A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
…
continue reading
"Data at Rest" is an accessible but informed discussion of current concepts, best practices, and personal experiences in computer security, network security, and information security overall, including interviews with expert guests and the history of each topic.
…
continue reading

1
Socvel intel threat quiz, Pearson Breached, nintendo bricking stuff, and kevintel.com
1:24:40
1:24:40
Play later
Play later
Lists
Like
Liked
1:24:40socvel.com/quiz if you want to play along! Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec join the Discord: https://bit.ly/brakesecDiscord Music: Music provided by Chillhop Music: https://chillhop.ffm.to/creatorcred "Flex" by Jeremy Blake Courtesy of Youtube media libraryBy Bryan Brake
…
continue reading

1
Bronwen Aker - harnessing AI for improving your workflows
1:37:26
1:37:26
Play later
Play later
Lists
Like
Liked
1:37:26Guest Info: Name: Bronwen Aker Contact Information (N/A): https://br0nw3n.com/ Time Zone(s): Pacific, Central, Eastern –Copy begins– Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change…
…
continue reading

1
post-bsides SD discussion, EPSS, the answer I should have given, and 'Lord Brake'
1:16:45
1:16:45
Play later
Play later
Lists
Like
Liked
1:16:45Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec or Youtube: https://youtube.com/c/BDSPodcast join the Discord: https://bit.ly/brakesecDiscord https://arxiv.org/abs/2302.14172 - EPSS whitepaper https://www.linkedin.com/posts/jayjacobs1_epss-threatintel-vulnerabiltymanagement-activity-7308146548767404032-RubN https://www.first.org/epss/…
…
continue reading

1
March23: buy browser extensions, attackers don't need exploits, socvel CTI quiz
1:12:38
1:12:38
Play later
Play later
Lists
Like
Liked
1:12:38Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec Join the Discord! https://bit.ly/brakesecDiscord Questions and topics: (please feel free to update or make comments for clarifications) * https://techoreon.com/http-flaw-in-apple-passwords-left-iphones-vulnerable/ * https://darkmarc.substack.com/p/attackers-dont-need-exploits-when * http…
…
continue reading

1
steam distributes malware in game form, RDP open from DOGE servers, hacking a supply chain for 50K
1:01:47
1:01:47
Play later
Play later
Lists
Like
Liked
1:01:47Youtube VOD: https://www.youtube.com/watch?v=zu_smyQGvG4 https://lcamtuf.substack.com/p/how-security-teams-fail https://cyberintel.substack.com/p/doge-exposes-once-secret-government https://x.com/SteamDB/status/1889610974484705314 – supply chain issues can crop up anywhere… are you blocking people from steam and popular software downloads online? h…
…
continue reading

1
Tanya Janca Talks secure coding, Semgrep Academy, and community building, and more!
1:27:18
1:27:18
Play later
Play later
Lists
Like
Liked
1:27:18Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec Join the Discord! https://discord.gg/brakesec #youtube VOD (in 1440p): https://www.youtube.com/watch?v=axQWGyd79NM Questions and topics: Bsides Vancouver discussion Semgrep Community and Academy Building communities What are ‘secure guardrails’ Reducing barriers between security and deve…
…
continue reading

1
Josh Grossman - building Appsec programs, bridging security and developer gaps
1:16:22
1:16:22
Play later
Play later
Lists
Like
Liked
1:16:22Youtube VOD: https://youtu.be/G3PxZFmDyj4 #appsec, #owasp, #ASVS, #joshGrossman, #informationsecurity, #SBOM, #supplychain, #podcast, #twitch, #brakesec, #securecoding, #Codeanalysis Questions and topics: 1. The background to the topic, why is it something that interests you? How do you convince developers to take your course? 2. What do you think …
…
continue reading

1
Managing messaging with management, becoming a CISO with Mary Gardner from Goldiknox
1:22:56
1:22:56
Play later
Play later
Lists
Like
Liked
1:22:56Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time based on new information and experiences and do not represent views of past, present, or future employers. Recorded: 08 …
…
continue reading

1
p2-accidentalCISO, building trust in new places
1:13:51
1:13:51
Play later
Play later
Lists
Like
Liked
1:13:51Full Youtube VOD: https://www.youtube.com/watch?v=uX7odQTBkyQ Questions and topics: Let’s talk about Mindful Business Podcast What’s the topics you cover? Topic #1: discuss your experiences when you were a new leader. What worked? What didn't? What would you have done differently? Do you emulate your manager's style? What have been your go-to manag…
…
continue reading

1
AccidentalCISO on BrakeSecEd, talking Leadership, SaaS development, and Appsec
29:35
29:35
Play later
Play later
Lists
Like
Liked
29:35Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time based on new information, and do not represent views of past, present, or future employers. Recorded: 28 Jan 2024 Youtub…
…
continue reading

1
1st show of 2024! Our 10th Anniversary...
59:35
59:35
Play later
Play later
Lists
Like
Liked
59:35It's our 10th anniversary and the first show of our 2024 season! Amanda was on "7 minute security" https://7minsec.com/projects/podcast Check out the complete VOD at https://youtu.be/vbmEtkxhAMg Explicit language warning www.brakeingsecurity.com https://twitch.tv/brakesec https://bit.ly/brakesecytBy Brian Boettcher, Bryan Brake, and Amanda Berlin
…
continue reading
Youtube Video: https://youtu.be/IUDPlQaQg8M https://forms.gle/rf145MoN7cskwMjf8 is the link to the survey. Your information (should you choose to identify yourself) will not be shared outside of the BrakeSec Team. Thank all of you for listening and for your input. RSS feed for the audio podcast is at https://www.brakeingsecurity.com/rss website: ht…
…
continue reading

1
How to get more headcount, BLUFFs Vulnerability, and Ranty Clause debuts!
1:19:11
1:19:11
Play later
Play later
Lists
Like
Liked
1:19:11Show Topic Summary: Ms. Berlin proposes a question of how to gather more headcount with metrics, we discuss the BLUFFS bluetooth vulnerability, and “Ranty Claus” talks about CISA’s remarks of putting the onus on device product makers to remove choice for customers and implement secure defaults. #youtube VOD: https://www.youtube.com/watch?v=emcAzTx9…
…
continue reading

1
25Oct - okta breached (again), Energy company hit by supply chain attack, and you can help hire the best people
45:53
45:53
Play later
Play later
Lists
Like
Liked
45:53Subscribe on Twitch using Amazon Prime and watch us live: https://twitch.tv/brakesec Check out our VODs on Youtube: https://www.youtube.com/@BrakeSecEd Join the BrakeSecEd discord: https://discord.gg/brakesec News: https://www.darkreading.com/remote-workforce/1password-latest-victim-okta-customer-service-breach https://www.documentcloud.org/documen…
…
continue reading

1
Nicole Sundin - CPO at Axio - SEC compliance, usable security, setting up risk mgmt programs
1:06:08
1:06:08
Play later
Play later
Lists
Like
Liked
1:06:08Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers. Guest Bio: Nicole is the Chief Product Officer at Axi…
…
continue reading

1
John Aron, letters of marque, what does a "junior" job look like with AI?
1:25:21
1:25:21
Play later
Play later
Lists
Like
Liked
1:25:21Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers. Guest Bio: John is the CEO of Aronetics. An avid clim…
…
continue reading

1
Megan Roddie - co-author of "Practical Threat Detecion Engineering"
1:46:53
1:46:53
Play later
Play later
Lists
Like
Liked
1:46:53Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers. Buy here: https://subscription.packtpub.com/book/secu…
…
continue reading

1
D@R 06x05 - UNC CAUSE 2022 - Open Doors, Zero Trust
44:07
44:07
Play later
Play later
Lists
Like
Liked
44:07Recorded in front of a live audience at UNC CAUSE in October, 2022! The Zero Trust Framework raises valid questions about risk reduction. But, as one CISO used to say, "we have to trust someone eventually, right?" Or do we? Universities, are built on a philosophy of openness and enrichment of public understanding. How do we preserve the public's tr…
…
continue reading

1
D@R 06x04 - Incident Handling Revisited (COBRAAAAAAAAAA!)
49:04
49:04
Play later
Play later
Lists
Like
Liked
49:04Charlie and Michael are joined by Drew Trumbull, Incident Handling Team Lead for UNC Chapel Hill's Information Security Office, to talk about the latest threats we see and what folks should do if they think they might have been targeted successfully by them, plus the importance of compassion and empathy in our field. There are also side discussions…
…
continue reading

