Qnap public
[search 0]
More
Download the App!
show episodes
 
Artwork

1
Immutable Podcast

The Solutions Team

Unsubscribe
Unsubscribe
Monthly
 
Immutability refers to the incapability for modification or erasure. Join solutions architects Stefan Ferrari and Ian Hall from CMS Distribution in their discussion of all things Enterprise Technology. CMS is a value-added technology distributor, meaning our in-house team of solutions experts act as a technical resource for clients who lack the infrastructure and knowledge to configure complex requirements. In the spirit of exceeding expectations, we are thrilled to be sharing some of our ex ...
  continue reading
 
Loading …
show series
 
On February 27, 2024, PCAST (President’s Council of Advisors on Science and Technology) sent a report to the President with recommendations to bolster the resilience and adaptability of the nation’s cyber-physical infrastructure resources. Phil was part of the team that worked on the report and comes on the show to talk about what was recommended a…
  continue reading
 
A clear pattern with startups getting funding this week are "autonomous" products and features. Automated detection engineering Autonomously map and predict malicious infrastructure ..."helps your workforce resolve their own security issues autonomously" automated remediation automated compliance management & reporting I'll believe it when I see it…
  continue reading
 
How can open source projects find a funding model that works for them? What are the implications with different sources of funding? Simon Bennetts talks about his stewardship of Zed Attack Proxy and its journey from OWASP to OpenSSF to an Open Source Fellowship with Crash Override. Mark Curphy adds how his experience with OWASP and the appsec commu…
  continue reading
 
Since 2016, we been hearing about the impending impact of CMMC. But so far, it's only been words. That looks to be changing. Edward Tourinsky, Founder & Managing Principal at DTS, joins Business Security Weekly to discuss the coming impact of CMMC v3. Edward will cover: The background of CMMC Standardization of CMMC CMMC v3 changes and implementati…
  continue reading
 
Protecting a normal enterprise environment is already difficult. What must it be like protecting a sports team? From the stadium to merch sales to protecting team strategies and even the players - securing an professional sports team and its brand is a cybersecurity challenge on a whole different level. In this interview, we'll talk to Joe McMann a…
  continue reading
 
Version 4.0 of the Payment Card Industry Data Security Standard (PCI DSS) puts greater emphasis on application security than did previous versions of the standard. It also adds a new “customized approach” option that allows merchants and other entities to come up with their own ways to comply with requirements, and which also has implications for a…
  continue reading
 
There are as many paths into infosec as there are disciplines within infosec to specialize in. Karan Dwivedi talks about the recent book he and co-author Raaghav Srinivasan wrote about security engineering. There's an appealing future to security taking on engineering roles and creating solutions to problems that orgs face. We talk about the breadt…
  continue reading
 
Startup founders dream of success, but it's much harder than it looks. As a former founder, I know the challenges of cultivating an idea, establishing product market fit, growing revenue, and finding the right exit. Trust me, it doesn't always end well. In this interview, we welcome Seth Spergel, Managing Partner at Merlin Ventures, to discuss how …
  continue reading
 
In the days when Mirai emerged and took down DynDNS, along with what seemed like half the Internet, DDoS was as active a topic in the headlines as it was behind the scenes (check out Andy Greenberg's amazing story on Mirai on Wired). We don't hear about DDoS attacks as much anymore. What happened? Well, they didn't go away. DDoS attacks are a more …
  continue reading
 
Jim joins the Security Weekly crew to discuss all things supply chain! Given the recent events with XZ we still have many topics to explore, especially when it comes to practical advice surrounding supply chain threats. Ahoi new VM attacks ahead! HTTP/2 floods, USB Hid and run, forwarded email tricks, attackers be scanning, a bunch of nerds write s…
  continue reading
 
We look into the supply chain saga of the XZ Utils backdoor. It's a wild story of a carefully planned long con to add malicious code to a commonly used package that many SSH connections rely on. It hits themes from social engineering and abuse of trust to obscuring the changes and suppressing warnings. It also has a few lessons about software devel…
  continue reading
 
Another week, another hack. The MacVoices Live! panel of Chuck Joiner, Dave Ginsburg, Brian Flanigan-Arthurs, Marty Jencius, Eric Bolden, Jeff Gamet, and Guy Serle discuss AT&T’s loss of customer data that has a bit of history to it, as well as a request from India to unlock an iPhone of a political figure. (Spoiler: they said no.) [embed]http://tr…
  continue reading
 
Chuck Joiner, David Ginsburg, Ben Roethig, Jim Rea, Marty Jencius, Brian Flanigan-Arthurs, Web Bixby, Mark Fuccio, and Jeff Gamet conclude a MacVoices Live! conversation about how Apple’s App Store fee critics are charging pretty much the same thing for similar services. That led to a debate over how free apps on the App Store fit into the equation…
  continue reading
 
The MacVoices Live! crew of Chuck Joiner, David Ginsburg, Ben Roethig, Jim Rea, Marty Jencius, Brian Flanigan-Arthurs, Web Bixby, Mark Fuccio, and Jeff Gamet have a few thoughts on China’s banning of Intel and AMD chips in government computers, and the way Microsoft “acquired” the Inflection team. A simple hiring, or a dodge around the regulators? …
  continue reading
 
In this discussion, we focus on vendor/tool challenges in infosec, from a security leader's perspective. To quote our guest, Ross, "running a security program is often confused with shopping". You can't buy an effective security program any more than you can buy respect, or a black belt in kung fu (there might be holes in these examples, but you ho…
  continue reading
 
