Security Nation: Recent Episodes

Jen Ellis and Tod Beardsley

Security Nation is a podcast dedicated to celebrating the champions in the cybersecurity community who are advancing security in their own ways. We also cover the latest developments in infosec that you should know about.

View Details

No Rapid Rundown this time! But you can get links to all the past episodes in Season 5, here:

  • Never Mind the Ears, Here's Security Nation

View Details

Interview links

  • Jeremi on Password Nihilism
  • The Rails bug Jeremi referenced

Rapid Rundown links

  • Risky Business Newsletter on fake PoCs: "GitHub aflood with fake and malicious PoCs"
  • The cited paper: "How security professionals are being attacked: A study of malicious CVE proof of concept exploits in GitHub"
  • Also relevant is Honeysploit by Curtis Brazzell

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview links

  • Jeremi on Password Nihilism
  • The Rails bug Jeremi referenced

Rapid Rundown links

  • Risky Business Newsletter on fake PoCs: "GitHub aflood with fake and malicious PoCs"
  • The cited paper: "How security professionals are being attacked: A study of malicious CVE proof of concept exploits in GitHub"
  • Also relevant is Honeysploit by Curtis Brazzell

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Prior Security Nation episode in which loads of PortSwigger references were dropped:
    • https://www.rapid7.com/blog/post/2021/08/18/security-nation-daniel-crowley/
  • New research from James about browser-powered desync attacks:
    • https://portswigger.net/research/browser-powered-desync-attacks

Rapid Rundown Links

  • Semi-secret Fortinet advisory:
    • https://twitter.com/Gi7w0rm/status/1578398457227878407
  • CVE Details as they come:
    • https://www.rapid7.com/blog/post/2022/10/07/cve-2022-40684-remote-authentication-bypass-vulnerability-in-fortinet-firewalls-web-proxies/
  • Existence of Fortinet CVE-2022-40684 PoC posted, but not the PoC itself:
    • https://twitter.com/Horizon3Attack/status/1579285863108087810
  • The Hidden Harms of Silent Patches:
    • https://www.rapid7.com/blog/post/2022/06/06/the-hidden-harm-of-silent-patches/

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Prior Security Nation episode in which loads of PortSwigger references were dropped:
    • https://www.rapid7.com/blog/post/2021/08/18/security-nation-daniel-crowley/
  • New research from James about browser-powered desync attacks:
    • https://portswigger.net/research/browser-powered-desync-attacks

Rapid Rundown Links

  • Semi-secret Fortinet advisory:
    • https://twitter.com/Gi7w0rm/status/1578398457227878407
  • CVE Details as they come:
    • https://www.rapid7.com/blog/post/2022/10/07/cve-2022-40684-remote-authentication-bypass-vulnerability-in-fortinet-firewalls-web-proxies/
  • Existence of Fortinet CVE-2022-40684 PoC posted, but not the PoC itself:
    • https://twitter.com/Horizon3Attack/status/1579285863108087810
  • The Hidden Harms of Silent Patches:
    • https://www.rapid7.com/blog/post/2022/06/06/the-hidden-harm-of-silent-patches/

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out Panasonic's delightful PSIRT page – especially if you have a vulnerability in one of Panasonic's many, many products to report.

Rapid Rundown Links

  • Check out Inti's research on "oops, we made a surveillance system" at notmyplate.com.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out Panasonic's delightful PSIRT page – especially if you have a vulnerability in one of Panasonic's many, many products to report.

Rapid Rundown Links

  • Check out Inti's research on "oops, we made a surveillance system" at notmyplate.com.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out Panasonic's delightful PSIRT page – especially if you have a vulnerability in one of Panasonic's many, many products to report.

Rapid Rundown Links

  • Check out Inti's research on "oops, we made a surveillance system" at notmyplate.com.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out the CVE blog post on handling cloud vulnerabilities.
  • Read up on the rules for assigning CVEs.
  • See an example cloud CVE affecting Microsoft Azure.
  • Read the Microsoft Security Response Center’s blog post on cloud vulnerabilities.

Rapid Rundown Links

  • Check out Dominic White’s tweet on iOS remembered networks.
  • Read the update on the recently released RFC 9293.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out the CVE blog post on handling cloud vulnerabilities.
  • Read up on the rules for assigning CVEs.
  • See an example cloud CVE affecting Microsoft Azure.
  • Read the Microsoft Security Response Center’s blog post on cloud vulnerabilities.

Rapid Rundown Links

  • Check out Dominic White’s tweet on iOS remembered networks.
  • Read the update on the recently released RFC 9293.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out the CVE blog post on handling cloud vulnerabilities.
  • Read up on the rules for assigning CVEs.
  • See an example cloud CVE affecting Microsoft Azure.
  • Read the Microsoft Security Response Center’s blog post on cloud vulnerabilities.

