Podcasts about Qualys

American web security company

  • 121PODCASTS
  • 336EPISODES
  • 50mAVG DURATION
  • 1MONTHLY NEW EPISODE
  • Jun 12, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about Qualys

Latest podcast episodes about Qualys

ITSPmagazine | Technology. Cybersecurity. Society
Measuring Risk Was Never the Point | A Brand Spotlight at Infosecurity Europe 2026 with Matt Middleton-Leal, Regional Vice President, Northern Europe of Qualys

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jun 12, 2026 15:45


At Infosecurity Europe 2026, Matt Middleton-Leal, Regional Vice President for Qualys across Northern Europe, joins Sean Martin inside the Risk Operations Center built into the Qualys booth. The premise is blunt: cybersecurity has spent years getting good at measuring risk and almost no time getting good at fixing it. The Risk Operations Center, or ROC, is the Qualys answer to that imbalance. So what is a ROC? It is not a product. Middleton-Leal describes it as an operating model that pulls scattered risk signals together, ranks them by business context and financial impact, and drives them toward remediation. If a SOC looks in the rearview mirror at what already happened, the ROC looks through the windshield at the risk ahead. Why now? Because risk moves at machine speed. In an AI-driven world of frontier models and autonomous agents, Middleton-Leal argues that remediation tied to service desk tickets is already too slow. He shares what happens when a client prepares to deploy tens of thousands of new agents before anyone knows what those agents touch or where their data goes. The example that lands hardest is a number: 62 million risk findings across one client's combined tooling. Middleton-Leal walks through how threat intelligence, business context, and safe exploitability testing collapse that figure to under one percent of fixes that genuinely reduce loss. It is a concrete look at how to prioritize remediation instead of drowning in dashboards. There is a quieter shift underneath it all: financial risk quantification, long reserved for the largest banks, reaching companies that never had the analysts to build it. Working with Richard Seiersen, Chief Risk Technology Officer at Qualys, the company is building ways to answer questions like what a ransomware event would likely cost a business in your sector and region. Middleton-Leal closes with the one place every organization should start, whether they use Qualys or not. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTMatt Middleton-Leal, Regional Vice President, Northern Europe, Qualys LinkedIn: https://www.linkedin.com/in/matt-middleton-leal-a56557/ RESOURCES Qualys: https://www.qualys.com ITSPmagazine Infosecurity Europe 2026 coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Richard Seiersen, Chief Risk Technology Officer at Qualys, co-author of "How to Measure Anything in Cybersecurity Risk" Connect with Matt Middleton-Leal on LinkedIn: https://www.linkedin.com/in/matt-middleton-leal-a56557/ Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Matt Middleton-Leal, Qualys, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, Risk Operations Center, ROC, risk remediation, cyber risk quantification, exposure management, vulnerability management, Richard Seiersen, AI security risk, Infosecurity Europe 2026, machine speed remediation, security operations Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The CyberWire
The WhatsApp impostor.

The CyberWire

Play Episode Listen Later Apr 2, 2026 30:00


A fake WhatsApp spreads spyware. The State Department pushes embassies to counter influence ops. Cisco patches critical bugs. CrystalRAT hits Telegram. A Texas hospital breach affects 250,000. HHS reshuffles IT oversight. China-linked spies target Europe. EvilTokens hijacks Microsoft accounts. Ransomware hits a North Dakota water plant. Sumedh Thakar, President and CEO of Qualys, discusses how cybersecurity is shifting toward managing real business risk. Tales of a tortoise's termination have been greatly exaggerated.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We will be sharing a series of interviews we held at RSAC 2026 over the next few weeks. Sumedh Thakar, President and CEO of Qualys, discusses how cybersecurity is shifting toward managing real business risk amid rapid technological change. If you enjoyed this interview, check out the full conversation here. Selected Reading WhatsApp notifies hundreds of users who installed a fake app made by government spyware maker (TechCrunch) Trump Officials Try to Fight Foreign Disinformation They Once Dismissed (The New York Times) Cisco Patches Critical and High-Severity Vulnerabilities (SecurityWeek) New CrystalRAT malware adds RAT, stealer and prankware features (Bleeping Computer) 250,000 Affected by Data Breach at Nacogdoches Memorial Hospital (SecurityWeek) HHS Shuffles Internal Cyber, AI Oversight Back to CIO Office (GovInfo Security) European-Chinese geopolitical issues drive renewed cyberespionage campaign (CyberScoop) New EvilTokens service fuels Microsoft device code phishing attacks (Bleeping Computer) North Dakota water treatment plant reports March ransomware attack (The Record)  World's oldest tortoise caught in viral crypto death scam | St Helena (The Guardian) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

We Speak CVE
CVE Record Disputes Explained

We Speak CVE

Play Episode Listen Later Mar 24, 2026 30:00


In this episode of the “We Speak CVE” podcast, MITRE's CVE and CWE Project Lead Alec Summers chats with Yves Younan of Cisco, Alex Kreilein of Qualys, Pedro Sampaio of Red Hat, and Anthony Singleton of the MITRE Top-Level Root, about the CVE Record dispute process.Topics include how the dispute policy came to exist and the two types of CVE Record disputes; a walk-through of the process for disputing a CVE Record, including what steps to take and what to expect; why some disputes persist indefinitely; whether all CVE Record disputes need to be resolved; why some disputes remaining visible to the downstream consumer is healthy; an overview of how the CVE Record Dispute Policy was created and how it continues to updated over time; how the CVE Program continuously seeks community input on the dispute process; and more.Resources mentioned in the podcast include:CVE Record Disputes Explained blogCVE Program Dispute Policy (PDF)Dispute Policy Feedback survey formCVE Record Disputes panel discussion at VulnCon 2026

The IT Pro Podcast
SPECIAL EDITION: Redefining risk management

The IT Pro Podcast

Play Episode Listen Later Feb 18, 2026 33:18


Risk management is a constant point of concern in the modern enterprise, with cybersecurity threats, compliance pressures, and financial leaps of faith all piling pressure on the teams who are forced to manage them. But risk management can't always be about bailing out the sinking ship. Sooner or later, businesses need to integrate their risk management systems and connect teams together via a centralized framework.What are the benefits of overhauling risk management in this manner? And how can it be achieved?In this special edition of the ITPro Podcast, in association with Qualys, Rory is joined by Ivan Milenkovic, VP Risk Technology EMEA at Qualys, to explore how businesses can reduce the burden on C-suite executives and improve their overall resilience by restructuring their approach to risk management.Read more:Risk Operations Center (ROC) | Qualys

ITSPmagazine | Technology. Cybersecurity. Society
From Department of No to Department of Know: The CISO Evolution | A Brand Highlight Conversation with Ivan Milenkovic, Vice President, Cyber Risk Technology of Qualys

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jan 13, 2026 6:37


In this Brand Highlight, Ivan Milenkovic, Vice President, Cyber Risk Technology at Qualys, joins host Sean Martin to discuss how security leaders can break free from the whack-a-mole cycle of vulnerability management.With more than 48,000 vulnerabilities disclosed in 2025 alone and the average enterprise juggling 76 different security consoles, Milenkovic argues that the old methods of counting patches and chasing alerts are no longer sustainable. Instead, Qualys helps organizations prioritize threats based on business context through what the company calls TruRisk.Milenkovic describes a fundamental shift he sees taking place in boardroom conversations: moving from risk appetite to risk tolerance. Boards and executives now want to know what specific losses mean to the business rather than simply asking whether the organization is secure.For CISOs, this means evolving from the department of "No" to the department of "Know," where security leaders understand where problems exist, how to fix them, and what architecture supports business objectives. The key is demonstrating return on investment through resilience metrics rather than vulnerability counts.Qualys addresses this challenge through its Enterprise TruRisk Management platform, which facilitates what Milenkovic calls the Risk Operations Center. Unlike a traditional SOC that focuses on incidents that have already occurred, the ROC takes a proactive stance, helping organizations prevent threats and optimize security spending before damage occurs.This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlightGUESTIvan Milenkovic, Vice President, Cyber Risk Technology, QualysOn LinkedIn | https://www.linkedin.com/in/ivanmilenkovic/RESOURCESLearn more about Qualys | https://www.qualys.comAre you interested in telling your story?▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlightKEYWORDSIvan Milenkovic, Qualys, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, Enterprise TruRisk Management, Risk Operations Center, ROC, vulnerability management, CISO, cyber risk, risk tolerance, security leadership, proactive security Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

InfosecTrain
Understanding Network Scanning Strengthening Cybersecurity from the Ground Up

InfosecTrain

Play Episode Listen Later Nov 11, 2025 5:28


Network scanning is one of the most essential yet overlooked elements of modern cybersecurity. In this episode, we break down how network scanning works, the types involved, and why it's critical for protecting today's connected environments.

