Podcasts by Pauls Security Weekly (Video-Only)

Paul's Security Weekly (Video-Only)

Security news, interviews, how-to technical segments. For security professionals by security professionals. We Hack Naked.

Further podcasts by Security Weekly

Podcast on the topic Technologie

All episodes

Paul's Security Weekly (Video-Only)
Pixelating Info, Pilfer Or Report, Digital Credit Unions, & Airtag Abuse - PSW #728 from 2022-02-18T10:00

This week in the Security News: To steal or collect a bug bounty, print bombing an NFL team, Webkit strikes again, hackers be framing, TIPC Linux kernels, is that an Airtag in your pocket or?, I...

Listen
Paul's Security Weekly (Video-Only)
Running Windows Inside Containers On Linux - PSW #728 from 2022-02-17T22:00

Yes, this is possible! We have incoporated into our vulhub-lab project a way to run Windows inside a Docker Container that is running on Linux. We didn't invent this technique but we will show y...

Listen
Paul's Security Weekly (Video-Only)
Cybersecurity Coordinator Under President Obama - Michael Daniel - PSW #728 from 2022-02-17T10:00

Michael joins us to discuss the importance of information sharing, how to convey cybersecurity practice and topics to senior leaders, cybersecurity regulation, myths surrounding militarizing cyb...

Listen
Paul's Security Weekly (Video-Only)
Uncovering a Major Linux PolicyKit Security Vulnerability: Pwnkit - Wheel - PSW #727 from 2022-02-11T10:00

Qualys researcher, Wheel, will discuss the discovery of the 12 year old Linux vulnerability in PolicyKit - which Qualys had dubbed, PwnKit. Wheel will provide an overview of the vulnerability an...

Listen
Paul's Security Weekly (Video-Only)
AR vs. VR, Hacking Mazdas, Risqué Latte Art, Crypto Wormholes, & Carding Forum Seized - PSW #727 from 2022-02-10T22:00

In the Security News for this week: Microsoft to block VBA macros by default (in some Office applications), Russia arrests it’s 3rd hacking group, The ‘Metaverse’ of security challenges, $323 Mi...

Listen
Paul's Security Weekly (Video-Only)
Cybersecurity Is Not Just a Technical Problem - Brian Honan - PSW #727 from 2022-02-10T10:00

We have spent decades tackling security threats with technology, and we are failing badly. We need to look and learn from other industries and see how they have improved their industry. In parti...

Listen
Paul's Security Weekly (Video-Only)
Securing Olympians, Hiding in UEFI, 'Fingerprinting GPUs', & P4x vs. North Korea - PSW #726 from 2022-02-04T10:00

This week in the Security News: Temporary phones, webcam hacks that are so much more, bags of cash, patch Wordpress plugins and patch them some more, crowd-sourced-government-funded vulnerabilit...

Listen
Paul's Security Weekly (Video-Only)
Linux Post Exploitation - PSW #726 from 2022-02-03T22:00

In this Technical Segment, Paul walks through Linux Post Exploitation!

Github: https://github.com/SecurityWeekly/vulhub-lab

...

Listen
Paul's Security Weekly (Video-Only)
Covert EDC & Physical Pen Tests - Brent White - PSW #726 from 2022-02-03T10:00

Discussing every-day-carry items that are utilized during covert entry assessments. Also discussing the concealment of these tools, and which tools we use for various assessment types.

Se...

Listen
Paul's Security Weekly (Video-Only)
12 Year Linux Bug, Recovering Bitcoin, Lulzsec's Impact, & Pimp My Cubicle - PSW #725 from 2022-01-28T10:00

This week in the Security News: More QR codes you shouldn't trust, race conditions in Rust, encrypting railways, Pwnkit - the latest Linux exploit, tricking researchers into crashing, cybersecur...

Listen
Paul's Security Weekly (Video-Only)
Securing Ubiquiti WiFi Systems - PSW #725 from 2022-01-27T22:00

Ubiquiti has become a crown favorite for WiFi (and many other solutions). Learn how to do some basic security, update the software, change passwords and more!

 

Visit Listen

Paul's Security Weekly (Video-Only)
Cracks in the Castle - Jimmy Sanders - PSW #725 from 2022-01-27T10:00

Enterprises today has an ever expanding attack surface. Jimmy Sanders, Head of Security for DVD.com, joins to discuss how Organizations are constantly trying to stay ahead of the latest known an...

Listen
Paul's Security Weekly (Video-Only)
REvil Gang Arrested, 5G & Airplanes, Zoom Zero-Click, & Stolen Brownies - PSW #724 from 2022-01-21T10:00

In the Security News: Malware targets Ukraine, I wonder where that's coming from?, evil Google Docs comments, Russia grabs REvil, funding a dictatorship, Zoom zero clicks, When 9-year old's laun...

Listen
Paul's Security Weekly (Video-Only)
Using WPScan To Find WordPress Vulnerabilities - PSW #724 from 2022-01-20T22:00

wpscan is a free tool for scanning WordPress, and let's face it, there are many vulnerabilities to be found in Wordpress! This segment will walk you through installing, configuring and using wps...

Listen
Paul's Security Weekly (Video-Only)
Cyber Resilience - Cybersecurity Mental Health - Neal O'Farrell - PSW #724 from 2022-01-20T14:58:29

What can we do to raise awareness on issues of mental health for cybersecurity professionals? Neal walks us through some of the issues and ways to deal with them. Neil has also put together trai...

Listen
Paul's Security Weekly (Video-Only)
Mailing USBs, DoS in DoorLock, Moxie Resigns, QR Code Mystery, & Jarring Revelations - PSW #723 from 2022-01-15T10:00

This week in the Security News: Attacking RDP (from the inside), NetUSB exposed, the old mailing USB drives trick, a persistent DoS in your doorLock, Signal gets a new CEO, attacking the patchin...

Listen
Paul's Security Weekly (Video-Only)
CanSecWest, PacSec, & PWN2OWN - Dragos Ruiu - PSW #723 from 2022-01-14T22:00

Dragos is the Organizer of CanSecWest, PACSEC, originator of PWN2OWN, and does security auditing, and virtual engagement/training.

 

Visit Listen

Paul's Security Weekly (Video-Only)
Log4j Exploit Step-By-Step - PSW #723 from 2022-01-13T16:13:15

The log4j vulnerability still exists in many environments. Learn how to exploit this vulnerability in our step-by-step guide. Please only use this information for research and testing purposes, ...

Listen
Paul's Security Weekly (Video-Only)
Zip Tie Pick, Wifi/Bluetooth Bugs, Domain Controllers, & Beetle Behavior - PSW #722 from 2021-12-24T10:00

The greatest exploit in the world, throw some more logs on the log4j fire, lock picking with a zip tie, hacking metal detectors, please disclose your vulnerabilities here, bugs in Wifi and Bluet...

Listen
Paul's Security Weekly (Video-Only)
The State Of Internet Exposed Services - John Matherly - PSW #722 from 2021-12-23T22:00

John joins us to talk about what its like to run scans of the Internet on a regular basis. We'll talk about some trends, such as what is more exposed, what is less exposed, and how select segmen...

Listen
Paul's Security Weekly (Video-Only)
Lock Picking & Physical Security - Deviant Ollam - PSW #722 from 2021-12-23T10:00

Many of us, myself included, learned lock picking techniques from Deviant. He comes on the show to talk about physical security in a pandemic, how to train for lock picking and physical security...

Listen
Paul's Security Weekly (Video-Only)
Printing Shellz, Block Chain For C2, Wordpress Theft, & Log4j Who? - PSW #721 from 2021-12-17T10:00

This week in the Security News: Printing Shellz, the exploit is in the link, 42 CVEs, time to update all of your browsers again, Microsoft App spoofing vulnerability, stealing credit cards in Wo...

Listen
Paul's Security Weekly (Video-Only)
What to Expect in 2022 - Sinan Eren - PSW #721 from 2021-12-16T22:00

Since it is Dec 15 - might make sense to have a discussion on what might be coming in 2022 in terms of security - topics could span Ransomware, and other threats as well as technology segments l...

Listen
Paul's Security Weekly (Video-Only)
All Your Holiday Hack Challenge Belong To Us - Ed Skoudis - PSW #721 from 2021-12-16T15:13:24

Let's talk about the 2021 SANS Holiday Hack Challenge. Lotsa great new stuff this year, with a focus on hardware hacking in a virtual world... plus TWO cons at the North Pole.

 

Se...

Listen
Paul's Security Weekly (Video-Only)
The 2021 Security Landscape & What Lies Ahead - Shailesh Athalye - PSW #720 from 2021-12-03T10:00

What are the key security challenges that customers faced this year? What did attackers do differently in 2021, and why are they succeeding more often? What can we expect in 2022? Shailesh will ...

Listen
Paul's Security Weekly (Video-Only)
Authentication Vulnerabilities - PSW #720 from 2021-12-03T10:00

Sven will present common vulnerabilities and issues that arise when implementing authentication and authorization in web applications.

 

This segment is sponsored by Invicti. Visit...

Listen
Paul's Security Weekly (Video-Only)
Bypassing Biometrics, Hiding in Plain Sight, Hacker Cinema, & High Aspirations - PSW #720 from 2021-12-02T22:00

In the Security News for this week: Stop hiding your secrets in plain sight, Detecting Wildcard DNS Abuse, $5 setup that hacks biometrics, Managing passwords with pen and paper, Windows 10 Zero ...

Listen
Paul's Security Weekly (Video-Only)
Suing Satoshi, Trojans in IDA, FBI Spam, Beg Bounties, & UPNP Strikes Again - PSW #719 from 2021-11-19T10:00

This week in the Security News: The FBI is spamming you, hacking exists in the mind, Beg Bounties, nasty top-level domains, MosesStaff, why own one npm package when you can own them all, how muc...

Listen
Paul's Security Weekly (Video-Only)
Skill Building: CTFs & Computer Fundamentals - Derek Rook - PSW #719 from 2021-11-18T22:00

Derek and the hosts will discuss technologies to build CTFs as well as what types of things to consider while doing so. They will also talk about the computer fundamentals that are often underva...

Listen
Paul's Security Weekly (Video-Only)
Building Vulnerable Docker Containers (On Purpose) - PSW #719 from 2021-11-18T15:01:09

I needed to create some vulnerable targets for testing exploits and my default password finder I wrote in Python (featured in previous episodes). I found a few useful projects, including Vulhub,...

Listen
Paul's Security Weekly (Video-Only)
TIPC Kernel Vulns, SBDCs, Truckloads of GPUs, & Hardcoded SSH Keys - PSW #718 from 2021-11-12T10:00

This week in the Security News: NPM hijacked again, hardcoding your keys, PAN-ODay, more Nmap in your python or python in your nmap, put your Docker API to rest, Busybox will own your box, Micro...

Listen
Paul's Security Weekly (Video-Only)
MAVSH - Sachin Mahajan - PSW #718 from 2021-11-11T22:00

Over the course of 2020 and 2021 new UAV regulations and restrictions, such as Remote Identification, have threatened UAV hobbyist's ability to fly freely. These new regulations did leave hobbyi...

Listen
Paul's Security Weekly (Video-Only)
Stalkerware Capabilities in the Real World - Lodrina Cherne, Martijn Grooten - PSW #718 from 2021-11-11T10:00

Can using technology risk your personal safety? Tracking information can be shared with attackers and facilitate cyberstalking in multiple ways including key logging and screen sharing. Explorat...

Listen
Paul's Security Weekly (Video-Only)
Shrootless Bug, Statistic Stats, Trojan Source, Fake Students, & Clippy Returns - PSW #717 from 2021-11-05T09:00

This week in the Security News: LOLbins that make you LOL, over exposing your medical records, Shrootless gets past SIP, 73.6% of statistics are made up and other such lies, we love Signal, if a...

Listen
Paul's Security Weekly (Video-Only)
Peel Back the Layers of Your Enterprise with Security Onion 2 - Doug Burks - PSW #717 from 2021-11-04T21:00

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. We've got a new container-based platform that is more flexible, more powerful, ...

Listen
Paul's Security Weekly (Video-Only)
Part 2: Scanning For Default Creds With Python - PSW #717 from 2021-11-04T09:00

We've updated our script with all sorts of new features. The latest version uses the TOML configuration file format to store the vendor information and the credentials to test with. We'll focus ...

Listen
Paul's Security Weekly (Video-Only)
Iranian Gas, Smelly Towns, View Source Legality, EBCDIC & GDPR, & Unlocking Oculus Go - PSW #716 from 2021-11-02T17:28:37

This week in the Security News we talk: Its still not illegal to look at HTML source code, Nobelium strikes again, npm infections, gas is cheap in Iran, if you can get it, Google Tensor, going b...

Listen
Paul's Security Weekly (Video-Only)
What Exactly Is an Incident Commander, Anyway - Matt Linton - PSW #716 from 2021-10-28T21:00

You may have seen the term "Incident Commander" in discussions about incident response, but do you know where that term came from and what it means? How can professionalizing your incident respo...

Listen
Paul's Security Weekly (Video-Only)
Focusing on Preventing Ransomware - Roger Grimes - PSW #716 from 2021-10-28T09:00

A good backup is not prevention. Its recovery. Roger A. Grimes, author of the just released Ransomware Protection Playbook (Wiley), and author of 12 other books and over 1100 articles on compute...

Listen
Paul's Security Weekly (Video-Only)
Wild Hippos, Chrome FTP, L0phtCrack Is Open-Source, Win 11 Pentium, & Legacy Systems - PSW #715 from 2021-10-23T09:00

This week in the Security News: More security advice for non-profits, faster 0-day exploits, ban all the things, you are still phishable, how to treat security researchers, what the heck is cybe...

Listen
Paul's Security Weekly (Video-Only)
Scanning For Default Credentials With Python - PSW #715 from 2021-10-22T21:00

We've been working on this Python project that will use the Nmap Python library to scan the local network, enumerate select systems and devices, try to login with default or known credentials, a...

Listen
Paul's Security Weekly (Video-Only)
Evolution & Maturity of the Cybersecurity Industry - Maxime Lamothe-Brassard - PSW #715 from 2021-10-22T09:00

The business of Security is gaining in maturity, from being an obscure corner of IT to becoming a core part of the C-Suite. How is this transformation happening and what can we learn from the si...

Listen
Paul's Security Weekly (Video-Only)
IoT Rickroll, Suing Over Disclosures, K-12 Cybersecurity Act, & SS7 Signaling - PSW #714 from 2021-10-16T09:00

This week in the Security News: Following the ransomware money, the Mystery Snail, school cybersecurity is the law, sue anyone, just not security researchers, "hacking" a flight school, refusing...

Listen
Paul's Security Weekly (Video-Only)
GraphQL - Sven Morgenroth - PSW #714 from 2021-10-15T21:00

Sven will talk about GraphQL APIs. He is going to show common issues that arise from its usage and how to attack GraphQL applications.

 

This segment is sponsored by Invicti. Visit...

Listen
Paul's Security Weekly (Video-Only)
Open Source Endpoint Security with Osquery & Fleet - Zach Wasserman - PSW #714 from 2021-10-14T21:00

The world's top tech organizations are pursuing an open-source endpoint security strategy using osquery. We will dig into how osquery and Fleet can enable observation, collection, and investigat...

Listen
Paul's Security Weekly (Video-Only)
LANtennas, ESXi & Python, Twitch Leaks, Facebook BGP, & iPhone Is Always On - PSW #713 from 2021-10-11T14:32:23

This week in the Security Weekly News: Brushing that data breach under the rug? Get sued by the US Government!, all your text messages belong to someone else, beware of the Python in your ESXi, ...

Listen
Paul's Security Weekly (Video-Only)
Up & Running With Security Onion - PSW #713 from 2021-10-08T21:00

There are many options to choose from when setting up The Security Onion. The use cases are vast, including a NIDS (Zeek, Suricata), HIDS (Beats, Wazuh, osquery) and standalone instances for a S...

Listen
Paul's Security Weekly (Video-Only)
Survey Says: Improve Your Security Posture by Purple Teaming - Dan DeCloss - PSW #713 from 2021-10-08T09:00

Today Dan DeCloss, CEO of PlexTrac, joins the panel to share results from a CyberRisk Alliance survey of 315 security practitioners in the U.S. and Canada. This research, sponsored by PlexTrac, ...

Listen
Paul's Security Weekly (Video-Only)
Pickpocketing Apple Pay, Mandatory Breach Reporting, Huawei Fears, & Cyber Criminals - PSW #712 from 2021-10-01T21:00

In the Security News, Microsoft adds automated mitigations for Exchange servers, Senior US cyber officials support mandatory breach reporting, 2021 has broken the record for 0days, but maybe tha...

Listen
Paul's Security Weekly (Video-Only)
Defense Strategies to Combat Sophisticated Ransomware - Mehul Revankar - PSW #712 from 2021-10-01T09:00

To defend themselves, companies need to detect ransomware attacks early, gather the intelligence to understand the attack, and prevent the attacks from occurring in the future. Qualys’ Mehul Rev...

Listen
Paul's Security Weekly (Video-Only)
Renting Your Phone, Public-Key Explained, Toilet Identification, & AutoDiscover Bug - PSW #711 from 2021-09-25T09:00

This week in the Security News: What to do with your old hardware, renting your phone, "persistently execute system software in the context of Windows", sensational headline: ransomware could ca...

Listen
Paul's Security Weekly (Video-Only)
Nzyme - Paul Asadoorian & Larry Pesce - PSW #711 from 2021-09-24T21:00

In this segment Paul and Larry attempt to confirm or deny that Nzyme performs intelligent device fingerprinting and behavioral analytics to detect rogue actors. Classic signature-based detection...

Listen
Paul's Security Weekly (Video-Only)
Velociraptor - Digging Deeper - Mike Cohen, Wes Lambert - PSW #711 from 2021-09-24T09:00

Velociraptor is a multi-platform, open-source, endpoint forensics, monitoring, and response platform that allows security professionals to quickly and easily dig through host artifacts and perfo...

Listen
Paul's Security Weekly (Video-Only)
Dubious Drones, NSO Group, Apple's Bug Bounties, Ghostscript 0-Day, & IBM Server Bugs - PSW #710 from 2021-09-18T09:00

This week in the Security News: Anonymous hacks Epik (with a K), Fuzzing Close-Source Javascript Engines, ForcedEntry, 8 Websites that can replace computer software, REvil decryptor key released...

Listen
Paul's Security Weekly (Video-Only)
Brakeman - Justin Collins - PSW #710 from 2021-09-17T21:00

Brakeman is a free static analysis security tool specifically designed for Ruby on Rails applications. It analyzes Rails application code to find security issues at any stage of development. Jus...

Listen
Paul's Security Weekly (Video-Only)
The State of Network Security in 2021 - Sinan Eren - PSW #710 from 2021-09-17T09:00

Network breaches, ransomware attacks, and remote-work challenges highlight the need for cloud-native Secure Access Service Edge (SASE) deployments.

 

Show Notes: Listen

Paul's Security Weekly (Video-Only)
Iframe Security - Benjamin Daniel Mussler - PSW #709 from 2021-09-04T09:00

Benjamin will discuss securing iframes with the sandbox attribute. This segment is sponsored by Acunetix.

 

Visit https://securitywee...

Listen
Paul's Security Weekly (Video-Only)
Hacking Honda, Insider Threat Galore, ChaosDB, USB File Weight, & Linux 5.14 - PSW #709 from 2021-09-03T21:00

This week in the Security News: Hacking Honda, a fact about single-factor, disarming your home and alarming vulnerability disclosure response, btw, you have a Sudo vulnerability, NSO under inves...

Listen
Paul's Security Weekly (Video-Only)
Nmap Vulnerability Scanning/Flan Scan - PSW #709 from 2021-09-03T09:00

Paul presents a Technical Segment that walks through Nmap, Vulners scripts, & Flan Scan!

 

Visit https://www.securityweekly.com/psw Listen

Paul's Security Weekly (Video-Only)
Yard Sales, Bitcoin Thief Charged, Mouse Privilege Escalation, & LED Eavesdropping - PSW #708 from 2021-08-28T09:00

This week in the Security News: Some describe T-Mobile security as not good, if kids steal bitcoin just sue the parents, newsflash: unpatched vulnerabilities are exploited, insiders planting mal...

Listen
Paul's Security Weekly (Video-Only)
Trends in Mac Malware & Apple Security - Patrick Wardle - PSW #708 from 2021-08-27T21:00

Apple's new M1 systems offer a myriad of benefits for both macOS users, and unfortunately, to malware authors as well. In this talk Patrick details the first malicious programs compiled to nativ...

Listen
Paul's Security Weekly (Video-Only)
Working With OpenVAS - PSW #708 from 2021-08-27T09:00

Gain some insights into the OpenVAS project, why you might want to use it and some of the best implementations. This segment will dive right into the extended setup by compiling OpenVAS, and all...

Listen
Paul's Security Weekly (Video-Only)
Shifting Left Probably Left You Vulnerable, Here’s How To Make it Right - Sonali Shah - PSW #707 from 2021-08-21T09:00

Shifting security left is good - but it’s an incomplete strategy that often leads to a false sense of security. In this segment, Sonali will discuss how organizations can reduce their risk of br...

Listen
Paul's Security Weekly (Video-Only)
Sequoia: A Local Privilege Escalation Vulnerability in Linux’s Filesystem Layer - . Wheel - PSW #707 from 2021-08-20T21:00

The Qualys Research Team discovered a size_t-to-int type conversion vulnerability in the Linux Kernel’s filesystem layer affecting most Linux operating systems. Any unprivileged user can gain ro...

Listen
Paul's Security Weekly (Video-Only)
Tractorload of John Deere Vulns, T-Mobile Breach, Kalay IoT Hack, & HolesWarm - PSW #707 from 2021-08-20T09:53:03

In the Security News for this week: Buffer overflows galore, how not to do Kerberos, no patches, no problem, all your IoTs belong to Kalay, the old pen test vs. vulnerability scan, application s...

Listen
Paul's Security Weekly (Video-Only)
Cyber-Symposiums, Apple Backdoor, Crypto Theft, & "Quadruple Extortion" - PSW #706 from 2021-08-14T09:00

This week in the Security News: Accenture gets Lockbit, $600 million in cryptocurrency is stolen, and they've started returning it, Lee and Jeff's data is leaked (among other senior citizens), a...

Listen
Paul's Security Weekly (Video-Only)
Offensive Operations With Mythic - Kyle Avery - PSW #706 from 2021-08-13T21:00

Mythic is an open-source, multi-platform framework for conducting red team engagements. This talk will cover the automated deployment of a Mythic server, developing new "wrappers" to extend the ...

Listen
Paul's Security Weekly (Video-Only)
OSINT & Social Engineering - Joe Gray - PSW #706 from 2021-08-13T15:14:38

Joe will discuss his upcoming Book, "Practical Social Engineering" in addition to OSINT. He is primarily passionate about OSINT and adjacent forms of Intelligence, but will need to discuss some ...

Listen
Paul's Security Weekly (Video-Only)
'Master Faces', Ship Hijacked, Windows Container Escape, & DNS Loopholes - PSW #705 from 2021-08-07T09:00

This week in the Security News: PwnedPiper and vulnerabilities that suck, assless chaps, how non-techy people use ARP, how to and how not to explain the history of crypto, they are still calling...

Listen
Paul's Security Weekly (Video-Only)
The Stakes Are Raised When Protecting the Foundation of Computing - Scott Scheferman - PSW #705 from 2021-08-06T21:00

With Eclypsium researchers' discovery of BIOSDisconnect and their upcoming talk and demo at DefCon 29 upon us, the stakes have never been higher when it comes to protecting the foundation of com...

Listen
Paul's Security Weekly (Video-Only)
RF Village at DefCon - Rick Farina, Rick Mellendick - PSW #705 from 2021-08-06T09:00

The RF Hackers Sanctuary is a group of experts in the areas of Information, Wifi, and Radio Frequency Security with the common purpose to teach the exploration of these technologies with a focus...

Listen
Paul's Security Weekly (Video-Only)
PetitPotam Attack, History of RickRolling, & Foxit PDF Vulns - PSW #704 from 2021-07-31T09:00

This week in the Security News: From a stolen laptop to inside the company network, the essential tool for hackers called "Discord", fixin' your highs, hacking DEF CON, an 11-year-old can show y...

Listen
Paul's Security Weekly (Video-Only)
Cyber-Physical Attacks - Michael Welch - PSW #704 from 2021-07-30T21:00

Join Michael Welch for a discussion on the ramifications a cyber-physical attack can have on ill prepared organizations. As a third-party expert, Michael can speak to: • The importance of being ...

Listen
Paul's Security Weekly (Video-Only)
The B Is for Business - Alyssa Miller - PSW #704 from 2021-07-30T09:00

Alyssa will discuss the growing trend of organizations implementing Business Information Security Officers. We'll talk about how the BISO builds bridges between the security and business organiz...

Listen
Paul's Security Weekly (Video-Only)
Windows Vulns Galore, Homoglyph Domains, Pegasus, & "Trust No One"! - PSW #703 from 2021-07-24T09:00

This week in the Security News: Trust no one, its all about the information, so many Windows vulnerabilities and exploits, so. many., Saudi Aramco data for sale, Sequoia, a perfectly named Linux...

Listen
Paul's Security Weekly (Video-Only)
CyberMarket & Democratisation/Globalisation of CyberSecurity Consulting - Gordon Draper - PSW #703 from 2021-07-23T21:00

CyberMarket.com is a marketplace where CyberSecurity Consultancies and clients can find each other. There is a growing trend where CyberSecurity Consultants recognize the gap between what they a...

Listen
Paul's Security Weekly (Video-Only)
Online Safety & Security: Dating Apps & Online Marketplaces - Jeff Tinsley - PSW #703 from 2021-07-23T09:00

Safety in online dating spaces is an issue the dating industry has grappled with for some time; with the surge of dating app usage during the pandemic, the demand for dating apps to take respons...

Listen
Paul's Security Weekly (Video-Only)
Ransomware Task Force, Year of the Linux Desktop?, & Ring Doorbell Encryption - PSW #702 from 2021-07-17T09:00

The White House announces a Ransomware Task Force, how much money Microsoft has paid out to security researchers last year, Amazon rolls out encryption for Ring doorbells, how a backdoor in popu...

Listen
Paul's Security Weekly (Video-Only)
The Journey from Network Security Engineer to Podcast Host - Jack Rhysider - PSW #702 from 2021-07-16T21:00

In this segment of Paul's Security Weekly, Paul and crew interview Jack Rhysider about how he got his start in Information Security, the projects and careers he worked on over the years, and how...

Listen
Paul's Security Weekly (Video-Only)
The BIOS Disconnect - Scott Scheferman - PSW #702 from 2021-07-16T09:00

Eclypsium researchers identified vulnerabilities affecting the BIOSConnect feature within Dell Client BIOS. This disconnect impacted 129 Dell models of consumer and business laptops, desktops, a...

Listen
Paul's Security Weekly (Video-Only)
LinkedIn Breach, Bitcoin From Banks, PrintNightmare, & NFC Flaws in ATMs - PSW #701 from 2021-07-03T09:00

This week in the Security News: LinkedIn breach exposes user data, Why MTTR is Bad for SecOps, 3 Things Every CISO Wishes You Understood, USA as a Cyber Power, is ignorance bliss for hackers, fl...

Listen
Paul's Security Weekly (Video-Only)
The Rise of Sim Swapping - Haseeb Awan - PSW #701 from 2021-07-02T21:00

80% of SIM-Swap attacks are successful. This could lead to greater financial loss and loss of social status since this is where hackers latch onto. The statistics are true and spreading like a w...

Listen
Paul's Security Weekly (Video-Only)
New Security Threats Stemming from PII Online - Rob Shavell - PSW #701 from 2021-07-02T09:00

Deep dive on the data broker industry, and how new threats are stemming from the widespread availability of employee/personal information publicly for sale at data broker websites.

 

...

Listen
Paul's Security Weekly (Video-Only)
Thermostat Hijacking, MA Androids, Windows 11, Hacking Pelotons, & John McAfee - PSW #700 from 2021-06-26T09:00

In the Security News for this week Paul and the crew talk: Windows 11, Drive-by RCE, Cookies for sale, McAfee has passed away, 30 Million Dell Devices at risk, & more!

 

Visit Listen

Paul's Security Weekly (Video-Only)
CFAA: Recent US Supreme Court Case Van Buren v. US - Thomas Lonardo - PSW #700 from 2021-06-25T21:00

Brief history and purpose of the CFAA. Discussion of the majority and dissenting "Van Buren" opinion. Implications for the computer forensic and security profession.

Segment Resources: Listen

Paul's Security Weekly (Video-Only)
Career Pathing and Advice From Offensive Security - Jim O'Gorman - PSW #700 from 2021-06-25T09:00

Offensive Security expert Jim O'Gorman talks through his own career progression and training, revealing what it takes to be successful in infosec. He also covers key learning tracks and gives co...

Listen
Paul's Security Weekly (Video-Only)
Web Cache Poisoning - Timur Guvenkaya - PSW #699 from 2021-06-21T16:11:37

This presentation will cover how incorrect implementation of caching mechanism within web application might lead to the Web Cache Poisoning vulnerability that can potentially affect all the user...

Listen
Paul's Security Weekly (Video-Only)
"Eavesdropping Cameras", Ransomware Poll Results, Windows 11, & CVS Records Leak - PSW #699 from 2021-06-18T21:00

This week in the Security News: Jeff, Larry, & Doug adjust to our Adrian Overlord! Ransomware galore, Ransomware Poll Results, Windows 11 & Windows 10's End-Of-Life, Drones that hunt for human s...

Listen
Paul's Security Weekly (Video-Only)
Avoiding the Silo: Bridging the Divide Between Security + Dev Teams - Brian Joe - PSW #699 from 2021-06-18T09:00

Too often, developers and security teams have a siloed relationship. That separation can lead to inefficiencies and gaps in security across software development, ultimately leading to anything f...

Listen
Paul's Security Weekly (Video-Only)
ANOM Bust, Ransomware Solutions, NAC, & A PCI Deathmatch! - PSW #698 from 2021-06-12T09:00

This week, In the Security News Paul & the crew discuss: Microsoft Patches 6 Zero-Days Under Active Attack, US seizes $2.3 million Colonial Pipeline paid to ransomware attackers, the largest pas...

Listen
Paul's Security Weekly (Video-Only)
Protecting the Attack Surface - Rob Gurzeev - PSW #698 from 2021-06-11T21:00

What does it mean to protect the attack surface? What's the difference between attack surface protection vs. attack surface management? Rob Gurzeev, CEO and Founder at Cycognito, joins us to dis...

Listen
Paul's Security Weekly (Video-Only)
OpenWRT for Enterprise and Labs - Gene Erik - PSW #698 from 2021-06-11T09:00

OpenWRT is a mature and well supported project. It is supported on many hardware platforms and available as production-level products. OpenWRT has developed into a platform that is filled with e...

Listen
Paul's Security Weekly (Video-Only)
CFAA Ruling, Amazon Sidewalk, Agile Security Testing, & WordPress Plugins - PSW #697 from 2021-06-05T09:00

This week In the Security News, Paul and the Crew talk: Establishing Confidence in IoT Device Security: How do we get there?, JBS hack latest escalation of Russia-based aggression ahead of June ...

Listen
Paul's Security Weekly (Video-Only)
Digital Transformation's Impact On IT Asset Visibility - Sumedh Thakar - PSW #697 from 2021-06-04T21:00

Over the past year, organizations have rapidly accelerated their digital transformation by leveraging technologies such as cloud and container that support the shift to IoT and a remote workforc...

