Hardware authentication device supporting MFA
POPULARITY
The episode highlights a structural shift in web traffic patterns: machine-driven activity, particularly from AI agents, now makes up the majority of website visits and increasingly determines how businesses are discovered and engaged online. Companies such as Cloudflare, Human Security, and SimilarWeb provide data showing automated and AI-initiated web events have surpassed human visits, with a significant acceleration in the role of AI-driven assistants and agents in both discovery and transaction processes. Quantitative evidence from Cloudflare indicates that automated traffic now accounts for nearly 58% of all page loads. Human Security's report shows an 8,000% increase in AI agent-driven traffic year over year. SimilarWeb data cited by TechCrunch finds Google's AI-generated answers now appear in 43% of searches, up from 15% in the previous year. Additionally, ESW's commercial announcement describes end-to-end automated purchasing workflows using AI agents, moving transaction control further from human users. Supporting developments include technical shifts in how web authentication and authorization are managed, with protocols such as the Model Context Protocol deprecating session-based trust in favor of per-request authorization with attached metadata. Yubico's security key update similarly enables authentication for specific actions rather than broad sessions. Microsoft's entrance into machine identity and agent security management with its own specialized model, combined with alliances like NVIDIA's Open Secure AI Alliance, signal organizing at platform scale, raising questions about who ultimately governs admission policies for AI-driven interactions. For MSPs and technology leaders, these changes increase operational dependence on platform and identity providers, reduce direct control over business discoverability and transactability, and pose new risks in reporting, fraud exposure, and client relationship management. Default platform settings may dictate client market access without their knowledge, shifting the role of the provider from technical implementer to advisor and policy manager. To minimize risk, providers must inventory and periodically review clients' current admissions policies for machine traffic, disentangle discoverability from transactional permissions, and proactively track changes imposed by vendors and platforms. 00:00 Most Traffic Isn't Human 03:49 Why the Login Is Breaking 06:36 Microsoft Wants the Doorway 10:07 Why Do We Care? Supported by: LogMeIn TimeZest
According to research by IBM, just 16% of AI initiatives have achieved scale. Why? Because few organizations have the structure and data to support long-term AI investments. So, how do you build an AI-ready system? Riley Rogers: Welcome to the Win/Win Podcast. I’m your host, Riley Rogers. Join us as we dive into changing trends in the workplace and how to navigate them successfully. Here to discuss this topic is Rich Weymer, Senior Director of Go-To-Market Strategy and Transformation at Yubico. Thank you so much for joining us today, Rich. I’m super excited to have you here to dig into all the expertise that you’re gonna bring to the table. As we’re kicking off, I’d love if you could just tell us a little bit about yourself, your background, and your role. Rich Weymer: Yeah. First off, thanks for having me. A repeat customer with Highspot, so excited to get invited to this, as we’ve worked with your organization for some time now. Like you said, Rich Weymer. I’ve spent time pretty much so in tech for most of my professional career in one form or fashion, from my earlier career days at Microsoft working in consumer goods, where I’ve worked on video games, your Office products, all your devices, through where I’m at today in the security world. RR: Well, amazing, and bravo, tech veteran. Not easy. RW: Yeah. It looks a lot different today than it did when I started, that’s for sure. RR: And I think that is exactly what we’re gonna talk about today. But before we go into where the world of tech has been to where we are today, I’d love if you could give us a little bit of foundational context for folks who might not be familiar with Yubico. Could you give us a little walkthrough of who your company is, what you do, who you serve? RW: Yeah. So Yubico does phishing resistance hardware MFA, which basically means we ship you a little bitty key that helps control access to all your online portals and logins and everything along those lines. RR: As somebody who is password challenged, I certainly see the value of that one. I wish we had a wonderful little bitty key that got me set up for success every single day. One thing that I think you set up early on is that Yubico, and pretty much every other organization in the industry, is moving fast, and it has to. Security in this day and age is harder than ever. And when it comes to working in a fast-moving organization, teams like yours also have to move fast. I’d guess that that pace of change is part of the reason why you have a really forward-looking approach to enablement and to go-to-market strategy. So why do you think it’s important to think critically about how technology can transform traditional workflows, processes that you’re accustomed to, things like that? RW: Again, to your point, things are moving so fast right now. That’s the biggest underlying factor that organizations really need to think through. Decisions that you’re making today are almost obsolete by the time you’re done signing the paperwork on whatever decisions or procurement you’re going through. So you need to be really thoughtful about the foundations that you’re building, the integrations that you’re gonna lean on, and the partners that you’re gonna select that are gonna be around for the long run. Measure twice, cut once, and also understand that there’s different types of decisions that you’re gonna be making. I use the analogy of a hat, a haircut, or a tattoo. What type of decision are you making when you’re thinking about your technologies? If it’s a hat, you can switch it in and out real quick. If it’s a haircut, maybe it takes a little bit of time to unwind. And those tattoos are the ones that you just can’t change. They’re gonna be– They’re– You’re gonna live with them forever. So you really gotta just understand the lens that you’re making the decisions through, as well as having an industry understanding of where things are heading. And as you look at your partners, thinking, “Hey, at the pace at which innovation is happening, is this someone that’s gonna be relevant six months, 12 months, 18 months from now?” RR: I have not heard that decision-making framework before, hat, haircut, tattoo. RW: It’s an easy one, yeah. A lot of organizations think everything’s a tattoo. So you make every decision like it’s the last decision you’re ever gonna make in that space. And it’s right for a lot of things, but framing it goes a long way, especially when you’re trying to move fast. Being able to categorize those decisions pretty quickly goes a long way. RR: Yeah. And it helps you avoid the problem of when everything’s important, nothing is. You mentioned systems, data, processes, having the right tools in place to move quickly. So with that perspective in mind, how are you thinking about layering on AI? RW: I think about it every day and night, in every meeting I’m sitting in, and every conversation I’m having, and every free minute when I’m thinking about work. The big thing is automation and AI for the sake of AI, and automation for the sake of automation, it really doesn’t mean anything unless you have a strong foundation and an understanding of your data. So to me, it all just boils down to a strong foundational data set and understanding what to measure and what moves your business, and then building around that first and foremost before you do anything else. RR: What do you need in that foundation before you can start building AI on top of it in order for those initiatives to be successful? RW: If I were to think through how I structure this, there’s no shortage of ways to measure the business, but landing on one that’s influential and helps you adjust the dials as you go is really important. So the way I operate is through the lens of sales velocity, which is a time-tested mathematical problem to give you a temperature check on how the business is doing. It’ll let you know whether you’re going up, down, left, right, staying center, or whatever it is. But where organizations stop is they stop at the top four measurements, which, if you think of sales velocity, is open opportunities, average deal size, win rate, and then you divide that by your deal cycle length. That gives you a daily throughput, which tells you part of the story because you can help understand your forecasting. When you take your close one business, you can use that to forecast days left in the quarter, what those numbers would look like. But where it gets really powerful, and what I think a lot of organizations haven’t spent the time to do, is go deeper on the leveling of those metrics. So if you think through the process lines, L1 is your executive metric. That’s the all-up number. Your L2s are your leadership numbers, where your managers need to understand those. But your L3, four, five, six, and you can keep going down the rabbit hole, really start impacting how your frontline folks operate. One of the things we’ll talk about today is AI Role Play, and when we think of it, we look at diagnosing issues in our win rates, and we think, “How is our competitive wins doing? What are we, we get very, very granular in how we look at those.” And then we can actually start layering on recommendations and automation. So we do that across probably close to 100 different metrics through the various layers that are our leading indicators. And this really helps us when we think through automation of where we go from here, ’cause once we understand those, we know how are we doing against certain competitors? Are we getting the right amount of MQLs? Are we talking about the right things? Do we get caught up in legal, security? We can understand all those different variables of the business, and then we can take a proactive approach to coaching where we need to coach, and then adjusting the business where we need to adjust the business. And you can’t really do that unless you have that entire foundation laid out and actually understand what all those levers are. So to me, taking the time to do that is really just beyond critical. RR: Yeah. Yeah. You know what you need to do, and you can start driving really aggressively against it, which I– it sounds like you alluded to an example there with AI Role Play, you’re doing the work to do. In that, you’re beginning to layer some of these new technologies, new tools on top of that foundation. What were some of those first use cases that you prioritized, and why did you start where you did? RW: I think the first win you always wanna go for is really a practical application of any new technology and how that can move the needle for the business. So when I think of practical applications, I think of AI Role Play as being a very early one. As an enablement team and a training team, how many times have people walked through certification programs, the one-on-ones with managers, all the Role Plays, all the back and forth and the headaches and the objectivity that goes into those exercises. That’s just a quick win that you can pick up and take care of almost all of that. The time saving alone and the cost of having a manager do these one-on-ones time and time again, it just drains an organization when every organization right now is trying to be lean, mean, focused on sales efficiency. So anything we can do to give back and level the team up, I think is just a no-brainer. So AI Role Play is a huge one for us. We looked at a lot of different places. We tried a lot of different things, and we landed on the Highspot implementation of that because it’s important to be able to do that stuff, but also it has to be within the context of everything you’re doing and all the content and everything that you do have. It can’t be this standalone siloed thing that happens in the background. We need to bring it to the forefront. Yeah, those are the really practical first-step wins that I’ve been excited about. RR: Yeah, and that’s such a good example of mapping it back to those foundational levers. The path there is very clear, I think. RW: Yeah, absolutely. Think of a competitive– your competitive intelligence programs. You do all this work understanding your competitors. Now you can understand when a seller of yours struggles with insert competitor X, Y, or Z. You can identify those trainings, you can recommend the trainings, you can verify they’ve been through them, and then if that’s not working, then you can escalate to coaching and go a little bit deeper from there. So the foundation of the data will help you identify that stuff, and then you start applying the technologies. That’s how you go fix the gap. And then you can monitor it and just keep it going, almost near real time, which is incredible. A lot of the time, organizations are really spending most of their time hearing yesterday’s weather. And when I mean that, I think of, you do a QBR, you go through a quarter, you spend 30 days doing the QBR. At the end of the QBR, you find the problems, you take 30 more days to figure out what the underlying problems are, then you spend 120 days fixing those problems. Then you’re six months removed from what the problem was, and now you got a whole new set of problems that you’re not even keeping up with the business. So being able to identify these things, move quickly, and make recommendations really fast is incredible in the amount of time it buys back an organization to execute, and that you’re focused on the right things at the right time. RR: I’d be curious to hear a little bit about, you mentioned a handful of teams there in some of the early AI Role Play rollout and piloting. How did you start thinking about who you wanted to test this with, the kinds of pilots you wanted to build, and how has that going so far? RW: We tested globally as a global organization. We tried US-based, EMEA, APJ folks. We took a look at various groups from various geographical regions because adoption’s an uptick, and accountability is different at the global scale. The use cases really were tied around what’s our biggest blind spots, and what do we not know, and how do we validate that? As a group that has a BDR team, an SDR team as an example, if you have sellers that don’t wanna work with their BDRs ’cause they’re not confident that their BDRs are competent, then here’s a great way to say, “Hey, actually, we’ve already been them– we’ve taken them through the ringer. We’ve seen that they’re able to demonstrate this stuff, and honestly, we’re building scenarios that are harder for them to get through than you actually deal with, with customers.” So we can stress test the teams, and then sellers don’t respond to customers with ABC answers. They have to be able to be versed in these conversations, so being able to do that was a huge unlock for us, because folks aren’t practicing with their paycheck. Well, the worst place you wanna go figure this stuff out is in front of a customer, so give someone a very safe space to go practice and cut their teeth, and they will just accelerate if they get behind it and really try this stuff out. So yeah, find the high ROI cases, double down on those, share that experience, be vocal about it, and make sure others feel it. Then yeah, that’s how you just get that adoption and the needle moving. RR: Something that I feel like is not as spoken about when it comes to training, Role Plays, et cetera, all of that stuff, is now you have this trust between your counterparts, and you have more of this connective tissue purely because of that, which is really interesting, and I’ve not, I don’t think, heard anyone speak to that element of it before. So curious if you could give me a little bit more of a sense of what that has done for you guys. RW: Yeah. And, as I mentioned, I’ve– I’m five-ish years into the security business, and this is just a business built on trust. So we have to gain the trust of our customers. It’s important in any sales cycle. It’s a hundredfold more important when you’re talking about the security of your organization. So I think intrinsically our– the businesses are highly trust-driven with the folks that they work with, even internally. So, if you think through customer journeys, from trusting they’re landing the right messaging and marketing, to the right message that BDRs are delivering, our sellers deliver it, talking about the right things and delivering the proposals towards the outcomes that the customers are expecting, to how your account team then goes and manages that account or gets ready for renewals. There has to be that thread of trust across those because each one sets one up for failure if not done correctly. And having a verified way of saying, “Hey, I can trust that my coworkers that are working upstream for me are doing the right things and they are competent,” that’s only gonna make you deliver and do better in your particular role, and it’s gonna want you to step your game up, too. RR: Sometimes I feel like folks present a strategy the way it’s working out for them, and I have a thoughtful response to it. But in this case, the only thing I have to say is that’s so cool. It’s really, really cool to see all the different ways that this can show up for an organization beyond what we expect. RW: If you were to turn the clock back two years, AI-based Role Play, that was beyond the bleeding edge. There wasn’t even an edge. It was so far out of the realm. But these things come up quickly, and you wanna be able to jump on ’em and move on ’em. Again, it’s just moving so fast that you have to have that trust and have a team around you that’s willing to build on the successes you’ve had in a past life. So it does take time to get to that point. It doesn’t happen overnight. It gets quicker, that’s the thing, ’cause now, if you think through how you go through a launch in a past life, go back two years: you spin up the marketing machine, they come up with the slides, you host a call, you do a webinar, you send the field out, say, “Go figure it out.” If you’re lucky, you did Role Plays with the managers, you had a competency test, you sat down, maybe you brought some external resources in to actually manage this. And now with technology, you can scope it, build it, deploy it, have everybody through it in a few weeks, and you can actually verify that people can do these things, where in a past life, just none of that existed. You can build trust