In this episode of the podcast, host Paul Roberts speaks with Colin O'Flynn, CTO and founder of the firm NewAE about his work to patch shoddy software on his home's electric oven - and the bigger questions about owners rights to fix, tinker with or replace the software that powers their connected stuff.
The post Black Hat: Colin O’Flynn On Hacking An Oven To Make It Stop Lying first appeared on The Security Ledger with Paul F. Roberts.
The post Black Hat: Colin O’Flynn On Hacking An Oven To Make It Stop Lying appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 250: Window Snyder of Thistle on Making IoT Security Easy * Forget the IoT. Meet the IoZ: our Internet of Zombie things * Attacks on APIs demand a Security Re-Think
In this Spotlight podcast interview, David Monnier of Team Cymru talks about the evolution of the threat intelligence into actionable and target specific “threat reconnaissance.”
The post Spotlight Podcast: Are you ready for Threat Reconnaissance? first appeared on The Security Ledger with Paul F. Roberts.
The post Spotlight Podcast: Are you ready for Threat Reconnaissance? appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Spotlight: Making the Most of Cyber Threat Intelligence with Itsik Kesler of KELA * Spotlight: SIEMs suck. Panther is out to change that. * Episode 249: Intel Federal CTO Steve Orrin on the CHIPS Act and Supply Chain Security
Host Paul Roberts speaks with Boyd Multerer, the CEO and founder of Kry10, which has made a secure OS for the Internet of Things.
The post Episode 251: Kry10 CEO Boyd Multerer on building a secure OS for the IoT appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 250: Window Snyder of Thistle on Making IoT Security Easy * Forget the IoT. Meet the IoZ: our Internet of Zombie things * Spotlight: Traceable CSO Richard Bird on Securing the API Economy
Getting a start-up off the ground isn’t easy in the best of times. Now imagine doing it just as a global pandemic is shutting down society...and the economy. Our guest this week, Josh McCarthy of Revelstoke Security, did it and lived to tell the tale.
The post Episode 246: SOARing out of Lockdown with Revelstoke Security appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 244: ZuoRAT brings APT Tactics to Home Networks * Episode 243: The CSTO is a thing- a conversation with Chris Hoff of LastPass * Episode 242: Hacking the Farm (and John Deere) with Sick Codes
Six decades in, password use has tipped into the absurd, while two-factor authentication is showing its limits. We talk with Matt Salisbury of Honeybadger HQ, which is using AI and machine learning to re-imagine knowledge-based authentication.
The post Episode 245: How AI is remaking knowledge-based authentication appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 244: ZuoRAT brings APT Tactics to Home Networks * Episode 243: The CSTO is a thing- a conversation with Chris Hoff of LastPass * Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen
In this episode of the Security Ledger podcast, brought to you by ReversingLabs, we interview Danny Adamitis (@dadamitis) of Black Lotus Labs about the discovery of ZuoRAT, malware that targets SOHO routers – and is outfitted with APT-style tools for attacking the devices connected to home networks. As always, you can check our full conversation in our latest Security Ledger podcast at Blubrry. You can also listen to it on iTunes and Spotify. Or, check us out on Google Podcasts, Stitcher, Radio Public and more. Also: if you enjoy this podcast, consider signing up to receive it in your email. Just point your web browser to securityledger.com/subscribe to get notified whenever a new podcast is posted. [MP3] Cyber attacks on small office and home office (or SOHO) routers aren’t new. Back in 2016, the malware known as Mirai made headlines across the world by infecting hundreds of thousands of weekly protected SOHO routers and DVR devices and stringing them into […]
The post Episode 244: ZuoRAT brings APT Tactics to Home Networks appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen * Episode 241: If Its Smart, Its Vulnerable a Conversation wit Mikko Hyppönen * Episode 240: As Stakes Of Attacks Grow, Can Cyber Policy “Shift Right”?
Paul talks with Chris Hoff the Chief Secure Technology Officer at LastPass about the CSTO role and the security implications of “software eating the world.”
The post Episode 243: The CSTO is a thing- a conversation with Chris Hoff of LastPass appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen * Episode 241: If Its Smart, Its Vulnerable a Conversation wit Mikko Hyppönen * Episode 237: Jacked on the Beanstalk – DeFi’s Security Debt Runs Wide, Deep
In our latest podcast, Paul caught up with Sick Codes (@sickcodes) to talk about his now-legendary presentation at the DEF CON Conference in Las Vegas, in which he demonstrated a hack that ran the Doom first person shooter on a John Deere 4240 touch-screen monitor.
