Blue Security Podcast
Blue Security Podcast
  • 228
  • 20 596
Blue Security Podcast - 2025-01-07 - Sophos, Chinese Hackers, and other news
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss significant cybersecurity updates, including the indictment of a Chinese hacker involved in attacks on Sophos firewalls. They explore the growing competition from Chinese electric vehicle manufacturers and the vulnerabilities of digital license plates. The conversation also covers the investigation into TP-Link routers due to national security concerns and the launch of a free tier for GitHub Copilot, enhancing accessibility for developers.
----------------------------------------------------
Audio Podcast Link: creators.spotify.com/pod/show/blue-security-podcast/episodes/Sophos--Digital-License-Plates--TP-Link--Github-Copilot-e2t397r
----------------------------------------------------
Documentation:
www.justice.gov/opa/pr/china-based-hacker-charged-conspiring-develop-and-deploy-malware-exploited-tens-thousands
www.wired.com/story/digital-license-plate-jailbreak-hack/
9to5mac.com/2024/12/18/most-popular-home-internet-routers-in-us-may-be-banned-as-national-security-risk/
github.blog/news-insights/product-news/github-copilot-in-vscode-free/
----------------------------------------------------
Contact Us:
Website: ⁠⁠⁠bluesecuritypod.com
Bluesky: bsky.app/profile/bluesecuritypod.com
LinkedIn: www.linkedin.com/company/bluesecpod
TH-cam: ⁠th-cam.com/users/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: bsky.app/profile/ajawzero.com
LinkedIn: ⁠⁠⁠⁠⁠www.linkedin.com/in/andyjaw/
Email: ⁠andy@bluesecuritypod.com⁠
----------------------------------------------------
Adam Brewer
Twitter: ajbrewer
LinkedIn: www.linkedin.com/in/adamjbrewer/
Email: adam@bluesecuritypod.com
มุมมอง: 28

