POPULARITY
In this episode of SecurPod, Ralph C. Jensen enjoys a conversation with Vikram Phatak, the founder and CEO of CyberRatings.org. The conversation starts with the topic of ChatGPT and its pros and cons in the cyber world. We also talk about testing of the latest cybersecurity technology — the asymmetry, or market distortion — because there is not enough transparency into how security products work. Testing provides ratings and test scores on security product effectiveness, performance and management and reporting capabilities. The CyberRatings.org team has unique security product testing expertise with a combined proficiency spanning more than three decades. Its executives have fostered well-established relationships with most large and small security vendors and have built an earned trust with vendors and enterprises. As one of the industry's foremost thought leaders, Phatak has extensive experience in cybersecurity technologies protecting networks, endpoints and the cloud. Phatak founded NSS Labs, Inc. in 2007 as a go-to source for trusted independent, fact-based guidance on security product efficacy. For more than a decade, he grew NSS Labs from a small test lab to a global leader in security product testing.
Some of what Dina talks about: Finding a way to connect with your team in a way you haven't before Building safe spaces to allow people to be heard All slack channels are public Create a culture committee to have employees be a part of the solution Break down assumptions that have been made Time and space introduce attribution error Meet: Dina Bruzek has over 31 years of experience in technology with more than 23 years of experience leading teams in the development of market-leading cybersecurity products. At Huntress Labs, Dina is Senior Vice President of Product and Engineering and is responsible for guiding the execution of the company's product strategy across the engineering and product management groups to bring enterprise-grade solutions to Mid-Market and SMB partners. Prior to joining Huntress Labs, Dina was also the SVP of Product and Engineering at NSS Labs and The Media Trust. Prior to that, Dina led Cisco's Network Threat Defense (NTD) group, where she was responsible for a $1.5 billion product portfolio. Dina joined Cisco through the 2013 acquisition of Sourcefire for $2.7 billion. At Cisco, she led the company's strategy to deliver the first threat-focused next-generation firewall. In addition, she led the integration of the Sourcefire and Cisco development teams and the agile transformation of the development and test organizations to form the NTD group, which consisted of more than 800 engineers. Before joining Cisco, Dina was the Vice President of Product Development at Sourcefire, where she was responsible for software and hardware development for Sourcefire network security products. She has also held various technical, strategic, and management roles in Internet security at Secure Computing Corporation and Network Associates. She started her career as a communications systems engineer at the Johns Hopkins University Applied Physics Laboratory. Dina holds a BS in Electrical Engineering from Purdue University and an MS in Engineering from Johns Hopkins University. If you have any questions for Dina, please feel free to reach out via: https://www.linkedin.com/in/dina-bruzek-997941/ https://twitter.com/dbruzek I hope you enjoyed the episode, the best place to connect with me is on Linkedin - https://www.linkedin.com/in/amirbormand (Amir Bormand). Please send me a message if you would like me to cover certain topics with future guests.
About Chris Morales: We're here this week with an AI and threat modeling guru, Chris Morales! He's Netenrich's FIRST CISO and Head of Security Strategy overseeing the strategic development, implementation, and market execution of the company's security solutions and processes. Chris has 20-something years of information security experience, having previously led advisory services and security analytics for Vectra AI – while at Vectra he educated many of the Cloud Security Alliance chapter members on dissecting a Microsoft Office 365 attack. During his career, he has advised and designed incident response and threat management programs for some of the world's largest enterprises. Chris has held senior roles in cybersecurity engineering, consulting, sales and research at companies such as HyTrust, an Entrust company, NSS Labs, 451 Research, Accuvant (acquired by Blackstone Group), McAfee and IBM. He is also currently a council member with CompTIA Cybersecurity and advisory board member for Saporo. He not only brings his wicked smart knowledge on cyber; his candor and wit is refreshing. To