Bryan Brake, Amanda Berlin, and Brian Boettcher
BrakeSec Education Podcast
A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.
Author
Bryan Brake, Amanda Berlin, and Brian Boettcher
Category
Podcast website
Latest episode
Jul 17, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
2019-008-windows retpoline patches, PSremoting, underthewire, thunderclap vuln 04.03.2019 56:01
BrakeingDownIR show #10 GrumpySec appearance? https://support.microsoft.com/en-us/help/4482887/windows-10-update-kb4482887 https://techcommunity.microsoft.com/t5/Windows-Kernel-Internals/Mitigating-Spectre-variant-2-with-Retpoline-on-Windows/ba-p/295618 https://blogs.technet.microsoft.com/srd/2018/03/15/mitigating-speculative-execution-side-channel-hardware-vulnerabilities/ "Microsoft has added su...
2019-007-bsides_seattle_recap-new_phishing_vector-Kernel_use_after_free_vuln 25.02.2019 44:45
Bsides Seattle recap (Bryan) New phishing technique to bypass email filters- https://www.helpnetsecurity.com/2019/02/20/phishers-new-trick-for-bypassing-email-url-filters/ https://en.wikipedia.org/wiki/Office_Open_XML_file_formats#Relationships Use after free in Linux kernel: https://securityboulevard.com/2019/02/linux-use-after-free-vulnerability-found-in-linux-2-6-through-4-20-11/ https://www.we...
2019-006: CSRF, XSS, infosec hypocrites, and the endless cycle 18.02.2019 40:40
https://www.zdnet.com/article/google-working-on-new-chrome-security-feature-to-obliterate-dom-xss/ https://www.owasp.org/index.php/DOM_Based_XSS CSRF - confused deputy https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF) Google Cloud Platform - tip tricks, stuff ms. berlin learned Layer 8 conference - Rhode Island'' I was wrong…..cycles don't sync --Ms. Berlin https://health.c...
2019-005: Security Researcher attack, disabling SPECTER, and Systemd discussion 11.02.2019 55:23
SpecterOps Class: https://www.eventbrite.com/e/adversary-tactics-red-team-operations-training-course-boston-june-2019-tickets-54970050902 https://www.secjuice.com/security-researcher-assaulted-ice-atrient/ https://www.csoonline.com/article/3338112/security/vendor-allegedly-assaults-security-researcher-who-disclosed-massive-vulnerability.html Tweet of application teardown: https://twitter.co...
2019-004-ShmooCon, and Bsides Leeds discussion, Facetime bug (with update), a town for ransom 04.02.2019 44:51
Facetime bug update: https://www.cnbc.com/2019/02/01/apple-facetime-bug-fix-and-apology.html ShmooCon discussion Bsides Leeds discussion @largeCardinal @bsidesLeeds https://www.bbc.co.uk/news/uk-scotland-edinburgh-east-fife-47028244 https://www.theverge.com/2019/1/27/18195630/gdpr-right-of-access-data-download-facebook-google-amazon-apple https://www.theverge.com/2019/1/25/18198006/uber-...
2019-003-Liz Rice, creating processes to shift security farther left in DevOps 28.01.2019 1:03:34
BIO: Liz Rice is the Technology Evangelist with container security specialists Aqua Security, where she also works on container-related open source projects including kube-hunter and kube-bench . She was Co-Chair of the CNCF's KubeCon + CloudNativeCon 2018 events in Copenhagen, Shanghai and Seattle, and co-author of the O'Reilly Kubernetes Security book. She has a wealth of software development,...
2019-002-part 2 of the OWASP IoT Top 10 with Aaron Guzman 22.01.2019 46:04
intro CFP for Bsides Barcelona is open! https://bsides.barcelona Aaron Guzman: @scriptingxss https://www.computerweekly.com/news/252443777/Global-IoT-security-standard-remains-elusive https://www.owasp.org/index.php/IoT_Attack_Surface_Areas https://scriptingxss.gitbooks.io/embedded-appsec-best-practices//executive_summary/9_usage_of_data_collection_and_storage_-_privacy.html OWASP SLACK: https://o...
2019-001: OWASP IoT Top 10 discussion with Aaron Guzman 14.01.2019 36:54
Aaron Guzman: @scriptingxss https://www.computerweekly.com/news/252443777/Global-IoT-security-standard-remains-elusive https://www.owasp.org/index.php/IoT_Attack_Surface_Areas https://scriptingxss.gitbooks.io/embedded-appsec-best-practices//executive_summary/9_usage_of_data_collection_and_storage_-_privacy.html OWASP SLACK: https://owasp.slack.com/ https://www.owasp.org/images/7/79/OWASP_2018_IoT_...
