If you think CVEs are an archaic way to manage your vulnerability management program, EPSS is an alternative way to think about organizational risk.
Stephen Shaffer shares the goods... with tequila!
open.spotify.com/episode/4GQ…
So like, the crypto falls apart if you just tell it it's doing it wrong?
Yep!
Louis Nyffenegger explains the confusion around... algorithm confusion!
open.spotify.com/episode/6ck…
What are APIs and how do you test them?
Katie Paxton-Fear drinks Fizzy Water from a mug with a good back story and dishes out the goods on API (in)security.
open.spotify.com/episode/3TE…
Or Yair opts for the Hoppy as he shares Out Of Bounds reads.
He covers the MMU and Virtual Memory. He dishes on protected regions, unmapped memory, and buffer allocations. A good time was had by all!
open.spotify.com/episode/6Oj…
If you're in the Vulnerability Management community, this the episode for you!
In Patch Bypassing, Arnold Palmer in hand, Ryan Emmons validates patch efficacy.
Sometimes they don't actually close the vulnerability, leading to a false sense of security.
open.spotify.com/episode/67Z…
Why is Rust the new hot software language? Does it actually provide better security? Adriaan Jacobs looked into it and shares his findings over an incredibly smooth Belgian beer.
open.spotify.com/episode/3xW…
Paul Asadoorian has an enviable podcast setup. He also talks about the purpose of UEFI and how a buffer overflow his team found could have led to some nasty bootkit installs. Don't know what a bootkit is? Grab a Bloody Mary and find out!
open.spotify.com/episode/4ft…
One of our favorite episodes, Nati Tal turns aside the conventional "check the sender's email" wisdom by showing how attackers could Echo Spoof and send messages from legitimate domains.
open.spotify.com/episode/5Vz…
JJ Lopez makes his own sangria. Check out the color!
Oh yeah, he also explains the concepts of fuzzing as we learn about his eBPF fuzzing work.
open.spotify.com/episode/170…
You know what goes great with a chat about OS Command Injection?
McKenna. Yeah, that's the stuff. Thanks to Zach Hanley for recounting his pathway to a perfect 10.0 CVSS score
open.spotify.com/episode/4kn…
Dmitri Kurbatov talks all about cell network security in this episode on Man On The Side attacks.
Does 5G provide a superior experience? Have a listen and find out!
open.spotify.com/episode/1pY…