1
meeting new people, walking on your keyboard causes issues, even google gets phone numbers wrong.
1:20:11
1:20:11
Play later
Play later
Lists
Like
Liked
1:20:11Check out our sponsor (BLUMIRA) at https://blumira.com/brake youtube channel link: https://youtube.com/c/BDSPodcast Full video on our youtube Channel! https://www.youtube.com/watch?v=BkBeLuM_urk https://www.rapid7.com/blog/post/2023/07/11/cve-2023-29298-adobe-coldfusion-access-control-bypass/ https://www.darkreading.com/remote-workforce/hacker-infe…
…
continue reading

1
Bsides Seattle and Austin, SecureBoot patch, and more
1:12:36
1:12:36
Play later
Play later
Lists
Like
Liked
1:12:36BrakeSec Show Outline – No Guest Show Topic Summary (less than 300 words) Bsides Seattle and Bsides Austin Youtube VOD: https://youtube.com/live/UGRaRSYj7kc Questions and potential sub-topics (5 minimum): Bsides Seattle update and Bsides Austin Patching the unpatchable https://en.wikipedia.org/wiki/Parkerian_Hexad Power and influence (is power bad?…
…
continue reading

1
lynsey wolf, conducting insider threat investigations, CASB and UEBA utlization to good use.
1:34:09
1:34:09
Play later
Play later
Lists
Like
Liked
1:34:09Show Topic Summary (less than 300 words) Insider threat still exists, Lynsey Wolf talks with us about HR’s role in insider threat, how prevalent investigations are in the post-pandemic work from home environment. Questions and potential sub-topics (5 minimum): What is the difference between insider threat and insider risk? Motivators of insider thr…
…
continue reading

1
D@R 06x03 - Privacy, Policy, and Privacy Policies
37:36
37:36
Play later
Play later
Lists
Like
Liked
37:36Security and privacy are often mentioned hand-in-hand in our industry, but they're actually very different fields with different considerations and concerns--and the policies applying to one are not necessarily meant to address those of the other. Charlie and Michael welcome Kim Stahl, Senior Policy and Process Lead for UNC Chapel Hill's Informatio…
…
continue reading

1
D@R 06x02 - Communicating with Students & Young Users
37:53
37:53
Play later
Play later
Lists
Like
Liked
37:53Charlie and Michael have discussed communicating security risks and strategies to older users and at-risk users, but what about students and younger users? We welcome guests Lila Davidson and Louise Flinn from the UNC Chapel Hill ITS Communications team to discuss things to consider when we do outreach focusing on students and others on the cusp of…
…
continue reading
Anyone who works in information security knows that we, perhaps more than any other IT sector, are reliant on a forest of vendors, each promising the moon and often duplicating others' capabilities. Join Charlie and Michael for a frank discussion of the best and worst parts of managing those vendor relationships and what we look to gain from them. …
…
continue reading

1
3CX supply chain attack, Mark Russinovich and Sysinternals, CISA ransomware notifications, and emotional intelligence
1:24:50
1:24:50
Play later
Play later
Lists
Like
Liked
1:24:50Show Topic Summary (less than 300 words) 3CX supply chain attack, Mark Russinovich and Sysinternals, ransomware notifications from CISA, and emotional intelligence Youtube VOD: https://www.youtube.com/watch?v=afZHiBUr-2g Questions and potential topics (5 minimum): https://www.straitstimes.com/tech/downloading-a-cracked-version-of-fifa-23-or-hogwart…
…
continue reading

1
Dish Network is still busted, John Deere avoiding OSS requests, Is DAST dead?
1:29:37
1:29:37
Play later
Play later
Lists
Like
Liked
1:29:37Show Topic Summary (less than 300 words) Dish Network is still busted due to ransomware, your Pixel phone baseband RCE, Nothing runs like a Deere (away from OSS requests, anyway), and “Are we past DAST?” Questions and potential sub-topics (5 minimum): https://techcrunch.com/2023/03/15/dish-customers-kept-in-the-dark-as-ransomware-fallout-continues/…
…
continue reading

1
Nickolas Means talks about Security, Devops velocity, blameless orgs, and conferences infosec should attend
1:14:50
1:14:50
Play later
Play later
Lists
Like
Liked
1:14:50Guest info Name and Title: Nickolas Means, VP of Engineering at SYM Email/Social Media Contact: @nmeans on Twitter, @[email protected] on Mastodon Time Zone (if other than Pacific): Central (Austin, TX) Show Topic Summary / Intro We welcome Nickolas Means to the stream. Nick is the VP of Engineering at Sym, the adaptive access tool built for devel…
…
continue reading