Podcasts about Fortinet

  • 508PODCASTS
  • 1,966EPISODES
  • 33mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Nov 21, 2025LATEST

POPULARITY

20172018201920202021202220232024

Categories



Best podcasts about Fortinet

Show all podcasts related to fortinet

Latest podcast episodes about Fortinet

Security Conversations
Gemini 3 reactions, Fortinet/Chrome zero-days, a Cloudflare monoculture and a billion-dollar crypto twist

Security Conversations

Play Episode Listen Later Nov 21, 2025 139:41


(Presented by Material Security (https://material.security): We protect your company's most valuable materials -- the emails, files, and accounts that live in your Google Workspace and Microsoft 365 cloud offices.) Three Buddy Problem - Episode 73: The buddies react to Google's release of Gemini 3 and its early performance, new Chrome interface changes landing on users' machines, and major highlights from CYBERWARCON. We revisit the long-running debate over APT naming conventions, examine Amazon's latest threat-intel reporting on Iranian activity, and walk through the Cloudflare outage that briefly knocked chunks of the internet offline. Plus, new APT reports from ESET, Positive Technologies, and SecurityScorecard, and China's CN-CERT (now validated claim) that the U.S. government seized billions in Bitcoin tied to the Lubian mining-pool hack. Cast: Juan Andres Guerrero-Saade (https://twitter.com/juanandres_gs), Ryan Naraine (https://twitter.com/ryanaraine) and Costin Raiu (https://twitter.com/craiu).

The CyberWire
Eviction notice for Media Land.

The CyberWire

Play Episode Listen Later Nov 20, 2025 33:49


The US and allies sanction Russian bulletproof hosting providers. The White House looks to sue states over AI regulations. The US Border Patrol flags citizens' “suspicious” travel patterns. Lawmakers seek to strengthen the SEC's cybersecurity posture. A new Android banking trojan captures content from end-to-end encrypted apps. A hidden browser API raises security concerns. Fortinet patches a zero-day. A Philippine former mayor gets life in prison for scam center human trafficking. Our guest is Cliff Crosland, CEO and Co-founder at Scanner.dev, discussing why security data lakes are ideal for AI in the SOC. Green energy gets hijacked for a blockchain side-hustle.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Cliff Crosland, CEO and Co-founder at Scanner.dev, discussing why security data lakes are ideal for AI in the SOC. Listen to Cliff's full conversation here. Selected Reading Russian bulletproof hosting provider sanctioned over ransomware ties (Bleeping Computer) White House drafts order directing Justice Department to sue states that pass AI regulations (Washington Post) Border Patrol is monitoring US drivers and detaining those with 'suspicious' travel patterns (Associated Press) Lawmakers reintroduce bill to bolster cybersecurity at Securities and Exchange Commission (The Record) Multi-threat Android malware Sturnus steals Signal, WhatsApp messages (Bleeping Computer) Hidden API in Comet AI browser raises security red flags for enterprises (CSO Online) Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime (Infosecurity Magazine) Fortinet Patches Actively Exploited FortiWeb Zero Day Flaw (HIPAA Journal) Ex-Philippine mayor Alice Guo given life sentence for human trafficking (Reuters) Wind farm worker sentenced after turning turbines into a secret crypto mine (Bitdefender) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

The CyberWire
The oversized file that stalled the internet.

The CyberWire

Play Episode Listen Later Nov 19, 2025 29:46


Cloudflare's outage is rooted in an internal configuration error. The Trump administration is preparing a new national cyber strategy. CISA gives federal agencies a week to secure a new Fortinet flaw. MI5 warns that China is using LinkedIn headhunters and covert operatives to target lawmakers. Experts question the national security risks of TP-Link routers. The China-aligned PlushDaemon threat group hijacks software updates. Researchers discover WhatsApp's entire global member directory accessible online without protection. LG Energy Solution confirms a ransomware attack. ShinySp1d3r makes its debut. Rotem Tsadok, Director of Security Operations and Forensics at Varonis, is sharing lessons learned from thousands of forensics investigations. A judge says Google's claims to water use secrecy are all wet.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Rotem Tsadok, Director of Security Operations and Forensics at Varonis, sharing lessons learned from thousands of forensics investigations. Listen to Rotem's full conversation here. Selected Reading Cloudflare blames this week's massive outage on database issues (Bleeping Computer) National cyber strategy will include focus on ‘shaping adversary behavior,' White House official says (The Record) CISA gives govt agencies 7 days to patch new Fortinet flaw (Bleeping Computer) Chinese Spies Are Using LinkedIn to Target U.K. Lawmakers, MI5 Warns (The New York Times) No evidence that TP-Link routers are a Chinese security threat (CSO Online) PlushDaemon compromises network devices for adversary-in-the-middle attacks (welivesecurity) 3.5 Billion Accounts: Complete WhatsApp Directory Retrieved and Evaluated (heise online) LG Energy Solution reports ransomware attack, hackers claim theft of 1.7 terabytes of data (beyondmachines) Meet ShinySp1d3r: New Ransomware-as-a-Service created by ShinyHunters (Bleeping Computer) Google Strives To Keep Data Center Water Use Secret After Judge Orders Records Released (Roanoke Rambler) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Risky Business
Risky Business #815 -- Anthropic's AI APT report is a big deal

Risky Business

Play Episode Listen Later Nov 19, 2025 51:24


In this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: Anthropic says a Chinese APT orchestrated attacks using its AI It's a day ending in -y, so of course there are shamefully bad Fortinet exploits in the wild Turns out slashing CISA was a bad idea, now it's time for a hiring spree Researchers brute force entire phone number space against Whatsapp contact discovery API DOJ figures out how to make SpaceX turn off scam compounds' Starlink service This week's episode is sponsored by Mastercard. Senior Vice President of Mastercard Cybersecurity Urooj Burney joins to talk about how the roles of fraud and cyber teams in the financial sector are starting to converge. Mastercard also recently acquired Recorded Future, and Urooj talks about how they aim to integrate cyber threat intelligence into the financial world. This episode is also available on Youtube. Show notes Full report: Disrupting the first reported AI-orchestrated cyber espionage campaign Researchers question Anthropic claim that AI-assisted attack was 90% autonomous - Ars Technica China's ‘autonomous' AI-powered hacking campaign still required a ton of human work | CyberScoop Amazon discovers APT exploiting Cisco and Citrix zero-days | AWS Security Blog CISA gives federal agencies one week to patch exploited Fortinet bug | The Record from Recorded Future News PSIRT | FortiGuard Labs CISA, eyeing China, plans hiring spree to rebuild its depleted ranks | Cybersecurity Dive This Is the Platform Google Claims Is Behind a 'Staggering' Scam Text Operation | WIRED A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers | WIRED DOJ Issued Seizure Warrant to Starlink Over Satellite Internet Systems Used at Scam Compound | WIRED Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million | The Record from Recorded Future News Cyberattack leaves Jaguar Land Rover short of £680 million | The Record from Recorded Future News FBI: Akira gang has received nearly $250 million in ransoms | The Record from Recorded Future News Operation Endgame: Police reveal takedowns of three key cybercrime tools | The Record from Recorded Future News Inside a Wild Bitcoin Heist: Five-Star Hotels, Cash-Stuffed Envelopes, and Vanishing Funds | WIRED

Cierre de mercados
Cierre de Mercados: 19/11/2025

Cierre de mercados

Play Episode Listen Later Nov 19, 2025 53:59


No terminan de recuperar el pulso los mercados. Están en pausa los castigos recientes a la espera de acontecimientos. El ambiente es de cautela antes de que presente sus resultados Nvidia y se den a conocer datos de empleo en Estados Unidos. La preocupación por las elevadas valoraciones ha puesto a Nasdaq100 más de un 6% por debajo del máximo histórico tocado a finales de octubre. A los inversores también les preocupa que la caída en índices de aprobación y popularidad de Donald Trump pueda impulsar el gasto fiscal y avivar la inflación. Eso mantiene a raya un activo refugio como los bonos del Tesoro. Analizamos el mercado esta hora con José Francisco Ibáñez, de Tressis. En Bolsa española, lideran las caídas Solaria, Indra y Endesa. Los que más rebotan son ArcelorMittal, IAG y Fluidra. También hablamos de IA y ciberseguridad con Acacio Martín, de Fortinet.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Nov 17, 2025 7:10


Fortiweb Vulnerability Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly. https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486 https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/ https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com Flnger.exe and ClickFix Attackers started to use the finger.exe binary to retrieve additional payload in ClickFix attacks https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492

Cyber Security Today
Fortinet Zero Day In Active Exploitation, North Korean Infiltration Grows And More: .Cybersecurity Today for November 16 2025

Cyber Security Today

Play Episode Listen Later Nov 17, 2025 15:33


Critical Cybersecurity Updates: Fortinet Zero Day, North Korean Infiltration & JLR Cyber Attack In this episode of Cybersecurity Today, host David Chipley discusses the latest critical updates in the cybersecurity world. Fortinet faces a massive zero-day vulnerability actively exploited, leading to major security patches. North Korean IT workers have infiltrated 136 companies, massively impacting corporate security and funneling millions to the DPRK. Jaguar Land Rover's cyber attack results in a startling $220 million loss, affecting the UK's economy. Lastly, we delve into widespread copy-pasted flaws across leading AI platforms like Meta and Nvidia. Stay updated, stay secure! 00:00 Introduction and Sponsor Message 00:55 Fortinet Zero-Day Vulnerability 04:32 North Korean IT Worker Infiltration 07:45 Jaguar Land Rover Cyber Attack Impact 10:19 AI Platforms Hit with Copy-Pasted Flaw 13:42 Conclusion and Upcoming Events

Risky Business
Risky Business #814 -- It's a bad time to be a scam compound operator

Risky Business

Play Episode Listen Later Nov 12, 2025 63:19


In this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: The KK Park scam compound in Myanmar gets blasted with actual dynamite China sentences more scammers TO DEATH While Singapore is opting to lash them with the cane Chinese security firm KnownSec leaks a bunch of documents Necromancy continues on NSO Group, with a Trump associate in charge OWASP freshens up the Top 10, you won't believe what's number three! This week's episode is sponsored by Thinkst Canary. Big bird Haroon Meer joins and, as usual, makes a good point. If you're going to trust a vendor to do something risky like put a box on your network, they have an obligation to explain how they make that safe. Thinkst has a /security page that does exactly that. So why do we let Palo Alto and Fortinet get away with “trust me, bro”? This episode is also available on Youtube. Show notes Myanmar Junta Dynamites Scam Hub in PR Move as Global Pressure Grows China sentences 5 Myanmar scam kingpins to death | The Record from Recorded Future News Law passed for scammers, mules to be caned after victims in Singapore lose almost $4b since 2020 | The Straits Times KnownSec breach: What we know so far. - NetAskari Risky Bulletin: Another Chinese security firm has its data leaked Inside Congress Live The Government Shutdown Is a Ticking Cybersecurity Time Bomb | WIRED Former Trump official named NSO Group executive chairman | The Record from Recorded Future News Short-term renewal of cyber information sharing law appears in bill to end shutdown | The Record from Recorded Future News Jaguar Land Rover hack hurt the U.K.'s GDP, Bank of England says Monetary Policy Report - November 2025 | Bank of England SonicWall says state-linked actor behind attacks against cloud backup service | Cybersecurity Dive Japanese media giant Nikkei reports Slack breach exposing employee and partner records | The Record from Recorded Future News "Intel sues former employee for allegedly stealing confidential data" Post by @campuscodi.risky.biz — Bluesky Introduction - OWASP Top 10:2025 RC1

Manufacturing Happy Hour
261: Energy Transition Explained: How Manufacturers Can Save Energy and Build a Sustainable Future featuring Veregy's Eric Spink & Shiva Subramanya

Manufacturing Happy Hour

Play Episode Listen Later Nov 11, 2025 52:52


Sustainability goals are everywhere in manufacturing; net-zero by 2030, carbon neutral by 2035. While many manufacturers have set ambitious targets, the gap between goals and execution remains a challenge, especially when sustainability projects compete with production priorities for capital.Eric Spink and Shiva Subramanya from Veregy join the show to talk about energy transition and what it looks like in practice. Energy used to be just another line item and the cost of doing business, now it's tied to resilience, sustainability, and a company's long-term strategy.One key insight from the conversation was how the equipment on the perimeter of your manufacturing floor (think compressed air systems, boilers, refrigeration, and HVAC) consumes 60-80% of your plant's total energy.But manufacturers typically don't have expertise in these support utilities, which is why they get overlooked for efficiency opportunities.We dive into real projects, including a five-plant dairy operation where AI can predict steam demand based on production data. Plus, how performance contracting allows manufacturers to fund these projects using energy savings rather than tying up capital.In this episode, find out:Why energy has evolved from an expense to a strategic priorityHow perimeter equipment consumes 60-80% of plant energy but often receives the least attentionWhy sustainability projects typically compete with production priorities for budgetHow performance contracting uses energy savings to fund improvements without capital investmentThe low-hanging fruit in most plants, such as compressed air leaks, lighting upgrades, and controls optimizationWhat happens when you connect production data with utility systems using AI and advanced controlsReal examples from dairy processing that delivered significant energy savingsEnjoying the show? Please leave us a review here. Even one sentence helps. It's feedback from Manufacturing All-Stars like you that keeps us going!Tweetable Quotes:“Traditionally, manufacturing companies have relied on their own capital to implement sustainability projects. But they always compete with productivity goals. With performance contractors, companies can now use the savings from energy reductions and put their capital elsewhere but still implement energy efficiency projects.” - Eric Spink“Upgrading control systems by putting in PLC-based controls, and adding instrumentation and metering really allows all these systems to consume a lot less energy. Historically these have yielded very high paybacks, between one and a half and two years in many cases.” - Eric Spink“Having a sustainability goal is important, but having a sustainability plan is key. The sustainability plan needs to include how the organization is going to implement it and how it's going to be funded year-on-year.” - Shiva SubramanyaLinks & mentions:Veregy, an award-winning decarbonization company providing turnkey engineering and construction services to reduce energy costs through efficiency upgrades, smart building technology, EV infrastructure, and clean energy solutions.Skillwork, a premier staffing agency providing skilled industrial technicians on a contract basis to augment facility teams across 30+ states for elevated impact and decreased downtime.Fortinet, securing the world's largest enterprises, service...

NY to ZH Täglich: Börse & Wirtschaft aktuell
Wall Street mit Vorsicht zu genießen | New York to Zürich Täglich

NY to ZH Täglich: Börse & Wirtschaft aktuell

Play Episode Listen Later Nov 6, 2025 14:53


In Folge der Quartalszahlen geht es bei den Aktien von Snap, Moderna, Figma, ARM und Albermarle teils deutlich bergauf. Wir sehen hingegen massive Kurseinbrüche bei Duolingo, DoorDash, Elf Beauty und Fortinet. Medienberichten zur Folge hat Softbank zu Beginn des Jahres eine Übernahme von Marvell in Erwägung gezogen. Die beiden Parteien konnten sich nicht einigen. Wie dem auch sei, geht es wegen dieser Berichte bei dem Wert aufwärts. Nach dem Closing werden die Ergebnisse von Airbnb, Affirm und Block im Fokus stehen. Außerdem beginnt um 22 Uhr MEZ die Hauptversammlung von Tesla. Marktteilnehmer gehen davon aus, dass trotz des Widerstands einiger Aktionäre, das $1 Bio. Zahlungspaket an Musk genehmigt wird. Was den Regierungs-Shutdown betrifft, sehen wir ab diesen Freitag bei 40 Flughäfen eine Reduktion der Flüge um 10%. Immer mehr Fluglotsen bleiben wegen der Gehaltsausfälle zu Hause. Abonniere den Podcast, um keine Folge zu verpassen! ____ Folge uns, um auf dem Laufenden zu bleiben: • X: http://fal.cn/SQtwitter • LinkedIn: http://fal.cn/SQlinkedin • Instagram: http://fal.cn/SQInstagram

Wall Street mit Markus Koch
Vorsichtig Optimistisch | Bild bleibt zerrissen

Wall Street mit Markus Koch

Play Episode Listen Later Nov 6, 2025 19:43


Der Grundton an der Wall Street ist positiv, wobei das Bild zerrissen bleibt. In Folge der Quartalszahlen geht es bei den Aktien von Snap, Moderna, Figma, ARM und Albermarle teils deutlich bergauf. Wir sehen hingegen massive Kurseinbrüche bei Duolingo, DoorDash, Elf Beauty und Fortinet. Medienberichten zur Folge hat Softbank zu Beginn des Jahres eine Übernahme von Marvell in Erwägung gezogen. Die beiden Parteien konnten sich nicht einigen. Wie dem auch sei, geht es wegen dieser Berichte bei dem Wert aufwärts. Nach dem Closing werden die Ergebnisse von Airbnb, Affirm und Block im Fokus stehen. Außerdem beginnt um 22 Uhr MEZ die Hauptversammlung von Tesla. Marktteilnehmer gehen davon aus, dass trotz des Widerstands einiger Aktionäre, das $1 Bio. Zahlungspaket an Musk genehmigt wird. Was den Regierungs-Shutdown betrifft, sehen wir ab diesen Freitag bei 40 Flughäfen eine Reduktion der Flüge um 10%. Immer mehr Fluglotsen bleiben wegen der Gehaltsausfälle Zuhause. Ein Podcast - featured by Handelsblatt. +++ Alle Rabattcodes und Infos zu unseren Werbepartnern findet ihr hier: https://linktr.ee/wallstreet_podcast +++ +++ Hinweis zur Werbeplatzierung von Meta: https://backend.ad-alliance.de/fileadmin/Transparency_Notice/Meta_DMAJ_TTPA_Transparency_Notice_-_Ad_Alliance_approved.pdf +++ Der Podcast wird vermarktet durch die Ad Alliance. Die allgemeinen Datenschutzrichtlinien der Ad Alliance finden Sie unter https://datenschutz.ad-alliance.de/podcast.html Die Ad Alliance verarbeitet im Zusammenhang mit dem Angebot die Podcasts-Daten. Wenn Sie der automatischen Übermittlung der Daten widersprechen wollen, klicken Sie hier: https://datenschutz.ad-alliance.de/podcast.html Impressum: https://www.360wallstreet.de/impressum

Business of Tech
MSP Market Surges to $300B, AI Struggles to Scale, and New Tools Transform Business Operations

Business of Tech

Play Episode Listen Later Nov 4, 2025 14:34


The managed service provider (MSP) market has surpassed $305 billion and is projected to reach $571 billion by 2033, indicating a strong trend toward consolidation within the sector. In the second quarter of 2025 alone, there were 92 announced mergers and acquisitions, as companies aim to enhance their cybersecurity capabilities and automate operations. Key areas of focus for leading MSPs include operations, talent, security, automation, and compliance, which are essential for navigating the current landscape. Notable transactions include Comcast's acquisition of Nitell and Telus Digital's acquisition of Garrent.Research indicates that while artificial intelligence (AI) investments are expected to rise, particularly in telecommunications for predictive maintenance and network optimization, many AI projects struggle to scale effectively. A recent study from the Remote Labor Index found that top AI models completed less than 3% of assigned freelance tasks, highlighting a gap between expectations and actual performance. Additionally, a report from Fortinet revealed that 87% of cybersecurity professionals believe AI will enhance their roles, yet a significant skills gap persists, with over 4.7 million positions unfilled globally.Further developments include Intuit's launch of its AI-driven system, Intuit Intelligence, designed to streamline decision-making for small business owners, and Adobe's introduction of Firefly Foundry, which offers customized generative AI models for branding. Service Leadership has also released a new benchmarking tool aimed at smaller IT solution providers, enhancing their financial reporting capabilities. These initiatives reflect a growing trend of embedding AI into everyday business tools, which MSPs must navigate.For MSPs and IT service leaders, the implications are clear: the market is maturing rapidly, and providers must adapt by tightening operations, investing in automation, and prioritizing compliance. As AI becomes increasingly integrated into existing systems, MSPs should conduct audits to identify where AI is already active and establish governance frameworks to manage these technologies effectively. The focus should be on leveraging AI to enhance service delivery while ensuring that human oversight remains a critical component of technology management.Three things to know today00:00 From “Digital Transformation” to AI Operations: The MSP and IoT Boom Signals a More Mature IT Services Era05:28 AI's Promise Meets Its Limits: Reports Expose Gaps in Skills, Safety, and Real-World Capability09:22 From Finance to Branding, AI Is Already Inside Your Clients' SaaS Stack — Whether You Put It There or Not This is the Business of Tech.    Supported by:  https://try.auvik.com/dave-switchhttps://cometbackup.com/?utm_source=mspradio&utm_medium=podcast&utm_campaign=sponsorship

