Player FM - Internet Radio Done Right
Checked 3d ago
הוסף לפני five שנים
תוכן מסופק על ידי Breaking Badness. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Breaking Badness או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
Player FM - אפליקציית פודקאסט
התחל במצב לא מקוון עם האפליקציה Player FM !
התחל במצב לא מקוון עם האפליקציה Player FM !
Inside Morphing Meerkat and Proton66: How Cybercrime Is Getting Easier
Manage episode 479943334 series 2609238
תוכן מסופק על ידי Breaking Badness. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Breaking Badness או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
In this episode of Breaking Badness, the crew investigates two escalating threats in the cybercrime ecosystem: the cleverly named phishing-as-a-service platform Morphing Meerkat, and the bulletproof hosting provider Proton66, a favorite among amateur cybercriminals. First, they dig into how Morphing Meerkat uses DNS-over-HTTPS (DoH) and clever phishing kits to evade detection. Then, they shift focus to Proton66, a Russian-based bulletproof host that shelters a new generation of low-skill attackers, including a threat actor known as "Coquettte" with ties to the Horrid Hacking group.
…
continue reading
294 פרקים
Manage episode 479943334 series 2609238
תוכן מסופק על ידי Breaking Badness. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Breaking Badness או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
In this episode of Breaking Badness, the crew investigates two escalating threats in the cybercrime ecosystem: the cleverly named phishing-as-a-service platform Morphing Meerkat, and the bulletproof hosting provider Proton66, a favorite among amateur cybercriminals. First, they dig into how Morphing Meerkat uses DNS-over-HTTPS (DoH) and clever phishing kits to evade detection. Then, they shift focus to Proton66, a Russian-based bulletproof host that shelters a new generation of low-skill attackers, including a threat actor known as "Coquettte" with ties to the Horrid Hacking group.
…
continue reading
294 פרקים
All episodes
×
1 Inside Ransomware’s Supply Chain: Attribution, Rebrands, and Affiliate Betrayal 44:47
44:47
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:47
In this RSA Conference 2025 special episode, we explore two critical frontiers shaping the future of cybersecurity. First, Jon DiMaggio (Author of The Ransomware Diaries, Analyst1) breaks down the hidden supply chains behind ransomware gangs, including the economics of affiliate betrayal and the challenge of accurate attribution. He walks us through his methodology for identifying ransomware rebrands like BlackCat and RansomHub using evidence-based frameworks designed to eliminate human bias. Then we’re joined by Matt Radolec (VP of Incident Response at Varonis), who brings a fresh perspective on talent development in cybersecurity. Drawing from his keynote "From Gamer to Leader", Matt argues that gamers possess untapped potential as cybersecurity professionals and it’s time to design leadership pipelines like quest lines. From ransomware negotiations on underground forums to using AI-enhanced playbooks and transforming threat response teams into RPG-style guilds, this episode blends technical insight with cultural reflection.…

1 Beyond the Perimeter: How Attackers Use Domains, Phishing & AI and How to Fight Back 1:08:24
1:08:24
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:08:24
Welcome to a special RSAC 2025 episode of the Breaking Badness Cybersecurity Podcast! Today, we delve into the critical role of domains in modern cyber attacks. From sophisticated nation-state operations to AI-powered phishing kits and malicious browser extensions, domains are the foundational infrastructure for threat actors. Host Kali Fencl is joined by four leading cybersecurity experts Joe Slowik, Robert Duncan, John Fokker and Vivek Ramachandran to break down how domains are weaponized and what organizations can do to defend themselves on this ever-evolving frontline…
In this episode of Breaking Badness, we sit down with Raji Vannianathan, a cybersecurity leader at Microsoft driving the charge on AI security and safety. Raji shares her experience leading the team responsible for managing the end-to-end lifecycle of AI vulnerability disclosures, building proactive safety frameworks, and cultivating a global community of AI security researchers. From developing Microsoft's AI Bug Bar to launching the "Guardians of AI Safety" Discord community, she brings both vision and practical strategies to a rapidly evolving field. We discuss the shifting threat landscape as threat actors begin to leverage generative AI, the critical need for shared language and cross-functional collaboration, and how Microsoft is thinking about trust, transparency, and incident response in the AI era. If you’re navigating the challenges of AI risk, vulnerability coordination, or ethical deployment, this is an essential listen.…

1 Building Secure Campaigns and Better Humans: A Conversation with Mick Baccio 23:03
23:03
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי23:03
In this episode of Breaking Badness, Kali Fencl sits down with Mick Baccio, Global Security Advisor at Splunk and former CISO for Pete Buttigieg’s 2020 presidential campaign. Mick shares his journey from aspiring Navy nuclear engineer to leading security in some of the highest-stakes environments, including the White House. They explore how threat intelligence, storytelling, and mentorship shape the future of cybersecurity. From his early days in government to his work on the Splunk SURGe team, Mick opens up about what it takes to build secure systems, stronger teams, and more empathetic leadership in cybersecurity.…

1 Hacking the Stage: John Donovan on RSAC, BSides SF, and the Human Side of Cybersecurity 22:13
22:13
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי22:13
In this episode of Breaking Badness, we sit down with John Donovan of ZEDEDA to unpack the lighter and more profound sides of cybersecurity’s biggest gatherings. From RSA’s unexpected baby goats and vendor booth antics to BSides San Francisco’s community-driven keynote stage, John shares personal stories, industry insights, and valuable advice on how newcomers and veterans alike can navigate events like RSA, BSides, and DEF CON. You’ll hear how he "hacked" his way onto the main stage, what it means to wear a “No Purchasing Authority” pin, and why protecting your mom from scams might be more urgent than defending your enterprise.…

1 Inside Morphing Meerkat and Proton66: How Cybercrime Is Getting Easier 39:39
39:39
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:39
In this episode of Breaking Badness, the crew investigates two escalating threats in the cybercrime ecosystem: the cleverly named phishing-as-a-service platform Morphing Meerkat, and the bulletproof hosting provider Proton66, a favorite among amateur cybercriminals. First, they dig into how Morphing Meerkat uses DNS-over-HTTPS (DoH) and clever phishing kits to evade detection. Then, they shift focus to Proton66, a Russian-based bulletproof host that shelters a new generation of low-skill attackers, including a threat actor known as "Coquettte" with ties to the Horrid Hacking group.…

1 DFIR Foundations: Real-World Lessons in Containment, Eradication, and Recovery 54:45
54:45
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי54:45
In this powerful continuation of our DFIR series, cybersecurity experts Daniel Schwalbe, David Bianco, Lesley Carhart, and Sarah Sabotka dissect the heart of effective incident response, containment, eradication, recovery, and lessons learned. Packed with firsthand war stories, sharp tactical advice, and honest debates, this episode is a must-listen for anyone building or refining their digital forensics and incident response capabilities. Tune in to learn why planning matters, what to do (and not do) during a breach, and how to make the adversary's job harder, one containment plan at a time.…

1 DFIRside Chat: Lessons from the Frontlines of Incident Response 42:36
42:36
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:36
In Part 1 of this special two-part panel, the Breaking Badness podcast gathers leading cybersecurity experts to explore the foundations of DFIR - Digital Forensics and Incident Response. Featuring Daniel Schwalbe (DomainTools), Lesley Carhart (Dragos), David Bianco (Splunk), and Sarah Sabotka (Proofpoint), the panel dives into what makes an effective incident response program, why preparation is often overlooked, and how to bring technical and human elements together during high-stakes security events.…