Listen
Paul's Security Weekly (Video-Only)
Attack Surface Discovery and Enumeration - Dan Tentler - PSW #697 from 2021-06-04T09:00

We've let the compliance world drive security for so long there are folks that literally have no idea what 'reasonably secure' looks or feels like because they've never seen it before.

Se...

Listen
Paul's Security Weekly (Video-Only)
M1 Chip Flaw, Boeing 747 Hacking, Don't Blame the Intern, & John Deere - PSW #696 from 2021-05-29T09:00

This week in the Security Weekly News, Paul and the Crew Talk: Nagios exploits, hacking a Boeing 747, bypass container image scanning, unpatchable new vulnerability in Apple M1 chips, stop blami...

Listen
Paul's Security Weekly (Video-Only)
Cybersecurity Canon - Rick Howard - PSW #696 from 2021-05-28T21:00

Rick Howard joins to talk about his Cybersecurity Canon project, the rock and roll hall of fame for Cybersecurity literature! The Cybersecurity Canon Committee has announced it's hall of winners...

Listen
Paul's Security Weekly (Video-Only)
Polarity’s Power-up Sessions, Add an Ability in 15 Minutes - Paul Battista - PSW #696 from 2021-05-28T09:00

Training is critical but it is tough to break away from the day to day. Polarity is running free 15 minute training sessions that leverage our community edition to leave you with a new ability t...

Listen
Paul's Security Weekly (Video-Only)
21 Nails: Behind the Scenes Discussion of Qualys Exim Vulnerability Discovery - Wheel - PSW #695 from 2021-05-22T09:00

Join Qualys researcher Wheel for a discussion on the team's recent discovery and disclosure of multiple critical vulnerabilities in the Exim mail server. This includes discussion of the vulnerab...

Listen
Paul's Security Weekly (Video-Only)
Five by Five: Why the Cyber Defense Matrix Gets Great Reception - PSW #695 from 2021-05-21T21:00

Five years after Sounil Yu originally introduced the Cyber Defense Matrix at the 2016 RSA conference, he just wrapped up the third workshop based on the framework. CDM has its own website, is an...

Listen
Paul's Security Weekly (Video-Only)
Unplugging the Internet, Diversity, Cyber NTSB, & Best Practices - PSW #695 from 2021-05-21T09:00

This week in the Security News: Is the cyber NTSB a good thing?, Russian virtual keyboard for the win, information should be free, hang on while I unplug the Internet, security MUST be taken ser...

Listen
Paul's Security Weekly (Video-Only)
Executive Order, New & Old Wifi Vulns, Pipeline Hack, & Distro-Less Linux - PSW #694 from 2021-05-15T09:00

This week in the Security News: President Biden issues a 34-page executive order on Cybersecurity, Did you hear about the pipeline hack?, New/Old Wifi vulnerabilities, get this Apple didn't want...

Listen
Paul's Security Weekly (Video-Only)
Attack Surface Mapping w/ AMASS - PSW #694 from 2021-05-14T21:00

Learn how to use Amass to collect information about your Internet exposed assets. We'll cover usage of the configuration file (heavily), then put it altogether by integrating Nmap and a screensh...

Listen
Paul's Security Weekly (Video-Only)
How Hacking Naked Changed My Life - Alex Chaveriat - PSW #694 from 2021-05-14T09:00

"I hack naked" - Not my best choice of a phrase to use with a prospective client though, now that it is done, might as well go through with this terrible idea... This is the story of a kick-off ...

Listen
Paul's Security Weekly (Video-Only)
Job Expectations, Pi Password Thief, Python Masscan, & Pingback - PSW #693 from 2021-05-08T09:00

This week in the Security Weekly News the crew talks: Pingback is back, was it ever really gone?, damn QNAP ransomeware, anti-anti-porn software, Qualcomm vulnerabilities, spreading pandas on Di...

Listen
Paul's Security Weekly (Video-Only)
Biden Administration EO on Cyber - Jim Langevin - PSW #693 from 2021-05-07T21:00

US Congressman Jim Langevin joins to talk about Executive Orders, International Interest in Cyber, & more in this gripping interview!

 

Visit Listen

Paul's Security Weekly (Video-Only)
Building a Risk-Based Vulnerability Management Program - Bob Erdman - PSW #693 from 2021-05-07T09:00

Risk-based vulnerability management is more than just a vulnerability scan or assessment. It incorporates relevant risk context and analysis to prioritize the vulnerabilities that pose the great...

Listen
Paul's Security Weekly (Video-Only)
AirDrop Vulns, Linux Hypocrite Commits, Wi-Fi Code Execution, & We'll Miss You Dan - PSW #692 from 2021-05-01T09:00

This week in the Security News, Penetration testing leaving organizations with too many blind spots, A New PHP Composer Bug Could Enable Widespread Supply-Chain Attacks, Apple AirDrop Vulnerabil...

Listen
Paul's Security Weekly (Video-Only)
Smart Building Control System Cybersecurity - The Real World - Fred Gordy - PSW #692 from 2021-04-30T21:00

Currently, in the United States, there are over 87 billion square feet of commercial real estate. Smart Building control systems pervasive throughout these buildings and helped increase efficien...

Listen
Paul's Security Weekly (Video-Only)
Protecting the Hybrid Workforce - Fleming Shi - PSW #692 from 2021-04-30T09:00

Fleming will cover the vulnerabilities of a hybrid workforce and how employees are now working from anywhere, not just their homes. Zero trust will play a large part in securing workforces in th...

Listen
Paul's Security Weekly (Video-Only)
Feds Have a Busy Two Weeks, British Tween Takes On TikTok, & More Facebook Woes... - PSW #691 from 2021-04-24T09:00

This week in the Security News, U.S Formally Attributes SolarWinds Attack to Russian Intelligence Agency, FBI Clears ProxyLogon Web Shells from Hundreds of Orgs, Justice Dept. Creates Task Force...

Listen
Paul's Security Weekly (Video-Only)
Encrypted Collaboration & Communication - Joel Wallenstrom - PSW #691 from 2021-04-23T21:00

This conversation will introduce Wickr to the PSW listeners. Joel Wallenstrom will discuss the importance of end-to-end encrypted collaboration and communication as it relates to enterprise and ...

Listen
Paul's Security Weekly (Video-Only)
Why Now is the Time for K-12 Cybersecurity Education - Kevin Nolten - PSW #691 from 2021-04-23T09:00

With the U.S. facing a shortage of roughly 314,000 cybersecurity professionals in the workforce, according to CSIS, there is an urgent need to build cybersecurity skills and fill the workforce p...

Listen
Paul's Security Weekly (Video-Only)
Facebook Dump, Hacking Your Dishwasher, Zoom 0-Click Exploit, & Ubiquity Response - PSW #690 from 2021-04-10T09:00

This week in the Security News, Polish blogger sued after revealing security issue in encrypted messenger, The Facebook dump and Have I Been Pwned, LinkedIn and more_eggs, APTs targeting Fortine...

Listen
Paul's Security Weekly (Video-Only)
Lessons Learned When Migrating from On Prem to Cloud - Dutch Schwartz - PSW #690 from 2021-04-09T21:00

Less than 15% of enterprise customers are primarily cloud native. With so many companies still in early stages of cloud migration, what are the key lessons learned from early adopters as well as...

Listen
Paul's Security Weekly (Video-Only)
nzyme - Free & Open WiFi Defense System - Lennart Koopmann - PSW #690 from 2021-04-09T09:00

Nzyme is a new kind of WiFi IDS (WIDS) that detects adversaries by looking at hard to spoof characteristics of an attacker. Existing WIDS tend to look at extremely easy to spoof metadata like ch...

Listen
Paul's Security Weekly (Video-Only)
Ubiquiti Breach, Tesla, PHP, & More Sagas - PSW #689 from 2021-04-03T09:00

npm netmask library has a critical bug, when AI attacks, firmware attacks on the rise, Microsoft Hololens and order 66, a real executive order 13694, The Ubiquity breach saga, the FreeBSD and wi...

Listen
Paul's Security Weekly (Video-Only)
Cybersecurity Journalist - Robert Lemos - PSW #689 from 2021-04-02T21:00

Paul, and the rest of the PSW Hosts, will talk to Robert about how he got his start in InfoSec.

 

Visit https://www.securityweekly.com...

Listen
Paul's Security Weekly (Video-Only)
The Intersection of Cybersecurity & Cryptocurrency - Nick Percoco - PSW #689 from 2021-04-02T09:00

With an uptick in malware scams and email compromises, the best thing we can do is educate the cryptocurrency community about risks and security best practices. Listen

Paul's Security Weekly (Video-Only)
Open Redirects - An Underestimated Vulnerability - PSW #688 from 2021-03-27T09:00

Learn what redirects are, the different types, how they work and how they are exploited by attackers. Oh, also learn how to defend against redirect attacks!

Sven's Slide Deck - Open Redir...

Listen
Paul's Security Weekly (Video-Only)
DOOM Exploit, iPhone Deep Fakes, & 11 0-Days Infect Devices - PSW #688 from 2021-03-26T21:00

This week in the Security News: Doom exploit wins an award, a puzzle honors Alan Turing, anyone can create a deepfake, Jabber bugs, unquoted service paths, Nim malware, Deadly sins of secure cod...

Listen
Paul's Security Weekly (Video-Only)
Taming Vulnerability Overload - Mehul Revankar - PSW #688 from 2021-03-26T09:00

Almost weekly, hackers discover and exploit vulnerabilities in popular programs like SolarWinds and Microsoft Exchange Server, impacting thousands. While it would be great to eradicate these vul...

Listen
Paul's Security Weekly (Video-Only)
Plextrac Mini-Series Episode 1: Purple Teaming - Bryson Bort - PSW #687 from 2021-03-20T09:00

The first episode of Security Weekly's podcast mini-series with PlexTrac "Getting the Real Work Done in Cybersecurity" starts with PlexTrac's bread and butter, Purple Teaming! The group - along ...

Listen
Paul's Security Weekly (Video-Only)
Security Grades, Mirai, Quantum Cryptography, & Hacking "Beer" - PSW #687 from 2021-03-19T21:00

In the Security News, If software got a security grade, most would get an F, SolarWinds hackers got some source code, new old bugs in the Linux kernel, hack stuff and get blown up, stop hacking ...

Listen
Paul's Security Weekly (Video-Only)
Getting The Real Work Done With Plextrac - Dan DeCloss - PSW #687 from 2021-03-19T09:00

Dan will run through some customer testimonials on how they are using Plextrac effectively to get the real work done in security! This segment is sponsored by PlexTrac.

 

Visit Listen

Paul's Security Weekly (Video-Only)
Ransomware Research, Threats, and Futures - Assaf Dahan - PSW #686 from 2021-03-13T10:00

Assaf Dahan, Sr Director, Head of Threat Research at Cybereason, discusses current trends in ransomware research. What happens when we're not watching or watching the wrong indicators? And threa...

Listen
Paul's Security Weekly (Video-Only)
Russian regex, John McAfee, Verkada Hack, & Microsoft Exchange - PSW #686 from 2021-03-12T22:00

Microsoft Exchange had some vulnerabilities, how could you not hear about them?, Russians try to throttle Twitter, silicon valley security camera company has been breached and we get to see what...

Listen
Paul's Security Weekly (Video-Only)
How Illicit Markets Really Operate - David Hétu - PSW #686 from 2021-03-12T10:00

David has been studying the structure, size and scope of illicit markets for over 10 years. He has come to realize just how fragmented illicit markets are, how a few select vendors often control...

Listen
Paul's Security Weekly (Video-Only)
Patching Exchange Servers, Book Reviews, Rockwell, & Forgotten AM Broadcasts - PSW #685 from 2021-03-06T10:00

This week, In the Security News, Calling all people who know how to patch MS Exchange servers, we need you, Rockwell Automation PLC flaws and what you can't do about it, a book review I agree wi...

Listen
Paul's Security Weekly (Video-Only)
How To Build A Kick-Ass PC - PSW #685 from 2021-03-05T22:00

Paul recently built a new PC for daily work and security-related tasks. It's a monster PC! The build was researched heavily, and in this segment, Paul will share all the tips and tricks to you c...

Listen
Paul's Security Weekly (Video-Only)
Offensive Cybersecurity Education and Getting Started in Pentesting - Phillip Wylie - PSW #685 from 2021-03-05T10:00

Phillip will discuss his passion for offensive cybersecurity education, mentoring, and getting started in pentesting. He co-authored a book based on his conference talk "The Pentester Blueprint:...

Listen
Paul's Security Weekly (Video-Only)
TV Hacking, Nvidia, Nation States, NASA, & WMware - PSW #684 from 2021-02-27T10:00

This week In the Security News, Nvidia tries to throttle cryptocurrency mining, Digging deeper into the SolarWinds breach, now with executive orders, NASA's secret message on Mars, vulnerabiliti...

Listen
Paul's Security Weekly (Video-Only)
Wait, You Did What? How To Be A Cybersecurity Hero... - Bryan Seely - PSW #684 from 2021-02-26T22:00

Bryan will talk about how and why he wire-tapped the US Secret Service and FBI, how he used his Marine Corps training, cyber abilities, social engineering, and OSINT to rescue his foster daughte...

Listen
Paul's Security Weekly (Video-Only)
"Confessions of a CIA Spy - The Art of Human Hacking" Book Release - Peter Warmka - PSW #684 from 2021-02-26T10:00

Peter will tell the story behind the story of his new book "Confessions of a CIA Spy - The Art of Human Hacking" including key highlights from the book regarding data protection. Peter's new boo...

Listen
Paul's Security Weekly (Video-Only)
Unearthing a 10-Year Old SUDO Vulnerability - . Wheel - PSW #683 from 2021-02-13T10:00

“Wheel” was part of the team that discovered the heap overflow vulnerability in SUDO, Baron Samedit (CVE-2021-3156), that impacted major Unix-like operating systems included Linux, macOS, AIX an...

Listen
Paul's Security Weekly (Video-Only)
CD Projekt Ransomwared, Ciphers, Water Supply Hacked, & Clubhouse Security Risks - PSW #683 from 2021-02-12T22:00

This week in the Security News, Police Playing copyrighted music to stop video of them being posted online, Border agents can search phones freely under new circuit court ruling, Microsoft warns...

Listen
Paul's Security Weekly (Video-Only)
What Does Zero Trust Mean To You? - Peter Smith - PSW #683 from 2021-02-12T10:00

In this segment we'll unpack "Zero Trust", what does it mean and how can it be applied as a concept to information security today? It certainly begs the question what and who do you trust? Often...

Listen
Paul's Security Weekly (Video-Only)
Vending Machine Hack, Chucky's Amber Alert, HarmonyOS, & Realtek Vulns - PSW #682 from 2021-02-06T10:00

Security in a Complex World, Huawei’s HarmonyOS embodies “Fake it till you make it”, Hackers Infiltrating the World of Online Gaming, Sloppy patches breed zero-day exploits, Dutch researcher hac...

Listen
Paul's Security Weekly (Video-Only)
Quantum Computing & Finding the Truth - Bill DeLisi - PSW #682 from 2021-02-05T22:00

Bill will provide insight on best practices for internet safety, for work from home, family-friendly internet habits which leads to the conversation of secure chats/files, & more!

 

<...

Listen
Paul's Security Weekly (Video-Only)
Starting A Non-Profit To Help Small Companies With CMMC - Josh Marpet - PSW #682 from 2021-02-05T10:00

Small federal contractors are being required to become compliant with a new standard, CMMC. They've never had to do the level of security and compliance maturity that it requires! What do they d...

Listen
Paul's Security Weekly (Video-Only)
Fighting IoT Insecurities - Terry Dunlap - PSW #657 from 2021-01-31T22:10:42.023393

Arrested at 17 while hacking with a Commodore 64, Terry went on to work for the US National Security Agency help track terrorists. He left the NSA in 2007 to bootstrap Tactical Network Solutions...

Listen
Paul's Security Weekly (Video-Only)
Larry Pesce, Getting Started with FL2k - Paul's Security Weekly #570 from 2021-01-31T22:10:42.023393

An introduction to FL2K: Software Defined Radio is all the rage for detecting unknown signals and transmitters. We'll show you how to set up and use a surreptitious transmitter to start your jou...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #469 - Russell Beauchemin from 2021-01-31T22:10:42.023393

Russell is a graduate of RIC with a B.A. in English, minor in Chem, M.A. in Media Studies, and currently pursuing his PhD in Education at Lesley University.

Full Show Notes: http://wiki.s...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #462 - Sean Metcalf from 2021-01-31T22:10:42.023393

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #449 - Security News from 2021-01-31T22:10:42.023393

We talk about the dangers of selfies, the FTC coming to our rescue encouraging open source for IoT devices and so much more! Jack, Paul, Larry, Not Kevin, Essobi and Apollo host.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #448 - Security News from 2021-01-31T22:10:42.023393

We talk about the dangers of selfies, the FTC coming to our rescue encouraging open source for IoT devices and so much more! Jack, Paul, Larry, Not Kevin, Essobi and Apollo host.

Listen
Paul's Security Weekly (Video-Only)
Recorded Future and Virsec - PSW #617 from 2021-01-31T22:10:42.023393

We interview Roman Sannikov, the Director and Analyst on Demand at Recorded Future. We also interview Ray DeMeo, the Chief Operating Officer at Virsec.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
LogRhythm To The Cloud - Sam Straka - PSW - Interview #614 from 2021-01-31T22:10:42.023393

Sam Straka is the Technical Product Manager at LogRhythm, and he will be talking about the movement of their market to the Cloud, how LogRhythm is innovating in that area, and why total cost of ...

Listen
Paul's Security Weekly (Video-Only)
MITRE ATT&CK: Katie Nickels, MITRE - Paul's Security Weekly #612 from 2021-01-31T22:10:42.023393

Katie Nickels is the ATT&CK Threat Intelligence Lead at MITRE Corporation. MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observatio...

Listen
Paul's Security Weekly (Video-Only)
Biometric Authentication, Jumio - Paul's Security Weekly #611 from 2021-01-31T22:10:42.023393

Growth of account takeover and how to prevent it Data breaches continue to threaten organizations and expose usernames and passwords on the Dark Web, enabling fraudsters to use stolen data to ac...

Listen
Paul's Security Weekly (Video-Only)
SambaCry, FBI Warnings, and Hacking Segways - Paul's Security Weekly #523 from 2021-01-31T22:10:42.023393

Exploiting SambaCry, a warning from the FBI, hacks versus hurricanes, hacking segways, and more security news!

Full Show Notes: https...

Listen
Paul's Security Weekly (Video-Only)
AttackDefense Labs Platform - Paul's Security Weekly #609 from 2021-01-31T22:10:42.023393

We interview Vivek Ramachandranis the Founder & CEO of Pentester Academy. Pentester Academy, our AttackDefense Labs platform and other topics. Vivek will show a demo of their AttackDefense labs....

Listen
Paul's Security Weekly (Video-Only)
OneLogin Woes, Shadow Brokers Identity, oAuth Nightmares - Paul's Security Weekly #516 from 2021-01-31T22:10:42.023393

Chipotle and OneLogin suffer breaches, Windows XP Too Unstable To Spread WannaCry, Patches Available for Linux Sudo Vulnerability, Cisco, Netgear Readying Patches For Samba Vulnerability, oAuth ...

Listen
Paul's Security Weekly (Video-Only)
Exploiting Client-Side Node.js with Moses Hernandez - Paul's Security Weekly #516 from 2021-01-31T22:10:42.023393

I know what you're thinking, Node.js is server-side right? Not exactly. It turns out many client-side applications have embedded Node.js. And its not always updated to the latest version. And, i...

Listen
Paul's Security Weekly (Video-Only)
David Conrad, ICANN - Paul's Security Weekly #501 from 2021-01-31T22:10:42.023393

David Conrad is a long-time and active participant in Internet infrastructure, development, and operations. As the CTO of ICANN, David is at the heart the organization’s mission to help maintain...

Listen
Paul's Security Weekly (Video-Only)
EMOTET Disrupted, "Ghost" Hackers, & Why Privacy is 'Like Bubblewrap' - PSW #681 from 2021-01-30T10:00

In the Security News, why privacy is like bubble wrap, South African government releases its own browser just to re-enable flash support, former Lulzsec hacker releases VPN zero-day used to hack...

Listen
Paul's Security Weekly (Video-Only)
How Tall Do You Have to Be to Ride the Ride? - Dan DeCloss - PSW #681 from 2021-01-29T22:00

Today’s segment will discuss effective assessments, the maturity of your security posture, and the composition of your team. Specific topics in the episode include the what, when, and how of con...

Listen
Paul's Security Weekly (Video-Only)
XDR and Vitamins - Michael Roytman - PSW #681 from 2021-01-29T10:00

What is XDR? How do we know the security protections we're investing in are working? All this and Paul's CBD Pineapple Pizza Drink on this week's show.

 

This segment is sponsored ...

Listen
Paul's Security Weekly (Video-Only)
WRT54G Hacking History, 70 Unpatched Cisco Vulns, & Bypassing MFA - PSW #680 from 2021-01-16T10:00

In the Security News, How two authors became part of WRT54G hacking history, European police and German law enforcement have taken down the illegal "DarkMarket" online marketplace, 70 unpatched ...

Listen
Paul's Security Weekly (Video-Only)
Hacking Ubiquiti Devices - Jon Gorenflo - PSW #680 from 2021-01-15T22:00

Ubiquiti network gear has become a favorite among tech enthusiasts, but various Ubiquiti products have had some serious vulnerabilities in recent history. Listen in as we discuss hack, secure, a...

Listen
Paul's Security Weekly (Video-Only)
Beyond Phishing Blockers - Ryan Noon - PSW #680 from 2021-01-15T10:00

Ryan Noon joins Paul, and the rest of the PSW team, this week to chat through the importance of resilience in everything companies do to protect cloud-stored data and IP, unpack growing enterpri...

Listen
Paul's Security Weekly (Video-Only)
Custom Python Encryption, Shady 0-Days, & The Great iPwn - PSW #679 from 2021-01-09T10:00

In the Security News, Nissan Source code leaked, how the shady 0-Day sales game is evolving, Hack the Army 3.0 announced, creating your own custom encryption in python, FBI warns of swatting att...

Listen
Paul's Security Weekly (Video-Only)
What Has Changed (or Not) Since Our Last Visit? - Ming Chow - PSW #679 from 2021-01-08T22:00

-What are we seeing from infosec graduates as they come into the enterprise to begin their careers? -How has data privacy changed since 2014? -Is the cloud a solution, or creates more problems? ...

Listen
Paul's Security Weekly (Video-Only)
Automated Vulnerability Remediation - The Good, the Bad and the Ugly - PSW #679 from 2021-01-08T10:00

The way we identify, prioritize, and mitigate software vulnerabilities was built in the reverse order. Why did it happen? Could a new remediation strategy finally form an alliance between IT and...

Listen
Paul's Security Weekly (Video-Only)
SolarWinds Attack, AIR-FI Technique, & Zodiac Cypher Decoded - PSW #678 from 2020-12-19T10:00

In the Security News, How suspected Russian hackers outed their massive cyberattack, Millions of Unpatched IoT, OT Devices Threaten Critical Infrastructure, Zodiac Killer Cipher Solved, a Securi...

Listen
Paul's Security Weekly (Video-Only)
Securing The Enterprise Software Supply Chain - Harry Sverdlove - PSW #678 from 2020-12-18T22:00

SolarWinds is just the latest example of how the enterprise software supply chain, when compromised, can be used successfully by attackers. These coordinated and well-managed attacks prey on tru...

Listen
Paul's Security Weekly (Video-Only)
Generating Threat Insights Using Data Science - Roi Cohen, Shani Dodge - PSW #678 from 2020-12-18T10:00

In this world of countless vulnerabilities, we need to find a way to identify threats. Prioritizing known vulnerabilities is a step in the right direction but definitely not enough. There is a n...

Listen
Paul's Security Weekly (Video-Only)
Hacking Matters Panel - PSW #677 from 2020-12-12T10:00

Hacking matters. The term hacking has gotten away from us over the years. I believe we've reclaimed it, to a certain extent. The goal of this panel is to discuss all things hacking culture. What...

Listen
Paul's Security Weekly (Video-Only)
Innovative Blue Team Techniques Panel - PSW #677 from 2020-12-11T22:30

We often hear that offensive security techniques are "sexier" than defensive blue team techniques. In this panel discussion, we attempt to level the playing field (on so many levels...) between ...

Listen
Paul's Security Weekly (Video-Only)
The State Of Penetration Testing Panel - PSW #677 from 2020-12-11T10:00

Join us for a lively discussion surrounding the topic of penetration testing. Sure, we've called out differences between vulnerability scanning and penetration testing. Moving past this particul...

Listen
Paul's Security Weekly (Video-Only)
Security News w/ Ed Skoudis - PSW #676 from 2020-12-05T10:00

Ed Skoudis returns to talk to us about the Holiday Hack Challenge! Then, in the Security News, Thousands of unsecured medical records were exposed online, Advanced Persistent Threat Actors Targe...

Listen
Paul's Security Weekly (Video-Only)
Zero Trust Data Security - Jeff Capone - PSW #676 from 2020-12-04T22:00

Ensure all your data is secure, without impacting the business.

 

This segment is sponsored by SecureCircle. Visit https://securi...

Listen
Paul's Security Weekly (Video-Only)
From Chaos to Topia - Vicarius - PSW #676 from 2020-12-04T10:00

More computers, more software, and faster development cycles lead to more vulnerabilities. The security and IT teams are put under immense pressure to tackle the growing number of vulnerabilitie...

Listen
Paul's Security Weekly (Video-Only)
IoT Cybersecurity Improvement Act, TCL Smart TV Flaw, & Popping Reverse Shells - PSW #675 from 2020-11-21T10:00

In the Security News, Verizon has suggestions on how to make DNS more secure, Microsoft is trying to fix another Kerberos vulnerability, Bumble made some security blunders, why trying to write a...

Listen
Paul's Security Weekly (Video-Only)
Understanding How Data Science Applies to Infosec - Michael Roytman - PSW #675 from 2020-11-20T22:00

Michael takes us through some of the common AI and ML methods of data science and how they apply to our InfoSec problems.

 

This segment is sponsored by Kenna Security. Visit Listen

Paul's Security Weekly (Video-Only)
Threat Actors & Recent Trends - Jamie Fernandes, Karsten Chearis - PSW #675 from 2020-11-20T10:00

Jamie and Karsten join us for a discussion about recent attack trends, threat actors, and campaigns carried out by malicious threat actors. Everything from gift card scams to the latest techniqu...

Listen
Paul's Security Weekly (Video-Only)
Cobalt Strike Leak, DNS Cache Poisoning, & Decrypting Open SSH - PSW #674 from 2020-11-14T10:00

In the Security News, not all cyberattacks are created equal, Google patches two more Chrome zero days, What does threat intelligence really mean, Cobalt Strike leaked source code, DNS cache poi...

Listen
Paul's Security Weekly (Video-Only)
Challenges With Securing Container Environments - Badri Raghunathan, Sumedh Thakar - PSW #674 from 2020-11-13T22:00

Sumedh and Badri discuss challenges associated with container Security & DevOps need for visibility into containers. Qualys' new approach to runtime security.

 

This segment is spo...

Listen
Paul's Security Weekly (Video-Only)
Disrupt Attacks at the Endpoint with Attivo Networks - Joseph Salazar - PSW #674 from 2020-11-13T10:00

Attackers have repeatedly demonstrated that they can evade perimeter defenses to compromise a system inside the network. Once they get in, they must break out from that beachhead, conduct discov...

Listen
Paul's Security Weekly (Video-Only)
Multiple iOS 0-Days, Intel Malware Defense, & Windows 0-Day Under Attack - PSW #673 from 2020-11-07T10:00

In the Security News, Deception Technology: No Longer Only A Fortune 2000 Solution, Windows 10 zero-day could allow hackers to seize control of your computer, A Nameless Hiker and the Case the I...

Listen
Paul's Security Weekly (Video-Only)
Proactive Security Using Runbooks - Dan DeCloss - PSW #673 from 2020-11-06T22:00

Runbooks can be a game changer when it comes to executing proactive security assessments and tabletop exercises. This segment will highlight how to use runbooks to enhance your proactive securit...

Listen
Paul's Security Weekly (Video-Only)
Abusing JWT (JSON Web Tokens) - Sven Morgenroth - PSW #673 from 2020-11-06T10:00

Learn how JWTs are implemented, both the correct way and the insecure way. Spoiler alert, most implement them insecurely. Sven will also show you some of the common attacks against JWTs, for use...

Listen
Paul's Security Weekly (Video-Only)
JavaScript Web Tokens, NVIDIA GeForce Experience Vulns, & Hacking Coffee Pots - PSW #672 from 2020-10-31T09:00

In the Security News, the KashmirBlack botnet is behind attacks on CMSs such as WordPress, Joomla, and Drupal, Cybercriminals are Coming After Your Coffee, irriation systems and door openers are...

Listen
Paul's Security Weekly (Video-Only)
How Computer Vision Balances Thoroughness & Speed - PSW #672 from 2020-10-30T21:00

Polarity uses computer vision that works like augmented reality for your data. It's not a new dashboard to search or a new portal to manage. Polarity augments your existing workflows, enriching ...

Listen
Paul's Security Weekly (Video-Only)
Determining Vulnerability Exploitation With Real Software Activity - PSW #672 from 2020-10-30T09:00

Only integrating vulnerability characteristics to determine risk leaves half the prioritization canvas empty. Observing and analyzing user interaction and other surrounding software characterist...

Listen
Paul's Security Weekly (Video-Only)
Discord Vulnerabilities, Chrome 0-Day, & Severe WordPress Flaw - PSW #671 from 2020-10-24T09:00

In the Security News, Testing firm NSS Labs closes up shop, stringing vulnerabilities together to pwn the Discord desktop app, a Wordpress plugin aimed at protecting Wordpress does the opposite,...

Listen
Paul's Security Weekly (Video-Only)
Hackers Hitting Below The Belt - Scott Scheferman - PSW #671 from 2020-10-23T21:00

In 2020 attackers are increasingly targeting firmware and hardware - going below the operating system to hide from traditional security solutions and gain persistence. Both nation state actors a...

Listen
Paul's Security Weekly (Video-Only)
Sysmon Endpoint Monitoring, Now w/ Clipboard Voyeurism - Corey Thuen - PSW #671 from 2020-10-23T09:00

Sysmon is a free endpoint monitoring tool published by Microsoft in their sysinternals suite. It generates process creations, network connections, file creations, DNS, and now clipboard monitori...

Listen
Paul's Security Weekly (Video-Only)
'BleedingTooth' Vulnerability, Zoom Rolls Out E2EE, & 50,000 Cameras Compromised - PSW #670 from 2020-10-17T09:00

In the Security News, Microsoft Uses Trademark Law to Disrupt Trickbot Botnet, Barnes & Noble cyber incident could expose customer shipping addresses and order history, Zoom Rolls Out End-to-End...

Listen
Paul's Security Weekly (Video-Only)
Democratizing & Saasifying Security Operations - Patrick Garrity - PSW #670 from 2020-10-16T21:00

Threats are no longer only a concern of large sophisticated organizations and there is a continued need to democratize security operations and controls so they are accessible to organizations of...

