T1SP: Episode 23

T1SP: Episode 23



[ Subscribe to the Podcast: iTunes | Android | RSS ]

News


* [ ] Juniper backdoor; could have been found with diff; signs point to NSA
* [ ] RCE on FireEye appliances
* [ ] Hyatt got hacked; malware on POS
* [ ] 45K drones registered with FAA within 2 days
* [ ] Industry moving towards password-free logins; still single factor, now the factor is your device; although access to device could require factors
* [ ] Microsoft will now tell you if your account has been targeted by government authorities
* [ ] Tor announced it’s doing a bug bounty, looks like it’ll be internal
* [ ] Steam had a DoS that revealed 34K user details
* [ ] Linode has been suffering a massive DDoS on its datacenters, DNS infrastructure
* [ ] Spy files found in North Korea’s Operating System


Ideas, updates, and discussion


* [ ] 3 things you should do every January
* [ ] Web Scanner Series: Burp vs. Netsparker
* [ ] When you’re interviewing, make sure you make it clear that you’re the asset too, not just them
* [ ] Failing at the basics in intelligence and infosec
* [ ] Why Trump is Winning
* [ ] Sensitive data sent in URL over HTTPS
* [ ] Difference between correlation and causation
* [ ] Paul Graham’s REFRAGMENTATION post
* [ ] The relationship between Relaxation, Fun, and Performance
* [ ] Michael Coates makes the argument that false negatives are way better than false positives because false positives create unnecessary work for his team
* [ ] Brainstorm questions, not solutions


Tools and projects


* [ ] BLUTO
* [ ] Serpico
* [ ] Firmware Extraction from Craig Smith
* [ ] Vulnerability Database Resources
* [ ] IoT Attack Surfaces Project
* [ ] RobotsDisallowed Project
* [ ] Nowhere.net (CyberPunk)
* [ ] EyeWitness
* [ ] REST Security Cheat Sheet
* [ ] Censys.io
* [ ] GithubDorks
* [ ] InstaRecon (DNS lookups, whois, shodan, google dorks, etc)
* [ ] twfactorauth.org


Announcements


* [ ] Speaking at OWASP Cali end of January
* [ ] Currently working on an ICS / SCADA primer


Miscellaneous


* [ ] Need to check out the Benedict Evans blog
* [ ] Serial Podcast / Making a Murderer on Netflix
* [ ] If you know any Army veterans who are getting out and want to get into InfoSec, let me know
* [ ] Twitter account: CISSP Googling
* [ ] Sam Altman (Startup Playbook)


[ Subscribe to the Podcast: iTunes | Android | RSS ]

Notes


* The intro track is from one of my favorite EDM artists: Zomby. The song is ‘Orion’, and it’s from the ‘With Love’ album. Highly recommended if you like chill EDM.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(541)

The 4 AAAAs of the AI ECOSYSTEM: Assistants, APIs, Agents, and Augmented Reality

The 4 AAAAs of the AI ECOSYSTEM: Assistants, APIs, Agents, and Augmented Reality

In this episode, I break down what I believe is the emerging structure of the AI-powered world we're all building—consciously or not. I call it the “Four A’s”: Assistants, APIs, Agents, and Augmented ...

22 Huhti 202527min

Using the Smartest AI to Rate Other AI

Using the Smartest AI to Rate Other AI

In this episode, I walk through a Fabric Pattern that assesses how well a given model does on a task relative to humans. This system uses your smartest AI model to evaluate the performance of other AI...

19 Huhti 20259min

A Conversation with Patrick Duffy from Material Security

A Conversation with Patrick Duffy from Material Security

➡ Secure what your business is made of with Martial Security: https://material.security/ In this episode, I speak with Patrick Duffy from Material Security about modern approaches to email and cloud w...

15 Huhti 202526min

AICAD: Artificial Intelligence Capabilities For Attack & Defense

AICAD: Artificial Intelligence Capabilities For Attack & Defense

AI is changing cybersecurity at a fundamental level—but how do we decide what to build, and when? In this episode, I outline a structured way to think about AI for security: from foundational ideas to...

12 Huhti 202542min

A Possible Path to ASI

A Possible Path to ASI

The conversation around AGI and ASI is louder than ever—but the definitions are often abstract, technical, and disconnected from what actually matters. In this episode, I break down a human-centered w...

8 Huhti 202510min

A Conversation With Matt Muller From Tines

A Conversation With Matt Muller From Tines

➡ Build, run, and monitor workflows with Tines at: tines.com In this episode, I speak with Matt Muller, Field CSCO at Tines, about how automation and AI are transforming security operations at scale. ...

1 Huhti 202539min

UL NO. 474 | Signal OPSEC, White-box Red-teaming LLMs, Unified Company Context (UCC), New Book Recommendations, Single Apple Note Technique, and much more...

UL NO. 474 | Signal OPSEC, White-box Red-teaming LLMs, Unified Company Context (UCC), New Book Recommendations, Single Apple Note Technique, and much more...

STANDARD EDITION: Signal OPSEC, White-box Red-teaming LLMs, Unified Company Context (UCC), New Book Recommendations, Single Apple Note Technique, and much more... You are currently listening to the St...

31 Maalis 202518min

A Conversation With Slava Konstantinov From ThreatLocker

A Conversation With Slava Konstantinov From ThreatLocker

➡ Allow what you need, block everything else with ThreatLocker: threatlocker.com In this episode, I speak with Slava Konstantinov, ThreatLocker's MacOS Lead Architect, about their zero-trust approach ...

18 Maalis 202533min