A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
…
continue reading

1
Socvel intel threat quiz, Pearson Breached, nintendo bricking stuff, and kevintel.com
1:24:40
1:24:40
Play later
Play later
Lists
Like
Liked
1:24:40socvel.com/quiz if you want to play along! Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec join the Discord: https://bit.ly/brakesecDiscord Music: Music provided by Chillhop Music: https://chillhop.ffm.to/creatorcred "Flex" by Jeremy Blake Courtesy of Youtube media libraryBy Bryan Brake
…
continue reading

1
Bronwen Aker - harnessing AI for improving your workflows
1:37:26
1:37:26
Play later
Play later
Lists
Like
Liked
1:37:26Guest Info: Name: Bronwen Aker Contact Information (N/A): https://br0nw3n.com/ Time Zone(s): Pacific, Central, Eastern –Copy begins– Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change…
…
continue reading

1
post-bsides SD discussion, EPSS, the answer I should have given, and 'Lord Brake'
1:16:45
1:16:45
Play later
Play later
Lists
Like
Liked
1:16:45Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec or Youtube: https://youtube.com/c/BDSPodcast join the Discord: https://bit.ly/brakesecDiscord https://arxiv.org/abs/2302.14172 - EPSS whitepaper https://www.linkedin.com/posts/jayjacobs1_epss-threatintel-vulnerabiltymanagement-activity-7308146548767404032-RubN https://www.first.org/epss/…
…
continue reading

1
March23: buy browser extensions, attackers don't need exploits, socvel CTI quiz
1:12:38
1:12:38
Play later
Play later
Lists
Like
Liked
1:12:38Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec Join the Discord! https://bit.ly/brakesecDiscord Questions and topics: (please feel free to update or make comments for clarifications) * https://techoreon.com/http-flaw-in-apple-passwords-left-iphones-vulnerable/ * https://darkmarc.substack.com/p/attackers-dont-need-exploits-when * http…
…
continue reading

1
steam distributes malware in game form, RDP open from DOGE servers, hacking a supply chain for 50K
1:01:47
1:01:47
Play later
Play later
Lists
Like
Liked
1:01:47Youtube VOD: https://www.youtube.com/watch?v=zu_smyQGvG4 https://lcamtuf.substack.com/p/how-security-teams-fail https://cyberintel.substack.com/p/doge-exposes-once-secret-government https://x.com/SteamDB/status/1889610974484705314 – supply chain issues can crop up anywhere… are you blocking people from steam and popular software downloads online? h…
…
continue reading

1
Tanya Janca Talks secure coding, Semgrep Academy, and community building, and more!
1:27:18
1:27:18
Play later
Play later
Lists
Like
Liked
1:27:18Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec Join the Discord! https://discord.gg/brakesec #youtube VOD (in 1440p): https://www.youtube.com/watch?v=axQWGyd79NM Questions and topics: Bsides Vancouver discussion Semgrep Community and Academy Building communities What are ‘secure guardrails’ Reducing barriers between security and deve…
…
continue reading

1
Josh Grossman - building Appsec programs, bridging security and developer gaps
1:16:22
1:16:22
Play later
Play later
Lists
Like
Liked
1:16:22Youtube VOD: https://youtu.be/G3PxZFmDyj4 #appsec, #owasp, #ASVS, #joshGrossman, #informationsecurity, #SBOM, #supplychain, #podcast, #twitch, #brakesec, #securecoding, #Codeanalysis Questions and topics: 1. The background to the topic, why is it something that interests you? How do you convince developers to take your course? 2. What do you think …
…
continue reading

1
Managing messaging with management, becoming a CISO with Mary Gardner from Goldiknox
1:22:56
1:22:56
Play later
Play later
Lists
Like
Liked
1:22:56Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time based on new information and experiences and do not represent views of past, present, or future employers. Recorded: 08 …
…
continue reading

