Paul’s Security Weekly Episode #697 – June 03, 2021
Subscribe to all of our shows and mailing list by visiting: https://securityweekly.com/subscribe
1. Attack Surface Discovery and Enumeration – 06:00 PM-06:45 PM
Announcements
-
Do you want to stay in the loop on all things Security Weekly? Visit https://securityweekly.com/subscribe to subscribe on your favorite podcast catcher or our Youtube channel, sign up for our mailing list, join our Discord Server, and follow us on our newest live-streaming platform, Twitch!
-
Security Weekly is ecstatic to announce that Security Weekly Unlocked will be held IN PERSON this December 5-8 at the Hilton Lake Buena Vista! Call for presentations & early registration for Security Weekly listeners is open now! Visit securityweekly.com/unlocked to submit your presentation & register for the early registration price before it expires!
Description
We’ve let the compliance world drive security for so long there are folks that literally have no idea what ‘reasonably secure’ looks or feels like because they’ve never seen it before.
Segment Resources:
phobos.io/orbital
Guest(s)
|
Dan Tentler – Executive Founder at Phobos Group @Viss Dan Tentler is the executive founder of Phobos Group, a boutique information services and products company focused on shifting the overton window from compliance to actual measurable security. |
Hosts
Jeff Man @MrJeffMan #HackingisNotaCrime Advocate, Sr. InfoSec Consultant at Online Business Systems |
Larry Pesce @haxorthematrix Principal Managing Consultant and Director of Research & Development at InGuardians |
Lee Neely @lelandneely Senior Cyber Analyst at Lawrence Livermore National Laboratory |
Paul Asadoorian @securityweekly Founder at Security Weekly |
Tyler Robinson @tyler_robinson Director of Offensive Security & Research at Trimarc and Founder & CEO of Dark Element at Trimarc Security |
2. Digital Transformation’s Impact On IT Asset Visibility – 07:00 PM-07:45 PM
Sponsored By

Visit https://securityweekly.com/ for more information!
Announcements
-
Security Weekly is more than happy to announce that we will be at InfoSec World 2021 IN PERSON October 25th-27th, 2021! This year, our annual partnership with InfoSec World is extra special, as we are both business units under the CyberRisk Alliance brand! What does that mean for Security Weekly listeners & InfoSec World attendees? You will get to see and hear from many of the Security Weekly team at the event AND you will save 20% off on your world pass! Visit https://securityweekly.com/isw2021 to register using our discount code!
Description
Visit https://securityweekly.com/ for more information!
Announcements
-
Security Weekly is more than happy to announce that we will be at InfoSec World 2021 IN PERSON October 25th-27th, 2021! This year, our annual partnership with InfoSec World is extra special, as we are both business units under the CyberRisk Alliance brand! What does that mean for Security Weekly listeners & InfoSec World attendees? You will get to see and hear from many of the Security Weekly team at the event AND you will save 20% off on your world pass! Visit https://securityweekly.com/isw2021 to register using our discount code!
Description
Over the past year, organizations have rapidly accelerated their digital transformation by leveraging technologies such as cloud and container that support the shift to IoT and a remote workforce. Implementing these technologies has led to considerable growth in the number of IT assets deployed within the enterprise. Traditionally, IT oversees the management of these assets and focuses on administration responsibilities like inventory, software support, and license oversight. Sumedh will discuss why the shift to digital calls for a new approach to asset visibility.
Segment Resources:
View the CyberSecurity Asset Management video: https://vimeo.com/551723071/7cc671fc38
Read our CEO’s blog on CyberSecurity Asset Management: https://blog.qualys.com/qualys-insights/2021/05/18/reinventing-asset-management-for-security
Read the detailed blog on CyberSecurity Asset Management: https://blog.qualys.com/product-tech/2021/05/18/introducing-cybersecurity-asset-management
This segment is sponsored by Qualys.
Visit https://securityweekly.com/qualys to learn more about them!
Guest(s)
|
Sumedh Thakar – CEO at Qualys @ssthakar As CEO, Sumedh leads the company’s vision, strategic direction and implementation. He joined Qualys in 2003 in engineering and grew within the company, taking various leadership roles focused on helping Qualys deliver on its platform vision. Since 2014, he has served as Chief Product Officer at Qualys, where he oversaw all things product, including engineering, development, product management, cloud operations, DevOps, and customer support. A product fanatic and engineer at heart, he is a driving force behind expanding the platform from Vulnerability Management into broader areas of security and compliance, helping customers consolidate their security stack. This includes the rollout of the game-changing VMDR (Vulnerability Management, Detection and Response) that continually detects and prevents risk to their systems, Multi-Vector EDR, which focuses on protecting endpoints as well as Container Security, Compliance and Web Application Security solutions. Sumedh was also instrumental in the build-up of multiple Qualys sites resulting in a global 24×7 follow-the-sun product team. Sumedh is a long-time proponent of SaaS and cloud computing. He previously worked at Intacct, a cloud-based financial and accounting software provider. He also worked at Northwest Airlines developing complex algorithms for its yield and revenue management reservation system. Sumedh has a bachelor’s degree in computer engineering with distinction from the University of Pune. |
Hosts
Jeff Man @MrJeffMan #HackingisNotaCrime Advocate, Sr. InfoSec Consultant at Online Business Systems |
Larry Pesce @haxorthematrix Principal Managing Consultant and Director of Research & Development at InGuardians |
Lee Neely @lelandneely Senior Cyber Analyst at Lawrence Livermore National Laboratory |
Paul Asadoorian @securityweekly Founder at Security Weekly |
Tyler Robinson @tyler_robinson Director of Offensive Security & Research at Trimarc and Founder & CEO of Dark Element at Trimarc Security |
3. CFAA Ruling, Amazon Sidewalk, Agile Security Testing, & WordPress Plugins – 08:00 PM-09:30 PM
Announcements
-
Join us on June 10 at 11am ET for our technical training on insider risk to learn how to quickly mitigate data exposure risks. Then join us June 24 at 11 AM ET to learn how web application firewalls can help mitigate exposure in a complex threat landscape. Visit https://securityweekly.com/webcasts to register now! If you missed any of our previously recorded webcasts or technical trainings, they are available for your viewing pleasure at https://securityweekly.com/ondemand
Description
This week In the Security News, Paul and the Crew talk: Establishing Confidence in IoT Device Security: How do we get there?, JBS hack latest escalation of Russia-based aggression ahead of June 16 Putin summit, why Vulnerability Management is the Key to Stopping Attacks, Overcoming Compliance Issues in Cloud Computing, Attack on meat supplier came from REvil, ransomware’s most cutthroat gang, WordPress Plugins Are Responsible for 98% of All Vulnerabilities, and more!
Hosts
Jeff Man @MrJeffMan
#HackingisNotaCrime Advocate, Sr. InfoSec Consultant at Online Business Systems |
Larry Pesce @haxorthematrix
Principal Managing Consultant and Director of Research & Development at InGuardians |
|
Lee Neely @lelandneely
Senior Cyber Analyst at Lawrence Livermore National Laboratory |
|
Paul Asadoorian @securityweekly
Founder at Security Weekly |
|
Tyler Robinson @tyler_robinson
Director of Offensive Security & Research at Trimarc and Founder & CEO of Dark Element at Trimarc Security |