Bryan Brake, Amanda Berlin, and Brian Boettcher

BrakeSec Education Podcast

News EN ↓ 463 episodes

A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.

Author

Bryan Brake, Amanda Berlin, and Brian Boettcher

Category

News

Podcast website

www.youtube.com

Latest episode

Jul 17, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

2020-035-ransomware death in Germany, Zerologon woes, drovorub, and corp data on personal devices 29.09.2020

FIND US NOW ON AMAZON MUSIC! https://music.amazon.com/podcasts/51b7da82-c223-4de4-8fc1-d1c3dd61984a/Brakeing-Down-Security-Podcast Shout to the organizers of Bsides Edmonton, Alberta, Canada for a great conference! Amanda's social media take over this week Bryan's plumbing story (A tale of 3 toilets) https://www.infosecurity-magazine.com/news/corporate-data-on-personal-devices/ https://www.infosec...

2020-034-Fortnite account selling, process change agility, IRS wanting to track the 'untrackable' 14.09.2020

https://www.kitploit.com/2020/05/web-hackers-weapons-collection-of-cool.html   https://www.ehackingnews.com/2020/09/hackers-attack-gaming-industry-sell.html   https://www.secjuice.com/windows-10-penetration-testing-os/ Nice to see stories about using Win10 as a pentest platform. Was always a PITA to update Kali or whatever. @secjuice One reason I enjoyed Dave Kennedy's 'pentester framework' --brbr...

2020-033-garmin hack, Tesla employee thwarted IP espionage, Slack RCE payout, and more! 31.08.2020

WWFH Class: (Ms. Berlin) "Breaching the Cloud" @dafthack   https://www.blackhillsinfosec.com/breaching-the-cloud-perimeter-w-beau-bullock/   https://wildwesthackinfest.com/wwhf-at-secure-wv/   IWCE 2020 panel: "Being a thought leader"   ADKAR class Book Club: 03 September 2020 7pm: https://smile.amazon.com/ADKAR-Change-Business-Government-Community/dp/1930885504/ref=sr_1_1?dchild=1&keywords=ADKAR&...

2020-032-Dr. Allan Friedman, SBOM, Software Transparency, and how the sausage is made - Part 2 24.08.2020

Ms. Berlin: Tabletop D&D exercise     Blumira is hiring https://www.blumira.com/career/lead-backend-engineer/   Allan Friedman - Director of Cybersecurity Initiatives, NTIA, US Department of Commerce   NTIA.gov - National Telecommunications and Information Administration   https://www.ntia.gov/sbom   SBOM guidance   Healthcare SBOM PoC - https://www.ntia.gov/files/ntia/publications/ntia_sbom_healt...

2020-031-Allan Friedman, SBOM, software transparency, and knowing how the sausage is made 18.08.2020

  Ms. Berlin: Tabletop D&D exercise Blumira is hiring https://www.blumira.com/career/lead-backend-engineer/   Allan Friedman - Director of Cybersecurity Initiatives, NTIA, US Department of Commerce NTIA.gov - National Telecommunications and Information Administration https://www.ntia.gov/sbom   SBOM guidance Healthcare SBOM PoC - https://www.ntia.gov/files/ntia/publications/ntia_sbom_healthcare_po...

2020-030- Mick Douglas, Defenses against powercat, offsec tool release, SRUM logs, and more! 10.08.2020

WISP.org donation page: https://wisporg.z2systems.com/np/clients/wisporg/donation.jsp Mick Douglas (@bettersafetynet on Twitter) Powercat: https://github.com/besimorhino/powercat Netcat in a powershell environment https://blog.rapid7.com/2018/09/27/the-powershell-boogeyman-how-to-defend-against-malicious-powershell-attacks/ https://www.hackingarticles.in/powercat-a-powershell-netcat/ Defenses agai...

2020-029- Brad Spengler, Linux kernel security in the past 10 years, software dev practices in Linux, WISP.org PSA 31.07.2020

WISP.org PSA at 35m56s - 37m 19s   Agenda: Bio/background Why are you here (topic discussion) What is the Linux Security Summit North America https://grsecurity.net/   Questions from the meeting invite:   This only affects people who want to use a custom kernel, correct? This doesn't affect you if you are running bog-standard linux (debian, gentoo, Ubuntu) right? What options do people have in clo...

