is flawed, hidden backdoors, Cloudbleed gets triggered, and more in this week’s security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Incident Response & Forensic Reporting, Doug White - Paul's Security Weekly #503 from 2017-03-06T10:00

Our very own Doug White delivers a demonstration/rant about incident response and forensic reporting in this week’s technical segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Alan White, Dell SecureWorks/US Army - Paul's Security Weekly #503 from 2017-03-05T10:00

Alan White is the Global Regions Consulting and Services Director for Dell SecureWorks, and is part of the US Army's Computer Emergency Research Team. Previously, Alan was the Director of Securi...

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #35 from 2017-03-03T10:00

The first threat intelligence platform compliant with STIX 2.0 is here, LightCyber joins Palo Alto, Flowmon teams up with Ixia, and more in this week’s Enterprise News!

Full Show Notes: <...

Listen
Paul's Security Weekly TV
Chris Clymer, Jack Nichelson, and Jason Middaugh, InfoSec World - Enterprise Security Weekly #35 from 2017-03-02T23:52:03

We welcome three InfoSec World speakers to the program! Chris Clymer is Director of Security Services for MRK, Jack Nichelson is Director of Infrastructure & Security for Chart Industries, and J...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #28 from 2017-03-01T10:00

Verizon closes in on Yahoo, 8 key ingredients to a profitable consulting business, building a repeatable sales process, and when should you fire yourself?

Full Show Notes: Listen

Paul's Security Weekly TV
February 28, 2017 - Hack Naked News #113 from 2017-02-28T22:00

Microsoft browsers are hit with a 0-day, Apple severs ties with Supermicro, IoT toy are spying on kids, and more. Jason Wood of Paladin Security joins us to talk about how the NSA is using cyber...

Listen
Paul's Security Weekly TV
Mike Kail, Cybric - Startup Security Weekly #28 from 2017-02-28T10:00

Mike Kail is the Co-Founder and CIO of Cybric. Prior to founding Cybric, Mike was Yahoo’s CIO and SVP of Infrastructure and VP of IT Operations at Netflix. He has more than 24 years of IT operat...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #502 from 2017-02-27T10:00

Lawmakers prepare to overturn broadband privacy rules, Windows vulnerabilities await patches, new security technologies debut at RSA, and are Slack conversations really private?

Full Show...

Listen
Paul's Security Weekly TV
Tech Segment: David Fletcher, Symantec - Paul's Security Weekly #502 from 2017-02-26T10:00

This webcast, driven by John Strand, brings together some of Black Hills Information Security’s best to discuss antivirus. David Fletcher shows us how to bypass Symantec in this technical segmen...

Listen
Paul's Security Weekly TV
Don Pezet, ItPro.TV - Paul's Security Weekly #502 from 2017-02-25T10:00

Don Pezet is no stranger to the Security Weekly network! In this episode, Don chats with Paul, Doug, Jeff, Joff, and Carlos about tactics, laws, and problems related to incident response.

Listen
Paul's Security Weekly TV
News - Enterprise Security Weekly #34 from 2017-02-24T09:30

Cisco touts next-generation firewall gear, a new decryption tool from Avast, Centrify stops breaches in real time, and more in this week’s Enterprise News!

Full Show Notes: http://wiki.se...

Listen
Paul's Security Weekly TV
Jim Routh, Aetna - Enterprise Security Weekly #34 from 2017-02-23T23:34:55

Jim Routh is the Chief Security Officer and leads the Global Security function for Aetna. He is also the Chairman of the NH-ISAC Board, and has previously worked for JP Morgan Chase and American...

Listen
Paul's Security Weekly TV
Scott Kannry and Jason Christopher, Axio - Startup Security Weekly #27 from 2017-02-22T10:00

We welcome the CEO and CTO of Axio to the show, Scott Kannry and Jason Christopher, respectively. Axio aims to help organizations implement more comprehensive cyber risk management based on an a...

Listen
Paul's Security Weekly TV
February 21, 2017 - Hack Naked News #112 from 2017-02-21T21:19:31

A lone hacker breaches 60 universities and federal agencies, Yahoo loses $350 million from breaches, more bug bounty programs for porn sites, and is your child a hacker? Jason Wood of Paladin Se...

Listen
Paul's Security Weekly TV
Security News - Paul's Security Weekly #501 from 2017-02-21T10:00

Drive-by exploits are about to become much worse, how to use Scuba to run a database vulnerability scan, more Patch Tuesday delays, and why is it that the more infosec changes, the more it stays...

Listen
Paul's Security Weekly TV
News - Startup Security Weekly #27 from 2017-02-21T10:00

Sophos acquires Invincea, the startup fundraising dictionary, five tough lessons every solopreneur needs to know, and how much is a Shark Tank appearance worth? Listen

Paul's Security Weekly TV
Slipping Executables Past Firewall, Carrie Roberts - Paul's Security Weekly #501 from 2017-02-20T10:00

Carrie Roberts joined Black Hills InfoSec after working for HP's Global Cyber Security group, where she worked as a network penetration tester.

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #501 - David Conrad, ICANN from 2017-02-19T10:00

David Conrad is a long-time and active participant in Internet infrastructure, development, and operations. As the CTO of ICANN, David is at the heart the organization’s mission to help maintain...

Listen
Paul's Security Weekly TV
Rules for Security Vendors - Enterprise Security Weekly #33 from 2017-02-18T10:00

Nerdio partners with CensorNet, ThreatConnect reveals a new threat intelligence product suite, free cyberthreat hunter, and defender tools for security analysts. Paul and John review the CISO Ma...

Listen
Paul's Security Weekly TV
Startup Security Weekly #26 - William Lin, Trident Capital Cybersecurity from 2017-02-17T10:00

William Lin is the Vice President of Trident Capital Cybersecurity. He has deployed more than $60 million across nearly a dozen cybersecurity companies to date. William also serves as a board ob...

Listen
Paul's Security Weekly TV
Startup Security Weekly #26 - News from 2017-02-16T10:00

12 KPIs you need to know before pitching your startup, VC firms back a record number of cybersecurity startups in 2016, and why should entrepreneurs think like farmers?

Full Show Notes: <...

Listen
Paul's Security Weekly TV
Hack Naked News #111 - February 14, 2017 from 2017-02-15T17:00

Microsoft delays Patch Tuesday, WordPress continues to fail at failing, Valve eradicates a Steam bug, ransomware that makes you do terrible things, and more. Jason Wood of Paladin Security joins...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #32 - Lior Frenkel, Waterfall Security from 2017-02-15T10:00

Lior Frenkel is the CEO and Co-Founder of Waterfall Security, a leading provider of unidirectional security gateways and stronger-than-firewall perimeter security solutions for industrial contro...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #32 - News from 2017-02-14T21:46:34

CyberArk beefs up its cloud security, Kenna Security partners with Exodus, Gigamon is eliminating network blind spots, and more in this week’s Enterprise News!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #500 - Round Table: Penetration Testing pt. 2 from 2017-02-12T10:00

Paul has trapped everyone in a blizzard at G-Unit Studios in Rhode Island! They must talk about penetration testing or they will be penetra...well, never mind. Watch this segment to hear our pan...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #500 - Round Table: IoT Security pt. 1 from 2017-02-11T10:00

Paul and crew kick off the episode 500 festivities by hosting a roundtable discussion on the current state and future of IoT security!

Full Show Notes: Listen

Paul's Security Weekly TV
Startup Security Weekly #25 - News from 2017-02-09T10:00

How to prevent startup burnout, five IoT cybersecurity predictions for 2017, three tips to help entrepreneurs make the right sacrifices, and what exactly is your income statement telling you? Listen

Paul's Security Weekly TV
Hack Naked News #110 - February 7, 2017 from 2017-02-08T20:06:54

Android vulnerabilities are patched, your TV is watching you, iOS apps are vulnerable, the lamest crypto bug, and more. Jason Wood joins us to talk about a former NSA contractor who may have sto...

Listen
Paul's Security Weekly TV
Startup Security Weekly #25 - Archie Agarwal, ThreatModeler from 2017-02-08T10:00

Archie Agarwal is the Founder, CEO, and Chief Technical Architect of ThreatModeler. He has leveraged his more than ten years of real-world experience in threat modeling and threat assessment to ...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #499 - Security News from 2017-02-07T10:00

A patchwork quilt of IoT security, President Trump’s cyber executive order, how Google fought a botnet (and won), and why didn’t WordPress tell us about their recent zero-day?

Full Show N...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #499 - Nathaniel "Q" Quist, LogRhythm from 2017-02-06T10:00

Nathaniel “Q” Quist is an Incident Response Engineer at LogRhythm Labs. Q is actively focused on Active Defense countermeasures and methods to increase the defensive capabilities of various orga...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #499 - Katherine Teitler, MISTI from 2017-02-05T10:00

Katherine Teitler is the Director of Content for MISTI, where she is responsible for programming information security conferences, workshops, and summits. Previously, she served as Director of C...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #31 - News from 2017-02-04T10:00

Distil Networks wants to leverage device fingerprints, Exabeam reveals its latest security intelligence program, HPE acquires Niara, and more in this week’s Enterprise News!

Full Show Not...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #31 - Matt Alderman, Tenable from 2017-02-03T10:00

As Tenable’s Vice President of Strategy, Matt Alderman is responsible for developing long-term strategies for messaging, new market entries, and product development to meet the emerging needs of...

Listen
Paul's Security Weekly TV
Startup Security Weekly #24 - Eddy Bobritsky, Minerva Labs from 2017-02-02T10:00

Eddy Bobritsky is the Founder and CEO of Minerva Labs, an Israeli threat detection and defense company. Eddy also founded BOBSEC, and possesses 7 years of experience in different cyber units for...

Listen
Paul's Security Weekly TV
Startup Security Weekly #24 - News from 2017-02-01T10:00

GFI acquires Kerio, why 2017 will be tough for seed startups, the MVP you’ve probably never heard of, why your product team is failing, and more in this week’s Startup News!

Full Show Not...

Listen
Paul's Security Weekly TV
Hack Naked News #109 - January 31, 2017 from 2017-01-31T22:00

Don Pezet of ITPro.TV joins us to discuss why a luxury hotel has gone analog, ransomware shutting down security cameras, and more hacking news. Stay tuned!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #498 - Security News from 2017-01-31T10:00

President Trump is tweeting from an insecure phone, Asus gives Raspberry Pi a run for its money, how to use your heartbeat as a password, and can you revive an old laptop with a free OS?

...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #498 - Tech Segment: Jeff's HP Adventures from 2017-01-30T10:00

Our very own Jeff Man attended HP Print Security Tech Day at HP’s headquarters in Palo Alto, California. He documents his experience at HP and how their business model influences printer securit...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #498 - Chris Kubecka, HypaSec from 2017-01-29T10:00

Chris Kubecka is an experienced and certified IT security expert. In addition to curating the popular Security Evangelist blog, she also serves as a member of the Executive Steering Committee wi...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #30 - Jayne Groll and Alan Shimel, DevOps from 2017-01-28T10:00

Jayne Groll and Alan Shimel are both Co-Founders of the Florida-based software development and IT operations company, DevOps. Both carry extensive IT credentials, extensive industry experience, ...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #30 - News from 2017-01-27T10:00

SyferLock announces a technology alliance with OpenIAM, RiskIQ strengthens their digital threat mitigation capabilities, RiskSense Platform 7.0 is here, on Enterprise Security News!

Full ...

Listen
Paul's Security Weekly TV
Hack Naked News #108 - Jason Wood, Paladin Security from 2017-01-26T22:00

Jason Wood is the Founder and and primary consultant of Paladin Security. Prior to starting Paladin Security, Jason was a Principal Security Consultant at Secure Ideas, and taught classes on vul...

Listen
Paul's Security Weekly TV
Startup Security Weekly #23 - News from 2017-01-26T10:00

Nine ways to distance your business from cyber attacks, lessons learned from Target, 11 free tools every first-time entrepreneur should use, and can your startup generate venture-scale returns?<...

Listen
Paul's Security Weekly TV
Hack Naked News #108 - News: January 25, 2017 from 2017-01-25T21:00:46

Firefox attempts to protect users, Android threats that matter (and one that doesn't), Cisco patches a critical flaw, and why are film festivals a target for attackers?

Full Show Notes: <...

Listen
Paul's Security Weekly TV
Startup Security Weekly #23 - Ron Gula, Gula Tech Adventures from 2017-01-25T10:00

Ron Gula is a serial entrepreneur with quite a track record; he’s known for co-founding Tenable, founding Network Security Wizards, and serving as VP of Intrusion Detection Products for Enterasy...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #497 - Security News from 2017-01-24T10:00

We discuss Chelsea Manning’s commutation, Guccifer 2.0 resurfacing, the identity of the Mirai botnet creator, and more in this week’s security news!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #497 - Bruce Potter, ShmooCon from 2017-01-23T10:00

Bruce Potter is the Founder and an organizer of ShmooCon, a long-running, yearly hacker convention in Washington, D.C. He also serves as the CTO of KeyW Corporation and Ponte Technologies. Bruce...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #497 - Jason Blanchard, SANS Institute from 2017-01-22T10:00

Jason Blanchard is the Curriculum Marketing Manager of Penetration Testing for the SANS Institute. In addition to speaking at conventions like DerbyCon and BSides Orlando, he has served as the S...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #29 - News from 2017-01-21T10:00

How to choose the right distributed ledger program, Ixia and K2 integrate IoT platforms, SyferLock announces multi-factor authentication integration, and is a new antivirus program really the ne...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #29 - Zane Lackey, Signal Sciences from 2017-01-20T10:00

Zane Lackey is the Founder and Chief Security Officer of Signal Sciences. Prior to becoming a vendor, Zane was the Director of Security Engineering at Etsy and a Senior Security Consultant at iS...

Listen
Paul's Security Weekly TV
Startup Security Weekly #22 - News from 2017-01-19T10:00

Getting your metrics together, why founders fail to market their products, and does communication determine the success of your business?

Full Show Notes: Listen

Paul's Security Weekly TV
Startup Security Weekly #22 - Robert Stratton, Mach37 from 2017-01-18T10:00

Bob Stratton is a serial Internet and cybersecurity entrepreneur. Prior to Mach37, Bob was Director of Government Research at Symantec Research Labs and founded many product and service companie...

Listen
Paul's Security Weekly TV
Hack Naked News #107 - January 17, 2017 from 2017-01-17T22:00

Israel Barak of Cybereason joins us to discuss endpoint security, malware, ransomware, and more news stories in this week’s episode of Hack Naked News!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #496 - Security News from 2017-01-17T10:00

The Trump Administration urges more coordination on cyberthreats, more raw intelligence data sharing permissions for the NSA, and why are the feds suing D-Link?

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #496 - Tech Segment: Bypassing AV on Android, Beau Bullock from 2017-01-16T10:00

Beau Bullock shows us how to bypassing antivirus software using Android in this week’s tech segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #496 - Lesley Carhart, Motorola Solutions/US Air Force Reserve from 2017-01-15T10:00

Lesley Carhart (@hacks4pancakes) is a veteran security incident responder and digital forensics analyst. Programming since the age of 7, she forged her name in the industry by working with organ...

