Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest Videos

Exploitation Walkthrough: ESC15/EKUwu with Justin Bollinger from TrustedSec

Justin Bollinger, Principal Security Consultant at TrustedSec, discussed his research and mitigation guidance on ADCS ESC15 (CVE-2024-49019), also known as EKUwu, a vulnerability in Microsoft's Active Directory Certificate Services.

The Age of AI-Powered Scams | The 443 Podcast

This week on the podcast, Marc Laliberte and Corey Nachreiner dive into a research white paper that explores how attackers could use AI to execute a full-scale money or credential theft scam from start to finish. Before that, they discuss Sophos's five-year battle with Chinese hackers targeting network devices, followed by a conversation about Microsoft’s ongoing fight against password spray attacks through compromised network devices.

How ARMO Reduced Secrets Exposure with GitGuardian

ARMO, a cloud-native security company, has been able to strengthen its security posture and ensure the protection of its client's data, thanks to GitGuardian. The company's CTO and co-founder, Ben Hirschberg, shared his experience of how GitGuardian has helped them close a significant security gap and instill a culture of security awareness throughout the organization.

Random but Memorable - Episode 13.9: Safe Search Biscuit Record with Vladimir Prelovac from Kagi

Why don’t we treat the information we consume online with the same care as the food we put in our bodies? To unpack this question and much more, we're joined by Vladimir Prelovac, founder and CEO of privacy-focused search engine Kagi. Tune in as we dive into the true cost of free search engines, how Kagi is disrupting the landscape, and the impact of AI on the future of search. If that wasn't enough to get you reaching for your headphones, we discuss chatbot woes and ransomware records in Watchtower Weekly. Plus, we live up to our name by randomly discussing biscuits in.

Secure Python code faster with Code Sight: Real-time issue detection in Visual Studio | Black Duck

Join David Bohannan, an R&D engineer at Black Duck, as he demonstrates using Black Duck's IDE plug-in, Code Sight to run static analysis on Python code within Visual Studio. Watch as Code Sight instantly detects vulnerabilities like OS command injection and cross-site request forgery while code is being written, helping developers fix issues early in the software lifecycle. David will demonstrate how leveraging Coverity's Rapid Scanning engine through Code Sight can allow developers to tackle issues such as secret scanning and ensure hardcoded secrets are flagged before they become risks to applications further downstream.