วีดีโอ

Blue Security Podcast - 2024-12-31 - Defenders for ARM, DNS, and AI
มุมมอง 68วันที่ผ่านมา
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the latest developments in Azure cloud security, focusing on the Defender solutions for Resource Manager, DNS, and AI workloads. They emphasize the importance of protecting these foundational elements of Azure, particularly the Resource Manager, which serves as the control plane for all resources. The c...
Blue Security Podcast - 2024-12-24 - Defenders for App Service, Databases
มุมมอง 4514 วันที่ผ่านมา
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the importance of cloud security, focusing on Microsoft's Defender services. They explore Defender for App Service, highlighting its ease of activation and the security recommendations it provides. The conversation then shifts to Defender for Databases, detailing its capabilities in protecting SQL datab...
Blue Security Podcast - 2024-12-17 - Defenders for Key Vault, APIs
มุมมอง 3721 วันที่ผ่านมา
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into Azure Key Vault and its security features, particularly focusing on Defender for Key Vault and Defender for API. They discuss the importance of securely managing sensitive information, the ease of deploying these security solutions, and the critical need for visibility and threat detection in cloud e...
Blue Security Podcast - 2024-12-10 - Options for Microsoft Training
มุมมอง 55หลายเดือนก่อน
Summary In this episode, Andy and Adam discuss various resources available for training on Microsoft technologies. They emphasize the importance of the Learn Microsoft portal, highlight the benefits of Ninja training for deep dives into specific topics, and recommend various TH-cam channels for bite-sized learning. The conversation also covers the significance of tech community blogs, hands-on ...
Blue Security Podcast - 2024-12-03 - Microsoft Ignite 2024 Highlights
มุมมอง 70หลายเดือนก่อน
On this week's episode, Andy and Adam...
Blue Security Podcast - 2024-11-26 - Cybersecurity Maturity Model Cert. (CMMC), guest Justin Orcutt
มุมมอง 38หลายเดือนก่อน
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer welcome Justin Orcutt from Microsoft to discuss the Cybersecurity Maturity Model Certification (CMMC). The conversation covers the history and requirements of CMMC, the steps companies need to take to prepare for audits, and the importance of continuous monitoring. Justin shares insights on the anxiety surround...
Blue Security Podcast - 2024-11-19 - T-Mobile Breach, Sophos Hacks Back, Bluesky Surges
มุมมอง 69หลายเดือนก่อน
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the recent T-Mobile breach attributed to Chinese state-sponsored hackers, emphasizing the importance of parsing corporate statements. They delve into the implications of cybersecurity threats, referencing a Sophos report detailing a five-year cat-and-mouse game with Chinese attackers. The conversation s...
Blue Security Podcast - 2024-11-12 - Securing Contingent Workers
มุมมอง 59หลายเดือนก่อน
Summary In this episode, Andy and Adam discuss the challenges and strategies for securing seasonal and contingent workers using a Zero Trust approach. They emphasize the importance of managed devices, the complexities of hybrid domain joins, and explore alternative solutions such as cloud-based services. The conversation also touches on the significance of security policies and the need for exc...
Blue Security Podcast - 2024-11-05 - Offboarding Users
มุมมอง 492 หลายเดือนก่อน
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the critical steps involved in offboarding employees, particularly focusing on Microsoft 365 environments. They cover essential practices such as blocking user sign-ins, managing mailbox contents, device management, and ensuring data protection. The conversation emphasizes the importance of modernizing device m...
Blue Security Podcast - 2024-10-29 - AD Security Guide, MDE Safe Deployment, macOS Entra SSO
มุมมอง 702 หลายเดือนก่อน
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss critical cybersecurity insights, focusing on Active Directory security techniques, the implications of recent incidents involving Microsoft Defender for Endpoint, and the introduction of passwordless solutions for Apple devices. They emphasize the importance of foundational knowledge in cybersecurity, t...
Blue Security Podcast - 2024-10-22 - Microsoft Digital Defense Report '24