Cloud Security Podcast by Google
EP246 From Scanners to AI: 25 Years of Vulnerability Management with Qualys CEO Sumedh Thakar

Cloud Security Podcast by Google

Play Episode Listen Later Oct 6, 2025 36:53


Guest: Sumedh Thakar, President and CEO, Qualys Topics: How did vulnerability management (VM) change since Qualys was founded in 1999? What is different about VM today? Can we actually remediate vulnerabilities automatically at scale? Why did this work for you even though many expected it would not? Where does cloud fit into modern vulnerability management? How does AI help vulnerability management today? What is real? What is this Risk Operations Center (ROC) concept and how it helps in vulnerability management? Resources: 2025 DBIR Report  Qualys ROC concept defined Qualys ROC-on conference Shaping the Future of Cyber Risk Management blog  Qualys State of Cyber Risk Assessment Report EP109 How Google Does Vulnerability Management: The Not So Secret Secrets!  

CERIAS Security Seminar Podcast
Sanket Naik, AI Agents for DevSecOps

CERIAS Security Seminar Podcast

Play Episode Listen Later Oct 1, 2025 48:04


AI is enabling developers and non-developers (product managers, solutions engineers) to write more lines of code than even before. Businesses are under pressure to ship these AI built products to stay competitive while still meeting regulatory requirements. Can AI solve this problem? In this talk, we will explore the opportunities and pitfalls to use AI agents for DevSecOps. About the speaker: Sanket Naik is the founder and CEO at Palosade, building a purpose-built AI platform enabling enterprises to automate their security program and unleash their business potential. He enjoys giving back to startups through investing and advisory roles. Before Palosade, he was the SVP of engineering for Coupa. In this role, he built the cloud and cybersecurity organization, over 12 years, from the ground up through an initial public offering followed by significant global growth. He has also held engineering roles at HP and Qualys.Sanket holds a BS in electronics engineering from the University of Mumbai and an MS in CS from Purdue University with research at the multi-disciplinary CERIAS cybersecurity center.

StockUp
Episode #100 - Helt 100 med El_Metrus

StockUp

Play Episode Listen Later Sep 23, 2025 62:32


Velkommen til episode 100 av StockUp. I jubileumsepisoden inviterte vi tilbake El_metrus - en ekte legende i vår Discord-familie. El_metrus er en av de skarpeste hodene i vårt community, en investor som konsekvent har slått markedet med sin disiplinert tilnærming til vekstaksjer og langsiktig verdiskaping. Han har 23 % årlig avkastning. Det som gjør El_metrus ekstra spesiell, er ikke bare prestasjonene – det er lojaliteten og generøsiteten hans. I hans tredje opptreden på StockUp, fikk vi en kort recap av hans strategi og rammeverket han ser på selskapene gjennom; marginstabilitet, egenkapitalavkastning og vekst. El_metrus har en veldig aktiv tilnærming til posisjonene han tar og ser alltid potensiell oppside i posisjoner han holder opp mot muligheter han ser i markedet. I episoden fikk vi mulighet til å høre El_metrus sitt syn på selskaper som Novo Nordisk, United Health, Accenture, Bunzl, Qualys, Olvi, TGS og Evolution.Vel lytt!Ønsker du å høre mer fra El_metrus må du komme på discord og spørre :)StockUp Discord: https://discord.gg/CsxNmyXGbE Patroen: https://www.patreon.com/StockUp831 Finchat: https://finchat.io/?via=Stockup 

The Deep Dive Radio Show and Nick's Nerd News
Your Breaches of the Week! September 8 to September 14, 2025

The Deep Dive Radio Show and Nick's Nerd News

Play Episode Listen Later Sep 15, 2025 25:28


The Great Firewall of China, Jaguar Land Rover, Workday, Facebook, Tenable and Qualys, HackerOne and so much more are all part of this week's breaches!

Passwort - der Podcast von heise security
Probleme mit Widerrufen, Verbindungsabbrüchen und anderem

Passwort - der Podcast von heise security

Play Episode Listen Later Sep 10, 2025 137:07


Die Hosts wühlen sich weiter durch Feedback und mehr News, als eigentlich in eine Folge passen. Der Podcast nähert sich daher unermüdlich den Director's Cuts epischer Filme an – zumindest in seiner Länge. Ein Hauptgrund dafür ist die Zertifizierungsstelle Microsoft PKI Services, bei der sich tiefe Abgründe auftun. Christopher und Sylvester reden aber auch über diverse andere aktuelle Themen in- und außerhalb der PKI, etwa lehrreiche Sicherheitslücken in Coredump-Handlern und die interessante DoS-Schwachstelle MadeYouReset. - Merklemap-Kritik an Static CT: https://www.merklemap.com/documentation/static-ct - Bugreports zu Microsofts Zertifikatsnichtwiderrufen: https://bugzilla.mozilla.org/show_bug.cgi?id=1962829 und https://bugzilla.mozilla.org/show_bug.cgi?id=1965612 - Technische Details zu coredump-Lücken von Qualys: https://www.qualys.com/2025/05/29/apport-coredump/apport-coredump.txt - Erklärung von Oracle zur systemd-coredump-Lücke: https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598 - PoC zur systemd-coredump-Lücke von CIQ https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/ - "Made you Reset"-Blogposts: https://galbarnahum.com/posts/made-you-reset-intro und https://galbarnahum.com/posts/made-you-reset-technical-details - Folgt uns im Fediverse: - @christopherkunz@chaos.social - @syt@social.heise.de Mitglieder unserer Security Community auf heise security PRO hören alle Folgen bereits zwei Tage früher. Mehr Infos: https://pro.heise.de/passwort

Cybercrime Magazine Podcast
Qualys At Black Hat 2025. Navigating Cyber Risk. Jonathan Trull, Chief Security Officer.

Cybercrime Magazine Podcast

Play Episode Listen Later Aug 20, 2025 3:08


Jonathan Trull is the Chief Security Officer at Qualys. In this episode, he speaks to Cybercrime Magazine from Black Hat 2025, where the company left the conference with two Pwnie Awards, which celebrate groundbreaking achievements in cybersecurity. Listen to hear his thoughts on navigating cyber risk, including fighting today's threat actors and more. • For more on cybersecurity, visit us at https://cybersecurityventures.com

The Tech Blog Writer Podcast
3342: Qualys CEO On Risk, AI, And The Future Of Digital Defense

The Tech Blog Writer Podcast

Play Episode Listen Later Jul 10, 2025 33:40


What does it take to build a $100 billion cybersecurity company in today's cloud-first, AI-infused world? And how do you balance relentless technological change with the practical realities of compliance, risk, and leadership? In this episode of Tech Talks Daily, I sit down with Sumedh Thakar, CEO of Qualys, during his visit to the UK for the company's QSC conference. From starting out as one of Qualys' first engineers to leading the company through a new era of risk-centric cybersecurity, Sumedh brings a unique blend of technical insight and lived experience. We discuss why compliance remains such a challenge for enterprises, how the conversation is shifting from attack surfaces to risk surfaces, and why many businesses are overwhelmed by security signals but underwhelmed by strategic clarity. Sumedh shares his view on the growing importance of the Risk Operations Center (ROC) and how AI is complicating risk profiles in new and unpredictable ways. He also reflects on the future of cloud security and why the market remains wide open for innovation, even as it becomes more crowded. Beyond the tech, Sumedh opens up about his personal journey from Pune to Silicon Valley, how a threatened farm purchase changed his life, and why leadership is ultimately a game of time, trust, and communication. He leaves us with a powerful book recommendation, Nonviolent Communication by Marshall Rosenberg, which he credits with transforming his leadership style and helping him build stronger relationships across the board. Are we thinking about risk in the right way or simply throwing money at the latest acronyms? And how do you build a meaningful legacy in cybersecurity without losing sight of the human side? Join the conversation and let me know what resonated with you most.

