Security Weekly Podcast Network (Audio)

Security Weekly Productions
undefined
Dec 9, 2025 • 35min

Hypnotoad, AI Galore, Storm-0249, DocuSign, Broadside, Goldblade, Aaran Leyland... - SWN #536

We've got: Hypnotoad, AI Galore, Storm-0249, DocuSign, Broadside, Goldblade, Ships at Sea, Sora, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-536
undefined
Dec 9, 2025 • 1h 8min

Making OAuth Scale Securely for MCPs - Aaron Parecki - ASW #360

The MCP standard gave rise to dreams of interconnected agents and nightmares of what those interconnected agents would do with unfettered access to APIs, data, and local systems. Aaron Parecki explains how OAuth's new Client ID Metadata Documents spec provides more security for MCPs and the reasons why the behavior and design of MCPs required a new spec like this. Segment resources: https://aaronparecki.com/2025/11/25/1/mcp-authorization-spec-update https://www.ietf.org/archive/id/draft-ietf-oauth-client-id-metadata-document-00.html https://oauth.net/cross-app-access/ https://oauth.net/2/oauth-best-practice/ Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-360
undefined
Dec 8, 2025 • 1h 35min

Fix your dumb misconfigurations, AI isn't people, and the weekly news - Wendy Nather, Danny Jenkins - ESW #436

Interview with Danny Jenkins: How badly configured are your endpoints? Misconfigurations are one of the most overlooked areas in terms of security program quick wins. Everyone freaks out about vulnerabilities, patching, and exploits. Meanwhile, security tools are misconfigured. Thousands of unused software packages increase remediation effort and attack surface. The most basic misconfigurations lead to breaches. Threatlocker spotted this opportunity and have extended their agent-based product to increase attention on these common issues. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more! Interview with Wendy Nather: Recalibrating how we think about AI AI and the case for toxic anthropomorphism. When Wendy coined this phrase on Mastodon a few weeks ago, I knew that she had hit on something important and that we needed to discuss it on this podcast. We were lucky to find some time for Wendy to come on the show! Quick note: while this was not a sponsored segment, 1Password IS currently a sponsor of this podcast. That doesn’t really change the conversation any, except that I have to be nice to Wendy. But why would anyone ever be mean to Wendy??? Weekly Enterprise News Finally, in the enterprise security news, Dozens of funding rounds over the past two weeks Windows is becoming an Agentic OS? We talk about what that actually means. Some great free tools the latest cyber insurance trends we analyze some recent breaches the stop hacklore campaign some essays worth reading and a how a whole country dropped off the internet, because someone forgot to pay a GoDaddy invoice All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-436
undefined
Dec 5, 2025 • 33min

Toilet Cams, N. Korea, Brickstorm, MCP, React2Shell, Proxmox, Metaverse, Josh Marpet - SWN #535

Dive into the world of North Korea's recruitment schemes that use AI and stolen identities. Learn about BrickStorm's backdoor threats targeting VMware and the risks tied to new AI interfaces. Discover the fallout from India's controversial government app mandate. Hear the buzz about critical React flaws exploited by groups linked to China. Plus, an entertaining live report from a wedding, a quirky discussion on a $600 Kohler toilet camera, and insights into the Metaverse's impact on business risks.
undefined
Dec 4, 2025 • 2h 11min

Holiday Hack Challenge, AI, Internet of Trash - Ed Skoudis - PSW #903

This week we welcome Ed Skoudis to talk about the holiday hack challenge (https://sans.org/HolidayHack). In the security news: Oh Asus Dashcam botnets Weird CVEs being issued CodeRED, but not the worm Free IP checking Internet space junk and IoT Decade old Linux kernel vulnerabilities Breaking out of Claude code Malicious LLMs Hacker on a plan gets 7 years Putting passwords into random websites NPM supply chains strike again LLMs will never be intelligent Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-903
undefined
Dec 3, 2025 • 1h 6min

Shadow Risks in SaaS, Cybersecurity Market Has Lost Its Mind, and Rise of the CTrO - Mike Puglia - BSW #424

Mike Puglia, General Manager of Kaseya Labs, dives into the growing security blind spots in popular SaaS platforms like Microsoft 365 and Salesforce. He highlights how attackers are exploiting these vulnerabilities, particularly through hijacking tokens and misconfigured integrations. The conversation shifts to the crucial role of the Chief Trust Officer and the debate over reliance on big cloud providers. Mike also offers strategies for SMBs on managing SaaS security, along with the necessity for enhanced visibility across organizational apps.
undefined
Dec 2, 2025 • 36min

AI semantics, Calendly, Teams, Schmaltz, India, Antigravity, Scada, Aaran Leyland... - SWN #534

AI semantics, Calendly, GreyNoise, Teams, Schmaltz, India, Antigravity, Scada, Aaran Leyland, and More... Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-534
undefined
Dec 2, 2025 • 59min

Making TN Critical Infrastructure the Most Secure in the Nation - T. Gwyddon 'Data' ("Gwee-thin") Owen, James Cotter - ASW #359

For OT systems, uptime is paramount. That's a hard rule that makes maintaining, upgrading, and securing them a complex struggle. Tomas "Data" Owens and James Cotter discuss how Tennessee is tackling the organizational and technical challenges that come with hardening OT systems across the state. Those challenges range from old technology (like RS-232 over Wi-Fi!?) to limited budgets. They talk about the different domains where OT appears and provide some examples of how the next generation of builders and breakers can start learning about this space. Segment Resources: Free Cyber OT Training (INL): https://ics-training.inl.gov/ Free Cyber Hygiene Training (CISA): https://www.cisa.gov/cyber-hygiene-services Recommendations for network hardening (CISA): https://www.cisa.gov/shields-up More OT and ICS resources: https://github.com/biero-el-corridor/OTICSressource_list   Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-359
undefined
Dec 1, 2025 • 1h 43min

From Misconfigurations to Mission Control: Lessons from InfoSec World 2025 - Marene Allison, Dr. Ron Ross, Ryan Heritage, Patricia Titus, Perry Schumacher, Rob Allen - ESW #435

In a dynamic discussion, cybersecurity leaders share insights from InfoSec World 2025. Perry Schumacher explores challenges for mid-sized companies, emphasizing AI for efficiency and resilience. Maureen Allison introduces Security Control Management, advocating for automated oversight. Ryan Heritage discusses operationalizing security and insider risks, notably among Gen Z. Patricia Titus highlights the rise of AI phishing and innovative behavioral defenses. Dr. Ron Ross stresses the importance of secure hardware and community diversity in building a robust cybersecurity framework.
undefined
8 snips
Nov 28, 2025 • 42min

Dealing with loss, phone loss with Aaran, Doug, and Josh. - SWN #533

Aaron Leland, a security practitioner, and Josh Marpet, an expert in SIM swapping, delve into the crucial topic of mobile device security and strategies for handling phone loss. They share personal theft stories, highlighting the urgency of being prepared while traveling. The duo discusses immediate response tactics, from bricking phones to utilizing Find My iPhone. Practical advice includes using strong passcodes, protecting critical apps with biometrics, and having a disaster plan in place. Tune in for expert insights on safeguarding your digital life!

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app