25 episodios

A news analysis focused information security podcast dedicated to getting you the actionable information and analysis you need to improve your company's posture and response!

Security Serengeti David Schwendinger and Matthew Keener

    • Tecnología

A news analysis focused information security podcast dedicated to getting you the actionable information and analysis you need to improve your company's posture and response!

    SS-NEWS-145 - Snowflakes are not unique, summary of incidents at .gov

    SS-NEWS-145 - Snowflakes are not unique, summary of incidents at .gov

    This week we discuss the FY23 incidents in the US Government's annual report, and then we discuss Snowflake a bit, and some of the issues around SAAS and Malware Remediation (infostealers steal more than just the work accounts!)
    Article 1 - White House report dishes deets on all 11 major government breaches from 2023Supporting Article:Microsoft breach led to theft of 60,000 US State Dept emails
    Article 2 - Snowflake customers not using MFA are not unique – over 165 of them have been compromisedSupporting Articles:UNC5537 Targets Snowflake Customer Instances for Data Theft and ExtortionNo Snow, No Flakes: Pondering Cloud Security Shared Responsibility, Again!Mapping Snowflake’s Access Landscape
    If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

    • 44 min
    SS-NEWS-144

    SS-NEWS-144

    This week we discuss the shocking new revelation of ORB networks!  Oh wait, it's just a rebrand.  Still, kind of interesting.  Then we talk about the privacy implications of Apple and Android Wifi Positioning Systems, which is a little overblown, but still interesting.  Wow, this week was kind of a disappointment.  
    Article 1 - Chinese-linked hacking units increasingly use ‘ORBs’ to obfuscate espionage, researchers saySupporting Article:Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warns
    Article 2 - Privacy Implications of Tracking Wireless Access Points
    If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

    • 51 min
    SS-NEWS-143: Minimum Viable SOC Transformation!

    SS-NEWS-143: Minimum Viable SOC Transformation!

    We turn back to one of my (Matthew's) favorite analysts, Anton Chuvakin and his recent article on what a Minimum Viable SOC Transformation looks like.  Then we take a few minutes at the end to discuss making self-driving cars ignore stop signs. Cheeky and fun shenanigans!
    Article 1 - Baby ASO: A Minimal Viable Transformation for Your SOC
    Article 2 - GhostStripe attack haunts self-driving cars by making them ignore road signs
    If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

    • 52 min
    SS-NEWS-142: GM Sharing Driving Data, Testing Detections

    SS-NEWS-142: GM Sharing Driving Data, Testing Detections

    This week, David and I discuss how GM is fraudulently collecting driving data and selling it to insurers, and Anton Chuvakin has another article on Detection Engineering - How to test your detections!
    Article 1 - Long Article on GM Spying on Its Cars’ DriversSupporting Articles:How GM Tricked Millions of Drivers Into Being Spied On (Including Me) [Non-Paywalled]GM Shuts Down Tool That Collects Data on Driving Style
    Article 2 - Testing in Detection Engineering (Part 8)
    If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

    • 45 min
    SS-NEWS-141: American Privacy Rights Act

    SS-NEWS-141: American Privacy Rights Act

    This week we review the new, proposed American Privacy Rights Act.  Lots of words that sound good, but like most government legislation, there are exceptions big enough to drive a truck through.
    Article - Committee Chairs Rodgers, Cantwell Unveil Historic Draft Comprehensive Data Privacy LegislationSupport Links:Philip Dru: Administrator
    If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

    • 49 min
    SS-RPRT-140: Consolidation and Merging in Cybersecurity

    SS-RPRT-140: Consolidation and Merging in Cybersecurity

    This week David and I discuss an article from Venture in Security on how other industries have consolidated, and what lessons we can take from that into Security.  It's more interesting than it sounds, I swear!
    Article - Three types of consolidation in cybersecurity, and how monopolization and commoditization are shaping the industry of tomorrow
    If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

    • 43 min

Top podcasts en Tecnología

Programa tu mente
Daniel Cubillos
Topes de Gama Unplugged
Topes De Gama
Acquired
Ben Gilbert and David Rosenthal
Applelianos
Applelianos
Miércoles de QA Minders
QA Minds
The Real Python Podcast
Real Python