1562237108
Security Serengeti

Advertise on podcast: Security Serengeti

Rating
★★★★★
5
from
1 reviews
This podcast has
25 episodes
Language
English
Date created
2021/04/08
Latest episode
2024/02/26
Average duration
53 min.
Release period
14 days

Description

A news analysis focused information security podcast dedicated to getting you the actionable information and analysis you need to improve your company's posture and response!

Unlock Security Serengeti podcast Email contact info,
Listeners & Audience details

Email contact information

Direct podcast contact details

Listeners

Audience numbers & engagement insights

Audience details

Podcast Insights

Podcast episodes

Check latest episodes from Security Serengeti podcast


SS-RPRT-137: The Blue Report
2024/02/26
This week we take a look at the Picus Security Blue Report, and provide some analysis of the statements.  Interesting findings here.  The report was reasonably short, so we also discussed the recent documents leak from the Chinese contractor iSoon, and a surprise article on autonomous drones! Article 1 - THE BLUE REPORT 2023Supporting Articles:SS-RPRT-103: The Red Report 2023 Article 2 - An online dump of Chinese hacking documents offers a rare window into pervasive state surveillanceSupporting Articles:@[email protected] Article 3 - Former Google CEO Gets Into the AI-Powered Kamikaze Drone Business With ‘White Stork’Supporting Articles:CW - Soldier Killed by Kamikaze DroneHorror Short Film - Slaughterbots If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-RPRT-136: 2024 Security Predictions
2024/02/12
This week we take a look at 2024 Security Predictions.  We found a summary article that listed 24 other companies predictions for the coming year, and we took a look and picked out the most interesting ones.  Then we completed the podcast with some of our own predictions! Article - The Top 24 Security Predictions for 2024 If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-NEWS-135: Atlas of Surveillance and the MOAB
2024/01/29
This week we discuss the expansion of the EFF's Atlas of Surveillance, the Mother of all Breaches (not to be mistaken with the Mother of all Bombs), and AI Sleeper Agents that are going to eventually surround us all. Article 1 - EFF adds Street Surveillance Hub so Americans can check who's checking on themSupporting Articles:Atlas of SurveillanceRing will no longer allow police to request users' doorbell camera footageLicense plate readers used by repo businesses in the Valley Article 2 - ‘Mother of all breaches’ uncovered after 26 billion records leakedSupporting Articles:Mother of all breaches reveals 26 billion records: what we know so farCheck if your data has been leaked Article 3 - AI Sleeper Agents If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-NEWS-134: Blockchain Serving Lawsuits, SEC Twitter Security
2024/01/16
This week we discuss serving lawsuits using the Blockchain, the SEC's poor Twitter security practices, LLM's as bug hunters, and an update to the 23andMe saga! Article 1 - Here’s Some Bitcoin: Oh, and You’ve Been Served!Supporting Articles:email-on-blockchainCourt Grills Government Over $86M FBI Raid On Security Deposit Boxes Article 2 - After hack, X claims SEC failed to use two-factor authenticationSupporting Articles:Capacity Enhancement Guide Article 3 - How AI hallucinations are making bug hunting harder Article 4 - 23andMe blames “negligent” breach victims, says it’s their own fault If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-DISC-133: Modern SOC
2024/01/01
This week David and Matthew sit down to discuss Modern SOC, as defined by Netflix, Facebook, Meta (and more!), and described by Anton Chuvakin.   We talk about what constitutes "SOC Classic" and "New SOC", some pros and cons, and finally, a 6 step mid-level plan (over a couple of years) to get there.   Original Article that sparked the conversation - WTH is Modern SOC, Part 1 We HIGHLY recommend reading the article and the many, many, internal links.  There's an enormous amount of information behind that single link. If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-NEWS-132: AI Drones, OAuth Abuse, and 23andMe!
2023/12/18
This week we discuss Microsoft shutting down a bot network that created millions of fraudulent accounts, the coming AI Drone Overlords, OAuth Abuse, and 23andMe losing 5.5 million folks genetic information. Article 1 - Microsoft seizes infrastructure of top cybercrime groupSupporting Articles:Disrupting the gateway services to cybercrime Article 2 - A.I.-controlled killer drones become realitySupporting Articles:Kill Decision by Daniel Suarez Article 3 - Threat actors misuse OAuth applications to automate financially driven attacks Article 4 - 23andMe says, er, actually some genetic and health data might have been accessed in recent breach If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-DISC-131: Custom GPT's for Security
2023/12/06
This week we did something a little different.  There's been a list of Security GPT's that's been making the rounds, so we tested a few of them, and checked out the custom GPT creation functionality, and tried to create a custom SerengetiSecGPT to provide information about the podcast! Links:Awesome GPTs (Agents) for CybersecurityIntroducing GPTs   If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-NEWS-130: Skills Shortage and Ransomware reports to SEC
2023/11/20