The post Episode 242: Hacking the Farm (and John Deere) with Sick Codes appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* DEF CON DOOM Patrol: Deere Jailbreak Raises Questions on Security, Competition * Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen
We speak with Mikko Hyppönen on the sidelines of the DEF CON Conference in Las Vegas to talk about his new book, “If its Smart it Vulnerable."
The post Episode 241: If Its Smart, Its Vulnerable a Conversation with Mikko Hyppönen appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 241: If Its Smart, Its Vulnerable a Conversation wit Mikko Hyppönen * Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * DEF CON DOOM Patrol: Deere Jailbreak Raises Questions on Security, Competition
In this episode of the podcast (#240) Lauren Zabierek, the Executive Director for the Cyber Project at the Belfer Center at Harvard’s Kennedy School joins us to talk about the need for a re-think of national cybersecurity preparedness, as major hacks like the attack on Colonial Pipeline put the focus on resilience and public safety.
The post Episode 240: As Stakes Of Attacks Grow, Can Cyber Policy “Shift Right”? appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 239: Power shifts from Russia to China in the Cyber Underground * Episode 238: Robots Are The Next Frontier In Healthcare Cyber Risk
An “everywhere,” hybrid workforce is no longer concept, but reality. But securing hybrid workplaces requires big changes to how IT security gets done, argues Jason Lee, the CISO of Zoom in this Expert Insight.
The post Hybrid Work Is Here: Is Your Security Strategy Ready for It? appeared first on The Security Ledger with Paul F. Roberts.
Related Stories* Tapping into the Power of the Security Community * The Future of Attack Surface Management: How to Prepare * The Concerning Statistics About Mental Health in Cybersecurity
Naomi Yusupov, a Chinese Intelligence Analyst at the threat intelligence firm CyberSixGill talks to host Paul Roberts about that company’s new report: The Bear and the Dragon: Analyzing the Russian and Chinese Cybercriminal Communities.
The post Episode 239: Power shifts from Russia to China in the Cyber Underground appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 238: Robots Are The Next Frontier In Healthcare Cyber Risk * Episode 236: Cyberwar Takes A Back Seat In Ukraine (For Now)
In this episode of the podcast (#238) we speak with Daniel Brodie, the CTO at the firm Cynerio. about his firm’s discovery of a string of critical security flaws in an autonomous medical robot, TUG, that is already deployed in hundreds of clinical settings and the growing issue of medical device insecurity and cyber risks to healthcare providers.
The post Episode 238: Robots Are The Next Frontier In Healthcare Cyber Risk appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 235: Justine Bone of MedSec on Healthcare Insecurity * Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Cyber Attack Halts Production at Ag Equipment Maker AGCO Fendt
The hack of Beanstalk is just the latest major compromise of a decentralized finance (DeFi) platform. In this podcast, Jennifer Fernick of NCC Group joins me to talk about why DeFi’s security woes are much bigger than Beanstalk.
The post Episode 237: Jacked on the Beanstalk – DeFi’s Security Debt Runs Wide, Deep appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 230: Are Vaccine Passports Cyber Secure? * Episode 235: Justine Bone of MedSec on Healthcare Insecurity * Tapping into the Power of the Security Community
we sit down with Christian Sorenson, the former lead of the international cyber warfare team at US Cyber Command and CEO of cybersecurity firm, SightGain, to talk about what we’ve learned so far from Russia’s war in Ukraine, and what may be coming next.
The post Episode 236: Cyberwar Takes A Back Seat In Ukraine (For Now) appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 234: Rep. Jim Langevin on Cyber Policy in an Age of Political Polarization * Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert
Seven in 10 SOC analysts say they are “burned out.” Six in 10 plan to leave their job “in the next year.” Tines CEO Eoin Hinchy says https://feeds.feedblitz.com/-/41936664/0/securityledgerpodcasts-code automation may be a way to reduce the burhttps://feeds.feedblitz.com/-/41936664/0/securityledgerpodcastsut and retain top talent.
The post How to Bring the Power of No-Code Security Automation to Your Team in 2022 appeared first on The Security Ledger with Paul F. Roberts.
Related Stories* Why Security Practitioners Are Unhappy With Their Current SIEM * State of Modern Application Security: 6 Key Takeaways For 2022 * Tapping into the Power of the Security Community
In this episode of the podcast (#235) Justine Bone, the CEO of Medsec, joins Paul to talk about cyber threats to healthcare organizations in the age of COVID. Justine’s firm works with hospitals and healthcare organizations to understand their cyber risk and defend against attacks, including ransomware.