faster and move quicker today because the technologies enable that stuff. It’s not the, I’ve got a six-month sales cycle, so I don’t know what my sales look like, or I don’t know how well things are going until six months down the line when you’re actually seeing the end-of-line conversions. You just move so much faster right now. It’s, yeah, really exciting. RR: Okay. So we’ve touched on, I think, a lot of some of the granular detail, and I think gotten a picture of what work at Yubico looks like right now. And I think it has been what sounds like a busy few months to get to this point. So since making some of these changes, being really thoughtful about building out your foundation, starting to layer in those early AI use cases, what impact have you seen on things like seller efficiency, time savings, productivity, anything like that? RW: We are cutting so much time out of the administrative burden of our team. It’s hard to put an exact number on it, but we’re looking at reducing sales cycles by upwards of 25% this year. Where if you think through a longer sales cycle on the security side, where things can take six, seven, eight months, if you can carve out a month back on those processes, it unlocks a lot of organizational capacity. So we are heavy on how we are doing that this year, and sales efficiency is one of our big topics for this year. And ideally, in a perfect world, you have the right team that, as you give efficiency time back and give them time to focus on selling, they go out and sell more. You can cut their day down to two hours a day, but what are they gonna do with the rest of the hours of those days to actually go get after it? So we’re cutting time out of their workload, making things easier on them, and then how are we surfacing the latest and greatest new opportunities and more guidance to them, to be a little bit more honed on where to go and focus on the stuff that technology’s not replacing right now, which is the human interaction and the conversations you have to have with your buyers. So that’s our goal today, it’s just every single day, how do we chip away, chip away, chip away? And I think we’re doing a pretty, pretty solid job of that right now. And things that take hours, three, four, five hours to do, you can do in a button click these days. So on a 40-hour week, if that’s all you work, that would be nice. But if you’re doing 40 hours a week and you’re cutting four or five hours out, 10%, 12% of your week is a huge give back on a timing perspective. So we are, yeah, really excited about all that work right now. RR: You mentioned that 25% reduction, which you said, “That’s a solid, that’s solid progress.” I would call that more than solid progress, but that’s just me. Would you say that part of that or some of that could be attributed to that improved ability to practice those conversations and show up better when you’re actually having them live? RW: Absolutely. There’s the process side of house, which is where we can carve a lot of time out, but the competency within that process goes a long way. Just the basics. Can you get somebody to set that follow-up call? Don’t let the customer off the call until you have a next step booked. Even just little things like that, that you get off the call and then it takes you a couple days to schedule that next meeting. You just get rid of coaching that stuff out. Those basics that every seller always knows about, that adds up when you’re thinking enterprise-wide. That goes a long way. So again, foundational data, even just looking at the basics and doing really good at the basics and training people to that, you’re gonna find time back. RR: To my earlier point about a lot of people are excited but don’t quite know what to do, that’s a very specific example of what can you coach to meaningfully? How can you use Role Play to help you train away those bad behaviors that decrease your velocity, decrease your momentum, and in turn cause that chain reaction down the line? So with all this work in mind, what do you think the future of go-to-market, of enablement, looks like at Yubico? What’s next? RW: Ooh, that’s the multi-multi-multi-million dollar question. Someone who’s been around tech for a while, you see patterns in where things are going. I challenge everybody that I talk to about some form of initiative, or obviously a lot of AI discussions today. But if you challenge things from a first-principles perspective, why are you even doing these things? And I think that is a question that organizations need to ask themselves, is why are you doing this, and why are you doing it this way? Does that even make sense in tomorrow’s world of where things are heading? It’s how are you driving decisions? How are you recommending actions? And how are you actually activating on the data and the information that you have? I think that’s where go-to-market goes. It becomes less understanding and reading yesterday’s weather, as I say, and it takes that data and makes it actionable and pushes us forward versus just catches us up, which is also very, very exciting because the things that we thought were out of reach six months ago are in reach now. RR: For people listening who might be, with that last sentence, feeling a little bit inspired but also uncertain, like, oh gosh, how do I keep pace? What would you say to leaders in tech and in other spaces who feel pressured to do AI, perform the thing, layer it into their programs where they can, but aren’t sure where to start? What would you– What advice would you give them, having done it yourself? RW: Start. That’s the key. It sounds silly, but everybody kinda has this not really sure where to start, and that’s okay. I think you just gotta start. First and foremost, you have to just dabble a little bit, get your feet wet, and it all starts to come clear. If you’re thinking through the models that are out there, ask it questions, use it to teach you what you don’t know and where to go. But really it’s your thought partner in how you use these things. You have questions? Ask it questions. You get stuck? Ask it why you’re stuck. Ask it wh– it can do a lot of the things that I think would really surprise people, that will help them head down the right direction. And again, we’re– I say it jokingly, we’re not protein folding. It’s not that crazy, the stuff that we’re doing. You’ll see that there’s a lot of people that have been successful, and you can go a long way just asking the right questions. Don’t be afraid. Do things in a smart way. Make sure your identities are locked down. Shout out, Yubico. Make sure that you’re working with your security teams and doing the right things, and you’ve got access controls in place, of course. But just start. That’s the biggest thing I could tell people, is just start. You’d be amazed how far you can go. RR: Very inspirational to close with. And also, I think a bitter truth sometimes. It’s very much the best way to learn is by doing. RW: Yeah, 100%. I always get the, “Rich, what should I do?” I’m like, “Well, just ask the question.” Just literally just start. Just start. Just get in there and do it, and get going. And really the other thing I would say, on the starting point, is try and build a system where you give people the guardrails to be successful, get the benefits of AI, but also don’t get in the way and stifle innovation. You wanna empower people to go figure things out. Give them the chance to start as well. If you’re a leader in one of these organizations, empower the folks on the front lines to do these things, because this technology is just peeling out those middle layers. The closer you sit to the customers, the more impactful work you’re gonna be able to do. So get your frontline people working on this stuff. RR: I have to say, I think I said it a couple times, but some really interesting, very actionable things, I think, you shared today. So I really appreciate you taking the time to give us some of those recommendations on how to get started with AI, what’s working for you with AI Role Play, all of the goodness on how to not be scared to get started. RW: Thank you again for having me. This has been a lot of fun. RR: Yeah. To our audience, thank you for listening to this episode of the Win/Win Podcast. Be sure to tune in next time for more insights on how you can maximize go-to-market success with Highspot.
Adieu les codes : Comment la biométrie comportementale va tuer le mot de passe en 2026 Par Régis BAUDOUIN Se souvenir d’une majuscule, d’un chiffre, d’un caractère spécial, et changer le tout tous les trois mois… Cette corvée mentale, vestige des débuts de l’informatique, vit ses toutes dernières heures. En ce mois de juin 2026, le déploiement mondial des standards de connexion de nouvelle génération marque une bascule historique. Menée par l’alliance des géants de la tech, la sécurité ne repose plus sur ce que vous connaissez (un mot de passe), ni même uniquement sur ce que vous êtes (votre empreinte digitale), mais sur la façon dont vous vous comportez. Bienvenue dans l'ère de la biométrie comportementale décentralisée. Le coût de l’oubli : Selon les dernières données du cabinet Gartner, les demandes de réinitialisation de mots de passe représentent encore 20% à 30% de l’ensemble des tickets d’assistance informatique en entreprise, pour un coût moyen estimé à 15€ par intervention. Comment votre téléphone sait que c'est vous La biométrie traditionnelle (Iris, FaceID, empreinte) cartographie des caractéristiques physiques figées. La biométrie comportementale, elle, analyse la dynamique de vos actions en temps réel. C'est une science algorithmique qui transforme vos habitudes inconscientes en une signature mathématique unique. Lorsque vous saisissez votre smartphone, plusieurs dizaines de capteurs physiques s’activent en arrière-plan : L'accéléromètre et le gyroscope : Ils mesurent l’angle exact et la micro-oscillation de votre main. Le capteur de pression tactile : Il évalue la surface de contact de votre pouce et la force exercée sur la dalle en verre. Le rythme de frappe : L’algorithme calcule au millième de seconde près le temps de pression sur chaque touche et l’intervalle de transition entre deux lettres. Les publications de la IEEE Biometrics Council démontrent qu’en analysant seulement 30 à 40 frappes consécutives, un algorithme de notation comportementale atteint un taux de précision supérieur à 99% pour identifier le véritable propriétaire de l’appareil. Pour l’Intelligence Artificielle locale de votre téléphone, votre manière de taper ou de balayer votre fil d’actualité est aussi unique qu’une empreinte génétique. Si un tiers subtilise votre téléphone déverrouillé, le système détecte le changement de rythme en moins de 1,5 seconde et reverrouille l’appareil automatiquement. Source Le standard Passkeys 2.0 de l’alliance FIDO La question légitime que pose une telle innovation est celle de la vie privée. Hors de question que nos rythmes de frappe ou nos données de marche soient envoyés sur des serveurs Cloud pour y être analysés. C’est ici que la prouesse technique prend tout son sens : tout reste en local. Cette révolution s’appuie sur l’évolution des Passkeys, un protocole mondial développé par la FIDO Alliance. Les statistiques d’adoption de la FIDO Alliance pour 2026 révèlent que plus de 12 milliards de comptes en ligne dans le monde supportent désormais cette technologie. Métrique de SécuritéMots de Passe ClassiquesPasskeys + Biométrie ComportementaleSensibilité au Phishing (Hameçonnage)100% (Vulnérable)0% (Immunisé)Temps moyen de connexion~15 secondes~2,5 secondesTaux d’échec à l’authentification~14% (Erreurs de saisie)Moins de 0,5% Le principe repose sur la cryptographie asymétrique. Lorsque vous créez un compte, votre téléphone génère une paire de clés : une clé publique émise au site internet, et une clé privée, jalousement gardée dans l’enclave matérielle sécurisée de votre processeur (le Secure Element). La biométrie comportementale sert uniquement de déclencheur physique pour “libérer” cette clé privée locale. Le site distant ne reçoit jamais vos données comportementales ; il reçoit simplement une validation mathématique. Focus sur les Passkey Le principe fondamental d’un Passkey est qu’il n’existe aucun secret partagé entre vous et le service en ligne (Netflix, votre banque, Amazon). Contrairement à un mot de passe classique, qui est stocké sur les serveurs de l’entreprise (et donc vulnérable aux fuites de données), le Passkey sépare la sécurité en deux éléments mathématiques distincts et indissociables. [ Votre Appareil ] [ Serveur Web ] Clé Privée (Secrète) ── Chiffre le défi ──> Clé Publique (Connue) (Reste dans le SE) (Ne sert qu'à vérifier) Comment se déroule une connexion passkey ? 1.La génération de la paire de clés :Lors de l’inscription. Le gestionnaire de Passkeys de votre appareil génère une clé privée (qui reste enfermée dans la puce physique sécurisée de votre téléphone) et une clé publique (qui est envoyée au serveur du site). 2.L’envoi du défi (Challenge) :Lors de la connexion. Lorsque vous voulez vous connecter, le site web envoie un “défi” (un message aléatoire chiffré) à votre appareil. 3.Le déverrouillage biométrique :Validation locale. Votre appareil vous demande de valider votre identité (via FaceID, empreinte ou la fameuse biométrie comportementale). Cette action locale sert d’autorisation pour réveiller la clé privée. 4.La signature mathématique :Finalisation. La clé privée signe le défi envoyé par le site et renvoie la réponse. Le serveur utilise votre clé publique pour vérifier la signature. Si le calcul correspond, vous êtes connecté. Aucun mot de passe n’a voyagé sur le réseau. Les deux grandes familles de solutions Passkeys L’écosystème de 2026 se divise en deux approches techniques pour gérer ces clés cryptographiques. Elles répondent à des besoins de mobilité ou de sécurité informatique différents. 1. Les Passkeys Synchronisés (Multi-appareils / Synced Passkeys) C’est la solution grand public par excellence, intégrée nativement dans nos systèmes d’exploitation. La clé privée est stockée dans le trousseau Cloud du constructeur (Apple iCloud Keychain, Google Password Manager, Microsoft Account). Le fonctionnement : Si vous créez un Passkey sur votre iPhone, il est automatiquement disponible sur votre Mac ou votre iPad via iCloud. Le mécanisme de secours : Si vous perdez votre smartphone, vos Passkeys ne sont pas perdus : ils sont restaurés dès que vous vous reconnectez à votre compte cloud principal avec une authentification forte. Le cas du cross-platform : Si vous êtes sur un PC Windows et voulez vous connecter à un site avec le Passkey de votre iPhone, le PC affiche un QR Code. Votre iPhone le scanne, vérifie via une liaison Bluetooth de proximité que les deux appareils sont dans la même pièce, et valide la connexion. 2. Les Passkeys Matériels Liés (Single-device / Hardware-bound Passkeys) Cette approche est privilégiée par les entreprises, les banques ou les profils à haute visibilité (journalistes, politiciens). La clé privée est générée à l’intérieur d’un composant matériel dont elle ne pourra jamais sortir, interdisant toute copie dans le cloud. Les clés de sécurité physiques : Les clés USB/NFC (comme les YubiKeys de Yubico) matérialisent ce principe. La clé privée est scellée dans la puce de l’objet. Pour se connecter, il faut impérativement insérer la clé ou la badger contre son téléphone. Le niveau de sécurité supérieur : Même si votre compte iCloud ou Google est piraté, personne ne peut voler vos Passkeys matériels car ils n’existent nulle part sur internet. Les acteurs du marché des passkey en 2026 Le marché des solutions s’est considérablement structuré autour de trois grands types d’acteurs : Les natifs (Les OS) : Apple, Google et Microsoft fournissent l’infrastructure de base gratuite. C’est transparent pour l’utilisateur mais cela tend à verrouiller ce dernier dans leur écosystème respectif. Les gestionnaires indépendants (Cross-platform) : Des logiciels comme 1Password, Dashlane ou l’alternative open-source Bitwarden permettent de stocker et de synchroniser vos Passkeys de manière agnostique (fonctionne aussi bien entre un téléphone Android et un navigateur Safari sur Mac). Les solutions d’infrastructure (B2B) : Des plateformes comme Okta ou Ping Identity déploient ces architectures au sein des réseaux d’entreprises pour supprimer définitivement le risque de piratage interne. Le Passkey résout définitivement la faille numéro un de la sécurité informatique : l’erreur humaine. Un algorithme ne peut pas se faire berner par un faux site d’hameçonnage (phishing), car la clé publique est mathématiquement liée au nom de domaine exact du site. Si l’URL change d’une seule lettre, l’appareil refuse tout simplement de signer le défi. Sécurité absolue et friction zéro Pour l’utilisateur comme pour l’économie numérique, les bénéfices de cette numérisation invisible de la sécurité sont colossaux. Immunité totale contre le Phishing : Le rapport annuel de Verizon sur les fuites de données rappelle que 74% des cyberattaques impliquent encore un facteur humain (vol d’identifiants ou ingénierie sociale). N’ayant plus de mot de passe à taper, vous ne pouvez plus vous le faire voler par un faux email ou un site miroir. L’accessibilité universelle : Pour les personnes âgées ou en situation de handicap, la fin des barrières de saisie de codes complexes supprime la principale cause de l’exclusion numérique. La rentabilité pour les plateformes : Les géants du e-commerce constatent déjà une hausse de 5% à 7% des taux de conversion lors de l’étape de paiement depuis que les processus d’authentification contraignants ont été remplacés par la validation passive en arrière-plan. L’authentification invisible Le mot de passe était une anomalie ergonomique, une interface artificielle qui forçait l’humain à parler le langage de la machine. En 2026, la technologie est enfin devenue assez mature pour s’adapter à l’humain. En observant nos mouvements et nos rythmes sans jamais les trahir, nos appareils transforment nos gestes du quotidien en la plus sûre des clés. La haute sécurité n’est plus une contrainte, elle est devenue une seconde nature. Références et publications scientifiques pour approfondir : Le standard industriel et statistiques d’adoption : Pour comprendre l’architecture des clés d’accès décentralisées, consultez le portail officiel de la FIDO Alliance sur la technologie Passkey. Recherche en informatique et taux de précision : Pour les fondements scientifiques de l’analyse du rythme de frappe, voir les études indexées par le IEEE Xplore Digital Library sur les Keystroke Dynamics. Statistiques sur les cyberattaques : Consultez les rapports d’analyse des menaces sur le Verizon Data Breach Investigations Report pour les données liées au vol d’identifiants. The post Quand le mot de passe c'est vous first appeared on XY Magazine.
