Bryan Brake, Amanda Berlin, and Brian Boettcher

BrakeSec Education Podcast

News EN ↓ 463 episodes

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Author

Bryan Brake, Amanda Berlin, and Brian Boettcher

Category

News

Podcast website

www.youtube.com

Latest episode

Jul 17, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

logging analysis, log correlation, and threat analysis dicussion continues - p2 10.04.2022

https://twitch.tv/brakesec www.brakeingsecurity.com @infosystir on Twitter @bryanbrake @boettcherpwned

Amanda and Bryan discusses log analysis, finding, IOCs, and what to do about them. 05.04.2022

https://twitch.tv/brakesec www.brakeingsecurity.com @infosystir on Twitter @bryanbrake @boettcherpwned

Shannon Noonan and Stacey Cameron - process automation -p2 22.03.2022

Shannon Noonan and Stacey Cameron - QoS Consulting https://www.bizagi.com/en/blog/digital-process-automation/4-ways-to-deliver-change-management-for-process-automation https://www.forrester.com/blogs/the-new-change-management-automated-and-decentralized/   https://www.tibco.com/reference-center/what-is-process-automation   https://kissflow.com/workflow/workflow-automation/an-8-step-checklist-to-ge...

Shannon Noonan and Stacey Cameron - process automation 12.03.2022

https://www.twitch.tv/brakesec Youtube video (full version): https://www.youtube.com/watch?v=eRwYB22XMNw Shannon Noonan and Stacey Cameron - QoS Consulting https://www.bizagi.com/en/blog/digital-process-automation/4-ways-to-deliver-change-management-for-process-automation https://www.forrester.com/blogs/the-new-change-management-automated-and-decentralized/   https://www.tibco.com/reference-center...

K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p2 01.03.2022

For context, we at the K12 Security Information Exchange (K12 SIX) are a relatively new K12-specific ISAC – launched to help protect the US K12 sector from emerging cybersecurity risk. One of our signature accomplishments in our first year was the development and release of our 'essential protections' series – an effort to establish baseline cybersecurity standards for schools. See: https://www.k1...

K12SIX's Eric Lankford and Doug Levin on helping schools get added security -p1 22.02.2022

The K12 Security Information Exchange (K12 SIX) are a relatively new K12-specific ISAC – launched to help protect the US K12 sector from emerging cybersecurity risk. One of our signature accomplishments in our first year was the development and release of our 'essential protections' series – an effort to establish baseline cybersecurity standards for schools. See: https://www.k12six.org/essential-...

April Wright and Alyssa Miller - IoT platforms, privacy and security, embracing standards 15.02.2022

Alyssa Milller (@AlyssaM_InfoSec) April Wright (@Aprilwright)   Open Source issues (quick discussion, because I value your opinions, and supply chain is important in the IoT world too.) Log4j and OSS software management and profitability Free as in beer, but you pay for the cup… (license costs $$, not the software).  "If you make money using our software, you must buy a license" - not an end-user...

Alyssa Miller, April Wright, on IoT Privacy & Security, using tech for stalking, what could be done? Part1 07.02.2022

Alyssa Milller (@AlyssaM_InfoSec) April Wright (@Aprilwright) Talk about side projects, podcasts, speaking events, etc (if you want to) Open Source issues (quick discussion, because I value your opinions, and supply chain is important in the IoT world too.) Log4j and OSS software management and profitability Free as in beer, but you pay for the cup… (license costs $$, not the software).  "If you m...

Bit of news, Belarus train system hack, VMware Horizon vulns, edge network device vulns 01.02.2022

News articles we covered this week: https://www.wired.com/story/belarus-railways-ransomware-hack-cyber-partisans/ https://www.hackingarticles.in/linux-privilege-escalation-polkit-cve-2021-3560/ https://old.reddit.com/r/msp/comments/s48iji/vmware_horizon_servers_being_actively_hit_with/ https://www.bleepingcomputer.com/news/security/over-20-000-data-center-management-systems-exposed-to-hackers/ Whi...

