Podcasts about Blast radius

  • 92PODCASTS
  • 108EPISODES
  • 46mAVG DURATION
  • 1EPISODE EVERY OTHER WEEK
  • Sep 4, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about Blast radius

Latest podcast episodes about Blast radius

Breaking Analysis with Dave Vellante
Beyond Shared Responsibility: When AI Acts, Who Owns the Blast Radius?

Breaking Analysis with Dave Vellante

Play Episode Listen Later Sep 4, 2026 46:26


The cloud shared responsibility model was initially not well understood by many customers. In fact, early adopters often believed that simply having data in the cloud meant that Amazon, or a SaaS vendor were responsible for safeguarding it. Amazon had to educate its customers and partners that security and compliance duties were split between the vendor and the client organization. In short, the vendor was responsible for securing the cloud resources but you, the buyer, were responsible for securing what you put inside the cloud; based on your policies, priorities and budget. We believe a similar but much more consequential dynamic is unfolding with respect to agentic AI. Specifically, Cloud computing divided responsibility by infrastructure layer. Agentic AI distributes authority across a chain of models, platforms, clouds, partners and customers. Our premise is the industry now needs a shared accountability model for the decisions, actions and outcomes that chain produces.In short - The cloud shared-responsibility model told customers who secures what. The agentic shared-accountability model must define who can do what, who can stop it, who can prove what happened and who pays when it goes wrong.Welcome to episode 326 of Breaking Analysis. Beyond Shared Responsibility - When AI Acts, Who owns the Blast Radius. In this Breaking Analysis, Principal CUBE Research Analyst Krista Case and I explain why the agentic era demands a new accountability model. We'll draw on learnings from last week's CrowdStrike Fal.Con event, where the post Mythos moment and the OpenAI/Hugging Face “accident” were front and center. We'll also draw on other new datapoints, including conversations with CISOs at Fal.Con and Palo Alto Networks' earnings print from last week, to unpack what we've defined as a new AI accountability model. We'll also test this new model against our Sovereignty framework, developed by Amit Govrin and assess sovereignty in the context of business recovery. We'll explore the sequence of events that leads up to the ultimate question of who pays when something goes wrong? 

The Tech Blog Writer Podcast
Testing the Blast Radius of Agentic AI With NTT DATA

The Tech Blog Writer Podcast

Play Episode Listen Later Aug 30, 2026 29:47


What happens when an AI agent follows your documented process perfectly, but that process bears little resemblance to how decisions are actually made? In this episode, I speak with Bill Wilson, Executive Head of Data and AI Solutions at NTT DATA UK&I. Bill oversees AI globally for NTT DATA's public sector work, giving him a close view of how governments are using AI while trying to manage risk, accountability, public confidence, and constrained resources. Bill offers a refreshingly practical test for any proposed AI system: is it competent, and what is the worst thing that could go wrong? He describes this potential consequence as the system's "blast radius." An AI assistant helping somebody understand a grant application presents a very different level of risk from an agent making decisions that affect employment, justice, taxation, or access to public services. We also discuss why companies can make a mistake before deploying their first agent. Automating an inefficient process simply allows the organization to perform the wrong work faster. Bill argues that teams should examine complete workflows, identify where several AI capabilities could produce a measurable result, and remain prepared to redesign the process as they learn. Another major problem is tacit knowledge. Employees frequently make decisions using experience that was never written down. An agent trained solely on formal documentation may therefore understand the official process while missing how the work gets done in practice. Bill explains how targeted questions, behavioral traces, feedback, and supervised learning could capture some of that reasoning. Public sector AI provides several useful examples. Bill discusses systems that process volumes of information beyond human capacity, emergency response work in Tennessee, and case management applications that gather information before a human reviews it. In these situations, AI can reduce administrative work and waiting times while leaving consequential decisions with people. But human approval alone provides no guarantee. If employees lose direct experience of the work, they may eventually approve whatever the system recommends. Bill compares this with airline pilots maintaining manual flying skills and describes how known test cases can reveal when reviewers are becoming overly trusting. For CIOs deciding which AI pilots should reach production, the advice is equally direct: choose work with measurable returns, group related use cases where their combined effect can be seen, learn from a varied set of deployments, and avoid building something a software provider is about to include in an existing product. As AI agents gain access to external information, internal data, and operational tools, how should your organization decide what they may do alone and when a person must intervene? Listen to the conversation and share your thoughts with me.

Breaking Analysis with Dave Vellante
CrowdStrike's Post-Mythos Surge: Moat, Momentum and the Blast-Radius Test

Breaking Analysis with Dave Vellante

Play Episode Listen Later Aug 28, 2026 34:53


Breaking Analysis with Dave Vellante

momentum surge mythos crowdstrike moat blast radius dave vellante
Innovation in Compliance with Tom Fox
Brian Holyfield on Reducing Cybersecurity Blast Radius

Innovation in Compliance with Tom Fox

Play Episode Listen Later Aug 25, 2026 25:39


Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom visits with Brian Holyfield, Co-Founder & Chief Product Officer at SendSafely. Holyfield discusses why the right compliance question on cybersecurity is not whether a breach will happen but when and what data will be exposed, often through vendors. He explains “blast radius” as the scope of access and data reachable during an incident and argues organizations should prioritize architecture, data minimization, and retention controls alongside prevention. He also highlights risks from accumulated file attachments, overbroad user access, interconnected systems using OAuth tokens, and “standing access” via long-lived machine credentials that can be abused without obvious login anomalies. Holyfield discusses examples involving ServiceNow and Salesforce that illustrate platform vulnerabilities, trusted upstream vendor connections, and end-user compromise, and advises leaders to inventory connections, define retention/archiving, and move sensitive data out of frontline platforms; SendSafely positions itself as an end-to-end encrypted trust layer, including for AI chatbot attachments. Key highlights: Assume the Breach Blast Radius Explained ServiceNow and Salesforce Lessons Board-Level Questions AI Changes the Game Compliance and Governance Fit Resources: SendSafely Brian Holyfield on LinkedIn Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Tank Talks
What 30 years inside critical infrastructure teaches you about security | Karl Holmqvist, CEO of Lastwall

Tank Talks

Play Episode Listen Later Aug 21, 2026 51:43


In this episode of Tank Talks, host Matt Cohen sits down with Karl Holmqvist, co-founder and CEO of Lastwall, a FedRAMP-certified identity security platform built for the highest-risk use cases. Karl has been deep in cybersecurity since the 1990s, with early experience building critical infrastructure, including Canada's first high-speed mobile data network, and a recent focus on identity security at the forefront of making systems quantum-resilient. In this conversation, they explore the evolution of Lastwall from early behavioral biometrics and cognitive signals to today's hybrid post-quantum cryptography.They also dig into the journey to FedRAMP approval and what it really takes to sell to the hardest customers on the planet, from the DOD's Innovation Unit to critical infrastructure operators globally. Karl shares his view on why hybrid cryptography is the only responsible path right now, the magnified risk of the AI agent era, and his strongly held belief that when it comes to quantum resiliency, you're either going to be too early or too late.Whether you're a founder navigating a path into regulated markets, a security leader thinking about the agentic AI era, or just curious about what it takes to protect critical infrastructure, Karl delivers a grounded, technical, and occasionally unsettling look at where identity security is headed.–A big thanks to our sponsor, Moomoo CanadaThis is the kind of tooling that used to live on a Bloomberg terminal, but now it is on your phone, just a few taps away. They offer real-time data, full options chains, and an AI assistant that actually explains trading strategies.Moomoo is the perfect place for people who want to take their money seriously. Open an account today at moomoo.caGrowing Up in Dubai During the Gulf War (03:50)* Karl's childhood in Dubai as an expat during the Gulf War* Visiting the USS Nimitz and seeing 5,000 people living on an aircraft carrier* How jets overhead and allied ships shaped his early view of technology and defense* The BBS era and the thrill of finding information that wasn't available to everyoneFrom Mobile Data Skepticism to Building Canada's First High-Speed Network (05:31)* Why people thought mobile internet was “the stupidest thing” in the early 2000s* Building a data-only carrier when no one believed you'd want internet everywhere* The Nokia Communicator as his favorite tech gadget and early glimpse of mobile data* Connecting critical infrastructure and discovering default credentials left wide openThe Wake-Up Call: Wastewater Plants and Unsecured Dams (12:58)* Finding a wastewater flow control valve dangling on the internet with admin/admin credentials* The “air-gapped” power plant where an engineer plugged his BlackBerry in to charge* How Shodan and friends revealed dams and power facilities publicly accessible* The founding of Lastwall: “Hackers will be everywhere. We've got to do something.”From Behavioral Biometrics to Quantum Resilience (19:11)* Why 85% of hacks still use valid stolen credentials, the same as the 1990s* Early experiments with keyboard dynamics, mouse movements, and cognitive biometrics* Tracking Peter Shor's algorithm since university and the IBM factorization of 15 in 2001* The 2017 to 2018 decision to embed quantum resiliency natively into LastwallSelling to the Pentagon: DIU and the “Hard Mode First” Strategy (26:07)* Landing the first major deployment with the U.S. Department of Defense Innovation Unit* How DIU pioneered procurement that matches innovation cycles, months instead of years* The advice from Carbon Black founders: build the regulated stack first* Why defense tech used to shut VC doors and how times have changedFedRAMP, Canada, and the Case for Harmonization (33:25)* FedRAMP as the gold standard: do compliance once, reuse everywhere* The Canadian challenge: every agency doing its own security review* Why Canada should base its program on NIST 800 and harmonize with the U.S.* The reality of the integrated North American power grid and shared defenseAI Agents and the Blast Radius of Credential Theft (37:44)* Why 50 to 100 agents per human in 2 to 3 years will magnify damage exponentially* The OpenClaw lesson: agents do what agents do, not what you expect* The “YOLO” approach to AI deployment and why enterprises aren't calling enough* Advice for founders: sandbox first, don't connect your whole drive, go slowlyThe $60M Series A Extension and the Path Forward (43:13)* Raising BDC Capital's Strong North Fund led by Major General (Ret.) Peter Dawe* The milestone of FedRAMP certification and opening the floodgates to U.S. agencies* Deploying in disconnected environments: field containers for critical infrastructure* Why defense is ultimately about protecting the economyAbout Karl HolmqvistKarl Holmqvist is co-founder and CEO of Lastwall, an identity-as-a-service platform built on Zero Trust principles and public key infrastructure, hardened with post-quantum cryptographic resilience. Lastwall serves the U.S. Department of Defense and a growing number of civilian government agencies and critical infrastructure operators. Karl has been a cybersecurity enthusiast since the 1990s, with a background spanning telecommunications infrastructure (including building one of Canada's first high-speed mobile data networks), renewable energy infrastructure across the Middle East, North Africa, and Southern Europe, and international investing. He studied at Mount Allison University and is based in Vancouver, BC.Connect with Karl Holmqvist on LinkedIn: https://www.linkedin.com/in/karlholmqvist/Visit Lastwall's website: https://www.lastwall.com/Connect with Matt Cohen on LinkedIn: https://ca.linkedin.com/in/matt-cohen1Visit the Ripple Ventures website: https://www.rippleventures.com/ This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit tanktalks.substack.com

Reversim Podcast
518 - Carburetor 42

Reversim Podcast

Play Episode Listen Later Aug 19, 2026


פרק מספר 518 של רברס עם פלטפורמה - קרבורטור מספר 42. רן ואורי מארחים שוב את נתי שלום לפרק המשך בסדרה על סוכני קידוד, והפעם - מה קורה כשסוכני AI (Agents) מגיעים לסביבת הפרודקשן. אנחנו צוללים לתוך השינוי הטקטוני שעוברת תעשיית ה-Observability, התרסקות המודלים העסקיים המוכרים, ומי הולך להרוויח את הזכות לא רק לתצפת על המערכות, אלא גם לתקן אותן בפועל. [01:24] מ-Assisted SRE לתיקון אוטונומי מה קורה כשהסוכנים מגיעים לפרודקשן ומה ההבדל בין פרסונת ה-DevOps לפרסונת ה-SRE בארגון. הבשלות של התעשייה: משתמשים כבר לא רוצים מערכות "מסייעות" (Assisted) שרק זורקות המלצות ומייצרות יותר עבודת פענוח לאדם. הדרישה כיום היא לסוכנים שפשוט פותרים את הבעיה. [05:51] הרגע שבו Datadog הבינו את המשחק דיון על חברת Datadog (ואיך הם קיבלו את השם שלהם ממדבקה על שרת אקראי). רעידת האדמה בתעשייה: ההבנה של ענקיות ה-Observability שהמודל הישן מת. המנכ"ל של Datadog מודה בעצמו שהארגונים מצפים עכשיו לפתרונות אקטיביים ולא רק לאיסוף נתונים וצפייה. לקריאה נוספת והעמקה על הדיסוננס של החברה מול השוק, קראו את הפוסט של נתי בנושא: Datadog beat Q2 and the market sold it off: here's the tension the number hides. ההשוואה ההיסטורית למאבק של VMware מול AWS: זה לא רק פער טכנולוגי, אלא שינוי דרמטי במודל העסקי שמחסל את החפיר (Moat) הישן. [12:02] כשל השוק של ה-Data Lakes בעיית העלות המובנית: המודל העסקי של חברות האובזרבביליטי מבוסס על תמחור לפי נפח הנתונים (Ingestion). רוב המידע שנשמר הוא "זבל" - לוגים ונתונים שאיש לא קורא עד שיש תקלה, אך ארגונים משלמים עליהם פרמיום כמעין תעודת ביטוח. סוכני AI הופכים את אגירת כל הנתונים באגם מרכזי ללא כלכלית בעליל (לא ססטיינבילית), מה שמאיץ את הנפילה מצוק של ספקיות המסורתיות. [16:27] רגע ה-Claude Code של עולם הפרודקשן בניגוד לאימון על היסטוריית תקלות רנדומלית, מערכות אוטונומיות אמיתיות צריכות "סימולטור" - יכולת לשחזר תקלה בסביבה מבוקרת (Reinforcement Learning Verified Rewards). בדיוק כמו ש-Claude Code מריץ ובודק מול הקומפיילר כדי להגיע לדיוק, סוכן SRE חייב Feedback Loop אמיתי ולא רק להתבסס על ארכיון לוגים. רוב הידע הבסיסי על תקלות נפוצות ממילא כבר מקודד פנימה בתוך הזיכרון הפרמטרי של ה-LLMs (הם ה"Stack Overflow" של עצמם). [29:21] רדיוס הפיצוץ: איך סומכים על סוכן בפרודקשן? החשש הטבעי: מה יקרה אם הסוכן האוטונומי ישנה קונפיגורציית רשת או יוריד שרתים בטעות? הדילמה הפסיכולוגית מול סטטיסטיקה - כמו ההבדל בין נהג אנושי למכונית אוטונומית או טייס אוטומטי במטוס. הפתרון: מנגנוני בקרה אוטומטיים שמחשבים מראש את "רדיוס הפיצוץ" (Blast Radius) של התקלה. הסוכן מחליט מתי מותר לו לתקן לבד ומתי האימפקט גדול מדי ומצריך התערבות אנושית. [34:36] קונטקסט לוקאלי מול גלובאלי תקלות רבות נולדות משינויים (Drift), ורוב הקונטקסט הדרוש כדי לפתור אותן נמצא ברמת הקלאסטר הלוקאלי. למה איסוף כל הנתונים לענן מרכזי שגוי: בעיות אבטחת מידע, עלויות מטורפות, ו-Latency (איחור בהגעת לוגים ומטריקות שמבלבל את תמונת המצב בזמן אמת). דילמת החדשנות: חברות ה-Observability הגדולות מזהות את הבעיה (וקונות חברות בתחום), אבל מתקשות לשנות כיוון בגלל התלות במודל ההכנסות הקיים שלהן. [40:27] חוקר התקלות לעומת יוצר התקלות חשיבה מחדש על התהליך: במקום להגיע ל"זירת פשע" בדיעבד, מה קורה אם ה-AI שכתב ודחף את הקוד (ה"פושע") הוא גם זה שמנתח ומזהה את התקלה? החשיבות העצומה של Efficiency (יעילות) בעולמות התשתית של ה-AI היום, ואיך היא משפיעה על הערכות שווי של חברות אוטונומיות (כמו Devin). השורה התחתונה: אין טעם לקחת תהליך שבור וצוותים מופרדים ולהדביק להם AI כפלסטר. זו הזדמנות לעשות הנדסה מחדש לדרך שבה אנחנו מנהלים את האמינות של המערכות שלנו. האזנה נעימה!