Flera bolag har rapporterat bra för första kvartalet och trots orosmoment är börsindex upp. Panelen diskuterar även megatrender, köptips och säljtips.Aktierna vi nämner i aktiepodden denna gång är i tur och ordning Hansa, Bahnhof, Investor, Bravida, Huskvarna, Dometic, Enea, Apotea, Electrolux, Indutrade, Addnode, Sweco, Hexatronic, Yubico, ABB, SpaceX, Studsvik, SMP Global Water ETF, Munters, Lundin Mining, Plejd, H&M, AkerBP, Exchange Income, Anoto, Active Biotech, IPC, Alligo, Meren Energy, Epiroc och Alcadon. Börspanelens alla sajter hittar du här:shows.acast.com/tresmarta/aboutHernhag.seBorspsykologen.seSternersforlag.se Hosted on Acast. See acast.com/privacy for more information.
Ronnie Manning, Chief Brand Advocate for Yubico and a cyber-security expert, discusses modern risks and best practices for securing your business and/or professional data -- from simple matters like passwords, to multi-factor-authentication resources (like a phone verification), to hardware devices like Yubikeys. Visit YUBICO.COM for more information.
Andy sits down with Joe Scalone of Yubico to break down why passwords are no longer enough to keep your family safe online and what's replacing them. Joe explains how passkeys and physical security keys are changing the future of cybersecurity, why hackers are moving faster than ever (thanks to AI), and what that means for everyday families. The conversation also dives into parenting in a digital world from managing kids' online identities to building trust, communication, and smart guardrails at home. They also tackle the controversial rise of age verification, digital IDs, and whether giving your face or ID to tech companies is a risk parents should be concerned about. For more on Yubico check out: https://www.yubico.com/ Take control of your data with DeleteMe. Because they sponsor the podcast you can get 20% off a privacy plan from DeleteMe with promo code: DAD. Connect
One of the key highlights of the Defense Department's recent memo on multi-factor authentication for unclassified and secret networks is the clarification that DoD Public Key Infrastructure — not the common access card itself — is the department's primary authenticator. Previous policies would often go back and forth between describing the CAC or PKI as DoD's primary credential, creating confusion. Plus, the memo finally introduces passwordless authentication methods designed to give service members faster, more flexible access to systems. For more, Federal News Network's Anastasia Obis spoke with Alex Antrim and Adam Oliver, senior solutions engineers at Yubico..See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
Dagens ämnen: 0:00 Intro 5:02 Truecaller 9:42 Yubico 11:58 Coffee Stain 14:40 Eutelsat 16:15 AI 30:28 Råvaror 39:45 Index 43:24 Veckans Fill or Kill www.instagram.com/fillorkillpodden Tack @savr! www.savr.com Tack Virtune! www.virtune.com
Vi pratar om börstrenden och kursrekylen, kraxande olyckskorpar, rapportfloden, samt Arne Talvings nya bok Hitta börsens vinnare – aktieproffsens bästa tips. Dessutom är investmentbolagens rabatter större än vanligt. I podden får du även höra en rabattkod på Sterners Förlag. Aktierna vi nämner i podden är i tur och ordning Atlas Copco, ABB, Epiroc, Sandvik, Volvo Cars, Ericsson, Bilia, Byggmax, H&M, Astra Zeneca, Lundin Mining, Munters, Yubico, Evolution, Lime Technologies, Addtech, Pandox, AAK, Raysearch, Investor, Lundbergs, Acast, VBG, Linc, Vitec Software och Arjo.Börspanelens alla sajter hittar du här:shows.acast.com/tresmarta/aboutHernhag.seBorspsykologen.seSternersforlag.se Hosted on Acast. See acast.com/privacy for more information.
Dramatiken är påtaglig efter fredagens digra rapportskörd, där Saab lyfter tillsammans med bolag som Munters och Hexagon. Även förvärvaren Lifco går starkt och Lars-Erik Lundgren från Aktieansvar smälter intrycken tillsammans med Alpcots Jonas Olavi. Även förlorare som vinstvarnande Yubico och Bravida, liksom konsultbolaget Afry diskuteras i veckans sista Börslunch.
Why Self-host?, Advanced ZFS Dataset Management, Building a Simple Router with OpenBSD, Minimal pkgbase jails / chroots, WSL-For-FreeBSD, Yubico yubikey 5 nfc on FreeBSD, The Q3 2025 Issue of the FreeBSD Journal, and more NOTES This episode of BSDNow is brought to you by Tarsnap (https://www.tarsnap.com/bsdnow) and the BSDNow Patreon (https://www.patreon.com/bsdnow) Headlines Why Self-host? (https://romanzipp.com/blog/why-a-homelab-why-self-host) Advanced ZFS Dataset Management: Snapshots, Clones, and Bookmarks (https://klarasystems.com/articles/advanced-zfs-dataset-management/) News Roundup Building a Simple Router with OpenBSD (https://btxx.org/posts/openbsd-router/) Minimal pkgbase jails / chroots (https://forums.FreeBSD.org/threads/minimal-pkgbase-jails-chroots-docker-oci-like.99512/) WSL-For-FreeBSD (https://github.com/BalajeS/WSL-For-FreeBSD) Yubico yubikey 5 nfc on FreeBSD (https://forums.freebsd.org/threads/yubico-yubikey-5-nfc-on-freebsd.99529) The Q3 2025 Issue of the FreeBSD Journal is Now Available (https://freebsdfoundation.org/blog/the-q3-2025-issue-of-the-freebsd-journal-is-now-available/) Tarsnap This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups. Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv (mailto:feedback@bsdnow.tv) Join us and other BSD Fans in our BSD Now Telegram channel (https://t.me/bsdnow)
Sedan årsskiftet har vinstprognoserna för innevarande år skruvats upp för de en majoritet av börsbolagen. Men sedan förra rapportperioden har trenden vänt och vi sett fler nedrevideringar. Kanske var vi lite för optimistiska tidigare, kanske var Q2:orna lite svagare än väntat. Oaktat anledningen får vi snart facit! Veckans case är Yubico, verksamt i den hetaste av branscher - cybersäkerhet. Men Q2:anblevenbesvikelse. Felskär eller trend? Lyssna på Aktiepodden!
Alla shownotes finns på https://www.enlitenpoddomit.se , skulle det se konstigt ut i din poddspelare så titta gärna där efter alla länkar kring det vi pratar om Avsnitt 544 spelades in den 11 januari och därför så handlar dagens avsnitt om: INTRO: - Johan fixar saker i post. - Alla har haft en vecka... David har stått på scenen på China teater, kört samma presentation i Köpenhamn, varit ute och sprungit, haft städdag, och åkt tåg till högskolan i Skövde. Björn har varit på Cybersecurity Summit i Stockholm och Köpenhamn, sovit SUPERLÄNGE, också haft städdag. Johan har varit i Malmö och sprungit Malmö Maraton(!!!!!!!!), bråkat med ett lås, gått på kurs. David vill be om ursäkt till Johan. FEEDBACK AND BACKLOG: - 100x zoom i Pixel 10 Pro - Tivo slutar göra hårdvara https://www.engadget.com/entertainment/tv-movies/tivo-has-discontinued-its-dvr-boxes-123037999.html ALLMÄNT NYTT - Signals nya kryptering https://computersweden.se/article/4068127/signals-nya-kryptering-ska-kunna-sta-emot-kvanthot.html - AI skapar ny teknisk skuld https://computersweden.se/article/4069338/ai-kan-bli-cios-varsta-teknikskuld-hittills.html - Dashlane samarbetar med Yubico https://www.thurrott.com/cloud/328216/dashlane-partners-with-yubico-in-a-first-for-security-keys - Framework har hittat en bugg I UEFI https://www.bleepingcomputer.com/news/security/secure-boot-bypass-risk-on-nearly-200-000-linux-framework-sytems/ MICROSOFT - GitHub flyttar till Azure https://www.techbuzz.ai/articles/github-s-azure-migration-signals-end-of-independence-era - Microsoft förlänger Windows 10 mot att man registrerar sig https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-that-windows-10-reaches-end-of-support-today/ - Om man vill läsa om hur Microsoft bygger med nVidia grejjer i azure https://azure.microsoft.com/en-us/blog/microsoft-azure-delivers-the-first-large-scale-cluster-with-nvidia-gb300-nvl72-for-openai-workloads/ - TIPS från Björns fru "Start mail merge" eller "Starta dokumentkoppling" BONUSLÄNK: https://blog.admindroid.com/how-to-use-mail-merge-in-the-new-outlook-to-send-personalized-emails/#What%E2%80%99s-Coming%3A-Advanced-Mail-Merge-in-Outlook APPLE - Apple skrotar appen Clips https://www.macworld.se/article/2938605/apple-skrotar-en-av-sina-appar-men-du-kommer-knappast-att-sakna-den.html - Apple TV + blir Apple TV https://apple.slashdot.org/story/25/10/14/0138239/apple-renames-apple-tv-to-apple-tv - NU kanske det lönar sig att få barnen att börja plugga till bug bounty jägare? https://apple.slashdot.org/story/25/10/10/1610213/apple-doubles-its-biggest-bug-bounty-reward-to-2-million GOOGLE: - Potentiell sårbarhet på Android https://swedroid.se/illasinnad-app-kan-lasa-allt-skarminnehall-utan-systemtillatelse/ - Chrome hanterar notifieringar https://9to5google.com/2025/10/10/chrome-unsubscribe-notifications/ - David delar med sig av första veckan med en Pixel Watch 4. - Ny laddare till Pixel Watch 4 https://www.engadget.com/wearables/the-best-thing-about-the-pixel-watch-4-is-googles-new-charger-170052942.html - GrapheneOS bryts loss från Pixel https://www.androidauthority.com/graphene-os-major-android-oem-partnership-3606853/ - Google Meet kan sminka dig https://swedroid.se/nu-kan-google-meet-sminka-dig-annu-mer/ TIPS: - Commodore fabriken är uppe https://www.youtube.com/watch?v=BffeaLbKHkw PRYLLISTA - Björn: Du vet de där ögonfransarna man kan köpa till sin bil? #I_Raise_You_THIS!! https://www.amazon.com/dp/B0D3PX56WG/ - David: https://www.dustinhome.se/product/5011141961/professional-presenter-r800 - Johan: https://www.elgato.com/se/sv/p/prompter-xl EGNA LÄNKAR - En Liten Podd Om IT på webben, http://enlitenpoddomit.se/ - En Liten Podd Om IT på Facebook, https://www.facebook.com/EnLitenPoddOmIt/ - En Liten Podd Om IT på Youtube, https://www.youtube.com/enlitenpoddomit - Ge oss gärna en recension - https://podcasts.apple.com/se/podcast/en-liten-podd-om-it/id946204577?mt=2#see-all/reviews - https://www.podchaser.com/podcasts/en-liten-podd-om-it-158069 LÄNKAR TILL VART MAN HITTAR PODDEN FÖR ATT LYSSNA: - Apple Podcaster (iTunes), https://itunes.apple.com/se/podcast/en-liten-podd-om-it/id946204577 - Overcast, https://overcast.fm/itunes946204577/en-liten-podd-om-it - Acast, https://www.acast.com/enlitenpoddomit - Spotify, https://open.spotify.com/show/2e8wX1O4FbD6M2ocJdXBW7?si=HFFErR8YRlKrELsUD--Ujg%20 - Stitcher, https://www.stitcher.com/podcast/the-nerd-herd/en-liten-podd-om-it - YouTube, https://www.youtube.com/enlitenpoddomit LÄNK TILL DISCORD DÄR MAN HITTAR LIVE STREAM + CHATT - http://discord.enlitenpoddomit.se (Och glöm inte att maila bjorn@enlitenpoddomit.se om du vill ha klistermärken, skicka med en postadress bara. :)
Forget the doomsday headlines about Windows 10's end of life. Paul, Richard, and Leo break down why most users can relax, what Microsoft really has planned, and why the supposed landfill crisis around old PCs is mostly exaggeration. Also, Microsoft said OneDrive's new app was coming next year, but your file system says otherwise. Windows 11 October Patch Tuesday arrives, 1st for 25H2 Copilot+ PCs: Click to Do improvements, AI agent in Settings, File Explorer improvements 24H2/25H2: Desktop improvements, File Explorer improvements, Keyboard shortcuts for en and em dashes, Administrator Protection (off by default), Passkey improvements, Game Bar improvements Windows 10 (didn't) reach EOL and the world didn't end Zorin OS and ChromeOS Flex seize the moment Windows Insider: Copilot on Windows gets Connectors, Document creation and export. Copilot on Windows gets Settings support. Dev and Beta get AI agent in Settings improvements (Copilot+ PC), Setting search improvements (ditto), Drag Tray, Click to Do improvements, Dark mode improvements Dashlane partners with Yubico to make security keys primary vault access Lenovo ThinkCentre neo 50q QC is a Snapdragon X-based SFF PC HP OmniBook 5 16-inch shows why even the cheapest Snapdragon X chip is a winner Hope springs eternal: Intel Panther Lake is the efficiency of Lunar Lake plus the performance of Arrow Lake. Hopefully, it's not the reliability of either IDC: PC sales jumped 9.4 percent in Q3, just not where you live AI AI is the end of apps Microsoft reveals its first image generation model Opera Neon adds Nano Banana (image gen) and Sora (video gen) capabilities Xbox and gaming Target and Walmart will keep selling Xbox consoles unlike those losers at Costco A veteran of Halo Studios leaves, warns everyone Sorry, but there will be a sequel to the Minecraft movie Game Pass member? Call of Duty: Black Ops 6 is free to play for one more day Sony and AMD trickle out some PS6 news in a bizarre way - oh, and we're just getting started Tips and picks Tip of the week: Yes, Virginia, you can still sign in to Windows 11 25H2 with a local account App pick of the week: The new OneDrive app RunAs Radio this week: The End of NTML with Steve Syfuhs Brown liquor pick of the week: Holladay Soft Red Wheat Bourbon Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/windows bitwarden.com/twit
