Claroty
Nexus: A Claroty Podcast
Nexus is a cybersecurity podcast hosted by Claroty Editorial Director Mike Mimoso. Nexus will feature discussions with cybersecurity leaders responsible for the security and protection of cyber-physical systems. Guests include cybersecurity researchers, executives, innovators, and influencers, discussing the topics affecting cybersecurity professionals in OT, IoT, and IoMT environments.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Dan Ricci on the ICS Advisory Project 06.07.2022 33:02
Dan Ricci joins the podcast to discuss the ICS Advisory Project. Ricci founded the project in 2018, which provides vulnerability management teams with a searchable, intuitive dashboard that visualizes industrial control system security and vulnerability advisories and threat data. In this episode, Ricci explains how the ICS Advisory Project got off the ground, some of the features it currently of...
Vera Mens on Hacking Flow Computers 30.06.2022 38:16
Claroty Team82 researcher Vera Mens joins the podcast to discuss her BSides Tel Aviv presentation today called, " Total Flaw: Hacking Flow Computers for Fun and Free Gas. " Flow computers calculate flow rates for gas, oil, and more, and could be a key target for an experienced attacker who is looking to disrupt or damage a process in the oil and gas industry. Mens uncovered two vulnera...
Don C. Weber on ICS Cybersecurity Training, Education 15.06.2022 46:48
Don C. Weber, founder of Cutaway Security, joins the podcast to discuss his extensive career in information security, his journey to industrial control system cybersecurity, and his desire to educate, train and mentor others in the community. Weber’s business focuses on security services for industrial environments through program reviews, security assessments, penetration testing, and training. H...
Idaho National Lab on the INL Control Environment Laboratory Resource (CELR) 02.06.2022 46:01
Tim Huddleston of Idaho National Laboratory joins the Aperture podcast to discuss the INL Control Environment Laboratory Resource (CELR). CELR is a simulated critical infrastructure environment where users may test their incident response capabilities against real-life attack scenarios. Users may also use the environment to conduct malware and vulnerability analysis of ICS and SCADA devices, and a...
Thomas Schmidt and Martin Scheu on the Common Security Advisory Framework 26.05.2022 36:28
Thomas Schmidt of the German Federal Office for Information Security and Martin Scheu, an OT Security Engineer at SWITCH-CERT, join the podcast to discuss the Common Security Advisory Framework (CSAF). CSAF automates the largely manual task of gathering security advisories and vulnerability remediation information, and then creates standardized, machine-readable advisories that users such as vend...
Daniel Kapellmann Zafra on Incontroller/Pipedream ICS Attack Tools 04.05.2022 39:25
Mandiant senior technical analysis manager Daniel Kapellmann Zafra joins the Claroty Aperture podcast to discuss the Incontroller/Pipedream attack tool . Incontroller is alleged to be a state-sponsored tool specifically designed to target industrial control systems. Incontroller was discovered before it was employed on a victim's network, yet nonetheless it remains one of the most sophisticat...
Sharon Brizinov on Hacking and Securing PLCs 20.04.2022 34:21
In this episode of the Aperture podcast, Claroty Team82 vulnerability research lead Sharon Brizinov covers a presentation he’s giving at the S4x22 conference in Miami that explains a unique attack against Siemens SIMATIC 1200 and 1500 PLCs that enabled native code execution on the device. Also, Brizinov explains his participation in the Pwn2Own contest. S4 hosts the only ICS-focused version of Pw...
Kylie McClanahan on Automating the Gathering of Vulnerability Information 29.03.2022 41:05
Kylie McClanahan, a University of Arkansas doctoral student and senior developer at Bastazo, joins the Aperture podcast to discuss her research into automating the gathering of vulnerability remediation and mitigation information from vendors and third-party sources. McClanahan explains how she and colleagues have used machine learning, natural language processing, and keyword techniques, among ot...
Sean Tufts on OT SOC Playbooks, Culture Challenges 24.02.2022 40:36
Sean Tufts, ICS and OT security practice director at Optiv, joins the Claroty Aperture podcast to discuss some of the security technology and cultural challenges facing industrial enterprises as they deal with digital transformation and convergence. Tufts, a former NFL player and college football star, also shares his non-conventional career path to OT cybersecurity and how some of the skills tra...
Patrick Miller on Securing Critical Infrastructure in a Time of Conflict 17.02.2022 43:09
Veteran ICS cybersecurity expert Patrick Miller joins Claroty's Aperture podcast to discuss the proactive measures ICS cybersecurity managers and OT asset owners and operators should be taking right now in light of geopolitical tensions around the world. Miller recently wrote a blog explaining what and how electric utilities and other CI organizations should be communicating and sharing in th...
OT-ISAC on Information-Sharing, Incident Recovery 30.01.2022 41:14
Bill Nelson, director and officer of the OT-ISAC, joins the podcast to discuss the growing need for adequate sharing of threat intelligence and incident information among operational technology professionals, including asset owners and security practitioners. Nelson explains some of the information-sharing challenges that continue to shadow ISACs, and why member organizations may be hesitant to sh...
Tom VanNorman on OT Cybersecurity Skills Gap 12.01.2022 40:04
ICS Village cofounder Tom VanNorman joins the Aperture podcast to discuss the recently announced Cybersecurity & Industrial Infrastructure Security Apprenticeship Program that aims to improve cybersecurity knowledge within operational technology. ICS Village is part of a consortium behind this apprenticeship program along with Siemens Energy, SANS Institute, and a number of academic institutio...
Claroty, JFrog on Fuzzing BusyBox 28.11.2021 38:45
Claroty researcher Vera Mens and JFrog researcher Shachar Menashe join the podcast to discuss a recent research collaboration between the two companies that looked at the security of BusyBox. Busybox is a popular embedded Linux utility suite, and is found everywhere in operational technology, including in devices such as PLCs, HMIs, and RTUs. The researchers published a paper that describes 14 vul...
ZDI's Dustin Childs on Pwn2Own Miami 15.11.2021 35:42
Dustin Childs of the Zero Day Initiative (ZDI) joins Claroty's Aperture podcast to discuss the upcoming Pwn2Own Miami hacking contest . This is the only hacking contest focused on finding zero-day vulnerabilities in industrial control systems (ICS) and operational technology (OT), and it will be held during the S4 conference in January. Childs is a veteran of the security industry and Pwn2Ow...
Exploring and Navigating OT for CISOs 10.11.2021 42:01
Splunk OT security strategist Chris Duffey and Global Advisory CISO Doug Brush join Claroty's Aperture podcast to discuss how CISOs can and must navigate the world of industrial control system (ICS) and operational technology cybersecurity. Digital transformation and convergence have forced IT and OT under the same umbrella for many industrial enterprises and critical infrastructure. For man...
Gary E. Miller on the GPSD Bug 27.10.2021 39:22
Gary E. Miller, principal maintainer of GPSD, joins the Aperture Podcast to discuss a bug in this service that potentially could have caused some disruptions on devices that rely on global positioning systems for precise time-keeping. GPSD is a service daemon that extracts time information from GPS appliances. GPSD can be found in anything from mobile phones, to submarine navigation systems, and...
Top 20 Secure PLC Coding Practices List 28.09.2021 40:27
Martin Scheu and Dirk Rotermund of the Top 20 Secure PLC Coding Practices project join Claroty's Aperture podcast to discuss how engineers can integrate secure coding practices into PLC programming. The group's list of secure coding practices was released earlier this year and is available as a free download . It’s a 44-page document that includes not only the list of secure coding pract...
Dennis Fisher on 'When Bug Bounties Went Boom' 20.09.2021 42:06
Decipher Editor in Chief Dennis Fisher joins the podcast to discuss a series he recently published on the history and evolution of bug bounties. In the series, Dennis talks to the hackers and researchers who took an idea and turned it into one of information security's most well-known and lucrative industries. In this episode, Fisher covers the early days of bug bounties, the No More Free Bug...
Tom Pace on SBOMs for ICS and OT 22.08.2021 48:58
Tom Pace, founder of security company NetRise joins Claroty's Aperture Podcast to discuss SBOMs, or software bill of materials, and how they can be leveraged to improve industrial control system and operational technology cybersecurity. SBOMs are analogous to ingredient labels on food products, or parts lists for automobiles. Yet for ICS and OT equipment, they are a rarity. That lack of visib...
Tony Baker on OT Cybersecurity Challenges, CIP Security 10.08.2021 37:27
Rockwell Automation Chief Product Safety and Security Officer Tony Baker joins the Claroty Aperture podcast to discuss the rash of cybersecurity challenges facing critical infrastructure and industry owners and operators. Baker is a Rockwell veteran and has specialized in cybersecurity for the last eight years. He shares his insight on some of the challenges and resource gaps defenders are facing...
Inside the Water Sector Cybersecurity Survey 02.07.2021 33:55
Michael Arceneaux, managing director of the Water Information Sharing and Analysis Center (WaterISAC), joins Claroty's Aperture podcast for a deep dive into the results of the recently released Water Sector Coordinating Council's cybersecurity survey . In short, the water sector needs cybersecurity help from industry organizations and the federal government. Respondents, identified four...
Adm. Mike Rogers on Ransomware and OT 25.06.2021 42:44
Retired Adm. Mike Rogers, former NSA Director and U.S. Cyber Command Commander, joins Claroty's Aperture Podcast to lend his insight and expertise into the rash of ransomware attacks starting to impact operational technology (OT) environments and critical infrastructure. Rogers covers the risk assessments that industrial enterprises are undertaking to handle the ransomware threat, and how to...
Mandiant on Low-Sophistication OT Attacks 08.06.2021 42:10
Mandiant Threat Intelligence Senior Manager Nathan Brubaker joins the Aperture Podcast to discuss the growing trend of low-sophistication attacks targeting operational technology and industrial control systems. Nathan coauthored a recent Mandiant report on the subject, identifying a number of trends worth monitoring as industrial enterprises continue to connect OT to the internet and converge IT a...
E-ISAC on Biden 100-Day Plan for Power Grid Cybersecurity 18.05.2021 33:19
Manny Cancel, CEO of the Electricity-ISAC, joins the Aperture podcast for a wide-ranging discussion on cybersecurity issues affecting electricity utilities and critical infrastructure. Cancel shares his thoughts on the Biden Administration's recent announcement of a 100-day plan to improve electricity and power grid cybersecurity. Specifically, the plan calls for the identification and deploy...
Katie Moussouris on Dan Kaminsky, Pay Equity, Vulnerability Disclosure Progress 29.04.2021 41:50
Luta Security founder, security entrepreneur, and vulnerability disclosure pioneer Katie Moussouris joins the Aperture Podcast to talk about influential researcher Dan Kaminsky, who died April 23 at 42 years old. Katie discusses the breadth of Dan's work as a researcher, and his friendship, empathy, and outreach within the security community. Katie also talks about her work advocating for pa...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.