Morning Somewhere
2026.08.18: Personal Blast Radius

Morning Somewhere

Play Episode Listen Later Aug 18, 2026 30:10


Burnie and Ashley discuss Snapdragon, emulation, printing issues, the Han Kuang war games, cameras to people, highest August gas prices, Collge Football Preseason poll, and the Grantown On Spey Remakery.

Threat Talks - Your Gateway to Cybersecurity Insights
JADEPUFFER: The AI Malware With No Human in the loop

Threat Talks - Your Gateway to Cybersecurity Insights

Play Episode Listen Later Jul 28, 2026 21:35


What if AI stopped being the assistant to cybercriminals and became the attacker itself? That's no longer hypothetical. JADEPUFFER is the first documented case of ransomware run entirely by an AI agent: it broke into a production database, hit a wall mid-attack, then found another way in within 31 seconds, faster than most human penetration testers can react. Rob Maas, Field CTO at ON2IT, sits down with Yuri Wit, SOC DevOps Engineer at ON2IT, to trace how agentic malware evolved out of AI-assisted attacks into a threat that plans, executes, and pivots entirely on its own.

First Coast Connect With Melissa Ross
The 'blast radius' of property tax cuts

First Coast Connect With Melissa Ross

Play Episode Listen Later Jul 20, 2026 51:00


Former Republican state Sen. Jeff Brandes says the real devastation caused by a proposed property tax cut will be the loss of local control.

Developer Tea
Your Single Most Important Tool for Managing the Uneven Downsides of Risk

Developer Tea

Play Episode Listen Later Jul 10, 2026 25:00


The skills you build and the tools you master matter, but they aren't your most important asset when things go wrong — and something eventually will. In this episode, I work through why our careers and lives are governed more by avoiding catastrophic downside than by chasing upside, and why the single best tool for surviving a bad event isn't testing, insurance, or money — it's genuine trust with the people around you. Here's a question to sit with: what is the most important tool you have as a software engineer and as a leader? Most of us reach for something technical, but the answer runs deeper than that. In this episode, I start with the humble premortem — the practice of assuming something has already gone wrong so we can pressure-test our plans — and use it to explore why so much of our work is really about predicting and mitigating risk. From there, I make the case that because we're all exposed to a far larger downside than upside on any given day, the tool that matters most is the one that helps you survive the bad event you couldn't prevent: your relationships with other people, built on real trust. The Premortem as a Risk Lens: Learn why assuming failure ahead of time is such a useful counter to our natural optimism. Our plans quietly assume everything will go right, and a premortem forces us to inspect the gaps our best-laid plans never covered. Life Is Already About Predicting Risk: Nearly every action we take — stepping forward, eating the sushi, merging into traffic — is a small bet on an outcome we can't prove in advance. Much of what we're managing isn't even our own behavior, but the risk other people put us through. Why the Downside Dwarfs the Upside: On a typical Monday, your potential gain is limited, but your potential loss is not. A single catastrophic event — a breached customer, untested code shipped, an injury for an athlete — can undo far more than any single good action could ever build. This is why avoiding failure, not chasing brilliance, quietly shapes most successful careers. Likelihood Times Impact: Even a one-in-a-hundred-days negative event can cost you your job or your company a fortune, while very few actions could produce a commensurate gain like doubling your salary. Our behavioral aversion to risk turns out to be rational. Mitigate the Blast Radius, Not Just the Incidence: You can never be 100% certain a bad event won't happen. Good people who show up, stay reliable, and grow their skills still get laid off. So beyond reducing the likelihood of harm, you have to reduce its impact when it lands. Relationships Are the Real Safety Net: The most important tool in your belt isn't technical — it's your relationships with other human beings. Invested in honestly, they pay you back forever, and they're the thing you fall back on when the negative event you tried to prevent happens anyway. Trust Is the Core Currency: Genuine relationships require reality — real curiosity and care, not performed name-remembering, which people can see through. Trust compounds like an asset, while money spent to buy loyalty is gone the moment it's paid. When you hit a hard deadline or discover something's broken, a reservoir of trust is what lets people extend their best effort without you having to throw more money on the table. Episode Homework: Go invest in your relationships regardless of your current risk profile. Spend extra time in your one-on-ones, with your team, and in your retros — and get curious about what the people around you actually want, instead of assuming you already know.

UBC News World
AI Workflow Guardrails: How to Scale Without Expanding Blast Radius

UBC News World

Play Episode Listen Later Jun 11, 2026 7:53


Attackers reached full data exfiltration in just 72 minutes—four times faster than the year before. Learn the three critical AI workflow guardrails every CISO needs to scale securely without expanding blast radius. ITRADE Innovations City: Fort Lauderdale Address: 501 E Las Olas Blvd Website: https://www.itradeinnovations.com/

Understanding Israel/Palestine
The Architecture of Empire: Walter L. Hixson on the Israel Lobby and the Machinery of Endless War

Understanding Israel/Palestine

Play Episode Listen Later May 22, 2026 28:30


Send us Fan MailThe Architecture of Empire: Walter L. Hixson on the Israel Lobby and the Machinery of Endless WarPart Two: The Nakba's Blast Radius and the Capture of U.S. Foreign PolicyEpisode DescriptionSeventy-eight years ago, the Nakba dismantled Palestinian society. Today, we are living inside its blast radius.What began in 1948 with the violent mass displacement of over 700,000 people has metastasized into a sprawling, multi-front geopolitical fire. We are now watching the Middle East get swallowed by a disastrous and widely rejected regional war with Iran—a conflict fueled by corrupt demagogues desperate to trade human lives for their own political survival.How does a republic repeatedly bankrupt its moral standing and its treasury to underwrite conflicts its citizens actively despise? It doesn't happen by accident. It is engineered.In Part Two of our historical deep-dive into the U.S.-Israel Special Relationship, host Jeremy Rothe-Kushel reaches back to a profoundly relevant late-2021 conversation with diplomatic and cultural historian Walter L. Hixson.Stripping away the polite fictions of Washington double-speak, Hixson exposes the actual plumbing of imperial power. We break down the modern Israel lobby in plain daylight: the massive flow of capital, the ruthless political coercion, and the organized infrastructure of silence that captures U.S. foreign policy and locks the American public into a perpetual cycle of militarism and repression.If we are ever going to extinguish the fire, we must first understand exactly who built the furnace. Step beyond the walls with us.Guest Bio: Walter L. Hixson is a diplomatic and cultural historian, a contributing editor of the Washington Report on Middle East Affairs, and the author of numerous vital books, including Architects of Repression: How Israel and Its Lobby Put Racism, Violence and Injustice at the Center of US Middle East Policy and Imperialism and War: The History Americans Need to Own.Listen & Explore Further:Walter Hixson's Bio & Work: University of AkronExplore the Show Archives: Listen to past episodes, including Part 1 with Grant Smith, at the KKFI Understanding Israel Palestine archive: kkfi.org/program/understanding-israel-palestine/Beyond the Walls Substack: beyondthewalls.substack.com

Politics By Faith w/Mike Slater
What To Do With The Donald Trump Blast Radius?

Politics By Faith w/Mike Slater

Play Episode Listen Later May 20, 2026 19:15


Thomas Massie lost his congressional seat. This is 3 races in a few weeks where the Trump endorsed candidates beat the incumbents. What does this mean for MAGA moving forward? And, why libertarianism isn't the same as being conservative.