Listen
Paul's Security Weekly (Video-Only)
Prioritize This, Prioritize That, Prioritize With Context! - Roi Cohen, Shani Dodge - PSW #670 from 2020-10-16T09:00

Software vulnerabilities are exploding in growth at an unprecedented rate, and security teams are struggling to stay afloat. Lifebuoys (i.e. CVSS base scores) aren’t doing much to save them, eit...

Listen
Paul's Security Weekly (Video-Only)
10 Years Since Stuxnet, Rare Bootkit Discovered, & Thin Client Vulnerabilities - PSW #669 from 2020-10-10T09:00

US Air Force slaps Googly container tech on yet another war machine to 'run advanced ML algorithms', Rare Firmware Rootkit Discovered Targeting Diplomats, NGOs, Hackers exploit Windows Error Rep...

Listen
Paul's Security Weekly (Video-Only)
Assembling Your First Infosec Home Lab - Tony "tjnull" Punturiero - PSW #669 from 2020-10-09T21:00

Assembling an infosec home lab is great way to learn more about the ever-changing programs and systems in the cyber world. However, it can get complicated to figure out what you really need to g...

Listen
Paul's Security Weekly (Video-Only)
Fast And Secure Web - Alexander Krizhanovsky - PSW #669 from 2020-10-09T09:00

Tempesta FW is an open source hybrid of an HTTPS accelerator and a firewall aiming to accelerate web resources and protect them against DDoS and web attacks. The project is built into the Linux ...

Listen
Paul's Security Weekly (Video-Only)
Ryuk Ransomware Attack, Windows XP Server Leak, & Potential Return to 'Hackers' - PSW #668 from 2020-10-03T09:00

In the Security News, Rumored Windows XP Source Code Leaked Online, Hospitals hit by countrywide ransomware attack, China-linked 'BlackTech' hackers start targeting U.S, a 13-year-old student wa...

Listen
Paul's Security Weekly (Video-Only)
Intrusion Detection Honeypots: Detection Through Deception - Chris Sanders - PSW #668 from 2020-10-02T21:00

Intrusion Detection Honeypots are fake services, data, and tokens placed inside the network to lure attackers into interacting with them to give away their presence. If you can control what the ...

Listen
Paul's Security Weekly (Video-Only)
NGINX As An RTMP Proxy - PSW #668 from 2020-10-02T09:00

Paul will discuss his process for creating a docker container for running NGINX as an RTMP proxy for streaming video to multiple services; complete with SSL and authentication.

 

V...

Listen
Paul's Security Weekly (Video-Only)
Zerologon Attack, CrimeOps, & BLESA Bluetooth Flaw - PSW #667 from 2020-09-19T09:00

Three Cybersecurity Lessons from a 1970s KGB Key Logger, MFA Bypass Bugs Opened Microsoft 365 to Attack, How Hackers Can Pick Your LocksJust By Listening, U.S. House Passes IoT Cybersecurity Bil...

Listen
Paul's Security Weekly (Video-Only)
Elastic Security Opens Public Detections Rules Repo - James Spiteri - PSW #667 from 2020-09-18T21:00

Following the release of our detection engine, Elastic opened up a new GitHub repo of our public detection rules. See: https://github.com/elastic/detection-rules. This is where our security inte...

Listen
Paul's Security Weekly (Video-Only)
Key Findings From The Newly Released BSIMM11 Report - Mike Ware - PSW #667 from 2020-09-18T09:00

BSIMM11, the latest version of the Building Security In Maturity Model (BSIMM), was created to help organizations plan, execute, measure, and improve their Application Security program/initiativ...

Listen
Paul's Security Weekly (Video-Only)
Chrome Sandbox Exploit, Cisco Jabber CVE, & Lea Snyder w/ BSides Boston - PSW #666 from 2020-09-12T09:00

We welcome special guest Lea Snyder, BSides Boston Organizer, to talk all things BSides Boston 2020 for its 10 year anniversary! In the Security News, Cisco Patches Critical Vulnerability in Jab...

Listen
Paul's Security Weekly (Video-Only)
Building Security Into the DevOps Lifecycle - Sumedh Thakar - PSW #666 from 2020-09-11T21:00

DevOps has gained momentum over the years as its methods have been used by teams worldwide to accelerate application delivery. But where we continue to struggle is in integrating security into t...

Listen
Paul's Security Weekly (Video-Only)
The Patchless Horseman - Roi Cohen & David Asraf - PSW #666 from 2020-09-11T09:00

Every time you deploy a patch nothing has ever gone wrong, right? Most of us have been burned by deploying a patch, causing downtime in your environment, getting in trouble with users and manage...

Listen
Paul's Security Weekly (Video-Only)
Slack RCE, Tesla Dodges Ransomware, & Cisco Router 0-Day - PSW #665 from 2020-09-05T09:00

The NSA Makes Its Powerful Cybersecurity Tool Open Source, The bizarre reason Amazon drivers are hanging phones in trees near Whole Foods, Elon Musk Confirms Serious Russian Bitcoin Ransomware A...

Listen
Paul's Security Weekly (Video-Only)
Cybersecurity & Patient Safety - Justin Armstrong - PSW #665 from 2020-09-04T21:00

Successful attacks on healthcare entities are steadily increasing. Sophisticated criminals and nation states are focusing more attention on healthcare than ever before. The main goals are to ste...

Listen
Paul's Security Weekly (Video-Only)
Lovable Security: Be a Data Custodian, Not a Data Owner - Fredrick "Flee" Lee - PSW #665 from 2020-09-04T18:43:12

Loveable Security: Flee's approach to cybersecurity is that is should be "loveable." He thinks cybersecurity perpetuates a myth of an elite, isolated team of stealth insiders who are seen as enf...

Listen
Paul's Security Weekly (Video-Only)
Predicting Vulnerabilities In Compiled Code - Roi Cohen & Shani Dodge - PSW #664 from 2020-08-29T09:00

The growth in software vulnerability exploitation creates a need for better prediction capabilities. Over time, there have been shifts in the ways of discovering vulnerabilities in binary code. ...

Listen
Paul's Security Weekly (Video-Only)
SWVHSC Micro Interviews: Polarity & Netsparker - Ferruh Mavituna, Paul Battista - PSW #664 from 2020-08-28T21:00

Most analysts will tell you that they balance between being thorough and getting the job done quickly. Paul Battista asked the security community to weigh in on this debate. He’ll share what the...

Listen
Paul's Security Weekly (Video-Only)
Hacking Tesla's Model 3, 28,000 Printers Hijacked, & iOS 14 Privacy Changes - PSW #664 from 2020-08-28T09:00

Google Researcher Reported 3 Flaws in Apache Web Server Software, Medical Data Leaked on GitHub Due to Developer Errors, Experts hacked 28,000 unsecured printers to raise awareness of printer se...

Listen
Paul's Security Weekly (Video-Only)
SWVHSC Micro Interviews: Gravwell & Rapid7 - Corey Thuen, Deral Heiland - PSW #663 from 2020-08-22T09:00

What use cases are addressed by Threat Hunting Platforms and SIEMs? Where is the overlap and where are the differences? Corey Thuen, Founder of Gravwell, covers the high level and low-level tech...

Listen
Paul's Security Weekly (Video-Only)
Voice Phishers, 'SpiKey' Lock Picking, & Coffee Cup Hackers - PSW #663 from 2020-08-21T21:00

New Microsoft Defender ATP Capability Blocks Malicious Behaviors, Voice Phishers Targeting Corporate VPNs, IBM finds vulnerability in IoT chips present in billions of devices, The Sounds a Key M...

Listen
Paul's Security Weekly (Video-Only)
Protecting Critical Infrastructure In Hybrid Clouds - Dan Perkins, Harry Sverdlove - PSW #663 from 2020-08-21T09:00

Customers are concerned about protecting critical services such as Active Directory from compromise. It's game over if AD is compromised. AD environments can be heterogeneous; public cloud, on-p...

Listen
Paul's Security Weekly (Video-Only)
Vulnerability Rich - Contextually Blind! - Michael Assraf - PSW #662 from 2020-08-15T09:00

It s not uncommon to find the traditional vulnerability assessment report buried under the CISO family picture, compliance books, and his latest blood pressure test. These reports highlight the ...

Listen
Paul's Security Weekly (Video-Only)
Adobe RCEs, Amazon Alexa Vulns, & TeamViewer Flaw - PSW #662 from 2020-08-14T21:00

This week, Amazon Alexa One-Click Attack Can Divulge Personal Data, Adobe tackles critical code execution vulnerabilities in Acrobat, Reader, Threat actors managed to control 23% of Tor Exit nod...

Listen
Paul's Security Weekly (Video-Only)
Why Elastic Is Making Endpoint Security 'Free And Open' - Mike Nichols - PSW #662 from 2020-08-14T09:00

Elastic believes that transparency and collaboration must be the new norm for the greater infosec community to succeed in stopping threats at scale. With many individuals now working from home, ...

Listen
Paul's Security Weekly (Video-Only)
Automating Your Vulnerability Management Program - Mehul Revankar, Sumedh Thakar - PSW #661 from 2020-08-08T09:00

In this segment, we discuss the importance of automating the Vulnerability Management Program and discuss Qualys VMDR which takes vulnerability management to the next level bringing detection an...

Listen
Paul's Security Weekly (Video-Only)
SWVHSC: Netgear Flaws, Satellite Spying, & Stealing UltraLoq Keys - PSW #661 from 2020-08-07T21:00

How hackers could spy on satellite internet traffic with just $300 of home TV equipment, Smart locks opened with nothing more than a MAC address, 17-Year-Old 'Mastermind' and 2 Others Behind the...

Listen
Paul's Security Weekly (Video-Only)
SWVHSC: Observing Disinformation Campaigns - Chad Anderson - PSW #661 from 2020-08-07T09:00

Chad talks about the DomainTools COVID research (and how they stumbled on the CovidLock Android ransomware), mapping the Reopen Campaigns in more detail. He will then touch on some of the work h...

Listen
Paul's Security Weekly (Video-Only)
GNU GRUB2 Vulnerability, 'BootHole' Secure Boot Threat, & Garmin Ransomware Hack - PSW #660 from 2020-08-04T17:47:08

A Vulnerability that Allowed Brute-Forcing Passwords of Private Zoom Meetings, Russia's GRU Hackers Hit US Government and Energy Targets, a New tool that detects shadow admin accounts in AWS and...

Listen
Paul's Security Weekly (Video-Only)
MIDAS - Siddharth Bhatia - PSW #660 from 2020-08-01T09:00

MIDAS uses unsupervised learning to detect anomalies in a streaming manner in real-time and has become a new baseline. It was designed keeping in mind the way recent sophisticated attacks occur....

Listen
Paul's Security Weekly (Video-Only)
Gravwell Big Bang Release - Corey Thuen - PSW #660 from 2020-07-31T21:00

The Gravwell Data Fusion platform is releasing a major update this week. New features make analyzing logs and network data much easier for new users while still keeping the raw power of a unix-l...

Listen
Paul's Security Weekly (Video-Only)
Cisco Security Flaw, Million Dollar Bounties, & Jackpotting ATMs - PSW #659 from 2020-07-25T09:00

Vulnerable Cellular Routers Targeted in Latest Attacks on Israel Water Facilities, Fugitive Wirecard Executive Jan Marsalek Was Involved In Attempt to Purchase Hacking Team Spyware, 8 Cybersecur...

Listen
Paul's Security Weekly (Video-Only)
The Power of the Cloud Platform: One Single Agent, One Global View - Sumedh Thakar - PSW #659 from 2020-07-24T21:00

Leveraging the unifying power of a cloud-based security platform to provide full context and comprehensive visibility into the entire attack chain for a complete, accurate risk-based analysis an...

Listen
Paul's Security Weekly (Video-Only)
Affects of COVID-19 on Web Applications - Zane Lackey - PSW #659 from 2020-07-24T09:00

Zane Lackey joins us once again to talk about Zero Trust, Cloud Security, and the impact of COVID-19 on Digital Transformation! This segment is sponsored by Signal Sciences.

 

Visi...

Listen
Paul's Security Weekly (Video-Only)
Twitter Mega Hack, 3rd Party IoT Vulns, & Windows DNS SIGRed RCE - PSW #658 from 2020-07-18T21:00

Microsoft fixes critical wormable RCE SigRed in Windows DNS servers, Zoom Addresses Vanity URL Zero-Day, Docker attackers devise clever technique to avoid detection,a massive DDoS Attack Launche...

Listen
Paul's Security Weekly (Video-Only)
Welcome Our Newest Host! - John Snyder - PSW #658 from 2020-07-18T09:00

The guys welcome our newest host to the family. John Snyder will replace Matt Alderman on Security and Compliance Weekly. Tune in to hear about how John made the jump from being a trial lawyer i...

Listen
Paul's Security Weekly (Video-Only)
Artificial Intelligence and Machine Learning in Cybersecurity - Ankur Chowdhary - PSW #658 from 2020-07-17T21:00

With advent of Internet of Things (IoT) and emerging cloud technologies, ensuring continued cybersecurity at scale is a challenging task. An ever growing increase in demand of cybersecurity work...

Listen
Paul's Security Weekly (Video-Only)
RCE Chaos, Zoom 0-Day, & Banning TikTok - PSW #657 from 2020-07-11T09:00

Hackers Are Exploiting a 5-Alarm Bug in Networking Equipment, Cisco Talos discloses technical details of Chrome and Firefox flaws, Palo Alto Networks Patches Command Injection Vulnerabilities in...

Listen
Paul's Security Weekly (Video-Only)
IPv6 Tunneling - Joff Thyer - PSW #657 from 2020-07-10T09:00

In this technical demo, Joff will show how you can bring up an IPv6 tunnel to learn and play with IPv6 connectivity and basic concepts. This tech segment will largely be a demo on a Debian based...

Listen
Paul's Security Weekly (Video-Only)
Netgear RCE, Guacamole Flaws, & 'Lucifer' DDoS Botnet - PSW #656 from 2020-07-05T09:00

Cisco Releases Security Advisory for Telnet Vulnerability in IOS XE Software, Firefox 78 is out with a mysteriously empty list of security fixes, Python Arbitrary File Write Prevention: The Tarb...

Listen
Paul's Security Weekly (Video-Only)
OSINT Scraping with Python - Ryan Hays - PSW #656 from 2020-07-04T18:23:20

With bug bounties becoming more and more main stream for organizations. The bounty hunters are turning to more and more automation. Open source intelligence gathering can be automated with the u...

Listen
Paul's Security Weekly (Video-Only)
Work From Home Cyber Security - Jerry Chen - PSW #656 from 2020-07-03T09:00

Hackers know that more people are working from home now and accessing/ sending/ sharing sensitive company data through their home networks. How can businesses help employees secure their home ne...

Listen
Paul's Security Weekly (Video-Only)
New Web Technology & Impact on Automated Security Testing - Benjamin Daniel Mussler - PSW #655 from 2020-06-13T21:00

As web applications have evolved from static HTML pages into fully-fledged applications with a native feel to them, web browsers continue to provide developers with truly novel functionality. Th...

Listen
Paul's Security Weekly (Video-Only)
OSS Vulnerabilities, UPnP Flaws, & 0-Days for Bad People - PSW #655 from 2020-06-13T09:00

Hospital-busting hacker crew may be behind ransomware attack that made Honda halt car factories, 3 common misconceptions about PCI compliance, SMBleed could allow a remote attacker to leak kerne...

Listen
Paul's Security Weekly (Video-Only)
Enhancing Vulnerability Management By Including Penetration Testing Results - Dan DeCloss - PSW #655 from 2020-06-12T21:00

We’ll discuss how organizations can improve their vulnerability management life cycle and demo some quick ways to get started with vulnerability management and combining penetration test results...

Listen
Paul's Security Weekly (Video-Only)
Root Cert Chaos, Octopus Scanner, & RobbinHood & the Merry Men - PSW #654 from 2020-06-06T21:00

Octopus Scanner Sinks Tentacles into GitHub Repositories, RobbinHood and the Merry Men, Zoom Restricts End-to-End Encryption to Paid Users, Hackers steal secrets from US nuclear missile contract...

Listen
Paul's Security Weekly (Video-Only)
PCAPS Or It Didn't Happen- Corey Thuen - PSW #654 from 2020-06-06T09:00

Threat hunting activities often require packet capture analysis but capturing and storing PCAP at scale is rough. This segment covers open source tools for collecting packet captures on demand w...

Listen
Paul's Security Weekly (Video-Only)
Lightweight Vulnerability Management Using NMAP - PSW #654 from 2020-06-05T21:00

Paul delivers a Technical Segment on Lightweight Vulnerability Management using NMAP!

 

Visit https://www.securityweekly.com/psw f...

Listen
Paul's Security Weekly (Video-Only)
Ed Skoudis & Security News - PSW #653 from 2020-05-30T09:00

In this week's Security News, NSA warns Russia-linked APT group is exploiting Exim flaw since 2019, Hackers Compromise Cisco Servers Via SaltStack Flaws, OpenSSH to deprecate SHA-1 logins due to...

Listen
Paul's Security Weekly (Video-Only)
"Burn-In: A Novel of the Real Robotic Revolution" - Peter Singer - PSW #653 from 2020-05-29T21:00

"Burn-In: A Novel of the Real Robotic Revolution" (May 26 release) is a new kind of novel+nonfiction. It uses the technothriller format as a way to share real research on the ways that AI+automa...

Listen
Paul's Security Weekly (Video-Only)
2020 MITRE ATT&CK Malware Trends - Greg Foss - PSW #653 from 2020-05-29T09:00

The MITRE ATT&CK framework has had a major impact on the cybersecurity industry and has given a defenders a haystack in which to focus their defensive efforts. What’s most interesting, perhaps, ...

Listen
Paul's Security Weekly (Video-Only)
Stuxnet, RCE's Everywhere, & Breach Chaos - PSW #652 from 2020-05-23T21:00

In the Security News, Hackers target the air-gapped networks of the Taiwanese and Philippine military, Stored XSS in WP Product Review Lite plugin allows for automated takeovers, Remote Code Exe...

Listen
Paul's Security Weekly (Video-Only)
HTTP Security Headers In Action - Sven Morgenroth - PSW #652 from 2020-05-23T09:00

HTTP security headers are an easy and effective way to harden your application against all kinds of client side attacks. We'll discuss which security headers there are, what functions they have ...

Listen
Paul's Security Weekly (Video-Only)
Building An InfoSec Career - Jason Nickola - PSW #652 from 2020-05-22T21:00

The guests on Trust Me I'm Certified have dropped some real knowledge and I'd like to distill that down as well as talk about building technical skills, looking at your career as a 'thing' that ...

Listen
Paul's Security Weekly (Video-Only)
Ramsay Malware, Top 10 CVE's, & Reverse RDP Attacks - PSW #651 from 2020-05-16T21:00

In the Security News, Palo Alto Networks Patches Many Vulnerabilities in PAN-OS, Zerodium will no longer acquire certain types of iOS exploits due to surplus, New Ramsay Malware Can Steal Sensit...

Listen
Paul's Security Weekly (Video-Only)
Securing Remote Access: Quarantines & Security - Harry Sverdlove - PSW #651 from 2020-05-15T21:00

We use terms such as Social Distancing, Quarantine, and Contact Tracing on a regular basis amid the current crisis. How do these apply to Information and Network Security?

 

To lea...

Listen
Paul's Security Weekly (Video-Only)
MITRE ATT&CK & Security Visibility: Looking Beyond Endpoint Data - Mike Nichols - PSW #651 from 2020-05-15T09:00

In this episode of Paul's Security Weekly, we will dive into the recently published MITRE ATT&CK second-round evaluation based on APT29. While MITRE does not declare a "winner," stressing that t...

Listen
Paul's Security Weekly (Video-Only)
Vulnerability Madness, IoT Botnets, & Breach Chaos - PSW #650 from 2020-05-11T16:32:54

In the Security News, Naikon APT Hid Five-Year Espionage Attack Under Radar, PoC Exploit Released for DoS Vulnerability in OpenSSL, 900,000 WordPress sites attacked via XSS vulnerabilities, Kaij...

Listen
Paul's Security Weekly (Video-Only)
Project Fantastic - Bringing The CLI to GUI Users - PSW #650 from 2020-05-08T21:00

Lots of IT and security professionals do not want to use the CLI, which has set them back. Fantastic exposes the same power as the CLI in an easy to use GUI that is more consistent and hopefully...

Listen
Paul's Security Weekly (Video-Only)
Public Utility Security and National Guard Support - Chris Elgee, Jim McPherson - PSW #650 from 2020-05-08T09:00

Public utilities are under fire from malicious actors now, more than ever. At the same time, authorities for National Guard units are expanding, allowing greater levels of support. However, this...

Listen
Paul's Security Weekly (Video-Only)
Defensive Strategies and Qualys VMDR - PSW #649 from 2020-05-02T21:00

The crew talks about how to accomplish asset management, vulnerability management, prioritization of remediation, and the actual remediation steps! No small task! Then check out a deep dive demo...

Listen
Paul's Security Weekly (Video-Only)
Python Pickling, Sophos 0-Day, & AWS RDS MySQL - PSW #649 from 2020-05-02T09:00

In the Security News, Half a Million Zoom Accounts Compromised by Credential Stuffing, Sold on Dark Web, Scammers pounce as stimulus checks start flowing, NSA shares list of vulnerabilities comm...

Listen
Paul's Security Weekly (Video-Only)
Fighting the Cyber War With Battlefield Tactics - Jeremy Miller, Philip Niedermair - PSW #649 from 2020-05-01T21:00

Jeremy Miller, a former Green Beret and current CEO of Lionfish Cyber Security, will discuss how mission set tactics used by Special Forces can be applied directly to the cyber war being waged t...

Listen
Paul's Security Weekly (Video-Only)
iOS Mail Hijack, Hacking Satellites, & 0-Days for Days - PSW #648 from 2020-04-25T21:00

In the Security News, Legions of cybersecurity volunteers rally to protect hospitals during COVID-19 crisis, Wanna hack a Satellite? The Navy will let you…, IBM 0-day released for days after not...

Listen
Paul's Security Weekly (Video-Only)
Layer8 Conference & WorkshopCon - Ori Zigindere, Patrick Laverty - PSW #648 from 2020-04-25T09:00

Patrick Laverty created and co-organizes the Layer 8 Conference with Lea Snyder. This year will be the 3rd annual conference that solely focuses on social engineering and OSINT topics. Ori Zigin...

Listen
Paul's Security Weekly (Video-Only)
The Insider Threat - Steven Bay - PSW #648 from 2020-04-24T21:00

Steven Bay has over 16 years of cybersecurity experience, spanning the military, government, consulting, and enterprise security. For 10 of those years, he supported the National Security Agency...

Listen
Paul's Security Weekly (Video-Only)
Hospital Hackers, $500K Zoom 0day, & SFO Windows Hackers - PSW #647 from 2020-04-18T21:00

This week in the Security News, How to teach your iPhone to recognize you while wearing a mask, Hackers Targeting Critical Healthcare Facilities With Ransomware During Coronavirus Pandemic, VMwa...

Listen
Paul's Security Weekly (Video-Only)
Pen Testing to Validate Vulnerability Scanners - Magno Gomes - PSW #647 from 2020-04-18T09:00

Many people inaccurately use vulnerability scans or vulnerability assessments as terms that are synonymous with penetration tests. Those that do know the difference often think you have to choos...

Listen
Paul's Security Weekly (Video-Only)
Threat Intel Program Strategies - Wade Woolwine - PSW #647 from 2020-04-17T21:00

Defining key areas of investment that organizations need to consider in their programs. Within the areas of investment, we talk about functional areas and defining capabilities within each funct...

Listen
Paul's Security Weekly (Video-Only)
Zoom, Kubernetes, and Hacking - PSW #646 from 2020-04-11T21:00

A little about Zoom vulnerabilities and data leaks and Cisco Webex vulnerabilities. We talk about security Kubernetes and how the same security principals apply, vulnerabilities in ICS systems a...

Listen
Paul's Security Weekly (Video-Only)
Tales From The Crypt...Analyst - Part 2 - Jeff Man - PSW #646 from 2020-04-11T09:00

In the second part of our interview series with the legend Jeff Man, he continues his discussion with Paul, Matt, and Lee, about the many myths, legends and fables in hacker history. One of the ...

Listen
Paul's Security Weekly (Video-Only)
To Hunt or Not To Hunt; This is Never a !=? - Tyler Robinson - PSW #646 from 2020-04-10T21:00

We welcome Security Weekly's own Tyler Robinson for a Technical Segment, to talk about how individuals are tracked and then demonstrates different TTPs Nisos uses to hunt and track people of int...

Listen
Paul's Security Weekly (Video-Only)
Security News - To Zoom or Not to Zoom - PSW #645 from 2020-04-04T16:00

This segment will largely focus on the recent Zoom vulnerabilities and the responses from security researchers, the security community and enterprises. Should you stop using Zoom? Tune in to fin...

Listen
Paul's Security Weekly (Video-Only)
IoT Devices: Security and Privacy Labels Research - Lorrie Cranor - PSW #645 from 2020-04-04T04:00

At Carnegie Mellon University we are designing a usable security and privacy label for smart devices to help consumers make informed choices about Internet of Things device purchases and encoura...

Listen
Paul's Security Weekly (Video-Only)
Collaboration Between NetOps and SecOps in Today's World - Matt Allen - PSW #645 from 2020-04-03T16:52:18

Matt and the Security Weekly crew will discuss how the interaction between network engineers and security operations has changed over the years, as well as the value of the network when identify...

Listen
Paul's Security Weekly (Video-Only)
Drobo Exploit, Docker Escape, SMBv3.11 - PSW #644 from 2020-03-21T09:00

SANS Penetration Testing | Microsoft SMBv3.11 Vulnerability and Patch CVE-20200796 Explained, Drobo 5N2 4.1.1 - Remote Command Injection, $100K Paid Out for Google Cloud Shell Root Compromise, W...

Listen
Paul's Security Weekly (Video-Only)
Zen And The Art Of Logs In The Cloud - Corey Thuen - PSW #644 from 2020-03-20T21:00

Struggling with how to get your logs from the cloud? Have no fear, Corey and the Security Weekly crew talk about how to configure your logs in the cloud, use cloud-native services to handle the ...

Listen
Paul's Security Weekly (Video-Only)
Work from home securely - PSW #644 from 2020-03-20T09:00

The challenges and differentiated values of desktop and laptop protection and administrative tool control (e.g., Powershell, SSH) for remote users and administrators to work securely. Visit http...

Listen
Paul's Security Weekly (Video-Only)
Protecting Data on Employee 0wned PCs - Gabe Gumbs - PSW #643 from 2020-03-15T10:30

COVID-19, among other things, has deemed it necessary for many to work from home. There are several security concerns that need to be raised, such as those who work from home still require acces...

Listen
Paul's Security Weekly (Video-Only)
Connected devices security - Dorit Naparstek - PSW #643 from 2020-03-15T09:00

Hacks performed on connected & IoT devices, such as routers, security cameras, smart meters, etc. are increasingly common, and revealing major vulnerabilities in existing security measure. This ...

Listen
Paul's Security Weekly (Video-Only)
Girls Who Hack and Secure Open Vote - Bianca Lewis - PSW #643 from 2020-03-14T16:00

Girls Who Hack teaches classes primarily to middle school girls on hacking and making. Secure Open Vote is an end to end, open source election system that is in the design stages. www.BiaSciLab....

Listen
Paul's Security Weekly (Video-Only)
Tomcat, AWS Malware, Hacker Movies - PSW #642 from 2020-03-09T16:24:37

Apache Tomcat AJP exploit, malware in AWS, hacker movies and more! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/PSWEpisode642...

Listen
Paul's Security Weekly (Video-Only)
Mark Cooper, PKI Solutions - Mark Cooper - PSW #642 from 2020-03-08T00:54:36

How SHAKEN/STIR and PKI will end the global robocall problem Link to an article Mark wrote for Dark Reading: https://www.darkreading.com/endpoint/shaken-stir-finally!-a-solution-to-caller-id-spo...

Listen
Paul's Security Weekly (Video-Only)
Active Directory, Azure and Windows Security - Sean Metcalf - PSW #642 from 2020-03-08T00:42:34

Active Directory & Microsoft Cloud (Azure AD & Office 365) Security, including a breakdown of Microsoft's security offerings and recommendations for cloud migrations for Active Directory.

Listen
Paul's Security Weekly (Video-Only)
Cool Things We Found At RSAC 2020 - PSW #641 from 2020-03-02T01:33:34

We found some cool stuff at RSAC 2020! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: Listen

Paul's Security Weekly (Video-Only)
Protect Ya Data - Gabe Gumbs - PSW #641 from 2020-03-01T23:59:28

Gabriel Gumbs and the Security Weekly crew discuss strategies for protecting your data. We will explore practical use-cases for needing to manage access and protect your data as it pertains to s...

Listen
Paul's Security Weekly (Video-Only)
Tales From The Crypt...Analyst - Jeff Man - PSW #641 from 2020-03-01T23:09:04

There are many myths, legends and fables in hacker history. One of the themes of these legends surrounds some of the first red team hackers working for the US Government out of NSA. The building...

Listen
Paul's Security Weekly (Video-Only)
Tesla Sensors, Israeli Soldiers Phished, Machine Learning - PSW #640 from 2020-02-24T10:00

Nedbank Says 1.7 Million Customers Impacted by Breach at Third-Party Provider, 500 Chrome Extensions Caught Stealing Private Data of 1.7 Million Users, 5 inch piece of electrical tape can fool T...

Listen
Paul's Security Weekly (Video-Only)
Kubernetes/Container Security - Ian Coldwater - PSW #640 from 2020-02-23T10:00

Ian Coldwater is the Lead Platform Security Engineer at Heroku. Ian will discuss Kubernetes and container security!

Visit https://www.securit...

Listen
Paul's Security Weekly (Video-Only)
Unifying SIEM And Endpoint Security - PSW #640 from 2020-02-22T10:00

Elastic recently released Elastic Security 7.6 - the culmination of months of work by the security team and a monumental leap forward toward delivering a unified threat protection and security a...

Listen
Paul's Security Weekly (Video-Only)
Docker, 42 Vulnerabilities, Backdoors, Spying on 100+ Foreign Govs. - PSW #639 from 2020-02-16T10:00

In the Security News, Misconfigured Docker Registries Expose Thousands of Repositories, a Forgotten motherboard driver turns out to be perfect for slipping Windows ransomware past antivirus chec...

Listen
Paul's Security Weekly (Video-Only)
The Unprotected Attack Surface of the Enterprise - John Loucaides - PSW #639 from 2020-02-15T10:00

Hackers are using firmware implants and backdoors to compromise enterprise security with attacks that are stealthy and persistent. It’s time for information security specialists to learn how to ...

Listen
Paul's Security Weekly (Video-Only)
Living in Blue Team Land and Skicon - O'Shea Bowens - PSW #639 from 2020-02-14T10:00

O'Shea Bowens is the CEO of Null Hat Security. O'Shea will discuss why I think blue teaming is as essential now as our red brothers. Mistakenly calling out APT's. A new type of security conferen...

Listen
Paul's Security Weekly (Video-Only)
Security News - PSW #638 from 2020-02-09T09:30

In the Security News, Twitter fixes API bug that can reveal users, Microsoft patches flaws in Azure stack, 8 cities that have been crippled by cyber attacks and how they fought against it, and s...

