- 1 Paul's Security Weekly - Episode 491
- 2 Announcements
- 3 Interview: John Hurd and Alex Valdivia, ThreatConnect - 6:00-7:00PM
- 4 Technical Segment: Jimmy Mesta, Containerizing your Security Operations Center - 7:00PM-7:30PM
- 5 Security News - 7:30PM-8:30PM
Paul's Security Weekly - Episode 491
This week John Hurd and Alex Valdivia from ThreatConnect join us for an update on some interesting threat intelligence topics, our technical segment tonight will be with Jimmy Mesta on Containerizing your Security Operations Center. In the security news discussion for the week a new Mirai worm takes out German ISP customers, Raspbian tries to lock down their platform, silent fixes from Microsoft, MUNI eats it, Russians spread election-related propaganda, and we'll discuss Rule 41, the one that has nothing to do with sexual fetishes, well maybe... All that AND more on this edition of Paul's Security Weekly. Recorded: December 1, 2016
- Jeffrey Man - Cryptanalyst, infosec analyst, pioneering ex-NSA pen tester, PCI specialist and certified security curmudgeon
- Jack Daniel - Works for Tenable Network Security and is a co-founder of Security BSides.
- Larry Pesce, Director of Research and Senior Managing Consultant at InGuardians
- Larry Pesce, Swami of Security, Oracle of the Online and Hotshot Of Hacking
- Larry Pesce, destroyer of embedded systems and injector of RF energy.
- Michael Santarcangelo - founder of SecurityCatalyst.com, author of Into the Breach, and creator of the leadership-driven Straight Talk Framework - with our favorite question, "What problem are you trying to solve?"
- Joff Thyer - SANS Instructor, Penetration Tester and Security Researcher with Black Hills Information Security.
- Joff Thyer, Geeking out with the best of them. Known to attract multiple waitresses with a single smile and utterance of g'day. Deployer of cocktail recipes in desperate situations. Hacker of many a thing! If it's got code running on it, it can be hacked.
- Joff Thyer, musician, proud father, and friend to many.
- Paul Asadoorian - He is a male who is extremely charming in manner because of his gentlemanly behavior. He has good looks and thinks that women are better than men. He also has a high pain tolerance and likes it kinky.
- Make sure you visit http://securityweekly.com/subscribe and subscribe to our new shows including Enterprise Security Weekly and Startup Security Weekly. You can also subscribe to all shows individually, as well as a main feed which contains this show, Hack Naked TV and Enterprise Security Weekly.
- Take our super cool survey! http://www.securityweekly.com/survey
Interview: John Hurd and Alex Valdivia, ThreatConnect - 6:00-7:00PM
- John Hurd and Alex Valdivia
John Hurd is an Intelligence Research Analyst. Alex Valdivia is a Threat Intel Researcher. Together they are part of the ThreatConnect team. They know what it takes to work at the front lines of cyber defense. They know that they’re stronger together than we are apart. They're strategic business thinkers. Since 2011, ThreatConnect has led the threat intelligence revolution, building the industry’s most comprehensive threat intelligence platform along with its largest trusted cybersecurity community.
discuss our platform, our research team, and/or recent findings of interest by our team
- Three words to describe yourself
- If you were a serial killer, what would be your weapon of choice?
- If you wrote a book about yourself, what would the title be?
- In the popular game of ass grabby-grabby, do you prefer to go first or second?
- Choose two celebrities to be your parents.
Technical Segment: Jimmy Mesta, Containerizing your Security Operations Center - 7:00PM-7:30PM
Jimmy Mesta is an application security leader that has been involved in Information Security for nearly 10 years. He is the chapter leader of OWASP Santa Barbara and co-organizer of the AppSec California security conference. Jimmy has spent time on both the offense and defense side of the industry and is constantly working towards building modern, developer-friendly security solutions. His core focus has been in application and cloud security with an emphasis on secure architecture, automated testing, developer training and defensive techniques.
Security News - 7:30PM-8:30PM
- New Mirai Worm Knocks 900K Germans Offline
- A security update for Raspbian PIXEL - Raspberry Pi
- Microsoft Silently Fixes Kernel Bug That Led to Chrome Sandbox Bypass
- Who Hacked The Lights In Ukraine?
- 'Dronejacking' may be the next big cyber threat
- Microsoft Azure Flaw Exposed RHEL Virtual Machines to Hacking Risk
- Shamoon wiper malware returns with a vengeance
- Firefox Patched for Zero-Day Vulnerability
- Can We Please Stop Pretending Car Hacking Is a Grave Threat? - The Drive
- Senators Make Last-Ditch Attempt To Block Expanded Government Hacking Authority
- Protocol96 | Bugtraq: SEC Consult SA-20161128-0 :: DoS & heap-based buffer overflow in Guidance Software EnCase Forensic
- Mirai Botnet Knocks Out Deutsche Telekom Routers
- Information Security: The Reporting Line of the CISO is Key to Success
- Windows Malware Infections Spiked 106% From Black Friday To Cyber Monday
- Why Credentials Are 'The New Perimeter'
- Comma OpenPilot released opensource
- Calendar invite iCloud spam
- San Francisco MUNI hacked
- Mirai gets some upgrades
- PyExifil, Puthon for data Exfil
- Reverse Engineering TDDP in TP-Link routers for shell
- The US government says there is no cybersecurity skills shortage contradicting most of the common wisdom.
- Rule 41 it's OK, I'm sure this won't be abused.
- The Saudis seem to be under "cyberattack" again although the details are not really details yet.
- A great post on health and wellness in infosec from Lesley Carhart (aka @hacks4pancakes)
- Time is running out for NTP. NTP is overworked and underfunded, and critical. Not a good combo.
- tumblr starts encrypting blogs by default thanks to @Aloria.
- Russian Propaganda Effort Helped Spread 'Fake News' During Election, Experts Say
- The Propaganda About Russian Propaganda
Comment from a friend: "a colleague of mine at the University of Maryland, is a Professor of Practice in the School of Journalism and continues to write for the Post. The Post suspects that there is an organized effort by unnamed Russian “operatives" to flood the comments sections attached to political reporting. The suspicion arises out of certain patterns of language that the Post's Russian speaking correspondents allege is likely to come from a native Russian speaker."