This week we talk about a Ransomware gang reporting a victim to the SEC, the CyberSecurity Skills shortage is not what it seems to be, and the disconnect between Threat Intelligence and Detection Engineering. Late breaking news article about Microsoft Defender for Endpoint adding Deception Article 1 - Ransomware gang files SEC complaint over victim’s undisclosed breach Article 2 - A Simple SOAR Adoption Maturity Model Article 3 - Cybersecurity talent shortage: not the lack of people, but the lack of the right people Article 4 - Frameworks for DE-Friendly CTI (Part 5) If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-NEWS-129: Solarwinds CISO Charged, AI Executive Order
2023/11/07
We had originally planned on a discussion about Threat Intel AI this week, but after some discussions with a few vendors, I don't think that the current "state of the art" is worth discussing yet.  Still Alpha products. So instead, there were a couple of really big announcements this week, so we discuss those in some depth.  We will get back to Threat Intel next episode!  Article 1 - SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control FailuresSupporting Articles:SEC sues SolarWinds and CISO, says they ignored flaws that led to major hack Article 2 - FACT SHEET: President Biden Issues Executive Order on Safe, Secure, and Trustworthy Artificial IntelligenceSupporting Articles:Cyber pros praise Biden executive order on artificial intelligenceEliezer Yudkowsky on the Dangers of AIYour phone vs. SupercomputersWhy Biden’s AI Executive Order Only Goes So Far If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-NEWS-128: AI Cipher Unsafe, SOC Heroes, and Malware on the Blockchain!
2023/10/23
This week we discuss Malware stored on the Blockchain (coming soon to a theater near you!), how to stop Heroes in your SOC (common discussion topic amongst villains!), US Gov requesting governments stop paying ransoms, and a slightly over excited paper on using ciphers to bypass alignment restrictions in LLMs.   I actually personally found the language issues introduced by chatting with LLMs in ciphertext more interesting personally, but... Article 1 - The Fake Browser Update Scam Gets a Makeover Article 2 - How to Banish Heroes from Your SOC?Supporting Articles:Does Your Company Lurch from Crisis to Crisis?Delivering Security at Scale: From Artisanal to Industrial6 ways to keep your top performers from jumping ship Article 3 - The US wants governments to commit to not paying ransoms Article 4 - GPT-4 IS TOO SMART TO BE SAFE: STEALTHY CHAT WITH LLMS VIA CIPHERSupporting Articles:Manna: Two Visions of Humanity's Future If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-BOOK-127: Avogadro Corp
2023/10/09
This week we discuss Avogadro Corp - The Singularity is Closer Than You Think.  This book, written in 2011, was very prescient, and predicted a number of things that AI seems capable of, or on the cusp of, doing.  We re-read the book, and go through some security related discussions on how to prevent the corporate takeover that occurs in the book, and then talk about the most and least believable capabilities of ELOPe.  Spoilers abound, but we tried to stay away from them.  If you truly care about spoilers, read the book first! Supporting Articles: Amazon.com - Avogadro Corp: The Singularity is Closer Than It AppearsIntroducing Microsoft 365 CopilotOpenAI Chat GPT Solved Problem with TaskRabbit - Business Insider ArticleHow Many Emails are Sent Per Day - Zippia ArticleNumber of Text Messages in the United States - Statista Article If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
SS-NEWS-126: Hackers as Insider Traders and AI Study on Effectiveness
2023/09/25
Title 1: Russian infosec boss gets nine years for $100M insider-trading caper using stolen data Summary: Vladislav Klyushin, owner of Russian firm M-13, was sentenced to nine years in the US for stealing corporate financial data and making $93 million through insider trading. He was only arrested because he flew to Switzerland for a Family Holiday. His four co-conspirators are still out there, probably still hacking. Supporting Articles: US Justice Department Article SEC Complaint Document ZDNet Article on SEC Data Breach Title 2: FBI, CISA Issue Joint Warning on 'Snatch' Ransomware-as-a-Service Summary: The FBI and CISA issue an advisory on the Snatch ransomware-as-a-service operation, highlighting its targeting of critical infrastructures and unique ability to force Windows systems to reboot in Safe Mode, evading antivirus detection. Supporting Articles: DarkReading Article Title 3: Retool blames breach on Google Authenticator MFA cloud sync feature Summary: Retool suffered a security breach after attackers compromised 27 cloud accounts through social engineering, exploiting a new Google Authenticator feature. This breach may be linked to the theft of $15 million from Fortress Trust. Supporting Articles: ArsTechnica Article Title 4: Centaurs and Cyborgs on the Jagged Frontier Summary: Wharton School of Business partnered with BCG to conduct an experiment on the efficiency of consultants using ChatGPT 4. AI-assisted tasks were completed faster and rated higher. The impact varied based on skill level, and the article discusses the implications of AI in the workforce. If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

Podcast reviews

Read Security Serengeti podcast reviews


5 out of 5
1 reviews

Podcast sponsorship advertising

Start advertising on Security Serengeti relevant audience podcasts


What do you want to promote?