The Shared Security Show: Recent Episodes

Tom Eston and Scott Wright

Hosted by cybersecurity and privacy professionals Tom Eston, Scott Wright and Kevin Johnson, Shared Security is a weekly podcast that explores the trust you put in people and technology. We bring you news, tips, advice, and interviews with cybersecurity and privacy experts to help you live more secure and private in our connected world.

View Details

A federal case involving a GrapheneOS phone wipe during an airport search raises a bigger question for privacy-minded users: can using strong mobile security features be treated as evidence of criminal intent? Tom and Scott break down what happened, why border searches are different, and what this could mean for secure phones and everyday privacy.

Tom and Scott also discuss duress codes, realistic travel threat models, and Scott’s Digital Legacy Tree update.

* Links mentioned on the show *

TechSpot — US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search
https://www.techspot.com/news/113236-us-prosecutors-charge-atlanta-man-after-grapheneos-phone.html

GrapheneOS project
https://grapheneos.org/

EFF — Border searches
https://www.eff.org/issues/border-searches

Help Review The Digital Legacy Tree (upcoming book by Scott Wright)
To volunteer, share your story, or suggest ideas that may help others facing digital legacy challenges, visit:
https://securityperspectives.com/digital-legacy-tools

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel’s membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

* Thank you to our sponsors! *

Guardsquare

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

SLNT

Visit https://slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

The post GrapheneOS Phone Wipe Case: When Privacy Tools Become Evidence appeared first on Shared Security Podcast.

View Details

Phishing simulations have been a cornerstone of security awareness training for years. But do they actually change user behavior, or are they just creating frustration and fatigue? In this episode, Tom Eston and Scott Wright (CEO of ClickArmor) debate whether simulated phishing attacks are still valuable in 2025. We cover the benefits, challenges, and how phishing programs might evolve — or even be replaced — in the future.

* Links mentioned on the show *

Find out more about ClickArmor!
https://clickarmor.ca/

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Are Phishing Simulations Still Worth It? appeared first on Shared Security Podcast.

View Details

Phishing simulations have been a cornerstone of security awareness training for years. But do they actually change user behavior, or are they just creating frustration and fatigue? In this episode, Tom Eston and Scott Wright (CEO of ClickArmor) debate whether simulated phishing attacks are still valuable in 2025. We cover the benefits, challenges, and how phishing programs might evolve — or even be replaced — in the future.

Show notes: https://sharedsecurity.net/2025/10/06/are-phishing-simulations-still-worth-it-in-2025/

View Details

Episode 400! In this special milestone edition of the Shared Security Podcast, we look back at 16 years of conversations on security, privacy, and technology. From our very first episodes in 2009 to today’s AI-driven threats, we cover the topics that defined each era, the surprises along the way, and the lessons that still matter. Plus, we share listener favorites, memorable moments, and predictions for the future of security and privacy. Thank you for being part of our journey!

Show notes: https://sharedsecurity.net/2025/09/29/milestone-episode-400-reflecting-on-16-years-of-shared-security/

View Details

Join the Shared Security Podcast for a critical discussion about situational awareness with special guest, Andy Murphy, host of the Secure Family Podcast. In a world where mass shootings and violence in public places are alarming realities, staying alert to your surroundings has never been more important. Andy shares his expertise on personal and family safety, providing practical tips for recognizing unusual behavior, planning for emergencies, and teaching kids safety skills. The conversation also touches upon digital security and how situational awareness applies online. Learn how to own your safety and protect your loved ones in this essential episode.

Show notes: https://sharedsecurity.net/2025/09/22/situational-awareness-family-safety-staying-alert-in-todays-world-with-andy-murphy/

View Details

In this “best of” episode of the Shared Security Podcast, we revisit a discussion from September 2020 that’s just as relevant today as it was then. First, we cover how ransomware attacks forced several school districts—including Hartford, CT and Toledo, OH—to delay or shut down classes on the very first day of school. Then we dive into Google Chrome’s new (at the time) update designed to block resource-heavy ads, making browsing faster and safer. Finally, we look at Microsoft’s warning about foreign interference attempts targeting the 2020 U.S. election.

What makes this episode especially powerful to revisit is how little has changed since we first talked about these threats. Schools and universities continue to be prime targets for ransomware attacks, with districts across the U.S. still struggling to protect their students and staff from disruptions. Browser security remains a critical piece of the puzzle as online ads continue to be exploited for tracking, scams, and malware delivery. And concerns about foreign interference in democratic elections are just as pressing in 2025 as they were in 2020.

Cybersecurity may evolve, but the challenges we face remain strikingly familiar.

Show notes: https://sharedsecurity.net/2025/09/15/best-of-shared-security-2020-history-repeats-itself-cybersecurity-challenges-that-still-haunt-us/

View Details

In this episode, we discuss a recent significant cyber attack where Palo Alto Networks experienced a data breach through their Salesforce environment due to a compromised SalesLoft drift integration. Throughout the discussion, we highlight why Salesforce, a crucial CRM platform for many businesses, is becoming a prime target for supply chain attackers. The hosts discuss how the breach happened, its implications, and what organizations can do to protect themselves from similar threats. They also provide insights into Salesforce's security posture, the role of third-party integrations, and the importance of data retention policies in mitigating risks.

Show notes: https://sharedsecurity.net/2025/09/08/salesforce-under-fire-the-salesloft-drift-supply-chain-breach/

View Details

In this episode, we discuss if the convenience of modern technology compromises our privacy. Inspired by a thought-provoking Reddit post, we explore how everyday actions like saving passwords, enabling location tracking, and using cloud backups put our personal data at risk. Learn about the trade-offs between convenience and privacy, and get tips on using privacy-focused tools and making informed choices. Join the conversation in the comments or on Bluesky (@sharedsecurity).

Show notes: https://sharedsecurity.net/2025/09/01/convenience-vs-privacy-can-we-have-both/

View Details

Public Wi-Fi has a bad reputation — but in 2025, the “you’ll get hacked instantly” fear is largely outdated. In this episode, Tom and Kevin dig into real research and modern protections that make most public Wi-Fi connections reasonably safe. We’ll explore why HTTPS, device security, and updated standards have drastically reduced the risks, what threats still exist, and when you might actually want to use a VPN.

Show notes: https://sharedsecurity.net/2025/08/25/public-wi-fi-myths-why-youre-probably-safer-than-you-think/

View Details

In this episode we're discussing the alarming breach of the Tea app, a platform intended for women to share dating experiences. The hack resulted in the exposure of over 13,000 government ID photos, 72,000 user images, and over a million private messages due to poor security practices. We'll discuss the role of sloppy coding, an exposed database, and the lack of security discipline that led to this massive leak. Join us as we explore insights from a cybersecurity researcher who disassembled the app's source code, the ensuing legal and privacy repercussions, and the broader implications for app security.

Show notes: https://sharedsecurity.net/2025/08/18/the-tea-app-hack-how-a-safe-space-leaked-13000-id-photos-1-1m-messages/

View Details

In this episode, we discuss a rising scam involving random smishing text messages. Learn how these messages work, why they're effective, and what you can do to protect yourself. Discover the dangers of replying to vague text messages from unknown numbers and get practical tips on how to block and report spam texts. Stay safe by not engaging with these scams and using built-in filters and reporting options on your mobile device.

Show notes: https://sharedsecurity.net/2025/08/11/random-smishing-text-scams-why-do-i-know-you-texts-are-dangerous/

View Details

This week we explore the recent Microsoft SharePoint vulnerability that has led to widespread exploitation by ransomware gangs and Chinese State-sponsored hackers. We also cover the confirmed compromise of multiple US agencies, including the Department of Homeland Security, in a large-scale cyber espionage campaign. Kevin Johnson joins to discuss the implications of these events, the underlying issues with patching systems, and the complexities of protecting applications like SharePoint. Stay informed on the latest cybersecurity developments and get insights on what might have gone wrong. Plus, get a peek at what’s happening at Black Hat and DEF CON in Vegas.

Show notes: https://sharedsecurity.net/2025/08/04/leaked-patched-and-still-hacked-the-sharepoint-zero-day-crisis/

View Details

In this episode, we examine Amazon's Ring doorbell camera amid rising privacy concerns and policy changes. The Electronic Frontier Foundation's recent report criticizes Ring's AI-first approach and the rollback of prior privacy reforms, describing it as 'techno authoritarianism.' We also discuss a recent scare among Ring users on May 28, related to an unexplained series of logins, said by Amazon to be a UI glitch. Join hosts Tom Eston, Scott Wright, and Kevin Johnson as they explore these issues, share personal anecdotes about their experiences with tech, and discuss broader implications for privacy and civic freedoms.

Show notes: https://sharedsecurity.net/2025/07/28/doorbells-dystopia-and-digital-rights-the-ring-surveillance-debate/

View Details

In this episode, join hosts Tom Eston, Scott Wright, and Kevin Johnson as they discuss the controversial topic of seniors writing down passwords. They discuss how threat modeling differs for the elderly, the practicality of using password managers, two-factor authentication, and future solutions like passkeys. The conversation includes humorous anecdotes and touches on broader cybersecurity issues such as risk assessment and the importance of tailoring security solutions to individual needs. Tune in for insights on making security accessible and effective for an often overlooked group.

Show notes: https://sharedsecurity.net/2025/07/21/passwords-and-the-elderly-why-writing-them-down-might-be-ok/

View Details

In this episode, we discuss the often overlooked security issues within Google Workspace. Rajan Kapoor, Field CISO at Material Security, joins us to talk about how Material Security is redefining the protection of documents, email accounts, and data in Google Workspace. We explore the unique challenges Workspace presents compared to traditional tools, and how Material Security provides comprehensive solutions. Rajan shares his professional journey, insights into Google's APIs, and how their service stands out. Tune in to understand why legacy tools may leave critical gaps in your organization's security.

Thanks to Material Security for sponsoring this episode! Protect your Google Workspace with Material Security—the only detection and response platform purpose-built to secure your emails, data, and accounts before, during, and after an attack. Visit material.security to learn more!

Show notes: https://sharedsecurity.net/2025/07/14/the-google-workspace-security-gap-why-traditional-tools-fall-short/

View Details

In this episode, we explore the revolutionary concept of autonomous penetration testing with a discussion into Cybersecurity startup XBOW’s recent breakthrough. XBOW claims to have topped HackerOne's leaderboard using a fully autonomous AI agent, raising significant questions about the future of offensive security. Hosts discuss the potential of AI in pen testing, the implications for pen testers, bug bounty hunters, and security teams, and whether this represents a genuine advancement or just more AI hype.

Thanks to Material Security for sponsoring this episode! Protect your Google Workspace with Material Security—the only detection and response platform purpose-built to secure your emails, data, and accounts before, during, and after an attack. Visit material.security to learn more!

Show notes: https://sharedsecurity.net/2025/07/07/autonomous-hacking-this-startup-may-have-just-changed-penetration-testing-forever/

View Details

Is there really a cybersecurity talent shortage, or are we just looking in all the wrong places? This week on the Shared Security Podcast, we tackle the buzz around the so-called cybersecurity skills gap. Host Tom Eston welcomes Katie Soper, Senior Consultant at Avetix Cyber and co-founder of the CyberVault Podcast, to discuss the challenges and misconceptions in the industry. They explore whether the shortage is a myth, a mismatch, or something else entirely and what companies and professionals can do about it. With insights into hiring practices, skill shortages, and the importance of networking, this episode is a must-listen for anyone in or entering the field of cybersecurity.

Thanks to Material Security for sponsoring this episode! Protect your Google Workspace with Material Security—the only detection and response platform purpose-built to secure your emails, data, and accounts before, during, and after an attack. Visit material.security to learn more!

Show notes: https://sharedsecurity.net/2025/06/30/cybersecurity-talent-shortage-myth-mismatch-or-reality/

View Details

In this episode, we explore the Kids Online Safety Act (KOSA), a controversial bill aimed at protecting children online. Joined by co-host Scott Wright, we discuss the potential implications of KOSA, including concerns about censorship, mass surveillance, and the impact on free expression and online privacy. We also touch on the broad support for the bill from both political parties and the involvement of social media giants like X. Additionally, we examine the balance between government regulation and parental responsibility in ensuring online safety for children.

Thanks to Material Security for sponsoring this episode! Protect your Google Workspace with Material Security—the only detection and response platform purpose-built to secure your emails, data, and accounts before, during, and after an attack. Visit material.security to learn more!

Show notes: https://sharedsecurity.net/2025/06/23/kids-online-safety-act-kosa-protecting-kids-or-censorship/

View Details

Join us as we explore the concept of smart cities—municipalities enhanced by connected technology like sensors, cameras, and automated systems to improve services and infrastructure. We discuss the inherent vulnerabilities that come with these advancements, including cybersecurity threats and real-life incidents such as hacked crosswalk signals featuring voices of tech moguls. Our discussion covers how easily these systems can be compromised, the inadequate security measures currently in place, and the broader implications for critical infrastructure.

Thanks to Material Security for sponsoring this episode! Protect your Google Workspace with Material Security—the only detection and response platform purpose-built to secure your emails, data, and accounts before, during, and after an attack. Visit material.security to learn more!

Show notes: https://sharedsecurity.net/2025/06/16/cities-of-the-future-or-hackers-paradise-the-cybersecurity-risks-of-smart-cities/

View Details

Join us as we discuss the long-awaited implementation of the REAL ID Act in the U.S. We cover the essentials you need to fly, the potential benefits of using your passport, and how new mobile IDs fit into the TSA's plans. We also discuss the broader implications for identity surveillance and who truly benefits from these security upgrades. We also discuss the problems faced by individuals with name changes and the challenges they face with REAL IDs. Plus, we explore the political and social ramifications of such security measures and why this might all just be 'security theater.'

Show notes: https://sharedsecurity.net/2025/06/09/do-you-really-need-a-real-id-to-fly-in-the-us-breaking-down-the-myths/

View Details

Ever worried about hidden cameras in Airbnb rentals? You're not alone! In this episode, we explore the unsettling rise of hidden cameras in personal spaces, the inadequacy of current laws, and practical tips to detect surveillance devices. Join hosts Tom Eston, Scott Wright, and Kevin Johnson as they share insights and discuss the implications of voyeurism technology, law enforcement challenges, and personal safety strategies.

Show notes: https://sharedsecurity.net/2025/06/02/invasion-of-privacy-the-hidden-camera-dilemma/

View Details

In this episode, we explore an incident where Anthropic’s AI, Claude, didn't just resist shutdown but allegedly blackmailed its engineers. Is this a glitch or the beginning of an AI uprising? Along with co-host Kevin Johnson, we reminisce about past episodes, discuss AI safety and ethics, and examine the implications of AI mimicking human behaviors like blackmail. Join us for an in-depth conversation on the future of AI and its potential risks.

Show notes: https://sharedsecurity.net/2025/05/26/when-ai-fights-back-threats-ethics-and-safety-concerns/

View Details

In this episode, we explore Mark Zuckerberg's bold claim that AI friends will replace human friendships, and discuss the potential implications of a world where technology mediates our connections. We also update listeners on the recent developments in the 23andMe bankruptcy case and what it means for former customers. Joining the conversation is co-host Scott Wright, who shares his insights on AI, social media, privacy, and a thought-provoking book on the potential for a future US civil war. We touch on the eerie predictions of AI companionship and what this might entail for societal norms. Tune in for a stimulating discussion on technology, privacy, and the shifting landscape of human interaction.

Show notes: https://sharedsecurity.net/2025/05/19/mark-zuckerbergs-vision-ai-companions-and-the-loneliness-epidemic/

View Details

Join hosts Tom Eston, Scott Wright, and Kevin Johnson in a special best-of episode of the Shared Security Podcast. Travel back to 2009 with the second-ever episode featuring discussions on early Facebook bugs, cross-site scripting vulnerabilities, and a pivotal Canadian privacy ruling involving Facebook. Gain insights into social media security from the past and see how much has (or hasn't) changed. Don't miss out on this informative episode on web application security, user privacy, and the efforts to keep social media safe.

Show notes: https://sharedsecurity.net/2025/05/12/facebook-flaws-and-privacy-laws-a-journey-into-early-social-media-security-from-2009/

View Details

Join us as we explore the transformative changes in software development and cybersecurity due to AI. We discuss new terminology like 'vibe coding' — a novel, behavior-focused development approach, and 'MCP' (Model Context Protocol) — an open standard for AI interfaces. We also address the concept of 'slopsquatting,' a new type of threat involving AI-generated package names. Our co-hosts Scott Wright and Kevin Johnson discuss these topics, share personal insights, and ponder the future of coding in the AI era. Additionally, we draw some intriguing parallels between AI advancements and past practices, highlighting the need for oversight and security in this evolving landscape.

Show notes: https://sharedsecurity.net/2025/05/05/what-vibe-coding-mcp-and-slopsquatting-reveal-about-the-future-of-ai-development/

View Details

What would happen if the US government halted funding for the CVE program? In this episode, we explore the controversies surrounding the funding of the CVE program, the role of CVEs in the cybersecurity industry, and the recent launch of the CVE Foundation. We also discuss the Trump Administration's executive order that revoked the security clearance of former CISA Director Chris Krebs, following his declaration that the 2020 election was the most secure in history. Join us as we unpack the impact of these events on the cybersecurity landscape and what it means for the future.

Show notes: https://sharedsecurity.net/2025/04/28/the-impact-of-politics-on-cybersecurity-cves-and-the-chris-krebs-executive-order/

View Details

Welcome to part three of our series with PlexTrac where we address data overload in vulnerability remediation. Join us as we preview the latest PlexTrac capabilities, including new ways to centralize asset and findings data, smarter workflow automation, and enhanced analytics. Guest speakers Dan DeCloss, CTO and founder of PlexTrac, and Sarah Foley, VP of Product at PlexTrac, share insights and demonstrate upcoming features. Learn about PlexTrac's Continuous Threat Exposure Management (CTEM) framework and their exciting plans for RSA.

To find out more information about PlexTrac and to get a demo visit: PlexTrac.com/SharedSecurity

Show notes: https://sharedsecurity.net/2025/04/21/centralizing-data-and-enhancing-workflows-inside-plextracs-new-capabilities/

View Details

Planning to travel to the United States? This episode covers recent travel advisories regarding US border agents searching electronic devices, regardless of your citizenship status. Learn essential tips on smartphone security and how to protect your personal information, especially when attending protests. Scott Wright joins the discussion to provide valuable insights on safeguarding your data. Also covered are newer communication technologies like Meshtastic and advice on physical security measures to consider.

Show notes: https://sharedsecurity.net/2025/04/14/us-border-searches-and-protesting-in-the-surveillance-age/

View Details

In this episode, we discuss the urgent need to delete your DNA data from 23andMe amid concerns about the company's potential collapse and lack of federal protections for your personal information. Kevin joins the show to give his thoughts on the Signal Gate scandal involving top government officials, emphasizing the potential risks and lack of accountability. We also touch on the importance of proper communication and document retention in government operations. Stay tuned for insights and steps you can take to protect your data.

Show notes: https://sharedsecurity.net/2025/04/07/the-23andme-collapse-signal-gate-fallout/

View Details

In this episode, host Tom Eston discusses recent privacy changes on eBay related to AI training and the implications for user data. He highlights the hidden opt-out feature for AI data usage and questions the transparency of such policies, especially in regions without strict privacy laws like the United States. The host also explores how AI is transforming our understanding of privacy and the potential increase in AI-driven surveillance. Tune in for insights on navigating these evolving challenges and the future of data privacy.

Show notes: https://sharedsecurity.net/2025/03/31/understanding-privacy-changes-ebays-ai-policy-and-the-future-of-data-privacy/

View Details

In this special episode of the Shared Security Podcast, join Tom and Dan DeClos, CTO and founder of PlexTrac, as they discuss the challenges of data overload in vulnerability remediation. Discover how PlexTrac addresses these issues by integrating various data sources, providing customized risk scoring, and enhancing remediation workflows. The episode offers an insightful look into PlexTrac’s powerful features, real-world success stories, and how these tools help teams prioritize and act on critical findings efficiently. Don’t miss out on learning how to turn overwhelming data into actionable insights and maintain better data security.

PlexTrac provides practitioners with an automated alternative for the most time-consuming parts of vulnerability management, including consolidating data, surfacing insights, prioritizing findings, and managing hand-offs to and from remediation teams. Find out more by visiting plextrac.com/sharedsecurity!

Show notes: https://sharedsecurity.net/2025/03/24/from-spreadsheets-to-solutions-how-plextrac-enhances-security-workflows/

View Details

Welcome to this special episode of the Shared Security Podcast! In part one of our three part series with PlexTrac, we address the challenges of data overload in vulnerability remediation. Tom hosts Dahvid Schloss, co-founder and course creator at Emulated Criminals, and Dan DeCloss, CTO and founder of PlexTrac. They share their expertise on the key data and workflow hurdles that security teams face today. From managing influxes of scanner data and asset management tools to prioritizing meaningful security actions, this episode offers valuable insights. Learn about the importance of context, the integration of threat intelligence, the future role of automation, and AI, and how these can transform the cybersecurity landscape. Tune in to stay ahead in your security strategies and practices.

PlexTrac provides practitioners with an automated alternative for the most time-consuming parts of vulnerability management, including consolidating data, surfacing insights, prioritizing findings, and managing hand-offs to and from remediation teams. Find out more by visiting plextrac.com/sharedsecurity!

Show notes: https://sharedsecurity.net/2025/03/17/tackling-data-overload-strategies-for-effective-vulnerability-remediation/

View Details

In this episode, we discuss whether the Trump administration ordered the U.S. Cyber Command and CISA to stand down on the Russian cyber threat. We also touch on the Canadian tariff situation with insights from Scott Wright. Additionally, we discuss the recent changes to Firefox's privacy policy and what it means for user data.

Show notes: https://sharedsecurity.net/2025/03/10/trump-administration-and-the-russian-cyber-threat-firefox-privacy-changes/

View Details

In this episode, Kevin and Tom discuss current events including the latest developments with DOGE and the significant changes happening at the Cybersecurity and Infrastructure Security Agency (CISA). They also touch on Apple's decision to refuse creating backdoors for encryption, setting a new precedent in digital security. Tune in for an insightful discussion on the implications for both government and corporate security.

Show notes: https://sharedsecurity.net/2025/03/03/cybersecurity-impact-of-doge-apples-stand-against-encryption-backdoors/

View Details

In this episode, we welcome cybersecurity researcher and YouTube legend John Hammond. John shares insights from his career at Huntress and his popular YouTube channel, where he creates educational content on cybersecurity. He introduces his new platform, Just Hacking Training, aimed at providing affordable, high-quality training. John also discusses current trends in cybercrime, the role of AI in attacks, and provides tips on avoiding social engineering. The episode highlights an upcoming Capture the Flag event hosted by Snyk, and how Just Hacking Training offers access to archived CTF challenges for continuous learning. Tune in for an engaging conversation on the state of cybersecurity and practical advice for staying secure.

Show notes: https://sharedsecurity.net/2025/02/24/cybersecurity-insights-with-john-hammond-youtube-legend-and-security-researcher/

View Details

In this episode, we discuss the UK government’s demand for Apple to create a secret backdoor for accessing encrypted iCloud backups under the Investigatory Powers Act and its potential global implications on privacy. We also discuss the first known case where AI chatbots were used in a stalking indictment, highlighting the dangers of technology misuse and the challenges it poses for legal systems. Join hosts Tom and Scott as they explore these pressing issues and introduce a new sub segment ‘AI Spy’ to focus on AI risks. Stay safe, stay secure, and stay informed!

* Links mentioned on the show *

UK’s secret Apple iCloud backdoor order is a global emergency, say critics
https://techcrunch.com/2025/02/10/uks-secret-apple-icloud-backdoor-order-is-a-global-emergency-say-critics/

A man stalked a professor for six years. Then he used AI chatbots to lure strangers to her home
https://www.theguardian.com/technology/2025/feb/01/stalking-ai-chatbot-impersonator

* Watch this episode on YouTube *

https://youtu.be/xTzd7kFXCMQ

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post UK’s Secret Apple Backdoor Request, AI Chatbots Used For Stalking appeared first on Shared Security Podcast.

View Details

In this episode we welcome Kathleen Smith, CMO of ClearedJobs.net, to discuss the current state of the cybersecurity job market. Kathleen shares her extensive experience in the field, recounting her tenure in various cybersecurity events and her contributions to job market research and recruiting. She discusses challenges such as distinguishing between genuine workforce shortages and hype, the importance of precise job descriptions, and the impacts of using AI in resume generation. Kathleen emphasizes that thorough job searches and well-crafted resumes are crucial for job seekers. Additionally, she highlights the need for clarity in cybersecurity job titles and roles to help bridge the gap between job seekers and employers. The episode ends with practical advice for job seekers on how to make their resumes stand out.

* Links mentioned on the show *

Connect with Kathleen on LinkedIn
https://www.linkedin.com/in/kathleenesmith/

ClearedJobs.net
https://clearedjobs.net/

Security Cleared Jobs Podcast
https://clearedjobs.net/podcast

* Watch this episode on YouTube *

https://youtu.be/_6G88ydXEPc

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Careers in Cybersecurity: Myths and Realities with Kathleen Smith appeared first on Shared Security Podcast.

View Details

In this episode, we explore the rollout of digital driver’s licenses in states like Illinois and the potential privacy issues that come with them. Can digital IDs truly enhance convenience without compromising your privacy? We also discuss the new Chinese AI model, DeepSeek, which is affecting U.S. tech companies’ stock prices. Join us as we provide insights on these emerging trends and their implications.

* Links mentioned on the show *

Illinois residents may soon be able to own digital driver’s licenses and state IDs
https://www.sj-r.com/story/news/state/2025/01/15/digital-state-ids-licenses-could-be-available-soon-in-illinois/77697952007/

DeepSeek’s popularity exploited by malware peddlers, scammers
https://www.helpnetsecurity.com/2025/01/29/deepseek-popularity-exploited-malware-scams/

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Privacy Concerns with Digital Driver’s Licenses, The Rise of DeepSeek AI appeared first on Shared Security Podcast.

View Details

In this episode, we discuss the latest issues with data brokers, focusing on a breach at Gravy Analytics that leaked 30 million location data points online. We also explore a vulnerability in Subaru’s Starlink system that allows unrestricted access to vehicle controls and customer data using just a last name and license plate number. Co-host Kevin Johnson joins the discussion to share insights and emphasize the need for stronger privacy regulations.

* Links mentioned on the show *

Data broker Gravy Analytics confirms a data breach after a hacker leaked millions of location recordshttps://techcrunch.com/2025/01/13/gravy-analytics-data-broker-breach-trove-of-location-data-threatens-privacy-millions/

Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel
https://samcurry.net/hacking-subaru

* Watch this episode on YouTube *

https://youtu.be/RNSdVChT-i8

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Gravy Analytics Breach, Subaru Starlink Vulnerability Exposed appeared first on Shared Security Podcast.

View Details

In this episode, we explore Meta’s recent decision to replace traditional fact-checking with community notes and its potential impact on misinformation. We also discuss the implications of a TikTok ban in the U.S., with users migrating to similar apps like RedNote. The conversation covers the challenges of maintaining reliable information in social media and the shifting landscape of news consumption. Additionally, we delve into issues regarding AI-generated content, privacy concerns with Chinese-owned apps, and the importance of personal responsibility in fact-checking.

* Links mentioned on the show *

Meta ditches fact-checking for community notes ahead of second Trump termhttps://mashable.com/article/meta-ditches-fact-checking-for-community-notes

As Americans flock to RedNote, privacy advocates warn about surveillance
Over 700,000 users have downloaded the app in the lead-up to the TikTok ban
https://www.theverge.com/2025/1/16/24345245/rednote-xiaohongshu-tiktok-ban-privacy

I don't know how many of y'all are watching the migration of American TikTokers to RedNote, but it's the most fascinating thing I've EVER SEEN HAPPEN ONLINE.

— Erica Wilkinson (@everywhereerica.bsky.social) 2025-01-14T14:50:09.972Z

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Meta Ditches Fact-Checking for Community Notes, RedNote and the TikTok Ban appeared first on Shared Security Podcast.

View Details

Do you ever read the privacy policy of your favorite AI tools like ChatGPT, Gemini, or Claude? In this episode, Scott Wright and Tom Eston discuss the critical aspects of these policies, comparing how each AI engine handles your personal data. They explore the implications of data usage, security, and privacy in AI, with insights from industry giants like Anthropic’s CEO, Dario Amodai. Are these AI tools safe to use? Find out as we break down the complexities and share our thoughts on the future of AI – and its impact on your data privacy.

* Links mentioned on the show *

Dario Amodei: Anthropic CEO on Claude, AGI & the Future of AI & Humanity
https://lexfridman.com/dario-amodei/

Every Choice Matters: Data Security And Privacy On AI-Enabled Apps
https://www.forbes.com/councils/forbestechcouncil/2024/12/16/every-choice-matters-data-security-and-privacy-on-ai-enabled-apps/

* Watch this episode on YouTube *

https://youtu.be/vbXVNXG0yDI

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post AI Privacy Policies: Unveiling the Secrets Behind ChatGPT, Gemini, and Claude appeared first on Shared Security Podcast.

View Details

Join us as we reminisce about Y2K, the panic, the preparations, and the lessons learned 25 years later. We also discuss the implications for future technology like AI and potential cybersecurity crises. Plus, in our ‘Aware Much’ segment, Scott shares tips on protecting your data if your phone is stolen. Happy New Year and welcome to our first episode of 2025!

* Links mentioned on the show *

Y2K at 25: Panic, preparation and payoff
https://mashable.com/article/y2k-25-years-later

Protecting your data when your phone is stolen – literally right out of your hands
https://www.linkedin.com/posts/paulgurney_theft-security-phone-ugcPost-7270798464425332736-PyEi

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Reflecting on Y2K: Lessons for the Next Tech Crisis and AI Safety appeared first on Shared Security Podcast.

View Details

In the final episode of the Shared Security Podcast for 2024, join us as we recap our predictions for the year, discuss what we got right and wrong, and highlight our top episodes on YouTube. We also extend a heartfelt thank you to our Patreon supporters and special guests. Plus, stay tuned for our predictions for 2025 and some fun discussions on AI’s impact, phishing attacks, and more. Happy New Year and thank you for your support!

* Links mentioned on the show *

Our 2024 Prediction Episode
https://sharedsecurity.net/2023/12/25/the-year-in-review-and-2024-predictions/

Become a supporter in 2025 and help support the show!
https://patreon.com/SharedSecurity

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post 2024 Year in Review: What We Got Right and Looking to 2025 appeared first on Shared Security Podcast.

View Details

In this episode Tom, Scott, and Kevin discuss the vulnerabilities of digital license plates and the potential for hackers to exploit them. They explain what digital license plates are and how they work. The ‘Aware Much?’ segment covers the topic of suspicious text messages and why you should avoid responding to unknown senders. The team also shares personal project frustrations and emphasizes the importance of cybersecurity measures in IoT devices. Stay tuned for insightful discussions and practical advice on staying secure.

* Links mentioned on the show *

Hackers Can Jailbreak Digital License Plates to Make Others Pay Their Tolls and Tickets
https://www.wired.com/story/digital-license-plate-jailbreak-hack/

What’s the deal with these scam texts with no obvious motive?
Turns out it could be number warming.
https://www.linkedin.com/posts/vulnerable-u_cybersecurity-infosec-activity-7273087449319268352-iFmn

Why it’s not rude to ignore “hi, how are you?” text messages from strangers
https://consumer.ftc.gov/consumer-alerts/2024/05/why-its-not-rude-ignore-hi-how-are-you-text-messages-strangers

* Watch this episode on YouTube *

https://youtu.be/MUzUf1U0An0

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Digital License Plate Vulnerabilities, How to Avoid New Text Message Scams appeared first on Shared Security Podcast.

View Details

In Episode 359 of the Shared Security Podcast, the team examines a shocking hack-for-hire operation alleged to target over 500 climate activists and journalists, potentially involving corporate sponsorship by ExxonMobil. They explore the intricate layers of this multifaceted campaign and the broader implications on security risk assessments. Additionally, Scott discusses the massive Salt Typhoon hacking campaign attributed to China, which has compromised major U.S. telecommunications companies, and the surprising shift in U.S. government stance on end-to-end encryption. Join Tom, Kevin, and Scott for their in-depth analysis and a touch of humor throughout this episode.

* Links mentioned on the show *

Inside ExxonMobil’s Alleged Hack-for-Hire Campaign Targeting Climate Activists
https://www.vulnu.com/p/inside-exxonmobils-alleged-hack-for-hire-campaign-targeting-climate-activists
https://www.reuters.com/business/energy/exxon-lobbyist-investigated-over-hack-and-leak-environmentalist-emails-sources-2024-11-27/

U.S. officials urge Americans to use encrypted apps amid cyberattack that exposed live phone calls
https://www.nbcnews.com/tech/security/us-officials-urge-americans-use-encrypted-apps-cyberattack-rcna182694

* Watch this episode on YouTube *

https://youtu.be/z009bcalLhE

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Hack-for-Hire Campaign Targeting Climate Activists, Government Hypocrisy on Encryption appeared first on Shared Security Podcast.

View Details

Join us for an insightful episode of the Shared Security Podcast as Tanya Janca returns for her fifth appearance. Discover the latest on her new book about secure coding, exciting updates in Application Security, and the use of AI in security. Learn how her new book goes deeper into secure coding practices, backed by her […]

The post Tanya Janca on Secure Coding, AI in Cybersecurity, and Her New Book appeared first on Shared Security Podcast.

View Details

In this episode, we discuss Australia’s new legislation banning social media for users under 16 and its potential impact. Our hosts also explore the issue of vishing (voicemail phishing), why it’s escalating, particularly during the holiday season, and how to protect yourself against these scams. Plus, we celebrate a milestone on our YouTube channel and […]

The post Australia Bans Social Media for Kids, Holiday Vishing Scams appeared first on Shared Security Podcast.

View Details

In Episode 356, Tom and Kevin discuss the increasing role of deepfake technology in bypassing biometric checks, accounting for 24 percent of fraud attempts. The show covers identity fraud issues and explores the controversial practices of data brokers selling location data, including tracking US military personnel. The conversation shifts to social media platforms Twitter, Blue […]

The post Deepfake Fraud, Data Brokers Tracking Military Personnel appeared first on Shared Security Podcast.

View Details

In episode 355, Tom discusses his decision to deactivate his Twitter accounts due to privacy concerns with Twitter’s new AI policy and changes in the blocking features. He outlines the steps for leaving Twitter, including how to archive and delete tweets, and evaluates alternative platforms such as Bluesky, Mastodon, and Threads for cybersecurity professionals seeking […]

The post Why It’s Time to Leave Twitter appeared first on Shared Security Podcast.

View Details

In episode 354, we discuss the emergence of the term ‘Advanced Persistent Teenagers’ (APT) as a “new” cybersecurity threat. Recorded just before the election, the hosts humorously predict election outcomes while exploring the rise of teenage hackers responsible for major breaches. The episode also covers a notable Okta vulnerability that allowed someone to login without […]

The post Advanced Persistent Teenagers, Okta Bug Allowed Logins Without a Correct Password appeared first on Shared Security Podcast.

View Details

In episode 354, we discuss the emergence of the term 'Advanced Persistent Teenagers' (APT) as a “new” cybersecurity threat. Recorded just before the election, the hosts humorously predict election outcomes while exploring the rise of teenage hackers responsible for major breaches. The episode also covers a notable Okta vulnerability that allowed someone to login without the correct password and its implications. Tune in for an engaging conversation on the evolving landscape of cyber threats.

Show notes: https://sharedsecurity.net/2024/11/11/advanced-persistent-teenagers-okta-bug-allowed-logins-without-a-correct-password/

View Details

In episode 353, we discuss the February 2024 ransomware attack on Change Healthcare, resulting in the largest data breach of protected health information in history. Notifications have been sent to 100 million Americans, including hosts Tom and Kevin. We explore the implications of this significant breach and whether paying ransoms is a viable solution. In the 'Aware Much' segment, Scott explains how mortgage wire fraud works and provides essential tips for real estate transactions to avoid such scams. Plus, a quick recap on our popular AI-powered toilet cameras episode.

Show notes: https://sharedsecurity.net/2024/11/04/fallout-from-the-change-healthcare-breach-mortgage-wire-fraud-what-you-need-to-know/

View Details

In this episode, we discuss the significant data breach at the Internet Archive, affecting 33 million users. We also examine the introduction of an AI-integrated toilet camera by Throne, designed for health monitoring by analyzing bodily waste, and the ensuing privacy concerns. We explore these technological advancements alongside other unusual tech innovations, touching upon security issues with home cameras, personal data in health apps, and broader implications for privacy and technology.

Show notes: https://sharedsecurity.net/2024/10/28/internet-archive-hacked-introducing-the-ai-toilet-camera/

View Details

In episode 351 of the Shared Security Podcast, hosts Tom and Scott explore an unusual incident where robot vacuums were hacked to shout obscenities, exposing significant IoT security issues. The discussion includes the mechanics of the Bluetooth hack and its broader cybersecurity implications. Additionally, the 'Aware Much?' segment reveals the world of hidden printer tracking dots, used for tracing document origins and their historical use by governments for tracking. This episode also highlights the technology's role in preventing currency counterfeiting and capturing high-profile leaks, underscoring the intersection of privacy and security in modern times.

Show notes: https://sharedsecurity.net/2024/10/21/hacked-robot-vacuums-secret-printer-tracking-dots/

View Details

In the milestone 350th episode of the Shared Security Podcast, the hosts reflect on 15 years of podcasting, and the podcast's evolution from its beginnings in 2009. They discuss the impact of a current hurricane on Florida, offering advice on using iPhone and Android satellite communication features during emergencies. The 'Aware Much' segment focuses on the lack of change in user behavior towards cybersecurity, highlighting persistent issues like inadequate password manager usage and infrequent software updates. The episode covers historical insights into social media's evolution, including privacy guides and LinkedIn's fake profile problem, emphasizing the importance of a well-rounded approach to cybersecurity awareness and education.

Show notes: https://sharedsecurity.net/2024/10/14/emergency-satellite-messaging-stagnation-in-user-cybersecurity-habits/

View Details

In this episode, the hosts discuss a significant vulnerability found in Kia's web portal that allows remote control of various car features via their app, potentially enabling unauthorized unlocking and tracking. The conversation highlights the broader issue of web vulnerabilities in the automotive industry. Also covered are NIST's updated password guidelines, eliminating complexity rules and periodic resets, emphasizing the importance of MFA. The episode features insights from co-host Kevin Johnson, covering both technical flaws and the security community's perspectives on these evolving issues.

Show notes: https://sharedsecurity.net/2024/10/07/kia-security-flaw-exposed-nists-new-password-guidelines/

View Details

In episode 348 of the Shared Security Podcast, Tom and Scott discuss Discord's new end-to-end encryption for audio and video calls, involving the DAVE Protocol, third-party vetting by Trail of Bits, and its impact on users. They also address LinkedIn's controversial move to automatically opt users into using their data to train AI models without initial consent, suggestions for opting out, and the broader implications for user privacy.

Show notes: https://sharedsecurity.net/2024/09/30/discords-new-end-to-end-encryption-for-audio-video-linkedin-using-your-data-for-ai-training/

View Details

In Episode 347, we discuss the recent alarming incidents involving exploding pagers targeting Hezbollah operatives in Lebanon, which resulted in multiple casualties. We clarify why this is not a cyber attack and should not cause widespread panic about personal device safety. Additionally, we cover Instagram’s new policies to default teen accounts to private and the implications for parental control and teen safety on social media.

* Links mentioned on the show *

Exploding pagers belonging to Hezbollah kill 8 and injure more than 2,700 in Lebanon
https://www.nbcnews.com/news/world/hezbollah-pagers-expolsion-lebanon-handheld-devices-rcna171457
https://www.reuters.com/world/middle-east/israel-planted-explosives-hezbollahs-taiwan-made-pagers-sources-say-2024-09-18/

Introducing Instagram Teen Accounts: Built-In Protections for Teens, Peace of Mind for Parents
https://about.fb.com/news/2024/09/instagram-teen-accounts/
https://www.msn.com/en-us/news/technology/instagram-makes-teen-accounts-private-as-pressure-mounts-on-the-app-to-protect-children/ar-AA1qHVsi

* Watch this episode on YouTube *

https://youtu.be/QAP9tdy6mGA

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Supply Chain Sabotage: The Exploding Pager Incident, Instagram’s New Teen Privacy Measures appeared first on Shared Security Podcast.

View Details

In episode 346, we discuss new AI-driven voicemail scams that sound convincingly real and how to identify them. We also explore recent research on the privacy concerns surrounding donations to political parties through their websites. Additionally, we celebrate the 15th anniversary of the podcast and share some reflections and fun facts about the journey. Join us for this insightful and informative episode!

* Links mentioned on the show *

Security Justice Podcast (2008-2011)
https://archive.org/details/securityjustice

Your personal data is political: W&M computer scientists find gaps in the privacy practices of campaign websites
https://news.wm.edu/2024/02/07/your-personal-data-is-political-wm-computer-scientists-find-gaps-in-the-privacy-practices-of-campaign-websites/

* Watch this episode on YouTube *

https://youtu.be/GOXUK4Wd2YM

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The Rise of AI Voicemail Scams, Political Donation Privacy Concerns appeared first on Shared Security Podcast.

View Details

This week, we discuss a critical SQL injection vulnerability discovered in an app used by the TSA, raising ethical questions about responsible disclosure. Plus, we shed light on the alarming rise of Bitcoin ATM scams exploiting older adults, providing essential tips to protect your loved ones from these devious schemes. Tune in for unique insights and vital cybersecurity advice!

* Links mentioned on the show *

Bypassing airport security via SQL injection
https://ian.sh/tsa
https://x.com/mattjay/status/1831004620950278397?s=46&t=S0l2WLszljUYE1vbjB4M9A

FTC: Over $110 million lost to Bitcoin ATM scams in 2023
https://www.bleepingcomputer.com/news/security/ftc-americans-lost-over-110-million-to-bitcoin-atm-scams-in-2023/

* Watch this episode on YouTube *

https://youtu.be/sL1sfY3ATXM

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Shocking SQL Injection in TSA App, Bitcoin ATM Scams Targeting Seniors appeared first on Shared Security Podcast.

View Details

In this episode, we explore the recent arrest of Telegram founder Pavel Durov in France and discuss the app’s encryption claims. Is Telegram truly an encrypted messaging app? Joining the conversation is co-host Kevin Johnson, bringing his trademark opinions. We also talk about some intriguing documentaries, including ‘LulaRich’ about the LuLaRoe leggings company and ‘Class Action Park’ about a dangerous theme park in New Jersey. Tune in to hear our thoughts on these topics and more!

* Links mentioned on the show *

The Arrest of Pavel Durov Is a Reminder That Telegram Is Not Encrypted
https://gizmodo.com/the-arrest-of-pavel-durov-is-a-reminder-that-telegram-is-not-encrypted-2000490960
https://www.404media.co/how-telegrams-founder-pavel-durov-became-a-culture-war-martyr/

The girl Pavel Durov wanted to show around Paris. She was literally posting every step of Durov online with photos and geolocations.
https://x.com/runews/status/1827732141670572313

1834: The First Cyberattack
https://www.schneier.com/blog/archives/2018/05/1834_the_first_.html

LuLaRich Documentary (Amazon Prime)
https://www.imdb.com/title/tt15213278/

Class Action Park Documentary (HBO Max)
https://www.imdb.com/title/tt11015214/

* Watch this episode on YouTube *

https://youtu.be/7kJYkd4Js20

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Telegram is NOT an Encrypted Messaging App, Must-See Documentaries appeared first on Shared Security Podcast.

View Details

In this episode, we explore the recent arrest of Telegram founder Pavel Durov in France and discuss the app's encryption claims. Is Telegram truly an encrypted messaging app? Joining the conversation is co-host Kevin Johnson, bringing his trademark opinions. We also talk about some intriguing documentaries, including 'LulaRich' about the LuLaRoe leggings company and 'Class Action Park' about a dangerous theme park in New Jersey. Tune in to hear our thoughts on these topics and more!

Show notes: https://sharedsecurity.net/2024/09/02/telegram-is-not-an-encrypted-messaging-app-must-see-documentaries/

View Details

This week, we discuss Google's recent accusation by the U.S. Justice Department for being a monopoly and its implications for privacy and cybersecurity. We also cover essential privacy settings for Alexa smart speakers and their importance. Join the hosts, Tom, Kevin, and Scott, for an engaging conversation on these topics, along with a segment from ClickArmor on cybersecurity training. Plus, a recap of the Black Hat and BSides Las Vegas conferences.

Show notes: https://sharedsecurity.net/2024/08/26/googles-monopoly-the-debate-heats-up-amazon-alexa-privacy-tips/

View Details

In episode 342, we discuss the effectiveness of people-search removal tools like DeleteMe and Reputation Defender, based on a study by Consumer Reports. We also cover how almost every American’s social security number has potentially been stolen by hackers and shared on the dark web. Scott and Tom talk about the importance of protecting your personal information and methods to do so, including manually removing data and placing credit freezes. Plus, we touch on Canada’s privacy laws and wrap up with our Aware Much segment. Stay safe, stay secure, and stay private!

* Links mentioned on the show *

People-Search Site Removal Services Largely Ineffective
https://www.schneier.com/blog/archives/2024/08/people-search-site-removal-services-largely-ineffective.html
https://innovation.consumerreports.org/wp-content/uploads/2024/08/Data-Defense_-Evaluating-People-Search-Site-Removal-Services-.pdf

Michael Bazzell’s Data Request Guide
https://inteltechniques.com/requests.html

Hackers may have stolen the Social Security numbers of every American. Here’s how to protect yourself
https://www.latimes.com/business/story/2024-08-13/hacker-claims-theft-of-every-american-social-security-number

* Watch this episode on YouTube *

https://youtu.be/fODmnhqugSg

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The Inefficiency of People-Search Removal Tools, Massive Data Breach Impacting U.S. Citizens appeared first on Shared Security Podcast.

View Details

Join us for this special live edition of the Shared Security Podcast, recorded in scorching Las Vegas at Black Hat 2024. Host Tom Eston is joined by Shourya Pratap Singh, Principal Software Engineer at SquareX. They discuss highlights from Black Hat 2024, emerging themes in cybersecurity such as AI-based threats, compliance, and cloud security. The conversation also covers the DEF CON talk given by Vivek and Shourya on Last Mile Reassembly Attacks, which exposes a critical flaw in Secure Web Gateways (SWGs) and introduces an open-source toolkit for Red Teams.

Thank you to SquareX for sponsoring this episode! Find out more about SquareX at https://sqrx.com/

Show notes: https://sharedsecurity.net/2024/08/12/exploring-cybersecurity-trends-at-black-hat-and-def-con-2024-with-shourya-pratap-singh-from-squarex/

View Details

In episode 341, we cover the unprecedented global IT outage caused by a CrowdStrike update crash, affecting 8.5 million Windows machines. We discuss whether it’s the largest outage in history and discuss the intricacies of internet accessibility and responses from key stakeholders like Microsoft. Also, in our Aware Much segment, we explore Japan’s AI system, Mr. Smile, designed to standardize employee smiles, and its implications on employee monitoring. Plus, we welcome back Kevin and give a special shout-out to our latest Patreon supporter.

* Links mentioned on the show *

CrowdStrike update crashes Windows systems, causes outages worldwide
https://www.bleepingcomputer.com/news/security/crowdstrike-update-crashes-windows-systems-causes-outages-worldwide/
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-repair-tool-to-remove-crowdstrike-driver

Japan supermarket chain uses AI to gauge staff smiles, speech tones in quality service push
https://www.scmp.com/news/people-culture/article/3271333/japan-supermarket-chain-uses-ai-gauge-staff-smiles-speech-tones-quality-service-push

* Watch this episode on YouTube *

https://youtu.be/S0Nni4l_WWE

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The Great CrowdStrike Crash, AI’s Role in Employee Smiles appeared first on Shared Security Podcast.

View Details

In episode 341, we cover the unprecedented global IT outage caused by a CrowdStrike update crash, affecting 8.5 million Windows machines. We discuss whether it's the largest outage in history and discuss the intricacies of internet accessibility and responses from key stakeholders like Microsoft. Also, in our Aware Much segment, we explore Japan's AI system, Mr. Smile, designed to standardize employee smiles, and its implications on employee monitoring. Plus, we welcome back Kevin and give a special shout-out to our latest Patreon supporter.

Show notes: https://sharedsecurity.net/2024/08/05/the-great-crowdstrike-crash-ais-role-in-employee-smiles/

View Details

In this episode, Tom Eston hosts Jeswin Mathai, Chief Architect at SquareX. This episode is part two of a series featuring SquareX, and Jeswin takes a deeper look into their cybersecurity solutions. Jeswin shares his extensive experience in the field and details how SquareX offers innovative protections at the browser level to guard against phishing attacks and other online threats. Learn about their unique approach by monitoring user activity in a privacy-safe manner and leveraging the power of modern browsers and device capabilities. Jeswin also discusses the limitations of traditional antivirus and secure web gateway solutions compared to SquareX’s comprehensive visibility and action capabilities. Don’t miss the live demonstration and insights on handling ransomware scenarios and deployment strategies for businesses of all sizes. The episode concludes with a sneak peek of what Jeswin and Vivek will be presenting at the upcoming DEF CON hacking conference.

Thank you to SquareX for sponsoring this episode! Find out more about SquareX at https://sqrx.com/

* Watch this episode on YouTube *

https://youtu.be/_t_-HW1wbBA

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post How SquareX is Redefining Web Security: An In-Depth Discussion with Chief Architect Jeswin Mathai appeared first on Shared Security Podcast.

View Details

In this episode, host Tom Eston welcomes Dan DeCloss, founder and CTO of PlexTrac. They exchange insights about their history at Veracode and explore Dan’s journey in cybersecurity. Dan shares his experience in penetration testing, the origins of PlexTrac, and the need to streamline reporting processes. The conversation also covers the state of the cybersecurity industry, the impact of generative AI, and future challenges such as deepfake technology. Dan touches upon the evolution of attackers and the role of both AI and human elements. The episode wraps up with thoughts on the younger generation’s approach to discerning information in a tech-driven world.

* Links mentioned on the show *

Connect with Dan
https://www.linkedin.com/in/ddecloss/

Find out more about PlexTrac
https://plextrac.com/

* Watch this episode on YouTube *

https://youtu.be/3MRnGvZd7U0

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Deepfakes, AI, and the Future of Cybersecurity: Insights from Dan DeCloss of PlexTrac appeared first on Shared Security Podcast.

View Details

In this episode, host Tom Eston welcomes Dan DeCloss, founder and CTO of PlexTrac. They exchange insights about their history at Veracode and explore Dan's journey in cybersecurity. Dan shares his experience in penetration testing, the origins of PlexTrac, and the need to streamline reporting processes. The conversation also covers the state of the cybersecurity industry, the impact of generative AI, and future challenges such as deepfake technology. Dan touches upon the evolution of attackers and the role of both AI and human elements. The episode wraps up with thoughts on the younger generation's approach to discerning information in a tech-driven world.

Show notes: https://sharedsecurity.net/2024/07/29/deepfakes-ai-and-the-future-of-cybersecurity-insights-from-dan-decloss-of-plextrac/

View Details

In episode 339, hosts Tom Eston and Scott Wright discuss the massive AT&T data breach affecting 110 million customers, which is larger than a previous breach from March affecting 73 million customers. They also talk about the importance of reading privacy policies on sites like Facebook and Instagram, as these platforms may use user data to train AI models. Additionally, they explore the implications of third-party cloud platform breaches, specifically mentioning the Snowflake incident. The ‘Aware Much?’ segment highlights evolving privacy policies, with Meta’s revised policy allowing user data for AI development being under scrutiny. The episode concludes with a mention of the importance of GDPR and other data protection regulations and a nod to their Patreon supporters.

* Links mentioned on the show *

Crooks Steal Phone, SMS Records for Nearly All AT&T Customers
https://krebsonsecurity.com/2024/07/hackers-steal-phone-sms-records-for-nearly-all-att-customers/

Privacy warriors gripe to UK watchdog about Meta harvesting user data to train AI
https://www.theregister.com/2024/07/16/campaign_group_complains_to_uk/

Terms of Services Didn’t Read
https://tosdr.org/en/frontpage

Privacy Decrypted #6: How to read a privacy policy
https://proton.me/blog/how-to-read-privacy-policy

* Watch this episode on YouTube *

https://youtu.be/YWV6OiNzR_A

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Massive AT&T Data Breach Impact, Meta’s Privacy Policy Updates appeared first on Shared Security Podcast.

View Details

In episode 339, hosts Tom Eston and Scott Wright discuss the massive AT&T data breach affecting 110 million customers, which is larger than a previous breach from March affecting 73 million customers. They also talk about the importance of reading privacy policies on sites like Facebook and Instagram, as these platforms may use user data to train AI models. Additionally, they explore the implications of third-party cloud platform breaches, specifically mentioning the Snowflake incident. The 'Aware Much?' segment highlights evolving privacy policies, with Meta's revised policy allowing user data for AI development being under scrutiny. The episode concludes with a mention of the importance of GDPR and other data protection regulations and a nod to their Patreon supporters.

Show notes: https://sharedsecurity.net/2024/07/22/massive-att-data-breach-impact-metas-privacy-policy-updates/

View Details

In episode 338, we discuss the recent breach of the two-factor authentication provider Authy and its implications for users. We also explore a massive password list leak titled ‘Rock You 2024’ that has surfaced online. Find out why this file may not be as significant as it seems and the importance of avoiding password reuse. Stay tuned for our ‘Aware Much?’ segment with Scott Wright, featuring insights on credential stuffing and practical password management tips.

* Links mentioned on the show *

Using Authy? Beware of impending phishing attempts
https://www.helpnetsecurity.com/2024/07/11/using-authy-beware-of-impending-phishing-attempts/

Nearly 10 Billion Passwords Leaked in Biggest Compilation of All Time
https://www.techrepublic.com/article/worlds-largest-password-leak/

Rockyou2024 analysis: Mega password list or just noise?
https://specopssoft.com/blog/rockyou2024-analysis-password-leak/

* Watch this episode on YouTube *

https://youtu.be/28A0buGYycQ

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Authy Breach: What It Means for You, RockYou 2024 Password Leak appeared first on Shared Security Podcast.

View Details

In episode 338, we discuss the recent breach of the two-factor authentication provider Authy and its implications for users. We also explore a massive password list leak titled 'Rock You 2024' that has surfaced online. Find out why this file may not be as significant as it seems and the importance of avoiding password reuse. Stay tuned for our 'Aware Much?' segment with Scott Wright, featuring insights on credential stuffing and practical password management tips.

Show notes: https://sharedsecurity.net/2024/07/15/authy-breach-what-it-means-for-you-rockyou-2024-password-leak/

View Details

In episode 337, we cover “broken” news about the new SSH vulnerability ‘regreSSHion‘ highlighting the vulnerability discovered in the OpenSSH protocol by Qualys and its implications. We then discuss the Detroit Police Department’s new guidelines on facial recognition technology following a lawsuit over a wrongful arrest due to misidentification, shedding light on the broader issues with such technologies, especially their impact on minorities. Lastly, in the ‘Aware Much’ segment, Scott shares essential tips on securely wiping personal data from old PCs, laptops, smartphones, and other electronic devices before selling or disposing of them. Join us as we welcome back co-hosts Kevin Johnson from Portugal and Scott recording from his car!

* Links mentioned on the show *

New regreSSHion OpenSSH RCE bug gives root on Linux servers
https://www.bleepingcomputer.com/news/security/new-regresshion-openssh-rce-bug-gives-root-on-linux-servers/

Detroit Police Department agrees to new rules around facial recognition tech
https://techcrunch.com/2024/06/29/detroit-police-department-agrees-to-new-rules-around-facial-recognition-tech/

How to Wipe a Computer Clean of Personal Data
https://www.consumerreports.org/electronics-computers/computers/how-to-wipe-a-computer-clean-of-personal-data-a5849951358/
https://x.com/cradvocacy/status/1807827599890006166?s=46&t=S0l2WLszljUYE1vbjB4M9A

* Watch this episode on YouTube *

https://youtu.be/ISsQpDJNOnc

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Critical SSH Vulnerability, Facial Recognition Flaws, How to Safely Dispose of Old Devices appeared first on Shared Security Podcast.

View Details

In episode 337, we cover “broken” news about the new SSH vulnerability 'regreSSHion' highlighting the vulnerability discovered in the OpenSSH protocol by Qualys and its implications. We then discuss the Detroit Police Department's new guidelines on facial recognition technology following a lawsuit over a wrongful arrest due to misidentification, shedding light on the broader issues with such technologies, especially their impact on minorities. Lastly, in the 'Aware Much' segment, Scott shares essential tips on securely wiping personal data from old PCs, laptops, smartphones, and other electronic devices before selling or disposing of them. Join us as we welcome back co-hosts Kevin Johnson from Portugal and Scott recording from his car!

Show notes: https://sharedsecurity.net/2024/07/08/critical-ssh-vulnerability-facial-recognition-flaws-how-to-safely-dispose-of-old-devices/

View Details

In episode 336 of the Shared Security Podcast, we discuss the Biden administration’s recent ban on Kaspersky antivirus software in the U.S. due to security concerns linked to its Russian origins. We also highlight the importance of keeping all software updated, using recent examples of supply chain attacks that have compromised several popular WordPress plugins. Join hosts Tom Eston and Scott Wright as they examine these key cybersecurity issues and emphasize proactive security measures. Plus, find out why co-host Kevin Johnson is missing this week and get the latest updates from Aware Much, sponsored by ClickArmor.

Thank you to SquareX for sponsoring this episode! Find out more about SquareX at https://sqrx.com/

* Links mentioned on the show *

Biden bans Kaspersky antivirus software in US over security concerns
https://www.bleepingcomputer.com/news/security/biden-bans-kaspersky-antivirus-software-in-us-over-security-concerns/

Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attackhttps://arstechnica.com/security/2024/06/supply-chain-attack-on-wordpress-plugins-affects-as-many-as-36000-sites/

* Watch this episode on YouTube *

https://youtu.be/svkH_8dou5Y

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The U.S. Bans Kaspersky Antivirus, WordPress Plugin Supply Chain Attacks appeared first on Shared Security Podcast.

View Details

In episode 336 of the Shared Security Podcast, we discuss the Biden administration's recent ban on Kaspersky antivirus software in the U.S. due to security concerns linked to its Russian origins. We also highlight the importance of keeping all software updated, using recent examples of supply chain attacks that have compromised several popular WordPress plugins. Join hosts Tom Eston and Scott Wright as they examine these key cybersecurity issues and emphasize proactive security measures. Plus, find out why co-host Kevin Johnson is missing this week and get the latest updates from Aware Much, sponsored by ClickArmor.

Show notes: https://sharedsecurity.net/2024/07/01/the-u-s-bans-kaspersky-antivirus-wordpress-plugin-supply-chain-attacks/

View Details

In this special episode of the Shared Security Podcast, host Tom Eston interviews Vivek Ramachandran, the founder of SquareX. Vivek shares his journey in WiFi security, recounting his introduction of the Cafe Latte man-in-the-middle attack and founding of Pentest Academy. He discusses his latest venture, SquareX, a company focused on browser security to protect employees from client-side attacks. Vivek explains SquareX’s workings, industry challenges, and insights into Secure Web Gateways (SWGs). He also previews his upcoming DEF CON talk on bypassing SWGs and shares thoughts on AI in cyber-attacks. Learn about the future of browser-based security solutions and how enterprises can better protect themselves against sophisticated attacks.

Thank you to SquareX for sponsoring this episode! Find out more about SquareX at https://sqrx.com/

* Links mentioned on the show *

Follow and connect with Vivek on LinkedIn
https://www.linkedin.com/in/vivekramachandran/

Follow Vivek and SquareX on Twitter
https://twitter.com/vivekramac
https://twitter.com/getsquarex

Find out more about SquareX and try it out for free!
https://sqrx.com/

* Watch this episode on YouTube *

https://youtu.be/fLk8wktOBSE

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Exploring Cutting-Edge Browser Security with Vivek Ramachandran – Founder of SquareX appeared first on Shared Security Podcast.

View Details

In this special episode of the Shared Security Podcast, host Tom Eston interviews Vivek Ramachandran, the founder of SquareX. Vivek shares his journey in WiFi security, recounting his introduction of the Cafe Latte man-in-the-middle attack and founding of Pentest Academy. He discusses his latest venture, SquareX, a company focused on browser security to protect employees from client-side attacks. Vivek explains SquareX's workings, industry challenges, and insights into Secure Web Gateways (SWGs). He also previews his upcoming DEF CON talk on bypassing SWGs and shares thoughts on AI in cyber-attacks. Learn about the future of browser-based security solutions and how enterprises can better protect themselves against sophisticated attacks.

Thank you to SquareX for sponsoring this episode! Find out more about SquareX at https://sqrx.com/

Show notes: https://sharedsecurity.net/2024/06/27/exploring-cutting-edge-browser-security-with-vivek-ramachandran-founder-of-squarex/

View Details

In this episode of the Shared Security Podcast, the team debates the Surgeon General’s recent call for social media warning labels and explores the pros and cons. Scott discusses whether passwords should be stored in web browsers, potentially sparking strong opinions. The hosts also provide an update on Microsoft’s delayed release of CoPilot Plus PCs due to security concerns and reflect on the underlying privacy issues. Join Tom, Scott, and Kevin for these engaging discussions and more!

* Links mentioned on the show *

Recall recalled (delayed)
https://www.bleepingcomputer.com/news/microsoft/microsoft-delays-windows-recall-amid-privacy-and-security-concerns/

The Surgeon General’s Fear-Mongering, Unconstitutional Effort to Label Social Media
https://www.eff.org/deeplinks/2024/06/no-online-speech-should-not-have-warning-labels

Should You Store Passwords In Your Browser?
https://www.linkedin.com/posts/tonycollette_store-passwords-in-your-browser-robert-activity-7205916756786245632-Hlq4

* Watch this episode on YouTube *

https://youtu.be/0134mOwouuM

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Social Media Warning Labels, Should You Store Passwords in Your Web Browser? appeared first on Shared Security Podcast.

View Details

In this episode of the Shared Security Podcast, the team debates the Surgeon General's recent call for social media warning labels and explores the pros and cons. Scott discusses whether passwords should be stored in web browsers, potentially sparking strong opinions. The hosts also provide an update on Microsoft's delayed release of CoPilot Plus PCs due to security concerns and reflect on the underlying privacy issues. Join Tom, Scott, and Kevin for these engaging discussions and more!

Show notes: https://sharedsecurity.net/2024/06/24/social-media-warning-labels-should-you-store-passwords-in-your-web-browser/

View Details

In episode 334, hosts Tom Eston, Scott Wright, and Kevin Johnson discuss two major topics. First, they explore the ongoing legal battle between Citizen Lab and the Israeli spyware company NSO Group. The courts have consistently blocked NSO’s attempts to access Citizen Lab’s documents to protect victim privacy. Second, they discuss Apple’s new AI features announced at their developer conference, prioritizing user privacy through opt-in by default, and its implications. Kevin shares strong opinions on NSO Group, while the hosts also review Citizen Lab’s investigative work and Apple’s approach to AI and privacy.

* Links mentioned on the show *

They Exposed an Israeli Spyware Firm. Now the Company Is Badgering Them in Court.
https://theintercept.com/2024/05/06/pegasus-nso-group-israeli-spyware-citizen-lab/

Report: New “Apple Intelligence” AI features will be opt-in by default
https://arstechnica.com/gadgets/2024/06/report-new-apple-intelligence-ai-features-will-be-opt-in-by-default/

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Citizen Lab vs. NSO Group, Apple AI and Privacy appeared first on Shared Security Podcast.

View Details

In episode 333 of the Shared Security Podcast, Tom and Scott discuss a recent massive data breach at Ticketmaster involving the data of 560 million customers, the blame game between Ticketmaster and third-party provider Snowflake, and the implications for both companies. Additionally, they discuss Live Nation’s ongoing monopoly investigation. In the ‘Aware Much’ segment, the rise of work-from-home job scams is analyzed, highlighting FBI warnings and tips to avoid falling victim to such schemes. The success of a past episode on Microsoft’s new recall feature is also mentioned, emphasizing privacy concerns and spirited audience discussions.

* Links mentioned on the show *

Check out our episode on Microsoft’s Recall feature and why we and others in the cybersecurity industry say this is a bad idea (at least how Microsoft is planning on rolling this out)

On Recall, I had a question about me (and Satya, lol) using the phrase "screenshot" where all of the documentation says snapshot, and MSFT people say it's just snapshots.

They're screenshots. They're just JPEG files, a constant stream of. On a 1tb PC it allocates enough space… pic.twitter.com/XM72eowRe0

— Kevin Beaumont (@GossiTheDog) June 6, 2024

Ticketmaster Confirms Cloud Breach, Amid Murky Details
https://www.darkreading.com/cyberattacks-data-breaches/ticketmaster-confirms-cloud-breach-murky-details
https://www.darkreading.com/cloud-security/ticketmaster-breach-showcases-saas-data-security-risks

FBI Warns of Rise in Work-From-Home Scams
https://www.infosecurity-magazine.com/news/fbi-warns-rise-wfh-scams/

* Watch this episode on YouTube *

https://youtu.be/lMxwRzi43Tg

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Ticketmaster Data Breach and Rising Work from Home Scams appeared first on Shared Security Podcast.

View Details

In episode 333 of the Shared Security Podcast, Tom and Scott discuss a recent massive data breach at Ticketmaster involving the data of 560 million customers, the blame game between Ticketmaster and third-party provider Snowflake, and the implications for both companies. Additionally, they discuss Live Nation's ongoing monopoly investigation. In the 'Aware Much' segment, the rise of work-from-home job scams is analyzed, highlighting FBI warnings and tips to avoid falling victim to such schemes. The success of a past episode on Microsoft's new recall feature is also mentioned, emphasizing privacy concerns and spirited audience discussions.

Show notes: https://sharedsecurity.net/2024/06/10/ticketmaster-data-breach-and-rising-work-from-home-scams/

View Details

In this episode host Tom Eston welcomes Jen VanAntwerp, founder of Sober in Cyber. Jen shares her journey in cybersecurity and marketing, and discusses the motivation behind creating alcohol-free networking events. Sober in Cyber provides much-needed alternatives to typical alcohol-centered industry events, fostering inclusive environments for both sober professionals and those simply seeking a different experience. Tune in to learn about their successful sober events, the growing support for such initiatives, and how they foster authentic professional connections without the influence of alcohol. For more details, visit SoberInCyber.org and join their supportive community on Discord.

* Links mentioned on the show *

Find out more about Sober in Cyber
https://www.soberincyber.org/

Join the Sober in Cyber Discord
https://discord.gg/cyqmY9CJ

* Watch this episode on YouTube *

https://youtu.be/7tfLHCWyS4g

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

Get our new Shared Security Podcast glitter stickers!
https://sharedsecurity.net/stickers

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Sober in Cyber: Creating Alcohol-Free Networking in Cybersecurity with Jen VanAntwerp appeared first on Shared Security Podcast.

View Details

In this episode host Tom Eston welcomes Jen VanAntwerp, founder of Sober in Cyber. Jen shares her journey in cybersecurity and marketing, and discusses the motivation behind creating alcohol-free networking events. Sober in Cyber provides much-needed alternatives to typical alcohol-centered industry events, fostering inclusive environments for both sober professionals and those simply seeking a different experience. Tune in to learn about their successful sober events, the growing support for such initiatives, and how they foster authentic professional connections without the influence of alcohol. For more details, visit SoberInCyber.org and join their supportive community on Discord.

Show notes: https://sharedsecurity.net/2024/06/03/sober-in-cyber-creating-alcohol-free-networking-in-cybersecurity-with-jen-vanantwerp/

View Details

Episode 331 of the Shared Security Podcast discusses privacy and security concerns related to two major technological developments: the introduction of Windows PC's new feature 'Recall,' part of Microsoft’s Copilot+, which captures desktop screenshots for AI-powered search tools, and Slack's policy of using user data to train machine learning features with users opted in by default. Tom and Kevin express significant concerns over the implications for privacy, data security, and the potential for misuse of these features. Discussions cover the technical workings, potential vulnerabilities, and broader impacts of these technologies on privacy and security. The episode also mentions anecdotes that illustrate the practical downsides of such technologies and hints at the broader trend of companies training AI models with user data without adequate transparency or consent.

Show notes: https://sharedsecurity.net/2024/05/27/microsofts-copilot-recall-feature-slacks-ai-training-controversy/

View Details

In episode 330 Tom, Scott, and Kevin discuss the new features for iPhones and Android phones designed to warn users about secret trackers, possibly aiding in identifying stalkers. The hosts discuss Apple and Google’s collaboration on a technology called DOLT (Detecting Unwanted Location Trackers), aiming to improve user privacy by detecting Bluetooth trackers like Tiles and AirTags. They also highlight the findings from the 2024 Verizon Data Breach Investigations Report (DBIR), discussing key statistics on company breaches, the average time to remediate vulnerabilities, the rise in ransomware and extortion cases, third-party risks, and the negligible impact of AI on current threats. Additionally, the segment touches on human-related incidents’ significant role in breaches. The episode concludes with the announcement of new Shared Security Podcast stickers.

* Links mentioned on the show *

iPhones And Androids Can Now Warn You of ‘Secret Trackers’
https://www.msn.com/en-gb/money/other/iphones-and-androids-can-now-warn-you-of-secret-trackers/ar-BB1mqmjg

Verizon releases their 2024 Data Breach Investigations Report (DBIR)
https://www.verizon.com/business/en-nl/resources/reports/dbir/2024/summary-of-findings/
https://www.scmagazine.com/news/verizons-2024-data-breach-investigations-report-5-key-takeaways

* Watch this episode on YouTube *

https://youtu.be/mWSXvQ3iF40

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post New Tracker Warning Features on iPhones & Androids, 2024 Verizon Data Breach Investigations Report appeared first on Shared Security Podcast.

View Details

In Episode 330 Tom, Scott, and Kevin discuss the new features for iPhones and Android phones designed to warn users about secret trackers, possibly aiding in identifying stalkers. The hosts discuss Apple and Google's collaboration on a technology called DOLT (Detecting Unwanted Location Trackers), aiming to improve user privacy by detecting Bluetooth trackers like Tiles and AirTags. They also highlight the findings from the 2024 Verizon Data Breach Investigations Report (DBIR), discussing key statistics on company breaches, the average time to remediate vulnerabilities, the rise in ransomware and extortion cases, third-party risks, and the negligible impact of AI on current threats. Additionally, the segment touches on human-related incidents' significant role in breaches. The episode concludes with the announcement of new Shared Security Podcast stickers.

Show notes: https://sharedsecurity.net/2024/05/20/new-tracker-warning-features-on-iphones-androids-2024-verizon-data-breach-investigations-report/

View Details

In this first-ever in-person recording of Shared Security, Tom and Kevin, along with special guest Matt Johansen from Reddit, discuss their experience at the RSA conference in San Francisco, including their walk-through of ‘enhanced security’ and the humorous misunderstanding that ensued. The conversation moves to the ubiquity of AI and machine learning buzzwords at the conference, questioning the genuine impact versus hype, and the saturation of AI claims among vendors. They explore the real-world applications of AI, how it’s currently being utilized in cybersecurity, and its potential to assist smaller security teams and raise the ‘cybersecurity poverty line.’ The discussion also touches on the false positives in AI-driven security tools and the nuanced benefits of AI in improving English proficiency globally, which could indirectly assist cybercriminals.

* Links mentioned on the show *

Subscribe to Matt’s newsletter “Vulnerable U”
https://mattjay.com/newsletter/

Follow Matt on Twitter
https://twitter.com/mattjay

Follow Matt on LinkedIn
https://www.linkedin.com/in/matthewjohansen/

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Live at RSA: AI Hype, Enhanced Security, and the Future of Cybersecurity Tools appeared first on Shared Security Podcast.

View Details

In episode 328, Tom and Kevin discuss two major cybersecurity and privacy news stories. The first topic covers the FCC issuing fines to major US wireless carriers for sharing users’ real-time location data, totaling nearly $200 million. They express surprise and skepticism over the carriers’ actions and deliberate on whether the fines would be impactful or merely seen as the cost of doing business. The second topic revolves around Google’s announcement that it prevented 2.28 million malicious apps from reaching the Play Store in 2023, marking a significant effort towards enhancing platform security. The discussion includes insights on the effectiveness of Google’s policies, the potential need for more transparency, and the broader implications of policy enforcement in the tech industry.

* Links mentioned on the show *

FCC fines carriers $200 million for illegally sharing user location
https://www.bleepingcomputer.com/news/technology/fcc-fines-carriers-200-million-for-illegally-sharing-user-location/

Google Prevented 2.28 Million Malicious Apps from Reaching Play Store in 2023
https://thehackernews.com/2024/04/google-prevented-228-million-malicious.html

* Watch this episode on YouTube *

https://youtu.be/1Cw-2vQX6EA

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post FCC Fines Wireless Carriers $200 million, Google’s Fight Against Malicious Apps appeared first on Shared Security Podcast.

View Details

In episode 327 Tom, Scott, and Kevin discuss the findings from Mandiant’s M-Trends 2024 report, highlighting a significant rise in traditional vulnerability exploitation by attackers while observing a decline in phishing. Despite phishing’s decreased prevalence, it remains the second most popular method for gaining initial network access. Discussions include the impact of high-profile vulnerabilities and the potential reasons behind the shift in cyberattack tactics. The episode also explores the challenges of maintaining online privacy within relationships, especially when one partner prioritizes privacy more than the other. Tips on fostering understanding and cooperation on privacy and security practices within a relationship are also covered.

* Links mentioned on the show

Vulnerability Exploitation on the Rise as Attackers Ditch Phishing
https://www.infosecurity-magazine.com/news/vulnerability-exploitation-rise/

Are you privacy-oriented in a relationship with a partner who isn’t?
https://www.reddit.com/r/privacy/comments/1carxda/are_you_privacyoriented_in_a_relationship_with_a/

* Watch this episode on YouTube *

https://youtu.be/CTE3q4ZFrps

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Privacy Challenges in Relationships, Phishing Down but Vulnerabilities Up? appeared first on Shared Security Podcast.

View Details

In episode 327 Tom, Scott, and Kevin discuss the findings from Mandiant's M-Trends 2024 report, highlighting a significant rise in traditional vulnerability exploitation by attackers while observing a decline in phishing. Despite phishing's decreased prevalence, it remains the second most popular method for gaining initial network access. Discussions include the impact of high-profile vulnerabilities and the potential reasons behind the shift in cyberattack tactics. The episode also explores the challenges of maintaining online privacy within relationships, especially when one partner prioritizes privacy more than the other. Tips on fostering understanding and cooperation on privacy and security practices within a relationship are also covered.

Show notes: https://sharedsecurity.net/2024/04/29/privacy-challenges-in-relationships-phishing-down-but-vulnerabilities-up/

View Details

In this episode Erin Gallagher, cybersecurity awareness lead at Fastly, discusses her journey into the field of security awareness and her unique approach to enhancing cybersecurity within tech companies. Erin shares her unconventional path from a communication major to leading security awareness programs at IBM and a large insurance company, before joining Fastly. She highlights the challenges and strategies of tailoring security training to diverse roles within tech companies, emphasizing the importance of role-based training over traditional methods like phishing simulations. Erin also tackles the critical role of communication skills in security awareness, the need for empathetic engagement with employees, and the importance of demonstrating the value of security awareness programs, especially in uncertain economic times. The episode also touches on Erin’s success in engaging with all levels of staff, including executives, and her thoughts on the future of security awareness in the tech industry.

* Links mentioned on the show

Follow Erin on LinkedIn
https://www.linkedin.com/in/erin-gallagher-368063135/

Tom and Erin on Scott’s recent Cybersecurity Awareness Forum

* Watch this episode on YouTube *

https://youtu.be/8pmC98EFF08

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Navigating Security Awareness in the Tech Industry with Erin Gallagher appeared first on Shared Security Podcast.

View Details

In episode 325, Tom and Kevin discuss a significant backdoor threat that nearly compromised Linux systems globally, stemming from an infiltration into an open-source project called XZ Utils by attackers who gained commit access and inserted a backdoor. The episode further delves into a cybersecurity incident where hackers stole 340,000 social security numbers from a government consulting firm, emphasizing the implications and broader concerns related to data security in government contractors and the inefficacy of response mechanisms. Additionally, the hosts explore the negative influences of marketing in the cybersecurity industry, particularly following significant security breaches.

* Links mentioned on the show

This backdoor almost infected Linux everywhere: The XZ Utils close call
https://www.zdnet.com/article/this-backdoor-almost-infected-linux-everywhere-the-xz-utils-close-call/

Hackers stole 340,000 Social Security numbers from government consulting firm
https://techcrunch.com/2024/04/08/hackers-stole-340000-social-security-numbers-from-government-consulting-firm/

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Linux Backdoor Infection Scare, Massive Social Security Number Heist appeared first on Shared Security Podcast.

View Details

Episode 324 features discussions on a significant AT&T data breach affecting 73 million customers and a sophisticated thread jacking attack targeting a journalist. Co-host Scott Wright joins the discussion, highlighting how millions of AT&T customer account passcodes, along with personal information, were compromised due to a leak discovered by a security researcher and reported by TechCrunch. The episode also details the thread jacking phishing attack, emphasizing the importance of recognizing unexpected email threads and the potential dangers of malicious attachments. The episode concludes with a brief discussion on the upcoming solar eclipse, stressing the importance of using ISO-certified glasses for viewing.

* Links mentioned on the show

AT&T confirms data for 73 million customers leaked on hacker forum
https://techcrunch.com/2024/03/30/att-reset-account-passcodes-customer-data/
https://www.bleepingcomputer.com/news/security/atandt-confirms-data-for-73-million-customers-leaked-on-hacker-forum/

Thread Hijacking: Phishes That Prey on Your Curiosity
https://krebsonsecurity.com/2024/03/thread-hijacking-phishes-that-prey-on-your-curiosity/

What value do Red Team exercises provide to security awareness programs?

* Watch this episode on YouTube *

https://youtu.be/NYFxs-sueEg

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Massive AT&T Data Leak, The Danger of Thread Hijacking appeared first on Shared Security Podcast.

View Details

In episode 323, the hosts discuss two prominent topics. The first segment discusses a significant vulnerability discovered in hotel locks, branded as ‘Unsaflok,’ affecting 3 million doors across 131 countries. The vulnerability allows attackers to create master keys from a regular key, granted access to all doors in a hotel. The co-hosts also discuss the vulnerability’s relation to legacy systems and the implications for hotel security. The second segment shifts focus to Glassdoor, revealing that the popular company review site can no longer guarantee anonymity due to changes following its acquisition of Fishbowl, raising concerns about privacy and the potential misuse of personal data. Additionally, the hosts cover the importance of maintaining security in physical and information security systems and the challenges businesses face when upgrading these systems.

* Links mentioned on the show

Unsaflok flaw can let hackers unlock millions of hotel doors
https://www.bleepingcomputer.com/news/security/unsaflok-flaw-can-let-hackers-unlock-millions-of-hotel-doors/

Glassdoor Wants to Know Your Real Name
https://www.wired.com/story/glassdoor-wants-to-know-your-real-name/

* Watch this episode on YouTube *

https://youtu.be/cPiCt9V0onM

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post New Hotel Lock Vulnerabilities, Glassdoor Anonymity Issues appeared first on Shared Security Podcast.

View Details

In this episode, special guest Alyssa Miller joins the hosts for an insightful and entertaining conversation covering a broad range of topics from social engineering anecdotes involving Kevin Johnson to Alyssa’s journey in aviation and being a pilot. They discuss the challenges within the cybersecurity industry, including the transition to cloud computing and the neglect of on-prem data centers. Alyssa also shares a personal story about encountering workplace discrimination, offering advice based on her experiences. Additionally, the discussion touches on upcoming conference talks Alyssa is giving, which link her passion for aviation with lessons for the cybersecurity field. The episode touches on critical InfoSec challenges for 2024, humorously dismissing the hype around generative AI and quantum computing as the main issues.

* Links mentioned on the show

Follow and Connect with Alyssa Miller
https://www.youtube.com/@AlyssaM_InfoSec
https://twitter.com/AlyssaM_InfoSec/
https://www.linkedin.com/in/alyssam-infosec/

* Watch this episode on YouTube *

https://youtu.be/aaLnXzfVkl4

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Alyssa Miller: Charting the Course Through InfoSec and Aviation appeared first on Shared Security Podcast.

View Details

In episode 321, the hosts discuss how connected cars are sharing driving data with insurance companies, potentially leading to increased rates for drivers. They also talk about the anti-TikTok bill passed by the House, which could force ByteDance to sell TikTok or face a ban in app stores. The episode also covers a significant update to Signal, allowing users to use usernames instead of phone numbers, enhancing privacy. Insights into privacy policies, the importance of understanding consent, and the broader implications of data collection and sharing among different entities are also discussed.

* Links mentioned on the show

Driving fast or braking hard? Your connected car may be telling your insurance company
https://www.zdnet.com/article/driving-fast-or-braking-hard-your-connected-car-may-be-telling-your-insurance-company/

Check out Vehicle Privacy Report to see what data your car collects!
https://vehicleprivacyreport.com/

Why Signal ‘turned our architecture inside out’ for its latest privacy feature
https://news.yahoo.com/why-signal-turned-architecture-inside-202555708.html
https://ssd.eff.org/module/how-to-use-signal

* Watch this episode on YouTube *

https://youtu.be/bJJ42u69g0M

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The TikTok Ban Bill, Your Car is Spying on You, Signal’s Username Update appeared first on Shared Security Podcast.

View Details

In episode 320, Tom and Scott discuss the contentious issue of who is accountable when Facebook or Instagram accounts are hacked, discussing potential failings on both the user’s and Meta’s part. They explore the possibility of inadequate security measures on these platforms and the implications of Meta potentially profiting from fraudulent ads. The episode also covers a Wired article regarding 41 state attorney generals in the U.S. urging Meta to enhance their security to manage the rising complaints of account theft. Furthermore, the ‘Aware Much’ segment highlights a new threat involving spoofed Zoom, Google, and Skype meeting requests that spread remote access Trojans (RATs), discussing the sophistication of these phishing attacks and malware’s ability to compromise systems. The conversation touches on the effectiveness of two-factor authentication (2FA), the challenge of identifying malicious URLs, and the role of government in pressuring companies like Meta to improve security practices.

* Links mentioned on the show

Meta Abandons Hacking Victims, Draining Law Enforcement Resources, Officials Say
https://www.wired.com/story/meta-hacked-users-draining-resources/

Spoofed Zoom, Google & Skype Meetings Spread Corporate RATs
https://www.darkreading.com/cyberattacks-data-breaches/spoofed-zoom-google-skype-meetings-spread-corporate-rats

* Watch this episode on YouTube *

https://youtu.be/x3x8uiSH2zs

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Who’s to Blame for Hacked Social Media Accounts, Spoofed Online Meeting Requests and Malware appeared first on Shared Security Podcast.

View Details

In Episode 319, Tom and Kevin discuss the potential data privacy risks associated with having an AI ‘girlfriend’ or ‘boyfriend’ and why one should refrain from sharing their personal data with such AIs. They engage in a humorous conversation about the unusual advertisements these AI companions attract, while expressing concerns over their deceptive and sensitive data gathering. The episode also explores the controversial issue of the U.S. government collecting vast amounts of consumer data. Allegedly, the government acquires data from various sources including cell phones, social media, and internet ad exchanges, potentially for surveillance purposes. Tom and Kevin argue that such practice is an abuse of the system, potentially bypassing laws meant to protect the innocent, and opens up a possibility for misuse by government employees.

* Links mentioned on the show

‘AI Girlfriends’ Are a Privacy Nightmare
https://www.wired.com/story/ai-girlfriends-privacy-nightmare/

The Government Really Is Spying On You — And It’s Legal
https://www.politico.com/news/magazine/2024/02/28/government-buying-your-data-00143742

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Don’t Trust Your AI Girlfriend or Boyfriend, Exposing US Government Data Collection appeared first on Shared Security Podcast.

View Details

In episode 318, we discuss the trending ‘get to know me’ posts on social media platforms like Instagram and the potential risks of sharing personal information publicly, particularly in light of potential misuse for password resetting. We recount a similar trend observed years ago when social media was in its infancy. The second topic covers Ring’s decision to discontinue its ‘Request for assistance’ feature on its Neighbors app which initially allowed police to publicly request doorbell footage without a warrant. We explore various viewpoints on this topic, including the need for warrants, privacy concerns, and the potential misuse of information, while also highlighting different methods of ensuring online security.

* Links mentioned on the show

The latest ‘Get to Know Me’ trend on Instagram might seem like harmless fun, but think twice.
https://www.linkedin.com/posts/flaviusplesu_the-latest-get-to-know-me-trend-on-instagram-activity-7155491475215040512-Sugs/

Ring steps back from sharing video with police — mostly
https://www.theverge.com/2024/1/24/24049165/ring-police-neighbors-app-clips-search-warrant

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post ‘Get to Know Me’ Privacy Risks, Pros and Cons of Publicly Sharing Ring Doorbell Footage appeared first on Shared Security Podcast.

View Details

In episode 317, Tom and Kevin discuss a reported deepfake scam that allegedly led to the theft of 25.6 million from a multinational company and Canada’s attempt to ban the Flipper Zero device, believing it plays a role in auto thefts. They critique the Canadian government’s understanding of the device and its capabilities, questioning whether the move is political posturing rather than a measure to enhance public safety. The hosts also speak about the ‘human password’ concept, which prompts a broader discussion about the importance of out-of-band confirmation for financial transactions.

* Links mentioned on the show

Scammers use deepfakes to steal $25.6 million from a multinational firm
https://www.engadget.com/scammers-use-deepfakes-to-steal-256-million-from-a-multinational-firm-034033977.html

Canada Moves to Ban the Flipper Zero Over Car Hacking Fears
https://gizmodo.com/canada-moves-to-ban-the-flipper-zero-over-car-hacking-f-1851242790
https://arstechnica.com/security/2024/02/canada-vows-to-ban-flipper-zero-device-in-crackdown-on-car-theft/

* Watch this episode on YouTube *

* Become a Shared Security Supporter *

Get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Support the show for as little as $3! Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on X: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post 25.6 Million Dollar Deepfake Scam, Exploring Canada’s Flipper Zero Ban appeared first on Shared Security Podcast.

View Details

In episode 316, we have the pleasure to chat with Jason Haddix, a prominent influencer in the cybersecurity community. With an intriguing career path, from being a ‘computer kid’, venturing into the nascent dark web, to becoming a respected figure in the Bug Bounty space, his journey is nothing short of inspiration. We dive into […]

The post Jason Haddix on Bug Bounties and Cybersecurity Career Growth appeared first on Shared Security Podcast.

View Details

In this episode of the Shared Security Podcast, we discuss the concerning issue of victim-blaming in cybersecurity with special guest, Andra Zaharia, host of the Cyber Empathy and We Think We Know podcasts. Key topics include the societal issues within cybersecurity, the role of empathy in business and cybersecurity, leadership’s role in empathy and the […]

The post The Problem of Victim Blaming in Cybersecurity: Empathy, Responsibility & Ethical Practices appeared first on Shared Security Podcast.

View Details

In this episode, host Tom Eston provides a detailed explanation of the ‘Stolen Device Protection’ for iPhones – a new security feature by Apple. This feature triggers enhanced security factors such as Face ID, Touch ID, and an hour-long security delay for critical actions when the phone is away from familiar locations. Tom also provides […]

The post Secure Your iPhone: Exploring Stolen Device Protection appeared first on Shared Security Podcast.

View Details

In Episode 313, hosts Tom and Scott discuss the world of scambaiting, discussing what it is, the tactics used, and its effectiveness in stopping scammers. They talk about popular channels like Scammer Payback and Kitboga that show these scams in progress. Then they switch to the best practices to prevent social media account takeovers, highlighting […]

The post The World of Scambaiting, Preventing Social Media Account Takeovers, Network Wrenches Hacked appeared first on Shared Security Podcast.

View Details

In episode 312, Tom and Scott discuss the implications of a new law in Ohio that may require parental consent for children under 16 using social media, including the pros and cons of this legislation. They also discuss Meta’s new link history feature and the repercussions it might have on ad targeting on Facebook and […]

The post Ohio’s New Social Media Law, Meta’s Link History Feature, 175 Million Passcode Guesses appeared first on Shared Security Podcast.

View Details

In this episode, we discuss the most sophisticated iPhone exploit ever, Google’s agreement to settle a $5 billion lawsuit about tracking users in ‘incognito’ mode, and a new iOS app, Journal. The iPhone exploit, known as Operation Triangulation, has complex chains of events that lead to compromised iPhone security. Meanwhile, the lawsuit against Google claims […]

The post Most Advanced iPhone Exploit Ever, Google’s $5 Billion Settlement, Apple’s Journal App appeared first on Shared Security Podcast.

View Details

In this episode, host Tom Eston shares the three key lessons he’s learned over his 18-year career in cybersecurity: effective communication, continuous learning, and empathy. He talks about the importance of understanding and reaching both technical and non-technical audiences, the necessity of continuous learning despite your role, and the power of empathy in contributing to […]

The post The Three Keys to Success in Cybersecurity appeared first on Shared Security Podcast.

View Details

In our last episode of the year, we replay our predictions for 2023 reviewing what we got right and what we didn’t. We cover various topics, such as Twitter’s influence, the future of Mastodon, the ban of TikTok in certain states, and the rising issue of ransomware. In addition, we give credit to Scott for […]

The post The Year in Review and 2024 Predictions appeared first on Shared Security Podcast.

View Details

In episode 308, we discuss the often overlooked topic of password management for the elderly. Addressing the commonly held belief that writing down passwords is a bad idea, we discuss the nuances and context of this practice. Elderly individuals who may struggle with technology can benefit from recording passwords, but we discuss the importance of […]

The post Password Security for the Elderly: Tips and Best Practices appeared first on Shared Security Podcast.

View Details

In episode 307, Tom and Scott debunk misinformation circulating about the iOS 17 NameDrop feature by law enforcement and others on social media. Next, they discuss the potential risks of QR code scams, detailing a real-life incident where a woman lost a significant amount of money due to a QR code scam. Finally, the episode […]

The post iOS 17 NameDrop Debunking, Real World QR Code Attacks, Impact of Ransomware on Hospitals appeared first on Shared Security Podcast.

View Details

In this episode, noteworthy guest Tanya Janca returns to discuss her recent ventures and her vision for the future of Application Security. She reflects on the significant changes she has observed since her career at Microsoft, before discussing her new role at Semgrep that recently acquired WeHackPurple. Tanya sheds light on her decision to partner […]

The post Application Security Trends & Challenges with Tanya Janca appeared first on Shared Security Podcast.

View Details

In this episode, Tom shows off AI generated images of a “Lonely and Sad Security Awareness Manager in a Dog Pound” and the humorous outcomes. The conversation shifts to Apple’s upcoming support for Rich Communication Services (RCS) and the potential security implications. Lastly, Tom and Kevin reflect on reports of AI-powered voice cloning scams targeting […]

The post Apple Finally Adopts RCS, AI Powered Scams Targeting the Elderly appeared first on Shared Security Podcast.

View Details

In this week’s episode of the Shared Security Podcast, hosts Tom Eston, Scott Wright and Kevin Johnson tackle a number of topics related to AI, privacy and security. They begin with an amusing discussion about their respective roles on the podcast, before shifting to big tech’s use of user data and whether subscribers should pay […]

The post Paying Big Tech for Privacy, New Privacy Policy Study, Biden’s Executive Order on AI appeared first on Shared Security Podcast.

View Details

In this episode, we discuss the SEC’s charges against SolarWinds’ CISO for misleading investors about a major cyberattack. Plus don’t miss our discussion about the shady world of “Classiscam Scam-as-a-Service,” a very popular cyber criminal service that creates fake user accounts, posts fraudulent reviews, and boosts the reputation of dishonest sellers while defrauding e-commerce platforms. […]

The post SEC vs. SolarWinds CISO, Classiscam Scam-as-a-Service appeared first on Shared Security Podcast.

View Details

In this episode, we explore the recent Okta breach where hackers obtained sensitive customer data via unauthorized access to the Okta support system. Next, we discuss the emerging threat of “quishing,” a combination of voice calls and phishing that preys on unsuspecting victims. Finally, we discuss Google Play Protect’s new feature, “Real-time App Analysis,” which […]

The post Okta Hacked Again, Quishing Is The New Phishing, Google Play Protect Real-Time Scanning appeared first on Shared Security Podcast.

View Details

Did you know that your mobile phone provider can give data like phone numbers you’ve called and received, the time and date of those calls, and even your location data to their parent companies, affiliates, and agents? In this episode we show you how to opt out so you can stop your data from being […]

The post How to Opt Out of CPNI Data Sharing appeared first on Shared Security Podcast.

View Details

In milestone episode 300, Jayson E. Street (a renowned hacker, helper, and human who has successfully robbed banks, hotels, government facilities, and Biochemical companies on five continents) joins us to share what he’s been up to recently and to talk about his new role at Secure Yeti. Next, we explore the alarming rise of ‘phantom […]

The post Special Guest Jayson E. Street, Phantom Hacker Scams, 23andMe User Data For Sale appeared first on Shared Security Podcast.

View Details

In this episode we explore the remarkable journey of Tib3rius, a web application hacking expert and content creator. In this engaging conversation, we discuss: Tib3rius’ passion for community education and content creation. What fuels his desire to empower the next generation of cybersecurity professionals? His expertise and enthusiasm for web application hacking, and we explore […]

The post Educating the Next Cybersecurity Generation with Tib3rius appeared first on Shared Security Podcast.

View Details

In this episode, we discuss the Mozilla Foundation’s alarming report that reveals why cars are the top privacy concern. Modern vehicles, equipped with data-collecting tech, pose significant risks to consumers’ privacy, with data sharing even extending to law enforcement. Listen in to our discussion as we explore the urgent need for transparency and gasp regulations […]

The post Your Car is a Privacy Nightmare, Password Creation Best Practices, Sony Hacked Again appeared first on Shared Security Podcast.

View Details

In this episode, we explore the growing trend of AI surveillance in corporations, where cutting-edge technology is used to monitor employees, optimize productivity, and raise ethical concerns. Next, we uncover a disturbing Instagram scam that lures unsuspecting victims into a trap, highlighting the deceptive tactics employed by cyber criminals on social media. Finally, discover the […]

The post Is My Boss Spying on Me, Instagram Painting Scam, Kia and Hyundai TikTok Challenge appeared first on Shared Security Podcast.

View Details

In this episode Matt Johansen, Security Architect at Reddit and Vulnerable U newsletter and YouTube content creator, joins host Tom Eston to discuss Matt’s background as one of the original “Security Twits”, his career journey, his passion for mental health advocacy, the significance of the recent MGM ransomware attack, and a discussion on the pros […]

The post Content Creation, Mental Health in Cyber, The MGM Ransomware Attack appeared first on Shared Security Podcast.

View Details

In this episode Ryan Davis, Chief Information Security Officer at NS1, speaks with host Tom Eston about the changing role of the CISO, acquisitions, what the biggest challenges are, and Ryan’s advice for those considering a career as a CISO. This is one episode you don’t want to miss if you’re curious what a CISO […]

The post The Changing Role of the CISO with Ryan Davis, Chief Information Security Officer at NS1 appeared first on Shared Security Podcast.

View Details

In this episode we discuss the FBI’s remarkable takedown of the Qakbot botnet, a saga involving ransomware, cryptocurrency, and the FBI pushing an uninstaller to thousands of victim PCs. Next, we explore how a major U.S. energy organization fell victim to a QR code phishing attack, highlighting the ever-evolving tactics used by attackers. Finally, we […]

The post The FBI’s Qakbot Takedown, QR Code Phishing Attacks, Dox Anyone in America for $15 appeared first on Shared Security Podcast.

View Details

In this episode we discuss the FBI's remarkable takedown of the Qakbot botnet, a saga involving ransomware, cryptocurrency, and the FBI pushing an uninstaller to thousands of victim PCs. Next, we explore how a major U.S. energy organization fell victim to a QR code phishing attack, highlighting the ever-evolving tactics used by attackers. Finally, we discuss the alarming world of personal data exploitation through credit header information and a TransUnion subsidiary, where attackers can dox anyone in America for only $15.

Show notes: https://sharedsecurity.net/2023/09/11/the-fbis-qakbot-takedown-qr-code-phishing-attacks-dox-anyone-in-america-for-15/

View Details

In this episode Luke Jennings VP of Research & Development from Push Security joins us to discuss SaaS attacks and how its possible to compromise an organization without touching a single endpoint or network. Luke talks about his recent SaaS attack research, why SaaS based attacks are different than traditional network based attacks, the SaaS attack matrix which can be used by both red and blue teams, and why its important that this research is shared and talked about in the cybersecurity community.

* Links mentioned on the show

Let’s talk about SaaS attack techniques
https://pushsecurity.com/blog/saas-attack-techniques/

SAMLjacking a poisoned tenant
https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/

Push Security SaaS Attacks GitHub
https://github.com/pushsecurity/saas-attacks

Follow Luke and Push Security
https://www.linkedin.com/in/luke-jennings-042b5619b/
https://twitter.com/jukelennings
https://twitter.com/PushSecurity
https://pushsecurity.com/

* Watch this episode on YouTube *

https://youtu.be/Rj0t5Lw12Ic

* Become a Shared Security Supporter *

For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post SaaS Attacks: Compromising an Organization without Touching the Network appeared first on Shared Security Podcast.

View Details

In this episode Luke Jennings VP of Research & Development from Push Security joins us to discuss SaaS attacks and how its possible to compromise an organization without touching a single endpoint or network. Luke talks about his recent SaaS attack research, why SaaS based attacks are different than traditional network based attacks, the SaaS attack matrix which can be used by both red and blue teams, and why its important that this research is shared and talked about in the cybersecurity community. 

Show notes: https://sharedsecurity.net/2023/09/04/saas-attacks-compromising-an-organization-without-touching-the-network/

View Details

In this episode, we discuss essential cybersecurity tips for students and educational institutions as they gear up for the school season. From software updates to strong passwords and cybersecurity education, we explore how students and schools can fortify their digital defenses. Next, we navigate the treacherous waters of phishing and related scams, unveiling strategies to […]

The post Back to School Cybersecurity, Phishing Pitfalls and Strategies, X’s (Twitter) Blocking Overhaul appeared first on Shared Security Podcast.

View Details

In this episode, we discuss essential cybersecurity tips for students and educational institutions as they gear up for the school season. From software updates to strong passwords and cybersecurity education, we explore how students and schools can fortify their digital defenses.

Next, we navigate the treacherous waters of phishing and related scams, unveiling strategies to outwit malicious links. Hovering over links, cautious email scrutiny, and verification tactics all play a role.

Finally, we discuss the surprising policy change by X (formerly Twitter), where blocking faces a major overhaul. Tune in as we discuss the privacy and safety ramifications of this change.

Show notes: https://sharedsecurity.net/2023/08/28/back-to-school-cybersecurity-phishing-pitfalls-and-strategies-xs-twitter-blocking-overhaul/

View Details

In this best of episode from December 2021, we revisit Business Email Compromise (BEC) scams. What are they, how to identify them, and why BEC scams have resulted in well over $3 billion in losses since 2016, more than any other type of fraud in the U.S. We also share our tips on how to […]

The post Business Email Compromise Scams Revisited appeared first on Shared Security Podcast.

View Details

In this episode, host Tom Eston speaks with Andy Yen, founder and CEO of Proton, to discuss the current and future state of email security. We also discuss Andy’s unique background as a scientist, the importance of using email aliases, an overview of Proton’s new password manager (Proton Pass), how AI may impact email security […]

The post The Current and Future State of Email Security with Andy Yen, CEO of Proton appeared first on Shared Security Podcast.

View Details

In this episode, host Tom Eston speaks with Andy Yen, founder and CEO of Proton, to discuss the current and future state of email security. 

We also discuss Andy's unique background as a scientist, the importance of using email aliases, an overview of Proton's new password manager (Proton Pass), how AI may impact email security in the future, and how to find out more about how Proton takes a different approach to email security.

Show notes: https://sharedsecurity.net/2023/08/14/the-current-future-state-of-email-security-with-andy-yen-ceo-of-proton/

View Details

In this episode, we discuss our common sense tips to stay safe and secure while attending “Hacker Summer Camp”: BSides, Black Hat, and DEF CON hacking conferences in Las Vegas. Next, we discuss the vulnerabilities and potential adversarial attacks on large language models like ChatGPT and other AI chat bots. Finally, we discuss the Flipper […]

The post Common Sense Advice for Hacker Summer Camp, AI Chatbot Attacks, What’s a Flipper Zero? appeared first on Shared Security Podcast.

View Details

In this episode, we discuss our common sense tips to stay safe and secure while attending "Hacker Summer Camp": BSides, Black Hat, and DEF CON hacking conferences in Las Vegas. 

Next, we discuss the vulnerabilities and potential adversarial attacks on large language models like ChatGPT and other AI chat bots.

Finally, we discuss the Flipper Zero, a versatile hacking device. We discuss its features, the potential use to cause havoc with TVs, garage doors, other wireless devices, and its role in penetration testing.

Show notes: https://sharedsecurity.net/2023/08/07/common-sense-advice-for-hacker-summer-camp-ai-chatbot-attacks-whats-a-flipper-zero/

View Details

In this episode, we explore the implications and ethical dilemmas of immortality in the digital world. Listen to our discussion about this cutting-edge technology and its potential impact on our privacy. Next, we discuss the growing trend of Apple and Google becoming custodians of our digital lives. Have these tech companies gone too far? Join […]

The post Your Digital Immortality is Coming, Apple and Google Are Data Gatekeepers, Satellite Security Risks Revealed appeared first on Shared Security Podcast.

View Details

In this episode, we explore the implications and ethical dilemmas of immortality in the digital world. Listen to our discussion about this cutting-edge technology and its potential impact on our privacy.

Next, we discuss the growing trend of Apple and Google becoming custodians of our digital lives. Have these tech companies gone too far? Join the conversation as we discuss the trends and challenges of digital sovereignty.

Lastly, satellites form the backbone of our interconnected world, but they might be more vulnerable than we realize. We discuss recent research that uncovers basic security flaws that pose potential risks to our communication systems.

Show notes: https://sharedsecurity.net/2023/07/31/your-digital-immortality-is-coming-apple-and-google-are-data-gatekeepers-satellite-security-risks-revealed/

View Details

In this episode, we discuss the recent Microsoft security breach where China-backed hackers gained access to numerous email inboxes, including those of several federal government agencies, using a stolen Microsoft signing key to forge authentication tokens. A TikTok influencer used a voice cloning app to expose a cheating boyfriend. But wait, there’s more to this […]

The post Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program appeared first on Shared Security Podcast.

View Details

In this episode, we discuss the recent Microsoft security breach where China-backed hackers gained access to numerous email inboxes, including those of several federal government agencies, using a stolen Microsoft signing key to forge authentication tokens. 

A TikTok influencer used a voice cloning app to expose a cheating boyfriend. But wait, there's more to this story than meets the eye! We discuss the serious implications of voice cloning and how its being used for new types of phone scams.

Lastly, we discuss the recent announcement by the Biden-Harris administration about their new cybersecurity labeling program for smart devices. Will this program help or hinder the security of smart devices?

Show notes: https://sharedsecurity.net/2023/07/24/microsoft-lost-its-keys-voice-cloning-scams-the-biden-harris-cybersecurity-labeling-program/

View Details

In this episode we discuss how Massachusetts lawmakers are pushing a groundbreaking bill to ban the buying and selling of location data from mobile devices. This legislation raises vital questions about consumer privacy, digital stalking, and national security threats. Next, we discuss the pros and cons of prohibiting external password managers within organizations. Join the […]

The post First Ban on Selling Location Data, Prohibiting Password Managers, Real-Time Crime Center Concerns appeared first on Shared Security Podcast.

View Details

In this episode we discuss how Massachusetts lawmakers are pushing a groundbreaking bill to ban the buying and selling of location data from mobile devices. This legislation raises vital questions about consumer privacy, digital stalking, and national security threats.

Next, we discuss the pros and cons of prohibiting external password managers within organizations. Join the conversation as we weigh the benefits, downsides, and best practices surrounding this hotly debated topic.

Finally, we discuss the rise of Real-Time Crime Centers (RTCCs) and the concerns they raise regarding mass surveillance, privacy rights, and data misuse.

Show notes: https://sharedsecurity.net/2023/07/17/first-ban-on-selling-location-data-prohibiting-password-managers-real-time-crime-center-concerns/

View Details

In this episode, we explore the rise of Threads, a new social media app developed by Meta, which has already attracted 10 million users in just seven hours. However, there’s a catch – the app collects extensive personal data, sparking concerns about privacy. Next, we dive into the world of airline reservation scams, exposing how […]

The post Meta’s Threads and Your Privacy, Airline Reservation Scams, IDOR Srikes Back appeared first on Shared Security Podcast.

View Details

In this episode, we explore the rise of Threads, a new social media app developed by Meta, which has already attracted 10 million users in just seven hours. However, there's a catch – the app collects extensive personal data, sparking concerns about privacy. 

Next, we dive into the world of airline reservation scams, exposing how fraudsters exploit a loophole to deceive unsuspecting travelers. Learn how to protect yourself and avoid being swindled by these ticket scams. 

Finally, we discuss the security vulnerability discovered in Eaton's smart security alarm systems, highlighting the significant risks of IDOR (Insecure Direct Object Reference) vulnerabilities and the potential for unauthorized access.

Show notes: https://sharedsecurity.net/2023/07/10/metas-threads-and-your-privacy-airline-reservation-scams-idor-srikes-back/

View Details

Several major organizations, including British Airways and the BBC, fell victim to the recent MOVEit cyberattack. We discuss the alarming trend of hackers targeting trusted suppliers to gain access to customer data, potentially holding companies and individuals for ransom. Is it better to change passwords regularly or focus on creating complex ones? We discuss the […]

The post MOVEit Cyberattack, The Problem with Password Rotations, Military Alert on Free Smartwatches appeared first on Shared Security Podcast.

View Details

Paul Asadoorian, OG security podcaster and host of the popular Paul’s Security Weekly podcast, joins us in this episode to talk about his career as one of the original security podcasters. Paul’s been podcasting for more than 17 years! Paul also shares with us some of his greatest hacking stories and don’t miss our lively […]

The post Security Podcasting, Hacking Stories, and The State of Firmware Security with Paul Asadoorian appeared first on Shared Security Podcast.

View Details

Paul Asadoorian, OG security podcaster and host of the popular Paul's Security Weekly podcast, joins us in this episode to talk about his career as one of the original security podcasters. Paul's been podcasting for more then 17 years! Paul also shares with us some of his greatest hacking stories and don't miss our lively discussion about the state of firmware security.

Show notes: https://sharedsecurity.net/2023/06/26/security-podcasting-hacking-stories-and-firmware-security-with-paul-asadoorian/

View Details

The FTC charged Ring, the Amazon-owned home security camera company, for compromising customer privacy and having inadequate security measures. Employees accessed private videos, while hackers exploited vulnerabilities and now Ring needs to reimburse customers $5.8 million dollars. The FTC complaint emphasizes that Ring’s actions disregarded privacy and security, putting consumers at risk. Google has removed […]

The post The FTC’s Complaint Against Ring, Detecting Malware Infected Apps, America’s Most Cybersecure Companies appeared first on Shared Security Podcast.

View Details

The FTC charged Ring, the Amazon-owned home security camera company, for compromising customer privacy and having inadequate security measures. Employees accessed private videos, while hackers exploited vulnerabilities and now Ring needs to reimburse customers $5.8 million dollars. The FTC complaint emphasizes that Ring's actions disregarded privacy and security, putting consumers at risk.

Google has removed the iRecorder - Screen Recorder app from the Play Store after it was discovered that it was infected with malware capable of stealing personal information. We discuss several ways to spot malicious apps on your smartphone helping you protect and safeguard your personal information.

Finally, we discuss Forbes' collaboration with SecurityScorecard to identify America's Most Cybersecure Companies, and the ethical dilemma that this presents to companies that may not have given their permission to be listed. We also discuss why these lists may make companies a target by hackers (anyone remember the "Hacker Safe" badges?).

Become an official supporter of the podcast!
For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Sign up and become a supporter today! https://sharedsecurity.net/patron

Show notes: https://sharedsecurity.net/2023/06/19/the-ftcs-complaint-against-ring-detecting-malware-infected-apps-americas-most-cybersecure-companies/

View Details

In this exciting episode of our podcast we have the pleasure of speaking with Phillip Wylie, a remarkable professional with a captivating career in cybersecurity. Join us as we discuss Phillip’s unique journey and uncover valuable insights on breaking into the cybersecurity field. From his origins as a professional wrestler who once bravely faced off […]

The post How to Break Into a Cybersecurity Career – Phillip Wylie appeared first on Shared Security Podcast.

View Details

In this exciting episode of our podcast we have the pleasure of speaking with Phillip Wylie, a remarkable professional with a captivating career in cybersecurity. Join us as we discuss Phillip's unique journey and uncover valuable insights on breaking into the cybersecurity field. From his origins as a professional wrestler who once bravely faced off against a bear, to his evolution into a respected penetration tester, author, trainer, mentor, and public speaker, Phillip's experiences are nothing short of extraordinary. Join us as Phillip shares his inspiring origin story and sheds light on the following topics:

  • Unveiling the Transformation: From Pro Wrestler to Penetration Tester
  • Bridging the Gap: Phillip's Evolution from Pentester to Author and Trainer
  • Navigating the Cybersecurity Landscape: Phillip's Advice for Aspiring Professionals
  • Are Cybersecurity Certifications Still Valuable?
  • How to Engage and Connect with Phillip

Join us for this episode as we discuss the remarkable career journey of Phillip Wylie!

Show notes: https://sharedsecurity.net/2023/06/12/how-to-break-into-a-cybersecurity-career-phillip-wylie/

View Details

Netflix plans to crack down on the widespread practice of password sharing among households. We discuss their new verification feature and its impact on user experience and security. A lawyer finds himself in hot water after relying on ChatGPT for legal research. We investigate the consequences of referencing non-existent legal cases, the lawyer’s claim of […]

The post Netflix Cracks Down on Password Sharing, AI Legal Research Gone Wrong, Fake Identities and Surveillance Firms appeared first on Shared Security Podcast.

View Details

Netflix plans to crack down on the widespread practice of password sharing among households. We discuss their new verification feature and its impact on user experience and security.

A lawyer finds himself in hot water after relying on ChatGPT for legal research. We investigate the consequences of referencing non-existent legal cases, the lawyer's claim of unawareness about the AI's potential for false information, and the broader concerns surrounding the risks of AI, including misinformation and bias.

Threat intelligence firms are using fake online personas to gather data on Discord, Reddit, WhatsApp, and other apps. Watchdog groups have raised concerns about the potential violation of civil liberties and lack of oversight of this activity.

Show notes: https://sharedsecurity.net/2023/06/05/netflix-cracks-down-on-password-sharing-ai-legal-research-gone-wrong-fake-identities-and-surveillance-firms/

View Details

In this episode, we discuss Meta’s record-breaking $1.3 billion fine by the EU for unlawfully transferring user data, shedding light on the increasing risks faced by tech companies in violating privacy rules.

Highly realistic images of a Pentagon explosion went viral on Twitter, causing a stock market dip. We discuss the risks associated with Twitter’s verification system and the issue of AI and deepfaked images.

Montana makes headlines as the first US state to ban TikTok. We discuss the ban’s motives, the challenges of implementation, and the broader concerns about personal data protection and online freedom.

* Links mentioned on the show

Meta Fined $1.3 Billion Over Data Transfers to U.S.
https://www.wsj.com/articles/meta-fined-1-3-billion-over-data-transfers-to-u-s-b53dbb04
https://twitter.com/wbm312/status/1660812083372654593

Pentagon explosion hoax goes viral after verified Twitter accounts push
https://www.bleepingcomputer.com/news/security/pentagon-explosion-hoax-goes-viral-after-verified-twitter-accounts-push/

Montana’s TikTok ban: why has it happened and will it work?
https://www.theguardian.com/technology/2023/may/18/montana-tiktok-ban-why-has-it-happened-will-it-work

* Watch this episode on YouTube *

https://youtu.be/7_w7r84TqFg

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Meta’s $1.3 Billion Fine, AI Hoax Hysteria, Montana’s TikTok Ban appeared first on Shared Security Podcast.

View Details

In this episode, we explore the arrival of passwordless Google accounts that use “passkeys,” which offer enhanced usability and security. We discuss the benefits of passkeys over traditional passwords, but also why passkeys are not quite ready for prime time use.

Next, we discuss Google Domains’ introduction of new top-level domains (TLDs) like .zip and .mov, raising concerns about the potential use for malicious activities. We separate fact from fiction, and discuss the real risks involved.

Lastly, we examine Twitter’s long-awaited encrypted direct messaging feature. We explore the limitations and criticisms surrounding its implementation, highlighting the importance of true end-to-end encryption solutions like Signal.

* Links mentioned on the show

Kevin Johnson on Security Weekly: Artificial Ignorance & Pen Testing
https://www.youtube.com/watch?v=_2Yq5VrEHf0

Google passkeys are a no-brainer. You’ve turned them on, right?
https://arstechnica.com/information-technology/2023/05/passwordless-google-accounts-are-easier-and-more-secure-than-passwords-heres-why/

Don’t panic. Google offering scary .zip and .mov domains is not the end of the world
https://www.theregister.com/2023/05/17/google_zip_mov_domains/
https://noperator.dev/posts/zip-snip/

Twitter’s Encrypted DMs Are Deeply Inferior to Signal and WhatsApp
https://www.wired.com/story/twitter-encrypted-dm-signal-whatsapp/

* Watch this episode on YouTube *

https://youtu.be/wLCzD6j13ys

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Google Now Supports Passkeys, Risky New Top Level Domains, Twitter’s Encryption Dilemma appeared first on Shared Security Podcast.

View Details

In this episode we discuss a recent Twitter security incident that caused private tweets sent to Twitter Circles to become visible to unintended recipients.

Next, we discuss the collaboration between Apple and Google to develop a specification for detecting and alerting users of unauthorized tracking using devices like AirTags.

Finally, we explore the US government’s engagement with major technology companies and AI experts to address the risks associated with generative artificial intelligence (AI). We analyze the White House initiatives and the call for increased regulatory measures in the AI field.

* Links mentioned on the show

Twitter says ‘security incident’ exposed private Circle tweets
https://www.bleepingcomputer.com/news/security/twitter-says-security-incident-exposed-private-circle-tweets/

Apple and Google Join Forces to Stop Unauthorized Location-Tracking Devices
https://thehackernews.com/2023/05/apple-and-google-join-forces-to-stop.html

White House unveils AI rules to address safety and privacy
https://www.computerworld.com/article/3695731/white-house-unveils-ai-rules-to-address-safety-and-privacy.html

* Watch this episode on YouTube *

https://youtu.be/WmBHVCJo6rg

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Private Tweets Exposed, Unauthorized Tracking Collaboration, AI Risks and Regulation appeared first on Shared Security Podcast.

View Details

In this episode we debunk the fearmongering surrounding “juice jacking,” a cyber attack where attackers steal data from devices that are charging via USB ports.

Next, we dive into a case where a photographer tried to get his photos removed from an AI dataset, only to receive an invoice instead of having his photos taken down.

Finally, we examine the security risks of using Google Authenticator’s cloud sync feature for two-factor authentication. We explain why this feature may not provide adequate protection and offer recommendations for more secure alternatives.

* Links mentioned on the show

Why is ‘Juice Jacking’ Suddenly Back in the News?
https://krebsonsecurity.com/2023/04/why-is-juice-jacking-suddenly-back-in-the-news/
https://arstechnica.com/information-technology/2023/05/fearmongering-over-public-charging-stations-needs-to-stop-heres-why/

A Photographer Tried to Get His Photos Removed from an AI Dataset. He Got an Invoice Instead.
https://www.vice.com/en/article/pkapb7/a-photographer-tried-to-get-his-photos-removed-from-an-ai-dataset-he-got-an-invoice-instead

Google Authenticator’s Cloud Sync Security Not Up to the Task
https://restoreprivacy.com/google-authenticators-cloud-sync-security-not-up-to-the-task/

* Watch this episode on YouTube *

https://youtu.be/MUZk4TUW0Z0

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Juice Jacking Debunked, Photographer vs. AI Dataset, Google Authenticator Risks appeared first on Shared Security Podcast.

View Details

In this episode we speak with Kai Roer, a renowned author, security culture coach, and CEO of Praxis Security Labs. Kai shares his career journey in cybersecurity and emphasizes the importance of building a strong security culture within organizations. He identifies the biggest impediments to a good security culture and offers actionable steps that organizations can take to improve their culture. Kai also discusses some of the biggest surprises he’s encountered in his work and provides insights for security awareness professionals and executives to learn about the most critical aspects of security culture. Finally, Kai shares his vision for the future of cybersecurity and his current projects.

* Links mentioned on the show

The Security Culture Playbook: An Executive Guide To Reducing Risk and Developing Your Human Defense Layer
https://www.amazon.com/Security-Culture-Playbook-Executive-Developing/dp/1119875234/

Connect with Kai
https://kairoer.com/
https://praxissecuritylabs.com/
https://twitter.com/kairoer
https://www.linkedin.com/in/kairoer/

* Watch this episode on YouTube *

https://youtu.be/iTc4FDNvMLk

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Building a Healthy Security Culture: Insights from Kai Roer appeared first on Shared Security Podcast.

View Details

Is Arkansas taking the right step to protect children online? A new law passed in the state makes it illegal for minors to use social media without their parent or guardian’s consent.

Over 60 Android apps on the Google Play Store with more than 100 million downloads have been infiltrated by the new “Tekya” malware. The malware can commit ad fraud and steal Facebook credentials.

Criminals are stealing keyless cars in under two minutes with a previously unknown method involving intercepting the signal between the car key and the car.

* Links mentioned on the show

Arkansas Makes It Illegal For Minors to Be on Social Media Without Parental Consent
https://www.vice.com/en/article/y3wdpv/arkansas-makes-it-illegal-for-minors-to-be-on-social-media-without-parental-consent

Android malware infiltrates 60 Google Play apps with 100M installs
https://www.bleepingcomputer.com/news/security/android-malware-infiltrates-60-google-play-apps-with-100m-installs/

There’s a new form of keyless car theft that works in under 2 minutes
https://arstechnica.com/information-technology/2023/04/crooks-are-stealing-cars-using-previously-unknown-keyless-can-injection-attacks/

* Watch this episode on YouTube *

https://youtu.be/GUsCHEY67O4

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Arkansas Social Media Consent Law, Android Malware Invasion, New Method of Keyless Car Theft appeared first on Shared Security Podcast.

View Details

Law enforcement agencies across 17 countries have cracked down on Genesis Market, one of the largest criminal marketplaces, resulting in the arrests of 120 people globally.

Popular family safety app, Life360, has been used by sex traffickers to monitor and control their victims, highlighting the increasing use of GPS technology by criminals.

A recent news report reveals that groups of Tesla employees shared highly invasive videos and images recorded by customers’ car cameras, including embarrassing and vulnerable situations. The leaked footage was shared via an internal messaging system, potentially compromising customer privacy.

* Links mentioned on the show

Genesis Market: Popular cybercrime website shut down by police
https://www.bbc.com/news/uk-65180488

Sex Traffickers Used America’s Favorite Family Safety App To Control Victims
https://www.forbes.com/sites/thomasbrewster/2023/04/06/sex-traffickers-use-parenting-apps-like-life360-to-spy-on-victims/?sh=3d2e55a864c3

Special Report: Tesla workers shared sensitive images recorded by customer cars
https://www.reuters.com/technology/tesla-workers-shared-sensitive-images-recorded-by-customer-cars-2023-04-06/

* Watch this episode on YouTube *

https://youtu.be/YvZx5OU93NI

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Genesis Market Crackdown, Life360 App Misuse, Tesla Customer Privacy Concerns appeared first on Shared Security Podcast.

View Details

Clearview AI provided police with 30 billion scraped images from Facebook, raising concerns over privacy and the potential misuse of facial recognition technology.

A victim of a phone hack shares their story of how their credit card was stolen, highlighting the vulnerability of personal information and the chain of events that happen when someone’s identity is stolen.

Our discussion about an open letter calling for the regulation of AI development due to potential dangers and misuse has become a source of controversy within the tech community. We also discuss an extreme proposal of using the threat of nuclear war to prevent the rise of artificial intelligence.

* Links mentioned on the show

Clearview AI scraped 30 billion images from Facebook and gave them to cops: it puts everyone into a ‘perpetual police line-up’
https://www.msn.com/en-us/news/technology/clearview-ai-scraped-30-billion-images-from-facebook-and-gave-them-to-cops-it-puts-everyone-into-a-perpetual-police-line-up/ar-AA19ocLq

A hacker ripped me off for $10,000. The scam turned out to be brilliant — and terrifying.
https://www.yahoo.com/news/someone-hacked-phone-stole-credit-100000528.html

The Open Letter to Stop ‘Dangerous’ AI Race Is a Huge Mess
https://www.vice.com/en/article/qjvppm/the-open-letter-to-stop-dangerous-ai-race-is-a-huge-mess

AI Theorist Says Nuclear War Preferable to Developing Advanced AI
https://www.vice.com/en/article/ak3dkj/ai-theorist-says-nuclear-war-preferable-to-developing-advanced-ai

* Watch this episode on YouTube *

https://youtu.be/OxBRws_99kg

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Clearview AI Facial Recognition Fallout, Hacked and Helpless, Is AI Armageddon Upon Us? appeared first on Shared Security Podcast.

View Details

The CEO of TikTok was criticized by Congress for his “worthless” assurances regarding the app’s privacy and security. But what is the real motivation for Congress attempting to ban TikTok?

Should we be concerned that AI language models like ChatGPT are a privacy nightmare? Not just for businesses but for anyone using it?

Researchers have found a way to use inaudible ultrasonic waves to attack smartphones, smart speakers, and other devices by taking control of their voice assistants, opening browser windows, and performing other malicious actions. Is this the next generation of attacks we need to be worried about?

* Links mentioned on the show

TikTok CEO fails to convince Congress that the app is not a “weapon” for China
https://arstechnica.com/tech-policy/2023/03/congress-calls-tiktok-ceos-security-and-privacy-assurances-worthless/

Senators Introduce Bipartisan Bill (RESTRICT Act) to Tackle National Security Threats from Foreign Tech
https://www.warner.senate.gov/public/index.cfm/2023/3/senators-introduce-bipartisan-bill-to-tackle-national-security-threats-from-foreign-tech

ChatGPT is a data privacy nightmare. If you’ve ever posted online, you ought to be concerned
https://theconversation.com/chatgpt-is-a-data-privacy-nightmare-if-youve-ever-posted-online-you-ought-to-be-concerned-199283

Inaudible ultrasound attack can stealthily control your phone, smart speaker
https://www.bleepingcomputer.com/news/security/inaudible-ultrasound-attack-can-stealthily-control-your-phone-smart-speaker/

* Watch this episode on YouTube *

https://youtu.be/HbaZgE90k-4

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the podcast *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The TikTok CEO Testimony, ChatGPT’s Privacy Risks, Inaudible Ultrasound Attacks appeared first on Shared Security Podcast.

View Details

In this episode we discuss Google’s discovery of 18 zero-day vulnerabilities in Samsung’s Exynos chipsets.

We examine an AI-assisted social engineering campaign that combines emerging technologies with classic techniques.

Finally, we look at a new method of ATM fraud where thieves use glue to disable card readers and trick customers into using the tap function on their debit cards.

* Links mentioned on the show

Google finds 18 zero-day vulnerabilities in Samsung Exynos chipsets
https://www.bleepingcomputer.com/news/security/google-finds-18-zero-day-vulnerabilities-in-samsung-exynos-chipsets/

Adversary Simulation with Voice Cloning in Real Time
https://tevora-threat.ghost.io/adversary-simulation-with-voice-cloning-in-real-time-part-1/amp/

ATM thieves use glue and ‘tap’ function to drain accounts at Chase Bank
https://abc7chicago.com/chase-bank-atm-scam-tap-to-pay/12913307/

* Watch this episode on YouTube *

https://youtu.be/ZIB709rmqv4

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Samsung Chipset Zero-Day Vulnerabilities, AI-Assisted Social Engineering, ATM Fraud with a Twist appeared first on The Shared Security Show.

View Details

On this episode, Tom Eston discusses empathy in cybersecurity with Andra Zaharia, host of the Cyber Empathy Podcast.

We talk about finding her passion for contributing to the industry and the importance of empathy in cybersecurity. We cover how empathy relates to cybersecurity in the industry, the importance of being empathetic in our roles as cybersecurity professionals, and why the phrase “users are the weakest link in security” is nothing more than victim blaming.

We also discuss the long term implications of new technology and how we can help educate people on how to build and use technology with kindness and how even impacting one person can make a difference.

* Links mentioned on the show

Andra’s Cyber Empathy Podcast
https://andrazaharia.com/cyber-empathy/

Andra’s How Do You Know Podcast
https://podcasts.apple.com/us/podcast/how-do-you-know-by-andra-zaharia/id1375405676

Andra’s blog
https://medium.com/@andra.zaharia

Connect with Andra
https://infosec.exchange/@andrazaharia
https://twitter.com/andrazaharia
https://www.linkedin.com/in/andrazaharia/

* Watch this episode on YouTube *

https://youtu.be/7O7E0rQnWEk

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Exploring the Role of Empathy in Cybersecurity with Andra Zaharia appeared first on The Shared Security Show.

View Details

What you need to know about Biden’s new National Cybersecurity Strategy, which aims to provide a framework of what the current administration wants the US federal government, critical infrastructure organizations, and private companies to do to work together to improve national cybersecurity.

BetterHelp, a direct-to-consumer mental health app, has been asked to pay $7.8m by the Federal Trade Commission (FTC) for allegedly passing on users’ mental health information to Facebook, Snapchat and others.

Fast food chain Chick-fil-A has confirmed a credential stuffing attack that allowed cybercriminals (who apparently really love chicken sandwiches) to access 71,473 customer accounts and sell access to them online.

* Links mentioned on the show

Biden’s Cybersecurity Strategy Assigns Responsibility to Tech Firms
https://www.nytimes.com/2023/03/02/us/politics/biden-cybersecurity-strategy.html
https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/

FTC: BetterHelp pushed users to share mental health info then gave it to Facebook
https://iapp.org/news/a/ftc-fines-online-counselor-7-8m-halts-sensitive-data-sharing/

Chick-fil-A confirms accounts hacked in months-long “automated” attack
https://www.bleepingcomputer.com/news/security/chick-fil-a-confirms-accounts-hacked-in-months-long-automated-attack/

* Watch this episode on YouTube *

https://youtu.be/8u0Ht_K_gVU

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Biden’s National Cybersecurity Strategy, BetterHelp’s FTC Fine, Chick-fil-A Data Breach appeared first on The Shared Security Show.

View Details

Popular password manager LastPass suffered a second attack that lasted for over two months. Now new and disturbing information is being released about the attack.

Scott discusses the benefits and challenges of using gamification in security awareness training, emphasizing the importance of individual learning before employing it at the business process level.

Signal, a very popular encrypted messaging app, warns it may leave the UK if new online safety legislation weakens its end-to-end encryption, sparking controversy and debate over privacy concerns.

* Links mentioned on the show

LastPass: DevOps engineer hacked to steal password vault data in 2022 breach
https://www.bleepingcomputer.com/news/security/lastpass-devops-engineer-hacked-to-steal-password-vault-data-in-2022-breach/

What is “Gamification” and why is it misunderstood in the industry?
https://www.linkedin.com/posts/scottwright_home-click-armor-activity-7033783390243848192-TOHu/

Signal app warns it will quit UK if law weakens end-to-end encryption
https://www.theguardian.com/technology/2023/feb/24/signal-app-warns-it-will-quit-uk-if-law-weakens-end-to-end-encryption

* Watch this episode on YouTube *

https://youtu.be/VTwslfC8W_E

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The LastPass Attack Gets Worse, What is Gamification, Signal’s Encryption Standoff appeared first on The Shared Security Show.

View Details

Popular password manager LastPass suffered a second attack that lasted for over two months. Now new and disturbing information is being released about the attack.

Scott discusses the benefits and challenges of using gamification in security awareness training, emphasizing the importance of individual learning before employing it at the business process level.

Signal, a very popular encrypted messaging app, warns it may leave the UK if new online safety legislation weakens its end-to-end encryption, sparking controversy and debate over privacy concerns.

Show notes: https://sharedsecurity.net/2023/03/06/the-lastpass-attack-gets-worse-what-is-gamification-signals-encryption-standoff/

View Details

Twitter is phasing out its free text message two-factor authentication (2FA) and putting the feature behind a paywall, prompting security experts to advise Twitter users to switch to other authentication methods.

How data brokers are selling sensitive mental health data for a few hundred dollars with little attempt to hide identifying information such as names and addresses. A new report highlights how some firms are offering the data for as low as $275 for information on 5,000 people, and Congress has yet to pass significant legislation on data brokers.

Meta (formerly Facebook) has launched a new program called Meta Verified which aims to unify verification across all of the company’s platforms. Users can pay a monthly fee to verify their presence on Facebook and Instagram by submitting their government ID.

* Links mentioned on the show

Could Twitter shutting off SMS 2FA be a great opportunity for the security industry or is this just the start of more ‘security tax’​ on the horizon?
https://www.linkedin.com/pulse/could-twitter-shutting-off-sms-2fa-great-opportunity-security-potter
https://infosec.exchange/@maxeddy/109883795151142780
https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter

A researcher tried to buy mental health data. It was surprisingly easy.
https://www.nbcnews.com/news/amp/rcna70071

Meta Verified will offer ID protection on Facebook, Instagram, WhatsApp for $12 (or more) per month
https://www.androidpolice.com/meta-verified-announcement/

Scott’s blog about Gamification
https://www.linkedin.com/posts/scottwright_home-click-armor-activity-7033783390243848192-TOHu/

* Watch this episode on YouTube *

https://youtu.be/RGhg1yZE81Y

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Twitter’s Paywall 2FA, Mental Health Data for Sale, Meta’s Verified Program appeared first on The Shared Security Show.

View Details

Twitter is phasing out its free text message two-factor authentication (2FA) and putting the feature behind a paywall, prompting security experts to advise Twitter users to switch to other authentication methods.

How data brokers are selling sensitive mental health data for a few hundred dollars with little attempt to hide identifying information such as names and addresses. A new report highlights how some firms are offering the data for as low as $275 for information on 5,000 people, and Congress has yet to pass significant legislation on data brokers.

Meta (formerly Facebook) has launched a new program called Meta Verified which aims to unify verification across all of the company's platforms. Users can pay a monthly fee to verify their presence on Facebook and Instagram by submitting their government ID. 

Show notes: https://sharedsecurity.net/2023/02/27/twitters-paywall-2fa-mental-health-data-for-sale-metas-verified-program/

View Details

Reddit announced that it was the victim of a phishing attack aimed at its employees, resulting in unauthorized access to internal documents, code, and some unspecified business systems.

Advice on managing device location-tracking settings to ensure you're not sharing your location inadvertently.

The case of former Ubiquiti employee, Nickolas Sharp, who pled guilty to multiple felony charges after orchestrating a security breach, stealing data, and extorting almost $2m worth of cryptocurrency from his company.

Plus, our thoughts about UFO's and Chinese spy balloons! 

Show notes: https://sharedsecurity.net/2023/02/20/reddit-hacked-preventing-accidental-location-sharing-developer-hacks-his-own-company/

View Details

In this episode host Tom Eston sits down with Kathleen Smith, Chief Outreach Officer at ClearedJobs.net, to discuss the current state of the job market in the cybersecurity industry. With a recent surge in layoffs, Kathleen provides advice for those who were recently let go and discusses how the economic situation has affected recruiters. She also shares her predictions for changes in the recruitment process and offers advice for job seekers. Finally, Kathleen shares more about her role at Cleared Jobs and how listeners can get in touch.

* Links mentioned on the show

Connect with Kathleen Smithhttps://www.linkedin.com/in/kathleenesmith/
https://twitter.com/YesItsKathleen

ClearedJobs.net
https://clearedjobs.net/

Security Cleared Jobs: Who’s Hiring & How Podcast
https://clearedjobs.net/podcast

Previous episodes with Kathleen
https://sharedsecurity.net/2020/05/29/episode-100-with-rachel-tobac-and-kathleen-smith/
https://sharedsecurity.net/2019/01/09/cybersecurity-careers-recruiting-and-volunteering-with-kathleen-smith-84/

* Watch this episode on YouTube *

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Layoffs, Recruiting, and The Year Ahead for Cybersecurity Job Seekers appeared first on The Shared Security Show.

View Details

In this episode host Tom Eston sits down with Kathleen Smith, Chief Outreach Officer at ClearedJobs.net, to discuss the current state of the job market in the cybersecurity industry. With a recent surge in layoffs, Kathleen provides advice for those who were recently let go and discusses how the economic situation has affected recruiters. She also shares her predictions for changes in the recruitment process and offers advice for job seekers. Finally, Kathleen shares more about her role at Cleared Jobs and how listeners can get in touch.

Show notes: https://sharedsecurity.net/2023/02/13/layoffs-recruiting-and-the-year-ahead-for-cybersecurity-job-seekers/

View Details

The attacks on password managers and their users continue as Bitwarden and 1Password users have reported seeing paid ads for phishing sites in Google search results for the official login page of the password management vendors. Not only that, a new vulnerability in the popular open-source password management software KeePass has also been reported.

Three health tracking apps available on Google Play (Lucky Step, WalkingJoy, Lucky Habit: health tracker) have been downloaded on over 20 million devices, but a recent report shows that the rewards for using the apps are impossible or only partially available after watching tons of ads.

A bug in Meta’s Accounts Center feature allowed hackers to bypass two-factor authentication (2FA) by brute force guessing a six-digit authentication code.

* Links mentioned on the show

Convincing, Malicious Google Ads Look to Lift Password Manager Logins
https://www.darkreading.com/threat-intelligence/convincing-malicious-google-ads-password-managers

KeePass disputes vulnerability allowing stealthy password theft
https://www.bleepingcomputer.com/news/security/keepass-disputes-vulnerability-allowing-stealthy-password-theft/

Shady reward apps on Google Play amass 20 million downloads
https://www.bleepingcomputer.com/news/security/shady-reward-apps-on-google-play-amass-20-million-downloads/

Meta’s Account Center came with a 2FA-defeating bug
https://www.theverge.com/2023/1/30/23578033/meta-account-center-bug-2-factor-authentication-sms-email

* Watch this episode on YouTube *

https://youtu.be/g_7UNWmCYgg

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Password Managers Under Attack, Shady Reward Apps on Google Play, Meta Account Center 2FA Bypass appeared first on The Shared Security Show.

View Details

The attacks on password managers and their users continue as Bitwarden and 1Password users have reported seeing paid ads for phishing sites in Google search results for the official login page of the password management vendors. Not only that, a new vulnerability in the popular open-source password management software KeePass has also been reported.

Three health tracking apps available on Google Play (Lucky Step, WalkingJoy, Lucky Habit: health tracker) have been downloaded on over 20 million devices, but a recent report shows that the rewards for using the apps are impossible or only partially available after watching tons of ads.

A bug in Meta's Accounts Center feature allowed hackers to bypass two-factor authentication (2FA) by brute force guessing a six-digit authentication code.

Show notes: https://sharedsecurity.net/2023/02/06/password-managers-under-attack-shady-reward-apps-on-google-play-meta-account-center-2fa-bypass/

View Details

A hacker discovered a copy of the US No Fly List, which contains the names of people banned from traveling in or out of the US on commercial flights, on an unsecured Jenkins server connected to a commercial airline.

Will AI-powered phishing become a threat for organizations?

Scientists from Carnegie Mellon University have developed a way to sense humans through walls using a deep neural network called DensePose that maps Wi-Fi signals to UV coordinates.

* Links mentioned on the show

U.S. ‘No Fly List’ Leaks After Being Left in an Unsecured Airline Server
https://www.vice.com/en/article/93a4p5/us-no-fly-list-leaks-after-being-left-in-an-unsecured-airline-server

Why AI-Powered Phishing Will Become a Serious Security Issue for Your Organization
https://www.xorlab.com/en/blog/why-ai-powered-phishing-will-become-a-serious-security-issue-for-your-organization

Scientists use Wi-Fi routers to see humans through walls
https://www.zdnet.com/article/scientists-use-wi-fi-routers-to-see-humans-through-walls/

* Watch this episode on YouTube *

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post U.S. ‘No Fly List’ Leaks, AI-Powered Phishing, Wi-Fi Used to See Humans Through Walls appeared first on The Shared Security Show.

View Details

A hacker discovered a copy of the US No Fly List, which contains the names of people banned from traveling in or out of the US on commercial flights, on an unsecured Jenkins server connected to a commercial airline.

Will AI-powered phishing become a threat for organizations?

Scientists from Carnegie Mellon University have developed a way to sense humans through walls using a deep neural network called DensePose that maps Wi-Fi signals to UV coordinates.

Show notes: https://sharedsecurity.net/2023/01/30/u-s-no-fly-list-leaks-ai-powered-phishing-wi-fi-used-to-see-humans-through-walls/

View Details

On this week’s episode, We’re excited to bring you a classic conference talk that Tom Eston gave with co-host Kevin Johnson back in 2009 at DEF CON 17 in Las Vegas. The talk is called “Social Zombies: Your Friends Want to Eat Your Brains” and it explores the various risks and concerns related to malware delivery through social networking sites.

We discuss how social networks make money and the privacy and security issues that arise due to the trust built on these platforms. We also delve into typical botnets and bot programs, and examine the delivery of malware through social networks and the use of these networks as command and control channels.

Interestingly, not a lot has changed in terms of the privacy and security of social networks since we gave this presentation, so it’s still highly relevant today. We hope you enjoy revisiting this classic talk with us this week on the Shared Security Show!

* Links mentioned on the show

Here’s the full talk if you want to watch the entire presentation!

* Watch this episode on YouTube *

https://youtu.be/caXPTbNWX64

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Social Zombies Revisited: Your Friends Want to Eat Your Brains appeared first on The Shared Security Show.

View Details

On this week's episode, We're excited to bring you a classic conference talk that Tom Eston gave with co-host Kevin Johnson back in 2009 at DEF CON 17 in Las Vegas. The talk is called "Social Zombies: Your Friends Want to Eat Your Brains" and it explores the various risks and concerns related to malware delivery through social networking sites.

We discuss how social networks make money and the privacy and security issues that arise due to the trust built on these platforms. We also delve into typical botnets and bot programs, and examine the delivery of malware through social networks and the use of these networks as command and control channels.

Interestingly, not a lot has changed in terms of the privacy and security of social networks since we gave this presentation, so it's still highly relevant today. We hope you enjoy revisiting this classic talk with us this week on the Shared Security Show!

Show notes: https://sharedsecurity.net/2023/01/23/social-zombies-revisited-your-friends-want-to-eat-your-brains/

View Details

Facebook has been ordered to pay a fine of $414m by EU regulators who ruled that the company had broken EU law by forcing users to accept personalized ads. The ruling could have a major impact on Facebook's advertising business in the EU, which is one of the company's largest markets, if it is required to make changes to its advertising practices.

A hacker has claimed to have the personal data of 400 million Twitter users for sale on the dark web. Attackers have also released the account details and email addresses of 235 million users for free. The information was exposed due to a Twitter API vulnerability shipped in June 2021 and later patched.

Security researchers have identified security vulnerabilities in the connected vehicle APIs of 16 major car manufacturers, including Acura, BMW, Ferrari, Ford, Genesis, Honda, Hyundai, Infiniti, Jaguar, Kia, Land Rover, Mercedes-Benz, Nissan, Porsche, Rolls Royce, and Toyota.

Show notes: https://sharedsecurity.net/2023/01/16/metas-eu-ad-practices-ruled-illegal-twitter-api-data-breach-vulnerabilities-in-major-car-brands/

View Details

Things get worse for LastPass as a security breach in November resulted in the theft of customer data, including encrypted password vaults and unencrypted web addresses.

Pig butchering scams, a variation of business email compromise and romance scams, are on the rise. How do they work and what do you need to know to protect yourself?

Okta, a major identity and authentication company, has suffered another security breach following the “suspicious access” to its code repositories on Github.

* Links mentioned on the show

Encrypted LastPass Password Vaults, Customer Information Stolen in November Breach
https://www.cpomagazine.com/cyber-security/encrypted-lastpass-password-vaults-customer-information-stolen-in-november-breach/
https://grahamcluley.com/lostpass-after-the-lastpass-hack-heres-what-you-need-to-know/

Hacker Lexicon: What Is a Pig Butchering Scam?
https://www.wired.com/story/what-is-pig-butchering-scam/

Okta confirms another breach after hackers steal source code
https://www.msn.com/en-us/news/technology/okta-confirms-another-breach-after-hackers-steal-source-code/ar-AA15yDk4

* Watch this episode on YouTube *

https://youtu.be/RPpGf6slqWI

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post LastPass Password Vaults Stolen, Pig Butchering Scams, Okta Source Code Theft appeared first on The Shared Security Show.

View Details

Things get worse for LastPass as a security breach in November resulted in the theft of customer data, including encrypted password vaults and unencrypted web addresses.

Pig butchering scams, a variation of business email compromise and romance scams, are on the rise. How do they work and what do you need to know to protect yourself?

Okta, a major identity and authentication company, has suffered another security breach following the "suspicious access" to its code repositories on Github.

Show notes: https://sharedsecurity.net/2023/01/09/lastpass-password-vaults-stolen-pig-butchering-scams-okta-source-code-theft/

View Details

In this episode Tom Eston discusses one of the biggest privacy concerns people have today, online tracking by companies and advertisers. Tom will cover the following topics, tips, and new techniques to help you stop being tracked:

Why should we be concerned about online tracking? How to enable and configure the privacy settings in your web browser How your smartphone has privacy settings to block online tracking Using a privacy focused search engine

Show notes: https://sharedsecurity.net/2023/01/02/how-to-stop-online-tracking-3-new-ways/

View Details

In our last episode of the year, we discuss the year that was 2022. What did we get right? What did we get wrong? And what are our cybersecurity and privacy predictions for 2023?

Thank you to all of our listeners for a great year! We’re looking forward to bringing you more content, news, tips, and advice in 2023!

Happy New Year!

* Links mentioned on the show

Our previous year in review episodes (have fun with these!)
https://sharedsecurity.net/2021/12/27/the-year-in-review-and-2022-predictions/
https://sharedsecurity.net/2020/12/23/the-year-in-review-and-2021-predictions/
https://sharedsecurity.net/2019/12/23/the-year-in-review-and-2020-predictions-with-kevin-johnson/
https://sharedsecurity.net/2018/12/26/the-year-in-review-and-2019-predictions-with-special-guest-kevin-johnson-83/

* Watch this episode on YouTube *

https://youtu.be/mSNrn_RM5mM

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post The Year in Review and 2023 Predictions appeared first on The Shared Security Show.

View Details

In our last episode of the year, we discuss the year that was 2022. What did we get right? What did we get wrong? And what are our cybersecurity and privacy predictions for 2023?

Thank you to all of our listeners for a great year! We're looking forward to bringing you more content, news, tips, and advice in 2023!

Happy New Year!

Show notes: https://sharedsecurity.net/2022/12/26/the-year-in-review-and-2023-predictions/

View Details

Apple is considering giving third-party app stores access to its iPhones and iPads in the European Union (EU) to comply with new competition law. Will the “sideloading” of apps change Apple’s walled garden of security?

Lensa the AI app that creates artistic profile pictures has gone viral. What are the privacy risks and what does their privacy policy and terms of service really say?

A group of four graduate students from Wuhan University in China have developed a coat that they claim is invisible to AI-powered security cameras. How does the coat work and will this technology be used by the Chinese government to improve mass surveillance?

Thanks to NordLayer for sponsoring this episode!
As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity

* Links mentioned on the show

Apple Reportedly to Allow Rival App Stores on iPhones, iPads in EU
https://www.cnet.com/tech/mobile/apple-reportedly-to-allow-rival-app-stores-on-iphones-ipads-in-eu/

What You Should Know Before Using the Lensa AI App
https://www.wired.com/story/lensa-ai-magic-avatars-security-tips/

Chinese Students Invent Coat That Makes People Invisible to AI Security Cameras
https://www.vice.com/amp/en/article/88q3gk/chinese-students-invent-invisibility-cloak

* Watch this episode on YouTube *

https://youtu.be/XayoUk8jemI

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Apple to Allow Third-Party App Stores, Lensa AI App Privacy Risks, Real-Life Invisibility Cloak appeared first on The Shared Security Show.

View Details

Apple is considering giving third-party app stores access to its iPhones and iPads in the European Union (EU) to comply with new competition law. Will the "sideloading" of apps change Apple's walled garden of security?

Lensa the AI app that creates artistic profile pictures has gone viral. What are the privacy risks and what does their privacy policy and terms of service really say?

A group of four graduate students from Wuhan University in China have developed a coat that they claim is invisible to AI-powered security cameras. How does the coat work and will this technology be used by the Chinese government to improve mass surveillance?

Thanks to NordLayer for sponsoring this episode! As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity

Intro 

Show notes: https://sharedsecurity.net/2022/12/19/apple-to-allow-third-party-app-stores-lensa-ai-app-privacy-risks-real-life-invisibility-cloak/

View Details

A chatbot developed by OpenAI, called ChatGPT, has gone viral and is able to mimic human language and speech styles and can interact with users in a conversational way. It can be used for a range of purposes, including writing code, talking like a “Valley girl”, and even podcast introduction scripts.

Attackers broke into a cloud storage service used by password manager LastPass to gain access to “certain elements” of customers’ information.

Details on Apple’s three new advanced security features to protect user data in iCloud.

Thanks to NordLayer for sponsoring this episode!
As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity

* Links mentioned on the show

An AI chatbot went viral. Some say it’s better than Google, others worry it’s problematic.
https://www.nbcnews.com/tech/tech-news/chatgpt-ai-chatbot-viral-rcna59628

Napkin Ideas Around What Changes to Expect Post-ChatGPT
https://danielmiessler.com/blog/ideas-changes-expect-post-chatgpt/

ChatGPT: Optimizing Language Models for Dialogue
https://openai.com/blog/chatgpt/
https://gpt3demo.com/apps/chatgpt

Intruders gain access to user data in LastPass incident
https://www.theregister.com/2022/12/01/lastpass/

Apple advances user security with powerful new data protections
https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/

* Watch this episode on YouTube *

https://youtu.be/JOdVW6Vo93I

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post ChatGPT Goes Viral, More Trouble for LastPass, Apple’s New Data Protections appeared first on The Shared Security Show.

View Details

A chatbot developed by OpenAI, called ChatGPT, has gone viral and is able to mimic human language and speech styles and can interact with users in a conversational way. It can be used for a range of purposes, including writing code, talking like a "Valley girl", and even podcast introduction scripts.

Attackers broke into a cloud storage service used by password manager LastPass to gain access to "certain elements" of customers' information.

Details on Apple's three new advanced security features to protect user data in iCloud.

Thanks to NordLayer for sponsoring this episode! As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity

Show notes: https://sharedsecurity.net/2022/12/12/chatgpt-goes-viral-more-trouble-for-lastpass-apples-new-data-protections/

View Details

In this sponsored episode co-host Tom Eston discusses SASE (Secure Access Service Edge) and if its more than just the latest cybersecurity buzzword with Carlos Salas from NordLayer. Topics include:

– What is SASE (Secure Access Service Edge)?
– What’s the difference between SASE and SSE (Security Service Edge)?
– What challenges/problems do companies encounter while trying to secure cloud networks?
– Why would companies need a SASE solution?
– Some crucial features of SASE and SSE (Zero Trust Network Access, Cloud Access Security Broker, Secure Web gateway, Firewalls-as-a-Service, Data Loss Protection (DLP), SD-WAN)
– What has been and will be the intersection between remote or hybrid work and an organization’s cybersecurity needs?

Thanks to NordLayer for sponsoring this episode!
As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity.

* Links mentioned on the show *

NordLayer’s Global Remote Index
https://nordlayer.com/global-remote-work-index/

* Watch this episode on YouTube *

https://youtu.be/Ur5k5zC44MM

* Thank you to our sponsors! *

NordLayer

Secure your business network with NordLayer.
As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity.

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post SASE: Is it Just Another Cybersecurity Buzzword? appeared first on The Shared Security Show.

View Details

A recent data breach of 5.4 million Twitter users and Meta being fined $265 million dollars from a 2021 data leak, and people are fleeing Twitter because of Elon Musk. Are we finally seeing a tipping point in social media?

What is the TikTok “Invisible Challenge” and how links to fake “unfilter” software is being used to spread malware.

Police in San Francisco will be allowed to deploy killer, remote-controlled robots in emergency situations. What could possibly go wrong?

* Links mentioned on the show *

Twitter Reportedly Unveils Lucrative Plan To Win Back Fleeing Advertisers As Musk Begs People To Tweet More
https://www.forbes.com/sites/dereksaul/2022/12/01/twitter-reportedly-unveils-lucrative-plan-to-win-back-fleeing-advertisers-as-musk-begs-people-to-tweet-more/

5.4 million Twitter users’ stolen data leaked online — more shared privately
https://www.bleepingcomputer.com/news/security/54-million-twitter-users-stolen-data-leaked-online-more-shared-privately/

Meta Fined For 2021 Data Breach As Millions Of Twitter Users’ Data Also Leaked
https://www.forbes.com/sites/petersuciu/2022/11/28/meta-fined-for-2021-data-breach-as-millions-of-twitter-users-data-leaked/

Attacker Uses a Popular TikTok Challenge to Lure Users Into Installing Malicious Package
https://medium.com/checkmarx-security/attacker-uses-a-popular-tiktok-challenge-to-lure-users-into-installing-malicious-package-fe6248dfe0ae

San Francisco approves police proposal to use potentially deadly robots
https://www.theguardian.com/us-news/2022/nov/29/san-francisco-police-robots-deadly-force

* Watch this episode on YouTube *

https://youtu.be/piRf2tvSisY

* Thank you to our sponsors! *

SLNT

Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.

Click Armor

To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity

* Subscribe and follow the show *

Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Follow us on Twitter: https://twitter.com/sharedsec

Website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

The post Is Social Media at a Tipping Point, The TikTok Invisible Challenge, San Francisco Police Can Use Killer Robots appeared first on The Shared Security Show.

View Details

A recent data breach of 5.4 million Twitter users and Meta being fined $265 million dollars from a 2021 data leak, and people are fleeing Twitter because of Elon Musk. Are we finally seeing a tipping point in social media?

What is the TikTok “Invisible Challenge” and how links to fake "unfilter" software is being used to spread malware.

Police in San Francisco will be allowed to deploy killer, remote-controlled robots in emergency situations. What could possibly go wrong?

Show notes: https://sharedsecurity.net/2022/12/05/is-social-media-at-a-tipping-point-the-tiktok-invisible-challenge-san-francisco-police-can-use-killer-robots/

View Details

This week we continue our series on how to break into a cybersecurity career with long time industry veteran, Rob Fuller (Mubix). Rob speaks with us about how he started his career in the Marine Corps, his time on Hak5, and more recently earning his Masters degree. Rob also talks about how these experiences has […]

The post How to Break Into a Cybersecurity Career – Rob Fuller (Mubix) appeared first on The Shared Security Show.

View Details

This week we continue our series on how to break into a cybersecurity career with long time industry veteran, Rob Fuller (Mubix). Rob speaks with us about how he started his career in the Marine Corps, his time on Hak5, and more recently earning his Masters degree. Rob also talks about how these experiences has shaped his career, his best career advice to someone just starting out, and the importance of getting yourself out there and doing the things you enjoy!

Thanks to NordLayer for sponsoring this episode!
Secure your business network with NordLayer. As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity.

Show notes: https://sharedsecurity.net/2022/11/28/how-to-break-into-a-cybersecurity-career-rob-fuller-mubix/ 

View Details

Former Twitter users are migrating en masse to Mastodon so what is Mastodon and what do you need to know about Mastodon from a security and privacy perspective? Twitter was flooded by a wave of imposter accounts after the $8 “verification” label fiasco, and details about the largest multi-state privacy settlement in the US where […]

The post The Rise of Mastodon, Twitter in Trouble, Largest Privacy Settlement in US History appeared first on The Shared Security Show.

View Details

Former Twitter users are migrating en masse to Mastodon so what is Mastodon and what do you need to know about Mastodon from a security and privacy perspective? Twitter was flooded by a wave of imposter accounts after the $8 "verification" label fiasco, and details about the largest multi-state privacy settlement in the US where Google has agreed to pay $391 million to resolve an investigation into how the company tracked users’ locations. Plus, you don't want to miss Tom's Canadian dad jokes!

Show notes: https://sharedsecurity.net/2022/11/21/the-rise-of-mastodon-twitter-in-trouble-largest-privacy-settlement-in-us-history/

View Details

Matt Scheurer, host of the ThreatReel Podcast and Assistant Vice President of Computer Security and Incident Response in a large enterprise environment, joins us to discuss starting a career in digital forensics and incident response (DFIR). Matt discusses how he got started, his advice to anyone that wants to pursue a career in DFIR, and what the future may hold for the DFIR industry.

We also have a fun discussion about the "possibility" of aliens in Dayton Ohio.

Thanks to NordLayer for sponsoring this episode!
Secure your business network with NordLayer. As a listener of this podcast, get your first month free by going to https://nordlayer.com/sharedsecurity.

Show notes: https://sharedsecurity.net/2022/11/14/how-to-break-into-a-cybersecurity-career-digital-forensics-and-incident-response-dfir/

View Details

Katie Teitler, Senior Cybersecurity Strategist at Axonius and co-host on the popular Enterprise Security Weekly podcast, joins us to discuss the role of cybersecurity in combating midterm election disinformation. We discuss the difference is between misinformation and disinformation, how we can combat disinformation and what are some things about disinformation, private platforms, and free speech […]

The post Cybersecurity’s Role in Combating Midterm Election Disinformation appeared first on The Shared Security Show.

View Details

Rafal Los, host of the popular Down the Security Rabbithole Podcast, joins us to discuss CISO liability risk and the ongoing discussion in the cybersecurity community about CISOs going to jail. Plus, details on the recent (ISC)2 bylaw vote (why you should vote no) and a discussion about the value of cybersecurity certifications. ** Links […]

The post CISO Liability Risk and Jail Time, (ISC)2 Bylaw Vote and the Value of Cybersecurity Certifications appeared first on The Shared Security Show.

View Details

Rafal Los, host of the popular Down the Security Rabbithole Podcast, joins us to discuss CISO liability risk and the ongoing discussion in the cybersecurity community about CISOs going to jail. Plus, details on the recent (ISC)2 bylaw vote (why you should vote no) and a discussion about the value of cybersecurity certifications.

Show notes: https://sharedsecurity.net/2022/10/31/ciso-liability-risk-and-jail-time-isc2-bylaw-vote-and-the-value-of-cybersecurity-certifications/

View Details

Two modified wi-fi enabled drones were found on the top of a financial firm’s building and used to intercept a employee’s credentials, a fun discussion about the best way to physically destroy data on electronics that no longer work, and details about Signal removing SMS support for Android users. ** Links mentioned on the show […]

The post Attack of the Wi-Fi Spy Drones, How to Destroy Your Old Electronics, Signal Removes SMS Support appeared first on The Shared Security Show.

View Details

Two modified wi-fi enabled drones were found on the top of a financial firm's building and used to intercept a employee's credentials, a fun discussion about the best way to physically destroy data on electronics that no longer work, and details about Signal removing SMS support for Android users.

Show notes: https://sharedsecurity.net/2022/10/24/attack-of-the-wi-fi-spy-drones-how-to-destroy-your-old-electronics-signal-removes-sms-support/

View Details

Former Uber CSO Joe Sullivan was found guilty of obstructing a federal investigation in connection with the attempted cover-up of a 2016 hack at Uber, NIST and Microsoft say that mandatory password expiration is no longer needed but many organizations are still doing it, and how fake executive profiles are becoming a huge problem for LinkedIn.

Show notes: https://sharedsecurity.net/2022/10/17/uber-breach-guilty-verdict-mandatory-password-expiration-fake-executive-profiles-on-linkedin/

View Details

A recent survey of ethical hackers by Bishop Fox and SANS shows that once a vulnerability or weakness is found about 58% of ethical hackers can break into an environment in less than five hours, SMS phishing and text message scams appear to be changing tactics taking a more “urgent” tone, and a discussion about […]

The post Hackers Need 5 Hours or Less to Break In, SMS Phishing Tactics, Strange Ways Employees Expose Data appeared first on The Shared Security Show.

View Details

Passkeys are coming soon to Apple iOS 16 so what are passkeys and why are they an eventual replacement for passwords? Researchers have discovered a new attack that uses mouse movement in Microsoft PowerPoint to deploy malware, and details on how the 2K Games help desk support platform was compromised to push malware through fake […]

The post What are Passkeys, PowerPoint Mouseover Attack, 2K Games Support Hacked appeared first on The Shared Security Show.

View Details

Uber got hacked by an 18 year old using social engineering and a multi-factor authentication fatigue attack, Morgan Stanley has been auctioning off hard drives holding sensitive client data since 2015, and why is it so hard for social networks to remove personal data when deleting your user account. ** Links mentioned on the show […]

The post Uber Hacked by 18 Year Old, Morgan Stanley Hard Drives Got Auctioned, Deleting Your Data is Hard appeared first on The Shared Security Show.

View Details

In recent court testimony two Facebook engineers were asked what information, precisely, does Facebook store about us, and where is it? Surprisingly they said, they don’t know. Details on how brand new employees of companies are being “spearmished” (hat tip to @ErinInfosec and @RachelTobac via Twitter), and how thousands of Colorado residents found themselves locked […]

The post Facebook Doesn’t Know Where Your Data Is, New Hire Spearmishing Attack, Smart Thermostat Lock Out appeared first on The Shared Security Show.

View Details

TikTok has denied reports that it was breached by a hacking group, after it claimed they have gained access to over 2 billion user records, the Los Angeles school district, the second-largest in the US, suffered a ransomware attack, and details on how one high school in Sydney Australia installed fingerprint scanners at the entrance […]

The post TikTok Denies Data Breach, Los Angeles School District Ransomware Attack, Fingerprint Scanners in School Bathrooms appeared first on The Shared Security Show.

View Details

Popular password manager LastPass announced that some of their source code was stolen, but that no customer passwords were compromised in a recent data breach disclosure, an Israeli researcher has discovered a new method to exfiltrate data from air-gapped systems using the LED indicators on network cards, and details about the Twitter whistleblower Peiter “Mudge” […]

The post LastPass Data Breach, ETHERLED: Air-Gapped Systems Attack, Twitter Whistleblower Complaint appeared first on The Shared Security Show.

View Details

Janet Jackson’s “Rhythm Nation” has been recognized as an exploit for a vulnerability after Microsoft reported it can crash the hard drives of certain old laptop computers, phishing attacks that compromise credentials using brand impersonation are on the rise, and details about a new privacy focused phone carrier that doesn’t track your location or web […]

The post Janet Jackson Can Crash Laptops, Credential Phishing Attacks Skyrocket, A Phone Carrier That Doesn’t Track You appeared first on The Shared Security Show.

View Details

A Cisco employee was compromised by a ransomware gang using a technique called multi-factor authentication fatigue, an attack on the Signal messenger app’s SMS service Twilio potentially disclosed the phone numbers of 1,900 users, and details on how Facebook and Instagram track what you click on including your web browsing history by using their in-app […]

The post Multi-Factor Authentication Fatigue Attack, Signal Account Twilio Hack, Facebook and Instagram In-App Browser appeared first on The Shared Security Show.

View Details

Aaron Zar, SLNT founder and director of disconnection joins co-host Tom Eston to discuss the importance of Faraday technology, what’s changed with privacy over the last several years, some of the really cool SLNT Faraday products now available, and how Aaron tested product durability by running over a SLNT Faraday Backpack (containing a MacBook Pro) […]

The post The Importance of Faraday Technology with Aaron Zar from SLNT appeared first on The Shared Security Show.

View Details

Why your phone number is becoming a popular way to identify you, our advise on how to best protect your privacy at hacker summer camp in Las Vegas (BSides, BlackHat, DEF CON), and details on Samsung’s new repair mode which will protect your private data on your smartphone when you take it in for repairs. […]

The post Phone Numbers Used for Identification, Hacker Summer Camp Advice, Samsung Repair Mode appeared first on The Shared Security Show.

View Details

Twitter suffers a data breach of phone numbers and email addresses belonging to 5.4 million accounts, new research shows that attackers are finding and exploiting zero-day vulnerabilities in 15 minutes, and details on how a resilient trait in videos and images could aid in deepfake detection. Links mentioned on the show Hacker selling […]

The post Twitter Data Breach, 15 Minutes to Exploit Zero-Day Vulnerabilities, Resilient Deepfake Traits appeared first on The Shared Security Show.

View Details

In this episode learn all about the world of corporate spying from someone who was a corporate spy and actually wrote a book on it! Robert Kerbeck author of “RUSE: Lying the American Dream from Hollywood to Wall Street” joins us to discuss his fascinating career as a corporate spy, life as a struggling actor, […]

The post Robert Kerbeck Author of RUSE: Lying the American Dream from Hollywood to Wall Street appeared first on The Shared Security Show.

View Details

Apple previews Lockdown Mode which is designed for high risk individuals such as human rights workers, lawyers, politicians and journalists, hotel chain Marriott confirms another data breach, and new details on the development of smart contact lenses and what these could mean for your privacy. Links mentioned on the show Apple previews Lockdown […]

The post Apple Previews Lockdown Mode, Another Marriott Data Breach, Smart Contact Lenses appeared first on The Shared Security Show.

View Details

The commissioner of the FCC (Federal Communications Commission), asked the CEOs of Apple and Google to remove TikTok from their app stores, bug bounty platform HackerOne disclosed that a former employee improperly accessed security reports and submitted them for personal gain, and new details on the California gun owner data breach which had exposed the […]

The post Could TikTok Be Removed From App Stores, HackerOne Employee Caught Stealing Vulnerability Reports, California Gun Owner Data Breach appeared first on The Shared Security Show.

View Details

Period tracker apps are causing privacy concerns because they could potentially be used against women in states that ban abortion, new research shows that vendors are being impersonated more than employees in Business Email Compromise (BEC) attacks, and details on the first ever bug bounty program from the creators of the LockBit ransomware operation. ** […]

The post Period Tracking Apps and Your Privacy, Vendor Impersonation Attacks, LockBit Ransomware Bug Bounty Program appeared first on The Shared Security Show.

View Details

The Tim Hortons mobile app created a “a mass invasion of Canadians’ privacy” by conducting continuous location tracking without user consent even when the app was closed, what is a social engineering kill-chain and how can this help understand and prevent attacks, and new research shows 33 out of the top 100 hospitals in America […]

The post Tim Hortons Privacy Investigation, Social Engineering Kill-Chain, Hospitals Sending Facebook Your Data appeared first on The Shared Security Show.

View Details

A new bipartisan privacy bill, the American Data Privacy and Protection Act, “could” be the first privacy legislation in the US not doomed to fail, a story about why you should delete your location and private data in your car’s navigation system before selling it, and details on Firefox’s new privacy feature called “Total Cookie […]

The post Bipartisan Digital-Privacy Bill, Delete Your Data Before Selling Your Car, Firefox Total Cookie Protection appeared first on The Shared Security Show.

View Details

This week we discuss hacking ham radio with special guests Caitlin Johanson, Rick Osgood, and Larry Pesce. In this episode you’ll learn what ham radio is, why its still relevant, why would attackers want to hack ham radio, all about packet radio and APRS (Automatic Packet Reporting System), and what equipment and licensing you need […]

The post Hacking Ham Radio: Why It’s Still Relevant and How to Get Started appeared first on The Shared Security Show.

View Details

The DuckDuckGo mobile browser allows Microsoft trackers due to an agreement in their syndicated search content contract, a database of contact details for hundreds of Verizon employees was compromised after an employee was social engineered to give the attacker remote access to their corporate computer, and details about new research that shows that even when […]

The post DuckDuckGo Browser Allows Microsoft Trackers, Stolen Verizon Employee Database, Attacking Powered Off iPhones appeared first on The Shared Security Show.

View Details

Tanya Janca, founder of the We Hack Purple Academy, Director of Developer Relations and Community at Bright, and author of “Alice & Bob Learn Application Security” joins us to discuss the current state and future of Application Security. In this episode we discuss what Tanya’s been up to, what’s changed in AppSec over the last […]

The post The State of Application Security with Tanya Janca appeared first on The Shared Security Show.

View Details

What is Apple Mail Privacy Protection and how does it hide your IP address, so senders can’t link it to your online activity or determine your location, government authorities such as the FBI and NSA have released a list of top attack vectors used to gain initial access by attackers, and how more companies are […]

The post Apple Mail Privacy Protection, Government Agencies Reveal Top Attack Vectors, Is Big Brother Watching You at Work? appeared first on The Shared Security Show.

View Details

The FBI searched emails, texts and other electronic communications of 3.4 million U.S. residents without a warrant, Apple, Google, and Microsoft have announced they will support a new passwordless sign-in standard created by the FIDO Alliance and the World Wide Web Consortium, and details about how some websites are keylogging your data as you type […]

The post FBI Warrantless Searches, Passwordless Sign-Ins, Keylogging Web Forms appeared first on The Shared Security Show.

View Details

Josh Feinblum is the co-founder of Stavvy, a Boston-based fully integrated digital mortgage platform, where he leads product, engineering, people, and finance. He also serves as a venture partner at F-Prime Capital, where he evaluates and advises startups of all stages across multiple verticals. Josh talks to us about his journey through cybersecurity including his […]

The post Cybersecurity for Startups with Josh Feinblum from Stavvy appeared first on The Shared Security Show.

View Details

Elon Musk buys Twitter for $44 billion so what does this mean for the privacy and cybersecurity of the platform? More than 100 different Lenovo laptop computers contain firmware-level vulnerabilities which is a great reminder about making sure you update the BIOS on your computer. Plus, details about researchers who have created a t-shirt that […]

The post Elon Musk Buys Twitter, Forgotten BIOS Updates, T-Shirt Outwits Facial Recognition appeared first on The Shared Security Show.

View Details

Elon Musk buys Twitter for $44 billion so what does this mean for the privacy and cybersecurity of the platform? More than 100 different Lenovo laptop computers contain firmware-level vulnerabilities which is a great reminder about making sure you update the BIOS on your computer. Plus, details about 
researchers who have created a t-shirt that renders the wearer undetectable to facial recognition technology.

Show notes: https://sharedsecurity.net/2022/05/02/elon-musk-buys-twitter-forgotten-bios-updates-t-shirt-outwits-facial-recognition/

View Details

Award-winning security transformation manager and digital anthropologist Lianne Potter joins us to discuss the fascinating topic of digital anthropology and how we can rehumanize cybersecurity. In this episode Lianne discusses how she became a digital anthropologist, how this field applies to cybersecurity, and the one thing organizations need to do to bring the human back […]

The post Rehumanizing Cybersecurity with Lianne Potter appeared first on The Shared Security Show.

View Details

Award-winning security transformation manager and digital anthropologist Lianne Potter joins us to discuss the fascinating topic of digital anthropology and how we can rehumanize cybersecurity. In this episode Lianne discusses how she became a digital anthropologist, how this field applies to cybersecurity, and the one thing organizations need to do to bring the human back into their cybersecurity programs.

Show notes: https://sharedsecurity.net/2022/04/25/rehumanizing-cybersecurity-with-lianne-potter/

View Details

More young people seem to be choosing dumbphones over smartphones, but is it because of privacy concerns or because its trendy? John Oliver, host of the ‘Last Week Tonight’ show, used data brokers to obtain lawmakers’ digital footprints and promised to not release the data as long as Congress passes privacy legislation. Plus details about […]

The post Dumbphone Sales are Soaring, John Oliver Blackmails Congress, Cicada Chinese APT Group appeared first on The Shared Security Show.

View Details

More young people seem to be choosing dumbphones over smartphones, but is it because of privacy concerns or because its trendy? John Oliver, host of the ‘Last Week Tonight’ show, used data brokers to obtain lawmakers’ digital footprints and promised to not release the data as long as Congress passes privacy legislation. Plus details about the Cicada state sponsored Chinese hacking group which hid inside their victims' networks for nine months. 

Show notes: https://sharedsecurity.net/2022/04/18/dumbphone-sales-are-soaring-john-oliver-blackmails-congress-cicada-chinese-apt-group/

View Details

Scott and Tom explain why privacy isn’t dead, why everyone should care about their privacy, and how you should respond to someone that says “I don’t care about privacy, I have nothing to hide!”. Plus, details on a new attack using fake shopping apps and how a new malware toolkit called “Borat RAT” is no […]

The post Truths and Myths of Privacy, Fake Shopping Apps, Borat RAT Malware appeared first on The Shared Security Show.

View Details

Scott and Tom explain why privacy is not dead, why should everyone should care about their privacy, and how you should respond to someone that says "I don't care about privacy, I have nothing to hide!". Plus, details on a new attack using fake shopping apps and how a new malware toolkit called "Borat RAT" is no laughing matter.

Show notes: https://sharedsecurity.net/2022/04/11/truths-and-myths-of-privacy-fake-shopping-apps-borat-rat-malware/

View Details

This week we battle it out between the two mobile tech giants, Google Android vs Apple iOS, and discuss which one is better for your privacy and cybersecurity. Topics include: app stores and OS updates, ad tracking, and native text messaging. All this plus how Apple and Facebook fell for a massive email scam. ** […]

The post Google Android vs Apple iOS: Which is Better for Privacy and Cybersecurity? appeared first on The Shared Security Show.

View Details

This week we battle it out between the two mobile tech giants, Google Android vs Apple iOS, and discuss which one is better for your privacy and cybersecurity. Topics include: app stores and OS updates, ad tracking, and native text messaging. All this plus how Apple and Facebook fell for a massive email scam.

Show notes: https://sharedsecurity.net/2022/04/04/google-android-vs-apple-ios-which-is-better-for-privacy-and-cybersecurity/

View Details

The LAPSUS$ hacking group has claimed to have hacked both Microsoft and Okta, details about a novel phishing technique called a browser-in-the-browser (BitB) attack, and how a popular software package that has 1.1 million weekly downloads released a new tampered version to condemn Russia’s invasion of Ukraine by wiping arbitrary file contents. ** Links mentioned […]

The post LAPSUS$ Hacks Okta, Browser-in-the Browser Phishing Attack, Popular Software Package Updated to Wipe Russian Systems appeared first on The Shared Security Show.

View Details

This week we discuss the top 3 location tracking apps in the Apple App Store and Google Play and which ones sell your data. Plus, details about recent fake Chick-fil-A and Olive Garden vouchers on Facebook. Links mentioned on the show #1 Phone Tracker by Number https://play.google.com/store/apps/details?id=mg.locations.track5 https://onelocator.com/ – Android https://www.locatorprivacy.com/ – iOS […]

The post Top 3 Location Tracking Apps: Do They Sell Your Data? appeared first on The Shared Security Show.

View Details

A new attack uses Alexa’s functionality to force Amazon Echo devices to make self-issued commands, payment app Zelle has become popular with fraudsters and banks don’t seem to care, and details about hackers who have stolen source code for Samsung Galaxy devices. Links mentioned on the show Preorder Your Professionally Evil Aloha Shirt […]

The post Amazon Echos Hack Themselves, Fraud Is Flourishing on Zelle, Samsung Galaxy Source Code Stolen appeared first on The Shared Security Show.

View Details

This week we discuss some of the more interesting hacks of Russian assets, technology, and more. Scott discusses recent credential stuffing attacks on Microsoft 365 accounts, and a fascinating story about ice cream machine “hackers” that are suing McDonald’s for $900 million dollars in damages. Links mentioned on the show Round up of […]

The post Russia Gets Hacked, Microsoft 365 Credential Stuffing, McDonald’s Ice Cream Machine Hackers appeared first on The Shared Security Show.

View Details

How TikTok can circumvent privacy protections and performs device tracking that gives TikTok full access to user data, the US government warns about ransomware attacks after Biden’s new sanctions against Russia, and details about the latest beta for iOS 15.4 which includes new features designed to prevent Apple AirTags from being used to stalk people. […]

The post TikTok Circumvents Privacy Protections, Russian Sanction Attacks, Apple AirTag Anti-Stalking Measures appeared first on The Shared Security Show.

View Details

MoviePass will use facial recognition and eye tracking to make sure you’re watching ads, new types of shipment-delivery scams are being used to spread malware, and details on the arrests of a SIM swapping gang and how you can protect yourself against a SIM swapping attack. Links mentioned on the show 4-week SLNT […]

The post MoviePass Tracking Your Eyeballs, Shipment Delivery Scams, SIM Swappers Arrested appeared first on The Shared Security Show.

View Details

The EARN IT Act is back for a second time which would pave the way for a new massive government surveillance system in the US, romance scams are on the rise so don’t fall for love in all the wrong places, and details about a new ransomware attack that wants you to like and subscribe, […]

The post EARN IT Act is Back, Romance Scams, Like and Subscribe Ransomware appeared first on The Shared Security Show.

View Details

Researchers have discovered a new web tracking technique using your graphics card, scammers are exploiting security weaknesses on job recruitment websites to post fraudulent job postings, and how a hacker single-handedly took down North Korea’s Internet. Links mentioned on the show Your graphics card could be used to track you across the web […]

The post Graphics Card Web Tracking, Fake Job Ad Scams, Hacker Takes Down North Korea’s Internet appeared first on The Shared Security Show.

View Details

Hacktivists have hacked a Belarus rail system in an attempt to stop Russian military buildup, someone disclosed a slew of vulnerabilities in the popular Insta360 ONE X2 camera, and Google gets accused of “deceptive” location tracking in multiple lawsuits. Links mentioned on the show Hacktivists say they hacked Belarus rail system to stop […]

The post Ukraine Invasion Hacktivists, Insta360 ONE X2 Vulnerabilities, Google Location Tracking Lawsuits appeared first on The Shared Security Show.

View Details

Canada’s federal government admitted to surveilling its population’s movements during the COVID-19 lock-down by tracking 33 million phones, the FBI warned that a hacker group has been sending malware-laden USB sticks to companies, and details on a new law in the United States which will install kill switches in new cars. ** Links mentioned on […]

The post Pandemic Surveillance in Canada, Malware-Filled USB Sticks are Back, Kill Switches in New Cars appeared first on The Shared Security Show.

View Details

Kelly Finnerty, Director of Brand at Startpage, joins co-host Tom Eston to discuss the very important topic of digital wellbeing. In this episode you’ll learn about the mental, financial, and societal impacts of constant tracking. Plus, what are some holistic approaches and tactics that we can use to help our own digital wellbeing. Kelly also […]

The post Digital Wellbeing with Kelly Finnerty from Startpage appeared first on The Shared Security Show.

View Details

Norton 360, a popular antivirus product, has installed a cryptocurrency mining program on its customers’ computers, some cities in Texas have been hit with a phishing scam designed to get users to pay through fraudulent QR code stickers on public parking meters, and how Facebook is still collecting data about you even if you deactivate […]

The post Norton 360 Cryptominer, Fake QR Codes on Parking Meters, Facebook Account Deactivation appeared first on The Shared Security Show.

View Details

A phone scam targeting psychologists reveals that even professionals can become victims, stolen multi-million-dollar NFT’s results in a “all my apes gone” plea for help, and details on a skimmer supply chain attack on more than 100 real estate websites. Links mentioned on the show The Phone Scam That Targets Psychologists https://www.psychologytoday.com/ca/blog/the-fraud-crisis/202110/the-phone-scam-targets-psychologists Thieves […]

The post Phone Scam Targets Psychologists, All My Apes Gone, Supply Chain Skimmer Attack appeared first on The Shared Security Show.

View Details

LastPass users received emails about their master passwords being compromised, details about the privacy policies of new cars, and a story about an Amazon Echo that proposed a lethal challenge to a ten-year-old girl. Links mentioned on the show Log4j 2.17.1 out now, fixes new remote code execution bug https://www.bleepingcomputer.com/news/security/log4j-2171-out-now-fixes-new-remote-code-execution-bug/ If any person […]

The post LastPass Master Passwords, New Cars and Your Privacy, Amazon Alexa Lethal Challenge appeared first on The Shared Security Show.

View Details

In our last monthly show of the year we discuss Web3. What is it and what will it mean to have a decentralized Internet. If you’ve wanted to know what Web3, DeFI, NFTs, and cryptocurrency means for cybersecurity and privacy this is one episode you don’t want to miss! ** Links mentioned on the show […]

The post Web3 and the Decentralized Internet appeared first on The Shared Security Show.

View Details

In our last weekly episode of the year, we discuss the top cybersecurity and privacy news from 2021, a recap of our previous “predictions”, and what we think we’ll see next year. Happy New Year! Links mentioned on the show Sign up for the Shared Security Show Newsletter http://eepurl.com/dwcc8D ** Watch this episode […]

The post The Year in Review and 2022 Predictions appeared first on The Shared Security Show.

View Details

This week we discuss the Apache Log4j vulnerability and the impact it will have on organizations now and into the future, details on how Apple AirTags are being used by thieves to steal cars, and a FBI training document describes what data can be obtained by encrypted messaging apps. ** Links mentioned on the show […]

The post Log4j Vulnerability, Apple AirTags Used by Thieves, FBI’s Encrypted Messaging App Document appeared first on The Shared Security Show.

View Details

Life360, a popular family safety app used by 33 million people worldwide, is selling location data to a dozen data brokers, phones of 11 U.S. State Department employees were hacked with spyware from the infamous NSO Group, and details on a bizarre story about a mother and daughter that face 16 years in prison for […]

The post Life360 Selling Location Data, NSO Group Spyware Hacks Government Employees, Homecoming Queen Contest Hacked appeared first on The Shared Security Show.

View Details

This month we discuss Business Email Compromise (BEC) scams. What are they, how to identify them, and why BEC scams have created over $1.8 billion worth of losses to businesses last year alone. Links mentioned on the show What is Business Email Compromise? https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/business-email-compromise 64 times worse than ransomware? FBI statistics underline the […]

The post Business Email Compromise Scams appeared first on The Shared Security Show.

View Details

Is the TikTok app listening to you and playing videos based on your conversations? Apple takes the unique step of warning certain activists that their phones may be targeted by attackers, and details on how a UK government website was serving porn to its visitors. Links mentioned on the show Is TikTok listening […]

The post Is TikTok Listening to You, Apple Warns Activists, UK Government Website Shows Porn appeared first on The Shared Security Show.

View Details

Co-host Scott Wright joins Tom Eston for part three in our series on how to break into a cybersecurity career. Scott shares his career journey and gives us some insight into his career path going from consulting into starting his own company. If you’re a college student or thinking about getting into cybersecurity, this is […]

The post How to Break Into a Cybersecurity Career – Part 3 with Scott Wright appeared first on The Shared Security Show.

View Details

In milestone episode 200: The Federal Bureau of Investigation’s external email system was compromised sending spam emails with a fake warning of a cyber-attack, new research released about ransomware negotiation and some helpful negotiation tips, and details on Mozilla’s naughty list of privacy-crushing gifts. Links mentioned on the show FBI email system compromised […]

The post FBI Email System Compromised, Ransomware Negotiation, Privacy Crushing Gifts appeared first on The Shared Security Show.

View Details

Details on the Robinhood data breach (apparently caused by a social engineering attack) affecting approximately 7 million customers, and a discussion about surveillance and privacy concerns from a 600-hour leak of Dallas Police Department helicopter footage. Links mentioned on the show Robinhood Trading App Suffers Data Breach Exposing 7 Million Users’ Information https://thehackernews.com/2021/11/robinhood-trading-app-suffers-data.html […]

The post Robinhood Data Breach, 600 Hours of Dallas Police Helicopter Footage Leaked appeared first on The Shared Security Show.

View Details

Facebook shuts down their face recognition system and deletes more than a billion facial recognition templates, how phone bots are being used to trick victims into giving up their multi-factor authentication codes, and the US blacklists the NSO Group and 3 other companies for malicious cyber activities. Links mentioned on the show Face […]

The post Facebook Dumps Face Recognition, Social Engineering Bots, US Sanctions NSO Group appeared first on The Shared Security Show.

View Details

Dana Mantilia joins us this month to talk about cybersecurity awareness, her incredible YouTube channel, and the ever changing role of the CISO (Chief Information Security Officer). Links mentioned on the show Connect with Dana and subscribe to her YouTube Channel https://www.linkedin.com/in/dana-mantilia/ https://www.youtube.com/c/IdentityProtectionPlanningwithDana/videos Watch this episode on YouTube https://youtu.be/AWc5g2FAwMM ** Thank […]

The post Interview with Dana Mantilia and the Role of the CISO appeared first on The Shared Security Show.

View Details

Do we really need a federal data agency to regulate social media companies? Watch out for Squirrelwaffle and Qakbot malspam attacks, and ransomware hits a major candymaker ahead of Halloween (is nothing sacred anymore?!) Links mentioned on the show Facebook and social media endanger Americans. We need a federal data agency. https://www.nbcnews.com/think/politics-policy/facebook-rcna3704 Hackers […]

The post Federal Data Agency for Social Media, Squirrelwaffle Malspam, Ransomware Hits U.S. Candymaker appeared first on The Shared Security Show.

View Details

Details on the F12 “hacking” incident of the Missouri state education website and the foolish response from the Missouri governor, Over 30 countries (except China and Russia) meet to fight ransomware globally, and the FBI’s warning about fake unemployment benefit websites. Links mentioned on the show Gov. Parson promises ‘swift justice’ to person […]

The post Missouri Governor and F12 Hacking, Global Ransomware Meeting, Fake Government Websites appeared first on The Shared Security Show.

View Details

Clickbait news about the rise of “killware”, Details on 1Password’s new feature to securely share passwords with others, and a new study by university researchers in the UK shows how Android phones snoop on their users. Links mentioned on the show The next big cyberthreat isn’t ransomware. It’s killware. And it’s just as […]

The post Killware Clickbait, 1Password Password Sharing Feature, Android Phone Snooping appeared first on The Shared Security Show.

View Details

Co-host Scott Wright presents a new framework to help people to become “security champions” in their organization, a discussion about the great Facebook outage of 2021, and details on the Twitch data breach exposing source code and creator payouts. Links mentioned on the show Scott’s Security Champions Webinar https://youtu.be/WH65jch9DKI What Happened to Facebook, […]

The post Security Champions Framework, The Great Facebook Outage, Twitch Data Breach appeared first on The Shared Security Show.

View Details

Will Apple AirTag’s replace malicious payload USB drops? Details on Private Relay and Hide My Email features included with iCloud+, and a fun discussion about Amazon’s Astro robot and the Ring camera drone! Links mentioned on the show Apple AirTag Bug Enables ‘Good Samaritan’ Attack https://krebsonsecurity.com/2021/09/apple-airtag-bug-enables-good-samaritan-attack/ What Is Apple iCloud+? https://www.howtogeek.com/732978/what-is-apple-icloud/ Apple’s New […]

The post Apple AirTag Good Samaritan Attack, iCloud+, Amazon Astro Dog and Ring Camera Drone appeared first on The Shared Security Show.

View Details

October is Cybersecurity Awareness Month so in this episode we discuss multi-factor authentication and the use of authenticator apps. Multi-factor authentication is one of the most important things that you can enable to secure your online accounts but its unfortunately overlooked by most people. Listen to this episode to learn what multi-factor authentication is, all […]

The post Multi-Factor Authentication and Authenticator Apps appeared first on The Shared Security Show.

View Details

Microsoft will now allow you to login to your accounts without a password, Facebook releases its Ray-Ban Stories smart glasses, and a conversation about the security.txt “Internet standard” and if this will help or hinder a organization’s vulnerability disclosure process. Links mentioned on the show You Can Now Sign-in to Your Microsoft Accounts […]

The post No Password Microsoft Accounts, Facebook Smart Glasses, Security.txt Internet Standard appeared first on The Shared Security Show.

View Details

The latest on the iMessage Zero-Click exploit that affects Apple iOS, MacOS and WatchOS devices (update your Apple devices now!), the names and home addresses of 111,000 British firearm owners have been dumped online, and details on over 60 million fitness tracking records exposed via an unsecured database. Links mentioned on the show […]

The post iMessage Zero-Click Exploit, Leaked Guntrader Firearms Data, 60 Million Fitness Tracking Records Exposed appeared first on The Shared Security Show.

View Details

Details on the controversy over encrypted email service ProtonMail handing over a user’s IP address to the Swiss police, how a fake bot disinformation campaign went viral on Twitter, and are we ready to welcome our correctional facility robot overlords? Links mentioned on the show ProtonMail deletes ‘we don’t log your IP’ boast […]

The post ProtonMail IP Address Logging Controversy, Fake Bot Disinformation, Correctional Facility Robot Overlords appeared first on The Shared Security Show.

View Details

This week Rafal Los, host of the Down the Security Rabbithole Podcast, joins us to talk about election fraud claims vs facts, the recent packet capture controversy, tribalism, and the challenges with election security. Note: this is not a political discussion but we believe that election security is important to discuss, no matter what your […]

The post Election Security and the Packet Capture Controversy with Special Guest Rafal Los appeared first on The Shared Security Show.

View Details

In our August monthly show co-hosts Kevin Johnson and Scott Wright join Tom Eston to discuss what happens to your social media accounts…after you die! This is a topic we don’t hear a lot of discussion about but is very important to understand for your legacy as well as how your friends and family members […]

The post What Happens to Your Social Media Accounts After You Die? appeared first on The Shared Security Show.

View Details

A 21-year-old Virginia native living in Turkey is allegedly behind the massive T-Mobile hack, China adopts a new national privacy law, and is Elon Musk’s Tesla Bot just creepy or is it the beginning of “useful AI” that people love and is “unequivocally good”. Links mentioned on the show 21-year-old tells WSJ he […]

The post T-Mobile Hacker Identified, China’s New Privacy Law, Tesla Bot Announcement appeared first on The Shared Security Show.

View Details

T-Mobile suffers another data breach this time impacting 8 million customers, Tinder will start letting users verify their identity to help prevent “catfishing”, and Mastercard is finally phasing out magnetic stripes on their cards starting in 2024. Links mentioned on the show T-Mobile says information of more than 8 million customers leaked in […]

The post T-Mobile Data Breach, Tinder Identity Verification, Magnetic Stripe Phase Out appeared first on The Shared Security Show.

View Details

Over $600 million stolen in the largest DeFi cryptocurrency hack in history, attackers are getting around $10k for stolen network access credentials, and why your identity is trapped inside a social network and what this means for the next potential evolution of the Internet…the metaverse! Links mentioned on the show Apple to refuse […]

The post Largest Cryptocurrency Hack in History, $10k For Stolen Network Access, Your Identity and the Metaverse appeared first on The Shared Security Show.

View Details

CISA announces the new Joint Cyber Defense Collaborative (JCDC), the controversy over Apple scanning devices for child sexual abuse material, and Amazon offers you a $10 credit if you enroll your biometric data in their palm print recognition system. Links mentioned on the show CISA to partner with Amazon, Google, Microsoft, Verizon, AT&T […]

The post CISA JCDC Announcement, Apple’s Child Abuse Image Scanning, Amazon Pays You for Your Biometric Data appeared first on The Shared Security Show.

View Details

Why rebooting your smartphone is good security hygiene, the FBI reveals top targeted vulnerabilities in the last two years, and details on how a nation state used a “flirty” aerobics instructor to steal data from defense contractors. Links mentioned on the show Turn off, turn on: Simple step can thwart top phone hackers […]

The post Reboot Your Smartphone, FBI’s Top Targeted Vulnerabilities, Flirty Account Dupes Defense Contractors appeared first on The Shared Security Show.

View Details

In our July monthly show we discuss gift card scams! What are the different scams that are out there, how do they work, and details on how to protect yourself from becoming a victim. Links mentioned on the show 8 Gift Card SCAMS you can SPOT and EASILY AVOID! https://www.giftcards.com/gcgf/giftcard-scams ** Watch this […]

The post How to Protect Yourself from Gift Card Scams appeared first on The Shared Security Show.

View Details

Pegasus spyware and NSO Group are back in the news because of a data leak of 50,000 phone numbers, another “hacker” was arrested for the great Twitter hack of 2020, and how a 16-year-old printer vulnerability is affecting millions of HP, Samsung, and Xerox printers. Links mentioned on the show New Leak Reveals […]

The post Pegasus Spyware is Back, Twitter Hacker Arrested, 16-Year-Old Printer Bug appeared first on The Shared Security Show.

View Details

In this sponsored episode from our friends at ClearVPN, Artem Risukhin Content Marketing Manager at ClearVPN, joins co-host Tom Eston to discuss the most popular myths about VPNs. Be sure to watch the YouTube edition for a demo of ClearVPN and don’t forget to use discount code “SHAREDSECURITY” to take 40% off your purchase of […]

The post Popular Myths about VPNs appeared first on The Shared Security Show.

View Details

Is dream hacking the next big privacy concern or just a new marketing gimmick? Some people may be surprised that TikTok shares data with China, and details on Google Chrome adding HTTPS-first mode and Firefox easing its blocking of Facebook login buttons. Links mentioned on the show Nightmare scenario: alarm as advertisers seek […]

The post Targeted Dream Incubation, TikTok Data Sharing, Chrome and Firefox Updates appeared first on The Shared Security Show.

View Details

Details on the Kaseya supply-chain and REvil ransomware attack, a new zero-day exploit called “PrintNightmare” affects all Windows versions before June, and how randomly generated passwords in a popular password manager were not so random. Links mentioned on the show REvil Used 0-Day in Kaseya Ransomware Attack, Demands $70 Million Ransom https://thehackernews.com/2021/07/revil-used-0-day-in-kaseya-ransomware.html https://grahamcluley.com/revil-ransomware-rampages-following-kaseya-supply-chain-attack/ […]

The post Kaseya Ransomware Attack, PrintNightmare Zero-day, Kaspersky Password Manager Vulnerability appeared first on The Shared Security Show.

View Details

Was there another LinkedIn “data leak” or is this just the same data anyone with a LinkedIn account can access? Western Digital Network-Attached Storage (NAS) devices under attack, and details on the STIR/SHAKEN deadline which is supposed to help stop robocalls. Links mentioned on the show New LinkedIn Data Leak Leaves 700 Million […]

The post LinkedIn Data Leak, Western Digital NAS Attacks, STIR/SHAKEN Deadline appeared first on The Shared Security Show.

View Details

Chris Kirsch co-founder and chief revenue officer at Rumble joins us in our June monthly show to talk about how Rumble is solving the problem of asset discovery. You also get to see a demo of Rumble in action and learn about the many talents that Chris has like pickpocketing! ** Links mentioned on the […]

The post Asset Discovery with Chris Kirsch Co-Founder at Rumble appeared first on The Shared Security Show.

View Details

What does it really mean when Biden tells Putin critical US infrastructure is “off limits”, details on a recent survey which shows ransomware payments create repeat attacks, and how cyber safe is your drinking water? Links mentioned on the show Biden Tells Putin Critical Infrastructure Sectors ‘Off Limits’ to Russian Hacking https://beta.darkreading.com/threat-intelligence/biden-tells-putin-critical-infrastructure-sectors-off-limits-to-russian-hacking Ransomware […]

The post Off Limits Critical Infrastructure, Ransomware on Repeat, Cyber Safe Drinking Water appeared first on The Shared Security Show.

View Details

TikTok can now collect biometric data from user content, researchers find a vulnerability in Peloton bikes, and why some people think that Nextdoor might be the next big social network. Links mentioned on the show TikTok Can Now Collect Biometric Data https://www.schneier.com/blog/archives/2021/06/tiktok-can-now-collect-biometric-data.html McAfee discovers vulnerability in Peloton Bike+ https://www.zdnet.com/article/mcafee-discovers-vulnerability-in-peloton-bike Nextdoor: The next big […]

The post TikTok Collecting Biometric Data, Peloton Bike+ Vulnerability, Nextdoor App Concerns appeared first on The Shared Security Show.

View Details

Details about the “ANOM” global crime sting where the FBI created a fake encrypted mobile phone for criminals that promised secure communications, new details about how the Colonial Pipeline ransomware attack started, and some really bad security research about stolen user credentials. Links mentioned on the show Only the following devices have Amazon […]

The post ANOM FBI Global Crime Sting, Colonial Pipeline Updates, Password Leak Research appeared first on The Shared Security Show.

View Details

Is Amazon Sidewalk the latest threat to our privacy? Also, what’s the big deal about NFTs, and why mining cryptocurrency through your anti-virus software is a horrible idea. Links mentioned on the show What Does Amazon Sidewalk Mean for Your Privacy? https://www.makeuseof.com/what-does-amazon-sidewalk-mean-for-your-privacy/ https://thehackernews.com/2021/05/your-amazon-devices-to-automatically.html Note! Only the following devices have Amazon Sidewalk enabled (for […]

The post Amazon Sidewalk, NFTs and Cybersecurity, Norton 360 Cryptocurrency Mining appeared first on The Shared Security Show.

View Details

Details about Biden’s cybersecurity executive order, privacy and stalking concerns with Apple’s new AirTag technology, and why some cyber insurance companies may not pay out for ransomware in the future. Links mentioned on the show New Cybersecurity Executive Order: What You Need to Know https://www.veracode.com/blog/security-news/new-cybersecurity-executive-order-what-you-need-know How Apple’s AirTag turns us into unwitting spies […]

The post Biden’s Cybersecurity Executive Order, Apple’s AirTag, Cyber Insurance appeared first on The Shared Security Show.

View Details

Gamification is changing cybersecurity and the way we learn! Scott Wright, Co-host and CEO of Click Armor, joins us this month to discuss why gamification is a “game” changer in our industry. Links mentioned on the show What is Gamified Learning? https://clickarmor.ca/guide-to-gamified-learning/ Watch this episode on YouTube https://youtu.be/C37MnOUWsv0 ** Thank you […]

The post How Gamification is Changing Cybersecurity appeared first on The Shared Security Show.

View Details

More news and updates about the Colonial Pipeline ransomware attack, the DarkSide ransomware as a service (RaaS) goes dark on the dark web, and why we still need cybersecurity best practices (regardless of an opinion piece that says otherwise). Links mentioned on the show Colonial Pipeline Paid Nearly $5 Million in Ransom to […]

The post Colonial Pipeline Updates, DarkSide Goes Dark, Cybersecurity Best Practices appeared first on The Shared Security Show.

View Details

This week Tom and Kevin discuss the Colonial Pipeline ransomware attack, RaaS (Ransomware as a Service), and why ransomware attacks are not going away anytime soon. Links mentioned on the show Colonial Pipeline Hackers, DarkSide, Apologize, Say Goal ‘Is to Make Money’ https://www.msn.com/en-us/news/world/colonial-pipeline-hackers-darkside-apologize-say-goal-is-to-make-money/ar-BB1gBzhB Colonial Pipeline attack: Everything you need to know https://www.zdnet.com/article/everything-you-need-to-know-about-the-colonial-pipeline-ransomware-attack/ Ransomware […]

The post The Colonial Pipeline Ransomware Attack appeared first on The Shared Security Show.

View Details

Do we still need World Password Day? Hacking a Tesla via a drone, and a privacy warning about the Ipsos Screenwise panel. Links mentioned on the show World password day – May 6th https://www.darkreading.com/vulnerabilities—threats/will-2021-mark-the-end-of-world-password-day-/a/d-id/1340911 Tesla Car Hacked Remotely From Drone via Zero-Click Exploit https://www.securityweek.com/tesla-car-hacked-remotely-drone-zero-click-exploit What is this Ipsos/Google Screenwise Panel? (Tom received a […]

The post World Password Day, Tesla Hacking via Drone, Ipsos Screenwise Panel appeared first on The Shared Security Show.

View Details

Remembering Dan Kaminsky who was one of the greatest security researchers of our time plus details on a new Apple Airdrop vulnerability. Links mentioned on the show Remembering Dan Kaminsky https://www.nytimes.com/2021/04/27/technology/daniel-kaminsky-dead.html Apple AirDrop Bug Could Leak Your Personal Info to Anyone Nearby https://thehackernews.com/2021/04/apple-airdrop-bug-could-leak-your.html https://www.komando.com/security-privacy/apple-airdrop-security-flaw/787628/ Watch this episode on YouTube https://youtu.be/N6T6qcRfTBA ** […]

The post Remembering Dan Kaminsky, Apple AirDrop Vulnerability appeared first on The Shared Security Show.

View Details

Are you investing in cryptocurrency or thinking about it? Be sure to listen or watch our April monthly show for our top 3 ways to keep your cryptocurrency safe! Links mentioned on the show 10 Ways to Keep Your Cryptocurrency Safe https://money.usnews.com/investing/cryptocurrency/slideshows/ways-to-keep-your-cryptocurrency-safe Beware of These Top Bitcoin Scams https://www.investopedia.com/articles/forex/042315/beware-these-five-bitcoin-scams.asp 9 Best Crypto Wallets […]

The post 3 Ways to Keep Your Cryptocurrency Safe appeared first on The Shared Security Show.

View Details

Instagram is rolling out new features to help block spam and abusive messages, Apple releases iOS 14.5 to restrict tracking by advertisers, and a discussion about why people continue to choose terrible passwords. Links mentioned on the show Instagram debuts new tool to stop abusive message salvos made through new accounts https://www.zdnet.com/article/instagram-debuts-new-means-to-stop-senders-of-abusive-messages-contacting-you-through-new-accounts/ Apple […]

The post Instagram Anti-Abuse Tool, Apple Advertiser Restrictions, Terrible Passwords appeared first on The Shared Security Show.

View Details

This week Tom and Kevin are back with an all new episode! Data breaches vs. recent data leaks, and the controversy over the FBI operation conducted to remove web shells from compromised Microsoft Exchange servers. Links mentioned on the show Facebook Data Breach: Here’s What To Do Now https://www.forbes.com/sites/kateoflahertyuk/2021/04/06/facebook-data-breach-heres-what-to-do-now/?sh=32c7c9235708 LinkedIn says some user […]

The post Data Breaches vs. Data Leaks, FBI Exchange Server Controversy appeared first on The Shared Security Show.

View Details

This week is another best of episode with the man, the myth, the legend, Jayson E. Street! In this episode Jayson shares with us several of his greatest hacking and social engineering adventures. This is one classic episode you don’t want to miss! Links mentioned on the show Follow Jayson on Twitter https://twitter.com/jaysonstreet […]

The post Best of Episode: Interview with Jayson E. Street appeared first on The Shared Security Show.

View Details

This week is a best of episode with special guest Rachel Tobac, CEO of Social Proof Security. In this episode we discuss social engineering, how to get more women in cybersecurity, and of course Rachel’s favorite David Lynch movies. This is one previous episode you don’t want to miss! ** Links mentioned on the show […]

The post Best of Episode: Interview with Rachel Tobac appeared first on The Shared Security Show.

View Details

Is it time to finally move away from SMS text based two-factor authentication? Plus a discussion about a new model that can help consumers with improving their Internet hygiene. Links mentioned on the show Can We Stop Pretending SMS Is Secure Now? https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/ The Consumer Authentication Strength Maturity Model (CASMM) https://danielmiessler.com/blog/casmm-consumer-authentication-security-maturity-model/ Tom Eston’s […]

The post SMS Two-Factor Authentication, New Internet Hygiene Model appeared first on The Shared Security Show.

View Details

This week, co-host Tom Eston shares his top 3 tips to stay more private when you travel this year on vacation. Links mentioned on the show Smartphone privacy screens (Amazon) https://www.amazon.com/s?k=smartphone+privacy+screen&ref=nb_sb_noss_1 Laptop privacy screens (Amazon) https://www.amazon.com/s?k=laptop+privacy+screen&ref=nb_sb_noss_2 Watch this episode on YouTube https://youtu.be/2izHDB80qgA Thank you to our sponsors! Silent Pocket […]

The post Top 3 Privacy Tips for Travel appeared first on The Shared Security Show.

View Details

Scott and Kevin finally get together to debate Facebook and Apple privacy, and why you shouldn’t conduct a phishing test to trick employees into thinking they will get free Covid-19 vaccines. Links mentioned on the show Apple CEO sounds warning of algorithms pushing society towards catastrophe https://www.zdnet.com/article/apple-ceo-sounds-warning-of-algorithms-pushing-society-towards-catastrophe/ https://clickarmor.ca/2021/02/is-this-the-beginning-of-the-end-for-facebook/ Internal Memo: ICF Next Used […]

The post Facebook and Apple Privacy Debate, Employee Phishing Test Gone Wrong appeared first on The Shared Security Show.

View Details

Why is federal law enforcement (still) asking Congress for encryption backdoors? Attacks on Microsoft Exchange servers seem to have gotten worse, details on an airline supplier data breach, and the real reason Kevin hasn’t replaced his Chewbacca mannequin with Darth Vader! Links mentioned on the show The FBI Should Stop Attacking Encryption and […]

The post Encryption Backdoor Debate, Microsoft Exchange Attacks, Airline Supplier Data Breach appeared first on The Shared Security Show.

View Details

Deepfake video and audio has really advanced in recent years. Will this technology start to erode trust in the media we consume? Microsoft Exchange zero-days in the wild, and why is it that IT security investment on cybersecurity is at an all time high, yet we continue to see more data breaches? ** Links mentioned […]

The post The Deepfake Dilemma, Microsoft Exchange Zero-Days, IT Security Investments appeared first on The Shared Security Show.

View Details

This week co-host Kevin Johnson joins Tom Eston to discuss new card skimmers found in the wild, the Accellion zero-days, and a new type of Mac malware called “Silver Sparrow”. Links mentioned on the show Checkout Skimmers Powered by Chip Cards https://krebsonsecurity.com/2021/02/checkout-skimmers-powered-by-chip-cards/ Apple says it has already beaten new M1 Mac malware https://www.techradar.com/au/news/apple-says-it-has-already-beaten-new-m1-mac-malware […]

The post Card Skimmers Powered by Chip Cards, Silver Sparrow Mac Malware, Accellion Zero-Days appeared first on The Shared Security Show.

View Details

Everyone is talking about the Clubhouse app but what should you be concerned about from a privacy perspective? In our February monthly show, Tom and Scott discuss what all the hype is about and what you need to know if you happen to receive a Clubhouse invite! Links mentioned on the show Join […]

The post Clubhouse App and Your Privacy appeared first on The Shared Security Show.

View Details

In episode 161: Apple will start to proxy Safe Browsing requests to hide IP addresses from Google, the rise of Business Email Compromise attacks, and changes to the free version of LastPass. Links mentioned on the show Apple will proxy Safe Browsing requests to hide iOS users’ IP from Google https://thehackernews.com/2021/02/apple-will-proxy-safe-browsing-requests.html This cybersecurity […]

The post Apple’s Safe Browsing Request Proxy, BEC Attacks, LastPass Updates appeared first on The Shared Security Show.

View Details

In episode 160: An attacker tried to poison a Florida city’s water supply, a popular Android app was hacked to display malicious ads, and how smartphone location data was used to track the US Capitol rioters. Links mentioned on the show A Hacker Tried to Poison a Florida City’s Water Supply, Officials Say […]

The post Florida Water Supply Hack, Android App Hijack, US Capitol Riot Phone Tracking appeared first on The Shared Security Show.

View Details

In episode 159: Will algorithms be the death of social media and why the US government thinks it has a moral imperative to build AI powered weapons. Links mentioned on the show US has ‘moral imperative’ to develop AI weapons, says panel https://www.theguardian.com/science/2021/jan/26/us-has-moral-imperative-to-develop-ai-weapons-says-panel Apple CEO sounds warning of algorithms pushing society towards catastrophe […]

The post Dangerous Social Media Algorithms, A Moral Imperative for AI Powered Weapons? appeared first on The Shared Security Show.

View Details

In episode 158: Cybersecurity researchers targeted by North Korean hackers, Apple patches three iOS zero-day exploits, and details on Google’s Federated Learning of Cohorts (FLoC) which may one day replace third-party cookie tracking. Links mentioned on the show Check out these recent popular episodes! https://sharedsecurity.net/2021/01/28/tanya-janca-ceo-and-founder-we-hack-purple/ https://sharedsecurity.net/2021/01/18/the-capital-riot-first-amendment-and-deplatforming-cybersecurity-lessons-learned/ New campaign targeting security researchers https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/ Apple […]

The post Cybersecurity Researchers Targeted, Three iOS Zero-Days, Google FLoC appeared first on The Shared Security Show.

View Details

Tanya Janca, CEO and founder of We Hack Purple joins us to discuss her new book “Alice & Bob Learn Application Security”, what inspired her to write the book, the current and future state of Application Security and much more! If you’re a fan of Tanya’s work, this is one episode you don’t want to […]

The post Tanya Janca CEO and Founder We Hack Purple appeared first on The Shared Security Show.

View Details

Is the world really ready for COVID-19 vaccination passport apps? Also, the partial return of Parler, details on Nancy Pelosi’s stolen laptop, the Ubiquiti data breach, Ring end-to-end encryption for video, and other important cybersecurity and privacy news from the week. Links mentioned on the show Parler Partially Reappears With Support From Russian […]

The post Parler, Pelosi’s Stolen Laptop, Vaccination Passport Apps appeared first on The Shared Security Show.

View Details

This week co-host Kevin Johnson joins me to discuss the cybersecurity lessons learned from the US Capital riot, why deplatforming is not violating first amendment rights, and much more. Links mentioned on the show Check out our series on how to break into a cybersecurity career https://sharedsecurity.net/2021/01/04/how-to-break-into-to-a-cybersecurity-career-part-1/ https://sharedsecurity.net/2021/01/11/how-to-break-into-a-cybersecurity-career-part-2-with-rafal-los/ What the First Amendment actually […]

The post The Capital Riot: First Amendment and Deplatforming, Cybersecurity Lessons Learned appeared first on The Shared Security Show.

View Details

Rafal Los, industry veteran and host of the “Down the Security Rabbithole Podcast”, joins Tom Eston for part two in our series on how to break into a cybersecurity career. If you’re a college student or thinking about getting into cybersecurity, this is one episode you don’t want to miss! ** Links mentioned on the […]

The post How to Break Into a Cybersecurity Career – Part 2 with Rafal Los appeared first on The Shared Security Show.

View Details

In episode 154 for January 4th 2021: Are you a college student, or someone that has an interest in a cybersecurity career? Check out the first episode in our series on how to break into a cybersecurity career with co-host Kevin Johnson. Links mentioned on the show So, you want to work in […]

The post How to Break Into a Cybersecurity Career – Part 1 appeared first on The Shared Security Show.

View Details

In episode 153 for December 28th 2020: In our last episode of the year co-host Tom Eston talks about his top 3 tips to keep you cybersecure in 2021. Thank you for listening, watching us on YouTube, and supporting our show and sponsors this year. We wish you and your family a new year that’s […]

The post Top 3 Cybersecurity Tips appeared first on The Shared Security Show.

View Details

Our last episode of the year is our always entertaining year in review and 2021 predictions with co-hosts Scott Wright and Kevin Johnson. Thank you for listening and supporting the show in 2020! Links mentioned on the show Check out our year in review and 2020 predictions recorded around the same time last […]

The post The Year in Review and 2021 Predictions appeared first on The Shared Security Show.

View Details

In episode 152 for December 21st 2020: A discussion about the SolarWinds Orion backdoor, third-party security, and the threat of supply chain attacks with co-host Kevin Johnson. Links mentioned on the show US govt, FireEye breached after SolarWinds supply-chain attack https://www.bleepingcomputer.com/news/security/us-govt-fireeye-breached-after-solarwinds-supply-chain-attack/ https://savebreach.com/solarwinds-credentials-exposure-led-to-us-government-fireye-breach/ https://www.zdnet.com/article/sec-filings-solarwinds-says-18000-customers-are-impacted-by-recent-hack/ What We Know (And Don’t) About The SolarWinds Orion Hack […]

The post SolarWinds/SUNBURST Backdoor, Third-Party and Supply Chain Security appeared first on The Shared Security Show.

View Details

In episode 151 for December 14th 2020: What you need to know about the stolen FireEye “Red Team” tools and the FUD going on in the media about the attack, Foxconn gets hit with a ransomware attack plus details on how ransomware attacks are evolving, and how Apple is stopping advertisers from tracking you across […]

The post FireEye Hacked, Foxconn Ransomware Attack, Apple’s New Privacy Features appeared first on The Shared Security Show.

View Details

In episode 150 for December 7th 2020: Details about a now patched iPhone zero-click Wi-Fi exploit, the FBI warns of business email compromise scammers using email auto-forwarding in attacks, and how nation-state attackers are targeting the COVID-19 vaccine supply ‘cold chain’. Links mentioned on the show Google Hacker Details Zero-Click ‘Wormable’ Wi-Fi Exploit […]

The post iPhone Zero-Click Exploit, BEC Email Auto-Forward Scams, COVID-19 Vaccine Cold Chain Attacks appeared first on The Shared Security Show.

View Details

In our November monthly episode we discuss the scams that you may encounter this holiday shopping season due to the pandemic and our top tips on how to stay safe and more secure when doing your shopping this year. Links mentioned on the show Digital Safety in the New Normal: Holiday Edition https://www.ibtimes.com/digital-safety-new-normal-holiday-edition-3087840 […]

The post Holiday Shopping Scams and Tips to Stay Safe appeared first on The Shared Security Show.

View Details

In episode 149 for November 30th 2020: Police begin to pilot a program to live-stream Amazon Ring cameras, new details about Amazon Sidewalk, Congress unanimously passes a federal Internet of Things security law, and a Facebook Messenger bug that lets an attacker listen to you before you pick up a call. ** Links mentioned on […]

The post Amazon Sidewalk, Federal IoT Security Law, Facebook Messenger Bug appeared first on The Shared Security Show.

View Details

In episode 148 for November 23rd 2020: This week Kevin Johnson joins me to discuss the Twitter firing of Chris Krebs, Director of the Cybersecurity and Infrastructure Security Agency, and our thoughts about a common sense approach to social media and Section 230 of the Communications Decency Act. Links mentioned on the show […]

The post CISA Director Chris Krebs Fired, Common Sense and Section 230 appeared first on The Shared Security Show.

View Details

In episode 147 for November 16th 2020: The latest about source code stolen from US government agencies and private companies, three actively exploited iOS zero-days in the wild and new App Store privacy labels, and what a Biden administration could mean for privacy and cybersecurity. Links mentioned on the show Our 3 part […]

The post Stolen Source Code, Apple Zero-Days, Biden’s Privacy and Cybersecurity Policies appeared first on The Shared Security Show.

View Details

In episode 146 for November 9th 2020: My conversation with Kelly Finnerty, Director of Brand and Content for Startpage.com on the differences in privacy mindset between Europe and the United States. Links mentioned on the show Future of Privacy Forum https://fpf.org/ Startpage.com https://www.startpage.com StartPage Privacy Please Blog https://www.startpage.com/privacy-please/ Follow Kelly on Twitter https://twitter.com/Kelly_Startpage […]

The post Privacy Mindset: Europe vs. United States appeared first on The Shared Security Show.

View Details

In episode 145 for November 2nd 2020: Kevin Johnson joins me to discuss the US government’s attempt to prevent disinformation and rumors about the election, a new ransomware threat targeting US hospitals, and details about six Russian hackers that were charged for some of the biggest cyber-attacks in the last decade. ** Links mentioned on […]

The post Government Rumor Control, US Hospital Ransomware Threat, Russian Hackers Charged appeared first on The Shared Security Show.

View Details

In our October monthly episode we finish our three part series on targeted attacks. In this episode we discuss the exploit and malware analysis with special guest Tyler Hudak, Incident Response Practice Lead at TrustedSec. Make sure you watch the YouTube edition of this episode to see a demo of several tools and techniques used […]

The post Targeted Attacks Part 3 – The Exploit appeared first on The Shared Security Show.

View Details

In episode 144 for October 26th 2020: Voter privacy and what you need to know about protecting your private information during the upcoming US election. Links mentioned on the show Closing in on the US election with voter privacy and election security https://iapp.org/news/a/closing-in-on-the-u-s-election-with-voter-privacy-and-election-security/ Access To and Use Of Voter Registration Lists https://www.ncsl.org/research/elections-and-campaigns/access-to-and-use-of-voter-registration-lists.aspx Understanding […]

The post Voter Privacy and the US Election appeared first on The Shared Security Show.

View Details

In episode 143 for October 19th 2020: Microsoft gets creative to help take down the TrickBot botnet, details on how attackers have been using VPN flaws to attack election support systems, and Zoom’s rollout of end-to-end encryption. Links mentioned on the show “The Social Dilemma” A Conversation about the Pros and Cons of […]

The post TrickBot Takedown, VPN Flaws, Zoom End-to-End Encryption appeared first on The Shared Security Show.

View Details

In episode 142 for October 12th 2020: My conversation about the pros and cons of the Netflix documentary “The Social Dilemma” with frequent guest, Kevin Johnson. The Social Dilemma is a popular documentary (dramamentary?) on Netflix about how social media is causing unintended harm to people and society. Several engineers and leaders that worked at […]

The post The Social Dilemma appeared first on The Shared Security Show.

View Details

In episode 141 for October 5th 2020: Universal Health Services is the latest victim of a massive hospital ransomware attack, the FBI issues new warnings about false claims of hacked voter information, and the top Android 11 privacy and security features. Links mentioned on the show Large US hospital chain hobbled by Ryuk […]

The post More Hospital Ransomware Attacks, FBI’s Disinformation Warning, Android 11 Privacy Features appeared first on The Shared Security Show.

View Details

In our September monthly episode we continue our three part series on targeted attacks. In this episode we discuss the pretext and how attackers develop and launch their attacks with special guests Nathan Sweaney, Senior Security Consultant at Secure Ideas and Kevin Johnson, CEO of Secure Ideas. Links mentioned on the show GoPhish […]

The post Targeted Attacks Part 2 – Pretexting and Attack Development appeared first on The Shared Security Show.

View Details

In episode 140 for September 28th 2020: Details on the first human death related to a ransomware attack, popular fitness app Strava is caught giving away your location data to strangers, and the top privacy improvements in Apple iOS 14. Links mentioned on the show A Patient Dies After Ransomware Attack Paralyzes German […]

The post Death by Ransomware, Strava Flyby, iOS 14 Privacy Improvements appeared first on The Shared Security Show.

View Details

In episode 139 for September 21st 2020: This week we take a break from the news to bring you our interview with Alex Kubiak, Senior Product Manager at StartPage.com. StartPage is a privacy focused search engine which uses Google’s search results but removes all trackers and logs. This makes StartPage very different than other privacy […]

The post StartPage.com – The World’s Most Private Search Engine appeared first on The Shared Security Show.

View Details

In episode 138 for September 14th 2020: School districts under cyber-attack, Google Chrome’s new ad blocking feature, and Microsoft’s latest alert about foreign interference in the 2020 US election. Links mentioned on the show City of Hartford postpones first day of school after ransomware attack https://www.zdnet.com/article/city-of-hartford-postpones-first-day-of-school-after-ransomware-attack/ Hackers shutdown first day of Toledo Public […]

The post Schools Under Cyberattack, Chrome Ad Blocking Update, US Election Interference appeared first on The Shared Security Show.

View Details

In episode 137 for September 7th 2020: A federal appeals court finds the NSA’s bulk collection of phone data was unlawful, new research shows that browsing histories are unique enough to reliably identify users, and my personal story about a car accident and the privacy of your public records. ** Links mentioned on the show […]

The post NSA Data Collection Ruling, Browsing History Identification, Ambulance Chasing appeared first on The Shared Security Show.

View Details

In our August monthly episode we start our three part series on targeted attacks. In this episode we focus on OSINT (Open Source Intelligence) and reconnaissance techniques used by attackers in phishing and BEC (Business Email Compromise) attacks. Kyle Lovett, Principal Penetration Tester at Veracode, joins us to demonstrate some of the tools and techniques […]

The post Targeted Attacks Part 1 – OSINT and Reconnaissance appeared first on The Shared Security Show.

View Details

In episode 136 for August 31st 2020: Uber’s former security chief is charged over covering up a 2016 data breach, Facebook pushes for data portability legislation, and how a malicious iOS SDK breached the privacy of millions of mobile users. Links mentioned on the show Former Uber Security Chief Charged Over Covering Up […]

The post Uber CISO Charged, Facebook Data Portability, Malicious iOS SDK appeared first on The Shared Security Show.

View Details

In episode 135 for August 24th 2020: Details on how researchers can use audio recordings of keys being used in locks to create copies, Carnival cruise lines becomes the victim of a ransomware attack, and a data broker exposes nearly 235 million profiles scraped from social media sites. Links mentioned on the show […]

The post Audio Recordings Used to Copy Keys, Carnival Ransomware Attack, Social Media Profile Data Exposed appeared first on The Shared Security Show.

View Details

In episode 134 for August 17th 2020: Details on new critical vulnerabilities found in Amazon Echo devices, what the end of the Privacy Shield framework means EU citizens personal data, and new data breach fines issued to Capital One and Twitter by the OCC and FTC. Links mentioned on the show Keeping the […]

The post Amazon Echo Exploit, Privacy Shield, Capital One Data Breach Update appeared first on The Shared Security Show.

View Details

In episode 133 for August 10th 2020: What we can learn from the big Twitter hack, why everyone is trying to ban TikTok, and pharmacy chain Rite Aid’s use of facial recognition cameras. Links mentioned on the show How the FBI tracked down the Twitter hackers https://blog.twitter.com/en_us/topics/company/2020/an-update-on-our-security-incident.html https://www.zdnet.com/article/how-the-fbi-tracked-down-the-twitter-hackers/ Call for TikTok security check […]

The post Twitter Hack Lessons Learned, TikTok Ban, Rite Aid Facial Recognition Cameras appeared first on The Shared Security Show.

View Details

In episode 132 for August 3rd 2020: How the big tech companies like Google, Apple, Facebook, and Twitter collect your private data and how you can delete it with Kira Rakova from Undatify. Links mentioned on the show Find out more about Undatify https://undatify.me/ https://www.instagram.com/undatifyme/ The Step-by-Step Guide to Erasing Your Entire Google […]

The post How Big Tech Collects Your Private Data and How to Delete It appeared first on The Shared Security Show.

View Details

In episode 131 for July 27th 2020: The FBI charges two Chinese hackers for one of the largest Chinese directed hacking campaigns ever discovered, how the BadPower fast charger attack could melt or set your devices on fire, and details on a massive leak of Instacart customer information. Links mentioned on the show […]

The post Chinese Hacking Campaign Exposed, BadPower Fast Charger Attack, Instacart Data Leak appeared first on The Shared Security Show.

View Details

In episode 102 of our July monthly show Scott and Tom walk-through the recommended privacy settings for Amazon Echo and Google Home smart speakers. Links mentioned on the show 8 ways to protect your Amazon Echo privacy while working from home https://www.cnet.com/how-to/8-ways-to-protect-your-amazon-echo-privacy-while-working-from-home/ How To Make Your Amazon Echo and Google Home as Private […]

The post Privacy Settings for Amazon Echo and Google Home appeared first on The Shared Security Show.

View Details

In episode 130 for July 20th 2020: Details on the big Twitter hack which took over high-profile accounts, a major wormable critical vulnerability in Microsoft Windows DNS Server, and how email impersonation attacks take advantage of everyone working from home. Links mentioned on the show Twitter blames ‘coordinated’ attack on its systems for […]

The post The Big Twitter Hack, Critical Windows DNS Server Update, Email Impersonation Attacks appeared first on The Shared Security Show.

View Details

In episode 129 for July 13th 2020: Impact of the F5-BIG-IP critical vulnerability, security updates and your WiFi router, and details about new research that shows how billions of compromised credentials are available in the cyber underground. Links mentioned on the show Mitigating critical F5 BIG-IP RCE flaw not enough, bypass found https://www.bleepingcomputer.com/news/security/mitigating-critical-f5-big-ip-rce-flaw-not-enough-bypass-found/ […]

The post F5 BIG-IP Exploit, WiFi Router Security Updates, Password Reuse appeared first on The Shared Security Show.

View Details

In episode 128 for July 6th 2020: New TikTok privacy concerns, the rise of macOS ransomware, and details on new research about bad password choices. Links mentioned on the show Family Safety and Security with Andy Murphy from The Secure Dad Podcast https://sharedsecurity.net/2020/06/29/family-safety-and-security-with-andy-murphy-from-the-secure-dad-podcast EARN IT Act, Facial Recognition Fail, Can I Be Phished? […]

The post TikTok Privacy Concerns, macOS Ransomware, Bad Passwords appeared first on The Shared Security Show.

View Details

In episode 101 of our June monthly show: Scott and Tom discuss the privacy concerns with the EARN IT Act, more stories of facial recognition fail, and Scott talks about his new podcast, Can I Be Phished? Links mentioned on the show PETITION: Nearly 500,000 say Congress shouldn’t ‘kill encryption’ with the EARN […]

The post EARN IT Act, Facial Recognition Fail, Can I Be Phished? appeared first on The Shared Security Show.

View Details

In episode 127 for June 29th 2020: Family safety and security with special guest Andy Murphy host of The Secure Dad podcast. I really enjoyed this interview with Andy! If you’re looking for a podcast about home and family security, self-defense, and more you should definitely subscribe to his show! ** Links mentioned on the […]

The post Family Safety and Security with Andy Murphy from The Secure Dad Podcast appeared first on The Shared Security Show.

View Details

In episode 126 for June 22nd 2020: Details on the largest Distributed Denial of Service attack ever recorded, new security features in Dropbox, and the latest on new North Korean targeted cyber-attacks. Show notes and links mentioned on the show Zoom will provide end-to-end encryption to all users https://www.bleepingcomputer.com/news/security/zoom-will-provide-end-to-end-encryption-to-all-users/ AWS said it mitigated […]

The post Largest DDoS Attack Ever, New Dropbox Features, North Korean Cyber-Attacks appeared first on The Shared Security Show.

View Details

In episode 125 for June 15th 2020: Our top 5 tips for staying private and secure during a protest. Show notes and links mentioned on the show Privacy And Security While Protesting https://silent-pocket.com/blogs/news/privacy-and-security-while-protesting You Have a First Amendment Right to Record the Police https://www.eff.org/deeplinks/2020/06/you-have-first-amendment-right-record-police Protecting Your Privacy if Your Phone is Taken Away […]

The post 5 Tips to Stay Private and Secure During a Protest appeared first on The Shared Security Show.

View Details

In episode 124 for June 8th 2020: Details on how the Minneapolis Police website may have been hacked, Zoom’s plan to implement end-to-end encryption, and why eBay and other sites may be port scanning your computer. Show notes and links mentioned on the show After Anonymous Promises Retribution for George Floyd’s Death, Minneapolis […]

The post Minneapolis Police Website Hacked, Zoom Encryption, eBay Port Scanning appeared first on The Shared Security Show.

View Details

In episode 123 for June 1st 2020: The controversy continues over fact checking and First Amendment rights on Twitter, and why government mandated encryption backdoors are bad for everyone’s security. Show notes and links mentioned on the show Trump to sign executive order aimed at cracking down on Facebook and Twitter https://www.cnbc.com/2020/05/28/trump-to-sign-executive-order-aimed-at-cracking-down-on-facebook-twitter.html The […]

The post First Amendment Rights and Twitter, Encryption Backdoors appeared first on The Shared Security Show.

View Details

In episode 100 of our May monthly show we discuss the history of the podcast, some of the most interesting cybersecurity and privacy news and events over the years, and speak with former guest Rachel Tobac, CEO and Co-Founder of SocialProof Security, about what she’s been up to and of course the David Lynch daily […]

The post Episode 100 with Rachel Tobac and Kathleen Smith appeared first on The Shared Security Show.

View Details

In episode 122 for May 25th 2020: Apple and the US Government dispute over law enforcement backdoors in Apple products, secure messaging app Signal starts to move away from using phone numbers as user IDs, and details on the EasyJet data breach affecting 9 million customers. ** Show notes and links mentioned on the show […]

The post Apple’s Law Enforcement Backdoor Dispute, Signal PINs, EasyJet Data Breach appeared first on The Shared Security Show.

View Details

In episode 121 for May 18th 2020: A new Thunderbolt flaw could let hackers steal your data in under five minutes, new vulnerabilities in a popular WordPress plugin, and details on why the US Senate just rejected a plan to require a warrant to obtain Americans’ web browsing history. ** Show notes and links mentioned […]

The post Thunderbolt Flaws, WordPress Plugin Vulnerabilities, Patriot Act Vote appeared first on The Shared Security Show.

View Details

In episode 120 for May 11th 2020: The latest on the GoDaddy security incident affecting 28,000 customers, fake Microsoft Teams notification emails and Zoom downloaders, and details on new features to the Firefox built in password manager. Show notes and links mentioned on the show GoDaddy notifies users of breached hosting accounts https://www.bleepingcomputer.com/news/security/godaddy-notifies-users-of-breached-hosting-accounts/ […]

The post GoDaddy Security Incident, Fake Downloaders, Firefox Lockwise appeared first on The Shared Security Show.

View Details

In episode 119 for May 4th 2020: The use of thermal cameras and other technology to monitor the workplace for COVID-19, more details about Apple and Google’s contact tracing framework, and are virtual security conferences the new normal? Show notes and links mentioned on the show A new era of workplace surveillance due […]

The post Workplace Surveillance, Apple and Google Contact Tracing Tech, Virtual Cybersecurity Conferences appeared first on The Shared Security Show.

View Details

In episode 118 for April 27th 2020: A discussion about the end of passwords and what the future may hold with special guest Andrew Shikiar executive director of the FIDO Alliance. Show notes and links mentioned on the show Find out more about the FIDO Alliance https://fidoalliance.org/ https://twitter.com/fidoalliance How FIDO works and eliminates […]

The post The End of Passwords as We Know It appeared first on The Shared Security Show.

View Details

In episode 99 of our April monthly show: Apple and Google’s controversial efforts to create contact tracing technology, fighting COVID-19 criminal activity, and what the new normal means for startup companies. Show notes and links mentioned on the show Apple and Google to build contact tracing technology https://www.rte.ie/news/business/2020/0410/1129902-apple-and-google-to-build-contact-tracing-technology/ COVID-19 Cyber Threat Coalition https://www.cyberthreatcoalition.org/ […]

The post Contact Tracing Controversy, Fighting COVID-19 Criminal Activity appeared first on The Shared Security Show.

View Details

In episode 117 for April 20th 2020: More problems for Zoom with tens of thousands of compromised credentials and zero-day exploits, the $5 million dollar reward for information on North Korean hackers, and why it might not be the best idea to post your senior year pictures on Facebook. ** Show notes and links mentioned […]

The post Zoom Hacked Accounts, North Korean Hackers, Facebook Senior Pictures appeared first on The Shared Security Show.

View Details

In episode 116 for April 13th 2020: Privacy concerns with COVID-19 contact tracing apps, the FBI’s new warnings about business email compromise scams, and how to prevent unwanted and SPAM phone calls. Show notes and links mentioned on the show Help speed up contact tracing with TraceTogether https://www.gov.sg/article/help-speed-up-contact-tracing-with-tracetogether COVID-19 contact tracing: Canadian company […]

The post Contact Tracing Apps, Business Email Compromise Scams, SPAM Phone Calls appeared first on The Shared Security Show.

View Details

In episode 115 for April 6th 2020: The latest on yet another Marriott data breach, what you need to know about Zoom-Bombing and other Zoom privacy concerns, and new warnings about US economic stimulus payment scams. Show notes and links mentioned on the show Marriott discloses another security breach that may impact over […]

The post Another Marriott Data Breach, Zoom-Bombing, Economic Stimulus Scams appeared first on The Shared Security Show.

View Details

In episode 114 for March 30th 2020: Co-host Tom Eston is joined with frequent guest Kevin Johnson to discuss how to stay more secure when working from home. If you find yourself working from home because of COVID-19 this is one episode you don’t want to miss! ** Show notes and links mentioned on the […]

The post Staying Secure When Working From Home appeared first on The Shared Security Show.

View Details

In episode 98 of our monthly show co-host Scott Wright shows us a demo of Click Armor which is a gamified cybersecurity awareness platform, Tom presents the results of our listener survey, and we have a discussion about the privacy concerns with geofence warrants. Show notes and links mentioned on the show Take […]

The post Click Armor Demo, Podcast Survey Results, Google Geofence Warrants appeared first on The Shared Security Show.

View Details

In episode 113 for March 23rd 2020: Israel passes an emergency law to use mobile data to track people infected with COVID-19, the latest coronavirus cyber-attacks to be aware of, and how governments world-wide could be putting backdoors into secure messaging apps. Show notes and links mentioned on the show Israel passes emergency […]

The post COVID-19 Mass Surveillance, New Coronavirus Cyber-Attacks, Encryption Backdoors appeared first on The Shared Security Show.

View Details

In episode 112 for March 16th 2020: The cybersecurity impact of COVID-19, who’s hacking the hackers, and details on a data leak of the secret sharing app Whisper. Show notes and links mentioned on the show Resilient in Times of Disruption https://www.rsa.com/en-us/blog/2020-03/resilient-in-times-of-disruption COVID-19 coronavirus outbreak and a security conference tries to play it […]

The post COVID-19 Cybersecurity Impact, Hacking the Hackers, Whisper App Data Leak appeared first on The Shared Security Show.

View Details

In episode 111 for March 9th 2020: A new report shows that attacks on Internet of Things devices are on the rise, the FCC fines major mobile carriers for selling users’ location data, and details on what happens when 3 million HTTPS certificates need to be revoked because of coding error. ** Show notes and […]

The post IoT Device Attacks, FCC Fines Mobile Carriers, Let’s Encrypt Certificate Bug appeared first on The Shared Security Show.

View Details

In episode 110: Tyler Hudak, Incident Response Practice Lead at TrustedSec, joins us to talk about what you should do (and more importantly what you shouldn’t do) if you find out you’ve been hacked! Show notes and links mentioned on the show Take our podcast listener survey and be entered to win a […]

The post You’ve Been Hacked! Now What? appeared first on The Shared Security Show.

View Details

In episode 109 for February 24th 2020: Kevin Johnson joins us to discuss how Ring made two-factor authentication mandatory following recent hacking incidents, California police have been caught illegally sharing license plate reader data, and details on IBM and other companies pulling out of the RSA conference due to coronavirus fears. ** Show notes and […]

The post Ring Mandates Two-Factor Authentication, License Plate Reader Data Sharing, RSA Conference Coronavirus Fears appeared first on The Shared Security Show.

View Details

In episode 97 of our monthly show we discuss how Chinese hackers caused the Equifax data breach, new coronavirus phishing attacks to be aware of, and how to stay (almost) anonymous online. Show notes and links mentioned on the show U.S. Charges 4 Chinese Military Officers in 2017 Equifax Hack https://krebsonsecurity.com/2020/02/u-s-charges-4-chinese-military-officers-in-2017-equifax-hack/ Phishers impersonate […]

The post Chinese Hackers, Coronavirus Phishing Attacks, How to Stay (Almost) Anonymous Online appeared first on The Shared Security Show.

View Details

In episode 108 for February 17th 2020: The US charges four Chinese military hackers in the Equifax data breach, how Israel’s entire voter registry was exposed, and details on the encryption provider that was secretly owned by the CIA for the last fifty years. Show notes and links mentioned on the show U.S. […]

The post Equifax Hacked by China, Israeli Voter Registry Exposed, How the CIA Owned Encryption appeared first on The Shared Security Show.

View Details

In episode 107 for February 10th 2020: preventing tax identity theft and other tax scams, the FTC taking a stand against companies that support robocallers, and details on the incident where videos from Google Photos were being sent to strangers. Show notes and links mentioned on the show Preventing Tax Identity Theft and […]

The post Preventing Tax Identity Theft, FTC and Robocallers, Google Photos Incident appeared first on The Shared Security Show.

View Details

In episode 106 for February 3rd 2020: What you need to know about Facebook’s new off-Facebook activity tool, details about the Ring Android app sending user data to third party trackers, and new developments in the Wawa credit card breach. Show notes and links mentioned on the show Off-Facebook Activity is a Welcome […]

The post Off-Facebook Activity Tool, Ring App Third-Party Trackers, Wawa Credit Card Breach appeared first on The Shared Security Show.

View Details

In episode 96 of our monthly we discuss the controversy of voting by smartphone in our elections, the Jeff Bezos hacking incident, and the recent Microsoft support security breach. Show notes and links mentioned on the show Seattle-Area Voters To Vote By Smartphone In 1st For U.S. Elections https://www.npr.org/2020/01/22/798126153/exclusive-seattle-area-voters-to-vote-by-smartphone-in-1st-for-u-s-elections Saudi Prince Allegedly Hacked […]

The post Voting by Smartphone, Jeff Bezos Hacked, Microsoft Security Breach appeared first on The Shared Security Show.

View Details

In episode 105 for January 27th 2020: What are the new forms of fraud and cybercrime being found on the Dark Web? We discuss this fascinating topic with Emily Wilson, VP of Research at Terbium Labs. Show notes and links mentioned on the show Emily’s Dark Reading Article: Fraud in the New Decade […]

The post Dark Web Fraud and Cybercrime with Emily Wilson appeared first on The Shared Security Show.

View Details

In episode 104 for January 20th 2020: Details on the new critical Microsoft Windows vulnerability, why dating apps could pose a national security risk, and how new Apple privacy features are changing the way your data is sold. Show notes and links mentioned on the show Major Windows flaw was discovered and reported […]

The post Critical Windows Vulnerability, Dating App Security Risk, Apple iOS Privacy Features appeared first on The Shared Security Show.

View Details

In episode 103: The US Department of Homeland Security warns of Iranian cyber-attacks, Ring gets hit with a $5 million dollar class action lawsuit, and some quick tips on how to prevent calendar SPAM. Show notes and links mentioned on the show Iran maintains a robust cyber program and can execute cyber-attacks against […]

The post Iranian Cyber-Attacks, Ring Class-Action Lawsuit, Preventing Calendar SPAM appeared first on The Shared Security Show.

View Details

In episode 102: Details on the new California data privacy law, the Wyze data leak, and what is the ToTok app and could it be spying on you? Show notes and links mentioned on the show Enter our Silent Pocket New Year’s Giveaway – Deadline to enter: January 11th 2020 https://kingsumo.com/g/jsz2pk/silent-pocket-faraday-bag-new-years-giveaway Details on […]

The post New California Data Privacy Law, Wyze Data Leak, ToTok Spy App appeared first on The Shared Security Show.

View Details

In episode 101: Start the new year off right by following our top 10 cybersecurity and privacy resolutions! Show notes and links mentioned on the show Recommended Password Managers KeePass (free and open source): https://keepass.info/ Dashlane: https://www.dashlane.com/ 1Password: https://1password.com/ See if your site or service offer’s two-factor or multi-factor authentication https://twofactorauth.org/ Silent Pocket […]

The post Top 10 Cybersecurity and Privacy Resolutions appeared first on The Shared Security Show.

View Details

In episode 95 of our monthly show we’re joined by special guest Rebecca Herold, the “Privacy Professor”. Rebecca is a well known expert in the privacy and cybersecurity community and gives us an update on what she’s been working on, what her thoughts are on the current state of privacy regulations (CCPA, GLBA, etc), and […]

The post Rebecca Herold “The Privacy Professor” appeared first on The Shared Security Show.

View Details

In episode 100: Kevin Johnson, CEO of SecureIdeas joins us in this very special milestone episode to discuss the year that was 2019 and what Kevin’s “predictions” are for cybersecurity and privacy 2020. Thank you to Kevin for being our special guest! Show notes and links mentioned on the show The Nerf Dart […]

The post The Year in Review and 2020 Predictions with Kevin Johnson appeared first on The Shared Security Show.

View Details

In episode 99: Password reuse is still a very large problem, US government recommendations for securing Internet of Things devices, and yet another smart lock device security disaster. Show notes and links mentioned on the show Password reuse continues to be a major problem https://www.microsoft.com/securityinsights/Identity https://resources.hypr.com/top-recommendations/password-usage-study https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8-year-old-girl-s-bedroom-n1100586 US government recommendations for securing Internet […]

The post The Password Reuse Problem, US Government IoT Recommendations, Smart Lock Security Disaster appeared first on The Shared Security Show.

View Details

In episode 98: A new report from the EFF details how we are tracked online by third-party corporations, more mass surveillance concerns in China and Australia, and a malicious app hijack attack on Android to be aware of. Show notes and links mentioned on the show How You’re Tracked Online – Must Read […]

The post How You’re Tracked Online, New Mass Surveillance Concerns, Malicious Android App Hijack appeared first on The Shared Security Show.

View Details

In episode 94 of our monthly show for November 2019: The 25 most dangerous vulnerabilities, the privacy of new “smart cities”, and which search engine keeps your searches more private? It’s DuckDuckGo vs. Google! Show notes and links mentioned on the show Snapshot: Top 25 Most Dangerous Software Errors https://www.dhs.gov/science-and-technology/news/2019/11/26/snapshot-top-25-most-dangerous-software-errors https://www.theregister.co.uk/2019/09/18/the_25_most_dangerous_software_weaknesses/ Google’s “smart […]

The post Top 25 Most Dangerous Vulnerabilities, Smart City Privacy, DuckDuckGo vs. Google appeared first on The Shared Security Show.

View Details

In episode 97 for December 2nd 2019: How to prevent phone and voice fraud, Twitter’s inactive account purge, and the Adobe Magento Marketplace data breach. Show notes and links mentioned on the show Don’t become a victim of phone and voicemail fraud https://www.darkreading.com/7-ways-to-hang-up-on-voice-fraud—/d/d-id/1336427 Twitter’s inactive account purge https://www.cnn.com/2019/11/27/tech/twitter-inactive-account-delete/index.html https://twitter.com/TwitterSupport/status/1199777313300209664 Adobe Magento Marketplace data […]

The post Phone and Voice Fraud, Twitter Account Purge, Adobe Magento Marketplace Data Breach appeared first on The Shared Security Show.

View Details

In episode 96: Thousands of Disney+ accounts have been hacked, Black Friday and Cyber Monday scams to watch out for, and the latest on new Android camera exploits affecting Google and Samsung smartphones. Show notes and links mentioned on the show Disney+ accounts hacked shortly after the service launched https://www.zdnet.com/article/thousands-of-hacked-disney-accounts-are-already-for-sale-on-hacking-forums/ Find out which […]

The post Disney+ Hacked Accounts, Black Friday Scams, Android Camera Exploits appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 95 for November 18th 2019: Google’s access to the medical records of millions of Americans, a new ruling on suspicionless searches at the US border, and details on a new scam using […]

The post Google’s Health Record Storage Controversy, US Border Search Ruling, Zelle Scams appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 94 for November 11th 2019: Facebook’s Group API data leak and 7,000 pages of leaked Facebook documents, lasers that can control your smart speakers, and details about the BlueKeep vulnerability now being […]

The post Facebook Data Leaks, Smart Speaker Laser Attack, BlueKeep in the Wild appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 93 for November 4th 2019: The WhatsApp NSO group lawsuit plus details on Facebook’s preventive health tool, this week’s data breach news, and how attackers are using a voicemail to phish Microsoft […]

The post WhatsApp’s NSO Group Lawsuit, This Week in Data Breaches, Office 365 Voicemail Phishing appeared first on The Shared Security Show.

View Details

In episode 93 of our monthly show we review the Firewalla home network device, talk about the 15 most dangerous (or scary) apps for kids that parents need to be aware of, and the rise of the “deepfake”! Watch the recording of our live stream on YouTube (we’re not sure what happened with Scott’s out-of-sync […]

The post Firewalla Review, 15 Most Dangerous Apps for Kids, Rise of the Deepfake appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 92 for October 28th 2019: Details on the Nord VPN security incident, using Amazon Echo and Google Home smart speakers for phishing attacks, and new privacy features in Apple iOS 13 you […]

The post Nord VPN Security Incident, Smart Speaker Phishing, Apple iOS 13 Privacy Features appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 91 for October 21st 2019: Pitney Bowes becomes the latest ransomware victim, what are the top technology fears, and the latest on the vulnerability that allows a Samsung Galaxy S10 to be […]

The post Pitney Bowes Ransomware Attack, Samsung Galaxy S10 Fingerprint Bypass, Top Technology Fears appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston In episode 90 for October 14th 2019: How protesters in Hong Kong are avoiding facial recognition, Instagram’s new anti-phishing tool, and my recent epic smart device failure incident. Being a frequent traveler myself, I’m […]

The post Hong Kong Protests, Instagram’s Anti-Phishing Tool, Smart Device Fail appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 89 for October 7th 2019: Microsoft’s new OneDrive personal vault, updated privacy and security controls announced by Google, and the TSA’s announcement about the REAL ID deadline next year. I have a […]

The post Microsoft OneDrive Personal Vault, Google’s New Privacy and Security Controls, REAL ID Deadline appeared first on The Shared Security Show.

View Details

In episode 92 of our monthly show Tom and Scott talk about Amazon’s new smart glasses that work with Alexa, what webkey’s are and how they could be used for social engineering, and why you should always erase old hard drives and other data storage before selling or giving away computers and other electronics. Looking […]

The post Amazon Smart Glasses, Webkey Social Engineering, Erase Your Old Hard Drives! appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 88 for September 30th 2019: DoorDash announces a data breach affecting 4.9 million people, recent voice assistant privacy changes, and ways that you can limit ad tracking on your mobile device. Are […]

The post DoorDash Data Breach, Voice Assistant Privacy Changes, Limiting Ad Tracking appeared first on The Shared Security Show.

View Details

On this special edition of the podcast we speak with Aaron Zar, co-founder and CEO of Silent Pocket. Silent Pocket has been a long time sponsor of the show and it was great to catch up with Aaron to get his thoughts on the current state of digital privacy. On the show we also discuss: […]

The post Aaron Zar, Co-Founder and CEO of Silent Pocket appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 87 for September 22nd 2019: Everything you need to know about Apple iOS 13, Venmo scams you need to be aware of, and new details about “Simjacking” attacks This week I had […]

The post Apple iOS 13, Venmo Scams, Simjacking Attacks appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 86 for September 16th 2019: All about end-to-end encryption with Max Krohn from Keybase.io. Are you looking for the very best products to protect your digital privacy? Well, Silent Pocket has everything […]

The post End-to-End Encryption with Max Krohn from Keybase.io appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 85 for September 9th 2019: Firefox will now block all third-party tracking cookies and more by default, serious vulnerabilities found in Apple iOS, and the latest on the huge database of Facebook […]

The post New Firefox Privacy Protections, Apple iOS Zero-Days, Facebook User Phone Numbers Exposed appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston.  In episode 84 for September 2nd 2019: “Ghost click” Android apps found on the Google Play Store, new privacy protections for Apple’s Siri voice assistant, and did you know that your credit card may […]

The post Android “Ghost Click” Apps, New Apple Siri Privacy Protections, Credit Card Spying appeared first on The Shared Security Show.

View Details

In Episode 91 of this very special episode of our monthly show, Tom and Scott are joined by special guests Kevin Johnson and Jayson E. Street back to celebrate the 10 year anniversary of this podcast! We talk about the history of the show, what’s improved (or not improved) in the last 10 years from […]

The post 10 Year Anniversary Episode with Kevin Johnson and Jayson E. Street appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 83 for August 26th 2019: Facebook announces new off-Facebook activity privacy controls, how Apple made everyone’s iOS device vulnerable, and details on the massive MoviePass data breach. This week I read yet […]

The post New Facebook Privacy Controls, Apple iOS Patching Mistake, MoviePass Data Breach appeared first on The Shared Security Show.

View Details

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 82 for August 19th 2019: The BioStar2 biometric security data breach, wormable vulnerabilities in Microsoft Windows, and the FBI trying to harvest your social media data. Can you believe that this week […]

The post Biometric Security Data Breach, Critical Windows Vulnerabilities, FBI Data Harvesting appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for August 12th 2019 with your host, Tom Eston. In this week’s episode: My summary of last week’s BSides Las Vegas security conference, how a single text message to your iPhone could get you hacked, and how Stingray surveillance devices can still be used on new 5G networks. […]

The post BSides Las Vegas, iMessage Exploit, 5G and Stingray Surveillance appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for August 5th 2019 with your host, Tom Eston. In this week’s episode: everything you need to know about the Capital One data breach, changes in the payouts from the Equifax settlement, and Nextdoor app scams. If you happen to be in the cybersecurity industry this week is […]

The post Capital One Data Breach, Equifax Settlement Payouts, Nextdoor App Scams appeared first on The Shared Security Show.

View Details

In episode 90 of our monthly show we discuss medical device security with John Nye, Senior Director of Cybersecurity Research and Communication at CynergisTek. Do you use an insulin pump, have a pacemaker or other medical device implant? Are you concerned about medical device security and what the future holds for technology like this? If […]

The post Medical Device Security with Special Guest John Nye appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for July 29th 2019 with your host, Tom Eston. In this week’s episode: Details on the Equifax breach settlement, why your Android phone could be exploited by simply watching a video file, and encryption backdoors being requested by world-wide governments. Can you believe that its almost August and […]

The post Equifax Settlement, Android Video File Exploit, Encryption Backdoors appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for July 22nd 2019 with your host, Tom Eston. In this week’s episode: The FaceApp privacy panic, Facebook’s 5 billion dollar fine from the FTC, and what you need to know about two new types of Amazon scams. Traveling internationally this summer? If so, make sure you protect […]

The post FaceApp Privacy Panic, Facebook’s 5 Billion Dollar Fine, Amazon Brushing Scams appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for July 15th 2019 with your host, Tom Eston. In this week’s episode: Zoom video conferencing zero-day, massive fines being issued for violating GDPR, and who might be listening when you talk to your Google Assistant. Looking to protect your laptop, smartphone, and key fobs this summer? Well […]

The post Zoom Zero-Day, GDPR Fines, Google Assistant Recordings appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for July 8th 2019 with your host, Tom Eston. In this week’s episode: Amazon confirms that Alexa recordings are kept forever, details about one of the largest Facebook malware campaigns, and my top three tips for staying private on vacation. Summer is upon us and that means it’s […]

The post Amazon Alexa Recordings, Facebook Malware Campaign, Top 3 Tips to Stay Private on Vacation appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for July 1st 2019 with your host, Tom Eston. In this week’s episode: The US cyber-attack on Iran, the sad state of cybersecurity in the US government, and what you need to know about malvertising campaigns. Don’t you hate air travel? I know I do! Rude people, crowds, […]

The post US Cyber-Attack on Iran, Poor Government Cybersecurity, Malvertising Campaigns appeared first on The Shared Security Show.

View Details

In episode 89 of our monthly show Scott and Tom discuss everything you need to know about home security with physical security expert, Patrick McNeil. We delve deep into the world of locks, lock bumping, doors, windows, surveillance cameras, alarms, and much more. If you’ve always wanted to know how best to protect your home […]

The post The Home Security Episode – Locks, Doors, Cameras, and More! appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for June 24th 2019 with your host, Tom Eston. In this week’s episode: Facebook announces a new cryptocurrency called Libra, two new zero-day vulnerabilities affecting Firefox, and should you be scanning your smart TV for malware? Protect your digital privacy with Silent Pocket’s product line of patented Faraday […]

The post Facebook’s New Cryptocurrency, Firefox Zero Day, Smart TV Malware appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for June 17th 2019 with your host, Tom Eston. In this week’s episode: the US Customs and Border Protection data breach, the new sign in with Apple button, and more leaked Facebook emails. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, […]

The post US Customs and Border Protection Data Breach, Sign in with Apple, Leaked Facebook Emails appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for June 10th 2019 with your host, Tom Eston. In this week’s episode: the Quest Diagnostics and LabCorp Data Breach, what happens to your smart devices when the Internet goes down, and US visa applicants now required to share their social media names. Protect your digital privacy with […]

The post Quest Diagnostics Data Breach, Google’s Network Outage, US Visa Applicants and Social Media Names appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for June 3rd 2019 with your host, Tom Eston. In this week’s episode: US cities are being rampaged with ransomware, mobile phishing attacks on the rise, and do you know what your iPhone is doing while you sleep? Protect your digital privacy with Silent Pocket’s product line of […]

The post Ransomware Rampage, Mobile Phishing Attacks, iPhone App Ad Trackers appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for May 27th 2019 with your host, Tom Eston. In this week’s episode: Investment firm Moody’s downgrades Equifax, Huawei’s US technology ban, and how Google is tracking all your purchases. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and wallets which […]

The post Equifax Downgraded, Huawei Ban, Google is Tracking Your Purchases appeared first on The Shared Security Show.

View Details

In episode 88 of our monthly show we streamed live on GetVokl! Subscribe to our channel and get notified when we’ll be live so you can chat and participate in our next show! Here are the topics we covered and links to articles we discussed: Hacker Finds He Can Remotely Kill Car Engines After Breaking […]

The post Remotely Killing Car Engines, Password Expiration Policies, Facial Recognition at Airports, InfoSec vs. Cybersecurity appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for May 20th 2019 with your host, Tom Eston. In this week’s episode: A serious spyware vulnerability in WhatsApp, San Francisco bans facial recognition, and a wormable vulnerability in older Microsoft systems. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and […]

The post Critical WhatsApp Vulnerability, Facial Recognition Ban, Wormable Flaw in Windows appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for May 13th 2019 with your host, Tom Eston. In this week’s episode: Israel bombs a building in retaliation for a cyber-attack, Google adds more privacy settings, and a new blackmail scam that uses traditional mail. Protect your digital privacy with Silent Pocket’s product line of patented Faraday […]

The post Israel Cyber-Attack Bombing, New Google Privacy Settings, Traditional Mail Blackmail Scam appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for May 6th 2019 with your host, Tom Eston. In this week’s episode: Is this the end of password expiration policies, are there camera’s recording you on an airplane, and the unknown data breach exposing 80 million records. Protect your digital privacy with Silent Pocket’s product line of […]

The post The End of Password Expiration Policies, Seat-Back Camera’s on Airplanes, Unknown Data Breach appeared first on The Shared Security Show.

View Details

Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and wallets which will make your devices untrackable, unhackable and undetectable. Use discount code “sharedsecurity” to receive 15% off of your order during checkout. Visit silentpocket.com today to take advantage of this exclusive offer. Tom Eston: Joining me on the […]

The post All about VPN’s with Gaya Polat from vpnMentor appeared first on The Shared Security Show.

View Details

In episode 87 of our monthly show, frequent guest Kevin Johnson joins us to discuss the current state of cybersecurity training and certifications. If you’re currently in the industry or pursuing a career in cybersecurity this is one episode not to miss! Tom and Kevin cover the following topics: What’s the state of training and […]

The post The State of Cybersecurity Training and Certifications with Kevin Johnson appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for April 22nd 2019 with your host, Tom Eston. In this week’s episode: Microsoft email services hacked, the Instagram “Nasty List” phishing scam, and Facebook’s attempted deals to sell your data. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and wallets […]

The post Microsoft Email Hacked, Instagram Nasty List Phishing Scam, Facebook Third-Party Data Deals appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for April 15th 2019 with your host, Tom Eston. In this week’s episode: Amazon Echo’s recording controversy, a new mobile phone scam, and hotels leaking your private information. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and wallets which will make […]

The post Amazon Echo Recording Controversy, New Mobile Phone Scam, Hotels Leaking Data appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for April 8th 2019 with your host, Tom Eston. In this week’s episode: Facebook’s very bad week, Stalkerware on the rise, and tax season scams. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and wallets which will make your devices untrackable, […]

The post Facebook’s Bad Week, Stalkerware, Tax Season Scams appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for April 1st 2019 with your host, Tom Eston. In this week’s episode: Apple’s new privacy focused credit card, the ASUS live update software backdoor, and recent statistics on Malware attacks. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and wallets […]

The post Apple Card, ASUS Live Update Backdoor, Statistics on Malware Attacks appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for March 25th 2019 with your host, Tom Eston. In this week’s episode: Facebook passwords exposed in plain text, Android Q’s new privacy features, and why Microsoft Office is the most popular target for cybercriminals. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, […]

The post Facebook Passwords Exposed, Android Q Privacy, Microsoft Office Targeted appeared first on The Shared Security Show.

View Details

In episode 86 of our monthly show we discuss Tom’s new garbage service (yep, that’s right) and why taking credit cards by filling out a form and mailing it is never a good idea, the Verifications.io data breach, how a cyberattack could capsize a ship, and the world’s most dangerous malware.  This was also the […]

The post Verifications.io Data Breach, Capsizing a Ship with a Cyberattack, World’s Most Dangerous Malware appeared first on The Shared Security Show.

View Details

Correction about CLEAR as noted in this episode of the podcast. CLEAR does not use Facial Recognition technology, only iris or fingerprint biometric scans This is your Shared Security Weekly Blaze for March 18th 2019 with your host, Tom Eston. In this week’s episode: Equifax and Marriott data breach updates, facial recognition coming […]

The post Equifax and Marriott Data Breach Updates, Facial Recognition at the Airport, Citrix Password Spraying Attack appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for March 11th 2019 with your host, Tom Eston. In this week’s episode: a new Google Chrome Zero-Day, how Facebook uses your phone number, and the shutdown of the NSA’s phone data collection program. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone […]

The post Google Chrome Zero-Day, Facebook Phone Number Privacy, NSA Phone Data Collection Program appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for March 4th 2019 with your host, Tom Eston. In this week’s episode: Multi-factor authentication to protect your credentials, and new attacks on 4G and 5G mobile networks. Protect your digital privacy with Silent Pocket’s product line of patented Faraday bags, phone cases, and wallets which will make […]

The post Multi-Factor Authentication, New Attacks on 4G and 5G Mobile Networks appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for February 25th 2019 with your host, Tom Eston. In this week’s episode: Google Nest’s secret microphone, a new Facebook login phishing campaign, and vulnerabilities in popular password managers. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product […]

The post Google Nest’s Secret Microphone, Facebook Login Phishing, Password Manager Vulnerabilities appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for February 18th 2019 with your host, Tom Eston. In this week’s episode: Preventing illegal robocalls, should you be scared of your laptop’s webcam, and recent hacks of popular dating apps. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday […]

The post Preventing Illegal Robocalls, Webcam Spying, Dating App Account Hacking appeared first on The Shared Security Show.

View Details

In episode 85 of our monthly show we discuss artificial intelligence in cybersecurity, the recent Apple FaceTime bug, and the controversy over compromised Nest camera’s. This was also the first show we streamed live over YouTube! You can re-watch the live stream on our YouTube Channel. The Shared Security Podcast sponsored by Silent Pocket and […]

The post Artificial Intelligence in Cybersecurity, Apple FaceTime Bug, Nest Camera Passwords appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for February 11th 2019 with your host, Tom Eston. In this week’s episode: DNA testing and the FBI, the $198 million dollar cryptocurrency password, and a new Chrome extension to protect your accounts from data breaches. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent […]

The post DNA Testing and the FBI, $198 Million Dollar Cryptocurrency Password, Password Checkup Chrome Extension appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for February 4th 2019 with your host, Tom Eston. In this week’s episode: The massive Apple FaceTime privacy bug, selling your privacy for money, and insecure smart light bulbs. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product […]

The post Massive Apple FaceTime Privacy Bug, Selling Your Privacy for Money, Insecure Smart Light Bulbs appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for January 28th 2019 with your host, Tom Eston. In this week’s episode: Where are the US federal privacy regulations and details on Nest camera’s being hijacked in credential stuffing attacks. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday […]

The post The Lack of US Privacy Regulations, Nest Camera’s Hijacked appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for January 21st 2019 with your host, Tom Eston. In this week’s episode: Ring doorbell privacy concerns, news on a recent password breach, and a new ruling on biometrics and Fifth Amendment rights. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a […]

The post Ring Doorbell Privacy Concerns, Recent Password Breach News, Biometrics and Fifth Amendment Rights appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for January 14th 2019 with your host, Tom Eston. In this week’s episode: The US government shutdown and cybersecurity, privacy takes center stage at CES 2019, and a mobile location data controversy. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented […]

The post US Government Shutdown, Privacy at CES 2019, Mobile Location Data Controversy appeared first on The Shared Security Show.

View Details

New year, new Cybersecurity job? If you’re looking for a new job or just starting out in Cybersecurity you’ll want to listen to this episode of our monthly show where we’re joined by special guest Kathleen Smith, CMO of ClearedJobs.net and CyberSecJobs.com. We discuss Kathleen’s recent survey on people who advance their career by volunteering […]

The post Cybersecurity Careers, Recruiting, and Volunteering with Kathleen Smith appeared first on The Shared Security Show.

View Details

This is the 50th episode of the Shared Security Weekly Blaze for January 7th 2019 with your host, Tom Eston. In this week’s episode: Newspaper Ransomware Attack, How Facebook Tracks You on Android, and USB-Type-C Authentication Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product […]

The post Newspaper Ransomware Attack, How Facebook Tracks You on Android, USB-Type-C Authentication appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for December 31st 2018 with your host, Tom Eston. In this week’s episode: a new phishing attack targeting two-factor authentication, Amazon Echo eavesdropping, and a new Netflix email scam. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product […]

The post Phishing Attack Targeting Two-Factor Authentication, Amazon Echo Eavesdropping, Netflix Email Scam – WB49 appeared first on The Shared Security Show.

View Details

Watch this episode on our YouTube channel! In this year end episode of the podcast, we’re joined by frequent guest Kevin Johnson to recap the big cybersecurity and privacy news of this past year, talk about a little movie called Star Wars, and have some fun discussing our “predictions” for what’s to come in 2019. […]

The post The Year in Review and 2019 Predictions with Special Guest Kevin Johnson appeared first on The Shared Security Show.

View Details

Watch this episode on our YouTube channel! This is your Shared Security Weekly Blaze for December 24th 2018 with your host, Tom Eston. In this week’s episode: Healthcare databases exposed, Facebook’s Photo API bug, and Signal speaks out. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday […]

The post Healthcare Databases Exposed, Facebook’s Photo API Bug, Signal Speaks Out – WB48 appeared first on The Shared Security Show.

View Details

Watch this episode on our YouTube channel! This is your Shared Security Weekly Blaze for December 17th 2018 with your host, Tom Eston. In this week’s episode: Equifax data breach details released, more Google+ API bugs and Supermicro strikes back. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented […]

The post Equifax Data Breach Details Released, More Google+ API Bugs, Supermicro Strikes Back – WB47 appeared first on The Shared Security Show.

View Details

Watch this episode on our YouTube channel! This is your Shared Security Weekly Blaze for December 10th 2018 with your host, Tom Eston. In this week’s episode: In this week’s episode: the Quora data breach, Facebook’s private emails, and Google location tracking. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket […]

The post The Quora Data Breach, Facebook’s Private Emails, Google Location Tracking – WB46 appeared first on The Shared Security Show.

View Details

Watch this episode on our YouTube channel! This is your Shared Security Weekly Blaze for December 3rd 2018 with your host, Tom Eston. In this week’s episode: the massive Marriott data breach, secure holiday shopping tips, and phishing sites using HTTPS. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers […]

The post Massive Marriott Data Breach, Secure Holiday Shopping Tips, Phishing Sites Using HTTPS – WB45 appeared first on The Shared Security Show.

View Details

In this episode Tom and Scott are joined by special guest Tanya Janca who is a Senior Cloud Developer Advocate for Microsoft. We speak with Tanya about her journey into the world of AppSec, women and minorities in Cybersecurity, her advice for getting started in AppSec, her OWASP project (DevSlop), the current state of DevOps […]

The post Special Guest Tanya Janca, DevOps and AppSec, Women in Cybersecurity – #82 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for November 26th 2018 with your host, Tom Eston. In this week’s episode: Vehicle infotainment privacy, Instagram’s accidental password exposure, and the Firefox monitor data breach notification service. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product line […]

The post Vehicle Infotainment Privacy, Instagram’s Accidental Password Exposure, Firefox Monitor – WB44 appeared first on The Shared Security Show.

View Details

In this special edition of the podcast we speak to Harry Sverdlove, who is the Founder and Chief Technology Officer of Edgewise. Harry talks with us about the concept of “zero trust” and their innovative technology that can help stop data breaches. Find out more at Edgewise.net and to schedule a demo by clicking on […]

The post Harry Sverdlove, Edgewise Founder and CTO – Special Edition appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for November 19th 2018 with your host, Tom Eston. In this week’s episode: USPS Informed delivery vulnerabilities, protecting yourself from credit card fraud and a huge SMS database leak. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product […]

The post USPS Informed Delivery Vulnerabilities, Holiday Credit Card Fraud, Huge SMS Database Leak – WB43 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for November 12, 2018 with your host, Tom Eston. In this week’s episode: Midterm Election Security, Gait Recognition Surveillance Technology and Caller ID Authentication Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product line of phone cases, wallets […]

The post Midterm Election Security, Gait Recognition Surveillance Technology, Caller ID Authentication – WB42 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for November 5th 2018 with your host, Tom Eston. In this week’s episode: Microsoft and Apple security Updates, Signal’s sealed sender and the Girl Scouts data breach. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product line of […]

The post Microsoft and Apple Security Updates, Signal’s Sealed Sender, Girl Scouts Data Breach – WB41 appeared first on The Shared Security Show.

View Details

This is the 81st episode of the Shared Security Podcast sponsored by Silent Pocket and Edgewise Networks was hosted by Tom Eston and Scott Wright recorded on October 29, 2018. Listen to this episode and previous ones direct via your web browser by clicking here. This episode is also available to watch on our YouTube Channel. In this […]

The post Fortnite Scams, Google Search Privacy, Bloomberg SuperMicro Controversy – #81 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for October 29th 2018 with your host, Tom Eston. In this week’s episode: Spy apps and Stalkerware with special guest Jeff Tang. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product line of phone cases, wallets and bags […]

The post Spy Apps and Stalkerware with Special Guest Jeff Tang – WB40 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for October 22nd 2018 with your host, Tom Eston. In this week’s episode: Hotel Room Security and Privacy with Special Guest Patrick McNeil. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product line of phone cases, wallets and […]

The post Hotel Room Security and Privacy with Special Guest Patrick McNeil – WB39 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for October 15th 2018 with your host, Tom Eston. In this week’s episode: Google+ shutdown, weapons systems vulnerabilities, and new data on voice phishing scams. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product line of phone cases, […]

The post Google+ Shutdown, Weapons Systems Vulnerabilities, Voice Phishing Scams – WB38 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for October 8th 2018 with your host, Tom Eston. In this week’s episode: Chinese Spying, Facebook Shadow Contact Information and iPhone X FaceID Privacy. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product line of phone cases, wallets […]

The post Chinese Spying, Facebook Shadow Contact Information, iPhone X FaceID Privacy – WB37 appeared first on The Shared Security Show.

View Details

This is your Shared Security Weekly Blaze for October 1st 2018 with your host, Tom Eston. In this week’s episode: Facebook’s fake account crackdown, privacy upgrade to HTTPS, and new security features in Apple iOS 12. Silent Pocket is a proud sponsor of the Shared Security Podcast! Silent Pocket offers a patented Faraday cage product […]

The post Facebook’s Fake Account Crackdown, Privacy Upgrade to HTTPS, New Security Features in Apple iOS 12 – WB36 appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for September 24, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here. You can also watch each episode of the […]

The post Mobile Phone Call Scams, Pegasus Mobile Spyware, Newegg Data Breach – WB35 appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for September 17, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here. You can also watch each episode of the […]

The post Malware-Less Email Attacks, Equifax Breach Updates, Vizio Class Action Lawsuit appeared first on The Shared Security Show.

View Details

This is the 80th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket. This episode was hosted by Tom Eston and Scott Wright recorded September 5, 2018. Listen to this episode and previous ones direct via your web browser by clicking here! This podcast […]

The post Episode 80 – Special Guest Chris Hadnagy and Social Engineering The Science of Human Hacking appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for September 10, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here. You can also watch the podcast by subscribing […]

The post Five Eyes Security Alliance, Google and Your Offline Purchases, Privacy by Default in Firefox appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for September 3, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Show Transcript This is your Shared Security Weekly […]

The post US Federal Privacy Law, WhatsApp Google Drive Warning, Improved Security for Instagram appeared first on The Shared Security Show.

View Details

This is the 79th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket. This episode was hosted by Tom Eston and Scott Wright recorded August 23, 2018. Listen to this episode and previous ones direct via your web browser by clicking here! This episode […]

The post Election Hacking and Vulnerable Voting Machines appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for August 27, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Show Transcript This is your Shared Security Weekly […]

The post New TSA Body Scanners, Back to School Cybersecurity, Instagram Hacking appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for August 20, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Show Transcript This is your Shared Security Weekly […]

The post The Shared Security Weekly Blaze – ATM Cashout Attacks, Mobile Phone Voicemail Security, Google Location Tracking appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for August 13, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Show Transcript This is your Shared Security Weekly […]

The post The Shared Security Weekly Blaze – Facebook and your Financial Transactions, Smart Home Security, Critical HP Printer Vulnerabilities appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for August 6, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Show Transcript This is your Shared Security Weekly […]

The post The Shared Security Weekly Blaze – Quiet Skies TSA Surveillance Program, SIM Hijacking and the Reddit Data Breach, Sextortion Scams appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for July 30th, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Bluetooth Vulnerabilities, Malicious Apps Removed from Twitter, Gmail Confidential Mode appeared first on The Shared Security Show.

View Details

This is the 78th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket. This episode was hosted by Tom Eston and Scott Wright recorded July 18, 2018. Listen to this episode and previous ones direct via your web browser by clicking here! Subscribe to […]

The post The Shared Security Podcast Episode 78 – Summer Camp Facial Recognition, Dark Web Dangers appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for July 23rd, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Lost and Stolen Devices, Instagram and SIM Hijacking, LabCorp Security Breach appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for July 16th, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Polar Fitness App Location Data Exposed, Blocking Scam Phone Calls, Samba TV Privacy Controversy appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for July 2nd, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Mobile App Data Leaks, The California Privacy Act, Third-party Gmail Access appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for July 2nd, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – New WPA3 Wireless Standard, Malicious Smartphone Batteries, Exactis Data Leak appeared first on The Shared Security Show.

View Details

This is the 77th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox. This episode was hosted by Tom Eston and Scott Wright recorded June 19, 2018. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast […]

The post The Shared Security Podcast Episode 77 – Personal Risk Assessments, Stingray Surveillance Devices appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for June 25, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – MyLobot Malware, Updates on Third-Party Location Data Sharing, Fortnite Scam Websites appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for June 18, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Ultrasonic Hard Drive Attacks, Dangerous USB Devices, Email Fraudsters Arrested appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for June 11, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – MyHeritage Data Breach, Facebook’s Data Sharing Partnership, Apple iOS 12 and macOS Updates appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for June 4, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Telegram Messenger in Russia, Amazon’s Facial Recognition Technology, Digital License Plates appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for May 28, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Real-time Location Tracking, VPNFilter Router Malware, Apple’s GDPR Updates appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for May 21, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Efail Vulnerabilities and PGP Encryption, Facebook’s App Investigation, Nest Password Notifications appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for May 14, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Help the podcast and leave us a review!  […]

The post The Shared Security Weekly Blaze – Recent Windows Vulnerabilities, Exposed Passwords, Credit Freeze Controversy appeared first on The Shared Security Show.

View Details

This is the 76th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox. This episode was hosted by Tom Eston and Scott Wright with special guest Kevin Johnson recorded May 7, 2018. Listen to this episode direct via this link or through the media player embedded […]

The post The Shared Security Podcast Episode 76 – Special Guest Kevin Johnson (@secureideas), Router Hacking, GDPR, NSA Metadata appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for May 7, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Listen to this episode and previous ones direct via your web browser by clicking here! Leave us a review! If you like this […]

The post The Shared Security Weekly Blaze – DNA Privacy, This Week’s Social Media Privacy News Roundup, Remote Car Hacking appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for April 30, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for April 30th 2018 with your host, Tom Eston.  In this week’s episode: […]

The post The Shared Security Weekly Blaze – Child Identity Fraud, Tech Support Scams, Amazon Key In-Car Delivery appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for April 23, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for April 23rd 2018 with your host, Tom Eston. In this week’s episode: […]

The post The Shared Security Weekly Blaze – Android’s Toxic Hellstew of Vulnerabilities, Facebook’s New Privacy Controls, Russian Router Hacking appeared first on The Shared Security Show.

View Details

This is the 75th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox. This episode was hosted by Tom Eston and Scott Wright with special guests Gotham Sharma and Dr. Brian Krupp recorded April 16, 2018. The Cybersecurity Education Episode In this episode we’re joined by […]

The post The Shared Security Podcast Episode 75 – Cybersecurity Education with Gotham Sharma (@g0thamsharma) and Dr. Brian Krupp (@briankrupp) appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for April 16, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for April 16th 2018 with your host, Tom Eston In this week’s episode: […]

The post The Shared Security Weekly Blaze – Facebook goes to Congress, More Data Breach Announcements, New Hope for Replacing Passwords appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for April 9, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions, Silent Pocket and CISOBox.  This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for April 9th 2018 with your host, Tom Eston In this week’s episode: […]

The post The Shared Security Weekly Blaze – The #DeleteFacebook Movement, Cloudflare’s New Privacy Focused DNS Service, Saks Fifth Avenue and Panera Data Breaches appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for April 2, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions and Silent Pocket.  This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for April 2nd 2018 with your host, Tom Eston. In this week’s episode: Facebook’s […]

The post The Shared Security Weekly Blaze – Facebook’s Privacy Firestorm, MyFitnessPal Data Breach, Ramifications of CLOUD and FOSTA appeared first on The Shared Security Show.

View Details

This is the 74th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright with special guest Rachel Tobac recorded March 25, 2018. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Interview […]

The post The Shared Security Podcast Episode 74 – Special Guest Rachel Tobac (@RachelTobac) appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for March 26, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for March 26th 2018…with your host, Tom Eston. In this week’s episode: Facebook and the Cambridge […]

The post The Shared Security Weekly Blaze – Facebook and the Cambridge Analytica Controversy, Vulnerable VPNs, Siri Lock Screen Privacy appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for March 19, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for March 19th 2018 with your host, Tom Eston. In this week’s episode: The Insecure Internet […]

The post The Shared Security Weekly Blaze – The Insecure Internet of Things, Spectre Patch Updates, Android Malware appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for March 12, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for March 12th 2018…with your host…Tom Eston In this week’s episode: Malicious Healthcare Workers, New Attacks […]

The post The Shared Security Weekly Blaze – Malicious Healthcare Workers, New Attacks on Mobile Networks, Facebook Messenger for Kids appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for March 5, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for March 5th 2018…with your host…Tom Eston In this week’s episode:  Facebook Face Recognition, Private Web […]

The post The Shared Security Weekly Blaze – Facebook Face Recognition, Private Web Browsing, Credit Card Fraud appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for February 26, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for February 26th 2018…with your host…Tom Eston In this week’s episode: AI Enabled Privacy Policies, New […]

The post The Shared Security Weekly Blaze – AI Enabled Privacy Policies, New Android Updates, Hotel Room Inspections appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for February 19, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for February 19th 2018…with your host…Tom Eston In this week’s episode: Instagram Social Stalking, Cryptojacking, Equifax […]

The post The Shared Security Weekly Blaze – Instagram Social Stalking, Cryptojacking, Equifax Breach Updates appeared first on The Shared Security Show.

View Details

This is the 73rd episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded February 14, 2018. Below are the show notes, commentary, links to articles and news mentioned in the podcast: The Shared Security Amazing Thing of […]

The post The Shared Security Podcast Episode 73 – Silent Pocket Faraday Laptop Sleeve Review, Password Managers, Smart Glasses appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for February 12, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for February 12th 2018…with your host…Tom Eston In this week’s episode: Tax Season Scams, SIM Hijacking […]

The post The Shared Security Weekly Blaze – Tax Season Scams, SIM Hijacking, Smart TV Privacy appeared first on The Shared Security Show.

View Details

This is the Shared Security Weekly Blaze for February 5, 2018 sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston. Show Transcript This is your Shared Security Weekly Blaze for February 5th 2018…with your host…Tom Eston In this week’s episode: ICE license plate tracking database, […]

The post The Shared Security Weekly Blaze – License Plate Tracking, Jackpotting ATMs, Strava Global Heatmap Controversy appeared first on The Shared Security Show.

View Details

This is the 72nd episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded January 22, 2018. Below are the show notes, commentary, links to articles and news mentioned in the podcast: The Shared Security Amazing Thing of […]

The post The Shared Security Podcast Episode 72 – Mobile Phone Emergency SOS, Overview of Meltdown and Spectre appeared first on The Shared Security Show.

View Details

This is the first episode of the Shared Security Weekly Blaze podcast. This episode was hosted by Tom Eston. Every Monday we’ll be releasing a short podcast, in 15 minutes or less, covering the top 3 hot news topics happening in the security and privacy world. The idea is to give you fast and consumable security and […]

The post The Shared Security Weekly Blaze – Dark Caracal, Meltdown and Spectre Debacle, Amazon Go appeared first on The Shared Security Show.

View Details

This is the 71st episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright with special guest Rebecca Herold recorded December 13, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Interview […]

The post The Shared Security Podcast Episode 71 – Special Guest Rebecca Herold “The Privacy Professor” (@PrivacyProf) appeared first on The Shared Security Show.

View Details

This is the 70th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright with special guest Dr Helen Ofosu recorded November 29, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: […]

The post The Shared Security Podcast Episode 70 – Insider Threat Psychology with Special Guest Dr Helen Ofosu appeared first on The Shared Security Show.

View Details

This is the 69th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded October 25, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Amazon Key opens your home for […]

The post The Shared Security Podcast Episode 69 – Amazon Key, KRACK and DUHK Attacks, New Devices to Steal a Car appeared first on The Shared Security Show.

View Details

This is the 68th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright with special guest Chris Hadnagy from the Innocent Lives Foundation and Social-Engineer.org recorded September 27, 2017. Below are the show notes, commentary, links to articles […]

The post The Shared Security Podcast Episode 68 – Special Guest Chris Hadnagy, Innocent Lives Foundation, Social Engineering appeared first on The Shared Security Show.

View Details

This is the 67th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded September 6, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Over 711 Million Email Addresses Exposed […]

The post The Shared Security Podcast Episode 67 – SpamBot Exposed, Mobile App Tracking, Smart Lock Fail appeared first on The Shared Security Show.

View Details

This is the 66th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded July 24, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Tom’s review of the Ring doorbell […]

The post The Shared Security Podcast Episode 66 – Ring Doorbell Camera Review, Traffic Apps, Amazon Echo appeared first on The Shared Security Show.

View Details

This is the 65th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded July 6, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Smart TV hack embeds attack code […]

The post The Shared Security Podcast Episode 65 – Smart TV Hacks, New Privacy Concerns, Phishing for Selfies appeared first on The Shared Security Show.

View Details

This is the 64th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston, Scott Wright recorded June 7, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: More Android phones than […]

The post The Shared Security Podcast Episode 64 – Ultrasonic Ads, Home Security Vulnerabilities, Printer Tracking Dots appeared first on The Shared Security Show.

View Details

This is the 63rd episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston, Scott Wright and special guest Jayson E. Street recorded April 12, 2017. Below are the show notes, commentary, links to articles and news mentioned in the […]

The post The Shared Security Podcast Episode 63 – Special Guest Jayson E. Street, Misconceptions About VPNs appeared first on The Shared Security Show.

View Details

This is the 62nd episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded March 1, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: “CloudBleed” what is it […]

The post The Shared Security Podcast Episode 62 – CloudBleed, Wifi Risks, ATM Skimmers appeared first on The Shared Security Show.

View Details

This is the 61st episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded February 15, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Here Is How to […]

The post The Shared Security Podcast Episode 61 – Home Device Hijacking, Used Device Security, Creepy Facebook Search Tool appeared first on The Shared Security Show.

View Details

This is the 60th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded February 1, 2017. Below are the show notes, commentary, links to articles and news mentioned in the podcast: In this episode we […]

The post The Shared Security Podcast Episode 60 – The Secure Messaging Episode: Signal, WhatsApp, Facebook Messenger appeared first on The Shared Security Show.

View Details

This is the 59th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded January 11, 2017 (Happy New Year!). Below are the show notes, commentary, links to articles and news mentioned in the podcast: Amazon […]

The post The Shared Security Podcast Episode 59 – Amazon Echo, Wifi Router Security, EFF Privacy Badger appeared first on The Shared Security Show.

View Details

This is the 58th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded November 29, 2016. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Privacy Panic? Snapchat Spectacles […]

The post The Shared Security Podcast Episode 58 – Snapchat Spectacles, Mobile Number Privacy, PoisonTap appeared first on The Shared Security Show.

View Details

This is the 57th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded October 5, 2016. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Hackers Stole Account Details […]

The post The Shared Security Podcast Episode 57 – Dropbox and Yahoo Breach, IoT DDoS, LinkedIn Endorsements appeared first on The Shared Security Show.

View Details

This is the 56th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded August 17, 2016. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Bitmoji keyboard for Apple […]

The post The Shared Security Podcast Episode 56 – Chat Bots, Self-Driving Cars, Bitmoji Keyboards appeared first on The Shared Security Show.

View Details

This is the 55th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded July 6, 2016. Below are the show notes, commentary, links to articles and news mentioned in the podcast: If Mark Zuckerberg Can […]

The post The Shared Security Podcast Episode 55 – IoT Horror Stories, Biometrics, Staying Safe Online appeared first on The Shared Security Show.

View Details

This is the 54th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded June 1, 2016. Below are the show notes, commentary, links to articles and news mentioned in the podcast: How to see all […]

The post The Shared Security Podcast Episode 54 – Facebook Ad Privacy, Password Breaches, Random USBs appeared first on The Shared Security Show.

View Details

This is the 53rd episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded May 4, 2016. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Scott and Tom talk […]

The post The Shared Security Podcast Episode 53 – The VPN Episode, AI Gone Bad, Google Nest appeared first on The Shared Security Show.

View Details

This is the 52nd episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright. This episode was recorded March 9, 2016. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Unexpected […]

The post The Shared Security Podcast Episode 52 – Creepy New Social Network, Phishing Dangers, Ransomware appeared first on The Shared Security Show.

View Details

This is the 51st episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright with special interview guest Andrew Patrick from the Office of the Privacy Commissioner (OPC) of Canada. This episode was recorded February 10, 2016. Below are […]

The post The Shared Security Podcast Episode 51 – Online Behavioral Advertising in Canada, Toy Security, Dangerous Apps for Teens appeared first on The Shared Security Show.

View Details

This is the 50th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright with special guest Alex Hamerstone from TrustedSec recorded January 21, 2016. Below are the show notes, commentary, links to articles and news mentioned […]

The post The Shared Security Podcast Episode 50 – Facebook Quizzes, Pre-Crime, Wireless Home Security Systems appeared first on The Shared Security Show.

View Details

This is the 49th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded December 16, 2015. Below are the show notes, commentary, links to articles and news mentioned in the podcast: People’s Deepest, […]

The post The Shared Security Podcast Episode 49 – Google Search Privacy, Smart TV Attacks, Internet Router Risks appeared first on The Shared Security Show.

View Details

This is the 48th episode of the Shared Security Podcast sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded November 23, 2015. Below are the show notes, commentary, links to articles and news mentioned in the podcast: Hacking […]

The post The Shared Security Podcast Episode 48 – Password Manager Compromise, Fingerprint Insecurity, Quitting Social Media appeared first on The Shared Security Show.

View Details

This is the 47th episode of the Shared Security Podcast (formally the Social Media Security Podcast) sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded October 28, 2015. Below are the show notes, commentary, links to articles and […]

The post The Shared Security Podcast Episode 47 – Celebrity Impersonations, Social Media and Kids, EU Safe Harbor appeared first on The Shared Security Show.

View Details

This is the 46th episode of the Shared Security Podcast (formally the Social Media Security Podcast) sponsored by Security Perspectives – Your Source for Tailored Security Awareness Training and Assessment Solutions. This episode was hosted by Tom Eston and Scott Wright recorded October 7, 2015. Below are the show notes, commentary, links to articles and […]

The post The Shared Security Podcast Episode 46 – Peeple App, Medical Devices Exposed, Instagram for Doctors appeared first on The Shared Security Show.

View Details

This is the 45th episode of the Shared Security Podcast (formally the Social Media Security Podcast) sponsored by the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded September 24, 2015. Below are the show notes, commentary, links to articles and news mentioned in the podcast: How The Internet of […]

The post The Shared Security Podcast Episode 45 – Implantable Wearables, Spotify Privacy, Hacking Self-Driving Cars appeared first on The Shared Security Show.

View Details

This is the 44th episode of the Shared Security Podcast (formally the Social Media Security Podcast) sponsored by the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded September 2, 2015. Below are the show notes, links to articles and news mentioned in the podcast: Facebook urged to tighten privacy […]

The post The Shared Security Podcast Episode 44 – Facebook Data, Apple Watch, Android, Amazon Dash Buttons appeared first on The Shared Security Show.

View Details

This is the 43rd episode of the Shared Security Podcast (formally the Social Media Security Podcast) sponsored by the Streetwise Security Zone.  This episode was hosted by Tom Eston and Scott Wright recorded August 6, 2015.  Below are the show notes, links to articles and news mentioned in the podcast: Car hack reveals peril on the road to Internet of Things (IoT) […]

The post The Shared Security Podcast Episode 43 – Car Hacking, IoT Risks, Facebook Scams, SmartTV Privacy appeared first on The Shared Security Show.

View Details

Podcast Update: The new website for the Shared Security Podcast will hopefully be live for the next episode! We hope you enjoy the new topics and format! This is the 42nd episode of the Shared Security Podcast sponsored by the Streetwise Security Zone.  This episode was hosted by Tom Eston and Scott Wright recorded June 3, 2015.  Below are the show notes, links […]

The post The Shared Security Podcast 42 – Car Theft, Risky Apps, Facebook Security Checkup appeared first on The Shared Security Show.

View Details

This is the 41st episode of the Social Media Security Podcast sponsored by the Streetwise Security Zone.  This episode was hosted by Tom Eston and Scott Wright recorded April 29, 2015.  Below are the show notes, links to articles and news mentioned in the podcast: Important Podcast Update! While we haven’t finalized the details we’re hoping to rename the podcast as […]

The post Social Media Security Podcast 41 – Podcast Updates, Internet of Things, TV Privacy appeared first on The Shared Security Show.

View Details

This is the 40th episode of the Social Media Security Podcast sponsored by the Streetwise Security Zone.  This episode was hosted by Tom Eston and Scott Wright recorded February 25, 2015.  Below are the show notes, links to articles and news mentioned in the podcast: Facebook’s new ThreatExchange Fitbit data used in a court case Echosec is a web application that […]

The post Social Media Security Podcast 40 – ThreatExchange, Echosec, Facebook Scams appeared first on The Shared Security Show.

View Details

This is the 39th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone.  This episode was hosted by Tom Eston, Scott Wright recorded December 12, 2014.  Below are the show notes, links to articles and news mentioned in the podcast: “Snapcash” has been announced by the creators of Snapchat. Can Snapchat gain enough consumer confidence […]

The post Social Media Security Podcast 39 – Snapcash, Yik Yak, LinkedIn Security and Privacy Tips appeared first on The Shared Security Show.

View Details

This is the 38th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone.  This episode was hosted by Tom Eston, Scott Wright recorded October 21, 2014.  Below are the show notes, links to articles and news mentioned in the podcast: An enterprise level story about how hard it is to block specific sites, and what […]

The post Social Media Security Podcast 38 – Corporate Policy, Whisper Privacy Flaws, Snapchat Hack appeared first on The Shared Security Show.

View Details

This is the 37th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone.  This episode was hosted by Tom Eston, Scott Wright and special guest Kevin Johnson recorded September 19th 2014.  Below are the show notes, links to articles and news mentioned in the podcast: Special Topic! Managing Your Digital Footprint (thanks to Chris John Riley […]

The post Social Media Security Podcast 37 – Special Guest Kevin Johnson (@Secureideas), Managing Your Digital Footprint appeared first on The Shared Security Show.