28 episodes

Since 2005, BlueHat has been where the security research community, and Microsoft, come together as peers; to debate, discuss, share, challenge, celebrate and learn. On The BlueHat Podcast, Microsoft and MSRC’s Nic Fillingham and Wendy Zenone will host conversations with researchers and industry leaders, both inside and outside of Microsoft, working to secure the planet’s technology and create a safer world for all. 
Hosted on Acast. See acast.com/privacy for more information.

The BlueHat Podcast Microsoft

    • Technology

Since 2005, BlueHat has been where the security research community, and Microsoft, come together as peers; to debate, discuss, share, challenge, celebrate and learn. On The BlueHat Podcast, Microsoft and MSRC’s Nic Fillingham and Wendy Zenone will host conversations with researchers and industry leaders, both inside and outside of Microsoft, working to secure the planet’s technology and create a safer world for all. 
Hosted on Acast. See acast.com/privacy for more information.

    Beyond the Code: Ethics and AI with Katie Paxton-Fear

    Beyond the Code: Ethics and AI with Katie Paxton-Fear

    Cyber Security Content Creator, Speaker & Ethical Hacker, Katie Paxton-Fear, joins Nic Fillingham on this week's episode of The BlueHat Podcast. Katie holds a PhD in defense and security AI plus cybersecurity and works as an academic, teaching undergraduate students cybersecurity topics. She also runs a popular YouTube channel focused on bug bounty hunting, hacking, and pen testing. Katie shares her journey into cybersecurity, reflects on her initial interest in undeciphered languages and how it parallels her approach to cybersecurity, both involving a fascination with solving mysteries and uncovering hidden meanings.  
     
    In This Episode You Will Learn:    
     
    Approaching AI systems with caution when translating less-documented languages Concerns surrounding the use of copyrighted training data in AI systems Recognizing and addressing AI system limitations and biases in real-world deployments.  
    Some Questions We Ask:     
     
    Can fine-tuning AI models prevent degradation and improve performance? What are the ethical implications of putting sensitive information into AI systems How does relying on niche or obscure training data impact AI models?  
    Resources:  
    View Katie Paxton-Fear on LinkedIn  
    View Wendy Zenone on LinkedIn 
    View Nic Fillingham on LinkedIn 
     
    Related Microsoft Podcasts:  
     
    Microsoft Threat Intelligence Podcast  Afternoon Cyber Tea with Ann Johnson  Uncovering Hidden Risks   
     
    Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

    Hosted on Acast. See acast.com/privacy for more information.

    • 43 min
    SaaS Exposed: Unmasking Cyber Risks in Cloud Integrations

    SaaS Exposed: Unmasking Cyber Risks in Cloud Integrations

    Luke Jennings, VP of Research & Development at Push Security joins Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. Luke explains his recent presentation on a new SaaS cyber kill chain, exploring how attackers might target modern organizations heavily reliant on cloud and SaaS services, even when traditional infrastructure is minimal. The latest kill chain involves developing attack techniques specific to this environment, covering topics like lateral movement without conventional network infrastructure and adapting known techniques such as password guessing attacks to the SaaS landscape. Luke, Wendy, and Nic discuss the complexities of SaaS security, the intricacies of evil twin integrations, detection challenges, mitigation strategies, and the overall impact of these security issues on organizations. 
      
     
    In This Episode You Will Learn:    
     
    Identifying malicious activities and understanding normal application behavior The importance of having structured methodologies for approving SaaS app usage Challenges organizations face in detecting and preventing SaaS application threats  
     
    Some Questions We Ask:     
     
    How can an organization create alerts for new, unknown SaaS app integrations? What happens when a SaaS app integration is duplicated by an attacker? Would having a structured methodology for SaaS app usage help minimize risk?  
    Resources:  
    View Luke Jennings on LinkedIn  
    View Wendy Zenone on LinkedIn 
    View Nic Fillingham on LinkedIn 
     
     
    Related Microsoft Podcasts:  
     
    Microsoft Threat Intelligence Podcast  Afternoon Cyber Tea with Ann Johnson  Uncovering Hidden Risks   
       
    Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

    Hosted on Acast. See acast.com/privacy for more information.