1 How Russian Disinformation Campaigns Exploit Domain Registrars and AI 38:57
38:57
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:57
In this episode of Breaking Badness, host Kali Fencl is joined by DomainTools' Daniel Schwabe and disinformation expert Scot Terban to uncover how modern Russian disinformation campaigns are using domain registrars, homoglyph attacks, and generative AI to mimic legitimate news outlets and manipulate public perception. From the eerie sophistication of Doppelganger operations to the exploitation of domain infrastructure, this episode sheds light on how truth is being weaponized in the digital era. We also explore how AI is accelerating the speed and scale of these attacks, and the limited levers defenders have to push back.…

1 DNS Masterclass: Attacks, Defenses, and the Day the Internet Was Saved 41:17
41:17
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי41:17
In this special DNS Masterclass episode of Breaking Badness, hosts Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce take a deep dive into the Domain Name System often dubbed the backbone and battleground of the internet. From its humble beginnings with host files to its critical role in modern security, the episode unpacks DNS’s evolution, vulnerabilities, and impact on InfoSec.…

1 From ValleyRAT to Silver Fox: How Graph-Based Threat Intel is Changing the Game 57:53
57:53
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי57:53
In this episode of Breaking Badness, host Kali Fencl welcomes Wes Young of CSIRT Gadgets and Daniel Schwalbe, CISO and head of investigations at DomainTools, dive into a recent DomainTools Investigations (DTI) analysis involving ValleyRAT and Silver Fox, and how new tools are enabling faster, more accessible analysis for junior and seasoned analysts alike. Whether you're a threat intel veteran or an aspiring analyst, this episode is packed with hard-earned lessons, technical insights, and future-forward thinking. They also unpack the evolution of threat intelligence from early higher-ed days of wiki-scraped snort rules to today’s graph-powered AI analysis. Wes shares the origin story behind his platform AlphaHunt, how it's being used to automate and enhance threat detection, and why community sharing remains essential even in an era of advanced tooling.…

1 APT 41’s VPN Exploits & The Great Firewall’s Leaky Secrets 31:17
31:17
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:17
In this episode of Breaking Badness, we dive into two major cybersecurity stories: the exploitation of a VPN vulnerability by Chinese APT 41 and the newly discovered “Wall Bleed” flaw in the Great Firewall of China. APT 41 has been using a critical VPN vulnerability to infiltrate operational technology (OT) organizations, targeting industries like aerospace and defense. Meanwhile, researchers have uncovered a flaw in China's DNS injection system, which inadvertently leaks internal data—an ironic twist for a government known for its strict internet censorship. Join us as we break down these exploits, their impact on cybersecurity, and what they reveal about modern cyber espionage. We also discuss best practices for securing VPNs, firewall vulnerabilities, and the ethical implications of studying censorship technologies.…

1 Hacked Chats & Telecom Takedowns: Black Basta & Salt Typhoon 43:23
43:23
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי43:23
Episode 202 of Breaking Badness takes a deep dive into two of the biggest cybersecurity stories of the year (so far): ● Black Basta’s Leaked Chats – A major data leak has exposed internal conversations from this notorious ransomware gang, revealing their internal struggles, ransom negotiations, and even workplace drama. ● Salt Typhoon’s Cyber Espionage – A sophisticated Chinese threat group has been caught infiltrating major U.S. telecommunications providers, raising serious concerns about national security.…

1 Building a Hacker Conference from Scratch: The Wild Origins of ShmooCon 44:32
44:32
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:32
In this episode of Breaking Badness, we sit down with Bruce and Heidi Potter, two of the masterminds behind ShmooCon, the legendary cybersecurity conference that ran for 20 years. They take us behind the scenes, from its hilarious bar-napkin origins to how they built a tight-knit hacker community that thrived for two decades.…

1 Takeovers, DeepSeek Deceptions & the Cloud’s Dirty Laundry 40:14
40:14
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי40:14
In this episode of Breaking Badness, we dive into two major cybersecurity concerns: the risks of abandoned S3 buckets and a wave of phishing attacks impersonating DeepSeek. Watchtowr Labs uncovers how forgotten AWS storage can be hijacked for malicious purposes, potentially compromising military, government, and enterprise systems. Meanwhile, attackers exploit DeepSeek’s rising popularity to create lookalike sites, tricking unsuspecting users into downloading malware or exposing credentials. Join hosts Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce as they break down these findings with humor, deep insights, and even a few pop culture references. Plus, we rate the severity of these threats on our infamous Hoodie Scale and wrap up with Gold, Guidance & Grievances.…
B
Breaking Badness

1 Cybersecurity’s Evolution, 200 Puns Later! 44:36
44:36
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:36
Welcome to the 200th episode of Breaking Badness! 🎉 In this special milestone edition, we take a nostalgic stroll down memory lane, discuss the evolution of cybersecurity, and explore how the podcast—and the security landscape—has changed since 2019. In this special milestone episode, hosts Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce are joined by longtime friend of the show, Allan Liska, to reflect on how both the podcast and cybersecurity world have evolved over the past six years. Let’s take a stroll down memory lane and explore how Breaking Badness went from an experimental idea to a trusted, pun-filled source of cybersecurity insights.…
B
Breaking Badness

1 Zero Trust, Secure Coding & Developer Incentives: Tanya Janca on AppSec’s Biggest Challenges 36:49
36:49
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי36:49
In this episode of Breaking Badness, we welcome back Tanya Janca, aka SheHacksPurple, to discuss her latest book, Alice and Bob Learn Secure Coding. Tanya dives deep into the fundamental principles of secure software development, the psychology behind developer incentives, and the often-overlooked importance of zero trust security.…
B
Breaking Badness

1 DNS Errors and Malware Builders Turning on Attackers 35:10
35:10
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:10
In this episode of Breaking Badness, we analyze two fascinating cybersecurity incidents that expose both corporate misconfigurations and hacker missteps. Security researcher Philippe Caturegli discovered a typo in MasterCard’s DNS records, which left the company open to traffic hijacking and data exposure. This long-overlooked flaw, dating back years, could have been exploited by attackers to redirect users, intercept data, and manipulate services. The Script Kiddie Trap: In a turn of events that underscores the “no honor among thieves” trope, a threat actor baited low-skilled hackers (script kiddies) with a fake malware builder. Instead of gaining hacking capabilities, they unwittingly installed a backdoor on their own machines, allowing the original attacker to steal their data and take control of their systems.…
B
Breaking Badness

1 Leveling Up Mental Health: Tackling Gaming Toxicity and Cybersecurity Burnout 35:46
35:46
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:46
In this episode of Breaking Badness, Tricia Howard of Akamai joins Kali Fencl and Ian Campbell to dive deep into the intersection of gaming culture, mental health, and cybersecurity. Tricia shares her journey from theater arts to cybersecurity research, her love for gaming, and her experiences tackling emotional toxicity in digital spaces. The episode covers the concept of "mind patches," the role of community in digital wellness, and how gaming and workspaces mirror each other in their challenges with mental health and collaboration. Tune in to hear her thoughts on reducing stigma, creating safe digital spaces, and embracing vulnerability for a healthier cybersecurity community.…
B
Breaking Badness

1 Spring Cleaning Your Digital Life: APT Threats, Third-Party Breaches, and Chat Risks 31:06
31:06
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:06
In this episode of Breaking Badness, we dive into the cybersecurity headlines making waves in 2025. We discuss the U.S. Treasury breach, allegedly orchestrated by Chinese hackers using third-party access. Learn about how lingering chat histories can expose sensitive data and the importance of digital spring cleaning.…
B
Breaking Badness

