『146 - Invisible Threats: The Risks of Automatic Code Execution』のカバーアート

146 - Invisible Threats: The Risks of Automatic Code Execution

146 - Invisible Threats: The Risks of Automatic Code Execution

無料で聴く

ポッドキャストの詳細を見る

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Send us Fan Mail

We track the thread running through the biggest security stories of the week: automatic execution paths that get trusted too far and monitored too little. We break down what went wrong across legacy servers, the software supply chain, edge devices, and AI platforms, then land on one practical way to reduce risk fast.
• ColdFusion path traversal leading to unauthenticated remote code execution under risky RDS settings
• Legacy exposure driven by forgotten toggles, missing ownership, and incomplete asset inventory
• JS Crambler NPM compromise using real publisher credentials and a cross-platform info stealer
• Attacker pivot from preinstall hooks to imported code that executes at runtime
• ORB relay networks built from compromised routers to hide espionage origins
• AI tooling risks where “small” permissions reach across tenants and managed runtimes
• NPM v12 turning install scripts off by default and winding down weak publisher tokens
• Typosquat payment SDKs and fake aged GitHub repos undermining trust heuristics
All of that is in this week's written issue at InfoSec.watch.


Support the show

Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


adbl_web_anon_alc_button_suppression_t1
まだレビューはありません