The Security Ledger: Recent Episodes

Paul F. Roberts

The Security Ledger: Cyber Security News & Analysis for The Internet of Things

View Details

Researcher Sam Curry revealed a flaw in a KIA website that gave anyone with the license plate number of a KIA vehicle access to vehicle controls and driver data - highlighting the dire state of smart vehicle cyber security.

The post KIA KO! Web Hackers Vs. The Auto Industry Round 2 appeared first on The Security Ledger with Paul F. Roberts.

View Details

In this episode of the podcast, host Paul Roberts speaks with Colin O'Flynn, CTO and founder of the firm NewAE about his work to patch shoddy software on his home's electric oven - and the bigger questions about owners rights to fix, tinker with or replace the software that powers their connected stuff.

The post Black Hat: Colin O’Flynn On...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 250: Window Snyder of Thistle on Making IoT Security Easy * Episode 251: Kry10 CEO Boyd Multerer on building a secure OS for the IoT * Forget the IoT. Meet the IoZ: our Internet of Zombie things

View Details

In this Spotlight podcast interview, David Monnier of Team Cymru talks about the evolution of the threat intelligence into actionable and target specific “threat reconnaissance.”

The post Spotlight Podcast: Are you ready for Threat Reconnaissance? first appeared on The Security Ledger with Paul F. Roberts.

The post Spotlight Podcast: Are you...

Read the whole entry... »

Click the icon below to listen. Related Stories* Spotlight: Making the Most of Cyber Threat Intelligence with Itsik Kesler of KELA * Spotlight: SIEMs suck. Panther is out to change that. * Episode 249: Intel Federal CTO Steve Orrin on the CHIPS Act and Supply Chain Security

View Details

New threats demand that we transform the way we think about securing the endpoints. Case in point: APIs, writes Ross Moore.

The post Attacks on APIs demand a Security Re-Think appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Malicious Automation is driving API Security Breaches * The surveys speak: supply chain threats are freaking people out * Researcher finds malicious packages lurked on npm for months

View Details

Host Paul Roberts speaks with Boyd Multerer, the CEO and founder of Kry10, which has made a secure OS for the Internet of Things.

The post Episode 251: Kry10 CEO Boyd Multerer on building a secure OS for the IoT appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Episode 250: Window Snyder of Thistle on Making IoT Security Easy * Forget the IoT. Meet the IoZ: our Internet of Zombie things * Spotlight: Traceable CSO Richard Bird on Securing the API Economy

View Details

The AI industry is pointing to the AI Village at DEF CON as a venue for assessing cybersecurity risk. But is a "village" the best way to test AI risk? Experts have their doubts.

The post Is a DEF CON Village the right way to assess AI risk? appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* The surveys speak: supply chain threats are freaking people out * Forget the IoT. Meet the IoZ: our Internet of Zombie things * Beware: Images, Video Shared on Signal Hang Around

View Details

I interview Jack Naglieri, CEO of Panther about the failures of the current SIEM technology and the need for what Naglieri terms “detection engineers."

The post Spotlight: SIEMs suck. Panther is out to change that. appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen.Related Stories* Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen * Episode 241: If Its Smart, Its Vulnerable a Conversation wit Mikko Hyppönen * Episode 240: As Stakes Of Attacks Grow, Can Cyber Policy “Shift Right”?

View Details

When it comes to measuring the security level of a device, a checklist of security ‘low hanging fruit’ is a good place to start. But more is needed, says Mike Sheward of Particle.io

The post The Future of IoT Security Standards appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Episode 240: As Stakes Of Attacks Grow, Can Cyber Policy “Shift Right”? * Episode 238: Robots Are The Next Frontier In Healthcare Cyber Risk * Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen

View Details

Getting a start-up off the ground isn’t easy in the best of times. Now imagine doing it just as a global pandemic is shutting down society...and the economy. Our guest this week, Josh McCarthy of Revelstoke Security, did it and lived to tell the tale.

