F5 Security Podcasts is a collaborative partnership between DevCentral (F5's User Community), F5 Security Incident Response Team and F5 Labs.
Our flagship show, 'This Month In Security,' is a long-format podcast on industry news and to disseminate data gathered by our security researchers.
We will also produce content for F5 Security disclosures - primarily Quarterly Security Notifications and Out of Band announcements.
In Episode 21, we change our name! Welcome AppSec Monthly, goodbye This Month In Security. In addition to that new in April of 2024, DevCentral's Aubrey King catches up with Semgrep's Jonathan Werrett to talk about how the AI phenomenon changes the game for Red and Blue Teamers out there in the security world. Also, Aubrey catches up with DevCentral OG, Peter Silva, to talk about 5g security and app isolation for security. Aaron Brailsford herds those cats named David Warburton and Malcolm Heath for our monthly roundtable, as well!
DevCentral's Aubrey King is joined by Dave Warburton, Malcolm Heath and Aaron Brailsford this month for the roundtable and he shares a conversation with Dan Barahona about the APISec University 2024 API Security Market Review they just published and shares the news about APISec Con, coming up on May 22. There's also a teaser of an #AppWorld2024 AI API Security panel conversation between Aubrey, Dan, Corey Ball and Cameron Delano.
In Episode 19 of This Month In Security, Aubrey King catches back up with Tashaffi Samin Yeasar to talk about her daily grind and an IoT coder who's using AI at the edge and some of the security implications of Edge AI. Also, Byron McNaught jumps into the monthly roundtable with Aaron Brailsford and David Warburton, where they talked a bit about AI and deepfakes, as well as some of the latest Ransomware news out there.
This Month In Security, Aubrey King gets to talk to DevCentral MVP Daniel Wolf about how he recommends customers build WAF policy from SBOM. Aaron Brailsford shares the roundtable with Malcolm Heath and Sander Vinberg. Also, we get a sample from This Week In Security.
This week in security, our editor is AaronJB, who brings news of a VMWare exploit that might be older than Aubrey! Also, countless exploits and some amazing videos from The 37th Chaos Communication Congress.
Read the full article here: https://community.f5.com/t5/technical-articles/time-to-exploit-and-large-scale-breaches-jan-15th-21st-2024-f5/ta-p/327201
This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.
This Week In Security, our editor is Jordan_Zebor, who shows the community about Github's Runner Poisoning, a cloud threat called F-Bot and an attack on Hadoop!
Read the full article here:
https://community.f5.com/t5/technical-articles/compromised-ci-cd-fbot-and-hadoop-attacks-jan-7th-14th-2023-f5/ta-p/326973
This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.
This Week In Security, our editor was Koichi and he brings us news about a faked public website, new Gmail Sender Guidelines, a GPS Spoofing attack and the OWASP Top 10 For Large Language Model Applications.
Read the full article here:
https://community.f5.com/t5/technical-articles/fake-website-gmail-guideline-gps-spoofing-owasp-llm-jan-1st-5th/ta-p/326724
This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.
Aubrey King recaps 2023 in a look back for the podcast before he's joined by Aaron Brailsford, Malcolm Heath and David Warburton to go over the F5 Labs 2024 Predictions report. Happy New Year to all of our listeners and viewers out there!
This Week In Security, our editor was Nagi, who filled us in on the Play Ransomware Advisory, the OpenSSH 9.6 release, the latest Bruce Schneier essay, Google's ending of geofence warrants via Google Maps and so much more!Read the full article here:https://community.f5.com/t5/technical-articles/ransomware-openssh-ai-and-trust-google-geofence-dec-10-17-2023/ta-p/325857This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.00:00 Introduction00:10 Play Ransomware00:31 OpenSSH 9.600:57 Bruce Schneier: AI & Trust01:19 Google Kills Geofence Warrants 01:34 Outro
This Week In Security for 11/27-12/3, 2023, can be found on F5 DevCentral here:https://community.f5.com/t5/technical-articles/exposed-hf-api-tokens-hacks-ms-news-dec-3-10-2023-f5-sirt-this/ta-p/325561This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.
This Week In Security for 11/20-11/26, 2023, can be found on F5 DevCentral here:https://community.f5.com/t5/technical-articles/once-more-with-feeling-nov-20-26-2023-f5-sirt-this-week-in/ta-p/324985This Week In Security is a contribution to DevCentral by the F5 Security Incident Response Team and you can find it in our Technical Articles section every week.
This Month In Security, Aubrey King and the crew try out a new show format. Aubrey catches up with Sandy Dunn, CISO, about her work on the AI Security And Governance Checklist. In addition, Sander talks to the roundtable about his latest contribution to Labs, The 2023 Identity Threat Report. David Warburton's back, as well, and sits in with Aaron Brailsford and malcolm Heath for the monthly roundtable. Strap On Those Earbuds!00:00 Movember01:26 Intro03:26 What Is Request Smuggling?10:08 November Roundtable34:48 2023 Identity Threat Report46:26 AI Security & Governance Checklist
This Month In Security, Aubrey King catches up with Ads on his involvement as a release lead for the OWASP Top Ten For Large Language Model Applications. Also, we hear from a fellow speaker at B-Sides Ottawa, Tashaffi Samin Yeassar, regarding her talk on Elder Care Security and how to pick a topic for your talk. Plus, Lori MacVittie joins the roundtable with Aubrey and Malcolm Heath.00:00 CyberSecurity Awareness Month Promo00:57 Introduction03:39 What's A "Release Lead?" Ask Ads!10:38 October's Roundtable w/ Lori MacVittie29:31 Security of ElderCare w/ Tashaffi Samin Yeasar34:21 Outro
This Month In Security, Aubrey King welcomes OWASP Top 10 for ML Applications Leads, Shain Singh and Sagar Bhure to find out more about the project. Sander Vinberg also shares his takeaways from the Vuln4Cast Colloquium and we welcome Malcolm Heath for a roundtable.00:00 Introduction01:31 Vuln4Cast 07:09 OWASP Top 10 for ML Apps19:07 RoundTable29:47 Outro
Join Aubrey King, from DevCentral, as he talks with a record number of guests - 8 - for August, 2023 This Month In Security! Topics are OpenSSF and "Hacker Summer Camp" in Las Vegas (B-Sides, BlackHat, Defcon), as well as the latest news. You'll hear from David Wheeler, from the Linux Foundation, Akira Brand, from Application Security Weekly podcast and F5'ers Buu Lam, Christine Abernathy, Trishan DeLanerole, Aaron Brailsford, Malcolm Heath and Sander Vinberg!00:00:00 Introduction00:02:55 Aubrey & Akira chat Ops and OpenSSF00:06:48 OpenSSF Update w/ David Wheeler00:24:11 B-Sides LasVegas & Defcon 2023 Report00:35:54 BlackHat 2023 Report00:43:12 Aubrey & Akira chat SecOps Perspectives00:46:13 The Latest CyberSecurity Buzz01:00:41 Outro
If you're hitting up BlackHat 2023, you're going to hear a LOT about Large Language Model security, which dominated the news this month in security. Also, Aubrey King talks with Jason Ross, from Rochester Institute of Technology and Jenn Carlson, from Apprenti, about cybersecurity apprenticeship options. 00:00 Introduction01:44 CyberSecurity Apprenticeship @ RIT06:26 Apprenti Skill Assessment14:16 Jason Ross on OWASP Top 10 for LLM16:19 The Month, In Review43:06 Outro
DevCentral's Aubrey King takes you through the (more than a) month of May (and June, too)in This Month In Security Episode 11. NXDOMAIN and Water Torture / Resource Exhaustion attacks against DNS are fairly prominent in an interview of Amina Mubeen, Security Support Engineer and with our newest Real Attack Story from DevCentral. Aaron Brailsford, Malcolm Heath and Sander Vinberg cover the latest interesting happenings.
This Episode, Aubrey King talks with Aaron Brailsford and Amina Mubeen about the latest happenings in security. He also meets up live with David Warburton, Sander Vinberg and Malcolm Heath, from F5 Labs in SanFrancisco at RSA 2023 to discuss conference perspectives and the Labs presentations this year. Strap on those earbuds!00:00 Introduction01:54 RSA Conference Recap27:40 The Cybersecurity Happenings45:04 Labs' Talks @ RSA54:54 Outro
Special guest, Ben Edwards, from The Cyentia Institute, joins Aubrey King, Aaron Brailsford and Sander Vinberg on This Month In Security for March, 2023. In addition to some of the latest security news, we focus on CVE, CVSS and the future of threat prediction research, plus we get to hear a tease on Ben and Sander's forthcoming RSA talk.00:00 Introduction: Ben Edwards03:22 Ben & Sander At RSA 05:20 Amazing MS Outlook Client Vuln!08:11 Aubrey's Solaris Confession09:30 Back To Outlook...10:43 WRT Exposure, How Long Is Long? 15:24 3CX VoIP Supply Chain Breach19:33 YouTube Takedown: Linus Tech Tips21:42 The CVE Report: Ben & Sander37:37 Exploit Prediction Scoring System40:23 Outro
Aubrey King, Aaron Brailsford and Malcolm Heath welcome special guest, Akira Brand, co-host of the Application Security Weekly podcast, for a chat this month about career paths, podcasting and the hottest news this month... in security.00:00 Introduction01:51 Akira on Application Security Weekly podcast04:58 Discussion on career paths17:58 Generalist vs. Specialist / Red vs. Blue32:17 LastPass continues... to affirm zero trust38:26 How secure is 'secure enough'? 43:02 F5 Labs' new DDoS report findings 47:16 News tidbits and out.