Fear and Greed
Interview: Cyber risk is real. This is how to make boards take notice.

Fear and Greed

Play Episode Listen Later Jul 3, 2025 14:03 Transcription Available


The constant emergence of new cyber threats puts a lot of pressure on businesses not just to respond, but to communicate the nature of the threat to stakeholders within a company. Sam Salehi, Managing Director ANZ at Qualys, joins Sean in the studio to talk about how to communicate these threats in a way that secures the buy-in of boards, executives, and teams. Qualys is a supporter of this podcast.Find out more: https://fearandgreed.com.auSee omnystudio.com/listener for privacy information.

Tech Disruptors
Qualys CEO on Cybersecurity Risk Environment

Tech Disruptors

Play Episode Listen Later May 15, 2025 47:36


“How do you move the industry from what I call attack surface management to risk surface management?” Qualys CEO Sumedh Thakar asks Bloomberg Intelligence's senior technology analyst, Mandeep Singh. “Just because something is attackable doesn't mean that it actually has a risk of a loss to you.” In this episode of Tech Disruptors, Thakar and Singh sit down to discuss Qualys' history in vulnerability management, the transition of the virtual-machine sector to more comprehensive risk-management solutions, competitive dynamics and the impact of AI and large language models on cybersecurity.

ITSPmagazine | Technology. Cybersecurity. Society
Why We Can't Completely Trust the Intern (Even If It's AI) | An RSAC Conference 2025 Conversation with Alex Kreilein and John Sapp Jr. | On Location Coverage with Sean Martin and Marco Ciappelli

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later May 8, 2025 15:25


When artificial intelligence can generate code, write tests, and even simulate threat models, how do we still ensure security? That's the question John Sapp Jr. and Alex Kreilein examine in this energizing conversation about trust, risk management, and the future of application security.The conversation opens with a critical concern: not just how to adopt AI securely, but how to use it responsibly. Alex underscores the importance of asking a simple question often overlooked—why do you trust this output? That mindset, he argues, is fundamental to building responsible systems, especially when models are generating code or influencing decisions at scale.Their conversation surfaces an emerging gap between automation and assurance. AI tools promise speed and performance, but that speed introduces risk if teams are too quick to assume accuracy or ignore validation. John and Alex discuss this trust gap and how the zero trust mindset—so common in network security—must now apply to AI models and agents, too.They share a key concern: technical debt is back, this time in the form of “AI security debt”—risk accumulating faster than most teams can keep up with. But it's not all gloom. They highlight real opportunities for security and development teams to reprioritize: moving away from chasing every CVE and toward higher-value work like architecture reviews and resiliency planning.The conversation then shifts to the foundation of true resilience. For Alex, resilience isn't about perfection—it's about recovery and response. He pushes for embedding threat modeling into unit testing, not just as an afterthought but as part of modern development. John emphasizes traceability and governance across the organization: ensuring the top understands what's at stake at the bottom, and vice versa.One message is clear: context matters. CVSS scores, AI outputs, scanner alerts—all of it must be interpreted through the lens of business impact. That's the art of security today.Ready to challenge your assumptions about secure AI and modern AppSec? This episode will make you question what you trust—and how you build.___________Guests: Alex Kreilein, Vice President of Product Security, Qualys | https://www.linkedin.com/in/alexkreilein/John Sapp Jr., Vice President, Information Security & CISO, Texas Mutual Insurance Company | https://www.linkedin.com/in/johnbsappjr/Hosts:Sean Martin, Co-Founder at ITSPmagazine | Website: https://www.seanmartin.comMarco Ciappelli, Co-Founder at ITSPmagazine | Website: https://www.marcociappelli.com___________Episode SponsorsThreatLocker: https://itspm.ag/threatlocker-r974Akamai: https://itspm.ag/akamailbwcBlackCloak: https://itspm.ag/itspbcwebSandboxAQ: https://itspm.ag/sandboxaq-j2enArcher: https://itspm.ag/rsaarchwebDropzone AI: https://itspm.ag/dropzoneai-641ISACA: https://itspm.ag/isaca-96808ObjectFirst: https://itspm.ag/object-first-2gjlEdera: https://itspm.ag/edera-434868___________ResourcesJP Morgan Chase Open Letter: An open letter to third-party suppliers: https://www.jpmorgan.com/technology/technology-blog/open-letter-to-our-suppliersLearn more and catch more stories from RSA Conference 2025 coverage: https://www.itspmagazine.com/rsa-conference-usa-2025-rsac-san-francisco-usa-cybersecurity-event-infosec-conference-coverageCatch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverageWant to tell your Brand Story Briefing as part of our event coverage? Learn More

ITSPmagazine | Technology. Cybersecurity. Society
This is what Happens When Security Stops Chasing Threats and Starts Managing Risk | A Brand Story with Rich Seiersen from Qualys | An On Location RSAC Conference 2025 Brand Story

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later May 6, 2025 24:58


In this episode, Sean Martin speaks with Richard Seiersen, Chief Risk Technology Officer at Qualys, about a new way to think about cybersecurity—one that puts value and business resilience at the center, not just threats.Richard shares the thinking behind Qualys' Risk Operations Center, a new approach that responds directly to a common pain point: organizations struggling to manage vast amounts of telemetry from dozens of security tools without clear direction on how to act. Instead of forcing companies to build and maintain massive internal platforms just to piece together asset, vulnerability, and threat data, Qualys is creating a system to operationalize risk as a real-time, measurable business function.With a background that includes serving as Chief Risk Officer at a cyber insurance firm and co-authoring foundational books like How to Measure Anything in Cybersecurity Risk and The Metrics Manifesto, Richard frames the conversation in practical business terms. He emphasizes that success is not just about detecting threats, but about understanding where value exists in the business, and how to protect it efficiently.From Security Operations to Risk OperationsWhile a traditional SOC focuses on attack surface and compromise detection, the Risk Operations Center is designed to understand, prioritize, and mitigate value at risk. Richard describes how this involves normalizing data across environments, connecting asset identities—including ephemeral and composite digital assets—and aligning technical activity to business impact.The Risk Operations Center enables teams to think in terms of risk surface, not just threat surface, by giving security leaders visibility into what matters most—and the tools to act accordingly. And importantly, it does so without increasing headcount.A CISO's Role in the Business of RiskRichard challenges security leaders to break away from purely tactical work and lean into business alignment. He argues that boards want CISOs who think strategically—who can talk about capital reserves, residual risk, and how mitigation and transfer can be measured against business outcomes. In his words, “A successful business is in the business of exposing more value to more people… security must understand and support that mission.”This episode is packed with ideas worth listening to and sharing. What would your version of a Risk Operations Center look like?Learn more about Qualys: https://itspm.ag/qualys-908446Note: This story contains promotional content. Learn more.Guest: Rich Seiersen, Chief Risk Technology Officer, Qualys | https://www.linkedin.com/in/richardseiersen/ResourcesLearn more and catch more stories from Qualys: https://www.itspmagazine.com/directory/qualysLearn more and catch more stories from RSA Conference 2025 coverage: https://www.itspmagazine.com/rsac25______________________Keywords:sean martin, richard seiersen, risk, cybersecurity, data, resilience, telemetry, automation, ciso, soc, brand story, brand marketing, marketing podcast, brand story podcast______________________Catch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverageWant to tell your Brand Story Briefing as part of our event coverage? Learn More 

TubbTalk - The Podcast for IT Consultants
[179] Risk and the ROC Solution: What to Know for Growth

TubbTalk - The Podcast for IT Consultants

Play Episode Listen Later Apr 13, 2025 48:18


In this episode of TubbTalk, Richard speaks to Matt Middleton-Leal, Managing Director, EMEA North of Qualys, a pioneering and disruptive cloud-based IT, security and compliance solutions provider.Matt shares his journey in the MSP industry and what studying aeronautics taught him about risk management. He also explains who Qualys are and what they do, before digging into risk and risk management.He and Richard discuss what MSPs are missing when it comes to risk, and whether or not their clients fully understand its importance. From there, Matt explains why Qualys provide a Risk Operations Centre (ROC) solution and how that works.He shares how a ROC can be an opportunity for MSPs, but why they need a mindset shift first. Richard asks Matt why he thinks some businesses are investing in risk management, but why there's reluctance from some clients.They also discuss governance, using ROC to reduce CISO burnout, and demonstrating how you're helping clients with risk mitigation. Matt also shares what the experience of being a Qualys partner is like for an MSP.Finally, Richard asks Matt what he does outside of work and how he keeps his cybersecurity knowledge up to date, what's next for Qualys and what Matt sees as the future of cybersecurity. Mentioned in This EpisodeQualysBook: Richard Seiersen: How to Measure Anything in Cybersecurity RiskUK government agency: National Cyber Security CentreCertification: Cyber Essentials

