Andy Jaw & Adam Brewer

Blue Security

A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.

Author

Andy Jaw & Adam Brewer

Category

Technology

Podcast website

bluesecuritypod.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

What we learned in 2022 in cybersecurity 02.01.2023

On this week's episode, Adam and Andy talk about some trends from this past year and what they would focus on securing for 2023. ------------------------------------------- Youtube Video Link:  https://youtu.be/x_Yx42cKa0A ------------------------------------------- Documentation: https://techcrunch-com.cdn.ampproject.org/c/s/techcrunch.com/2022/12/22/okta-breach-source-code-github/amp/ https...

Windows Autopatch with Special Guest Adam Nichols 26.12.2022

On this week's episode, Adam and Andy talk with Adam Nichols, a Product Manager for Windows Autopatch. They talk about all things patching and do a deep dive on how the Windows Autopatch service works. Listen in if you're curious about the service and how to take advantage of it! ------------------------------------------- YouTube Video Link: https://youtu.be/LCFA8D9pbCA --------------------------...

Passkeys 19.12.2022

On this week's episode, Adam and Andy talk about passkeys. This may be the replacement for passwords that we're looking for and it is starting to go mainstream with the collaboration between Microsoft, Apple, and Google. ------------------------------------------- YouTube Video Link: https://youtu.be/xYdtTWczwxQ ------------------------------------------- Documentation: https://passkeys.directory/...

Microsoft's Insider Risk Report 12.12.2022

On this week's episode, Adam and Andy talk about Microsoft's Insider Risk Report for 2022. This report give insight on how to build a holistic insider risk program but combining tooling, people management, trust, and processes. Insider risk is on the rise. Listen in as Andy and Adam break down the report and give you the highlights on how to get started on building your insider risk program. -----...

DDoS Protection 05.12.2022

On this week's episode, Adam and Andy talk about CISA's DDoS protection guidance. This follows the episode on Microsoft's Digital Defense Report where DDoS attacks and protections were also highlighting in the report. ------------------------------------------- YouTube Video Link: https://youtu.be/_9puZjc05H4 ------------------------------------------- Documentation: https://www.cisa.gov/sites/def...

Microsoft's Digital Defense Report 28.11.2022

On this week's episode, Adam and Andy talk about Microsoft's Digital Defense Report. This report has a wealth of information on the state of cybersecurity, current trends, attack vectors, and defense suggestions for organizations. They break down some key points so listen in if you do not have time to read the entire report. ------------------------------------------- YouTube Video Link: https://y...

How to Mastodon 21.11.2022

On this week's episode, Adam is back and joined by Andy to talk about Mastodon. This decentralized social media platform has been around since 2016 and recently has been growing exponentially due to the Twitter migration. Critical mass has already happened for many communities including the infosec community so it is in our best interest to learn about it and learn how to use it. -----------------...

Patch Tuesday, Medibank Breach, Twitter Meltdown 14.11.2022

This week, friend of the pod, Shannon Fritz, fills in for Adam and he and Andy talk about the big update for Patch Tuesday, the Medibank double extortion incident, and the meltdown happening at Twitter. ------------------------------------------- Youtube Video Link: ------------------------------------------- Documentation: https://support.microsoft.com/en-us/topic/november-8-2022-kb5019980-os-bui...

Old Phishing Tricks Are Still Working 07.11.2022

This week, Adam and Andy talk about the Dropbox and Twilio breach where old phishing tricks worked and attackers were able to get credentials. They also talk about CISA's new guidance on phish resistant MFA and Enhance Phishing Protection in Windows 11 22H2. ------------------------------------------- Youtube Video Link: https://youtu.be/06lGGC6GSJM ------------------------------------------- Docu...

SOCRadar and Ignite 2022 highlights 31.10.2022

This week, Adam and Andy talk about the SOCRadar disclosure of a misconfigured Microsoft endpoint that led to a data privacy incident. They talk about what happened and what you should know as a Microsoft customer. They also go over some of the highlights from Ignite 2022 with new features and brands for endpoint management, identity, and security. ------------------------------------------- Youtu...

IBM Incident Responder Report 24.10.2022

This week, Adam and Andy talk about IBM's Incident Responder Report. This report has some great empirical data on incident responder perceptions and how incidents impact mental health. Listen in as they discuss some of the key findings in this report. ------------------------------------------- Youtube Video Link: https://youtu.be/hhnxHMbvASw ------------------------------------------- Documentati...

BYOD Zero-Trust Architecture 17.10.2022

This week, Adam and Andy talk about how to look at BYOD policies in a Zero-Trust architecture. They go over a blueprint put out by Microsoft Middle East and Africa that's a little bit older but is a great reference for anyone looking for guidance. ------------------------------------------- Youtube Video Link:  https://youtu.be/pze2b0Ix8QI ------------------------------------------- Documenta...