2020-028-Shlomi Oberman, RIPPLE20, supply chain security discussion, software bill of materials 24.07.2020

Whitepaper:  https://www.jsof-tech.com/ripple20/ [blog] Build your own custom TCP/IP stack:  https://www.saminiir.com/lets-code-tcp-ip-stack-1-ethernet-arp/ Another custom TCP/IP stack:  https://github.com/tass-belgium/picotcp RIPPLE 20 Whitepaper:  https://drive.google.com/file/d/1d3NNVCRPVFk0-V0HUO5CxWWVn9pYIvmF/view?usp=sharing   Agenda: Part 1: Background on the report Why is it called RIPPLE2...

2020-027-RIPPLE20 Report, supply chain security, responsible disclosure, software development, and vendor care. 16.07.2020

Whitepaper: https://www.jsof-tech.com/ripple20/ [blog] Build your own custom TCP/IP stack: https://www.saminiir.com/lets-code-tcp-ip-stack-1-ethernet-arp/ Another custom TCP/IP stack: https://github.com/tass-belgium/picotcp RIPPLE 20 Whitepaper: https://drive.google.com/file/d/1d3NNVCRPVFk0-V0HUO5CxWWVn9pYIvmF/view?usp=sharing   Agenda: Part 1: Background on the report Why is it called RIPPLE20? W...

2020-026- WISP PSA, PAN-OS vuln redux, F5 has a bad weekend, vuln scoring, Twitter advice, and more! 08.07.2020

1st: WISP.org PSA from Rachel Tobac (@racheltobac) & @wisporg talking about #shareTheMicInCyber #SAML PAN-OS: https://twitter.com/RyanLNewington/status/1278074919092289537  F5 vulnerability: https://www.wired.com/story/f5-big-ip-networking-vulnerability/ https://research.nccgroup.com/2020/07/05/rift-f5-networks-k52145254-tmui-rce-vulnerability-cve-2020-5902-intelligence/   F5 Mitigation (if patchi...

2020-025-Cognizant breach, maze ransomware, PAN-OS CVE 2020-2021, SAML authentication walkthrough 29.06.2020

Thank you to Marcus Carey for his excellent guidance and leadership this week.   Cognizant breach: https://www.ehackingnews.com/2020/06/cognizant-reveals-employees-data.html Maze ransomware write-up: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/ransomware-maze/ https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html...

2020-024-Bit of news, Ripple20 vulns, IoT Security, windows error codes, captchas used for evil, Marine Momma 24.06.2020

https://blog.xpnsec.com/hiding-your-dotnet-complus-etwenabled/   https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3 https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4657 https://www.blumira.com/logmira-windows-logging-policies-for-better-threat-detection/   How would we map this against the MITRE matrix? Are there any MITRE attack types that are...

2020-023-James Nelson from Illumio, cyber resilence, business continuity 17.06.2020

James Nelson, VP of Infosec, Illumio How has COVID-19 changed cybersecurity? Why is cyber resilience especially important now? What are the most important steps to ensure cyber-resiliency? How do you talk to business leaders about investing in cybersecurity to boost resiliency? The best way for organizations to keep their 'crown jewels' secure is adopting a Zero Trust mindset. Organizations need t...

2020-022-Andrew Shikiar, FIDO Alliance, removing password from IoT, and discussing FIDO implementation 10.06.2020

Andrew Shikiar, executive director and CMO of the (Fast IDentity Online) FIDO Alliance.   What is FIDO? " open industry association launched in February 2013 whose mission is to develop and promote authentication standards that help reduce the world's over-reliance on passwords . FIDO addresses the lack of interoperability among strong authentication devices and reduces the problems users face cre...

2020-021- Derek Rook, redteam tactics, blue/redteam comms, and detection of testing 01.06.2020

**If Derek told you about us at SANS, send a DM to @brakeSec or email bds.podcast@gmail.com for an invite to our slack** OSCP/HtB/VulnHub is a game... d esigned to have a tester find a specific nugget of information to pivot or gain access to greater power on the system.  Far different in the 'real' world.   Privilege escalation in Windows: *as of June 2020, many of these items still work, may not...

2020-020-Andrew Shikiar - FIDO Alliance - making Cybersecurity more secure 27.05.2020

  Andrew Shikiar, executive director and CMO of the (Fast IDentity Online) FIDO Alliance.   What is FIDO? " open industry association launched in February 2013 whose mission is to develop and promote authentication standards that help reduce the world's over-reliance on passwords . FIDO addresses the lack of interoperability among strong authentication devices and reduces the problems users face c...

