loader from loading.io

Is Vuln Management Dead? - HD Moore - PSW #880

Paul's Security Weekly (Audio)

Release Date: 06/26/2025

Building a Hacking Lab in 2025 - PSW #906 show art Building a Hacking Lab in 2025 - PSW #906

Paul's Security Weekly (Audio)

The crew makes suggestions for building a hacking lab today! We will tackle: What is recommended today to build a lab, given the latest advancements in tech Hardware hacking devices and gadgets that are a must-have Which operating systems should you learn Virtualization technology that works well for a lab build Using AI to help build your lab Visit for all the latest episodes! Show Notes:

info_outline
With AI Nothing Is Safe - PSW #905 show art With AI Nothing Is Safe - PSW #905

Paul's Security Weekly (Audio)

This week in the security news: Linux process injection Threat actors need training too A Linux device "capable of practically anything" The Internet of webcams Hacking cheap devices Automating exploitation with local AI models Lame C2 Smallest SSH backdoor Your RDP is on the Internet These are not the high severity bugs you were looking for Low hanging fruit Your TV is spying on you, again no such thing as "offensive security" MCPs and RCEs Browser extensions collecting your AI chats And flooding TikTok with AI influencers Visit for all the latest episodes! Show Notes:

info_outline
Tech Segment: MITM Automation + Security News - Josh Bressers - PSW #904 show art Tech Segment: MITM Automation + Security News - Josh Bressers - PSW #904

Paul's Security Weekly (Audio)

This week in our technical segment, you will learn how to build a MITM proxy device using Kali Linux, some custom scripts, and a Raspberry PI! In the security news: Hacking Smart BBQ Probes China uses us as a proxy LOLPROX and living off the Hypervisor Are we overreating to React4Shell? Prolific Spyware vendors EDR evaluations and tin foil hats Compiling to Bash! How e-waste became a conference badge Overflows via underflows and reporting to CERT Users are using AI to complete mandatory infosec training! AI in your IDE is not a good idea Cybercrime is on the rise, and its the kids AI can...

info_outline
Holiday Hack Challenge, AI, Internet of Trash - Ed Skoudis - PSW #903 show art Holiday Hack Challenge, AI, Internet of Trash - Ed Skoudis - PSW #903

Paul's Security Weekly (Audio)

This week we welcome Ed Skoudis to talk about the holiday hack challenge (https://sans.org/HolidayHack). In the security news: Oh Asus Dashcam botnets Weird CVEs being issued CodeRED, but not the worm Free IP checking Internet space junk and IoT Decade old Linux kernel vulnerabilities Breaking out of Claude code Malicious LLMs Hacker on a plan gets 7 years Putting passwords into random websites NPM supply chains strike again LLMs will never be intelligent   Visit  for all the latest episodes! Show Notes:

info_outline
Vibe Coding For Success and Failure - PSW #902 show art Vibe Coding For Success and Failure - PSW #902

Paul's Security Weekly (Audio)

Tune in for some hands-on tips on how to use Claude code to create some amazing and not-so-amazing software. Paul will walk you through what worked and what didn't as he 100% vibe-coded a Python Flask application. The discussion continues with the crew discussing the future of vibe coding and how AI may better help in creating and securing software. Visit for all the latest episodes! Show Notes:

info_outline
Give Me Liberty or Linux, Badge Hacking Interview - Bryce Owen - PSW #901 show art Give Me Liberty or Linux, Badge Hacking Interview - Bryce Owen - PSW #901

Paul's Security Weekly (Audio)

In the security news: Cloudflare was down, it was not good Logitech breached The largest data breach in history? Fortinet Fortiweb - the saga continues Hacking Linux through your malware scanner, oh the irony I never stopped hating systemd The ASUS exploit that never existed If iRobot fails, can we deploy our own hacker bot army? Firmware encryption is a bitch Threat actors deply Claude Code Remembering the Viasat hack and why we can't have nice things Hacking re-entry sensors Sending signals in the wrong direction A File Format Uncracked for 20 Years And 2026 is the year of the Linux...

info_outline
Going Around EDR - PSW #900 show art Going Around EDR - PSW #900

Paul's Security Weekly (Audio)