Rapid Rundown Links

  • Check out Dominic White’s tweet on iOS remembered networks.
  • Read the update on the recently released RFC 9293.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out Nmap if, for some reason, you haven’t already.
  • Learn about Npcap, the packet capture library tool that Gordon and his company also offer.
  • Watch Gordon and HD Moore, the creator of Metasploit, chat about the evolution of network scanning on YouTube.

Rapid Rundown Links

  • Read the Bleeping Computer story on hackers using DeFi bugs to steal cryptocurrency.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Learn more about some of our favorite presentations from the Vegas conferences, including:

  • Susan Paskey on threat hunting in MFA logs
  • Jeremi Gosney on "passwords, but nihilism" (an apparently unscheduled, live threat modeling exercise on password risks)
  • Patrick Wardle on Zoom LPE vulnerabilities
  • Gaurav Keerthi, Pete Cooper, and Lily Newman on global policy challenges
  • Jake Baines on Cisco ASA vulnerabilities and weaknesses (check out the blog post, too)
  • Jonathan Leitschuh on fixing OSS vulnerabilities at scale
  • Eugene Lim on so many iCal standards within standards

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview links

  • Learn all about Defaultinator.
  • Read up on the Raspberry Pi default password vulnerability.
  • Check out the GitHub repositories for Defaultinator.

Rapid Rundown links

  • Read Derek Abdine's disclosures on Arris and Arris-like routers.
  • Check out the Security Boulevard article on keeping PoCs secret.
  • Peruse Matt Blaze’s tweet thread on teaching physical security secrets despite complaints from locksmiths.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • A Closer Look at CVSS Scores

Rapid Rundown Links

  • Bleeping Computer story: PyPI mandates 2FA for critical projects, developer pushes back
  • Twitter thread on deleting atomicwrites, and undeleting it

PyPi issues mentioned

  • https://github.com/pypi/warehouse/issues/11625
  • https://github.com/pypi/warehouse/issues/11805
  • https://github.com/pypi/warehouse/issues/11798

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Revisit our first episode with Peter and Irene from Season 4.
  • Read the paper on the UK government’s cybersecurity strategy through 2030.

Rapid Rundown Links

  • Check out the article on so-called pig-butchering scams.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Follow Steve on Twitter, and give the SpiderFoot official account a follow while you’re at it.
  • Check out the SpiderFoot website and GitHub page, and learn more about the SaaS version, SpiderFoot HX.
  • Learn about the latest SpiderFoot 4.0 release with YAML correlation rules.
  • Read Steve’s blog, especially his posts on the 10 years developing SpiderFoot and the misuse of OSINT to claim election fraud.

Rapid Rundown Links

  • Read the full paper, “A Closer Look at CVSS Scores.”
  • Follow the author, Jacques Chester, on Twitter.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out the latest on HoneyDB.
  • Interested in participating in the project? Head to the HoneyDB Agent Docs.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Check out Omer and Richard’s paper.
  • Learn more about Omer’s work and Richard’s work.

Rapid Rundown Links

  • Read the news about the change in DOJ policy toward ethical hackers.
  • Visit the Rapid7 blog on the same topic.
  • Dive into Harley’s great Twitter thread on the topic.
  • Read up on the HiQ and Missouri cases mentioned.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Learn more about Kali Linux.
  • Check out what they’re up to over at Offensive Security.
  • Follow g0tmi1k on Twitter, and check out his blog.

Rapid Rundown Links

  • Read the Krebs on Security article on the upcoming password changes.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Follow Whitney on Twitter, and check out her website.
  • Submit a CFP for this year’s Crypto & Privacy Village at DEF CON.

Rapid Rundown Links

  • Read Neil Madden’s blog post on psychic signatures.
  • Follow Neil Madden on Twitter.
  • Check out Project Wycheproof on GitHub.
  • Learn about Mount Wycheproof (the actual mountain).

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Read Project Zephyr’s blog post on Amnesia33.
  • Get Linux’s perspective on SBOM.
  • Listen to our previous episode on SBOM with Josh Corman and Audra Hatch.
  • Check out Zephyr’s Renode dashboard.
  • Learn about the Software Package Data Exchange (SPDX) specification from ISO.

Rapid Rundown Links

  • Read the story on the npm protestware.
  • Peruse the issue logged against the project on Github.
  • See Dark Reading’s homage to Mike Murray.
  • Watch Mike Murray talk about hiring hackers.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Listen to David’s previous Security Nation episode
  • Give him a follow on Twitter.
  • Read up on the PTSI bill.
  • Learn who the heck Mystic Meg is.
  • Check out ETSI (not the home crafts marketplace).

Rapid Rundown Links

  • Download Rapid7’s Vulnerability Intelligence Report.
  • Check out AttackerKB.
  • Listen to Caitlin Condon, lead author of the report, on Duo’s Decipher podcast.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Follow Bob on Twitter.
  • Check out the DNC Security Checklist.

Rapid Rundown Links

  • Read the paper on VPN influencer ads on YouTube.
  • Give the lead author, Omer, a follow on Twitter.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Learn more about Metasploit, AttackerKB, and Recog.
  • Read Matthew’s blog post on open-source security.
  • Remind yourself about Log4Shell (if you dare).
  • Read up on Linus’s Law.

Rapid Rundown Links

  • Read the Bleeping Computer article about DDoS amplification.
  • Check out the original USENIX paper.

View Details

Interview Links

  • Follow Amit on Twitter at @0xAmit.
  • Read Amit’s blog post on the Autodiscover leak.

Rapid Rundown Links

  • Read up on the vulnerability disclosure metrics from Google’s Project Zero.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Take up John on the offer to spam him on LinkedIn.
  • Learn more about what intelliflo is up to.

Rapid Rundown Links

  • Check out CISA’s KEV list.
  • Read up on the 8 vulnerabilities recently added to KEV.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Read GitHub’s blog on the Log4j vulnerability, and the follow-up.
  • Check out GitHub’s Dependabot.
  • Find out Why Johnny Can’t Encrypt.
  • Learn about GitHub’s Sponsor Program.
  • Read about the work going on at OpenSSF.
  • Delve into Mike’s blog post on GitHub’s exploit code policy.

Rapid Rundown Links

  • Get the info on Microsoft’s emergency fixes for Windows Server and VPN bugs.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • Listen to Chris’s podcast, First Impressions.
  • Check out the other, Jane Austen-themed First Impressions podcast.
  • Learn more about MVSP at the official site and in this blog post from Google.
  • Read up on the ETSI standard Jen mentioned.
  • Revisit our previous episode on Disclose.io with Casey Ellis.

Rapid Rundown Links

  • Read about the Sky router vulnerability.
  • If you just can’t wait till January to hear from us again, revisit Season 4.

View Details

Interview links

  • Learn more about the UK’s Department for International Trade.

Rapid Rundown links

  • Check out inTheWild, and follow them on Twitter.
  • Grab our 2022 planning resource. (Note! This is a direct PPTX link — don't be alarmed by the sudden download.)

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Apply to phase one of the UK Cabinet Office's Small Business Research Initiative (SBRI): Reducing Public Sector Risk through Culture Change. Want to tell a friend? Feel free to use this friendlier, human-readable and -speakable link:

https://r-7.co/cabinet-office-culture-competition

Note the deadline is fast approaching: Monday, November 8, 2021, 17:00 London UK time, and the research initiative is open to all small businesses with strong ties to the United Kingdom.

View Details

Interview Links

  • Check out the Ransomwhere site.
  • Listen to our previous episode with Jack on election security.

Rapid Rundown Links

  • Read the CISA notification on the critical RCE vulnerability in Discourse.
  • See Discourse’s announcement of the vulnerability on GitHub.
  • Peruse Discourse’s technical blog post about it.
  • Check out Discourse’s security program and policies.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview links

Follow Michael on Twitter @CyAlliancePrez

Learn more about the Cyber Threat Alliance

Check out the Ransomware Task Force, which Michael co-chairs

Read Jen's position piece on hack back

Rapid Rundown links

Read the full text of the Cyber Incident Reporting Act

Refresh your memory on the SolarWinds data breach

See who's on the House Homeland Security Committee

View Details

Interview Notes

  • Rob's live Tweet thread
  • Rob's archive of the provided RTFs (hex decoded)
  • Rob's BLX Container Extractor
  • All about Dennis Montgomery. Warning: this is a WIki rabbit hole.
  • A Torrent of several gigs of data from the Cyber-Symposium is available at:
    • magnet:?xt=urn:btih:39a9590de21e77687fdf7eacee4dd743f2683d72&dn=cyber-symposium&tr=udp://9.rarbg.me:2780/announce

Rapid Rundown Notes

  • The original Bleeping Computer story on Microsoft shutting off Basic Auth
  • The related story about Amit's Autodiscover bug finding that may have prompted the above
  • A somewhat early reference to some WPAD bugs
  • The earliest reference Tod could find about WPAD exploits... which happened to be written by the very same Tod back in 2009.

View Details

Interview Links

  • Craig is on Twitter, but his OpSec is pretty tight so good luck getting that follow back.
  • You can read up on Cisco Talos, and check their most recent on proxyware here.

Rapid Rundown Links

  • Check out the Bleeping Computer story on the ATM robbers.
  • Back in 2016, Rapid7's Weston Hecker demonstrated some EMV attacks.
  • But that doesn't matter because about half of all U.S. gas stations still don't operate with EMV payment.

