
Advertise on podcast: Security Headlines
Rating
5from
This podcast has
25 episodes
Language
EnglishPublisher
Firo SolutionsExplicit
No
Date created
2020/03/23
Latest episode
2022/03/03
Average duration
64 min.
Release period
46 days
Description
Security Headlines is a podcast about the latest security vulnerabilities with in the cyber security field. So if your interested about the latest security holes no mather if you are a tech savy penetration tester, a devops person, a programmer or just generally interested in the latest technology security news. Security headlines is here for you Security headlines is perfect to listen on when you want a quick update, on the way to work or when you are taking a walk out side The podcast is produced by firosolutions.com
Unlock Security Headlines podcast Email contact info,
Listeners & Audience details
Email contact information
Direct podcast contact details

Listeners
Audience numbers & engagement insights

Audience details
Podcast Insights

Podcast episodes
Check latest episodes from Security Headlines podcast
Introducing Hacker Talk
2022/03/03
Subscribe to Hacker Talk and listen to the latest episodes at:
https://anchor.fm/hacker-talk
Fuzzing with Patrick Ventuzelo
2021/10/24
In this episode of Security Headlines we deep dive into fuzzing with Patrick Ventuzelo.
topics that we cover:
being niched in cyber security
patricks background, doing pentests on telecom networks, doing security research on the android kernel for the french DoD, reverse engineering, development
Zero days in the android kernel
choicing a target when fuzzing
blackbox and whitebox fuzzing
fuzzing golang projects
fuzzing rust projects
setting up fuzzing enviroments
webassembly security
fuzzing webassembly
invalid web assembly opcodes
the next generation of browser exploits
javascript runtimes
exploiting webassembly in the browser
fuzzing blockchain applications
how to write a fuzzer
what to look for while fuzzing
fuzzing javascript
writing fuzzers in python
ataris fuzzer for python code
libfuzzer
llvm
analysing code repositories and finding bad patterns
golang built in fuzzing(go-fuzz, fuzzing draft)
fuzzing ethereum solidity smart contracts
fuzz bench by google
fuzzing the android kernel
beacon fuzz
reporting security bugs
github security advisory
favorite security conferences
External links:
https://fuzzinglabs.com/
http://stackoverflow.com/questions/43153964/ddg#43154559
https://www.youtube.com/channel/UCGD1Qt2jgnFRjrfAITGdNfQ
telegram fuzzlab lab
https://googleprojectzero.blogspot.com/2021/01/in-wild-series-chrome-exploits.html
Osint Special with Jay Townsend
2021/08/17
In this episode of Security Headlines, we are joined by Jay Townsend who is
maintaining several infosec tools such as the harvester and discover.
The harvester is a very popular tool for doing Osint analysis. Tune into this episode
as we deep dive into Osint, the opensource information gathering realms.
In this episode we cover:
what is osint and how can we use it?
discover, lee baird
the harvester
dnsrecon
bash
python
backtrack
wifi security, wep
wifi pineapple, bash bunny, hack5
hack the box, try hack me, hack this site.org
sysadmin, ansible
finding passwords in log files
how to apply security hardenings, systemctl hardenings
running weekly security scans
bug bounties
penetration tests
finding old applications in production
burpsuit
using the harvester
harvester in kali linux, parrotsec, blackarch and debian
porting the harvester to python 3
screen-shooting websites with the harvester
hidden features in the harvester
fierce dns hacking
dnsrecon
how to perform osint analysis on yourself and others
how to protect yourself against osint attacks
using throw away email addresses
how to use osint during penetration tests
python development
docker
linux firmware, wifi drivers
visual code
the latest windows exploits
Links:
https://en.wikipedia.org/wiki/PyCharm
https://www.parrotsec.org/
https://github.com/leebaird
https://www.youtube.com/watch?v=F9UZdPokkhw
https://github.com/laramies/theHarvester
https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-windows-10-serioussam-vulnerability/
https://en.wikipedia.org/wiki/Open-source_intelligence
https://twitter.com/jay_townsend1
https://bloodhound.readthedocs.io/en/latest/
https://www.ansible.com/
Security Headlines with Kolja Weber
2021/01/19
In this episode of Security Headlines, Kolja Weber the creator of flokinet.is joins us.
In this episode we talk about:
flokinet
internet privacy
german pirate party
internet privacy laws
Iceland
starting an internet service provider
running an internet service provider
ipv4 addresses
adoption of privacy friendly tools
handling abuse requests
starting an internet service provider
RIPE
denial of service attacks
mitigating denial of service attacks
starting a privacy focused internet service provider
DNS amplification attacks
security
free speech
adoption of https, starttls and dkim
external links:
https://flokinet.is
https://twitter.com/frelsisbaratta
https://www.afrinic.net/
https://ripe.net
https://en.wikipedia.org/wiki/RIPE_NCC
https://en.wikipedia.org/wiki/AFRINIC
https://letsencrypt.org/
https://www.qubes-os.org/
ChalmersCTF with Michael Dubell
2020/12/17
In this episode of Security Headlines, we are joined by Michael Dubell who co-founded Sweden's first student security
capture the flag team. What is capture the flag and how do you play it? How can you into hacking through the doors of playing
ctf's? Michael started playing around with security as a teenager and the journey led him the capture the flag team, known
as "ChalmersCTF".
Today, Michael is working with security during the day, and during the night he is developing the soon to
be released "bountrystrike"(which you can find on bountystrike.io) tool.
Tune in as we talk about CTF, and a lot more!
In this episode we cover:
halo one online
wallhack
war games
hacking on forums
hack this site
over the wire
https://www.hellboundhackers.org/
chalmers
chalmers CTF
how to start a "capture the flag" team
organizing capture the flag meetups
beginner ctfs
over the wire
the capture the flag scene in Sweden
over the wire
whitebox pentesting
bug bounties
automating scanning and automating bug bounties
vulnerability management
finding bugs in bug bounty programs
## External links:
https://github.com/search?q=capture%20the%20flag%20writeups&type=Everything&repo=&langOverride=&start_value=1
https://github.com/zardus/ctf-tools
https://ctftime.org
https://chalmersctf.se/
https://overthewire.org
https://twitter.com/StevenVanAcker
https://bountystrike.io/
https://dubell.io/
Security Headlines with Antoine Jacoutot
2020/12/04
In this episode of Security Headlines, we are joined by one of the minds behind the OpenBSD project, Antoine Jacoutot. He is responsible
for porting over 300 packages into OpenBSD. He is also involved in syspatch which handles security binary upgrades for OpenBSD.
Tune in, as we talk about development, security, programming, OpenBSD and a lot more!
## Topics that we cover:
OpenBSD's community
opensource
rcctl
init systems
classic BSD
background daemons in OpenBSD
OpenBSD desktops in the wild
companies running OpenBSD
writing shellcode
openup
binary patches in OpenBSD
How OpenBSD handle security issues
how security binary patches are carried out.
syspatch
porting software to OpenBSD
Gnome on OpenBSD
OpenBSDs future with Amazon AWS
sysmerge
submitting feature requests to OpenBSD
tmux
advice for first-time OpenBSD users
## External links:
https://www.OpenBSD.org/errata.html
https://bsdfrog.org/
https://twitter.com/ajacoutot
https://OpenBSD.org
https://gnome.org
https://www.OpenBSD.org/faq/ports/ports.html
https://man.OpenBSD.org/syspatch
https://man.OpenBSD.org/sysmerge
https://github.com/ajacoutot
https://man.OpenBSD.org/rcctl
DynaGuard Special
2020/11/30
In this episode of Security Headlines, we are joined by a great mind in the
memory security space. A spark was created when Theofilos peaked
into the realms of security. So he packed his bag and got to the next plane to the US in order to deep-dive more into the security field during
his studies. He became fascinated by the world of writing exploits
and "smashing the stack" as we say in the hacking field. He is a
brilliant guy when it comes to memory attack and he has co-written a
solution that solves the stack canary problem.
We had the chance to sit down with Theofilos Petsios and
get to hear his view on security, development and a lot more.
That you can tune into right here:
Stack canaries is a security mitigation technique that has been widely
adopted and you will find it in most systems today. But does it really work?
Topics that we touch upon in this episode:
Stack canaries
