Artwork for The 443 - Security Simplified
News

The 443 - Security Simplified

Secplicity

Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cybersecurity headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into easily understood and actionable insights.

  • 386 episodes
  • Updated Monday

Episodes386

  • May 3, 2021 · 39 min

    What Is Same-Origin Policy?

    This week on the podcast, we mourn a Dan Kaminsky, a well-loved hacker responsible for identifying one of the biggest vulnerabilities in the history of the internet. Then, we continue our dive into web app security standards with a discussion on Same-Origin Policy and Cross Origin Resource Sharing (CORS) and how they help protect us against Cross Site Request Forgery (CSRF) attacks.

  • Apr 28, 2021 · 37 min

    Cellebrite Good Times

    This week on the podcast, we cover Signal CEO Moxie Marlinspike's analysis of a phone forensic analysis tool made by the grey-hat hacking organization Cellebrite. Before that though, we cover another solved mystery from the SolarWinds Orion saga.

  • Apr 21, 2021 · 27 min

    On A Tuesday

    This week on the podcast we cover a couple of major events from April's Patch Tuesday including four new remote code execution vulnerabilities in Exchange Server and some additional developments in the saga of March's Exchange Server exploits.

  • Apr 14, 2021 · 1 hr 8 min

    Combating Disinformation with Nina Jankowicz Rewind

    This week on the podcast, we go back to one of our favorite episodes from last year near the start of the pandemic where we sat down with security expert Nina Jankowicz to discuss what the rapid change to remote work would mean for security.

  • Apr 8, 2021 · 1 hr 4 min

    Q4 2020 Internet Security Report

    Its that time of year again! This week on the podcast we dive in to the latest internet security report out of the WatchGuard Threat Lab. We'll cover the latest trends in malware, both at the perimeter and the endpoint, as well as network attacks and malicious domains. Additionally, we'll recap the top security incident from Q4, the Solar Winds Breach, and what it means for companies going forward.

  • Mar 30, 2021 · 49 min

    What Is Content Security Policy?

    This week on the podcast we take a look at Content Security Policy, a web app security standard designed to combat Cross Site Scripting attacks against websites and web apps. Before that though, we'll cover the latest security news including a resurgence in ransomware attacks and the long overdue death of TLS versions 1.0 and 1.1.

  • Mar 23, 2021 · 41 min

    Defense Tips from a Pentester

    This week on the podcast we cover key findings from the 2020 FBI Internet Crime Report and the latest reflective amplification vector for DDoS attacks. Then, we discuss a recent blog post from penetration tester Fabian Mosch that details the top weaknesses they target during their engagements. You can read more from Fabian here.

  • Mar 17, 2021 · 49 min

    Popping Webmail Shells

    This week on the podcast we take a deep dive into the Exchange Server vulnerabilities that Microsoft issued an emergency patch for after discovering foreign adversaries were actively exploiting the flaws in the wild. We'll go over the vulnerabilities, how they work, and give some tips for defending against similar attacks in the future.

  • Mar 9, 2021 · 39 min

    Hacked by Cosmic Rays

    This week on the podcast we cover Gootkitand Gootloader, two oddly-named pieces of an evasive trojan that researchers have been watching evolve into a fileless threat. We also discuss the security benefits and drawbacks of Apple's closed-door approach to security. Finally, we end with some research on what happens when a cosmic ray causes your computer to load up the wrong destination for a network connection.

  • Mar 3, 2021 · 36 min

    Microsoft Says “Regulate Us”

    This week on the podcast we cover an upcoming Chrome browser update with important behind-the-scenes changes, a 9.8/10 severity vulnerability in VMWare vCenter, and a plea from Microsoft for more breach disclosure regulation in the wake of the SolarWinds breaches.

  • Feb 24, 2021 · 31 min

    RIPE for the Taking

    This week on the podcast, we chat about an authentication attack against one of the world’s internet address registrars, another Russian threat actor targeting a popular IT software company, and research on a credential theft trojan and its delivery methods.

  • Feb 18, 2021 · 30 min

    So Confused

    This week on The 443, we cover a cyber-attack against the water supply of a small Florida town and research into a new class of vulnerabilities in software libraries called Dependency Confusion.

  • Feb 11, 2021 · 31 min

    CacheFlow

    This week on the podcast, we cover the latest research from Avast on evasion techniques in use by malicious Chrome extensions. After that, we discuss the latest report from Google's Threat Analysis Group on nation-state threat actors targeting white hat security researchers.

  • Jan 26, 2021 · 45 min

    It’s Always DNS

    This week on the podcast, we bring on Trevor Collins from the WatchGuard Threat Lab to chat about a the recently disclosed MalwareBytes breach and a series of vulnerabilities in a popular DNS forwarder, dubbed DNSPOOQ.

  • Jan 19, 2021 · 35 min

    AppleScryptominers

    This week on the podcast, we cover a cloud security alert courtesy of Cybersecurity & Infrastructure Security Agency (CISA) and encrypted DNS guidance from the NSA. We also discuss a macOS malware evasion technique that has eluded analysis for over 5 years, until now.

  • Jan 11, 2021 · 40 min

    The Hack of the Decade

    This week on the podcast we dive into what will likely be remembered as the hack of the decade. With victims including dozens of Fortune 500 companies and US Federal agencies, the SolarWinds supply chain breach has had a massive impact on the industry and as the potential to change client/vendor trust relationships going forward.

  • Dec 28, 2020 · 45 min

    Biohacking with Amal Graafstra Rewind

    Happy Holidays! This week on the podcast, we're going back to one of our favorite episodes from 2019 where we sat down with Biohacking pioneer Amal Graafstra to discuss implants, RFID technology and the future of human/technology interactions.

  • Dec 7, 2020 · 33 min

    2021 Security Predictions

    This week on the podcast, we jump in to WatchGuard Threat Lab's 2021 security predictions. From automated spear phishing to booby-trapped electric vehicle chargers, we'll discuss each of the 8 predictions we made and why we made them. You can read about the predictions in full at watchguard.com/predictions.

  • Nov 30, 2020 · 33 min

    2020 Predictions Recap

    Every November, WatchGuard Threat Lab tries to make predictions about potential security events in the coming year. While some predictions might come off as a bit extreme, they're all grounded in actual trends that we see and expect to continue. With 2020 almost under wraps, its time for us to look back to the predictions we made one year ago and grade ourselves on how well we did.

  • Nov 23, 2020 · 31 min

    Securing SMBs with John Grady

    This week on the podcast, we sit down with ESG Analyst John Grady again, this time to chat about the topic of SMB Security. We'll cover how the cyber threat landscape has changed throughout 2020 and what SMBs got right, and wrong when it came to adapting.