For the Month of January, 2023, Aubrey King sits down for a chat with Brian McHenry, Security PM, to talk about his role in starting the #Security B-Sides NYC Chapter and more, then Brian and Aubrey join Aaron Brailsford and David Warburton for the top of mind cybersecurity news from January.This Month In Security is a monthly, long-format, community driven technology Podcast, focused on malware, bots, dos and so much more in the realm of application security (appsec).00:00:00 Introduction00:01:24 Brian McHenry Intro 00:04:19 How Product Organizations Consume Governing Guidance00:09:12 Brian's Role With Security B-Sides NYC00:18:35 The Evolution of AppSec Architectures00:23:29 Breach Updates: LastPass Continues & More00:39:46 What Are Some Security Implications of ChatGPT?00:50:43 FBI Takes Down The Hive 00:57:34 F5 Labs Updates00:59:37 Outro
Aubrey King hosts the monthly security podcast with Aaron Brailsford & David Warburton. The final show of the year focuses on the three most critical segments of the year and a look at some predictions from F5 Labs' 2023 Predictions report.This Month In Security is a monthly, long-format, community driven technology Podcast, focused on malware, bots, dos and so much more in the realm of application security (appsec).::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::https://soundcloud.com/f5security::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::00:00 Introduction 01:12 ProxyNotShell Resurgence09:57 Quantum Security Impacts25:28 Android OEM App-Signing Keys Leaked33:06 Predictions Intro.33:59 MFA Will Become Ineffective 42:40 Software Repositories Become THE Target48:52 Outro
Aubrey King hosts the monthly security podcast with Aaron Brailsford, Sander Vinberg and Malcolm Heath. Discussion on the month's most relevant security happenings, including updates on guidance from CISA, a Dropbox breach, Supply Chain security and the SANS ICA Hyper-Encabulator!00:00 Introduction00:48 ANCIENT SQLite Vulnerability10:11 Latest CISA Supply Chain Guidance17:38 DropBox Breach and MFA Bypass26:44 Cranefly MS Logging C&C 35:35 SANS ICA HyperEncabulator37:14 Outro
This month's news includes some Supply Chain Security, Guidance from CISA and a worrisome UEFI BootkitOctober's feature story is Reseller Bots. What are they and how do they impact you? 00:00 Intro..01:25 CISA Guidance09:10 LofyGang Supply Chain News15:40 MS Exchange Zero Days23:27 Black Lotus UEFI BootKit 30:53 Labs Updates: Post-Breach, CIS34:04 Labs Feature: Reseller Bots42:23 Outro..
DevCentral's Aubrey King sits down with Aaron Brailsford, from F5 Security Incident Response Team (SIRT), Malcolm Heath and Sander Vinberg - both from F5 Labs - and break everything out, in-depth. In this episode, we talk about software supply chain security, the dangers of hard-coded credentials, package management, side-loading mobile applications and more. We also get to review and postulate on the latest data from F5 Labs' Sensor Intel Series, sampling CVE attempts at critical points on the internet backbone to understand the nature of attacks and how they're changing over time.00:00 Introduction01:25 High profile updates for Apple / Google02:20 Hard-Coded Credential Woes14:17 LastPass Breach21:52 Uber Breach28:52 Mudge Testimony36:10 F5 Labs SIS Report53:40 WRAP IT UP, B !!