This week: Minecraft on your lightbulb Sonicwall breached, who's next? Ditch Android, install Linux Hacking your face Thermostat freedom Pen test fails HackRF hacking times 2 Going around EDR Hackers in your printer Chinese data breach NFC relays and PCI Constructive construction hacks FlipperZero firmware update ICS, PLCs, and attacks Bayesian Swiss Cheese, taste good? Do you want to hack back? Keeping secrets Enforcing CMMC OWASP top ten gets a make over Android Spyware makes a LANDFALL Gemini's deep research into your documents Slopguard and AI datacenters in space! Visit for all the...

info_outline
Turning To The Darkside & AI Cyberslop - PSW #899 show art Turning To The Darkside & AI Cyberslop - PSW #899

Paul's Security Weekly (Audio)

This week: Reversing keyboard firmware Ghost networks Invasion of the face changers Ghost tapping and whole lot of FUD AI doesn't code securely, but Aardvark can secure code De-Googling Thermostats Dodgy Android TV boxes can run Debian HackRF vs. Honda Cyberslop AI paper Turning to the darkside Poisoning the watering hole Nagios vulnerabilities VPNs are a target Visit for all the latest episodes! Show Notes:

info_outline
Cybersecurity Is Dead - PSW #898 show art Cybersecurity Is Dead - PSW #898

Paul's Security Weekly (Audio)

In the security news this week: Cybersecurity is dead, and AI killed it Exploiting the patching system Apple makes it easier for spyware Who is patching Cisco ASA? Shove that DMCA somewhere HTTPS - a requirement Russia wants to own all the exploits Abandonware challenges Reversing at its hardest with Lua Hacking team is back, and leetspeak malware When you forget to authenticate your API Jamming with cool tech GoSpoof and After 35 Years, a Solution to the CIA’s Kryptos Puzzle Has Been Found! Visit for all the latest episodes! Show Notes:

info_outline
Its Always DNS - PSW #897 show art Its Always DNS - PSW #897

Paul's Security Weekly (Audio)

In the security news: When in doubt, blame DNS, you're almost always correct How to Make Windows 11 great, or at least suck less CSRF is the least of your problems Shady exploits Linux security table stakes (not steaks) The pill camera Give AI access to your UART Security products that actually try to be secure? Firmware vulnerabilities, lots of them Teams is spying on you More details on PolarEdge VSCode, marketplaces, and developers at risk Cisco SNMP flaw used to deploy malware The 90's called, they want their exploits back This segment is sponsored by ThreatLocker. Visit to learn more...

info_outline
 
More Episodes

This conversation explores the intersection of cybersecurity and emerging technologies, focusing on innovative hacking techniques, the evolution of vulnerability management, and the critical importance of asset discovery. The discussion also delves into the implications of cyber warfare, the persistent threat of default passwords, and the integration of open source tools in enhancing security measures. The conversation delves into various aspects of cybersecurity, focusing on aircraft tracking, data filtering, the evolution of vulnerability management, and the role of AI in enhancing security measures. The speakers discuss the challenges posed by default credentials and the shared responsibility model in cloud infrastructure. They also explore the limitations of AI in cybersecurity and the potential for future advancements, particularly in localized LLMs. The conversation delves into the intersection of technology, cybersecurity, and privacy, exploring the implications of AI on energy demands, vulnerabilities in telecom infrastructure, the complexities of network maintenance, and the challenges of ransomware negotiations. The discussion also touches on privacy concerns related to data tracking by major tech companies like Meta and Apple, as well as the evolving landscape of legal implications in the face of cyber threats.

This segment is sponsored by runZero. Get complete visibility across your total attack surface in literally minutes - no agents, no authentication required. Start a free trial or access the free Community Edition at https://securityweekly.com/runzero.

HD Moore joins us to discuss finding all the things and how vulnerability management has changed. In the security news:

  • Hacking from a light bulb
  • Reverse engineering, the easy ways
  • Detecting Jitter
  • FCC probes into Cyber Trust Mark
  • Bluetooth Jamming
  • New Wifi Apple features: What could go wrong?
  • Just turn off the Internet for the entire country
  • Meta's Localhost tracking
  • Hacking printers, for realz this time
  • Are we not patching 2023 CVEs?
  • Cleaning up legacy drivers
  • One of the Best Hackers in the Country is an AI Bot

Visit https://www.securityweekly.com/psw for all the latest episodes!

Show Notes: https://securityweekly.com/psw-880