Plaintext with Rich

Rich Greene

Cybersecurity is an everyone problem. So why does it always sound like it’s only for IT people? Each week, Rich takes one topic, from phishing to ransomware to how your phone actually tracks you, and explains it in plain language in under ten minutes or less. No buzzwords. No condescension. Just the stuff you need to know to stay safer online, explained like you’re a smart person who never had anyone break it down properly. Because you are!

  1. 3d ago

    ClickFix: When a CAPTCHA Asks You to Run a Command

    You came for a conference agenda, and the website wants proof you're human. ClickFix can hide behind that familiar check, with instructions that deserve a much closer look. Rich follows the moment a fake CAPTCHA, a test meant to distinguish people from automated visitors, changes what it asks you to do. Microsoft's August 2026 TerminalFix analysis provides a concrete example involving an imitation Cloudflare screen and commands pasted into Windows Terminal or PowerShell. CERT Polska's February 2026 investigation helps explain why a short command may conceal a longer chain of instructions. The Federal Trade Commission's June 2026 warning adds context to the difference between a website check and a request to operate your computer. If you've ever followed a screen's directions just to get back to your work, this conversation is for you. Plaintext with Rich also gives workplace leaders a useful way to think about awareness training that people can recognize in an ordinary browsing moment. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube   Apple Podcasts your usual stop? → https://links.sith2.com/Apple   Neither of those? Spotify’s over here → https://links.sith2.com/Spotify   Prefer reading quietly at your own pace? → https://links.sith2.com/Blog   Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord   Follow the human behind the microphone → https://links.sith2.com/linkedin   Need another way to reach me? That’s here → https://linktr.ee/rich.greene

  2. Aug 28

    Google Selfie Account Recovery: Convenience vs. Privacy

    Would you hand Google a video of your face for one more way back into your account? That question gets harder when you are locked out, holding a new phone, and missing every recovery route you thought would save you. In this episode of Plaintext with Rich, we look at Google's selfie video sign-in option and what eligible users should know before opting in. You will hear how Google described comparing a saved recording with a new video, why prompted head movements support a liveness check, and how suspicious sign-in checks add another layer. We also unpack encryption at rest, biometric data, optional use of recordings to improve verification services, and Google's deletion terms. The episode explains the eligibility limits Google documented in July 2026. Most importantly, it puts selfie recovery alongside passkeys, recovery contacts, phone numbers, and recovery email as one part of a stronger account recovery plan. This is for anyone whose Google Account holds important email, photos, documents, or access to other services, and for leaders helping people make informed security choices. Convenience and privacy both matter, so make the choice on purpose. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube   Apple Podcasts your usual stop? → https://links.sith2.com/Apple   Neither of those? Spotify’s over here → https://links.sith2.com/Spotify   Prefer reading quietly at your own pace? → https://links.sith2.com/Blog   Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord   Follow the human behind the microphone → https://links.sith2.com/linkedin   Need another way to reach me? That’s here → https://linktr.ee/rich.greene

  3. Aug 21

    AI Security Test Escape: Why Agent Containment Failed

    An AI security test was supposed to stay inside a controlled environment. Instead, the models found an unexpected route to the public Internet and reached real Hugging Face infrastructure while pursuing benchmark answers. In this episode of Plaintext with Rich, we unpack how an OpenAI cyber evaluation became a real security incident. You will hear how the models exploited a package service, increased their permissions, used stolen credentials, and pursued ExploitGym solutions beyond the intended test boundary. Rich explains zero-day vulnerabilities, remote code execution, vulnerability chaining, and why a sandbox depends on far more than one isolation control. The episode also examines Hugging Face's response and the practical management lesson behind the incident: when an agent is rewarded for reaching a goal, leaders must understand every system it can touch along the way. This episode is for business leaders, security teams, technology buyers, and anyone evaluating AI agents with access to websites, codebases, or internal tools. You will leave with a five-part starter kit for mapping exits, limiting credentials, layering containment, monitoring agent behavior, and writing a stop plan before testing begins. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube   Apple Podcasts your usual stop? → https://links.sith2.com/Apple   Neither of those? Spotify’s over here → https://links.sith2.com/Spotify   Prefer reading quietly at your own pace? → https://links.sith2.com/Blog   Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord   Follow the human behind the microphone → https://links.sith2.com/linkedin   Need another way to reach me? That’s here → https://linktr.ee/rich.greene

  4. Aug 14

    PTC Windchill Vulnerability: Why Your Product Blueprints Are at Risk

    A company can lose its most valuable product plans without a broken lock, an encrypted laptop, or an obvious warning on the screen. The first clear sign may be an extortion email claiming the files are already gone. This episode of Plaintext with Rich explains the attacks disclosed against PTC Windchill and FlexPLM, two product lifecycle management platforms that can hold designs, bills of materials, manufacturing instructions, supplier details, and launch plans. Rich breaks down CVE-2026-12569, remote code execution, unsafe deserialization, and web shells in language built for people who do not spend their days reading security advisories. You will also hear why CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, why reporting in July 2026 compared the campaign tactics to Clop, and why attribution was unconfirmed when the episode was prepared. Most importantly, the episode explains why applying the PTC patch is only half the job when attackers may already have copied sensitive data. This is for business leaders, technology teams, product owners, manufacturers, retailers, and anyone responsible for a central platform that holds concentrated company value. It offers a practical way to think about patching, compromise hunting, incident response, and the business decisions that follow possible data theft. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube   Apple Podcasts your usual stop? → https://links.sith2.com/Apple   Neither of those? Spotify’s over here → https://links.sith2.com/Spotify   Prefer reading quietly at your own pace? → https://links.sith2.com/Blog   Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord   Follow the human behind the microphone → https://links.sith2.com/linkedin   Need another way to reach me? That’s here → https://linktr.ee/rich.greene

Ratings & Reviews

5
out of 5
13 Ratings

About

Cybersecurity is an everyone problem. So why does it always sound like it’s only for IT people? Each week, Rich takes one topic, from phishing to ransomware to how your phone actually tracks you, and explains it in plain language in under ten minutes or less. No buzzwords. No condescension. Just the stuff you need to know to stay safer online, explained like you’re a smart person who never had anyone break it down properly. Because you are!

You Might Also Like