Today's Sports Headlines from JIJIPRESS
Men's Golf: Kota Kaneko Takes Sole Lead after 2nd Day of Fortinet Players Cup

Today's Sports Headlines from JIJIPRESS

Play Episode Listen Later Oct 31, 2025 0:06


Men's Golf: Kota Kaneko Takes Sole Lead after 2nd Day of Fortinet Players Cup

Get Connected
YouTube's new deepfake detection & WhatsApp's war on spammers

Get Connected

Play Episode Listen Later Oct 30, 2025 59:47


This week on the GetConnected Podcast with Mike Agerbo, tech journalist Carmi Levy joins us to dig into the biggest stories in tech — including OpenAI's new Atlas browser and whether it could be a Google Chrome killer. We'll also look at YouTube's new deepfake detection tools and WhatsApp's war on spammers. Then, Robert May from Fortinet shares important advice on cybersecurity for small businesses, and Omer Waysman from Michelin explains how the company is using AI to power smarter marketing and education

Cyber Briefing
October 27, 2025 - Cyber Briefing

Cyber Briefing

Play Episode Listen Later Oct 27, 2025 10:02


If you like what you hear, please subscribe, leave us a review and tell a friend!

The CyberWire
Derek Manky: Putting the rubber to the road. [Threat Intelligence] [Career Notes]

The CyberWire

Play Episode Listen Later Oct 26, 2025 9:38


Please enjoy this encore of Word Notes. Chief Security Strategist and VP of Global Threat Intelligence at FortiGuard Labs, Derek Manky, shares his story from programmer to cybersecurity and how it all came together. Derek started his career teaching programming because he had such a passion for it. When he joined Fortinet, Derek said putting where it "really started putting the rubber to the road and connecting my previous experience with programming and debugging and knowledge of operating systems and all that with real-world applications." Derek advises that it doesn't need to be complicated getting into the cybersecurity field and that there are many avenues to enter the field. He hopes to have made a real dent, or "hopefully a crater" in cyber crime when he ends his career. We thank Derek for sharing his story with us.  Learn more about your ad choices. Visit megaphone.fm/adchoices

Career Notes
Derek Manky: Putting the rubber to the road. [Threat Intelligence]

Career Notes

Play Episode Listen Later Oct 26, 2025 9:38


Please enjoy this encore of Career Notes. Chief Security Strategist and VP of Global Threat Intelligence at FortiGuard Labs, Derek Manky, shares his story from programmer to cybersecurity and how it all came together. Derek started his career teaching programming because he had such a passion for it. When he joined Fortinet, Derek said putting where it "really started putting the rubber to the road and connecting my previous experience with programming and debugging and knowledge of operating systems and all that with real-world applications." Derek advises that it doesn't need to be complicated getting into the cybersecurity field and that there are many avenues to enter the field. He hopes to have made a real dent, or "hopefully a crater" in cyber crime when he ends his career. We thank Derek for sharing his story with us.  Learn more about your ad choices. Visit megaphone.fm/adchoices

Packet Pushers - Heavy Networking
HN802: Unifying Networking and Security with Fortinet SASE: Architecture, Reality, and Lessons Learned (Sponsored)

Packet Pushers - Heavy Networking

Play Episode Listen Later Oct 24, 2025 58:39


The architecture and tech stack of a Secure Access Service Edge (SASE) solution will influence how the service performs, the robustness of its security controls, and the complexity of its operations. Sponsor Fortinet joins Heavy Networking to make the case that a unified offering, which integrates SD-WAN and SSE from a single vendor, provides a... Read more »

Packet Pushers - Full Podcast Feed
HN802: Unifying Networking and Security with Fortinet SASE: Architecture, Reality, and Lessons Learned (Sponsored)

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Oct 24, 2025 58:39


The architecture and tech stack of a Secure Access Service Edge (SASE) solution will influence how the service performs, the robustness of its security controls, and the complexity of its operations. Sponsor Fortinet joins Heavy Networking to make the case that a unified offering, which integrates SD-WAN and SSE from a single vendor, provides a... Read more »

Packet Pushers - Fat Pipe
HN802: Unifying Networking and Security with Fortinet SASE: Architecture, Reality, and Lessons Learned (Sponsored)

Packet Pushers - Fat Pipe

Play Episode Listen Later Oct 24, 2025 58:39


The architecture and tech stack of a Secure Access Service Edge (SASE) solution will influence how the service performs, the robustness of its security controls, and the complexity of its operations. Sponsor Fortinet joins Heavy Networking to make the case that a unified offering, which integrates SD-WAN and SSE from a single vendor, provides a... Read more »

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, October 15th, 2025: Microsoft Patchday; Ivanti Advisory; Fortinet Patches

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Oct 14, 2025 6:22


Microsoft Patch Tuesday Microsoft not only released new patches, but also the last patches for Windows 10, Office 2016, Office 2019, Exchange 2016 and Exchange 2019. https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368 Ivanti Advisory Ivanti released an advisory with some mitigation steps users can take until the recently made public vulnerablities are patched. https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US Fortinet Patches https://fortiguard.fortinet.com/psirt/FG-IR-25-010 https://fortiguard.fortinet.com/psirt/FG-IR-24-361

The CyberWire
When the breachers get breached.

The CyberWire

Play Episode Listen Later Oct 10, 2025 28:50


International law enforcement take down the Breachforums domains. Researchers link exploitation campaigns targeting Cisco, Palo Alto Networks, and Fortinet. Juniper Networks patches over 200 vulnerabilities. Apple and Google update their bug bounties. Evaluating AI use in application security (AppSec) programs. Microsegmentation can contain ransomware much faster and yield better cyber insurance terms. The new RondoDox botnet exploits over 50 vulnerabilities. Researchers tag 13 unpatched Ivanti Endpoint Manager flaws. Our guest is Jason Manar, CISO of Kaseya, sharing his insight into how the private and public sectors can work together for national security. Hackers mistake a decoy for glory.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by ⁠Jason Manar⁠, CISO of ⁠Kaseya⁠, sharing his insight into how the private and public sectors can/must work together for national security. Selected Reading FBI takes down BreachForums portal used for Salesforce extortion (Bleeping Computer) Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign (SecurityWeek) Juniper Networks Patches Critical Junos Space Vulnerabilities (OffSeq)   Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits (WIRED) Google Launches AI Bug Bounty with $30,000 Top Reward (Infosecurity Magazine) In AI We Trust? Increasing AI Adoption in AppSec Despite Limited Oversight (Fastly) Reducing Risk: Microsegmentation Means Faster Incident Response, Lower Insurance Premiums for Organizations (Akamai) RondoDox Botnet Takes ‘Exploit Shotgun' Approach (SecurityWeek) ZDI Drops 13 Unpatched Ivanti Endpoint Manager Vulnerabilities (SecurityWeek) Pro-Russian hackers caught bragging about attack on fake water utility (The Record) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Decipher Security Podcast
More Cl0p Clues and Huge Apple Bug Bounty Changes