1 Tanya Janca on Secure Coding, AppSec, and Breaking Barriers in Cybersecurity 47:28
47:28
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי47:28
In this episode of Breaking Badness, we sit down with Tanya Janca, aka SheHacksPurple, a cybersecurity educator, and author of the best-selling book Alice and Bob Learn Application Security. Tanya shares her journey from software developer to AppSec expert, dives into the unique challenges of teaching secure coding, and discusses the impact of cybersecurity breaches on industries and individuals. From her creative teaching methods to her advocacy for change in university curriculums, Tanya offers insights that resonate with developers, educators, and security professionals alike. Discover how Tanya is paving the way for accessible AppSec education, the role of AI in secure coding, and her mission to teach security as a fundamental skill for every developer.…
B
Breaking Badness

1 Cybersecurity Tales: Espionage, Ransomware, and the Stories Behind the Threats 34:03
34:03
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי34:03
Welcome to this special episode of the Breaking Badness Cybersecurity Podcast! We’re turning the spotlight on the books that have shaped the world of cybersecurity and inspired professionals in the field. As part of our ongoing book club series, this episode is a journey into storytelling, research, and the unique perspectives that make cybersecurity literature so compelling. From Ransomware Diaries to the geopolitics of cyber warfare, this discussion is packed with insights and actionable takeaways for anyone working in Infosec.…
B
Breaking Badness

1 Top Cyber Moments of 2024: Hoodies, Goodies, and Hilarious Puns 39:13
39:13
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:13
In this special episode of Breaking Badness, we wrap up 2024 with a countdown of the top episodes, puns, and cybersecurity moments that defined the year. From the hoodiest hacks to the goodiest wins, Kali, Tim, and Taylor reflect on critical insights, industry-changing events, and listener favorites. Tune in for discussions about evolving OT security, DNS mishaps, ransomware trends, and expert predictions for 2025. Featuring special moments like our Hacker Summer Camp interviews and top cybersecurity guests, this episode is both insightful and entertaining.…
B
Breaking Badness

1 2025 Cybersecurity Predictions: AI, Ransomware, and Quantum Threats 59:41
59:41
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי59:41
In this special 2025 Predictions episode of Breaking Badness, host Kali Fencl joins cybersecurity experts Sean McNee, Tim Helming, and Daniel Schwalbe to discuss the future of cyber threats and defense. From ransomware evolution and AI-powered attacks to quantum computing and “synthetic identity fraud,” the group compares their insights with predictions generated by leading AI platforms like ChatGPT, Claude, Copilot, and Meta AI. Will 2025 be the year of AI-compromised models or industrial control system hacks? Are biometric security risks on the rise, and what’s next for ransomware gangs? Tune in for insights, banter, and some predictions you’ll want to track!…
B
Breaking Badness

1 DNS Gone Rogue & DARPA’s Cyber Puzzle: Lessons in Security Innovation 32:26
32:26
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי32:26
In this episode of Breaking Badness, we dive into two fascinating stories shaping the cybersecurity landscape. First, we unpack the case of Gabriel Koo and his surprising acquisition of the domain us-east-1.com, a domain closely tied to AWS’s naming conventions. What insights can this seemingly simple purchase reveal about DNS misconfigurations and AWS security practices? Next, we shift focus to DARPA's ambitious new project aimed at revolutionizing cybersecurity by breaking software into smaller, more secure compartments. With expert analysis and intriguing insights, we explore the intersection of DNS, innovation, and the future of cybersecurity.…
B
Breaking Badness

1 The Rise of Holiday Scams and State-Sponsored Cyber Threats 44:20
44:20
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:20
In this episode of Breaking Badness, we delve into the cybersecurity trends shaping the holiday season. We unpack the 60% surge in scam domain registrations targeting holiday shoppers, discuss the tactics of TAG-112, a Chinese state-sponsored threat group, and analyze their use of compromised websites to deliver Cobalt Strike malware. Plus, we share actionable insights on mitigating these threats. Tune in for expert analysis, lighthearted banter, and a few cybersecurity holiday tips to keep you safe this season…
B
Breaking Badness

1 Breaking Down SBOMs: The Secret Weapon in Healthcare Security 31:22
31:22
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:22
In this episode of Breaking Badness, we dive into the critical challenges and innovations in healthcare cybersecurity with Ken Zalevsky, CEO of Vigilant Ops. From the vulnerabilities in medical devices to the revolutionary role of Software Bill of Materials (SBOMs), Ken shares his two decades of expertise in safeguarding patient safety and hospital systems against emerging threats. Tune in to learn about shifting cybersecurity left, the complexities of interconnected healthcare systems, and actionable strategies to combat ransomware and legacy vulnerabilities.…
B
Breaking Badness

1 195. From Wingdings to Warfare: Inside the Wildest Cybersecurity Stories 38:58
38:58
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:58
In this episode of Breaking Badness, we explore two fascinating cybersecurity stories. First, we delve into the unusual case of an ex-Disney employee who hacked menu systems, creating chaos in the happiest place on Earth. Next, we discuss Sophos' five-year-long battle with a determined group of attackers targeting their firewalls. Tune in as we break down the insider threat at Disney, the lessons learned from Sophos' transparency, and what it all means for the future of cybersecurity. Plus, don't miss our signature Gold, Guidance, and Grievances segment for unique insights and takeaways.…
B
Breaking Badness

1 Jason Haddix on Red Team Tactics, CISO Challenges, and the Battle for Gaming Security 44:21
44:21
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:21
In this episode of the Breaking Badness Cybersecurity Podcast, Jason Haddix dives into his unique journey from red teaming and pentesting to leading security teams as a CISO in high-profile organizations, including a top gaming company. Jason unpacks the distinct challenges of securing a gaming company, where risks come not only from state actors but also from clout-seeking young hackers. He shares valuable insights on building scalable security programs, secrets management, and the importance of radical transparency in corporate security cultures. Tune in to hear why, in Jason's words, "gaming saved me from a misspent youth," and learn about his latest ventures into offensive security training and AI-driven security solutions.…
B
Breaking Badness

1 194. Locate X Unleashed & APT29’s Latest Gambit: The Battle for Digital Privacy 32:54
32:54
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי32:54
In this week’s episode of Breaking Badness, we dive deep into two major cybersecurity stories that are shaping today’s landscape. First, we explore the alarming capabilities of Locate X, a powerful smartphone tracking tool used by U.S. law enforcement without a warrant. How does it work, what are the privacy implications, and what can individuals do to protect their data? We then shift gears to APT29’s latest campaign as discovered by Amazon, uncovering how this well-known threat actor employed advanced tactics to impersonate AWS infrastructure and target victims. Join Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce as they dissect these stories and share their expert insights. Stick around for the Grim Reaper’s hoodie ratings and our signature segment, Gold, Guidance, and Grievances.…
B
Breaking Badness

1 Inside the Mind of ‘The Gibson’: Ethics, Activism, and the Evolution of Hacking 41:30
41:30
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי41:30
Join Kali Fencl as she dives deep into a conversation with cybersecurity veteran The Gibson. With 25+ years in InfoSec, The Gibson shares his journey from coding as a child to shaping threat intelligence and privacy-first technology today. In this episode, they discuss hacker ethics, the influential hacker groups Loft and Cult of the Dead Cow, the evolution of hacktivism, and the groundbreaking work on privacy-focused projects like Veilid. Tune in for insights on hacking culture, cybersecurity ethics, and the balance between creativity and responsibility in the digital age.…
B
Breaking Badness

