
Send us Fan Mail A compliance deadline can change your security posture without changing a single bit of your encryption. We start with a simple sticker-on-the-windshield analogy that maps directly to what’s happening with FIPS 140 validations: your VPN can keep encrypting, your database can keep protecting data, and yet an assessor can still mark you down because “working” is not the same as “validated.” We walk through the practical CISSP Domain 3 lesson behind the noise: the difference be...
Sep 14
38 min

Send us Fan Mail 🔁 REPLAY — this episode originally aired as CCT 278 in September 2025. I'm heads-down finishing a Domain 3 cryptography episode, so I'm re-running one of the strongest episodes in the archive rather than shipping something thin. If you're newer to the show, you haven't heard this one. And if you're studying Domain 3 right now the timing works in your favor — security models are the foundation the rest of the domain sits on, and next week's episode picks up in the same domai...
Sep 7
31 min

Send us Fan Mail Nine million images. No password. No encryption. And the defence was basically: “It wasn’t public because you had to know the URL.” That single line opens up one of the most important CISSP Domain 2 conversations you can have: security through obscurity is not access control, and a hidden address is not a key. We take this real data exposure and translate it into the kind of manager-level reasoning the CISSP exam demands, not memorised trivia. We then zoom out into Asset Sec...
Aug 31
42 min

Send us Fan Mail A rogue AI agent didn’t “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying around. We walk through the Hugging Face intrusion story like a CISO briefing a board, step by step, translating a fast-moving AI-red-team narrative into the kind of clear threat modeling logic you need for ISC2 CISSP Domain 1.10 and for real risk decisions. From there, we shift into traini...
Aug 24
42 min

Send us Fan Mail A supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the package archive your CI/CD pipeline actually pulls, which is exactly why code review alone can’t b...
Aug 17
33 min
![CCT 365: Malicious QR Code Attacks and Digital Forensics Techniques Every CISSP Should Know [REPLAY]](https://cdn-images.podbay.fm/eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1cmwiOiJodHRwczovL3N0b3JhZ2UuYnV6enNwcm91dC5jb20vdTlxaXRuNHJwa2pocDJwbmNxOWlvN3hpc2R0OT8uanBnIiwiZmFsbGJhY2siOiJodHRwczovL2lzMS1zc2wubXpzdGF0aWMuY29tL2ltYWdlL3RodW1iL1BvZGNhc3RzMjExL3Y0LzZhLzljLzk0LzZhOWM5NDA3LTMyNWEtM2ZkMi01ZjU4LWE5ZGU4ZmZkNjQzYy9temFfMTY0NTQ1NTgwMDY0NDIxNjc2MC5qcGcvNjAweDYwMGJiLmpwZyJ9.toM-LoFpl8IOTNb1nA8rpe9qXbzV9w4D9O1dzE9Ru4s.jpg?width=200&height=200)
CCT 365: Malicious QR Code Attacks and Digital Forensics Techniques Every CISSP Should Know [REPLAY]
Send us Fan Mail One careless QR scan can quietly turn a “private” chat into a live wiretap. We start with a timely threat story: Russian APT-style actors abusing Signal’s linked device flow by pushing phishing links that contain malicious QR codes, so messages can be mirrored to an attacker device in real time. If you use Signal, WhatsApp, or Telegram at work, this is the kind of simple, human-triggered failure mode worth building into your security awareness habits. Then we shift into CISS...
Aug 10
25 min

Send us Fan Mail A breach can hit your headlines even when your own systems never get touched, and that’s exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputa...
Aug 3
46 min

Send us Fan Mail One bad AI decision can cost you more than money. It can cost you trust, trigger regulators overnight, and put your name on the hook when the board asks, “Who approved this?” We dig into AI governance through a CISSP lens, using real-world banking and credit union scenarios that show how fast things go sideways when AI tools slip outside your controls. We start with the uncomfortable reality behind modern AI adoption: vendors ship powerful models, teams connect third parties...
Jul 27
44 min

Send us Fan Mail That forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-style problem, what signals to look for, and the practical mitigations that matter most: proper dec...
Jul 20
34 min

Send us Fan Mail A six-instruction timing glitch in the Linux kernel can be the difference between “low-priv user” and full root control, and that is why we dig into the Bad EPoll vulnerability from a CISSP-ready, manager-first angle. We start by grounding what the Linux kernel EPoll subsystem does, why it is foundational to high-performance I/O, and why “just disable it” is not a real option when you’re dealing with production Linux servers, desktops, cloud workloads, and Android devices. T...
Jul 13
32 min
Load more
