

Shared Security Podcast
Tom Eston, Scott Wright, Kevin Johnson
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Johnson break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Episodes
Mentioned books

Dec 20, 2021 • 33min
Log4j Vulnerability, Apple AirTags Used by Thieves, FBI’s Encrypted Messaging App Document
This week we discuss the Apache Log4j vulnerability and the impact it will have on organizations now and into the future, details on how Apple AirTags are being used by thieves to steal cars, and a FBI training document describes what data can be obtained by encrypted messaging apps. ** Links mentioned on the show […]
The post Log4j Vulnerability, Apple AirTags Used by Thieves, FBI’s Encrypted Messaging App Document appeared first on Shared Security Podcast.

Dec 13, 2021 • 30min
Life360 Selling Location Data, NSO Group Spyware Hacks Government Employees, Homecoming Queen Contest Hacked
Life360, a popular family safety app used by 33 million people worldwide, is selling location data to a dozen data brokers, phones of 11 U.S. State Department employees were hacked with spyware from the infamous NSO Group, and details on a bizarre story about a mother and daughter that face 16 years in prison for […]
The post Life360 Selling Location Data, NSO Group Spyware Hacks Government Employees, Homecoming Queen Contest Hacked appeared first on Shared Security Podcast.

Dec 9, 2021 • 25min
Business Email Compromise Scams
This month we discuss Business Email Compromise (BEC) scams. What are they, how to identify them, and why BEC scams have created over $1.8 billion worth of losses to businesses last year alone. ** Links mentioned on the show ** What is Business Email Compromise? https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/business-email-compromise 64 times worse than ransomware? FBI statistics underline the […]
The post Business Email Compromise Scams appeared first on Shared Security Podcast.

Dec 6, 2021 • 24min
Is TikTok Listening to You, Apple Warns Activists, UK Government Website Shows Porn
Is the TikTok app listening to you and playing videos based on your conversations? Apple takes the unique step of warning certain activists that their phones may be targeted by attackers, and details on how a UK government website was serving porn to its visitors. ** Links mentioned on the show ** Is TikTok listening […]
The post Is TikTok Listening to You, Apple Warns Activists, UK Government Website Shows Porn appeared first on Shared Security Podcast.

Nov 29, 2021 • 29min
How to Break Into a Cybersecurity Career – Part 3 with Scott Wright
Co-host Scott Wright joins Tom Eston for part three in our series on how to break into a cybersecurity career. Scott shares his career journey and gives us some insight into his career path going from consulting into starting his own company. If you’re a college student or thinking about getting into cybersecurity, this is […]
The post How to Break Into a Cybersecurity Career – Part 3 with Scott Wright appeared first on Shared Security Podcast.

Nov 22, 2021 • 25min
FBI Email System Compromised, Ransomware Negotiation, Privacy Crushing Gifts
In milestone episode 200: The Federal Bureau of Investigation’s external email system was compromised sending spam emails with a fake warning of a cyber-attack, new research released about ransomware negotiation and some helpful negotiation tips, and details on Mozilla’s naughty list of privacy-crushing gifts. ** Links mentioned on the show ** FBI email system compromised […]
The post FBI Email System Compromised, Ransomware Negotiation, Privacy Crushing Gifts appeared first on Shared Security Podcast.

Nov 15, 2021 • 21min
Robinhood Data Breach, 600 Hours of Dallas Police Helicopter Footage Leaked
Details on the Robinhood data breach (apparently caused by a social engineering attack) affecting approximately 7 million customers, and a discussion about surveillance and privacy concerns from a 600-hour leak of Dallas Police Department helicopter footage. ** Links mentioned on the show ** Robinhood Trading App Suffers Data Breach Exposing 7 Million Users’ Information https://thehackernews.com/2021/11/robinhood-trading-app-suffers-data.html […]
The post Robinhood Data Breach, 600 Hours of Dallas Police Helicopter Footage Leaked appeared first on Shared Security Podcast.

Nov 8, 2021 • 22min
Facebook Dumps Face Recognition, Social Engineering Bots, US Sanctions NSO Group
Facebook shuts down their face recognition system and deletes more than a billion facial recognition templates, how phone bots are being used to trick victims into giving up their multi-factor authentication codes, and the US blacklists the NSO Group and 3 other companies for malicious cyber activities. ** Links mentioned on the show ** Face […]
The post Facebook Dumps Face Recognition, Social Engineering Bots, US Sanctions NSO Group appeared first on Shared Security Podcast.

Nov 5, 2021 • 24min
Interview with Dana Mantilia and the Role of the CISO
Dana Mantilia joins us this month to talk about cybersecurity awareness, her incredible YouTube channel, and the ever changing role of the CISO (Chief Information Security Officer). ** Links mentioned on the show ** Connect with Dana and subscribe to her YouTube Channel https://www.linkedin.com/in/dana-mantilia/ https://www.youtube.com/c/IdentityProtectionPlanningwithDana/videos ** Watch this episode on YouTube ** ** Thank you […]
The post Interview with Dana Mantilia and the Role of the CISO appeared first on Shared Security Podcast.

Nov 1, 2021 • 28min
Federal Data Agency for Social Media, Squirrelwaffle Malspam, Ransomware Hits U.S. Candymaker
Do we really need a federal data agency to regulate social media companies? Watch out for Squirrelwaffle and Qakbot malspam attacks, and ransomware hits a major candymaker ahead of Halloween (is nothing sacred anymore?!) ** Links mentioned on the show ** Facebook and social media endanger Americans. We need a federal data agency. https://www.nbcnews.com/think/politics-policy/facebook-rcna3704 Hackers […]
The post Federal Data Agency for Social Media, Squirrelwaffle Malspam, Ransomware Hits U.S. Candymaker appeared first on Shared Security Podcast.