Listen
Paul's Security Weekly (Video-Only)
Adventures In AWS Computing - PSW #638 from 2020-02-08T10:30

Paul shows you how to create secure Docker containers and begin to deploy them to Amazon ECS. This segment focuses on the security aspects of taking a legacy/non-contanerized application to the ...

Listen
Paul's Security Weekly (Video-Only)
BADASS Army - The Fight Against Revenge Porn - Katelyn Bowden - PSW #638 from 2020-02-07T10:00

After finding her own intimate photos online without her consent, Katelyn Bowden discovered that there weren't many resources for those who find themselves victims of this sort of abuse. In resp...

Listen
Paul's Security Weekly (Video-Only)
Wawa Breach, Citrix ADC, Magecart Hackers, Ragnarok Ransomware - PSW #637 from 2020-02-03T10:00

In the Security News, NHS alerted to severe bulbs in GE health equipment, Ragnarok Ransomware targets Citrix ADC & disables Windows Defender, suspected Magecart hackers arrested in Indonesia, Wa...

Listen
Paul's Security Weekly (Video-Only)
Stopping Python Backdoor Attacks - Peter Smith - PSW #637 from 2020-02-02T10:00

The recent MechaFlounder was a backdoor attack linked to Iranian threat actors who targeted Turkish entities. Similar Python-based backdoor attacks have managed to evade traditional network secu...

Listen
Paul's Security Weekly (Video-Only)
The Unicorn Project and The Five Ideals - Gene Kim - PSW #637 from 2020-02-01T10:00

In this week's episode of Paul's Security Weekly, Paul and the guys welcome back Gene Kim to interview him about his newest book "The Unicorn Project". Gene shares with us his goals and aspirati...

Listen
Paul's Security Weekly (Video-Only)
Tomatoes, Jeff Bezo, Vuln. In AMD ATI Radeon, 'The Rise of Skywalker' - PSW #636 from 2020-01-26T10:00

In the Security News, Microsoft Security Shocker As 250 Million Customer Records Exposed Online, the NSA Offers Guidance on Mitigating Cloud Flaws, Multiple Vulnerabilities Found in AMD ATI Rade...

Listen
Paul's Security Weekly (Video-Only)
Electronic Frontier Foundation (EFF), Godwin's Law, Freedom of Speech - Mike Godwin - PSW #636 from 2020-01-25T10:00

Paul, Doug and Tyler interview Mike Godwin about the creation of the EFF, why it was created and how he became involved, some of the first cases taken on by the EFF, Godwin's Law, the right to r...

Listen
Paul's Security Weekly (Video-Only)
Dug Song - Engineer to Entrepreneur - Dug Song - PSW #636 from 2020-01-24T18:21:43

Paul, Doug and Tyler interview Dug Song about how he got his start in Information Security, what prompted him to begin work for dsniff, his transition from engineer to entrepreneur, what he lear...

Listen
Paul's Security Weekly (Video-Only)
CVE-2020-0601, Netscaler RCE, npm - PSW #635 from 2020-01-19T10:00

We discuss the details and impact of the latest flaw, disclosed by NSA, in Windows 10 that allows attackers to pass off malware as signed applications and so much more. The Citric Netscaler vuln...

Listen
Paul's Security Weekly (Video-Only)
Hacking IoT Devices - Jeff Spielberg, Ryan Speers - PSW #635 from 2020-01-18T10:00

The world continues to see a proliferation of highly insecure IoT/embedded products. How can companies making embedded products design security in from the start, and why don t they do it today?...

Listen
Paul's Security Weekly (Video-Only)
What Does It Mean To Be A Hacker? - PSW #635 from 2020-01-17T21:58:47

This is the Hacker Culture Roundtable discussion from the Security Weekly Christmas podcast marathon and features almost all of our hosts and special guests. Hacking is a term used to describe t...

Listen
Paul's Security Weekly (Video-Only)
Security News: January 9, 2020 - PSW #634 from 2020-01-13T10:00

In the security news, Car hacking hits the streets, 4 Ring employees fired for spying on customers, MITRE presents ATT&CK for ICS, and Las Vegas suffers cyberattack on the first day of CES!

...

Listen
Paul's Security Weekly (Video-Only)
The Keys to Your Kingdom: Protecting Data in Hybrid and Multiple Public Clouds - Ambuj Kumar - PSW #634 from 2020-01-12T10:00

According to Gartner, 70% of businesses are adopting a hybrid cloud and multi-cloud strategy to augment their internal data centers. The challenges of protecting data and using encryption for mu...

Listen
Paul's Security Weekly (Video-Only)
Improve Pen Testing Outcomes With Purple Teaming - PSW #634 from 2020-01-11T10:00

Purple teaming reduces the lifespan of vulnerabilities found from pentests by facilitating knowledge transfer between red and blue teams in the remediation phase. PlexTrac provides a single inte...

Listen
Paul's Security Weekly (Video-Only)
Security News: January 2, 2020 - PSW #633 from 2020-01-05T10:00

In the security news, mysterious Drones are Flying over Colorado (watchout Mr. Alderman), 7 Tips for Maximizing Your SOC, The Most Dangerous People on the Internet This Decade, North Korean Hack...

Listen
Paul's Security Weekly (Video-Only)
Diplomacy, Norms and Deterrence in Cyberspace - Chris Painter - PSW #633 from 2020-01-04T09:30

Global conversations around acceptable norms of behavior in cyberspace (particularly for states), attribution, accountability, and deterrence (though we have not done well on the last one), rece...

Listen
Paul's Security Weekly (Video-Only)
Security History - Lessons from the past - PSW #632 from 2020-01-03T10:00

The history of security can be traced back to a variety of different sources. The amount of articles on the topic is dizzying. Most will cite names of early phone phreaks, Kevin Mitnick, Kevin P...

Listen
Paul's Security Weekly (Video-Only)
Who is Going to Protect the Brave New Virtual Worlds and HOW? - Kavya Pearlman - PSW #633 from 2020-01-03T02:58:57

Emerging technologies such as Virtual, Augmented and Mixed Reality are inevitably gaining momentum and helping businesses gain competitive advantage. These technological advancements are giving ...

Listen
Paul's Security Weekly (Video-Only)
Security vs. Compliance - PSW #632 from 2019-12-28T17:00

It was once said that if Security and Compliance were in a relationship the status would be "It's Complicated". This discussion will aim to help you understand this relationship and how it can b...

Listen
Paul's Security Weekly (Video-Only)
Holiday Hack Challenge - PSW #631 from 2019-12-25T10:00

Each year the team at Counterhack Challenges makes available the Holiday Hack Challenge. Led by Ed Skoudis, and created by some of the most talented security professionals in the industry, it is...

Listen
Paul's Security Weekly (Video-Only)
The State of Penetration Testing - PSW #631 from 2019-12-24T10:00

Penetration testing has evolved quite a bit in the past year. As defenses shift, and in some cases get much better, attack techniques and landscapes have changed as well. - What has changed in t...

Listen
Paul's Security Weekly (Video-Only)
DevOps and Securing Applications - PSW #632 from 2019-12-23T19:33:23

- Given that DevOps is a process and its execution requires many different tools, how do we get started "doing DevOps"? - What about DevOps allows us to produce more secure applications? - What ...

Listen
Paul's Security Weekly (Video-Only)
Blue Team Tactics and Techniques - PSW #631 from 2019-12-23T16:39:12

It's often said that attackers need only to get it right once, where defenders have to be right all of the time. Those of us who have worked in a security role as a defender know we don't always...

Listen
Paul's Security Weekly (Video-Only)
Risks, Ransomware, Data Leaks, Oh My! - PSW #630 from 2019-12-15T10:00

In the Security News, Reveton ransomware schemer stripped of six years of freedom, £270,000, and Rolex, Web-hosting firm 1&1 hit by almost €10 million GDPR fine over poor security at call centre...

Listen
Paul's Security Weekly (Video-Only)
Backdoors & Breaches - The Card Game - PSW #630 from 2019-12-14T10:00

John Strand is a Security Analyst, Founder of Black Hills Information Security, and CTO of Offensive Countermeasures. John will be talking about Backdoors & Breaches, the Incident Response card ...

Listen
Paul's Security Weekly (Video-Only)
Runtime Protection for Containers - Jorge Salamero - PSW #630 from 2019-12-13T10:00

Jorge Salamero is the Director of Technical Marketing at Sysdig. Jorge enjoys playing with containers and Kubernetes, home automation and DIY projects. Currently, he is part of the Sysdig team, ...

Listen
Paul's Security Weekly (Video-Only)
Defecting Chinese, IoT Smartwatch, and Malicious SDKs - PSW #629 from 2019-12-09T10:00

Netflix: BPF is a new type of software we use to run Linux apps securely in the kernel, Automated security tests with OWASP ZAP, HackerOne Breach Leads to $20,000 Bounty Reward, US-CERT AA19-339...

Listen
Paul's Security Weekly (Video-Only)
Open Source Intelligence (OSINT) in Cyber - PSW #629 from 2019-12-08T10:00

Micah Hoffman is the Principle Investigator at Spotlight Infosec. Looking to increase the publicity of using Open Source Intelligence (OSINT) in traditional cyber fields like pentest, DFIR, and ...

Listen
Paul's Security Weekly (Video-Only)
Outlook on Phishing in 2020 - Eric Brown - PSW #629 from 2019-12-07T10:00

Eric Brown is the Sr. Security Analyst at LogRhythm. Eric will cover topics including: Phishing Trends, 2020 Outlook, Top 4 Types Eric is seeing: Exec Phish / Legit websites (Box/sites.google/On...

Listen
Paul's Security Weekly (Video-Only)
The Marvel Universe - PSW #628 from 2019-11-28T10:00

In the Security News, Disney Plus Blames Past Hacks for User Accounts Sold Online, Why Multifactor Authentication Is Now a Hacker Target, How the Linux kernel balances the risks of public bug di...

Listen
Paul's Security Weekly (Video-Only)
Coalfire Incident & DerbyCon Communities - PSW #628 from 2019-11-27T10:00

Dave Kennedy is the Founder & CEO of TrustedSec. Dave comes on the show to talk about the Coalfire incident and DerbyCon communities.

Visit h...

Listen
Paul's Security Weekly (Video-Only)
The Next Generation of SOCs - Peter Liebert - PSW #628 from 2019-11-26T10:00

Peter Liebert is the CEO at Liebert Security. After working in and with SOCs for the majority of my career, as well as building one from the ground up for the State of California, there are some...

Listen
Paul's Security Weekly (Video-Only)
Humans vs. Machines - PSW #627 from 2019-11-18T10:00

Two security researchers earned $60,000 for hacking an Amazon Echo, Amazon Kindle, Embedded devices Open to Code-Execution, This App Will Tell You if Your iPhone Gets Hacked, Two New Carding Bot...

Listen
Paul's Security Weekly (Video-Only)
Simulating Ransomware Attacks with SCYTHE - PSW #627 from 2019-11-17T10:00

Bryson Bort (Founder and CEO of SCYTHE) will demonstrate how to safely simulate ransomware and a multi-staged APT with lateral movement in your production environment! How would your organizatio...

Listen
Paul's Security Weekly (Video-Only)
The Ethics of Surveillance - Dr. Kevin Harris - PSW #627 from 2019-11-16T10:00

As advancements have been made in technologies new surveillance tools have been designed giving those charged with protecting citizen’s additional opportunities to prevent crimes or identify tho...

Listen
Paul's Security Weekly (Video-Only)
Security News: November 7, 2019 - PSW #626 from 2019-11-11T10:00

In the Security News, Who is responsible for Active Directory security within your organization?, Apple publishes new technical details on privacy features, How to ensure online safety with DNS ...

Listen
Paul's Security Weekly (Video-Only)
Arcade Hustle - PSW #626 from 2019-11-10T10:00

Kevin Finisterre is a Co-founder of Arcade Hustle. Josh Valentine is a Co-founder of Arcade Hustle. Josh and Kevin have spent the last year immersing ourselves in arcade platforms, games, and ca...

Listen
Paul's Security Weekly (Video-Only)
Peter Smith, Edgewise - Peter Smith - PSW #626 from 2019-11-09T10:00

Peter Smith is the Founder & CEO of Edgewise.

Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: Listen

Paul's Security Weekly (Video-Only)
Security Weekly RoundTable, Cyberwire - PSW #625 from 2019-11-03T09:00

Paul and Matt sit down with Dave Bittner from Cyberwire to discuss the state of security podcasts, the latest security trends, and the security community.

Visit Listen

Paul's Security Weekly (Video-Only)
Format String Vulnerabilities - PSW #625 from 2019-11-02T09:00

Sven Morgenroth is the Security Researcher at Netsparker. Sven joins us again to talk about Formatting string vulnerabilities.

To learn more about Netsparker, visit: Listen

Paul's Security Weekly (Video-Only)
A New Prescription for Security - Philippe Courtot, Sumedh Thakar - PSW #625 from 2019-11-01T09:00

Philippe Courtot is the Chairman and CEO of Qualys. Sumedh Thakar is the Chief Product Officer Qualys. Philippe Courtot, chairman and CEO of Qualys will examine the impact of today's complex and...

Listen
Paul's Security Weekly (Video-Only)
Endgame To Elastic Endpoint Security - Mark Dufresne - PSW #624 from 2019-10-27T09:00

Last week, Elastic and Endgame announced that they have formally joined forces to introduce Elastic Endpoint Security. Together, they combine Elastic’s free and open SIEM with Endgame's endpoint...

Listen
Paul's Security Weekly (Video-Only)
Security News: October 24, 2019 - PSW #624 from 2019-10-26T09:00

In the news, we talk Security News, discussing how Amazon Echo and Kindle devices were affected by a WiFi bug, Ransomware and data breaches linked to uptick in fatal heart attacks, a woman was o...

Listen
Paul's Security Weekly (Video-Only)
Mental Health Hackers & Veterans - Tom Williams - PSW #624 from 2019-10-25T09:00

Tom Williams is the Director of Veterans Operations of Veterans MHH. Speaking about the challenges that veterans face and how MHH is looking to address those.

Visit Listen

Paul's Security Weekly (Video-Only)
Cybercrime, Threat Hunting, & APT - PSW #623 from 2019-10-21T09:00

Peter Kruse is the Founder of CSIS Security Group. "Nothing specific but a Google search will provide numerous research I have been involved with and conferences I have spoken at including Kaspe...

Listen
Paul's Security Weekly (Video-Only)
Security News: October 17, 2019 - PSW #623 from 2019-10-20T09:00

Cybercrime Tool Prices Bump Up in Dark Web Markets, Pen testers find mystery black box connected to ships engines, Using Machine Learning to Detect IP Hijacking - Schneier on Security, and much ...

Listen
Paul's Security Weekly (Video-Only)
What Makes A Good Pentest Report? - Daniel DeCloss - PSW #623 from 2019-10-19T09:00

DeCloss is the President and CEO of PlexTrac. The segment will focus on the importance of a high-quality report and what red and blue teamers should recognize goes into a good report. Often time...

Listen
Paul's Security Weekly (Video-Only)
Security News: October 3, 2019 - PSW #622 from 2019-10-07T09:00

This week, we talk Security News, how Turkey fines Facebook $282,000 over privacy breach, why the FBI is encouraging not to pay ransomware demands, the top 10 cybersecurity myths that criminals ...

Listen
Paul's Security Weekly (Video-Only)
Security & Compliance Introduction - PSW #622 from 2019-10-06T09:00

It’s the show, that bridges the requirements of regulations, compliance, and privacy with those of security. Your trusted source for complying with various mandates, building effective programs,...

Listen
Paul's Security Weekly (Video-Only)
Data Privacy and The Journey to Code - Stewart Room - PSW #622 from 2019-10-05T09:00

Stewart Room is a Partner of PwC. Security Professionals have long understood the need to deliver security outcomes in technology and data, but is the privacy community on the same page? Data Pr...

Listen
Paul's Security Weekly (Video-Only)
Security News: September 26, 2019 - PSW #621 from 2019-09-30T09:00

How a hacker took over a smart home with vulgar music and rising temperatures, a security warning for 23 million YouTube creators following a crazy hack attack, Vimeo sued for storing faceprints...

Listen
Paul's Security Weekly (Video-Only)
Perry Carpenter and Chris Edwards - PSW #621 from 2019-09-29T09:00

We interview Perry Carpenter and Chris Pritchard at DEF CON SE Village. Perry Carpenter talks about how (as someone on the autism spectrum) has used various social-engineering related skills to ...

Listen
Paul's Security Weekly (Video-Only)
Billy Boatright, Edward Miro, & Jayson Street - PSW #621 from 2019-09-28T09:00

We interview Billy Boatright, Edward Miro, and Jayson Street at DEF CON SE Village. Billy talks about Impostor Syndrome. Edward Miro talks about Rideshare OSINT – Car Based SE For Fun & Profit. ...

Listen
Paul's Security Weekly (Video-Only)
iOS, Equifax Is Back, & phpMyAdmin CSRF Zero-Day - PSW #620 from 2019-09-23T09:00

In the Security News, how an iOS 13 flaw could provide access to contacts with passcode, Equifax demands more information before making payouts, confidential data of 24.3 million patients were d...

Listen
Paul's Security Weekly (Video-Only)
Audio Security - PSW #620 from 2019-09-22T09:00

Wes Widner is the Cloud Engineering Manager at CrowdStrike. Wes will be talking about personal voice assistants are the wave of the future. So naturally we should wonder about the unique attack ...

Listen
Paul's Security Weekly (Video-Only)
Anything Red/Purple Teaming - Jason Lang - PSW #620 from 2019-09-20T09:00

Jason Lang is the Sr. Security Consultant of TrustedSec. Modern day red teaming against some of the largest company's in the US. Current passion is Ansible for red teamers (i.e. fast infrastruct...

Listen
Paul's Security Weekly (Video-Only)
SE Village Interviews: Chris Kirsch & Micah Zenko - PSW #619 from 2019-09-16T09:30

At DEF CON 2019, we interview Chris Kirsch on Getting Psychic: Cold Reading Techniques for Fortune Tellers and Social Engineers Cold reading is a technique to make others believe that you have p...

Listen
Paul's Security Weekly (Video-Only)
Capital One Breach, Edgewise - Peter Smith - PSW #619 from 2019-09-15T09:00

Peter Smith is the Founder & CEO of Edgewise. Peter will be covering the Capital One breach and the AWS metadata service with request forgery. He will explain how to solve this problem with Edge...

Listen
Paul's Security Weekly (Video-Only)
Security News: September 12, 2019 - PSW #619 from 2019-09-14T09:00

This week, we present the Security News, to discuss New ransomware grows 118% as cybercriminals adopt fresh tactics and code innovations, Period Tracker Apps share data with Facebook, U.S. Cyber...

Listen
Paul's Security Weekly (Video-Only)
SE Village 2020 and Innocent Lives Foundation - Christopher Hadnagy - PSW #618 from 2019-09-01T09:00

Christopher Hadnagy is the Chief Human Hacker of Social-Engineer, LLC. Chris will be giving an overview of inaugural SEVillage Orlando 2020. Brief description of the training workshops provided....

Listen
Paul's Security Weekly (Video-Only)
Analyzing Custom Log Sources - Corey Thuen - PSW #618 from 2019-08-31T09:00

Corey Thuen is the Co-Founder at Gravwell. Security analytics using the new Sysmon DNS logging and Sysmon DNS logging dropped this week.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Security News: August 28, 2019 - PSW #618 from 2019-08-30T09:00

In the news, we discuss how AT&T employees took bribes to plant malware on the company’s network, how hackers could decrypt your GSM calls, 80 suspects charged with massive BEC scam, and how the...

Listen
Paul's Security Weekly (Video-Only)
Critical Patches, Automox - Richard Melick - PSW #617 from 2019-08-25T09:00

Waiting to deploy critical patches makes you a bigger target - Cybercriminals Have Seven-Day Advantage to Weaponize Vulnerabilities, According to New Research from Tenable- Cyber Criminals have ...

Listen
Paul's Security Weekly (Video-Only)
Deobfuscating JavaScript to Investigate Phishing Domains - PSW #617 from 2019-08-24T09:00

Paul gives a technical segment on deobfuscating JavaScript to investigate phishing domains.

To learn more about DomainTools, visit: https...

Listen
Paul's Security Weekly (Video-Only)
DEF CON 27 Interviews - PSW #616 from 2019-08-19T09:00

In this segment, we interview O'Shea Bowens from Null Hat Security and Tyler Robinson from Nisos, Inc., from the Blue Team Village. Then we interview Aaran Leyland in the Social Engineering Vill...

Listen
Paul's Security Weekly (Video-Only)
Security News: August 15, 2019 - PSW #616 from 2019-08-18T09:00

The Huawei shenanigans get deeper and more broad. - This is why I have issues with supply chain, CapitalOne hacker may have stolen from 30 more companies, New Data Breach Has Exposed Millions Of...

Listen
Paul's Security Weekly (Video-Only)
Blue Team To Red Team, Offensive Security - Tony Punturiero - PSW #616 from 2019-08-17T09:00

Tony Punturiero is the Community Manager at Offensive Security. Discussing about my adventure transferring from being on the blue side to becoming a pentester/red teamer full time. Created an in...

Listen
Paul's Security Weekly (Video-Only)
Joshua Douglas, Mimecast - PSW #615 from 2019-08-15T09:00

During this discussion, Joshua and Paul will speak about the threats facing organizations today and how they are evolving. Josh will also discuss how IT and security teams need to understand the...

Listen
Paul's Security Weekly (Video-Only)
Security Do's and Don'ts - PSW #615 from 2019-08-14T09:00

Paul, Larry, Doug, and Gabe talk about Software Development: Security Do's & Don'ts.

?Visit our website: https://www.securityweekly.com
...

Listen
Paul's Security Weekly (Video-Only)
Gabriel Gumbs, Spirion - PSW #615 from 2019-08-13T18:44:09

Gabriel Gumbs is the VP of Product Management at Spirion where his focus is on the strategy and technology propelling Spirion’s rapidly-growing security platform.

?Visit our website: Listen

Paul's Security Weekly (Video-Only)
Security News - PSW - News #614 from 2019-08-05T09:00

In the Security News, the US government issues a light aircraft cyber alert, thieves steal a laptop with 30 years of Data from University of Western Australia, RCE is possible by exploiting flaw...

Listen
Paul's Security Weekly (Video-Only)
Signal Sciences Kubernetes, Doug Coburn - PSW #614 from 2019-08-04T09:00

Talk about the way Signal Sciences is implemented, especially in the container world. Where we sit in the stack for protection of the web apps in those containers and common first things identif...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #613 from 2019-07-26T17:36:11

In the Security News, a phishing scheme that targets AMEX cardholders, the list of labs affected by the American Medical Collection Agency data breach continues to grow, a Silk Road drug dealer get...

Listen
Paul's Security Weekly (Video-Only)
Integrity Through Prevention, WEforum - Paul's Security Weekly #613 from 2019-07-26T01:32:49

Troels Oerting is the Head of the Global Centre for Cybersecurity established by World Economic Forum in 2018. Troels talks about Security, Privacy, Integrity through Prevention, Protection and Pro...

Listen
Paul's Security Weekly (Video-Only)
DDoS, Murray Goldschmidt - Paul's Security Weekly #613 from 2019-07-26T01:12

Murray Goldschmidt is the COO & Co-founder of Sense of Security. Murray talks about the Intro to Sense of Security, DDoS in 2019, New trends, and How to address these issues! Full Show Notes: https...

Listen
Paul's Security Weekly (Video-Only)
Security News: July 18, 2019 - Paul's Security Weekly #612 from 2019-07-22T09:00

Slack Resets User Passwords After 2015 Data Breach, Hacker Breached Sprint Customer Accounts Through Samsung Website, Why 72% of people still recycle passwords Why 100% of Security Weekly hosts ...

Listen
Paul's Security Weekly (Video-Only)
Topic Segment: Security Roundtable - Paul's Security Weekly #612 from 2019-07-21T09:00

Topics being discussed: Vulnerability Management, Patching, Asset Management, and System Hardening.

Full Show Notes: https://wiki.sec...

Listen
Paul's Security Weekly (Video-Only)
Porn Pirating, Zoom RCE, & Huawei - Paul's Security Weekly #611 from 2019-07-15T09:00

In the Security News, Zoom's RCE Vulnerability is affecting over 700,000 companies, how YouTube is trying to ban hacking videos, 1TB of police body cam footage is available online, and how the U...

Listen
Paul's Security Weekly (Video-Only)
Blue/Purple Teaming (defense) - Paul's Security Weekly #611 from 2019-07-13T09:00

Ben has been working in technology and development for over 20 years. He spent 13 years doing defense in the medical industry before moving over to the offense. He uses his knowledge of defense ...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #610 from 2019-07-01T09:00

Nearly 100 drivers following Google Maps detour get stuck in muddy field, Breach at Cloud Solution Provider PCM Inc., Inside the West s failed fight against China s Cloud Hopper hackers, Mozilla...

Listen
Paul's Security Weekly (Video-Only)
Tools to Hack Your Career, CyberSecJobs - Paul's Security Weekly #610 from 2019-06-30T09:00

Kathleen Smith is the CMO at CyberSecJobs.Com/ClearedJobs.Net. We all have cool tools, but not necessarily the best ones for career search or professional development. Why is it so hard? Many of...

Listen
Paul's Security Weekly (Video-Only)
CySA+ & PenTest+ Certs, ITProTV - Paul's Security Weekly #610 from 2019-06-29T09:00

Don Pezet will be discussing the new CySA+ and PenTest+ certs that ITProTV has to offer! Don has been working in the IT industry for more than 18 years and in training for more than 12 years. He...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #609 from 2019-06-24T09:00

In the Security News, how not to prevent a cyberwar with Russia, the case against knee-jerk installation of Windows patches, U.S. customs and Border Protection data breach is the result of a sup...

Listen
Paul's Security Weekly (Video-Only)
Purple Teaming, SCYTHE - Paul's Security Weekly #609 from 2019-06-23T09:00

We welcome back Bryson Bort, who is the Founder/CEO of GRIMM. Bryson will be talking about Purple Teaming, Top Attack Simulation Scenarios, and Testing Command & Control Channels.

To lear...

Listen
Paul's Security Weekly (Video-Only)
Grim, Vim, & Neovim - Paul's Security Weekly #608 from 2019-06-18T09:00

In the Security News, the rise of purple teaming, the World's largest beer brewer sets up a Cyber-security team, a mystery signal shutting down key fobs in an Ohio neighborhood, why hackers igno...

Listen
Paul's Security Weekly (Video-Only)
Sysmon DNS Logging, Gravwell - Paul's Security Weekly #608 from 2019-06-17T13:12:59

We welcome back Corey Thuen, Founder and CEO of Gravwell, to talk about security analytics using the new Sysmon DNS logging that dropped this week!

To get involved with Gravwell, visit: <...

Listen
Paul's Security Weekly (Video-Only)
1 Click Microsegmentation, Edgewise - Paul's Security Weekly #608 from 2019-06-15T09:00

Peter Smith, Edgewise Founder and CEO, is a serial entrepreneur who built and deployed Harvard University’s first NAC system before it became a security category. Peter comes on the show to talk...

Listen
Paul's Security Weekly (Video-Only)
SalesForce, iPhones, & Old Androids - Paul's Security Weekly #607 from 2019-06-10T09:00

In the Security News, SalesForce bans customers from gun sales, what is your iPhone talking to overnight, Office retires support for old Android versions, and really how likely are weaponized ca...

Listen
Paul's Security Weekly (Video-Only)
Mental Health & Wellness - Paul's Security Weekly #607 from 2019-06-09T09:00

We welcome back Amanda Berlin, CEO of Mental Health Hackers to talk about why its important to educate technology professionals about unique mental health risks faced by people in the field, and...

Listen
Paul's Security Weekly (Video-Only)
Detection & Response, Endgame - Paul's Security Weekly #607 from 2019-06-08T09:00

In this episode of Paul's Security Weekly, we will talk with Paul Ewing of Endgame about how to close the 'breakout window' between detection and response, and hear about Endgame's recently anno...

Listen
Paul's Security Weekly (Video-Only)
Gatekeeper, WannaCry, and BlueKeep- Paul's Security Weekly #606 from 2019-06-03T09:00

In the security news, giving you the latest on thousands of infected servers from a cryptojacking campaign, an open letter to the GCHQ calling out spy agencies, and a new vulnerability that make...

Listen
Paul's Security Weekly (Video-Only)
Automate IT, SaltStack - Paul's Security Weekly #606 from 2019-06-02T09:00

David Boucha is a Sr. Engineer at SaltStack. David will be talking about how Salt Open and SaltStack Enterprise can help you automate your infrastructure including servers (cloud, on-prem, virtu...

Listen
Paul's Security Weekly (Video-Only)
BlueKeep Vulnerability, Robert Graham - Paul's Security Weekly #606 from 2019-06-01T09:00

Paul Asadoorian and Robert Graham from Errata Security show you how to search for the BlueKeep vulnerability, or CVE-2019-0708, that has been affecting hundreds of thousands of systems!

F...

Listen
Paul's Security Weekly (Video-Only)
Digital Hygiene & The School System - Paul's Security Weekly #606 from 2019-05-31T13:57:09

Eric Butash and Mike Klein from Highlander Institute, join us on the show to talk about, what schools are doing to protect Student Data?, how do we teach our student the importance of good digit...

Listen
Paul's Security Weekly (Video-Only)
Google, Huawei, & Windows 0-Day - Paul's Security Weekly #605 from 2019-05-27T09:00

In our final segment, Doug, Jeff, Patrick, and Lee give you the latest security news to talk about a Zero Day for Windows, the battle over Huawei with the US and Google, & unpatched hardware and...

Listen
Paul's Security Weekly (Video-Only)
Does DNS Fit Into A Secure Architecture - Paul's Security Weekly #605 from 2019-05-26T09:00

In our second segment, we welcome Justin Murphy, Cloud Security Engineer at Cisco, to talk about DNS in the Security Architecture!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Matthew McMahon, Salve Regina University - Paul's Security Weekly #605 from 2019-05-25T09:00

We welcome Matthew McMahon, Head of Security Analytics at Salve Regina University, to talk about Medical devices, Cybersecurity and Resilience, and Cybersecurity Training!

Full Show Notes...

Listen
Paul's Security Weekly (Video-Only)
Singapore, Cisco, and Israeli Spyware - Paul's Security Weekly #604 from 2019-05-20T09:00

In the Security News, Singapore passes an anti-fake news law, WhatsApp Vulnerability Exploited to Infect Phones with Israeli Spyware, major security issues found in Cisco routers, and Microsoft ...

Listen
Paul's Security Weekly (Video-Only)
Fixing Identity and Access Management - Paul's Security Weekly #604 from 2019-05-19T09:00

Federico Simonetti is the CTO of Xiid Corporation. Federico comes on the show to discuss How To Fix Identity & Access Management.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Julian Zottl, Raytheon - Paul's Security Weekly #604 from 2019-05-18T09:00

Julian Zottl is the Cyber and Information Operations SME at Raytheon. Julian joins us on the show to talk about side-channel attacks!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #603 from 2019-05-13T09:00

The top 5 mistakes that create field days for hackers, WordPress 5.2 brings new security features, a discontinued Insulin pump with security a security flaw in high demand, and how to communicat...

Listen
Paul's Security Weekly (Video-Only)
Chris Sanders, AND & RTF - Paul's Security Weekly #603 from 2019-05-12T09:00

Chris Sanders is the Founder of Applied Network Defense & Rural Technology Fund. He is also the Director of the Rural Technology Fund, a non-profit that donates scholarships and equipment to pub...