Listen
Paul's Security Weekly TV
Startup Security Weekly #21 - News from 2017-01-12T10:00

DIY home security suites, a cybersecurity company’s biggest 2016 failure, and what should you expect as a tech startup in 2017?

Full Show Notes: Listen

Paul's Security Weekly TV
Hack Naked News #106 - January 11, 2017 from 2017-01-11T21:29:57

The world’s easiest bug bounty program, Shamoon’s capabilities spread to desktops, the fridge who loved me, and are Geek Squad techs working for the FBI?

Full Show Notes:http://wiki.secur...

Listen
Paul's Security Weekly TV
Startup Security Weekly #21 - Justin Foster, Foster Thinking from 2017-01-11T10:00

Justin has been consulting Fortune 1000 companies and entrepreneurs about branding, marketing, and more for over a decade.

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #495 - Security News from 2017-01-10T10:00

MongoDB databases are under attack, info on buying internal domain access, smart meters are vulnerable, and why is a Florida man suing Verizon?

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #495 - Forensic Toolkit (FTK), Doug White from 2017-01-09T10:00

Doug White of Secure Technology provides a demo on forensic data carving using FTK on this tech segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #495 - Joe McCray, Strategic Security from 2017-01-08T10:00

Joe has an extensive background in computer security, pen testing, and system administration. He founded Strategic Security in 2010 with the vision of providing in-depth technical assessments of...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #28 - Cyber Insurance, Michael Santarcangelo from 2017-01-07T10:00

Would your company benefit from purchasing a cyber insurance policy? What should you be covering? How are insurance companies assessing you?

Full Show Notes: Listen

Paul's Security Weekly TV
Enterprise Security Weekly #28 - News from 2017-01-06T10:00

HP debuts new IoT devices, Bitdefender’s second BOX is here, FireMon announces support for Check Point R80, and more.

Full Show Notes: Listen

Paul's Security Weekly TV
Article Discussion and Startup News - Startup Security Weekly #67 from 2017-01-06T10:00

In our article discussion, we talk about management principles for highly functioning teams, how to pitch your app to investors, and calculating your total addressable market and making a great ...

Listen
Paul's Security Weekly TV
Hack Naked News #105 - January 3, 2017 from 2017-01-03T22:07:13

0day vulnerabilities in storage devices, why VMware sucks at key management, how to un-ransomware your Google TV, and did Russia really tamper with the 2016 election?

Full Show Notes: Listen

Paul's Security Weekly TV
Hack Naked News #104 - December 28, 2016 from 2016-12-29T10:00

Two critical vulnerabilities you will want to patch before 2017 and a free tool to keep ransomware off the new gadgets you received over the holidays.

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #494 - Security News from 2016-12-27T10:00

Nokia sues Apple, home routers are under attack, a Russian botnet is stealing millions of dollars per day, and should you give up on PGP? Find out in this week’s security news!

Full Show ...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #494 - Tech Segment: Rudolph the Credit Card-Swiping Reindeer from 2016-12-26T10:00

How do you find credit card numbers that have slipped out of the Cardholder Data Environment? Joshua Marpet and Scott Lyons show you how in this week’s tech segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #494 - Eric "Munin" Rand, Brown Hat Security from 2016-12-25T10:00

Munin is a professional blue-team consultant from Southern California who spends his days providing technical support to defensive security operations folks, finding a way to turn paranoia into ...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #27 - Win10 Ubuntu with John Strand from 2016-12-23T10:00

John Strand delivers a tech segment on how to use Ubuntu with Windows 10. Stay tuned!

Full Show Notes: http://wiki.se...

Listen
Paul's Security Weekly TV
Startup Security Weekly #20 - News from 2016-12-22T10:00

In this week's news, we talk about why many boom-time startups are fizzling out, the average age of startup founders, why Johnson & Johnson is getting into startups, and much more in this week's...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #493 - Security News from 2016-12-20T10:00

Austalia's tax office loses a petabyte (yes, a petabyte) of data, why it's time for organizations to start automating security, and could the news be any worse for Yahoo? All that and more in th...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #493 - Tech Segment: I Made The Switch to a Linux Laptop from 2016-12-19T10:00

Paul has been known by many as an Apple fanboy for a long time. What convinced him to ditch his Macbook for a Linux laptop? Find out in this week's tech segment!

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #493 - Dave Shackleford, Voodoo Security and SANS from 2016-12-18T10:00

Dave is the Founder of Voodoo Security, a company that provides information security consulting services to clients, specializing in virtualization and cloud security. Dave also serves as a Seni...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #26 - News from 2016-12-17T10:00

Ransomware’s effect on small business, another update from Ixia, Google Cloud customers have a new firewall offering, and much more in this week’s Enterprise News!

Full Show Notes: Listen

Paul's Security Weekly TV
Enterprise Security Weekly #26 - Don Pezet, ItPro.TV from 2016-12-16T10:00

Which skills should IT security folks learn that are not directly related to security? Why is it important to have these skills? How can people get training on these skills? What benefits will t...

Listen
Paul's Security Weekly TV
Startup Security Weekly #19 - News from 2016-12-15T10:00

In this week's news, we chat promising equity against issuing equity, why someone burned $10 million so you don't have to, and ask the age-old question: are you taking enough risks? Tune in to t...

Listen
Paul's Security Weekly TV
Startup Security Weekly #19 - Josh Lefkowitz and Chris Camacho, Flashpoint from 2016-12-14T10:00

We welcome two Flashpoint representatives to the show. Josh serves as the CEO, while Chris is the Chief Strategy Officer. Paul and Michael talk with Josh and Chris about their experience at Flas...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #492 - Security News from 2016-12-13T10:00

Old Linux and BSD code is vulnerable, your worst fears about IoT security are probably true, SSL-protected web sites, security for small businesses, and the hacking doomsday. All that and more i...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #492 - Ofri Ziv, GuardiCore from 2016-12-12T10:00

Ofri leads the Detection Development group at GuardiCore, which is responsible for security research, detection, and development of data analysis algorithms. Ofri educates us on the Oracle of De...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #492 - Ferruh Mavituna, Netsparker from 2016-12-11T10:00

Ferruh is certainly no stranger to the show! Paul, Larry, and Joff chat with Ferruh about web applications, mobile security, and updates on his journey at Netsparker on Paul’s Security Weekly! Listen

Paul's Security Weekly TV
Enterprise Security Weekly #25 - News from 2016-12-10T10:00

Juniper makes an acquisition, to IPO or not IPO, Ixia delivers an unprecedented visibility into virtual data center traffic, and much more in this week’s Enterprise News!

Full Show Notes:...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #25 - Don Pezet, ItPro.TV from 2016-12-09T10:00

Don serves as the CTO and host for ITPro.TV. His combination of real-world experience, textbook knowledge, and a questionable sense of humor have helped him to entertain and educate thousands of...

Listen
Paul's Security Weekly TV
Startup Security Weekly #18 - Michael Tanji, Managing Director at Wapack Labs from 2016-12-07T10:00

Michael is the Managing Director of Wapack Labs and the Co-Founder and CSO of Kyrus. Paul and Michael (Santarcangelo, that is) pick his brain about startups, the startup lifestyle, and his exper...

Listen
Paul's Security Weekly TV
Hack Naked News #103 - December 6, 2016 from 2016-12-06T21:05:04

The USB killer is on the loose, why you shouldn’t use Visa, Obama challenges the Trump administration (sorta), the dumbest car thief of the week, and much more on this edition of Hack Naked News...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #491 - Security News from 2016-12-06T10:00

A new Mirai worm knocks almost a million Germans offline, time is running out for NTP, the propaganda about Russian propaganda, and who hacked the lights in Ukraine? All that and more in this we...

Listen
Paul's Security Weekly TV
Startup Security Weekly #18 - News from 2016-12-06T10:00

What five habits should you abandon as your startup grows? What mistakes should you avoid during product development? Find out about all that and more in this week’s startup news!

Full Sh...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #491 - Tech Segment: Containerizing your Security Operations Center from 2016-12-05T10:00

Jimmy is the chapter leader of OWASP Santa Barbara and co-organizer of the AppSec California security conference. He has spent time on both the offense and defense side of the industry. Jimmy br...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #491 - John Hurd and Alex Valdivia, ThreatConnect from 2016-12-04T10:00

Two ThreatConnect personnel join us: John currently serves as a Threat Intelligence Research Analyst, while Alex is the Senior Threat Intelligence Research Engineer. They discuss their experienc...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #24 - Top 5 Defenses Against Penetration Testers (And Attackers) from 2016-12-03T10:00

How can you defend yourself against attackers who are successfully exploiting you? Paul and John tell you how to pwn an organization and why you don’t necessarily need a vendor’s help in this we...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #24 - News from 2016-12-02T10:00

SecureAuth aims to protect mobile users, Gurucul receives an award, Palo Alto Networks automates cloud security deployment on AWS, the cybersecurity skills shortage (and what you can do about it...

Listen
Paul's Security Weekly TV
Hack Naked News #102 - November 29, 2016 from 2016-11-29T21:26:04

WordPress security gets another black mark, free transit rides for all in San Francisco, routers are hacked again, NTP is vulnerable, why buy when you can rent....a botnet, that is, backdooring ...

Listen
Paul's Security Weekly TV
Startup Security Weekly #17 - News from 2016-11-24T10:00

Paul and Michael answer some listener feedback, talk about their Startup Journeys, as well as answer questions like, "How startups can use open source software to compete against the big guys?" ...

Listen
Paul's Security Weekly TV
Hack Naked News #101 - November 23, 2016 from 2016-11-23T20:42:35

Rumors of a new director of national intelligence, ATMs spill money into the streets of China, real security requires a hedgehog, and Oracle buys a now famous DNS company, all that and more on H...

Listen
Paul's Security Weekly TV
Startup Security Weekly #17 - Tyler Shields, Signal Sciences Corp from 2016-11-23T10:00

He is a highly competitive, visionary, strategic thinker with the expertise to challenge accepted norms, motivate, and clearly communicate ideas.

Full Show Notes: Listen

Paul's Security Weekly TV
Paul's Security Weekly #490 - Security News from 2016-11-22T10:00

Experts encourage congress to act on IoT security, wifi can imprint passwords on pins on radio signals, major Russian banks are hacked with powerful IoT devices focused Botnets, meet poison tap ...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #490 - Tech Segment: Alex Horan and Sebastian Bortnik, Onapsis from 2016-11-21T10:00

Alex Horan and Sebastian Bortnik will be discuss what Onapsis has updated in their company and software in the year. They discuss the trends they've seen in the past year (DHS CERT, SANS SAP rep...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #490 - Jen Ellis and Harley Geiger, Rapid7 from 2016-11-20T10:00

Jen Ellis is the VP Community & Public Affairs at Rapid 7 and Harley Geiger is the Director of Public Policy at Rapid 7. Jen Ellis wors with security researchers & policy makers to improve publi...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #23 - Open Source Enterprise Security Program? from 2016-11-19T10:00

Protect your enterprise with open source security. Can you use firewalls, IDS, networking monitoring, and much more with Paul and John on Enterprise Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly TV
Enterprise Security Weekly #23 - News from 2016-11-18T17:58:21

CyberArk announces endpoint privilege manager, Dome9 bring pay scale economics could security offering, dropbox announces network control capability to secure enterprise collaboration, and much ...

Listen
Paul's Security Weekly TV
Startup Security Weekly #16 - News from 2016-11-17T10:00

Owler's Cryptzone Profile, Illumio releases new templates that offer better security, Why the top entrepreneurs are seeking corporate venture money, and much more, here on Startup Security Weekl...

Listen
Paul's Security Weekly TV
Hack Naked News #100 - November 16, 2016 from 2016-11-16T21:53:28

Chinese company installed secret backdoor on hundreds of thousands of phones, hacking team back for your Android, major linux holes gapes open, and much more, here on Hack Naked News!

Ful...

Listen
Paul's Security Weekly TV
Startup Security Weekly #16 - Josh Marpet & Scott Lyons from 2016-11-16T10:00

Michael is joined by Joshua Marpet and Scott Lyons. We're going to talk about their experience building and supporting security startups. We'll also explore some additional things they are worki...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #489 - Security News from 2016-11-15T10:00

Regulation of the Internet of Things, Packet Capture Options, Hackers hijack Philips Hue lights with a drone, Facebook buys black market passwords for user account safety, and much more here on ...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #489 - Tech Segment: Outlook Web Access Two-Factor Authentication Bypass from 2016-11-14T10:00

A design weakness has been exposed that can allow an attacker to easily bypass 2FA and access an organization’s email inboxes, calendars, contacts and more.

See more at: Outlook Web Acces...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #489 - Greg Foss, Logrhythm from 2016-11-13T10:00

Greg Foss is LogRhythm’s Head of Global Security Operations, where he is tasked with leading both offensive and defensive aspects of corporate security.

Full Show Notes: http://wiki.secur...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #22 - Incident Response from 2016-11-12T10:00

Enterprise Security Weekly Quick Guide To Building A Successful Incident Response Program with Paul and John.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode22 Listen

Paul's Security Weekly TV
Enterprise Security Weekly #22 - News from 2016-11-11T10:00

OneLogin acquires Sphere Secure Workspace, Synopsys Acquires Cigital, Codiscope to Bolster Security Portfolio, Gartners Latest Report on the CASB Market, and much more here on Enterprise Securit...

Listen
Paul's Security Weekly TV
Startup Security Weekly #15 - News from 2016-11-10T10:00

The 3 most abstract tips to make your startup succeed, the 5 best presentation apps for your startup needs, non-expensive ways to make your small business feel big, and a giphy company that has ...

Listen
Paul's Security Weekly TV
Startup Security Weekly #15 - Adam Bixler, Efflux Systems from 2016-11-09T10:00

Adam Bixler is the Cofounder and Chief Ops Officer for Efflux Systems. Offering a security operations solution that detects lateral movement and attacker tradecraft.

Full Show Notes: http...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #488 - Security News from 2016-11-08T10:00

Can the election be affected by attackers on the internet, can IoT devices suffer anymore security vulnerabilities, Microsoft announces the end of life for EMET, and much more, here on Paul's Se...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #488 - Tech Segment: Considerations for Using Intel SGX from 2016-11-07T10:00

Intel SGX is a newer method of implementing trusted computing. Jack and Paul talk about SGX and discuss its pros and cons.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/E...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #488 - David Koplovitz, ProXPN from 2016-11-06T09:00

Over twenty years of experience in corporate leadership and management. Developed agile products, created solutions, integrated systems and deployed technologies for both external and internal c...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #21 - News from 2016-11-05T09:00

Rapid 7 makes a strategic integration, should you use artificial intelligence in your enterprise to replace your workforce?, what is your DDoS mitigation strategy?, a big social media company se...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #21 - Using Bro In The Enterprise from 2016-11-04T09:00

Bro is a fantastic open-source tool, capable of analyzing packets at high speeds and big bandwidth. Learn how you can implement this open-source tool in your enterprise today, for the win!

<...

Listen
Paul's Security Weekly TV
Hack Naked News #99 - November 3, 2016 from 2016-11-03T19:25:01

A popular cloud based website hosting company could become the next myspace, more powerful IoT botnet, browser vendors lack trust in 2CAs, and some, including myself about an election day hack. ...

Listen
Paul's Security Weekly TV
Startup Security Weekly #14 - News from 2016-11-03T09:00

Updates on Paul's and Michael's startup journeys, the 22 most active celebrity startup investors, and much more here on Startup Security Weekly!

Full Show Notes: http://wiki.securityweekl...

Listen
Paul's Security Weekly TV
Startup Security Weekly #14 - Brian Beyer, CEO of Red Canary from 2016-11-02T09:00

Brian leads Red Canary to deliver its mission of bringing world-class threat detection and response to every business. Prior to co-founding Red Canary, Brian incubated cybersecurity products at ...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #487 - Security News from 2016-11-01T09:00

Webcams used to attack Twitter and reddit will be recalled according to a Chinese manufacturer, a Windows 10 vulnerability called Atom Bombing, dirty cow, and much more here on Paul's Security W...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #487 - Tech Segment: Why Signatures Suck with Mark Dufresne, Endgame from 2016-10-31T09:00

Why signatures don’t really work for detection and about what folks should be thinking about instead.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode487#Technical_S...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #487 - Chris Roberts, Acalvio Technologies from 2016-10-30T09:00

Chris Roberts is considered one of the world’s foremost experts on counter threat intelligence within the Information security industry. At Acalvio, Chris helps drive Technology Innovation and P...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #20 - News from 2016-10-29T09:00

Carahsoft Adds Okta ID, FireMon acquires FortyCloud, Why Juniper Networks, Inc. stock soared today, and much more, here on Enterprise Security Weekly!

Full Show Notes: http://wiki.securit...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #20 - Multi-Factor Authentication from 2016-10-28T09:00

Should we use Multi-factor Authentication for our Enterprise? Find out whether you should have a 2FA or not, here on Enterprise Security Weekly!

Full Show Notes: http://wiki.securityweekl...

Listen
Paul's Security Weekly TV
Hack Naked News #98 - Don Pezet, ITPro.TV from 2016-10-26T21:00

Don Pezet joins us from ITPro.TV, to talk about how to secure those devices that hackers have been taking advantage of.


Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Startup Security Weekly #13 - News from 2016-10-25T09:00

In the Startup News this week, the differences between Angel and VC investments, expanding the concept of entrepreneurship, is running a startup for you?, How To Become A Cybersecurity Entrepren...

Listen
Paul's Security Weekly TV
Startup Security Weekly #13 - H.D. Moore, Metasploit Project from 2016-10-24T09:00

In our first interview every on the show we sit down with none other than HD Moore, founder of the Metasploit project and currently Principal at Special Circumstances, LLC.

Full show Note...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #486 - Security News from 2016-10-23T09:00

Donald Trump is running an insecure email server, Mirai bots more than double since source code release, Skyping and typing has some issues, IoT needs to learn from your Mitre Saw, and much more...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #486 - Listener Feedback: Fixing Pen Test Findings and XMLRPC from 2016-10-22T09:00

XMLRPC for the win or not? How long should you re-mediate vulnerabilities found in penetration test reports?

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode486#List...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #486 - Adrien de Beaupre from 2016-10-21T17:23:19

So do you really want to be a penetration tester? We get these questions all the time, and Adrien does too!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode486#Inter...

Listen
Paul's Security Weekly TV
Startup Security Weekly #12 - A Handwritten Thankyou from 2016-10-20T09:00

All things startup as it relates to security in the Startup mindset! Check out the updates on Paul and Michael's Startup Journey.

Full Show Notes: http://wiki.securityweekly.com/wiki/inde...

Listen
Paul's Security Weekly TV
Startup Security Weekly #12 - Stories from 2016-10-19T09:00

How to spot a bad kickstarter, Inside the mind of a venture capitalist, Front Series A Deck, Want to Become More Disruptive With Your Startup? and how to keep hackers from destroying your startu...

Listen
Paul's Security Weekly TV
Hack Naked News #97 - October 18, 2016 from 2016-10-18T21:25:33

Microsoft and Adobe, Guccifer, and ransomware! Hack Naked News with Aaron Lyons!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Hack_Naked_TV_October_18_2016

Visit ...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #485 - Security News from 2016-10-18T09:00

Disappearing messages added to signal app, IoT devices as proxies for Cybercrime, nuclear power plant disrupted by cyber attack, and more, here on Security Weekly!

Full Show Notes: http:/...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #485 - Listener Feedback, Drinking From The InfoSec Fire Hose from 2016-10-17T09:00

Questions from the Security Weekly listeners are answered during this segment.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode485#Listener_Feedback:_Drinking_From_T...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #485 - Scott Lyons and Joshua Marpet, Guarded Risk from 2016-10-16T09:00

Scott Lyons is the V.P. of Business Development for WarCollar. Joshua Marpet is a well known Security Researcher and speaker.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.ph...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #19 - Discussion from 2016-10-15T09:00

Combining network and endpoint analysis for the win, password management with endpoint security, deception and winning?

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_E...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #19 - Defending IoT Devices from 2016-10-14T09:00

Securing your data, and an account security solution, or ASS?, and securing IoT in the Enterprise!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode19

Visit...

Listen
Paul's Security Weekly TV
Startup Security Weekly #11 - Discussion from 2016-10-13T09:00

Fostering online trust to build a community, leading with culture to be a successful startup, pivotal stories every startup leader should know and so much more! Here on Startup Security Weekly!<...

Listen
Paul's Security Weekly TV
Startup Security Weekly #11 - Magic of Momentum from 2016-10-12T09:00

Check out the Magic of Momentum on your Startup!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode11

Visit http://securityweekly.com/ssw for all the latest epi...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #484 - Security News from 2016-10-11T09:00

Security news will discuss Yahoo! spying, Mirai source code lessons learned, I will try my best, but fail, at not saying "I told you so!", and more!

Full Show Notes: http://wiki.securityw...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #484 - Tech Segment: Pre-exploit Preventing from 2016-10-10T09:00

Cody Pierce from Endgame will be giving a 15 minute segment on Pre-exploit Preventing.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode484#Tech_Segment:_Pre-exploit_...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #484 - Ed Skoudis from 2016-10-09T09:00

Ed Skoudis of Counterhack Challenges and The SANS Institute. Ed will discuss IoT security, the Holiday Hack Challenge and upcoming SANS Hackfest conference.

Full Show Notes: http://wiki.s...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #18 - Darkweb Monitoring from 2016-10-08T09:00

Darkweb monitoring, is it really worth it and how can it help your enterprise? Find out on this edition of Enterprise Security Weekly!

Full Show Notes: http://wiki.securityweekly.com/wiki...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #18 - News from 2016-10-07T16:16:42

Juniper's bug push into security, a big endpoint player goes IPO, and a firewall company enters the Anti-Virus game.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Epis...

Listen
Paul's Security Weekly TV
Hack Naked News #95 - October 4, 2016 from 2016-10-05T15:44:31

WoSign, Cisco, Ransomware, and Linux crash! All that and more, so stay tuned!
Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Paul's Security Weekly #483 - Listener Feedback: Old vs New from 2016-10-03T09:00

Give us your questions and feedback and send it to psw@securityweekly.com and we'll put it on the show!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode483#Listener_...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #483 - Interview Ferruh Mavituna, Netsparker from 2016-10-01T09:00

Ferruh Mavituna from Netsparker. He's been Hacking web apps since 2003, web app sec expert, and the CEO of Netsparker.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episo...

Listen
Paul's Security Weekly TV
Paul's Security Weekly #483 - Security News from 2016-09-30T18:00:47

Yahoo is breached, open SSL has a bug, Raspberry Pi new Pixel update, thousands of Cisco devices still vulnerable, and stick around for Jack's rant! Here on Security News!

Full Show Notes...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #17 - News from 2016-09-30T09:00

A behavior analytics company has a new release, endpoint security for vulnerabilities and threats, outsource your threat hunting, get with the flow on your network, and waiting in the wings to g...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #17 - Security Training for Enterprises from 2016-09-29T22:59:19

Plus John and I discuss security training for the enterprise, what will work work best for you?

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode17

Visit ht...

Listen
Paul's Security Weekly TV
Security Weekly #450 - Security News from 2016-09-29T17:51

Tons of stories and Jack is just going to rant about DNS!

Listen
Paul's Security Weekly TV
Hack Naked News #94 - September 27, 2016 from 2016-09-28T09:00

Hack Naked coversthis week, CompTIA Security, CISSP, CEH v9, and Red Hat Linux. All that and more on Hack Naked TV!

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #16 - News from 2016-09-27T09:00

The run-time application self protection security market showing growth, cloud based access provider Duo Security unveils new single sign on for SaaS Applications, AlienVault Research and much m...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #16 - Privileged Alphabet Soup from 2016-09-26T09:00

Discuss privileged identity management with Paul and Santarcangelo. It is becoming more of trend.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode16

Visit ...

Listen
Paul's Security Weekly TV
Security Weekly #482 - Security News from 2016-09-25T09:00

Alibaba fires employees for hacking their way to free mooncakes, How I gained access to TMobile’s national network for free, Employees download new malware every four seconds, all that and more ...

Listen
Paul's Security Weekly TV
Security Weekly #482 - Tech Segment: Securing a Shell Script from 2016-09-24T09:00

Paul explains how to try to make a secure shell script, along with introducing DisplayGoat!

Full Show Notes: https://github.com/pasadoorian/displaygoat/blob/master/displaygoat.sh

S...

Listen
Paul's Security Weekly TV
Security Weekly #482 - Kobi and Doron Naim, Cyberark Labs from 2016-09-23T16:11:36

Kobi Ben-Naim Senior Director of Cyber Research Kobi is an accomplished information security professional, well-known for his pioneering work in the field of Advanced Persistent Threats (APTs) a...

Listen
Paul's Security Weekly TV
Hack Naked News #93 - September 22, 2016 from 2016-09-22T19:58:06

Lots of Ransomware, Cisco, Lauri Love news, S.W.I.F.T, and Yahoo! gets hacked! All that and more on Hack Naked TV!

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Startup Security Weekly #10 - Startup News from 2016-09-21T16:00

Startup,security weekly,startup news,10,paul asadoorian,michael santarcangelo,7 pitching habits,Stories,discussion,startup,Security,Startup Security Weekly,Paul

Listen
Paul's Security Weekly TV
Security Weekly #481 - Security News from 2016-09-19T09:00

Privacy and Internet connected vibrators. Volkswagon launches a new cyber security firm to tackle car security, Ad Block Plus ridiculousness, and hacking cable modems. All that and more, so stay...

Listen
Paul's Security Weekly TV
Security Weekly #481 - Josh Abraham, Praetorian from 2016-09-18T09:00

At Praetorian, Josh is a key member of the technical execution team. In this capacity, he is responsible for leading, directing, and executing client-facing engagements that include Praetorian's...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #15 - Documentation from 2016-09-17T09:00

Ean Meyer joins us to discuss this topic as he wrote an article we discussed on a previous show.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode15

Visit h...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #15 - News from 2016-09-16T09:00

Microsoft partners with Ping, CyberArk gets a new patent, yet even more behavior based endpoint protection, Intel sells Mcafee, teaming up with MSPs, and embracing change in the cloud.

Fu...

Listen
Paul's Security Weekly TV
Hack Naked News #92 - September 15, 2016 from 2016-09-15T21:30:37

Malware, Mysql exploits, and ransomeware ransomeware ransomeware! Here on Hack Naked TV!

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Hack Naked News #91 - September 13, 2016 from 2016-09-13T18:38:01

Aaron Lyons tells us what he does here on Hack Naked TV. Tyler interviews Aaron Lyons on this subject.

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #14 - News from 2016-09-13T09:00

Mcafee trademark dispute, customers want large security vendors?, do you trust your pin in the cloud, CyberArk struggles and embrace change!

Full Show Notes: http://wiki.securityweekly.co...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #14 - Super Cyberman from 2016-09-12T09:00

Enterprise Security User Awareness Training and Paul dancing!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode14

Visit http://securityweekly.com/esw for al...

Listen
Paul's Security Weekly TV
Security Weekly #480 - Security News from 2016-09-11T09:00

DHS urges vigilance in protecting networking gear, How spoofing an ethernet adapter lets you sniff PC credentials, and FAA considers a ban on Samsung's exploding smartphones. All that and more, ...

Listen
Paul's Security Weekly TV
Security Weekly #480 - Tech Segment: ODROID C2 vs. Raspberry PI 3 from 2016-09-10T09:00

Which hardware is best for your next nerdy security (or non-security) project? The Security Weekly crew will discuss the differences between two of the new model embedded Linux boards on the mar...

Listen
Paul's Security Weekly TV
Security Weekly #480 - Marcus J. Ranum, Tenable Inc. from 2016-09-09T18:27:47

Marcus J. Ranum works for Tenable Security, Inc. and is a world-renowned expert on security system design and implementation. He has been involved in every level of the security industry from pr...

Listen
Paul's Security Weekly TV
Hack Naked News #90 - September 8, 2016 from 2016-09-08T20:01:27

Gucifer, Sophos Blue Screen, and Sundown Exploit Kit here on Hack Naked TV!

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Security Weekly #479 - Security News from 2016-09-04T09:00

A new take on Windows 10, One million IoT devices infected by Bashlite malware-driven DDoS botnet, Encryption Technology Causes More Cyber Attacks? All that and more, so stay tuned!

Full ...

Listen
Paul's Security Weekly TV
Security Weekly #479 - Listener Feedback: Magic Wiffle Dust from 2016-09-03T09:00

Data security either on premise or in the cloud and the merits of each.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode479#Listener_Feedback:_Magic_Wiffle_Dust_-_6:...

Listen
Paul's Security Weekly TV
Security Weekly #479 - Josh Corman, Cyber Statecraft Initiative from 2016-09-02T19:04:43

Joshua Corman is Director of the Cyber Statecraft Initiative for the Atlantic Council. He co-founded @RuggedSoftware and @IamTheCavalry to encourage new security approaches in response to increa...

Listen
Paul's Security Weekly TV
Hack Naked News #89 - September 1, 2016 from 2016-09-02T09:00

Aaron talks with Paul Paget, CEO of Pwnie Express, about the Pwn Phone being on the USA network hit show Mr. Robot.

Full Show Notes:
http://wiki.securityweekly.com/wiki/index.php/Ha...

Listen
Paul's Security Weekly TV
Hack Naked News #88 - August 30, 2016 from 2016-09-01T09:00

Ios Zero Days, Russian Hacker convicted in the US, and a certificate authority makes a blunder. Here on Hack Naked TV!

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Security Weekly #478 - Security News from 2016-08-30T09:00

Facial recognition, VxWorks, Leaked Shadowbrokers, Bitcoin, and much more on Security Weekly!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode478#Security_News_-_6:3...