2020-019-Masha Sedova, customized training, phishing, ransomware, and privacy implications 20.05.2020

Masha Sedova - Founder, Elevate Security   Topic ideas from the PR company:   Inability to measure human security behaviors leads to increased risk in our computing environments. For too long, we've accepted training completion and mock phishing data as a sufficient way to measure this risk. But where do the vulnerabilities and strengths truly lie?    The secret is, security teams have installed t...

2020-018- Masha Sedova, bespoke security training, useful metrics to tailor training 13.05.2020

Masha Sedova - Founder, Elevate Security Inability to measure human security behaviors leads to increased risk in our computing environments. For too long, we've accepted training completion and mock phishing data as a sufficient way to measure this risk. But where do the vulnerabilities and strengths truly lie?  The secret is, security teams have installed tons of security tooling that can give i...

2020-017-Cameron Smith, business decisions, and how it affects Security 05.05.2020

Cameron Smith  @Secnomancer   Layer8conference is virtual (https://layer8conference.com/layer-8-is-online-this-year/) https://csrc.nist.gov/publications/detail/sp/800-171/rev-1/final   CMMC: https://info.summit7systems.com/blog/cmmc https://www.comptia.org/certifications/project  - Project+ Cameron's Smith =  www.twitter.com/secnomancer Cybersmith.com - Up by 14 April   Ask@thecybersmith.com Camer...

2020-016-Cameron Smith, Business decisions and their (in)secure outcomes - Part 1 29.04.2020

Cameron Smith @Secnomancer   Layer8conference is virtual (https://layer8conference.com/layer-8-is-online-this-year/) https://csrc.nist.gov/publications/detail/sp/800-171/rev-1/final   CMMC: https://info.summit7systems.com/blog/cmmc https://www.comptia.org/certifications/project - Project+ Cameron's Smith = www.twitter.com/secnomancer Cybersmith.com - Up by 14 April   Ask@thecybersmith.com Cameron@...

2020-015-Tanya_Janca-Using Github Actions in your Devops Environment, workflow automation 21.04.2020

Github actions - https://github.com/features/actions How are these written?  It looks like a marketplace format? How do they maintain code quality? What does it take setup the actions? It looks like IFTTT for DevOps? What kind of integrations does it allow for? Will it handle logins or API calls for you? Is it moderated in some way? What's the acceptance criteria for these? What are you trying to...

2020-014-Server Side Request Forgery defense, Tanya Janca, AppSec discussion 14.04.2020

Tanya's AppSec Course https://www.shehackspurple.dev/server-side-request-forgery-ssrf-defenses https://www.shehackspurple.dev Server-side request forgery - https://portswigger.net/web-security/ssrf What are differences between Stored XSS and SSRF?  This requires a MITM type of issue? Doesn't stored XSS get stored on the server? What conditions must exist for SSRF to be possible? What mitigations n...

2020-013- part 2, education security, ransomware, april mardock, Nathan McNulty, and Jared folkins 07.04.2020

April Mardock - CISO - Seattle Public Schools Jared Folkins - IT Engineer - Bend La Pine Schools Nathan McNulty - Information Security Architect - Beaverton School District   OpSecEdu -  https://www.opsecedu.com/ Slack   https://www.a4l.org/default.aspx     https://clever.com/     BEC -  https://www.trendmicro.com/vinfo/us/security/definition/business-email-compromise-(bec)     https://www.k12cybe...

2020-012-April Mardock, Nathan McNulty, Jared Folkins, school security, ransomware attacks 29.03.2020

April Mardock - CISO - Seattle Public Schools Jared Folkins - IT Engineer - Bend La Pine Schools Nathan McNulty - Information Security Architect - Beaverton School District   OpSecEdu - https://www.opsecedu.com/ Slack   https://www.a4l.org/default.aspx     https://clever.com/     BEC - https://www.trendmicro.com/vinfo/us/security/definition/business-email-compromise-(bec)     https://www.k12cybers...

2020-011-Alyssa miller, deep fakes, threatmodeling for Devops environments, and virtual conferences 25.03.2020

https://twitter.com/AlyssaM_InfoSec/status/1159877471161839617?s=19   Looking forward to sharing my vision for ending the 60 year cycle of bad defense strategies in #infosec and my challenge to think about security in a more effective way. https://sched.co/TAqU @dianainitiative #DianaInitiative2019 #cdwsocial @CDWCorp   1961 - MIT - CTSS - https://en.wikipedia.org/wiki/Compatible_Time-Sharing_Syst...

Listen to the BrakeSec Education Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.