This is a weekly podcast on cyber security domains. We discuss, dissect and demystify the world of security by providing an in-depth coverage on the cybersecurity topics that matter most. All these in plain easy to understand language. Like it, share it, and most importantly enjoy it!
Enjoying the content? Let us know your feedback!
Let me paint you a picture. You lose your work laptop. Maybe it's lifted off a café table, maybe it walks out of the back of a taxi. And your first thought — once the panic settles — is, "well, at least the drive is encrypted. Whoever has it can't actually read anything." Right? That's the whole deal. That's the promise.
Today's episode is about the week that promise got broken on Windows 11. Not with a supercomputer. Not with some nation-state crypto-cracking lab. With a USB stick and a folder. The exploit is called YellowKey, and it does something that, frankly, should not be possible, it walks right past BitLocker without touching the encryption at all.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week we are going to talk about a bug with one of the most misleading names I have seen in a while. It is called copy.fail. And if you saw that name pop up in your feed, you would be forgiven for thinking it was some clever browser demo, or maybe a problem with your clipboard. It is neither.
copy.fail is a Linux kernel vulnerability. Its official label is CVE-2026-31431. And what makes it worth a full episode is not how exotic it is — it is actually quite simple — but how wide its reach is. This single flaw lets an ordinary, unprivileged user on a Linux machine promote themselves all the way up to root. And it does so on nearly every modern Linux distribution shipped since 2017.
https://xint.io:copy.fail
https://www.cisa.gov: CVE-2026-31431
https://www.bugcrowd.com: Hacker Opinion Piece How Lazy Hacking Killed Curls Bug-bounty
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today's episode is one of those stories that, when you start pulling the thread, the whole thing just keeps unravelling. We are going to talk about the Mercor breach. Now, if that name doesn't ring a bell, Mercor is a ten-billion-dollar AI recruiting startup. They match human experts with companies like OpenAI, Meta, and Anthropic to help train AI models. Big clients. Big data. Big target.
Towards the end of March of this year, a threat group called TeamPCP and no, that is not a household cleaning detergent type of product - managed to steal roughly four terabytes of data from Mercor. And the way they did it? They didn't attack Mercor directly. They didn't even attack the software Mercor relied on directly. They attacked the security tool that was supposed to protect that software. Let me say that again. They compromised the vulnerability scanner.
We have all that coming up next in this week's episode.
https://securitylabs.datadoghq.com: LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign
https://www.securityweek.com: SecurityWeek — Mercor Hit by LiteLLM Supply Chain Attack:
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today's episode is one of those stories that really does hit home. Not a bank breach. Not some government leak. I want to talk about the water coming out of your tap.
On March 14th, 2026, hackers dropped ransomware on a water treatment plant in Minot, North Dakota. Staff walked in that morning, saw a ransom note sitting on a server screen, and had to unplug the whole thing. For the next sixteen hours, plant operators were physically walking through the facility, reading gauges by hand — old school, the way it was done decades ago — while the FBI got the call.
The city says the water stayed safe. Nobody got sick. But this incident ripped the cover off a problem the cybersecurity community has been warning about for years: water infrastructure is dangerously exposed. And most people have no idea.
Today I want to unpack what happened in Minot, why water utilities are such soft targets, what SCADA systems actually are and why they are so difficult to defend, and what defenders and regulators are doing — and should be doing — about all of this.
https://therecord.media: North Dakota Ransomware Water Plant
https://www.cisa.gov: CISA — Adapting Zero Trust Principles to Operational Technology
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This is Part 2 of our deep dive into Anthropic's Claude Mythos Preview and Project Glasswing. In Part 1, we covered what Mythos is, how it fits into the Claude model family, and why Anthropic is pushing the boundaries of extended thinking and complex reasoning. Today, we are picking up right where we left off and turning our attention to Project Glasswing — what it is, what it means for security professionals, and why this convergence of advanced AI reasoning and autonomous capability should be on every defender's radar. If you have not listened to Part 1 yet, I would recommend going back and starting there, but if you are already caught up, let us get right into it.
https://www.forrester.com: Project Glasswing The 10 Consequences Nobody Writing About Yet
https://www.anthropic.com: Project Glasswing
https://blogs.cisco.com: Rising To the Era of AI Powered Cyber Defense
https://www.wired.com: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
About three weeks ago, on the 7th of April, Anthropic — the company behind the Claude family of AI models — announced something called Claude Mythos Preview. They paired the announcement with a coordinated industry effort they're calling Project Glasswing. And the headlines that followed have been, frankly, alarming.
Fortune ran a piece headlined that Mythos can hack nearly anything, and we aren't ready. Coindesk reported that banks like JP Morgan, and crypto exchanges like Coinbase and Binance, are already approaching Anthropic to test it. And Anthropic's own researchers described this as a watershed moment — meaning, a before-and-after divide in how we think about software security.
So let's break this down. What is Mythos? What can it actually do? And — most importantly — what should you and I, as defenders, be doing about it starting today?
https://www.anthropic.com: Project Glasswing
https://blogs.cisco.com: Rising To the Era of AI Powered Cyber Defense
https://www.wired.com: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
We have got two big stories to get through today. First, the FBI just released its 2025 Internet Crime Report — and the numbers are not just record-breaking, they are genuinely alarming. We are talking about over twenty billion dollars in reported losses in a single year. And for the first time ever, the report includes a dedicated section on how criminals are using artificial intelligence to supercharge their scams.
Then, we are going to pivot to Microsoft's April 2026 Patch Tuesday — one of the largest patch cycles we have seen in a long time. A hundred and sixty-seven vulnerabilities fixed, including an actively exploited zero-day in SharePoint Server. If your organisation runs SharePoint, and most do, you are going to want to hear this.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
If you've been watching the cybersecurity space for the last two years, you've noticed something. Almost every breach report, every vendor pitch, every board meeting — AI is in the conversation. Sometimes as the hero, sometimes as the villain, and very often as both at the same time.
But here's the uncomfortable truth. Most organisations are racing to deploy AI far faster than they are learning how to secure it. We're plugging large language models into customer service, into code pipelines, into decision-making workflows — and we're often doing it without a framework to guide us.
So in today's episode, I want to fix that. I want to walk you through the three frameworks that have become the gold standards for AI security. They are NIST AI RMF, MITRE ATLAS, and the OWASP Top 10 for LLM Applications.
Hopefully by the end of the next fifteen minutes, you will know what each one is, what each acronym actually stands for, what problem each one solves, and — most importantly — how they fit together so you can use them in the real world.
https://www.nist.gov: AI Risk Management Framework
https://atlas.mitre.org: MITRE ATLAS
https://owasp.org: OWASP Top 10 for Large Language Model Applications
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, I am joined by my good old friend Shakel Ahmed, a cybersecurity practitioner with over 20 years of experience across some of the most demanding environments in the industry. We are covering the importance of skills and cyber resilience — and this is particularly important for those of you who are responsible for building and maintaining security teams, managing risk at a strategic level, or simply trying to figure out where to focus your energy in an industry that never sits still. Whether you are an analyst wondering which skills will keep you relevant in the age of AI, or a CISO trying to ensure your organisation can absorb a hit and keep operating, this conversation is for you. Shakel brings a practitioner's perspective — not theory, not vendor talk — just hard-won insight on what it actually takes to build resilient people, resilient processes, and resilient organisations. So grab a coffee, settle in, and let's get into it.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Just over a week ago, on 11 March 2026, a cyberattack brought one of the world's largest medical device makers to its knees. Stryker - a $25 billion company that manufactures surgical robots, joint implants and emergency equipment - woke up to find thousands of employee devices wiped clean, its ordering systems offline, and surgeries being rescheduled around the world.
This was not ransomware. This was something more deliberate and destructive - a wiper attack carried out by a state sponsored-linked hacking group called Handala, who exploited a trusted Microsoft device management tool to erase data from up to 80,000 employee phones and laptops in one move.
In this episode, we break down exactly what happened, how it happened, and what it means for every organisation that relies on cloud-based device management tools. We also look at the governance lessons - from business continuity planning to privileged access controls - that this attack makes impossible to ignore.
https://csrc.nist.gov: NIST SP 800-34 Rev. 1
https://www.cybersecuritydive.com: Stryker attack raises concerns about role of Microsoft Intune
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we are talking about a protocol that is older than most of the people working in IT security right now, a protocol that has powered some of the most catastrophic cyberattacks in history, a protocol that security professionals have been trying to retire for years — and a protocol that is still quietly running in the background of almost every Windows environment on the planet. I am talking about SMB — the Server Message Block protocol. By the end of this episode, you will understand what it does, why it has been so dangerous, how it connects to something we have touched on before called Kerberos and NTLM authentication, and most importantly, what you should actually be doing about it in your organisation today.
So, lots to talk about today. Lets go!
https://learn.microsoft.com: SMB Security Hardening
https://blog.barracuda.com: Majority of Attacks Against SMB Protocol Attempt to Exploit EternalBlue
https://securelist.com: NTLM Is Being Abused In 2025
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
It has been a little while since my last update episode, and a lot has been happening in the world of cybersecurity. So today I want to catch you up on three things that have been on my radar and, more importantly, should be on yours.
First, we are going to talk about ClickFix — a social engineering attack technique that has exploded in popularity over the past year and is now being used by everyone from cybercriminals to nation-state hackers. I will explain what it is, how it works, and why it is so dangerous.
Second, we are going to tackle a question that more and more people are asking: can I just ask an AI chatbot to generate a password for me? The short answer is no, and I will explain exactly why using some very revealing research that just came out.
And third, we are going to cover an important change happening in the world of digital certificates right now — specifically code signing certificates, which are getting significantly shorter lifespans starting this year. I will explain what code signing is, why it matters to defenders, and what your organisation needs to do.
Lots to get through, so let us dive right in.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In late February 2026, a Meta executive lost her entire email inbox when an AI agent she was using deleted everything despite explicit instructions to confirm before taking action. At the same time, over 40K OpenClaw AI agent instances were found exposed to the internet, vulnerable to complete takeover by any malicious website a developer happened to visit. This isn't a story about a theoretical vulnerability or a proof-of-concept attack—this is happening right now, and if your organization is using AI agents for automation, you need to understand what just went wrong and why it matters.
https://thehackernews.com: ClawJacked Flaw
https://www.oasis.security: OpenClaw Vulnerability
https://www.microsoft.com: Cyber Pulse AI Security Report
https://www.microsoft.com: 80% Of Fortune 500 Use Active AI Agents Observability Governance And Security Shape The New Frontier
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Cisco Live is one of the largest networking and security conferences in the world, bringing together thousands of IT and security professionals for a week of learning, innovation, and hands-on experience — and this year, I was there, working as a SOC analyst on the ground -protecting the event. At an event of this scale, thousands of devices and connections are generating traffic around the clock, and behind the scenes, a dedicated SOC team is watching every packet, every connection, and every anomaly in real time. This week, I sat down with the Director of the SOC to pull back the curtain on what it actually takes to secure an event like this — from threat patterns unique to a security-savvy crowd, to the tools and team structure that keep it all running.This is a conversation you don't want to miss
https://blogs.cisco.com: SOC In A Box
http://cs.co/SOCEvents: Inside the event SOC-Securing the world's flagship conferences
https://www.cisco.com: Endace
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
On June 27, 2024, millions of people worldwide suddenly couldn't access one of the internet's most popular DNS services—not because of a cyberattack in the traditional sense, but because a single network in Brazil convinced the internet that it owned an IP address that belonged to someone else. This wasn't hacking in the way most people understand it—no passwords were stolen, no systems were breached, yet traffic from 300 networks across 70 countries was instantly rerouted into oblivion. In this episode, we break down BGP hijacking: the invisible routing attack that lets anyone with the right access redirect your internet traffic anywhere they want, and why the protocol holding the entire internet together was built on a foundation of trust that no longer makes sense in 2026.
https://gcore.com: What IS BGP?
https://isbgpsafeyet.com: Is BGP Safe Yet?
https://blog.apnic.net: APNIC Blog – BGP Security Analysis and Updates
https://en.wikipedia.org: Regional Internet Registries
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
On January 17, 2025, the European Union's Digital Operational Resilience Act — known as DORA — became fully enforceable, fundamentally changing how financial institutions across Europe manage cyber and operational risk. One year into enforcement, regulators have designated critical ICT providers, penalties are now being levied, and the January 2026 supervisory review is underway. In this episode, we break down what DORA actually requires, who it applies to, why it matters even if you're not in the EU, and what the upcoming review means for the financial sector globally.
https://www.eiopa.europa.eu: Digital Operational Resilience Act (DORA)
https://eur-lex.europa.eu: The regulation
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
After sixty years of password resets, forgotten credentials, and phishing attacks, the authentication landscape is finally shifting — and 2026 marks the tipping point. In this episode, we break down what passkeys actually are, why over a billion people have already adopted them, and what the regulatory push from NIST, CISA, and global financial regulators means for your organisation. Passwords aren't dead yet, but for the first time, they're genuinely on the way out.
We have all that coming up next, in this week's podcast!
https://passkeys.io: Comprehensive implementation guides, device compatibility checker, and passkey directory
https://pages.nist.gov/800-63-4: Official SP 800-63-4 with AAL2/AAL3
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In Part 1 of this series, we explored why Microsoft is finally saying goodbye to NTLM authentication after more than 25 years of service. We discussed NTLM's security weaknesses, from relay attacks to weak cryptography, and touched on Kerberos as the obvious alternative that's been waiting in the wings since ...well....Windows 2000.
Today in Part 2, we're getting practical. We'll explore the two groundbreaking major Microsoft is adding to Kerberos—IAKerb and Local KDC—that will finally allow organizations to eliminate NTLM entirely. More importantly, we'll discuss what this means for you as a defender, how to prepare your environment, and of course...what timeline you're working with.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we're diving into a significant announcement from Microsoft that will fundamentally change how Windows handles authentication. In this two-part series, we'll explore Microsoft's plan to phase out the NT LAN Manager protocol, better known as NTLM, and fully embrace Kerberos authentication in Windows 11. This isn't just a minor technical adjustment—this represents a major shift in how organizations will secure their Windows environments.
In Part 1 today, we'll understand what NTLM is, why it's been around for so long despite its security weaknesses, and explore the fundamental reasons Microsoft has decided it's finally time to pull the plug.
- techcommunity.microsoft.com: The evolution of Windows authentication
- www.securityweek.com: Microsoft Improving Windows Authentication, Disabling NTLM
- www.bleepingcomputer.com: Microsoft plans to kill off NTLM authentication in Windows 11
- thehackernews.com: Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
It has been a while since we've done a news update episode. So today, we're diving into two major stories that have been dominating cybersecurity headlines this past week. First, we'll unpack React2Shell, a critical vulnerability that's being called one of the most serious web application flaws in recent memory. Then we'll discuss the Instagram data breach affecting over seventeen million users. Both incidents highlight how quickly the threat landscape can shift.
https://react.dev: React Security Advisory
https://www.wiz.io: Wiz Research Technical Analysis
https://aws.amazon.com: AWS Threat Intelligence Report
https://www.cisa.go: CISA Alert on CVE-2025-55182
https://haveibeenpwned.com: Instagram Breach
https://www.cisa.gov: Multi-Factor Authentication Guide
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In late 2025, Jaguar Land Rover was hit by a debilitating cyberattack that brought its global production to a near-standstill and ultimately exposed sensitive employee and contractor data, marking one of the most disruptive breaches in the automotive industry in recent memory.** The incident not only shuttered factories and hammered sales, but also served as a stark reminder of how deeply cybersecurity failures can ripple through complex modern supply chains and operations.
-https://www.cyfirma.com: Investigation Report on Jaguar Land Rover Cyber Attack
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
As we've done at the end of each year, it's time to look back at what resonated most with you, our listeners. 2025 brought us some incredible episodes covering everything from fundamental security concepts to cutting-edge AI developments. But three episodes truly stood out—pulling the highest download numbers and sparking the most conversation.
These weren't just popular because they covered trending topics. They addressed real, practical challenges that defenders face every single day. So let's dive into the best of 2025.
First up: Episode 207 - Microsoft Windows Actively Exploited Vulnerabilities
Released on January 18th, this episode tackled something every Windows administrator loses sleep over—actively exploited vulnerabilities. We broke down three critical flaws that attackers were leveraging in the wild, and more importantly, what you needed to do about them right away. This episode hit home because it wasn't theoretical—these were real threats demanding immediate action.
Next: Episode 213 - Stealing Data in Plain Sight: How Cybercriminals Exfiltrate Your Secrets and How to Stop Them
Published on March 1st, this deep dive into data exfiltration struck a nerve. We explored how attackers don't just break in anymore—they quietly steal your most valuable assets while blending into normal network traffic. From DNS tunneling to cloud storage abuse, we covered the techniques defenders need to recognize and the controls that actually work. This episode became essential listening because data exfiltration isn't just a technical problem—it's a business survival issue.
And finally, wrapping up our 2025 year in review: Episode 219 - What Is Agentic AI?
Released on April 12th, this episode ventured into territory that's reshaping our entire field—Agentic AI. We explored autonomous systems that can make decisions and take actions without human intervention. Why did this resonate so strongly? Because AI agents aren't science fiction anymore—they're being deployed in security operations, and defenders need to understand both their potential and their risks. This episode helped demystify where AI is heading and what it means for everyday security professionals.
Enjoy!
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we're tackling one of the fastest-emerging threats of 2025—one that's probably already active in your organization right now, whether you know it or not. We're talking about Shadow AI, and the statistics are alarming: That means right now, as you're listening to this, someone in your organization is likely pasting sensitive data into ChatGPT, Claude, or another AI tool—and your security team has no idea it's happening. Lets peel the onion to see what this is so.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we're talking about one of the most dangerous yet underestimated threats in cybersecurity right now. While everyone's worried about ransomware making headlines with million-dollar extortion demands, there's a quieter threat that's actually fueling those attacks. It's called infostealer malware, and in 2024 alone, these silent digital pickpockets were responsible for nearly one in four cyberattacks. They stole over 2 billion credentials and enabled some of the most devastating breaches of the year. The scary part? Most victims don't even know they've been infected until it's far too late.
https://nvlpubs.nist.gov: NIST Special Publication 800-83 Rev. 1 - Guide to Malware Incident Prevention and Handling
https://media.defense.gov: NSA Cybersecurity Advisory - Top Ten Cybersecurity Mitigation Strategies
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Imagine discovering that your organization is running nearly ten times more applications than your IT team knows about. Imagine learning that two out of every three cloud tools being used by your employees were never approved, never vetted for security, and are completely invisible to your monitoring systems. Now imagine that one-third of all data breaches last year involved exactly these kinds of hidden applications. This isn't a hypothetical scenario from some dystopian cybersecurity future—this is happening right now in organizations of every size, including yours. Today, we're talking about Shadow IT and SaaS sprawl, the security crisis that's hiding in plain sight, costing companies millions, and creating vulnerabilities that most security teams don't even know exist yet.
https://csrc.nist.gov: NIST Special Publication 800-53 - Security Controls for Shadow IT
https://www.ibm.com: Data-breach
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we're lifting the hood on something you interact with dozens of times per day but probably never think about: Windows password security. What actually happens when you type your password and hit Enter? Where does Windows store that password? And perhaps most importantly, why do attackers spend so much time trying to steal password databases?
https://learn.microsoft.com:Prevent Windows Store LMHash Password
https://www.nist.gov: How Do I Create a good password
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we're talking about the future of security operations, specifically three technologies that have dominated the conversation for the past few years: SIEM, XDR, and SOAR. And I'm going to make a case that might surprise some people: these tools are converging. They're merging into unified platforms, and that's actually a good thing.
Now, if you're a security professional, you've probably noticed this trend already. Vendors are starting to blur the lines between these categories. SIEM vendors are adding XDR capabilities. XDR platforms are adding automation features that look a lot like SOAR. And everyone's claiming they can do everything.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we're tackling a question I get asked constantly: "Should we do a pentest, a red team engagement, or a vulnerability assessment?"
These terms get thrown around interchangeably, but they're actually very different things with different goals, different costs, and they're appropriate for different situations. Choosing the wrong one can either waste money on overkill testing or leave you with a false sense of security.
Here's the reality: most organizations need all three at different times. But if you're trying to figure out where to start, you need to understand what each one actually does.
https://www.sans.org: Penetration Testing: The Shift to Red Team and Purple Team Strategies
-https://nvlpubs.nist.gov: Technical Guide to Information Security Testing and Assessment
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we're talking about one of the most common yet misunderstood cyber attacks happening right now: credential stuffing. And I do mean right now. As I'm recording this, somewhere in the world, automated bots are attempting billions of login attempts across thousands of websites, trying to break into accounts using stolen usernames and passwords.
https://www.usenix.org: Protecting accounts from credential stuffing with password breach alerting
https://www.cs.cornell.edu: Beyond Credential Stuffing: Password Similarity Models using Neural Networks
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we're diving into something that keeps cybersecurity professionals up at night, and no, it's not the latest ransomware attack or data breach. It's something much more frustrating: the fact that despite spending billions of dollars on security awareness training every year, employees keep clicking on phishing emails, using weak passwords, and falling for social engineering attack.
https://www.verizon.com: 2025 Data Breach Investigations Report
https://ebbinghausmuseum.org: The Forgetting Curve
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Something fundamental changed in how we browse the internet in October 2025, and most people have no idea. In just 48 hours, OpenAI launched ChatGPT Atlas, Microsoft fired back with a revamped Edge, and suddenly every major tech company was racing to release AI-powered browsers that don't just load web pages—they can read your emails, book your travel, and access every logged-in account you have, all autonomously. The marketing promises unprecedented productivity, but security researchers found critical vulnerabilities within days—attacks where a single Reddit comment could drain your bank account or a malicious website could steal all your emails without you knowing. Today, we're breaking down what it means for your security, asking the question that actually matters: Are AI browsers a productivity breakthrough or a security disaster? Let's dive in.
https://openai.com: Introducing ChatGPT Atlas
https://www.perplexity.ai: Introducing Comet
https://blogs.windows.com: Your AI Browser
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
So today, we're unpacking what vibe coding is, why it's creating serious security risks, and what you can do about it. Because whether you love it or hate it, vibe coding isn't going anywhere. The question is: are we shipping features, or are we shipping vulnerabilities?
All that coming up next in today's episode.
https://cloud.google.com: What Is Vibe Coding?- https://learningnetwork.cisco.com: Escaping Abstraction: Why AI-Generated Code Demands More Than Just Trust
https://claude.ai: Vibe Code Best Practice
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week, we've got three stories that really caught my attention, and honestly, they're all pretty alarming in their own ways.
If you're new here, welcome to the show where we break down the latest cybersecurity news and help you understand what's really happening in the cyber security domains.
We're going to talk about a shocking discovery about AI security - turns out it takes way fewer malicious documents than anyone thought to completely poison an AI model. Then we'll discuss something that should make every security professional cringe - CISA just added a dozen vulnerabilities to their Known Exploited Vulnerabilities catalog, and half of them are over a decade old. And finally, we'll cover Salesforce's bold decision not to pay ransom to hackers who claim to have stolen data from dozens of major companies.
https://www.anthropic.com: Small Samples Poison
https://www.turing.ac.uk: LLMS May Be More Vulnerable Data Poisoning W Thought
https://www.theregister.com: Salesforce Refuses To Pay Ransomware
https://www.sans.org: CISA Adds 12 CVEs to KEV; Half are a Decade or More Old
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Picture this: You're at London Heathrow, Europe's busiest airport, ready to check in for your flight. But the kiosks aren't working. The screens are blank. Airport staff are scrambling with iPads and even pen and paper to manually check passengers in. Your flight is delayed, maybe canceled. And you're stuck in a long line with thousands of other frustrated travelers.
Today we're diving into something that disrupted the travel plans of thousands of people just a few weeks ago - a massive cyberattack that brought some of Europe's busiest airports to a grinding halt.
This wasn't a scene from the 1970s - this happened in September 2025. And it wasn't just Heathrow. Brussels, Berlin, Dublin - major airports across Europe were hit simultaneously.
Over the next 30 mins or so, we're going to unpack what happened, who was behind it, how the attack unfolded, and what this means for the future of critical infrastructure security. We'll also look back at other major airport attacks from recent years to understand the bigger picture.
So whether you're a security analyst, a CISO, or just someone who travels and wants to understand these threats, stick around.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.
I am your host Ibrahim Yusuf...
This is part 2 of where we will continue covering the debate that's been heating up in security circles: Are Web Application Firewalls obsolete?
Now, if you've been in the security game for a while, you've probably heard the whispers. Some people are saying WAFs are dead weight, legacy technology from a bygone era. Others swear by them as the cornerstone of application security. So which is it?
Well, listen to these two part episode. I suggest you start with episode 1 first then come back to this one. In episode 1, we covered all the foundational parts and background. In our second part, we will kick off with modern attacks. Enjoy.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
We're tackling a debate that's been heating up in security circles: Are Web Application Firewalls obsolete?
Now, if you've been in the security game for a while, you've probably heard the whispers. Some people are saying WAFs are dead weight, legacy technology from a bygone era. Others swear by them as the cornerstone of application security. So which is it?
Well, stay tuned because this is exactly what you will find out in today's episode.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode I am joined by my good old friend Shakel Ahmed a cyber security practitioner with over 20 years of experience. We discussing how the cybersecurity landscape is at a tipping point as AI revolutionizes both defenses and threat capabilities. While tools like ML/LLM boost defender and developer efficiency, they're simultaneously empowering attackers with unprecedented advantages—operating without the ethical constraints that limit defenders. As traditional security measures struggle to keep pace, innovative strategies like specialized AI models and strategic honeypot deployments are emerging as critical weapons in this evolving digital battleground.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we're unpacking one of the most significant supply chain attacks of 2025 - the Salesloft-Drift OAuth breach that sent shockwaves through the enterprise software world.
We'll explore how a compromise at one marketing company led to data theft at some of the biggest names in cybersecurity and technology. We'll break down the technology at the heart of it all - i.e. those digital keys that let applications talk to each other - and examine how threat actors turned them into free passes for corporate data theft.
https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today’s episode is all about Volt Typhoon, a Chinese state-sponsored hacking group whose stealthy techniques and strategic missions have caused significant concern for defenders worldwide. We’ll break down who Volt Typhoon is, analyze the recent major report covering their activities, walk through real examples of the organizations they targeted, and explain every bit of technical jargon so everyone can follow along. By the end, you’ll understand why this group is considered one of the top cyber threats facing critical infrastructure today—globally and in the West.
https://www.cyber.nj.gov: VOLT TYPHOON APT A Strategic Threat Assessment
https://www.cisa.gov: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week, the cybersecurity landscape delivers two major stories that demand attention. Microsoft’s August Patch Tuesday brought a wave of critical updates and exposed gaps, challenging defenders to reassess their priorities and protections. Meanwhile, Google’s Project Zero team is changing the rules on how and when the world learns about new vulnerabilities—speeding up transparency and raising fresh questions for vendors and users alike.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this episode, we’re diving into how companies are working to secure Generative AI—the technology behind chatbots, image creators, and code-writing assistants. We’ll break down how it’s different from traditional enterprise security, look at real-world attack examples, bust some myths, and explore what the future holds.
https://owaspai.org: AI Security Overview
https://artificialintelligenceact.eu: The EU AI Act
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we’re tackling a critical subject that causes countless data breaches yet often gets misunderstood: misconfiguration — what it is, why it’s different from a software vulnerability, and why it remains one of the biggest security risks organizations face.
One quick reminder before we dive into the main topic:Microsoft reminds of Windows 10 support ending in two months
Windows 10 Sunset Alert: What You Need to Know Before October 2025
https://learn.microsoft.com: Windows 10 End Of Service Reminder
https://owasp.org: Security Misconfiguration
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we focus on a critical and rapidly evolving Microsoft SharePoint vulnerability that’s rocked the security world in July 2025. We’ll walk you through what it is, why it matters, how attackers exploit it, and most importantly, what you and your organization can do to defend against it.
For those new to cybersecurity, we’ll also explain the tricky technical jargon around this vulnerability, so you can follow along confidently, whether you’re an entry-level analyst or someone keen to learn more.
https://www.sans.org: Critical SharePoint Zero-Day Exploited: What You Need to Know About CVE-2025-53770
https://msrc.microsoft.com: Update Guide Vulnerability CVE-2025-53770
https://msrc.microsoft.com: Guidance For Sharepoint Vulnerability CVE 2025-53770/
https://www.bleepingcomputer.com: US nuclear weapons agency hacked in Microsoft SharePoint attacks
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
The world of cybersecurity isn’t just about defending laptops and servers—it’s also about safeguarding the “invisible” corners of our networks: those printers, cameras, routers, and dozens of other devices that quietly power our organizations. But what do you do when you can’t install security software or agents on these endpoints? In this episode of YusufOnSecurity, we’re digging into the art and science of protecting infrastructure you can’t easily touch or monitor from within. From game-changing network tactics to clever monitoring tricks, we’ll explore the evolving landscape of agentless security—and why protecting these overlooked devices just might be the next frontier in building a truly resilient environment. Stay with me as we unlock the secrets of securing the unmanageable.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, we talk through the technical details of CI/CD (Continuous Integration/Continuous Development) pipelines: what they are, how they work, the jargon around them, and the potential security risks organizations need to be aware of. Finally, we’ll bust a persistent myth in software development that you might find surprising.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today’s episode takes you through three intersecting stories revealing how technology shapes both our vulnerabilities and our digital identity—from the sprawling and adaptable threat of AsyncRAT malware, to critical Bluetooth vulnerabilities threatening millions of vehicles globally, and finally to a thought-provoking glimpse into how AI models create intimate profiles of their users.
https://simonwillison.net/2025: Simon's ChatGPT dossier
https://blog.talosintelligence.com/AsyncRAT
https://www.bankinfosecurity.com: PerfektBlue Bug
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we’re focusing on the critical lessons from one of the most disruptive IT failures in recent memory: the global outage triggered by a CrowdStrike software update on July 19, 2024. While the headlines focused on grounded flights and downed systems, the real story lies in what this incident revealed about the way we build, secure, and rely on digital infrastructure.
This episode isn’t just about a faulty update—it’s about the cascading impact of vendor trust, software architecture, and system design decisions made long before disaster strikes. We’ll explore how over-reliance on a single vendor can introduce hidden points of failure, why resilience must be baked into every layer of our IT stack, and how incident response can make or break reputations in a hyperconnected world. We’ll also look at Microsoft’s rapid response and how this moment might reshape the rules for how security software integrates with Windows. The takeaway? In cybersecurity, it’s not enough to be secure—you also have to be prepared for when your most trusted systems fail.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week on YusufOnSecurity, we’re diving into a topic that’s become increasingly critical as our world grows more connected: the security of the Internet of Things, or IoT. From smart thermostats and wearable fitness trackers to industrial sensors and connected cars, IoT devices are now woven into the fabric of our daily lives and business operations. They promise greater convenience, efficiency, and innovation—but they also introduce new risks and vulnerabilities that many organizations and individuals are just beginning to understand.
Securing IoT isn’t just about protecting gadgets; it’s about safeguarding the data they collect, the networks they connect to, and ultimately, the people and processes that rely on them. As the number of IoT devices skyrockets, attackers are finding new ways to exploit weak points—sometimes with far-reaching consequences. In this episode, we’ll explore why IoT security matters, the unique challenges it presents, and practical steps you can take to protect your connected world.
https://www.cisco.com: What is iOT?
https://www.iiconsortium.org: Security Maturity Model
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In today’s interconnected world, the security of our digital infrastructure relies heavily on cryptography—the science of protecting information by transforming it into unreadable formats for unauthorized users. But how do we know the cryptographic solutions we use are truly secure? That’s where standards like FIPS 140-3 come in.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In today’s episode is about a seismic shift in the world of cyber threats. The emergence of AI-powered malware. We’ll unpack how this new breed of malware works, the science behind it, real-world incidents, and what the latest academic research reveals.
We will also look at the latest news that some are calling "The mother of all breaches".
We have all that coming up next, in this week's podcast!
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we’ll answer a pressing question in cybersecurity: Is UTM still relevant in 2025? We’ll trace the origins of UTM, explain why it was created, break down its core features, compare it to newer technologies, and finish by busting a common cybersecurity myth.
Before we dive into our main topic, let’s take a quick look at a major tech update making headlines:
The emergence of AI powered malware is becoming more real
https://en.wikipedia.org: UTM
https://perception-point.io: AI Malware: Types, Real Life Examples, and Defensive Measures
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, we get into some detailed exploration of an up and coming malware. Looking at it closer, it is one of the most advanced post-exploitation code families shaping the cybersecurity landscape in 2025. Over the time we have together, we’ll unravel what this malware is, how it works, why it’s so dangerous, and most importantly what businesses can do to defend themselves. Along the way, we’ll break down technical terms and processes, to make the topic less complex as I need it to be accessible and engaging to everyone.
Before we dive into our main topic, let’s take a quick look at a major tech update making headlines:
-https://www.bleepingcomputer.com: Ransomware gangs increasingly use Skitnet post-exploitation malware
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week we are exploring what Content Delivery Networks —commonly known as CDNs— are and whether they protect modern businesses. We’ll dive deep into the mechanics of how CDNs work, the technologies behind them, and whether they defend organizations from threats or just deliver content at blazing speeds. Along the way, we’ll highlight two of the world’s leading CDN providers.
https://en.wikipedia.org: Content Delivery Network
https://www.cloudflare.com: What Is CDN?
https://www.akamai.com: What Is CDN?
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, we are looking at the latest Cisco Talos’ 2024 report.
In this comprehensive report, we will delve into the major cybersecurity trends and threats observed over the past year. Cisco Talos team, has compiled this report to provide valuable insights and guidance for organizations to enhance their security postures.
But before we get in to the main topic, I have one security news for you and that is:
The European Union launches a new vulnerability Database - EUVD
https://euvd.enisa.europa.eu: EUVD
https://euvd.enisa.europa.eu/faq: EUVD FAQ
https://blog.talosintelligence.com: 2024 Year In Review Report
https://www.forbes.com: Why Quantum Computers Will Work Alongside Classical Systems
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This is the part 2 of RSAC 2025 episode. If you have not listened to episode 1 (that episode 222), I would suggest you listen to episode 1 before you listen this episode.
Before you we get into part 2, lets review what has been happening last week on the news front.
UK shares security tips after major retail cyberattacks
https://www.bleepingcomputer.com: UK NCSC Cyber Attack A Wake Up call
https://www.ncsc.gov.uk:NCSC statement - Incident impacting retailers
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
It was RSAC week and it would be remiss of me if I did not give you a highlight on what went on this year, 2025. After all, RSAC has a critical role in security. We will be reviewing the top key announcements from this year's event, including some exciting news from the major security players in the industry. Whether you're a cybersecurity professional, a tech enthusiast, or just curious about the latest in the world of cyber security, this episode is definitely for you. So, let's get started!
Before we dive into the main segment, we will also add one more topic that I think is of major importance on top of everything else and that is from Microsoft.
Microsoft makes All new Account Passwordless by default
https://techcommunity.microsoft.com: New User Experience
https://www.rsaconference.com: RSA Conference 2025
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week's episode looks at the FBI’s 2024 Annual Internet Crime Report -an analysis that not only highlights the scale of cybercrime but also reveals the evolving tactics of cybercriminals and the staggering financial impact on individuals and businesses alike. This of course relates to US but it is an indicative what might be happening elsewhere.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Imagine visiting your favorite website-one you trust, one you’ve browsed a hundred times before-only to discover it’s become a silent gateway for cybercriminals. What if the real danger wasn’t in suspicious emails or obvious scams, but lurking in the very places you feel safest online? In today’s episode, we’ll unravel a cunning technique that preys on trust and routine, catching even the most vigilant users off guard. Stay tuned as we explore the origins, methods, and real-world impact of one of the most deceptive cyber threats in existence.
But before we get to the main topic, lets cover the top security news first
Lazarus hackers breach multiple organisation in a not so new attack method. We will find out what the technique is.
https://attack.mitre.org: Lazarus
https://attack.mitre.org: Drive by compromise
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode we are touching an intriguing topic. We're going to explore Agentic AI, a fascinating area within artificial intelligence that focuses on autonomous systems capable of making decisions and performing tasks without human intervention. We'll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear
But we before we dive into the topic, lets recap the top security news this week:
Microsoft defender will isolate undiscovered endpoing to block attacks
https://learn.microsoft.com: Whatsbnew in Microsoft Defender Endpoint - Apri 2025
https://en.wikipedia.org: Alan Turing
https://www.nvidia.com: Agentic AI
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week, we re going to explore what Fast Flux is, a sophisticated technique used by cybercriminals to evade detection and maintain their malicious activities. We'll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear. So without further ado, grab your coffee, or keep your eyes on the road if you are driving, sit back, and let's get started!"
HellCat Ransomware
https://therecord.media: Schneider Electric Hackers Accessed Internal Project Tracking Platform
https://www.infosecurity-magazine.com: Hellcat Ransomware Humiliation
https://attack.mitre.org: Dynamic Resolution: Fast Flux DNS
https://www.cisa.gov: Fasst Flux, A National Security Threat
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week's episode is continuation of Troy Hunt's cautionary tale , the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We'll continue to break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end where we bust our myth of the week!
We will also look at this week's cyber security news which is
Ubuntu Linux security bypasses
https://blog.qualys.com: Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions
https://www.troyhunt.com: A sneaky phish just grabbed my Mailchimp mailing list
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode we have a fascinating and cautionary tale about none other than Troy Hunt, the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We'll break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end for tips on how to stay vigilant against phishing attacks and our myth of the week!
we will also look at the cyber security news. Here is what caught my attention this week.
PSTools dll injection vulnerability
https://www.foto-video-it.de: Disclosure Sysinternals (You will need to translate to English if you are not a German speaker)
https://learn.microsoft.com: PSTool
https://www.troyhunt.com: A sneaky phish just grabbed my Mailchimp mailing list
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this episode, we’ll look into a cybersecurity assessment method that mimics real-world attacks to test an organization's security defenses and response capabilities: Threat emulation. It is one of the strategies to keep you ahead of the game. Threat emulation aims to identify and mitigate security gaps before attackers exploit them, providing a more comprehensive evaluation than traditional assessments.
Before we dive into the main topic, lets glance what is happening on the security front:
March Microsoft Patch Tuesday has landed!
https://msrc.microsoft.com: March 2025 Security Updates
https://detect-respond.blogspot.com: Pyramid Of Pain
https://www.atomicredteam.io: Atomic Read Team
https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this episode, we’ll be exploring a particularly intriguing file types: polyglot files. These digital shapeshifters have become a powerful tool in the arsenal of cyber attackers, capable of bypassing security measures, confusing systems, and delivering malicious payloads in ways that are both creative and devastating.
Over the next 20 to 30 minutes or so, we’ll break down what polyglot files are, how they work, and why they’re so dangerous. We’ll also examine some real-world examples where polyglot files were used in cyberattacks. We will reference the MITRE ATT&CK framework to understand how these techniques fit into the broader landscape of adversarial tactics. Finally, we’ll discuss mitigation strategies and close with a cybersecurity myth that needs busting
Before we dive into the main topic, lets glance what is happening on the security front:
UEFI Secure Boot bypass vulnerability
https://en.wikipedia.org: Polyglot
https://attack.mitre.org: Masquerading
https://arxiv.org: Where the Polyglots Are: How Polyglot Files Enable Cyber Attack Chains and Methods for Detection & Disarmament
https://medium.com: Polyglot Files A Hackers Best Friend
https://www.bleepingcomputer.com: New polyglot malware hits aviation, satellite communication firms
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In today's episode, we're diving deep into Data Exfiltration; one of the most serious threats facing organizations today.
We'll break down exactly what data exfiltration is, where it fits in the MITRE ATT&CK framework, the tools and techniques attackers use, and, most importantly, how organizations can defend themselves. We’ll also cover real-world examples, including publicly known cases that had major consequences.
So, whether you're a seasoned security professional or just starting out in the field, stick around as we unravel the methods attackers use and how to stop them.
First lets look at one of the trending security news this week, and that is:
News: Caldera Vulnerability
https://github.com/mitre/caldera: Security Notice
https://nvd.nist.gov: CVE-2025-27364
https://medium.com: MITRE Caldera Security Advisory — Remote Code Execution (CVE-2025–27364)
https://www.mitre.org: Caldera
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
We are continuing with part 2 of "Behind the Login Screen - Understanding OS Authentication." If you missed our first episode, I highly recommend giving it a listen before diving into today's content. In part one, we started to explore the fascinating world of operating system authentications, focusing on Windows, Linux/Unix, and Mac OS. We discussed how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks.
In today's episode, we'll build on that foundation and delve even deeper into the topic of OS authentication mechanisms. So again, if you haven't already, make sure to catch up on part one to get the full picture.
Now, let's get started with part two of our journey into the world of OS authentication! lets look at one of the trending security news this week, and that is:
Newly discovered OpenSSH vulnerabilities.
https://blog.qualys.com: Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466
https://learn.microsoft.com: Kerberos Authentication Overview
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In today's episode, we're going to explore the fascinating topic of operating systems authentications. We all use it but how many of us wondered how the behind the curtains machinery work. We'll be focusing on Windows, Linux/Unix, and Mac OS. We'll discuss how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks and their countermeasures, the benefits of password-less authentication using hardware keys, password cracking, the shadow file in Unix/Linux, and the mechanics of how each OS protects passwords and how attackers try to circumvent these protections.
Scareware blocker, now available in Microsoft Edge
https://blogs.windows.com: Stand Up To Scareware With Scareware Blocker
https://learn.microsoft.com: Kerberos Authentication Overview
https://www.microsoft.com: Scareware Blocker
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
As AI-generated content becomes more advanced, the risk of adversarial misuse—where bad actors manipulate AI for malicious purposes—has skyrocketed. But what does this mean in practical terms? What risks do we face, and how one of the big players is addressing them? Stick around as we break Google’s Adversarial Misuse of Generative AI report, explain the key jargon, and bust a cybersecurity myth at the end of the show.
Before we get into the main topic, lets have a look at one important news update, and that is:
Microsoft has expanded its Windows 11 administrator protection tests
https://cloud.google.com: Adversarial Misuse of Generative AI
https://deepmind.google: Mapping the misuse of generative AI
https://learn.microsoft.com: User Account Control overview
https://learn.microsoft.com: How User Account Control works
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we’ve got something really exciting for you. If you’ve been following the world of artificial intelligence lately, you’ve probably heard a lot about a new player in town: DeepSeek.
Now, let me tell you, DeepSeek is shaking things up. They’re doing something completely different that’s not only disrupting the AI space but could also be a game-changer in how we approach cost, performance, and security in the future of AI technology. So, grab a seat on a solid ground and buckle up—this week, we’re diving into how DeepSeek is leveling the playing field for AI vendors everywhere, cutting costs, and leveraging some really smart techniques that are turning heads in the industry.
And, of course, at the end of today’s episode, we’ll be busting a big cybersecurity myth that might surprise you. But first, let’s talk all things DeepSeek.
Before we dive into the main, we will also bring you update todate on the news front:
Deepseek date breach. Yes they were hit already!
https://www.technologyreview.com: How DeepSeek
ripped up the AI playbook—and why everyone’s going to follow its lead
https://www.digitaltrends.com: Microsoft is letting anyone use ChatGPT’s $200 reasoning model for free
https://www.wiz.io: Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this episode we will detail the significant announcement from Let’s Encrypt – the trusted nonprofit Certificate Authority that has been at the forefront of making the web more secure.
Let’s Encrypt has revealed its plans to drastically reduce the lifetime of its TLS certificates from 90 days to just 6 days. This decision, outlined in their 2024 annual report, is aimed at strengthening the security of online communications by minimizing the risks associated with compromised keys. But what does this mean for website owners, IT administrators, and the broader cybersecurity landscape? That’s what we’ll explore in detail today.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This episode is one for you system admins out there! Today we’re discussing three actively exploited vulnerabilities you absolutely need to know about—CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335. These vulnerabilities have been making headlines, and understanding them could mean the difference between staying secure and falling victim to a breach.
We’ll explore what these vulnerabilities are, how they’re being exploited, the adversaries leveraging them, and what organizations and individuals can do to protect themselves. And, as always, we’ll break down the jargon and bust a popular cybersecurity myth towards the end of the show.
Before we get into the main topic, lets recap the top security news this week
Microsoft dropped the January Patch Tuesday and boy was it a whopper! We will dig into the details in more ways than one!
https://isc.sans.edu: Microsoft January 2025 Patch Tuesday
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This is the podcast where we explore the ever-evolving world of cybersecurity and provide practical advice for staying ahead of threats. I’m your host, Yusuf, and today’s episode is all about starting the new year with a solid plan.
We’re diving into _Cybersecurity Resolutions for 2025: Best Practices for Individuals and Organizations._ As we step into a new year, it’s the perfect time to reflect on how we protect our digital lives—whether at home or in the workplace.
From bolstering personal security habits to implementing stronger organizational policies, this episode will cover actionable resolutions you can adopt today. Along the way, we’ll explain key jargon, explore real-life examples, and, as always, bust a common cybersecurity myth at the end.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we’re tackling a fundamental yet often misunderstood tool in every cybersecurity professional's arsenal—vulnerability scanners. What role do they play in protecting our organizations? Where do they shine, and where do they fall short?
As always, we’ll cut through the jargon and break things down for everyone—from seasoned professionals to those just beginning their journey in cybersecurity. And stick around until the end for this week’s myth-busting segment, where we debunk a misconception about cyber security in general that many people still believe.
So grab your favorite beverage, get set, and let’s dive right in!
All that coming up next, in this week episode.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This final episode of 2024, we recap the best the most listened to episodes of the year. And this year we have a great four back to back of the greatest of them all.
Lets start with the first eisode 191 - Is The Browser The New Operating System? released on the 28th of September. Next is episode 172 - SSL VPN versus IPsec VPN - Part 1 and part 2 released 18th of May and 25 of May respectively.
And finally Episode 191 - APIs and Webhooks released on the the 5th October.
Enjoy and see you in the new year!
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
It is a topical episode we’re diving into a high-stakes challenge every organization faces: It is holiday season, how do you manage threats when most of the security team is off duty.
Imagine a holiday season, a long weekend, or even an unexpected emergency. With key team members unavailable, how do we keep our defenses strong? This episode will provide actionable strategies, backed by real-world examples, to help you stay prepared.
Stick around until the end, where we’ll also bust a common cybersecurity myth.
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, we’re diving into a concerning and highly consequential topic: the Volt Typhoon espionage campaign—an advanced persistent threat that has sent shockwaves through the cybersecurity and telecommunications industries.
Volt Typhoon, a state-backed APT group, has been making headlines for its stealthy and highly sophisticated attacks on telecom networks. In this episode, we’ll dissect the technical details of this malware campaign, the vulnerabilities it exploited, and the regulatory loopholes that attackers took advantage of. We’ll also explore lessons the industry can learn to bolster defenses and, as always, bust a common cybersecurity myth along the way.
As always, we will break down all the jargon so that anyone can understand. Whatever you are doing, settle in or keep your eyes on the road, and let’s get started.
Before we get into the main topic, we will start with a recap of top trending security news this week...and that is:
The Last Patch Tuesday
https://msrc.microsoft.com: Microsoft - December 2024 Security Updates
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week episode, we dive into one of the most fascinating aspects of digital investigations: Windows forensic artifacts.
It does not matter who you are: a security professional, an aspiring investigator, or simply curious about how experts uncover the digital breadcrumbs left on your computer, this episode will walk you through the essential pieces of evidence, known as _forensic artifacts_.
We’ll dip our hand into that Shellbags...wait what bags? I heard you say, Don't worry we will break down those complex terms, discuss real-world cases, and provide you with an in-depth understanding of artifacts like Shellbags, Prefetch files, and more.
Before we go any futher, we will review one top trending security news, this week... and that is:
Microsoft NTLM Zero Won't get fixed until April 2025!
https://blog.0patch.com: NTLM Hash Disclosure Vulnerability (0day)
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we’re tackling a topic that every organization, big or small, absolutely must take seriously: Incident Response Playbook
Imagine this: It’s 3 a.m., and your phone buzzes with an alert. A possible ransomware attack has been detected in your network. Do you panic, or do you execute a clear, structured plan? That’s the difference an Incident Response (IR) playbook can make—it turns chaos into control.
Today, we’ll break down what an IR playbook is, why it’s crucial, and how to implement one effectively. We’ll demystify technical jargon and provide actionable insights that you can apply right away. Stick around for the final section, where we’ll bust a common cybersecurity myth that everyone should know about.
Before we go ahead with the show, lets review the top trending security news this week:
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week, we’re diving into a hot-off-the-presses report from the FBI, CISA, and NSA —a breakdown of the most exploited vulnerabilities of 2023. Think of this as the hackers' “most wanted” list: the weaknesses in software and systems that bad actors love to exploit because they’re effective and widely available.
Before we get into that, lets review the top security news this week.
Pygmy Goat: The Sophisticated Linux Backdoor Targeting Network Devices
https://www.ncsc.gov.uk: Pygmy Goat Analysis
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we’ll dive into what browser engines are, how they power your online experiences, and the security efforts shaping the modern web. We’ll also unpack extension security, with a spotlight on Google’s Manifest v3, and see how Safari and Firefox approach these challenges.
Whether you’re a casual browser user or a budding tech enthusiast, this episode is designed to give you insight into a part of your digital life that you might not even realize exists—the browser engine.
So If phrases like “browser engines” and “Manifest v3” sound daunting, don’t worry! I’ll break it all down so it’s as simple as possible. By the end, you’ll not only understand these terms but also appreciate why they’re crucial for a safer internet.
Before we get started, lets review a top trending piece of news this week....and that is:
iOS 18.1 Forcing Reboots
https://www.macrumors.com: iOS 18.1 Forcing Reboots
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
It is another week and another podcast shaw on YusufOnSecurity where we deep dive into the complex world of cybersecurity that concerns both professionals and anyone interested in how attackers continue to evolve their methods.
This week we will be covering advanced malware evasion techniques—strategies used by malicious software to avoid detection—and, crucially, the countermeasures that can help protect against these threats.
Before we get started, lets review a top trending piece of news this week....and that is:
SANS' Holiday Hack Challenge 2024 is Up
https://www.sans.org: SANS' Holiday Hack Challenge 2024
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode I will unpack the complexities of the cybersecurity world and help you stay informed and secure. Today, we’re going to dig into some intriguing concepts shaping the cybersecurity landscape: the Shared Fate Model and Trust Anchors. Some say these concepts are becoming so vital in modern IT security, their pros and cons, and how they compare with traditional security models that, quite frankly, aren’t cutting it anymore.
Before we get started, lets review a top trending piece of news this week....and that is:
Australia looks at setting a minimum for social media use
https://edition.cnn.com: Australia Minimum Age Limit on Social Media
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Lets face it, the cyber crooks are always lurking aroud waiting for an opportunity to come in. They choose the path of least resistant and password is often their way in. Unfortunately password is still with us and for sometime to come too.
In today episode, we’re digging deep into top common types of password attacks—and, most importantly, I’ll walk you through effective ways to stop them. Passwords are often the first line of defense, but they’re also a favorite target for hackers. Understanding these attack methods can empower you to protect your data better, avoid common pitfalls, and even educate those around you. So, let’s get into it!
A newly discovered ransomware serves a wake up all for Mac Users.
https://xkcd.com: How To Create A Strong Password
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week's episode is an interview with Nadim Lahoud from Red Sift at GITEX the Global IT Expo that is held yearly in Dubai. It is the largest tech startup gathering in the world.
Redsift is a company that provides a cloud-based DMARC, DKIM and SPF configuration and management platform called OnDMARC. They also provide:
-Continuous certificate discovery and monitoring as well as
-Brand Trust through AI-driven brand impersonation discovery and monitoring.
Before we get into that we will recap the top trending security this week. That is:
FIDO Alliance Drafts New Protocol to Simplify Passkey Transfers Across Different Platforms
https://fidoalliance.org: Specifications Credential Exchange Specifications
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we’re going to peel back the layers of Microsoft Windows architecture. For many of us, Windows has been a part of our computing lives for decades, whether at work or at home. But how much do we really know about how it works under the hood? In this episode, we’ll take a closer look at what makes Windows tick, compare it with Unix/Linux systems, and explore how it has evolved over the years.
Before we get into the topic, lets review this week's top trending security news:
Criminals Are Testing Their Ransomware Campaigns in Africa
https://www.performanta.com: Africa A testing Ground
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In today's episode, we’re diving into the world of APIs and Webhooks—two key technologies that power much of the automation and interaction between services online. Whether you’re a developer, security expert, or someone just curious about how data flows through the internet, this episode will give you valuable insights into how these tools work, their history, and, most importantly, how to keep them secure.
We’ll also look at real-world examples of API-based attacks on major brands and break down what went wrong. By the end of this episode, you’ll have a full understanding of both APIs and Webhooks, and you’ll be armed with the must-know security measures for each. So, stick around and by keep listening!
Having said that, lets have a look at the top trending news this week.
Mitre launches AI Incident Sharing Initiative. Awsome move!
https://owasp.org: OWASP API Security Top 10
Be sure to subscribe!
You can also stream from https://yusufonsecurity.com
In there, you will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today we’re discussing an exciting trend in the world of technology—the browser is no longer just a window to the web. So we asked is it becoming the operating system itself?
From the early days of Mosaic and Netscape Navigator to today’s cloud-powered Chromebooks, the browser has evolved dramatically. In this episode, we’ll explore the security implication, the history of browsers, the famous browser wars, and how today’s browsers are blurring the lines between web interfaces and operating systems.
Having said that, lets recap a top trending security news shall we?
Exploiting CUPS: How Recent Vulnerabilities Could Compromise Linux Security
https://www.evilsocket.net: Attacking On UNIX Systems Via CUPS Part I
-https://en.wikipedia.org: History of The Web Browsers
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this episode lets look at the world of DevSecOps—a vital practice in modern software development that has implication on security. We’ll trace the history of software development, discuss the evolution of methodologies, and examine the challenges that have led to the emergence of DevSecOps. So, whether you’re a seasoned developer who is curious about the cyber security world, or a veteran security practitioner, this is an episode you would not want to miss..
As always, lets review what is trending in the news front first.
Microsoft officially deprecates Windows Server Update Service aka WSUS.
https://techcommunity.microsoft.com: Windows Server Update Services WSUS Deprecation
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today’s topic is one that mixes the marvel of modern technology with some very real concerns. We’re talking about the rise of Large Language Models, or LLMs, how they’re rapidly being adopted across industries, and the potential for sensitive data leakage on the open web. It’s a thrilling time for AI technologies, but as with all new frontiers, there are risks if we're not careful.
News: MSHTML platform spoofing vulnerability. And yes, It is a big one.
https://blogs.cisco.com: Securing The LLM Stack
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this episode we’re diving into an important topic that concerns one of the most trusted hardware security tokens on the market—the YubiKey 5 series.
We’ll discuss a recently discovered vulnerability affecting YubiKeys and go over what it means for the broader world of authentication and cryptographic security. To help you fully understand the issue, I’ll also provide a quick primer on key concepts like digital signatures, elliptic curves, and the cryptographic algorithm known as ECDSA.
With that said, this episode is an update as well as a main topic and all in all it will give you the tools you need to stay informed and protected.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
Today, we will look into two essential cybersecurity solutions: File Integrity Monitoring or FIM and Endpoint Detection and Response, commonly known as EDR.
Both of these technologies are crucial for protecting systems, but they work in very different ways. We’ll be comparing and contrasting their capabilities, benefits, and use cases.
Before we get into the main topic, lets review a top trending piece of security news:
SANS Institute released a Critical Infrastructure Strategy Guide
https://www.sans.org: SANS Institute released a Critical Infrastructure Strategy Guide
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In today episode we’re diving into something that’s been making waves in the cybersecurity community—NIST Cybersecurity Framework 2.0.
The NIST Cybersecurity Framework has long been a cornerstone for building robust security practices, and with the release of version 2.0, there are some exciting new developments that are relevant given todays threat landscape.
As always, lets review what is trending in the news front.
CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet
https://www.akamai.com: Mirai Botnet Infects CCTV Used in Critical Infrastructures
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode we will dig in exploring a critical framework that’s reshaping how organizations approach cybersecurity—especially in the energy sector—known as the Cybersecurity Capability Maturity Model. This is also refer to C2M2.
We’ll unpack what C2M2 is, why it’s so important, and how it helps organizations assess and improve their cybersecurity practices. So, grab a coffee, sit back, and let’s dive in.
But wait, lets first review this week's trending news.
-https://www.theregister.com: RnsomHub EDRKilling Malware/
- https://c2m2.doe.gov: Cybersecurity Capability Maturity Model
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, we’re unpacking a topic that’s crucial for anyone connected to the digital world: _Why Hackers Target Stolen Credentials_. From understanding the value behind those stolen usernames and passwords to exploring the dark web marketplaces where they’re traded, we’ll break it all down and look at what this means for your security.
Before we get into the topic, lets review this week's top trending security news:
A UK IT provide faces hefty fines for ransomware breach
https://ico.org.uk: Provisional decision to impose £6m fine on software provider following 2022 ransomware attack that disrupted NHS and social care services
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, we're diving into the Malware Information Sharing Platform, or MISP. We'll explore how MISP helps organizations share and leverage threat intelligence, enhancing their defense against cyber threats. Stay tuned as we unpack its features, benefits, challenges, and practical tips for implementation.
Before we get into the main topic, lets touch a top trending piece of news this week. And that is:
Ransomware is on the rise, while technology becomes most targeted section
https://blog.talosintelligence.com: IR Trends: Ransomware on the rise, while technology becomes most targeted sector
https://www.misp-project.org: MISP Project
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
In this week's episode, we will dig into the risk benefit analysis of allowing kernel level access to third party application. We will look into the inherent risks this brings into the operating system and the benefit thereof.
We will also compare the approach the two major operatic system makers took i.e. Microsoft and Apple. We will include snippet of what Microsoft says post CrowStrike outage.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
This week's episode needs very little introduction: The CrowdStrike IT Outage.
We will delve into the unprecedented IT outage caused by a corrupt update from CrowdStrike, which led to widespread Blue Screen of Death (BSOD) errors on Windows systems across globe. Join us as we explore how this incident became the largest IT outage in history and what lessons can be learned from it.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Enjoying the content? Let us know your feedback!
As I said in part of this two part series episode, It's easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today's episode, we will be diving into the reasons behind the surge in data breaches and exploits, and how these incidents are becoming more frequent and damaging. Join us as we explore the fundamental factors contributing to this trend and examine some major breaches from the past few years. Please listen to part 1, beforehand.
Lets now turn to our top trending news this week and that is:
There is a critical Exim Mail Server Vulnerability
https://informationisbeautiful.net/visualizations: Worlds Biggest Data Breaches Hacks
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
We love to hear from you!
It's easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today's episode, we will be diving into the reasons behind the surge in data breaches and exploits, and how these incidents are becoming more frequent and damaging. Join us as we explore the fundamental factors contributing to this trend and exa
Having said that, lets turn to a couple of top trending news this week and they are
Who are behind the Brain Cipher ransomware?
https://media.inti.asia: Understanding the Brain Cipher Ransomware Attack
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
We love to hear from you!
In this episode, we’re focusing on the rising trend of IT outsourcing and its implications for cybersecurity. As more businesses delegate non-core tasks to third-party providers, they inadvertently open doors to trust relationship attacks. We'll explore how attackers exploit the trust between companies and their service providers, leading to potentially devastating breaches. Join us as we delve into the mechanisms, real-world examples, and strategies to defend against these insidious threats.
And before we get into the meant of the matter, lets catch up on what has been trending this week:
A large number of companies are potentially exposed in SnowFlake's related attacks.
https://cyberscoop.com: Snowflake related attacks
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
We love to hear from you!
This week's episode will continue with part 2 of "The Importance of Automation and Orchestration in Cyber Security."
As I said in the episode one, the need for efficient and effective security measures has never been more critical.
I suggest you listen to E1, before you dive into this one.
Without further ado, lets first get what is trending this week in term of news and updates.
Hundreds of personal computer as well as Server Models could be Affected by a serious UEFI Vulnerability
https://eclypsium.com: UEFICanHazBufferOverflow Widespread Impact From Vulnerability In Popular PC And Server Firmware
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode of the podcast we dissect "The Importance of Automation and Orchestration in Cyber Security."
As you are well aware cyber threats are becoming increasingly sophisticated and frequent.
The need for efficient and effective security measures has never been more critical. Equally, automation and orchestration have never more important for organizations to defend themselves and to streamlining processes, reducing response times, and enhancing overall security posture.
In my view this is an important way of tipping the balance in favor of the defenders.
Having said that and before we get into the main topic, lets touch a trending piece of news this week. And that is:
Phishing Email Abuses Windows Search Protocol
https://www.trustwave.com: Search Spoof Abuse O Windows Search T Redirect To Malware
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode, we're tackling a topic that has become increasingly relevant in our post-pandemic world: the hidden dangers posed by remote work.
As more companies embrace flexible work arrangements, the convenience and efficiency of working from home bring new set of challenges.
From cybersecurity threats to data privacy concerns, remote work introduces vulnerabilities that many organizations are not fully prepared to handle.
In this episode, we'll explore the risks associated with remote work, share real-world examples of security breaches, and discuss practical steps that businesses and employees can take to safeguard sensitive information.
Before we get into the main topic, lets touch a trending piece of news this week. And that is:
More backlash about Microsoft's Recall technology.
https://www.computing.co.uk: Microsoft overhauls Recall, makes it opt-in
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode we're exploring an exciting and transformative innovation: Digital Twins technology and its groundbreaking application in cybersecurity.
Imagine having a virtual replica of your entire digital infrastructure—a detailed, dynamic model that mirrors every aspect of your environment.
In particular, we will look at how this cutting-edge technology enhances our ability to test, patch and update our environment and therefore anticipate, detect, and respond to cyber threats with unmatched precision and agility.
Before we get into the main topic, lets touch a top trending piece of news this week. And that is:
Kaspersky releases free tool that scans Linux for known threats
https://www.bleepingcomputer.com: Kaspersky Releases Free Tool That Scans Linux For Known Threats
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this episode we continue with part 2 on comparing SSL VPN and IPsec VPN, two popular technologies used for secure remote access.
As I said last week, understanding the nuances of these technologies is therefore crucial. We'll explore how each VPN works, their security features, performance differences, and the scenarios where each excels. Please listen to episode 172 before you listen to this episode.
With that said, lets turn to a top trending news this week:
Microsoft's "Recall" feature raises privacy concern.
https://www.wired.com: Microsoft Recall AI May Be A Privacy Nightmare
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode we're diving into the world of VPNs, Specifically we will compare SSL VPN and IPsec VPN, two popular technologies used for secure remote access. In the post pandemic area, remote work become part of the new normal post. Understanding the nuances of these technologies is therefore crucial. We'll explore how each VPN works, their security features, performance differences, and the scenarios where each excels.
Having said that and before we get into VPN, lets turn to a top trending news this week and they are:
Recap of RSA Conference. The biggest security conference in the US.
https://en.wikipedia.org: Virtual_private_network
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode, we will be exploring the fascinating world of remote browser isolation technology or RBI as it appreciated. We will delve into what remote browser isolation is, how it works, and the limitations it faces. Join us as we uncover the complexities of this innovative cybersecurity approach, shedding light on its benefits and challenges. Whether you are new to the concept or a seasoned professional, there is something here for everyone.
Having said that and before we get into RBI, lets turn to a couple of top trending news this week and they are:
Dell data breach, 49 million customer records stolen
https://techcrunch.com: Threat Actor Scraped- 49M Dell customer Addresses Before The Company Found Out
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In part 2 on eBPF we continue demystifying this promising new technology that is strengthening the cyber space. Please listen to the previous episode i.e. Episode 169 before you to listen to this one.
Having said that, lets recap a top trending security news, shall we?
New UK Law: No Default Passwords on Smart Devices from April 2024
https://www.ncsc.gov.uk: Smart Devices Law
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this episode, we're diving deep to demystif a groundbreaking technology that's gathering pace on the security front. It is not something of people are aware of. This technology is bringing enhanced visibility, increased performance to enabling powerful security measures.
Hang around as we unravel the potential of eBPF in bolstering cybersecurity defenses, from real-time threat detection to proactive mitigation strategies, and explore how this revolutionary tool is reshaping the landscape of security.
Before we get into that, lets recap a top trending security news: and that is
https://ebpf.foundation: eBPF
https://cloudblogs.microsoft.com: Making eBPF work on Windows
https://en.wikipedia.org: Protection ring
https://cilium.io: Cilium
https://blogs.cisco.com: Cisco HyperShield Reimagining Security
https://www.linkedin.com: Skyfall eBPF Agent For Infrastructure Observability
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode, we will continue with part 2 on "Preparing for and responding to ransomeware attack"
As I said last week, ransomware is a threat that will be around us for the foreseeable future.
Do listen to part 1 before you listen to this episode.
With that out of the way, lets have a look a top trending piece of update for you.
https://blog.talosintelligence.com: Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials
- https://attack.mitre.org: Turla
- https://www.chainalysis.com: ransomware 2024
- https://www.cohesity.com: Ransomware Recovery
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Ransomware is a threat that will be around us for the foreseeable future.
In this week's episode we will look at the history of ransomware, the common TTPs in use by threat actors such as Turla, how to align our incident response to that threat and others, and finally how to contain, eradicate, and recover from it.
In addition we will answer the following pertinent question that are top of minds for the SOC team. Questions such as:
- What are the best methods to inhibiter Threat actor's lateral movement?
- What are the critical components that drive ransomware?
etc...
But before we dig into these gems, lets touch one important top trending piece of news. And that is:
CISA makes its malware analysis system publicly available
https://www.cisa.gov: CISA Announces Malware Next-Gen Analysis
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This week we will dive into a collection of powerful system utilities and tools designed to help users diagnose, troubleshoot, and monitor Windows operating system.
These utilities provide advanced functionality beyond what is typically available in Windows, as they offer insights into system internals, processes, file systems, networking, and more.
But before we dig into these gems, lets touch one important top trending piece of news. And that is:
There is a Post Authentication Stack Overflow on a NetGear Router.
https://blog.talosintelligence.com: Netgear wireless router open to code execution after buffer overflow vulnerability
https://www.talosintelligence.com:
Netgear RAX30 JSON Parsing getblockschedule() stack-based buffer overflow vulnerability
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
AI is getting into all sorts of places but no less than in cybersecurity in both a good way and bad ways. In a good way with bolstering Incident response live cycle but unfortunately in a bad way with generating convincing phishing email or assisting with script and coding etc.
In this week's episode we will focus on how AI is helping IR in getting to the bottom of what might have happened.
Before we get into the main topic, lets touch one important top trending piece of news. And that is:
RedHat warns of a backdoor in a tool used in most of Linux distributions.
https://www.redhat.com: Urgent security alert Fedora 41 and rawhide users
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In our second episode, we continue exploring the concept of adopting a platform security.
In this second part we will continue where we left off from last week and will encourage you to listed to the first episode if you have not done so.
Before we get into the main topic, lets touch one important top trending piece of news this week. And that is:
https://www.cisco.com: XDR- Platform approach to security
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In this episode, we explore the recently much talked about concept of adopting a platform security. As technology advances, cyber criminals continually adapt their tactics. Engaged in a constant cat-and-mouse game, staying ahead is crucial. It begins with a deep understanding of which strategies best align with your objectives, safeguarding not only your digital assets but also your bottom line.
Before we get into the main topic, lets touch a top trending piece of news this week. And that is:
The United States lost record $12.5 billion to online crime in 2023
https://www.ic3.gov:2023 IC3 Report
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It was the LEAP event this past week. LEAP is a technology event in Saudi Arabia, Riyadh and it attracts every technology company imaginable especially in the cyber security domain. This is year was no different.
At LEAP, I met with Port53, a firm that helps from SMB to enterprise businesses with their cyber security mission by delivering enterprise-grade solutions to deploy and management effortlessly.
Before we get into that lets turn to a top trending news this week which
New email scam that targets NTLM hashes
https://port53.com: Port53
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This week I attended Qatar Web Summit. This is a technology and start-up summit held yearly in Doha, Qatar. There were a lot going on and I am lucky to have spent time with the Ken Fee, the CEO of Business Technology Architect shorten as BTA where we talked about security, network optimisation and automation.
Ransomware-as-a-Service attacks increase in Middle East & Africa region
https://techcrunch.com: Feds hack LockBit, LockBit springs back. Now what?
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this episode, we are continuing with part 2 of the risks paused by default configuration. As I said last week, while default config is convenient for initial setup, these settings are may introduce significant security risks that can leave systems vulnerable to exploitation by malicious actors. Please listen to the first episode before you listen to this episode. That way you will get the background and full context of the topic.
Having said that, lets turn to a couple of top trending news this week and they are:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today's interconnected world, default configurations are ubiquitous across various systems and devices, from routers to software applications. While convenient for initial setup, these default settings often harbor significant security risks that can leave systems vulnerable to exploitation by malicious actors. In this episode, we delve into the hidden dangers posed by default configurations, exploring real-world examples and discussing strategies to mitigate these risks effectively. Join us as we uncover the critical importance of securing systems against the perils of default settings.
Before that, lets recap on what is top of mind on the news front.
Your favorite browser might have a feature that defends your home network
https://www.forbes.com: Surprising 3 million hacked toothbrushes story goes viral is it true?
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This is the second episode of our two part episode on whether quantum computing is a threat to cryptography really. Make sure you listen to episode 1 first as we laid the foundation on what is coming up in this episode.
As always lets review this week's top trending security news first.
Google's AI assisted with detection
https://www.computer.org: Quantum Computing
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Cryptography are the backbone of privacy since time immemorial. Toda is THE foundational block of the connected world without which the Internet will crumble as we know it.
There is a feverish discussions happening and fast improving of a new era in computing - Quantum computing, and it is improving year after year taking us ever closer to question the strength of the existing cryptography. So we asked "Is quantum computing a threat to cryptography, really?"
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Accessing and managing various applications and services remotely is a daily occurrence for a typical administrator. It is often the fastest way to accomplish a quick task while you are on the move or say something urgent is needed while you are still on your way to your desk. While that is nothing new, we see an uptick on the number of successful attack taking advantage on these exposed administrative interfaces. What is causing the recent increase in Web UI initial access? Well, that is the topic our episode this week.
I am your host Ibrahim Yusuf
Just before we hit the main topic, lets review a couple top of mind recent news:
UK and US Water Utilities Hit with Cyberattacks
https://www.microsoft.com: Midnight Blizzard guidance for responders on nation state-attack
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
When things go wrong, they go wrong fast. This week will dive into the widespread exploitation on iVanti VPN solution that attracted a lot of attention from both the security community as well as from the bad guys. What went wrong? Stay tuned.
Just before we get into iVanti, lets review the other top security news this week.
SonicWall API attracts attacks that can impacts over 170 thousand firewalls.
https://psirt.global.sonicwall.com: CVE-2022-22274
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
We are continuing demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the terms Exfil or DLP. So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here.
Make sure you listen to part 1 beforehand.
And as alware before we get into the weeds, lets review the recent top trending news this week. These are
Mandiant X account hacked
https://www.bleepingcomputer.com: Decryptor for Babuk ransomware variant released after hacker arrested
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
We will kick off the year with demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the terms Exfil or DLP. So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here.
Before we get into the weeds, lets review the recent top trending news this week. These are
We'll talk about Terrapin and what protocol that is abusing as well.
https://sec-consult.com: SMTP Smuggling, spoofing e-mails worldwide
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.
Well 2023 came and is is now gone, in this final episode we are unwinding the tape to go back to our most popular episodes. If you ever wondered hey what are the most listened to episode. This is the answer. I am sure you will find them beneficial as our listeners did.
We won't cover the latest news this time to give room to the content and it is mostly quiet this time of year and nothing has flared up like some recent years.
Enjoy the recap and the year end!
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.
In our penultimate episode, we will review the twist and turn of 2023. We will go over the trend that stood out the most and both the trends and players behind them throughout he course of year.
Before that, lets review the top security news of this past week:
International authorities disrupts a major adversary infrastructure
https://blog.google: New performance and safety features are coming to Chrome
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Digital inter-connectivity define our era. One of the primary challenges facing supply chain cyber security is the expanding attack surface.
In this week's episode we will turn to Supply Chain Security, how attackers carry out such attacks. We will also look at previous examples and what mitigations can be mounted to prevent these do not happen again.
But before that and as always ahead of the main topic we stop and reflect on the trending news and this week we have two notable security pieces including:
Microsoft's December 2023 Patch Tuesday
https://www.cisa.gov: CISA secure design alert urges manufacturers eliminate default passwords
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
The holiday season is when most of us let our guard down. For the cyber criminal though, it is their hunting season.
In this episode we will give you practical advise on how to stay one step ahead of the miscreants and avoid getting their hands on your sensitive data or cash or both.
To get started, lets review top trending security news this:
New Flaws in Fingerprint Sensors Let Attackers Bypass Login
https://www.crowdstrike.com: How malicious insiders use known vulnerabilities against organizations
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In episode 148 we look inside the mysterious world of the Dark Web. The Dark Web is a hidden area of the internet that is often obscured by mystery and intrigue to many, and it is unlike standard search engines and browsing destination. I will try to deconstruct this covert network and make you aware of what makes it different from the surface web and how it functions. By doing so, we will shed light on its importance and the consequences it bears for today's digital world.
Memory Tagging Extension (MTE) technology by google and partners
https://msrc.microsoft.com: Windows SmartScreen Security Feature Bypass Vulnerability
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
One of the go tools for attackers are Web shells. In this episode we will explore what these are, their background, how they are used and how you can avoid be turned against you.
These deceptive tools bring immense power to the hands of hackers, acting as covert entry door to infiltrate and control the machines that power the Internet, web servers.
Before we get into that, lets review top of mind security news.
Critical bug in OwnCloud file sharing
https://www.enisa.europa.eu: NIS visual tool
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
During Gitex Global in Dubai I sat down with the leaders and founders of Source Technology an organisation based in Swizerland that developed a tool called Source Security. This is ...quote... "technology to integrate behavioral analytics with Symbolic Language that can significantly enhance cybersecurity by providing a deeper understanding of user actions, intentions, emotions, and potential threats.
It also adds a human-centric dimension to threat detection and prevention. It enables organizations to not only analyze patterns of behavior but also understand the emotional context, making it a powerful tool for staying ahead of cyber threats and protecting sensitive data." unquote.
Saudi Arabi arms public sector with Google Cloud services
https://therecord.media: CISA-FBI warn of Scattered-Spider cybercrime group
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
I'm your your host Ibrahim Yusuf
In today's episode, we're shedding light on a critical yet often overlooked aspect of cybersecurity - Indications of Compromise, also known as IOCs. These vital pieces of forensic data can be the canary in the coal mine, alerting us to potential network intrusions before they wreak havoc on our systems.
We'll discuss what IOCs are, why they are essential, and how you can use them proactively to enhance your cybersecurity strategy.
But first, a quick look on what is top of mind in the security news this week.
The source of Okta breach....no price for guessing
https://www.ncsc.gov.uk: Next steps preparing for post quantum cryptography
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Today, we're diving into the world of cybersecurity with an eye to vulnerability scoring system. C We've got a topic that's on the mind of anyone with interest in risk management, one that's of paramount importance to anyone concerned with the safety and integrity of their assets. That's right, today we're talking about the brand-new version of the Common Vulnerability Scoring System, or CVSS v4!
The cybersecurity landscape is constantly evolving, and as threats become more sophisticated, it's essential for the tools and methodologies we use to keep pace. In this episode, we'll explore the latest iteration of CVSS, its key updates, and what it means for security professionals, organizations. Whether you're a seasoned cybersecurity expert or just someone with a keen interest in staying safe online, you won't want to miss this.
Arid-Viper mobile spyware
https://techcrunch.comBoeing cyber incident ransomware gang claims data theft
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
And in today's episode we ponder over how technology continues to reach every aspect of our lives and now the places we call our castles...our homes.
The other week at GITEX I also sat down with Floris Grandvarlet, EMEA Innovation, Sustainability, CTO at CISCO. More that later, but first..... we look at at recent breach and mishaps that left multiple giants in the tech and security industry affected.
Cisco IOS X Web UI Vulnerabilities
https://cybernews.com: Ccleaner confirms data breach
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This was GITEX 2023 Dubai week. GITEX, short for the "Gulf Information Technology Exhibition," is a prominent annual technology event and trade show held in Dubai, United Arab Emirates. It is one of the largest and most influential technology exhibitions in the Middle East, attracting participants and visitors from around the world.
At GITEX I sat down with Eric Vedel Directory of CISO Advisory at Cisco. It is an insightful conversation that you will find practical as it it is filled much needed advise.
Having said that, lets have a look at the top security news this week:
Advancing Cybersecurity: Google's AI-Powered Access Control System
https://www.gitex.com: GITEX 2023
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This is the second part of our Threat Modeling episode. Please listen to last week week's episode, that is episode 140 before you dive into this one.
Having said that, lets have a look at the top security news this week:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode I step through what Threat Modeling is. And yes it a crucial aspect of cybersecurity that is often overlooked. Join us as we explain this concept by carefully examining its definition, and, more importantly, highlighting its effectiveness as a powerful tool in the ever-changing threat, defenses and mitigation.
But before that here are the topics of what is trending this week:
The push to catch up with DMARC
https://blog.google: New Gmail protections for a safer, less spammy inbox
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Today's episode is a continuation of what we've started last week: Initial Access. This is part 2.
And as I said, it truly is the point where the rubber hits the road when it comes to the important stages to look out for during an attack. Thoroughly investigation the Initial Access stage allows us finding how an attacker made their way into our environment.
But before that here are the topics of what is trending this week:
UK's NCSA nudging governments on setting their similar organisation
https://www.europol.europa.eu: Cyber-attacks: the apex of crime-as-a-service (IOCTA 2023)
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today's episode, we're peeling back the layers of cybersecurity to delve into a critical phase of the attack lifecycle: Initial Access. It's the point where the rubber truly hits the road during a cyberattack. We will uncover the strategies, tactics, and technologies involved in gaining that crucial foothold in target systems for both attackers and defenders.
But before that and as always ahead of the main topic we stop and reflect on the trending news and this week we have two notable security pieces including:
MGM and Caesar's response to their ransomware attack.
https://www.europol.europa.eu: Cyber-attacks: the apex of crime-as-a-service (IOCTA 2023)
https://www.reuters.com: Power influence notoriety Gen-Z hackers who struckM-Caesars
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security. And what better way than to cover "Introduction to Cyber Security" in this episode.
But before that, we will recap other trending security news including:
The stolen LastPass vaults may have been cracked
https://securitylab.github.com: Notepad++ pushes out fixes for four security vulnerabilities
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security. And what better way than to cover "Introduction to Cyber Security" in this episode.
But before that, we will recap other trending security news including:
Years-old Microsoft security holes still hot targets for cyber-crooks
https://securitylab.github.com: Notepad++ pushes out fixes for four security vulnerabilities
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In the ever-evolving landscape of digital threats and vulnerabilities, the importance of selecting the right tools for the job cannot be overstated. Just like a skilled craftsman relies on the right tools to create a masterpiece, cybersecurity professionals must carefully choose their tools to safeguard digital asset effectively. Join us as we delve into the world of cyber tool selection and explore how each tool plays a crucial role in fortifying our digital defenses.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
I'm Ibrahim Yusuf, your host, and in today's episode, we're exploring an exciting intersection between generative AI and cybersecurity.
In particular we will look into whether cyber security can benefit from generative AI such as ChatGPT? What about the cyber-crooks, is this helping this too?
All that and more in today's episod.
- www.group-ib.com: Traders' Dollars in Danger: CVE-2023-38831 Zero-Day vulnerability in WinRAR exploited by cybercriminals to target traders
- https://blog.google: Introducing Googles Secure AI Framework
- https://services.google.com: Google AI Red Team
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the second part. Enjoy
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the first part. Enjoy
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In today's episode, we'll explore a critical aspect of endpoint security – the ransomware rollback feature. Ransomware is still a prevailing threat, targeting individuals and organizations alike. To fight back, many endpoint security solutions offer a rollback feature, to mitigate data lost in the first place.
By the end of this episode you will understand its inner working and how it keeps cybercriminals at bay sometimes.
But before that, we will recap other trending security news including:
What is the most exploited vulnerabilities? We will have a look at what the industry's major cyber security agencies agreed?
https://www.hsdl.org: CISA releases its Cybersecurity Strategic Plan, FY2024-2026
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Listen to this very insightful episode on differentiating two important cybersecurity domains that are both intriguing and essential: Threat Hunting and Incident Response.
We all agree that staying one step ahead of cybercrooks is paramount. But what sets these two critical practices apart, and how do they work together to safeguard businesses?
While we at it, we will demystify the key differences between these two cybersecurity corner stones. We'll explore the core principles, methodologies, and objectives that distinguish these two powerful approaches .
But before that, we will recap other trending security news including:
A particular ransomware gangs are taking the usual steps to leak their victim's data on the clearweb sites.
https://news.sophos.com: Sophos discovers ransomware abusing Sophos' name
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
This is another exciting episode of our cybersecurity podcast! Today, we've got a topic that's hot off the press—the newly released Payment Card Industry Data Security Standard version 4, or PCI DSS v4. If you're in the world of payments, data security, or simply curious about the latest in safeguarding your customers' sensitive information, this episode is a must-listen.
In this edition, we'll explore the key updates and changes in PCI DSS v4, the reasons behind its release, and what it means for businesses processing credit card transactions. From enhanced authentication measures to the latest encryption protocols, the new standard promises to fortify data protection and combat emerging cyber threats.
So, get ready to dive into the cutting-edge world of PCI DSS v4 as we unravel the advancements that'll shape the future of secure payment processing. Let's jump right in with the start of this week's top trending news.
https://support.virustotal.com:How it works
https://www.virustotal.com: Upload
https://www.bleepingcomputer.com: Stolen Microsoft key offered widespread access to Microsoft cloud services
https://www.bleepingcomputer.com: Microsoft expands access to cloud logging data for free after Exchange hacks
https://listings.pcisecuritystandards.org: PCI-DSS-v3-2-1 to v4-0 Summary of Changes
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Today, we continue with part 2 the critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it's a data breach, a malware attack, or a network intrusion, incidents can disrupt operations, compromise sensitive information, and damage reputation. That's why having an effective incident response strategy is crucial. In this episode, we'll explore the key principles and strategies behind incident response best practices. We'll discuss the steps organizations should take to prepare, detect, respond, and recover from security incidents.
But before that, we will recap other trending security news including:
https://www.group-ib.com: Digital Risk Report 2023
https://www.sans.org/tools/: The Pyramid Of Pain
https://the-decoder.com/chatgpt-with-no-ethical-boundaries-wormgpt-fuels-ai-generated-scams/
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Today, we delve into a critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it's a data breach, a malware attack, or a network intrusion, incidents can disrupt operations, compromise sensitive information, and damage reputation. That's why having an effective incident response strategy is crucial. In this episode, we'll explore the key principles and strategies behind incident response best practices. We'll discuss the steps organizations should take to prepare, detect, respond, and recover from security incidents.
But before that, we will recap other trending security news including:
Meta's twitter alternative
https://www.sans.org/tools/: The Pyramid Of Pain
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode, we'll explore the fundamental purpose of cyber threat intelligence and why it has become an essential pillar of modern cybersecurity.
Cybercriminals are constantly adapting their tactics, making it crucial for organizations and individuals to stay one step ahead. That's where cyber threat intelligence comes in.
Whether you're a cybersecurity professional looking to deepen your knowledge or an individual seeking to protect yourself in an increasingly connected world, this episode will provide you with valuable insights and practical strategies.
But before that, we will recap other trending security news including:
Who is dominating the ransomeware landscape?
https://www.cisa.gov: 2023 CWE Top 25 most dangerous software weaknesses
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Today we dive deep into the key takeaways of the highly anticipated Version Data Breach Investigation Report.
In a world where data breaches have become all too common, understanding the intricacies and lessons from these incidents is more important than ever. The Verizon Data Breach Investigation Report (DBIR), compiled by a team of expert analysts, provides invaluable insights into the causes, impacts, and preventive measures surrounding a significant breach that rocked the tech industry.
https://www.fortiguard.com: FortiNAC - Argument injection in XML interface on port tcp/5555- https://cve.report: CVE-2023-33299- https://blog.talosintelligence.com: Vendor contractor account abuse-https://www.verizon.com: DBIR
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from
analyst to the C-Suites, in plain english.
In today's episode, we cover two important data models and their applicability to security. I am talking about data lake and data warehouse.
I will look into their similarity, differences and practical considerations surrounding these two popular data storage and analytics approaches.
In doing so I will leave you with a clarity on which option if not both are used when combating cyber attack.
But before that, we will recap other trending security news including:
https://jetpack.com: JetPack Critical Security Update
https://krebsonsecurity.com: Microsoft Patch Tuesday June 2023 Edition
https://www.splunk.com: Data warehouse vs. Data Lake
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
This is episode 2 of on how how exactly cybercriminals join forces for profit. Make sure you caught up with episode 1 first before you listen to this episode.
Lets continue demystifying their collaborative nature.
But before that, we will recap other trending security news including:
Cisco Releases Updates to Fix AnyConnect Privilege Elevation Vulnerability
https://community.progress.com: MOVEit Transfer Critical Vulnerability
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
It is true, there is no loyalty between criminals but there is a profit to be made between them.
How exactly cybercriminals join forces for profit?
We will answer that question in this week's episode as we uncover the secret collaborations of cybercrime and delve into the intricate web of connections, strategies, and specialized roles in the world of cybercrime. From hackers to phishers and money mules, we'll demystify their collaborative nature.
But before that, we will recap other trending security news including:
A wave of SMS Phishing Campaign Aimed at a Middle Eastern Country. We'll find out more about this.
https://www.e ropol.europa.eu: Joint Cybercrime action Task force
-https://www.darkreading.com: PostalFurious sms attacks target UAE Citizens data theft
-https://blogs.windows.com: Announcing Windows 11 insider preview build-25381/
-https://techcommunity.microsoft.com/How to defend users from interception attacks via SMB client
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
The ATT&CK Navigator is a web-based tool created and maintained by the Mitre organisation. The tools is used for annotating and exploring ATT&CK matrices. It is often used to visualize defensive coverage, red/blue team planning, the frequency of detected techniques etc.
That is the topic of our show today.
In addition, we will recap other trending security news including:
Microsoft secure boot bug
https://arstechnica.com: Microsoft patches secure boot flaw but wont enable fix by default until early 2024
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In this week's episode we will continue with Part 2 on Demystifying Digital Certificates.
To take the most out of this week's episode - If you have not listen to Part 1, I suggest you listen to the first before you listen to this episode.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In this episode, I want to shine a brigt light on an important yet frequently misunderstood part of online security: digital certificates. Certificates are essential in today's digital world for safeguarding communication and confirming identities. Nonetheless, they are frequently obscure to many, resulting to confusion and misunderstandings. Join us as we demistify digital certificates, examine their importance, and explain their role in guaranteeing safe and the ever dependable digital communication.
In addition, we will recap other trending security news including:
- https://www.kali.org: Kali-linux-2023-1-release/
- https://support.apple.com: Apple Rapid Security Response
- https://www.ibm.com: Overview of Digital Certificates
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In the second part of the podcast, we'll delve further into the different types of email security protocols and explore how they can be implemented to enhance the security of your email communications. We'll discuss the benefits of end-to-end encryption, which ensures that only the intended recipient can access the content of your emails, as well as the importance of authentication mechanisms. We'll also explore the role of digital signatures in verifying the authenticity and integrity of email messages. By the end of this episode, you'll have a better understanding of how to protect your sensitive information from cyber threats and ensure the confidentiality of your email communications.
If you have not listen to episode 1, I suggest you listen to the first before you listen to this episode.
In addition, we will recap other trending security news including:
Mirai-iot-botnet is exploiting-tp-link-router you need to patch it now
https://users.ece.cmu.edu: PGP intro
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In the era of messaging apps such as WhatsApp, Telegram and Twitter, emails are still the primary mode of communication for businesses and goverments alike. However, the convenience and ease of email communication also come with significant risks such as phishing, malware attacks, and unauthorized access.
This show aims to provide insights into various email security protocols such as encryption, authentication, and digital signatures, and how they work together to protect your email data from cyber threats.
Join me as I explain the intricacies of email security and uncover the best practices for safeguarding your online communications.
In addition, we will recap other trending security news including:
Cisco unveiled a compelling net new product XDR
https://www.bankinfosecurity.com: Final Review RSA Conference 2023
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In this week's episode we will continue with Part 2, by continuing at exploring the complex world of data classification systems and the ongoing difficulty of preventing data leaks.
If you have not listening to Part 1, I would encourage you to back to the firest episode before you jump no this one.
In addition, we will recap other trending security news including:
Open letter to the UK Gov regarding their Online Safe Bill
https://blog.whatsapp.com: An Open letter
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In this week's episode, we will explore the complex world of data classification systems and the ongoing difficulty of preventing data leaks in extremely sensitive settings. Even after putting in place reliable classification protocols, extremely sensitive organisations still have to deal with ongoing threats to their most important data. In this podcast, we'll look at the fundamentals of data classification, their origin and evaluate the systems in use. We will talk about the underlying causes of data leaks, which are still a major issue.
In addition, we will recap other trending security news including:
Google launches a new cybersecurity initial. We will look what that entailes
https://www.washingtonpost.com: FBI public phone charging stations juice jacking- - https://www.fcc.gov: Juice jacking dangers public USB charging stations
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In today's digital world, businesses face an increasing number of cyber threats that can disrupt their operations and affect their bottom line. That's why it's more important than ever to have strong security measures in place to protect your organization
In this episodee, we'll discuss how strong security measures can not only protect your business from cyber threats but also enable continuity and resilience.
In addition, we will recap other trending security news including:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Cloud computing has become a ubiquitous part of business, but it presents unique security challenges. In this podcast, we'll take a closer look at public, private, and hybrid clouds, discussing the benefits and risks of each so that you are well informed on securing your data and applications in the cloud. This is going to be engaging as it is informative session on navigating cloud security.
The United Kingdom’s National Crime Agency (NCA) sets up a fake DDOS for hire service
https://www.cisco.com: What is cloud security
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In this podcast, we will continue exploring the technical details of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet.
I would suggest you listen to last week episode first before you listen to this session.
In addition, we will recap other trending security news including:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In this podcast, we will explore the technical intricacies of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet.
OAuth stands for "Open Authorization". It is an open standard for authorization that allows users to grant access to their resources, without sharing their credentials (such as username and password) with third-party applications. OAuth is commonly used by social media platforms, APIs, and other web services to allow users to log in or grant access to their accounts without the need for the application to store their sensitive login information.
Whether you're an experienced cybersecurity professional or a curious learner, join me as we analyze the underlying principles of OAuth, its different implementations, and its role in shaping the future of online security.
In addition, we will recap other trending security news includes:
https://www.linkedin.com: My interview with event organiser
https://oauth.net: OAuth
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Threat intelligence is crucial in today's cyber landscape to identify and mitigate potential risks before they can cause damage. It involves gathering and analyzing information about potential threats and attackers, allowing organizations to stay one step ahead of cyber threats. Join us on "Know Your Enemy: Why Threat Intelligence Matters" to learn more about the importance of threat intelligence in keeping your data and systems secure.
In addition, we will recap other trending security news includes:
-https://blogs.windows.com: Introducing LSA Protection Enablement on Upgrade
- https://www.cisco.com: The importance of Threat Intelligence and how
Cisco Talos uses intelligence to protect customers
- https://blogs.cisco.com: Threat intelligence SecureX API
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Remember when the Internet was unencrypted? Yes, there was a time when security was the exception rather than the default. That is to say the majority of the Internet traffic was served over HTTP rather than HTTPS.
Fastfoward to today and it is unconceivable to access any website without the lock sign on the browser url field. That is because privacy by way of using encryption became a thing to protect us from prying eyes ready to steal your private information. Unfortunately, the same tool -encryption that is, provide a cloak for the the crooks to hide their malware and other navarious artifacts inside the encrypted traffic. How do you find these malware in an encrypted traffic without decrypting it? That is the topic of the today's episode.
In addition, we will recap other trending security news includes
Google's gmail client side encryption is now publicly available
https://support.lastpass.com/help: Incident 2 additional details of the attack
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
In today's hybrid world it is important to take your home network security seriously. After all what happens at home can crawl its way to to the corporate network. In today's episode we look at some measure you should take to mitigate most of the risks introduced by lax or non-existing security hygiene.
In addition, we will recap other trending security news includes:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
When a vulnerability is discovered, reported ang assigned a score called a CVE its impacts must be understood beyond the CVE number. A common method information security specialists use for this process is the Common Vulnerability Scoring System (CVSS). That is the topic of this week episode.
In addition, we will recap other trending security news includes:
Cisco issued a fix for ClamAV
https://sec.cloudapps.cisco.com: ClamAV HFS+ Partition Scanning Buffer Overflow Vulnerability Affecting Cisco Products: February 2023
https://cve.mitre.org: CVE-2023-20032
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Ensuring an optimum setup of your toolsets is a critical part of the your ongoing mitigation effort.
Is this episode we will look at the do's and don't of setting up your endpoint detection and response:
- www.nist.gov: NIST Selects ‘Lightweight Cryptography’ Algorithms to Protect Small Devices
- csrc.nist.gov: Lightweight Cryptography
- www.theregister.com: Uncle Sam wants to strip the IoS out of IoT with light crypto
- www.zdnet.com: Tiny IoT devices are getting their own special encryption algorithms
- www.cisa.gov: ESXiArgs Ransomware Virtual Machine Recovery Guidance
- github.com: ESXiArgs-Recover
- www.theregister.com: Among the thousands of ESXiArgs ransomware victims? FBI and CISA to the rescue
-https://blogs.cisco.com: An easier way to secure your endpoints
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
Password security is an essential aspect of online safety. You and I know, remembering all the passwords can be overwhelming. This is where password managers come in, providing a convenient and secure means keep your password in one place. However, with the recent breach at LastPass, it's important to understand the potential risks and take the necessary steps now in the event of a password manager breach. Why, because once it is breached it is too late. In this article, we will explore the measures you can take to prepare yourself for a password manager breach and keep your online accounts secure.
In addition, we will recap other trending security news includes:
Microsoft is urging organisation with Exchange on premise to patch sooner rather than later
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
We will continue last week's topic on "What is Netflow Protocol used for". This is part 2. If you have not listen to last week's show, I suggest you listen to Part 1 first.
In addition, we will recap other trending security news including:
-https://therecord.media: Pakistani authorities investigating if cyberattack caused nationwide-blackout
- https://www.goto.com/blog: Our response to a recent security incident
- https://ipcisco.com: Netflow and Netflow Configuration
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
This week, lets have look at one of those protocols that often under-used by analyst. It is a way to look at the data that traverse your network to pinpoint what might be lurking beneath the surface. We will cover this in two parts. This is part 1. More on that later.
In addition, we will recap other trending security news includes:
Old Cisco Routers susceptible to RCE attack
https://sec.cloudapps.cisco.com: Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Vulnerabilities
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
As a security analyst, you investigate. You want to query devices as part of your investigation of security incidents or maybe you are working to determine the effectiveness of a security control. So you always need real-time, granular inventory data about the systems you want to look at.
In this week's episode we touch one of those tools that makes a security analyst's life a lot less painful: OSQuery.
In addition, we will recap other trending security news, including:
-https://personal.help.royalmail.com: Service Update
- https://www.telegraph.co.uk Parcels letters stuck limbo royal mail hit suspected hack
- https://arstechnica.com/information-technology: ChatGPT is enabling script kiddies to write functional malware
- https://openai.com: ChatGPT
- https://www.osquery.io: OSQuery
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.
I hope you had a good start with 2023!
Our first episode of the year is all about the Red Teaming tools. We will look at an open source testing and validation library call Atomic Read Team.
In addition, we will recap other trending security news includes:
Amazon S3 will now encrypt all new data
https://aws.amazon.com: Amazon S3 encrypts new objects by default
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome to YusufOnSecurity episode 100! Perfect timing to finish off the year with the 100th episode!
As it is customary and being the end of the year, we will go back to the best of 2021 episodes. There are quite a few popular ones. Enjoy!
Just last like last year the YusufOnSecurity podcast kept me in cadence on this fast evolving threat landscape. I learned a great deal of stuff while researching and putting the past 52 episode together. I hope it help you some ways too.
On to another year!
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
2022, what a year it has been! in our 99th episode which nicely coincides the year end we are look back at the rear view mirror to revisit the big cybersecurity events. so bacle up because it will be an eventfull listening!
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is often said, attacks are when and not if they will happen at all. However, when they happen what matters is how hard you fall, scope and recover.
In this week's episode, I will talk about the steps taken by attackers when they successfully breach organisations so that you can limit the damage and recover faster.
In addition, we will recap other trending security news includes:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome to YusufOnSecurity episode 97. Yes we are nearly at the grand number of 100!
This week I am talking about privilege escalation. It is the critical step during an attack and it is vital to understand how the bad guys pull this off. By understand their the methods and some the tool used, you will hopefully minimise their success on using this technique and limit the damage that may ensue otherwise.
In addition, we will recap other trending security news includes:
Leaked Signing Keys Are Being Used to Sign Malware
https://attack.mitre.org: MuddyWater
-https://blog.talosintelligence.com: Muddy Water targets turkey
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome to YusufOnSecurity.
Making use of what resources you have is an import aspect of technology use whether that is virtualisation or containarisation. But it is important to understand the impact the choices you make have on security. Are containers more secure? That is the questions of this week's episode.
In addition, we will recap other trending security news and this week we look at:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome back once again!
Complexity is the greatest challenge in cyber security. With millions of software applications, services, and systems in use today, each one has its own features and use cases independently: It is called the silo dilemma. With exchanging information, they can never hope to have meaningful common use cases or act as a coherent solution.
So, in the face of increasing complexity and a lack of universal vendor to vendor integration, what can you do? For many organizations, the answer is to use a REST API. But what exactly is a REST API, and why do you need care.
In addition, we will recap other trending security news includes:
Zeppelin Ransomware Decryptor
https://securityintelligence.com: Ransomexx upgrades Rust
Fo the majority of enterprises, security can turn out to be extremely challenging, especially with the move to remote and/or hybrid work and the current geo-political tension.
The International Information Systems Security Certification Consortium also known as (ICS)2, estimates that 23% of companies have seen an increase in cybersecurity incidents since they’ve asked their employees to remote work.
Cyber security skill sets are always in demand, and most organizations do not have the capability to attract good talent. So, is MSSP the right move for you?
In addition, we will recap the week's top trending security news.
-https://blackhatmea.com: BlackHatMEA
-https://www.mitre.org: Mitre engenuity publishes attack evaluations security service providers
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Attackers target the weakest link. Lately though there is one tool that is in their cross-hair: MFA.
MFA has been a torn on the side of the cyber crooks and they up their anti-to come up ingenious way to circumvent it. How do they do it. This is the topic of this week's episode.
In addition, we will recap the week's top trending security news:
Scanning the internet for fun and profit. The National Cyber Security Centre (NCSC) has a project to scan the UK's Internet.
https://https://dropbox.tech: How we handled a recent phishing incident that targeted Dropbox
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Cyber security roles are in demand. Everyone talks about this fact. So I often asked "How do I security in cyber security"?
I will cover this question in this week's episode and provides some pointers to would be new starter in Cyber Security.
In addition, we will recap the week's top trending security news.
Mastodon, the new micro blogging.
https://en.wikipedia.org: Mastodon
-https://www.bleepingcomputer.com: Mastodon now has over 1 million users amid twitter tensions
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Every organisation goes and purchase the tools they thing is good for the job. Often, some rotated the installation of their security products every 2 to 3 years or when they think it is starting to fall behind in features and detection capabilities. All these are well and good but very few organisations test the effectiveness of the tools they installed. That is where validation comes in and it is our topic of the week
In addition, we will recap other trending security news includes:
-https://twitter.com: Critical CVE out next Tuesday
-https://www.openssl.org: OpenSSL
-https://www.cisco.com: Technical Alliance Partners
-https://www.sans.org:Continuous security validation
-https://i.crn.com:Security Validation Platform
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In our journey to a more secure posture, zero trust is talked about a lot. The question most businesses usually ask is where do you start. After all ZT is not a product but a framework to a better posture day in and day out. This is our topic of the week.
In addition, we will recap top of mind trending security news including:
-https://labs.withsecure.com: Microsoft Office 365 message encryption insecure mode of operation
-https://learn.microsoft.com: Message Encryption
-https://www.educative.io: What is ECB?
- https://www.n-able.com: Understanding AES 256 Encryption
- https://www.microsoft.com: Microsoft- 365 FAQs
- https://blog.talosintelligence.com: Quarterly report incident response
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, thanks for tuning in!
Waow, have a good a great content for you! I am in Dubai and it is the Gulf Information Technology Exhibition week, short for GITEX 2022. I think they named it Gitex Global this year.
It's been a week filled with sampling cool cyber security tools and technology as well as meeting like minded techies from around the world. I will let you listen as I interacted with some of those security practitioners.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Here is one of those memes related to the topic du jour "Someone once told me that none of us are actually afraid of the dark; we're scared of what it conceals from us. We're afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too." Well this week we will cover not so talked about topic: Insider treat.
In addition, we will recap other trending security news including:
- https://www.zdnet.com: Got hit by a cyber attack hackers will probably come after you again within a year.
-https://www.cisa.gov: Defining-insider threats
- https://scholarworks.waldenu.edu: Insider Threats' Behaviors and Data Security
Management Strategies
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Here is one of those memes related to the topic du jour "Someone once told me that none of us are actually afraid of the dark; we're scared of what it conceals from us. We're afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too." Well this week we will cover not so talked about topic: Insider treat.
In addition, we will recap other trending security news including:
- www.bleepingcomputer.com:
-https://www.cisa.gov: Defining-insider threats
- https://scholarworks.waldenu.edu: Insider Threats' Behaviors and Data Security Management Strategies
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome back once again!**
Security teams face an ongoing challenge: how best to collect event data from all of their tools and infrastructure - network, endpoint and anyting in between. The critial part being how to turn this mass of data into threat intelligence to prevent or stop the next cyber attacks. This is the topic of this week's episode.
In addition, I will mention few security news and draw some useful conclusions out of them.
- techcommunity.microsoft.com: Tamper protection will be turned on for all enterprise customers
- www.govinfosecurity.com: Iranian Hackers Accessed Albania's Network for 14 Months
- www.cisa.gov: Alert (AA22-264A) Iranian State Actors Conduct Cyber Operations Against the Government of Albania
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome back once again!
In our march to architecting a solution approach to security, today we will talk about one such approach. The network and how the data that flows through can help paint a picture to help us gain more visibility into what is lurking beneath the surface.
In addition, we will recap one important security news for your downloaders out there:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com](https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective & causing further damage until you kick them out.
That is the topic of this week's episo, in addition, we will recap one
trending security news includes:
-https://blogs.cisco.com: Network analytics what you can't see you can't control
- https://www.paypal.com: How to spot a fake PayPal Email
- http://www.pentest-standard.org: Post Exploitation
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at
When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective & causing further damage until you kick them out.
That is the topic of this week's episo, in addition, we will recap one
trending security news includes:
PayPal Phishing Scam Uses Invoices Sent Via PayPal
https://www.paypal.com: Common scams
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Bringing one outsider into your network can introduces many but if you deal something as complex as supply chain it can appear as a daunting task. It does not have to be though; With adequate due diligence and basic hygiene, you can stay one step ahead of the bad guys. Lets see how you go about this in this this week's episode.
In addition, we will recap a couple of this week's trending security news, includes:
- blog.lastpass.com: Notice of Recent Security Incident
- www.theregister.com: LastPass source code, blueprints stolen by intruder
- www.cyfirma.com: Thousands of Hikvision Cameras are still vulnerable and can be potentially exploited (PDF)
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
While we wait for a passwordless future, it is paramount you limit exposing and leaving your password in many places. I deliberately chose the title of this episode to draw attention of this fact. I will go over the many place we often put our password in the quest for convenience over security. There are lessons of how me make these choices.
In addition, we will recap a couple of this week's trending security news, includes:
- https://www.bleepingcomputer.com: Over 9-000 VNC servers exposed online without a password
- https://www.theverge.com: USB Rubber Ducky review
- https://www.nytimes.com: The secret life of passwords
- https://haveibeenpwned.com: Have I Been Pawned?
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This is part 2 of our two part series on "How machine learning helps the cybersecurity industry".
If you have not listen to part 1, we recommend you go back to the previous episode.
In addition, we will recap other trending security news includes:
Black Hat 2022: Few presentations that you might find particularly interesting
www.theregister.com: Slack leaked hashed passwords from its servers for years
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
As the adage we grew up with goes, "you cannot predict the future but you can be prepared for it". Predicting the future is exactly what we do everyday to stay one step ahead of malware attack. For instance the industry has put a great deal of work on taking advantage of Machine Learning, but what is Machine Learning anyway and how does it help us in everyday situation? This is the topic of this week's episode.
In addition, we will recap other trending security news includes:
-https://blog.virustotal.com: Deception at scale
-https://www.cisa.gov: Top malware strains of 2021
-https://cset.georgetown.edu: Mmachine learning and cybersecurity
-https://discover.cisco.com: AI whitepaper
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites. In plain english.
Malware can hide but it must run. Yes, in the cat and mouse game between cyber crimal and defenders, the threat landscape is constantly shifting.
Malware's tactics to evade detection tools include the topic of this week's episode, going fileless.
We will cover what file-less malware is, how different it is from other typical malware that you might be aware.
In addition, we will recap other trending security news, including:
-https://www.apple.com/newsroom: Apple expands commitment to protect users from mercenary spyware
-https://blog.talosintelligence.com: What Talos incident response learned
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
As a craftsperson, you would not excel in your chosen trade without the right tools. Even better, you need to carefully select those tools, sharpen them when they become blunt and upgrade them when new ones come around that will improve your work.
Cyber security is no different, we need well calibrated machinery to use in our defensive strategy.
In this week's episode, we will look at some of the right tools and methodology to protect your bottom line.
In addition, we will recap other trending security news, including:
All that, coming up next, on YusufOnSecurity!
-https://www.sonicwall.com: Security notice Sonicwall GMS SQL injection vulnerability
-https://www.redpacketsecurity.com: Sonicwall Global Management System GMS and analytics SQL injection CVE
-https://www.cisa.gov/shields-up: Shields Up
-https://threatpost.com: Callback phishing campaign impersonate security firms
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This week's episode is about what is giving us privacy at the heart of security, that is encryption algorithm. As computer power and speed improves so is the danger of these algorithm being broken. We need alternatives that can withstand them being compromised. We need resistant algorithms.
In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach this pressing issue.
-https://www.microsoft.com: From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
- arstechnica.com: Ongoing phishing campaign can hack you even when you’re protected with MFA
- support.lenovo.com: Lenovo Notebook BIOS Vulnerabilities
- www.bleepingcomputer.com: New UEFI firmware flaws impact over 70 Lenovo laptop models
-https://www.nist.gov/news-events: NIST announces first four quantum resistant cryptographic algorithms
-https://www.pqsecurity.com: Post Quantum Standardization Discussion paper
Be sure to subscribe!
If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too
Companies come in different sizes and complexity and they face different challenges but also demand various level of mitigations that meets their obligation.
In this week's episode, lets take a step back and look at how we approach security and how can this be improved.
In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach to security.
-https://en.wikipedia.org: OpenSSL
-https://www.cvedetails.com: CVE-2022-2274
-https://thehackernews.com: OpenSSL releases patch for high
-https://www.nist.gov/news-events: NIST announces first four quantum resistant cryptographic algorithms
-https://www.pqsecurity.com: Post Quantum Standardization Discussion paper
- https://www.nationwidesecuritycorp.com: Benefits integrated security
Be sure to subscribe!
If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too
In this week's episode, I will continue with PowerShell and dwell a bit more on logging. If you have not listen to to last week's episode, I would suggest you do that first.
Before that though, let's recap few topics that worth your attention. They might help you mitigate more risk to your business.
Up next!
-https://chromereleases.googleblog.com: Google Chrome 0-Day
https://duo.com/decipher/zuorat-malware-found-hitting-home-routers
-https://blog.talosintelligence.com: VPN Filter
-https://docs.microsoft.com: PowerShell loggings
Be sure to subscribe!
If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too
Often times, organisation focus on technology, procuring the next shinny things in the market or the leading products according to analyst, peer review or testing labs. Although there is not thing wrong with, there is one important ingredient that are mostly overlooked: a well structure, efficient security team. This is what we will cover this week.
In addition, we will recap other trending security news includes:
All that, coming up next, on YusufOnSecurity!
Be sure to subscribe!
If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too
The one constant them of this ever expanding threat landscpare is the creativity of the cybercrooks and their ability of improvising existing tools and techology. One case in point is the use of a combination of HTML5 and JavaScript to avade existing business defenses.
Other top top trending security news include:
Follina is Being Actively Exploited to Spread Malware
www.securityweek.com: 'Follina' Vulnerability Exploited to Deliver Qbot, AsyncRAT, Other Malware
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Most business rely on an old fashioned approach to security. A hard on the outside and soft on the inside. In this episode we will look at why that can be dangerous in today pervasive connectivity and work from anywhere concept.
Additionally, we will recap other top trending security news that are most pertinent today:
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
The more we learn, the more we know how less we know.
In this episode we will cover important takeaways of the recently release Virison Data Breach Investigations Report. There are key points to be mindful of.
In addition, we will recap other top trending security news, including
RCE on Microsoft Diagnostic Tool (MSDT)
CISA adds more exploited vulnerabilities to the Catalog
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In a world where everyone...well most, wants to snoop into your privacy, we asked how one sends and receives ones email in an encrypted format. After all email is not build fro privacy. Click send and, and it is as you posted a postcard! With some effort a dedication, a privacy hungry miscreants can watch your messages go by in clear text.
Also coming up, a couple of pertinent recent security news: these are
- docs.microsoft.com: Windows 11 known issues and notifications
-https://www.zdnet.com: Microsofts out of band patch fixes Windows AD authentication failures
- www.theregister.com: Your snoozing iOS 15 iPhone may actually be sleeping with one antenna open
- arstechnica.com: Researchers devise iPhone malware that runs even when device is turned off
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Attack Surface is talked about a lot but it means different things to different people. This is what we will step through this week.
Also coming up, a couple of pertinent recent security news: these are
Apple Mail Now Blocks Email Trackers
https://blog.talosintelligence.com: Bitter APT adds Bangladesh to their targets
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome back.
Given the prevalence of security holes in software and the constant shifting of the threat landscape, it is paramount that organisation carry out periodic exercises that test their security preparedness. And that is exactly what we will dive into this week.
Also coming up, few pertinent security news this week:
-https://www.nozominetworks.com/blog: Nozomi networks discovers unpatched DNS bugin popular C standard library putting IoT at risk
- www.zdnet.com: Google, Apple, Microsoft make a new commitment for a "passwordless future"
- www.bleepingcomputer.com: Microsoft, Apple, and Google to support FIDO passwordless logins
-https://csrc.nist.gov: Security assessment
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Welcome to YusufOnSecuriy, a weekly cyber security podcast where we look at the most relevant security news of the week and follow up with a deeper look at a carefully selected cyber security domain.
In this week's episode we will continue digging into the software errors and their consequences, vulnerabilities and exploitation. I said it is part of life but it does not has to stay that way.
Also coming up, are a number of security updates this week. These are:
-www.google.com: New options for removing your personally identifiable information from Google Search
-www.cloudflare.com: Cloudflare blocks 15M rps HTTPS DDoS attack
-www.sans.org: SANS top 25 dangerous software errors of 2021
-https://cwe.mitre.org: 2021 CWE Top 25 Most Dangerous Software Weaknesses
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Vulnerabilities is part of life. It is even more so in the cyber world. This week we will look in to the type of vulnerabilities that are there. Once thing is for sure, they are not all exploited equally. Some are more damaging, others take time, resources and perseverance to pull them off. Simply put they are part of the firebrick of modern technology.
Also coming up, a number of security updates, including this week
-Google Project Zero tracked a record exploited in the wild
-Microsoft Windows Autopatch
-https://googleprojectzero.blogpost.com: Google Project Zero tracked a record exploited-in-the-wild
-https://docs.google.com: 0day "In the Wild" sheet
-https://thehackernews.com: Google project zero detects record Zero-Day exploits in 2021
-https://techcommunity.microsoft.com: Get current and stay current with Windows Autopatch
-https://www.sans.org: Top 25 software errors
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, I welcome you to the show in this fine April day.
I talk a lot about cyber security for businesses and enterprises at large but about the individuals; they too suffer the consequence of cyber attacks aren't they? Well that is what I will cover this week: how do you go about your day to day usage of technology and the internet in particular while staying safe from the cyber crooks?
Also coming up, a couple of top of mind security updates:
- Ransomware gangs operate just like a business
- A new versatile malware toolkit against Industrial Control System emerged
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome back.
Often it is not about what came in but rather what has been left behind. This week we willl continue our introduction to digital forensics and what is involved when carrying out this painstaking process. In this episode, we will go one level down into the details. So bucle up!
Also coming up, a couple of pertinent security news that you might find relevant, including:
The cyber crooks are using fake police data requests against tech companies
https://thehackernews.com: First malware targeting AWS Lambda Serverless Platform discovered
https://krebsonsecurity.com: Hackers are obtaining sensitive data through fake emergency requests
https://www.volatilityfoundation.org: Open Source Forensics tools
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome onboard to this week's show.
Often it is not about what came in but rather what has been left behind. This week we will look at introducing digital forensics and what is involved when carrying out this painstaking process.
Also coming up, a couple of pertinent security news that you might find relevant, including MITTRE Evaluation round 4 is out. Gitlab vuln that might need your attention.
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this week's episode, I am bring you coverage from Gulf Information Security Expo & Conference (GISEC) 2022 Dubai. GISEC is a security focus version of GITEX the "Gulf Information Technology Exhibition" that is held in October each in Dubai where thousands of exhibitors and ten of thousands of visitors decent each year in October.
Also coming up, a couple of top of mind security news that caught the eyes of many:
-https://www.vice.com: Microsoft Investigating Lapsus$ Hacking Claims
- https://media.fidoalliance.org: FIDO Alliance’s Vision for Passwordless Authentication
-https://www.gisec.ae: GISEC 2022 Dubai
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for you yet another YusufOnSecurity episode. Welcome back.
This week I will have a look at the important topic of remote access. I think you will agree that this is top of mind for CISO and any C-suite that cares about the bottom line of their business.
Also comping up:
Microsoft Releases Scanner to Detect TrickBot-Infected Devices
Internet Explorer 11 is Being Retired in June
- www.microsoft.com: Uncovering Trickbot’s use of IoT devices in command-and-control infrastructure
- www.theregister.com: Has Trickbot gang hijacked your router? This scanner may have an answer
- docs.microsoft.com: Internet Explorer 11 desktop app retires June 15, 2022
- techcommunity.microsoft.com: Internet Explorer 11 desktop app retirement FAQ
-www.cisco.com: Secure Access
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this weeks' show, lets turn our attention to an ever increasing army of small things which are becoming more pervasive: Internet Of Things.
Also coming up, a number of updates including:
A couple of leaks and this time from the good side unfortunately - Nvidia and Samsung
A firefox emergency update. Browsers are the windows to the internet for many. So it is important that they get the attention they deserve.
- www.theregister.com: Leaked stolen Nvidia cert can sign Windows malware
- www.scmagazine.com: Samsung confirms Galaxy device source code leaked after breach
-www.blogs.cisco.com: iOT Security
-https://www.gartner.com: iOT security primer challenges and emerging practices
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this weeks' episode I will look into demystifying the concept of XDR. I will try to do just to compare and contrast with other technology that came before it: SIEM and SOAR in particular.
But before that, and as always I have a few update for you this week on what to keep an eye on.
Canti ransomware leaked a treasure trove of chat communication
Hive Ransomware encryption succumb to academic analysis
http://krebsonsecurity.com: Conti ransomware group diaries
https://cyberintelmag.com: Hive ransomware master key recovered
http://www.cisco.com: What is XDR?
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this episode lets have a look at an important aspect of security, one that is becoming a battle ground lately: identity and authentication.
As always I have a fews update for you this week on what is churning lately including:
-https://blog.talosintelligence.com: Threat Advisory Cyclops blink
- www.wired.com: Russia’s Sandworm Hackers Have Built a Botnet of Firewalls
-https://www.euronews.com: Is Russia using cyberattacks in the war with Ukraine and could sanctions provoke more of them?
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This is part 2 of a two parts episode where I am covering Lessons from the Irish Health Services Executive Hack. If you have not listen to part 1, please do so. In part 1, I gave the introduction to the incident and other related background details.
As always I have a fews update for you on what is in news this week. This including:
-U.S. Cybersecurity Agency Publishes List of Free Security Tools and Services
-Google’s Project Zero 2021 Metrics
-https://www.cisa.gov: Free tools from CIS for the public and private sector
- googleprojectzero.blogspot.com: A walk through Project Zero metrics
-https://www.hse.ie: Conti cyber attack on the HSE full report
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
This is a two part episode and my goodness is it loaded with useful technical details. Additionally I'll look at at two particular security updates pertaining to the most popular platform when it comes to operating systems: Windows! Microsoft took important steps forward in reducing the surface of attack. All that before we get into the meat of the matter for today: lessons learned from the Irish HSE
-https://docs.microsoft.com: WMIC
-https://docs.microsoft.com: Internet macros blocked
-https://docs.microsoft.com: Windows10 deprecated features
-https://www.hse.ie: Conti cyber attack on the HSE full report
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this episode I will delve into the vulnerability measuring and scoring metrics, the subsets of those and the why and how these are used. An important knowledge to be had if you are responsible of security pertaining to a SOC/RISK or Security teams.
In addition, we will recap other top trending security news including:
-ESET antivirus bug leads to system privilege gain.
-O365 and Azure AD were target of billions of brute-force attacks
Here are useful resources related to this episode:
-https://support.eset.com: Local privilege escalation vulnerability fixed in ESET products for windows
-https://www.bleepingcomputer.com: ESET antivirus bug let attackers gain windows system privileges
- https://news.microsoft.com: Cyber Signal
- https://www.zdnet.com: Strong authentication protects against phishing so why aren't more people using it
- https://www.kennasecurity.com/blog: Vulnerability scores and risk scores
- https://www.first.org: CVSS
- https://www.recordedfuture.com: CVSS scoresguide
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
The episode before last, we've looked at the Malware targetting the Mac world, this time we will look at the other side of the fense, the Linux echo systems.
The linux platform is the one operating system business rely on for their mission critical applications regardless whether they are on-premise, cloud native or somewhere in between i.e. hybrid.
Yusuf on Security is 1 year old! Time flies when you are talking security every week for 52 weeks consecutively. And in doing you are informing the people.
https://www.centos.org: CentOS end of life
https://thehackernews.com: Patching the CentOS Encryption is urgent...
- arstechnica.com: Google drops FLoC after widespread opposition, pivots to “Topics API” plan
- blog.google: Get to know the new Topics API for Privacy Sandbox
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Attackers are resorting to way to cut corners. In doing so they cleverly are increasing their ROI while at the same time keeping pace with technology advancement
With a new finding by Cisco Talos, we will look into a new campaign employing remote access trojans (RAT), not one or two but three variants of RAT!
-https://www.cisa.gov: Implement Cybersecurity Measures Now to
Protect Against Potential Critical Threats
-https://thehackernews.com: Experts Find Strategic Similarities b/w NotPetya and WhisperGate Attacks on Ukraine
- https://blog.talosintelligence.com: Nanocore, Netwire and AsyncRAT spreading campaign uses public cloud infrastructure
- https://blog.talosintelligence.com: WhisperGate
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this show I will have a look at the recent feature to Apple's ecosystem and in particular the Private Relay.
In addition, we will recap other top trending security news which includes poisoned USB drives are sent to businesses and REvil ransomware gangs allegedly arrested by Russian agents.
-https://therecord.media: FBI - FIN7 Hackers target US companies with BadUS- devices to install ransomware
-https://en.wikipedia.org: REvil
-https://thehackernews.com: Russia arrests REvil ransomware gang
-https://www.macworld.com: icloud plus private relay Safari vpn encryption privacy
-https://support.apple.com: About iCloud Private Relay
-https://developer.apple.com: Technical presentation video on Private Relay
sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this episode we will look at a growing threat facing the Mac world. While not attacked as much as Windows platform, the signs are showing Mac is indeed not unvulnerable
Before we get into the main topic, lets have a look at a couple of trending security news. This will we briefly talk about Norton 360 which brings you a crypto-mining feature and an important bug patched by VMWare.
-https://krebsonsecurity.com: Norton 360 now comes with a cryptominer
- threatpost.com: Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover
- www.vmware.com: VMware Workstation, Fusion and ESXi updates address a heap-overflow vulnerability (CVE-2021-22045)
-https://vuldb.com: Vulnerability database
-http://objective-see.com: The Mac Malware of 2021
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
There is no better way to start the year than stepping back and having a good look at where you are in your security journey. To that end, a good baseline is not a bad idea. In this episode we will dive into the The Center for Internet Security (CIS) Critical controls. These are great ways to steps through your existing (or lack of) controls.
- www.bleepingcomputer.com: QNAP NAS devices hit in surge of ech0raix ransomware attacks
-https://www.qnap.com: QNAP Recommendations
https://www.sans.org/blog/cis-controls-v8/
- My look at the road ahead - 2022 landscape.
-https://www.sans.org: CIS Controls v8
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome back once again!
In this episode we will go back to the best of 2021 episodes. There are quite a few popular ones.
But first, lets recap the top trending security news.
- techcommunity.microsoft.com: SAM Name impersonation
- www.bleepingcomputer.com: Microsoft warns of easy Windows domain takeover via Active Directory bugs
-https://www.cisa.gov: CISA, FBI, NSA and international partners issue advisory to mitigate Apache Log4j vulnerabilities
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for YusufOnSecurity, welcome back once again!
In this episode we will stay on the topic of Log4j still developing vulnerability.
-https://threatpost.com : Malicious Joker App Scores Half-Million Downloads on Google Play
-https://www.bleepingcomputer.com: Karakurt: A New Emerging Data Theft and Cyber Extortion Hacking Group
-https://yusufonsecurity.com: Log4j vulnerabilities
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In this episode we will cover an actively exploited vulnerability whose importance can not overstated. Well the Internet is on fire, as someone put it.
In addition, we will recap other top trending security news which includes:
-https://blog.mozilla.org: Site Isolation in Firefox
-https://en.wikipedia.org: Same Origin Policy
-eclypsium.com: When honey bees become murder hornets
- logging.apche.org: Apache log4j vulnerability
-https://www.cisa.gov Most commonly exploited vulnerabilitiesBe sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today's episode, we will cover the best practice that we mostly forget this time of the year.
I am sure a lot of you become the Help Desk for the entire family for anything to do with IT or technology.
We will recap the top trending security news which includes:
-https://blog.talosintelligence.com: Attackers exploiting zero-day vulnerability in Windows Installer
- thehackernews.com: Researches Detail 17 Malicious Frameworks Used to Attack Air-Gapped Networks
It is all coming up next on YusufOnsecurity!
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today's episode, lets talk about password and the future of password for that matter.
We will recap the top trending security news which includes:
-www.bbc.co.uk: UK proposed to ban default passwords
-www.apple.com: Apple sues the NSO Group
- www.nytimes.com: The secret life of passwords
-https://fidoalliance.org: What is FIDO?
-https://www.cisco.com: Kiss Passwords G00dby3: Cisco Secure Unveils Passwordless Future with Stronger Security for All
Be sure to subscribe!
If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
**In today's episode, I am discussing OWASP Top 10. We will introduce what this is for those not in the know and then go indepth on how this helps the industry and how it changed in its last evolution.
- https://finance.yahoo.com**: Malware just got even more stealthier
- www.gov.uk: National Security and Investment Act 2021: Statement for the purposes of section
- https://owasp.org: OWASP T0p 10
Be sure to subscribe!
If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today's episode, I am discussing endpoint security with Information Security Media Group better known as ISMG. In particular we will delve into
- blog.google: Analyzing a watering hole campaign using macOS exploits
- support.apple.com: About the security content of Security Update 2021-006 Catalina
- threatpost.com: Millions of Routers, IoT Devices at Risk from BotenaGo Malware
Be sure to subscribe!
If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome again!
In today’s episode we will dive into the most widely adopted framework, The NIST Cybersecurity Framework.
-www.vice.com:The booming underground market for bots that steal 2FA codes
- www.zdnet.com: Commerce Dept sanctions NSO Group, Positive Technologies and more for selling spyware and hacking tool
-https://nvlpubs.nist.gov: NIST Cybersecurity Framework
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard!
In today’s episode lets look at an analysis carried out by google on 80M samples they’ve received through VirusTotal.
- security.googleblog.com: Launching a collaborative minimum security baseline
- helpx.adobe.com: Security Bulletins and Advisories
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard!
We will look into the modern vulnerability Management today, episode,
But before that, lets recap top trending security news:
It is all coming up next on Yusuf on Security!
-https://blog.google.com: Google gives away 10K security keys to high risk users
-https://www.schneier.com: Problem with multi-factor authentication
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim YUSUF.
In this episode, we will cover a topic related to our previous episode. We will look at a new way of reconciling driving revenue through ads while ‘not tracking individuals’.
- www.microsoft.com: Iran-linked DEV-0343 targeting defense, GIS, and maritime sectors
- www.businesswire.com: MITRE Labs Launches Innovation Organizations for Critical Infrastructure, Clinical Health Data
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim
In this episode, we look take a taste of cookies but before we get into that there is only one story that dominated the scene last week, the Facebook fall. We will look into what went wrong and the underlying plumping that had a catastrophic cascading impacting on the company.
-www.krebsonsecurity.com - What happened to Facebook...?
-www.wikipedia.com - Cookies
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim Yusuf!
October is Cyber Security month and it is only fitting we focus on this on this episode/
It is all coming up next on Yusuf on Security!
-theharckernews.com: Be Care Of Fake Amnesty International AV
-www.technologyreview.com: The proliferation of zero-days
-www.govinfosecurity.com: NSA, CISA Release VPN Security Guidance
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, Ibrahim is here. Welcome back.
This week I have a great content. It is a recording I had with Mathew Schwartz at ISMG -Information Security Media Group.
Having said that… we will start with few top of mind security news including….
- www.darkreading.com: IoT 'Nutrition' Labels Aim to Put Security on Display
- www.bleepingcomputer.com: Researchers compile list of vulnerabilities abused by ransomware gangs
-stopransomware.gov - Stop ransomware
-event.ismg.io - Information Security Media Group
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, Ibrahim is here. Welcome back.
We will get into our second part of our two parts series into Security Operation Center.
Having said that… we will start with few top of mind security news including….
- www.wired.com: Time to Patch All The Things
- threatpost.com: Universal Decryptor for REvil/Sodinokibi Released
-https://protonmail.com/privacy-policy: ProtonMail Policy
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, Ibrahim is here. Welcome to the show.
We will look into the need of a SOC and what that entails today. This will be a two part series.
www.fortinet.com: Malicious Actor Discloses FortiGate SSL-VPN Credentials
www.bleepingcomputer.com: Netgear fixes severe security bugs in over a dozen smart switches
www.bleepingcomputer.com: Angry Conti ransomware affiliate leaks gang's attack playbook
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, Ibrahim is here. Welcome to the show.
We have our first guest, yes! It finally happened and we will talk about t Red Teaming but first, we will start with few top of mind security news.
- statescoop.com: Industry group offers new cyber guidance for K-12 schools
-cybersecuritydive.com: US govt warns orgs to patch massively exploited Confluence bug
- www.scmagazine.com: ISAC group unveils pragmatic, attainable cyber standards for school districts
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, Ibrahim is here. Glad you are joining me today.
Today we will look in the MITRE ATT&CK Evaluation which provides vendors with an assessment of their ability to defend against specific adversary tactics and techniques.
But first, we will start with few top of mind security news.
https://www.bleepingcomputer.com - FBI releases alert about Hive ransomware
https://attack.mitre.org - The FIN7 Group
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, Ibrahim is here. Welcome back.
**In this episode we will tackle Apple new child protection feature - child abuse detection system -CSAM
- www.rapid7.com: Fortinet FortiWeb OS Command Injection
- googleprojectzero.blogspot.com: Understanding Network Access in Windows AppContainers
- https://www.cybereason.com: Disgrounted Employees to Deploy Ransomware to share ransomware profit
This is Yusuf On Security,**
Episode 28
Recorded Saturday 21st August 2021 : Apple’s CSAM Detection System
It is time for Yusuf On Security, Ibrahim is here. Welcome back.
This week’s show is quit interesting show. We delve into the mindset of the notorious REvil ransomware group.
But first, we will start with few top of mind security news.
It is all coming up next on Yusuf on Security!
- www.zdnet.com: Firefox 91 gets HTTPS default in private mode, enhanced cookie clearing and
- github.blog: Git password authentication is shutting down
-reuters.com: Accenture restores affected systems after reported ransomware attack
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today’s show I will provide you an interview I had with Information Security Media Group better known as ISMG.
-https://www.tripwire.com: BlackMatter rises from the ashes of notorious cybercrime gangs to pose new ransomware threat
-https://www.esa.int: Reprogrammable satellite launched
-https://securityaffairs.co: BlackMatter Ransomware gang attack ESXi Server with ransomware
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, Ibrahim is here. Great to have you onboard.
In this week’s episode I’ll details of a tool I used from time time.
But first, we will start with few top of mind security news.
- blogs.blackberry.com: Old Dogs New Tricks: Attackers Adopt Exotic Programming Languages
- blog.mozilla.org: Stopping FTP support in Firefox 90
- www.govinfosecurity.com: 18 Companies to Participate in NIST 'Zero Trust' Project
-Cyberchef: The Cyber Swiss Army Knife
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
It is time for Yusuf On Security, I am your host Ibrahim Yusuf. Great to have you onboard again.
We will continue into the Intrusion Analysis subject we began last week to help you spotting abnormal behavior within your environment.
But first, we will start with top of mind security news.
- techcrunch.com: This tool tells you if NSO’s Pegasus spyware targeted your phone
- www.kaseya.com: Updates Regarding VSA Security Incident
- arstechnica.com: Kaseya gets master decryptor to help customers still suffering from REvil attack
- arstechnica.com: Saudi Aramco confirms data leak after $50 million cyber ransom demand
- New research shows cryptographic vulnerabilities on popular messaging platform, TelegramBe sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
In today’s show we will look at Intrusion Analysis, spotting abnormal behavior within your environment.
As usual we will start with some trending security news
- www.sonicwall.com: Urgent Security Notice: Critical Risk To Unpatched End-Of-Life SRA & SMA 8.X Remote Access Devices
- www.zdnet.com: SonicWall releases urgent notice about 'imminent' ransomware targeting firmware
- www.theregister.com: REvil ransomware gang's websites vanish soon after Kaseya fiasco, Uncle Sam threatens retaliation
- www.zdnet.com: REvil websites down after governments pressured to take action following Kaseya attack
- www.scmagazine.com: Microsoft fixes 117 vulnerabilities, four exploited in the wild
- www.zdnet.com: Microsoft July 2021 Patch Tuesday: 117 vulnerabilities, Pwn2Own Exchange Server bug fixed
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim Yusuf. Welcome back again.
A TV station reached out to me and I thought it would be good to provide you with that interview. However , lets start with some current security news.
- threatpost.com: Kaseya Attack Fallout: CISA, FBI Offer Guidance
- www.bleepingcomputer.com: CISA, FBI share guidance for victims of Kaseya ransomware
- media.defense.gov: Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments (PDF)
- www.wired.com: Russian Hackers Are Trying to Brute-Force Hundreds of Networks
- www.govinfosecurity.com: CISA Tool Helps Measure Readiness to Thwart Ransomware
- US-cert.cisa.gov: CISA’s CSET Tool Sets Sights on Ransomware
-CBATV – Threat Horn of Africa fastest growing TV
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
Today we will look at a supplement security product. Why supplement, I heard you ask - well supplement to an already existing security tool. Before we get into that though, lets start with some current security news.
-Cyber Insurance and the Cyber Security Challenge
-rusi.org: Cyber Insurance and the Cyber Security Challenge
-The DarkSide Ransomware GangBe sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
It is time for Yusuf On Security, I am your host Ibrahim Yusuf. Glad you’re joining me once again.
We will go and demystify another one of those buzz word in the industry. It is SASE but before we get into that, lets start with some current security news.- Secure Access Service Edge (SASE)- The Rise of Direct Internet Access (DIA)
- The Future of Network Security Is in the Cloud
- Complexity versus Security
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
We will continue ploughing through our second installment of Data Leak Prevent. We ask the question, how companies prevent data leaving their network in an unauthorized manner.
Before we get into the second the part of the show, lets start with some current security news.
WordPress force installs Jetpack security update on 5 million sites
Most of Cisco Talos Incident Response’s engagements last quarter involved the exploitation (or attempted exploitation) of zero-day vulnerabilities in Microsoft Exchange Server disclosed earlier this year.
-Hackers Breached Colonial Pipeline Using Compromised Password
-SMIME
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today’s show we will look at data leak protection or as it is commonly known DLP. How should organization prevent data ending up into the wrong hands.
I will cover the topic in two parts. We will kick off with part 1 today.
But first, we will start with some current security news.
- us-cert.cisa.gov: Unpatched VMware vCenter Software
- www.zdnet.com: Patch now: Attackers are hunting for this critical VMware vCentre flaw
- arstechnica.com: US seizes $2.3 million Colonial Pipeline paid to ransomware attackers
- www.justice.gov: Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside
- www.bbc.com: ANOM: Hundreds arrested in massive global crime sting using messaging app
Good to meet you again. We will continue what we started last week. The critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security.
But first, Lets have a look at has been trending since we met last.
- www.sonicwall.com: Security Advisory: On-Prem SonicWall Network Security Manager (NSM) Command Injection Vulnerability
- www.govinfosecurity.com: FBI to Share Compromised Passwords With Have I Been Pwned
- www.darkreading.com: 'Have I Been Pwned' Code Base Now Open Source
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
**I hope you all had a fantastic week. Today we turn our eyes to a critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security. But firrst lets review the week's most notable security events and news.
- support.apple.com: Apple security updates
- www.theregister.com: Air India admits to data breach impacting 4.5m customers, sat on the news for five weeks
- www.securityweek.com: Tulsa Computer System Hacks Stopped by Security Shutdown
- techcommunity.microsoft.com: Internet Explorer 11 desktop app retirement FAQ
- www.zdnet.com**: FBI identifies 16 Conti ransomware attacks striking US healthcare, first responders
- www.computerweekly.com: Why securing the DNS layer is crucial to fight cyber crime
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
You will find a list of all previous episodes in there too.
In today’s episode we will discuss recommendations put forward by a task force setup to combat the surge of ransomware attacks.
- us-cert.cisa.gov: Eviction Guidance for Networks Affected by the SolarWinds and Active Directory/M365 Compromise
www.bleepingcomputer.com: Insurer AXA hit by ransomware after dropping support for ransom payments
- www.securityweek.com: AXA Confirms Ransomware Attack Impacted Operations in Asia
- arstechnica.com: Pipeline attacker DarkSide suddenly goes dark—here’s what we know
- www.gov.uk: New plans to boost cyber resilience of UK’s critical supply chains
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
In today’s show we will plough through The PCI DSS, the global payment account data security standard ; but first lets begin with current industry security news.
- msrc.microsoft.com: Security Update Guide
- www.bloomberg.com: Colonial Pipeline Paid Hackers Nearly $5 Million in Ransom
- www.rapid7.com: Rapid7’s Response to Codecov Incident
- PCI DSS Requirement: The twelve requirements for building and maintaining a secure network and systems
-Braking Codecov: Breaking Down the Codecov Attack: Finding a Malicious Needle in a Code Haystack
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
In this episode we will recap recent noteworthy news and then finish the show with demystifying a rather over used buzz word in security, it is Zero Trust.
Google nudges their users to adopt 2FA
- blog.google: A simpler and safer future — without passwords
- www.vice.com: Google Wants to Make Everyone Use Two Factor Authentication
- www.bleepingcomputer.com: Google wants to enable multi-factor authentication by default
- www.bleepingcomputer.com: Largest U.S. pipeline shuts down operations after ransomware attack
Exim Server
- www.exim.org: Latest Version: 4.94.2
- www.theregister.com: 21 nails in Exum mail server: Vulnerabilities enable 'full remote unauthenticated code execution', millions of boxes at risk
- www.scmagazine.com: 21 vulnerabilities in Exim mail server leave web, cloud operations exposed
Be sure to subscribe!
If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com
In this episode we will go over a rather popular topic in security, it is Threat Hunting.
Here are a number of places where you can read more about Emotet:
- www.theregister.com: Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs
- www.scmagazine.com: Following similar move in US, Europol prepares coup de gras for Emotet’s remains
In this episode we will start with some current news which you may find interesting and will continue with the topic du jour: The Changing Face Of Rasomware
In this episode we begin with a current news which you may find interesting. You might agree or disagree with the topic but it important to see where this leads.
As always as the topic of the show, we will cover why you should not login to you important sites, storage or applications with one single factor. I’ll explain what I mean.
In this episode we will cover the SMTP Authentication Protocols. I think you will agree this is a just in time and topical subject.
In this episode we will cover the The MITRE ATT&CK Framework, a framework that digs deep on how the cyber crooks behave when doing their bad deed.
In this episode we will cover the recently discovered Microsoft Exchange exploits. These are so serious that Microsoft has taken immediate action to help the industry. Lets get into these!
In this episode we will cover encryption. We often hear encryption and in particular encryption on data at rest. What is it good for and what are the different type of encryptions typical organization use. Where are these different type of encryption usually used and how?
This is a follow up episode to our "Anatomy Of A Phishing Attack" episode. You might want to listen to that episode first.
In this episode we will cover email deception attacks and why this is so successful than you might think.
What are the different highly used tactics the bad guys use to to lure people in and take out of their perimeter protections. As always I will sprinkles with suggestions of what you take care of to protect yourselves against these types of attacks.
In this episode we will cover the last line of defense of any organisation, why it is so important today than ever, what to take into consideration for an effective endpoint telemetry. Is it really the center of an effective cyber hygiene? Join me to find out if it is!
In this episode of we will dive into a topic that might be the worst nightmare of any security analyst. When you face your opponent, what do you do. What are the realities that organisations are facing today, big or small? What do bad guys or girls do when they breach an organisation’s defences? We will cover all that and some key take aways in the end.
In this episode we will look at Phishing. How it is executed and what are the different steps involved.