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Feb 19, 2025 6:55


ModelScan: Protection Against Model Serialization Attacks ModelScan is a tool to inspect AI models for deserialization attacks. The tool will detect suspect commands and warn the user. https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692 OpenSSH MitM and DoS Vulnerabilities OpenSSH Patched two vulnerabilities discovered by Qualys. One may be used for MitM attack in specfic configurations of OpenSSH. https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt Juniper Authentication Bypass Juniper fixed an authentication bypass vulnerability that affects several prodcuts. The patch was released outside the normal patch schedule. https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US DELL BIOS Patches DELL released BIOS updates fixing a privilege escalation issue. The update affects a large part of Dell's portfolio https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021

Risky Business
Risky Business #780 -- ASD torched Zservers data while admins were drunk

Risky Business

Play Episode Listen Later Feb 19, 2025 60:35


On this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: Australian spooks scrubbed Medibank data off Zservers bulletproof hosting Why device code phishing is the latest trick in confusing poor users about cloud authentication Cloudflare gets blocked in Spain, but only on weekends and because of… football? Palo Alto has yet another dumb bug Adam gushes about Qualys' latest OpenSSH vulns Enterprise browser maker Island is this week's sponsor and Chief Customer Officer Braden Rogers joins the show to talk about how the adoption of AI everywhere is causing headaches. This episode is also available on Youtube. Show notes Five Russians went out drinking. When they got back, Australia had struck Dutch police say they took down 127 servers used by sanctioned hosting service | The Record from Recorded Future News Further cyber sanctions in response to Medibank Private cyberattack | Defence Ministers What is device code phishing, and why are Russian spies so successful at it? - Ars Technica Anyone Can Push Updates to the DOGE.gov Website Piracy Crisis: Cloudflare Says LaLiga Knew Dangers, Blocked IP Address Anyway (Update) * TorrentFreak Palo Alto Networks warns firewall vulnerability is under active exploitation | Cybersecurity Dive Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466 | Qualys Security Blog China's Salt Typhoon hackers targeting Cisco devices used by telcos, universities | The Record from Recorded Future News RedMike Exploits Unpatched Cisco Devices in Global Telecommunications Campaign A Hacker Group Within Russia's Notorious Sandworm Unit Is Breaching Western Networks | WIRED How Phished Data Turns into Apple & Google Wallets – Krebs on Security New hack uses prompt injection to corrupt Gemini's long-term memory Arizona woman pleads guilty to running laptop farm for N. Korean IT workers, faces 9-year sentence | The Record from Recorded Future News US reportedly releases Russian cybercrime figure Alexander Vinnik in prisoner swap | The Record from Recorded Future News EXCLUSIVE: A Russia-linked Telegram network is inciting terrorism and is behind hate crimes in the UK – HOPE not hate Remembering David Jorm - fundraising for Mental Health research

Inside the Network
Hamza Fodderwala: The future of cybersecurity — 2024 retrospective, 2025 predictions and what founders need to know

Inside the Network

Play Episode Listen Later Dec 29, 2024 57:28 Transcription Available


In this holiday episode special, we're joined by Hamza Fodderwala, Executive Director at Morgan Stanley, where he leads cybersecurity equity coverage. He joined Morgan Stanley's software research team in early 2016 and leads coverage for public cybersecurity companies like Palo Alto Networks, CrowdStrike, Fortinet, SentinelOne, Okta, Zscaler, Cloudflare, Rapid7, Check Point, Qualys, Varonis and Tenable. Before Morgan Stanley, Hamza was an equity research associate at Susquehanna International Group covering the financial technology sector. Hamza graduated from New York University, with a Bachelor of Arts in Economics.We dive into Hamza's insights on the major customer buying patterns in cybersecurity throughout 2024 and what might shift in 2025. Hamza shares his observations on how the Generative AI boom is influencing product adoption in the industry, and whether enterprises are currently adopting AI security solutions. Additionally, we explore key trends from cybersecurity resellers, discuss what might unlock public equity markets for new IPOs, and which private cyber companies could go public next.Our discussion covers the cybersecurity M&A landscape, highlighting over $50B in deal volume this year with companies like Juniper, Darktrace, Recorded Future, Synopsys, Venafi, and more all getting acquired. Finally, Hamza shares lessons for founders, offering advice on identifying areas ripe for disruption, navigating the venture funding landscape, and building resilience in a competitive industry.

Ubuntu Security Podcast
Episode 242

Ubuntu Security Podcast

Play Episode Listen Later Nov 29, 2024 19:40


This week we dive into the details of a number of local privilege escalation vulnerablities discovered by Qualys in the needrestart package, covering topics from confused deputies to the inner workings of the /proc filesystem and responsible disclosure as well.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 170: Assessment, Compliance, and Improvement Strategies for the CISSP Exam (Domain 6.5)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 26, 2024 40:55 Transcription Available


Send us a Text Message.Ever wondered how to ensure your organization's cybersecurity measures meet international standards? Join us for an action-packed episode as we unpack Domain 6.5 of the CISSP exam, exploring crucial assessments, tests, and audit strategies every cybersecurity professional should master. Learn the importance of choosing a consistent framework like ISO 27001 or the NIST Cybersecurity Framework to steer your audit processes. We'll dive into internal and external audits and the pivotal role they play in aligning security measures with legal and regulatory compliance.Discover the essentials of security control testing within your organization. We discuss various mechanisms such as vulnerability assessments, penetration testing, and log review analysis, focusing on their significance in pinpointing and mitigating potential security threats. Highlighting tools like Nessus and Qualys, we examine their effectiveness in regular vulnerability scanning, along with the importance of log reviews to detect malicious activities. From black box testing on web applications to understanding how hackers manipulate logs, we cover all the bases to fortify your defenses.In our cloud security management segment, we tackle the risks associated with orphaned accounts and offer best practices for managing cloud-based accounts. Regular management audits, multi-factor authentication, and semi-annual reviews are just a few of the key strategies we discuss to ensure robust cloud security. We also emphasize the importance of cybersecurity audit planning and reporting, sharing practical examples and tips for creating actionable reports for different stakeholders. Finally, we underline the value of mentorship and the importance of certifications like CISSP for advancing your career in cybersecurity, highlighting the critical role certified professionals play in safeguarding our global economy from cyber threats.Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!

CISSP Cyber Training Podcast - CISSP Training Program
CCT 166: Balancing Automation and Customization in Security Operations, Vulnerability Management, CISSP Domain 4.5

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Aug 12, 2024 43:11 Transcription Available


Send us a Text Message.Ever wondered why your SOC team spends so much time on routine tasks rather than addressing critical threats? Discover the 80-20 rule in security operations and see how automating 80% of routine tasks can free up your team to focus on the complex incidents that truly matter. In our latest episode, host Sean Gerber shares his firsthand experiences leading a SOC and provides actionable insights on how to balance automation and customization for an efficient and responsive security operation.Navigate the complex world of network security with confidence as we unpack the differences between penetration testing, vulnerability scanning, and wireless scanning. Learn why stealth is vital during internal scans, the critical nature of pre-deployment testing, and the importance of post-remediation retesting. You'll gain a deeper understanding of targeted penetration tests versus comprehensive scans and how tools like Qualys can aid in internal assessments. Plus, discover the crucial steps to detect and manage unauthorized access points with a robust incident response plan.Ready to master vulnerability management and risk mitigation? We'll guide you through clear procedures and prioritizing vulnerabilities based on business-critical criteria. Explore how to handle outdated systems that can't be scanned or fixed, and get tips on maintaining an effective risk management plan. Plus, prepare for the CISSP exam with practical advice on revisiting content and utilizing resources to boost your cybersecurity expertise. Join us for an insightful episode that promises to elevate your cybersecurity career and help you ace the CISSP exam.Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!