Join DevCentral's Aubrey King and SIRT's Aaron Brailsford as they break down the past month in cybersecurity news in and around the industry!Associated content:https://community.f5.com/t5/technical-articles/f5-sirt-this-week-in-security-june-6th-to-19th-phishing-qnap/ta-p/297263https://community.f5.com/t5/technical-articles/f5-sirt-this-week-in-security-follina-zero-day-karakurt-agent/ta-p/296852https://community.f5.com/t5/technical-articles/apple-vmware-supply-chain-and-breaches-f5-sirt-this-week-in/ta-p/300079
DevCentral & SIRT Present: This Month In SecurityAubrey King hooks up with Aaron Brailsford to recap top stories for the month in F5 Security. This month we discuss some academic processor side-channel vulnerabilities, as well as covering UEFI vulnerabilities, some rather alarming disclosures in a popular data center application and much more!00:00 Introduction02:26 Academics: New Processor Vulnerabilities!14:23 Stolen Credentials22:27 Hardware Hardships36:02 Peace Out!
If you're hitting up BlackHat 2023, you're going to hear a LOT about Large Language Model security, which dominated the news this month in security. Also, Aubrey King talks with Jason Ross, from Rochester Institute of Technology and Jenn Carlson, from Apprenti, about cybersecurity apprenticeship options.
DevCentral's Aubrey King takes you through the (more than a) month of May (and June, too)in This Month In Security Episode 11. NXDOMAIN and Water Torture / Resource Exhaustion attacks against DNS are fairly prominent in an interview of Amina Mubeen, Security Support Engineer and with our newest Real Attack Story from DevCentral. Aaron Brailsford, Malcolm Heath and Sander Vinberg cover the latest interesting happenings.
This Episode, Aubrey King talks with Aaron Brailsford and Amina Mubeen about the latest happenings in security. He also meets up live with David Warburton, Sander Vinberg and Malcolm Heath, from F5 Labs in SanFrancisco at RSA to discuss conference perspectives and the Labs presentations this year. Strap on those earbuds!
Special guest, Ben Edwards, from The Cyentia Institute, joins Aubrey King, Aaron Brailsford and Sander Vinberg on This Month In Security. In addition to some of the latest security news, we focus on CVE, CVSS and the future of threat prediction research, plus we get to hear a tease on Ben and Sander's forthcoming RSA talk.00:00 Introduction: Ben Edwards03:22 Ben & Sander At RSA 05:20 Amazing MS Outlook Client Vuln!08:11 Aubrey's Solaris Confession09:30 Back To Outlook...10:43 WRT Exposure, How Long Is Long? 15:24 3CX VoIP Supply Chain Breach19:33 YouTube Takedown: Linus Tech Tips21:42 The CVE Report: Ben & Sander37:37 Exploit Prediction Scoring System40:23 Outro
Aubrey King, Aaron Brailsford and Malcolm Heath welcome special guest, Akira Brand, co-host of the Application Security Weekly podcast, for a chat this month about career paths, podcasting and the hottest news this month... in security.
Aubrey King, Aaron Brailsford and David Warburton deliver the January events in security with special guest, Brian McHenry, co-founder of Security B-Sides NYC.This Month In Security is a monthly, long-format, community driven technology podcast, focused on malware, bots, dos and so much more in the realm of application security (appsec).
Aubrey King hosts the monthly security podcast with Aaron Brailsford & David Warburton. The final show of the year focuses on the three most critical segments of the year and a look at some predictions from F5 Labs' 2023 Predictions report.This Month In Security is a monthly, long-format, community driven technology Podcast, focused on malware, bots, dos and so much more in the realm of application security (appsec).
Aubrey King, from F5 DevCentral, has a chat with Aaron Brailsford, from F5 Security Incident Response Team, and Malcolm Heath and Sander Vinberg, from F5 Labs. This month, we talk about continued guidance from CISA and SBOMs, a fairly noteworthy breach give a quick nod to the SANS ICS Hyper-Encabulator and more..
On November 16th, F5 issued a coordinated disclosure with Rapid7 regarding the BIG-IP and BIG-IP product families.
This Month In Security is a collaboration from DevCentral, F5's Community, F5 Security Incident Response Team and F5 Labs.This summary for September covers news around a couple of high profile Breaches at Uber and LastPass, as well as the Twitter testimony by Mudge and brand new data from F5 Labs' Sensor Intel Series! It was initially published on https://YouTube.com/DevCentral at this link: https://youtu.be/eUN_gvMaV0c
This Month In Security is a partnership between F5 Labs, F5's Security Incident Response Team and DevCentral, F5's Community. The intent is to increase security awareness