Forget the doomsday headlines about Windows 10's end of life. Paul, Richard, and Leo break down why most users can relax, what Microsoft really has planned, and why the supposed landfill crisis around old PCs is mostly exaggeration. Also, Microsoft said OneDrive's new app was coming next year, but your file system says otherwise. Windows 11 October Patch Tuesday arrives, 1st for 25H2 Copilot+ PCs: Click to Do improvements, AI agent in Settings, File Explorer improvements 24H2/25H2: Desktop improvements, File Explorer improvements, Keyboard shortcuts for en and em dashes, Administrator Protection (off by default), Passkey improvements, Game Bar improvements Windows 10 (didn't) reach EOL and the world didn't end Zorin OS and ChromeOS Flex seize the moment Windows Insider: Copilot on Windows gets Connectors, Document creation and export. Copilot on Windows gets Settings support. Dev and Beta get AI agent in Settings improvements (Copilot+ PC), Setting search improvements (ditto), Drag Tray, Click to Do improvements, Dark mode improvements Dashlane partners with Yubico to make security keys primary vault access Lenovo ThinkCentre neo 50q QC is a Snapdragon X-based SFF PC HP OmniBook 5 16-inch shows why even the cheapest Snapdragon X chip is a winner Hope springs eternal: Intel Panther Lake is the efficiency of Lunar Lake plus the performance of Arrow Lake. Hopefully, it's not the reliability of either IDC: PC sales jumped 9.4 percent in Q3, just not where you live AI AI is the end of apps Microsoft reveals its first image generation model Opera Neon adds Nano Banana (image gen) and Sora (video gen) capabilities Xbox and gaming Target and Walmart will keep selling Xbox consoles unlike those losers at Costco A veteran of Halo Studios leaves, warns everyone Sorry, but there will be a sequel to the Minecraft movie Game Pass member? Call of Duty: Black Ops 6 is free to play for one more day Sony and AMD trickle out some PS6 news in a bizarre way - oh, and we're just getting started Tips and picks Tip of the week: Yes, Virginia, you can still sign in to Windows 11 25H2 with a local account App pick of the week: The new OneDrive app RunAs Radio this week: The End of NTML with Steve Syfuhs Brown liquor pick of the week: Holladay Soft Red Wheat Bourbon Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/windows bitwarden.com/twit
Forget the doomsday headlines about Windows 10's end of life. Paul, Richard, and Leo break down why most users can relax, what Microsoft really has planned, and why the supposed landfill crisis around old PCs is mostly exaggeration. Also, Microsoft said OneDrive's new app was coming next year, but your file system says otherwise. Windows 11 October Patch Tuesday arrives, 1st for 25H2 Copilot+ PCs: Click to Do improvements, AI agent in Settings, File Explorer improvements 24H2/25H2: Desktop improvements, File Explorer improvements, Keyboard shortcuts for en and em dashes, Administrator Protection (off by default), Passkey improvements, Game Bar improvements Windows 10 (didn't) reach EOL and the world didn't end Zorin OS and ChromeOS Flex seize the moment Windows Insider: Copilot on Windows gets Connectors, Document creation and export. Copilot on Windows gets Settings support. Dev and Beta get AI agent in Settings improvements (Copilot+ PC), Setting search improvements (ditto), Drag Tray, Click to Do improvements, Dark mode improvements Dashlane partners with Yubico to make security keys primary vault access Lenovo ThinkCentre neo 50q QC is a Snapdragon X-based SFF PC HP OmniBook 5 16-inch shows why even the cheapest Snapdragon X chip is a winner Hope springs eternal: Intel Panther Lake is the efficiency of Lunar Lake plus the performance of Arrow Lake. Hopefully, it's not the reliability of either IDC: PC sales jumped 9.4 percent in Q3, just not where you live AI AI is the end of apps Microsoft reveals its first image generation model Opera Neon adds Nano Banana (image gen) and Sora (video gen) capabilities Xbox and gaming Target and Walmart will keep selling Xbox consoles unlike those losers at Costco A veteran of Halo Studios leaves, warns everyone Sorry, but there will be a sequel to the Minecraft movie Game Pass member? Call of Duty: Black Ops 6 is free to play for one more day Sony and AMD trickle out some PS6 news in a bizarre way - oh, and we're just getting started Tips and picks Tip of the week: Yes, Virginia, you can still sign in to Windows 11 25H2 with a local account App pick of the week: The new OneDrive app RunAs Radio this week: The End of NTML with Steve Syfuhs Brown liquor pick of the week: Holladay Soft Red Wheat Bourbon Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/windows bitwarden.com/twit
Forget the doomsday headlines about Windows 10's end of life. Paul, Richard, and Leo break down why most users can relax, what Microsoft really has planned, and why the supposed landfill crisis around old PCs is mostly exaggeration. Also, Microsoft said OneDrive's new app was coming next year, but your file system says otherwise. Windows 11 October Patch Tuesday arrives, 1st for 25H2 Copilot+ PCs: Click to Do improvements, AI agent in Settings, File Explorer improvements 24H2/25H2: Desktop improvements, File Explorer improvements, Keyboard shortcuts for en and em dashes, Administrator Protection (off by default), Passkey improvements, Game Bar improvements Windows 10 (didn't) reach EOL and the world didn't end Zorin OS and ChromeOS Flex seize the moment Windows Insider: Copilot on Windows gets Connectors, Document creation and export. Copilot on Windows gets Settings support. Dev and Beta get AI agent in Settings improvements (Copilot+ PC), Setting search improvements (ditto), Drag Tray, Click to Do improvements, Dark mode improvements Dashlane partners with Yubico to make security keys primary vault access Lenovo ThinkCentre neo 50q QC is a Snapdragon X-based SFF PC HP OmniBook 5 16-inch shows why even the cheapest Snapdragon X chip is a winner Hope springs eternal: Intel Panther Lake is the efficiency of Lunar Lake plus the performance of Arrow Lake. Hopefully, it's not the reliability of either IDC: PC sales jumped 9.4 percent in Q3, just not where you live AI AI is the end of apps Microsoft reveals its first image generation model Opera Neon adds Nano Banana (image gen) and Sora (video gen) capabilities Xbox and gaming Target and Walmart will keep selling Xbox consoles unlike those losers at Costco A veteran of Halo Studios leaves, warns everyone Sorry, but there will be a sequel to the Minecraft movie Game Pass member? Call of Duty: Black Ops 6 is free to play for one more day Sony and AMD trickle out some PS6 news in a bizarre way - oh, and we're just getting started Tips and picks Tip of the week: Yes, Virginia, you can still sign in to Windows 11 25H2 with a local account App pick of the week: The new OneDrive app RunAs Radio this week: The End of NTML with Steve Syfuhs Brown liquor pick of the week: Holladay Soft Red Wheat Bourbon Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/windows bitwarden.com/twit
Forget the doomsday headlines about Windows 10's end of life. Paul, Richard, and Leo break down why most users can relax, what Microsoft really has planned, and why the supposed landfill crisis around old PCs is mostly exaggeration. Also, Microsoft said OneDrive's new app was coming next year, but your file system says otherwise. Windows 11 October Patch Tuesday arrives, 1st for 25H2 Copilot+ PCs: Click to Do improvements, AI agent in Settings, File Explorer improvements 24H2/25H2: Desktop improvements, File Explorer improvements, Keyboard shortcuts for en and em dashes, Administrator Protection (off by default), Passkey improvements, Game Bar improvements Windows 10 (didn't) reach EOL and the world didn't end Zorin OS and ChromeOS Flex seize the moment Windows Insider: Copilot on Windows gets Connectors, Document creation and export. Copilot on Windows gets Settings support. Dev and Beta get AI agent in Settings improvements (Copilot+ PC), Setting search improvements (ditto), Drag Tray, Click to Do improvements, Dark mode improvements Dashlane partners with Yubico to make security keys primary vault access Lenovo ThinkCentre neo 50q QC is a Snapdragon X-based SFF PC HP OmniBook 5 16-inch shows why even the cheapest Snapdragon X chip is a winner Hope springs eternal: Intel Panther Lake is the efficiency of Lunar Lake plus the performance of Arrow Lake. Hopefully, it's not the reliability of either IDC: PC sales jumped 9.4 percent in Q3, just not where you live AI AI is the end of apps Microsoft reveals its first image generation model Opera Neon adds Nano Banana (image gen) and Sora (video gen) capabilities Xbox and gaming Target and Walmart will keep selling Xbox consoles unlike those losers at Costco A veteran of Halo Studios leaves, warns everyone Sorry, but there will be a sequel to the Minecraft movie Game Pass member? Call of Duty: Black Ops 6 is free to play for one more day Sony and AMD trickle out some PS6 news in a bizarre way - oh, and we're just getting started Tips and picks Tip of the week: Yes, Virginia, you can still sign in to Windows 11 25H2 with a local account App pick of the week: The new OneDrive app RunAs Radio this week: The End of NTML with Steve Syfuhs Brown liquor pick of the week: Holladay Soft Red Wheat Bourbon Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/windows bitwarden.com/twit
Forget the doomsday headlines about Windows 10's end of life. Paul, Richard, and Leo break down why most users can relax, what Microsoft really has planned, and why the supposed landfill crisis around old PCs is mostly exaggeration. Also, Microsoft said OneDrive's new app was coming next year, but your file system says otherwise. Windows 11 October Patch Tuesday arrives, 1st for 25H2 Copilot+ PCs: Click to Do improvements, AI agent in Settings, File Explorer improvements 24H2/25H2: Desktop improvements, File Explorer improvements, Keyboard shortcuts for en and em dashes, Administrator Protection (off by default), Passkey improvements, Game Bar improvements Windows 10 (didn't) reach EOL and the world didn't end Zorin OS and ChromeOS Flex seize the moment Windows Insider: Copilot on Windows gets Connectors, Document creation and export. Copilot on Windows gets Settings support. Dev and Beta get AI agent in Settings improvements (Copilot+ PC), Setting search improvements (ditto), Drag Tray, Click to Do improvements, Dark mode improvements Dashlane partners with Yubico to make security keys primary vault access Lenovo ThinkCentre neo 50q QC is a Snapdragon X-based SFF PC HP OmniBook 5 16-inch shows why even the cheapest Snapdragon X chip is a winner Hope springs eternal: Intel Panther Lake is the efficiency of Lunar Lake plus the performance of Arrow Lake. Hopefully, it's not the reliability of either IDC: PC sales jumped 9.4 percent in Q3, just not where you live AI AI is the end of apps Microsoft reveals its first image generation model Opera Neon adds Nano Banana (image gen) and Sora (video gen) capabilities Xbox and gaming Target and Walmart will keep selling Xbox consoles unlike those losers at Costco A veteran of Halo Studios leaves, warns everyone Sorry, but there will be a sequel to the Minecraft movie Game Pass member? Call of Duty: Black Ops 6 is free to play for one more day Sony and AMD trickle out some PS6 news in a bizarre way - oh, and we're just getting started Tips and picks Tip of the week: Yes, Virginia, you can still sign in to Windows 11 25H2 with a local account App pick of the week: The new OneDrive app RunAs Radio this week: The End of NTML with Steve Syfuhs Brown liquor pick of the week: Holladay Soft Red Wheat Bourbon Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: zapier.com/windows bitwarden.com/twit
