Tomcat, AWS Malware, Hacker Movies – PSW #642

Apache Tomcat AJP exploit, malware in AWS, hacker movies and more!

Visit for all the latest episodes!

Full Episode Show Notes

To learn more about our sponsors visit: The Security Weekly Sponsor’s Page

Tomcat, AWS Malware, Hacker Movies

Why Doesn’t Software Get Sold With a List of Ingredients? Allan Friedman talks about the ‘Software Bill of Materials’
Time for cybersecurity to take back control of its story What do yours truly and Sulu have in common? THIS!Black Market White Washing: Why You Shouldn’t Take Legal Advice From Criminals
Backdoor malware is being spread through fake security certificate alerts
Shark Tank TV star loses almost $400,000 in Business Email…
Venezuela Power outage knocked out part of the internet connectivity
Researchers use ultrasound waves vibrating through tables to access cellphones
Apache Tomcat – AJP ‘Ghostcat File Read/Inclusion
WiFi Kr00K and plaintext traffic – and more
Exploiting WiFi OWE


Jeff Man
Jeff Man – Sr. InfoSec Consultant
Joff Thyer
Joff Thyer – Security Analyst
Larry Pesce
Larry Pesce – Senior Managing Consultant and Director of Research
Lee Neely
Lee Neely – Senior Cyber Analyst
Paul Asadoorian
Paul Asadoorian – Founder & CTO



  • Our first-ever virtual training is happening on March 19th at 11:00am ET with Adam Kehler & Rob Harvey from the Online Business Systems Risk, Security & Privacy Team. In this training you will learn how to generate a complex SHA-256 hashed password and then use password cracking tools to break it. Register for our upcoming webcasts & trainings by visiting, selecting the webcast/training drop down from the top menu bar and clicking registration.
  • Join us at InfoSecWorld 2020 – March 30 – April 1, 2020 at the Disney Contemporary Resort! Security Weekly listeners save 15% off the InfoSec World Main Conference or World Pass! Visit, click the register button to register with our discount code or the schedule button to sponsor a micro-interview!
  • OSHEAN and the Pell Center are partnering together to present Cybersecurity Exchange Day on Wednesday, March 18th from 9am-3pm at Salve Regina University in the beautiful Newport, RI! Visit to register for free and come join in the fun!