Podcasts about Mobile security

Security risk and prevention for mobile devices

  • 192PODCASTS
  • 445EPISODES
  • 33mAVG DURATION
  • 1EPISODE EVERY OTHER WEEK
  • Aug 10, 2026LATEST
Mobile security

POPULARITY

20192020202120222023202420252026


Best podcasts about Mobile security

Latest podcast episodes about Mobile security

The Shared Security Show
GrapheneOS Phone Wipe Case: When Privacy Tools Become Evidence

The Shared Security Show

Play Episode Listen Later Aug 10, 2026 16:25


A federal case involving a GrapheneOS phone wipe during an airport search raises a bigger question for privacy-minded users: can using strong mobile security features be treated as evidence of criminal intent? Tom and Scott break down what happened, why border searches are different, and what this could mean for secure phones and everyday privacy.Tom and Scott also discuss duress codes, realistic travel threat models, and Scott's Digital Legacy Tree update.** Links mentioned on the show **TechSpot — US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search https://www.techspot.com/news/113236-us-prosecutors-charge-atlanta-man-after-grapheneos-phone.htmlGrapheneOS project https://grapheneos.org/EFF — Border searches https://www.eff.org/issues/border-searchesHelp Review The Digital Legacy Tree (upcoming book by Scott Wright)To volunteer, share your story, or suggest ideas that may help others facing digital legacy challenges, visit:https://securityperspectives.com/digital-legacy-tools** Watch this episode on YouTube **https://youtu.be/Cch3pG2EO-g** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **GuardsquareSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contactSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.

Hacker Valley Studio
Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

Hacker Valley Studio

Play Episode Listen Later Aug 7, 2026 38:27


What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from homeless high school dropout to Army infantry to building a company that rethinks mobile security from the ground up. Jared makes the case for something more radical than most vendors will admit: stop defending the edge device entirely, and make sure sensitive data never lands there in the first place. He and Ron cover MDM and MAM's blind spots, executive protection, and the shadow AI habits quietly becoming every security leader's next headache. The episode also lands at a tense moment for the defense industrial base with the Pentagon having just paused third party CMMC assessments, now putting the burden of proof back on self attestation. If you're still trusting the edge device to protect you, this episode is your wake up call. Impactful Moments  00:00 - Introduction  02:00 - Hack The Headlines: Top new from around the industry 07:30 - Meet Jared Shepard, founder and CEO of Hypori  10:00 - What Hypori does and how it started  15:40 - MDM vs. MAM: why both miss the real problem  18:45 - Shadow AI and the security habits practitioners can't ignore  20:30 - Collapsing the attack surface and bringing back BYOD (Bring Your Own Device)  22:40 - The 4-gigabit-speed "parlor trick" that proves the Cloud beats your device 25:20 - What the 60-day CMMC pause really changes (and what it doesn't) 29:20 - China, stolen tech, and the rise of AI models like Mythos  36:00 - Closing the loop on the CMMC pause    Links  Connect with Jared Shepard on LinkedIn: https://www.linkedin.com/in/shepardj  Learn more about Hypori: https://hypori.com  –  Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/  

Paul's Security Weekly
AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

Paul's Security Weekly

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

Enterprise Security Weekly (Audio)
AppSec, Shopify-Style; State of Mobile Security; the News - Kern Smith, Andrew Dunbar - ESW #470

Enterprise Security Weekly (Audio)

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-470

Paul's Security Weekly TV
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Paul's Security Weekly TV

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

Enterprise Security Weekly (Video)
AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

Enterprise Security Weekly (Video)

Play Episode Listen Later Aug 3, 2026 97:00


Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

The Inventive Journey

In this episode of The Inventive Journey, Devin Miller interviews Sergey Korolev about a founder path that refuses to stay in one lane. Sergey's story begins with robotics engineering at Bauman Technical University in Moscow, includes competitive water polo, moves into enterprise automation, and then grows into Just Food, a meal kit and delivery business that reached roughly $10 million in annual revenue over about six years.Just Food was not a cute side project with a logo and three inspirational quotes taped to a wall. It was a real operating business with logistics, customer expectations, influencer marketing, engineering demands, and the daily joy of discovering that food delivery is simple only when someone else is doing it. Sergey and his team grew the company in Russia's health and fitness market, learning how to build systems, manage pressure, and turn a real customer need into a scaling company.Then the environment changed. Sergey explains how geopolitical constraints made it difficult to build the kind of global company he wanted from Russia. He eventually moved to Portugal and stepped away from running the food tech company. That transition forced a bigger founder question: after building one successful company, what comes next?Sergey did not want to simply recreate the same model in a different wrapper. He wanted a company that could be global from the beginning, a category with meaningful technical depth, and an engineering partner who could bring serious domain expertise. That search led him into mobile application security and to the creation of Oversecured.Oversecured helps enterprises find vulnerabilities in mobile applications. The company focuses on a problem that is becoming harder for businesses to ignore. Mobile apps are not just tiny brand brochures anymore. They handle authentication, payments, private data, location, workflows, and connections to backend systems. When mobile security is treated as an afterthought, the risks can become very real, very fast, and very unpleasant for everyone except the attacker.In the conversation, Sergey also shares one of his toughest founder lessons: underestimating emotions in negotiations. Founders often want to believe that business conflict is rational because there are contracts, spreadsheets, and people using phrases like “alignment.” But negotiations are full of pride, fear, trust, control, timing, and incentives. Ignoring the emotional side can turn a business disagreement into an expensive lesson with legal paperwork attached.Sergey's advice to founders is memorable: act more and think less. The point is not to be careless. The point is to stop mistaking private overthinking for progress. Startups learn by testing, selling, shipping, listening, and adapting. A founder who takes action creates feedback. A founder who only plans creates prettier uncertainty.This episode is especially useful for startup founders and small business owners thinking about pivots, market constraints, cofounder selection, enterprise sales, or how to build after a previous chapter ends. Sergey's journey shows that a pivot is not automatically a failure. Sometimes it is the most honest response to what the market, the world, and your own ambition are telling you.Listen for a conversation about reinvention, global company-building, cybersecurity, zero-day vulnerabilities, negotiation mistakes, and why the founder path often looks obvious only after you have already survived it.You will also hear how Sergey approached the zero-to-one stage differently the second time around. His criteria were clearer: build with the right technical partner, avoid regional limitations, and choose a market where deep expertise could become a durable advantage. That is useful perspective for any founder who has outgrown one chapter but has not yet named the next one.To chat about this one-on-one, grab a free consult at strategymeeting.com

Artificial Intelligence in Industry with Daniel Faggella
The Mobile Security Imperative for Regulated Industries - with Tom Tovar of Appdome

Artificial Intelligence in Industry with Daniel Faggella

Play Episode Listen Later Jul 21, 2026 30:49


Mobile app attackers already operate at machine speed, but most enterprise cyber functions still rely on manual, human-paced patch cycles to keep up. In this episode, Tom Tovar, Co-Creator at Appdome, examines how agentic AI is replacing manual vulnerability assessment and forcing cyber teams to become producers of protection rather than evaluators of risk. The conversation covers the shift from application-level security policies to release- and user-level personalization, the data and context needed to run agentic protection pipelines, and the accountability questions that come with agentic decision-making.   This episode is sponsored by Appdome.   Learn how financial institutions are digitizing paper-based records to unlock usable data for AI, and using alternative data to enhance risk assessment. Download our free PDF report, "AI in Financial Services Executive Cheat Sheet" at emerj.com/fcs1

Besser Wissen
Der Fokus auf mobile Security

Besser Wissen

Play Episode Listen Later Jun 15, 2026 67:34


Jiska lehrt am HPI in Potsdam und erzählt im Podcast, wie sie dorthin gekommen ist - und was mobile Sicherheit bedeutet.

KCSB
Chair of Temporary AS Senate Student Safety Committee Discusses Mobile Security Units on Campus

KCSB

Play Episode Listen Later Apr 15, 2026 19:58


The AS Senate at UCSB has the ability to create temporary Senate committees to address concerns and important issues on campus. In early February, the Senate convened to form a temporary Student Safety Committee following a reported sexual assault at the UCSB Lagoon in October 2025. KCSB's Tatiana Jacquez spoke with Senator Riss, Chair of the new Student Safety Committee, to learn more about the MSUs, next steps, and what the committee learned from the pilot program.

The Leading Difference
Katie Bochnowski | SVP Customer Success & Services, NowSecure | Navigating Mobile Security in MedTech

