<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/1673686.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>YusufOnSecurity.com</title>

  <lastBuildDate>Wed, 03 Jun 2026 05:47:43 +0400</lastBuildDate>
  <link>https://yusufonsecurity.com</link>
  <language>en-gb</language>
  <copyright>© 2026 YusufOnSecurity.com</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>9cdc86dd-e98e-56c4-83a0-4765ea91bc71</podcast:guid>
  <podcast:txt purpose="verify">nomaduk@gmail.com</podcast:txt>
  <itunes:author>YusufOnSecurity.Com</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[<p>This is a weekly podcast on cyber security domains. We discuss, dissect and demystify the world of security by providing an in-depth coverage on the cybersecurity topics that matter most. All these in plain easy to understand language. Like it, share it, and most importantly enjoy it!</p>]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:keywords>Cyber security, security, threats, vulnerability, exploits, malware, virus, trojan horse, worm, CVE</itunes:keywords>
  <itunes:owner>
    <itunes:name>YusufOnSecurity.Com</itunes:name>
    <itunes:email>nomaduk@gmail.com</itunes:email>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/8f4ytaednkk1hymx38hue2wkv7ww?.jpg</url>
     <title>YusufOnSecurity.com</title>
     <link>https://yusufonsecurity.com</link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/8f4ytaednkk1hymx38hue2wkv7ww?.jpg" />
  <itunes:category text="Technology" />
  <podcast:person role="host" img="https://storage.buzzsprout.com/o6hq3twmnnlf64r9225txn801bz9">Ibrahim Yusuf</podcast:person>
  <item>
    <itunes:title>276 - copy.fail Explained-The Linux Kernel Bug That Turns Any User Into Root</itunes:title>
    <title>276 - copy.fail Explained-The Linux Kernel Bug That Turns Any User Into Root</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week we are going to talk about a bug with one of the most misleading names I have seen in a while. It is called copy.fail. And if you saw that name pop up in your feed, you would be forgiven for thinking it was some clever browser demo, or maybe a problem with your clipboard. It is neither. copy.fail is a Linux kernel vulnerability. Its official label is CVE-2026-31431. And what makes it worth a full episode is not how exotic it is — it i...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week we are going to talk about a bug with one of the most misleading names I have seen in a while. It is called copy.fail. And if you saw that name pop up in your feed, you would be forgiven for thinking it was some clever browser demo, or maybe a problem with your clipboard. It is neither.</p><p>copy.fail is a Linux kernel vulnerability. Its official label is CVE-2026-31431. And what makes it worth a full episode is not how exotic it is — it is actually quite simple — but how wide its reach is. This single flaw lets an ordinary, unprivileged user on a Linux machine promote themselves all the way up to root. And it does so on nearly every modern Linux distribution shipped since 2017.</p><p>- <a href='https://xint.io/blog/copy-fail-linux-distributions'>https://xint.io</a>:copy.fail</p><p>- <a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog'>https://www.cisa.gov</a>: CVE-2026-31431</p><p>- <a href='https://www.bugcrowd.com/blog/hacker-opinion-piece-how-lazy-hacking-killed-curls-bug-bounty/'>https://www.bugcrowd.com</a>: Hacker Opinion Piece How Lazy Hacking Killed Curls Bug-bounty</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week we are going to talk about a bug with one of the most misleading names I have seen in a while. It is called copy.fail. And if you saw that name pop up in your feed, you would be forgiven for thinking it was some clever browser demo, or maybe a problem with your clipboard. It is neither.</p><p>copy.fail is a Linux kernel vulnerability. Its official label is CVE-2026-31431. And what makes it worth a full episode is not how exotic it is — it is actually quite simple — but how wide its reach is. This single flaw lets an ordinary, unprivileged user on a Linux machine promote themselves all the way up to root. And it does so on nearly every modern Linux distribution shipped since 2017.</p><p>- <a href='https://xint.io/blog/copy-fail-linux-distributions'>https://xint.io</a>:copy.fail</p><p>- <a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog'>https://www.cisa.gov</a>: CVE-2026-31431</p><p>- <a href='https://www.bugcrowd.com/blog/hacker-opinion-piece-how-lazy-hacking-killed-curls-bug-bounty/'>https://www.bugcrowd.com</a>: Hacker Opinion Piece How Lazy Hacking Killed Curls Bug-bounty</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/19285545-276-copy-fail-explained-the-linux-kernel-bug-that-turns-any-user-into-root.mp3" length="20188308" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19285545</guid>
    <pubDate>Sat, 16 May 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1679</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>275 - The Mercor Breach-When Your Security Scanner Becomes the Attack Vector</itunes:title>
    <title>275 - The Mercor Breach-When Your Security Scanner Becomes the Attack Vector</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today's episode is one of those stories that, when you start pulling the thread, the whole thing just keeps unravelling. We are going to talk about the Mercor breach. Now, if that name doesn't ring a bell, Mercor is a ten-billion-dollar AI recruiting startup. They match human experts with companies like OpenAI, Meta, and Anthropic to help train AI models. Big clients. Big data. Big target. Towards the end of March of this year, a threat group c...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today&apos;s episode is one of those stories that, when you start pulling the thread, the whole thing just keeps unravelling. We are going to talk about the Mercor breach. Now, if that name doesn&apos;t ring a bell, Mercor is a ten-billion-dollar AI recruiting startup. They match human experts with companies like OpenAI, Meta, and Anthropic to help train AI models. Big clients. Big data. Big target.</p><p>Towards the end of March of this year, a threat group called TeamPCP  and no, that is not a household cleaning detergent type of product - managed to steal roughly four terabytes of data from Mercor. And the way they did it? They didn&apos;t attack Mercor directly. They didn&apos;t even attack the software Mercor relied on directly. They attacked the security tool that was supposed to protect that software. Let me say that again. They compromised the vulnerability scanner.<br/> We have all that coming up next in this week&apos;s episode.</p><p>- <a href='https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/'>https://securitylabs.datadoghq.com</a>: LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign</p><p>- <a href='https://www.securityweek.com/mercor-hit-by-litellm-supply-chain-attack/'>https://www.securityweek.com</a>: SecurityWeek — Mercor Hit by LiteLLM Supply Chain Attack:</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today&apos;s episode is one of those stories that, when you start pulling the thread, the whole thing just keeps unravelling. We are going to talk about the Mercor breach. Now, if that name doesn&apos;t ring a bell, Mercor is a ten-billion-dollar AI recruiting startup. They match human experts with companies like OpenAI, Meta, and Anthropic to help train AI models. Big clients. Big data. Big target.</p><p>Towards the end of March of this year, a threat group called TeamPCP  and no, that is not a household cleaning detergent type of product - managed to steal roughly four terabytes of data from Mercor. And the way they did it? They didn&apos;t attack Mercor directly. They didn&apos;t even attack the software Mercor relied on directly. They attacked the security tool that was supposed to protect that software. Let me say that again. They compromised the vulnerability scanner.<br/> We have all that coming up next in this week&apos;s episode.</p><p>- <a href='https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/'>https://securitylabs.datadoghq.com</a>: LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign</p><p>- <a href='https://www.securityweek.com/mercor-hit-by-litellm-supply-chain-attack/'>https://www.securityweek.com</a>: SecurityWeek — Mercor Hit by LiteLLM Supply Chain Attack:</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/19243997-275-the-mercor-breach-when-your-security-scanner-becomes-the-attack-vector.mp3" length="21760671" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19243997</guid>
    <pubDate>Sat, 09 May 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1810</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>274 - Ransomware Hit a Water Plant - Why Your Tap Water Is a Cybersecurity Problem</itunes:title>
    <title>274 - Ransomware Hit a Water Plant - Why Your Tap Water Is a Cybersecurity Problem</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today's episode is one of those stories that really does hit home. Not a bank breach. Not some government leak. I want to talk about the water coming out of your tap. On March 14th, 2026, hackers dropped ransomware on a water treatment plant in Minot, North Dakota. Staff walked in that morning, saw a ransom note sitting on a server screen, and had to unplug the whole thing. For the next sixteen hours, plant operators were physically walking thr...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today&apos;s episode is one of those stories that really does hit home. Not a bank breach. Not some government leak. I want to talk about the water coming out of your tap.</p><p>On March 14th, 2026, hackers dropped ransomware on a water treatment plant in Minot, North Dakota. Staff walked in that morning, saw a ransom note sitting on a server screen, and had to unplug the whole thing. For the next sixteen hours, plant operators were physically walking through the facility, reading gauges by hand — old school, the way it was done decades ago — while the FBI got the call.</p><p>The city says the water stayed safe. Nobody got sick. But this incident ripped the cover off a problem the cybersecurity community has been warning about for years: water infrastructure is dangerously exposed. And most people have no idea.</p><p>Today I want to unpack what happened in Minot, why water utilities are such soft targets, what SCADA systems actually are and why they are so difficult to defend, and what defenders and regulators are doing — and should be doing — about all of this.</p><p>- <a href='https://therecord.media/north-dakota-ransomware-water-plant'>https://therecord.media</a>: North Dakota Ransomware Water Plant</p><p>- <a href='https://www.cisa.gov/news-events/alerts/2026/04/01/adapting-zero-trust-principles-operational-technology'>https://www.cisa.gov</a>: CISA — Adapting Zero Trust Principles to Operational Technology</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today&apos;s episode is one of those stories that really does hit home. Not a bank breach. Not some government leak. I want to talk about the water coming out of your tap.</p><p>On March 14th, 2026, hackers dropped ransomware on a water treatment plant in Minot, North Dakota. Staff walked in that morning, saw a ransom note sitting on a server screen, and had to unplug the whole thing. For the next sixteen hours, plant operators were physically walking through the facility, reading gauges by hand — old school, the way it was done decades ago — while the FBI got the call.</p><p>The city says the water stayed safe. Nobody got sick. But this incident ripped the cover off a problem the cybersecurity community has been warning about for years: water infrastructure is dangerously exposed. And most people have no idea.</p><p>Today I want to unpack what happened in Minot, why water utilities are such soft targets, what SCADA systems actually are and why they are so difficult to defend, and what defenders and regulators are doing — and should be doing — about all of this.</p><p>- <a href='https://therecord.media/north-dakota-ransomware-water-plant'>https://therecord.media</a>: North Dakota Ransomware Water Plant</p><p>- <a href='https://www.cisa.gov/news-events/alerts/2026/04/01/adapting-zero-trust-principles-operational-technology'>https://www.cisa.gov</a>: CISA — Adapting Zero Trust Principles to Operational Technology</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/19190185-274-ransomware-hit-a-water-plant-why-your-tap-water-is-a-cybersecurity-problem.mp3" length="25811334" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19190185</guid>
    <pubDate>Sat, 02 May 2026 21:00:00 +0400</pubDate>
    <itunes:duration>2147</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>273 - Project Glasswing (Mythos) - Anthropic Watershed Moment for Cybersecurity - Part 2</itunes:title>
    <title>273 - Project Glasswing (Mythos) - Anthropic Watershed Moment for Cybersecurity - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is Part 2 of our deep dive into Anthropic's Claude Mythos Preview and Project Glasswing. In Part 1, we covered what Mythos is, how it fits into the Claude model family, and why Anthropic is pushing the boundaries of extended thinking and complex reasoning. Today, we are picking up right where we left off and turning our attention to Project Glasswing — what it is, what it means for security professionals, and why this convergence of advanc...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is Part 2 of our deep dive into Anthropic&apos;s Claude Mythos Preview and Project Glasswing. In Part 1, we covered what Mythos is, how it fits into the Claude model family, and why Anthropic is pushing the boundaries of extended thinking and complex reasoning. Today, we are picking up right where we left off and turning our attention to Project Glasswing — what it is, what it means for security professionals, and why this convergence of advanced AI reasoning and autonomous capability should be on every defender&apos;s radar. If you have not listened to Part 1 yet, I would recommend going back and starting there, but if you are already caught up, let us get right into it.</p><p><a href='https://www.forrester.com/blogs/project-glasswing-the-10-consequences-nobodys-writing-about-yet/'>https://www.forrester.com</a>: Project Glasswing The 10 Consequences Nobody Writing About Yet</p><p>- <a href='https://www.anthropic.com/project/glasswing'>https://www.anthropic.com</a>: Project Glasswing</p><p>- <a href='https://blogs.cisco.com/news/rising-to-the-era-of-ai-powered-cyber-defense'>https://blogs.cisco.com</a>: Rising To the Era of AI Powered Cyber Defense</p><p>- <a href='https://www.wired.com/story/mozilla-used-anthropics-mythos-to-find-271-bugs-in-firefox/'>https://www.wired.com</a>: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is Part 2 of our deep dive into Anthropic&apos;s Claude Mythos Preview and Project Glasswing. In Part 1, we covered what Mythos is, how it fits into the Claude model family, and why Anthropic is pushing the boundaries of extended thinking and complex reasoning. Today, we are picking up right where we left off and turning our attention to Project Glasswing — what it is, what it means for security professionals, and why this convergence of advanced AI reasoning and autonomous capability should be on every defender&apos;s radar. If you have not listened to Part 1 yet, I would recommend going back and starting there, but if you are already caught up, let us get right into it.</p><p><a href='https://www.forrester.com/blogs/project-glasswing-the-10-consequences-nobodys-writing-about-yet/'>https://www.forrester.com</a>: Project Glasswing The 10 Consequences Nobody Writing About Yet</p><p>- <a href='https://www.anthropic.com/project/glasswing'>https://www.anthropic.com</a>: Project Glasswing</p><p>- <a href='https://blogs.cisco.com/news/rising-to-the-era-of-ai-powered-cyber-defense'>https://blogs.cisco.com</a>: Rising To the Era of AI Powered Cyber Defense</p><p>- <a href='https://www.wired.com/story/mozilla-used-anthropics-mythos-to-find-271-bugs-in-firefox/'>https://www.wired.com</a>: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/19152139-273-project-glasswing-mythos-anthropic-watershed-moment-for-cybersecurity-part-2.mp3" length="20449766" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19152139</guid>
    <pubDate>Sat, 25 Apr 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1700</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>272 - Project Glasswing (Mythos) - Anthropic Watershed Moment for Cybersecurity - Part 1</itunes:title>
    <title>272 - Project Glasswing (Mythos) - Anthropic Watershed Moment for Cybersecurity - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! About three weeks ago, on the 7th of April, Anthropic — the company behind the Claude family of AI models — announced something called Claude Mythos Preview. They paired the announcement with a coordinated industry effort they're calling Project Glasswing. And the headlines that followed have been, frankly, alarming. Fortune ran a piece headlined that Mythos can hack nearly anything, and we aren't ready. Coindesk reported that banks like JP Mor...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>About three weeks ago, on the 7th of April, Anthropic — the company behind the Claude family of AI models — announced something called Claude Mythos Preview. They paired the announcement with a coordinated industry effort they&apos;re calling Project Glasswing. And the headlines that followed have been, frankly, alarming.</p><p>Fortune ran a piece headlined that Mythos can hack nearly anything, and we aren&apos;t ready. Coindesk reported that banks like JP Morgan, and crypto exchanges like Coinbase and Binance, are already approaching Anthropic to test it. And Anthropic&apos;s own researchers described this as a watershed moment — meaning, a before-and-after divide in how we think about software security.</p><p>So let&apos;s break this down. What is Mythos? What can it actually do? And — most importantly — what should you and I, as defenders, be doing about it starting today?</p><p>- <a href='https://www.anthropic.com/project/glasswing'>https://www.anthropic.com</a>: Project Glasswing</p><p>- <a href='https://blogs.cisco.com/news/rising-to-the-era-of-ai-powered-cyber-defense'>https://blogs.cisco.com</a>: Rising To the Era of AI Powered Cyber Defense</p><p>- <a href='https://www.wired.com/story/mozilla-used-anthropics-mythos-to-find-271-bugs-in-firefox/'>https://www.wired.com</a>: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>About three weeks ago, on the 7th of April, Anthropic — the company behind the Claude family of AI models — announced something called Claude Mythos Preview. They paired the announcement with a coordinated industry effort they&apos;re calling Project Glasswing. And the headlines that followed have been, frankly, alarming.</p><p>Fortune ran a piece headlined that Mythos can hack nearly anything, and we aren&apos;t ready. Coindesk reported that banks like JP Morgan, and crypto exchanges like Coinbase and Binance, are already approaching Anthropic to test it. And Anthropic&apos;s own researchers described this as a watershed moment — meaning, a before-and-after divide in how we think about software security.</p><p>So let&apos;s break this down. What is Mythos? What can it actually do? And — most importantly — what should you and I, as defenders, be doing about it starting today?</p><p>- <a href='https://www.anthropic.com/project/glasswing'>https://www.anthropic.com</a>: Project Glasswing</p><p>- <a href='https://blogs.cisco.com/news/rising-to-the-era-of-ai-powered-cyber-defense'>https://blogs.cisco.com</a>: Rising To the Era of AI Powered Cyber Defense</p><p>- <a href='https://www.wired.com/story/mozilla-used-anthropics-mythos-to-find-271-bugs-in-firefox/'>https://www.wired.com</a>: Mozilla Used Anthropics Mythos To Find 271 Bugs In Firefox</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/19119489-272-project-glasswing-mythos-anthropic-watershed-moment-for-cybersecurity-part-1.mp3" length="19896230" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19119489</guid>
    <pubDate>Sat, 18 Apr 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1654</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>271 - $21 Billion Lost to Cybercrime — FBI&#39;s 2025 Report and Microsoft&#39;s Massive April Patch Tuesday</itunes:title>
    <title>271 - $21 Billion Lost to Cybercrime — FBI&#39;s 2025 Report and Microsoft&#39;s Massive April Patch Tuesday</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! We have got two big stories to get through today. First, the FBI just released its 2025 Internet Crime Report — and the numbers are not just record-breaking, they are genuinely alarming. We are talking about over twenty billion dollars in reported losses in a single year. And for the first time ever, the report includes a dedicated section on how criminals are using artificial intelligence to supercharge their scams. Then, we are going to pivot...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We have got two big stories to get through today. First, the FBI just released its 2025 Internet Crime Report — and the numbers are not just record-breaking, they are genuinely alarming. We are talking about over twenty billion dollars in reported losses in a single year. And for the first time ever, the report includes a dedicated section on how criminals are using artificial intelligence to supercharge their scams.</p><p>Then, we are going to pivot to Microsoft&apos;s April 2026 Patch Tuesday — one of the largest patch cycles we have seen in a long time. A hundred and sixty-seven vulnerabilities fixed, including an actively exploited zero-day in SharePoint Server. If your organisation runs SharePoint, and most do, you are going to want to hear this.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We have got two big stories to get through today. First, the FBI just released its 2025 Internet Crime Report — and the numbers are not just record-breaking, they are genuinely alarming. We are talking about over twenty billion dollars in reported losses in a single year. And for the first time ever, the report includes a dedicated section on how criminals are using artificial intelligence to supercharge their scams.</p><p>Then, we are going to pivot to Microsoft&apos;s April 2026 Patch Tuesday — one of the largest patch cycles we have seen in a long time. A hundred and sixty-seven vulnerabilities fixed, including an actively exploited zero-day in SharePoint Server. If your organisation runs SharePoint, and most do, you are going to want to hear this.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/19088482-271-21-billion-lost-to-cybercrime-fbi-s-2025-report-and-microsoft-s-massive-april-patch-tuesday.mp3" length="16048731" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-19088482</guid>
    <pubDate>Sat, 11 Apr 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1334</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>270 - Securing AI - The 3 Frameworks Every Defender Must Know</itunes:title>
    <title>270 - Securing AI - The 3 Frameworks Every Defender Must Know</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! If you've been watching the cybersecurity space for the last two years, you've noticed something. Almost every breach report, every vendor pitch, every board meeting — AI is in the conversation. Sometimes as the hero, sometimes as the villain, and very often as both at the same time. But here's the uncomfortable truth. Most organisations are racing to deploy AI far faster than they are learning how to secure it. We're plugging large language mo...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>If you&apos;ve been watching the cybersecurity space for the last two years, you&apos;ve noticed something. Almost every breach report, every vendor pitch, every board meeting — AI is in the conversation. Sometimes as the hero, sometimes as the villain, and very often as both at the same time.</p><p>But here&apos;s the uncomfortable truth. Most organisations are racing to deploy AI far faster than they are learning how to secure it. We&apos;re plugging large language models into customer service, into code pipelines, into decision-making workflows — and we&apos;re often doing it without a framework to guide us.</p><p>So in today&apos;s episode, I want to fix that. I want to walk you through the three frameworks that have become the gold standards for AI security. They are <b>NIST AI RMF</b>, <b>MITRE ATLAS</b>, and the <b>OWASP Top 10 for LLM Applications</b>.</p><p>Hopefully by the end of the next fifteen minutes, you will know what each one is, what each acronym actually stands for, what problem each one solves, and — most importantly — how they fit together so you can use them in the real world.</p><p>- <a href='https://www.nist.gov/itl/ai-risk-management-framework'>https://www.nist.gov</a>: AI Risk Management Framework</p><p>- <a href='https://atlas.mitre.org'>https://atlas.mitre.org</a>: MITRE ATLAS</p><p>- <a href='https://owasp.org/www-project-top-10-for-large-language-model-applications/'>https://owasp.org</a>: OWASP Top 10 for Large Language Model Applications</p><p><br/></p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>If you&apos;ve been watching the cybersecurity space for the last two years, you&apos;ve noticed something. Almost every breach report, every vendor pitch, every board meeting — AI is in the conversation. Sometimes as the hero, sometimes as the villain, and very often as both at the same time.</p><p>But here&apos;s the uncomfortable truth. Most organisations are racing to deploy AI far faster than they are learning how to secure it. We&apos;re plugging large language models into customer service, into code pipelines, into decision-making workflows — and we&apos;re often doing it without a framework to guide us.</p><p>So in today&apos;s episode, I want to fix that. I want to walk you through the three frameworks that have become the gold standards for AI security. They are <b>NIST AI RMF</b>, <b>MITRE ATLAS</b>, and the <b>OWASP Top 10 for LLM Applications</b>.</p><p>Hopefully by the end of the next fifteen minutes, you will know what each one is, what each acronym actually stands for, what problem each one solves, and — most importantly — how they fit together so you can use them in the real world.</p><p>- <a href='https://www.nist.gov/itl/ai-risk-management-framework'>https://www.nist.gov</a>: AI Risk Management Framework</p><p>- <a href='https://atlas.mitre.org'>https://atlas.mitre.org</a>: MITRE ATLAS</p><p>- <a href='https://owasp.org/www-project-top-10-for-large-language-model-applications/'>https://owasp.org</a>: OWASP Top 10 for Large Language Model Applications</p><p><br/></p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/19039407-270-securing-ai-the-3-frameworks-every-defender-must-know.mp3" length="19473568" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-19039407</guid>
    <pubDate>Sat, 04 Apr 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1619</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>269 - Cyber Resilience in 2026 - The Skills Gap, Team Readiness, and What Security Leaders Must Do Now</itunes:title>
    <title>269 - Cyber Resilience in 2026 - The Skills Gap, Team Readiness, and What Security Leaders Must Do Now</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, I am joined by my good old friend Shakel Ahmed, a cybersecurity practitioner with over 20 years of experience across some of the most demanding environments in the industry. We are covering the importance of skills and cyber resilience — and this is particularly important for those of you who are responsible for building and maintaining security teams, managing risk at a strategic level, or simply trying to figure out wh...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, I am joined by my good old friend Shakel Ahmed, a cybersecurity practitioner with over 20 years of experience across some of the most demanding environments in the industry. We are covering the importance of skills and cyber resilience — and this is particularly important for those of you who are responsible for building and maintaining security teams, managing risk at a strategic level, or simply trying to figure out where to focus your energy in an industry that never sits still. Whether you are an analyst wondering which skills will keep you relevant in the age of AI, or a CISO trying to ensure your organisation can absorb a hit and keep operating, this conversation is for you. Shakel brings a practitioner&apos;s perspective — not theory, not vendor talk — just hard-won insight on what it actually takes to build resilient people, resilient processes, and resilient organisations. So grab a coffee, settle in, and let&apos;s get into it.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, I am joined by my good old friend Shakel Ahmed, a cybersecurity practitioner with over 20 years of experience across some of the most demanding environments in the industry. We are covering the importance of skills and cyber resilience — and this is particularly important for those of you who are responsible for building and maintaining security teams, managing risk at a strategic level, or simply trying to figure out where to focus your energy in an industry that never sits still. Whether you are an analyst wondering which skills will keep you relevant in the age of AI, or a CISO trying to ensure your organisation can absorb a hit and keep operating, this conversation is for you. Shakel brings a practitioner&apos;s perspective — not theory, not vendor talk — just hard-won insight on what it actually takes to build resilient people, resilient processes, and resilient organisations. So grab a coffee, settle in, and let&apos;s get into it.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18949408-269-cyber-resilience-in-2026-the-skills-gap-team-readiness-and-what-security-leaders-must-do-now.mp3" length="31111515" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18949408</guid>
    <pubDate>Sat, 28 Mar 2026 22:00:00 +0400</pubDate>
    <itunes:duration>2589</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>268 - The Stryker Attack: How State Sponsored Hackers Weaponised a Microsoft Tool to Wipe 80K Devices</itunes:title>
    <title>268 - The Stryker Attack: How State Sponsored Hackers Weaponised a Microsoft Tool to Wipe 80K Devices</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Just over a week ago, on 11 March 2026, a cyberattack brought one of the world's largest medical device makers to its knees. Stryker - a $25 billion company that manufactures surgical robots, joint implants and emergency equipment - woke up to find thousands of employee devices wiped clean, its ordering systems offline, and surgeries being rescheduled around the world.  This was not ransomware. This was something more deliberate and destructive...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Just over a week ago, on 11 March 2026, a cyberattack brought one of the world&apos;s largest medical device makers to its knees. Stryker - a $25 billion company that manufactures surgical robots, joint implants and emergency equipment - woke up to find thousands of employee devices wiped clean, its ordering systems offline, and surgeries being rescheduled around the world.<br/><br/>This was not ransomware. This was something more deliberate and destructive - a wiper attack carried out by a state sponsored-linked hacking group called Handala, who exploited a trusted Microsoft device management tool to erase data from up to 80,000 employee phones and laptops in one move.<br/><br/>In this episode, we break down exactly what happened, how it happened, and what it means for every organisation that relies on cloud-based device management tools. We also look at the governance lessons - from business continuity planning to privileged access controls - that this attack makes impossible to ignore.</p><p>- <a href='https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final'>https://csrc.nist.gov</a>: NIST SP 800-34 Rev. 1 </p><p>- <a href='https://www.cybersecuritydive.com/news/stryker-attack-device-management-microsoft-iran/814816/'>https://www.cybersecuritydive.com</a>: Stryker attack raises concerns about role of Microsoft Intune</p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Just over a week ago, on 11 March 2026, a cyberattack brought one of the world&apos;s largest medical device makers to its knees. Stryker - a $25 billion company that manufactures surgical robots, joint implants and emergency equipment - woke up to find thousands of employee devices wiped clean, its ordering systems offline, and surgeries being rescheduled around the world.<br/><br/>This was not ransomware. This was something more deliberate and destructive - a wiper attack carried out by a state sponsored-linked hacking group called Handala, who exploited a trusted Microsoft device management tool to erase data from up to 80,000 employee phones and laptops in one move.<br/><br/>In this episode, we break down exactly what happened, how it happened, and what it means for every organisation that relies on cloud-based device management tools. We also look at the governance lessons - from business continuity planning to privileged access controls - that this attack makes impossible to ignore.</p><p>- <a href='https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final'>https://csrc.nist.gov</a>: NIST SP 800-34 Rev. 1 </p><p>- <a href='https://www.cybersecuritydive.com/news/stryker-attack-device-management-microsoft-iran/814816/'>https://www.cybersecuritydive.com</a>: Stryker attack raises concerns about role of Microsoft Intune</p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18887509-268-the-stryker-attack-how-state-sponsored-hackers-weaponised-a-microsoft-tool-to-wipe-80k-devices.mp3" length="22106528" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18887509</guid>
    <pubDate>Sat, 21 Mar 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1839</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>267 - SMB Protocol Explained-Why It Keeps Getting Hacked and Why We Can&#39;t Remove it?</itunes:title>
    <title>267 - SMB Protocol Explained-Why It Keeps Getting Hacked and Why We Can&#39;t Remove it?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we are talking about a protocol that is older than most of the people working in IT security right now, a protocol that has powered some of the most catastrophic cyberattacks in history, a protocol that security professionals have been trying to retire for years — and a protocol that is still quietly running in the background of almost every Windows environment on the planet. I am talking about SMB — the Server Message Block protocol. By ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we are talking about a protocol that is older than most of the people working in IT security right now, a protocol that has powered some of the most catastrophic cyberattacks in history, a protocol that security professionals have been trying to retire for years — and a protocol that is still quietly running in the background of almost every Windows environment on the planet. I am talking about SMB — the Server Message Block protocol. By the end of this episode, you will understand what it does, why it has been so dangerous, how it connects to something we have touched on before called Kerberos and NTLM authentication, and most importantly, what you should actually be doing about it in your organisation today. <br/><br/>So, lots to talk about today. Lets go!</p><p>- <a href='https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-security-hardening'>https://learn.microsoft.com</a>: SMB Security Hardening </p><p>- <a href='ttps://blog.barracuda.com/2022/05/11/attacks-smb-protocol-eternalblue'>https://blog.barracuda.com</a>: Majority of Attacks Against SMB Protocol Attempt to Exploit EternalBlue</p><p>- <a href='https://securelist.com/ntlm-abuse-in-2025/118132/'>https://securelist.com</a>: NTLM Is Being Abused In 2025</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we are talking about a protocol that is older than most of the people working in IT security right now, a protocol that has powered some of the most catastrophic cyberattacks in history, a protocol that security professionals have been trying to retire for years — and a protocol that is still quietly running in the background of almost every Windows environment on the planet. I am talking about SMB — the Server Message Block protocol. By the end of this episode, you will understand what it does, why it has been so dangerous, how it connects to something we have touched on before called Kerberos and NTLM authentication, and most importantly, what you should actually be doing about it in your organisation today. <br/><br/>So, lots to talk about today. Lets go!</p><p>- <a href='https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-security-hardening'>https://learn.microsoft.com</a>: SMB Security Hardening </p><p>- <a href='ttps://blog.barracuda.com/2022/05/11/attacks-smb-protocol-eternalblue'>https://blog.barracuda.com</a>: Majority of Attacks Against SMB Protocol Attempt to Exploit EternalBlue</p><p>- <a href='https://securelist.com/ntlm-abuse-in-2025/118132/'>https://securelist.com</a>: NTLM Is Being Abused In 2025</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18876166-267-smb-protocol-explained-why-it-keeps-getting-hacked-and-why-we-can-t-remove-it.mp3" length="21281130" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18876166</guid>
    <pubDate>Sat, 14 Mar 2026 23:00:00 +0400</pubDate>
    <itunes:duration>1770</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>266 -  Why ClickFix Is Exploding, LLMs Make Terrible Password Generators, and Certificates Are Getting Shorter?</itunes:title>
    <title>266 -  Why ClickFix Is Exploding, LLMs Make Terrible Password Generators, and Certificates Are Getting Shorter?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It has been a little while since my last update episode, and a lot has been happening in the world of cybersecurity. So today I want to catch you up on three things that have been on my radar and, more importantly, should be on yours.  First, we are going to talk about ClickFix — a social engineering attack technique that has exploded in popularity over the past year and is now being used by everyone from cybercriminals to nation-state hackers....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It has been a little while since my last update episode, and a lot has been happening in the world of cybersecurity. So today I want to catch you up on three things that have been on my radar and, more importantly, should be on yours.<br/><br/>First, we are going to talk about ClickFix — a social engineering attack technique that has exploded in popularity over the past year and is now being used by everyone from cybercriminals to nation-state hackers. I will explain what it is, how it works, and why it is so dangerous.<br/><br/>Second, we are going to tackle a question that more and more people are asking: can I just ask an AI chatbot to generate a password for me? The short answer is no, and I will explain exactly why using some very revealing research that just came out.<br/><br/>And third, we are going to cover an important change happening in the world of digital certificates right now — specifically code signing certificates, which are getting significantly shorter lifespans starting this year. I will explain what code signing is, why it matters to defenders, and what your organisation needs to do.<br/><br/>Lots to get through, so let us dive right in.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It has been a little while since my last update episode, and a lot has been happening in the world of cybersecurity. So today I want to catch you up on three things that have been on my radar and, more importantly, should be on yours.<br/><br/>First, we are going to talk about ClickFix — a social engineering attack technique that has exploded in popularity over the past year and is now being used by everyone from cybercriminals to nation-state hackers. I will explain what it is, how it works, and why it is so dangerous.<br/><br/>Second, we are going to tackle a question that more and more people are asking: can I just ask an AI chatbot to generate a password for me? The short answer is no, and I will explain exactly why using some very revealing research that just came out.<br/><br/>And third, we are going to cover an important change happening in the world of digital certificates right now — specifically code signing certificates, which are getting significantly shorter lifespans starting this year. I will explain what code signing is, why it matters to defenders, and what your organisation needs to do.<br/><br/>Lots to get through, so let us dive right in.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18831224-266-why-clickfix-is-exploding-llms-make-terrible-password-generators-and-certificates-are-getting-shorter.mp3" length="18238285" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18831224</guid>
    <pubDate>Sat, 07 Mar 2026 23:00:00 +0400</pubDate>
    <itunes:duration>1516</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>265 - The AI Agent Security Crisis – How OpenClaw&#39;s ClawJacked Flaw Compromised 40K Systems</itunes:title>
    <title>265 - The AI Agent Security Crisis – How OpenClaw&#39;s ClawJacked Flaw Compromised 40K Systems</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In late February 2026, a Meta executive lost her entire email inbox when an AI agent she was using deleted everything despite explicit instructions to confirm before taking action. At the same time, over 40K OpenClaw AI agent instances were found exposed to the internet, vulnerable to complete takeover by any malicious website a developer happened to visit. This isn't a story about a theoretical vulnerability or a proof-of-concept attack—this i...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In late February 2026, a Meta executive lost her entire email inbox when an AI agent she was using deleted everything despite explicit instructions to confirm before taking action. At the same time, over 40K OpenClaw AI agent instances were found exposed to the internet, vulnerable to complete takeover by any malicious website a developer happened to visit. This isn&apos;t a story about a theoretical vulnerability or a proof-of-concept attack—this is happening right now, and if your organization is using AI agents for automation, you need to understand what just went wrong and why it matters.</p><p>- <a href='https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html'>https://thehackernews.com</a>: ClawJacked Flaw </p><p>- <a href='https://www.oasis.security/blog/openclaw-vulnerability'>https://www.oasis.security</a>: OpenClaw Vulnerability</p><p>- <a href='https://www.microsoft.com/en-us/security/security-insider/emerging-trends/cyber-pulse-ai-security-report'>https://www.microsoft.com</a>: Cyber Pulse AI Security Report</p><p>- <a href='https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/'>https://www.microsoft.com</a>: 80%  Of Fortune 500 Use Active AI Agents Observability Governance And Security Shape The New Frontier</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In late February 2026, a Meta executive lost her entire email inbox when an AI agent she was using deleted everything despite explicit instructions to confirm before taking action. At the same time, over 40K OpenClaw AI agent instances were found exposed to the internet, vulnerable to complete takeover by any malicious website a developer happened to visit. This isn&apos;t a story about a theoretical vulnerability or a proof-of-concept attack—this is happening right now, and if your organization is using AI agents for automation, you need to understand what just went wrong and why it matters.</p><p>- <a href='https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html'>https://thehackernews.com</a>: ClawJacked Flaw </p><p>- <a href='https://www.oasis.security/blog/openclaw-vulnerability'>https://www.oasis.security</a>: OpenClaw Vulnerability</p><p>- <a href='https://www.microsoft.com/en-us/security/security-insider/emerging-trends/cyber-pulse-ai-security-report'>https://www.microsoft.com</a>: Cyber Pulse AI Security Report</p><p>- <a href='https://www.microsoft.com/en-us/security/blog/2026/02/10/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/'>https://www.microsoft.com</a>: 80%  Of Fortune 500 Use Active AI Agents Observability Governance And Security Shape The New Frontier</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18787562-265-the-ai-agent-security-crisis-how-openclaw-s-clawjacked-flaw-compromised-40k-systems.mp3" length="21082353" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18787562</guid>
    <pubDate>Sat, 28 Feb 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1753</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>264 - Inside the Cisco Live SOC: Securing the World&#39;s Biggest Networking Event</itunes:title>
    <title>264 - Inside the Cisco Live SOC: Securing the World&#39;s Biggest Networking Event</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Cisco Live is one of the largest networking and security conferences in the world, bringing together thousands of IT and security professionals for a week of learning, innovation, and hands-on experience — and this year, I was there, working as a SOC analyst on the ground -protecting the event. At an event of this scale, thousands of devices and connections are generating traffic around the clock, and behind the scenes, a dedicated SOC team is ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Cisco Live is one of the largest networking and security conferences in the world, bringing together thousands of IT and security professionals for a week of learning, innovation, and hands-on experience — and this year, I was there, working as a SOC analyst on the ground -protecting the event. At an event of this scale, thousands of devices and connections are generating traffic around the clock, and behind the scenes, a dedicated SOC team is watching every packet, every connection, and every anomaly in real time. This week, I sat down with the Director of the SOC to pull back the curtain on what it actually takes to secure an event like this — from threat patterns unique to a security-savvy crowd, to the tools and team structure that keep it all running.This is a conversation you don&apos;t want to miss</p><p>- <a href='https://blogs.cisco.com/security/cisco-live-melbourne-2025-soc'>https://blogs.cisco.com</a>: SOC In A Box</p><p>- <a href='http://cs.co/SOCEvents'>http://cs.co/SOCEvents</a>: Inside the event SOC-Securing the world&apos;s flagship conferences</p><p>- <a href='https://www.cisco.com/c/en/us/products/security/technical-alliance-partners/endace.html'>https://www.cisco.com</a>: Endace</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Cisco Live is one of the largest networking and security conferences in the world, bringing together thousands of IT and security professionals for a week of learning, innovation, and hands-on experience — and this year, I was there, working as a SOC analyst on the ground -protecting the event. At an event of this scale, thousands of devices and connections are generating traffic around the clock, and behind the scenes, a dedicated SOC team is watching every packet, every connection, and every anomaly in real time. This week, I sat down with the Director of the SOC to pull back the curtain on what it actually takes to secure an event like this — from threat patterns unique to a security-savvy crowd, to the tools and team structure that keep it all running.This is a conversation you don&apos;t want to miss</p><p>- <a href='https://blogs.cisco.com/security/cisco-live-melbourne-2025-soc'>https://blogs.cisco.com</a>: SOC In A Box</p><p>- <a href='http://cs.co/SOCEvents'>http://cs.co/SOCEvents</a>: Inside the event SOC-Securing the world&apos;s flagship conferences</p><p>- <a href='https://www.cisco.com/c/en/us/products/security/technical-alliance-partners/endace.html'>https://www.cisco.com</a>: Endace</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18760285-264-inside-the-cisco-live-soc-securing-the-world-s-biggest-networking-event.mp3" length="21515228" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18760285</guid>
    <pubDate>Mon, 23 Feb 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1789</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>263 - BGP Hijacking - The Invisible Threat That Can Redirect Your Traffic Anywhere</itunes:title>
    <title>263 - BGP Hijacking - The Invisible Threat That Can Redirect Your Traffic Anywhere</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! On June 27, 2024, millions of people worldwide suddenly couldn't access one of the internet's most popular DNS services—not because of a cyberattack in the traditional sense, but because a single network in Brazil convinced the internet that it owned an IP address that belonged to someone else. This wasn't hacking in the way most people understand it—no passwords were stolen, no systems were breached, yet traffic from 300 networks across 70 cou...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>On June 27, 2024, millions of people worldwide suddenly couldn&apos;t access one of the internet&apos;s most popular DNS services—not because of a cyberattack in the traditional sense, but because a single network in Brazil convinced the internet that it owned an IP address that belonged to someone else. This wasn&apos;t hacking in the way most people understand it—no passwords were stolen, no systems were breached, yet traffic from 300 networks across 70 countries was instantly rerouted into oblivion. In this episode, we break down BGP hijacking: the invisible routing attack that lets anyone with the right access redirect your internet traffic anywhere they want, and why the protocol holding the entire internet together was built on a foundation of trust that no longer makes sense in 2026.</p><p>- <a href='https://gcore.com/learning/what-is-bgp'>https://gcore.com</a>: What IS BGP?</p><p>- <a href='https://isbgpsafeyet.com'>https://isbgpsafeyet.com</a>: Is BGP Safe Yet?  </p><p>- <a href='https://blog.apnic.net'>https://blog.apnic.net</a>: APNIC Blog – BGP Security Analysis and Updates </p><p>- <a href='https://en.wikipedia.org/wiki/Regional_Internet_registry'>https://en.wikipedia.org</a>: Regional Internet Registries</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>On June 27, 2024, millions of people worldwide suddenly couldn&apos;t access one of the internet&apos;s most popular DNS services—not because of a cyberattack in the traditional sense, but because a single network in Brazil convinced the internet that it owned an IP address that belonged to someone else. This wasn&apos;t hacking in the way most people understand it—no passwords were stolen, no systems were breached, yet traffic from 300 networks across 70 countries was instantly rerouted into oblivion. In this episode, we break down BGP hijacking: the invisible routing attack that lets anyone with the right access redirect your internet traffic anywhere they want, and why the protocol holding the entire internet together was built on a foundation of trust that no longer makes sense in 2026.</p><p>- <a href='https://gcore.com/learning/what-is-bgp'>https://gcore.com</a>: What IS BGP?</p><p>- <a href='https://isbgpsafeyet.com'>https://isbgpsafeyet.com</a>: Is BGP Safe Yet?  </p><p>- <a href='https://blog.apnic.net'>https://blog.apnic.net</a>: APNIC Blog – BGP Security Analysis and Updates </p><p>- <a href='https://en.wikipedia.org/wiki/Regional_Internet_registry'>https://en.wikipedia.org</a>: Regional Internet Registries</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18747751-263-bgp-hijacking-the-invisible-threat-that-can-redirect-your-traffic-anywhere.mp3" length="25705068" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18747751</guid>
    <pubDate>Sat, 14 Feb 2026 22:00:00 +0400</pubDate>
    <itunes:duration>2138</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>262 - DORA Explained – What Financial Firms Need to Know About EU&#39;s Cyber Resilience Law</itunes:title>
    <title>262 - DORA Explained – What Financial Firms Need to Know About EU&#39;s Cyber Resilience Law</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! On January 17, 2025, the European Union's Digital Operational Resilience Act — known as DORA — became fully enforceable, fundamentally changing how financial institutions across Europe manage cyber and operational risk. One year into enforcement, regulators have designated critical ICT providers, penalties are now being levied, and the January 2026 supervisory review is underway. In this episode, we break down what DORA actually requires, who i...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>On January 17, 2025, the European Union&apos;s Digital Operational Resilience Act — known as DORA — became fully enforceable, fundamentally changing how financial institutions across Europe manage cyber and operational risk. One year into enforcement, regulators have designated critical ICT providers, penalties are now being levied, and the January 2026 supervisory review is underway. In this episode, we break down what DORA actually requires, who it applies to, why it matters even if you&apos;re not in the EU, and what the upcoming review means for the financial sector globally.<br/><br/></p><p>- <a href='https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en'>https://www.eiopa.europa.eu</a>: Digital Operational Resilience Act (DORA)</p><p>- <a href='https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554'>https://eur-lex.europa.eu</a>: The regulation</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>On January 17, 2025, the European Union&apos;s Digital Operational Resilience Act — known as DORA — became fully enforceable, fundamentally changing how financial institutions across Europe manage cyber and operational risk. One year into enforcement, regulators have designated critical ICT providers, penalties are now being levied, and the January 2026 supervisory review is underway. In this episode, we break down what DORA actually requires, who it applies to, why it matters even if you&apos;re not in the EU, and what the upcoming review means for the financial sector globally.<br/><br/></p><p>- <a href='https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en'>https://www.eiopa.europa.eu</a>: Digital Operational Resilience Act (DORA)</p><p>- <a href='https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554'>https://eur-lex.europa.eu</a>: The regulation</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18724946-262-dora-explained-what-financial-firms-need-to-know-about-eu-s-cyber-resilience-law.mp3" length="17822630" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18724946</guid>
    <pubDate>Sat, 07 Feb 2026 23:00:00 +0400</pubDate>
    <itunes:duration>1482</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>261 - Passkeys in 2026 – Are We Finally Done With Passwords?</itunes:title>
    <title>261 - Passkeys in 2026 – Are We Finally Done With Passwords?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! After sixty years of password resets, forgotten credentials, and phishing attacks, the authentication landscape is finally shifting — and 2026 marks the tipping point. In this episode, we break down what passkeys actually are, why over a billion people have already adopted them, and what the regulatory push from NIST, CISA, and global financial regulators means for your organisation. Passwords aren't dead yet, but for the first time, they're ge...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>After sixty years of password resets, forgotten credentials, and phishing attacks, the authentication landscape is finally shifting — and 2026 marks the tipping point. In this episode, we break down what passkeys actually are, why over a billion people have already adopted them, and what the regulatory push from NIST, CISA, and global financial regulators means for your organisation. Passwords aren&apos;t dead yet, but for the first time, they&apos;re genuinely on the way out.<br/><br/>We have all that coming up next, in this week&apos;s podcast!</p><p>- <a href='https://passkeys.io/'>https://passkeys.io</a>: Comprehensive implementation guides, device compatibility checker, and passkey directory</p><p>- <a href='https://pages.nist.gov/800-63-4/'>https://pages.nist.gov/800-63-4</a>: Official SP 800-63-4 with AAL2/AAL3</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>After sixty years of password resets, forgotten credentials, and phishing attacks, the authentication landscape is finally shifting — and 2026 marks the tipping point. In this episode, we break down what passkeys actually are, why over a billion people have already adopted them, and what the regulatory push from NIST, CISA, and global financial regulators means for your organisation. Passwords aren&apos;t dead yet, but for the first time, they&apos;re genuinely on the way out.<br/><br/>We have all that coming up next, in this week&apos;s podcast!</p><p>- <a href='https://passkeys.io/'>https://passkeys.io</a>: Comprehensive implementation guides, device compatibility checker, and passkey directory</p><p>- <a href='https://pages.nist.gov/800-63-4/'>https://pages.nist.gov/800-63-4</a>: Official SP 800-63-4 with AAL2/AAL3</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18711023-261-passkeys-in-2026-are-we-finally-done-with-passwords.mp3" length="10513722" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18711023</guid>
    <pubDate>Sat, 31 Jan 2026 22:00:00 +0400</pubDate>
    <itunes:duration>872</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>260 - From NTLM to Kerberos - Microsoft&#39;s Security Transformation Begins - Part 2</itunes:title>
    <title>260 - From NTLM to Kerberos - Microsoft&#39;s Security Transformation Begins - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In Part 1 of this series, we explored why Microsoft is finally saying goodbye to NTLM authentication after more than 25 years of service. We discussed NTLM's security weaknesses, from relay attacks to weak cryptography, and touched on Kerberos as the obvious alternative that's been waiting in the wings since ...well....Windows 2000.  Today in Part 2, we're getting practical. We'll explore the two groundbreaking major Microsoft is adding to Kerb...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In Part 1 of this series, we explored why Microsoft is finally saying goodbye to NTLM authentication after more than 25 years of service. We discussed NTLM&apos;s security weaknesses, from relay attacks to weak cryptography, and touched on Kerberos as the obvious alternative that&apos;s been waiting in the wings since ...well....Windows 2000.<br/><br/>Today in Part 2, we&apos;re getting practical. We&apos;ll explore the two groundbreaking major Microsoft is adding to Kerberos—IAKerb and Local KDC—that will finally allow organizations to eliminate NTLM entirely. More importantly, we&apos;ll discuss what this means for you as a defender, how to prepare your environment, and of course...what timeline you&apos;re working with.</p><p>- <a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-evolution-of-windows-authentication/ba-p/3926848'>techcommunity.microsoft.com</a>: The evolution of Windows authentication<br/>- <a href='https://www.securityweek.com/microsoft-improving-windows-authentication-disabling-ntlm/'>www.securityweek.com</a>: Microsoft Improving Windows Authentication, Disabling NTLM<br/>- <a href='https://www.bleepingcomputer.com/news/security/microsoft-plans-to-kill-off-ntlm-authentication-in-windows-11/'>www.bleepingcomputer.com</a>: Microsoft plans to kill off NTLM authentication in Windows 11<br/><b>-</b> <a href='https://thehackernews.com/2023/10/microsoft-to-phase-out-ntlm-in-favor-of.html'>thehackernews.com</a>: Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In Part 1 of this series, we explored why Microsoft is finally saying goodbye to NTLM authentication after more than 25 years of service. We discussed NTLM&apos;s security weaknesses, from relay attacks to weak cryptography, and touched on Kerberos as the obvious alternative that&apos;s been waiting in the wings since ...well....Windows 2000.<br/><br/>Today in Part 2, we&apos;re getting practical. We&apos;ll explore the two groundbreaking major Microsoft is adding to Kerberos—IAKerb and Local KDC—that will finally allow organizations to eliminate NTLM entirely. More importantly, we&apos;ll discuss what this means for you as a defender, how to prepare your environment, and of course...what timeline you&apos;re working with.</p><p>- <a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-evolution-of-windows-authentication/ba-p/3926848'>techcommunity.microsoft.com</a>: The evolution of Windows authentication<br/>- <a href='https://www.securityweek.com/microsoft-improving-windows-authentication-disabling-ntlm/'>www.securityweek.com</a>: Microsoft Improving Windows Authentication, Disabling NTLM<br/>- <a href='https://www.bleepingcomputer.com/news/security/microsoft-plans-to-kill-off-ntlm-authentication-in-windows-11/'>www.bleepingcomputer.com</a>: Microsoft plans to kill off NTLM authentication in Windows 11<br/><b>-</b> <a href='https://thehackernews.com/2023/10/microsoft-to-phase-out-ntlm-in-favor-of.html'>thehackernews.com</a>: Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18569873-260-from-ntlm-to-kerberos-microsoft-s-security-transformation-begins-part-2.mp3" length="20027510" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18569873</guid>
    <pubDate>Sat, 24 Jan 2026 22:00:00 +0400</pubDate>
    <itunes:duration>1665</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>259 - From NTLM to Kerberos - Microsoft&#39;s Security Transformation Begins - Part 1</itunes:title>
    <title>259 - From NTLM to Kerberos - Microsoft&#39;s Security Transformation Begins - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we're diving into a significant announcement from Microsoft that will fundamentally change how Windows handles authentication. In this two-part series, we'll explore Microsoft's plan to phase out the NT LAN Manager protocol, better known as NTLM, and fully embrace Kerberos authentication in Windows 11. This isn't just a minor technical adjustment‚Äîthis represents a major shift in how organizations will secure their Windows environments....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re diving into a significant announcement from Microsoft that will fundamentally change how Windows handles authentication. In this two-part series, we&apos;ll explore Microsoft&apos;s plan to phase out the NT LAN Manager protocol, better known as NTLM, and fully embrace Kerberos authentication in Windows 11. This isn&apos;t just a minor technical adjustment‚Äîthis represents a major shift in how organizations will secure their Windows environments.</p><p>In Part 1 today, we&apos;ll understand what NTLM is, why it&apos;s been around for so long despite its security weaknesses, and explore the fundamental reasons Microsoft has decided it&apos;s finally time to pull the plug.</p><p><b>- </b><a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-evolution-of-windows-authentication/ba-p/3926848'><b>techcommunity.microsoft.com</b></a>: The evolution of Windows authentication<br/><b>- </b><a href='https://www.securityweek.com/microsoft-improving-windows-authentication-disabling-ntlm/'><b>www.securityweek.com</b></a>: Microsoft Improving Windows Authentication, Disabling NTLM<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/microsoft-plans-to-kill-off-ntlm-authentication-in-windows-11/'><b>www.bleepingcomputer.com</b></a>: Microsoft plans to kill off NTLM authentication in Windows 11<br/><b>- </b><a href='https://thehackernews.com/2023/10/microsoft-to-phase-out-ntlm-in-favor-of.html'><b>thehackernews.com</b></a>: Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re diving into a significant announcement from Microsoft that will fundamentally change how Windows handles authentication. In this two-part series, we&apos;ll explore Microsoft&apos;s plan to phase out the NT LAN Manager protocol, better known as NTLM, and fully embrace Kerberos authentication in Windows 11. This isn&apos;t just a minor technical adjustment‚Äîthis represents a major shift in how organizations will secure their Windows environments.</p><p>In Part 1 today, we&apos;ll understand what NTLM is, why it&apos;s been around for so long despite its security weaknesses, and explore the fundamental reasons Microsoft has decided it&apos;s finally time to pull the plug.</p><p><b>- </b><a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-evolution-of-windows-authentication/ba-p/3926848'><b>techcommunity.microsoft.com</b></a>: The evolution of Windows authentication<br/><b>- </b><a href='https://www.securityweek.com/microsoft-improving-windows-authentication-disabling-ntlm/'><b>www.securityweek.com</b></a>: Microsoft Improving Windows Authentication, Disabling NTLM<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/microsoft-plans-to-kill-off-ntlm-authentication-in-windows-11/'><b>www.bleepingcomputer.com</b></a>: Microsoft plans to kill off NTLM authentication in Windows 11<br/><b>- </b><a href='https://thehackernews.com/2023/10/microsoft-to-phase-out-ntlm-in-favor-of.html'><b>thehackernews.com</b></a>: Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18558407-259-from-ntlm-to-kerberos-microsoft-s-security-transformation-begins-part-1.mp3" length="19796221" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18558407</guid>
    <pubDate>Sat, 17 Jan 2026 21:00:00 +0400</pubDate>
    <itunes:duration>1646</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>258 - React2Shell Mass Exploit and Instagram 17 million breach</itunes:title>
    <title>258 - React2Shell Mass Exploit and Instagram 17 million breach</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It has been a while since we've done a news update episode. So today, we're diving into two major stories that have been dominating cybersecurity headlines this past week. First, we'll unpack React2Shell, a critical vulnerability that's being called one of the most serious web application flaws in recent memory. Then we'll discuss the Instagram data breach affecting over seventeen million users. Both incidents highlight how quickly the threat l...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It has been a while since we&apos;ve done a news update episode. So today, we&apos;re diving into two major stories that have been dominating cybersecurity headlines this past week. First, we&apos;ll unpack React2Shell, a critical vulnerability that&apos;s being called one of the most serious web application flaws in recent memory. Then we&apos;ll discuss the Instagram data breach affecting over seventeen million users. Both incidents highlight how quickly the threat landscape can shift.</p><p>- <a href='https://react.dev/blog/2025/12/03/react-rsc-vulnerabilities'>https://react.dev</a>: React Security Advisory</p><p>- <a href='https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182'>https://www.wiz.io</a>: Wiz Research Technical Analysis</p><p>- <a href='https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/'>https://aws.amazon.com</a>: AWS Threat Intelligence Report</p><p>- <a href='https://www.cisa.gov/news-events/alerts](https://www.cisa.gov/news-events/alerts'>https://www.cisa.go</a>: CISA Alert on CVE-2025-55182</p><p>- <a href='https://haveibeenpwned.com/Breach/Instagram'>https://haveibeenpwned.com</a>: Instagram Breach</p><p>- <a href='https://www.cisa.gov/mfa'>https://www.cisa.gov</a>: Multi-Factor Authentication Guide<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It has been a while since we&apos;ve done a news update episode. So today, we&apos;re diving into two major stories that have been dominating cybersecurity headlines this past week. First, we&apos;ll unpack React2Shell, a critical vulnerability that&apos;s being called one of the most serious web application flaws in recent memory. Then we&apos;ll discuss the Instagram data breach affecting over seventeen million users. Both incidents highlight how quickly the threat landscape can shift.</p><p>- <a href='https://react.dev/blog/2025/12/03/react-rsc-vulnerabilities'>https://react.dev</a>: React Security Advisory</p><p>- <a href='https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182'>https://www.wiz.io</a>: Wiz Research Technical Analysis</p><p>- <a href='https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/'>https://aws.amazon.com</a>: AWS Threat Intelligence Report</p><p>- <a href='https://www.cisa.gov/news-events/alerts](https://www.cisa.gov/news-events/alerts'>https://www.cisa.go</a>: CISA Alert on CVE-2025-55182</p><p>- <a href='https://haveibeenpwned.com/Breach/Instagram'>https://haveibeenpwned.com</a>: Instagram Breach</p><p>- <a href='https://www.cisa.gov/mfa'>https://www.cisa.gov</a>: Multi-Factor Authentication Guide<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18508044-258-react2shell-mass-exploit-and-instagram-17-million-breach.mp3" length="18395602" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18508044</guid>
    <pubDate>Sat, 10 Jan 2026 21:00:00 +0400</pubDate>
    <itunes:duration>1529</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>257 - Jaguar Land Rover Cyberattack-How the Breach Disrupted Production and Exposed Sensitive Data</itunes:title>
    <title>257 - Jaguar Land Rover Cyberattack-How the Breach Disrupted Production and Exposed Sensitive Data</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In late 2025, Jaguar Land Rover was hit by a debilitating cyberattack that brought its global production to a near-standstill and ultimately exposed sensitive employee and contractor data, marking one of the most disruptive breaches in the automotive industry in recent memory.** The incident not only shuttered factories and hammered sales, but also served as a stark reminder of how deeply cybersecurity failures can ripple through complex modern...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In late 2025, Jaguar Land Rover was hit by a debilitating cyberattack that brought its global production to a near-standstill and ultimately exposed sensitive employee and contractor data, marking one of the most disruptive breaches in the automotive industry in recent memory.** The incident not only shuttered factories and hammered sales, but also served as a stark reminder of how deeply cybersecurity failures can ripple through complex modern supply chains and operations.</p><p>- <a href='https://treblle.com/blog/jlr-breach-breakdown-analysis'>https://treblle.com</a>: JLR Breach Breackdown Analysis</p><p>-<a href='https://www.cyfirma.com/research/investigation-report-on-jaguar-land-rover-cyberattack/'>https://www.cyfirma.com</a>: Investigation Report on Jaguar Land Rover Cyber Attack</p><p>- <a href='https://therecord.media/jaguar-land-rover-quarterly-loss-cyberattack'>https://therecord.media</a>: Juaguard Land Rover Quarter Loss Cyber Attack</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In late 2025, Jaguar Land Rover was hit by a debilitating cyberattack that brought its global production to a near-standstill and ultimately exposed sensitive employee and contractor data, marking one of the most disruptive breaches in the automotive industry in recent memory.** The incident not only shuttered factories and hammered sales, but also served as a stark reminder of how deeply cybersecurity failures can ripple through complex modern supply chains and operations.</p><p>- <a href='https://treblle.com/blog/jlr-breach-breakdown-analysis'>https://treblle.com</a>: JLR Breach Breackdown Analysis</p><p>-<a href='https://www.cyfirma.com/research/investigation-report-on-jaguar-land-rover-cyberattack/'>https://www.cyfirma.com</a>: Investigation Report on Jaguar Land Rover Cyber Attack</p><p>- <a href='https://therecord.media/jaguar-land-rover-quarterly-loss-cyberattack'>https://therecord.media</a>: Juaguard Land Rover Quarter Loss Cyber Attack</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18494878-257-jaguar-land-rover-cyberattack-how-the-breach-disrupted-production-and-exposed-sensitive-data.mp3" length="20556681" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18494878</guid>
    <pubDate>Sat, 03 Jan 2026 21:00:00 +0400</pubDate>
    <itunes:duration>1709</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>256 - The best of 2025</itunes:title>
    <title>256 - The best of 2025</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! As we've done at the end of each year, it's time to look back at what resonated most with you, our listeners. 2025 brought us some incredible episodes covering everything from fundamental security concepts to cutting-edge AI developments. But three episodes truly stood out—pulling the highest download numbers and sparking the most conversation.  These weren't just popular because they covered trending topics. They addressed real, practical chal...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As we&apos;ve done at the end of each year, it&apos;s time to look back at what resonated most with you, our listeners. 2025 brought us some incredible episodes covering everything from fundamental security concepts to cutting-edge AI developments. But three episodes truly stood out—pulling the highest download numbers and sparking the most conversation.<br/><br/>These weren&apos;t just popular because they covered trending topics. They addressed real, practical challenges that defenders face every single day. So let&apos;s dive into the best of 2025.<br/><br/>First up: Episode 207 - Microsoft Windows Actively Exploited Vulnerabilities<br/><br/>Released on January 18th, this episode tackled something every Windows administrator loses sleep over—actively exploited vulnerabilities. We broke down three critical flaws that attackers were leveraging in the wild, and more importantly, what you needed to do about them right away. This episode hit home because it wasn&apos;t theoretical—these were real threats demanding immediate action.<br/><br/>Next: Episode 213 - Stealing Data in Plain Sight: How Cybercriminals Exfiltrate Your Secrets and How to Stop Them<br/><br/>Published on March 1st, this deep dive into data exfiltration struck a nerve. We explored how attackers don&apos;t just break in anymore—they quietly steal your most valuable assets while blending into normal network traffic. From DNS tunneling to cloud storage abuse, we covered the techniques defenders need to recognize and the controls that actually work. This episode became essential listening because data exfiltration isn&apos;t just a technical problem—it&apos;s a business survival issue.<br/>And finally, wrapping up our 2025 year in review: Episode 219 - What Is Agentic AI?<br/><br/>Released on April 12th, this episode ventured into territory that&apos;s reshaping our entire field—Agentic AI. We explored autonomous systems that can make decisions and take actions without human intervention. Why did this resonate so strongly? Because AI agents aren&apos;t science fiction anymore—they&apos;re being deployed in security operations, and defenders need to understand both their potential and their risks. This episode helped demystify where AI is heading and what it means for everyday security professionals.</p><p>Enjoy!<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As we&apos;ve done at the end of each year, it&apos;s time to look back at what resonated most with you, our listeners. 2025 brought us some incredible episodes covering everything from fundamental security concepts to cutting-edge AI developments. But three episodes truly stood out—pulling the highest download numbers and sparking the most conversation.<br/><br/>These weren&apos;t just popular because they covered trending topics. They addressed real, practical challenges that defenders face every single day. So let&apos;s dive into the best of 2025.<br/><br/>First up: Episode 207 - Microsoft Windows Actively Exploited Vulnerabilities<br/><br/>Released on January 18th, this episode tackled something every Windows administrator loses sleep over—actively exploited vulnerabilities. We broke down three critical flaws that attackers were leveraging in the wild, and more importantly, what you needed to do about them right away. This episode hit home because it wasn&apos;t theoretical—these were real threats demanding immediate action.<br/><br/>Next: Episode 213 - Stealing Data in Plain Sight: How Cybercriminals Exfiltrate Your Secrets and How to Stop Them<br/><br/>Published on March 1st, this deep dive into data exfiltration struck a nerve. We explored how attackers don&apos;t just break in anymore—they quietly steal your most valuable assets while blending into normal network traffic. From DNS tunneling to cloud storage abuse, we covered the techniques defenders need to recognize and the controls that actually work. This episode became essential listening because data exfiltration isn&apos;t just a technical problem—it&apos;s a business survival issue.<br/>And finally, wrapping up our 2025 year in review: Episode 219 - What Is Agentic AI?<br/><br/>Released on April 12th, this episode ventured into territory that&apos;s reshaping our entire field—Agentic AI. We explored autonomous systems that can make decisions and take actions without human intervention. Why did this resonate so strongly? Because AI agents aren&apos;t science fiction anymore—they&apos;re being deployed in security operations, and defenders need to understand both their potential and their risks. This episode helped demystify where AI is heading and what it means for everyday security professionals.</p><p>Enjoy!<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18446644-256-the-best-of-2025.mp3" length="72491561" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18446644</guid>
    <pubDate>Sat, 27 Dec 2025 22:00:00 +0400</pubDate>
    <itunes:duration>6037</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>255 - Shadow AI-The Invisible Security Risk Already Inside Your Organization</itunes:title>
    <title>255 - Shadow AI-The Invisible Security Risk Already Inside Your Organization</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we're tackling one of the fastest-emerging threats of 2025—one that's probably already active in your organization right now, whether you know it or not. We're talking about Shadow AI, and the statistics are alarming: That means right now, as you're listening to this, someone in your organization is likely pasting sensitive data into ChatGPT, Claude, or another AI tool—and your security team has no idea it's happening. Lets peel the onio...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re tackling one of the fastest-emerging threats of 2025—one that&apos;s probably already active in your organization right now, whether you know it or not. We&apos;re talking about Shadow AI, and the statistics are alarming: That means right now, as you&apos;re listening to this, someone in your organization is likely pasting sensitive data into ChatGPT, Claude, or another AI tool—and your security team has no idea it&apos;s happening. Lets peel the onion to see what this is so.</p><p>- <a href='https://www.ibm.com/reports/data-breach](https://www.ibm.com/reports/data-breachIBM Security'>https://www.ibm.com</a>: Cost of a Data Breach Report 2025-   <a href='https://www.splunk.com/en_us/blog/learn/shadow-ai.html'>https://www.splunk.com</a>: Introduction to Shadow AI <br/>- <a href='https://www.nist.gov/itl/ai-risk-management-framework'>https://www.nist.gov</a>: NIST - AI Risk Management Framework (AI RMF) </p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re tackling one of the fastest-emerging threats of 2025—one that&apos;s probably already active in your organization right now, whether you know it or not. We&apos;re talking about Shadow AI, and the statistics are alarming: That means right now, as you&apos;re listening to this, someone in your organization is likely pasting sensitive data into ChatGPT, Claude, or another AI tool—and your security team has no idea it&apos;s happening. Lets peel the onion to see what this is so.</p><p>- <a href='https://www.ibm.com/reports/data-breach](https://www.ibm.com/reports/data-breachIBM Security'>https://www.ibm.com</a>: Cost of a Data Breach Report 2025-   <a href='https://www.splunk.com/en_us/blog/learn/shadow-ai.html'>https://www.splunk.com</a>: Introduction to Shadow AI <br/>- <a href='https://www.nist.gov/itl/ai-risk-management-framework'>https://www.nist.gov</a>: NIST - AI Risk Management Framework (AI RMF) </p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18442888-255-shadow-ai-the-invisible-security-risk-already-inside-your-organization.mp3" length="16968404" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18442888</guid>
    <pubDate>Sat, 20 Dec 2025 21:00:00 +0400</pubDate>
    <itunes:duration>1410</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>254 - Infostealers-The Silent Malware Stealing Everything</itunes:title>
    <title>254 - Infostealers-The Silent Malware Stealing Everything</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we're talking about one of the most dangerous yet underestimated threats in cybersecurity right now. While everyone's worried about ransomware making headlines with million-dollar extortion demands, there's a quieter threat that's actually fueling those attacks. It's called infostealer malware, and in 2024 alone, these silent digital pickpockets were responsible for nearly one in four cyberattacks. They stole over 2 billion credentials an...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re talking about one of the most dangerous yet underestimated threats in cybersecurity right now. While everyone&apos;s worried about ransomware making headlines with million-dollar extortion demands, there&apos;s a quieter threat that&apos;s actually fueling those attacks. It&apos;s called infostealer malware, and in 2024 alone, these silent digital pickpockets were responsible for nearly one in four cyberattacks. They stole over 2 billion credentials and enabled some of the most devastating breaches of the year. The scary part? Most victims don&apos;t even know they&apos;ve been infected until it&apos;s far too late.</p><p>- <a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-83r1.pdf'>https://nvlpubs.nist.gov</a>: NIST Special Publication 800-83 Rev. 1 - Guide to Malware Incident Prevention and Handling</p><p>-<a href='https://media.defense.gov/2019/Jul/16/2002158046/-1/-1/0/CSI-NSAS-TOP10-CYBERSECURITY-MITIGATION-STRATEGIES.PDF'> https://media.defense.gov</a>: NSA Cybersecurity Advisory - Top Ten Cybersecurity Mitigation Strategies</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re talking about one of the most dangerous yet underestimated threats in cybersecurity right now. While everyone&apos;s worried about ransomware making headlines with million-dollar extortion demands, there&apos;s a quieter threat that&apos;s actually fueling those attacks. It&apos;s called infostealer malware, and in 2024 alone, these silent digital pickpockets were responsible for nearly one in four cyberattacks. They stole over 2 billion credentials and enabled some of the most devastating breaches of the year. The scary part? Most victims don&apos;t even know they&apos;ve been infected until it&apos;s far too late.</p><p>- <a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-83r1.pdf'>https://nvlpubs.nist.gov</a>: NIST Special Publication 800-83 Rev. 1 - Guide to Malware Incident Prevention and Handling</p><p>-<a href='https://media.defense.gov/2019/Jul/16/2002158046/-1/-1/0/CSI-NSAS-TOP10-CYBERSECURITY-MITIGATION-STRATEGIES.PDF'> https://media.defense.gov</a>: NSA Cybersecurity Advisory - Top Ten Cybersecurity Mitigation Strategies</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18421272-254-infostealers-the-silent-malware-stealing-everything.mp3" length="19865763" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18421272</guid>
    <pubDate>Sat, 13 Dec 2025 21:00:00 +0400</pubDate>
    <itunes:duration>1652</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>253 - Shadow IT and SaaS Sprawl - The Hidden Security Risk in Your Organization</itunes:title>
    <title>253 - Shadow IT and SaaS Sprawl - The Hidden Security Risk in Your Organization</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Imagine discovering that your organization is running nearly ten times more applications than your IT team knows about. Imagine learning that two out of every three cloud tools being used by your employees were never approved, never vetted for security, and are completely invisible to your monitoring systems. Now imagine that one-third of all data breaches last year involved exactly these kinds of hidden applications. This isn't a hypothetical ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Imagine discovering that your organization is running nearly ten times more applications than your IT team knows about. Imagine learning that two out of every three cloud tools being used by your employees were never approved, never vetted for security, and are completely invisible to your monitoring systems. Now imagine that one-third of all data breaches last year involved exactly these kinds of hidden applications. This isn&apos;t a hypothetical scenario from some dystopian cybersecurity future—this is happening right now in organizations of every size, including yours. Today, we&apos;re talking about Shadow IT and SaaS sprawl, the security crisis that&apos;s hiding in plain sight, costing companies millions, and creating vulnerabilities that most security teams don&apos;t even know exist yet.</p><p>- <a href='https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final'>https://csrc.nist.gov</a>: NIST Special Publication 800-53 - Security Controls for Shadow IT</p><p>- <a href='https://www.ibm.com/reports/data-breach'>https://www.ibm.com</a>: Data-breach</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Imagine discovering that your organization is running nearly ten times more applications than your IT team knows about. Imagine learning that two out of every three cloud tools being used by your employees were never approved, never vetted for security, and are completely invisible to your monitoring systems. Now imagine that one-third of all data breaches last year involved exactly these kinds of hidden applications. This isn&apos;t a hypothetical scenario from some dystopian cybersecurity future—this is happening right now in organizations of every size, including yours. Today, we&apos;re talking about Shadow IT and SaaS sprawl, the security crisis that&apos;s hiding in plain sight, costing companies millions, and creating vulnerabilities that most security teams don&apos;t even know exist yet.</p><p>- <a href='https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final'>https://csrc.nist.gov</a>: NIST Special Publication 800-53 - Security Controls for Shadow IT</p><p>- <a href='https://www.ibm.com/reports/data-breach'>https://www.ibm.com</a>: Data-breach</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18354805-253-shadow-it-and-saas-sprawl-the-hidden-security-risk-in-your-organization.mp3" length="10136607" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18354805</guid>
    <pubDate>Sat, 06 Dec 2025 22:00:00 +0400</pubDate>
    <itunes:duration>841</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>252 - Windows password security - What is under the hood?</itunes:title>
    <title>252 - Windows password security - What is under the hood?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we're lifting the hood on something you interact with dozens of times per day but probably never think about: Windows password security. What actually happens when you type your password and hit Enter? Where does Windows store that password? And perhaps most importantly, why do attackers spend so much time trying to steal password databases?  https://learn.microsoft.com:Prevent Windows Store LMHash Password  https://www.nist.go...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re lifting the hood on something you interact with dozens of times per day but probably never think about: Windows password security. What actually happens when you type your password and hit Enter? Where does Windows store that password? And perhaps most importantly, why do attackers spend so much time trying to steal password databases?</p><p> <a href=' https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/prevent-windows-store-lm-hash-password'>https://learn.microsoft.com</a>:Prevent Windows Store LMHash Password</p><p> <a href='https://www.nist.gov/cybersecurity/how-do-i-create-good-password'>https://www.nist.gov</a>: How Do I Create a good password</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re lifting the hood on something you interact with dozens of times per day but probably never think about: Windows password security. What actually happens when you type your password and hit Enter? Where does Windows store that password? And perhaps most importantly, why do attackers spend so much time trying to steal password databases?</p><p> <a href=' https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/prevent-windows-store-lm-hash-password'>https://learn.microsoft.com</a>:Prevent Windows Store LMHash Password</p><p> <a href='https://www.nist.gov/cybersecurity/how-do-i-create-good-password'>https://www.nist.gov</a>: How Do I Create a good password</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18311160-252-windows-password-security-what-is-under-the-hood.mp3" length="23601640" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18311160</guid>
    <pubDate>Sat, 29 Nov 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1963</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>251 - The Future of Security Operations- Are SIEM, XDR, and SOAR Converging or Moving Apart?</itunes:title>
    <title>251 - The Future of Security Operations- Are SIEM, XDR, and SOAR Converging or Moving Apart?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we're talking about the future of security operations, specifically three technologies that have dominated the conversation for the past few years: SIEM, XDR, and SOAR. And I'm going to make a case that might surprise some people: these tools are converging. They're merging into unified platforms, and that's actually a good thing.  Now, if you're a security professional, you've probably noticed this trend already. Vendors are starting to ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re talking about the future of security operations, specifically three technologies that have dominated the conversation for the past few years: SIEM, XDR, and SOAR. And I&apos;m going to make a case that might surprise some people: these tools are converging. They&apos;re merging into unified platforms, and that&apos;s actually a good thing.<br/><br/>Now, if you&apos;re a security professional, you&apos;ve probably noticed this trend already. Vendors are starting to blur the lines between these categories. SIEM vendors are adding XDR capabilities. XDR platforms are adding automation features that look a lot like SOAR. And everyone&apos;s claiming they can do everything.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re talking about the future of security operations, specifically three technologies that have dominated the conversation for the past few years: SIEM, XDR, and SOAR. And I&apos;m going to make a case that might surprise some people: these tools are converging. They&apos;re merging into unified platforms, and that&apos;s actually a good thing.<br/><br/>Now, if you&apos;re a security professional, you&apos;ve probably noticed this trend already. Vendors are starting to blur the lines between these categories. SIEM vendors are adding XDR capabilities. XDR platforms are adding automation features that look a lot like SOAR. And everyone&apos;s claiming they can do everything.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18285632-251-the-future-of-security-operations-are-siem-xdr-and-soar-converging-or-moving-apart.mp3" length="16171232" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18285632</guid>
    <pubDate>Sat, 22 Nov 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1344</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>250 - PenTesting vs Red Teaming vs Vulnerability Assessment-Which One Do You Need?</itunes:title>
    <title>250 - PenTesting vs Red Teaming vs Vulnerability Assessment-Which One Do You Need?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we're tackling a question I get asked constantly: "Should we do a pentest, a red team engagement, or a vulnerability assessment?"  These terms get thrown around interchangeably, but they're actually very different things with different goals, different costs, and they're appropriate for different situations. Choosing the wrong one can either waste money on overkill testing or leave you with a false sense of security.  Here's the reality: ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re tackling a question I get asked constantly: &quot;Should we do a pentest, a red team engagement, or a vulnerability assessment?&quot;<br/><br/>These terms get thrown around interchangeably, but they&apos;re actually very different things with different goals, different costs, and they&apos;re appropriate for different situations. Choosing the wrong one can either waste money on overkill testing or leave you with a false sense of security.<br/><br/>Here&apos;s the reality: most organizations need all three at different times. But if you&apos;re trying to figure out where to start, you need to understand what each one actually does.</p><p><a href='https://www.sans.org/blog/shifting-from-penetration-testing-to-red-team-and-purple-team'>https://www.sans.org</a>: Penetration Testing: The Shift to Red Team and Purple Team Strategies</p><p>-<a href='https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-115.pdf'>https://nvlpubs.nist.gov</a>: Technical Guide to Information Security Testing and Assessment</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re tackling a question I get asked constantly: &quot;Should we do a pentest, a red team engagement, or a vulnerability assessment?&quot;<br/><br/>These terms get thrown around interchangeably, but they&apos;re actually very different things with different goals, different costs, and they&apos;re appropriate for different situations. Choosing the wrong one can either waste money on overkill testing or leave you with a false sense of security.<br/><br/>Here&apos;s the reality: most organizations need all three at different times. But if you&apos;re trying to figure out where to start, you need to understand what each one actually does.</p><p><a href='https://www.sans.org/blog/shifting-from-penetration-testing-to-red-team-and-purple-team'>https://www.sans.org</a>: Penetration Testing: The Shift to Red Team and Purple Team Strategies</p><p>-<a href='https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-115.pdf'>https://nvlpubs.nist.gov</a>: Technical Guide to Information Security Testing and Assessment</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18277676-250-pentesting-vs-red-teaming-vs-vulnerability-assessment-which-one-do-you-need.mp3" length="14990737" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18277676</guid>
    <pubDate>Sat, 15 Nov 2025 21:00:00 +0400</pubDate>
    <itunes:duration>1245</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>249 - What Is Credential Stuffing? How Hackers Use Your Old Passwords Against You</itunes:title>
    <title>249 - What Is Credential Stuffing? How Hackers Use Your Old Passwords Against You</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we're talking about one of the most common yet misunderstood cyber attacks happening right now: credential stuffing. And I do mean right now. As I'm recording this, somewhere in the world, automated bots are attempting billions of login attempts across thousands of websites, trying to break into accounts using stolen usernames and passwords. - https://www.usenix.org: Protecting accounts from credential stuffing with password breach alerti...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re talking about one of the most common yet misunderstood cyber attacks happening right now: credential stuffing. And I do mean right now. As I&apos;m recording this, somewhere in the world, automated bots are attempting billions of login attempts across thousands of websites, trying to break into accounts using stolen usernames and passwords.</p><p>- <a href='https://www.usenix.org/conference/usenixsecurity19/presentation/thomas'>https://www.usenix.org</a>: Protecting accounts from credential stuffing with password breach alerting</p><p>- <a href='https://www.cs.cornell.edu/~rahul/papers/ppsm.pdf'>https://www.cs.cornell.edu</a>: Beyond Credential Stuffing: Password Similarity Models using Neural Networks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re talking about one of the most common yet misunderstood cyber attacks happening right now: credential stuffing. And I do mean right now. As I&apos;m recording this, somewhere in the world, automated bots are attempting billions of login attempts across thousands of websites, trying to break into accounts using stolen usernames and passwords.</p><p>- <a href='https://www.usenix.org/conference/usenixsecurity19/presentation/thomas'>https://www.usenix.org</a>: Protecting accounts from credential stuffing with password breach alerting</p><p>- <a href='https://www.cs.cornell.edu/~rahul/papers/ppsm.pdf'>https://www.cs.cornell.edu</a>: Beyond Credential Stuffing: Password Similarity Models using Neural Networks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18277520-249-what-is-credential-stuffing-how-hackers-use-your-old-passwords-against-you.mp3" length="21660424" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18277520</guid>
    <pubDate>Sat, 08 Nov 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1801</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>248 - The Truth About Security Awareness Training- Why 95% of Programs Don&#39;t Work</itunes:title>
    <title>248 - The Truth About Security Awareness Training- Why 95% of Programs Don&#39;t Work</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we're diving into something that keeps cybersecurity professionals up at night, and no, it's not the latest ransomware attack or data breach. It's something much more frustrating: the fact that despite spending billions of dollars on security awareness training every year, employees keep clicking on phishing emails, using weak passwords, and falling for social engineering attack. - https://www.sans.org: Security Awareness Training  - http...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re diving into something that keeps cybersecurity professionals up at night, and no, it&apos;s not the latest ransomware attack or data breach. It&apos;s something much more frustrating: the fact that despite spending billions of dollars on security awareness training every year, employees keep clicking on phishing emails, using weak passwords, and falling for social engineering attack.</p><p>- <a href='https://www.sans.org/security-awareness-training/resources/reports/'>https://www.sans.org</a>: Security Awareness Training<br/> - <a href='https://www.verizon.com/business/resources/reports/dbir/'>https://www.verizon.com</a>: 2025 Data Breach Investigations Report</p><p>- <a href='https://ebbinghausmuseum.org/'>https://ebbinghausmuseum.org</a>: The Forgetting Curve</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re diving into something that keeps cybersecurity professionals up at night, and no, it&apos;s not the latest ransomware attack or data breach. It&apos;s something much more frustrating: the fact that despite spending billions of dollars on security awareness training every year, employees keep clicking on phishing emails, using weak passwords, and falling for social engineering attack.</p><p>- <a href='https://www.sans.org/security-awareness-training/resources/reports/'>https://www.sans.org</a>: Security Awareness Training<br/> - <a href='https://www.verizon.com/business/resources/reports/dbir/'>https://www.verizon.com</a>: 2025 Data Breach Investigations Report</p><p>- <a href='https://ebbinghausmuseum.org/'>https://ebbinghausmuseum.org</a>: The Forgetting Curve</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18235268-248-the-truth-about-security-awareness-training-why-95-of-programs-don-t-work.mp3" length="21053182" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18235268</guid>
    <pubDate>Sat, 01 Nov 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1751</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>247 - AI-Powered Browsers-The Privacy and Security Risks No One Talks About</itunes:title>
    <title>247 - AI-Powered Browsers-The Privacy and Security Risks No One Talks About</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Something fundamental changed in how we browse the internet in October 2025, and most people have no idea. In just 48 hours, OpenAI launched ChatGPT Atlas, Microsoft fired back with a revamped Edge, and suddenly every major tech company was racing to release AI-powered browsers that don't just load web pages—they can read your emails, book your travel, and access every logged-in account you have, all autonomously. The marketing promises unprece...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Something fundamental changed in how we browse the internet in October 2025, and most people have no idea. In just 48 hours, OpenAI launched ChatGPT Atlas, Microsoft fired back with a revamped Edge, and suddenly every major tech company was racing to release AI-powered browsers that don&apos;t just load web pages—they can read your emails, book your travel, and access every logged-in account you have, all autonomously. The marketing promises unprecedented productivity, but security researchers found critical vulnerabilities within days—attacks where a single Reddit comment could drain your bank account or a malicious website could steal all your emails without you knowing. Today, we&apos;re breaking down what it means for your security, asking the question that actually matters: Are AI browsers a productivity breakthrough or a security disaster? Let&apos;s dive in.</p><p>- <a href='https://openai.com/index/introducing-chatgpt-atlas/'>https://openai.com</a>: Introducing ChatGPT Atlas</p><p>- <a href='https://www.perplexity.ai/hub/blog/introducing-comet'>https://www.perplexity.ai</a>: Introducing Comet</p><p>- <a href='https://blogs.windows.com/msedgedev/2025/10/23/meet-copilot-mode-in-edge-your-ai-browser/'>https://blogs.windows.com</a>: Your AI Browser</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Something fundamental changed in how we browse the internet in October 2025, and most people have no idea. In just 48 hours, OpenAI launched ChatGPT Atlas, Microsoft fired back with a revamped Edge, and suddenly every major tech company was racing to release AI-powered browsers that don&apos;t just load web pages—they can read your emails, book your travel, and access every logged-in account you have, all autonomously. The marketing promises unprecedented productivity, but security researchers found critical vulnerabilities within days—attacks where a single Reddit comment could drain your bank account or a malicious website could steal all your emails without you knowing. Today, we&apos;re breaking down what it means for your security, asking the question that actually matters: Are AI browsers a productivity breakthrough or a security disaster? Let&apos;s dive in.</p><p>- <a href='https://openai.com/index/introducing-chatgpt-atlas/'>https://openai.com</a>: Introducing ChatGPT Atlas</p><p>- <a href='https://www.perplexity.ai/hub/blog/introducing-comet'>https://www.perplexity.ai</a>: Introducing Comet</p><p>- <a href='https://blogs.windows.com/msedgedev/2025/10/23/meet-copilot-mode-in-edge-your-ai-browser/'>https://blogs.windows.com</a>: Your AI Browser</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18190767-247-ai-powered-browsers-the-privacy-and-security-risks-no-one-talks-about.mp3" length="17178689" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18190767</guid>
    <pubDate>Sat, 25 Oct 2025 21:00:00 +0400</pubDate>
    <itunes:duration>1428</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>246 - Is AI-Generated Code Safe-The Hidden Dangers of Vibe Coding</itunes:title>
    <title>246 - Is AI-Generated Code Safe-The Hidden Dangers of Vibe Coding</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! So today, we're unpacking what vibe coding is, why it's creating serious security risks, and what you can do about it. Because whether you love it or hate it, vibe coding isn't going anywhere. The question is: are we shipping features, or are we shipping vulnerabilities?  All that coming up next in today's episode. - https://cloud.google.com: What Is Vibe Coding?- https://learningnetwork.cisco.com: Escaping Abstraction: Why AI-Generated Code De...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>So today, we&apos;re unpacking what vibe coding is, why it&apos;s creating serious security risks, and what you can do about it. Because whether you love it or hate it, vibe coding isn&apos;t going anywhere. The question is: are we shipping features, or are we shipping vulnerabilities?<br/><br/>All that coming up next in today&apos;s episode.</p><p>- <a href='https://cloud.google.com/discover/what-is-vibe-coding'>https://cloud.google.com</a>: What Is Vibe Coding?- <a href='https://learningnetwork.cisco.com/s/blogs/a0DKd00006bjy76MAA/escaping-abstraction-why-aigenerated-code-demands-more-than-just-trust'>https://learningnetwork.cisco.com</a>: Escaping Abstraction: Why AI-Generated Code Demands More Than Just Trust</p><p>- <a href='https://claude.ai/public/artifacts/a2e1f3a1-747e-4e86-89f0-23bf3f1f2014'>https://claude.ai</a>: Vibe Code Best Practice</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>So today, we&apos;re unpacking what vibe coding is, why it&apos;s creating serious security risks, and what you can do about it. Because whether you love it or hate it, vibe coding isn&apos;t going anywhere. The question is: are we shipping features, or are we shipping vulnerabilities?<br/><br/>All that coming up next in today&apos;s episode.</p><p>- <a href='https://cloud.google.com/discover/what-is-vibe-coding'>https://cloud.google.com</a>: What Is Vibe Coding?- <a href='https://learningnetwork.cisco.com/s/blogs/a0DKd00006bjy76MAA/escaping-abstraction-why-aigenerated-code-demands-more-than-just-trust'>https://learningnetwork.cisco.com</a>: Escaping Abstraction: Why AI-Generated Code Demands More Than Just Trust</p><p>- <a href='https://claude.ai/public/artifacts/a2e1f3a1-747e-4e86-89f0-23bf3f1f2014'>https://claude.ai</a>: Vibe Code Best Practice</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18190729-246-is-ai-generated-code-safe-the-hidden-dangers-of-vibe-coding.mp3" length="15551814" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-18190729</guid>
    <pubDate>Sat, 18 Oct 2025 18:00:00 +0400</pubDate>
    <itunes:duration>1292</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>245 - 50 Documents Can Poison AI Models - CISA KEV Adds 12 Decade-Old Vulnerabilities and Salesforce Ransomware</itunes:title>
    <title>245 - 50 Documents Can Poison AI Models - CISA KEV Adds 12 Decade-Old Vulnerabilities and Salesforce Ransomware</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week, we've got three stories that really caught my attention, and honestly, they're all pretty alarming in their own ways.  If you're new here, welcome to the show where we break down the latest cybersecurity news and help you understand what's really happening in the cyber security domains. We're going to talk about a shocking discovery about AI security - turns out it takes way fewer malicious documents than anyone thought to compl...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, we&apos;ve got three stories that really caught my attention, and honestly, they&apos;re all pretty alarming in their own ways. </p><p>If you&apos;re new here, welcome to the show where we break down the latest cybersecurity news and help you understand what&apos;s really happening in the cyber security domains.</p><p>We&apos;re going to talk about a shocking discovery about AI security - turns out it takes way fewer malicious documents than anyone thought to completely poison an AI model. Then we&apos;ll discuss something that should make every security professional cringe - CISA just added a dozen vulnerabilities to their Known Exploited Vulnerabilities catalog, and half of them are over a decade old. And finally, we&apos;ll cover Salesforce&apos;s bold decision not to pay ransom to hackers who claim to have stolen data from dozens of major companies.</p><p>- <a href='https://www.anthropic.com/research/small-samples-poison'>https://www.anthropic.com</a>: Small Samples Poison</p><p>- <a href='https://www.turing.ac.uk/blog/llms-may-be-more-vulnerable-data-poisoning-we-thought'>https://www.turing.ac.uk</a>: LLMS May Be More Vulnerable Data Poisoning W Thought</p><p>- <a href='https://www.theregister.com/2025/10/08/salesforce_refuses_to_pay_ransomware/'>https://www.theregister.com</a>: Salesforce Refuses To Pay Ransomware</p><p>- <a href='https://www.sans.org/newsletters/newsbites/xxvii-73'>https://www.sans.org</a>: CISA Adds 12 CVEs to KEV; Half are a Decade or More Old</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, we&apos;ve got three stories that really caught my attention, and honestly, they&apos;re all pretty alarming in their own ways. </p><p>If you&apos;re new here, welcome to the show where we break down the latest cybersecurity news and help you understand what&apos;s really happening in the cyber security domains.</p><p>We&apos;re going to talk about a shocking discovery about AI security - turns out it takes way fewer malicious documents than anyone thought to completely poison an AI model. Then we&apos;ll discuss something that should make every security professional cringe - CISA just added a dozen vulnerabilities to their Known Exploited Vulnerabilities catalog, and half of them are over a decade old. And finally, we&apos;ll cover Salesforce&apos;s bold decision not to pay ransom to hackers who claim to have stolen data from dozens of major companies.</p><p>- <a href='https://www.anthropic.com/research/small-samples-poison'>https://www.anthropic.com</a>: Small Samples Poison</p><p>- <a href='https://www.turing.ac.uk/blog/llms-may-be-more-vulnerable-data-poisoning-we-thought'>https://www.turing.ac.uk</a>: LLMS May Be More Vulnerable Data Poisoning W Thought</p><p>- <a href='https://www.theregister.com/2025/10/08/salesforce_refuses_to_pay_ransomware/'>https://www.theregister.com</a>: Salesforce Refuses To Pay Ransomware</p><p>- <a href='https://www.sans.org/newsletters/newsbites/xxvii-73'>https://www.sans.org</a>: CISA Adds 12 CVEs to KEV; Half are a Decade or More Old</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18072169-245-50-documents-can-poison-ai-models-cisa-kev-adds-12-decade-old-vulnerabilities-and-salesforce-ransomware.mp3" length="22097409" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18072169</guid>
