POPULARITY
AI is transforming cybersecurity, but securing AI systems is a unique challenge. In this full course session, InfosecTrain breaks down the core differences between securing with AI and securing AI itself. Discover AI/ML foundations, blue and red team defense tactics, MLOps, API security, and practical threat modeling techniques to future-proof your security career.The "course titled" Practical AI Security Engineering Program provides hands-on expertise to defend AI pipelines.
Hash values, IP addresses, and domains are virtually useless as primary detection mechanisms in the era of AI-driven polymorphic malware and short-lived phishing kits. If your detection strategy is still stuck at the bottom of the Pyramid of Pain, your incident response team is doused in noise while true threats slip through undetected. In this episode, Ashish sits down with Nicole Beckwith, Senior Director of Security Engineering & Operations at Cribl (former Secret Service investigator and Kroger security ops lead), to break down Cribl's open APEX framework. Nicole explains how APEX focuses on behavioral chaining, time-boxing, and clustering over raw telemetry to build high-fidelity detections without needing a thousand individual rules for every MITRE ATT&CK box. We also explore the shift from a "single pane of glass" to a deterministic "single lens" over federated data, why AI agents must be provisioned as true identities rather than unmonitored service accounts, and how to analyze hyper-fast threat archetypes like Anthropic's GTG 1002. Guest Socials - Nicole's Linkedin Podcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter If you are interested in AI Security, you can check out our sister podcast - AI Security PodcastQuestions asked:(00:00) Introduction & The Death of Hashes and IP Detections(02:20) Nicole Beckwith's Background (Secret Service, GE Aerospace, Kroger, Cribl)(04:30) Moving Up David Bianco's Pyramid of Pain to TTPs(06:20) Replacing the "Single Pane of Glass" with a Single Lens on Federated Data(09:40) Deciding What Logs to Pipe to a Data Lake vs. Keep in a SIEM(13:30) The Cost and Context Risks of Pointing AI Agents Directly at Unstructured Data Lakes(16:30) IAM Mistakes: Why AI Agents Must Be Provisioned as Identities, Not Service Accounts(18:40) The Biggest Blind Spot in AI Detection Engineering (Rule Writing vs. Tuning)(20:40) Why AI SOCs Break on Normalized Schemas and Need Raw Telemetry(22:20) Deconstructing the APEX Framework: Chaining, Time-Boxing, and Clustering(27:00) Detecting Anthropic's GTG 1002 Archetype and MCP Scaffolding Abuse(30:30) How to Apply the APEX Framework to Any Existing Security Stack(34:20) Empowering Analysts: Why AI Should Not Be Used to Cut SOC HeadcountResources spoken about during the interview APEX Framework
Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode, Ron sits down with Myke Lyons, CISO at Cribl, who cut his teeth in telemetry and logging decades ago and has landed right back there in the age of AI. Ron and Myke dig into why most telemetry failures aren't data problems at all, they're decisions nobody made about why the logs are being collected in the first place. Myke breaks down what to track on every agent in your environment, why token spend belongs on the security team's plate, why dashboards are quietly dying, and why treating an AI agent like just another employee is a mistake that's going to bite security teams hard. Underneath it all is one question Myke keeps circling back to: do you actually know what normal looks like for every agent in your environment? Impactful Moments 00:00 - Introduction 01:50 - Myth Busting: AI Agents Aren't Just Another User Account 04:25 - Meet Myke Lyons, CISO at Cribl 05:05 - What it means to run security at a telemetry company 06:10 - From gigabytes of logs at GE to petabytes today 07:45 - MITRE ATT&CK, Cribl's new APEX framework, and orienting telemetry 10:20 - Why most telemetry problems are decision problems, not data problems 13:20 - OCSF and how security teams are rethinking their schemas 14:25 - Why the dashboard is dying 17:35 - What Myke wants to track about every AI agent 20:10 - How to spot an agent going rogue 23:15 - Making your data AI-ready and the case for schematizing everything 27:10 - Tokenomics: treating AI spend as a security responsibility 29:05 - The non-negotiable logs every org should be collecting 31:50 - Hot takes: build vs. buy, tier two to three, and Myke's daily AI briefing 33:35 - Closing thoughts and outro Links Connect with Myke Lyons on LinkedIn: https://www.linkedin.com/in/mykelyons/ Learn more about Cribl: https://cribl.io/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/
Send us Fan MailA rogue AI agent didn't “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying around. We walk through the Hugging Face intrusion story like a CISO briefing a board, step by step, translating a fast-moving AI-red-team narrative into the kind of clear threat modeling logic you need for ISC2 CISSP Domain 1.10 and for real risk decisions. From there, we shift into training mode and get concrete about threat modeling concepts and methodologies. We define threat modeling the way the exam cares about it: proactive, iterative, and designed to produce security requirements and prioritised countermeasures that feed your SDLC and risk register. We break down the three starting perspectives (asset-centric, attack-centric, and system-centric), then anchor STRIDE to data flow diagrams and trust boundaries so you can identify what security property is actually being violated, not just recite acronyms. We also cover the difference between identifying and ranking threats so you don't fall into the classic traps: DREAD ranks threats you already found, while PASTA starts with business objectives and risk appetite and is built for risk-centric outputs leaders can fund. We talk attack trees, why MITRE ATT&CK is an input rather than a methodology, and why your threat actor catalog must include authorized non-human identities and vendor integrations that can operate outside intended scope. If this helps, subscribe, share it with a study buddy, and leave a quick review so more CISSP candidates can find it.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
One piece of malware. No phishing. No user clicking anything. And on May 12, 2017, WannaCry took the UK's National Health Service offline in a single afternoon — 19,000 appointments cancelled, MRI scanners locked out, ambulances diverted.In this Breach File we walk through exactly what happened: the 59-day gap between the Microsoft patch and detonation, how the Shadow Brokers' leak of EternalBlue armed Lazarus Group to build a self-propagating cryptoworm, and how the kernel memory corruption in SMBv1 actually worked — no jargon, no glossing.Then we run it through the Threat and Control Method: Inventory, Threats, Controls, Scale — the same four-step loop we teach at Blue Team Academy for turning IT experience into blue team judgment.If you already work in IT — sysadmin, network engineer, help desk, cloud, ops — WannaCry is the clearest existing worked example of how the environments you already run get turned into weapons, and how ordinary IT hygiene applied with a defender's intent would have stopped almost all of it.━━━━━━━━━━━━━━━━━━━━━━━━━━CHAPTERS━━━━━━━━━━━━━━━━━━━━━━━━━━00:00 The Attack That Needed No Clicks00:24 Why WannaCry Still Matters01:18 Timeline of an Epidemic03:33 Lazarus Group and the Nation-State Threat05:21 How EternalBlue Actually Worked09:10 The $4 Billion Human Cost10:24 The Defense — Inventory, Threats, Controls, Scale15:11 Why This Isn't History16:03 Cybersecurity Is Not Rocket Science━━━━━━━━━━━━━━━━━━━━━━━━━━READ THE FULL BREACH FILE━━━━━━━━━━━━━━━━━━━━━━━━━━Full written breakdown with sources and code samples:https://blueteam-academy.com/breaches/wannacry-ransomware-attack-eternalblue-cryptoworm/━━━━━━━━━━━━━━━━━━━━━━━━━━BLUE TEAM ACADEMY━━━━━━━━━━━━━━━━━━━━━━━━━━We help experienced IT professionals move into defensive cybersecurity — without starting over. We teach the Threat and Control Method: a repeatable four-step decision process (Inventory → Threats → Controls → Scale) applied to real incidents like this one.Learn more: https://www2.blueteam-academy.com/from-it-to-cybersecurity/Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signupBlog: https://blueteam-academy.com/blogInstagram: @blueteamacad━━━━━━━━━━━━━━━━━━━━━━━━━━SOURCES━━━━━━━━━━━━━━━━━━━━━━━━━━- Microsoft Security Bulletin MS17-010 (March 14, 2017)- CISA/US-CERT Alert TA17-132A — WannaCry indicators- U.S. Department of Justice indictment of Park Jin Hyok (September 6, 2018)- UK National Audit Office — "Investigation: WannaCry cyber attack and the NHS" (October 2017)- Europol statement, May 2017 — 200,000 systems / 150 countries- MITRE ATT&CK — EternalBlue / T1210━━━━━━━━━━━━━━━━━━━━━━━━━━#Cybersecurity #BlueTeam #WannaCry #Ransomware #EternalBlue
