Player FM - Internet Radio Done Right
Checked 13d ago
Vor vier Jahren hinzugefügt
Inhalt bereitgestellt von Steve Stonebraker. Alle Podcast-Inhalte, einschließlich Episoden, Grafiken und Podcast-Beschreibungen, werden direkt von Steve Stonebraker oder seinem Podcast-Plattformpartner hochgeladen und bereitgestellt. Wenn Sie glauben, dass jemand Ihr urheberrechtlich geschütztes Werk ohne Ihre Erlaubnis nutzt, können Sie dem hier beschriebenen Verfahren folgen https://de.player.fm/legal.
Player FM - Podcast-App
Gehen Sie mit der App Player FM offline!
Gehen Sie mit der App Player FM offline!
Ephemeral Security
Alle als (un)gespielt markieren ...
Manage series 2966069
Inhalt bereitgestellt von Steve Stonebraker. Alle Podcast-Inhalte, einschließlich Episoden, Grafiken und Podcast-Beschreibungen, werden direkt von Steve Stonebraker oder seinem Podcast-Plattformpartner hochgeladen und bereitgestellt. Wenn Sie glauben, dass jemand Ihr urheberrechtlich geschütztes Werk ohne Ihre Erlaubnis nutzt, können Sie dem hier beschriebenen Verfahren folgen https://de.player.fm/legal.
Interviews and fun with professionals, hackers, and everything in between.
…
continue reading
17 Episoden
Alle als (un)gespielt markieren ...
Manage series 2966069
Inhalt bereitgestellt von Steve Stonebraker. Alle Podcast-Inhalte, einschließlich Episoden, Grafiken und Podcast-Beschreibungen, werden direkt von Steve Stonebraker oder seinem Podcast-Plattformpartner hochgeladen und bereitgestellt. Wenn Sie glauben, dass jemand Ihr urheberrechtlich geschütztes Werk ohne Ihre Erlaubnis nutzt, können Sie dem hier beschriebenen Verfahren folgen https://de.player.fm/legal.
Interviews and fun with professionals, hackers, and everything in between.
…
continue reading
17 Episoden
Alle Folgen
×E
Ephemeral Security

1 Jason Costain - Fraud Defense with Javloc 1:21:27
1:21:27
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked1:21:27
Jason Costain, founder of Javloc, joins us to discuss his 30 years of experience in fraud prevention and bank defense systems. Jason shares insights into the evolution of fraud, from early check scams to modern-day threats like voice deepfakes and machine learning-driven credit card fraud. He also highlights the UK's regulatory responses, the importance of customer education, and the role of technology in combating scams. Jason introduces Javloc's mission to help banks and companies enhance their scam defenses. Highlights Include: Early experiences with fraud and the evolution of scam tactics. The impact of real-time payments and internet banking on global fraud. UK regulatory measures like the voluntary refund code and consumer protection reforms. Advanced scam techniques, including voice deepfakes and machine learning. The role of banks in educating customers and implementing biometric security measures. Javloc's approach to advising organizations on fraud prevention. Pick of the Week: Steve Stonebraker - Real Dictators podcast. Jason Costain - Surrounded by Psychopaths by Thomas Erikson. Guest: Jason Costain - https://www.linkedin.com/in/jason-costain-b529746/ Javloc - https://www.javloc.com/ Links : Podcast Website: https://ephemeralsecuritypodcast.com Steve's Other Podcast: https://aolunderground.com/ Brakertech LLC: https://brakertech.com Github: https://github.com/ssstonebraker Social : LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech Credits : Audio Editing by Sam Fox - sam.fox.london@gmail.com Intro music by Margo Stonebraker…
E
Ephemeral Security