Decipher Security Podcast

Play Episode Listen Later Oct 10, 2025 14:17


This week brings some new insights into the origins and length of the Cl0p extortion attacks tied to the Oracle E-Business Suite vulnerability, big surges in scanning for Cisco ASA, Palo Alto, and Fortinet devices, and a huge upgrade to Apple bug bounty payouts.  Plus: Does Dennis have a dog yet?https://security.apple.com/blog/apple-security-bounty-evolved/https://decipher.sc/2025/10/08/data-connects-scanning-surges-for-cisco-fortinet-pan-devices/https://decipher.sc/2025/10/09/oracle-clop-data-theft-campaign-started-months-ago/

Secure Networks: Endace Packet Forensics Files
Episode 63: Jack Chan, VP of Product and Field CTO at Fortinet

Secure Networks: Endace Packet Forensics Files

Play Episode Listen Later Oct 1, 2025 25:21


Why NDR is Evolving—And What Enterprises Should Demand From ItIn this episode of  the @Endace Packet Forensic Files, Michael Morris is joined by Jack Chan, VP of Product and Field CTO at Fortinet, to unpack what makes a truly effective Network Detection and Response (NDR) solution. Jack shares his perspective on why visibility, historical context, and deep threat hunting capabilities matter more than flashy features.They explore how AI and machine learning are transforming NDR—helping detect threats in encrypted traffic and reduce alert fatigue for SOC teams. Jack also talks about integrating NDR with firewalls and EDR tools to improve response decisions and streamline investigations.Finally, Jack leaves us with a powerful reminder: security starts with people. From secure coding to user awareness, the human element is often the weakest link—and the best place to strengthen your defences.ABOUT ENDACE *****************Endace (https://www.endace.com) is a world leader in high-performance packet capture solutions for cybersecurity, network and application performance. EndaceProbes are deployed on some of the world's largest, fastest and most critical networks. EndaceProbe models are available for on-premise, private cloud and public cloud deployments - delivering complete hybrid cloud visibility from a 'single-pane-of-glass'.Endace's open EndaceProbe Analytics appliances (https://www.endace.com/endaceprobe) can be deployed in on-prem locations and can also host third-party security and performance monitoring solutions while simultaneously recording a 100% accurate history of network activity.

Packet Pushers - Full Podcast Feed
PP080: The State of OT Risks in 2025 (and What to Do About Them)

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Sep 30, 2025 44:32


What does the risk environment for Operational Technology (OT) look like in 2025? JJ and Drew review four recent reports on the state of OT security from Dragos, Fortinet, and others. We discuss ransomware impacts, ongoing risks of RDP traffic, directly exposed OT devices, and overall attack trends and the tools and processes that organizations... Read more »

Packet Pushers - Fat Pipe
PP080: The State of OT Risks in 2025 (and What to Do About Them)

Packet Pushers - Fat Pipe

Play Episode Listen Later Sep 30, 2025 44:32


What does the risk environment for Operational Technology (OT) look like in 2025? JJ and Drew review four recent reports on the state of OT security from Dragos, Fortinet, and others. We discuss ransomware impacts, ongoing risks of RDP traffic, directly exposed OT devices, and overall attack trends and the tools and processes that organizations... Read more »

Chip Stock Investor Podcast
Netskope (NTSK) Stock Analysis: What Investors Need to Know

Chip Stock Investor Podcast

Play Episode Listen Later Sep 30, 2025 12:23


Netskope, a competitor in cloud security and SASE, has just hit the public market with its new IPO (NTSK). While the company operates in the booming cybersecurity industry and is growing revenue at over 30%, there are several critical risks potential investors must consider.In this analysis, we run Netskope through our investing framework to uncover the opportunities and the red flags. We'll explore its innovative SASE platform, the ongoing "Browser Wars" in the AI era, and the complicated legal battles and shareholder structure lurking beneath the surface. Is this a top cybersecurity stock to buy now, or a high-risk bet for your portfolio?In this video, we cover:[00:00:00] A Hot New Cybersecurity IPO: Introducing Netskope and its role in the emerging "Enterprise Browser Wars".[00:01:00] The Venture Capital Connection: Examining the role of top shareholder Lightspeed Ventures and its connection to another recent IPO, Rubrik[00:03:00] The SASE Market Opportunity: A breakdown of Netskope's focus on the Secure Access Service Edge (SASE) market and how its platform unifies cloud security.[00:05:00] Patent Battles & Legal Risks: Netskope's ongoing legal proceedings with competitor Fortinet over patent infringement claims.[00:06:00] Complex Shareholder Structure: Unpacking the risks of the dual-class share structure, where Class B shares get 20 votes each, concentrating control among insiders and VCs.[00:08:00] The Financial Red Flags: Netskope's GAAP net losses and negative free cash flow, despite impressive revenue growth.[00:10:00] Balance Sheet Concerns: A look at potential burdens on common shareholders from convertible debt and preferred stock.[00:11:00] Our Final Takeaway: Why we are still interested in Netskope as a potential small bet and a hedge against SASE leaders like Palo Alto Networks and Fortinet.What are your thoughts on the Netskope IPO? Let us know in the comments below!

Packet Pushers - Heavy Networking
HN798: Fortinet Offers a SOC Every Org Can Grow Into (Sponsored)

Packet Pushers - Heavy Networking

Play Episode Listen Later Sep 26, 2025 44:00


On today's Heavy Networking: the Security Operations Center, or SOC. When I think of a SOC, I picture a miniature version of NASA's mission control: lots of computers, lots of people, some big boards with lines and arrows and telemetry scrolling across the screens. I also think of SOCs as requiring a lot of gear,... Read more »

Packet Pushers - Full Podcast Feed
HN798: Fortinet Offers a SOC Every Org Can Grow Into (Sponsored)

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Sep 26, 2025 44:00


On today's Heavy Networking: the Security Operations Center, or SOC. When I think of a SOC, I picture a miniature version of NASA's mission control: lots of computers, lots of people, some big boards with lines and arrows and telemetry scrolling across the screens. I also think of SOCs as requiring a lot of gear,... Read more »

Packet Pushers - Fat Pipe
HN798: Fortinet Offers a SOC Every Org Can Grow Into (Sponsored)

Packet Pushers - Fat Pipe

Play Episode Listen Later Sep 26, 2025 44:00


On today's Heavy Networking: the Security Operations Center, or SOC. When I think of a SOC, I picture a miniature version of NASA's mission control: lots of computers, lots of people, some big boards with lines and arrows and telemetry scrolling across the screens. I also think of SOCs as requiring a lot of gear,... Read more »

K12 Tech Talk
Episode 233 - Teenagers Using AI Companions?

