The BlueHat Podcast cover art

The BlueHat Podcast

By: Microsoft
  • Summary

  • Since 2005, BlueHat has been where the security research community, and Microsoft, come together as peers; to debate, discuss, share, challenge, celebrate and learn. On The BlueHat Podcast, Microsoft and MSRC’s Nic Fillingham and Wendy Zenone will host conversations with researchers and industry leaders, both inside and outside of Microsoft, working to secure the planet’s technology and create a safer world for all.

    Hosted on Acast. See acast.com/privacy for more information.

    ©2024 Microsoft
    Show More Show Less
Episodes
  • From Specs to Security
    May 15 2024

    Dor Dali, Head of Security Research at Cyolo, joins Nic Fillingham on this week's episode of The BlueHat Podcast. They delve into Dor's journey into cybersecurity, from pranking friends as a teenager to his professional roles, including his involvement in the Blue Hat conference through GE, where he helped create the Capture The Flag (CTF) challenge. Dor details the vulnerabilities in the RDP protocol by closely following the protocol specifications and identifying discrepancies that led to security flaws. They detail a vulnerability related to RDP Gateway's UDP cookie authentication process, the implications of Dor's research for other security researchers and hackers and the importance of leveraging available resources, such as protocol specifications and open-source implementations, to understand closed-source systems better and potentially uncover vulnerabilities.

    In This Episode You Will Learn:

    • The unique perspective Dor has with RDP security research
    • How to approach security research when following the protocol specifications
    • The importance of clear documentation in preventing security vulnerabilities

    Some Questions We Ask:

    • How did you design and build the Capture the Flag event?
    • Did you face any unexpected hurdles while researching the RDP protocol's security?
    • Have you found other security vulnerabilities by closely adhering to protocol specifications?

    Resources:

    View Dor Dali on LinkedIn

    View Wendy Zenone on LinkedIn

    View Nic Fillingham on LinkedIn

    Related Microsoft Podcasts:

    • Microsoft Threat Intelligence Podcast
    • Afternoon Cyber Tea with Ann Johnson
    • Uncovering Hidden Risks

    Discover and follow other Microsoft podcasts at microsoft.com/podcasts


    Hosted on Acast. See acast.com/privacy for more information.

    Show More Show Less
    34 mins
  • Beyond the Code: Ethics and AI with Katie Paxton-Fear
    May 1 2024

    Cyber Security Content Creator, Speaker & Ethical Hacker, Katie Paxton-Fear, joins Nic Fillingham on this week's episode of The BlueHat Podcast. Katie holds a PhD in defense and security AI plus cybersecurity and works as an academic, teaching undergraduate students cybersecurity topics. She also runs a popular YouTube channel focused on bug bounty hunting, hacking, and pen testing. Katie shares her journey into cybersecurity, reflects on her initial interest in undeciphered languages and how it parallels her approach to cybersecurity, both involving a fascination with solving mysteries and uncovering hidden meanings.


    In This Episode You Will Learn:

    • Approaching AI systems with caution when translating less-documented languages
    • Concerns surrounding the use of copyrighted training data in AI systems
    • Recognizing and addressing AI system limitations and biases in real-world deployments.

    Some Questions We Ask:

    • Can fine-tuning AI models prevent degradation and improve performance?
    • What are the ethical implications of putting sensitive information into AI systems
    • How does relying on niche or obscure training data impact AI models?

    Resources:

    View Katie Paxton-Fear on LinkedIn

    View Wendy Zenone on LinkedIn

    View Nic Fillingham on LinkedIn

    Related Microsoft Podcasts:

    • Microsoft Threat Intelligence Podcast
    • Afternoon Cyber Tea with Ann Johnson
    • Uncovering Hidden Risks

    Discover and follow other Microsoft podcasts at microsoft.com/podcasts


    Hosted on Acast. See acast.com/privacy for more information.

    Show More Show Less
    44 mins
  • SaaS Exposed: Unmasking Cyber Risks in Cloud Integrations
    Apr 17 2024

    Luke Jennings, VP of Research & Development at Push Security joins Wendy Zenone and Nic Fillingham on this week's episode of The BlueHat Podcast. Luke explains his recent presentation on a new SaaS cyber kill chain, exploring how attackers might target modern organizations heavily reliant on cloud and SaaS services, even when traditional infrastructure is minimal. The latest kill chain involves developing attack techniques specific to this environment, covering topics like lateral movement without conventional network infrastructure and adapting known techniques such as password guessing attacks to the SaaS landscape. Luke, Wendy, and Nic discuss the complexities of SaaS security, the intricacies of evil twin integrations, detection challenges, mitigation strategies, and the overall impact of these security issues on organizations.

    In This Episode You Will Learn:

    • Identifying malicious activities and understanding normal application behavior
    • The importance of having structured methodologies for approving SaaS app usage
    • Challenges organizations face in detecting and preventing SaaS application threats

    Some Questions We Ask:

    • How can an organization create alerts for new, unknown SaaS app integrations?
    • What happens when a SaaS app integration is duplicated by an attacker?
    • Would having a structured methodology for SaaS app usage help minimize risk?

    Resources:

    View Luke Jennings on LinkedIn

    View Wendy Zenone on LinkedIn

    View Nic Fillingham on LinkedIn

    Related Microsoft Podcasts:

    • Microsoft Threat Intelligence Podcast
    • Afternoon Cyber Tea with Ann Johnson
    • Uncovering Hidden Risks

    Discover and follow other Microsoft podcasts at microsoft.com/podcasts


    Hosted on Acast. See acast.com/privacy for more information.

    Show More Show Less
    39 mins

More from the same

What listeners say about The BlueHat Podcast

Average Customer Ratings

Reviews - Please select the tabs below to change the source of reviews.

In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.