1
p2-accidentalCISO, building trust in new places
1:13:51
1:13:51
Play later
Play later
Lists
Like
Liked
1:13:51Full Youtube VOD: https://www.youtube.com/watch?v=uX7odQTBkyQ Questions and topics: Let’s talk about Mindful Business Podcast What’s the topics you cover? Topic #1: discuss your experiences when you were a new leader. What worked? What didn't? What would you have done differently? Do you emulate your manager's style? What have been your go-to manag…
…
continue reading

1
AccidentalCISO on BrakeSecEd, talking Leadership, SaaS development, and Appsec
29:35
29:35
Play later
Play later
Lists
Like
Liked
29:35Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time based on new information, and do not represent views of past, present, or future employers. Recorded: 28 Jan 2024 Youtub…
…
continue reading

1
1st show of 2024! Our 10th Anniversary...
59:35
59:35
Play later
Play later
Lists
Like
Liked
59:35It's our 10th anniversary and the first show of our 2024 season! Amanda was on "7 minute security" https://7minsec.com/projects/podcast Check out the complete VOD at https://youtu.be/vbmEtkxhAMg Explicit language warning www.brakeingsecurity.com https://twitch.tv/brakesec https://bit.ly/brakesecytBy Brian Boettcher, Bryan Brake, and Amanda Berlin
…
continue reading
Youtube Video: https://youtu.be/IUDPlQaQg8M https://forms.gle/rf145MoN7cskwMjf8 is the link to the survey. Your information (should you choose to identify yourself) will not be shared outside of the BrakeSec Team. Thank all of you for listening and for your input. RSS feed for the audio podcast is at https://www.brakeingsecurity.com/rss website: ht…
…
continue reading

1
How to get more headcount, BLUFFs Vulnerability, and Ranty Clause debuts!
1:19:11
1:19:11
Play later
Play later
Lists
Like
Liked
1:19:11Show Topic Summary: Ms. Berlin proposes a question of how to gather more headcount with metrics, we discuss the BLUFFS bluetooth vulnerability, and “Ranty Claus” talks about CISA’s remarks of putting the onus on device product makers to remove choice for customers and implement secure defaults. #youtube VOD: https://www.youtube.com/watch?v=emcAzTx9…
…
continue reading

1
25Oct - okta breached (again), Energy company hit by supply chain attack, and you can help hire the best people
45:53
45:53
Play later
Play later
Lists
Like
Liked
45:53Subscribe on Twitch using Amazon Prime and watch us live: https://twitch.tv/brakesec Check out our VODs on Youtube: https://www.youtube.com/@BrakeSecEd Join the BrakeSecEd discord: https://discord.gg/brakesec News: https://www.darkreading.com/remote-workforce/1password-latest-victim-okta-customer-service-breach https://www.documentcloud.org/documen…
…
continue reading

1
Nicole Sundin - CPO at Axio - SEC compliance, usable security, setting up risk mgmt programs
1:06:08
1:06:08
Play later
Play later
Lists
Like
Liked
1:06:08Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers. Guest Bio: Nicole is the Chief Product Officer at Axi…
…
continue reading

1
John Aron, letters of marque, what does a "junior" job look like with AI?
1:25:21
1:25:21
Play later
Play later
Lists
Like
Liked
1:25:21Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers. Guest Bio: John is the CEO of Aronetics. An avid clim…
…
continue reading

1
Megan Roddie - co-author of "Practical Threat Detecion Engineering"
1:46:53
1:46:53
Play later
Play later
Lists
Like
Liked
1:46:53Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers. Buy here: https://subscription.packtpub.com/book/secu…
…
continue reading

1
meeting new people, walking on your keyboard causes issues, even google gets phone numbers wrong.
1:20:11
1:20:11
Play later
Play later
Lists
Like
Liked
1:20:11Check out our sponsor (BLUMIRA) at https://blumira.com/brake youtube channel link: https://youtube.com/c/BDSPodcast Full video on our youtube Channel! https://www.youtube.com/watch?v=BkBeLuM_urk https://www.rapid7.com/blog/post/2023/07/11/cve-2023-29298-adobe-coldfusion-access-control-bypass/ https://www.darkreading.com/remote-workforce/hacker-infe…
…
continue reading