In this Risky Business News sponsor interview Tom Uren talks to Derek Hanson, Yubico's Field CTO about making account recovery and onboarding for employees phishing-resistant. They also discuss the problems and opportunities of syncable passkeys. Show notes
Dagens ämnen: 0:00 Intro 5:36 SBB och norska miljardärer 19:44 Yubico m.fl. 25:11 Lundin Gold 28:54 Silver 31:12 Tullsnack 37:33 Biotech 45:18 Fredssamtal 47:24 Index 48:43 Veckans Fill or Kill www.instagram.com/fillorkillpodden Tack IG! https://upl.inc/ig_fillorkill Tack Virtune! http://virtune.com Tack Carla! www.carla.se Tack RoboMarkets! http://gorobo.pro/2aue @RoboMarketsSE
On this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news: Oracle quietly cops to being hacked, but immediately pivots into pretending it didn't matter NSA and CyberCom leaders fired for not being MAGA enough US Treasury had some dusty corners it hadn't found China in yet, looked, found China in them …which is a great time to discuss slashing CISA's staffing Ransomware crews and bullet proof hosting providers are getting rekt, and we love it And Microsoft patches yet another logging 0-day being used in the wild. This episode is sponsored by Yubico, makers of Yubikey hardware authentication tokens. Yubico's Vice President of Solutions Architecture and Alliances Derek Hanson joins to discuss how the consumer-centric passkey ecosystem has become a real challenge for enterprises. One that Yubico is actually ideally positioned to solve. This episode is also available on Youtube. Show notes Oracle privately confirms Cloud breach to customers Oracle have finally issued a written notification to customers about their cybersecurity incident. Head of NSA and US Cyber Command reportedly fired | Cybersecurity Dive Trump fires numerous National Security Council staff - The Washington Post Trump administration under scrutiny as it puts major round of CISA cuts on the table | Cybersecurity Dive Hackers Spied on US Bank Regulators' Emails for Over a Year - Bloomberg This is how Jeffrey Goldberg got added to the Signal chat Cybercriminals are trying to loot Australian pension accounts in new campaign | The Record from Recorded Future News $500,000 stolen in Australian super fund data breach | Superannuation | The Guardian Australian regulator pulls licenses of 95 companies in effort to crack down on investment scams | The Record from Recorded Future News Everest ransomware group's darknet site offline following defacement | The Record from Recorded Future News On March 28, 2025, a threat actor leaked internal data from Medialand, a major bulletproof hosting (BPH) provider long linked to Yalishanda (LARVA-34). There's a ransomware group named DragonForce going around hacking its rivals. After Mamona and BlackLock, the group has now hacked RansomHub The DragonForce ransomware group hacked two rivals this month CISA, experts warn of Crush file transfer attacks as ransomware gang makes threats | The Record from Recorded Future News Kill Security Campaign Targets CrushFTP Servers National Vulnerability Database | NIST Microsoft patches zero-day actively exploited in string of ransomware attacks | CyberScoop Exploitation of CLFS zero-day leads to ransomware activity | Microsoft Security Blog Is The Sofistication In The Room With Us? - X-Forwarded-For and Ivanti Connect Secure (CVE-2025-22457)
Ronnie Manning is the Chief Brand Associate at Yubico, a global cybersecurity company renowned for inventing the YubiKey, which offers phishing-resistant multi-factor authentication solutions. With over 20 years of experience in agency and corporate communications, he has focused on public relations and marketing strategies to bring new technology products to market. Prior to joining Yubico, Ronnie held positions at Raytheon/Websense and Edelman Public Relations. At Yubico, he has been instrumental in promoting the adoption of hardware-based authentication solutions and advocating for enhanced cybersecurity measures. In this episode… Cyber threats are evolving faster than ever, yet many users and organizations still rely on outdated or weak authentication methods. With phishing attacks on the rise and data breaches growing costlier, the need for robust-yet-intuitive security solutions has never been greater. But how do you convince people to adopt a physical device for digital protection in a world that's increasingly mobile and virtual? According to Ronnie Manning, a cybersecurity branding expert, the answer lies in simplicity. He explains that strong security doesn't necessitate complicated processes. Ronnie also highlights how real-world usability, like eliminating the need to fumble with codes or apps, drives faster adoption. This shift toward user-friendly security builds trust, saves time, and reduces risk. He adds that educating new markets with human-centered storytelling plays a key role in overcoming resistance and legacy perceptions about hardware-based solutions. In this episode of the Revenue Engine Podcast, host Alex Gluz sits down with Ronnie Manning, Chief Brand Associate at Yubico, to talk about making cybersecurity simple, scalable, and phishing resistant. They explore how physical keys streamline enterprise authentication, why user education is key to adoption, and how phishing-resistant methods like FIDO are gaining traction. Ronnie also shares strategies for large-scale rollout and onboarding in hybrid work environments.
Bienvenidos a un nuevo episodio de Spicy4tuna, en el día de hoy trataremos sobre un producto que le da mucha tranquilidad a WillyRex, el negocio de los Jibbitz, la posible guerra en Europa, el conflicto entre Pedro Sánchez y El Xokas, la película un hombre de familia, una reunión estratégica con la empresa de Euge Oller y cómo pasar de facturar 600€ a 7.000€ al mes. Sin más dilación, empecemos. : Invierte de forma segura y recibe un 2,53% sobre tu efectivo con Trade Republic: https://trade.re/spicy4tuna Invertir conlleva riesgos, los rendimientos no están garantizados. Aplican T&Cs. ️ Disfruta de 30 días gratis y acceder a los mejores podcast sin anuncios en Podimo: https://go.podimo.com/spicy4tuna Aplica al puesto de Case Study Analyst: https://bit.ly/4iJQAVG Protege tus cuentas con Yubico: https://amzn.to/43Oo00u ☕ Prueba el mejor café de especialidad directo a la puerta de tu casa con Incapto: https://bit.ly/SpicyXIncapto Inspecciona tu futura vivienda y evita que se convierta en una pesadilla: https://hausum.com/?utm_source=spicy4tuna&utm_medium=youtube&utm_campaign=premier Abre tu cuenta de empresa en Finom y comienza a operar en 24h: https://bit.ly/SpicyFinom Apuesta por la certeza con Acer for Business: https://www.acer.com/es-es/business Crea tu Página Web con Hostinger: https://www.hostinger.com/spicy4tuna Cupón de 10% de Descuento para planes de +12 meses: SPICY4TUNA Invierte en inmuebles de forma pasiva y sin dolores de cabeza con Inversiva: https://link.inversiva.com/spicy4tuna_youtube Encuentra tu hogar con un alquiler con opción a compra fácil y flexible con Wannaprop: https://wannaprop.es/?utm_source=youtube&utm_medium=spicy4tuna&utm_campaign=acceso_a_la_vivienda Aprende a hablar inglés como un Nativo: https://youtalkonline.com/spicy4tuna ️ El curso digital #1 de Oratoria y Comunicación para Hablar en Público con Confianza: https://go.hotmart.com/L97199651U ⚪️ Consigue tu pulsera Whoop: https://join.whoop.com/Spicy4tuna ════════════════ ️ Accede a la Web de Spicy4tuna y Suscríbete a nuestra Newsletter: https://www.spicy4tuna.com Contacto para Sponsors ➡ https://tally.so/r/nrPNE5 Email de Contacto ➡ podcast@spicy4tuna.com ════════════════ Todos los episodios completos: https://www.youtube.com/playlist?list=PL9XxulgDZKuzf6zuPWcuF6anvQOrukMom ════════════════ REDES SOCIALES DE SPICY4TUNA ➜ INSTAGRAM: https://www.instagram.com/spicy4tunapodcast/ ➜ TIKTOK: https://www.tiktok.com/@spicy4tuna ➜ FACEBOOK: https://www.facebook.com/spicy4tuna ════════════════ ️ ESCUCHA SPICY4TUNA EN FORMATO PODCAST Spotify: https://open.spotify.com/show/2QPC17Z9LhTntCA4c3Ijk9?si=39b610a14bb24f1f iTunes: https://podcasts.apple.com/es/podcast/spicy4tuna/id1714279648 iVoox: https://www.ivoox.com/escuchar-audios-spicy4tuna_al_33258956_1.html ════════════════ ¿QUIÉNES SOMOS? · Euge Oller: https://www.instagram.com/euge.oller/ · Willyrex: https://www.instagram.com/willyrex/ · Marc Urgell: https://www.instagram.com/marcurgelldiaz/ · Alvaro845: https://www.instagram.com/alvaro845/ ════════════════ 00:00:00 INTRODUCCIÓN 00:05:11 ¿GUERRA EN EUROPA? 00:11:05 EL XOKAS vs PEDRO SÁNCHEZ 00:16:11 CONSEJOS DE INVERSIÓN AVANZADOS 00:31:13 LA REUNIÓN ESTRATÉGICA DE EUGE 00:43:14 DE 600€/al mes a 7.000€/al mes 00:50:16 EL PRODUCTO DE LA TRANQUILIDAD DE WILLYREX 01:09:47 FILMS & BUSINESS 01:33:25 EL NEGOCIO DE JIBBITZ
In this episode, we sit with security leader and venture investor Sergej Epp to discuss the Cloud-native Security Landscape. Sergej currently serves as the Global CISO and Executive at Cloud Security leader Sysdig and is a Venture Partner at Picus Capital. We will dive into some insights from Sysdig's recent "2025 Cloud-native Security and Usage Report."Big shout out to our episode sponsor, Yubico!Passwords aren't enough. Cyber threats are evolving, and attackers bypass weak authentication every day. YubiKeys provides phishing-resistant security for individuals and businesses—fast, frictionless, and passwordless.Upgrade your security:https://yubico.comSergj and I dove into a lot of great topics related to Cloud-native Security, including:Some of the key trends in the latest Sysdig 2025 Cloud-native Security Report and trends that have stayed consistent YoY. Sergj points out that while attackers have stayed consistent, organizations have and continue to make improvements to their securitySergj elaborated on his current role as Sysdig's internal CISO and his prior role as a field CISO and the differences between the two roles in terms of how you interact with your organization, customers, and the community.We unpacked the need for automated Incident Response, touching on how modern cloud-native attacks can happen in as little as 10 minutes and how organizations can and do struggle without sufficient visibility and the ability to automate their incident response.The report points out that machine identities, or Non-Human Identities (NHI), are 7.5 times riskier than human identities and that there are 40,000 times more of them to manage. This is a massive problem and gap for the industry, and Sergj and I walked through why this is a challenge and its potential risks.Vulnerability prioritization continues to be crucial, with the latest Sysdig report showing that just 6% of vulnerabilities are “in-use”, or reachable. Still, container bloat has ballooned, quintupling in the last year alone. This presents real problems as organizations continue to expand their attack surface with expanded open-source usage but struggle to determine what vulnerabilities truly present risks and need to be addressed.We covered the challenges with compliance, as organizations wrestle with multiple disparate compliance frameworks, and how compliance can drive better security but also can have inverse impacts when written poorly or not keeping pace with technologies and threats.We rounded out the conversation with discussing AI/ML packages and the fact they have grown by 500% when it comes to usage, but organizations have decreased public exposure of AI/ML workloads by 38% since the year prior, showing some improvements are being made to safeguarding AI workloads from risks as well.
Think your employees are good at security? You're in the minority. Recent studies reveal that personal accounts, particularly social media, are frequently compromised. A recent Yubico survey found that 47% of Gen Z users and 46% of Millennials reported having had their social media account passwords hacked. This translates to potentially tens of millions of stolen credentials that cybercriminals could leverage to access other, more sensitive services, including online banking, email, and cryptocurrency accounts. If employees reuse passwords across personal and work systems, a compromised social media account can create significant security risks for your organization. A single compromised password could provide attackers with access to internal networks, sensitive data, and critical systems. Therefore, it's crucial to emphasize to your employees the importance of using unique and complex passwords for all accounts, especially ensuring that personal passwords are never reused for work-related systems. On a positive note, the same Yubico survey indicated a growing understanding among Gen Z of the value of multi-factor authentication, or MFA, in bolstering social media account security. Encourage your employees to extend this practice to all accounts, especially work accounts, as MFA significantly reduces the risk of unauthorized access, even if a password is compromised. The 60-second "Security Nudge" is brought to you by CybSafe, developers of the Human Risk Management Platform. Learn more at https://cybsafe.com
The FBI warns agents of hacked call and text logs. The US Treasury sanctions entities tied to North Korea's fake IT worker operations. Russian hacking group Star Blizzard attempted to infiltrate WhatsApp accounts of nonprofits supporting Ukraine. Yubico discloses a critical vulnerability in its Pluggable Authentication Module)software. Google releases an open-source library for software composition analysis. CISA hopes to close the software understanding gap. Pumakit targets critical infrastructure. Simplehelp patches multiple flaws in their remote access software. The FTC bans GM from selling driver data. HHS outlines their efforts to protect hospitals and healthcare. Our guest Maria Tranquilli, Executive Director at Common Mission Project, speaks with N2K's Executive Editor Brandon Karpf about the origins and impact of Hacking for Defense. Even the best of red teamers are humbled by AI. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest Maria Tranquilli, Executive Director at Common Mission Project, speaks with N2K's Executive Editor Brandon Karpf about the origins and impact of Hacking for Defense, and how universities can get involved. Selected Reading FBI Has Warned Agents It Believes Hackers Stole Their Call Logs (Bloomberg) US Announces Sanctions Against North Korean Fake IT Worker Network (SecurityWeek) Russian Star Blizzard hackers exploit WhatsApp accounts to spy on nonprofits aiding Ukraine (The Record) Yubico PAM Module Vulnerability Let Attackers Bypass Authentications In Certain Configurations (Cyber Security News) Google Releases Open Source Library for Software Composition Analysis (SecurityWeek) Closing the Software Understanding Gap (CISA) Pumakit - A Sophisticated Linux Rootkit Attack Critical Infrastructure (Cyber Security News) Vulnerabilities in SimpleHelp Remote Access Software May Lead to System Compromise (SecurityWeek) FTC hands GM a 5-year ban on selling sensitive driver info to data brokers (The Record) How HHS has strengthened cybersecurity of hospitals and health care systems (CyberScoop) Microsoft AI Red Team says security work will never be done (The Register) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
0:06 – 0:22 – Welcome Back! Larry and Joe kick off the latest episode of their podcast with excitement, diving straight into the cybersecurity topics of the day. 0:56 – 3:56 – The Mobile Carrier Breach Joe breaks down the recent breach involving major telecom carriers (AT&T, Verizon, T-Mobile), discussing how hackers exploited outdated Cisco routers to access sensitive wiretap systems and target political figures. https://techcrunch.com/2024/11/14/us-confirms-china-backed-hackers-breached-telecom-providers-to-steal-wiretap-data/ 3:56 – 4:33 – Implications for Everyday Users Joe explains the importance of encrypted communication apps like iMessage, WhatsApp, and Signal, highlighting vulnerabilities in text messaging protocols between iPhone and Android users. 4:33 – 6:09 – Best Practices for 2FA The hosts emphasize moving away from SMS-based two-factor authentication and adopting authenticator apps or phishing-resistant methods like hardware keys. https://techcommunity.microsoft.com/blog/identity/its-time-to-hang-up-on-phone-transports-for-authentication/1751752 6:25 – 8:55 – Protecting Personal Accounts Larry and Joe discuss practical ways for regular users to improve password security, including using randomized passwords, password managers, and even a physical password vault. 9:04 – 10:29 – The Pros and Cons of Password Managers Joe explores the trade-offs between web-based solutions like LastPass and local password safes https://pwsafe.org/ secured with hardware keys from Yubico https://www.yubico.com/product/yubikey-5-series/yubikey-5c-nfc/, offering insights into selecting the right solution for your needs. 10:30 – 12:38 – VPNs and DNS Privacy Joe delves into VPNs, DNS encryption, and how they protect user privacy, while explaining why these measures are essential for blocking ISPs from selling your data to advertisers. https://en.wikipedia.org/wiki/DNS_over_HTTPS 12:39 – 14:54 – Guarding Against Scams Larry shares personal stories of family members targeted by scams, prompting tips from Joe on spotting phishing attempts, verifying suspicious emails, and avoiding QR code traps. 14:54 – 16:37 – The Wild West of the Internet The conversation turns philosophical as the hosts discuss the current state of online security and the challenges of protecting vulnerable users, including the elderly, from relentless cybercriminals. Reminds me of "The Beekeeper" movie https://www.imdb.com/title/tt15314262/ 16:37 – 17:55 – QR Code Scams in the Real World Joe uncovers the risks of QR code fraud, including fake stickers in restaurants or parking meters and malicious links sent in packages, and how to avoid falling victim to these scams. https://www.instagram.com/cybersecuritygirl/reel/DCaetPtuBIw/ 18:17 – 20:33 – Simple Security Steps for Everyone Larry asks Joe for his top advice for everyday users, resulting in actionable steps like maintaining unique passwords for every account and writing them down in a secure password book. 20:33 – 21:50 – Credential Stuffing Explained Joe explains the mechanics of credential stuffing, how hackers automate attacks, and why using different passwords for every account is critical. https://en.wikipedia.org/wiki/Credential_stuffing 21:50 – 22:09 – Planning for the Future Joe reflects on how maintaining a secure and accessible password book can help families manage accounts after a loved one's passing, underscoring the value of preparedness.
In this interview Patrick Gray talks to Yubico's COO and President Jerrod Chong about a new Yubikey feature: pre-registration. You can now ship pre-registered Yubikeys to your staff so you don't need to rely on your staff to enrol them. They've achieved this with really slick Okta and Entra ID integrations. Jerrod also talks about a recent trip to Singapore and concerns he has about the cybersecurity of critical infrastructure in the energy sector.
If it feels like cybersecurity attacks are everywhere, you're not alone: half of respondents to a recent Yubico global survey said they had been exposed to a cyber attack at work during the past year – and 1 in 5 said that one of their personal bank, email, social media, or other personal accounts had been hacked. And no wonder: 39 per cent of the respondents said they believe a simple username and password are the most secure way to protect their accounts and information. This, of course, is wrong – new innovations like multi factor authentication and secure passkeys offer better security than the humble password – but people are creatures of habit. That's why the scariest thing Yubico learned was that, as the New York Post reports, fewer than a quarter of respondents said their employers required them to undertake security training after being attacked. Without training, bad habits will never change – and this puts your data, and the data of the company you work for, at risk. If you are the victim of an attack, or know someone at work who was, do everyone a favor and make sure you undertake cyber training so it never happens again. The 60-second "Security Nudge" is brought to you by CybSafe, developers of the Human Risk Management Platform. Learn more at https://cybsafe.com
Nyheterna om bolag och fenomen i det nya näringslivet tycks aldrig ta slut! I det senaste avsnitt av Breakit Podcast får du höra om allt du behöver kolla på. (03:29) Klarna ansöker om börsnotering – här är Breakits analys(07:12) Shoppinghögtiden närmar sig med stormsteg – aktörer förlänger Black Week: “Spårar ur totalt”(14:28) Fem snabba nyheter från veckan:# Volkswagen-toppen lämnar krisande Northvolts styrelse # Embracer säljer del av verksamheten: “Nollställer bolagets balansräkning”# Spotify lägger korten på bordet: “Aldrig varit i en starkare position” # Elon Musk ska ge råd om hur USA ska sänka statens kostnader # Yubico rapporterar och visar rejäl tillväxt (16:43) Från kris till lönsamhet – så lyckades bolaget vända trots tuffa tider: “Dra av plåstret snabbt” Och du – glöm inte att ge feedback till podcast@breakit.se. Hosted on Acast. See acast.com/privacy for more information.
As Halloween approaches, there's nothing more unsettling than the thought of our online accounts - and valuable personal data - falling into the wrong hands. With online banking part of daily routines and e-commerce platforms storing user payment information, keeping login details secure is more crucial than ever. But with cyber criminals constantly evolving their tactics, staying safe online can feel more like a trick than a treat. According to Yubico's 2024 State of Global Authentication survey of 20,000 employees, 70 percent of respondents have been exposed to cyber attacks in their personal lives over the past year. This scary statistic highlights how frequently cyber criminals target unsuspecting victims. As Cybersecurity Awareness Month draws to a close, now is the perfect time to shed light on the most disturbing threats haunting our online accounts. Here are three to watch out for this Halloween: Fearsome Phishing: Phishing involves tricking individuals into revealing personal information by impersonating legitimate people or entities through emails, text messages, or fake websites. This common tactic is used by hackers to gain access to sensitive information and is highly successful, with 80 percent of all cyber attacks resulting from stolen login credentials Abominable AI: Cyber criminals are using the power of AI to enhance the speed and effectiveness of their phishing attacks. This allows attackers to analyse vast amounts of data and generate sophisticated phishing schemes, making these scams even more difficult to detect. Yubico's survey revealed that 72 percent of respondents believe online scams and phishing attacks have become more sophisticated due to the use of AI - demonstrating a growing level of concern Insidious identity theft: This unfortunate outcome of phishing and AI-enabled cybercrime is any user's worst fear, as it's impossible to retrieve stolen details once they fall into the hands of hackers. Victims of identity theft often lack strong authentication methods, relying instead on insecure and reused passwords. In fact, Yubico's survey found that respondents' most commonly compromised passwords protect the apps and services that hold their most confidential financial and personal information, such as payments, messaging and banking apps To help make sure your cybersecurity doesn't keep you up at night this Halloween, Niall McConachie, Regional Director (UK & Ireland) at Yubico, explains how users can stay safe online: "The threat of users' accounts being compromised through phishing and social engineering - especially those driven by AI - is exacerbated by the widespread use of outdated authentication methods like passwords. Alarmingly, our survey found that almost four in ten individuals (39 percent) believe passwords are the most secure authentication method, despite being inherently insecure and outdated. "Simple passwords are easy to remember but also easy to guess. Updated requirements that prompt users to create complex passwords cause increased frustration when trying to log in, especially in time-sensitive situations. Furthermore, once a password is stolen, cyber criminals can easily bypass other login methods, such as codes sent by text message. "Instead of relying on passwords to keep accounts safe, users seeking to protect their accounts with the highest level of security can use hardware security keys to manage logins across platforms and devices. Security keys are phishing-resistant and can't be intercepted or stolen by remote attackers, meaning only the key holder can gain access to their accounts. By using the highest-assurance authentication method that a security key provides, individuals can better protect themselves and their data. This gives them one less thing to fear this Halloween."
Dagens ämnen: 00:00 Intro 03:55 Integrum 07:41 Yubico 14:15 Moberg 18:36 Complete Solaria 26:05 Råvaror 32:29 Försvarssektorn 36:46 Fed 43:20 Neonode 45:08 Veckans Fill or Kill www.instagram.com/fillorkillpodden Tack RoboMarkets! http://gorobo.pro/2aue @RoboMarketsSE
Coming up in this episode * Death & Taxes * Stop Filing Bug Reports! -- like that * and Your Emails! 0:00 Cold Open 1:25 Yubikeys are DEAD! 10:41 Deep In the Heart of Ptyxis 28:01 The Do's and Don'ts of Bug Reports 42:47 Email: Scott J 49:47 Email: Ben 52:49 Email: Bruce H 57:48 Email: Rob Simmons 1:03:22 Email: DailyDriver 1:04:24 Email: J 1:08:34 Pnext Time 1:10:17 Pstinger See the Video on Youtube (https://youtu.be/jWSVnDYeEe4)! https://youtu.be/jWSVnDYeEe4 Your Yubikey is DEAD! The Yubico advisory (https://www.yubico.com/support/security-advisories/ysa-2024-03/) arsTechnica coverage (https://arstechnica.com/security/2024/09/yubikeys-are-vulnerable-to-cloning-attacks-thanks-to-newly-discovered-side-channel/) The really deep dive details (https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf)
Following Friday's global IT outage, which saw airlines, media, banks, hospitals and many other enterprises affected, international cyber defence organisations have issued warnings concerning the likelihood of malicious activity by cyber criminals. Cyber agencies in the UK, USA, and Australia all issued statements over the weekend regarding increased phishing activity linked to the incident, reminding people of the need for vigilance as they receive fake emails and calls promising to resolve the issues caused by the event. In fact, the UK's National Cyber Security Centre (NCSC) noted that it had already observed an increase in phishing relating to the outage. In the wake of the worldwide IT outage, Niall McConachie, regional director (UK & Ireland) at Yubico, comments on how bad actors take advantage of events like this and explains how organisations and individuals can ensure they're protected against subsequent phishing attacks: "Cyber criminals often capitalise on events when a lot of confusion and panic is prevalent, such as Friday's global IT outage. In the hours and days following the incident, bad actors have been tweaking their existing attack methods to take advantage of the situation. For instance, hackers have already adjusted their phishing campaigns to offer information about the outage, promising to help those impacted - providing cyber criminals with a way of hacking individuals and organisations. "The spike in phishing activity associated with the incident highlights the urgent need for better cybersecurity training for employees and customers alike so that both know how to spot and report phishing attacks to keep both themselves and the business secure. Most employees do not receive frequent cybersecurity training, which leaves them and their organisations vulnerable. To establish an effective cybersecurity awareness training programme, organisations must ensure this is properly resourced - as opposed to treating it like a collateral duty - in addition to frequently updating the training with the latest information on methodologies being used by hackers. This will reduce the vulnerability of employees facing increasingly sophisticated phishing attacks and, in turn, make services safer for customers to use - keeping the sensitive data of the business and customers secure. "In conjunction with regular and up-to-date security training, organisations should consider implementing phishing-resistant authentication solutions. Basic username and password and weak multi-factor authentication (MFA) methods alone are far too easy for attackers to circumvent, allowing unauthorised access to online accounts and personal data. Instead, phishing-resistant MFA, such as passkeys like physical security keys, is more secure and user-friendly and can be used for both personal and professional data security. This is because it requires something you know (a PIN), something you have (the security key), and something you are (a physical touch of the key when prompted to gain access). These tools are especially important as cyber attacks relating to the global IT outage are unlikely to be limited to companies, but will also directly target customers and employees too."