The Leading Difference

Play Episode Listen Later Dec 12, 2025 29:01


Katie Bochnowski is the Senior Vice President of Customer Success & Services at NowSecure. Katie shares her journey from studying cyber forensics at Purdue University to becoming an expert in mobile app security and forensics. She discusses the impactful work her team does in securing mobile apps, especially in the medtech industry. Katie also offers valuable advice on building relationships within organizations, the importance of security best practices, and staying curious as a professional.  Guest links: https://www.linkedin.com/in/katiestrzempka/ | https://www.nowsecure.com/ Charity supported: Save the Children Interested in being a guest on the show or have feedback to share? Email us at theleadingdifference@velentium.com.  PRODUCTION CREDITS Host & Editor: Lindsey Dinneen Producer: Velentium Medical   EPISODE TRANSCRIPT Episode 070 - Katie Bochnowski [00:00:00] Lindsey Dinneen: Hi, I'm Lindsey and I'm talking with MedTech industry leaders on how they change lives for a better world. [00:00:09] Diane Bouis: The inventions and technologies are fascinating and so are the people who work with them. [00:00:15] Frank Jaskulke: There was a period of time where I realized, fundamentally, my job was to go hang out with really smart people that are saving lives and then do work that would help them save more lives. [00:00:28] Diane Bouis: I got into the business to save lives and it is incredibly motivating to work with people who are in that same business, saving or improving lives. [00:00:38] Duane Mancini: What better industry than where I get to wake up every day and just save people's lives. [00:00:42] Lindsey Dinneen: These are extraordinary people doing extraordinary work, and this is The Leading Difference. Hello, and welcome back to another episode of The Leading Difference podcast. I'm your host, Lindsey, and today I am absolutely delighted to introduce you to my guest, Katie Bochnowski. Katie is Senior Vice President of Customer Success and Services at NowSecure co-author of the book, "iPhone and iOS Forensics," and a recognized expert in mobile forensics and app security testing. Katie holds a master's in Cyber Forensics and Bachelor's of Science and Computer Technology from Purdue University. In her current role, Katie oversees customer support, onboarding and success departments, as well as the mobile AppSec Professional Services Organization that is responsible for pen testing, training, and consulting. All right. Well, welcome. Thank you so much for being here. I'm so delighted to speak with you today. [00:01:37] Katie Bochnowski: Awesome. I'm really happy to be here. [00:01:39] Lindsey Dinneen: Excellent. Well, I would love, if you wouldn't mind just starting off by telling us a little bit about yourself, your background, and what led you to medtech. [00:01:48] Katie Bochnowski: Awesome. Sure. So, I'm Katie Bochnowski. I work for a company called NowSecure. My background, dating back many years to school is in computer technology and more specifically cyber forensics. Where I am now is mobile app security. How I got into that industry is, is really from that forensic background. Our company used to do data recovery and forensic investigations on mobile devices, and we kind of quickly realized that mobile apps are storing a lot of data. So we shifted into proactively working with organizations to secure those apps that reside on devices. And in terms of medtech, obviously you can probably make that connection, but we began working closely with first, companies that really care about the data that's being stored, and transmitted on those apps, which absolutely includes medtech industry. [00:02:43] Lindsey Dinneen: Awesome. Okay, so going back a little bit. So when you were first deciding on college paths and career paths and all those lovely things, what drew you to where you ended up? [00:02:55] Katie Bochnowski: You know, I don't have a great, like "aha" moment for this question. It was just one of those things. I grew up, I had a computer in my house. I did Typing Tutor when I was really young on MS Dos, and I just always en enjoyed that. I had a friend in high school and we both got interested in making our own website with HTML. So, it was just enjoying being around computers and also tinkering to figure out what was wrong with something from a technology perspective. Purdue is where I attended. Purdue had a more generic computer technology degree that I didn't have to know exactly what I wanted to do. You could try different paths, so that's kind of what got me into it. It's not like I knew I wanted to do that my whole life, but I never really went back or questioned it. I always just kind of enjoyed it along the way. [00:03:45] Lindsey Dinneen: Yeah. Excellent. Okay, so the phrase cyber forensics is just exciting. So, can you dive a little bit more into exactly what that means and entails and what it looks like? [00:03:57] Katie Bochnowski: Yeah, absolutely. So, it is exciting- -so much so, in fact, that my senior year of college, the very first time they offered this class, it was called Cyber Forensics, it was an elective and it sounded amazing. And, it was amazing. It was really cool. We went through from start to finish, how you collect evidence from a computer and technology perspective, how you keep it pristine, how you collect the data off of it. We even got to work with local law enforcement as part of an internship to do all that, so I was very lucky in that my very last semester of my four years, they offered this and I just really, really liked it. It always was there in the back of my mind. So yeah, cyber forensics is really the collective of all things digital, which is everything, now. I don't do, necessarily, that work anymore, but I can't even imagine all of the data collection off of Alexas and, and all of those devices. But yeah, that's, that's kind of how I got into that. [00:04:56] Lindsey Dinneen: Wow, that's really cool. Yeah. So, okay, so talking about this data collection and all of these things, I'm curious, what are maybe one or two things that just really surprised you when you started getting into the industry and doing the work? [00:05:11] Katie Bochnowski: I know people always said this, and it shouldn't have been a surprise, but when I first started working for NowSecure-- which was actually called Via Forensics back in the day when I first started-- we worked on a lot of individual cases, so people saying, " Can you recover my deleted text messages, and pictures..." and things like that, and the amount of data that really does reside on those devices still after you delete them, going back months, years. So, I don't know if that's still the case now. I don't know if they do a better job of that, but that was surprising to us. What was also surprising was how much apps are storing and transmitting data on those devices when you don't think about it. So a lot of these cases that we would work on, they would focus so much on voicemails, emails, photos, and text messages, but nobody ever said, "Hey, can you go check the Facebook app or the Messenger app you're using?" That was something we realized pretty quickly, and were shocked to see-- this was 15 years ago-- how many apps were storing incredibly sensitive information on those devices. [00:06:20] Lindsey Dinneen: Yeah. And so now that there's more awareness of this and people are maybe, hopefully taking a little bit more ownership of even their own awareness and education with all of it, what do you see are the changes and shifts towards better protection? [00:06:38] Katie Bochnowski: Yeah. Great question. So there's a couple things: One, people are more aware, so they are leveraging the best practices really for these things. So there's places you should and shouldn't store data on devices, and you should use encryption for sensitive information and encryption that can't easily be broken into. The platforms themselves, too--Android, iOS-- have also made improvements in protecting those sandboxes. But, it's not everything, so you absolutely still have to be mindful of that. A lot of organizations like medtech companies and financial organizations do add a lot of those extra protections. But a lot of people don't, still. They're not either, don't think about it as much or aren't aware of it. And then the other thing that we see is everyone could have, you know, a hundred percent perfect intentions in storing and protecting that data, but you make a mistake, or you accidentally leave a debug flag on or something like that, where this information still can be accessed even though developers and security organizations are following the best practices there. [00:07:51] Lindsey Dinneen: Hmm. Yeah. So as you look toward the future of device security in general and cybersecurity, what are you looking forward to in terms of improvements, and hope for the future? Because I know there's a lot of things to worry about, just in life. But, what are some of the things that you're hopeful about? [00:08:11] Katie Bochnowski: Yeah. I'm hopeful for the--I'm going to call it the camaraderie--we're seeing between security and development groups. Not that there was argument or debate between them before-- there probably was a little bit-- but we are seeing a lot more organizations have what they refer to as a Security Champions Program, which brings those groups together. Security used to be seen, and probably in a lot of cases still, is seen as that blocker. Developers are being rushed and pushed to release features quickly. They have deadlines, timelines, and then if security finds an issue, it has to go back to the drawing board to remediate. But, with these programs, we're seeing either a development group that has a security champion there, or just teams kind of melding together a little bit more to build that testing earlier on. That's a trend we're seeing increase more and more. And, I believe that's going to only continue because it's just the right thing to do for everyone all around. [00:09:12] Lindsey Dinneen: Yeah, and that collaboration piece is so critical to eventual success, or hopefully even shorter-term success, like said, so that there's not as many iterations. It's like, "No, let's just integrate and do this from the start well together." Yeah. [00:09:27] Katie Bochnowski: Yep. [00:09:27] Lindsey Dinneen: Cool. Okay, so, you started with NowSecure, and then eventually you got your first medtech client. Could you talk about that experience? [00:09:36] Katie Bochnowski: Yeah, absolutely. Actually, before I even started with NowSecure, I worked for a Fortune 100 company in their security department doing firewall rule management. And, it was all good and everything, but I remember thinking throughout my career, I'm the type of person that likes to do things meaningful, making an impact on people. So, for many years, I was like, "Okay, what am I doing? I'm just executing firewall rules, I'm recovering data..." That's why the forensic work was so appealing to me because you were actually helping assist with investigations that mattered. Then, getting into the mobile app security industry was certainly important, but it took it to a whole new level for me when we got our first medtech client. I remember going on site and seeing some of the things that the apps can do in conjunction with medical devices, implants, et cetera, and thinking, "If you get this wrong, this can impact a human life." That helped bring all of this to a whole new level, and it's something I talk about internally within our organization as well to help people understand how meaningful it is --what we do, what the medtech industry does, and how important it is to get security right. It's just helped me with a new perspective. I love working with our medtech industry clients. It's contagious to be around them and see how much they care about what they do, and, how important it is to their lives --makes an impact on the way I work as well, then. [00:11:06] Lindsey Dinneen: Yeah, I love that. I think that's so true. I get so inspired by even just talking with these incredible founders, their devices and their heart behind why they're doing what they're doing. It's not an easy road so choosing to do so, and then hearing that passion is what drives them sometimes in those crazy late nights, early mornings, hassle in between, you know? So you started getting medtech clients, and now you've developed a niche offering for that group. I'm wondering, what are some of the common themes that you see companies maybe aren't aware to consider when they're starting their development of their devices and apps? And, perhaps just some general advice: What should people be on the lookout for? [00:11:50] Katie Bochnowski: Yeah, so I guess you-- I shouldn't say unique, but specific to organizations like medtech industry or, financial or healthcare and the apps they build-- is that highly sensitive information. And so I guess my advice and the thing I would point out that I see in those types of applications is not only, of course, best security practices and understanding what's unique in mobile is super important because web apps have been developed for many, many years. Mobile apps now have been many years, but people don't necessarily know that it is unique in the way that they are developed and the different attack surface, right? You have the local device attack surface. You have the attack surface of other apps that could be malicious that are installed on that device. So, understanding what those mobile unique security best practices are is my number one piece of advice for developers. Number two would then be multiple layers of security protection. So, developing a secure app is one part of it, and a very important part of it. What we see is a lot of organizations sometimes are dependent on either the protections of the device OS itself--the Android OS protections or iOS protections. And, there are tools out there that offer protections like tamper detection: If you detect the app is being tampered with, don't launch it. If you detect the app is installed on an exploited, rooted, jailbroken device, don't launch it. Or, don't allow login. Those are important, but those can be bypassed and so I say multiple layers of protection. I'm not against those protections. I think they're very important. I think you should do them, but you should also assume in some cases they can be bypassed, and you need to have that foundational security in the way you develop your applications. [00:13:48] Lindsey Dinneen: Yeah. So, you've had a really interesting career so far, and I'm sure you've seen a lot of things over the years. What are some moments that really stand out to you, especially with your medtech clients, as, as hitting home that, "Wow, I am in the right place at the right time, making an impact." [00:14:09] Katie Bochnowski: I think it's hard because it's not like there's one single moment. Because what you want to avoid in this industry is a breach, is something like this "oh my gosh," this big negative moment. And so honestly, it's seeing the organizations we work with, not having that happen. When you do see a breach that might be mobile-specific, I immediately jump in and see, "Okay, what happened? How did they exploit this? What was the actual vulnerability that led to this?" We check for that, and we help our customers test for that and knowing, "Okay, whew. They're covered." And we see that kind of stuff all the time. So I don't have, necessarily, a big moment, but I do have those moments along the way where it's like, you see something in the news, and you are not surprised by the way that was exploited. It's something that is foundational to mobile app security, and you know your customers are protected. [00:15:09] Lindsey Dinneen: Yeah. Well, that's a really good reminder in general because sometimes you get those big, crazy, sort of in-your-face moments that are going, "Yes, okay, I know why I'm here." But then, those don't happen all that much, usually. So having those little encouragements along the way of, "No, you're on the right path, you're doing the right things is incredibly... [00:15:30] Katie Bochnowski: It's funny; it actually reminds me of sometimes we'll work with customers and they'll use our products or services--and, they'll be upset because we haven't found anything in a certain amount of time. Seriously. And they're like, "You must not be testing enough" or " You haven't found anything high risk in six months." Sometimes, we have to remind them that's good. "Green is good," is what we always say. "Green is good." And, of course you want to check and make sure you're doing everything, in depth as possible. But, if you do a full two-week pen test and nothing big is found, that's good. You're doing a great job. So, take the win. Green is good. [00:16:07] Lindsey Dinneen: Green is good. I love it. Words to live by. You have had a really interesting trajectory even through NowSecure, but throughout your career and you've stepped into different kinds of leadership roles. I'm wondering how has that evolution been for you as a leader? What are some of your key takeaways that you've discovered work really well, and maybe some lessons learned? [00:16:29] Katie Bochnowski: Yeah, so I was not the person coming out of college that said, "I want to get my MBA, I want to be a CEO, I want to be, you know, high up in an organization." I just knew I liked computer technology, I liked tinkering--that kind of stuff. So I wanted to do things that were interesting. Via forensics, and now, NowSecure really was amazing for me because I got to do all of that. I got to grow with the company. I was really the first employee with the co-founder here, and as the company grew, I naturally started developing the managerial and the leadership roles as we hired more people and got more clients. So for me, I learned on the job, along the way, and when I think about it, I see people that are very ambitious to be a manager and, that's okay too. The best leaders that I've seen have been leaders that have naturally and organically developed a mutual respect, trust, and collaboration with their teams, seeing them as partners and peers and not someone to delegate things to in an authoritative way. And that's not just necessarily from a managerial perspective, because I see individual contributors, on my team for example, that exhibit amazing leadership skills, developing those relationships with other departments. And when you do that, you get-- I don't mean this in the way it's gonna sound, but you get people to do things for you because they want to, because they want to support you. And so that's what I always like to focus on is, just building those relationships, having empathy for other people. And, of course there's delegation that comes with that, but when you do that, then they want to do that for you or for the organization because you've, you've built that foundation. [00:18:20] Lindsey Dinneen: Yes. That's great advice. I really appreciate that. There were several things in there that, stood out to me. One of them was your comment about even individual contributors can be leaders, so even if you are not technically in a managerial role, or you don't have anyone working underneath you at the moment, doesn't mean you can't develop those skill sets and lead yourself and lead your own direction. So I think that's a really important note. And, something to give a little bit of perhaps inspiration, too. So if you want to be in that leadership role at some point, but you're not there yet, doesn't mean you can't build the skills along the way. [00:18:54] Katie Bochnowski: Yeah, absolutely. And I think about, I, I have heard people in the past say, "Oh, I can't go ask them to do something. I don't have the authority to do that." I hear that a lot. " I'm not their manager. I can't tell them to do that." And then there's people that don't even think that way, and just build that relationship and get others to collaborate and work with them. Those are the natural leaders that managers are going to see and want to promote to be the next manager. Right? So, if I'm gonna give another piece of advice, it would say, never say, "I don't have the authority, or I don't have the power to do that." Or "It's above my pay grade" is something that I'm like, "Oh, don't say that," because nothing is. You just need to learn to work with others to figure out how to do that. [00:19:41] Lindsey Dinneen: Yeah, and I think you're absolutely right about relationship building and collaboration being such a key to success in general. I mean, I think about all of the opportunities that are created and these sort of magical, what feel like magical, synergistic moments that happen, but they're not magical. They're because of intentionally cultivating these relationships. So yeah, I love that. And then helping people come up alongside you. So that's actually a concept I'd love to hear about your experience, either as a mentor or mentee, or anything like that that you've experienced that has really been inspirational to you. [00:20:18] Katie Bochnowski: Yeah. Well, I guess I have maybe two examples. I had someone that was working on my team many years ago and, again, we worked very closely as, I saw him as a partner and he got to a place basically at the organization where I would always tell him, "We could switch jobs, and you could do this and I could report to you and it doesn't matter," because I saw him grow that quickly. And he is now in another position that's probably double my pay and I don't know. But that's... you want to see that. And, some people might be threatened by that, but you shouldn't be, if you are doing the right thing because you want to see people grow into those roles. I don't know if this directly answers your question, but there is a leader who's a CEO of another organization who I have always looked up to, and I just see this is exactly how she leads. You know, everybody respects her. Everybody wants to support her and her mission at her company. Even when you're not working at her company like me, you just see the way she leads and the way she has built relationships throughout all of the employees in her organization. It's just something that I aspire to. [00:21:27] Lindsey Dinneen: Yeah, absolutely. And sometimes it's really helpful 'cause you'll get your share of... well I think most people at least have had the experience of getting their share of people in leadership roles that they would maybe not wish to emulate. So getting to be inspired by the people who are doing it correctly is is lovely. Yeah. Yeah. I love that. What is your number one, if you could boil it down, piece of advice for ordinary folks who are looking to up their own security game and just be more aware. [00:22:04] Katie Bochnowski: Be curious; don't wait for someone to show you or teach you how to do something. Part of what I oversee is managing a group of mobile app pen testers, and the best pen testers that I've seen are not the ones that have tons of experience or skill. It's actually, we've had two interns come straight out of school, come in and just dive into things without being asked, and just go figure it out and learn. And so be curious. Go try online exams and labs, even if you have no clue what you're doing, just try it, research and figure it out, and be curious. And I guess that's my biggest thing. [00:22:45] Lindsey Dinneen: I love it. Yeah. Curiosity gets you far in life. Yeah. I love that. Okay, so pivoting the conversation a little bit, just for fun. Imagine that you were to be offered a million dollars to teach a masterclass on anything you want. It doesn't have to be in your industry, but it could be. What would you choose to teach? [00:23:07] Katie Bochnowski: Okay, this might take a nerdy turn. [00:23:11] Lindsey Dinneen: Excellent. [00:23:12] Katie Bochnowski: And I would need a lot of education or somebody else who's an expert in this to actually teach the class. But, I've personally gotten really interested the last couple years into brain health, neuroplasticity, managing stress, and the importance of it. And, this is from a personal situation that I went through and not really understanding how just everyday, little stressors--I never saw myself as a highly stressed person. I was actually quite the opposite--but, when you internalize a lot of, just like I said, everyday stressors, doesn't have to be anything big-- arguing with my daughter every morning to get dressed before school has an impact on your body and your brain health. And it started having physical symptoms in me that got scary, right? I don't need to dive into that, but from that, it helped me in meeting with a bunch of health experts and learning that what an impact your brain health really has on you. So if I could go back and teach some of the exercises that I was given--super simple things like these little games on your app that just help work different areas of your brain that you don't normally work. When you get into a routine at work, and every morning you wake up, send your kid to school, sit down at your desk, do the same meetings, emails, you have the same routine every day--you don't have, just a change in your routine, or try new hobbies, things like that, then your brain doesn't grow and, and that affects your health, and your mood, and all of that. I've just learned so much about that, and I remember getting to a point where I was like, "Why isn't this a class, a required class, in high school, college, and beyond. It should be part of onboarding at every job. So I guess that's my answer. I don't think I'm quite qualified to teach it, but I'd love to attend it. [00:25:14] Lindsey Dinneen: There you go. You can facilitate it. How about that? [00:25:16] Katie Bochnowski: Yeah. [00:25:17] Lindsey Dinneen: Excellent. Excellent. Yeah, and how do you wish to be remembered after you leave this world? [00:25:24] Katie Bochnowski: Oh, this is the hard one for me. I think it's probably a cliche answer, but just, you know, caring for others, doing things for others, being kind-- just being a good person... [00:25:38] Lindsey Dinneen: Yeah. [00:25:38] Katie Bochnowski: ...is really all I want. [00:25:40] Lindsey Dinneen: Yeah. Very nice. And then final question. What is one thing that makes you smile every time you see or think about it? [00:25:50] Katie Bochnowski: Oh, this is also gonna be probably a common answer--my daughter, my daughter, who is six, going on 16, very much a teenager, but I remember a friend of mine telling me 'cause I remember asking her, when your child grows up, isn't it so sad that, oh, they're no longer a baby, they're no longer one, like to see them grow up. And she said, "Well, maybe a little bit. Each stage is something so new that you're so proud of, of what they've developed and grown that you don't even really think about that." Oh, and it's so true. It's just seeing her read and seeing her-- she's going to be a future leader. I guarantee it. [00:26:27] Lindsey Dinneen: Yay! [00:26:28] Katie Bochnowski: Just the way I've seen her, and so just seeing that, that pride overcomes any kind of, oh, I miss that one. But, of course, I still miss her when she was a baby. But, yeah, so that makes me smile. That and yoga! [00:26:42] Lindsey Dinneen: Yes. Yoga is so wonderful. I mean. Yeah. And speaking of ways to help de-stress, calm down a bit. Yeah. [00:26:51] Katie Bochnowski: It has helped me dramatically, for sure. So... [00:26:53] Lindsey Dinneen: Excellent. Excellent. Well, it has been a true pleasure and honor to have you here today, Katie. So thank you so much for spending a little bit of time, and we are so honored to be making a donation on your behalf as a thank you for your time today to Save the Children, which works to end the cycle of poverty by ensuring communities have the resources to provide children with a healthy, educational, and safe environment. So thank you so much for choosing that charity to support, and also thank you for continuing to work to change lives for a better world. We're grateful, and I wish you the most amazing continued success. [00:27:33] Katie Bochnowski: Thank you for having me. This was awesome. I appreciate it. [00:27:37] Lindsey Dinneen: Awesome. And yeah. Thank you also to our listeners for tuning in, and if you're feeling as inspired as I am right now, I'd love it if you shared an episode with a colleague or two, and we'll catch you next time. [00:27:52] Dan Purvis: The Leading Difference is brought to you by Velentium Medical. Velentium Medical is a full service CDMO, serving medtech clients worldwide to securely design, manufacture, and test class two and class three medical devices. Velentium Medical's four units include research and development-- pairing electronic and mechanical design, embedded firmware, mobile app development, and cloud systems with the human factor studies and systems engineering necessary to streamline medical device regulatory approval; contract manufacturing-- building medical products at the prototype, clinical, and commercial levels in the US, as well as in low cost regions in 1345 certified and FDA registered Class VII clean rooms; cybersecurity-- generating the 12 cybersecurity design artifacts required for FDA submission; and automated test systems, assuring that every device produced is exactly the same as the device that was approved. Visit VelentiumMedical.com to explore how we can work together to change lives for a better world.