    <pubDate>Sat, 11 Oct 2025 21:00:00 +0400</pubDate>
    <itunes:duration>1838</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>244 - The Recent Cyberattacks on European Airports - A Wake-Up Call for Critical Infrastructure</itunes:title>
    <title>244 - The Recent Cyberattacks on European Airports - A Wake-Up Call for Critical Infrastructure</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Picture this: You're at London Heathrow, Europe's busiest airport, ready to check in for your flight. But the kiosks aren't working. The screens are blank. Airport staff are scrambling with iPads and even pen and paper to manually check passengers in. Your flight is delayed, maybe canceled. And you're stuck in a long line with thousands of other frustrated travelers.  Today we're diving into something that disrupted the travel plans of thousand...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Picture this: You&apos;re at London Heathrow, Europe&apos;s busiest airport, ready to check in for your flight. But the kiosks aren&apos;t working. The screens are blank. Airport staff are scrambling with iPads and even pen and paper to manually check passengers in. Your flight is delayed, maybe canceled. And you&apos;re stuck in a long line with thousands of other frustrated travelers.<br/><br/>Today we&apos;re diving into something that disrupted the travel plans of thousands of people just a few weeks ago - a massive cyberattack that brought some of Europe&apos;s busiest airports to a grinding halt.<br/><br/>This wasn&apos;t a scene from the 1970s - this happened in September 2025. And it wasn&apos;t just Heathrow. Brussels, Berlin, Dublin - major airports across Europe were hit simultaneously.<br/><br/>Over the next 30 mins or so, we&apos;re going to unpack what happened, who was behind it, how the attack unfolded, and what this means for the future of critical infrastructure security. We&apos;ll also look back at other major airport attacks from recent years to understand the bigger picture.<br/><br/>So whether you&apos;re a security analyst, a CISO, or just someone who travels and wants to understand these threats, stick around.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Picture this: You&apos;re at London Heathrow, Europe&apos;s busiest airport, ready to check in for your flight. But the kiosks aren&apos;t working. The screens are blank. Airport staff are scrambling with iPads and even pen and paper to manually check passengers in. Your flight is delayed, maybe canceled. And you&apos;re stuck in a long line with thousands of other frustrated travelers.<br/><br/>Today we&apos;re diving into something that disrupted the travel plans of thousands of people just a few weeks ago - a massive cyberattack that brought some of Europe&apos;s busiest airports to a grinding halt.<br/><br/>This wasn&apos;t a scene from the 1970s - this happened in September 2025. And it wasn&apos;t just Heathrow. Brussels, Berlin, Dublin - major airports across Europe were hit simultaneously.<br/><br/>Over the next 30 mins or so, we&apos;re going to unpack what happened, who was behind it, how the attack unfolded, and what this means for the future of critical infrastructure security. We&apos;ll also look back at other major airport attacks from recent years to understand the bigger picture.<br/><br/>So whether you&apos;re a security analyst, a CISO, or just someone who travels and wants to understand these threats, stick around.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/18054968-244-the-recent-cyberattacks-on-european-airports-a-wake-up-call-for-critical-infrastructure.mp3" length="31221844" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-18054968</guid>
    <pubDate>Sat, 04 Oct 2025 22:00:00 +0400</pubDate>
    <itunes:duration>2598</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>243 - Are Web Application Firewalls (WAFs) Obsolete in 2025? Pros, Cons, and Future of Application Security - Part 2</itunes:title>
    <title>243 - Are Web Application Firewalls (WAFs) Obsolete in 2025? Pros, Cons, and Future of Application Security - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.  I am your host Ibrahim Yusuf...  This is part 2 of  where we will continue covering the debate that's been heating up in security circles: Are Web Application Firewalls obsolete? Now, if you've been in the security game for a while, you've probably heard the whispers. Some people are...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.<br/><br/>I am your host Ibrahim Yusuf...<br/><br/>This is part 2 of  where we will continue covering the debate that&apos;s been heating up in security circles: Are Web Application Firewalls obsolete?<br/>Now, if you&apos;ve been in the security game for a while, you&apos;ve probably heard the whispers. Some people are saying WAFs are dead weight, legacy technology from a bygone era. Others swear by them as the cornerstone of application security. So which is it?<br/>Well, listen to these two part episode. I suggest you start with episode 1 first  then come back to this one. In episode 1, we covered all the foundational parts and background. In our second part, we will kick off with modern attacks. Enjoy.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.<br/><br/>I am your host Ibrahim Yusuf...<br/><br/>This is part 2 of  where we will continue covering the debate that&apos;s been heating up in security circles: Are Web Application Firewalls obsolete?<br/>Now, if you&apos;ve been in the security game for a while, you&apos;ve probably heard the whispers. Some people are saying WAFs are dead weight, legacy technology from a bygone era. Others swear by them as the cornerstone of application security. So which is it?<br/>Well, listen to these two part episode. I suggest you start with episode 1 first  then come back to this one. In episode 1, we covered all the foundational parts and background. In our second part, we will kick off with modern attacks. Enjoy.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17993560-243-are-web-application-firewalls-wafs-obsolete-in-2025-pros-cons-and-future-of-application-security-part-2.mp3" length="20656451" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17993560</guid>
    <pubDate>Sat, 27 Sep 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1718</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>242 - Are Web Application Firewalls (WAFs) Obsolete in 2025? Pros, Cons, and Future of Application Security - Part 1</itunes:title>
    <title>242 - Are Web Application Firewalls (WAFs) Obsolete in 2025? Pros, Cons, and Future of Application Security - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! We're tackling a debate that's been heating up in security circles: Are Web Application Firewalls obsolete? Now, if you've been in the security game for a while, you've probably heard the whispers. Some people are saying WAFs are dead weight, legacy technology from a bygone era. Others swear by them as the cornerstone of application security. So which is it? Well, stay tuned because this is exactly what you will find out in today's episode.   -...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We&apos;re tackling a debate that&apos;s been heating up in security circles: Are Web Application Firewalls obsolete?<br/>Now, if you&apos;ve been in the security game for a while, you&apos;ve probably heard the whispers. Some people are saying WAFs are dead weight, legacy technology from a bygone era. Others swear by them as the cornerstone of application security. So which is it?<br/>Well, stay tuned because this is exactly what you will find out in today&apos;s episode.<br/><br/></p><p>- <a href='https://en.wikipedia.org/wiki/Web_application_firewall'>https://en.wikipedia.org</a>: Web Application Firewall</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We&apos;re tackling a debate that&apos;s been heating up in security circles: Are Web Application Firewalls obsolete?<br/>Now, if you&apos;ve been in the security game for a while, you&apos;ve probably heard the whispers. Some people are saying WAFs are dead weight, legacy technology from a bygone era. Others swear by them as the cornerstone of application security. So which is it?<br/>Well, stay tuned because this is exactly what you will find out in today&apos;s episode.<br/><br/></p><p>- <a href='https://en.wikipedia.org/wiki/Web_application_firewall'>https://en.wikipedia.org</a>: Web Application Firewall</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17965419-242-are-web-application-firewalls-wafs-obsolete-in-2025-pros-cons-and-future-of-application-security-part-1.mp3" length="16736830" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17965419</guid>
    <pubDate>Sat, 20 Sep 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1391</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>241 - AI vs. Cybersecurity-How LLMs Are Reshaping the Defender-Attacker Battle</itunes:title>
    <title>241 - AI vs. Cybersecurity-How LLMs Are Reshaping the Defender-Attacker Battle</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode I am joined by my good old friend Shakel Ahmed a cyber security practitioner with over 20 years of experience. We discussing how the cybersecurity landscape is at a tipping point as AI revolutionizes both defenses and threat capabilities. While tools like ML/LLM boost defender and developer efficiency, they're simultaneously empowering attackers with unprecedented advantages—operating without the ethical constraints that ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode I am joined by my good old friend Shakel Ahmed a cyber security practitioner with over 20 years of experience. We discussing how the cybersecurity landscape is at a tipping point as AI revolutionizes both defenses and threat capabilities. While tools like ML/LLM boost defender and developer efficiency, they&apos;re simultaneously empowering attackers with unprecedented advantages—operating without the ethical constraints that limit defenders. As traditional security measures struggle to keep pace, innovative strategies like specialized AI models and strategic honeypot deployments are emerging as critical weapons in this evolving digital battleground.</p><p>- <a href='https://cyberdesserts.com'>https://cyberdesserts.com</a>: Shakel Ahmed&apos;s blog<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode I am joined by my good old friend Shakel Ahmed a cyber security practitioner with over 20 years of experience. We discussing how the cybersecurity landscape is at a tipping point as AI revolutionizes both defenses and threat capabilities. While tools like ML/LLM boost defender and developer efficiency, they&apos;re simultaneously empowering attackers with unprecedented advantages—operating without the ethical constraints that limit defenders. As traditional security measures struggle to keep pace, innovative strategies like specialized AI models and strategic honeypot deployments are emerging as critical weapons in this evolving digital battleground.</p><p>- <a href='https://cyberdesserts.com'>https://cyberdesserts.com</a>: Shakel Ahmed&apos;s blog<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17916974-241-ai-vs-cybersecurity-how-llms-are-reshaping-the-defender-attacker-battle.mp3" length="39850733" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17916974</guid>
    <pubDate>Sat, 13 Sep 2025 22:00:00 +0400</pubDate>
    <itunes:duration>3317</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>240 - The Great OAuth Heist: How Salesloft&#39;s Breach Exposed Major Cybersecurity Firms</itunes:title>
    <title>240 - The Great OAuth Heist: How Salesloft&#39;s Breach Exposed Major Cybersecurity Firms</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we're unpacking one of the most significant supply chain attacks of 2025 - the Salesloft-Drift OAuth breach that sent shockwaves through the enterprise software world.  We'll explore how a compromise at one marketing company led to data theft at some of the biggest names in cybersecurity and technology. We'll break down the technology at the  heart of it all - i.e. those digital keys that let applications talk to each other - and exa...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re unpacking one of the most significant supply chain attacks of 2025 - the Salesloft-Drift OAuth breach that sent shockwaves through the enterprise software world.<br/><br/>We&apos;ll explore how a compromise at one marketing company led to data theft at some of the biggest names in cybersecurity and technology. We&apos;ll break down the technology at the  heart of it all - i.e. those digital keys that let applications talk to each other - and examine how threat actors turned them into free passes for corporate data theft.</p><p>https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift</p><p>- <a href='https://krebsonsecurity.com/2025/09/the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft/'>https://krebsonsecurity.com</a>: The Ongoing Fallout From- A Breach At AI Chatbot-Maker Salesloft</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we&apos;re unpacking one of the most significant supply chain attacks of 2025 - the Salesloft-Drift OAuth breach that sent shockwaves through the enterprise software world.<br/><br/>We&apos;ll explore how a compromise at one marketing company led to data theft at some of the biggest names in cybersecurity and technology. We&apos;ll break down the technology at the  heart of it all - i.e. those digital keys that let applications talk to each other - and examine how threat actors turned them into free passes for corporate data theft.</p><p>https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift</p><p>- <a href='https://krebsonsecurity.com/2025/09/the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft/'>https://krebsonsecurity.com</a>: The Ongoing Fallout From- A Breach At AI Chatbot-Maker Salesloft</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17897699-240-the-great-oauth-heist-how-salesloft-s-breach-exposed-major-cybersecurity-firms.mp3" length="26983404" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17897699</guid>
    <pubDate>Sat, 06 Sep 2025 22:00:00 +0400</pubDate>
    <itunes:duration>2245</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>239 - Volt Typhoon Report-How Critical Infrastructure Was Targeted and Compromised</itunes:title>
    <title>239 - Volt Typhoon Report-How Critical Infrastructure Was Targeted and Compromised</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today’s episode is all about Volt Typhoon, a Chinese state-sponsored hacking group whose stealthy techniques and strategic missions have caused significant concern for defenders worldwide. We’ll break down who Volt Typhoon is, analyze the recent major report covering their activities, walk through real examples of the organizations they targeted, and explain every bit of technical jargon so everyone can follow along. By the end, you’ll und...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today’s episode is all about Volt Typhoon, a Chinese state-sponsored hacking group whose stealthy techniques and strategic missions have caused significant concern for defenders worldwide. We’ll break down who Volt Typhoon is, analyze the recent major report covering their activities, walk through real examples of the organizations they targeted, and explain every bit of technical jargon so everyone can follow along. By the end, you’ll understand why this group is considered one of the top cyber threats facing critical infrastructure today—globally and in the West.</p><p>- <a href='https://www.cyber.nj.gov/home/showpublisheddocument/1133/638918997893370000'>https://www.cyber.nj.gov</a>: VOLT TYPHOON APT A Strategic Threat Assessment</p><p>- <a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a'>https://www.cisa.gov</a>: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today’s episode is all about Volt Typhoon, a Chinese state-sponsored hacking group whose stealthy techniques and strategic missions have caused significant concern for defenders worldwide. We’ll break down who Volt Typhoon is, analyze the recent major report covering their activities, walk through real examples of the organizations they targeted, and explain every bit of technical jargon so everyone can follow along. By the end, you’ll understand why this group is considered one of the top cyber threats facing critical infrastructure today—globally and in the West.</p><p>- <a href='https://www.cyber.nj.gov/home/showpublisheddocument/1133/638918997893370000'>https://www.cyber.nj.gov</a>: VOLT TYPHOON APT A Strategic Threat Assessment</p><p>- <a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a'>https://www.cisa.gov</a>: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17876838-239-volt-typhoon-report-how-critical-infrastructure-was-targeted-and-compromised.mp3" length="18506246" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17876838</guid>
    <pubDate>Sat, 30 Aug 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1538</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>238 - Patchwork and Transparency -Microsoft’s August Security Updates &amp; Google&#39;s Project Zero Redefined</itunes:title>
    <title>238 - Patchwork and Transparency -Microsoft’s August Security Updates &amp; Google&#39;s Project Zero Redefined</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week, the cybersecurity landscape delivers two major stories that demand attention. Microsoft’s August Patch Tuesday brought a wave of critical updates and exposed gaps, challenging defenders to reassess their priorities and protections. Meanwhile, Google’s Project Zero team is changing the rules on how and when the world learns about new vulnerabilities—speeding up transparency and raising fresh questions for vendors and users alike. - ht...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, the cybersecurity landscape delivers two major stories that demand attention. Microsoft’s August Patch Tuesday brought a wave of critical updates and exposed gaps, challenging defenders to reassess their priorities and protections. Meanwhile, Google’s Project Zero team is changing the rules on how and when the world learns about new vulnerabilities—speeding up transparency and raising fresh questions for vendors and users alike.</p><p>- <a href='https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html'>https://thehackernews.com</a>: Microsoft August-= 2025 Patch Tuesday<br/>- <a href=' https://www.infosecurity-magazine.com/news/google-report-new-vulnerabilities/'>https://www.infosecurity-magazine.com</a>: Google to Publicly Report New Vulnerabilities Within One Week of Vendor Disclosure</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, the cybersecurity landscape delivers two major stories that demand attention. Microsoft’s August Patch Tuesday brought a wave of critical updates and exposed gaps, challenging defenders to reassess their priorities and protections. Meanwhile, Google’s Project Zero team is changing the rules on how and when the world learns about new vulnerabilities—speeding up transparency and raising fresh questions for vendors and users alike.</p><p>- <a href='https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html'>https://thehackernews.com</a>: Microsoft August-= 2025 Patch Tuesday<br/>- <a href=' https://www.infosecurity-magazine.com/news/google-report-new-vulnerabilities/'>https://www.infosecurity-magazine.com</a>: Google to Publicly Report New Vulnerabilities Within One Week of Vendor Disclosure</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17829207-238-patchwork-and-transparency-microsoft-s-august-security-updates-google-s-project-zero-redefined.mp3" length="11100624" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17829207</guid>
    <pubDate>Sat, 23 Aug 2025 22:00:00 +0400</pubDate>
    <itunes:duration>921</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>237 - Generative AI Security-How Companies Protect Against Attacks and Data Risks</itunes:title>
    <title>237 - Generative AI Security-How Companies Protect Against Attacks and Data Risks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode, we’re diving into how companies are working to secure Generative AI—the technology behind chatbots, image creators, and code-writing assistants. We’ll break down how it’s different from traditional enterprise security, look at real-world attack examples, bust some myths, and explore what the future holds.   - https://owaspai.org: AI Security Overview - https://artificialintelligenceact.eu: The EU AI Act Be sure to subscribe!&nb...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we’re diving into how companies are working to secure Generative AI—the technology behind chatbots, image creators, and code-writing assistants. We’ll break down how it’s different from traditional enterprise security, look at real-world attack examples, bust some myths, and explore what the future holds.<br/><br/></p><p>- <a href='https://owaspai.org/docs/ai_security_overview/'>https://owaspai.org</a>: AI Security Overview</p><p>- https://artificialintelligenceact.eu: The EU AI Act</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we’re diving into how companies are working to secure Generative AI—the technology behind chatbots, image creators, and code-writing assistants. We’ll break down how it’s different from traditional enterprise security, look at real-world attack examples, bust some myths, and explore what the future holds.<br/><br/></p><p>- <a href='https://owaspai.org/docs/ai_security_overview/'>https://owaspai.org</a>: AI Security Overview</p><p>- https://artificialintelligenceact.eu: The EU AI Act</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17794982-237-generative-ai-security-how-companies-protect-against-attacks-and-data-risks.mp3" length="16302605" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17794982</guid>
    <pubDate>Sat, 16 Aug 2025 21:00:00 +0400</pubDate>
    <itunes:duration>1355</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>236 - The Hidden Danger in Your Cloud-Why Misconfiguration Is the Real Vulnerability</itunes:title>
    <title>236 - The Hidden Danger in Your Cloud-Why Misconfiguration Is the Real Vulnerability</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we’re tackling a critical subject that causes countless data breaches yet often gets misunderstood: misconfiguration — what it is, why it’s different from a software vulnerability, and why it remains one of the biggest security risks organizations face.  One quick reminder before we dive into the main topic:Microsoft reminds of Windows 10 support ending in two months   Windows 10 Sunset Alert: What You Need to Know Before October 2025- ht...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we’re tackling a critical subject that causes countless data breaches yet often gets misunderstood: misconfiguration — what it is, why it’s different from a software vulnerability, and why it remains one of the biggest security risks organizations face.<br/><br/>One quick reminder before we dive into the main topic:Microsoft reminds of Windows 10 support ending in two months<br/><br/></p><ul><li>Windows 10 Sunset Alert: What You Need to Know Before October 2025</li></ul><p>- <a href='https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3632'>https://learn.microsoft.com</a>: Windows 10 End Of Service Reminder</p><p>-  <a href='https://owasp.org/Top10/A05_2021-Security_Misconfiguration/'>https://owasp.org</a>: Security Misconfiguration</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we’re tackling a critical subject that causes countless data breaches yet often gets misunderstood: misconfiguration — what it is, why it’s different from a software vulnerability, and why it remains one of the biggest security risks organizations face.<br/><br/>One quick reminder before we dive into the main topic:Microsoft reminds of Windows 10 support ending in two months<br/><br/></p><ul><li>Windows 10 Sunset Alert: What You Need to Know Before October 2025</li></ul><p>- <a href='https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3632'>https://learn.microsoft.com</a>: Windows 10 End Of Service Reminder</p><p>-  <a href='https://owasp.org/Top10/A05_2021-Security_Misconfiguration/'>https://owasp.org</a>: Security Misconfiguration</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17719516-236-the-hidden-danger-in-your-cloud-why-misconfiguration-is-the-real-vulnerability.mp3" length="22017471" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17719516</guid>
    <pubDate>Sat, 09 Aug 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1831</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>235 - The Microsoft SharePoint vulnerability</itunes:title>
    <title>235 - The Microsoft SharePoint vulnerability</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we focus on a critical and rapidly evolving Microsoft SharePoint vulnerability that’s rocked the security world in July 2025. We’ll walk you through what it is, why it matters, how attackers exploit it, and most importantly, what you and your organization can do to defend against it.  For those new to cybersecurity, we’ll also explain the tricky technical jargon around this vulnerability, so you can follow along confidently, whether you’...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we focus on a critical and rapidly evolving Microsoft SharePoint vulnerability that’s rocked the security world in July 2025. We’ll walk you through what it is, why it matters, how attackers exploit it, and most importantly, what you and your organization can do to defend against it.<br/><br/>For those new to cybersecurity, we’ll also explain the tricky technical jargon around this vulnerability, so you can follow along confidently, whether you’re an entry-level analyst or someone keen to learn more.</p><p>- <a href='https://www.sans.org/blog/critical-sharepoint-zero-day-exploited-what-you-need-to-know-about-cve-2025-53770'>https://www.sans.org</a>: Critical SharePoint Zero-Day Exploited: What You Need to Know About CVE-2025-53770</p><p>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770'>https://msrc.microsoft.com</a>: Update Guide Vulnerability CVE-2025-53770</p><p>- <a href='https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/'>https://msrc.microsoft.com</a>: Guidance For Sharepoint Vulnerability CVE 2025-53770/</p><p>- <a href='https://www.bleepingcomputer.com/news/security/us-nuclear-weapons-agency-hacked-in-microsoft-sharepoint-attacks/'>https://www.bleepingcomputer.com</a>: US nuclear weapons agency hacked in Microsoft SharePoint attacks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we focus on a critical and rapidly evolving Microsoft SharePoint vulnerability that’s rocked the security world in July 2025. We’ll walk you through what it is, why it matters, how attackers exploit it, and most importantly, what you and your organization can do to defend against it.<br/><br/>For those new to cybersecurity, we’ll also explain the tricky technical jargon around this vulnerability, so you can follow along confidently, whether you’re an entry-level analyst or someone keen to learn more.</p><p>- <a href='https://www.sans.org/blog/critical-sharepoint-zero-day-exploited-what-you-need-to-know-about-cve-2025-53770'>https://www.sans.org</a>: Critical SharePoint Zero-Day Exploited: What You Need to Know About CVE-2025-53770</p><p>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770'>https://msrc.microsoft.com</a>: Update Guide Vulnerability CVE-2025-53770</p><p>- <a href='https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/'>https://msrc.microsoft.com</a>: Guidance For Sharepoint Vulnerability CVE 2025-53770/</p><p>- <a href='https://www.bleepingcomputer.com/news/security/us-nuclear-weapons-agency-hacked-in-microsoft-sharepoint-attacks/'>https://www.bleepingcomputer.com</a>: US nuclear weapons agency hacked in Microsoft SharePoint attacks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17662407-235-the-microsoft-sharepoint-vulnerability.mp3" length="20097027" type="audio/mpeg" />
    <link>https://yusufonsecurity.com</link>
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17662407</guid>
    <pubDate>Sat, 02 Aug 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1671</itunes:duration>
    <itunes:keywords>sharepoint</itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>234 - Protecting the Invisible-How to Secure Infrastructure without Agents</itunes:title>
    <title>234 - Protecting the Invisible-How to Secure Infrastructure without Agents</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! The world of cybersecurity isn’t just about defending laptops and servers—it’s also about safeguarding the “invisible” corners of our networks: those printers, cameras, routers, and dozens of other devices that quietly power our organizations. But what do you do when you can’t install security software or agents on these endpoints? In this episode of YusufOnSecurity, we’re digging into the art and science of protecting infrastructure you can’t ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The world of cybersecurity isn’t just about defending laptops and servers—it’s also about safeguarding the “invisible” corners of our networks: those printers, cameras, routers, and dozens of other devices that quietly power our organizations. But what do you do when you can’t install security software or agents on these endpoints? In this episode of YusufOnSecurity, we’re digging into the art and science of protecting infrastructure you can’t easily touch or monitor from within. From game-changing network tactics to clever monitoring tricks, we’ll explore the evolving landscape of agentless security—and why protecting these overlooked devices just might be the next frontier in building a truly resilient environment. Stay with me as we unlock the secrets of securing the unmanageable.</p><p>- <a href='https://www.techtarget.com/searchsecurity/tip/Agent-vs-agentless-security-Learn-the-differences'>https://www.techtarget.com</a>: Agent vs Agentless Security Learn The Differences</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The world of cybersecurity isn’t just about defending laptops and servers—it’s also about safeguarding the “invisible” corners of our networks: those printers, cameras, routers, and dozens of other devices that quietly power our organizations. But what do you do when you can’t install security software or agents on these endpoints? In this episode of YusufOnSecurity, we’re digging into the art and science of protecting infrastructure you can’t easily touch or monitor from within. From game-changing network tactics to clever monitoring tricks, we’ll explore the evolving landscape of agentless security—and why protecting these overlooked devices just might be the next frontier in building a truly resilient environment. Stay with me as we unlock the secrets of securing the unmanageable.</p><p>- <a href='https://www.techtarget.com/searchsecurity/tip/Agent-vs-agentless-security-Learn-the-differences'>https://www.techtarget.com</a>: Agent vs Agentless Security Learn The Differences</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17627803-234-protecting-the-invisible-how-to-secure-infrastructure-without-agents.mp3" length="20075822" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17627803</guid>
    <pubDate>Sat, 26 Jul 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1669</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>233 - CI-CD Pipelines and Associated Security Risks</itunes:title>
    <title>233 - CI-CD Pipelines and Associated Security Risks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we talk through the technical details of CI/CD (Continuous Integration/Continuous Development) pipelines: what they are, how they work, the jargon around them, and the potential security risks organizations need to be aware of. Finally, we’ll bust a persistent myth in software development that you might find surprising. - https://www.cisco.com: What is CI/CD? Be sure to subscribe!   You can also stream from htt...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we talk through the technical details of CI/CD (Continuous Integration/Continuous Development) pipelines: what they are, how they work, the jargon around them, and the potential security risks organizations need to be aware of. Finally, we’ll bust a persistent myth in software development that you might find surprising.</p><p>- <a href='https://www.cisco.com/site/us/en/learn/topics/computing/what-is-ci-cd.html'>https://www.cisco.com</a>: What is CI/CD?</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we talk through the technical details of CI/CD (Continuous Integration/Continuous Development) pipelines: what they are, how they work, the jargon around them, and the potential security risks organizations need to be aware of. Finally, we’ll bust a persistent myth in software development that you might find surprising.</p><p>- <a href='https://www.cisco.com/site/us/en/learn/topics/computing/what-is-ci-cd.html'>https://www.cisco.com</a>: What is CI/CD?</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17599474-233-ci-cd-pipelines-and-associated-security-risks.mp3" length="19881687" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17599474</guid>
    <pubDate>Sat, 19 Jul 2025 23:00:00 +0400</pubDate>
    <itunes:duration>1653</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>232 - Catching up with security</itunes:title>
    <title>232 - Catching up with security</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today’s episode takes you through three intersecting stories revealing how technology shapes both our vulnerabilities and our digital identity—from the sprawling and adaptable threat of AsyncRAT malware, to critical Bluetooth vulnerabilities threatening millions of vehicles globally, and finally to a thought-provoking glimpse into how AI models create intimate profiles of their users.  - https://simonwillison.net/2025: Simon's ChatGPT doss...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today’s episode takes you through three intersecting stories revealing how technology shapes both our vulnerabilities and our digital identity—from the sprawling and adaptable threat of AsyncRAT malware, to critical Bluetooth vulnerabilities threatening millions of vehicles globally, and finally to a thought-provoking glimpse into how AI models create intimate profiles of their users. </p><p>- <a href='https://simonwillison.net/2025/May/21/chatgpt-new-memory/'>https://simonwillison.ne</a>t/2025: Simon&apos;s ChatGPT dossier</p><p>- <a href='https://blog.talosintelligence.com/asyncrat-3losh-update/'>https://blog.talosintelligence.com</a>/AsyncRAT</p><p>- <a href='https://www.bankinfosecurity.com/perfektblue-bug-chain-exposes-cars-to-bluetooth-hacking-a-28958'>https://www.bankinfosecurity.com</a>: PerfektBlue Bug</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today’s episode takes you through three intersecting stories revealing how technology shapes both our vulnerabilities and our digital identity—from the sprawling and adaptable threat of AsyncRAT malware, to critical Bluetooth vulnerabilities threatening millions of vehicles globally, and finally to a thought-provoking glimpse into how AI models create intimate profiles of their users. </p><p>- <a href='https://simonwillison.net/2025/May/21/chatgpt-new-memory/'>https://simonwillison.ne</a>t/2025: Simon&apos;s ChatGPT dossier</p><p>- <a href='https://blog.talosintelligence.com/asyncrat-3losh-update/'>https://blog.talosintelligence.com</a>/AsyncRAT</p><p>- <a href='https://www.bankinfosecurity.com/perfektblue-bug-chain-exposes-cars-to-bluetooth-hacking-a-28958'>https://www.bankinfosecurity.com</a>: PerfektBlue Bug</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17576747-232-catching-up-with-security.mp3" length="23427299" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17576747</guid>
    <pubDate>Sat, 12 Jul 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1949</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title> 231 - A Crash Course in Vendor Risk, Lessons from the CrowdStrike Outage</itunes:title>
    <title> 231 - A Crash Course in Vendor Risk, Lessons from the CrowdStrike Outage</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we’re focusing on the critical lessons from one of the most disruptive IT failures in recent memory: the global outage triggered by a CrowdStrike software update on July 19, 2024. While the headlines focused on grounded flights and downed systems, the real story lies in what this incident revealed about the way we build, secure, and rely on digital infrastructure.  This episode isn’t just about a faulty update—it’s about the cascading im...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’re focusing on the critical lessons from one of the most disruptive IT failures in recent memory: the global outage triggered by a CrowdStrike software update on July 19, 2024. While the headlines focused on grounded flights and downed systems, the real story lies in what this incident revealed about the way we build, secure, and rely on digital infrastructure.<br/><br/>This episode isn’t just about a faulty update—it’s about the cascading impact of vendor trust, software architecture, and system design decisions made long before disaster strikes. We’ll explore how over-reliance on a single vendor can introduce hidden points of failure, why resilience must be baked into every layer of our IT stack, and how incident response can make or break reputations in a hyperconnected world. We’ll also look at Microsoft’s rapid response and how this moment might reshape the rules for how security software integrates with Windows. The takeaway? In cybersecurity, it’s not enough to be secure—you also have to be prepared for when your most trusted systems fail.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’re focusing on the critical lessons from one of the most disruptive IT failures in recent memory: the global outage triggered by a CrowdStrike software update on July 19, 2024. While the headlines focused on grounded flights and downed systems, the real story lies in what this incident revealed about the way we build, secure, and rely on digital infrastructure.<br/><br/>This episode isn’t just about a faulty update—it’s about the cascading impact of vendor trust, software architecture, and system design decisions made long before disaster strikes. We’ll explore how over-reliance on a single vendor can introduce hidden points of failure, why resilience must be baked into every layer of our IT stack, and how incident response can make or break reputations in a hyperconnected world. We’ll also look at Microsoft’s rapid response and how this moment might reshape the rules for how security software integrates with Windows. The takeaway? In cybersecurity, it’s not enough to be secure—you also have to be prepared for when your most trusted systems fail.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17497075-231-a-crash-course-in-vendor-risk-lessons-from-the-crowdstrike-outage.mp3" length="21109642" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17497075</guid>
    <pubDate>Sat, 05 Jul 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1755</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>230 - Security Of iOT</itunes:title>
    <title>230 - Security Of iOT</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week on YusufOnSecurity, we’re diving into a topic that’s become increasingly critical as our world grows more connected: the security of the Internet of Things, or IoT. From smart thermostats and wearable fitness trackers to industrial sensors and connected cars, IoT devices are now woven into the fabric of our daily lives and business operations. They promise greater convenience, efficiency, and innovation—but they also introduce new ris...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week on YusufOnSecurity, we’re diving into a topic that’s become increasingly critical as our world grows more connected: the security of the Internet of Things, or IoT. From smart thermostats and wearable fitness trackers to industrial sensors and connected cars, IoT devices are now woven into the fabric of our daily lives and business operations. They promise greater convenience, efficiency, and innovation—but they also introduce new risks and vulnerabilities that many organizations and individuals are just beginning to understand.<br/><br/>Securing IoT isn’t just about protecting gadgets; it’s about safeguarding the data they collect, the networks they connect to, and ultimately, the people and processes that rely on them. As the number of IoT devices skyrockets, attackers are finding new ways to exploit weak points—sometimes with far-reaching consequences. In this episode, we’ll explore why IoT security matters, the unique challenges it presents, and practical steps you can take to protect your connected world.</p><p>- <a href='https://www.cisco.com/site/us/en/learn/topics/industrial-iot/what-is-iot.html#tabs-35d568e0ff-item-4bd7dc8124-tab'>https://www.cisco.com</a>: What is iOT?</p><p>- <a href='https://www.iiconsortium.org/smm/'>https://www.iiconsortium.org</a>: Security Maturity Model</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week on YusufOnSecurity, we’re diving into a topic that’s become increasingly critical as our world grows more connected: the security of the Internet of Things, or IoT. From smart thermostats and wearable fitness trackers to industrial sensors and connected cars, IoT devices are now woven into the fabric of our daily lives and business operations. They promise greater convenience, efficiency, and innovation—but they also introduce new risks and vulnerabilities that many organizations and individuals are just beginning to understand.<br/><br/>Securing IoT isn’t just about protecting gadgets; it’s about safeguarding the data they collect, the networks they connect to, and ultimately, the people and processes that rely on them. As the number of IoT devices skyrockets, attackers are finding new ways to exploit weak points—sometimes with far-reaching consequences. In this episode, we’ll explore why IoT security matters, the unique challenges it presents, and practical steps you can take to protect your connected world.</p><p>- <a href='https://www.cisco.com/site/us/en/learn/topics/industrial-iot/what-is-iot.html#tabs-35d568e0ff-item-4bd7dc8124-tab'>https://www.cisco.com</a>: What is iOT?</p><p>- <a href='https://www.iiconsortium.org/smm/'>https://www.iiconsortium.org</a>: Security Maturity Model</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17447906-230-security-of-iot.mp3" length="27225639" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17447906</guid>
    <pubDate>Sat, 28 Jun 2025 22:00:00 +0400</pubDate>
    <itunes:duration>2265</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>229 - What is FIPS 140-3</itunes:title>
    <title>229 - What is FIPS 140-3</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today’s interconnected world, the security of our digital infrastructure relies heavily on cryptography—the science of protecting information by transforming it into unreadable formats for unauthorized users. But how do we know the cryptographic solutions we use are truly secure? That’s where standards like FIPS 140-3 come in. - https://csrc.nist.gov: FIPS-140-40-3 Be sure to subscribe!   You can also stream from https://yusufonsec...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s interconnected world, the security of our digital infrastructure relies heavily on cryptography—the science of protecting information by transforming it into unreadable formats for unauthorized users. But how do we know the cryptographic solutions we use are truly secure? That’s where standards like FIPS 140-3 come in.</p><p>- <a href='https://csrc.nist.gov/pubs/fips/140-3/final'>https://csrc.nist.gov</a>: FIPS-140-40-3</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s interconnected world, the security of our digital infrastructure relies heavily on cryptography—the science of protecting information by transforming it into unreadable formats for unauthorized users. But how do we know the cryptographic solutions we use are truly secure? That’s where standards like FIPS 140-3 come in.</p><p>- <a href='https://csrc.nist.gov/pubs/fips/140-3/final'>https://csrc.nist.gov</a>: FIPS-140-40-3</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17394868-229-what-is-fips-140-3.mp3" length="16541354" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17394868</guid>
    <pubDate>Sat, 21 Jun 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1375</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>228 -  How the Emergence of AI-Powered Malware works</itunes:title>
    <title>228 -  How the Emergence of AI-Powered Malware works</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today’s episode is about a seismic shift in the world of cyber threats. The emergence of AI-powered malware. We’ll unpack how this new breed of malware works, the science behind it, real-world incidents, and what the latest academic research reveals.   We will also look at the latest news that some are calling "The mother of all breaches". We have all that coming up next, in this week's podcast! - https://www.bleepingcomputer.com: No, t...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s episode is about a seismic shift in the world of cyber threats. The emergence of AI-powered malware. We’ll unpack how this new breed of malware works, the science behind it, real-world incidents, and what the latest academic research reveals. <br/><br/>We will also look at the latest news that some are calling &quot;The mother of all breaches&quot;.</p><p>We have all that coming up next, in this week&apos;s podcast!</p><p>- <a href='https://www.bleepingcomputer.com/news/security/no-the-16-billion-credentials-leak-is-not-a-new-data-breach/'>https://www.bleepingcomputer.com</a>: No, the 16 billion credentials leak is not a new data breach</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s episode is about a seismic shift in the world of cyber threats. The emergence of AI-powered malware. We’ll unpack how this new breed of malware works, the science behind it, real-world incidents, and what the latest academic research reveals. <br/><br/>We will also look at the latest news that some are calling &quot;The mother of all breaches&quot;.</p><p>We have all that coming up next, in this week&apos;s podcast!</p><p>- <a href='https://www.bleepingcomputer.com/news/security/no-the-16-billion-credentials-leak-is-not-a-new-data-breach/'>https://www.bleepingcomputer.com</a>: No, the 16 billion credentials leak is not a new data breach</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17370428-228-how-the-emergence-of-ai-powered-malware-works.mp3" length="18998019" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17370428</guid>
    <pubDate>Sat, 14 Jun 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1579</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>227 - Is UTM Still Relevant?</itunes:title>
    <title>227 - Is UTM Still Relevant?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we’ll answer a pressing question in cybersecurity: Is UTM still relevant in 2025? We’ll trace the origins of UTM, explain why it was created, break down its core features, compare it to newer technologies, and finish by busting a common cybersecurity myth.  Before we dive into our main topic, let’s take a quick look at a major tech update making headlines:  The emergence of AI powered malware is becoming more real- https://en.wikipe...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’ll answer a pressing question in cybersecurity: Is UTM still relevant in 2025? We’ll trace the origins of UTM, explain why it was created, break down its core features, compare it to newer technologies, and finish by busting a common cybersecurity myth.<br/><br/>Before we dive into our main topic, let’s take a quick look at a major tech update making headlines: </p><ul><li>The emergence of AI powered malware is becoming more real</li></ul><p>- <a href='https://en.wikipedia.org/wiki/UTM'>https://en.wikipedia.org</a>: UTM</p><p>- <a href='https://perception-point.io/guides/ai-security/ai-malware-types-real-life-examples-defensive-measures/'>https://perception-point.io</a>: AI Malware: Types, Real Life Examples, and Defensive Measures</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’ll answer a pressing question in cybersecurity: Is UTM still relevant in 2025? We’ll trace the origins of UTM, explain why it was created, break down its core features, compare it to newer technologies, and finish by busting a common cybersecurity myth.<br/><br/>Before we dive into our main topic, let’s take a quick look at a major tech update making headlines: </p><ul><li>The emergence of AI powered malware is becoming more real</li></ul><p>- <a href='https://en.wikipedia.org/wiki/UTM'>https://en.wikipedia.org</a>: UTM</p><p>- <a href='https://perception-point.io/guides/ai-security/ai-malware-types-real-life-examples-defensive-measures/'>https://perception-point.io</a>: AI Malware: Types, Real Life Examples, and Defensive Measures</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17340955-227-is-utm-still-relevant.mp3" length="32156526" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17340955</guid>
    <pubDate>Sat, 07 Jun 2025 23:00:00 +0400</pubDate>
    <itunes:duration>2676</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>226 - Inside A Stealthy Malware Powering Modern Cyber Attacks</itunes:title>
    <title>226 - Inside A Stealthy Malware Powering Modern Cyber Attacks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we get into some detailed exploration of an up and coming  malware. Looking at it closer, it is one of the most advanced post-exploitation code families shaping the cybersecurity landscape in 2025. Over the time we have together, we’ll unravel what this malware is, how it works, why it’s so dangerous, and most importantly what businesses can do to defend themselves. Along the way, we’ll break down technical terms an...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we get into some detailed exploration of an up and coming  malware. Looking at it closer, it is one of the most advanced post-exploitation code families shaping the cybersecurity landscape in 2025. Over the time we have together, we’ll unravel what this malware is, how it works, why it’s so dangerous, and most importantly what businesses can do to defend themselves. Along the way, we’ll break down technical terms and processes, to make the topic less complex as I need it to be accessible and engaging to everyone.<br/><br/>Before we dive into our main topic, let’s take a quick look at a major tech update making headlines: <br/><br/></p><ul><li>Microsoft Authenticator Now Warns To Export Passwords Before July Cut Off</li></ul><p>-<a href='https://www.bleepingcomputer.com/news/security/ransomware-gangs-increasingly-use-skitnet-post-exploitation-malware/'>https://www.bleepingcomputer.com</a>: Ransomware gangs increasingly use Skitnet post-exploitation malware</p><p>- <a href='https://otx.alienvault.com/pulse/68277457715a0eb67108a0a5'>https://otx.alienvault.com</a>: Skitnet IOCs</p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we get into some detailed exploration of an up and coming  malware. Looking at it closer, it is one of the most advanced post-exploitation code families shaping the cybersecurity landscape in 2025. Over the time we have together, we’ll unravel what this malware is, how it works, why it’s so dangerous, and most importantly what businesses can do to defend themselves. Along the way, we’ll break down technical terms and processes, to make the topic less complex as I need it to be accessible and engaging to everyone.<br/><br/>Before we dive into our main topic, let’s take a quick look at a major tech update making headlines: <br/><br/></p><ul><li>Microsoft Authenticator Now Warns To Export Passwords Before July Cut Off</li></ul><p>-<a href='https://www.bleepingcomputer.com/news/security/ransomware-gangs-increasingly-use-skitnet-post-exploitation-malware/'>https://www.bleepingcomputer.com</a>: Ransomware gangs increasingly use Skitnet post-exploitation malware</p><p>- <a href='https://otx.alienvault.com/pulse/68277457715a0eb67108a0a5'>https://otx.alienvault.com</a>: Skitnet IOCs</p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17297619-226-inside-a-stealthy-malware-powering-modern-cyber-attacks.mp3" length="34226066" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17297619</guid>
    <pubDate>Sat, 31 May 2025 22:00:00 +0400</pubDate>
    <itunes:duration>2848</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>225 - What Is a Content Delivery Network—And Do They Really Protect Businesses?</itunes:title>
    <title>225 - What Is a Content Delivery Network—And Do They Really Protect Businesses?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week we are exploring what Content Delivery Networks —commonly known as CDNs— are and whether they protect modern businesses. We’ll dive deep into the mechanics of how CDNs work, the technologies behind them, and whether they defend organizations from  threats or just deliver content at blazing speeds. Along the way, we’ll highlight two of the world’s leading CDN providers. - https://en.wikipedia.org: Content Delivery Network - https:...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week we are exploring what Content Delivery Networks —commonly known as CDNs— are and whether they protect modern businesses. We’ll dive deep into the mechanics of how CDNs work, the technologies behind them, and whether they defend organizations from  threats or just deliver content at blazing speeds. Along the way, we’ll highlight two of the world’s leading CDN providers.</p><p>- <a href='https://en.wikipedia.org/wiki/Content_delivery_network#:~:text=A%20content%20delivery%20network%20or,spatially%20relative%20to%20end%20users.'>https://en.wikipedia.org</a>: Content Delivery Network</p><p>- <a href='https://www.cloudflare.com/learning/cdn/what-is-a-cdn/'>https://www.cloudflare.com</a>: What Is CDN?</p><p>- <a href='https://www.akamai.com/glossary/what-is-a-cdn#:~:text=A%20content%20delivery%20network%20(CDN,closer%20to%20where%20users%20are.'>https://www.akamai.com</a>: What Is CDN?</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week we are exploring what Content Delivery Networks —commonly known as CDNs— are and whether they protect modern businesses. We’ll dive deep into the mechanics of how CDNs work, the technologies behind them, and whether they defend organizations from  threats or just deliver content at blazing speeds. Along the way, we’ll highlight two of the world’s leading CDN providers.</p><p>- <a href='https://en.wikipedia.org/wiki/Content_delivery_network#:~:text=A%20content%20delivery%20network%20or,spatially%20relative%20to%20end%20users.'>https://en.wikipedia.org</a>: Content Delivery Network</p><p>- <a href='https://www.cloudflare.com/learning/cdn/what-is-a-cdn/'>https://www.cloudflare.com</a>: What Is CDN?</p><p>- <a href='https://www.akamai.com/glossary/what-is-a-cdn#:~:text=A%20content%20delivery%20network%20(CDN,closer%20to%20where%20users%20are.'>https://www.akamai.com</a>: What Is CDN?</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17264907-225-what-is-a-content-delivery-network-and-do-they-really-protect-businesses.mp3" length="17670217" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17264907</guid>
    <pubDate>Sat, 24 May 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1469</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>224 - Cisco Talos Year 2024 In Review</itunes:title>
    <title>224 - Cisco Talos Year 2024 In Review</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we are looking at the latest Cisco Talos’ 2024 report.   In this comprehensive report, we will delve into the major cybersecurity trends and threats observed over the past year. Cisco Talos team, has compiled this report to provide valuable insights and guidance for organizations to enhance their security postures.  But before we get in to the main topic, I have one security news for you and that is:  - The European...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we are looking at the latest Cisco Talos’ 2024 report.  <br/>In this comprehensive report, we will delve into the major cybersecurity trends and threats observed over the past year. Cisco Talos team, has compiled this report to provide valuable insights and guidance for organizations to enhance their security postures.<br/><br/>But before we get in to the main topic, I have one security news for you and that is:<br/><br/>- The European Union launches a new vulnerability Database - EUVD</p><p>- <a href='https://euvd.enisa.europa.eu/'>https://euvd.enisa.europa.eu</a>: EUVD</p><p>- <a href='https://euvd.enisa.europa.eu/faq'>https://euvd.enisa.europa.eu/faq</a>: EUVD FAQ</p><p>- <a href='https://blog.talosintelligence.com/content/files/2025/03/2024YiR-report.pdf'>https://blog.talosintelligence.com</a>: 2024 Year In Review Report</p><p>- <a href='https://www.forbes.com/councils/forbestechcouncil/2025/05/23/20-modern-tech-tools-that-are-advancing-public-safety/'>https://www.forbes.com</a>: Why Quantum Computers Will Work Alongside Classical Systems</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we are looking at the latest Cisco Talos’ 2024 report.  <br/>In this comprehensive report, we will delve into the major cybersecurity trends and threats observed over the past year. Cisco Talos team, has compiled this report to provide valuable insights and guidance for organizations to enhance their security postures.<br/><br/>But before we get in to the main topic, I have one security news for you and that is:<br/><br/>- The European Union launches a new vulnerability Database - EUVD</p><p>- <a href='https://euvd.enisa.europa.eu/'>https://euvd.enisa.europa.eu</a>: EUVD</p><p>- <a href='https://euvd.enisa.europa.eu/faq'>https://euvd.enisa.europa.eu/faq</a>: EUVD FAQ</p><p>- <a href='https://blog.talosintelligence.com/content/files/2025/03/2024YiR-report.pdf'>https://blog.talosintelligence.com</a>: 2024 Year In Review Report</p><p>- <a href='https://www.forbes.com/councils/forbestechcouncil/2025/05/23/20-modern-tech-tools-that-are-advancing-public-safety/'>https://www.forbes.com</a>: Why Quantum Computers Will Work Alongside Classical Systems</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17218741-224-cisco-talos-year-2024-in-review.mp3" length="24978358" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-17218741</guid>
    <pubDate>Sat, 17 May 2025 23:00:00 +0400</pubDate>
    <itunes:duration>2078</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>223 - RSAC 2025 - Part 2</itunes:title>
    <title>223 - RSAC 2025 - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is the part 2 of RSAC 2025 episode. If you have not listened to episode 1 (that episode 222), I would suggest you listen to episode 1 before you listen this episode.  Before you we get into part 2, lets review what has been happening last week on the news front.  - UK shares security tips after major retail cyberattacks - https://www.bleepingcomputer.com: UK NCSC Cyber Attack A Wake Up call - https://www.ncsc.gov.uk:NCSC statement - I...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the part 2 of RSAC 2025 episode. If you have not listened to episode 1 (that episode 222), I would suggest you listen to episode 1 before you listen this episode.<br/><br/>Before you we get into part 2, lets review what has been happening last week on the news front.<br/><br/>- UK shares security tips after major retail cyberattacks</p><p>- <a href='https://www.bleepingcomputer.com/news/security/uk-ncsc-cyberattacks-impacting-uk-retailers-are-a-wake-up-call/'>https://www.bleepingcomputer.com</a>: UK NCSC Cyber Attack A Wake Up call</p><p>- <a href='https://www.ncsc.gov.uk/news/retailers-incident'>https://www.ncsc.gov.uk</a>:NCSC statement - Incident impacting retailers</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the part 2 of RSAC 2025 episode. If you have not listened to episode 1 (that episode 222), I would suggest you listen to episode 1 before you listen this episode.<br/><br/>Before you we get into part 2, lets review what has been happening last week on the news front.<br/><br/>- UK shares security tips after major retail cyberattacks</p><p>- <a href='https://www.bleepingcomputer.com/news/security/uk-ncsc-cyberattacks-impacting-uk-retailers-are-a-wake-up-call/'>https://www.bleepingcomputer.com</a>: UK NCSC Cyber Attack A Wake Up call</p><p>- <a href='https://www.ncsc.gov.uk/news/retailers-incident'>https://www.ncsc.gov.uk</a>:NCSC statement - Incident impacting retailers</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17182106-223-rsac-2025-part-2.mp3" length="15825077" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17182106</guid>
    <pubDate>Sat, 10 May 2025 17:00:00 +0400</pubDate>
    <itunes:duration>1315</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>222 - RSAC 2025 - Part 1</itunes:title>
    <title>222 - RSAC 2025 - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It was RSAC week and it would be remiss of me if I did not give you a highlight on what went on this year, 2025. After all, RSAC has a critical role in security.  We will be reviewing the top key announcements from this year's event, including some exciting news from the major security players in the industry. Whether you're a cybersecurity professional, a tech enthusiast, or just curious about the latest in the world of cyber security, th...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It was RSAC week and it would be remiss of me if I did not give you a highlight on what went on this year, 2025. After all, RSAC has a critical role in security.  We will be reviewing the top key announcements from this year&apos;s event, including some exciting news from the major security players in the industry. Whether you&apos;re a cybersecurity professional, a tech enthusiast, or just curious about the latest in the world of cyber security, this episode is definitely for you. So, let&apos;s get started!<br/><br/>Before we dive into the main segment, we will also add one more topic that I think is of major importance on top of everything else and that is from Microsoft.<br/><br/></p><ul><li>Microsoft makes All new Account Passwordless by default</li></ul><p>- <a href='https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-user-experience-for-consumer-authentication/3822035'>https://techcommunity.microsoft.com</a>: New User Experience</p><p>- <a href='https://www.rsaconference.com/'>https://www.rsaconference.com</a>: RSA Conference 2025</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It was RSAC week and it would be remiss of me if I did not give you a highlight on what went on this year, 2025. After all, RSAC has a critical role in security.  We will be reviewing the top key announcements from this year&apos;s event, including some exciting news from the major security players in the industry. Whether you&apos;re a cybersecurity professional, a tech enthusiast, or just curious about the latest in the world of cyber security, this episode is definitely for you. So, let&apos;s get started!<br/><br/>Before we dive into the main segment, we will also add one more topic that I think is of major importance on top of everything else and that is from Microsoft.<br/><br/></p><ul><li>Microsoft makes All new Account Passwordless by default</li></ul><p>- <a href='https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-user-experience-for-consumer-authentication/3822035'>https://techcommunity.microsoft.com</a>: New User Experience</p><p>- <a href='https://www.rsaconference.com/'>https://www.rsaconference.com</a>: RSA Conference 2025</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17149727-222-rsac-2025-part-1.mp3" length="25895908" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17149727</guid>
    <pubDate>Sat, 03 May 2025 22:00:00 +0400</pubDate>
    <itunes:duration>2154</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>221 - FBI’s 2024 Annual Internet Crime Report</itunes:title>
    <title>221 - FBI’s 2024 Annual Internet Crime Report</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week's episode looks at the FBI’s 2024 Annual Internet Crime Report -an analysis that not only highlights the scale of cybercrime but also reveals the evolving tactics of cybercriminals and the staggering financial impact on individuals and businesses alike. This of course relates to US but it is an indicative what might be happening elsewhere. - https://www.ic3.gov: Federal Bureau Of Investigation - Internet Crime Report 2024 Be sure to s...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode looks at the FBI’s 2024 Annual Internet Crime Report -an analysis that not only highlights the scale of cybercrime but also reveals the evolving tactics of cybercriminals and the staggering financial impact on individuals and businesses alike. This of course relates to US but it is an indicative what might be happening elsewhere.</p><p>- <a href='https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf'>https://www.ic3.gov</a>: Federal Bureau Of Investigation - Internet Crime Report 2024</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode looks at the FBI’s 2024 Annual Internet Crime Report -an analysis that not only highlights the scale of cybercrime but also reveals the evolving tactics of cybercriminals and the staggering financial impact on individuals and businesses alike. This of course relates to US but it is an indicative what might be happening elsewhere.</p><p>- <a href='https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf'>https://www.ic3.gov</a>: Federal Bureau Of Investigation - Internet Crime Report 2024</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17078033-221-fbi-s-2024-annual-internet-crime-report.mp3" length="23282242" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17078033</guid>
    <pubDate>Sat, 26 Apr 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1936</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>220 - Watering Hole Attacks-The Hidden Danger of Trusted Spaces</itunes:title>
    <title>220 - Watering Hole Attacks-The Hidden Danger of Trusted Spaces</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Imagine visiting your favorite website-one you trust, one you’ve browsed a hundred times before-only to discover it’s become a silent gateway for cybercriminals. What if the real danger wasn’t in suspicious emails or obvious scams, but lurking in the very places you feel safest online? In today’s episode, we’ll unravel a cunning technique that preys on trust and routine, catching even the most vigilant users off guard. Stay tuned as we explore ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Imagine visiting your favorite website-one you trust, one you’ve browsed a hundred times before-only to discover it’s become a silent gateway for cybercriminals. What if the real danger wasn’t in suspicious emails or obvious scams, but lurking in the very places you feel safest online? In today’s episode, we’ll unravel a cunning technique that preys on trust and routine, catching even the most vigilant users off guard. Stay tuned as we explore the origins, methods, and real-world impact of one of the most deceptive cyber threats in existence.<br/><br/>But before we get to the main topic, lets cover the top security news first<br/><br/></p><ul><li>Lazarus hackers breach multiple organisation in a not so new attack method. We will find out what the technique is.</li></ul><p>- <a href='https://attack.mitre.org/groups/G0032/?utm_source=chatgpt.com'>https://attack.mitre.org</a>: Lazarus</p><p>- <a href='https://attack.mitre.org/techniques/T1189/'>https://attack.mitre.org</a>: Drive by compromise</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Imagine visiting your favorite website-one you trust, one you’ve browsed a hundred times before-only to discover it’s become a silent gateway for cybercriminals. What if the real danger wasn’t in suspicious emails or obvious scams, but lurking in the very places you feel safest online? In today’s episode, we’ll unravel a cunning technique that preys on trust and routine, catching even the most vigilant users off guard. Stay tuned as we explore the origins, methods, and real-world impact of one of the most deceptive cyber threats in existence.<br/><br/>But before we get to the main topic, lets cover the top security news first<br/><br/></p><ul><li>Lazarus hackers breach multiple organisation in a not so new attack method. We will find out what the technique is.</li></ul><p>- <a href='https://attack.mitre.org/groups/G0032/?utm_source=chatgpt.com'>https://attack.mitre.org</a>: Lazarus</p><p>- <a href='https://attack.mitre.org/techniques/T1189/'>https://attack.mitre.org</a>: Drive by compromise</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17055664-220-watering-hole-attacks-the-hidden-danger-of-trusted-spaces.mp3" length="23581641" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17055664</guid>
    <pubDate>Sat, 19 Apr 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1961</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>219 - What Is Agentic AI?</itunes:title>
    <title>219 - What Is Agentic AI?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode we are touching an intriguing topic. We're going to explore Agentic AI, a fascinating area within artificial intelligence that focuses on autonomous systems capable of making decisions and performing tasks without human intervention. We'll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear  But we before we dive into the topic, lets recap the top securit...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we are touching an intriguing topic. We&apos;re going to explore Agentic AI, a fascinating area within artificial intelligence that focuses on autonomous systems capable of making decisions and performing tasks without human intervention. We&apos;ll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear<br/><br/>But we before we dive into the topic, lets recap the top security news this week: </p><ul><li>Microsoft defender will isolate undiscovered endpoing to block attacks </li></ul><p>- <a href='https://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint#april-2025'>https://learn.microsoft.com</a>: Whatsbnew in Microsoft Defender Endpoint - Apri 2025</p><p>- <a href='https://en.wikipedia.org/wiki/Alan_Turing'>https://en.wikipedia.org</a>: Alan Turing</p><p>- <a href='https://www.nvidia.com/en-us/ai/'>https://www.nvidia.com</a>: Agentic AI</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we are touching an intriguing topic. We&apos;re going to explore Agentic AI, a fascinating area within artificial intelligence that focuses on autonomous systems capable of making decisions and performing tasks without human intervention. We&apos;ll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear<br/><br/>But we before we dive into the topic, lets recap the top security news this week: </p><ul><li>Microsoft defender will isolate undiscovered endpoing to block attacks </li></ul><p>- <a href='https://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint#april-2025'>https://learn.microsoft.com</a>: Whatsbnew in Microsoft Defender Endpoint - Apri 2025</p><p>- <a href='https://en.wikipedia.org/wiki/Alan_Turing'>https://en.wikipedia.org</a>: Alan Turing</p><p>- <a href='https://www.nvidia.com/en-us/ai/'>https://www.nvidia.com</a>: Agentic AI</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/17012183-219-what-is-agentic-ai.mp3" length="24232014" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-17012183</guid>
    <pubDate>Sat, 12 Apr 2025 22:00:00 +0400</pubDate>
    <itunes:duration>2016</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>218 - Fast Flux-The Cybercriminal&#39;s Hide and Seek</itunes:title>
    <title>218 - Fast Flux-The Cybercriminal&#39;s Hide and Seek</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week, we re going to explore what Fast Flux is, a sophisticated technique used by cybercriminals to evade detection and maintain their malicious activities. We'll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear. So without further ado, grab your coffee, or keep your eyes on the road if you are driving, sit back, and let's get started!" HellCat Ransomware- https://there...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, we re going to explore what Fast Flux is, a sophisticated technique used by cybercriminals to evade detection and maintain their malicious activities. We&apos;ll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear. So without further ado, grab your coffee, or keep your eyes on the road if you are driving, sit back, and let&apos;s get started!&quot;</p><ul><li>HellCat Ransomware</li></ul><p>- https://therecord.media: Schneider Electric Hackers Accessed Internal Project Tracking Platform</p><p>- https://www.infosecurity-magazine.com: Hellcat Ransomware Humiliation</p><p>- <a href='https://attack.mitre.org/techniques/T1568/001/'>https://attack.mitre.org</a>: Dynamic Resolution: Fast Flux DNS</p><p>- <a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-093a'>https://www.cisa.gov</a>: Fasst Flux, A National Security Threat</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, we re going to explore what Fast Flux is, a sophisticated technique used by cybercriminals to evade detection and maintain their malicious activities. We&apos;ll break it down for those new to cybersecurity, delve into some technical details, and use analogies to make it all clear. So without further ado, grab your coffee, or keep your eyes on the road if you are driving, sit back, and let&apos;s get started!&quot;</p><ul><li>HellCat Ransomware</li></ul><p>- https://therecord.media: Schneider Electric Hackers Accessed Internal Project Tracking Platform</p><p>- https://www.infosecurity-magazine.com: Hellcat Ransomware Humiliation</p><p>- <a href='https://attack.mitre.org/techniques/T1568/001/'>https://attack.mitre.org</a>: Dynamic Resolution: Fast Flux DNS</p><p>- <a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-093a'>https://www.cisa.gov</a>: Fasst Flux, A National Security Threat</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16930556-218-fast-flux-the-cybercriminal-s-hide-and-seek.mp3" length="19347845" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16930556</guid>
    <pubDate>Sat, 05 Apr 2025 17:00:00 +0400</pubDate>
    <itunes:duration>1609</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>217 - Phishing the Expert-The Unexpected Cybersecurity Breach - Part 2                   </itunes:title>
    <title>217 - Phishing the Expert-The Unexpected Cybersecurity Breach - Part 2                   </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week's episode is continuation of Troy Hunt's cautionary tale , the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We'll continue to break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end where we bust our myth of the week!  We will also look at this week's cyber security news which...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode is continuation of Troy Hunt&apos;s cautionary tale , the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We&apos;ll continue to break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end where we bust our myth of the week!<br/><br/>We will also look at this week&apos;s cyber security news which is</p><ul><li>Ubuntu Linux security bypasses</li></ul><p>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions'>https://blog.qualys.co</a>m: Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions</p><p>- <a href='https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/'>https://www.troyhunt.com</a>: A sneaky phish just grabbed my Mailchimp mailing list</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode is continuation of Troy Hunt&apos;s cautionary tale , the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We&apos;ll continue to break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end where we bust our myth of the week!<br/><br/>We will also look at this week&apos;s cyber security news which is</p><ul><li>Ubuntu Linux security bypasses</li></ul><p>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions'>https://blog.qualys.co</a>m: Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions</p><p>- <a href='https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/'>https://www.troyhunt.com</a>: A sneaky phish just grabbed my Mailchimp mailing list</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16905908-217-phishing-the-expert-the-unexpected-cybersecurity-breach-part-2.mp3" length="20588637" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16905908</guid>
    <pubDate>Sat, 29 Mar 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1712</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>216 - Phishing The Expert-The Unexpected Cybersecurity Breach - Part 1</itunes:title>
    <title>216 - Phishing The Expert-The Unexpected Cybersecurity Breach - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode we have a fascinating and cautionary tale about none other than Troy Hunt, the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We'll break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end for tips on how to stay vigilant against phishing attacks and our myth of the ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we have a fascinating and cautionary tale about none other than Troy Hunt, the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We&apos;ll break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end for tips on how to stay vigilant against phishing attacks and our myth of the week!<br/><br/>we will also look at the cyber security news. Here is what caught my attention this week.<br/><br/>- PSTools dll injection vulnerability</p><p>- <a href='https://www.foto-video-it.de/2025/allgemein/disclosure-sysinternals/'>https://www.foto-video-it.de</a>: Disclosure Sysinternals (You will need to translate to English if you are not a German speaker)</p><p>- <a href='https://learn.microsoft.com/en-us/sysinternals/downloads/pstools'>https://learn.microsoft.com</a>: PSTool</p><p>- <a href='https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/'>https://www.troyhunt.com</a>: A sneaky phish just grabbed my Mailchimp mailing list</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we have a fascinating and cautionary tale about none other than Troy Hunt, the creator of HaveIBeenPwned. Despite being a renowned security expert, Troy recently fell victim to a sophisticated phishing attack through Mailchimp. We&apos;ll break down what happened, how it happened, and what we can all learn from this incident. Stay tuned till the end for tips on how to stay vigilant against phishing attacks and our myth of the week!<br/><br/>we will also look at the cyber security news. Here is what caught my attention this week.<br/><br/>- PSTools dll injection vulnerability</p><p>- <a href='https://www.foto-video-it.de/2025/allgemein/disclosure-sysinternals/'>https://www.foto-video-it.de</a>: Disclosure Sysinternals (You will need to translate to English if you are not a German speaker)</p><p>- <a href='https://learn.microsoft.com/en-us/sysinternals/downloads/pstools'>https://learn.microsoft.com</a>: PSTool</p><p>- <a href='https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/'>https://www.troyhunt.com</a>: A sneaky phish just grabbed my Mailchimp mailing list</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16877380-216-phishing-the-expert-the-unexpected-cybersecurity-breach-part-1.mp3" length="23268499" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16877380</guid>
    <pubDate>Sat, 22 Mar 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1935</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>215 - Cyber Threat Emulation - Strategies for Staying Ahead Of Cyber Attacks</itunes:title>
    <title>215 - Cyber Threat Emulation - Strategies for Staying Ahead Of Cyber Attacks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode, we’ll look into a cybersecurity assessment method that mimics real-world attacks to test an organization's security defenses and response capabilities: Threat emulation. It is one of the strategies to keep you ahead of the game.  Threat emulation aims to identify and mitigate security gaps before attackers exploit them, providing a more comprehensive evaluation than traditional assessments.  Before we dive into the main to...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we’ll look into a cybersecurity assessment method that mimics real-world attacks to test an organization&apos;s security defenses and response capabilities: Threat emulation. It is one of the strategies to keep you ahead of the game.  Threat emulation aims to identify and mitigate security gaps before attackers exploit them, providing a more comprehensive evaluation than traditional assessments.<br/><br/>Before we dive into the main topic, lets glance what is happening on the security front:</p><ul><li>March Microsoft Patch Tuesday has landed!</li></ul><p>- <a href='https://msrc.microsoft.com/update-guide/releaseNote/2025-mar'>https://msrc.microsoft.com</a>: March 2025 Security Updates</p><p>- <a href='https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html'>https://detect-respond.blogspot.com</a>: Pyramid Of Pain</p><p>- <a href='https://www.atomicredteam.io/'>https://www.atomicredteam.io</a>: Atomic Read Team</p><p>- <a href='https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html'>https://www.ecb.europa.eu</a>/paym/cyber-resilience/tiber-eu/html/index.en.html</p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we’ll look into a cybersecurity assessment method that mimics real-world attacks to test an organization&apos;s security defenses and response capabilities: Threat emulation. It is one of the strategies to keep you ahead of the game.  Threat emulation aims to identify and mitigate security gaps before attackers exploit them, providing a more comprehensive evaluation than traditional assessments.<br/><br/>Before we dive into the main topic, lets glance what is happening on the security front:</p><ul><li>March Microsoft Patch Tuesday has landed!</li></ul><p>- <a href='https://msrc.microsoft.com/update-guide/releaseNote/2025-mar'>https://msrc.microsoft.com</a>: March 2025 Security Updates</p><p>- <a href='https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html'>https://detect-respond.blogspot.com</a>: Pyramid Of Pain</p><p>- <a href='https://www.atomicredteam.io/'>https://www.atomicredteam.io</a>: Atomic Read Team</p><p>- <a href='https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html'>https://www.ecb.europa.eu</a>/paym/cyber-resilience/tiber-eu/html/index.en.html</p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16837122-215-cyber-threat-emulation-strategies-for-staying-ahead-of-cyber-attacks.mp3" length="26729789" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16837122</guid>
    <pubDate>Sat, 15 Mar 2025 23:00:00 +0400</pubDate>
    <itunes:duration>2224</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>214 - What are polyglot files and how bad are they?</itunes:title>
    <title>214 - What are polyglot files and how bad are they?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode, we’ll be exploring a particularly intriguing file types: polyglot files. These digital shapeshifters have become a powerful tool in the arsenal of cyber attackers, capable of bypassing security measures, confusing systems, and delivering malicious payloads in ways that are both creative and devastating.  Over the next  20 to 30 minutes or so, we’ll break down what polyglot files are, how they work, and why they’re so dange...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we’ll be exploring a particularly intriguing file types: polyglot files. These digital shapeshifters have become a powerful tool in the arsenal of cyber attackers, capable of bypassing security measures, confusing systems, and delivering malicious payloads in ways that are both creative and devastating.<br/><br/>Over the next  20 to 30 minutes or so, we’ll break down what polyglot files are, how they work, and why they’re so dangerous. We’ll also examine some real-world examples where polyglot files were used in cyberattacks. We will reference the MITRE ATT&amp;CK framework to understand how these techniques fit into the broader landscape of adversarial tactics. Finally, we’ll discuss mitigation strategies and close with a cybersecurity myth that needs busting<br/><br/>Before we dive into the main topic, lets glance what is happening on the security front:</p><ul><li>UEFI Secure Boot bypass vulnerability</li></ul><p>-<a href='https://en.wikipedia.org/wiki/Polyglot_(computing)'> https://en.wikipedia.org</a>: Polyglot</p><p>- <a href='https://attack.mitre.org/techniques/T1036/'>https://attack.mitre.org</a>: Masquerading</p><p>- <a href='https://arxiv.org/html/2407.01529v1'>https://arxiv.org</a>: Where the Polyglots Are: How Polyglot Files Enable Cyber Attack Chains and Methods for Detection &amp; Disarmament</p><p>- <a href='https://medium.com/swlh/polyglot-files-a-hackers-best-friend-850bf812dd8a'>https://medium.com</a>: Polyglot Files A Hackers Best Friend</p><p>- <a href='https://www.bleepingcomputer.com/news/security/new-polyglot-malware-hits-aviation-satellite-communication-firms/'>https://www.bleepingcomputer.com</a>: New polyglot malware hits aviation, satellite communication firms</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we’ll be exploring a particularly intriguing file types: polyglot files. These digital shapeshifters have become a powerful tool in the arsenal of cyber attackers, capable of bypassing security measures, confusing systems, and delivering malicious payloads in ways that are both creative and devastating.<br/><br/>Over the next  20 to 30 minutes or so, we’ll break down what polyglot files are, how they work, and why they’re so dangerous. We’ll also examine some real-world examples where polyglot files were used in cyberattacks. We will reference the MITRE ATT&amp;CK framework to understand how these techniques fit into the broader landscape of adversarial tactics. Finally, we’ll discuss mitigation strategies and close with a cybersecurity myth that needs busting<br/><br/>Before we dive into the main topic, lets glance what is happening on the security front:</p><ul><li>UEFI Secure Boot bypass vulnerability</li></ul><p>-<a href='https://en.wikipedia.org/wiki/Polyglot_(computing)'> https://en.wikipedia.org</a>: Polyglot</p><p>- <a href='https://attack.mitre.org/techniques/T1036/'>https://attack.mitre.org</a>: Masquerading</p><p>- <a href='https://arxiv.org/html/2407.01529v1'>https://arxiv.org</a>: Where the Polyglots Are: How Polyglot Files Enable Cyber Attack Chains and Methods for Detection &amp; Disarmament</p><p>- <a href='https://medium.com/swlh/polyglot-files-a-hackers-best-friend-850bf812dd8a'>https://medium.com</a>: Polyglot Files A Hackers Best Friend</p><p>- <a href='https://www.bleepingcomputer.com/news/security/new-polyglot-malware-hits-aviation-satellite-communication-firms/'>https://www.bleepingcomputer.com</a>: New polyglot malware hits aviation, satellite communication firms</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16740147-214-what-are-polyglot-files-and-how-bad-are-they.mp3" length="23059013" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16740147</guid>
    <pubDate>Sat, 08 Mar 2025 22:00:00 +0400</pubDate>
    <itunes:duration>1918</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>213 - Stealing Data in Plain Sight -How Cybercriminals Exfiltrate Your Secrets and How to Stop Them</itunes:title>
    <title>213 - Stealing Data in Plain Sight -How Cybercriminals Exfiltrate Your Secrets and How to Stop Them</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, we're diving deep into Data Exfiltration; one of the most serious threats facing organizations today.  We'll break down exactly what data exfiltration is, where it fits in the MITRE ATT&amp;CK framework, the tools and techniques attackers use, and, most importantly, how organizations can defend themselves. We’ll also cover real-world examples, including publicly known cases that had major consequences.  So, whether you're a ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we&apos;re diving deep into Data Exfiltration; one of the most serious threats facing organizations today.<br/><br/>We&apos;ll break down exactly what data exfiltration is, where it fits in the MITRE ATT&amp;CK framework, the tools and techniques attackers use, and, most importantly, how organizations can defend themselves. We’ll also cover real-world examples, including publicly known cases that had major consequences.<br/><br/>So, whether you&apos;re a seasoned security professional or just starting out in the field, stick around as we unravel the methods attackers use and how to stop them.<br/><br/>First lets look at one of the trending security news this week, and that is:<br/><br/></p><ul><li>News: Caldera Vulnerability</li></ul><p>- <a href='https://github.com/mitre/caldera'>https://github.com/mitre/caldera</a>: Security Notice</p><p>- <a href='https://nvd.nist.gov/vuln/detail/CVE-2025-27364'>https://nvd.nist.gov</a>: CVE-2025-27364</p><p>- <a href='https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e'>https://medium.com</a>: MITRE Caldera Security Advisory — Remote Code Execution (CVE-2025–27364)</p><p>- <a href='https://www.mitre.org/ourimpact/intellectual-property/caldera'>https://www.mitre.org</a>: Caldera</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we&apos;re diving deep into Data Exfiltration; one of the most serious threats facing organizations today.<br/><br/>We&apos;ll break down exactly what data exfiltration is, where it fits in the MITRE ATT&amp;CK framework, the tools and techniques attackers use, and, most importantly, how organizations can defend themselves. We’ll also cover real-world examples, including publicly known cases that had major consequences.<br/><br/>So, whether you&apos;re a seasoned security professional or just starting out in the field, stick around as we unravel the methods attackers use and how to stop them.<br/><br/>First lets look at one of the trending security news this week, and that is:<br/><br/></p><ul><li>News: Caldera Vulnerability</li></ul><p>- <a href='https://github.com/mitre/caldera'>https://github.com/mitre/caldera</a>: Security Notice</p><p>- <a href='https://nvd.nist.gov/vuln/detail/CVE-2025-27364'>https://nvd.nist.gov</a>: CVE-2025-27364</p><p>- <a href='https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e'>https://medium.com</a>: MITRE Caldera Security Advisory — Remote Code Execution (CVE-2025–27364)</p><p>- <a href='https://www.mitre.org/ourimpact/intellectual-property/caldera'>https://www.mitre.org</a>: Caldera</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16740148-213-stealing-data-in-plain-sight-how-cybercriminals-exfiltrate-your-secrets-and-how-to-stop-them.mp3" length="36684996" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16740148</guid>
    <pubDate>Sat, 01 Mar 2025 22:00:00 +0400</pubDate>
    <itunes:duration>3053</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>212  - Behind the login Screen - Understanding OS Authentication - Part 2</itunes:title>
    <title>212  - Behind the login Screen - Understanding OS Authentication - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! We are continuing with part 2 of "Behind the Login Screen - Understanding OS Authentication." If you missed our first episode, I highly recommend giving it a listen before diving into today's content. In part one, we started to explore the fascinating world of operating system authentications, focusing on Windows, Linux/Unix, and Mac OS. We discussed how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We are continuing with part 2 of &quot;Behind the Login Screen - Understanding OS Authentication.&quot; If you missed our first episode, I highly recommend giving it a listen before diving into today&apos;s content. In part one, we started to explore the fascinating world of operating system authentications, focusing on Windows, Linux/Unix, and Mac OS. We discussed how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks. <br/><br/>In today&apos;s episode, we&apos;ll build on that foundation and delve even deeper into the topic of OS authentication mechanisms. So again, if you haven&apos;t already, make sure to catch up on part one to get the full picture.<br/><br/>Now, let&apos;s get started with part two of our journey into the world of OS authentication! lets look at one of the trending security news this week, and that is:<br/><br/>- Newly discovered OpenSSH vulnerabilities.</p><p>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466?utm_source=chatgpt.com'>https://blog.qualys.com</a>: Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 &amp; CVE-2025-26466</p><p>- <a href='https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview'>https://learn.microsoft.com</a>: Kerberos Authentication Overview</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We are continuing with part 2 of &quot;Behind the Login Screen - Understanding OS Authentication.&quot; If you missed our first episode, I highly recommend giving it a listen before diving into today&apos;s content. In part one, we started to explore the fascinating world of operating system authentications, focusing on Windows, Linux/Unix, and Mac OS. We discussed how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks. <br/><br/>In today&apos;s episode, we&apos;ll build on that foundation and delve even deeper into the topic of OS authentication mechanisms. So again, if you haven&apos;t already, make sure to catch up on part one to get the full picture.<br/><br/>Now, let&apos;s get started with part two of our journey into the world of OS authentication! lets look at one of the trending security news this week, and that is:<br/><br/>- Newly discovered OpenSSH vulnerabilities.</p><p>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466?utm_source=chatgpt.com'>https://blog.qualys.com</a>: Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 &amp; CVE-2025-26466</p><p>- <a href='https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview'>https://learn.microsoft.com</a>: Kerberos Authentication Overview</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16703151-212-behind-the-login-screen-understanding-os-authentication-part-2.mp3" length="35389375" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16703151</guid>
    <pubDate>Sat, 22 Feb 2025 23:00:00 +0400</pubDate>
    <itunes:duration>2945</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>211 - Behind the login Screen: Understanding OS Authentication - Part 2</itunes:title>
    <title>211 - Behind the login Screen: Understanding OS Authentication - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, we're going to explore the fascinating topic of operating systems authentications. We all use it but how many of us wondered how the behind the curtains machinery work. We'll be focusing on Windows, Linux/Unix, and Mac OS. We'll discuss how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks and their countermeasures, the benefits of password-less authentication using hardware keys, pas...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we&apos;re going to explore the fascinating topic of operating systems authentications. We all use it but how many of us wondered how the behind the curtains machinery work. We&apos;ll be focusing on Windows, Linux/Unix, and Mac OS. We&apos;ll discuss how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks and their countermeasures, the benefits of password-less authentication using hardware keys, password cracking, the shadow file in Unix/Linux, and the mechanics of how each OS protects passwords and how attackers try to circumvent these protections. </p><ul><li>Scareware blocker, now available in Microsoft Edge</li></ul><p>- <a href='https://blogs.windows.com/msedgedev/2025/01/27/stand-up-to-scareware-with-scareware-blocker/'>https://blogs.windows.com</a>: Stand Up To Scareware With Scareware Blocker</p><p>- <a href='https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview'>https://learn.microsoft.com</a>: Kerberos Authentication Overview</p><p>- <a href='https://www.microsoft.com/en-us/edge/features/scareware-blocker?form=MA13FJ'>https://www.microsoft.com</a>: Scareware Blocker</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we&apos;re going to explore the fascinating topic of operating systems authentications. We all use it but how many of us wondered how the behind the curtains machinery work. We&apos;ll be focusing on Windows, Linux/Unix, and Mac OS. We&apos;ll discuss how hashes are used in authentication, the concept of salt in passwords, rainbow table attacks and their countermeasures, the benefits of password-less authentication using hardware keys, password cracking, the shadow file in Unix/Linux, and the mechanics of how each OS protects passwords and how attackers try to circumvent these protections. </p><ul><li>Scareware blocker, now available in Microsoft Edge</li></ul><p>- <a href='https://blogs.windows.com/msedgedev/2025/01/27/stand-up-to-scareware-with-scareware-blocker/'>https://blogs.windows.com</a>: Stand Up To Scareware With Scareware Blocker</p><p>- <a href='https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview'>https://learn.microsoft.com</a>: Kerberos Authentication Overview</p><p>- <a href='https://www.microsoft.com/en-us/edge/features/scareware-blocker?form=MA13FJ'>https://www.microsoft.com</a>: Scareware Blocker</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16667560-211-behind-the-login-screen-understanding-os-authentication-part-2.mp3" length="25506622" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16667560</guid>
    <pubDate>Sat, 15 Feb 2025 23:00:00 +0400</pubDate>
    <itunes:duration>2122</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>210 - Adversarial Misuse of Generative AI</itunes:title>
    <title>210 - Adversarial Misuse of Generative AI</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! As AI-generated content becomes more advanced, the risk of adversarial misuse—where bad actors manipulate AI for malicious purposes—has skyrocketed. But what does this mean in practical terms? What risks do we face, and how one of the big players is addressing them? Stick around as we break Google’s Adversarial Misuse of Generative AI report, explain the key jargon, and bust a cybersecurity myth at the end of the show.  Before we get into the m...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As AI-generated content becomes more advanced, the risk of adversarial misuse—where bad actors manipulate AI for malicious purposes—has skyrocketed. But what does this mean in practical terms? What risks do we face, and how one of the big players is addressing them? Stick around as we break Google’s Adversarial Misuse of Generative AI report, explain the key jargon, and bust a cybersecurity myth at the end of the show.<br/><br/>Before we get into the main topic, lets have a look at one important news update, and that is:</p><ul><li>Microsoft has expanded its Windows 11 administrator protection tests</li></ul><p>- <a href='https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai'>https://cloud.google.com</a>: Adversarial Misuse of Generative AI</p><p>- <a href='https://deepmind.google/discover/blog/mapping-the-misuse-of-generative-ai/'>https://deepmind.google</a>: Mapping the misuse of generative AI</p><p>- <a href='https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/'>https://learn.microsoft.com</a>: User Account Control overview</p><p>- <a href='https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/how-it-works'>https://learn.microsoft.com</a>: How User Account Control works</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As AI-generated content becomes more advanced, the risk of adversarial misuse—where bad actors manipulate AI for malicious purposes—has skyrocketed. But what does this mean in practical terms? What risks do we face, and how one of the big players is addressing them? Stick around as we break Google’s Adversarial Misuse of Generative AI report, explain the key jargon, and bust a cybersecurity myth at the end of the show.<br/><br/>Before we get into the main topic, lets have a look at one important news update, and that is:</p><ul><li>Microsoft has expanded its Windows 11 administrator protection tests</li></ul><p>- <a href='https://cloud.google.com/blog/topics/threat-intelligence/adversarial-misuse-generative-ai'>https://cloud.google.com</a>: Adversarial Misuse of Generative AI</p><p>- <a href='https://deepmind.google/discover/blog/mapping-the-misuse-of-generative-ai/'>https://deepmind.google</a>: Mapping the misuse of generative AI</p><p>- <a href='https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/'>https://learn.microsoft.com</a>: User Account Control overview</p><p>- <a href='https://learn.microsoft.com/en-us/windows/security/application-security/application-control/user-account-control/how-it-works'>https://learn.microsoft.com</a>: How User Account Control works</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16609314-210-adversarial-misuse-of-generative-ai.mp3" length="36302448" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16609314</guid>
    <pubDate>Sat, 08 Feb 2025 23:00:00 +0400</pubDate>
    <itunes:duration>3021</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>209 - DeepSeek</itunes:title>
    <title>209 - DeepSeek</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we’ve got something really exciting for you. If you’ve been following the world of artificial intelligence lately, you’ve probably heard a lot about a new player in town: DeepSeek.  Now, let me tell you, DeepSeek is shaking things up. They’re doing something completely different that’s not only disrupting the AI space but could also be a game-changer in how we approach cost, performance, and security in the future of AI technology. So, g...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’ve got something really exciting for you. If you’ve been following the world of artificial intelligence lately, you’ve probably heard a lot about a new player in town: DeepSeek.<br/><br/>Now, let me tell you, DeepSeek is shaking things up. They’re doing something completely different that’s not only disrupting the AI space but could also be a game-changer in how we approach cost, performance, and security in the future of AI technology. So, grab a seat on a solid ground and buckle up—this week, we’re diving into how **DeepSeek** is leveling the playing field for AI vendors everywhere, cutting costs, and leveraging some really smart techniques that are turning heads in the industry.<br/><br/>And, of course, at the end of today’s episode, we’ll be busting a big cybersecurity myth that might surprise you. But first, let’s talk all things DeepSeek.<br/><br/>Before we dive into the main, we will also bring you update todate on the news front:<br/><br/>- Deepseek date breach. Yes they were hit already!</p><p>- <a href='https://www.technologyreview.com/2025/01/31/1110740/how-deepseek-ripped-up-the-ai-playb ook-and-why-everyones-going-to-follow-it/'>https://www.technologyreview.com</a>: How DeepSeek<br/>ripped up the AI playbook—and why everyone’s going to follow its lead</p><p>- <a href='https://www.digitaltrends.com/computing/microsoft-lets-you-use-chatgpts-priciest-ai-model-for-free/'>https://www.digitaltrends.com</a>: Microsoft is letting anyone use ChatGPT’s $200 reasoning model for free</p><p>- <a href='https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak'>https://www.wiz.io</a>: Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’ve got something really exciting for you. If you’ve been following the world of artificial intelligence lately, you’ve probably heard a lot about a new player in town: DeepSeek.<br/><br/>Now, let me tell you, DeepSeek is shaking things up. They’re doing something completely different that’s not only disrupting the AI space but could also be a game-changer in how we approach cost, performance, and security in the future of AI technology. So, grab a seat on a solid ground and buckle up—this week, we’re diving into how **DeepSeek** is leveling the playing field for AI vendors everywhere, cutting costs, and leveraging some really smart techniques that are turning heads in the industry.<br/><br/>And, of course, at the end of today’s episode, we’ll be busting a big cybersecurity myth that might surprise you. But first, let’s talk all things DeepSeek.<br/><br/>Before we dive into the main, we will also bring you update todate on the news front:<br/><br/>- Deepseek date breach. Yes they were hit already!</p><p>- <a href='https://www.technologyreview.com/2025/01/31/1110740/how-deepseek-ripped-up-the-ai-playb ook-and-why-everyones-going-to-follow-it/'>https://www.technologyreview.com</a>: How DeepSeek<br/>ripped up the AI playbook—and why everyone’s going to follow its lead</p><p>- <a href='https://www.digitaltrends.com/computing/microsoft-lets-you-use-chatgpts-priciest-ai-model-for-free/'>https://www.digitaltrends.com</a>: Microsoft is letting anyone use ChatGPT’s $200 reasoning model for free</p><p>- <a href='https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak'>https://www.wiz.io</a>: Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16580064-209-deepseek.mp3" length="20820818" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16580064</guid>
    <pubDate>Sat, 01 Feb 2025 23:00:00 +0400</pubDate>
    <itunes:duration>1731</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>208 - Lets Encrypt on shortening certification lifetime to just 6 days!</itunes:title>
    <title>208 - Lets Encrypt on shortening certification lifetime to just 6 days!</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will detail the significant announcement from Let’s Encrypt – the trusted nonprofit Certificate Authority that has been at the forefront of making the web more secure.  Let’s Encrypt has revealed its plans to drastically reduce the lifetime of its TLS certificates from 90 days to just 6 days. This decision, outlined in their 2024 annual report, is aimed at strengthening the security of online communications by minimizing the ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will detail the significant announcement from Let’s Encrypt – the trusted nonprofit Certificate Authority that has been at the forefront of making the web more secure.<br/><br/>Let’s Encrypt has revealed its plans to drastically reduce the lifetime of its TLS certificates from 90 days to just 6 days. This decision, outlined in their 2024 annual report, is aimed at strengthening the security of online communications by minimizing the risks associated with compromised keys. But what does this mean for website owners, IT administrators, and the broader cybersecurity landscape? That’s what we’ll explore in detail today.<br/><br/>- <a href='https://community.letsencrypt.org/t/2024-isrg-annual-report/230159'>https://community.letsencrypt.org</a>: 2024 ISRG Annual Report<br/>- <a href='https://www.malwarebytes.com/blog/news/2025/01/7-zip-bug-could-allow-a-bypass-of-a-windows-security-feature-update-now'>https://www.malwarebytes.com</a>: 7-zip bug could allow a bypass of a windows security feature update now<br/>- <a href='https://digital.nhs.uk/cyber-alerts/2025/cc-4610'>https://digital.nhs.uk</a>: Proof-of-Concept Exploit Released for CVE-2025-0411 in 7-Zip</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will detail the significant announcement from Let’s Encrypt – the trusted nonprofit Certificate Authority that has been at the forefront of making the web more secure.<br/><br/>Let’s Encrypt has revealed its plans to drastically reduce the lifetime of its TLS certificates from 90 days to just 6 days. This decision, outlined in their 2024 annual report, is aimed at strengthening the security of online communications by minimizing the risks associated with compromised keys. But what does this mean for website owners, IT administrators, and the broader cybersecurity landscape? That’s what we’ll explore in detail today.<br/><br/>- <a href='https://community.letsencrypt.org/t/2024-isrg-annual-report/230159'>https://community.letsencrypt.org</a>: 2024 ISRG Annual Report<br/>- <a href='https://www.malwarebytes.com/blog/news/2025/01/7-zip-bug-could-allow-a-bypass-of-a-windows-security-feature-update-now'>https://www.malwarebytes.com</a>: 7-zip bug could allow a bypass of a windows security feature update now<br/>- <a href='https://digital.nhs.uk/cyber-alerts/2025/cc-4610'>https://digital.nhs.uk</a>: Proof-of-Concept Exploit Released for CVE-2025-0411 in 7-Zip</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16533730-208-lets-encrypt-on-shortening-certification-lifetime-to-just-6-days.mp3" length="23541169" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16533730</guid>
    <pubDate>Sat, 25 Jan 2025 23:00:00 +0400</pubDate>
    <itunes:duration>1958</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>207 - Microsoft Windows Actively Exploited Vulnerabilities</itunes:title>