Crogl calls it a Knowledge Engine for Security Operations, and the idea is simple: analysts are drowning in alerts, and cutting corners isn't the fix. Every alert deserves a real look. So Crogl built an AI that works alongside the analyst, not instead of them, an assistant one investor called an "Iron Man suit" for security researchers. The goal isn't to replace the team. It's to make every single analyst as effective as the whole team combined. Monzy Merza, Co-founder and CEO of Crogl, joins us today on BarCode to talk community, what's coming at Black Hat, and why the best defense in cybersecurity might just be showing up and sharing what you know.SYMLINKS[Crogl] - https://crogl.com An AI-powered security operations platform that helps security teams investigate alerts, perform threat hunting, and automate cybersecurity workflows while keeping customer data within their own environment.[Monzy Mirza – LinkedIn] - https://www.linkedin.com/in/monzymerza/ The official LinkedIn profile of Monzy Mirza, Co-founder and CEO of Crogl, where he shares insights on AI, cybersecurity, and security operations.[MITRE ATT&CK® Framework] - https://attack.mitre.org/ A globally recognized cybersecurity knowledge base maintained by MITRE that documents adversary tactics, techniques, and procedures (TTPs). Crogl references the framework for investigating security alerts and threat hunting.[CISA] - https://www.cisa.gov/ The U.S. Cybersecurity and Infrastructure Security Agency. The episode discusses using CISA advisories, such as those related to Volt Typhoon, as inputs for threat hunting.[Volt Typhoon Advisory] - https://www.cisa.gov/news-events/cybersecurity-advisories CISA's collection of official cybersecurity advisories, including guidance on the Volt Typhoon threat actor. The episode references uploading these advisories into Crogl for automated threat hunting.[Slack] - https://slack.com/ A workplace collaboration platform. Crogl provides customers with access to a Slack community where users can interact directly with the engineering team and provide product feedback.[Black Hat USA] - https://www.blackhat.com/us-25/ One of the world's leading cybersecurity conferences. Monzy mentions that the Crogl team will host a booth, hackathon, and community sessions during Black Hat.
Je leverancier roept trots dat hij soeverein is. Maar als de wet Amerikaans is en de stekker in Washington zit, wie is er dan echt de baas? Digitale soevereiniteit is in een half jaar van vakjargon naar chefsache gegaan, en Randal is het woord inmiddels een beetje zat. Brenno de Winter (auteur van “Soevereiniteit! Hoe dan?”) en Ellen Mok (Digitale Doetank) leggen uit waarom het toch een groot ding is: door onze digitale afhankelijkheid hebben we een stuk macht uit handen gegeven aan bedrijven waar we geen regie over hebben. Het gesprek gaat van de Westfaalse vrede naar het uitzetten van AI-modellen voor niet-Amerikanen, en van het mondkapjes-moment naar Chinese staatshackers die dertien jaar in de systemen van Volkswagen zaten. De oplossing is volgens Ellen grappig genoeg niet zo complex: we geven het geld al uit, we moeten het alleen anders uitgeven. Onderweg dreigt Ellen haar Mistral-abonnement op te zeggen (waarna het model zich netjes gedraagt) en bouwt Brenno al zijn slides om naar platte markdown, inclusief herbruikbare katplaatjes. Over Ellen Mok Ellen Mok is oprichter van de Digitale Doetank, een steward-owned advieskantoor dat overheden en bedrijven helpt bij digitale autonomie. Ze werkte eerder als Manager Cyber Strategy & Risk bij KPMG en als cybersecurity-onderzoeker bij de AIVD (onder meer in het Cyber China-team), en was in 2024 kandidaat voor D66 voor het Europees Parlement. Ze is daarnaast extern adviseur van het Digitale Autonomie Competentiecentrum (DACC). LinkedIn: https://www.linkedin.com/in/ellen-mok-a238727b/ Website: https://www.digitaledoetank.nl/ Over Brenno de Winter Brenno de Winter is informatiebeveiligingsexpert, voormalig onderzoeksjournalist (Journalist van het Jaar 2011) en auteur van “Soevereiniteit! Hoe dan?”. Hij is voorzitter van Stichting LibreKAT (rond OpenKAT) en actief vanuit zijn bedrijf Vigilis B.V. In de aflevering presenteert hij zijn nieuwe open source presentatietool op basis van markdown. LinkedIn: https://www.linkedin.com/in/brenno Website: https://dewinter.com/ Sponsor: Rabobank Misschien niet de eerste plek waar je kijkt als IT’er, maar wel één waar je je sneller thuis voelt dan je denkt. Ontdek waarom op rabobank.jobs/ITIn deze aflevering 0:00:00 Intro: soevereiniteit sexy maken en een Europese virusscanner0:02:15 Ellens Digitale Doetank: een advieskantoor zonder afhankelijkheid als verdienmodel0:04:11 Gemeente Amsterdam als launching customer en de beslisboom voor de cloud0:09:07 Soevereiniteit versus digitale autonomie, en waarom “wij kunnen geen hyperscalers” onzin is0:14:13 De kostencurve: Europees doet vooraf pijn, Amerikaans achteraf0:17:07 Van de Westfaalse vrede naar big tech als de nieuwe baas0:20:33 Het mondkapjes-moment en AI-modellen die voor niet-Amerikanen dichtgaan0:23:02 Waarom de IT geen leermechanisme heeft zoals de luchtvaart0:28:03 Slides als platte markdown: Brenno’s ontsnapping uit PowerPoint (met katten)0:31:42 Sponsor: Rabobank0:36:20 Vibecoden met Amerikaanse modellen: mag dat als je hier zo tegen bent?0:46:06 Van ISO 27001 tot een echt soevereiniteitsstempel0:57:49 Het Cloud Sovereignty Framework, de SEAL-niveaus en de wildgroei aan modellen1:05:22 Nationale veiligheid Amerikaanse stijl: toegang tot de meest gevoelige data1:13:57 256 miljard per jaar naar big tech, ongeveer een heel land aan economie1:20:22 Chinese staatshackers, dertien jaar bij Volkswagen en gedumpte e-auto’s1:29:07 Luistervraag Boba: wordt soevereiniteit ooit sexy?1:36:17 Luistervraag Robert-Jan: wat moeten nerds nog bouwen? Genoemd in deze aflevering Soevereiniteit! Hoe dan?, het boek van Brenno de Winter Digitale Doetank, Ellens advieskantoor voor digitale autonomie Cloud Sovereignty Framework, het Europese model met SEAL-niveaus 0 tot 4 Volwassenheidsmodel Digitale Autonomie (DACC), zelftest voor je organisatie MITRE ATT&CK Framework, het community-model dat als inspiratie diende Nextcloud All-in-One, open source werkplek om zelf te hosten The Good Cloud, Nederlandse gehoste Nextcloud-dienst Stichting LibreKAT, Brenno’s stichting rond OpenKAT Tips van de tafel Brenno: Maak van je presentaties platte markdown in plaats van PowerPoint; doorzoekbaar, herbruikbaar en het scheelt gigabytes aan opslag.Brenno: Vibecode gerust met AI, maar lees je eigen code en sla geen stappen over, anders bouw je cognitieve schuld op.Ellen: Koop bij een aanbesteding op je eigen normen en waarden, niet op de laagste prijs; anders komt er nooit een volwassen Europees alternatief.Ellen: Ga deze week bewust iets vets kopen of gebruiken dat Europees is.See omnystudio.com/listener for privacy information.