Dr. Ethan Heilman, CTO of Bastion Zero, joins us to discuss the latest advancements in secure access technology and the ethical implications of AI systems. Dr. Heilman explains how Bastion Zero provides secure, passwordless access to servers, databases, and Kubernetes clusters without the need for VPNs or SSH keys. Key features include session recording, multi-factor authentication (MFA), and short-lived credentials to ensure robust security. Highlights include: Bastion Zero’s Approach to Secure Access: Eliminates shared credentials by using SSL identities and MFA. Enables real-time session monitoring and auditing. Supports secure access for on-premises and cloud environments (AWS, GCP, etc.). Introduces Split Cert, a multi-party computation (MPC) technique for generating secure, short-lived database credentials without single points of compromise. Remote Desktop Protocol (RDP) and Kubernetes Access: Pick of the Week: Steve Stonebraker - The man who broke into Windsor Castle to assassinate the late Queen with a crossbow had discussed his plans with his AI chatbot girlfriend Man Dies by Suicide After Talking with AI Chatbot, Widow Says Ethan Heilman - A Collection of Unmitigated Pedantry – A history blog offering in-depth, approachable explorations of historical topics. Guest: Dr. Ethan Heilman - https://www.linkedin.com/in/ethan-heilman-39896934/ BastionZero's website - https://www.bastionzero.com/ Video on how multiple MFA works with Bastion Zero - https://brakertech.com/aws-systems-manager-session-manager-on-steroids/ Links: Podcast Website: https://ephemeralsecuritypodcast.com Steve's Other Podcast: https://aolunderground.com/ Brakertech LLC: https://brakertech.com Github: https://github.com/ssstonebraker Social: LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech Credits: Audio Editing by Sam Fox - sam.fox.london@gmail.com Intro music by Margo Stonebraker…
E
Ephemeral Security

We dive deep into the evolution of neworks and security from early internet to today. Mentioned in the show: Cyber Trust Mark Pick of the Week: Steve Stonebraker - The Artifice Girl Jim Rigney - Healthy Gamer GG - "You Are Burned Out And Don't Even Know It" Episode Show Notes: Jim Rigney - https://www.linkedin.com/in/rigney/ Links: Podcast Website: https://ephemeralsecuritypodcast.com Steve's Other Podcast: https://aolunderground.com/ Brakertech LLC: https://brakertech.com Github: https://github.com/ssstonebraker Social: LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech Credits: Audio Editing by Sam Fox - sam.fox.london@gmail.com Intro music by Margo Stonebraker…
E
Ephemeral Security

1 Dan Nowak - Threat Intelligence, Insider/Nation State Threats, and Beyond 1:13:23
1:13:23
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked1:13:23
Chat with Dan Nowak about threat intelligence, insider threats, deception techniques, intellectual property theft, Made in China 2025, Unlimited Warfare, the future of ransomware, and Defcon. Pick of the Week: Steve - The Americans Dan - Meat Church Guys - The Whisky Bent Barbecue Episode Show Notes: Dan Nowak - https://www.linkedin.com/in/nowakdaniel/ Website: www.celsus.io Substack: https://archetypesandobjectives.substack.com Links: Podcast Website: https://ephemeralsecuritypodcast.com Steve's Other Podcast: https://aolunderground.com/ Brakertech LLC: https://brakertech.com Github: https://github.com/ssstonebraker Social: LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech Credits: Audio Editing by Sam Fox - sam.fox.london@gmail.com Intro music by Margo Stonebraker…
Chat with Matt Wright, Senior Security Engineer on Cloud Security Posture Management (CSPM), Attack Surface Management (ASM), Artificial Intelligence. We also cover some news, talk about zero days, and responsible disclosure Episode Show Notes: Matt Wright - https://www.linkedin.com/in/matt1337/ Links: Podcast Website: https://ephemeralsecuritypodcast.com Github: https://github.com/ssstonebraker Brakertech LLC: https://brakertech.com Social: LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech Credits: Audio Editing by Sam Fox - sam.fox.london@gmail.com Intro music by Margo Stonebraker…
E
Ephemeral Security

1 Presenting: AOL Underground "AOL History from the people that lived it - Erci Stern" 1:14:09
1:14:09
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked1:14:09
Erci Stern tells us her origin story. We review in depth how she battled users that were uploading Warez on a customer's Anonymous FTP site and also hear a funny story about Slingo. She takes us through her entire career at AOL where she started in Site Reliability (Systems Administration/Operations), moving to Information Security/QA, and then went into project management. We also cover her life after AOL where she went back to System Administration and has been a champion of security along the way throughout her career. Other topics include Configuration Management, Security Certifications, passion projects, etc.. Erici also shares with us her experience mentoring at "Girls who Code" and advice for girls that want to go into IT. Guest: Erci Stern Host: Steve Stonebraker CoverArt: Created by Broast ( https://broast.org ), original idea by LampGold. -- AOL Underground Podcast Follow us on twitter - @AOLUnderground @brakertech Merch - https://www.redbubble.com/people/AOL-Underground/shop Donate - https://www.buymeacoffee.com/AOLUnderground Contact the Host - https://aolunderground.com/contact-host/ Reconnect with old AOLers - https://discord.gg/reaol https://aolunderground.com/community/…
E
Ephemeral Security