Fruitfulujah
15 Mobile Security Tips You Need - A Deep Dive into the 3 Layers of Defense

Fruitfulujah

Play Episode Listen Later Nov 10, 2025 11:04


Are your mobile devices truly safe from hacking attempts?In today's episode, we dive into 15 essential strategies designed to help you protect your phone from modern cyber threats. From using a VPN on public Wi-Fi and enabling Multi-Factor Authentication (MFA), to staying alert against phishing links and limiting app permissions, we're breaking down the smart moves that keep your data secure.We'll also explore how simple habits like updating your operating system and using strong, unique passwords can drastically reduce your vulnerability to attacks.It's a practical, easy-to-follow guide to defending your digital life — one layer at a time.Tune in to The Fruitfulujah Podcast today, and learn how to make your phone a fortress against hackers.

Packet Pushers - Full Podcast Feed
PP082: Building a Workable Mobile Security Strategy In a World of Risky Apps

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Oct 14, 2025 62:01


Today we're bringing back one of our favorite guests — Akili Akridge. He's a former Baltimore cop who transitioned to building and leading mobile offense and defense teams for federal agencies and Fortune 100s. These days he's a straight-talking expert on all things mobile security. We're digging into mobile threats, why they keep CISOs up... Read more »

Packet Pushers - Fat Pipe
PP082: Building a Workable Mobile Security Strategy In a World of Risky Apps

Packet Pushers - Fat Pipe

Play Episode Listen Later Oct 14, 2025 62:01


Today we're bringing back one of our favorite guests — Akili Akridge. He's a former Baltimore cop who transitioned to building and leading mobile offense and defense teams for federal agencies and Fortune 100s. These days he's a straight-talking expert on all things mobile security. We're digging into mobile threats, why they keep CISOs up... Read more »

Privacy Please
S6, E257 - How Apple's New Chip Rewrites Mobile Security

Privacy Please

Play Episode Listen Later Oct 3, 2025 31:48 Transcription Available


Send us a textWe unpack how Apple's Memory Integrity Enforcement changes the rules of mobile security by rebuilding memory architecture, not just adding guardrails. We weigh who should upgrade now, what this means for Android, and why people remain the biggest risk.• memory corruption explained with apartment analogy• why NOP sleds and heap sprays fail under MIE• tags, type segregation, and synchronous checks at runtime• market-share vs design: Apple, Windows, Android trade-offs• Pegasus, zero-click exploits, and threat profiles• game hacking parallels: reading vs corrupting memory• should you upgrade: high-risk users vs everyday users• why architecture-level security beats bolt-on tools Support the show

Outgrow's Marketer of the Month
Snippet: Philipp Schulte, CEO of Giesecke+Devrient Mobile Security, Emphasizes the Importance of Efficiency and Waste Reduction in Combating Climate Change

Outgrow's Marketer of the Month

Play Episode Listen Later Sep 4, 2025 0:53


The Engineering Leadership Podcast
How Box Builds AI Agents, Redefines Technical Vision, and Balances Speed with Security w/ Ben Kus #230