This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of high-value accounts, emerging phishing campaigns abusing OpenAI invitations and Microsoft 365 device code authentication, and recent Oracle security updates. They also cover convictions tied to the Transport for London and U.S. healthcare intrusions, Google's Android earthquake warning system, concerns over MITRE ATT&CK evaluation methodology, and the ongoing debate surrounding threat intelligence researchers interacting with cybercriminals.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis
Join us for this week's Defender Fridays as Carlo Anez, Founder and Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down how to build practical blue team skills using open-source labs, MITRE ATTACK, and real-world defender workflows, and where AI fits into the picture without replacing the analyst.At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.What We'll DiscussIn this episode, Carlo Anez draws on years of SOC operations, detection engineering, and cybersecurity instruction to make the case for hands-on, open-source training as the foundation for developing confident, capable defenders.Key Topics:Why cybersecurity training must move beyond passive learning and into real defender workflowsHow the OpenSOC initiative uses open-source tools like Wazuh, MISP, The Hive, and TimeSketch to simulate a small-scale fusion center environmentHow open-source stacks build transferable skills that translate to enterprise platforms like Splunk and LimaCharlieWhere AI fits in the SOC: summarizing noisy alerts, mapping activity to MITRE ATT&CK, drafting investigation questions, and improving report clarityWhy AI literacy means knowing how to validate AI output against evidence, not just knowing how to write promptsWhy the analyst owns the evidence, the decision, and the communicationHow the DEF CON boot camp and online pilot program structure five days of scenario-based training around a final analyst report and CTF capstoneAbout Our GuestCarlo Anez is the Founder and Lead Instructor at IgniteCyber Academy and a DEFCON Training Instructor. He spent five years at Rapid7 doing detection engineering, threat hunting, and DFIR workflows, and has supported SOC operations, government contractors, and projects with DARPA, the US Army, and the US Navy. He currently creates SOC-focused content with TCM Security and leads Blue Team Village at DEF CON, where he also presents and trains annually.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.Why LimaCharlie?Eliminate vendor sprawl and tool complexityDeploy and scale effortlessly on native multi-tenant architectureReduce costs with intelligent data routing and free 1-year retentionBuild custom solutions with 100+ security capabilities on-demandAccelerate response with agentic AI that acts directly within predefined workflowsTry the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieioX: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - Founder at LimaCharlieGuest: Carlo Anez - Founder & Lead Instructor at IgniteCyber Academy
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
Discover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet another SD-WAN 0-day in the wild. Why is it so difficult to author secure PHP code. Teens use "WeedHack" to spy and attack each other. Researchers create the first AI-enabled Internet worm. Google Chrome pops-up "Shop with confidence." What... The discovered and irresponsibly disclosed HTTP/2 Bomb. What Anthropic learns from their past year of Claude abuse: It's bad Show Notes - https://www.grc.com/sn/SN-1082-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com for Security Now outsystems.com/twit guardsquare.com doppel.com cyberhoot.com/securitynow
This episode covers the rising costs and restrictions surrounding AI agents, including token consumption, model access policies, and the growing dependence on AI tools for security work. The hosts discuss Troy Hunt's retrospective on Have I Been Pwned reaching its 1,000th tracked breach, examining why breach disclosures appear to be slowing and how GDPR and CCPA requirements affect notification practices. Additional topics include password and email hygiene, the value of breach-notification services, AI infrastructure and data center costs, and new research mapping AI-enabled cyber threats to the MITRE ATT&CK framework.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis
Recorded live at PSConfEU 2026, Andrew sits down with returning guest Miriam Wiesner, Senior Security Researcher at Microsoft, for a wide-ranging conversation on PowerShell security, cookie-based attacks, and the evolving threat landscape. Miriam walks through her two conference talks — one on Microsoft Teams session cookie hijacking (a follow-up to her 2025 Entra ID cookie talk, complete with Cookie Monster branding and actual handcuffs), and a joint session with Stéphane van Gulick on using Microsoft Defender's Live Response feature for incident investigation. The conversation also covers the current state of PowerShell security, why sophisticated attackers are moving away from PowerShell, and why defenders who haven't enabled script block logging and AMSI are leaving easy wins on the table. On top of the technical deep dive, Miriam and Andrew get into the human side of the conference community — nerves before presenting, imposter syndrome, and why showing up is already half the battle. Key Takeaways: Cookie-based identity attacks are an active and growing threat. Microsoft Teams, SharePoint, and OneDrive share session cookies, meaning a single cookie theft can give an attacker broad access across your organization's collaboration tools — no re-authentication required. Sophisticated threat actors are moving away from PowerShell specifically because its security features work. Script block logging, AMSI, and Constrained Language Mode make PowerShell activity highly visible and detectable. If your org hasn't enabled these, you're handing attackers an easy path. Visibility beats prevention. You can't prevent what you can't see. Detection through proper logging is not a consolation prize — it's a core security strategy, and Microsoft Defender's Live Response feature gives teams a powerful way to investigate isolated endpoints without needing RDP or PowerShell remoting enabled. Guest Bio: Miriam Wiesner is a Senior Security Research Program Manager at Microsoft with over 15 years of experience in IT security, penetration testing, and security automation. She works on research behind Microsoft Defender and Sentinel and is the creator of widely used open source PowerShell security tools EventList and JEAnalyzer. Miriam is a sought-after speaker at major security and PowerShell conferences including Black Hat, PSConfEU, and MITRE ATT&CK Workshops. She's also the author of "PowerShell Automation and Scripting for Cybersecurity," published by Packt. Her conference speaker career started at PSConfEU 2018 and she's been a fixture of the community ever since. Resource Links Miriam's 2025 Cookies talk - https://www.youtube.com/watch?v=8xDcq0pPNPs Book – PowerShell Automation and Scripting for Cybersecurity (Packt): https://www.amazon.com/PowerShell-Automation-Scripting-Cybersecurity-Hacking/dp/1800566379 Miriam on LinkedIn: https://www.linkedin.com/in/miriamwiesner Miriam on X/Twitter: https://x.com/MiriamXyra Miriam's GitHub (EventList, JEAnalyzer, and more): https://github.com/miriamxyra Miriam's Website: https://miriamxyra.com Connect with Andrew: https://andrewpla.tech/links The PowerShell Podcast on YouTube: https://youtu.be/zxJOqcEwgWE
Join us for this week's Defender Fridays as Bobby Ford, Chief Strategy and Experience Officer at Doppel, talks about open-source labs, MITRE ATT&CK, and real-world defender workflows.At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.About Our GuestBobby is a globally recognized cybersecurity “geek” with almost three decades of experience, including the last 14 years as a CISO, protecting some of the world's most complex and operationally intensive enterprises. His career began in the military as a founding member of the Pentagon Computer Incident Response Team. Bobby built and led cybersecurity programs in the Aerospace and Defense industry. He was the first CISO at Exelis Inc. and was the architect of ITT's global cybersecurity audit function under DOJ oversight.Transitioning from public to private sector, Bobby served as the first CISO at Abbott Labs, was CISO for Unilever, and most recently was SVP and Chief Security Officer at Hewlett Packard Enterprise (HPE). Known for his collaborative style and empathetic leadership, Bobby fosters an inclusive culture that empowers entire security organizations to excel.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.Why LimaCharlie?Eliminate vendor sprawl and tool complexityDeploy and scale effortlessly on native multi-tenant architectureReduce costs with intelligent data routing and free 1-year retentionBuild custom solutions with 100+ security capabilities on-demandAccelerate response with agentic AI that acts directly within predefined workflowsTry the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieioX: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - Founder at LimaCharlieGuest: Charles Grandjean - CTO and Co-founder at Hexiagon AI
