Paul's Security Weekly (Audio)
by Paul Asadoorian
© 2024 CyberRisk Alliance
Sep 17, 2026Recent reviews on Apple Podcasts (3)
Good info, laid back
I’ve listened to Paul and crew since I was new to sec, years ago. Great way to hear sec news with the guys’ discussion from their years of experience.
Chris Mc.38 ·
Great Vibe! Amazing amount of knowledge shared
This is the type of podcast where you and your buddies who are professionals at what you do sit down and talk shop while having a great time. There’s a ton of knowledge while also keeping it light hearted with an amazing diversity of knowledge and personalities. Regardless of where you are in your security journey or just security curious, this is a great podcast to dive into!
statictear ·
Fantastic
Great news, great interviews, great hosts. Also happy to see the main show only feed.
d1str0 ·
Episodes (649)

AI hates CAPTCHAs - PSW #944
Sep 17, 20262h 4m
In the security news this week: UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act

It's More Secure When It's Disabled - PSW #943
Sep 10, 20262h 2m
In the security news this week: Microsoft patches all the things Commissary freezers enter cyberwar Fake AV, real Defender nap Rowhammer comes for the GPU BIOS updates are no longer optional CVSS is not a crystal ball Kw

Linux Threat Hunting - PSW #942
Sep 3, 20262h 12m
First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the s

Hacking All The Devices, with AI? - Rob Allen - PSW #941
Aug 27, 20262h 6m
Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit

Rejoice In The Nostalgia - PSW #940
Aug 20, 20262h 8m
In the security news this week: Cursor opens your repo, the repo opens you If you want the good model I'm going to need to see your ID Flock's a Flocking mess Defender was supposed to be the chosen one Side stepping Secu

The Breached WiFi AI Ports... What? - PSW #939
Aug 13, 20262h 4m
In the security news this week: North Carolina ports and contingency plans Back to paper and pencils Midnight Blizzard compromises hotel Wi-Fi DNS strikes again Captive portals, stolen credentials, and nation-state scale

When AI Commits Felonies - PSW #938
Aug 6, 20261h 58m
This week: When you are not at summer camp you can't read about it The Fettle continues Using the CFAA against AI Social contracts are not security models VSCode extentions, again Bugtraq is back! NVIDA, LVFS, and unrave

Sandwich Hats - PSW #937
Jul 30, 20262h 5m
In the security news: 2.2 million cars, one shared Bluetooth key JFrog tries to spin an AI 0-day into a win Sextortion scammers recycling ShinyHunters' leaks The first hack ever, from 1966 Prompt injection as a service,

Fixing Vulns Is Harder Than Finding Them - PSW #936
Jul 23, 20262h 2m
In the news this week: InfraTrust and knowing what to patch Adversary in the middle triggered command injection Exploitarium again FreeRDP comes with free vulnerabilities AI breaking out of sandboxes on its own Wordpress

1999 Called and It Wants It's Exploits Back - PSW #935
Jul 16, 20262h 11m
This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python imple

AI Is Annoying & IoT Devices Still Get Hacked - PSW #934
Jul 9, 20262h 5m
In the security news: Son of Anton strikes again! HalluSquatting and using Claude to defend itself CISA KEV's Revolving Door LLM's hallucinate and companies get sued Additionally - GitLost Yet even more Linux vulnerabili

Linux Tech Segment & Vulnerabilities Galore - PSW #933
Jul 2, 20262h 9m
This week we have a technical segment based on the response to "Atomic Arch", an updated open-source tool to help you catch malicious packages. In the security news: Exploitarium A hot messy summer of vulnerabilities AI

Cloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #932
Jun 25, 20262h 13m
First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure! This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Next up in the securi

GPS, PCI, ARCH, OH MY! - PSW #931
Jun 18, 20262h 6m
In the security news this week: GPS spoofing and satellite jamming are getting way too accessible Rekeying satellites in orbit sounds terrifying Cyber extortion and whether criminals still have ethics AI helping cybersec

Trolling Microsoft With Vulnerabilities - PSW #930
Jun 11, 20262h 2m
In the security news: Trolling Microsoft With Vulnerabilities Fable 5 loves guardrails Binwalk vulnerability EMBA and local models EDRChoker AI worms Interesting Arista vulnerability added to KEV BOD 26-04 and stakeholde

Security Researchers Are Threat Actors - PSW #929
Jun 4, 20262h 1m
This week in the security news: Security Researchers Are Threat Actors according to Microsoft Hands-free malicious firmware If you've ever typed "ls" in Windows, this is for you Cisco makes more patches, wants you to pay

Linux Supply Chain How-To - PSW #928
May 28, 20262h 4m
This week we have a technical segment focused on Linux! Paul released a script that helps you get a handle on Linux supply chain security, and new features allow you to assess the state of Secure Boot on your Linux syste

FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927
May 21, 20262h 2m
In the security news this week: FCC router bans and the hidden firmware update problem Why extending support timelines actually improves security Github supply chain concerns and the evolving SBOM ecosystem CRA and NIS2

You're not going to patch your way out of this - PSW #926
May 14, 20262h 2m
This week: New Yellowkey bitlocker bypass and what it means for you Hackers can run you over with a robot lawnmower FCC says new things about routers, again Glitching with AI almost no false positives AI thought it was e

Getting Rid of Your VPN - Rob Allen - PSW #925
May 7, 20262h 4m
Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is spon

FIRESTARTER - PSW #924
Apr 30, 20262h 2m
This week in the security news: Are you a FIRESTARTER? Eavesdropping via fiber-optic cables Copy Fail - more Linux LPE Github RCE Running Linux on a PS5 BadUSB tricks SilentGlass and HDMI threats Sonicwall and vague deta

Back to (or Start) Fundamentals? - Rajesh Khazanchi - PSW #923
Apr 23, 20262h 3m
This week: Larry's in the host seat and chaos ensues. We dig into: A very questionable story about tracking a warship with a $5 Bluetooth tracker Serial-to-IP devices quietly sitting in critical infrastructure… and full

The AI "Vulnpocolypse" Is Real? - PSW #922
Apr 16, 20262h 4m
This week: CSA issues guidance to CISOs on Mythos Vuln management woes Windows tells you about Secure Boot AI-assisted firmware vuln hunting The dumbest hack Edge decay and the failing perimeter Mac OS X on a Wii Little

AI Makes All Bug Shallow? - PSW #921
Apr 9, 20262h 5m
This week: Rage dropping 0-Day Claude Mythos, things are different now From UART to root, on a device made in China, where's the FCC? More CUPS vulnerabilities Russians are hacking routers, FCC ban doesn't stop them Mong

What Is A Router? (And all things AI) - PSW #920
Apr 2, 20262h 5m
In the Security News: Claude leaks source code and new models Two really smart people say AI is finding vulnerabilities better than ever Windows is using your internet to send updates to strangers BIG-IP APM vulnerabilit