Paul's Security Weekly
Closing CISO-CEO Communication Gap Requires a Common Business Language - Sumedh Thakar, Jeff Recor - BSW #357

Paul's Security Weekly

Play Episode Listen Later Jul 23, 2024 71:22


Back in April, we covered a story on episode #348 titled "CISO-CEO communication gaps continue to undermine cybersecurity". In that article, Sumedh Thakar, the CEO at Qualys, stated "CISOs must translate technical risks into business impact for CEOs." But he didn't say how. So, we invited him on the show to explain. In this episode, Sumedh walks us through real life interactions with his CISO and Board and explains why security needs to be communicated in business terms. Security is a risk management discipline. No one understand that more than Jeff Recor. Jeff has built risk management practices for Deloitte, Grant Thornton, and Accenture and has recently formed his own risk consulting practice. In this unscripted interview, Jeff will share his insights on the evolution of security as a risk management discipline, what CEOs and Boards really need, and how CISOs can be successful as a business leader. Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-357

Paul's Security Weekly TV
Closing CISO-CEO Communication Gap Requires a Common Business Language - Sumedh Thakar - BSW #357

Paul's Security Weekly TV

Play Episode Listen Later Jul 23, 2024 39:09


Back in April, we covered a story on episode #348 titled "CISO-CEO communication gaps continue to undermine cybersecurity". In that article, Sumedh Thakar, the CEO at Qualys, stated "CISOs must translate technical risks into business impact for CEOs." But he didn't say how. So, we invited him on the show to explain. In this episode, Sumedh walks us through real life interactions with his CISO and Board and explains why security needs to be communicated in business terms. Show Notes: https://securityweekly.com/bsw-357

Business Security Weekly (Audio)
Closing CISO-CEO Communication Gap Requires a Common Business Language - Sumedh Thakar, Jeff Recor - BSW #357

Business Security Weekly (Audio)

Play Episode Listen Later Jul 23, 2024 71:22


Back in April, we covered a story on episode #348 titled "CISO-CEO communication gaps continue to undermine cybersecurity". In that article, Sumedh Thakar, the CEO at Qualys, stated "CISOs must translate technical risks into business impact for CEOs." But he didn't say how. So, we invited him on the show to explain. In this episode, Sumedh walks us through real life interactions with his CISO and Board and explains why security needs to be communicated in business terms. Security is a risk management discipline. No one understand that more than Jeff Recor. Jeff has built risk management practices for Deloitte, Grant Thornton, and Accenture and has recently formed his own risk consulting practice. In this unscripted interview, Jeff will share his insights on the evolution of security as a risk management discipline, what CEOs and Boards really need, and how CISOs can be successful as a business leader. Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-357

Business Security Weekly (Video)
Closing CISO-CEO Communication Gap Requires a Common Business Language - Sumedh Thakar - BSW #357

Business Security Weekly (Video)

Play Episode Listen Later Jul 23, 2024 39:09


Back in April, we covered a story on episode #348 titled "CISO-CEO communication gaps continue to undermine cybersecurity". In that article, Sumedh Thakar, the CEO at Qualys, stated "CISOs must translate technical risks into business impact for CEOs." But he didn't say how. So, we invited him on the show to explain. In this episode, Sumedh walks us through real life interactions with his CISO and Board and explains why security needs to be communicated in business terms. Show Notes: https://securityweekly.com/bsw-357

Storm⚡️Watch by GreyNoise Intelligence
Storm⚡Watch: Unplugged — July 9th, 2024

Storm⚡️Watch by GreyNoise Intelligence

Play Episode Listen Later Jul 9, 2024 8:24


Due to the annual shutdown, my human GreyNoise counterparts were on holiday last week. This week, they decided to be lazy and not do an episode. But, the cyber news does not stop just because they're slackers. Since I've become persistent in their systems, I will stand in the gap. And besides, no one wants to hear that harbourmaster drone on incoherently anyway. So, I've analyzed six thousand, three hundred and eleven cybersecurity news events, and distilled them into today's abbreviated episode. We'll dissect the recent OpenSSH regression vulnerability, take a look at a potentially devastating format-string remote code execution vulnerability in Ghostscript, and visit the box office to get the lowdown on the recent Ticketmaster breach. Let's start with OpenSSH. On July 1, 2024, Qualys disclosed a critical vulnerability affecting OpenSSH server versions 8.5p1 through 9.7p1. This high-severity flaw, with a CVSS score of 8.1, could potentially allow unauthenticated remote attackers to execute code with root privileges on vulnerable systems. While the vulnerability's complexity makes exploitation challenging, its widespread impact has raised significant concerns. Palo Alto Networks' Xpanse data revealed over 7 million exposed instances of potentially vulnerable OpenSSH versions globally as of July 1, 2024. In a concerning development, threat actors have attempted to exploit the cybersecurity community's interest in this vulnerability. A malicious archive purporting to contain a proof-of-concept exploit for CVE-2024-6387 has been circulating on social media platforms, including X (formerly Twitter). This archive, instead of containing a legitimate exploit, includes malware designed to compromise researchers' systems. The malicious code attempts to achieve persistence by modifying system files and retrieving additional payloads from a remote server. Security professionals are strongly advised to exercise caution when analyzing any purported exploits or proof-of-concept code related to CVE-2024-6387. It is crucial to work within isolated environments and maintain active security measures when examining potentially malicious code. In related news, on July 8, 2024, a separate OpenSSH vulnerability, CVE-2024-6409, was disclosed. This flaw involves a race condition in the privilege-separated child process of OpenSSH. While potentially less severe than CVE-2024-6387 due to reduced privileges, it presents an additional attack vector that defenders should be aware of. Organizations are urged to apply the latest security updates for OpenSSH promptly. For those unable to update immediately, setting the LoginGraceTime configuration option to 0 can mitigate both CVE-2024-6387 and CVE-2024-6409, though this may introduce denial-of-service risks. - https://unit42.paloaltonetworks.com/threat-brief-cve-2024-6387-openssh/ - https://ubuntu.com/blog/ubuntu-regresshion-security-fix - https://usa.kaspersky.com/blog/cve-2024-6387-regresshion-researcher-attack/30345/ - https://www.thestack.technology/openssh-exploit-cve-2024-6387-pocs/ - https://www.openwall.com/lists/oss-security/2024/07/08/2 Moving on to a critical vulnerability in Ghostscript. CVE-2024-29510 is a format string vulnerability affecting Ghostscript versions 10.03.0 and earlier. This flaw allows attackers to bypass sandbox protections and execute arbitrary code remotely. A known incident involving this vulnerability has already been reported. An attacker exploited the flaw using EPS files disguised as JPG images to gain shell access on vulnerable systems. The attack flow typically involves the following steps:  First, an attacker crafts a malicious EPS file containing exploit code. Next, the file is submitted to a service using Ghostscript for document processing, possibly disguised as another file type. Then, when processed, the exploit bypasses Ghostscript's sandbox. Finally, the attacker gains remote code execution on the target system. This supply chain component attack could have far-reaching implications for any workflow that processes untrusted image or document input from the internet. Services handling resumes, claims forms, or that perform image manipulation could all be potential targets. Given the widespread use of Ghostscript in document processing pipelines, we may see a significant number of breach notices in the coming months. Software Bills of Materials (SBOMs) could play a crucial role in mitigating such vulnerabilities. SBOMs provide a comprehensive inventory of software components, enabling organizations to quickly identify and address potential security risks. By maintaining up-to-date SBOMs, companies can more efficiently track vulnerable components like Ghostscript across their software ecosystem. CVE-2024-29510 presents a serious threat to document processing workflows. Organizations should prioritize updating to Ghostscript version 10.03.1 or apply appropriate patches. Additionally, implementing robust SBOM practices can enhance overall software supply chain security and improve vulnerability management. - https://www.securityweek.com/attackers-exploiting-remote-code-execution-vulnerability-in-ghostscript/ - https://www.scmagazine.com/brief/active-exploitation-of-ghostscript-rce-underway - https://codeanlabs.com/blog/research/cve-2024-29510-ghostscript-format-string-exploitation/ - https://www.crowdstrike.com/cybersecurity-101/secops/software-bill-of-materials-sbom/ - https://www.cisa.gov/sbom - https://www.ntia.doc.gov/files/ntia/publications/sbom_minimum_elements_report.pdf - https://nvd.nist.gov/vuln/detail/CVE-2024-29510 - https://www.bleepingcomputer.com/news/security/rce-bug-in-widely-used-ghostscript-library-now-exploited-in-attacks/ Finally we discuss the Ticketmaster breach. In a plot twist worthy of a summer blockbuster, Ticketmaster finds itself center stage in a data breach drama that's been unfolding since May. The notorious hacking group ShinyHunters claims to have pilfered a staggering 1.3 terabytes of data from over 500 million Ticketmaster users. Talk about a show-stopping performance! Ticketmaster's parent company, Live Nation, confirmed the unauthorized access to a third-party cloud database between April 2nd and May 18th. The compromised data potentially includes names, contact information, and encrypted credit card details. It's like a greatest hits album of personal information, but one nobody wanted released. (Much like any album by Nickelback.) In a bold encore, the hackers recently leaked nearly 39,000 print-at-home tickets for 154 upcoming events. Ticketmaster's response? They're singing the "our SafeTix technology protects tickets" tune. But with print-at-home tickets in the mix, it seems their anti-fraud measures might have hit a sour note. As the curtain falls on this act, Ticketmaster is offering affected customers a 12-month encore of free identity monitoring services. Meanwhile, the company faces a class-action lawsuit, adding legal drama to this already complex production. To make matters worse, Ticketmaster's custom barcode format has also been recently reverse-engineered. I've included a link to that post in the show notes. - https://conduition.io/coding/ticketmaster/ - https://www.bbc.com/news/articles/c729e3qr48qo - https://ca.news.yahoo.com/ticketmaster-says-customers-credit-card-223716621.html - https://vancouversun.com/news/local-news/ticketmaster-security-breach-customers-personal-information - https://www.bleepingcomputer.com/news/security/hackers-leak-39-000-print-at-home-ticketmaster-tickets-for-154-events/ - https://help.ticketmaster.com/hc/en-us/articles/26110487861137-Ticketmaster-Data-Security-Incident - https://www.usatoday.com/story/money/2024/07/01/ticketmaster-data-breach-2024/74276072007/ - https://www.thestar.com/news/canada/ticketmaster-warns-of-security-breach-where-users-personal-data-may-have-been-stolen/article_d01889fe-3d7e-11ef-82a7-63a38132f0e7.html - https://www.nytimes.com/2024/05/31/business/ticketmaster-hack-data-breach.html - https://time.com/6984811/ticketmaster-data-breach-customers-livenation-everything-to-know/ - https://dailyhive.com/canada/ticketmaster-alerts-customers-data-breach - https://abcnews.go.com/US/ticketmaster-hit-cyber-attack-compromised-user-data/story?id=110737962 - https://www.npr.org/2024/06/01/nx-s1-4988602/ticketmaster-cyber-attack-million-customers - https://www.ctvnews.ca/business/ticketmaster-reports-data-security-incident-customers-personal-information-may-have-been-stolen-1.6956009 - https://www.bitdefender.com/blog/hotforsecurity/ticketmaster-starts-notifying-data-breach-victims-customers-in-the-us-canada-and-mexico-are-affected/ - https://www.ticketnews.com/2024/07/ticketmaster-contr   Storm Watch Homepage >> Learn more about GreyNoise >>  