The post Episode 246: SOARing out of Lockdown with Revelstoke Security appeared first on The...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 244: ZuoRAT brings APT Tactics to Home Networks * Episode 243: The CSTO is a thing- a conversation with Chris Hoff of LastPass * Episode 242: Hacking the Farm (and John Deere) with Sick Codes

View Details

Results from a survey of 2,000 enterprises found an increasing supply chain risk, with 98% of respondents reported having been "negatively impacted" by a breach in their supply chain

The post Report: Digital Supply Chain Breaches Impact 98% of Organizations appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Episode 237: Jacked on the Beanstalk – DeFi’s Security Debt Runs Wide, Deep * Episode 243: The CSTO is a thing- a conversation with Chris Hoff of LastPass * Hybrid Work Is Here: Is Your Security Strategy Ready for It?

View Details

Six decades in, password use has tipped into the absurd, while two-factor authentication is showing its limits. We talk with Matt Salisbury of Honeybadger HQ, which is using AI and machine learning to re-imagine knowledge-based authentication.

The post Episode 245: How AI is remaking knowledge-based authentication appeared first on The Security...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 244: ZuoRAT brings APT Tactics to Home Networks * Episode 243: The CSTO is a thing- a conversation with Chris Hoff of LastPass * Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen

View Details

In this episode of the Security Ledger podcast, brought to you by ReversingLabs, we interview Danny Adamitis (@dadamitis) of Black Lotus Labs about the discovery of ZuoRAT, malware that targets SOHO routers – and is outfitted with APT-style tools for attacking the devices connected to home networks. As always, you can check our full...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen * Episode 241: If Its Smart, Its Vulnerable a Conversation wit Mikko Hyppönen * Episode 240: As Stakes Of Attacks Grow, Can Cyber Policy “Shift Right”?

View Details

Researchers at Checkmarx say that a cybercriminal group, LofyGang, has targeted the open-source supply chain with hundreds of malicious packages to steal credit card information, stream accounts, and promote hacking tools.

The post Supply Chain Hackers LofyGang Behind Hundreds of Malicious Packages appeared first on The Security Ledger with Paul...

Read the whole entry... »

Related Stories* DEF CON DOOM Patrol: Deere Jailbreak Raises Questions on Security, Competition * State of Modern Application Security: 6 Key Takeaways For 2022 * Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security

View Details

Paul talks with Chris Hoff the Chief Secure Technology Officer at LastPass about the CSTO role and the security implications of “software eating the world.”

The post Episode 243: The CSTO is a thing- a conversation with Chris Hoff of LastPass appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen * Episode 241: If Its Smart, Its Vulnerable a Conversation wit Mikko Hyppönen * Episode 237: Jacked on the Beanstalk – DeFi’s Security Debt Runs Wide, Deep

View Details

In our latest podcast, Paul caught up with Sick Codes (@sickcodes) to talk about his now-legendary presentation at the DEF CON Conference in Las Vegas, in which he demonstrated a hack that ran the Doom first person shooter on a John Deere 4240 touch-screen monitor.

The post Episode 242: Hacking the Farm (and John Deere) with Sick Codes appeared...

Read the whole entry... »

Click the icon below to listen. Related Stories* DEF CON DOOM Patrol: Deere Jailbreak Raises Questions on Security, Competition * Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen

View Details

We speak with Mikko Hyppönen on the sidelines of the DEF CON Conference in Las Vegas to talk about his new book, “If its Smart it Vulnerable."

The post Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Episode 241: If Its Smart, Its Vulnerable a Conversation wit Mikko Hyppönen * Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * DEF CON DOOM Patrol: Deere Jailbreak Raises Questions on Security, Competition

View Details

A researcher presented the results of a year-long effort to reverse engineer John Deere hardware to run a version of the DOOM first person shooter. He also discovered a number of security flaws along the way.

The post DEF CON DOOM Patrol: Deere Jailbreak Raises Questions on Security, Competition appeared first on The Security Ledger with Paul F....

