Tom Eston, Scott Wright, Kevin Tackett

Shared Security Podcast

News EN ↓ 568 episodes

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Author

Tom Eston, Scott Wright, Kevin Tackett

Category

News

Podcast website

sharedsecurity.net

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

The FBI’s Qakbot Takedown, QR Code Phishing Attacks, Dox Anyone in America for $15 11.09.2023

In this episode we discuss the FBI's remarkable takedown of the Qakbot botnet, a saga involving ransomware, cryptocurrency, and the FBI pushing an uninstaller to thousands of victim PCs. Next, we explore how a major U.S. energy organization fell victim to a QR code phishing attack, highlighting the ever-evolving tactics used by attackers. Finally, we discuss the alarming world of personal data exp...

SaaS Attacks: Compromising an Organization without Touching the Network 04.09.2023

In this episode Luke Jennings VP of Research & Development from Push Security joins us to discuss SaaS attacks and how its possible to compromise an organization without touching a single endpoint or network. Luke talks about his recent SaaS attack research, why SaaS based attacks are different than traditional network based attacks, the SaaS attack matrix which can be used by both red and blu...

Back to School Cybersecurity, Phishing Pitfalls and Strategies, X’s (Twitter) Blocking Overhaul 28.08.2023

In this episode, we discuss essential cybersecurity tips for students and educational institutions as they gear up for the school season. From software updates to strong passwords and cybersecurity education, we explore how students and schools can fortify their digital defenses. Next, we navigate the treacherous waters of phishing and related scams, unveiling strategies to outwit malicious links....

Business Email Compromise Scams Revisited 21.08.2023

In this best of episode from December 2021, we revisit Business Email Compromise (BEC) scams. What are they, how to identify them, and why BEC scams have resulted in well over $3 billion in losses since 2016, more than any other type of fraud in the U.S. We also share our tips on how to protect yourself and your business from these scams.

The Current and Future State of Email Security with Andy Yen, CEO of Proton 14.08.2023

In this episode, host Tom Eston speaks with Andy Yen, founder and CEO of Proton, to discuss the current and future state of email security. We also discuss Andy's unique background as a scientist, the importance of using email aliases, an overview of Proton's new password manager (Proton Pass), how AI may impact email security in the future, and how to find out more about how Proton takes a differ...

Common Sense Advice for Hacker Summer Camp, AI Chatbot Attacks, What’s a Flipper Zero? 07.08.2023

In this episode, we discuss our common sense tips to stay safe and secure while attending "Hacker Summer Camp": BSides, Black Hat, and DEF CON hacking conferences in Las Vegas. Next, we discuss the vulnerabilities and potential adversarial attacks on large language models like ChatGPT and other AI chat bots. Finally, we discuss the Flipper Zero, a versatile hacking device. We discuss its features,...

Your Digital Immortality is Coming, Apple and Google Are Data Gatekeepers, Satellite Security Risks Revealed 31.07.2023

In this episode, we explore the implications and ethical dilemmas of immortality in the digital world. Listen to our discussion about this cutting-edge technology and its potential impact on our privacy. Next, we discuss the growing trend of Apple and Google becoming custodians of our digital lives. Have these tech companies gone too far? Join the conversation as we discuss the trends and challeng...

Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program 24.07.2023

In this episode, we discuss the recent Microsoft security breach where China-backed hackers gained access to numerous email inboxes, including those of several federal government agencies, using a stolen Microsoft signing key to forge authentication tokens. A TikTok influencer used a voice cloning app to expose a cheating boyfriend. But wait, there's more to this story than meets the eye! We discu...

First Ban on Selling Location Data, Prohibiting Password Managers, Real-Time Crime Center Concerns 17.07.2023

In this episode we discuss how Massachusetts lawmakers are pushing a groundbreaking bill to ban the buying and selling of location data from mobile devices. This legislation raises vital questions about consumer privacy, digital stalking, and national security threats. Next, we discuss the pros and cons of prohibiting external password managers within organizations. Join the conversation as we wei...

Meta’s Threads and Your Privacy, Airline Reservation Scams, IDOR Srikes Back 10.07.2023

In this episode, we explore the rise of Threads, a new social media app developed by Meta, which has already attracted 10 million users in just seven hours. However, there's a catch – the app collects extensive personal data, sparking concerns about privacy. Next, we dive into the world of airline reservation scams, exposing how fraudsters exploit a loophole to deceive unsuspecting travelers. Lear...

MOVEit Cyberattack, The Problem with Password Rotations, Military Alert on Free Smartwatches 03.07.2023

Several major organizations, including British Airways and the BBC, fell victim to the recent MOVEit cyberattack. We discuss the alarming trend of hackers targeting trusted suppliers to gain access to customer data, potentially holding companies and individuals for ransom. Is it better to change passwords regularly or focus on creating complex ones? We discuss the pitfalls of frequent password cha...

Security Podcasting, Hacking Stories, and The State of Firmware Security with Paul Asadoorian 26.06.2023

Paul Asadoorian, OG security podcaster and host of the popular Paul's Security Weekly podcast, joins us in this episode to talk about his career as one of the original security podcasters. Paul's been podcasting for more then 17 years! Paul also shares with us some of his greatest hacking stories and don't miss our lively discussion about the state of firmware security.