    • 39 min
    Decoding Conference Proposals with Lea Snyder

    Decoding Conference Proposals with Lea Snyder

    Lea Snyder, Principal Security Engineer at Microsoft joins Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. Lea is a security leader focused on security strategy and helping organizations mature their security posture and security programs, focusing on areas including IAM, product security, and risk management. Lea explains her unique role as a security architect, highlighting problem-solving across various domains within Microsoft. She shares her unconventional path to cybersecurity, starting with a background in economics and an MBA, and how she transitioned from IT roles to security. Lea, Wendy, and Nic discuss the importance of diverse backgrounds in the industry and offer advice on entering the cybersecurity field. Lea also discusses her involvement in community-driven conferences, particularly B-sides, highlighting their diverse and unique content. 
      
     
    In This Episode You Will Learn:    
     
    Tips for submitting conference proposals Challenges when balancing anonymity during a submission The importance of a supportive approach in the conference submission process  
    Some Questions We Ask:     
     
    Is there a typical anonymization process to ensure fairness and inclusivity? What are some challenges when selecting talks that resonate with an audience? Can you elaborate on the value behind B-sides conferences and the unique atmosphere?   
    Resources:  
    View Lea Snyder on LinkedIn 
    View Wendy Zenone on LinkedIn 
    View Nic Fillingham on LinkedIn 
     
     
    Related Microsoft Podcasts:  
     
    Microsoft Threat Intelligence Podcast  Afternoon Cyber Tea with Ann Johnson  Uncovering Hidden Risks   
       
    Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

    Hosted on Acast. See acast.com/privacy for more information.

    • 47 min
    Securing the Past with Dustin Heywood

    Securing the Past with Dustin Heywood

    Dustin Heywood, Hacker, Researcher, and Senior Leader at IBM, joins Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. Dustin provided a live demonstration of cracking NTLM version 1 during his BlueHat presentation, showcasing the process of responding to challenges, using coercion techniques, and ultimately extracting and cracking the NTLM hash. Dustin, Nic, and Wendy discuss checking group policies, auditing every object, ensuring relevant systems, and managing IT assets effectively. They emphasize the importance of IT asset management and recommend quarantining legacy systems with restricted access. 
      
     
    In This Episode You Will Learn:    
     
    Why security professionals need business skills for effective communication Advice for auditing legacy systems with vulnerable protocols  Extracting DPAPI keys and decrypting browser session history  
     
    Some Questions We Ask:     
     
    How do you manage risk for legacy systems deemed necessary for business? Can you discuss some of the outdated protocols in current IT environments? What guidance would you offer to IT professionals looking to audit their systems? 
     
    Resources:  
    View Dustin Heywood on LinkedIn 
    View Wendy Zenone on LinkedIn 
    View Nic Fillingham on LinkedIn 
     
     
    Related Microsoft Podcasts:  
     
    Microsoft Threat Intelligence Podcast  Afternoon Cyber Tea with Ann Johnson  Uncovering Hidden Risks   
    Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

    Hosted on Acast. See acast.com/privacy for more information.

    • 41 min
    Breaking Bias: Tera Joyce and Tina Zhang-Powell on Celebrating Women in Cybersecurity

    Breaking Bias: Tera Joyce and Tina Zhang-Powell on Celebrating Women in Cybersecurity

    Microsoft Principal Security Engineering, Tera Joyce and Senior Security Program Manager at Microsoft, Tina Zhang-Powell join Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. As we celebrate International Women's Day and Women's History Month, Tina and Tera join the show to discuss the importance of allies in promoting inclusivity and diversity within the industry. They both  provide valuable perspectives on assumptions made about women in cybersecurity and offer guidance on fostering an inclusive environment. They highlight the importance of leaders being aware of representation and ensuring diverse perspectives are considered in the decision-making processes and share internal resources like mentoring programs and external opportunities such as conferences to support women in the field. Tina and Tera also offer advice to allies, encouraging them to actively include diverse voices and how they can contribute to creating a more inclusive cybersecurity community. 
     