Address layer space randomization
Blind Return Oriented Programming (BROP)
Return Oriented Programming
Static code analysis
Rest in peace Andrea Bittau
security mitigations
Write Xor Execute(W^X)
Dynaguard
Where stack canaries fail and the operating systems approach to it.
hardening systems
where the future of security is going
CVE's over time
Memory corruption bugs
builtin security in the compilers
Security vs Overhead
Using memory in the Thread-local storage
adoption of security mitigations
stack clash
Pin, Intel's dynamic binary instrumentation framework
Defense Advanced Research Projects Agency
whitepapers and Proof of concepts
Fuzzing
building better security tools
Cost vs benefit in the security field
Switching from userspace to kernel space mitigations
linters
secure codebases
formal verifications
"Stack canaries is just one little stone, one a the beach that keeps getting hit by big waves"
External links
https://twitter.com/theofilospe
https://www.cs.columbia.edu/~theofilos/files/slides/dynaguard.pdf
https://www.cs.columbia.edu/~theofilos/files/papers/2015/dynaguard.pdf
http://www.scs.stanford.edu/brop/
http://www.scs.stanford.edu/brop/bittau-brop.pdf
https://github.com/nettrino/DynaGuard
https://software.intel.com/content/www/us/en/develop/articles/pin-a-dynamic-binary-instrumentation-tool.html
https://github.com/nezha-dt/nezha
https://llvm.org/docs/LibFuzzer.html
https://github.com/nettrino/vimconf
https://capsule8.com/blog/millions-of-binaries-later-a-look-into-linux-hardening-in-the-wild/
https://youtu.be/Er44ur7wkXQ?t=44
Security Headlines with Jonas Lejon
2020/11/20
Jonas Lejon is an amazing mind in the Swedish security world. A
great entrepreneur, hacker, and security-expert!
We had the pleasure of talking with him in this episode of Security Headlines.
he wanted to specialize in security so he packed his bag and headed over
to the capital city to work more in-dept with security. He wanted to
go deeper and deeper, so spent his extra hours learning the assembly programming
and getting into the low-level brain of the computer system. He managed
to land a job working for the Swedish version of NSA.
Jonas now runs his own company called "Triop" and has a lot of fun side
projects that we dig into.
In this episode we also cover:
Micro blogging
building search engines
bloggz dot se
Getting over 20K users within a few weeks
Twitter in the early days
Building Sweden's biggest micro-blogging platform
testing in production
WordPress Security
bug bounties
Finding security holes in Zoom
writing about encryption and security
fuzzing
Hacking Bluetooth
ISOC-SE
the swedish top level domains .se and .nu
the internet in Sweden
beatboxing
pentesting
enumerating existing users based on validation time
updated, security by default systems
network logging
Programming
leaving python 2
Customizing Kali linux
Time-of-check to time-of-use attacks
writing exploits
## External links:
https://triop.se
https://kryptera.se
https://web.archive.org/web/20081102073248/http://bloggz.se/
https://web.archive.org/web/20110630210858/http://bloggy.se/
https://en.wikipedia.org/wiki/Memcached
https://wpsec.com/
https://utvbloggen.se/
https://se.linkedin.com/in/jonaslejon
https://www.youtube.com/channel/UCI49rLPi_Lbbux5eo8ewLKA
https://en.wikipedia.org/wiki/Dave_Aitel
https://github.com/SofianeHamlaoui/Spike-Fuzzer
https://isoc.se/
https://internetstiftelsen.se/en/
https://www.netnod.se/
https://en.wikipedia.org/wiki/Kali_Linux
https://en.wikipedia.org/wiki/Arcade_Fire
https://en.wikipedia.org/wiki/Time-of-check_to_time-of-use
https://github.com/juliocesarfort/public-pentesting-reports
https://www.hackerone.com/
https://www.bugcrowd.com/
https://twitter.com/jonasl
Security Headlines with Johan Rydberg Moller
2020/11/13
In this episode of Security Headlines, we are joined by one of Gothenburg's security evangelist, Mr Johan Rydberg Moller.
Johan is the cofounder of Gothenburg's own security conference *Security Fest*, sakerhetspodcasten - the first swedish security
podcast, hacker, explorer, and musician. We get to hear the tale of how Johan got sucked into the world of hacking, that
has been his home for a lot of years now, as well as adventures with publicly disclosing security holes in some of
sweden's biggest websites. This and a lot more in this episode of Security Headlines:
## In this episode we cover:
learning web security when web security was a new thing
Reporting security vulnerabilities.
life as a web developer.
finding security holes in the top 100 websites in Sweden.
PHP security
cofounding assured
starting the "security fest" conference
tattooing the conference logo
starting the first Swedish security podcast
pentesting
gothenburg
owasp
web caching attacks
## External links
https://twitter.com/JohanRMoller
https://securityfest.com
https://sec-t.org
https://www.assured.se/
https://securitywithoutborders.org/blog.html
https://portswigger.net/burp
https://portswigger.net/research
https://www.youtube.com/watch?v=zP4b3pw94s0
https://www.theverge.com/2020/3/24/21192830/apple-safari-intelligent-tracking-privacy-full-third-party-cookie-blocking
https://soundcloud.com/johanrm
https://www.dagensmedia.se/medier/digitalt/soderhavet-kritiseras-for-sakerhetshal-6176181
https://sakerhetspodcasten.se/lyssna/
https://owasp.org/www-chapter-gothenburg/
Security Headlines with Eijah
2020/11/06
In this episode we are Joined by the developer, hacker and Code Siren founder Eijah.
We walk down a road of 2 hours of honest conversation about Development, Morals,
working with McAfee, Hacking, Motivation, Mental Health, Security and a lot more!
Eija, an advocate for privacy and individual rights, quit a well paid job at rockstar games to start on a
journey pursuing what he loved. He went on a journey with the goal of creating technology that
enhance personal liberty and freedom. The journey has had its bumps in the road but he as continued
marching forward, despite various problems. Today, Eijah runs a software company called CodeSiren.
Working on revolutionary technology
In this episode we cover:
hacker spirit, engineer, tinkerer
C++, Java
Max payne 3, Red Dead Redemption, grand theft auto 5
programming for the love of it
game developer,
Working at rockstar, life at rockstar
life as a developer
hacking blueray and finding the blueray device keys
Large code bases, code maintenance, clean modular code
your code is your documentation
Xbox360 vs Playstation 3
The failures of VPN companies, selling people's private companies.
Drinking pints, in Edinburgh
Starting and developing demonsaw
file sharing
privacy
traffic obfuscation and traffic subterfuge, bypassing deep packet inspection
great firewall of china
Surveillance
Privacy
Cryptography
Censorship
John Mcafee
Being a senior programmer
"My greatness stems from not having achieved what I am here to achieve" - Eijah
## External links:
https://twitter.com/demon_saw
https://codesiren.com
https://demonsaw.com
https://en.wikipedia.org/wiki/Commodore_VIC-20
https://darknetdiaries.com/episode/16/
https://en.wikipedia.org/wiki/Advanced_Encryption_Standard
https://en.wikipedia.org/wiki/CPU_time
https://forum.doom9.org/
https://www.reddit.com/domain/forum.doom9.org/
https://en.wikipedia.org/wiki/Hackers_(film)
https://en.wikipedia.org/wiki/Dunning-Kruger_effect
https://en.wikipedia.org/wiki/Impostor_syndrome
https://en.wikipedia.org/wiki/Allocator_(C%2B%2B)
https://en.wikipedia.org/wiki/PlayStation_technical_specifications
https://www.nextplatform.com/2019/01/24/unified-memory-the-final-piece-of-the-gpu-programming-puzzle/
https://www.youtube.com/watch?v=lTngMxmymX4
https://www.youtube.com/watch?v=fMfQQoHHLBA
https://steelpantherrocks.com/
https://www.youtube.com/watch?v=WjElZ-O9EpM
Security Headlines with Johnny Xmas
2020/10/30
In this episode of Security Headlines, we are joined by
the Hacker Johnny Xmas. Johnny is a very interesting character
with a lot of fun projects behind him.
Join us as we get to hear Johnny's stories as we deep dive
into this weeks episode of Security Headlines:
## Venmo
After giving a talk about it and releasing software that made everyone
able to easily abuse this, Luckily venmo took action and limited the
amount of data avaliable. Johnny found a way to generate api keys with
just making a simple request to the
## Bypassing Webb application firewalls
A lot of firewalls just focus on IP filtering which is a huge problem
when, in todays world it is really easy and cheap for a consumer
to aquire a large sets off ip addresses.
One provider of proxied ip addresses is Hola VPN that lets their free
users act as exit nodes that they sell using platforms such as luminate.
Other people have adopted this approach but with mobile development toolkits.
