

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
Jerry Bell and Andrew Kalat
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
Episodes
Mentioned books

May 10, 2017 • 1h 49min
Defensive Security Podcast Episode 190
http://www.verizonenterprise.com/resources/reports/rp_DBIR_2017_Report_en_xg.pdf

Apr 25, 2017 • 52min
Defensive Security Podcast Episode 189
https://www.wsj.com/articles/cybersecurity-startup-tanium-exposed-california-hospitals-network-in-demos-without-permission-1492624287
https://hotforsecurity.bitdefender.com/blog/95-of-enterprise-risk-assessments-find-employees-using-tor-private-vpns-to-bypass-security-report-says-17902.html
http://www.csoonline.com/article/3191286/security/most-employees-willing-to-share-sensitive-information-survey-says.html
https://www.bleepingcomputer.com/news/security/over-36-000-computers-infected-with-nsas-doublepulsar-malware/

Apr 17, 2017 • 1h 4min
Defensive Security Podcast Episode 188
https://arstechnica.com/security/2017/04/purported-shadow-brokers-0days-were-in-fact-killed-by-mysterious-patch/
https://www.bleepingcomputer.com/news/security/former-sysadmin-accused-of-planting-time-bomb-in-companys-database/
http://www.computerworld.com/article/3189059/security/what-prevents-breaches-process-technology-or-people-one-answer-is-pc-and-one-is-right.html
http://www.csoonline.com/article/3187422/network-security/report-30-of-malware-is-zero-day-missed-by-legacy-antivirus.amp.html
https://www.wired.com/2017/04/hackers-hijacked-banks-entire-online-operation/
http://news.softpedia.com/news/two-laptops-with-hong-kong-s-3-7-million-voters-data-stolen-514346.shtml
http://researchcenter.paloaltonetworks.com/2017/03/unit42-threat-brief-credential-theft-keystone-shamoon-2-attacks/

Mar 28, 2017 • 48min
Defensive Security Podcast Episode 187
http://www.itworld.com/article/3182431/security/some-https-inspection-tools-might-weaken-security.html
https://www.bleepingcomputer.com/news/legal/former-it-admin-accused-of-leaving-backdoor-account-accessing-it-700-times/
http://www.securityweek.com/what-cisos-can-learn-er-doctors
http://www.csoonline.com/article/3180762/data-breach/inside-the-russian-hack-of-yahoo-how-they-did-it.html
https://arstechnica.com/security/2017/03/microsofts-silence-over-unprecedented-patch-delay-doesnt-smell-right/

Mar 14, 2017 • 56min
Defensive Security Podcast Episode 186
http://www.bankinfosecurity.com/emory-healthcare-database-breach-what-happened-a-9745
http://www.networkworld.com/article/3176718/security/dealing-with-overwhelming-volume-of-security-alerts.html#tk.rss_security
http://www.networkworld.com/article/3175030/security/trend-micro-report-ransomware-booming.html
https://www.helpnetsecurity.com/2017/03/02/yahoo-cookie-forging-incident/
http://www.darkreading.com/risk/new-cybersecurity-regulations-begin-today-for-ny-banks/d/d-id/1328295
http://www.pcworld.com/article/3179348/security/after-cia-leak-intel-security-releases-detection-tool-for-efi-rootkits.html
https://arstechnica.com/security/2017/03/wikileaks-publishes-what-it-says-is-trove-of-cia-hacking-tools/
http://www.csoonline.com/article/3177994/security/cia-false-flag-team-repurposed-shamoon-data-wiper-other-malware.html

Feb 28, 2017 • 53min
Defensive Security Podcast Episode 185
https://www.bleepingcomputer.com/news/security/malware-used-to-attack-polish-banks-contained-false-flags-blaming-russian-hackers/
http://www.csoonline.com/article/3173639/security/bleeding-clouds-cloudflare-server-errors-blamed-for-leaked-customer-data.html
http://www.csoonline.com/article/3174153/security/carders-capitalize-on-cloudflare-problems-claim-150-million-logins-for-sale.amp.html
http://www.securityweek.com/what-hackers-think-your-defenses
http://www.csoonline.com/article/3171154/security/verizon-knocks-off-350m-from-yahoo-deal-after-breaches.html

Feb 20, 2017 • 48min
Defensive Security Podcast Episode 184
https://gallery.technet.microsoft.com/ATA-Playbook-ef0a8e38/file/169827/1/ATA%20Playbook.pdf
http://www.securityweek.com/google-shares-data-corporate-email-attacks
http://www.databreachtoday.com/reworked-ny-cybersecurity-regulation-takes-effect-in-march-a-9733
http://www.computerworld.com/article/3169386/security/recent-malware-attacks-on-polish-banks-tied-to-wider-hacking-campaign.html#tk.rss_security
http://www.computerworld.com/article/3166824/security/polish-banks-on-alert-after-mystery-malware-found-on-computers.html
http://www.forbes.com/sites/thomasbrewster/2017/02/16/dnc-fancy-bear-russia-hackers-mac-malware-hacking-team-fbi-fsb/#3998bc7812bc

Feb 14, 2017 • 1h 1min
Defensive Security Podcast Episode 183
https://arstechnica.com/information-technology/2017/01/antivirus-is-bad/?amp=1
http://www.darkreading.com/risk/7-tips-for-getting-your-security-budget-approved/d/d-id/1328004
https://www.asd.gov.au/publications/protect/essential-eight-explained.htm
http://www.csoonline.com/article/3163068/application-development/how-to-secure-active-directory.html
https://securosis.com/mobile/tidal-forces-software-as-a-service-is-the-new-back-office/full

Jan 23, 2017 • 1h 5min
Defensive Security Podcast Episode 182
http://www.securityweek.com/cyber-threat-intelligence-shows-majority-cybercrime-not-sophisticated
http://www.databreachtoday.com/new-in-depth-analysis-anthem-breach-a-9627
http://www.databreachtoday.com/475000-hipaa-penalty-for-tardy-breach-notification-a-9624
http://www.databreachtoday.com/insurer-slapped-22-million-hipaa-settlement-a-9643
https://krebsonsecurity.com/2017/01/extortionists-wipe-thousands-of-databases-victims-who-pay-up-get-stiffed/
https://securosis.com/mobile/tidal-forces-endpoints-are-different-more-secure-and-less-open/full

Jan 9, 2017 • 59min
Defensive Security Podcast Episode 181
http://www.businessinsider.com/russian-hacking-fears-reportedly-triggered-by-vermont-employee-checking-his-email-2017-1
http://www.cio.com/article/3153706/security/4-information-security-threats-that-will-dominate-2017.html
http://www.databreachtoday.com/major-breach-insurer-blames-system-integrator-a-9603
http://www.zdnet.com/article/this-ransomware-targets-hr-departments-with-fake-job-applications/
https://securosis.com/mobile/tidal-forces-the-trends-tearing-apart-security-as-we-know-it/full
Network Security in the Cloud Age: Everything Changes
http://blog.erratasec.com/2017/01/notes-about-ftc-action-against-d-link.html
Slack Channel: http://https://defensivesecurity.org/slack-channel/