The FTC’s Complaint Against Ring, Detecting Malware Infected Apps, America’s Most Cybersecure Companies 19.06.2023

The FTC charged Ring, the Amazon-owned home security camera company, for compromising customer privacy and having inadequate security measures. Employees accessed private videos, while hackers exploited vulnerabilities and now Ring needs to reimburse customers $5.8 million dollars. The FTC complaint emphasizes that Ring's actions disregarded privacy and security, putting consumers at risk. Google...

How to Break Into a Cybersecurity Career – Phillip Wylie 12.06.2023

In this exciting episode of our podcast we have the pleasure of speaking with Phillip Wylie, a remarkable professional with a captivating career in cybersecurity. Join us as we discuss Phillip's unique journey and uncover valuable insights on breaking into the cybersecurity field. From his origins as a professional wrestler who once bravely faced off against a bear, to his evolution into a respect...

Netflix Cracks Down on Password Sharing, AI Legal Research Gone Wrong, Fake Identities and Surveillance Firms 05.06.2023

Netflix plans to crack down on the widespread practice of password sharing among households. We discuss their new verification feature and its impact on user experience and security. A lawyer finds himself in hot water after relying on ChatGPT for legal research. We investigate the consequences of referencing non-existent legal cases, the lawyer's claim of unawareness about the AI's potential for...

Meta’s $1.3 Billion Fine, AI Hoax Hysteria, Montana’s TikTok Ban 29.05.2023

In this episode, we discuss Meta's record-breaking $1.3 billion fine by the EU for unlawfully transferring user data, shedding light on the increasing risks faced by tech companies in violating privacy rules. Highly realistic images of a Pentagon explosion went viral on Twitter, causing a stock market dip. We discuss the risks associated with Twitter's verification system and the issue of AI and d...

Google Now Supports Passkeys, Risky New Top Level Domains, Twitter’s Encryption Dilemma 22.05.2023

In this episode, we explore the arrival of passwordless Google accounts that use "passkeys," which offer enhanced usability and security. We discuss the benefits of passkeys over traditional passwords, but also why passkeys are not quite ready for prime time use. Next, we discuss Google Domains' introduction of new top-level domains (TLDs) like .zip and .mov, raising concerns about the potential u...

Private Tweets Exposed, Unauthorized Tracking Collaboration, AI Risks and Regulation 15.05.2023

In this episode we discuss a recent Twitter security incident that caused private tweets sent to Twitter Circles to become visible to unintended recipients. Next, we discuss the collaboration between Apple and Google to develop a specification for detecting and alerting users of unauthorized tracking using devices like AirTags. Finally, we explore the US government's engagement with major technolo...

Juice Jacking Debunked, Photographer vs. AI Dataset, Google Authenticator Risks 08.05.2023

In this episode we debunk the fearmongering surrounding "juice jacking," a cyber attack where attackers steal data from devices that are charging via USB ports. Next, we dive into a case where a photographer tried to get his photos removed from an AI dataset, only to receive an invoice instead of having his photos taken down. Finally, we examine the security risks of using Google Authenticator's c...

Building a Healthy Security Culture: Insights from Kai Roer 01.05.2023

In this episode we speak with Kai Roer, a renowned author, security culture coach, and CEO of Praxis Security Labs. Kai shares his career journey in cybersecurity and emphasizes the importance of building a strong security culture within organizations. He identifies the biggest impediments to a good security culture and offers actionable steps that organizations can take to improve their culture....

Arkansas Social Media Consent Law, Android Malware Invasion, New Method of Keyless Car Theft 24.04.2023

Is Arkansas taking the right step to protect children online? A new law passed in the state makes it illegal for minors to use social media without their parent or guardian's consent. Over 60 Android apps on the Google Play Store with more than 100 million downloads have been infiltrated by the new "Tekya" malware. The malware can commit ad fraud and steal Facebook credentials. Criminals are steal...

Genesis Market Crackdown, Life360 App Misuse, Tesla Customer Privacy Concerns 17.04.2023

Law enforcement agencies across 17 countries have cracked down on Genesis Market, one of the largest criminal marketplaces, resulting in the arrests of 120 people globally. Popular family safety app, Life360, has been used by sex traffickers to monitor and control their victims, highlighting the increasing use of GPS technology by criminals. A recent news report reveals that groups of Tesla employ...

Clearview AI Facial Recognition Fallout, Hacked and Helpless, Is AI Armageddon Upon Us? 10.04.2023

Clearview AI provided police with 30 billion scraped images from Facebook, raising concerns over privacy and the potential misuse of facial recognition technology. A victim of a phone hack shares their story of how their credit card was stolen, highlighting the vulnerability of personal information and the chain of events that happen when someone's identity is stolen. Our discussion about an open...

The TikTok CEO Testimony, ChatGPT’s Privacy Risks, Inaudible Ultrasound Attacks 03.04.2023

The CEO of TikTok was criticized by Congress for his "worthless" assurances regarding the app's privacy and security. But what is the real motivation for Congress attempting to ban TikTok? Should we be concerned that AI language models like ChatGPT are a privacy nightmare? Not just for businesses but for anyone using it? Researchers have found a way to use inaudible ultrasonic waves to attack smar...

Samsung Chipset Zero-Day Vulnerabilities, AI-Assisted Social Engineering, ATM Fraud with a Twist 27.03.2023

In this episode we discuss Google's discovery of 18 zero-day vulnerabilities in Samsung's Exynos chipsets. We examine an AI-assisted social engineering campaign that combines emerging technologies with classic techniques. Finally, we look at a new method of ATM fraud where thieves use glue to disable card readers and trick customers into using the tap function on their debit cards.

Listen to the Shared Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.