มุมมอง 972 หลายเดือนก่อน
Summary In this episode, Andy and Adam discuss Microsoft's 2024 Digital Defense Report, which highlights the evolving cyber threat landscape, the rise of ransomware, identity attacks, and DDoS attacks. They emphasize the importance of centering organizations around security, the shift towards passwordless authentication, and the impact of AI on cybersecurity. The conversation provides actionabl...
Blue Security Podcast - 2024-10-15 - Microsoft Secure Future Initiative Update
มุมมอง 962 หลายเดือนก่อน
Summary In this episode, Andy Jaw and Adam Brewer discuss Microsoft's Secure Future Initiative (SFI), which emphasizes security by design, default, and operations. They explore the initiative's six key security pillars, the impact of recent cyber incidents, and the ongoing progress in enhancing security measures across Microsoft. The conversation highlights the importance of employee accountabi...
Blue Security Podcast - 2024-10-08 - Let's Talk About Passwords!
มุมมอง 1143 หลายเดือนก่อน
Summary In this episode of the BlueScarity Podcast, hosts Andy Jaw and Adam Brewer discuss the evolution of password guidelines, focusing on the recent updates from NIST and Microsoft. They explore the implications of these changes, emphasizing the importance of understanding human behavior in password security and the need for organizations to adopt passwordless solutions. The conversation hig...
Blue Security Podcast - 2024-10-01 - Protect Against Token Theft
มุมมอง 1223 หลายเดือนก่อน
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into the critical topic of token theft in identity management. They discuss the importance of multi-factor authentication (MFA) as a primary defense against identity attacks, the nature of tokens, and how attackers exploit vulnerabilities to steal these tokens. The conversation highlights the introduction of toke...
Blue Security Podcast - 2024-09-24 - BSP Turns 4, WSUS Deprecated, macOS Firewall Woes
มุมมอง 783 หลายเดือนก่อน
Blue Security Podcast - 2024-09-24 - BSP Turns 4, WSUS Deprecated, macOS Firewall Woes
Blue Security Podcast - 2024-09-17 - Cloud Security: Containers 101 & Defender for Containers
มุมมอง 653 หลายเดือนก่อน
Blue Security Podcast - 2024-09-17 - Cloud Security: Containers 101 & Defender for Containers
Blue Security Podcast - 2024-09-10 - IBM Cost of a Data Breach Report
มุมมอง 654 หลายเดือนก่อน
Blue Security Podcast - 2024-09-10 - IBM Cost of a Data Breach Report
Blue Security Podcast - 2024-09-03 - Entra Suite Overview
มุมมอง 694 หลายเดือนก่อน
Blue Security Podcast - 2024-09-03 - Entra Suite Overview
Blue Security Podcast - 2024-08-27 - Where Do You Find Training?
มุมมอง 654 หลายเดือนก่อน
Blue Security Podcast - 2024-08-27 - Where Do You Find Training?
Blue Security Podcast - 2024-08-20 - Trump Campaign + NPD Hacked, Microsoft Admin MFA
มุมมอง 554 หลายเดือนก่อน
Blue Security Podcast - 2024-08-20 - Trump Campaign NPD Hacked, Microsoft Admin MFA
Blue Security Podcast - 2024-08-13 - Defender for Storage
มุมมอง 524 หลายเดือนก่อน
Blue Security Podcast - 2024-08-13 - Defender for Storage
Blue Security Podcast - 2024-08-06 - Windows Autopilot and Microsoft Intune updates
มุมมอง 2745 หลายเดือนก่อน
Blue Security Podcast - 2024-08-06 - Windows Autopilot and Microsoft Intune updates
Blue Security Podcast - 2024-07-30 - Cloud Security Posture Management
มุมมอง 575 หลายเดือนก่อน
Blue Security Podcast - 2024-07-30 - Cloud Security Posture Management
Blue Security Podcast - 2024-07-22 - CrowdStrike Major Incident
มุมมอง 2025 หลายเดือนก่อน
Blue Security Podcast - 2024-07-22 - CrowdStrike Major Incident
Blue Security Podcast - 2024-07-16 - Cybersecurity is Full?
มุมมอง 2945 หลายเดือนก่อน
Blue Security Podcast - 2024-07-16 - Cybersecurity is Full?
Blue Security Podcast - 2024-07-09 - Defender for Servers
มุมมอง 996 หลายเดือนก่อน
Blue Security Podcast - 2024-07-09 - Defender for Servers
Blue Security Podcast - 2024-07-02 - Exchange Online Protection Configuration
มุมมอง 886 หลายเดือนก่อน
Blue Security Podcast - 2024-07-02 - Exchange Online Protection Configuration
Blue Security Podcast - 2024-06-25 - Kaspersky Ban, and A Tale of Two Hacks
มุมมอง 2256 หลายเดือนก่อน
Blue Security Podcast - 2024-06-25 - Kaspersky Ban, and A Tale of Two Hacks
Blue Security Podcast - 2024-06-18 - Snowflake, Findlay Auto Ransomware, Olympics
มุมมอง 716 หลายเดือนก่อน
Blue Security Podcast - 2024-06-18 - Snowflake, Findlay Auto Ransomware, Olympics