Listen
Paul's Security Weekly TV
Security Weekly #478 - Heather Mahalik, SANS from 2016-08-29T17:54:04

Heather Mahalik is leading the forensic effort as a Principal Forensic Scientist for ManTech CARD.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode478#Interview:_Hea...

Listen
Paul's Security Weekly TV
Security Weekly #478 - Listener Feedback, A Host's Perspective from 2016-08-29T09:00

Listener feedback segment will be The Host's Perspective, common questions we've asked our guests will be answered by some of the hosts!

Full Show Notes: http://wiki.securityweekly.com/wi...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #13 - News from 2016-08-28T09:00

Threat Intelligence gets funding, Security products in the cloud, incorporating virus totaling in your products, two factor authentication for voice-over IP.

Full Show Notes: http://wiki....

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #13 - To MSSP or not to MSSP from 2016-08-27T09:00

To MSSP or not to MSSP is the question. All that and more on Enterprise Security Weekly!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode13
Visit http://sec...

Listen
Paul's Security Weekly TV
Hack Naked News #87 - August 25, 2016 from 2016-08-26T18:53:47

Updates on the Shadowbroker dump, Malware on Wiki Leaks, and some brand new ransomware!

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Hack Naked News #86 - August 24, 2016 from 2016-08-24T17:01:26

Juniper joins Cisco and Fortigate, US and Canada store were infected by malware, and DARPA Cyber Grand Challenge that ran at DEFCON.

Visit http://hacknaked.tv to get all the latest episod...

Listen
Paul's Security Weekly TV
Hack Naked TV - August 22, 2016 from 2016-08-22T17:37:49

Event Viewer UAC bypass, AppWhitelisting Bypass, 80% of Android Devices vulnerable to Hijacking, PowerShell Open Sourced, and Tool of the Week! - DataSploit.

Visit http://hacknaked.tv to ...

Listen
Paul's Security Weekly TV
Security Weekly #477 - Security News from 2016-08-22T09:00

Snowden Thinks Russia Hacked The NSA, How to disable WPAD on Windows so hackers can't hijack your computer, and People Ignore Security Alerts Up To 90% Of The Time. All that and more, so stay Tu...

Listen
Paul's Security Weekly TV
Security Weekly #477 - Interview with Alex Horan, Onapsis from 2016-08-21T09:00

Alex Horan from Onapsis joins us. Alex is a security focused IT professional with strong experience leading and motivating IT teams and departments.

Full Show Notes: http://wiki.securityw...

Listen
Paul's Security Weekly TV
Security Weekly #477 - Listener Feedback from 2016-08-20T09:00

To Be or Not to be A Contractor. A listener of Security Weekly asks Paul and his crew.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode477#Listener_Feedback:_To_Be_o...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #12 - Detecting Rogue In The Enterprise from 2016-08-19T09:00

Integration in the enterprise security space, Cisco cuts its work force, and Pwnie Express Paul Paget.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/ES_Episode12

V...

Listen
Paul's Security Weekly TV
Hack Naked TV - August 18, 2016 from 2016-08-18T21:14:01

Well the “shortage” of IT and InfoSec Professionals made have just been solved by Cisco. Yesterday Cisco announce it is planning to cut 5,500 jobs from its workforce. The layoffs will supposedly...

Listen
Paul's Security Weekly TV
Hack Naked TV - August 16, 2016 from 2016-08-16T19:51:20

NSA hacked by the "Shadowbrokers", Scolex malware, Cerber ransomware, and hacking naked! News on Hack Naked TV!

Visit http://hacknaked.tv to get all the latest episodes!

Listen
Paul's Security Weekly TV
Security Weekly #476 - Security News from 2016-08-15T09:00

Paul, Larry, Joff and Lance discuss the news for the week on Frequent Password Changes Is a Bad Security Idea, Facebook’s favorite hacker is back, Linux malware? That'll never happen, and much m...

Listen
Paul's Security Weekly TV
Security Weekly #476 - Tech Segment, TachyonNet from 2016-08-14T09:00

TachyonNet is a multi-threaded Python tool that has the ability to listen on all 65535 TCP/UDP ports, as well as listen for ICMP traffic.

Full Show Notes: http://wiki.securityweekly.com/w...

Listen
Paul's Security Weekly TV
Security Weekly #476 - Lance James, Flashpoint from 2016-08-13T09:00

Lance James serves as Chief Scientist at Flashpoint where he heads up research and engages in thought leadership. Prior to joining Flashpoint, Mr. James was the Head of Cyber Intelligence at Del...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #11 - Documentation and Quotes from 2016-08-12T16:10:39

This week Logrhythm has a free network monitoring tool, SAP HANA, the hottest technology you didn't see at Blackhat, free anti-ransomware, Beyondtrust product announcement and traps.

Visi...

Listen
Paul's Security Weekly TV
Security Weekly #475 - Security News from 2016-07-31T09:00

This week we talk about Verizon buying Yahoo, Ransomware, Zero Day holes in Lastpass, hackers can sniff your keystrokes from nearby, and vulnerabilities and light bulbs. Stay tuned!

Subsc...

Listen
Paul's Security Weekly TV
Security Weekly #475 - Listener Feedback from 2016-07-30T09:00

We discuss about Jeff, a current listener of Security Weekly, how to maintain working full time in security and having children, getting married, and balancing everything out equally.

Sub...

Listen
Paul's Security Weekly TV
Security Weekly #475 - Federico Kirschbaum from 2016-07-29T17:47:58

Federico Kirschbaum is currently the CTO of Infobyte Security Research, company based in Buenos Aires, Argentina. With more than 10 years of experience researching and pentesting networks, he ha...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #10 - It's For Stupid People from 2016-07-29T09:00

User behavior analytics wins and fails, the top 10 emerging security vendors (according to some), and virtually testing your network, all that and more so stay tuned!

Full Show Notes: htt...

Listen
Paul's Security Weekly TV
Security Weekly #474 - John Kindervag from 2016-07-24T09:00

John Kindervag is a Principal Analyst on the Security and Risk Management team and works out of the Dallas Research Center. John covers various topics in Information Security including PCI Data ...

Listen
Paul's Security Weekly TV
Security Weekly #474 - Security News from 2016-07-23T09:00

This week Paul tells how to cheat in Pokemon Go, everything you need to know about webshells, Mr. Robot easter eggs, and much more! Here on Security News!

Full Show Notes: http: //wiki.se...

Listen
Paul's Security Weekly TV
Security Weekly #474 - Tech Segment: Bluetooth Scanning Using The PwnPad 4 & Blue Hydra from 2016-07-22T17:31:05

While many are focused on securing the network, it could be the devices within your location, not even on the network, that cause security issues. In this segment we talk about a new, open-sourc...

Listen
Paul's Security Weekly TV
Hack Naked TV - July 19, 2016 from 2016-07-20T19:24:08

This week on Hack Naked TV, Beau Bullock talks about OpenSSHd Username Enum vulnerability, Attack of the Printers, there’s no Hacking in Baseball, and Ubuntu forum breached.

Listen
Paul's Security Weekly TV
Security Weekly #473 - Security News from 2016-07-17T09:00

This week on Security News, Paul talks about Pokemon Go, Kaspersky Labs, FBI Malware, Kim Dotcom Plans for 2017, and much more!

Full Show Notes: http://wiki.securityweekly.com/wiki/index....

Listen
Paul's Security Weekly TV
Security Weekly #473 - Bob Stratton, Mach37 from 2016-07-16T09:00

This week, we welcome Bob Stratton! He is a General Partner at Mach37, a startup accelerator investing in information security product companies. Bob is a “repeat offender” with security startup...

Listen
Paul's Security Weekly TV
Security Weekly #473 - Tech Segment: DNS Blackhole Server with Python from 2016-07-16T09:00

Joff will write a Python script that can download malware domain name lists from a URL, and create a DNS blackhole bind9 based configuration file on the domain names obtained.

Full Show N...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #9 - Sniffing Each Others' Farts from 2016-07-15T16:47:45

This week in the news no excuses to go Phish yourself, a services vendor helps you identify risk, the #1 privileged identity management solution (According to some), and a huge blow to the Endpo...

Listen
Paul's Security Weekly TV
Hack Naked TV - July 12, 2016 from 2016-07-12T20:16:09

Aaron Lyons will be talking about S.W.I.F.T. Network, Ransomware, Angler Exploit Kit, and Pokemon Go! Here on Hack Naked TV!

Listen
Paul's Security Weekly TV
Security Weekly #472 - Security News from 2016-07-11T09:00

This week on Security News, Paul, and Jack talk about how Sony, Microsoft, and other gadget makers violate Federal Warranty Laws, Pen Test Partners, FBI, warrant Canarys, and much more! Here on ...

Listen
Paul's Security Weekly TV
Security Weekly #472 - Tech Segment: Blocking Ads and Malware Using Bind DNS from 2016-07-10T09:00

Ads are annoying, malware is bad. pfSense wanted to be Paul's DNS server in order to block host names. Paul built his own DNS and DHCP servers. This is how he did it.

Full Show Notes: htt...

Listen
Paul's Security Weekly TV
Security Weekly #472 - Elizabeth Gossell from 2016-07-09T09:00

Paul talks with Elizabeth Gossell who is a Product Strategist at Tenable with a solid background in network security at both Lockheed Martin and Tenable. All that and more, so stay tuned!

Listen
Paul's Security Weekly TV
Hack Naked TV - July 7, 2016 from 2016-07-08T18:38:03

I’m your host Aaron Lyons and today I’ll be talking about Palo Alto’s upcoming CTF, Update on Symantec’s most recent vulnerabilities, and password sharing conviction.

Listen
Paul's Security Weekly TV
Hack Naked TV - July 5, 2016 from 2016-07-05T19:56:36

Welcome to another episode of Hack Naked TV recorded July 5th 2016. Your host, Aaron Lyons, will be covering Zepto, Facebook, and Privacy Shield. All that and more, so stay tuned!

Listen
Paul's Security Weekly TV
Security Weekly #471 - Security News from 2016-07-03T09:00

This week Paul talks about sharing threat intelligence, Facebook using physical location to suggest friends, interview with an NSA hacker, and much more! So stay tuned!

Full Show Notes: h...

Listen
Paul's Security Weekly TV
Security Weekly #471 - Tech Segment: Building A PfSense Firewall - Part 1 - The Hardware from 2016-07-02T09:00

For your home or small office, everyone needs a firewall! Well, I supposed you don't NEED one, but it helps. More important than just protecting you from curious people on the Internet, there ar...

Listen
Paul's Security Weekly TV
Security Weekly #471 - Interview with Mark Baggett, SANS from 2016-07-01T19:25:47

Mark has more than 28 years of commercial and government experience ranging from Software Developer to CISO. All that and more, so stay tuned!

Full Show Notes: http://wiki.securityweekly....

Listen
Paul's Security Weekly TV
Hack Naked TV - June 30, 2016 from 2016-06-30T21:10:02

I'm your host Aaron Lyons and today I'll be covering password re-use attackes, symantec, and another SWIFT bank heist.

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #8 - Securing "Air Gapped" Networks from 2016-06-30T17:26:41

Cisco makes an acquisition in cloud security, Palerra claims a first in the same space, Crowdstrike bundles prevent breaches? And Barracuda makes it easier to give them money for Next-Gen firewa...

Listen
Paul's Security Weekly TV
Security Weekly #470 - Security News from 2016-06-26T09:00

The security news is flooded this week! Paul talks about ASUS UEFI update driver, Verizon patches serious email flaw, and Tor coders harden the Onion against surveillance. All that and more, so ...

Listen
Paul's Security Weekly TV
Security Weekly #470 - Rick Farina, Pwn Pad 4 from 2016-06-25T09:00

This segment is an interview with Rick Farina, who is an expert in the new Pwn Pad 4. He explains all it's features and perks. Paul will show off the one on set and tell you how you can win a Pw...

Listen
Paul's Security Weekly TV
Security Weekly #470 - Cory Doctorow from 2016-06-24T17:43:26

This week on Security Weekly, Paul, Larry, and Jack Daniel host the interview with none other than Cory Doctorow. Cory Doctorow (craphound.com) is a science fiction author, activist, journalist ...

Listen
Paul's Security Weekly TV
Hack Naked TV - Interview with Don Pezet from 2016-06-23T18:51:53

Welcome to another Hack TV, this episode we have a special interview with Don Pezet from IT Pro. Stay Tuned!

Full Wiki Notes: http://wiki.securityweekly.com/wiki/index.php/Hack_Naked_TV_J...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #7 - Web Application Scanning from 2016-06-23T09:00

This week on Enterprise Security Weekly, tenable makes a strategic partnership to ease authenticated vulnerability scanning, avast announces a much faster antivirus engine, Risksense unveils cyb...

Listen
Paul's Security Weekly TV
Hack Naked TV - June 21, 2016 from 2016-06-22T16:29:42

This week on Hack Naked TV, Beau Bullock talks about Bad Tunnel, GoToMyPC, and how Ransomware is all Javascript. Watch for full stories, here on Hack Naked TV!

Beau teaching SANS SEC504 i...

Listen
Paul's Security Weekly TV
Security Weekly #469 - Tech Segment: Telepresence Robot from 2016-06-19T09:00

The model robot featured in this segment is called a Double Generation One. This Telepresence robot consists of a telescoping rod connecting a Segway like base and an iPad Air 2 head.

Ful...

Listen
Paul's Security Weekly TV
Security Weekly #469 - Security News from 2016-06-18T09:00

This week is a special segment where Paul, Jeff, Doug, and Russell talk about WordPress Patches Zero Day, Hack The Pentagon Shutters 100 Bugs, GitHub, and much more

Full Show Notes: http:...

Listen
Paul's Security Weekly TV
Security Weekly #469 - Russell Beauchemin from 2016-06-17T16:57:19

Russell is a graduate of RIC with a B.A. in English, minor in Chem, M.A. in Media Studies, and currently pursuing his PhD in Education at Lesley University.

Full Show Notes: http://wiki.s...

Listen
Paul's Security Weekly TV
Hack Naked TV - June 16, 2016 from 2016-06-17T00:49:40

I'm your host Aaron Lyons and today I'll be covering Microsoft, hard drive decryption, ISIS hackers, and GitHub.

Listen
Paul's Security Weekly TV
Hack Naked TV - June 14, 2016 from 2016-06-14T19:50:50

Welcome to another episode of Hack Naked TV. Recorded June 14th 2016. Aaron Lyons will be covering Symantec buying Bluecoat, Microsoft buying linkedin, Michael Thomas and the CFAA, and the Penta...

Listen
Paul's Security Weekly TV
Security Weekly #468 - Chris Poulin, X-Force from 2016-06-11T09:00

Security Weekly has a special co-host, Russell Beauchemin who will be in studio with Larry and our guest Chris Poulin.

Full Show Notes:
http://wiki.securityweekly.com/wiki/index.php...