True Story with Mike Slater
What To Do With The Donald Trump Blast Radius?

True Story with Mike Slater

Play Episode Listen Later May 20, 2026 19:15


Thomas Massie lost his congressional seat. This is 3 races in a few weeks where the Trump endorsed candidates beat the incumbents. What does this mean for MAGA moving forward? And, why libertarianism isn't the same as being conservative.

Voice of the DBA
Limit the Blast Radius

Voice of the DBA

Play Episode Listen Later May 19, 2026 3:35


You still need DBAs (that know how to back up systems and test restores). If you think you don't, or if you manager does, then perhaps they ought to read this piece on how an AI agent deleted a production database. This wasn't the case of an agent just running around with sysadmin access to all resources, or a lack of tests that allowed bad code to flow through a CI/CD process. This was a system design that had a hole in it. An API call to change infrastructure that could change both staging and production. Not something an AI set up, but humans did. A hole from both PocketOS and the API vendor that allowed the AI agent to make the same type of mistake we've seen humans make. A mistake of not double checking, not verifying, not following the rules of getting a second set of eyes, even a second set of virtual eyes, on the code that could drop resources. Read the rest of Limit the Blast Radius

Beyond The Horizon
The Epstein Files, Missing Racketeering Charges, and the Fear of Expanding the Blast Radius (5/8/26)

Beyond The Horizon

Play Episode Listen Later May 8, 2026 19:57 Transcription Available


The handling of Jeffrey Epstein's criminal enterprise appeared narrow from the very beginning, not because investigators lacked awareness of the broader network surrounding him, but because expanding the scope would have risked exposing powerful institutions and influential figures across politics, finance, academia, royalty, and international elite circles. Rather than pursuing a sweeping enterprise case under statutes like RICO, prosecutors repeatedly confined the investigations to smaller, more manageable prosecutions focused primarily on Epstein and later Ghislaine Maxwell. A true racketeering case would have required investigators to map the full structure of the operation, including recruiters, facilitators, financial systems, social gatekeepers, and institutional enablers. That kind of investigation would have inevitably widened the blast radius and forced public scrutiny onto banks, universities, charities, political figures, and global power networks connected to Epstein's world. Instead, authorities consistently appeared to prioritize containment, reputational management, and institutional stability over fully exposing the entire ecosystem surrounding Epstein's activities.For years, that containment strategy largely worked because the public only saw fragments of the story through isolated headlines, civil lawsuits, and limited criminal proceedings. But the release of large volumes of court filings, emails, depositions, and investigative records fundamentally changed the landscape by allowing independent journalists, researchers, and the public to connect patterns that had previously remained compartmentalized. As more information surfaced, the narrative stopped looking like a scandal centered on one wealthy predator and increasingly resembled a broader story about institutional protection, selective accountability, and elite networks operating behind layers of influence and plausible deniability. The government's reluctance to aggressively pursue co-conspirators, combined with its repeated use of tightly controlled prosecutions, fueled growing public skepticism that authorities were intentionally limiting exposure to avoid destabilizing powerful institutions and damaging politically sensitive relationships. What officials long feared—a scandal too large to effectively manage—has now become reality as the Epstein story continues expanding far beyond the narrow scope authorities originally attempted to impose upon it.to contact me:bobbycapucci@protonmail.com

The Moscow Murders and More
The Epstein Files, Missing Racketeering Charges, and the Fear of Expanding the Blast Radius (5/8/26)

The Moscow Murders and More

Play Episode Listen Later May 8, 2026 19:57 Transcription Available


The handling of Jeffrey Epstein's criminal enterprise appeared narrow from the very beginning, not because investigators lacked awareness of the broader network surrounding him, but because expanding the scope would have risked exposing powerful institutions and influential figures across politics, finance, academia, royalty, and international elite circles. Rather than pursuing a sweeping enterprise case under statutes like RICO, prosecutors repeatedly confined the investigations to smaller, more manageable prosecutions focused primarily on Epstein and later Ghislaine Maxwell. A true racketeering case would have required investigators to map the full structure of the operation, including recruiters, facilitators, financial systems, social gatekeepers, and institutional enablers. That kind of investigation would have inevitably widened the blast radius and forced public scrutiny onto banks, universities, charities, political figures, and global power networks connected to Epstein's world. Instead, authorities consistently appeared to prioritize containment, reputational management, and institutional stability over fully exposing the entire ecosystem surrounding Epstein's activities.For years, that containment strategy largely worked because the public only saw fragments of the story through isolated headlines, civil lawsuits, and limited criminal proceedings. But the release of large volumes of court filings, emails, depositions, and investigative records fundamentally changed the landscape by allowing independent journalists, researchers, and the public to connect patterns that had previously remained compartmentalized. As more information surfaced, the narrative stopped looking like a scandal centered on one wealthy predator and increasingly resembled a broader story about institutional protection, selective accountability, and elite networks operating behind layers of influence and plausible deniability. The government's reluctance to aggressively pursue co-conspirators, combined with its repeated use of tightly controlled prosecutions, fueled growing public skepticism that authorities were intentionally limiting exposure to avoid destabilizing powerful institutions and damaging politically sensitive relationships. What officials long feared—a scandal too large to effectively manage—has now become reality as the Epstein story continues expanding far beyond the narrow scope authorities originally attempted to impose upon it.to contact me:bobbycapucci@protonmail.comBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-moscow-murders-and-more--5852883/support.

The Epstein Chronicles
The Epstein Files, Missing Racketeering Charges, and the Fear of Expanding the Blast Radius (5/7/26)

The Epstein Chronicles

Play Episode Listen Later May 7, 2026 19:57 Transcription Available


The handling of Jeffrey Epstein's criminal enterprise appeared narrow from the very beginning, not because investigators lacked awareness of the broader network surrounding him, but because expanding the scope would have risked exposing powerful institutions and influential figures across politics, finance, academia, royalty, and international elite circles. Rather than pursuing a sweeping enterprise case under statutes like RICO, prosecutors repeatedly confined the investigations to smaller, more manageable prosecutions focused primarily on Epstein and later Ghislaine Maxwell. A true racketeering case would have required investigators to map the full structure of the operation, including recruiters, facilitators, financial systems, social gatekeepers, and institutional enablers. That kind of investigation would have inevitably widened the blast radius and forced public scrutiny onto banks, universities, charities, political figures, and global power networks connected to Epstein's world. Instead, authorities consistently appeared to prioritize containment, reputational management, and institutional stability over fully exposing the entire ecosystem surrounding Epstein's activities.For years, that containment strategy largely worked because the public only saw fragments of the story through isolated headlines, civil lawsuits, and limited criminal proceedings. But the release of large volumes of court filings, emails, depositions, and investigative records fundamentally changed the landscape by allowing independent journalists, researchers, and the public to connect patterns that had previously remained compartmentalized. As more information surfaced, the narrative stopped looking like a scandal centered on one wealthy predator and increasingly resembled a broader story about institutional protection, selective accountability, and elite networks operating behind layers of influence and plausible deniability. The government's reluctance to aggressively pursue co-conspirators, combined with its repeated use of tightly controlled prosecutions, fueled growing public skepticism that authorities were intentionally limiting exposure to avoid destabilizing powerful institutions and damaging politically sensitive relationships. What officials long feared—a scandal too large to effectively manage—has now become reality as the Epstein story continues expanding far beyond the narrow scope authorities originally attempted to impose upon it.to contact me:bobbycapucci@protonmail.comBecome a supporter of this podcast: https://www.spreaker.com/podcast/the-epstein-chronicles--5003294/support.