2018-045: end of the year podcast! 27.12.2018 1:11:26
Join the combined forces of: Jerry Bell (@maliciousLink) from Defensive Security Podcast! ( https://defensivesecurity.org/) Bill Gardner from the "RebootIt! podcast" https://itunes.apple.com/us/podcast/reboot-it/id1256466198?mt=2 Ms. Berlin and Bryan Brake for the end of the year podcast! BrakeSec Podcast = www.brakeingsecurity.com RSS: https://www.brakeingsecurity.com/rss
2018-044: Mike Samuels discusses NodeJS hardening initiatives 18.12.2018 56:11
Mike Samuels https://twitter.com/mvsamuel https://github.com/mikesamuel/attack-review-testbed https://nodejs-security-wg.slack.com/ Hardening NodeJS Speaking engagement talks: A Node.js Security Roadmap at JSConf.eu - https://www.youtube.com/watch?v=1Gun2lRb5Gw Improving Security by Improving the Framework @ Node Summit - https://vimeo.com/287516009 Achieving Secure Software through Redesign at...
2018-043-Adam-Baldwin, npmjs Director of Security, event stream post mortem, and making your package system more secure 11.12.2018 1:11:15
Adam Baldwin (@adam_baldwin) Director of Security, npm https://foundation.nodejs.org/ https://spring.io/understanding/javascript-package-managers Role in the NodeJS project Advisory? Active role? Maintain security modules? Are there any requirements to being a dev? Are there different roles in the NodeJS environment? Is there any review of system sensitive packages? (or has tha...
2018-042-Election security processes in the state of Ohio 03.12.2018 1:24:50
Where in the world is Ms. Amanda Berlin? Keynoting hackerconWV Election Security Cuyahoga County: Intro: Jeremy Mio (@cyborg00101 Name? Why are you here? Discussing Ohio does election operations. Walk through the process Pre-Elections Elections Night Post Elections All about the C.I.A. Votes must be confidential Votes must not be compromised (integrity) Voting should be available...
2018-041: part 2 of Kubernetes security insights w/ ian Coldwater 26.11.2018 44:57
@IanColdwater https://www.redteamsecure.com/ *new gig* So many different moving parts Plugins Code Hardware She's working on speaking schedule for 2019 How would I use these at home? https://kubernetes.io/docs/setup/minikube/ Kubernetes - up and running https://www.amazon.com/Kubernetes-Running-Dive-Future-Infrastructure/dp/1491935677 General wikipedia article (with architectur...
2018-040- Jarrod Frates discusses pentest processes 19.11.2018 1:21:18
Jarrod Frates Inguardians @jarrodfrates "Skittering Through Networks" Ms. Berlin in Germany - How'd it go? TinkerSec's story: https://threadreaderapp.com/thread/1063423110513418240.html Takeaways Blue Team: - Least Privilege Model - Least Access Model "limited remote access to only a small number of IT personnel" "This user didn't need Citrix, so her Citrix linked to NOTHING" "They lim...
2018-039-Ian Coldwater, kubernetes, container security 12.11.2018 50:16
Ian Coldwater- @IanColdwater https://www.redteamsecure.com/ *new gig* So many different moving parts Plugins Code Hardware She's working on speaking schedule for 2019 How would I use these at home? https://kubernetes.io/docs/setup/minikube/ Kubernetes - up and running https://www.amazon.com/Kubernetes-Running-Dive-Future-Infrastructure/dp/1491935677 General wikipedia article (with...
2018-038-InfosecSherpa, security culture, 05.11.2018 59:12
@InfoSecSherpa I have two talks coming up: Empathy as a Service to Create a Culture of Security at the Cofense Submerge conference Deep Dive into Social Media as an OSINT Tool at the H-ISAC Fall Summit (Health Information Sharing and Analysis Center) *Shameless Plug* My Nuzzel newsletters https://nuzzel.com/InfoSecSherpa https://nuzzel.com/InfoSecSherpa/cybersecurity-africa News stories -...
2018-037-iWatch save man's life, Alexa detects your mood, and post-derby discussion 22.10.2018 44:31
Health & Tech? https://arstechnica.com/gadgets/2018/10/amazon-patents-alexa-tech-to-tell-if-youre-sick-depressed-and-sell-you-meds/ https://hackaday.io/project/151388-minder (774 results for "health" on hackaday) (def don't need to talk about, but still funny AF) https://hackaday.io/project/11407-myflow https://9to5mac.com/2017/12/15/apple-watch-saves-life-managing-heart-attack/ https://ww...
2018-036-Derbycon 2018 Audio with Cheryl Biswas and Tomasz Tula 15.10.2018 39:57
Derbycon is probably one of the best infosec conferences of the calendar year. The podcast always has so much fun meeting listeners, meeting new people, and getting some audio to share with folks who can't be there. This year, we still got some audio, and it's great. We talked with Cheryl Biswas (@3ncr1pt3d) with her talks at #Derbycon and her work with the #dianaInitiative Check out her talks at...
2018-035-software bloat is forever; malicious file extensions; WMIC abuses 01.10.2018 52:43
Pizza Party Link - https://www.eventbrite.com/e/brakesec-derbycon-pizza-meetup-tickets-50719385046 News stories- Software/library bloat http://tonsky.me/blog/disenchantment/ https://hackernoon.com/how-it-feels-to-learn-javascript-in-2016-d3a717dd577f https://gbhackers.com/hackers-abusing-windows-management-interface-command-tool-to-deliver-malware-that-steal-email-account-passwords/ ...
2018-034-Pentester_Scenario 25.09.2018 40:03
Interesting email from one of our listeners. Detailing an issue that came up on a client engagement. We walk through best ways to store information post-engagement, and what you need to do to document test procedures so you don't get bit by a potential issue perhaps months down the line. Check out our Store on Teepub! https://brakesec.com/store Join us on our #Slack Channel! Send a request to @b...
2018-031-Derbycon ticket CTF, Windows Event forwarding, SIEM collection, and missing events... oh my! 01.09.2018 1:08:27
We are back with a new episode this week! We got over our solutions for some of the #derbyCon ticket #CTF challenges and include links to some of the challenges. We talk about Windows Event Forwarder, and all log forwarders seem to losing events! Thanks to our Patrons! Gonna be at Derbycon, come see us! Congrats to our Derbycon Ticket CTF winners! Winner: @gigstaggart 2nd Place: @ohai_ninja 3...
2018-030: Derbycon CTF and Auction info, T-mobile breach suckage, and lockpicking 26.08.2018 1:01:35
CTF information: Official site: https://scoreboard.totallylegitsite.com (thanks Matt Domko (@hashtagcyber) for hosting and allowing us to use his employee discount!) Please do not pentest the environment, not DDoS, nor cause anything undesirable to happen to the site. View the page, submit the flags, leave everything else alone... Derbycon Auction - starts September 8th at 9am Pacific Ti...
2018-029-postsummercamp-future_record_breached-vulns_nofix 17.08.2018 55:31
Post-Hacker Summercamp IppSec Walkthroughs Brakesec Derbycon ticket CTF - Drama - (hotel room search gate) AirconditionerGate Personal privacy Ask for ID Call the front desk Use the deadbolt - can be bypassed Plug the peephole with TP Hotel rooms aren't secure (neither are the safes) Probably the most hostile environment infosec people go into to try and be secu...
2018-028-runkeys, DNS Logging, derbycon Talks 09.08.2018 50:36
HTTPS on www.brakeingsecurity.com , Libsyn RSS syncing of itunes/google Play is over TLS Amanda giving a talk at Diana Initiative Derbycon Talk - mental health Volunteer/Topic request form - https://goo.gl/forms/wAiLW5Dh5h0MR5bO2 http://www.hexacorn.com/blog/2018/07/29/beyond-good-ol-run-key-part-82/ https://blogs.technet.microsoft.com/teamdhcp/2015/11/23/network-forensics-with-windows-dns-a...
2018-027-Godfrey Daniels talks about his book about the Mojave Phonebooth 01.08.2018 37:46
Godfrey Daniels - author of " Adventures with the Mojave Phone Booth " on sale at mojavephoneboothbook.com https://en.wikipedia.org/wiki/Mojave_phone_booth https://www.tripsavvy.com/the-mojave-phone-booth-1474047 https://www.dailydot.com/debug/mojave-phone-booth-back-number/ https://www.npr.org/2014/08/22/342430204/the-mojave-phone-booth https://www.reddit.com/r/UnresolvedMysteries/comment...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.