boot, he's from the friendship state – Texas, so listen to this podcast – it's like hearing from a friend!Guest Chris Morales LinkedIn: https://www.linkedin.com/in/cmatx/ (https://www.linkedin.com/in/cmatx/) Twitter: https://twitter.com/MoralesATX (https://twitter.com/MoralesATX) Highlights: 0:00 - Introductions & About Netenrich Netenrich, Ingram Micro and expanding from roots Evolving IT & Security specialization Moving from consulting to CISO 7:10 - Pathway to CISO What's the definition who makes a good CxO? Six Types of CISO - Ref: https://www.forrester.com/blogs/the-future-of-the-ciso-six-types-of-security-leaders/ (Forrester Article, Jan 2020) Identifying different types of personalities for industries Every company is a tech company 14:26 - Difference: Secure Operations vs. Security Operations Question of proactive vs reactive Two different focuses - predictive with cultural challenges and buy in Enhancing customer experience Situational awareness is important with looking at same set of data between groups to communicate daily. 18:16 - Bring Value of "Why Do I Care?" Entire management chain needs to care Alignment is important with the C-suite Look at data, threat modeling to share how and why it impacts key holder Chris learned a lot from statistical analysis and appreciation of data 22:48 - How Chris Came To Security Started as Computer Science to make video games Dropped out of college to launch his own business Joined the military Listened to his Dad talk about "The Art of War," Sun Tzu Spent time hacking to get video games Moving positions and being open to job challenges 31:35 - Advice to Future Leaders The title doesn't mean anything It's more important on what you do Have insight and empathy on why people do things, and learn their pain points Don't worry about being good at everything. Pick one thing and be good at it Hacking is social engineering Security breached through end users is a failure of the security team Don't be afraid to fail as a leader People are the victims, not the problem People are suffering from our technology problem 37:25 - How Chris Avoids Burn Out The question - How do you get more sleep? There is no magic answer and sometimes hitting the wall can be scary "I Am Me" - Chris needs to write this book on addressing burn out Do what you like and works for you. Burn out - Working too hard and no one cares. Final Thoughts: On avoiding burn out: Working hard is ok, but recognize when you are working too hard and no one cares.
Companies spend trillions on cyber security each year. But how do they decide which products and services are the best?We dig down into the sometimes shady world of cyber security sales, market analysis and product testing. How do the relationships work between clients, salespeople, analysts, testers and the media?Simon Edwards (SE Labs) talks to special guests Allison Elizondo (ex-NSS Labs, now SentinelOne) and Nabil Khokhar (ex-Glencore, now DarkGuard)(Full Show Notes available on our website.)
In the Security News, Testing firm NSS Labs closes up shop, stringing vulnerabilities together to pwn the Discord desktop app, a Wordpress plugin aimed at protecting Wordpress does the opposite, the FDA approves the use of a new tool for medical device vulnerability scoring, 8 new hot, steamy, moist cybersecurity certifications, and 5 things you can do to secure your home office without hiring an expert! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/psw671
In the Security News, Testing firm NSS Labs closes up shop, stringing vulnerabilities together to pwn the Discord desktop app, a Wordpress plugin aimed at protecting Wordpress does the opposite, the FDA approves the use of a new tool for medical device vulnerability scoring, 8 new hot, steamy, moist cybersecurity certifications, and 5 things you can do to secure your home office without hiring an expert! Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/psw671
This week, we welcome back Corey Thuen from Gravwell, to talk about Sysmon Endpoint Monitoring complete with Clipboard Voyeurism! Next up, Scott Scheferman, the Principal Cyber Strategist at Eclypsium, joins us to talk about how Hackers Are Hitting Below The Belt! In the Security News, testing firm NSS Labs closes up shop, stringing vulnerabilities together to pwn the Discord desktop app, a Wordpress plugin aimed at protecting Wordpress does the opposite, the FDA approves the use of a new tool for medical device vulnerability scoring, and 8 new hot, steamy, moist cybersecurity certifications! Show Notes: https://wiki.securityweekly.com/psw671 Visit https://securityweekly.com/gravwell to learn more about them! Visit https://securityweekly.com/eclypsium to learn more about them! Visit https://www.securityweekly.com/psw for all the latest episodes! Visit https://securityweekly.com/acm to sign up for a demo or buy our AI Hunter! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly
This week, we welcome back Corey Thuen from Gravwell, to talk about Sysmon Endpoint Monitoring complete with Clipboard Voyeurism! Next up, Scott Scheferman, the Principal Cyber Strategist at Eclypsium, joins us to talk about how Hackers Are Hitting Below The Belt! In the Security News, testing firm NSS Labs closes up shop, stringing vulnerabilities together to pwn the Discord desktop app, a Wordpress plugin aimed at protecting Wordpress does the opposite, the FDA approves the use of a new tool for medical device vulnerability scoring, and 8 new hot, steamy, moist cybersecurity certifications! Show Notes: https://wiki.securityweekly.com/psw671 Visit https://securityweekly.com/gravwell to learn more about them! Visit https://securityweekly.com/eclypsium to learn more about them! Visit https://www.securityweekly.com/psw for all the latest episodes! Visit https://securityweekly.com/acm to sign up for a demo or buy our AI Hunter! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly
TrickBot came back, but so did its nemesis from Redmond--Microsoft and its partners have taken down most of the new infrastructure the gang reestablished. CISA publishes election rumor control. The Cyberspace Solarium Commission has a white paper on supply chain security. Japan says it will take steps to secure next summer’s Olympics. Joe Carrigan takes issue with Twitter and Facebook limiting the spread of published news stories. Our guest is Carolyn Crandall from Attivo with a look at the market for cyber deception tools. And a familiar name exits the industry. For links to all of today's stories check out our CyberWire daily news brief: https://www.thecyberwire.com/newsletters/daily-briefing/9/204
On this week’s show Patrick and Adam discuss the week’s security news, including: US DoJ unseals indictments against Sandworm operators Twitter backtracks on “hacked materials” policy No consensus on Trickbot c2 status NSA publishes “most exploited” listicle that’s actually interesting Much, much more Cmd Security is this week’s sponsor. Its CEO Jake King and CTO Mike Sample join the show this week to talk though a new remote access tech release from Hashicorp called Boundary and what it might mean for Linux system observability in your environment. Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing. Show notes US Indicts Sandworm, Russia's Most Destructive Cyberwar Unit | WIRED UK says Russia was preparing cyber-attacks against the Tokyo Olympics | ZDNet Sandworm operators indicted - Risky Business Microsoft says it took down 94% of TrickBot's command and control servers | ZDNet NSA publishes list of top vulnerabilities currently targeted by Chinese hackers | ZDNet 800,000 SonicWall VPNs vulnerable to new remote code execution bug | ZDNet VMSA-2020-0023 New York Post Published Hunter Biden Report Amid Newsroom Doubts - The New York Times Twitter Says It Blocked NY Post Hunter Biden Article Because It Contains Hacked Data The Media Just Passed a Test It Failed Four Years Ago | WIRED Brevard voters threatened in emails purportedly from 'Proud Boys' Google offers details on Chinese hacking group that targeted Biden campaign Industry alert pins state, local government hacking on suspected Russian group New York regulator faults Twitter for lax security measures prior to big account breach German authorities raid FinFisher offices | ZDNet Shannon Vavra on Twitter: "Details via @hsu_spencer & @kfahim https://t.co/QTRooHnw0I" / Twitter Encrochat Hack That Brought Down Hundreds of Criminals Faces Legal Challenges Hackney Council unable to pay housing benefit after cyber attack | Science & Tech News | Sky News London's Hackney Borough Council hit by hack attack - BBC News Hackney Council services to be disrupted ‘for some time’ Meet FIN11, a cybercrime outfit going after pharma companies while leaning on extortion QAnon/8Chan Sites Briefly Knocked Offline — Krebs on Security Alexander Vinnik heads to trial in France on ransomware, money laundering charges Alleged KickassTorrents founder Artem Vaulin jumped bail in Poland Thousands of infected IoT devices used in for-profit anonymity service | Ars Technica Microsoft adds option to disable JScript in Internet Explorer | ZDNet Zoom to roll out end-to-end encrypted (E2EE) calls | ZDNet QRadar: Popular IBM security tool open to remote code execution attacks | The Daily Swig Google releases Chrome security update to patch actively exploited zero-day | ZDNet Security testing firm NSS Labs ceases operations, citing coronavirus | TechCrunch Ryuk in 5 Hours – The DFIR Report
