Artwork for Decipher Security Podcast
Technology

Decipher Security Podcast

Decipher

Every week, Dennis Fisher and Lindsey O'Donnell-Welch, the editors of Decipher, bring you exclusive, in-depth conversations with security researchers, CISOs, founders, and security experts to hellp you understand the threat landscape and better protect your organizations.

  • 370 episodes
  • Updated Friday

Episodes370

  • Jul 8, 2022 · 5 min

    Source Code 7/8

    Welcome back to this week’s Source Code podcast by Decipher, where we go over the top security news of the week with input from our sources. This week, we discuss the U.S. government's warning that North Korean-backed actors are using the Maui ransomware to target health care and public health organizations; a software supply-chain attack involving packages hosted on the NPM Package Manager; and the new Hive ransomware variant. Support the show

  • Jul 6, 2022 · 1 hr 1 min

    Joe Grand

    Dennis Fisher talks with Joe Grand, renowned hardware hacker and member of the L0pht, about his recent work hacking hardware crypto wallets, hacking culture, and why curiosity matters. Support the show

  • Jul 1, 2022 · 6 min

    Source Code 7/1

    Welcome back to another episode of our weekly Source Code news wrap podcast. This week, Gustavo Palazolo with Netskope talks about how Emotet attackers are still skirting Microsoft's VBA macros security measures while using old delivery methods, and John Hultquist with Mandiant talks about why a Chinese information operations campaign targeted rare earths mining companies in the U.S. Support the show

  • Jun 28, 2022 · 27 min

    John Hultquist

    John Hultquist, VP of Mandiant Intelligence, talks about new Mandiant research that exposes a Chinese information operation campaign targeting U.S., Canadian and Australian rare earths mining companies, including a processing facility in Texas, and how these types of information operations can be detrimental to private companies. Support the show

  • Jun 24, 2022 · 6 min

    Source Code 6/24

    In this week's Source Code podcast, Forescout researchers discuss the impact of 56 vulnerabilities that they discovered in operational technology (OT) devices, and Cisco Talos researchers talk about the top takeaways from a recently exposed AvosLocker ransomware campaign. Support the show

  • Jun 21, 2022 · 39 min

    Decipher Podcast: Daniel dos Santos

    Daniel dos Santos, head of security research with Forescout, talks about a set of over 50 vulnerabilities discovered in operational technology (OT) devices from 10 different vendors, and why patching levels are so low for OT. Support the show

  • Jun 17, 2022 · 6 min

    Source Code 6/17

    Welcome back to Source Code, Decipher’s weekly news wrap podcast. This week, researchers exposed a spear-phishing campaign that targeted several high-ranking officials from the U.S. and Israel. Also this week, Microsoft issued a patch for a previously disclosed RCE vulnerability that has been under active exploitation by attackers. Finally, researchers discuss a recently discovered malware family that they say is “highly evasive.” Support the show

  • Jun 3, 2022 · 7 min

    Source Code 6/3

    On this week's Source Code podcast, security experts discuss attacker exploitation of a vulnerability in certain WSO2 products, a Microsoft zero day in many current versions of Office, Office 365, and Windows, and new research that shows attackers getting quicker at launching ransomware attacks against enterprises. Support the show

  • May 20, 2022 · 5 min

    Source Code 5/20

    Welcome back to Source Code, Decipher’s weekly news wrap podcast. This week, we go over a landmark change to the Computer Fraud and Abuse Act, a serious remote code execution bug in Zyxel firewall products and an emergency directive that orders civilian executive branch agencies to apply updates for several VMware products within five days. Support the show

  • May 13, 2022 · 6 min

    Source Code 5/13

    Welcome back to Source Code, Decipher’s weekly security news podcast. This week, the State Department said it will offer rewards for more information for the Conti group. Also this week, cybersecurity agencies from the U.S, UK, Australia, Canada and New Zealand warned that cybercriminals are increasingly targeting managed service providers. Finally, researchers released more details on a sophisticated post-exploitation framework being deployed on Microsoft Exchange server instances. Support the show

  • May 6, 2022 · 4 min

    Source Code 5/6

    In this week's Source Code podcast, Decipher discusses plans by GitHub to require anyone who contributes code on the platform to use some form of MFA by the end of next year. Also in this week's podcast, researchers talk about a newly discovered threat group that targets companies focusing on corporate development, mergers and acquisitions and large corporate transactions. Support the show

  • May 4, 2022 · 37 min

    Jonathan Reiber

    Lindsey O'Donnell-Welch speaks with Jonathan Reiber, Vice President, Cybersecurity Strategy and Policy at AttackIQ. Support the show

  • Apr 29, 2022 · 8 min

    Source Code 4/29

    In this week's Source Code podcast, Decipher looks at a novice, sophisticated malware loader and a new tactic being used by the BlackCat ransomware to speed up its encryption process. Support the show

  • Apr 26, 2022 · 36 min

    Don Smith

    Don Smith of the Secureworks CTU joins Dennis Fisher to discuss the effects of the Conti leaks, the ransomware landscape, and how law enforcement and researchers are countering attackers' ploys. Support the show

  • Apr 22, 2022 · 6 min

    Source Code 4/22

    Topping this week's Source Code podcast, Lenovo released security updates addressing vulnerabilities related to Unified Extensible Firmware Interface (UEFI) firmware drivers in its products. Also, the U.S. government warned of recent Lazarus APT campaigns and the BlackCat ransomware-as-a-service. Finally, Decipher this week talked to Justine Bone, CEO of MedSec, about the challenges of securing medical devices. Support the show

  • Apr 19, 2022 · 37 min

    Justine Bone

    Justine Bone, CEO of MedSec, discusses the security threats that hospitals and healthcare providers face, and the challenges of securing medical devices. Support the show

  • Apr 11, 2022 · 37 min

    Martin Roesch

    Martin Roesch, CEO of Netography and creator of Snort and former CEO of Sourcefire, joins Dennis Fisher to talk about why he decided to come out of retirement and what the big challenges are for security right now. Support the show

  • Apr 8, 2022 · 5 min

    Source Code 4/8

    Welcome back to Source Code, Decipher’s weekly news podcast with input from our sources. In this week’s podcast, a Ukrainian man was sentenced to five years in jail this week for his work with the financially motivated FIN7 cybercrime group, which researchers with Mandiant in an analysis revealed continues to evolve its tactics for initial access, first-stage malware delivery and more. Also this week, Meta announced it disrupted two separate cyberespionage groups from Iran that were using a variety of tactics on its platforms to target academics, activists, journalists and other victims. Support the show

  • Apr 5, 2022 · 47 min

    Tazin Khan

    Tazin Khan, founder of Cyber Collective, joins Dennis Fisher to talk about the ethos behind the group's work and the challenges of educating people about the safest ways to use technology. Support the show

  • Apr 1, 2022 · 6 min

    Source Code 4/1

    Topping the news in this week's Source Code podcast were several security warnings and alerts from the U.S. government, including a phishing attack that targeted U.S. election officials, and attacks on UPS devices. Also this week, researchers warned of an IcedID malware attack leveraging compromised Microsoft Exchange servers to send phishing emails. Support the show