    <title>207 - Microsoft Windows Actively Exploited Vulnerabilities</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This episode is one for you system admins out there! Today we’re discussing three actively exploited vulnerabilities you absolutely need to know about—CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335. These vulnerabilities have been making headlines, and understanding them could mean the difference between staying secure and falling victim to a breach. We’ll explore what these vulnerabilities are, how they’re being exploited, the adversaries ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This episode is one for you system admins out there! Today we’re discussing three actively exploited vulnerabilities you absolutely need to know about—CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335. These vulnerabilities have been making headlines, and understanding them could mean the difference between staying secure and falling victim to a breach.<br/>We’ll explore what these vulnerabilities are, how they’re being exploited, the adversaries leveraging them, and what organizations and individuals can do to protect themselves. And, as always, we’ll break down the jargon and bust a popular cybersecurity myth towards the end of the show. <br/><br/>Before we get into the main topic, lets recap the top security news this week</p><ul><li>Microsoft dropped the January Patch Tuesday and boy was it a whopper! We will dig into the details in more ways than one!</li></ul><p>- <a href='https://isc.sans.edu/diary/Microsoft+January+2025+Patch+Tuesday/31590/?is=6e1204429d0d03157fc14f8290a508ea86f81a3375f2aa901f8f602246fb4096'>https://isc.sans.edu</a>: Microsoft January 2025 Patch Tuesday<br/>- <a href='https://www.theregister.com/2025/01/15/patch_tuesday_january_2025/?is=6e1204429d0d03157fc14f8290a508ea86f81a3375f2aa901f8f602246fb4096'>https://www.theregister.com</a>: Microsoft fixes under-attack privilege-escalation holes in Hyper-V</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This episode is one for you system admins out there! Today we’re discussing three actively exploited vulnerabilities you absolutely need to know about—CVE-2025-21333, CVE-2025-21334, and CVE-2025-21335. These vulnerabilities have been making headlines, and understanding them could mean the difference between staying secure and falling victim to a breach.<br/>We’ll explore what these vulnerabilities are, how they’re being exploited, the adversaries leveraging them, and what organizations and individuals can do to protect themselves. And, as always, we’ll break down the jargon and bust a popular cybersecurity myth towards the end of the show. <br/><br/>Before we get into the main topic, lets recap the top security news this week</p><ul><li>Microsoft dropped the January Patch Tuesday and boy was it a whopper! We will dig into the details in more ways than one!</li></ul><p>- <a href='https://isc.sans.edu/diary/Microsoft+January+2025+Patch+Tuesday/31590/?is=6e1204429d0d03157fc14f8290a508ea86f81a3375f2aa901f8f602246fb4096'>https://isc.sans.edu</a>: Microsoft January 2025 Patch Tuesday<br/>- <a href='https://www.theregister.com/2025/01/15/patch_tuesday_january_2025/?is=6e1204429d0d03157fc14f8290a508ea86f81a3375f2aa901f8f602246fb4096'>https://www.theregister.com</a>: Microsoft fixes under-attack privilege-escalation holes in Hyper-V</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16460507-207-microsoft-windows-actively-exploited-vulnerabilities.mp3" length="27252934" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16460507</guid>
    <pubDate>Sat, 18 Jan 2025 22:00:00 +0400</pubDate>
    <itunes:duration>2267</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>206 - Cybersecurity Resolutions for 2025 - Best Practices for Individuals and Organizations</itunes:title>
    <title>206 - Cybersecurity Resolutions for 2025 - Best Practices for Individuals and Organizations</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is the podcast where we explore the ever-evolving world of cybersecurity and provide practical advice for staying ahead of threats. I’m your host, Yusuf, and today’s episode is all about starting the new year with a solid plan.  We’re diving into _Cybersecurity Resolutions for 2025: Best Practices for Individuals and Organizations._ As we step into a new year, it’s the perfect time to reflect on how we protect our digital lives—whether at ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the podcast where we explore the ever-evolving world of cybersecurity and provide practical advice for staying ahead of threats. I’m your host, Yusuf, and today’s episode is all about starting the new year with a solid plan.<br/><br/>We’re diving into _Cybersecurity Resolutions for 2025: Best Practices for Individuals and Organizations._ As we step into a new year, it’s the perfect time to reflect on how we protect our digital lives—whether at home or in the workplace.<br/><br/>From bolstering personal security habits to implementing stronger organizational policies, this episode will cover actionable resolutions you can adopt today. Along the way, we’ll explain key jargon, explore real-life examples, and, as always, bust a common cybersecurity myth at the end.<br/><br/>- <a href='https://nypost.com/2025/01/11/tech/apple-users-warned-of-hi-tech-mac-malware-that-steals-personal-data-goes-undetected-for-months-heres-how-to-stay-safe/?utm_source=chatgpt.com'>https://nypost.com</a>: Apple users warned of hi-tech Mac malware that steals personal data, goes undetected for months— here’s how to stay safe<br/>- <a href='https://www.youtube.com/watch?v=CyWCaxe7yi0'>https://www.youtube.com</a>: When Do We Get to Play On Easy Mode?</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the podcast where we explore the ever-evolving world of cybersecurity and provide practical advice for staying ahead of threats. I’m your host, Yusuf, and today’s episode is all about starting the new year with a solid plan.<br/><br/>We’re diving into _Cybersecurity Resolutions for 2025: Best Practices for Individuals and Organizations._ As we step into a new year, it’s the perfect time to reflect on how we protect our digital lives—whether at home or in the workplace.<br/><br/>From bolstering personal security habits to implementing stronger organizational policies, this episode will cover actionable resolutions you can adopt today. Along the way, we’ll explain key jargon, explore real-life examples, and, as always, bust a common cybersecurity myth at the end.<br/><br/>- <a href='https://nypost.com/2025/01/11/tech/apple-users-warned-of-hi-tech-mac-malware-that-steals-personal-data-goes-undetected-for-months-heres-how-to-stay-safe/?utm_source=chatgpt.com'>https://nypost.com</a>: Apple users warned of hi-tech Mac malware that steals personal data, goes undetected for months— here’s how to stay safe<br/>- <a href='https://www.youtube.com/watch?v=CyWCaxe7yi0'>https://www.youtube.com</a>: When Do We Get to Play On Easy Mode?</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16428057-206-cybersecurity-resolutions-for-2025-best-practices-for-individuals-and-organizations.mp3" length="23751547" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16428057</guid>
    <pubDate>Sat, 11 Jan 2025 23:00:00 +0400</pubDate>
    <itunes:duration>1976</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>205 - Vulnerability Scanners-The Heroes and Hidden Limits of Cybersecurity</itunes:title>
    <title>205 - Vulnerability Scanners-The Heroes and Hidden Limits of Cybersecurity</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we’re tackling a fundamental yet often misunderstood tool in every cybersecurity professional's arsenal—vulnerability scanners. What role do they play in protecting our organizations? Where do they shine, and where do they fall short?  As always, we’ll cut through the jargon and break things down for everyone—from seasoned professionals to those just beginning their journey in cybersecurity. And stick around until the end for this week’s...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’re tackling a fundamental yet often misunderstood tool in every cybersecurity professional&apos;s arsenal—vulnerability scanners. What role do they play in protecting our organizations? Where do they shine, and where do they fall short?<br/><br/>As always, we’ll cut through the jargon and break things down for everyone—from seasoned professionals to those just beginning their journey in cybersecurity. And stick around until the end for this week’s myth-busting segment, where we debunk a misconception about cyber security in general that many people still believe.<br/><br/>So grab your favorite beverage, get set, and let’s dive right in!</p><ul><li>Tenable Scanner Agent went offline globally</li></ul><p>All that coming up next, in this week episode.<br/><br/>- <a href='https://docs.tenable.com/release-notes/Content/nessus-agent/2025.htm?utm_source=chatgpt.com'>https://docs.tenable.com</a>: Tenable Nessus Agent 2025 Release Notes<br/>- <a href='https://www.splunk.com/en_us/blog/learn/vulnerability-scanning.html?utm_source=chatgpt.com'>https://www.splunk.com</a>: Vulnerability Scanners Primer</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’re tackling a fundamental yet often misunderstood tool in every cybersecurity professional&apos;s arsenal—vulnerability scanners. What role do they play in protecting our organizations? Where do they shine, and where do they fall short?<br/><br/>As always, we’ll cut through the jargon and break things down for everyone—from seasoned professionals to those just beginning their journey in cybersecurity. And stick around until the end for this week’s myth-busting segment, where we debunk a misconception about cyber security in general that many people still believe.<br/><br/>So grab your favorite beverage, get set, and let’s dive right in!</p><ul><li>Tenable Scanner Agent went offline globally</li></ul><p>All that coming up next, in this week episode.<br/><br/>- <a href='https://docs.tenable.com/release-notes/Content/nessus-agent/2025.htm?utm_source=chatgpt.com'>https://docs.tenable.com</a>: Tenable Nessus Agent 2025 Release Notes<br/>- <a href='https://www.splunk.com/en_us/blog/learn/vulnerability-scanning.html?utm_source=chatgpt.com'>https://www.splunk.com</a>: Vulnerability Scanners Primer</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16408849-205-vulnerability-scanners-the-heroes-and-hidden-limits-of-cybersecurity.mp3" length="20786457" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16408849</guid>
    <pubDate>Sat, 04 Jan 2025 23:00:00 +0400</pubDate>
    <itunes:duration>1728</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>204 - Recap of the best episodes of 2024</itunes:title>
    <title>204 - Recap of the best episodes of 2024</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This final episode of 2024, we recap the best the most listened to episodes of the year. And this year we have a great four back to back of the greatest of them all.   Lets start with the first eisode 191 - Is The Browser The New Operating System? released on the 28th of September. Next is episode 172 - SSL VPN versus IPsec VPN - Part 1 and part 2 released 18th of May and 25 of May respectively. And finally Episode 191 - APIs and Webhooks ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This final episode of 2024, we recap the best the most listened to episodes of the year. And this year we have a great four back to back of the greatest of them all. <br/><br/>Lets start with the first eisode 191 - Is The Browser The New Operating System? released on the 28th of September. Next is episode 172 - SSL VPN versus IPsec VPN - Part 1 and part 2 released 18th of May and 25 of May respectively.<br/>And finally Episode 191 - APIs and Webhooks released on the the 5th October.<br/><br/>Enjoy and see you in the new year!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This final episode of 2024, we recap the best the most listened to episodes of the year. And this year we have a great four back to back of the greatest of them all. <br/><br/>Lets start with the first eisode 191 - Is The Browser The New Operating System? released on the 28th of September. Next is episode 172 - SSL VPN versus IPsec VPN - Part 1 and part 2 released 18th of May and 25 of May respectively.<br/>And finally Episode 191 - APIs and Webhooks released on the the 5th October.<br/><br/>Enjoy and see you in the new year!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16350644-204-recap-of-the-best-episodes-of-2024.mp3" length="66025926" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16350644</guid>
    <pubDate>Sat, 28 Dec 2024 22:00:00 +0400</pubDate>
    <itunes:duration>5498</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>203 - Tips In Securing Your Organization - When the Security Team is Away</itunes:title>
    <title>203 - Tips In Securing Your Organization - When the Security Team is Away</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is a topical episode we’re diving into a high-stakes challenge every organization faces: It is holiday season, how do you manage threats when most of the security team is off duty.  Imagine a holiday season, a long weekend, or even an unexpected emergency. With key team members unavailable, how do we keep our defenses strong? This episode will provide actionable strategies, backed by real-world examples, to help you stay prepared.  Stick aro...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is a topical episode we’re diving into a high-stakes challenge every organization faces: It is holiday season, how do you manage threats when most of the security team is off duty.<br/><br/>Imagine a holiday season, a long weekend, or even an unexpected emergency. With key team members unavailable, how do we keep our defenses strong? This episode will provide actionable strategies, backed by real-world examples, to help you stay prepared.<br/><br/>Stick around until the end, where we’ll also bust a common cybersecurity myth.<br/><br/>- <a href='https://www.bleepingcomputer.com/news/security/cisa-urges-switch-to-signal-like-encrypted-messaging-apps-after-telecom-hacks/'>https://www.bleepingcomputer.com</a>: CISA Urges Switch To Signal Like-Encrypted Messaging Apps After Telecom Hacks<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is a topical episode we’re diving into a high-stakes challenge every organization faces: It is holiday season, how do you manage threats when most of the security team is off duty.<br/><br/>Imagine a holiday season, a long weekend, or even an unexpected emergency. With key team members unavailable, how do we keep our defenses strong? This episode will provide actionable strategies, backed by real-world examples, to help you stay prepared.<br/><br/>Stick around until the end, where we’ll also bust a common cybersecurity myth.<br/><br/>- <a href='https://www.bleepingcomputer.com/news/security/cisa-urges-switch-to-signal-like-encrypted-messaging-apps-after-telecom-hacks/'>https://www.bleepingcomputer.com</a>: CISA Urges Switch To Signal Like-Encrypted Messaging Apps After Telecom Hacks<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16340646-203-tips-in-securing-your-organization-when-the-security-team-is-away.mp3" length="15927942" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16340646</guid>
    <pubDate>Sat, 21 Dec 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1324</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>202 - Volt Typhoon</itunes:title>
    <title>202 - Volt Typhoon</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we’re diving into a concerning and highly consequential topic: the Volt Typhoon espionage campaign—an advanced persistent threat that has sent shockwaves through the cybersecurity and telecommunications industries.  Volt Typhoon, a state-backed APT group, has been making headlines for its stealthy and highly sophisticated attacks on telecom networks. In this episode, we’ll dissect the technical details of this malware ca...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we’re diving into a concerning and highly consequential topic: the Volt Typhoon espionage campaign—an advanced persistent threat that has sent shockwaves through the cybersecurity and telecommunications industries.<br/><br/>Volt Typhoon, a state-backed APT group, has been making headlines for its stealthy and highly sophisticated attacks on telecom networks. In this episode, we’ll dissect the technical details of this malware campaign, the vulnerabilities it exploited, and the regulatory loopholes that attackers took advantage of. We’ll also explore lessons the industry can learn to bolster defenses and, as always, bust a common cybersecurity myth along the way.<br/><br/>As always, we will break down all the jargon so that anyone can understand. Whatever you are doing, settle in or keep your eyes on the road, and let’s get started.<br/><br/>Before we get into the main topic, we will start with a recap of top trending security news this week...and that is:</p><ul><li>The Last Patch Tuesday</li></ul><p>- <a href='https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec'>https://msrc.microsoft.com</a>: Microsoft - December 2024 Security Updates<br/>- <a href='https://www.cisa.gov/news-events/alerts/2024/03/19/cisa-and-partners-release-joint-fact-sheet-leaders-prc-sponsored-volt-typhoon-cyber-activity'>https://www.cisa.gov</a>: CISA and Partners Release Joint Fact Sheet for Leaders on PRC-sponsored Volt Typhoon Cyber Activity<br/>- <a href='https://www.cisco.com/c/dam/global/en_au/pdfs/china-and-volt-typhoon-splunk-and-talos-presentation.pdf'>https://www.cisco.com</a>: China APT’s, Volt Typhoon, and what to do!<br/>- <a href='https://www.fcc.gov/calea#:~:text=The%20Communications%20Assistance%20for%20law,necessary%20surveillance%20capabilities%20to%20comply'>https://www.fcc.gov</a>:  Communications Assistance for Law Enforcement Act</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we’re diving into a concerning and highly consequential topic: the Volt Typhoon espionage campaign—an advanced persistent threat that has sent shockwaves through the cybersecurity and telecommunications industries.<br/><br/>Volt Typhoon, a state-backed APT group, has been making headlines for its stealthy and highly sophisticated attacks on telecom networks. In this episode, we’ll dissect the technical details of this malware campaign, the vulnerabilities it exploited, and the regulatory loopholes that attackers took advantage of. We’ll also explore lessons the industry can learn to bolster defenses and, as always, bust a common cybersecurity myth along the way.<br/><br/>As always, we will break down all the jargon so that anyone can understand. Whatever you are doing, settle in or keep your eyes on the road, and let’s get started.<br/><br/>Before we get into the main topic, we will start with a recap of top trending security news this week...and that is:</p><ul><li>The Last Patch Tuesday</li></ul><p>- <a href='https://msrc.microsoft.com/update-guide/releaseNote/2024-Dec'>https://msrc.microsoft.com</a>: Microsoft - December 2024 Security Updates<br/>- <a href='https://www.cisa.gov/news-events/alerts/2024/03/19/cisa-and-partners-release-joint-fact-sheet-leaders-prc-sponsored-volt-typhoon-cyber-activity'>https://www.cisa.gov</a>: CISA and Partners Release Joint Fact Sheet for Leaders on PRC-sponsored Volt Typhoon Cyber Activity<br/>- <a href='https://www.cisco.com/c/dam/global/en_au/pdfs/china-and-volt-typhoon-splunk-and-talos-presentation.pdf'>https://www.cisco.com</a>: China APT’s, Volt Typhoon, and what to do!<br/>- <a href='https://www.fcc.gov/calea#:~:text=The%20Communications%20Assistance%20for%20law,necessary%20surveillance%20capabilities%20to%20comply'>https://www.fcc.gov</a>:  Communications Assistance for Law Enforcement Act</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16300148-202-volt-typhoon.mp3" length="26146934" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16300148</guid>
    <pubDate>Sat, 14 Dec 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2175</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>201 - Digital Breadcrumbs - Tracing the Hidden Trails for Evidence</itunes:title>
    <title>201 - Digital Breadcrumbs - Tracing the Hidden Trails for Evidence</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week episode, we dive into one of the most fascinating aspects of digital investigations: Windows forensic artifacts.  It does not matter who you are: a security professional, an aspiring investigator, or simply curious about how experts uncover the digital breadcrumbs left on your computer, this episode will walk you through the essential pieces of evidence, known as _forensic artifacts_.  We’ll dip our hand into that Shellbags...wait wha...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week episode, we dive into one of the most fascinating aspects of digital investigations: Windows forensic artifacts.<br/><br/>It does not matter who you are: a security professional, an aspiring investigator, or simply curious about how experts uncover the digital breadcrumbs left on your computer, this episode will walk you through the essential pieces of evidence, known as _forensic artifacts_.<br/><br/>We’ll dip our hand into that Shellbags...wait what bags? I heard you say, Don&apos;t worry we will break down those complex terms, discuss real-world cases, and provide you with an in-depth understanding of artifacts like Shellbags, Prefetch files, and more. <br/><br/>Before we go any futher, we will review one top trending security news, this week... and that is:<br/><br/></p><ul><li> Microsoft NTLM Zero Won&apos;t get fixed until April 2025!</li></ul><p><br/>- <a href='https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html'>https://blog.0patch.com</a>: NTLM Hash Disclosure Vulnerability (0day) <br/>- <a href='https://www.splunk.com/en_us/blog/learn/cyber-forensics.html'>https://www.splunk.com</a>: Cyber Forensics<br/>- <a href='https://www.coursera.org/learn/digital-forensics-concepts?specialization=computerforensics'>https://www.coursera.org</a>: Digital Forensics Concepts</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week episode, we dive into one of the most fascinating aspects of digital investigations: Windows forensic artifacts.<br/><br/>It does not matter who you are: a security professional, an aspiring investigator, or simply curious about how experts uncover the digital breadcrumbs left on your computer, this episode will walk you through the essential pieces of evidence, known as _forensic artifacts_.<br/><br/>We’ll dip our hand into that Shellbags...wait what bags? I heard you say, Don&apos;t worry we will break down those complex terms, discuss real-world cases, and provide you with an in-depth understanding of artifacts like Shellbags, Prefetch files, and more. <br/><br/>Before we go any futher, we will review one top trending security news, this week... and that is:<br/><br/></p><ul><li> Microsoft NTLM Zero Won&apos;t get fixed until April 2025!</li></ul><p><br/>- <a href='https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html'>https://blog.0patch.com</a>: NTLM Hash Disclosure Vulnerability (0day) <br/>- <a href='https://www.splunk.com/en_us/blog/learn/cyber-forensics.html'>https://www.splunk.com</a>: Cyber Forensics<br/>- <a href='https://www.coursera.org/learn/digital-forensics-concepts?specialization=computerforensics'>https://www.coursera.org</a>: Digital Forensics Concepts</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16268543-201-digital-breadcrumbs-tracing-the-hidden-trails-for-evidence.mp3" length="21887659" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16268543</guid>
    <pubDate>Sat, 07 Dec 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1820</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>200 -  Incident Response Playbook- Turning Chaos into Control</itunes:title>
    <title>200 -  Incident Response Playbook- Turning Chaos into Control</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we’re tackling a topic that every organization, big or small, absolutely must take seriously: Incident Response Playbook  Imagine this: It’s 3 a.m., and your phone buzzes with an alert. A possible ransomware attack has been detected in your network. Do you panic, or do you execute a clear, structured plan? That’s the difference an Incident Response (IR) playbook can make—it turns chaos into control.  Today, we’ll break down what an IR pl...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’re tackling a topic that every organization, big or small, absolutely must take seriously: Incident Response Playbook<br/><br/>Imagine this: It’s 3 a.m., and your phone buzzes with an alert. A possible ransomware attack has been detected in your network. Do you panic, or do you execute a clear, structured plan? That’s the difference an Incident Response (IR) playbook can make—it turns chaos into control.<br/><br/>Today, we’ll break down what an IR playbook is, why it’s crucial, and how to implement one effectively. We’ll demystify technical jargon and provide actionable insights that you can apply right away. Stick around for the final section, where we’ll bust a common cybersecurity myth that everyone should know about.<br/><br/>Before we go ahead with the show, lets review the top trending security news this week:</p><ul><li> <a href='https://www.bleepingcomputer.com/news/microsoft/microsoft-says-having-a-tpm-is-non-negotiable-for-windows-11/'>https://www.bleepingcomputer.com</a>: Microsoft TPM is non-negotiable</li><li><a href='https://learn.microsoft.com/en-us/windows/compatibility/windows-11/'>https://learn.microsoft.com</a>: Windows 11 Hardware and Software Requirements<b><br/></b><br/></li></ul><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’re tackling a topic that every organization, big or small, absolutely must take seriously: Incident Response Playbook<br/><br/>Imagine this: It’s 3 a.m., and your phone buzzes with an alert. A possible ransomware attack has been detected in your network. Do you panic, or do you execute a clear, structured plan? That’s the difference an Incident Response (IR) playbook can make—it turns chaos into control.<br/><br/>Today, we’ll break down what an IR playbook is, why it’s crucial, and how to implement one effectively. We’ll demystify technical jargon and provide actionable insights that you can apply right away. Stick around for the final section, where we’ll bust a common cybersecurity myth that everyone should know about.<br/><br/>Before we go ahead with the show, lets review the top trending security news this week:</p><ul><li> <a href='https://www.bleepingcomputer.com/news/microsoft/microsoft-says-having-a-tpm-is-non-negotiable-for-windows-11/'>https://www.bleepingcomputer.com</a>: Microsoft TPM is non-negotiable</li><li><a href='https://learn.microsoft.com/en-us/windows/compatibility/windows-11/'>https://learn.microsoft.com</a>: Windows 11 Hardware and Software Requirements<b><br/></b><br/></li></ul><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16231607-200-incident-response-playbook-turning-chaos-into-control.mp3" length="24629566" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-16231607</guid>
    <pubDate>Sat, 30 Nov 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2049</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>199 - FBI-CISA-NSA&#39;s list of the most exploited vulnerabilities of 2023</itunes:title>
    <title>199 - FBI-CISA-NSA&#39;s list of the most exploited vulnerabilities of 2023</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week, we’re diving into a hot-off-the-presses report from the FBI, CISA, and NSA —a breakdown of the most exploited vulnerabilities of 2023. Think of this as the hackers' “most wanted” list: the weaknesses in software and systems that bad actors love to exploit because they’re effective and widely available.  Before we get into that, lets review the top security news this week. Pygmy Goat: The Sophisticated Linux Backdoor Targeting Network...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, we’re diving into a hot-off-the-presses report from the FBI, CISA, and NSA —a breakdown of the most exploited vulnerabilities of 2023. Think of this as the hackers&apos; “most wanted” list: the weaknesses in software and systems that bad actors love to exploit because they’re effective and widely available.<br/><br/>Before we get into that, lets review the top security news this week.</p><ul><li>Pygmy Goat: The Sophisticated Linux Backdoor Targeting Network Devices</li></ul><p>- <a href='https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/pygmy-goat/ncsc-mar-pygmy-goat.pdf'>https://www.ncsc.gov.uk</a>: Pygmy Goat Analysis<br/>- <a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a'>https://www.cisa.gov</a>: 2023 Top Routinely Exploited Vulnerabilities</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week, we’re diving into a hot-off-the-presses report from the FBI, CISA, and NSA —a breakdown of the most exploited vulnerabilities of 2023. Think of this as the hackers&apos; “most wanted” list: the weaknesses in software and systems that bad actors love to exploit because they’re effective and widely available.<br/><br/>Before we get into that, lets review the top security news this week.</p><ul><li>Pygmy Goat: The Sophisticated Linux Backdoor Targeting Network Devices</li></ul><p>- <a href='https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/pygmy-goat/ncsc-mar-pygmy-goat.pdf'>https://www.ncsc.gov.uk</a>: Pygmy Goat Analysis<br/>- <a href='https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a'>https://www.cisa.gov</a>: 2023 Top Routinely Exploited Vulnerabilities</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16163219-199-fbi-cisa-nsa-s-list-of-the-most-exploited-vulnerabilities-of-2023.mp3" length="25683732" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16163219</guid>
    <pubDate>Sat, 23 Nov 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2137</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>198 - Browser Engines Security</itunes:title>
    <title>198 - Browser Engines Security</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we’ll dive into what browser engines are, how they power your online experiences, and the security efforts shaping the modern web. We’ll also unpack extension security, with a spotlight on Google’s Manifest v3, and see how Safari and Firefox approach these challenges.  Whether you’re a casual browser user or a budding tech enthusiast, this episode is designed to give you insight into a part of your digital life that you might not even re...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’ll dive into what browser engines are, how they power your online experiences, and the security efforts shaping the modern web. We’ll also unpack extension security, with a spotlight on Google’s Manifest v3, and see how Safari and Firefox approach these challenges.<br/><br/>Whether you’re a casual browser user or a budding tech enthusiast, this episode is designed to give you insight into a part of your digital life that you might not even realize exists—the browser engine.<br/><br/>So If phrases like “browser engines” and “Manifest v3” sound daunting, don’t worry! I’ll break it all down so it’s as simple as possible. By the end, you’ll not only understand these terms but also appreciate why they’re crucial for a safer internet.<br/><br/>Before we  get started, lets review a top trending piece of news this week....and that is:</p><ul><li>iOS 18.1 Forcing Reboots</li></ul><p>- <a href='https://www.macrumors.com/2024/11/07/ios-18-forcing-reboots-law-enforcement/'>https://www.macrumors.com</a>: iOS 18.1 Forcing Reboots<br/>- <a href='https://en.wikipedia.org/wiki/Browser_engine'>https://en.wikipedia.org</a>: Browser_engine, what they are<br/>- <a href='https://en.wikipedia.org/wiki/Comparison_of_browser_engines'>https://en.wikipedia.org</a>: Comparison OF Browser Engines<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we’ll dive into what browser engines are, how they power your online experiences, and the security efforts shaping the modern web. We’ll also unpack extension security, with a spotlight on Google’s Manifest v3, and see how Safari and Firefox approach these challenges.<br/><br/>Whether you’re a casual browser user or a budding tech enthusiast, this episode is designed to give you insight into a part of your digital life that you might not even realize exists—the browser engine.<br/><br/>So If phrases like “browser engines” and “Manifest v3” sound daunting, don’t worry! I’ll break it all down so it’s as simple as possible. By the end, you’ll not only understand these terms but also appreciate why they’re crucial for a safer internet.<br/><br/>Before we  get started, lets review a top trending piece of news this week....and that is:</p><ul><li>iOS 18.1 Forcing Reboots</li></ul><p>- <a href='https://www.macrumors.com/2024/11/07/ios-18-forcing-reboots-law-enforcement/'>https://www.macrumors.com</a>: iOS 18.1 Forcing Reboots<br/>- <a href='https://en.wikipedia.org/wiki/Browser_engine'>https://en.wikipedia.org</a>: Browser_engine, what they are<br/>- <a href='https://en.wikipedia.org/wiki/Comparison_of_browser_engines'>https://en.wikipedia.org</a>: Comparison OF Browser Engines<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16133293-198-browser-engines-security.mp3" length="18012114" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16133293</guid>
    <pubDate>Sat, 16 Nov 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1497</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>197 - Advanced Malware evasion Techniques And Their Counter Measures</itunes:title>
    <title>197 - Advanced Malware evasion Techniques And Their Counter Measures</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is another week and another podcast shaw on YusufOnSecurity where we deep dive into the complex world of cybersecurity that concerns both  professionals and anyone interested in how attackers continue to evolve their methods.  This week we will be covering advanced malware evasion techniques—strategies used by malicious software to avoid detection—and, crucially, the countermeasures that can help protect against these threats.  Bef...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is another week and another podcast shaw on YusufOnSecurity where we deep dive into the complex world of cybersecurity that concerns both  professionals and anyone interested in how attackers continue to evolve their methods. <br/>This week we will be covering advanced malware evasion techniques—strategies used by malicious software to avoid detection—and, crucially, the countermeasures that can help protect against these threats.<br/><br/>Before we  get started, lets review a top trending piece of news this week....and that is:</p><ul><li> SANS&apos; Holiday Hack Challenge 2024 is Up</li></ul><p>-<a href='https://www.sans.org/mlp/holiday-hack-challenge-2024/'> https://www.sans.org</a>: SANS&apos; Holiday Hack Challenge 2024<br/>- <a href='https://redcanary.com/blog/threat-detection/defense-evasion-why-is-it-so-prominent-how-can-you-detect-it/'>https://redcanary.com</a>: Defense- Evasion Why Is It So Prominent How Can You Detect It?<br/>- https://attack.mitre.org/tactics/TA0005/<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is another week and another podcast shaw on YusufOnSecurity where we deep dive into the complex world of cybersecurity that concerns both  professionals and anyone interested in how attackers continue to evolve their methods. <br/>This week we will be covering advanced malware evasion techniques—strategies used by malicious software to avoid detection—and, crucially, the countermeasures that can help protect against these threats.<br/><br/>Before we  get started, lets review a top trending piece of news this week....and that is:</p><ul><li> SANS&apos; Holiday Hack Challenge 2024 is Up</li></ul><p>-<a href='https://www.sans.org/mlp/holiday-hack-challenge-2024/'> https://www.sans.org</a>: SANS&apos; Holiday Hack Challenge 2024<br/>- <a href='https://redcanary.com/blog/threat-detection/defense-evasion-why-is-it-so-prominent-how-can-you-detect-it/'>https://redcanary.com</a>: Defense- Evasion Why Is It So Prominent How Can You Detect It?<br/>- https://attack.mitre.org/tactics/TA0005/<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16090140-197-advanced-malware-evasion-techniques-and-their-counter-measures.mp3" length="19890185" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16090140</guid>
    <pubDate>Sat, 09 Nov 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1654</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>196 - What are Shared Fate Model and Trust Anchors?</itunes:title>
    <title>196 - What are Shared Fate Model and Trust Anchors?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode I will unpack the complexities of the cybersecurity world and help you stay informed and secure. Today, we’re going to dig into some intriguing concepts shaping the cybersecurity landscape: the Shared Fate Model and Trust Anchors. Some say these concepts are becoming so vital in modern IT security, their pros and cons, and how they compare with traditional security models that, quite frankly, aren’t cutting it anymore. Be...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode I will unpack the complexities of the cybersecurity world and help you stay informed and secure. Today, we’re going to dig into some intriguing concepts shaping the cybersecurity landscape: the Shared Fate Model and Trust Anchors. Some say these concepts are becoming so vital in modern IT security, their pros and cons, and how they compare with traditional security models that, quite frankly, aren’t cutting it anymore.</p><p>Before we  get started, lets review a top trending piece of news this week....and that is:</p><ul><li>Australia looks at setting a minimum for social media use</li></ul><p>- <a href='https://edition.cnn.com/2024/09/10/tech/australia-minimum-age-limit-social-media/index.html'>https://edition.cnn.com</a>: Australia Minimum Age Limit on Social Media<br/>- <a href='https://cloud.google.com/security/shared-fate'>https://cloud.google.com</a>: Shared Fate Model<br/>- <a href='https://csrc.nist.gov/glossary/term/trust_anchor#:~:text=An%20authoritative%20entity%20for%20which,issued%20by%20that%20trust%2Danchor.'>https://csrc.nist.gov</a>: Trust Anchor</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode I will unpack the complexities of the cybersecurity world and help you stay informed and secure. Today, we’re going to dig into some intriguing concepts shaping the cybersecurity landscape: the Shared Fate Model and Trust Anchors. Some say these concepts are becoming so vital in modern IT security, their pros and cons, and how they compare with traditional security models that, quite frankly, aren’t cutting it anymore.</p><p>Before we  get started, lets review a top trending piece of news this week....and that is:</p><ul><li>Australia looks at setting a minimum for social media use</li></ul><p>- <a href='https://edition.cnn.com/2024/09/10/tech/australia-minimum-age-limit-social-media/index.html'>https://edition.cnn.com</a>: Australia Minimum Age Limit on Social Media<br/>- <a href='https://cloud.google.com/security/shared-fate'>https://cloud.google.com</a>: Shared Fate Model<br/>- <a href='https://csrc.nist.gov/glossary/term/trust_anchor#:~:text=An%20authoritative%20entity%20for%20which,issued%20by%20that%20trust%2Danchor.'>https://csrc.nist.gov</a>: Trust Anchor</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16043518-196-what-are-shared-fate-model-and-trust-anchors.mp3" length="20754386" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16043518</guid>
    <pubDate>Sat, 02 Nov 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1726</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>195 - Top Common Password Attacks and How to Defend Against Them</itunes:title>
    <title>195 - Top Common Password Attacks and How to Defend Against Them</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Lets face it, the cyber crooks are always lurking aroud waiting for an opportunity to come in. They choose the path of least resistant and password is often their way in. Unfortunately password is still with us and for sometime to come too. In today episode, we’re digging deep into top common types of password attacks—and, most importantly, I’ll walk you through effective ways to stop them. Passwords are often the first line of defense, but the...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Lets face it, the cyber crooks are always lurking aroud waiting for an opportunity to come in. They choose the path of least resistant and password is often their way in. Unfortunately password is still with us and for sometime to come too.<br/>In today episode, we’re digging deep into top common types of password attacks—and, most importantly, I’ll walk you through effective ways to stop them. Passwords are often the first line of defense, but they’re also a favorite target for hackers. Understanding these attack methods can empower you to protect your data better, avoid common pitfalls, and even educate those around you. So, let’s get into it!</p><ul><li>A newly discovered ransomware serves a wake up all for Mac Users.</li></ul><p>-<a href='https://xkcd.com/936/'> https://xkcd.com</a>: How To Create A Strong Password<br/>- <a href='https://haveibeenpwned.com/'>https://haveibeenpwned.com</a>: Have I Been Pawned<br/>- <a href='https://pages.nist.gov/800-63-4/sp800-63b.html#appA'>https://pages.nist.gov</a>: Password<br/>- <a href='https://www.infosecurity-magazine.com/news/nist-scraps-passwords-mandatory/'>https://www.infosecurity-magazine.com</a>: NIST Scraps Passwords Complexity and Mandatory Changes in New Guidelines</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Lets face it, the cyber crooks are always lurking aroud waiting for an opportunity to come in. They choose the path of least resistant and password is often their way in. Unfortunately password is still with us and for sometime to come too.<br/>In today episode, we’re digging deep into top common types of password attacks—and, most importantly, I’ll walk you through effective ways to stop them. Passwords are often the first line of defense, but they’re also a favorite target for hackers. Understanding these attack methods can empower you to protect your data better, avoid common pitfalls, and even educate those around you. So, let’s get into it!</p><ul><li>A newly discovered ransomware serves a wake up all for Mac Users.</li></ul><p>-<a href='https://xkcd.com/936/'> https://xkcd.com</a>: How To Create A Strong Password<br/>- <a href='https://haveibeenpwned.com/'>https://haveibeenpwned.com</a>: Have I Been Pawned<br/>- <a href='https://pages.nist.gov/800-63-4/sp800-63b.html#appA'>https://pages.nist.gov</a>: Password<br/>- <a href='https://www.infosecurity-magazine.com/news/nist-scraps-passwords-mandatory/'>https://www.infosecurity-magazine.com</a>: NIST Scraps Passwords Complexity and Mandatory Changes in New Guidelines</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/16013027-195-top-common-password-attacks-and-how-to-defend-against-them.mp3" length="27585537" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-16013027</guid>
    <pubDate>Sat, 26 Oct 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2295</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>194 - Interview With Red Sift</itunes:title>
    <title>194 - Interview With Red Sift</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week's episode is an interview with Nadim Lahoud from Red Sift at GITEX the Global IT Expo that is held yearly in Dubai. It is the largest tech startup gathering in the world.   Redsift is a company that provides a cloud-based DMARC, DKIM and SPF configuration and management platform called OnDMARC. They also provide: -Continuous certificate discovery and monitoring as well as  -Brand Trust through AI-driven brand impersonation d...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode is an interview with Nadim Lahoud from Red Sift at GITEX the Global IT Expo that is held yearly in Dubai. It is the largest tech startup gathering in the world. <br/><br/>Redsift is a company that provides a cloud-based DMARC, DKIM and SPF configuration and management platform called OnDMARC. They also provide:<br/>-Continuous certificate discovery and monitoring as well as <br/>-Brand Trust through AI-driven brand impersonation discovery and monitoring.<br/><br/>Before we get into that we will recap the top trending security this week. That is:<br/><br/></p><ul><li>FIDO Alliance Drafts New Protocol to Simplify Passkey Transfers Across Different Platforms</li></ul><p><br/>- <a href='https://fidoalliance.org/specifications-credential-exchange-specifications/'>https://fidoalliance.org</a>: Specifications Credential Exchange Specifications<br/>- <a href='https://redsift.com/about-us'>https://redsift.com</a>: About Red Sift</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode is an interview with Nadim Lahoud from Red Sift at GITEX the Global IT Expo that is held yearly in Dubai. It is the largest tech startup gathering in the world. <br/><br/>Redsift is a company that provides a cloud-based DMARC, DKIM and SPF configuration and management platform called OnDMARC. They also provide:<br/>-Continuous certificate discovery and monitoring as well as <br/>-Brand Trust through AI-driven brand impersonation discovery and monitoring.<br/><br/>Before we get into that we will recap the top trending security this week. That is:<br/><br/></p><ul><li>FIDO Alliance Drafts New Protocol to Simplify Passkey Transfers Across Different Platforms</li></ul><p><br/>- <a href='https://fidoalliance.org/specifications-credential-exchange-specifications/'>https://fidoalliance.org</a>: Specifications Credential Exchange Specifications<br/>- <a href='https://redsift.com/about-us'>https://redsift.com</a>: About Red Sift</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15985144-194-interview-with-red-sift.mp3" length="24462685" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15985144</guid>
    <pubDate>Sat, 19 Oct 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2035</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>193 - Microsoft Windows Architecture</itunes:title>
    <title>193 - Microsoft Windows Architecture</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we’re going to peel back the layers of Microsoft Windows architecture. For many of us, Windows has been a part of our computing lives for decades, whether at work or at home. But how much do we really know about how it works under the hood? In this episode, we’ll take a closer look at what makes Windows tick, compare it with Unix/Linux systems, and explore how it has evolved over the years.  Before we get into the topic, lets review this ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we’re going to peel back the layers of Microsoft Windows architecture. For many of us, Windows has been a part of our computing lives for decades, whether at work or at home. But how much do we really know about how it works under the hood? In this episode, we’ll take a closer look at what makes Windows tick, compare it with Unix/Linux systems, and explore how it has evolved over the years.<br/><br/>Before we get into the topic, lets review this week&apos;s top trending security news:<br/><br/></p><ul><li>Criminals Are Testing Their Ransomware Campaigns in Africa</li></ul><p>- <a href='https://www.performanta.com/ebook-cyber-warfare'>https://www.performanta.com</a>: Africa A testing Ground<br/>- <a href='https://en.wikipedia.org/wiki/Architecture_of_Windows_NT'>https://en.wikipedia.org</a>: Architecture Of Windows NT<br/>- <a href='https://techcommunity.microsoft.com/t5/ask-the-performance-team/windows-architecture-the-basics/ba-p/372345'>https://techcommunity.microsoft.com</a>: Windows Architecture The Basics<br/>- <a href='https://learn.microsoft.com/en-us/training/modules/explore-windows-architecture/'>https://learn.microsoft.com</a>: Explore Windows Architecture/</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we’re going to peel back the layers of Microsoft Windows architecture. For many of us, Windows has been a part of our computing lives for decades, whether at work or at home. But how much do we really know about how it works under the hood? In this episode, we’ll take a closer look at what makes Windows tick, compare it with Unix/Linux systems, and explore how it has evolved over the years.<br/><br/>Before we get into the topic, lets review this week&apos;s top trending security news:<br/><br/></p><ul><li>Criminals Are Testing Their Ransomware Campaigns in Africa</li></ul><p>- <a href='https://www.performanta.com/ebook-cyber-warfare'>https://www.performanta.com</a>: Africa A testing Ground<br/>- <a href='https://en.wikipedia.org/wiki/Architecture_of_Windows_NT'>https://en.wikipedia.org</a>: Architecture Of Windows NT<br/>- <a href='https://techcommunity.microsoft.com/t5/ask-the-performance-team/windows-architecture-the-basics/ba-p/372345'>https://techcommunity.microsoft.com</a>: Windows Architecture The Basics<br/>- <a href='https://learn.microsoft.com/en-us/training/modules/explore-windows-architecture/'>https://learn.microsoft.com</a>: Explore Windows Architecture/</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15951921-193-microsoft-windows-architecture.mp3" length="28585448" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15951921</guid>
    <pubDate>Sat, 12 Oct 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2378</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>192 - APIs and Webhooks</itunes:title>
    <title>192 - APIs and Webhooks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, we’re diving into the world of APIs and Webhooks—two key technologies that power much of the automation and interaction between services online. Whether you’re a developer, security expert, or someone just curious about how data flows through the internet, this episode will give you valuable insights into how these tools work, their history, and, most importantly, how to keep them secure.  We’ll also look at real-world examp...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we’re diving into the world of APIs and Webhooks—two key technologies that power much of the automation and interaction between services online. Whether you’re a developer, security expert, or someone just curious about how data flows through the internet, this episode will give you valuable insights into how these tools work, their history, and, most importantly, how to keep them secure.<br/><br/>We’ll also look at real-world examples of API-based attacks on major brands and break down what went wrong. By the end of this episode, you’ll have a full understanding of both APIs and Webhooks, and you’ll be armed with the must-know security measures for each. So, stick around and by keep listening!<br/><br/>Having said that, lets have a look at the top trending news this week.</p><ul><li>Mitre launches AI Incident Sharing Initiative. Awsome move!</li></ul><p>- <a href='https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/'>https://owasp.org</a>: OWASP API Security Top 10<br/>- <a href='https://ai-incidents.mitre.org/'>https://ai-incidents.mitre.org</a>: Mitre ATLAS</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we’re diving into the world of APIs and Webhooks—two key technologies that power much of the automation and interaction between services online. Whether you’re a developer, security expert, or someone just curious about how data flows through the internet, this episode will give you valuable insights into how these tools work, their history, and, most importantly, how to keep them secure.<br/><br/>We’ll also look at real-world examples of API-based attacks on major brands and break down what went wrong. By the end of this episode, you’ll have a full understanding of both APIs and Webhooks, and you’ll be armed with the must-know security measures for each. So, stick around and by keep listening!<br/><br/>Having said that, lets have a look at the top trending news this week.</p><ul><li>Mitre launches AI Incident Sharing Initiative. Awsome move!</li></ul><p>- <a href='https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/'>https://owasp.org</a>: OWASP API Security Top 10<br/>- <a href='https://ai-incidents.mitre.org/'>https://ai-incidents.mitre.org</a>: Mitre ATLAS</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15890933-192-apis-and-webhooks.mp3" length="27530335" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15890933</guid>
    <pubDate>Sat, 05 Oct 2024 20:00:00 +0400</pubDate>
    <itunes:duration>2290</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>191 - Is The Browser The New Operating System?</itunes:title>
    <title>191 - Is The Browser The New Operating System?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we’re discussing an exciting trend in the world of technology—the browser is no longer just a window to the web. So we asked is it becoming the operating system itself?  From the early days of Mosaic and Netscape Navigator to today’s cloud-powered Chromebooks, the browser has evolved dramatically. In this episode, we’ll explore the security implication, the history of browsers, the famous browser wars, and how today’s browsers are blurrin...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we’re discussing an exciting trend in the world of technology—the browser is no longer just a window to the web. So we asked is it becoming the operating system itself?<br/><br/>From the early days of Mosaic and Netscape Navigator to today’s cloud-powered Chromebooks, the browser has evolved dramatically. In this episode, we’ll explore the security implication, the history of browsers, the famous browser wars, and how today’s browsers are blurring the lines between web interfaces and operating systems.<br/>Having said that, lets recap a top trending security news shall we?</p><ul><li>Exploiting CUPS: How Recent Vulnerabilities Could Compromise Linux Security</li></ul><p>- <a href='https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/'>https://www.evilsocket.net</a>: Attacking On UNIX Systems Via CUPS Part I<br/>-<a href='https://en.wikipedia.org/wiki/History_of_the_web_browser'>https://en.wikipedia.org</a>: History of The Web Browsers<br/>- <a href='https://en.wikipedia.org/wiki/Browser_wars'>https://en.wikipedia.org</a>: Browser Wars</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we’re discussing an exciting trend in the world of technology—the browser is no longer just a window to the web. So we asked is it becoming the operating system itself?<br/><br/>From the early days of Mosaic and Netscape Navigator to today’s cloud-powered Chromebooks, the browser has evolved dramatically. In this episode, we’ll explore the security implication, the history of browsers, the famous browser wars, and how today’s browsers are blurring the lines between web interfaces and operating systems.<br/>Having said that, lets recap a top trending security news shall we?</p><ul><li>Exploiting CUPS: How Recent Vulnerabilities Could Compromise Linux Security</li></ul><p>- <a href='https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/'>https://www.evilsocket.net</a>: Attacking On UNIX Systems Via CUPS Part I<br/>-<a href='https://en.wikipedia.org/wiki/History_of_the_web_browser'>https://en.wikipedia.org</a>: History of The Web Browsers<br/>- <a href='https://en.wikipedia.org/wiki/Browser_wars'>https://en.wikipedia.org</a>: Browser Wars</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15864258-191-is-the-browser-the-new-operating-system.mp3" length="19090218" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15864258</guid>
    <pubDate>Sat, 28 Sep 2024 22:00:00 +0400</pubDate>
    <itunes:duration>1587</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>190 - DevSecOps</itunes:title>
    <title>190 - DevSecOps</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode lets look at the world of DevSecOps—a vital practice in modern software development that has implication on security. We’ll trace the history of software development, discuss the evolution of methodologies, and examine the challenges that have led to the emergence of DevSecOps. So, whether you’re a seasoned developer who is curious about the cyber security world, or a veteran security practitioner, this is an episode you would n...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode lets look at the world of DevSecOps—a vital practice in modern software development that has implication on security. We’ll trace the history of software development, discuss the evolution of methodologies, and examine the challenges that have led to the emergence of DevSecOps. So, whether you’re a seasoned developer who is curious about the cyber security world, or a veteran security practitioner, this is an episode you would not want to miss..<br/><br/>As always, lets review what is trending in the news front first.</p><ul><li>Microsoft officially deprecates Windows Server Update Service aka WSUS.</li></ul><p>- <a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436'>https://techcommunity.microsoft.com</a>: Windows Server Update Services WSUS Deprecation<br/>- <a href='https://www.cisco.com/c/en/us/solutions/collateral/executive-perspectives/devsecops-addressing-security-challenges.html'>https://www.cisco.com</a>: Addressing Security Challenges in a Fast Evolving Landscape White Paper</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode lets look at the world of DevSecOps—a vital practice in modern software development that has implication on security. We’ll trace the history of software development, discuss the evolution of methodologies, and examine the challenges that have led to the emergence of DevSecOps. So, whether you’re a seasoned developer who is curious about the cyber security world, or a veteran security practitioner, this is an episode you would not want to miss..<br/><br/>As always, lets review what is trending in the news front first.</p><ul><li>Microsoft officially deprecates Windows Server Update Service aka WSUS.</li></ul><p>- <a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436'>https://techcommunity.microsoft.com</a>: Windows Server Update Services WSUS Deprecation<br/>- <a href='https://www.cisco.com/c/en/us/solutions/collateral/executive-perspectives/devsecops-addressing-security-challenges.html'>https://www.cisco.com</a>: Addressing Security Challenges in a Fast Evolving Landscape White Paper</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15808979-190-devsecops.mp3" length="18924958" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15808979</guid>
    <pubDate>Sat, 21 Sep 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1573</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>189 - The Risks of Rushing LLM Implementation and Sensitive Data Leakage on the Open Web</itunes:title>
    <title>189 - The Risks of Rushing LLM Implementation and Sensitive Data Leakage on the Open Web</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today’s topic is one that mixes the marvel of modern technology with some very real concerns. We’re talking about the rise of Large Language Models, or LLMs, how they’re rapidly being adopted across industries, and the potential for sensitive data leakage on the open web. It’s a thrilling time for AI technologies, but as with all new frontiers, there are risks if we're not careful. News: MSHTML platform spoofing vulnerability. And yes, It is a ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today’s topic is one that mixes the marvel of modern technology with some very real concerns. We’re talking about the rise of Large Language Models, or LLMs, how they’re rapidly being adopted across industries, and the potential for sensitive data leakage on the open web. It’s a thrilling time for AI technologies, but as with all new frontiers, there are risks if we&apos;re not careful.</p><ul><li>News: MSHTML platform spoofing vulnerability. And yes, It is a big one.</li></ul><p>- <a href='https://blogs.cisco.com/learning/securing-the-llm-stack'>https://blogs.cisco.com</a>: Securing The LLM Stack<br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43461'>https://msrc.microsoft.com</a>: CVE-2024-43461<br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38112'>https://msrc.microsoft.com</a>: CVE-2024-38112<br/>- <a href='https://www.trendmicro.com/en_us/research/24/g/CVE-2024-38112-void-banshee.html'>https://www.trendmicro.com</a>: CVE-2024-38112 Void-Banshee </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today’s topic is one that mixes the marvel of modern technology with some very real concerns. We’re talking about the rise of Large Language Models, or LLMs, how they’re rapidly being adopted across industries, and the potential for sensitive data leakage on the open web. It’s a thrilling time for AI technologies, but as with all new frontiers, there are risks if we&apos;re not careful.</p><ul><li>News: MSHTML platform spoofing vulnerability. And yes, It is a big one.</li></ul><p>- <a href='https://blogs.cisco.com/learning/securing-the-llm-stack'>https://blogs.cisco.com</a>: Securing The LLM Stack<br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43461'>https://msrc.microsoft.com</a>: CVE-2024-43461<br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38112'>https://msrc.microsoft.com</a>: CVE-2024-38112<br/>- <a href='https://www.trendmicro.com/en_us/research/24/g/CVE-2024-38112-void-banshee.html'>https://www.trendmicro.com</a>: CVE-2024-38112 Void-Banshee </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15767041-189-the-risks-of-rushing-llm-implementation-and-sensitive-data-leakage-on-the-open-web.mp3" length="23308660" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15767041</guid>
    <pubDate>Sat, 14 Sep 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1939</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>188 - Yubikey Vulnerability</itunes:title>
    <title>188 - Yubikey Vulnerability</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we’re diving into an important topic that concerns one of the most trusted hardware security tokens on the market—the YubiKey 5 series.  We’ll discuss a recently discovered vulnerability affecting YubiKeys and go over what it means for the broader world of authentication and cryptographic security. To help you fully understand the issue, I’ll also provide a quick primer on key concepts like digital signatures, elliptic curves, a...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we’re diving into an important topic that concerns one of the most trusted hardware security tokens on the market—the YubiKey 5 series.<br/><br/>We’ll discuss a recently discovered vulnerability affecting YubiKeys and go over what it means for the broader world of authentication and cryptographic security. To help you fully understand the issue, I’ll also provide a quick primer on key concepts like digital signatures, elliptic curves, and the cryptographic algorithm known as ECDSA. <br/>With that said, this episode is an update as well as a main topic  and all in all it will give you the tools you need to stay informed and protected.<br/><br/>- https://www.yubico.com: Yubico Advisories<br/>- <a href='https://ninjalab.io/eucleak/'>https://ninjalab.io</a>: The research <br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we’re diving into an important topic that concerns one of the most trusted hardware security tokens on the market—the YubiKey 5 series.<br/><br/>We’ll discuss a recently discovered vulnerability affecting YubiKeys and go over what it means for the broader world of authentication and cryptographic security. To help you fully understand the issue, I’ll also provide a quick primer on key concepts like digital signatures, elliptic curves, and the cryptographic algorithm known as ECDSA. <br/>With that said, this episode is an update as well as a main topic  and all in all it will give you the tools you need to stay informed and protected.<br/><br/>- https://www.yubico.com: Yubico Advisories<br/>- <a href='https://ninjalab.io/eucleak/'>https://ninjalab.io</a>: The research <br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15751471-188-yubikey-vulnerability.mp3" length="18823993" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15751471</guid>
    <pubDate>Sat, 07 Sep 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1565</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>187 - File Integrity Monitoring or EDR?</itunes:title>
    <title>187 - File Integrity Monitoring or EDR?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we will look into two essential cybersecurity solutions: File Integrity Monitoring or FIM and Endpoint Detection and Response, commonly known as EDR.  Both of these technologies are crucial for protecting systems, but they work in very different ways. We’ll be comparing and contrasting their capabilities, benefits, and use cases.  Before we get into the main topic, lets review a top trending piece of security news: SANS Institute release...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we will look into two essential cybersecurity solutions: File Integrity Monitoring or FIM and Endpoint Detection and Response, commonly known as EDR.<br/><br/>Both of these technologies are crucial for protecting systems, but they work in very different ways. We’ll be comparing and contrasting their capabilities, benefits, and use cases.<br/><br/>Before we get into the main topic, lets review a top trending piece of security news:</p><ul><li>SANS Institute released a Critical Infrastructure Strategy Guide</li></ul><p>- <a href='https://www.sans.org/mlp/ics-business-guide-2024/?utm_medium=Sponsored_Content&amp;utm_source=Hacker_News&amp;utm_content=DP_Article_ICS_Strat_Guide_Why_SANS_2&amp;utm_campaign=SANS%20Cyber%20Defense%20Initiative%202024'>https://www.sans.org</a>: SANS Institute released a Critical Infrastructure Strategy Guide<br/>- <a href='https://en.wikipedia.org/wiki/File_integrity_monitoring'>https://en.wikipedia.org</a>: File Integrity Monitoring<br/>- <a href='https://www.cisco.com/c/en/us/products/security/endpoint-security/what-is-endpoint-detection-response-edr-medr.html'>https://www.cisco.com</a>: What is an EDR?<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we will look into two essential cybersecurity solutions: File Integrity Monitoring or FIM and Endpoint Detection and Response, commonly known as EDR.<br/><br/>Both of these technologies are crucial for protecting systems, but they work in very different ways. We’ll be comparing and contrasting their capabilities, benefits, and use cases.<br/><br/>Before we get into the main topic, lets review a top trending piece of security news:</p><ul><li>SANS Institute released a Critical Infrastructure Strategy Guide</li></ul><p>- <a href='https://www.sans.org/mlp/ics-business-guide-2024/?utm_medium=Sponsored_Content&amp;utm_source=Hacker_News&amp;utm_content=DP_Article_ICS_Strat_Guide_Why_SANS_2&amp;utm_campaign=SANS%20Cyber%20Defense%20Initiative%202024'>https://www.sans.org</a>: SANS Institute released a Critical Infrastructure Strategy Guide<br/>- <a href='https://en.wikipedia.org/wiki/File_integrity_monitoring'>https://en.wikipedia.org</a>: File Integrity Monitoring<br/>- <a href='https://www.cisco.com/c/en/us/products/security/endpoint-security/what-is-endpoint-detection-response-edr-medr.html'>https://www.cisco.com</a>: What is an EDR?<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15700393-187-file-integrity-monitoring-or-edr.mp3" length="21333391" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15700393</guid>
    <pubDate>Sat, 31 Aug 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1774</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>186 - The New NIST Framework 2.0</itunes:title>
    <title>186 - The New NIST Framework 2.0</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today episode we’re diving into something that’s been making waves in the cybersecurity community—NIST Cybersecurity Framework 2.0.  The NIST Cybersecurity Framework has long been a cornerstone for building robust security practices, and with the release of version 2.0, there are some exciting new developments that are relevant given todays threat landscape.   As always, lets review what is trending in the news front. CCTV Zero-Day Expo...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today episode we’re diving into something that’s been making waves in the cybersecurity community—NIST Cybersecurity Framework 2.0.<br/><br/>The NIST Cybersecurity Framework has long been a cornerstone for building robust security practices, and with the release of version 2.0, there are some exciting new developments that are relevant given todays threat landscape. <br/><br/>As always, lets review what is trending in the news front.</p><ul><li>CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet</li></ul><p>- <a href='https://www.akamai.com/blog/security-research/2024-corona-mirai-botnet-infects-zero-day-sirt#iocs'>https://www.akamai.com</a>: Mirai Botnet Infects CCTV Used in Critical Infrastructures<br/>- <a href='https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework'>https://www.nist.gov</a>: IST Cybersecurity Framework 2.0.<br/>- <a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1299.pdf'>https://nvlpubs.nist.gov</a>: NIST Cybersecurity Framework 2.0.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today episode we’re diving into something that’s been making waves in the cybersecurity community—NIST Cybersecurity Framework 2.0.<br/><br/>The NIST Cybersecurity Framework has long been a cornerstone for building robust security practices, and with the release of version 2.0, there are some exciting new developments that are relevant given todays threat landscape. <br/><br/>As always, lets review what is trending in the news front.</p><ul><li>CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet</li></ul><p>- <a href='https://www.akamai.com/blog/security-research/2024-corona-mirai-botnet-infects-zero-day-sirt#iocs'>https://www.akamai.com</a>: Mirai Botnet Infects CCTV Used in Critical Infrastructures<br/>- <a href='https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework'>https://www.nist.gov</a>: IST Cybersecurity Framework 2.0.<br/>- <a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1299.pdf'>https://nvlpubs.nist.gov</a>: NIST Cybersecurity Framework 2.0.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15668456-186-the-new-nist-framework-2-0.mp3" length="25887723" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15668456</guid>
    <pubDate>Sat, 24 Aug 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2154</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>185 - Cybersecurity Capability Maturity Model</itunes:title>
    <title>185 - Cybersecurity Capability Maturity Model</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode we will dig in exploring a critical framework that’s reshaping how organizations approach cybersecurity—especially in the energy sector—known as the Cybersecurity Capability Maturity Model. This is also refer to C2M2.  We’ll unpack what C2M2 is, why it’s so important, and how it helps organizations assess and improve their cybersecurity practices. So, grab a coffee, sit back, and let’s dive in.  But wait, lets first revie...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we will dig in exploring a critical framework that’s reshaping how organizations approach cybersecurity—especially in the energy sector—known as the Cybersecurity Capability Maturity Model. This is also refer to C2M2.<br/><br/>We’ll unpack what C2M2 is, why it’s so important, and how it helps organizations assess and improve their cybersecurity practices. So, grab a coffee, sit back, and let’s dive in.<br/><br/>But wait, lets first review this week&apos;s trending news.</p><ul><li>A ransomware group launched an EDR process killer utility</li></ul><p>-<a href='https://www.theregister.com/2024/08/19/ransomhub_edrkilling_malware/'>https://www.theregister.com</a>: RnsomHub EDRKilling Malware/<br/>- <a href='https://c2m2.doe.gov/'>https://c2m2.doe.gov</a>: Cybersecurity Capability Maturity Model<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we will dig in exploring a critical framework that’s reshaping how organizations approach cybersecurity—especially in the energy sector—known as the Cybersecurity Capability Maturity Model. This is also refer to C2M2.<br/><br/>We’ll unpack what C2M2 is, why it’s so important, and how it helps organizations assess and improve their cybersecurity practices. So, grab a coffee, sit back, and let’s dive in.<br/><br/>But wait, lets first review this week&apos;s trending news.</p><ul><li>A ransomware group launched an EDR process killer utility</li></ul><p>-<a href='https://www.theregister.com/2024/08/19/ransomhub_edrkilling_malware/'>https://www.theregister.com</a>: RnsomHub EDRKilling Malware/<br/>- <a href='https://c2m2.doe.gov/'>https://c2m2.doe.gov</a>: Cybersecurity Capability Maturity Model<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15594773-185-cybersecurity-capability-maturity-model.mp3" length="23846123" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15594773</guid>
    <pubDate>Sat, 17 Aug 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1983</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>184 - Why Hackers Target Stolen Credentials</itunes:title>
    <title>184 - Why Hackers Target Stolen Credentials</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we’re unpacking a topic that’s crucial for anyone connected to the digital world: _Why Hackers Target Stolen Credentials_. From understanding the value behind those stolen usernames and passwords to exploring the dark web marketplaces where they’re traded, we’ll break it all down and look at what this means for your security.   Before we get into the topic, lets review this week's top trending security news:   A UK ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we’re unpacking a topic that’s crucial for anyone connected to the digital world: _Why Hackers Target Stolen Credentials_. From understanding the value behind those stolen usernames and passwords to exploring the dark web marketplaces where they’re traded, we’ll break it all down and look at what this means for your security. <br/><br/>Before we get into the topic, lets review this week&apos;s top trending security news:<br/><br/></p><ul><li>A UK IT provide faces hefty fines for ransomware breach</li></ul><p>- <a href='https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/08/provisional-decision-to-impose-6m-fine-on-software-provider-following-2022-ransomware-attack/'>https://ico.org.uk</a>: Provisional decision to impose £6m fine on software provider following 2022 ransomware attack that disrupted NHS and social care services<br/>- https://en.wikipedia.org: Credential Stuffing<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we’re unpacking a topic that’s crucial for anyone connected to the digital world: _Why Hackers Target Stolen Credentials_. From understanding the value behind those stolen usernames and passwords to exploring the dark web marketplaces where they’re traded, we’ll break it all down and look at what this means for your security. <br/><br/>Before we get into the topic, lets review this week&apos;s top trending security news:<br/><br/></p><ul><li>A UK IT provide faces hefty fines for ransomware breach</li></ul><p>- <a href='https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/08/provisional-decision-to-impose-6m-fine-on-software-provider-following-2022-ransomware-attack/'>https://ico.org.uk</a>: Provisional decision to impose £6m fine on software provider following 2022 ransomware attack that disrupted NHS and social care services<br/>- https://en.wikipedia.org: Credential Stuffing<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15594775-184-why-hackers-target-stolen-credentials.mp3" length="26958243" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15594775</guid>
    <pubDate>Sat, 10 Aug 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2243</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>183 - The Malware Information Sharing Platform</itunes:title>
    <title>183 - The Malware Information Sharing Platform</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we're diving into the Malware Information Sharing Platform, or MISP. We'll explore how MISP helps organizations share and leverage threat intelligence, enhancing their defense against cyber threats. Stay tuned as we unpack its features, benefits, challenges, and practical tips for implementation.   Before we get into the main topic, lets touch a top trending piece of news this week. And that is: Ransomware is on the...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we&apos;re diving into the Malware Information Sharing Platform, or MISP. We&apos;ll explore how MISP helps organizations share and leverage threat intelligence, enhancing their defense against cyber threats. Stay tuned as we unpack its features, benefits, challenges, and practical tips for implementation. <br/><br/>Before we get into the main topic, lets touch a top trending piece of news this week. And that is:</p><ul><li>Ransomware is on the rise, while technology becomes most targeted section</li></ul><p><br/>- <a href='https://blog.talosintelligence.com/ir-trends-ransomware-on-the-rise-q2-2024/'>https://blog.talosintelligence.com</a>: IR Trends: Ransomware on the rise, while technology becomes most targeted sector</p><p>- <a href='https://www.misp-project.org/'>https://www.misp-project.org</a>: MISP Project<br/>- <a href='https://www.misp-project.org/documentation/'>https://www.misp-project.org</a>: Documentation<br/>- <a href='https://github.com/MISP/MISP'>https://github.com</a>: MISP GitHub</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we&apos;re diving into the Malware Information Sharing Platform, or MISP. We&apos;ll explore how MISP helps organizations share and leverage threat intelligence, enhancing their defense against cyber threats. Stay tuned as we unpack its features, benefits, challenges, and practical tips for implementation. <br/><br/>Before we get into the main topic, lets touch a top trending piece of news this week. And that is:</p><ul><li>Ransomware is on the rise, while technology becomes most targeted section</li></ul><p><br/>- <a href='https://blog.talosintelligence.com/ir-trends-ransomware-on-the-rise-q2-2024/'>https://blog.talosintelligence.com</a>: IR Trends: Ransomware on the rise, while technology becomes most targeted sector</p><p>- <a href='https://www.misp-project.org/'>https://www.misp-project.org</a>: MISP Project<br/>- <a href='https://www.misp-project.org/documentation/'>https://www.misp-project.org</a>: Documentation<br/>- <a href='https://github.com/MISP/MISP'>https://github.com</a>: MISP GitHub</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15549788-183-the-malware-information-sharing-platform.mp3" length="21642748" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15549788</guid>
    <pubDate>Sat, 03 Aug 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1800</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>82 - Weighting The Risk Benefit Of Kernel Level Access By 3rd Party Apps</itunes:title>
    <title>82 - Weighting The Risk Benefit Of Kernel Level Access By 3rd Party Apps</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we will dig into the risk benefit analysis of allowing kernel level access to third party application. We will look into the inherent risks this brings into the operating system and the benefit thereof. We will also compare the approach the two major operatic system makers took i.e. Microsoft and Apple. We will include snippet of what Microsoft says post CrowStrike outage.  - https://www.microsoft.com: Windows Security B...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we will dig into the risk benefit analysis of allowing kernel level access to third party application. We will look into the inherent risks this brings into the operating system and the benefit thereof.<br/>We will also compare the approach the two major operatic system makers took i.e. Microsoft and Apple. We will include snippet of what Microsoft says post CrowStrike outage.<br/><br/>- <a href='https://www.microsoft.com/en-us/security/blog/2024/07/27/windows-security-best-practices-for-integrating-and-managing-security-tools/'>https://www.microsoft.com</a>: Windows Security Best Practices For Integrating And Managing Security Tools<br/>- <a href='https://support.apple.com/guide/deployment/system-and-kernel-extensions-in-macos-depa5fb8376f/web'>https://support.apple.com</a>: System And Kernel Extensions In MacOS<br/>- <a href='https://www.theverge.com/2024/7/26/24206719/microsoft-windows-changes-crowdstrike-kernel-driver'>https://www.theverge.com</a>: Microsoft Windows Changes Crowdstrike Kernel Driver <br/>- <a href='https://learn.microsoft.com/en-us/troubleshoot/windows-server/setup-upgrade-and-drivers/support-policy-third-party-kernel-level-attestation'>https://learn.microsoft.com</a>: Support Policy Third Party Kernel Level Attestation</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we will dig into the risk benefit analysis of allowing kernel level access to third party application. We will look into the inherent risks this brings into the operating system and the benefit thereof.<br/>We will also compare the approach the two major operatic system makers took i.e. Microsoft and Apple. We will include snippet of what Microsoft says post CrowStrike outage.<br/><br/>- <a href='https://www.microsoft.com/en-us/security/blog/2024/07/27/windows-security-best-practices-for-integrating-and-managing-security-tools/'>https://www.microsoft.com</a>: Windows Security Best Practices For Integrating And Managing Security Tools<br/>- <a href='https://support.apple.com/guide/deployment/system-and-kernel-extensions-in-macos-depa5fb8376f/web'>https://support.apple.com</a>: System And Kernel Extensions In MacOS<br/>- <a href='https://www.theverge.com/2024/7/26/24206719/microsoft-windows-changes-crowdstrike-kernel-driver'>https://www.theverge.com</a>: Microsoft Windows Changes Crowdstrike Kernel Driver <br/>- <a href='https://learn.microsoft.com/en-us/troubleshoot/windows-server/setup-upgrade-and-drivers/support-policy-third-party-kernel-level-attestation'>https://learn.microsoft.com</a>: Support Policy Third Party Kernel Level Attestation</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15523394-82-weighting-the-risk-benefit-of-kernel-level-access-by-3rd-party-apps.mp3" length="21450694" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15523394</guid>
    <pubDate>Sat, 27 Jul 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1784</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>181 - The Crowdstrike IT Outage</itunes:title>
    <title>181 - The Crowdstrike IT Outage</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week's episode needs very little introduction: The CrowdStrike IT Outage. We will delve into the unprecedented IT outage caused by a corrupt update from CrowdStrike, which led to widespread Blue Screen of Death (BSOD) errors on Windows systems across globe. Join us as we explore how this incident became the largest IT outage in history and what lessons can be learned from it.  - https://www.crowdstrike.com: Falcon Update For Windows Hosts ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode needs very little introduction: The CrowdStrike IT Outage.<br/>We will delve into the unprecedented IT outage caused by a corrupt update from CrowdStrike, which led to widespread Blue Screen of Death (BSOD) errors on Windows systems across globe. Join us as we explore how this incident became the largest IT outage in history and what lessons can be learned from it.<br/><br/>- <a href='https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/'>https://www.crowdstrike.com</a>: Falcon Update For Windows Hosts Technical Details<br/>- <a href='https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/'>https://www.crowdstrike.com</a>: Falcon Content Update Remediation And Guidance Hub</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode needs very little introduction: The CrowdStrike IT Outage.<br/>We will delve into the unprecedented IT outage caused by a corrupt update from CrowdStrike, which led to widespread Blue Screen of Death (BSOD) errors on Windows systems across globe. Join us as we explore how this incident became the largest IT outage in history and what lessons can be learned from it.<br/><br/>- <a href='https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/'>https://www.crowdstrike.com</a>: Falcon Update For Windows Hosts Technical Details<br/>- <a href='https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/'>https://www.crowdstrike.com</a>: Falcon Content Update Remediation And Guidance Hub</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15473141-181-the-crowdstrike-it-outage.mp3" length="34296901" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15473141</guid>
    <pubDate>Sat, 20 Jul 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2854</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>180 - Unmasking Data Breaches - Understanding the Surge and Examining Recent Major Incidents - Part 2</itunes:title>
    <title>180 - Unmasking Data Breaches - Understanding the Surge and Examining Recent Major Incidents - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! As I said in part of this two part series episode, It's easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today's episode, we will be diving into the reaso...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As I said in part of this two part series episode, It&apos;s easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today&apos;s episode, we will be diving into the reasons behind the surge in data breaches and exploits, and how these incidents are becoming more frequent and damaging. Join us as we explore the fundamental factors contributing to this trend and  examine some major breaches from the past few years. Please listen to part 1, beforehand. <br/><br/>Lets now turn to our top trending news this week and that is:</p><ul><li>There is a critical Exim Mail Server Vulnerability</li></ul><p>- <a href='https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/'>https://informationisbeautiful.net/visualizations</a>: Worlds Biggest Data Breaches Hacks<br/>- <a href='https://bugs.exim.org/show_bug.cgi?id=3099#c4'>https://bugs.exim.org</a>: Incorrect parsing of multiline rfc2231 header filename<br/>- <a href='https://nvd.nist.gov/vuln/detail/CVE-2024-39929'>https://nvd.nist.gov</a>: CVE-2024-39929</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As I said in part of this two part series episode, It&apos;s easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today&apos;s episode, we will be diving into the reasons behind the surge in data breaches and exploits, and how these incidents are becoming more frequent and damaging. Join us as we explore the fundamental factors contributing to this trend and  examine some major breaches from the past few years. Please listen to part 1, beforehand. <br/><br/>Lets now turn to our top trending news this week and that is:</p><ul><li>There is a critical Exim Mail Server Vulnerability</li></ul><p>- <a href='https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/'>https://informationisbeautiful.net/visualizations</a>: Worlds Biggest Data Breaches Hacks<br/>- <a href='https://bugs.exim.org/show_bug.cgi?id=3099#c4'>https://bugs.exim.org</a>: Incorrect parsing of multiline rfc2231 header filename<br/>- <a href='https://nvd.nist.gov/vuln/detail/CVE-2024-39929'>https://nvd.nist.gov</a>: CVE-2024-39929</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15423740-180-unmasking-data-breaches-understanding-the-surge-and-examining-recent-major-incidents-part-2.mp3" length="25628359" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15423740</guid>
    <pubDate>Sat, 13 Jul 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2132</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>179 -Unmasking Data Breaches - Understanding the Surge and Examining Recent Major Incidents - Part 1</itunes:title>
    <title>179 -Unmasking Data Breaches - Understanding the Surge and Examining Recent Major Incidents - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It's easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today's episode, we will be diving into the reasons behind the surge in data breaches and exploits, ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It&apos;s easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today&apos;s episode, we will be diving into the reasons behind the surge in data breaches and exploits, and how these incidents are becoming more frequent and damaging. Join us as we explore the fundamental factors contributing to this trend and examine some major breaches from the past few years.<br/><br/>Having said that, lets turn to a couple of top trending news this week and they are</p><ul><li>Who are behind the Brain Cipher ransomware?</li></ul><p>- <a href='https://media.inti.asia/read/understanding-the-brain-cipher-ransomware-attack-on-the-national-data-center'>https://media.inti.asia</a>: Understanding the Brain Cipher Ransomware Attack<br/>- <a href='https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/'>https://informationisbeautiful.net/visualizations</a>: Worlds Biggest Data Breaches Hacks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It&apos;s easy to feel like nothing is secure these days, with constant reports of data breaches and exploits occurring everywhere you look. From major corporations to small businesses, no one seems immune to these pervasive cyber threats. The frequency and scale of these incidents can make it seem like our digital world is under continuous siege. In today&apos;s episode, we will be diving into the reasons behind the surge in data breaches and exploits, and how these incidents are becoming more frequent and damaging. Join us as we explore the fundamental factors contributing to this trend and examine some major breaches from the past few years.<br/><br/>Having said that, lets turn to a couple of top trending news this week and they are</p><ul><li>Who are behind the Brain Cipher ransomware?</li></ul><p>- <a href='https://media.inti.asia/read/understanding-the-brain-cipher-ransomware-attack-on-the-national-data-center'>https://media.inti.asia</a>: Understanding the Brain Cipher Ransomware Attack<br/>- <a href='https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/'>https://informationisbeautiful.net/visualizations</a>: Worlds Biggest Data Breaches Hacks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15391267-179-unmasking-data-breaches-understanding-the-surge-and-examining-recent-major-incidents-part-1.mp3" length="20725382" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15391267</guid>
    <pubDate>Sat, 06 Jul 2024 22:00:00 +0400</pubDate>
    <itunes:duration>1723</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>178 - Trusted Relationship Attacks</itunes:title>
    <title>178 - Trusted Relationship Attacks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  In this episode, we’re focusing on the rising trend of IT outsourcing and its implications for cybersecurity. As more businesses delegate non-core tasks to third-party providers, they inadvertently open doors to trust relationship attacks. We'll explore how attackers exploit the trust between companies and their service providers, leading to potentially devastating breaches. Join us as we delve into the mechanisms, real-world examples, and str...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><br/>In this episode, we’re focusing on the rising trend of IT outsourcing and its implications for cybersecurity. As more businesses delegate non-core tasks to third-party providers, they inadvertently open doors to trust relationship attacks. We&apos;ll explore how attackers exploit the trust between companies and their service providers, leading to potentially devastating breaches. Join us as we delve into the mechanisms, real-world examples, and strategies to defend against these insidious threats.<br/><br/>And before we get into the meant of the matter, lets catch up on what has been trending this week:<br/><br/></p><ul><li>A large number of companies are potentially exposed in SnowFlake&apos;s related attacks.</li></ul><p>- <a href='https://cyberscoop.com/as-many-as-165-companies-potentially-exposed-in-snowflake-related-attacks-mandiant-says/'>https://cyberscoop.com</a>: Snowflake related attacks<br/>- <a href='https://attack.mitre.org/techniques/T1199/'>https://attack.mitre.org/techniques</a>: Trust Relationship</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><br/>In this episode, we’re focusing on the rising trend of IT outsourcing and its implications for cybersecurity. As more businesses delegate non-core tasks to third-party providers, they inadvertently open doors to trust relationship attacks. We&apos;ll explore how attackers exploit the trust between companies and their service providers, leading to potentially devastating breaches. Join us as we delve into the mechanisms, real-world examples, and strategies to defend against these insidious threats.<br/><br/>And before we get into the meant of the matter, lets catch up on what has been trending this week:<br/><br/></p><ul><li>A large number of companies are potentially exposed in SnowFlake&apos;s related attacks.</li></ul><p>- <a href='https://cyberscoop.com/as-many-as-165-companies-potentially-exposed-in-snowflake-related-attacks-mandiant-says/'>https://cyberscoop.com</a>: Snowflake related attacks<br/>- <a href='https://attack.mitre.org/techniques/T1199/'>https://attack.mitre.org/techniques</a>: Trust Relationship</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15347278-178-trusted-relationship-attacks.mp3" length="30872568" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15347278</guid>
    <pubDate>Sat, 29 Jun 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2569</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>177 - The Importance Of Automation And Orchestration In Cyber Security - Part 2</itunes:title>
    <title>177 - The Importance Of Automation And Orchestration In Cyber Security - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week's episode will continue with part 2 of  "The Importance of Automation and Orchestration in Cyber Security."  As I said in the episode one, the need for efficient and effective security measures has never been more critical.  I suggest you listen to E1, before you dive into this one.  Without further ado, lets first get what is  trending  this week in term of news and updates.   Hundreds of personal computer as well...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode will continue with part 2 of  &quot;The Importance of Automation and Orchestration in Cyber Security.&quot; <br/>As I said in the episode one, the need for efficient and effective security measures has never been more critical.<br/><br/>I suggest you listen to E1, before you dive into this one.<br/><br/>Without further ado, lets first get what is  trending  this week in term of news and updates.<br/><br/></p><ul><li>Hundreds of personal computer as well as Server Models could be Affected by a serious UEFI Vulnerability</li></ul><p>- <a href='https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/'>https://eclypsium.com</a>: UEFICanHazBufferOverflow Widespread Impact From Vulnerability In Popular PC And Server Firmware<br/>- <a href='https://eclypsium.com/blog/multiplying-security-research-how-eclypsium-automates-binary-analysis-at-scale/'>https://eclypsium.com</a>: How Eclypsium Automates Binary Analysis At Scale<br/>- <a href='https://en.wikipedia.org/wiki/Orchestration_(computing)'>https://en.wikipedia.org</a>: Orchestration (computing)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode will continue with part 2 of  &quot;The Importance of Automation and Orchestration in Cyber Security.&quot; <br/>As I said in the episode one, the need for efficient and effective security measures has never been more critical.<br/><br/>I suggest you listen to E1, before you dive into this one.<br/><br/>Without further ado, lets first get what is  trending  this week in term of news and updates.<br/><br/></p><ul><li>Hundreds of personal computer as well as Server Models could be Affected by a serious UEFI Vulnerability</li></ul><p>- <a href='https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/'>https://eclypsium.com</a>: UEFICanHazBufferOverflow Widespread Impact From Vulnerability In Popular PC And Server Firmware<br/>- <a href='https://eclypsium.com/blog/multiplying-security-research-how-eclypsium-automates-binary-analysis-at-scale/'>https://eclypsium.com</a>: How Eclypsium Automates Binary Analysis At Scale<br/>- <a href='https://en.wikipedia.org/wiki/Orchestration_(computing)'>https://en.wikipedia.org</a>: Orchestration (computing)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15293057-177-the-importance-of-automation-and-orchestration-in-cyber-security-part-2.mp3" length="29577351" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15293057</guid>
    <pubDate>Sat, 22 Jun 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2461</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>176 - The importance Of Automation And Orchestration In Cyber Security - Part 1</itunes:title>
    <title>176 - The importance Of Automation And Orchestration In Cyber Security - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode of the podcast we dissect "The Importance of Automation and Orchestration in Cyber Security."  As you are well aware cyber threats are becoming increasingly sophisticated and frequent.  The need for efficient and effective security measures has never been more critical. Equally, automation and orchestration have never more important for organizations to defend themselves and to streamlining processes, reducing r...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode of the podcast we dissect &quot;The Importance of Automation and Orchestration in Cyber Security.&quot; <br/>As you are well aware cyber threats are becoming increasingly sophisticated and frequent. <br/>The need for efficient and effective security measures has never been more critical. Equally, automation and orchestration have never more important for organizations to defend themselves and to streamlining processes, reducing response times, and enhancing overall security posture. <br/>In my view this is an important way of tipping the balance in favor of the defenders.<br/><br/>Having said that and before we get into the main topic, lets touch a trending piece of news this week. And that is:</p><ul><li>Phishing Email Abuses Windows Search Protocol</li></ul><p>- <a href='https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/search-spoof-abuse-of-windows-search-to-redirect-to-malware/'>https://www.trustwave.com</a>: Search Spoof Abuse O Windows Search T Redirect To Malware<br/>- <a href='https://learn.microsoft.com/en-us/previous-versions/windows/desktop/legacy/cc144083(v=vs.85)'>https://learn.microsoft.com</a>: Using the search Protocol<br/>- <a href='https://benjamin-altpeter.de/doc/thesis-electron.pdf'>https://benjamin-altpeter.de</a>: An Analysis of the State of Electron Security in the Wild<br/>- <a href='https://en.wikipedia.org/wiki/Orchestration_(computing)'>https://en.wikipedia.org</a>: Orchestration (computing)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode of the podcast we dissect &quot;The Importance of Automation and Orchestration in Cyber Security.&quot; <br/>As you are well aware cyber threats are becoming increasingly sophisticated and frequent. <br/>The need for efficient and effective security measures has never been more critical. Equally, automation and orchestration have never more important for organizations to defend themselves and to streamlining processes, reducing response times, and enhancing overall security posture. <br/>In my view this is an important way of tipping the balance in favor of the defenders.<br/><br/>Having said that and before we get into the main topic, lets touch a trending piece of news this week. And that is:</p><ul><li>Phishing Email Abuses Windows Search Protocol</li></ul><p>- <a href='https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/search-spoof-abuse-of-windows-search-to-redirect-to-malware/'>https://www.trustwave.com</a>: Search Spoof Abuse O Windows Search T Redirect To Malware<br/>- <a href='https://learn.microsoft.com/en-us/previous-versions/windows/desktop/legacy/cc144083(v=vs.85)'>https://learn.microsoft.com</a>: Using the search Protocol<br/>- <a href='https://benjamin-altpeter.de/doc/thesis-electron.pdf'>https://benjamin-altpeter.de</a>: An Analysis of the State of Electron Security in the Wild<br/>- <a href='https://en.wikipedia.org/wiki/Orchestration_(computing)'>https://en.wikipedia.org</a>: Orchestration (computing)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15268167-176-the-importance-of-automation-and-orchestration-in-cyber-security-part-1.mp3" length="26405422" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15268167</guid>
    <pubDate>Sat, 15 Jun 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2197</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>175 - The Dangers Of Remote Workers</itunes:title>
    <title>175 - The Dangers Of Remote Workers</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we're tackling a topic that has become increasingly relevant in our post-pandemic world: the hidden dangers posed by remote work. As more companies embrace flexible work arrangements, the convenience and efficiency of working from home bring new set of challenges.   From cybersecurity threats to data privacy concerns, remote work introduces vulnerabilities that many organizations are not fully prepared to handle.  I...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we&apos;re tackling a topic that has become increasingly relevant in our post-pandemic world: the hidden dangers posed by remote work.<br/>As more companies embrace flexible work arrangements, the convenience and efficiency of working from home bring new set of challenges. <br/><br/>From cybersecurity threats to data privacy concerns, remote work introduces vulnerabilities that many organizations are not fully prepared to handle.<br/><br/>In this episode, we&apos;ll explore the risks associated with remote work, share real-world examples of security breaches, and discuss practical steps that businesses and employees can take to safeguard sensitive information.<br/><br/>Before we get into the main topic, lets touch a trending piece of news this week. And that is:</p><ul><li> More backlash about Microsoft&apos;s Recall technology.</li></ul><p>- <a href='https://www.computing.co.uk/news/4319952/microsoft-overhauls-recall-makes-opt#:~:text=Microsoft%20is%20making%20a%20U,screens%20constantly%20monitored%20a...'>https://www.computing.co.uk</a>: Microsoft overhauls Recall, makes it opt-in<br/>- <a href='https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2020/pdf/DGTL-PSOSEC-1007.pdf'>https://www.ciscolive.com</a>: Protecting Remote Workers,<br/>the Right Way</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we&apos;re tackling a topic that has become increasingly relevant in our post-pandemic world: the hidden dangers posed by remote work.<br/>As more companies embrace flexible work arrangements, the convenience and efficiency of working from home bring new set of challenges. <br/><br/>From cybersecurity threats to data privacy concerns, remote work introduces vulnerabilities that many organizations are not fully prepared to handle.<br/><br/>In this episode, we&apos;ll explore the risks associated with remote work, share real-world examples of security breaches, and discuss practical steps that businesses and employees can take to safeguard sensitive information.<br/><br/>Before we get into the main topic, lets touch a trending piece of news this week. And that is:</p><ul><li> More backlash about Microsoft&apos;s Recall technology.</li></ul><p>- <a href='https://www.computing.co.uk/news/4319952/microsoft-overhauls-recall-makes-opt#:~:text=Microsoft%20is%20making%20a%20U,screens%20constantly%20monitored%20a...'>https://www.computing.co.uk</a>: Microsoft overhauls Recall, makes it opt-in<br/>- <a href='https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2020/pdf/DGTL-PSOSEC-1007.pdf'>https://www.ciscolive.com</a>: Protecting Remote Workers,<br/>the Right Way</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15242410-175-the-dangers-of-remote-workers.mp3" length="34342692" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15242410</guid>
    <pubDate>Sat, 08 Jun 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2858</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>174 - Digital Twin Technology And Its Application In Security</itunes:title>
    <title>174 - Digital Twin Technology And Its Application In Security</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode we're exploring an exciting and transformative innovation: Digital Twins technology and its groundbreaking application in cybersecurity.  Imagine having a virtual replica of your entire digital infrastructure—a detailed, dynamic model that mirrors every aspect of your environment. In particular, we will look at how this cutting-edge technology enhances our ability to test, patch and update our environment  and theref...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we&apos;re exploring an exciting and transformative innovation: Digital Twins technology and its groundbreaking application in cybersecurity.<br/><br/>Imagine having a virtual replica of your entire digital infrastructure—a detailed, dynamic model that mirrors every aspect of your environment.<br/>In particular, we will look at how this cutting-edge technology enhances our ability to test, patch and update our environment  and therefore anticipate, detect, and respond to cyber threats with unmatched precision and agility.<br/><br/>Before we get into the main topic, lets touch a top trending piece of news this week. And that is:</p><ul><li>Kaspersky releases free tool that scans Linux for known threats</li></ul><p>- <a href='https://www.bleepingcomputer.com/news/software/kaspersky-releases-free-tool-that-scans-linux-for-known-threats/'>https://www.bleepingcomputer.com</a>: Kaspersky Releases Free Tool That Scans Linux For Known Threats<br/>- <a href='https://en.wikipedia.org/wiki/Digital_twin'>https://en.wikipedia.org</a>: Digital-Twin<br/>- <a href='https://blogs.cisco.com/security/cisco-hypershield-reimagining-security'>https://blogs.cisco.com/securit</a>: Cisco HyperShield Reimagining Security</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode we&apos;re exploring an exciting and transformative innovation: Digital Twins technology and its groundbreaking application in cybersecurity.<br/><br/>Imagine having a virtual replica of your entire digital infrastructure—a detailed, dynamic model that mirrors every aspect of your environment.<br/>In particular, we will look at how this cutting-edge technology enhances our ability to test, patch and update our environment  and therefore anticipate, detect, and respond to cyber threats with unmatched precision and agility.<br/><br/>Before we get into the main topic, lets touch a top trending piece of news this week. And that is:</p><ul><li>Kaspersky releases free tool that scans Linux for known threats</li></ul><p>- <a href='https://www.bleepingcomputer.com/news/software/kaspersky-releases-free-tool-that-scans-linux-for-known-threats/'>https://www.bleepingcomputer.com</a>: Kaspersky Releases Free Tool That Scans Linux For Known Threats<br/>- <a href='https://en.wikipedia.org/wiki/Digital_twin'>https://en.wikipedia.org</a>: Digital-Twin<br/>- <a href='https://blogs.cisco.com/security/cisco-hypershield-reimagining-security'>https://blogs.cisco.com/securit</a>: Cisco HyperShield Reimagining Security</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15185521-174-digital-twin-technology-and-its-application-in-security.mp3" length="27729167" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15185521</guid>
    <pubDate>Sat, 01 Jun 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2307</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>173 - SSL VPN versus IPsec VPN - Part 2</itunes:title>
    <title>173 - SSL VPN versus IPsec VPN - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we continue with part 2 on comparing SSL VPN and IPsec VPN, two popular technologies used for secure remote access.  As I said last week, understanding the nuances of these technologies is therefore crucial. We'll explore how each VPN works, their security features, performance differences, and the scenarios where each excels. Please listen to episode 172 before you listen to this episode.  With that said, lets turn to a top tre...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we continue with part 2 on comparing SSL VPN and IPsec VPN, two popular technologies used for secure remote access. <br/>As I said last week, understanding the nuances of these technologies is therefore crucial. We&apos;ll explore how each VPN works, their security features, performance differences, and the scenarios where each excels. Please listen to episode 172 before you listen to this episode.<br/><br/>With that said, lets turn to a top trending news this week:<br/><br/>- Microsoft&apos;s &quot;Recall&quot; feature raises privacy concern.<br/><br/>- <a href='https://www.wired.com/story/microsoft-recall-ai-privacy-nightmare-security-roundup/'>https://www.wired.com</a>: Microsoft Recall AI May Be A Privacy Nightmare <br/>- <a href='https://en.wikipedia.org/wiki/Virtual_private_network'>https://en.wikipedia.org</a>: Virtual_private_network<br/>- <a href='https://en.wikipedia.org/wiki/Transport_Layer_Security'>https://en.wikipedia.org</a>: Transport Layer Security<br/><a href='https://www.bleepingcomputer.com/news/security/norway-recommends-replacing-ssl-vpn-to-prevent-breaches/'>https://www.bleepingcomputer.com</a>: Norway Recommends Replacing SSL VPN To Prevent Breaches</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we continue with part 2 on comparing SSL VPN and IPsec VPN, two popular technologies used for secure remote access. <br/>As I said last week, understanding the nuances of these technologies is therefore crucial. We&apos;ll explore how each VPN works, their security features, performance differences, and the scenarios where each excels. Please listen to episode 172 before you listen to this episode.<br/><br/>With that said, lets turn to a top trending news this week:<br/><br/>- Microsoft&apos;s &quot;Recall&quot; feature raises privacy concern.<br/><br/>- <a href='https://www.wired.com/story/microsoft-recall-ai-privacy-nightmare-security-roundup/'>https://www.wired.com</a>: Microsoft Recall AI May Be A Privacy Nightmare <br/>- <a href='https://en.wikipedia.org/wiki/Virtual_private_network'>https://en.wikipedia.org</a>: Virtual_private_network<br/>- <a href='https://en.wikipedia.org/wiki/Transport_Layer_Security'>https://en.wikipedia.org</a>: Transport Layer Security<br/><a href='https://www.bleepingcomputer.com/news/security/norway-recommends-replacing-ssl-vpn-to-prevent-breaches/'>https://www.bleepingcomputer.com</a>: Norway Recommends Replacing SSL VPN To Prevent Breaches</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15136122-173-ssl-vpn-versus-ipsec-vpn-part-2.mp3" length="21902667" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15136122</guid>
