<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/css/feed.css"?>
<rss xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0">
<channel>
<title>BrakeSec Education Podcast</title>
<link>//podcastplus.net/feed/brakeing-down-security-podcast~8e505da2</link>
<description>A podcast about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security professionals need to know, or refresh the memories of seasoned veterans.</description>
<pubDate>Wed, 26 Aug 2026 03:08:22 +0000</pubDate>
<item>
<title>Tanya Janca Talks secure coding, Semgrep Academy, and community building, and more!</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/Tanya-Janca-secure-coding-community-building-semgrep.mp3?dest-id=177487</link>
<description>  Check out the BrakeSecEd Twitch at https://twitch.tv/brakesec   Join the Discord! https://discord.gg/brakesec   #youtube VOD (in 1440p):  https://www.youtube.com/watch?v=axQWGyd79NM      Questions and topics:  Bsides Vancouver discussion  Semgrep Community and Academy  Building communities  What are ‘secure guardrails’  Reducing barriers between security and developers  How to sell security to devs: “hey, if you want to see us less, buy/use this?”  “Security is your barrier, but we have goals that we can’t reach without your help.”  https://wehackpurple.com/devsecops-worst-practices-artificial-gates/   How are you seeing things like AI being used to help with DevOps or is it just making things more complicated? Not just helping write code, but infrastructure Ops, software inventories, code repo hygiene, etc?  OWASP PNW https://www.appsecpnw.org/  Alice and Bob coming next year!   Additional information / pertinent LInks (Would you like to know more?):  shehackpurple.ca   Semgrep (https://se...</description>
<pubDate>Sat, 01 Jun 2024 20:57:00 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/Tanya-Janca-secure-coding-community-building-semgrep.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/Tanya-Janca-secure-coding-community-building-semgrep.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Bsides Seattle and Austin, SecureBoot patch, and more</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/Bsides_Seattle_and_Austin_SecureBoot_patch_and_more.mp3?dest-id=177487</link>
<description>   BrakeSec Show Outline   – No Guest                  Show Topic Summary (less than 300 words)         Bsides Seattle and Bsides Austin              Youtube VOD:    https://youtube.com/live/UGRaRSYj7kc                       Questions and potential sub-topics (5 minimum):           Bsides Seattle update and Bsides Austin             Patching the unpatchable              https://en.wikipedia.org/wiki/Parkerian_Hexad                  Power and influence  (is power bad? Is influence?)           5.     https://deliverypdf.ssrn.com/delivery.php?ID=357001027119125105074103081006094117005092014048001013007086030071009081068110103025024041103038045036033080107020112080097022024073029064061065125002071028013110008011045013116002084024000066075067001126004101003027004086091007025096080019022003104&amp;amp;EXT=pdf&amp;amp;INDEX=TRUE    (A Theory of Creepy: Technology, Privacy and Shifting Social Norms)         (contact info for people to reach out later):                      Additional information / pertinent Links (...</description>
<pubDate>Sat, 27 May 2023 04:48:00 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/Bsides_Seattle_and_Austin_SecureBoot_patch_and_more.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/Bsides_Seattle_and_Austin_SecureBoot_patch_and_more.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p2</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p2.mp3?dest-id=177487</link>
<description>  For context, we at the K12 Security Information Exchange (K12 SIX) are a relatively new K12-specific ISAC – launched to help protect the US K12 sector from emerging cybersecurity risk. One of our signature accomplishments in our first year was the development and release of our ‘essential protections’ series – an effort to establish baseline cybersecurity standards for schools. See:    https://www.k12six.org/essential-cybersecurity-protections     https://www.grf.org/     Global Resilience Federation     We will help your industry develop or enhance a trusted threat information sharing community, obtain actionable intelligence, and support you in emergencies.         We all count on the resiliency of essential services - services from the electricity powering our homes and the connectivity of entertainment apps, to the legal systems and financial pipelines driving the global economy. But this infrastructure faces constant threats from hacktivists, criminals, and rogue states, and they are growing i...</description>
<pubDate>Tue, 01 Mar 2022 06:48:15 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p2.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p2.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>K12SIX's Eric Lankford and Doug Levin on helping schools get added security -p1</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p1.mp3?dest-id=177487</link>