In this episode, Jason Brvenik, CEO of NSS Labs, joins the podcast for a second time. He and Ashwin discuss what makes a successful security program and the paradox of achieving that success for CISOs. Amidst all the marketing noise, Jason believes the continuous assessment of vendors remains crucial in helping enterprises make informed security […]
In the news, Mimecast Challenges Shadow IT for Cloud App Usage on Mobile and Desktop Devices, CloudKnox Security Announces Integration with AWS IAM Access Analyzer, Morphisec Achieves AWS Security Competency Status for Cloud Server Workload Protection, and more! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/ESWEpisode164
In the news, Mimecast Challenges Shadow IT for Cloud App Usage on Mobile and Desktop Devices, CloudKnox Security Announces Integration with AWS IAM Access Analyzer, Morphisec Achieves AWS Security Competency Status for Cloud Server Workload Protection, and more! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://wiki.securityweekly.com/ESWEpisode164
Cybersecurity’s Watchdog Jason offers an insight into the philosophy and work of NSS Labs. He discusses outdated dogma in cybersecurity, offers advice for vendors from large players to scrappy startups, and shares why he chose a career in cyber – he knew it was a domain that would never be mundane. 04:23 Vendors cover a spectrum […]
This week, Paul and Matt Alderman talk Enterprise News, to discuss a Privilege Escalation Vulnerability that existed in Check Point Software, Untangle survey finds SMBs continue to struggle with IT Security, Tufin delivers enhanced Visibility and Topology modeling for Cisco ACI Migration, and how the OS that powered smartphones started from failure! In our second segment, we air two pre recorded interviews from BlackHat 2019 with Jason Brvenik of NSS Labs and Mehul Revankar of SaltStack! In our final segment, we air two more pre-recorded interviews from BlackHat 2019 with Carolyn Crandall of Attivo Networks and Krupa Srivatsan of Infoblox! Full Show Notes: https://wiki.securityweekly.com/ES_Episode152 Visit https://www.securityweekly.com/esw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly
We interview Jason Brvenik, the Chief Executive Officer at NSS Labs. Jason will cover The Importance of Independent, Third-Party Testing. We interview Mehul Revankar, the Senior Product Manager at SaltStack. Mehul will be talking about the intersection between security and IT operations. Full Show Notes: https://wiki.securityweekly.com/ES_Episode152 Visit https://www.securityweekly.com/esw for all the latest episodes!
We interview Jason Brvenik, the Chief Executive Officer at NSS Labs. Jason will cover The Importance of Independent, Third-Party Testing. We interview Mehul Revankar, the Senior Product Manager at SaltStack. Mehul will be talking about the intersection between security and IT operations. Full Show Notes: https://wiki.securityweekly.com/ES_Episode152 Visit https://www.securityweekly.com/esw for all the latest episodes!
This week, Paul and Matt Alderman talk Enterprise News, to discuss a Privilege Escalation Vulnerability that existed in Check Point Software, Untangle survey finds SMBs continue to struggle with IT Security, Tufin delivers enhanced Visibility and Topology modeling for Cisco ACI Migration, and how the OS that powered smartphones started from failure! In our second segment, we air two pre recorded interviews from BlackHat 2019 with Jason Brvenik of NSS Labs and Mehul Revankar of SaltStack! In our final segment, we air two more pre-recorded interviews from BlackHat 2019 with Carolyn Crandall of Attivo Networks and Krupa Srivatsan of Infoblox! Full Show Notes: https://wiki.securityweekly.com/ES_Episode152 Visit https://www.securityweekly.com/esw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly
We are delighted to bring 2nd of the 3 part series in conversation with the very passionate and dynamic Gaurav Aggarwal, Chief Marketing Officer of NSS Labs. In this episode, we will talk about the importance of companies like NSS labs who tackle Cybersecurity threat in the market with bespoke offerings to corporates of the world.
Newsworthy Items: 1. NSS Labs fires off anti-malware-testing lawsuit at infosec toolmakers 2. Gartner says EDR will be a 1.5 BILLION, with a B business by 2020 3. Forrester Report on is EDR overblown
This week's Risk & Repeat podcast discusses NSS Labs' antitrust suit against several security vendors, including CrowdStrike and the Anti-Malware Testing Standards Organization.
This week's Risk & Repeat podcast discusses NSS Labs' antitrust suit against several security vendors, including CrowdStrike and the Anti-Malware Testing Standards Organization.
Insecure - Cyber Security Podcast With Keith Wilson and John Morton
In this episode Keith and John talk translating security tools to business value, establishing expertise to further your career, and how to people network in-person even if you are an introvert. Also, our hosts touch on the NSS Labs lawsuit & a Hack the Vote event that took place in Boston. Closing Music: "Booty Wurk" by T-Pain feat. Joey Galaxy Get The Latest Episode On: iTunes: https://apple.co/2MvqaM6 Stitcher: http://bit.ly/insecurestitcher Google Play: http://bit.ly/insecuregp Spotify: http://bit.ly/insecurepod Opinions of the hosts and its guests are their own. This podcast in no way represents the views of the host's or guest's respective companies or their affiliates.
In the news, RSA Spotlight: VMware and Sophos discuss latest innovations, Fortinet receives recommended rating in NSS Labs latest advanced endpoint protection test report, Twitter bans Kaspersky Lab from advertising on its platform, SANS Experts share five most dangerous new attack techniques, and more on this episode of Enterprise Security Weekly! Full Show Notes: https://wiki.securityweekly.com/ES_Episode88 Visit http://securityweekly.com/esw for all the latest episodes!
In the news, RSA Spotlight: VMware and Sophos discuss latest innovations, Fortinet receives recommended rating in NSS Labs latest advanced endpoint protection test report, Twitter bans Kaspersky Lab from advertising on its platform, SANS Experts share five most dangerous new attack techniques, and more on this episode of Enterprise Security Weekly! Full Show Notes: https://wiki.securityweekly.com/ES_Episode88 Visit http://securityweekly.com/esw for all the latest episodes!
Our guest Adam Haberer, Esq. has experience counseling small businesses and startups. Adam is currently an in house Attorney at NSS Labs out of Austin, Texas See acast.com/privacy for privacy and opt-out information.
Wade is joined by Gautam Aggarwal who is Head of Products and Chief Marketing Officer with NSS Labs and they discuss the challenges and successes of measuring control effectiveness.
Jason Brvenik of NSS Labs brings more than 20 years of experience in systems design, integration, and security for both commercial and open markets. He was most recently a Principal Engineer in the Office of the Chief Security Architect at Cisco. Jason joins Michael and Matt to discuss the dogma of the industry! Full Show Notes: https://wiki.securityweekly.com/SSWEpisode55 Visit http://securityweekly.com/category/ssw for all the latest episodes!
Jason Brvenik of NSS Labs joins us. In the news, attributes of a scalable business, founder struggles, how to grow your startup, and updates from AppGuard, Securonix, CashShield, and more on this episode of Startup Security Weekly!Full Show Notes: https://wiki.securityweekly.com/SSWEpisode55Visit https://www.securityweekly.com/ssw for all the latest episodes!
Jason Brvenik of NSS Labs joins us. In the news, attributes of a scalable business, founder struggles, how to grow your startup, and updates from AppGuard, Securonix, CashShield, and more on this episode of Startup Security Weekly!Full Show Notes: https://wiki.securityweekly.com/SSWEpisode55Visit https://www.securityweekly.com/ssw for all the latest episodes!
Jason Brvenik of NSS Labs brings more than 20 years of experience in systems design, integration, and security for both commercial and open markets. He was most recently a Principal Engineer in the Office of the Chief Security Architect at Cisco. Jason joins Michael and Matt to discuss the dogma of the industry! Full Show Notes: https://wiki.securityweekly.com/SSWEpisode55 Visit http://securityweekly.com/category/ssw for all the latest episodes!
On this extra episode of The Cybersecurity Podcast, reporter Jack Detsch brings you the highlights from Beat the Breach, an event cohosted by Passcode and Invincea during the RSA Conference in San Francisco. The live discussion focused on how the Trump administration will confront the nation's biggest cybersecurity challenges. You'll hear from former White House Homeland Security Adviser Lisa Monaco, former US Chief Information Security Officer Greg Touhill, General Motors' Jeffrey Massimilla, and US Deputy Assistant Attorney General Adam Hickey. This bonus episode is sponsored by Forcepoint, NSS Labs, and Vectra Networks.
Handbags at dawn for CrowdStrike and NSS Labs! Donald Trump's insecure Android phone! File-less malware - is that so new? And StalkScan makes it easier to reveal what Facebook users have been carelessly sharing... Computer security veterans Graham Cluley, Carole Theriault and Vanja Svajcer discuss. SHOW NOTES AEP Public Test Announcement NSS Labs Report Confirms Testing of CrowdStrike Falcon was Incomplete and Wrong Some thoughts on the CrowdStrike vs NSS Labs debacle Which Android phone does Donald Trump use? Senators raise concerns over Donald Trump's smartphone security Google claims ‘massive’ Stagefright Android bug had 'sod all effect' A Scary New Kind of Malware Is Invading Banks All Over the World Fileless attacks against enterprise networks StalkScan This creepy Facebook tool is revealing a LOT about you Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Vanja Švajcer.
The boys actually talk security, The Guys from NSS Labs join in, Exploit Hub, All kinds of other greatness, Intro: "Virus" By Deltron 3030, Outro: "Truth From Fiction" By Supreme Beings of Leisure
The boys actually talk security, The Guys from NSS Labs join in, Exploit Hub, All kinds of other greatness, Intro: "Virus" By Deltron 3030, Outro: "Truth From Fiction" By Supreme Beings of Leisure
Connected Futures: A Cisco podcast exploring business innovation insights
There is no silver bullet to enterprise security. As the Internet of Everything (IoE) drives the proliferation and sophistication of connections, the likelihood of attacks are no longer a matter of if, but when. It is only a matter of time before any organization is compromised. So how can enterprise systems and networks ensure mission survivability in a cyber-compromised environment? In this podcast, Cisco's Jason Brvenik and Mike Spanbauer, Vice President of Research at NSS Labs discuss how organizations can become cyber resilient in today's Internet of Everything landscape. Join the conversation, #FutureOfIT
Episode 18 - A great discussion on the recent news with NSS vs PAN, choosing technology from continuous requirements and a SAA update. SAA is joined by Brian Engle (CISO for state of Texas), John Johnson (Global Security Strategist @ John Deere).
Hello! This is a special episode in that it's our year-end wrap-up. We bring together 3 of the industry's best to talk about the year that was, the things that made were on your mind, and maybe give us a hint at what is to come... Guests Will Gragido ( @wgragido ) - Will is the Sr. Manager of threat Research Intelligence for RSA NetWitness and a lightweight with the cold medicine. John Pirc ( @jopirc ) - John is the Vice President of Research at NSS Labs, with very strong hair. David Marcus ( @DaveMarcus ) - David is the Director and Chief Architect of the Federal Advanced Program Group at McAfee and a kettle bell monster! Notably absent, but invited, were Dave Lewis ("fell asleep") and Dave Kennedy ("was on an airplane") ...apparently because I thought it would be fun to invite every Dave I know....... but seriously next time guys :) James and I would like to wish all our listeners a very merry holiday season, and a happy, healthy and prosperous 2014.
In this episode... We discuss the true nature of many of the security products decisions CISOs have to make every day Frank and Raf make very poorly thought-out sports analogies There are uncomfortable length of silence (mostly edited out) The crew discusses NSS Labs, and what they do to help the CISOs out there make smarter decisions "Someone" asks about anti-virus... [ More info on NSS Labs and the two guests today can be found here: https://www.nsslabs.com/analysts and https://www.nsslabs.com/ ] Guests Frank Artes ( @franklyfranc ) - Research Director Francisco Artes is a recognized information security executive who has helped form some of the motion picture & television industry’s best practices for securing intellectual property. Artes is also know for his work with on cybercrime, hacking and forensic security issues with various federal, state and local government and law enforcement agencies such as the US Dept. of Homeland Security, the FBI, the Texas Rangers, US Marshals and several others. Mr. Artes most recently served as Vice President, Chief Architect / Content Protection for Trace3, and as Vice President, Security Worldwide for Deluxe Entertainment Services Group. Artes has presented on six of the seven continents, serves on several boards and is a Trusted Adviser for The Security Consortium. John Pirc ( @jopirc ) - Research Vice President John Pirc is a noted security intelligence and cybercrime expert, an author and a renowned speaker, with more than 15 years of experience across all areas of security. The co-author of two books, “Blackhatonomics: An Inside Look at the Economics of Cybercrime” (published in December 2012), and “Cyber Crime and Espionage” (published in February 2011), Pirc has been named a security thought leader from the SANS Institute and speaks at top tier security conferences worldwide. Mr. Pirc’s extensive expertise in the security field includes roles in cybersecurity research and development for the Central Intelligence Agency, Chief Technology Officer at CSG LTD, Product Manager at Cisco, Product Line Executive for Security Products at IBM Internet Security Systems, Director of McAfee's Network Defense Business Unit and, most recently, Director of Security Intelligence at HP Enterprise Security Products, where he led the strategy for next generation security products. In addition to a bachelor's degree in Business Administration, Pirc holds the NSA-IAM and CEH certifications.
Episode 0x2A -- Happy One Year Later And we still suck at scheduling Despite efforts to the contrary... we're still not good at this. We should be getting better. Upcoming this week... Lots of News Breaches SCADA / Cyber, cyber... etc. finishing it off with DERPs/Mailbag and There will be a DEEP DIVE And there are weekly Briefs - no arguing or discussion allowed And if you've got commentary, please sent it to mailbag@liquidmatrix.org for us to check out. DISCLAIMER: It's not that explicit, but you may want to use headphones if you're at work. ADDITIONAL DISCLAIMER: In case it is unclear, this is the story of 5 opinionated infosec pros who have sufficient opinions of their own they don't need to speak for anyone except themselves. Ok? Good. In this episode: News and Commentary IE 10 Most Secure Browser according to NSS Labs ....Really? Privacy commissioner baffled about gas plant emails Google says 7 days! The Canadian Government's Embarrassing Opposition to Security Breach Disclosure Legislation (actual details on the opposition) Breaches Drupal France learns e-voting is Haaarrdddd SCADA / Cyber, cyber... etc BBC: Smart meters need to be harder to hack, experts say China blamed after ASIO blueprints stolen in major cyber attack on Canberra HQ Confidential report lists U.S. weapons system designs compromised by Chinese cyberspies DERP Woman Brags About Hitting Cyclist, Discovers Police Also Use Twitter (a hurr durr) Twitter is evil!!! Paypal bounty program FAIL Mailbag So I was listening to 0x29 and a thought came to me during the part about Moxie and the line that the Saudi recruiter used on him which was the standard refrain of: "You either stand with us, or you stand with the terrorists!" Or "You either stand for surveillance or you stand with the child pornographers." Can we not just turn that on its head using their own logic and say: "You either stand for privacy and security or you stand with the human rights abusers." Since the people pushing the big brother agenda only chose to use black and white in their pictures of the world, what happens when the colours are reversed? Bob The Deep Dive The Case For A Government Bug Bounty Program Briefly - NO ARGUING OR DISCUSSION ALLOWED Facebook Bug Bounty 4500.. Blackhats say worth $800k Google forbids facial recognition in Google Glass for privacy reasons Wintersmith - another static site generator The global cyber game Lahana!!! Getting started with login verification (Twitter 2FA) Liquidmatrix Staff Projects The Liquidmatrix Vegas Party- You've asked when and where - that'd be "We don't know yet" and "The week of Blackhat/BSides/DEFCON". You can beg your way onto the list by sending an email to vegas2013party@liquidmatrix.org. The BSidesLV Ticket Give-away- Three tickets up for grabs: best original piece of artwork incorporating a security rock star; bonus points for using a unicorn best rap song about a major breach best poem describing a vendor DERP Judging will be done by The Liquidmatrix Intern. Mocking will be done by us. I'd suggest you start buying a vote early. Email your submission to bsideslv2013@liquidmatrix.org The Security Conference Library Contribute to the Strategic Defense Execution Standard (#SDES) and you'll be Doing Infosec Right in no time. If you're interested in helping out with openCERT.ca, drop a line to info@openCERT.ca Upcoming Appearances: James Training (with Rich Mogull) and Matt Speaking at BHUSA. Dave will be speaking at SC Congress Toronto and attending Black Hat, DEF CON, Secure Asia in Manila and Security Congress 2013. Matt and Wil will be at Blackhat/DEF CON and James, Ben and Dave will be joined by Mike Rothman for SecTor 2013's return of the (canadian) fail panel. In Closing Movie Review -- GoldenEye: The answer is always send a SPIKE everyday is CTF! go set up a team Signing up for a SANS course? Be sure to use the code "Liquidmatrix_150" and save $150 off the course fee! And Liquidmatrix_5 for 5% off a course Seacrest Says: I can't say Z properly Creative Commons license: BY-NC-SA