Like the show? Want to keep Jen and Tod in the podcasting business? Feel free to rate and review with your favorite podcast purveyor, like Apple Podcasts.

View Details

Interview Links

  • National Cyber Security Center
  • Colorado Cyber Resource Center
  • Cybersecurity HSAC Subcommittee

Rapid Rundown Links

  • Firefox follows Chrome and prepares to block insecure downloads by Catalin Cimpanu
  • hxxp://smart4alarm.com/ is the website Tod ran into that plops an APK right in your Downloads with no clicks. Is this okay?

View Details

Interview Links:

  • IBM X-Force Red Internship program now open for Summer 2022 applicants!
  • The original Watchfire paper on HTTP Request Smuggling from 2005
  • HTTP request smuggling reborn by James Kettle
  • HTTP/2 Request Smuggling from DEF CON 2021
  • Free TCP/IP bugs
  • Free ICS bugs
  • Snyk's Zip Slip research

Rapid Rundown Links:

  • All the DEF CON videos
  • Tempest Radio Station Presentation by Paz Hameiri
  • Tempest Radio Station paper
  • How to get started in cybersecurity AMA on Reddit
  • Rob Graham's Live Tweeting of the Cyber Symposium

View Details

From the discussion with Richard:

  • Amedisys, Richard's home healthcare employer
  • S02E06: Our first time around with Richard
  • S02E10: The mentioned episode with Oliver Day

From the Rapid Rundown:

  • The Record on the PyPI bug
  • The original research from RyotaK
  • Jen's Python joke

View Details

  • Philipp Amann is the Head of Strategy at European Cybercrime Center
  • No More Ransom, an incredibly useful self-serve library of ransomware crackers, from Alpha to Ziggy
  • Need some specific guidance on what to do if you suffer a ransomware attack? Check out NMR's publication!
  • Also mentioned was Europol's annual Internet Organised Crime Threat Assessment report, which is a great read
  • Interested in partnering with NMR? Send in a request here!
  • The Rapid Rundown is mostly about the PetitPotam proof of concept NTLM attack, as discovered by @topotam77
  • Microsoft's helpful mitigation KB for the same
  • The SANS Diary writeup of this novel NTLM attack quite capably demonstrates the risks of this attack

View Details

Want to know more? Check out these links!

  • The very best place to have a few beers while at Infosec Europe in person is, naturally, the Prince of Teck
  • Follow up to the HSE attack in Ireland, from ZDNet's Danny Palmer
  • Ireland's first CERT, co-founded by Brian Honan; they announced their intention for IRISSCON 2021 in November on Twitter
  • Rob Wright, of SearchSecurity, interviewed Jeremiah Grossman about SentinelOne's cyber warranty program

Real quick correction for the Rapid Rundown: In the original recording, Tod once accidentally referred to "14.4" as the current version of iOS, when he should have said 14.6. He edited that correction directly in the audio and tried to make it sound normal. But, with that said, 14.7 was released right before we published this episode, but we still don't know if the DoS was fixed there.

Now for the links mentioned in the Rapid Rundown:

  • WifiDemon is described in detail over at ZecOps
  • Apple Developer Support , which notes what's current out in the iOS world
  • The mentioned job Rapid7 hiring for is right here
  • And here's where you can learn about the DEF CON IoT Village

View Details

  • Intrigue.IO
  • The Monpass breach
  • Avast's findings on Monpass
  • Apple trusted root certificates
  • Mozilla trusted root certificates
  • Microsoft trusted root certificates

View Details

https://go.chainalysis.com/2021-Crypto-Crime-Report.html

Tod is not Satoshi. Nor is he HD Moore, nor is he Dustin Trammel. It's wild how many people Tod isn't.

Cyberscoop's Tim Stark covers the Hydra dark net marketplace, mentioned by Kim.

The Vice story on 2G-era crypto breakage and the research paper it covers.

Detroit News on election audits in Cheboygan County, which Tod is… worried about. If you live in Michigan, tell us what you think.

View Details

If you're interested in learning more about the Payment Card Industry Data Security Standard (PCI DSS), head on over to https://www.pcisecuritystandards.org/. You should also check out Jeff's regular podcast, Security & Compliance Weekly.

If you're wondering how GitHub actually landed on their new acceptable use policy (AUP), check the diff, or read Mike Hanley's explainer blog on the same. To cap it off, see the DoJ's press release about seizing 63.7 Bitcoin, which, at this moment, is worth about USD$2 million.

View Details

Follow the Deception Lab on Twitter, and get up to speed on how to leverage the "digital, physical, and psychological" elements of the cyber battle space.

As for the news, you can check out the original release from Google (now edited to include the four in-the-wild bugs), as well as read the referenced Ransomware Task Force Report.

