

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
Jerry Bell and Andrew Kalat
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
Episodes
Mentioned books

Jan 31, 2022 • 51min
Defensive Security Podcast Episode 261
https://www.bleepingcomputer.com/news/security/hackers-are-taking-over-ceo-accounts-with-rogue-oauth-apps/
https://blog.f-secure.com/insight-from-a-large-scale-phishing-study/
https://www.darkreading.com/attacks-breaches/log4j-proved-public-disclosure-still-helps-attackers
https://www.csoonline.com/article/3647756/how-to-prioritize-and-remediate-vulnerabilities-in-the-wake-of-log4j-and-microsofts-patch-tuesday-b.html

Jan 17, 2022 • 31min
Defensive Security Podcast Episode 260
https://www.csoonline.com/article/3647209/why-you-should-secure-your-embedded-server-management-interfaces.html
https://www.csoonline.com/article/3646613/cybercrime-group-elephant-beetle-lurks-inside-networks-for-months.html
https://www.zdnet.com/article/when-open-source-developers-go-bad/
https://www.bleepingcomputer.com/news/microsoft/microsoft-resumes-rollout-of-january-windows-server-updates/

Jan 3, 2022 • 50min
Defensive Security Podcast Episode 259

Aug 15, 2021 • 50min
Defensive Security Podcast Episode 258
https://arstechnica.com/gadgets/2021/07/malicious-pypi-packages-caught-stealing-developer-data-and-injecting-code/
https://arstechnica.com/gadgets/2021/07/feds-list-the-top-30-most-exploited-vulnerabilities-many-are-years-old/
https://www.securityweek.com/hospital-network-reveals-cause-2020-cyberattack
https://www.csoonline.com/article/3628331/recent-shadow-it-related-incidents-present-lessons-to-cisos.html
https://www.natlawreview.com/article/another-court-orders-production-cybersecurity-firm-s-forensic-report-data-breach
https://www.secureworld.io/industry-news/ciso-lawsuit-solarwinds

Jul 25, 2021 • 41min
Defensive Security Podcast Episode 257
https://therecord.media/using-vms-to-hide-ransomware-attacks-is-becoming-more-popular/
https://blog.erratasec.com/2021/07/ransomware-quis-custodiet-ipsos-custodes.html?m=1
https://www.databreachtoday.com/how-mespinoza-ransomware-group-hits-targets-a-17086
https://krebsonsecurity.com/2021/07/dont-wanna-pay-ransom-gangs-test-your-backups/
https://arstechnica.com/gadgets/2021/07/kaseya-gets-master-decryptor-to-help-customers-still-suffering-from-revil-attack/

Jul 11, 2021 • 43min
Defensive Security Podcast Episode 256
https://www.csoonline.com/article/3623760/printnightmare-vulnerability-explained-exploits-patches-and-workarounds.html#tk.rss_all
https://www.securityweek.com/continuous-updates-everything-you-need-know-about-kaseya-ransomware-attack
https://www.databreachtoday.com/kaseya-raced-to-patch-before-ransomware-disaster-a-17006

Jun 27, 2021 • 41min
Defensive Security Podcast Episode 255
https://www.reuters.com/technology/us-sec-official-says-agency-has-begun-probe-cyber-breach-by-solarwinds-2021-06-21/
https://www.databreachtoday.com/cisa-firewall-rules-could-have-blunted-solarwinds-malware-a-16919
https://www.wired.com/story/the-full-story-of-the-stunning-rsa-hack-can-finally-be-told/
https://www.bleepingcomputer.com/news/security/microsoft-admits-to-signing-rootkit-malware-in-supply-chain-fiasco/

Jun 20, 2021 • 48min
Defensive Security Podcast Episode 254
We’re baaaack

Jul 15, 2020 • 47min
Defensive Security Podcast Episode 253
https://www.securityinformed.com/news/intruder-research-mongodb-databases-breached-connected-internet-co-1594211095-ga-co-1594211806-ga.1594215158.html
https://www.zdnet.com/article/hackers-are-trying-to-steal-admin-passwords-from-f5-big-ip-devices/
https://www.csoonline.com/article/3564726/privilege-escalation-explained-why-these-flaws-are-so-valuable-to-hackers.html#tk.rss_all
https://arstechnica.com/information-technology/2020/06/theft-of-top-secret-cia-hacking-tools-was-result-of-woefully-lax-security/

May 31, 2020 • 27min
Defensive Security Podcast Episode 252
https://www.bankinfosecurity.com/capital-one-must-turn-over-mandiant-forensics-report-a-14352
https://www.databreachtoday.com/insider-threat-lessons-from-3-incidents-a-14312
https://www.zdnet.com/article/ransomware-deploys-virtual-machines-to-hide-itself-from-antivirus-software/