K12 Tech Talk

Play Episode Listen Later Sep 26, 2025 67:59 Transcription Available


Episode 233 discusses the newest tensions between AI and schools: teenagers using AI companions and alarming incidents tied to platforms like Character.ai that have drawn federal attention. Josh talks about his student MFA pilot using Clever, how onboarding works (and how MFA can be network-aware to reduce classroom friction), and using student-led help desks to test the rollout. The guys discuss a post from Jay on K12TechPro asking about IT leadership background (educators and non‑educators in K12 tech dept roles). The episode's guest is Peter Kaplan from Fortinet, an E‑Rate expert. He breaks down why E‑Rate matters, outlines the FCC's cybersecurity pilot (challenges with procurement, reporting, and evaluating success), and discusses gaps left by potential MS‑ISAC funding changes. He also highlights CISA's K12 resources and Fortinet's no‑cost cybersecurity awareness materials for schools. Our new Swag Store is OPEN - Buy some swag (tech dept gift boxes, shirts, hoodies...)!!! -------------------- NTP Managed Methods Arista VIZOR Fortinet -------------------- Join the K12TechPro Community (exclusively for K12 Tech professionals) Buy some swag (tech dept gift boxes, shirts, hoodies...)!!! Email us at k12techtalk@gmail.com OR our "professional" email addy is info@k12techtalkpodcast.com Call us at 314-329-0363 X @k12techtalkpod Facebook Visit our LinkedIn Music by Colt Ball Disclaimer: The views and work done by Josh, Chris, and Mark are solely their own and do not reflect the opinions or positions of sponsors or any respective employers or organizations associated with the guys. K12 Tech Talk itself does not endorse or validate the ideas, views, or statements expressed by Josh, Chris, and Mark's individual views and opinions are not representative of K12 Tech Talk. Furthermore, any references or mention of products, services, organizations, or individuals on K12 Tech Talk should not be considered as endorsements related to any employer or organization associated with the guys.

NZ Tech Podcast
AWS NZ region opens, Operational Tech Security, Microsoft AI model + more

NZ Tech Podcast

Play Episode Listen Later Sep 2, 2025 44:22


Join host Paul Spain and Joshua Alcock (Fortinet) as they explore the cybersecurity threats facing Operational Technology (OT) environments and the latest insights from Fortinet's 2025 Industrial Cybersecurity Report. They also delve into some of the latest tech news, including the launch of AWS data centers in New Zealand, Fieldays' NZ-Brazil AgriTech opportunities, Microsoft's Internal AI developments, Masterdon's Age verification challenges. Plus, Workdays research into AI Agent adoption in the workplace.Thanks to our Partners One NZ, Workday, 2degrees, HP, Spark and Gorilla Technology

Risky Business
Risky Business #803 -- Oracle's CSO Mary Ann Davidson quietly departs

Risky Business

Play Episode Listen Later Aug 20, 2025 58:28


On this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: Oracle's long term CSO departs, and we're not that sad about it Canada's House of Commons gets popped through a Microsoft bug Russia degrades voice calls via Whatsapp and Telegram to push people towards Max South-East Asian scam compounds are also behind child sextortion Reports that the UK has backed down on Apple crypto are… strange Oh and of course there's a Fortinet bug! There's always a Fortinet bug! This week's episode is sponsored by open source identity provider Authentik. CEO Fletcher Heisler joins the show this week, and explains the journey of implementing SSO backed login on Windows, Mac and Linux. You'll never guess which one was a few lines of PAM config, and which was a multi-month engineering project! This episode is also available on Youtube. Show notes Is Oracle facing headwinds? After layoffs, its 4-decade veteran Chief Security Officer Mary Ann Davidson departs Oracle CSO blasted over anti-security research rant - iTnews New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts | The Record from Recorded Future News Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump' Cashout Scheme – Krebs on Security How we found TeaOnHer spilling users' driver's licenses in less than 10 minutes | TechCrunch UK has backed down on demand to access US Apple user data, spy chief says DNI Tulsi Gabbard on X: "As a result, the UK has agreed to drop its mandate for" Hackers target Workday in social engineering attack Russia curbs WhatsApp, Telegram calls to counter cybercrime | The Record from Recorded Future News Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability | The Record from Recorded Future News Norway police believe pro-Russian hackers were behind April dam sabotage | The Record from Recorded Future News US agencies, international allies issue guidance on OT asset inventorying | Cybersecurity Dive FortMajeure: Authentication Bypass in FortiWeb (CVE-2025-52970) U.S. State Dept - Near Eastern Affairs on X: "He did not claim diplomatic immunity and was released by a state judge" 493 Cases of Sextortion Against Children Linked to Notorious Scam Compounds | WIRED .:: Phrack Magazine ::. Accenture to buy Australian cyber security firm CyberCX - iTnews

Black Hills Information Security
Cyberattack Bricks Speed Cameras – 2025-08-18

Black Hills Information Security

Play Episode Listen Later Aug 20, 2025 58:10


Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com00:00 - PreShow Banter™ — The gif that keeps on giffing01:46 - Cyberattack Bricks Speed Cameras – BHIS - Talkin' Bout [infosec] News 2025-08-1802:39 - Story # 1: Perplexity made a sky-high $34.5 billion bid for Google Chrome — a bold and unusual move in the midst of antitrust scrutiny07:16 - Story # 2: Exclusive: US embeds trackers in AI chip shipments to catch diversions to China, sources say10:22 - Story # 3: How we found TeaOnHer spilling users' driver's licenses in less than 10 minutes12:17 - Story # 4: Cisco discloses maximum-severity defect in firewall software13:56 - Story # 5: Data Dump From APT Actor Yields Clues to Attacker Capabilities19:13 - Story # 6: Russian cyberattack in the Netherlands leaves speed cameras offline indefinitely23:30 - Story # 7: HTTP/2 MadeYouReset Vulnerability Enables Massive DDoS Attacks24:51 - Story # 8: LAPD Eyes ‘GeoSpy', an AI Tool That Can Geolocate Photos in Seconds29:05 - Story # 9: Manpower discloses data breach affecting nearly 145,000 people34:51 - Story # 10: Hacker Offers to Sell 15.8 Million Plain-Text PayPal Credentials On Dark Web Forum35:34 - Story # 11: The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived40:54 - Story # 12: New Clever Phishing Attack Uses Japanese Character “ん” to Mimic Forward Slash “/”46:28 - Story # 13: Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild48:13 - Story # 14: Plex warns users to patch security vulnerability immediately50:53 - ChickenSec: Noble Foods using soil mapping technology at organic egg farm

Packet Pushers - Full Podcast Feed
NB539: Boom Times for Arista; SonicWall Offers $200K Firewall Warranty

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Aug 18, 2025 31:03


Take a Network Break! We start with critical vulnerabilities in Cisco Secure Firewall Management Center and Fortinet’s FortiSIEM. On the news front, SonicWall announces Gen8 firewalls plus a $200,000 warranty for customers that sign on to SonicWall’s Managed Protection Security Suite. IBM Cloud suffers its fourth major outage since May of this year, SASE vendor... Read more »

Packet Pushers - Network Break
NB539: Boom Times for Arista; SonicWall Offers $200K Firewall Warranty

Packet Pushers - Network Break

Play Episode Listen Later Aug 18, 2025 31:03


Take a Network Break! We start with critical vulnerabilities in Cisco Secure Firewall Management Center and Fortinet’s FortiSIEM. On the news front, SonicWall announces Gen8 firewalls plus a $200,000 warranty for customers that sign on to SonicWall’s Managed Protection Security Suite. IBM Cloud suffers its fourth major outage since May of this year, SASE vendor... Read more »

