DevOps or DevSecOps? – Application Security Weekly #10

Does DevOps handle security, or does it need to be DevSecOps? Maybe your not doing DevOps if you’re not doing security. This week Paul and Keith discuss the debate between the two! Topic: Is it DevOps or DevSecOps? – Musings on setting up a Secur… Continue reading DevOps or DevSecOps? – Application Security Weekly #10→

Cloudflare, Facebook, & Red Team Wisdom – Application Security Weekly #10

In the news, uncovering a bug in Cloudflare’s Minification Service, how security alerts are keeping your code safer, Red Team wisdom, Facebook scraped call, text message data for years from Android phones, & more on this episode of Applicatio… Continue reading Cloudflare, Facebook, & Red Team Wisdom – Application Security Weekly #10→

APT, MITRE, DoD, and Panera – Hack Naked News #167

This week, Drupal vulnerabilities, APT detection, DoD bug bounties, new DNS services and breaches galore from Under Armour, Saks, Lord and Taylor, and Panera! Jason Wood from Paladin Security joins us for expert commentary so stay tuned to this episode… Continue reading APT, MITRE, DoD, and Panera – Hack Naked News #167→

Cisco, SensorNet, Wombat, and Google – Enterprise Security Weekly #85

In the news, Cisco commits $50 million to end homelessness in Silicon Valley, Distil Networks’ annual bad bot report finds one in five companies now block Russian traffic, Alex Stamos’ original thoughts on Cambridge Analytica, and more on t… Continue reading Cisco, SensorNet, Wombat, and Google – Enterprise Security Weekly #85→

The Phoenix Project – Enterprise Security Weekly #85

Paul and Keith Hoodlet discuss The Phoenix Project: A Novel about IT, DevOps, and Helping Your Business Win! Topic: The Pheonix Project Book Review For Enterprise Security Professionals I’ve just finished reading this book (again) and found it ev… Continue reading The Phoenix Project – Enterprise Security Weekly #85→

Evading Network-Based Detection Mechanisms – Tradecraft Security Weekly #24

In this episode of Tradecraft Security Weekly hosts Beau Bullock (@dafthack) and Mike Felch (@ustayready) discuss methods for evading network-based detection mechanisms. Many commercial IDS/IPS devices do a pretty decent job of detecting standard pente… Continue reading Evading Network-Based Detection Mechanisms – Tradecraft Security Weekly #24→