Paul's Security Weekly (Video)

Paul's Security Weekly (Video)

Paul Asadoorian
País Estados Unidos
Idioma EN
Episodios 1208
Último 10.09.2026

Where security veterans unpack the latest IT security news, vulnerabilities, and research through a historical and technical lens that can cut through even the thickest cigar smoke. Hosted by Paul Asadoorian and Larry Pesce. Co-hosts: Josh Marpet, Jeff Man, Mandy Logan, Tyler Robinson.

Episodios

  • It's More Secure When It's Disabled - PSW #943 10.09.2026 2h 2m
    In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kworker, but make it malware FortiGate gets a post-exploitation RAT CERN goes Debian underground UEFI shells strike again Australia loses the plot, and phones Cisco routers become covert gateways MikroTik patches the takeover chain WeWorm wriggles through mobile The year of Linux television Browsers become backdoors Fake IT calls, real data theft CVE attribution gets weird Boston Scientific keeps talking Security tools misconfigure themselves AI circuit breakers for rogue agents Passkeys meet the real world Vibe coding, vibe vulnerabilities AI loss of control keeps climbing AI agents report themselves to Schneier Show Notes: https://securityweekly.com/psw-943
  • Linux Threat Hunting - PSW #942 03.09.2026 2h 12m
    First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week: SonicWall zero-days, again AI finds a pile of Cisco bugs, and a root RCE Claude Code Auto Mode dangers BGP hijacks your unsigned software update California, Linux and age verification Free movies, complimentary malware Citrix puts Linux alongside Windows Signal's "secure" enclave An expired domain answers military phone calls MORE Cheap Android TV boxes arrive pre-pwned CISA red teams meet critical infrastructure PaperCut vulnerability cuts both ways Big Tech asks everyone to secure its AI future Pacemaker monitoring DOJ files on a criminal leak site Water utility security, right after the breaches Show Notes: https://securityweekly.com/psw-942
  • Hacking All The Devices, with AI? - Rob Allen - PSW #941 27.08.2026 2h 6m
    Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the security news this week: Sixteen-year-old Linux LPEs still work Ubiquiti UniFi, patch it, also light on details If you remember magicJack, you too are old Slovakia doesn't trust its own speed cameras More homework on NIST's vulnerability database Your webcam, mic, and key light, all owned Printer moonlights as Minecraft server Zombie credit cards Your car's infotainment system fuels botnets Feds warn about AI-powered PLC attacks Can an AI actually reverse engineer its way out? Denver International's security breach, volume six Charlotte's breach and a parking company Why your ancient tech might be the safe one Microsoft counts billions of phishing emails A password vault that leaked to any website Australia sells password books at the post office Another perfect ten, this time in Entra ID Cisco's bug scores read like Olympic gymnastics Show Notes: https://securityweekly.com/psw-941
  • Rejoice In The Nostalgia - PSW #940 20.08.2026 2h 8m
    In the security news this week: Cursor opens your repo, the repo opens you If you want the good model I'm going to need to see your ID Flock's a Flocking mess Defender was supposed to be the chosen one Side stepping Secure boot - twice SonicWall: a LAMP stack in a fancy case Macs don't get viruses, part infinity Flipper One, but why not Nix? NetScaler is back in the room Borrowing phone's good reputation USB and how to make Windows download stuff A KVM with the expensive letters removed Five steps to stop the webcam creeps PlexTrac acquired NIST asks the internet to fix the NVD Poland's health software has a very bad week If Apple pings you about spyware, believe it A macOS stealer that drives your browser for you T-Mobile's incident response tool of choice may suprise you, or not... Show Notes: https://securityweekly.com/psw-940
  • The Breached WiFi AI Ports... What? - PSW #939 13.08.2026 2h 4m
    In the security news this week: • North Carolina ports and contingency plans • Back to paper and pencils • Midnight Blizzard compromises hotel Wi-Fi • DNS strikes again • Captive portals, stolen credentials, and nation-state scale • Phishing-resistant MFA • Goodbye SMS and voice authentication • Cornflake RAT and Chaco Shell • The NPM worm • Hundreds of compromised packages • AI lowers the barrier to mass exploitation • Rethinking "secure enough" • Back to basics: know what's on your network • Get off my PCI lawn Show Notes: https://securityweekly.com/psw-939
  • When AI Commits Felonies - PSW #938 06.08.2026 1h 58m
    This week: When you are not at summer camp you can't read about it The Fettle continues Using the CFAA against AI Social contracts are not security models VSCode extentions, again Bugtraq is back! NVIDA, LVFS, and unraveling AI infrastructure More routers that come with backdoors Do we care about LPE? Even more AI that finds vulnerabilities When AI breaks its own guardtails Show Notes: https://securityweekly.com/psw-938
  • Sandwich Hats - PSW #937 30.07.2026 2h 5m
