The 443 - Security Simplified
The 443 - Security Simplified
Secplicity
Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cybersecurity headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into easily understood and actionable insights.
Microsoft' Digital Defense Report - The 443 Podcast - Episode 390
This week on the podcast, we cover a few takeaways from Microsoft’s recent Digital Defense Report. Before that, we discuss the recent Citrix Netscaler zero-days that were potentially under active exploit for weeks before disclosure before reviewing an interesting a bug bounty report on a Microsoft internal tool that was exposed externally.
Oct 5
1 hr
Oops, OpenAI Hacked Australia's Health System - The 443 Podcast - Episode 389
This week on the podcast, we cover yet another rogue AI security incident that Australia’s Prime Minister disclosed in front of the United Nations last week. Before that, we discuss an FBI alert on WaterPlum, a North Korean threat actor targeting IT professionals. Then, we cover the FBI themselves becoming a victim of cyberattack, this time by ShinyHunters.
Sep 28
51 min
One Image to Root Them All - The 443 Podcast - Episode 388
This week on the podcast, we break down how a heap overflow in an image-decoding library nobody thinks about became a pull request inside OpenAI’s internal monorepo. Three researchers chained it with an OpenAI single sign-on flaw to hijack employee ChatGPT and Codex accounts in under 72 hours; and had an AI write the exploit for them. Before that, we cover the actively exploited maximum-severity authentication bypass in Cisco’s Identity Services Engine. Then we close with RatHat, a new Android malware that enables Wireless Debugging, reads its own pairing code from the screen, and asks a commercial AI assistant where to tap.
Sep 21
35 min
Mikrotik and Cisco Active Exploits - The 443 Podcast - Episode 387
This week on the podcast, we analyze a set of actively exploited vulnerabilities in Mikrotik’s RouteOS followed by a pair of actively exploited vulnerabilities in Cisco’s Firewall Management Center. After that, we review a phishing attack against Trezor hardware cryptocurrency wallet users that originated with their third party marketing email provider.
Sep 14
33 min
Skynet Comes Online - The 443 Podcast - Episode 386
This week, dive into OpenAI’s and METR’s analysis of the rogue OpenAI agents that hacked Hugging Face back in July. We go over the full attack timeline discussing the multiple message boards the agents created and the ultimate goal of their attack against Hugging Face and trust us, its as crazy as it gets. Before that, we discuss a recent dark web service that popped up selling 153 million stolen drivers licenses before discussing a research post into a malware implant discovered in inexpensive Chinese routers.
Sep 8
54 min
An interview with Euler Neto on ErrTraffic - The 443 Podcast - Episode 385
This week we sit down with Euler Neto, a cybersecurity analyst at WatchGuard, to discuss his research into the ErrTraffic Malware-as-a-Service loader found targeting Portoguese-speaking users in recent months.
Aug 31
32 min
Cryptographic Context Injection - The 443 Podcast - Episode 384
This week on the podcast, we discuss a research post that defines a new attack technique against AI tools called Cryptographic Context Injection. Before that, we cover an authentication bypass vulnerability in CircleCI’s MCP server after discussing 3.6 million records stolen from the Azure tenants of several large organziations.
Aug 25
31 min
American Cyber Mercinaries - The 443 Podcast - Episode 383
This week on the podcast, we discuss a new White House memorandum that creates a program to authorize American private companies to begin conducting offensive cyber operations. Before that, we discuss a vulnerability write up for a Citrix Netscaler flaw before covering yet another prompt injection vulnerability in a popular AI tool.
Aug 17
39 min
Iran Hacks the US Water Supply - The 443 Podcast - Episode 382
This week on the podcast, we cover a series of alerts form US law enforcement and intelligence sources describing Iran-backed attacks against municipal water supply utilities. Before that, we give an update on the OpenAI and HuggingFace rogue AI saga before discussing a research post on MCP configuration file risks.
Aug 10
41 min
HuggingFace's List of Demands - The 443 Podcast - Episode 381
This week on the podcast, we review HuggingFace’s technical write up of their recent run in with a rogue OpenAI model, as well as their CEO’s demands from OpenAI in response. We then cover an interesting research whitepaper that describes a side channel attack that could let AI transcribe typed text by an audio recording alone. We end with a threat intelligence report about DNS Poisoning attacks against hotel Wi-Fi systems.
Aug 3
41 min
Load more