The Five Eyes issue a rare joint warning on China. Jen Easterly weighs in on Trump's AI EO. Researchers warn everyday notifications can become AI attack vectors. IronWorm is a sophisticated Rust-based infostealer targeting software developers. Cisco patches a critical vulnerability in its Unified Communications Manager platform. Anthropic maps AI-enabled cyber activity to the MITRE ATT&CK framework. Authorities dismantle an online counterfeit identity marketplace. Our guest is Jason Kikta, CTO from Automox, discussing AI vulnerabilities, real risk, and the speed problem. An extortion crew is forced to open a customer support ticket. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today on our Industry Voices segment, we are joined by Jason Kikta, CTO from Automox, who is discussing AI vulnerabilities, real risk, and the speed problem. If you enjoyed this conversation, check out the full interview here. Selected Reading U.S. and intelligence allies issue rare joint warning about China (Washington Post) Safeguarding Our Secrets (MI5) Opinion | The Government Is Finally Taking A.I. Risk Seriously (New York Times) CISA directive for AI executive order to be released this week, Andersen says (The Record) Gemini Voice Assistant Hijacked via Messaging Notifications (SecurityWeek) IronWorm: Shai-Hulud's rustier cousin (JFrog Security Research) Cisco warns of critical Unified CM flaw with PoC exploit code (Bleeping Computer) Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator (Anthropic) Police dismantles fake ID marketplace used by migrant smugglers (Bleeping Computer) Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown (SecurityWeek) 'Dumbass' criminal breaks the 'first rule of ransomware club' (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
拡張子って何? 機械オンチにその役割やおもしろさを話しつつ、「拡張子表示設定をすべき」と説きました。【目次】0:00 コンピュータ好きはアレを表示している2:28 拡張子って何?9:37 拡張子で解釈の仕方が違う23:36 ZipかZip以外か28:09 Wordが本当にZipか見てみよう32:46 CSVってなんでみんな使うの?34:47 なんとなく見るだけで発見があ【参考文献】◯PKWARE「APPNOTE.TXT - .ZIP File Format Specification(Version 6.3.10, 2022-11-01)」https://pkware.cachefly.net/webdocs/casestudies/APPNOTE.TXT◯Chromium Issue Tracker「Issue 172529: Saving a Twitter image results in "jpg-large" file extension」https://bugs.chromium.org/p/chromium/issues/detail?id=172529◯Google Developers Blog「WebP, a new image format for the Web」(2010-09-30)https://developers.googleblog.com/en/webp-a-new-image-format-for-the-web/◯MITRE ATT&CK「Masquerading: Double File Extension, Sub-technique T1036.007 - Enterprise」https://attack.mitre.org/techniques/T1036/007/【サポーターコミュニティへの加入はこちらから!】https://yurugengo.com/support【親チャンネル:ゆる言語学ラジオ】https://www.youtube.com/@yurugengo【実店舗プロジェクト:ゆる学徒カフェ】https://www.youtube.com/@yurugakuto【お仕事依頼はこちら!】info@pedantic.jp【堀元見プロフィール】慶應義塾大学理工学部卒。専攻は情報工学。理屈っぽいコンテンツを作り散らかすことで生計を立てている。Twitter→https://twitter.com/kenhori2noteマガジン→https://note.com/kenhori2/m/m125fc4524aca個人YouTube→https://www.youtube.com/@kenHorimoto【水野太貴プロフィール】1995年生まれ。愛知県出身。名古屋大学文学部卒。専攻は言語学。本業は雑誌編集者。著書に『会話の0.2秒を言語学する 』(新潮社)などがある。Podcast「神保町で会いましょう」のパーソナリティも務める。Twitter→https://x.com/yuru_mizuno神保町で会いましょう→https://open.spotify.com/show/6cYkvDO0HnJKLPgDBGUjjS
Ebben az epizódban a MITRE ATT&CK keretrendszerről beszélgetünk Rékával: arról, hogyan lehet valós támadói viselkedéseket taktikákra, technikákra és procedúrákra bontva elemezni. Szóba kerül a TTP-k szerepe, a detekció és az ATT&CK mitigációs lehetőségei, a MITRE D3FEND, valamint az is, hogyan segíti a framework a riportolást, a CTI-munkát és a red team / blue team együttműködést. Az adásban Réka a saját szakdolgozati témájáról is mesél, amelyben CTI-jelentésekből próbál TTP-ket automatikusan kinyerni NLP és mesterséges intelligencia segítségével.
#SecurityConfidential #DarkRhiinoSecurityDiyar Saadi Ali is a cybersecurity professional specializing in cybercrime investigations, SOC operations, and malware analysis. A contributor to the MITRE ATT&CK framework, Diyar has helped strengthen global threat intelligence efforts and defensive strategies. Diyar regularly speaks at international cybersecurity conferences including Arab Cyber Security, DeepSec, GISEC, BlackHat, and SulyCon, contributing to the advancement of the global cyber community.00:00 Intro02:26 Our Guest03:42 Learning Cybersecurity in Iraq07:40 The MITRE attack Framework: Is that all the knowledge we know? 11:30 There are still tons of unknown vulnerabilities13:30 You can't fake motivation17:00 Defenders are to blame19:16 Who is coming up with Malware?22:10 Every crime leaves a trace24:12 AI is making malware easy29:00 Governance and Trust38:02 Presentations and News from Diyar----------------------------------------------------------------------To learn more about Diyar visit https://www.linkedin.com/in/diyarsaadi/To learn more about Dark Rhiino Security visit https://www.darkrhiinosecurity.com
Diyar Saadi Ali is a cybersecurity professional specializing in cybercrime investigations, SOC operations, and malware analysis. A contributor to the MITRE ATT&CK framework, Diyar has helped strengthen global threat intelligence efforts and defensive strategies. Diyar regularly speaks at international cybersecurity conferences, including Arab Cyber Security, DeepSec, GISEC, BlackHat, and SulyCon, contributing to the advancement of the global cyber community.00:00 Intro02:26 Our Guest03:42 Learning Cybersecurity in Iraq07:40 The MITRE attack Framework: Is that all the knowledge we know? 11:30 There are still tons of unknown vulnerabilities13:30 You can't fake motivation17:00 Defenders are to blame19:16 Who is coming up with Malware?22:10 Every crime leaves a trace24:12 AI is making malware easy29:00 Governance and Trust38:02 Presentations and News from Diyar
Podcast: Exploited: The Cyber Truth Episode: AI vs. Vulnerabilities: Who Really Wins?Pub date: 2026-03-26Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationArtificial intelligence is transforming cybersecurity but not in the way many expect. While defenders are using AI to accelerate detection, triage, and threat hunting, adversaries are leveraging the same tools to scale reconnaissance, automate exploit development, and dramatically increase the speed of attack. In this episode of Exploited: The Cyber Truth, host Paul Ducklin is joined by RunSafe Security CEO Joe Saunders and Joe Slowik, Director of Cybersecurity Alerting Strategy at Dataminr, to discuss one critical question: Does AI actually reduce vulnerability risk or just accelerate the conflict? With a background including MITRE ATT&CK, Dragos, Los Alamos National Laboratory, and U.S. government offensive operations, Slowik offers a dual-lens perspective on how AI is reshaping both sides of cybersecurity. Together, they explore: How AI is increasing the velocity of vulnerability discovery and exploitationWhy attackers may benefit from “good enough” AI outputs, while defenders require precisionThe rise in CVEs and why more vulnerabilities doesn't necessarily mean worse securityThe growing risk in OT, IoT, and unmanaged edge devicesWhy AI is a powerful tool—not a magic bullet—and what that means for defenders From enterprise security teams to critical infrastructure operators, this episode breaks down what security leaders must understand to stay ahead in an AI-accelerated threat landscape.The podcast and artwork embedded on this page are from RunSafe Security, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Can You Identify the Malware Family?Out of the Woods: The Threat Hunting Podcast returns with another live, interactive edition designed to test how you analyze malicious activity. This session will focus on a specific malware family, revealing its behavior in stages as our hosts walk through execution patterns, infrastructure clues, and operational tradecraft.Participants will examine how observed behaviors align to MITRE ATT&CK, how the malware evolves across campaigns, and how delivery methods and post-exploitation activity signal attribution. Before the final reveal, attendees will have the opportunity to submit their best guess on which malware family is responsible.What You'll Learn: Real-world malware behavior – A phase-by-phase breakdown of an active malware campaign MITRE ATT&CK in context – How techniques manifest during execution Behavioral fingerprinting – Identifying patterns across variants and infrastructure Delivery and objectives – What infection chains reveal about operator intent Interactive analysis – Submit your guess before the final reveal Watch the episode here: https://youtu.be/wo-Vy6okKVI
What does secure coding look like today? Carl and Richard talk to Chris Ayers about the MITRE ATT&CK matrix, a comprehensive breakdown of the tactics, techniques, and procedures black hats use to exploit your systems. Chris talks about the role of developers in creating more secure software, starting with logging - surfacing important data about the use of applications that can help indicate when a black hat is taking advantage of it. The conversation also digs into supply chain attacks, various techniques for resisting exploits being introduced through libraries, and the ever-expanding array of threats affecting software today!
What does secure coding look like today? Carl and Richard talk to Chris Ayers about the MITRE ATT&CK matrix, a comprehensive breakdown of the tactics, techniques, and procedures black hats use to exploit your systems. Chris talks about the role of developers in creating more secure software, starting with logging - surfacing important data about the use of applications that can help indicate when a black hat is taking advantage of it. The conversation also digs into supply chain attacks, various techniques for resisting exploits being introduced through libraries, and the ever-expanding array of threats affecting software today!
This week we are joined by Marcelle Lee, cybersecurity consultant and researcher, discussing "CTI tradecraft: Investigating a mobile scareware campaign." She details how a routine click on a Google News story led to a mobile scareware pop-up—and a deeper investigation into a broader campaign. Using free tools like Censys, URLScan, VirusTotal, and CyberChef, she pivoted from two domains to uncover more than 100 related domains, shared infrastructure, and links to questionable antivirus apps in the Google Play Store. The findings are mapped to the MITRE ATT&CK framework, showing how freely available resources can power meaningful, actionable threat intelligence. The research can be found here: CTI tradecraft: Investigating a mobile scareware campaign Learn more about your ad choices. Visit megaphone.fm/adchoices
This week we are joined by Marcelle Lee, cybersecurity consultant and researcher, discussing "CTI tradecraft: Investigating a mobile scareware campaign." She details how a routine click on a Google News story led to a mobile scareware pop-up—and a deeper investigation into a broader campaign. Using free tools like Censys, URLScan, VirusTotal, and CyberChef, she pivoted from two domains to uncover more than 100 related domains, shared infrastructure, and links to questionable antivirus apps in the Google Play Store. The findings are mapped to the MITRE ATT&CK framework, showing how freely available resources can power meaningful, actionable threat intelligence. The research can be found here: CTI tradecraft: Investigating a mobile scareware campaign Learn more about your ad choices. Visit megaphone.fm/adchoices
Du denkst, dein IoT-Kram ist harmlos: ein Thermometer, ein Staubsaugerroboter, ein bisschen Smart Home. Aber was, wenn genau diese Geräte der perfekte Tunnel aus deinem Netzwerk sind, weil sie selten sauber segmentiert werden, kaum jemand Egress Traffic prüft und Authentifizierung oft mit Autorisierung verwechselt wird?In dieser Episode nehmen wir drei Sicherheitsvorfälle auseinander und ziehen konkrete Learnings daraus:Den Aquarium-Thermometer-Case im Casino mit ungewöhnlichem Outbound Traffic, alternative Exfiltration Kanäle und die Frage, ob IoT wirklich das Einfallstor war oder eher der Exit. Ein Jeep Cherokee Hack von 2015, inklusive offenen Port 6667, DBus-Zugriff, Firmware ohne Signierung, CAN-Bus und einem Diagnosemodus, der plötzlich die Bremsen ausknipst. Ein MQTT Case rund um Staubsaugerroboter, Pub/Sub, Wildcards und fehlende ACLs, also Mandantenisolierung zum Weglaufen.Am Ende bleibt eine unbequeme, aber sehr praktische Checkliste: Segmentierung, Zero Trust, Least Privilege, Monitoring und Logging, Secure Boot und vor allem Egress Traffic als First Class Control.Und jetzt Hand aufs Herz: Was ist deine beste Ausrede, warum dein Netzwerk noch nicht segmentiert ist?Unsere aktuellen Werbepartner findest du auf https://engineeringkiosk.dev/partnersDas schnelle Feedback zur Episode:
In this episode Michael and Mark talk with guest Blake Strom about the origins of the MITRE ATT&CK framework, how it was developed, and how it has evolved over time. We also discuss how the framework is used in the industry and its impact on cybersecurity.We also discuss Azure Security news about Azure Monitor, Azure Application Gateway, AKS, Azure Front Door, AMD v6 Confidential VMs, and xxxhttps://aka.ms/azsecpod
Fraud hasn't disappeared - it got smarter. Organized rings now aim upstream at SaaS platforms and ISVs that embed payments, where a single gap in onboarding, transaction logic, or refund flows can be scaled into thousands of attacks overnight. We sit down with Brian Rust, SVP and Deputy Chief Information Security Officer at Worldpay, to map the real fraud journey (entry, action, exit) and the concrete moves product and security leaders can make right now to protect merchants and brand trust.We start with the why: platforms offer leverage. Brian explains how bots and AI generate convincing synthetic businesses that pass weak KYC, and what early signals still break the spell - impossible form completion times, IP and address mismatches, and brand-new domains claiming long histories. From there, we dive into the middle of the kill chain: card testing. You'll hear how velocity spikes, elevated decline rates, and geo anomalies betray large-scale testing and how adaptive limits for new merchants can contain losses and prevent network penalties. Then we confront refund abuse, where attackers exploit trust by refunding to different instruments or flooding high-value returns. The fix isn't blanket friction - it's precision: refund-to-original-card only, refund velocity caps, and targeted reviews that slow bad actors while keeping good customers moving.Brian lays out the layers that matter now: device fingerprinting, behavioral analytics, and transaction monitoring that can halt suspect money movement before funds leave your orbit. He also makes the case for a fraud-cyber fusion model, aligning teams and intelligence using frameworks like MITRE ATT&CK to anticipate tactics as cyber and financial motives blend. Finally, we close with three actions you can ship this quarter: audit onboarding with bot controls and threat modeling, enforce velocity controls that adapt as trust grows, and tap your processor's data and filters (AVS, CVV) to harden defaults.If you lead product, risk, or engineering for a payments-enabled platform, this conversation gives you a practical blueprint to raise attacker costs, protect your merchants, and guard your reputation.
*Threat Hunting Workshop: Hunting for Privilege Escalation - Level 2February 11, 2026 | 12:00 - 1:00 PM ETSign Up: https://www.intel471.com/resources/webinars/threat-hunting-workshop-hunting-for-privilege-escalation-level-2----------Out of the Woods: The Threat Hunting Podcast returned with a live episode focused on the trends threat hunters saw repeatedly throughout 2025 and what those patterns point to next.This episode serves as a threat hunter's year in review. The discussion walks through the actors, malware, behaviors, tactics, and techniques that consistently surfaced over the year, ties those findings back to MITRE ATT&CK, and connects themes across recent episodes. The focus is on what stayed consistent, what mattered most during hunts, and what those signals reveal about where attention should remain.The conversation also looks ahead. Based on what emerged in 2025 and how hunts played out across environments, the panel shares perspectives on what is likely to continue, where focus is expected to remain in 2026, and what threat hunters should keep in mind going forward.Topics covered include: Threat actors, malware, and behaviors that appeared most often in 2025 Tactics and techniques that consistently surfaced across hunts, mapped to MITRE ATT&CK Common hunt themes observed across environments throughout the year What 2025 trends suggest about threat hunting focus in 2026 Behaviors and techniques likely to remain relevant moving forward Watch the episode here: https://youtu.be/GyYTTMNyjCE?si=WynwmHS1psGN9KqO----------Stay in Touch!Twitter: https://twitter.com/Intel471IncLinkedIn: https://www.linkedin.com/company/intel-471/YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkgDiscord: https://discord.gg/DR4mcW4zBrFacebook: https://www.facebook.com/Intel471Inc/
Podcast: Cloud Security Podcast by Google (LS 36 · TOP 2.5% what is this?)Episode: EP257 Beyond the 'Kaboom': What Actually Breaks When OT Meets the Cloud?Pub date: 2026-01-05Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationGuest: Chris Sistrunk, Technical Leader, OT Consulting, Mandiant Topics: When we hear "attacks on Operational Technology (OT)" some think of Stuxnet targeting PLCs or even backdoored pipeline control software plot in the 1980s. Is this space always so spectacular or are there less "kaboom" style attacks we are more concerned about in practice? Given the old "air-gapped" mindset of many OT environments, what are the most common security gaps or blind spots you see when organizations start to integrate cloud services for things like data analytics or remote monitoring? How is the shift to cloud connectivity - for things like data analytics, centralized management, and remote access - changing the security posture of these systems? What's a real-world example of a positive security outcome you've seen as a direct result of this cloud adoption? How do the Tactics, Techniques, and Procedures outlined in the MITRE ATT&CK for ICS framework change or evolve when attackers can leverage cloud-based reconnaissance and command-and-control infrastructure to target OT networks? Can you provide an example? OT environments are generating vast amounts of operational data. What is interesting for OT Detection and Response (D&R)? Resources: Video version Cybersecurity Forecast 2026 report by Google Complex, hybrid manufacturing needs strong security. Here's how CISOs can get it done blog "Security Guidance for Cloud-Enabled Hybrid Operational Technology Networks" paper by Google Cloud Office of the CISO DEF CON 23 - Chris Sistrunk - NSM 101 for ICS MITRE ATT&CK for ICS The podcast and artwork embedded on this page are from Anton Chuvakin, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
In this episode of CISO Tradecraft, host G Mark Hardy welcomes special guest Rajan Kapoor, VP of Security at Material Security, to discuss critical topics in cloud workspace security. From discussing the increased attack surfaces in cloud environments like Google Workspace and Microsoft 365 to practical solutions for mitigating these risks, Rajan provides invaluable insights into creating a secure cloud office environment. Tune in for expert advice on improving security maturity, managing cloud security tools efficiently, and leveraging modern technology for enhanced protection and reduced dwell time. Whether you're a small enterprise or a large corporation, this episode has actionable insights to help you strengthen your security posture.Check out the Material Security Scorecard to measure your Cloud Office Securityhttps://material.security/workspace-security-scorecardRajan Kapoorhttps://www.linkedin.com/in/rajankkapoor/MITRE ATT&CK® Office Suite platform https://attack.mitre.org/matrices/enterprise/cloud/officesuite/
Can You Identify the Nation-State Actor? Out of the Woods: The Threat Hunting Podcast returns for another special edition episode that challenges how you think about adversary behavior. This live, interactive session will focus on a nation-state actor, revealing one phase of their campaign at a time as our hosts provide tradecraft clues and analysis. Participants will examine how observed techniques align to MITRE ATT&CK, how vertical-specific targeting shapes operational decisions, and how behavioral patterns emerge across campaigns. Before the final reveal, attendees will have the chance to submit their best guess on which nation-state threat actor is behind the activity. What You'll Learn: Real adversary behavior – A phase-by-phase look at a real nation-state campaign MITRE ATT&CK in context – How techniques appear in real incidents Recognizing tradecraft patterns – What links behaviors across operations Sector-specific targeting – How industries influence attacker decisions Interactive analysis – Submit your guess before the reveal Watch the episode here: https://youtu.be/GyYTTMNyjCE?si=WynwmHS1psGN9KqO
In this episode, James Maude sits down with Kevin E. Green, Chief Security Strategist at BeyondTrust, whose 25+ year career stretches from configuring Nokia firewalls in basements to shaping federal research initiatives. Kevin recalls how crashing systems during penetration tests at Ernst & Young was once considered a win - a “capture the flag” moment - and how he crossed paths with future industry leaders like Stuart McClure and George Kurtz, who went on to found Cylance. He shares his pivotal work in mapping NIST 800-53 controls to the MITRE ATT&CK framework, transforming static security catalogs into threat-informed heat maps that show which defenses light up against real-world attacks. Blending technical depth with cultural insight, Kevin also draws unexpected parallels between cybersecurity and hip-hop — from how attacker techniques echo rapper “signatures” to why his alter ego "Kevtorious" and his "Secure Coding by Nature" brand reflect the creativity and pattern recognition needed in both fields.
Please enjoy this encore of Word Notes. A knowledge base of adversary tactics, techniques, and procedures established and maintained by the MITRE Corporation. CyberWire Glossary link: https://thecyberwire.com/glossary/mitre-attck Audio reference link: “Attack Frameworks - SY0-601 CompTIA Security+ : 4.2,” Professor Messer, YouTube, 29 April 2021.
Please enjoy this encore of Word Notes. A knowledge base of adversary tactics, techniques, and procedures established and maintained by the MITRE Corporation. CyberWire Glossary link: https://thecyberwire.com/glossary/mitre-attck Audio reference link: “Attack Frameworks - SY0-601 CompTIA Security+ : 4.2,” Professor Messer, YouTube, 29 April 2021. Learn more about your ad choices. Visit megaphone.fm/adchoices
In this episode, Mike Kosak explains what threat intelligence really is (Mike's former boss said you have to “rub some thinking on it.”), how to define priority intelligence requirements (PIRs), how to treat model, where to find threat intel, and how to keep in actionable with tight feedback loops—not panic. Key takeaways:Threat intel ≠ data. It's analyzed info focused “walls-out” (what's outside your org), then shared clearly so people can act.Start with PIRs. Ask: What are we protecting? What is most valuable to our company? What might threat actors want? How do they operate? What do we need to know to defend? Do this with a broad set of stakeholders, not just the security team.Communicate clearly and with context. Intelligence is only valuable if it's shared in a way others can understand and act on. Avoid overwhelming people with raw data or inducing panic — provide actionable insights that are right-sized for the audience. Mike's advice: “As a threat intelligence analyst, if you're doing your job right, when somebody hears from you they know they need to act on it. You don't want to be the chicken little where you make everybody freak out about everything.”Start small and iterate. Even if you're a one-person team, you can make a big impact. Use free resources (like MITRE ATT&CK, open-source feeds, or even vendor reports), summarize what's relevant, and push that out. Then refine based on feedback—treat it as a continuous cycle, not a one-and-done project. Mike admits, “I always say it's like painting the Golden Gate Bridge. As soon as you get done, you gotta start back at the other end. That's basically what it is.”Mike Kosak is the Senior Principal Intelligence Analyst at Lastpass. Mike references a series of articles he wrote, including “Setting Up a Threat Intelligence Program From Scratch.” https://blog.lastpass.com/posts/setting-up-a-threat-intelligence-program-from-scratch-in-plain-language
In this episode, Richard speaks to Gerald Beuchelt. He's the Chief Information Security Officer at Acronis, a company protecting millions of endpoints across 54 data centres, many of them managed by MSPs just like you. He's led security through IPOs, a $5 billion merger, and now heads up the Acronis Threat Research Unit, or TRU. And that's a team uncovering wild cyber threats that potentially pose a risk to all MSPs and their clients.Richard asks Gerald to explain the role of a CISO in his own words, how he got into cybersecurity and how his background in mathematics helps him in his work today.They explore the Acronis Threat Research Unit (TRU) and what Acronis looks like in 2025, with Gerald talking through the changes they've made. He also offers suggestions on how MSPs can deal with vendor fatigue and how bringing everything into one place makes it easier.Richard asks Gerald to explain what a cyber snake and chaosRAT are and how MSPs can support clients using older systems, as well as cyber threats to be aware of and how to educate clients on them.Gerald shares his thoughts on what a security-first MSP is, why EDR and RMM are merging and how MSPs can prepare for that and how AI use by cyber criminals is getting ever more sophisticated.He gives one practical habit MSPs can use to improve their security posture, how to get started with Acronis and make the most of its features and what's coming next for the organisation. Mentioned in This EpisodeAcronisWindows domain networks directory: Active DirectoryComputer programme: KerberosThreat knowledge base: MITRE ATT&CK Verizon breach reportCRM software: SalesforceCyber threat: Sidewinder ATPSpeaker and author: Karl PalachukDark web: Digital UndergroundMSP event: MSP GlobalCyber event: Infosec LondonCloned Richard podcast
Security leaders from Anthropic and AWS discuss how agentic AI is transforming cybersecurity functions to autonomously handle everything from code reviews to SOC operations.Topics Include:Agentic AI differs from traditional AI through autonomy and agencyTraditional AI handles single workflow nodes, agents collapse multiple stepsHigher model intelligence enables understanding of broader business contextsAgents make intelligent decisions across complex multi-step workflows processesEnterprise security operations are seeing workflow consolidation through GenAIOrganizations embedding GenAI directly into customer-facing production applicationsSoftware-as-a-service transitioning to service-as-software through AI agentsSecuring AI requires guardrails to prevent hallucinations in applicationsNew vulnerabilities appear at interaction points between system componentsAttackers target RAG systems and identity/authorization layers insteadLLMs hallucinate non-existent packages, attackers create malicious honeypotsGovernance frameworks must be machine-readable for autonomous agent reasoningAmazon investing in automated reasoning to prove software correctnessAnthropic uses Claude to write over 50% of codeAutomated code review systems integrated into CI/CD pipelinesSecurity design reviews use MITRE ATT&CK framework automationLow-risk assessments enable developers to self-approve security reviews40% reduction in application security team review workloadAnthropic eliminated SOC, replaced entirely with Claude-based automationIT support roles transitioning to engineering as automation replaces frontlineCompliance questionnaires fully automated using agentic AI workflowsISO 42001 framework manages AI deployment risks alongside securityExecutive risk councils evaluate AI risks using traditional enterprise processesAWS embeds GenAI into testing, detection, and user experienceFinding summarization helps L1 analysts understand complex AWS environmentsAmazon encourages teams to "live in the future" with AIInterview candidates expected to demonstrate Claude usage during interviewsSecurity remains biggest barrier to enterprise AI adoption beyond POCsVirtual employees predicted to arrive within next 12 monthsModel Context Protocol (MCP) creates new supply chain security risksParticipants:Jason Clinton – Chief Information Security Officer, AnthropicGee Rittenhouse – Vice President, Security Services, AWSHart Rossman – Vice President, Global Services Security, AWSBrian Shadpour – GM of Security and B2B Software Sales, AWSSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon.com/isv/
Clue by Clue: Can You Name the Threat Actor? Out of the Woods: The Threat Hunting Podcast returns with a special edition live episode built to sharpen how threat hunters think about adversary behavior. Our hosts will walk through a real-world threat actor's activity one phase at a time, revealing tradecraft clues as the investigation unfolds. Listeners will have the chance to analyze the behavior and submit their best guess before the final reveal. This live, interactive session is grounded in real tradecraft and practical threat hunting techniques. You'll see how MITRE ATT&CK techniques map to observed activity, how vertical-specific targeting shapes decisions, and how behavioral patterns can point to attribution faster. What We'll Cover: Real adversary behavior – A phase-by-phase walkthrough of a known threat actor's campaign MITRE ATT&CK in context – How techniques are applied in real incidents Recognizing tradecraft patterns – What links certain behaviors across threat actors Sector-specific targeting – How industry focus shapes attacker decisions Interactive analysis – Submit your guess before the threat actor is revealed live Engage with the Community! Join our Discord server during the episode to follow the clues, connect with other hunters, and share your thoughts in real time. Don't miss this chance to train your instincts and challenge your threat hunting perspective. Join the discussion here: https://discord.gg/DR4mcW4zBr ---- Stay in Touch! Twitter: https://twitter.com/Intel471Inc LinkedIn: https://www.linkedin.com/company/intel-471/ YouTube: https://www.youtube.com/channel/UCIL4ElcM6oLd3n36hM4_wkg Discord: https://discord.gg/DR4mcW4zBr Facebook: https://www.facebook.com/Intel471Inc/
This fireside chat explores achieving resilience in the "Cyber War," particularly concerning cyber security in open source systems. Moderated by Ashley Fairman, the discussion with Damian Taylor (USPS) and Jennifer (Supply Chain Risk Management expert) defines resilience as the ability to recover quickly or preempt disruptions. They advocate for a "defense-in-depth" approach with multiple layers of security, acknowledging that disruption is inevitable. The evolution of cyber threats, from simple viruses to sophisticated, state-sponsored attacks often leveraging AI, is discussed, highlighting how interconnected systems increase the impact and cost of incidents, such as the SolarWinds supply chain attack. The panelists emphasize that humans are often the weakest link and stress the need for continuous monitoring, detection, and response. Key tips for enhancing resilience include sourcing from reputable vendors, conducting third-party assessments, understanding how systems are used, and leveraging security frameworks like MITRE ATT&CK. Strategic investments in people (training and knowledge sharing) and prioritized technology (like active disaster recovery systems) are identified as crucial. They underline the importance of collaboration across government, academia, and industry, noting challenges like overclassification hindering vulnerability sharing.• Discusses cybersecurity resilience in the context of open source systems.• Defines resilience as the ability to get back up quickly when knocked down or preempt disruption.• Advocates for a defense-in-depth strategy, using multiple layers of security measures.• Describes the evolution of cyber threats from simple viruses to sophisticated, agenda-driven, state-sponsored attacks, increasingly leveraging AI.• Highlights the significant impact and increasing cost of cyber incidents, citing the SolarWinds supply chain attack as an example.• Identifies humans as often the weakest link and stresses the need to think as part of a larger, interconnected ecosystem.• Provides tips for enhancing resilience: sourcing from reputable vendors, conducting third-party assessments, understanding how systems are used, and implementing continuous monitoring, detection, and response.• Stresses building a true secure environment that goes beyond mere compliance checklists.• Recommends strategic investments in people (training, knowledge sharing) and prioritized technology (active disaster recovery systems, security frameworks like MITRE ATT&CK).• Underlines the critical importance of collaboration across government, academia, and industry, suggesting efforts to lower barriers to entry, particularly for state and local entities.• Discusses challenges in validating the security of hardware and software from potentially untrusted sources and the difficulty of assessing models.• Mentions the need for better vulnerability sharing and moving past overclassification in government.• Highlights the value of "red teaming" (simulated attacks) for testing defenses and training staff.For more content like this check out www.projectgeospatial.com#FedGeoDay #Cybersecurity #Resilience #OpenSource #SupplyChainRisk #CyberWar #DefenseInDepth #MITREATTCK #CyberThreats #RiskManagement #Collaboration #USPS #DICECyber