    <pubDate>Sat, 25 May 2024 23:00:00 +0400</pubDate>
    <itunes:duration>1822</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>172 - SSL VPN versus IPsec VPN - Part 1</itunes:title>
    <title>172 - SSL VPN versus IPsec VPN - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode  we're diving into the world of VPNs,  Specifically we will compare SSL VPN and IPsec VPN, two popular technologies used for secure remote access. In the post pandemic area, remote work become part of the new normal post. Understanding the nuances of these technologies is therefore crucial. We'll explore how each VPN works, their security features, performance differences, and the scenarios where each excels.  H...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode  we&apos;re diving into the world of VPNs,  Specifically we will compare SSL VPN and IPsec VPN, two popular technologies used for secure remote access. In the post pandemic area, remote work become part of the new normal post. Understanding the nuances of these technologies is therefore crucial. We&apos;ll explore how each VPN works, their security features, performance differences, and the scenarios where each excels.<br/><br/>Having said that and before we get into VPN, lets turn to a top trending news this week and they are:</p><ul><li>Recap of RSA Conference. The biggest security conference in the US.</li></ul><p>- <a href='https://en.wikipedia.org/wiki/Virtual_private_network'>https://en.wikipedia.org</a>: Virtual_private_network<br/>- <a href='https://en.wikipedia.org/wiki/Transport_Layer_Security'>https://en.wikipedia.org</a>: Transport Layer Security<br/><a href='https://www.bleepingcomputer.com/news/security/norway-recommends-replacing-ssl-vpn-to-prevent-breaches/'>https://www.bleepingcomputer.com</a>: Norway Recommends Replacing SSL VPN To Prevent Breaches<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode  we&apos;re diving into the world of VPNs,  Specifically we will compare SSL VPN and IPsec VPN, two popular technologies used for secure remote access. In the post pandemic area, remote work become part of the new normal post. Understanding the nuances of these technologies is therefore crucial. We&apos;ll explore how each VPN works, their security features, performance differences, and the scenarios where each excels.<br/><br/>Having said that and before we get into VPN, lets turn to a top trending news this week and they are:</p><ul><li>Recap of RSA Conference. The biggest security conference in the US.</li></ul><p>- <a href='https://en.wikipedia.org/wiki/Virtual_private_network'>https://en.wikipedia.org</a>: Virtual_private_network<br/>- <a href='https://en.wikipedia.org/wiki/Transport_Layer_Security'>https://en.wikipedia.org</a>: Transport Layer Security<br/><a href='https://www.bleepingcomputer.com/news/security/norway-recommends-replacing-ssl-vpn-to-prevent-breaches/'>https://www.bleepingcomputer.com</a>: Norway Recommends Replacing SSL VPN To Prevent Breaches<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15106527-172-ssl-vpn-versus-ipsec-vpn-part-1.mp3" length="25445812" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15106527</guid>
    <pubDate>Sat, 18 May 2024 11:00:00 +0400</pubDate>
    <itunes:duration>2117</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>171 - Remote Browser Isolation</itunes:title>
    <title>171 - Remote Browser Isolation</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we will be exploring the fascinating world of remote browser isolation technology or RBI as it appreciated. We will delve into what remote browser isolation is, how it works, and the limitations it faces. Join us as we uncover the complexities of this innovative cybersecurity approach, shedding light on its benefits and challenges. Whether you are new to the concept or a seasoned professional, there is something here for...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we will be exploring the fascinating world of remote browser isolation technology or RBI as it appreciated. We will delve into what remote browser isolation is, how it works, and the limitations it faces. Join us as we uncover the complexities of this innovative cybersecurity approach, shedding light on its benefits and challenges. Whether you are new to the concept or a seasoned professional, there is something here for everyone. <br/><br/>Having said that and before we get into RBI, lets turn to a couple of top trending news this week and they are:</p><ul><li>Dell data breach, 49 million customer records stolen</li></ul><p>- <a href='https://techcrunch.com/2024/05/10/threat-actor-scraped-49m-dell-customer-addresses-before-the-company-found-out/?guccounter=1'>https://techcrunch.com</a>: Threat Actor Scraped- 49M Dell customer Addresses Before The Company Found Out<br/>- <a href='https://www.w3.org/TR/REC-DOM-Level-1/introduction.html'>https://www.w3.org</a>: Introduction to DOM<br/>- <a href='https://en.wikipedia.org/wiki/Browser_isolation'>https://en.wikipedia.org</a>: Browser Isolation</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we will be exploring the fascinating world of remote browser isolation technology or RBI as it appreciated. We will delve into what remote browser isolation is, how it works, and the limitations it faces. Join us as we uncover the complexities of this innovative cybersecurity approach, shedding light on its benefits and challenges. Whether you are new to the concept or a seasoned professional, there is something here for everyone. <br/><br/>Having said that and before we get into RBI, lets turn to a couple of top trending news this week and they are:</p><ul><li>Dell data breach, 49 million customer records stolen</li></ul><p>- <a href='https://techcrunch.com/2024/05/10/threat-actor-scraped-49m-dell-customer-addresses-before-the-company-found-out/?guccounter=1'>https://techcrunch.com</a>: Threat Actor Scraped- 49M Dell customer Addresses Before The Company Found Out<br/>- <a href='https://www.w3.org/TR/REC-DOM-Level-1/introduction.html'>https://www.w3.org</a>: Introduction to DOM<br/>- <a href='https://en.wikipedia.org/wiki/Browser_isolation'>https://en.wikipedia.org</a>: Browser Isolation</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15057960-171-remote-browser-isolation.mp3" length="34613257" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-15057960</guid>
    <pubDate>Sat, 11 May 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2881</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>170 - eBPF - Part 2</itunes:title>
    <title>170 - eBPF - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  In part 2 on eBPF we continue demystifying this promising new technology that is strengthening  the cyber space. Please listen to the previous episode i.e. Episode 169 before you to listen to this one.   Having said that, lets recap a top trending security news, shall we? New UK Law: No Default Passwords on Smart Devices from April 2024- https://www.ncsc.gov.uk: Smart Devices Law - https://www.ncsc.gov.uk: Leaflet To Consumer On...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> In part 2 on eBPF we continue demystifying this promising new technology that is strengthening  the cyber space. Please listen to the previous episode i.e. Episode 169 before you to listen to this one.<br/> <br/>Having said that, lets recap a top trending security news, shall we?</p><ul><li>New UK Law: No Default Passwords on Smart Devices from April 2024</li></ul><p>- <a href='https://www.ncsc.gov.uk/blog-post/smart-devices-law'>https://www.ncsc.gov.uk</a>: Smart Devices Law<br/>- <a href='https://www.ncsc.gov.uk/files/Security-law-smart-devices-NCSC.pdf'>https://www.ncsc.gov.uk</a>: Leaflet To Consumer On Security Law Smart Devices<a href='https://ebpf.foundation/'><br/>- https://ebpf.foundation</a>: eBPF<br/>- <a href='https://cloudblogs.microsoft.com/opensource/2021/05/10/making-ebpf-work-on-windows/'>https://cloudblogs.microsoft.com</a>: Making eBPF work on Windows<br/>- <a href='https://en.wikipedia.org/wiki/Protection_ring'>https://en.wikipedia.org</a>: Protection ring<br/>- <a href='https://cilium.io/get-started/'>https://cilium.io</a>: Cilium<br/>- <a href='https://blogs.cisco.com/security/cisco-hypershield-reimagining-security'>https://blogs.cisco.com</a>: Cisco HyperShield Reimagining Security<br/>- <a href='https://www.linkedin.com/blog/engineering/infrastructure/skyfall-ebpf-agent-for-infrastructure-observability'>https://www.linkedin.com</a>: Skyfall eBPF Agent For Infrastructure Observability<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> In part 2 on eBPF we continue demystifying this promising new technology that is strengthening  the cyber space. Please listen to the previous episode i.e. Episode 169 before you to listen to this one.<br/> <br/>Having said that, lets recap a top trending security news, shall we?</p><ul><li>New UK Law: No Default Passwords on Smart Devices from April 2024</li></ul><p>- <a href='https://www.ncsc.gov.uk/blog-post/smart-devices-law'>https://www.ncsc.gov.uk</a>: Smart Devices Law<br/>- <a href='https://www.ncsc.gov.uk/files/Security-law-smart-devices-NCSC.pdf'>https://www.ncsc.gov.uk</a>: Leaflet To Consumer On Security Law Smart Devices<a href='https://ebpf.foundation/'><br/>- https://ebpf.foundation</a>: eBPF<br/>- <a href='https://cloudblogs.microsoft.com/opensource/2021/05/10/making-ebpf-work-on-windows/'>https://cloudblogs.microsoft.com</a>: Making eBPF work on Windows<br/>- <a href='https://en.wikipedia.org/wiki/Protection_ring'>https://en.wikipedia.org</a>: Protection ring<br/>- <a href='https://cilium.io/get-started/'>https://cilium.io</a>: Cilium<br/>- <a href='https://blogs.cisco.com/security/cisco-hypershield-reimagining-security'>https://blogs.cisco.com</a>: Cisco HyperShield Reimagining Security<br/>- <a href='https://www.linkedin.com/blog/engineering/infrastructure/skyfall-ebpf-agent-for-infrastructure-observability'>https://www.linkedin.com</a>: Skyfall eBPF Agent For Infrastructure Observability<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/15023055-170-ebpf-part-2.mp3" length="30449370" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-15023055</guid>
    <pubDate>Sat, 04 May 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2534</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>169 - eBPF - Part 1</itunes:title>
    <title>169 - eBPF - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  In this episode, we're diving deep to demystif  a groundbreaking technology that's gathering pace on the security front. It is not something most  people are aware of. This technology is bringing enhanced visibility, increased performance to enabling powerful security measures.    Hang around as we unravel the potential of eBPF in bolstering cybersecurity defenses, from real-time threat detection to proactive mitigation str...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> In this episode, we&apos;re diving deep to demystif  a groundbreaking technology that&apos;s gathering pace on the security front. It is not something most  people are aware of. This technology is bringing enhanced visibility, increased performance to enabling powerful security measures.  <br/><br/>Hang around as we unravel the potential of eBPF in bolstering cybersecurity defenses, from real-time threat detection to proactive mitigation strategies, and explore how this revolutionary tool is reshaping the landscape  of security.<br/><br/>Before we get into that, lets recap a top trending security news: and that is</p><ul><li>Threat Actors Were Exploiting an Antivirus Update Mechanism to Spread Malware</li></ul><p>- <a href='https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/'>https://decoded.avast.io</a>: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining<br/>- <a href='https://ebpf.foundation'>https://ebpf.foundation</a>: eBPF<br/>- <a href='https://cloudblogs.microsoft.com/opensource/2021/05/10/making-ebpf-work-on-windows/'>https://cloudblogs.microsoft.com</a>: Making eBPF work on Windows<br/>- <a href='https://en.wikipedia.org/wiki/Protection_ring'>https://en.wikipedia.org</a>: Protection ring<br/>- <a href='https://cilium.io/get-started/'>https://cilium.io</a>: Cilium<br/>- <a href='https://blogs.cisco.com/security/cisco-hypershield-reimagining-security'>https://blogs.cisco.com</a>: Cisco HyperShield Reimagining Security<br/>- <a href='https://www.linkedin.com/blog/engineering/infrastructure/skyfall-ebpf-agent-for-infrastructure-observability'>https://www.linkedin.com</a>: Skyfall eBPF Agent For Infrastructure Observability</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> In this episode, we&apos;re diving deep to demystif  a groundbreaking technology that&apos;s gathering pace on the security front. It is not something most  people are aware of. This technology is bringing enhanced visibility, increased performance to enabling powerful security measures.  <br/><br/>Hang around as we unravel the potential of eBPF in bolstering cybersecurity defenses, from real-time threat detection to proactive mitigation strategies, and explore how this revolutionary tool is reshaping the landscape  of security.<br/><br/>Before we get into that, lets recap a top trending security news: and that is</p><ul><li>Threat Actors Were Exploiting an Antivirus Update Mechanism to Spread Malware</li></ul><p>- <a href='https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/'>https://decoded.avast.io</a>: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining<br/>- <a href='https://ebpf.foundation'>https://ebpf.foundation</a>: eBPF<br/>- <a href='https://cloudblogs.microsoft.com/opensource/2021/05/10/making-ebpf-work-on-windows/'>https://cloudblogs.microsoft.com</a>: Making eBPF work on Windows<br/>- <a href='https://en.wikipedia.org/wiki/Protection_ring'>https://en.wikipedia.org</a>: Protection ring<br/>- <a href='https://cilium.io/get-started/'>https://cilium.io</a>: Cilium<br/>- <a href='https://blogs.cisco.com/security/cisco-hypershield-reimagining-security'>https://blogs.cisco.com</a>: Cisco HyperShield Reimagining Security<br/>- <a href='https://www.linkedin.com/blog/engineering/infrastructure/skyfall-ebpf-agent-for-infrastructure-observability'>https://www.linkedin.com</a>: Skyfall eBPF Agent For Infrastructure Observability</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14990121-169-ebpf-part-1.mp3" length="33781863" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14990121</guid>
    <pubDate>Sat, 27 Apr 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2811</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>168 - Preparing for and responding to ransomeware attack - Part 2</itunes:title>
    <title>168 - Preparing for and responding to ransomeware attack - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we will continue with part 2 on "Preparing for and responding to ransomeware attack" As I said last week, ransomware is a threat that will be around us for the foreseeable future. Do listen to part 1 before you listen to this episode.  With that out of the way, lets have a look a top trending piece of update for you.   There is large-scale brute-force activity targeting VPNs, SSH services with commonly used login credent...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we will continue with part 2 on &quot;Preparing for and responding to ransomeware attack&quot;<br/>As I said last week, ransomware is a threat that will be around us for the foreseeable future.<br/>Do listen to part 1 before you listen to this episode.<br/><br/>With that out of the way, lets have a look a top trending piece of update for you.<br/><br/></p><ul><li>There is large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials</li></ul><p><br/><a href='https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/'>https://blog.talosintelligence.com</a>: Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials<br/>- <a href='https://attack.mitre.org/groups/G0010/'>https://attack.mitre.org</a>: Turla<br/>- <a href='https://www.chainalysis.com/blog/ransomware-2024/'>https://www.chainalysis.com</a>: ransomware 2024<br/>- <a href='https://www.cohesity.com/blogs/adaptive-and-automated-data-protection-with-cohesity-datahawk-and-cisco-xdr/'>https://www.cohesity.com</a>: Ransomware Recovery</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we will continue with part 2 on &quot;Preparing for and responding to ransomeware attack&quot;<br/>As I said last week, ransomware is a threat that will be around us for the foreseeable future.<br/>Do listen to part 1 before you listen to this episode.<br/><br/>With that out of the way, lets have a look a top trending piece of update for you.<br/><br/></p><ul><li>There is large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials</li></ul><p><br/><a href='https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/'>https://blog.talosintelligence.com</a>: Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials<br/>- <a href='https://attack.mitre.org/groups/G0010/'>https://attack.mitre.org</a>: Turla<br/>- <a href='https://www.chainalysis.com/blog/ransomware-2024/'>https://www.chainalysis.com</a>: ransomware 2024<br/>- <a href='https://www.cohesity.com/blogs/adaptive-and-automated-data-protection-with-cohesity-datahawk-and-cisco-xdr/'>https://www.cohesity.com</a>: Ransomware Recovery</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14926011-168-preparing-for-and-responding-to-ransomeware-attack-part-2.mp3" length="24181015" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14926011</guid>
    <pubDate>Sat, 20 Apr 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2011</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>167 - Preparing for and responding to ransomeware attack</itunes:title>
    <title>167 - Preparing for and responding to ransomeware attack</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Ransomware is a threat that will be around us for the foreseeable future.  In this week's episode we will look at the history of ransomware, the common TTPs in use by threat actors such as Turla, how to align our incident response to that threat and others, and finally how to contain, eradicate, and recover from it. In addition we will answer the following pertinent question that are top of minds for the SOC team. Questions such as: - What...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Ransomware is a threat that will be around us for the foreseeable future.<br/> In this week&apos;s episode we will look at the history of ransomware, the common TTPs in use by threat actors such as Turla, how to align our incident response to that threat and others, and finally how to contain, eradicate, and recover from it.<br/>In addition we will answer the following pertinent question that are top of minds for the SOC team. Questions such as:<br/>- What are the best methods to inhibiter Threat actor&apos;s lateral movement?<br/>- What are the critical components that drive ransomware?<br/>etc...<br/>But before we dig into these gems, lets touch one important top trending piece of news. And that is:<br/><br/>- CISA makes its malware analysis system publicly available<br/><br/>- <a href='https://www.cisa.gov/news-events/news/cisa-announces-malware-next-gen-analysis'>https://www.cisa.gov</a>: CISA Announces Malware Next-Gen Analysis<br/>- <a href='https://attack.mitre.org/groups/G0010/'>https://attack.mitre.org</a>: Turla<br/>- <a href='https://www.chainalysis.com/blog/ransomware-2024/'>https://www.chainalysis.com</a>: ransomware 2024<br/>- <a href='https://www.cohesity.com/blogs/adaptive-and-automated-data-protection-with-cohesity-datahawk-and-cisco-xdr/'>https://www.cohesity.com</a>: Ransomware Recovery<br/><br/></p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Ransomware is a threat that will be around us for the foreseeable future.<br/> In this week&apos;s episode we will look at the history of ransomware, the common TTPs in use by threat actors such as Turla, how to align our incident response to that threat and others, and finally how to contain, eradicate, and recover from it.<br/>In addition we will answer the following pertinent question that are top of minds for the SOC team. Questions such as:<br/>- What are the best methods to inhibiter Threat actor&apos;s lateral movement?<br/>- What are the critical components that drive ransomware?<br/>etc...<br/>But before we dig into these gems, lets touch one important top trending piece of news. And that is:<br/><br/>- CISA makes its malware analysis system publicly available<br/><br/>- <a href='https://www.cisa.gov/news-events/news/cisa-announces-malware-next-gen-analysis'>https://www.cisa.gov</a>: CISA Announces Malware Next-Gen Analysis<br/>- <a href='https://attack.mitre.org/groups/G0010/'>https://attack.mitre.org</a>: Turla<br/>- <a href='https://www.chainalysis.com/blog/ransomware-2024/'>https://www.chainalysis.com</a>: ransomware 2024<br/>- <a href='https://www.cohesity.com/blogs/adaptive-and-automated-data-protection-with-cohesity-datahawk-and-cisco-xdr/'>https://www.cohesity.com</a>: Ransomware Recovery<br/><br/></p><p><br/></p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14917340-167-preparing-for-and-responding-to-ransomeware-attack.mp3" length="25161216" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14917340</guid>
    <pubDate>Sat, 13 Apr 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2093</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>166 - The SysInternal Utilities</itunes:title>
    <title>166 - The SysInternal Utilities</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week we will dive into a collection of powerful system utilities and tools designed to help users diagnose, troubleshoot, and monitor Windows operating system. These utilities provide advanced functionality beyond what is typically available in Windows, as they offer insights into system internals, processes, file systems, networking, and more.  But before we dig into these gems, lets touch one important top trending piece of news. And tha...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week we will dive into a collection of powerful system utilities and tools designed to help users diagnose, troubleshoot, and monitor Windows operating system.<br/>These utilities provide advanced functionality beyond what is typically available in Windows, as they offer insights into system internals, processes, file systems, networking, and more.<br/><br/>But before we dig into these gems, lets touch one important top trending piece of news. And that is:<br/><br/></p><ul><li>There is a Post Authentication Stack Overflow on a NetGear Router.</li></ul><p>- <a href='https://blog.talosintelligence.com/vulnerability-roundup-march-20-2024/'>https://blog.talosintelligence.com</a>: Netgear wireless router open to code execution after buffer overflow vulnerability<br/><a href='https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1887'>https://www.talosintelligence.com</a>: <br/>Netgear RAX30 JSON Parsing getblockschedule() stack-based buffer overflow vulnerability<br/>- <a href='https://kb.netgear.com/000066037/Security-Advisory-for-Post-Authentication-Stack-Overflow-on-the-RAX30-PSV-2023-0160'>https://kb.netgear.com</a>: Security Advisory for Post Authentication Stack-Overflow on the RAX30<br/>- <a href='https://learn.microsoft.com/en-us/sysinternals/downloads/pstools'>https://learn.microsoft.com</a>: PSTools<br/>- <a href='https://learn.microsoft.com/en-us/sysinternals/'>https://learn.microsoft.com</a>: SysInternals<br/>- <a href='https://en.wikipedia.org/wiki/Mark_Russinovich'>https://en.wikipedia.org/wiki</a>: Mark Russinovich</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week we will dive into a collection of powerful system utilities and tools designed to help users diagnose, troubleshoot, and monitor Windows operating system.<br/>These utilities provide advanced functionality beyond what is typically available in Windows, as they offer insights into system internals, processes, file systems, networking, and more.<br/><br/>But before we dig into these gems, lets touch one important top trending piece of news. And that is:<br/><br/></p><ul><li>There is a Post Authentication Stack Overflow on a NetGear Router.</li></ul><p>- <a href='https://blog.talosintelligence.com/vulnerability-roundup-march-20-2024/'>https://blog.talosintelligence.com</a>: Netgear wireless router open to code execution after buffer overflow vulnerability<br/><a href='https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1887'>https://www.talosintelligence.com</a>: <br/>Netgear RAX30 JSON Parsing getblockschedule() stack-based buffer overflow vulnerability<br/>- <a href='https://kb.netgear.com/000066037/Security-Advisory-for-Post-Authentication-Stack-Overflow-on-the-RAX30-PSV-2023-0160'>https://kb.netgear.com</a>: Security Advisory for Post Authentication Stack-Overflow on the RAX30<br/>- <a href='https://learn.microsoft.com/en-us/sysinternals/downloads/pstools'>https://learn.microsoft.com</a>: PSTools<br/>- <a href='https://learn.microsoft.com/en-us/sysinternals/'>https://learn.microsoft.com</a>: SysInternals<br/>- <a href='https://en.wikipedia.org/wiki/Mark_Russinovich'>https://en.wikipedia.org/wiki</a>: Mark Russinovich</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14847451-166-the-sysinternal-utilities.mp3" length="33855948" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14847451</guid>
    <pubDate>Sat, 06 Apr 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2817</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>165 - How AI is helping Incident Responders</itunes:title>
    <title>165 - How AI is helping Incident Responders</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! AI is getting into all sorts of places but no less than in cybersecurity in both a good way and bad ways. In a good way with bolstering Incident response live cycle but unfortunately in a bad way with generating convincing phishing email or assisting with script and coding etc.  In this week's episode we will focus on how AI is helping IR in getting to the bottom of what might have happened.  Before we get into the main topic, lets touch one im...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>AI is getting into all sorts of places but no less than in cybersecurity in both a good way and bad ways. In a good way with bolstering Incident response live cycle but unfortunately in a bad way with generating convincing phishing email or assisting with script and coding etc.<br/><br/>In this week&apos;s episode we will focus on how AI is helping IR in getting to the bottom of what might have happened.<br/><br/>Before we get into the main topic, lets touch one important top trending piece of news. And that is:</p><ul><li>RedHat warns of a backdoor in a tool used in most of Linux distributions.</li></ul><p>- <a href='https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users'>https://www.redhat.com</a>: Urgent security alert Fedora 41 and rawhide users<br/>- <a href='https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094'>https://www.cisa.gov</a>: Reported supply chain compromise affecting XZ Utils data compression library CVE-2024-3094<br/>- <a href='https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2024/pdf/BRKSEC-2113.pdf'>https://www.ciscolive.com</a>: AI Assistance (page 52)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>AI is getting into all sorts of places but no less than in cybersecurity in both a good way and bad ways. In a good way with bolstering Incident response live cycle but unfortunately in a bad way with generating convincing phishing email or assisting with script and coding etc.<br/><br/>In this week&apos;s episode we will focus on how AI is helping IR in getting to the bottom of what might have happened.<br/><br/>Before we get into the main topic, lets touch one important top trending piece of news. And that is:</p><ul><li>RedHat warns of a backdoor in a tool used in most of Linux distributions.</li></ul><p>- <a href='https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users'>https://www.redhat.com</a>: Urgent security alert Fedora 41 and rawhide users<br/>- <a href='https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094'>https://www.cisa.gov</a>: Reported supply chain compromise affecting XZ Utils data compression library CVE-2024-3094<br/>- <a href='https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2024/pdf/BRKSEC-2113.pdf'>https://www.ciscolive.com</a>: AI Assistance (page 52)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14801485-165-how-ai-is-helping-incident-responders.mp3" length="25276001" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14801485</guid>
    <pubDate>Sat, 30 Mar 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2102</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>164 - What Is Platform Approach To Security? - Part 2</itunes:title>
    <title>164 - What Is Platform Approach To Security? - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In our second episode, we continue exploring  the  concept of adopting a platform security.  In this second part we will continue where we left off from last week and will encourage you to listed to the first episode if you have not done so.  Before we get into the main topic, lets touch one important top trending piece of news this week. And that is:   - Github added AI powered vulnerability auto-fix feature - https://www.cisco....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In our second episode, we continue exploring  the  concept of adopting a platform security. <br/>In this second part we will continue where we left off from last week and will encourage you to listed to the first episode if you have not done so.<br/><br/>Before we get into the main topic, lets touch one important top trending piece of news this week. And that is:<br/><br/></p><ul><li>- Github added AI powered vulnerability auto-fix feature</li></ul><p><br/>- <a href='https://www.cisco.com/c/en/us/products/collateral/security/xdr/xdr-buyer-guide.html'>https://www.cisco.com</a>: XDR- Platform approach to security<br/>- <a href='https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/'>https://github.blog</a>: Introducing Code Ccanning Auto-Fix Powered By Ggithub Copilot And CodeQL</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In our second episode, we continue exploring  the  concept of adopting a platform security. <br/>In this second part we will continue where we left off from last week and will encourage you to listed to the first episode if you have not done so.<br/><br/>Before we get into the main topic, lets touch one important top trending piece of news this week. And that is:<br/><br/></p><ul><li>- Github added AI powered vulnerability auto-fix feature</li></ul><p><br/>- <a href='https://www.cisco.com/c/en/us/products/collateral/security/xdr/xdr-buyer-guide.html'>https://www.cisco.com</a>: XDR- Platform approach to security<br/>- <a href='https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/'>https://github.blog</a>: Introducing Code Ccanning Auto-Fix Powered By Ggithub Copilot And CodeQL</p><p><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14754615-164-what-is-platform-approach-to-security-part-2.mp3" length="23578584" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14754615</guid>
    <pubDate>Sat, 23 Mar 2024 16:00:00 +0400</pubDate>
    <itunes:duration>1961</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>163 - What Is Platform Approach To Security? - Part 1</itunes:title>
    <title>163 - What Is Platform Approach To Security? - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In this episode, we explore  the recently much talked about concept of adopting a platform security. As technology advances, cyber criminals continually adapt their tactics. Engaged in a constant cat-and-mouse game, staying ahead is crucial. It begins with a deep understanding of which st...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this episode, we explore  the recently much talked about concept of adopting a platform security. As technology advances, cyber criminals continually adapt their tactics. Engaged in a constant cat-and-mouse game, staying ahead is crucial. It begins with a deep understanding of which strategies best align with your objectives, safeguarding not only your digital assets but also your bottom line.<br/><br/>Before we get into the main topic, lets touch a top trending piece of news this week. And that is:</p><ul><li>The United States lost record $12.5 billion to online crime in 2023</li></ul><p><br/>- <a href='https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf'>https://www.ic3.gov</a>:2023 IC3 Report<br/>- <a href='https://www.cisco.com/c/en/us/products/collateral/security/xdr/xdr-buyer-guide.html'>https://www.cisco.com</a>: XDR- Platform approach to security</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this episode, we explore  the recently much talked about concept of adopting a platform security. As technology advances, cyber criminals continually adapt their tactics. Engaged in a constant cat-and-mouse game, staying ahead is crucial. It begins with a deep understanding of which strategies best align with your objectives, safeguarding not only your digital assets but also your bottom line.<br/><br/>Before we get into the main topic, lets touch a top trending piece of news this week. And that is:</p><ul><li>The United States lost record $12.5 billion to online crime in 2023</li></ul><p><br/>- <a href='https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf'>https://www.ic3.gov</a>:2023 IC3 Report<br/>- <a href='https://www.cisco.com/c/en/us/products/collateral/security/xdr/xdr-buyer-guide.html'>https://www.cisco.com</a>: XDR- Platform approach to security</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14719777-163-what-is-platform-approach-to-security-part-1.mp3" length="25017095" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14719777</guid>
    <pubDate>Sat, 16 Mar 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2081</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>162 - LEAP 2024 - Riyadh</itunes:title>
    <title>162 - LEAP 2024 - Riyadh</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It was the LEAP event this past week. LEAP is a technology event in Saudi Arabia, Riyadh and it attracts every technology company imaginable especially in the cyber security domain. This is year was no different.  At LEAP, I met with Port53, a firm that helps from SMB to enterprise businesses with their cyber security mission by delivering enterprise-grade solutions to deploy and management effortlessly.  Before we get into that lets turn to a ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It was the LEAP event this past week. LEAP is a technology event in Saudi Arabia, Riyadh and it attracts every technology company imaginable especially in the cyber security domain. This is year was no different.<br/><br/>At LEAP, I met with Port53, a firm that helps from SMB to enterprise businesses with their cyber security mission by delivering enterprise-grade solutions to deploy and management effortlessly.<br/><br/>Before we get into that lets turn to a top trending news this week which</p><ul><li>New email scam that targets NTLM hashes</li></ul><p>- <a href='https://port53.com/'>https://port53.com</a>: Port53<br/>- <a href='https://www.bleepingcomputer.com/news/security/hackers-steal-windows-ntlm-authentication-hashes-in-phishing-attacks/#:~:text=Using%20phishing%20to%20steal%20NTLM%20hashes&amp;text=When%20the%20Windows%20device%20connects,steal%20the%20NTLM%20authentication%20hashes.'>https://www.bleepingcomputer.com</a>: Hackers steal Windows NTLM authentication hashes in phishing attacks<br/>- <a href='https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview'>https://learn.microsoft.com</a>: NTLM Overview</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It was the LEAP event this past week. LEAP is a technology event in Saudi Arabia, Riyadh and it attracts every technology company imaginable especially in the cyber security domain. This is year was no different.<br/><br/>At LEAP, I met with Port53, a firm that helps from SMB to enterprise businesses with their cyber security mission by delivering enterprise-grade solutions to deploy and management effortlessly.<br/><br/>Before we get into that lets turn to a top trending news this week which</p><ul><li>New email scam that targets NTLM hashes</li></ul><p>- <a href='https://port53.com/'>https://port53.com</a>: Port53<br/>- <a href='https://www.bleepingcomputer.com/news/security/hackers-steal-windows-ntlm-authentication-hashes-in-phishing-attacks/#:~:text=Using%20phishing%20to%20steal%20NTLM%20hashes&amp;text=When%20the%20Windows%20device%20connects,steal%20the%20NTLM%20authentication%20hashes.'>https://www.bleepingcomputer.com</a>: Hackers steal Windows NTLM authentication hashes in phishing attacks<br/>- <a href='https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview'>https://learn.microsoft.com</a>: NTLM Overview</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14674373-162-leap-2024-riyadh.mp3" length="20812786" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14674373</guid>
    <pubDate>Sat, 09 Mar 2024 22:00:00 +0400</pubDate>
    <itunes:duration>1730</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>161 - Qatar Web Summit</itunes:title>
    <title>161 - Qatar Web Summit</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week I attended Qatar Web Summit. This is a technology and start-up summit held yearly in Doha, Qatar. There were a lot going on and I am lucky to have spent time with the Ken Fee, the CEO of Business Technology Architect shorten as BTA where we talked about security, network optimisation and automation.  The return of LockBit Ransomware-as-a-Service attacks increase in Middle East &amp; Africa region- https://techcrunch.com:&nbs...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week I attended Qatar Web Summit. This is a technology and start-up summit held yearly in Doha, Qatar. There were a lot going on and I am lucky to have spent time with the Ken Fee, the CEO of Business Technology Architect shorten as BTA where we talked about security, network optimisation and automation. </p><ul><li>The return of LockBit </li><li>Ransomware-as-a-Service attacks increase in Middle East &amp; Africa region</li></ul><p>- <a href='https://techcrunch.com/2024/02/26/lockbit-ransomware-takedown-now-what/'>https://techcrunch.com</a>:  Feds hack LockBit, LockBit springs back. Now what?<br/>- <a href='https://www.group-ib.com/resources/research-hub/hi-tech-crime-trends-2023-mea/'>https://www.group-ib.com</a>: Hi-Tech crime trends 2023 MEA<br/>- <a href='https://qatar.websummit.com/'>https://qatar.websummit.com</a>: Qatar Web Summit</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week I attended Qatar Web Summit. This is a technology and start-up summit held yearly in Doha, Qatar. There were a lot going on and I am lucky to have spent time with the Ken Fee, the CEO of Business Technology Architect shorten as BTA where we talked about security, network optimisation and automation. </p><ul><li>The return of LockBit </li><li>Ransomware-as-a-Service attacks increase in Middle East &amp; Africa region</li></ul><p>- <a href='https://techcrunch.com/2024/02/26/lockbit-ransomware-takedown-now-what/'>https://techcrunch.com</a>:  Feds hack LockBit, LockBit springs back. Now what?<br/>- <a href='https://www.group-ib.com/resources/research-hub/hi-tech-crime-trends-2023-mea/'>https://www.group-ib.com</a>: Hi-Tech crime trends 2023 MEA<br/>- <a href='https://qatar.websummit.com/'>https://qatar.websummit.com</a>: Qatar Web Summit</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14630063-161-qatar-web-summit.mp3" length="32510257" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14630063</guid>
    <pubDate>Sat, 02 Mar 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2705</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>160 - The Hidden Risks of Default Configurations - Part 2</itunes:title>
    <title>160 - The Hidden Risks of Default Configurations - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode, we are continuing with part 2 of the risks paused by default configuration. As I said last week, while default config is convenient for initial setup, these  settings are may introduce significant security risks that can leave systems vulnerable to exploitation by malicious actors.  Please listen to the first episode before you listen to this episode. That way you will get the background and full context of the topic....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we are continuing with part 2 of the risks paused by default configuration. As I said last week, while default config is convenient for initial setup, these  settings are may introduce significant security risks that can leave systems vulnerable to exploitation by malicious actors.  Please listen to the first episode before you listen to this episode. That way you will get the background and full context of the topic.<br/><br/></p><ul><li>Well intended Network Traversal Tool is Being Abused for malicious gain. Where have we seen that beofore</li><li>Law enforcement from the UK and others disrupt Lockbit Ransomware group infrastructure</li></ul><p><br/>Having said that, lets turn to a couple of top trending news this week and they are:<br/><br/>- <a href='https://joshua.hu/ssh-snake-ssh-network-traversal-discover-ssh-private-keys-network-graph'>https://joshua.hu</a>: SSH-Snake SSH network traversal discover SSH private keys network graph<br/>- <a href='https://www.nationalcrimeagency.gov.uk/news/nca-leads-international-investigation-targeting-worlds-most-harmful-ransomware-group'>https://www.nationalcrimeagency.gov.uk</a>/ NCA leads international investigation targeting worlds most harmful ransomware group<br/> - <a href='https://www.chainalysis.com/blog/lockbit-takedown-sanctions-february-2024/#:~:text=On%20February%2020%2C%202024%2C%20the,over%20the%20last%20few%20years.'>https://www.chainalysis.com</a>: LockBit takedown sanctions</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode, we are continuing with part 2 of the risks paused by default configuration. As I said last week, while default config is convenient for initial setup, these  settings are may introduce significant security risks that can leave systems vulnerable to exploitation by malicious actors.  Please listen to the first episode before you listen to this episode. That way you will get the background and full context of the topic.<br/><br/></p><ul><li>Well intended Network Traversal Tool is Being Abused for malicious gain. Where have we seen that beofore</li><li>Law enforcement from the UK and others disrupt Lockbit Ransomware group infrastructure</li></ul><p><br/>Having said that, lets turn to a couple of top trending news this week and they are:<br/><br/>- <a href='https://joshua.hu/ssh-snake-ssh-network-traversal-discover-ssh-private-keys-network-graph'>https://joshua.hu</a>: SSH-Snake SSH network traversal discover SSH private keys network graph<br/>- <a href='https://www.nationalcrimeagency.gov.uk/news/nca-leads-international-investigation-targeting-worlds-most-harmful-ransomware-group'>https://www.nationalcrimeagency.gov.uk</a>/ NCA leads international investigation targeting worlds most harmful ransomware group<br/> - <a href='https://www.chainalysis.com/blog/lockbit-takedown-sanctions-february-2024/#:~:text=On%20February%2020%2C%202024%2C%20the,over%20the%20last%20few%20years.'>https://www.chainalysis.com</a>: LockBit takedown sanctions</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14553755-160-the-hidden-risks-of-default-configurations-part-2.mp3" length="32706821" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14553755</guid>
    <pubDate>Sat, 24 Feb 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2721</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>159 - The Hidden Risks of Default Configurations - Part 1</itunes:title>
    <title>159 - The Hidden Risks of Default Configurations - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's interconnected world, default configurations are ubiquitous across various systems and devices, from routers to software applications. While convenient for initial setup, these default settings often harbor significant security risks that can leave systems vulnerable to exploitation by malicious actors. In this episode, we delve into the hidden dangers posed by default configurations, exploring real-world examples and discussing stra...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s interconnected world, default configurations are ubiquitous across various systems and devices, from routers to software applications. While convenient for initial setup, these default settings often harbor significant security risks that can leave systems vulnerable to exploitation by malicious actors. In this episode, we delve into the hidden dangers posed by default configurations, exploring real-world examples and discussing strategies to mitigate these risks effectively. Join us as we uncover the critical importance of securing systems against the perils of default settings.<br/><br/>Before that, lets recap on what is  top of mind on the news front.<br/><br/></p><ul><li>The toothbrush DDOS that never was</li><li>Your favorite browser might have a feature that defends your home network</li></ul><p>- <a href='https://www.forbes.com/sites/daveywinder/2024/02/08/surprising-3-million-hacked-toothbrushes-story-goes-viral-is-it-true/?sh=1e18f8d16147'>https://www.forbes.com</a>: Surprising 3 million hacked toothbrushes story goes viral is it true?<br/>- <a href='https://chromestatus.com/feature/4869685172764672'>https://chromestatus.com</a>: Private Network Access<br/>- <a href='https://owasp.org/Top10/A05_2021-Security_Misconfiguration/'>https://owasp.org</a>: Security Misconfiguration/</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s interconnected world, default configurations are ubiquitous across various systems and devices, from routers to software applications. While convenient for initial setup, these default settings often harbor significant security risks that can leave systems vulnerable to exploitation by malicious actors. In this episode, we delve into the hidden dangers posed by default configurations, exploring real-world examples and discussing strategies to mitigate these risks effectively. Join us as we uncover the critical importance of securing systems against the perils of default settings.<br/><br/>Before that, lets recap on what is  top of mind on the news front.<br/><br/></p><ul><li>The toothbrush DDOS that never was</li><li>Your favorite browser might have a feature that defends your home network</li></ul><p>- <a href='https://www.forbes.com/sites/daveywinder/2024/02/08/surprising-3-million-hacked-toothbrushes-story-goes-viral-is-it-true/?sh=1e18f8d16147'>https://www.forbes.com</a>: Surprising 3 million hacked toothbrushes story goes viral is it true?<br/>- <a href='https://chromestatus.com/feature/4869685172764672'>https://chromestatus.com</a>: Private Network Access<br/>- <a href='https://owasp.org/Top10/A05_2021-Security_Misconfiguration/'>https://owasp.org</a>: Security Misconfiguration/</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14553756-159-the-hidden-risks-of-default-configurations-part-1.mp3" length="26914533" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14553756</guid>
    <pubDate>Sat, 17 Feb 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2239</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>158 - Is quantum computing a threat to cryptography, really? - Part 2</itunes:title>
    <title>158 - Is quantum computing a threat to cryptography, really? - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is the second episode of our two part episode on whether quantum computing is a threat to cryptography really. Make sure you listen to episode 1 first as we laid the foundation on what is coming up in this episode.  As always lets review this week's top trending security news first. CISA and the FBI release Living of the land technique guidancesGoogle's AI assisted with detection- https://www.computer.org: Quantum Computing - https://thequ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the second episode of our two part episode on whether quantum computing is a threat to cryptography really. Make sure you listen to episode 1 first as we laid the foundation on what is coming up in this episode.<br/><br/>As always lets review this week&apos;s top trending security news first.</p><ul><li>CISA and the FBI release Living of the land technique guidances</li><li>Google&apos;s AI assisted with detection</li></ul><p>- <a href='https://www.computer.org/resources/quantum-computing'>https://www.computer.org</a>: Quantum Computing<br/>- <a href='https://thequantuminsider.com/2022/05/16/quantum-research/'>https://thequantuminsider.com</a>: Quantum Research<br/>- <a href='https://cqn-erc.org/about/about-cqn/'>https://cqn-erc.org/about</a>: The Center for Quantum Networks<br/>- <a href='https://www.cisa.gov/sites/default/files/2024-02/Joint-Guidance-Identifying-and-Mitigating-LOTL_V3508c.pdf'>https://www.cisa.gov</a>: Joint Guidance Identifying and Mitigating LOTL<br/>- <a href='http://security.googleblog.com/2024/01/scaling-security-with-ai-from-detection.html'>http://security.googleblog.com</a>: Scaling security with AI from detection<br/>- <a href='https://safety.google/cybersecurity-advancements/saif/'>https://safety.google</a>: Cybersecurity Advancements<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the second episode of our two part episode on whether quantum computing is a threat to cryptography really. Make sure you listen to episode 1 first as we laid the foundation on what is coming up in this episode.<br/><br/>As always lets review this week&apos;s top trending security news first.</p><ul><li>CISA and the FBI release Living of the land technique guidances</li><li>Google&apos;s AI assisted with detection</li></ul><p>- <a href='https://www.computer.org/resources/quantum-computing'>https://www.computer.org</a>: Quantum Computing<br/>- <a href='https://thequantuminsider.com/2022/05/16/quantum-research/'>https://thequantuminsider.com</a>: Quantum Research<br/>- <a href='https://cqn-erc.org/about/about-cqn/'>https://cqn-erc.org/about</a>: The Center for Quantum Networks<br/>- <a href='https://www.cisa.gov/sites/default/files/2024-02/Joint-Guidance-Identifying-and-Mitigating-LOTL_V3508c.pdf'>https://www.cisa.gov</a>: Joint Guidance Identifying and Mitigating LOTL<br/>- <a href='http://security.googleblog.com/2024/01/scaling-security-with-ai-from-detection.html'>http://security.googleblog.com</a>: Scaling security with AI from detection<br/>- <a href='https://safety.google/cybersecurity-advancements/saif/'>https://safety.google</a>: Cybersecurity Advancements<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14494335-158-is-quantum-computing-a-threat-to-cryptography-really-part-2.mp3" length="27246208" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14494335</guid>
    <pubDate>Sat, 10 Feb 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2266</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>157 - Is quantum computing a threat to cryptography, really? - Part 1</itunes:title>
    <title>157 - Is quantum computing a threat to cryptography, really? - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Cryptography are the backbone of privacy since time immemorial. Toda is THE foundational block of the connected world without which the Internet will crumble as we know it. There is a feverish discussions happening and fast improving of a new era in computing - Quantum computing, and it is improving year after year taking us ever closer to question the strength of the existing cryptography. So we asked "Is quantum computing a threat to cryptogr...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Cryptography are the backbone of privacy since time immemorial. Toda is THE foundational block of the connected world without which the Internet will crumble as we know it.<br/>There is a feverish discussions happening and fast improving of a new era in computing - Quantum computing, and it is improving year after year taking us ever closer to question the strength of the existing cryptography. So we asked &quot;Is quantum computing a threat to cryptography, really?&quot;<br/><br/>- <a href='https://blog.cloudflare.com/thanksgiving-2023-security-incident'>https://blog.cloudflare.com</a>: Thanks-Giving 2023 security incident<br/>- <a href='https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical'>https://www.justice.gov</a>: US government disrupts botnet <br/>- <a href='https://www.computer.org/resources/quantum-computing'>https://www.computer.org</a>: Quantum Computing<br/>- <a href='https://thequantuminsider.com/2022/05/16/quantum-research/'>https://thequantuminsider.com</a>: Quantum Research<br/>- <a href='https://cqn-erc.org/about/about-cqn/'>https://cqn-erc.org/about</a>: The Center for Quantum Networks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Cryptography are the backbone of privacy since time immemorial. Toda is THE foundational block of the connected world without which the Internet will crumble as we know it.<br/>There is a feverish discussions happening and fast improving of a new era in computing - Quantum computing, and it is improving year after year taking us ever closer to question the strength of the existing cryptography. So we asked &quot;Is quantum computing a threat to cryptography, really?&quot;<br/><br/>- <a href='https://blog.cloudflare.com/thanksgiving-2023-security-incident'>https://blog.cloudflare.com</a>: Thanks-Giving 2023 security incident<br/>- <a href='https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical'>https://www.justice.gov</a>: US government disrupts botnet <br/>- <a href='https://www.computer.org/resources/quantum-computing'>https://www.computer.org</a>: Quantum Computing<br/>- <a href='https://thequantuminsider.com/2022/05/16/quantum-research/'>https://thequantuminsider.com</a>: Quantum Research<br/>- <a href='https://cqn-erc.org/about/about-cqn/'>https://cqn-erc.org/about</a>: The Center for Quantum Networks</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14458047-157-is-quantum-computing-a-threat-to-cryptography-really-part-1.mp3" length="28774371" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14458047</guid>
    <pubDate>Sat, 03 Feb 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2394</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>156 - The risks of exposing Web UI</itunes:title>
    <title>156 - The risks of exposing Web UI</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  Accessing and managing various applications and services remotely is a daily occurrence for a typical administrator. It is often the fastest way to accomplish a quick task while you are on the move or say something urgent is needed while you are still on your way to your desk. While that is no...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Accessing and managing various applications and services remotely is a daily occurrence for a typical administrator. It is often the fastest way to accomplish a quick task while you are on the move or say something urgent is needed while you are still on your way to your desk. While that is nothing new, we see an uptick on the number of successful attack taking advantage on these exposed administrative interfaces. What is causing the recent increase in Web UI initial access? Well, that is the topic our episode this week.<br/><br/>I am your host Ibrahim Yusuf<br/><br/>Just before we hit the main topic, lets review a couple top of mind recent news:<br/><br/></p><ul><li>Not long ago, Microsoft&apos;s exchange online was breached. They now revealed how this happened.</li><li>UK and US Water Utilities Hit with Cyberattacks</li></ul><p>- <a href='https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/'>https://www.microsoft.com</a>: Midnight Blizzard guidance for responders on nation state-attack<br/>- <a href='https://www.securityweek.com/major-us-uk-water-companies-hit-by-ransomware/'>https://www.securityweek.com</a>: Major UK and US  water companies hit by ransomware<br/><a href='https://www.cisa.gov/resources-tools/resources/water-and-wastewater-sector-incident-response-guide-0'>https://www.cisa.gov</a>: Water and wastewater sector incident response guide </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Accessing and managing various applications and services remotely is a daily occurrence for a typical administrator. It is often the fastest way to accomplish a quick task while you are on the move or say something urgent is needed while you are still on your way to your desk. While that is nothing new, we see an uptick on the number of successful attack taking advantage on these exposed administrative interfaces. What is causing the recent increase in Web UI initial access? Well, that is the topic our episode this week.<br/><br/>I am your host Ibrahim Yusuf<br/><br/>Just before we hit the main topic, lets review a couple top of mind recent news:<br/><br/></p><ul><li>Not long ago, Microsoft&apos;s exchange online was breached. They now revealed how this happened.</li><li>UK and US Water Utilities Hit with Cyberattacks</li></ul><p>- <a href='https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/'>https://www.microsoft.com</a>: Midnight Blizzard guidance for responders on nation state-attack<br/>- <a href='https://www.securityweek.com/major-us-uk-water-companies-hit-by-ransomware/'>https://www.securityweek.com</a>: Major UK and US  water companies hit by ransomware<br/><a href='https://www.cisa.gov/resources-tools/resources/water-and-wastewater-sector-incident-response-guide-0'>https://www.cisa.gov</a>: Water and wastewater sector incident response guide </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14392339-156-the-risks-of-exposing-web-ui.mp3" length="33448757" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14392339</guid>
    <pubDate>Sat, 27 Jan 2024 22:00:00 +0400</pubDate>
    <itunes:duration>2783</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>155 - iVanti&#39;s widespread exploitation</itunes:title>
    <title>155 - iVanti&#39;s widespread exploitation</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! When things go wrong, they go wrong fast. This week will dive into the widespread exploitation on iVanti VPN solution that attracted a lot of attention from both the security community as well as from the bad guys. What went wrong? Stay tuned. Just before we get into iVanti, lets review the other top security news this week. Millions of passwords of top brands such as facebook and others were found for sale.SonicWall API attracts attacks that c...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>When things go wrong, they go wrong fast. This week will dive into the widespread exploitation on iVanti VPN solution that attracted a lot of attention from both the security community as well as from the bad guys. What went wrong? Stay tuned.<br/>Just before we get into iVanti, lets review the other top security news this week.</p><ul><li>Millions of passwords of top brands such as facebook and others were found for sale.</li><li>SonicWall API attracts attacks that can impacts over 170 thousand firewalls.</li></ul><p>- <a href='https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003'>https://psirt.global.sonicwall.com</a>: CVE-2022-22274<br/>- <a href='https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004'>https://psirt.global.sonicwall.com</a>: CVE-2023-0656<br/>- <a href='https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US'>https://forums.ivanti.com</a>: CVE-2023-46805 Authentication Bypass and CVE-2024-21887 Command Injection for Ivanti Connect Secure and Ivanti Policy Secure Gateways<br/>- <a href='https://forums.ivanti.com/s/article/KB44755?language=en_US'>https://forums.ivanti.com</a>: Pulse Connect Secure (PCS) Integrity Assurance<b><br/>- </b><a href='https://www.mandiant.com/resources/blog/suspected-apt-targets-ivanti-zero-day'>https://www.mandiant.com:</a><b> </b> Suspected APT targets Ivanti zeroday<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>When things go wrong, they go wrong fast. This week will dive into the widespread exploitation on iVanti VPN solution that attracted a lot of attention from both the security community as well as from the bad guys. What went wrong? Stay tuned.<br/>Just before we get into iVanti, lets review the other top security news this week.</p><ul><li>Millions of passwords of top brands such as facebook and others were found for sale.</li><li>SonicWall API attracts attacks that can impacts over 170 thousand firewalls.</li></ul><p>- <a href='https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003'>https://psirt.global.sonicwall.com</a>: CVE-2022-22274<br/>- <a href='https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004'>https://psirt.global.sonicwall.com</a>: CVE-2023-0656<br/>- <a href='https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US'>https://forums.ivanti.com</a>: CVE-2023-46805 Authentication Bypass and CVE-2024-21887 Command Injection for Ivanti Connect Secure and Ivanti Policy Secure Gateways<br/>- <a href='https://forums.ivanti.com/s/article/KB44755?language=en_US'>https://forums.ivanti.com</a>: Pulse Connect Secure (PCS) Integrity Assurance<b><br/>- </b><a href='https://www.mandiant.com/resources/blog/suspected-apt-targets-ivanti-zero-day'>https://www.mandiant.com:</a><b> </b> Suspected APT targets Ivanti zeroday<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14344465-155-ivanti-s-widespread-exploitation.mp3" length="30892109" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14344465</guid>
    <pubDate>Sat, 20 Jan 2024 21:00:00 +0400</pubDate>
    <itunes:duration>2570</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>154 - Exfil or DLP - Part 2</itunes:title>
    <title>154 - Exfil or DLP - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! We are continuing demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the  terms Exfil or DLP.  So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here. Make sure you listen to part 1 beforehand.  And as alware before we get into the weeds, lets review the recent top trending news...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We are continuing demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the  terms Exfil or DLP.  So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here.<br/>Make sure you listen to part 1 beforehand.<br/><br/>And as alware before we get into the weeds, lets review the recent top trending news this week. These are</p><ul><li>Babuk variant decryption key made available</li><li>Mandiant X account hacked </li></ul><p>- <a href='https://www.bleepingcomputer.com/news/security/decryptor-for-babuk-ransomware-variant-released-after-hacker-arrested/'>https://www.bleepingcomputer.com</a>:  Decryptor for Babuk ransomware variant released after hacker arrested<br/>- <a href='https://grahamcluley.com/security-firm-mandiant-says-it-didnt-have-2fa-enabled-on-its-hacked-twitter-account/'>https://grahamcluley.com</a>:   Security firm Mandiant says it did not have 2FA enabled on its hacked Twitter account <br/>- <a href='https://www.nomoreransom.org/'>https://www.nomoreransom.org</a>: No-More-Ransom site</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We are continuing demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the  terms Exfil or DLP.  So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here.<br/>Make sure you listen to part 1 beforehand.<br/><br/>And as alware before we get into the weeds, lets review the recent top trending news this week. These are</p><ul><li>Babuk variant decryption key made available</li><li>Mandiant X account hacked </li></ul><p>- <a href='https://www.bleepingcomputer.com/news/security/decryptor-for-babuk-ransomware-variant-released-after-hacker-arrested/'>https://www.bleepingcomputer.com</a>:  Decryptor for Babuk ransomware variant released after hacker arrested<br/>- <a href='https://grahamcluley.com/security-firm-mandiant-says-it-didnt-have-2fa-enabled-on-its-hacked-twitter-account/'>https://grahamcluley.com</a>:   Security firm Mandiant says it did not have 2FA enabled on its hacked Twitter account <br/>- <a href='https://www.nomoreransom.org/'>https://www.nomoreransom.org</a>: No-More-Ransom site</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14316878-154-exfil-or-dlp-part-2.mp3" length="27078104" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14316878</guid>
    <pubDate>Sat, 13 Jan 2024 07:00:00 +0400</pubDate>
    <itunes:duration>2252</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>153 - Exfil or DLP - Part 1</itunes:title>
    <title>153 - Exfil or DLP - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! We will kick off the year with demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the  terms Exfil or DLP.  So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here.  Before we get into the weeds, lets review the recent top trending news this week. These are A new threat abusing t...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We will kick off the year with demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the  terms Exfil or DLP.  So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here.<br/><br/>Before we get into the weeds, lets review the recent top trending news this week. These are</p><ul><li>A new threat abusing the good old SMTP protocol</li><li>We&apos;ll talk about Terrapin and what protocol that is abusing as well.</li></ul><p>- <a href='https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/'>https://sec-consult.com</a>: SMTP Smuggling,  spoofing e-mails worldwide<br/>-  <a href='https://www.postfix.org/smtp-smuggling.html'>https://www.postfix.org</a>: SMTP Smuggling<br/>- <a href='https://arstechnica.com/security/2024/01/millions-still-havent-patched-terrapin-ssh-protocol-vulnerability/'>https://arstechnica.com</a>:  Millions still haven&apos;t patched Terrapin SSH protocol vulnerability<br/>- <a href='https://terrapin-attack.com/'>https://terrapin-attack.com</a>: Terrapin Attack<br/>- <a href='https://attack.mitre.org/'> https://attack.mitre.org</a>: ATT&amp;CK</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We will kick off the year with demystifying a couple of terms that folks new to the realm of cyber security often mix up. Those are the  terms Exfil or DLP.  So by the end of the session you will surely understand where you stand the next time you will hear an Exfil has happened to so and so org or a DLP is require here.<br/><br/>Before we get into the weeds, lets review the recent top trending news this week. These are</p><ul><li>A new threat abusing the good old SMTP protocol</li><li>We&apos;ll talk about Terrapin and what protocol that is abusing as well.</li></ul><p>- <a href='https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/'>https://sec-consult.com</a>: SMTP Smuggling,  spoofing e-mails worldwide<br/>-  <a href='https://www.postfix.org/smtp-smuggling.html'>https://www.postfix.org</a>: SMTP Smuggling<br/>- <a href='https://arstechnica.com/security/2024/01/millions-still-havent-patched-terrapin-ssh-protocol-vulnerability/'>https://arstechnica.com</a>:  Millions still haven&apos;t patched Terrapin SSH protocol vulnerability<br/>- <a href='https://terrapin-attack.com/'>https://terrapin-attack.com</a>: Terrapin Attack<br/>- <a href='https://attack.mitre.org/'> https://attack.mitre.org</a>: ATT&amp;CK</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14264216-153-exfil-or-dlp-part-1.mp3" length="29375208" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14264216</guid>
    <pubDate>Sat, 06 Jan 2024 23:00:00 +0400</pubDate>
    <itunes:duration>2444</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>152 - Recap of most popular episodes of 2023</itunes:title>
    <title>152 - Recap of most popular episodes of 2023</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.  Well 2023 came and is is now gone, in this final episode we are unwinding the tape to go back to our most popular episodes. If you ever wondered hey what are the most listened to episode. This is the answer. I am sure you will find them beneficial as our listeners did. We won't cover the ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.<br/><br/>Well 2023 came and is is now gone, in this final episode we are unwinding the tape to go back to our most popular episodes. If you ever wondered hey what are the most listened to episode. This is the answer. I am sure you will find them beneficial as our listeners did.<br/>We won&apos;t cover the latest news this time to give room to the content and it is mostly quiet this time of year and nothing has flared up like some recent years.<br/><br/>Enjoy the recap and the year end!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.<br/><br/>Well 2023 came and is is now gone, in this final episode we are unwinding the tape to go back to our most popular episodes. If you ever wondered hey what are the most listened to episode. This is the answer. I am sure you will find them beneficial as our listeners did.<br/>We won&apos;t cover the latest news this time to give room to the content and it is mostly quiet this time of year and nothing has flared up like some recent years.<br/><br/>Enjoy the recap and the year end!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14233450-152-recap-of-most-popular-episodes-of-2023.mp3" length="73953097" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14233450</guid>
    <pubDate>Sat, 30 Dec 2023 23:00:00 +0400</pubDate>
    <itunes:duration>6159</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>151 - Cyber Security Review Of 2023</itunes:title>
    <title>151 - Cyber Security Review Of 2023</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.  In our penultimate episode, we will review the twist and turn of 2023. We will go over the trend that stood out the most and both the trends and players behind them throughout he course of year.  Before that, lets review the top security news of this past week: Chrome now scans for compro...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.<br/><br/>In our penultimate episode, we will review the twist and turn of 2023. We will go over the trend that stood out the most and both the trends and players behind them throughout he course of year.<br/><br/>Before that, lets review the top security news of this past week:</p><ul><li>Chrome now scans for compromised password, finally!</li><li>International authorities disrupts a major adversary infrastructure</li></ul><p>- <a href='https://blog.google/products/chrome/google-chrome-december-2023-update/'>https://blog.google</a>: New performance and safety features are coming to Chrome<br/>- <a href='https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant'>https://www.justice.gov</a>: Justice Department disrupts prolific ALPHV/Backcat ransomware variant</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain English.<br/><br/>In our penultimate episode, we will review the twist and turn of 2023. We will go over the trend that stood out the most and both the trends and players behind them throughout he course of year.<br/><br/>Before that, lets review the top security news of this past week:</p><ul><li>Chrome now scans for compromised password, finally!</li><li>International authorities disrupts a major adversary infrastructure</li></ul><p>- <a href='https://blog.google/products/chrome/google-chrome-december-2023-update/'>https://blog.google</a>: New performance and safety features are coming to Chrome<br/>- <a href='https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant'>https://www.justice.gov</a>: Justice Department disrupts prolific ALPHV/Backcat ransomware variant</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14204488-151-cyber-security-review-of-2023.mp3" length="34344968" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14204488</guid>
    <pubDate>Sat, 23 Dec 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2858</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>150 - Supply Chain Security</itunes:title>
    <title>150 - Supply Chain Security</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Digital inter-connectivity define our era.  One of the primary challenges facing supply chain cyber security is the expanding attack surface.  In this week's episode we will turn to Supply Chain Security, how attackers carry out such attacks. We will also look at previous examples and what mitigations can be mounted to prevent these do not happen again.  But before that and as always ahead of the main topic we stop and reflect on the ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Digital inter-connectivity define our era.  One of the primary challenges facing supply chain cyber security is the expanding attack surface. <br/>In this week&apos;s episode we will turn to Supply Chain Security, how attackers carry out such attacks. We will also look at previous examples and what mitigations can be mounted to prevent these do not happen again.<br/><br/>But before that and as always ahead of the main topic we stop and reflect on the trending news and this week we have two  notable  security pieces  including:</p><ul><li>CISA urges to get rid of default passwords</li><li>Microsoft&apos;s December 2023 Patch Tuesday</li></ul><p>- <a href='https://www.cisa.gov/news-events/alerts/2023/12/15/cisa-secure-design-alert-urges-manufacturers-eliminate-default-passwords'>https://www.cisa.gov</a>: CISA secure design alert urges manufacturers eliminate default passwords<br/>- <a href='https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-manufacturers-can-protect-customers-eliminating-default-passwords'>https://www.cisa.gov</a>: Secure Design alert how manufacturers can protect customers eliminating default passwords<br/>- <a href='https://www.cisa.gov/resources-tools/resources/secure-by-design'>https://www.cisa.gov</a>: Secure by design<br/>- <a href='https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec'>https://msrc.microsoft.com</a>:  Release Note 2023 Dec<br/>- <a href='https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480'>https://isc.sans.edu/diary</a>:Microsoft Patch Tuesday December 2023</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Digital inter-connectivity define our era.  One of the primary challenges facing supply chain cyber security is the expanding attack surface. <br/>In this week&apos;s episode we will turn to Supply Chain Security, how attackers carry out such attacks. We will also look at previous examples and what mitigations can be mounted to prevent these do not happen again.<br/><br/>But before that and as always ahead of the main topic we stop and reflect on the trending news and this week we have two  notable  security pieces  including:</p><ul><li>CISA urges to get rid of default passwords</li><li>Microsoft&apos;s December 2023 Patch Tuesday</li></ul><p>- <a href='https://www.cisa.gov/news-events/alerts/2023/12/15/cisa-secure-design-alert-urges-manufacturers-eliminate-default-passwords'>https://www.cisa.gov</a>: CISA secure design alert urges manufacturers eliminate default passwords<br/>- <a href='https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-manufacturers-can-protect-customers-eliminating-default-passwords'>https://www.cisa.gov</a>: Secure Design alert how manufacturers can protect customers eliminating default passwords<br/>- <a href='https://www.cisa.gov/resources-tools/resources/secure-by-design'>https://www.cisa.gov</a>: Secure by design<br/>- <a href='https://msrc.microsoft.com/update-guide/releaseNote/2023-Dec'>https://msrc.microsoft.com</a>:  Release Note 2023 Dec<br/>- <a href='https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480'>https://isc.sans.edu/diary</a>:Microsoft Patch Tuesday December 2023</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14172746-150-supply-chain-security.mp3" length="31425298" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14172746</guid>
    <pubDate>Sat, 16 Dec 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2615</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>149 - Be cyber vigilant this holiday</itunes:title>
    <title>149 - Be cyber vigilant this holiday</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! The holiday season is when most of us let our guard down. For the cyber criminal though, it is their hunting season.  In this episode we will give you practical advise on how to stay one step ahead of the miscreants and avoid getting their hands on your sensitive data or cash or both.  To get started, lets review top trending security news this: Privilege elevation exploits used in over 50% of insider attacksNew Flaws in Fingerprint Sensor...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The holiday season is when most of us let our guard down. For the cyber criminal though, it is their hunting season. <br/>In this episode we will give you practical advise on how to stay one step ahead of the miscreants and avoid getting their hands on your sensitive data or cash or both.<br/><br/>To get started, lets review top trending security news this:</p><ul><li>Privilege elevation exploits used in over 50% of insider attacks</li><li>New Flaws in Fingerprint Sensors Let Attackers Bypass Login</li></ul><p>- <a href='https://www.crowdstrike.com/blog/how-malicious-insiders-use-known-vulnerabilities-against-organizations/'>https://www.crowdstrike.com</a>: How malicious insiders use known vulnerabilities against organizations<br/>- <a href='https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/'>https://blackwinghq.com</a>: A touch of pwn part<br/><a href='https://blog.talosintelligence.com/threat-source-newsletter-dec-7-2023/'>https://blog.talosintelligence.com</a>: Cybersecurity considerations to have when shopping for holiday gifts</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The holiday season is when most of us let our guard down. For the cyber criminal though, it is their hunting season. <br/>In this episode we will give you practical advise on how to stay one step ahead of the miscreants and avoid getting their hands on your sensitive data or cash or both.<br/><br/>To get started, lets review top trending security news this:</p><ul><li>Privilege elevation exploits used in over 50% of insider attacks</li><li>New Flaws in Fingerprint Sensors Let Attackers Bypass Login</li></ul><p>- <a href='https://www.crowdstrike.com/blog/how-malicious-insiders-use-known-vulnerabilities-against-organizations/'>https://www.crowdstrike.com</a>: How malicious insiders use known vulnerabilities against organizations<br/>- <a href='https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/'>https://blackwinghq.com</a>: A touch of pwn part<br/><a href='https://blog.talosintelligence.com/threat-source-newsletter-dec-7-2023/'>https://blog.talosintelligence.com</a>: Cybersecurity considerations to have when shopping for holiday gifts</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14119348-149-be-cyber-vigilant-this-holiday.mp3" length="33102691" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14119348</guid>
    <pubDate>Sat, 09 Dec 2023 16:00:00 +0400</pubDate>
    <itunes:duration>2754</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>148 - What is the Dark Web?</itunes:title>
    <title>148 - What is the Dark Web?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In episode 148 we look inside the mysterious world of the Dark Web. The Dark Web is a hidden area of the internet that is often obscured by mystery and intrigue to many, and it is unlike standard search engines and browsing destination. I will try to deconstruct this covert network and make you aware of what makes it different from the surface web and how it functions. By doing so, we will shed light on its importance and the consequences it be...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In episode 148 we look inside the mysterious world of the Dark Web. The Dark Web is a hidden area of the internet that is often obscured by mystery and intrigue to many, and it is unlike standard search engines and browsing destination. I will try to deconstruct this covert network and make you aware of what makes it different from the surface web and how it functions. By doing so, we will shed light on its importance and the consequences it bears for today&apos;s digital world.<br/><br/></p><ul><li>Exploit for critical Windows defender by-pass goes public</li><li>Memory Tagging Extension (MTE) technology by google and partners</li></ul><p><br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36025'>https://msrc.microsoft.com</a>: Windows SmartScreen Security Feature Bypass Vulnerability<br/>-<a href=' https://nvd.nist.gov/vuln/detail/CVE-2023-36025'> https://nvd.nist.gov</a>: CVE-2023-36025 details<br/>- <a href=' https://security.googleblog.com/2023/11/mte-promising-path-forward-for-memory.html?m=1'>https://security.googleblog.com</a>: MTE - The promising path forward for memory safety<br/>- <a href='https://blog.talosintelligence.com/what-is-the-dark-web/#:~:text=The%20dark%20web%20is%20intentionally,good%2C%20but%20criminals%20abuse%20them.'>https://blog.talosintelligence.com</a>: What is the Dark Web<br/>- <a href='https://en.wikipedia.org/wiki/Dark_web'>https://en.wikipedia.org</a>: The Dark Web</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In episode 148 we look inside the mysterious world of the Dark Web. The Dark Web is a hidden area of the internet that is often obscured by mystery and intrigue to many, and it is unlike standard search engines and browsing destination. I will try to deconstruct this covert network and make you aware of what makes it different from the surface web and how it functions. By doing so, we will shed light on its importance and the consequences it bears for today&apos;s digital world.<br/><br/></p><ul><li>Exploit for critical Windows defender by-pass goes public</li><li>Memory Tagging Extension (MTE) technology by google and partners</li></ul><p><br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36025'>https://msrc.microsoft.com</a>: Windows SmartScreen Security Feature Bypass Vulnerability<br/>-<a href=' https://nvd.nist.gov/vuln/detail/CVE-2023-36025'> https://nvd.nist.gov</a>: CVE-2023-36025 details<br/>- <a href=' https://security.googleblog.com/2023/11/mte-promising-path-forward-for-memory.html?m=1'>https://security.googleblog.com</a>: MTE - The promising path forward for memory safety<br/>- <a href='https://blog.talosintelligence.com/what-is-the-dark-web/#:~:text=The%20dark%20web%20is%20intentionally,good%2C%20but%20criminals%20abuse%20them.'>https://blog.talosintelligence.com</a>: What is the Dark Web<br/>- <a href='https://en.wikipedia.org/wiki/Dark_web'>https://en.wikipedia.org</a>: The Dark Web</p><p><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14090510-148-what-is-the-dark-web.mp3" length="35017657" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-14090510</guid>
    <pubDate>Sat, 02 Dec 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2914</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>147 - Web shells - Understanding Their Role in Cyber Attacks</itunes:title>
    <title>147 - Web shells - Understanding Their Role in Cyber Attacks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! One of the go tools for attackers are Web shells. In this episode we will explore what these are, their background, how they are used and how you can avoid be turned against you. These deceptive tools bring immense power to the hands of hackers, acting as covert entry door to infiltrate and control the machines that power the Internet, web servers.  Before we get into that, lets review top of mind security news. Europe's Network Information Sec...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>One of the go tools for attackers are Web shells. In this episode we will explore what these are, their background, how they are used and how you can avoid be turned against you.<br/>These deceptive tools bring immense power to the hands of hackers, acting as covert entry door to infiltrate and control the machines that power the Internet, web servers.<br/><br/>Before we get into that, lets review top of mind security news.</p><ul><li>Europe&apos;s Network Information Security Directives revision 2</li><li>Critical bug in OwnCloud file sharing</li></ul><p>- <a href='https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new/nis-visualtool'>https://www.enisa.europa.eu</a>: NIS  visual tool<br/>- <a href='https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new'>https://www.enisa.europa.eu</a>:New NIS directive<br/><a href='https://www.bleepingcomputer.com/news/security/critical-bug-in-owncloud-file-sharing-app-exposes-admin-passwords/'>https://www.bleepingcomputer.com</a>: Critical bug in OwnCloud file sharing app exposes admin passwords <br/>-<a href='https://blog.talosintelligence.com/what-is-a-web-shell/'> https://blog.talosintelligence.com</a>: What is a web shell?<br/>- <a href='https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/2159419/detect-prevent-cyber-attackers-from-exploiting-web-servers-via-web-shell-malware/'>https://www.nsa.gov</a>: Detect prevent cyber attackers from exploiting web servers via web shell malware<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>One of the go tools for attackers are Web shells. In this episode we will explore what these are, their background, how they are used and how you can avoid be turned against you.<br/>These deceptive tools bring immense power to the hands of hackers, acting as covert entry door to infiltrate and control the machines that power the Internet, web servers.<br/><br/>Before we get into that, lets review top of mind security news.</p><ul><li>Europe&apos;s Network Information Security Directives revision 2</li><li>Critical bug in OwnCloud file sharing</li></ul><p>- <a href='https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new/nis-visualtool'>https://www.enisa.europa.eu</a>: NIS  visual tool<br/>- <a href='https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new'>https://www.enisa.europa.eu</a>:New NIS directive<br/><a href='https://www.bleepingcomputer.com/news/security/critical-bug-in-owncloud-file-sharing-app-exposes-admin-passwords/'>https://www.bleepingcomputer.com</a>: Critical bug in OwnCloud file sharing app exposes admin passwords <br/>-<a href='https://blog.talosintelligence.com/what-is-a-web-shell/'> https://blog.talosintelligence.com</a>: What is a web shell?<br/>- <a href='https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/2159419/detect-prevent-cyber-attackers-from-exploiting-web-servers-via-web-shell-malware/'>https://www.nsa.gov</a>: Detect prevent cyber attackers from exploiting web servers via web shell malware<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14034705-147-web-shells-understanding-their-role-in-cyber-attacks.mp3" length="29592531" type="audio/mpeg" />
    <link>https://yusufonsecurity.com</link>
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14034705</guid>
    <pubDate>Sat, 25 Nov 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2462</itunes:duration>
    <itunes:keywords>yusufonsecurity.com; ibrahimyusuf</itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>146 - Symbolic Language in cyber security</itunes:title>
    <title>146 - Symbolic Language in cyber security</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! During Gitex Global in Dubai I sat down with the leaders and founders of Source Technology an organisation based in Swizerland that developed a tool called Source Security. This is ...quote... "technology to integrate behavioral analytics with Symbolic Language that can significantly enhance cybersecurity by providing a deeper understanding of user actions, intentions, emotions, and potential threats.  It also adds a human-centric dimension to ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>During Gitex Global in Dubai I sat down with the leaders and founders of Source Technology an organisation based in Swizerland that developed a tool called Source Security. This is ...quote... &quot;technology to integrate behavioral analytics with Symbolic Language that can significantly enhance cybersecurity by providing a deeper understanding of user actions, intentions, emotions, and potential threats.<br/><br/>It also adds a human-centric dimension to threat detection and prevention. It enables organizations to not only analyze patterns of behavior but also understand the emotional context, making it a powerful tool for staying ahead of cyber threats and protecting sensitive data.&quot; unquote.<br/><br/></p><ul><li>FBI and CISA publish a detailed report on Scattered-Spider</li><li>Saudi Arabi arms public sector with Google Cloud services</li></ul><p>- <a href='https://therecord.media/cisa-fbi-warn-of-scattered-spider-cybercrime-group'>https://therecord.media</a>: CISA-FBI warn of Scattered-Spider cybercrime group<br/>- <a href='https://www.intelligentciso.com/2023/11/15/google-cloud-and-haboob-partner-to-strengthen-saudi-arabias-nationwide-cyberdefence/'>https://www.intelligentciso.com</a>: Google-Cloud and Haboob partner to strengthen Saudi Arabias nationwide cyberdefence<br/>- <a href='https://sctfoundation.org/pages/what-is-symbolic-language%C2%AE'>https://sctfoundation.org</a>: What is Symbolic Language?<br/>-<a href='https://sctfoundation.org/products/source-security'> https://sctfoundation.org</a>: Source security</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>During Gitex Global in Dubai I sat down with the leaders and founders of Source Technology an organisation based in Swizerland that developed a tool called Source Security. This is ...quote... &quot;technology to integrate behavioral analytics with Symbolic Language that can significantly enhance cybersecurity by providing a deeper understanding of user actions, intentions, emotions, and potential threats.<br/><br/>It also adds a human-centric dimension to threat detection and prevention. It enables organizations to not only analyze patterns of behavior but also understand the emotional context, making it a powerful tool for staying ahead of cyber threats and protecting sensitive data.&quot; unquote.<br/><br/></p><ul><li>FBI and CISA publish a detailed report on Scattered-Spider</li><li>Saudi Arabi arms public sector with Google Cloud services</li></ul><p>- <a href='https://therecord.media/cisa-fbi-warn-of-scattered-spider-cybercrime-group'>https://therecord.media</a>: CISA-FBI warn of Scattered-Spider cybercrime group<br/>- <a href='https://www.intelligentciso.com/2023/11/15/google-cloud-and-haboob-partner-to-strengthen-saudi-arabias-nationwide-cyberdefence/'>https://www.intelligentciso.com</a>: Google-Cloud and Haboob partner to strengthen Saudi Arabias nationwide cyberdefence<br/>- <a href='https://sctfoundation.org/pages/what-is-symbolic-language%C2%AE'>https://sctfoundation.org</a>: What is Symbolic Language?<br/>-<a href='https://sctfoundation.org/products/source-security'> https://sctfoundation.org</a>: Source security</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/14027008-146-symbolic-language-in-cyber-security.mp3" length="25606758" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-14027008</guid>
    <pubDate>Sat, 18 Nov 2023 21:00:00 +0400</pubDate>
    <itunes:duration>2130</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>145 - Indication of compromise best practice</itunes:title>
    <title>145 - Indication of compromise best practice</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  I'm  your your host Ibrahim Yusuf  In today's episode, we're shedding light on a critical yet often overlooked aspect of cybersecurity - Indications of Compromise, also known as IOCs. These vital pieces of forensic data can be the canary in the coal mine, alerting us to potential net...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I&apos;m  your your host Ibrahim Yusuf<br/><br/>In today&apos;s episode, we&apos;re shedding light on a critical yet often overlooked aspect of cybersecurity - Indications of Compromise, also known as IOCs. These vital pieces of forensic data can be the canary in the coal mine, alerting us to potential network intrusions before they wreak havoc on our systems.<br/><br/>We&apos;ll discuss what IOCs are, why they are essential, and how you can use them proactively to enhance your cybersecurity strategy.<br/><br/>But first, a quick look on what is top of mind in the security news this week.</p><ul><li>NCSC releases more details designed to help organisations how to migrate to post-quantum crypto</li><li>The source of Okta breach....no price for guessing</li></ul><p>- <a href='https://www.ncsc.gov.uk/whitepaper/next-steps-preparing-for-post-quantum-cryptography'>https://www.ncsc.gov.uk</a>: Next steps preparing for post quantum cryptography<br/>- <a href='https://www.linkedin.com/pulse/okta-data-breach-lesson-browser-security-sharpits-b9qae/?trk=article-ssr-frontend-pulse_more-articles_related-content-card'>https://www.linkedin.com</a>: Okta data breach lesson browser security <br/>- <a href='https://www.scmagazine.com/news/okta-breach-linked-to-workers-personal-google-account'>https://www.scmagazine.com</a>: Okta breach linked to workers personal google account<br/>- <a href='https://www.attackiq.com/glossary/pyramid-of-pain/#:~:text=As%20outlined%20by%20David%20J,files%20involved%20in%20an%20intrusion'>https://www.attackiq.com</a>: Pyramid of pain<br/>- <a href='https://github.com/Cisco-Talos/IOCs'>https://github.com/Cisco-Talos</a>: IOCs<br/>- <a href='https://sec.cloudapps.cisco.com/security/center/resources/iocs.html#:~:text=This%20document%20provides%20standardized%20content,Impact%20Metric%20Categories%20outlined%20below.'>https://sec.cloudapps.cisco.com</a>: Indication Of Compromise Reference Guide<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome back and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I&apos;m  your your host Ibrahim Yusuf<br/><br/>In today&apos;s episode, we&apos;re shedding light on a critical yet often overlooked aspect of cybersecurity - Indications of Compromise, also known as IOCs. These vital pieces of forensic data can be the canary in the coal mine, alerting us to potential network intrusions before they wreak havoc on our systems.<br/><br/>We&apos;ll discuss what IOCs are, why they are essential, and how you can use them proactively to enhance your cybersecurity strategy.<br/><br/>But first, a quick look on what is top of mind in the security news this week.</p><ul><li>NCSC releases more details designed to help organisations how to migrate to post-quantum crypto</li><li>The source of Okta breach....no price for guessing</li></ul><p>- <a href='https://www.ncsc.gov.uk/whitepaper/next-steps-preparing-for-post-quantum-cryptography'>https://www.ncsc.gov.uk</a>: Next steps preparing for post quantum cryptography<br/>- <a href='https://www.linkedin.com/pulse/okta-data-breach-lesson-browser-security-sharpits-b9qae/?trk=article-ssr-frontend-pulse_more-articles_related-content-card'>https://www.linkedin.com</a>: Okta data breach lesson browser security <br/>- <a href='https://www.scmagazine.com/news/okta-breach-linked-to-workers-personal-google-account'>https://www.scmagazine.com</a>: Okta breach linked to workers personal google account<br/>- <a href='https://www.attackiq.com/glossary/pyramid-of-pain/#:~:text=As%20outlined%20by%20David%20J,files%20involved%20in%20an%20intrusion'>https://www.attackiq.com</a>: Pyramid of pain<br/>- <a href='https://github.com/Cisco-Talos/IOCs'>https://github.com/Cisco-Talos</a>: IOCs<br/>- <a href='https://sec.cloudapps.cisco.com/security/center/resources/iocs.html#:~:text=This%20document%20provides%20standardized%20content,Impact%20Metric%20Categories%20outlined%20below.'>https://sec.cloudapps.cisco.com</a>: Indication Of Compromise Reference Guide<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13954824-145-indication-of-compromise-best-practice.mp3" length="36928415" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13954824</guid>
    <pubDate>Sat, 11 Nov 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13954824/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:34" title="NCSC quantum crypto guide" />
  <psc:chapter start="17:06" title="The source of Okta breach" />
  <psc:chapter start="25:05" title="IOC best practice" />
</psc:chapters>
    <itunes:duration>3073</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>144 - The New Common Vulnerability Scoring System </itunes:title>
    <title>144 - The New Common Vulnerability Scoring System </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today, we're diving into the world of cybersecurity with an eye to vulnerability scoring system. C We've got a topic that's on the mind of anyone with interest in risk management, one that's of paramount importance to anyone concerned with the safety and integrity of their assets. That's right, today we're talking about the brand-new version of the Common Vulnerability Scoring System, or CVSS v4!  The cybersecurity landscape is constantly evolv...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re diving into the world of cybersecurity with an eye to vulnerability scoring system. C We&apos;ve got a topic that&apos;s on the mind of anyone with interest in risk management, one that&apos;s of paramount importance to anyone concerned with the safety and integrity of their assets. That&apos;s right, today we&apos;re talking about the brand-new version of the Common Vulnerability Scoring System, or CVSS v4!<br/><br/>The cybersecurity landscape is constantly evolving, and as threats become more sophisticated, it&apos;s essential for the tools and methodologies we use to keep pace. In this episode, we&apos;ll explore the latest iteration of CVSS, its key updates, and what it means for security professionals, organizations. Whether you&apos;re a seasoned cybersecurity expert or just someone with a keen interest in staying safe online, you won&apos;t want to miss this.</p><ul><li>Boeing confirms system compromise alerting customers</li><li>Arid-Viper mobile spyware</li></ul><p>- <a href='https://techcrunch.com/2023/11/02/boeing-cyber-incident-ransomware-gang-claims-data-theft/?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAANBOKaayPP4wAxiU8634tRGt3OtvpT05Lfrll4ZKdrcl6shFnqItt5ZiqWig0-hGUKc2zfCNNJwgnkeW_zLTyeDQG0RFHoHJwH6lSz73rAL0aFQEEpeytqOE3WLORiOsmpKfWUlofQujheT8l8lVRic9U_hLwuKLXav0nbDkHVVL'>https://techcrunch.com</a>Boeing cyber incident ransomware gang claims data theft<br/>- <a href='https://www.darkreading.com/endpoint/boeing-confirms-system-compromise-alerting-customers'>https://www.darkreading.com</a>: Boeing confirms system compromise alerting customers<br/>- <a href='https://blog.talosintelligence.com/arid-viper-mobile-spyware/'>https://blog.talosintelligence.com</a>: Arid-Viper mobile spyware <br/>- <a href='https://www.first.org/cvss/v4.0/specification-document'>https://www.first.org</a>: CVSS v4 specification document</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today, we&apos;re diving into the world of cybersecurity with an eye to vulnerability scoring system. C We&apos;ve got a topic that&apos;s on the mind of anyone with interest in risk management, one that&apos;s of paramount importance to anyone concerned with the safety and integrity of their assets. That&apos;s right, today we&apos;re talking about the brand-new version of the Common Vulnerability Scoring System, or CVSS v4!<br/><br/>The cybersecurity landscape is constantly evolving, and as threats become more sophisticated, it&apos;s essential for the tools and methodologies we use to keep pace. In this episode, we&apos;ll explore the latest iteration of CVSS, its key updates, and what it means for security professionals, organizations. Whether you&apos;re a seasoned cybersecurity expert or just someone with a keen interest in staying safe online, you won&apos;t want to miss this.</p><ul><li>Boeing confirms system compromise alerting customers</li><li>Arid-Viper mobile spyware</li></ul><p>- <a href='https://techcrunch.com/2023/11/02/boeing-cyber-incident-ransomware-gang-claims-data-theft/?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAANBOKaayPP4wAxiU8634tRGt3OtvpT05Lfrll4ZKdrcl6shFnqItt5ZiqWig0-hGUKc2zfCNNJwgnkeW_zLTyeDQG0RFHoHJwH6lSz73rAL0aFQEEpeytqOE3WLORiOsmpKfWUlofQujheT8l8lVRic9U_hLwuKLXav0nbDkHVVL'>https://techcrunch.com</a>Boeing cyber incident ransomware gang claims data theft<br/>- <a href='https://www.darkreading.com/endpoint/boeing-confirms-system-compromise-alerting-customers'>https://www.darkreading.com</a>: Boeing confirms system compromise alerting customers<br/>- <a href='https://blog.talosintelligence.com/arid-viper-mobile-spyware/'>https://blog.talosintelligence.com</a>: Arid-Viper mobile spyware <br/>- <a href='https://www.first.org/cvss/v4.0/specification-document'>https://www.first.org</a>: CVSS v4 specification document</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13917881-144-the-new-common-vulnerability-scoring-system.mp3" length="32174332" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13917881</guid>
    <pubDate>Sat, 04 Nov 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13917881/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="2:01" title="Boeing Cybersecurity breach" />
  <psc:chapter start="8:50" title="Arid Viper Mobile Spyware" />
  <psc:chapter start="15:35" title="CSS v4" />
</psc:chapters>
    <itunes:duration>2677</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>143 - Smart Homes - Discussion with Floris Grandvarlet EMEA Innovation and Sustainability CTO at Cisco</itunes:title>
    <title>143 - Smart Homes - Discussion with Floris Grandvarlet EMEA Innovation and Sustainability CTO at Cisco</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! And in today's episode we  ponder over how technology continues to reach every aspect of our lives and now the places we call our castles...our homes.  The other week at GITEX I also sat down with Floris Grandvarlet, EMEA Innovation, Sustainability, CTO at CISCO. More that later, but first..... we look at at recent breach and mishaps that left multiple giants in the tech and security industry affected. CCleaner compromise through MOVE...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>And in today&apos;s episode we  ponder over how technology continues to reach every aspect of our lives and now the places we call our castles...our homes. <br/>The other week at GITEX I also sat down with Floris Grandvarlet, EMEA Innovation, Sustainability, CTO at CISCO. More that later, but first..... we look at at recent breach and mishaps that left multiple giants in the tech and security industry affected.</p><ul><li>CCleaner compromise through MOVEit</li><li>Cisco IOS X Web UI Vulnerabilities</li></ul><p>- <a href='https://cybernews.com/news/ccleaner-confirms-data-breach/'>https://cybernews.com</a>: Ccleaner confirms data breach<br/>- <a href='https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z'>https://sec.cloudapps.cisco.com</a>: Cisco Security Advisory<br/>- <a href='https://www.cisco.com/c/en/us/solutions/smart-building/what-is-a-smart-building.html'>https://www.cisco.com</a>: What is a smart building<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>And in today&apos;s episode we  ponder over how technology continues to reach every aspect of our lives and now the places we call our castles...our homes. <br/>The other week at GITEX I also sat down with Floris Grandvarlet, EMEA Innovation, Sustainability, CTO at CISCO. More that later, but first..... we look at at recent breach and mishaps that left multiple giants in the tech and security industry affected.</p><ul><li>CCleaner compromise through MOVEit</li><li>Cisco IOS X Web UI Vulnerabilities</li></ul><p>- <a href='https://cybernews.com/news/ccleaner-confirms-data-breach/'>https://cybernews.com</a>: Ccleaner confirms data breach<br/>- <a href='https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z'>https://sec.cloudapps.cisco.com</a>: Cisco Security Advisory<br/>- <a href='https://www.cisco.com/c/en/us/solutions/smart-building/what-is-a-smart-building.html'>https://www.cisco.com</a>: What is a smart building<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13871531-143-smart-homes-discussion-with-floris-grandvarlet-emea-innovation-and-sustainability-cto-at-cisco.mp3" length="21467975" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13871531</guid>
    <pubDate>Sat, 28 Oct 2023 23:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13871531/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:07" title="CCleaner compromise through MOVEit" />
  <psc:chapter start="8:26" title="Cisco IOS Web UI Vulnerabilities" />
  <psc:chapter start="14:35" title="Smart Homes with Floris Grandvarlet" />
</psc:chapters>
    <itunes:duration>1785</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>142 - Discussion With Eric Vedel Directory CISO Advisory at Cisco</itunes:title>
    <title>142 - Discussion With Eric Vedel Directory CISO Advisory at Cisco</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This was GITEX 2023 Dubai week. GITEX, short for the "Gulf Information Technology Exhibition," is a prominent annual technology event and trade show held in Dubai, United Arab Emirates. It is one of the largest and most influential technology exhibitions in the Middle East, attracting participants and visitors from around the world.  At GITEX I sat down with Eric Vedel Directory of CISO Advisory at Cisco. It is an insightful conversation that y...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This was GITEX 2023 Dubai week. GITEX, short for the &quot;Gulf Information Technology Exhibition,&quot; is a prominent annual technology event and trade show held in Dubai, United Arab Emirates. It is one of the largest and most influential technology exhibitions in the Middle East, attracting participants and visitors from around the world.<br/><br/>At GITEX I sat down with Eric Vedel Directory of CISO Advisory at Cisco. It is an insightful conversation that you will find practical as it it is filled much needed advise.<br/><br/>Having said that, lets have a look at the top security news this week:</p><ul><li>Critical RCE flaws found in SolarWinds access audit solution</li><li>Advancing Cybersecurity: Google&apos;s AI-Powered Access Control System</li></ul><p>- <a href='https://www.gitex.com/'>https://www.gitex.com</a>: GITEX 2023<br/>- <a href='https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/'>https://www.bleepingcomputer.com</a>: Critical RCE flaws found in Solarwinds access audit solution<br/>- <a href='https://security.googleblog.com/2023/10/scaling-beyondcorp-with-ai-assisted.html#:~:text=In%20July%202023%2C%20four%20Googlers,with%20Access%20Control%20Lists%20%2D%20SpeakACL.'>https://security.googleblog.com</a>: SpeakACL</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This was GITEX 2023 Dubai week. GITEX, short for the &quot;Gulf Information Technology Exhibition,&quot; is a prominent annual technology event and trade show held in Dubai, United Arab Emirates. It is one of the largest and most influential technology exhibitions in the Middle East, attracting participants and visitors from around the world.<br/><br/>At GITEX I sat down with Eric Vedel Directory of CISO Advisory at Cisco. It is an insightful conversation that you will find practical as it it is filled much needed advise.<br/><br/>Having said that, lets have a look at the top security news this week:</p><ul><li>Critical RCE flaws found in SolarWinds access audit solution</li><li>Advancing Cybersecurity: Google&apos;s AI-Powered Access Control System</li></ul><p>- <a href='https://www.gitex.com/'>https://www.gitex.com</a>: GITEX 2023<br/>- <a href='https://www.bleepingcomputer.com/news/security/critical-rce-flaws-found-in-solarwinds-access-audit-solution/'>https://www.bleepingcomputer.com</a>: Critical RCE flaws found in Solarwinds access audit solution<br/>- <a href='https://security.googleblog.com/2023/10/scaling-beyondcorp-with-ai-assisted.html#:~:text=In%20July%202023%2C%20four%20Googlers,with%20Access%20Control%20Lists%20%2D%20SpeakACL.'>https://security.googleblog.com</a>: SpeakACL</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13834488-142-discussion-with-eric-vedel-directory-ciso-advisory-at-cisco.mp3" length="22525313" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13834488</guid>
    <pubDate>Sat, 21 Oct 2023 10:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13834488/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:36" title="Critical RCE flaws found in SolarWinds " />
  <psc:chapter start="9:25" title=" Google&#39;s AI-Powered Access Control System" />
  <psc:chapter start="15:22" title=" Discussion With Eric Vedel Directory CISO Advisory at Cisco" />
</psc:chapters>
    <itunes:duration>1873</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>141 - Threat Modeling - Part 2</itunes:title>