Listen
Paul's Security Weekly TV
Security Weekly #468 - Security News from 2016-06-10T01:04:24

Larry is on the show with Russell and Chris, and they discuss Security News for the week! They talk about Typo squatting package managers, 20 years of red teaming, Spear Phishing, Infosec is a s...

Listen
Paul's Security Weekly TV
Security Weekly #468 - Russell Beauchemin, Hololens from 2016-06-10T00:09:07

We have a special co-host on the show, Russell Beauchemin, IT Instructor II at Year Up. Larry will discuss with Russell about his new Hololens!

Listen
Paul's Security Weekly TV
Security Weekly #467 - Security News from 2016-06-07T09:00

Security news this week will uncover password breaches galore, Facebook listening to your conversations. Also, congrats! You got a new laptop! And a boatload of vulnerabilities out of the box!

Listen
Paul's Security Weekly TV
Security Weekly #467 - Listener Feedback, Crypto from 2016-06-06T21:00

In this listener feedback segment, we will answer the question "should you implement your own Crypto?"

Listen
Paul's Security Weekly TV
Security Weekly #467 - Jon Searles and Will Genovese, BSides Security from 2016-06-06T09:00

This week we interview Jon Searles and Will Genovese, the founders of the NESIT hacker space and organizers of Bsides Connecticut.

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #6 - IDS/IPS from 2016-06-04T09:00

This week is, well, rough, ServiceNow buys threat intelligence company, memory scanning in the hypervisor, and next-generation network segmentation and NAC, and John and I discuss the evolution ...

Listen
Paul's Security Weekly TV
Security Weekly #466 - Security News from 2016-06-02T21:00

Paul discusses on this Security News segment, Jeremiah Grossman, Apple hires crypto-wizard Jon Callas to beef up security, Google To Kill Passwords On Android, and a ton more from our other gues...

Listen
Paul's Security Weekly TV
Security Weekly #466 - Listener Feedback from 2016-06-02T09:00

This week on Security Weekly, we answer more of your questions! Paul, Jack, Jeff, and Larry answer the listeners feedback, here on Security Weekly!

Listen
Paul's Security Weekly TV
Security Weekly #466 - Wade Baker from 2016-06-01T21:00

Wade Baker is the Vice President, Strategy and Risk Analytics at ThreatConnect. He believes improving information security starts with improving security information. In keeping with this belief...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #5 - "SEIM" from 2016-05-31T21:00

"Cyber Deception" comes to Defcon and IoT, Cisco makes a push for Voice over WiFi, Sumo Logic monitors your Lambdas, and identity management integrates with SEIM? All that and more so stay tuned...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #4 - Patch Management from 2016-05-30T09:00

Two vulnerability management vendors announce integrations with ServiceNow, "Cyber Deception" firm illusive networks raises 3 million in funding, CA Identity Suite adds real-time analytics to st...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #3 - Vulnerability Management from 2016-05-29T09:00

Do you know how to manage security vulnerability? Paul and John Strand educate on the topic of vulnerability management. They explain how to have control of patching and have mitigation control....

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #2 - Threat Intelligence from 2016-05-28T09:00

Do you know what Macworld and Cloudflare are? Paul and John Strand talk about these topics and Threat Intelligence!

http://wiki.securityweekly.com/wiki/index.php/ES_Episode2

Securi...

Listen
Paul's Security Weekly TV
Security Weekly #465 - Security News from 2016-05-27T09:00

Need a more in-depth News coverage? Here on Security Weekly we stay up-to-date on the latest Stories! Hear about LinkedIn Zombies, Top 10 Security Podcasts, When encryption is not enough for HIP...

Listen
Paul's Security Weekly TV
Security Weekly #465 - Listener Feedback from 2016-05-26T09:00

Do you have any questions for the Security Weekly Team? Here are some of our listener's asking questions!

Listen
Paul's Security Weekly TV
Security Weekly #465 - Neil Wyler, Grifter from 2016-05-25T09:00

Do you know the elusive Grifter? He's a Hacker, Geek, DEFCON & Black Hat CFP Review Board Member, DEFCON Contest\Village\Events Lead Goon, Black Hat Staff, DC801 Founder, and a 801Labs Hackerspa...

Listen
Paul's Security Weekly TV
Enterprise Security Weekly #1 - Threat Hunting from 2016-05-24T09:00

Paul and John Strand begin a new series here on Security Weekly. They delve into Threat Hunting, FireEye, Tripwire IP360, and much more. Check this prime OG Episode of Enterprise Security Weekly...

Listen
Paul's Security Weekly TV
Security Weekly #464 - Douglas White, Ph.D. from 2016-05-15T16:00

Doug White was the first certified instructor for the ISFCE digital forensics boot camps and has worked for a variety of professional training organizations and corporations teaching and working...

Listen
Paul's Security Weekly TV
Security Weekly #464 - Stories of the Week from 2016-05-14T16:00

Want to know the security news for the week? Paul and the gang cover a wide variety of stories that involve news, bug bounties, and creative personal stories! Here this weeks special about Pornh...

Listen
Paul's Security Weekly TV
Security Weekly #464 - Tech Segment, Listener Feedback from 2016-05-13T16:25:31

This is a special Tech Segment where we answer some listeners questions and the professionals will answer the questions on the show! Only here, on Security Weekly!

Listen
Paul's Security Weekly TV
Security Weekly #463 - Interview with Ferruh Mavituna from 2016-05-10T16:00

Do you want to know the inside scoop of Netsparker? Watch us interview Ferruh Mavituna who is in the security industry for well over a decade and his ambition to ease the process of automaticall...

Listen
Paul's Security Weekly TV
Security Weekly #462 - Interview with Sean Metcalf from 2016-05-09T16:18:38

Our guest on the show will be Sean Metcalf! Sean Metcalf is a Microsoft Certified Master/Microsoft Certified Solutions Master in Directory Services which is an elite group of Active Directory ex...

Listen
Paul's Security Weekly TV
Security Weekly #463 - Tech Segment, Amazon from 2016-05-09T15:04:21

Want to find the dirt on Amazon and how they manage security? Apollo Clark discusses user access and how to adhere to the best practices of security.

Listen
Paul's Security Weekly TV
Security Weekly #463 - Stories of the Week from 2016-05-06T15:59:38

Wonder how safe your comments really are? A 10 year old boy discovers vulnerability in Instagram comments. We have Paul, Apollo, Larry, Joff, and Santarcangelo on the show to debate some sensual...

Listen
Paul's Security Weekly TV
Security Weekly #462 - Stories of the Week from 2016-05-02T15:38:31

Paul chats with Joff, Carlos, and NotKevin about In the Press:
Redmond Magazine published an article on PowerShell security
quoting my post on Detecting Offensive PowerShell Attack Tools...

Listen
Paul's Security Weekly TV
Security Weekly #461 - Jeff's Round Table from 2016-04-23T16:00

This week Jeff comes on the show and hosts Jeff's Round Table. He talks about Google Play Music, Jedi Conference, vulnerability management venders, and integrations into asset discovery. All tha...

Listen
Paul's Security Weekly TV
Security Weekly #461 - Stories of the Week from 2016-04-22T19:45:46

Paul, Jeff, Santarcangelo, and Joff tell bad jokes! They tell about throwing out advice, but having lack of planning. They also talk about breaching and penetration testing.

Listen
Paul's Security Weekly TV
Hack Naked TV - April 21, 2016 from 2016-04-21T20:20:13

Aaron Lyons will be covering the recent sentencing of some malicious insiders, and the creators of the the SpyEye botnet creator.

Listen
Paul's Security Weekly TV
Security Weekly #460 - Stories of the Week from 2016-04-17T16:00

This Stories of the week episode 'CyberUL' Launched For IoT, ZDNet, Ars Technica, and Hack the World. All that and more, here on Security Weekly.

Listen
Paul's Security Weekly TV
Security Weekly #460 - Interview with Lee Holmes, Powershell from 2016-04-16T16:00

Lee Holmes is the lead security architect of Microsoft's Enterprise Cloud Group, covering Windows Server, Azure Stack, System Center, and Operations Management Suite. He is author of the Windows...

Listen
Paul's Security Weekly TV
Security Weekly #460 - Tech Segment, MSF Venom from 2016-04-15T17:42:33

This Tech Segment is performed, by our own Joff Thyer.

Listen
Paul's Security Weekly TV
Hack Naked TV - April 8, 2016 from 2016-04-12T18:01:42

Welcome to another episode of Hack Naked TV recorded April 8th 2016. Aaron covers the Panama Papers, Cyber-Insurance, Ransomware, Hacking Team, and the Pentagon's bug bounty program.

Listen
Paul's Security Weekly TV
Security Weekly #459 - Stories of the Week from 2016-04-10T16:00

Paul, Larry, and Apollo talk about their stories about security hacks in China's firewall, malware for your car, and much more!

Listen
Paul's Security Weekly TV
Security Weekly #459 - Technical Segment - Apollo Clark from 2016-04-09T16:00

This Tech Segment is presented by Apollo Clark. He gives tips on teaching material, the VPN, researching, and self-training. Stay alive for more on Security Weekly!

Listen
Paul's Security Weekly TV
Security Weekly #459 - Interview with James Lyne from 2016-04-08T17:19:54

We interview James Lyne from SANS. He comes from a background in cryptography but over the years has worked in a wide variety of security problem domains including anti-malware and hacking. Jame...

Listen
Paul's Security Weekly TV
Hack Naked TV - April 7, 2016 from 2016-04-07T21:02:14

This week Paul takes the place of Aaron Lyons who is busy fighting Ninja Lamas. Paul discusses Car future Malware, Ubuntu Patches Kernel Vulnerabilities, OSVDB Shuts Down For Good, Flash zero-da...

Listen
Paul's Security Weekly TV
Security Weekly #458 - Stories of the Week from 2016-04-03T16:00

This week on Stories of the week Paul and Jack Daniels, talk about Live Journal Hit with Angler exploit kit, and FBI investigates hacks against U.S. law firm. They talk about a lot more. Stay tu...

Listen
Paul's Security Weekly TV
Security Weekly #458 - Interview with Alex Horan from 2016-04-02T18:00

This week we talk with Alex Horan from Onapsis. He is a security focused IT professional with strong experience leading and motivating IT teams and departments.

Listen
Paul's Security Weekly TV
Hack Naked TV - March 31, 2016 from 2016-04-01T17:02:48

This week on Hack Naked TV Aaron Lyons talks about FBI vs Apple, the new Android bug, Cisco Firepower/Snort IDS, and ransomware.

Listen
Paul's Security Weekly TV
Security Weekly #457 - Interview with Ferruh Mavituna from 2016-03-31T05:00

This week on Security Weekly, we talk with Ferruh from Netsparker. He explains how he can scan 1,000 websites simultaneously and what he does with the information he collects from the websites. ...

Listen
Paul's Security Weekly TV
Security Weekly #457 - Stories of the Week from 2016-03-30T15:32:02

Security Weekly covers the topics of Internet privacy, bugs in CCTV software, a TP-Link firmware block, and much more! Stay tuned.

Listen
Paul's Security Weekly TV
Security Weekly #457 - Technical Segment from 2016-03-29T20:51:39

On this Tech Segment, Paul talks about Scanning websites with Nmap.

Listen
Paul's Security Weekly TV
Hack Naked TV - March 24, 2016 from 2016-03-24T17:12:09

This week Beau reviews SANS Netwars. He also talks about CTFs.

Listen
Paul's Security Weekly TV
Security Weekly #456 - Interview with Jared Atkinson from 2016-03-19T16:00

This week on Security Weekly, we talk with Jared Atkinson, who is the Hunt Capability Lead with Veris Group's Adaptive. Passionate about PowerShell and the Open Source community, Jared is the le...

Listen
Paul's Security Weekly TV
Security Weekly #456 - Stories of the Week from 2016-03-18T18:15:50

Paul, Larry, Jeff, Joff and NotKevin talk about remote sex toys! Control your toys through phones or tablets. These devices getting hacked and Vulnerability Scanners Turn Up Mostly False Positiv...

Listen
Paul's Security Weekly TV
Hack Naked TV - March 17, 2016 from 2016-03-17T19:45:25

This week on Hack Naked TV, Aaron Lyons talks about FBI's most wanted hackers, Google's Bug, the Home Depot data breach, man-in-the-middle attacks, and ransomware.

Listen
Paul's Security Weekly TV
Security Weekly #455 - Interview with Dennis Fisher from 2016-03-13T16:00

Paul, Larry, and Jack talk with Dennis Fisher from Pindrop and On the Wire. Dennis expalins what are some of the more interesting trends in security news and how to overcome major problems in hi...

Listen
Paul's Security Weekly TV
Security Weekly #455 - Stories of the Week from 2016-03-11T18:56:22

Paul and the gang talk about the Erin Andrews, Big news, why your security tools are exposing you to added risks, patch management, and much much more! Stay tuned into Security Weekly Stories of...

Listen
Paul's Security Weekly TV
Hack Naked - March 10, 2016 from 2016-03-10T20:00:26

Listen
Paul's Security Weekly TV
Hack Naked TV - March 10, 2016 from 2016-03-10T19:42:27

Aaron Lyons talks about Tor, Apple ransomware, the banning of Kali, and fake facebook profiles. Check all that and more, here on Hack Naked TV!

Listen
Paul's Security Weekly TV
Security Weekly #454 - Paul's Big News and Interview w/ Inguardians from 2016-03-08T20:00

This week Paul makes a big announcement! We are lucky to have several of the fine folks at Inguardians come on the show and share their wisdom and knowledge on the topic of perimeter protection....

Listen
Paul's Security Weekly TV
Security Weekly #454 - Stories of the Week from 2016-03-08T08:00

Stories of the week include DROWN, cool tools for analyzing firmware and Z-Wave, and much more!

Listen
Paul's Security Weekly TV
Hack Naked TV - 3/3/2016 from 2016-03-07T17:19:29

This week on Hack Naked TV, Aaron Lyons does a follow up on Apple and the FBI, Cross-site Scripting, the Drown Attack, and a brief blurb about Infosec.

Listen
Paul's Security Weekly TV
Security Weekly #453 - Stories of the Week from 2016-03-01T17:21:40

On Security Weekly, Paul, Larry, and Mike talk about the Hacker Summer Camp Planning Guide, Open DNS Blogs, wireless mics and keyboards, and excessive amounts of lube! The best place to get info...

Listen
Paul's Security Weekly TV
Security Weekly #453 - Interview with Jeff Frisk and Jeff Pike from 2016-02-26T20:03:12

This week on Security Weekly we interview Jeff Pike and Jeff Frisk from SANS GIAC. Paul and Larry talk about 'digital badges', CPEs, and SANS training. Watch the whole episode for more informati...

Listen
Paul's Security Weekly TV
Hack Naked TV - February 18, 2016 from 2016-02-24T20:00

Norse Corp followup, DHS and FBI Employee info leak, ENCRYPT Act, and Hackers aren't smart.


Show notes for this episode: http://wiki.securityweekly.com/wiki/index.php/Hack_Naked_TV_Fe...

