

Shared Security Podcast
Tom Eston, Scott Wright, Kevin Tackett
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Episodes
Mentioned books

Oct 30, 2023 • 7min
How to Opt Out of CPNI Data Sharing
Did you know that your mobile phone provider can give data like phone numbers you’ve called and received, the time and date of those calls, and even your location data to their parent companies, affiliates, and agents? In this episode we show you how to opt out so you can stop your data from being being shared!
** Links mentioned on the show *
AT&T CPNI Opt Out
https://www.att.com/consent/cpni/
https://about.att.com/privacy/full_privacy_policy.html#CPNI
Verizon CPNI Opt Out
https://www.verizon.com/support/customer-cpni/
Alternatively for Verizon, you can also opt out by calling 1-800-333-9956 and follow the recorded directions. Or, you can call 1800-922-0204 to reach a Customer Service Representative who can process your opt-out for you.
T-Mobile Opt Out
https://www.t-mobile.com/privacy-center/education/phone-privacy
** Watch this episode on YouTube **
https://youtu.be/uA9tfay4bRU
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on X: https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post How to Opt Out of CPNI Data Sharing appeared first on Shared Security Podcast.

Oct 23, 2023 • 25min
Special Guest Jayson E. Street, Phantom Hacker Scams, 23andMe User Data For Sale
In milestone episode 300, Jayson E. Street (a renowned hacker, helper, and human who has successfully robbed banks, hotels, government facilities, and Biochemical companies on five continents) joins us to share what he’s been up to recently and to talk about his new role at Secure Yeti.
Next, we explore the alarming rise of ‘phantom hacker’ scams targeting the elderly. The FBI issues a stern warning about these evolving tech support scams that are draining the savings of unsuspecting seniors. We uncover the extent of the issue, with staggering victim losses and disturbing trends.
Finally, we unravel the unsettling revelation that private user data from 23andMe has been scraped and is up for sale, raising concerns about credential stuffing attacks, user privacy, and data security.
For our Patreon supporters, check out this week’s bonus episode where Jayson shares his recent gaming adventures in Starfield and No Man’s Sky! If you’re not a supporter yet, head to https://patreon.com/sharedsecurity to discover how you can access this exclusive content.
** Links mentioned on the show *
Follow and connect with Jayson Street
https://twitter.com/jaysonstreet
https://www.linkedin.com/in/jstreet/
https://jaysonestreet.com/
FBI warns of surge in ‘phantom hacker’ scams impacting the elderly
https://www.bleepingcomputer.com/news/security/fbi-warns-of-surge-in-phantom-hacker-scams-impacting-elderly/amp/
23andMe says private user data is up for sale after being scraped
https://arstechnica.com/security/2023/10/private-23andme-user-data-is-up-for-sale-after-online-scraping-spree/
https://twitter.com/RachelTobac/status/1711797959086801365
** Watch this episode on YouTube **
https://youtu.be/JIFSKbvvJ4w
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on X: https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Special Guest Jayson E. Street, Phantom Hacker Scams, 23andMe User Data For Sale appeared first on Shared Security Podcast.

Oct 16, 2023 • 18min
Educating the Next Cybersecurity Generation with Tib3rius
In this episode we explore the remarkable journey of Tib3rius, a web application hacking expert and content creator. In this engaging conversation, we discuss:
Tib3rius’ passion for community education and content creation. What fuels his desire to empower the next generation of cybersecurity professionals?
His expertise and enthusiasm for web application hacking, and we explore the transformative shifts in Application Security over recent years.
If you’re new to the industry and aspire to be a web application pentester, don’t miss the valuable insights Tib3rius has to offer.
Get the inside scoop on Tib3rius’ latest move to TCM Security and his courses, with a spotlight on his upcoming web application security pentesting course!
For our Patreon supporters, an extraordinary bonus episode awaits, where Tib3rius unveils two of his most astonishing hacks! This is a discussion you won’t want to miss. If you’re not a supporter yet, head to patreon.com/sharedsecurity to discover how you can access this exclusive content.
** Links mentioned on the show *
Follow Tib3rius on X
https://twitter.com/0xTib3rius
Subscribe to his YouTube channel and his live streams on Twitch
https://www.youtube.com/@Tib3rius
https://www.twitch.tv/0xtib3rius
** Watch this episode on YouTube **
https://youtu.be/o9VmqxnUD04
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on X: https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Educating the Next Cybersecurity Generation with Tib3rius appeared first on Shared Security Podcast.