As most of you have probably heard there was a scary supply chain attack against the open source compression software called "xz". The security weekly hosts will break down all the details and provide valuable insights. https://blog.qualys.com/vulnerabilities-threat-research/2024/03/29/xz-utils-sshd-backdoor https://gynvael.coldwind.pl/?id=782 http…
  continue reading
 
NVD checked out, then they came back? Maybe? Should the xz backdoor be treated as a vulnerability? Is scan-driven vulnerability management obsolete when it comes to alerting on emerging threats? What were some of the takeaways from the first-ever VulnCon? EPSS is featured in over 100 security products, but is it properly supported by those that ben…
  continue reading
 
The MacVoices Live! discussion of the DOJ’s action against Apple continues as Chuck Joiner, David Ginsburg, Ben Roethig, Jim Rea, Marty Jencius, Brian Flanigan-Arthurs, Web Bixby, Mark Fuccio, and Jeff Gamet examine some of the more unusual aspects of the pleadings, what Apple’s response will be, and how the media is addressing the developments. (P…
  continue reading
 
MacVoices Live! digs into the DOJ action against Apple to try to understand what is behind it. Chuck Joiner, David Ginsburg, Ben Roethig, Jim Rea, Marty Jencius, Brian Flanigan-Arthurs, Web Bixby, Mark Fuccio, and Jeff Gamet consider the made-up categories of the iPhone market, the questionable quality of the complaint as a competent legal document…
  continue reading
 
Sometimes infosec problems can be summarized succinctly, like "patching is hard". Sometimes a succinct summary sounds convincing, but is based on old data, irrelevant data, or made up data. Adrian Sanabria walks through some of the archeological work he's done to dig up the source of some myths. We talk about some of our favorite (as in most dislik…
  continue reading
 
Harold Rivas has held multiple CISO roles. In his current CISO role, he's championing Trellix's overall mission to address the issues CISOs face every day, encouraging information sharing and collaborative discussions among the CISO community to help address challenges and solve real problems together - part of this is through Trellix's Mind of the…
  continue reading
 
Chuck Joiner, Brian Flanigan-Arthurs, Eric Bolden, Marty Jencius, Jim Rea, Jeff Gamet, and David Ginsburg wrap up a MacVoices Live! discussion by talking about the latest report on switching to the Mac, as well as what might be behind LinkedIn’s announcement that they are adding gaming to their platform. This edition of MacVoices is supported by Ma…
  continue reading
 
Many years ago, I fielded a survey focused on the culture of cybersecurity. One of the questions asked what initially drew folks to cybersecurity as a career. The most common response was a deep sense of curiosity. Throughout my career, I noticed another major factor in folks that brought a lot of value to security teams: diversity. Diversity of pe…
  continue reading
 
Charlotte Henry and Chuck Joiner celebrate a year of the TV+ Talk collaboration by looking at how Apple TV+ has evolved since its beginnings, their original content moving to other services, a recent article citing the quality of the service, and more. Show Notes: Chapters: 00:00 TV Plus Talk Anniversary Reflections 01:46 Apple TV+ Quality Recognit…
  continue reading
 
The 2024-03 MacVoices Update includes an explanation of why there are monthly updates, an evolution of MacVoices Live! for our non-live listeners and viewers, why MacVoices Magazine is picking up steam again, and the monthly Support Report. Show Notes: Support: Become a MacVoices Patron on Patreon http://patreon.com/macvoices Enjoy this episode? Ma…
  continue reading
 
Jason Healey comes on the show to discuss new ideas on whether the new national cybersecurity strategy is working. Segment Resources: DEFRAG Hacker Film Festival short documentary (https://youtu.be/NYvHWcQsIRE) on hackers and their favorite films. For educational purposes only, as we don’t have the rights to the clips. YouTube link to Wargames even…
  continue reading
 
The privacy theme rolls on as Chuck Joiner, Brian Flanigan-Arthurs, Eric Bolden, Marty Jencius, Jim Rea, Jeff Gamet, and David Ginsburg look at the almost unbelievable Terms of Service in the most recent Roku update and how it applies to which Roku device/channel/app. Then, the MacVoices panel delivers some initial thoughts on what appears to be a …
  continue reading
 
Our privacy theme continues as the MacVoices Live! panel looks at HP’s new option to rent a printer. Is that a good idea given the seemingly onerous contract terms, let alone the possible privacy concerns over an always-connected-to-the-Internet printer? Chuck Joiner, Brian Flanigan-Arthurs, Eric Bolden, Marty Jencius, Jim Rea, Jeff Gamet, and Davi…
  continue reading
 
With hundreds or thousands of SaaS apps to secure with no traditional perimeter, Identity becomes the focal point for SaaS Security in the modern enterprise. Yet with Shadow IT, now recast as Business-Led IT, quickly becoming normal practice, it’s more complicated than trying to centralize all identities with an Identity Provider (IdP) for Single S…
  continue reading
 
Chuck Joiner, Brian Flanigan-Arthurs, Eric Bolden, Marty Jencius, and Jim Rea discuss the hacking of a panel member’s Instagram account, along with what appeared to be an attack on his Facebook account. They discuss scams, other personal experiences with compromises, and a couple information pieces that caught their attention. This edition of MacVo…
  continue reading
 
Loading …

Quick Reference Guide