

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec
Jerry Bell and Andrew Kalat
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
Episodes
Mentioned books

Jan 15, 2019 • 49min
Defensive Security Podcast Episode 231
https://lifehacker.com/why-smart-people-make-stupid-mistakes-1831503216
https://www.chicagotribune.com/business/ct-biz-tribune-publishing-malware-20181230-story,amp.html
https://www.securityweek.com/was-north-korea-wrongly-accused-ransomware-attacks
https://www.healthcareitnews.com/news/staff-lapses-and-it-system-vulnerabilities-are-key-reasons-behind-singhealth-cyberattack
https://www.nextgov.com/cybersecurity/2019/01/hhs-releases-voluntary-cybersecurity-practices-health-industry/153835/
https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/
https://arstechnica.com/information-technology/2018/12/iranian-phishers-bypass-2fa-protections-offered-by-yahoo-mail-and-gmail/

Dec 4, 2018 • 55min
Defensive Security Podcast Episode 230
https://arstechnica.com/information-technology/2018/11/hacker-backdoors-widely-used-open-source-software-to-steal-bitcoin/
https://krebsonsecurity.com/2018/11/marriott-data-on-500-million-guests-stolen-in-4-year-breach/
https://krebsonsecurity.com/2018/12/what-the-marriott-breach-says-about-security/

Nov 27, 2018 • 1h 4min
Defensive Security Podcast Episode 229
https://www.dutchnews.nl/news/2018/11/internet-con-men-ripped-off-pathe-nl-for-e19m-in-sophisticated-fraud/
https://lifehacker.com/how-password-constraints-give-you-a-false-sense-of-secu-1830564360
https://www.csoonline.com/article/3319704/data-protection/the-end-of-security-as-we-know-it.html
https://www.careersinfosecurity.com/breach-settlement-has-unusual-penalty-a-11669
https://motherboard.vice.com/en_us/article/bje8na/massive-data-leaks-keep-happening-because-big-companies-can-afford-to-lose-your-data
https://www.zdnet.com/article/city-of-valdez-alaska-admits-to-paying-off-ransomware-infection/

Nov 13, 2018 • 47min
Defensive Security Podcast Episode 228
https://www.zdnet.com/article/this-is-how-artificial-intelligence-will-become-weaponized-in-future-cyberattacks/
https://www.securityinfowatch.com/article/12434583/everyone-needs-to-take-responsibility-for-cybersecurity-in-the-workplace
https://www.zdnet.com/article/adobe-coldfusion-servers-under-attack-from-apt-group/
https://www.securityweek.com/troubled-waters-how-new-wave-cyber-attacks-targeting-maritime-trade
https://securityaffairs.co/wordpress/77676/malware/industrial-facilities-malware.html

Oct 30, 2018 • 58min
Defensive Security Podcast Episode 227
https://www.zdnet.com/article/equifax-engineer-who-designed-breach-portal-gets-8-months-of-house-arrest-for-insider-trading/
https://www.csoonline.com/article/3314557/security/ransomware-attack-hits-north-carolina-water-utility-following-hurricane.html
https://www.securityweek.com/insurer-anthem-will-pay-record-16m-massive-data-breach
https://blog.sucuri.net/2018/10/malicious-redirects-from-newsharecounts-com-tweet-counter.html
https://www.thinkadvisor.com/2018/09/26/sec-hits-voya-financial-advisors-with-1m-fine-over/
https://www.healthcareitnews.com/news/debunking-cybersecurity-thought-humans-are-weakest-link

Oct 8, 2018 • 1h 1min
Defensive Security Podcast Episode 226 redux
Note: this episode is being re-released to fix a problem with the mp3 download.
https://www.tripwire.com/state-of-security/security-data-protection/bec-as-a-service-offers-hacked-business-accounts-for-as-little-as-150/
https://www.bleepingcomputer.com/news/security/ic3-issues-alert-regarding-remote-desktop-protocol-rdp-attacks/
https://krebsonsecurity.com/2018/10/supply-chain-security-is-the-whole-enchilada-but-whos-willing-to-pay-for-it/

Sep 9, 2018 • 53min
Defensive Security Podcast Episode 225
https://motherboard.vice.com/en_us/article/pa8emg/russian-indicted-jp-morgan-chase-hack
https://www.zdnet.com/article/us-government-releases-post-mortem-report-on-equifax-hack/
https://www.zdnet.com/article/phishing-alert-north-korean-hacking-attacks-shows-your-email-is-still-the-weakest-link/
https://www.verizon.com/about/news/lifting-lid-cybercrime

Aug 31, 2018 • 44min
Defensive Security Podcast Episode 224
https://www.zdnet.com/article/this-destructive-ransomware-has-made-crooks-6m-by-encrypting-data-and-backups/
https://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/
https://www.databreachtoday.com/art-steal-fin7s-highly-effective-phishing-a-11286
https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/

Jul 31, 2018 • 46min
Defensive Security Podcast Episode 223
https://www.straitstimes.com/singapore/personal-info-of-15m-singhealth-patients-including-pm-lee-stolen-in-singapores-most
https://www.bankinfosecurity.com/labcorp-still-recovering-from-ransomware-attack-a-11235
https://www.securityweek.com/cyber-axis-evil-rewriting-cyber-kill-chain
https://arstechnica.com/information-technology/2018/07/prolific-hacking-group-steals-almost-1-million-from-russian-bank/#p3
https://www.bleepingcomputer.com/news/government/us-charges-12-russian-intelligence-officers-for-hacking-dnc-running-dcleaks/

Jul 15, 2018 • 52min
Defensive Security Podcast Episode 222
https://www.csoonline.com/article/3285982/data-protection/4-reasons-why-cisos-must-think-like-developers-to-build-cybersecurity-platforms.html
https://www.csoonline.com/article/3287655/phishing/stop-training-your-employees-to-fall-for-phishing-attacks.html
https://www.bankinfosecurity.com/cryptojacking-displaces-ransomware-as-top-malware-threat-a-11165
https://wiki.gentoo.org/wiki/Project:Infrastructure/Incident_Reports/2018-06-28_Github