Skip to content
Artwork for Security Weekly Podcast Network (Video)
TechnologyNewsTech News

Security Weekly Podcast Network (Video)

Security Weekly Productions

Welcome to the Security Weekly Podcast Network, your all-in-one source for the latest in cybersecurity! This feed features a diverse lineup of shows, including Application Security Weekly, Business Security Weekly, Paul's Security Weekly, Enterprise Security Weekly, and Security Weekly News. Whether you're a cybersecurity professional, business leader, or tech enthusiast, we cover all angles of the cybersecurity landscape.

Tune in for in-depth panel discussions, expert guest interviews, and breaking news on the latest hacking techniques, vulnerabilities, and industry trends. Stay informed and secure with the most trusted voices in cybersecurity!

Play
  • 28 episodes
  • daily
  • Avg 1 hr 10 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Yesterday · 2 hr 4 min

    The Breached WiFi AI Ports... What? - PSW #939

    In the security news this week: • North Carolina ports and contingency plans • Back to paper and pencils • Midnight Blizzard compromises hotel Wi-Fi • DNS strikes again • Captive portals, stolen credentials, and nation-state scale • Phishing-resistant MFA • Goodbye SMS and voice authentication • Cornflake RAT and Chaco Shell • The NPM worm • Hundreds of compromised packages • AI lowers the barrier to mass exploitation • Rethinking "secure enough" • Back to basics: know what's on your network • Get off my PCI lawn Show Notes: https://securityweekly.com/psw-939

  • Wednesday · 1 hr 7 min

    Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Ihab Shraim, Greg Baker, Lynn Dohm - BSW #460

    As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company's IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team's research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks. Segment Resources: CSC 2026 Domain Security Report: https://www.cscdbs.com/en/resources/domain-security-report-2026/ CSC 2026 CISO Outlook Report: https://www.cscdbs.com/en/resources/ciso-outlook-2026-report/ How AI Is Reshaping What's Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased. Greg Baker will explore how AI can create a continuously updated understanding of both the enterprise security program and the market around it—giving CISOs the context to model scenarios, prioritize investments, and move from insight to action with greater speed and confidence. For more information about Balance Theory, please visit: https://securityweekly.com/balancetheorybh The Business Case for Cybersecurity Workforce Resilience - Black Hat Interview with Lynn Dohm, Executive Director of WiCyS The joint report from WiCyS and FourOne Insights reveals that mentorship, skills-based promotion, and third-party partnerships don't just improve workforce outcomes — they deliver measurable ROI, including more than $125,000 in savings per employee. As cybersecurity leaders grapple with persistent talent shortages, AI-driven skill shifts, and demographic headwinds, the report positions workforce resilience as a measurable business advantage — not just an HR initiative. Segment Resources: https://www.wicys.org/resources/the-roi-of-resilience/ https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/ This segment is sponsored by Women in CyberSecurity (WiCyS). Visit https://securityweekly.com/wicysbh to learn more about them! Show Notes: https://securityweekly.com/bsw-460

  • Tuesday · 1 hr 9 min

    Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

    Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: https://projectdiscovery.io/research/ai-coding-impact-report https://projectdiscovery.io/blog/oh-my-rogue-agent Show Notes: https://securityweekly.com/asw-395

  • Monday · 1 hr 37 min

    Three interviews: system fragility, operational clarity, and Identity for AI agents - Robin Macfarlane, Kyle Sandy, Todd Thiemann - ESW #471

    Interview 1: Robin Macfarlane from RRMac Associats The Mattress Money Principle: What a 50-Year Veteran Knows About System Fragility In this interview, Robin and Adrian discuss how technology has evolved over the past 50 years. Despite massive technological changes over the decades: the PC revolution, the Internet, smartphones, the Cloud, and now Generative AI - the majority of financial institutions still use mainframes and midrange machines. Why? We explore the reasons why older technology persists alongside the new and the lessons retiring technologists can pass on to new generations inheriting an increasingly diverse tech landscape. Interview 2 with Kyle Sandy from Logically Operational Clarity as the New Customer Experience Kyle Sandy joins Adrian to discuss how prioritizing resilience affects how organizations should plan for incident response. In the past, security teams were focused on prevention and limiting breach damage. Today, boards want to know how long it will take to recover operations. The interview wraps up with a discussion of the right and wrong way to handle a breach and the three most important things every company must get right in order to handle an incident well. Interview 3 with Todd Thiemann from Omdia AI Agents and Identity Security: How Enterprises Are Rewriting the Rules Todd joins ESW with some eye-opening survey insights on the topic of IAM for AI agents. While cybersecurity conversations about internal AI use often revolve around the SOC and security operations, Omdia surveyed identity professionals for a more holistic enterprise perspective. Unsurprisingly, AI agent use is as diverse as enterprise business units. The surprises are around where the budget comes from for these AI projects, and how authentication is handled. Show Notes: https://securityweekly.com/esw-471

  • August 6 · 1 hr 58 min

    When AI Commits Felonies - PSW #938

    This week: When you are not at summer camp you can't read about it The Fettle continues Using the CFAA against AI Social contracts are not security models VSCode extentions, again Bugtraq is back! NVIDA, LVFS, and unraveling AI infrastructure More routers that come with backdoors Do we care about LPE? Even more AI that finds vulnerabilities When AI breaks its own guardtails Show Notes: https://securityweekly.com/psw-938

  • August 5 · 50 min

    Say Easy, Do Hard - Performance Through People - Greg Hoffman - BSW #459

    This week, we air our thirteenth pre-recorded segment called "Say Easy, Do Hard". Inspired by my co-host, Jason Albuquerque, we discuss "Performance Through People". Greg Hoffman joined us a few weeks back to discuss his new book. This week, we dig into his five disciplines of Performance Through People and do the hard part. Show Notes: https://securityweekly.com/bsw-459

  • August 4 · 1 hr 3 min

    Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394

    There's already an increase in volume of security flaws found by LLMs. And orgs are already turning to LLMs to write code. So, what happens when orgs lean on LLMs to create patches for those security flaws? Keith Hoodlet gives an exclusive early look at his team's recent research into the success, quality, and failures of LLM-generated security patches. Notably, they saw scenarios across a spectrum from robust, effective patches to patches that changed the software's behavior to patches that introduced new vulns to patches that didn't even fix the original vuln while also introducing a new vuln. The research considers factors like quality and correctness of prompts, complexity of the target software, programming language, and expertise required to understand what a robust patch should look like. If you're going to spend tokens on fixing security flaws, you want a feedback loop that fixes them correctly -- not an infinite loop of new flaws creeping in with every LLM iteration. Watch for this research, its toolset, and data to be released on Thursday August 6th during Black Hat. Show Notes: https://securityweekly.com/asw-394

  • August 3 · 1 hr 37 min

    AppSec, Shopify-Style; State of Mobile Security; the News - Andrew Dunbar, Kern Smith - ESW #470

    Interview with Andrew Dunbar, CISO at Shopify After 13 years at Shopify, Andrew has some valuable insights to share on application security. In this episode, we discuss how AI has changed application security processes where bug bounty now fits in a post-Mythos, post-AI harness world. Andrew's Resources: https://shopify.engineering/building-an-agentic-harness-that-outlasts-the-model Interview with Kern Smith Kern Smith, VP of Global Solutions at Zimperium, joins us to talk about the state of mobile security. This was a great conversation, talking about the history of mobile devices in the enterprise and how challenging securing mobile apps is in the age of vibe-coding. Segment Resources https://zimperium.com/resources/new-zimperium-research-reveals-that-ai-based-attacks-are-targeting-and-succeeding-on-mobile Global Mobile Threat Report 2026 Enterprise Security News Finally, in the enterprise security news, Pre-black hat funding goes nuts we have 4 new cybersecurity unicorns! Cyera acquires Oasis for one BILLION dollars Lots of new product announcements with hacker summer camp next week Hugging Face got hacked by a competitor's agent and are cool with it? Finding out that wiping a burner phone is illegal the week before DEF CON is not ideal Are open, local models the future of AI? AI isn't coming for your job lots of vendor reports bad cybersecurity takes are apparently mainstream memes now??? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-470

  • July 30 · 2 hr 5 min

    Sandwich Hats - PSW #937

    In the security news: 2.2 million cars, one shared Bluetooth key JFrog tries to spin an AI 0-day into a win Sextortion scammers recycling ShinyHunters' leaks The first hack ever, from 1966 Prompt injection as a service, $150 a month Cisco's mystery "static credential" BMCs still on the internet, still handing out hashes Scattered Spider duo sentenced over the TfL hack Air-gapped data sneaking out over the video cable A ghost in the network DNS poisoning checks into hotel WiFi Microsoft's cut-rate cybersecurity AI Learning to trust USB drives again Agentic pentesting shows up just in time for Black Hat Microsoft rethinks security for the AI age, again Show Notes: https://securityweekly.com/psw-937

