Synopsis
Rapid7 podcast series discussing all things security. Join us as we discuss information security with thought leaders in the space.
Episodes
-
How Philip Reiner Created the Ransomware Task Force
14/04/2021 Duration: 45minIn our latest episode of Security Nation, we talk to Philip Reiner about his work with the Ransomware Task Force. Stick around for our Rapid Rundown, where Tod talks about a recently released bulletin from CISA about APT exploiting both new and old SAP vulnerabilities.
-
Beau Woods and Fotios Chantzis Discuss Their New Book, "Practical IoT Hacking"
31/03/2021 Duration: 53minIn our latest episode of Security Nation, we speak with Beau Woods and Fotios Chantzis about their newly released book, "Practical IoT Hacking." Stick around for our Rapid Rundown, where Tod encourages listeners to patch their Apple iOS devices against the recently announced WebKit bug, and to not panic about PHP's compromised Git server.
-
Nontraditional Paths into Cybersecurity, Part 3: Starburst Data's Katie Ledoux
17/03/2021 Duration: 44minIn our latest episode of Security Nation, we talk with Katie Ledoux about her unconventional journey into the cybersecurity industry—from her marketing agency days to her time at Rapid7, to her current role as Head of Information Security at Starburst Data. Katie talks about imposter syndrome, what it was like to "start over" in her career, the importance of contributions from non-technical roles—and, of course, what she would want to see out of a "Hackers" sequel.Stick around for our Rapid Rundown, where it's "All Exchange, all the time," in the wake of Microsoft's four critical bugs. Tod and Jen also discuss the recent Github controversy surrounding the ban of exploit code.
-
The CyberPeace Institute's Adrien Ogee Talks Launching a Nonprofit Amid COVID-19 and the Importance of Healthcare Security
10/03/2021 Duration: 40minIn this week's episode of Security Nation, we interview Adrien Ogee, COO of the CyberPeace Institute. He discusses what it was like to launch and staff a brand-new nonprofit during the COVID-19 pandemic, and how his team worked to get the cybersecurity industry to trust them and get involved. Adrien also talks about the CyberPeace Institute's recently released "Playing With Lives: Cyberattacks on Healthcare Are Cyberattacks on People" report.Stick around for our Rapid Rundown, where Tod discusses the National Cybersecurity Center's recently released Cyber Action Plan, a short questionnaire that generates actionable recommendations for shoring up your security. He also talks through Portswigger's recently published list of the top 10 web hacking techniques of 2020.
-
Datto’s Ryan Weeks Discusses a CISO’s Unique Role in Crafting a Pandemic Response
26/02/2021 Duration: 44minIn our latest episode of Security Nation, Ryan Weeks joined the podcast to discuss deploying thousands of assets into a hostile environment: the home offices of workers everywhere as they were forced remote amidst the pandemic. He’ll discuss how he balances privacy expectations with necessary regulations of workers’ computers and phones as they go remote. We’ll also talk about managing an attack surface you don’t understand as well as how lack of transparency can lead to security organizations earning bad reputations. Plus why Jen thinks the work-from-home culture is here to stay, and what organizations can do to prepare.
-
Nontraditional Paths Into Security, Part 2: How Steve Ragan Innovates at the Intersection of Journalism and Tech
04/02/2021 Duration: 38minIn our latest episode of Security Nation, Steve Ragan joined the podcast to discuss his unlikely journey from reluctant security expert to journalist. For Steve, having the tech knowledge is important, but so is crafting a good story. We take deep dives on topics like where the industry was in the ‘90s plus the unique way he approaches Akamai’s “The State of the Internet” report (and their own podcast). We’ll hear why writing with empathy is a foundation of Steve’s process when tackling deeper technical subjects. Also, the joys of shameless self-promotion... Stick around for our Rapid Rundown, where we get quite the rapid rundown of three big events in security: North Korea’s campaign targeting security researchers, the takedown of the Emotet botnet, and (most importantly) the long-awaited cracking of Tod’s seven-year-old Dogecoin CTF.
-
How Santander’s Mark Carney and Daniel Cuthbert Are Working to Demystify Quantum Cryptography
21/01/2021 Duration: 51minhttps://community.signalusers.org/t/signal-should-warn-users-who-are-likely-using-insecure-ime-apps/10272
-
-
Cub Llewellyn-Davies Discusses the U.K.'s Cyber Aware Campaign and Quick Tips to Shore Up Security
17/12/2020 Duration: 52minhttps://www.ncsc.gov.uk/cyberaware/home
-
How Rick Holland's Diverse Experience Helps Him Find Security Talent in Unique Places
18/11/2020 Duration: 46minIn our latest episode of Security Nation, Rick Holland joined the podcast to discuss how his past informs his present, particularly when it comes to sourcing and hiring the best talent. Rick elaborates on how a lack of direct reports—for several years across multiple companies—led to a bit of imposter syndrome when he became CISO at Digital Shadows and suddenly was tasked with staffing and managing a team. Sometimes smaller talent pools can lead to inspired hiring choices.Stick around for our Rapid Rundown, where Tod delves into Samy Kamkar's NAT slipstreaming mechanism in which an attacker can trick a router into opening straight-shot ports to any listening service on a machine.