ความคิดเห็น

  • @jastation321
    @jastation321 15 วันที่ผ่านมา

    great podcast

  • @MDALIMUDDIN-1999
    @MDALIMUDDIN-1999 2 หลายเดือนก่อน

    Hello TH-cam Star- I have watched all your videos. Your videos are very nice but there is some problem with your channel. Your channel is not optimized properly and your channel SEO score is very low due to which your channel is not getting good views. If you solve your channel problems, you will get many Subscriber views on your channel. Have a Good

  • @Dannyk-hy2on
    @Dannyk-hy2on 2 หลายเดือนก่อน

    Thanks guys!

  • @Dannyk-hy2on
    @Dannyk-hy2on 3 หลายเดือนก่อน

    Thanks guys!

  • @Dannyk-hy2on
    @Dannyk-hy2on 3 หลายเดือนก่อน

    Thanks guys, CAE for everything forever :)

  • @Dannyk-hy2on
    @Dannyk-hy2on 3 หลายเดือนก่อน

    Thanks as usual guys, I always look forward to Tuesdays :)

  • @LostinNoir
    @LostinNoir 3 หลายเดือนก่อน

    I have little understanding of the tech/IT world. This video was still helpful nevertheless.

  • @Dannyk-hy2on
    @Dannyk-hy2on 3 หลายเดือนก่อน

    Thank you guys! I use this product and it's really powerful. Our dev team has work cut out for them for months to come😅

  • @Dannyk-hy2on
    @Dannyk-hy2on 4 หลายเดือนก่อน

    You guys are the best, you are highly appreciated. Thank you!!

  • @anamikatarjani
    @anamikatarjani 5 หลายเดือนก่อน

    Indian Railways ran unaffected with daily passengers count 28M due to the fact that they use unix based system.

  • @PP_Mclappins
    @PP_Mclappins 5 หลายเดือนก่อน

    I think there is some truth to the idea that there is an oversaturation in the market. A great example was given to me when I recently interviewed for role for which I was well qualified. I have a number of bootcamp certificates from University of Michigan, CompTIA Security + (2024), CCNA (renewed 2023), Microsoft SC-200 (renewed in 2023 azure security), google IT professional certification, and a couple more vague certs, along with 3 years of experience in enterprise support and 2.5 years managing network infrastructure for a local small business (including hosting and building their website within security best practices). I always interview quite well, and bring my best in professional behavior and knowledge to the table. I was told that another candidate was filling the role, and informed by my recruiter that the reason they hired the other candidate was that he was "younger, more green, and cost less money" The pay scale was 56,000 - 62,000 which is relatively low though I wanted the position so that I could finally break into "security". I asked for 60,000 which only $1,000 per year more than I make in help desk. The other guy apparently was willing to work for 55k

  • @ThePoser010
    @ThePoser010 5 หลายเดือนก่อน

    Cyber is also taxing us on the body. Most people I work with are sedentary and alcoholics. There was this guy in /r/netsecstudents passing this site around. He posted his resume in another post with a bunch of consulting experience and still being employed. It was kind of fucked up

  • @roughbartl9231
    @roughbartl9231 6 หลายเดือนก่อน

    Been following the podcast on Spotify for a while now. But I have to write a comment here and praise it. By far the best technical podcast that always manages to give you something you can use in the real world. Many thanks for this and best regards from Germany!

  • @manolito7045
    @manolito7045 7 หลายเดือนก่อน

    Only 4 likes... ok, I'm a bit late but 2 years later, I still find your video very usefull, thanks for your work guys.

  • @TrumpSucks7257
    @TrumpSucks7257 8 หลายเดือนก่อน

    i am just now seeing this and using this feature. great job guys. you helped my understanding alot.

  • @AdamBrewerTech
    @AdamBrewerTech 9 หลายเดือนก่อน

    Did you like it?

  • @ceeg0865
    @ceeg0865 10 หลายเดือนก่อน

    I agree! This is how companies are getting raided for trade secrets and cash. Then we wonder how the competition suddenly appeared.

  • @Akira29H
    @Akira29H 11 หลายเดือนก่อน

    As domain admins Need to use jumpbox? Or RSAT will do.? What you mean to have Server access but not DC access?

  • @whize1
    @whize1 11 หลายเดือนก่อน

    I WANT entra-joined only. But getting a fully functional workstation that is like-for-like seems a bit unsurmountable at this point. Had to build out on-prem Intune Certificate Connector for Global Protect VPN, and getting that to work was not easy. And there are many different ways to deploy VPN App (Win32/wintune format/UWP) and Configuration Profiles (poorly documented on Palo Alto's side and Microsoft side), which one to use and configure? And drive mappings (yeah, we still have folks using lots of department-specific drive mappings for the last 20 years, some of it very sensitive), and there are multiple solutions out there for that but nothing that reliable. Even setting workstation background is a complete redesign (used to use a file share, but now have to come up with Azure blob storage, and it's too complex for the Marketing layperson that used to just drop a couple picture files in a local file share). Co-Management with our MECM is difficult, as we don't allow on-prem admin accounts to replicate to Entra (security reasons), and thus have difficulty with setting up roles in Entra AND MECM at the same time, and (again, for security), and we haven't built out CMG. This is going to take sooo many iterations that it is daunting.