    In the security news: 2.2 million cars, one shared Bluetooth key JFrog tries to spin an AI 0-day into a win Sextortion scammers recycling ShinyHunters' leaks The first hack ever, from 1966 Prompt injection as a service, $150 a month Cisco's mystery "static credential" BMCs still on the internet, still handing out hashes Scattered Spider duo sentenced over the TfL hack Air-gapped data sneaking out over the video cable A ghost in the network DNS poisoning checks into hotel WiFi Microsoft's cut-rate cybersecurity AI Learning to trust USB drives again Agentic pentesting shows up just in time for Black Hat Microsoft rethinks security for the AI age, again Show Notes: https://securityweekly.com/psw-937
  • Fixing Vulns Is Harder Than Finding Them - PSW #936 23.07.2026 2h 2m
    In the news this week: InfraTrust and knowing what to patch Adversary in the middle triggered command injection Exploitarium again FreeRDP comes with free vulnerabilities AI breaking out of sandboxes on its own Wordpress RCE DMA dangers Nightmware eclypse is at it again Fortisandbox Turning AI to the dark side more prompt injection Secure boot is broken, still and again... Show Notes: https://securityweekly.com/psw-936
  • 1999 Called and It Wants It's Exploits Back - PSW #935 16.07.2026 2h 11m
    This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously discussed! Then in the security news: The GodDamn Ransomware CMMC suspended Holy Microsoft Tuesday! Lessons learned Without the Internet, do we still get water? The forgotten shims More than two BIOS passwords Cracking firmware encryption with Claude 1999 called, and it wants its "Exploits" back Prompt injection for defenders Grok has your repo You're not going to outpatch AI Show Notes: https://securityweekly.com/psw-935
  • AI Is Annoying & IoT Devices Still Get Hacked - PSW #934 09.07.2026 2h 5m
    In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV's Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabilities Citrix just keeps bleeding Old hardware is new again A sneak peak into next week's tech segment Tenda hidden backdoors We're still talking about Mirai Today was not a good day for Roundcube Canada is hacking criminals AI safeguards are still annnoying All cars will spy on you The FatFs unpatched vulnerability in millions of embedded devices Windows OS market share drops below 60% (Paul uses Arch) 'We Cannot Choose to Become Idiots' - or can we? Show Notes: https://securityweekly.com/psw-934
  • Linux Tech Segment & Vulnerabilities Galore - PSW #933 02.07.2026 2h 9m
    This week we have a technical segment based on the response to "Atomic Arch", an updated open-source tool to help you catch malicious packages. In the security news: Exploitarium A hot messy summer of vulnerabilities AI Squatting Linux LPE - no shortage of those Fingerprinting Favicons Windows 10 extended Can Clothes Make You Invisible to Facial Recognition? Fable and Mythos for All Do we care about Quantum? Execs have AI risk under control Biological warefare in Spyware The scripts in-scope for PCI We don't have privacy, but we may get age restrictions Show Notes: https://securityweekly.com/psw-933
  • Cloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #932 25.06.2026 2h 13m
    First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure! This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Next up in the security news: Help, I am Fortibleeding Cisco SD-WAN needs help The secret life of probe requests Help, I am Squidbleeding XSS to RCE and why CVSS isn't the full picture TVs spy on you Foundational security practices Cybersecurity costs money Happy "Its too late to update your KEK key" day You don't have security flaws if no one can report them Rickrolling FIFA Domain takeovers End of life, out of luck The key to Encryption... Show Notes: https://securityweekly.com/psw-932
  • GPS, PCI, ARCH, OH MY! - PSW #931 18.06.2026 2h 6m
    In the security news this week: GPS spoofing and satellite jamming are getting way too accessible Rekeying satellites in orbit sounds terrifying Cyber extortion and whether criminals still have ethics AI helping cybersecurity research... and drug discovery Data centers eating regional power grids Nuclear, solar, natural gas, and the future of AI infrastructure What happens when GPS stops being trustworthy? Satellite constellations as the next critical infrastructure target AI guardrails and why sci-fi warned us first Cyber ranges that don't simulate reality anymore The weird morality line between hackers, scammers, and criminals Future satellite warfare without calling it warfare Security standards for infrastructure nobody thought would be online Historical cybersecurity stories that suddenly feel very current Why AI changes both offense and defense simultaneously And how much of modern cyber defense is just educated guessing Show Notes: https://securityweekly.com/psw-931
  • Trolling Microsoft With Vulnerabilities - PSW #930 11.06.2026 2h 2m
    In the security news: Trolling Microsoft With Vulnerabilities Fable 5 loves guardrails Binwalk vulnerability EMBA and local models EDRChoker AI worms Interesting Arista vulnerability added to KEV BOD 26-04 and stakeholder specific vulnerability categorization Bring your own execution environment Homelab tips MikroTik routers as interceptors Ivanti Sentry and irony Smart TV botnets Privacy laws Solarwinds Serv-U lives on More Cisco SD-WAN fun! Russia can jam GPS No nudes for you says UK Government "Why would someone want to learn code when AI does it better and faster?" Show Notes: https://securityweekly.com/psw-930
