Synopsis
Threatpost writers Mike Mimoso and Chris Brook discuss security threats, attacks, vulnerability research and trends with a variety of industry executives, researchers and experts.
Episodes
-
Inside the Hackers’ Toolkit
09/08/2022 Duration: 16minThere is no question that companies are in the sights of would-be criminals looking to exploit them. While companies look at solutions and trainings to help keep the perimeter secure, the biggest fail point is often the employees, AKA the human element. In this Threatpost podcast, sponsored by Egress, we sit down with Jack Chapman to discuss the steps and tactics that companies can take to stay one step ahead of their adversaries. During our conversation, we discuss: Weaknesses that attackers look to exploit Evolution of toolkits Securing MFA and more
-
Being prepared for adversarial attacks
02/06/2022 Duration: 22minThere is no question that the level of threats facing today’s businesses continues to change on a daily basis. So what are the trends that CISOs need to be on the lookout for? For this episode of the Threatpost podcast, I am joined by Derek Manky, , Chief Security Strategist & VP Global Threat Intelligence, Fortinet’s FortiGuard Labs to discuss the threats facing CISOs along with more. During the course of our discussion, we dive into: What an attack on all fronts looks like The current state of the threat landscape New techniques being leveraged be adversaries The automation of threats We also lay out what CISOs need to consider when laying out and producing their threat action plan.
-
The State of the Secret Sprawl
06/05/2022 Duration: 16minCan I tell you a secret? Will you keep it between us? You’ve probably said this or heard this when it comes to friends and family. However, do you also know that secret keeping, or lack thereof is one of the biggest issues that businesses face? According to the recent The State of the Secret Sprawl from GitGuardian further defines the breadth of business secrets. “A secret can be any sensitive data that we want to keep private. When discussing secrets in the context of software development, secrets generally refer to digital authentication credentials that grant access to services, systems and data. These are most commonly API keys, usernames and passwords, or security certificates. Secrets are what tie together different building blocks of a single application by creating a secure connection between each component. Secrets grant access to the most sensitive systems.” In this podcast with Mackenzie Jackson, developer advocate at GitGuardian, we dive into the report and also the issues that corporations face w
-
The Truth Behind ‘Mythical’ MacOS Malware – Podcast
31/03/2022 Duration: 18minThreatpost editor Lindsey O'Donnell discusses security threats, attacks, vulnerability research and trends with a variety of industry executives, researchers and experts.
-
A Blockchain Primer and a Bored Ape Headscratcher – Podcast
31/03/2022 Duration: 27minThreatpost editor Lindsey O'Donnell discusses security threats, attacks, vulnerability research and trends with a variety of industry executives, researchers and experts.
-
Cyberattackers Put the Pedal to the Metal – Podcast
28/03/2022 Duration: 18minThreatpost editor Lindsey O'Donnell discusses security threats, attacks, vulnerability research and trends with a variety of industry executives, researchers and experts.
-
Top 3 Attack Trends in API Security – Podcast
23/03/2022 Duration: 21minThreatpost editor Lindsey O'Donnell discusses security threats, attacks, vulnerability research and trends with a variety of industry executives, researchers and experts.
-
Reporting Mandates to Clear Up Feds' Hazy Look into Threat Landscape – Podcast
16/03/2022 Duration: 24minIt’s about time, AttackIQ’s Jonathan Reiber said about 24H/72H report deadlines mandated in the new spending bill: Visibility into adversary behavior has been muck.
-
Staff Think Conti Group Is a Legit Employer – Podcast
14/03/2022 Duration: 39minThe ransomware group’s benefits – monthly bonuses, fines, employee of the month, performance reviews and top-notch training materials – might be better than your own company’s, says BreachQuest’s Marco Figueroa.
-
Multi-Ransomwared Victims Have It Coming
08/03/2022 Duration: 28minThere's a yawning gap between IT decision makers' confidence about security vs. their concession that repeated incidents are their own fault, says ExtraHop's Jamie Moles.
-
Russia Leaks Data From a Thousand Cuts–Podcast
03/03/2022 Duration: 17minIt’s not just Ukraine: Threat intel experts are seeing a flood of data on Russian military, nukes and crooks, even with the Conti ransomware gang having shuttered its leaking Jabber chat server.
-
Securing Data With a Frenzied Remote Workforce–Podcast
26/02/2022 Duration: 27minStock your liquor cabinets and take a shot whenever you hear GitLab Staff Security Researcher Mark Loveless say “Zero Trust.”
-
The Art of Non-boring Cybersec Training–Podcast
24/02/2022 Duration: 19minWith human error being the common factor in most cyberattacks, employee training has got to get better. To that end, Trustwave cybersec training expert Darren Van Booven explains the importance of fish stress balls and management buy-in.
-
Killing Cloud Risk by Bulletproofing App Security: Podcast
16/02/2022 Duration: 25minApplications are the most preferred vectors for cybercriminals. Yet no single team or process can assure the rollout of safe cloud applications. From code design to unit testing to deployment, teams and tools have to work together to detect risks early while keeping the pipeline of digital products moving. Alex Rice, CTO at HackerOne and Johnathan Hunt, VP of Security at GitLab, help development teams evolve their processes to build security directly into their workflows for smooth and safe cloud app rollouts. They dropped by the Threatpost podcast recently to share tips on DevSecOps, including: How to build a continual testing, monitoring, and feedback processes to drive down application risk. Developing a continuous approach to application security and DevOps security tools. Why collaboration and continual feedback is essential across development, cloud and security teams. …as well as how to deal with the boatload of animosity between development and security teams. One tip: Assume positive intent
-
Former FBI Gumshoe Nabs Cybercrooks Using Proven Behavioral Clues
08/02/2022 Duration: 22minThreatpost editor Lindsey O'Donnell discusses security threats, attacks, vulnerability research and trends with a variety of industry executives, researchers and experts.
-
How to Buy Precious Patching Time as Log4j Exploits Fly
14/12/2021 Duration: 19minThreatpost podcast: Cybereason CTO Yonatan Striem-Amit shares details about the company's vaccine: a fast shot in the arm released within hours of the Apache Log4j zero-day horror show having been disclosed.
-
Attackers Will Flock to Crypto Wallets, Linux in 2022: Podcast
23/11/2021 Duration: 28minCyberattackers will target those & more as they pick up APT techniques to hurl more-destructive ransomware & supply-chain attacks, predicts Fortinet’s Derek Manky.
-
Podcast: Could the Zoho Flaw Trigger the Next SolarWinds?
18/10/2021 Duration: 11minThat’s what clients are worried about, says Redscan’s George Glass: that the powerful, highly privileged app could be a convenient point of entry for attackers, to areas deep inside an enterprise’s footprint.
-
Podcast: 67% of Orgs Have Been Hit by Ransomware at Least Once
05/10/2021 Duration: 26minFortinet’s Derek Manky discusses a recent global survey showing that two-thirds of surveyed entities suffered at least one ransomware attack, while half were hit multiple times.
-
DDoS Attacks Are a Flourishing Business for Cybercrooks – Podcast
14/09/2021 Duration: 24minImperva’s Peter Klimek visited Threatpost podcast to discuss the evolution of DDoS attacks: They started out as inconveniences but evolved to the point where attackers can disrupt businesses for as little as the price of a cup of coffee,