## Grimm
Johnny is currently working for the security engineering firm Grimm, a company known for its involvement in the ICS(Industrial control system) security work.
Currently working on developing
Grimm is currently hiring people, do you want to get paid to develop security training platforms ?
then Grimm is the place for you!
External links:
https://twitch.tv/j0hnnyxm4s
https://twitter.com/J0hnnyXm4s/
https://www.youtube.com/c/JohnnyXmas/
https://github.com/johnnyxmas/Talk_Decks/tree/master/2019/Sorry%20about%20your%20WAF
https://ghost.express/
https://www.cnbc.com/2020/05/07/zoom-buys-keybase-in-first-deal-as-part-of-plan-to-fix-security.html
https://www.twitch.tv/mr_horologist
https://twitter.com/cigarsec
https://www.icsvillage.com/
https://www.grimm-co.com/careers
https://en.wikipedia.org/wiki/Venmo
https://www.technowize.com/grindr-security-flaw-lets-anyone-hijack-user-accounts/
https://en.wikipedia.org/wiki/Principle_of_least_privilege
https://en.wikipedia.org/wiki/Branched-chain_amino_acid
https://opihr.com/
https://en.wikipedia.org/wiki/Sub7
https://nmap.org/book/man-nse.html
https://en.wikipedia.org/wiki/Less_Than_Jake
https://en.wikipedia.org/wiki/Oh,_Sleeper
https://luminati.io/
https://selenium.dev/
https://blog.firosolutions.com
Tokio special with Carl Lerche
2020/10/23
In this podcast episode of Security Headlines: Carl Lerche, Rust developer and
maintainer of the popular Rust programming library Tokio joins us.
He walks us through what Rust and Tokio is, how companies are building their stacks with Rust.
This and a lot more on this episode of Security Headlines!
Carl heard about this new programming language called Rust and wanted to check it out.
What started as a hobby project led Carl down the rust path and he now works for Amazon as a
Rust developer! Helping Amazon build stable infrastructure.
We get to hear the story of how Tokio got started and how the Rust programming language has changed
over the years.
Since a large chunk of Tokio code is focusing on making it easy for developers to write asynchronous functions.
And be able to write fast code that does not get stuck and lets the data flow.
But how does non-blocking code really work? What differs Rust from the programming language Golang is
Golangs, adoption of green threads instead of using regular threads.
Carl walks us through how this works and how Rust tackles this problem "the Rust way".
Do you want to build reliable network services with Rust?
Then Tokio is something you should check out, try out the new 0.3 release here:
https://github.com/tokio-rs/tokio/releases/tag/tokio-0.3.1
In this episode we also cover:
slowing down syscalls to protect against Spectre
async syscalls with io-uring
building high-performance systems with non-blocking sockets
writing code without syscalls
getting started with Tokio
async operating system api's
how to start coding with tokio
External links:
https://doc.rust-lang.org/stable/rust-by-example/
https://discord.gg/tokio
https://tokio.rs/
https://twitter.com/carllerche
https://github.com/tokio-rs/
https://github.com/tokio-rs/io-uring
https://blogs.oracle.com/linux/an-introduction-to-the-io_uring-asynchronous-io-framework
https://www.howtogeek.com/338269/a-huge-intel-security-hole-could-slow-down-your-pc-soon/
https://www.rustaceans.org/
https://rust-lang.github.io/async-book/
https://github.com/tokio-rs/mini-redis
https://pop.system76.com/
https://rust-analyzer.github.io/
https://en.wikipedia.org/wiki/Epoll
https://twitter.com/tokio_rs
https://github.com/carllerche
Podcast sponsorship advertising
Start advertising on Security Headlines relevant audience podcasts
You may also like to advertise on these Podcasts

4.71563727
The Side Hustle Show
Nick Loper of Side Hustle Nation | YAP Media

4.76207441
Tides of History
Audible / Patrick Wyman

4.7204310
The Startup Ideas Podcast
Greg Isenberg

4.5423228
The Other Side NDE (Near Death Experiences)
MWW Productions, Bleav

4.72954475
Expanded Perspectives
Expanded Perspectives

4.920769
The Horse First: A Veterinary Sport Horse Podcast
Audrey DeClue, DVM

59574
Filter Stories - Coffee Documentaries
James Harper

4.8187538
Total Party Kill
The Incomparable Dungeon Masters

4.7388509
RealLife English: Learn and Speak Confident, Natural English
RealLife English

4.722881332
Menace2Sports with Zach Smith
Menace 2 Sports with Zach Smith