In episode 75 of the Summits Podcast, co-hosts Vince Todd, Jr. and Daniel Abdallah are joined by California-native Kevin Bohn of Yubico. At just 25 years old, Kevin was blindsided with a stage 4 lymphoma diagnosis, resulting in removal of his stomach and spleen. Post-treatment, Kevin eventually committed himself to growth after cancer, focusing on his mental health and energy. Now five years post-treatment, Kevin has ran multiple half-marathons and will run the Santa Rosa Marathon in August 2024. Don't miss Kevin's story of strength and perseverance.
On this week's show Patrick Gray and Adam Boileau are joined by long-time NSA boffin Rob Joyce. Now Rob's left the government service, he's hobnobbing with us pundits, talking through the week's news: Apple announces a big leap for confidential cloud computing into the mass market While at the same time, letting you just mosey around your iPhone from your Mac Mandiant reports in about the Snowflake breach Moody's say credit ratings might consider cyber incidents Microsoft fixes an Azure flaw with a… “comprehensive documentation update” And much, much more. This week's show is sponsored by Yubico, maker of the Yubikey hardware authentication token. Jerrod Chong, Yubico's COO and President joins to talk about the challenges of the passkey and hardware authenticator ecosystem. Show notes Apple makes a password manager play in a heavily targeted market | Cybersecurity Dive macOS Sequoia takes productivity and intelligence on Mac to new heights - Apple The Wiretap: Apple's AI Announcement Promises Big Security Boosts–Not Everyone Is Convinced Matthew Green on X: "Ok there are probably half a dozen more technical details in the blog post. It's a very thoughtful design. Indeed, if you gave an excellent team a huge pile of money and told them to build the best “private” cloud in the world, it would probably look like this. 14/" / X Risky Biz News: Microsoft budges on Windows 11 Recall Tenable finds an Azure flaw, Microsoft calls it a feature • The Register LendingTree confirms that cloud services attack potentially affected subsidiary Hackers steal “significant volume” of data from hundreds of Snowflake customers | Ars Technica 7,000 LockBit decryption keys now in the hands of the FBI, offering victims hope | Ars Technica Urgent call for O-type blood donations following London hospitals ransomware attack Darknet site for Qilin gang, suspected in London hospitals ransomware attack, goes down Cyberattacks pose mounting risks to creditworthiness: Moody's | Cybersecurity Dive Apple refused to pay bug bounty to Russian cybersecurity firm Kaspersky Lab FCC moves ahead on internet routing security rules | CyberScoop House Republicans propose eliminating funding for election security | CyberScoop New DJI policy: No flight record syncing for US drone pilots Semiconductor giants Nvidia and Arm warn of new flaws in their graphics processors Critical PHP CVE is under attack — research shows it's easy to exploit | Cybersecurity Dive A US Company Enabled a North Korean Scam That Raised Money for WMDs | WIRED
"Identity security has been around forever though", you might be thinking. Allow me to clarify. Identity is the largest cybersecurity product category, but most of it is focused on identity governance, authentication, multi-factor, etc. Very little of it is focused on operational identity security. It's this trend, where we recently (within the last 2 years) started seeing the ITDR (Identity Threat Detection and Response) acronym that we'll be focused on today. Particularly: Why is this trend/spike occurring now? What was or is missing to do identity security properly? What does the future of securing identity look like? And it's difficult to do better for this conversation than Will Lin. He spent the last half decade as a VC. On a daily basis, he was looking at the big picture of cybersecurity markets and trends. He discussed security challenges with CISOs and other security buyers on a regular basis, both directly and through the Security Tinkerers community he founded. All this led to a decision to quit the VC world to become a founder himself. Of all the categories he could have chosen, he chose identity security, and that's why we're happy to have him for this conversation. Segment Resources: The Future of Identity AKA Identity promo video focused on the future of Identity We start off discussing the latest round of fundings, centered largely around data security and securing LLM use. This dovetails into a discussion about marketing language and how difficult it can be for buyers to work out what the latest round of early stage startups are doing. Next, we discuss Cloudflare and Bugcrowd's acquisitions, as well as Synopsys's divestiture of its appsec portfolio. From here, we dive into a raft of new features across both IT and cybersecurity products, like Azure, Dashlane, LastPass, and PagerDuty. Discussing Huntress's active remediation feature triggers a conversation about this latest product trend: vendors seem to think buyers are ready for fully automated remediation actions. We're not so sure they are. To wrap up the cybersecurity coverage, Brandon Dixon has an interesting tutorial regarding a Security Copilot use case that looks a LOT like the default phishing enrichment use case that has been used for every SOAR POC ever. To clarify, this is a great piece in that it is all practical, has no marketing fluff, and shows you how to do something useful with Security Copilot. Where it pulls up short is managing to live up to the hype we've been hearing about Security Copilot from day one. We agree to table the discussion on Microsoft Recall until we know more about what GA of the feature will look like, and then dig into a VERY interesting squirrel story about an audio-based hacking puzzle created by a rock band. The interview will delve into the healthcare industry's tumultuous year in 2023, marked by 124 million breached health records across 725 hacking incidents (according to The HIPAA Journal). This interview will explore the critical role that MSSPs play in safeguarding health data and systems against potential security incidents, such as ransomware and business email compromise attacks. Jim Broome will share how to proactively prepare for an incident - including establishing a comprehensive incident response plan, outlining strategies for containment, restoration, and ongoing security operations, and how an MSSP can help. Segment Resources: Tales from the Road Blog: An External Pen Test at a Healthcare Organization Reveals the Dangers of the Dark Web - https://www.directdefense.com/tales-from-the-road-an-external-pen-test-reveals-the-dangers-of-the-dark-web/ 2023 Security Operations Threat Report: https://go.directdefense.com/2023-Security-Operations-Threat-Report This segment is sponsored by DirectDefense. Visit https://securityweekly.com/directdefensersac to learn more about them! In the dynamic landscape of cybersecurity, the urgency to eliminate passwords as a security vulnerability has never been more critical. Organizations are continuing to face a surge in the variety and complexity of cyber threats at historical rates, often fueled by compromised employee login credentials – resulting from attacks such as phishing which has been exacerbated by the rise in use of Artificial Intelligence (AI). The 2023 Verizon Data Breach Investigations Report underscores the staggering impact of breaches caused by stolen credentials, accounting for a staggering 74% of incidents. Christopher Harrell, Yubico's Chief Technology Officer, shares how organizations can achieve passwordless authentication at scale with high assurance phishing-resistant multi-factor authentication (MFA) to elevate their security posture against phishing attacks while creating phishing-resistant users. Segment Resources: https://www.yubico.com/blog/empowering-enterprise-security-at-scale-with-new-product-innovations-yubikey-5-7-and-yubico-authenticator-7/ https://www.yubico.com/press-releases/yubicos-key-product-innovations-empower-enterprise-security-and-phishing-resistant-passwordless-authentication-at-scale/ This segment is sponsored by Yubico. Visit https://securityweekly.com/yubicorsac to learn more about them! In this podcast segment, we delve into Sophos' fifth annual State of Ransomware report, exploring significant findings and trends in the evolving ransomware landscape. We'll discuss the sharp increase in recovery costs, the strategic targeting of backups by hackers, and the evolving role of cyber insurance in ransom payments. Our discussion will provide insights into how organizations can adapt their cybersecurity measures to mitigate these heightened threats and recover more effectively from attacks. Segment Resources: Blog: The State of Ransomware 2024 Report: https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2024-wp.pdf Press release: Ransomware Payments Increase 500% In the Last Year, Finds Sophos State of Ransomware Report This segment is sponsored by Sophos. Visit https://www.securityweekly.com/sophosrsac to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-364
The interview will delve into the healthcare industry's tumultuous year in 2023, marked by 124 million breached health records across 725 hacking incidents (according to The HIPAA Journal). This interview will explore the critical role that MSSPs play in safeguarding health data and systems against potential security incidents, such as ransomware and business email compromise attacks. Jim Broome will share how to proactively prepare for an incident - including establishing a comprehensive incident response plan, outlining strategies for containment, restoration, and ongoing security operations, and how an MSSP can help. Segment Resources: Tales from the Road Blog: An External Pen Test at a Healthcare Organization Reveals the Dangers of the Dark Web - https://www.directdefense.com/tales-from-the-road-an-external-pen-test-reveals-the-dangers-of-the-dark-web/ 2023 Security Operations Threat Report: https://go.directdefense.com/2023-Security-Operations-Threat-Report This segment is sponsored by DirectDefense. Visit https://securityweekly.com/directdefensersac to learn more about them! In the dynamic landscape of cybersecurity, the urgency to eliminate passwords as a security vulnerability has never been more critical. Organizations are continuing to face a surge in the variety and complexity of cyber threats at historical rates, often fueled by compromised employee login credentials – resulting from attacks such as phishing which has been exacerbated by the rise in use of Artificial Intelligence (AI). The 2023 Verizon Data Breach Investigations Report underscores the staggering impact of breaches caused by stolen credentials, accounting for a staggering 74% of incidents. Christopher Harrell, Yubico's Chief Technology Officer, shares how organizations can achieve passwordless authentication at scale with high assurance phishing-resistant multi-factor authentication (MFA) to elevate their security posture against phishing attacks while creating phishing-resistant users. Segment Resources: https://www.yubico.com/blog/empowering-enterprise-security-at-scale-with-new-product-innovations-yubikey-5-7-and-yubico-authenticator-7/ https://www.yubico.com/press-releases/yubicos-key-product-innovations-empower-enterprise-security-and-phishing-resistant-passwordless-authentication-at-scale/ This segment is sponsored by Yubico. Visit https://securityweekly.com/yubicorsac to learn more about them! In this podcast segment, we delve into Sophos' fifth annual State of Ransomware report, exploring significant findings and trends in the evolving ransomware landscape. We'll discuss the sharp increase in recovery costs, the strategic targeting of backups by hackers, and the evolving role of cyber insurance in ransom payments. Our discussion will provide insights into how organizations can adapt their cybersecurity measures to mitigate these heightened threats and recover more effectively from attacks. Segment Resources: Blog: The State of Ransomware 2024 Report: https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2024-wp.pdf Press release: Ransomware Payments Increase 500% In the Last Year, Finds Sophos State of Ransomware Report This segment is sponsored by Sophos. Visit https://www.securityweekly.com/sophosrsac to learn more about them! Show Notes: https://securityweekly.com/esw-364
The interview will delve into the healthcare industry's tumultuous year in 2023, marked by 124 million breached health records across 725 hacking incidents (according to The HIPAA Journal). This interview will explore the critical role that MSSPs play in safeguarding health data and systems against potential security incidents, such as ransomware and business email compromise attacks. Jim Broome will share how to proactively prepare for an incident - including establishing a comprehensive incident response plan, outlining strategies for containment, restoration, and ongoing security operations, and how an MSSP can help. Segment Resources: Tales from the Road Blog: An External Pen Test at a Healthcare Organization Reveals the Dangers of the Dark Web - https://www.directdefense.com/tales-from-the-road-an-external-pen-test-reveals-the-dangers-of-the-dark-web/ 2023 Security Operations Threat Report: https://go.directdefense.com/2023-Security-Operations-Threat-Report This segment is sponsored by DirectDefense. Visit https://securityweekly.com/directdefensersac to learn more about them! In the dynamic landscape of cybersecurity, the urgency to eliminate passwords as a security vulnerability has never been more critical. Organizations are continuing to face a surge in the variety and complexity of cyber threats at historical rates, often fueled by compromised employee login credentials – resulting from attacks such as phishing which has been exacerbated by the rise in use of Artificial Intelligence (AI). The 2023 Verizon Data Breach Investigations Report underscores the staggering impact of breaches caused by stolen credentials, accounting for a staggering 74% of incidents. Christopher Harrell, Yubico's Chief Technology Officer, shares how organizations can achieve passwordless authentication at scale with high assurance phishing-resistant multi-factor authentication (MFA) to elevate their security posture against phishing attacks while creating phishing-resistant users. Segment Resources: https://www.yubico.com/blog/empowering-enterprise-security-at-scale-with-new-product-innovations-yubikey-5-7-and-yubico-authenticator-7/ https://www.yubico.com/press-releases/yubicos-key-product-innovations-empower-enterprise-security-and-phishing-resistant-passwordless-authentication-at-scale/ This segment is sponsored by Yubico. Visit https://securityweekly.com/yubicorsac to learn more about them! In this podcast segment, we delve into Sophos' fifth annual State of Ransomware report, exploring significant findings and trends in the evolving ransomware landscape. We'll discuss the sharp increase in recovery costs, the strategic targeting of backups by hackers, and the evolving role of cyber insurance in ransom payments. Our discussion will provide insights into how organizations can adapt their cybersecurity measures to mitigate these heightened threats and recover more effectively from attacks. Segment Resources: Blog: The State of Ransomware 2024 Report: https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2024-wp.pdf Press release: Ransomware Payments Increase 500% In the Last Year, Finds Sophos State of Ransomware Report This segment is sponsored by Sophos. Visit https://www.securityweekly.com/sophosrsac to learn more about them! Show Notes: https://securityweekly.com/esw-364
