
Sign up to save your podcasts
Or


Download full study questions for CISSP Domain 1-8 (200 questions) at: https://www.patreon.com/DecodedPodcast.
Download full study questions for CISSP Domain 1-8 (200 questions) at: https://www.patreon.com/DecodedPodcast.
Several sources highlight significant cybersecurity concerns, including a CISA advisory on the evasive "fast flux" technique and active exploitation of a CrushFTP vulnerability. Additionally, a zero-day flaw in CentreStack is being actively exploited to breach enterprise file servers, prompting a CISA warning. The ransomware attack on Sensata Technologies further illustrates the ongoing threat to operational technology. Finally, an opinion piece proposes a "Cyber Council of Nicaea" to unify America's fragmented cyber defenses in response to increasing threats.
Patreon Support:
https://www.patreon.com/DecodedPodcast
These sources collectively address the significant cybersecurity challenge of lateral movement, where attackers navigate compromised networks to reach valuable assets. TechTarget and CERT-EU offer technical insights into common techniques like Pass-the-Hash and Pass-the-Ticket, detailing detection methods within Windows environments using event logs. Bleeping Computer and Medium explain how these attacks work, emphasizing the role of compromised credentials and outlining preventative measures such as strong password policies and multi-factor authentication. CrowdStrike discusses "Living off the Land" tactics that utilize legitimate system tools for lateral movement and advocates for proactive detection strategies. Finally, a Reddit discussion highlights the persistent difficulty in detecting lateral movement despite advanced security tools and suggests approaches like improved baselining and network segmentation, while Palo Alto Networks promotes the principle of least privilege as a fundamental defense against such threats by limiting user access.
Patreon Support:
https://www.patreon.com/DecodedPodcast
A podcast episode transcript titled "The Hackable Highway: Smart Cars and Cybersecurity" features host Edward and cybersecurity expert The Kernel discussing the vulnerabilities present in modern smart vehicles. The conversation explores how features like infotainment systems, Bluetooth, Wi-Fi, mobile apps, and over-the-air updates create potential entry points for cyberattacks. The Kernel outlines various hacking methods, including exploiting wireless connections, manipulating the internal network (CAN bus), relaying key fob signals, abusing mobile app APIs, and injecting malicious firmware. Real-world examples of car hacks and the tools used by both attackers and defenders are also highlighted. Finally, the discussion covers defensive measures for both automakers and drivers, emphasizing the increasing need for robust security as vehicles become more connected and autonomous.
Patreon Support:
https://www.patreon.com/DecodedPodcast
Edward Henriquez's podcast script for Decoded: The Cybersecurity Podcast explains the Path Traversal vulnerability from a hacker's perspective. This technique exploits weaknesses in web applications that allow users to specify file paths. By manipulating these paths with sequences like "../", attackers can navigate outside intended directories to access sensitive files such as configuration files, source code, and SSH keys. Henriquez also describes advanced methods to bypass common defenses, like double encoding and null byte injection. The script uses a real-world example of a GitHub Enterprise vulnerability to illustrate the impact and emphasizes that trusting user-supplied file paths is the root cause. Finally, it provides concrete defense strategies for developers, including input sanitization, path normalization, and restricting file access.
Patreon Support:
https://www.patreon.com/DecodedPodcast
Multiple sources highlight the escalating and evolving cybersecurity landscape as of early April 2025. The WEF report emphasizes proactive OT security strategies for industrial organizations facing complex threats like geopolitical tensions and AI-driven attacks. Another article reveals a new AI-powered platform, Lovable, highly susceptible to "VibeScamming" for creating sophisticated phishing campaigns, while others detail Microsoft patching numerous vulnerabilities, including an actively exploited Windows flaw. Separate alerts from the NCSC warn of mobile spyware targeting specific communities, and reports indicate ransomware attacks are at an all-time high despite dwindling payouts. Finally, concerns arise over proposed cuts to CISA potentially weakening US cyber defenses, alongside news of a significant hack at the Treasury Department's bank regulator.
Patreon Support:
https://www.patreon.com/DecodedPodcast
Patreon Support:
https://www.patreon.com/DecodedPodcast
Recent reports highlight escalating cybersecurity concerns across various sectors. AI agents are identified as emerging targets for cyberattacks due to their increasing presence in organizational infrastructures. Critical infrastructure, such as water and power utilities, faces heightened threats from nation-state cyberattacks, leading to data corruption and public safety risks. Healthcare organizations grapple with protecting sensitive patient data in an increasingly AI-driven landscape, facing risks like phishing and ransomware. Additionally, a data breach at Kellogg's in late 2024 exposed personally identifiable information. Finally, experts predict a significant rise in mobile security threats for 2025, including ransomware and banking Trojans, while the financial sector confronts a crisis of trust due to sophisticated phishing and fraud tactics. A security vulnerability was also identified in Umbraco CMS, requiring users to apply available patches.
Patreon Support:
https://www.patreon.com/DecodedPodcast
Decoded: The Cybersecurity Podcast features Edward Henriquez, in character as a top hacker, exploring the often-overlooked realm of Non-Human Digital Identities (NHDIs) such as bots and API keys. The podcast highlights the security risks associated with the proliferation and poor management of these identities, explaining how attackers can exploit their weaknesses, often leading to significant breaches. Henriquez details common attack paths, emphasizing the lack of monitoring and excessive permissions frequently granted to NHDIs. Furthermore, the podcast offers actionable advice for organizations on how to better secure these non-human accounts, including inventory, least privilege, secrets management, and continuous monitoring, underscoring the increasing importance of NHDI security in the modern digital landscape.
From the publisher's feed