The Engineering Leadership Podcast

Play Episode Listen Later Aug 26, 2025 46:14


"If we were building Box today, what would we do?” Ben Kus (CTO @ Box) deconstructs their playbook for enterprise AI innovation. We cover their journey to reimagine & reorient the company to a new technical vision, how they run a “multi-speed” org that balances startup agility and & enterprise-grade stability, and their “platform first” approach to build AI features. Ben also explains why security/compliance was foundational from "day negative one" in their AI strategy, the evolution of agentic AI, determining the right guardrails for AI agents & the future of multi-agent systems, enterprise trends & more. ABOUT BEN KUSBen Kus is the Chief Technology Officer at Box, where he leads technology and AI strategy to help enterprises securely unlock insights from their unstructured data. Ben's career spans engineering, product leadership, and startup innovation—including co-founding Subspace (acquired by Box) and being an early employee at BigFix (acquired by IBM), where he later served as Chief Architect of Mobile Security. Ben holds a degree in Computer Science from UC Berkeley. ToolHive Unlocks the Full Value of MCP & Your AI AgentsSo you've invested in AI agents for code generation, but they're limited to experiments or even stuck on the shelf. To do real, valuable work, those AI agents need access to your data and systems.ToolHive helps you confidently connect the pieces by making it simple and secure for you to use the Model Context Protocol (MCP).ToolHive includes a pre-vetted registry of MCP servers, containerizes every MCP server for consistency and leans on built-in security to keep your secrets safe.Leaders trust ToolHive to put MCP into production and put their AI agents to work.ToolHive is open source, so get started for free at toolhive.dev Join us at ELC Annual 2025ELC Annual is the premier event for engineering leaders. This is our biggest event of the year: 1,000+ CTOs, VPs & Directors in San Francisco @ ELC Annual 2025 for two days of leadership breakthroughs, tactical peer learning & curated connections!

Jamf After Dark
Inside JNUC 2025: Sessions, Swag & the Party You Can't Miss

Jamf After Dark

Play Episode Listen Later Aug 21, 2025 36:17


Join co-hosts Josh Thornton and Kat Garbis along with members of the Jamf events team to discuss JNUC 2025. Jeff Ovik (Sr. Event Specialist) and Kelsey Dahl (Sr. Event Specialist) join the podcast to help discuss what listeners can expect at JNUC 2025. From hotel accommodations, things to do in Denver, Braindates, session topics, the Global Partner Summit, Level Up, and of course — the JNUC party, the team unpacks all the exciting things that will happen at JNUC.   Need help getting approval to go? The team discusses money saving strategies, JNUC value-adds, as well as the helpful “Convince Your Boss” letter.  Important links: Register for JNUC 2025 Grab cool JNUC 2025 Swag Store  

UBC News World
Maximizing Safety with Mobile Security Patrols: A Construction Site Essential

UBC News World

Play Episode Listen Later Jun 16, 2025 5:19


Construction site theft costs the industry up to $1 billion annually. Hub Security's mobile patrols offer cost-effective protection by creating visible deterrence, providing comprehensive coverage, and integrating with surveillance systems for maximum security effectiveness. Hub Security & Investigative Group City: Boston Address: 7 Whittier Pl Website: https://hubsecurityandinvestigativegroup.com/

Scrum Master Toolbox Podcast
AI and Cybersecurity - An Introduction to The Hidden Threats in Our Connected World | Dr. Eric Cole

Scrum Master Toolbox Podcast

Play Episode Listen Later Mar 29, 2025 37:46


BONUS: AI and Cybersecurity - An Introduction to The Hidden Threats in Our Connected World with Dr. Eric Cole In this BONUS episode, we explore the evolving landscape of cybersecurity in the age of artificial intelligence. Dr. Eric Cole, a renowned cybersecurity expert and author of Cyber Crisis: Protecting Your Business from Real Threats in the Virtual World, shares critical insights about how AI is transforming security strategies. From the privacy concerns of our always-connected devices to practical tips for protecting your business and personal information, this conversation offers essential knowledge for navigating our increasingly digital world. The Double-Edged Sword of AI in Cybersecurity "We are giving away our IP, our data, and our privacy. The data set is what gives value to AI." The rise of artificial intelligence presents both opportunities and serious risks in the cybersecurity landscape. Dr. Cole emphasizes that while many focus solely on AI's benefits, we often overlook the fact that we're surrendering vast amounts of our sensitive information, intellectual property, and private data to AI providers. This data becomes the foundation of AI's value and capabilities, creating a significant privacy concern that many organizations fail to properly address. As we embrace these new technologies, we must carefully consider what information we're willing to share and what safeguards should be in place. Modern Attack Vectors: The Human Element "Attacks today are mostly social engineering. We end up having to retrain people to not trust their email." Today's cybersecurity threats have evolved beyond traditional technical exploits to focus primarily on social engineering—manipulating people into compromising their own security. Dr. Cole explains that modern attackers increasingly target the human element, requiring organizations to fundamentally retrain employees to approach communications with healthy skepticism. Particularly concerning are mobile threats, as our phones constantly record audio and other personal data. Dr. Cole warns that "free" apps often come with a hidden price: your privacy and security. Understanding these attack vectors is essential for developing effective defense strategies in both personal and professional contexts. Cybersecurity as a Business Enabler "Security is not a barrier, not an obstacle. Cybersecurity is a business enabler." Dr. Cole challenges the common perception that security measures primarily restrict functionality and impede business operations. Instead, he reframes cybersecurity as a critical business enabler that should be integrated into strategic decision-making. Organizations need to make deliberate decisions about the tradeoffs between security and functionality, understanding that proper security measures protect business continuity and reputation. Dr. Cole particularly warns about supply chain attacks, which have become increasingly prevalent, and emphasizes that awareness is the foundation of any effective protection strategy. He recommends centralizing data for easier security management and advises that client devices should minimize storing sensitive data. Mobile Phones: The Ultimate Tracking Device "You don't go anywhere without your cell phone. Your cell phone is never more than a foot from you it's with you wherever you go... which means if somebody wants to track and monitor you they can." We often worry about theoretical tracking technologies while overlooking the sophisticated tracking device we voluntarily carry everywhere—our mobile phones. Dr. Cole points out the irony that people who would never accept being "chipped" for tracking purposes willingly keep their phones within arm's reach at all times. These devices record our locations, conversations, messages, and activities, creating a comprehensive digital trail of our lives. With access to someone's phone, anyone can trace their movements for months and access an alarming amount of personal information. This risk is compounded when we back up this data to cloud services, effectively giving third parties access to our most sensitive information. Understanding these vulnerabilities is the first step toward more mindful mobile security practices. Business Opportunities in the Security Space "We have too much information, too much data. How can we use that data effectively?" The cybersecurity landscape presents significant business opportunities, particularly in making sense of the overwhelming amount of security data organizations collect. Dr. Cole identifies data correlation and effective data utilization as key investment areas. Modern security systems generate vast quantities of logs and alerts, but transforming this raw information into actionable intelligence remains a challenge. Companies that can develop solutions to effectively analyze, correlate, and extract meaningful insights from security data will find substantial opportunities in the market, helping organizations strengthen their security posture while managing the complexity of modern threats. Essential Training for Security-Conscious Developers "Go for secure coding courses. This helps us understand how software can be exploited." For software developers looking to build more secure applications, Dr. Cole recommends focusing on penetration testing skills and secure coding practices. Understanding how software can be exploited from an attacker's perspective provides invaluable insights for designing more robust systems. By learning the methodologies and techniques used by malicious actors, developers can anticipate potential vulnerabilities and incorporate appropriate safeguards from the beginning of the development process. This proactive approach to security helps create applications that are inherently more resistant to attacks rather than requiring extensive security patches and updates after deployment. About Dr. Eric Cole Dr. Eric Cole is the author of "Cyber Crisis, Protecting Your Business from Real Threats in the Virtual World." He is a renowned cybersecurity expert with over 20 years of experience helping organizations identify vulnerabilities and build robust defense solutions against advanced threats. He has trained over 65,000 professionals worldwide through his best-selling cybersecurity courses and is dedicated to making cyberspace a safe place for all. You can link with Dr. Eric Cole on LinkedIn, or visit his company's website Secure-Anchor.com. 

Uncommon Sense with Ginny Robinson

Today, I'm sharing something deeply personal and serious—my stalker story. For over a year, Timothy C. (we can share his full name soon if need be) has been physically stalking me, and his digital harassment goes back even further. Law enforcement is now involved, but I wanted to update you all in case anything happens to me—so there's no question about who did it. This episode isn't just about my experience; it's also about the reality of stalking, the dangers of obsession, and the importance of taking threats seriously. Stay aware, stay safe, and let's talk about it all, shall we?—https://noblegoldinvestments.com

fear mental health law trauma crime revenge threats empowerment tracking red flags true crime cybersecurity selfhelp social justice self awareness obsessive compulsive disorder lawsuit domestic violence case study hacking law enforcement toxic relationships surveillance human trafficking gaslighting martial arts stalker criminal justice self defense stalking harassment public safety cybercrime identity theft intimidation community support missing person malware cyberbullying justice system blackmail defamation true crime podcasts personality disorders court cases encryption emotional resilience risk assessment taser emotional abuse crime scene extortion data protection media coverage social engineering narcissistic abuse private investigators trauma recovery personal freedom criminal justice reform emergency preparedness background checks situational awareness healing from trauma emergency response cyber threats mental resilience spyware peeping toms forensic science revenge porn criminal charges legal action restraining orders post traumatic stress security policies surveillance state whistleblowing home security data breaches federal laws psychological warfare it security digital literacy security cameras mental health resources doxxing security breach forensic psychology victim blaming personal boundaries pepper spray internet safety criminal defense digital footprint threat intelligence crime prevention self protection neighborhood watch police accountability personal safety witness protection public records digital security news coverage legal protection cyber defense emotional manipulation cyberstalking ethical hacking digital rights crisis hotline threat assessment online harassment public awareness security tips emotional distress internet privacy personal security mobile security protective services gps tracking identity fraud online fraud email security forensic investigations identity protection onlinepredators criminal behavior crime scene investigations local law enforcement victim support emotional recovery detective work behavioral analysis legal advocacy privacy settings criminal profiling digital evidence crime reporting criminal intent security awareness training aggressive behavior protective gear whistleblower protection home protection personal rights police reports victim advocacy personal defense relationship abuse private browsing technology safety cyber investigations
Audience 1st
Why Mobile Security is Dangerously Overlooked (And What To Do About It)

Audience 1st

Play Episode Listen Later Feb 28, 2025 34:33


What happens when you meet a cybersecurity founder over dinner and 12 hours later, they're on your podcast? You get one of the most brutally honest conversations about mobile security. In this episode, Rocky Cole, co-founder of iVerify, lays out why mobile security is dangerously behind—and why businesses are in denial about the scale of the threat. We dive into: The biggest myth in mobile security—why MDM (Mobile Device Management) is not a security tool and never was. Why enterprise security leaders are still ignoring mobile security (even when businesses are now prime targets). How attackers have outpaced traditional mobile security measures—and what needs to change. The operational bottlenecks holding CISOs back from fixing the problem—and how to work around them. Rocky shares raw insights from the frontlines of mobile security, including how his team uncovered new Pegasus infections, why BYOD security is broken, and what companies should be doing NOW. If you're still treating mobile devices differently than desktops, this episode will change your perspective—fast.

The Six Five with Patrick Moorhead and Daniel Newman
Samsung Launches Flagship Phone Positioned as “A True AI Companion” - Six Five On The Road at Galaxy Unpacked

The Six Five with Patrick Moorhead and Daniel Newman

Play Episode Listen Later Jan 27, 2025 17:04


Outgrow's Marketer of the Month
Snippet: Philipp Schulte, CEO of Giesecke+Devrient Mobile Security Concerns Reducing Waste for Real Value!

Outgrow's Marketer of the Month

Play Episode Listen Later Dec 5, 2024 0:44


He emphasizes the impact of reducing waste by just 5% in logistics and explains how simple changes, like reducing container usage, can bring significant cost savings and add real value to the business. Watch the full episode here

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Connect to John Gilroy on LinkedIn   https://www.linkedin.com/in/john-gilroy/ Want to listen to other episodes? www.Federaltechpodcast.com Using a phone to read or communicate has become so standard that church people are expected to read scripture with their phones. Using mobile devices to transmit secure information. Traditionally, secure communication was based on desktop systems; today, we need to pivot and learn how to apply mobile device management to leverage the cloud to provide safe and secure communications through mobile devices. Our guest today, Harold Smith, has spent the last twenty years gaining a deep understanding of secure communications and applying that understanding to developing a trusted mobile development platform. During the interview, you will be bombarded with acronyms like NIAC (National Information Assurance Partnership), MATTER (Mobile Apps to the Tactical Edge Ready), and many more. As a bonus, Harold provides a brilliant sidebar on another acronym: SBIR (Small Business Innovation Research). If you are trying to break into the federal market, this precis is just what you need. The takeaway is that Monkton provides a platform for developers to deliver safe and secure code to people in our mobile world. This can mean a warfighter, a clinician, or even an emergency responder from FEMA.  

Business of Tech
Mobile Security, Generational Attitudes, AI Impact, & Data Governance Trends w/ Denis O'Shea

Business of Tech

Play Episode Listen Later Nov 28, 2024 21:43


Host Dave Sobel welcomes Dennis O'Shea, CEO of Mobile Mentor, a managed services provider (MSP) with a unique background in mobile technology. Dennis shares insights from his extensive experience in the industry, particularly focusing on the generational differences in attitudes toward data security and privacy. He highlights how younger generations, especially Generation Z, have a more relaxed approach to sharing personal information, influenced by their social media habits, contrasting sharply with the more privacy-conscious attitudes of older generations.The conversation shifts to the evolving landscape of device usage in the workplace, where mobile devices are becoming increasingly prevalent. Dennis recounts his journey from working at Nokia to founding Mobile Mentor, where he initially focused on helping businesses adopt mobile technology. As Microsoft introduced Microsoft 365, Dennis recognized the need for comprehensive security across various device platforms, leading Mobile Mentor to expand its services to include endpoint security for a diverse range of devices, including smartphones, tablets, and laptops.Dennis also discusses the impact of regional regulations on data security practices, particularly comparing the stringent privacy laws in Australia and New Zealand to the more relaxed regulatory environment in the United States. He notes that organizations in regulated markets tend to take security more seriously, often having dedicated budgets and personnel for security, while those in unregulated markets may adopt a more casual approach. This disparity highlights the importance of understanding local regulations and their influence on organizational security practices.As the episode concludes, Dennis emphasizes the critical need for organizations to establish robust data governance frameworks, especially in light of the increasing integration of AI technologies. He warns that many organizations are unprepared for the challenges posed by AI, particularly regarding data classification and protection. By automating basic IT operations, organizations can free up resources to focus on data governance, ultimately positioning themselves to leverage AI effectively in the future. All our Sponsors: https://businessof.tech/sponsors/ Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/ Support the show on Patreon: https://patreon.com/mspradio/ Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com Follow us on:LinkedIn: https://www.linkedin.com/company/28908079/YouTube: https://youtube.com/mspradio/Facebook: https://www.facebook.com/mspradionews/Instagram: https://www.instagram.com/mspradio/TikTok: https://www.tiktok.com/@businessoftechBluesky: https://bsky.app/profile/businessoftech.bsky.social

TechBurst Asia Podcast
057: SAMSUNG'S GALAXY AI: Exploring Innovation, Security and Real-World Applications for AI on the Smartphone

TechBurst Asia Podcast

Play Episode Listen Later Nov 28, 2024 42:01


In this episode of Tech Burst Talks, I sit down with Ian Chong from Samsung Electronics to talk about his work on the mobile B2B team and the cutting-edge advancements Samsung is making, particularly in AI technology for smartphones. We dive into the new Galaxy AI capabilities, including features like Circle to Search, Live Translate, and Transcript Assist. Ian shares why on-device AI is critical for ensuring both security and speed and discusses Samsung's collaborations with major tech players. We also explore how AI is being implemented in industries like law enforcement and finance. On a lighter note, Ian opens up about his passion for coffee and his quirky sock collection. To wrap up, we talk about the future of AI and its transformative potential across different sectors. Show Notes: 00:45 Welcome to Tech Burst Talks 01:00 Introducing Ian Chong and His Role at Samsung 01:35 AI Innovations in Samsung Smartphones 02:13 Galaxy AI Features in Action 04:25 Live Translate and Business Features 08:00 Samsung's Security Measures 10:49 Rugged Devices for Various Industries 13:27 Customer Insights on AI 16:58 Samsung's Open Ecosystem and Partnerships 21:45 Enhancing Experiences with AI 22:21 Addressing AI Skepticism 24:25 The Power of Hyper-Connected Devices 25:38 Future of AI and Gen AI 26:44 AI in Retail and B2B Applications 29:36 Transformative AI in Healthcare 31:20 Personal Addictions: Coffee and Crazy Socks 36:18 Reflections and Future Aspirations 38:29 Final Thoughts and Farewell  

Outgrow's Marketer of the Month
Snippet: Philipp Schulte, CEO of Giesecke+Devrient Mobile Security, Discusses Shaping Industry Standards!

Outgrow's Marketer of the Month

Play Episode Listen Later Nov 13, 2024 0:35


He discusses the dynamic nature of the market and how his company plays a pivotal role in setting industry standards. Their mission? Ensuring top-tier security for customers in a constantly evolving landscape. Watch the full episode here

The Tech Blog Writer Podcast
3072: A CISO's Guide to Mobile Security: Key Strategies from Jamf

The Tech Blog Writer Podcast

Play Episode Listen Later Oct 30, 2024 24:28


In this episode, we tackle a fresh perspective on a common cybersecurity question: What keeps a CISO awake at night? According to Michael Covington, VP of Strategy at Jamf, the real issue isn't about external threats but rather a lack of robust security processes, especially in mobile device management. Covington shares insights on how a well-thought-out strategy can let CISOs rest easy, with their minds at ease knowing that key areas, from cyber hygiene to compliance, are under control. Our conversation dives into three primary areas that Covington believes are essential for keeping mobile device vulnerabilities at bay and ensuring secure integration within enterprise ecosystems. First, he highlights the often-overlooked importance of cyber hygiene. He notes that nearly 40% of mobile users operate devices with known vulnerabilities, a staggering figure that reveals the challenges organizations face in keeping devices up-to-date and correctly configured. Covington argues that regular updates, vigilant configuration management, and consistent patching practices are not just best practices—they're fundamental in building a secure foundation. Second, we explore the complexities of compliance, particularly when it comes to mobile devices. Covington points out that many organizations struggle to balance security regulations with the diverse landscape of personal and work devices. He suggests that the right tools can streamline compliance, ensuring that mobile devices align with broader corporate standards without creating unnecessary friction. Lastly, Covington addresses the evolving nature of BYOD (Bring Your Own Device) policies and the intricacies of managing shared devices. Despite their long-standing presence, these device policies often present challenges, with many organizations lacking effective management strategies. Covington emphasizes the need for layered solutions that integrate into existing security frameworks without overwhelming IT teams or sacrificing the user experience. Join us as we unpack Jamf's approach to these challenges and discuss the future of mobile security in industries from healthcare to aviation. How can organizations prepare for the next wave of AI-driven data on mobile devices? And what steps can they take now to ensure seamless, secure access for users? Listen in and share your thoughts on the balance between security, compliance, and user enablement in today's mobile-driven world.

ai strategy guide covington ciso key strategies cisos mobile security jamf security key byod bring your own device michael covington
Outgrow's Marketer of the Month
Snippet: Philipp Schulte, CEO of Giesecke+Devrient Mobile Security Talks About Securing Connectivity in Critical Infrastructures!

Outgrow's Marketer of the Month

Play Episode Listen Later Oct 25, 2024 0:47


He delves into the challenges of working with critical infrastructures and IoT. He emphasizes ensuring secure connectivity and reliable data transmission between devices to safeguard essential systems. Watch the full episode here

Swift Academy The Podcast
Deep Dive into iOS Mobile Security with Dave Poirier

Swift Academy The Podcast

Play Episode Listen Later Oct 14, 2024 72:19


Join us as we dive into the world of iOS mobile security with Dave Poirier, a senior iOS developer and security expert. Dave shares his extensive knowledge on topics like iOS security frameworks, common security pitfalls, handling sensitive data, incident response, and the ever-evolving mobile threat landscape. Drawing from his experience and resources such as OWASP and NIST, Dave provides actionable advice for developers looking to secure their apps.

The Security Podcast of Silicon Valley
Haseeb Awan, Founder and CEO of Efani, Revolutionizing Mobile Security for the Digital Age

The Security Podcast of Silicon Valley

Play Episode Listen Later Oct 1, 2024 31:39


In this episode of The Security Podcast of Silicon Valley, host Jon McLachlan sits down with Haseeb Awan, the visionary Founder and CEO of Efani Secure Mobile. Join us as Haseeb shares his inspiring journey from co-founding BitAccess to creating a bulletproof mobile service designed to protect against the rising threat of SIM swapping and digital identity theft. Haseeb opens up about his personal experiences with security breaches, the challenges he faced, and the innovative solutions Efani offers to ensure top-notch security for its users. Tune in for an engaging conversation filled with insights, resilience, and a commitment to making the digital world a safer place.

Outgrow's Marketer of the Month
Snippet: Philipp Schulte, CEO of Giesecke+Devrient Mobile Security, Examines investing in secure connections!

Outgrow's Marketer of the Month

Play Episode Listen Later Sep 24, 2024 0:57


He discusses the strategic investment in Mobile Virtual Network Operators (MVNOs) at the Total Telecom Congress. He emphasizes how this move can secure any connection to any network. Watch the full episode here

Breaking Into Cybersecurity
Breaking into Cybersecurity: The Current Mobile Security Landscape

Breaking Into Cybersecurity

Play Episode Listen Later Sep 20, 2024 36:54


In this episode, we dive into the rapidly evolving mobile security landscape, exploring how the rise in SIM swap attacks and data breaches shapes the market. We discuss the future of secure mobile services, highlighting key trends and challenges consumers must know. We also debunk common misconceptions about mobile security, particularly around SIM swaps, and offer practical advice on how individuals can protect themselves. Finally, we examine the critical features and practices that make a mobile service truly secure and why these still need to be widely adopted across the industry. Don't miss this insightful discussion on staying safe in the mobile world.Find more information at https://efani.com/bicshttps://www.efani.com/numberscanMark Kreitzman is a seasoned cybersecurity expert with over twenty-five years of experience building cybersecurity companies. He has deep insights into the evolving threats to digital assets, with a particular focus on mobile security and data privacy. Mark's extensive background in cybersecurity makes him an invaluable resource for discussing current and emerging threats in our increasingly mobile and digitized world, as well as how to mitigate personal and business risks related to mobile communications.Sponsored by CPF Coaching LLC - http://cpf-coaching.comThe Breaking into Cybersecurity: It's a conversation about what they did before, why they pivoted into cyber, what process they went through to Break into Cybersecurity, how they keep up, and advice/tips/tricks along the way.The Breaking into Cybersecurity Leadership Series is an additional series focused on cybersecurity leadership and hearing directly from different leaders in cybersecurity (high and low) on what it takes to be a successful leader. We focus on the skills and competencies associated with cybersecurity leadership and tips/tricks/advice from cybersecurity leaders.Check out our books: Develop Your Cybersecurity Career Path: How to Break into Cybersecurity at Any Level https://amzn.to/3443AUIHack the Cybersecurity Interview: A complete interview preparation guide for jumpstarting your cybersecurity career

Feds At The Edge by FedInsider
Ep. 166 Mobile Security - a Requirement for National Security

Feds At The Edge by FedInsider

Play Episode Listen Later Sep 11, 2024 57:16


rev 1 COVID has made the workforce remote; phones have enabled that transition. Unfortunately, one result of this transformation is your phone is now part of the attack surface. After you listen to this interview, you will never look at your phone again in the same way. You will learn that your phone is packed with vulnerabilities. You can have apps on your phone that are sending data back to China without you doing a thing. This may give an individual a security concern, but what if you work for the federal government? It is not just the phone. Malicious actors are taking sites by cybersecurity companies and copying them down to the pixel. From there, a harried phone user sees a site that appears to be valid and exchanges identity information. Today we have a couple of experts on securing mobile devices. They review ways to protect applications, maintain operating systems, and suggest ways to train people to resist web-based attacks.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 173: Practice CISSP Questions - Media Protection, Encryption, and Mobile Security for the CISSP (Domain 7.5)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Sep 5, 2024 18:52 Transcription Available


Send us a textUnlock the secrets to safeguarding your organization's most sensitive data and enhance your cybersecurity acumen. Join us on the CISSP Cyber Training Podcast as I, Sean Gerber, break down the critical importance of managing secrets within popular collaboration tools like Slack, Jira, and Confluence. Discover practical methods such as real-time monitoring and swift remediation to secure API keys and encryption tokens. Learn how fostering a culture of security awareness through educational initiatives can significantly mitigate risks and enhance overall security posture.Next, we turn our attention to data sanitization and media destruction—essential processes for maintaining confidentiality and regulatory compliance. I'll guide you through various methods of data sanitization and media destruction, from degaussing to shredding and pulping, while also demystifying the concepts of MTBF and MTTF. We'll delve into the challenges of data classification and the importance of proper data labeling. Whether you're prepping for the CISSP exam or simply looking to deepen your cybersecurity knowledge, this episode is rich with actionable insights and expert guidance. Tune in and elevate your cybersecurity skills to the next level!Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 172: Exploring Media Protection, Encryption, and Mobile Security for the CISSP (Domain 7.5)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Sep 2, 2024 30:31 Transcription Available


Send us a textWhat if AI could be your company's best asset—and its biggest risk? Join me, Sean Gerber, on this enlightening episode of the CISSP Cyber Training Podcast, where we journey through the essentials of cybersecurity with a particular focus on media protection techniques from Domain 7.5 of the CISSP ISC² training manual. We'll also navigate the secure-by-design principles crucial in the age of artificial intelligence. With AI transforming large enterprises, I'll share eye-opening statistics on its adoption and delve into the risks it brings, such as cloud misconfigurations leading to severe breaches. Plus, we'll discuss the alarming rise of deepfake scams with a real-world example that shook a UK energy firm to its core.Ever wondered how to choose the best data encryption method for your needs? This episode has got you covered! We'll discuss various encryption techniques like AES, RSA, and ECC, and why it's essential to select the right one based on media type. Trust me, understanding key management and rotation is vital for maintaining data integrity, especially when dealing with cloud storage and third-party providers. I'll also walk you through secure erasure methods, from the DOD 5220.22-M standard to physical destruction techniques like shredding and degaussing, ensuring your data truly becomes irretrievable.Lastly, don't miss our deep dive into mobile device protection. I'll highlight the critical software and physical security measures necessary to defend your devices against threats, emphasizing the importance of regular updates and robust antivirus solutions. We'll explore strategies for data encryption, backup, and recovery, and clarify the differences between MTBF and MTTF and their relevance to your systems. Wrapping up with the environmental factors affecting device usage and data management, this episode is packed with actionable insights to elevate your cybersecurity game. Tune in now to arm yourself with the knowledge necessary to protect your digital world!Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!

Outgrow's Marketer of the Month
Snippet: Philipp Schulte, CEO of Giesecke+Devrient Mobile Security Emphasizes Combating Climate Change.

Outgrow's Marketer of the Month

Play Episode Listen Later Aug 22, 2024 0:53


Philipp highlights the importance of efficiency and waste reduction in combating climate change. He shares how his firm is heavily invested in E-sim technology, which boasts a 42% carbon reduction advantage compared to traditional plastic SIM cards. Watch the full episode here

Outgrow's Marketer of the Month
Snippet: Philipp Schulte, CEO of Giesecke+Devrient Mobile Security, Discusses his Work in Critical Infrastructures.

Outgrow's Marketer of the Month

Play Episode Listen Later Jul 18, 2024 0:49


Schulte highlights the importance of providing security technology that ensures all customers can enjoy its benefits. He explains IoT as connecting everything that runs on power, showcasing the future of interconnected devices. Watch the full episode here

ITSPmagazine | Technology. Cybersecurity. Society
From Theory to Process to Practice: Cracking Mobile and IoT Security and Vulnerability Management | An OWASP AppSec Global Lisbon 2024 Conversation with Abraham Aranguren | On Location Coverage with Sean Martin and Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 28, 2024 33:08


Guest: Abraham Aranguren, Managing Director at 7ASecurity [@7aSecurity]On LinkedIn | https://www.linkedin.com/in/abrahamaranguren/____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this On Location episode recorded in Lisbon at the OWASP AppSec Global event, Sean Martin engages in a comprehensive discussion with Abraham Aranguren, a cybersecurity trainer skilled at hacking IoT, iOS, and Android devices. The conversation delves into the intricacies of mobile application security, touching on both the technical and procedural aspects that organizations must consider to build and maintain secure apps.Abraham Aranguren, known for his expertise in cybersecurity training, shares compelling insights into identifying IoT vulnerabilities without physically having the device. By reverse engineering applications, one can uncover potential security flaws and understand how apps communicate with their IoT counterparts. For instance, Aranguren describes exercises where students analyze mobile apps to reveal hardcoded passwords and unsecured Wi-Fi connections used to manage devices like drones.A significant portion of the discussion revolves around real-world examples of security lapses in mobile applications. Aranguren details an incident involving a Chinese government app that harvests personal data from users' phones, highlighting the serious privacy implications of such vulnerabilities. Another poignant example is Hong Kong's COVID-19 contact-tracing app, which stored sensitive user information insecurely, revealing how even high-budget applications can suffer from critical security flaws if not properly tested.Sean Martin, drawing from his background in software quality assurance, emphasizes the importance of establishing clear, repeatable processes and workflows to ensure security measures are consistently applied throughout the development and deployment phases. He and Aranguren agree that while developers need to be educated in secure coding practices, organizations must also implement robust processes, including code reviews, automated tools for static analysis, and third-party audits to identify and rectify potential vulnerabilities.Aranguren stresses the value of pentests, noting that organizations often show significant improvement over multiple tests. He shares experiences of clients who, after several engagements, greatly reduced the number of exploitable vulnerabilities. Regular, comprehensive testing, combined with a proactive approach to fixing identified issues, helps create a robust security posture, ultimately making applications harder to exploit and dissuading potential attackers.For businesses developing apps, this episode underscores the necessity of integrating security from the ground up, continuously educating developers, enforcing centralized security controls, and utilizing pentests as a tool for both validation and education. The ultimate goal is to make applications resilient enough to deter attackers, ensuring both the business and its users are protected.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________Follow our OWASP AppSec Global Lisbon 2024 coverage: https://www.itspmagazine.com/owasp-global-2024-lisbon-application-security-event-coverage-in-portugalOn YouTube:

Redefining CyberSecurity
From Theory to Process to Practice: Cracking Mobile and IoT Security and Vulnerability Management | An OWASP AppSec Global Lisbon 2024 Conversation with Abraham Aranguren | On Location Coverage with Sean Martin and Marco Ciappelli

Redefining CyberSecurity

Play Episode Listen Later Jun 28, 2024 33:08


Guest: Abraham Aranguren, Managing Director at 7ASecurity [@7aSecurity]On LinkedIn | https://www.linkedin.com/in/abrahamaranguren/____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this On Location episode recorded in Lisbon at the OWASP AppSec Global event, Sean Martin engages in a comprehensive discussion with Abraham Aranguren, a cybersecurity trainer skilled at hacking IoT, iOS, and Android devices. The conversation delves into the intricacies of mobile application security, touching on both the technical and procedural aspects that organizations must consider to build and maintain secure apps.Abraham Aranguren, known for his expertise in cybersecurity training, shares compelling insights into identifying IoT vulnerabilities without physically having the device. By reverse engineering applications, one can uncover potential security flaws and understand how apps communicate with their IoT counterparts. For instance, Aranguren describes exercises where students analyze mobile apps to reveal hardcoded passwords and unsecured Wi-Fi connections used to manage devices like drones.A significant portion of the discussion revolves around real-world examples of security lapses in mobile applications. Aranguren details an incident involving a Chinese government app that harvests personal data from users' phones, highlighting the serious privacy implications of such vulnerabilities. Another poignant example is Hong Kong's COVID-19 contact-tracing app, which stored sensitive user information insecurely, revealing how even high-budget applications can suffer from critical security flaws if not properly tested.Sean Martin, drawing from his background in software quality assurance, emphasizes the importance of establishing clear, repeatable processes and workflows to ensure security measures are consistently applied throughout the development and deployment phases. He and Aranguren agree that while developers need to be educated in secure coding practices, organizations must also implement robust processes, including code reviews, automated tools for static analysis, and third-party audits to identify and rectify potential vulnerabilities.Aranguren stresses the value of pentests, noting that organizations often show significant improvement over multiple tests. He shares experiences of clients who, after several engagements, greatly reduced the number of exploitable vulnerabilities. Regular, comprehensive testing, combined with a proactive approach to fixing identified issues, helps create a robust security posture, ultimately making applications harder to exploit and dissuading potential attackers.For businesses developing apps, this episode underscores the necessity of integrating security from the ground up, continuously educating developers, enforcing centralized security controls, and utilizing pentests as a tool for both validation and education. The ultimate goal is to make applications resilient enough to deter attackers, ensuring both the business and its users are protected.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________Follow our OWASP AppSec Global Lisbon 2024 coverage: https://www.itspmagazine.com/owasp-global-2024-lisbon-application-security-event-coverage-in-portugalOn YouTube:

The Tech Blog Writer Podcast
2936: Revolutionizing Mobile Security with Metalenz

The Tech Blog Writer Podcast

Play Episode Listen Later Jun 19, 2024 33:49


Today on Tech Talks Daily, we're diving into the world of cutting-edge technology with Rob Devlin, co-founder and CEO of Metalenz. This pioneering company, spun out of Harvard, is reshaping how we think about optics in technology with their groundbreaking meta-surface optics. Metalenz has introduced a revolutionary flat lens technology that manipulates light much like traditional curved lenses but on a nanostructured surface. This innovation allows for multi-lens stacks to be collapsed into a single flat optic at a semiconductor scale, drastically reducing size and cost while enhancing the capabilities of sensing devices. Rob discusses Metalenz's first-generation technology, which is already enhancing tens of millions of devices with advanced 3D sensing for mobile augmented reality and photography. Looking ahead, Metalenz is setting ambitious goals with their next-gen "PolarID," aimed at providing secure facial recognition for Android users. This new technology, developed in partnership with Samsung, promises to deliver secure face unlock solutions that are not only more compact but also three times cheaper than current technologies used by competitors like Apple. The impact of Metalenz's innovations extends beyond just cost and size reduction. By enabling polarization imaging, Metalenz is poised to bring this sophisticated security feature to over a billion Android users worldwide who seek Apple-level security without the hefty price tag. This strategic move, enhanced by their collaboration with Samsung to co-optimize optics and image sensors, is set to redefine the standards of mobile security and performance. Furthermore, Rob shares insights into the potential future applications of Metalenz technology, including biomarker detection and health monitoring through polarization imaging. These advancements are expected to enrich machine vision and autonomous systems with richer data inputs, paving the way for significant breakthroughs in various industries. Join us as Rob Devlin explores the journey of Metalenz from its academic roots to becoming a key player in global technology markets, aiming to make enhanced security accessible to millions more consumers without compromising on cost or functionality. What are your thoughts on the integration of such advanced technologies in everyday devices? Let's discuss how innovations like Metalenz are setting new paradigms in the tech world.