Listen
Paul's Security Weekly (Video-Only)
From IT to OT Security, Lesley Carhart - Paul's Security Weekly #603 from 2019-05-11T09:00

Lesley Carhart is the Principal Threat Analyst at Dragos Inc.. Lesley has been performing digital forensics and incident response on unconventional systems and advanced adversary attacks for ove...

Listen
Paul's Security Weekly (Video-Only)
Nokia 9, Julian Assange, & Tenable - Paul's Security Weekly #602 from 2019-05-06T15:30:45

In the Security News, how Tenable experts found 15 flaws in wireless penetration systems, Julian Assange refused exfiltration to the US, PoC exploits for old SAP config flaws increase risk of at...

Listen
Paul's Security Weekly (Video-Only)
Joshua Abraham, Praetorian - Paul's Security Weekly #602 from 2019-05-05T09:00

Josh Abraham is in studio! He is a Staff Engineer at Praetorian, and he is going to talk about the MITRE attack framework for attackers!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Philip Niedermair, National Cyber Group - Paul's Security Weekly #602 from 2019-05-04T09:00

We welcome Philip Niedermair from National Cyber Group. Philip is the CEO at National Cyber Group and he joins us to discuss the National Cyber Education Program!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Fujifilm, Facebook, & Black Holes - Paul's Security Weekly #601 from 2019-04-30T09:00

Serious vulnerabilities found in Fujifilm x-ray devices, Facebook could be fined 5 billion over privacy violations, preinstalled malware on bootleg streaming devices, hackers using SIM swapping ...

Listen
Paul's Security Weekly (Video-Only)
The Canary Tool, Thinkst - Paul's Security Weekly #601 from 2019-04-28T16:00

Haroon Meer is the CEO and Researcher at Thinkst. He is coming on the show to talk about why hackers should create companies, and some of the technical details behind Thinkst' tool Canary!

<...

Listen
Paul's Security Weekly (Video-Only)
SaaS Product, Cloudneeti - Paul's Security Weekly #601 from 2019-04-28T09:00

Guru Pandurangi is the CEO and Founder of Cloudneeti, to talk about how their SaaS product is delivering continuous cloud security and compliance assurance to businesses migrating or using cloud...

Listen
Paul's Security Weekly (Video-Only)
Merissa & Jessica, WSC - Paul's Security Weekly #600 from 2019-04-15T09:00

Merissa Villalobos is the North America Talent Acquisition Leader for NCC Group, a global security consulting firm and has been recruiting in security for 10 years. She got her start in Virginia...

Listen
Paul's Security Weekly (Video-Only)
Bitcoin, WikiLeaks, & Julian Assange - Paul's Security Weekly #600 from 2019-04-15T09:00

In the news, Bitcoin mining ban considered by China's economic planner, Yahoo strikes $117.5 million data breach settlement, Serious flaws leave WPA3 vulnerable to hacks that steal Wi-Fi passwor...

Listen
Paul's Security Weekly (Video-Only)
Gabriel Gumbs, Spirion - Paul's Security Weekly #600 from 2019-04-13T09:00

Gabriel Gumbs is the VP of Product Management at Spirion where his focus is on the strategy and technology propelling Spirion’s rapidly-growing security platform. A cybersecurity industry vetera...

Listen
Paul's Security Weekly (Video-Only)
OceanLotus, Russia, & Google - Paul's Security Weekly #599 from 2019-04-01T09:00

In the Security News, Attackers exploiting IMAP to bypass MFA on O365 and G-Suite accounts, Vietnam's OceanLotus Group Ramps up hacking car companies, UC Browser violates Google Play Store Rules...

Listen
Paul's Security Weekly (Video-Only)
Threat Hunting & AI Hunter, ACM - Paul's Security Weekly #599 from 2019-03-31T09:00

In the Technical Segment, we welcome back our friend Chris Brenton, Chief Operating Officer at Active Countermeasures, to discuss why threat hunting is the missing link between our protection to...

Listen
Paul's Security Weekly (Video-Only)
Mary Beth Borgwing, Cyber Social Club - Paul's Security Weekly #599 from 2019-03-30T09:00

This week, we welcome back Mary Beth Borgwing, President and Founder of of the Cyber Social Club, to talk about Uniting Women in Cyber!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Android Q, Sirens, & Korean Hotels - Paul's Security Weekly #598 from 2019-03-25T09:00

In the Security News, how Android Q will come with improved privacy protections, hacked tornado sirens taken offline ahead of a major storm, and how Putty released an update that fixed 8 new sec...

Listen
Paul's Security Weekly (Video-Only)
Iris, DomainTools - Paul's Security Weekly #598 from 2019-03-24T09:00

In this segment, we run a Technical Demo with our sponsor DomainTools, all about Domain Investigation with DomainTools Iris!

To learn more about DomainTools, visit: Listen

Paul's Security Weekly (Video-Only)
Marcus Carey, Tribe of Hackers - Paul's Security Weekly #598 from 2019-03-23T09:00

Marcus Carey is the Founder & CEO at Threatcare. Navy Cryptologist turned cybersecurity entrepreneur, Marcus Carey is Currently working as founder and CEO of cybersecurity company Threatcare. He...

Listen
Paul's Security Weekly (Video-Only)
Malware Sandboxing, VMRay - Paul's Security Weekly #597 from 2019-03-18T09:00

We interview Carsten Williams, Co-Founder and CEO at VMRay, discussing malware sandboxing! Carsten is the original developer of CWSandbox, a commercial malware analysis suite that was later rena...

Listen
Paul's Security Weekly (Video-Only)
Tesla, YouTube, & Sexy Selfies - Paul's Security Weekly #597 from 2019-03-17T09:00

New WordPress flaw lets unauthenticated remote attackers hack sites, Tesla allegedly spied on and ran a smear campaign on a whistleblower, Facebook and Instagram suffer most severe outage ever, ...

Listen
Paul's Security Weekly (Video-Only)
Evolution of Zero Trust, Edgewise - Paul's Security Weekly #597 from 2019-03-16T08:30

We welcome Peter Smith, Founder and CEO of Edgewise to talk about the evolution of Zero Trust! Smith, Edgewise Founder and CEO, is a serial entrepreneur who built and deployed Harvard University...

Listen
Paul's Security Weekly (Video-Only)
YouTube Censorship & Vulnerabilities- Paul's Security Weekly #596 from 2019-03-04T10:00

YouTube controversy on ALL fronts, Cisco SOHO wireless VPN firewalls and routers open to attack, Ring doorbell flaw opens door to spying, bot plagues, free hacking toolkits, and everything you n...

Listen
Paul's Security Weekly (Video-Only)
David Marble, OSHEAN - Paul's Security Weekly #596 from 2019-03-03T10:00

David Marble is the President & CEO at OSHEAN. David joins us to talk about what to expect at at this years Rhode Island Cybersecurity Exchange Day! This conference will be held on March 13th 20...

Listen
Paul's Security Weekly (Video-Only)
Threat Intelligence, Recorded Future - Paul's Security Weekly #596 from 2019-03-02T10:00

Allan Liska is the Senior Solutions Architect at Recorded Future. Allan talks about threat intelligence – no longer just for the secret squirrels among us. While the term can elicit reactions ra...

Listen
Paul's Security Weekly (Video-Only)
Passwords, Splunk, & Nest Microphones - Paul's Security Weekly #595 from 2019-02-25T10:00

In the Security News, password managers leaking data in memory, security analysts are only human, Splunk changes position of Russian customers, Google admits error over hidden microphone, and a ...

Listen
Paul's Security Weekly (Video-Only)
Steve Brown, SecureWorld Keynote - Paul's Security Weekly #595 from 2019-02-24T10:00

Steve Brown, Keynote Speaker at SecureWorld Boston 2019 to discuss his talk about Building Your Strategic Roadmap for the Next Wave of Digital Transformation!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
SILENTRINITY Updates, BHIS - Paul's Security Weekly #595 from 2019-02-23T10:00

Marcello Salvati, Security Analyst at our sponsor Black Hills Information Security, to give some updates on his Post Exploitation Tool SILENTRINITY! Sign up for the BHIS Mailing List to receive ...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #594 from 2019-02-18T10:00

Why it's way too easy to sell counterfeit goods on amazon, how to defend against the runC container vulnerability, creating a dream team for the new age of cyber security, how you can get a wind...

Listen
Paul's Security Weekly (Video-Only)
Enterprise-ish Network Security: Pt. 1 - Paul's Security Weekly #594 from 2019-02-17T10:00

There are quite a few choices for selecting open-source and inexpensive hardware to build your network and provide tools to monitor for security events. In this segment we'll discuss some of the...

Listen
Paul's Security Weekly (Video-Only)
Harry Sverdlove, Edgewise - Paul's Security Weekly #594 from 2019-02-16T10:00

Harry Sverdlove, Chief Technology Officer of Edgewise for an interview, to talk about The Future of Firewalls!

To learn more about Edgewise, visit: Listen

Paul's Security Weekly (Video-Only)
Connie Mastovich, InfoSec World 2019 - Paul's Security Weekly #593 from 2019-02-11T10:00

Connie Mastovich is the Sr. Security Compliance Analyst at Reclamere and she will be speaking at InfoSec World 2019. Connie's talk will be about "The Dark Web 2.0: How It Is Evolving, and How Ca...

Listen
Paul's Security Weekly (Video-Only)
DetectionLab, Chris Long - Paul's Security Weekly #593 from 2019-02-10T10:00

DetectionLab is a collection of Vagrant and Packer scripts that allows you to automate the creation of a small active directory network that is pre-loaded with endpoint security tooling and logg...

Listen
Paul's Security Weekly (Video-Only)
5G, Zero-Days, & National Museum - Paul's Security Weekly #593 from 2019-02-10T10:00

5G networks must be secured from hackers and bad actors, zero-day vulnerability highlights the responsible disclosure dilemma, a flaw in multiple airline systems exposes passenger data, security...

Listen
Paul's Security Weekly (Video-Only)
Japan, Imperva, & DDoS - Paul's Security Weekly #592 from 2019-02-04T10:00

In the Security News, 5 tips for access control from an ethical hacker, Japan is to hunt down Citizens insecure IoT devices, kid tracking watches allow attackers to monitor real time location da...

Listen
Paul's Security Weekly (Video-Only)
The Future Of Security - Paul's Security Weekly #592 from 2019-02-03T10:00

In our second segment, the Security Weekly hosts will discuss the Future of Security, such as major changes, evolving threats, and security culture!

Full Show notes: Listen

Paul's Security Weekly (Video-Only)
Web App Scanning w/ Authentication, Acunetix - Paul's Security Weekly #592 from 2019-02-02T10:00

Benjamin Daniel Mussleris the Senior Security Researcher at Acunetix. Benjamin will come on the show to talk about Web App Scanning with authentication.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
DerbyCon, Flaws, & Azure DevOps - Paul's Security Weekly #590 from 2019-01-21T10:00

Two code execution flaws patched in Drupal, 773 million records exposed in massive data breach, prices for zero-day exploits are rising, new attacks target recent PHP framework vulnerability, an...

Listen
Paul's Security Weekly (Video-Only)
PowerShell for Fun and Profit - Paul's Security Weekly #590 from 2019-01-20T10:00

Joff will demonstrate some syntax with PowerShell useful for transferring data into a network while pen testing. The technical segment assumes that the pen testing is able to directly use PowerS...

Listen
Paul's Security Weekly (Video-Only)
Dr. Eric Cole, Secure Anchor Consulting - Paul's Security Weekly #590 from 2019-01-19T10:00

Dr. Eric Cole is the leading cybersecurity expert in the world, known as the go-to for major political and business power players.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Hyatt, El Chapo's IT, and Amazon Key - Paul's Security Weekly #589 from 2019-01-14T10:00

Why Hyatt Is Launching a Public Bug Bounty Program, Amazon Key partners with myQ, Web vulnerabilities up, IoT flaws down, enterprise iPhones will soon be able to use security dongles, and how El...

Listen
Paul's Security Weekly (Video-Only)
pktrecon, Kory Findley - Paul's Security Weekly #589 from 2019-01-13T10:00

Kory Findley talks about his Github project pktrecon. Internal network segment reconnaissance using packets captured from broadcast and service discovery protocol traffic. pktrecon is a tool for...

Listen
Paul's Security Weekly (Video-Only)
Bryson Bort, SCYTHE - Paul's Security Weekly #589 from 2019-01-12T10:00

Bryson is the Founder and CEO of SCYTHE and Founder of GRIMM. He comes on the show to talk about Attack Simulation.

To learn more about SCYTHE.io, go to: Listen

Paul's Security Weekly (Video-Only)
Android, Nest, & Linux Malware - Paul's Security Weekly #591 from 2019-01-08T10:00

Cellular carriers are implementing services to identify cell scam leveraging, New Android Malware uses motion sensor to avoid detection, Linux Malware disables security software to mine cryptocu...

Listen
Paul's Security Weekly (Video-Only)
PewDiePie, DOOM Roomba, and 9/11 - Paul's Security Weekly #588 from 2019-01-07T10:00

Hijacking smart TV's to promote PewDiePie, hackers attempt to sell stolen 9/11 documents, turning your house into a DOOM level with a Roomba, and hopefully you're over that New Year's hangover, ...

Listen
Paul's Security Weekly (Video-Only)
Breaches, Privacy, Compliance and More! - Paul's Security Weekly #588 from 2019-01-06T10:00

The Security Weekly crew has a lively topic discussion on the following: Security Breaches, Privacy, Vulnerability Disclosure, Evaluating Security Solutions, and Compliance.

Full Show Not...

Listen
Paul's Security Weekly (Video-Only)
Topics & Questions - Paul's Security Weekly #591 from 2019-01-06T10:00

In our second segment, the Security Weekly hosts talks about some of our favorite hacker movies, influencers in the community, and what software and devices make appearances in our labs!

...

Listen
Paul's Security Weekly (Video-Only)
Helping People In The Security Community - Paul's Security Weekly #588 from 2019-01-05T10:00

"Phoneboy" has been helping the security community for over 15 years. We fondly remember Phoneboy as a resource that helped us configure our Check Point firewalls back in the day! Phoneboy comes...

Listen
Paul's Security Weekly (Video-Only)
Chris Morales, Vectra - Paul's Security Weekly #591 from 2019-01-05T10:00

Christopher Morales is Head of Security Analytics at Vectra, where he advises and designs incident response and threat management programs for Fortune 500 enterprise clients. Christopher is a wi...

Listen
Paul's Security Weekly (Video-Only)
Hacking the Brainstem, Mandy Logan - Paul's Security Weekly #587 from 2018-12-24T10:00

Following a series of 5 strokes and major head injuries, Mandy is no longer in the construction engineering industry. Instead, she is pursuing all things InfoSec with an emphasis on Incident Res...

Listen
Paul's Security Weekly (Video-Only)
What The Heck Are "Security Basics"? - Paul's Security Weekly #587 from 2018-12-23T10:00

The question comes up quite often, what should organizations be doing to meet the basic security requirements? We often hear the terms "Security Basics", "Minimum Security Standards" or dear lor...

Listen
Paul's Security Weekly (Video-Only)
Detecting Attacker Behavior, LogRhythm - Paul's Security Weekly #587 from 2018-12-22T10:00

Vaughn will discuss using freely available tools and logs you are already collecting to detect attacker behavior. Vaughn has a cookbook that will allow you to configure and analyze logs to detec...

Listen
Paul's Security Weekly (Video-Only)
Taylor Swift, KringleCon, & 3D Head - Paul's Security Weekly #586 from 2018-12-17T10:00

How Taylor Swift used Facial Recognition to Thwart Stalkers, unlocking android phones with a 3D printed head, Ticketmaster fails to take responsibility for malware, and it's December of 2018, To...

Listen
Paul's Security Weekly (Video-Only)
Don Murdoch, Regent University Cyber Range - Paul's Security Weekly #586 from 2018-12-15T10:00

Don Murdoch is the Assistant Director at Regent University Cyber Range. Don discusses his book "Blue Team Handbook Incident Response Edition".

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Ed Skoudis, Counter Hack Challenge - Paul's Security Weekly #586 from 2018-12-14T20:47:46

Ed Skoudis, Founder of the Counter Hack Challenge and Kringle Con 2018, joins us on the show to talk about this years challenge and what's in store! "Welcome to Counter Hack Challenges, an organ...

Listen
Paul's Security Weekly (Video-Only)
Marriott Breach, Lame Printer Hack, and Docker - Paul's Security Weekly #585 from 2018-12-10T10:00

This week, how Docker containers can be exploited to mine for cryptocurrency, WordPress sites attacking other WordPress sites, why the Marriott Breach is a valuable IT lesson, malicious Chrome e...

Listen
Paul's Security Weekly (Video-Only)
Marcello Salvati, BHIS - Paul's Security Weekly #585 from 2018-12-09T09:30

Marcello Salvati is a security consultant at BHIS, and is giving a technical segment on SilentTrinity. Marcello will solve the red team tradecraft problem of gaining dynamic access to the .net a...

Listen
Paul's Security Weekly (Video-Only)
Lenny Zeltser, Minerva Labs - Paul's Security Weekly #585 from 2018-12-08T10:00

Lenny Zeltser the VP of Products at Minerva, will be giving a technical segment on Evasion Tactics in Malware from the Inside Out. He will explain the tactics malware authors use to evade detect...

Listen
Paul's Security Weekly (Video-Only)
Wietse Venema & Dan Farmer, SATAN - Paul's Security Weekly #584 from 2018-12-02T10:00

Wietse Venema and Dan Farmer, the Developers of Security Administrator Tool for Analyzing Networks (SATAN), talk about their experience as developers, their journey to creating SATAN and their d...

Listen
Paul's Security Weekly (Video-Only)
Sven Morgenroth, Netsparker - Paul's Security Weekly #584 from 2018-12-01T10:00

Sven will talk about PHP Object injection vulnerabilities and explain the dangers of PHP's unserialize function. He will show the format of serialized PHP Objects, explain PHP's magic methods an...

Listen
Paul's Security Weekly (Video-Only)
"Dunkin" Donuts, Microsoft, & Marijuana - Paul's Security Weekly #584 from 2018-12-01T10:00

Hackers breach Dunkin Donuts, how insiders are serious threats to security in an organization, the return of email flooding, Microsoft helps police shut down fake tech support in India, and how ...

Listen
Paul's Security Weekly (Video-Only)
Spectre, ATMs, and Japan's Minister - Paul's Security Weekly #583 from 2018-11-19T10:00

7 new Spectre/Meltdown attacks, Hacking ATM's for free cash is easier than Windows XP, AI can now fake fingerprints fooling ID scanners, and Japan's cybersecurity minister admits he's never used...

Listen
Paul's Security Weekly (Video-Only)
John Moran, DFLabs - Paul's Security Weekly #583 from 2018-11-18T10:00

John is a Senior Product Manager at DFLabs, where he performs a wide variety of tasks from product management to content development and partner management. John Moran talks about IncMan SOAR an...

Listen
Paul's Security Weekly (Video-Only)
Jon Buhagiar, Sybex - Paul's Security Weekly #583 from 2018-11-17T10:00

Jon Buhagiar is responsible for Network Operations at Pittsburgh Technical College for the past 19 years. Jon is currently a Network+ Review Course Instructor at Sybex, and he joins us to talk a...

Listen
Paul's Security Weekly (Video-Only)
Apache, Dirty Cow, & Edge - Paul's Security Weekly #582 from 2018-11-12T10:30

Cisco accidentally released Dirty Cow exploit code, Apache Struts Vulnerabilities, Zero Day exploit published for VM Escape flaw, Spam spewing IoT botnet infects 100,000 routers, and some of the...

Listen
Paul's Security Weekly (Video-Only)
Eyal Neemany, Javelin Networks - Paul's Security Weekly #582 from 2018-11-11T10:00

Former Head of Israeli Air Force CERT & Forensics Team, Senior Security Researcher at Javelin Networks. Eyal will be discussing securing remote administration, remote credentials, explains that ...

Listen
Paul's Security Weekly (Video-Only)
Corin Imai, DomainTools - Paul's Security Weekly #582 from 2018-11-10T10:00

Corin Imai is Sr. Security Advisor for DomainTools. Corin began her career working on desktop virtualization, networking, and cloud computing technologies before delving into security. This inte...

Listen
Paul's Security Weekly (Video-Only)
AWS Lambda, Bleedingbit, and Cisco - Paul's Security Weekly #581 from 2018-11-05T10:00

AWS Security Best Practices, Masscan and massive address lists, Bleedingbit vulnerabilities, and Cisco Zero-Day exploited in the wild, ! All that and more, on this episode of Paul's Security Wee...

Listen
Paul's Security Weekly (Video-Only)
Matt Toussain, BHIS - Paul's Security Weekly #581 from 2018-11-04T09:00

Matt Toussain a Security Analyst at Black Hills Information Security, will be giving a tech segment on remote access tools (RAS).

To learn more about BHIS, go to: Listen

Paul's Security Weekly (Video-Only)
Aleksei Tiurin, Acunetix - Paul's Security Weekly #581 from 2018-11-03T09:00

Aleksei Tiurin is the Senior Security Researcher for Acunetix. Aleksei is giving a technical segment on insecure deserialization in Java/JVM and explains what polymorphism is. Aleksei Tiurin is ...

Listen
Paul's Security Weekly (Video-Only)
AI Fear, FDA, Tesla, and D-Link - Paul's Security Weekly #580 from 2018-10-29T09:00

Fear of AI attacks, the FDA releases cybersecurity guidance, watch hackers steal a Tesla, serious D-Link router security flaw may never be patched, and California addresses default passwords! Al...

Listen
Paul's Security Weekly (Video-Only)
Yossi Sassi, Javelin Networks - Paul's Security Weekly #580 from 2018-10-28T09:00

Yossi Sassi is the Co-Founder and Cybersecurity Researcher at CyberArtSecurity.com. Yossi joins us for a tech segment to talk about using windows powershell, discussing DCSync, DCShadow, creativ...

Listen
Paul's Security Weekly (Video-Only)
Veronica Schmitt, DFIRLABS - Paul's Security Weekly #580 from 2018-10-27T09:00

Veronica Schmitt is the Sr. Digital Forensic Scientist for DFIRLABS. Veronica explains what SRUM is in WIndows 10. She explains how SRUM can be a valuable tool in Digital Forensics.

Full ...

Listen
Paul's Security Weekly (Video-Only)
Shodan, Apache, ICS, and Controllers - Paul's Security Weekly #579 from 2018-10-22T09:00

How to use the Shodan search engine to secure an enterprise's internet presence, Apache access vulnerability could affect thousands of applications, vulnerable controllers could allow attackers ...

Listen
Paul's Security Weekly (Video-Only)
John Walsh, CyberArk - Paul's Security Weekly #579 from 2018-10-21T09:00

John Walsh the DevOps Evangelist for CyberArk joins us on the show. John talks about the articles he wrote for CyberArk about Kubernetes, DevSecOps, and how to strengthen your container authenti...

Listen
Paul's Security Weekly (Video-Only)
Mark Dufresne, Endgame - Paul's Security Weekly #579 from 2018-10-20T09:00

Mark Dufresne explains why MITRE created their tool and what the MITRE attack framework is.

Full Show Notes: https://wiki.securitywee...

Listen
Paul's Security Weekly (Video-Only)
DerbyCon, Russians, and Next Story - Paul's Security Weekly #578 from 2018-10-15T09:00

New Apple and Microsoft security flaws at Black Hat Europe, CCTV makers leaves at least 9 million cameras public, upset Google+ users are sueing Google, US weapons systems apparently can be easi...

Listen
Paul's Security Weekly (Video-Only)
Omer Yair, Javelin - Paul's Security Weekly #578 from 2018-10-14T09:00

Omer is End-Point team lead at Javelin Networks. The team focuses on methods to covertly manipulate OS internals. Before Javelin Networks, he was a malware researcher at IBM Trusteer for two yea...

Listen
Paul's Security Weekly (Video-Only)
Lee Neely, Lawrence Livermore National Lab - Paul's Security Weekly #578 from 2018-10-13T09:00

Lee Neely is a senior IT and security professional at LLNL with over 25 years of extensive experience with a wide variety of technology and applications from point implementations to enterprise ...

Listen
Paul's Security Weekly (Video-Only)
Linux Bugs, macOS Zero-Day, & Twitter Exposed - Paul's Security Weekly #577 from 2018-10-01T09:00

In the security news, Russian Hackers use Malware that can survive OS reinstalls, Facebook’s 2-Factor authentication With a phone number isn’t only for security, it’s used for ads ,FBI warns com...

Listen
Paul's Security Weekly (Video-Only)
Offensive Operating Against SysMon, Carlos Perez - Paul's Security Weekly #577 from 2018-09-30T09:00

Carlos Perez delivers the Technical Segment on How to Operate Offensively Against Sysmon. He talks about how SysMon allows him to create rules, and track specific types of tradecraft, around pro...

Listen
Paul's Security Weekly (Video-Only)
Mike Nichols, Keith McCammon, & Shawn Smith - Paul's Security Weekly #577 from 2018-09-29T09:00

Mike Nichols is the VP of Product Management at Endgame, and he manages the Endgame endpoint protection platform. Keith McCammon is the Chief Security Officer and Co-Founder of Red Canary, and h...

Listen
Paul's Security Weekly (Video-Only)
GovPayNow.com, AmazonBasics, and FBI - Paul's Security Weekly #576 from 2018-09-25T21:00

Senate can't protect senators staff from Cyber Attacks, Equifax fined by ICO over data breach that hit Britons, US Military given the power to hack back and defend forward,and AmazonBasics Micro...

Listen
Paul's Security Weekly (Video-Only)
Threat Hunting in the Cloud, Apollo Clark - Paul's Security Weekly #576 from 2018-09-23T09:00

Apollo Clark goes through inventory management, access management, config management, patch management, automated remediation, logging and monitoring, and deployment tools.

Full Show Note...

Listen
Paul's Security Weekly (Video-Only)
Mike Ahmadi, DigiCert - Paul's Security Weekly #576 from 2018-09-22T09:00

Mike Ahmadi oversees IoT security solutions and technical implementations for DigiCert customers across various verticals that include industrial, transportation, smart city, consumer devices an...

Listen
Paul's Security Weekly (Video-Only)
Microsoft, Elon Musk, Kernel and Powershell - Paul's Security Weekly #575 from 2018-09-17T09:00

Microsoft accidentally lets encrypted Windows 10 out the the world, Kernel exploit discovered in macOS, PowerShell obfuscation ups the anty on anti virus, Google outlines incident response proce...

Listen
Paul's Security Weekly (Video-Only)
Bypassing PAM, Eyal Neemany - Paul's Security Weekly #575 from 2018-09-16T09:00

Eyal Neemany describes how to bypass Linux Pluggable Authentication Modules provide dynamic authentication support for applications and services in a Linux or GNU/kFreeBSD system. Eyal Neemany i...

Listen
Paul's Security Weekly (Video-Only)
Brian Coulson, LogRhythm - Paul's Security Weekly #575 from 2018-09-15T09:00

Brian Coulson is a Senior Security Research Engineer in the Threat Research Group of LogRhythm Labs in Boulder, CO. His primary focus is the Threat Detection Modules such as UEBA, and NTBA.

...

Listen
Paul's Security Weekly (Video-Only)
Supermicro, Apache Struts, & HTTPS - Paul's Security Weekly #574 from 2018-09-10T09:00

In the security news, Spanish driver tests positive for every drug test, vulnerabilities found in the remote management interface of Supermicro servers, Apache Struts 2 flaw in the wild, HTTPS c...

Listen
Paul's Security Weekly (Video-Only)
Beacon Analysis, Chris Brenton - Paul's Security Weekly #574 from 2018-09-09T09:00

Beacon analysis is an integral part of threat hunting. If you are not looking for beacons you take the chance of missing compromised IoT devices or anything that does not have a threat mitigatio...

Listen
Paul's Security Weekly (Video-Only)
Wim Remes, Wire Security bvba - Paul's Security Weekly #574 from 2018-09-08T09:00

Wim Remes from Wire Security bvba comes on the show to talk about pentesting, SDLC, the state of security, life of a (virtual) CISO, and certifications.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Texas, T-Mobile, and Jack Daniel - Paul's Security Weekly #573 from 2018-09-03T09:00

In the Security News this week, Zero-Day Windows exploits, How to hide sensitive files in encrypted containers, Misfortune Cookie vulnerability returns, and bank robbers faked Cosmos backend to ...

Listen
Paul's Security Weekly (Video-Only)
No-Script Automation Tool, John Moran - Paul's Security Weekly #573 from 2018-09-02T09:00

John is a Senior Product Manager at DFLabs, where he performs a wide variety of tasks from product management to content development and partner management. Prior to joining DFLabs John worked f...

Listen
Paul's Security Weekly (Video-Only)
Jayson Street, SphereNY - Paul's Security Weekly #573 from 2018-09-01T09:00

Jayson E. Street is an author of the "Dissecting the hack: Series". Also the DEF CON Groups Global Ambassador. Plus the VP of InfoSec for SphereNY. He has also spoken at DEF CON, DerbyCon, GRRCo...

Listen
Paul's Security Weekly (Video-Only)
Burp Suite 2.0, DNC, and NotPetya - Paul's Security Weekly #572 from 2018-08-27T09:00

The Untold story of NotPetya, New Apache Struts RCE Flaw, How door cameras are creating dilemmas for police, Google gets sued for tracking you even when your location history is off, and Artific...

Listen
Paul's Security Weekly (Video-Only)
PHP Type Juggling Vulnerabilities, Netsparker - Paul's Security Weekly #572 from 2018-08-26T09:00

Sven Morgenroth is a security researcher at Netsparker. He found filter bypasses for Chrome's XSS auditor and several web application firewalls. He comes on the show to discuss PHP Type Juggling...

Listen
Paul's Security Weekly (Video-Only)
Tod Beardsley, Rapid7 - Paul's Security Weekly #572 from 2018-08-25T09:00

Tod Beardsley is the Director of Research at Rapid7. Paul talks to Tod about his recent projects Sonar and Heisenberg. They also discuss Tod's Under the Hoodie pentest report.

Full Show N...

Listen
Paul's Security Weekly (Video-Only)
Cigars and Security - Paul's Security Weekly #571 from 2018-08-21T09:00

Paul and Matt Alderman had the chance at DEF CON to sit down and talk about Cigars and Security. In our very first episode, Paul asks Matt questions on how he got started in Security, who some o...

Listen
Paul's Security Weekly (Video-Only)
Spoofing GPS with a hackRF, Larry Pesce - Paul's Security Weekly #571 from 2018-08-20T17:24:46

Our very own Larry Pesce delivers the Technical Segment this week on Spoofing GPS with a hackRF.

Full Show Notes: https://wiki.securi...

Listen
Paul's Security Weekly (Video-Only)
ThinkPenguin, Hacking Bodycams, & Adobe Flaws - Paul's Security Weekly #571 from 2018-08-19T16:00

In the Security News this week, Hacking Police Bodycams, Adobe fixes critical code execution flaws in latest patch update, Researchers develop device to aid in hunt for stealthy ATM card skimmer...

Listen
Paul's Security Weekly (Video-Only)
Yale University, Spam's Revival, and SDR - Paul's Security Weekly #570 from 2018-08-06T09:00

Reddit breached after hackers bypass 2FA, Yale University discloses old school data breach, and 5 steps to fight unauthorized cryptomining. All that and more, here on security weekly!

Ful...