-
How to Combat the Spread of Misinformation and Disinformation Ahead of the Election
29/10/2020 Duration: 48minIn our most recent episode of Security Nation, we spoke with Maria Barsallo Lynch, Executive Director of the Defending Digital Democracy Project (D3P) at the Belfer Center for Science and International Affairs at the Harvard Kennedy School, about her work informing election officials of the rise of misinformation and disinformation campaigns centered around elections. Stick around for the Rapid Rundown, where Tod cautions against panicking if (completely normal) disruptions occur on Election Day.
-
From the Dorm Room to the White House: How Researcher Jack Cable Works to Ensure Election Security
06/10/2020 Duration: 45minIn our latest episode of Security Nation, we are joined by a rising star in Stanford University’s junior class: Jack Cable. We discuss everything from hacking the Pentagon in high school to ensuring progress in election security beyond just voting machines today. Stick around for our Rapid Rundown, where Tod ditches his talk about the FBI's disinformation campaigns warning to discuss what really matters—a potential "Hackers" movie reboot. Hey, we have priorities!
-
How Entrepreneur Christian Wentz Takes On Identity Authentication and Data Integrity One Line of Code at a Time
25/09/2020 Duration: 48minIn our latest episode of Security Nation, we are joined by Christian Wentz, CEO, CTO, founder of Gradient, and multiple Ph.D holder. From an electrical-engineering-applied-to-neuroscience background to a privacy and data protector present, we discuss what it’s like to thread the needle between internet profitability and end-user privacy. There’s technology, there’s politics, there’s policy, and there’s Tod getting very excited about code.Stick around for our Rapid Rundown, where Tod talks through CVE-2020-1472, a CVSS-10 privilege escalation vulnerability in Microsoft’s Netlogon authentication process that the paper's authors christened “Zerologon.”
-
How Security Pro Dave Kennedy Keeps His InfoSec Skills Sharp While Telecommuting
14/08/2020 Duration: 50minIn our latest episode of Security Nation, Dave Kennedy, founder of the cybersecurity firms TrustedSec and Binary Defense, stopped by to discuss how he’s staying busy while working from home during the pandemic. Wrangling dogs and keeping his skills sharp on Red Team engagements are a major part of the story. Stick around for our Rapid Rundown, where Tod talks about a fascinating attack he learned about at virtual Black Hat called EtherOops, as well as implications around election security that were discussed during the event.
-
Joe FitzPatrick on the Future of Hardware Security Training Sessions
29/07/2020 Duration: 46minOn this week’s episode of Security Nation, Joe FitzPatrick, a lead researcher at securinghardware.com, discusses what it takes to run a successful hardware training session virtually—from organizing equipment logistics to audience engagement, and more.
-
Citizen Science and Medical Consumerism: Confronting the Tech Wisdom Gap in Modern Healthcare
13/07/2020 Duration: 58minBiohacking Village Executive Director Nina Alli joins the Rapid7 team this week to discuss the intersection of tech and medicine on our latest episode of Security Nation. Stick around for our Rapid Rundown, where Tod discusses the two vulnerabilities that plagued infosec professionals over the holiday weekend.
-
Advancements in Vulnerability Reporting in the Post-PGP Era: A Conversation with Art Manion
22/06/2020 Duration: 54minThis week’s episode of Security Nation features Art Manion, Vulnerability Analysis Technical Manager at CERT Coordination Center. Join us as we discuss common API, network topologies, and the quickly evolving world of vulnerability reporting. Stick around for our Rapid Rundown, where Tod talks through the recent bug in the Samsung Quram image processor.
-
Developing Sustainable Vulnerability Management with Katie Moussouris
09/06/2020 Duration: 37minKatie Moussouris, CEO and Founder of Luta Security, joins us on this week’s episode of Security Nation to discuss vulnerability disclosure, bug bounties, and building systems that support sustainable security. Stick around for our Rapid Rundown, where Tod talks through the recent bug in the Samsung Quram image processor.
-
Advocating for Tech Literacy and Transparency: A Discussion with I Am The Calvary’s Josh Corman and Audra Hatch
01/05/2020 Duration: 38minOn this week’s episode of Security Nation, Josh Corman and Audra Hatch of I Am The Cavalry share insights into the software bill of materials (SBoM) and software transparency. Stick around for our Rapid Rundown, where Tod breaks down the latest iPhone bug that wasn’t and Sophos bug that was.
-
Where Tech Meets Legal: Discussing Crowdsourced Security Testing with Bugcrowd’s Casey Ellis
24/04/2020 Duration: 46minOn our latest episode of Security Nation, we caught up with Casey Ellis, founder and CTO at Bugcrowd. Joining us during the 2020 RSA Conference, he takes the time to discuss normalizing vulnerability disclosure, the safe harbor debate, and the legal implications of crowdsourced security testing.Stick around for our Rapid Rundown, where Tod breaks down the recent controversy on online vs. mail-in voting, and gives the inside scoop on Rapid7’s newest project, AttackerKB.