Defensive Security Podcast Episode 252

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive_security_podcast_episode_252.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSShttps://www.bankinfosecurity.com/capital-one-must-turn-over-mandiant-forensics-report-a-14352 https://www.databreachtoday.com/insider-threat-lessons-from-3-incidents-a-14312 https://www.zdnet.com/article/ransomware-deploys-virtual-machines-to-hide-itself-from-antivirus-software/

Defensive Security Podcast Episode 188

https://media.blubrry.com/1463551/content.blubrry.com/1463551/Defensive-security-podcast-episode-188.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSShttps://arstechnica.com/security/2017/04/purported-shadow-brokers-0days-were-in-fact-killed-by-mysterious-patch/ https://www.bleepingcomputer.com/news/security/former-sysadmin-accused-of-planting-time-bomb-in-companys-database/ http://www.computerworld.com/article/3189059/security/what-prevents-breaches-process-technology-or-people-one-answer-is-pc-and-one-is-right.html http://www.csoonline.com/article/3187422/network-security/report-30-of-malware-is-zero-day-missed-by-legacy-antivirus.amp.html How Hackers Hijacked a Bank’s Entire Online Operation http://news.softpedia.com/news/two-laptops-with-hong-kong-s-3-7-million-voters-data-stolen-514346.shtml Threat Brief: Credential Theft – The Keystone of the Shamoon 2 Attacks

Defensive Security Podcast Episode 183

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive-security-podcast-episode-183.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSShttps://arstechnica.com/information-technology/2017/01/antivirus-is-bad/?amp=1 http://www.darkreading.com/risk/7-tips-for-getting-your-security-budget-approved/d/d-id/1328004 https://www.asd.gov.au/publications/protect/essential-eight-explained.htm http://www.csoonline.com/article/3163068/application-development/how-to-secure-active-directory.html https://securosis.com/mobile/tidal-forces-software-as-a-service-is-the-new-back-office/full

Defensive Security Podcast Episode 178

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive-security-podcast-episode-178.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSSSlack channel:  https://defensivesecurity.org/slack-channel/ http://blog.checkpoint.com/2016/11/24/imagegate-check-point-uncovers-new-method-distributing-malware-images/ http://www.csoonline.com/article/3143713/analytics/shall-we-care-about-zero-day.html http://www.databreachtoday.com/umass-amherst-hit-650000-hipaa-settlement-a-9554 http://arstechnica.com/security/2016/11/elegant-0day-unicorn-underscores-serious-concerns-about-linux-security/ http://www.securityweek.com/disgruntled-gamer-likely-behind-october-us-hacking-expert http://www.theregister.co.uk/2016/11/17/google_hacker_pleads_try_whitelists_not_just_bunk_antivirus_ids/ https://blog.instant2fa.com/an-economic-model-for-security-spending-3d982d05d0c1#.fpcnkz5qn http://www.securityweek.com/when-ransomware-hits-business-paying-unlikely-guarantee-resolution http://www.csoonline.com/article/3142889/security/ransomware-victims-able-to-thwart-attacks-report-says.html

Defensive Security Podcast Episode 177

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive-security-podcast-episode-177.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSSBook recommendations: https://defensivesecurity.org/resources/recommended-books/ Slack channel: http://https://defensivesecurity.org/slack-channel/ http://arstechnica.com/information-technology/2016/11/kaspersky-accuses-microsoft-of-anticompetitive-bundling-of-antivirus-software/ https://nakedsecurity.sophos.com/2016/11/11/yahoo-staff-knew-they-were-breached-two-years-ago/ http://www.csoonline.com/article/3139311/security/412-million-friendfinder-accounts-exposed-by-hackers.html

Defensive Security Podcast Episode 165

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive-security-podcast-episode-165.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSSTiaracon: http://tiaracon.org/ http://www.cbc.ca/news/technology/antivirus-software-1.3668746 http://www.csoonline.com/article/3089439/business-continuity/9-critical-controls-for-todays-threats.html http://www.bankinfosecurity.com/interviews/heartbleed-update-america-vulnerable-i-3242 http://www.bankinfosecurity.com/blogs/av-wars-sophos-vs-cylance-p-2172 http://www.reuters.com/article/us-cyber-fdic-china-idUSKCN0ZT20M http://blog.talosintel.com/2016/07/ranscam.html

Defensive Security Podcast Episode 51

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive-security-podcast-episode-51.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSSBob’s wisdom for the week;  Learning from the Target breach; Question: given the massive Target breach, the Neiman Marcus breach and rumors of 6 other significant retailers being breached, assuming Target and others were complying with PCI rules, what will be the PCI council’s response?  AWS … Continue reading Defensive Security Podcast Episode 51

Defensive Security Podcast Episode 17

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive-security-podcast-episode-17.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSSThis week: Twitter warns news agencies of attacks and to use dedicated PCs for using twitter, the US department of Labor website was compromised and serving up an 0day for IE8, 18 12-13 year olds in Alaska socially engineered passwords for 300 computers out of their … Continue reading Defensive Security Podcast Episode 17

The Usefulness of Security Education

Bruce Schneier recently wrote a blog post about the value of security training on Dark Reading that is a bit provocative. Similar to the comments Dave Aitel made last year, Bruce asserts that money spent on education is more useful if spent elsewhere on improving security. I both strongly agree and disagree with this position. … Continue reading The Usefulness of Security Education

Defensive Security Podcast Episode 11

https://media.blubrry.com/1463551/content.blubrry.com/1463551/defensive-security-episode-11.mp3Podcast: Play in new window | Download | EmbedSubscribe: RSSSubscribe in iTunes | Podcast RSS Feed | Twitter | Email Krebs Swatted: http://krebsonsecurity.com/2013/03/the-world-has-no-room-for-cowards/ China: http://www.slate.com/articles/technology/future_tense/2013/03/the_u_s_response_to_chinese_cyberespionage_will_backfire.html http://www.crn.com/news/security/240150929/new-exploit-evades-all-antivirus-products-for-almost-a-day.htm http://www.net-security.org/malware_news.php?id=2441 http://m.threatpost.com/en_us/blogs/ramnit-malware-back-and-better-avoiding-detection-031513 http://www.honeynet.org/node/1031 http://arstechnica.com/security/2013/03/national-vulnerability-database-taken-down-by-vulnerability-exploiting-hack/ Mandiant report: http://www.mandiant.com/library/M-Trends_2013.pdf Solutionary report: http://www.solutionary.com/dms/solutionary/Files/SERT/2013GTIR.pdf