April Wright and Alyssa Miller- Open Source sustainabilty 24.01.2022

Alyssa Milller (@AlyssaM_InfoSec) April Wright (@Aprilwright) 0. Open Source issues (quick discussion, because I value your opinions, and supply chain is important in the IoT world too.) Log4j and OSS software management and profitability Free as in beer, but you pay for the cup… (license costs $$, not the software).  "If you make money using our software, you must buy a license" - not an end-user...

Amélie Koran and Adam Baldwin discuss OSS sustainability, supply chain security,, governance, and outreach for popular applications - part2 18.01.2022

Adam Baldwin (@adam_baldwin) Amélie Koran (@webjedi)   https://logging.apache.org/log4j/2.x/license.html https://www.theregister.com/2021/12/14/log4j_vulnerability_open_source_funding/ https://www.zdnet.com/article/security-firm-blumira-discovers-major-new-log4j-attack-vector/ F/OSS developer deliberately bricks his software in retaliation for big companies not supporting OSS. https://twitter.com/...

OSS sustainability, log4j fallout, developer damages own code-p1 12.01.2022

Adam Baldwin (@adam_baldwin) Amélie Koran (@webjedi)   Log4j vulnerability   https://logging.apache.org/log4j/2.x/license.html https://www.theregister.com/2021/12/14/log4j_vulnerability_open_source_funding/ https://www.zdnet.com/article/security-firm-blumira-discovers-major-new-log4j-attack-vector/   F/OSS developer deliberately bricks his software in retaliation for big companies not supporting O...

2021-046-Mick Douglas, Log4j vulnerabilities, egress mitigations- part2 23.12.2021

  Introduction Overview of Log4j vuln (as of 16 December 2021) Why is it a big deal? (impact/criticality/risk) Talk about patching vs. mitigation why wasn't this given the same visibility in 2009? Because it's Oracle or Java? Good callout is building slides to brief org leadership, detections, and other educational tools. Vuln fatigue (Java vulns in 2009 and pretty much forever cause us fatigue) A...

2021-045-Mick Douglas, Log4j vulnerabilities, egress mitigations- part1 16.12.2021

Introduction Overview of Log4j vuln (as of 16 December 2021) Why is it a big deal? (impact/criticality/risk) Talk about patching vs. mitigation why wasn't this given the same visibility in 2009? Because it's Oracle or Java? Good callout is building slides to brief org leadership, detections, and other educational tools. Vuln fatigue (Java vulns in 2009 and pretty much forever cause us fatigue) Are...

2021-044-Litmoose discusses stalking and protecting yourself 13.12.2021

New $3 patron! 🎉Thank you John K.!   National Domestic Violence Hotline at 1-800-799-7233, or by online chat. National Sexual Assault Hotline at 1-800-656-4673, or by online chat. https://www.stalkingawareness.org/wp-content/uploads/2019/01/SPARC_StalkngFactSheet_2018_FINAL.pdf TALKING VICTIMIZATION  An estimated 6-7.5 million people are #stalked in a one year period in the United States.  Nearly...

2021-043- Fred Jennings, Vuln Disclosure policy, VEP, and 0day disclosure - p2 21.11.2021

https://twitter.com/Esquiring - Fred Jennings   Vulnerabilities Equity program (VEP), vuln disclosure program (VDP), and what is the a way for disclosure of 0day? ('proper' is different and dependent)   This show was inspired by this Tweet thread from @k8em0 and @_MG_ https://twitter.com/k8em0/status/1459715464691535877 https://twitter.com/_MG_/status/1459718518346174465   Legal Safe Harbor? Copy-...

2021-042- Fred Jennings, VDP, Vuln Equity, And 0day disclosure - p1 21.11.2021

https://twitter.com/Esquiring - Fred Jennings Vulnerabilities Equity program (VEP), vuln disclosure program (VDP), and what is the best way for disclosure of 0day? ('proper' is different and dependent) This show was inspired by this Tweet thread from @k8em0 and @_MG_ https://twitter.com/k8em0/status/1459715464691535877 https://twitter.com/_MG_/status/1459718518346174465   Legal Safe Harbor? Copy-l...