Listen
Paul's Security Weekly (Video-Only)
Joshua Abraham, Praetorian - Paul's Security Weekly #570 from 2018-08-04T09:00

Josh is a key member of the technical execution team. In this capacity, he is responsible for leading, directing, and executing client-facing engagements that include Praetorian’s tactical and s...

Listen
Paul's Security Weekly (Video-Only)
Bluetooth Bug, Tenable, and Cosco - Paul's Security Weekly #569 from 2018-07-30T09:00

Bluetooth bug allows man-in-the-middle attacks on phones and laptops, serial killer electrocutes himself in jail cell sex act, Google launches its own USB-based FIDO U2F keys, and GhostPack.

...

Listen
Paul's Security Weekly (Video-Only)
Chris Dale, Netsecurity - Paul's Security Weekly #569 from 2018-07-29T09:00

Chris Dale is the Head of the Penetration Testing & Incident Handling groups at Netsecurity, a mid-sized company based out of Norway. Along with significant security expertise, Chris has a backg...

Listen
Paul's Security Weekly (Video-Only)
Dean Coclin, DigiCert - Paul's Security Weekly #569 from 2018-07-28T08:30

Dean Coclin is the Senior Director of Business Development at DigiCert. Dean brings more than 30 years of business development and product management experience in software, security, and teleco...

Listen
Paul's Security Weekly (Video-Only)
Pen Testing, SIM Hijackers, & Mining Bitcoin - Paul's Security Weekly #568 from 2018-07-24T09:00

In the Security News this week, the evolutionary waves of the penetration testing, the SIM Hijackers, Roblox blames virtual "gang rape" on hack, thousands of Mega logins dumped online, Facebook ...

Listen
Paul's Security Weekly (Video-Only)
Chris Spehn, Mandiant's Red Team - Paul's Security Weekly #568 from 2018-07-23T09:00

Chris 'Lopi' Spehn is a consultant on Mandiant's red team. Chris was formerly a penetration tester for major credit card companies and retailers. Chris is also the founder of Illinois State Univ...

Listen
Paul's Security Weekly (Video-Only)
Davi Ottenheimer, MongoDB - Paul's Security Weekly #568 from 2018-07-22T09:00

Davi Ottenheimer is a strategist and author focused on cultural disruptions and defense ethics in emerging data platforms and intelligent machines; for more than twenty years’ he has led global ...

Listen
Paul's Security Weekly (Video-Only)
Airport Security, Dark Web, and Apple - Paul's Security Weekly #567 from 2018-07-16T09:00

In the Security News this week, Hackers put Airport Security system Access on the Dark Web, Arch Linux PDF reader package poisoned,Chrome defends Spectre, & Cisco patches bug in VoIP phones.

...

Listen
Paul's Security Weekly (Video-Only)
Limor Elbaz, Peerlyst - Paul's Security Weekly #567 from 2018-07-15T09:00

Limor is an entrepreneur, product evangelist, security expert, and a business development executive. She is the Founder of Peerlyst, the largest community of security professionals, serving more...

Listen
Paul's Security Weekly (Video-Only)
Zane Lackey, Signal Sciences - Paul's Security Weekly #567 from 2018-07-14T09:00

Zane Lackey is the Founder/Chief Security Officer at Signal Sciences and serves on the Advisory Boards of the Internet Bug Bounty Program and the US State Department-backed Open Technology Fund....

Listen
Paul's Security Weekly (Video-Only)
WPA3, Ticketmaster, and Don't Wipe So Hard - Paul's Security Weekly #566 from 2018-07-03T09:00

Terrible passwords outlawed in Microsoft's new Azure tool, Ticketmaster suffers security breach in personal and payment data, stop wiping your butt so hard, Toronto cops in big trouble for eatin...

Listen
Paul's Security Weekly (Video-Only)
Fun with Android APK's, Joff Thyer - Paul's Security Weekly #566 from 2018-07-02T09:00

Ever wonder how to get started pen testing Android Apps? This tech segment will demonstrate a few basic techniques and tools to give you a taste of mobile app assessments with the Android platfo...

Listen
Paul's Security Weekly (Video-Only)
Tom Brennan & Gary Berman - Paul's Security Weekly #566 from 2018-07-01T09:00

Tom Brennan from Proactive Risk and Gary Berman from Cyberman Security, come on the show and talk about their journey up till their comic. They give us the inside scoop on their comic book, "The...

Listen
Paul's Security Weekly (Video-Only)
Golden Tickets, 911 Callers, and Hacking Therapy - Paul's Security Weekly #565 from 2018-06-25T09:00

In the Security News this week, shutting down the Internet to prevent cheating, Yubico claims a bug bounty and upsets researchers, patching MRI scanners, getting your money back after being scam...

Listen
Paul's Security Weekly (Video-Only)
NMAP Scripts With LUA and NSE - Paul's Security Weekly #565 from 2018-06-24T09:00

Jason Wood delivers this technical segment on NMAP. Everyone loves using Nmap and the Nmap Scripting Engine. We don't always write NSE scripts though. Writing scripts for can be a bit intimidati...

Listen
Paul's Security Weekly (Video-Only)
Galen Hunt, Microsoft Azure - Paul's Security Weekly #565 from 2018-06-23T09:00

Founder of Microsoft Azure Sphere, Galen Hunt is a Distinguished Engineer at Microsoft. Azure Sphere provides an end-to-end solution that enables any device manufacturer to create highly-secured...

Listen
Paul's Security Weekly (Video-Only)
Pennsylvania, Equifax, and US Senators - Paul's Security Weekly #564 from 2018-06-19T09:00

In the Security News this week, Smart lock can be hacked in seconds, librarian sues Equifax over 2017 data breach wins $600, Neighbors of Cold War Air Force deserter knew him as 'Tim'. In the ra...

Listen
Paul's Security Weekly (Video-Only)
Keith Hoodlet: Bug Bounty Hunting - Paul's Security Weekly #564 from 2018-06-18T09:00

Keith will be talking through some of the tools, techniques, and procedures he uses to perform recon, identify targets of interest, and report findings faster and easier.

Full Show Notes:...

Listen
Paul's Security Weekly (Video-Only)
Jason Haddix, Bugcrowd - Paul's Security Weekly #564 from 2018-06-17T09:00

As the Vice President of Trust & Security, Jason works with clients and security researchers to create high value, sustainable, and impactful bug bounty programs.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
CounterTack, Phishing Attacks, and Who Uses Flash? - Paul's Security Weekly #563 from 2018-06-11T09:00

In the Security News this week, Google Chrome has a critical vulnerability, Flash has another zero-day exploit, Colorado passes “most stringent” breach notification law, hackers hack a plane fro...

Listen
Paul's Security Weekly (Video-Only)
John Kinsella, Layered Insight - Paul's Security Weekly #563 from 2018-06-10T09:00

John Kinsella is a co-founder and head of product for Layered Insight, a container security startup based in San Francisco, California. His 20-year background includes security and network consu...

Listen
Paul's Security Weekly (Video-Only)
Jake Reynolds, LogRhythm - Paul's Security Weekly #563 from 2018-06-09T09:00

Jake Reynolds is the Technology Alliances Engineer at LogRhythm, where he is responsible for supporting the development and management of the company’s integrations with third-party technology p...

Listen
Paul's Security Weekly (Video-Only)
Acoustic Attacks, Bromium, and New GDPR Law - Paul's Security Weekly #562 from 2018-06-04T09:00

Dozens of vulnerabilities discovered in DoD's enterprise travel system, what Apple hiding with iOS 11.4, Git repository vulnerability leds to remote code execution attacks, and feeling for Kaspe...

Listen
Paul's Security Weekly (Video-Only)
Chris Elgee & Lee Ford, Mass. Army National Guard G-6 - Paul's Security Weekly #562 from 2018-06-03T09:00

Chris is a full time husband, father of four, and pen tester; he's a part time Army officer, an aspiring SANS instructor, and the back-up church bass player. Lee Ford spent 2yrs in Information s...

Listen
Paul's Security Weekly (Video-Only)
Ronnie Flathers, Uptake Technologies - Paul's Security Weekly #562 from 2018-06-02T09:00

Ronnie Flathers is an experienced pentester and security consultant who is equally addicted to both netsec and appsec and splits his time appropriately. He currently is the AppSec Pentest Lead a...

Listen
Paul's Security Weekly (Video-Only)
GDPR, DOJ Sinkholes, & PornHub - Paul's Security Weekly #561 from 2018-05-28T09:00

In the news, what will GDPR's impact be on U.S. consumer privacy, DOJ Sinkholes VPNfilter control servers found in U.S., the most important characteristics of a successful DevOps engineer, FBI s...

Listen
Paul's Security Weekly (Video-Only)
Bypassing Chrome's XSS Auditor - Paul's Security Weekly #561 from 2018-05-27T09:00

Sven Morgenroth is a security researcher at Netsparker. He found filter bypasses for Chrome's XSS auditor and several web application firewalls. He likes to exploit vulnerabilities in creative w...

Listen
Paul's Security Weekly (Video-Only)
Steven Bellovin, Columbia University - Paul's Security Weekly #561 from 2018-05-26T09:00

Steven M. Bellovin is the Percy K. and Vidal L. W. Hudson Professor of Computer Science at Columbia University, member of the Cybersecurity and Privacy Center of the university's Data Science In...

Listen
Paul's Security Weekly (Video-Only)
Project Zero, Securus, and CIA's "Vault 7" Mega-Leak - Paul's Security Weekly #560 from 2018-05-22T09:00

Google Project Zero call Windows 10 Edge Defense ACG flawed, Wapiti Web Application vulnerability scanner 3.0.1 packet storm, CIA's "Vault 7" Mega-Leak, and Trump eliminates national cyber-coord...

Listen
Paul's Security Weekly (Video-Only)
Configuring Your Own Travel Router with OpenVPN - Paul's Security Weekly #560 from 2018-05-21T09:00

Sometimes you just need a router handy when traveling. This allows you to connect multiple devices, use a VPN for all of them, and allow you to connect to a network via Wifi, Ethernet or USB 4G ...

Listen
Paul's Security Weekly (Video-Only)
Matthew Silva, RWU - Paul's Security Weekly #560 from 2018-05-20T09:00

This week we interview Matthew Silva, an Undergraduate student attending Roger Williams University, and is the President and Founder of the Cybersecurity and Intel Club!

Full Show Notes: ...

Listen
Paul's Security Weekly (Video-Only)
Microsoft Zero-Day, Mirai DDoS Attack, and GDPR - Paul's Security Weekly #559 from 2018-05-14T09:00

"Microsoft Patches Two Zero-Day Flaws Under Active Attack", "5 Powerful Botnets Found Exploiting Unpatched GPON Router Flaws", "Mirai DDoS attack against KrebsOnSecurity cost device owners $300,...

Listen
Paul's Security Weekly (Video-Only)
Docker Security Incident: Lessons Learned - Paul's Security Weekly #559 from 2018-05-13T09:00

Paul delivers the Technical Segment this week entitled "Docker Security Incident: Lessons Learned"!

Full Show Notes: https://wiki.sec...

Listen
Paul's Security Weekly (Video-Only)
Joe Gray, Advanced Persistent Security - Paul's Security Weekly #559 from 2018-05-12T09:00

Joe Gray is a native of East Tennessee. He joined the U.S. Navy directly out of High School and served for 7 years as a Submarine Navigation Electronics Technician. He joins Paul and the crew th...

Listen
Paul's Security Weekly (Video-Only)
Drupal, Twitter, iLo Ransomware, and Cambridge Analytica - Paul's Security Weekly #558 from 2018-05-06T09:00

Firms running Cisco WebEx are told to update their software, Medical devices vulnerable to KRACK Wi-Fi attacks, Kitty Cryptomining Malware Cashes in on Drupalgeddon 2.0, Facebook fires engineer ...

Listen
Paul's Security Weekly (Video-Only)
Leonard Rose, Principal Security Architect at Limelight Networks - Paul's Security Weekly #558 from 2018-05-05T09:00

Leonard Rose, Principal Security Architect at Limelight Networks, joins Paul and the crew this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Equifax, Amazon, & Hacking Hotels - Paul's Security Weekly #557 from 2018-04-30T09:00

In the news, Western Digital My Cloud EX2 NAS device leaks files, Equifax has spent $242.7 million on its data breach so far, New Skill let Amazon Alexa Spy on Users, Hackers find devious way to...

Listen
Paul's Security Weekly (Video-Only)
Jeff Man, Recap of RSAC - Paul's Security Weekly #557 from 2018-04-29T09:00

This week in the Topic Segment, our very own Jeff Man gives us a recap on the 2018 RSA Conference! He discusses HackerOne CEO talking Bug Bounty programs, DevSecOps day at RSA demonstrates how t...

Listen
Paul's Security Weekly (Video-Only)
Ferruh Mavituna, Founder of Netsparker - Paul's Security Weekly #557 from 2018-04-28T09:00

Ferruh Mavituna is the Founder and Product Manager of Netsparker. He developed the first and only proof-based web security scanner with state-of-the-art, accurate vulnerability detection and exp...

Listen
Paul's Security Weekly (Video-Only)
Drupal, Microsoft, & NSA - Paul's Security Weekly #556 from 2018-04-23T09:00

In the news, Microsoft built its own custom Linux OS to secure IoT devices, another critical flaw found in Drupal CorePatch your sites immediately, Facebook plans to build its own chips for hard...

Listen
Paul's Security Weekly (Video-Only)
Long Live Penetration Testing - Paul's Security Weekly #556 from 2018-04-22T09:00

We've spent time defining the value of penetration testing, how we can do them better and how organizations can make the most out of this activity. The question today is, "Do we still need penet...

Listen
Paul's Security Weekly (Video-Only)
Adrian Sanabria, Savage Security - Paul's Security Weekly #556 from 2018-04-21T09:00

Adrian is the Research Director and Co-Founder of Savage Security. He spent a decade building security programs and defending large financial firms. He also spent many years as a consultant, per...

Listen
Paul's Security Weekly (Video-Only)
RTF Bugs, Attacking Accountants, & Trollcave - Paul's Security Weekly #555 from 2018-04-16T09:00

In the news, RTF bug finally gets patched, so many ways to bridge an air gap, attacking accountants, spoofing all the ports and Trollcave, and more on this episode of Paul’s Security Weekly!

...

Listen
Paul's Security Weekly (Video-Only)
Got Privs? Extract and Crack the Creds - Paul's Security Weekly #555 from 2018-04-15T09:00

In the bad old days we used to exploit LSASS memory to dump hashed credentials from memory. When dealing with a domain controller, and a large environment this is dangerous. This segment will ad...

Listen
Paul's Security Weekly (Video-Only)
Ron Gula, Gula Tech Adventures - Paul's Security Weekly #555 from 2018-04-14T09:00

Ron is a Serial Cyber Security Entrepreneur. He founded Tenable Network Security and Network Security Wizards, and has 15+ years experience as CEO in cyber security industry. He joins Paul and t...

Listen
Paul's Security Weekly (Video-Only)
Intel, Cisco, Facebook, & Twitter - Paul's Security Weekly #554 from 2018-04-09T09:00

In the news, Intel drops plans to develop Spectre microcode for ancient chips, Critical flaw leaves thousands of Cisco Switches vulnerable to remote hacking, VirusTotal launches 'Droidy' sandbox...

Listen
Paul's Security Weekly (Video-Only)
Masha Sedova, Elevate Security - Paul's Security Weekly #554 from 2018-04-08T09:00

Masha Sedova is an industry-recognized people-security expert, speaker and trainer focused on engaging people to be key elements of secure organizations. She is the co-founder of Elevate Securit...

Listen
Paul's Security Weekly (Video-Only)
Katherine Teitler, MISTI - Paul's Security Weekly #554 from 2018-04-07T09:00

Katherine Teitler is the Director of Content for MISTI, where she is responsible for programming information security conferences, workshops, and summits. Katherine also writes on a variety of s...

Listen
Paul's Security Weekly (Video-Only)
Apple, Meltdown, & Atlanta Hackers - Paul's Security Weekly #553 from 2018-04-02T09:00

In the news, Apple macOS Bug Reveals Passwords for APFS Encrypted Volumes in Plaintext, Windows 7 Meltdown patch opens worse vulnerability, Atlanta Hit by Ransomware Attack Impacting Multiple Se...

Listen
Paul's Security Weekly (Video-Only)
Cutting The Cord: The Ideal Home Network Setup - Paul's Security Weekly #553 from 2018-04-01T09:00

In this weeks Technical Segment, Paul delivers his segment entitled Cutting The Cord: The Ideal Home Network Setup. Paul and the crew discuss Nvidia Shield, Firewalls, Parental Control, and othe...

Listen
Paul's Security Weekly (Video-Only)
Rob Cheyne, SourceBoston - Paul's Security Weekly #553 from 2018-03-31T09:00

Rob Cheyne is a highly regarded technologist, trainer, security expert and serial entrepreneur. He has 25 years of experience in the information technology field and has been working in informat...

Listen
Paul's Security Weekly (Video-Only)
Alex Stamos, Facebook, Uber, and The Cuban Sonic Weapon - Paul's Security Weekly #552 from 2018-03-25T09:00

The Scarlett Johansson PostgreSQL Malware Attack, Alex Stamos might be leaving Facebook, is Mark Zuckerberg in trouble with the law again?, Uber self-driving car hits and kills pedestrian, and C...

Listen
Paul's Security Weekly (Video-Only)
How To Find The Most Innovative Tech At A Security Show - Paul's Security Weekly #552 from 2018-03-24T09:00

Paul and Jeff express their likes and dislikes of vendor booths. Discover how to be a good sales-rep for your company, how to make yourself stand out in the vendor space, and how to be loose in ...

Listen
Paul's Security Weekly (Video-Only)
Dick Wilkins, Phoenix Technologies - Paul's Security Weekly #551 from 2018-03-20T09:00

Dick Wilkins is an Associate Professor of Computer Science at Thomas College in central Maine and is Principal Technology Liaison for Phoenix Technologies, a USA based system boot firmware devel...

Listen
Paul's Security Weekly (Video-Only)
Flash, Pwn2Own, & VMware - Paul's Security Weekly #551 from 2018-03-19T09:00

In the news, Memcrashed Memcached DDoS exploit tool, Flash, Windows Users: It's Time to Patch, VMware releases security updates, what happens when Bitcoin miners take over your town, and more on...

Listen
Paul's Security Weekly (Video-Only)
Patrick Laverty, Rapid7 - Paul's Security Weekly #551 from 2018-03-18T09:00

Patrick is a pentester for Rapid7, has done SIRT work for Akamai and was a web application developer at Brown University. He joins Paul and the crew this week for an interview!

Full Show ...

Listen
Paul's Security Weekly (Video-Only)
Cisco, Kali, Equifax, & Facebook - Paul's Security Weekly #550 from 2018-03-12T09:00

In the news, Cisco hardcoded passwords, Kali on Windows, Equifax recovers $114 million on $26.5 million in expenses from breach, and more on this episode of Paul's Security Weekly!

Full S...

Listen
Paul's Security Weekly (Video-Only)
Sven Morgenroth, Netsparker - Paul's Security Weekly #550 from 2018-03-11T10:00

Sven Morgenroth is a security researcher at Netsparker. He found filter bypasses for Chrome's XSS auditor and several web application firewalls.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Stefano Righi, UEFI - Paul's Security Weekly #550 from 2018-03-10T10:00

Stefano has over 35 years of experience in research and development. Stefano is representing AMI on the UEFI Forum Board of Directors and serves on the UEFI Security Response Team. He joins Larr...

Listen
Paul's Security Weekly (Video-Only)
Quickjack, Olympics, Largest DDoS Attack, and Bad AI is Still Bad AI - Paul's Security Weekly #549 from 2018-03-05T10:00

In the news, Quickjack advanced Clickjacking & frame slicing attack tool, how to fight mobile number port-out scams, the Russians hacked the Olympics, top 5 ways security vulnerabilities hide in...

Listen
Paul's Security Weekly (Video-Only)
Bruce Sussman, SecureWorld Boston - Paul's Security Weekly #549 from 2018-03-04T10:00

Bruce Sussman spent more than 20 years on TV screens in Portland, Oregon. He joins Paul and crew this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Mary Beth Borgwing, Mach37 - Paul's Security Weekly #549 from 2018-03-03T10:00

Mary Beth Borgwing is an Advisor to MACH 37 and Center for Innovation (CIT). She joins Paul and team this week for an interview! Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
DoubleDoor, NSA, & Google - Paul's Security Weekly #548 from 2018-02-18T10:00

In the news, DoubleDoor IoT botnet abuses two vulnerabilities to circumvent firewalls, cyber-attackers continue to be financially motivated, Internet security threats at the 2018 Olympics, and m...

Listen
Paul's Security Weekly (Video-Only)
Michael Bazzell, OSINT & Privacy Consultant - Paul's Security Weekly #548 from 2018-02-17T10:00

Michael Bazzell spent 18 years as a government computer crime investigator. He joins Paul and crew this week for an interview!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Steve Tcherchian, XYPRO Technology - Paul's Security Weekly #548 from 2018-02-16T10:00

Steve Tcherchian, CISSP, PCI-ISA, PCIP is the Chief Information Security Officer and the Director of Product Management for XYPRO Technology. He joins Paul and team this week for an interview! Listen

Paul's Security Weekly (Video-Only)
Bitcoin, NSA, and Facebook - Paul's Security Weekly #547 from 2018-02-12T10:00

In the news, multiple vulnerabilities in 7-Zip, how getting granular improves network security, NSA exploit use on rise for cryptocurrency mining,and more on this episode of Paul’s Security Week...

Listen
Paul's Security Weekly (Video-Only)
ESP8266 SoC0, Larry Pesce - Paul's Security Weekly #547 from 2018-02-11T10:00

Larry Pesce delivers the Technical Segment on an intro to the ESP8266 SoC!

Full Show Notes: https://wiki.securityweekly.com/Episode54...

Listen
Paul's Security Weekly (Video-Only)
Zane Lackey, Signal Sciences Paul's Security Weekly #547 from 2018-02-10T10:00

Zane Lackey is the Founder/Chief Security Officer at Signal Sciences and serves on the Advisory Boards of the Internet Bug Bounty Program and the US State Department-backed Open Technology Fund....

Listen
Paul's Security Weekly (Video-Only)
MITRE, John Strand - Paul's Security Weekly #546 from 2018-02-04T10:00

John Strand, Managing Intern of Black Hills Information Security, delivers the Technical Segment on MITRE!

Full Show Notes: https://w...

Listen
Paul's Security Weekly (Video-Only)
Mark Arnold & Will Gragido, InfoSecWorld 2018 - Paul's Security Weekly #546 from 2018-02-03T10:00

Will Gragido is an internationally recognized information security specialist. Mark Arnold brings more than 20 years of technical and leadership experience to his role as a Senior Director of Se...

Listen
Paul's Security Weekly (Video-Only)
AI Celebrity Porn, NSA Exploit, and Bitcoin Exchange - Paul's Security Weekly #546 from 2018-02-02T17:55:29

Bitcoin exchange robbed, Deepfakes AI celebrity porn channel shut down by Discord, NSA Exploit Use On Rise For Crypto Currency Mining, First Jackpotting Attacks Hit U.S. ATMs, and more! Full Show N...

Listen
Paul's Security Weekly (Video-Only)
BIND, Intel, and Brickerbot - Paul's Security Weekly #545 from 2018-01-29T10:00

In the news, Intel warns "Don’t install our patch!", what you need to know about hash length extension attacks, Meltdown and Spectre patching has been a total train wreck,and more on this episod...

Listen
Paul's Security Weekly (Video-Only)
Critical Security Control Resources, John Strand - Paul's Security Weekly #545 from 2018-01-28T10:00

John Strand delivers the Technical Segment on Critical Security Control Resources!

Full Show Notes: https://wiki.securityweekly.com/E...

Listen
Paul's Security Weekly (Video-Only)
Kevin Donovan, ObserveIT - Paul's Security Weekly #545 from 2018-01-27T10:00

Kevin is one of ObserveIT's insider threat experts and a Senior Solutions Architect. He joins Larry and team this week for an interview on Paul's Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
BIND, Intel, and Brickerbot - Paul's Security Weekly #544 from 2018-01-22T10:00

In the news, BIND comes apart thanks to ancient denial of service vuln, Brickerbot taking out your IoT one device at a time, Intel fix causes reboots and slowdowns, WiFi alliance announces WPA3 ...

Listen
Paul's Security Weekly (Video-Only)
Adam Gordon, ItPro.TV - Paul's Security Weekly #544 from 2018-01-20T10:00

With over 30 years of experience as both an educator and IT professional, Adam holds numerous Professional IT Certifications. He joins Paul and team this week for an interview on Paul’s Security...

Listen
Paul's Security Weekly (Video-Only)
Rebekah Brown, Rapid7 - Paul's Security Weekly #544 from 2018-01-19T15:25:41

Rebekah Brown has spent more than a decade working in intelligence and information security. Today, Rebekah leads the threat intelligence programs at Rapid7, where her responsibilities include prog...

Listen
Paul's Security Weekly (Video-Only)
Skype, Apple, and Wi-Fi Alliance - Paul's Security Weekly #543 from 2018-01-15T10:00

In the news, prosecutors say Mac Spyware stole millions of user images over 13 years, Skype finally getting end-to-end encryption, Apple set to patch yet another macOS password security flaw, 14...

Listen
Paul's Security Weekly (Video-Only)
Jake Williams, SANS - Paul's Security Weekly #543 from 2018-01-14T10:00

Jake Williams is the founder of Rendition Infosec and is a Senior Instructor at the SANS Institute. MalwareJake clears last weeks news story with the latest news on Meltdown and Spectre. He join...

Listen
Paul's Security Weekly (Video-Only)
Diana Kelley & Ed Moyle, Security Curve - Paul's Security Weekly #543 from 2018-01-13T10:00

Diana Kelley is the Cybersecurity Field CTO at Microsoft and a cybersecurity thought leader, practitioner, executive advisor, speaker, author and co-founder of SecurityCurve. Ed Moyle is current...

Listen
Paul's Security Weekly (Video-Only)
VMWare, Meltdown, Spectre, and Chip Hacks That Work - Paul's Security Weekly #542 from 2018-01-08T10:00

10 things in cybersecurity that you might have missed in 2017, a flaw in major browsers, a critical flaw in phpMyAdmin, beware of a VMWare VDP remote root issue, how to protect your home router,...

Listen
Paul's Security Weekly (Video-Only)
Mimikatz Event Log Clearing Feature with John Strand - Paul's Security Weekly #542 from 2018-01-07T10:00

John will be talking about the new mimikatz event log clearing feature.

Full Show Notes: https://wiki.securityweekly.com/Episode542 Listen

Paul's Security Weekly (Video-Only)
Marcello Salvati, Coalfire Labs - Paul's Security Weekly #542 from 2018-01-06T10:00

Marcello Salvati is a senior security consultant at Coalfire Labs by day and by night a tool developer who discovered a novel technique to turn tea, sushi and dank memes into somewhat functionin...

Listen
Paul's Security Weekly (Video-Only)
Fake Bitecoin, North Korea, and Wordpress - Paul's Security Weekly #541 from 2017-12-27T10:00

In the news, we discuss Uber paying hacker to keep quiet, flaw in Intel processors, banking apps found vulnerable to MITM attacks, Apple patching all other High Sierra security holes,and more on...

Listen
Paul's Security Weekly (Video-Only)
Kevin Finisterre, Department 13 - Paul's Security Weekly #541 from 2017-12-26T10:00

Kevin Finisterre is a principal of the security consultancy Digitalmunition, he enjoys testing the limits and is constantly dedicated to thinking outside the box. Kevin’s primary focus has alway...

Listen
Paul's Security Weekly (Video-Only)
Bob Hillery, InGuardians - Paul's Security Weekly #541 from 2017-12-25T10:00

Bob Hillery join us on Security Weekly and is an experienced consultant in Information Systems Security Management. He is a founder and Chief Research Officer with InGuardians, Inc. and has an e...

Listen
Paul's Security Weekly (Video-Only)
On-Demand Webcasts, Net Neutrality, and Pentesting - Paul's Security Weekly #540 from 2017-12-18T10:00

In the news, we talk about pentesting, On-Demand webcasts, net neutrality, Vegemite, and more on this episode of Paul’s Security Weekly!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Ed Skoudis, Holiday Hack Challenge - Paul's Security Weekly #540 from 2017-12-17T10:00

Ed Skoudis has taught cyber incident response and advanced penetration testing techniques to more than 12,000 cybersecurity professionals. He is a SANS Faculty Fellow and the lead for the SANS P...

Listen
Paul's Security Weekly (Video-Only)
Joe Gray, Advanced Persistent Security - Paul's Security Weekly #540 from 2017-12-16T10:00

Joe Gray is a native of East Tennessee. He joined the U.S. Navy directly out of High School and served for 7 years as a Submarine Navigation Electronics Technician. He is also the owner of the A...

Listen
Paul's Security Weekly (Video-Only)
Uber, Vulnerable Banking Apps, and Bluetooth - Paul's Security Weekly #539 from 2017-12-11T10:00

In the news, a new Windows evasion technique, naked rowers, undetectable malware, social engineering from your shed and banking apps vulnerable to MITM attacks.

?Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Bypassing Two-Factor Authentication - Paul's Security Weekly #539 from 2017-12-10T10:00

Former Head of Israeli Air Force CERT & Forensics Team, Senior Security Researcher at Javelin Networks. Eyal Neemany talks about bypassing two-factor authentication on Active Directory.

?...

Listen
Paul's Security Weekly (Video-Only)
Lisa O'Connor, Accenture - Paul's Security Weekly #539 from 2017-12-09T10:00

Lisa leads Global Security Research and Development at Accenture Labs. In this role, she curates and manages a portfolio of cyber research, including threat intelligence, advanced cyber hunting,...

Listen
Paul's Security Weekly (Video-Only)
High Sierra, NSA, WordPress, and HP - Paul's Security Weekly #538 from 2017-12-04T10:00

More secure WordPress updates, paying attention to SD-WAN security, NSA's "Red Disk" data leak, why gets you root, HP bloatware, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Network Telemetry with Mick Douglas, SANS Institute - Paul's Security Weekly #538 from 2017-12-03T10:00

Our good friend Mick Douglas takes an excerpt from SANS 555 and demonstrates using network telemetry to find unauthorized hosts with ELK stacks!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Allison Miller Paul's Security Weekly #538 from 2017-12-02T10:00

Allison Miller has been working in the intersection of cybersecurity, human behavior, and predictive analytics for almost two decades. She has pioneered the use of data-driven detection technolo...

Listen
Paul's Security Weekly (Video-Only)
DoD, Oracle, Apple, and Boeing - Paul's Security Weekly #537 from 2017-11-20T10:00

Blaming Russia, compromising Apple’s facial recognition, books to give to your 30-year old self, malware on NSA employee computers, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Mike Roderick & Adam Gordon, ITProTV - Paul's Security Weekly #537 from 2017-11-19T10:00

Our good friends Mike Roderick and Adam Gordon, two of ITProTV’s many security ninjas, deliver a tech segment and demo on virtualization, TPM, VMware, and virtual desktop infrastructure (VDI) as...

