Épisodes

  • Azure DDoS, Certificate Revocations, and ESXi Ransomware
    Aug 12 2024

    📢 From DDoS attacks to discovering a new cryptojacking campaign, tune in to our NEW episode of #CryingOutCloud to learn about all the latest cloud security news. Join our hosts Eden and Amitai as they dive into the latest cloud security stories: * SeleniumGreed: Wiz Research discovered a new cryptojacking campaign targeting SeleniumGrid * Why your Starbucks app went down? * Internet chaos and lessons learned from DigiCert revoked certificates. * ESXi ransomware: The danger of trusting by name.

    Afficher plus Afficher moins
    25 min
  • Navigating Hyper Growth, AI Impact, and Mandiant Memories - Special Guest: Ryan Kazanciyan
    Aug 5 2024

    📢 Tune in for an exclusive session with Ryan Kazanciyan on securing a security vendor, hyper-growth, and AI impact in the latest podcast episode of #CryingOutCloud! Join our hosts, Amitai Cohen and Eden Koby Naftali, as they dive into cloud security with Ryan Kazanciyan, our seasoned expert leading security at @Wiz. 🔍 Episode Highlights: 📌 Managing security during hyper growth: challenges and lessons learned. 📌 Ryan's experiences at Mandiant and the impact of the APT1 investigation on his approach to security. 📌 Current security trends and the role of AI in security. 📌 Ensuring safe use of AI tools like ChatGPT within the organization for internal use and product development.

    Afficher plus Afficher moins
    38 min
  • SAPwned: SAP AI Core vulnerabilities - Special Guest: Hillai Ben-Sasson
    Jul 17 2024

    📢 Tune in to our special episode with Hillai Ben-Sasson with all you need to know about #SAPwned. TL;DR - The Wiz Research Team uncovered serious vulnerabilities in SAP AI Core, revealing potential risks in #AI infrastructure.

    Afficher plus Afficher moins
    9 min
  • CROC Talks - Securing DBs, Cloud Threat Intel, and Detection- Special Guest: Snowflakes’ Haider Dost
    Jul 15 2024

    📢 Tune in to Snowflake's Haider Dost for an exclusive session on Securing Databases, Cloud Threat Intelligence, and Detection strategies.

    The latest podcast episode of #CryingOutCloud is LIVE! Join our special hosts, @Alon Schindel and @Eden, as they dive deep into the world of cloud security with Haider Dost, Head of Global Threat Detection and Threat Intelligence at Snowflake. 🔍 Episode Highlights: 📌 Recent campaign targeting Snowflake customers. 📌 Discussion on the new mandatory MFA for Snowflake admins and its impact. 📌 Architecture of detection in the cloud & logging. What does it mean to work in a highly regulated environment compared to a fast-growing company like Snowflake. 📌 Defining "good security" in traditional vs. cloud-native settings.

    Afficher plus Afficher moins
    30 min
  • CROC News: Firewall Fumbles, Gitloker Etiquette, and Private Cloud Compute
    Jun 28 2024

    📢 From data privacy norms in the age of AI — tune in to the latest episode of #CryingOutCloud with all you need to know from the cloud security news 🚨 Join Eden Naftali and Amitai Cohen as they dive into: 🔍 How a new AI processing cloud service is challenging data privacy norms.

    🛡️ The implications of a potential firewall misconfiguration and how to secure your environment.

    🔐 The latest ransomware attacks on GitHub repositories and how to safeguard your data.

    ⚠️ A new discovery by Wiz research: crypto-jacking campaign targeting Kubernetes clusters.

    🐘 Critical remote code execution vulnerability in PHP and how to mitigate the risk.

    Afficher plus Afficher moins
    24 min
  • CROC Talks: RCE Vulnerability in Ollama explained
    Jun 24 2024

    💥 EXCLUSIVE: Wiz Research uncovers CVE-2024-37032, aka #Probllama — a vulnerability in Ollama that that left thousands of #AI models exposed 😲

    Afficher plus Afficher moins
    11 min
  • CROC Talks: Chief Llama Officer and IBM CISO - Jerry Bell
    Jun 6 2024

    What is it like to be IBM's 'Chief Llama Officer'? 🦙 🎙️ Tune in as Jerry Bell shares his journey from crashing his first computer at 10 to leading IBM's Public Cloud Security What's on today's agenda? 😲 Managing a popular 'Mastodon' server post-Twitter acquisition 🛡️ Challenges and surprises as IBM's CISO 🔐 Insights on the security implications of M&A

    Afficher plus Afficher moins
    39 min
  • CROC News: Ninjas, Grand Theft AI, and Backlogged CVEs
    May 27 2024

    🎙️ All that's 🔥 in the cloud: From logging and cloud attacks to NVD backlog updates. what's on today's agenda? 1️⃣ Discover how logging bypass made password-spray attacks undetectable. 2️⃣ Learn about the latest way attackers are monetizing cloud access - by selling access to other people's AI models. 3️⃣ NVD's ongoing backlog - Hear about how the industry is dealing with it.

    Afficher plus Afficher moins
    23 min