1 193. Rogue Hackers and the Internet Archive Breach: 31 Million Accounts Exposed! 44:48
44:48
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:48
In this episode of Breaking Badness, Kali, Tim, and Taylor discuss two major stories shaking up the cybersecurity world. First, a researcher has discovered how attackers are exploiting Whois data to grant themselves unprecedented superpowers in the digital space. Second, the Internet Archive suffers a breach possibly exposing 31 million accounts, raising questions about the security of trusted online platforms. Join the team as they break down these complex stories, share lessons learned, and explore how organizations can better protect themselves in similar situations.…
B
Breaking Badness

1 The Future of Endpoint Security: AI, EDR, and SOC Evolution 37:03
37:03
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי37:03
In this episode of Breaking Badness, we dive deep into the evolving world of Endpoint Detection and Response (EDR) and its critical role in modern cybersecurity. With threats advancing and the sheer volume of endpoint data skyrocketing, AI and deep learning are becoming game changers in threat detection and prevention. Join us as Carl Froggett, CIO at Deep Instinct, and Melissa Bischoping, Senior Director of Security at Tanium, discuss the past, present, and future of EDR, the impact of AI on cybersecurity, and how SOC teams are evolving to stay ahead of bad actors. Learn about how generative AI is influencing attacks, the challenge of SOC burnout, and the innovations shaping the future of endpoint security.…
B
Breaking Badness

1 Cracking the Code: API Security, Mobile Myths, and Real-World Threats 39:10
39:10
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:10
In this episode of Breaking Badness, we dive deep into the critical world of API security and governance, uncovering key strategies to keep data safe in today’s threat landscape. Special guests Matthias Friedlingsdorf (iVerify), Tristan Kalos (ESCAPE), and Aqsa Taylor (Gutsy) join the conversation to share their experiences with detecting advanced threats like Pegasus, the importance of API governance, and the powerful role bug bounty programs play in identifying critical vulnerabilities. Whether you're an API developer, cybersecurity professional, or someone navigating the risks of mobile device exploits, this episode will arm you with the knowledge to better protect your digital assets.…
B
Breaking Badness

1 Defending Your Digital Domain: AI, Ransomware, and the Power of Reputation 30:29
30:29
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי30:29
In this episode of Breaking Badness, we dive into the rapidly evolving world of cybersecurity with three industry leaders: Raymond Dijkxhoorn, CEO of SURBL; Nabil Hannan, Field CISO at NetSPI; and Jason Mar-Tang, Field CISO at Pentera. They explore the critical role of domain reputation in combating phishing and spam, how AI is reshaping both offensive and defensive cybersecurity strategies, and the growing threat of ransomware in today’s digital landscape. With insights from BlackHat and beyond, we discuss everything from the future of phishing defense to the challenges AI poses in securing sensitive data, as well as how ransomware continues to evolve. Tune in to gain actionable insights on staying ahead of cyber threats and protecting your digital domain.…
B
Breaking Badness

1 Achieving Cyber Resilience through Vulnerability Management and Supply Chain Security 25:39
25:39
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי25:39
In this special Black Hat edition of Breaking Badness, Part 2 of a 5 Part Series, we dive deep into the world of vulnerability management, cyber resilience, and supply chain security. Our expert guests—Jacob Graves, Director of Solution Architecture at Gutsy, Theresa Lanowitz, Chief Evangelist at Level Blue, Pukar Hamal, CEO at SecurityPal, and Vinay Anand, Chief Product Officer at NetSPI discuss the increasing complexity of managing vulnerabilities, the critical importance of reducing mean time to detect (MTTD) and mean time to repair (MTTR), and the emerging strategies for securing the supply chain against growing risks. Learn how vulnerability management isn’t just a technical challenge but an organizational one, and explore the nuanced roles of the CIO, CTO, and CISO in maintaining a resilient cyber infrastructure.…
B
Breaking Badness

1 AI’s Role in Cybersecurity: From EDR Evolution to Generative AI Threats and Supply Chain Risks 22:02
22:02
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי22:02
In this special Black Hat edition of the Breaking Badness Cybersecurity Podcast, Part 1 of a 5 Part Series, we dive deep into how artificial intelligence is transforming the cybersecurity landscape. Our guests—Mark Wojtasiak (VP of Product at Vectra AI), Carl Froggett (CIO at Deep Instinct), Dan Fernandez (Staff Product Manager at Chainguard), and Marcus Ludwig (CEO of Ticura)—join us to explore the evolution of Endpoint Detection and Response (EDR), the growing threats posed by generative AI, and the complexities of securing AI in supply chains. With AI becoming a tool for both attackers and defenders, this episode uncovers the ongoing "AI arms race" and highlights the urgent need for a more preventative approach to cybersecurity.…
B
Breaking Badness

1 Breaking Down Retail Targeted Campaigns: Domain Fraud, Copycats, and Ponzi Schemes 30:35
30:35
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי30:35
In this special research edition of Breaking Badness, hosts Kali Fencl, Tim Helming, Sean McNee, and guest Sasha Angus from Sylla Intel dive deep into the world of cybercriminal campaigns targeting retailers. They explore how bad actors exploit the growing threat landscape, discussing specific fraud tactics, infrastructure reuse, and ways organizations can defend themselves. From pandemic-driven scams to sophisticated brand impersonation schemes, this episode offers valuable insights for both retailers and consumers navigating the complex world of e-commerce security.…
B
Breaking Badness

1 Industrial Cybersecurity Explained with Lesley Carhart 25:16
25:16
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי25:16
Kali Fencl and Daniel Schwalbe sat down with Lesley Carhart, a seasoned incident responder specializing in Operational Technology (OT) cybersecurity at Dragos, in person at BlackHat USA 2024. Lesley shares their journey, from their unique background in avionics and electronics to becoming a leading expert in the field. We explore the evolving landscape of OT cybersecurity, the challenges of protecting legacy systems, and the critical importance of building strong relationships between cybersecurity teams and operational engineers. Lesley also discusses the realities of incident response in industrial environments, the misconceptions surrounding OT security, and the human-centric approach needed to tackle these complex issues. Tune in to learn about the delicate balance between innovation and safety in protecting the critical infrastructure that powers our world.…
B
Breaking Badness

Kali Fencl, Daniel Schwalbe, and Tim Helming discuss Brian Krebs’ article on namespace collisions and the risks associated with new generic TLDs (gTLDs) along with facial recognition and privacy concerns at major sporting events
B
Breaking Badness

1 191. Hacker Summer Camp Retrospective 52:32
52:32
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי52:32
Kali Fencl, Daniel Schwalbe, and Malachi Walker discuss all things Hacker Summer Camp. What sessions were their favorites? How did they beat the heat? Listen to the episode and find out!
B
Breaking Badness

1 190. The Weak Security Default in Our Stars 51:42
51:42
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי51:42
This week we compromised domains targeting DeFi protocols along with the JFrog research team's findings regarding a leaked access token with admin access to Python repositories
B
Breaking Badness

1 Voices from Infosec: Tanya Janca 1:02:49
1:02:49
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:02:49
We're thrilled Tanya Janca (aka SheHacksPurple) joined us this week on the podcast! She and Kali Fencl discuss secure guardrails, Semgrep Academy, the process of writing two books, gardening, and so much more.
B
Breaking Badness

