Episodios

  • Malware Laced Printer Drivers - PSW #875
    May 22 2025

    This week in the security news:

    • Malware-laced printer drivers
    • Unicode steganography
    • Rhode Island may sue Deloitte for breach. They may even win.
    • Japan's active cyber defense law
    • Stop with the ping
    • LLMs replace Stack Overflow - ya don't say?
    • Aggravated identity theft is aggravating
    • Ivanti DSM and why you shouldn't use it
    • EDR is still playing cat and mouse with malware
    • There's a cellular modem in your solar gear
    • Don't slack on securing Slack
    • XSS in your mail
    • SIM swapping and the SEC
    • Ivanti and libraries
    • Supercomputers in space!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-875

    Más Menos
    2 h y 2 m
  • Ransomware in your CPU - PSW #874
    May 15 2025

    This week in the security news:

    • Android catches up to iOS with its own lockdown mode
    • Just in case, there is a new CVE foundation
    • Branch privilege injection attacks
    • My screen is vulnerable
    • The return of embedded devices to take over the world - 15 years later
    • Attackers are going after MagicINFO
    • Hacking Starlink
    • Mitel SIP phones can be hacked
    • Reversing with Hopper
    • Supercharge your Ghidra with AI
    • Pretending to be an anti-virus to bypass anti-virus
    • macOS RCE - perfect colors
    • End of life routers are a hackers dream, and how info sharing sucks
    • Ransomware in your CPU
    • Disable ASUS DriverHub
    • Age verification and privacy concerns

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-874

    Más Menos
    1 h y 58 m
  • Are You Down With RDP? - PSW #873
    May 8 2025

    Security news for this week:

    • RDP and credentials that are not really revoked, and some RDP bitmap caching fun
    • Some magic info on MagicINFO
    • Vulnerability Management Zombies
    • There is a backdoor in your e-commerce
    • Airborne: vulnerabilities in AirPlay
    • Bring your own installer - crafty EDR bypass
    • The Signal clone used by US government officials: shocker: has been hacked
    • AI slop vulnerability reporting
    • Bricking iPhones with a single line of code
    • Hacking planet technology
    • Vibe hacking for the win?
    • Cybersecurity CEO arrested for deploying malware
    • Hello my perverted friend
    • FastCGI - fast, but vulnerable

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-873

    Más Menos
    2 h y 5 m
  • AI Tips, Tricks, and Traps! - PSW #872
    May 1 2025

    The PSW crew discusses tips, tricks, and traps for using AI and LLMs. We discuss a wide range of AI-related topics, including how to utilize AI tools for writing, coding, data analysis, website design, and more! Some key takeaways include:

    • AI has rapidly shifted from novelty to an essential tool in security and other fields.
    • Paid AI versions offer significant advantages for professionals.
    • Legal, ethical, and copyright questions around AI-generated content remain unresolved.
    • Human skills, critical thinking, communication, and adaptability are more important than ever.
    • AI is a powerful assistant, but not a replacement for expertise, creativity, or judgment.
    • Fact-checking AI outputs and understanding bias are critical in the age of generative AI.

    This episode offers a comprehensive, practical, and philosophical look at how AI is reshaping security, education, and society, providing both optimism and caution for the future.

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-872

    Más Menos
    1 h y 37 m
  • Hacking Crosswalks and Attacking Boilers - PSW #871
    Apr 24 2025

    The crosswalk is talking to me man!, don't block my website without due process, Florida is demanding encryption backdoors, attacking boilers and banning HackRF Ones, time to update your flipper zero, using AI to create working exploits, what happens when you combine an RP2350 and an ESP32? Hopefully good hackery things!, more evidence that patching is not enough, auditing the PHP source code, reading the MEGA advisories, threat actors lie about data breaches (you don't say?), the data breach that Hertz, CISA warns of ransomware, some can't get Ahold of data breaches, please don't let people take control of your PC over Zoom and Paul's hot takes on: 4chan hack, the CVE program, and Microsoft Recall!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-871

    Más Menos
    2 h y 4 m
  • Govt Unravelling, AI Hijinx, Bot Chaos, Recall, Oracle, Slopesquatting, Tycoon 2FA... - PSW #870
    Apr 17 2025

    Govt Unravelling, AI Hijinx, Bot Chaos, Recall, Oracle, Slopesquatting, Tycoon 2FA, College, who knows, a lot more... On Paul's Security Weekly.

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-870

    Más Menos
    2 h y 7 m
  • You Should Just Patch - PSW #869
    Apr 10 2025

    In the security news this week: You should really just patch things, the NVD backlog, Android phones with malware pre-installed, so convenient, keyloggers and a creepy pharmacist, snooping on federal workers, someone stole your browser history, NSA director fired, deputy director of NSA also fired, CrushFTP the saga continues, only steal the valid credit cards, another post that vanished from the Internet, hiding in NVRAM, protecting the Linux kernel, you down with MCP?, more EOL IoT, bypassing kernel protections, when are you ready for a pen test, red team and bug bounty, what EDR is really missing, and based on this story you should just patch everything all the time!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-869

    Más Menos
    2 h y 5 m
  • Not-So-Secure Boot - Rob Allen - PSW #868
    Apr 3 2025

    Rob Allen, Chief Product Officer at Threatlocker joins us for an interview segment on using AI in security products: What works and what's not fully baked! Then in the security news, There are more holes in your boot...loader according to Microsoft, related: Secure Boot is in danger and no one is really talking about it (still), Dear Microsoft: I don't want to send you my data, I don't grant you remote access, and I don't want to create a MS account, CrushFTP has to crush some bugs, bypassing unprivileged user namespace restrictions, FBI raids, attackers using your GPU, Find My anything, protecting GlobalProtect, the exploits will continue until things improve, your call records were not protected, good vs. bad drivers, AI is hacking AI, time traveling attacks, and a bizarre call for security researchers.

    This segment is sponsored by ThreatLocker. Visit https://www.securityweekly.com/threatlocker to learn more about them!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-868

    Más Menos
    2 h y 13 m
adbl_web_global_use_to_activate_T1_webcro805_stickypopup