1
Bsides Seattle and Austin, SecureBoot patch, and more
1:12:36
1:12:36
Play later
Play later
Lists
Like
Liked
1:12:36BrakeSec Show Outline – No Guest Show Topic Summary (less than 300 words) Bsides Seattle and Bsides Austin Youtube VOD: https://youtube.com/live/UGRaRSYj7kc Questions and potential sub-topics (5 minimum): Bsides Seattle update and Bsides Austin Patching the unpatchable https://en.wikipedia.org/wiki/Parkerian_Hexad Power and influence (is power bad?…
…
continue reading

1
lynsey wolf, conducting insider threat investigations, CASB and UEBA utlization to good use.
1:34:09
1:34:09
Play later
Play later
Lists
Like
Liked
1:34:09Show Topic Summary (less than 300 words) Insider threat still exists, Lynsey Wolf talks with us about HR’s role in insider threat, how prevalent investigations are in the post-pandemic work from home environment. Questions and potential sub-topics (5 minimum): What is the difference between insider threat and insider risk? Motivators of insider thr…
…
continue reading

1
3CX supply chain attack, Mark Russinovich and Sysinternals, CISA ransomware notifications, and emotional intelligence
1:24:50
1:24:50
Play later
Play later
Lists
Like
Liked
1:24:50Show Topic Summary (less than 300 words) 3CX supply chain attack, Mark Russinovich and Sysinternals, ransomware notifications from CISA, and emotional intelligence Youtube VOD: https://www.youtube.com/watch?v=afZHiBUr-2g Questions and potential topics (5 minimum): https://www.straitstimes.com/tech/downloading-a-cracked-version-of-fifa-23-or-hogwart…
…
continue reading

1
Dish Network is still busted, John Deere avoiding OSS requests, Is DAST dead?
1:29:37
1:29:37
Play later
Play later
Lists
Like
Liked
1:29:37Show Topic Summary (less than 300 words) Dish Network is still busted due to ransomware, your Pixel phone baseband RCE, Nothing runs like a Deere (away from OSS requests, anyway), and “Are we past DAST?” Questions and potential sub-topics (5 minimum): https://techcrunch.com/2023/03/15/dish-customers-kept-in-the-dark-as-ransomware-fallout-continues/…
…
continue reading

1
Nickolas Means talks about Security, Devops velocity, blameless orgs, and conferences infosec should attend
1:14:50
1:14:50
Play later
Play later
Lists
Like
Liked
1:14:50Guest info Name and Title: Nickolas Means, VP of Engineering at SYM Email/Social Media Contact: @nmeans on Twitter, @[email protected] on Mastodon Time Zone (if other than Pacific): Central (Austin, TX) Show Topic Summary / Intro We welcome Nickolas Means to the stream. Nick is the VP of Engineering at Sym, the adaptive access tool built for devel…
…
continue reading

1
SPECIAL INTERVIEW: John Aron and Jerod Brennen
1:21:10
1:21:10
Play later
Play later
Lists
Like
Liked
1:21:10BrakeSec Show Outline (all links valid as of 27 Jan 2023, subject to change) Is it scheduled? Yes || No|| Completed Date: 2023/01/26 Guest info Name and Title: John Aron, Founder/CEO of Aronetics Email: [email protected] Time Zone (if other than Pacific): Eastern Standard Guest info Name and Title: Jerod Brennen Email: [email protected] …
…
continue reading

1
Layoff discussions, another TMO breach, OneNote Malware, and more!
1:23:04
1:23:04
Play later
Play later
Lists
Like
Liked
1:23:04Lots of Layoffs (meta, Microsoft, Amazon, Sophos, Alphabet, Google) talk about the future effects of that, did it affect security? Attack surface management is risk management, Breaches and the TSA no-fly list leaked, and more! Full youtube video: https://www.youtube.com/watch?v=1Dgq8FpnWPw Questions and/or potential sub-topics (5 minimum): Layoffs…
…
continue reading