Artwork for Decipher Security Podcast
Technology

Decipher Security Podcast

Decipher

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.

  • 370 episodes
  • Updated Friday

Episodes370

  • Apr 6, 2023 · 43 min

    Mike Hanley

    Mike Hanley, CSO and SVP of engineering at GitHub, joins Dennis Fisher to talk about the company's move to enforce 2FA for all developers, the changing role of the CISO, and what's ahead for software supply chain security. Support the show

  • Mar 13, 2023 · 48 min

    Chris Wysopal

    Chris Wysopal, CTO and founder of Veracode, joins Dennis Fisher to dive into the new White House National Cybersecurity Strategy and discuss what's missing, how practical the pillars are, and when these ideas may be implemented. Support the show

  • Mar 9, 2023 · 36 min

    Courtney Nash

    Courtney Nash joins Dennis Fisher to talk about the 2022 VOID Report on incidents, why mean time to resolve is no longer a meaningful metric, whether the duration of an incident matters, and how organizations can get better at responding to an analyzing incidents. Support the show

  • Mar 3, 2023 · 50 min

    Andrew Morris

    Andrew Morris, the founder and CEO of GreyNoise, joins Dennis Fisher to talk about software liability, the evolution of the security industry, and why we're not getting better at securing our systems. Support the show

  • Feb 3, 2023 · 46 min

    Michelle Finneran Dennedy

    Michelle Finneran Dennedy, co-founder of Privacy Code and co-author of The Privacy Engineer's Manifesto, joins Dennis Fisher to talk about her new startup, her path from studying psychology to becoming the first chief privacy officer at Sun and Cisco, and what everyone gets wrong about privacy. Support the show

  • Jan 11, 2023 · 39 min

    Chris Eng on the 2023 State of Software Security Report

    Chris Eng, chief research officer at Veracode, joins Dennis Fisher to discuss the company's new State of Software Security report, whether we're getting better at fixing bugs, and the fragility of open source projects an the software supply chain. Support the show

  • Dec 22, 2022 · 53 min

    Deciphering Home Alone

    Kevin McCallister may not be a hacker or even own a computer (as far as we know), but no one embodies the hacker ethic better than he does, an eight-year-old boy left alone at Christmas who is forced to use his imagination and creativity to defend a prime target and lure his adversaries into his trap. This is Deciphering Home Alone. Support the show

  • Dec 14, 2022 · 50 min

    Andy Greenberg

    Wired journalist and author Andy Greenberg joins Dennis Fisher to discuss his new book Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency, which tells the stories of the agents, academics, and security experts who tracked the admins of the Silk Road, AlphaBay, and other darknet markets through specialized blockchain tracing techniques. Support the show

  • Dec 6, 2022 · 47 min

    Haroon Meer Returns

    Haroon Meer of Thinkst joins Dennis Fisher to talk about the state of the security industry, the value of treating customers with respect, and what the economic downturn could mean for the security community. Support the show

  • Nov 18, 2022 · 6 min

    Source Code 11/18

    Welcome back to the Source Code news wrap podcast. This week, we discuss recent changes to the Emotet malware and vulnerabilities disclosed in F5 BIG-IP appliances. Support the show

  • Nov 16, 2022 · 38 min

    Dan Lorenc

    Dan Lorenc, CEO and founder of Chainguard, joins Dennis Fisher to talk about supply chain security, asset inventory, Sigstore, and the challenges of helping developers write more secure code. Support the show

  • Nov 4, 2022 · 5 min

    Source Code 11/4

    Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources. This week's podcast looks at a new analysis linking Black Basta ransomware to FIN7 tools, the release of a new OpenSSL version addressing high-severity flaws and top findings about the adoption of authentication methods highlighted in the 2022 Duo Trusted Access report. Support the show

  • Nov 3, 2022 · 31 min

    Dave Lewis

    Dave Lewis, Global Advisory CISO at Cisco, talks about the top takeaways of the 2022 Duo Trusted Access Report and the driving factors behind increased adoption of WebAuthn, MFA and biometrics. Support the show

  • Oct 28, 2022 · 4 min

    Source Code 10/28

    Welcome to Source Code: Decipher's behind the scenes look at the weekly news with input from our sources. In this week's podcast, we discuss a government agency alert for healthcare providers about the Daixin group, a new FTC proposed order against Drizly and a set of voluntary performance goals for critical infrastructure organizations released by CISA. Support the show

  • Oct 26, 2022 · 40 min

    Kelley Misata

    Kelley Misata, senior director of open source of open source at Corelight and CEO of Sightline Security, joins Dennis Fisher to talk about her road to get into security, the importance of protecting at-risk populations, and the challenges of building community in the open source world. Support the show

  • Oct 21, 2022 · 4 min

    Source Code 10/21

    In this week's Source Code news wrap podcast, we discuss a critical remote code execution flaw in certain versions of the Apache Commons Text library; recent efforts by Fortinet to encourage organizations to apply patches for a vulnerability in its products that is under attack; and a new variant of Ursnif that has been reconstructed from a banking trojan into a generic backdoor. Support the show

  • Oct 20, 2022 · 38 min

    Martin Roesch Returns

    Martin Roesch, CEO of Netography, joins Dennis Fisher to talk about the evolution of network security, protecting hybrid computing environments, and where that Snort pig couch came from. Support the show

  • Oct 14, 2022 · 6 min

    Source Code 10/14

    Welcome back to Source Code, Decipher’s weekly news wrap podcast. Highlights from this week’s security news lineup include a newly discovered flaw in some Siemens S7 PLCs, and Log4j attacks by the known Budworm threat group targeting an unnamed U.S.-based state legislature. Support the show

  • Oct 12, 2022 · 23 min

    David Agranovich

    David Agranovich, director of threat disruption with Meta, discusses how threat groups are evolving their inauthentic behavior on social media platforms, as well as recent cyber espionage and malware activity highlighted in Meta’s adversarial reports. Support the show

  • Oct 7, 2022 · 5 min

    Source Code 10/7

    Welcome back to Source Code, Decipher’s weekly news wrap podcast. This week, new research showed the Lazarus Group leveraged a rootkit in two attacks that abused a known vulnerability in a Dell driver in order to disable various Windows monitoring features. Also this week, a new government directive required federal agencies to set up measurable processes needed to perform automated asset discovery and vulnerability detection at regular intervals. Finally, analysts released research into the Bumblebee malware loader, which is a relatively new malware loader that first emerged in March. Support the show