Listen
Paul's Security Weekly TV
Security Weekly #452 - Security News from 2016-02-24T08:00

Carlos, Michael, Joff, NotKevin, Jack and Paul talk about the government order to weaken 5c security, the glibc bug, shiny new instagram 2FA, and a whole lot more!

Listen
Paul's Security Weekly TV
Security Weekly #452 - DIY Routers with Joff from 2016-02-23T20:00:45

This week Joff talks with Larry, Carlos, Michael and Paul about building DIY linux-based routers.

Listen
Paul's Security Weekly TV
Security Weekly #451 - Stories of the Week from 2016-02-14T23:00

This week on Security Weekly, we hear Joff's Hacker Haiku. They discuss D-Link, ASUS Router Administration, Weird Fitbit data, and more! Watch for the latest scoop.

Listen
Paul's Security Weekly TV
Hack Naked TV: February 19, 2016 from 2016-02-14T11:00

Today on Hack Naked TV, Aaron will be talking about some Holiday DDoS attacks, Fortigate backdoors, Ubuntu Privileged escalations, and Shodan the big threat to security.

Listen
Paul's Security Weekly TV
Security Weekly #447 - Stories Of The Week from 2016-02-14T11:00

This week Carlos, Jack, Michael, Joff, Paul and Larry talk about Windows updates, Sean Penn, WordPress XSS, Windows compatibility issues, TrendMicro's node.js password manager (now featuring arb...

Listen
Paul's Security Weekly TV
Security Weekly #450 - Interview with Patrick Heim, Dropbox Head of Security from 2016-02-13T11:00

This week on Security Weekly, we interview Patrick Heim who is the Dropbox Head of Security. Listen in as we dive deep into the intricacy of Dropbox.

Listen
Paul's Security Weekly TV
Security Weekly #449 - Security News from 2016-02-12T23:00

We talk about the dangers of selfies, the FTC coming to our rescue encouraging open source for IOT devices and so much more! Jack, Paul, Larry, Not Kevin, Essobi and Apollo host.

Listen
Paul's Security Weekly TV
Hack Naked TV: February 12, 2016 from 2016-02-12T19:28:14

Today on Hack Naked TV, Beau talks about Cash for Creds, Gmail Warnings, IRS PIN Compromise, and Cisco ASA RCE. Here on Hack Naked TV!

Listen
Paul's Security Weekly TV
Security Weekly #451 - Interview with Mike Strouse from 2016-02-12T17:00

This week on Security Weekly, we introduce Mike Strouse who is the CEO of ProXPN. He explains how he got started in ProXPN and more!

Listen
Paul's Security Weekly TV
Security Weekly #449 - Interview with Essobi from 2016-02-12T11:00

On this episode, we talk about scanning the internet, android vulnerabilities, mini UPNPD vulnerabilities, hackers and heroine to Brian Krebs. Much much more, on Paul's Security Weekly!

Listen
Paul's Security Weekly TV
Security Weekly #448 - Security News from 2016-02-11T23:00

This week on Security News, Paul and friends talk about the Top story of the week where HG Moore is leaving Rapid7 and threatbutt! They also discuss threat intelligence and passwords.

Listen
Paul's Security Weekly TV
Hack Naked TV - February 4, 2016 from 2016-02-10T21:20:49

This week on Hack Naked TV, Aaron will be talking about Norse Co., Java, Cyber Terrorism, and Safe Harbor.

Listen
Paul's Security Weekly TV
Hack Naked TV - January 26, 2016 from 2016-01-27T21:00

This week Aaron Lyons talks about Trustwave being sued over Incident Response, HD Moore leaving Rapid 7, Safe Harbor deadline looms, Kali rolling distro released, and Sony Entertainment and Sony...

Listen
Paul's Security Weekly TV
Hack Naked TV - January 22, 2016 from 2016-01-26T20:39:48

Beau talks about Backdoor in AMX, Linux Kernel Vuln, Apple Sharing Cookies, Hot Potato, Backhat 2016 Course, BSides Orlando.

Listen
Paul's Security Weekly TV
Security Weekly #447 - Interview with Chris Domas from 2016-01-22T17:25:17

This week we interview Chris Domas. Chris is a researcher interested in reverse engineering and exploitation. He joins us to talk about visualizing binaries, accessing ring -2 and making reverse...

Listen
Paul's Security Weekly TV
Security Weekly #446 - Stories of the Week from 2016-01-14T17:00

This week Paul, Larry, John, Joff and special guest star Adrien talk
about Juniper backdoors, the "biggest" security threats for 2016, axing
Internet Explorer and Uber fines for data...

Listen
Paul's Security Weekly TV
Security Weekly #446 - Interview With Adrien de Beaupre from 2016-01-13T19:44:22

This week we interview Adrien de Beaupre, a SANS instructor and
Internet Storm Center handler. Adrien has been researching the security
of HTTP/2 and even does a live demo! We put ou...

Listen
Paul's Security Weekly TV
Hack Naked TV: Januray 8, 2016 from 2016-01-12T19:40:37

This week Beau talks about malicious Google Play apps, Comcast home security systems, attacking ICS and MS15-132

Listen
Paul's Security Weekly TV
Security Weekly #445 - Sharon Goldberg from 2015-12-22T17:00

This week we're joined by Sharon Goldberg, an associate professor in the Computer Science Department at Boston University, and a member of the Listen

Paul's Security Weekly TV
Hack Naked TV December 17 2015 from 2015-12-21T17:00

Welcome to another episode of Hack Naked TV recorded December 17th 2015. Aaron talks about the FBI using 0-Days, Drone Registration, Root DNS attack, and RCE in FireEye.

Listen
Paul's Security Weekly TV
Security Weekly #445 - News from 2015-12-20T17:00

Paul, Joff and Not Kevin talk about registering drones, reply to all, CISA and much more!

Listen
Paul's Security Weekly TV
Hack Naked TV: November 20, 2015 from 2015-12-20T17:00

Welcome to another episode of Hack Naked TV recorded November 20th 2015. Today Beau talks Bitlocker bypass, Gmail address spoofing and more.

Listen
Paul's Security Weekly TV
Security Weekly #444 - Stories of the Week from 2015-12-19T17:00

This week we talk about the quest to reveal the identity of Bitcoin's creator, DDoSing the root name servers and much more!

Listen
Paul's Security Weekly TV
Security Weekly #444 - Pen Testing 5 Questions with John Strand from 2015-12-18T17:00

John Strand answers Paul's 5 tough questions on penetration testing. With Larry Pesce and Jeff Man.

Security Weekly Web Site: http://securityweekly.com

Hack Naked Gear: http://shop...

Listen
Paul's Security Weekly TV
Security Weekly #444 - Ed Skoudis Holiday Hack Challenge from 2015-12-17T17:00

Ed Skoudis joins us via Skype to talk about the all new 2015 Holiday Hack Challenge! Ed also answers the all new 5 Questions, not to be missed!


Security Weekly Web Site: http://securi...

Listen
Paul's Security Weekly TV
Hack Naked TV December 10, 2015 from 2015-12-11T17:00

Welcome to another episode of Hack Naked TV recorded December 10th 2015. Today Aaron talks about Cybersecurity Information Sharing Act, Kazakhstan, Flash updates, encryption backdoors, and cyber...

Listen
Paul's Security Weekly TV
Hack Naked TV: December 2, 2015 from 2015-12-10T20:58:39

Welcome to another episode of Hack Naked TV recorded December 2nd 2015. Today Aaron talks about Dell root certificate fiasco, Hacking Back being reviewed by the government, the LANDesk breach, n...

Listen
Paul's Security Weekly TV
Security Weekly #443 - Interview with Micah Zenko from 2015-12-07T13:59:46

Micah Zenko, a senior fellow at the Council on Foreign Relations and author of the new book "Red Team: How to Succeed By Thinking Like the Enemy." We talk to Micah about techniques to prevent do...

Listen
Paul's Security Weekly TV
Security Weekly News #442 - Failed Windows 3.1 and Hacking Back from 2015-11-20T17:00

Security news this week we talk about the latest iThing, this one brews your coffee. Find out why its a bad idea to run Windows 3.1 in your environment, or Windows NT. Paul goes back in time, ta...

Listen
Paul's Security Weekly TV
Security Weekly #442 - Interview with Ferruh Mavituna from 2015-11-19T17:00

Security Weekly brings back Ferruh Mavituna to discuss SLDC and writing vulnerable command injection in PHP. For a full list of topics discussed, visit our wiki: http://wiki.securityweekly.com/w...

Listen
Paul's Security Weekly TV
Hack Naked TV: November 19, 2015 from 2015-11-19T17:00

Welcome to another episode of Hack Naked TV recorded November 19th 2015. Today Aaron talks about encrypted communications in the Paris terrorist attacks, Google security news, Comcast password r...

Listen
Paul's Security Weekly TV
Security Weekly News #441 - IoT Security In Alarm Clocks from 2015-11-16T15:30

Security news this week features the unmasking of TOR users, an alarm clock that slaps you around and more. For a full list of stories, visit our wiki: http://wiki.securityweekly.com/wiki/index....

Listen
Paul's Security Weekly TV
Security Weekly #441 - Interview with Miron Livny and Barton Miller from 2015-11-13T02:36:28

This week, we interview Miron Livny and Barton Miller of SWAMP. SWAMP simultaneously alleviates the costs, maintenance and licensing burdens of tools, while also eliminating the need to learn nu...

Listen
Paul's Security Weekly TV
Security Weekly News #440 - Canadian Encryption from 2015-11-11T19:30

This week, Paul and the crew discusses the million dollar bug bounty for iPhones and why it may be legal to hack your car. For a full list of stories talked about during the show, visit our wiki...

Listen
Paul's Security Weekly TV
Security Weekly #440 - Interview with Michael Bazzell from 2015-11-10T11:30

This week we interview Michael Bazzell author of "Open Source Intelligence Techniques", "Hiding from the Internet" and the technical advisor for TV hacker drama "Mr. Robot" on the USA network. <...

Listen
Paul's Security Weekly TV
Hack Naked TV - November 9, 2015 from 2015-11-09T14:30

Today Beau talks about vBulletin RCE, PageFair serving malware, and a million dollar bug bounty for iOS 9.  For a full list of stories visit http://wiki.securityweekly.com/wiki/index.php/Hack_Na...

Listen
Paul's Security Weekly TV
Security Weekly News #439 - Chip and Pin Hacked from 2015-11-03T16:00

This week in the news we learn about how chip and pin was hacked in France and are you fooled by fake online reviews? For a full list of stories including links, visit the wiki http://wiki.secur...

Listen
Paul's Security Weekly TV
Security Weekly #439 - Making The Most Of Threat Intelligence from 2015-11-02T15:00

This week, Paul and Mike discuss the current state of threat intelligence. In this segment, Paul and Mike dive deep in using threat intelligence properly.

Security Weekly Web Site: ht...

Listen
Paul's Security Weekly TV
Hack Naked TV - October 23, 2015 from 2015-11-01T14:00

Today Beau talks about MITM NTP, chip and pin vulnerabilities. and encrypting all the things by default.

For a full list of stories discussed today, visit our wiki: http://wiki.secur...

Listen
Paul's Security Weekly TV
Hack Naked TV - October 20, 2015 from 2015-10-31T14:00

Today Aaron talks about the E-Trade breach, China still hacking the US, CyberInsurance, and More.

Security Weekly Web Site: http://securityweekly.com

Hack Naked Gear: http:...

Listen
Paul's Security Weekly TV
Security Weekly #438 - Hacker Jeopardy from 2015-10-30T13:30

Hacker Jeopardy includes popular topics such as famous hackers and decimal to binary conversions. Test your knowledge now!

Security Weekly Web Site: http://securityweekly.com
Listen

Paul's Security Weekly TV
Security Weekly #438 - Interview wth Peiter "Mudge" Zakto from 2015-10-29T12:30

Peiter C. Zatko, better known as Mudge, is a network security expert, open source programmer, writer, and a hacker. Peiter talks about his start in information security, rather him starting info...

Listen
Paul's Security Weekly TV
Security Weekly #438 - Bug Bounty and Responsible Disclosure from 2015-10-27T14:00

We bring back Samy Kamkar "Samy's My Hero," and bring on special guests Casey Ellis from BugCrowd and Katie Moussouris from HackerOne. We talk about the tough ethical questions and the future of...

Listen
Paul's Security Weekly TV
Security Weekly #438 - Mobile Security and Privacy from 2015-10-26T12:00

We get Simple Nomad and David Schwartzberg to join us for a panel discussion on Mobile Security and Privacy. David Schwartzberg is a Sr. Security Engineer at MobileIron and Simple has been doing...

Listen
Paul's Security Weekly TV
Security Weekly #438 - L0pht Heavy Industries Panel from 2015-10-25T12:00

L0pht Heavy Industries was a hacker collective active between 1992 and 2000 and located in the Boston, Massachusetts area. We learn about the history of the L0pht and the future.


Listen

Paul's Security Weekly TV
Hack Naked TV - October 13, 2015 from 2015-10-21T03:15:26

Today Aaron talks about breaches of LoopPay, Uber, and Dow-Jones.

For a full list of stories, visit our wiki: http://wiki.securityweekly.com/wiki/index.php/Hack_Naked_TV_October_13_20...

Listen
Paul's Security Weekly TV
Security Weekly #438 - Interview with Mikko Hypponen from 2015-10-20T23:36:34

To kick off our ten-year anniversary we interview Mikko Hypponen of F-Secure. We talk about the first virus discovered, reviewing printed viruses, and more.

Visit our wiki for list o...

Listen
Paul's Security Weekly TV
Security Weekly News #437 - Facebook Sex tapes and rooting the OnHub from 2015-10-14T12:30

This week in security news, we talk about Stagefright 2.0, how to root your very own Google OnHub, breaking SHA-1, and AWS WAF's.

For a full list of stories, visit our wiki: http://w...

Listen
Paul's Security Weekly TV
Security Weekly #437 - Interview with Dafydd Stuttard from 2015-10-09T22:26:05

This week, we interview Dafydd Stuttard the creator of Burp Suite and the author of the Web Application hacker's Handbook. We talk about the source of the name "Burp" and the future of webapp sc...

Listen
Paul's Security Weekly TV
Hack Naked TV - October 8, 2015 from 2015-10-09T01:48:09

Brought to you by Black Hills Information Security and Cybrary!
This week Aaron talks about the Experian/T-mobile and Scottrade breaches, Safe Harbor and MORE!


Visit our wi...

Listen
Paul's Security Weekly TV
Hack Naked TV - October 1, 2015 from 2015-10-02T15:00:05

Today Aaron talks about BitPay, OPM, Volkswagen, and new TrueCrypt Flaws. For a full list of stories, visit the wiki: http://wiki.securityweekly.com/wiki/index.php/Hack_Naked_TV_October_1_2015#A...

Listen
Paul's Security Weekly TV
Security Weekly #435 - Password Cracking with Larry from 2015-10-02T14:29:37

This week on Security Weekly, we are joined by none other than Larry Pesce. After his recent DerbyCon talk, Larry gives us some insight on his 600 dollar password cracking machine.


 <...