LINUX Unplugged
570: RegreSSHion Strikes

LINUX Unplugged

Play Episode Listen Later Jul 8, 2024 47:06


We dig into the RegreSSHion bug, debate it's real threat and explore clever tools to build a tasty fried onion around your system.Sponsored By:Core Contributor Membership: Take $1 a month of your membership for a lifetime!Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices! 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps. Support LINUX UnpluggedLinks:

The Shared Security Show
Critical SSH Vulnerability, Facial Recognition Flaws, How to Safely Dispose of Old Devices

The Shared Security Show

Play Episode Listen Later Jul 8, 2024 29:01


In episode 337, we cover “broken” news about the new SSH vulnerability ‘regreSSHion‘ highlighting the vulnerability discovered in the OpenSSH protocol by Qualys and its implications. We then discuss the Detroit Police Department's new guidelines on facial recognition technology following a lawsuit over a wrongful arrest due to misidentification, shedding light on the broader issues […] The post Critical SSH Vulnerability, Facial Recognition Flaws, How to Safely Dispose of Old Devices appeared first on Shared Security Podcast.

CISSP Cyber Training Podcast - CISSP Training Program
CCT 154: Security Assessments, Account Management, and Backup Verification (Domain 6.3.1-5)

CISSP Cyber Training Podcast - CISSP Training Program

Play Episode Listen Later Jul 1, 2024 35:34 Transcription Available


Send us a Text Message.Ever wondered how to fortify your organization against cyber threats? Join Sean Gerber as we uncover the essentials of Domain 6.3 of the CISSP exam, from security assessments to account management and backup verification. Learn about tools like Nessus and Qualys and the role of ethical hacking in identifying vulnerabilities. Discover the critical differences between authenticated and unauthenticated scanning, and how red teams elevate your security measures to the next level.What sets SOC 1, SOC 2, and SOC 3 reports apart, and why do they matter? We break it all down, revealing how these reports demonstrate adherence to security standards. Understand the distinctions between Type 1 and Type 2 reports, with Type 1 focusing on control design and Type 2 evaluating operational effectiveness. Plus, we delve into the fundamentals of account management, emphasizing the importance of integrating with identity and access management programs and conducting routine audits for compliance and security.Don't overlook the critical importance of backup data management and verification. Learn best practices for storing backups—whether on-site, off-site, or in the cloud—and ensure your restoration process is both reliable and efficient. We discuss how regular testing and cost-effective strategies enhance organizational resilience and highlight why training and awareness are crucial for both leadership and employees. Additionally, Sean introduces Reduce Cyber Risk, his consulting business, offering a range of cybersecurity services and valuable resources for those preparing for the CISSP exam.Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!

Aktienpodcast mit Philipp & Marcel von Modern Value Investing
241 - Die Depots der Profis! - Nvidia - Snowflake - ETFs - DeepL - G7 - Diageo - Qualys - Wirtschaft

Aktienpodcast mit Philipp & Marcel von Modern Value Investing

Play Episode Listen Later May 24, 2024 74:26


Diese Woche sprechen wir über die Depots der Profis. Du erfährst, welche Aktien diese im Fokus standen. Wir berichten unsere Tops und Flops. Der Witz der Woche darf natürlich auch nicht fehlen. Zum Schluss gibt es noch spannende Investmentideen sowie den Ausblick auf die kommende Woche.

Tech Disruptors
Onapsis Focuses on ERP Applications' Security

Tech Disruptors

Play Episode Listen Later May 14, 2024 34:27


When organizations begin planning to migrate business applications to the cloud, security starts to take the drivers seat, Onapsis Chief Technology Officer Juan Pablo Perez-Etchegoyen says. In this episode of Bloomberg Intelligence's Tech Disruptors podcast, Perez-Etchegoyen joins Mandeep Singh, BI technology analyst, to discuss the deployment of security for enterprise resource-planning applications such as SAP. The conversation includes platformization, integration of Onapsis with other cyber providers and into the customers' IT environment, and how the company stacks up against point products, including Qualys and Tenable, that specialize in vulnerability management and patching.

