steam distributes malware in game form, RDP open from DOGE servers, hacking a supply chain for 50K
Release Date: 02/17/2025
BrakeSec Education Podcast
Youtube Video: Questions and topics: (please feel free to update or make comments for clarifications) * Everyone wants us to use AI, but only when it benefits them * “Don’t use AI to submit your resume to our company” * “Do know how to use AI” * “Don’t use AI to answer the interview questions” * AI implementations range from “super easy” to “crazy easy” * If you already know how to use AI * Setting it up wrong can really hurt your company * Tasks in AI that can get you into trouble *...
info_outlineBrakeSec Education Podcast
Youtube Video at: https://www.youtube.com/watch?v=yHPvGVfPgjI Jay Beale is a principal security consultant and CEO/CTO for InGuardians. He is the architect of multiple open source projects, including the Peirates attack tool for Kubernetes (in Kali Linux), the Bustakube CTF Kubernetes cluster, and Bastille Linux. Jay created and leads the Kubernetes CTF at DEF CON and previously helped in the Kubernetes project's Security efforts. He’s co-written eight books and given many public talks at Black Hat, DEF CON, RSA, CanSecWest, Blue Hat, ToorCon, DerbyCon, WWHF, HushCon and others. He...
info_outlineBrakeSec Education Podcast
socvel.com/quiz if you want to play along! Check out the BrakeSecEd Twitch at join the Discord: https://bit.ly/brakesecDiscord Music: Music provided by Chillhop Music: https://chillhop.ffm.to/creatorcred "Flex" by Jeremy Blake Courtesy of Youtube media library
info_outlineBrakeSec Education Podcast
Guest Info: Name: Bronwen Aker Contact Information (N/A): Time Zone(s): Pacific, Central, Eastern –Copy begins– Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time based on new information and experiences, and do not represent views of past, present, or future employers. Recorded: Show Topic Summary: By harnessing AI, we can assist in being...
info_outlineBrakeSec Education Podcast
Check out the BrakeSecEd Twitch at or Youtube: https://youtube.com/c/BDSPodcast join the Discord: https://bit.ly/brakesecDiscord https://arxiv.org/abs/2302.14172 - EPSS whitepaper https://www.linkedin.com/posts/jayjacobs1_epss-threatintel-vulnerabiltymanagement-activity-7308146548767404032-RubN https://www.first.org/epss/ https://events.zoom.us/ev/AmoNH3baC7HVqDlDmgUtd2uCmTCMwJXfkR8mG6I5OxzbW01nhRMQ~AoEYQz5ROK4ybE4iX9b0PL-1utz4z0nbyrTjT4lskH_08_zfesR_Q_rNlA - BHIS training with Bronwen Aker on 03 April 2025 Music: Music provided by Chillhop Music:...
info_outlineBrakeSec Education Podcast
Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec Join the Discord! https://bit.ly/brakesecDiscord Questions and topics: (please feel free to update or make comments for clarifications) * https://techoreon.com/http-flaw-in-apple-passwords-left-iphones-vulnerable/ * https://darkmarc.substack.com/p/attackers-dont-need-exploits-when * https://www.techzine.eu/news/security/129713/the-browser-is-riddled-with-bugs-2025-may-squash-them/ * https://medium.com/@vanvleet/compound-probability-you-dont-need-100-coverage-to-win-a2e650da21a4 (interesting article on quantifying attack risk by...
info_outlineBrakeSec Education Podcast
Youtube VOD: – supply chain issues can crop up anywhere… are you blocking people from steam and popular software downloads online? <- 100 digits of pi <- periodic table song Additional information / pertinent LInks (Would you like to know more?): https://www.socvel.com/quiz/ https://xphantom.nl/posts/Offensive-Security-Lab/ Show points of Contact: Amanda Berlin: Brian Boettcher: Bryan Brake: Brakesec Website: Youtube channel: discord: https://discord.gg/brakesec Twitch Channel: Music: "Flex" by Jeremy...
info_outlineBrakeSec Education Podcast
Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec Join the Discord! https://discord.gg/brakesec #youtube VOD (in 1440p): Questions and topics: Bsides Vancouver discussion Semgrep Community and Academy Building communities What are ‘secure guardrails’ Reducing barriers between security and developers How to sell security to devs: “hey, if you want to see us less, buy/use this?” “Security is your barrier, but we have goals that we can’t reach without your help.” https://wehackpurple.com/devsecops-worst-practices-artificial-gates/ How are you seeing things...
info_outlineBrakeSec Education Podcast
Youtube VOD: #appsec, #owasp, #ASVS, #joshGrossman, #informationsecurity, #SBOM, #supplychain, #podcast, #twitch, #brakesec, #securecoding, #Codeanalysis Questions and topics: 1. The background to the topic, why is it something that interests you? How do you convince developers to take your course? 2. What do you think the root cause of the gap is? 3. Who is causing the gaps? (‘go fast’ culture, overzealous security, GRC requirements, basically everyone?) 4. Where do gaps begin? Is it the ‘need’ to ‘move fast’? 5. What can devs do to involve security in their process?...
info_outlineBrakeSec Education Podcast
Disclaimer: The views, information, or opinions expressed on this program are solely the views of the individuals involved and by no means represent absolute facts. Opinions expressed by the host and guests can change at any time based on new information and experiences and do not represent views of past, present, or future employers. Recorded: 08 Apr 2024 Youtube VOD: https://www.youtube.com/watch?v=K8qApvsFtqw Show Topic Summary: If you want to get in the mind of a board member, I submit to you my discussion with we did last night on . Join Mary and I as we discuss...
info_outlineYoutube VOD: https://www.youtube.com/watch?v=zu_smyQGvG4
-
https://cyberintel.substack.com/p/doge-exposes-once-secret-government
-
https://x.com/SteamDB/status/1889610974484705314 – supply chain issues can crop up anywhere… are you blocking people from steam and popular software downloads online?
-
https://www.landh.tech/blog/20250211-hack-supply-chain-for-50k/
-
https://medium.com/@cyberengage.org/rethinking-incident-response-from-picerl-to-dair-7b153a76e044
-
https://www.youtube.com/watch?v=3HRkKznJoZA <- 100 digits of pi
-
https://www.youtube.com/watch?v=rz4Dd1I_fX0 <- periodic table song
Additional information / pertinent LInks (Would you like to know more?):
-
https://www.socvel.com/quiz/
-
https://xphantom.nl/posts/Offensive-Security-Lab/
Show points of Contact:
Amanda Berlin: https://www.linkedin.com/in/amandaberlin/
Brian Boettcher: https://www.linkedin.com/in/bboettcher96/
Bryan Brake: https://linkedin.com/in/brakeb
Brakesec Website: https://www.brakeingsecurity.com
Youtube channel: https://youtube.com/@brakeseced
discord: https://discord.gg/brakesec
Twitch Channel: https://twitch.tv/brakesec
Music: https://chillhop.ffm.to/creatorcred "Flex" by Jeremy Blake
Courtesy of Youtube media library