Artwork for The 443 - Security Simplified
News

The 443 - Security Simplified

Secplicity

Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cybersecurity headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into easily understood and actionable insights.

  • 386 episodes
  • Updated Yesterday

Episodes386

  • Aug 29, 2022 · 33 min

    The Twitter Thing

    This week on the podcast, we cover the big whistleblower complaint against Twitter including our hot takes on who to believe. We then cover an FBI alert on evasion techniques cyber criminals are deploying in their authentication attacks before finishing with a highlight of a very convincing phish.

  • Aug 22, 2022 · 53 min

    2022 Black Hat and Def Con Recap

    This week on the podcast we review our time at this year's Black Hat and Def Con cybersecurity conferences in Las Vegas. We'll cover how the WatchGuard CTF contest went this year and discuss takeaways from a few of the briefings we attended.

  • Aug 9, 2022 · 36 min

    Hacker Summer Camp 2022

    This week on the podcast, we give our preview of the Black Hat and Def Con cybersecurity conferences, aka Hacker Summer Camp. Throughout the episode, we'll discuss the briefings and panels we're most excited to see and what we hope to get out of them. If you're not able to attend either conference in person this year, be sure to watch the Def Con Youtube channel for recordings! Also, check out our capture the flag contest at WGCTF.com!

  • Aug 2, 2022 · 35 min

    Private Sector Offensive Actors

    This week on the podcast we discuss the shifting landscape of phishing attacks in the wake of Microsoft's efforts to block malicious Office macros. We then cover a private organization that has been found not just selling exploit tools but also participating in offensive cyber operations. We end the episode with a review of IBM and the Ponemon Institute's Cost of a Breach Report for 2022.

  • Jul 25, 2022 · 37 min

    USA’s Answer to GDPR

    This week on the podcast, we discuss the current cyber skills gab and a federal program designed to help combat it. After that, we dive in to the American Data Privacy protection Act and what it potentially means if passed by US Congress. We end this week with a quick update on Microsoft's attempts to protect users from malicious macro-enabled documents.

  • Jul 21, 2022 · 49 min

    Rolling PWN

    This week on the podcast we cover the latest in car hacking research, this time targeting vulnerabilities in remote keyless entry. We then dive in to Microsoft's latest research on Adversary in the Middle (AitM) attacks and end with key findings from the latest WatchGuard Threat Lab quarterly Internet Security Report.

  • Jun 27, 2022 · 48 min

    Grading Gartner’s Guesses

    This week on the podcast, we discuss two recent security reports, one on the topic of open source software and the other on "insecure by design" in the Operational Technology (OT) space. We go through the key findings from each report and what our thoughts are on their accuracy within the real world. We end the week by covering Gartner's 8 security prediction from their Security and Risk Management summit last week and what we think their likelihood of hitting are in the years to come.

  • Jun 21, 2022 · 1 hr 14 min

    200th Episode Extravaganza

    In celebration of our 200th episode, this week on the podcast we take a look back at the last few years and revisit some of our favorite episodes. Along the way, we'll give updates on a few of our cybersecurity predictions from years past that took just a little bit longer than anticipated to come true. Finally, we end with a round of Q & A and a few quick news updates.

  • Jun 14, 2022 · 39 min

    Robux Ransomware

    This week on the podcast we cover the latest and most bizarre ransomware extortion demand we've seen in recent memory. Before that though, we cover the latest updates on nation state hacking activity including threats of escalating attacks leading to physical retaliation.

  • Jun 9, 2022 · 31 min

    0-Days for Days

    This week on the podcast we cover two fresh 0-day vulnerabilities, one in Windows and another in Atlassian's Confluence, both under active exploitation in the wild. Additionally, we cover Costa Rica's no good, terrible month in Cybersecurity.

  • May 31, 2022 · 38 min

    Package Hijacking

    This week on the podcast, we discuss the line between ethical security research and malicious activity thanks to a compromised open source software package. After that we cover the latest industry to fall victim to Ransomware and end by highlighting a 0-click vulnerability in Zoom’s message system discovered by Google Project Zero.

  • May 23, 2022 · 45 min

    Building Security Strategies with Matt Lee

    This week on the podcast we sit down for a chat with Matt Lee, Sr. Director of Security and Compliance at Pax8 and well-known cyber security educator, to discuss security strategies for MSPs and midsize enterprises in the face of a dynamic threat landscape. We cover everything from picking a framework to getting buy in from stakeholders and take a forward look at what future cyber regulations may look like to all organizations.

  • May 17, 2022 · 42 min

    CISA Guidance for MSPs

    This week on the podcast we walk through CISA alert AA222-131A which gives bulleted guidance to MSPs and customers of MSPs on how to navigate their relationship security as threats targeting service providers continue to grow. We'll walk through the list and hit each recommendation and give our own guidance on top of them for both MSPs and their customers. After that, we cover the the latest Microsoft patch Tuesday and end the episode with the latest updates on SAT COM hacking.

  • May 9, 2022 · 35 min

    The REturn of REvil?

    This week on the podcast we discuss the latest rumblings around the return of the prolific ransomware-as-a-service organization REvil. Before that though, we dive in to the latest tools, tactics and procedures of the Lazarous nation state hacking group as well as a recently discovered form of fileless malware evasion.

  • May 2, 2022 · 49 min

    Most Exploited Vulnerabilities of 2021

    This week on the podcast, we dive into CISA's list of the 15 most exploited vulnerabilities in 2021. We'll walk through each flaw and give a refresher on their history and how attackers have exploited them. After that, we cover the latest ransomware-as-a-service threat that has victimized over 60 organizations worldwide before ending with a quick chat about our "favorite" topic, NFTs.

  • Apr 26, 2022 · 39 min

    Psychic Signatures

    This week on the podcast we cover a critical and easily-exploited vulnerability in how some recent versions of Java handle cryptography. We also discuss the latest in a series of alerts from CISA and international intelligence organizations on cyber threats to critical infrastructure. Finally, we end with a condensed overview of the latest internet security report from the WatchGuard Threat Lab.

  • Apr 18, 2022 · 35 min

    Hidden Hafnium

    This week on the podcast, we cover the latest evasion and persistence techniques from the state-sponsored threat actors known as Hafnium. Then, we dive into the world of ICS and SCADA devices to discuss the latest joint-agency alert from the US Government. We then round out the episode by highlighting some recent research into spoofing using Unicode BiDi (Bi-Directional) characters.

  • Apr 4, 2022 · 35 min

    Patch Management Lag

    This week on the podcast we discuss one of the most rampant yet easily resolved risks facing many organizations today, not installing vendor-supplied security fixes. We'll cover some of the reasons why organizations might fall behind on patching as well as the potentially serious consequences. After that, we cover the latest 0-day Chromium vulnerability before a quick chat about the latest in US cybersecurity legislation.

  • Mar 28, 2022 · 37 min

    The Rise and Fall of Lapsus$

    This week on the podcast we cover the hacking organization Lapsus$ including their tactics, targets, and how they ended up with several members arrested last week. After that, we cover the cyber cold war and threats of Russian revenge attacks against the US energy sector that prompted classified meetings with potentially targeted organizations.

  • Mar 21, 2022 · 31 min

    SATCOM Security

    This week on the podcast, we cover a CISA alert on securing satellite communications (SATCOM) in the wake of several recent incidents involving providers and networks in eastern Europe. After that, we check in on the TSA's cybersecurity rules for pipeline distribution networks and how adoption is going so far in the industry.