Blumira Sponsor #3 - Emily Eubanks, more actionable events, incident response help, and more 21.11.2021

In this sponsored BDS episode, Bryan Brake and Amanda Berlin interview Emily Eubanks, a Security Operations Analyst for #Blumira. We discuss common business risks like IT staff turnover, a lack of Incident Response procedures, choosing not to follow PowerShell best practices, and MFA use for critical or sensitive applications. We also discuss ways to improve security posture to mitigate these risk...

2021-041-0day disclosure, Randori, FBI email server pwnage 16.11.2021

https://www.bleepingcomputer.com/news/security/us-education-dept-urged-to-boost-k-12-schools-ransomware-defenses/ https://securityaffairs.co/wordpress/124570/cyber-crime/fbi-hacked-email-server.html https://www.zdnet.com/article/security-company-faces-backlash-for-waiting-12-months-to-disclose-palo-alto-0-day/   https://www.randori.com/blog/why-zero-days-are-essential-to-security/ https://twitter....

2021-040-Sweden's parents rebel over poor App design, US government forcing patching of systems, and Vuln chaining 08.11.2021

News stories covered this week, as well as links of note: https://www.wired.co.uk/article/sweden-stockholm-school-app-open-source https://curtbraz.medium.com/a-konami-code-for-vuln-chaining-combos-1a29d0a27c2a     https://docs.google.com/presentation/d/17gISafUZzEyjV7wkdHaTQZmtxstBqECa/edit#slide=id.p4   https://www.securityweek.com/braktooth-new-bluetooth-vulnerabilities-could-affect-millions-dev...

2021-039-Minimum Viable vendor security sheet, Federal logging requirements, and more! 02.11.2021

https://securityaffairs.co/wordpress/123948/security/2021-list-of-most-common-hardware-weaknesses.html ?   https://www.whitehouse.gov/wp-content/uploads/2021/08/M-21-31-Improving-the-Federal-Governments-Investigative-and-Remediation-Capabilities-Related-to-Cybersecurity-Incidents.pdf    https://www.darkreading.com/application-security/tech-companies-create-security-baseline-for-enterprise-software...

SPONSOR-Blumira's Nato Riley on Log Classification, Security Maturity, 01.11.2021

 From Nato's email: Hi Bryan,   Discussing the challenges that come with not having good logging in place could be a great topic!  We could make it partly about how security maturity works, in the idea that security generally starts with awareness and visibility.   The topic sort of gets into the idea that knowing is half the battle, so logging can be transformative for helping a company properly...

2021-038-Liz Saling, 5 pillars of building a good team 25.10.2021

Blog post that inspired this episode: https://lizsaling.com/SWE-team-five-pillars/   Liz Saling  (@lizsaling) https://www.mindtools.com/pages/article/newLDR_86.htm http://www.mspguide.org/tool/tuckman-forming-norming-storming-performing https://michaelhyatt.com/3-roadblocks-to-avoid-for-optimal-team-performance Erin meyer is the one who did the netflix study! https://bigthink.com/the-present/high-...

2021-037-Tony Robinson, leveraging your home lab for job success - Part2 17.10.2021

Tony Robinson (@da_667) Thought we'd put in a little news to round out the show https://www.bbc.com/news/world-us-canada-58863678 - nuclear secrets hidden in a peanut butter sandwich https://www.theregister.com/2018/04/20/rsa_security_conference_insecure_mobile_app/ https://www.vice.com/en/article/jg8w9b/the-twitch-hack-is-worse-for-streamers-than-for-twitch https://nakedsecurity.sophos.com/2021/1...

2021-036-Tony Robinson, twtich breach, @da_667 lab setup new book edition! -part1 14.10.2021

Tony Robinson (@da_667) Thought we'd put in a little news to round out the show https://www.bbc.com/news/world-us-canada-58863678 - nuclear secrets hidden in a peanut butter sandwich https://www.theregister.com/2018/04/20/rsa_security_conference_insecure_mobile_app/ https://www.vice.com/en/article/jg8w9b/the-twitch-hack-is-worse-for-streamers-than-for-twitch https://nakedsecurity.sophos.com/2021/1...

Listen to the BrakeSec Education Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.