YOUR HOME FOR LINUX-RELATED FUN AND LEARNING

Connect with Learn Linux TV:

  • YouTube
  • LinkedIn
  • GitHub
  • Patreon
  • Latest Updates
  • Courses
    • Linux Essentials: The Complete Certification Workshop
    • Linux Crash Course
    • Getting started with Ansible
    • vim Text Editor for Beginners
    • Getting Started with Tmux
    • Bash Scripting on Linux
    • OpenStack Administration Guide
    • Proxmox Virtual Environment Full Course
    • Docker Essentials
  • Shop
  • Books
  • Community
  • Linux Consulting
  • About
    • About LearnLinuxTV
    • Content Ethics
    • Request Assistance
  • Latest Updates
  • Courses
    • Linux Essentials: The Complete Certification Workshop
    • Linux Crash Course
    • Getting started with Ansible
    • vim Text Editor for Beginners
    • Getting Started with Tmux
    • Bash Scripting on Linux
    • OpenStack Administration Guide
    • Proxmox Virtual Environment Full Course
    • Docker Essentials
  • Shop
  • Books
  • Community
  • Linux Consulting
  • About
    • About LearnLinuxTV
    • Content Ethics
    • Request Assistance

All Content

⇨

see all

  • Enterprise Linux Security Episode 86 – The ‘xz’ Fiasco

    On this podcast, Jay and Joao have discussed multiple times a situation where a threat actor submits a pull request that’s more than the project bargained for. And now, we have a situation where OpenSSH was (almost) backdoored by a commit by a maintainer of the xz project. Don’t miss this episode for all the details!

    YouTube player

    Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

    Download Links

    • MP3 version
    • Ogg version

    Relevant Articles

    • A Deep Dive on the xz Compromise (Joao’s Article)
    • XZ Utils Supply Chain Attack: A Threat Actor Spent Two Years to Implement a Linux Backdoor

    ⇨

    Read more: Enterprise Linux Security Episode 86 – The ‘xz’ Fiasco
  • Enterprise Linux Security Episode 84 – Security Debt

    You may have heard of “technical debt”, but have you heard of “security debt”? In this episode, Jay and Joao will tell you all about it and why it’s a major issue for organizations.

    YouTube player

    Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

    Relevant Articles

    • Why software ‘security debt’ is becoming a serious problem for developers

    Download Links

    • MP3 version
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 84 – Security Debt
  • Enterprise Linux Security Episode 83 – FBI/NCA vs Lockbit

    Through a joint effort, the FBI as well as NCA struck a major blow to the Lockbit ransomware group. In this episode, Jay and Joao will discuss this story as well as the state of Linux in the enterprise/open-source landscape.

    YouTube player

    Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

    Relevant Articles

    • Lockbit cybercrime gang disrupted by Britain, US and EU
    • Enterprise Linux & Open-Source Landscape Report
    • Police arrest LockBit ransomware members, release decryptor in global crackdown
    • United States Sanctions Affiliates of Russia-Based LockBit Ransomware Group
    • Lockbit Decryptor

    Download Links

    • MP3 version
    • Ogg version

    /etc

    Here’s a screenshot of the snarky message that was mentioned during the podcast.

    ⇨

    Read more: Enterprise Linux Security Episode 83 – FBI/NCA vs Lockbit
  • Enterprise Linux Security Episode 82 – In the Name of the Law

    When a threat actor breaks into a router and adds firewall rules that the owner didn’t approve of, that’s considered hacking. But when the FBI does it… …it isn’t?! In this episode Jay and Joao discuss a recent story where the FBI did exactly that, and they’ll also discuss how Microsoft has become the biggest “face palm” discussed on the podcast so far.

    YouTube player

    Thanks to TuxCare for sponsoring the Enterprise Linux Security podcast. Check out their awesome services to see how they can simplify Linux administration!

    Relevant Articles

    • Chinese malware removed from SOHO routers after FBI issues covert commands
    • Russia Hacked Microsoft Execs β€” SolarWinds Hackers at it Again

    Download links

    • MP3 Version
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 82 – In the Name of the Law
  • Enterprise Linux Security Episode 80 – Stop Paying Threat Actors!

    In this episode, Jay and Joao will discuss an update on the GTA source code theft, how much threat actors are making from ransomware, and more!

    YouTube player

    Thanks to TuxCare for sponsoring this podcast! Check out how they can make managing Linux servers much easier.

    Episode-Specific Links

    • ‘everything’ blocks devs from removing their own npm package
    • CentOS Reaches End-of-Life (EoL) Soon

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, smaller filesize)
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 80 – Stop Paying Threat Actors!
  • Enterprise Linux Security Episode 78 – Mirai: The Untold Story

    The Mirai botnet brought the entirety of the internet to its breaking point back in 2016, taking down many prominent web sites. Now, an article from Wired has emerged that reveals the full story behind the scenes – how the threat actors got started, how the events played out, as well as what they’re up to these days. Join Jay and Joao as they discuss this very interesting story!

    YouTube player

    Thanks to TuxCare for sponsoring this podcast! Check them out to see how they can help you level up your Linux administration!

