InfoSec.Watch

Infosec.Watch

The InfoSec.Watch Podcast delivers the week’s most important cybersecurity news in a fast, clear, and actionable format. Each episode breaks down major incidents, vulnerabilities, threat-actor activity, and security trends affecting modern organizations — without the noise or hype. The show translates complex cyber topics into practical insights you can use immediately in your job, whether you work in security engineering, cloud security, threat detection, governance, or IT. If you want to stay ahead of emerging threats, sharpen your defensive mindset, and get a reliable summary of what actually matters each week, this is your new essential briefing. Actionable Cybersecurity Insights — Every Week.

  1. 18h ago

    147 - The Evidence Gap

    Send us Fan Mail We track a single failure pattern across patching, supply chain security, SOC triage, and ransomware recovery: confusing a status label with proof. Using SonicWall SMA 1000 exploitation, an async API NPM compromise with valid provenance, and Fairlife’s production disruption, we lay out what “closure evidence” actually looks like when consequences are real.  • the evidence gap between having a control and trusting its result  • SonicWall SMA 1000 vulnerabilities, exploited-in-the-wild context, and why patching is not a compromise verdict  • what to preserve and review after updating an internet-facing remote access appliance  • async API supply chain compromise mechanics using GitHub Actions to publish to NPM  • why OIDC provenance and build attestations prove lineage, not intent  • scoping guidance that separates lock file exposure from module execution evidence  • Fairlife ransomware disruption as a reminder that restored systems are not the same as restored production  • DHS HSIN false positive dismissals and why closure confidence must match asset consequence  • risk-based vulnerability management notes for Siemens RuggedCom ROCS 2, Microsoft ADFS, and Cisco Room OS  • a practical model for designing deliberate closure evidence across vuln management, CI pipelines, SOC cases, and resilience testing  One thing to do this week is run a bounded false positive quality review.  Support the show Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!

  2. May 18

    138 - Security Leverage Points

    Send us Fan Mail We track the security stories that give attackers the most leverage, from AI-assisted exploit development to SaaS platform compromise, manufacturing ransomware, and high-impact vulnerabilities. We end with a practical defensive check: a short control plane exposure register that shows exactly which systems could change trust, access, routing, revenue, or production at scale.  • AI-assisted zero-day exploit and why admin tools move to the top of the patch queue  • Phishing-resistant MFA and reviewing trusted path assumptions for bypass risk  • Canvas incident and the need for tenant-level SaaS impact assessment  • Manufacturing ransomware as business disruption strategy across logistics and production  • Cisco Catalyst SD-WAN controller authentication bypass and control plane blast radius  • Exchange OWA KEV-driven mitigations and using deadlines for escalation  • WordPress FunnelKit exploit leading to WooCommerce checkout skimming and script audits  • Leverage-point thinking for modern asset inventory and exposure management  • Control plane exposure register fields, owners, logs, rollback paths, review cadence  If you want daily updates between episodes, you can find us on X, Facebook, and LinkedIn. Just search InfoSecWatch. And if you haven't already, head over to InfoSec.watch and grab the free weekly newsletter. It's concise, it's practitioner focused, and it lands every week.  Support the show Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!

  3. Mar 6

    127 - From Cisco To EV Chargers: Active Exploits And Urgent Patches

    Send us Fan Mail A wave of edge and control‑plane threats drives urgent patching and smarter validation across Cisco SD‑WAN, EV charging, FileZen, and Serve‑U. We map real exploits, spotlight APT28 tradecraft, unpack Google risk shifts, and share a post‑patch playbook that assumes breach. • Cisco SD‑WAN 10.0 authentication bypass and active exploitation • CISA KEV update for FileZen and patch prioritization • EV charging platform flaws enabling session hijack and station impersonation • APT28 targeting MSHTML and legacy components as modern vectors • One Uptime 10.0 root‑level exploit via traceroute probes • Google localhost WebSocket risk and policy reversals on token proxying • Governance for agentic AI with supervised fine‑tuning and oversight • Quick hits on North Korean air‑gap tools and UNC2814 disruption • Serve‑U critical updates and file transfer exposure • EU CRA impacts on open source supply chains • Post‑patch validation: verify versions, confirm exposure is gone, hunt logs, rotate secrets • Continuous exposure management for control planes and edge systems For more in-depth analysis and links to everything we discussed today, be sure to subscribe to our newsletter at infosec.watch Support the show Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!

About

The InfoSec.Watch Podcast delivers the week’s most important cybersecurity news in a fast, clear, and actionable format. Each episode breaks down major incidents, vulnerabilities, threat-actor activity, and security trends affecting modern organizations — without the noise or hype. The show translates complex cyber topics into practical insights you can use immediately in your job, whether you work in security engineering, cloud security, threat detection, governance, or IT. If you want to stay ahead of emerging threats, sharpen your defensive mindset, and get a reliable summary of what actually matters each week, this is your new essential briefing. Actionable Cybersecurity Insights — Every Week.