Read the whole entry... »

Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * DEF CON: Security Holes in Deere, Case IH Shine Spotlight on Agriculture Cyber Risk * Cyber Attack Halts Production at Ag Equipment Maker AGCO Fendt

View Details

In this episode of the podcast (#240) Lauren Zabierek, the Executive Director for the Cyber Project at the Belfer Center at Harvard’s Kennedy School joins us to talk about the need for a re-think of national cybersecurity preparedness, as major hacks like the attack on Colonial Pipeline put the focus on resilience and public safety.

The post ...

Read the whole entry... »

Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 239: Power shifts from Russia to China in the Cyber Underground * Episode 238: Robots Are The Next Frontier In Healthcare Cyber Risk

View Details

An “everywhere,” hybrid workforce is no longer concept, but reality. But securing hybrid workplaces requires big changes to how IT security gets done, argues Jason Lee, the CISO of Zoom in this Expert Insight.

The post Hybrid Work Is Here: Is Your Security Strategy Ready for It? appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Tapping into the Power of the Security Community * The Future of Attack Surface Management: How to Prepare * The Concerning Statistics About Mental Health in Cybersecurity

View Details

Upwards of 70% of organizations have been compromised because of an unknown, unmanaged, or mismanaged visible asset. Improving your Attack Surface Management capabilities is critical, says David Monnier, a Fellow at Team Cymru.

The post The Future of Attack Surface Management: How to Prepare appeared first on The Security Ledger with Paul F....

Read the whole entry... »

Related Stories* How Vulnerability Management Has Evolved And Where It’s Headed Next * Identity Fraud: The New Corporate Battleground * State of Modern Application Security: 6 Key Takeaways For 2022

View Details

The blocking and tackling work of scan management is becoming a commodity, writes Lisa Xu, the CEO of NopSec in this Expert Insight. What organizations need now is complete visibility of their IT infrastructure and business applications.

The post How Vulnerability Management Has Evolved And Where It’s Headed Next appeared first on The Security...

Read the whole entry... »

Related Stories* The Future of Attack Surface Management: How to Prepare * Identity Fraud: The New Corporate Battleground * State of Modern Application Security: 6 Key Takeaways For 2022

View Details

Are cyber professionals as good at protecting their mental health as their IT environments? Thomas Kinsella, COO of Tines, talks about the worrying mental health statistics in cyber and how to protect your team.

The post The Concerning Statistics About Mental Health in Cybersecurity appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Identity Fraud: The New Corporate Battleground * Understanding the Economic Impact of Credential Stuffing Attacks * How to Bring the Power of No-Code Security Automation to Your Team in 2022

View Details

Naomi Yusupov, a Chinese Intelligence Analyst at the threat intelligence firm CyberSixGill talks to host Paul Roberts about that company’s new report: The Bear and the Dragon: Analyzing the Russian and Chinese Cybercriminal Communities.

The post Episode 239: Power shifts from Russia to China in the Cyber Underground appeared first on The...

Read the whole entry... »

Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 238: Robots Are The Next Frontier In Healthcare Cyber Risk * Episode 236: Cyberwar Takes A Back Seat In Ukraine (For Now)

View Details

The pandemic accelerated the migration to digital services, with millions of U.S. consumers turning to the internet for everything from medical care to shopping and banking. But as consumers increasingly move their transactions online, criminals enjoy a landscape ripe for identity fraud, John Buzzard of Javelin Strategy writes in this Expert...

Read the whole entry... »

Related Stories* Understanding the Economic Impact of Credential Stuffing Attacks * How to Bring the Power of No-Code Security Automation to Your Team in 2022 * State of Modern Application Security: 6 Key Takeaways For 2022

View Details

In this episode of the podcast (#238) we speak with Daniel Brodie, the CTO at the firm Cynerio. about his firm’s discovery of a string of critical security flaws in an autonomous medical robot, TUG, that is already deployed in hundreds of clinical settings and the growing issue of medical device insecurity and cyber risks to healthcare...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 235: Justine Bone of MedSec on Healthcare Insecurity * Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Cyber Attack Halts Production at Ag Equipment Maker AGCO Fendt

View Details

Credential stuffing attacks rose by 49% in 2020, according to one report. In this Expert Insight piece, Anastasios Arampatzis talks about simple steps companies can take to stop these attacks.

The post Understanding the Economic Impact of Credential Stuffing Attacks appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* How to Bring the Power of No-Code Security Automation to Your Team in 2022 * Why Security Practitioners Are Unhappy With Their Current SIEM * State of Modern Application Security: 6 Key Takeaways For 2022

View Details

A cyber attack has disrupted the operations of AGCO/Fendt, a major manufacturer of agricultural equipment, the company has ackhttps://feeds.feedblitz.com/-/41936664/0/thesecurityledgerwledged.

The post Cyber Attack Halts Production at Ag Equipment Maker AGCO Fendt appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * DEF CON: Security Holes in Deere, Case IH Shine Spotlight on Agriculture Cyber Risk * Episode 218: Denial of Sustenance Attacks -The Cyber Risk To Agriculture

View Details

The good news? John Deere bricked expensive farm equipment taken by thieving Russian troops. The bad news: those same remote access features could be used to launch crippling, large scale attacks on US farms.

The post Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Cyber Attack Halts Production at Ag Equipment Maker AGCO Fendt * DEF CON: Security Holes in Deere, Case IH Shine Spotlight on Agriculture Cyber Risk * Episode 235: Justine Bone of MedSec on Healthcare Insecurity

View Details

The hack of Beanstalk is just the latest major compromise of a decentralized finance (DeFi) platform. In this podcast, Jennifer Fernick of NCC Group joins me to talk about why DeFi’s security woes are much bigger than Beanstalk.

The post Episode 237: Jacked on the Beanstalk – DeFi’s Security Debt Runs Wide, Deep appeared first on The...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 230: Are Vaccine Passports Cyber Secure? * Episode 235: Justine Bone of MedSec on Healthcare Insecurity * Tapping into the Power of the Security Community

View Details

we sit down with Christian Sorenson, the former lead of the international cyber warfare team at US Cyber Command and CEO of cybersecurity firm, SightGain, to talk about what we’ve learned so far from Russia’s war in Ukraine, and what may be coming next.

The post Episode 236: Cyberwar Takes A Back Seat In Ukraine (For Now) appeared first on ...

Read the whole entry... »

Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 234: Rep. Jim Langevin on Cyber Policy in an Age of Political Polarization * Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert

View Details

Seven in 10 SOC analysts say they are “burned out.” Six in 10 plan to leave their job “in the next year.” Tines CEO Eoin Hinchy says https://feeds.feedblitz.com/-/41936664/0/thesecurityledger-code automation may be a way to reduce the burhttps://feeds.feedblitz.com/-/41936664/0/thesecurityledgerut and retain top talent.

The post How to...

Read the whole entry... »

Related Stories* Why Security Practitioners Are Unhappy With Their Current SIEM * State of Modern Application Security: 6 Key Takeaways For 2022 * Tapping into the Power of the Security Community

View Details

In this Expert Insight, Jack Naglieri, the CEO of Panther, writes about how today’s cloud-centric and data-driven environments make the SIEM technologies of the past inadequate and demand new approaches to security monitoring.

The post Why Security Practitioners Are Unhappy With Their Current SIEM appeared first on The Security Ledger with...

Read the whole entry... »

Related Stories* How to Overcome Threat Detection and Response Challenges * Tapping into the Power of the Security Community * How to Bring the Power of No-Code Security Automation to Your Team in 2022

View Details

In this Expert Insight, Harshil Parikh, CEO of Tromzo, reveals findings from the company's recent State of Modern Application Security Report, a survey of 400 appsec professionals.

The post State of Modern Application Security: 6 Key Takeaways For 2022 appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* How to Bring the Power of No-Code Security Automation to Your Team in 2022 * Tapping into the Power of the Security Community * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion

View Details

In this episode of the podcast (#235) Justine Bone, the CEO of Medsec, joins Paul to talk about cyber threats to healthcare organizations in the age of COVID. Justine’s firm works with hospitals and healthcare organizations to understand their cyber risk and defend against attacks, including ransomware.

