Crying Out Cloud

Wiz
undefined
Nov 8, 2024 โ€ข 35min

Canadian Cybersecurity, Open Source Risks, and AppSec Insights with Tanya Janca

๐ŸŽ™๏ธ Tune in to the latest #CryingOutCloud episode featuring Tanya Janca, where we dive into all things cloud! Join Eden and Amitai as they welcome Tanya Janca, founder of 'We Hack Purple', and the author of 'Alice and Bob Learn Application Security'. She's seen it allโ€”from launching AppSec programs to teaching secure coding and leading on education at Semgrep. In this episode: ๐ŸŒ Building security programs from scratch ๐Ÿ” The value of static analysis tools for developers ๐Ÿ‡จ๐Ÿ‡ฆ The Canadian cybersecurity landscape and her take on global challenges ๐Ÿ’ก Tips for securing AI applications in the age of generative AI
undefined
Oct 29, 2024 โ€ข 19min

Hybrid Cloud Attacks, Linux Malware, and LLMJacking Exposed

๐ŸŽ™๏ธ Ready for the latest on Hybrid Cloud Attacks, Linux Malware, and LLMJacking? Join our hosts Eden Koby Naftali and Amitai Cohen in our NEW #CryingOutCloud episode. In this episode: ๐Ÿ“Œ The perfctl malware campaignโ€”stealthily mining crypto on thousands of Linux machines undetected for years ๐Ÿ“Œ Storm-0501 hybrid cloud attacks, targeting everything from hospitals to law enforcement, with ransomware and stolen admin credentials ๐Ÿ“Œ LLMJackingโ€”the latest evolution in malicious cloud access, selling AI access on underground markets
undefined
Oct 8, 2024 โ€ข 24min

AI Toolkit Risks, CUPS Vulnerabilities, and Google's Infostealer Defenses

๐ŸŽ™๏ธ Catch the latest episode of #CryingOutCloud, where Amitai Cohen and Eden Koby Naftali tackle key cloud security challenges from AI Toolkit Risks to CUPS Vulnerabilities! Tune in to hear about: ๐Ÿ“Œ Wiz Research discovered a vulnerability affecting the Nvidia container toolkit ๐Ÿ“Œ Google's novel Info Stealers Mitigations ๐Ÿ“Œ All the talk around the CUPS vulnerabilities ๐Ÿ“Œ How to leverage Atomic Cloud IOCs [And so much more...]
undefined
Oct 4, 2024 โ€ข 28min

From NASA to GitLab: Democratizing Security, Open Source, and Empowering Women โ€“ With: Julie Davila

๐Ÿ“ข Tune in for the special episode of Crying Out Cloud with  @Gitlab 's Julie Davila! ๐Ÿš€ Join our Co-host Eden Koby Naftali and the cybersecurity leader Julie Davila, VP of Product Security at GitLab as they dive into: ๐Ÿ“Œ Balancing transparency in open-source tooling with security risks. ๐Ÿ“Œ Democratizing security: How GitLab empowers engineers to take ownership of security without disrupting their workflow. ๐Ÿ“Œ Plus, insights into empowering women in cloud security and why diverse representation is crucial for the industry's future.
undefined
Aug 12, 2024 โ€ข 25min

Azure DDoS, Certificate Revocations, and ESXi Ransomware

Discover the latest in cloud security with intriguing stories about a new cryptojacking campaign targeting SeleniumGrid. Learn how a DDoS attack disrupted Starbucks due to a configuration mishap. Dive into the chaos caused by DigiCert's mass certificate revocation, and explore the dangers of trusting popular platforms with security flaws. The podcast wraps up with essential tactics to safeguard cloud environments and the ever-evolving threats presented by ransomware in the VMware ESXi world.
undefined
Aug 5, 2024 โ€ข 38min

Navigating Hyper Growth, AI Impact, and Mandiant Memories - Special Guest: Ryan Kazanciyan

๐Ÿ“ข Tune in for an exclusive session with Ryan Kazanciyan on securing a security vendor, hyper-growth, and AI impact in the latest podcast episode of #CryingOutCloud! Join our hosts, Amitai Cohen and Eden Koby Naftali, as they dive into cloud security with Ryan Kazanciyan, our seasoned expert leading security at @Wiz. ๐Ÿ” Episode Highlights: ๐Ÿ“Œ Managing security during hyper growth: challenges and lessons learned. ๐Ÿ“Œ Ryan's experiences at Mandiant and the impact of the APT1 investigation on his approach to security. ๐Ÿ“Œ Current security trends and the role of AI in security. ๐Ÿ“Œ Ensuring safe use of AI tools like ChatGPT within the organization for internal use and product development.
undefined
Jul 17, 2024 โ€ข 9min

SAPwned: SAP AI Core vulnerabilities - Special Guest: Hillai Ben-Sasson

๐Ÿ“ข Tune in to our special episode with Hillai Ben-Sasson with all you need to know about #SAPwned. TL;DR - The Wiz Research Team uncovered serious vulnerabilities in SAP AI Core, revealing potential risks in #AI infrastructure.
undefined
Jul 15, 2024 โ€ข 30min

CROC Talks - Securing DBs, Cloud Threat Intel, and Detection- Special Guest: Snowflakesโ€™ Haider Dost

๐Ÿ“ข Tune in to Snowflake's Haider Dost for an exclusive session on Securing Databases, Cloud Threat Intelligence, and Detection strategies. The latest podcast episode of #CryingOutCloud is LIVE! Join our special hosts, @Alon Schindel and @Eden, as they dive deep into the world of cloud security with Haider Dost, Head of Global Threat Detection and Threat Intelligence at Snowflake. ๐Ÿ” Episode Highlights: ๐Ÿ“Œ Recent campaign targeting Snowflake customers. ๐Ÿ“Œ Discussion on the new mandatory MFA for Snowflake admins and its impact. ๐Ÿ“Œ Architecture of detection in the cloud & logging. What does it mean to work in a highly regulated environment compared to a fast-growing company like Snowflake. ๐Ÿ“Œ Defining "good security" in traditional vs. cloud-native settings.
undefined
Jun 28, 2024 โ€ข 24min

CROC News: Firewall Fumbles, Gitloker Etiquette, and Private Cloud Compute

๐Ÿ“ข From data privacy norms in the age of AI โ€” tune in to the latest episode of #CryingOutCloud with all you need to know from the cloud security news ๐Ÿšจ Join Eden Naftali and Amitai Cohen as they dive into: ๐Ÿ” How a new AI processing cloud service is challenging data privacy norms. ๐Ÿ›ก๏ธ The implications of a potential firewall misconfiguration and how to secure your environment. ๐Ÿ” The latest ransomware attacks on GitHub repositories and how to safeguard your data. โš ๏ธ A new discovery by Wiz research: crypto-jacking campaign targeting Kubernetes clusters. ๐Ÿ˜ Critical remote code execution vulnerability in PHP and how to mitigate the risk.
undefined
Jun 24, 2024 โ€ข 11min

CROC Talks: RCE Vulnerability in Ollama explained

๐Ÿ’ฅ EXCLUSIVE: Wiz Research uncovers CVE-2024-37032, aka #Probllama โ€” a vulnerability in Ollama that that left thousands of #AI models exposed ๐Ÿ˜ฒ  

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app