    Relevant Article

    • Original article by Wired that follows the entire story

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, smaller file size)
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 78 – Mirai: The Untold Story
  • Enterprise Linux Security Episode 77 – Security News Sync

    In this episode, Jay and Joao catch up on recent stories. Among the topics they’ll discuss another version of CentOS going end of life (and why upgrading isn’t so straight-forward), the recent curl vulnerability, and more!

    YouTube player

    Thanks toΒ TuxCareΒ for sponsoring this podcast! Check out theirΒ Extended Lifecycle Support solutionΒ to keep your CentOS 7 installations supported with continued security updates while you plan your migration!

    Video-specific links

    • Hyped up curl vulnerability falls short of expectations
    • CentOS 7 will reach its End of Life in June 2023
    • Hackers exploit Looney Tunables Linux bug, steal cloud creds
    • CentOS 8 Stream also reaches EOL soon

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, smaller file size)
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 77 – Security News Sync
  • Enterprise Linux Security Episode 75 – RepoJacking

    We’ve talked about Supply Chain Attacks on this podcast before, and in this episode Jay and Joao discuss another form of this popular attack vector – RepoJacking! RepoJacking occurs when a repository (such as one hosted on Github) changes information, and due to a link between the old repository info and the new – threat actors can take advantage of this. Join Jay and Joao for a discussion on this attack vector.

    YouTube player

    Relevant Articles

    Thanks to TuxCare for sponsoring this episode! Check them out to see how they can help take your Linux Administration game to the next level.

    • GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, smaller file size)
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 75 – RepoJacking
  • Enterprise Linux Security Episode 74 – Unlucky in Vegas

    There’s a multitude of ways you can lose money in Las Vegas, but this time it’s not from gambling. In this episode, Jay and Joao will discuss a recent and still developing story where MGM was the target of what appears to be a ransomware attack.

    YouTube player

    Thanks to TuxCare for sponsoring this podcast! Check them out and make your life as a SysAdmin much easier!

    Relevant Articles

    • What Happens in Vegas: MGM Reports β€˜Ransomware’ Attack
    • Cybersecurity the Biggest Challenge for Smaller Organizations

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, smaller file size)
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 74 – Unlucky in Vegas
  • Enterprise Linux Security Episode 73 – TruffleHog and CVSS version 4.0

    In this episode, Jay and Joao will discuss a recent discovery by Truffle Security that has found 4,500 websites that have exposed a very critical directory. In addition, the upcoming Common Vulnerability Scoring System (CVSS) update, which will bring to version 4.0 – along with some important changes you’ll need to understand.

    YouTube player

    Relevant Articles

    • 4,500 of the Top 1 Million Websites Leaked Source Code Secrets
    • Common Vulnerability Scoring System Version 4.0
    • CVSS version 4.0 Examples

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, smaller file size)
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 73 – TruffleHog and CVSS version 4.0
  • Enterprise Linux Security Episode 72 – Surveillance Facepalm

    Imagine needing to ask your government permission in order to perform tasks such as installing a security patch, implementing an Intrusion Detection System, updating firmware or upgrading your operating system? If this sounds too ridiculous to be true, then you’re right – it is ridiculous, but unfortunately it’s a real proposal. In the U.K., Investigatory Powers Act 2016 (IPA) has had an adjustment proposed that could potentially make securing your systems more difficult than it’s ever been. In this episode, Jay and Joao discuss how these potential changes will complicate pretty much everything.

    YouTube player

    Relevant Articles

    • Check out Joao’s Book “Bugs Behind the Vulnerabilities” (Free e-book)
    • UK Article Change Proposal
    • Article from justsecurity.org

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, lower quality)
    • Ogg version

    ⇨

    Read more: Enterprise Linux Security Episode 72 – Surveillance Facepalm
  • Enterprise Linux Security Episode 71 – Internet DRM

    In this episode, Jay and Joao talk about two recent news developments that may have important implications on the overall industry. First, In response to Microsoft’s recent Azure debacle, a US Senator calls for a probe to look into the matter. Second, our main story is yet another facepalm worthy idea from Google that aims to add “integrity” to our browsers, but it’s oddly lacking in said integrity and almost completely devoid of common sense. Google’s “Web Integrity Protection” seems to protect only their ad dollars while making browsing more tedious for the end-user. Will it pass? What is it exactly? Jay and Joao have all the answers in this episode!

    YouTube player

    Download Links

    • MP3 version
    • MP3 version (lower bitrate, smaller file size)
    • Ogg version

    Relevant Articles

    • Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email
    • Senator calls for probe in Microsoft breach
    • Vivaldi’s Take on Google’s “Web Integrity Protection”
    • Ars Technica article on Web Integrity Protection
    • Web Integrity Protection Github page

    ⇨

    Read more: Enterprise Linux Security Episode 71 – Internet DRM
Previous Page
1 2 3 4 5 … 7
Next Page
  • YouTube

YOUTUBE

  • Twitter

twitter

  • LinkedIn

LINKEDIN

Copyright 2024 Learn Linux TV, all rights reserved.

All content on this channel adheres to the company’s content ethics guidelines.