  • Security Researchers Are Threat Actors - PSW #929 04.06.2026 2h 1m
    This week in the security news: Security Researchers Are Threat Actors according to Microsoft Hands-free malicious firmware If you've ever typed "ls" in Windows, this is for you Cisco makes more patches, wants you to pay Ambiguous Secure Boot bypass Threat actors love network edge devices, and I have the chat logs and leaks to prove it The downside of chip sanctions Your VoIP phone is hacked Vulnerability disclosure and incentives Claude reccovers Bitcoin wallet an Instagram "Exploit" Turn the plane around The worms will continue PAN-OS global protect vulnerability The 1-Click Github token stealer Data-nuking prompt injection Turning Buses into spies SymJack NIST NVD mistakes, and how CNAs need to up their game Show Notes: https://securityweekly.com/psw-929
  • Linux Supply Chain How-To - PSW #928 28.05.2026 2h 4m
    This week we have a technical segment focused on Linux! Paul released a script that helps you get a handle on Linux supply chain security, and new features allow you to assess the state of Secure Boot on your Linux systems (that also use MS certificates, ironically). The script is in his Git repo: https://github.com/pasadoorian/Linux_Hacks. In the security news: The CVE chase The new security basics Enterprises are lacking more than AI Detections are falling behind Why DOOM!?! Chromium vulnerability The ambitious Flipper One I'm still curious who was behind these leaks Mitre moves Caldera to Apache foundation Wind cybersecurity PQC updates YellowKey Bitlocker Bypass updates The software supply chain is in deep trouble Show Notes: https://securityweekly.com/psw-928
  • FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927 21.05.2026 2h 2m
    In the security news this week: FCC router bans and the hidden firmware update problem Why extending support timelines actually improves security Github supply chain concerns and the evolving SBOM ecosystem CRA and NIS2 compliance deadlines are getting very real The EU Cyber Resilience Act's 24-hour vulnerability disclosure requirement Security regulation: vertical vs horizontal compliance models Vehicle-to-load EV systems powering homes during outages Solar, batteries, AI farms, and the future economics of electricity Data centers consuming regional power grids BitLocker "Yellow Key" fallout and large-scale remediation challenges AI-generated PowerShell fixes and the rise of vibe scripting Linux kernel exploits, module jail, and default deny strategies Medical biometric data theft and why fingerprints are terrible passwords Interpol cybercrime operations across the MENA region OT security, connected vehicles, and accepting real-world risk The crew also discusses threat intelligence obligations under the CRA, the operational realities of patching at enterprise scale, the economics of secure-by-default systems, and why making security cheaper than insecurity might finally move the industry forward. Show Notes: https://securityweekly.com/psw-927
  • You're not going to patch your way out of this - PSW #926 14.05.2026 2h 2m
    This week: New Yellowkey bitlocker bypass and what it means for you Hackers can run you over with a robot lawnmower FCC says new things about routers, again Glitching with AI almost no false positives AI thought it was evil DirtyFrag and the sad state of Linux LPEs You can buy better tools, perfect security, and other lies The Canvas breach Hackers can still take over trains Baby monitors, on the Internet! dnsmasq flaws I am now paying attention to Swordfish A neat vulnerability for ransomware Mythos, Curl, and how to do secure software Various ways to use AI to find bugs, spoiler, you don't need Mythos Show Notes: https://securityweekly.com/psw-926
  • Getting Rid of Your VPN - Rob Allen - PSW #925 07.05.2026 2h 4m
    Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them! In the Security News: Less details about the FCC router ban Canary traps that work Hacking trains and getting arrested You can be an adult if you have a mustache cPanel is being exploited Pro-Iran group takes down Ubuntu Anthropic's new security solution Safe AI Agents and other lies People still use screensavers? CISA and operating for weeks or months in isolation Paramiko issues fixes Find security research Copy/Fail and AI slop debate ESP32 simulator Spotting vibe coded malware Fast16 - Stuxnet before Stuxnet Show Notes: https://securityweekly.com/psw-925
  • FIRESTARTER - PSW #924 30.04.2026 2h 2m
    This week in the security news: Are you a FIRESTARTER? Eavesdropping via fiber-optic cables Copy Fail - more Linux LPE Github RCE Running Linux on a PS5 BadUSB tricks SilentGlass and HDMI threats Sonicwall and vague details Universities are for porn? The Banshee Before CVEs comes scanning Vendor addresses AirSnitch GitHub and not serious work Routers have country-specific backdoors Phones with Hotspot are fine Show Notes: https://securityweekly.com/psw-924

Popular en

Este podcast también aparece en las listas de podcasts de estos países.