The post Episode 235: Justine Bone of MedSec on Healthcare Insecurity appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 234: Rep. Jim Langevin on Cyber Policy in an Age of Political Polarization * Tapping into the Power of the Security Community
In this episode of the podcast (#234) US Representative Jim Langevin (D-RI), joins Paul to talk about the flurry of legislation passed on Capitol Hill in recent months to boost the U.S.’s cyber defenses.
The post Episode 234: Rep. Jim Langevin on Cyber Policy in an Age of Political Polarization appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage * Episode 235: Justine Bone of MedSec on Healthcare Insecurity
Massive growth in Zoom’s customer base as a result of the COVID 19 pandemic brought new business - but also new challenges and security requirements. Establishing a CISO Council gave those customers a voice and a seat at the table, writes CISO Jason Lee.
The post Tapping into the Power of the Security Community appeared first on The Security Ledger with Paul F. Roberts.
Related Stories* Why Security Practitioners Are Unhappy With Their Current SIEM * State of Modern Application Security: 6 Key Takeaways For 2022 * Episode 230: Are Vaccine Passports Cyber Secure?
What does 2022 have in store? Dean Coclin of DigiCert speaks with host Paul Roberts about the trends that will shape the New Year, from cloud sovereignty to the growing reliance on PKI to secure digital identities, DEVOPs and more.
The post Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 230: Are Vaccine Passports Cyber Secure? * Tapping into the Power of the Security Community * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion
Host Paul Roberts speaks with Marc Blackmer of ShardSecure about that company’s new approach to protecting data at rest, which relies on fragmenting and scattering data to make it impossible to steal.
The post Spotlight: ShardSecure on Protecting Data At Rest Without Encryption appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * State of Modern Application Security: 6 Key Takeaways For 2022 * Tapping into the Power of the Security Community
In this episode of the podcast (#233) Mark Stanislav, a Vice President at the firm Gemini, joins Paul to talk about what went wrong with disclosure of Log4Shell, the critical, remote code execution flaw in the Log4j open source library. Mark talks about how the Internet community can come together ahead of the next vulnerability to make sure the mistakes that are evident in the response to Log4j aren’t repeated.
The post Episode 233: Unpacking Log4Shell’s Un-coordinated Disclosure Chaos appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Feel Good Ukraine Tractor Story Highlights Ag Cyber Risk * Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting
In this episode of the podcast (#232), Tomislav Peričin of the firm ReversingLabs joins us to talk about Log4Shell, the vulnerability in the ubiquitous Log4j Apache library. Tomislav tells us why issues related to Log4j won’t be going away anytime soon and how organizations must adapt to deal with the risk it poses.
The post Episode 232: Log4j Won’t Go Away (And What To Do About It.) appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 233: Unpacking Log4Shell’s Un-coordinated Disclosure Chaos * Episode 235: Justine Bone of MedSec on Healthcare Insecurity * Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security
Rodney Petersen, the director of the National Initiative for Cybersecurity Education (NICE) talks about the massive shortage of information security workers at the United States - estimated at more than 400,000 workers.
The post Episode 231: Solving the US’s Endemic Cybersecurity Worker Shortage appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security * Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert * Episode 232: Log4j Won’t Go Away (And What To Do About It.)
Mackenzie Jackson, the Developer Advocate at GitGuardian joins Paul to discuss how “secrets sprawl” on sites like GitHub threatens software supply chains.
The post Spotlight: How Secrets Sprawl Undermines Software Supply Chain Security appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Spotlight: Your IoT Risk Is Bigger Than You Think. (And What To Do About It.) * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion
In this episode of the podcast (#230) Siddarth Adukia, a regional Director at NCC Group, joins host Paul Roberts to talk about the (cyber) risks and (public health) rewards of vaccine passport systems: how they work, how they can be compromised and what to do about it.
The post Episode 230: Are Vaccine Passports Cyber Secure? appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Spotlight: COVID, Cloud Sovereignty and Other 2022 Trends with DigiCert * Tapping into the Power of the Security Community * Spotlight: COVID Broke Security. Can We Fix It In 2022?
We talk with Casey Ellis, founder and CTO of BugCrowd about how the market for software bugs has changed since the first bug bounty programs emerged nearly 20 years ago, and what’s hot in bug hunting in 2021.
The post Episode 229: BugCrowd’s Casey Ellis On What’s Hot In Bug Hunting appeared first on The Security Ledger with Paul F. Roberts.
Click the icon below to listen. Related Stories* Episode 233: Unpacking Log4Shell’s Un-coordinated Disclosure Chaos * Episode 232: Log4j Won’t Go Away (And What To Do About It.) * Spotlight: Automation Beckons as DevOps, IoT Drive PKI Explosion