Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Security Weekly Productions. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Security Weekly Productions or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Secrets and their role in infrastructure security - Jawahar Sivasankaran, Chas Clawson, Sergey Gorbaty, Fernando Medrano - ESW #406

2:14:05
 
Share
 

Manage episode 482206786 series 70666
Content provided by Security Weekly Productions. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Security Weekly Productions or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.
Segment 1 - Secrets and their role in infrastructure security

From API keys and tokens to environment variables and credentials, secrets are foundational—and often overlooked—attack surfaces in cloud-native and distributed systems. We break down the risks tied to poor secret hygiene, discuss emerging patterns for secure secret management at scale, and shares insights on integrating secrets management into systems design.

This segment is sponsored by Fastly. Visit https://securityweekly.com/fastly to learn more about them!

Segment 2 - Weekly Enterprise News

In this week's enterprise security news, we have:

  1. Funding, mostly focused on identity security and ‘secure-by-design’
  2. Palo Alto acquires one of the more mature AI security startups, Protect AI
  3. LimaCharlie is first with a cybersecurity-focused MCP offering
  4. Meta releases a ton of open source AI security tooling, including LlamaFirewall
  5. Exploring the state of AI in the SOC
  6. The first research on whether AI is replacing jobs is out
  7. Some CEOs are requiring employees to be more productive with AI
  8. Are prompts the new IOCs?
  9. Are puppies the new booth babes?
  10. We get closure on two previous stories we covered:
    1. one about an ex-Disney employee,
    2. and one about a tiny dog
Segment 3 - Executive Interviews from RSAC

CYWARE The legacy SecOps market is getting disrupted. The traditional way of ingesting large troves of data, analysis and actioning is not efficient today. Customers and the market are moving towards a more threat centric approach to effectively solve their security operations challenges.

  1. CERT Water Management Case Study
  2. Cybersecurity Alert Fatigue! How Threat Intelligence Can Turn Data Overload Into Actionable Insights Blog
  3. Frost & Sullivan's 2024 Threat Intelligence Platform Radar Report
  4. 2025 TIP Buyer’s Guide

This segment is sponsored by Cyware. Visit https://securityweekly.com/cywarersac to request a demo!

SUMOLOGIC Intelligent SecOps is more than a buzzword—it's a blueprint for modernizing security operations through real-time analytics, contextual threat intelligence, and AI-powered automation. In this segment, Sumo Logic’s Field CTO Chas Clawson explains how SOC teams can accelerate detection and response, cut through alert noise, and improve security outcomes by fusing AI-driven automation with human context and expertise. He also shares the latest security capabilities Sumo Logic announced at the RSA Conference to help organizations build and operate Intelligent SecOps.

This segment is sponsored by Sumo Logic. Visit https://securityweekly.com/sumologicrsac to learn more about them!

Visit https://www.securityweekly.com/esw for all the latest episodes!

Show Notes: https://securityweekly.com/esw-406

  continue reading

3101 episodes

Artwork
iconShare
 
Manage episode 482206786 series 70666
Content provided by Security Weekly Productions. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Security Weekly Productions or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.
Segment 1 - Secrets and their role in infrastructure security

From API keys and tokens to environment variables and credentials, secrets are foundational—and often overlooked—attack surfaces in cloud-native and distributed systems. We break down the risks tied to poor secret hygiene, discuss emerging patterns for secure secret management at scale, and shares insights on integrating secrets management into systems design.

This segment is sponsored by Fastly. Visit https://securityweekly.com/fastly to learn more about them!

Segment 2 - Weekly Enterprise News

In this week's enterprise security news, we have:

  1. Funding, mostly focused on identity security and ‘secure-by-design’
  2. Palo Alto acquires one of the more mature AI security startups, Protect AI
  3. LimaCharlie is first with a cybersecurity-focused MCP offering
  4. Meta releases a ton of open source AI security tooling, including LlamaFirewall
  5. Exploring the state of AI in the SOC
  6. The first research on whether AI is replacing jobs is out
  7. Some CEOs are requiring employees to be more productive with AI
  8. Are prompts the new IOCs?
  9. Are puppies the new booth babes?
  10. We get closure on two previous stories we covered:
    1. one about an ex-Disney employee,
    2. and one about a tiny dog
Segment 3 - Executive Interviews from RSAC

CYWARE The legacy SecOps market is getting disrupted. The traditional way of ingesting large troves of data, analysis and actioning is not efficient today. Customers and the market are moving towards a more threat centric approach to effectively solve their security operations challenges.

  1. CERT Water Management Case Study
  2. Cybersecurity Alert Fatigue! How Threat Intelligence Can Turn Data Overload Into Actionable Insights Blog
  3. Frost & Sullivan's 2024 Threat Intelligence Platform Radar Report
  4. 2025 TIP Buyer’s Guide

This segment is sponsored by Cyware. Visit https://securityweekly.com/cywarersac to request a demo!

SUMOLOGIC Intelligent SecOps is more than a buzzword—it's a blueprint for modernizing security operations through real-time analytics, contextual threat intelligence, and AI-powered automation. In this segment, Sumo Logic’s Field CTO Chas Clawson explains how SOC teams can accelerate detection and response, cut through alert noise, and improve security outcomes by fusing AI-driven automation with human context and expertise. He also shares the latest security capabilities Sumo Logic announced at the RSA Conference to help organizations build and operate Intelligent SecOps.

This segment is sponsored by Sumo Logic. Visit https://securityweekly.com/sumologicrsac to learn more about them!

Visit https://www.securityweekly.com/esw for all the latest episodes!

Show Notes: https://securityweekly.com/esw-406

  continue reading

3101 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Listen to this show while you explore
Play