Oct 9, 2023 • 27min
Your Car is a Privacy Nightmare, Password Creation Best Practices, Sony Hacked Again
In this episode, we discuss the Mozilla Foundation’s alarming report that reveals why cars are the top privacy concern. Modern vehicles, equipped with data-collecting tech, pose significant risks to consumers’ privacy, with data sharing even extending to law enforcement. Listen in to our discussion as we explore the urgent need for transparency and *gasp* regulations in the automotive industry.
Next, we explore the best practices around password creation and why password requirements are so different between organizations and applications you use every day.
Lastly, Sony has suffered two security breaches in the past four months. In their latest breach, we discuss how a zero-day vulnerability led to unauthorized access and the Clop ransomware gang’s involvement, affecting thousands of individuals.
** Links mentioned on the show *
It’s Official: Cars Are the Worst Product Category We Have Ever Reviewed for Privacy
https://foundation.mozilla.org/en/privacynotincluded/articles/its-official-cars-are-the-worst-product-category-we-have-ever-reviewed-for-privacy/
What Data Does My Car Collect About Me and Where Does It Go?
https://foundation.mozilla.org/en/privacynotincluded/articles/what-data-does-my-car-collect-about-me-and-where-does-it-go/
What are the rules and best practices for password creation these days?
https://www.reddit.com/r/cybersecurity/comments/16y2g47/these_password_rules_for_a_bank_web_site_i_use_why/
https://blog.netwrix.com/2022/11/14/nist-password-guidelines/
Sony confirms data breach impacting thousands in the U.S.
https://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/
https://www.thewrap.com/sony-hack-attack-timeline/
** Watch this episode on YouTube **
https://youtu.be/g6zJb9DhTK0
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, bonus episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on X (Twitter): https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Your Car is a Privacy Nightmare, Password Creation Best Practices, Sony Hacked Again appeared first on Shared Security Podcast.

Oct 2, 2023 • 21min
Is My Boss Spying on Me, Instagram Painting Scam, Kia and Hyundai TikTok Challenge
In this episode, we explore the growing trend of AI surveillance in corporations, where cutting-edge technology is used to monitor employees, optimize productivity, and raise ethical concerns. Next, we uncover a disturbing Instagram scam that lures unsuspecting victims into a trap, highlighting the deceptive tactics employed by cyber criminals on social media. Finally, discover the startling vulnerabilities in Kia and Hyundai vehicles that make them easy targets for car thieves. We discuss the security flaws, the scale of affected vehicles, and practical steps owners can take to protect their cars. Find out how manufacturers are addressing this issue and what it means for your vehicle’s security.
** Links mentioned on the show *
Your Boss’s Spyware Could Train AI to Replace You
https://www.wired.com/story/corporate-surveillance-train-ai/
Instagram Scam: I Want to Use Your Photos for Mural or Painting and Steal Your Money
https://geekmamas.com/2022/09/25/instagram-scam-i-want-to-use-your-photos-for-mural-or-painting-and-steal-your-money/
Car-stealing TikTok trend launches Kia and Hyundai into top 10 most stolen cars
https://www.msn.com/en-us/autos/news/car-stealing-tiktok-trend-launches-kia-and-hyundai-into-top-10-most-stolen-cars/ar-AA1gp1rL#image=1
https://www.marketwatch.com/guides/insurance-services/insuring-your-kia-or-hyundai/
https://www.vox.com/technology/2023/6/1/23742757/kia-hyundai-challenge-tiktok-instagram-youtube
** Watch this episode on YouTube **
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on X (Twitter): https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Is My Boss Spying on Me, Instagram Painting Scam, Kia and Hyundai TikTok Challenge appeared first on Shared Security Podcast.

Sep 25, 2023 • 28min
Content Creation, Mental Health in Cyber, The MGM Ransomware Attack
In this episode Matt Johansen, Security Architect at Reddit and Vulnerable U newsletter and YouTube content creator, joins host Tom Eston to discuss Matt’s background as one of the original “Security Twits”, his career journey, his passion for mental health advocacy, the significance of the recent MGM ransomware attack, and a discussion on the pros and cons of paying ransoms.
** Links mentioned on the show *
Follow Matt on X aka: Twitter
https://twitter.com/mattjay
Follow Matt on LinkedIn
https://www.linkedin.com/in/matthewjohansen/
Vulnerable U Newsletter and YouTube Channel
https://mattjay.com/newsletter/
https://youtube.com/@VulnerableU?si=MAyCiCJ6fDbL0uHs
Threat Modeling Depression
https://www.mattjay.com/blog/threat-model-depression
Threat Modeling Depression: Part Two – Attack Tree
https://www.mattjay.com/blog/attack-tree-depression
Hackers Shut Down MGM in a 10-Min Phone Call
https://bluoceancyber.com/hackers-shut-down-mgm-in-a-10-min-phone-call/
https://x.com/BushidoToken/status/1702423413904867406?s=20
Caesars Entertainment confirms ransom payment, customer data theft
https://www.bleepingcomputer.com/news/security/caesars-entertainment-confirms-ransom-payment-customer-data-theft/
** Watch this episode on YouTube **
https://youtu.be/vvJjdy8K73g
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on X (Twitter): https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Content Creation, Mental Health in Cyber, The MGM Ransomware Attack appeared first on Shared Security Podcast.

Sep 18, 2023 • 26min
The Changing Role of the CISO with Ryan Davis, Chief Information Security Officer at NS1
In this episode Ryan Davis, Chief Information Security Officer at NS1, speaks with host Tom Eston about the changing role of the CISO, acquisitions, what the biggest challenges are, and Ryan’s advice for those considering a career as a CISO. This is one episode you don’t want to miss if you’re curious what a CISO does, thinking about becoming one, or currently a CISO yourself.
** Links mentioned on the show *
Connect with Ryan on LinkedIn
https://www.linkedin.com/in/ryancdavis/
** Watch this episode on YouTube **
https://youtu.be/nI114nSZgjI
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on Twitter: https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post The Changing Role of the CISO with Ryan Davis, Chief Information Security Officer at NS1 appeared first on Shared Security Podcast.

Sep 11, 2023 • 25min
The FBI’s Qakbot Takedown, QR Code Phishing Attacks, Dox Anyone in America for $15
In this episode we discuss the FBI’s remarkable takedown of the Qakbot botnet, a saga involving ransomware, cryptocurrency, and the FBI pushing an uninstaller to thousands of victim PCs. Next, we explore how a major U.S. energy organization fell victim to a QR code phishing attack, highlighting the ever-evolving tactics used by attackers. Finally, we discuss the alarming world of personal data exploitation through credit header information and a TransUnion subsidiary, where attackers can dox anyone in America for only $15.
** Links mentioned on the show *
NOTACON 8: Pen Testing – Moving from Art to Science (Matt Neely)
https://www.youtube.com/watch?v=n71RE6Pk9NI
Qakbot botnet dismantled after infecting over 700,000 computers
https://www.bleepingcomputer.com/news/security/qakbot-botnet-dismantled-after-infecting-over-700-000-computers/
Major U.S. energy org targeted in QR code phishing attack
https://www.bleepingcomputer.com/news/security/major-us-energy-org-targeted-in-qr-code-phishing-attack/
The Secret Weapon Hackers Can Use to Dox Nearly Anyone in America for $15
https://www.404media.co/the-secret-weapon-hackers-can-use-to-dox-nearly-anyone-in-america-for-15-tlo-usinfosearch-transunion/
** Watch this episode on YouTube **
https://youtu.be/BdtSnT1si3s
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on Twitter: https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post The FBI’s Qakbot Takedown, QR Code Phishing Attacks, Dox Anyone in America for $15 appeared first on Shared Security Podcast.