1 189. Malware the Wild Things Are 46:56
46:56
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי46:56
In this episode of the Breaking Badness Cybersecurity Podcast, Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss vulnerabilities impacting your phone's 5G connection along with the new owner of the popular Polyfill JS project injecting malware into more than 100,000 sites.
B
Breaking Badness

1 Voices from Infosec: Jake Bernardes 38:15
38:15
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:15
Jake Bernardes, Field CISO of Anecdotes, joins the Breaking Badness Cybersecurity Podcast in this week’s episode! We’re sharing Jake’s background and path within infosec along with what’s intriguing him about the industry currently, how conferences and in-person events can still play a role in community involvement, and we’ll touch briefly on American history.…
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss vishing attacks against CISA along with a threat campaign targeting Snowflake customer database instances.
B
Breaking Badness

1 [Mini Series] The Art of the Possible: Aqsa Taylor 29:52
29:52
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי29:52
It is the final episode of our mini-series from RSAC 2024! Join Kali as she speaks with Aqsa Taylor, Director of Product Management at Gutsy! They'll discuss Aqsa's path to infosec, the importance of governance strategy and how to achieve a cleaner security posture, women in cybersecurity, and how to break into the field.…
B
Breaking Badness

1 [Mini Series] The Art of the Possible: Zack Schuler and Lawrence Gentilello 42:21
42:21
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:21
It's the penultimate episode of our RSAC mini series! We're speaking with Zack Schuler of NINJIO in the first half of the episode and in the second, we speak with Lawrence Gentilello of Optery.
B
Breaking Badness

1 [Mini Series] The Art of the Possible: Joe Slowik and David Goldschlag 50:02
50:02
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי50:02
We're halfway through our RSAC mini series! We're speaking with Joe Slowik of MITRE in the first half of the episode and in the second, Kali is joined by Daniel Schwalbe to speak with David Goldschlag of Aembit.
B
Breaking Badness

1 [Mini Series] The Art of the Possible: Ben April and Allan Liska 52:53
52:53
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי52:53
In our second iteration of our mini-series, we'll speak with Ben April of Maltego and Allan Liska of Recorded Future. We'll cover topics such as AI, the LockBit ransomware gang, cybersecurity comic books, and more!
B
Breaking Badness

1 [Mini Series] The Art of the Possible: Jori VanAntwerp and Steve Stone 1:05:32
1:05:32
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:05:32
In our first episode of our mini-series, we'll speak with Jori VanAntwerp of EmberOT and Steve Stone of Rubrik Zero Labs. We'll cover topics like IT and operational technology and how ransomware is impacting the healthcare space.
We're back on the road at RSA 2024 talking with thought leaders in the infosecurity space! Be sure to check in weekly as we share nine interviews with folks from Recorded Future, Gutsy, Maltego, Aembit, MITRE, EmberOT, Optery, Rubrik, and NINJIO.
B
Breaking Badness

1 Breaking Badness Book Club with Dmitri Alperovitch 49:04
49:04
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי49:04
This week on the Breaking Badness Cybersecurity podcast, Kali Fencl is joined by CEO of DomainTools, Tim Chen, and Executive Chairman of the Silverado Policy Accelerator and co-founder of CrowdStrike, Dmitri Alperovitch to discuss his book, “World on the Brink: How America Can Beat China in the Race for the 21st Century.”…
B
Breaking Badness

1 Voices from Infosec: Kymberlee Price 1:01:03
1:01:03
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:01:03
In this edition of Voices from Infosec, we're talking with Founder and CEO of Zatik Security, Kymberlee Price! We'll cover her path to infosec, the origins of her organization and its goals, and her passions outside of the industry.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Ian Campbell discuss mercenary spyware attacks along with the US, Philippines, and Japan entering into a cyber intel sharing alliance.
B
Breaking Badness

1 186. While My Vidar Gently Weeps 56:57
56:57
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי56:57
Kali Fencl, Tim Helming, and Ian Campbell discuss spoofed domains and the American Girl brand along with @Proofpoint’s findings regarding distribution of malware on YouTube.
B
Breaking Badness

Episode 185 of Breaking Badness is here! This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss Brian Krebs’ article on thread hijacking along with the latest alert from CISA that affects XZ Utils.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Austin Northcutt discuss threat actors using DDP sites for phishing, credential harvesting, and more along with Wired’s reporting of how researchers discovered how to open 3 million hotel keycard locks
B
Breaking Badness

Episode 183 of Breaking Badness is here! This week Kali Fencl, Ian Campbell, and Austin Northcutt do a deep dive on the AlphV/BlackCat ransomware gang.
B
Breaking Badness

Episode 182 of Breaking Badness is here! This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss Palo Alto’s latest findings on Bifrost along with the rise of laid off tech workers turning to cybercrime.
B
Breaking Badness

Episode 181 of Breaking Badness is here! This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss CISA’s caution against a hacked VPN getaway along with Guardio Security’s discovery of a large subdomain hacking campaign.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss China’s involvement with I-Soon along with DNSSEC and the #KeyTrap vulnerability
B
Breaking Badness

Episode 179 of Breaking Badness is here! This week Kali Fencl, Kelly Molloy, and Ian Campbell discuss Cory Doctorow’s recent blog post about his experience getting scammed along with the decade-long issue of email sent to .ml addresses rather than .mil ones.
B
Breaking Badness

Episode 178 of Breaking Badness is here! This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss the US disabling of Volt Typhoon along with AnyDesk’s recent cyberattack.
B
Breaking Badness

1 [Special Report] Ransomware and Mortgage Brokers 1:02:36
1:02:36
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:02:36
In the latest episode of Breaking Badness, Kali Fencl, Austin Northcutt, and Yelisey Bohuslavskiy discuss a string of mortgage brokers who have been hit with ransomware over the past several months. What are the targeting patterns? Who are the victims?
B
Breaking Badness

1 Breaking Badness Book Club #3 1:30:42
1:30:42
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:30:42
This week on the Breaking Badness podcast, Allan Liska and Jon DiMaggio join Kali Fencl to discuss Jon’s book, The Art of Cyberwarfare, along with other favorite cybersecurity picks!
B
Breaking Badness

1 177. Just Around the COLDRIVER Bend 48:40
48:40
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי48:40
This week it’s all about targeting expansions! Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss threat actors COLDRIVER expanding their targeting along with Mint Sandstorm.
B
Breaking Badness

1 Breaking Badness Book Club Episode #2 46:10
46:10
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי46:10
We’re coming back with another iteration of our Book Club on the Breaking Badness podcast! Kali Fencl, Ian Campbell, and Daniel Schwalbe discuss their top cybersecurity book picks along with books outside the industry.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss a new method of hacking compromising Google accounts along with findings from Operation Triangulation.
B
Breaking Badness

This week we're taking a look back at 2023! We're reminiscing about the guests we spoke with and counting down to the top episode...and the top puns!
B
Breaking Badness

It’s been a big year in infosec/cybersecurity, but we could say that almost every year. We did a similar discussion last year if you’d like to check that out, and we wanted to follow up on those predictions along with sharing some new ones for 2024.
B
Breaking Badness

Episode 175 of Breaking Badness is here! This week Kali Fencl, Tim Helming, and Ian Campbell discuss bad actors using shell companies in Wyoming for global attacks along with BazarCall attacks leveraging Google Forms.
B
Breaking Badness

1 [Special Report] Father Phishmas, Give Us The Money 55:12
55:12
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי55:12
A special Phishmas episode of Breaking Badness is here! We’re talking with @nullcookies about the recent phishing attacks targeting the United States Postal Service, its implications, and possible mitigations. Listen here:
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss a recent attack on a municipal water authority along with Timo Longin and SEC Consult’s latest research on DNS cache poisoning
B
Breaking Badness