EChannelNews Podcast
Mapping the Blast Radius: WanAware's Actionable Observability and the OneWire Roadmap

EChannelNews Podcast

Play Episode Listen Later Apr 29, 2026 41:06


Send us Fan MailJeff Collins, CEO of WanAware, explored the shift toward Visibility-as-a-Service (VaaS), a model designed to help MSPs manage the increasing complexity of AI-accelerated infrastructure. He defined their core value proposition as “actionable observability”—a method that moves beyond simple data collection to map the complex relationships and “blast radius” of dependencies across cloud, on-premises, IoT, and OT environments. By establishing a real-time knowledge graph, the platform can auto-discover ephemeral or developer-deployed resources that traditional scanners often miss, effectively reducing the noise of false positives that plague modern security operations.He also addressed the telemetry trap, where organizations collect massive amounts of data in silos but fail to derive automated context. WanAware's solution uses a lightweight, no-code integrator to ingest disparate APIs and correlate them into a unified view. This architectural approach allows MSPs to capture tribal knowledge from their senior engineers and convert it into automated playbooks. These playbooks are then executed with strict AI grounding and per-action verification, ensuring that incident responses are consistent, documented, and free from the risks of manual, spreadsheet-driven workflows.

The Resilient Journey
Episode 228 - Understanding Blast Radius in Resilience - Mark Hoffman

The Resilient Journey

Play Episode Listen Later Mar 30, 2026 24:40


Mark recently posted a poll on LinkedIn, asking if people use the phrase "blast radius". Some of you said yes, you use it, but most said no. And others expressed concern about the phrase itself. Let's dig into it.   Hello everyone and welcome to episode 228 of the Resilient Journey Podcast, presented by Anesis Consulting Group!   This week Mark takes a few minutes to share the concept of 'blast radius' and its use in terms of business resilience strategies.   He starts by addressing the thoughtful comments of our colleagues regarding the phrase and how it may not be received well in some settings. But whether you use the term blast radius or impact radius, the concepts are worth noting. Mark talks about Concentration risk,  and says that “Resilience isn't about preventing failure—it's about preventing failure from becoming catastrophic.”   Be sure to follow The Resilient Journey!  We sure do appreciate it! Check out the Resilient Journey Hub! Want to learn more about Mark? Click here or on LinkedIn. Special thanks to Bensound for the music.

The CyberWire
A subtle flaw, a massive blast radius. [Research Saturday]

The CyberWire

Play Episode Listen Later Mar 21, 2026 17:18


Yuval Avrahami from Wiz joins to share their work on "CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild." Wiz Research uncovered “CodeBreach,” a critical supply chain vulnerability caused by a subtle misconfiguration in AWS CodeBuild pipelines that allowed attackers to take over key GitHub repositories, including the widely used AWS JavaScript SDK that powers the AWS Console. By exploiting an unanchored regex filter, unauthenticated attackers could trigger privileged builds, steal credentials, and potentially inject malicious code into software used across a majority of cloud environments. AWS has since remediated the issue and introduced stronger safeguards, but the incident highlights a growing trend of attackers targeting CI/CD pipelines where small misconfigurations can lead to massive downstream impact. The research can be found here: CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild Learn more about your ad choices. Visit megaphone.fm/adchoices

Research Saturday
A subtle flaw, a massive blast radius.

Research Saturday

Play Episode Listen Later Mar 21, 2026 17:18


Yuval Avrahami from Wiz joins to share their work on "CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild." Wiz Research uncovered “CodeBreach,” a critical supply chain vulnerability caused by a subtle misconfiguration in AWS CodeBuild pipelines that allowed attackers to take over key GitHub repositories, including the widely used AWS JavaScript SDK that powers the AWS Console. By exploiting an unanchored regex filter, unauthenticated attackers could trigger privileged builds, steal credentials, and potentially inject malicious code into software used across a majority of cloud environments. AWS has since remediated the issue and introduced stronger safeguards, but the incident highlights a growing trend of attackers targeting CI/CD pipelines where small misconfigurations can lead to massive downstream impact. The research can be found here: CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild Learn more about your ad choices. Visit megaphone.fm/adchoices

@BEERISAC: CPS/ICS Security Podcast Playlist
Opportunistic by Default: How OT gets pulled into the blast radius

@BEERISAC: CPS/ICS Security Podcast Playlist

Play Episode Listen Later Jan 30, 2026 34:21


Podcast: Safe Mode Podcast (LS 25 · TOP 10% what is this?)Episode: Opportunistic by Default: How OT gets pulled into the blast radiusPub date: 2026-01-29Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationIn this episode of Safe Mode, we look at how opportunistic campaigns—often starting as loud disruption like DDoS—can probe for weak points and, in some cases, move closer to operational technology and industrial control systems. Using a recent Justice Department case tied to pro‑Russia hacktivist groups as a jumping-off point, we discuss what this pattern says about the OT threat landscape in 2025, from remote access and trust boundaries to engineering workflows and data integrity risk. Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks, joins to explain what defenders should prioritize now to keep “noise” from becoming real-world operational impact.The podcast and artwork embedded on this page are from Safe Mode Podcast, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.

PolySécure Podcast
Actu - 7 septembre - Parce que... c'est l'épisode 0x626!

PolySécure Podcast

Play Episode Listen Later Sep 8, 2025 31:44


Parce que… c'est l'épisode 0x626! Shameless plug 10 et 11 septembre 2025 - GoSec 2025 Code rabais de 15% - GSPOL25 13 septembre 2025 - BSides Montreal 2025 12 au 17 octobre 2025 - Objective by the sea v8 14 et 15 octobre 2025 - ATT&CKcon 6.0 14 et 15 octobre 2025 - Forum inCyber Canada Code rabais de 30% - CA25KDUX92 10 au 12 novembre 2025 - IAQ - Le Rendez-vous IA Québec 17 au 20 novembre 2025 - European Cyber Week 25 et 26 février 2026 - SéQCure 2026 Description Notes Divers How Has IoT Security Changed Over the Past 5 Years? Hackers Leverage Raw Disk Reads to Bypass EDR Solutions and Access Highly Sensitive Files Qantas penalizes executives for July cyberattack CVE-2025-6785 - Tesla Model 3 Physical CAN Bus Injection Android drops mega patch bomb - 120 fixes, two already exploited Automated Sextortion Spyware Takes Webcam Pics of Victims Watching Porn SIM Swapping Attacks on the Rise – How eSIM can Make SIM Swapping Harder Europe Putin the blame on Russia after GPS jamming disrupts president's plane Almost Every State Has Its Own Deepfakes Law Now No, Google did not warn 2.5 billion Gmail users to reset passwords IA Hackers Use AI Platforms to Steal Microsoft 365 Credentials in Phishing Campaign AI code assistants make developers more efficient at creating security problems Comment manipuler psychologiquement une IA ? Les techniques qui marchent vraiment LegalPWN - Pour piéger les IA avec les petites lignes Indirect Prompt Injection Attacks Against LLM Assistants BruteForceAI - L'IA qui cracke vos mots de passe Hackers Leverage Hexstrike-AI Tool to Exploit Zero Day Vulnerabilities Within 10 Minutes Ollama - 14 000 serveurs IA laissés en libre-service sur Internet Europe et souveraineté EUVD: first step toward Europe's cybersecurity sovereignty? Switzerland Launches Apertus: A Public, Open-Source AI Model Built for Privacy EU court's dismissal of US data transfer challenge raises privacy advocates' ire SAP to invest over 20 billion euros in ‘sovereign cloud' in boost to Europe's AI ambitions Chaine d'approchées Blast Radius of Salesloft Drift Attacks Remains Uncertain Addressing the unauthorized issuance of multiple TLS certificates for 1.1.1.1 How big will this Drift get? Cloudflare cops to Salesloft Drift breach The impact of the Salesloft Drift breach on Cloudflare and our customers Zscaler Confirms Data Breach – Hackers Compromised Salesforce Instance and Stole Customer Data Collaborateurs Nicolas-Loïc Fortin Crédits Montage par Intrasecure inc Locaux réels par Intrasecure inc

Cyber Morning Call
820 - Juniper corrige Blast-RADIUS e falha crítica em interface web

