BrakeSec Education Podcast

Bryan Brake, Amanda Berlin, and Brian Boettcher

About

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Available on

Community

464 episodes

p2-accidentalCISO, building trust in new places

  Full Youtube VOD: https://www.youtube.com/watch?v=uX7odQTBkyQ      Questions and topics: __ __ __ __ Additional information / pertinent LInks (Would you like to know more?): __ __ Show points of Contact: Amanda Berlin: @infosystir @hackershealth  Brian Boettcher: @boettcherpwned Bryan Brake: https://linkedin.com/in/brakeb  Brakesec Website: https://www.brakeingsecurity.com Youtube channel: https://youtube.com/@brakeseced Twitch Channel: https://twitch.tv/brakesec

1h 13m
Feb 13, 2024
AccidentalCISO on BrakeSecEd, talking Leadership, SaaS development, and Appsec

Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time based on new information, and do not represent views of past, present, or future employers.   Recorded: 28 Jan 2024 Youtube VOD: https://youtube.com/live/uX7odQTBkyQ Questions and topics: __ __ __ __ Additional information / pertinent LInks (Would you like to know more?): __ __ Show points of Contact: Amanda Berlin: @infosystir @hackershealth  Brian Boettcher: @boettcherpwned Bryan Brake: https://linkedin.com/in/brakeb  Brakesec Website: https://www.brakeingsecurity.com Youtube channel: https://youtube.com/@brakeseced Twitch Channel: https://twitch.tv/brakesec

29m
Feb 02, 2024
1st show of 2024! Our 10th Anniversary...

It's our 10th anniversary and the first show of our 2024 season! Amanda was on "7 minute security" https://7minsec.com/projects/podcast   Check out the complete VOD at https://youtu.be/vbmEtkxhAMg   www.brakeingsecurity.com https://twitch.tv/brakesec https://bit.ly/brakesecyt  

59m
Jan 09, 2024
Brakesec Call to Action 2023

Youtube Video:  https://youtu.be/IUDPlQaQg8M https://forms.gle/rf145MoN7cskwMjf8   is the link to the survey. Your information (should you choose to identify yourself) will not be shared outside of the BrakeSec Team. Thank all of you for listening and for your input. RSS feed for the audio podcast is at https://www.brakeingsecurity.com/rss  website: https://www.brakeingsecurity.com 

2m
Dec 18, 2023
How to get more headcount, BLUFFs Vulnerability, and Ranty Clause debuts!

Show Topic Summary: Ms. Berlin proposes a question of how to gather more headcount with metrics, we discuss the BLUFFS bluetooth vulnerability, and “Ranty Claus” talks about CISA’s remarks of putting the onus on device product makers to remove choice for customers and implement secure defaults. #youtube VOD: https://www.youtube.com/watch?v=emcAzTx9z0c  Questions and topics: __ __ Additional information / pertinent LInks (Would you like to know more?): __ __ Show points of Contact: Amanda Berlin: @infosystir @hackershealth  Brian Boettcher: @boettcherpwned Bryan Brake: @bryanbrake on Mastodon.social, https://linkedin.com/in/brakeb  Brakesec Website: https://www.brakeingsecurity.com Twitter: @brakesec  Youtube channel: https://youtube.com/c/BDSPodcast Twitch Channel: https://twitch.tv/brakesec

1h 19m
Dec 04, 2023
25Oct - okta breached (again), Energy company hit by supply chain attack, and you can help hire the best people

Subscribe on Twitch using Amazon Prime and watch us live: https://twitch.tv/brakesec Check out our VODs on Youtube: https://www.youtube.com/@BrakeSecEd  Join the BrakeSecEd discord: https://discord.gg/brakesec    News: https://www.darkreading.com/remote-workforce/1password-latest-victim-okta-customer-service-breach https://www.documentcloud.org/documents/24075435-bhi-notice https://www.bleepingcomputer.com/news/security/us-energy-firm-shares-how-akira-ransomware-hacked-its-systems/ https://www.bleepingcomputer.com/news/security/ransomware-isnt-going-away-the-problem-is-only-getting-worse/ https://www.shacknews.com/article/137505/ransomware-group-capcom-2020-arrested https://www.bleepingcomputer.com/news/security/flipper-zero-can-now-spam-android-windows-users-with-bluetooth-alerts/ https://www.nasdaq.com/articles/three-cybersecurity-sectors-that-resist-economic-downturns  

45m
Oct 26, 2023
NIcole Sundin - CPO at Axio - SEC compliance, usable security, setting up risk mgmt programs

Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers.   Guest Bio:  Nicole is the Chief Product Officer at Axio. Nicole has spent her career building awareness around the benefits of usable security and human-centered security as a way to increase company revenue and create a seamless user experience.   Youtube VOD Link: https://youtube.com/live/tFaAB9an47g   Questions and topics: __ __   Additional Links: https://csrc.nist.gov/CSRC/media/Projects/usable-cybersecurity/images-media/Is%20Usable%20Security%20an%20Oxymoron.pdf  http://web.mit.edu/Saltzer/www/publications/protection/Basic.html  https://www.sec.gov/news/press-release/2023-139  https://www.sec.gov/news/statement/munter-statement-assessing-materiality-030922  https://www.pwc.com/us/en/services/consulting/cybersecurity-risk-regulatory/sec-final-cybersecurity-disclosure-rules.html  https://www.nasa.gov/centers/ames/research/technology-onepagers/hc-computing.html  https://securityscorecard.com/blog/what-is-cyber-security-performance-management/  

1h 6m
Sep 23, 2023
John Aron, letters of marque, what does a "junior" job look like with AI?

Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers.   Guest Bio: John is the CEO of Aronetics. An avid climber and runner, John has spoken at many conferences about topics like ZeroTrust, BIOS/UEFI security, communication security, and malware. Aronetics is a technology-enabled service provider.    Youtube VOD: https://youtube.com/live/5dIVTwVZLAU Linkedin VOD: https://www.linkedin.com/video/live/urn:li:ugcPost:7101738254823030784 Show Topic Summary:   John joins us to discuss “letters of Marque” in an effort for hackers to ‘hack back’... the overreliance on automation, and communication siloes. We also talk about what a ‘junior position’ in infosec looks like with AI doing all the “Level 1 SOC Analyst” type roles normally given to someone fresh to the security industry.   Questions and topics: __ __ __ __ __   Aronetics’ Thor provides defense and counter-offense tamper-proof technology digitally tied to    Letter of Marque - good idea, or geopolitical disaster waiting to happen? Siloes and communication -best ways to overcome those in an org and outside? How do we overcome siloing?   Overcoming security challenges?Identity management - 2FA is everywhere, there’s already ways around 2FA, so what now? 3FA? Biometrics? Make everyone carry around physical tokens that we can lose?   Blog post: https://www.aronetics.com/post-quantum-cryptography/ What do we need to protect against? Nation states with quantum computers? Rubber hose cryptography?   Crime thrives in areas of low visibility. https://www.aronetics.com/unknown/    https://www.aronetics.com/inside-the-breach/ (threat detection - the crime thrives in low vis areas)   Show points of Contact: Brakesec Website: https://www.brakeingsecurity.com Youtube channel: https://youtube.com/c/BDSPodcast Twitch Channel: https://twitch.tv/brakesec Amanda Berlin: @infosystir@infosec.exchange (Mastodon) @hackershealth  Brian Boettcher: @boettcherpwned Bryan Brake: @bryanbrake on Mastodon.social

1h 25m
Sep 03, 2023
Megan Roddie - co-author of "Practical Threat Detecion Engineering"

Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time, and do not represent views of past, present, or future employers. Buy here: https://subscription.packtpub.com/book/security/9781801076715 Amazon Link: https://packt.link/megan Youtube VOD: https://www.youtube.com/watch?v=p1_jQa9OQ2w   Show Topic Summary: Megan Roddie is currently working as a Senior Security Engineer at IBM. Along with her work at IBM, she works with the SANS Institute as a co-author of FOR509, presents regularly at security conferences, and serves as CFO of Mental Health Hackers. Megan has two Master's degrees, one in Digital Forensics and the other in Information Security Engineering, along with many industry certifications in a wide range of specialties. When Megan is not fighting cybercrime, she is an active competitor in Muay Thai/Kickboxing. She is a co-author of “Practical Threat Detection Engineering” from Packt publishing, on sale now in print and e-book. Buy here: https://subscription.packtpub.com/book/security/9781801076715   https://packt.link/megan ← Amazon redirect link that publisher uses if you want something easier on the notes   Questions and topics: __ __ Additional information / pertinent LInks (Would you like to know more?): __ __ Show points of Contact: Amanda Berlin: @infosystir @hackershealth  Brian Boettcher: @boettcherpwned Bryan Brake: @bryanbrake on Mastodon.social, Twitter, bluesky Brakesec Website: https://www.brakeingsecurity.com Twitter: @brakesec  Youtube channel: https://youtube.com/c/BDSPodcast Twitch Channel: https://twitch.tv/brakesec

1h 46m
Aug 25, 2023
meeting new people, walking on your keyboard causes issues, even google gets phone numbers wrong.

Check out our sponsor (BLUMIRA) at https://blumira.com/brake youtube channel link: https://youtube.com/c/BDSPodcast Full video on our youtube Channel! https://www.youtube.com/watch?v=BkBeLuM_urk https://www.rapid7.com/blog/post/2023/07/11/cve-2023-29298-adobe-coldfusion-access-control-bypass/ https://www.darkreading.com/remote-workforce/hacker-infected-foiled-by-own-infostealer https://therecord.media/cisa-warnings-adobe-microsoft-citrix-vulnerabilities https://www.itsecurityguru.org/2023/07/18/millions-of-keyboard-walk-patterns-found-in-compromised-passwords/ https://therecord.media/airline-customer-support-phone-number-fraud-google https://twitter.com/Shmuli/status/1680669938468499458 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 https://www.jdsupra.com/legalnews/tabletop-exercises-as-risk-mitigation-5278057/ https://www.darkreading.com/vulnerabilities-threats/linux-ransomware-poses-significant-threat-to-critical-infrastructure https://bevyengine.org/  - Rust game engine https://godotengine.org/ - a more mature Rust game engine https://flappybird.io/ - which I suck at, BTW Intro/outro music: "Flex" by Jeremy Blake Courtesy of YouTube Music Library (used with proper permissions)  

1h 20m
Jul 21, 2023
Bsides Seattle and Austin, SecureBoot patch, and more

BrakeSec Show Outline – No Guest   * ------------------------- -------------------------   Youtube VOD: https://youtube.com/live/UGRaRSYj7kc    * ------------------------- __ __ __ __ __ __ __ __ -------------------------   * ------------------------- -------------------------   * ------------------------- -------------------------  

1h 12m
May 27, 2023
lynsey wolf, conducting insider threat investigations, CASB and UEBA utlization to good use.

* ------------------------- -------------------------   * ------------------------- __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ -------------------------   * ------------------------- -------------------------   * ------------------------- -------------------------

1h 34m
Apr 30, 2023
3CX supply chain attack, Mark Russinovich and Sysinternals, CISA ransomware notifications, and emotional intelligence

* ------------------------- ------------------------- Youtube VOD: https://www.youtube.com/watch?v=afZHiBUr-2g  * ------------------------- __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ __ -------------------------   * ------------------------- -------------------------   * ------------------------- -------------------------

1h 24m
Apr 08, 2023
Dish Network is still busted, John Deere avoiding OSS requests, Is DAST dead?

* ------------------------- -------------------------   * ------------------------- __ __ __ __ __ __ __ __ __ __ __ __ __ __ -------------------------   * ------------------------- -------------------------   * ------------------------- -------------------------

1h 29m
Mar 24, 2023
Nickolas Means talks about Security, Devops velocity, blameless orgs, and conferences infosec should attend

  * ------------------------- -------------------------   * ------------------------- -------------------------   * ------------------------- __ __ __ __ __ __ __ __ __ __ -------------------------   * ------------------------- -------------------------   * ------------------------- -------------------------  

1h 14m
Mar 04, 2023
SPECIAL INTERVIEW: John Aron and Jerod Brennen

BrakeSec Show Outline (all links valid as of 27 Jan 2023, subject to change)   * ------------------------- -------------------------   * ------------------------- -------------------------   * ------------------------- -------------------------   * ------------------------- -------------------------   * ------------------------- __ __ __ __ __ __ __ __ __ __ __ __ __ __ -------------------------   * ------------------------- ------------------------- * ------------------------- -------------------------  

1h 21m
Feb 10, 2023
Layoff discussions, another TMO breach, OneNote Malware, and more!

------------------------- ------------------------- Full youtube video: https://www.youtube.com/watch?v=1Dgq8FpnWPw   ------------------------- -------------------------   ------------------------- -------------------------   ------------------------- -------------------------

1h 23m
Jan 24, 2023
GPS car hacks, Google Threat report, notable topics of 2020, satellite threat modelling, twitter breach(?)

------------------------- __ __ __ __ __ __ __ __ __ __ __ __ -------------------------   ------------------------- -------------------------   ------------------------- -------------------------

1h 25m
Jan 10, 2023
Josh-Whalen-risk-management-data_visualization-tools, value-creating activities -p2

Full stream video on Youtube: https://youtu.be/i1xpAfNFCvY John's Youtube channel, to find more training/contact information: https://www.youtube.com/channel/UC3ctyx980M8jLa_cEiQveLQ https://en.wikipedia.org/wiki/Capability_Maturity_Model_Integration ADKAR model: https://www.prosci.com/methodology/adkar CCE framework: https://inl.gov/cce/ Dashboard (non-sponsored link): https://monday.com Diagrammming tool: https://figma.com https://www.sciencedirect.com/topics/computer-science/system-analysis Amazon book: https://www.amazon.com/Engineering-Safer-World-Systems-Thinking/dp/0262533693

1h 7m
Dec 20, 2022
John Whalen, data visualization tools, risk management, handling org risk-p1

Full stream video on Youtube: https://youtu.be/i1xpAfNFCvY   https://en.wikipedia.org/wiki/Capability_Maturity_Model_Integration ADKAR model: https://www.prosci.com/methodology/adkar CCE framework: https://inl.gov/cce/ Dashboard (non-sponsored link): https://monday.com Diagrammming tool: https://figma.com https://www.sciencedirect.com/topics/computer-science/system-analysis Amazon book: https://www.amazon.com/Engineering-Safer-World-Systems-Thinking/dp/0262533693  

37m
Dec 11, 2022
Interview with Infrared - one of the Seattle Community Network organizers

https://youtu.be/iW39Mugj4OM  -Full stream video (interview starts at 28m22s)   Broadcasted live on Twitch -- Watch live at https://www.twitch.tv/brakesec Seattle Community Network - https://seattlecommunitynetwork.org/ https://medium.com/seattle-community-network/ 

52m
Nov 22, 2022
JAMBOREE - an Android App testing platform from @operat0r -part2

introducing @operat0r talked a bit about mobile device hacking and rooting/jailbreaking phones for testing Grab the powershell script here: https://github.com/freeload101/Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy   Check out the Youtube videos, including demo! Part2 is here: https://www.youtube.com/watch?v=RXgwUWpRuYA

1h 4m
Nov 07, 2022
JAMBOREE - an Android App testing platform from @operat0r

introducing @operat0r talked a bit about mobile device hacking and rooting/jailbreaking phones for testing Grab the powershell script here: https://github.com/freeload101/Java-Android-Magisk-Burp-Objection-Root-Emulator-Easy   Check out the Youtube videos, including demo! Part 2 will be available soon! Part 1:  https://youtu.be/U5SFav9h1L4 

13m
Oct 30, 2022
07-oct-news-twitch streaming

https://www.bnbchain.org/en/blog/bnb-chain-ecosystem-update/ https://medium.com/@johnblatt23/uber-hack-reveals-weakness-in-the-human-firewall-8b44a87d43b4 https://securityintelligence.com/articles/what-to-know-honda-key-fob-vulnerability/ https://www.theregister.com/2022/10/07/binance_hack_566m/ https://www.bnbchain.org/en/blog/bnb-chain-ecosystem-update/ https://www.bbc.com/news/business-58193396 https://www.theverge.com/2022/4/18/23030754/beanstalk-cryptocurrency-hack-182-million-dao-voting https://www.coindesk.com/business/2022/10/06/celsius-top-execs-cashed-out-17m-in-crypto-before-bankruptcy/ https://jpgormally.medium.com/cybersecurity-is-a-successfully-failure-9bcf92a1bc88 https://www.bitsight.com/blog/zero-50k-infections-pseudomanuscrypt-sinkholing-part-1  

54m
Oct 12, 2022
Uber Breach, MFA fatigue, who can help communicate biz risk?

https://www.theverge.com/2022/9/16/23356213/uber-hack-teen-slack-google-cloud-credentials-powershell https://www.zdnet.com/article/uber-security-breach-looks-bad-potentially-compromising-all-systems/ https://twitter.com/RachelTobac/status/1571542949606957057   Twitter: @boettcherpwned @infosystir @brakeSec @bryanbrake www.brakeingsecurity.com Twitch: https://twitch.tv/brakesec  

1h 9m
Sep 19, 2022
Manual Code reviews/analysis, post-infosec Campout discussion

checkout our website: https://www.brakeingsecurity.com Follow and subscribe with your Amazon Prime account to our Twitch stream: https://twitch.tv/brakesec   Twitter: @infosystir @boettcherpwned @bryanbrake @brakesec Find us on all your favorite podcast platforms! Please leave us a 5 star review to help us grow!

1h 0m
Sep 02, 2022
Amanda's Sysmon Talk -p2

Part 2 of our discussion this week with Amanda, Brian, and Bryan on sysmon, We discuss use cases from her talk, and best ways to get sysmon integrated into your environment.   BrakeSec is: Amanda Berlin @infosystir Brian Boettcher @boettcherpwned Bryan Brake @bryanbrake https://www.brakeingsecurity.com https://www.brakeingsecurity.com/   Our #twitch stream can be found at: Https://twitch.tv/brakesec https://twitch.tv/brakesec (subscription is req'd to see full videos)

42m
Aug 15, 2022
Amanda's Sysmon Talk -p1

This week Amanda, Brian, and Bryan discuss sysmon, how it works to detect IOCs in your org, and how it extends beyond regular Windows event monitoring.   oh... and it's available for Linux too! BrakeSec is: Amanda Berlin @infosystir Brian Boettcher @boettcherpwned Bryan Brake @bryanbrake https://www.brakeingsecurity.com   Our #twitch stream can be found at: Https://twitch.tv/brakesec (subscription is req'd to see full videos)

37m
Aug 07, 2022
Tanya Janca, Securing APIs, finding Security Champions, and accepting Risk

Tanya Janca, also known as @SheHacksPurple, is the best-selling author of ‘Alice and Bob Learn Application Security https://aliceandboblearn.com/’. She is also the founder of We Hack Purple, an online learning academy, community and podcast that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over twenty years, won countless awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, & Nokia). She has worn many hats; startup founder, pentester, CISO, AppSec Engineer, and software developer. She is an award-winning public speaker, active blogger & streamer and has delivered hundreds of talks and trainings on 6 continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives. https://wehackpurple.com   BrakeSec is: Amanda Berlin @infosystir Brian Boettcher @boettcherpwned Bryan Brake @bryanbrake www.brakeingsecurity.com https://twitch.tv/brakesec  

41m
Jul 30, 2022
Tanya Janca on secure coding practices, Swagger docs, and why documentation matters

Tanya Janca, also known as @SheHacksPurple, is the best-selling author of ‘Alice and Bob Learn Application Security https://aliceandboblearn.com/’. She is also the founder of We Hack Purple, an online learning academy, community and podcast that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over twenty years, won countless awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, & Nokia). She has worn many hats; startup founder, pentester, CISO, AppSec Engineer, and software developer. She is an award-winning public speaker, active blogger & streamer and has delivered hundreds of talks and trainings on 6 continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives.   https://shehackspurple.ca/   BrakeSec is: Amanda Berlin @infosystir Brian Boettcher @boettcherpwned Bryan Brake @bryanbrake www.brakeingsecurity.com

39m
Jul 24, 2022