Original Fuzz public
[search 0]
Download the App!
show episodes
 
Almost Cancelled is a TV show review show by Peter and Connor of Mild Fuzz TV. This feed will host audio versions of their reviews of the bigger cable shows such as Twin Peaks, Better Call Saul, The Handmaid's Tale, The Expanse and more. We have a dedicated feed for Netflix original reviews as well as a dedicated Mr Robot feed.
  continue reading
 
Artwork
 
The Hacker Mind is an original podcast from the makers of Mayhem Security. It’s the stories from the individuals behind the hacks you’ve read about. It’s about meeting some of the security challenges in software through advanced techniques such as fuzz testing. It’s a view of the hackers and their world that you may not have heard before.
  continue reading
 
Artwork

1
The Yellow Sub Sandwich

A Somethin’ Else production for Apple Corps and Universal Music

Unsubscribe
Unsubscribe
Daily+
 
The Yellow Sub Sandwich is the official podcast to accompany and celebrate the 50th anniversary cinema re-release of the Beatles’ #YellowSubmarine movie. http://www.yellowsubmarine.film/#tickets Presented by music and movies expert Edith Bowman and movie critic Robbie Collin, this is a podcast with a difference; it comes in two parts: “before” and “after” - a bit to listen to before you see the movie and a bit for after. With great stories about the making of the movie and fresh insight into ...
  continue reading
 
Loading …
show series
 
Over the moon; The moon is made of green cheese; Love you to the moon and back; Shoot the moon; Moonshot; Ask for the moon; Moon on a stick; Cast beyond the moon; Barking at the moon; Harvest moon; Blood moon; Moon-faced; Moongazing
  continue reading
 
Bots are actionable scripts that can slow your day to day business, be enlisted in denial of service attacks, or even keep you from getting those tickets Taylor Swift you desperately want. Antoine Vastel from DataDome explains how it's an arms race: the better we get at detecting them, the more the bots evolve to evade detection. Transcript here.…
  continue reading
 
You would think there is a procedure to End-of-Life a medical device, right? Erase personal health info. Erase network configuration info. Speaking at SecTor 2023, Deral Heiland from Rapid 7 said he found that he was able to buy infusion pumps on the secondary market with the network credentials for the original Health Care Delivery Organization in…
  continue reading
 
With the recent Clop attack on customers of MoveIt, ransomware is now old news. Attackers are skipping the encryption and simply extorting the exfiltrated data, according to Thomas “Mannie” Wilken, from the Accenture Cyber Threat Intelligence Dark Web Reconnaissance Team. He should know; he spends his days on the Dark Web seeing the rise of new inf…
  continue reading
 
Imagine a data dump of files similar to the Snowden Leaks in 2013, only this it’s not from the NSA but from NT Vulkan, a Russian contractor. And it’s a framework for targeting critical IT infrastructures. In a talk at DEF CON 31, Joe Slowick from Huntress, shares what a Russian whistleblower released in the form of emails and documents, and how we …
  continue reading
 
Rather than use backdoor exploits, attackers are stealing credentials going through the front door. How are they gaining credentials. Sometimes it’s from the tools we trust. Paul Geste and Thomas Chauchefoin discuss their DEF CON 31 presentation Visual Studio Code is why I have (Workspace) Trust issues as well as the larger question of how much we …
  continue reading
 
Ни пуха ни пера, Break a leg; Когда рак на горе свистнет, When pigs fly; Делать из мухи слона, Make a mountain out of a molehill; Не в своей тарелке, Not in one’s element, or like a fish out of water; Первый блин всегда комом; Prvi se mačići u vodu bacaju; Bogu iza nogu; Ne traži dlaku u jajetu; Mlatiti praznu slamu, Beat a dead horse; There’s no c…
  continue reading
 
How do you conduct an incident response for an entire country? When it’s 27 different life-critical government ministries each with up to 850 individual devices -- that’s uncharted territory. Esteban Jimenez of ATTI Cyber talks about his experience with the reconstruction of the cybersecurity system following Conti, how the country handled a second…
  continue reading
 
What is is like to hack an entire country, to take it’s government services offline, to deny a government an ability to function? Costa Rica knows. Esteban Jimenez of ATTI Cyber has been helping Costa Rica improve its cybersecurity posture for more than 16 years, and he has been helping them recently recover from a crippling ransomware attack in Ap…
  continue reading
 
Speaking at Black Hat 2023, Kelly Shortridge is bringing cybersecurity out of the dark ages by infusing security by design to create secure patterns and practices. It’s a subject of her new book on Security Chaos Computing, and it’s a topic that’s long overdue to be discussed in the field. Transcript.…
  continue reading
 
Are we doing enough to secure our health delivery organizations? Given the rise of ransomware attacks, one could day we are not. Karl Sigler from Trustwave SpiderLabs, talks about a new report that his team has written that is focused on the threat landscape for medical devices and the healthcare industry in general. Transcript here.…
  continue reading
 
Internet domains are brittle. One could hack into a military, a foreign government, or even global commercial web services domain using flaws in the underlying architecture. Fredrik Nordberg Almroth, co-founder of Detectify, talks about how he did just that -- hack .mil, hack the top level domain of the Democratic Republic of Congo, and even Gmail …
  continue reading
 
Phishing is everywhere. Who among us has not seen phish in their inbox? Aviv Grafi, from Votiro, gets into the weeds about how malicious documents are formed and how they might (despite good secure posture) still end up in your inbox or browser. He’s created a rather novel method to strip out the good content from the bad without affecting your ove…
  continue reading
 
Could the nudges and prompts like those from our Fitbits and Apple watches be effective in enforcing good security behavior as well? Oz Alashe, CEO and founder of CybSafe, brings his experience in the UK Intelligence Community to the commercial world along with some solid science around what motivates us to make changes in our lives. It’s not just …
  continue reading
 
Say you’re an organization that’s been hit with ransomware. At what point do you need to bring in a ransomware negotiator? Should you pay, should you not? Mark Lance, the VP of DFIR and Threat Intelligence for GuidePoint Security, provides The Hacker Mind with stories of ransomware cases he’s handled and best practices for how to handle such an eve…
  continue reading
 
Small to Medium Business are increasingly the target of APTs and ransomware. Often they lack the visibility of a SOC. Or even basic low level threat analysis. Chris Gray of Deepwatch talks about the view from the inside of a virtual SOC, the ability to see threats against a large number of SMB organizations, and the changes to cyber insurance we’re…
  continue reading
 
Use a sledgehammer to crack a nut; Throw a spanner in the works; Bodies upon the gears; Maslow's hammer; Between the hammer and the anvil; Between a rock and a hard place; Drop the hammer on; Go under the hammer; Dumb as a bag of hammers; Dumb as a box of rocks; Not the sharpest tool in the shed; Sledgehammer argument; Poor craftsman that blames hi…
  continue reading
 
More and more criminals are identified through open source intelligence (OSINT). Sometimes a negative Yelp review can reveal their true identity. Daniel Clemens, CEO of ShadowDragon, talks about his more than two decades of digital investigations, from the origins of the Code Red worm to the mass shooter in Las Vegas, with a fair number of pedophil…
  continue reading
 
It’s time to evolve beyond the UNIX operating system. OSes today are basically ineffective database managers, so why not build an OS that’s a database manager? Michael Coden, Associate Director, Cybersecurity, MIT Sloan, along with Michael Stonebreaker will present this novel concept at RSAC 2023. You can learn more at dbos-project.github.io…
  continue reading
 
Incident response in the cloud. How is it different, and why do we need to pay more attention to it today, before something major happens tomorrow. James Campbell, CEO of Cado Security, shares his experience with traditional incident response, and how the cloud, with its elastic structure, able to spin up and spin down instances, is changing incide…
  continue reading
 
We’ve seen drug marketplaces and extremists use the Dark Web. Will generative AI tools like ChatGPT make things crazier by lowering the barrier to entry? Delilah Schwartz, from Cybersixgill, brings her extensive background with online extremism to The Hacker Mind to talk about how she’s seeing a lot of chatter in the dark web.about AI online. She d…
  continue reading
 
Out at elbows; Out at heels; Drag your heels; Set back on your heels; At someone's heels; Hard on someone's heels; Hot on someone's heels; Under the thumb; Show a clean pair of heels; Cop a heel; Spin on one's heels; Turn on your heels; Fall head over heels in love; Head over heels in debt; Real heel…
  continue reading
 
Booth babes and rampant sexism were more of a problem in infosec in the past. That is, until Chenxi Wang spoke up. And she’s not done changing the industry. She’s an amazing person who has done an incredible number of things in a short amount of time -- a PhD in Computer Engineering, inventor of a process still used by the DoD today, a successful t…
  continue reading
 
What if DEF CON CTFs were televised? What if you could see their screens and have interviews with the players in the moment? Turns out, you can. Jordan Wiens, from Vector 35, maker of Binary Ninja, is no stranger to CTFs. He’s played in ten final DEF CON CTFs, was a part of DARPA’s Cyber Grand Challenge, and recently he’s moderated the live broadca…
  continue reading
 
Bad egg; Don't put all your eggs in one basket; Egg money; Bald as an egg; Which came first, the chicken or the egg; Over-egg the pudding; Egging; Teaching your grandma to suck eggs; Rotten egg; Last one in is a rotten egg; Can't boil an egg; Can't unboil an egg.
  continue reading
 
When we hear about bad actors on a compromised system for 200+ days, we wonder how they survived for so long. Often they hide in common misconfigurations. From her talk at SecTor 2022, Paula Januszkiewicz, CEO of Cqure, returns to The Hacker Mind and explains how a lot of little configuration errors in common Windows tools and services can open the…
  continue reading
 
Having a common framework around vulnerabilities, around threats, helps us understand the infosec landscape better. STRIDE provides an easy mnemonic. Adam Shostack has a new book, Threats: What Every Engineer Should Learn From Star Wars. that uses both Star Wars and STRIDE to help engineers under vulnerabilities and threats in software development.…
  continue reading
 
Hacking websites is perhaps often underestimated yet is super interesting with all its potential for command injections and cross site scripting attacks. Tib3rius from White Oak Security discusses his experience as a web application security pen tester, his OSCP certification, and how he’s giving back to the community with his Twitch, Youtube, and …
  continue reading
 
If you call someone on the other side of the world, perhaps you notice the delay in their response. For voice that’s okay, but for live music that’s disastrous. Mark Goldstein thinks he’s solved the latency problem associated with the production of live musical performances online. Having one musician in Bangalore, another in California, and yet an…
  continue reading
 
Loading …

Quick Reference Guide