  • July 29 · 41 min

    Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458

    Since the pandemic, managing remote teams have been challenging. How do you measure performance and motivate teams when they are remote? Charles Gaudet, CEO & Founder at Predictable Profits, joins Business Security Weekly to discuss why transparency is the key to team motivation for remote workers. Charles will discuss how culture and performance metrics create that transparency. He will also discuss how to motivate your team based on their personality type. Segment 1 Resources: https://www.PredictableProfits.com Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Show Notes: https://securityweekly.com/bsw-458

  • July 28 · 1 hr 9 min

    Inside the OWASP Agent Security Regression Harness Project - Mert Satilmaz - ASW #393

    Orgs need to be able to use agents, MCPs, and LLMs in ways that don't lead to unexpected actions and undesirable outcomes. The OWASP Agent Security Regression Harness project is an approach for defining customizable scenarios and testing whether those systems fail against known security threats. Mert Saltimaz talks about the background of the project, how orgs can use it as they bring more LLMs into their environment, and how the project intends to grow. Importantly, we also talk about the security controls and designs that orgs can build around the systems and data that models interact with in addition to evaluating the security of the agents and agent harnesses themselves. Segment Resources: https://github.com/OWASP/Agent-Security-Regression-Harness https://youtu.be/6DWs5EwbFQ0?si=r0IJ_F0SZnkPzzYg -- "What Trading Systems Taught Me About Breaking (And Defending) Infrastructure" Show Notes: https://securityweekly.com/asw-393

  • July 27 · 1 hr 50 min

    Exploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - O'Shea Bowens, Jeremiah Grossman - ESW #469

    Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company's roadmap. The move from chatbots to AI agents doubled down on that disruption. Now agents need to talk to each other? Boom: we have MCP. A2A. Universal Commerce Protocol. General purpose and specialized protocols for agent communication. What does this look like from the network perspective, though? O'Shea Bowen joins us to answer this question, and he thinks the results are interesting enough to spark a resurgence of interest in network security tooling. Segment Resources: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSIMCPSECURITY.pdf?ver=bmgiSbNQLP6Z_GiWtRt6bg%3D%3D https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ https://cyberone.security/blog/building-an-ai-security-strategy-without-stalling-business-growth Segment 2 - Interview with Jeremiah Grossman Jeremiah Grossman on why we've been measuring cyber risk wrong for 20 years After decades helping shape modern web security, and building companies that were ultimately acquired by Synopsys and Tenable, Jeremiah Grossman believes cybersecurity has arrived at an inflection point. His argument is a provocative one: for years, the industry has optimized around the wrong metrics. His latest venture, Root Evidence, aims to help security teams identify which risks are most likely to cause meaningful business loss, and he has the evidence - real-world breach data, cyber insurance claims, digital forensics intelligence, attack surface intelligence, and observed attacker behavior - to back it up. Find all of CyberRisk TV's Black Hat 2026 coverage at: https://www.securityweekly.com/blackhat Segment 3 - Weekly Enterprise News Finally, in the enterprise security news, We vibe check the AI model situation hidden devices in California cars causes concerns OpenAI's models escape sandboxes and breaches another AI company, totally by accident, they promise! Grok Build uploads all your files, totally by accident, they promise! Eclipsium debuts a firmware version of patch tuesday! HTTP gets a new method common problems with incident response Which one of the security weekly hosts would consider switching to a "dumb phone"? All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-469

  • July 23 · 2 hr 2 min

    Fixing Vulns Is Harder Than Finding Them - PSW #936

    In the news this week: InfraTrust and knowing what to patch Adversary in the middle triggered command injection Exploitarium again FreeRDP comes with free vulnerabilities AI breaking out of sandboxes on its own Wordpress RCE DMA dangers Nightmware eclypse is at it again Fortisandbox Turning AI to the dark side more prompt injection Secure boot is broken, still and again... Show Notes: https://securityweekly.com/psw-936

  • July 22 · 58 min

    AI's Disruption as Cybersecurity's Economics Are Broken, Compounding Security Debt - Ben Gilliland - BSW #457

    America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American history? Ben Gilliland, author of the upcoming book Breaking the Compact, joins Business Security Weekly to discuss why business leaders need to be prepared for the upcoming AI disruption. The impact of AI, which has not fully materialized, goes far beyond security and job displacement. It will impact our economy, our privacy, and our way of life. The closest recent warning is the "China shock," the period of rapidly increasing import competition that followed China's integration into the global trading system. AI will dwarf that. Ben will discuss the human advantage and how we can prepare now. In the leadership and communications segment, Cybersecurity's Economics Are Broken. Automation Alone Won't Fix It, The business case for burning down security debt: A practical approach for CISOs, The last human relationship in cybersecurity, and more! Show Notes: https://securityweekly.com/bsw-457

Showing 1–20 of 28 episodes