Listen
Paul's Security Weekly TV
Hack Naked TV - September 23, 2015 from 2015-09-26T12:00

This week on Hack Naked TV Beau talks iOS malware, Kaspersky vulnerabilities in their AV engine and more. Links to all stories are below.


Android Screen Lock Bypass - http://sit...

Listen
Paul's Security Weekly TV
Security Weekly #435 Security News - Exploding Chips and Cisco Routers from 2015-09-24T13:00

Today in the news we discuss an Apple iOS directory traversal vulnerability in AirDrop. Also in Security News is the Facebook 'Dislike' button. Not to be confused with with a downvote, more alon...

Listen
Paul's Security Weekly TV
Security Weekly #435 - Interview with Josh Pyorre from 2015-09-18T17:57:21

This week interview Josh Pyorre from OpenDNS on honeypots and malware. Josh  is a security analyst with OpenDNS. Josh has presented at Defcon, multiple Bsides across the USA and Source Boston. Listen

Paul's Security Weekly TV
Hack Naked TV - September 15, 2015 from 2015-09-15T19:32:12

Brought to you by Black Hills Information Security and Cybrary!
This week Aaron talks about the Ubiquity email scam, the Excellus BCBS breach, Netflix dumping antivirus, McAfee for Presiden...

Listen
Paul's Security Weekly TV
Hack Naked TV - September 11, 2015 from 2015-09-12T12:25:19

Listen

Paul's Security Weekly TV
Hack Naked TV - September 8, 2015 from 2015-09-09T18:38:58

Brought to you by Black Hills Information Security and Cybrary!


 


This week Aaron talks about the OPM breach, Windows 10 data collection be...

Listen
Paul's Security Weekly TV
Security Weekly #433 - Talking Security Outside The Echo Chamber from 2015-09-08T00:00

This week Larry and Jack join Paul in studio, Carlos is on via Skype without a shirt and none other than Google-Image-Search-John-Strand joins us...from his car none the less! 


Jack r...

Listen
Paul's Security Weekly TV
Security Weekly #432 News - Hacked "Smart" Fridge, More Ashley Madison from 2015-09-05T13:00

Jack gets into full rant mode in this segment, where we cover some more news about the epic Ashley Madison breach, Smart fridge that gets hacked, and more!


 


Show Notes: ht...

Listen
Paul's Security Weekly TV
Security Weekly #433 Security News - Password Cracking and UPnP Exploits from 2015-09-04T16:03:23

This week, we talk about a recent article describing how to crack the passwords resulting from the Ashley Madison breach. Paul's prediction of UPnP being used for evil is in the news, this time ...

Listen
Paul's Security Weekly TV
Security Weekly #432 - Jack Daniel's Uplifting Rants from 2015-09-04T13:00

No seriously, Jack was in rare form: Uplifting, sympathetic, offering help, and dare I s...

Listen
Paul's Security Weekly TV
Hack Naked TV - September 1, 2015 from 2015-09-03T12:00

Brought to you by Black Hills Information Security and Cybrary!


This week Aaron talks about the U...

Listen
Paul's Security Weekly TV
Hack Naked TV - Favorite Hacking Tools from 2015-08-31T12:59:11

This week on Hack Naked TV, Beau talks about his top 5 favorite pentest and hacking tools as seen at BlackHat/DefCon/B-Sides.


 


tinyurl.com/HNTV-EMPIRE


tinyurl.c...

Listen
Paul's Security Weekly TV
Episode 431 Stories: Ashley Madison Hack from 2015-08-26T17:00

This week in the news we discuss Googles new Wifi router and finding staff to work for Uber. 


http://wiki.securityweekly.com/wiki/index.php/Episode431#Stories_of_the_Week_-_7:00PM-8:0...

Listen
Paul's Security Weekly TV
Episode 431: Interview with Phil Young and Chad Rikansrud from 2015-08-24T17:00

This week, we interview Bigendian Smalls and the Soldier of Fortran on mainframe hacking. Learn about writing exploits for z/OS and nmap modules. 


 


For additional informat...

Listen
Paul's Security Weekly TV
Episode 430: Interview with Daniel Miessler from 2015-08-17T17:00

Listen

Paul's Security Weekly TV
Hack Naked TV August 13, 2015 from 2015-08-13T19:07:24

This week we talk about bind DoS, Ubiquiti, Kali 2.0, Windows 10, Alphabet, Oracle and more.

Listen
Paul's Security Weekly TV
Episode 429: Defcon is Coming! from 2015-07-31T02:04:23

Defcon is just around the corner and there is a lot happening in the news. For this special segment, we talk about our plans for Defcon in addition to top stories this week including the self ai...

Listen
Paul's Security Weekly TV
Hack Naked TV July 28th 2015 from 2015-07-28T18:15:21

This week on HackNakedTV we talk about StageFright, The Hacking Team and OPM breaches and more.

Listen
Paul's Security Weekly TV
Episode 427: Stories of the Week from 2015-07-18T21:17:21

This week for stories, we discuss authentication bypass in Siemens SICAM MIC, Adobe patches yet another zero-day, and are you ready for forced automatic updates? We are looking at you, Microsoft.

Listen
Paul's Security Weekly TV
Episode 427: Ed Skoudis on NetWars from 2015-07-18T21:16:46

Listen
Paul's Security Weekly TV
Episode 427: Matt Duren from 2015-07-18T21:16:43

This week, we interview Matt Duren who is a technical recruiter for Tenable Network Security. Always looking for talented security engineers, C/C++ engineers, front-end / back-end devs, and securit...

Listen
Paul's Security Weekly TV
Hack Naked TV: Hacker Summer Camp, Hacking Team, Adobe Flash (July 14, 2015) from 2015-07-15T21:10:55

Host Aaron Lyons talks about "Hacker Summer Camp" aka Blackhat, BsidesLV and Defcon conferences, HackingTeam and Adobe Flash.

Listen
Paul's Security Weekly TV
Episode 426: Stories of the Week from 2015-07-12T23:21:47

This week in news we talk about Hacking team hacked, Adobe patches a zero-day, and new OpenSSL certificate chain vulnerability.

Listen
Paul's Security Weekly TV
Episode 426: Andrew Hay from 2015-07-12T23:21:45

This week on Paul's Security Weekly, we interview Andrew Hay. Andrew is the Director of Research at OpenDNS where he leads the research efforts for the company.

Listen
Paul's Security Weekly TV
Episode 425: Stories of the Week from 2015-07-04T23:24:10

For this week in cyber news, we are joined by Apollo Clark in studio mixing drinks. We discuss WiFi sense on Windows 10, why CyberUL is a bad idea (drink), and is Amazon replacing the current TLS l...

Listen
Paul's Security Weekly TV
Episode 425: Information Security Career from 2015-07-04T23:23:26

On this week's discussion, we talk about the top 10 reasons to dive into Information Security as a career.

Listen
Paul's Security Weekly TV
Episode 425: Shay Chen from 2015-07-04T23:21:22

This week, we interview Shay Chen. He currently runs several large-scale researches, published annually:

1) The WAVSEP vulnerability scanner comparison test-bed and annual benchmark, c...

Listen
Paul's Security Weekly TV
Episode 424: Stories of the Week from 2015-06-28T22:28:48

This week for stories, we dive into Samsung woes with their keyboard. We also discuss the ClueBat, the alternative to the Clue by four. We are joined by Not Kevin in studio and Rick Farina hangs wi...

Listen
Paul's Security Weekly TV
Episode 424: Roll Your Own Password Management from 2015-06-28T22:28:33

Listener submitted discussion on pros and cons of rolling your own password manager.

Listen
Paul's Security Weekly TV
Episode 424: Rick Farina from 2015-06-28T22:28:09

This week, we interview Rick Farina who is a well known wireless hacker and member of the DEF CON Wireless Village team and the Wireless Capture the Flag team.



He talks wireless ...

Listen
Paul's Security Weekly TV
Episode 423: Stories of the Week - LastPass Breach, Google Bug Bounty from 2015-06-20T21:35:41

In stories this week, we talk about how to properly handle a security breach (LastPass), and how HackerOne connects hackers with companies. You can view the full list of stories and links in our...

Listen
Paul's Security Weekly TV
Episode 423: Patrick Wardle from 2015-06-20T21:35:37

This week, we interview Patrick Wardle to talk about Mac OS X security. He built a free application called KnockKnock. Find links to his website and twitter on the wiki here: http://wiki.securitywe...

Listen
Paul's Security Weekly TV
Hack Naked TV: OPM Breach, Corporate Espionage, Hacking Hospitals (Week of June 19, 2015 from 2015-06-20T21:27:16

In this episode we talk about the OPM hack, a little bit about corporate espionage, and the possibilities of hackers modifying drug pumps at hospitals to deliver fatal dosages to patients.

Listen
Paul's Security Weekly TV
Episode 422: Security for Startups from 2015-06-13T16:06:23

This week, we feature Apollo Clark in studio to mix up some mojitos and talk about security for startups.

Listen
Paul's Security Weekly TV
Episode 422: Stories of the Week from 2015-06-13T16:05:31

This week, we talk about Apple moving to 6-character passcodes and the OpenSesame attack to open non-rolling code Garage Doors.

Listen
Paul's Security Weekly TV
Episode 422: Ferruh Mavituna from 2015-06-13T16:04:42

CEO / Product Architect Ferruh Mavituna has been working in the application security industry for well over a decade and his ambition to ease the process of automatically detecting web application ...

Listen
Paul's Security Weekly TV
Episode 421: Stories of the Week from 2015-06-10T17:26:33

This week for stories, we are joined by Not Kevin in studio. We discuss what percentage of weapons make it past the TSA, DoS'ing Windows Skype users, and Microsoft to support and include OpenSSH.

Listen
Paul's Security Weekly TV
Episode 421: Stephen Sims from 2015-06-10T17:25:40

Stephen Sims is an industry expert with over 15 years of experience in information technology and security. Stephen currently works out of San Francisco as a consultant performing reverse engineeri...

Listen
Paul's Security Weekly TV
Episode 420: Stories of the Week from 2015-05-31T22:58:15

For this weeks stories, we feature Trey Ford and figure out how to reboot iPhones with just a text message.

Listen
Paul's Security Weekly TV
Episode 420: Byron Cleary from 2015-05-31T22:55:09

Listen
Paul's Security Weekly TV
Episode 419: Stories of the Week from 2015-05-24T00:17:04

Logjam, Wordpress vulnerabability, and more.

Listen
Paul's Security Weekly TV
Episode 419: Gavin Millard from 2015-05-24T00:16:58

This week Gavin Millard from Tenable Network Security joins us to shine a light on Shadow IT, talk about how to get things done in security, and several more topics related to information securi...

Listen
Paul's Security Weekly TV
Episode 418: Stories of the Week from 2015-05-16T20:16:20

Listen
Paul's Security Weekly TV
Episode 418: Security Deathmatch from 2015-05-16T20:16:17

Listen
Paul's Security Weekly TV
Episode 417: Stories of the Week from 2015-05-10T19:17:55

Listen
Paul's Security Weekly TV
Episode 417: Chris Roberts from 2015-05-10T19:17:19

Listen
Paul's Security Weekly TV
Hack Naked TV: Week of May 8, 2015 from 2015-05-08T19:18:09

Listen
Paul's Security Weekly TV
Episode 416: Stories of the Week from 2015-05-03T17:00:49

Listen
Paul's Security Weekly TV
Episode 415: Stories of the Week from 2015-04-27T16:05:18

Listen
Paul's Security Weekly TV
Episode 415: Bash Command-Line Tips from 2015-04-27T16:05:15

Listen
Paul's Security Weekly TV
Episode 415: Apollo Clark from 2015-04-27T16:05:05

Listen
Paul's Security Weekly TV
Episode 414: Stories of the Week from 2015-04-19T18:43:08

Listen
Paul's Security Weekly TV
Episode 414: Israel Barak from 2015-04-19T18:43:06

Listen
Paul's Security Weekly TV
Episode 414: Jon Callas from 2015-04-19T18:43:03

Listen
Paul's Security Weekly TV
Episode 413: Stories of the Week from 2015-04-13T05:08:14

Listen
Paul's Security Weekly TV
Episode 413: Steve Crocker from 2015-04-13T05:06:58

Listen
Paul's Security Weekly TV
Episode 412: John McAfee from 2015-04-07T22:20:45

Listen
Paul's Security Weekly TV
Episode 412: Stories of the Week from 2015-04-06T17:03:24

Listen
Paul's Security Weekly TV
Episode 412: The Dapper Hacker from 2015-04-06T17:03:21

Listen
Paul's Security Weekly TV
Episode 411: Stories of the Week from 2015-03-27T23:53:43

Listen
Paul's Security Weekly TV
Episode 411: Russ McRee from 2015-03-27T23:53:35

Listen
Paul's Security Weekly TV
Episode 410: Stories of the Week from 2015-03-24T02:08:54

Listen
Paul's Security Weekly TV
Episode 409: Stories of the Week from 2015-03-16T02:20:57

Listen
Paul's Security Weekly TV
Episode 409: Keren Elazari from 2015-03-16T02:20:54

Listen
Paul's Security Weekly TV
Episode 408: Stories of the Week from 2015-03-09T17:05:59

Listen
Paul's Security Weekly TV
Episode 408: Jayson Street from 2015-03-09T17:05:57

Listen
Paul's Security Weekly TV
Episode 407: Stories of the Week from 2015-02-23T05:18:07

Listen
Paul's Security Weekly TV
Episode 407: Security Deathmatch from 2015-02-23T05:17:54

Listen
Paul's Security Weekly TV
Episode 406: Stories of the Week from 2015-02-15T02:11:59

Listen
Paul's Security Weekly TV
Episode 406: Interview with Onapsis from 2015-02-15T02:11:57

Listen
Paul's Security Weekly TV
Episode 405: Stories from 2015-02-08T01:37:18

Listen
Paul's Security Weekly TV
Episode 404: Stories from 2015-02-01T05:14:09

Listen
Paul's Security Weekly TV
Episode 403: Stories from 2015-01-26T01:24

Listen
Paul's Security Weekly TV
Episode 403: Paul Henry from 2015-01-26T01:23:58

Listen
Paul's Security Weekly TV
Episode 402: Stories from 2015-01-19T01:54:35

Listen
Paul's Security Weekly TV
Episode 402: Kimberly Crawley from 2015-01-19T01:54:29

Listen
Paul's Security Weekly TV
Episode 401: Stories from 2015-01-10T06:49:52

Listen
Paul's Security Weekly TV
Episode 401: Reuben Paul from 2015-01-10T06:48:40

Listen
Paul's Security Weekly TV
Episode 400: Mike Poor from 2014-12-23T08:19:24

Listen
Paul's Security Weekly TV
Episode 400: Billy Rios from 2014-12-23T08:17:52

Listen
Paul's Security Weekly TV
Episode 400: Marcus Ranum from 2014-12-23T08:17:34

Listen
Paul's Security Weekly TV
Episode 399: Stories of the Week from 2014-12-15T04:36:09

Listen
Paul's Security Weekly TV
Episode 398: Stories of the Week from 2014-12-07T01:18:07

