PodcastyTechnologia7 Minute Security

7 Minute Security

Brian Johnson
7 Minute Security
Najnowszy odcinek

718 odcinków

  • 7 Minute Security

    7MS #719: Baby's First OpenClaw

    24.04.2026 | 28 min.
    Hey friends! This week's episode is "Baby's First OpenClaw" – basically me shouting into the void hoping a smart listener will DM me and explain why this thing is supposed to be life-changing. Because right now? I'm a little underwhelmed.
    Here's the journey so far:
    The Mac mini quest: After seeing OpenClaw all over my feeds (people curing diseases! solving crimes!), I caved and impulse-bought a Mac mini. They were sold out everywhere, so I ended up paying twice what I wanted. Ick.
    Surprise MDM: First boot on the shiny new Mac, I found it auto-pre-enrolled in some other company's MDM with full remote control. Massive props to the Amazon seller for getting the serial untagged in Apple's database within an hour, so I could wipe and reinstall fresh.
    Pro tips for using Claude on projects like this: (1) give it a few paragraphs of context up front about who you are and what you want, and (2) have it maintain a README.md as you go so you don't lose context when you come back to the project later.
    Security-forward OpenClaw setup: Separate admin and daily-driver accounts, enable FileVault, isolate the box, run OpenClaw as a limited user, lock down Telegram so only my user ID can talk to the bot (apparently strangers have found other folks' bots and started issuing shell commands – yikes).
    The underwhelm: So far OpenClaw can check my email (or I can open my email app)… add a calendar event (or I can open Outlook)… write a script (or I can fire up Claude Code). And a lot of the juicier integrations are flagged as suspicious. So overall, I'm kind of gun-shy around this very expensive chat bot.
    This is a call for help, friends! If you're an OpenClaw power user and it's made your life meaningfully better, please reach out and help me see the light.
  • 7 Minute Security

    7MS #718: Fun Professional and Personal AI Project Ideas

    17.04.2026 | 28 min.
    Hey friends! After last week's heavy episode about my wife's health scare in Punta Cana, today's is a lighter one. (Quick update: she's doing better – still recovering, but appetite's back and she's got some pep again. Thanks so much to everyone who sent kind messages.)
    Today I'm gushing about how AI has been making my IT and security life way more efficient:
    Firewall migration: Had AI walk me through a WatchGuard T15W → T25W migration (no clean config export path). AI captured everything – screenshots, branch office VPN, VLANs, firewall rules, DHCP reservations – all organized and replayed step-by-step. The whole project took ~1 hr 15 min (plus 30 min hunting down a subnet typo that was 100% my fault).
    GOAD lab automation: Worked with AI to build a script that handles the full lifecycle of my Light Pentest GOAD student lab – tear it down, rebuild from latest, assign Tommy Boy-themed passwords and sync user accounts to the Apache Guacamole and lab connections. Speaking of which – Light Pentest GOAD class will be re-offered soon once the calendar firms up!
    External pentest wrapper scripts: Finally automated the boring auxiliary testing stuff – nmap, Shodan API, Nessus queuing, subdomain hijacking checks, metadata searches, cred spraying against M365, sysleaks lookups – all correlated and deduplicated into one push-button menu.
    SysReptor automation: If you're not using SysReptor for reporting, check it out. Piping JSON findings straight into reports via API as I test has been a game-changer. A webinar on this might be in 7MinSec's future.
    Got cool ways you're using AI for IT/security work? We'd love to hear them!
  • 7 Minute Security

    7MS #717: I Gave Up My Wife's PHI (And I'd Do It Again)

    10.04.2026 | 48 min.
    Hello friends! Today's episode is a bit of a detour from our usual content — it's part vacation horror story, part security/privacy confession. My wife got seriously ill during our spring break trip to Punta Cana, and in the chaos of navigating a foreign hospital at 2 a.m. with zero sleep and a pile of Spanish medical documents, I threw every privacy best practice I've ever preached straight into the ocean. Here's what we cover:
    How a dream all-inclusive resort trip turned into an ambulance ride and a 3-day hospital stay faster than you can say "gastroenteritis"
    Why I uploaded my wife's full medical history, labs, and medication records to AI — unredacted (with no regrets)
    How AI helped me translate docs, track lab trends, brief stateside nurses, and build a full medication schedule with phone reminders (helpful considering the hospital staff's answer to everything was "sorry, no English")
    The absolute legend named Luis who got us through Punta Cana airport security in 15 minutes flat
    Why if you're ever the person back home receiving updates about a medical emergency overseas, Google is not your friend
    My honest security take: sometimes the right risk-based decision is to breach yourself
  • 7 Minute Security

    7MS #716: Tales of Pentest Pwnage – Part 83

    03.04.2026 | 33 min.
    Today is my favorite pentest pwnage tale of 2026 – and maybe ever!  It centers around an ADCS abuse via an attack path I'd never seen before.  Tips include:
    Use Netexec to pull Powershell history
    Trying to steal reg hives and the EDR is made?  Try copying them out to \\some-other-server.domain.com\share
    This post featured interesting use of the Responder -N option
  • 7 Minute Security

    7MS #715: Tales of Pentest Pwnage – Part 82

    27.03.2026 | 20 min.
    Hola friends!  Today's another fun tale of pentest pwnage.  This time we started with no credentials and then set off on the bumpy journey from no-cred zero to domain admin hero!  One specific reference in today's podcast that may be helpful to you is setting up ntlmrelayx to listen on port 3128.

Więcej Technologia podcastów

O 7 Minute Security

7 Minute Security is a weekly information security podcast focusing on penetration testing, blue teaming and building a career in security. The podcast also features in-depth interviews with industry leaders who share their insights, tools, tips and tricks for being a successful security engineer.
Strona internetowa podcastu

Słuchaj 7 Minute Security, AI CODZIENNIE - czyli co słychać w sztucznej inteligencji i wielu innych podcastów z całego świata dzięki aplikacji radio.pl

Uzyskaj bezpłatną aplikację radio.pl

  • Stacje i podcasty do zakładek
  • Strumieniuj przez Wi-Fi lub Bluetooth
  • Obsługuje Carplay & Android Auto
  • Jeszcze więcej funkcjonalności

7 Minute Security: Podcasty w grupie

  • Podcast You Are Heroic with Brian Johnson
    You Are Heroic with Brian Johnson
    Edukacja, Medycyna Alternatywna, Samodoskonalenie, Zdrowie i Fitness
Media spoecznościowe
v8.8.12| © 2007-2026 radio.de GmbH
Generated: 4/26/2026 - 8:12:28 AM