MDE Tamper Protection 10.10.2022

This week, Adam and Andy talk about Microsoft Defender for Endpoint's Tamper Protection. This type of feature is also available on other endpoint protection solutions. They talk about what it is, what's changing soon, and why you should turn this on. ------------------------------------------- Youtube Video Link: https://youtu.be/ZhhlianhqgY ------------------------------------------- Documentatio...

Active Directory Security Tips 03.10.2022

This week, Adam and Andy talk about some tips on securing Active Directory. This was inspired by a session led by Trimarc Security at The Experts Conference. ------------------------------------------- Youtube Video Link: https://youtu.be/7HQZQh-UzmQ ------------------------------------------- Documentation: https://www.trimarcsecurity.com/ https://www.quest.com/the-experts-conference/ https://www...

Kerberoasted 26.09.2022

This week, Adam and Andy talk about kerberoasting: how it works and how to defend against it. Listen in on this unique attack technique! ------------------------------------------- Youtube Video Link: https://youtu.be/sr75jgscnkQ ------------------------------------------- Documentation: https://www.linkedin.com/posts/heathadams_i-got-domain-admin-on-an-internal-pentest-activity-697604783669396684...

Microsoft Teams, Patreon, and Uber 19.09.2022

This week, Adam and Andy talk about Microsoft Teams and the post-exploit technique that was discovered by Vetra's Project Team and the decision of Patreon to lay off their entire internal information security team. The also talk about Uber's on-going cybersecurity incident including some initial reports of how it happened as well as mitigations to prevent this type of attack in the future. -------...

Cloudflare and Kiwi Farms 12.09.2022

This week, Adam and Andy breakdown what led to Cloudflare dropping Kiwi Farms as a customer, why the media and Twitter were up-in-arms about the whole incident, and their thoughts about the decision. ------------------------------------------- Youtube Video Link: https://youtu.be/NrNe_n95Tfk ------------------------------------------- Documentation: https://blog.cloudflare.com/cloudflares-abuse-po...

Cloud Security 101 05.09.2022

This week, Adam and Andy talk about cloud security. If you're looking to learn about cloud security concepts, this is the show for you. They talk about basic and advanced security as well as risk assessment and other things you should consider when designing and architecting your security in the cloud. ------------------------------------------- Youtube Video Link: https://youtu.be/1sc1R8iL3wc ---...

Beyond E5, Rebranding, Public Previews in Microsoft Security 29.08.2022

This week, Adam and Andy pull together all the new product launches and rebranding for Microsoft Security over the last couple of months. Listen in to learn about Microsoft Entra, Defender Threat Intel, App Governance, and Threat Experts. ------------------------------------------- Youtube Video Link: https://youtu.be/PSm97tY4q1E ------------------------------------------- Documentation: https://w...

Quantum & Cryptography Follow-up, TikTok, and Janet Jackson 22.08.2022

This week, Adam and Andy follow up on a few things from the post quantum cryptography episode talking about how one of the quantum resistant algorithms was broken and a lawsuit against the US government related to quantum encryption. They also chat about how TikTok may be storing information of US citizens on Chinese servers. Finally, they talk about how sound can be used as a cyber attack vector....

Post Quantum Series - Part 2 - Quantum Cryptography 15.08.2022

This week, Adam and Andy talk about post quantum cryptography this week. They go over why quantum computers are a threat to classical cryptography like public key encryption, quantum key distribution, and finally NIST's selection of quantum resistant cryptography. ------------------------------------------- Youtube Video Link:  https://youtu.be/v8CVq09tnB4 ------------------------------------...

Post Quantum Series - Part 1 - Quantum Computers 08.08.2022

This week, Adam and Andy start a two part series on post-quantum computer information security. This first part goes into understanding how quantum computers work and how they differ from classical computers. While it's not necessary to understand how quantum computers work to know the threat to information security they have, as technologist, it's always fun to expand our knowledge on these topic...

Exchange Online Protection Deep-Dive 01.08.2022

This week, Adam and Andy do a technical deep dive on Exchange Online Protection (EOP). They talk about the pre-delivery and post-delivery protections. They also talk about some of the zero-day protections that Defender for Office 365 provides similar to other competitors in the space and MX record vs API protection. ------------------------------------------- Youtube Video Link:  https://yout...

Personal and Organization Privacy 25.07.2022

This week, Adam and Andy talk about privacy both in organizations and your personal life. They talk about some of the new Microsoft Purview Compliance Classifiers and how it might be an invasive for some orgs when implemented in the wrong way. They also talk about mobile device privacy in light of SCOTUS overturning Roe v Wade and how our data might be weaponized against us. Finally, they tal...

Microsoft Security News 18.07.2022

This week, Adam and Andy talk about some security news relating to Microsoft. First they talk about a phishing campaign that Microsoft detailed that was going on affecting more than 10,000 orgs where the attackers are able to bypass MFA. They also talk about Microsoft's decision to roll back disabling VBA macros by default. Finally, they talk about Microsoft's DART team and how they approach ranso...

Listen to the Blue Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.