Packet Pushers - Fat Pipe
NB539: Boom Times for Arista; SonicWall Offers $200K Firewall Warranty

Packet Pushers - Fat Pipe

Play Episode Listen Later Aug 18, 2025 31:03


Take a Network Break! We start with critical vulnerabilities in Cisco Secure Firewall Management Center and Fortinet’s FortiSIEM. On the news front, SonicWall announces Gen8 firewalls plus a $200,000 warranty for customers that sign on to SonicWall’s Managed Protection Security Suite. IBM Cloud suffers its fourth major outage since May of this year, SASE vendor... Read more »

Cyber Security Today
Breaking Cybersecurity News: Canada's House of Commons Breached and Windows 10 Support Ending Soon

Cyber Security Today

Play Episode Listen Later Aug 18, 2025 9:51 Transcription Available


  In this episode of Cybersecurity Today, host David Shipley reports from Fredericton, New Brunswick, amidst severe forest fires. The main story covers a data breach in Canada's House of Commons involving parliamentary employee information, attributed to a recent Microsoft vulnerability. The episode also discusses Fortinet's recent high-severity vulnerability patches and Microsoft's reminder of Windows 10 support ending in October 2025. Additionally, there's rare good news as researchers gain insights into the iMac 3.0 malware after a source code leak. The episode encourages vigilance, patching, and awareness of upcoming support changes while offering contact information and solicitation for audience engagement. 00:00 Introduction and Headlines 00:35 Canada's House of Commons Data Breach 03:48 Fortinet Vulnerabilities and Patches 05:49 Windows 10 End of Life Announcement 07:17 Malware Source Code Leak Insights 09:08 Conclusion and Viewer Engagement

Paul's Security Weekly
Creepy chatbots, Fortinet, CISA, Agentic AI, FIDO, EDR, Aaran Leyland, and More... - SWN #503

Paul's Security Weekly

Play Episode Listen Later Aug 15, 2025 35:09


Creepy chatbots, Fortinet, CISA, Agentic AI, FIDO, EDR, Aaran Leyland, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-503

K12 Tech Talk
Episode 227 - State‑Mandated AI, Back‑to‑School Mayhem & the Birth of "Grumpy Josh"

K12 Tech Talk

Play Episode Listen Later Aug 15, 2025 46:23 Transcription Available


Josh, Chris and Mark dive into the chaos of the back‑to‑school rush and the latest K‑12 tech headlines. Topics include Ohio's new requirement that districts adopt AI policies, the pros and cons of writing evergreen AI regulations, and how that mandate could interact with existing tech agreements. The trio also covers recent news like ChatGPT‑5's launch and integrations, a Fortinet vulnerability alert, and San Francisco Unified's payroll/ERP struggles. Between updates they share candid stories from the frontline: ticket surges as staff return, construction and classroom rollouts, recovering deleted Google accounts, and practical coping strategies for IT teams (from daily planning tricks to quick wellness tips). Expect first‑hand anecdotes, real‑world advice for managing summer‑to‑school transitions and a light‑hearted finale — the improvised children's story “Grumpy Josh and the Magical Gummies.” Tune in for an episode that blends policy debate, troubleshooting war stories, and a little comic relief. Referenced Links: https://marketbrief.edweek.org/regulation-policy/ohio-is-requiring-ai-policies-for-all-k-12-schools-will-other-states-follow/2025/08 https://www.govtech.com/education/k-12/sfusd-payroll-software-prompts-teachers-union-labor-complaint Grumpy Josh Storybook: https://g.co/gemini/share/477028792b1c 00:00:00-Intro 00:12:44-AI Policies in Education 00:17:00-Summer Woes 00:42:55-Grumpy Josh -------------------- NTP Managed Methods CTL VIZOR Fortinet -------------------- Join the K12TechPro Community (exclusively for K12 Tech professionals) Buy some swag (shirts, hoodies...)!!! Email us at k12techtalk@gmail.com OR our "professional" email addy is info@k12techtalkpodcast.com Call us at 314-329-0363 X @k12techtalkpod Facebook Visit our LinkedIn Music by Colt Ball Disclaimer: The views and work done by Josh, Chris, and Mark are solely their own and do not reflect the opinions or positions of sponsors or any respective employers or organizations associated with the guys. K12 Tech Talk itself does not endorse or validate the ideas, views, or statements expressed by Josh, Chris, and Mark's individual views and opinions are not representative of K12 Tech Talk. Furthermore, any references or mention of products, services, organizations, or individuals on K12 Tech Talk should not be considered as endorsements related to any employer or organization associated with the guys.

Paul's Security Weekly TV
Creepy chatbots, Fortinet, CISA, Agentic AI, FIDO, EDR, Aaran Leyland, and More... - SWN #503

Paul's Security Weekly TV

Play Episode Listen Later Aug 15, 2025 35:09


Creepy chatbots, Fortinet, CISA, Agentic AI, FIDO, EDR, Aaran Leyland, and More on this episode of the Security Weekly News. Show Notes: https://securityweekly.com/swn-503

The CyberWire
Dialysis down, data out.

The CyberWire

Play Episode Listen Later Aug 14, 2025 26:46


A ransomware attack exposes personal medical records of VA patients. New joint guidance from CISA and the NSA emphasizes asset inventory and OT taxonomy. The UK government reportedly spent millions to cover up a data breach. Researchers identified two critical flaws in a widely used print orchestration platform.  Phishing attacks increasingly rely on personalization. Rooting and jailbreaking frameworks pose serious enterprise risks. Fortinet warns of a critical command injection flaw in FortiSIEM. Estonian nationals are sentenced in a crypto Ponzi scheme. Michele Campobasso from Forescout joins us to unpack new research separating the hype from reality around “vibe hacking.” Meet the Blockchain Bandits of Pyongyang. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Michele Campobasso from Forescout joins us to unpack new research separating the hype from reality around “vibe hacking.” Their team tested open-source, underground, and commercial AI models on vulnerability research and exploit development tasks—finding high failure rates and significant limitations, even among top commercial systems. Selected Reading Medical records for 1 million dialysis patients breached in data hack of VA vendor (Stars and Stripes) NSA Joins CISA and Others to Share OT Asset Inventory Guidance (NSA.gov) CISA warns of N-able N-central flaws exploited in zero-day attacks (Bleeping Computer) U.K. Secretly Spent $3.2 Million to Stop Journalists From Reporting on Data Breach (The New York Times) From Support Ticket to Zero Day  (Horizon3.ai) Personalization in Phishing: Advanced Tactics for Malware Delivery (Cofense) The Root(ing) Of All Evil: Security Holes That Could Compromise Your Mobile Device (Zimperium) Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild (Bleeping Computer) Estonians behind $577 million cryptomining fraud sentenced to 16 months (The Record) Someone counter-hacked a North Korean IT worker: Here's what they found (Cointelegraph) Audience Survey Complete our annual audience survey before August 31. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 14th, 2025: Equation Editor; Kerberos Patch; XZ-Utils Backdoor; ForitSIEM/FortiWeb patches

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 14, 2025 7:16


CVE-2017-11882 Will Never Die The (very) old equation editor vulnerability is still being exploited, as this recent sample analyzed by Xavier shows. The payload of the Excel file attempts to download and execute an infostealer to exfiltrate passwords via email. https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196 Windows Kerberos Elevation of Privilege Vulnerability Yesterday, Microsoft released a patch for a vulnerability that had already been made public. This vulnerability refers to the privilege escalation taking advantage of a path traversal issue in Windows Kerberos affecting Exchange Server in hybrid mode. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779 Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images Some old Debian Docker images containing the xz-utils backdoor are still available for download from Docker Hub via the official Debian account. https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images FortiSIEM / FortiWeb Vulnerablities Fortinet patched already exploited vulnerabilities in FortiWeb and FortiSIEM https://fortiguard.fortinet.com/psirt/FG-IR-25-152 https://fortiguard.fortinet.com/psirt/FG-IR-25-448

Cyber Security Headlines
Court filing system hack explained, PA AG weighs in on attack, Fortinet attacks raise concerns

Cyber Security Headlines

Play Episode Listen Later Aug 14, 2025 7:22


Hack of federal court filing system exploited security flaws known since 2020 Pennsylvania attorney general says cyberattack knocked phone, email systems offline Spike in Fortinet VPN brute-force attacks raises zero-day concerns Huge thanks to our sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that's…a new way to GRC. Get started at Vanta.com/headlines  

Cyber Security Today
Urgent Vulnerabilities: Patching Exchange, Citrix, and Fortinet

Cyber Security Today

Play Episode Listen Later Aug 13, 2025 14:33 Transcription Available


In this episode of Cybersecurity Today, host David Shipley covers critical security updates and vulnerabilities affecting Microsoft Exchange, Citrix NetScaler, and Fortinet SSL VPNs. With over 29,000 unpatched Exchange servers posing a risk for admin escalation and potential full domain compromise, urgent action is needed. Citrix Bleed 2 is actively being exploited, with significant incidents reported in the Netherlands and thousands of devices still unpatched globally. Fortinet SSL VPNs are experiencing a spike in brute force attacks, hinting at a possible new vulnerability on the horizon. Lastly, Shipley highlights notable moments from DEFCON 33, including innovative security hacks and sobering realities of the hacker community. Tune in for detailed breakdowns and insights on how to stay vigilant against these threats. 00:00 Introduction and Overview 00:32 Microsoft Exchange Vulnerability 02:54 Citrix Bleed Two Exploits 05:21 Fortinet SSL VPN Brute Force Attacks 07:39 Insights from DEFCON 33 13:46 Conclusion and Final Thoughts

Packet Pushers - Full Podcast Feed
NB536: Fortinet FortiOS Goes Post-Quantum; Intel Scales Back Global Projects

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jul 28, 2025 27:43


Take a Network Break! In our Red Alert section we note that memory safety bugs bug Firefox and Thunderbird, and on-prem SharePoint instances are under attack. In tech news, Fortinet adds support for Post Quantum Cryptography in FortiOS, Cato Networks integrates Azure Virtual WANs to its SASE offering, and we weigh the pros and cons... Read more »

Packet Pushers - Network Break
NB536: Fortinet FortiOS Goes Post-Quantum; Intel Scales Back Global Projects

Packet Pushers - Network Break

Play Episode Listen Later Jul 28, 2025 27:43


Take a Network Break! In our Red Alert section we note that memory safety bugs bug Firefox and Thunderbird, and on-prem SharePoint instances are under attack. In tech news, Fortinet adds support for Post Quantum Cryptography in FortiOS, Cato Networks integrates Azure Virtual WANs to its SASE offering, and we weigh the pros and cons... Read more »

Packet Pushers - Fat Pipe
NB536: Fortinet FortiOS Goes Post-Quantum; Intel Scales Back Global Projects

Packet Pushers - Fat Pipe

Play Episode Listen Later Jul 28, 2025 27:43


Take a Network Break! In our Red Alert section we note that memory safety bugs bug Firefox and Thunderbird, and on-prem SharePoint instances are under attack. In tech news, Fortinet adds support for Post Quantum Cryptography in FortiOS, Cato Networks integrates Azure Virtual WANs to its SASE offering, and we weigh the pros and cons... Read more »

Packet Pushers - Full Podcast Feed
PP071: SSE Vendor Test Results; Can HPE and Juniper Get Along?

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jul 22, 2025 46:20


CyberRatings, a non-profit that performs independent testing of security products and services, has released the results of comparative tests it conducted on Secure Service Edge, or SSE, services. Tested vendors include Cisco, Cloudflare, Fortinet, Palo Alto Networks, Skyhigh Security, Versa Networks, and Zscaler. We look at what was tested and how, highlight results, and discuss... Read more »

The CyberWire
Behind the firewall, trouble brews.

The CyberWire

Play Episode Listen Later Jul 11, 2025 31:49


Fortinet patches a critical flaw in its FortiWeb web application firewall.  Hackers are exploiting a critical vulnerability in Wing FTP Server. U.S. Cyber Command's fiscal 2026 budget includes a new AI project.  Czechia's cybersecurity agency has issued a formal warning about Chinese AI company DeepSeek. The DoNot APT group targets Italy's Ministry of Foreign Affairs. Mexico's former president is under investigation for alleged bribes to secure spyware contracts. The FBI seizes a major Nintendo Switch piracy site. CISA releases 13 ICS advisories.  A retired US Army lieutenant colonel pleads guilty to oversharing classified information on a dating app. Our guest is Catherine Woneis, VP of Product at Fingerprint, to discuss how bots are being used to facilitate music royalty fraud. A federal judge is not impressed with a crypto-thief's lack of restitution. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Catherine Woneis, VP of Product at Fingerprint, to discuss how bots are being used to facilitate music royalty fraud and how companies can protect themselves. Selected Reading Critical SQL injection vulnerability in Fortinet FortiWeb enables unauthenticated remote code execution (Beyond Machines) Critical Wing FTCritical Wing FTP Server Vulnerability Exploited - SecurityWeekP Server Vulnerability Exploited (SecurityWeek) Cyber Command creates new AI program in fiscal 2026 budget (DefenseScoop) DeepSeek a threat to national security, warns Czech cyber agency (The Record) Indian Cyber Espionage Group Targets Italian Government (Infosecurity Magazine) Former Mexican president investigated over allegedly taking bribes from spyware industry (The Record) Major Nintendo Switch Piracy Website Seized By FBI (Kotaku) CISA Releases Thirteen Industrial Control Systems Advisories (CISA) Lovestruck US Air Force worker admits leaking secrets on dating app (The Register) Crypto Scammer Truglia Gets 12 Years Prison, Up From 18 Months (Bloomberg) Audience Survey Complete our annual audience survey before August 31. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices