Bringing Autonomy to AppSec – Dr. David Brumley – ESW #255
Article on competition: https://www.darpa.mil/about-us/timeline/cyber-grand-challengeTechnical article on approach: https://spectrum.ieee.org/mayhem-the-machine-that-finds-software-vulnerabilities-then-patches-themExample vulns discovered: https://forallsecure.com/blog/forallsecure-uncovers-critical-vulnerabilities-in-das-u-boothttps://github.com/forallsecure/vulnerabilitieslab
Dr. Brumley is the CEO and co-founder of ForAllSecure, a company with the mission to secure the world’s software. He is also is an Associate Professor at Carnegie Mellon University (currently on leave) with a primary appointment in the Electrical and Computer Engineering Department and a courtesy appointment in the Computer Science Department. He is also the previous Director of CyLab, the CMU Security and Privacy Institute. His research focuses on software security.
Prof. Brumley received his Ph.D. in Computer Science from Carnegie Mellon University, an MS in Computer Science from Stanford University, and a BA in Mathematics from the University of Northern Colorado. He served as a Computer Security Officer for Stanford University from 1998-2002 and handled thousands of computer security incidents in that capacity. He is the faculty mentor for the CMU Hacking Team Plaid Parliament of Pwning (PPP), which is ranked internationally as one of the top teams in the world according to ctftime.org. The team was ranked #1 in 2011, #2 in 2012, and #1 in 2013, and won DefCon 2013. He received the USENIX Security best paper awards in 2003 and 2007, an ICSE distinguished paper award in 2014.
Prof. Brumley honors include being selected for the 2010 DARPA CSSP program and 2013 DARPA Information Science and Technology Advisory Board, a 2010 NSF CAREER award, a 2010 United States Presidential Early Career Award for Scientists and Engineers (PECASE) from President Obama (the highest award in the US for early career scientists according to wikipedia), and a 2013 Sloan Foundation award.
- We're always looking for great guests for all of the Security Weekly shows! Submit your suggestions by visiting https://securityweekly.com/guests and completing the form!
Dragons & Unicorns, Phishing Training, GreyNoise, & Becoming Domain Admin – ESW #255
- Don't miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!
- We had an absolute blast putting together this year's SW Unlocked virtual event! All presentations are now available on-demand for your viewing pleasure. Please visit https://securityweekly.com/unlocked to register and watch now!
Adrian Sanabria
- FUNDING: Corellium Secures $25M Series A Round, Led by Paladin Capital Group with Participation from Cisco Investments
- TRENDS: Why the startup world needs to ditch “unicorns” for “dragons”
- GOING PUBLIC: Cybersecurity Saas company ZeroFox to go public via merger with SPAC in deal valued at about $1.4 billion
- REPORTS: Phishing in Organizations: Findings from a Large-Scale and Long-Term StudySecurity awareness training might be less valuable than we had thought. Potentially harmful, even?
- SUPPLY CHAIN: AWS suffers third outage of the monthhttps://arstechnica.com/information-technology/2021/12/aws-suffers-third-outage-of-the-month/
- VULNERABILITIES: Microsoft warns of easy Windows domain takeover via Active Directory bugsThis title is evergreen - both historically and into the future.
- LOG4J: As Log4j sent defenders scrambling, this startup made its threat data free
- RUMORS: SentinelOne’s $2.5 billion takeover of Orca Security falls through after shares plummet
- SQUIRREL: Tardigrade is first multicellular organism to be quantum entangled
- SQUIRREL: RadioShack Returns as a Crypto Company
ESW End-of-Year Wrap Up – ESW #255
- Don't forget to check out our library of on-demand webcasts & technical trainings at securityweekly.com/ondemand.