<description>   The K12 Security Information Exchange (K12 SIX) are a relatively new K12-specific ISAC – launched to help protect the US K12 sector from emerging cybersecurity risk. One of our signature accomplishments in our first year was the development and release of our ‘essential protections’ series – an effort to establish baseline cybersecurity standards for schools. See:    https://www.k12six.org/essential-cybersecurity-protections       https://www.grf.org/      Global Resilience Federation     We will help your industry develop or enhance a trusted threat information sharing community, obtain actionable intelligence, and support you in emergencies.         We all count on the resiliency of essential services - services from the electricity powering our homes and the connectivity of entertainment apps, to the legal systems and financial pipelines driving the global economy. But this infrastructure faces constant threats from hacktivists, criminals, and rogue states, and they are growing in sophisticatio...</description>
<pubDate>Tue, 22 Feb 2022 18:00:54 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p1.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/K12SIX-project-Doug_Levin-Eric_Lankford-threat_intel-edusec-p1.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>April Wright and Alyssa Miller - IoT platforms, privacy and security, embracing standards</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/part3-IoT-stalking-background-Airtags_privacy_standards.mp3?dest-id=177487</link>
<description>  Alyssa Milller (@AlyssaM_InfoSec)    April Wright (@Aprilwright)          Open Source issues (quick discussion, because I value your opinions, and supply chain is important in the IoT world too.)      Log4j and OSS software management and profitability     Free as in beer, but you pay for the cup… (license costs $$, not the software).      “If you make money using our software, you must buy a license” - not an end-user license         Open source conference at Whitehouse:      https://www.zdnet.com/article/log4j-after-white-house-meeting-google-calls-for-list-of-critical-open-source-projects/       https://www.wsj.com/articles/white-house-convenes-open-source-security-summit-amid-log4j-risks-11642119406      “For too long, the software community has taken comfort in the assumption that open source software is generally secure due to its transparency and the assumption that many eyes were watching to detect and resolve problems,” said Kent Walker, chief legal officer at Google in    a blog post ...</description>
<pubDate>Tue, 15 Feb 2022 03:49:27 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/part3-IoT-stalking-background-Airtags_privacy_standards.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/part3-IoT-stalking-background-Airtags_privacy_standards.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Alyssa Miller, April Wright, on IoT Privacy &amp; Security, using tech for stalking, what could be done? Part1</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/part2-IoT-stalking-background-Airtags-and-more.mp3?dest-id=177487</link>
<description>   (Please feel free to add anything you like… We want our guests to have as much input as possible) -brbr         Zoom is on…  https://us02web.zoom.us/j/88629788990?pwd=NFNBVlgwM0dDM0s2eUY3YnBITlRNdz09         Alyssa Milller (@AlyssaM_InfoSec)     April Wright (@Aprilwright)     Talk about side projects, podcasts, speaking events, etc (if you want to)           Open Source issues (quick discussion, because I value your opinions, and supply chain is important in the IoT world too.)      Log4j and OSS software management and profitability     Free as in beer, but you pay for the cup… (license costs $$, not the software).      “If you make money using our software, you must buy a license” - not an end-user license         Open source conference at Whitehouse:      https://www.zdnet.com/article/log4j-after-white-house-meeting-google-calls-for-list-of-critical-open-source-projects/       https://www.wsj.com/articles/white-house-convenes-open-source-security-summit-amid-log4j-risks-11642119406      ...</description>
<pubDate>Mon, 07 Feb 2022 19:49:31 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/part2-IoT-stalking-background-Airtags-and-more.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/part2-IoT-stalking-background-Airtags-and-more.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Bit of news, Belarus train system hack, VMware Horizon vulns, edge network device vulns</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/news-belarus-train-system-hacked-vmware-Horizon-vulns.mp3?dest-id=177487</link>
<description>  News articles we covered this week:     https://www.wired.com/story/belarus-railways-ransomware-hack-cyber-partisans/       https://www.hackingarticles.in/linux-privilege-escalation-polkit-cve-2021-3560/       https://old.reddit.com/r/msp/comments/s48iji/vmware_horizon_servers_being_actively_hit_with/       https://www.bleepingcomputer.com/news/security/over-20-000-data-center-management-systems-exposed-to-hackers/     Whimmery's Walkthroughs: Join @whimmery on her twitch or on the @brakesec Youtube channel for walkthroughs on Burp Suite training and more!   Twitter handles:  Official Podcast: @brakesec    Brian Boettcher: @boettcherpwned    Amanda Berlin: @infosystir @hackersHealth @infosecroleplay   Bryan Brake: @bryanbrake      </description>
<pubDate>Tue, 01 Feb 2022 19:06:02 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/news-belarus-train-system-hacked-vmware-Horizon-vulns.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/news-belarus-train-system-hacked-vmware-Horizon-vulns.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>April Wright and Alyssa Miller- Open Source sustainabilty</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/Part1-open_source_sustainability.mp3?dest-id=177487</link>
<description>  Alyssa Milller (@AlyssaM_InfoSec)  April Wright (@Aprilwright)   0. Open Source issues (quick discussion, because I value your opinions, and supply chain is important in the IoT world too.)  Log4j and OSS software management and profitability  Free as in beer, but you pay for the cup… (license costs $$, not the software).   “If you make money using our software, you must buy a license” - not an end-user license   Open source conference at Whitehouse:  https://www.zdnet.com/article/log4j-after-white-house-meeting-google-calls-for-list-of-critical-open-source-projects/  https://www.wsj.com/articles/white-house-convenes-open-source-security-summit-amid-log4j-risks-11642119406  “For too long, the software community has taken comfort in the assumption that open source software is generally secure due to its transparency and the assumption that many eyes were watching to detect and resolve problems,” said Kent Walker, chief legal officer at Google in a blog post published after the meeting. “But in f...</description>
<pubDate>Mon, 24 Jan 2022 18:08:12 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/Part1-open_source_sustainability.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/Part1-open_source_sustainability.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Amélie Koran and Adam Baldwin discuss OSS sustainability, supply chain security,, governance, and outreach for popular applications - part2</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/OSS_sustainability_log4j_fallout_developer_damages_own_code-p2.mp3?dest-id=177487</link>
<description>  Adam Baldwin (@adam_baldwin)  Amélie Koran (@webjedi)        https://logging.apache.org/log4j/2.x/license.html      https://www.theregister.com/2021/12/14/log4j_vulnerability_open_source_funding/      https://www.zdnet.com/article/security-firm-blumira-discovers-major-new-log4j-attack-vector/     F/OSS developer deliberately bricks his software in retaliation for big companies not supporting OSS.   https://twitter.com/BleepinComputer/status/1480182019854327808     https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/      https://developers.slashdot.org/story/22/01/09/2336239/open-source-developer-intentionally-corrupts-his-own-widely-used-libraries    Faker.js -  https://www.npmjs.com/package/faker    Generate massive amounts of fake contextual data  Colors.js -  https://www.npmjs.com/pafaker    - npm package/colors get color and style in your node.js console    https://abc7ny.com/suspicious-package-queens-astoria-fire/6425363/    Should OSS t...</description>
<pubDate>Tue, 18 Jan 2022 19:50:16 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/OSS_sustainability_log4j_fallout_developer_damages_own_code-p2.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/OSS_sustainability_log4j_fallout_developer_damages_own_code-p2.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
<item>
<title>OSS sustainability, log4j fallout, developer damages own code-p1</title>
<link>https://traffic.libsyn.com/secure/brakeingsecurity/OSS_sustainability_log4j_fallout_developer_damages_own_code-p1.mp3?dest-id=177487</link>
<description>   Adam Baldwin (@adam_baldwin)     Amélie Koran (@webjedi)         Log4j vulnerability          https://logging.apache.org/log4j/2.x/license.html       https://www.theregister.com/2021/12/14/log4j_vulnerability_open_source_funding/       https://www.zdnet.com/article/security-firm-blumira-discovers-major-new-log4j-attack-vector/              F/OSS developer deliberately bricks his software in retaliation for big companies not supporting OSS.       https://twitter.com/BleepinComputer/status/1480182019854327808       https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/       https://developers.slashdot.org/story/22/01/09/2336239/open-source-developer-intentionally-corrupts-his-own-widely-used-libraries          Faker.js -     https://www.npmjs.com/package/faker    Generate massive amounts of    fake    contextual data     Colors.js -     https://www.npmjs.com/pa     faker - npm     ckage/colors    get color and style in your node.js console  ...</description>
<pubDate>Wed, 12 Jan 2022 00:20:03 +0000</pubDate>
<guid>https://traffic.libsyn.com/secure/brakeingsecurity/OSS_sustainability_log4j_fallout_developer_damages_own_code-p1.mp3?dest-id=177487</guid>
<enclosure url="https://traffic.libsyn.com/secure/brakeingsecurity/OSS_sustainability_log4j_fallout_developer_damages_own_code-p1.mp3?dest-id=177487" type="audio/mpeg" length="1"/>
</item>
</channel>
</rss>
