

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
Jerry Bell and Andrew Kalat
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
Episodes
Mentioned books

Aug 29, 2017 • 51min
Defensive Security Podcast Episode 200
http://www.securityweek.com/three-questions-every-ciso-should-be-able-answer
https://arstechnica.com/information-technology/2017/08/powerful-backdoor-found-in-software-used-by-100-banks-and-energy-cos/?amp=1
https://krebsonsecurity.com/2017/08/blowing-the-whistle-on-bad-attribution/
http://www.csoonline.com/article/3213030/security/when-it-comes-to-the-cloud-do-cisos-have-their-heads-in-the-sand.html
http://www.zdnet.com/article/petya-ransomware-cyber-attack-costs-could-hit-300m-for-shipping-giant-maersk/
https://www.helpnetsecurity.com/2017/08/24/crystal-finance-millennium-compromised/
https://www.lacyberlab.org/what-los-angeles-cyber-lab

Aug 14, 2017 • 52min
Defensive Security Podcast Episode 199
https://www.theregister.co.uk/2017/08/10/salesforce_fires_its_senior_security_engineers_after_defcon_talk/?mt=1502653861726
PR fight ensues after claims of leaked Carbon Black data
https://www.theregister.co.uk/2017/08/10/carbon_black_denies_sec_sys_broken/
http://www.databreachtoday.com/ocr-tells-organizations-to-step-up-phishing-scam-awareness-a-10174
https://www.infosecurity-magazine.com/news/anthem-medicare-patients-hit-breach/
https://www.theregister.co.uk/2017/08/07/cba_blames_software_for_money_laundering_miss/

Aug 7, 2017 • 53min
Defensive Security Podcast Episode 198
https://www.darkreading.com/vulnerabilities—threats/wannacry-inspires-worm-like-module-in-trickbot/d/d-id/1329491
http://www.securityweek.com/one-million-exposed-adware-hijacked-chrome-extension
https://www.darkreading.com/risk/can-your-risk-assessment-stand-up-under-scrutiny/a/d-id/1329435

Jul 24, 2017 • 49min
Defensive Security Podcast Episode 197
http://thehackernews.com/2017/07/adwind-rat-malware.html
https://www.theregister.co.uk/2017/07/13/swiss_domain_name_hijack/
http://www.databreachtoday.com/fedex-warns-notpetya-will-negatively-affect-profits-a-10118
http://www.cnbc.com/2017/07/21/a-cyberattack-is-going-to-cause-this-tech-company-to-miss-earnings.html
http://www.securityweek.com/alarming-percentage-employees-hide-security-incidents-report

Jul 12, 2017 • 1h 14min
Defensive Security Podcast Episode 196
http://www.databreachtoday.com/notpetya-patient-zero-ukrainian-accounting-software-vendor-a-10080
http://blog.talosintelligence.com/2017/07/the-medoc-connection.html?m=1
http://www.databreachtoday.com/police-seize-backdoored-firms-servers-to-stop-attacks-a-10083
https://www.bleepingcomputer.com/news/security/m-e-doc-software-was-backdoored-3-times-servers-left-without-updates-since-2013/
https://www.wired.com/story/petya-plague-automatic-software-updates/
https://www.theregister.co.uk/2017/06/28/petya_notpetya_ransomware/https://apnews.com/962db1cd370d4fdda6083d064b94dd1b
https://infosec.engineering/notpetya-complex-attacks-and-the-fog-of-war/

Jun 27, 2017 • 59min
Defensive Security Podcast Episode 195
http://securityaffairs.co/wordpress/60243/data-breach/dra-data-leak.html
https://www.wired.com/story/crash-override-malware/
https://threatpost.com/fin10-extorting-canadian-mining-companies-casinos/126382/
http://variety.com/2017/digital/features/netflix-orange-is-the-new-black-leak-dark-overlord-larson-studios-1202471400/amp/
https://arstechnica.com/information-technology/2017/06/32tb-of-windows-10-beta-builds-driver-source-code-leaked/
https://arstechnica.com/security/2017/06/5-weeks-after-wcry-outbreak-nsa-derived-worm-shuts-down-a-honda-factory/

Jun 22, 2017 • 42min
Defensive Security Podcast Episode 194
https://hotforsecurity.bitdefender.com/blog/heartbleed-still-hurting-hard-uk-council-fined-100000-after-data-breach-18205.html
https://threatpost.com/ransomware-attack-hobbles-prestigious-university-college-london/126299/
http://www.securityweek.com/web-hosting-provider-pays-1-million-ransomware-attackers
https://infosec.engineering/improving-the-effectiveness-of-vulnerability-remediation-targeting/

Jun 12, 2017 • 31min
Defensive Security Podcast Episode 193
http://www.csoonline.com/article/3198492/security/ceos-risky-behaviors-compromise-security.html
https://www.bleepingcomputer.com/news/security/ex-admin-deletes-all-customer-data-and-wipes-servers-of-dutch-hosting-provider
http://thehackernews.com/2017/06/intel-amt-firewall-bypass.html
http://thehackernews.com/2017/06/microsoft-powerpoint-malware.html

Jun 6, 2017 • 36min
Defensive Security Podcast Episode 192
http://www.csoonline.com/article/3198496/compliance/sometimes-it-is-necessary-to-bend-the-rules-a-bit.html
http://www.securityweek.com/nature-vs-nurture-bad-cybersecurity-our-dna
http://gizmodo.com/top-defense-contractor-left-sensitive-pentagon-files-on-1795669632
https://nakedsecurity.sophos.com/2017/06/02/onelogin-warns-that-attacker-could-be-able-to-decrypt-data/

May 25, 2017 • 48min
Defensive Security Podcast Episode 191
https://arstechnica.com/security/2017/05/windows-7-not-xp-was-the-reason-last-weeks-wcry-worm-spread-so-widely/
http://www.publictechnology.net/articles/news/nhs-cyber-attack-forces-week-long-council-email-block
https://www.washingtonpost.com/business/technology/nsa-officials-worried-about-the-day-its-potent-hacking-tool-would-get-loose-then-it-did/2017/05/16/50670b16-3978-11e7-a058-ddbb23c75d82_story.html
https://www.grahamcluley.com/companies-keeping-bitcoin-hand-case-ransomware-attacks/
http://www.eweek.com/security/zomato-docusign-breaches-reveal-common-security-risks