⬥GUEST⬥Allie Mellen, Principal Analyst, Forrester | On LinkedIn: https://www.linkedin.com/in/hackerxbella/⬥HOST⬥Host: Sean Martin, Co-Founder at ITSPmagazine and Host of Redefining CyberSecurity Podcast | On ITSPmagazine: https://www.itspmagazine.com/sean-martin⬥EPISODE NOTES⬥In this episode, Allie Mellen, Principal Analyst on the Security and Risk Team at Forrester, joins Sean Martin to discuss the latest results from the MITRE ATT&CK Ingenuity Evaluations and what they reveal about detection and response technologies.The Role of MITRE ATT&CK EvaluationsMITRE ATT&CK is a widely adopted framework that maps out the tactics, techniques, and procedures (TTPs) used by threat actors. Security vendors use it to improve detection capabilities, and organizations rely on it to assess their security posture. The MITRE Ingenuity Evaluations test how different security tools detect and respond to simulated attacks, helping organizations understand their strengths and gaps.Mellen emphasizes that MITRE's evaluations do not assign scores or rank vendors, which allows security leaders to focus on analyzing performance rather than chasing a “winner.” Instead, organizations must assess raw data to determine how well a tool aligns with their needs.Alert Volume and the Cost of Security DataOne key insight from this year's evaluation is the significant variation in alert volume among vendors. Some solutions generate thousands of alerts for a single attack scenario, while others consolidate related activity into just a handful of actionable incidents. Mellen notes that excessive alerting contributes to analyst burnout and operational inefficiencies, making alert volume a critical metric to assess.Forrester's analysis includes a cost calculator that estimates the financial impact of alert ingestion into a SIEM. The results highlight how certain vendors create a massive data burden, leading to increased costs for organizations trying to balance security effectiveness with budget constraints.The Shift Toward Detection and Response EngineeringMellen stresses the importance of detection engineering, where security teams take a structured approach to developing and maintaining high-quality detection rules. Instead of passively consuming vendor-generated alerts, teams must actively refine and tune detections to align with real threats while minimizing noise.Detection and response should also be tightly integrated. Forrester's research advocates linking every detection to a corresponding response playbook. By automating these processes through security orchestration, automation, and response (SOAR) solutions, teams can accelerate investigations and reduce manual workloads.Vendor Claims and the Reality of Security ToolsWhile many vendors promote their performance in the MITRE ATT&CK Evaluations, Mellen cautions against taking marketing claims at face value. Organizations should review MITRE's raw evaluation data, including screenshots and alert details, to get an unbiased view of how a tool operates in practice.For security leaders, these evaluations offer an opportunity to reassess their detection strategy, optimize alert management, and ensure their investments in security tools align with operational needs.For a deeper dive into these insights, including discussions on AI-driven correlation, alert fatigue, and security team efficiency, listen to the full episode.⬥SPONSORS⬥LevelBlue: https://itspm.ag/attcybersecurity-3jdk3ThreatLocker: https://itspm.ag/threatlocker-r974⬥RESOURCES⬥Inspiring Post: https://www.linkedin.com/posts/hackerxbella_go-beyond-the-mitre-attck-evaluation-to-activity-7295460112935075845-N8GW/Blog | Go Beyond The MITRE ATT&CK Evaluation To The True Cost Of Alert Volumes: https://www.forrester.com/blogs/go-beyond-the-mitre-attck-evaluation-to-the-true-cost-of-alert-volumes/⬥ADDITIONAL INFORMATION⬥✨ More Redefining CyberSecurity Podcast:
Eric Carter of Sysdig joins Corey to tackle the evolving landscape of cloud security, particularly in AWS environments. As attackers leverage automation to strike within minutes, Sysdig focuses on real-time threat detection and rapid response. Tools like Runtime Insights and open-source Falco help teams identify and mitigate misconfigurations, excessive permissions, and stealthy attacks, while Kubernetes aids in limiting lateral movement. Eric introduced the “10-minute benchmark” for defense, combining automation and human oversight. Adapting to constant change, Sysdig integrates frameworks like MITRE ATT&CK to stay ahead of threats. Corey and Eric also discuss Sysdig's conversational AI security analyst, which simplifies decision-making.Show Highlights(0:00) Intro(0:32) Sysdig sponsor read(0:51) What they do at Sysdig(3:28) When you need a human in the loop vs when AI is useful(5:12) How AI may affect career progression for cloud security analysts(8:18) The importance of security for AI(12:18) Sysdig sponsor read(12:39) Security practices in AWS(15:19) How Sysdig's security reports have shaped Corey's thinking(18:10) Where the cloud security industry is headed(20:03) Cloud security increasingly feeling like an arms race between attackers and defenders(23:33) Frustrations with properly configuring leased permissions(28:17) How to keep up with Eric and SysdigAbout Eric CarterEric is an AWS Cloud Partner Advocate focused on cultivating Sysdig's technology cloud and container partner ecosystem. Eric has spearheaded marketing efforts for enterprise technology solutions across various domains, such as security, monitoring, storage, and backup. He is passionate about working with Sysdig's alliance partners, and outside of work, enjoys performing as a guitarist in local cover bands.LinksSysdig's website: https://sysdig.com/Sysdig's AWS Cloud Security: https://sysdig.com/ecosystem/aws/Sysdig's 5 Steps to Securing AWS Cloud Infrastructure: https://sysdig.com/content/c/pf-5-steps-to-securing-aws-cloud-infrastructure?x=Xx8NSJSponsorSysdig: https://www.sysdig.com
The assassination attempt on former President Trump sparks online disinformation. AT&T pays to have stolen data deleted. Rite Aid recovers from ransomware. A hacktivist group claims to have breached Disney's Slack. Checkmarx researchers uncover Python packages exfiltrating user data. HardBit ransomware gets upgraded with enhanced obfuscation. Threat actors can weaponize proof-of-concept (PoC) exploits in as little as 22 minutes. Google may be in the market for Wiz. Rick Howard previews his analysis of the MITRE ATT&CK framework. Blockchain sleuths follow the money. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. This Week on CSO Perspectives Dave chats with Rick Howard, The CSO, Chief Analyst, and Senior Fellow at N2K Cyber, about his latest episode of CSO Perspectives which focuses on the current state of MITRE ATT&CK. If you are a N2K Pro subscriber, you can find this installment of CSO Perspectives here. The accompanying essay is available here. If you're not a subscriber and want to check out a sample of the discussion Rick has with his Hash Table members about MITRE ATT&CK, you can find it here. Selected Reading Conspiracy theories spread swiftly in hours after Trump rally shooting (The Washington Post) AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records (WIRED) Pharmacy Giant Rite Aid Hit By Ransomware (Infosecurity Magazine) Disney's Internal Slack Breached? NullBulge Leaks 1.1 TiB of Data (HackRead) Malicious Python packages found exfiltrating user data to Telegram bot (Computing) HardBit ransomware version 4.0 supports new obfuscation techniques (Security Affairs) Hackers use PoC exploits in attacks 22 minutes after release (Bleeping Computer) Google is reportedly planning its biggest startup acquisition ever (The Verge) Automotive SaaS provider CDK paid $25 million ransom to hackers (BeyondMachines.net) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
Rick Howard, The CSO, Chief Analyst, and Senior Fellow at N2K Cyber, discusses the current state of MITRE ATT&CK with CyberWire Hash Table guests Frank Duff, Tidal Cyber's Chief Innovation Officer, Amy Robertson, MITRE Threat Intelligence Engineer and ATT&CK Engagement lead, and Rick Doten, Centene's VP of Information Security. References: Amy L. Robertson, 2024. ATT&CK 2024 Roadmap [Essay]. Medium. Blake E. Strom, Andy Applebaum, Doug P. Miller, Kathryn C. Nickels, Adam G. Pennington, Cody B. Thomas, 2018. MITRE ATT&CK: Design and Philosophy [Historical Paper]. MITRE. Eric Hutchins, Michael Cloppert, Rohan Amin, 2010. Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains [Historic Paper]. Lockheed Martin Corporation. Nick Selby, 2014. One Year Later: The APT1 Report [Essay]. Dark Reading. Rick Howard, 2023. Cybersecurity First Principles: A Reboot of Strategy and Tactics [Book]. Goodreads. Rick Howard, 2020. Intrusion kill chains: a first principle of cybersecurity. [Podcast]. The CyberWire. Rick Howard, 2022. Kill chain trifecta: Lockheed Martin, ATT&CK, and Diamond. [Podcast]. The CyberWire. Rick Howard, 2020. cyber threat intelligence (CTI) (noun) [Podcast]. Word Notes: The CyberWire. Kevin Mandia, 2014. State of the Hack: One Year after the APT1 Report [RSA Conference Presentation]. YouTube. SAHIL BLOOM, 2023. The Blind Men & the Elephant [Website]. The Curiosity Chronicle. Sergio Caltagirone, Andrew Pendergast, and Christopher Betz. 05 July 2011. The Diamond Model of Intrusion Analysis. Center for Cyber Threat Intelligence and Threat Research.[Historical Paper] Staff, n.d. Home Page [Website]. Tidal Cyber. Learn more about your ad choices. Visit megaphone.fm/adchoices