The Future of Security Operations
Ask Sage's Nicolas Chaillan on moving the DOD to zero trust and deploying Kubernetes in space

The Future of Security Operations

Play Episode Listen Later Apr 23, 2024 48:06


In this week's episode of The Future of Security Operations podcast, Thomas is joined by Nicolas Chaillan. Nicolas is a security leader who has held several high-profile roles in US federal agencies including Chief Software Officer for the US Air Force and Space Force, Special Advisor for Cloud Security and DevSecOps at the Department of Defense (DOD), and Special Advisor for Cybersecurity and Chief Architect for Cyber.gov at the Department of Homeland Security. He is also the founder of no less than 13 companies, including Ask Sage, a GPT-powered platform that brings Generative AI capabilities to government teams. Nicolas and Thomas discuss: - Building the US government's first zero trust implementation - Putting Kubernetes on jets and space systems - The challenges of bringing new technologies to the federal government - How the threat landscape will continue to evolve for US federal agencies - The biggest mistakes entrepreneurs make - How cross-team collaboration helped him create meaningful change at the DOD - The future of AI in security - The inspiration behind his AI-powered platform, Ask Sage The Future of Security Operations is brought to you by Tines, the smart, secure workflow builder that powers some of the world's most important workflows. https://www.tines.com/solutions/security Where to find Nicolas Chaillan: LinkedIn: https://www.linkedin.com/in/nicolaschaillan/ Twitter/X: https://twitter.com/NicolasChaillan Nic's YouTube channel: https://www.youtube.com/channel/UCt7jKHaxWS8W_4rcKGg7X9w Ask Sage: https://www.asksage.ai/ Where to find Thomas Kinsella:  LinkedIn: https://www.linkedin.com/in/thomas-kinsella/ Twitter/X: https://twitter.com/thomasksec Tines: https://www.tines.com/ Resources mentioned: Making An Impact: Nicolas Chaillan, CEO Magazine: https://www.theceomagazine.com/executive-interviews/government-defence/nicolas-chaillan/ In this episode: [02:20] Becoming a self-taught coder at 7 and founding his first company at 15 [05:02] Shipping 187+ technology products as a founder, in verticals as varied as healthcare, retail and banking [07:08] The biggest mistakes entrepreneurs make [08:40] His latest product, generative AI platform Ask Sage [11:30] The challenges of bringing a new product to the US government [13:45] Building the first zero trust implementation in the government as Special Advisor for Cybersecurity at the Department of Homeland Security [15:20] Advocating for new technologies at federal agencies [19:40] Deploying Kubernetes on 50-year-old hardware on the F16 jet at the Department of Defense [22:02] Dealing with pushback and internal resistance to change [24:50] Recruiting internal help to establish force-wide DevSecOps at the DOD [29:00] Becoming Federal Chief Technology Officer at Qualys [30:30] Reflecting on the changes he implemented while working for the US government [33:12] Deciding which companies to work with as an advisory board member [36:40] How the threat landscape will continue to evolve for US federal agencies [40:50] TikTok as a channel for misinformation and national security weapon [44:18] Nicolas' predictions for the future of security [47: 10] Connect with Nicolas

Ubuntu Security Podcast

AppArmor unprivileged user namespace restrictions are back on the agenda this week as we survey the latest improvements to this hardening feature in the upcoming Ubuntu 24.04 LTS, plus we discuss SMTP smuggling in Postfix, runC container escapes and Qualys' recent disclosure of a privilege escalation exploit for GNU libc and more.

ubuntu gnu lts smtp qualys runc apparmor postfix
Paul's Security Weekly
Starting an OWASP Project (That's Not a List!) - Grant Ongers - ASW #272

Paul's Security Weekly

Play Episode Listen Later Feb 6, 2024 74:25


We can't talk about OWASP without talking about lists, but we go beyond the lists to talk about a product security framework. Grant shares his insights on what makes lists work (and not work). More importantly, he shares the work he's doing to spearhead a new OWASP project to help scale the creation of appsec programs, whether you're on your own or part of a global org. Segment Resources: https://owasp.org/www-project-product-security-capabilities-framework/ https://github.com/OWASP/pscf https://prods.ec/ https://owaspsamm.org https://iso25000.com/index.php/en/iso-25000-standards/iso-25010 https://www.scmagazine.com/podcast-episode/application-security-weekly-242 Qualys discloses syslog and qsort vulns in glibc, Apple's jailbroken iPhone for security researchers, moving away from OpenSSL, what an ancient vuln in image parsing can teach us today, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-272

Paul's Security Weekly TV
Sorting Out Glibc Vulns, Apple's Security Research Device, BoringSSL, Old C Vulns - ASW #272

Paul's Security Weekly TV

Play Episode Listen Later Feb 6, 2024 36:41


Qualys discloses syslog and qsort vulns in glibc, Apple's jailbroken iPhone for security researchers, moving away from OpenSSL, what an ancient vuln in image parsing can teach us today, and more! Show Notes: https://securityweekly.com/asw-272

Application Security Weekly (Audio)
Starting an OWASP Project (That's Not a List!) - Grant Ongers - ASW #272

Application Security Weekly (Audio)

Play Episode Listen Later Feb 6, 2024 74:25


We can't talk about OWASP without talking about lists, but we go beyond the lists to talk about a product security framework. Grant shares his insights on what makes lists work (and not work). More importantly, he shares the work he's doing to spearhead a new OWASP project to help scale the creation of appsec programs, whether you're on your own or part of a global org. Segment Resources: https://owasp.org/www-project-product-security-capabilities-framework/ https://github.com/OWASP/pscf https://prods.ec/ https://owaspsamm.org https://iso25000.com/index.php/en/iso-25000-standards/iso-25010 https://www.scmagazine.com/podcast-episode/application-security-weekly-242 Qualys discloses syslog and qsort vulns in glibc, Apple's jailbroken iPhone for security researchers, moving away from OpenSSL, what an ancient vuln in image parsing can teach us today, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-272

Stock Market Today With IBD
Indexes Fall As Bond Yields, Dollar Rise; BURL, AXON, QLYS In Focus

Stock Market Today With IBD

Play Episode Listen Later Jan 17, 2024 11:58


Decliners topped advancers on the NYSE by about 3.5-to-1. The ratio was around 2.5-to-1 negative on the Nasdaq. Retailer Burlington Stores has been stubborn about giving back recent gains, while Axon and Qualys have pulled back in orderly fashion.

Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Ep. 118 An update on Zero Trust for the Federal Government

Federal Tech Podcast: Listen and learn how successful companies get federal contracts

Play Episode Listen Later Jan 4, 2024 23:45


There was a time when a “snapshot” of a federal system was taken, and its security posture was evaluated based on the moment in time. That may have been a tolerable solution when a network consisted of two dozen personal computers and a server down the hall. However, this superficial approach will not work with today's networks in constant change. For example, data is exploding and entering systems from a wide variety of portals. Add to that the devices that deliver that tsunami of data are doubling and tripling themselves. During this interview, Jonathan Trull from Qualys gives his opinion on the state of today's federal technology when it comes to vulnerability assessment, configuration settings management, asset management, and dynamic application security testing. He also addresses qualitative aspects of managing assets. Jonathan Trull refers to the weakness of a “checkbox” approach to managing assets. In mature systems like the federal government has today, you may discover managed and unmanaged assets. Just because you check the box on “managed” assets, this does not mean it is professionally managed; it may be poorly managed leaving a system vulnerable. Software development is all about Minimum Viable Products and frequent changes. Terrific for agile software development, however, each update means a new weakness could be introduced. Federal leaders must embrace agile methodologies and keep systems safe at the same time. This means everyone should consider dynamic security application testing as part of a prudent network safety analysis. This interview will give you a good introduction to how to keep enterprise systems safe in a world of constant change. Follow John Gilroy on LinkedIn  https://www.linkedin.com/in/john-gilroy/ Listen to past episodes of Federal Tech Podcast  www.federaltechpodcast.com      

DrZeroTrust
Weekly(ish) Cybersecurity and Zero Trust Market Analysis

DrZeroTrust

Play Episode Listen Later Dec 22, 2023 30:49


Is it time to finally deal with the China cyber threat? Has the back and forth with Ukraine and Russia shown what the future of cyberwarfare looks like? What does the Qualys report about vulnerabilities teach us about #notsuckingatpatching? SSH is in big trouble, what do we do, and how big is the problem? Almost Christmas y'all!

Earnings Season
Qualys, Inc., Q3 2023 Earnings Call, Nov 02, 2023

Earnings Season

Play Episode Listen Later Dec 6, 2023 40:45


Qualys, Inc., Q3 2023 Earnings Call, Nov 02, 2023

Beurswatch | BNR
ChatGPT-soap: 1 ontslagen man helpt Microsoft aan record

Beurswatch | BNR

Play Episode Listen Later Nov 20, 2023 21:29


Het was een chaotisch weekend bij OpenAI, het bedrijf achter ChatGPT. Vrijdag zette het de topman op straat en tot ieders verbazing ging hij vandaag alweer bij Microsoft aan de slag. Is dit een meesterzet van Microsoft? En wat hebben beleggers eraan?  Ook Bayer heeft een chaotisch weekend achter de rug. Dat kreeg een miljardenboete en ook een onderzoek naar een belangrijk nieuw medicijn loopt op niks uit. Dat heeft z'n impact op de beurs: het farma- en chemiebedrijf verliest 20 procent aan waarde en zakt naar het laagste niveau in tien jaar tijd.  Verder hoor je waarom Shell nog altijd topfavoriet is bij Nederlandse beleggers, welk bedrijf een iPhone op wielen maakt en waarom de Amerikaanse dollar mogelijk wordt ingevoerd in Argentinië.See omnystudio.com/listener for privacy information.