Sep 4, 2023 • 22min
SaaS Attacks: Compromising an Organization without Touching the Network
In this episode Luke Jennings VP of Research & Development from Push Security joins us to discuss SaaS attacks and how its possible to compromise an organization without touching a single endpoint or network. Luke talks about his recent SaaS attack research, why SaaS based attacks are different than traditional network based attacks, the SaaS attack matrix which can be used by both red and blue teams, and why its important that this research is shared and talked about in the cybersecurity community.
** Links mentioned on the show *
Let’s talk about SaaS attack techniques
https://pushsecurity.com/blog/saas-attack-techniques/
SAMLjacking a poisoned tenant
https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/
Push Security SaaS Attacks GitHub
https://github.com/pushsecurity/saas-attacks
Follow Luke and Push Security
https://www.linkedin.com/in/luke-jennings-042b5619b/
https://twitter.com/jukelennings
https://twitter.com/PushSecurity
https://pushsecurity.com/
** Watch this episode on YouTube **
https://youtu.be/Rj0t5Lw12Ic
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on Twitter: https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post SaaS Attacks: Compromising an Organization without Touching the Network appeared first on Shared Security Podcast.

Aug 28, 2023 • 26min
Back to School Cybersecurity, Phishing Pitfalls and Strategies, X’s (Twitter) Blocking Overhaul
In this episode, we discuss essential cybersecurity tips for students and educational institutions as they gear up for the school season. From software updates to strong passwords and cybersecurity education, we explore how students and schools can fortify their digital defenses.
Next, we navigate the treacherous waters of phishing and related scams, unveiling strategies to outwit malicious links. Hovering over links, cautious email scrutiny, and verification tactics all play a role.
Finally, we discuss the surprising policy change by X (formerly Twitter), where blocking faces a major overhaul. Tune in as we discuss the privacy and safety ramifications of this change.
** Links mentioned on the show *
Back-To-School Cybersecurity Tips
https://www.eschoolnews.com/it-leadership/2023/08/15/4-back-to-school-cybersecurity-tips/
https://convergetp.com/2023/08/03/checklist-cybersecurity-program-k-12-schools/
https://www.10news.com/news/back-to-school/back-to-school-a-closer-look-at-data-breaches-in-school-districts
https://www.cisa.gov/protecting-our-future-cybersecurity-k-12
4 ways to avoid clicking malicious links that everyone online should know
https://www.zdnet.com/article/4-ways-to-avoid-clicking-on-malicious-links-and-the-phishing-and-scams-behind-them/
Elon Musk says users on X, formerly Twitter, will lose ability to block unwanted followers, eliminating key safety feature
https://www.cnbc.com/2023/08/18/elon-musk-says-x-users-will-be-losing-the-ability-to-block-content-.html
Join OWASP so you can vote for Kevin who is running for the board of directors!
https://owasp.org/membership/
** Watch this episode on YouTube **
** Become a Shared Security Supporter **
For only $5 per month get exclusive access to ad-free episodes, listen to new episodes before they are released, get access to our private Discord server, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today! https://patreon.com/SharedSecurity
** Thank you to our sponsors! **
SLNT
Visit slnt.com to check out SLNT’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Subscribe and follow the podcast **
Join the Shared Security Community on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Watch and Subscribe on Odysee (YouTube alternative)
https://odysee.com/@SharedSecurity:c
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Follow us on Twitter: https://twitter.com/sharedsec
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact
The post Back to School Cybersecurity, Phishing Pitfalls and Strategies, X’s (Twitter) Blocking Overhaul appeared first on Shared Security Podcast.