View Details

After the deep dive on ransomware payments and how to beat back this latest crime wave, we spend several minutes in the Rapid Rundown NOT talking about the Colonial Pipeline ransomware event. Instead, we jump into Google's renewed push for automatic enrollment in 2FA, I mean, 2SV. Hooray MFA!

Links:

Read the Ransomware Task Force Report (mentioned throughout the episode)

See Bleeping Computer's coverage of Google's default 2SV

Biographical notes:

Megan Stifel is Executive Director, Americas, at the Global Cyber Alliance. She previously served as Cybersecurity Policy Director at Public Knowledge. Prior to her work with nonprofits Megan served as a Director for International Cyber Policy at the National Security Council and in the U.S. Department of Justice, including as Director for Cyber Policy in the National Security Division and as counsel in the Criminal Division’s Computer Crime and Intellectual Property Section.

Ms. Stifel was previously in private practice, where she advised clients on sanctions and FCPA compliance. Before law school, Ms. Stifel worked for the U.S. House of Representatives Permanent Select Committee on Intelligence. She received a Juris Doctorate from the Maurer School of Law at Indiana University, and a Bachelor of Arts, magna cum laude, from the University of Notre Dame. She is a partner with Social Venture Partners Charleston.

Professor Ciaran Martin, CB, is Professor of Practice at the Blavatnik School of Government at the University of Oxford. He is also an adviser to Paladin Capital in the United States, and Garrison Technology Ltd in the United Kingdom.

For six and a half years ending in the middle of 2020, Ciaran led the UK Government’s work on cybersecurity. This included establishing the National Cyber Security Centre in 2016. The UK NCSC is now recognized as one of the leading public authorities in the world for cybersecurity, and Ciaran has been running it for its first four years. During Ciaran’s tenure, the UK rose from eighth to first in the International Telecommunications Union’s Global Cybersecurity Index. The NCSC’s approach to intervening to make technology safer–and easier to use safely–as well as managing national level incidents proactively has been lauded around the world. Ciaran has been honored within the UK, Europe, the United States, and beyond for his groundbreaking efforts to combat cyber threats.

Prior to running the NCSC, Ciaran held a series of senior roles in the UK Cabinet Office. As Director of Constitution, he oversaw the agreement for arrangements for the Scottish Independence Referendum in 2014. He also served as Director of Security and Intelligence as well as head of the Cabinet Secretary’s office. Additionally, he has worked in the UK Treasury and National Audit Office. Originally from Northern Ireland, he holds a first-class degree in history from the University of Oxford.

View Details

Marina and int eighty talk about how they came up with the idea for the Twitch livestream, what they’ve learned along the way, and future plans for the games. We also speak with int eighty about his “hacker rapper” gig, Dual Core Music.

This episode's Rapid Rundown comes with a rare content warning: We're discussing the life, impact, and passing of Dan Kaminsky. It gets pretty emotional, as you might expect. As Matt Blaze said, may his memory be a blessing.

Enjoy the links below for more!

  • Hacking Esports on Twitter and Twitch
  • More about Dual Core (also on Twitter)
  • Duo's cartoon about the Kaminsky Bug
  • Dan Kaminsky's New York Times obituary
  • Dan's 2016 r00tz talk, "How the Internet Actually Works" is on YouTube, thanks to  the r00tz  channel.

View Details

In our latest episode of Security Nation, we talk to Philip Reiner about his work with the Ransomware Task Force. Stick around for our Rapid Rundown, where Tod talks about a recently released bulletin from CISA about APT exploiting both new and old SAP vulnerabilities.

View Details

In our latest episode of Security Nation, we speak with Beau Woods and Fotios Chantzis about their newly released book, "Practical IoT Hacking." Stick around for our Rapid Rundown, where Tod encourages listeners to patch their Apple iOS devices against the recently announced WebKit bug, and to not panic about PHP's compromised Git server.

View Details

In our latest episode of Security Nation, we talk with Katie Ledoux about her unconventional journey into the cybersecurity industry—from her marketing agency days to her time at Rapid7, to her current role as Head of Information Security at Starburst Data. Katie talks about imposter syndrome, what it was like to "start over" in her career,  the importance of contributions from non-technical roles—and, of course, what she would want to see out of a "Hackers" sequel.

Stick around for our Rapid Rundown, where it's "All Exchange, all the time," in the wake of Microsoft's four critical bugs. Tod and Jen also discuss the recent Github controversy surrounding the ban of exploit code.

View Details

In this week's episode of Security Nation, we interview Adrien Ogee, COO of the CyberPeace Institute.  He discusses what it was like to launch and staff a brand-new nonprofit during the COVID-19 pandemic, and how his team worked to get the cybersecurity industry to trust them and get involved. Adrien also talks about the CyberPeace Institute's recently released "Playing With Lives: Cyberattacks on Healthcare Are Cyberattacks on People" report.

Stick around for our Rapid Rundown, where Tod discusses the National Cybersecurity Center's recently released Cyber Action Plan, a short questionnaire that generates actionable recommendations for shoring up your security. He also talks through Portswigger's recently published list of the top 10 web hacking techniques of 2020. 

View Details

In our latest episode of Security Nation, Ryan Weeks joined the podcast to discuss deploying thousands of assets into a hostile environment: the home offices of workers everywhere as they were forced remote amidst the pandemic. He’ll discuss how he balances privacy expectations with necessary regulations of workers’ computers and phones as they go remote.

We’ll also talk about managing an attack surface you don’t understand as well as how lack of transparency can lead to security organizations earning bad reputations. Plus why Jen thinks the work-from-home culture is here to stay, and what organizations can do to prepare.

View Details

In our latest episode of Security Nation, Steve Ragan joined the podcast to discuss his unlikely journey from reluctant security expert to journalist. For Steve, having the tech knowledge is important, but so is crafting a good story.

We take deep dives on topics like where the industry was in the ‘90s plus the unique way he approaches Akamai’s “The State of the Internet” report (and their own podcast). We’ll hear why writing with empathy is a foundation of Steve’s process when tackling deeper technical subjects. Also, the joys of shameless self-promotion...

Stick around for our Rapid Rundown, where we get quite the rapid rundown of three big events in security: North Korea’s campaign targeting security researchers, the takedown of the Emotet botnet, and (most importantly) the long-awaited cracking of Tod’s seven-year-old Dogecoin CTF.

View Details

https://community.signalusers.org/t/signal-should-warn-users-who-are-likely-using-insecure-ime-apps/10272

View Details

https://www.ncsc.gov.uk/cyberaware/home

View Details

In our latest episode of Security Nation, Rick Holland joined the podcast to discuss how his past informs his present, particularly when it comes to sourcing and hiring the best talent. Rick elaborates on how a lack of direct reports—for several years across multiple companies—led to a bit of imposter syndrome when he became CISO at Digital Shadows and suddenly was tasked with staffing and managing a team. Sometimes smaller talent pools can lead to inspired hiring choices.

Stick around for our Rapid Rundown, where Tod delves into Samy Kamkar's NAT slipstreaming mechanism in which an attacker can trick a router into opening straight-shot ports to any listening service on a machine.

View Details

In our most recent episode of Security Nation, we spoke with Maria Barsallo Lynch, Executive Director of the Defending Digital Democracy Project (D3P) at the Belfer Center for Science and International Affairs at the Harvard Kennedy School, about her work informing election officials of the rise of misinformation and disinformation campaigns centered around elections. Stick around for the Rapid Rundown, where Tod cautions against panicking if (completely normal) disruptions occur on Election Day.

View Details

In our latest episode of Security Nation, we are joined by a rising star in Stanford University’s junior class: Jack Cable. We discuss everything from hacking the Pentagon in high school to ensuring progress in election security beyond just voting machines today. Stick around for our Rapid Rundown, where Tod ditches his talk about the FBI's disinformation campaigns warning to discuss what really matters—a potential "Hackers" movie reboot. Hey, we have priorities!

View Details

In our latest episode of Security Nation, we are joined by Christian Wentz, CEO, CTO, founder of Gradient, and multiple Ph.D holder. From an electrical-engineering-applied-to-neuroscience background to a privacy and data protector present, we discuss what it’s like to thread the needle between internet profitability and end-user privacy. There’s technology, there’s politics, there’s policy, and there’s Tod getting very excited about code.

Stick around for our Rapid Rundown, where Tod talks through CVE-2020-1472, a CVSS-10 privilege escalation vulnerability in Microsoft’s Netlogon authentication process that the paper's authors christened “Zerologon.”

View Details

In our latest episode of Security Nation, Dave Kennedy, founder of the cybersecurity firms TrustedSec and Binary Defense, stopped by to discuss how he’s staying busy while working from home during the pandemic. Wrangling dogs and keeping his skills sharp on Red Team engagements are a major part of the story. Stick around for our Rapid Rundown, where Tod talks about a fascinating attack he learned about at virtual Black Hat called EtherOops, as well as implications around election security that were discussed during the event.

View Details

On this week’s episode of Security Nation, Joe FitzPatrick, a lead researcher at securinghardware.com, discusses what it takes to run a successful hardware training session virtually—from organizing equipment logistics to audience engagement, and more.

View Details

Biohacking Village Executive Director Nina Alli joins the Rapid7 team this week to discuss the intersection of tech and medicine on our latest episode of Security Nation. Stick around for our Rapid Rundown, where Tod discusses the two vulnerabilities that plagued infosec professionals over the holiday weekend.

View Details

This week’s episode of Security Nation features Art Manion, Vulnerability Analysis Technical Manager at CERT Coordination Center. Join us as we discuss common API, network topologies, and the quickly evolving world of vulnerability reporting. Stick around for our Rapid Rundown, where Tod talks through the recent bug in the Samsung Quram image processor.

View Details

Katie Moussouris, CEO and Founder of Luta Security, joins us on this week’s episode of Security Nation to discuss vulnerability disclosure, bug bounties, and building systems that support sustainable security. Stick around for our Rapid Rundown, where Tod talks through the recent bug in the Samsung Quram image processor.

View Details

On this week’s episode of Security Nation, Josh Corman and Audra Hatch of I Am The Cavalry share insights into the software bill of materials (SBoM) and software transparency. Stick around for our Rapid Rundown, where Tod breaks down the latest iPhone bug that wasn’t and Sophos bug that was.

View Details

On our latest episode of Security Nation, we caught up with Casey Ellis, founder and CTO at Bugcrowd. Joining us during the 2020 RSA Conference, he takes the time to discuss normalizing vulnerability disclosure, the safe harbor debate, and the legal implications of crowdsourced security testing.

Stick around for our Rapid Rundown, where Tod breaks down the recent controversy on online vs. mail-in voting, and gives the inside scoop on Rapid7’s newest project, AttackerKB.

View Details

In this week’s episode of Security Nation, we had the pleasure of speaking with Stephanie Helm, director of the MassCyberCenter. In this interview, we discuss how she went from working in the Navy to becoming the director of this new initiative in Massachusetts and how her team is helping municipalities develop incident response plans and getting buy-in and budget for security amidst other priorities.

Stick around for the Rapid Rundown, where Tod chats about Recog, Rumble, and the concept of contact tracing amid the COVID-19 pandemic. 

View Details

On this week’s episode of Security Nation, we spoke with John Strand, CEO of Black Hills Information Security, about how his team works remote, how they created a virtual event in just three days amid the COVID-19 pandemic and now teach others to do the same, and his predictions on the future of events. Stick around for our Rapid Rundown, where Tod explains why Zoom’s recent cybersecurity woes might not be as bad as recent news has made them seem.

View Details

In a recent episode of Rapid7’s podcast, Security Nation, we talked with Jonathan Cran, Head of Research at Kenna Security, about his side project, Intrigue, and how security professionals are spending their time while on coronavirus lockdown. And, in our Rapid Rundown news segment, Tod and Jen discuss electronic surveillance and contact tracing in the time of COVID-19.

View Details

https://gist.github.com/todb-r7/7c2c6487902c57981732124724a2ae44

View Details

How do you turn a small security conference with friends into a phenomenon? Just ask Nick Percoco! In our latest episode of Security Nation, we sit down with the founder of THOTCON to chat about how he came up with the idea for the Chicago-based conference, the challenges he has faced over the years, and how the conference has evolved over time to become what it is today.

View Details

Please be advised the following podcast contains sensitive subject matter.

In this week’s episode of Security Nation, we sit down with Chris Hadnagy, CEO and founder of the Innocent Lives Foundation, about the charity’s work in unmasking anonymous online predators to help bring them to justice. The foundation leverages a network of OSINT-savvy volunteers to uncover people who produce and profit from child pornography and those who traffic children in order to bring those findings to members of federal and local law enforcement. Throughout the podcast, Chris talks about what inspired him to start this charity, what it took to get other people involved, how the program works, the importance of maintaining volunteers’ mental well-being, and how interested parties can get involved.

Stick around for our Rapid Rundown, where Tod highlights a few vulnerabilities that didn’t get their time in the spotlight after the recent Patch Tuesday announcement.

View Details

In our latest episode of Security Nation, we talk to Tod Beebe, the Information Security Officer for an oil and gas company in Texas. Todd breaks down how he leveraged the MITRE ATT&CK framework to build an automated threat simulation system that enabled his organization to conduct daily threat simulation to validate their detective and preventive controls.

View Details

In honor of the 10-year anniversary of Rapid7’s acquisition of Metasploit, our latest episode of Security Nation features an interview with its founder, HD Moore. In it, HD gives his opinion on Metasploit’s current state and breaks down his latest project, Rumble, which makes it easy to discover what types of devices are on your network.

View Details

In this episode of Security Nation, we chat with Oliver Day about his experience embedding security into the engineering team at a medium-sized publisher. Oliver discusses the importance of understanding other people’s roles and what matters to them, and how that helps drive security efforts.

Also, join Tod for the Rapid Rundown, where he digs into the latest BlueKeep attacks in everyone’s favorite segment, “BlueKeep Watch.”

