『147 - The Evidence Gap』のカバーアート

147 - The Evidence Gap

147 - The Evidence Gap

無料で聴く

ポッドキャストの詳細を見る

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Send us Fan Mail

We track a single failure pattern across patching, supply chain security, SOC triage, and ransomware recovery: confusing a status label with proof. Using SonicWall SMA 1000 exploitation, an async API NPM compromise with valid provenance, and Fairlife’s production disruption, we lay out what “closure evidence” actually looks like when consequences are real.
• the evidence gap between having a control and trusting its result
• SonicWall SMA 1000 vulnerabilities, exploited-in-the-wild context, and why patching is not a compromise verdict
• what to preserve and review after updating an internet-facing remote access appliance
• async API supply chain compromise mechanics using GitHub Actions to publish to NPM
• why OIDC provenance and build attestations prove lineage, not intent
• scoping guidance that separates lock file exposure from module execution evidence
• Fairlife ransomware disruption as a reminder that restored systems are not the same as restored production
• DHS HSIN false positive dismissals and why closure confidence must match asset consequence
• risk-based vulnerability management notes for Siemens RuggedCom ROCS 2, Microsoft ADFS, and Cisco Room OS
• a practical model for designing deliberate closure evidence across vuln management, CI pipelines, SOC cases, and resilience testing

One thing to do this week is run a bounded false positive quality review.


Support the show

Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


adbl_web_anon_alc_button_suppression_t1
まだレビューはありません