1 Presenting: AOL Underground "Origin story of a Digital Forensic Incident Responder (DFIR)" 2:10:56
2:10:56
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked2:10:56
Surf Kahuna (Ryan Chapman) shares his origin story about a series of events that occurred on AOL that rocked his world and led him down the path of digital forensics. Then Steve and Ryan talk espionage, multiple Advanced Persistent Threats, retro gaming, password spraying, ransomware, and what has helped Ryan be successful in Infosec. Guest: Surf Kahuna/Mac Diablo (Ryan Chapman) Host: Steve Stonebraker CoverArt: Created by Broast ( https://broast.org ), original idea by LampGold. -- Ryan Chapman Follow Ryan on Twitter - @rj_chap Ryan's Blog - https://incidentresponse.training/ Author of SANS FOR528 "Ransomware for Incident Responders" - for528.com/course Instructor of SANS FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques - https://www.sans.org/cyber-security-courses/reverse-engineering-malware-malware-analysis-tools-techniques/ Part of the @CactusCon crew - https://www.cactuscon.com/ -- AOL Underground Podcast Follow us on twitter - @AOLUnderground @brakertech Merch - https://www.redbubble.com/people/AOL-Underground/shop Donate - https://www.buymeacoffee.com/AOLUnderground Contact the Host - https://aolunderground.com/contact-host/ Reconnect with old AOLers - https://discord.gg/reaol https://aolunderground.com/community/…
Chat with Sandeep Lahane, CEO of Deepfence, on how ThreatStryker is changing the game for Cloud Workload Protection. We go deep in to the product's unique full SSL decryption and packet capture capability, identification of an organizations most vulnerable endpoints, and automated workflows to remediate compromised systems. Episode Show Notes: Sandeep Lahane - https://www.linkedin.com/in/sandeep-lahane-b9520a4/ Deepfence - https://deepfence.io/ Review of Deepfence's sandbox environment - https://brakertech.com/deepfence-cloud-native-workload-protection-for-infosec-pros/ Links: Podcast Website: https://ephemeralsecuritypodcast.com Blog: https://brakertech.com Github: https://github.com/ssstonebraker Social: LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech Credits: Intro music by Margo Stonebraker…
E
Ephemeral Security

1 Ryan Fried - Senior Security Engineer & Adjunct Professor 1:06:44
1:06:44
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked1:06:44
Chat with Ryan Fried about being and adjunct professor in the Cyber Security space, being a virtual CISO and talking to executives, purple teaming, true positive security incidents, validating your controls and what you think you know, and Atomic Red Team . Episode Show Notes: Ryan Fried - https://www.linkedin.com/in/ryan-fried-65747938/ Atomic Red Team - https://github.com/redcanaryco/atomic-red-team Bloodhound - https://github.com/BloodHoundAD/BloodHound Checkov - https://www.checkov.io/ Links: Podcast Website: https://ephemeralsecuritypodcast.com Blog: https://brakertech.com Github: https://github.com/ssstonebraker Social: LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech Credits: Podcast edited and mastered by Charlie Clark, https://www.fiverr.com/chuckaudio Intro music by Margo Stonebraker…
Chat with Lisa Falzone and Michael Green of Athena Security Athena Security focuses on Entryway Security - https://www.athena-security.com/ Guests Michael Green, CEO and Co-Founder Lisa Falzone, President and Co-Founder Show Notes https://ephemeralsecuritypodcast.com/athena-security/ Podcast edited and mastered by Charlie Clark, https://www.fiverr.com/chuckaudio Intro music by Margo Stonebraker…
E
Ephemeral Security

1 Ethan Heilman – BastionZero 1:07:02
1:07:02
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked1:07:02
Chat with @Ethan_Heilman, CTO of @getBastionZero on how they are adding additional security when accessing remote infrastructure. BastionZero adds an additional separate Multi Factor Authentication into the authentication process and has a unique multi-root security model. Ethan can be found at: LinkedIn: https://www.linkedin.com/in/ethan-heilman-39896934/ Twitter: https://twitter.com/Ethan_Heilman //Show Notes// BastionZero's website - https://www.bastionzero.com/ Video on how multiple MFA works with Bastion Zero - https://brakertech.com/aws-systems-manager-session-manager-on-steroids/ Podcast edited and mastered by Charlie Clark, https://www.fiverr.com/chuckaudio Intro music by Margo Stonebraker //Chapter Timestamps// 00:00:41 Meet Ethan Heilman 00:01:10 When did you first use a computer? 00:01:29 How did you get into Information Security 00:02:42 Crypto Company to Bastion Zero 00:05:08 Multiparty Computation 00:06:07 Certificate Authorities 00:08:13 AWS PrivateLink/VPC Endpoints 00:10:38 How does Bastion Zero Work? 00:14:55 Shared Responsibility 00:16:50 Dynamic Targets 00:19:46 What does the term "Zero Trust" mean to you? 00:21:01 Proxying HTTP 00:23:17 SELinux 00:23:45 Privileged Access Management 00:27:35 AWS Root Account 00:33:26 Separate Admin Accounts 00:36:12 API Keys 00:40:58 Response for product in the wild? 00:45:11 Stopping Ransomware 00:52:26 Phishing 01:01:21 Modifying Linux Pluggable Authentication Module 01:06:18 Goodbye…
E
Ephemeral Security