View Details

In this episode of Security Nation, we sit down with Mark Geeslin, senior director of product security at Asurion, to talk about his success in building the organization’s Security Mavens program to create a culture of security. Learn about the program, how his unique approach to bringing on members has kept momentum going, and why he thinks getting buy-in from the top early was a key component to Security Mavens’ success. 

Also, in this episode’s Rapid Rundown, Tod talks about the various VPN breaches that were reported in mid-October and muses on why people use VPNs to begin with.

View Details

In this episode of Security Nation, we speak with Rob Graham, founder of Errata Security Consultancy, well-known security blogger, and soon-to-be book author. In it, he talks about the process of creating (and naming!) BlackICE, and his new efforts to write a book “out of spite” to right the security wrongs he is seeing in the industry. Rob also shares some of his writing process and advice for others looking to take on similar projects.

Also, join Tod for the Rapid Rundown where he discusses how security pros can weigh in on election security through the Election Assistance Commission’s 2020 Election Administration and Voting Survey (2020 EAVS) and IT-ISAC’s request for information in the Election Industry SIG. Tod also reveals some key findings from Rapid7’s latest Industry Cyber-Exposure Report (ICER), which examines the level of exposure in top German organizations.

View Details

Security Nation returns this week with a new episode that's all about collaboration. We are joined by Katie Trimble of the Department of Homeland Security and Chris Coffin of MITRE for a discussion about their contribution to the CVE Project. The two talk how they got their start in their respective organizations, why the CVE Project is so important for security professionals, challenges they've faced to get this project off the ground and optimize their operations, and how others can pitch in as a CVE Numbering Authority (CNA). 

You'll also hear from Tod in our Rapid Rundown, where he compares and contrasts the the InfoSec world's response to the vBulletin and Internet Explorer zero-days this past week, and (as usual) brings you the latest in our BlueKeep Watch.

View Details

In this episode of Security Nation, Richard Kaufmann discusses what it took to drive digital transformation and improve security approches at Amedisys, a home health, hospice, and personal care provider. He dives into what inspired him to join Amedisys and help further their mission, why security works best when it's not seen, tactics he's learned to help empower other members on his team, and what his favorite dinosaur hacker movie is.

In our Rapid Rundown segment, you'll also hear Tod and Jen run through the biggest security news of the week, including our continued BlueKeep watch and the security implications of phone number-based security measures. 

We publish new podcast episodes every two weeks, so stay tuned for future episodes, and if you like what you hear, please subscribe below! Our next podcast will be released on Friday, Sept. 27.

View Details

In this episode of Security Nation, we chat with Wendy Nather, head of advisory CISO services at Duo Security, about her work bringing awareness around the unspoken issue of the Security Poverty Line (aka, how difficult it is for organizations to build effective security programs when they lack the resources to make it happen). Wendy talks about how budget, expertise, capability, and influence can influence an organization’s security standing, the issues that arise when security pros can’t agree on what’s needed to be “secure,” and the importance of empathy in understanding why organizations may make decisions that are considered less secure.

In our Rapid Rundown, Tod and Jen share their biggest takeaways from Black Hat and DEF CON and discuss being on "BlueWatch" (cue the "Baywatch" theme song) for RDP vulnerabilities such as DejaBlue.

View Details

In this episode, Beau Woods of I Am the Calvary, the Atlantic Council, and Stratigos Security and Meg King of the Wilson Center discuss their mission to improve collaboration between policymakers and the security community and better educate congressional staff on industry issues. Central to this mission is immersing congressional staff in the tech world by having them travel to Hacker Summer Camp in Las Vegas so they can learn and absorb all things cybersecurity.

Learn what it takes to put a program like this together, what challenges Beau and Meg have encountered along the way, and what advice they would give people who want to get involved and work with policymakers.

We also chat with Patrick Kiley of Rapid7 about his recently released research on the security of CAN bus systems in small aircraft, and Tod breaks down what you need to know about RDP and BlueKeep.

View Details

In this podcast, David Rogers breaks down his journey into the world of security, and how his IoT security standards got him recognized by the Queen of England. Tod and Jen also zoom through the recent Zoom vulnerability disclosure, and discuss what to look forward to in Las Vegas during Hacker Summer Camp.

View Details

In this episode of Security Nation, we catch up with Lee Brotherston, director of security at IoT startup ecobee, to chat about what it takes to launch a security program and get buy-in from leadership.

View Details

In this episode of Security Nation, we sit down with Zate Berg, senior manager of security at Indeed.com, to discuss how he and his team avoided becoming a bottleneck in their software engineering team’s high-velocity process by integrating in automated application security. Zate shares his successes, challenges, and learnings for building a scalable, progressive appsec process.

We wrap up with our "Rapid Rundown," in which Tod Beardsley, director of research at Rapid7, highlights the top three cybersecurity headlines you should be paying attention to this week.