The post Episode 235: Justine Bone of...

Read the whole entry... »

Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 234: Rep. Jim Langevin on Cyber Policy in an Age of Political Polarization * Tapping into the Power of the Security Community

View Details

In this episode of the podcast (#234) US Representative Jim Langevin (D-RI), joins Paul to talk about the flurry of legislation passed on Capitol Hill in recent months to boost the U.S.’s cyber defenses.

The post Episode 234: Rep. Jim Langevin on Cyber Policy in an Age of Political Polarization appeared first on The Security Ledger with Paul F....

Read the whole entry... »

Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage * Episode 235: Justine Bone of MedSec on Healthcare Insecurity

View Details

Massive growth in Zoom’s customer base as a result of the COVID 19 pandemic brought new business - but also new challenges and security requirements. Establishing a CISO Council gave those customers a voice and a seat at the table, writes CISO Jason Lee.

The post Tapping into the Power of the Security Community appeared first on The Security...

Read the whole entry... »

Related Stories* Why Security Practitioners Are Unhappy With Their Current SIEM * State of Modern Application Security: 6 Key Takeaways For 2022 * Episode 230: Are Vaccine Passports Cyber Secure?

View Details

What does 2022 have in store? Dean Coclin of DigiCert speaks with host Paul Roberts about the trends that will shape the New Year, from cloud sovereignty to the growing reliance on PKI to secure digital identities, DEVOPs and more.

The post Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert appeared first on The Security...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 230: Are Vaccine Passports Cyber Secure? * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion * Spotlight: COVID Broke Security. Can We Fix It In 2022?

View Details

Host Paul Roberts speaks with Marc Blackmer of ShardSecure about that company’s new approach to protecting data at rest, which relies on fragmenting and scattering data to make it impossible to steal.

The post Spotlight: ShardSecure on Protecting Data At Rest Without Encryption appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Episode 230: Are Vaccine Passports Cyber Secure? * Tapping into the Power of the Security Community * Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert

View Details

In this episode of the podcast (#233) Mark Stanislav, a Vice President at the firm Gemini, joins Paul to talk about what went wrong with disclosure of Log4Shell, the critical, remote code execution flaw in the Log4j open source library. Mark talks about how the Internet community can come together ahead of the next vulnerability to make sure the...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting * Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert

View Details

President and Chairman of Trusted Computing Group (TCG), Dr. Joerg Borchert, shares the news regarding TCG's first ever CodeGen Developer Challenge.

The post Leonardo DRZ wins first ever TCG CodeGen Developer Challenge appeared first on The Security Ledger with Paul F. Roberts.

Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion * Spotlight: E-Commerce’s Bot and Mouse Game

View Details

In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses.

The post Episode 232: Log4j...

Read the whole entry... »

Click the icon below to listen. Related Stories* Episode 233: Unpacking Log4Shell’s Un-coordinated Disclosure Chaos * Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting

View Details

Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) talks about the massive shortage of information security workers at the United States - estimated at more than 400,000 workers.

The post Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage appeared first on The Security Ledger with Paul F....

Read the whole entry... »

Click the icon below to listen. Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert * Episode 232: Log4j Won’t Go Away (And What To Do About It.)

View Details

In this Expert Insight, Jack Naglieri, the founder and CEO of Panther Labs, talks about the many challenges of enterprise-scale threat detection and response. Jack provides some steps organizations can take to prepare themselves for the future.

The post How to Overcome Threat Detection and Response Challenges appeared first on The Security Ledger...

Read the whole entry... »

Related Stories* Tapping into the Power of the Security Community * Spotting Hackers at the Pace of XDR – From Alerts to Incidents * Spotlight: ShardSecure on Protecting Data At Rest Without Encryption

View Details

Mackenzie Jackson, the Developer Advocate at GitGuardian joins Paul to discuss how “secrets sprawl” on sites like GitHub threatens software supply chains.

The post Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security appeared first on The Security Ledger with Paul F. Roberts.

Click the icon below to listen. Related Stories* Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.) * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion