¡Disfruta todo 1 año de Premium al 45% de dto! ¡LO QUIERO!
Security Nation
Podcast

Security Nation

142
2

Security Nation is a podcast dedicated to celebrating the champions in the cybersecurity community who are advancing security in their own ways. We also cover the latest developments in infosec that you should know about.

Security Nation is a podcast dedicated to celebrating the champions in the cybersecurity community who are advancing security in their own ways. We also cover the latest developments in infosec that you should know about.

142
2

Tod and Jen and Jennifer on Season 5 of Security Nation

No Rapid Rundown this time! But you can get links to all the past episodes in Season 5, here: Never Mind the Ears, Here's Security Nation
Internet and technology 3 years
0
0
5
25:00

Jeremi Gosney on the Psychology of Password Hygiene

Interview links Jeremi on Password Nihilism The Rails bug Jeremi referenced Rapid Rundown links Risky Business Newsletter on fake PoCs: "GitHub aflood with fake and malicious PoCs" The cited paper: "How security professionals are being attacked: A study of malicious CVE proof of concept exploits in GitHub" Also relevant is Honeysploit by Curtis Brazzell Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
5
48:37

James Kettle of PortSwigger on Advancing Web-Attack Research

Interview Links Prior Security Nation episode in which loads of PortSwigger references were dropped:https://www.rapid7.com/blog/post/2021/08/18/security-nation-daniel-crowley/ New research from James about browser-powered desync attacks:https://portswigger.net/research/browser-powered-desync-attacks Rapid Rundown Links Semi-secret Fortinet advisory: https://twitter.com/Gi7w0rm/status/1578398457227878407 CVE Details as they come: https://www.rapid7.com/blog/post/2022/10/07/cve-2022-40684-remote-authentication-bypass-vulnerability-in-fortinet-firewalls-web-proxies/ Existence of Fortinet CVE-2022-40684 PoC posted, but not the PoC itself:https://twitter.com/Horizon3Attack/status/1579285863108087810 The Hidden Harms of Silent Patches: https://www.rapid7.com/blog/post/2022/06/06/the-hidden-harm-of-silent-patches/ Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
7
36:00

Taki Uchiyama of Panasonic on Product Security and Incident Response

Interview Links Check out Panasonic's delightful PSIRT page – especially if you have a vulnerability in one of Panasonic's many, many products to report. Rapid Rundown Links Check out Inti's research on "oops, we made a surveillance system" at notmyplate.com. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
6
30:05

Chris Levendis and Lisa Olson on Cloud CVEs

Interview Links Check out the CVE blog post on handling cloud vulnerabilities. Read up on the rules for assigning CVEs. See an example cloud CVE affecting Microsoft Azure. Read the Microsoft Security Response Center’s blog post on cloud vulnerabilities. Rapid Rundown Links Check out Dominic White’s tweet on iOS remembered networks. Read the update on the recently released RFC 9293. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
6
36:20

Gordon “Fyodor” Lyon on Nmap, the Open-Source Security Scanner

Interview Links Check out Nmap if, for some reason, you haven’t already. Learn about Npcap, the packet capture library tool that Gordon and his company also offer. Watch Gordon and HD Moore, the creator of Metasploit, chat about the evolution of network scanning on YouTube. Rapid Rundown Links Read the Bleeping Computer story on hackers using DeFi bugs to steal cryptocurrency. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
6
37:00

Jen and Tod on Hacker Summer Camp 2022

Learn more about some of our favorite presentations from the Vegas conferences, including:  Susan Paskey on threat hunting in MFA logs Jeremi Gosney on "passwords, but nihilism" (an apparently unscheduled, live threat modeling exercise on password risks) Patrick Wardle on Zoom LPE vulnerabilities Gaurav Keerthi, Pete Cooper, and Lily Newman on global policy challenges Jake Baines on Cisco ASA vulnerabilities and weaknesses (check out the blog post, too) Jonathan Leitschuh on fixing OSS vulnerabilities at scale Eugene Lim on so many iCal standards within standards   Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
7
33:56

Curt Barnard on Defaultinator (Black Hat Arsenal Preview)

Interview links Learn all about Defaultinator. Read up on the Raspberry Pi default password vulnerability. Check out the GitHub repositories for Defaultinator. Rapid Rundown links Read Derek Abdine's disclosures on Arris and Arris-like routers. Check out the Security Boulevard article on keeping PoCs secret. Peruse Matt Blaze’s tweet thread on teaching physical security secrets despite complaints from locksmiths. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
7
32:24

Jacques Chester of Shopify Talks CVSS Scores

Interview Links A Closer Look at CVSS Scores Rapid Rundown Links Bleeping Computer story: PyPI mandates 2FA for critical projects, developer pushes back Twitter thread on deleting atomicwrites, and undeleting it PyPi issues mentioned https://github.com/pypi/warehouse/issues/11625 https://github.com/pypi/warehouse/issues/11805 https://github.com/pypi/warehouse/issues/11798 Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
5
39:36