    <title>141 - Threat Modeling - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is the second part of our Threat Modeling episode. Please listen to last week week's episode, that is episode 140 before you dive into this one. Having said that, lets have a look at the top security news this week:  - https://blog.google: New Gmail protections for a safer, less spammy inbox - https://blog.postmaster.yahooinc.com: More Secure, Less Spam: Enforcing Email Standards for a Better Experience - https://www.nist.gov: Cybersecurit...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the second part of our Threat Modeling episode. Please listen to last week week&apos;s episode, that is episode 140 before you dive into this one.<br/>Having said that, lets have a look at the top security news this week:<br/><br/>- <a href='https://blog.google/products/gmail/gmail-security-authentication-spam-protection/'>https://blog.google</a>: New Gmail protections for a safer, less spammy inbox<br/>- <a href='https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spam'>https://blog.postmaster.yahooinc.com</a>: More Secure, Less Spam: Enforcing Email Standards for a Better Experience<br/>- <a href='https://www.nist.gov/cybersecurity/cybersecurity-awareness-month'>https://www.nist.gov</a>: Cybersecurity Awareness Month<br/>- <a href='https://arstechnica.com/security/2023/09/critical-vulnerabilities-in-exim-threaten-over-250k-email-servers-worldwide/'>https://arstechnica.com</a>: Critical Vulnerabilities in EXIM threaten over 250k email servers worldwide<br/>- <a href='https://owasp.org/www-community/Threat_Modeling'>https://owasp.org</a>: Threat Modeling</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is the second part of our Threat Modeling episode. Please listen to last week week&apos;s episode, that is episode 140 before you dive into this one.<br/>Having said that, lets have a look at the top security news this week:<br/><br/>- <a href='https://blog.google/products/gmail/gmail-security-authentication-spam-protection/'>https://blog.google</a>: New Gmail protections for a safer, less spammy inbox<br/>- <a href='https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spam'>https://blog.postmaster.yahooinc.com</a>: More Secure, Less Spam: Enforcing Email Standards for a Better Experience<br/>- <a href='https://www.nist.gov/cybersecurity/cybersecurity-awareness-month'>https://www.nist.gov</a>: Cybersecurity Awareness Month<br/>- <a href='https://arstechnica.com/security/2023/09/critical-vulnerabilities-in-exim-threaten-over-250k-email-servers-worldwide/'>https://arstechnica.com</a>: Critical Vulnerabilities in EXIM threaten over 250k email servers worldwide<br/>- <a href='https://owasp.org/www-community/Threat_Modeling'>https://owasp.org</a>: Threat Modeling</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13806884-141-threat-modeling-part-2.mp3" length="26266368" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13806884</guid>
    <pubDate>Sat, 14 Oct 2023 23:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13806884/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:09" title="October is cyber security month" />
  <psc:chapter start="8:40" title="Exim vulnerabilities" />
  <psc:chapter start="16:15" title="Threat Modeling - Part 2" />
</psc:chapters>
    <itunes:duration>2185</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>140 -  Threat Modeling - Part 1</itunes:title>
    <title>140 -  Threat Modeling - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode I step through what Threat Modeling is. And yes it a crucial aspect of cybersecurity that is often overlooked. Join us as we explain this concept by carefully examining its definition, and, more importantly, highlighting its effectiveness as a powerful tool in the ever-changing threat, defenses and mitigation. But before that here are the topics of what is trending this week: SMS is still with us despite its weaknessesThe...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode I step through what Threat Modeling is. And yes it a crucial aspect of cybersecurity that is often overlooked. Join us as we explain this concept by carefully examining its definition, and, more importantly, highlighting its effectiveness as a powerful tool in the ever-changing threat, defenses and mitigation.<br/>But before that here are the topics of what is trending this week:</p><ul><li>SMS is still with us despite its weaknesses</li><li>The push to catch up with DMARC</li></ul><p>- <a href='https://blog.google/products/gmail/gmail-security-authentication-spam-protection/'>https://blog.google</a>: New Gmail protections for a safer, less spammy inbox<br/>- <a href='https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spam'>https://blog.postmaster.yahooinc.com</a>: More Secure, Less Spam: Enforcing Email Standards for a Better Experience<br/>- <a href='https://owasp.org/www-community/Threat_Modeling'>https://owasp.org</a>: Threat Modeling<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode I step through what Threat Modeling is. And yes it a crucial aspect of cybersecurity that is often overlooked. Join us as we explain this concept by carefully examining its definition, and, more importantly, highlighting its effectiveness as a powerful tool in the ever-changing threat, defenses and mitigation.<br/>But before that here are the topics of what is trending this week:</p><ul><li>SMS is still with us despite its weaknesses</li><li>The push to catch up with DMARC</li></ul><p>- <a href='https://blog.google/products/gmail/gmail-security-authentication-spam-protection/'>https://blog.google</a>: New Gmail protections for a safer, less spammy inbox<br/>- <a href='https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spam'>https://blog.postmaster.yahooinc.com</a>: More Secure, Less Spam: Enforcing Email Standards for a Better Experience<br/>- <a href='https://owasp.org/www-community/Threat_Modeling'>https://owasp.org</a>: Threat Modeling<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13756026-140-threat-modeling-part-1.mp3" length="32632163" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13756026</guid>
    <pubDate>Sat, 07 Oct 2023 23:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13756026/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:18" title="SMS is still with us despite its weakness" />
  <psc:chapter start="11:48" title="The push to catch up with DMARC" />
  <psc:chapter start="25:01" title="Threat Modeling - Part 1" />
</psc:chapters>
    <itunes:duration>2715</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>139 - Initial Access - When the Rubber Hits the Road During the Attack Phases - Part 2</itunes:title>
    <title>139 - Initial Access - When the Rubber Hits the Road During the Attack Phases - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today's episode is a continuation of what we've started last week: Initial Access. This is part 2.  And as I said, it truly is the point where the rubber hits the road when it comes to the important stages to look out for during an attack. Thoroughly investigation the Initial Access stage allows us finding how an attacker made their way into our environment.  But before that here are the topics of what is trending this week: Microsoft brin...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today&apos;s episode is a continuation of what we&apos;ve started last week: Initial Access. This is part 2. <br/>And as I said, it truly is the point where the rubber hits the road when it comes to the important stages to look out for during an attack. Thoroughly investigation the Initial Access stage allows us finding how an attacker made their way into our environment.<br/><br/>But before that here are the topics of what is trending this week:</p><ul><li>Microsoft brings in Passkey</li><li>UK&apos;s NCSA nudging governments on setting their similar organisation</li></ul><p>- <a href='https://www.europol.europa.eu/publication-events/main-reports/cyber-attacks-apex-of-crime-service-iocta-2023'>https://www.europol.europa.eu</a>: Cyber-attacks: the apex of crime-as-a-service (IOCTA 2023)<br/>- <a href='https://www.reuters.com/technology/power-influence-notoriety-gen-z-hackers-who-struck-mgm-caesars-2023-09-22/'>https://www.reuters.com</a>: Power influence notoriety Gen-Z hackers who struckM-Caesars<br/>- <a href='https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html'>https://www.lockheedmartin.com</a>/: Cyber-Kill-Chain<br/>- <a href='https://attack.mitre.org/'>https://attack.mitre.org</a>: ATT&amp;CK<br/>- <a href='https://www.darkreading.com/dr-global/q-a-uk-ambassador-on-creating-new-cybersecurity-agencies-around-the-world'>https://www.darkreading.com</a>: UK ambassador on creating new cybersecurity agencies around the world<br/>-<a href='https://blogs.windows.com/windowsexperience/2023/09/26/the-most-personal-windows-11-experience-begins-rolling-out-today/'> https://blogs.windows.com</a>:The most personal Windows 11 experience begins-rolling-out-today</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today&apos;s episode is a continuation of what we&apos;ve started last week: Initial Access. This is part 2. <br/>And as I said, it truly is the point where the rubber hits the road when it comes to the important stages to look out for during an attack. Thoroughly investigation the Initial Access stage allows us finding how an attacker made their way into our environment.<br/><br/>But before that here are the topics of what is trending this week:</p><ul><li>Microsoft brings in Passkey</li><li>UK&apos;s NCSA nudging governments on setting their similar organisation</li></ul><p>- <a href='https://www.europol.europa.eu/publication-events/main-reports/cyber-attacks-apex-of-crime-service-iocta-2023'>https://www.europol.europa.eu</a>: Cyber-attacks: the apex of crime-as-a-service (IOCTA 2023)<br/>- <a href='https://www.reuters.com/technology/power-influence-notoriety-gen-z-hackers-who-struck-mgm-caesars-2023-09-22/'>https://www.reuters.com</a>: Power influence notoriety Gen-Z hackers who struckM-Caesars<br/>- <a href='https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html'>https://www.lockheedmartin.com</a>/: Cyber-Kill-Chain<br/>- <a href='https://attack.mitre.org/'>https://attack.mitre.org</a>: ATT&amp;CK<br/>- <a href='https://www.darkreading.com/dr-global/q-a-uk-ambassador-on-creating-new-cybersecurity-agencies-around-the-world'>https://www.darkreading.com</a>: UK ambassador on creating new cybersecurity agencies around the world<br/>-<a href='https://blogs.windows.com/windowsexperience/2023/09/26/the-most-personal-windows-11-experience-begins-rolling-out-today/'> https://blogs.windows.com</a>:The most personal Windows 11 experience begins-rolling-out-today</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13722618-139-initial-access-when-the-rubber-hits-the-road-during-the-attack-phases-part-2.mp3" length="30288741" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13722618</guid>
    <pubDate>Sat, 30 Sep 2023 23:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13722618/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:29" title="Microsoft brings in Passkey" />
  <psc:chapter start="10:11" title="UK&#39;s NCSA nudging governments on setting their similar organisation" />
  <psc:chapter start="17:02" title="Initial Access - Part 2" />
</psc:chapters>
    <itunes:duration>2520</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>138 - Initial Access - When the Rubber Hits the Road During the Attack Phases</itunes:title>
    <title>138 - Initial Access - When the Rubber Hits the Road During the Attack Phases</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, we're peeling back the layers of cybersecurity to delve into a critical phase of the attack lifecycle: Initial Access. It's the point where the rubber truly hits the road during a cyberattack. We will uncover the strategies, tactics, and technologies involved in gaining that crucial foothold in target systems for both attackers and defenders.   But before that and as always ahead of the main topic we stop and reflect on...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we&apos;re peeling back the layers of cybersecurity to delve into a critical phase of the attack lifecycle: Initial Access. It&apos;s the point where the rubber truly hits the road during a cyberattack. We will uncover the strategies, tactics, and technologies involved in gaining that crucial foothold in target systems for both attackers and defenders. <br/><br/>But before that and as always ahead of the main topic we stop and reflect on the trending news and this week we have two  notable  security pieces  including:</p><ul><li>Europol publishes report on malware-based cyber attacks. </li><li>MGM and Caesar&apos;s response to their ransomware attack.</li></ul><p>- <a href='https://www.europol.europa.eu/publication-events/main-reports/cyber-attacks-apex-of-crime-service-iocta-2023'>https://www.europol.europa.eu</a>: Cyber-attacks: the apex of crime-as-a-service (IOCTA 2023)</p><p>- <a href='https://www.reuters.com/technology/power-influence-notoriety-gen-z-hackers-who-struck-mgm-caesars-2023-09-22/'>https://www.reuters.com</a>: Power influence notoriety Gen-Z hackers who struckM-Caesars<br/>- <a href='https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html'>https://www.lockheedmartin.com</a>/: Cyber-Kill-Chain<br/>- <a href='https://attack.mitre.org/'>https://attack.mitre.org</a>: ATT&amp;CK</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we&apos;re peeling back the layers of cybersecurity to delve into a critical phase of the attack lifecycle: Initial Access. It&apos;s the point where the rubber truly hits the road during a cyberattack. We will uncover the strategies, tactics, and technologies involved in gaining that crucial foothold in target systems for both attackers and defenders. <br/><br/>But before that and as always ahead of the main topic we stop and reflect on the trending news and this week we have two  notable  security pieces  including:</p><ul><li>Europol publishes report on malware-based cyber attacks. </li><li>MGM and Caesar&apos;s response to their ransomware attack.</li></ul><p>- <a href='https://www.europol.europa.eu/publication-events/main-reports/cyber-attacks-apex-of-crime-service-iocta-2023'>https://www.europol.europa.eu</a>: Cyber-attacks: the apex of crime-as-a-service (IOCTA 2023)</p><p>- <a href='https://www.reuters.com/technology/power-influence-notoriety-gen-z-hackers-who-struck-mgm-caesars-2023-09-22/'>https://www.reuters.com</a>: Power influence notoriety Gen-Z hackers who struckM-Caesars<br/>- <a href='https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html'>https://www.lockheedmartin.com</a>/: Cyber-Kill-Chain<br/>- <a href='https://attack.mitre.org/'>https://attack.mitre.org</a>: ATT&amp;CK</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13654177-138-initial-access-when-the-rubber-hits-the-road-during-the-attack-phases.mp3" length="33302945" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-13654177</guid>
    <pubDate>Sat, 23 Sep 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13654177/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:32" title="Europol Cryber Crime Report" />
  <psc:chapter start="11:21" title="MGM and Caesar&#39;s responses" />
  <psc:chapter start="26:52" title="Initial Access" />
</psc:chapters>
    <itunes:duration>2771</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>137 - Introduction to Cybersecurity - Part 2</itunes:title>
    <title>137 - Introduction to Cybersecurity - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security.  And what better way than to cover "Introduction to Cyber Security" in this episode.  But before that, we will recap other  trending  security news  including:  The stolen LastPass vaults may have been cracked- https://securitylab.github.com: Notepad++  pushes out fixes for four security vulnerabilitie...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security.  And what better way than to cover &quot;Introduction to Cyber Security&quot; in this episode.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li> The stolen LastPass vaults may have been cracked</li></ul><p>- <a href='https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/'>https://securitylab.github.com</a>: Notepad++  pushes out fixes for four security vulnerabilities<br/>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2023/09/04/qualys-top-20-exploited-vulnerabilities'>https://blog.qualys.com</a>: Qualys&apos; top 20 exploited vulnerabilities<br/>- <a href='https://skillsforall.com/course/introduction-to-cybersecurity?courseLang=en-US'>https://skillsforall.com</a>: Introduction to cybersecurity<br/>- <a href='https://learn.cisco.com/'>https://learn.cisco.com</a>: Learning and development</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security.  And what better way than to cover &quot;Introduction to Cyber Security&quot; in this episode.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li> The stolen LastPass vaults may have been cracked</li></ul><p>- <a href='https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/'>https://securitylab.github.com</a>: Notepad++  pushes out fixes for four security vulnerabilities<br/>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2023/09/04/qualys-top-20-exploited-vulnerabilities'>https://blog.qualys.com</a>: Qualys&apos; top 20 exploited vulnerabilities<br/>- <a href='https://skillsforall.com/course/introduction-to-cybersecurity?courseLang=en-US'>https://skillsforall.com</a>: Introduction to cybersecurity<br/>- <a href='https://learn.cisco.com/'>https://learn.cisco.com</a>: Learning and development</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13603927-137-introduction-to-cybersecurity-part-2.mp3" length="29306368" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13603927</guid>
    <pubDate>Sat, 16 Sep 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13603927/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:08" title="Stolen LastPass&#39; vaults may have been cracked" />
  <psc:chapter start="24:28" title="Introduction to Cyber Security -Part 2" />
</psc:chapters>
    <itunes:duration>2438</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>136 - Introduction to Cybersecurity - Part 1</itunes:title>
    <title>136 - Introduction to Cybersecurity - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security.  And what better way than to cover "Introduction to Cyber Security" in this episode.  But before that, we will recap other  trending  security news  including:  Notepad++ 8.5.7 released with fixes for four security vulnerabilities Years-old Microsoft security holes still hot targets for cyber-crooks- h...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security.  And what better way than to cover &quot;Introduction to Cyber Security&quot; in this episode.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li> Notepad++ 8.5.7 released with fixes for four security vulnerabilities</li><li> Years-old Microsoft security holes still hot targets for cyber-crooks</li></ul><p>- <a href='https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/'>https://securitylab.github.com</a>: Notepad++  pushes out fixes for four security vulnerabilities<br/>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2023/09/04/qualys-top-20-exploited-vulnerabilities'>https://blog.qualys.com</a>: Qualys&apos; top 20 exploited vulnerabilities<br/>- <a href='https://skillsforall.com/course/introduction-to-cybersecurity?courseLang=en-US'>https://skillsforall.com</a>: Introduction to cybersecurity<br/>- <a href='https://learn.cisco.com/'>https://learn.cisco.com</a>: Learning and development<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we will step back and talk about the fundamentals to understanding this ever-evolving field: cyber security.  And what better way than to cover &quot;Introduction to Cyber Security&quot; in this episode.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li> Notepad++ 8.5.7 released with fixes for four security vulnerabilities</li><li> Years-old Microsoft security holes still hot targets for cyber-crooks</li></ul><p>- <a href='https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/'>https://securitylab.github.com</a>: Notepad++  pushes out fixes for four security vulnerabilities<br/>- <a href='https://blog.qualys.com/vulnerabilities-threat-research/2023/09/04/qualys-top-20-exploited-vulnerabilities'>https://blog.qualys.com</a>: Qualys&apos; top 20 exploited vulnerabilities<br/>- <a href='https://skillsforall.com/course/introduction-to-cybersecurity?courseLang=en-US'>https://skillsforall.com</a>: Introduction to cybersecurity<br/>- <a href='https://learn.cisco.com/'>https://learn.cisco.com</a>: Learning and development<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13582487-136-introduction-to-cybersecurity-part-1.mp3" length="27149174" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13582487</guid>
    <pubDate>Sat, 09 Sep 2023 21:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13582487/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:09" title="Notepad++ 8.5.7 released with fixes" />
  <psc:chapter start="8:35" title="Years-old Microsoft security holes" />
  <psc:chapter start="18:30" title="Introduction to Cyber Security" />
</psc:chapters>
    <itunes:duration>2258</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>135 - Cybersecurity&#39;s Key - Choosing the Right Tools</itunes:title>
    <title>135 - Cybersecurity&#39;s Key - Choosing the Right Tools</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  In the ever-evolving landscape of digital threats and vulnerabilities, the importance of selecting the right tools for the job cannot be overstated. Just like a skilled craftsman relies on the right tools to create a masterpiece, cybersecurity professionals must carefully choose their tools to safeguard digital asset effectively. Join us as we delve into the world of cyber tool selection and explore how each tool plays a crucial role in f...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> In the ever-evolving landscape of digital threats and vulnerabilities, the importance of selecting the right tools for the job cannot be overstated. Just like a skilled craftsman relies on the right tools to create a masterpiece, cybersecurity professionals must carefully choose their tools to safeguard digital asset effectively. Join us as we delve into the world of cyber tool selection and explore how each tool plays a crucial role in fortifying our digital defenses.<br/><br/>- <a href='https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849'>https://techcommunity.microsoft.com</a>:  Enabling Extended Protection on Exchange Server by Default<br/>- <a href='https://www.cisa.gov/news-events/analysis-reports/ar23-243a'>https://www.cisa.gov</a>: Infamous Chisel Analysis report</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> In the ever-evolving landscape of digital threats and vulnerabilities, the importance of selecting the right tools for the job cannot be overstated. Just like a skilled craftsman relies on the right tools to create a masterpiece, cybersecurity professionals must carefully choose their tools to safeguard digital asset effectively. Join us as we delve into the world of cyber tool selection and explore how each tool plays a crucial role in fortifying our digital defenses.<br/><br/>- <a href='https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849'>https://techcommunity.microsoft.com</a>:  Enabling Extended Protection on Exchange Server by Default<br/>- <a href='https://www.cisa.gov/news-events/analysis-reports/ar23-243a'>https://www.cisa.gov</a>: Infamous Chisel Analysis report</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13539396-135-cybersecurity-s-key-choosing-the-right-tools.mp3" length="26468662" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13539396</guid>
    <pubDate>Sat, 02 Sep 2023 23:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13539396/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="135 - Cybersecurity&#39;s Key - Choosing the Right Tools" />
  <psc:chapter start="0:02" title="Intro" />
  <psc:chapter start="1:31" title="Infamous Chisel Report" />
  <psc:chapter start="9:18" title="Microsoft Exchange Extended Protection" />
  <psc:chapter start="14:20" title="Cybersecurity&#39;s Key - Choosing the Right Tools" />
</psc:chapters>
    <itunes:duration>2201</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>134 - How does Generative AI help in Cybersecurity</itunes:title>
    <title>134 - How does Generative AI help in Cybersecurity</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  I'm Ibrahim Yusuf, your host, and in today's episode, we're exploring an exciting intersection between generative AI and cybersecurity. In particular we will look into whether cyber security can benefit from generative AI such as ChatGPT? What about the cyber-crooks, is this helping them too? ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I&apos;m Ibrahim Yusuf, your host, and in today&apos;s episode, we&apos;re exploring an exciting intersection between generative AI and cybersecurity.<br/>In particular we will look into whether cyber security can benefit from generative AI such as ChatGPT? What about the cyber-crooks, is this helping them too? <br/><br/>All that and more in today&apos;s episode.<br/><br/><b>- </b><a href='https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/'><b>www.group-ib.com</b></a>: Traders&apos; Dollars in Danger: CVE-2023-38831 Zero-Day vulnerability in WinRAR exploited by cybercriminals to target traders<br/>- <a href='https://blog.google/technology/safety-security/introducing-googles-secure-ai-framework/'><b>https://blog.google</b></a>: Introducing Googles Secure AI Framework<br/>- <a href='https://services.google.com/fh/files/blogs/google_ai_red_team_digital_final.pdf'><b>https://services.google.com</b></a>: Google AI Red Team</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I&apos;m Ibrahim Yusuf, your host, and in today&apos;s episode, we&apos;re exploring an exciting intersection between generative AI and cybersecurity.<br/>In particular we will look into whether cyber security can benefit from generative AI such as ChatGPT? What about the cyber-crooks, is this helping them too? <br/><br/>All that and more in today&apos;s episode.<br/><br/><b>- </b><a href='https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/'><b>www.group-ib.com</b></a>: Traders&apos; Dollars in Danger: CVE-2023-38831 Zero-Day vulnerability in WinRAR exploited by cybercriminals to target traders<br/>- <a href='https://blog.google/technology/safety-security/introducing-googles-secure-ai-framework/'><b>https://blog.google</b></a>: Introducing Googles Secure AI Framework<br/>- <a href='https://services.google.com/fh/files/blogs/google_ai_red_team_digital_final.pdf'><b>https://services.google.com</b></a>: Google AI Red Team</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13472990-134-how-does-generative-ai-help-in-cybersecurity.mp3" length="29257751" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13472990</guid>
    <pubDate>Sat, 26 Aug 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13472990/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:15" title="Google Creates Red Team for AI" />
  <psc:chapter start="8:10" title="Zero-Day vulnerability in WinRAR" />
</psc:chapters>
    <itunes:duration>2434</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>133- Interview with Cohaesus Group - Part 2</itunes:title>
    <title>133- Interview with Cohaesus Group - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the second part. Enjoy  - https://group.cohaesus.co.uk: Cohaesus Group Be sure to subscribe!   You can also...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the second part. Enjoy<br/><br/>- <a href='https://group.cohaesus.co.uk/'>https://group.cohaesus.co.uk</a>: Cohaesus Group</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the second part. Enjoy<br/><br/>- <a href='https://group.cohaesus.co.uk/'>https://group.cohaesus.co.uk</a>: Cohaesus Group</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13472882-133-interview-with-cohaesus-group-part-2.mp3" length="17581511" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13472882</guid>
    <pubDate>Sat, 19 Aug 2023 06:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13472882/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="0:51" title="Interview with Cohaesus Group - Part 2" />
</psc:chapters>
    <itunes:duration>1461</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>132 - Interview with Cohaesus Group - Part 1</itunes:title>
    <title>132 - Interview with Cohaesus Group - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the first part. Enjoy  - https://group.cohaesus.co.uk: Cohaesus Group Be sure to subscribe!   You can also ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the first part. Enjoy<br/><br/>- <a href='https://group.cohaesus.co.uk/'>https://group.cohaesus.co.uk</a>: Cohaesus Group</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>I had the pleasure of sitting down with Cohaesus Group. We touched various areas of cyber security. I split the talk into two parts as it went on a bit. Without further ado, here is the first part. Enjoy<br/><br/>- <a href='https://group.cohaesus.co.uk/'>https://group.cohaesus.co.uk</a>: Cohaesus Group</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13427169-132-interview-with-cohaesus-group-part-1.mp3" length="16969307" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13427169</guid>
    <pubDate>Sat, 12 Aug 2023 21:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13427169/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="0:30" title="Interview with Cohaesus Group - part 1" />
</psc:chapters>
    <itunes:duration>1410</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>131 - How do ransomeware rollback features actually work?</itunes:title>
    <title>131 - How do ransomeware rollback features actually work?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender  from analyst to the C-Suites, in plain english.   In today's episode, we'll explore a critical aspect of endpoint security – the ransomware rollback feature. Ransomware is still a prevailing threat, targeting individuals and organizations alike. To fight back, many endpoint security solutions offer a rollback feature, to mitigate&...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender  from analyst to the C-Suites, in plain english.<br/><br/> In today&apos;s episode, we&apos;ll explore a critical aspect of endpoint security – the ransomware rollback feature. Ransomware is still a prevailing threat, targeting individuals and organizations alike. To fight back, many endpoint security solutions offer a rollback feature, to mitigate  data lost in the first place.<br/> By the end of this episode you will understand its inner working and how it keeps cybercriminals at bay sometimes. <br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li>CISA releases its Cybersecurity Strategic Plan, FY2024-2026</li><li>What is the most exploited vulnerabilities? We will have a look at what the industry&apos;s major cyber security agencies agreed?</li></ul><p>- <a href='https://www.hsdl.org/c/abstract/?docid=881040'>https://www.hsdl.org</a>: CISA releases its Cybersecurity Strategic Plan, FY2024-2026<br/>-<a href='https://www.cisa.gov/news-events/alerts/2023/08/03/cisa-nsa-fbi-and-international-partners-release-joint-csa-top-routinely-exploited-vulnerabilities'> https://www.cisa.gov/news-event</a>: CISA, NSA, FBI, and International Partners Release Joint CSA on Top Routinely Exploited Vulnerabilities of 2022</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome and thank you for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender  from analyst to the C-Suites, in plain english.<br/><br/> In today&apos;s episode, we&apos;ll explore a critical aspect of endpoint security – the ransomware rollback feature. Ransomware is still a prevailing threat, targeting individuals and organizations alike. To fight back, many endpoint security solutions offer a rollback feature, to mitigate  data lost in the first place.<br/> By the end of this episode you will understand its inner working and how it keeps cybercriminals at bay sometimes. <br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li>CISA releases its Cybersecurity Strategic Plan, FY2024-2026</li><li>What is the most exploited vulnerabilities? We will have a look at what the industry&apos;s major cyber security agencies agreed?</li></ul><p>- <a href='https://www.hsdl.org/c/abstract/?docid=881040'>https://www.hsdl.org</a>: CISA releases its Cybersecurity Strategic Plan, FY2024-2026<br/>-<a href='https://www.cisa.gov/news-events/alerts/2023/08/03/cisa-nsa-fbi-and-international-partners-release-joint-csa-top-routinely-exploited-vulnerabilities'> https://www.cisa.gov/news-event</a>: CISA, NSA, FBI, and International Partners Release Joint CSA on Top Routinely Exploited Vulnerabilities of 2022</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13353549-131-how-do-ransomeware-rollback-features-actually-work.mp3" length="39404378" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13353549</guid>
    <pubDate>Sat, 05 Aug 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13353549/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:26" title="CISA releases its Cybersecurity Strategic Plan, FY2024-2026" />
  <psc:chapter start="9:58" title="What are the most exploited vulnerabilities?" />
  <psc:chapter start="21:44" title="How do ransomeware rollback features work?" />
</psc:chapters>
    <itunes:duration>3279</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>130 - What is the difference between Incidence Response and Threat Hunting?</itunes:title>
    <title>130 - What is the difference between Incidence Response and Threat Hunting?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Listen to this very insightful episode on differentiating two important cybersecurity domains that are both intriguing and essential: Threat Hunting and Incident Response. We all agree that staying one step ahead of cybercrooks is paramount. But what sets these two critical practices apart, and how do they work together to safeguard businesses?  While we at it, we will demystify the key differences between these two cybersecurity corner stones....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div>Listen to this very insightful episode on differentiating two important cybersecurity domains that are both intriguing and essential: Threat Hunting and Incident Response.<br/>We all agree that staying one step ahead of cybercrooks is paramount. But what sets these two critical practices apart, and how do they work together to safeguard businesses?<br/><br/>While we at it, we will demystify the key differences between these two cybersecurity corner stones. We&apos;ll explore the core principles, methodologies, and objectives that distinguish these two powerful approaches . <br/><br/> But before that, we will recap other  trending  security news  including:<br/><br/></div><ul><li>Cybersecurity firm Sophos impersonated by a ransomware tool</li><li>A particular ransomware gangs are taking the usual steps to leak their victim&apos;s data on the clearweb sites.</li></ul><div>- <a href='https://news.sophos.com/en-us/2023/07/18/sophos-discovers-ransomware-abusing-sophos-name/'>https://news.sophos.com</a>: Sophos discovers ransomware abusing Sophos&apos; name<br/>- <a href='https://cisoseries.com/cyber-security-headlines-clop-leaks-on-clearweb-eu-pushes-back-on-csa-centralization-rising-data-breach-costs/'>https://cisoseries.com</a>: Clop leaks on clearweb <br/>- <a href='https://www.computing.co.uk/news/4120724/clop-clearweb-publish-moveit'>https://www.computing.co.uk</a>: Clop clearweb publish Moveit<br/>- <a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf'>https://nvlpubs.nist.gov</a>: NIST.SP.800-61r2<br/>- <a href='https://www.stickmancyber.com/cybersecurity-blog/incident-response-frameworks-nist-sans'>https://www.stickmancyber.com</a>:: Incident Response Frameworks NIST-SANS<br/><br/></div><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div>Listen to this very insightful episode on differentiating two important cybersecurity domains that are both intriguing and essential: Threat Hunting and Incident Response.<br/>We all agree that staying one step ahead of cybercrooks is paramount. But what sets these two critical practices apart, and how do they work together to safeguard businesses?<br/><br/>While we at it, we will demystify the key differences between these two cybersecurity corner stones. We&apos;ll explore the core principles, methodologies, and objectives that distinguish these two powerful approaches . <br/><br/> But before that, we will recap other  trending  security news  including:<br/><br/></div><ul><li>Cybersecurity firm Sophos impersonated by a ransomware tool</li><li>A particular ransomware gangs are taking the usual steps to leak their victim&apos;s data on the clearweb sites.</li></ul><div>- <a href='https://news.sophos.com/en-us/2023/07/18/sophos-discovers-ransomware-abusing-sophos-name/'>https://news.sophos.com</a>: Sophos discovers ransomware abusing Sophos&apos; name<br/>- <a href='https://cisoseries.com/cyber-security-headlines-clop-leaks-on-clearweb-eu-pushes-back-on-csa-centralization-rising-data-breach-costs/'>https://cisoseries.com</a>: Clop leaks on clearweb <br/>- <a href='https://www.computing.co.uk/news/4120724/clop-clearweb-publish-moveit'>https://www.computing.co.uk</a>: Clop clearweb publish Moveit<br/>- <a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf'>https://nvlpubs.nist.gov</a>: NIST.SP.800-61r2<br/>- <a href='https://www.stickmancyber.com/cybersecurity-blog/incident-response-frameworks-nist-sans'>https://www.stickmancyber.com</a>:: Incident Response Frameworks NIST-SANS<br/><br/></div><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13315167-130-what-is-the-difference-between-incidence-response-and-threat-hunting.mp3" length="28288003" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13315167</guid>
    <pubDate>Sat, 29 Jul 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13315167/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:40" title="Cybersecurity firm Sophos impersonated by a ransomware tool" />
  <psc:chapter start="8:16" title="ransomware gangs are taking the usual steps to leak their victim&#39;s data on the clearweb sites" />
  <psc:chapter start="15:02" title="What is the difference between Incidence Response and Threat Hunting? " />
</psc:chapters>
    <itunes:duration>2353</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>129 - What is new in PCI DSS v4.0?</itunes:title>
    <title>129 - What is new in PCI DSS v4.0?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. This is another exciting episode of our cybersecurity podcast! Today, we've got a topic that's hot off the press—the newly released Payment Card Industry Data Security Standard version 4, or PCI DSS v4. If you're in the world of payments, data security, or simply curious about the latest in safeguarding...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>This is another exciting episode of our cybersecurity podcast! Today, we&apos;ve got a topic that&apos;s hot off the press—the newly released Payment Card Industry Data Security Standard version 4, or PCI DSS v4. If you&apos;re in the world of payments, data security, or simply curious about the latest in safeguarding your customers&apos; sensitive information, this episode is a must-listen.<br/><br/>In this edition, we&apos;ll explore the key updates and changes in PCI DSS v4, the reasons behind its release, and what it means for businesses processing credit card transactions. From enhanced authentication measures to the latest encryption protocols, the new standard promises to fortify data protection and combat emerging cyber threats.<br/><br/>So, get ready to dive into the cutting-edge world of PCI DSS v4 as we unravel the advancements that&apos;ll shape the future of secure payment processing. Let&apos;s jump right in with the start of  this week&apos;s top trending news. <br/><br/></p><ul><li>Accidental VirusTotal upload is a valuable reminder to double check what you share</li><li>Microsoft allows logging access to all their license tiers like E3</li></ul><p><a href='https://support.virustotal.com/hc/en-us/articles/115002126889-How-it-works'>https://support.virustotal.com</a>:How it works<br/><a href='https://www.virustotal.com'>https://www.virustotal.com</a>: Upload<br/><a href='https://www.bleepingcomputer.com/news/security/stolen-microsoft-key-offered-widespread-access-to-microsoft-cloud-services/'>https://www.bleepingcomputer.com</a>: Stolen Microsoft key offered widespread access to Microsoft cloud services<br/><a href='https://www.bleepingcomputer.com/news/microsoft/microsoft-expands-access-to-cloud-logging-data-for-free-after-exchange-hacks/'>https://www.bleepingcomputer.com</a>: Microsoft expands access to cloud logging data for free after Exchange hacks<br/><a href='https://listings.pcisecuritystandards.org/documents/PCI-DSS-v3-2-1-to-v4-0-Summary-of-Changes-r1.pdf'>https://listings.pcisecuritystandards.org</a>: PCI-DSS-v3-2-1 to v4-0 Summary of Changes</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>This is another exciting episode of our cybersecurity podcast! Today, we&apos;ve got a topic that&apos;s hot off the press—the newly released Payment Card Industry Data Security Standard version 4, or PCI DSS v4. If you&apos;re in the world of payments, data security, or simply curious about the latest in safeguarding your customers&apos; sensitive information, this episode is a must-listen.<br/><br/>In this edition, we&apos;ll explore the key updates and changes in PCI DSS v4, the reasons behind its release, and what it means for businesses processing credit card transactions. From enhanced authentication measures to the latest encryption protocols, the new standard promises to fortify data protection and combat emerging cyber threats.<br/><br/>So, get ready to dive into the cutting-edge world of PCI DSS v4 as we unravel the advancements that&apos;ll shape the future of secure payment processing. Let&apos;s jump right in with the start of  this week&apos;s top trending news. <br/><br/></p><ul><li>Accidental VirusTotal upload is a valuable reminder to double check what you share</li><li>Microsoft allows logging access to all their license tiers like E3</li></ul><p><a href='https://support.virustotal.com/hc/en-us/articles/115002126889-How-it-works'>https://support.virustotal.com</a>:How it works<br/><a href='https://www.virustotal.com'>https://www.virustotal.com</a>: Upload<br/><a href='https://www.bleepingcomputer.com/news/security/stolen-microsoft-key-offered-widespread-access-to-microsoft-cloud-services/'>https://www.bleepingcomputer.com</a>: Stolen Microsoft key offered widespread access to Microsoft cloud services<br/><a href='https://www.bleepingcomputer.com/news/microsoft/microsoft-expands-access-to-cloud-logging-data-for-free-after-exchange-hacks/'>https://www.bleepingcomputer.com</a>: Microsoft expands access to cloud logging data for free after Exchange hacks<br/><a href='https://listings.pcisecuritystandards.org/documents/PCI-DSS-v3-2-1-to-v4-0-Summary-of-Changes-r1.pdf'>https://listings.pcisecuritystandards.org</a>: PCI-DSS-v3-2-1 to v4-0 Summary of Changes</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13277567-129-what-is-new-in-pci-dss-v4-0.mp3" length="28865742" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13277567</guid>
    <pubDate>Sat, 22 Jul 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13277567/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="2:01" title="Accidental VirusTotal upload" />
  <psc:chapter start="10:13" title="Microsoft allows logging access to all their license tiers" />
  <psc:chapter start="18:06" title="What is new in PCI DSS 4.0?v" />
</psc:chapters>
    <itunes:duration>2401</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>128 - How to Achieve Cyber Resilience - Best Practices for Effective Incident Response - Part  2</itunes:title>
    <title>128 - How to Achieve Cyber Resilience - Best Practices for Effective Incident Response - Part  2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  Today, we continue with part 2 the critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it's a data breach, a malware attack, or a network intrusion, incidents can disrupt operations,...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Today, we continue with part 2 the critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it&apos;s a data breach, a malware attack, or a network intrusion, incidents can disrupt operations, compromise sensitive information, and damage reputation. That&apos;s why having an effective incident response strategy is crucial. In this episode, we&apos;ll explore the key principles and strategies behind incident response best practices. We&apos;ll discuss the steps organizations should take to prepare, detect, respond, and recover from security incidents.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li><a href=' https://the-decoder.com/chatgpt-with-no-ethical-boundaries-wormgpt-fuels-ai-generated-scams/'>https://the-decoder.com</a>: ChatGPT with no ethical boundaries WormGPT fuels AI generated scams</li><li><a href='https://www.group-ib.com/resources/research-hub/drp-report-2023/'>https://www.group-ib.com</a>: Digital Risk Report 2023 </li></ul><p>- <a href='https://www.sans.org/tools/the-pyramid-of-pain/'>https://www.sans.org/tools/</a>: The Pyramid Of Pain<br/>- <a href='https://support.microsoft.com/en-us/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318'>https://support.microsoft.com</a>:Microsoft edge secure network to protect your browsing<br/>- <a href='https://www.theverge.com/2023/7/10/23787453/meta-instagram-threads-100-million-users-milestone'>https://www.theverge.com</a>: Meta Instagram threads<br/>- <a href='https://talosintelligence.com/incident_response/plans'>https://talosintelligence.com</a>: Incident Response Plans<br/>- <a href='https://www.sans.org/media/score/504-incident-response-cycle.pdf'>https://www.sans.org</a>: Incident Response Cycle<br/>- <a href='https://www.cisco.com/c/en/us/products/security/sas-incident-response.html#~news-events'>https://www.cisco.co</a>:  Incident Response Services<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Today, we continue with part 2 the critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it&apos;s a data breach, a malware attack, or a network intrusion, incidents can disrupt operations, compromise sensitive information, and damage reputation. That&apos;s why having an effective incident response strategy is crucial. In this episode, we&apos;ll explore the key principles and strategies behind incident response best practices. We&apos;ll discuss the steps organizations should take to prepare, detect, respond, and recover from security incidents.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li><a href=' https://the-decoder.com/chatgpt-with-no-ethical-boundaries-wormgpt-fuels-ai-generated-scams/'>https://the-decoder.com</a>: ChatGPT with no ethical boundaries WormGPT fuels AI generated scams</li><li><a href='https://www.group-ib.com/resources/research-hub/drp-report-2023/'>https://www.group-ib.com</a>: Digital Risk Report 2023 </li></ul><p>- <a href='https://www.sans.org/tools/the-pyramid-of-pain/'>https://www.sans.org/tools/</a>: The Pyramid Of Pain<br/>- <a href='https://support.microsoft.com/en-us/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318'>https://support.microsoft.com</a>:Microsoft edge secure network to protect your browsing<br/>- <a href='https://www.theverge.com/2023/7/10/23787453/meta-instagram-threads-100-million-users-milestone'>https://www.theverge.com</a>: Meta Instagram threads<br/>- <a href='https://talosintelligence.com/incident_response/plans'>https://talosintelligence.com</a>: Incident Response Plans<br/>- <a href='https://www.sans.org/media/score/504-incident-response-cycle.pdf'>https://www.sans.org</a>: Incident Response Cycle<br/>- <a href='https://www.cisco.com/c/en/us/products/security/sas-incident-response.html#~news-events'>https://www.cisco.co</a>:  Incident Response Services<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13232414-128-how-to-achieve-cyber-resilience-best-practices-for-effective-incident-response-part-2.mp3" length="32300956" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13232414</guid>
    <pubDate>Sat, 15 Jul 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2688</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>127 - How to Achieve Cyber Resilience: Best Practices for Effective Incident Response - Part 1</itunes:title>
    <title>127 - How to Achieve Cyber Resilience: Best Practices for Effective Incident Response - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  Today, we delve into a critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it's a data breach, a malware attack, or a network intrusion, incidents can disrupt operations, compr...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div> Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Today, we delve into a critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it&apos;s a data breach, a malware attack, or a network intrusion, incidents can disrupt operations, compromise sensitive information, and damage reputation. That&apos;s why having an effective incident response strategy is crucial. In this episode, we&apos;ll explore the key principles and strategies behind incident response best practices. We&apos;ll discuss the steps organizations should take to prepare, detect, respond, and recover from security incidents.<br/><br/>But before that, we will recap other  trending  security news  including:<br/><br/></div><ul><li>Microsoft Edge free built-in VPN</li><li>Meta&apos;s twitter alternative</li></ul><p>- <a href='https://www.sans.org/tools/the-pyramid-of-pain/'>https://www.sans.org/tools/</a>: The Pyramid Of Pain<br/>- <a href='https://support.microsoft.com/en-us/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318'>https://support.microsoft.com</a>:Microsoft edge secure network to protect your browsing<br/>- <a href='https://www.theverge.com/2023/7/10/23787453/meta-instagram-threads-100-million-users-milestone'>https://www.theverge.com</a>: Meta Instagram threads<br/>- <a href='https://talosintelligence.com/incident_response/plans'>https://talosintelligence.com</a>: Incident Response Plans<br/>- <a href='https://www.sans.org/media/score/504-incident-response-cycle.pdf'>https://www.sans.org</a>: Incident Response Cycle<br/>- <a href='https://www.cisco.com/c/en/us/products/security/sas-incident-response.html#~news-events'>https://www.cisco.co</a>:  Incident Response Services</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div> Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Today, we delve into a critical aspect of cybersecurity: incident response best practices. Given the unforgiving threat landscape, organizations face an ever-increasing number of cyber threats. Whether it&apos;s a data breach, a malware attack, or a network intrusion, incidents can disrupt operations, compromise sensitive information, and damage reputation. That&apos;s why having an effective incident response strategy is crucial. In this episode, we&apos;ll explore the key principles and strategies behind incident response best practices. We&apos;ll discuss the steps organizations should take to prepare, detect, respond, and recover from security incidents.<br/><br/>But before that, we will recap other  trending  security news  including:<br/><br/></div><ul><li>Microsoft Edge free built-in VPN</li><li>Meta&apos;s twitter alternative</li></ul><p>- <a href='https://www.sans.org/tools/the-pyramid-of-pain/'>https://www.sans.org/tools/</a>: The Pyramid Of Pain<br/>- <a href='https://support.microsoft.com/en-us/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318'>https://support.microsoft.com</a>:Microsoft edge secure network to protect your browsing<br/>- <a href='https://www.theverge.com/2023/7/10/23787453/meta-instagram-threads-100-million-users-milestone'>https://www.theverge.com</a>: Meta Instagram threads<br/>- <a href='https://talosintelligence.com/incident_response/plans'>https://talosintelligence.com</a>: Incident Response Plans<br/>- <a href='https://www.sans.org/media/score/504-incident-response-cycle.pdf'>https://www.sans.org</a>: Incident Response Cycle<br/>- <a href='https://www.cisco.com/c/en/us/products/security/sas-incident-response.html#~news-events'>https://www.cisco.co</a>:  Incident Response Services</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13193930-127-how-to-achieve-cyber-resilience-best-practices-for-effective-incident-response-part-1.mp3" length="34457889" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13193930</guid>
    <pubDate>Sat, 08 Jul 2023 23:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13193930/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:36" title="Microsoft Edge free built-in VPN" />
  <psc:chapter start="7:21" title="Meta&#39;s twitter alternative" />
  <psc:chapter start="20:10" title="How to Achieve Cyber Resilience: Best Practices for Effective Incident Response" />
</psc:chapters>
    <itunes:duration>2867</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>126 - Unmasking cyber threats - The power of cyber threat intel</itunes:title>
    <title>126 - Unmasking cyber threats - The power of cyber threat intel</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, we'll explore the fundamental purpose of cyber threat intelligence and why it has become an essential pillar of modern cybersecurity.  Cybercriminals are constantly adapting their tactics, making it crucial for organizations and individuals to stay one step ahead. That's where cyber threat intelligence comes in.  Whether you're a cybersecurity professional looking to deepen your knowledge or an individual seeking to prot...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we&apos;ll explore the fundamental purpose of cyber threat intelligence and why it has become an essential pillar of modern cybersecurity.<br/><br/>Cybercriminals are constantly adapting their tactics, making it crucial for organizations and individuals to stay one step ahead. That&apos;s where cyber threat intelligence comes in.<br/><br/>Whether you&apos;re a cybersecurity professional looking to deepen your knowledge or an individual seeking to protect yourself in an increasingly connected world, this episode will provide you with valuable insights and practical strategies.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li>MITRE Announces Most Dangerous Software Weaknesses</li><li>Who is dominating the ransomeware landscape?</li></ul><p>- <a href='https://www.cisa.gov/news-events/alerts/2023/06/29/2023-cwe-top-25-most-dangerous-software-weaknesses'>https://www.cisa.gov</a>: 2023 CWE Top 25 most dangerous software weaknesses<br/>- <a href='https://www.acronis.com/en-us/resource-center/resource/acronis-mid-year-cyberthreats-report-2023/'>https://www.acronis.com</a>: Acronis mid-year cyberthreats report 2023<br/>- <a href='https://www.cisco.com/c/en/us/products/security/what-is-cyber-threat-intelligence.html'>https://www.cisco.com</a>: What ciscyber threat intelligence</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, we&apos;ll explore the fundamental purpose of cyber threat intelligence and why it has become an essential pillar of modern cybersecurity.<br/><br/>Cybercriminals are constantly adapting their tactics, making it crucial for organizations and individuals to stay one step ahead. That&apos;s where cyber threat intelligence comes in.<br/><br/>Whether you&apos;re a cybersecurity professional looking to deepen your knowledge or an individual seeking to protect yourself in an increasingly connected world, this episode will provide you with valuable insights and practical strategies.<br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li>MITRE Announces Most Dangerous Software Weaknesses</li><li>Who is dominating the ransomeware landscape?</li></ul><p>- <a href='https://www.cisa.gov/news-events/alerts/2023/06/29/2023-cwe-top-25-most-dangerous-software-weaknesses'>https://www.cisa.gov</a>: 2023 CWE Top 25 most dangerous software weaknesses<br/>- <a href='https://www.acronis.com/en-us/resource-center/resource/acronis-mid-year-cyberthreats-report-2023/'>https://www.acronis.com</a>: Acronis mid-year cyberthreats report 2023<br/>- <a href='https://www.cisco.com/c/en/us/products/security/what-is-cyber-threat-intelligence.html'>https://www.cisco.com</a>: What ciscyber threat intelligence</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13152588-126-unmasking-cyber-threats-the-power-of-cyber-threat-intel.mp3" length="36229568" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13152588</guid>
    <pubDate>Sat, 01 Jul 2023 21:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13152588/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:34" title="MITRE&#39;s Most Dangerous Software Weaknesses" />
  <psc:chapter start="10:15" title="Who is dominating the ransomeware landscape?" />
  <psc:chapter start="17:06" title="Unmasking cyber threats - The power of cyber threat intel" />
</psc:chapters>
    <itunes:duration>3015</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>125 -  Verizon Data breach Investigation Report - Key Takeaways</itunes:title>
    <title>125 -  Verizon Data breach Investigation Report - Key Takeaways</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  Today we dive deep into the key takeaways of the highly anticipated Version Data Breach Investigation Report.  In a world where data breaches have become all too common, understanding the intricacies and lessons from these incidents is more important than ever. The Verizon Data Breach Investigation Report (D...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Today we dive deep into the key takeaways of the highly anticipated Version Data Breach Investigation Report.<br/><br/>In a world where data breaches have become all too common, understanding the intricacies and lessons from these incidents is more important than ever. The Verizon Data Breach Investigation Report (DBIR), compiled by a team of expert analysts, provides invaluable insights into the causes, impacts, and preventive measures surrounding a significant breach that rocked the tech industry.</p><ul><li>Fortinet fixes critical REC vulnerability in FortiNAC</li><li>Vendor contractor account abuse</li></ul><p><a href='https://www.fortiguard.com/psirt/FG-IR-23-096'>https://www.fortiguard.com</a>: FortiNAC - Argument injection in XML interface on port tcp/5555<b><br/></b>- <a href='https://cve.report/CVE-2023-33299'>https://cve.report</a>: CVE-2023-33299<b><br/></b>- <a href='https://blog.talosintelligence.com/vendor-contractor-account-abuse/'>https://blog.talosintelligence.com</a>: Vendor contractor account abuse-<a href='https://www.verizon.com/business/resources/reports/dbir/'>https://www.verizon.com</a><b>: </b>DBIR</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Today we dive deep into the key takeaways of the highly anticipated Version Data Breach Investigation Report.<br/><br/>In a world where data breaches have become all too common, understanding the intricacies and lessons from these incidents is more important than ever. The Verizon Data Breach Investigation Report (DBIR), compiled by a team of expert analysts, provides invaluable insights into the causes, impacts, and preventive measures surrounding a significant breach that rocked the tech industry.</p><ul><li>Fortinet fixes critical REC vulnerability in FortiNAC</li><li>Vendor contractor account abuse</li></ul><p><a href='https://www.fortiguard.com/psirt/FG-IR-23-096'>https://www.fortiguard.com</a>: FortiNAC - Argument injection in XML interface on port tcp/5555<b><br/></b>- <a href='https://cve.report/CVE-2023-33299'>https://cve.report</a>: CVE-2023-33299<b><br/></b>- <a href='https://blog.talosintelligence.com/vendor-contractor-account-abuse/'>https://blog.talosintelligence.com</a>: Vendor contractor account abuse-<a href='https://www.verizon.com/business/resources/reports/dbir/'>https://www.verizon.com</a><b>: </b>DBIR</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13115296-125-verizon-data-breach-investigation-report-key-takeaways.mp3" length="23442351" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13115296</guid>
    <pubDate>Sat, 24 Jun 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13115296/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="125 -  Verizon Data breach Investigation Report - Key Takeaways" />
  <psc:chapter start="1:34" title="FortiNAC CVE" />
  <psc:chapter start="8:13" title="Adversaries infiltrate networks using contractor&#39;s account" />
  <psc:chapter start="19:31" title="Verizon DBIR Key Takeaways" />
</psc:chapters>
    <itunes:duration>1949</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>124 - Comparing data lake and data warehouse</itunes:title>
    <title>124 - Comparing data lake and data warehouse</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from  analyst to the C-Suites, in plain english.  In today's episode, we cover two important data models and their applicability to security. I am talking about data lake and data warehouse.  I will look into their similarity, differences and practical considerations surrounding these two popular data storage and analytics approaches.  In do...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from <br/>analyst to the C-Suites, in plain english.<br/><br/>In today&apos;s episode, we cover two important data models and their applicability to security. I am talking about data lake and data warehouse. <br/>I will look into their similarity, differences and practical considerations surrounding these two popular data storage and analytics approaches. <br/>In doing so I will leave you with a clarity on which option if not both are used when combating cyber attack. <br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li>Decade old critical vulnerability in JetPack Wordpress plugin</li><li>Microsoft June 2023 Patch Tuesday</li></ul><p><a href='https://jetpack.com/blog/jetpack-12-1-1-critical-security-update/'>https://jetpack.com</a>: J<span style='background-color: highlight;'>etPack Critical Security Update</span><br/><a href=' https://krebsonsecurity.com/2023/06/microsoft-patch-tuesday-june-2023-edition/'>https://krebsonsecurity.com</a>: Microsoft Patch Tuesday June 2023 Edition<br/><a href='https://www.splunk.com/en_us/blog/learn/data-warehouse-vs-data-lake.html'>https://www.splunk.com</a>: Data warehouse vs. Data Lake</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from <br/>analyst to the C-Suites, in plain english.<br/><br/>In today&apos;s episode, we cover two important data models and their applicability to security. I am talking about data lake and data warehouse. <br/>I will look into their similarity, differences and practical considerations surrounding these two popular data storage and analytics approaches. <br/>In doing so I will leave you with a clarity on which option if not both are used when combating cyber attack. <br/><br/>But before that, we will recap other  trending  security news  including:</p><ul><li>Decade old critical vulnerability in JetPack Wordpress plugin</li><li>Microsoft June 2023 Patch Tuesday</li></ul><p><a href='https://jetpack.com/blog/jetpack-12-1-1-critical-security-update/'>https://jetpack.com</a>: J<span style='background-color: highlight;'>etPack Critical Security Update</span><br/><a href=' https://krebsonsecurity.com/2023/06/microsoft-patch-tuesday-june-2023-edition/'>https://krebsonsecurity.com</a>: Microsoft Patch Tuesday June 2023 Edition<br/><a href='https://www.splunk.com/en_us/blog/learn/data-warehouse-vs-data-lake.html'>https://www.splunk.com</a>: Data warehouse vs. Data Lake</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13059785-124-comparing-data-lake-and-data-warehouse.mp3" length="34281340" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13059785</guid>
    <pubDate>Sat, 17 Jun 2023 22:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13059785/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro music change" />
  <psc:chapter start="1:10" title="Intro" />
  <psc:chapter start="2:39" title="Decade Old JetPack Vulnerability" />
  <psc:chapter start="8:50" title="Microsoft June 2023 Patch Tuesday" />
  <psc:chapter start="17:30" title="Comparing Data Lake &amp; Data Warehouse" />
</psc:chapters>
    <itunes:duration>2853</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>123-Inside the Cyber Underworld - How Cybercriminals Join Forces for Profit - Part 2</itunes:title>
    <title>123-Inside the Cyber Underworld - How Cybercriminals Join Forces for Profit - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  This is episode 2 of on how how exactly  cybercriminals join forces for profit. Make sure you caught up with episode 1 first before you listen to this episode.  Lets continue demystifying their collaborative nature. But before that, we will recap other  trending  security news  including:...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>This is episode 2 of on how how exactly  cybercriminals join forces for profit. Make sure you caught up with episode 1 first before you listen to this episode.<br/><br/>Lets continue demystifying their collaborative nature.<br/>But before that, we will recap other  trending  security news  including:</p><ul><li>Zero-day Vulnerability in MOVEit Transfer is Being Actively Exploited</li><li>Cisco Releases Updates to Fix AnyConnect Privilege Elevation Vulnerability</li></ul><p>- <a href='https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023'>https://community.progress.com</a>: MOVEit Transfer Critical Vulnerability<br/>- <a href='https://abcnews.go.com/Technology/wireStory/bbc-british-airways-big-victims-moveit-software-hack-99896828'>https://abcnews.go.com</a>:  BBC, British airways big victims MoveIt software hack<br/>- <a href='https://www.europol.europa.eu/operations-services-and-innovation/services-support/joint-cybercrime-action-taskforce'>https://www.e ropol.europa.eu</a>: Joint Cybercrime action Task force<br/>-<a href='https://www.darkreading.com/dr-global/postalfurious-sms-attacks-target-uae-citizens-data-theft'>https://www.darkreading.com</a>: PostalFurious sms attacks target UAE Citizens data theft<br/>-<a href='https://blogs.windows.com/windows-insider/2023/06/02/announcing-windows-11-insider-preview-build-25381/'>https://blogs.windows.com</a>: Announcing Windows 11 insider preview build-25381/<br/>-<a href='https://techcommunity.microsoft.com/t5/itops-talk-blog/how-to-defend-users-from-interception-attacks-via-smb-client/ba-p/1494995'>https://techcommunity.microsoft.com</a>/How to defend users from interception attacks via SMB client<br/>- <a href='https://blog.talosintelligence.com/talos-year-in-review-2022'>https://blog.talosintelligence.com</a>:Talos year in review 2022</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>This is episode 2 of on how how exactly  cybercriminals join forces for profit. Make sure you caught up with episode 1 first before you listen to this episode.<br/><br/>Lets continue demystifying their collaborative nature.<br/>But before that, we will recap other  trending  security news  including:</p><ul><li>Zero-day Vulnerability in MOVEit Transfer is Being Actively Exploited</li><li>Cisco Releases Updates to Fix AnyConnect Privilege Elevation Vulnerability</li></ul><p>- <a href='https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023'>https://community.progress.com</a>: MOVEit Transfer Critical Vulnerability<br/>- <a href='https://abcnews.go.com/Technology/wireStory/bbc-british-airways-big-victims-moveit-software-hack-99896828'>https://abcnews.go.com</a>:  BBC, British airways big victims MoveIt software hack<br/>- <a href='https://www.europol.europa.eu/operations-services-and-innovation/services-support/joint-cybercrime-action-taskforce'>https://www.e ropol.europa.eu</a>: Joint Cybercrime action Task force<br/>-<a href='https://www.darkreading.com/dr-global/postalfurious-sms-attacks-target-uae-citizens-data-theft'>https://www.darkreading.com</a>: PostalFurious sms attacks target UAE Citizens data theft<br/>-<a href='https://blogs.windows.com/windows-insider/2023/06/02/announcing-windows-11-insider-preview-build-25381/'>https://blogs.windows.com</a>: Announcing Windows 11 insider preview build-25381/<br/>-<a href='https://techcommunity.microsoft.com/t5/itops-talk-blog/how-to-defend-users-from-interception-attacks-via-smb-client/ba-p/1494995'>https://techcommunity.microsoft.com</a>/How to defend users from interception attacks via SMB client<br/>- <a href='https://blog.talosintelligence.com/talos-year-in-review-2022'>https://blog.talosintelligence.com</a>:Talos year in review 2022</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/13013688-123-inside-the-cyber-underworld-how-cybercriminals-join-forces-for-profit-part-2.mp3" length="34366747" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-13013688</guid>
    <pubDate>Sat, 10 Jun 2023 20:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/13013688/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="0:00" title="Inside the Cyber Underworld - How Cybercriminals Join Forces for Profit" />
  <psc:chapter start="1:03" title="Zero-day Vulnerability in MOVEit Transfer" />
  <psc:chapter start="18:40" title="Cisco Releases Updates to Fix AnyConnect Privilege Elevation Vulnerability" />
</psc:chapters>
    <itunes:duration>2860</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>122 - Inside the Cyber Underworld - How Cybercriminals Join Forces for Profit - Part 1 </itunes:title>
    <title>122 - Inside the Cyber Underworld - How Cybercriminals Join Forces for Profit - Part 1 </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. It is true, there is no loyalty between criminals but there is a profit to be made between them. How exactly cybercriminals join forces for profit? We will answer that question in this week's episode as we uncover the secret collaborations of cybercrime and delve into the intricate web of connections, strateg...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.</p><p>It is true, there is no loyalty between criminals but there is a profit to be made between them.<br/>How exactly cybercriminals join forces for profit?</p><p>We will answer that question in this week&apos;s episode as we uncover the secret collaborations of cybercrime and delve into the intricate web of connections, strategies, and specialized roles in the world of cybercrime. From hackers to phishers and money mules, we&apos;ll demystify their collaborative nature.</p><p>But before that, we will recap other trending security news including:</p><ul><li>SMB Relay Attack and what Microsoft is doing about it</li><li>A wave of SMS Phishing Campaign Aimed at a Middle Eastern Country. We&apos;ll find out more about this.</li></ul><p>- <a href='https://www.europol.europa.eu/operations-services-and-innovation/services-support/joint-cybercrime-action-taskforce'>https://www.e ropol.europa.eu</a>: Joint Cybercrime action Task force<br/>-<a href='https://www.darkreading.com/dr-global/postalfurious-sms-attacks-target-uae-citizens-data-theft'>https://www.darkreading.com</a>: PostalFurious sms attacks target UAE Citizens data theft<br/>-<a href='https://blogs.windows.com/windows-insider/2023/06/02/announcing-windows-11-insider-preview-build-25381/'>https://blogs.windows.com</a>: Announcing Windows 11 insider preview build-25381/<br/>-<a href='https://techcommunity.microsoft.com/t5/itops-talk-blog/how-to-defend-users-from-interception-attacks-via-smb-client/ba-p/1494995'>https://techcommunity.microsoft.com</a>/How to defend users from interception attacks via SMB client<br/>- <a href='https://blog.talosintelligence.com/talos-year-in-review-2022'>https://blog.talosintelligence.com</a>:Talos year in review 2022<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.</p><p>It is true, there is no loyalty between criminals but there is a profit to be made between them.<br/>How exactly cybercriminals join forces for profit?</p><p>We will answer that question in this week&apos;s episode as we uncover the secret collaborations of cybercrime and delve into the intricate web of connections, strategies, and specialized roles in the world of cybercrime. From hackers to phishers and money mules, we&apos;ll demystify their collaborative nature.</p><p>But before that, we will recap other trending security news including:</p><ul><li>SMB Relay Attack and what Microsoft is doing about it</li><li>A wave of SMS Phishing Campaign Aimed at a Middle Eastern Country. We&apos;ll find out more about this.</li></ul><p>- <a href='https://www.europol.europa.eu/operations-services-and-innovation/services-support/joint-cybercrime-action-taskforce'>https://www.e ropol.europa.eu</a>: Joint Cybercrime action Task force<br/>-<a href='https://www.darkreading.com/dr-global/postalfurious-sms-attacks-target-uae-citizens-data-theft'>https://www.darkreading.com</a>: PostalFurious sms attacks target UAE Citizens data theft<br/>-<a href='https://blogs.windows.com/windows-insider/2023/06/02/announcing-windows-11-insider-preview-build-25381/'>https://blogs.windows.com</a>: Announcing Windows 11 insider preview build-25381/<br/>-<a href='https://techcommunity.microsoft.com/t5/itops-talk-blog/how-to-defend-users-from-interception-attacks-via-smb-client/ba-p/1494995'>https://techcommunity.microsoft.com</a>/How to defend users from interception attacks via SMB client<br/>- <a href='https://blog.talosintelligence.com/talos-year-in-review-2022'>https://blog.talosintelligence.com</a>:Talos year in review 2022<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12968171-122-inside-the-cyber-underworld-how-cybercriminals-join-forces-for-profit-part-1.mp3" length="38892615" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12968171</guid>
    <pubDate>Sat, 03 Jun 2023 23:00:00 +0400</pubDate>
    <podcast:chapters url="https://www.buzzsprout.com/1673686/12968171/chapters.json" type="application/json" />
    <psc:chapters>
  <psc:chapter start="0:00" title="Intro" />
  <psc:chapter start="1:23" title=" News 1 of 2: SMB Relay Attack" />
  <psc:chapter start="13:42" title="SMS Phishing Campaign Aimed at a Middle Eastern Country" />
  <psc:chapter start="22:23" title="Inside the Cyber Underworld - How Cybercriminals Join Forces for Profit" />
</psc:chapters>
    <itunes:duration>3237</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>121 - The MITRE ATT&amp;CK Navigator</itunes:title>
    <title>121 - The MITRE ATT&amp;CK Navigator</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  The ATT&amp;CK Navigator is a web-based tool created and maintained by the Mitre organisation. The tools is used for annotating and exploring ATT&amp;CK matrices. It is often used to visualize defensive coverage, red/blue team planning, the frequency of detected techniques etc. That is the topic of our show ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>The ATT&amp;CK Navigator is a web-based tool created and maintained by the Mitre organisation. The tools is used for annotating and exploring ATT&amp;CK matrices. It is often used to visualize defensive coverage, red/blue team planning, the frequency of detected techniques etc.<br/>That is the topic of our show today.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>CISA Adds Barracuda Vulnerability to KEV Catalog</li><li>Microsoft secure boot bug</li></ul><p>- <a href='https://arstechnica.com/information-technology/2023/05/microsoft-patches-secure-boot-flaw-but-wont-enable-fix-by-default-until-early-2024/'>https://arstechnica.com</a>: Microsoft patches secure boot flaw but wont enable fix by default until early 2024<br/>- <a href='https://www.cisa.gov/news-events/alerts/2023/05/26/cisa-adds-one-known-exploited-vulnerability-catalog'>https://www.cisa.gov</a>: CISA adds one known exploited vulnerability catalog<br/>- <a href='https://mitre-attack.github.io/attack-navigator/'>https://mitre-attack.github.io</a>: ATT&amp;CK  Navigator<br/>- <a href='https://mitre-attack.github.io/attack-navigator/'>https://mitre-attack.github.io</a>: ATT&amp;CK Navigator v2 Enterprise<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>The ATT&amp;CK Navigator is a web-based tool created and maintained by the Mitre organisation. The tools is used for annotating and exploring ATT&amp;CK matrices. It is often used to visualize defensive coverage, red/blue team planning, the frequency of detected techniques etc.<br/>That is the topic of our show today.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>CISA Adds Barracuda Vulnerability to KEV Catalog</li><li>Microsoft secure boot bug</li></ul><p>- <a href='https://arstechnica.com/information-technology/2023/05/microsoft-patches-secure-boot-flaw-but-wont-enable-fix-by-default-until-early-2024/'>https://arstechnica.com</a>: Microsoft patches secure boot flaw but wont enable fix by default until early 2024<br/>- <a href='https://www.cisa.gov/news-events/alerts/2023/05/26/cisa-adds-one-known-exploited-vulnerability-catalog'>https://www.cisa.gov</a>: CISA adds one known exploited vulnerability catalog<br/>- <a href='https://mitre-attack.github.io/attack-navigator/'>https://mitre-attack.github.io</a>: ATT&amp;CK  Navigator<br/>- <a href='https://mitre-attack.github.io/attack-navigator/'>https://mitre-attack.github.io</a>: ATT&amp;CK Navigator v2 Enterprise<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12960097-121-the-mitre-att-ck-navigator.mp3" length="24774741" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12960097</guid>
    <pubDate>Sat, 27 May 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2060</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>120 - Demystifying Digital Certificates- Shedding Light on an Obscure yet Crucial Aspect of Online Security - Part 2</itunes:title>
    <title>120 - Demystifying Digital Certificates- Shedding Light on an Obscure yet Crucial Aspect of Online Security - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In this week's episode we will continue with Part 2 on Demystifying Digital Certificates. To take the most out of this week's episode - If you have not listen to Part 1, I suggest you listen to the first before you listen to this episode.  - https://blog.talosintelligence.com: Qakbot levels up with new obfus...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this week&apos;s episode we will continue with Part 2 on Demystifying Digital Certificates.<br/>To take the most out of this week&apos;s episode - If you have not listen to Part 1, I suggest you listen to the first before you listen to this episode.<br/><br/>- <a href='https://blog.talosintelligence.com/qakbot-levels-up-with-new-obfuscation/'>https://blog.talosintelligence.com</a>: Qakbot levels up with new obfuscation<br/><a href='https://www.papercut.com/kb/Main/CommonSecurityQuestions'>https://www.papercut.com</a>: Vulnerability information<br/><a href='https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software'>https://www.huntress.com</a>: Critical vulnerabilities in Papercut print management software<br/>- <a href='https://www.ibm.com/docs/en/integration-bus/10.0?topic=overview-digital-certificates'>https://www.ibm.com</a>: Overview of Digital Certificates</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this week&apos;s episode we will continue with Part 2 on Demystifying Digital Certificates.<br/>To take the most out of this week&apos;s episode - If you have not listen to Part 1, I suggest you listen to the first before you listen to this episode.<br/><br/>- <a href='https://blog.talosintelligence.com/qakbot-levels-up-with-new-obfuscation/'>https://blog.talosintelligence.com</a>: Qakbot levels up with new obfuscation<br/><a href='https://www.papercut.com/kb/Main/CommonSecurityQuestions'>https://www.papercut.com</a>: Vulnerability information<br/><a href='https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software'>https://www.huntress.com</a>: Critical vulnerabilities in Papercut print management software<br/>- <a href='https://www.ibm.com/docs/en/integration-bus/10.0?topic=overview-digital-certificates'>https://www.ibm.com</a>: Overview of Digital Certificates</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12901517-120-demystifying-digital-certificates-shedding-light-on-an-obscure-yet-crucial-aspect-of-online-security-part-2.mp3" length="26538802" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12901517</guid>
    <pubDate>Sat, 20 May 2023 11:00:00 +0400</pubDate>
    <itunes:duration>2207</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>119 - Demystifying Digital Certificates- Shedding Light on an Obscure yet Crucial Aspect of Online Security - Part 1</itunes:title>
    <title>119 - Demystifying Digital Certificates- Shedding Light on an Obscure yet Crucial Aspect of Online Security - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In this episode, I want to shine a brigt light on an important yet frequently misunderstood part of online security: digital certificates. Certificates are essential in today's digital world for safeguarding communication and confirming identities. Nonetheless, they are frequently obscure to many, resulting ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this episode, I want to shine a brigt light on an important yet frequently misunderstood part of online security: digital certificates. Certificates are essential in today&apos;s digital world for safeguarding communication and confirming identities. Nonetheless, they are frequently obscure to many, resulting to confusion and misunderstandings. Join us as we demistify digital certificates, examine their importance, and explain their role in guaranteeing safe and the ever dependable digital communication.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Kali Linux introduces purple team distro</li><li>Apple Fast Update</li></ul><p> - <a href=' https://www.kali.org/blog/kali-linux-2023-1-release/'>https://www.kali.org</a>: Kali-linux-2023-1-release/<br/>- <a href='https://support.apple.com/en-ae/guide/deployment/dep93ff7ea78/web'>https://support.apple.com:</a> Apple  Rapid Security Response<br/>- <a href='https://www.ibm.com/docs/en/integration-bus/10.0?topic=overview-digital-certificates'>https://www.ibm.com</a>: Overview of Digital Certificates</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this episode, I want to shine a brigt light on an important yet frequently misunderstood part of online security: digital certificates. Certificates are essential in today&apos;s digital world for safeguarding communication and confirming identities. Nonetheless, they are frequently obscure to many, resulting to confusion and misunderstandings. Join us as we demistify digital certificates, examine their importance, and explain their role in guaranteeing safe and the ever dependable digital communication.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Kali Linux introduces purple team distro</li><li>Apple Fast Update</li></ul><p> - <a href=' https://www.kali.org/blog/kali-linux-2023-1-release/'>https://www.kali.org</a>: Kali-linux-2023-1-release/<br/>- <a href='https://support.apple.com/en-ae/guide/deployment/dep93ff7ea78/web'>https://support.apple.com:</a> Apple  Rapid Security Response<br/>- <a href='https://www.ibm.com/docs/en/integration-bus/10.0?topic=overview-digital-certificates'>https://www.ibm.com</a>: Overview of Digital Certificates</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12844573-119-demystifying-digital-certificates-shedding-light-on-an-obscure-yet-crucial-aspect-of-online-security-part-1.mp3" length="30399177" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12844573</guid>
    <pubDate>Sat, 13 May 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2529</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>118 - Sealed and delivered - Understanding How Email Protocols Keep You Secure - Part 2</itunes:title>
    <title>118 - Sealed and delivered - Understanding How Email Protocols Keep You Secure - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In the second part of the podcast, we'll delve further into the different types of email security protocols and explore how they can be implemented to enhance the security of your email communications. We'll discuss the benefits of end-to-end encryption, which ensures that only the intended recipient can acc...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In the second part of the podcast, we&apos;ll delve further into the different types of email security protocols and explore how they can be implemented to enhance the security of your email communications. We&apos;ll discuss the benefits of end-to-end encryption, which ensures that only the intended recipient can access the content of your emails, as well as the importance of authentication mechanisms. We&apos;ll also explore the role of digital signatures in verifying the authenticity and integrity of email messages. By the end of this episode, you&apos;ll have a better understanding of how to protect your sensitive information from cyber threats and ensure the confidentiality of your email communications.<br/><br/>If you have not listen to episode 1, I suggest you listen to the first before you listen to this episode.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Google rolls out passkey login for all accounts</li><li>Mirai-iot-botnet is exploiting-tp-link-router you need to patch it now</li></ul><p>- <a href='https://users.ece.cmu.edu/~adrian/630-f04/PGP-intro.html'>https://users.ece.cmu.edu</a>: PGP intro<br/>- <a href='https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-0/user_guide_fs/b_ESA_Admin_Guide_11_0/b_ESA_Admin_Guide_chapter_010011.html'>https://www.cisco.com</a>: S/MIME<br/>- <a href='https://www.cisco.com/c/en/us/products/security/registered-envelope-service/index.html'>https://www.cisco.com</a>:  Registered envelope service<br/>- <a href='https://security.googleblog.com/2023/05/so-long-passwords-thanks-for-all-phish.html'>https://security.googleblog.com</a>: So long passwords thanks for all phish<br/>- <a href=' https://duo.com/decipher/mirai-botnet-attackers-exploit-tp-link-bug'>https://duo.com</a>:  Mirai botnet attackers exploit TP-Link bug</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In the second part of the podcast, we&apos;ll delve further into the different types of email security protocols and explore how they can be implemented to enhance the security of your email communications. We&apos;ll discuss the benefits of end-to-end encryption, which ensures that only the intended recipient can access the content of your emails, as well as the importance of authentication mechanisms. We&apos;ll also explore the role of digital signatures in verifying the authenticity and integrity of email messages. By the end of this episode, you&apos;ll have a better understanding of how to protect your sensitive information from cyber threats and ensure the confidentiality of your email communications.<br/><br/>If you have not listen to episode 1, I suggest you listen to the first before you listen to this episode.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Google rolls out passkey login for all accounts</li><li>Mirai-iot-botnet is exploiting-tp-link-router you need to patch it now</li></ul><p>- <a href='https://users.ece.cmu.edu/~adrian/630-f04/PGP-intro.html'>https://users.ece.cmu.edu</a>: PGP intro<br/>- <a href='https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-0/user_guide_fs/b_ESA_Admin_Guide_11_0/b_ESA_Admin_Guide_chapter_010011.html'>https://www.cisco.com</a>: S/MIME<br/>- <a href='https://www.cisco.com/c/en/us/products/security/registered-envelope-service/index.html'>https://www.cisco.com</a>:  Registered envelope service<br/>- <a href='https://security.googleblog.com/2023/05/so-long-passwords-thanks-for-all-phish.html'>https://security.googleblog.com</a>: So long passwords thanks for all phish<br/>- <a href=' https://duo.com/decipher/mirai-botnet-attackers-exploit-tp-link-bug'>https://duo.com</a>:  Mirai botnet attackers exploit TP-Link bug</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12822995-118-sealed-and-delivered-understanding-how-email-protocols-keep-you-secure-part-2.mp3" length="31918505" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12822995</guid>
    <pubDate>Sat, 06 May 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2656</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>117 - Sealed and delivered - Understanding How Email Protocols Keep You Secure - Part 1</itunes:title>
    <title>117 - Sealed and delivered - Understanding How Email Protocols Keep You Secure - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In the era of messaging apps such as WhatsApp, Telegram and Twitter, emails are still the primary mode of communication for businesses and goverments alike. However, the convenience and ease of email communication also come with significant risks such as phishing, malware attacks, and unauthorized access.&nb...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In the era of messaging apps such as WhatsApp, Telegram and Twitter, emails are still the primary mode of communication for businesses and goverments alike. However, the convenience and ease of email communication also come with significant risks such as phishing, malware attacks, and unauthorized access. <br/>This show aims to provide insights into various email security protocols such as encryption, authentication, and digital signatures, and how they work together to protect your email data from cyber threats.<br/>Join me as I explain the intricacies of email security and uncover the best practices for safeguarding your online communications.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>It was RSA Conference week. We will look into the the hot topics this year.</li><li>Cisco unveiled a compelling net new product XDR</li></ul><p>- <a href='https://www.bankinfosecurity.com/ismg-editors-final-review-rsa-conference-2023-a-21906'>https://www.bankinfosecurity.com</a>: Final Review RSA Conference 2023<br/>- <a href='https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2023/m04/cisco-unveils-new-solution-to-rapidly-detect-advanced-cyber-threats-and-automate-response.html'>https://newsroom.cisco.com</a>: Cisco unveils new solution to rapidly detect advanced cyber threats and automate response<br/>- <a href='https://users.ece.cmu.edu/~adrian/630-f04/PGP-intro.html'>https://users.ece.cmu.edu</a>: PGP intro <br/>- <a href='https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-0/user_guide_fs/b_ESA_Admin_Guide_11_0/b_ESA_Admin_Guide_chapter_010011.html'>https://www.cisco.com</a>: S/MIME<br/>- <a href='https://www.cisco.com/c/en/us/products/security/registered-envelope-service/index.html'>https://www.cisco.com</a>:  Registered envelope service</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In the era of messaging apps such as WhatsApp, Telegram and Twitter, emails are still the primary mode of communication for businesses and goverments alike. However, the convenience and ease of email communication also come with significant risks such as phishing, malware attacks, and unauthorized access. <br/>This show aims to provide insights into various email security protocols such as encryption, authentication, and digital signatures, and how they work together to protect your email data from cyber threats.<br/>Join me as I explain the intricacies of email security and uncover the best practices for safeguarding your online communications.<br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>It was RSA Conference week. We will look into the the hot topics this year.</li><li>Cisco unveiled a compelling net new product XDR</li></ul><p>- <a href='https://www.bankinfosecurity.com/ismg-editors-final-review-rsa-conference-2023-a-21906'>https://www.bankinfosecurity.com</a>: Final Review RSA Conference 2023<br/>- <a href='https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2023/m04/cisco-unveils-new-solution-to-rapidly-detect-advanced-cyber-threats-and-automate-response.html'>https://newsroom.cisco.com</a>: Cisco unveils new solution to rapidly detect advanced cyber threats and automate response<br/>- <a href='https://users.ece.cmu.edu/~adrian/630-f04/PGP-intro.html'>https://users.ece.cmu.edu</a>: PGP intro <br/>- <a href='https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-0/user_guide_fs/b_ESA_Admin_Guide_11_0/b_ESA_Admin_Guide_chapter_010011.html'>https://www.cisco.com</a>: S/MIME<br/>- <a href='https://www.cisco.com/c/en/us/products/security/registered-envelope-service/index.html'>https://www.cisco.com</a>:  Registered envelope service</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12756309-117-sealed-and-delivered-understanding-how-email-protocols-keep-you-secure-part-1.mp3" length="38528948" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12756309</guid>
    <pubDate>Sat, 29 Apr 2023 22:00:00 +0400</pubDate>
    <itunes:duration>3207</itunes:duration>
    <itunes:keywords>117</itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>116 - Classified Chaos - The Persistent Threat of Data Leaks - Part 2</itunes:title>
    <title>116 - Classified Chaos - The Persistent Threat of Data Leaks - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In this week's episode we will continue with Part 2, by continuing at exploring the complex world of data classification systems and the ongoing difficulty of preventing data leaks. If you have not listening to Part 1, I would encourage you to back to the firest episode before you jump no this one. In additi...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.</b><br/><br/>In this week&apos;s episode we will continue with Part 2, by continuing at exploring the complex world of data classification systems and the ongoing difficulty of preventing data leaks.<br/>If you have not listening to Part 1, I would encourage you to back to the firest episode before you jump no this one.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Microsoft SQl Server Hacked to deploy Tripona Ransomware</li><li>Open letter to the UK Gov regarding their Online Safe Bill</li></ul><p>- <a href='https://blog.whatsapp.com/an-open-letter'>https://blog.whatsapp.com:</a> An Open letter<br/>- <a href='https://www.gov.uk/guidance/a-guide-to-the-online-safety-bill'>https://www.gov.uk</a>: A guide to the online safety bill<br/>- <a href='https://www.washingtonpost.com/technology/2023/04/11/fbi-public-phone-charging-stations-juice-jacking/'>https://www.washingtonpost.com</a>: FBI public phone charging stations juice jacking- - <a href='https://www.fcc.gov/juice-jacking-dangers-public-usb-charging-stations'>https://www.fcc.gov</a>: Juice jacking dangers public USB charging stations<br/>- <a href='https://thehackernews.com/2023/04/google-launches-new-cybersecurity.html?m=1'>https://blog.google</a>: New initiatives to-reduce the risk of vulnerabilities and protect researchers<br/>- <a href='https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model'>https://en.wikipedia.org</a>: Bell LaPadula Model<br/>- <a href='https://en.wikipedia.org/wiki/Biba_model'>https://en.wikipedia.org</a>:Biba Model<br/>- <a href='https://en.wikipedia.org/wiki/Clark%E2%80%93Wilson_model'>https://en.wikipedia.org</a>: Clark Wilson Model</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.</b><br/><br/>In this week&apos;s episode we will continue with Part 2, by continuing at exploring the complex world of data classification systems and the ongoing difficulty of preventing data leaks.<br/>If you have not listening to Part 1, I would encourage you to back to the firest episode before you jump no this one.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Microsoft SQl Server Hacked to deploy Tripona Ransomware</li><li>Open letter to the UK Gov regarding their Online Safe Bill</li></ul><p>- <a href='https://blog.whatsapp.com/an-open-letter'>https://blog.whatsapp.com:</a> An Open letter<br/>- <a href='https://www.gov.uk/guidance/a-guide-to-the-online-safety-bill'>https://www.gov.uk</a>: A guide to the online safety bill<br/>- <a href='https://www.washingtonpost.com/technology/2023/04/11/fbi-public-phone-charging-stations-juice-jacking/'>https://www.washingtonpost.com</a>: FBI public phone charging stations juice jacking- - <a href='https://www.fcc.gov/juice-jacking-dangers-public-usb-charging-stations'>https://www.fcc.gov</a>: Juice jacking dangers public USB charging stations<br/>- <a href='https://thehackernews.com/2023/04/google-launches-new-cybersecurity.html?m=1'>https://blog.google</a>: New initiatives to-reduce the risk of vulnerabilities and protect researchers<br/>- <a href='https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model'>https://en.wikipedia.org</a>: Bell LaPadula Model<br/>- <a href='https://en.wikipedia.org/wiki/Biba_model'>https://en.wikipedia.org</a>:Biba Model<br/>- <a href='https://en.wikipedia.org/wiki/Clark%E2%80%93Wilson_model'>https://en.wikipedia.org</a>: Clark Wilson Model</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12718598-116-classified-chaos-the-persistent-threat-of-data-leaks-part-2.mp3" length="26814561" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12718598</guid>
    <pubDate>Sat, 22 Apr 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2230</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>115 - Classified Chaos: The Persistent Threat of Data Leaks - Part 1</itunes:title>
    <title>115 - Classified Chaos: The Persistent Threat of Data Leaks - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In this week's episode, we will explore the complex world of data classification systems and the ongoing difficulty of preventing data leaks in extremely sensitive settings. Even after putting in place reliable classification protocols, extremely sensitive organisations still have to deal with ongoing threat...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this week&apos;s episode, we will explore the complex world of data classification systems and the ongoing difficulty of preventing data leaks in extremely sensitive settings. Even after putting in place reliable classification protocols, extremely sensitive organisations still have to deal with ongoing threats to their most important data. In this podcast, we&apos;ll look at the fundamentals of data classification, their origin and evaluate the systems in use. We will talk about the underlying causes of data leaks, which are still a major issue. <br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Juice Jacking, why charging your devices in public place is a bad thing</li><li>Google launches a new cybersecurity initial. We will look what that entailes</li></ul><p>- <a href='https://www.washingtonpost.com/technology/2023/04/11/fbi-public-phone-charging-stations-juice-jacking/'>https://www.washingtonpost.com</a>: FBI public phone charging stations juice jacking- - <a href='https://www.fcc.gov/juice-jacking-dangers-public-usb-charging-stations'>https://www.fcc.gov</a>: Juice jacking dangers public USB charging stations<br/>- <a href='https://thehackernews.com/2023/04/google-launches-new-cybersecurity.html?m=1'>https://blog.google</a>: New initiatives to-reduce the risk of vulnerabilities and protect researchers<br/>- <a href='https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model'>https://en.wikipedia.org</a>: Bell LaPadula Model<br/>- <a href='https://en.wikipedia.org/wiki/Biba_model'>https://en.wikipedia.org</a>:Biba Model<br/>- <a href='https://en.wikipedia.org/wiki/Clark%E2%80%93Wilson_model'>https://en.wikipedia.org</a>: Clark Wilson Model<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this week&apos;s episode, we will explore the complex world of data classification systems and the ongoing difficulty of preventing data leaks in extremely sensitive settings. Even after putting in place reliable classification protocols, extremely sensitive organisations still have to deal with ongoing threats to their most important data. In this podcast, we&apos;ll look at the fundamentals of data classification, their origin and evaluate the systems in use. We will talk about the underlying causes of data leaks, which are still a major issue. <br/><br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Juice Jacking, why charging your devices in public place is a bad thing</li><li>Google launches a new cybersecurity initial. We will look what that entailes</li></ul><p>- <a href='https://www.washingtonpost.com/technology/2023/04/11/fbi-public-phone-charging-stations-juice-jacking/'>https://www.washingtonpost.com</a>: FBI public phone charging stations juice jacking- - <a href='https://www.fcc.gov/juice-jacking-dangers-public-usb-charging-stations'>https://www.fcc.gov</a>: Juice jacking dangers public USB charging stations<br/>- <a href='https://thehackernews.com/2023/04/google-launches-new-cybersecurity.html?m=1'>https://blog.google</a>: New initiatives to-reduce the risk of vulnerabilities and protect researchers<br/>- <a href='https://en.wikipedia.org/wiki/Bell%E2%80%93LaPadula_model'>https://en.wikipedia.org</a>: Bell LaPadula Model<br/>- <a href='https://en.wikipedia.org/wiki/Biba_model'>https://en.wikipedia.org</a>:Biba Model<br/>- <a href='https://en.wikipedia.org/wiki/Clark%E2%80%93Wilson_model'>https://en.wikipedia.org</a>: Clark Wilson Model<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12655515-115-classified-chaos-the-persistent-threat-of-data-leaks-part-1.mp3" length="29824178" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12655515</guid>
    <pubDate>Sat, 15 Apr 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2481</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>114 - Ensuring Business Continuity Through Strong Security Measures</itunes:title>
    <title>114 - Ensuring Business Continuity Through Strong Security Measures</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In today's digital world, businesses face an increasing number of cyber threats that can disrupt their operations and affect their bottom line. That's why it's more important than ever to have strong security measures in place to protect your organization  In this episodee, we'll discuss how strong security ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In today&apos;s digital world, businesses face an increasing number of cyber threats that can disrupt their operations and affect their bottom line. That&apos;s why it&apos;s more important than ever to have strong security measures in place to protect your organization<br/><br/>In this episodee, we&apos;ll discuss how strong security measures can not only protect your business from cyber threats but also enable continuity and resilience.<br/><br/>In addition, we will recap other  trending  security news  including:<br/><br/>- <a href='https://www.techtarget.com/searchsecurity/news/365534903/Microsoft-Fortra-get-court-order-to-disrupt-Cobalt-Strike#:~:text=Microsoft,%20Fortra%20and%20the%20Health,curb%20malicious%20Cobalt%20Strike%20use.&amp;text=Microsoft%20is%20taking%20technical%20and,commonly%20deployed%20in%20ransomware%20attacks.'>https://www.techtarget.com</a>: Microsoft and Fortra get court order to disrupt Cobalt Strike<br/>- <a href='https://cloud7.news/security/self-extracting-winrar-archives-plant-backdoors/'>https://cloud7.news</a>: WinRAR SFX archives can run PowerShell without being detected<br/>- <a href='https://partners.wsj.com/cisco/powering-an-inclusive-future/how-does-cybersecurity-need-to-change-to-become-a-business-enabler/'>https://partners.wsj.com</a>: How does cybersecurity need to change to become a business enabler<br/>- <a href='https://blogs.cisco.com/security/how-cybersecurity-is-enabling-not-defeating-business-innovation'>https://blogs.cisco.com/Security</a>:  How cybersecurity is enabling not defeating business innovation<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In today&apos;s digital world, businesses face an increasing number of cyber threats that can disrupt their operations and affect their bottom line. That&apos;s why it&apos;s more important than ever to have strong security measures in place to protect your organization<br/><br/>In this episodee, we&apos;ll discuss how strong security measures can not only protect your business from cyber threats but also enable continuity and resilience.<br/><br/>In addition, we will recap other  trending  security news  including:<br/><br/>- <a href='https://www.techtarget.com/searchsecurity/news/365534903/Microsoft-Fortra-get-court-order-to-disrupt-Cobalt-Strike#:~:text=Microsoft,%20Fortra%20and%20the%20Health,curb%20malicious%20Cobalt%20Strike%20use.&amp;text=Microsoft%20is%20taking%20technical%20and,commonly%20deployed%20in%20ransomware%20attacks.'>https://www.techtarget.com</a>: Microsoft and Fortra get court order to disrupt Cobalt Strike<br/>- <a href='https://cloud7.news/security/self-extracting-winrar-archives-plant-backdoors/'>https://cloud7.news</a>: WinRAR SFX archives can run PowerShell without being detected<br/>- <a href='https://partners.wsj.com/cisco/powering-an-inclusive-future/how-does-cybersecurity-need-to-change-to-become-a-business-enabler/'>https://partners.wsj.com</a>: How does cybersecurity need to change to become a business enabler<br/>- <a href='https://blogs.cisco.com/security/how-cybersecurity-is-enabling-not-defeating-business-innovation'>https://blogs.cisco.com/Security</a>:  How cybersecurity is enabling not defeating business innovation<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12614922-114-ensuring-business-continuity-through-strong-security-measures.mp3" length="32757309" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12614922</guid>
    <pubDate>Sat, 08 Apr 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2726</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>113 - Navigating Cloud Security: A Look at Public, Hybrid, and Private Cloud</itunes:title>
    <title>113 - Navigating Cloud Security: A Look at Public, Hybrid, and Private Cloud</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. Cloud computing has become a ubiquitous part of business, but it presents unique security challenges. In this podcast, we'll take a closer look at public, private, and hybrid clouds, discussing the benefits and risks of each so that you are well informed on securing your data and applications in the cloud. Th...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>Cloud computing has become a ubiquitous part of business, but it presents unique security challenges. In this podcast, we&apos;ll take a closer look at public, private, and hybrid clouds, discussing the benefits and risks of each so that you are well informed on securing your data and applications in the cloud. This is going to be engaging as it is informative session on navigating cloud security.</p><ul><li>ChatGPT expose user&apos;s private data</li><li>The United Kingdom’s National Crime Agency (NCA) sets up a fake DDOS for hire service</li></ul><p>- <a href='https://www.cisco.com/c/en_ae/products/security/cloud-security/what-is-cloud-security.html#~types-of-threats'>https://www.cisco.com</a>: What is cloud security<br/>- <a href='https://www.cisco.com/c/en/us/solutions/collateral/enterprise/design-zone-security/safe-secure-cloud-architecture-guide.html'>https://www.cisco.com</a>: Safe secure cloud architecture guide</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>Cloud computing has become a ubiquitous part of business, but it presents unique security challenges. In this podcast, we&apos;ll take a closer look at public, private, and hybrid clouds, discussing the benefits and risks of each so that you are well informed on securing your data and applications in the cloud. This is going to be engaging as it is informative session on navigating cloud security.</p><ul><li>ChatGPT expose user&apos;s private data</li><li>The United Kingdom’s National Crime Agency (NCA) sets up a fake DDOS for hire service</li></ul><p>- <a href='https://www.cisco.com/c/en_ae/products/security/cloud-security/what-is-cloud-security.html#~types-of-threats'>https://www.cisco.com</a>: What is cloud security<br/>- <a href='https://www.cisco.com/c/en/us/solutions/collateral/enterprise/design-zone-security/safe-secure-cloud-architecture-guide.html'>https://www.cisco.com</a>: Safe secure cloud architecture guide</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12593187-113-navigating-cloud-security-a-look-at-public-hybrid-and-private-cloud.mp3" length="30930741" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12593187</guid>
    <pubDate>Sat, 01 Apr 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2573</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>112 - OAuth Protocol - Part 2</itunes:title>
    <title>112 - OAuth Protocol - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In this podcast, we will continue exploring the technical details of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet.  **I would suggest you listen to last week episode first before you listen to this session.**  In addition, we will recap other ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this podcast, we will continue exploring the technical details of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet. <br/>**I would suggest you listen to last week episode first before you listen to this session.**<br/><br/>In addition, we will recap other  trending  security news  including:<br/><br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397'>https://msrc.microsoft.com</a>: Update guide CVE-2023-23397<br/>- <a href='https://www.theregister.com/2022/12/13/pwn2own_wraps/'>https://www.theregister.com</a>: Pwn2Own Wraps<br/>- <a href='https://en.wikipedia.org/wiki/Pwn2Own'>https://en.wikipedia.org</a>: Pwn2Own<br/>- <a href='https://oauth.net/2/'>https://oauth.net</a>: OAuth<br/>- <a href='https://auth0.com/intro-to-iam/what-is-oauth-2'>https://auth0.com</a>: What is 0Auth-2</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this podcast, we will continue exploring the technical details of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet. <br/>**I would suggest you listen to last week episode first before you listen to this session.**<br/><br/>In addition, we will recap other  trending  security news  including:<br/><br/>- <a href='https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397'>https://msrc.microsoft.com</a>: Update guide CVE-2023-23397<br/>- <a href='https://www.theregister.com/2022/12/13/pwn2own_wraps/'>https://www.theregister.com</a>: Pwn2Own Wraps<br/>- <a href='https://en.wikipedia.org/wiki/Pwn2Own'>https://en.wikipedia.org</a>: Pwn2Own<br/>- <a href='https://oauth.net/2/'>https://oauth.net</a>: OAuth<br/>- <a href='https://auth0.com/intro-to-iam/what-is-oauth-2'>https://auth0.com</a>: What is 0Auth-2</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12512529-112-oauth-protocol-part-2.mp3" length="31992368" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12512529</guid>
    <pubDate>Sat, 25 Mar 2023 22:00:00 +0400</pubDate>
    <podcast:soundbite startTime="0.0" duration="30.0" />
    <itunes:duration>2662</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>111 - OAuth Protocol - Part 1</itunes:title>
