Risky Biz Soap Box: Running a global vulnerability management program

In short, it's hard...

Today’s soap box is brought to you by Nucleus Security.

Nucleus makes a platform that ingests vulnerability scan information from all your vuln scanning tech so that you can do things like assign different vulnerabilities to different teams to manage and remediate. Send these ones to infrastructure, send these ones to app teams, send everything up and down this stack to this department etc.

If you want to see Nucleus in action I have recorded a demo and it’s on our YouTube product demos page, I’ve linked through to it in the show notes for this podcast.

Our guest in this episode is Scott Kuffer, co-founder of Nucleus, and the topic is running a vulnerability management program in a very large enterprise.

Srsly Risky Biz #3 — China Gonna China

PLUS: Microsoft under fire for its report on cyber-attacks in Ukraine.

This podcast is a discussion between Patrick Gray and Tom Uren on the big stories affecting people in cyber policy.

It’s based on the latest Seriously Risky Business newsletter, which you can find here.

Risky Business #670 -- China's world record data breach

A billion records from Shanghai police servers for sale...

On this week’s show Patrick Gray and guest cohost Mark Piper discuss the week’s security news, including:

  • A billion records leaked in China
  • China to develop desktop operating system
  • HackerOne fires insider for stealing hackers’ work and bounties
  • FSB officer charged with stealing hacker’s bitcoin
  • Why Microsoft is wrong on Russia and Ukraine
  • Much, much more

Red Canary’s Adam Mashinchi and Brian Donohue will be along in this week’s sponsor interview to talk about Atomic Red Team, the open source adversary emulation framework they help to maintain.

Risky Biz News: Hackers hit Iranian steel industry

PLUS: FSB officer detained for stealing crypto from a hacker, and Russia tried to hack Ukraine's TV channels.

A short podcast updating listeners on the security news of the last few days, as prepared and presented by Catalin Cimpanu.

You can find the newsletter version of this podcast here.

Risky Business #669 -- Finally, an ICS attack that made stuff explode!

Shabbat shalom, motherf---ers!

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Activists who are totally not Israeli military hackers make Iranian steel mills firebally
  • Chinese APT crews use ransomware to muddy attribution
  • Attackers are now ransoming cloud access
  • Chinese APTs using building control systems for persistence and stealth
  • USA, UK and NZ govts issue PowerShell advice
  • Much, much more

This week’s show is brought to you by Material Security. JJ Agha, CISO at Compass, joins the show to talk about how he’s using it to make phishing triage and automation less traumatic.

Risky Business #668 -- Microsoft is hiding its Azure security problems

PLUS: Paige Thompson guilty of Capital One hack...

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Paige Thompson guilty of Capital One hack
  • Microsoft is hiding serious Azure security issues
  • New Australian government lobbying for Julian Assange
  • How to ransomware documents in the cloud
  • Microsoft stops Windows 10/11 downloads in Russia
  • Belarusian cyber partisans obtain spy agency’s audio recordings
  • Much, much more

This week’s edition of the show is brought to you by Gigamon. Josh Day, Gigamon’s Director of applied threat research team, will be along in this week’s sponsor interview to talk about detecting badness on your network in encrypted traffic.


SUBSCRIBE NOW:
Risky Business main podcast feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Our extra podcasts feed:
Listen on Apple Podcasts Listen on Overcast Listen on Pocket Casts Listen on Spotify Subscribe with RSS
Subscribe to our newsletters: