『InfoSec.Watch』のカバーアート

InfoSec.Watch

InfoSec.Watch

著者: Infosec.Watch
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

The InfoSec.Watch Podcast delivers the week’s most important cybersecurity news in a fast, clear, and actionable format.
Each episode breaks down major incidents, vulnerabilities, threat-actor activity, and security trends affecting modern organizations — without the noise or hype.

The show translates complex cyber topics into practical insights you can use immediately in your job, whether you work in security engineering, cloud security, threat detection, governance, or IT.

If you want to stay ahead of emerging threats, sharpen your defensive mindset, and get a reliable summary of what actually matters each week, this is your new essential briefing.

Actionable Cybersecurity Insights — Every Week.

© 2026 InfoSec.Watch
政治・政府 経済学
エピソード
  • 146 - Invisible Threats: The Risks of Automatic Code Execution
    2026/07/13

    Send us Fan Mail

    We track the thread running through the biggest security stories of the week: automatic execution paths that get trusted too far and monitored too little. We break down what went wrong across legacy servers, the software supply chain, edge devices, and AI platforms, then land on one practical way to reduce risk fast.
    • ColdFusion path traversal leading to unauthenticated remote code execution under risky RDS settings
    • Legacy exposure driven by forgotten toggles, missing ownership, and incomplete asset inventory
    • JS Crambler NPM compromise using real publisher credentials and a cross-platform info stealer
    • Attacker pivot from preinstall hooks to imported code that executes at runtime
    • ORB relay networks built from compromised routers to hide espionage origins
    • AI tooling risks where “small” permissions reach across tenants and managed runtimes
    • NPM v12 turning install scripts off by default and winding down weak publisher tokens
    • Typosquat payment SDKs and fake aged GitHub repos undermining trust heuristics
    All of that is in this week's written issue at InfoSec.watch.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    11 分
  • 138 - Security Leverage Points
    2026/05/18

    Send us Fan Mail

    We track the security stories that give attackers the most leverage, from AI-assisted exploit development to SaaS platform compromise, manufacturing ransomware, and high-impact vulnerabilities. We end with a practical defensive check: a short control plane exposure register that shows exactly which systems could change trust, access, routing, revenue, or production at scale.
    • AI-assisted zero-day exploit and why admin tools move to the top of the patch queue
    • Phishing-resistant MFA and reviewing trusted path assumptions for bypass risk
    • Canvas incident and the need for tenant-level SaaS impact assessment
    • Manufacturing ransomware as business disruption strategy across logistics and production
    • Cisco Catalyst SD-WAN controller authentication bypass and control plane blast radius
    • Exchange OWA KEV-driven mitigations and using deadlines for escalation
    • WordPress FunnelKit exploit leading to WooCommerce checkout skimming and script audits
    • Leverage-point thinking for modern asset inventory and exposure management
    • Control plane exposure register fields, owners, logs, rollback paths, review cadence
    If you want daily updates between episodes, you can find us on X, Facebook, and LinkedIn. Just search InfoSecWatch. And if you haven't already, head over to InfoSec.watch and grab the free weekly newsletter. It's concise, it's practitioner focused, and it lands every week.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    11 分
  • 147 - The Evidence Gap
    2026/07/21

    Send us Fan Mail

    We track a single failure pattern across patching, supply chain security, SOC triage, and ransomware recovery: confusing a status label with proof. Using SonicWall SMA 1000 exploitation, an async API NPM compromise with valid provenance, and Fairlife’s production disruption, we lay out what “closure evidence” actually looks like when consequences are real.
    • the evidence gap between having a control and trusting its result
    • SonicWall SMA 1000 vulnerabilities, exploited-in-the-wild context, and why patching is not a compromise verdict
    • what to preserve and review after updating an internet-facing remote access appliance
    • async API supply chain compromise mechanics using GitHub Actions to publish to NPM
    • why OIDC provenance and build attestations prove lineage, not intent
    • scoping guidance that separates lock file exposure from module execution evidence
    • Fairlife ransomware disruption as a reminder that restored systems are not the same as restored production
    • DHS HSIN false positive dismissals and why closure confidence must match asset consequence
    • risk-based vulnerability management notes for Siemens RuggedCom ROCS 2, Microsoft ADFS, and Cisco Room OS
    • a practical model for designing deliberate closure evidence across vuln management, CI pipelines, SOC cases, and resilience testing

    One thing to do this week is run a bounded false positive quality review.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    13 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません