Enterprise Linux Security: Recent Episodes

Jay LaCroix and Joao Correia

Enterprise Linux Security takes a look at security-related topics in enterprise IT, with a special focus on Linux. Join Jay and Joao as they discuss Linux security in the ever-changing world of technology.

View Details

In this episode, Jay and Joao discuss a recent decision made by VMWare, CISA security requirements, and more about how ransomware can be especially problematic in health care.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Related Articles* Ransomware Attacks on Healthcare Sector ‘Pose a Direct and Systemic Risk to Global Public Health and Security’ * VMware Fusion and Workstation are Now Free for All Users * VMware Workstation Shifting From Proprietary Code To Using Upstream KVM * CISA proposes new security requirements to protect govt, personal data

Download Links* MP3 version * Ogg version

View Details

In the 100th episode, Jay and Joao discuss some stories that literally come full circle from earlier stories in the podcast – encryption back doors, the largest migration cost we’ve ever covered, and more!

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Related Articles* Microsoft said it lost weeks of security logs for its customers’ cloud products * China hacked Verizon, AT&T and Lumen using the FBI’s backdoor * “Extreme” Broadcom-proposed price hike would up VMware costs 1,050%, AT&T says

Download Links* MP3 version * Ogg version

View Details

In this day and age, we can spin up servers and entire networks in seconds. But should we? It’s easy to throw resources at problems, but we’ll just end up creating more work for ourselves. In this episode, Jay and Joao will discuss provisioning resources more reasonably – and the health of your entire company’s network might depend on that!

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Download Links* MP3 version * Ogg version

View Details

In this episode, Jay and Joao discuss the “EUCLEAK” vulnerability, as well as a recent story that outlines one of the many ways the industry is vulnerable to the same old tricks with outdated perimeter protection. Don’t miss it!

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* Yikes, YubiKey Vulnerable — ‘EUCLEAK’ FIDO FAIL? * Old Habits, New Threats: Why More Phishing Attacks are Bypassing Outdated Perimeter Detection

Download Links* MP3 version * Ogg version

View Details

Recently, an 18-year old bug is making new waves across the Internet, dubbed the “0.0.0.0-Day Vulnerability”. What is it? Should you be concerned? Jay and Joao will discuss this and a few other stories in this episode of Enterprise Linux Security.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* The 0.0.0.0 day browser vulnerability: A comprehensive analysis * On-Premises Data Centers Aren’t Dead or Dying — Not by a Long Shot * Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now * CISA warns critical SolarWinds RCE bug is exploited in attacks * CISA warns of Jenkins RCE bug exploited in ransomware attacks

Download Links* MP3 version * Ogg version

View Details

In DevOps, there’s many great tools we appreciate – CI/CD workflows definitely being one of them. Github Workflows is one such tool, but vulnerabilities were recently found. Also, AT&T suffers a breach (and more!)

Relevant Articles* Report Surfaces Thousands of Potential Vulnerabilities in GitHub Workflows * Survey Finds Confidence in Data Security Despite Ransomware Scourge * AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach * AT&T Says 110M Customers’ Data Leaked — Yep, it’s Snowflake Again

Download Links* MP3 version * Ogg version

View Details

In this episode, Jay and Joao discuss several recent cybersecurity news stories, including Polyfill – which is another example of why supply chain attacks are something everyone should be paying attention to.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* China-Backed Threat Group Rapidly Exploits New Flaws * Biggest Ever Password Leak – but is ObamaCare’s RockYou2024 Really NEW? * Polyfill Becomes a Supply-Chain Risk to 100,000 Websites

Download Links* MP3 version * Ogg version

View Details

In this episode, Jay and Joao will discuss the recent regreSSHion vulnerability, which claims to be a path to root – although it might take a while. Also, recent developments with Teamviewer are also discussed.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems * regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server * TeamViewer IT security update

Download Links* MP3 version * Ogg version

View Details

In this episode, Jay and Joao discuss the recent breach suffered by Ticketmaster. Also, several new or updated news stories will be discussed.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* The Ticketmaster Data Breach May Be Just the Beginning * Hackers Detail How They Allegedly Stole Ticketmaster Data From Snowflake * New York Times Responds to Source Code Leak * The kernel becomes its own CNA

Download Links* MP3 version * Ogg version

View Details

What would you do if your organization’s cloud servers were deleted? That’s exactly what happened to a Singaporean company, which found their servers wiped by a disgruntled employee. Plus, the FBI distributes over 7,000 unlock keys, and Europol launches their biggest botnet operation yet.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!Relevant Articles

Relevant Articles

  • Largest ever operation against botnets hits dropper malware ecosystem
  • A disgruntled ex-employee at a Singaporean IT firm caused carnage after deleting over 180 servers
  • FBI Distributes 7,000 LockBit Ransomware Decryption Keys to Help Victims
  • EU chat control law proposes scanning your messages
  • Operation: Endgame

Download Links* MP3 version * Ogg version

View Details

In the last episode, we discussed a story where a company literally lost their cloud – at no fault of their own. But what is truly your responsibility when working with a cloud provider? What is their responsibility? In this episode, Jay and Joao discuss where the line is drawn between you and your cloud provider.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Download Links* MP3 version * Ogg version

Relevant Articles* Unprecedented Google Cloud event wipes out customer account and its backups * A joint statement from UniSuper CEO Peter Chun, and Google Cloud CEO, Thomas Kurian

View Details

In this episode, Jay and Joao talk about a story that’s every cloud administrator’s worst nightmare – your entire environment, backups, everything – gone. That’s exactly what happened to UniSuper, a customer of Google Cloud. In this cautionary tale, we’ll explore the case of the missing cloud.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Note: The video version of this episode was edited and re-uploaded, in order to fix audio issues.

Download Links* MP3 version * Ogg version

Relevant Articles* Unprecedented Google Cloud event wipes out customer account and its backups * A joint statement from UniSuper CEO Peter Chun, and Google Cloud CEO, Thomas Kurian

View Details

There’s a lot for sysadmins to keep track of when it comes to security, so naturally there’s going to be some misconceptions every now and then. In this episode, Jay and Joao discuss some common misconceptions when it comes to security.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Download Links* MP3 version * Ogg version

Relevant Articles* Debunking The Top 5 Cybersecurity Myths

View Details

In this episode, Jay and Joao discuss the 2024 Verizon Data Breach Investigations Report (DBIR), which includes some interesting finds regarding threat actor motives, how user error impacts business, and more!

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Download Links* MP3 version * Ogg version

Relevant Articles* Shortridge Makes Sense of the 2024 Verizon DBIR * Original DBIR report from Verizon (warning: pay gate)

View Details

Ransomware is bad enough, but when it impacts healthcare it’s even worse! In this episode, Jay and Joao will discuss recent developments at Change Healthcare and their ransomware fiasco, news updates, and more!

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Download Links* MP3 version * Ogg version

Relevant Articles* UnitedHealth to take up to $1.6 billion hit this year from Change hack * Hackers start leaking stolen Change Healthcare data * Change Healthcare’s New Ransomware Nightmare Goes From Bad to Worse (Warning: Paywall)

View Details

On this podcast, Jay and Joao have discussed multiple times a situation where a threat actor submits a pull request that’s more than the project bargained for. And now, we have a situation where OpenSSH was (almost) backdoored by a commit by a maintainer of the xz project. Don’t miss this episode for all the details!

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Download Links* MP3 version * Ogg version

Relevant Articles* A Deep Dive on the xz Compromise (Joao’s Article) * XZ Utils Supply Chain Attack: A Threat Actor Spent Two Years to Implement a Linux Backdoor

View Details

What goes on behind the scenes when it comes to managing a project as large as a Linux distribution? In this episode, Jay and Joao has a chat with benny Vasquez who is not only a wealth of knowledge on that very subject, she’s also the Chair of the Board of Directors for AlmaLinux OS. Don’t miss this episode!

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Links* benny Vasquez on LinkedIn * How to Build an Open Source Community (written by benny) * AlmaLinux OS * AlmaLinux OS Community Event Volunteer Signup * AlmaLinux OS Chat (come on in and chat if you want to hang out and/or get involved) * AlmaLinux Day: Germany * AlmaLinux: How to make a RHEL compatible distribution

Download Links* MP3 version * Ogg version

View Details

You may have heard of “technical debt”, but have you heard of “security debt”? In this episode, Jay and Joao will tell you all about it and why it’s a major issue for organizations.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* Why software ‘security debt’ is becoming a serious problem for developers

Download Links* MP3 version * Ogg version

View Details

Through a joint effort, the FBI as well as NCA struck a major blow to the Lockbit ransomware group. In this episode, Jay and Joao will discuss this story as well as the state of Linux in the enterprise/open-source landscape.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* Lockbit cybercrime gang disrupted by Britain, US and EU * Enterprise Linux & Open-Source Landscape Report * Police arrest LockBit ransomware members, release decryptor in global crackdown * United States Sanctions Affiliates of Russia-Based LockBit Ransomware Group * Lockbit Decryptor

Download Links* MP3 version * Ogg version

/etcHere’s a screenshot of the snarky message that was mentioned during the podcast.

View Details

When a threat actor breaks into a router and adds firewall rules that the owner didn’t approve of, that’s considered hacking. But when the FBI does it… …it isn’t?! In this episode Jay and Joao discuss a recent story where the FBI did exactly that, and they’ll also discuss how Microsoft has become the biggest “face palm” discussed on the podcast so far.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Relevant Articles* Chinese malware removed from SOHO routers after FBI issues covert commands * Russia Hacked Microsoft Execs — SolarWinds Hackers at it Again

Download links* MP3 Version * Ogg version

View Details

Here we are, yet again, with an industry problem caused by the decision of just one software vendor. This time it’s VMware that’s causing a ruckus. In recent news, it’s been reported that VMware will be killing off 56 (yes, 56) of their stand-alone products, and that’s on top of the news that broke late last year regarding changes in their licensing model. In this episode, Jay and Joao discuss these recent VMware-related shenanigans.

Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

Related Articles* Why Broadcom Is Killing off VMware’s Standalone Products * Broadcom is killing off VMware perpetual licences

Download Links* MP3 version * Ogg version

View Details

In this episode, Jay and Joao will discuss an update on the GTA source code theft, how much threat actors are making from ransomware, and more!

Thanks to TuxCare for sponsoring this podcast! Check out how they can make managing Linux servers much easier.

Episode-Specific Links* ‘everything’ blocks devs from removing their own npm packages * CentOS Reaches End-of-Life (EoL) Soon

Download Links* MP3 version * MP3 version (lower bitrate, smaller filesize) * Ogg version

View Details

In this episode, Jay and Joao will discuss a report earlier this year that reveals the “top 10 cybersecurity misconfigurations”. These ten common mistakes can make it trivial for a threat actor to gain access to your infrastructure, so it’s definitely a list everyone should pay close attention to.

Thanks to TuxCare for sponsoring this podcast! Check them out to see how they can help you level up your Linux administration!

Relevant Article* NSA and CISA reveal top 10 cybersecurity misconfigurations

Download Links* MP3 version * MP3 version (lower bitrate, smaller file size) * Ogg version

View Details

The Mirai botnet brought the entirety of the internet to its breaking point back in 2016, taking down many prominent web sites. Now, an article from Wired has emerged that reveals the full story behind the scenes – how the threat actors got started, how the events played out, as well as what they’re up to these days. Join Jay and Joao as they discuss this very interesting story!

Thanks to TuxCare for sponsoring this podcast! Check them out to see how they can help you level up your Linux administration!

Relevant Article* Original article by Wired that follows the entire story

Download Links* MP3 version * MP3 version (lower bitrate, smaller file size) * Ogg version

View Details

In this episode, Jay and Joao catch up on recent stories. Among the topics they'll discuss another version of CentOS going end of life (and why upgrading isn't so straight-forward), the recent curl vulnerability, and more!

View Details

In this episode, Jay and Joao discuss the recent Exim news, which consists of several CVE's. Also, they'll discuss why it's a good idea to make sure you audit the services that are running on your Linux server, and remove the ones you're not using.

View Details

We've talked about Supply Chain Attacks on this podcast before, and in this episode Jay and Joao discuss another form of this popular attack vector - RepoJacking! RepoJacking occurs when a repository (such as one hosted on Github) changes information, and due to a link between the old repository info and the new - threat actors can take advantage of this. Join Jay and Joao for a discussion on this attack vector.

View Details

There's a multitude of ways you can lose money in Las Vegas, but this time it's not from gambling. In this episode, Jay and Joao will discuss a recent and still developing story where MGM was the target of what appears to be a ransomware attack.

View Details

In this episode, Jay and Joao will discuss a recent discovery by Truffle Security that has found 4,500 websites that have exposed a very critical directory. In addition, the upcoming Common Vulnerability Scoring System (CVSS) update, which will bring to version 4.0 – along with some important changes you’ll need to understand.

Relevant Articles* 4,500 of the Top 1 Million Websites Leaked Source Code Secrets * Common Vulnerability Scoring System Version 4.0 * CVSS version 4.0 Examples

Download Links* MP3 version * MP3 version (lower bitrate, smaller file size) * Ogg version

View Details

Imagine needing to ask your government permission in order to perform tasks such as installing a security patch, implementing an Intrusion Detection System, updating firmware or upgrading your operating system? If this sounds too ridiculous to be true, then you're right - it is ridiculous, but unfortunately it's a real proposal. In the U.K., Investigatory Powers Act 2016 (IPA) has had an adjustment proposed that could potentially make securing your systems more difficult than it's ever been. In this episode, Jay and Joao discuss how these potential changes will complicate pretty much everything.

View Details

In this episode, Jay and Joao talk about two recent news developments that may have important implications on the overall industry. First, In response to Microsoft's recent Azure debacle, a US Senator calls for a probe to look into the matter. Second, our main story is yet another facepalm worthy idea from Google that aims to add "integrity" to our browsers, but it's oddly lacking in said integrity and almost completely devoid of common sense. Google's "Web Integrity Protection" seems to protect only their ad dollars while making browsing more tedious for the end-user. Will it pass? What is it exactly? Jay and Joao have all the answers in this episode!

View Details

The ongoing saga with Red Hat continues, and now that some time has passed since their controversial announcement, we now have statements from other distributions, including (but not limited to) Oracle and SUSE. In this episode, Jay and Joao talk about the recent developments on this story, and also touch on some trouble that Fortigate has been having nowadays.

View Details

When it comes to Linux in the Enterprise, we have quite a few challenges we have to overcome on a day to day basis to ensure we can depend on our technology. We never thought Red Hat themselves would some day become our opponent, but here we are. In this episode, Jay and Joao will discuss discuss the latest impulsive and irresponsible decision Red Hat has made - as well as how that decision results in the company undermining their own customer base, while alienating the Linux Community at the same time.

View Details

Don't you just love e-mail? It's the gift that keeps on giving, and this time managing e-mail is even more annoying for Barracuda's customers, with CVE-2023-2868. This isn't just any CVE, this is a complete system own by the threat actors. In fact, it's so bad that the situation isn't as simple as installing a patch. In this episode, Jay and Joao discuss this vulnerability and just how big of a deal it is.

View Details

We've all heard the cloud referred to as "Someone Else's Computer", but what do you do if you find your data is on No One Else's Computer? In this example, there was a happy ending (data was restored) but it's still an important consideration all the same. What do you do if your cloud provider all of a sudden doesn't have your data? In this episode, Jay and Joao discuss a recent situation in which Azure customers found themselves in a bit of a bad situation.

View Details

In this episode, Jay and Joao discuss another form of security, job security! Throughout the series, we’ve advised and educated on enhancing the security of your enterprise network, but in this episode the focus is on YOU. Specifically, how to safeguard yourself from turnover, raise awareness of your importance to your organization, and how to navigate potential “awkward” conversations that System Administrators may find themselves having with their boss. Don’t miss this episode!

Download links* MP3 version * MP3 version (lower bitrate, smaller file size) * Ogg version

View Details

Open Source Intelligence is a very interesting topic – it’s all about the things that might get unknowingly leaked, and this leaked information is perfectly legal to know and possess! The IP address that points to a domain, vacation photos on twitter, or even what you had for lunch can be used against you in order to build a profile. In this episode, Jay and Joao discuss OSINT and some tools that are commonly used to find it.

Download links* MP3 version * MP3 version (lower bitrate, lower file size) * Ogg version

View Details

There are many security certifications that an organization can utilize to prove compliance with one or more standards, and being in compliance can bring additional benefits and opportunities. Federal Information Processing Standard (FIPS) is one of these certifications, and in this episode, Jay and Joao are joined by Nikos from Tuxcare to discuss FIPS and why your organization might consider it.

Download Links* MP3 version * MP3 version (lower bitrate, smaller file size) * Ogg version

View Details

According to several sources, and confirmed by Western Digital themselves, there’s been a breach regarding the company’s cloud related offerings, such as “My Cloud” and various cloud-enabled storage products. Many of the details have yet to be revealed, but considering that Western Digital filed a 10-K form with the SEC, it’s very possible that it could be serious. In this episode, Jay and Joao discuss this story so far, with more specific details sure to come.

Download Links* MP3 version * MP3 version (lower bitrate, smaller file size) * Ogg version

Relevant Articles* Western Digital confirms digital burglary, calls the cops * Hackers claim vast access to Western Digital systems

View Details

A multi-national effort took down a leading market for ill-gotten credentials, resulting in well over 100 arrests. This initiative was dubbed “Operation: Cookie Monster”, and while that certainly sounds like satire – it’s totally not. Genesis, the marketplace in question, was seized by a law enforcement team consisting of personnel from multiple countries. In this episode, Jay and Joao discuss this story. But not only that, what are some of the ramifications of this? Could this have lasting impacts on the industry in general? Definitely don’t miss this episode!

Relevant Articles* ‘Operation Cookie Monster’: International police action seizes dark web market

Download Links* MP3 version * MP3 version (lower bitrate, smaller size) * Ogg version

View Details

With the recent takeover of the “Linus Tech Tips” YouTube channel, what can we learn? In this episode, Jay and Joao will discuss some of the ways you can prevent such an event from happening to you (and it’s not just YouTube that’s a target).

Download Links* MP3 version * MP3 version (lower bitrate, smaller size) * Ogg version

View Details

When it comes to Enterprise IT (and especially the security sector) we have our work cut out for us. As the workload increases, we look for tools and utilities to help us keep up with the demand. But what about artificial intelligence? As we discussed in a previous episode, AI is here to stay and will be making waves in security. In this episode, Jay and Joao dive in to just a few of the ways this tech might transform the security field and those that work within it (directly or indirectly).

Download Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* Cybersecurity Leaders Stressed Over Email Security * How to Protect Your Company in a ChatGPT World * The AI Risk Landscape: How ChatGPT Is Shaping the Way Threat Actors Work * AI and the Cybersecurity Landscape

View Details

AlmaLinux OS was created around the time of “that big CentOS” announcement, and has been a worthy solution for enterprises that wish to continue with Enterprise Linux, but without the fear of the distribution being changed into something else entirely. As a drop-in replacement for Red Hat, AlmaLinux OS continues to tackle new ground and builds a strong community. In this video, Jay and Joao are joined by Atalay Kelestemur who works on the project to discuss this distribution – and there may even be some surprises in store.

Download Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* ELevate (migration utility for switching between RHEL derivatives) * AlmaCare (enterprise support for AlmaLinux OS)

View Details

Tasks that penetration testers and security analysis perform in order to expose security weaknesses may seem like a mysterious and complicated art. Most of the time, these tasks are considered “secret sauce” and unless you work for a red team, you may not be aware of what it may look like while someone attempts to gain access from the outside. In this episode, Jay and Joao discuss a report released by CISA, that provides a very detailed account at what goes into this type of work. This report is definitely a must-read, and this episode is a must-listen!

Download Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks * Ticket Granting Tickets (one of the strategies used by CISA)https://learnlinux.link/golden-ticket

View Details

DDoS (Denial of Service) attacks are incredibly common, and apparently, are breaking records. In this episode, Jay and Joao discuss a recent blog post from Cloudflare regarding how popular this attack vector is becoming nowadays, as well as a quick refresher on Denial of Service attacks in general.

Download Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* Cloudflare mitigates record-breaking 71 million request-per-second DDoS attack

View Details

Ransomware is one of the absolute worst things that can happen to your organization, often resulting in weeks of downtime. We discussed Ransomware recently, and now we have an interesting and time-appropriate story – a popular ransomware group apparently had an imposter within their ranks.

Download links* MP3 version * MP3 version (lower bitrate, smaller file) * Ogg version

Relevant Articles

  • FBI Takes Down Hive Criminal Ransomware Group
  • Dutch police take down Exclu encrypted chat service with 42 arrests, €4 million seized
  • Dutch Cops Bust ‘Exclu’ Messaging Service, Arrest 42

View Details

Passwords – for better or worse, they’re a reality and something we have to deal with. With the average person having many accounts, it’s gotten to the point where we just can’t manage these by ourselves. Password managers help us securely store these confidential secrets, but recently Lastpass (one of the most popular password managers) has suffered a breach. Although no actual passwords within vaults were cracked, recent events do raise a red flag. In this episode, Jay and Joao discuss whether or not you should trust password managers.

Live video versionDownload Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* LastPass Customers Need to Change All of Their Passwords

View Details

Ransomware – an extremely frustrating security threat that can cause business disruption, data loss, as well as long work days during the recovery process. But how do you recover from such an event? In this foundational episode, Jay and Joao discuss some tips on how to deal with this, tips you’ll hopefully never need but are good to have nonetheless.

Download Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* CISA Ransomware Guide

View Details

By using clever infrastructure engineering strategies to increase reliability, you can minimize disruption and downtime for your organization. Another technique to consider is the concept of Digital Twin – having a full system clone/mirror you can use to test enhancements, perform a root-cause analysis, or more. In this episode, Jay and Joao discuss Digital Twins and how the concept can potentially help your organization.

Download Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* Digital Twin (Wikipedia article) * More malicious packages posted to online repository. This time it’s PyPI

View Details

Note: There’s no video version for this episode, Jay’s camera stopped working near the beginning. It’s fixed now, but this episode is audio-only as a result.

Artificial intelligence seems to be all the rage nowadays, and not just in SciFi movies. Organizations can utilize AI to assist with difficult or time-consuming tasks. Now, AI has made its way into the security industry – and AI tools to check for security concerns are already starting to pop up. In this episode, Jay and Joao discuss AISecOps.

Download Links* MP3 version * MP3 version (lower quality, smaller file) * Ogg version

Relevant articles Cisco App Dynamics (Note: This is not* an endorsement – just an example of one of these solutions)

View Details

Adding unnecessary components to the Kernel is generally a bad idea, as it increases its threat surface. In this episode, Jay and Joao discuss a recent story that’s a perfect example of why it’s important to keep this under control. A vulnerability was recently discovered in the Linux kernel that scored the highest possible rating, and it all started when ksmbd was added.

Download Links* MP3 version * MP3 version (smaller file, lower bitrate) * Ogg version

Relevant Articles* Southwest Meltdown Shows Airlines Need Tighter Software Integration * Ohio court: Non-physical software damage in ransomware attack not covered under insurance * Will this CVSS 10 Linux Kernel vuln ruin your holiday?

View Details

When it comes to patching, were you aware that there’s more than one type of patch? In this episode of Enterprise Linux Security, Jay and Joao discuss the various types of patching that’s performed today.

Download Links* MP3 version * MP3 version (lower bitrate, smaller file) * Ogg version

Relevant Articles* The Many Faces of Patching

View Details

Open-Source is great – with code being open, everyone has access to it. That means that the code can be audited – and that makes it more secure, right? Well, possibly. In the recent talk “The Code is Open, But Who’s Looking at it?” Joao discusses the concept in detail. This talk was recorded at OSAD 2022. New episodes of Enterprise Linux Security will resume after the holidays. But for now, enjoy the talk!

Download Links* MP3 version * MP3 version (lower bitrate, smaller file) * Ogg version

View Details

While it’s certainly never a good thing to become the victim of a cyber-attack, it can be even more embarrassing if the CVE the threat actor used to get a foothold into your systems was patched a long time ago. In this episode, Jay and Joao discuss malware that’s currently taking advantage of vulnerabilities that were patched over a year ago! As important as software updates happen to be, why are so many organizations unable to keep up with them?

Download Links* MP3 version * MP3 version (lower bitrate, smaller file) * Ogg version

Relevant Articles* Shikitega – New stealthy malware targeting Linux

View Details

Supply chain attacks in open source software projects are a real possibility. In fact, we've covered actual incidents in previous episodes of this podcast. In this episode, Jay and Joao discuss developing legislation that will require the components within open source projects to be a part of a bill of materials (among other requirements). This is definitely something you'll want to be aware of if your organization produces open-source software, but even non-developers should be aware of it as well.

View Details

If you're in charge of maintaining servers and related equipment, what should you monitor? While monitoring is something that will grow and expand over time, Jay and Joao will give you some tips in this episode. Check out this episode for some tips on some of the baseline checks you should implement with your monitoring solution of choice.

View Details

As if Wi-Fi couldn't get anymore tedious, five (yes, FIVE) vulnerabilities were discovered in the Linux mac80211 framework, which can potentially impact literally anyone that uses Wi-Fi. Thankfully, patches are already out to fix these vulnerabilities, but there's important lessons to be learned here that this recent incident makes incredibly clear. Also, the ongoing White House security directive saga continues with some adjustments that broaden its scope.

View Details

In this episode, Jay and Joao discuss how much of a target Linux is, as well as some myths surrounding Linux and security. Also, there will be some news updates as well.

View Details

In this episode, Jay and Joao discuss a handful of cybersecurity events in the news. While none of these stories are super exciting from a technical standpoint, there's definitely some lessons to be learned. As part of this discussion, Jay and Joao will talk about topics related to the recent Grand Theft Auto leak, as breaches that targeted Uber, 2k games, and more.

View Details

Recent news of Patreon firing their security team is making the rounds online, and in this episode, Jay and Joao will talk about this very strange story and some takeaways from it.

View Details

What are some of the important areas that a Chief Information Security Officer should focus on? In this episode, Jay and Joao discuss a recent…

View Details

Continuous Integration/Continuous Delivery is huge concept when it comes to application deployment nowadays, and with good reason. Automating the compilation, testing, and other aspects of the development process increases efficiency and reliability. Security is another layer of a good CI/CD system, and in this episode, Jay and Joao discuss CI/CD and the security aspects of the popular deployment style.

View Details

What happens when you open up the Remote Desktop Protocol (RDP) to the public Internet? Definitely some shenanigans, that's what. In this episode, Jay and Joao discuss some recent news, which includes a company that made the mistake of making RDP available to everyone, multiple crypto-malwares at the same time, and other news.

View Details

When Ransomware attacks begin spreading, how would officials go about finding the source? Most of the time, finding the culprit(s) behind cyber-attacks is a very challenging task. In this episode of Enterprise Linux Security, Joao and Jay discuss some methods that were recently used to de-anonymize ransomware domains.

View Details

System Administrators are the heroes we need, and in today's episode of Enterprise Linux Security, we celebrate Sysadmin Day 2022 and the many people that work tirelessly to keep our servers running.

View Details

In episode 36 of the Enterprise Linux Security podcast, Jay and Joao record an episode live for the first time.

View Details

In this episode, Jay and Joao discuss a recent report that identifies the "Top 25 most dangerous software weaknesses." This list includes the usual suspects, as well as some very interesting findings as well. In addition, the descriptions of the common weaknesses serves as a good jumping in point if you're new to this podcast.

View Details

What would it be like to suffer a cyberattack event, that literally closes down an entire business? That's exactly what happened to United Structures of America, a steel manufacturing company. In this episode, Jay and Joao discuss what happened, and some of the lessons learned that should cause other organizations to take a hard look at how insecure their own systems are.

View Details

Atlassian software is constantly under attack, and often the source of many lost weekends for IT admins. Recently, a brand-new vulnerability has been discovered - CVE-2022-26134. This particular vulnerability is remotely exploitable, and has been listed as critical. In this episode, Jay and Joao discuss this vulnerability, as well as some of the struggles around Atlassian software in general.

View Details

Are you a fan of MySQL? What if we told you that there's an infinite supply of it online, right out in the open?! It's literally as bad as it sounds! In this episode, Jay and Joao discuss how over 3.6 million MySQL instances are publicly available, as well as other forms of unintended public access.

View Details

A "researcher" with a screen name of "Sockpuppets" decides to demonstrate how insecure some specific online resources are, in the worst way possible. You can't make this stuff up! In this episode, Jay and Joao discuss what this individual wanted to accomplish (and what happened instead).

View Details

There are many tools and utilities around security and network management, and in this episode of Enterprise Linux Security, Jay and Joao discuss some of their favorites.

View Details

In this episode, Jay and Joao unpack some recent news around the BVP47 vulnerability, and some very interesting details around it and how it came to be. This is one of those "spy thriller" type episodes, so don't miss it!

View Details

Through the course of the podcast so far, Jay and Joao have discussed foundational topics, as well as news and current trends. In this episode, second factor authentication is discussed. This foundational episode will go over what it is, why you should use it, and also some of the things that can potentially weaken its benefit.

View Details

In the industry, we spend a great deal of time hardening our security, doing our due diligence when it comes to patching, implementing firewalls, avoiding EOL software, as well as many other aspects of our security focus. But unfortunately, even a well thought out implementation of common security controls can be rendered useless if we miss the low hanging fruit - such as training our employees and making sure they understand how serious security is, and how they can help. In this episode, Jay and Joao will discuss that and more.

View Details

In the 25th episode of Enterprise Linux Security, Jay and Joao catch up on a few things in the news, including the results of a recent Internet Crime Report, and more!

View Details

The situation surrounding Lapsus$ is becoming more and more interesting, and in this episode of Enterprise Linux Security Jay and Joao discuss the latest developments regarding the group that has caused quite a ruckus recently.

View Details

Cyber security is a huge topic, and through the years the industry changes rapidly to keep up with current threats and related challenges. As a result, some of the beliefs and mindsets we've adopted in the industry have changed as well. In this episode, Jay and Joao discuss 5 myths in the security industry that either need to be adjusted, or downright debunked.

View Details

Encryption is a great benefit to take advantage of, especially when it comes to hosting web sites. But how exactly do TLS certificates work? In this episode, Jay and Joao discuss foundational concepts surrounding certificates, as well as some advice and recommended practices.

View Details

In the 21st episode of Enterprise Linux Security, Jay and Joao discuss the recent "Dirty Pipe" vulnerability, as well as Nvidia's recent breach.

View Details

Cloud Computing is all the rage these days - but what happens when a company moves to the cloud to quickly? While cloud computing can be a very rewarding technology, it can also get out of hand quite quickly. In this video, Joao and Jay discuss the concept of Cloud Governance, something that any organization that utilizes the cloud can (and should) take advantage of.

View Details

2021 is now in the past, but there's some very interesting details in the year-end vulnerability report produced by RBS. These details give us a look at some of the trends that will impact 2022 and beyond. In this episode, Joao and Jay discuss the report and some of its findings.

View Details

The New Year is just beginning, and we already have a few important CVE's to discuss, this time around Polkit and LUKS. The CVE numbers for these vulnerabilities are CVE-2021-4034 and CVE-2021-4122 respectively. In this episode, Jay and Joao discuss these vulnerabilities.

View Details

We've discussed supply-chain attacks in the past, and now it's time to see an actual example that happened recently. However, this particular incident is especially unique as the libraries in question were allegedly poisoned by the actual developer. In this episode, Joao and Jay discuss the recent sabotage regarding two very popular NPM libraries.

View Details

It's frustrating when critical infrastructure encounters an issue that results in a disruption of service. High Availability is a concept that aims to help alleviate (or hopefully eliminate) such downtime, and is a very attractive goal for system administrators. In this episode, Jay and Joao discuss high availability, as well as its pros and cons.

View Details

Disasters in the world of tech are frustrating for everyone, not just the company that experienced the incident. In this episode, Jay and Joao discuss thoughts around what it actually means to recovery from a disaster, and why it's typically n

View Details

urity. CrowdSec aims to prevent intrusions and other forms of malicious activity, but it does it in a different way - it utilizes intelligence gathered from other users in order to enhance its protection. In this episode, Jay and Joao discuss CrowdSec with Philippe Humeau, the CEO of the project.

View Details

Joao and Jay talk about the worst healthcare breaches of 2021, and some lessons that can be learned from these events.

View Details

center of the development cycle (rather than an outside resource). In this episode, Jay and Joao discuss DevOps and how it's changed the landscape.

View Details

Recently, some interesting security news has occurred, and two specific developments are the main discussion in this episode. Trojan Source is a newly discovered tactic that can be used to hide malicious code and execute something completely unexpected, even when the source code appears to be syntactically correct. In addition, CISA recently mandated a large number of CVE's to be patched in the very near future, which will likely have ramifications even outside of the United States. Also, Jay and Joao also discuss the recently released Fedora 35, which is a distribution that has a large presence on the workstations that administrators use.

View Details

Remaining on legacy Linux distributions can lead to additional security risks as time goes on, and migrating to a newer and better supported distribution can be a very difficult endeavor for most administrators. In this episode, Jay and Joao are joined by Jack from AlmaLinux, and we talk about ELevate - a tool that can be used to migrate from a distribution in the Enterprise Linux family to another Enterprise Linux distribution. This helps alleviate some of the burden of distro migration, and as a community project it's also a great project to get started with contributing to an open-source project.

View Details

Although there's no such thing as a "perfect" deployment image, including some sane defaults into your images and templates can save you a lot of work down the road, and also give you the opportunity to include more secure defaults. In this episode, we'll discuss deployment image defaults as well as some recent news.

View Details

We've talked about Enterprise Linux Security from the worldview of the system administrator, but what's it like on the other side? In this episode, Jay and Joao are joined by Atalay Kelestemur, an Ethical Hacker, as we discuss the mindset of the attacker.

View Details

When you write software, there's no reason to reinvent the wheel - shared libraries and other resources exist to enable you to create applications while avoiding redundant work. Unfortunately, sometimes the software supply itself chain is attacked, which would mean that your application contain malware or security threats you didn't account for. In this episode of Enterprise Linux Security, Joao and I discuss supply chain attacks, as well as some ways to mitigate this threat.

View Details

Jay and Joao discuss the challenges when it comes to migrating Linux distributions, and the effect this has on security.

View Details

Regardless of your role in your company, understanding the various types of attack vectors is extremely important. In this episode of Enterprise Linux Security, Jay and Joao discuss the most common attack vectors that are used today, which will set the foundation for future episodes.

View Details

In episode 1 of the Enterprise Linux Security Podcast, Jay and Joao talk about CVEs: Common Vulnerabilities and Exposures. It's an important topic to understand in the world of security, and we'll talk about what this means, how they're classified, and much more!

View Details

Enjoy the first episode of a brand new, bi-weekly podcast. Joao and I will get together in each episode and talk about all things Linux Security, with a focus on the Enterprise.