    <title>111 - OAuth Protocol - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  In this podcast, we will explore the technical intricacies of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet.   OAuth stands for "Open Authorization". It is an open standard for authorization that allows users to grant access to their resources,...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this podcast, we will explore the technical intricacies of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet. <br/><br/>OAuth stands for &quot;Open Authorization&quot;. It is an open standard for authorization that allows users to grant access to their resources, without sharing their credentials (such as username and password) with third-party applications. OAuth is commonly used by social media platforms, APIs, and other web services to allow users to log in or grant access to their accounts without the need for the application to store their sensitive login information.<br/><br/>Whether you&apos;re an experienced cybersecurity professional or a curious learner, join me in this two parts series as we analyze the underlying principles of OAuth, its different implementations, and its role in shaping the future of online security.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li><a href='https://gisec.ae/about-the-show'>https://gisec.ae</a>: GISEC 2023</li><li><a href='https://www.linkedin.com/feed/update/urn:li:activity:7041827881789833216/'>https://www.linkedin.com</a>: My interview with event organiser</li></ul><p>- <a href='https://oauth.net/2/'>https://oauth.net</a>: OAuth<br/>- <a href='https://auth0.com/intro-to-iam/what-is-oauth-2'>https://auth0.com</a>: What is 0Auth-2</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>In this podcast, we will explore the technical intricacies of the OAuth protocol - a widely adopted framework for user authentication and authorization on the internet. <br/><br/>OAuth stands for &quot;Open Authorization&quot;. It is an open standard for authorization that allows users to grant access to their resources, without sharing their credentials (such as username and password) with third-party applications. OAuth is commonly used by social media platforms, APIs, and other web services to allow users to log in or grant access to their accounts without the need for the application to store their sensitive login information.<br/><br/>Whether you&apos;re an experienced cybersecurity professional or a curious learner, join me in this two parts series as we analyze the underlying principles of OAuth, its different implementations, and its role in shaping the future of online security.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li><a href='https://gisec.ae/about-the-show'>https://gisec.ae</a>: GISEC 2023</li><li><a href='https://www.linkedin.com/feed/update/urn:li:activity:7041827881789833216/'>https://www.linkedin.com</a>: My interview with event organiser</li></ul><p>- <a href='https://oauth.net/2/'>https://oauth.net</a>: OAuth<br/>- <a href='https://auth0.com/intro-to-iam/what-is-oauth-2'>https://auth0.com</a>: What is 0Auth-2</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12479656-111-oauth-protocol-part-1.mp3" length="39329119" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12479656</guid>
    <pubDate>Sat, 18 Mar 2023 23:00:00 +0400</pubDate>
    <itunes:duration>3273</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>110 - Know Your Enemy: Why Threat Intelligence Matters</itunes:title>
    <title>110 - Know Your Enemy: Why Threat Intelligence Matters</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  Threat intelligence is crucial in today's cyber landscape to identify and mitigate potential risks before they can cause damage. It involves gathering and analyzing information about potential threats and attackers, allowing organizations to stay one step ahead of cyber threats. Join us on "Know Your Enemy: ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Threat intelligence is crucial in today&apos;s cyber landscape to identify and mitigate potential risks before they can cause damage. It involves gathering and analyzing information about potential threats and attackers, allowing organizations to stay one step ahead of cyber threats. Join us on &quot;Know Your Enemy: Why Threat Intelligence Matters&quot; to learn more about the importance of threat intelligence in keeping your data and systems secure.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Microsoft enables LSA protection by default in Windows</li><li>GitHub Rolling Out Mandatory Multifactor-Factor Authentication for Developers</li></ul><p>-<a href='https://blogs.windows.com/windows-insider/2023/03/08/announcing-windows-11-insider-preview-build-25314/'>https://blogs.windows.com</a>: Introducing LSA Protection Enablement on Upgrade<br/>- <a href='https://www.cisco.com/c/dam/global/en_sg/assets/pdfs/the-importance-of-threat-intel-by-benny-ketelslegers.pdf'>https://www.cisco.com</a>: The importance of Threat Intelligence and how<br/>Cisco Talos uses intelligence to protect customers<br/>- <a href='https://blogs.cisco.com/developer/threat-intelligence-securex-api'>https://blogs.cisco.com</a>: Threat intelligence SecureX API</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Threat intelligence is crucial in today&apos;s cyber landscape to identify and mitigate potential risks before they can cause damage. It involves gathering and analyzing information about potential threats and attackers, allowing organizations to stay one step ahead of cyber threats. Join us on &quot;Know Your Enemy: Why Threat Intelligence Matters&quot; to learn more about the importance of threat intelligence in keeping your data and systems secure.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Microsoft enables LSA protection by default in Windows</li><li>GitHub Rolling Out Mandatory Multifactor-Factor Authentication for Developers</li></ul><p>-<a href='https://blogs.windows.com/windows-insider/2023/03/08/announcing-windows-11-insider-preview-build-25314/'>https://blogs.windows.com</a>: Introducing LSA Protection Enablement on Upgrade<br/>- <a href='https://www.cisco.com/c/dam/global/en_sg/assets/pdfs/the-importance-of-threat-intel-by-benny-ketelslegers.pdf'>https://www.cisco.com</a>: The importance of Threat Intelligence and how<br/>Cisco Talos uses intelligence to protect customers<br/>- <a href='https://blogs.cisco.com/developer/threat-intelligence-securex-api'>https://blogs.cisco.com</a>: Threat intelligence SecureX API</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12423266-110-know-your-enemy-why-threat-intelligence-matters.mp3" length="26786005" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12423266</guid>
    <pubDate>Sat, 11 Mar 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2228</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>109 - Finding malware in encrypted traffic</itunes:title>
    <title>109 - Finding malware in encrypted traffic</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  Remember when the Internet was unencrypted? Yes, there was a time when security was the exception rather than the default. That is to say the majority of the Internet traffic was served over HTTP rather than HTTPS. Fastfoward to today and it is unconceivable to access any website without the lock sign on the...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Remember when the Internet was unencrypted? Yes, there was a time when security was the exception rather than the default. That is to say the majority of the Internet traffic was served over HTTP rather than HTTPS.<br/>Fastfoward to today and it is unconceivable to access any website without the lock sign on the browser url field. That is because privacy by way of using encryption became a thing to protect us from prying eyes ready to steal your private information. Unfortunately, the same tool -encryption that is, provide a cloak for the the crooks to hide their malware and other navarious artifacts inside the encrypted traffic. How do you find these malware in an encrypted traffic without decrypting it? That is the topic of the today&apos;s episode.<br/><br/>In addition, we will recap other  trending  security news  includes</p><ul><li>Lastpass&apos;s latest Update</li><li>Google&apos;s gmail client side encryption is now publicly available</li></ul><p>- <a href='https://support.lastpass.com/help/incident-2-additional-details-of-the-attack'>https://support.lastpass.com/help</a>: Incident 2 additional details of the attack<br/>-<a href='https://workspace.google.com/blog/product-announcements/gmail-and-calendar-client-side-encryption'> https://workspace.google.com/blog</a>:  Gmail and calendar client side encryption<br/>- <a href='https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/enterprise-network-security/nb-09-encrytd-traf-anlytcs-wp-cte-en.html'>https://www.cisco.com</a>: Encrypted Traffic Analytics<br/>- <a href='https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2019/pdf/BRKSEC-1000.pdf'>https://www.ciscolive.com</a>: Operationalizing Encrypted Traffic Analytics</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Remember when the Internet was unencrypted? Yes, there was a time when security was the exception rather than the default. That is to say the majority of the Internet traffic was served over HTTP rather than HTTPS.<br/>Fastfoward to today and it is unconceivable to access any website without the lock sign on the browser url field. That is because privacy by way of using encryption became a thing to protect us from prying eyes ready to steal your private information. Unfortunately, the same tool -encryption that is, provide a cloak for the the crooks to hide their malware and other navarious artifacts inside the encrypted traffic. How do you find these malware in an encrypted traffic without decrypting it? That is the topic of the today&apos;s episode.<br/><br/>In addition, we will recap other  trending  security news  includes</p><ul><li>Lastpass&apos;s latest Update</li><li>Google&apos;s gmail client side encryption is now publicly available</li></ul><p>- <a href='https://support.lastpass.com/help/incident-2-additional-details-of-the-attack'>https://support.lastpass.com/help</a>: Incident 2 additional details of the attack<br/>-<a href='https://workspace.google.com/blog/product-announcements/gmail-and-calendar-client-side-encryption'> https://workspace.google.com/blog</a>:  Gmail and calendar client side encryption<br/>- <a href='https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/enterprise-network-security/nb-09-encrytd-traf-anlytcs-wp-cte-en.html'>https://www.cisco.com</a>: Encrypted Traffic Analytics<br/>- <a href='https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2019/pdf/BRKSEC-1000.pdf'>https://www.ciscolive.com</a>: Operationalizing Encrypted Traffic Analytics</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12390850-109-finding-malware-in-encrypted-traffic.mp3" length="43246886" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12390850</guid>
    <pubDate>Sat, 04 Mar 2023 22:00:00 +0400</pubDate>
    <itunes:duration>3600</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>108 - Securing your home network</itunes:title>
    <title>108 - Securing your home network</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. In today's hybrid world it is important to take your home network security seriously. After all what happens at home  can crawl its way to to the corporate network. In today's episode we look at some measure you should take to mitigate most of the risks introduced  by lax or non-existing security hy...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>In today&apos;s hybrid world it is important to take your home network security seriously. After all what happens at home  can crawl its way to to the corporate network. In today&apos;s episode we look at some measure you should take to mitigate most of the risks introduced  by lax or non-existing security hygiene.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/><br/>- <a href='https://techcommunity.microsoft.com/t5/exchange-team-blog/update-on-the-exchange-server-antivirus-exclusions/ba-p/3751464'>https://techcommunity.microsoft.com</a>: Update on the exchange server antivirus exclusions<br/> - <a href='https://www.fortiguard.com/psirt/FG-IR-22-398'>https://www.fortiguard.com</a>: FG-IR-22-398<br/>-<a href='https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF'>https://media.defense.gov</a>: CSI best practice for securing your home network<br/>- <a href='https://www.cisco.com/c/dam/m/en_hk/products/meraki/5-simple-ways-to-secure-your-network.pdf'>https://www.cisco.com</a>: 5 simple ways to secure your network <br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>In today&apos;s hybrid world it is important to take your home network security seriously. After all what happens at home  can crawl its way to to the corporate network. In today&apos;s episode we look at some measure you should take to mitigate most of the risks introduced  by lax or non-existing security hygiene.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/><br/>- <a href='https://techcommunity.microsoft.com/t5/exchange-team-blog/update-on-the-exchange-server-antivirus-exclusions/ba-p/3751464'>https://techcommunity.microsoft.com</a>: Update on the exchange server antivirus exclusions<br/> - <a href='https://www.fortiguard.com/psirt/FG-IR-22-398'>https://www.fortiguard.com</a>: FG-IR-22-398<br/>-<a href='https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF'>https://media.defense.gov</a>: CSI best practice for securing your home network<br/>- <a href='https://www.cisco.com/c/dam/m/en_hk/products/meraki/5-simple-ways-to-secure-your-network.pdf'>https://www.cisco.com</a>: 5 simple ways to secure your network <br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12328961-108-securing-your-home-network.mp3" length="33768492" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12328961</guid>
    <pubDate>Sat, 25 Feb 2023 12:00:00 +0400</pubDate>
    <itunes:duration>2810</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>107 - Understanding CVSS Scoring System </itunes:title>
    <title>107 - Understanding CVSS Scoring System </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. When a vulnerability is discovered, reported ang  assigned a score called a CVE its impacts must be understood beyond the CVE number.  A common method information security specialists use for this process is the [Common Vulnerability Scoring System (CVSS)](https://www.first.org/cvss/).  That is...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>When a vulnerability is discovered, reported ang  assigned a score called a CVE its impacts must be understood beyond the CVE number.  A common method information security specialists use for this process is the [Common Vulnerability Scoring System (CVSS)](https://www.first.org/cvss/).  That is the topic of this week episode.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Atlasian data leak was caused by an employee&apos;s stolen credential</li><li>Cisco issued a fix for ClamAV </li></ul><p>- <a href='https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy'>https://sec.cloudapps.cisco.com</a>: ClamAV HFS+ Partition Scanning Buffer Overflow Vulnerability Affecting Cisco Products: February 2023</p><p>- <a href='https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20032'>https://cve.mitre.org</a>: CVE-2023-20032<br/>- <a href='https://www.first.org/cvss/'>https://www.first.org</a>: CVSS Specification Document</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>When a vulnerability is discovered, reported ang  assigned a score called a CVE its impacts must be understood beyond the CVE number.  A common method information security specialists use for this process is the [Common Vulnerability Scoring System (CVSS)](https://www.first.org/cvss/).  That is the topic of this week episode.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Atlasian data leak was caused by an employee&apos;s stolen credential</li><li>Cisco issued a fix for ClamAV </li></ul><p>- <a href='https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy'>https://sec.cloudapps.cisco.com</a>: ClamAV HFS+ Partition Scanning Buffer Overflow Vulnerability Affecting Cisco Products: February 2023</p><p>- <a href='https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20032'>https://cve.mitre.org</a>: CVE-2023-20032<br/>- <a href='https://www.first.org/cvss/'>https://www.first.org</a>: CVSS Specification Document</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12295502-107-understanding-cvss-scoring-system.mp3" length="30523159" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12295502</guid>
    <pubDate>Sat, 18 Feb 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2539</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>106 - Optimise your last line of defense</itunes:title>
    <title>106 - Optimise your last line of defense</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Ensuring an optimum setup of your toolsets is a critical part of the your ongoing mitigation effort. Is this episode we will look at the do's and don't of setting up your endpoint detection and response: ESXiArgs ransomware puts the heat onNIST selects a lightweight cryptography.- www.nist.gov: NIST Selects ‘Lightweight Cryptography’ Algorithms to Protect Small Devices - csrc.nist.gov: Lightweight Cryptography - www.theregister.com: Uncle Sam w...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Ensuring an optimum setup of your toolsets is a critical part of the your ongoing mitigation effort.<br/>Is this episode we will look at the do&apos;s and don&apos;t of setting up your endpoint detection and response:</p><ul><li>ESXiArgs ransomware puts the heat on</li><li>NIST selects a lightweight cryptography.</li></ul><p><b>- </b><a href='https://www.nist.gov/news-events/news/2023/02/nist-selects-lightweight-cryptography-algorithms-protect-small-devices'><b>www.nist.gov</b></a>: NIST Selects ‘Lightweight Cryptography’ Algorithms to Protect Small Devices<br/><b>- </b><a href='https://csrc.nist.gov/projects/lightweight-cryptography'><b>csrc.nist.gov</b></a>: Lightweight Cryptography<br/><b>- </b><a href='https://www.theregister.com/2023/02/09/nist_iot_hpc_algorithms/'><b>www.theregister.com</b></a>: Uncle Sam wants to strip the IoS out of IoT with light crypto<br/><b>- </b><a href='https://www.zdnet.com/article/tiny-iot-devices-are-getting-their-own-special-encryption-algorithms/'><b>www.zdnet.com</b></a>: Tiny IoT devices are getting their own special encryption algorithms<br/><b>- </b><a href='https://www.cisa.gov/uscert/ncas/alerts/aa23-039a'><b>www.cisa.gov</b></a>: ESXiArgs Ransomware Virtual Machine Recovery Guidance<br/><b>- </b><a href='https://github.com/cisagov/ESXiArgs-Recover'><b>github.com</b></a>: ESXiArgs-Recover<br/><b>- </b><a href='https://www.theregister.com/2023/02/08/esxiargs_ransomware_recovery_script/'><b>www.theregister.com</b></a>: Among the thousands of ESXiArgs ransomware victims? FBI and CISA to the rescue<br/>-<a href='https://blogs.cisco.com/customerexperience/an-easier-way-to-secure-your-endpoints'>https://blogs.cisco.com</a>: An easier way to secure your endpoints<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Ensuring an optimum setup of your toolsets is a critical part of the your ongoing mitigation effort.<br/>Is this episode we will look at the do&apos;s and don&apos;t of setting up your endpoint detection and response:</p><ul><li>ESXiArgs ransomware puts the heat on</li><li>NIST selects a lightweight cryptography.</li></ul><p><b>- </b><a href='https://www.nist.gov/news-events/news/2023/02/nist-selects-lightweight-cryptography-algorithms-protect-small-devices'><b>www.nist.gov</b></a>: NIST Selects ‘Lightweight Cryptography’ Algorithms to Protect Small Devices<br/><b>- </b><a href='https://csrc.nist.gov/projects/lightweight-cryptography'><b>csrc.nist.gov</b></a>: Lightweight Cryptography<br/><b>- </b><a href='https://www.theregister.com/2023/02/09/nist_iot_hpc_algorithms/'><b>www.theregister.com</b></a>: Uncle Sam wants to strip the IoS out of IoT with light crypto<br/><b>- </b><a href='https://www.zdnet.com/article/tiny-iot-devices-are-getting-their-own-special-encryption-algorithms/'><b>www.zdnet.com</b></a>: Tiny IoT devices are getting their own special encryption algorithms<br/><b>- </b><a href='https://www.cisa.gov/uscert/ncas/alerts/aa23-039a'><b>www.cisa.gov</b></a>: ESXiArgs Ransomware Virtual Machine Recovery Guidance<br/><b>- </b><a href='https://github.com/cisagov/ESXiArgs-Recover'><b>github.com</b></a>: ESXiArgs-Recover<br/><b>- </b><a href='https://www.theregister.com/2023/02/08/esxiargs_ransomware_recovery_script/'><b>www.theregister.com</b></a>: Among the thousands of ESXiArgs ransomware victims? FBI and CISA to the rescue<br/>-<a href='https://blogs.cisco.com/customerexperience/an-easier-way-to-secure-your-endpoints'>https://blogs.cisco.com</a>: An easier way to secure your endpoints<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12234882-106-optimise-your-last-line-of-defense.mp3" length="39227577" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12234882</guid>
    <pubDate>Sat, 11 Feb 2023 22:00:00 +0400</pubDate>
    <itunes:duration>3265</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>105 - Be prepared for the next password manager breach</itunes:title>
    <title>105 - Be prepared for the next password manager breach</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  Password security is an essential aspect of online safety. You and I know, remembering all the passwords can be overwhelming. This is where password managers come in, providing a convenient and secure means keep your password in one place. However, with the recent breach at LastPass, it's important to unders...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Password security is an essential aspect of online safety. You and I know, remembering all the passwords can be overwhelming. This is where password managers come in, providing a convenient and secure means keep your password in one place. However, with the recent breach at LastPass, it&apos;s important to understand the potential risks and take the necessary steps now in the event of a password manager breach. Why, because once it is breached it is too late. In this article, we will explore the measures you can take to prepare yourself for a password manager breach and keep your online accounts secure.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/>Microsoft is urging organisation with Exchange on premise to patch sooner rather than later<br/><br/>- <a href='https://techcommunity.microsoft.com/t5/exchange-team-blog/protect-your-exchange-servers/ba-p/3726001'>techcommunity.microsoft.com</a>: Protect Your Exchange Servers<br/>- <a href='https://www.bleepingcomputer.com/news/security/microsoft-urges-admins-to-patch-on-premises-exchange-servers/'>www.bleepingcomputer.com</a>: Microsoft urges admins to patch on-premises Exchange servers<br/>- <a href='https://microsoft.github.io/CSS-Exchange/Diagnostics/HealthChecker/'>https://microsoft.github.io</a>: Microsoft Exchange Health Checker<br/>- <a href='https://www.grc.com/haystack.htm'>https://www.grc.com</a>: How strong is your password<br/> - <a href='https://haveibeenpwned.com/'>https://haveibeenpwned.com</a>: Have I been Pawne?<br/> - <a href='https://www.itsasap.com/blog/nist-password-guidelines https://xkcd.com/936/'>https://www.itsasap.com:</a> NIST  passwordguidelines<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>Password security is an essential aspect of online safety. You and I know, remembering all the passwords can be overwhelming. This is where password managers come in, providing a convenient and secure means keep your password in one place. However, with the recent breach at LastPass, it&apos;s important to understand the potential risks and take the necessary steps now in the event of a password manager breach. Why, because once it is breached it is too late. In this article, we will explore the measures you can take to prepare yourself for a password manager breach and keep your online accounts secure.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/>Microsoft is urging organisation with Exchange on premise to patch sooner rather than later<br/><br/>- <a href='https://techcommunity.microsoft.com/t5/exchange-team-blog/protect-your-exchange-servers/ba-p/3726001'>techcommunity.microsoft.com</a>: Protect Your Exchange Servers<br/>- <a href='https://www.bleepingcomputer.com/news/security/microsoft-urges-admins-to-patch-on-premises-exchange-servers/'>www.bleepingcomputer.com</a>: Microsoft urges admins to patch on-premises Exchange servers<br/>- <a href='https://microsoft.github.io/CSS-Exchange/Diagnostics/HealthChecker/'>https://microsoft.github.io</a>: Microsoft Exchange Health Checker<br/>- <a href='https://www.grc.com/haystack.htm'>https://www.grc.com</a>: How strong is your password<br/> - <a href='https://haveibeenpwned.com/'>https://haveibeenpwned.com</a>: Have I been Pawne?<br/> - <a href='https://www.itsasap.com/blog/nist-password-guidelines https://xkcd.com/936/'>https://www.itsasap.com:</a> NIST  passwordguidelines<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12191764-105-be-prepared-for-the-next-password-manager-breach.mp3" length="27518583" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12191764</guid>
    <pubDate>Sat, 04 Feb 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2289</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>104 - What is NetFlow Protocol used for? - Part 2</itunes:title>
    <title>104 - What is NetFlow Protocol used for? - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. We will continue last week's topic on "What is Netflow Protocol used for". This is part 2.  If you have not listen to last week's show, I suggest you listen to Part 1 first. In addition, we will recap other  trending  security news  including: Could Pakistan's nationwide power outage been ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>We will continue last week&apos;s topic on &quot;What is Netflow Protocol used for&quot;. This is part 2.  If you have not listen to last week&apos;s show, I suggest you listen to Part 1 first.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Could Pakistan&apos;s nationwide power outage been caused by a cyber attack?</li><li>GoTo, the parent company of LastPass was also breached.</li></ul><p>-<a href='https://therecord.media/pakistani-authorities-investigating-if-cyberattack-caused-nationwide-blackout/'>https://therecord.media</a>: Pakistani authorities investigating if cyberattack caused nationwide-blackout<br/>- <a href='https://www.goto.com/blog/our-response-to-a-recent-security-incident'>https://www.goto.com/blog</a>: Our response to a recent security incident<br/>- <a href='https://ipcisco.com/lesson/netflow-and-netflow-configuration/'>https://ipcisco.com</a>: Netflow and Netflow Configuration<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>We will continue last week&apos;s topic on &quot;What is Netflow Protocol used for&quot;. This is part 2.  If you have not listen to last week&apos;s show, I suggest you listen to Part 1 first.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Could Pakistan&apos;s nationwide power outage been caused by a cyber attack?</li><li>GoTo, the parent company of LastPass was also breached.</li></ul><p>-<a href='https://therecord.media/pakistani-authorities-investigating-if-cyberattack-caused-nationwide-blackout/'>https://therecord.media</a>: Pakistani authorities investigating if cyberattack caused nationwide-blackout<br/>- <a href='https://www.goto.com/blog/our-response-to-a-recent-security-incident'>https://www.goto.com/blog</a>: Our response to a recent security incident<br/>- <a href='https://ipcisco.com/lesson/netflow-and-netflow-configuration/'>https://ipcisco.com</a>: Netflow and Netflow Configuration<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12138564-104-what-is-netflow-protocol-used-for-part-2.mp3" length="29934795" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12138564</guid>
    <pubDate>Sat, 28 Jan 2023 23:00:00 +0400</pubDate>
    <itunes:duration>2490</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>103 - What is NetFlow Protocol used for? - Part 1</itunes:title>
    <title>103 - What is NetFlow Protocol used for? - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. This week, lets have  look at one of those protocols that often under-used by analyst. It is a way to look at the data that traverse your network to pinpoint what might be lurking beneath the surface. We will cover this in two parts. This is part 1. More on that later. In addition, we will recap other&nb...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>This week, lets have  look at one of those protocols that often under-used by analyst. It is a way to look at the data that traverse your network to pinpoint what might be lurking beneath the surface. We will cover this in two parts. This is part 1. More on that later.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Microsoft is knocking on the door to see if you are sitting on an unsupported uninstalling</li><li>Old Cisco Routers susceptible to RCE attack</li></ul><p>- <a href='https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5#workarounds:~:text=Block%20Access%20to%20Ports%20443%20and%2060443'>https://sec.cloudapps.cisco.com</a>: Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Vulnerabilities<br/>- <a href='https://support.microsoft.com/en-au/topic/january-17-2023-update-for-office-2013-office-2010-and-office-2007-kb5021751-f4a23c1d-4d1f-44ba-a43a-7a5528afb4ea'>https://support.microsoft.com</a>: Update for Office 2013 Office 2010 and Office 2007<br/>- <a href='https://ipcisco.com/lesson/netflow-and-netflow-configuration/'>https://ipcisco.com</a>: Netflow and Netflow Configuration</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>This week, lets have  look at one of those protocols that often under-used by analyst. It is a way to look at the data that traverse your network to pinpoint what might be lurking beneath the surface. We will cover this in two parts. This is part 1. More on that later.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Microsoft is knocking on the door to see if you are sitting on an unsupported uninstalling</li><li>Old Cisco Routers susceptible to RCE attack</li></ul><p>- <a href='https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5#workarounds:~:text=Block%20Access%20to%20Ports%20443%20and%2060443'>https://sec.cloudapps.cisco.com</a>: Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Vulnerabilities<br/>- <a href='https://support.microsoft.com/en-au/topic/january-17-2023-update-for-office-2013-office-2010-and-office-2007-kb5021751-f4a23c1d-4d1f-44ba-a43a-7a5528afb4ea'>https://support.microsoft.com</a>: Update for Office 2013 Office 2010 and Office 2007<br/>- <a href='https://ipcisco.com/lesson/netflow-and-netflow-configuration/'>https://ipcisco.com</a>: Netflow and Netflow Configuration</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12099454-103-what-is-netflow-protocol-used-for-part-1.mp3" length="23421215" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12099454</guid>
    <pubDate>Sat, 21 Jan 2023 22:00:00 +0400</pubDate>
    <itunes:duration>1948</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>102 - OSQuery</itunes:title>
    <title>102 - OSQuery</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.  As a security analyst, you investigate. You want to query devices as part of your investigation of security incidents or maybe you are working to determine the effectiveness of a security control. So you always need real-time, granular inventory data about the systems you want to look at.  In this week's epi...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>As a security analyst, you investigate. You want to query devices as part of your investigation of security incidents or maybe you are working to determine the effectiveness of a security control. So you always need real-time, granular inventory data about the systems you want to look at.<br/><br/>In this week&apos;s episode we touch one of those tools that makes a security analyst&apos;s life a lot less painful: OSQuery.<br/><br/>In addition, we will recap other  trending  security news, including:</p><ul><li>UK Royal Mail Ransomware Attack</li><li>ChatGPT-Written Malware</li></ul><p>-<a href='https://personal.help.royalmail.com/app/answers/detail/a_id/12556'>https://personal.help.royalmail.com</a>: Service Update<br/>- <a href='https://www.telegraph.co.uk/business/2023/01/11/parcels-letters-stuck-limbo-royal-mail-hit-suspected-hack/'>https://www.telegraph.co.uk</a>  Parcels letters stuck limbo royal mail hit suspected hack<br/>- <a href='https://arstechnica.com/information-technology/2023/01/chatgpt-is-enabling-script-kiddies-to-write-functional-malware/'>https://arstechnica.com/information-technology</a>: ChatGPT is enabling script kiddies to write functional malware<br/>- <a href='https://openai.com/blog/chatgpt/'>https://openai.com</a>: ChatGPT<br/>- <a href='https://www.osquery.io/'>https://www.osquery.io</a>: OSQuery</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/><br/>As a security analyst, you investigate. You want to query devices as part of your investigation of security incidents or maybe you are working to determine the effectiveness of a security control. So you always need real-time, granular inventory data about the systems you want to look at.<br/><br/>In this week&apos;s episode we touch one of those tools that makes a security analyst&apos;s life a lot less painful: OSQuery.<br/><br/>In addition, we will recap other  trending  security news, including:</p><ul><li>UK Royal Mail Ransomware Attack</li><li>ChatGPT-Written Malware</li></ul><p>-<a href='https://personal.help.royalmail.com/app/answers/detail/a_id/12556'>https://personal.help.royalmail.com</a>: Service Update<br/>- <a href='https://www.telegraph.co.uk/business/2023/01/11/parcels-letters-stuck-limbo-royal-mail-hit-suspected-hack/'>https://www.telegraph.co.uk</a>  Parcels letters stuck limbo royal mail hit suspected hack<br/>- <a href='https://arstechnica.com/information-technology/2023/01/chatgpt-is-enabling-script-kiddies-to-write-functional-malware/'>https://arstechnica.com/information-technology</a>: ChatGPT is enabling script kiddies to write functional malware<br/>- <a href='https://openai.com/blog/chatgpt/'>https://openai.com</a>: ChatGPT<br/>- <a href='https://www.osquery.io/'>https://www.osquery.io</a>: OSQuery</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12054307-102-osquery.mp3" length="30800839" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12054307</guid>
    <pubDate>Sat, 14 Jan 2023 22:00:00 +0400</pubDate>
    <itunes:duration>2563</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>101- Atomic Red Team</itunes:title>
    <title>101- Atomic Red Team</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english. I hope you had a good start with 2023!  Our first episode of the year is all about the Red Teaming tools. We will look at an open source testing and validation library call Atomic Read Team. In addition, we will recap other  trending  security news  includes: Apple's iCloud encryptionAmazo...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>I hope you had a good start with 2023! <br/>Our first episode of the year is all about the Red Teaming tools. We will look at an open source testing and validation library call Atomic Read Team.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Apple&apos;s iCloud encryption</li><li>Amazon S3 will now encrypt all new data</li></ul><p>- <a href='https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/'>https://aws.amazon.com</a>:  Amazon S3 encrypts new objects by default<br/>- <a href='https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/#:~:text=%E2%80%9CAdvanced%20Data%20Protection%20is%20Apple&apos;s,Protection%20keeps%20most%20iCloud%20data'>https://www.apple.com</a>: Apple new data encryption<br/>- <a href='https://github.com/redcanaryco/atomic-red-team'>https://github.com</a>:  Atomic Red Team github<br/>- <a href='https://github.com/redcanaryco/atomic-red-team/wiki/Getting-started'>https://github.com</a>: Atomic Red Team getting started<br/>- <a href='https://github.com/redcanaryco/atomic-red-team/wiki/FAQs Be sure to subscribe!'>https://github.com</a>: Atomic Red Team FAQs<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Thanks for tuning in to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites, in plain english.<br/>I hope you had a good start with 2023! <br/>Our first episode of the year is all about the Red Teaming tools. We will look at an open source testing and validation library call Atomic Read Team.<br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Apple&apos;s iCloud encryption</li><li>Amazon S3 will now encrypt all new data</li></ul><p>- <a href='https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/'>https://aws.amazon.com</a>:  Amazon S3 encrypts new objects by default<br/>- <a href='https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/#:~:text=%E2%80%9CAdvanced%20Data%20Protection%20is%20Apple&apos;s,Protection%20keeps%20most%20iCloud%20data'>https://www.apple.com</a>: Apple new data encryption<br/>- <a href='https://github.com/redcanaryco/atomic-red-team'>https://github.com</a>:  Atomic Red Team github<br/>- <a href='https://github.com/redcanaryco/atomic-red-team/wiki/Getting-started'>https://github.com</a>: Atomic Red Team getting started<br/>- <a href='https://github.com/redcanaryco/atomic-red-team/wiki/FAQs Be sure to subscribe!'>https://github.com</a>: Atomic Red Team FAQs<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/12008308-101-atomic-red-team.mp3" length="37361767" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-12008308</guid>
    <pubDate>Sat, 07 Jan 2023 23:00:00 +0400</pubDate>
    <itunes:duration>3109</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>100 - The Best of 2022</itunes:title>
    <title>100 - The Best of 2022</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome to YusufOnSecurity episode 100! Perfect timing to finish off the year with the 100th episode!  As it is customary and being the end of the year, we will go back to the best of 2021 episodes. There are quite a few popular ones. Enjoy!  Just last like last year the YusufOnSecurity podcast kept me in cadence on this fast evolving threat landscape. I learned a great deal of stuff while researching and putting the past 52 episode together. I...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity episode 100! Perfect timing to finish off the year with the 100th episode!<br/><br/>As it is customary and being the end of the year, we will go back to the best of 2021 episodes. There are quite a few popular ones. Enjoy!<br/><br/>Just last like last year the YusufOnSecurity podcast kept me in cadence on this fast evolving threat landscape. I learned a great deal of stuff while researching and putting the past 52 episode together. I hope it help you some ways too.<br/>On to another year!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity episode 100! Perfect timing to finish off the year with the 100th episode!<br/><br/>As it is customary and being the end of the year, we will go back to the best of 2021 episodes. There are quite a few popular ones. Enjoy!<br/><br/>Just last like last year the YusufOnSecurity podcast kept me in cadence on this fast evolving threat landscape. I learned a great deal of stuff while researching and putting the past 52 episode together. I hope it help you some ways too.<br/>On to another year!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11960039-100-the-best-of-2022.mp3" length="93658417" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11960039</guid>
    <pubDate>Sat, 31 Dec 2022 22:00:00 +0400</pubDate>
    <itunes:duration>7801</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>99 - Revisiting the impactful major 2022 cybersecurity events</itunes:title>
    <title>99 - Revisiting the impactful major 2022 cybersecurity events</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! 2022, what a year it has been! in our 99th episode which nicely coincides the year end we are look back at the rear view mirror to revisit the big cybersecurity events. so bacle up because it will be an eventfull listening!  - https://blog.talosintelligence.com: Talos-year in review 2022 - https://cybersecurityventures.com: Cybersecurity Almanac 2022 (included this for you to review the prediction that was made then) Be sure to subscribe! ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>2022, what a year it has been! in our 99th episode which nicely coincides the year end we are look back at the rear view mirror to revisit the big cybersecurity events. so bacle up because it will be an eventfull listening!<br/><br/>- <a href='https://blog.talosintelligence.com/talos-year-in-review-2022/'>https://blog.talosintelligence.com</a>: Talos-year in review 2022<br/>- <a href='https://cybersecurityventures.com/cybersecurity-almanac-2022/'>https://cybersecurityventures.com</a>: Cybersecurity Almanac 2022 (included this for you to review the prediction that was made then)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>2022, what a year it has been! in our 99th episode which nicely coincides the year end we are look back at the rear view mirror to revisit the big cybersecurity events. so bacle up because it will be an eventfull listening!<br/><br/>- <a href='https://blog.talosintelligence.com/talos-year-in-review-2022/'>https://blog.talosintelligence.com</a>: Talos-year in review 2022<br/>- <a href='https://cybersecurityventures.com/cybersecurity-almanac-2022/'>https://cybersecurityventures.com</a>: Cybersecurity Almanac 2022 (included this for you to review the prediction that was made then)</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11951384-99-revisiting-the-impactful-major-2022-cybersecurity-events.mp3" length="18038342" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11951384</guid>
    <pubDate>Sat, 24 Dec 2022 09:00:00 +0400</pubDate>
    <itunes:duration>1499</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>98 - Post-Compromise</itunes:title>
    <title>98 - Post-Compromise</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is often said, attacks are when and not if they will happen at all. However, when they happen what matters is how hard you fall, scope and recover. In this week's episode,  I will talk about the steps taken by attackers  when they successfully breach organisations so that you can limit the damage and recover faster.  In addition, we will recap other  trending  security news  includes:  - https://www.redhat.com: RedHa...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is often said, attacks are when and not if they will happen at all. However, when they happen what matters is how hard you fall, scope and recover.<br/>In this week&apos;s episode,  I will talk about the steps taken by attackers  when they successfully breach organisations so that you can limit the damage and recover faster.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/><br/>- <a href='https://www.redhat.com/en/blog/cryptographic-signatures-zip-distributions'>https://www.redhat.com</a>: RedHat started to sign its zip files<br/>- <a href='https://www.sans.org/mlp/holiday-hack-challenge/'>https://www.sans.org</a>: Holiday Hack Challenge<br/>- <a href='https://attack.mitre.org/techniques/enterprise/'>https://attack.mitre.org</a>: Techniques<br/>- <a href='https://attack.mitre.org/tactics/TA0042/'>https://attack.mitre.org</a>: TA0042<br/>- <a href='https://www.cisa.gov/uscert/ncas/alerts/aa21-077a'>https://www.cisa.gov/uscert</a>: CISA Hunt and Incident Response Program (CHIRP) tool<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is often said, attacks are when and not if they will happen at all. However, when they happen what matters is how hard you fall, scope and recover.<br/>In this week&apos;s episode,  I will talk about the steps taken by attackers  when they successfully breach organisations so that you can limit the damage and recover faster.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/><br/>- <a href='https://www.redhat.com/en/blog/cryptographic-signatures-zip-distributions'>https://www.redhat.com</a>: RedHat started to sign its zip files<br/>- <a href='https://www.sans.org/mlp/holiday-hack-challenge/'>https://www.sans.org</a>: Holiday Hack Challenge<br/>- <a href='https://attack.mitre.org/techniques/enterprise/'>https://attack.mitre.org</a>: Techniques<br/>- <a href='https://attack.mitre.org/tactics/TA0042/'>https://attack.mitre.org</a>: TA0042<br/>- <a href='https://www.cisa.gov/uscert/ncas/alerts/aa21-077a'>https://www.cisa.gov/uscert</a>: CISA Hunt and Incident Response Program (CHIRP) tool<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11910188-98-post-compromise.mp3" length="26460556" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11910188</guid>
    <pubDate>Sat, 17 Dec 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2201</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>97 -  Privilege Escalation 101 and how to mitigate it</itunes:title>
    <title>97 -  Privilege Escalation 101 and how to mitigate it</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome to YusufOnSecurity episode 97. Yes we are nearly at the grand number of 100! This week I am talking about privilege escalation. It is the critical step during an attack and it is vital to understand how the bad guys pull this off. By understand their the methods and some the tool used, you will hopefully minimise their success on using this technique and limit the damage that may ensue otherwise.  In addition, we will recap other  ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity episode 97. Yes we are nearly at the grand number of 100!<br/>This week I am talking about privilege escalation. It is the critical step during an attack and it is vital to understand how the bad guys pull this off. By understand their the methods and some the tool used, you will hopefully minimise their success on using this technique and limit the damage that may ensue otherwise.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>MuddyWater Hackers Target Asian and Middle East Countries</li><li>Leaked Signing Keys Are Being Used to Sign Malware</li></ul><p>- <a href='https://attack.mitre.org/groups/G0069/'>https://attack.mitre.org</a>: MuddyWater<br/>-<a href='https://blog.talosintelligence.com/iranian-apt-muddywater-targets-turkey/'>https://blog.talosintelligence.com</a>: Muddy Water targets turkey<br/>- <a href='https://bugs.chromium.org/p/apvi/issues/detail?id=100'>https://bugs.chromium.org</a>: Platform certificates used to sign malware<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity episode 97. Yes we are nearly at the grand number of 100!<br/>This week I am talking about privilege escalation. It is the critical step during an attack and it is vital to understand how the bad guys pull this off. By understand their the methods and some the tool used, you will hopefully minimise their success on using this technique and limit the damage that may ensue otherwise.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>MuddyWater Hackers Target Asian and Middle East Countries</li><li>Leaked Signing Keys Are Being Used to Sign Malware</li></ul><p>- <a href='https://attack.mitre.org/groups/G0069/'>https://attack.mitre.org</a>: MuddyWater<br/>-<a href='https://blog.talosintelligence.com/iranian-apt-muddywater-targets-turkey/'>https://blog.talosintelligence.com</a>: Muddy Water targets turkey<br/>- <a href='https://bugs.chromium.org/p/apvi/issues/detail?id=100'>https://bugs.chromium.org</a>: Platform certificates used to sign malware<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11852109-97-privilege-escalation-101-and-how-to-mitigate-it.mp3" length="36868119" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11852109</guid>
    <pubDate>Sat, 10 Dec 2022 23:00:00 +0400</pubDate>
    <itunes:duration>3068</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>96 - Are containers more secure?</itunes:title>
    <title>96 - Are containers more secure?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome to YusufOnSecurity. Making use of what resources you have is an import aspect of technology use whether that is virtualisation or containarisation. But it is important to understand the impact the choices you make have on security. Are containers more secure? That is the questions of this week's episode.  In addition, we will recap other  trending  security news  and this week we look at:  - https://blog.talosintelligence...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity.<br/>Making use of what resources you have is an import aspect of technology use whether that is virtualisation or containarisation. But it is important to understand the impact the choices you make have on security. Are containers more secure? That is the questions of this week&apos;s episode.<br/><br/>In addition, we will recap other  trending  security news  and this week we look at:<br/><br/>- <a href='https://blog.talosintelligence.com/vulnerability-spotlight-lansweeper-directory-traversal-and-cross-site-scripting-vulnerabilities/'>https://blog.talosintelligence.com</a>: Vulnerability spotlight lansweeper directory traversal and cross site scripting vulnerabilities<br/>- <a href='https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/'>https://blog.lastpass.com</a>: Notice of recent security incident<br/>-<span style='background-color: highlight;'> </span><a href='https://www.veritis.com/blog/containers-vs-vms-glance-at-security-pros-and-cons/#:~:text=Traditional%20applications%20are%20not%20properly,of%20security%20and%20remaining%20unharmed.'>https://www.veritis.com/blog</a>: Containers vs VMs glance at security pros and cons<br/>-<a href='https://cloud.google.com/learn/what-are-containers'>https://cloud.google.com/learn</a>: What are containers<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity.<br/>Making use of what resources you have is an import aspect of technology use whether that is virtualisation or containarisation. But it is important to understand the impact the choices you make have on security. Are containers more secure? That is the questions of this week&apos;s episode.<br/><br/>In addition, we will recap other  trending  security news  and this week we look at:<br/><br/>- <a href='https://blog.talosintelligence.com/vulnerability-spotlight-lansweeper-directory-traversal-and-cross-site-scripting-vulnerabilities/'>https://blog.talosintelligence.com</a>: Vulnerability spotlight lansweeper directory traversal and cross site scripting vulnerabilities<br/>- <a href='https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/'>https://blog.lastpass.com</a>: Notice of recent security incident<br/>-<span style='background-color: highlight;'> </span><a href='https://www.veritis.com/blog/containers-vs-vms-glance-at-security-pros-and-cons/#:~:text=Traditional%20applications%20are%20not%20properly,of%20security%20and%20remaining%20unharmed.'>https://www.veritis.com/blog</a>: Containers vs VMs glance at security pros and cons<br/>-<a href='https://cloud.google.com/learn/what-are-containers'>https://cloud.google.com/learn</a>: What are containers<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11809738-96-are-containers-more-secure.mp3" length="37550813" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11809738</guid>
    <pubDate>Sat, 03 Dec 2022 22:00:00 +0400</pubDate>
    <itunes:duration>3125</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>95 - Benefits of RestAPI and why should you care?</itunes:title>
    <title>95 - Benefits of RestAPI and why should you care?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome back once again! Complexity is the greatest challenge in cyber security. With millions of software applications, services, and systems in use today, each one has its own features and use cases independently: It is called the silo dilemma. With exchanging information, they can never hope to have meaningful common use cases or act as a coherent solution.  So, in the face of increasing complexity and a lack ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/>Complexity is the greatest challenge in cyber security. With millions of software applications, services, and systems in use today, each one has its own features and use cases independently: It is called the silo dilemma. With exchanging information, they can never hope to have meaningful common use cases or act as a coherent solution.<br/><br/>So, in the face of increasing complexity and a lack of universal vendor to vendor integration, what can you do? For many organizations, the answer is to use a REST API. But what exactly is a REST API, and why do you need care. <br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>RansomExx Malware Moves to Rust, Evading Anti-Virus scan engines</li><li>Zeppelin Ransomware Decryptor</li></ul><p>- <a href='https://securityintelligence.com/posts/ransomexx-upgrades-rust/'>https://securityintelligence.com:</a> Ransomexx upgrades Rust<br/>- <a href='https://krebsonsecurity.com/2022/11/researchers-quietly-cracked-zeppelin-ransomware-keys/'>https://krebsonsecurity.com</a>: Researchers quietly cracked zeppelin ransomware keys<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/>Complexity is the greatest challenge in cyber security. With millions of software applications, services, and systems in use today, each one has its own features and use cases independently: It is called the silo dilemma. With exchanging information, they can never hope to have meaningful common use cases or act as a coherent solution.<br/><br/>So, in the face of increasing complexity and a lack of universal vendor to vendor integration, what can you do? For many organizations, the answer is to use a REST API. But what exactly is a REST API, and why do you need care. <br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>RansomExx Malware Moves to Rust, Evading Anti-Virus scan engines</li><li>Zeppelin Ransomware Decryptor</li></ul><p>- <a href='https://securityintelligence.com/posts/ransomexx-upgrades-rust/'>https://securityintelligence.com:</a> Ransomexx upgrades Rust<br/>- <a href='https://krebsonsecurity.com/2022/11/researchers-quietly-cracked-zeppelin-ransomware-keys/'>https://krebsonsecurity.com</a>: Researchers quietly cracked zeppelin ransomware keys<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11779765-95-benefits-of-restapi-and-why-should-you-care.mp3" length="30408447" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11779765</guid>
    <pubDate>Sat, 26 Nov 2022 13:00:00 +0400</pubDate>
    <itunes:duration>2530</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>94 - Is MSSP right for you?</itunes:title>
    <title>94 - Is MSSP right for you?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  Fo the majority of enterprises, security can turn out to be extremely challenging, especially with  the move to remote and/or  hybrid work and the current geo-political tension.    The International Information Systems Security Certification Consortium also known as (ICS)2, estimates that 23% of companies have seen an increase in cybersecurity incidents since they’ve asked their employees to remote work.   Cyber s...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> Fo the majority of enterprises, security can turn out to be extremely challenging, especially with  the move to remote and/or  hybrid work and the current geo-political tension.<br/> <br/> The International Information Systems Security Certification Consortium also known as (ICS)2, estimates that 23% of companies have seen an increase in cybersecurity incidents since they’ve asked their employees to remote work.<br/> <br/>Cyber security skill sets are always in demand, and most organizations do not have the capability to attract good talent. So, is MSSP the right move for you?<br/><br/>In addition, we will recap the week&apos;s top trending security news.</p><ul><li>I attended BlackHatMEA</li><li>MITRE Engenuity Launches Evaluations for Security Service Providers</li></ul><p>-<a href='https://blackhatmea.com/'>https://blackhatmea.com</a>: BlackHatMEA<br/>-<a href='https://www.mitre.org/news-insights/news-release/mitre-engenuity-publishes-attack-evaluations-security-service-providers'>https://www.mitre.org</a>: Mitre engenuity publishes attack evaluations security service providers<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p> Fo the majority of enterprises, security can turn out to be extremely challenging, especially with  the move to remote and/or  hybrid work and the current geo-political tension.<br/> <br/> The International Information Systems Security Certification Consortium also known as (ICS)2, estimates that 23% of companies have seen an increase in cybersecurity incidents since they’ve asked their employees to remote work.<br/> <br/>Cyber security skill sets are always in demand, and most organizations do not have the capability to attract good talent. So, is MSSP the right move for you?<br/><br/>In addition, we will recap the week&apos;s top trending security news.</p><ul><li>I attended BlackHatMEA</li><li>MITRE Engenuity Launches Evaluations for Security Service Providers</li></ul><p>-<a href='https://blackhatmea.com/'>https://blackhatmea.com</a>: BlackHatMEA<br/>-<a href='https://www.mitre.org/news-insights/news-release/mitre-engenuity-publishes-attack-evaluations-security-service-providers'>https://www.mitre.org</a>: Mitre engenuity publishes attack evaluations security service providers<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11729714-94-is-mssp-right-for-you.mp3" length="23103313" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11729714</guid>
    <pubDate>Sat, 19 Nov 2022 22:00:00 +0400</pubDate>
    <itunes:duration>1921</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>93 - Why companies are breached even when they have MFA on?</itunes:title>
    <title>93 - Why companies are breached even when they have MFA on?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Attackers target the weakest link. Lately though there is one tool that is in their cross-hair: MFA.  MFA has been a torn on the side of the cyber crooks and they up their anti-to come up ingenious way to circumvent it. How do they do it. This is the topic of this week's episode. In addition, we will recap the week's top trending security news: Dropbox breach, what happened?Scanning the internet for fun and profit. The National Cyber Secur...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Attackers target the weakest link. Lately though there is one tool that is in their cross-hair: MFA. <br/>MFA has been a torn on the side of the cyber crooks and they up their anti-to come up ingenious way to circumvent it. How do they do it. This is the topic of this week&apos;s episode.<br/>In addition, we will recap the week&apos;s top trending security news:</p><ul><li>Dropbox breach, what happened?</li><li>Scanning the internet for fun and profit. The National Cyber Security Centre (NCSC) has a project to scan the UK&apos;s Internet.</li></ul><p>- <a href='https://dropbox.tech/security/a-recent-phishing-campaign-targeting-dropbox'>https://https://dropbox.tech</a>: How we handled a recent phishing incident that targeted Dropbox<br/>- <a href='https://www.blazemeter.com/blog/circleci-jmeter'>https://www.blazemeter.com</a>: CircleCI<br/>-<a href='https://www.ncsc.gov.uk/blog-post/scanning-the-internet-for-fun-and-profit'>https://www.ncsc.gov.uk</a>: Scanning the internet for fun and profit<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Attackers target the weakest link. Lately though there is one tool that is in their cross-hair: MFA. <br/>MFA has been a torn on the side of the cyber crooks and they up their anti-to come up ingenious way to circumvent it. How do they do it. This is the topic of this week&apos;s episode.<br/>In addition, we will recap the week&apos;s top trending security news:</p><ul><li>Dropbox breach, what happened?</li><li>Scanning the internet for fun and profit. The National Cyber Security Centre (NCSC) has a project to scan the UK&apos;s Internet.</li></ul><p>- <a href='https://dropbox.tech/security/a-recent-phishing-campaign-targeting-dropbox'>https://https://dropbox.tech</a>: How we handled a recent phishing incident that targeted Dropbox<br/>- <a href='https://www.blazemeter.com/blog/circleci-jmeter'>https://www.blazemeter.com</a>: CircleCI<br/>-<a href='https://www.ncsc.gov.uk/blog-post/scanning-the-internet-for-fun-and-profit'>https://www.ncsc.gov.uk</a>: Scanning the internet for fun and profit<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11681017-93-why-companies-are-breached-even-when-they-have-mfa-on.mp3" length="31847919" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11681017</guid>
    <pubDate>Sat, 12 Nov 2022 23:00:00 +0400</pubDate>
    <itunes:duration>2650</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>92 - How to start your cyber security career?</itunes:title>
    <title>92 - How to start your cyber security career?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Cyber security roles are in demand. Everyone talks about this fact. So I often asked "How do I start in cyber security"? I will cover this question in this week's episode and provides some pointers to would be new starter in Cyber Security.  In addition, we will recap the week's top trending security news. Mastodon, the new micro blogging. - https://en.wikipedia.org: Mastodon -https://www.bleepingcomputer.com: Mastodon now has over 1 milli...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Cyber security roles are in demand. Everyone talks about this fact. So I often asked &quot;How do I start in cyber security&quot;?<br/>I will cover this question in this week&apos;s episode and provides some pointers to would be new starter in Cyber Security.<br/><br/>In addition, we will recap the week&apos;s top trending security news.</p><ul><li>Mastodon, the new micro blogging. </li></ul><p>- <a href='https://en.wikipedia.org/wiki/Mastodon_(software)'>https://en.wikipedia.org</a>: Mastodon<br/>-<a href='https://www.bleepingcomputer.com/news/technology/mastodon-now-has-over-1-million-users-amid-twitter-tensions/'>https://www.bleepingcomputer.com</a>: Mastodon now has over 1 million users amid twitter tensions<br/>- <a href='https://www.coursera.org/articles/cybersecurity-career-paths'>https://www.coursera.org</a>:  Cybersecurityvcareervpaths<br/>- <a href='https://www.eccouncil.org/cybersecurity-exchange/cybersecurity-technician/begin-your-cybersecurity-career/'>https://www.eccouncil.org</a>: Begin your cybersecurity career<br/>- <a href='https://www.coursera.org/articles/cybersecurity-career-paths'>https://www.coursera.org</a>: Cybersecurity career paths<br/>- <a href='https://www.coursera.org'>https://tryhackme.com</a><br/>-<a href='https://hackthebox.com'>https://hackthebox.com</a><br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Cyber security roles are in demand. Everyone talks about this fact. So I often asked &quot;How do I start in cyber security&quot;?<br/>I will cover this question in this week&apos;s episode and provides some pointers to would be new starter in Cyber Security.<br/><br/>In addition, we will recap the week&apos;s top trending security news.</p><ul><li>Mastodon, the new micro blogging. </li></ul><p>- <a href='https://en.wikipedia.org/wiki/Mastodon_(software)'>https://en.wikipedia.org</a>: Mastodon<br/>-<a href='https://www.bleepingcomputer.com/news/technology/mastodon-now-has-over-1-million-users-amid-twitter-tensions/'>https://www.bleepingcomputer.com</a>: Mastodon now has over 1 million users amid twitter tensions<br/>- <a href='https://www.coursera.org/articles/cybersecurity-career-paths'>https://www.coursera.org</a>:  Cybersecurityvcareervpaths<br/>- <a href='https://www.eccouncil.org/cybersecurity-exchange/cybersecurity-technician/begin-your-cybersecurity-career/'>https://www.eccouncil.org</a>: Begin your cybersecurity career<br/>- <a href='https://www.coursera.org/articles/cybersecurity-career-paths'>https://www.coursera.org</a>: Cybersecurity career paths<br/>- <a href='https://www.coursera.org'>https://tryhackme.com</a><br/>-<a href='https://hackthebox.com'>https://hackthebox.com</a><br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11676689-92-how-to-start-your-cyber-security-career.mp3" length="24201432" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11676689</guid>
    <pubDate>Sat, 05 Nov 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2013</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>91 - Continuous security validation</itunes:title>
    <title>91 - Continuous security validation</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Every organisation goes and purchase the tools they thing is good for the job. Often, some rotated  the installation of their security products every 2 to 3 years or when they think it is starting to fall behind in features and detection capabilities. All these are well and good but very few organisations test the effectiveness of the tools they installed. That is where validation comes in and it is our topic of the week.  In addition, we ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Every organisation goes and purchase the tools they thing is good for the job. Often, some rotated  the installation of their security products every 2 to 3 years or when they think it is starting to fall behind in features and detection capabilities. All these are well and good but very few organisations test the effectiveness of the tools they installed. That is where validation comes in and it is our topic of the week.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>OpenSSL warns of critical security vulnerability with upcoming patch</li><li>Security vendors started to work on cross-integration between products</li></ul><p>-<a href='https://twitter.com/iamamoose/status/1584908434855628800'>https://twitter.com</a>: Critical CVE out next Tuesday<br/>-<a href='https://www.openssl.org/'>https://www.openssl.org</a>: OpenSSL<br/>-<a href='https://www.cisco.com/c/en/us/products/security/technical-alliance-partners/crowdstrike.html'>https://www.cisco.com</a>: Technical Alliance Partners<br/>-<a href='https://www.sans.org/webcasts/continuous-security-validation-ever-changing-landscape-118000/'>https://www.sans.org</a>:Continuous security validation <br/>-<a href='https://i.crn.com/sites/default/files/ckfinderimages/userfiles/images/crn/custom/2019/AttackIQ_WP_CSVP_Guide.pdf'>https://i.crn.com</a>:Security Validation Platform<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Every organisation goes and purchase the tools they thing is good for the job. Often, some rotated  the installation of their security products every 2 to 3 years or when they think it is starting to fall behind in features and detection capabilities. All these are well and good but very few organisations test the effectiveness of the tools they installed. That is where validation comes in and it is our topic of the week.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>OpenSSL warns of critical security vulnerability with upcoming patch</li><li>Security vendors started to work on cross-integration between products</li></ul><p>-<a href='https://twitter.com/iamamoose/status/1584908434855628800'>https://twitter.com</a>: Critical CVE out next Tuesday<br/>-<a href='https://www.openssl.org/'>https://www.openssl.org</a>: OpenSSL<br/>-<a href='https://www.cisco.com/c/en/us/products/security/technical-alliance-partners/crowdstrike.html'>https://www.cisco.com</a>: Technical Alliance Partners<br/>-<a href='https://www.sans.org/webcasts/continuous-security-validation-ever-changing-landscape-118000/'>https://www.sans.org</a>:Continuous security validation <br/>-<a href='https://i.crn.com/sites/default/files/ckfinderimages/userfiles/images/crn/custom/2019/AttackIQ_WP_CSVP_Guide.pdf'>https://i.crn.com</a>:Security Validation Platform<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11609358-91-continuous-security-validation.mp3" length="27137366" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11609358</guid>
    <pubDate>Sat, 29 Oct 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2257</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>90 - Where do you start with Zero Trust?</itunes:title>
    <title>90 - Where do you start with Zero Trust?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In our journey to a more secure posture, zero trust is talked about a lot. The question most businesses usually ask is where do you start. After all ZT is not a product but a framework to a better posture day in and day out. This is our topic of the week.  In addition, we will recap top of mind  trending  security news  including: Quarterly Report: Incident Response Trends in Q3 2022 from Cisco TalosMicrosoft Office 365 Message E...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In our journey to a more secure posture, zero trust is talked about a lot. The question most businesses usually ask is where do you start. After all ZT is not a product but a framework to a better posture day in and day out. This is our topic of the week.<br/><br/>In addition, we will recap top of mind  trending  security news  including:</p><ul><li>Quarterly Report: Incident Response Trends in Q3 2022 from Cisco Talos</li><li>Microsoft Office 365 Message Encryption is light in confidentiality</li></ul><p>-<a href='https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation'>https://labs.withsecure.com</a>: Microsoft Office 365 message encryption insecure mode of operation<br/>-<a href='https://learn.microsoft.com/en-us/microsoft-365/compliance/ome?view=o365-worldwide'>https://learn.microsoft.com</a>: Message Encryption<br/>-<a href='https://www.educative.io/answers/what-is-ecb'>https://www.educative.io</a>: What is ECB?<br/>- <a href='https://www.n-able.com/blog/aes-256-encryption-algorithm'>https://www.n-able.com</a>: Understanding AES 256 Encryption<br/>- <a href='https://www.microsoft.com/en-us/microsoft-365/microsoft-365-faqs'>https://www.microsoft.com:</a>  Microsoft- 365 FAQs<br/>- <a href='https://blog.talosintelligence.com/2022/10/quarterly-report-incident-response.html#more'>https://blog.talosintelligence.com</a>: Quarterly report incident response<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In our journey to a more secure posture, zero trust is talked about a lot. The question most businesses usually ask is where do you start. After all ZT is not a product but a framework to a better posture day in and day out. This is our topic of the week.<br/><br/>In addition, we will recap top of mind  trending  security news  including:</p><ul><li>Quarterly Report: Incident Response Trends in Q3 2022 from Cisco Talos</li><li>Microsoft Office 365 Message Encryption is light in confidentiality</li></ul><p>-<a href='https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation'>https://labs.withsecure.com</a>: Microsoft Office 365 message encryption insecure mode of operation<br/>-<a href='https://learn.microsoft.com/en-us/microsoft-365/compliance/ome?view=o365-worldwide'>https://learn.microsoft.com</a>: Message Encryption<br/>-<a href='https://www.educative.io/answers/what-is-ecb'>https://www.educative.io</a>: What is ECB?<br/>- <a href='https://www.n-able.com/blog/aes-256-encryption-algorithm'>https://www.n-able.com</a>: Understanding AES 256 Encryption<br/>- <a href='https://www.microsoft.com/en-us/microsoft-365/microsoft-365-faqs'>https://www.microsoft.com:</a>  Microsoft- 365 FAQs<br/>- <a href='https://blog.talosintelligence.com/2022/10/quarterly-report-incident-response.html#more'>https://blog.talosintelligence.com</a>: Quarterly report incident response<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11578513-90-where-do-you-start-with-zero-trust.mp3" length="38598130" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11578513</guid>
    <pubDate>Sat, 22 Oct 2022 22:00:00 +0400</pubDate>
    <itunes:duration>3212</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>89 - GITEX 2022 Dubai </itunes:title>
    <title>89 - GITEX 2022 Dubai </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, thanks for tuning in! Waow, have a good a great content for you! I am in Dubai and it is the Gulf Information Technology Exhibition week, short for GITEX 2022. I think they named it Gitex Global this year. It's been a week filled with sampling cool cyber security tools and technology as well as meeting like minded techies from around the world. I will let you listen as I interacted with some of those security pra...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div>It is time for YusufOnSecurity, thanks for tuning in!<br/>Waow, have a good a great content for you! I am in Dubai and it is the Gulf Information Technology Exhibition week, short for GITEX 2022. I think they named it Gitex Global this year.<br/>It&apos;s been a week filled with sampling cool cyber security tools and technology as well as meeting like minded techies from around the world. I will let you listen as I interacted with some of those security practitioners.<br/><br/>- <a href='https://gitex.com'>https://gitex.com</a><br/>- <a href='https://dgc.org'>https://dgc.org</a><br/>- <a href='https://performit.co'>https://performit.co</a><br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/> <br/>You will find a list of all previous episodes in there too.<br/><br/></div><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div>It is time for YusufOnSecurity, thanks for tuning in!<br/>Waow, have a good a great content for you! I am in Dubai and it is the Gulf Information Technology Exhibition week, short for GITEX 2022. I think they named it Gitex Global this year.<br/>It&apos;s been a week filled with sampling cool cyber security tools and technology as well as meeting like minded techies from around the world. I will let you listen as I interacted with some of those security practitioners.<br/><br/>- <a href='https://gitex.com'>https://gitex.com</a><br/>- <a href='https://dgc.org'>https://dgc.org</a><br/>- <a href='https://performit.co'>https://performit.co</a><br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/> <br/>You will find a list of all previous episodes in there too.<br/><br/></div><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11508832-89-gitex-2022-dubai.mp3" length="19082431" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11508832</guid>
    <pubDate>Sat, 15 Oct 2022 22:00:00 +0400</pubDate>
    <itunes:duration>1586</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>88 - Insider treat, the danger within - Part 2</itunes:title>
    <title>88 - Insider treat, the danger within - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Here is one of those memes related to the topic du jour "Someone once told me that none of us are actually afraid of the dark; we're scared of what it conceals from us. We're afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too." Well this week we will cover not so talked about topic: Insider treat. In addition, we will recap other  trending&...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Here is one of those memes related to the topic du jour &quot;Someone once told me that none of us are actually afraid of the dark; we&apos;re scared of what it conceals from us. We&apos;re afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too.&quot; Well this week we will cover not so talked about topic: Insider treat.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Increase of multiple attacks on organisations</li></ul><p><b>- </b><a href='https://www.zdnet.com/article/got-hit-by-a-cyber-attack-hackers-will-probably-come-after-you-again-within-a-year/'>https://www.zdnet.com</a>: Got hit by a cyber attack hackers will probably come after you again within a year.<br/>-<a href='https://www.cisa.gov/defining-insider-threats'>https://www.cisa.gov</a>: Defining-insider threats<br/>- <a href='https://scholarworks.waldenu.edu/cgi/viewcontent.cgi?article=12251&amp;context=dissertations'>https://scholarworks.waldenu.edu</a>: Insider Threats&apos; Behaviors and Data Security <br/><br/>Management Strategies<br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/> <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Here is one of those memes related to the topic du jour &quot;Someone once told me that none of us are actually afraid of the dark; we&apos;re scared of what it conceals from us. We&apos;re afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too.&quot; Well this week we will cover not so talked about topic: Insider treat.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>Increase of multiple attacks on organisations</li></ul><p><b>- </b><a href='https://www.zdnet.com/article/got-hit-by-a-cyber-attack-hackers-will-probably-come-after-you-again-within-a-year/'>https://www.zdnet.com</a>: Got hit by a cyber attack hackers will probably come after you again within a year.<br/>-<a href='https://www.cisa.gov/defining-insider-threats'>https://www.cisa.gov</a>: Defining-insider threats<br/>- <a href='https://scholarworks.waldenu.edu/cgi/viewcontent.cgi?article=12251&amp;context=dissertations'>https://scholarworks.waldenu.edu</a>: Insider Threats&apos; Behaviors and Data Security <br/><br/>Management Strategies<br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/> <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11462765-88-insider-treat-the-danger-within-part-2.mp3" length="18433911" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11462765</guid>
    <pubDate>Sat, 08 Oct 2022 23:00:00 +0400</pubDate>
    <itunes:duration>1532</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>87 - Insider treat, the danger within - Part 1</itunes:title>
    <title>87 - Insider treat, the danger within - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Here is one of those memes related to the topic du jour "Someone once told me that none of us are actually afraid of the dark; we're scared of what it conceals from us. We're afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too." Well this week we will cover not so talked about topic: Insider treat. In addition, we will recap other  trending&...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Here is one of those memes related to the topic du jour &quot;Someone once told me that none of us are actually afraid of the dark; we&apos;re scared of what it conceals from us. We&apos;re afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too.&quot; Well this week we will cover not so talked about topic: Insider treat.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>American Airlines Learned of Breach from Phishing Targets</li></ul><p><b>- </b><a href='https://www.bleepingcomputer.com/news/security/american-airlines-learned-it-was-breached-from-phishing-targets/'><b>www.bleepingcomputer.com</b></a>:  American airline learned it was breached from phishing targets <br/>-<a href='https://www.cisa.gov/defining-insider-threats'>https://www.cisa.gov</a>: Defining-insider threats<br/>- <a href='https://scholarworks.waldenu.edu/cgi/viewcontent.cgi?article=12251&amp;context=dissertations'>https://scholarworks.waldenu.edu</a>: Insider Threats&apos; Behaviors and Data Security Management Strategies<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Here is one of those memes related to the topic du jour &quot;Someone once told me that none of us are actually afraid of the dark; we&apos;re scared of what it conceals from us. We&apos;re afraid of having something with the potential to hurt us standing right before our eyes and not registering it as a threat. People can be like that too.&quot; Well this week we will cover not so talked about topic: Insider treat.<br/>In addition, we will recap other  trending  security news  including:</p><ul><li>American Airlines Learned of Breach from Phishing Targets</li></ul><p><b>- </b><a href='https://www.bleepingcomputer.com/news/security/american-airlines-learned-it-was-breached-from-phishing-targets/'><b>www.bleepingcomputer.com</b></a>:  American airline learned it was breached from phishing targets <br/>-<a href='https://www.cisa.gov/defining-insider-threats'>https://www.cisa.gov</a>: Defining-insider threats<br/>- <a href='https://scholarworks.waldenu.edu/cgi/viewcontent.cgi?article=12251&amp;context=dissertations'>https://scholarworks.waldenu.edu</a>: Insider Threats&apos; Behaviors and Data Security Management Strategies<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11419180-87-insider-treat-the-danger-within-part-1.mp3" length="20954205" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11419180</guid>
    <pubDate>Sat, 01 Oct 2022 21:00:00 +0400</pubDate>
    <itunes:duration>1742</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>86 - SIEM versus XDR - Who is the winner?</itunes:title>
    <title>86 - SIEM versus XDR - Who is the winner?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome back once again! Security teams face an ongoing challenge: how best to collect event data from all of their  tools and infrastructure - network, endpoint and anything in between. The critical part being how  to turn this mass of data into threat intelligence to prevent or stop  the next cyber attacks. This is the topic of this week's episode. In addition, I will mention few security news an...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/>Security teams face an ongoing challenge: how best to collect event data from all of their  tools and infrastructure - network, endpoint and anything in between. The critical part being how  to turn this mass of data into threat intelligence to prevent or stop  the next cyber attacks. This is the topic of this week&apos;s episode.<br/>In addition, I will mention few security news and draw some useful conclusions out of them.</p><ul><li>Tamper Protection Will be On by Default for all Microsoft Defender for Endpoint Users</li><li>Hackers Lurked in Albanian Government Network for More Than a Year</li></ul><p><b>- </b><a href='https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478'><b>techcommunity.microsoft.com</b></a>: Tamper protection will be turned on for all enterprise customers<br/><b>- </b><a href='https://www.govinfosecurity.com/iranian-hackers-accessed-albanias-network-for-14-months-a-20130'><b>www.govinfosecurity.com</b></a>: Iranian Hackers Accessed Albania&apos;s Network for 14 Months<br/><b>- </b><a href='https://www.cisa.gov/uscert/ncas/alerts/aa22-264a'><b>www.cisa.gov</b></a>: Alert (AA22-264A) Iranian State Actors Conduct Cyber Operations Against the Government of Albania<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/>Security teams face an ongoing challenge: how best to collect event data from all of their  tools and infrastructure - network, endpoint and anything in between. The critical part being how  to turn this mass of data into threat intelligence to prevent or stop  the next cyber attacks. This is the topic of this week&apos;s episode.<br/>In addition, I will mention few security news and draw some useful conclusions out of them.</p><ul><li>Tamper Protection Will be On by Default for all Microsoft Defender for Endpoint Users</li><li>Hackers Lurked in Albanian Government Network for More Than a Year</li></ul><p><b>- </b><a href='https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478'><b>techcommunity.microsoft.com</b></a>: Tamper protection will be turned on for all enterprise customers<br/><b>- </b><a href='https://www.govinfosecurity.com/iranian-hackers-accessed-albanias-network-for-14-months-a-20130'><b>www.govinfosecurity.com</b></a>: Iranian Hackers Accessed Albania&apos;s Network for 14 Months<br/><b>- </b><a href='https://www.cisa.gov/uscert/ncas/alerts/aa22-264a'><b>www.cisa.gov</b></a>: Alert (AA22-264A) Iranian State Actors Conduct Cyber Operations Against the Government of Albania<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11386491-86-siem-versus-xdr-who-is-the-winner.mp3" length="25816156" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11386491</guid>
    <pubDate>Sat, 24 Sep 2022 23:00:00 +0400</pubDate>
    <itunes:duration>2147</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>85 - Turning your network into a sensor</itunes:title>
    <title>85 - Turning your network into a sensor</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome back once again! In our march to architecting a solution approach to security, today we will talk about one such approach. The network and how the data that flows through can help paint a picture to help us gain more visibility into what is lurking beneath the surface.  In addition, we will recap one  important security news  for your downloaders out there:  - https://arstechnica.com: Trojanized...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/>In our march to architecting a solution approach to security, today we will talk about one such approach. The network and how the data that flows through can help paint a picture to help us gain more visibility into what is lurking beneath the surface.<br/><br/>In addition, we will recap one  important security news  for your downloaders out there:<br/><br/>- <a href='https://arstechnica.com/information-technology/2022/09/trojanized-versions-of-putty-utility-being-used-to-spread-backdoor/'>https://arstechnica.com</a>: Trojanized versions of putty utility being used to spread backdoor<br/>- <a href='https://www.thousandeyes.com/learning/glossary/netflow'>https://www.thousandeyes.com</a>: What is network detection response<br/>- <a href='https://www.cisco.com/c/en/us/products/security/what-is-network-detection-response.html'>https://www.cisco.com</a>: What is network detection response<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me <b>@iayusuf</b> or read my blog at <b>https://yusufonsecurity.com](https://yusufonsecurity.com</b><br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/>In our march to architecting a solution approach to security, today we will talk about one such approach. The network and how the data that flows through can help paint a picture to help us gain more visibility into what is lurking beneath the surface.<br/><br/>In addition, we will recap one  important security news  for your downloaders out there:<br/><br/>- <a href='https://arstechnica.com/information-technology/2022/09/trojanized-versions-of-putty-utility-being-used-to-spread-backdoor/'>https://arstechnica.com</a>: Trojanized versions of putty utility being used to spread backdoor<br/>- <a href='https://www.thousandeyes.com/learning/glossary/netflow'>https://www.thousandeyes.com</a>: What is network detection response<br/>- <a href='https://www.cisco.com/c/en/us/products/security/what-is-network-detection-response.html'>https://www.cisco.com</a>: What is network detection response<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me <b>@iayusuf</b> or read my blog at <b>https://yusufonsecurity.com](https://yusufonsecurity.com</b><br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11337953-85-turning-your-network-into-a-sensor.mp3" length="24700777" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11337953</guid>
    <pubDate>Sat, 17 Sep 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2054</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>84 - Post-Exploitation used by cyber criminals - Part 2</itunes:title>
    <title>84 - Post-Exploitation used by cyber criminals - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective  &amp; causing further damage until you kick them out.  That is the topic of this week's episo, in addition, we will recap one  trending  security news  includes:   Rise of network analytics-https://blo...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective  &amp; causing further damage until you kick them out.<br/><br/>That is the topic of this week&apos;s episo, in addition, we will recap one <br/>trending  security news  includes:<br/><br/></p><ul><li>Rise of network analytics</li></ul><p>-<a href='https://blogs.cisco.com/networking/network-analytics-what-you-cant-see-you-cant-control'>https://blogs.cisco.com</a>: Network analytics what you can&apos;t see you can&apos;t control<br/>- <a href='https://newsroom.paypal-corp.com/2021-09-02-How-to-Spot-a-Fake-PayPal-Email'>https://www.paypal.com</a>: How to spot a fake PayPal Email<br/>- <a href='http://www.pentest-standard.org/index.php/Post_Exploitation'>http://www.pentest-standard.org</a>: Post Exploitation<br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective  &amp; causing further damage until you kick them out.<br/><br/>That is the topic of this week&apos;s episo, in addition, we will recap one <br/>trending  security news  includes:<br/><br/></p><ul><li>Rise of network analytics</li></ul><p>-<a href='https://blogs.cisco.com/networking/network-analytics-what-you-cant-see-you-cant-control'>https://blogs.cisco.com</a>: Network analytics what you can&apos;t see you can&apos;t control<br/>- <a href='https://newsroom.paypal-corp.com/2021-09-02-How-to-Spot-a-Fake-PayPal-Email'>https://www.paypal.com</a>: How to spot a fake PayPal Email<br/>- <a href='http://www.pentest-standard.org/index.php/Post_Exploitation'>http://www.pentest-standard.org</a>: Post Exploitation<br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11298265-84-post-exploitation-used-by-cyber-criminals-part-2.mp3" length="23908672" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11298265</guid>
    <pubDate>Sat, 10 Sep 2022 22:00:00 +0400</pubDate>
    <itunes:duration>1988</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>83 - Post-Exploitation used by cyber criminals - Part 1</itunes:title>
    <title>83 - Post-Exploitation used by cyber criminals - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective  &amp; causing further damage until you kick them out.  That is the topic of this week's episo, in addition, we will recap one  trending  security news  includes: PayPal Phishing Scam Uses Invoices Sent...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective  &amp; causing further damage until you kick them out.<br/><br/>That is the topic of this week&apos;s episo, in addition, we will recap one <br/>trending  security news  includes:</p><ul><li>PayPal Phishing Scam Uses Invoices Sent Via PayPal</li></ul><p>- <a href='https://www.paypal.com/dm/webapps/mpp/security/common-scams'>https://www.paypal.com</a>: Common scams<br/>- <a href='https://newsroom.paypal-corp.com/2021-09-02-How-to-Spot-a-Fake-PayPal-Email'>https://www.paypal.com</a>: How to spot a fake PayPal Email<br/>- <a href='http://www.pentest-standard.org/index.php/Post_Exploitation'>http://www.pentest-standard.org</a>: Post Exploitation<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>When cyber criminals attack an organisation, they is usually follow a beaten path. So there is method to their madness. Understanding this will allow you to follow their trail, over take and deny them reaching their objective  &amp; causing further damage until you kick them out.<br/><br/>That is the topic of this week&apos;s episo, in addition, we will recap one <br/>trending  security news  includes:</p><ul><li>PayPal Phishing Scam Uses Invoices Sent Via PayPal</li></ul><p>- <a href='https://www.paypal.com/dm/webapps/mpp/security/common-scams'>https://www.paypal.com</a>: Common scams<br/>- <a href='https://newsroom.paypal-corp.com/2021-09-02-How-to-Spot-a-Fake-PayPal-Email'>https://www.paypal.com</a>: How to spot a fake PayPal Email<br/>- <a href='http://www.pentest-standard.org/index.php/Post_Exploitation'>http://www.pentest-standard.org</a>: Post Exploitation<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11263553-83-post-exploitation-used-by-cyber-criminals-part-1.mp3" length="23334082" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11263553</guid>
    <pubDate>Sat, 03 Sep 2022 21:00:00 +0400</pubDate>
    <itunes:duration>1940</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>82 - Consultant and contractor control</itunes:title>
    <title>82 - Consultant and contractor control</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Bringing an outsider into your network can introduces many risks but if you deal something as complex as supply chain it can appear as a daunting task. It does not have to be though; with adequate due diligence and basic hygiene, you can stay one step ahead of the bad guys. Lets see how you go about this in this this week's episode.  -   LastPass Discloses Security Incident -   More than 80,000 Hikvision Cameras are still unpatched  I...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Bringing an outsider into your network can introduces many risks but if you deal something as complex as supply chain it can appear as a daunting task. It does not have to be though; with adequate due diligence and basic hygiene, you can stay one step ahead of the bad guys. Lets see how you go about this in this this week&apos;s episode.<br/><br/>-   LastPass Discloses Security Incident<br/>-   More than 80,000 Hikvision Cameras are still unpatched<br/><br/>In addition, we will recap a couple of this week&apos;s trending  security news,  includes:<br/><br/><b>- </b><a href='https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/'><b>blog.lastpass.com</b></a>: Notice of Recent Security Incident<br/><b>- </b><a href='https://www.theregister.com/2022/08/25/lastpass_security/'><b>www.theregister.com</b></a>: LastPass source code, blueprints stolen by intruder<br/><b>- </b><a href='https://www.cyfirma.com/wp-content/uploads/2022/08/HikvisionSurveillanceCamerasVulnerabilities.pdf'><b>www.cyfirma.com</b></a>: Thousands of Hikvision Cameras are still vulnerable and can be potentially exploited (PDF)<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Bringing an outsider into your network can introduces many risks but if you deal something as complex as supply chain it can appear as a daunting task. It does not have to be though; with adequate due diligence and basic hygiene, you can stay one step ahead of the bad guys. Lets see how you go about this in this this week&apos;s episode.<br/><br/>-   LastPass Discloses Security Incident<br/>-   More than 80,000 Hikvision Cameras are still unpatched<br/><br/>In addition, we will recap a couple of this week&apos;s trending  security news,  includes:<br/><br/><b>- </b><a href='https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/'><b>blog.lastpass.com</b></a>: Notice of Recent Security Incident<br/><b>- </b><a href='https://www.theregister.com/2022/08/25/lastpass_security/'><b>www.theregister.com</b></a>: LastPass source code, blueprints stolen by intruder<br/><b>- </b><a href='https://www.cyfirma.com/wp-content/uploads/2022/08/HikvisionSurveillanceCamerasVulnerabilities.pdf'><b>www.cyfirma.com</b></a>: Thousands of Hikvision Cameras are still vulnerable and can be potentially exploited (PDF)<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11230389-82-consultant-and-contractor-control.mp3" length="24279472" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11230389</guid>
    <pubDate>Sat, 27 Aug 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2019</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>81 - Critical! Know where you passwords are!</itunes:title>
    <title>81 - Critical! Know where you passwords are!</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! While we wait for a passwordless future, it is paramount you limit exposing and leaving your password in many places. I deliberately chose the title of this episode to draw attention to this fact. I will go over the many place we often put our password in the quest for convenience over security. There are lessons of how me make these choices.  In addition, we will recap a couple of this week's trending  security news,  including: - ht...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>While we wait for a passwordless future, it is paramount you limit exposing and leaving your password in many places. I deliberately chose the title of this episode to draw attention to this fact. I will go over the many place we often put our password in the quest for convenience over security. There are lessons of how me make these choices.<br/><br/>In addition, we will recap a couple of this week&apos;s trending  security news,  including:<br/>- <a href='https://www.bleepingcomputer.com/news/security/over-9-000-vnc-servers-exposed-online-without-a-password/'>https://www.bleepingcomputer.com</a>: Over 9-000 VNC servers exposed online without a password<br/>- <a href='https://www.theverge.com/23308394/usb-rubber-ducky-review-hack5-defcon-duckyscript'>https://www.theverge.com</a>: USB  Rubber Ducky review<br/>- <a href='https://www.nytimes.com/2014/11/19/magazine/the-secret-life-of-passwords.html'>https://www.nytimes.com</a>: The secret life of passwords<br/>- <a href='https://haveibeenpwned.com/'>https://haveibeenpwned.com:</a> Have I Been Pawned?<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>While we wait for a passwordless future, it is paramount you limit exposing and leaving your password in many places. I deliberately chose the title of this episode to draw attention to this fact. I will go over the many place we often put our password in the quest for convenience over security. There are lessons of how me make these choices.<br/><br/>In addition, we will recap a couple of this week&apos;s trending  security news,  including:<br/>- <a href='https://www.bleepingcomputer.com/news/security/over-9-000-vnc-servers-exposed-online-without-a-password/'>https://www.bleepingcomputer.com</a>: Over 9-000 VNC servers exposed online without a password<br/>- <a href='https://www.theverge.com/23308394/usb-rubber-ducky-review-hack5-defcon-duckyscript'>https://www.theverge.com</a>: USB  Rubber Ducky review<br/>- <a href='https://www.nytimes.com/2014/11/19/magazine/the-secret-life-of-passwords.html'>https://www.nytimes.com</a>: The secret life of passwords<br/>- <a href='https://haveibeenpwned.com/'>https://haveibeenpwned.com:</a> Have I Been Pawned?<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11172682-81-critical-know-where-you-passwords-are.mp3" length="34555637" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11172682</guid>
    <pubDate>Sat, 20 Aug 2022 21:00:00 +0400</pubDate>
    <itunes:duration>2875</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>80 - How machine learning helps the cybersecurity industry - Part 2</itunes:title>
    <title>80 - How machine learning helps the cybersecurity industry - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is part 2 of our two part series on "How machine learning helps the cybersecurity industry". If you have not listen to part 1, we recommend you go back to the previous episode.  In addition, we will recap other  trending  security news  includes: Slack Resets Some Users’ PasswordsBlack Hat 2022: Few presentations that you might find particularly interesting- www.theregister.com: Slack leaked hashed passwords from its servers...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is part 2 of our two part series on &quot;How machine learning helps the cybersecurity industry&quot;.<br/>If you have not listen to part 1, we recommend you go back to the previous episode.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Slack Resets Some Users’ Passwords</li><li>Black Hat 2022: Few presentations that you might find particularly interesting</li></ul><p>- <a href='https://www.theregister.com/2022/08/08/slack_passwords/'>www.theregister.com</a>: Slack leaked hashed passwords from its servers for years<br/>- <a href='https://www.bleepingcomputer.com/news/security/slack-resets-passwords-after-exposing-hashes-in-invitation-links/'>www.bleepingcomputer.com</a>: Slack resets passwords after exposing hashes in invitation links<br/>- <a href='https://slack.com/intl/en-gb/blog/news/notice-about-slack-password-resets'>slack.com</a>: Notice about Slack password resets<br/>- <a href='https://www.theguardian.com/technology/2016/dec/15/passwords-hacking-hashing-salting-sha-2'>https://www.theguardian.com</a>: Passwords hacking, hashing, salting, sha-2 explained<br/>- <a href='https://www.blackhat.com/us-22/briefings/schedule/index.html'>https://www.blackhat.com</a>: Schedules index<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is part 2 of our two part series on &quot;How machine learning helps the cybersecurity industry&quot;.<br/>If you have not listen to part 1, we recommend you go back to the previous episode.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Slack Resets Some Users’ Passwords</li><li>Black Hat 2022: Few presentations that you might find particularly interesting</li></ul><p>- <a href='https://www.theregister.com/2022/08/08/slack_passwords/'>www.theregister.com</a>: Slack leaked hashed passwords from its servers for years<br/>- <a href='https://www.bleepingcomputer.com/news/security/slack-resets-passwords-after-exposing-hashes-in-invitation-links/'>www.bleepingcomputer.com</a>: Slack resets passwords after exposing hashes in invitation links<br/>- <a href='https://slack.com/intl/en-gb/blog/news/notice-about-slack-password-resets'>slack.com</a>: Notice about Slack password resets<br/>- <a href='https://www.theguardian.com/technology/2016/dec/15/passwords-hacking-hashing-salting-sha-2'>https://www.theguardian.com</a>: Passwords hacking, hashing, salting, sha-2 explained<br/>- <a href='https://www.blackhat.com/us-22/briefings/schedule/index.html'>https://www.blackhat.com</a>: Schedules index<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11134240-80-how-machine-learning-helps-the-cybersecurity-industry-part-2.mp3" length="26968470" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11134240</guid>
    <pubDate>Sat, 13 Aug 2022 23:00:00 +0400</pubDate>
    <itunes:duration>2243</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>79 - How machine learning helps the cybersecurity industry - Part 1</itunes:title>
    <title>79 - How machine learning helps the cybersecurity industry - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! As the adage we grew up with goes, "you cannot predict the future but you can be prepared for it". Predicting the future is exactly what we do everyday to stay one step ahead of malware attack. For instance the industry has put a great deal of work on taking advantage of Machine Learning, but what is Machine Learning anyway and how does it help us in everyday situation? This is the topic of this week's episode.  In addition, we will recap other...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As the adage we grew up with goes, &quot;you cannot predict the future but you can be prepared for it&quot;. Predicting the future is exactly what we do everyday to stay one step ahead of malware attack. For instance the industry has put a great deal of work on taking advantage of Machine Learning, but what is Machine Learning anyway and how does it help us in everyday situation? This is the topic of this week&apos;s episode.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/><br/></p><ul><li>A study on the top most impersonated software</li><li>Top Malware Strains of 2021</li></ul><p>-<a href='https://blog.virustotal.com/2022/08/deception-at-scale.html'>https://blog.virustotal.com</a>:  Deception at scale<br/>-<a href='https://www.cisa.gov/uscert/ncas/alerts/aa22-216a'>https://www.cisa.gov</a>:  Top malware strains of 2021<br/>-<a href='https://cset.georgetown.edu/publication/machine-learning-and-cybersecurity/'>https://cset.georgetown.edu</a>:  Mmachine learning and cybersecurity<br/>-<a href='https://discover.cisco.com/en/us/digital-transformation/whitepaper/ai-whitepaper/introduction-517AW-38966J.html?'>https://discover.cisco.com</a>: AI whitepaper<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As the adage we grew up with goes, &quot;you cannot predict the future but you can be prepared for it&quot;. Predicting the future is exactly what we do everyday to stay one step ahead of malware attack. For instance the industry has put a great deal of work on taking advantage of Machine Learning, but what is Machine Learning anyway and how does it help us in everyday situation? This is the topic of this week&apos;s episode.<br/><br/>In addition, we will recap other  trending  security news  includes:<br/><br/></p><ul><li>A study on the top most impersonated software</li><li>Top Malware Strains of 2021</li></ul><p>-<a href='https://blog.virustotal.com/2022/08/deception-at-scale.html'>https://blog.virustotal.com</a>:  Deception at scale<br/>-<a href='https://www.cisa.gov/uscert/ncas/alerts/aa22-216a'>https://www.cisa.gov</a>:  Top malware strains of 2021<br/>-<a href='https://cset.georgetown.edu/publication/machine-learning-and-cybersecurity/'>https://cset.georgetown.edu</a>:  Mmachine learning and cybersecurity<br/>-<a href='https://discover.cisco.com/en/us/digital-transformation/whitepaper/ai-whitepaper/introduction-517AW-38966J.html?'>https://discover.cisco.com</a>: AI whitepaper<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)  <br/>  <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11098281-79-how-machine-learning-helps-the-cybersecurity-industry-part-1.mp3" length="26678198" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11098281</guid>
    <pubDate>Sat, 06 Aug 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2219</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>78 - Fileless Malware</itunes:title>
    <title>78 - Fileless Malware</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites. In plain english.  Malware can hide but it must run. Yes, in the cat and mouse game between cyber crimal and defenders, the threat landscape is constantly shifting.  Malware's tactics to evade detection tools include the topic of this week's episode, going fileless. We will cover what  file-less malware is, how different it is fr...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites. In plain english.<br/><br/>Malware can hide but it must run. Yes, in the cat and mouse game between cyber crimal and defenders, the threat landscape is constantly shifting. <br/>Malware&apos;s tactics to evade detection tools include the topic of this week&apos;s episode, going fileless.<br/>We will cover what  file-less malware is, how different it is from other typical malware that you might be aware.<br/>In addition, we will recap other  trending  security news, including:</p><ul><li>Apple Lockdown mode</li><li>Qakbot attack hijacking old email threads</li></ul><p>-<a href='https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/'>https://www.apple.com/newsroom</a>: Apple expands commitment to protect users from mercenary spyware<br/>-<a href='https://blog.talosintelligence.com/2022/07/what-talos-incident-response-learned.html'>https://blog.talosintelligence.com</a>: What Talos incident response learned<br/><br/>Be sure to subscribe!    <br/>   <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com  <br/>   <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecurity, the cyber-security podcast for everyday defender from analyst to the C-Suites. In plain english.<br/><br/>Malware can hide but it must run. Yes, in the cat and mouse game between cyber crimal and defenders, the threat landscape is constantly shifting. <br/>Malware&apos;s tactics to evade detection tools include the topic of this week&apos;s episode, going fileless.<br/>We will cover what  file-less malware is, how different it is from other typical malware that you might be aware.<br/>In addition, we will recap other  trending  security news, including:</p><ul><li>Apple Lockdown mode</li><li>Qakbot attack hijacking old email threads</li></ul><p>-<a href='https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/'>https://www.apple.com/newsroom</a>: Apple expands commitment to protect users from mercenary spyware<br/>-<a href='https://blog.talosintelligence.com/2022/07/what-talos-incident-response-learned.html'>https://blog.talosintelligence.com</a>: What Talos incident response learned<br/><br/>Be sure to subscribe!    <br/>   <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com  <br/>   <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11067099-78-fileless-malware.mp3" length="34716715" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11067099</guid>
    <pubDate>Sat, 30 Jul 2022 11:00:00 +0400</pubDate>
    <itunes:duration>2889</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>77 - Tools and methodologies to apply to your defense strategy</itunes:title>
    <title>77 - Tools and methodologies to apply to your defense strategy</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! As a craftsperson, you would not excel in your chosen trade without the right tools.  Even better, you need to carefully select those tools, sharpen them when they become blunt and upgrade them when new ones come around that will improve your work.   Cyber security is no different, we need well calibrated machinery to use in our defensive strategy. In this week's episode, we will look at some of the right tools and methodology to...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As a craftsperson, you would not excel in your chosen trade without the right tools.  Even better, you need to carefully select those tools, sharpen them when they become blunt and upgrade them when new ones come around that will improve your work. <br/> Cyber security is no different, we need well calibrated machinery to use in our defensive strategy.<br/>In this week&apos;s episode, we will look at some of the right tools and methodology to protect your bottom line.<br/><br/>In addition, we will recap other  trending  security news, including:</p><ul><li>SonicWall urges to patch a critical SQL injection bug </li><li>Be aware of the callback phishing campaign that is making the round.</li></ul><p>All that, coming up next, on YusufOnSecurity!<br/><br/>-<a href='https://www.sonicwall.com/support/knowledge-base/security-notice-sonicwall-gms-sql-injection-vulnerability/220613083124303/'>https://www.sonicwall.com</a>: Security notice Sonicwall GMS SQL injection vulnerability<br/>-<a href='https://www.redpacketsecurity.com/sonicwall-global-management-system-gms-and-analytics-sql-injection-cve-2022-22280/'>https://www.redpacketsecurity.com</a>: Sonicwall Global Management System GMS and analytics SQL injection CVE<br/>-<a href='https://www.cisa.gov/shields-up'>https://www.cisa.gov/shields-up</a>: Shields Up<br/>-<a href='https://threatpost.com/callback-phishing-security-firms/180182/'>https://threatpost.com</a>: Callback phishing campaign impersonate security firms<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>As a craftsperson, you would not excel in your chosen trade without the right tools.  Even better, you need to carefully select those tools, sharpen them when they become blunt and upgrade them when new ones come around that will improve your work. <br/> Cyber security is no different, we need well calibrated machinery to use in our defensive strategy.<br/>In this week&apos;s episode, we will look at some of the right tools and methodology to protect your bottom line.<br/><br/>In addition, we will recap other  trending  security news, including:</p><ul><li>SonicWall urges to patch a critical SQL injection bug </li><li>Be aware of the callback phishing campaign that is making the round.</li></ul><p>All that, coming up next, on YusufOnSecurity!<br/><br/>-<a href='https://www.sonicwall.com/support/knowledge-base/security-notice-sonicwall-gms-sql-injection-vulnerability/220613083124303/'>https://www.sonicwall.com</a>: Security notice Sonicwall GMS SQL injection vulnerability<br/>-<a href='https://www.redpacketsecurity.com/sonicwall-global-management-system-gms-and-analytics-sql-injection-cve-2022-22280/'>https://www.redpacketsecurity.com</a>: Sonicwall Global Management System GMS and analytics SQL injection CVE<br/>-<a href='https://www.cisa.gov/shields-up'>https://www.cisa.gov/shields-up</a>: Shields Up<br/>-<a href='https://threatpost.com/callback-phishing-security-firms/180182/'>https://threatpost.com</a>: Callback phishing campaign impersonate security firms<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/11017561-77-tools-and-methodologies-to-apply-to-your-defense-strategy.mp3" length="30953597" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-11017561</guid>