Kali Fencl, Tim Helming, Taylor Wilkes-Pierce, and Sean McNee discuss their favorite #cybersecurity books! Listen and learn what we’ve enjoyed and what we’ve found helpful in our careers along with non-industry books we’re currently enjoying.
B
Breaking Badness

1 Special Report - Quadrant Security [Re-Release] 1:01:17
1:01:17
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:01:17
We're taking this opportunity to share how grateful we are for the guests and discussions we've had this past year on Breaking Badness. One of which is our conversation with Champ Clark III and Steven Drenning-Blalock from Quadrant Security on how they thwarted the Black Basta ransomware gang. If you didn't have a chance to listen when we initially released this episode, now's a great time to catch up!…
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss a private industry notification from the FBI along with Mandiant’s findings from a #Sandworm attack targeting Ukraine.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss the SEC charges against SolarWinds and its CISO along with the 0-day exploitation impacting NetScaler ADC and NetScaler Gateway appliances.
B
Breaking Badness

This week on Breaking Badness, Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss the latest accusations against Fancy Bear along with a look at 404 Media’s findings about the SIM Swapper group known as The Comm.
B
Breaking Badness

We like to MOVEit MOVEit on Breaking Badness. This week on the pod, Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss Cisco’s zero-day vulnerability along with the latest from the Clop ransomware gang and the MOVEit file transfer software.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss curl 8.4.0 along with one of the biggest DDoSes of all time.
B
Breaking Badness

1 [Special Report] Two Seans, a Tim, and a Pig Butchering Ring 55:32
55:32
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי55:32
This week on Breaking Badness, Kali Fencl, Tim Helming, and Sean McNee speak with Sean Gallagher from Sophos X-Ops on the latest iteration in pig butchering schemes along with how AI could change the game.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss a previously unknown compression side channel in GPUs along with the Johnson Controls #ransomware attack.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Ian Campbell discuss the ransom attacks against MGM and Caesars Entertainment along with Cisco’s acquisition of Splunk.
B
Breaking Badness

1 Voices From Infosec - Tony Robinson aka da_667 51:41
51:41
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי51:41
In this special episode of Breaking Badness, Kali Fencl and Tim Helming speak with Tony Robinson, Senior Security Researcher with the Emerging Threats team at Proofpoint. We talk about his path to #infosec, #InformationStealers, and more!
B
Breaking Badness

1 166. I’m W3LL Aware of BEC Attacks 50:04
50:04
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי50:04
This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss Group-IB’s findings on the hidden phishing ecosystem driving BEC attacks along with Microsoft’s follow-up on Storm-0558
B
Breaking Badness

1 Voices From Infosec - Peter Lowe 1:04:49
1:04:49
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:04:49
Peter Lowe joins Kali Fencl and Daniel Schwalbe for this edition of Voices from Infosec! We discuss Peter’s background, AI, its progress, and where we think it’s headed, informed consent on the Internet, and some of Peter’s interests outside of cybersecurity.
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss telekopye and online marketplace scams along with NIST’s publication of the first draft standards for post-quantum cryptography. Listen here:
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss the Downfall Intel CPU vulnerability along with MoustachedBouncer’s espionage against Belarus.
B
Breaking Badness

1 [Bonus Episode] Voices from Infosec - Allan Liska Returns! 50:34
50:34
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי50:34
A second week of Breaking Badness with a special guest? 😱 Allan Liska is back to talk about his upcoming comic book: Yours Truly, Johnny Dollar - America’s fabulous cyber insurance investigator, taking on #ransomware attacks, insider threats, and more!
B
Breaking Badness

1 [Bonus Episode] Voices from Infosec with Tracy Maleeff 42:52
42:52
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:52
In this special episode of Breaking Badness, Kali Fencl and Tim Helming speak with none other than Tracy Maleeff (aka InfoSec Sherpa!) We’re excited to share our conversation on her background, empathy in infosec, industry myths she’d like to bust, and more!
B
Breaking Badness

This week on the pod, Kali Fencl, Daniel Schwalbe, and Ian Campbell discuss Cisco Talos' blog on what authentication attacks might look like in a phishing-resistant future along with the SEC’s approval of new cyber reporting regulations for public companies
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss the investigation of Storm-0558 along with Ukraine’s most recent takedown of a massive bot farm.
B
Breaking Badness

1 161. The Early Bird Gets the WormGPT 54:26
54:26
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי54:26
Math puns abound in episode 161 of Breaking Badness! But Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce do manage to discuss Daniel Kelley’s blog on how AI is revolutionizing BEC attacks along with details of the national #cybersecurity strategy.
B
Breaking Badness

This week Kali Fencl, Ian Campbell, and Taylor Wilkes-Pierce discuss France’s pending phone monitoring bill along with Nickelodeon’s recent data breach (includes a healthy dose of 90s nostalgia!)
B
Breaking Badness

1 159. Do or Do Not…There is No Triangulation 53:21
53:21
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי53:21
This week Kelsey LaBelle, Tim Helming, and Ian Campbell discuss the new variant of the Mirai botnet along with Graham Cluley’s article on zero-day flaws used in spy attacks against Kaspersky.
B
Breaking Badness

On this week's episode of Breaking Badness, Kali Fencl, Tim Helming, and Taylor Wilkes-Pierce discuss the new Fortigate firmware updates along with Brian Krebs article on replacing Barracuda hardware.
B
Breaking Badness

This week Tim Helming, Sean McNee, and guest researcher Sasha Angus discuss the most prolific ransomware families and share cybersecurity gold, guidance, and grievances.
B
Breaking Badness

This week Kelsey LaBelle, Kelly Molloy, and Taylor Wilkes-Pierce discuss a pandemic catfishing scam along with Eclypsium’s detection of backdoor behavior from Gigabyte systems.
B
Breaking Badness

1 [Mini Series] Stronger Together: Tim Chen, Daniel Schwalbe, and Your Friends at DomainTools 35:46
35:46
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:46
We've made it to the final installment of our Stronger Together Mini-Series! In this episode, you'll hear from folks at DomainTools including CEO Tim Chen, veteran podcaster Daniel Schwalbe, and more!
B
Breaking Badness

This week Kali Fencl, Tim Helming, and Ian Campbell discuss Kim Zetter’s work on the SolarWinds investigation along with the Senate’s hearing on AI regulation.
B
Breaking Badness

1 [Mini Series] Stronger Together: Katie Nickels, Don Jeter, Ben April, Lesley Carhart & Jeff Stout 53:40
53:40
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי53:40
We’ve made it to the third installment of our Stronger Together Mini Series! In this episode we’re joined by researchers, threat analysts, and C-Suites including Katie Nickels from Red Canary and the SANS Institute, Don Jeter from Torq, Ben April from Maltego, Lesley Carhart from Dragos, and Jeff Stout from Akamai. We have some great discussions on the pros and cons of AI, protecting industrial control systems, imposter syndrome, and more.…
B
Breaking Badness

1 [Mini Series] Stronger Together feat. Jamie Williams, Jon DiMaggio, Corey Thuen, and Renee Burton 48:54
48:54
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי48:54
Welcome to episode number two of our Breaking Badness Mini-Series: Stronger Together! We hope you had a chance to check out last week’s episode of our conversation with Allan Liska. This week we’re going to be hearing from Jamie Williams, Jon DiMaggio, Corey Thuen, and Renee Burton as we continue to focus on RSA’s 2023 theme: Stronger Together. We cover a lot of ground in these interviews, but the theme we keep coming back to is how we can take our individual specialities and come together to give bad actors more bad days.…
B
Breaking Badness

