Épisodes

  • Holiday Hack Challenge, AI, Internet of Trash - Ed Skoudis - PSW #903
    Dec 4 2025

    This week we welcome Ed Skoudis to talk about the holiday hack challenge (https://sans.org/HolidayHack). In the security news:

    • Oh Asus
    • Dashcam botnets
    • Weird CVEs being issued
    • CodeRED, but not the worm
    • Free IP checking
    • Internet space junk and IoT
    • Decade old Linux kernel vulnerabilities
    • Breaking out of Claude code
    • Malicious LLMs
    • Hacker on a plan gets 7 years
    • Putting passwords into random websites
    • NPM supply chains strike again
    • LLMs will never be intelligent

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-903

    Voir plus Voir moins
    2 h et 11 min
  • Vibe Coding For Success and Failure - PSW #902
    Nov 27 2025

    Tune in for some hands-on tips on how to use Claude code to create some amazing and not-so-amazing software. Paul will walk you through what worked and what didn't as he 100% vibe-coded a Python Flask application. The discussion continues with the crew discussing the future of vibe coding and how AI may better help in creating and securing software.

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-902

    Voir plus Voir moins
    1 h et 7 min
  • Give Me Liberty or Linux, Badge Hacking Interview - Bryce Owen - PSW #901
    Nov 20 2025

    In the security news:

    • Cloudflare was down, it was not good
    • Logitech breached
    • The largest data breach in history?
    • Fortinet Fortiweb - the saga continues
    • Hacking Linux through your malware scanner, oh the irony
    • I never stopped hating systemd
    • The ASUS exploit that never existed
    • If iRobot fails, can we deploy our own hacker bot army?
    • Firmware encryption is a bitch
    • Threat actors deply Claude Code
    • Remembering the Viasat hack and why we can't have nice things
    • Hacking re-entry sensors
    • Sending signals in the wrong direction
    • A File Format Uncracked for 20 Years
    • And 2026 is the year of the Linux desktop!

    Then, high school junior Bryce Owen joins us to discuss how he created the "Space Badge"!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-901

    Voir plus Voir moins
    2 h et 10 min
  • Going Around EDR - PSW #900
    Nov 13 2025

    This week:

    • Minecraft on your lightbulb
    • Sonicwall breached, who's next?
    • Ditch Android, install Linux
    • Hacking your face
    • Thermostat freedom
    • Pen test fails
    • HackRF hacking times 2
    • Going around EDR
    • Hackers in your printer
    • Chinese data breach
    • NFC relays and PCI
    • Constructive construction hacks
    • FlipperZero firmware update
    • ICS, PLCs, and attacks
    • Bayesian Swiss Cheese, taste good?
    • Do you want to hack back?
    • Keeping secrets
    • Enforcing CMMC
    • OWASP top ten gets a make over
    • Android Spyware makes a LANDFALL
    • Gemini's deep research into your documents
    • Slopguard
    • and AI datacenters in space!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-900

    Voir plus Voir moins
    2 h et 6 min
  • Turning To The Darkside & AI Cyberslop - PSW #899
    Nov 6 2025

    This week:

    • Reversing keyboard firmware
    • Ghost networks
    • Invasion of the face changers
    • Ghost tapping and whole lot of FUD
    • AI doesn't code securely, but Aardvark can secure code
    • De-Googling Thermostats
    • Dodgy Android TV boxes can run Debian
    • HackRF vs. Honda
    • Cyberslop AI paper
    • Turning to the darkside
    • Poisoning the watering hole
    • Nagios vulnerabilities
    • VPNs are a target

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-899

    Voir plus Voir moins
    2 h et 8 min
  • Cybersecurity Is Dead - PSW #898
    Oct 30 2025

    In the security news this week:

    • Cybersecurity is dead, and AI killed it
    • Exploiting the patching system
    • Apple makes it easier for spyware
    • Who is patching Cisco ASA?
    • Shove that DMCA somewhere
    • HTTPS - a requirement
    • Russia wants to own all the exploits
    • Abandonware challenges
    • Reversing at its hardest with Lua
    • Hacking team is back, and leetspeak malware
    • When you forget to authenticate your API
    • Jamming with cool tech
    • GoSpoof
    • and After 35 Years, a Solution to the CIA’s Kryptos Puzzle Has Been Found!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-898

    Voir plus Voir moins
    2 h et 4 min
  • Its Always DNS - PSW #897
    Oct 23 2025

    In the security news:

    • When in doubt, blame DNS, you're almost always correct
    • How to Make Windows 11 great, or at least suck less
    • CSRF is the least of your problems
    • Shady exploits
    • Linux security table stakes (not steaks)
    • The pill camera
    • Give AI access to your UART
    • Security products that actually try to be secure?
    • Firmware vulnerabilities, lots of them
    • Teams is spying on you
    • More details on PolarEdge
    • VSCode, marketplaces, and developers at risk
    • Cisco SNMP flaw used to deploy malware
    • The 90's called, they want their exploits back

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-897

    Voir plus Voir moins
    2 h et 4 min
  • AI, EDR, and Hacking Things - PSW #896
    Oct 16 2025

    First up is a technical segment on UEFI shells: determining if they contain dangerous functionality that allows attackers to bypass Secure Boot.

    Then in the security news:

    • Your vulnerability scanner is your weakest link
    • Scams that almost got me
    • The state of EDR is not good
    • You don't need to do that on a phone or Raspberry PI
    • Hash cracking and exploits
    • Revisiting LG WebOS
    • Hardening Docker images
    • Hacking Moxa NPort
    • Shoddy academic research
    • The original sin of computing
    • Bodycam hacking
    • A new OS for ESP32
    • The AI bubble is going to burt
    • Mobile VPNs are not always secure

    Visit https://www.securityweekly.com/psw for all the latest episodes!

    Show Notes: https://securityweekly.com/psw-896

    Voir plus Voir moins
    2 h et 5 min