Listen
Paul's Security Weekly (Video-Only)
Kyle Wilhoit, DomainTools - Paul's Security Weekly #537 from 2017-11-18T10:00

Kyle Wilhoit, a Senior Security Researcher for DomainTools, discusses all things dark web, illegal internet trade, and more with Paul!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Ex-NSA, Microsoft, Vault 8, and Backdoor in SATNAV - Paul's Security Weekly #536 from 2017-11-13T10:00

Marissa Mayer testifies, starting wars by hacking back, hacking fingerprint biometrics, the halfway point of Mr. Robot, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Tech Segment: Sven Morgenroth, Netsparker - Paul's Security Weekly #536 from 2017-11-12T10:00

We welcome Sven Morgenroth back to the show! Sven currently works as a Security Researcher at Netsparker. He rejoins us to deliver a technical segment on content security policies and cross-site...

Listen
Paul's Security Weekly (Video-Only)
Amanda Berlin, NetWorks Group and Lee Brotherston, Wealthsimple - Paul's Security Weekly #536 from 2017-11-11T10:00

Amanda Berlin of NetGroup and Lee Brotherston of Wealthsimple join Paul, Michael, and Larry for a discussion on the Defensive Security Handbook and its implications in the world of security!

...

Listen
Paul's Security Weekly (Video-Only)
Gadi Evron, Cymmetria - Paul's Security Weekly #535 from 2017-11-06T10:00

Gadi Evron founded Cymmetria in 2014 with a vision of revolutionizing security technology, strategy, and innovation. He joins Paul, Doug, and Jeff for an interview about honeypots, hacking back,...

Listen
Paul's Security Weekly (Video-Only)
Tim Medin, SANS Institute - Paul's Security Weekly #535 from 2017-11-05T09:00

Tim Medin from SANS comes on the show and does a tech segment on Windows PowerShell using PowerShell Empire.

Full Show Notes: https:/...

Listen
Paul's Security Weekly (Video-Only)
Richard Moulds, Whitewood Security - Paul's Security Weekly #535 from 2017-11-04T09:00

Richard Moulds, General Manager of Whitewood Security, makes his triumphant return to the show!

Full Show Notes: https://wiki.securit...

Listen
Paul's Security Weekly (Video-Only)
Microsoft, KRACK, Docker, and Kubernetes - Paul's Security Weekly #534 from 2017-10-23T09:00

Microsoft mocks Google for failed security fix, 5 steps to building a vulnerability management program, Pornhub, and kids smartwatches are harbouring major security flaws.

Full Show Notes...

Listen
Paul's Security Weekly (Video-Only)
Borrowing Data, Joe Vest and Andrew Chiles, MINIS - Paul's Security Weekly #534 from 2017-10-22T09:00

Joe Vest and Andrew Chiles from MINIS talk about Borrowing data to hide binaries. Joe Vest is the Co-Founder of the security consulting company MINIS LLC. He has over 17 years' experience with a...

Listen
Paul's Security Weekly (Video-Only)
Wendy Nather, Duo Security - Paul's Security Weekly #534 from 2017-10-21T09:00

Wendy Nather is Principal Security Strategist at Duo Security. Wendy is also a good friend of the Security Weekly team! She speaks regularly on topics ranging from threat intelligence to identit...

Listen
Paul's Security Weekly (Video-Only)
Windows, Disqus, Cyberattacks, and FBI Cyberstalker - Paul's Security Weekly #533 from 2017-10-16T09:00

Windows Phone is dead, Disqus gets hacked, malvertising on X rated websites, North Korea ups their cyberattack game, the FBI arrests a cyberstalker, and more security news!

Full Show Note...

Listen
Paul's Security Weekly (Video-Only)
Matthew Toussain, SANS Institute - Paul's Security Weekly #533 from 2017-10-15T09:00

Matthew Toussain is an active-duty Air Force officer and the founder of Spectrum Information Security. He regularly hunts for vulnerabilities in computer systems and releases tools to demonstrat...

Listen
Paul's Security Weekly (Video-Only)
Pausing Processes with PowerShell with Mick Douglas, SANS - Paul's Security Weekly #533 from 2017-10-14T09:00

Mick Douglas is a SANS instructor and the Managing Partner for InfoSec Innovations. He joins us to demonstrate pausing potentially malicious executables in PowerShell!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Equifax, Google, Alex Stamos, and Kaspersky - Paul's Security Weekly #532 from 2017-10-09T09:00

New Gmail security, who to blame for the Equifax breach, three billion compromised Yahoo accounts, embarrassing encryption ignorance, and why is Alex Stamos hunting down Russian political ads on...

Listen
Paul's Security Weekly (Video-Only)
Ran Levi, Podcast Israel Media - Paul's Security Weekly #532 from 2017-10-08T09:00

Ran Levi started Making History! Podcast in 2007, which has become the most successful podcast in Israel. He has authored three books on malware, science, and more.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Don Pezet, ITProTV - Paul's Security Weekly #532 from 2017-10-07T09:00

Our good friend Don Pezet joins Paul, Doug, and Ran for a discussion on his background in security! Don is a Co-Founder and Host of ITProTV, a video IT training company based in central Florida....

Listen
Paul's Security Weekly (Video-Only)
#TrevorForget, PGP, Oracle, and Linux Kernel - Paul's Security Weekly #531 from 2017-10-04T09:00

Don't worry about PGP private key exposure, Signal taps up Intel's SGX for increased security, a two-year-old Linux Kernel issue resurfaces, Bill Gates's biggest mistake, Oracle patches away, an...

Listen
Paul's Security Weekly (Video-Only)
Ed Skoudis, Counter Hack - Paul's Security Weekly #531 from 2017-10-03T09:00

Ed Skoudis is a SANS Faculty Fellow and the lead for the SANS Penetration Testing Curriculum. He has the rare ability to translate advanced technical knowledge into easy-to-master guidance. Ed r...

Listen
Paul's Security Weekly (Video-Only)
Jim Nitterauer, AppRiver - Paul's Security Weekly #531 from 2017-10-02T09:00

Jim Nitterauer, CISSP is currently a Senior Security Specialist at AppRiver. He's well-versed in ethical hacking and penetration testing techniques. Jim joins us for a nostalgia-packed DNS discu...

Listen
Paul's Security Weekly (Video-Only)
Windows 10, Zerodium, Linus Torvalds, and Equifax - Paul's Security Weekly #530 from 2017-09-18T09:00

No excuses for Equifax, mixed reviews for Apple’s facial recognition, Adobe and Microsoft patch away, one MILLION dollars for Tor zero-days, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
What It Takes To Attack an ICS with Mike Assante, SANS Institute - Paul's Security Weekly #530 from 2017-09-17T09:00

Mike Assante is the Director of Critical Infrastructure and ICS for the SANS Institute. He clears up the confusion of Dragonfly 2.0 and explains control systems and how those attacks work.

<...

Listen
Paul's Security Weekly (Video-Only)
Ted Demopoulos, SANS Institute - Paul's Security Weekly #530 from 2017-09-16T09:00

Ted Demopoulos is a Senior SANS Instructor, a recipient of the Department of Defense Award of Excellence, and the author of Infosec Rock Star: How to Accelerate Your Career Because Geek Will Onl...

Listen
Paul's Security Weekly (Video-Only)
Flaw in Apache, Wikileaks Unveils Project Protego, and Linux 4.13 - Paul's Security Weekly #529 from 2017-09-12T09:00

The nightmare that is patching IoT devices, essential bug bounty programs, controlling voice assistants, flaws in Apache Struts2, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Mobile Application Assessment with Chris Crowley, SANS Institute - Paul's Security Weekly #529 from 2017-09-10T09:00

Chris Crowley is a SANS instructor and independent consultant based in the Washington, D.C. area. Mr. Crowley overviews his approach to keeping mobile applications secure in this technical segme...

Listen
Paul's Security Weekly (Video-Only)
Michele Jordan, Under the Oak Consulting - Paul's Security Weekly #529 from 2017-09-09T09:00

Michele Jordan is the Founder and Principal Consultant of Under the Oak Consulting. She has worked in IT and network security for over 35 years. Michele delves into her background in security, h...

Listen
Paul's Security Weekly (Video-Only)
FCC, The Fappening, and Boarding Passes - Paul's Security Weekly #528 from 2017-09-04T09:00

Are you sick of The Fappening yet? We're not! Larry and Dave have fun with boarding passes, hacking pacemakers, the FCC hosting your memes, and more information security news!

Full Show N...

Listen
Paul's Security Weekly (Video-Only)
Dave Kennedy, DerbyCon 2017 Preview - Paul's Security Weekly #528 from 2017-09-03T09:00

Larry and Dave discuss the upcoming DerbyCon conference, shenanigans from past cons, and reiterate the mission that DerbyCon was founded around in the first place!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Tech Segment: Kyle Wilhoit, DomainTools - Paul's Security Weekly #528 from 2017-09-02T09:00

Kyle Wilhoit is a Senior Security Researcher at DomainTools; he focuses on research DNS-related exploits, investigate current cyber threats, and exploration of attack origins and threat actors. ...

Listen
Paul's Security Weekly (Video-Only)
Larry's Capture-the-Flag Scenario - Paul's Security Weekly #527 from 2017-08-28T09:00

Larry had a technical problem that he needed to solve. Larry demonstrates a new capture-the-flag scenario. Larry explains how to capture a particular wireless packet in the middle of all this no...

Listen
Paul's Security Weekly (Video-Only)
Richard Moulds, Whitewood Security - Paul's Security Weekly #527 from 2017-08-27T09:00

Richard Moulds is the General Manager of Whitewood Security. Whitewood aims to help its customers to take control of the generation of random numbers across their application infrastructure.

...

Listen
Paul's Security Weekly (Video-Only)
Fappening 2017, Open AWS, Flipboard, and Bitcoin - Paul's Security Weekly #527 from 2017-08-26T09:00

More Celebrity Nude Photos Hacked and Leaked Online, A Company Offers $500,000 For Secure Messaging Apps Zero-Day Exploits, Beware of Windows/MacOS/Linux Virus Spreading Through Facebook Messeng...

Listen
Paul's Security Weekly (Video-Only)
Airdrop, Rowhammer, and Profexor Goes Dark - Paul's Security Weekly #526 from 2017-08-21T09:00

More Chrome extensions have been compromised, disabling safety features in cars, being targeted via AirDrop, USB is less secure (go figure), and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Bypassing Input Filters with Sven Morgenroth, Netsparker - Paul's Security Weekly #526 from 2017-08-20T09:00

Your WAF is not safe! Sven Morgenroth, a Security Researcher at Netsparker, blows Paul’s mind with his ninja-esque input filter bypass skills in this technical segment!

Full Show Notes: <...

Listen
Paul's Security Weekly (Video-Only)
Bryson Bort, GRIMM - Paul's Security Weekly #526 from 2017-08-19T09:00

Bryson Bort is the Founder and CEO of GRIMM, a Washington, D.C. based security engineering and consulting services company. Bryson delves in-depth into his entrepreneurship journey, the problems...

Listen
Paul's Security Weekly (Video-Only)
Paul's Printer Hacking Adventures - Paul's Security Weekly #525 from 2017-08-15T09:00

Printer attacks have been around for some time. Paul describes some of the latest techniques and research into printer hacking, including capturing print jobs, manipulating print jobs and other ...

Listen
Paul's Security Weekly (Video-Only)
Dropbox, BeyondTrust, Marcus Hutchins, and DEF CON - Paul's Security Weekly #525 from 2017-08-14T09:00

Mystery bug bounties, Marcus Hutchins pleads not guilty, a password guru regrets past advice, Dropbox and offline two-factor authentication, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Aram Jivanyan, BeSafe - Paul's Security Weekly #525 from 2017-08-13T09:00

Aram is the Founder and CEO of BeSafe (formerly Skycryptor), an encrypted cloud company that uses proxy re-encryption techniques to protect user data. He provides a demo on his techniques to ens...

Listen
Paul's Security Weekly (Video-Only)
WannaCry, FBI Arrests Researcher, and Smart Guns - Paul's Security Weekly #524 from 2017-08-08T09:00

WannaCry's killswitch domain registrant is arrested, making infosec more inclusive, hacking 113-year-old subway signs, security standards for smart devices, and more security news!

Full S...

Listen
Paul's Security Weekly (Video-Only)
VaporTrail with Larry Pesce and Galen Alderson, InGuardians - Paul's Security Weekly #524 from 2017-08-07T09:00

Larry and his intern, Galen Alderson, present a demo of their Vaportrail project! Galen shows us how to exfiltrate data from networks using broadcast FM radio and other inexpensive materials. Listen

Paul's Security Weekly (Video-Only)
Danny Miller, Ericom Software - Paul's Security Weekly #524 from 2017-08-06T09:00

Danny Miller, the Director of Product Marketing at Ericom Software, joins us to discuss how enterprises can protect themselves by utilizing isolated browsing and other techniques!

Full Sh...

Listen
Paul's Security Weekly (Video-Only)
Bypassing Corporate Firewalls with Sven Morgenroth, Netsparker - Paul's Security Weekly #523 from 2017-07-23T09:00

Sven Morgenroth of Netsparker joins us to expound upon an original blog post on bypassing corporate firewalls and vulnerable web applications in this technical segment!

Full Show Notes: <...

Listen
Paul's Security Weekly (Video-Only)
Javelin ADProtect vs. Microsoft ATA with Almog Ohayon - Paul's Security Weekly #523 from 2017-07-22T09:00

Almog Ohayon of Javelin Networks pits Javelin ADProtect against Microsoft ATA in an epic threat analytics showdown!

Full Show Notes: ...

Listen
Paul's Security Weekly (Video-Only)
Windows Vulnerabilities, Dirty Radio Songs, and Prime Day - Paul's Security Weekly #522 from 2017-07-17T09:00

Russians on PornHub, dirty songs on the radio, Windows security protocol vulnerabilities, tomato plant security, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Hardening Software RNGs with Don Pezet, ITProTV - Paul's Security Weekly #522 from 2017-07-16T09:00

This is a random technical segment on implementing random number generators in Linux. Don shows us the ins and outs of the entropy pool, the different between /dev/random and /dev/urandom, and s...

Listen
Paul's Security Weekly (Video-Only)
Joe Desimone, Endgame - Paul's Security Weekly #522 from 2017-07-15T09:00

Learn about "fileless" malware, threat actors, evading detection on the endpoint and more!

Joe Desimone is a Malware Researcher at Endgame. He focuses on tracking and countering APTs, rev...

Listen
Paul's Security Weekly (Video-Only)
Tim Helming, DomainTools - Paul's Security Weekly #521 from 2017-07-11T09:00

Tim Helming joins us to talk about all things related to domains, including luxury domain abuses, the security value of the whois database and more!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Demystifying the Art of Hunting with Paul Ewing, Endgame - Paul's Security Weekly #521 from 2017-07-10T20:45:29

Paul Ewing from Endgame talks about the different types of threat hunting (network, host and logs) and the pros and cons of each!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Google Patches, Wordpress, and GnuPG - Paul's Security Weekly #521 from 2017-07-10T09:00

How to hire infosec professionals, patching automation code, hijacked Android devices, Bitdefender support for Mac, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Linux hacking, Petya, and Windows - Paul's Security Weekly #520 from 2017-07-03T09:00

Separating the hacked and the paranoid, remote Linux hacking, Petya goes postal at FedEx, today’s mainstream hacktivism tools, and why choosing Windows should get you fired!

Full Show Not...

Listen
Paul's Security Weekly (Video-Only)
Domain Admin in Active Directory, Guy Franco - Paul's Security Weekly #520 from 2017-07-02T09:00

Guy came on the show and gave a live demo on how to become Domain Admin in an Active Directory environment, and keep those privileges for 20+ years. Guys shows us how to abuse service accounts t...

Listen
Paul's Security Weekly (Video-Only)
Moses Hernandez, Cisco Systems - Paul's Security Weekly #520 from 2017-07-01T09:00

Moses returns to the show to discuss his background in technology and security (which is eerily similar to Paul's!). The crew then got into a deep discussion of the history of many different tec...

Listen
Paul's Security Weekly (Video-Only)
Bye Bye Chrome, GhostHook, and Cisco - Paul's Security Weekly #519 from 2017-06-26T09:00

Why Firefox is superior, spies in Mexico, WannaCry shuts down a car plant, Cisco patches critical vulnerabilities, hacking air-gapped networks, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Reverse Analyzing Attacks for Detection, Justin Henderson Paul's Security Weekly #519 from 2017-06-25T09:00

Learn how to use Windows Event Logs to catch attackers in your network, including domain admin group enumeration and mimikatz attacks! Justin Henderson (@SecurityMapper) categorizes these techni...

Listen
Paul's Security Weekly (Video-Only)
Eric Conrad, SANS - Paul's Security Weekly #519 from 2017-06-24T09:00

Eric Conrad comes into the studio to talk about a groundbreaking new CTF aimed at the defenders and how to become a SANS instructor. A healthy dose of UNIX/Linux nerd talk and how to give effect...

Listen
Paul's Security Weekly (Video-Only)
Iot is broken and 1 Million Exposed Endpoints - Paul's Security Weekly #518 from 2017-06-19T16:32:12

One MILLION endpoints, WannaCry is linked to North Korea, IoT is broken (what's new?),inside a porn-pimping spam botnet, fixing Windows Defender, and more security news!

Full Show Notes: ...

Listen
Paul's Security Weekly (Video-Only)
ProxyCannon with Carrie Roberts, Black Hills Information Security - Paul's Security Weekly #518 from 2017-06-17T12:30

Carrie Roberts of Black Hills Information Security joins us to show hot to use Burp and ProxyCannon to Prevent IP blacklisting while password spraying in this technical segment!

Full Show...

Listen
Paul's Security Weekly (Video-Only)
Trey Forgety, NENA - Paul's Security Weekly #518 from 2017-06-16T19:29:18

Trey Forgety is the Director of Government Affairs and Information Security Issues at the National Emergency Number Association. He worked with the White House to develop policy for a nationwide...

Listen
Paul's Security Weekly (Video-Only)
NSA Contractor Arrested, PPT Malware - Paul's Security Weekly #517 from 2017-06-13T04:00

• FBI Arrests NSA Contractor for Leaking Secrets
• getsploit: Search & Download Exploits!
• Some non-lessons from WannaCry
• IDG Contributor Network: Top 5 InfoSec concerns for...

Listen
Paul's Security Weekly (Video-Only)
Detecting The Empire's Death Star Attack Paul's Security Weekly #517 from 2017-06-12T21:00

byt3bl33d3r recently released "DeathStar", which use Powershell Empire's API to automatically obtain Domain Admin privileges in an Active Directory environment with the Click of a button. Some m...

Listen
Paul's Security Weekly (Video-Only)
Graham Cluley - Paul's Security Weekly #517 from 2017-06-12T16:38:15

Graham Cluley is an award-winning security blogger, researcher and public speaker. In this interview, we discuss ransomware, stealing content, the motivations of attackers, IoT, and more!

Listen
Paul's Security Weekly (Video-Only)
Security For Small Business - Paul's Security Weekly #516 from 2017-06-03T09:00

Don Pezet from ITPro.TV joins us on the show to help us identify security challenges and solutions for small business/mid-market. Backups are key, as are ease of use and support. The most import...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #515 from 2017-05-31T09:00

Gravityscan is keeping WordPress sites safe, WiFi to see through walls, Dodged a bullet and stepped in front of another one, Twitter Flaw Allowed You To Tweet From Any Account, and Latest Cb Def...

Listen
Paul's Security Weekly (Video-Only)
Tech Segment: How Compromise Happens: Active Directory is Vulnerable - Paul's Security Weekly #515 from 2017-05-30T16:53:07

Almog Ohayon from Javelin Networks gives a demo on how compromises happen and counteract them.

Full Show Notes: https://wiki.security...

Listen
Paul's Security Weekly (Video-Only)
Branden Williams - Paul's Security Weekly #515 from 2017-05-27T09:00

Dr. Branden R. Williams has twenty years of experience in business, technology, and information security as a consultant, leader, and an executive. Branden has world for well known Information S...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #514 from 2017-05-22T09:00

WordPress announces a bug bounty program, stealing voice prints, hacking Mar-a-Lago, XP PCs dodge WannaCry’s ransom, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Tech Segment: Disabling SMBv1 - Paul's Security Weekly #514 from 2017-05-21T09:00

Microsoft has advised that customers disable SMBv1. This tech segment walks you through the steps required to do so on all Windows platforms, the pitfalls, and scanning for non-domain computers ...

Listen
Paul's Security Weekly (Video-Only)
Joel Scambray, NCC Group - Paul's Security Weekly #514 from 2017-05-20T09:00

Widely recognized as Co-Author of the Hacking Exposed book series, Joel has worked/consulted for companies like Foundstone (co-founder), Microsoft, Amazon, Costco, Softcard, and Ernst & Young. J...

Listen
Paul's Security Weekly (Video-Only)
Steve Lipner, SAFECode - Paul's Security Weekly #513 from 2017-05-15T15:22:19

Steve Lipner is the Executive Director of SAFECode, a non-profit organization dedicated to increasing trust in ICT products and services. He retired in 2015 as Partner Director of Software Secur...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #513 from 2017-05-13T09:00

Avast blocks the entire internet (again), over 120,000 cameras are vulnerable to a new botnet, WordPress malware, stronger authentication on government sites, and more security news!

Full...

Listen
Paul's Security Weekly (Video-Only)
Tech Segment: Roi Abutbul and Guy Franco, Javelin Networks - Paul's Security Weekly #513 from 2017-05-12T06:00

Roi Abutbul and Guy Franco of Javelin Networks explain how to protect your active directory and deceive attackers in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #512 from 2017-05-09T09:00

Phishing attacks in Google Docs, GE fixes its Smart Grid, hackers remotely control robots, and who is publishing NSA and CIA secrets (and why)?

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Tech Segment: Second Order Attacks with Ferruh Mavituna, Netsparker Paul's Security Weekly #512 from 2017-05-07T09:00

Ferruh Mavituna of Netsparker gives a demo on exploiting application vulnerabilities and second order attacks in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Javvad Malik, AlienVault - Paul's Security Weekly #512 from 2017-05-06T09:00

Javvad Malik is a Security Advocate at AlienVault, a blogger event speaker, and industry commentator. Prior to joining AlienVault, Javvad was a Senior Analyst at 451’s Enterprise Security Practi...

Listen
Paul's Security Weekly (Video-Only)
Mimi Herrmann, Taylor and Francis - Paul's Security Weekly #511 from 2017-05-02T09:00

Mimi Herrmann is a Network Security Engineer based in the Washington, D.C. area. She is also a contributing author and peer reviewer for Taylor and Francis. Mimi has been in security for more th...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #511 from 2017-04-30T09:00

Advances in ad blocking, PGP hijacking, the lack of security talent in the healthcare industry, and more security news!

Show Notes: Listen

Paul's Security Weekly (Video-Only)
Tech Segment: Staying Secure at Hacker Conferences, Part 2 - Paul's Security Weekly #511 from 2017-04-29T09:00

Back by popular demand, Paul drops more conference security knowledge in this technical segment!

Show Notes: http://wik...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #510 from 2017-04-24T09:00

Hacking SEIMs, hijacking routers, Oracle’s recent path, the FBI can finally find hackers that don’t smoke weed, and more security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Tech Segment: Staying Secure at Hacker Conferences - Paul's Security Weekly #510 from 2017-04-23T09:00

Paul gives his top 10 tips on keeping your devices safe at hacker cons in this technical segment!

Full Show Notes: http...

Listen
Paul's Security Weekly (Video-Only)
Philip Zimmerman, Silent Circle - Paul's Security Weekly #510 from 2017-04-22T09:00

Phil Zimmermann is the creator of Pretty Good Privacy (PGP), the most widely used email encryption software in the world. Phil is also a Co-Founder of Silent Circle, a provider of secure communi...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #509 from 2017-04-17T09:00

Free health apps are selling your data, SAP’s TREX exposes HANA and NetWeaver, Microsoft patches another Word bug, your phone PIN is at risk, and more in this week’s security news!

Full S...

Listen
Paul's Security Weekly (Video-Only)
Tech Segment: Basics of Abusing WMI Events - Paul's Security Weekly #509 from 2017-04-16T09:00

Our very own Carlos Perez demonstrates the basics of WMI events and how to abuse them in this technical segment!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode509<...

Listen
Paul's Security Weekly (Video-Only)
Alex Horan, Onapsis - Paul's Security Weekly #509 from 2017-04-15T09:00

We welcome Alex Horan back to the show! Alex is the Director of Product Management at Onapsis. He has experience in startup-based project management, meeting with customers, prospects, and analy...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #508 from 2017-04-09T09:00

Android ransomware bypasses all AV programs, McAfee gets a fresh start, the CIA and WikiLeaks saga continues, and Wi-Fi sex toys are vulnerable (again) in this week’s Security News!

Full ...

Listen
Paul's Security Weekly (Video-Only)
Tech Segment: Jeff's Trip to IBM InterConnect - Paul's Security Weekly #508 from 2017-04-08T09:00

Our very own Jeff Man made a trip to the IBM InterConnect Conference on behalf of Security Weekly. Learn about his experience in this segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Anna Manley, Manley Law Inc. - Paul's Security Weekly #508 from 2017-04-07T15:59:42

Anna Manley is an internet and privacy lawyer based in Nova Scotia, Canada. She is the principal of Manley Law Inc. and founder of Advocate Cognitive Technologies Inc. She also writes a blog cov...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #507 from 2017-04-02T09:00

The CIA hacks Cisco, Trump extends an executive order on cybersecurity, ISP privacy rules are being repealed, and why was 2016 a record year for vulnerabilities?

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Technical Segment: Blocking Ads and Malware With Pi-hole In The Cloud - Paul's Security Weekly #507 from 2017-04-01T09:00

Paul shows you how to use Raspberry Pi’s Pi-hole to block ads and malware in the cloud in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Brad Antoniewicz, OpenDNS/BSides NYC - Paul's Security Weekly #507 from 2017-03-31T16:49:25

Brad Antoniewicz works in Cisco Umbrella’s security research group. He founded the NYC branch of Security BSides. Brad is also a contributing author to both the Hacking Exposed and Hacking Expos...

Listen
Paul's Security Weekly (Video-Only)
Tech Segment: Arlo Wireless Camera System Security - Paul's Security Weekly #506 from 2017-03-26T09:00

Paul lists the pros and cons of using Arlo wireless cameras to secure your home in this technical segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Tech Segment: Secure Online Backups, Don Pezet, ITProTV - Paul's Security Weekly #506 from 2017-03-25T09:00

Online backups are a double-edged sword. They provide fast, easy backups with inexpensive storage; however, by being online, they are able to be targeted by attackers. Don Pezet of ITPro.TV show...

Listen
Paul's Security Weekly (Video-Only)
Ferruh Mavituna, NetSparker - Paul's Security Weekly #506 from 2017-03-24T16:26:50

Ferruh Mavituna is the Founder and Product Manager of Netsparker. He developed the first and only proof-based web security scanner with vulnerability detection and exploitation features. Ferruh ...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #505 from 2017-03-19T09:00

The origin of threat hunting, your microwave is spying on you, 10 must-read books for infosec professionals, and why is IR automation and orchestration so hot?

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Brad Haines (a.k.a. Render Man) on Internet of Dongs - Paul's Security Weekly #505 from 2017-03-18T09:00

Brad Haines (aka Render Man) is security enthusiast with a focus on security threats of all sorts. He is the person your sysadmin warned you about. Brad spearheads the Internet of Dongs Project,...

Listen
Paul's Security Weekly (Video-Only)
Andrew Whitaker, Rapid7 - Paul's Security Weekly #505 from 2017-03-17T18:14:39

Andrew Whitaker is the Director of Global Services at Rapid7. He leads Rapid7’s penetration testing services that help organizations around the world gain insight into real-world risk and remedi...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #504 from 2017-03-12T10:00

Lots of news involving the CIA, Firefox 52 expands non-secure HTTP warnings, WiFi cameras are insecure, email is safer in Office 365, and who is joining the IoT Cybersecurity Alliance?

Fu...

Listen
Paul's Security Weekly (Video-Only)
Keith Hoodlet, InfoSec Mentor Project - Paul's Security Weekly #504 from 2017-03-11T10:00

Keith Hoodlet works as an Engineer on the Customer Success team at Rapid7. He is currently rebooting the InfoSec Mentors Project, providing a platform for finding and connecting mentors and ment...

Listen
Paul's Security Weekly (Video-Only)
Hyrum Anderson, Endgame - Paul's Security Weekly #504 from 2017-03-10T19:36:55

Hyrum Anderson is the Technical Director for Data Science at Endgame. He received his PhD in Electrical Engineering from the University of Washington and BS/MS degrees from Brigham Young Univers...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #503 from 2017-03-05T10:00

The risks of using an Android password manager, another WordPress plugin is flawed, hidden backdoors, Cloudbleed gets triggered, and more in this week’s security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Incident Response & Forensic Reporting, Doug White - Paul's Security Weekly #503 from 2017-03-04T10:00

Our very own Doug White delivers a demonstration/rant about incident response and forensic reporting in this week’s technical segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Alan White, Dell SecureWorks/US Army - Paul's Security Weekly #503 from 2017-03-03T19:41:43

Alan White is the Global Regions Consulting and Services Director for Dell SecureWorks, and is part of the US Army's Computer Emergency Research Team. Previously, Alan was the Director of Securi...

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #502 from 2017-02-26T10:00

Lawmakers prepare to overturn broadband privacy rules, Windows vulnerabilities await patches, new security technologies debut at RSA, and are Slack conversations really private?

Full Show...

Listen
Paul's Security Weekly (Video-Only)
Tech Segment: David Fletcher, Symantec - Paul's Security Weekly #502 from 2017-02-25T10:00

This webcast, driven by John Strand, brings together some of Black Hills Information Security’s best to discuss antivirus. David Fletcher shows us how to bypass Symantec in this technical segmen...

Listen
Paul's Security Weekly (Video-Only)
Don Pezet, ItPro.TV - Paul's Security Weekly #502 from 2017-02-24T18:56:53

Don Pezet is no stranger to the Security Weekly network! In this episode, Don chats with Paul, Doug, Jeff, Joff, and Carlos about tactics, laws, and problems related to incident response.

Listen
Paul's Security Weekly (Video-Only)
Security News - Paul's Security Weekly #501 from 2017-02-19T10:00

Drive-by exploits are about to become much worse, how to use Scuba to run a database vulnerability scan, more Patch Tuesday delays, and why is it that the more infosec changes, the more it stays...

Listen
Paul's Security Weekly (Video-Only)
Slipping Executables Past Firewall, Carrie Roberts - Paul's Security Weekly #501 from 2017-02-18T10:00

Carrie Roberts joined Black Hills InfoSec after working for HP's Global Cyber Security group, where she worked as a network penetration tester.

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #500 - Round Table: Penetration Testing pt. 2 from 2017-02-12T10:00

Paul has trapped everyone in a blizzard at G-Unit Studios in Rhode Island! They must talk about penetration testing or they will be penetra...well, never mind. Watch this segment to hear our pan...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #500 - Round Table: IoT Security pt. 1 from 2017-02-11T10:00

Paul and crew kick off the episode 500 festivities by hosting a roundtable discussion on the current state and future of IoT security!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #499 - Security News from 2017-02-06T10:00

A patchwork quilt of IoT security, President Trump’s cyber executive order, how Google fought a botnet (and won), and why didn’t WordPress tell us about their recent zero-day?

Full Show N...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #499 - Nathaniel "Q" Quist, LogRhythm from 2017-02-04T10:00

Nathaniel “Q” Quist is an Incident Response Engineer at LogRhythm Labs. Q is actively focused on Active Defense countermeasures and methods to increase the defensive capabilities of various orga...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #499 - Katherine Teitler, MISTI from 2017-02-03T18:18:34

Katherine Teitler is the Director of Content for MISTI, where she is responsible for programming information security conferences, workshops, and summits. Previously, she served as Director of C...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #498 - Security News from 2017-01-29T10:00

President Trump is tweeting from an insecure phone, Asus gives Raspberry Pi a run for its money, how to use your heartbeat as a password, and can you revive an old laptop with a free OS?

...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #498 - Tech Segment: Jeff's HP Adventures from 2017-01-28T10:00

Our very own Jeff Man attended HP Print Security Tech Day at HP’s headquarters in Palo Alto, California. He documents his experience at HP and how their business model influences printer securit...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #498 - Chris Kubecka, HypaSec from 2017-01-27T19:03:58

Chris Kubecka is an experienced and certified IT security expert. In addition to curating the popular Security Evangelist blog, she also serves as a member of the Executive Steering Committee wi...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #497 - Security News from 2017-01-22T10:00

We discuss Chelsea Manning’s commutation, Guccifer 2.0 resurfacing, the identity of the Mirai botnet creator, and more in this week’s security news!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #497 - Bruce Potter, ShmooCon from 2017-01-21T10:00

Bruce Potter is the Founder and an organizer of ShmooCon, a long-running, yearly hacker convention in Washington, D.C. He also serves as the CTO of KeyW Corporation and Ponte Technologies. Bruce...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #497 - Jason Blanchard, SANS Institute from 2017-01-20T18:56:23

Jason Blanchard is the Curriculum Marketing Manager of Penetration Testing for the SANS Institute. In addition to speaking at conventions like DerbyCon and BSides Orlando, he has served as the S...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #496 - Security News from 2017-01-16T10:00

The Trump Administration urges more coordination on cyberthreats, more raw intelligence data sharing permissions for the NSA, and why are the feds suing D-Link?

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #496 - Tech Segment: Bypassing AV on Android, Beau Bullock from 2017-01-14T10:00

Beau Bullock shows us how to bypassing antivirus software using Android in this week’s tech segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #496 - Lesley Carhart, Motorola Solutions/US Air Force Reserve from 2017-01-13T10:00

Lesley Carhart (@hacks4pancakes) is a veteran security incident responder and digital forensics analyst. Programming since the age of 7, she forged her name in the industry by working with organ...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #495 - Security News from 2017-01-08T10:00

MongoDB databases are under attack, info on buying internal domain access, smart meters are vulnerable, and why is a Florida man suing Verizon?

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #495 - Forensic Toolkit (FTK), Doug White from 2017-01-07T10:00

Doug White of Secure Technology provides a demo on forensic data carving using FTK on this tech segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #495 - Joe McCray, Strategic Security from 2017-01-06T17:51:27

Joe has an extensive background in computer security, pen testing, and system administration. He founded Strategic Security in 2010 with the vision of providing in-depth technical assessments of...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #494 - Security News from 2016-12-26T10:00

Nokia sues Apple, home routers are under attack, a Russian botnet is stealing millions of dollars per day, and should you give up on PGP? Find out in this week’s security news!

Full Show ...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #494 - Tech Segment: Rudolph the Credit Card-Swiping Reindeer from 2016-12-25T10:00

How do you find credit card numbers that have slipped out of the Cardholder Data Environment? Joshua Marpet and Scott Lyons show you how in this week’s tech segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #494 - Eric "Munin" Rand, Brown Hat Security from 2016-12-24T10:00

Munin is a professional blue-team consultant from Southern California who spends his days providing technical support to defensive security operations folks, finding a way to turn paranoia into ...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #493 - Security News from 2016-12-18T10:00

Austalia's tax office loses a petabyte (yes, a petabyte) of data, why it's time for organizations to start automating security, and could the news be any worse for Yahoo? All that and more in th...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #493 - Tech Segment: I Made The Switch to a Linux Laptop from 2016-12-17T10:00

Paul has been known by many as an Apple fanboy for a long time. What convinced him to ditch his Macbook for a Linux laptop? Find out in this week's tech segment!

Full Show Notes: Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #493 - Dave Shackleford, Voodoo Security and SANS from 2016-12-16T18:28:41

Dave is the Founder of Voodoo Security, a company that provides information security consulting services to clients, specializing in virtualization and cloud security. Dave also serves as a Seni...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #492 - Security News from 2016-12-11T10:00

Old Linux and BSD code is vulnerable, your worst fears about IoT security are probably true, SSL-protected web sites, security for small businesses, and the hacking doomsday. All that and more i...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #492 - Ofri Ziv, GuardiCore from 2016-12-10T10:30

Ofri leads the Detection Development group at GuardiCore, which is responsible for security research, detection, and development of data analysis algorithms. Ofri educates us on the Oracle of De...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #492 - Ferruh Mavituna, Netsparker from 2016-12-09T18:07:47

Ferruh is certainly no stranger to the show! Paul, Larry, and Joff chat with Ferruh about web applications, mobile security, and updates on his journey at Netsparker on Paul’s Security Weekly! Listen

Paul's Security Weekly (Video-Only)
Paul's Security Weekly #491 - Security News from 2016-12-04T10:00

A new Mirai worm knocks almost a million Germans offline, time is running out for NTP, the propaganda about Russian propaganda, and who hacked the lights in Ukraine? All that and more in this we...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #491 - Tech Segment: Containerizing your Security Operations Center from 2016-12-03T10:00

Jimmy is the chapter leader of OWASP Santa Barbara and co-organizer of the AppSec California security conference. He has spent time on both the offense and defense side of the industry. Jimmy br...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #491 - John Hurd and Alex Valdivia, ThreatConnect from 2016-12-02T18:49:08

Two ThreatConnect personnel join us: John currently serves as a Threat Intelligence Research Analyst, while Alex is the Senior Threat Intelligence Research Engineer. They discuss their experienc...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #490 - Security News from 2016-11-20T10:00

Experts encourage congress to act on IoT security, wifi can imprint passwords on pins on radio signals, major Russian banks are hacked with powerful IoT devices focused Botnets, meet poison tap ...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #490 - Tech Segment: Alex Horan and Sebastian Bortnik, Onapsis from 2016-11-19T10:00

Alex Horan and Sebastian Bortnik will be discuss what Onapsis has updated in their company and software in the year. They discuss the trends they've seen in the past year (DHS CERT, SANS SAP rep...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #490 - Jen Ellis and Harley Geiger, Rapid7 from 2016-11-18T18:45:04

Jen Ellis is the VP Community & Public Affairs at Rapid 7 and Harley Geiger is the Director of Public Policy at Rapid 7. Jen Ellis wors with security researchers & policy makers to improve publi...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #489 - Security News from 2016-11-13T10:00

Regulation of the Internet of Things, Packet Capture Options, Hackers hijack Philips Hue lights with a drone, Facebook buys black market passwords for user account safety, and much more here on ...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #489 - Tech Segment: Outlook Web Access Two-Factor Authentication Bypass from 2016-11-12T10:00

A design weakness has been exposed that can allow an attacker to easily bypass 2FA and access an organization’s email inboxes, calendars, contacts and more.

See more at: Outlook Web Acces...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #489 - Greg Foss, Logrhythm from 2016-11-11T18:17:58

Greg Foss is LogRhythm’s Head of Global Security Operations, where he is tasked with leading both offensive and defensive aspects of corporate security.

Full Show Notes: http://wiki.secur...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #488 - Security News from 2016-11-06T09:00

Can the election be affected by attackers on the internet, can IoT devices suffer anymore security vulnerabilities, Microsoft announces the end of life for EMET, and much more, here on Paul's Se...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #488 - Tech Segment: Considerations for Using Intel SGX from 2016-11-05T09:00

Intel SGX is a newer method of implementing trusted computing. Jack and Paul talk about SGX and discuss its pros and cons.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/E...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #488 - David Koplovitz, ProXPN from 2016-11-04T16:54:34

Over twenty years of experience in corporate leadership and management. Developed agile products, created solutions, integrated systems and deployed technologies for both external and internal c...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #487 - Security News from 2016-10-30T09:00

Webcams used to attack Twitter and reddit will be recalled according to a Chinese manufacturer, a Windows 10 vulnerability called Atom Bombing, dirty cow, and much more here on Paul's Security W...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #487 - Tech Segment: Why Signatures Suck with Mark Dufresne, Endgame from 2016-10-29T09:00

Why signatures don’t really work for detection and about what folks should be thinking about instead.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode487#Technical_S...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #487 - Chris Roberts, Acalvio Technologies from 2016-10-28T16:14:15

Chris Roberts is considered one of the world’s foremost experts on counter threat intelligence within the Information security industry. At Acalvio, Chris helps drive Technology Innovation and P...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #486 - Security News from 2016-10-23T09:00

Donald Trump is running an insecure email server, Mirai bots more than double since source code release, Skyping and typing has some issues, IoT needs to learn from your Mitre Saw, and much more...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #486 - Listener Feedback: Fixing Pen Test Findings and XMLRPC from 2016-10-22T09:00

XMLRPC for the win or not? How long should you re-mediate vulnerabilities found in penetration test reports?

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode486#List...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #486 - Adrien de Beaupre from 2016-10-21T17:00:18

So do you really want to be a penetration tester? We get these questions all the time, and Adrien does too!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode486#Inter...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #485 - Security News from 2016-10-16T09:00

Disappearing messages added to signal app, IoT devices as proxies for Cybercrime, nuclear power plant disrupted by cyber attack, and more, here on Security Weekly!

Full Show Notes: http:/...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #485 - Scott Lyons and Joshua Marpet, Guarded Risk from 2016-10-15T09:00

Scott Lyons is the V.P. of Business Development for WarCollar. Joshua Marpet is a well known Security Researcher and speaker.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.ph...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #485 - Listener Feedback, Drinking From The InfoSec Fire Hose from 2016-10-14T17:56:13

Questions from the Security Weekly listeners are answered during this segment.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode485#Listener_Feedback:_Drinking_From_T...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #484 - Tech Segment: Pre-exploit Preventing from 2016-10-09T09:00

Cody Pierce from Endgame will be giving a 15 minute segment on Pre-exploit Preventing.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode484#Tech_Segment:_Pre-exploit_...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #484 - Security News from 2016-10-08T09:00

Security news will discuss Yahoo! spying, Mirai source code lessons learned, I will try my best, but fail, at not saying "I told you so!", and more!

Full Show Notes: http://wiki.securityw...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #484 - Ed Skoudis from 2016-10-07T16:23:18

Ed Skoudis of Counterhack Challenges and The SANS Institute. Ed will discuss IoT security, the Holiday Hack Challenge and upcoming SANS Hackfest conference.

Full Show Notes: http://wiki.s...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #483 - Listener Feedback: Old vs New from 2016-10-02T09:00

Give us your questions and feedback and send it to psw@securityweekly.com and we'll put it on the show!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode483#Listener_...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #483 - Interview Ferruh Mavituna, Netsparker from 2016-10-01T09:00

Ferruh Mavituna from Netsparker. He's been Hacking web apps since 2003, web app sec expert, and the CEO of Netsparker.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episo...

Listen
Paul's Security Weekly (Video-Only)
Paul's Security Weekly #483 - Security News from 2016-09-30T17:51:24

Yahoo is breached, open SSL has a bug, Raspberry Pi new Pixel update, thousands of Cisco devices still vulnerable, and stick around for Jack's rant! Here on Security News!

Full Show Notes...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #446 - Interview With Adrien de Beaupre from 2016-09-29T19:26:24

Security Weekly Web Site: http://securityweekly.com

Hack Naked Gear: http://shop.securityweekly.com

Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode446

Foll...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #482 - Security News from 2016-09-25T09:00

Alibaba fires employees for hacking their way to free mooncakes, How I gained access to TMobile’s national network for free, Employees download new malware every four seconds, all that and more ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #482 - Tech Segment: Securing a Shell Script from 2016-09-24T09:00

Paul explains how to try to make a secure shell script, along with introducing DisplayGoat!

Full Show Notes: https://github.com/pasadoorian/displaygoat/blob/master/displaygoat.sh

S...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #482 - Kobi and Doron Naim, Cyberark Labs from 2016-09-23T16:13:27

Kobi Ben-Naim Senior Director of Cyber Research Kobi is an accomplished information security professional, well-known for his pioneering work in the field of Advanced Persistent Threats (APTs) a...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #481 - Security News from 2016-09-17T09:00

Privacy and Internet connected vibrators. Volkswagon launches a new cyber security firm to tackle car security, Ad Block Plus ridiculousness, and hacking cable modems. All that and more, so stay...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #481 - Josh Abraham, Praetorian from 2016-09-16T18:24:33

At Praetorian, Josh is a key member of the technical execution team. In this capacity, he is responsible for leading, directing, and executing client-facing engagements that include Praetorian's...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #480 - Security News from 2016-09-11T09:00

DHS urges vigilance in protecting networking gear, How spoofing an ethernet adapter lets you sniff PC credentials, and FAA considers a ban on Samsung's exploding smartphones. All that and more, ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #480 - Tech Segment: ODROID C2 vs. Raspberry PI 3 from 2016-09-10T09:00

Which hardware is best for your next nerdy security (or non-security) project? The Security Weekly crew will discuss the differences between two of the new model embedded Linux boards on the mar...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #480 - Marcus J. Ranum, Tenable Inc. from 2016-09-09T18:24:13

Marcus J. Ranum works for Tenable Security, Inc. and is a world-renowned expert on security system design and implementation. He has been involved in every level of the security industry from pr...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #479 - Security News from 2016-09-04T09:00

A new take on Windows 10, One million IoT devices infected by Bashlite malware-driven DDoS botnet, Encryption Technology Causes More Cyber Attacks? All that and more, so stay tuned!

Full ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #479 - Listener Feedback: Magic Wiffle Dust from 2016-09-03T09:00

Data security either on premise or in the cloud and the merits of each.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode479#Listener_Feedback:_Magic_Wiffle_Dust_-_6:...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #479 - Josh Corman, Cyber Statecraft Initiative from 2016-09-02T18:55:48

Joshua Corman is Director of the Cyber Statecraft Initiative for the Atlantic Council. He co-founded @RuggedSoftware and @IamTheCavalry to encourage new security approaches in response to increa...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #478 - Heather Mahalik, SANS from 2016-08-30T09:00

Heather Mahalik is leading the forensic effort as a Principal Forensic Scientist for ManTech CARD.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode478#Interview:_Hea...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #478 - Security News from 2016-08-29T18:06:16

Facial recognition, VxWorks, Leaked Shadowbrokers, Bitcoin, and much more on Security Weekly!

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode478#Security_News_-_6:3...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #478 - Listener Feedback, A Host's Perspective from 2016-08-26T20:09:36

Listener feedback segment will be The Host's Perspective, common questions we've asked our guests will be answered by some of the hosts!

Full Show Notes: http://wiki.securityweekly.com/wi...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #477 - Interview with Alex Horan, Onapsis from 2016-08-21T09:00

Alex Horan from Onapsis joins us. Alex is a security focused IT professional with strong experience leading and motivating IT teams and departments.

Full Show Notes: http://wiki.securityw...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #477 - Listener Feedback from 2016-08-20T09:00

To Be or Not to be A Contractor. A listener of Security Weekly asks Paul and his crew.

Full Show Notes: http://wiki.securityweekly.com/wiki/index.php/Episode477#Listener_Feedback:_To_Be_o...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #477 - Security News from 2016-08-19T18:49:12

Snowden Thinks Russia Hacked The NSA, How to disable WPAD on Windows so hackers can't hijack your computer, and People Ignore Security Alerts Up To 90% Of The Time. All that and more, so stay Tu...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #476 - Security News from 2016-08-14T09:00

Paul, Larry, Joff and Lance discuss the news for the week on Frequent Password Changes Is a Bad Security Idea, Facebook’s favorite hacker is back, Linux malware? That'll never happen, and much m...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #476 - Tech Segment, TachyonNet from 2016-08-13T09:00

TachyonNet is a multi-threaded Python tool that has the ability to listen on all 65535 TCP/UDP ports, as well as listen for ICMP traffic.

Full Show Notes: http://wiki.securityweekly.com/w...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #476 - Lance James, Flashpoint from 2016-08-12T16:48:47

Lance James serves as Chief Scientist at Flashpoint where he heads up research and engages in thought leadership. Prior to joining Flashpoint, Mr. James was the Head of Cyber Intelligence at Del...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #475 - Security News from 2016-07-31T09:00

This week we talk about Verizon buying Yahoo, Ransomware, Zero Day holes in Lastpass, hackers can sniff your keystrokes from nearby, and vulnerabilities and light bulbs. Stay tuned!

Subsc...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #475 - Listener Feedback from 2016-07-30T09:00

We discuss about Jeff, a current listener of Security Weekly, how to maintain working full time in security and having children, getting married, and balancing everything out equally.

Sub...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #475 - Federico Kirschbaum from 2016-07-29T17:40:22

Federico Kirschbaum is currently the CTO of Infobyte Security Research, company based in Buenos Aires, Argentina. With more than 10 years of experience researching and pentesting networks, he ha...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #474 - John Kindervag from 2016-07-24T09:00

John Kindervag is a Principal Analyst on the Security and Risk Management team and works out of the Dallas Research Center. John covers various topics in Information Security including PCI Data ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #474 - Tech Segment: Bluetooth Scanning Using The PwnPad 4 & Blue Hydra from 2016-07-23T09:00

While many are focused on securing the network, it could be the devices within your location, not even on the network, that cause security issues. In this segment we talk about a new, open-sourc...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #474 - Security News from 2016-07-22T17:45:35

This week Paul tells how to cheat in Pokemon Go, everything you need to know about webshells, Mr. Robot easter eggs, and much more! Here on Security News!

Full Show Notes:  http://wiki.se...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #473 - Security News from 2016-07-17T09:00

This week on Security News, Paul talks about Pokemon Go, Kaspersky Labs, FBI Malware, Kim Dotcom Plans for 2017, and much more!

Full Show Notes: http://wiki.securityweekly.com/wiki/index....

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #473 - Bob Stratton, Mach37 from 2016-07-16T09:00

This week, we welcome Bob Stratton! He is a General Partner at Mach37, a startup accelerator investing in information security product companies. Bob is a “repeat offender” with security startup...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #473 - Tech Segment: DNS Blackhole Server with Python from 2016-07-15T18:58:58

Joff will write a Python script that can download malware domain name lists from a URL, and create a DNS blackhole bind9 based configuration file on the domain names obtained.

Full Show N...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #472 - Security News from 2016-07-11T09:00

This week on Security News, Paul, and Jack talk about how Sony, Microsoft, and other gadget makers violate Federal Warranty Laws, Pen Test Partners, FBI, warrant Canarys, and much more! Here on ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #472 - Tech Segment: Blocking Ads and Malware Using Bind DNS from 2016-07-10T09:00

Ads are annoying, malware is bad. pfSense wanted to be Paul's DNS server in order to block host names. Paul built his own DNS and DHCP servers. This is how he did it.

Full Show Notes: htt...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #472 - Elizabeth Gossell from 2016-07-09T09:00

Paul talks with Elizabeth Gossell who is a Product Strategist at Tenable with a solid background in network security at both Lockheed Martin and Tenable. All that and more, so stay tuned!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #471 - Security News from 2016-07-03T09:00

This week Paul talks about sharing threat intelligence, Facebook using physical location to suggest friends, interview with an NSA hacker, and much more! So stay tuned!

Full Show Notes: h...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #471 - Tech Segment: Building A PfSense Firewall - Part 1 - The Hardware from 2016-07-02T09:00

For your home or small office, everyone needs a firewall! Well, I supposed you don't NEED one, but it helps. More important than just protecting you from curious people on the Internet, there ar...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #471 - Interview with Mark Baggett, SANS from 2016-07-01T19:29:52

Mark has more than 28 years of commercial and government experience ranging from Software Developer to CISO. All that and more, so stay tuned!

Full Show Notes: http://wiki.securityweekly....

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #470 - Security News from 2016-06-26T09:00

The security news is flooded this week! Paul talks about ASUS UEFI update driver, Verizon patches serious email flaw, and Tor coders harden the Onion against surveillance. All that and more, so ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #470 - Rick Farina, Pwn Pad 4 from 2016-06-25T09:00

This segment is an interview with Rick Farina, who is an expert in the new Pwn Pad 4. He explains all it's features and perks. Paul will show off the one on set and tell you how you can win a Pw...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #470 - Interview with Cory Doctorow from 2016-06-24T18:17:26

This week on Security Weekly, Paul, Larry, and Jack Daniel host the interview with none other than Cory Doctorow. Cory Doctorow (craphound.com) is a science fiction author, activist, journalist ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #469 - Tech Segment: Telepresence Robot from 2016-06-19T09:00

The model robot featured in this segment is called a Double Generation One. This Telepresence robot consists of a telescoping rod connecting a Segway like base and an iPad Air 2 head.

Ful...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #469 - Security News from 2016-06-17T18:01:36

This week is a special segment where Paul, Jeff, Doug, and Russell talk about WordPress Patches Zero Day, Hack The Pentagon Shutters 100 Bugs, GitHub, and much more!

Full Show Notes: http...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #468 - Chris Poulin, X-Force from 2016-06-12T09:00

Security Weekly has a special co-host, Russell Beauchemin who will be in studio with Larry and our guest Chris Poulin.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #468 - Security News from 2016-06-11T09:00

Larry is on the show with Russell and Chris, and they discuss Security News for the week! They talk about Typo squatting package managers, 20 years of red teaming, Spear Phishing, Infosec is a s...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #468 - Russell Beauchemin, Hololens from 2016-06-10T09:00

We have a special co-host on the show, Russell Beauchemin, IT Instructor II at Year Up. Larry will discuss with Russell about his new Hololens!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #467 - Security News from 2016-06-05T09:00

Security news this week will uncover password breaches galore, Facebook listening to your conversations. Also, congrats! You got a new laptop! And a boatload of vulnerabilities out of the box!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #467 - Listener Feedback, Crypto from 2016-06-04T09:00

In this listener feedback segment, we will answer the question "should you implement your own Crypto?"

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #467 - Jon Searles and Will Genovese, BSides Security from 2016-06-03T20:09:25

This week we interview Jon Searles and Will Genovese, the founders of the NESIT hacker space and organizers of Bsides Connecticut.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #466 - Listener Feedback from 2016-06-02T23:00

This week on Security Weekly, we answer more of your questions! Paul, Jack, Jeff, and Larry answer the listeners feedback, here on Security Weekly!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #466 - Wade Baker from 2016-06-02T23:00

Wade Baker is the Vice President, Strategy and Risk Analytics at ThreatConnect. He believes improving information security starts with improving security information. In keeping with this belief...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #455 - Interview with Dennis Fisher from 2016-06-02T15:48:18

Paul, Larry, and Jack talk with Dennis Fisher from Pindrop and On the Wire. Dennis expalins what are some of the more interesting trends in security news and how to overcome major problems in hi...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #459 - Technical Segment Apollo Clark from 2016-06-02T15:22:07

This Tech Segment is presented by Apollo Clark. He gives tips on teaching material, the VPN, researching, and self-training. Stay alive for more on Security Weekly!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #459 - Stories of the Week from 2016-06-02T15:21:19

This Tech Segment is presented by Apollo Clark. He gives tips on teaching material, the VPN, researching, and self-training. Stay alive for more on Security Weekly!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #459 - Interview with James Lyne from 2016-06-02T15:20:31

We interview James Lyne from SANS. He comes from a background in cryptography but over the years has worked in a wide variety of security problem domains including anti-malware and hacking. Jame...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #458 - Stories of the Week from 2016-06-02T15:18:59

This week on Stories of the week Paul and Jack Daniels, talk about Live Journal Hit with Angler exploit kit, and FBI investigates hacks against U.S. law firm. They talk about a lot more. Stay tu...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #458 - Interview with Alex Horan from 2016-06-02T15:17:25

This week we talk with Alex Horan from Onapsis. He is a security focused IT professional with strong experience leading and motivating IT teams and departments.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #452 - Security News from 2016-06-02T15:14:33

Carlos, Michael, Joff, NotKevin, Jack and Paul talk about the government order to weaken 5c security, the glibc bug, shiny new instagram 2FA, and a whole lot more!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #452 - DIY Routers with Joff from 2016-06-02T15:12:48

This week Joff talks with Larry, Carlos, Michael and Paul about building DIY linux-based routers.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #451 - Stories of the Week from 2016-06-02T15:11:39

This week on Security Weekly, we hear Joff's Hacker Haiku. They discuss D-Link, ASUS Router Administration, Weird Fitbit data, and more! Watch for the latest scoop.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #450 - Interview with Patrick Heim, Dropbox Head of Security from 2016-06-02T15:09:55

This week on Security Weekly, we interview Patrick Heim who is the Dropbox Head of Security. Listen in as we dive deep into the intricacy of Dropbox.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #449 - Interview with Essobi from 2016-06-02T15:06:53

On this episode, we talk about scanning the internet, android vulnerabilities, mini UPNPD vulnerabilities, hackers and heroine to Brian Krebs. Much much more, on Paul's Security Weekly!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #447 - Stories Of The Week from 2016-06-02T15:03:34

This week Carlos, Jack, Michael, Joff, Paul and Larry talk about Windows updates, Sean Penn, WordPress XSS, Windows compatibility issues, TrendMicro's node.js password manager (now featuring arb...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #457 - Tech Segment from 2016-06-02T15:02:13

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #456 - Stories of the Week from 2016-06-02T15:00:08

Paul, Larry, Jeff, Joff and NotKevin talk about remote sex toys! Control your toys through phones or tablets. These devices getting hacked and Vulnerability Scanners Turn Up Mostly False Positiv...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #456 - Interview with Jared Atkinson from 2016-06-02T14:58:41

This week on Security Weekly, we talk with Jared Atkinson, who is the Hunt Capability Lead with Veris Group's Adaptive. Passionate about PowerShell and the Open Source community, Jared is the le...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #455 - Stories of the Week from 2016-06-02T14:56:53

Paul and the gang talk about the Erin Andrews, Big news, why your security tools are exposing you to added risks, patch management, and much much more! Stay tuned into Security Weekly Stories of...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #454 - Stories of the Week from 2016-06-02T14:55:23

Stories of the week include DROWN, cool tools for analyzing firmware and Z-Wave, and much more!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #454 - Paul's Big News and Interview w/ Inguardians from 2016-06-02T14:53:53

This week Paul makes a big announcement! We are lucky to have several of the fine folks at Inguardians come on the show and share their wisdom and knowledge on the topic of perimeter protection....

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #453 - Stories of the Week from 2016-06-02T14:52:11

On Security Weekly, Paul, Larry, and Mike talk about the Hacker Summer Camp Planning Guide, Open DNS Blogs, wireless mics and keyboards, and excessive amounts of lube! The best place to get info...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #453 - Interview with Jeff Frisk and Jeff Pike from 2016-06-02T14:49:45

This week on Security Weekly we interview
Jeff Pike and Jeff Frisk from SANS GIAC. Paul and Larry talk about 'digital badges', CPEs, and SANS training. Watch the whole
episode for mo...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #446 - Stories Of The Week from 2016-06-02T14:46:15

"This week Paul, Larry, John, Joff and special guest star Adrien talk about Juniper backdoors, the "biggest" security threats for 2016, axing Internet Explorer and Uber fines for data breaches"<...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #447 - Interview with Chris Domas from 2016-06-02T14:41:07

This week we interview Chris Domas. Chris is a researcher interested in reverse engineering and exploitation. He joins us to talk about visualizing binaries, accessing ring -2 and making reverse...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #445 - Sharon Goldberg from 2016-06-02T14:40:10

Sharon Goldberg joins us to talk about her research into NTP, BGP and DNS protocol security. Sharon has deep knowledge of these protocols, networking and crypto and I promise you are going to lo...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #445 - Security News from 2016-06-02T14:37:55

Paul, Joff and Not Kevin talk about registering zones, reply to all, CISA and much more!

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #466 - Security News from 2016-05-27T09:00

Paul discusses on this Security News segment, Jeremiah Grossman, Apple hires crypto-wizard Jon Callas to beef up security, Google To Kill Passwords On Android, and a ton more from our other gues...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #450 - Security News from 2016-02-11T17:00

Tons of stories and Jack rants about DNS.

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #444 - Stories of the Week from 2015-12-21T17:00

This week we talk about the quest to reveal the identity of Bitcoin's creator, DDoS attacks against the internet's root name servers, and a whole lot more!

Security Weekly Web Site:...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #444 - Ed Skoudis Holiday Hack Challenge from 2015-12-15T17:00

Ed Skoudis joins us via Skype to talk about the all new 2015 Holiday Hack Challenge! Ed also answers the all new 5 Questions, not to be missed!

Security Weekly Web Site: http://securitywe...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #444 - Pen Testing 5 Questions with John Strand from 2015-12-12T17:00

John Strand answers Paul's 5 tough questions on penetration testing. With Larry Pesce and Jeff Man.

Security Weekly Web Site: http://securityweekly.com

Hack Naked Gear: http://shop...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #443 - Security News from 2015-12-08T10:00

The Security Weekly crew discusses software security, how to create more secure code, legacy code, IoT devices and more!

Security Weekly Web Site: http://securityweekly.com

Follow ...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #443 - Interview with Micah Zenko from 2015-12-07T10:00

Micah Zenko, a senior fellow at the Council on Foreign Relations and author of the new book "Red Team: How to Succeed By Thinking Like the Enemy." We talk to Micah about techniques to prevent do...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly News #442 - Failed Windows 3.1 and Hacking Back from 2015-11-20T10:00

Security news this week we talk about the latest iThing, this one brews your coffee. Find out why its a bad idea to run Windows 3.1 in your environment, or Windows NT. Paul goes back in time, ta...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #442 - Interview with Ferruh Mavituna from 2015-11-19T10:00

Security Weekly brings back Ferruh Mavituna to discuss SLDC and writing vulnerable command injection in PHP. For a full list of topics discussed, visit our wiki: http://wiki.securityweekly.com/w...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly News #441 - IoT Security In Alarm Clocks from 2015-11-12T17:00

Security news this week features the unmasking of TOR users, an alarm clock that slaps you around and more. For a full list of stories, visit our wiki: http://wiki.securityweekly.com/wiki/index....

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #441 - Interview with Miron Livny and Barton Miller from 2015-11-12T17:00

This week, we interview Miron Livny and Barton Miller of SWAMP. SWAMP simultaneously alleviates the costs, maintenance and licensing burdens of tools, while also eliminating the need to learn nu...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #440 - Interview with Michael Bazzell from 2015-11-05T17:00

This week we interview Michael Bazzell author of "Open Source Intelligence Techniques", "Hiding from the Internet" and the technical advisor for TV hacker drama "Mr. Robot" on the USA network. Listen

Paul's Security Weekly (Video-Only)
Security Weekly #440 - Canadian Encryption from 2015-11-05T10:00

This week, Paul and the crew discusses the million dollar bug bounty for iPhones and why it may be legal to hack your car. For a full list of stories talked about during the show, visit our wiki...

Listen
Paul's Security Weekly (Video-Only)
Security Weekly #439 - Making The Most Of Threat Intelligence from 2015-10-22T16:00

This week, Paul and Mike discuss the current state of threat intelligence. In this segment, Paul and Mike dive deep in using threat intelligence properly.

Security Weekly Web Site: http:/...

Listen