1 [Mini Series] Stronger Together with Allan Liska 35:47
35:47
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:47
In this episode for the Stronger Together Mini-Series, we are joined by Allan Liska, Ransomware Researcher at Recorded Future. We sat down (or rather, stood and leaned against a wall away from noise) to discuss his path to infosec, interesting talks at RSA, liberal arts and cybersecurity, a pending passion project, and general geeking out over DNS.…
In this special Mini-Series, Breaking Badness goes on the road to RSA to talk to researchers, intelligence analysts, security advocates, VPs, and C-suites on how we can come together in the industry to give bad actors more bad days.
B
Breaking Badness

1 154. Not Your Neurotypical Episode 1:08:22
1:08:22
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:08:22
This week Kali Fencl, Ian Campbell, and Travis Hall discuss neurodiversity in cybersecurity including their own experiences, advice for managers, and neurodivergent Employee Resource Groups.
B
Breaking Badness

This week Kelsey LaBelle, Tim Helming, and Aaron Gee-Clough discuss the 5 pillars of the White House’s National Cybersecurity Strategy.
B
Breaking Badness

This week Kelsey LaBelle, Tim Helming, and Taylor Wilkes-Pierce discuss Cisco Talos’ Ukraine task unit one year into the Ukraine/Russia conflict along with the Google Pixel and Windows 11 uncropping bugs
B
Breaking Badness

1 151. Epic Bail: The Collapse of Silicon Valley Bank Its Impact on Infosec 46:05
46:05
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי46:05
This week on Breaking Badness, Kelsey LaBelle, Daniel Schwalbe, and Tim Helming discuss the recent collapse of Silicon Valley Bank. We’ll dive into what we’ve been seeing on our end, predictions on what we may see from bad actors, and practical advice for moving forward.
B
Breaking Badness

1 150. Thrifty, Nifty, Never Shifty (Part II) 49:33
49:33
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי49:33
The 150th celebration of Breaking Badness continues this week for Part II! We’re talking to Daniel Schwalbe, Sean McNee, Aaron Gee-Clough, and Kelly Molloy about their paths to infosec favorite pod memories, and interests outside of work.
B
Breaking Badness

1 150. Thrifty, Nifty, Never Shifty (Part I) 56:25
56:25
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי56:25
We’re celebrating 150 episodes of Breaking Badness! Join us for Part I of a 2 week extravaganza! We’re talking to Kelsey LaBelle, Tim Helming, Taylor Wilkes-Pierce, and Ian Campbell this week on their paths to infosec, favorite pod memories, and interests outside of work.
B
Breaking Badness

Oooh it’s the last episode of Breaking Badness before the big 150! This week Kelsey LaBelle, Daniel Schwalbe, and Taylor Wilkes-Pierce discuss the rise of phishing as a service along with a discussion on how mental health data is obtained via third parties.
B
Breaking Badness

This week Kelsey LaBelle, Ian Campbell, and Taylor Wilkes-Pierce get out the 🍿 to discuss the dismantling of Exclu along with hackers who exploited a 2 year old VMware vulnerability.
B
Breaking Badness

This week Kelsey LaBelle, Tim Helming, and Taylor Wilkes-Pierce discuss malvertising using Google Ads along with ProofPoint’s recent research on use of Microsoft OneNote for delivering malware
B
Breaking Badness

1 146. I Am Extortionary (If You Ever Get To Know Me) 50:40
50:40
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי50:40
This week Kelsey LaBelle, Tim Helming, and Taylor Wilkes-Pierce discuss the FBI takedown of the Hive ransomware variant along with insights from the 2022 GuidePoint Research and Intelligence Team ransomware report.
B
Breaking Badness

1 Special Report - Quadrant Security 1:00:10
1:00:10
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי1:00:10
This week on Breaking Badness we've got a Special Report. We're talking to Champ Clark III and Steven Drenning-Blalock from Quadrant Security about a re-emergence of the Black Basta ransomware group. Plus—we’ll get their Gold, Guidance and Grievances.
B
Breaking Badness

This week Kelsey LaBelle, Tim Helming, and Taylor Wilkes-Pierce discuss vulnerabilities in Siemens programmable logic controllers along with Kevin Chung’s blog post on resurrecting the defunct IoT NYCTrainSign.
B
Breaking Badness

This week Tim Helming speaks with CISO Daniel Schwalbe and SecOps Engineer Ian Campbell on the LastPass breach
B
Breaking Badness

That's a wrap on 2022! Tune in to hear Kali Fencl discuss your favorite puns and episodes from the past year along with our podcast plans for 2023!
B
Breaking Badness

1 142. Pheast of the Seven Phishes 54:45
54:45
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי54:45
This week Kelsey LaBelle, Tim Helming, and Taylor Wilkes-Pierce discuss domains seized by the FBI linked to DDoS-for-hire services along with Rick Osgood’s blog on ChatGPT’s phishing potential.
B
Breaking Badness

This week Kelsey LaBelle, Tim Helming, and special guest Sean McNee discuss Wired’s article on scammers scammed by scammers along with Jan Schaumann’s research on who controls the Internet.
B
Breaking Badness

It’s a special in-person episode of Breaking Badness! Kelsey LaBelle, Tim Helming, Daniel Schwalbe, Taylor Wilkes-Pierce, and Sean McNee talk about the ongoing T.Swift/Ticketmaster security saga, the war in Ukraine, and the Disneyland Team post from Brian Krebs.
B
Breaking Badness

1 [Bonus Episode] Voices from Infosec with Caitlin Kiska 35:51
35:51
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:51
In this special episode of Breaking Badness, Tim Helming sat down at GrrCon with Incident Responder, Caitlin Kiska, to discuss her path to cybersecurity, the alert fatigue battle, and bird watching.
B
Breaking Badness

1 139. Something’s Polyglot To Give 47:43
47:43
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי47:43
This week Taylor Wilkes-Pierce, Kali Fencl, and Tim Helming discuss a recent Forbes article on cybersecurity layoffs along with StrelaStealer - the new info-stealing malware.
B
Breaking Badness

Episode 138 of Breaking Badness, Kelsey LaBelle, Tim Helming, and special guest Aaron Gee-Clough discuss SocGholish JavaScript malware along with Phylum’s research regarding PyPI packages in ongoing supply chain attacks.
B
Breaking Badness

Breaking Badness gets spooky this week 👻 Recorded on Halloween, Ian Campbell, Kelsey LaBelle, and Daniel Schwalbe discuss clop ransomware (not short for ‘cyclops’ apparently) and its link to the Raspberry Robin worm along with vishing and the latest Twilio breach
B
Breaking Badness

Episode 136 of Breaking Badness gets spooky! This week Taylor Wilkes-Pierce, Kelsey LaBelle, and Tim Helming discuss the classic movie Gremlins since it comes up while discussing OldGremlin, along with double extortion attacks from BlackByte. Listen here:
B
Breaking Badness

In this episode of Breaking Badness, Kelsey LaBelle, Taylor Wilkes-Pierce, and special guest Kelly Molloy discuss the future of Network Time Protocol along with consumer drones used for hacking
B
Breaking Badness