    <pubDate>Sat, 23 Jul 2022 21:00:00 +0400</pubDate>
    <podcast:soundbite startTime="5.033" duration="20.0" />
    <itunes:duration>2575</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>76 - NIST’s Quantum-Resistant Algorithms</itunes:title>
    <title>76 - NIST’s Quantum-Resistant Algorithms</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This week's episode is about what is giving us privacy at the heart of security, that is encryption algorithm. As computer power and speed improves so is the danger of these algorithm being broken. We need alternatives that can withstand them being compromised. We need resistant algorithms.  In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach this pressing issue.  -https:/...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode is about what is giving us privacy at the heart of security, that is encryption algorithm. As computer power and speed improves so is the danger of these algorithm being broken. We need alternatives that can withstand them being compromised. We need resistant algorithms.<br/><br/>In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach this pressing issue.<br/><br/>-<a href='https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/#:~:text=Indicators%20of%20compromise%20(IOCs)'>https://www.microsoft.com</a>: From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud<br/>- <a href='https://arstechnica.com/information-technology/2022/07/microsoft-details-phishing-campaign-that-can-hijack-mfa-protected-accounts/'>arstechnica.com</a>: Ongoing phishing campaign can hack you even when you’re protected with MFA<br/>- <a href='https://support.lenovo.com/sk/en/product_security/len-91369'>support.lenovo.com</a>: Lenovo Notebook BIOS Vulnerabilities<br/>- <a href='https://www.bleepingcomputer.com/news/security/new-uefi-firmware-flaws-impact-over-70-lenovo-laptop-models/'>www.bleepingcomputer.com</a>: New UEFI firmware flaws impact over 70 Lenovo laptop models<br/>-<a href='https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms'>https://www.nist.gov/news-events</a>: NIST announces first four quantum resistant  cryptographic algorithms<br/>-<a href='https://www.pqsecurity.com/wp-content/uploads/2020/02/PQ-Standardization-Discussion.pdf'>https://www.pqsecurity.com</a>: Post Quantum Standardization Discussion paper<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This week&apos;s episode is about what is giving us privacy at the heart of security, that is encryption algorithm. As computer power and speed improves so is the danger of these algorithm being broken. We need alternatives that can withstand them being compromised. We need resistant algorithms.<br/><br/>In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach this pressing issue.<br/><br/>-<a href='https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/#:~:text=Indicators%20of%20compromise%20(IOCs)'>https://www.microsoft.com</a>: From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud<br/>- <a href='https://arstechnica.com/information-technology/2022/07/microsoft-details-phishing-campaign-that-can-hijack-mfa-protected-accounts/'>arstechnica.com</a>: Ongoing phishing campaign can hack you even when you’re protected with MFA<br/>- <a href='https://support.lenovo.com/sk/en/product_security/len-91369'>support.lenovo.com</a>: Lenovo Notebook BIOS Vulnerabilities<br/>- <a href='https://www.bleepingcomputer.com/news/security/new-uefi-firmware-flaws-impact-over-70-lenovo-laptop-models/'>www.bleepingcomputer.com</a>: New UEFI firmware flaws impact over 70 Lenovo laptop models<br/>-<a href='https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms'>https://www.nist.gov/news-events</a>: NIST announces first four quantum resistant  cryptographic algorithms<br/>-<a href='https://www.pqsecurity.com/wp-content/uploads/2020/02/PQ-Standardization-Discussion.pdf'>https://www.pqsecurity.com</a>: Post Quantum Standardization Discussion paper<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10990907-76-nist-s-quantum-resistant-algorithms.mp3" length="18574697" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10990907</guid>
    <pubDate>Sat, 16 Jul 2022 22:00:00 +0400</pubDate>
    <itunes:duration>1544</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>75 - Solution Approach to Security</itunes:title>
    <title>75 - Solution Approach to Security</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Companies come in different sizes and complexity and they face different challenges but also demand various level of mitigations that meets their obligation.  In this week's episode, lets take a step back and look at how we approach security and how can this be improved.  In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach to security. -https://en.wikipedia.org: OpenSSL -h...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Companies come in different sizes and complexity and they face different challenges but also demand various level of mitigations that meets their obligation.<br/><br/>In this week&apos;s episode, lets take a step back and look at how we approach security and how can this be improved.<br/><br/>In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach to security.<br/>-<a href='https://en.wikipedia.org/wiki/OpenSSL'>https://en.wikipedia.org</a>: OpenSSL<br/>-<a href='https://www.cvedetails.com/cve/CVE-2022-2274/'>https://www.cvedetails.com</a>: CVE-2022-2274<br/>-<a href='https://thehackernews.com/2022/07/openssl-releases-patch-for-high.html'>https://thehackernews.com</a>:  OpenSSL releases patch for high<br/>- <a href='https://www.nationwidesecuritycorp.com/2020/03/16/top-five-benefits-integrated-security-system/#:~:text=Instead%20of%20devoting%20resources%20to,maintain%20oversight%20at%20all%20times.'>https://www.nationwidesecuritycorp.com</a>: Benefits integrated security<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Companies come in different sizes and complexity and they face different challenges but also demand various level of mitigations that meets their obligation.<br/><br/>In this week&apos;s episode, lets take a step back and look at how we approach security and how can this be improved.<br/><br/>In addition, we will recap a couple of top of mind security news and then get into the meat of the matter on how to approach to security.<br/>-<a href='https://en.wikipedia.org/wiki/OpenSSL'>https://en.wikipedia.org</a>: OpenSSL<br/>-<a href='https://www.cvedetails.com/cve/CVE-2022-2274/'>https://www.cvedetails.com</a>: CVE-2022-2274<br/>-<a href='https://thehackernews.com/2022/07/openssl-releases-patch-for-high.html'>https://thehackernews.com</a>:  OpenSSL releases patch for high<br/>- <a href='https://www.nationwidesecuritycorp.com/2020/03/16/top-five-benefits-integrated-security-system/#:~:text=Instead%20of%20devoting%20resources%20to,maintain%20oversight%20at%20all%20times.'>https://www.nationwidesecuritycorp.com</a>: Benefits integrated security<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10968097-75-solution-approach-to-security.mp3" length="30354501" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-10968097</guid>
    <pubDate>Sat, 09 Jul 2022 10:00:00 +0400</pubDate>
    <itunes:duration>2525</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>74 - PowerShell Continued</itunes:title>
    <title>74 - PowerShell Continued</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, I will continue with PowerShell and dwell a bit more on logging. If you have not listen to to last week's episode, I would suggest you do that first.   Before that though, let's recap few topics that worth your attention. They might help you mitigate more risk to your business.  Up next!   Google Chrome 0Day. Update NowZuoRAT malware is targeting routers-https://chromereleases.googleblog.com: Google Chrome 0-Day htt...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, I will continue with PowerShell and dwell a bit more on logging. If you have not listen to to last week&apos;s episode, I would suggest you do that first. <br/><br/>Before that though, let&apos;s recap few topics that worth your attention. They might help you mitigate more risk to your business.<br/><br/>Up next!<br/><br/></p><ul><li>Google Chrome 0Day. Update Now</li><li>ZuoRAT malware is targeting routers</li></ul><p>-<a href='https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html'>https://chromereleases.googleblog.com</a>: Google Chrome 0-Day<br/>https://duo.com/decipher/zuorat-malware-found-hitting-home-routers<br/>-<a href='https://blog.talosintelligence.com/2018/05/VPNFilter.html'>https://blog.talosintelligence.com</a>: VPN Filter<br/>-<a href='https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows?view=powershell-7.2'>https://docs.microsoft.com</a>: PowerShell loggings<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, I will continue with PowerShell and dwell a bit more on logging. If you have not listen to to last week&apos;s episode, I would suggest you do that first. <br/><br/>Before that though, let&apos;s recap few topics that worth your attention. They might help you mitigate more risk to your business.<br/><br/>Up next!<br/><br/></p><ul><li>Google Chrome 0Day. Update Now</li><li>ZuoRAT malware is targeting routers</li></ul><p>-<a href='https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html'>https://chromereleases.googleblog.com</a>: Google Chrome 0-Day<br/>https://duo.com/decipher/zuorat-malware-found-hitting-home-routers<br/>-<a href='https://blog.talosintelligence.com/2018/05/VPNFilter.html'>https://blog.talosintelligence.com</a>: VPN Filter<br/>-<a href='https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_logging_windows?view=powershell-7.2'>https://docs.microsoft.com</a>: PowerShell loggings<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10894306-74-powershell-continued.mp3" length="26303204" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-10894306</guid>
    <pubDate>Sat, 02 Jul 2022 23:00:00 +0400</pubDate>
    <itunes:duration>2188</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>73 - PowerShell - Use it wisely</itunes:title>
    <title>73 - PowerShell - Use it wisely</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome back once again!  The bad guys love using legitimate tools to circumvent security monitoring and controls. One tool in particular stands head and shoulder above other programs and operating system components to attack Microsoft Windows users: That is PowerShell. In addition, we will recap other trending security news includes: - https://www.bbc.com: Loosing removable drives with sensitive data  - www.blee...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/><br/>The bad guys love using legitimate tools to circumvent security monitoring and controls. One tool in particular stands head and shoulder above other programs and operating system components to attack Microsoft Windows users: That is PowerShell.</p><p>In addition, we will recap other trending security news includes:</p><p>- <a href='https://www.bbc.com/news/world-asia-61921222'>https://www.bbc.com</a>: Loosing removable drives with sensitive data<br/> - <a href='https://www.bleepingcomputer.com/news/security/nsa-shares-tips-on-securing-windows-devices-with-powershell/'>www.bleepingcomputer.com</a>: NSA shares tips on securing Windows devices with PowerShell<br/>- <a href='https://www.theregister.com/2022/06/23/keep_poewrshell_security_advice/'>www.theregister.com</a>: Don&apos;t ditch PowerShell to improve security, say infosec agencies from UK, US, and NZ<br/>- <a href='https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF'>media.defense.gov</a>: Keeping PowerShell: Security Measures to Use and Embrace (PDF)<br/>- <a href='https://blog.talosintelligence.com/2019/11/hunting-for-lolbins.html'>https://blog.talosintelligence.com</a>:  Hunting for LOLbins <br/>-<a href='https://www.cisa.gov/uscert/ncas/alerts/aa22-174a'>https://www.cisa.gov</a>: Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems<b><br/></b><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/><br/>The bad guys love using legitimate tools to circumvent security monitoring and controls. One tool in particular stands head and shoulder above other programs and operating system components to attack Microsoft Windows users: That is PowerShell.</p><p>In addition, we will recap other trending security news includes:</p><p>- <a href='https://www.bbc.com/news/world-asia-61921222'>https://www.bbc.com</a>: Loosing removable drives with sensitive data<br/> - <a href='https://www.bleepingcomputer.com/news/security/nsa-shares-tips-on-securing-windows-devices-with-powershell/'>www.bleepingcomputer.com</a>: NSA shares tips on securing Windows devices with PowerShell<br/>- <a href='https://www.theregister.com/2022/06/23/keep_poewrshell_security_advice/'>www.theregister.com</a>: Don&apos;t ditch PowerShell to improve security, say infosec agencies from UK, US, and NZ<br/>- <a href='https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF'>media.defense.gov</a>: Keeping PowerShell: Security Measures to Use and Embrace (PDF)<br/>- <a href='https://blog.talosintelligence.com/2019/11/hunting-for-lolbins.html'>https://blog.talosintelligence.com</a>:  Hunting for LOLbins <br/>-<a href='https://www.cisa.gov/uscert/ncas/alerts/aa22-174a'>https://www.cisa.gov</a>: Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems<b><br/></b><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10853594-73-powershell-use-it-wisely.mp3" length="31063562" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-10853594</guid>
    <pubDate>Mon, 27 Jun 2022 19:00:00 +0400</pubDate>
    <itunes:duration>2584</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>72 - Beating cyber threats with an efficient security team</itunes:title>
    <title>72 - Beating cyber threats with an efficient security team</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Often times, organisation focus on technology, procuring the next shinny things in the market or the leading products according to analyst, peer review or testing labs. Although there is not thing wrong with, there is one important ingredient that are mostly overlooked: a well structure, efficient security team. This is what we will cover this week.  In addition, we will recap other  trending  security news  includes: Internet Ex...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Often times, organisation focus on technology, procuring the next shinny things in the market or the leading products according to analyst, peer review or testing labs. Although there is not thing wrong with, there is one important ingredient that are mostly overlooked: a well structure, efficient security team. This is what we will cover this week.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Internet Explorer says goodbye for the last time</li><li>In cybersecurity, what you can’t see can hurt you</li></ul><p>All that, coming up next, on YusufOnSecurity!<br/><br/>- <a href='https://blogs.windows.com/windowsexperience/2022/06/15/internet-explorer-11-has-retired-and-is-officially-out-of-support-what-you-need-to-know/'>https://blogs.windows.com</a>: Internet explorer 11 has retired and is officially out of support what you need to know<br/>- <a href='https://www.gigamon.com/resources/learning-center/network-visibility/what-is-network-visibility.html'>https://www.gigamon.com</a>:  Network visibility what is network visibility <br/>- <a href='https://www.cisco.com/c/en/us/products/collateral/security/stealthwatch/white-paper-c11-737513.pdf'>https://www.cisco.com</a>: The suspicious seven<br/>- <a href='https://www.microsoft.com/security/blog/2020/08/06/organize-security-team-evolution-cybersecurity-roles-responsibilities/'>https://www.microsoft.com</a>: Organize security team evolution cybersecurity roles responsibilities<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Often times, organisation focus on technology, procuring the next shinny things in the market or the leading products according to analyst, peer review or testing labs. Although there is not thing wrong with, there is one important ingredient that are mostly overlooked: a well structure, efficient security team. This is what we will cover this week.<br/><br/>In addition, we will recap other  trending  security news  includes:</p><ul><li>Internet Explorer says goodbye for the last time</li><li>In cybersecurity, what you can’t see can hurt you</li></ul><p>All that, coming up next, on YusufOnSecurity!<br/><br/>- <a href='https://blogs.windows.com/windowsexperience/2022/06/15/internet-explorer-11-has-retired-and-is-officially-out-of-support-what-you-need-to-know/'>https://blogs.windows.com</a>: Internet explorer 11 has retired and is officially out of support what you need to know<br/>- <a href='https://www.gigamon.com/resources/learning-center/network-visibility/what-is-network-visibility.html'>https://www.gigamon.com</a>:  Network visibility what is network visibility <br/>- <a href='https://www.cisco.com/c/en/us/products/collateral/security/stealthwatch/white-paper-c11-737513.pdf'>https://www.cisco.com</a>: The suspicious seven<br/>- <a href='https://www.microsoft.com/security/blog/2020/08/06/organize-security-team-evolution-cybersecurity-roles-responsibilities/'>https://www.microsoft.com</a>: Organize security team evolution cybersecurity roles responsibilities<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me on twitter @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10814230-72-beating-cyber-threats-with-an-efficient-security-team.mp3" length="30005971" type="audio/mpeg" />
    <itunes:author></itunes:author>
    <guid isPermaLink="false">Buzzsprout-10814230</guid>
    <pubDate>Sun, 19 Jun 2022 15:00:00 +0400</pubDate>
    <itunes:duration>2496</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>71 - HTML Smuggling attack</itunes:title>
    <title>71 - HTML Smuggling attack</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! The one constant them of this ever expanding threat landscpare is the creativity of the cybercrooks and their ability of improvising existing tools and techology. One case in point is the use of a combination of HTML5 and JavaScript to avade existing  business defenses.  Other top top trending security news include: GDPR turns 4Follina is Being Actively Exploited to Spread Malware- www.securityweek.com: 'Follina' Vulnerability Exploited to...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The one constant them of this ever expanding threat landscpare is the creativity of the cybercrooks and their ability of improvising existing tools and techology. One case in point is the use of a combination of HTML5 and JavaScript to avade existing  business defenses.<br/><br/>Other top top trending security news include:</p><ul><li>GDPR turns 4</li><li>Follina is Being Actively Exploited to Spread Malware</li></ul><p>- <a href='https://www.securityweek.com/follina-vulnerability-exploited-deliver-qbot-asyncrat-other-malware'>www.securityweek.com</a>: &apos;Follina&apos; Vulnerability Exploited to Deliver Qbot, AsyncRAT, Other Malware<br/>- <a href='https://www.theregister.com/2022/06/09/qbot-malware-microsoft-follina/'>www.theregister.com</a>: Now Windows Follina zero-day exploited to infect PCs with Qbot-<a href='https://gdpr.eu/tag/gdpr/'>https://gdpr.eu/tag/gdpr</a>: GDPR<br/>-<a href='https://www.onetrust.com/blog/how-four-years-of-gdpr-has-changed-the-privacy-landscape/'>https://www.onetrust.com</a>:  How four years of GDPR has changed the privacy landscape<br/>- <a href='https://info.menlosecurity.com/Evaluating-evasive-threats-in-todays-cyber-landscape_report.html'>https://info.menlosecurity.com</a>: Evaluating evasive threats in todays cyber landscape report<br/>-<a href='https://www.microsoft.com/security/blog/2021/11/11/html-smuggling-surges-highly-evasive-loader-technique-increasingly-used-in-banking-malware-targeted-attacks/'>https://microsoft.com</a>:  HTML smuggling surges highly evasive loader technique increasingly used in banking malware targeted attacks<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The one constant them of this ever expanding threat landscpare is the creativity of the cybercrooks and their ability of improvising existing tools and techology. One case in point is the use of a combination of HTML5 and JavaScript to avade existing  business defenses.<br/><br/>Other top top trending security news include:</p><ul><li>GDPR turns 4</li><li>Follina is Being Actively Exploited to Spread Malware</li></ul><p>- <a href='https://www.securityweek.com/follina-vulnerability-exploited-deliver-qbot-asyncrat-other-malware'>www.securityweek.com</a>: &apos;Follina&apos; Vulnerability Exploited to Deliver Qbot, AsyncRAT, Other Malware<br/>- <a href='https://www.theregister.com/2022/06/09/qbot-malware-microsoft-follina/'>www.theregister.com</a>: Now Windows Follina zero-day exploited to infect PCs with Qbot-<a href='https://gdpr.eu/tag/gdpr/'>https://gdpr.eu/tag/gdpr</a>: GDPR<br/>-<a href='https://www.onetrust.com/blog/how-four-years-of-gdpr-has-changed-the-privacy-landscape/'>https://www.onetrust.com</a>:  How four years of GDPR has changed the privacy landscape<br/>- <a href='https://info.menlosecurity.com/Evaluating-evasive-threats-in-todays-cyber-landscape_report.html'>https://info.menlosecurity.com</a>: Evaluating evasive threats in todays cyber landscape report<br/>-<a href='https://www.microsoft.com/security/blog/2021/11/11/html-smuggling-surges-highly-evasive-loader-technique-increasingly-used-in-banking-malware-targeted-attacks/'>https://microsoft.com</a>:  HTML smuggling surges highly evasive loader technique increasingly used in banking malware targeted attacks<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10775456-71-html-smuggling-attack.mp3" length="25467861" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10775456</guid>
    <pubDate>Sat, 11 Jun 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2118</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>70 - Network Segmentation</itunes:title>
    <title>70 - Network Segmentation</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Most business rely on an old fashioned approach to security. A hard on the outside and soft on the inside. In this episode we will look at why that can be dangerous in today pervasive connectivity and work from anywhere concept. Additionally, we will recap other top trending security news that are most pertinent today: - www.expressvpn.com: Rejecting data demands, ExpressVPN removes VPN servers in India - www.theregister.com: ExpressVPN moves s...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Most business rely on an old fashioned approach to security. A hard on the outside and soft on the inside. In this episode we will look at why that can be dangerous in today pervasive connectivity and work from anywhere concept.</p><p>Additionally, we will recap other top trending security news that are most pertinent today:</p><p>- <a href='https://www.expressvpn.com/blog/remove-india-vpn-servers/'>www.expressvpn.com</a>: Rejecting data demands, ExpressVPN removes VPN servers in India<br/>- <a href='https://www.theregister.com/2022/06/02/expressvpnservers_out_of_india/'>www.theregister.com</a>: ExpressVPN moves servers out of India to escape customer data retention law<br/>-<a href='https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/'>https://cloudsek.com</a>: Cybercriminals exploit reverse tunnel services and URL shorteners <br/>-<a href='https://www.cisco.com/c/en/us/products/security/what-is-network-segmentation.html'>https://www.cisco.com</a>: What is network segmentation<br/>-<a href='https://www.techtarget.com/searchnetworking/definition/network-segmentation'>https://techtarget.com</a>: Network segmentation<br/>-<a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf'>https://nvlpubs.nist.gov</a>: NIST SP800-207<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Most business rely on an old fashioned approach to security. A hard on the outside and soft on the inside. In this episode we will look at why that can be dangerous in today pervasive connectivity and work from anywhere concept.</p><p>Additionally, we will recap other top trending security news that are most pertinent today:</p><p>- <a href='https://www.expressvpn.com/blog/remove-india-vpn-servers/'>www.expressvpn.com</a>: Rejecting data demands, ExpressVPN removes VPN servers in India<br/>- <a href='https://www.theregister.com/2022/06/02/expressvpnservers_out_of_india/'>www.theregister.com</a>: ExpressVPN moves servers out of India to escape customer data retention law<br/>-<a href='https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/'>https://cloudsek.com</a>: Cybercriminals exploit reverse tunnel services and URL shorteners <br/>-<a href='https://www.cisco.com/c/en/us/products/security/what-is-network-segmentation.html'>https://www.cisco.com</a>: What is network segmentation<br/>-<a href='https://www.techtarget.com/searchnetworking/definition/network-segmentation'>https://techtarget.com</a>: Network segmentation<br/>-<a href='https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf'>https://nvlpubs.nist.gov</a>: NIST SP800-207<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10736644-70-network-segmentation.mp3" length="35436186" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10736644</guid>
    <pubDate>Sat, 04 Jun 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2949</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>69 - Key takeways in Verison 2022&#39;s Data Breach Investigations Report</itunes:title>
    <title>69 - Key takeways in Verison 2022&#39;s Data Breach Investigations Report</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! The more we learn, the more we know how less we know. In this episode we will cover important takeaways of the recently release Virison Data Breach Investigations Report. There are key points to be mindful of.  In addition, we will recap other top trending security news, including RCE on Microsoft Diagnostic Tool (MSDT) CISA adds more exploited vulnerabilities to the Catalog  - https://msrc-blog.microsoft.com: Guidance for CVE-2022-30190 Micros...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The more we learn, the more we know how less we know.<br/>In this episode we will cover important takeaways of the recently release Virison Data Breach Investigations Report. There are key points to be mindful of.<br/><br/>In addition, we will recap other top trending security news, including<br/>RCE on Microsoft Diagnostic Tool (MSDT)<br/>CISA adds more exploited vulnerabilities to the Catalog<br/><br/>- <a href='https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/'>https://msrc-blog.microsoft.com</a>: Guidance for CVE-2022-30190 Microsoft-support-diagnostic tool vulnerability<br/><b>- </b><a href='https://www.verizon.com/about/news/ransomware-threat-rises-verizon-2022-data-breach-investigations-report'><b>www.verizon.com</b></a>: Ransomware threat rises: Verizon 2022 Data Breach Investigations Report<br/><b>- </b><a href='https://www.theregister.com/2022/05/26/verizon-cybersecurity-report-ransomware/'><b>www.theregister.com</b></a>: Verizon: Ransomware sees biggest jump in five years<br/><b>- </b><a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog'><b>www.cisa.gov</b></a>: Known Exploited Vulnerabilities Catalog<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The more we learn, the more we know how less we know.<br/>In this episode we will cover important takeaways of the recently release Virison Data Breach Investigations Report. There are key points to be mindful of.<br/><br/>In addition, we will recap other top trending security news, including<br/>RCE on Microsoft Diagnostic Tool (MSDT)<br/>CISA adds more exploited vulnerabilities to the Catalog<br/><br/>- <a href='https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/'>https://msrc-blog.microsoft.com</a>: Guidance for CVE-2022-30190 Microsoft-support-diagnostic tool vulnerability<br/><b>- </b><a href='https://www.verizon.com/about/news/ransomware-threat-rises-verizon-2022-data-breach-investigations-report'><b>www.verizon.com</b></a>: Ransomware threat rises: Verizon 2022 Data Breach Investigations Report<br/><b>- </b><a href='https://www.theregister.com/2022/05/26/verizon-cybersecurity-report-ransomware/'><b>www.theregister.com</b></a>: Verizon: Ransomware sees biggest jump in five years<br/><b>- </b><a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog'><b>www.cisa.gov</b></a>: Known Exploited Vulnerabilities Catalog<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10697087-69-key-takeways-in-verison-2022-s-data-breach-investigations-report.mp3" length="27477286" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10697087</guid>
    <pubDate>Sat, 28 May 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2286</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>68 - How to keep your email safe from prying eyes?</itunes:title>
    <title>68 - How to keep your email safe from prying eyes?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In a world where everyone...well most, wants to snoop into your privacy, we asked how one sends and receives ones email in an encrypted format. After all email is not build fro privacy. Click send and, and it is as you posted a postcard! With some effort a dedication, a privacy hungry miscreants can watch your messages go by in clear text.  Also coming up, a couple of pertinent recent security news: these are  - iPhones are Never Fully Powered ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In a world where everyone...well most, wants to snoop into your privacy, we asked how one sends and receives ones email in an encrypted format. After all email is not build fro privacy. Click send and, and it is as you posted a postcard! With some effort a dedication, a privacy hungry miscreants can watch your messages go by in clear text.<br/><br/>Also coming up, a couple of pertinent recent security news: these are<br/><br/>- iPhones are Never Fully Powered Down<br/>- Microsoft Released an Out-of-Band Update<br/><br/><b>- </b><a href='https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2'><b>docs.microsoft.com</b></a>: Windows 11 known issues and notifications<br/>-<a href='https://www.zdnet.com/article/microsofts-out-of-band-patch-fixes-windows-ad-authentication-failures/'><b>https://www.zdnet.com</b></a>:  Microsofts out of band patch fixes Windows AD authentication failures <br/><b>- </b><a href='https://www.theregister.com/2022/05/19/apple-iphone-malware/'><b>www.theregister.com</b></a>: Your snoozing iOS 15 iPhone may actually be sleeping with one antenna open<br/><b>- </b><a href='https://arstechnica.com/information-technology/2022/05/researchers-devise-iphone-malware-that-runs-even-when-device-is-turned-off/'><b>arstechnica.com</b></a>: Researchers devise iPhone malware that runs even when device is turned off<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In a world where everyone...well most, wants to snoop into your privacy, we asked how one sends and receives ones email in an encrypted format. After all email is not build fro privacy. Click send and, and it is as you posted a postcard! With some effort a dedication, a privacy hungry miscreants can watch your messages go by in clear text.<br/><br/>Also coming up, a couple of pertinent recent security news: these are<br/><br/>- iPhones are Never Fully Powered Down<br/>- Microsoft Released an Out-of-Band Update<br/><br/><b>- </b><a href='https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2'><b>docs.microsoft.com</b></a>: Windows 11 known issues and notifications<br/>-<a href='https://www.zdnet.com/article/microsofts-out-of-band-patch-fixes-windows-ad-authentication-failures/'><b>https://www.zdnet.com</b></a>:  Microsofts out of band patch fixes Windows AD authentication failures <br/><b>- </b><a href='https://www.theregister.com/2022/05/19/apple-iphone-malware/'><b>www.theregister.com</b></a>: Your snoozing iOS 15 iPhone may actually be sleeping with one antenna open<br/><b>- </b><a href='https://arstechnica.com/information-technology/2022/05/researchers-devise-iphone-malware-that-runs-even-when-device-is-turned-off/'><b>arstechnica.com</b></a>: Researchers devise iPhone malware that runs even when device is turned off<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at  https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10653438-68-how-to-keep-your-email-safe-from-prying-eyes.mp3" length="20644556" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10653438</guid>
    <pubDate>Fri, 20 May 2022 21:00:00 +0400</pubDate>
    <itunes:duration>1716</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>67 - Reducing your attack surface</itunes:title>
    <title>67 - Reducing your attack surface</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Attack Surface is talked about a lot but it means different things to different people. This is what we will step through this week.  Also coming up, a couple of pertinent recent security news: these are  - South Asian Governments Targeted by Bitter APT Group - Apple Mail Now Blocks Email Trackers  - https://blog.talosintelligence.com: Bitter APT adds Bangladesh to their targets - https://www.wired.com: Apple mail blocks email tracking - https:...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Attack Surface is talked about a lot but it means different things to different people. This is what we will step through this week.<br/><br/>Also coming up, a couple of pertinent recent security news: these are<br/><br/>- South Asian Governments Targeted by Bitter APT Group<br/>- Apple Mail Now Blocks Email Trackers<br/><br/>- <a href='https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html#more'>https://blog.talosintelligence.com</a>: Bitter APT adds Bangladesh to their targets<br/>- <a href='https://www.wired.com/story/apple-mail-blocks-email-tracking-heres-what-it-means/'>https://www.wired.com</a>: Apple mail blocks email tracking<br/>- <a href='https://www.kaseya.com/blog/2022/01/31/attack-surface-definition-management-reduction/'>https://www.kaseya.com</a>: Attack surface<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Attack Surface is talked about a lot but it means different things to different people. This is what we will step through this week.<br/><br/>Also coming up, a couple of pertinent recent security news: these are<br/><br/>- South Asian Governments Targeted by Bitter APT Group<br/>- Apple Mail Now Blocks Email Trackers<br/><br/>- <a href='https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html#more'>https://blog.talosintelligence.com</a>: Bitter APT adds Bangladesh to their targets<br/>- <a href='https://www.wired.com/story/apple-mail-blocks-email-tracking-heres-what-it-means/'>https://www.wired.com</a>: Apple mail blocks email tracking<br/>- <a href='https://www.kaseya.com/blog/2022/01/31/attack-surface-definition-management-reduction/'>https://www.kaseya.com</a>: Attack surface<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10617105-67-reducing-your-attack-surface.mp3" length="27183493" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10617105</guid>
    <pubDate>Sat, 14 May 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2261</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>66 -  Security Assessment</itunes:title>
    <title>66 -  Security Assessment</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome back.  Given the prevalence of security holes in software and the constant shifting of the threat landscape, it is paramount that organisation carry out periodic exercises that test their security preparedness. And that is exactly what we will dive into this week.  Also coming up, few pertinent security news this week:  -https://www.nozominetworks.com/blog: Nozomi networks discovers unpatched DNS bugin po...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back.<br/><br/>Given the prevalence of security holes in software and the constant shifting of the threat landscape, it is paramount that organisation carry out periodic exercises that test their security preparedness. And that is exactly what we will dive into this week.<br/><br/>Also coming up, few pertinent security news this week:<br/><br/>-<a href='https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-dns-bug-in-popular-c-standard-library-putting-iot-at-risk/'>https://www.nozominetworks.com/blog</a>: Nozomi networks discovers unpatched DNS bugin popular  C standard library putting IoT at risk<br/><b>- </b><a href='https://www.zdnet.com/article/google-apple-microsoft-make-a-new-commitment-for-a-passwordless-future/'>www.zdnet.com</a>: Google, Apple, Microsoft make a new commitment for a &quot;passwordless future&quot;<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/microsoft-apple-and-google-to-support-fido-passwordless-logins/'>www.bleepingcomputer.com</a>: Microsoft, Apple, and Google to support FIDO passwordless logins<br/>-<a href='https://csrc.nist.gov/glossary/term/security_assessment'>https://csrc.nist.gov</a>: Security assessment<br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/> <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back.<br/><br/>Given the prevalence of security holes in software and the constant shifting of the threat landscape, it is paramount that organisation carry out periodic exercises that test their security preparedness. And that is exactly what we will dive into this week.<br/><br/>Also coming up, few pertinent security news this week:<br/><br/>-<a href='https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-dns-bug-in-popular-c-standard-library-putting-iot-at-risk/'>https://www.nozominetworks.com/blog</a>: Nozomi networks discovers unpatched DNS bugin popular  C standard library putting IoT at risk<br/><b>- </b><a href='https://www.zdnet.com/article/google-apple-microsoft-make-a-new-commitment-for-a-passwordless-future/'>www.zdnet.com</a>: Google, Apple, Microsoft make a new commitment for a &quot;passwordless future&quot;<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/microsoft-apple-and-google-to-support-fido-passwordless-logins/'>www.bleepingcomputer.com</a>: Microsoft, Apple, and Google to support FIDO passwordless logins<br/>-<a href='https://csrc.nist.gov/glossary/term/security_assessment'>https://csrc.nist.gov</a>: Security assessment<br/><br/>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/> <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10576079-66-security-assessment.mp3" length="29274005" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10576079</guid>
    <pubDate>Sat, 07 May 2022 20:00:00 +0400</pubDate>
    <itunes:duration>2435</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>65 - Top software errors leading to vulnerabilities</itunes:title>
    <title>65 - Top software errors leading to vulnerabilities</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Welcome to YusufOnSecuriy, a weekly cyber security podcast where we look at the most relevant security news of the week and follow up with a deeper look at a carefully selected cyber security domain.  In this week's episode we will continue digging into the software errors and their consequences, vulnerabilities and exploitation.  I said it is part of life but it does not has to stay that way.  Also coming up, are a number of security...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecuriy, a weekly cyber security podcast where we look at the most relevant security news of the week and follow up with a deeper look at a carefully selected cyber security domain. <br/>In this week&apos;s episode we will continue digging into the software errors and their consequences, vulnerabilities and exploitation.  I said it is part of life but it does not has to stay that way.<br/><br/>Also coming up, are a number of security updates this week. These are:</p><ul><li>Cloudflare blocked huge DDoS attack</li><li>You Can Now Ask Google to Remove Your Phone Number, Email or Address from Search Results</li></ul><p>-<a href='https://blog.google/products/search/new-options-for-removing-your-personally-identifiable-information-from-search/'>www.google.com</a>: New options for removing your personally identifiable information from Google Search<br/>-<a href='https://blog.cloudflare.com/15m-rps-ddos-attack/'>www.cloudflare.com</a>: Cloudflare blocks 15M rps HTTPS DDoS attack<br/>-<a href='https://www.sans.org/top25-software-errors/'>www.sans.org</a>: SANS top 25 dangerous  software errors of 2021<br/>-<a href='https://cwe.mitre.org/top25/archive/2021/2021_cwe_top25.html'>https://cwe.mitre.org</a>: 2021 CWE Top 25 Most Dangerous Software Weaknesses<br/><br/></p><p>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/> <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Welcome to YusufOnSecuriy, a weekly cyber security podcast where we look at the most relevant security news of the week and follow up with a deeper look at a carefully selected cyber security domain. <br/>In this week&apos;s episode we will continue digging into the software errors and their consequences, vulnerabilities and exploitation.  I said it is part of life but it does not has to stay that way.<br/><br/>Also coming up, are a number of security updates this week. These are:</p><ul><li>Cloudflare blocked huge DDoS attack</li><li>You Can Now Ask Google to Remove Your Phone Number, Email or Address from Search Results</li></ul><p>-<a href='https://blog.google/products/search/new-options-for-removing-your-personally-identifiable-information-from-search/'>www.google.com</a>: New options for removing your personally identifiable information from Google Search<br/>-<a href='https://blog.cloudflare.com/15m-rps-ddos-attack/'>www.cloudflare.com</a>: Cloudflare blocks 15M rps HTTPS DDoS attack<br/>-<a href='https://www.sans.org/top25-software-errors/'>www.sans.org</a>: SANS top 25 dangerous  software errors of 2021<br/>-<a href='https://cwe.mitre.org/top25/archive/2021/2021_cwe_top25.html'>https://cwe.mitre.org</a>: 2021 CWE Top 25 Most Dangerous Software Weaknesses<br/><br/></p><p>Be sure to subscribe!  <br/> <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/> <br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10531738-65-top-software-errors-leading-to-vulnerabilities.mp3" length="25650664" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10531738</guid>
    <pubDate>Sat, 30 Apr 2022 14:00:00 +0400</pubDate>
    <itunes:duration>2133</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>64 - What are the different types of vulnerabilities?</itunes:title>
    <title>64 - What are the different types of vulnerabilities?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Vulnerabilities is part of life. It is even more so in the cyber world. This week we will look in to the type of vulnerabilities that are there. Once thing is for sure, they are not all exploited equally. Some are more damaging, others take time, resources and perseverance to pull them off. Simply put they are part of the firebrick of modern technology. Also coming up, a number of security updates, including this week -Google Project Zero track...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Vulnerabilities is part of life. It is even more so in the cyber world. This week we will look in to the type of vulnerabilities that are there. Once thing is for sure, they are not all exploited equally. Some are more damaging, others take time, resources and perseverance to pull them off. Simply put they are part of the firebrick of modern technology.<br/>Also coming up, a number of security updates, including this week<br/>-Google Project Zero tracked a record  exploited in the wild<br/>-Microsoft Windows Autopatch<br/><br/>-<a href='https://googleprojectzero.blogspot.com/2022/04/the-more-you-know-more-you-know-you.html'>https://googleprojectzero.blogpost.com</a>: Google Project Zero tracked a record  exploited-in-the-wild<br/>-<a href='https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit#gid=0'>https://docs.google.com</a>: 0day &quot;In the Wild&quot; sheet<br/>-<a href='https://thehackernews.com/2022/04/google-project-zero-detects-record.html'>https://thehackernews.com</a>: Google project zero detects record Zero-Day exploits in 2021<br/>-<a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-current-and-stay-current-with-windows-autopatch/ba-p/3271839'>https://techcommunity.microsoft.com</a>: Get current and stay current with Windows Autopatch<br/> -<a href='https://www.sans.org/top25-software-errors'>https://www.sans.org</a>: Top 25 software errors<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Vulnerabilities is part of life. It is even more so in the cyber world. This week we will look in to the type of vulnerabilities that are there. Once thing is for sure, they are not all exploited equally. Some are more damaging, others take time, resources and perseverance to pull them off. Simply put they are part of the firebrick of modern technology.<br/>Also coming up, a number of security updates, including this week<br/>-Google Project Zero tracked a record  exploited in the wild<br/>-Microsoft Windows Autopatch<br/><br/>-<a href='https://googleprojectzero.blogspot.com/2022/04/the-more-you-know-more-you-know-you.html'>https://googleprojectzero.blogpost.com</a>: Google Project Zero tracked a record  exploited-in-the-wild<br/>-<a href='https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit#gid=0'>https://docs.google.com</a>: 0day &quot;In the Wild&quot; sheet<br/>-<a href='https://thehackernews.com/2022/04/google-project-zero-detects-record.html'>https://thehackernews.com</a>: Google project zero detects record Zero-Day exploits in 2021<br/>-<a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-current-and-stay-current-with-windows-autopatch/ba-p/3271839'>https://techcommunity.microsoft.com</a>: Get current and stay current with Windows Autopatch<br/> -<a href='https://www.sans.org/top25-software-errors'>https://www.sans.org</a>: Top 25 software errors<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10489143-64-what-are-the-different-types-of-vulnerabilities.mp3" length="27528663" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10489143</guid>
    <pubDate>Sat, 23 Apr 2022 18:00:00 +0400</pubDate>
    <itunes:duration>2290</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>63 - How can everyday person protect themself from cyber attack?</itunes:title>
    <title>63 - How can everyday person protect themself from cyber attack?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, I welcome you to the show in this fine April day.  I talk a lot about cyber security for businesses and enterprises at large but about the individuals; they too suffer the consequence of cyber attacks aren't they? Well that is what I will cover this week: how do you go about your day to day usage of technology and the internet in particular while staying safe from the cyber crooks?  Also coming up, a couple of to...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, I welcome you to the show in this fine April day.<br/><br/>I talk a lot about cyber security for businesses and enterprises at large but about the individuals; they too suffer the consequence of cyber attacks aren&apos;t they? Well that is what I will cover this week: how do you go about your day to day usage of technology and the internet in particular while staying safe from the cyber crooks?<br/><br/>Also coming up, a couple of top of mind security updates:<br/>- Ransomware gangs operate just like a business<br/>- A new versatile malware toolkit against Industrial Control System emerged<br/><br/>-<a href='https://www.zdnet.com/article/leaks-reveal-the-surprisingly-mundane-reality-of-working-for-a-ransomware-gang/'> https://zdnet.com</a>: Ransomware gang operate just like a real business<br/> -<a href='https://hub.dragos.com/hubfs/116-Whitepapers/Dragos_ChernoviteWP_v2b.pdf'>www.hub.dragos.com</a>: PIPEDREAM<br/>-<a href='https://www.wired.com/story/pipedream-ics-malware/'>www.wired.com</a>:  Feds Uncover a ‘Swiss Army Knife’ for Hacking Industrial Control Systems<br/>- <a href='https://duo.com'>https://duo.com</a>: Two Factor Authentication<br/>- <a href='https://haveibeenpwned.com'>https://haveibeenpwned.com</a>: Check if you email appeared in a data breach<br/>- <a href='https://www.cisa.gov/4-things-you-can-do-keep-yourself-cyber-safe'>https://www.cisa.gov</a>: Things you can do keep yourself cyber safe<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, I welcome you to the show in this fine April day.<br/><br/>I talk a lot about cyber security for businesses and enterprises at large but about the individuals; they too suffer the consequence of cyber attacks aren&apos;t they? Well that is what I will cover this week: how do you go about your day to day usage of technology and the internet in particular while staying safe from the cyber crooks?<br/><br/>Also coming up, a couple of top of mind security updates:<br/>- Ransomware gangs operate just like a business<br/>- A new versatile malware toolkit against Industrial Control System emerged<br/><br/>-<a href='https://www.zdnet.com/article/leaks-reveal-the-surprisingly-mundane-reality-of-working-for-a-ransomware-gang/'> https://zdnet.com</a>: Ransomware gang operate just like a real business<br/> -<a href='https://hub.dragos.com/hubfs/116-Whitepapers/Dragos_ChernoviteWP_v2b.pdf'>www.hub.dragos.com</a>: PIPEDREAM<br/>-<a href='https://www.wired.com/story/pipedream-ics-malware/'>www.wired.com</a>:  Feds Uncover a ‘Swiss Army Knife’ for Hacking Industrial Control Systems<br/>- <a href='https://duo.com'>https://duo.com</a>: Two Factor Authentication<br/>- <a href='https://haveibeenpwned.com'>https://haveibeenpwned.com</a>: Check if you email appeared in a data breach<br/>- <a href='https://www.cisa.gov/4-things-you-can-do-keep-yourself-cyber-safe'>https://www.cisa.gov</a>: Things you can do keep yourself cyber safe<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10448421-63-how-can-everyday-person-protect-themself-from-cyber-attack.mp3" length="29820146" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10448421</guid>
    <pubDate>Sat, 16 Apr 2022 14:00:00 +0400</pubDate>
    <itunes:duration>2481</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>62 - Digital Forensics 101 - Part 2</itunes:title>
    <title>62 - Digital Forensics 101 - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome back.  Often it is not about what came in but rather what has been left behind. This week we willl continue our introduction to digital forensics and what is involved when carrying out this painstaking process. In this episode, we will go one level down into the details. So bucle up! Also coming up, a couple of pertinent security news that you might find relevant, including: First malware targeting A...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back. <br/>Often it is not about what came in but rather what has been left behind. This week we willl continue our introduction to digital forensics and what is involved when carrying out this painstaking process. In this episode, we will go one level down into the details. So bucle up!<br/>Also coming up, a couple of pertinent security news that you might find relevant, including:</p><ul><li>First malware targeting AWS Lambda Serverless Platform. </li><li>The cyber crooks are using fake police data requests against tech companies</li></ul><p>- <a href='https://thehackernews.com/2022/04/first-malware-targeting-aws-lambda.html'>https://thehackernews.com</a>: First malware targeting AWS Lambda Serverless Platform discovered<br/>- <a href='https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/'>https://krebsonsecurity.com</a>: Hackers are obtaining sensitive data through fake emergency requests<br/> <br/>- <a href='https://www.volatilityfoundation.org'>https://www.volatilityfoundation.org</a>: Open Source Forensics tools<br/>- <a href='https://www.kroll.com/en/insights/publications/cyber/kroll-artifact-parser-extractor-kape'>https://kroll.com</a>:  KAPE - Artifact parser extractor<br/>- <a href='https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training/'>https://www.sans.org</a>: The forensic course from SANS - DFIR508<br/>- <a href='https://www.coursera.org/lecture/introduction-cybersecurity-cyber-attacks/what-is-digital-forensics-g4XXt'>https://coursera.org</a>: Introduction to digital forensics<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back. <br/>Often it is not about what came in but rather what has been left behind. This week we willl continue our introduction to digital forensics and what is involved when carrying out this painstaking process. In this episode, we will go one level down into the details. So bucle up!<br/>Also coming up, a couple of pertinent security news that you might find relevant, including:</p><ul><li>First malware targeting AWS Lambda Serverless Platform. </li><li>The cyber crooks are using fake police data requests against tech companies</li></ul><p>- <a href='https://thehackernews.com/2022/04/first-malware-targeting-aws-lambda.html'>https://thehackernews.com</a>: First malware targeting AWS Lambda Serverless Platform discovered<br/>- <a href='https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/'>https://krebsonsecurity.com</a>: Hackers are obtaining sensitive data through fake emergency requests<br/> <br/>- <a href='https://www.volatilityfoundation.org'>https://www.volatilityfoundation.org</a>: Open Source Forensics tools<br/>- <a href='https://www.kroll.com/en/insights/publications/cyber/kroll-artifact-parser-extractor-kape'>https://kroll.com</a>:  KAPE - Artifact parser extractor<br/>- <a href='https://www.sans.org/cyber-security-courses/advanced-incident-response-threat-hunting-training/'>https://www.sans.org</a>: The forensic course from SANS - DFIR508<br/>- <a href='https://www.coursera.org/lecture/introduction-cybersecurity-cyber-attacks/what-is-digital-forensics-g4XXt'>https://coursera.org</a>: Introduction to digital forensics<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10406868-62-digital-forensics-101-part-2.mp3" length="40280562" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10406868</guid>
    <pubDate>Sat, 09 Apr 2022 14:00:00 +0400</pubDate>
    <itunes:duration>3353</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>61 - Digital Forensics 101 - Part 1</itunes:title>
    <title>61 - Digital Forensics 101 - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome onboard to this week's show. Often it is not about what came in but rather what has been left behind. This week we will look at introducing digital forensics and what is involved when carrying out this painstaking process.  Also coming up, a couple of pertinent security news that you might find relevant, including MITTRE Evaluation round 4 is out. Gitlab vuln that might need your attention.   - https://ww...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome onboard to this week&apos;s show.<br/>Often it is not about what came in but rather what has been left behind. This week we will look at introducing digital forensics and what is involved when carrying out this painstaking process. <br/>Also coming up, a couple of pertinent security news that you might find relevant, including MITTRE Evaluation round 4 is out. Gitlab vuln that might need your attention. <br/><br/>- <a href='https://www.cynet.com/blog/learn-how-to-interpret-the-2022-mitre-attck-evaluation-results/?utm_source=thn'>https://www.cynet.com</a>: 2022 MITRE ATT&amp;CK Evaluation Results Overview<br/> - <a href='https://attack.mitre.org'>https://attack.mitre.org</a>: ATT&amp;CK<br/>- <a href='https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/'>https://about.gitlab.com</a>: Critical security release GitLab 14-9-2 released<br/>- <a href='https://en.wikipedia.org/wiki/Digital_forensics'>https://en.wikipedia.org</a>: Digital forensics<br/>-<a href='https://www.trustwave.com/en-us/resources/library/documents/2019-trustwave-global-security-report/'>https://trustwave.com</a>: 2019 Trustwave global security report. Please review this within the context of today more recent version. <br/>-<a href='https://www.verizon.com/business/resources/reports/dbir/'>https://www.verizon.com</a>: Data Breach Investigations Report<br/>-<a href='https://www.cisco.com/c/en/us/products/security/security-outcomes-study.html?CCID=cc000160&amp;DTID=odicdc000016&amp;OID=rptsc023926'>https://www.cisco.com</a>: Security outcomes study report<br/>- <a href='https://talosintelligence.com/incident_response/emergency'>https://talosintelligence.com</a>: Incident Response Emergency<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome onboard to this week&apos;s show.<br/>Often it is not about what came in but rather what has been left behind. This week we will look at introducing digital forensics and what is involved when carrying out this painstaking process. <br/>Also coming up, a couple of pertinent security news that you might find relevant, including MITTRE Evaluation round 4 is out. Gitlab vuln that might need your attention. <br/><br/>- <a href='https://www.cynet.com/blog/learn-how-to-interpret-the-2022-mitre-attck-evaluation-results/?utm_source=thn'>https://www.cynet.com</a>: 2022 MITRE ATT&amp;CK Evaluation Results Overview<br/> - <a href='https://attack.mitre.org'>https://attack.mitre.org</a>: ATT&amp;CK<br/>- <a href='https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/'>https://about.gitlab.com</a>: Critical security release GitLab 14-9-2 released<br/>- <a href='https://en.wikipedia.org/wiki/Digital_forensics'>https://en.wikipedia.org</a>: Digital forensics<br/>-<a href='https://www.trustwave.com/en-us/resources/library/documents/2019-trustwave-global-security-report/'>https://trustwave.com</a>: 2019 Trustwave global security report. Please review this within the context of today more recent version. <br/>-<a href='https://www.verizon.com/business/resources/reports/dbir/'>https://www.verizon.com</a>: Data Breach Investigations Report<br/>-<a href='https://www.cisco.com/c/en/us/products/security/security-outcomes-study.html?CCID=cc000160&amp;DTID=odicdc000016&amp;OID=rptsc023926'>https://www.cisco.com</a>: Security outcomes study report<br/>- <a href='https://talosintelligence.com/incident_response/emergency'>https://talosintelligence.com</a>: Incident Response Emergency<br/><br/>Be sure to subscribe!  <br/>  <br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com <br/>  <br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10365700-61-digital-forensics-101-part-1.mp3" length="23329078" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10365700</guid>
    <pubDate>Sat, 02 Apr 2022 21:00:00 +0400</pubDate>
    <itunes:duration>1940</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>60 - GISEC 2022 Dubai</itunes:title>
    <title>60 - GISEC 2022 Dubai</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this week's episode, I am bring you coverage from Gulf Information Security Expo &amp; Conference (GISEC) 2022 Dubai. GISEC is a security focus version of GITEX the "Gulf Information Technology Exhibition" that is held in October each in Dubai where thousands of exhibitors and ten of thousands of visitors decent each year in October.  Also coming up, a couple of top of mind security news that caught the eyes of many: -https://www.vice.com: M...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, I am bring you coverage from Gulf Information Security Expo &amp; Conference (GISEC) 2022 Dubai. GISEC is a security focus version of GITEX the &quot;Gulf Information Technology Exhibition&quot; that is held in October each in Dubai where thousands of exhibitors and ten of thousands of visitors decent each year in October.<br/><br/>Also coming up, a couple of top of mind security news that caught the eyes of many:<br/>-<a href='https://www.vice.com/en/article/y3vk9x/microsoft-hacked-lapsus-extortion-investigating &quot;www.vice.com/en/article/y3vk9x/microsoft-hacked-lapsus-extortion-investigating'>https://www.vice.com</a>: Microsoft Investigating Lapsus$ Hacking Claims<br/>- <a href='https://media.fidoalliance.org/wp-content/uploads/2022/03/FIDO-White-Paper-Choosing-FIDO-Authenticators-for-Enterprise-Use-Cases-RD10-2022.03.01.pdf'>https://media.fidoalliance.org</a>: FIDO Alliance’s Vision for Passwordless Authentication<br/>-<a href='https://www.gisec.ae'>https://www.gisec.ae</a>: GISEC 2022 Dubai<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this week&apos;s episode, I am bring you coverage from Gulf Information Security Expo &amp; Conference (GISEC) 2022 Dubai. GISEC is a security focus version of GITEX the &quot;Gulf Information Technology Exhibition&quot; that is held in October each in Dubai where thousands of exhibitors and ten of thousands of visitors decent each year in October.<br/><br/>Also coming up, a couple of top of mind security news that caught the eyes of many:<br/>-<a href='https://www.vice.com/en/article/y3vk9x/microsoft-hacked-lapsus-extortion-investigating &quot;www.vice.com/en/article/y3vk9x/microsoft-hacked-lapsus-extortion-investigating'>https://www.vice.com</a>: Microsoft Investigating Lapsus$ Hacking Claims<br/>- <a href='https://media.fidoalliance.org/wp-content/uploads/2022/03/FIDO-White-Paper-Choosing-FIDO-Authenticators-for-Enterprise-Use-Cases-RD10-2022.03.01.pdf'>https://media.fidoalliance.org</a>: FIDO Alliance’s Vision for Passwordless Authentication<br/>-<a href='https://www.gisec.ae'>https://www.gisec.ae</a>: GISEC 2022 Dubai<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10320917-60-gisec-2022-dubai.mp3" length="21191815" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10320917</guid>
    <pubDate>Sat, 26 Mar 2022 13:00:00 +0400</pubDate>
    <itunes:duration>1762</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>59 - Secure Access</itunes:title>
    <title>59 - Secure Access</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for you yet another YusufOnSecurity episode. Welcome back.  This week I will have a look at the important topic of remote access. I think you will agree that this is top of mind for CISO and any C-suite that cares about the bottom line of their business.  Also comping up:  Microsoft Releases Scanner to Detect TrickBot-Infected Devices Internet Explorer 11 is Being Retired in June  - www.microsoft.com: Uncovering Trickbot’s use of IoT...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for you yet another YusufOnSecurity episode. Welcome back.<br/><br/>This week I will have a look at the important topic of remote access. I think you will agree that this is top of mind for CISO and any C-suite that cares about the bottom line of their business.<br/><br/>Also comping up:<br/><br/><strong>Microsoft Releases Scanner to Detect TrickBot-Infected Devices<br/>Internet Explorer 11 is Being Retired in June<br/></strong><br/><strong>- </strong><a href='https://www.microsoft.com/security/blog/2022/03/16/uncovering-trickbots-use-of-iot-devices-in-command-and-control-infrastructure/'><strong>www.microsoft.com</strong></a>: Uncovering Trickbot’s use of IoT devices in command-and-control infrastructure<br/><strong>- </strong><a href='https://www.theregister.com/2022/03/17/microsoft_trickbot_scanner/'><strong>www.theregister.com</strong></a>: Has Trickbot gang hijacked your router? This scanner may have an answer<br/><br/><strong>- </strong><a href='https://docs.microsoft.com/en-us/windows/release-health/windows-message-center#2792'><strong>docs.microsoft.com</strong></a>: Internet Explorer 11 desktop app retires June 15, 2022<br/><strong>- </strong><a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/internet-explorer-11-desktop-app-retirement-faq/ba-p/2366549'><strong>techcommunity.microsoft.com</strong></a>: Internet Explorer 11 desktop app retirement FAQ<br/>-<a href='https://www.cisco.com/c/m/en_us/solutions/enterprise-networks/secure-network-access/secure-access-infographic.html'>www.cisco.com</a>: Secure Access <br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for you yet another YusufOnSecurity episode. Welcome back.<br/><br/>This week I will have a look at the important topic of remote access. I think you will agree that this is top of mind for CISO and any C-suite that cares about the bottom line of their business.<br/><br/>Also comping up:<br/><br/><strong>Microsoft Releases Scanner to Detect TrickBot-Infected Devices<br/>Internet Explorer 11 is Being Retired in June<br/></strong><br/><strong>- </strong><a href='https://www.microsoft.com/security/blog/2022/03/16/uncovering-trickbots-use-of-iot-devices-in-command-and-control-infrastructure/'><strong>www.microsoft.com</strong></a>: Uncovering Trickbot’s use of IoT devices in command-and-control infrastructure<br/><strong>- </strong><a href='https://www.theregister.com/2022/03/17/microsoft_trickbot_scanner/'><strong>www.theregister.com</strong></a>: Has Trickbot gang hijacked your router? This scanner may have an answer<br/><br/><strong>- </strong><a href='https://docs.microsoft.com/en-us/windows/release-health/windows-message-center#2792'><strong>docs.microsoft.com</strong></a>: Internet Explorer 11 desktop app retires June 15, 2022<br/><strong>- </strong><a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/internet-explorer-11-desktop-app-retirement-faq/ba-p/2366549'><strong>techcommunity.microsoft.com</strong></a>: Internet Explorer 11 desktop app retirement FAQ<br/>-<a href='https://www.cisco.com/c/m/en_us/solutions/enterprise-networks/secure-network-access/secure-access-infographic.html'>www.cisco.com</a>: Secure Access <br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10278238-59-secure-access.mp3" length="24711444" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10278238</guid>
    <pubDate>Sat, 19 Mar 2022 15:00:00 +0400</pubDate>
    <itunes:duration>2055</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>58 - iOT Security </itunes:title>
    <title>58 - iOT Security </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this weeks' show, lets turn our attention to an ever increasing army of small things which are becoming more pervasive: Internet Of Things.   Also coming up, a number of updates including:  A couple of leaks and this time from the good side unfortunately - Nvidia and Samsung A firefox emergency update. Browsers are the windows to the internet for many. So it is important that they get the attention they deserve.  - www.theregister.com: Leake...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this weeks&apos; show, lets turn our attention to an ever increasing army of small things which are becoming more pervasive: Internet Of Things. <br/><br/>Also coming up, a number of updates including:<br/><br/>A couple of leaks and this time from the good side unfortunately - Nvidia and Samsung<br/>A firefox emergency update. Browsers are the windows to the internet for many. So it is important that they get the attention they deserve.<br/><br/><strong>- </strong><a href='https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/'><strong>www.theregister.com</strong></a>: Leaked stolen Nvidia cert can sign Windows malware<br/><strong>- </strong><a href='https://www.scmagazine.com/news/breach/samsung-confirms-galaxy-device-source-code-leaked-after-breach'><strong>www.scmagazine.com</strong></a>: Samsung confirms Galaxy device source code leaked after breach<br/>-<a href='https://blogs.cisco.com/tag/iot-security'>www.blogs.cisco.com</a>: iOT Security<br/>-<a href='https://www.gartner.com/en/doc/iot-security-primer-challenges-and-emerging-practices'>https://www.gartner.com</a>: iOT security primer challenges and emerging practices<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this weeks&apos; show, lets turn our attention to an ever increasing army of small things which are becoming more pervasive: Internet Of Things. <br/><br/>Also coming up, a number of updates including:<br/><br/>A couple of leaks and this time from the good side unfortunately - Nvidia and Samsung<br/>A firefox emergency update. Browsers are the windows to the internet for many. So it is important that they get the attention they deserve.<br/><br/><strong>- </strong><a href='https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/'><strong>www.theregister.com</strong></a>: Leaked stolen Nvidia cert can sign Windows malware<br/><strong>- </strong><a href='https://www.scmagazine.com/news/breach/samsung-confirms-galaxy-device-source-code-leaked-after-breach'><strong>www.scmagazine.com</strong></a>: Samsung confirms Galaxy device source code leaked after breach<br/>-<a href='https://blogs.cisco.com/tag/iot-security'>www.blogs.cisco.com</a>: iOT Security<br/>-<a href='https://www.gartner.com/en/doc/iot-security-primer-challenges-and-emerging-practices'>https://www.gartner.com</a>: iOT security primer challenges and emerging practices<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10236984-58-iot-security.mp3" length="26483800" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10236984</guid>
    <pubDate>Sat, 12 Mar 2022 21:00:00 +0400</pubDate>
    <itunes:duration>2203</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>57 - Concept of XDR</itunes:title>
    <title>57 - Concept of XDR</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this weeks' episode I will look into demystifying the concept of XDR. I will try to do just to compare and contrast with other technology that came before it: SIEM and SOAR in particular.  But before that, and as always I have a few update for you this week on what to keep an eye on. Canti ransomware leaked a treasure trove of chat communication Hive Ransomware encryption succumb to academic analysis http://krebsonsecurity.com: Conti ransomw...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this weeks&apos; episode I will look into demystifying the concept of XDR. I will try to do just to compare and contrast with other technology that came before it: SIEM and SOAR in particular.<br/><br/>But before that, and as always I have a few update for you this week on what to keep an eye on.<br/>Canti ransomware leaked a treasure trove of chat communication<br/>Hive Ransomware encryption succumb to academic analysis<br/><a href='https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-iii-weaponry/'>http://krebsonsecurity.com</a>: Conti ransomware group diaries<br/><a href='https://cyberintelmag.com/malware-viruses/hive-ransomwares-master-key-recovered-using-weakness-in-its-encryption-algorithm/'>https://cyberintelmag.com</a>: Hive ransomware master key recovered<br/><a href='https://www.cisco.com/c/en/us/products/security/what-is-xdr.html'>http://www.cisco.com</a>: What is XDR?<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this weeks&apos; episode I will look into demystifying the concept of XDR. I will try to do just to compare and contrast with other technology that came before it: SIEM and SOAR in particular.<br/><br/>But before that, and as always I have a few update for you this week on what to keep an eye on.<br/>Canti ransomware leaked a treasure trove of chat communication<br/>Hive Ransomware encryption succumb to academic analysis<br/><a href='https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-iii-weaponry/'>http://krebsonsecurity.com</a>: Conti ransomware group diaries<br/><a href='https://cyberintelmag.com/malware-viruses/hive-ransomwares-master-key-recovered-using-weakness-in-its-encryption-algorithm/'>https://cyberintelmag.com</a>: Hive ransomware master key recovered<br/><a href='https://www.cisco.com/c/en/us/products/security/what-is-xdr.html'>http://www.cisco.com</a>: What is XDR?<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10192949-57-concept-of-xdr.mp3" length="33320882" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10192949</guid>
    <pubDate>Sat, 05 Mar 2022 20:00:00 +0400</pubDate>
    <itunes:duration>2773</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>56 -Identity and authentication</itunes:title>
    <title>56 -Identity and authentication</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode lets have a look at an important aspect of security, one that is becoming a battle ground lately: identity and authentication.  As always I have a fews update for you this week on what is churning lately  including: -https://blog.talosintelligence.com: Threat Advisory Cyclops blink - www.wired.com: Russia’s Sandworm Hackers Have Built a Botnet of Firewalls -https://www.euronews.com: Is Russia using cyberattacks in the war w...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode lets have a look at an important aspect of security, one that is becoming a battle ground lately: identity and authentication.<br/><br/>As always I have a fews update for you this week on what is churning lately  including:<br/>-<a href='https://blog.talosintelligence.com/2022/02/threat-advisory-cyclops-blink.html'><b>https://blog.talosintelligence.com</b></a>: Threat Advisory Cyclops blink<br/><b>- </b><a href='https://www.wired.com/story/sandworm-cyclops-blink-hacking-tool/'><b>www.wired.com</b></a>: Russia’s Sandworm Hackers Have Built a Botnet of Firewalls<br/>-<a href='https://www.euronews.com/next/2022/02/24/russia-is-using-cyberattacks-in-the-war-with-ukraine-and-sanctions-may-increase-them'>https://www.euronews.com</a>: Is Russia using cyberattacks in the war with Ukraine and could sanctions provoke more of them?</p><p>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode lets have a look at an important aspect of security, one that is becoming a battle ground lately: identity and authentication.<br/><br/>As always I have a fews update for you this week on what is churning lately  including:<br/>-<a href='https://blog.talosintelligence.com/2022/02/threat-advisory-cyclops-blink.html'><b>https://blog.talosintelligence.com</b></a>: Threat Advisory Cyclops blink<br/><b>- </b><a href='https://www.wired.com/story/sandworm-cyclops-blink-hacking-tool/'><b>www.wired.com</b></a>: Russia’s Sandworm Hackers Have Built a Botnet of Firewalls<br/>-<a href='https://www.euronews.com/next/2022/02/24/russia-is-using-cyberattacks-in-the-war-with-ukraine-and-sanctions-may-increase-them'>https://www.euronews.com</a>: Is Russia using cyberattacks in the war with Ukraine and could sanctions provoke more of them?</p><p>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10147168-56-identity-and-authentication.mp3" length="32657919" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10147168</guid>
    <pubDate>Sat, 26 Feb 2022 19:00:00 +0400</pubDate>
    <itunes:duration>2717</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>55 -Lessons from the Irish Health Services Executive Hack - Part 2</itunes:title>
    <title>55 -Lessons from the Irish Health Services Executive Hack - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is part 2  of a two parts episode where I am covering Lessons from the Irish Health Services Executive Hack. If you have not listen to part 1, please do so. In part 1, I gave the introduction to the incident and other related background details.  As always I have a fews update for you on what is in news this week. This including: -U.S. Cybersecurity Agency Publishes List of Free Security Tools and Services -Google’s Project Zero 2021 ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is part 2  of a two parts episode where I am covering Lessons from the Irish Health Services Executive Hack. If you have not listen to part 1, please do so. In part 1, I gave the introduction to the incident and other related background details.<br/><br/>As always I have a fews update for you on what is in news this week. This including:<br/>-U.S. Cybersecurity Agency Publishes List of Free Security Tools and Services<br/>-Google’s Project Zero 2021 Metrics<br/><br/>-<a href='https://www.cisa.gov/news/2022/02/18/cisa-launches-new-catalog-free-public-and-private-sector-cybersecurity-services'>https://www.cisa.gov</a>: Free tools from CIS for the public and private sector <br/><b>- </b><a href='https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html'>googleprojectzero.blogspot.com</a>: A walk through Project Zero metrics<br/>-<a href='https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf'>https://www.hse.ie</a>: Conti cyber attack on the HSE full report<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is part 2  of a two parts episode where I am covering Lessons from the Irish Health Services Executive Hack. If you have not listen to part 1, please do so. In part 1, I gave the introduction to the incident and other related background details.<br/><br/>As always I have a fews update for you on what is in news this week. This including:<br/>-U.S. Cybersecurity Agency Publishes List of Free Security Tools and Services<br/>-Google’s Project Zero 2021 Metrics<br/><br/>-<a href='https://www.cisa.gov/news/2022/02/18/cisa-launches-new-catalog-free-public-and-private-sector-cybersecurity-services'>https://www.cisa.gov</a>: Free tools from CIS for the public and private sector <br/><b>- </b><a href='https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html'>googleprojectzero.blogspot.com</a>: A walk through Project Zero metrics<br/>-<a href='https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf'>https://www.hse.ie</a>: Conti cyber attack on the HSE full report<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10105945-55-lessons-from-the-irish-health-services-executive-hack-part-2.mp3" length="24479259" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10105945</guid>
    <pubDate>Sat, 19 Feb 2022 23:00:00 +0400</pubDate>
    <itunes:duration>2036</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>54 - Lessons from the Irish Health Services Executive Hack - Part 1</itunes:title>
    <title>54 - Lessons from the Irish Health Services Executive Hack - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is a two part episode and my goodness is it loaded with useful technical details.  Additionally I'll look at at two particular security updates pertaining to the most popular  platform when it comes to operating systems: Windows!  Microsoft took important steps forward in reducing the surface of attack. All that before we get into the meat of the matter for today: lessons learned from the Irish HSE  -https://docs.microsoft.c...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is a two part episode and my goodness is it loaded with useful technical details.  Additionally I&apos;ll look at at two particular security updates pertaining to the most popular  platform when it comes to operating systems: Windows!  Microsoft took important steps forward in reducing the surface of attack. All that before we get into the meat of the matter for today: lessons learned from the Irish HSE<br/><br/>-<a href='https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmic'>https://docs.microsoft.com</a>: WMIC<br/><br/>-<a href='https://docs.microsoft.com/en-us/deployoffice/security/internet-macros-blocked'>https://docs.microsoft.com</a>: Internet macros blocked<br/><br/>-<a href='https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-deprecated-features'>https://docs.microsoft.com</a>: Windows10 deprecated features<br/><br/>-<a href='https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf'>https://www.hse.ie</a>: Conti cyber attack on the HSE full report<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is a two part episode and my goodness is it loaded with useful technical details.  Additionally I&apos;ll look at at two particular security updates pertaining to the most popular  platform when it comes to operating systems: Windows!  Microsoft took important steps forward in reducing the surface of attack. All that before we get into the meat of the matter for today: lessons learned from the Irish HSE<br/><br/>-<a href='https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmic'>https://docs.microsoft.com</a>: WMIC<br/><br/>-<a href='https://docs.microsoft.com/en-us/deployoffice/security/internet-macros-blocked'>https://docs.microsoft.com</a>: Internet macros blocked<br/><br/>-<a href='https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-deprecated-features'>https://docs.microsoft.com</a>: Windows10 deprecated features<br/><br/>-<a href='https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf'>https://www.hse.ie</a>: Conti cyber attack on the HSE full report<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10061766-54-lessons-from-the-irish-health-services-executive-hack-part-1.mp3" length="20667473" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10061766</guid>
    <pubDate>Sat, 12 Feb 2022 20:00:00 +0400</pubDate>
    <itunes:duration>1718</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>53 - Common Vulnerability Scoring System (CVSS)</itunes:title>
    <title>53 - Common Vulnerability Scoring System (CVSS)</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode I will delve into the vulnerability measuring and scoring metrics, the subsets of those and the why and how these are used. An important knowledge to be had if you are responsible of security pertaining to a SOC/RISK or Security teams. In addition, we will recap other top trending security news including: -ESET antivirus bug leads to system privilege gain. -O365 and Azure AD were target of billions of brute-force attacks  Here a...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode I will delve into the vulnerability measuring and scoring metrics, the subsets of those and the why and how these are used. An important knowledge to be had if you are responsible of security pertaining to a SOC/RISK or Security teams.<br/>In addition, we will recap other top trending security news including:<br/>-ESET antivirus bug leads to system privilege gain.<br/>-O365 and Azure AD were target of billions of brute-force attacks<br/><br/>Here are useful resources related to this episode:<br/>-<a href='https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows'>https://support.eset.com</a>: Local privilege escalation vulnerability fixed in ESET products for windows<br/>-<a href='https://www.bleepingcomputer.com/news/microsoft/eset-antivirus-bug-let-attackers-gain-windows-system-privileges/'>https://www.bleepingcomputer.com</a>: ESET antivirus bug let attackers gain windows system privileges<br/>- <a href='https://news.microsoft.com/wp-content/uploads/prod/sites/626/2022/02/Cyber-Signals-E-1.pdf'>https://news.microsoft.com</a>: Cyber Signal<br/>- <a href='https://www.zdnet.com/article/strong-authentication-protects-against-phishing-so-why-arent-more-people-using-it/'>https://www.zdnet.com</a>: Strong authentication protects against phishing so why aren&apos;t more people using it <br/>-<a href='https://www.kennasecurity.com/blog/what-is-the-difference-between-cve-and-cvss/'> https://www.kennasecurity.com/blog:</a> Vulnerability scores and risk scores<br/>- <a href='https://www.first.org/cvss/'>https://www.first.org: </a>CVSS<br/>- <a href='https://www.recordedfuture.com/cvss-scores-guide/'>https://www.recordedfuture.com</a>: CVSS scoresguide<br/><br/></p><p>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode I will delve into the vulnerability measuring and scoring metrics, the subsets of those and the why and how these are used. An important knowledge to be had if you are responsible of security pertaining to a SOC/RISK or Security teams.<br/>In addition, we will recap other top trending security news including:<br/>-ESET antivirus bug leads to system privilege gain.<br/>-O365 and Azure AD were target of billions of brute-force attacks<br/><br/>Here are useful resources related to this episode:<br/>-<a href='https://support.eset.com/en/ca8223-local-privilege-escalation-vulnerability-fixed-in-eset-products-for-windows'>https://support.eset.com</a>: Local privilege escalation vulnerability fixed in ESET products for windows<br/>-<a href='https://www.bleepingcomputer.com/news/microsoft/eset-antivirus-bug-let-attackers-gain-windows-system-privileges/'>https://www.bleepingcomputer.com</a>: ESET antivirus bug let attackers gain windows system privileges<br/>- <a href='https://news.microsoft.com/wp-content/uploads/prod/sites/626/2022/02/Cyber-Signals-E-1.pdf'>https://news.microsoft.com</a>: Cyber Signal<br/>- <a href='https://www.zdnet.com/article/strong-authentication-protects-against-phishing-so-why-arent-more-people-using-it/'>https://www.zdnet.com</a>: Strong authentication protects against phishing so why aren&apos;t more people using it <br/>-<a href='https://www.kennasecurity.com/blog/what-is-the-difference-between-cve-and-cvss/'> https://www.kennasecurity.com/blog:</a> Vulnerability scores and risk scores<br/>- <a href='https://www.first.org/cvss/'>https://www.first.org: </a>CVSS<br/>- <a href='https://www.recordedfuture.com/cvss-scores-guide/'>https://www.recordedfuture.com</a>: CVSS scoresguide<br/><br/></p><p>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/10017239-53-common-vulnerability-scoring-system-cvss.mp3" length="23546963" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10017239</guid>
    <pubDate>Sat, 05 Feb 2022 22:00:00 +0400</pubDate>
    <itunes:duration>1958</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>52 - Linux Malware Increased in 2021</itunes:title>
    <title>52 - Linux Malware Increased in 2021</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! The episode before last, we've looked at the Malware targetting the Mac world, this time we will look at the other side of the fense, the Linux echo systems.  The linux platform is the one operating system business rely on for their  mission critical applications regardless whether they are on-premise, cloud native or somewhere in between i.e. hybrid.  Yusuf on Security is 1 year old! Time flies when you are talking security every week for...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The episode before last, we&apos;ve looked at the Malware targetting the Mac world, this time we will look at the other side of the fense, the Linux echo systems. <br/>The linux platform is the one operating system business rely on for their  mission critical applications regardless whether they are on-premise, cloud native or somewhere in between i.e. hybrid.<br/><br/>Yusuf on Security is 1 year old! Time flies when you are talking security every week for 52 weeks consecutively. And in doing you are informing the people.<br/><br/><a href='https://www.centos.org/centos-linux-eol/'>https://www.centos.org</a>: CentOS end of life<br/><a href='https://thehackernews.com/2022/01/patching-centos-8-encryption-bug-is.html'>https://thehackernews.com:</a> Patching the CentOS Encryption is urgent... <br/><b>- </b><a href='https://arstechnica.com/gadgets/2022/01/google-drops-floc-after-widespread-opposition-pivots-to-topics-api-plan/'>arstechnica.com</a>: Google drops FLoC after widespread opposition, pivots to “Topics API” plan<br/><b>- </b><a href='https://blog.google/products/chrome/get-know-new-topics-api-privacy-sandbox/'>blog.google</a>: Get to know the new Topics API for Privacy Sandbox<br/><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>The episode before last, we&apos;ve looked at the Malware targetting the Mac world, this time we will look at the other side of the fense, the Linux echo systems. <br/>The linux platform is the one operating system business rely on for their  mission critical applications regardless whether they are on-premise, cloud native or somewhere in between i.e. hybrid.<br/><br/>Yusuf on Security is 1 year old! Time flies when you are talking security every week for 52 weeks consecutively. And in doing you are informing the people.<br/><br/><a href='https://www.centos.org/centos-linux-eol/'>https://www.centos.org</a>: CentOS end of life<br/><a href='https://thehackernews.com/2022/01/patching-centos-8-encryption-bug-is.html'>https://thehackernews.com:</a> Patching the CentOS Encryption is urgent... <br/><b>- </b><a href='https://arstechnica.com/gadgets/2022/01/google-drops-floc-after-widespread-opposition-pivots-to-topics-api-plan/'>arstechnica.com</a>: Google drops FLoC after widespread opposition, pivots to “Topics API” plan<br/><b>- </b><a href='https://blog.google/products/chrome/get-know-new-topics-api-privacy-sandbox/'>blog.google</a>: Get to know the new Topics API for Privacy Sandbox<br/><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9974579-52-linux-malware-increased-in-2021.mp3" length="26032126" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9974579</guid>
    <pubDate>Sat, 29 Jan 2022 22:00:00 +0400</pubDate>
    <itunes:duration>2165</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>51 - A new RAT campaign</itunes:title>
    <title>51 - A new RAT campaign</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Attackers are  resorting to way to cut corners. In doing so they cleverly are increasing their ROI while at the same time keeping pace with  technology advancement  With a new finding by Cisco Talos, we will look into a new campaign employing remote access trojans (RAT), not one or two but three variants of RAT!  -https://www.cisa.gov: Implement Cybersecurity Measures Now to Protect Against Potential Critical Threats  -https://thehack...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Attackers are  resorting to way to cut corners. In doing so they cleverly are increasing their ROI while at the same time keeping pace with  technology advancement <br/>With a new finding by Cisco Talos, we will look into a new campaign employing remote access trojans (RAT), not one or two but three variants of RAT!<br/><br/>-<a href='https://www.cisa.gov/sites/default/files/publications/CISA_Insights-Implement_Cybersecurity_Measures_Now_to_Protect_Against_Critical_Threats_508C.pdf'>https://www.cisa.gov</a>: Implement Cybersecurity Measures Now to<br/>Protect Against Potential Critical Threats <br/>-<a href='https://thehackernews.com/2022/01/experts-find-strategic-similarities-bw.html'>https://thehackernews.com</a>: Experts Find Strategic Similarities b/w NotPetya and WhisperGate Attacks on Ukraine<br/>- <a href='https://blog.talosintelligence.com/2022/01/nanocore-netwire-and-asyncrat-spreading.html'>https://blog.talosintelligence.com</a>: Nanocore, Netwire and AsyncRAT spreading campaign uses public cloud infrastructure<br/>-<a href='https://blog.talosintelligence.com/2022/01/ukraine-campaign-delivers-defacement.html'> https://blog.talosintelligence.com: </a>WhisperGate<a href='https://blog.talosintelligence.com/2022/01/ukraine-campaign-delivers-defacement.html'> </a><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Attackers are  resorting to way to cut corners. In doing so they cleverly are increasing their ROI while at the same time keeping pace with  technology advancement <br/>With a new finding by Cisco Talos, we will look into a new campaign employing remote access trojans (RAT), not one or two but three variants of RAT!<br/><br/>-<a href='https://www.cisa.gov/sites/default/files/publications/CISA_Insights-Implement_Cybersecurity_Measures_Now_to_Protect_Against_Critical_Threats_508C.pdf'>https://www.cisa.gov</a>: Implement Cybersecurity Measures Now to<br/>Protect Against Potential Critical Threats <br/>-<a href='https://thehackernews.com/2022/01/experts-find-strategic-similarities-bw.html'>https://thehackernews.com</a>: Experts Find Strategic Similarities b/w NotPetya and WhisperGate Attacks on Ukraine<br/>- <a href='https://blog.talosintelligence.com/2022/01/nanocore-netwire-and-asyncrat-spreading.html'>https://blog.talosintelligence.com</a>: Nanocore, Netwire and AsyncRAT spreading campaign uses public cloud infrastructure<br/>-<a href='https://blog.talosintelligence.com/2022/01/ukraine-campaign-delivers-defacement.html'> https://blog.talosintelligence.com: </a>WhisperGate<a href='https://blog.talosintelligence.com/2022/01/ukraine-campaign-delivers-defacement.html'> </a><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9935506-51-a-new-rat-campaign.mp3" length="23144420" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9935506</guid>
    <pubDate>Sun, 23 Jan 2022 20:00:00 +0400</pubDate>
    <itunes:duration>1925</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>50 - Apple Private Relay</itunes:title>
    <title>50 - Apple Private Relay</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this show I will have a look at the recent feature to Apple's ecosystem and in particular the Private Relay. In addition, we will recap other top trending security news which includes poisoned USB drives are sent to businesses and REvil ransomware gangs  allegedly arrested by Russian agents.  -https://therecord.media: FBI - FIN7 Hackers target US companies with BadUS- devices to install ransomware -https://en.wikipedia.org: REvil -https...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this show I will have a look at the recent feature to Apple&apos;s ecosystem and in particular the Private Relay.<br/>In addition, we will recap other top trending security news which includes poisoned USB drives are sent to businesses and REvil ransomware gangs  allegedly arrested by Russian agents.<br/><br/>-<a href='https://therecord.media/fbi-fin7-hackers-target-us-companies-with-badusb-devices-to-install-ransomware/'>https://therecord.media</a>: FBI - FIN7 Hackers target US companies with BadUS- devices to install ransomware<br/>-<a href=' https://en.wikipedia.org/wiki/REvil'>https://en.wikipedia.org</a>: REvil<br/>-<a href='https://thehackernews.com/2022/01/russia-arrests-revil-ransomware-gang.html'>https://thehackernews.com</a>: Russia arrests REvil ransomware gang<br/>-<a href='https://www.macworld.com/article/348965/icloud-plus-private-relay-safari-vpn-encryption-privacy.html'>https://www.macworld.com</a>: icloud plus private relay Safari vpn encryption privacy<br/>-<a href='https://support.apple.com/en-gb/HT212614'>https://support.apple.com:</a> About iCloud Private Relay<br/><br/></p><p>-<a href='https://developer.apple.com/videos/play/wwdc2021/10096/'>https://developer.apple.com</a>: Technical presentation video on Private Relay<br/><br/>sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this show I will have a look at the recent feature to Apple&apos;s ecosystem and in particular the Private Relay.<br/>In addition, we will recap other top trending security news which includes poisoned USB drives are sent to businesses and REvil ransomware gangs  allegedly arrested by Russian agents.<br/><br/>-<a href='https://therecord.media/fbi-fin7-hackers-target-us-companies-with-badusb-devices-to-install-ransomware/'>https://therecord.media</a>: FBI - FIN7 Hackers target US companies with BadUS- devices to install ransomware<br/>-<a href=' https://en.wikipedia.org/wiki/REvil'>https://en.wikipedia.org</a>: REvil<br/>-<a href='https://thehackernews.com/2022/01/russia-arrests-revil-ransomware-gang.html'>https://thehackernews.com</a>: Russia arrests REvil ransomware gang<br/>-<a href='https://www.macworld.com/article/348965/icloud-plus-private-relay-safari-vpn-encryption-privacy.html'>https://www.macworld.com</a>: icloud plus private relay Safari vpn encryption privacy<br/>-<a href='https://support.apple.com/en-gb/HT212614'>https://support.apple.com:</a> About iCloud Private Relay<br/><br/></p><p>-<a href='https://developer.apple.com/videos/play/wwdc2021/10096/'>https://developer.apple.com</a>: Technical presentation video on Private Relay<br/><br/>sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9891074-50-apple-private-relay.mp3" length="19202642" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9891074</guid>
    <pubDate>Sat, 15 Jan 2022 21:00:00 +0400</pubDate>
    <itunes:duration>1596</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>49 - Mac Malware</itunes:title>
    <title>49 - Mac Malware</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will look at a growing threat  facing the Mac world.  While not attacked as much as Windows platform, the signs are showing Mac is indeed not unvulnerable  Before we get into the main topic, lets have a look at a couple of trending security news. This will we briefly talk about Norton 360 which brings you a crypto-mining feature and an important bug patched by VMWare.  -https://krebsonsecurity.com: Norton 360 now co...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will look at a growing threat  facing the Mac world.  While not attacked as much as Windows platform, the signs are showing Mac is indeed not unvulnerable<br/><br/>Before we get into the main topic, lets have a look at a couple of trending security news. This will we briefly talk about Norton 360 which brings you a crypto-mining feature and an important bug patched by VMWare.<br/><br/>-<a href='https://krebsonsecurity.com/2022/01/norton-360-now-comes-with-a-cryptominer/'><b>https://krebsonsecurity.com:</b></a> Norton 360 now comes with a cryptominer<br/><b>- </b><a href='https://threatpost.com/unpatched-vmware-bug-hypervisor-takeover/177428/'><b>threatpost.com</b></a>: Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover<br/><b>- </b><a href='https://www.vmware.com/security/advisories/VMSA-2022-0001.html'><b>www.vmware.com</b></a>: VMware Workstation, Fusion and ESXi updates address a heap-overflow vulnerability (CVE-2021-22045)<br/>-<a href='https://vuldb.com/?id.189688'><b>https://vuldb.com</b></a>: Vulnerability database <br/>-<a href='https://objective-see.com/blog/blog_0x6B.html?mc_cid=b290d3ad64&amp;mc_eid=ffc6f25574'><b>http://objective-see.com</b></a>: The Mac Malware of 2021<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will look at a growing threat  facing the Mac world.  While not attacked as much as Windows platform, the signs are showing Mac is indeed not unvulnerable<br/><br/>Before we get into the main topic, lets have a look at a couple of trending security news. This will we briefly talk about Norton 360 which brings you a crypto-mining feature and an important bug patched by VMWare.<br/><br/>-<a href='https://krebsonsecurity.com/2022/01/norton-360-now-comes-with-a-cryptominer/'><b>https://krebsonsecurity.com:</b></a> Norton 360 now comes with a cryptominer<br/><b>- </b><a href='https://threatpost.com/unpatched-vmware-bug-hypervisor-takeover/177428/'><b>threatpost.com</b></a>: Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover<br/><b>- </b><a href='https://www.vmware.com/security/advisories/VMSA-2022-0001.html'><b>www.vmware.com</b></a>: VMware Workstation, Fusion and ESXi updates address a heap-overflow vulnerability (CVE-2021-22045)<br/>-<a href='https://vuldb.com/?id.189688'><b>https://vuldb.com</b></a>: Vulnerability database <br/>-<a href='https://objective-see.com/blog/blog_0x6B.html?mc_cid=b290d3ad64&amp;mc_eid=ffc6f25574'><b>http://objective-see.com</b></a>: The Mac Malware of 2021<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9854791-49-mac-malware.mp3" length="20368732" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9854791</guid>
    <pubDate>Sun, 09 Jan 2022 22:00:00 +0400</pubDate>
    <itunes:duration>1694</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>48 - CIS Controls</itunes:title>
    <title>48 - CIS Controls</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! There is no better way to start the year than stepping back and having a good look at where you are in your security journey. To that end, a good baseline is not a bad idea. In this episode we will dive into the The Center for Internet Security (CIS) Critical controls. These are great ways to steps through your existing (or lack of) controls.  - www.bleepingcomputer.com: QNAP NAS devices hit in surge of ech0raix ransomware attacks -https://www....]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>There is no better way to start the year than stepping back and having a good look at where you are in your security journey. To that end, a good baseline is not a bad idea. In this episode we will dive into the The Center for Internet Security (CIS) Critical controls. These are great ways to steps through your existing (or lack of) controls.<br/><br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/qnap-nas-devices-hit-in-surge-of-ech0raix-ransomware-attacks/'><b>www.bleepingcomputer.com</b></a>: QNAP NAS devices hit in surge of ech0raix ransomware attacks<br/>-<a href='https://www.qnap.com/en/how-to/faq/article/what-is-the-best-practice-for-enhancing-nas-security'>https://www.qnap.com</a>: QNAP Recommendations<br/>https://www.sans.org/blog/cis-controls-v8/<br/>- My look at the road ahead - 2022 landscape. <br/><b>-</b><a href='https://www.sans.org/blog/cis-controls-v8/'><b>https://www.sans.org</b></a><b>: </b> CIS Controls v8<br/><br/>Be sure to subscribe!<br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>There is no better way to start the year than stepping back and having a good look at where you are in your security journey. To that end, a good baseline is not a bad idea. In this episode we will dive into the The Center for Internet Security (CIS) Critical controls. These are great ways to steps through your existing (or lack of) controls.<br/><br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/qnap-nas-devices-hit-in-surge-of-ech0raix-ransomware-attacks/'><b>www.bleepingcomputer.com</b></a>: QNAP NAS devices hit in surge of ech0raix ransomware attacks<br/>-<a href='https://www.qnap.com/en/how-to/faq/article/what-is-the-best-practice-for-enhancing-nas-security'>https://www.qnap.com</a>: QNAP Recommendations<br/>https://www.sans.org/blog/cis-controls-v8/<br/>- My look at the road ahead - 2022 landscape. <br/><b>-</b><a href='https://www.sans.org/blog/cis-controls-v8/'><b>https://www.sans.org</b></a><b>: </b> CIS Controls v8<br/><br/>Be sure to subscribe!<br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9815284-48-cis-controls.mp3" length="33358906" type="audio/mpeg" />
    <itunes:author>YusufOnSecurity.Com</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9815284</guid>
    <pubDate>Sat, 01 Jan 2022 21:00:00 +0400</pubDate>
    <itunes:duration>2776</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>47 - The best of 2021!</itunes:title>
    <title>47 - The best of 2021!</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  It is time for YusufOnSecurity, welcome back once again!  In this episode we will go back to the best of 2021 episodes. There are quite a few popular ones. But first, lets recap the top trending security news. - techcommunity.microsoft.com: SAM Name impersonation - www.bleepingcomputer.com: Microsoft warns of easy Windows domain takeover via Active Directory bugs -https://www.cisa.gov:  CISA, FBI, NSA and international partners issue advi...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><br/>It is time for YusufOnSecurity, welcome back once again!<br/><br/>In this episode we will go back to the best of 2021 episodes. There are quite a few popular ones.<br/>But first, lets recap the top trending security news.<br/><b>- </b><a href='https://techcommunity.microsoft.com/t5/security-compliance-and-identity/sam-name-impersonation/ba-p/3042699'><b>techcommunity.microsoft.com</b></a>: SAM Name impersonation<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-easy-windows-domain-takeover-via-active-directory-bugs/'><b>www.bleepingcomputer.com</b></a>: Microsoft warns of easy Windows domain takeover via Active Directory bugs<br/>-<a href='https://www.cisa.gov/news/2021/12/22/cisa-fbi-nsa-and-international-partners-issue-advisory-mitigate-apache-log4j'>https://www.cisa.gov</a>:  CISA, FBI, NSA and international partners issue advisory to mitigate Apache Log4j vulnerabilities</p><p>- <a href='https://github.com/CERTCC/CVE-2021-44228_scanner'>https://github.com</a>: CISA Scanner<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><br/>It is time for YusufOnSecurity, welcome back once again!<br/><br/>In this episode we will go back to the best of 2021 episodes. There are quite a few popular ones.<br/>But first, lets recap the top trending security news.<br/><b>- </b><a href='https://techcommunity.microsoft.com/t5/security-compliance-and-identity/sam-name-impersonation/ba-p/3042699'><b>techcommunity.microsoft.com</b></a>: SAM Name impersonation<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-easy-windows-domain-takeover-via-active-directory-bugs/'><b>www.bleepingcomputer.com</b></a>: Microsoft warns of easy Windows domain takeover via Active Directory bugs<br/>-<a href='https://www.cisa.gov/news/2021/12/22/cisa-fbi-nsa-and-international-partners-issue-advisory-mitigate-apache-log4j'>https://www.cisa.gov</a>:  CISA, FBI, NSA and international partners issue advisory to mitigate Apache Log4j vulnerabilities</p><p>- <a href='https://github.com/CERTCC/CVE-2021-44228_scanner'>https://github.com</a>: CISA Scanner<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at [https://yusufonsecurity.com](https://yusufonsecurity.com/)<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9786844-47-the-best-of-2021.mp3" length="64911652" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9786844</guid>
    <pubDate>Sat, 25 Dec 2021 16:00:00 +0400</pubDate>
    <itunes:duration>5405</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>46 - Apache Log4j Continues</itunes:title>
    <title>46 - Apache Log4j Continues</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for YusufOnSecurity, welcome back once again!  In this episode we will stay on the topic of Log4j still developing vulnerability.  -https://threatpost.com : Malicious Joker App Scores Half-Million Downloads on Google Play -https://www.bleepingcomputer.com:  Karakurt: A New Emerging Data Theft and Cyber Extortion Hacking Group -https://yusufonsecurity.com: Log4j vulnerabilities   Be sure to subscribe! If you like the content. Fol...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/><br/>In this episode we will stay on the topic of Log4j still developing vulnerability.<br/><br/>-<a href='https://threatpost.com/malicious-joker-app-downloads-google-play/177139/'>https://threatpost.com </a>: Malicious Joker App Scores Half-Million Downloads on Google Play</p><p>-<a href='https://www.bleepingcomputer.com/news/security/new-karakurt-hacking-group-focuses-on-data-theft-and-extortion/'>https://www.bleepingcomputer.com</a>:  Karakurt: A New Emerging Data Theft and Cyber Extortion Hacking Group</p><p>-<a href='https://yusufonsecurity.com/2021/12/16/log4j-vulnerability/'>https://yusufonsecurity.com</a>: Log4j vulnerabilities<br/><br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com/'>https://yusufonsecurity.com</a></p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for YusufOnSecurity, welcome back once again!<br/><br/>In this episode we will stay on the topic of Log4j still developing vulnerability.<br/><br/>-<a href='https://threatpost.com/malicious-joker-app-downloads-google-play/177139/'>https://threatpost.com </a>: Malicious Joker App Scores Half-Million Downloads on Google Play</p><p>-<a href='https://www.bleepingcomputer.com/news/security/new-karakurt-hacking-group-focuses-on-data-theft-and-extortion/'>https://www.bleepingcomputer.com</a>:  Karakurt: A New Emerging Data Theft and Cyber Extortion Hacking Group</p><p>-<a href='https://yusufonsecurity.com/2021/12/16/log4j-vulnerability/'>https://yusufonsecurity.com</a>: Log4j vulnerabilities<br/><br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com/'>https://yusufonsecurity.com</a></p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9745423-46-apache-log4j-continues.mp3" length="15330836" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9745423</guid>
    <pubDate>Sat, 18 Dec 2021 23:00:00 +0400</pubDate>
    <itunes:duration>1273</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>45 - Critical Vulnerability in Apache Log4j</itunes:title>
    <title>45 - Critical Vulnerability in Apache Log4j</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover an actively exploited vulnerability whose importance can not overstated. Well the Internet is on fire, as someone put it.  In addition, we will recap other top trending security news which includes: -https://blog.mozilla.org: Site Isolation in Firefox  -https://en.wikipedia.org: Same Origin Policy -eclypsium.com: When honey bees become murder hornets - logging.apche.org: Apache log4j vulnerability -https://www...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover an actively exploited vulnerability whose importance can not overstated. Well the Internet is on fire, as someone put it. </p><p>In addition, we will recap other top trending security news which includes:</p><p>-<a href='https://blog.mozilla.org/security/2021/05/18/introducing-site-isolation-in-firefox/'>https://blog.mozilla.org</a>: Site Isolation in Firefox <br/>-<a href='https://en.wikipedia.org/wiki/Same-origin_policy'>https://en.wikipedia.org</a>: Same Origin Policy<br/>-<a href='https://eclypsium.com/2021/12/09/when-honey-bees-become-murder-hornets/'>eclypsium.com</a>: When honey bees become murder hornets<br/>- <a href='https://logging.apache.org/log4j/2.x/security.html'>logging.apche.org</a>: Apache log4j vulnerability<br/>-<a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog'>https://www.cisa.gov</a> Most commonly exploited vulnerabilities<b><br/><br/></b>Be sure to subscribe!</p><p> If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com/'>https://yusufonsecurity.com</a></p><p> You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover an actively exploited vulnerability whose importance can not overstated. Well the Internet is on fire, as someone put it. </p><p>In addition, we will recap other top trending security news which includes:</p><p>-<a href='https://blog.mozilla.org/security/2021/05/18/introducing-site-isolation-in-firefox/'>https://blog.mozilla.org</a>: Site Isolation in Firefox <br/>-<a href='https://en.wikipedia.org/wiki/Same-origin_policy'>https://en.wikipedia.org</a>: Same Origin Policy<br/>-<a href='https://eclypsium.com/2021/12/09/when-honey-bees-become-murder-hornets/'>eclypsium.com</a>: When honey bees become murder hornets<br/>- <a href='https://logging.apache.org/log4j/2.x/security.html'>logging.apche.org</a>: Apache log4j vulnerability<br/>-<a href='https://www.cisa.gov/known-exploited-vulnerabilities-catalog'>https://www.cisa.gov</a> Most commonly exploited vulnerabilities<b><br/><br/></b>Be sure to subscribe!</p><p> If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com/'>https://yusufonsecurity.com</a></p><p> You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9702569-45-critical-vulnerability-in-apache-log4j.mp3" length="19704079" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9702569</guid>