1 Devin Casadey – Global Red Team Lead 1:11:27
1:11:27
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked1:11:27
Chat with @DevinCasadey , Managing Principal / Global Red Team Lead. Devin's Certifications: OSCE3 (OSWE, OSEP, OSED), OSCP, OSCE, OSEE, OSWP, eCTHP, GCPN Devin can be found at: Hack the Box: https://www.hackthebox.eu/profile/28293 HTB & CTF Team: https://www.hackthebox.eu/teams/profile/1685 Github: https://keramas.github.io/about.html LinkedIn: https://www.linkedin.com/in/devin-casadey-198117b/ Twitter: https://twitter.com/DevinCasadey Show Notes Don't Roll Your Own: Devin's Writeup for how he decoded the database (referenced in the episode) - https://keramas.github.io/2022/05/03/dont-roll-your-own.html EvilGinx: Man in the Middle Two Factor Auth - https://github.com/kgretzky/evilginx2 Chapter Timestamps 01:09 -- Why are you passionate about Infosec? 02:17 -- First use a computer? 05:31 -- What are you doing now? 06:16 -- Best way to hone skills? 07:54 -- Difference between Redteaming and Pentesting 09:12 -- Are Pentesters ever asked to emulate APTs? 11:51 -- Do you test different EDR Vendors? 16:18 -- Test Scenario 17:42 -- Do you have to write custom exploits for engagements? 23:31 -- Do you tell vendors you can bypass their EDR product? 26:02 -- Trying to get caught by Security Team 27:21 -- What can customers do to get the most out of a pentesitng engagement? 32:09 -- Pentest Client Behavior 35:56 -- Linux Boxes 37:11 -- Windows Security 40:30 -- Found Machine Already Compromised? 41:44 -- Pentest Planning 43:46 -- Memorable Engagements 47:07 -- Zero Trust 53:44 -- Initial Point of Entry 58:55 -- Okta Breach 01:01:27 -- Triple MFA 01:02:53 -- Avoid Burnout? 01:05:00 -- Joining a Redteam 01:09:44 -- Any Passion Projects? 01:10:21 -- Goodbye Links: Podcast Website: https://ephemeralsecuritypodcast.com Blog: https://brakertech.com Github: https://github.com/ssstonebraker Social: LinkedIn: https://www.linkedin.com/in/stevestonebraker Twitter: https://twitter.com/brakertech…
E
Ephemeral Security

1 Mike Wyatt: CYDERES 1:08:29
1:08:29
Später Spielen
Später Spielen
Listen
Gefällt mir
Geliked1:08:29
Chat with Mike Wyatt, Chief Security Officer at CYDERES Mike can be found at: https://twitter.com/cleverexploit https://www.linkedin.com/in/cleverexploit/ Note: This episode has chapters embedded in the file!
E
Ephemeral Security

The Cyclops Blink botnet is explained (how it worked) and a question is posed to the guests if this should be considered an act of Cyber War Guests: Matt Wright and Brad Lindsley Episode Extras: https://ephemeralsecuritypodcast.com/cyclops-blink/ (includes diagram of botnet, link to the court order to disrupt the botnet, and more)…
E
Ephemeral Security

Guest: Iman Joshua - Head of Information Security at Vimeo Host: Steve Stonebraker stevestonebraker.com Special Thanks Audio Editing and Sound - Adam Joesph - https://www.adamjosephsounds.com/ Theme music - Margo Stonebraker - codewithmargo.com
Willkommen auf Player FM!
Player FM scannt gerade das Web nach Podcasts mit hoher Qualität, die du genießen kannst. Es ist die beste Podcast-App und funktioniert auf Android, iPhone und im Web. Melde dich an, um Abos geräteübergreifend zu synchronisieren.