DrZeroTrust

Dr. Chase Cunningham
undefined
Jun 2, 2023 • 28min

Weekly(ish) Cyber and ZT News Analysis

Youtube flagged my content for PII violations, but what did I do to get put in the penalty box? CISO's plan on investing more for cybersecurity over the next few years, new research from Nuspire indicates the growing spending trend. Mitiga has found some configuration issues with Gdrive and Gsuite, what should businesses know to defend themselves? Armorblox says brand impersonation is increasing, how much of a threat is this type of attack? Gigabyte hardware and firmware has been found to be shipped with embedded back doors, uh oh. The IDSA has produced some new research on the status of iam and strategy, what can we learn from that? And G2 has unbiased reviews on security tooling and solutions, what can you learn from visiting that site. Those points and more on this episode!
undefined
May 30, 2023 • 27min

Crowdsec and collective security conversation

Ever wanted to learn the difference between a Lama and an Alapaca, we talk about that here. Weird but interesting. Crowdsec discusses their approach to changing the way we handle malicious IP's and domains. Their approach to Zero Trust as part of a global network is innovative. We chat about how open source solutions can help businesses of all sizes better defend themselves. Some discussion on collective threat intelligence, and conversations about sharing information to dynamically defend the network.
undefined
May 24, 2023 • 24min

DrZeroTrust Podcast for 5/24/2023

Should we be concerned that our leaders (and former leaders) are posting deepfakes onto social media? What can we learn from the Uber case and the final decision by the lawmakers? What did the general counsel do in that case, what about the CEO? How should we plan for a ransomware attack? Can we learn from the lessons that a CISO has been through and be better prepared (hint: yes). When is the best time to learn when to fight, before the event or during? And was I wrong about my thoughts on executive punishment for breaches, probably...
undefined
May 4, 2023 • 26min

Weekly(ish) Cyber and ZT News Analysis 5/3/2023

Are K-12 organizations and universities prepared for the onslaught of cyber threats? How long does it take me to find a vulnerable school district, it ain't long? An appeals court has upheld Merck's claim in the the NotPetya case. What does that mean for cyber insurance, and why does this make me so happy? Iran is moving quickly into the realm of influence operations, are they mirroring the Russian operations and how will this affect the upcoming election cycle? ChatGPT had a breach issue, how much of a threat or problem is this? Should we have expected anything less? Phishing is getting worse, statistically speaking, but how is this possible with all of the training we get? Is there a technical alternative that works? Those questions and more on this episode!
undefined
Apr 19, 2023 • 22min

Weekly(ish) Cyber and ZT News Analysis

How hard is it to use "ai" to clone your own voice? I did it and you can hear the sample on this podcast. What should we learn about the recent Pentagon leaker? Was it a technical failure, insider threat, of failure of leadership? What does MIT say about privacy for ChatGPT and "ai" and are there violations taking place? Are MAC's a viable target for ransomware, seems like that is a reality now. Those questions, points, and a line up of some of my schedule at RSA if you happen to be around!
undefined
Apr 13, 2023 • 30min

Cyber news and Zero Trust insights for 4/12/2023

Can ChatGPT make me a less crappy programmer? That isn't hard to be honest, but there are implications to consider. Can you use AI (I really hate using that term but you can't beat the market I guess) to be an artist? Does that impact other talented people's future earning potential? How hard is it to use StableDiffusion to create bogus images? How bad was FTX's cybersecurity? Hint: It rhymes with pepto-bismol. What else should we know about cyber insurance and who do insurers actually "take care of?" What about the leaks from the DoD? How does this keep happening? Those points and more on this episode!
undefined
Apr 7, 2023 • 30min

Cyber news and Zero Trust insights for 4/6/2023

How many vulnerable systems out there are connected to the internet with a ten year old vulnerability, with RCE, and have no authentication? Surely the answer is 0? Operation Cookie Monster took down a dark marketplace, so what? Should there be a victory lap? KnowBe4 published some research on state and local security and BEC statistics, what should we learn from that document? Fake ransomware attacks are taking place, what the hell is that? Crowdstrike and others are publishing on threat groups, but the nomenclature is all over the place. How do we know what attackers are doing what if we can't align on the naming conventions? More insights on the Silicon Valley Bank fiasco (the executives did some "questionable" things). What does that mean for the cybersecurity market at large? Those questions and more on this episode.
undefined
Mar 30, 2023 • 34min

Cyber news and Zero Trust insights for 3/29/2023

Did the Pope wear a puffy jacket? So what? How might applied deepfakes be used to manipulate the collective narrative? What about our political system? Cofense published their annual report on the state of email security. What can we learn from that? Cymulate also published their analysis of more than 1 million security assessments. What's in there for us to learn? Lloyds CEO said they might take a hit on their cyber insurance offering due to their policies around the "war clause. Ok, what's the big deal? Ivanti published a report on government cyber security status. Surely all is well if the government is involved (and this is a global analysis, not just the US y'all.) Those points and more on this episode!
undefined
Mar 21, 2023 • 30min

New Approach to Security Strategy via Distributed Ledgers

Not Blockchain...Or, kinda...But not really?  Anyway listen to smarter folks than me (lots of those) talk about how we can innovate around the use of distributed ledgers as part of a security strategy.  And how is this approach being accepted internationally, especially in Australia?  Cool new methods of enabling security with the folks from Tide (not the soap, the security guys).  Some solid conversation on this one y'all!
undefined
Mar 16, 2023 • 24min

Cyber news and Zero Trust insights for 3/15/2023

Did I spread misinformation about the SVB fiasco? Uh oh.  Did Ring get hit with ransomware, and are they secure?  What weird ports do Ring cameras use?  Rubrik has some issues going on, but did they handle it well?  Is it smart to market your organization or brand as Zero Trust?  Oh crap I am in trouble.  SpaceX may have been hit via a third party, ouch.  Why does third party risk continue to lead to compromise?  A recent report states that you can make up to 250k as a developer for the dark web.  Might be time for a career change.  Those points and more on this episode!

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app