Listen
Paul's Security Weekly TV
Episode 397: Stories of the Week from 2014-11-27T08:31:02

Listen
Paul's Security Weekly TV
Episode 397: Paul Coggin from 2014-11-27T08:30:53

Listen
Paul's Security Weekly TV
Episode 396: Stories of the Week from 2014-11-24T03:32:25

Listen
Paul's Security Weekly TV
Episode 396: Brandon McCann Phishes from 2014-11-24T03:32:22

Listen
Paul's Security Weekly TV
Episode 395: Stories from 2014-11-18T02:49:50

Listen
Paul's Security Weekly TV
Episode 394: Stories from 2014-11-10T08:39:20

Listen
Paul's Security Weekly TV
Episode 393: Stories from 2014-11-03T06:18:57

Listen
Paul's Security Weekly TV
Episode 392: Stories from 2014-10-27T20:20:48

Listen
Paul's Security Weekly TV
Episode 391: Stories from 2014-10-20T07:38:35

Listen
Paul's Security Weekly TV
Episode 390: Stories from 2014-10-15T01:44:25

Listen
Paul's Security Weekly TV
Episode 390: Red Team Field Manual from 2014-10-15T01:44:23

Listen
Paul's Security Weekly TV
Episode 389: Shellshock & Stories from 2014-10-06T02:31:40

Listen
Paul's Security Weekly TV
Episode 389: Rob Wiess on SCADA CTF from 2014-10-06T02:31:37

Listen
Paul's Security Weekly TV
Episode 388: Stories from 2014-09-20T23:40:55

Listen
Paul's Security Weekly TV
Episode 388: Michael Gough from 2014-09-20T23:40:50

Listen
Paul's Security Weekly TV
Episode 387: Stories of the Week from 2014-09-14T21:24:46

Listen
Paul's Security Weekly TV
Episode 386: Stories from 2014-09-06T01:00

Listen
Paul's Security Weekly TV
Episode 386: Powercat Demonstration from 2014-09-06T00:59:56

Listen
Paul's Security Weekly TV
Episode 386: Mike Murray from 2014-09-06T00:59:53

Listen
Paul's Security Weekly TV
Episode 385: Stories from 2014-09-04T17:18:23

Listen
Paul's Security Weekly TV
Episode 384: Stories from 2014-08-22T20:57:35

Listen
Paul's Security Weekly TV
Episode 384: Dave Kennedy from 2014-08-22T20:57:33

Listen
Paul's Security Weekly TV
Episode 384: Sarah Edwards from 2014-08-22T20:57:31

Listen
Paul's Security Weekly TV
Episode 383: Stories from 2014-08-18T19:33:29

Listen
Paul's Security Weekly TV
Episode 382: Stories from 2014-08-04T03:54:32

Listen
Paul's Security Weekly TV
Episode 381: Stories from 2014-07-28T08:18:46

Listen
Paul's Security Weekly TV
Episode 380: Stories from 2014-07-12T22:38:46

Listen
Paul's Security Weekly TV
Episode 380: Bill Swearingen's Meat from 2014-07-12T22:38:35

Listen
Paul's Security Weekly TV
Episode 379: Stories from 2014-07-09T10:35:30

Listen
Paul's Security Weekly TV
Episode 378: Stories from 2014-06-30T08:37:30

Listen
Paul's Security Weekly TV
Episode 378: Hacking Android from 2014-06-30T08:37:27

Listen
Paul's Security Weekly TV
Episode 378: Interview with Onapsis from 2014-06-30T08:37:25

Listen
Paul's Security Weekly TV
Episode 377: Stories of the Week from 2014-06-23T07:51:02

Listen
Paul's Security Weekly TV
Episode 376: Stories from 2014-06-09T06:15:29

Listen
Paul's Security Weekly TV
Episode 376: Scanning DNS with Nmap from 2014-06-09T06:15:27

Listen
Paul's Security Weekly TV
Episode 375: Stories from 2014-06-02T04:10:10

Listen
Paul's Security Weekly TV
Episode 374: Stories from 2014-05-26T05:26:25

Listen
Paul's Security Weekly TV
Episode 374: Embedded Security from 2014-05-26T05:26:19

Listen
Paul's Security Weekly TV
Episode 374: OJ Reeves from 2014-05-26T05:26:14

Listen
Paul's Security Weekly TV
Episode 373: Stories from 2014-05-19T05:16:08

Listen
Paul's Security Weekly TV
Episode 372: Stories from 2014-05-12T02:48:23

Listen
Paul's Security Weekly TV
Episode 371: Stories from 2014-05-05T06:41:23

Listen
Paul's Security Weekly TV
Episode 370: Stories from 2014-04-20T21:11:53

Listen
Paul's Security Weekly TV
Episode 369: Stories from 2014-04-17T19:22:54

Listen
Paul's Security Weekly TV
Episode 368: Stories from 2014-04-17T19:21:45

Listen
Paul's Security Weekly TV
Episode 366: Interview with Gary McGraw from 2014-03-24T00:00:46

Gary McGraw is an author of many books and over a 100 peer-reviewed publications on IT security. In addition, Gary McGraw serves on the Dean’s Advisory Council for the School of Informatics of Indi...

Listen
Paul's Security Weekly TV
Episode 366: Stories from 2014-03-24T00:00:19

Listen
Paul's Security Weekly TV
Episode 366: Wordpress Defacement: Lessons Learned from 2014-03-24T00:00:06

On March 14, 2014 the securityweekly.com website was defaced (index.php was modified) by an attacker at approximately 6:30AM EST. We discovered this attack, via Twitter in fact, at 8:00AM that morn...

Listen
Paul's Security Weekly TV
Hack Naked TV 14-5 from 2014-02-25T12:30:42

Listen

Paul's Security Weekly TV
Episode 353: Guest Interview with Kat Sweet from 2014-02-21T01:04:08

Listen

Paul's Security Weekly TV
Drunken Security News 362 from 2014-02-14T01:22:33

Listen

Paul's Security Weekly TV
Django Source Code Security Scanner - Joff Thyer from 2014-02-14T01:09:14

Listen

Paul's Security Weekly TV
Paul Paget - Pwnie Express - Episode 362 from 2014-02-14T01:01:48

Listen

Paul's Security Weekly TV
Hack Naked TV 14-4 from 2014-02-12T11:55:09

Listen

Paul's Security Weekly TV
Episode 361: Stories from 2014-02-07T02:14:17

Listen

Paul's Security Weekly TV
Episode 361: Interview with Brian Richardson from 2014-02-07T01:07:38

Listen

Paul's Security Weekly TV
Episode 360: Stories from 2014-01-31T02:55:05

Listen

Paul's Security Weekly TV
Episode 360: Tech Segment by Carlos Perez from 2014-01-31T00:17:50

Listen

Paul's Security Weekly TV
Episode 360: Interview with Jared DeMott from 2014-01-31T00:05:01

Listen

Paul's Security Weekly TV
Episode 358: Stories of the Week from 2014-01-26T16:15:32

Listen

Paul's Security Weekly TV
Episode 358: Tech Segment with Joff Thyer from 2014-01-26T16:06:11

Listen

Paul's Security Weekly TV
Episode 358: Interview with Joel Yonts from 2014-01-26T15:57:58

Listen

Paul's Security Weekly TV
Hack Naked TV 14-2 from 2014-01-25T17:38:18

Listen

Paul's Security Weekly TV
Why Did the Podcast Name Change? from 2014-01-14T15:15:49

Listen

Paul's Security Weekly TV
Drunken Security News - Episode 357 from 2014-01-12T15:09:47

Listen

Paul's Security Weekly TV
Tech Segment with Rob Lee - Episode 357 from 2014-01-12T14:49:46

Listen

Paul's Security Weekly TV
Interview with Ian Iamit - Episode 357 from 2014-01-12T14:43:43

Listen

Paul's Security Weekly TV
HackNaked TV Episode 14-1 from 2014-01-07T15:28:39

Listen

Paul's Security Weekly TV
Pentest Preparations: Post exploitation from 2013-12-09T22:02:07

Listen

Paul's Security Weekly TV
Episode 355: Stories of the Week from 2013-12-08T13:39:20

Listen

Paul's Security Weekly TV
Episode 355: Tech Segment on Scriptalert1 from 2013-12-08T13:23:01

Listen

Paul's Security Weekly TV
Episode 355: Interview with Jens Steube from 2013-12-08T13:15:15

Listen

Paul's Security Weekly TV
Episode 354: Stories of the Week from 2013-11-28T19:17:15

Listen

Paul's Security Weekly TV
Episode 353 - Stories of the Week from 2013-11-23T16:28:10

Listen

Paul's Security Weekly TV
Episode 353 - Interview with Kyle 'esSOBI' Stone from 2013-11-22T22:16:30

Listen

Paul's Security Weekly TV
Episode 353 - Crypto Challenge from 2013-11-22T21:28:33

Listen

Paul's Security Weekly TV
Episode 352: Interview with Winn Schwartau from 2013-11-12T13:26:21

Listen

Paul's Security Weekly TV
Episode 352: I am the Calvary from 2013-11-12T13:22:34

Listen

Paul's Security Weekly TV
Episode 351: Token Stealing with Steve Sims from 2013-11-12T13:17:52

Listen

Paul's Security Weekly TV
Episode 351: Interview with Dan Philpot from 2013-11-12T13:15:59

Listen

Paul's Security Weekly TV
Episode 351: Rob Kornmeyer on Mona.py from 2013-11-11T01:02:29

Listen

Paul's Security Weekly TV
Episode 350: Active Defense from 2013-11-07T20:20:44

Listen

Paul's Security Weekly TV
Episode 350: SCADA Panel from 2013-11-07T18:39:57

Listen

Paul's Security Weekly TV
Stogie Geeks: Episode 70 from 2013-11-07T04:32:08

Listen

Paul's Security Weekly TV
Episode 350: Wings for Warriors and Veterans from 2013-11-07T02:32:31

Listen

Paul's Security Weekly TV
Episode 350: Interview with Kevin Finisterre from 2013-11-07T01:52:58

Listen

Paul's Security Weekly TV
Episode 350: Interview with Jayson Street from 2013-11-07T01:33:13

Listen

Paul's Security Weekly TV
Episode 350: Angelo & Leo - Honeynet.org from 2013-11-07T01:18:28

Listen

Paul's Security Weekly TV
Episode 350: Graham, Auerbach and Thuen from 2013-11-07T01:11:14

Listen

Paul's Security Weekly TV
Security Weekly #350 - Whitelisting Java from 2013-11-04T17:35:15


Greg Hetrick shows us how to better lock down our Java apps since ...

Listen
Paul's Security Weekly TV
Stories of the Week - Episode 348 from 2013-10-16T13:12:15

Listen

Paul's Security Weekly TV
Tech Segment with Heather Mahalik - Episode 348 from 2013-10-12T16:22:20

Listen

Paul's Security Weekly TV
Interview with Thierry Zoller - Episode 348 from 2013-10-12T04:26:36

Listen

Paul's Security Weekly TV
Stories and Rants of the Week - Episode 347 from 2013-10-07T12:01:45

Listen

Paul's Security Weekly TV
Tech Segment with Jared DeMott - Episode 347 from 2013-10-06T18:02:12

Listen

Paul's Security Weekly TV
Interview with Jaime Filson - Episode 347 from 2013-10-04T12:04:52

Listen

Paul's Security Weekly TV
Interview with Vivek Ramachandran from 2013-09-26T21:46:44

Listen

Paul's Security Weekly TV
Stories of the Week - Episode 346 from 2013-09-26T03:25:34

Listen

Paul's Security Weekly TV
Monica Jain - HP Protect 2013 from 2013-09-20T14:22:07

Listen

Paul's Security Weekly TV
DerbyCon Organizers and Stories - Episode 345 from 2013-09-13T17:09:15

Listen

Paul's Security Weekly TV
Tech Segment with Pete Finnigan - Episode 345 from 2013-09-13T16:10:42

Listen

Paul's Security Weekly TV
Interview with Rich Mogull - Episode 345 from 2013-09-13T15:53:15

Listen

Paul's Security Weekly TV
Drunken Security News - Episode 344 from 2013-09-09T01:02:10

Listen

Paul's Security Weekly TV
Interview with Richard Stiennon from 2013-09-09T00:31:58

Listen

Paul's Security Weekly TV
Drunken Security News - Episode 343 from 2013-09-05T13:28:26

Listen

Paul's Security Weekly TV
Enumerating a Domain using ADSI in PowerShell from 2013-09-05T02:53:07

Listen

Paul's Security Weekly TV
Interview with Ira Winkler - Episode 343 from 2013-09-04T19:28:06

Listen

Paul's Security Weekly TV
BruCon Matt - Episode 343 from 2013-09-04T19:20:48

Listen

Paul's Security Weekly TV
Interview with Phil Young - Episode 342 from 2013-08-28T15:45:32

Listen

Paul's Security Weekly TV
Tech Segment with Zach Cutlip - Episode 342 from 2013-08-28T12:52:03

Listen

Paul's Security Weekly TV
Drunken Security News - Episode 342 from 2013-08-28T12:42:33

Listen

Paul's Security Weekly TV
Drunken Security News - Episode 341 from 2013-08-16T15:43:38

Listen

Paul's Security Weekly TV
Tech Segment with Allison Nixon - Episode 341 from 2013-08-16T14:55:47

Listen

Paul's Security Weekly TV
Interview with Whitfield Diffie - Episode 341 from 2013-08-16T14:29:38

Listen

Paul's Security Weekly TV
Drunken Security News - Episode 340 from 2013-08-13T14:33:59

Listen

Paul's Security Weekly TV
Tech Segment: Honeyports - Episode 340 from 2013-08-13T13:41:40

Listen

Paul's Security Weekly TV
Hack Naked TV Episode 59 from 2013-08-07T16:08:16

Listen

Paul's Security Weekly TV
Hack Naked TV Episode 57 from 2013-07-19T15:06:46

Listen

Paul's Security Weekly TV
OWASP Top 10 (2013) with Dave Wichers from 2013-07-19T12:23:57

Listen

Paul's Security Weekly TV
Interview with Troy Hunt - Episode 339 from 2013-07-19T11:48:05

Listen

Paul's Security Weekly TV
Interview with Onapsis - Episode 338 from 2013-07-15T02:14:55

Listen

Paul's Security Weekly TV
Interview with Schuyler Towne - Episode 338 from 2013-07-15T01:25:14

Listen

Paul's Security Weekly TV
Interview with Kati Rodzon and Mike Murray from 2013-07-03T18:56:59

Listen

Paul's Security Weekly TV
Interview with Matt Bergin - Episode 337 from 2013-07-03T18:14:49

Listen

Paul's Security Weekly TV
Hack naked TV 56ish from 2013-06-27T11:50:30

Listen

Paul's Security Weekly TV
Drunken Security News - Episode 336 from 2013-06-21T17:04:06

Listen

Paul's Security Weekly TV
Tech Segment: Bro IDS from 2013-06-21T17:00:16

Listen