     
    In This Episode You Will Learn:    
     
    The significance of allies in promoting diversity and inclusivity How we can address small instances of unconscious bias The importance of discovering one's calling within the security field  
     
    Some Questions We Ask:     
     
    Can you share any resources or ways to support women in cybersecurity? How can allies better support women in the cybersecurity industry? Any advice for women or individuals interested in entering the tech and cybersecurity field?  
    Resources:  
    View Tera Joyce on LinkedIn 
    View Tina Zhang-Powell on LinkedIn 
    View Wendy Zenone on LinkedIn 
    View Nic Fillingham on LinkedIn 
     
    Related Microsoft Podcasts:  
     
    Microsoft Threat Intelligence Podcast  Afternoon Cyber Tea with Ann Johnson  Uncovering Hidden Risks   
     
    Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

    Hosted on Acast. See acast.com/privacy for more information.

    • 51 min
    Black Voices Matter: The Role of Allyship in Cybersecurity with Devin Price and Derrick Love

    Black Voices Matter: The Role of Allyship in Cybersecurity with Devin Price and Derrick Love

    Microsoft Security Technical Program Manager Devin Price and Sr. Program Manager Derrick Love join Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. The discussion delves into the experience of being Black in the cybersecurity field. Derrick and Devin share their thoughts on the representation of Black individuals in tech, noting the underrepresentation in the field. The significance of representation and allyship is also discussed while emphasizing the importance of paying it forward, mentoring others, and highlighting the responsibility to support those coming up in the field. Devin and Derrick share the importance of involvement with events that promote the black community, black businesses, and black-led nonprofits. These events aim to create a supportive network within the community, particularly for those working in the technology sector. It underlines the significance of adopting a growth mindset, fostering a sense of community, and actively contributing to the empowerment of individuals within the cybersecurity landscape.  
       
    In This Episode You Will Learn:    
     
    How mentorship can help the growth of underrepresented individuals in security Actionable advice for fostering diversity in the industry Why representation and allyship is so vital for Cybersecurity  
    Some Questions We Ask:     
     
    What challenges and rewards come with working in cybersecurity? How can we positively affect and support the Black community in tech? Can you share actionable advice for fostering diversity in the industry?  
    Resources:  
    View Devin Price on LinkedIn  
    View Derrick Love on LinkedIn  
    View Wendy Zenone on LinkedIn 
    View Nic Fillingham on LinkedIn 
    Beam Foundation  
    Sync Seattle  
     
    The Talking Tech Podcast  
    BAM Scholarship 
     
    Related Microsoft Podcasts:  
     
    Microsoft Threat Intelligence Podcast  Afternoon Cyber Tea with Ann Johnson  Uncovering Hidden Risks    
    Discover and follow other Microsoft podcasts at microsoft.com/podcasts

    Hosted on Acast. See acast.com/privacy for more information.

    • 58 min

Top Podcasts In Technology

Dev Interrupted
LinearB
Acquired
Ben Gilbert and David Rosenthal
WhatsApp World: Reviews and Insights
AN WhatsApp APK
HomeKit Insider
AppleInsider
Optimise Your Body with Martin Silva
Optimise Your Body with Martin Silva
Inside SAP S/4HANA Cloud
SAP SE

You Might Also Like

Defense in Depth
David Spark
Risky Business
Patrick Gray
Risky Business News
risky.biz
CyberWire Daily
N2K Networks
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Cyber Security Headlines
CISO Series