  • @AdamBrewerTech
    @AdamBrewerTech ปีที่แล้ว

    I’m commenting myself

  • @for14556
    @for14556 ปีที่แล้ว

    Just found this one - amazing content !!!

  • @Chris-tu8qd
    @Chris-tu8qd ปีที่แล้ว

    Great video! I appreciate the deeper dive into the technical aspect of the technology. Definitely going to check out more of your podcasts. Liked & Subscribed!

  • @davidj.534
    @davidj.534 ปีที่แล้ว

    Love this channel, thank you both!

  • @bertvdl1178
    @bertvdl1178 ปีที่แล้ว

    great coverage 🙏 I believe Microsoft really has to step up their game, this is becoming a national security threat.

  • @atumf87
    @atumf87 ปีที่แล้ว

    Very i formative and inspiring. Thank you, guys. Keep it up!

  • @LabelsAreMeaningless
    @LabelsAreMeaningless ปีที่แล้ว

    Corporatism is not Capitalism. They are diametrically opposed to each-other in more ways than not. People really need to relearn the difference between the two because the twist was intentionally introduced to protect corporate monopolies and power.

  • @mjcro8055
    @mjcro8055 ปีที่แล้ว

    Great podcast. Wholistic view, which is rare to see in corporate IT.

  • @simimik.
    @simimik. ปีที่แล้ว

    I am waiting also for the Proton Pass features for the Free version.

  • @EricS-uf9mv
    @EricS-uf9mv ปีที่แล้ว

    Unlike Bitwarden, it looks like Proton Pass will have restricted functionality as a "free" OSS password manager. When this comes out of beta, they're planning to paywall several as yet to be announced premium features. And knowing how Proton operates, they're NOT GENEROUS w/ their free tier... ex, free Email accts limited to 500mb which is UNUSABLE, it's HIGHLY LIKELY Proton Pass will implement equally unusable artificial limits. Think along the lines of... "Free accts limited to 5 credentials"; or "Can only be simultaneously logged in on a single device at a time"; or "Device-to-Device sync disabled for free accts", rendering multi-device login moot; or some other equally inane limitation to force premium account subscription to the full Proton Acct suite. OTOH Bitwarden's core suite of functionality is avail to the free tier. IMO BW's only major "core" features withheld are "YubiKey HW key 2FA authentication for Bitwarden acct sign-in's not allowed", and "Built-in 2FA TOTP generator for sites stored in BW disabled". You can still use software & SMS based 2FA to secure your BW acct, but YubiKey FIDO/U2F protocol is disabled for free accts. And the 2nd thing isn't an issue b/c Info Sec 101 (and the Lastpass breach) tells us NOT TO STORE our 2FA seeds with our Passwords. And no, I'm not a Proton hater. I subscribe to their premium VPN service. Hopefully someone will fork their OSS code & release a full featured PW manager to the community.

  • @richpoorworstbest4812
    @richpoorworstbest4812 ปีที่แล้ว

    enjoyable and interesting

  • @MonSkelton
    @MonSkelton ปีที่แล้ว

    I enjoyed this episode.

  • @SpyBot-dt2lt
    @SpyBot-dt2lt ปีที่แล้ว

    Hello, I have a question about yubikey 5 nfc. I first want to say thank you so much providing this kinds of information. I recently got hacked and even though I had google Authenticator for the totp’s, I still got hacked, so after doing some research I found videos just like yours and now I see how easy it is to get the session token with evilginx to bypass 2fa. So I’m still a bit new at this, but… now I understand that hardware token is probably the best bet for me as a normal person with gmail and steam accounts and what not, so thank once again for knowledge. My question is that, would evilginx still be able to get the session token if I were to use the yubico Authenticator app for the totp with the yubikey in combination? I noticed that only big company’s support the actual key by itself, but I have steam accounts and ect aswell. I hope I asked the question correctly. Thanks you so much once again. 😊

  • @kafidipeadetunji5971
    @kafidipeadetunji5971 ปีที่แล้ว

    Great Podcast. Very enlightening

  • @user-tx8el3vr9k
    @user-tx8el3vr9k 2 ปีที่แล้ว

    When NAC podcast comes?

  • @user-tx8el3vr9k
    @user-tx8el3vr9k 2 ปีที่แล้ว

    Please make a podcast for NAC ( NETWORK ACESS CONTROL)

  • @user-tx8el3vr9k
    @user-tx8el3vr9k 2 ปีที่แล้ว

    Please make a podcast on NAC solution.

  • @peconomusman
    @peconomusman 2 ปีที่แล้ว

    Missing the podcast this week gentlemen!

    • @BlueSecurityPodcast
      @BlueSecurityPodcast 2 ปีที่แล้ว

      Sorry for the delay. The audio podcast was released on time but video took a while. We just published two episodes on the YT channel.

  • @Toommy78
    @Toommy78 2 ปีที่แล้ว

    The provisioning of WHfB requires the MFA during enrollment. Can I enable the WHfB for accounts not having MFA registered ?

    • @BlueSecurityPodcast
      @BlueSecurityPodcast ปีที่แล้ว

      No, you must register MFA to use WHfB. This is because WHfB sends the MFA token for any SSO apps that you require MFA for.

  • @myotahapeaofbabylon6510
    @myotahapeaofbabylon6510 2 ปีที่แล้ว

    Hey, I'm being electronically gang stalked. I don't know what to do. I've gotten desperate and started leaving comments about it in ao many different spaces.

  • @odlyotter1139
    @odlyotter1139 2 ปีที่แล้ว

    Oh look, I am the first view and comment. Nice.

  • @dinargalimov2030
    @dinargalimov2030 2 ปีที่แล้ว

    Awesome! Perfect video podcast! We are going to deploy CG over our company. You explained me in one video all stuff that I been looking for! Thank you!

  • @kapilhudiya1022
    @kapilhudiya1022 2 ปีที่แล้ว

    REALLY GOOD SESSION, Diagram or ppt would be more beneficial

  • @cameronfairbairn
    @cameronfairbairn 2 ปีที่แล้ว

    Very helpful, thank you!

  • @Byteben
    @Byteben 2 ปีที่แล้ว

    Another great episode, thanks for sharing 🙌🏻

  • @byron_glover
    @byron_glover 2 ปีที่แล้ว

    Regarding LOS to a DC during enrollment with hybrid cloud trust, should we deploy via GPO instead? What will happen if we deploy via Intune and they receive the reg change while off network? Then they sign-in later on still off network and get prompted to enroll? Will it fail/error?

    • @BlueSecurityPodcast
      @BlueSecurityPodcast 2 ปีที่แล้ว

      You can deploy it either via GPO or Intune. If you're doing it via Intune (on Hybrid AAD Join devices), this needs to be a separate policy than the Intune WHfB build in policy. It has to be a custom config template. It also can only be received upon enrollment of Intune. If the device is already enrolled in Intune, it will not work. And since it's a configuration policy in Intune, you'll also need to have co-management turned on with configuration offloaded to Intune and not SCCM. The documentation has some additional details. docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trust

  • @sweatpantsclub
    @sweatpantsclub 2 ปีที่แล้ว

    This was super helpful thank you!

  • @unatommer
    @unatommer 2 ปีที่แล้ว

    Hey guys, love the podcast. Just some quick feedback, listened to the whole thing and at the very end the tidbit “win 10 enterprise only” was inserted. Maybe include that up front eh? Lots of orgs don’t have enterprise licensing. Keep up the good work and keep the episodes coming!

  • @lilgoodluxboi
    @lilgoodluxboi 2 ปีที่แล้ว

    This information is fire!!!! Love it!

  • @bobpilkington4972
    @bobpilkington4972 3 ปีที่แล้ว

    Great info, more orgs should implement this. Keep it up!

  • @TheChewingGroundsPodcast
    @TheChewingGroundsPodcast 3 ปีที่แล้ว

    Woah learned a lot! Amazing podcast!! I love the topics discussed. I’ll be taking away some from this for my podcast. I’m a new fan and supporter, keep up the great work. I just uploaded a podcast on my channel too!