Cyber Morning Call

Play Episode Listen Later Jul 10, 2025 5:05


Referências do Episódio2025-07 Security Bulletin: Junos OS and Junos OS Evolved: Vulnerability in the RADIUS protocol for Subscriber Management (Blast-RADIUS) (CVE-2024-3596)Blast-RADIUS2025-07 Security Bulletin: Juniper Security Director: Insufficient authorization for multiple endpoints in web interface (CVE-2025-52950)ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLsFrom Click to Compromise: Unveiling the Sophisticated Attack of DoNot APT Group on Southern European Government EntitiesIranian group Pay2Key.I2P ramps Up ransomware attacks against Israel and US with incentives for affiliatesRoteiro e apresentação: Carlos Cabral e Bianca OliveiraEdição de áudio: Paulo ArruzzoNarração de encerramento: Bianca Garcia

Cloud Security Podcast
Adapting to New Threats, Copilot Risks & The Future of Data (Feat. Matthew Radolec, Varonis)

Cloud Security Podcast

Play Episode Listen Later Jun 3, 2025 39:31


AI is reshaping cybersecurity as we know it. From sophisticated AI-driven phishing attacks to the amplified risk of insider threats using tools like Copilot, the landscape is shifting at an unprecedented pace. How can security leaders and practitioners adapt?Join Ashish Rajan and Matthew Radolec (Varonis) as they explore the critical challenges and opportunities AI presents. Learn why 86% of attacks involve credential misuse and how AI agents are making it easier than ever for non-technical insiders to exfiltrate data.In this episode, you'll learn about:The "Blast Radius": How AI tools can dramatically increase data exposure.From "Breaking In" to "Logging In": The dominance of credential-based attacks.AI-Powered Social Engineering: The rise of "conversational bait".Copilot Use Cases & "Aha!" MomentsData Integrity in AI: The critical, overlooked pillar of AI security.The Enduring Importance of Access Management in an AI World.Transforming Security Operations: AI for incident response, playbooks, and forensics.Guest Socials - ⁠Matt's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Cybersecurity, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ AI Cybersecurity PodcastQuestions asked:(00:00) Introduction(01:57) New Threat Landscape in Cloud & AI(08:08) Use cases for regulated industries(10:03) Impact of Agentic AI in the cybersecurity space(12:22) Blind spots of going into AI(18:06) Shared responsibility for LLM providers(20:56) Lifting up security programs for AI(27:82) How is incident response changing with AI?(29:30) Cybersecurity areas that will be most impacted by AI(34:43) The Fun SectionThank you to our episode sponsor Varonis

Shark Theory
Protect Your Circle: Manage Your Battles and Blast Radius

Shark Theory

Play Episode Listen Later May 1, 2025 6:31


In this engaging episode of "Shark Theory," host Baylor Barbee delves into the complexities of personal struggles and their impact on those around us. The central theme revolves around his thought-provoking quote: "Don't let others get caught in the crossfire of you battling your own demons." Through personal anecdotes and a reflective analysis of human behavior, Baylor navigates the challenges of maintaining personal integrity and empathy when facing life's inevitable hurdles. Baylor emphasizes the importance of recognizing personal and professional "blast radii" — the zones within which negative emotions can inadvertently affect others. By understanding these emotional boundaries, individuals can mitigate unintended harm to others during difficult times. The episode underscores the universal truth that everyone carries hidden battles, urging listeners to practice compassion and self-awareness. Baylor prods listeners to confront their adversities head-on to prevent ongoing cycles of harm and to fully step into their strengths. Key Takeaways: Empathy in Relationships: Our personal struggles often affect those close to us, making empathy and understanding crucial in maintaining strong relationships. Awareness of Impact: Recognizing one's "blast radius" can help limit the adverse effects of our struggles on others. Battle Recognition: Understanding that everyone faces their own battles highlights the need for grace and compassion. Facing Fears: Confronting personal demons is vital to breaking cycles that harm ourselves and those around us. Communication is Key: Notifying others about personal boundaries can help protect relationships and prevent miscommunication. Notable Quotes: "Don't let others get caught in the crossfire of you battling your own demons." "Nobody has it all together. Nobody is as carefree as they may lead out to believe." "If you're standing in this perimeter of where this thing lands, you're going to get hurt." "You have to realize the gravity of what you have and knowing how big your blast radius is." "It's time to stand up. It's time to fight. It's time to step into who you are."

The Loh Down on Science
Brain Blast Radius

The Loh Down on Science

Play Episode Listen Later Feb 21, 2025 1:00


Target acquired. Locked On. And… Bullseye!

Storm⚡️Watch by GreyNoise Intelligence
Ivanti's Blast Radius Expands, CFIUS Hack, & Censeye Automates Threat Hunting

Storm⚡️Watch by GreyNoise Intelligence

Play Episode Listen Later Jan 14, 2025 60:13


Forecast: Breach storms surge with Chinese actors, Ivanti spreads wider, and malware disguises itself—stay alert and patched! ‍ This episode of Storm⚡️Watch features exciting developments in security tooling and concerning breaches in critical infrastructure. We're thrilled to finally talk about Censeye on the pod! It's Censys's powerful new automated hunting platform that's revolutionizing how security teams conduct threat hunting. This innovative tool combines automation with Censys's comprehensive internet scanning capabilities, complete with new gadgets that enhance threat detection and analysis capabilities. In major security news, a significant breach at the US Treasury's Committee on Foreign Investment (CFIUS) has been attributed to Chinese state-sponsored actors. This concerning development potentially exposed sensitive data about national security reviews of foreign investments in American companies. The Ivanti vulnerability situation continues to evolve, with UK domain registry giant Nominet now confirming they've been impacted by the recent Ivanti VPN exploits. This development highlights the expanding blast radius of this critical security issue. 2025 has already seen sophisticated threat actors weaponizing exploits, with researchers uncovering an information stealer disguised as a proof-of-concept exploit for the LDAPNightmare vulnerability (CVE-2024-49113). We'll explore how Censys Search is strengthening phishing prevention through advanced SSL/TLS certificate monitoring, providing organizations with crucial tools to identify and prevent potential phishing campaigns. The episode concludes with an in-depth look at GreyNoise classifications, particularly focusing on suspicious activity patterns identified in the last 24 hours. We'll break down what these classifications mean for security teams and how to leverage this intelligence effectively. Storm Watch Homepage >> Learn more about GreyNoise >>  

Backup Central's Restore it All
Reducing Your Cyberattack Blast Radius: Expert Tips

Backup Central's Restore it All

Play Episode Listen Later Aug 19, 2024 37:51 Transcription Available


In this eye-opening episode of The Backup Wrap-up, we delve into the critical concept of minimizing the cyberattack blast radius. Joined by cybersecurity expert Dr. Mike Saylor, we explore practical strategies to significantly reduce the impact of a breach on your organization.We start by discussing the principle of least privilege access and its role in containing a cyberattack's blast radius. Next, we examine the importance of network segmentation in limiting the spread of an attack. The conversation then shifts to the often-overlooked aspect of controlling outbound traffic to prevent data exfiltration.Throughout the episode, we provide actionable insights and best practices that IT professionals and business owners can implement to enhance their cybersecurity posture. By focusing on minimizing the cyberattack blast radius, organizations can better protect their digital assets and mitigate potential damages in the event of a breach.

No More Secrets
What's old is new again!

No More Secrets

Play Episode Listen Later Jul 25, 2024 26:46


Sit a spell and listen in as our team talks about another Patch Tuesday! Also, did you know that RADIUS is still in use? There's a new attack for it dubbed "Blast-RADIUS," and we're just as surprised as you are about it. We cover the "new" RockYou 2024 password list, and our guest, Brian Gittinger tells us about his journey into information security. All that, and other topics on Episode 6! Hosts: Ryan Hamrick & Chris DeBrunner Editor & Producer: Lance Hart Executive Producers: Gabby Scott & Jana Korfhagen Contact email: nmspod@protonmail.com

radius patch tuesday blast radius rock you
The Cybersecurity Defenders Podcast
#143 - Intel Chat: Blast-RADIUS, Chrome, AT&T, Kaspersky & Crowdstrike

The Cybersecurity Defenders Podcast

Play Episode Listen Later Jul 24, 2024 39:04


In this episode of The Cybersecurity Defenders Podcast, we discuss some cutting-edge intel coming out of LimaCharlie's community Slack channel.Blast-RADIUS is a vulnerability in the RADIUS protocol that allows a man-in-the-middle attacker to forge valid protocol accept messages in response to failed authentication requests.The blog post on Syntax-Err0r details a technique for silently installing a Chrome extension to maintain persistence, bypassing typical detection methods.American telecom service provider AT&T has confirmed that threat actors managed to access data belonging to "nearly all" of its wireless customers as well as customers of mobile virtual network operators using AT&T's wireless network.The U.S. Department of Commerce added Kaspersky to its Entity List, barring U.S. businesses from engaging with the company due to national security concerns related to the Russian government's influence over Kaspersky's operations.On July 19th Crowdstrike distributed a faulty update to its Falcon sensors that caused widespread problems with computers running Microsoft Windows. As a result, roughly 8.5 million systems crashed, bringing up the feared blue screen of death, in what is being called the largest IT outage in history (+outage 1-month ago, +outage 3-months ago).