Pete Cooper and Irene Pontisso on the Results of the UK Government’s Security Culture Challenge

Interview Links Revisit our first episode with Peter and Irene from Season 4. Read the paper on the UK government’s cybersecurity strategy through 2030. Rapid Rundown Links Check out the article on so-called pig-butchering scams. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
7
36:03

Steve Micallef of SpiderFoot on Open-Source Intelligence

Interview Links Follow Steve on Twitter, and give the SpiderFoot official account a follow while you’re at it. Check out the SpiderFoot website and GitHub page, and learn more about the SaaS version, SpiderFoot HX. Learn about the latest SpiderFoot 4.0 release with YAML correlation rules.  Read Steve’s blog, especially his posts on the 10 years developing SpiderFoot and the misuse of OSINT to claim election fraud. Rapid Rundown Links Read the full paper, “A Closer Look at CVSS Scores.” Follow the author, Jacques Chester, on Twitter. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 3 years
0
0
6
30:02

Phillip Maddux on HoneyDB, the Open-Source Honeypot Data Project

Interview Links Check out the latest on HoneyDB. Interested in participating in the project? Head to the HoneyDB Agent Docs. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
5
20:48

Omer Akgul and Richard Roberts on YouTube VPN Ads

Interview Links Check out Omer and Richard’s paper. Learn more about Omer’s work and Richard’s work. Rapid Rundown Links Read the news about the change in DOJ policy toward ethical hackers. Visit the Rapid7 blog on the same topic. Dive into Harley’s great Twitter thread on the topic. Read up on the HiQ and Missouri cases mentioned. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
6
38:46

Jim O’Gorman and g0tmi1k on Kali Linux

Interview Links Learn more about Kali Linux. Check out what they’re up to over at Offensive Security. Follow g0tmi1k on Twitter, and check out his blog. Rapid Rundown Links Read the Krebs on Security article on the upcoming password changes. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
8
33:15

Whitney Merrill on the Crypto & Privacy Village (and the Latest in Data Privacy)

Interview Links Follow Whitney on Twitter, and check out her website. Submit a CFP for this year’s Crypto & Privacy Village at DEF CON. Rapid Rundown Links Read Neil Madden’s blog post on psychic signatures. Follow Neil Madden on Twitter. Check out Project Wycheproof on GitHub. Learn about Mount Wycheproof (the actual mountain). Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
5
38:50

Kate Stewart on Open-Source Projects at the Linux Foundation

Interview Links Read Project Zephyr’s blog post on Amnesia33. Get Linux’s perspective on SBOM. Listen to our previous episode on SBOM with Josh Corman and Audra Hatch. Check out Zephyr’s Renode dashboard. Learn about the Software Package Data Exchange (SPDX) specification from ISO. Rapid Rundown Links Read the story on the npm protestware. Peruse the issue logged against the project on Github. See Dark Reading’s homage to Mike Murray. Watch Mike Murray talk about hiring hackers. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
7
38:29

David Rogers on IoT Security Legislation

Interview Links Listen to David’s previous Security Nation episode Give him a follow on Twitter. Read up on the PTSI bill. Learn who the heck Mystic Meg is. Check out ETSI (not the home crafts marketplace). Rapid Rundown Links Download Rapid7’s Vulnerability Intelligence Report. Check out AttackerKB. Listen to Caitlin Condon, lead author of the report, on Duo’s Decipher podcast. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
7
32:40

Bob Lord on Securing the DNC

Interview Links Follow Bob on Twitter. Check out the DNC Security Checklist. Rapid Rundown Links Read the paper on VPN influencer ads on YouTube. Give the lead author, Omer, a follow on Twitter. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
6
36:42

Matthew Kienow on Open-Source Security and the Recog Framework

Interview Links Learn more about Metasploit, AttackerKB, and Recog. Read Matt’s blog post on open-source security. Remind yourself about Log4Shell (if you dare). Read up on Linus’s Law. Rapid Rundown Links Read the Bleeping Computer article about DDoS amplification. Check out the original USENIX paper.
Internet and technology 4 years
0
0
5
29:51

Amit Serper on Finding Leaks in Autodiscover

Interview Links Follow Amit on Twitter at @0xAmit. Read Amit’s blog post on the Autodiscover leak. Rapid Rundown Links Read up on the vulnerability disclosure metrics from Google’s Project Zero. Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.
Internet and technology 4 years
0
0
6
37:08
You may also like View more
Red de Sospechosos Habituales Sospechosos Habituales Updated
No Tiene Nombre Ahora hablo mucho de AI, antes era una serie de charlas con amigos sobre tecnología en general. Aunque por ahora No Tenemos Nombre, en un futuro seguro que maduramos y lo tenemos. https://notienenombre.com/ Updated
TISKRA Podcast sobre tecnología de consumo y software. Análisis estratégico del mundo Apple, Google, Microsoft, Tesla y Amazon así como de todos aquellos productos de entretenimiento y su posible impacto económico y social. Conducido por @JordiLlatzer Updated
Go to Internet and technology