Outgrow's Marketer of the Month
EPISODE 188- From Banknotes to Bytes: G+D Mobile Security's CEO Philipp Schulte's Blueprint for the IoT Era Innovation and Marketing

Outgrow's Marketer of the Month

Play Episode Listen Later May 9, 2024 19:06


Philipp Schulte, CEO of Giesecke+Devrient Mobile Security, pioneers connectivity and IoT innovation. His corporate strategy expertise, coupled with CFO experience, drives his passion for innovation. With a background in management consulting and academia, he brings a strategic vision to the forefront. On The Menu: 1. IoT provides secure technology for critical infrastructures, ensuring reliable data transmission and security benefits. 2. Investments in transportation, logistics, and tracking solutions optimizing supply chains, and enhancing environmental control. 3. Efficiency and waste reduction, such as eliminating plastic SIM cards, lead to CO2 footprint advantages. 4. Reducing complexity and ensuring interoperability is crucial for IoT's full growth potential. 5. Importance of balancing regulatory changes like the AI Act and Cyber Resilience Act to foster a healthy IoT ecosystem. 6. Security is built into all layers, including chips, operating systems, encryption technology, and data management. Click here for a free trial: https://bit.ly/495qC9U Follow us on social media to hear from us more - Facebook- https://bit.ly/3ZYLiew Instagram- https://bit.ly/3Usdrtf Linkedin- https://bit.ly/43pdmdU Twitter- https://bit.ly/43qPvKX Pinterest- https://bit.ly/3KOOa9u Happy creating! #PhilippSchulte #G+D #MarketerOfTheMonth #IoT #Innovation #Outgrow #Podcastoftheday #MarketingPodcast #Marketing

State of Identity
Mobile Identity: Charting the Future of Digital Security

State of Identity

Play Episode Listen Later Apr 9, 2024 35:01


In this episode of State of Identity, host Cameron D'Ambrosi welcomes Uku Tomikas, CEO of Messente, for an in-depth exploration of the digital identity landscape and the role of mobile communications within it. Discover what's shifting in the digital identity as mobile devices become central to our digital selves as literal authenticators and symbolic representations of our identity. Learn how Messente navigates the changing landscape of digital identity, combating fraud and enhancing security with innovative mobile technology while uncovering key takeaways on the future of authentication, the impact of SMS OTPs, and the revolutionary potential of subscriber data in digital identity verification.  

The Daily Decrypt - Cyber News and Discussions
Ransomware as a Service Recruiting, Loop DoS Attack, White House Water Warning, and Who’s Been Popped with HGF – CyberSecurity News

The Daily Decrypt - Cyber News and Discussions

Play Episode Listen Later Mar 21, 2024


HGF Delivers the weekly breaches in “Whose Been Popped?” Oracle's macOS 14.4 Java hiccup, the ever-adapting landscape of ransomware warfare, the emerging threat of Loop DoS attacks, and the Biden-Harris administration's call to action for water sector cybersecurity. Original URLs: https://www.bleepingcomputer.com/news/apple/oracle-warns-that-macos-144-update-breaks-java-on-apple-cpus/ https://www.guidepointsecurity.com/blog/t-o-x-i-n-b-i-o-ransomware-recruitment-efforts-following-law-enforcement-disruption/ https://www.helpnetsecurity.com/2024/03/20/raas-recruit-affiliates/ https://thehackernews.com/2024/03/new-loop-dos-attack-impacts-hundreds-of.html https://cispa.de/en/loop-dos https://www.epa.gov/newsreleases/biden-harris-administration-engages-states-safeguarding-water-sector-infrastructure https://www.cybersecuritydive.com/news/warnings-state-linked-cyber-threats-water/710834/ Thanks to Jered Jones for providing the music for this episode. https://www.jeredjones.com/ Logo Design by https://www.zackgraber.com/ macOS 14.4, Java Issues, Oracle Warning, Ransomware Wars, Law Enforcement, Cybersecurity, Loop DoS Attack, Water Sector Cyber Threats, Biden-Harris Administration, Cyberattack Prevention, Mobile Security, Password Managers, Apple Silicon CPUs Search Phrases: macOS 14.4 Java problems Oracle advice on macOS update Ransomware recruitment post-crackdown Effects of law enforcement on ransomware Understanding Loop DoS attacks Cyber threats to water infrastructure Biden-Harris cyber security efforts Protecting against cyberattacks in the water sector How ransomware groups adapt Cybersecurity measures for water systems Impact of macOS updates on Java Dealing with ransomware wars New cybersecurity threats 2024 Administration's response to cybersecurity in infrastructure Cybersecurity tips for protecting critical infrastructure Transcript: mar 21 [00:00:00] offsetkeyz: welcome back to the Daily Decrypt. Today, we're joined by HotGirlFarmer, as she delivers last week's breaches in your favorite segment, Who's Been Popped. Also, the company Oracle alerts customers that the new Mac OS 14. 4 update will disrupt Java functionality and urges. Customers to postpone this update. Ransomware as a Service groups are upping their recruitment efforts, defying law enforcement disruptions. With cunning resilience. What are ransomware as a service groups and how are they recruiting? Stick around to find out. And the White House is really doubling down on water utilities, urging states and governors to collaborate to help protect this critical infrastructure. And finally, researchers have discovered a new loop denial of service attack that targets [00:01:00] UDP based application level protocols, putting an estimated 300, internet hosts at risk for continuous looping and unneeded stress. How will this affect everyday users? Alrighty, so before we get into the breaches with Hot Girl Farmer, I just wanted to warn macOS users to maybe postpone the most recent update to avoid any system disruptions. There are no current workarounds and Java isn't liking the new update. This isn't like how it used to be in the earlier 2000s where Java ran everything on your computer. It shouldn't affect you unless you're developing in Java. But besides Java issues, Updated users are reporting issues with their printer drivers, lost iCloud files, and connectivity issues with USB hubs and monitors. So let's just hold off on the new macOS 14. 4 upgrade for a few more days. [00:01:53] HGF: [00:02:00] First off, hackers targeted MediaWorks, a company in New Zealand, demanding a ransom in cryptocurrency from victims who just wanted to win a free radio contest. MediaWorks is out here like, sorry, your name, address, and birthday were part of our grand prize giveaway to some hackers. Hopping on a financial rollercoaster, the International Monetary Fund got their emails hacked. And these weren't just any emails, they were the kind that you use fancy words in hoping to sound smart. The IMF is like the person who insists on using a $10 word when a $1 word will do, and now everyone knows they've been using "Synergy" wrong this whole time. [00:02:41] HGF: Meanwhile in France, they've turned data breaches into an art form, with up to 43 million people affected. It's a breach so chic, it's practically wearing a striped shirt and smoking a cigarette. And let's not forget Alabama, where the state government websites faced a denial of service [00:03:00] attack. Alabama's like, Our websites are slower than molasses in January, but don't you worry, your data's as safe as a church potluck. Except in this case, the potluck's been crashed by every hacker in a 10 mile radius. So, what have we learned aside from the fact that the world is a hacker's oyster? Keep your friends close, your passwords closer, and maybe, try not to store your entire life on a device that could be hacked by a 12 year old with a grudge. In the grand scheme of things, we're all just trying to make it through this digital world. [00:03:32] transition: Thanks for watching! [00:03:38] offsetkeyz: We've been hearing a lot coming out of the White House about critical infrastructure, such as power and water. They've been providing a lot of guidance recently and encouraging collaboration to avoid cyber attacks. So what do they know that we don't know? It's starting to get me a little scared. So just two days ago, the Biden Harris administration released some more guidance on how to stay safe, but is [00:04:00] also urgently calling governors and state governments to start collaborating. and really hardening the systems of their critical water infrastructure. When we think about crippling cyber threats, we tend to think about big corporations and ransomware and things like that, but those may be where the money is, but those who are out to get the United States of America, like maybe China and maybe Russia, I'm not sure. We'll be targeting our critical infrastructure first Now, if you are working in it in a critical infrastructure like power or water, our hats are off to you. I know what you're up against and even. The White House knows what you're up against, which is why they're starting to step in. So keep doing the Lord's work out there and try to get it as secure as possible. Because, hey, we all need water to live. And I don't want to be making that Walmart run when my water stops working. That's going to be crazy. So part of the major efforts by the Biden Harris administration includes creating a cybersecurity task force between the EPA and the [00:05:00] NSC, promoting existing resources to protect against cyberattacks on water systems. According to the letter from the White House, there have been an increased amount of attacks on water systems driven by both countries or nation state actors and run of the mill cyber criminals. So I'm glad to see our federal government stepping in and helping where they can. But we might be reaching the point where we need to take our own health and wellbeing into our own hands, stock up on water, buy a nice filter, maybe get a rain bucket for outside. Make sure that you and your family are taken care of in the event that the water does go down. [00:05:40] offsetkeyz: Recently we've been seeing a lot of ransomware as a service groups being shut down by the FBI and other three letter organizations, which is great. But the FBI can only do so much, and what they've been doing is trying to capture individuals who are responsible for running these ransomware as a service groups or developers, [00:06:00] but mostly they're just shutting down dark web websites. with big banners that say claimed by the FBI. So in most instances, the individuals behind these ransomware as a service groups are just moving and creating new ransomware as a service groups, or joining others, strengthening their staffing. But let's back up for a second. What is ransomware as a service? Well, this is the new hot thing in ransomware, where it's essentially Cloud as a service, or something that you would sign up to use not really knowing how to make it yourself, but you want to use the tools to conduct a ransomware. So a good example of something you might use as a service is something like Squarespace, where if you don't know how to do web development, but you want a website, you would then pay for Squarespace's services and they give you some features, right? Depending on how much you're willing to pay. So Squarespace specifically is considered software as a service. Now ransomware as a service does exactly [00:07:00] that. I would like to ransomware somebody. So I go sign up for an account at one of these places. Such as Medusa or Cloak, as referenced in the article by HelpNet Security that's linked in our show notes below. And depending on the amount you want to pay for this service, you can get perks. Thanks. The amounts are surprisingly low between 800 to 1, 000 a year to access this product and they're getting lower. They're being pushed harder onto end users and the perks are getting better too. One of the lowest tiers is once you reach a million dollars in ransom payments, you get access to dumped hashes, you get access to a bunch of tools that make it easier to do the initial compromise. There have also been a string of Exit scams across the dark web, which is essentially when a company like Medusa or any ransomware as a service will Receive the ransom that you [00:08:00] went out and earned and then just close down their site keeping all of the money most ransomware as a services Set up the platform to receive the money And then they pay you about 85 percent of the ransom, as agreed upon before using the service. But now these groups are starting to let you collect the ransom, and then allow you to pay that 15 percent usage fee. helping to encourage people to use their services and not be so afraid of exit scams or other scams on the dark web. But what's so crazy about this is that they're literally just posting ads on the dark web. They're in forums and they are offering these perks and security researchers are able to see them in real time and see who's interacting with them. And the beauty of the dark web is that. If you're doing it correctly, it can be completely anonymous. Now I don't encourage you to get on the dark web to see this type of activity, but it is available to you. And if you'd like more information about the dark web, I released a talk about a week ago, maybe two weeks ago at this point, outlining at a high level how the dark web [00:09:00] works. [00:09:12] offsetkeyz: And finally, researchers have developed or discovered a new denial of service or DOS attack. that relies on UDP based application level protocols. And if you're not familiar, there are two main protocols on the transport layer that you interact with on a daily basis. UDP and TCP. UDP is the faster of the two, and it doesn't require any sort of verification that the data has been received. And this is often used when gaming online with your friends or talking, or even streaming like YouTube videos. Those rely heavily on UDP because you need to get the data as quickly as possible when streaming videos. And it doesn't really matter if every single frame is accounted for, you can occasionally drop frames, which might result in a little skip, but [00:10:00] overall, most of them are going to get through kind of like a shotgun spray. Whereas TCP is more for like text based communications or things where data needs to be verified on both ends, and it's a little slower due to the verification. So, UDP inherently doesn't verify, which is important to understand this type of attack, because this loop denial of service exploits UDP's lack of source IP validation to create endless communication loops between servers, eventually overwhelming them. Additionally, protocols like DNS, NTP, and TFTP are among those vulnerable to these attacks, potentially affecting basic internet functionalities. So this does tie back into the attack on DNS, which is essentially like a lookup of what you're trying to navigate to. So, when you navigate to facebook.com it reaches out to a DNS server and says, Hey, what the heck is facebook. com? And it replies with an address. Without those [00:11:00] DNS servers, we actually can't move about the internet like we do on the day to day. So this attack is easily triggered by a single spoofed message and can stress entire networks with 300, 000 hosts already at risk. There's no evidence of this loop denial of service being used in the wild, but its exploitation is considered trivial, affecting major vendors like Cisco and Microsoft. Now, these are likely a little further down the pipeline than you're familiar with as a regular user or even as a cybersecurity analyst. but you might notice slower internet speeds, stuff like that, if this happens, with the potential for it to completely shut down your internet connection. And on that note, not much is to be done on the user level. Just letting you know what's possible and what the attackers are doing. Hitting you from all kinds of angles. All right, and that is all we've got for you today. A little bit longer of an episode because we missed yesterday due to technical [00:12:00] issues, but we're back and better than ever, and we will talk to you some more tomorrow.

The Audit
Email and Mobile Security Tips with Dean Morstad

The Audit

Play Episode Listen Later Jan 15, 2024 44:02 Transcription Available


Is your digital footprint secure? In our latest episode we unravel the complexities of email and mobile security. Join Dean Morstad, a seasoned cybersecurity expert, as he shares invaluable insights and practical tips to enhance your digital safety. The conversation includes: - Why and how are most of us viewed as a “product”?  - Practical email security tips and best practices - How to avoid phishing scams and other social engineering strategies - Mobile device and location tracking insights - Organizational security policy tips  - Why use a password manager 

Holistic Investment w Constantin Kogan

In this enlightening and comprehensive interview, we sit down with Mark Kreitzman, the General Manager of Ifani, to delve into the critical and often overlooked world of mobile security. Mark shares his personal journey into the realm of cybersecurity, providing valuable insights into the challenges and solutions in protecting our digital lives. Don't miss!

ITSPmagazine | Technology. Cybersecurity. Society
Navigating the Privacy Maze: Mozilla's Vehicle Privacy Report Sparks a Drive | A BlackCloak Brand Story with Chris Pierson and Ingrid Gliottone

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Oct 18, 2023 37:07


The recent report by Mozilla, shedding light on the privacy concerns around modern vehicles, struck a chord. Notably, every car brand reviewed, including behemoths like Ford, Volkswagen, and Toyota, flunked the privacy test. This revelation steered a fascinating conversation with Chris Pierson and Ingrid Gliottone from BlackCloak during a brand story recording for the Redefining Society podcast. Our focus veered towards the lurking privacy and security issues tied to the modern, tech-savvy vehicles we so casually entrust with our data.The modern car is no longer just a mode of transport—it's a smart gadget, a data hub on wheels. But as the wheels spin, so does the reel of our personal information, weaving into the vast web of data, ready for harvest by not just the car makers, but a string of 'they' – the infotainment system providers, app developers, network providers, and possibly cyber rogues. The conversation took a deeper dive as Chris, the CEO of BlackCloak, elucidated the firm's mission—shielding corporate executives and key personnel from personal cyber threats that could ricochet back to the corporations.The Mozilla report is an alarm bell, underscoring the high time to separate the wheat from the chaff in terms of what data is essential for functionality and what merely serves as a gold mine for advertisers or a hunting ground for cyber-attackers. This blend of privacy and security, or the lack thereof, is a cocktail we are forced to sip, as Ingrid pointed out the lack of clarity presented to buyers at the point of sale concerning the privacy policies tied to these vehicles.The promise of tech advancements in vehicles is dazzling—better shocks for off-roaders, safety features to prevent accidents during a sudden snooze, and so on. Yet, as Chris highlighted, there's a dark side. Some policies mentioned collecting data about one's sex life and genetic information— a far cry from the basic expectations of privacy.As the conversation with BlackCloak unrolled, the blend of excitement and concern was palpable. The question now is not about halting the march of technology but steering it towards a path where privacy and security are not the passengers but co-drivers.The findings from the Mozilla report and insights from BlackCloak are not just food for thought, but a call to action. It is crucial to reckon with the reality of the modern-day vehicles doubling as data hubs and to steer the conversation towards a road where transparency, consent, and security are the landmarks. I urge you to dive into BlackCloak's offerings to explore how they are redefining the security landscape, ensuring the privacy and security of your personal digital realm, including that computer on wheels parked in your driveway. Visit BlackCloak to discover what they offer in shielding the modern-day knights from the unseen arrows of the digital world.Guests:Chris Pierson, Founder and CEO of BlackCloak [@BlackCloakCyber]On Linkedin | https://www.linkedin.com/in/drchristopherpierson/On Twitter | https://twitter.com/drchrispiersonIngrid Gliottone, Chief Experience Officer of BlackCloak [@BlackCloakCyber]On LinkedIn | https://www.linkedin.com/in/ingridgliottone/ResourcesLearn more about BlackCloak and their offering: https://itspm.ag/itspbcwebAre you interested in telling your story?https://www.itspmagazine.com/telling-your-story

All TWiT.tv Shows (MP3)
This Week in Enterprise Tech 538: Paving the Mobile Security Potholes

All TWiT.tv Shows (MP3)

Play Episode Listen Later Apr 8, 2023 70:26


Amazon Web Services and Microsoft Azure face antitrust probe. Cybercriminals 'CAN' steal your car, using novel IoT hack Romance Scams: Authorities claw back funds from "Pig-butchering" cybercrime ring EU Chips act likely to get the green light on April 18 Designing Tabletop exercises that actually thwart attacks Vincent Korstanje, CEO of Kigen, talks about how to make IoT devices more secure and trustworthy. Hosts: Louis Maresca, Brian Chee, and Curtis Franklin Guest: Vincent Korstanje Download or subscribe to this show at https://twit.tv/shows/this-week-in-enterprise-tech. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: decisions.com/twit bitwarden.com/twit ZipRecruiter.com/twiet

ITSPmagazine | Technology. Cybersecurity. Society
Come Fly with us to the Aerospace Village | ITSPmagazine Event Coverage: RSAC 2023 San Francisco, USA | A Conversation with Steve Luczynski and Henry Danielson

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Mar 27, 2023 45:13


GuestsSteve Luczynski, Senior Manager / Critical Infrastructure Security, Accenture Federal Services [@Accenture] and Chairman of the Board for the Aerospace Village [@secureaerospace]On LinkedIn | https://www.linkedin.com/in/steveluczynski/On Twitter | https://twitter.com/cyberpilot22Henry Danielson, Adjunct Professor/Lecturer, Cal Poly College of Liberal Arts [@CalPolyCLA], Technical Advisor, California Polytechnic State University California Cybersecurity Institute [@CalPolyCCI], and Volunteer at Aerospace Village [@secureaerospace]On LinkedIn | https://www.linkedin.com/in/henry-danielson-43a61213/On Twitter | https://twitter.com/hdanielsonAt Cal Poly | https://cci.calpoly.edu/about-cci/staff____________________________Hosts:Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________This Episode's SponsorsBlackCloak | https://itspm.ag/itspbcweb____________________________Episode Notes"Discover the exciting world of the Aerospace Village at RSA Conference 2023, and dive into hands-on experiences with cybersecurity experts and cutting-edge technology." Welcome to ITSPmagazine's RSA Conference 2023 coverage, where we dive into the world of cybersecurity and engage with experts in a week full of fun and exciting activities. We're on the road to RSA Conference 2023 in San Francisco, and one event we can't miss is the Sandbox, specifically the Aerospace Village. In this podcast episode, we're joined by our good friends Steve Luczynski and Henry Danielson from the Aerospace Village to discuss what's in store for us at this year's conference.The Aerospace Village is a small nonprofit run by volunteers from around the world, aiming to build relationships between government, industry, security researchers, and hackers, inspire people to join the cybersecurity workforce, and promote awareness in the aviation and space sectors. This year, RSA Conference 2023 features a Sandbox where attendees can interact with the latest technical hands-on experiences, learn from experts, and explore what's happening in the cybersecurity world.In this episode, our guests discuss the various partners and activities in the Aerospace Village, such as CT Cubed's drone quadcopter simulation in AR and VR experience, IntelleGenesis's runway lighting scenario demonstration, and Boeing's continuous security level maintenance activity. You'll also get a chance to try out a real Airbus simulator, courtesy of pen test partners, to understand the potential vulnerabilities in electronic flight bags and their impact on pilot operations.Join us for an exciting, fun-filled week at RSA Conference 2023, where you can learn, network, and discover the latest trends in cybersecurity. Don't miss out on this unique opportunity to interact with experts, explore cutting-edge technologies, and immerse yourself in the world of aerospace cybersecurity. Be sure to listen, share, and subscribe to ITSPmagazine's podcast for more exciting episodes and insights from the RSA Conference 2023!____________________________ResourcesLearn more, explore the agenda, and register for RSA Conference: https://itspm.ag/rsa-cordbw____________________________Catch the video here: https://www.youtube.com/watch?v=Htvn7AkCJSsFor more RSAC Conference Coverage podcast and video episodes visit: https://www.itspmagazine.com/rsa-conference-usa-2023-rsac-san-francisco-usa-cybersecurity-event-coverageAre you interested in telling your story in connection with RSA Conference by sponsoring our coverage?