Episode 134 of Breaking Badness is here! This week, Taylor Wilkes-Pierce, Tim Helming, and Kali Fencl discuss research into the cybercrime group, LofyGang along with the latest CISA and FBI PSA on disinformation in the upcoming US midterm election
B
Breaking Badness

On Wednesdays we wear pink! Recorded on National Mean Girls Day, in this latest podcast episode Tim Helming, Kelsey LaBelle, and Taylor Wilkes-Pierce discuss two zero day flaws in Microsoft Exchange along with news regarding Brute Ratel.
B
Breaking Badness

Ahoy! Lots of pirate puns in Episode 132 of Breaking Badness! This week Kelsey LaBelle returns and she, Tim Helming, and Daniel Schwalbe discuss the Steam browser-in-the-browser attacks along with a phishing opportunity in WhatsApp.
B
Breaking Badness

Episode 131 of Breaking Badness is now available. This week Taylor Wilkes-Pierce returns! He, Tim Helming, and Kali Fencl discuss AT&T Alien Labs' research on Shikitega malware along with Apple’s rollout of passkeys.
B
Breaking Badness

Episode 130 of Breaking Badness is now available. This week Kali Fencl, Tim Helming, and Ian Campbell discuss how the Kimsuky threat group always gets the right victims along with Group-IB’s research on 0ktapus.
B
Breaking Badness

Episode 129 of Breaking Badness is now available. This week Tim Helming, Kali Fencl, and special guest Daniel Schwalbe discuss the Twilio data breach along with a social engineering attack from Lazarus.
B
Breaking Badness

Episode 128 of Breaking Badness is now available. This week Tim Helming, Kali Fencl, and special guest Aaron Gee-Clough discuss bad characters and trojan source vulnerabilities along with Starlink research findings presented at Black Hat!
B
Breaking Badness

113. Threat Actors DDoS a Line by DomainTools
B
Breaking Badness

112. A Fluid Situation by DomainTools
B
Breaking Badness

111. Neither Hide nor Malware by DomainTools
B
Breaking Badness

110. A Sad State of Malwares by DomainTools
B
Breaking Badness

109. The Big REvil by DomainTools
B
Breaking Badness

1 108. Malware is not my Cup of IoT 38:30
38:30
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:30
108. Malware is not my Cup of IoT by DomainTools
B
Breaking Badness

107. A Fraudster’s Scam Dunk by DomainTools
B
Breaking Badness

In Breaking Badness Episode 106, Taylor Wilkes-Pierce, Tim Helming, and Kelsey LaBelle discuss Project Zero’s deep dive into an NSO zero-click iMessage exploit and the impact and takeaways of the log4j vulnerability.
B
Breaking Badness

1 105. The Call Is Coming From Inside the House 39:22
39:22
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:22
105. The Call Is Coming From Inside the House by DomainTools
B
Breaking Badness

104. The Old Bait and Glitch by DomainTools
B
Breaking Badness

103. Malware and Tear by DomainTools
B
Breaking Badness

1 102. Tales of Justice, Cash, and Shrootlessness 34:20
34:20
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי34:20
Co-hosts Tim Helming, Chad Anderson, and Taylor Wilkes-Pierce discuss a $10M bounty on the DarkSide ransomware gang, and a critical Apple vulnerability Microsoft dubbed "Shrootless."
B
Breaking Badness

1 101. Ransomware and Malware and Justice, Oh My! 41:34
41:34
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי41:34
101. Ransomware and Malware and Justice, Oh My! by DomainTools
B
Breaking Badness

1 [Bonus Episode] Voices from Infosec On the Road: Regina Elwell and Alyssa Rahman 38:43
38:43
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:43
BB host Tim Helming was at the Mandiant Cyber Defense Summit recently, and caught up with two analysts, Regina Elwell and Alyssa Rahman. They describe their roles, how they got into infosec, and what they're researching at the moment.
B
Breaking Badness

100. The Big One Pundred by DomainTools
B
Breaking Badness

1 127. Like Shooting Phish in a Barrel 40:31
40:31
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי40:31
Episode 127 of Breaking Badness is now available. This week Tim Helming and Kelsey LaBelle discuss a new speculative execution attack called Retbleed along with a discussion on the Phuture of Phishing
B
Breaking Badness

1 126. Give ‘Em the Old RaaSleDazzle 43:34
43:34
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי43:34
Episode 126 of Breaking Badness is now available and the gang is back together! This week Taylor Wilkes-Pierce, Kelsey LaBelle, and Tim Helming discuss new exploits using Brute Ratel along with Maui ransomware attacks against the healthcare industry.
B
Breaking Badness

1 125 . Nobody Makes Me HertzBleed My Own Blood 46:33
46:33
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי46:33
Episode 125 of Breaking Badness is now available. This week Taylor Wilkes-Pierce, Tim Helming, and special guest Kali Fencl discuss Hertzbleed, the new family of side channel attacks, along with #ransomware used as a decoy to cover up malicious activity
B
Breaking Badness

Episode 124 of Breaking Badness is now available. This week Taylor Wilkes-Pierce, Kelsey LaBelle, and special guest Daniel Schwalbe discuss MIT’s research regarding Apple’s M1 chips along with the remote code execution vulnerability experienced by Atlassian’s Confluence servers.
B
Breaking Badness

Episode 123 of Breaking Badness is now available. This week Tim Helming and special guests Ian Campbell and Kali Fencl discuss vulnerabilities modzero discovered regarding the Meeting Owl Pro along with mitigations Microsoft shared to block attacks from the recently discovered zero-day flaw
B
Breaking Badness

1 122. Inside the Threat Actor’s Studio 44:43
44:43
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:43
This week Tim Helming, Kelsey LaBelle, and special guest Ian Campbell discuss the Justice Department’s policy changes regarding the Computer Fraud and Abuse Act (CFAA) along with ThreatLabz discovery of fraudulent #domains posing as Microsoft’s Windows 11 download portal.
B
Breaking Badness

1 121. IR You Afraid of the Dark Web? 34:15
34:15
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי34:15
This week Taylor Wilkes-Pierce, Tim Helming, and Kelsey LaBelle discuss CISA’s warning on MSPs along with a new phishing trick - but does it have staying power? Listen and find out
B
Breaking Badness

This week Taylor Wilkes-Pierce, Tim Helming, and Kelsey LaBelle discuss a recent DNS poisoning attack along with DLL hijacking used by a researcher to turn the tables on ransomware gangs.
B
Breaking Badness

1 119. A Steaming Cup of Malicious Javascript 45:28
45:28
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי45:28
This week Taylor Wilkes-Pierce, Tim Helming, and Kelsey LaBelle discuss recent DDoS attacks against Ukraine along with the recently discovered subgroups of the threat group known as TA410
B
Breaking Badness

1 118. Don’t Let Ransomware You Down 41:39
41:39
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי41:39
This week Taylor Wilkes-Pierce, Tim Helming, and Kelsey LaBelle discuss the Pipedream malware toolkit along with the recent seizure of the RaidForums website.
B
Breaking Badness

1 [Bonus Episode] Voices from Infosec with Harshil Parikh 52:37
52:37
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי52:37
[Bonus Episode] Voices from Infosec with Harshil Parikh by DomainTools
B
Breaking Badness

117. Fire in the Wall! by DomainTools
B
Breaking Badness

116. A Breach? I’m Afraid SSO by DomainTools
B
Breaking Badness

1 115. A Ransomware for the Dramatic 42:42
42:42
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי42:42
115. A Ransomware for the Dramatic by DomainTools
B
Breaking Badness

114. Domains of our Lives by DomainTools
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.