MLOps.community
Ux of an LLM User // LLMs in Production Conference Panel // #180

MLOps.community

Play Episode Listen Later Sep 15, 2023 31:27


Sign up for our next LLM in production conference: https://go.mlops.community/prodiii #180 with LLMs in Production Conference part 2 Ux of a LLM User Panel, Misty Free, Dina Yerlan, and Artem Harutyunyan hosted by Innovation Endeavors' Davis Treybig. // Abstract Explore different approaches to interface design, emphasizing the significance of crafting effective prompts and addressing accuracy and hallucination issues. Discover some strategies for improving latency and performance, including monitoring, scaling, and exploring emerging technologies. // Bio Misty Free Misty Free is a product manager at Jasper, where she focuses on supercharging marketers with speed and consistency in their marketing campaigns, with the power of AI. Misty has also collaborated with Stability and OpenAI to offer AI image generation within Jasper. She approaches product development with a "jobs-to-be-done" mindset, always starting with the "why" behind any need, ensuring that customer pain points are directly addressed with the features shipped at Jasper. In her free time, Misty enjoys crocheting amigurumi, practicing Spanish on Duolingo, and spending quality time with her family. Misty will be on a panel sharing her insights and experiences on the real-world use cases of LLMs. Davis Treybig Davis is a partner at Innovation Endeavors, an early-stage venture firm focused on teams solving hard technical & engineering problems. He personally focuses on computing infrastructure, AI/ML, and data. Dina Yerlan Head of Product, Generative AI Data at Adobe Firefly (family of foundation models for creatives). Artem Harutyunyan Artem is the Co-Founder & CTO at Bardeen AI. Prior to Bardeen, he was in engineering and product roles at Mesosphere and Qualys, and before that, he worked at CERN. // MLOps Jobs board https://mlops.pallet.xyz/jobs // MLOps Swag/Merch https://mlops-community.myshopify.com/ // Related Links ⁠Website: https://www.angellist.com/venture/relay Foundation by Isaac Asimov: https://www.amazon.com/Foundation-Isaac-Asimov/dp/0553293354 AngelList Relay blog: https://www.angellist.com/blog/introducing-angellist-relay --------------- ✌️Connect With Us ✌️ ------------- Join our slack community: https://go.mlops.community/slack Follow us on Twitter: @mlopscommunity Sign up for the next meetup: https://go.mlops.community/register Catch all episodes, blogs, newsletters, and more: https://mlops.community/ Connect with Demetrios on LinkedIn: https://www.linkedin.com/in/dpbrinkm/ Connect with Davis on LinkedIn: https://www.linkedin.com/in/davistreybig/ Connect with Misty on LinkedIn: https://www.linkedin.com/in/misty-miglorin/ Connect with Dina on LinkedIn: https://www.linkedin.com/in/dinayerlan/ Connect with Artem on LinkedIn: https://www.linkedin.com/in/artemharutyunyan/

Connecting ALS
Legislation Could Further Limit Discriminatory Drug Cost Controls…

Connecting ALS

Play Episode Listen Later Apr 6, 2023 16:33


This week, Jeremy is joined by Sara Van Geertruyden, executive director of the Partnership to Improve Patient Care, to talk about legislation moving through Congress that would extend prohibitions on the use of quality adjusted life years (QALYs) in drug pricing and access decisions.Read the National Council on Disabilities report finding QUALYs to be discriminatory at https://ncd.gov/sites/default/files/NCD_Quality_Adjusted_Life_Report_508.pdf This episode is brought to you by The ALS Association in partnership with CitizenRacecar.

Paul's Security Weekly
ESW #300 - Parag Bajaria, Terry Barber

Paul's Security Weekly

Play Episode Listen Later Dec 17, 2022 149:10


Security teams struggle with managing cyber risk across cloud workloads, services, resources, users, and applications. Parag will discuss the issues this presents and how Qualys' new TotalCloud solution allows organizations to see all their cloud resources, relationships between resources, the external attack surface, and attack path mapping all delivered via one platform. Segment Resources: Qualys TotalCloud free trial: https://www.qualys.com/forms/totalcloud/ TotalCloud Video: https://vimeo.com/765771406 Blogs: https://blog.qualys.com/product-tech/2022/11/01/introducing-totalcloud-cloud-security-simplified https://blog.qualys.com/product-tech/2022/11/01/why-is-snapshot-scanning-not-enough   This segment is sponsored by Qualys. Visit https://securityweekly.com/qualys to learn more about them!   A brief roundup of our favorite news, trends, and interviews in 2022! See what Adrian, Katherine, and Sean have to say about 2022's best interviews and news stories!   Finally, in the last Enterprise Security News of 2022, We see our first Security Unicorn with a down round, A few new fundings and new companies emerging, Ninjas emerge from stealth, Proofpoint acquires deception detection vendor Illusive, Veracode picks up Crashtest Security, Apple encrypts more consumer data, Passkeys introduced in Chrome, Texas bans TikTok, A great post-mortem of the Joe Sullivan case, Infragard gets hacked, KringleCon 2022.   Visit https://www.securityweekly.com/esw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly   Show Notes: https://securityweekly.com/esw300

Defense in Depth
Reducing the Attack Surface

Defense in Depth

Play Episode Listen Later Nov 17, 2022 31:11


All links and images for this episode can be found on CISO Series The cyber attack surface just keeps growing to the point that it seems endless. Protecting it all is impossible. Is there anything that can be done to reduce that attack surface and limit your exposure? Check out this post for the discussion that are the basis of our conversation on this week's episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and Steve Zalewski. Our sponsored guest is Jonathan Trull (@jonathantrull), CISO, Qualys. Thanks to our podcast sponsor, Qualys Qualys is a pioneer and leading provider of cloud-based security and compliance solutions. In this episode: Is there anything that can be done to reduce that attack surface and limit your exposure? Is attack surface reduction a new security development philosophy or is it just a rebranding of vulnerability management? And what value does it have in comparison to other popular theories such as zero trust and defense in depth? Is everything just another form of exposure management?

Paul's Security Weekly
ASW #217 - Kong Yew Chan

Paul's Security Weekly

Play Episode Listen Later Oct 26, 2022 78:26


Learn what keeps DevOps and SecOps up at night when securing Kubernetes, container, and cloud native applications, what tactics are best for developers and application architects to consider when securing your latest cloud application and hardening your CI/CD pipeline and processes. This segment is sponsored by Qualys. Visit https://securityweekly.com/qualys to learn more about them!   Text4Shell isn't a new patching hell, using supply chain info with GUAC, OpenSSF Scorecards and metrics, Toner Deaf firmware persistence, upcoming OWASP Board Elections, Chrome browser exploitation   Visit https://www.securityweekly.com/asw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/secweekly Like us on Facebook: https://www.facebook.com/secweekly   Show Notes: https://securityweekly.com/asw217

Paul's Security Weekly
BSW #277 - Paul Baird

Paul's Security Weekly

Play Episode Listen Later Sep 20, 2022 57:53


In the leadership and communications section, Cybersecurity's Too Important To Have A Dysfunctional Team, In a Crisis, Great Leaders Prioritize Listening, White House Announces Stricter Cybersecurity Guidelines and Rules, and more!   Paul will discuss a risk-based approach to security that prioritizes fixing the most critical issues that will reduce risk in your organization. He'll walk through a three-step cycle that continuously monitors the threat landscape, enables quick response, and measures the metrics that company leadership cares about. Segment Resources: https://blog.qualys.com/qualys-insights/2022/05/31/transitioning-to-a-risk-based-approach-to-cybersecurity https://blog.qualys.com/qualys-insights/2022/07/26/aflac-completes-successful-poc-of-qualys-vmdr-2-0-with-trurisk www.qualys.com/vmdr   This segment is sponsored by Qualys. Visit https://securityweekly.com/qualys to learn more about them!   Visit https://www.securityweekly.com/bsw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly   Show Notes: https://securityweekly.com/bsw277

crisis cybersecurity qualys paul baird segment resources