The Other Side Of The Firewall
Is The New RADIUS Vulnerability A Blast? Everything You Need To Know About The Blast Radius Attack

The Other Side Of The Firewall

Play Episode Listen Later Jul 16, 2024 15:29


The conversation discusses a recent article about a new attack on a 30-year-old protocol called RADIUS. The protocol is widely used in networks for client-server interactions, including VPN access, DSL and fiber connections, and 5G authentication. The attack, called Blast Radius, exploits vulnerabilities in the MD5 hash used in the protocol. The attack allows adversaries to elicit a response from the Radius server and gain unauthorized access to the network. The conversation highlights the importance of identifying and mitigating the vulnerabilities in the protocol to protect networks. Article: New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere https://arstechnica.com/security/2024/07/new-blast-radius-attack-breaks-30-year-old-protocol-used-in-networks-everywhere/?fbclid=IwZXh0bgNhZW0CMTAAAR24e6Catk5kfoECwbCrkcWDlpHdNmajX4dWBn5rw1ZIq4tfFw1nkXFY_4g_aem_EMmWxbRvyOaRTCMQchyQiQ Please LISTEN

The 443 - Security Simplified

https://youtu.be/wozYlHlPPmE This week on the podcast we discover the newly-disclosed protocol vulnerability in certain RADIUS implementations. Before that, we give an update on the continued fallout from the Snowflake customer databreaches including a new disclosure from AT&T. We also discuss a blog post from JFrog that details how they saved the world from what could have been the worst supply chain attack in history.

snowflakes radius blast radius
Paul's Security Weekly TV
More Vulnerability Shenanigans - PSW #834

Paul's Security Weekly TV

Play Episode Listen Later Jul 12, 2024 141:14


Bats in your headset, Windows Wifi driver vulnerabilities, Logitech's dongles, lighthttpd is heavy with vulnerabilities, node-ip's not vulnerability, New Intel CPU non-attacks, Blast Radius, Flipper Zero alternatives, will OpenSSH be exploited, emergency Juniper patches, and the D-Link botnet grows. Show Notes: https://securityweekly.com/psw-834

Paul's Security Weekly (Video-Only)
More Vulnerability Shenanigans - PSW #834

Paul's Security Weekly (Video-Only)

Play Episode Listen Later Jul 12, 2024 141:14


Bats in your headset, Windows Wifi driver vulnerabilities, Logitech's dongles, lighthttpd is heavy with vulnerabilities, node-ip's not vulnerability, New Intel CPU non-attacks, Blast Radius, Flipper Zero alternatives, will OpenSSH be exploited, emergency Juniper patches, and the D-Link botnet grows. Show Notes: https://securityweekly.com/psw-834

Paul's Security Weekly
RFID hacking & More Vulnerability Shenanigans - Iceman - PSW #834

Paul's Security Weekly

Play Episode Listen Later Jul 11, 2024 210:33


Bats in your headset, Windows Wifi driver vulnerabilities, Logitech's dongles, lighthttpd is heavy with vulnerabilities, node-ip's not vulnerability, New Intel CPU non-attacks, Blast Radius, Flipper Zero alternatives, will OpenSSH be exploited, emergency Juniper patches, and the D-Link botnet grows. Iceman comes on the show to talk about RFID and NFC hacking including the tools, techniques, and hardware. We'll also talk about the ethics behind the disclosure of vulnerabilities and weaknesses in these systems that are used in everything from building access to cars. Segment Resources: Youtube channel - https://www.youtube.com/@iceman1001 Proxmark3 forums - http://www.proxmark.org/forum/index.php Proxmark3 Repository - https://github.com/rfidresearchgroup/proxmark3 Awesome RFID talks - https://github.com/doegox/awesome-rfid-talks Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-834

Paul's Security Weekly (Podcast-Only)
RFID hacking & More Vulnerability Shenanigans - Iceman - PSW #834

Paul's Security Weekly (Podcast-Only)

Play Episode Listen Later Jul 11, 2024 210:33


Bats in your headset, Windows Wifi driver vulnerabilities, Logitech's dongles, lighthttpd is heavy with vulnerabilities, node-ip's not vulnerability, New Intel CPU non-attacks, Blast Radius, Flipper Zero alternatives, will OpenSSH be exploited, emergency Juniper patches, and the D-Link botnet grows. Iceman comes on the show to talk about RFID and NFC hacking including the tools, techniques, and hardware. We'll also talk about the ethics behind the disclosure of vulnerabilities and weaknesses in these systems that are used in everything from building access to cars. Segment Resources: Youtube channel - https://www.youtube.com/@iceman1001 Proxmark3 forums - http://www.proxmark.org/forum/index.php Proxmark3 Repository - https://github.com/rfidresearchgroup/proxmark3 Awesome RFID talks - https://github.com/doegox/awesome-rfid-talks Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-834

The CyberWire
Old school, new threat.

The CyberWire

Play Episode Listen Later Jul 10, 2024 35:29


Blast-RADIUS targets a network authentication protocol. The US disrupts a Russian disinformation campaign. Anonymous messaging app NGL is slapped with fines and user restrictions. The NEA addresses AI use in classrooms. Gay Furry Hackers release data from a conservative think tank. Microsoft and Apple change course on OpenAI board seats. Australia initiates a nationwide technology security review. A Patch Tuesday rundown. Guest Jack Cable, Senior Technical Advisor at CISA, with the latest from CISA's Secure by Design Alert series. Our friend Graham Cluley ties the knot.  Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Guest Jack Cable, Senior Technical Advisor at CISA, joins us to share an update on CISA's Secure by Design Alert series. For some background, you can find CISA's Secure by Design whitepaper here. Details on today's update can be found here.  Selected Reading New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere (Ars Technica) US Disrupts AI-Powered Russian Bot Farm on X (SecurityWeek) FTC says anonymous messaging app failed to stop ‘rampant cyberbullying' (The Verge) NEA Approves AI Guidance, But It's Vital for Educators to Tread Carefully (EducationWeek) Hackvists release two gigabytes of Heritage Foundation data (CyberScoop) Microsoft and Apple ditch OpenAI board seats amid regulatory scrutiny (The Verge) Australia instructs government entities to check for tech exposed to foreign control (The Record) Microsoft July 2024 Patch Tuesday fixes 142 flaws, 4 zero-days (BleepingComputer) Graham Cluley ties the knot (Mastodon)  Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.  Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

EC&M ”On Air”
Determining Blast Radius for Debris During an Arc Flash with Tommy Northcott — EC&M On Air Highlights

EC&M ”On Air”

Play Episode Listen Later Jul 8, 2024 8:53


In Episode 49 of “EC&M On Air,” Ellen Parson, editor-in-chief of EC&M, is highlighting some of the most popular technical content we've been running recently, but this time brought to you in audio-only form. In case you missed it, this content was originally brought to you in our EC&M Asks Q&A video series. This week, we're featuring subject matter expert Tommy Northcott, who addresses some of our readers' most pressing questions about arc flash hazards, including why calculating the blast radius for debris during an arc flash event can be more complicated than you might think, the difference between arc flash versus arc blast hazards, the consequences for not performing regular maintenance on electrical equipment, how circuit breakers work to clear a fault to minimize potential damage, and safety best practices when conducting thermography or infrared scans on energized electrical equipment.  

Binärgewitter
Binärgewitter Talk #340: the crowd strikes back

Binärgewitter

Play Episode Listen Later Jun 28, 2024 126:02


Sommerurlaubszeit. Es ist heiß und auch die Computer striken. Felix und Ingo begleiten euch durch die kaputte IT. Blast from the Past Japan ist die Floppy Disk (fast) los Floppy Disks für die Marine Toter der Woche Nike Self-Tying Sneakers Amazon Astro Roboter Ring Drohne noch nicht in Deutschland Shapeways Untoter der Woche AI der Woche Fotograf gewinnt in AI Art Contest News alles kaputt Cellebrite und die Smartphones… crowdstrike Maus Radio MausZoom: “Großes Chaos weltweit wegen Computer-Problem” WP: Stuxnet regresshion Atlassian verliert 15 Millionen E-Mail Adressen von Trello Nutzern Rockyou2024 Linux Kernel Privilege Escalation gitlab wird vielleicht gekauft von datadog Tesla hat nicht mehr alle Tassen im Schrank SAPwned BLAST RADIUS Firefox Mastodon: Gabriele Svelto Nvida Kernelmodule Butter aus Luft Rechtschreibrat: Geliked, geliket oder gelikt Lesefoo What you need to know about laziness 1% der Bevölkerung Brother Labelmaker Picks Pipes NixCon2024

West of Centre
‘Blast radius' in B.C. politics

West of Centre

Play Episode Listen Later Jun 21, 2024 51:29


As the provincial political campaign begins a slow burn toward the fall election in British Columbia, the governing B.C. NDP are heading into the summer with a comfortable lead in the polls ahead of their two rival, centre-right parties. But momentum is suddenly building for the B.C. Conservatives, with the party snatching candidates from the opposition B.C. United (formerly known as the British Columbia Liberal Party). What matters more to B.C. United, according to one of West of Centre's guests, is how that "blast radius" affects the party's ability to ready itself to fight in October's election. Are we seeing the "end of the B.C. Liberal era," as another of our guests suggests? Joining West of Centre host Kathleen Petty this week to break down why politics in British Columbia is never boring are Shachi Kurl, president of the Angus Reid Institute; Les Leyne, legislature columnist with the Victoria Times Colonist; and Mike McDonald, political strategist and co-host of Hotel Pacifico, a West Coast political podcast.

The Black Rasslin' Podcast
Blast Radius

The Black Rasslin' Podcast

Play Episode Listen Later Jan 12, 2024 116:26


The Black Rasslin' Podcast returns to discuss The Rock's latest comments about WWE, Jinder Mahal and HOOK getting world title shots next week, Oba Femi winning the NXT North American title, B Fab linking with Bobby Lashley and the Street Profits, early Royal Rumble predictions, and much more! Watch this episode on YouTube: https://youtube.com/live/3ChHkwc0kso Become a BRPatreon member: www.patreon.com/blackrasslin The Black Rasslin' Podcast Theme is produced by Anikan & Vader. www.instagram.com/anikanandvader Subscribe to The Black Rasslin' Podcast: YouTube: youtube.com/c/blackrasslin Apple Podcasts: bit.ly/blackrasslinIT Spotify: bit.ly/blackrasslinSP Google Podcasts: bit.ly/blackrasslinGP SoundCloud: @black-rasslin-podcast

As It Happens from CBC Radio
January 3: Blast radius

As It Happens from CBC Radio

Play Episode Listen Later Jan 3, 2024 51:20


Iran attacks, Palestinian exit applications, Steamboat Mickey horror, Hershey chocolate lawsuit, Star Trek fan ashes and more

Gay Girl Gone
EP 6 - The Blast Radius

Gay Girl Gone

Play Episode Listen Later Dec 13, 2023 54:15


The fallout from the revelation about Amina — and others like her — continue to ripple across the world. A furious Sandra wants closure. Danny, living in Damascus, faces a life-threatening decision. And the blog's loyal readers are left with one persistent question — why?

damascus blast radius
Paul's Security Weekly TV
It's All About the Data: Understanding Your Blast Radius to Reduce Risk - Matt Radolec - BSW #307

Paul's Security Weekly TV

Play Episode Listen Later May 22, 2023 31:15


You can rebuild infrastructure. But you can't un-breach data – Data sits at the core of an organization and is often the most open and vulnerable. This is why data security is the most important and urgent security problem to solve right now. We're joined by Matt Radolec, Senior Director of Incident Response and Cloud Operations at Varonis, to walk through the blast radius concept – from what it is and how to use it to understand your organization's risk, to how it can serve as a guide to securing data from insiders and external attackers. Segment Resources: The Great SaaS Data Risk Exposure report: https://info.varonis.com/hubfs/Files/docs/research_reports/Varonis-The-Great-SaaS-Data-Exposure.pdf The Forrester Wave™: Data Security Platforms, Q1 2023 https://reprints2.forrester.com/#/assets/2/1646/RES178465/report Learn more about the Varonis Data Security Platform https://www.varonis.com/products/data-security-platform   This segment is sponsored by Varonis. Visit https://securityweekly.com/varonis to learn more about them!   Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw307 

Data Mesh Radio
#201 Choose Your Blast Radius and Other Lessons Learned Across 10s of Data Mesh Implementations - Interview w/ Vanya Seth

Data Mesh Radio

Play Episode Listen Later Mar 3, 2023 80:47


Data Mesh Radio Patreon - get access to interviews well before they are releasedEpisode list and links to all available episode transcripts (most interviews from #32 on) hereProvided as a free resource by DataStax AstraDB; George Trujillo's contact info: email (george.trujillo@datastax.com) and LinkedInTranscript for this episode (link) provided by Starburst. See their Data Mesh Summit recordings here and their great data mesh resource center here. You can download their Data Mesh for Dummies e-book (info gated) here.Vanya's LinkedIn: https://www.linkedin.com/in/vanyaseth1809/In this episode, Scott interviewed Vanya Seth, Head of Technology for Thoughtworks India and Global 'Data Mesh Guild' Lead for Thoughtworks. To be clear, Vanya was only representing her own views on the episode.Some key takeaways/thoughts from Vanya's point of view:Data mesh is at a similar inflection point to where microservices was a decade ago. Let's not relearn all the hard lessons they already learned. We should adapt/contextualize to data of course but we can skip a lot of the anti-patterns. Similarly, many people are stuck thinking "there's no way that could work" regarding data mesh like they were when people suggested development and operations be combined in DevOps. It's understandable - it's hard to imagine a post monolithic world when all you've known is monoliths.?Controversial?: We should try hard to prevent creating the fear of missing out (FOMO) for those not doing data mesh. If data mesh isn't right for your org, especially if it isn't right at this time, that's perfectly okay. Don't take on the overhead cost of data mesh if it won't bring more value than cost. Scott note: PREACH!?Controversial?: Some CDOs or CAOs, their organizations don't really get the value of data so they are implementing data mesh to try to prove out value and make their mark. That can obviously create issues if their organizations aren't ready.A few indicators an org is ready for data mesh (see below for expanded context): A) data/AI investments are not delivering the promised/expected returns and/or it's hard to point to the value delivered in general from data/AI investments; B) the organization is attempting to throw more people at centralized data management and it's not working (platform included); and C) there's extremely...

The Alan Cox Show
Jizz Day/ Wednesday's Gone/ Dey Lost/ Flowers In The Static/ Blast Radius/ Clip Clip Boom/ Effin' Trouble/ Hitting The Pipe/ Loan Wolf

The Alan Cox Show

Play Episode Listen Later Jan 30, 2023 170:58


The Alan Cox Show

lost wolf boom flowers hitting loans pipe static jizz effin blast radius lost flowers alan cox show
As It Happens from CBC Radio
August 22: Blast radius

As It Happens from CBC Radio

Play Episode Listen Later Aug 23, 2022 53:59


Russia: Dugina Killing, NL Hydrogen Deal, Andrew Tate Ban, Fruit Art Copyright, Imran Khan Charges, Italy Rice Farmer and more.

blast radius