    <pubDate>Sat, 11 Dec 2021 20:00:00 +0400</pubDate>
    <itunes:duration>1638</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>44 - Holiday best practice</itunes:title>
    <title>44 - Holiday best practice</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, we will cover the best practice that we mostly forget this time of the year. I am sure a lot of you become the Help Desk for the entire family for anything to do with IT or technology. We will recap the top trending security news which includes: -https://blog.talosintelligence.com: Attackers exploiting zero-day vulnerability in Windows Installer  - thehackernews.com: Researches Detail 17 Malicious Frameworks Used to Att...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we will cover the best practice that we mostly forget this time of the year.</p><p>I am sure a lot of you become the Help Desk for the entire family for anything to do with IT or technology.</p><p>We will recap the top trending security news which includes:</p><p>-<a href='https://blog.talosintelligence.com/2021/11/attackers-exploiting-zero-day.html#more'>https://blog.talosintelligence.com:</a> Attackers exploiting zero-day vulnerability in Windows Installer </p><p><b>- </b><a href='https://thehackernews.com/2021/12/researches-detail-17-malicious.html'><b>thehackernews.com</b></a>: Researches Detail 17 Malicious Frameworks Used to Attack Air-Gapped Networks</p><p>- <a href='https://blog.talosintelligence.com/2021/11/talos-tips-for-staying-safe-while.html'>blog.talosintelligence.com</a>: Tips for holiday season from Talos Intelligence<br/>-<a href='https://www.first.org/cvss/v2/faq#What-are-the-details-of-the-Temporal-Metrics'>www.first.org</a>: CVSS FAQ<br/>-<a href='https://www.adobe.com/marketing/pdf-page.html?pdfTarget=aHR0cHM6Ly9idXNpbmVzcy5hZG9iZS5jb20vY29udGVudC9kYW0vZHgvdXMvZW4vcmVzb3VyY2VzL2RpZ2l0YWwtaW5zaWdodHMvcGRmL2Fkb2JlLWhvbGlkYXktc2hvcHBpbmctcmVwb3J0LTIwMjEucGRm'>www.adobe.com:</a> Adobe Insight’s recent &quot;Holiday Shopping Forecast&quot;<br/><br/></p><p>It is all coming up next on YusufOnsecurity!</p><p>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com/'>https://yusufonsecurity.com</a></p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today&apos;s episode, we will cover the best practice that we mostly forget this time of the year.</p><p>I am sure a lot of you become the Help Desk for the entire family for anything to do with IT or technology.</p><p>We will recap the top trending security news which includes:</p><p>-<a href='https://blog.talosintelligence.com/2021/11/attackers-exploiting-zero-day.html#more'>https://blog.talosintelligence.com:</a> Attackers exploiting zero-day vulnerability in Windows Installer </p><p><b>- </b><a href='https://thehackernews.com/2021/12/researches-detail-17-malicious.html'><b>thehackernews.com</b></a>: Researches Detail 17 Malicious Frameworks Used to Attack Air-Gapped Networks</p><p>- <a href='https://blog.talosintelligence.com/2021/11/talos-tips-for-staying-safe-while.html'>blog.talosintelligence.com</a>: Tips for holiday season from Talos Intelligence<br/>-<a href='https://www.first.org/cvss/v2/faq#What-are-the-details-of-the-Temporal-Metrics'>www.first.org</a>: CVSS FAQ<br/>-<a href='https://www.adobe.com/marketing/pdf-page.html?pdfTarget=aHR0cHM6Ly9idXNpbmVzcy5hZG9iZS5jb20vY29udGVudC9kYW0vZHgvdXMvZW4vcmVzb3VyY2VzL2RpZ2l0YWwtaW5zaWdodHMvcGRmL2Fkb2JlLWhvbGlkYXktc2hvcHBpbmctcmVwb3J0LTIwMjEucGRm'>www.adobe.com:</a> Adobe Insight’s recent &quot;Holiday Shopping Forecast&quot;<br/><br/></p><p>It is all coming up next on YusufOnsecurity!</p><p>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at <a href='https://yusufonsecurity.com/'>https://yusufonsecurity.com</a></p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9661464-44-holiday-best-practice.mp3" length="20177070" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9661464</guid>
    <pubDate>Sat, 04 Dec 2021 19:00:00 +0400</pubDate>
    <itunes:duration>1677</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>43 - Passwordless future</itunes:title>
    <title>43 - Passwordless future</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, lets talk about password and the future of password for that matter.   We will recap the top trending security news which includes:  -www.bbc.co.uk: UK proposed to ban default passwords -www.apple.com: Apple sues the NSO Group - www.nytimes.com: The secret life of passwords -https://fidoalliance.org: What is FIDO? -https://www.cisco.com: Kiss Passwords G00dby3: Cisco Secure Unveils Passwordless Future with Stronger Security ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today&apos;s episode, lets talk about password and the future of password for that matter. </b><br/><br/>We will recap the top trending security news which includes:<br/><br/>-<a href='https://www.bbc.com/news/technology-59400762'>www.bbc.co.uk</a>: UK proposed to ban default passwords<br/>-<a href='https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/'>www.apple.com</a>: Apple sues the NSO Group<br/>- <a href='https://www.nytimes.com/2014/11/19/magazine/the-secret-life-of-passwords.html'>www.nytimes.com</a>: The secret life of passwords<br/>-<a href='https://fidoalliance.org/what-is-fido/'>https://fidoalliance.org:</a> What is FIDO?<br/>-<a href='https://newsroom.cisco.com/press-release-content?articleId=2150390'>https://www.cisco.com</a>: Kiss Passwords G00dby3: Cisco Secure Unveils Passwordless Future with Stronger Security for All</p><p><br/>Be sure to subscribe!<br/><br/>If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today&apos;s episode, lets talk about password and the future of password for that matter. </b><br/><br/>We will recap the top trending security news which includes:<br/><br/>-<a href='https://www.bbc.com/news/technology-59400762'>www.bbc.co.uk</a>: UK proposed to ban default passwords<br/>-<a href='https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/'>www.apple.com</a>: Apple sues the NSO Group<br/>- <a href='https://www.nytimes.com/2014/11/19/magazine/the-secret-life-of-passwords.html'>www.nytimes.com</a>: The secret life of passwords<br/>-<a href='https://fidoalliance.org/what-is-fido/'>https://fidoalliance.org:</a> What is FIDO?<br/>-<a href='https://newsroom.cisco.com/press-release-content?articleId=2150390'>https://www.cisco.com</a>: Kiss Passwords G00dby3: Cisco Secure Unveils Passwordless Future with Stronger Security for All</p><p><br/>Be sure to subscribe!<br/><br/>If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9619505-43-passwordless-future.mp3" length="20168289" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9619505</guid>
    <pubDate>Sat, 27 Nov 2021 09:00:00 +0400</pubDate>
    <itunes:duration>1677</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>42 - OWASP Top 10</itunes:title>
    <title>42 - OWASP Top 10</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, I am discussing OWASP Top 10. We will introduce what this is for those not in the know and then go indepth on how this helps the industry and how it changed in its last evolution.  - https://finance.yahoo.com: Malware just got even more stealthier - www.gov.uk: National Security and Investment Act 2021: Statement for the purposes of section -  https://owasp.org: OWASP T0p 10    Be sure to subscribe!  If you like th...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today&apos;s episode, I am discussing OWASP Top 10. We will introduce what this is for those not in the know and then go indepth on how this helps the industry and how it changed in its last evolution.<br/><br/>- </b><a href='https://finance.yahoo.com/news/research-fileless-malware-attacks-surge-040100107.html?_guc_consent_skip=1637407077'><b>https://finance.yahoo.com</b></a><b>: </b>Malware just got even more stealthier</p><p><b>- </b><a href='https://www.gov.uk/government/publications/national-security-and-investment-statement-about-exercise-of-the-call-in-power/national-security-and-investment-act-2021-statement-for-the-purposes-of-section-3'><b>www.gov.uk</b></a>: National Security and Investment Act 2021: Statement for the purposes of section</p><p>-  <a href='https://owasp.org/www-project-top-ten/'>https://owasp.org</a>: OWASP T0p 10 <br/><br/><br/>Be sure to subscribe!<br/><br/>If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today&apos;s episode, I am discussing OWASP Top 10. We will introduce what this is for those not in the know and then go indepth on how this helps the industry and how it changed in its last evolution.<br/><br/>- </b><a href='https://finance.yahoo.com/news/research-fileless-malware-attacks-surge-040100107.html?_guc_consent_skip=1637407077'><b>https://finance.yahoo.com</b></a><b>: </b>Malware just got even more stealthier</p><p><b>- </b><a href='https://www.gov.uk/government/publications/national-security-and-investment-statement-about-exercise-of-the-call-in-power/national-security-and-investment-act-2021-statement-for-the-purposes-of-section-3'><b>www.gov.uk</b></a>: National Security and Investment Act 2021: Statement for the purposes of section</p><p>-  <a href='https://owasp.org/www-project-top-ten/'>https://owasp.org</a>: OWASP T0p 10 <br/><br/><br/>Be sure to subscribe!<br/><br/>If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9581903-42-owasp-top-10.mp3" length="21186424" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9581903</guid>
    <pubDate>Sat, 20 Nov 2021 14:00:00 +0400</pubDate>
    <itunes:duration>1761</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>41 -  Endpoint security and the shift to remote work </itunes:title>
    <title>41 -  Endpoint security and the shift to remote work </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today's episode, I am discussing endpoint security with Information Security Media Group better known as ISMG. In particular we will delve into  How the shift to remote work changed security imperatives when it comes to endpoint;The evolving role of endpoint security;Best practices your organization can implement now to maximize visibility and simplicity.- blog.google: Analyzing a watering hole campaign using macOS exploits - support.ap...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today&apos;s episode, I am discussing endpoint security with Information Security Media Group better known as ISMG. In particular we will delve into </b></p><ul><li>How the shift to remote work changed security imperatives when it comes to endpoint;</li><li>The evolving role of endpoint security;</li><li>Best practices your organization can implement now to maximize visibility and simplicity.</li></ul><p><b>- </b><a href='https://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/'><b>blog.google</b></a>: Analyzing a watering hole campaign using macOS exploits</p><p><b>- </b><a href='https://support.apple.com/en-us/HT212825'><b>support.apple.com</b></a>: About the security content of Security Update 2021-006 Catalina<br/>- <a href='https://threatpost.com/routers-iot-open-source-malware/176270/'>threatpost.com</a>: Millions of Routers, IoT Devices at Risk from BotenaGo Malware</p><p><br/>Be sure to subscribe!<br/><br/>If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today&apos;s episode, I am discussing endpoint security with Information Security Media Group better known as ISMG. In particular we will delve into </b></p><ul><li>How the shift to remote work changed security imperatives when it comes to endpoint;</li><li>The evolving role of endpoint security;</li><li>Best practices your organization can implement now to maximize visibility and simplicity.</li></ul><p><b>- </b><a href='https://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/'><b>blog.google</b></a>: Analyzing a watering hole campaign using macOS exploits</p><p><b>- </b><a href='https://support.apple.com/en-us/HT212825'><b>support.apple.com</b></a>: About the security content of Security Update 2021-006 Catalina<br/>- <a href='https://threatpost.com/routers-iot-open-source-malware/176270/'>threatpost.com</a>: Millions of Routers, IoT Devices at Risk from BotenaGo Malware</p><p><br/>Be sure to subscribe!<br/><br/>If you like the content, follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9540869-41-endpoint-security-and-the-shift-to-remote-work.mp3" length="33555371" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9540869</guid>
    <pubDate>Sat, 13 Nov 2021 09:00:00 +0400</pubDate>
    <itunes:duration>2792</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>40 - NIST Cybersecurity Framework</itunes:title>
    <title>40 - NIST Cybersecurity Framework</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome again! In today’s episode we will dive into the most widely adopted framework, The NIST Cybersecurity Framework.  -www.vice.com:The booming underground market for bots that steal 2FA codes - www.zdnet.com: Commerce Dept sanctions NSO Group, Positive Technologies and more for selling spyware and hacking tool -https://nvlpubs.nist.gov: NIST Cybersecurity Framework  Be su...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome again!</b></p><p><b>In today’s episode we will dive into the most widely adopted framework, The NIST Cybersecurity Framework. </b></p><p>-<a href='http://www.vice.com'>www.vice.com</a>:The booming underground market for bots that steal 2FA codes</p><p><b>- </b><a href='https://www.zdnet.com/article/commerce-dept-sanctions-nso-group-positive-technologies-and-more-for-selling-spyware-and-hacking-tools/'><b>www.zdnet.com</b></a>: Commerce Dept sanctions NSO Group, Positive Technologies and more for selling spyware and hacking tool</p><p>-<a href='https://nvlpubs.nist.gov:'>https://nvlpubs.nist.gov:</a> NIST Cybersecurity Framework<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome again!</b></p><p><b>In today’s episode we will dive into the most widely adopted framework, The NIST Cybersecurity Framework. </b></p><p>-<a href='http://www.vice.com'>www.vice.com</a>:The booming underground market for bots that steal 2FA codes</p><p><b>- </b><a href='https://www.zdnet.com/article/commerce-dept-sanctions-nso-group-positive-technologies-and-more-for-selling-spyware-and-hacking-tools/'><b>www.zdnet.com</b></a>: Commerce Dept sanctions NSO Group, Positive Technologies and more for selling spyware and hacking tool</p><p>-<a href='https://nvlpubs.nist.gov:'>https://nvlpubs.nist.gov:</a> NIST Cybersecurity Framework<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9502846-40-nist-cybersecurity-framework.mp3" length="19704372" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9502846</guid>
    <pubDate>Sat, 06 Nov 2021 21:00:00 +0400</pubDate>
    <itunes:duration>1638</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>39 - What 80M Ransomware Analysis Revealed</itunes:title>
    <title>39 - What 80M Ransomware Analysis Revealed</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard! In today’s episode lets look at an analysis carried out by google on 80M samples they’ve received through VirusTotal. - security.googleblog.com: Launching a collaborative minimum security baseline - helpx.adobe.com: Security Bulletins and Advisories  Be sure to subscribe! If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com You...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard!</b></p><p><b>In today’s episode lets look at an analysis carried out by google on 80M samples they’ve received through VirusTotal.</b></p><p><b>- </b><a href='https://security.googleblog.com/2021/10/launching-collaborative-minimum.html'><b>security.googleblog.com</b></a>: Launching a collaborative minimum security baseline<br/><b>- </b><a href='https://helpx.adobe.com/security/security-bulletin.html'><b>helpx.adobe.com</b></a>: Security Bulletins and Advisories<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard!</b></p><p><b>In today’s episode lets look at an analysis carried out by google on 80M samples they’ve received through VirusTotal.</b></p><p><b>- </b><a href='https://security.googleblog.com/2021/10/launching-collaborative-minimum.html'><b>security.googleblog.com</b></a>: Launching a collaborative minimum security baseline<br/><b>- </b><a href='https://helpx.adobe.com/security/security-bulletin.html'><b>helpx.adobe.com</b></a>: Security Bulletins and Advisories<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9464570-39-what-80m-ransomware-analysis-revealed.mp3" length="12611519" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9464570</guid>
    <pubDate>Sun, 31 Oct 2021 21:00:00 +0400</pubDate>
    <itunes:duration>1047</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>38 - Modern Vulnerability Management</itunes:title>
    <title>38 - Modern Vulnerability Management</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard!  We will look into the modern vulnerability Management today, episode,   But before that, lets recap top trending security news:  It is all coming up next on Yusuf on Security!   -https://blog.google.com: Google gives away 10K security keys to high risk users -https://www.schneier.com: Problem with multi-factor authentication   Be sure to subscribe!  If y...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div><strong>It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard!<br/></strong><br/></div><div><strong>We will look into the modern vulnerability Management today, episode, <br/></strong><br/></div><div>But before that, lets recap top trending security news:<br/><br/></div><div><strong>It is all coming up next on Yusuf on Security!<br/></strong><br/></div><div><br/>-<a href=' https://blog.google/technology/safety-security/delivering-10000-security-keys-high-risk-users/'>https://blog.google.com:</a> Google gives away 10K security keys to high risk users<br/>-<a href='https://www.schneier.com/blog/archives/2021/10/problems-with-multifactor-authentication.html'>https://www.schneier.com</a>: Problem with multi-factor authentication <br/><br/>Be sure to subscribe!<br/><br/></div><div>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/></div><div>You will find a list of all previous episodes in there too.<br/><br/></div><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><div><strong>It is time for Yusuf On Security, I am your host Ibrahim YUSUF. Welcome onboard!<br/></strong><br/></div><div><strong>We will look into the modern vulnerability Management today, episode, <br/></strong><br/></div><div>But before that, lets recap top trending security news:<br/><br/></div><div><strong>It is all coming up next on Yusuf on Security!<br/></strong><br/></div><div><br/>-<a href=' https://blog.google/technology/safety-security/delivering-10000-security-keys-high-risk-users/'>https://blog.google.com:</a> Google gives away 10K security keys to high risk users<br/>-<a href='https://www.schneier.com/blog/archives/2021/10/problems-with-multifactor-authentication.html'>https://www.schneier.com</a>: Problem with multi-factor authentication <br/><br/>Be sure to subscribe!<br/><br/></div><div>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/></div><div>You will find a list of all previous episodes in there too.<br/><br/></div><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9419685-38-modern-vulnerability-management.mp3" length="18933871" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9419685</guid>
    <pubDate>Sat, 23 Oct 2021 19:00:00 +0400</pubDate>
    <itunes:duration>1574</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>38</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>37 - What is FLOC?</itunes:title>
    <title>37 - What is FLOC?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim YUSUF. In this episode, we will cover a topic related to our previous episode. We will look at a new way of reconciling driving revenue through ads while ‘not tracking individuals’. - www.microsoft.com: Iran-linked DEV-0343 targeting defense, GIS, and maritime sectors - www.businesswire.com: MITRE Labs Launches Innovation Organizations for Critical Infrastructure, Clinical Health Data  Be...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim YUSUF.</b></p><p><b>In this episode, we will cover a topic related to our previous episode. We will look at a new way of reconciling driving revenue through ads while ‘not tracking individuals’.</b></p><p><b>- </b><a href='https://www.microsoft.com/security/blog/2021/10/11/iran-linked-dev-0343-targeting-defense-gis-and-maritime-sectors/'><b>www.microsoft.com</b></a>: Iran-linked DEV-0343 targeting defense, GIS, and maritime sectors</p><p><b>- </b><a href='https://www.businesswire.com/news/home/20211011005498/en/MITRE-Labs-Launches-Innovation-Organizations-for-Critical-Infrastructure-Clinical-Health-Data'><b>www.businesswire.com</b></a>: MITRE Labs Launches Innovation Organizations for Critical Infrastructure, Clinical Health Data<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim YUSUF.</b></p><p><b>In this episode, we will cover a topic related to our previous episode. We will look at a new way of reconciling driving revenue through ads while ‘not tracking individuals’.</b></p><p><b>- </b><a href='https://www.microsoft.com/security/blog/2021/10/11/iran-linked-dev-0343-targeting-defense-gis-and-maritime-sectors/'><b>www.microsoft.com</b></a>: Iran-linked DEV-0343 targeting defense, GIS, and maritime sectors</p><p><b>- </b><a href='https://www.businesswire.com/news/home/20211011005498/en/MITRE-Labs-Launches-Innovation-Organizations-for-Critical-Infrastructure-Clinical-Health-Data'><b>www.businesswire.com</b></a>: MITRE Labs Launches Innovation Organizations for Critical Infrastructure, Clinical Health Data<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9379371-37-what-is-floc.mp3" length="18347647" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9379371</guid>
    <pubDate>Sat, 16 Oct 2021 20:00:00 +0400</pubDate>
    <itunes:duration>1525</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>37</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>36 - Cookies</itunes:title>
    <title>36 - Cookies</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim  In this episode, we look take a taste of cookies but before we get into that there is only one story that dominated the scene last week, the Facebook fall. We will look into what went wrong and the underlying plumping that had a catastrophic cascading impacting on the company.  -www.krebsonsecurity.com - What happened to Facebook...? -www.wikipedia.com - Cookies Be sure to subscribe...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim </b></p><p>I<b>n this episode, we look take a taste of cookies but before we get into that there is only one story that dominated the scene last week, the Facebook fall. We will look into what went wrong and the underlying plumping that had a catastrophic cascading impacting on the company.<br/></b><br/>-<a href='https://krebsonsecurity.com/2021/10/what-happened-to-facebook-instagram-whatsapp/'>www.krebsonsecurity.com</a> - What happened to Facebook...?<br/>-<a href='https://en.wikipedia.org/wiki/HTTP_cookie'>www.wikipedia.com </a>- Cookies</p><p>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim </b></p><p>I<b>n this episode, we look take a taste of cookies but before we get into that there is only one story that dominated the scene last week, the Facebook fall. We will look into what went wrong and the underlying plumping that had a catastrophic cascading impacting on the company.<br/></b><br/>-<a href='https://krebsonsecurity.com/2021/10/what-happened-to-facebook-instagram-whatsapp/'>www.krebsonsecurity.com</a> - What happened to Facebook...?<br/>-<a href='https://en.wikipedia.org/wiki/HTTP_cookie'>www.wikipedia.com </a>- Cookies</p><p>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9338229-36-cookies.mp3" length="21687651" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9338229</guid>
    <pubDate>Sat, 09 Oct 2021 15:00:00 +0400</pubDate>
    <itunes:duration>1803</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>36</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>35 - It Is Cyber Security Month!</itunes:title>
    <title>35 - It Is Cyber Security Month!</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim Yusuf! October is Cyber Security month and it is only fitting we focus on this on this episode/ It is all coming up next on Yusuf on Security! -theharckernews.com: Be Care Of Fake Amnesty International AV -www.technologyreview.com:  The proliferation of zero-days - www.govinfosecurity.com: NSA, CISA Release VPN Security Guidance  Be sure to subscribe! If you like the content. Follow ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim Yusuf!</b></p><p><b>October is Cyber Security month and it is only fitting we focus on this on this episode/</b></p><p><b>It is all coming up next on Yusuf on Security!</b></p><p><a href='https://thehackernews.com/2021/10/beware-of-fake-amnesty-international.html'>-theharckernews.com: </a>Be Care Of Fake Amnesty International AV<br/>-<a href='https://www.technologyreview.com/2021/09/23/1036140/2021-record-zero-day-hacks-reasons/'>www.technologyreview.com</a>:  The proliferation of zero-days<br/>-<b> </b><a href='https://www.govinfosecurity.com/nsa-cisa-release-vpn-security-guidance-a-17640'><b>www.govinfosecurity.com</b></a>: NSA, CISA Release VPN Security Guidance<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim Yusuf!</b></p><p><b>October is Cyber Security month and it is only fitting we focus on this on this episode/</b></p><p><b>It is all coming up next on Yusuf on Security!</b></p><p><a href='https://thehackernews.com/2021/10/beware-of-fake-amnesty-international.html'>-theharckernews.com: </a>Be Care Of Fake Amnesty International AV<br/>-<a href='https://www.technologyreview.com/2021/09/23/1036140/2021-record-zero-day-hacks-reasons/'>www.technologyreview.com</a>:  The proliferation of zero-days<br/>-<b> </b><a href='https://www.govinfosecurity.com/nsa-cisa-release-vpn-security-guidance-a-17640'><b>www.govinfosecurity.com</b></a>: NSA, CISA Release VPN Security Guidance<br/><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9296686-35-it-is-cyber-security-month.mp3" length="18663652" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9296686</guid>
    <pubDate>Sat, 02 Oct 2021 10:00:00 +0400</pubDate>
    <itunes:duration>1551</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>34 - Office 365 Email Security - A Talk with ISGM </itunes:title>
    <title>34 - Office 365 Email Security - A Talk with ISGM </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here.  Welcome back. This week I have a great content. It is a recording I had with Mathew Schwartz at ISMG -Information Security Media Group. Having said that… we will start with few top of mind security news including…. - www.darkreading.com: IoT 'Nutrition' Labels Aim to Put Security on Display - www.bleepingcomputer.com: Researchers compile list of vulnerabilities abused by ransomware gangs ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here.  Welcome back.</b></p><p><b>This week I have a great content. It is a recording I had with Mathew Schwartz at ISMG -Information Security Media Group.</b></p><p><b>Having said that… we will start with few top of mind security news including….</b></p><p><b>- </b><a href='https://www.darkreading.com/endpoint/iot-nutrition-labels-aim-to-put-security-on-display'><b>www.darkreading.com</b></a>: IoT &apos;Nutrition&apos; Labels Aim to Put Security on Display</p><p><b>- </b><a href='https://www.bleepingcomputer.com/news/security/researchers-compile-list-of-vulnerabilities-abused-by-ransomware-gangs/'><b>www.bleepingcomputer.com</b></a>: Researchers compile list of vulnerabilities abused by ransomware gangs</p><p>-<a href='http://stopransomware.gov/'>stopransomware.gov</a> - Stop ransomware</p><p>-<a href='http://event.ismg.io'>event.ismg.io</a> - Information Security Media Group </p><p><br/></p><p><b><br/></b>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here.  Welcome back.</b></p><p><b>This week I have a great content. It is a recording I had with Mathew Schwartz at ISMG -Information Security Media Group.</b></p><p><b>Having said that… we will start with few top of mind security news including….</b></p><p><b>- </b><a href='https://www.darkreading.com/endpoint/iot-nutrition-labels-aim-to-put-security-on-display'><b>www.darkreading.com</b></a>: IoT &apos;Nutrition&apos; Labels Aim to Put Security on Display</p><p><b>- </b><a href='https://www.bleepingcomputer.com/news/security/researchers-compile-list-of-vulnerabilities-abused-by-ransomware-gangs/'><b>www.bleepingcomputer.com</b></a>: Researchers compile list of vulnerabilities abused by ransomware gangs</p><p>-<a href='http://stopransomware.gov/'>stopransomware.gov</a> - Stop ransomware</p><p>-<a href='http://event.ismg.io'>event.ismg.io</a> - Information Security Media Group </p><p><br/></p><p><b><br/></b>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9261879-34-office-365-email-security-a-talk-with-isgm.mp3" length="32197729" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9261879</guid>
    <pubDate>Sun, 26 Sep 2021 21:00:00 +0400</pubDate>
    <itunes:duration>2679</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>33 - Modern Security Operation Center - Part 2</itunes:title>
    <title>33 - Modern Security Operation Center - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here.  Welcome back. We will get into our second part of our two parts series into Security Operation Center.  Having said that… we will start with few top of mind security news including…. - www.wired.com: Time to Patch All The Things - threatpost.com: Universal Decryptor for REvil/Sodinokibi Released -https://protonmail.com/privacy-policy: ProtonMail Policy  Be sure to subscribe! If you l...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here.  Welcome back.</b></p><p><b>We will get into our second part of our two parts series into Security Operation Center. </b></p><p><b>Having said that… we will start with few top of mind security news including….</b></p><p><b>- </b><a href='https://www.wired.com/story/update-ios-windows-chrome-zero-day-patch/'><b>www.wired.com</b></a>: Time to Patch All The Things</p><p><b>- </b><a href='https://threatpost.com/revil-sodinokibi-ransomware-universal-decryptor/169498/'><b>threatpost.com</b></a>: <b>Universal Decryptor for REvil/Sodinokibi Released</b></p><p>-<a href='https://protonmail.com/privacy-policy'>https://protonmail.com/privacy-policy</a>: ProtonMail Policy</p><p><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here.  Welcome back.</b></p><p><b>We will get into our second part of our two parts series into Security Operation Center. </b></p><p><b>Having said that… we will start with few top of mind security news including….</b></p><p><b>- </b><a href='https://www.wired.com/story/update-ios-windows-chrome-zero-day-patch/'><b>www.wired.com</b></a>: Time to Patch All The Things</p><p><b>- </b><a href='https://threatpost.com/revil-sodinokibi-ransomware-universal-decryptor/169498/'><b>threatpost.com</b></a>: <b>Universal Decryptor for REvil/Sodinokibi Released</b></p><p>-<a href='https://protonmail.com/privacy-policy'>https://protonmail.com/privacy-policy</a>: ProtonMail Policy</p><p><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9217409-33-modern-security-operation-center-part-2.mp3" length="20438857" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9217409</guid>
    <pubDate>Sat, 18 Sep 2021 19:00:00 +0400</pubDate>
    <itunes:duration>1699</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>32 - Modern Security Operation Center - Part 1</itunes:title>
    <title>32 - Modern Security Operation Center - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here. Welcome to the show. We will look into the need of a SOC and what that entails today. This will be a two part series. - www.fortinet.com: Malicious Actor Discloses FortiGate SSL-VPN Credentials - www.bleepingcomputer.com: Netgear fixes severe security bugs in over a dozen smart switches - www.bleepingcomputer.com: Angry Conti ransomware affiliate leaks gang's attack playbook  Be sure to subscri...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Welcome to the show.</b></p><p><b>We will look into the need of a SOC and what that entails today. This will be a two part series.</b></p><p>- <a href='https://www.fortinet.com/blog/psirt-blogs/malicious-actor-discloses-fortigate-ssl-vpn-crede'>www.fortinet.com:</a> Malicious Actor Discloses FortiGate SSL-VPN Credentials</p><p>- <a href='https://www.bleepingcomputer.com/news/security/netgear-fixes-severe-security-bugs-in-over-a-dozen-smart-switches/'>www.bleepingcomputer.com</a>: Netgear fixes severe security bugs in over a dozen smart switches</p><p><a href='https://www.bleepingcomputer.com/news/security/angry-conti-ransomware-affiliate-leaks-gangs-attack-playbook/'>- www.bleepingcomputer.com</a>: Angry Conti ransomware affiliate leaks gang&apos;s attack playbook</p><p><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Welcome to the show.</b></p><p><b>We will look into the need of a SOC and what that entails today. This will be a two part series.</b></p><p>- <a href='https://www.fortinet.com/blog/psirt-blogs/malicious-actor-discloses-fortigate-ssl-vpn-crede'>www.fortinet.com:</a> Malicious Actor Discloses FortiGate SSL-VPN Credentials</p><p>- <a href='https://www.bleepingcomputer.com/news/security/netgear-fixes-severe-security-bugs-in-over-a-dozen-smart-switches/'>www.bleepingcomputer.com</a>: Netgear fixes severe security bugs in over a dozen smart switches</p><p><a href='https://www.bleepingcomputer.com/news/security/angry-conti-ransomware-affiliate-leaks-gangs-attack-playbook/'>- www.bleepingcomputer.com</a>: Angry Conti ransomware affiliate leaks gang&apos;s attack playbook</p><p><br/>Be sure to subscribe!</p><p>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9176595-32-modern-security-operation-center-part-1.mp3" length="15037780" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9176595</guid>
    <pubDate>Sat, 11 Sep 2021 16:00:00 +0400</pubDate>
    <itunes:duration>1249</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>32</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>31 - Red Teaming</itunes:title>
    <title>31 - Red Teaming</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here. Welcome to the show. We have our first guest, yes! It finally happened and we will talk about t Red Teaming but first, we will start with few top of mind security news. - statescoop.com: Industry group offers new cyber guidance for K-12 schools  -cybersecuritydive.com: US govt warns orgs to patch massively exploited Confluence bug  - www.scmagazine.com: ISAC group unveils pragmatic, attainable ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, Ibrahim is here. Welcome to the show.</p><p>We have our first guest, yes! It finally happened and we will talk about t Red Teaming but first, we will start with few top of mind security news.</p><p><b>- </b><a href='https://statescoop.com/industry-group-offers-new-cyber-guidance-for-k-12-schools/'><b>statescoop.com</b></a>: Industry group offers new cyber guidance for K-12 schools<br/><br/>-<a href='https://www.cybersecuritydive.com/news/cyber-command-patch-atlassian-confluence-bug/606093/'><b>cybersecuritydive.com</b></a>: US govt warns orgs to patch massively exploited Confluence bug<br/><br/><b>- </b><a href='https://www.scmagazine.com/analysis/leadership/isac-group-unveils-pragmatic-attainable-cyber-standards-for-school-districts'><b>www.scmagazine.com</b></a>: ISAC group unveils pragmatic, attainable cyber standards for school districts<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, Ibrahim is here. Welcome to the show.</p><p>We have our first guest, yes! It finally happened and we will talk about t Red Teaming but first, we will start with few top of mind security news.</p><p><b>- </b><a href='https://statescoop.com/industry-group-offers-new-cyber-guidance-for-k-12-schools/'><b>statescoop.com</b></a>: Industry group offers new cyber guidance for K-12 schools<br/><br/>-<a href='https://www.cybersecuritydive.com/news/cyber-command-patch-atlassian-confluence-bug/606093/'><b>cybersecuritydive.com</b></a>: US govt warns orgs to patch massively exploited Confluence bug<br/><br/><b>- </b><a href='https://www.scmagazine.com/analysis/leadership/isac-group-unveils-pragmatic-attainable-cyber-standards-for-school-districts'><b>www.scmagazine.com</b></a>: ISAC group unveils pragmatic, attainable cyber standards for school districts<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9139586-31-red-teaming.mp3" length="27425090" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9139586</guid>
    <pubDate>Sat, 04 Sep 2021 22:00:00 +0400</pubDate>
    <itunes:duration>2281</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>31</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>30 - MITRE Engenuity ATT&amp;CK Evaluation</itunes:title>
    <title>30 - MITRE Engenuity ATT&amp;CK Evaluation</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here. Glad you are joining me today. Today we will look in the MITRE ATT&amp;CK Evaluation which provides vendors with an assessment of their ability to defend against specific adversary tactics and techniques.  But first, we will start with few top of mind security news.  - www.bloomberg.com Microsoft Fixed Security Issue in Azure Cosmos DB  - https://www.bleepingcomputer.com - FBI releases ale...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Glad you are joining me today.</b></p><p><b>Today we will look in the MITRE ATT&amp;CK Evaluation which provides vendors with an assessment of their ability to defend against specific adversary tactics and techniques. </b></p><p><b>But first, we will start with few top of mind security news.</b></p><p><br/>- <a href='https://www.bloomberg.com/news/articles/2021-08-27/microsoft-cloud-databases-vulnerable-for-years-researchers-say'><b>www.bloomberg.com</b></a><b> Microsoft Fixed Security Issue in Azure Cosmos DB<br/></b><br/>-<a href='https://www.bleepingcomputer.com/news/security/fbi-shares-technical-details-for-hive-ransomware/'> https://www.bleepingcomputer.com</a> - FBI releases alert about Hive ransomware</p><p>- <a href='https://attack.mitre.org/groups/G0046/'>https://attack.mitre.org </a>- The FIN7 Group<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Glad you are joining me today.</b></p><p><b>Today we will look in the MITRE ATT&amp;CK Evaluation which provides vendors with an assessment of their ability to defend against specific adversary tactics and techniques. </b></p><p><b>But first, we will start with few top of mind security news.</b></p><p><br/>- <a href='https://www.bloomberg.com/news/articles/2021-08-27/microsoft-cloud-databases-vulnerable-for-years-researchers-say'><b>www.bloomberg.com</b></a><b> Microsoft Fixed Security Issue in Azure Cosmos DB<br/></b><br/>-<a href='https://www.bleepingcomputer.com/news/security/fbi-shares-technical-details-for-hive-ransomware/'> https://www.bleepingcomputer.com</a> - FBI releases alert about Hive ransomware</p><p>- <a href='https://attack.mitre.org/groups/G0046/'>https://attack.mitre.org </a>- The FIN7 Group<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9100251-30-mitre-engenuity-att-ck-evaluation.mp3" length="13698622" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9100251</guid>
    <pubDate>Sat, 28 Aug 2021 13:00:00 +0400</pubDate>
    <itunes:duration>1137</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>29 - Apple’s CSAM Detection System</itunes:title>
    <title>29 - Apple’s CSAM Detection System</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here. Welcome back. In this episode we will tackle Apple new child protection feature - child abuse detection system -CSAM    - www.rapid7.com: Fortinet FortiWeb OS Command Injection - googleprojectzero.blogspot.com: Understanding Network Access in Windows AppContainers - https://www.cybereason.com: Disgrounted Employees to Deploy Ransomware to share ransomware profit  This is Yusuf On Security,...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Welcome back.</b></p><p><b>In this episode we will tackle Apple new child protection feature - child abuse detection system -CSAM  <br/><br/>- </b><a href='https://www.rapid7.com/blog/post/2021/08/17/fortinet-fortiweb-os-command-injection/'><b>www.rapid7.com</b></a>: Fortinet FortiWeb OS Command Injection<br/><b>- </b><a href='https://googleprojectzero.blogspot.com/2021/08/understanding-network-access-windows-app.html'><b>googleprojectzero.blogspot.com</b></a>: Understanding Network Access in Windows AppContainers<br/>- <a href='https://www.cybereason.com/blog/lockbit-ransomware-wants-to-hire-your-employees'><b>https://www.cybereason.com</b></a>:<b> Disgrounted Employees to Deploy Ransomware to share ransomware profit<br/><br/>This is Yusuf On Security, <br/><br/></b><br/></p><p><b>Episode 28</b></p><p><b>Recorded Saturday 21st August 2021 :  Apple’s CSAM Detection System</b></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Welcome back.</b></p><p><b>In this episode we will tackle Apple new child protection feature - child abuse detection system -CSAM  <br/><br/>- </b><a href='https://www.rapid7.com/blog/post/2021/08/17/fortinet-fortiweb-os-command-injection/'><b>www.rapid7.com</b></a>: Fortinet FortiWeb OS Command Injection<br/><b>- </b><a href='https://googleprojectzero.blogspot.com/2021/08/understanding-network-access-windows-app.html'><b>googleprojectzero.blogspot.com</b></a>: Understanding Network Access in Windows AppContainers<br/>- <a href='https://www.cybereason.com/blog/lockbit-ransomware-wants-to-hire-your-employees'><b>https://www.cybereason.com</b></a>:<b> Disgrounted Employees to Deploy Ransomware to share ransomware profit<br/><br/>This is Yusuf On Security, <br/><br/></b><br/></p><p><b>Episode 28</b></p><p><b>Recorded Saturday 21st August 2021 :  Apple’s CSAM Detection System</b></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9063617-29-apple-s-csam-detection-system.mp3" length="21924992" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9063617</guid>
    <pubDate>Sat, 21 Aug 2021 14:00:00 +0400</pubDate>
    <itunes:duration>1823</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>29</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>28 - The BlackMatter Interview</itunes:title>
    <title>28 - The BlackMatter Interview</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here. Welcome back. This week’s show is quit interesting show. We delve into the mindset of the notorious REvil ransomware group. But first, we will start with few top of mind security news. It is all coming up next on Yusuf on Security! - www.zdnet.com: Firefox 91 gets HTTPS default in private mode, enhanced cookie clearing and  - github.blog: Git password authentication is shutting down -reuters.co...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Welcome back.</b></p><p><b>This week’s show is quit interesting show. We delve into the mindset of the notorious REvil ransomware group.</b></p><p><b>But first, we will start with few top of mind security news.</b></p><p><b>It is all coming up next on Yusuf on Security!</b></p><p><b>- </b><a href='https://www.zdnet.com/article/firefox-91-gets-https-default-in-private-mode-enhanced-cookie-clearing-and-windows-sso/'><b>www.zdnet.com</b></a>: Firefox 91 gets HTTPS default in private mode, enhanced cookie clearing and <br/><b>- </b><a href='https://github.blog/changelog/2021-08-12-git-password-authentication-is-shutting-down/'><b>github.blog</b></a>: Git password authentication is shutting down<br/>-<a href='https://www.reuters.com/technology/accenture-restores-affected-systems-after-reported-ransomware-attack-2021-08-11/'>reuters.com</a>: Accenture restores affected systems after reported ransomware attack<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, Ibrahim is here. Welcome back.</b></p><p><b>This week’s show is quit interesting show. We delve into the mindset of the notorious REvil ransomware group.</b></p><p><b>But first, we will start with few top of mind security news.</b></p><p><b>It is all coming up next on Yusuf on Security!</b></p><p><b>- </b><a href='https://www.zdnet.com/article/firefox-91-gets-https-default-in-private-mode-enhanced-cookie-clearing-and-windows-sso/'><b>www.zdnet.com</b></a>: Firefox 91 gets HTTPS default in private mode, enhanced cookie clearing and <br/><b>- </b><a href='https://github.blog/changelog/2021-08-12-git-password-authentication-is-shutting-down/'><b>github.blog</b></a>: Git password authentication is shutting down<br/>-<a href='https://www.reuters.com/technology/accenture-restores-affected-systems-after-reported-ransomware-attack-2021-08-11/'>reuters.com</a>: Accenture restores affected systems after reported ransomware attack<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/9030020-28-the-blackmatter-interview.mp3" length="17788442" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9030020</guid>
    <pubDate>Sun, 15 Aug 2021 10:00:00 +0400</pubDate>
    <itunes:duration>1478</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>28</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>27  -  Interview With Information Security Media Group </itunes:title>
    <title>27  -  Interview With Information Security Media Group </title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today’s show I will provide you an interview I had with Information Security Media Group better known as ISMG. -https://www.tripwire.com: BlackMatter rises from the ashes of notorious cybercrime gangs to pose new ransomware threat -https://www.esa.int: Reprogrammable satellite launched -https://securityaffairs.co: BlackMatter Ransomware gang attack ESXi Server with ransomware  Be sure to subscribe!  If you like the content. Follow me @iayusu...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today’s show I will provide you an interview I had with Information Security Media Group better known as ISMG.</b></p><p>-<a href='https://www.tripwire.com/state-of-security/featured/blackmatter-pose-new-ransomware-threat/'>https://www.tripwire.com</a>: BlackMatter rises from the ashes of notorious cybercrime gangs to pose new ransomware threat</p><p><a href='https://www.esa.int/Applications/Telecommunications_Integrated_Applications/Reprogrammable_satellite_launched'>-https://www.esa.int:</a> Reprogrammable satellite launched</p><p><a href='https://securityaffairs.co'>-https://securityaffairs.co:</a> BlackMatter Ransomware gang attack ESXi Server with ransomware<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>In today’s show I will provide you an interview I had with Information Security Media Group better known as ISMG.</b></p><p>-<a href='https://www.tripwire.com/state-of-security/featured/blackmatter-pose-new-ransomware-threat/'>https://www.tripwire.com</a>: BlackMatter rises from the ashes of notorious cybercrime gangs to pose new ransomware threat</p><p><a href='https://www.esa.int/Applications/Telecommunications_Integrated_Applications/Reprogrammable_satellite_launched'>-https://www.esa.int:</a> Reprogrammable satellite launched</p><p><a href='https://securityaffairs.co'>-https://securityaffairs.co:</a> BlackMatter Ransomware gang attack ESXi Server with ransomware<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8990906-27-interview-with-information-security-media-group.mp3" length="31883643" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8990906</guid>
    <pubDate>Sat, 07 Aug 2021 22:00:00 +0400</pubDate>
    <itunes:duration>2653</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>26 - CyberChef</itunes:title>
    <title>26 - CyberChef</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, Ibrahim is here. Great to have you onboard. In this week’s episode I’ll details of a tool I used from time time. But first, we will start with few top of mind security news.  - blogs.blackberry.com: Old Dogs New Tricks: Attackers Adopt Exotic Programming Languages - blog.mozilla.org: Stopping FTP support in Firefox 90 - www.govinfosecurity.com: 18 Companies to Participate in NIST 'Zero Trust' Project -Cyberchef...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, Ibrahim is here. Great to have you onboard.<br/>In this week’s episode I’ll details of a tool I used from time time.<br/>But first, we will start with few top of mind security news.<br/><br/><b>- </b><a href='https://blogs.blackberry.com/en/2021/07/old-dogs-new-tricks-attackers-adopt-exotic-programming-languages'><b>blogs.blackberry.com</b></a>: Old Dogs New Tricks: Attackers Adopt Exotic Programming Languages<br/><b>- </b><a href='https://blog.mozilla.org/security/2021/07/20/stopping-ftp-support-in-firefox-90/'><b>blog.mozilla.org</b></a>: Stopping FTP support in Firefox 90<br/><b>- </b><a href='https://www.govinfosecurity.com/18-companies-to-participate-in-nist-zero-trust-project-a-17145'><b>www.govinfosecurity.com</b></a>: 18 Companies to Participate in NIST &apos;Zero Trust&apos; Project<br/>-<a href='https://gchq.github.io/CyberChef/'>Cyberchef</a>: The Cyber Swiss Army Knife<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, Ibrahim is here. Great to have you onboard.<br/>In this week’s episode I’ll details of a tool I used from time time.<br/>But first, we will start with few top of mind security news.<br/><br/><b>- </b><a href='https://blogs.blackberry.com/en/2021/07/old-dogs-new-tricks-attackers-adopt-exotic-programming-languages'><b>blogs.blackberry.com</b></a>: Old Dogs New Tricks: Attackers Adopt Exotic Programming Languages<br/><b>- </b><a href='https://blog.mozilla.org/security/2021/07/20/stopping-ftp-support-in-firefox-90/'><b>blog.mozilla.org</b></a>: Stopping FTP support in Firefox 90<br/><b>- </b><a href='https://www.govinfosecurity.com/18-companies-to-participate-in-nist-zero-trust-project-a-17145'><b>www.govinfosecurity.com</b></a>: 18 Companies to Participate in NIST &apos;Zero Trust&apos; Project<br/>-<a href='https://gchq.github.io/CyberChef/'>Cyberchef</a>: The Cyber Swiss Army Knife<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8953022-26-cyberchef.mp3" length="18987117" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8953022</guid>
    <pubDate>Sat, 31 Jul 2021 21:00:00 +0400</pubDate>
    <itunes:duration>1578</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>26</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>25 - Intrusion Analysis - Part 2</itunes:title>
    <title>25 - Intrusion Analysis - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim Yusuf. Great to have you onboard again.  We will continue into the Intrusion Analysis subject we began last week to help you spotting abnormal behavior within your environment.   But first, we will start with top of mind security news. - techcrunch.com: This tool tells you if NSO’s Pegasus spyware targeted your phone - www.kaseya.com: Updates Regarding VSA Security Incident  - arstechnica...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, I am your host Ibrahim Yusuf. Great to have you onboard again.<br/><br/>We will continue into the Intrusion Analysis subject we began last week to help you spotting abnormal behavior within your environment. <br/><br/>But first, we will start with top of mind security news.<br/><b>- </b><a href='https://techcrunch.com/2021/07/19/toolkit-nso-pegasus-iphone-android/'><b>techcrunch.com</b></a>: This tool tells you if NSO’s Pegasus spyware targeted your phone<br/><b>- </b><a href='https://www.kaseya.com/potential-attack-on-kaseya-vsa/'><b>www.kaseya.com</b></a>: Updates Regarding VSA Security Incident<br/> <b>- </b><a href='https://arstechnica.com/gadgets/2021/07/kaseya-gets-master-decryptor-to-help-customers-still-suffering-from-revil-attack/'><b>arstechnica.com</b></a>: Kaseya gets master decryptor to help customers still suffering from REvil attack<br/><b>- </b><a href='https://arstechnica.com/information-technology/2021/07/saudi-aramco-confirms-data-leak-after-50-million-cyber-ransom-demand/'><b>arstechnica.com</b></a>: Saudi Aramco confirms data leak after $50 million cyber ransom demand<br/>- <a href='https://es.royalholloway.ac.uk/about-us/news/new-research-shows-cryptographic-vulnerabilities-on-popular-messaging-platform-telegram/'><b>New research shows cryptographic vulnerabilities on popular messaging platform, Telegram</b></a><b><br/><br/></b>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, I am your host Ibrahim Yusuf. Great to have you onboard again.<br/><br/>We will continue into the Intrusion Analysis subject we began last week to help you spotting abnormal behavior within your environment. <br/><br/>But first, we will start with top of mind security news.<br/><b>- </b><a href='https://techcrunch.com/2021/07/19/toolkit-nso-pegasus-iphone-android/'><b>techcrunch.com</b></a>: This tool tells you if NSO’s Pegasus spyware targeted your phone<br/><b>- </b><a href='https://www.kaseya.com/potential-attack-on-kaseya-vsa/'><b>www.kaseya.com</b></a>: Updates Regarding VSA Security Incident<br/> <b>- </b><a href='https://arstechnica.com/gadgets/2021/07/kaseya-gets-master-decryptor-to-help-customers-still-suffering-from-revil-attack/'><b>arstechnica.com</b></a>: Kaseya gets master decryptor to help customers still suffering from REvil attack<br/><b>- </b><a href='https://arstechnica.com/information-technology/2021/07/saudi-aramco-confirms-data-leak-after-50-million-cyber-ransom-demand/'><b>arstechnica.com</b></a>: Saudi Aramco confirms data leak after $50 million cyber ransom demand<br/>- <a href='https://es.royalholloway.ac.uk/about-us/news/new-research-shows-cryptographic-vulnerabilities-on-popular-messaging-platform-telegram/'><b>New research shows cryptographic vulnerabilities on popular messaging platform, Telegram</b></a><b><br/><br/></b>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8915931-25-intrusion-analysis-part-2.mp3" length="18999691" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8915931</guid>
    <pubDate>Sat, 24 Jul 2021 23:00:00 +0400</pubDate>
    <itunes:duration>1579</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>24 - Intrusion Analysis - Part 1</itunes:title>
    <title>24 - Intrusion Analysis - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today’s show we will look at Intrusion Analysis, spotting abnormal behavior within your environment.  As usual we will start with some trending security news   - www.sonicwall.com: Urgent Security Notice: Critical Risk To Unpatched End-Of-Life SRA &amp; SMA 8.X Remote Access Devices  - www.zdnet.com: SonicWall releases urgent notice about 'imminent' ransomware targeting firmware - www.theregister.com: REvil ransomware gang's websites vanish ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s show we will look at Intrusion Analysis, spotting abnormal behavior within your environment. <br/>As usual we will start with some trending security news <br/><br/><b>- </b><a href='https://www.sonicwall.com/support/product-notification/urgent-security-notice-critical-risk-to-unpatched-end-of-life-sra-sma-8-x-remote-access-devices/210713105333210/'><b>www.sonicwall.com</b></a>: Urgent Security Notice: Critical Risk To Unpatched End-Of-Life SRA &amp; SMA 8.X Remote Access Devices<br/> <b>- </b><a href='https://www.zdnet.com/article/sonicwall-releases-urgent-notice-about-imminent-ransomware-targeting-firmware/'><b>www.zdnet.com</b></a>: SonicWall releases urgent notice about &apos;imminent&apos; ransomware targeting firmware<br/><b>- </b><a href='https://www.theregister.com/2021/07/13/revil_ransomware_shuts/'><b>www.theregister.com</b></a>: REvil ransomware gang&apos;s websites vanish soon after Kaseya fiasco, Uncle Sam threatens retaliation<br/> <b>- </b><a href='https://www.zdnet.com/article/revil-websites-down-after-governments-pressured-to-take-action-following-kaseya-attack/'><b>www.zdnet.com</b></a>: REvil websites down after governments pressured to take action following Kaseya attack<br/><b>- </b><a href='https://www.scmagazine.com/brief/patch-management/microsoft-fixes-117-vulnerabilities-four-exploited-in-the-wild'><b>www.scmagazine.com</b></a>: Microsoft fixes 117 vulnerabilities, four exploited in the wild<br/> <b>- </b><a href='https://www.zdnet.com/article/microsoft-july-2021-patch-tuesday-117-vulnerabilities-pwn2own-exchange-server-bug-fixed/'><b>www.zdnet.com</b></a>: Microsoft July 2021 Patch Tuesday: 117 vulnerabilities, Pwn2Own Exchange Server bug fixed<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s show we will look at Intrusion Analysis, spotting abnormal behavior within your environment. <br/>As usual we will start with some trending security news <br/><br/><b>- </b><a href='https://www.sonicwall.com/support/product-notification/urgent-security-notice-critical-risk-to-unpatched-end-of-life-sra-sma-8-x-remote-access-devices/210713105333210/'><b>www.sonicwall.com</b></a>: Urgent Security Notice: Critical Risk To Unpatched End-Of-Life SRA &amp; SMA 8.X Remote Access Devices<br/> <b>- </b><a href='https://www.zdnet.com/article/sonicwall-releases-urgent-notice-about-imminent-ransomware-targeting-firmware/'><b>www.zdnet.com</b></a>: SonicWall releases urgent notice about &apos;imminent&apos; ransomware targeting firmware<br/><b>- </b><a href='https://www.theregister.com/2021/07/13/revil_ransomware_shuts/'><b>www.theregister.com</b></a>: REvil ransomware gang&apos;s websites vanish soon after Kaseya fiasco, Uncle Sam threatens retaliation<br/> <b>- </b><a href='https://www.zdnet.com/article/revil-websites-down-after-governments-pressured-to-take-action-following-kaseya-attack/'><b>www.zdnet.com</b></a>: REvil websites down after governments pressured to take action following Kaseya attack<br/><b>- </b><a href='https://www.scmagazine.com/brief/patch-management/microsoft-fixes-117-vulnerabilities-four-exploited-in-the-wild'><b>www.scmagazine.com</b></a>: Microsoft fixes 117 vulnerabilities, four exploited in the wild<br/> <b>- </b><a href='https://www.zdnet.com/article/microsoft-july-2021-patch-tuesday-117-vulnerabilities-pwn2own-exchange-server-bug-fixed/'><b>www.zdnet.com</b></a>: Microsoft July 2021 Patch Tuesday: 117 vulnerabilities, Pwn2Own Exchange Server bug fixed<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8877441-24-intrusion-analysis-part-1.mp3" length="19243178" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8877441</guid>
    <pubDate>Sat, 17 Jul 2021 08:00:00 +0400</pubDate>
    <itunes:duration>1600</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>24</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>23 - Interview with CBA TV</itunes:title>
    <title>23 - Interview with CBA TV</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim Yusuf.  Welcome back again.  A TV station reached out to me and I thought it would be good to provide you with that interview. However , lets start with some current security news.   - threatpost.com: Kaseya Attack Fallout: CISA, FBI Offer Guidance  - www.bleepingcomputer.com: CISA, FBI share guidance for victims of Kaseya ransomware  - media.defense.gov: Russian GRU Conducting Globa...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, I am your host Ibrahim Yusuf.  Welcome back again.<br/><br/>A TV station reached out to me and I thought it would be good to provide you with that interview. However , lets start with some current security news. <br/><br/><b>- </b><a href='https://threatpost.com/kaseya-attack-fallout/167541/'><b>threatpost.com</b></a>: Kaseya Attack Fallout: CISA, FBI Offer Guidance<br/> <b>- </b><a href='https://www.bleepingcomputer.com/news/security/cisa-fbi-share-guidance-for-victims-of-kaseya-ransomware-attack/'><b>www.bleepingcomputer.com</b></a>: CISA, FBI share guidance for victims of Kaseya ransomware <br/><b>- </b><a href='https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/1/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF'><b>media.defense.gov</b></a>: Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments (PDF)<br/> <b>- </b><a href='https://www.wired.com/story/fancy-bear-russia-brute-force-hacking/'><b>www.wired.com</b></a>: Russian Hackers Are Trying to Brute-Force Hundreds of Networks<br/><b>- </b><a href='https://www.govinfosecurity.com/cisa-tool-helps-measure-readiness-to-thwart-ransomware-a-16973'><b>www.govinfosecurity.com</b></a>: CISA Tool Helps Measure Readiness to Thwart Ransomware<br/><b>- </b><a href='https://us-cert.cisa.gov/ncas/current-activity/2021/06/30/cisas-cset-tool-sets-sights-ransomware-threat'><b>US-cert.cisa.gov</b></a>: CISA’s CSET Tool Sets Sights on Ransomware <a href='https://cbatv.net/'><br/>-CBATV – </a>Threat Horn of Africa fastest growing TV<a href='https://cbatv.net/'> </a></p><p>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>It is time for Yusuf On Security, I am your host Ibrahim Yusuf.  Welcome back again.<br/><br/>A TV station reached out to me and I thought it would be good to provide you with that interview. However , lets start with some current security news. <br/><br/><b>- </b><a href='https://threatpost.com/kaseya-attack-fallout/167541/'><b>threatpost.com</b></a>: Kaseya Attack Fallout: CISA, FBI Offer Guidance<br/> <b>- </b><a href='https://www.bleepingcomputer.com/news/security/cisa-fbi-share-guidance-for-victims-of-kaseya-ransomware-attack/'><b>www.bleepingcomputer.com</b></a>: CISA, FBI share guidance for victims of Kaseya ransomware <br/><b>- </b><a href='https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/1/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF'><b>media.defense.gov</b></a>: Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments (PDF)<br/> <b>- </b><a href='https://www.wired.com/story/fancy-bear-russia-brute-force-hacking/'><b>www.wired.com</b></a>: Russian Hackers Are Trying to Brute-Force Hundreds of Networks<br/><b>- </b><a href='https://www.govinfosecurity.com/cisa-tool-helps-measure-readiness-to-thwart-ransomware-a-16973'><b>www.govinfosecurity.com</b></a>: CISA Tool Helps Measure Readiness to Thwart Ransomware<br/><b>- </b><a href='https://us-cert.cisa.gov/ncas/current-activity/2021/06/30/cisas-cset-tool-sets-sights-ransomware-threat'><b>US-cert.cisa.gov</b></a>: CISA’s CSET Tool Sets Sights on Ransomware <a href='https://cbatv.net/'><br/>-CBATV – </a>Threat Horn of Africa fastest growing TV<a href='https://cbatv.net/'> </a></p><p>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8857281-23-interview-with-cba-tv.mp3" length="19834448" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8857281</guid>
    <pubDate>Tue, 13 Jul 2021 19:00:00 +0400</pubDate>
    <itunes:duration>1649</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>23</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>22 - Is Internal Email Scan Necessary?</itunes:title>
    <title>22 - Is Internal Email Scan Necessary?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Today we will look at a supplement security product. Why supplement, I heard you ask - well supplement to an already existing security tool. Before we get into that though, lets start with some current security news.   - PrintNightmare -  A zero day for every supported Windows OS version in the wild   -Cyber Insurance and the Cyber Security Challenge -rusi.org: Cyber Insurance and the Cyber Security Challenge  -The DarkSide Ransomware Gang...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we will look at a supplement security product. Why supplement, I heard you ask - well supplement to an already existing security tool. Before we get into that though, lets start with some current security news. <br/><br/>- <a href='https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c'>PrintNightmare -  A zero day for every supported Windows OS version in the wild </a><br/><br/>-<a href='https://static.rusi.org/247-op-cyber-insurance-v2.pdf'>Cyber Insurance and the Cyber Security Challenge</a><br/>-<a href='https://rusi.org/explore-our-research/publications/occasional-papers/cyber-insurance-and-cyber-security-challenge'><b>rusi.org</b></a>: Cyber Insurance and the Cyber Security Challenge<br/><br/>-<a href='https://www.schneier.com/blog/archives/2021/06/the-darkside-ransomware-gang.html'><b>The DarkSide Ransomware Gang</b></a><b><br/><br/></b>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Today we will look at a supplement security product. Why supplement, I heard you ask - well supplement to an already existing security tool. Before we get into that though, lets start with some current security news. <br/><br/>- <a href='https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c'>PrintNightmare -  A zero day for every supported Windows OS version in the wild </a><br/><br/>-<a href='https://static.rusi.org/247-op-cyber-insurance-v2.pdf'>Cyber Insurance and the Cyber Security Challenge</a><br/>-<a href='https://rusi.org/explore-our-research/publications/occasional-papers/cyber-insurance-and-cyber-security-challenge'><b>rusi.org</b></a>: Cyber Insurance and the Cyber Security Challenge<br/><br/>-<a href='https://www.schneier.com/blog/archives/2021/06/the-darkside-ransomware-gang.html'><b>The DarkSide Ransomware Gang</b></a><b><br/><br/></b>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.<br/><br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8805273-22-is-internal-email-scan-necessary.mp3" length="20159540" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8805273</guid>
    <pubDate>Sat, 03 Jul 2021 15:00:00 +0400</pubDate>
    <itunes:duration>1676</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>22</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>21 - Secure Access Service Edge (SASE)</itunes:title>
    <title>21 - Secure Access Service Edge (SASE)</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! It is time for Yusuf On Security, I am your host Ibrahim Yusuf.  Glad you’re joining me once again. We will go and demystify another one of those buzz word in the industry. It is SASE but before we get into that, lets start with some current security news.   - Secure Access Service Edge (SASE) - The Rise of Direct Internet Access (DIA) - The Future of Network Security Is in the Cloud - Complexity versus Security  Be sure to subscribe!  If ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim Yusuf.  Glad you’re joining me once again.</b></p><p><b>We will go and demystify another one of those buzz word in the industry. It is SASE but before we get into that, lets start with some current security news. <br/><br/></b>- <a href='https://en.wikipedia.org/wiki/Secure_Access_Service_Edge'>Secure Access Service Edge (SASE)<b><br/></b></a>- <a href=' https://security.umbrella.com/esg-report-rise-of-dia'>The Rise of Direct Internet Access (DIA)</a><br/>- <a href='https://www.gartner.com/en/documents/3957375/invest-implications-the-future-of-network-security-is-in'>The Future of Network Security Is in the Cloud</a><br/><em>- </em><a href='https://www.schneier.com/blog/archives/2013/01/complexity_and.html'>Complexity versus Security</a><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>It is time for Yusuf On Security, I am your host Ibrahim Yusuf.  Glad you’re joining me once again.</b></p><p><b>We will go and demystify another one of those buzz word in the industry. It is SASE but before we get into that, lets start with some current security news. <br/><br/></b>- <a href='https://en.wikipedia.org/wiki/Secure_Access_Service_Edge'>Secure Access Service Edge (SASE)<b><br/></b></a>- <a href=' https://security.umbrella.com/esg-report-rise-of-dia'>The Rise of Direct Internet Access (DIA)</a><br/>- <a href='https://www.gartner.com/en/documents/3957375/invest-implications-the-future-of-network-security-is-in'>The Future of Network Security Is in the Cloud</a><br/><em>- </em><a href='https://www.schneier.com/blog/archives/2013/01/complexity_and.html'>Complexity versus Security</a><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8767606-21-secure-access-service-edge-sase.mp3" length="18548307" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8767606</guid>
    <pubDate>Sat, 26 Jun 2021 22:00:00 +0400</pubDate>
    <itunes:duration>1542</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>20 - DLP - Part 2</itunes:title>
    <title>20 - DLP - Part 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! We will continue ploughing through our second installment of Data Leak Prevent. We ask the question,  how  companies prevent data leaving their network in an unauthorized manner. Before we get into the second the part of the show, lets start with some current security news.   - WordPress force installs Jetpack security update on 5 million sites  - Most of Cisco Talos Incident Response’s engagements last quarter involved the exploitati...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We will continue ploughing through our second installment of Data Leak Prevent. We ask the question,  how  companies prevent data leaving their network in an unauthorized manner.</p><p>Before we get into the second the part of the show, lets start with some current security news. <br/><br/>- <a href='https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories/'>WordPress force installs Jetpack security update on 5 million sites</a><br/><br/><a href='https://blog.talosintelligence.com/2021/06/quarterly-report-incident-response.html'>- Most of Cisco Talos Incident Response’s engagements last quarter involved the exploitation (or attempted exploitation) of zero-day vulnerabilities in Microsoft Exchange Server disclosed earlier this year.</a><br/><br/><a href='https://www.bloomberg.com/news/articles/2021-06-04/hackers-breached-colonial-pipeline-using-compromised-password'>-Hackers Breached Colonial Pipeline Using Compromised Password</a><br/><br/><a href='https://en.wikipedia.org/wiki/S/MIME'>-SMIME</a><br/><br/>- <a href='https://en.wikipedia.org/wiki/Pretty_Good_Privacy'>PGP</a><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>We will continue ploughing through our second installment of Data Leak Prevent. We ask the question,  how  companies prevent data leaving their network in an unauthorized manner.</p><p>Before we get into the second the part of the show, lets start with some current security news. <br/><br/>- <a href='https://jetpack.com/2021/06/01/jetpack-9-8-engage-your-audience-with-wordpress-stories/'>WordPress force installs Jetpack security update on 5 million sites</a><br/><br/><a href='https://blog.talosintelligence.com/2021/06/quarterly-report-incident-response.html'>- Most of Cisco Talos Incident Response’s engagements last quarter involved the exploitation (or attempted exploitation) of zero-day vulnerabilities in Microsoft Exchange Server disclosed earlier this year.</a><br/><br/><a href='https://www.bloomberg.com/news/articles/2021-06-04/hackers-breached-colonial-pipeline-using-compromised-password'>-Hackers Breached Colonial Pipeline Using Compromised Password</a><br/><br/><a href='https://en.wikipedia.org/wiki/S/MIME'>-SMIME</a><br/><br/>- <a href='https://en.wikipedia.org/wiki/Pretty_Good_Privacy'>PGP</a><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8729878-20-dlp-part-2.mp3" length="20567635" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8729878</guid>
    <pubDate>Sat, 19 Jun 2021 23:00:00 +0400</pubDate>
    <itunes:duration>1710</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>19 - DLP - Part 1</itunes:title>
    <title>19 - DLP - Part 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today’s show we will look at data leak protection or as it is commonly known DLP. How should organization prevent data ending up into the wrong hands. I will cover the topic in two parts. We will kick off with part 1 today.  But first, we will start with some current security news.  - us-cert.cisa.gov: Unpatched VMware vCenter Software  - www.zdnet.com: Patch now: Attackers are hunting for this critical VMware vCentre flaw - arstechnica.com:...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s show we will look at data leak protection or as it is commonly known DLP. How should organization prevent data ending up into the wrong hands.<br/>I will cover the topic in two parts. We will kick off with part 1 today.<br/><br/>But first, we will start with some current security news. <br/><b>- </b><a href='https://us-cert.cisa.gov/ncas/current-activity/2021/06/04/unpatched-vmware-vcenter-software'><b>us-cert.cisa.gov</b></a>: Unpatched VMware vCenter Software<br/> <b>- </b><a href='https://www.zdnet.com/article/patch-now-attackers-are-hunting-for-this-critical-vmware-vcentre-flaw/'><b>www.zdnet.com</b></a>: Patch now: Attackers are hunting for this critical VMware vCentre flaw<br/><b>- </b><a href='https://arstechnica.com/gadgets/2021/06/us-seizes-2-3-million-colonial-pipeline-paid-to-ransomware-attackers/'><b>arstechnica.com</b></a>: US seizes $2.3 million Colonial Pipeline paid to ransomware attackers<br/><b>- </b><a href='https://www.justice.gov/opa/pr/department-justice-seizes-23-million-cryptocurrency-paid-ransomware-extortionists-darkside'><b>www.justice.gov</b></a>: Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside<br/><b>- </b><a href='https://www.bbc.com/news/world-57394831'><b>www.bbc.com</b></a>: ANOM: Hundreds arrested in massive global crime sting using messaging app<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s show we will look at data leak protection or as it is commonly known DLP. How should organization prevent data ending up into the wrong hands.<br/>I will cover the topic in two parts. We will kick off with part 1 today.<br/><br/>But first, we will start with some current security news. <br/><b>- </b><a href='https://us-cert.cisa.gov/ncas/current-activity/2021/06/04/unpatched-vmware-vcenter-software'><b>us-cert.cisa.gov</b></a>: Unpatched VMware vCenter Software<br/> <b>- </b><a href='https://www.zdnet.com/article/patch-now-attackers-are-hunting-for-this-critical-vmware-vcentre-flaw/'><b>www.zdnet.com</b></a>: Patch now: Attackers are hunting for this critical VMware vCentre flaw<br/><b>- </b><a href='https://arstechnica.com/gadgets/2021/06/us-seizes-2-3-million-colonial-pipeline-paid-to-ransomware-attackers/'><b>arstechnica.com</b></a>: US seizes $2.3 million Colonial Pipeline paid to ransomware attackers<br/><b>- </b><a href='https://www.justice.gov/opa/pr/department-justice-seizes-23-million-cryptocurrency-paid-ransomware-extortionists-darkside'><b>www.justice.gov</b></a>: Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside<br/><b>- </b><a href='https://www.bbc.com/news/world-57394831'><b>www.bbc.com</b></a>: ANOM: Hundreds arrested in massive global crime sting using messaging app<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8686915-19-dlp-part-1.mp3" length="21883580" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8686915</guid>
    <pubDate>Sat, 12 Jun 2021 00:00:00 +0400</pubDate>
    <itunes:duration>1820</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>18 - DNS Layer Security Part. 2</itunes:title>
    <title>18 - DNS Layer Security Part. 2</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! Good to meet you again. We will continue what we started last week. The critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security. But first, Lets have a look at has been trending since we met last.   - www.sonicwall.com: Security Advisory: On-Prem SonicWall Network Security Mana...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Good to meet you again. We will continue what we started last week. The critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security.<br/>But first, Lets have a look at has been trending since we met last. <br/><br/><b>- </b><a href='https://www.sonicwall.com/support/product-notification/security-advisory-on-prem-sonicwall-network-security-manager-nsm-command-injection-vulnerability/210525121534120/'><b>www.sonicwall.com</b></a>: Security Advisory: On-Prem SonicWall Network Security Manager (NSM) Command Injection Vulnerability<br/><br/><b>- </b><a href='https://www.govinfosecurity.com/fbi-to-share-compromised-passwords-have-i-been-pwned-a-16760'><b>www.govinfosecurity.com</b></a>: FBI to Share Compromised Passwords With Have I Been Pwned<br/><br/><b>- </b><a href='https://www.darkreading.com/threat-intelligence/have-i-been-pwned-code-base-now-open-source/d/d-id/1341156'><b>www.darkreading.com</b></a>: &apos;Have I Been Pwned&apos; Code Base Now Open Source<br/><br/>- <a href='https://www.computerweekly.com/feature/Why-securing-the-DNS-layer-is-crucial-to-fight-cyber-crime'>www.computerweekly.com:</a> Why securing the  DNS layer  is crucial to fight cyber crime<br/><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>Good to meet you again. We will continue what we started last week. The critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security.<br/>But first, Lets have a look at has been trending since we met last. <br/><br/><b>- </b><a href='https://www.sonicwall.com/support/product-notification/security-advisory-on-prem-sonicwall-network-security-manager-nsm-command-injection-vulnerability/210525121534120/'><b>www.sonicwall.com</b></a>: Security Advisory: On-Prem SonicWall Network Security Manager (NSM) Command Injection Vulnerability<br/><br/><b>- </b><a href='https://www.govinfosecurity.com/fbi-to-share-compromised-passwords-have-i-been-pwned-a-16760'><b>www.govinfosecurity.com</b></a>: FBI to Share Compromised Passwords With Have I Been Pwned<br/><br/><b>- </b><a href='https://www.darkreading.com/threat-intelligence/have-i-been-pwned-code-base-now-open-source/d/d-id/1341156'><b>www.darkreading.com</b></a>: &apos;Have I Been Pwned&apos; Code Base Now Open Source<br/><br/>- <a href='https://www.computerweekly.com/feature/Why-securing-the-DNS-layer-is-crucial-to-fight-cyber-crime'>www.computerweekly.com:</a> Why securing the  DNS layer  is crucial to fight cyber crime<br/><br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8649778-18-dns-layer-security-part-2.mp3" length="16425165" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8649778</guid>
    <pubDate>Mon, 07 Jun 2021 00:00:00 +0400</pubDate>
    <itunes:duration>1365</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>18</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>17 - DNS Layer Security Part. 1</itunes:title>
    <title>17 - DNS Layer Security Part. 1</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! I hope you all had a fantastic week. Today we turn our eyes to a critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security. But firrst lets review the week's most notable security events and news.  - support.apple.com: Apple security updates - www.theregister.com: Air India admit...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>I hope you all had a fantastic week. Today we turn our eyes to a critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security. But firrst lets review the week&apos;s most notable security events and news.<br/><br/>- </b><a href='https://support.apple.com/en-us/HT201222'><b>support.apple.com</b></a>: Apple security updates<br/><b>- </b><a href='https://www.theregister.com/2021/05/24/air_india_sita_data_breach/'><b>www.theregister.com</b></a>: Air India admits to data breach impacting 4.5m customers, sat on the news for five weeks<br/><b>- </b><a href='https://www.securityweek.com/tulsa-computer-system-hacks-stopped-security-shutdown'><b>www.securityweek.com</b></a>: Tulsa Computer System Hacks Stopped by Security Shutdown<br/><b>- </b><a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/internet-explorer-11-desktop-app-retirement-faq/ba-p/2366549'><b>techcommunity.microsoft.com</b></a>: Internet Explorer 11 desktop app retirement FAQ<br/><b>- </b><a href='https://www.zdnet.com/article/fbi-identifies-16-conti-ransomware-attacks-striking-us-healthcare-first-responders/'><b>www.zdnet.com</b></a>: FBI identifies 16 Conti ransomware attacks striking US healthcare, first responders<br/>- <a href='https://www.computerweekly.com/feature/Why-securing-the-DNS-layer-is-crucial-to-fight-cyber-crime'>www.computerweekly.com:</a> Why securing the  DNS layer  is crucial to fight cyber crime<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><b>I hope you all had a fantastic week. Today we turn our eyes to a critical part of the Internet infrastructure where security can be delivered effectively and in return this allows organization to mitigate attacks at an early stage. In this two part series we will discuss DNS Layer Security. But firrst lets review the week&apos;s most notable security events and news.<br/><br/>- </b><a href='https://support.apple.com/en-us/HT201222'><b>support.apple.com</b></a>: Apple security updates<br/><b>- </b><a href='https://www.theregister.com/2021/05/24/air_india_sita_data_breach/'><b>www.theregister.com</b></a>: Air India admits to data breach impacting 4.5m customers, sat on the news for five weeks<br/><b>- </b><a href='https://www.securityweek.com/tulsa-computer-system-hacks-stopped-security-shutdown'><b>www.securityweek.com</b></a>: Tulsa Computer System Hacks Stopped by Security Shutdown<br/><b>- </b><a href='https://techcommunity.microsoft.com/t5/windows-it-pro-blog/internet-explorer-11-desktop-app-retirement-faq/ba-p/2366549'><b>techcommunity.microsoft.com</b></a>: Internet Explorer 11 desktop app retirement FAQ<br/><b>- </b><a href='https://www.zdnet.com/article/fbi-identifies-16-conti-ransomware-attacks-striking-us-healthcare-first-responders/'><b>www.zdnet.com</b></a>: FBI identifies 16 Conti ransomware attacks striking US healthcare, first responders<br/>- <a href='https://www.computerweekly.com/feature/Why-securing-the-DNS-layer-is-crucial-to-fight-cyber-crime'>www.computerweekly.com:</a> Why securing the  DNS layer  is crucial to fight cyber crime<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/>You will find a list of all previous episodes in there too.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8610278-17-dns-layer-security-part-1.mp3" length="16007937" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8610278</guid>
    <pubDate>Sat, 29 May 2021 23:00:00 +0400</pubDate>
    <itunes:duration>1330</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>17</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>16 - The Ransomware Task Force Recommendations</itunes:title>
    <title>16 - The Ransomware Task Force Recommendations</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today’s episode we will discuss recommendations put forward by a task force setup to combat the surge of ransomware attacks.   - us-cert.cisa.gov: Eviction Guidance for Networks Affected by the SolarWinds and Active Directory/M365 Compromise www.bleepingcomputer.com: Insurer AXA hit by ransomware after dropping support for ransom payments - www.securityweek.com: AXA Confirms Ransomware Attack Impacted Operations in Asia - arstechnica.com: Pi...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s episode we will discuss recommendations put forward by a task force setup to combat the surge of ransomware attacks. <br/><br/><b>- </b><a href='https://us-cert.cisa.gov/ncas/analysis-reports/ar21-134a'><b>us-cert.cisa.gov</b></a>: Eviction Guidance for Networks Affected by the SolarWinds and Active Directory/M365 Compromise<br/><a href='https://www.bleepingcomputer.com/news/security/insurer-axa-hit-by-ransomware-after-dropping-support-for-ransom-payments/'><b>www.bleepingcomputer.com</b></a>: Insurer AXA hit by ransomware after dropping support for ransom payments<br/><b>- </b><a href='https://www.securityweek.com/axa-confirms-ransomware-attack-impacted-operations-asia'><b>www.securityweek.com</b></a>: AXA Confirms Ransomware Attack Impacted Operations in Asia<br/><b>- </b><a href='https://arstechnica.com/gadgets/2021/05/pipeline-attacker-darkside-suddenly-goes-dark-heres-what-we-know/'><b>arstechnica.com</b></a>: Pipeline attacker DarkSide suddenly goes dark—here’s what we know<br/><b>- </b><a href='https://www.gov.uk/government/news/new-plans-to-boost-cyber-resilience-of-uks-critical-supply-chains'><b>www.gov.uk</b></a>: New plans to boost cyber resilience of UK’s critical supply chains<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s episode we will discuss recommendations put forward by a task force setup to combat the surge of ransomware attacks. <br/><br/><b>- </b><a href='https://us-cert.cisa.gov/ncas/analysis-reports/ar21-134a'><b>us-cert.cisa.gov</b></a>: Eviction Guidance for Networks Affected by the SolarWinds and Active Directory/M365 Compromise<br/><a href='https://www.bleepingcomputer.com/news/security/insurer-axa-hit-by-ransomware-after-dropping-support-for-ransom-payments/'><b>www.bleepingcomputer.com</b></a>: Insurer AXA hit by ransomware after dropping support for ransom payments<br/><b>- </b><a href='https://www.securityweek.com/axa-confirms-ransomware-attack-impacted-operations-asia'><b>www.securityweek.com</b></a>: AXA Confirms Ransomware Attack Impacted Operations in Asia<br/><b>- </b><a href='https://arstechnica.com/gadgets/2021/05/pipeline-attacker-darkside-suddenly-goes-dark-heres-what-we-know/'><b>arstechnica.com</b></a>: Pipeline attacker DarkSide suddenly goes dark—here’s what we know<br/><b>- </b><a href='https://www.gov.uk/government/news/new-plans-to-boost-cyber-resilience-of-uks-critical-supply-chains'><b>www.gov.uk</b></a>: New plans to boost cyber resilience of UK’s critical supply chains<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8563541-16-the-ransomware-task-force-recommendations.mp3" length="20694962" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8563541</guid>
    <pubDate>Sat, 22 May 2021 01:00:00 +0400</pubDate>
    <itunes:duration>1720</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>15 - PCI DSS</itunes:title>
    <title>15 - PCI DSS</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In today’s show we will plough through The PCI DSS, the global payment account data security standard ; but first lets begin with current industry security news.  - msrc.microsoft.com: Security Update Guide -  www.bloomberg.com: Colonial Pipeline Paid Hackers Nearly $5 Million in Ransom -  www.rapid7.com: Rapid7’s Response to Codecov Incident - PCI DSS Requirement: The twelve requirements for building and maintaining a secure network ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s show we will plough through The PCI DSS, the global payment account data security standard ; but first lets begin with current industry security news.<br/><br/><b>- </b><a href='https://msrc.microsoft.com/update-guide/vulnerability'><b>msrc.microsoft.com</b></a>: Security Update Guide<br/><b>-  </b><a href='https://www.bloomberg.com/news/articles/2021-05-13/colonial-pipeline-paid-hackers-nearly-5-million-in-ransom'><b>www.bloomberg.com</b></a>: Colonial Pipeline Paid Hackers Nearly $5 Million in Ransom<br/><b>-  </b><a href='https://www.rapid7.com/blog/post/2021/05/13/rapid7s-response-to-codecov-incident/'><b>www.rapid7.com</b></a>: Rapid7’s Response to Codecov Incident<br/>- <a href='https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard#Requirements'>PCI DSS Requirement: </a>The twelve requirements for building and maintaining a secure network and systems<br/>-<a href='https://www.cyberark.com/resources/blog/breaking-down-the-codecov-attack-finding-a-malicious-needle-in-a-code-haystack'>Braking Codecov</a>:  Breaking Down the Codecov Attack: Finding a Malicious Needle in a Code Haystack<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In today’s show we will plough through The PCI DSS, the global payment account data security standard ; but first lets begin with current industry security news.<br/><br/><b>- </b><a href='https://msrc.microsoft.com/update-guide/vulnerability'><b>msrc.microsoft.com</b></a>: Security Update Guide<br/><b>-  </b><a href='https://www.bloomberg.com/news/articles/2021-05-13/colonial-pipeline-paid-hackers-nearly-5-million-in-ransom'><b>www.bloomberg.com</b></a>: Colonial Pipeline Paid Hackers Nearly $5 Million in Ransom<br/><b>-  </b><a href='https://www.rapid7.com/blog/post/2021/05/13/rapid7s-response-to-codecov-incident/'><b>www.rapid7.com</b></a>: Rapid7’s Response to Codecov Incident<br/>- <a href='https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard#Requirements'>PCI DSS Requirement: </a>The twelve requirements for building and maintaining a secure network and systems<br/>-<a href='https://www.cyberark.com/resources/blog/breaking-down-the-codecov-attack-finding-a-malicious-needle-in-a-code-haystack'>Braking Codecov</a>:  Breaking Down the Codecov Attack: Finding a Malicious Needle in a Code Haystack<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8525054-15-pci-dss.mp3" length="26797829" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8525054</guid>
    <pubDate>Sun, 16 May 2021 18:00:00 +0400</pubDate>
    <itunes:duration>2229</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>14 - Zero Trust</itunes:title>
    <title>14 - Zero Trust</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will recap recent noteworthy news and then finish the show with demystifying a rather over used buzz word in security, it is Zero Trust.  Google nudges their users to adopt 2FA - blog.google: A simpler and safer future — without passwords - www.vice.com: Google Wants to Make Everyone Use Two Factor Authentication - www.bleepingcomputer.com: Google wants to enable multi-factor authentication by default - www.bleepingcomputer.c...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will recap recent noteworthy news and then finish the show with demystifying a rather over used buzz word in security, it is Zero Trust.<br/><br/><b>Google nudges their users to adopt 2FA</b></p><p><b>- </b><a href='https://blog.google/technology/safety-security/a-simpler-and-safer-future-without-passwords'><b>blog.google</b></a>: A simpler and safer future — without passwords<br/><b>- </b><a href='https://www.vice.com/en/article/93yyqe/google-wants-to-make-everyone-use-two-factor-authentication'><b>www.vice.com</b></a>: Google Wants to Make Everyone Use Two Factor Authentication<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/google-wants-to-enable-multi-factor-authentication-by-default/'><b>www.bleepingcomputer.com</b></a>: Google wants to enable multi-factor authentication by default<br/>-<a href='https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/'> www.bleepingcomputer.com</a>:  Largest U.S. pipeline shuts down operations after ransomware attack</p><p><b>Exim Server</b> <br/><b>- </b><a href='https://www.exim.org/'><b>www.exim.org</b></a>: Latest Version: 4.94.2<br/><b>- </b><a href='https://www.theregister.com/2021/05/05/21_nails_in_exim_mail/'><b>www.theregister.com</b></a>: 21 nails in Exum mail server: Vulnerabilities enable &apos;full remote unauthenticated code execution&apos;, millions of boxes at risk<br/><b>- </b><a href='https://www.scmagazine.com/home/security-news/vulnerabilities/21-vulnerabilities-in-exim-mail-server-leave-web-cloud-operations-exposed/'><b>www.scmagazine.com</b></a>: 21 vulnerabilities in Exim mail server leave web, cloud operations exposed<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will recap recent noteworthy news and then finish the show with demystifying a rather over used buzz word in security, it is Zero Trust.<br/><br/><b>Google nudges their users to adopt 2FA</b></p><p><b>- </b><a href='https://blog.google/technology/safety-security/a-simpler-and-safer-future-without-passwords'><b>blog.google</b></a>: A simpler and safer future — without passwords<br/><b>- </b><a href='https://www.vice.com/en/article/93yyqe/google-wants-to-make-everyone-use-two-factor-authentication'><b>www.vice.com</b></a>: Google Wants to Make Everyone Use Two Factor Authentication<br/><b>- </b><a href='https://www.bleepingcomputer.com/news/security/google-wants-to-enable-multi-factor-authentication-by-default/'><b>www.bleepingcomputer.com</b></a>: Google wants to enable multi-factor authentication by default<br/>-<a href='https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/'> www.bleepingcomputer.com</a>:  Largest U.S. pipeline shuts down operations after ransomware attack</p><p><b>Exim Server</b> <br/><b>- </b><a href='https://www.exim.org/'><b>www.exim.org</b></a>: Latest Version: 4.94.2<br/><b>- </b><a href='https://www.theregister.com/2021/05/05/21_nails_in_exim_mail/'><b>www.theregister.com</b></a>: 21 nails in Exum mail server: Vulnerabilities enable &apos;full remote unauthenticated code execution&apos;, millions of boxes at risk<br/><b>- </b><a href='https://www.scmagazine.com/home/security-news/vulnerabilities/21-vulnerabilities-in-exim-mail-server-leave-web-cloud-operations-exposed/'><b>www.scmagazine.com</b></a>: 21 vulnerabilities in Exim mail server leave web, cloud operations exposed<br/><br/>Be sure to subscribe!<br/><br/>If you like the content. Follow me @iayusuf or read my blog at https://yusufonsecurity.com<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8481508-14-zero-trust.mp3" length="19167990" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8481508</guid>
    <pubDate>Sat, 08 May 2021 23:00:00 +0400</pubDate>
    <itunes:duration>1593</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>14</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>13 - What is Threat Hunting?</itunes:title>
    <title>13 - What is Threat Hunting?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback!  In this episode we will go over a rather popular topic in security, it is Threat Hunting.  Here are a number of places where you can read more about Emotet:  - https://blog.talosintelligence.com/2019/01/return-of-emotet.html  - www.theregister.com: Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs  - www.scmagazine.com: Following similar move in US, Europol prepares coup de gras for Emotet’s remains Be sure...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><br/>In this episode we will go over a rather popular topic in security, it is Threat Hunting.<br/><br/>Here are a number of places where you can read more about Emotet:<br/><br/>- https://blog.talosintelligence.com/2019/01/return-of-emotet.html<br/><br/><b>- </b><a href='https://www.theregister.com/2021/04/26/emotet_sunday_25_april_killswitch_date/'><b>www.theregister.com</b></a>: Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs<br/> <b>- </b><a href='https://www.scmagazine.com/home/security-news/malware/following-similar-move-in-us-europol-prepares-coup-de-gras-for-emotets-remains/'><b>www.scmagazine.com</b></a>: Following similar move in US, Europol prepares coup de gras for Emotet’s remains</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p><br/>In this episode we will go over a rather popular topic in security, it is Threat Hunting.<br/><br/>Here are a number of places where you can read more about Emotet:<br/><br/>- https://blog.talosintelligence.com/2019/01/return-of-emotet.html<br/><br/><b>- </b><a href='https://www.theregister.com/2021/04/26/emotet_sunday_25_april_killswitch_date/'><b>www.theregister.com</b></a>: Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs<br/> <b>- </b><a href='https://www.scmagazine.com/home/security-news/malware/following-similar-move-in-us-europol-prepares-coup-de-gras-for-emotets-remains/'><b>www.scmagazine.com</b></a>: Following similar move in US, Europol prepares coup de gras for Emotet’s remains</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8439120-13-what-is-threat-hunting.mp3" length="14702331" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8439120</guid>
    <pubDate>Sun, 02 May 2021 02:00:00 +0400</pubDate>
    <itunes:duration>1221</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>12 - The Changing Face Of Ransomware</itunes:title>
    <title>12 - The Changing Face Of Ransomware</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will start with some current news which you may find interesting and will continue with the topic du jour: The Changing Face Of Rasomware Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will start with some current news which you may find interesting and will continue with the topic du jour: The Changing Face Of Rasomware</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will start with some current news which you may find interesting and will continue with the topic du jour: The Changing Face Of Rasomware</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8398701-12-the-changing-face-of-ransomware.mp3" length="19478681" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8398701</guid>
    <pubDate>Tue, 27 Apr 2021 09:00:00 +0400</pubDate>
    <itunes:duration>1619</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>11 - 2FA</itunes:title>
    <title>11 - 2FA</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we begin with a current news which you may find interesting. You might agree or disagree with the topic but it important to see where this leads. As always as the topic of the show, we will cover why you should not login to you important sites, storage or applications with one single factor. I’ll explain what I mean. Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a ...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we begin with a current news which you may find interesting. You might agree or disagree with the topic but it important to see where this leads.<br/>As always as the topic of the show, we will cover why you should not login to you important sites, storage or applications with one single factor. I’ll explain what I mean.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we begin with a current news which you may find interesting. You might agree or disagree with the topic but it important to see where this leads.<br/>As always as the topic of the show, we will cover why you should not login to you important sites, storage or applications with one single factor. I’ll explain what I mean.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8351313-11-2fa.mp3" length="18079611" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8351313</guid>
    <pubDate>Sat, 17 Apr 2021 17:00:00 +0400</pubDate>
    <itunes:duration>1503</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>10 - SMTP Authentication Protocols</itunes:title>
    <title>10 - SMTP Authentication Protocols</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover the SMTP Authentication Protocols. I think you will agree this is a just in time and topical subject. Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the SMTP Authentication Protocols. I think you will agree this is a just in time and topical subject.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the SMTP Authentication Protocols. I think you will agree this is a just in time and topical subject.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8308746-10-smtp-authentication-protocols.mp3" length="16743970" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8308746</guid>
    <pubDate>Sat, 10 Apr 2021 21:00:00 +0400</pubDate>
    <itunes:duration>1391</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>09 - Dynamic Malware Analysis</itunes:title>
    <title>09 - Dynamic Malware Analysis</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover the process of Dynamic Malware analysis. Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the process of Dynamic Malware analysis.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the process of Dynamic Malware analysis.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8275834-09-dynamic-malware-analysis.mp3" length="13728071" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8275834</guid>
    <pubDate>Mon, 05 Apr 2021 21:00:00 +0400</pubDate>
    <itunes:duration>1140</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>08 - IR</itunes:title>
    <title>08 - IR</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover the process of IR - Incident Response.   Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the process of IR - Incident Response.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the process of IR - Incident Response.<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8222324-08-ir.mp3" length="11100840" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8222324</guid>
    <pubDate>Sat, 27 Mar 2021 23:00:00 +0400</pubDate>
    <itunes:duration>921</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>07 - The MITRE ATT&amp;CK Framework</itunes:title>
    <title>07 - The MITRE ATT&amp;CK Framework</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover the The MITRE ATT&amp;CK Framework, a framework that digs deep on how the cyber crooks behave when doing their bad deed. Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the The MITRE ATT&amp;CK Framework, a framework that digs deep on how the cyber crooks behave when doing their bad deed.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the The MITRE ATT&amp;CK Framework, a framework that digs deep on how the cyber crooks behave when doing their bad deed.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8204246-07-the-mitre-att-ck-framework.mp3" length="14770360" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8204246</guid>
    <pubDate>Wed, 24 Mar 2021 22:00:00 +0400</pubDate>
    <itunes:duration>1227</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>06 - Hafnium</itunes:title>
    <title>06 - Hafnium</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover the recently discovered Microsoft Exchange exploits. These are so serious that Microsoft has taken immediate action to help the industry. Lets get into these! Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the recently discovered Microsoft Exchange exploits. These are so serious that Microsoft has taken immediate action to help the industry. Lets get into these!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the recently discovered Microsoft Exchange exploits. These are so serious that Microsoft has taken immediate action to help the industry. Lets get into these!</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8133246-06-hafnium.mp3" length="12037183" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8133246</guid>
    <pubDate>Sat, 13 Mar 2021 21:00:00 +0400</pubDate>
    <itunes:duration>999</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>05 - Encrypting  Your Data</itunes:title>
    <title>05 - Encrypting  Your Data</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover encryption. We often hear encryption and in particular encryption on data at rest. What is it good for and what are the different type of encryptions typical organization use. Where are these different type of encryption usually used and how?  Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover encryption. We often hear encryption and in particular encryption on data at rest. What is it good for and what are the different type of encryptions typical organization use. Where are these different type of encryption usually used and how? </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover encryption. We often hear encryption and in particular encryption on data at rest. What is it good for and what are the different type of encryptions typical organization use. Where are these different type of encryption usually used and how? </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8092193-05-encrypting-your-data.mp3" length="11789883" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8092193</guid>
    <pubDate>Sun, 07 Mar 2021 17:00:00 +0400</pubDate>
    <itunes:duration>978</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>04. Deception Attacks</itunes:title>
    <title>04. Deception Attacks</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! This is a follow up episode to our "Anatomy Of A Phishing Attack" episode. You might want to listen to that episode first.  In this episode we will cover email deception attacks and why this is so successful than you might think. What are the different highly used tactics the bad guys use to  to lure people in and take out of their perimeter protections. As always I will sprinkles with suggestions of what you take care of to protect y...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is a follow up episode to our &quot;Anatomy Of A Phishing Attack&quot; episode. You might want to listen to that episode first. <br/>In this episode we will cover email deception attacks and why this is so successful than you might think.<br/>What are the different highly used tactics the bad guys use to  to lure people in and take out of their perimeter protections. As always I will sprinkles with suggestions of what you take care of to protect yourselves against these types of attacks.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>This is a follow up episode to our &quot;Anatomy Of A Phishing Attack&quot; episode. You might want to listen to that episode first. <br/>In this episode we will cover email deception attacks and why this is so successful than you might think.<br/>What are the different highly used tactics the bad guys use to  to lure people in and take out of their perimeter protections. As always I will sprinkles with suggestions of what you take care of to protect yourselves against these types of attacks.</p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/8044903-04-deception-attacks.mp3" length="13424303" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-8044903</guid>
    <pubDate>Sun, 28 Feb 2021 21:00:00 +0400</pubDate>
    <itunes:duration>1115</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>03. The Last Line Of Defense</itunes:title>
    <title>03. The Last Line Of Defense</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will cover the last line of defense of any organisation, why it is so important today than ever, what to take into consideration for an effective endpoint telemetry. Is it really the center of an effective cyber hygiene? Join me to find out if it is!   Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the last line of defense of any organisation, why it is so important today than ever, what to take into consideration for an effective endpoint telemetry. Is it really the center of an effective cyber hygiene? Join me to find out if it is!<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will cover the last line of defense of any organisation, why it is so important today than ever, what to take into consideration for an effective endpoint telemetry. Is it really the center of an effective cyber hygiene? Join me to find out if it is!<br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/7980442-03-the-last-line-of-defense.mp3" length="12156647" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-7980442</guid>
    <pubDate>Sat, 20 Feb 2021 22:00:00 +0400</pubDate>
    <itunes:duration>1009</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>02. Your Adversary Is In, Now What?</itunes:title>
    <title>02. Your Adversary Is In, Now What?</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode of we will dive into a topic that might be the worst nightmare of any security analyst. When you face your opponent, what do you do. What are the realities that organisations are facing today, big or small? What do bad guys or girls do when they breach an organisation’s defences? We will cover all that and some key take aways in the end.  Be sure to subscribe!   You can also stream from https://yusufonsecurity.com...]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode of we will dive into a topic that might be the worst nightmare of any security analyst. When you face your opponent, what do you do. What are the realities that organisations are facing today, big or small? What do bad guys or girls do when they breach an organisation’s defences? We will cover all that and some key take aways in the end. </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode of we will dive into a topic that might be the worst nightmare of any security analyst. When you face your opponent, what do you do. What are the realities that organisations are facing today, big or small? What do bad guys or girls do when they breach an organisation’s defences? We will cover all that and some key take aways in the end. </p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/7844764-02-your-adversary-is-in-now-what.mp3" length="10221614" type="audio/mpeg" />
    <itunes:author>Yusuf</itunes:author>
    <guid isPermaLink="false">Buzzsprout-7844764</guid>
    <pubDate>Sat, 13 Feb 2021 20:00:00 +0400</pubDate>
    <itunes:duration>848</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>01. Anatomy Of A Phishing Attack</itunes:title>
    <title>01. Anatomy Of A Phishing Attack</title>
    <itunes:summary><![CDATA[Enjoying the content? Let us know your feedback! In this episode we will look at Phishing. How it is executed and what  are the different steps involved.    Be sure to subscribe!   You can also stream from https://yusufonsecurity.com In there, you will find a list of all previous episodes in there too. ]]></itunes:summary>
    <description><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will look at Phishing. How it is executed and what  are the different steps involved. <br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></description>
    <content:encoded><![CDATA[<p><a target="_blank" href="https://www.buzzsprout.com/1673686/fan_mail/new">Enjoying the content? Let us know your feedback!</a></p><p>In this episode we will look at Phishing. How it is executed and what  are the different steps involved. <br/><br/></p><p>Be sure to subscribe!  <br/>You can also stream from <a href='https://yusufonsecurity.com'>https://yusufonsecurity.com</a><br/>In there, you will find a list of all previous episodes in there too.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1673686/episodes/7712212-01-anatomy-of-a-phishing-attack.mp3" length="4381991" type="audio/mpeg" />
    <itunes:author>Ibrahim</itunes:author>
    <guid isPermaLink="false">Buzzsprout-7712212</guid>
    <pubDate>Sat, 06 Feb 2021 23:00:00 +0400</pubDate>
    <itunes:duration>361</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
