Understanding Web Application Client-Side Risk – Matt McGuirk – ESW #276
Matt McGuirk is an expert in JavaScript, web technologies, and both client-side risk and client-side attacks. He has over 15 years of experience in web application development, website administration, and cybersecurity. Additionally, he has provided consultation and analysis to Fortune 50 companies on how best to secure their customer-facing web properties and business critical web applications. Matt lives in the American Northeast with his wife and two dogs.
- Security Weekly listeners, save $100 on your RSA Conference 2022 Full Conference Pass! RSA Conference will be live in San Francisco June 6th-9th, 2022. Security Weekly will be there in full force, delivering real-time, live coverage and interviewing some of the event’s top speakers and sponsors. To register using our discount code, please visit https://securityweekly.com/rsac2022 and use the code 52UCYBER. We hope to see you there!
Salesforce’s Journey Towards Complete Customer MFA – Ian Glazer – ESW #276
Ian Glazer is the Senior Vice President for Identity Product Management, at Salesforce. His responsibilities include leading the product management team, product strategy and identity standards work. Prior to that, he was a research vice president and agenda manager on the Identity and Privacy Strategies team at Gartner, where he oversaw the entire team’s research. He is the co-founder IDPro, the professional organization for digital identity management, and works to deliver more services and value to the IDPro membership, raise funds for the organization, and help identity management professionals learn from one another. During his career in the identity industry, he has co-authored a patent on federated user provisioning, co-authored and contributed to user provisioning specifications, is a noted blogger, speaker, and photographer of his socks.
- Don't miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!
ReliaQuest, Mimecast Delisted, 57th Unicorn, Expired Certs, & CyberSec Skill Crisis – ESW #276
- Don't forget to check out our library of on-demand webcasts & technical trainings at securityweekly.com/ondemand.
- We're always looking for great guests for all of the Security Weekly shows! Submit your suggestions by visiting https://securityweekly.com/guests and completing the form!
Adrian Sanabria
- FUNDING: Security Vendor Semperis Lands $200M Funding Round Led By KKR
- FUNDING: Devo Announces $100 Million Funding Round Led by Eurazeo to Fuel Global Expansion and Acquisitions$100M Series F with a valuation of $2B, making Devo our newest and 56th Cybersecurity unicorn! Eurazeo led the round along with Insight Partners, Georgian, TCV, General Atlantic, Bessemer Venture Partners, Kibo Ventures and ISAI Cap Venture
- FUNDING: JupiterOne Achieves Valuation of Over $1B with $70M Series C Funding to Fuel Innovation in Cybersecurity and Democratize Access for AllAnd our very own Tyler Shield's company makes our 57th Unicorn after a $70M Series C with a $1B+ valuation!
- FUNDING: Announcing the First Images Designed for a Secure Software Supply Chain$50M Series A. The round was led by Sequoia Capital with participation from Amplify Partners, Chainsmoker’s Mantis VC, K5/JPMC, Banana Capital, and LiveOak Venture Partners
- FUNDING: Ordr Secures $40 Million in Series C Funding to Answer Increased Demand for Connected Device Security
- FUNDING: Hoxhunt raises $40M to solve the hardest part of cybersecurity: people
- FUNDING: Seemplicity Raises $32 Million with First-of-its-Kind Productivity Platform for Modern Security Teams to Scale Risk Reduction Efforts
- FUNDING: Open Source Security Gets $30M Boost From Industry Heavy Hitters
- FUNDING: Laminar Doubles Funding in Less Than Six Months to $67 Million, Leading the Way in Cloud Data Security
- FUNDING: Vade Lands $30 Million in New Funding Round
- FUNDING: Tidelift Raises $27 Million in Series C Funding as Open Source Software Supply Chain Health and Security Become Urgent Priorities
- FUNDING: Incognia Raises $15.5M Series A to Combat Increased Identity Fraud
- FUNDING: ShardSecure Secures $11M in Series A Funding
- FUNDING: Forgepoint Capital Fuels Cyber Market, Launches New Incident Response Firm Surefire Cyber with $10 Million in Series A Funding
- FUNDING: OT Remote Access Firm Xona Raises $7.2 Million in Series A Funding
- FUNDING: Red Access Emerges from Stealth with $6M Round to Secure Every Web Session Across any Browser, App and Device
- ACQUISITIONS: Mimecast goes private after Permira completes $5.8B acquisition – Boston Business JournalFirst announced last December, this acquisition has now closed and Mimecast has been taken private.
- ACQUISITIONS: ReliaQuest to Acquire Digital Shadows
- NEW PRODUCT: Another arrow in the quiver: Mastercard strengthens cybersecurity consulting practice with new Cyber Front threat simulation platform
- TRENDS: Cybersecurity performance in public markets & 2022 economic downturn
- TRENDS: Cybersecurity Performance Summary – Public Markets (updated automatically every 20 minutes)
- TRENDS: Trellix Survey Findings: A Closer Look at the Cyber Talent GapIf you want to jump into the full survey results for the previous story, it's all here.
- TRENDS: Bad news: The cybersecurity skills crisis is about to get even worse"Cybersecurity firm Trellix commissioned a survey of 1,000 cybersecurity professionals globally and found that 30% are planning to change professions within two or more years." This is a decent sample size. While surveys are difficult and unreliable in the best of times, the question was well worded and does trouble me a bit. One issue is that it didn't account for soon-to-be-retirees. The biggest thing I'd want to see is the cross section of time-in-industry across this 30%. Are we losing new people? Industry veterans? Even losses across time-in-industry?
- REBRANDING: McAfee Enterprise SSE Business Renamed Skyhigh Security
- SQUIRREL: Expired Cert + IoT = PAINJoey Piccola on Twitter - Never thought I’d say this: My window blinds won’t open because of an expired cert.
- SQUIRREL: Gene-editing experiment turns fluffy hamsters into ‘aggressive’ rage monsters











