T1SP: Episode 23

T1SP: Episode 23



[ Subscribe to the Podcast: iTunes | Android | RSS ]

News


* [ ] Juniper backdoor; could have been found with diff; signs point to NSA
* [ ] RCE on FireEye appliances
* [ ] Hyatt got hacked; malware on POS
* [ ] 45K drones registered with FAA within 2 days
* [ ] Industry moving towards password-free logins; still single factor, now the factor is your device; although access to device could require factors
* [ ] Microsoft will now tell you if your account has been targeted by government authorities
* [ ] Tor announced it’s doing a bug bounty, looks like it’ll be internal
* [ ] Steam had a DoS that revealed 34K user details
* [ ] Linode has been suffering a massive DDoS on its datacenters, DNS infrastructure
* [ ] Spy files found in North Korea’s Operating System


Ideas, updates, and discussion


* [ ] 3 things you should do every January
* [ ] Web Scanner Series: Burp vs. Netsparker
* [ ] When you’re interviewing, make sure you make it clear that you’re the asset too, not just them
* [ ] Failing at the basics in intelligence and infosec
* [ ] Why Trump is Winning
* [ ] Sensitive data sent in URL over HTTPS
* [ ] Difference between correlation and causation
* [ ] Paul Graham’s REFRAGMENTATION post
* [ ] The relationship between Relaxation, Fun, and Performance
* [ ] Michael Coates makes the argument that false negatives are way better than false positives because false positives create unnecessary work for his team
* [ ] Brainstorm questions, not solutions


Tools and projects


* [ ] BLUTO
* [ ] Serpico
* [ ] Firmware Extraction from Craig Smith
* [ ] Vulnerability Database Resources
* [ ] IoT Attack Surfaces Project
* [ ] RobotsDisallowed Project
* [ ] Nowhere.net (CyberPunk)
* [ ] EyeWitness
* [ ] REST Security Cheat Sheet
* [ ] Censys.io
* [ ] GithubDorks
* [ ] InstaRecon (DNS lookups, whois, shodan, google dorks, etc)
* [ ] twfactorauth.org


Announcements


* [ ] Speaking at OWASP Cali end of January
* [ ] Currently working on an ICS / SCADA primer


Miscellaneous


* [ ] Need to check out the Benedict Evans blog
* [ ] Serial Podcast / Making a Murderer on Netflix
* [ ] If you know any Army veterans who are getting out and want to get into InfoSec, let me know
* [ ] Twitter account: CISSP Googling
* [ ] Sam Altman (Startup Playbook)


[ Subscribe to the Podcast: iTunes | Android | RSS ]

Notes


* The intro track is from one of my favorite EDM artists: Zomby. The song is ‘Orion’, and it’s from the ‘With Love’ album. Highly recommended if you like chill EDM.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(541)

UL NO. 485: STANDARD EDITION: Netflix RCE, My Current AI Stack, All-in on Claude Code, and more...

UL NO. 485: STANDARD EDITION: Netflix RCE, My Current AI Stack, All-in on Claude Code, and more...

STANDARD EDITION: Netflix RCE, My Current AI Stack, All-in on Claude Code, and more... You are currently listening to the Standard version of the podcast, consider upgrading and becoming a member to u...

19 Kesä 202536min

UL NO. 484: STANDARD EDITION: OpenAI's Malicious AI Report, Disappointed with WWDC, AI's First Actual Science Breakthrough, and more...

UL NO. 484: STANDARD EDITION: OpenAI's Malicious AI Report, Disappointed with WWDC, AI's First Actual Science Breakthrough, and more...

UL NO. 484: STANDARD EDITION: OpenAI's Malicious AI Report, Disappointed with WWDC, AI's First Actual Science Breakthrough, and more... You are currently listening to the Standard version of the podca...

12 Kesä 202543min

UL NO. 483 | STANDARD EDITION: A Chrome 0-Day, Meta Automates Security Assessments, New Essays, My New Video on Hacking with AI, Ukraine's Asymmetrical Attack, Thoughts on My AI Skeptical Friends, The Dangers of Winning the Wrong Game, and more...

UL NO. 483 | STANDARD EDITION: A Chrome 0-Day, Meta Automates Security Assessments, New Essays, My New Video on Hacking with AI, Ukraine's Asymmetrical Attack, Thoughts on My AI Skeptical Friends, The Dangers of Winning the Wrong Game, and more...

A Chrome 0-Day, Meta Automates Security Assessments, New Essays, My New Video on Hacking with AI, Ukraine's Asymmetrical Attack, Thoughts on My AI Skeptical Friends, The Dangers of Winning the Wrong G...

5 Kesä 202531min

The Future of Hacking is Context

The Future of Hacking is Context

Sponsored by Vanta. Vanta takes the busywork out of GRC so you can focus on what actually matters—improving your security, not chasing compliance. https://ul.live/vanta This isn’t just another AI podc...

3 Kesä 202533min

UL NO. 482 | STANDARD EDITION: AI Finds an 0-Day!, Postman Leaking Secrets, High Agency Mental Model, My Unified Entity Context Video, Github MCP Leaks Private Repos, Google vs. OpenAI vs. Apple on AI Vision, and more...

UL NO. 482 | STANDARD EDITION: AI Finds an 0-Day!, Postman Leaking Secrets, High Agency Mental Model, My Unified Entity Context Video, Github MCP Leaks Private Repos, Google vs. OpenAI vs. Apple on AI Vision, and more...

AI Finds an 0-Day!, Postman Leaking Secrets, High Agency Mental Model, My Unified Entity Context Video, Github MCP Leaks Private Repos, Google vs. OpenAI vs. Apple on AI Vision, and more... You are cu...

30 Touko 202531min

Unified Entity Context

Unified Entity Context

🔹 Thanks to ProjectDiscovery for sponsoring today’s video. I've been using their tools like Nuclei and Subfinder for years, and now they’ve brought that power to the cloud with a full vulnerability m...

15 Touko 202530min

Reviewing RSA 2025 with Jason Haddix

Reviewing RSA 2025 with Jason Haddix

What really happened at RSA 2024? Daniel Miessler and Jason Haddix break it down. Fresh off a whirlwind RSA week, Daniel sits down with Jason Haddix (Arcanum Information Security) to talk about what m...

8 Touko 20251h 21min

A Conversation with Bar-El Tayouri from Mend.io

A Conversation with Bar-El Tayouri from Mend.io

➡ Get full visibility, risk insights, red teaming, and governance for your AI models, AI agents, RAGs, and more—so you can securely deploy AI powered applications with ul.live/mend In this episode, I ...

6 Touko 202545min