"Identity security has been around forever though", you might be thinking. Allow me to clarify. Identity is the largest cybersecurity product category, but most of it is focused on identity governance, authentication, multi-factor, etc. Very little of it is focused on operational identity security. It's this trend, where we recently (within the last 2 years) started seeing the ITDR (Identity Threat Detection and Response) acronym that we'll be focused on today. Particularly: Why is this trend/spike occurring now? What was or is missing to do identity security properly? What does the future of securing identity look like? And it's difficult to do better for this conversation than Will Lin. He spent the last half decade as a VC. On a daily basis, he was looking at the big picture of cybersecurity markets and trends. He discussed security challenges with CISOs and other security buyers on a regular basis, both directly and through the Security Tinkerers community he founded. All this led to a decision to quit the VC world to become a founder himself. Of all the categories he could have chosen, he chose identity security, and that's why we're happy to have him for this conversation. Segment Resources: The Future of Identity AKA Identity promo video focused on the future of Identity We start off discussing the latest round of fundings, centered largely around data security and securing LLM use. This dovetails into a discussion about marketing language and how difficult it can be for buyers to work out what the latest round of early stage startups are doing. Next, we discuss Cloudflare and Bugcrowd's acquisitions, as well as Synopsys's divestiture of its appsec portfolio. From here, we dive into a raft of new features across both IT and cybersecurity products, like Azure, Dashlane, LastPass, and PagerDuty. Discussing Huntress's active remediation feature triggers a conversation about this latest product trend: vendors seem to think buyers are ready for fully automated remediation actions. We're not so sure they are. To wrap up the cybersecurity coverage, Brandon Dixon has an interesting tutorial regarding a Security Copilot use case that looks a LOT like the default phishing enrichment use case that has been used for every SOAR POC ever. To clarify, this is a great piece in that it is all practical, has no marketing fluff, and shows you how to do something useful with Security Copilot. Where it pulls up short is managing to live up to the hype we've been hearing about Security Copilot from day one. We agree to table the discussion on Microsoft Recall until we know more about what GA of the feature will look like, and then dig into a VERY interesting squirrel story about an audio-based hacking puzzle created by a rock band. The interview will delve into the healthcare industry's tumultuous year in 2023, marked by 124 million breached health records across 725 hacking incidents (according to The HIPAA Journal). This interview will explore the critical role that MSSPs play in safeguarding health data and systems against potential security incidents, such as ransomware and business email compromise attacks. Jim Broome will share how to proactively prepare for an incident - including establishing a comprehensive incident response plan, outlining strategies for containment, restoration, and ongoing security operations, and how an MSSP can help. Segment Resources: Tales from the Road Blog: An External Pen Test at a Healthcare Organization Reveals the Dangers of the Dark Web - https://www.directdefense.com/tales-from-the-road-an-external-pen-test-reveals-the-dangers-of-the-dark-web/ 2023 Security Operations Threat Report: https://go.directdefense.com/2023-Security-Operations-Threat-Report This segment is sponsored by DirectDefense. Visit https://securityweekly.com/directdefensersac to learn more about them! In the dynamic landscape of cybersecurity, the urgency to eliminate passwords as a security vulnerability has never been more critical. Organizations are continuing to face a surge in the variety and complexity of cyber threats at historical rates, often fueled by compromised employee login credentials – resulting from attacks such as phishing which has been exacerbated by the rise in use of Artificial Intelligence (AI). The 2023 Verizon Data Breach Investigations Report underscores the staggering impact of breaches caused by stolen credentials, accounting for a staggering 74% of incidents. Christopher Harrell, Yubico's Chief Technology Officer, shares how organizations can achieve passwordless authentication at scale with high assurance phishing-resistant multi-factor authentication (MFA) to elevate their security posture against phishing attacks while creating phishing-resistant users. Segment Resources: https://www.yubico.com/blog/empowering-enterprise-security-at-scale-with-new-product-innovations-yubikey-5-7-and-yubico-authenticator-7/ https://www.yubico.com/press-releases/yubicos-key-product-innovations-empower-enterprise-security-and-phishing-resistant-passwordless-authentication-at-scale/ This segment is sponsored by Yubico. Visit https://securityweekly.com/yubicorsac to learn more about them! In this podcast segment, we delve into Sophos' fifth annual State of Ransomware report, exploring significant findings and trends in the evolving ransomware landscape. We'll discuss the sharp increase in recovery costs, the strategic targeting of backups by hackers, and the evolving role of cyber insurance in ransom payments. Our discussion will provide insights into how organizations can adapt their cybersecurity measures to mitigate these heightened threats and recover more effectively from attacks. Segment Resources: Blog: The State of Ransomware 2024 Report: https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2024-wp.pdf Press release: Ransomware Payments Increase 500% In the Last Year, Finds Sophos State of Ransomware Report This segment is sponsored by Sophos. Visit https://www.securityweekly.com/sophosrsac to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-364
Today we interview Shane Sims, CEO of Kivu Consulting. We'll be talking about the current state of cybercrime and insights from incidents his consulting firm has recently worked. We'll discuss some of the latest stats and trends related to ransomware, as well as thoughts on future cybercrime trends. Shane will also share some stories from his time as an FBI agent, working undercover as a cybercriminal. Segment Resources: Report - Mitigating Ransomware Risk: Determining Optimal Strategies for Business One of the biggest challenges in security today is organizations' reluctance to share attack information. Perhaps legal teams are worried about liability, or maybe execs are just embarrassed about security failures. Whatever the reason, this trend makes it difficult for organizations to help each other. CrowdSec's mission is to make this process automated, anonymized, and seamless for security teams. We talk to Phillip Humeau, one of CrowdSec's founders, about what it's like to build a such an unconventional cybersecurity business - one based around crowdsourcing and open source software. This week, in the enterprise security news, AI dominates new funding rounds (I'm shocked. This is my shocked face.) The buyer's market continues, with lots of small acquisitions SingTel sells off Trustwave at a significant loss Yubico goes public (actually, a month ago, sorry we missed it) Yubico can also now ship pre-registered security keys New cybersecurity tools for board and exec-level folks Lessons learned from recent ransomware attacks Healthcare is increasingly under attack A study on CISO tenure - longer than you might think! Don't miss today's squirrel stories at the end! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly Show Notes: https://securityweekly.com/esw-336
Today we interview Shane Sims, CEO of Kivu Consulting. We'll be talking about the current state of cybercrime and insights from incidents his consulting firm has recently worked. We'll discuss some of the latest stats and trends related to ransomware, as well as thoughts on future cybercrime trends. Shane will also share some stories from his time as an FBI agent, working undercover as a cybercriminal. Segment Resources: Report - Mitigating Ransomware Risk: Determining Optimal Strategies for Business One of the biggest challenges in security today is organizations' reluctance to share attack information. Perhaps legal teams are worried about liability, or maybe execs are just embarrassed about security failures. Whatever the reason, this trend makes it difficult for organizations to help each other. CrowdSec's mission is to make this process automated, anonymized, and seamless for security teams. We talk to Phillip Humeau, one of CrowdSec's founders, about what it's like to build a such an unconventional cybersecurity business - one based around crowdsourcing and open source software. This week, in the enterprise security news, AI dominates new funding rounds (I'm shocked. This is my shocked face.) The buyer's market continues, with lots of small acquisitions SingTel sells off Trustwave at a significant loss Yubico goes public (actually, a month ago, sorry we missed it) Yubico can also now ship pre-registered security keys New cybersecurity tools for board and exec-level folks Lessons learned from recent ransomware attacks Healthcare is increasingly under attack A study on CISO tenure - longer than you might think! Don't miss today's squirrel stories at the end! All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Follow us on Twitter: https://www.twitter.com/securityweekly Like us on Facebook: https://www.facebook.com/secweekly Show Notes: https://securityweekly.com/esw-336
This week, in the enterprise security news, AI dominates new funding rounds (I'm shocked. This is my shocked face.) The buyer's market continues, with lots of small acquisitions SingTel sells off Trustwave at a significant loss Yubico goes public (actually, a month ago, sorry we missed it) Yubico can also now ship pre-registered security keys New cybersecurity tools for board and exec-level folks Lessons learned from recent ransomware attacks Healthcare is increasingly under attack A study on CISO tenure - longer than you might think! Don't miss today's squirrel stories at the end! All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-336
Patrick Gray speaks to Yubico's Jerrod Chong about how organisations can better verify the identities of users when performing MFA resets. In other words, how to not get MGM'd. He also talks about the chain-of-trust issues inherent to synchronisable passkey implementations.
Patrick Gray speaks to Yubico's Jerrod Chong about how organisations can better verify the identities of users when performing MFA resets. In other words, how to not get MGM'd. He also talks about the chain-of-trust issues inherent to synchronisable passkey implementations.
Threat actors are really enjoying home networks and BYOD these days… On this week's show Patrick Gray and Adam Boileau discuss the week's security news, including: Why our LastPass/DPRK hunch weakened CISA launches ransomware warning program Is the Ring data extortion real? White House flags cloud service security regulation Pig Butchering overtakes BEC as top cybercrime earner Much more! This week's show is sponsored by Yubico. The company's COO, Jerrod Chong, is this week's sponsor guest. Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that's your thing. Show notes Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 | Mandiant Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW | Mandiant North Korean hackers target security researchers with a new backdoor | Ars Technica Ring won't say if it was hacked after ransomware gang claims attack | TechCrunch Biden admin's cloud security problem: ‘It could take down the internet like a stack of dominos' - POLITICO CISA unveils ransomware warning pilot for critical infrastructure Data breach hits lawmakers and staff on Capitol Hill Hacker posts more D.C. Health Link data online, exposing lawmakers' personal information | CyberScoop Cancer patient sues medical provider after ransomware group posts her photos online | CyberScoop Telehealth startup Cerebral shared millions of patients' data with advertisers | TechCrunch The FBI Just Admitted It Bought US Location Data | WIRED ‘Pig Butchering' Scams Are Now a $3 Billion Threat | WIRED Malware infecting widely used security appliance survives firmware updates | Ars Technica People Used Facebook's Leaked AI to Create a 'Based' Chatbot that Says the N-Word OpenAI releases GPT-4, artificial intelligence that can 'see' and do taxes Australian official demands Russia bring criminal hackers ‘to heel' DEV-1101 enables high-volume AiTM campaigns with open-source phishing kit - Microsoft Security Blog Sued by Meta, Freenom Halts Domain Registrations – Krebs on Security Twitter's Most Important Anti-Censorship Tool Is Currently Dead CVE-2023-23415 - Security Update Guide - Microsoft - Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability CVE-2023-23397 - Security Update Guide - Microsoft - Microsoft Outlook Elevation of Privilege Vulnerability
Threat actors are really enjoying home networks and BYOD these days… On this week's show Patrick Gray and Adam Boileau discuss the week's security news, including: Why our LastPass/DPRK hunch weakened CISA launches ransomware warning program Is the Ring data extortion real? White House flags cloud service security regulation Pig Butchering overtakes BEC as top cybercrime earner Much more! This week's show is sponsored by Yubico. The company's COO, Jerrod Chong, is this week's sponsor guest. Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that's your thing. Show notes Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 | Mandiant Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW | Mandiant North Korean hackers target security researchers with a new backdoor | Ars Technica Ring won't say if it was hacked after ransomware gang claims attack | TechCrunch Biden admin's cloud security problem: ‘It could take down the internet like a stack of dominos' - POLITICO CISA unveils ransomware warning pilot for critical infrastructure Data breach hits lawmakers and staff on Capitol Hill Hacker posts more D.C. Health Link data online, exposing lawmakers' personal information | CyberScoop Cancer patient sues medical provider after ransomware group posts her photos online | CyberScoop Telehealth startup Cerebral shared millions of patients' data with advertisers | TechCrunch The FBI Just Admitted It Bought US Location Data | WIRED ‘Pig Butchering' Scams Are Now a $3 Billion Threat | WIRED Malware infecting widely used security appliance survives firmware updates | Ars Technica People Used Facebook's Leaked AI to Create a 'Based' Chatbot that Says the N-Word OpenAI releases GPT-4, artificial intelligence that can 'see' and do taxes Australian official demands Russia bring criminal hackers ‘to heel' DEV-1101 enables high-volume AiTM campaigns with open-source phishing kit - Microsoft Security Blog Sued by Meta, Freenom Halts Domain Registrations – Krebs on Security Twitter's Most Important Anti-Censorship Tool Is Currently Dead CVE-2023-23415 - Security Update Guide - Microsoft - Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability CVE-2023-23397 - Security Update Guide - Microsoft - Microsoft Outlook Elevation of Privilege Vulnerability
Yubico, the company behind the YubiKey, is revolutionizing online security with its hardware-based security keys. These keys provide an extra layer of protection for your online accounts, making them less vulnerable to cyber threats such as phishing, man-in-the-middle (MitM) attacks, SIM swapping and account takeovers. The YubiKey is the world's first security key and protects over 4,000 organizations worldwide. The shift to remote work due to the pandemic has highlighted the need for better cybersecurity measures. According to Yubico's research, 42% of people feel more vulnerable to cyber threats while working from home, and 39% feel unsupported by IT. However, hardware-based security keys like the YubiKey provide a more secure solution while reducing friction at login. They meet the FIDO2 and WebAuthn standards, helping to pave the way for interoperability. Niall McConachie, Regional Director (UK & Ireland) at Yubico discusses the most common cyber threats people face and why not all security is equal. He emphasized that while one-time passcodes (OTPs) sent by SMS or mobile authentication apps are the most popular forms of two-factor authentication (2FA), they are still vulnerable to attacks. On the other hand, hardware-based security keys provide strong authentication and reduce the friction of logging in to multiple apps and accounts each day. Niall also discusses the future of secure, passwordless authentication. The evolving modern authentication ecosystem, with the help of hardware-based security keys, is paving the way for a future where passwords are no longer the primary form of authentication. This not only makes our online accounts more secure, but also reduces the hassle of remembering multiple passwords. Sponsored VPN Offer https://www.piavpn.com/techtalksdaily