<?xml version="1.0" encoding="UTF-8"?><!-- generator="podbean/5.5" -->
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
     xmlns:spotify="http://www.spotify.com/ns/rss"
     xmlns:podcast="https://podcastindex.org/namespace/1.0"
    xmlns:media="http://search.yahoo.com/mrss/">

<channel>
    <title>Error Code</title>
    <atom:link href="https://feed.podbean.com/errorcode/feed.xml" rel="self" type="application/rss+xml"/>
    <link>https://errorcode.podbean.com</link>
    <description>Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code resilience and dependability. Work that can lead to autonomous vehicles and smart cities. It’s your window in the research solving tomorrow’s code problems today.</description>
    <pubDate>Wed, 22 Jul 2026 07:50:39 -0700</pubDate>
    <generator>https://podbean.com/?v=5.5</generator>
    <language>en</language>
        <copyright>Copyright 2024 All rights reserved.</copyright>
    <category>Technology</category>
    <ttl>1440</ttl>
    <itunes:type>episodic</itunes:type>
          <itunes:summary>Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code resilience and dependability.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
<itunes:category text="Technology" />
    <itunes:owner>
        <itunes:name>Robert Vamosi</itunes:name>
            </itunes:owner>
    	<itunes:block>No</itunes:block>
	<itunes:explicit>false</itunes:explicit>
    <itunes:image href="https://pbcdn1.podbean.com/imglogo/image-logo/15244354/ERRORCODE0123_rvg5ix.jpg" />
    <image>
        <url>https://pbcdn1.podbean.com/imglogo/image-logo/15244354/ERRORCODE0123_rvg5ix.jpg</url>
        <title>Error Code</title>
        <link>https://errorcode.podbean.com</link>
        <width>144</width>
        <height>144</height>
    </image>
    <item>
        <title>EP 90:  Your Weakest Vendor Is Someone’s Biggest Problem</title>
        <itunes:title>EP 90:  Your Weakest Vendor Is Someone’s Biggest Problem</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-90-your-weakest-vendor-is-someone-s-biggest-problem/</link>
                    <comments>https://errorcode.podbean.com/e/ep-90-your-weakest-vendor-is-someone-s-biggest-problem/#comments</comments>        <pubDate>Wed, 22 Jul 2026 07:50:39 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/9da124d5-fb80-32cf-bb42-26e2df420a54</guid>
                                    <description><![CDATA[<p>Why one vendor breach can take down dozens of banks — third-party risk, AI-driven attacks, and why patching fast may beat patching safe today.  Jeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite, explains.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Why one vendor breach can take down dozens of banks — third-party risk, AI-driven attacks, and why patching fast may beat patching safe today.  Jeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite, explains.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/st58ypwsgdusv4js/EP90FINAL.mp3" length="51488436" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Why one vendor breach can take down dozens of banks — third-party risk, AI-driven attacks, and why patching fast may beat patching safe today.  Jeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite, explains.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2142</itunes:duration>
                <itunes:episode>91</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 89: How AI Is Breaking OT Cybersecurity</title>
        <itunes:title>EP 89: How AI Is Breaking OT Cybersecurity</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-89-how-ai-is-breaking-ot-cybersecurity/</link>
                    <comments>https://errorcode.podbean.com/e/ep-89-how-ai-is-breaking-ot-cybersecurity/#comments</comments>        <pubDate>Tue, 07 Jul 2026 16:41:16 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/cbbf4eb0-cdb7-3f3e-bda9-58fdc9c86330</guid>
                                    <description><![CDATA[<p>AI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won't save it. Jori VanAntwerp, CEO and founder of <a href='https://www.emberot.com/'>Ember OT</a>, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>AI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won't save it. Jori VanAntwerp, CEO and founder of <a href='https://www.emberot.com/'>Ember OT</a>, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cd222tpmy8z2y898/EP89FINAL.mp3" length="56776037" type="audio/mpeg"/>
        <itunes:summary>AI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won’t save it. Jori VanAntwerp, CEO and founder of Ember OT, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2362</itunes:duration>
                <itunes:episode>90</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 88:  Securing the Infrastructure AI Just Made Vulnerable</title>
        <itunes:title>EP 88:  Securing the Infrastructure AI Just Made Vulnerable</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-88-securing-the-infrastructure-ai-just-made-vulnerable/</link>
                    <comments>https://errorcode.podbean.com/e/ep-88-securing-the-infrastructure-ai-just-made-vulnerable/#comments</comments>        <pubDate>Tue, 09 Jun 2026 08:24:59 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/6101a718-b1dc-322e-8422-d6d204ec76de</guid>
                                    <description><![CDATA[<p>Critical infrastructure is under attack. AI just made it easier. Legacy devices can't be patched. Piotr Kupisiewicz, CTO at Elisity, describes how your best defense is the basics that you're ignoring.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Critical infrastructure is under attack. AI just made it easier. Legacy devices can't be patched. Piotr Kupisiewicz, CTO at Elisity, describes how your best defense is the basics that you're ignoring.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pw7k7bcg2cgzgcmn/EP88FINAL.mp3" length="49149954" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Critical infrastructure is under attack. AI just made it easier. Legacy devices can't be patched. Piotr Kupisiewicz, CTO at Elisity, describes how your best defense is the basics that you're ignoring.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2045</itunes:duration>
                <itunes:episode>89</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 87: Backup, Control Gaps, and the Real Cost of Agentic AI Actions</title>
        <itunes:title>EP 87: Backup, Control Gaps, and the Real Cost of Agentic AI Actions</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-87-backup-control-gaps-and-the-real-cost-of-agentic-ai-actions/</link>
                    <comments>https://errorcode.podbean.com/e/ep-87-backup-control-gaps-and-the-real-cost-of-agentic-ai-actions/#comments</comments>        <pubDate>Wed, 27 May 2026 09:56:00 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/cff25ce9-5764-3600-80d2-ce5f6446d3c1</guid>
                                    <description><![CDATA[<p>An AI agent wiped out an entire company’s data in just 9 seconds — no hacker, no ransomware involved. Todd Thorsen, Chief Information Security Officer at<a href='https://www.crashplan.com/?utm_source=chatgpt.com'> CrashPlan</a>, explains how a misconfigured AI agent operating without safeguards may have caused the incident — and asks a troubling question: could your organization be next? </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>An AI agent wiped out an entire company’s data in just 9 seconds — no hacker, no ransomware involved. Todd Thorsen, Chief Information Security Officer at<a href='https://www.crashplan.com/?utm_source=chatgpt.com'> CrashPlan</a>, explains how a misconfigured AI agent operating without safeguards may have caused the incident — and asks a troubling question: could your organization be next? </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jvvaau773qq9a8x4/EP87FINAL.mp3" length="43016612" type="audio/mpeg"/>
        <itunes:summary><![CDATA[An AI agent wiped out an entire company’s data in just 9 seconds — no hacker, no ransomware involved. Todd Thorsen, Chief Information Security Officer at CrashPlan, explains how a misconfigured AI agent operating without safeguards may have caused the incident — and asks a troubling question: could your organization be next? ]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1789</itunes:duration>
                <itunes:episode>88</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 86: The Trusted Channel: AT Command Exploits and Cellular IoT Security</title>
        <itunes:title>EP 86: The Trusted Channel: AT Command Exploits and Cellular IoT Security</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-86-the-trusted-channel-at-command-exploits-and-cellular-iot-security/</link>
                    <comments>https://errorcode.podbean.com/e/ep-86-the-trusted-channel-at-command-exploits-and-cellular-iot-security/#comments</comments>        <pubDate>Tue, 12 May 2026 14:30:46 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/23c669ad-4bfa-3a9e-aecf-1e6bcf37b36f</guid>
                                    <description><![CDATA[<p>Cellular modules in your IoT devices are trusted and that trust can be an insecure  pivot point into your network for attackers. Deral Heiland, Principal Security Research for IoT at Rapid 7 discusses his presentation at RSAC 2026 on AT command exploits and supply chain risk.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Cellular modules in your IoT devices are trusted and that trust can be an insecure  pivot point into your network for attackers. Deral Heiland, Principal Security Research for IoT at Rapid 7 discusses his presentation at RSAC 2026 on AT command exploits and supply chain risk.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/eytuz428guk8uemh/EP86FINAL.mp3" length="46151933" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Cellular modules in your IoT devices are trusted and that trust can be an insecure  pivot point into your network for attackers. Deral Heiland, Principal Security Research for IoT at Rapid 7 discusses his presentation at RSAC 2026 on AT command exploits and supply chain risk.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1920</itunes:duration>
                <itunes:episode>87</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 85: From Colonial Pipeline to Agentic AI: What OT Security Actually Requires</title>
        <itunes:title>EP 85: From Colonial Pipeline to Agentic AI: What OT Security Actually Requires</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-85-from-colonial-pipeline-to-agentic-ai-what-ot-security-actually-requires/</link>
                    <comments>https://errorcode.podbean.com/e/ep-85-from-colonial-pipeline-to-agentic-ai-what-ot-security-actually-requires/#comments</comments>        <pubDate>Tue, 28 Apr 2026 16:30:27 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/0faf392b-1142-30fd-8f07-c7a9afa6bb97</guid>
                                    <description><![CDATA[<p>Let’s face it, the Purdue model's DMZ is gone. Trevor Dearing, Director of Critical Infrastructure Solutions at Illumio, explains how zero trust, micro-segmentation, and explicit policy are now the only reliable defense for critical infrastructure OT.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Let’s face it, the Purdue model's DMZ is gone. Trevor Dearing, Director of Critical Infrastructure Solutions at Illumio, explains how zero trust, micro-segmentation, and explicit policy are now the only reliable defense for critical infrastructure OT.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/tc6hxhxzbz7h6pau/EP85FINAL.mp3" length="53299035" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Let’s face it, the Purdue model's DMZ is gone. Trevor Dearing, Director of Critical Infrastructure Solutions at Illumio, explains how zero trust, micro-segmentation, and explicit policy are now the only reliable defense for critical infrastructure OT.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2218</itunes:duration>
                <itunes:episode>86</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 84: Airports as Critical Infrastructure:  OT Security and Operational Disruption</title>
        <itunes:title>EP 84: Airports as Critical Infrastructure:  OT Security and Operational Disruption</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-84-airports-as-critical-infrastructure-ot-security-and-operational-disruption/</link>
                    <comments>https://errorcode.podbean.com/e/ep-84-airports-as-critical-infrastructure-ot-security-and-operational-disruption/#comments</comments>        <pubDate>Wed, 15 Apr 2026 10:11:59 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/40a343c6-7fe5-335f-a10f-d25c82e17f2b</guid>
                                    <description><![CDATA[<p>Airports illustrate the potential impact of OT attacks that disrupt functionality. Dan Gunter, CEO of Insane Cyber, talks about how industrial environments differ from traditional IT, particularly in their reliance on availability and safety, where disruptions can have significant real-world and financial consequences.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Airports illustrate the potential impact of OT attacks that disrupt functionality. Dan Gunter, CEO of Insane Cyber, talks about how industrial environments differ from traditional IT, particularly in their reliance on availability and safety, where disruptions can have significant real-world and financial consequences.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qbrjitshnzq9qwpu/EP84FINAL.mp3" length="53813752" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Airports illustrate the potential impact of OT attacks that disrupt functionality. Dan Gunter, CEO of Insane Cyber, talks about how industrial environments differ from traditional IT, particularly in their reliance on availability and safety, where disruptions can have significant real-world and financial consequences.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2239</itunes:duration>
                <itunes:episode>85</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 83:  Cybersecurity and Risk in a Decentralized Energy Grid</title>
        <itunes:title>EP 83:  Cybersecurity and Risk in a Decentralized Energy Grid</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-83-cybersecurity-and-risk-in-a-decentralized-energy-grid/</link>
                    <comments>https://errorcode.podbean.com/e/ep-83-cybersecurity-and-risk-in-a-decentralized-energy-grid/#comments</comments>        <pubDate>Tue, 31 Mar 2026 10:02:01 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/dce2dda6-d79a-37c8-9d36-3902be70fa6f</guid>
                                    <description><![CDATA[<p>The surge in renewables and decentralized power is reshaping grids—and exposing them to new operational and cyber risks. In this episode, Rafael Narezzi, Co-Founder &amp; CEO of Centrii, explains how rising connectivity widens the attack surface, leaving energy infrastructure increasingly vulnerable.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The surge in renewables and decentralized power is reshaping grids—and exposing them to new operational and cyber risks. In this episode, Rafael Narezzi, Co-Founder &amp; CEO of Centrii, explains how rising connectivity widens the attack surface, leaving energy infrastructure increasingly vulnerable.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/5jj8isvkmwgsixiy/EP83FINAL.mp3" length="35719045" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The surge in renewables and decentralized power is reshaping grids—and exposing them to new operational and cyber risks. In this episode, Rafael Narezzi, Co-Founder &amp; CEO of Centrii, explains how rising connectivity widens the attack surface, leaving energy infrastructure increasingly vulnerable.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1485</itunes:duration>
                <itunes:episode>84</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 82: Kerberos in OT: RC4 Downgrade Attacks</title>
        <itunes:title>EP 82: Kerberos in OT: RC4 Downgrade Attacks</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-82-kerberos-in-ot-rc4-downgrade-attacks/</link>
                    <comments>https://errorcode.podbean.com/e/ep-82-kerberos-in-ot-rc4-downgrade-attacks/#comments</comments>        <pubDate>Tue, 03 Mar 2026 17:28:21 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/737edbe6-6b43-3efe-bd01-965a5a4b95f6</guid>
                                    <description><![CDATA[<p>Kerberos, a decades-old authentication protocol, creates hidden risks in OT environments. Dor Segal, security researcher team lead at <a href='https://www.silverfort.com/'>Silverfort</a>, discusses delegation abuse, cipher downgrade attacks, and person-in-the-middle threats—highlighting why legacy encryption, patching challenges, and operational constraints make identity security critical in industrial networks.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Kerberos, a decades-old authentication protocol, creates hidden risks in OT environments. Dor Segal, security researcher team lead at <a href='https://www.silverfort.com/'>Silverfort</a>, discusses delegation abuse, cipher downgrade attacks, and person-in-the-middle threats—highlighting why legacy encryption, patching challenges, and operational constraints make identity security critical in industrial networks.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/g6f8qg8yqfgymbaw/EP82FINAL.mp3" length="38518326" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Kerberos, a decades-old authentication protocol, creates hidden risks in OT environments. Dor Segal, security researcher team lead at Silverfort, discusses delegation abuse, cipher downgrade attacks, and person-in-the-middle threats—highlighting why legacy encryption, patching challenges, and operational constraints make identity security critical in industrial networks.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1602</itunes:duration>
                <itunes:episode>83</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 81: Root of Trust: Why Security Now Starts in Silicon</title>
        <itunes:title>EP 81: Root of Trust: Why Security Now Starts in Silicon</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-81-root-of-trust-why-security-now-starts-in-silicon/</link>
                    <comments>https://errorcode.podbean.com/e/ep-81-root-of-trust-why-security-now-starts-in-silicon/#comments</comments>        <pubDate>Tue, 17 Feb 2026 11:25:42 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/1d9b15cf-101f-36eb-8a9b-49d16d860668</guid>
                                    <description><![CDATA[<p>Rising software complexity in safety-critical industries is forcing cybersecurity requirements on systems previously not thought about before.  David Sequino, CEO of OmniTrust (formerly ISS), talks about the need to secure digital certificates on life critical systems like cars and planes and the challenges in doing so.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Rising software complexity in safety-critical industries is forcing cybersecurity requirements on systems previously not thought about before.  David Sequino, CEO of OmniTrust (formerly ISS), talks about the need to secure digital certificates on life critical systems like cars and planes and the challenges in doing so.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/r6xijxhhsk29rjwj/EP81FINAL.mp3" length="49865918" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Rising software complexity in safety-critical industries is forcing cybersecurity requirements on systems previously not thought about before.  David Sequino, CEO of OmniTrust (formerly ISS), talks about the need to secure digital certificates on life critical systems like cars and planes and the challenges in doing so.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2075</itunes:duration>
                <itunes:episode>82</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 80: The Dangers of White Label Devices</title>
        <itunes:title>EP 80: The Dangers of White Label Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-80-the-dangers-of-white-label-devices/</link>
                    <comments>https://errorcode.podbean.com/e/ep-80-the-dangers-of-white-label-devices/#comments</comments>        <pubDate>Tue, 03 Feb 2026 12:47:16 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/e26c3b47-59bc-3e5d-85e0-e35927d722f7</guid>
                                    <description><![CDATA[<p>Many devices on modern networks aren’t what their labels claim. This episode, Rob King, Director of Applied Security Research at <a href='https://www.runzero.com/'>runZero</a>, explores white-labeled surveillance and IoT hardware, why some vendors are banned by governments, and how hidden risks can spread across enterprises. Discovery, device fingerprinting, and protocol analysis reveal what’s really connected—and why knowing your true inventory is now essential for security, compliance, and trust.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Many devices on modern networks aren’t what their labels claim. This episode, Rob King, Director of Applied Security Research at <a href='https://www.runzero.com/'>runZero</a>, explores white-labeled surveillance and IoT hardware, why some vendors are banned by governments, and how hidden risks can spread across enterprises. Discovery, device fingerprinting, and protocol analysis reveal what’s really connected—and why knowing your true inventory is now essential for security, compliance, and trust.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/i4wia9qp3dn9wz77/EP80FINAL.mp3" length="54877040" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Many devices on modern networks aren’t what their labels claim. This episode, Rob King, Director of Applied Security Research at runZero, explores white-labeled surveillance and IoT hardware, why some vendors are banned by governments, and how hidden risks can spread across enterprises. Discovery, device fingerprinting, and protocol analysis reveal what’s really connected—and why knowing your true inventory is now essential for security, compliance, and trust.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2283</itunes:duration>
                <itunes:episode>81</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 79: Ignore OT Security At Your Own Peril</title>
        <itunes:title>EP 79: Ignore OT Security At Your Own Peril</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-79-ignore-ot-security-at-your-own-peril/</link>
                    <comments>https://errorcode.podbean.com/e/ep-79-ignore-ot-security-at-your-own-peril/#comments</comments>        <pubDate>Thu, 22 Jan 2026 12:12:46 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/93e2d437-6743-3a20-ab00-3efc0fc4e3cb</guid>
                                    <description><![CDATA[<p>The growing importance of OT security, highlighting overlooked risks in critical infrastructure, legacy systems, and supply chains. Through real-world examples, Eric Durr, Chief Product Officer at Tenable, shows why OT security differs from IT, emphasizing visibility, resilience, and risk prioritization to protect safety, operations, and business continuity.</p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The growing importance of OT security, highlighting overlooked risks in critical infrastructure, legacy systems, and supply chains. Through real-world examples, Eric Durr, Chief Product Officer at Tenable, shows why OT security differs from IT, emphasizing visibility, resilience, and risk prioritization to protect safety, operations, and business continuity.</p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jw3k4xcnsr47htnj/EP79FINAL.mp3" length="55389249" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The growing importance of OT security, highlighting overlooked risks in critical infrastructure, legacy systems, and supply chains. Through real-world examples, Eric Durr, Chief Product Officer at Tenable, shows why OT security differs from IT, emphasizing visibility, resilience, and risk prioritization to protect safety, operations, and business continuity.
 ]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2305</itunes:duration>
                <itunes:episode>80</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 78: In Defense of Autonomous Vehicles</title>
        <itunes:title>EP 78: In Defense of Autonomous Vehicles</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-78-in-defense-of-autonomous-vehicles/</link>
                    <comments>https://errorcode.podbean.com/e/ep-78-in-defense-of-autonomous-vehicles/#comments</comments>        <pubDate>Wed, 07 Jan 2026 15:35:54 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/67606bc3-a1f6-3262-b891-8c2b08328352</guid>
                                    <description><![CDATA[<p>At<a href='https://www.blackhat.com/us-25/'> Black Hat USA 2025</a>, Dan Berte, IoT Director at <a href='https://www.bitdefender.com/'>Bitdefender</a>, discusses the successes and failures of ride-sharing autonomous vehicles in San Francisco, and how these lessons might help design better IoT integrations of cities and AVs in the future.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>At<a href='https://www.blackhat.com/us-25/'> Black Hat USA 2025</a>, Dan Berte, IoT Director at <a href='https://www.bitdefender.com/'>Bitdefender</a>, discusses the successes and failures of ride-sharing autonomous vehicles in San Francisco, and how these lessons might help design better IoT integrations of cities and AVs in the future.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qmi7c97pguxhz2kv/EP78FINAL.mp3" length="33453504" type="audio/mpeg"/>
        <itunes:summary><![CDATA[At Black Hat USA 2025, Dan Berte, IoT Director at Bitdefender, discusses the successes and failures of ride-sharing autonomous vehicles in San Francisco, and how these lessons might help design better IoT integrations of cities and AVs in the future.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1391</itunes:duration>
                <itunes:episode>79</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 77: Building a Cyber Physical System Device Library</title>
        <itunes:title>EP 77: Building a Cyber Physical System Device Library</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-77-building-a-cyber-physical-system-device-library/</link>
                    <comments>https://errorcode.podbean.com/e/ep-77-building-a-cyber-physical-system-device-library/#comments</comments>        <pubDate>Tue, 09 Dec 2025 12:14:34 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/89716501-53bd-3e05-8051-bd1ac49bd46f</guid>
                                    <description><![CDATA[<p>Do you really know what’s on your network? A lot of OT devices are white labeled, meaning they have a brand name but under the hood they’re made by someone else. Sean Tufts, Field CTO for Claroty, explains how his team is using AI to sift through all the available data and build a cyber physical library that starts to add specificity to remediation operations, and improve cyber physical security overall</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Do you really know what’s on your network? A lot of OT devices are white labeled, meaning they have a brand name but under the hood they’re made by someone else. Sean Tufts, Field CTO for Claroty, explains how his team is using AI to sift through all the available data and build a cyber physical library that starts to add specificity to remediation operations, and improve cyber physical security overall</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/n5ve5pdxay4n8vqm/EP77FINAL.mp3" length="39661863" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Do you really know what’s on your network? A lot of OT devices are white labeled, meaning they have a brand name but under the hood they’re made by someone else. Sean Tufts, Field CTO for Claroty, explains how his team is using AI to sift through all the available data and build a cyber physical library that starts to add specificity to remediation operations, and improve cyber physical security overall]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1649</itunes:duration>
                <itunes:episode>78</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 76: Why Security Certs for New Medical Devices Might Just Work</title>
        <itunes:title>EP 76: Why Security Certs for New Medical Devices Might Just Work</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-76-why-security-certs-for-new-medical-devices-might-just-work/</link>
                    <comments>https://errorcode.podbean.com/e/ep-76-why-security-certs-for-new-medical-devices-might-just-work/#comments</comments>        <pubDate>Wed, 26 Nov 2025 09:47:48 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/c015a48d-e70d-34cb-b98c-376225b5b758</guid>
                                    <description><![CDATA[<p>Diversity in healthcare devices complicates segmentation, security controls, and zero-trust approaches. New certifications aim to help. Bob Lyle, CRO of Medcrypt, identifies how layered defenses, rigorous cybersecurity requirements for new devices, continuous monitoring, and dark-web credential surveillance can reduce risk.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Diversity in healthcare devices complicates segmentation, security controls, and zero-trust approaches. New certifications aim to help. Bob Lyle, CRO of Medcrypt, identifies how layered defenses, rigorous cybersecurity requirements for new devices, continuous monitoring, and dark-web credential surveillance can reduce risk.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/yf4zbyzypzgqvavy/EP76FINAL.mp3" length="53112834" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Diversity in healthcare devices complicates segmentation, security controls, and zero-trust approaches. New certifications aim to help. Bob Lyle, CRO of Medcrypt, identifies how layered defenses, rigorous cybersecurity requirements for new devices, continuous monitoring, and dark-web credential surveillance can reduce risk.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2210</itunes:duration>
                <itunes:episode>77</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 75: IoT-based Living Off The Land Attacks and Air-Gapping Solar Systems</title>
        <itunes:title>EP 75: IoT-based Living Off The Land Attacks and Air-Gapping Solar Systems</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-75-iot-based-living-off-the-land-attacks-and-air-gapping-solar-systems/</link>
                    <comments>https://errorcode.podbean.com/e/ep-75-iot-based-living-off-the-land-attacks-and-air-gapping-solar-systems/#comments</comments>        <pubDate>Tue, 11 Nov 2025 13:35:17 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/353490be-7ddd-390c-a6e0-0591af6e5aa8</guid>
                                    <description><![CDATA[<p>At <a href='https://www.blackhat.com/us-25/'>Black Hat USA 2025</a>, Dan Berte, IoT Director at Bitdefender, revisits his talk last year about hacking solar panels in light of the blackout in Spain and Portugal. While the Iberian Peninsula blackout wasn’t an attack, it shows how sensitive these systems are when mixing old and new technologies, and how living off the land attacks might someday take advantage of that. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>At <a href='https://www.blackhat.com/us-25/'>Black Hat USA 2025</a>, Dan Berte, IoT Director at Bitdefender, revisits his talk last year about hacking solar panels in light of the blackout in Spain and Portugal. While the Iberian Peninsula blackout wasn’t an attack, it shows how sensitive these systems are when mixing old and new technologies, and how living off the land attacks might someday take advantage of that. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/d9yjvqj88ma25wx2/EP75FINAL.mp3" length="34687730" type="audio/mpeg"/>
        <itunes:summary><![CDATA[At Black Hat USA 2025, Dan Berte, IoT Director at Bitdefender, revisits his talk last year about hacking solar panels in light of the blackout in Spain and Portugal. While the Iberian Peninsula blackout wasn’t an attack, it shows how sensitive these systems are when mixing old and new technologies, and how living off the land attacks might someday take advantage of that. ]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1442</itunes:duration>
                <itunes:episode>76</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 74: Turning Surveillance Cameras on their Axis</title>
        <itunes:title>EP 74: Turning Surveillance Cameras on their Axis</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-74-turning-surveillance-cameras-on-their-axis/</link>
                    <comments>https://errorcode.podbean.com/e/ep-74-turning-surveillance-cameras-on-their-axis/#comments</comments>        <pubDate>Tue, 28 Oct 2025 12:06:20 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/688c6091-5b8c-373f-a16a-47960fec8e5e</guid>
                                    <description><![CDATA[<p>At <a href='https://www.blackhat.com/us-25/'>Black Hat USA 2025</a>, Noam Moshe from <a href='https://claroty.com/team82/research'>Claroty’s Team 82</a> revealed several vulnerabilities in <a href='https://i.blackhat.com/BH-USA-25/Presentations/US-25-Moshe-Turning-Camera-Surveillance-on-its-Axis-Wednesday.pdf'>Axis Communications’ IP camera systems</a>, including a deserialization flaw that could let attackers run remote code. The team worked with Axis to patch the issues. Moshe says that this case highlights the broader security risks still common in the billions of common IoT devices in the world today.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>At <a href='https://www.blackhat.com/us-25/'>Black Hat USA 2025</a>, Noam Moshe from <a href='https://claroty.com/team82/research'>Claroty’s Team 82</a> revealed several vulnerabilities in <a href='https://i.blackhat.com/BH-USA-25/Presentations/US-25-Moshe-Turning-Camera-Surveillance-on-its-Axis-Wednesday.pdf'>Axis Communications’ IP camera systems</a>, including a deserialization flaw that could let attackers run remote code. The team worked with Axis to patch the issues. Moshe says that this case highlights the broader security risks still common in the billions of common IoT devices in the world today.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/psri5d9y7u8a72rs/EP74FINAL.mp3" length="41266944" type="audio/mpeg"/>
        <itunes:summary><![CDATA[At Black Hat USA 2025, Noam Moshe from Claroty’s Team 82 revealed several vulnerabilities in Axis Communications’ IP camera systems, including a deserialization flaw that could let attackers run remote code. The team worked with Axis to patch the issues. Moshe says that this case highlights the broader security risks still common in the billions of common IoT devices in the world today.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1716</itunes:duration>
                <itunes:episode>75</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 73: BADBOX 2.0: Blurring the line between bots and human for cybercrime</title>
        <itunes:title>EP 73: BADBOX 2.0: Blurring the line between bots and human for cybercrime</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-73-badbox-20-blurring-the-line-between-bots-and-human-for-cybercrime/</link>
                    <comments>https://errorcode.podbean.com/e/ep-73-badbox-20-blurring-the-line-between-bots-and-human-for-cybercrime/#comments</comments>        <pubDate>Tue, 14 Oct 2025 08:33:28 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/727f0505-e272-3fcc-8488-10a6503c0bd3</guid>
                                    <description><![CDATA[<p>Ad fraud driven by both humans and AI agents require new signals beyond traditional bot-vs-human checks. Gavin Reid and Lindsay Kaye from <a href='https://www.humansecurity.com/'>HUMAN Security</a> discuss how monetization includes ad and click fraud (peach pit), selling residential proxy access, and operating botnets for hire and preventing harm requires dismantling criminal infrastructure and collaboration across industry, since many infected devices cannot be practically cleansed by end users.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Ad fraud driven by both humans and AI agents require new signals beyond traditional bot-vs-human checks. Gavin Reid and Lindsay Kaye from <a href='https://www.humansecurity.com/'>HUMAN Security</a> discuss how monetization includes ad and click fraud (peach pit), selling residential proxy access, and operating botnets for hire and preventing harm requires dismantling criminal infrastructure and collaboration across industry, since many infected devices cannot be practically cleansed by end users.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/e34k4fzpq7dkcrjm/EP73FINAL.mp3" length="54710274" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Ad fraud driven by both humans and AI agents require new signals beyond traditional bot-vs-human checks. Gavin Reid and Lindsay Kaye from HUMAN Security discuss how monetization includes ad and click fraud (peach pit), selling residential proxy access, and operating botnets for hire and preventing harm requires dismantling criminal infrastructure and collaboration across industry, since many infected devices cannot be practically cleansed by end users.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2276</itunes:duration>
                <itunes:episode>74</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 72: Does a CISSP Certification Make Sense For OT?</title>
        <itunes:title>EP 72: Does a CISSP Certification Make Sense For OT?</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-72-does-a-cissp-certification-make-sense-for-ot/</link>
                    <comments>https://errorcode.podbean.com/e/ep-72-does-a-cissp-certification-make-sense-for-ot/#comments</comments>        <pubDate>Tue, 30 Sep 2025 14:43:24 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/541f47f0-9829-3ca0-b6b4-1d5a98288f0e</guid>
                                    <description><![CDATA[<p>Certification exams increasingly reflect the IT OT convergence, acknowledging that many protections apply across both domains requiring holistic security approaches rather than siloed solutions. John France, CISO at ISC2, explains that as threats grow more complex, certifications, continuous learning, and diverse skills are essential to building a resilient global workforce.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Certification exams increasingly reflect the IT OT convergence, acknowledging that many protections apply across both domains requiring holistic security approaches rather than siloed solutions. John France, CISO at ISC2, explains that as threats grow more complex, certifications, continuous learning, and diverse skills are essential to building a resilient global workforce.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qaycnrcmx5uvgtm9/EP72FINAL.mp3" length="40132694" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Certification exams increasingly reflect the IT OT convergence, acknowledging that many protections apply across both domains requiring holistic security approaches rather than siloed solutions. John France, CISO at ISC2, explains that as threats grow more complex, certifications, continuous learning, and diverse skills are essential to building a resilient global workforce.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1669</itunes:duration>
                <itunes:episode>73</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 71: Meeting Cybersecurity Requirements That Don’t Yet Exist</title>
        <itunes:title>EP 71: Meeting Cybersecurity Requirements That Don’t Yet Exist</itunes:title>
        <link>https://errorcode.podbean.com/e/e71-meeting-cybersecurity-requirements-that-don-t-yet-exist/</link>
                    <comments>https://errorcode.podbean.com/e/e71-meeting-cybersecurity-requirements-that-don-t-yet-exist/#comments</comments>        <pubDate>Tue, 16 Sep 2025 14:19:48 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/3af5947a-3ea4-36f6-a296-a4ad16aa62a7</guid>
                                    <description><![CDATA[<p>The EU’s new Cyber Resilience Act (CRA) sets higher security requirements but leaves many technical details undecided. This puts pressure on vendors of connected or software-based products to either redesign, retrofit, or withdraw from the market. According to Roland Marx, Senior Product Manager at <a href='https://www.swissbit.com/en/'>Swissbit</a>, the CRA’s three-year rollout is meant to give companies time to adapt while regulators finalize the specifics.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The EU’s new Cyber Resilience Act (CRA) sets higher security requirements but leaves many technical details undecided. This puts pressure on vendors of connected or software-based products to either redesign, retrofit, or withdraw from the market. According to Roland Marx, Senior Product Manager at <a href='https://www.swissbit.com/en/'>Swissbit</a>, the CRA’s three-year rollout is meant to give companies time to adapt while regulators finalize the specifics.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/6gqqkaf8dveavb3t/EP71FINAL.mp3" length="67985076" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The EU’s new Cyber Resilience Act (CRA) sets higher security requirements but leaves many technical details undecided. This puts pressure on vendors of connected or software-based products to either redesign, retrofit, or withdraw from the market. According to Roland Marx, Senior Product Manager at Swissbit, the CRA’s three-year rollout is meant to give companies time to adapt while regulators finalize the specifics.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2829</itunes:duration>
                <itunes:episode>72</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 70: Securing Medical Devices You Might Not Have Thought to Secure</title>
        <itunes:title>EP 70: Securing Medical Devices You Might Not Have Thought to Secure</itunes:title>
        <link>https://errorcode.podbean.com/e/ep70-securing-medical-devices-you-might-not-have-thought-to-secure/</link>
                    <comments>https://errorcode.podbean.com/e/ep70-securing-medical-devices-you-might-not-have-thought-to-secure/#comments</comments>        <pubDate>Tue, 02 Sep 2025 10:43:35 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/fdd79655-3744-3546-b618-7e909c2690a9</guid>
                                    <description><![CDATA[<p>Healthcare organizations are prone to the same weaknesses that any other office or manufacturing site may have. Sonu Shankar, Chief Product Officer at <a href='https://phosphorus.io/'>Phosphorus Cybersecurity</a>, explains how the devices you might not suspect might be the ones to bring down your organization if they’re not secured. That includes the printer used to print patient wristbands.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Healthcare organizations are prone to the same weaknesses that any other office or manufacturing site may have. Sonu Shankar, Chief Product Officer at <a href='https://phosphorus.io/'>Phosphorus Cybersecurity</a>, explains how the devices you might not suspect might be the ones to bring down your organization if they’re not secured. That includes the printer used to print patient wristbands.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/v9caa2t9cqn7pips/EP70FINAL.mp3" length="48328037" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Healthcare organizations are prone to the same weaknesses that any other office or manufacturing site may have. Sonu Shankar, Chief Product Officer at Phosphorus Cybersecurity, explains how the devices you might not suspect might be the ones to bring down your organization if they’re not secured. That includes the printer used to print patient wristbands.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2010</itunes:duration>
                <itunes:episode>71</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 69: Adding Crypto Agility to OT Systems</title>
        <itunes:title>EP 69: Adding Crypto Agility to OT Systems</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-69-adding-crypto-agility-to-ot-systems/</link>
                    <comments>https://errorcode.podbean.com/e/ep-69-adding-crypto-agility-to-ot-systems/#comments</comments>        <pubDate>Tue, 19 Aug 2025 15:08:38 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/bfe1a620-8d8e-3eb4-a572-0fdda2158c2c</guid>
                                    <description><![CDATA[<p>Quantum computers could break today’s encryption, leaving many OT systems—which often lack encryption entirely—at even greater risk. Dave Krauthamer, Field CTO at <a href='https://www.qusecure.com/'>QuSecure</a>, warns that nation-state attackers may target critical infrastructure like power, water, and food supplies first, making it urgent to adopt quantum-resistant cryptography across both IT and OT systems.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Quantum computers could break today’s encryption, leaving many OT systems—which often lack encryption entirely—at even greater risk. Dave Krauthamer, Field CTO at <a href='https://www.qusecure.com/'>QuSecure</a>, warns that nation-state attackers may target critical infrastructure like power, water, and food supplies first, making it urgent to adopt quantum-resistant cryptography across both IT and OT systems.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hrfrwhdpe9zykarr/EP69FINAL.mp3" length="57074460" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Quantum computers could break today’s encryption, leaving many OT systems—which often lack encryption entirely—at even greater risk. Dave Krauthamer, Field CTO at QuSecure, warns that nation-state attackers may target critical infrastructure like power, water, and food supplies first, making it urgent to adopt quantum-resistant cryptography across both IT and OT systems.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2375</itunes:duration>
                <itunes:episode>70</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 68: Hacking Cruise Ships and Data Centers</title>
        <itunes:title>EP 68: Hacking Cruise Ships and Data Centers</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-68-hacking-cruise-ships-and-data-centers/</link>
                    <comments>https://errorcode.podbean.com/e/ep-68-hacking-cruise-ships-and-data-centers/#comments</comments>        <pubDate>Tue, 05 Aug 2025 12:00:00 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/323a2d44-4487-3a79-b56a-625ba0012ef3</guid>
                                    <description><![CDATA[<p>This is a story where one maritime company found multiple vendors maintaining unrestricted VPN access to systems across a cruise vessel, exposing safety-critical functions to potential compromise. Bill Moore, CEO of Xona Systems, returns to Error Code to talk about how that company and others, such as data center operators, are recognizing their latent multiple-vendor OT exposure and learning how to address it today.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is a story where one maritime company found multiple vendors maintaining unrestricted VPN access to systems across a cruise vessel, exposing safety-critical functions to potential compromise. Bill Moore, CEO of Xona Systems, returns to Error Code to talk about how that company and others, such as data center operators, are recognizing their latent multiple-vendor OT exposure and learning how to address it today.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pk4zuvjy3fwg4fne/EP68FINAL.mp3" length="48096070" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This is a story where one maritime company found multiple vendors maintaining unrestricted VPN access to systems across a cruise vessel, exposing safety-critical functions to potential compromise. Bill Moore, CEO of Xona Systems, returns to Error Code to talk about how that company and others, such as data center operators, are recognizing their latent multiple-vendor OT exposure and learning how to address it today.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2001</itunes:duration>
                <itunes:episode>69</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 67:  Collateral Damage</title>
        <itunes:title>EP 67:  Collateral Damage</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-67-collateral-damage/</link>
                    <comments>https://errorcode.podbean.com/e/ep-67-collateral-damage/#comments</comments>        <pubDate>Tue, 22 Jul 2025 13:09:20 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/56ca14b7-b3f8-38de-b5c4-1d3a6d890cd5</guid>
                                    <description><![CDATA[<p>Operational technology (OT) systems are no longer limited to nation-states; criminal groups and hacktivists now actively target these systems, often driven by financial or ideological motives. Kurt Gaudette, Vice President of Intelligence and Services at Dragos, explains why these systems might not even be the primary targets.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Operational technology (OT) systems are no longer limited to nation-states; criminal groups and hacktivists now actively target these systems, often driven by financial or ideological motives. Kurt Gaudette, Vice President of Intelligence and Services at Dragos, explains why these systems might not even be the primary targets.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kce9sm5v6382vimz/ep67FINAL.mp3" length="33837696" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Operational technology (OT) systems are no longer limited to nation-states; criminal groups and hacktivists now actively target these systems, often driven by financial or ideological motives. Kurt Gaudette, Vice President of Intelligence and Services at Dragos, explains why these systems might not even be the primary targets.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1407</itunes:duration>
                <itunes:episode>68</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 66: Secure only the OT code that actually runs</title>
        <itunes:title>EP 66: Secure only the OT code that actually runs</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-66-secure-only-the-ot-code-that-actually-runs/</link>
                    <comments>https://errorcode.podbean.com/e/ep-66-secure-only-the-ot-code-that-actually-runs/#comments</comments>        <pubDate>Tue, 08 Jul 2025 12:03:14 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/e224500d-7830-3984-8d3c-d491e23a4d45</guid>
                                    <description><![CDATA[<p>Many organizations spend valuable security resources fixing vulnerabilities in code that never actually runs—an inefficient and often unnecessary effort. Jeff Williams, CTO and founder at <a href='https://www.contrastsecurity.com/'>Contrast Security</a>, says that 62% of open source libraries included in software are never even loaded into memory, let alone executed. This means only 38% of libraries are typically active and worth prioritizing. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Many organizations spend valuable security resources fixing vulnerabilities in code that never actually runs—an inefficient and often unnecessary effort. Jeff Williams, CTO and founder at <a href='https://www.contrastsecurity.com/'>Contrast Security</a>, says that 62% of open source libraries included in software are never even loaded into memory, let alone executed. This means only 38% of libraries are typically active and worth prioritizing. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9fvfjnpc369dqk87/EP66FINAL.mp3" length="33472723" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Many organizations spend valuable security resources fixing vulnerabilities in code that never actually runs—an inefficient and often unnecessary effort. Jeff Williams, CTO and founder at Contrast Security, says that 62% of open source libraries included in software are never even loaded into memory, let alone executed. This means only 38% of libraries are typically active and worth prioritizing. ]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1391</itunes:duration>
                <itunes:episode>67</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 65: Hacking Critical Infrastructure Through Supply Chains</title>
        <itunes:title>EP 65: Hacking Critical Infrastructure Through Supply Chains</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-65-hacking-critical-infrastructure-through-supply-chains/</link>
                    <comments>https://errorcode.podbean.com/e/ep-65-hacking-critical-infrastructure-through-supply-chains/#comments</comments>        <pubDate>Tue, 24 Jun 2025 14:22:14 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/517a84d0-ef85-3a27-b5ac-3d4e35bfb507</guid>
                                    <description><![CDATA[<p>Critical Infrastructure software lacks the strict liability standards found in industries like automotive manufacturing, leading to minimal accountability for insecure products when they get exploited.  Alex Santos, CEO of <a href='https://www.fortressinfosec.com/'>Fortress Information Security</a>, explains how they’re typically hired by buyers of ICS equipment—such as utilities—to assess and mitigate supply chain risks, including working with OEMs to improve security.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Critical Infrastructure software lacks the strict liability standards found in industries like automotive manufacturing, leading to minimal accountability for insecure products when they get exploited.  Alex Santos, CEO of <a href='https://www.fortressinfosec.com/'>Fortress Information Security</a>, explains how they’re typically hired by buyers of ICS equipment—such as utilities—to assess and mitigate supply chain risks, including working with OEMs to improve security.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/36kvix4wz7jq4bd3/EP65FINAL.mp3" length="43802793" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Critical Infrastructure software lacks the strict liability standards found in industries like automotive manufacturing, leading to minimal accountability for insecure products when they get exploited.  Alex Santos, CEO of Fortress Information Security, explains how they’re typically hired by buyers of ICS equipment—such as utilities—to assess and mitigate supply chain risks, including working with OEMs to improve security.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1822</itunes:duration>
                <itunes:episode>66</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 64: Volt Typhoon</title>
        <itunes:title>EP 64: Volt Typhoon</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-64-volt-typhoon/</link>
                    <comments>https://errorcode.podbean.com/e/ep-64-volt-typhoon/#comments</comments>        <pubDate>Tue, 10 Jun 2025 12:33:33 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/7693fc80-27e4-3faf-b054-b1f78b7b877f</guid>
                                    <description><![CDATA[<p>While cybersecurity threats targeting critical infrastructure, particularly focusing on the vulnerabilities of operational technology (OT) and industrial control systems (ICS).mostly originate on the business or IT side, there’s increasing concern about attacks crossing into OT, which could result in catastrophic consequences, especially in centralized systems like utilities. Michael Welch,  managing director from <a href='https://mfcyber.com/'>MorganFranklin Cyber</a>, discusses how Volt Typhoon and other attacks are living off the land, and lying in wait.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>While cybersecurity threats targeting critical infrastructure, particularly focusing on the vulnerabilities of operational technology (OT) and industrial control systems (ICS).mostly originate on the business or IT side, there’s increasing concern about attacks crossing into OT, which could result in catastrophic consequences, especially in centralized systems like utilities. Michael Welch,  managing director from <a href='https://mfcyber.com/'>MorganFranklin Cyber</a>, discusses how Volt Typhoon and other attacks are living off the land, and lying in wait.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cypmi64634r3gz4g/EP64FINAL.mp3" length="63063606" type="audio/mpeg"/>
        <itunes:summary><![CDATA[While cybersecurity threats targeting critical infrastructure, particularly focusing on the vulnerabilities of operational technology (OT) and industrial control systems (ICS).mostly originate on the business or IT side, there’s increasing concern about attacks crossing into OT, which could result in catastrophic consequences, especially in centralized systems like utilities. Michael Welch,  managing director from MorganFranklin Cyber, discusses how Volt Typhoon and other attacks are living off the land, and lying in wait.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2624</itunes:duration>
                <itunes:episode>65</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 63: Chief Hacking Officer</title>
        <itunes:title>EP 63: Chief Hacking Officer</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-63-chief-hacking-officer/</link>
                    <comments>https://errorcode.podbean.com/e/ep-63-chief-hacking-officer/#comments</comments>        <pubDate>Tue, 27 May 2025 16:46:00 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/491b5471-48d6-3535-ad17-5ef2735f9048</guid>
                                    <description><![CDATA[<p>This is a story about a Chief Hacking Officer who draws on his expertise in physical and virtual security assessments—along with some intuitive AI-driven coding—to safeguard Operational Technology. Colin Murphy of Frenos and Mitnick Security talks about how some of his early assessment work with Kevin Mitnick is helping him with OT security today.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is a story about a Chief Hacking Officer who draws on his expertise in physical and virtual security assessments—along with some intuitive AI-driven coding—to safeguard Operational Technology. Colin Murphy of Frenos and Mitnick Security talks about how some of his early assessment work with Kevin Mitnick is helping him with OT security today.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/mnermug62u7pjitp/EP63FINAL.mp3" length="39048768" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This is a story about a Chief Hacking Officer who draws on his expertise in physical and virtual security assessments—along with some intuitive AI-driven coding—to safeguard Operational Technology. Colin Murphy of Frenos and Mitnick Security talks about how some of his early assessment work with Kevin Mitnick is helping him with OT security today.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1624</itunes:duration>
                <itunes:episode>64</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 62: Defending the Unknown in OT Security</title>
        <itunes:title>EP 62: Defending the Unknown in OT Security</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-62-defending-the-unknown-in-ot-security/</link>
                    <comments>https://errorcode.podbean.com/e/ep-62-defending-the-unknown-in-ot-security/#comments</comments>        <pubDate>Tue, 13 May 2025 15:30:29 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/025f9290-c2f2-3154-b666-96858f3d4014</guid>
                                    <description><![CDATA[<p>ROI is always a tricky subject in cybersecurity. If you’re paying millions of dollars in securing your OT networks, you’d want to be able to show that it was worth it. Andrew Hural of <a href='https://underdefense.com/'>UnderDefense</a> talks about the need for continuous vigilance, risk management, and proactive defense, acknowledging both the human and technological elements in cybersecurity and how just because something didn’t happen doesn’t mean that it didn’t.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>ROI is always a tricky subject in cybersecurity. If you’re paying millions of dollars in securing your OT networks, you’d want to be able to show that it was worth it. Andrew Hural of <a href='https://underdefense.com/'>UnderDefense</a> talks about the need for continuous vigilance, risk management, and proactive defense, acknowledging both the human and technological elements in cybersecurity and how just because something didn’t happen doesn’t mean that it didn’t.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/37bc5es5zkxku25r/EP62FINAL.mp3" length="45625931" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ROI is always a tricky subject in cybersecurity. If you’re paying millions of dollars in securing your OT networks, you’d want to be able to show that it was worth it. Andrew Hural of UnderDefense talks about the need for continuous vigilance, risk management, and proactive defense, acknowledging both the human and technological elements in cybersecurity and how just because something didn’t happen doesn’t mean that it didn’t.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1898</itunes:duration>
                <itunes:episode>63</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 61: Applying Zero Trust to OT systems</title>
        <itunes:title>EP 61: Applying Zero Trust to OT systems</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-61-applying-zero-trust-to-ot-systems/</link>
                    <comments>https://errorcode.podbean.com/e/ep-61-applying-zero-trust-to-ot-systems/#comments</comments>        <pubDate>Tue, 29 Apr 2025 17:32:08 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/9ba858e8-883b-3cf2-a90f-4f16a36f8e75</guid>
                                    <description><![CDATA[<p>Zero Trust is a security model based on default-deny policies and fine-grained access control governed by identity, authentication, and contextual signals. For <a href='https://www.rsaconference.com/usa'>RSAC 2025</a>, John Kindervag, Chief Evangelist of <a href='http://illumio'>Illumio</a> and the creator of Zero Trust, talks about introducing a "protect surface" into legacy OT systems —isolating critical data, applications, assets, or services into secure zones for targeted Zero Trust implementation.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Zero Trust is a security model based on default-deny policies and fine-grained access control governed by identity, authentication, and contextual signals. For <a href='https://www.rsaconference.com/usa'>RSAC 2025</a>, John Kindervag, Chief Evangelist of <a href='http://illumio'>Illumio</a> and the creator of Zero Trust, talks about introducing a "protect surface" into legacy OT systems —isolating critical data, applications, assets, or services into secure zones for targeted Zero Trust implementation.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/c6533j962cyskqda/EP61FINAL1.mp3" length="52097193" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Zero Trust is a security model based on default-deny policies and fine-grained access control governed by identity, authentication, and contextual signals. For RSAC 2025, John Kindervag, Chief Evangelist of Illumio and the creator of Zero Trust, talks about introducing a "protect surface" into legacy OT systems —isolating critical data, applications, assets, or services into secure zones for targeted Zero Trust implementation.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2167</itunes:duration>
                <itunes:episode>62</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 60: Hacking Solar Power Inverters</title>
        <itunes:title>EP 60: Hacking Solar Power Inverters</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-60-hacking-solar-power-inverters/</link>
                    <comments>https://errorcode.podbean.com/e/ep-60-hacking-solar-power-inverters/#comments</comments>        <pubDate>Tue, 15 Apr 2025 16:33:57 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/e10f2684-1e54-377f-8d3e-c822fe53fe75</guid>
                                    <description><![CDATA[<p>Solar power systems are rapidly becoming essential elements of power grids throughout the world, especially in the US and EU. However, cybersecurity for these systems is often an afterthought, creating a growing risk to grid stability and availability. Daniel de Santos, Head of Research at <a href='https://www.forescout.com/'>Forescout</a>, talks about his recent research into vulnerabilities associated with solar panel investors, how they might affect the power grid or the end-user, and what we can do about it. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Solar power systems are rapidly becoming essential elements of power grids throughout the world, especially in the US and EU. However, cybersecurity for these systems is often an afterthought, creating a growing risk to grid stability and availability. Daniel de Santos, Head of Research at <a href='https://www.forescout.com/'>Forescout</a>, talks about his recent research into vulnerabilities associated with solar panel investors, how they might affect the power grid or the end-user, and what we can do about it. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/yb472pneupubpsq3/EP60FINAL.mp3" length="56729644" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Solar power systems are rapidly becoming essential elements of power grids throughout the world, especially in the US and EU. However, cybersecurity for these systems is often an afterthought, creating a growing risk to grid stability and availability. Daniel de Santos, Head of Research at Forescout, talks about his recent research into vulnerabilities associated with solar panel investors, how they might affect the power grid or the end-user, and what we can do about it. ]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2361</itunes:duration>
                <itunes:episode>61</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 59: Automotive Hacking In Your Own Garage</title>
        <itunes:title>EP 59: Automotive Hacking In Your Own Garage</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-59-automotive-hacking-in-your-own-garage/</link>
                    <comments>https://errorcode.podbean.com/e/ep-59-automotive-hacking-in-your-own-garage/#comments</comments>        <pubDate>Tue, 01 Apr 2025 14:23:38 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/eeb0039c-f750-33a6-88f3-66a31ffc0b65</guid>
                                    <description><![CDATA[<p>Gone are the days when you could repair your own car. Even ICE cars have more electronics than ever before. Alexander Pick is an independent hardware hacker specializing in automotive systems. He says if you start off small, like looking at ECUs, there’s a lot of great research yet to be done by both hobbyists and professionals alike.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Gone are the days when you could repair your own car. Even ICE cars have more electronics than ever before. Alexander Pick is an independent hardware hacker specializing in automotive systems. He says if you start off small, like looking at ECUs, there’s a lot of great research yet to be done by both hobbyists and professionals alike.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/6fq7zds3i3nvfpva/EP59FINAL.mp3" length="52282140" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Gone are the days when you could repair your own car. Even ICE cars have more electronics than ever before. Alexander Pick is an independent hardware hacker specializing in automotive systems. He says if you start off small, like looking at ECUs, there’s a lot of great research yet to be done by both hobbyists and professionals alike.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2175</itunes:duration>
                <itunes:episode>60</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 58: Hacking Office Supplies</title>
        <itunes:title>EP 58: Hacking Office Supplies</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-58-hacking-office-supplies/</link>
                    <comments>https://errorcode.podbean.com/e/ep-58-hacking-office-supplies/#comments</comments>        <pubDate>Tue, 18 Mar 2025 16:40:46 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/fbc8ee78-5bad-3149-b3c9-25d4262fe52b</guid>
                                    <description><![CDATA[<p>It’s becoming easier for criminals to use counterfeit or altered chips in common office products, such as printer toner cartridges, with the aim of espionage or simple financial gain. Tony Moor, Senior Director Of Silicon Lab Services For <a href='https://ioactive.com/'>IOActive</a>, explains how the hacking embedded silicon within common objects in our day to day lives is becoming more common, and what the consequences of this lack of security might mean.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>It’s becoming easier for criminals to use counterfeit or altered chips in common office products, such as printer toner cartridges, with the aim of espionage or simple financial gain. Tony Moor, Senior Director Of Silicon Lab Services For <a href='https://ioactive.com/'>IOActive</a>, explains how the hacking embedded silicon within common objects in our day to day lives is becoming more common, and what the consequences of this lack of security might mean.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/vknipmpb5b4t2c6u/EP58FINAL.mp3" length="65892981" type="audio/mpeg"/>
        <itunes:summary><![CDATA[It’s becoming easier for criminals to use counterfeit or altered chips in common office products, such as printer toner cartridges, with the aim of espionage or simple financial gain. Tony Moor, Senior Director Of Silicon Lab Services For IOActive, explains how the hacking embedded silicon within common objects in our day to day lives is becoming more common, and what the consequences of this lack of security might mean.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2742</itunes:duration>
                <itunes:episode>59</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 57: Strengthening Embedded Device Security with Cloud-Based SCADA</title>
        <itunes:title>EP 57: Strengthening Embedded Device Security with Cloud-Based SCADA</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-57-strengthening-embedded-device-security-with-cloud-based-scada/</link>
                    <comments>https://errorcode.podbean.com/e/ep-57-strengthening-embedded-device-security-with-cloud-based-scada/#comments</comments>        <pubDate>Tue, 04 Mar 2025 17:20:49 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/7fa2a4aa-7c4c-3445-bfae-36029a370bc4</guid>
                                    <description><![CDATA[<p>Embedded devices need basic security measures like multi-factor authentication and unique credentials to reduce vulnerabilities and protect against cyber threats. Mauritz Botha, co-founder and CTO of XiO Inc., explains that cloud-based SCADA can update old systems and provide the visibility that’s currently missing.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Embedded devices need basic security measures like multi-factor authentication and unique credentials to reduce vulnerabilities and protect against cyber threats. Mauritz Botha, co-founder and CTO of XiO Inc., explains that cloud-based SCADA can update old systems and provide the visibility that’s currently missing.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4s8d2u7xywz8ac3p/EP57FINAL.mp3" length="48473487" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Embedded devices need basic security measures like multi-factor authentication and unique credentials to reduce vulnerabilities and protect against cyber threats. Mauritz Botha, co-founder and CTO of XiO Inc., explains that cloud-based SCADA can update old systems and provide the visibility that’s currently missing.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2016</itunes:duration>
                <itunes:episode>58</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 56: Hacking OT and ICS in the Era of Cloud and Automation</title>
        <itunes:title>EP 56: Hacking OT and ICS in the Era of Cloud and Automation</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-56-hacking-ot-and-ics-in-the-era-of-cloud-and-automation/</link>
                    <comments>https://errorcode.podbean.com/e/ep-56-hacking-ot-and-ics-in-the-era-of-cloud-and-automation/#comments</comments>        <pubDate>Tue, 18 Feb 2025 15:26:49 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/9e256470-e408-3e0d-bc4a-856950c94c5c</guid>
                                    <description><![CDATA[<p>As industrial enterprises lurch toward digital transformation and Industry 4.0, a new report looks at the security OT systems and finds it wanting. Grant Geyer, the Chief Strategy Officer for <a href='https://claroty.com/'>Claroty</a>, talks about the findings from over one million devices in the field today, and what industries must do now to secure them.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>As industrial enterprises lurch toward digital transformation and Industry 4.0, a new report looks at the security OT systems and finds it wanting. Grant Geyer, the Chief Strategy Officer for <a href='https://claroty.com/'>Claroty</a>, talks about the findings from over one million devices in the field today, and what industries must do now to secure them.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qhtpcy26y27hamsx/EP56FINAL.mp3" length="61022921" type="audio/mpeg"/>
        <itunes:summary><![CDATA[As industrial enterprises lurch toward digital transformation and Industry 4.0, a new report looks at the security OT systems and finds it wanting. Grant Geyer, the Chief Strategy Officer for Claroty, talks about the findings from over one million devices in the field today, and what industries must do now to secure them.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2539</itunes:duration>
                <itunes:episode>57</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 55: Building Secure Storage for Autonomous Vehicles</title>
        <itunes:title>EP 55: Building Secure Storage for Autonomous Vehicles</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-55-creating-secure-device-storage-for-autonomous-vehicles/</link>
                    <comments>https://errorcode.podbean.com/e/ep-55-creating-secure-device-storage-for-autonomous-vehicles/#comments</comments>        <pubDate>Tue, 04 Feb 2025 14:38:35 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/15ed851b-7500-350e-a481-01192bcc68d5</guid>
                                    <description><![CDATA[<p>I recently rode in a Waymo, Google’s self-driving taxi service, and it was fantastic. What if we took that vehicle off the safe roads of California and put it in a warzone like Ukraine? If it was captured, could the enemy get its data or its algorithms? Brent Hansen, Chief Growth Officer at Cigent, talks about the data risks associated with autonomous vehicles and remote servers, and how data security is essential in these in the field locations.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>I recently rode in a Waymo, Google’s self-driving taxi service, and it was fantastic. What if we took that vehicle off the safe roads of California and put it in a warzone like Ukraine? If it was captured, could the enemy get its data or its algorithms? Brent Hansen, Chief Growth Officer at Cigent, talks about the data risks associated with autonomous vehicles and remote servers, and how data security is essential in these in the field locations.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/f36ughpv48bkryjq/EP55FINAL.mp3" length="41547695" type="audio/mpeg"/>
        <itunes:summary><![CDATA[I recently rode in a Waymo, Google’s self-driving taxi service, and it was fantastic. What if we took that vehicle off the safe roads of California and put it in a warzone like Ukraine? If it was captured, could the enemy get its data or its algorithms? Brent Hansen, Chief Growth Officer at Cigent, talks about the data risks associated with autonomous vehicles and remote servers, and how data security is essential in these in the field locations.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1728</itunes:duration>
                <itunes:episode>56</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 54: From Cyber Chaos to Control: Lessons from a Kansas Water District</title>
        <itunes:title>EP 54: From Cyber Chaos to Control: Lessons from a Kansas Water District</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-54-from-cyber-chaos-to-control-lessons-from-a-kansas-water-district/</link>
                    <comments>https://errorcode.podbean.com/e/ep-54-from-cyber-chaos-to-control-lessons-from-a-kansas-water-district/#comments</comments>        <pubDate>Tue, 21 Jan 2025 12:32:54 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/7a52a0c7-3d45-3d27-9884-c631bdd0a781</guid>
                                    <description><![CDATA[<p>Imagine your best worst day during a cyber attack. Can you switch to manual systems in case of a failure? Has your team practiced for that? Dave Gunter, OT Cybersecurity Director at <a href='https://armexa.com/'>Armexa</a>, discusses how a water and waste water utility in Kansas responded correctly to a cyberattack in 2024 by falling back to manual and issuing clear, and concise press releases to assure the public that their water was safe to drink.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Imagine your best worst day during a cyber attack. Can you switch to manual systems in case of a failure? Has your team practiced for that? Dave Gunter, OT Cybersecurity Director at <a href='https://armexa.com/'>Armexa</a>, discusses how a water and waste water utility in Kansas responded correctly to a cyberattack in 2024 by falling back to manual and issuing clear, and concise press releases to assure the public that their water was safe to drink.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/3abpwgm5gubd4hxn/EP54FINAL.mp3" length="49060929" type="audio/mpeg"/>
        <itunes:summary>Imagine your best worst day during a cyber attack. Can you switch to manual systems in case of a failure? Has your team practiced for that?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2041</itunes:duration>
                <itunes:episode>55</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 53: Securing Smart OT Systems Already In The Field</title>
        <itunes:title>EP 53: Securing Smart OT Systems Already In The Field</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-53-securing-smart-ot-systems-already-in-the-field/</link>
                    <comments>https://errorcode.podbean.com/e/ep-53-securing-smart-ot-systems-already-in-the-field/#comments</comments>        <pubDate>Tue, 07 Jan 2025 15:40:29 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/bef808fc-5697-36d5-a081-f846af8abd8c</guid>
                                    <description><![CDATA[<p>This is the story of how the security of OT devices in the field can be modernized virtual isolation in the cloud, adding both authentication and encryption into the mix. Bill Moore, founder and CEO of Xona, explains how you can virtualize the OT network and interact with it, adding 2FA and encryption to legacy systems already in the field. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is the story of how the security of OT devices in the field can be modernized virtual isolation in the cloud, adding both authentication and encryption into the mix. Bill Moore, founder and CEO of Xona, explains how you can virtualize the OT network and interact with it, adding 2FA and encryption to legacy systems already in the field. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ptjbq5cy7gpc7wvg/EP53FINAL.mp3" length="45126261" type="audio/mpeg"/>
        <itunes:summary>This is the story of how the security of OT devices in the field can be modernized virtual isolation in the cloud, adding both authentication and encryption into the mix. Bill Moore, founder and CEO of Xona, explains how you can virtualize the OT network and interact with it, adding 2FA and encryption to legacy systems already in the field.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1877</itunes:duration>
                <itunes:episode>54</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 52: Hacking Cellular-Enabled IoT Devices</title>
        <itunes:title>EP 52: Hacking Cellular-Enabled IoT Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-52-hacking-cellular-enabled-iot-devices/</link>
                    <comments>https://errorcode.podbean.com/e/ep-52-hacking-cellular-enabled-iot-devices/#comments</comments>        <pubDate>Tue, 17 Dec 2024 16:48:48 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/8e2ef9c8-ef5d-36e3-a9eb-f338ab20ed69</guid>
                                    <description><![CDATA[<p>This is the story of the secret life of cellular chips and why we need to mitigate against the unintended access they provide. Deral Heiland, Principal Security Research for IoT at <a href='https://www.rapid7.com/'>Rapid 7</a>, describes a research project he presented at the IoT Village at DEF CON 32 where they compiled AT command manuals from various vendors, discovering unexpected functionalities, such as internal web services.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is the story of the secret life of cellular chips and why we need to mitigate against the unintended access they provide. Deral Heiland, Principal Security Research for IoT at <a href='https://www.rapid7.com/'>Rapid 7</a>, describes a research project he presented at the IoT Village at DEF CON 32 where they compiled AT command manuals from various vendors, discovering unexpected functionalities, such as internal web services.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4z7pvndvigyb2dwt/EP52FINAL.mp3" length="54781118" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This is the story of the secret life of cellular chips and why we need to mitigate against the unintended access they provide. Deral Heiland, Principal Security Research for IoT at Rapid 7, describes a research project he presented at the IoT Village at DEF CON 32 where they compiled AT command manuals from various vendors, discovering unexpected functionalities, such as internal web services.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2279</itunes:duration>
                <itunes:episode>53</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 51: Hacking High-Performance Race Cars</title>
        <itunes:title>EP 51: Hacking High-Performance Race Cars</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-51-hacking-high-performance-race-cars/</link>
                    <comments>https://errorcode.podbean.com/e/ep-51-hacking-high-performance-race-cars/#comments</comments>        <pubDate>Tue, 03 Dec 2024 16:09:22 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/4e1b2163-4bab-35a5-ab4a-cc052f3e39b2</guid>
                                    <description><![CDATA[<p>When we think of IoT, we first think of our smart light bulbs, our smart TVs, our smart baby monitors. However, we don't typically associate IoT with high-performance race cars, and yet they collect terabytes of data each race. Austin Allen, Director of Solutions Architecture at <a href='https://www.airlockdigital.com/'>Airlock Digital</a>, discusses the growing presence of smart devices and the responsibility of securing them—should it be the developers who write the code, or the individuals who implement it?</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>When we think of IoT, we first think of our smart light bulbs, our smart TVs, our smart baby monitors. However, we don't typically associate IoT with high-performance race cars, and yet they collect terabytes of data each race. Austin Allen, Director of Solutions Architecture at <a href='https://www.airlockdigital.com/'>Airlock Digital</a>, discusses the growing presence of smart devices and the responsibility of securing them—should it be the developers who write the code, or the individuals who implement it?</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/nk2t7d34tzxki4u8/EP51FINAL.mp3" length="62922545" type="audio/mpeg"/>
        <itunes:summary><![CDATA[When we think of IoT, we first think of our smart light bulbs, our smart TVs, our smart baby monitors. However, we don't typically associate IoT with high-performance race cars, and yet they collect terabytes of data each race. Austin Allen, Director of Solutions Architecture at Airlock Digital, discusses the growing presence of smart devices and the responsibility of securing them—should it be the developers who write the code, or the individuals who implement it?]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2619</itunes:duration>
                <itunes:episode>52</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 50: Keeping The Lights On In Ukraine</title>
        <itunes:title>EP 50: Keeping The Lights On In Ukraine</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-50-keeping-the-lights-on-in-ukraine/</link>
                    <comments>https://errorcode.podbean.com/e/ep-50-keeping-the-lights-on-in-ukraine/#comments</comments>        <pubDate>Tue, 19 Nov 2024 15:06:39 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/2ea58fa6-30f7-3e55-9989-b2ea68ecbcfa</guid>
                                    <description><![CDATA[<p>What would happen if your GPS signal were jammed? It would impact more than just navigation – you'd also lose access to financial data and power. Joe Marshall, Senior IoT Strategist and Threat Researcher at <a href='https://talosintelligence.com/'>Cisco Talos</a>, discusses an innovative solution to maintain the country's power grid operations in the event of GPS jamming, whether it's a precautionary measure or an act of war.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What would happen if your GPS signal were jammed? It would impact more than just navigation – you'd also lose access to financial data and power. Joe Marshall, Senior IoT Strategist and Threat Researcher at <a href='https://talosintelligence.com/'>Cisco Talos</a>, discusses an innovative solution to maintain the country's power grid operations in the event of GPS jamming, whether it's a precautionary measure or an act of war.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/i89iufukfvnmw6ac/EP50FINAL.mp3" length="63616566" type="audio/mpeg"/>
        <itunes:summary><![CDATA[What would happen if your GPS signal were jammed? It would impact more than just navigation – you'd also lose access to financial data and power. Joe Marshall, Senior IoT Strategist and Threat Researcher at Cisco Talos, discusses an innovative solution to maintain the country's power grid operations in the event of GPS jamming, whether it's a precautionary measure or an act of war.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2647</itunes:duration>
                <itunes:episode>51</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 49: Hacking Android-Based ICS Devices</title>
        <itunes:title>EP 49: Hacking Android-Based ICS Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-49-hacking-android-based-ics-devices/</link>
                    <comments>https://errorcode.podbean.com/e/ep-49-hacking-android-based-ics-devices/#comments</comments>        <pubDate>Tue, 05 Nov 2024 14:35:40 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/5ffd74e0-8935-3840-9d29-b4710283cc7f</guid>
                                    <description><![CDATA[<p>Cybercriminal tactics against ICS include direct threats against individuals for MFA credentials, sometimes escalating to physical violence if they won’t share. Jim Coyle, US Public Sector CTO for <a href='https://www.lookout.com/'>Lookout</a>, warns about the increasing use of Android in critical Industrial Control Systems (ICS), such as HVAC systems, and how stealing MFA tokens from mobile devices could affect critical services like healthcare, finance, and water supply, depending on the goals of the attackers. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Cybercriminal tactics against ICS include direct threats against individuals for MFA credentials, sometimes escalating to physical violence if they won’t share. Jim Coyle, US Public Sector CTO for <a href='https://www.lookout.com/'>Lookout</a>, warns about the increasing use of Android in critical Industrial Control Systems (ICS), such as HVAC systems, and how stealing MFA tokens from mobile devices could affect critical services like healthcare, finance, and water supply, depending on the goals of the attackers. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/8mkykq7kt5g63ch8/EP49FINAL.mp3" length="56879482" type="audio/mpeg"/>
        <itunes:summary>Cybercriminal tactics against ICS include direct threats against individuals for MFA credentials, sometimes escalating to physical violence if they won’t share.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2367</itunes:duration>
                <itunes:episode>50</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 48: The New Insider Threat: Hacking Corporate Office Devices</title>
        <itunes:title>EP 48: The New Insider Threat: Hacking Corporate Office Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-48-the-new-insider-threat-hacking-corporate-office-devices/</link>
                    <comments>https://errorcode.podbean.com/e/ep-48-the-new-insider-threat-hacking-corporate-office-devices/#comments</comments>        <pubDate>Tue, 22 Oct 2024 14:49:56 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/c8cc36f0-8ea6-3938-bb1e-6591e885113a</guid>
                                    <description><![CDATA[<p>If smart buildings are vulnerable to hacking, what about smart offices? Even devices like printers and lighting systems could give an attacker a way in. John Terrill, CSO at <a href='https://phosphorus.io/'>Phosphorus</a>, recalls a moment while working at a hedge fund when he found himself in a room filled with priceless art. He realized that the security cameras safeguarding these artworks were operating on outdated software, potentially containing known vulnerabilities.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>If smart buildings are vulnerable to hacking, what about smart offices? Even devices like printers and lighting systems could give an attacker a way in. John Terrill, CSO at <a href='https://phosphorus.io/'>Phosphorus</a>, recalls a moment while working at a hedge fund when he found himself in a room filled with priceless art. He realized that the security cameras safeguarding these artworks were operating on outdated software, potentially containing known vulnerabilities.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/7psma8qtjf5xvjne/EP48FINAL.mp3" length="58912018" type="audio/mpeg"/>
        <itunes:summary><![CDATA[If smart buildings are vulnerable to hacking, what about smart offices? Even devices like printers and lighting systems could give an attacker a way in. John Terrill, CSO at Phosphorus, recalls a moment while working at a hedge fund when he found himself in a room filled with priceless art. He realized that the security cameras safeguarding these artworks were operating on outdated software, potentially containing known vulnerabilities.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2451</itunes:duration>
                <itunes:episode>49</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 47: Hacking Smart Buildings</title>
        <itunes:title>EP 47: Hacking Smart Buildings</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-47-hacking-smart-buildings/</link>
                    <comments>https://errorcode.podbean.com/e/ep-47-hacking-smart-buildings/#comments</comments>        <pubDate>Tue, 08 Oct 2024 14:01:23 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/7303c382-5c80-37f6-957e-bcaf9af1cbc9</guid>
                                    <description><![CDATA[<p>If you are in IT, you are probably not thinking about the risks associated with the Otis Elevator or the Coke machine. Maybe you should. Chester Wisnieski, the director and global field CTO at <a href='https://www.sophos.com/en-us'>Sophos</a>, points out that IoT devices, big and small, create an outsized threat to any organization. And that’s why IoT vendors need to secure these devices, even if they only “phone home” for more Coke. If they’re on your network, they need to be secured. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>If you are in IT, you are probably not thinking about the risks associated with the Otis Elevator or the Coke machine. Maybe you should. Chester Wisnieski, the director and global field CTO at <a href='https://www.sophos.com/en-us'>Sophos</a>, points out that IoT devices, big and small, create an outsized threat to any organization. And that’s why IoT vendors need to secure these devices, even if they only “phone home” for more Coke. If they’re on your network, they need to be secured. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kwup2qy49sbeqjnb/EP47FINAL.mp3" length="60398490" type="audio/mpeg"/>
        <itunes:summary><![CDATA[If you are in IT, you are probably not thinking about the risks associated with the Otis Elevator or the Coke machine. Maybe you should. Chester Wisnieski, the director and global field CTO at Sophos, points out that IoT devices, big and small, create an outsized threat to any organization. And that’s why IoT vendors need to secure these devices, even if they only “phone home” for more Coke. If they’re on your network, they need to be secured. ]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2513</itunes:duration>
                <itunes:episode>48</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 46: Hacking Israeli-made Water Treatment Devices In Pennsylvania</title>
        <itunes:title>EP 46: Hacking Israeli-made Water Treatment Devices In Pennsylvania</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-46-hacking-israeli-made-water-treatment-devices-in-pennsylvania/</link>
                    <comments>https://errorcode.podbean.com/e/ep-46-hacking-israeli-made-water-treatment-devices-in-pennsylvania/#comments</comments>        <pubDate>Tue, 24 Sep 2024 15:05:09 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/bd56aa88-cb2f-30b7-953d-0b127be36f83</guid>
                                    <description><![CDATA[<p>Political hacktivism once mainly focused on website defacement. Now it has shifted to targeting physical devices, affecting critical infrastructure such as water treatment plants. At Black Hat USA 2024, Noam Moshe from <a href='https://claroty.com/'>Claroty</a> highlighted how the HMIs in PLC devices from Israeli manufacturers may be susceptible to political attacks by nation-state actors using unknown vulnerabilities in the PComm protocol.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Political hacktivism once mainly focused on website defacement. Now it has shifted to targeting physical devices, affecting critical infrastructure such as water treatment plants. At Black Hat USA 2024, Noam Moshe from <a href='https://claroty.com/'>Claroty</a> highlighted how the HMIs in PLC devices from Israeli manufacturers may be susceptible to political attacks by nation-state actors using unknown vulnerabilities in the PComm protocol.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fs4j8p8shyw6iarw/EP46FINAL.mp3" length="48420824" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Political hacktivism once mainly focused on website defacement. Now it has shifted to targeting physical devices, affecting critical infrastructure such as water treatment plants. At Black Hat USA 2024, Noam Moshe from Claroty highlighted how the HMIs in PLC devices from Israeli manufacturers may be susceptible to political attacks by nation-state actors using unknown vulnerabilities in the PComm protocol.]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2014</itunes:duration>
                <itunes:episode>47</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 45: Laser Fault Injections on a Shoestring Budget</title>
        <itunes:title>EP 45: Laser Fault Injections on a Shoestring Budget</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-45-performing-laser-fault-injections-on-a-shoestring-budget/</link>
                    <comments>https://errorcode.podbean.com/e/ep-45-performing-laser-fault-injections-on-a-shoestring-budget/#comments</comments>        <pubDate>Tue, 10 Sep 2024 14:59:54 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/758fc32f-000d-3b8d-8268-9df5f2d92fe9</guid>
                                    <description><![CDATA[<p>What if you could build your own embedded security tools, glitching devices for a fraction of the cost that you might expect. Like having a $150,000 laser setup for less than $500. A talk at Black Hat USA 2024 says you can. Sam Beaumont (Panth13r), Director of Transportation, mobility and cyber physical systems at <a href='https://www.netspi.com/'>NetSPI</a>, and Larry Trowell (patch), Director of hardware embedded systems at <a href='https://www.netspi.com/'>NetSPI</a>, along with a team of others, say that you can. Their talk, Laser Beams &amp; Light Streams: Letting Hackers Go Pew Pew, Building Affordable Light-Based Hardware Security Tooling, should be a wake up call for all IoT and OT device vendors who should defend our IoT and OT devices, even against the unlikely attacks. Because soon enough, those attacks will become likely.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What if you could build your own embedded security tools, glitching devices for a fraction of the cost that you might expect. Like having a $150,000 laser setup for less than $500. A talk at Black Hat USA 2024 says you can. Sam Beaumont (Panth13r), Director of Transportation, mobility and cyber physical systems at <a href='https://www.netspi.com/'>NetSPI</a>, and Larry Trowell (patch), Director of hardware embedded systems at <a href='https://www.netspi.com/'>NetSPI</a>, along with a team of others, say that you can. Their talk, Laser Beams &amp; Light Streams: Letting Hackers Go Pew Pew, Building Affordable Light-Based Hardware Security Tooling, should be a wake up call for all IoT and OT device vendors who should defend our IoT and OT devices, even against the unlikely attacks. Because soon enough, those attacks will become likely.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4jubbpr2j3rshpm8/EP45FINAL.mp3" length="46997673" type="audio/mpeg"/>
        <itunes:summary>What if you could build your own embedded security tools, glitching devices for a fraction of the cost that you might expect. Like having a $150,000 laser setup for less than $500. A talk at Black Hat USA 2024 says you can.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1955</itunes:duration>
                <itunes:episode>46</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 44: Performing Security Assessments on ICS systems</title>
        <itunes:title>EP 44: Performing Security Assessments on ICS systems</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-44-performing-security-assessments-on-ics-systems/</link>
                    <comments>https://errorcode.podbean.com/e/ep-44-performing-security-assessments-on-ics-systems/#comments</comments>        <pubDate>Tue, 27 Aug 2024 15:33:48 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/2dc98b85-4029-3e01-a4b8-e35670f0203f</guid>
                                    <description><![CDATA[<p>Too few vulnerabilities in industrial control systems (ICS) are assigned CVEs because of client non-disclosure agreements. This results in repeatedly discovering the same vulnerabilities for different clients, especially in critical infrastructure. Don C. Weber from <a href='https://ioactive.com/'>IOActive</a> shares his experiences as an ICS security professional and suggests improvements, including following the SANS best practices for ICS security.. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Too few vulnerabilities in industrial control systems (ICS) are assigned CVEs because of client non-disclosure agreements. This results in repeatedly discovering the same vulnerabilities for different clients, especially in critical infrastructure. Don C. Weber from <a href='https://ioactive.com/'>IOActive</a> shares his experiences as an ICS security professional and suggests improvements, including following the SANS best practices for ICS security.. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/mgtsdiyfnd95rygv/EP44FINAL.mp3" length="49428315" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Too few vulnerabilities in industrial control systems (ICS) are assigned CVEs because of client non-disclosure agreements. This results in repeatedly discovering the same vulnerabilities for different clients, especially in critical infrastructure. Don C. Weber from IOActive shares his experiences as an ICS security professional and suggests improvements, including following the SANS best practices for ICS security.. ]]></itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2056</itunes:duration>
                <itunes:episode>45</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 43: Hacking Large-Scale Off-Grid Solar Systems and Other Consumer IoT Devices</title>
        <itunes:title>EP 43: Hacking Large-Scale Off-Grid Solar Systems and Other Consumer IoT Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-43-hacking-large-scale-off-grid-solar-systems-and-other-consumer-iot-devices/</link>
                    <comments>https://errorcode.podbean.com/e/ep-43-hacking-large-scale-off-grid-solar-systems-and-other-consumer-iot-devices/#comments</comments>        <pubDate>Tue, 13 Aug 2024 15:13:26 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/4000c5d9-abbd-3d91-9248-8703c7ca5b6a</guid>
                                    <description><![CDATA[<p>At DEF CON 32, in the ICS village, researchers disclosed vulnerabilities in home and commercial solar panel systems that could potentially disrupt the grid. Dan Berte, Director of IoT security for <a href='https://www.bitdefender.com/'>Bitdefender</a>, discusses his more than a decade in IoT, how the vendor maturity often isn’t there for our smart TVs or even for our solar panels, so reporting vulnerabilities sometimes goes nowhere. That doesn’t stop defenders like Dan, who, along with his team, work hard to change and to educate the industry.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>At DEF CON 32, in the ICS village, researchers disclosed vulnerabilities in home and commercial solar panel systems that could potentially disrupt the grid. Dan Berte, Director of IoT security for <a href='https://www.bitdefender.com/'>Bitdefender</a>, discusses his more than a decade in IoT, how the vendor maturity often isn’t there for our smart TVs or even for our solar panels, so reporting vulnerabilities sometimes goes nowhere. That doesn’t stop defenders like Dan, who, along with his team, work hard to change and to educate the industry.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ind7czw6i3f3mker/EP43FINAL.mp3" length="73157321" type="audio/mpeg"/>
        <itunes:summary>At DEF CON 32, in the ICS village, researchers disclosed vulnerabilities in home and commercial solar panel systems that could potentially disrupt the grid.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3045</itunes:duration>
                <itunes:episode>44</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 42: OT-CERT</title>
        <itunes:title>EP 42: OT-CERT</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-42-ot-cert/</link>
                    <comments>https://errorcode.podbean.com/e/ep-42-ot-cert/#comments</comments>        <pubDate>Tue, 30 Jul 2024 16:51:44 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/eba571ed-2dc6-3ffe-b1ab-904f577e08ce</guid>
                                    <description><![CDATA[<p>The resources available at small utilities are scarce, and that’s a big problem because small water, gas, and electric facilities are increasingly under attack. Dawn Capelli of <a href='https://www.dragos.com/'>Dragos</a> is the Director of OT-CERT, an independent organization that provides free resources to educate and even protect small and medium sized utilities from attack.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The resources available at small utilities are scarce, and that’s a big problem because small water, gas, and electric facilities are increasingly under attack. Dawn Capelli of <a href='https://www.dragos.com/'>Dragos</a> is the Director of OT-CERT, an independent organization that provides free resources to educate and even protect small and medium sized utilities from attack.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/gi3m2eiwerusw6mq/EP42FINAL.mp3" length="49590692" type="audio/mpeg"/>
        <itunes:summary>The resources available at small utilities are scarce, and that’s a big problem because small water, gas, and electric facilities are increasingly under attack.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2063</itunes:duration>
                <itunes:episode>43</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 41: Firmware SBOMs, Zero Trust, And IoT Truth Bombs</title>
        <itunes:title>EP 41: Firmware SBOMs, Zero Trust, And IoT Truth Bombs</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-41-firmware-sboms-zero-trust-and-iot-truth-bombs/</link>
                    <comments>https://errorcode.podbean.com/e/ep-41-firmware-sboms-zero-trust-and-iot-truth-bombs/#comments</comments>        <pubDate>Tue, 16 Jul 2024 13:43:33 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/5d934158-f5b7-30ea-9f73-db48dcbb35f1</guid>
                                    <description><![CDATA[<p>For the last twenty years we’ve invested in software security without parallel development in firmware security. Why is that? Tom Pace, co-founder and CEO of <a href='https://www.netrise.io/'>NetRise</a>, returns to Error Code to discuss the need for firmware software bills of materials, and why Zero Trust is a great idea yet so poorly implemented. As in Episode 30, Tom is a straight shooter, imparting necessary truth bombs about our industry. Fortunately he’s optimistic about our future.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>For the last twenty years we’ve invested in software security without parallel development in firmware security. Why is that? Tom Pace, co-founder and CEO of <a href='https://www.netrise.io/'>NetRise</a>, returns to Error Code to discuss the need for firmware software bills of materials, and why Zero Trust is a great idea yet so poorly implemented. As in Episode 30, Tom is a straight shooter, imparting necessary truth bombs about our industry. Fortunately he’s optimistic about our future.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/xw9nwvxrajkfvaby/EP41FINAL.mp3" length="59744593" type="audio/mpeg"/>
        <itunes:summary>For the last twenty years we’ve invested in software security without parallel development in firmware security. Why is that?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2486</itunes:duration>
                <itunes:episode>42</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 40: Hacking IoT Surveillance Cameras For Espionage Operations</title>
        <itunes:title>EP 40: Hacking IoT Surveillance Cameras For Espionage Operations</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-40-hacking-iot-surveillance-cameras-for-espionage-operations/</link>
                    <comments>https://errorcode.podbean.com/e/ep-40-hacking-iot-surveillance-cameras-for-espionage-operations/#comments</comments>        <pubDate>Tue, 02 Jul 2024 11:31:35 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/32c2dc1b-a607-399f-aa01-f21b9729a0b2</guid>
                                    <description><![CDATA[<p>That camera above your head might not seem like a good foreign target, yet in the Ukraine there’s evidence of Russian-backed hackers passively counting the number of foreign aid workers at the local train stations. Andrew Hural of <a href='https://underdefense.com/'>UnderDefense</a> talks about the need to secure everything around a person, everything around an organization, and everything around a nation because every one can be a target.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>That camera above your head might not seem like a good foreign target, yet in the Ukraine there’s evidence of Russian-backed hackers passively counting the number of foreign aid workers at the local train stations. Andrew Hural of <a href='https://underdefense.com/'>UnderDefense</a> talks about the need to secure everything around a person, everything around an organization, and everything around a nation because every one can be a target.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/7r2i8uuy7fdajzzp/EP40FINAL.mp3" length="41043636" type="audio/mpeg"/>
        <itunes:summary>That camera above your head might not seem like a good foreign target, yet in the Ukraine there’s evidence of Russian-backed hackers passively counting the number of foreign aid workers at the local train stations.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1707</itunes:duration>
                <itunes:episode>41</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 39: Hacking Water Systems and the OT Skills Gap</title>
        <itunes:title>EP 39: Hacking Water Systems and the OT Skills Gap</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-39-hacking-water-systems-and-the-ot-skills-gap/</link>
                    <comments>https://errorcode.podbean.com/e/ep-39-hacking-water-systems-and-the-ot-skills-gap/#comments</comments>        <pubDate>Tue, 18 Jun 2024 15:40:23 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/29e25368-f452-3c42-a54c-b2008762f6c8</guid>
                                    <description><![CDATA[<p>A critical skills gap in Operational Technology security could have a real effect on your water supply and other areas of the critical infrastructures. Christopher Walcutt from <a href='https://www.directdefense.com/'>DirectDefense</a> explains how the IT OT convergence, and the lack of understanding of what OT systems are, might be contributing to the spate of water systems attacks in 2024. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>A critical skills gap in Operational Technology security could have a real effect on your water supply and other areas of the critical infrastructures. Christopher Walcutt from <a href='https://www.directdefense.com/'>DirectDefense</a> explains how the IT OT convergence, and the lack of understanding of what OT systems are, might be contributing to the spate of water systems attacks in 2024. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/s29fs7nqpfjvwfg9/EP39FINAL.mp3" length="58147153" type="audio/mpeg"/>
        <itunes:summary>A critical skills gap in Operational Technology security could have a real effect on your water supply and other areas of the critical infrastructures.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2420</itunes:duration>
                <itunes:episode>40</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 38: Regulating OT Data Breaches And Ransomware Reporting</title>
        <itunes:title>EP 38: Regulating OT Data Breaches And Ransomware Reporting</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-38-regulating-ot-data-breaches-and-ransomware-reporting/</link>
                    <comments>https://errorcode.podbean.com/e/ep-38-regulating-ot-data-breaches-and-ransomware-reporting/#comments</comments>        <pubDate>Tue, 04 Jun 2024 11:54:21 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/6a90de07-582c-3724-b4cf-9391cc33eec6</guid>
                                    <description><![CDATA[<p>When critical infrastructure is shut down due to ransomware or some other malicious attack, who gets notified and when? Chris Warner, from <a href='https://www.guidepointsecurity.com/'>GuidePoint Security</a>, discusses the upcoming Cyber Incident Reporting for Critical Infrastructure Act or CIRCIA and what it will mean for critical infrastructure organizations.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>When critical infrastructure is shut down due to ransomware or some other malicious attack, who gets notified and when? Chris Warner, from <a href='https://www.guidepointsecurity.com/'>GuidePoint Security</a>, discusses the upcoming Cyber Incident Reporting for Critical Infrastructure Act or CIRCIA and what it will mean for critical infrastructure organizations.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ubjc7dbis2m6wuif/EP38FINAL.mp3" length="61753304" type="audio/mpeg"/>
        <itunes:summary>When critical infrastructure is shut down due to ransomware or some other malicious attack. Who gets notified when? And does that help or hinder trying to keep the systems back up and running?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2570</itunes:duration>
                <itunes:episode>39</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 37: Solving Mysteries. Saving Lives. Just Another Day with OT Incident Response and Forensics</title>
        <itunes:title>EP 37: Solving Mysteries. Saving Lives. Just Another Day with OT Incident Response and Forensics</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-37-solving-mysteries-saving-lives-just-another-day-with-ot-incident-response-and-forensics/</link>
                    <comments>https://errorcode.podbean.com/e/ep-37-solving-mysteries-saving-lives-just-another-day-with-ot-incident-response-and-forensics/#comments</comments>        <pubDate>Tue, 21 May 2024 16:02:16 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/8e9e2af0-e61a-3b86-baf9-3aa8a8095c4a</guid>
                                    <description><![CDATA[<p>When an enterprise network goes down, you call in the Incident Response team and they do forensics. When your SCADA goes down, who do you call? Meet Lesley Carhart, technical director of incident response at <a href='https://www.dragos.com/'>Dragos</a>, who focuses on products and services for the non standard part of cybersecurity. That means things like performing digital forensics on SCADA, industrial control systems, and critical infrastructure. There’s still some normal enterprise computing involved, but very often the stories told by practitioners are … well, just plain weird. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>When an enterprise network goes down, you call in the Incident Response team and they do forensics. When your SCADA goes down, who do you call? Meet Lesley Carhart, technical director of incident response at <a href='https://www.dragos.com/'>Dragos</a>, who focuses on products and services for the non standard part of cybersecurity. That means things like performing digital forensics on SCADA, industrial control systems, and critical infrastructure. There’s still some normal enterprise computing involved, but very often the stories told by practitioners are … well, just plain weird. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cnynmfmvncd3ybbp/EP37FINAL.mp3" length="60676224" type="audio/mpeg"/>
        <itunes:summary>When an enterprise network goes down, you call in the Incident Response team and they do forensics. When your SCADA goes down, who do you call? Meet Lesley Carthart, technical director of incident response at Dragos.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2525</itunes:duration>
                <itunes:episode>38</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 36: Securing SCADA Systems In The Cloud</title>
        <itunes:title>EP 36: Securing SCADA Systems In The Cloud</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-36-securing-scada-systems-in-the-cloud/</link>
                    <comments>https://errorcode.podbean.com/e/ep-36-securing-scada-systems-in-the-cloud/#comments</comments>        <pubDate>Tue, 07 May 2024 09:53:58 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/84576f44-cfb2-3526-89f5-7a32060b9f0e</guid>
                                    <description><![CDATA[<p>This is a story about how organizations are moving their SCADA systems to the cloud and how they need to secure them or they’ll be attacked. Chris Doman, co-founder and CTO of Cado Security discusses the new NSC guidelines on SCADA in the Cloud and whether the guidelines are prescriptive enough.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is a story about how organizations are moving their SCADA systems to the cloud and how they need to secure them or they’ll be attacked. Chris Doman, co-founder and CTO of Cado Security discusses the new NSC guidelines on SCADA in the Cloud and whether the guidelines are prescriptive enough.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2ekugpgwgvsaneim/EP36FINAL.mp3" length="37556602" type="audio/mpeg"/>
        <itunes:summary>This is a story about how organizations are moving their SCADA systems to the cloud and how they need to secure them or they’ll be attacked.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1562</itunes:duration>
                <itunes:episode>37</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 35: Outsized Kinetic Response to OT Attacks</title>
        <itunes:title>EP 35: Outsized Kinetic Response to OT Attacks</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-35-outsized-kinetic-response-to-ot-attacks/</link>
                    <comments>https://errorcode.podbean.com/e/ep-35-outsized-kinetic-response-to-ot-attacks/#comments</comments>        <pubDate>Tue, 23 Apr 2024 13:23:42 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/97129a96-dbdf-36c9-9491-88c2d94c698a</guid>
                                    <description><![CDATA[<p>If you knock down an email server, you could stand up a parallel server or you could find workarounds. If you knock down a factory floor, there is no real parallel, alternative to a factory floor.  Dane Grace, product manager at <a href='https://www.brinqa.com/'>Brinqa</a> talks about how the risks to OT carries with it an outsized kinetic response in the real world. For example, what would happen if someone managed to put a botnet on a defibrillator?</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>If you knock down an email server, you could stand up a parallel server or you could find workarounds. If you knock down a factory floor, there is no real parallel, alternative to a factory floor.  Dane Grace, product manager at <a href='https://www.brinqa.com/'>Brinqa</a> talks about how the risks to OT carries with it an outsized kinetic response in the real world. For example, what would happen if someone managed to put a botnet on a defibrillator?</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rjgm5i9xvphzzegb/EP35FINAL.mp3" length="56544697" type="audio/mpeg"/>
        <itunes:summary>If you knock down an email server, you could stand up a parallel server or you could find workarounds. If you knock down a factory floor, there is no real parallel, alternative to a factory floor.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2353</itunes:duration>
                <itunes:episode>36</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 34: Quantifying Risk in IoT and OT Systems</title>
        <itunes:title>EP 34: Quantifying Risk in IoT and OT Systems</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-34-assessing-cyber-risk-in-ot-systems/</link>
                    <comments>https://errorcode.podbean.com/e/ep-34-assessing-cyber-risk-in-ot-systems/#comments</comments>        <pubDate>Tue, 09 Apr 2024 15:03:32 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/a5990c5a-9448-347a-8057-9e1617b1bbc9</guid>
                                    <description><![CDATA[<p>One of the problems with security is ROI. If I put in next gen this and next gen that and no security events happen, am I justified in making those expenditures? How do you quantify a risk like that?  Padraic O’Reilly, founder and Chief Innovation Officer at CyberSaint, walks us through the risk analysis for IoT and OT systems, and why it’s important to understand this as we secure our critical infrastructure.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>One of the problems with security is ROI. If I put in next gen this and next gen that and no security events happen, am I justified in making those expenditures? How do you quantify a risk like that?  Padraic O’Reilly, founder and Chief Innovation Officer at CyberSaint, walks us through the risk analysis for IoT and OT systems, and why it’s important to understand this as we secure our critical infrastructure.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/w32rfp/EP34FINAL1.mp3" length="58735221" type="audio/mpeg"/>
        <itunes:summary>One of the problems with security is ROI. If I put in next gen this and next gen that and no security events happen, am I justified in making those expenditures? How do you quantify a risk like that?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2444</itunes:duration>
                <itunes:episode>35</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 33: Turning EDRs and Cloud Backups into Malicious Wipers</title>
        <itunes:title>EP 33: Turning EDRs and Cloud Backups into Malicious Wipers</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-33-turning-edrs-and-cloud-backups-to-malicious-wipers/</link>
                    <comments>https://errorcode.podbean.com/e/ep-33-turning-edrs-and-cloud-backups-to-malicious-wipers/#comments</comments>        <pubDate>Tue, 26 Mar 2024 10:19:04 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/80d162b9-a362-3ae5-85ea-76cf24494877</guid>
                                    <description><![CDATA[<p>This is the story of how a researcher turns commercial and commonly used EDRs and Cloud-based backup systems into wipers against the very data they’re designed to protect. Or Yair, security research team lead at Safe Breach, talks about his two presentations at SecTor 2023 that consider how to turn common security tools into potentially malicious weapons. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is the story of how a researcher turns commercial and commonly used EDRs and Cloud-based backup systems into wipers against the very data they’re designed to protect. Or Yair, security research team lead at Safe Breach, talks about his two presentations at SecTor 2023 that consider how to turn common security tools into potentially malicious weapons. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/zqijnd/EP33FINAL.mp3" length="47319920" type="audio/mpeg"/>
        <itunes:summary>This is the story of how a researcher turns commercial and commonly used EDRs and Cloud-based backup systems into wipers against the very data they’re designed to protect.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1968</itunes:duration>
                <itunes:episode>34</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 32: Using ChatGPT To Perform Side Channel Attacks On Real Hardware</title>
        <itunes:title>EP 32: Using ChatGPT To Perform Side Channel Attacks On Real Hardware</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-32-using-chatgpt-to-perform-side-channel-attacks-on-real-hardware/</link>
                    <comments>https://errorcode.podbean.com/e/ep-32-using-chatgpt-to-perform-side-channel-attacks-on-real-hardware/#comments</comments>        <pubDate>Tue, 12 Mar 2024 17:03:15 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/ccf96d53-1393-3e59-938a-6c96e40d9498</guid>
                                    <description><![CDATA[<p>There’s a lot of talk about using AI and LLM in security. For example, could ChatGPT detect the vulnerable spots for power for analysis in particular pieces of code using Advanced Encryption Standard?  Witold Waligora, CEO of CloudVA, talks about his Black Hat Europe presentation, How We Taught ChatGPT-4 to Break mbedTLS AES With Side-Channel Attacks. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>There’s a lot of talk about using AI and LLM in security. For example, could ChatGPT detect the vulnerable spots for power for analysis in particular pieces of code using Advanced Encryption Standard?  Witold Waligora, CEO of CloudVA, talks about his Black Hat Europe presentation, How We Taught ChatGPT-4 to Break mbedTLS AES With Side-Channel Attacks. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/timt5k/EP32FINAL.mp3" length="44616560" type="audio/mpeg"/>
        <itunes:summary>There’s a lot of talk about using AI and LLM in security. For example, could ChatGPT detect the vulnerable spots for power for analysis in particular pieces of code using Advanced Encryption Standard?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1856</itunes:duration>
                <itunes:episode>33</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 31: How Operation Volt Typhoon Shows That IoT &amp; OT Devices Could Be Used In Cyberwarfare</title>
        <itunes:title>EP 31: How Operation Volt Typhoon Shows That IoT &amp; OT Devices Could Be Used In Cyberwarfare</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-31-how-operation-volt-typhoon-shows-that-iot-ot-devices-could-be-used-in-cyberwarfare/</link>
                    <comments>https://errorcode.podbean.com/e/ep-31-how-operation-volt-typhoon-shows-that-iot-ot-devices-could-be-used-in-cyberwarfare/#comments</comments>        <pubDate>Tue, 27 Feb 2024 15:10:37 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/0ec71e1f-e69d-3870-bcb0-761db61520f3</guid>
                                    <description><![CDATA[<p>You might think that internet connected cameras would be limited in use by a bad actor. Actually such devices can be an entry point into an organization, providing yet another means of accessing the internal network. Mohammad Waqas, a field CTO at Armis, spoke at SecTor 2023 about the threat posed by IoT and OT devices in future cyberwarfare and discusses here why we need to broaden our attack surface defenses to include them.  </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>You might think that internet connected cameras would be limited in use by a bad actor. Actually such devices can be an entry point into an organization, providing yet another means of accessing the internal network. Mohammad Waqas, a field CTO at Armis, spoke at SecTor 2023 about the threat posed by IoT and OT devices in future cyberwarfare and discusses here why we need to broaden our attack surface defenses to include them.  </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/332ux8/EP31FINAL.mp3" length="62738852" type="audio/mpeg"/>
        <itunes:summary>You might think that internet connected cameras would be limited in use by a bad actor. Actually such devices can be an entry point into an organization, providing yet another means of accessing the internal network.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2611</itunes:duration>
                <itunes:episode>32</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 30: Of IoT Vulnerabilities and Consumer IoT Labels</title>
        <itunes:title>EP 30: Of IoT Vulnerabilities and Consumer IoT Labels</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-30-of-iot-vulnerabilities-and-consumer-iot-labels/</link>
                    <comments>https://errorcode.podbean.com/e/ep-30-of-iot-vulnerabilities-and-consumer-iot-labels/#comments</comments>        <pubDate>Tue, 13 Feb 2024 15:05:43 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/661a60c9-25ff-3615-8898-bd5df499de0e</guid>
                                    <description><![CDATA[<p>There’s a fake news report about three million internet-enabled toothbrushes contributing to a botnet. Unfortunately the mainstream media ran with the story before questioning its basic assumptions. This is a story about IoT devices and the fact that we still don’t understand how they are vulnerable. Tom Pace, co-founder and CEO of <a href='https://www.netrise.io/'>NetRise</a>, talks about vulnerabilities inherent in the IoT space that are often misconstrued and how we need to ask more questions about the software and the hardware being used if we want to secure critical infrastructure tomorrow.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>There’s a fake news report about three million internet-enabled toothbrushes contributing to a botnet. Unfortunately the mainstream media ran with the story before questioning its basic assumptions. This is a story about IoT devices and the fact that we still don’t understand how they are vulnerable. Tom Pace, co-founder and CEO of <a href='https://www.netrise.io/'>NetRise</a>, talks about vulnerabilities inherent in the IoT space that are often misconstrued and how we need to ask more questions about the software and the hardware being used if we want to secure critical infrastructure tomorrow.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9q5n9y/EP30FINAL.mp3" length="63181471" type="audio/mpeg"/>
        <itunes:summary>There’s a fake new report about three million internet-enabled toothbrushes contributing to a botnet. Unfortunately the mainstream media ran with the story before questioning its basic assumptions.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2629</itunes:duration>
                <itunes:episode>31</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcodelogo_4c3bvb.png" />    </item>
    <item>
        <title>EP 29: The Rise of Smash and Grab Data Exfiltration</title>
        <itunes:title>EP 29: The Rise of Smash and Grab Data Exfiltration</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-29-the-rise-of-smash-and-grab-data-exfiltration/</link>
                    <comments>https://errorcode.podbean.com/e/ep-29-the-rise-of-smash-and-grab-data-exfiltration/#comments</comments>        <pubDate>Tue, 30 Jan 2024 11:55:57 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/95c040d7-c1be-3b04-9b8b-ccec1d101786</guid>
                                    <description><![CDATA[<p>Ransomware groups have bifurcated with some doing pure ransomware and others going straight to extortion; it's whether the data is ransomed on your network or theirs. Nick Biasini from <a href='https://blog.talosintelligence.com/sapphirestealer-goes-open-source/'>Cisco Talos</a> talks about the threats he’s seeing, in particular, SapphireStealer which is open source and using GitHub to crowdsource new features. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Ransomware groups have bifurcated with some doing pure ransomware and others going straight to extortion; it's whether the data is ransomed on your network or theirs. Nick Biasini from <a href='https://blog.talosintelligence.com/sapphirestealer-goes-open-source/'>Cisco Talos</a> talks about the threats he’s seeing, in particular, SapphireStealer which is open source and using GitHub to crowdsource new features. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/gt6jcd/EP29FINAL.mp3" length="52144214" type="audio/mpeg"/>
        <itunes:summary>Ransomware groups have bifurcated with doing pure ransomware and others going straight to extortion; it’s whether the data is ransomed on your network or theirs.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2169</itunes:duration>
                <itunes:episode>30</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 28: Why Mapping IT Security to OT Networks Doesn’t Always Work</title>
        <itunes:title>EP 28: Why Mapping IT Security to OT Networks Doesn’t Always Work</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-28-why-mapping-it-security-to-ot-networks-doesn-t-always-work/</link>
                    <comments>https://errorcode.podbean.com/e/ep-28-why-mapping-it-security-to-ot-networks-doesn-t-always-work/#comments</comments>        <pubDate>Tue, 16 Jan 2024 15:26:48 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/a468491c-3a80-3844-8452-9c30becc397f</guid>
                                    <description><![CDATA[<p>The Purdue Model used in OT is essentially network security from the 1990s. New threats and new tech however required us to rethink that on the network side so how do we bring that new thinking to work with legacy OT systems? John Taylor of <a href='https://versa-networks.com/'>Versa Networks</a> explains how there's a lot of implicit trust in the IoT and OT devices themselves, yet they don't have antivirus. Or firewalls. Worse, you're basically depending on the manufacturer of that device to provide security updates if necessary, and oftentimes they don't. Perhaps it’s time for a new approach such as SASE or secure access service edge.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The Purdue Model used in OT is essentially network security from the 1990s. New threats and new tech however required us to rethink that on the network side so how do we bring that new thinking to work with legacy OT systems? John Taylor of <a href='https://versa-networks.com/'>Versa Networks</a> explains how there's a lot of implicit trust in the IoT and OT devices themselves, yet they don't have antivirus. Or firewalls. Worse, you're basically depending on the manufacturer of that device to provide security updates if necessary, and oftentimes they don't. Perhaps it’s time for a new approach such as SASE or secure access service edge.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pqbi6d/EP28FINAL.mp3" length="61234199" type="audio/mpeg"/>
        <itunes:summary>The Purdue Model used in OT is essentially network security from the 1990s. New threats and new tech however required us to rethink that on the network side so how do we bring that new thinking to work with legacy OT system?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2548</itunes:duration>
                <itunes:episode>29</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 27:  Cyber Physical Security As A Shared Responsibility</title>
        <itunes:title>EP 27:  Cyber Physical Security As A Shared Responsibility</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-27-cyber-physical-security-as-a-shared-responsibility/</link>
                    <comments>https://errorcode.podbean.com/e/ep-27-cyber-physical-security-as-a-shared-responsibility/#comments</comments>        <pubDate>Fri, 05 Jan 2024 10:10:12 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/46bf3988-f958-36c3-a280-a5b36057eb61</guid>
                                    <description><![CDATA[<p>Flaws within the chips in our laptops, in our homes, and in our critical infrastructure could become the access one needs to steal data if not just shut down an assembly line, or hold up production of a vital resource like power or water. Josh Salmanson, senior vice president at <a href='https://www.telos.com/'>Telos</a>, discusses why we’re seeing more and more pre-compromised routers in critical environments today and what we might do to mitigate that in the near future.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Flaws within the chips in our laptops, in our homes, and in our critical infrastructure could become the access one needs to steal data if not just shut down an assembly line, or hold up production of a vital resource like power or water. Josh Salmanson, senior vice president at <a href='https://www.telos.com/'>Telos</a>, discusses why we’re seeing more and more pre-compromised routers in critical environments today and what we might do to mitigate that in the near future.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/be7mz3/EP27FINAL.mp3" length="50714793" type="audio/mpeg"/>
        <itunes:summary>Flaws within the chips in our laptops, in our homes, and in our critical infrastructure could become the access one needs to steal data if not just shut down an assembly line, or hold up production of a vital resource like power or water.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2110</itunes:duration>
                <itunes:episode>28</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 26: Securing Railroad OT Systems</title>
        <itunes:title>EP 26: Securing Railroad OT Systems</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-26-securing-railroad-ot-systems/</link>
                    <comments>https://errorcode.podbean.com/e/ep-26-securing-railroad-ot-systems/#comments</comments>        <pubDate>Tue, 19 Dec 2023 16:22:12 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/526c23b4-1692-3684-a4d0-7cba8c1903d1</guid>
                                    <description><![CDATA[<p>Can your OT function if the IT system goes down? OT self-sufficiency is critical for infrastructure such as rail systems. Christopher Warner, from <a href='https://www.guidepointsecurity.com/'>GuidePoint Security</a>, discusses how this infrastructure resilience is important not only for the rail industry but for most of the other critical infrastructures in general. </p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Can your OT function if the IT system goes down? OT self-sufficiency is critical for infrastructure such as rail systems. Christopher Warner, from <a href='https://www.guidepointsecurity.com/'>GuidePoint Security</a>, discusses how this infrastructure resilience is important not only for the rail industry but for most of the other critical infrastructures in general. </p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/yg4k87/EP26FINAL.mp3" length="60860544" type="audio/mpeg"/>
        <itunes:summary>Can your OT function if the IT system goes down? OT self-sufficiency is critical for infrastructure such as rail systems.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2533</itunes:duration>
                <itunes:episode>27</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 25: Crypto Agility And The End Of Diffie Hellman Key Exchange</title>
        <itunes:title>EP 25: Crypto Agility And The End Of Diffie Hellman Key Exchange</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-25-crypto-agility-and-the-end-of-diffie-hellman-key-exchange/</link>
                    <comments>https://errorcode.podbean.com/e/ep-25-crypto-agility-and-the-end-of-diffie-hellman-key-exchange/#comments</comments>        <pubDate>Tue, 05 Dec 2023 15:41:54 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/38e3bae0-f0f2-315e-887a-bfc03e34bb58</guid>
                                    <description><![CDATA[<p>Quantum computers will change and even break the cryptography we have today. To defeat a "Harvest Now, Decrypt Later" strategy by bad actors (even nation states), Denis Mandich, CTO and co-founder of <a href='https://www.qrypt.com/'>Qrypt</a>, is proposing a type of crypto agility that compiles the keys on your laptop instead of distributing them across the internet. He also talks about how you won’t need a quantum computer in your home; you’ll be able to access one in the cloud the way you can access AWS today.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Quantum computers will change and even break the cryptography we have today. To defeat a "Harvest Now, Decrypt Later" strategy by bad actors (even nation states), Denis Mandich, CTO and co-founder of <a href='https://www.qrypt.com/'>Qrypt</a>, is proposing a type of crypto agility that compiles the keys on your laptop instead of distributing them across the internet. He also talks about how you won’t need a quantum computer in your home; you’ll be able to access one in the cloud the way you can access AWS today.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wrpnzt/EP25FINAL.mp3" length="56014934" type="audio/mpeg"/>
        <itunes:summary>Quantum computers will change and even break the cryptography we have today. To defeat a ”Harvest Now, Decrypt Later” strategy by bad actors (even nation states), Denis Mandich, CTO and co-founder of Qrypt, is proposing a type of crypto agility that compiles the keys on your laptop instead of distributing them across the internet.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2331</itunes:duration>
                <itunes:episode>26</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 24: Securing OT Devices In The Field</title>
        <itunes:title>EP 24: Securing OT Devices In The Field</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-24-securing-ot-devices-in-the-field/</link>
                    <comments>https://errorcode.podbean.com/e/ep-24-securing-ot-devices-in-the-field/#comments</comments>        <pubDate>Thu, 26 Oct 2023 13:20:49 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/be396562-1a90-3ce2-9780-bcff715b301d</guid>
                                    <description><![CDATA[<p>When we think of massive compute power, we think of the Cloud when we really should consider the millions of unprotected OT devices with even greater slack computer power than all our current Cloud services combined. Sonu Shankar, Vice President of Product at <a href='https://phosphorus.io/'>Phosphorus Cybersecurity</a>, talks about the challenge of communicating with PLCs and other devices, the risks from newer OT devices, and how all password-less OT devices really need to be protected. He says attacks aren’t just DDoS; today OT attacks can exfiltrate data as well.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>When we think of massive compute power, we think of the Cloud when we really should consider the millions of unprotected OT devices with even greater slack computer power than all our current Cloud services combined. Sonu Shankar, Vice President of Product at <a href='https://phosphorus.io/'>Phosphorus Cybersecurity</a>, talks about the challenge of communicating with PLCs and other devices, the risks from newer OT devices, and how all password-less OT devices really need to be protected. He says attacks aren’t just DDoS; today OT attacks can exfiltrate data as well.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4esavt/EP24FINAL.mp3" length="63537572" type="audio/mpeg"/>
        <itunes:summary>When we think of massive compute power, we think of the Cloud when we really should consider the millions of unprotected OT devices with even greater slack computer power that our current cloud services combined.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2644</itunes:duration>
                <itunes:episode>25</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 23: Hacking Wireless</title>
        <itunes:title>EP 23: Hacking Wireless</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-23-hacking-wireless/</link>
                    <comments>https://errorcode.podbean.com/e/ep-23-hacking-wireless/#comments</comments>        <pubDate>Tue, 26 Sep 2023 15:31:58 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/0994eda0-dd53-318e-a7d7-54f6db37c07d</guid>
                                    <description><![CDATA[<p>There’s much of the electromagnetic spectrum that we cannot see. Like how LED wristbands are triggered at concerts or how to identify someone at DEF CON in a crowd of cellphones and electrical devices. Eric Escobar of <a href='https://www.secureworks.com/'>SecureWorks</a> provides some really clear analogies to help anyone visualize the differences between NFC, Bluetooth, and Wi Fi such as how your router and your microwave are both 2.4GHz - the difference is the number of watts behind each signal.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>There’s much of the electromagnetic spectrum that we cannot see. Like how LED wristbands are triggered at concerts or how to identify someone at DEF CON in a crowd of cellphones and electrical devices. Eric Escobar of <a href='https://www.secureworks.com/'>SecureWorks</a> provides some really clear analogies to help anyone visualize the differences between NFC, Bluetooth, and Wi Fi such as how your router and your microwave are both 2.4GHz - the difference is the number of watts behind each signal.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/p2b4f2/EP23FINAL.mp3" length="62877406" type="audio/mpeg"/>
        <itunes:summary>There’s much of the electromagnetic spectrum that we cannot see. Like how LED wristbands are triggered at concerts or how to identify someone at DEF CON in a crowd of cellphones and electrical devices.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2617</itunes:duration>
                <itunes:episode>24</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 22:  Applying Zero Trust to OT Systems</title>
        <itunes:title>EP 22:  Applying Zero Trust to OT Systems</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-22-applying-zero-trust-to-ot-systems/</link>
                    <comments>https://errorcode.podbean.com/e/ep-22-applying-zero-trust-to-ot-systems/#comments</comments>        <pubDate>Tue, 12 Sep 2023 12:58:09 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/2462fae4-e00d-376d-b470-9ae7837ed8ad</guid>
                                    <description><![CDATA[<p>How might we mitigate the risk to millions of unauthenticated devices already out in the field?  Ron Fabela, Field CTO at <a href='https://www.xonasystems.com/'>XONA Systems</a>, has some ideas about how to achieve zero trust in either legacy or new OT systems. Really, it’s just a matter of reducing the attack surface. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>How might we mitigate the risk to millions of unauthenticated devices already out in the field?  Ron Fabela, Field CTO at <a href='https://www.xonasystems.com/'>XONA Systems</a>, has some ideas about how to achieve zero trust in either legacy or new OT systems. Really, it’s just a matter of reducing the attack surface. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/bfjf4v/EP22FINAL.mp3" length="64898029" type="audio/mpeg"/>
        <itunes:summary>How might we mitigate the risk to millions of unauthenticated devices already out in the field?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2701</itunes:duration>
                <itunes:episode>23</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 21: Exploiting OPC-UA in OT Environments</title>
        <itunes:title>EP 21: Exploiting OPC-UA in OT Environments</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-21-exploiting-opc-ua-in-ot-environments/</link>
                    <comments>https://errorcode.podbean.com/e/ep-21-exploiting-opc-ua-in-ot-environments/#comments</comments>        <pubDate>Wed, 16 Aug 2023 09:29:15 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/6c86c89e-9600-3015-97ae-6d3eb5c3a49e</guid>
                                    <description><![CDATA[<p>In a talk at <a href='https://www.blackhat.com/us-23/'>Black Hat USA 2023</a>, Sharon Brizinov and Noam Moshe from <a href='https://claroty.com/team82'>Claroty Team82</a>, disclosed a significant vulnerability in the Open Platform Communications Universal Architecture or OPC-UA, a univsersal protocol used to synchronize different OT devices. In this episode they also discuss a new open source OPC exploit framework designed to help OT vendors check their devices in development.</p>
<p><a href='https://medium.com/@robvamosi/exploiting-opc-ua-in-ot-environments-f5c0be630c14'>Transcript</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In a talk at <a href='https://www.blackhat.com/us-23/'>Black Hat USA 2023</a>, Sharon Brizinov and Noam Moshe from <a href='https://claroty.com/team82'>Claroty Team82</a>, disclosed a significant vulnerability in the Open Platform Communications Universal Architecture or OPC-UA, a univsersal protocol used to synchronize different OT devices. In this episode they also discuss a new open source OPC exploit framework designed to help OT vendors check their devices in development.</p>
<p><a href='https://medium.com/@robvamosi/exploiting-opc-ua-in-ot-environments-f5c0be630c14'>Transcript</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2qwn2r/EP21FINAL.mp3" length="53605608" type="audio/mpeg"/>
        <itunes:summary>In a talk at Black Hat USA 2023, Sharon Brizinov and Noam Moshe from Claroty Team82, disclosed a significant vulnerability in the Open Platform Communications Universal Architecture or OPC-UA.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2230</itunes:duration>
                <itunes:episode>22</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 20: Securing Satellite Communications With Quantum Cryptography</title>
        <itunes:title>EP 20: Securing Satellite Communications With Quantum Cryptography</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-20-securing-satellite-communications-with-quantum-cryptography/</link>
                    <comments>https://errorcode.podbean.com/e/ep-20-securing-satellite-communications-with-quantum-cryptography/#comments</comments>        <pubDate>Tue, 01 Aug 2023 15:54:21 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/c47c7200-7255-3b7c-8f04-8c7bb1481e7b</guid>
                                    <description><![CDATA[<p>What would happen if someone stole the encryption keys for a major satellite? Well, it’d be game over. Unless the satellite used quantum cryptography. Skip Sanzeri from QuSecure explains how using “quantum tunnels” will allow even legacy satellites in orbit today to become secure in a rapidly approaching post-quantum world. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What would happen if someone stole the encryption keys for a major satellite? Well, it’d be game over. Unless the satellite used quantum cryptography. Skip Sanzeri from QuSecure explains how using “quantum tunnels” will allow even legacy satellites in orbit today to become secure in a rapidly approaching post-quantum world. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jgt8us/EP20FINAL.mp3" length="55793624" type="audio/mpeg"/>
        <itunes:summary>What would happen if someone stole the encryption keys for a major satellite? Well, it’d be game over. Unless the satellite used quantum cryptography.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2322</itunes:duration>
                <itunes:episode>21</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 19: Hack-A-Sat 4</title>
        <itunes:title>EP 19: Hack-A-Sat 4</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-19-hack-a-sat-4/</link>
                    <comments>https://errorcode.podbean.com/e/ep-19-hack-a-sat-4/#comments</comments>        <pubDate>Thu, 06 Jul 2023 11:35:11 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/731c19d1-a773-3b11-87ac-17e4ff24effd</guid>
                                    <description><![CDATA[<p>This is a story of what's needed for the Capture The Flag competition at <a href='https://defcon.org/html/defcon-31/dc-31-index.html'>DEF CON 31</a> to be hosted for the first time on a live satellite orbiting 400 kilometers above the Earth. Mike Walker continues his conversation, focusing more on the game to be played in <a href='https://hackasat.com/'>Hack-A-Sat 4</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is a story of what's needed for the Capture The Flag competition at <a href='https://defcon.org/html/defcon-31/dc-31-index.html'>DEF CON 31</a> to be hosted for the first time on a live satellite orbiting 400 kilometers above the Earth. Mike Walker continues his conversation, focusing more on the game to be played in <a href='https://hackasat.com/'>Hack-A-Sat 4</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wnmrw4/EP19FINAL.mp3" length="42040468" type="audio/mpeg"/>
        <itunes:summary>This is a story of what’s needed for the Capture The Flag competition at DEF CON 31 to be hosted for the first time on a live satellite orbiting 400 kilometers above the Earth. Mike Walker continues his conversation, focusing more on the game to be played in Hack-A-Sat 4.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1748</itunes:duration>
                <itunes:episode>20</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 18: Hacking Moonlighter</title>
        <itunes:title>EP 18: Hacking Moonlighter</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-18-hacking-moonlighter/</link>
                    <comments>https://errorcode.podbean.com/e/ep-18-hacking-moonlighter/#comments</comments>        <pubDate>Fri, 23 Jun 2023 09:37:55 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/bd866902-cb94-3418-af25-dbf60c7f2293</guid>
                                    <description><![CDATA[<p>Moonlighter is the world’s first and only hacking sandbox in space. Currently orbiting the earth near the International Space Station, the satellite is the playground for this year’s Hack-A-Sat 4 competition at DEF CON 31. Mike Walker, from Cromulence, discusses the difference between hacking a live satellite in orbit vs the previous Hack-A-Sat CTFs which only simulated the experience. We discuss limited contact windows, latency, and other aspects of orbital mechanics which will surely influence how Hack-a-Sat 4 will be played.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Moonlighter is the world’s first and only hacking sandbox in space. Currently orbiting the earth near the International Space Station, the satellite is the playground for this year’s Hack-A-Sat 4 competition at DEF CON 31. Mike Walker, from Cromulence, discusses the difference between hacking a live satellite in orbit vs the previous Hack-A-Sat CTFs which only simulated the experience. We discuss limited contact windows, latency, and other aspects of orbital mechanics which will surely influence how Hack-a-Sat 4 will be played.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/un25c3/EP18FINAL.mp3" length="53137285" type="audio/mpeg"/>
        <itunes:summary>Moonlighter is the world’s first and only hacking sandbox in space. Currently orbiting the earth near the International Space Station, the satellite is the playground for this year’s Hack-A-Sat competition at DEF CON 31.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2211</itunes:duration>
                <itunes:episode>19</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 17: Hacking Personal Medical Devices</title>
        <itunes:title>EP 17: Hacking Personal Medical Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-17-hacking-personal-medical-devices/</link>
                    <comments>https://errorcode.podbean.com/e/ep-17-hacking-personal-medical-devices/#comments</comments>        <pubDate>Wed, 07 Jun 2023 11:19:35 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/b2c4158f-2973-315a-9163-1939a23344c2</guid>
                                    <description><![CDATA[<p>Could a personal medical device be a threat for an organization? Turns out it’s similar to protecting against an attack on a mobile device. Except a denial of service here could prove fatal. Todd Brasel, the author of <a href='https://www.amazon.com/Security-Issues-Personal-Medical-Devices-ebook/dp/B0C5N13WFH'>Security Issues of Personal Medical Devices: Concerns, Characteristics, and Controls</a>, discusses with Error Code the research he’s done on devices either inside the body or just outside, the vulnerabilities in communications they sometimes have, and the mitigations available today.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Could a personal medical device be a threat for an organization? Turns out it’s similar to protecting against an attack on a mobile device. Except a denial of service here could prove fatal. Todd Brasel, the author of <a href='https://www.amazon.com/Security-Issues-Personal-Medical-Devices-ebook/dp/B0C5N13WFH'>Security Issues of Personal Medical Devices: Concerns, Characteristics, and Controls</a>, discusses with Error Code the research he’s done on devices either inside the body or just outside, the vulnerabilities in communications they sometimes have, and the mitigations available today.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fdxq7u/EP17FINAL.mp3" length="58903241" type="audio/mpeg"/>
        <itunes:summary>Could a personal medical device be a threat for an organization? Turns out it’s similar to protecting against an attack on a mobile device. Except a denial of service here could prove fatal.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2451</itunes:duration>
                <itunes:episode>18</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 16: Hackers At The Capital, Doing Good</title>
        <itunes:title>EP 16: Hackers At The Capital, Doing Good</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-16-hackers-at-the-capital-doing-good/</link>
                    <comments>https://errorcode.podbean.com/e/ep-16-hackers-at-the-capital-doing-good/#comments</comments>        <pubDate>Tue, 23 May 2023 17:16:54 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/813776b0-2460-3825-8aef-f380eec01b0b</guid>
                                    <description><![CDATA[<p>Josh Corman, VP of Cyber Safety Strategy at Claroty, is a hacker who knows U.S. public policy well. Ten years ago he created a volunteer organization, <a href='https://iamthecavalry.org/'>I Am The Cavalry</a>, to help educate sitting legislators on active cybersecurity issues. In this episode of Error Code, Josh talks about the recently passed PATCH ACT and how it addresses some of the issues around patching medical devices over the lifetime of the device rather than just at the time of FDA certification. He also talks about his experience working for CISA during COVID-19 and how that helped inform issues within the PATCH ACT.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Josh Corman, VP of Cyber Safety Strategy at Claroty, is a hacker who knows U.S. public policy well. Ten years ago he created a volunteer organization, <a href='https://iamthecavalry.org/'>I Am The Cavalry</a>, to help educate sitting legislators on active cybersecurity issues. In this episode of Error Code, Josh talks about the recently passed PATCH ACT and how it addresses some of the issues around patching medical devices over the lifetime of the device rather than just at the time of FDA certification. He also talks about his experience working for CISA during COVID-19 and how that helped inform issues within the PATCH ACT.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/s22isc/EP16FINAL.mp3" length="79721997" type="audio/mpeg"/>
        <itunes:summary>Josh Corman, VP of Cyber Safety Strategy at Claroty, is a hacker who knows U.S. public policy well. Ten years ago he created a volunteer organization, IAMTHECALVALRY, to help educate sitting legislators on active cybersecurity issues.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3319</itunes:duration>
                <itunes:episode>17</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 15: Tracking Threats (and Risks) Against OT Devices</title>
        <itunes:title>EP 15: Tracking Threats (and Risks) Against OT Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/tracking-threats-and-risks-against-ot-devices/</link>
                    <comments>https://errorcode.podbean.com/e/tracking-threats-and-risks-against-ot-devices/#comments</comments>        <pubDate>Tue, 09 May 2023 08:02:41 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/0068b0d4-8b23-3792-a66e-6b99b0d4e2cd</guid>
                                    <description><![CDATA[<p>This is the story about researchers who monitor the threats against IoT and OT systems, and the steps being taken to mitigate them.  Ishmael Valenzuela, Vice President of the threat research and Intelligence Team at BlackBerry, shares the latest insights from his company’s Cybersecurity Global Threat Intelligence Report. We talk about threats from Latin America and elsewhere, how firewalls alone won’t necessarily protect OT devices, how attackers and defenders are using AI technology, and how hospitals are seeing perhaps the most increase in threats. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is the story about researchers who monitor the threats against IoT and OT systems, and the steps being taken to mitigate them.  Ishmael Valenzuela, Vice President of the threat research and Intelligence Team at BlackBerry, shares the latest insights from his company’s Cybersecurity Global Threat Intelligence Report. We talk about threats from Latin America and elsewhere, how firewalls alone won’t necessarily protect OT devices, how attackers and defenders are using AI technology, and how hospitals are seeing perhaps the most increase in threats. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/v9wi4u/EP15FINAL.mp3" length="58112671" type="audio/mpeg"/>
        <itunes:summary>This is the story about researchers who monitor the threats against IoT and OT systems, and the steps being taken to mitigate them.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2418</itunes:duration>
                <itunes:episode>16</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 14: Hacking the Power Grid</title>
        <itunes:title>EP 14: Hacking the Power Grid</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-14-hacking-the-power-grid/</link>
                    <comments>https://errorcode.podbean.com/e/ep-14-hacking-the-power-grid/#comments</comments>        <pubDate>Wed, 26 Apr 2023 16:09:35 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/b2495dfa-311f-3a28-8c54-9493efdab099</guid>
                                    <description><![CDATA[<p>There’s a lot of FUD around hacking the power grid. Most often, there’s a more common cause: Soot. Even Squirrels. Jori VanAntwerp, CEO of <a href='https://synsaber.com/'>SynSaber</a>. talks about the realities of the US power grid vs the myths. While there’s room to improve, there’s also a great amount of resilience already in the electrical system today.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>There’s a lot of FUD around hacking the power grid. Most often, there’s a more common cause: Soot. Even Squirrels. Jori VanAntwerp, CEO of <a href='https://synsaber.com/'>SynSaber</a>. talks about the realities of the US power grid vs the myths. While there’s room to improve, there’s also a great amount of resilience already in the electrical system today.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cmi3d7/EP14FINAL.mp3" length="57722088" type="audio/mpeg"/>
        <itunes:summary>There’s a lot of FUD around hacking the power grid. Most often, there’s a more common cause: Soot. Even Squirrels.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2402</itunes:duration>
                <itunes:episode>15</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP14.png" />    </item>
    <item>
        <title>EP 13: Hacking EV Charging Stations</title>
        <itunes:title>EP 13: Hacking EV Charging Stations</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-13-hacking-ev-charging-stations/</link>
                    <comments>https://errorcode.podbean.com/e/ep-13-hacking-ev-charging-stations/#comments</comments>        <pubDate>Tue, 11 Apr 2023 17:26:17 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/361610b4-0fb1-32b5-b234-4b841367f0a8</guid>
                                    <description><![CDATA[<p>How the rapid proliferation of EV charging stations is already leading to attacks on the stations and the vehicles themselves, and what we should do about it.  Charles Eagan, CTO of BlackBerry, talks about the rush to create these charging stations and the traditional problems with IoT – vulnerable versions of the OS, of the open source, and even some of the protocols being used. He also talks about how we can improve the security of software defined vehicles and their ecosystems. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>How the rapid proliferation of EV charging stations is already leading to attacks on the stations and the vehicles themselves, and what we should do about it.  Charles Eagan, CTO of BlackBerry, talks about the rush to create these charging stations and the traditional problems with IoT – vulnerable versions of the OS, of the open source, and even some of the protocols being used. He also talks about how we can improve the security of software defined vehicles and their ecosystems. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/y6d5pg/EP13FINAL.mp3" length="65630294" type="audio/mpeg"/>
        <itunes:summary>How the rapid proliferation of EV charging stations is already leading to attacks on the stations and the vehicles themselves, and what we should do about it.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2731</itunes:duration>
                <itunes:episode>14</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/ErrorCodeEP13.png" />    </item>
    <item>
        <title>EP 12: Adding ICS and OT to the National Cybersecurity Strategy</title>
        <itunes:title>EP 12: Adding ICS and OT to the National Cybersecurity Strategy</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-12-adding-ics-and-ot-to-the-national-cybersecurity-strategy/</link>
                    <comments>https://errorcode.podbean.com/e/ep-12-adding-ics-and-ot-to-the-national-cybersecurity-strategy/#comments</comments>        <pubDate>Tue, 28 Mar 2023 14:50:36 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/d1e3f472-d848-3f4c-a9a6-0ecc72cf6d89</guid>
                                    <description><![CDATA[<p>The Biden-Harris 2023 National Cybersecurity Strategy breaks with Cold War thinking and offers a bold new approach to today’s online offense and defense. Danielle Jablanski from <a href='https://www.nozominetworks.com/'>Nozomi Networks</a> breaks down the ambitious new policy which includes explicit mention of ICS and OT technologies for the first time.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The Biden-Harris 2023 National Cybersecurity Strategy breaks with Cold War thinking and offers a bold new approach to today’s online offense and defense. Danielle Jablanski from <a href='https://www.nozominetworks.com/'>Nozomi Networks</a> breaks down the ambitious new policy which includes explicit mention of ICS and OT technologies for the first time.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kff4ti/EP12FINAL.mp3" length="60086274" type="audio/mpeg"/>
        <itunes:summary>The Biden-Harris 2023 National Cybersecurity Strategy breaks with Cold War thinking and offers a bold new approach to today’s online offense and defense.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2500</itunes:duration>
                <itunes:episode>13</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP12A.png" />    </item>
    <item>
        <title>EP 11: Window Snyder Is Building A Secure IoT and OT Framework</title>
        <itunes:title>EP 11: Window Snyder Is Building A Secure IoT and OT Framework</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-11-building-a-framework-to-secure-iot-and-ot-devices-today/</link>
                    <comments>https://errorcode.podbean.com/e/ep-11-building-a-framework-to-secure-iot-and-ot-devices-today/#comments</comments>        <pubDate>Tue, 14 Mar 2023 16:36:18 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/afe52301-0855-32ef-9806-71a96d0c782b</guid>
                                    <description><![CDATA[<p>We’ve already seen botnets composed of compromised devices like routers and security cameras. So how do we secure them and our smart lightbulbs too? Window Snyder, CEO of <a href='https://thistle.tech/'>Thistle Technologies</a>, explains how new devices can be partitioned with failovers and then serviced with regular updates all monitored from a central dashboard. Even devices already in the field today can also be upgraded and secured in some cases.  </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We’ve already seen botnets composed of compromised devices like routers and security cameras. So how do we secure them and our smart lightbulbs too? Window Snyder, CEO of <a href='https://thistle.tech/'>Thistle Technologies</a>, explains how new devices can be partitioned with failovers and then serviced with regular updates all monitored from a central dashboard. Even devices already in the field today can also be upgraded and secured in some cases.  </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/u9rub2/ep11FINAL.mp3" length="53695260" type="audio/mpeg"/>
        <itunes:summary>We’ve already seen botnets composed of compromised devices like routers and security cameras. So how do we secure them and our smart lightbulbs too?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2234</itunes:duration>
                <itunes:episode>12</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/smartlightbulbB_pu55uk.png" />    </item>
    <item>
        <title>EP 10: The L0pht, According to Space Rogue</title>
        <itunes:title>EP 10: The L0pht, According to Space Rogue</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-10-the-l0pht-according-to-space-rogue/</link>
                    <comments>https://errorcode.podbean.com/e/ep-10-the-l0pht-according-to-space-rogue/#comments</comments>        <pubDate>Tue, 28 Feb 2023 16:53:17 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/1c5f06dc-71d6-3510-a649-7fc98e2e81dc</guid>
                                    <description><![CDATA[<p>This is the story of Cris Thomas aka Space Rogue, who’s written perhaps the best book about the early days of hacking, <a href='https://www.amazon.com/Space-Rogue-Hackers-Known-Changed/dp/B0BRR17PTC'>Space Rogue: How the Hackers Known as the Loft Changed The World</a>. Unlike a journalist merely chronicling events in Boston in the 1990s from the outside, Cris was on the inside. This is not only the story of the L0pht but it's also the story of his life, so he seamlessly provides the often missing context of the time with countless asides and anecdotes woven in instead of tacked on. In this episode of Error Code, Cris also drops a lot of names.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is the story of Cris Thomas aka Space Rogue, who’s written perhaps the best book about the early days of hacking, <a href='https://www.amazon.com/Space-Rogue-Hackers-Known-Changed/dp/B0BRR17PTC'>Space Rogue: How the Hackers Known as the Loft Changed The World</a>. Unlike a journalist merely chronicling events in Boston in the 1990s from the outside, Cris was on the inside. This is not only the story of the L0pht but it's also the story of his life, so he seamlessly provides the often missing context of the time with countless asides and anecdotes woven in instead of tacked on. In this episode of Error Code, Cris also drops a lot of names.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/diqyiz/EP10FINAL.mp3" length="90085295" type="audio/mpeg"/>
        <itunes:summary>This is the story of Cris Thomas aka Space Rogue, who’s written perhaps the best book about the early days of hacking, Space Rogue: How the Hackers Known as the Loft Changed The World.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3750</itunes:duration>
                <itunes:episode>11</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP10temp.png" />    </item>
    <item>
        <title>EP 09: Zhadnost</title>
        <itunes:title>EP 09: Zhadnost</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-09-zhadnost/</link>
                    <comments>https://errorcode.podbean.com/e/ep-09-zhadnost/#comments</comments>        <pubDate>Tue, 14 Feb 2023 16:39:51 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/28ec94b9-a612-35d0-8679-c4058759ad32</guid>
                                    <description><![CDATA[<p>This is the story of Zhadnost, of how an IoT-based botnet was conscripted into an online war in the days immediately before the kinetic Ukraine invasion. Ryan Slaney of SecurityScorecard walks us through the timeline of these attacks and the evidence of attribution he found linking it to Russia’s GRU. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is the story of Zhadnost, of how an IoT-based botnet was conscripted into an online war in the days immediately before the kinetic Ukraine invasion. Ryan Slaney of SecurityScorecard walks us through the timeline of these attacks and the evidence of attribution he found linking it to Russia’s GRU. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ywx9v7/EP09FINAL.mp3" length="63814052" type="audio/mpeg"/>
        <itunes:summary>This is the story of Zhadnost, of how an IoT-based botnet was conscripted into an online war in the days immediately before the kinetic Ukraine invasion.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2656</itunes:duration>
                <itunes:episode>10</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/ep09temp1_jzbdyb.png" />    </item>
    <item>
        <title>EP 08: A Matter Of Trust</title>
        <itunes:title>EP 08: A Matter Of Trust</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-08-ics-security/</link>
                    <comments>https://errorcode.podbean.com/e/ep-08-ics-security/#comments</comments>        <pubDate>Tue, 31 Jan 2023 20:47:57 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/4b2ffad7-7f98-30a8-b05b-128f272e94d0</guid>
                                    <description><![CDATA[<p>What if a vulnerability exists in popular ICS devices, yet the only fix is to re-issue the hardware? This is true with some embedded security flaws. Ang Cui, founder and CEO of Red Balloon Security, talks about his company’s discovery of CVE-2022-38773, which affects the secure boot process in Siemens S7 1500 PLCs, and what the mitigations for devices using that might look like. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What if a vulnerability exists in popular ICS devices, yet the only fix is to re-issue the hardware? This is true with some embedded security flaws. Ang Cui, founder and CEO of Red Balloon Security, talks about his company’s discovery of CVE-2022-38773, which affects the secure boot process in Siemens S7 1500 PLCs, and what the mitigations for devices using that might look like. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/8rzhh3/EP08FINAL.mp3" length="67040906" type="audio/mpeg"/>
        <itunes:summary>What if a vulnerability exists in popular ICS devices, yet the only fix is to re-issue the hardware? This is true with some embedded security flaws.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2790</itunes:duration>
                <itunes:episode>9</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP08image.png" />    </item>
    <item>
        <title>EP 07: Secure Medical IoT Devices</title>
        <itunes:title>EP 07: Secure Medical IoT Devices</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-07-secure-medical-iot-devices/</link>
                    <comments>https://errorcode.podbean.com/e/ep-07-secure-medical-iot-devices/#comments</comments>        <pubDate>Tue, 17 Jan 2023 17:07:33 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/8887c5c8-eef6-3ba3-8701-7bdce55660f9</guid>
                                    <description><![CDATA[<p>IoT can make patient care easier.. But how do we introduce new IoT medical devices into an ecosystem where we can’t even keep tabs on our legacy devices? Mohammad Waqas discusses conversations he’s had with hospitals about the device profiles they don’t necessarily know about – the over-the-counter glucose monitor app on an iPad that hasn’t gone through IT provisioning - and what they can do about it. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>IoT can make patient care easier.. But how do we introduce new IoT medical devices into an ecosystem where we can’t even keep tabs on our legacy devices? Mohammad Waqas discusses conversations he’s had with hospitals about the device profiles they don’t necessarily know about – the over-the-counter glucose monitor app on an iPad that hasn’t gone through IT provisioning - and what they can do about it. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/w3fgi2/EP07FINAL.mp3" length="73764824" type="audio/mpeg"/>
        <itunes:summary>IoT can make patient care easier.. But how do we introduce new IoT medical devices into an ecosystem where we can’t even keep tabs on our legacy devices?</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3070</itunes:duration>
                <itunes:episode>8</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP07.png" />    </item>
    <item>
        <title>EP 06: Vastaamo</title>
        <itunes:title>EP 06: Vastaamo</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-06-vastaamo/</link>
                    <comments>https://errorcode.podbean.com/e/ep-06-vastaamo/#comments</comments>        <pubDate>Tue, 03 Jan 2023 19:47:19 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/6c6ba222-7d0a-3b27-842f-957ae85485ee</guid>
                                    <description><![CDATA[<p>The Vastaamo data breach stands as one of the most heinous of internet crimes because of the 30,000 psychiatric records that were exposed and the lives it ruined. Antti Kurittu discusses his presentation at SecTor 2022, what we know thus far from the public record, and the news of the Finnish arrest warrant for the individual only previously known as “Ransomware_Man”.  </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The Vastaamo data breach stands as one of the most heinous of internet crimes because of the 30,000 psychiatric records that were exposed and the lives it ruined. Antti Kurittu discusses his presentation at SecTor 2022, what we know thus far from the public record, and the news of the Finnish arrest warrant for the individual only previously known as “Ransomware_Man”.  </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kffacw/EP06FINAL.mp3" length="78588491" type="audio/mpeg"/>
        <itunes:summary>The Vastaamo data breach stands as one of the most heinous of internet crimes because of the 30,000 psychiatric records that were exposed and the lives it ruined.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3271</itunes:duration>
                <itunes:episode>7</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/EP06.png" />    </item>
    <item>
        <title>EP 05: Food Production As Critical Infrastructure</title>
        <itunes:title>EP 05: Food Production As Critical Infrastructure</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-05-food-production-as-critical-infrastructure/</link>
                    <comments>https://errorcode.podbean.com/e/ep-05-food-production-as-critical-infrastructure/#comments</comments>        <pubDate>Thu, 08 Dec 2022 15:19:24 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/e905f3c5-ba2a-3ca5-aa84-e976b65a8b24</guid>
                                    <description><![CDATA[<p>IoT and Machine Learning can help farmers provide more food with fewer resources, so long as the devices in the field and the backend systems are secure. Seth Hardy, co-founder and CTO of <a href='https://bugmars.com/.'>Bug Mars</a>, a precision agtech company for insect farms, discusses his <a href='https://sector.ca/'>SecTor 2022</a> presentation, drawing upon his more than 20 years of security experience in his new role in sustainable food production.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>IoT and Machine Learning can help farmers provide more food with fewer resources, so long as the devices in the field and the backend systems are secure. Seth Hardy, co-founder and CTO of <a href='https://bugmars.com/.'>Bug Mars</a>, a precision agtech company for insect farms, discusses his <a href='https://sector.ca/'>SecTor 2022</a> presentation, drawing upon his more than 20 years of security experience in his new role in sustainable food production.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/r7ad5z/EP05FINAL.mp3" length="65401461" type="audio/mpeg"/>
        <itunes:summary>IoT and Machine Learning can help farmers provide more food with fewer resources, so long as the devices in the field and the backend systems are secure.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2722</itunes:duration>
                <itunes:episode>6</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/episode05A_h4fyyy.png" />    </item>
    <item>
        <title>EP 04: Hacking the Quantum Realm</title>
        <itunes:title>EP 04: Hacking the Quantum Realm</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-04-hacking-the-quantum-realm/</link>
                    <comments>https://errorcode.podbean.com/e/ep-04-hacking-the-quantum-realm/#comments</comments>        <pubDate>Tue, 22 Nov 2022 13:03:05 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/00ac232c-f472-352c-9d0b-283722c6717d</guid>
                                    <description><![CDATA[<p>Quantum computing will make great advances in science; it will also have the ability to decrypt banking, healthcare, and other industries' stolen data. Skip Sanzeri of QuSecure explains how quantum computing is advancing rapidly, how it has the power to crack RSA 2048 and other encryption that we know take for granted today, and why his and other companies are talking about our post-quantum encryption world today. Dn3NZumn4pPpnVhpt6GH</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Quantum computing will make great advances in science; it will also have the ability to decrypt banking, healthcare, and other industries' stolen data. Skip Sanzeri of QuSecure explains how quantum computing is advancing rapidly, how it has the power to crack RSA 2048 and other encryption that we know take for granted today, and why his and other companies are talking about our post-quantum encryption world today. Dn3NZumn4pPpnVhpt6GH</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/7qdmbk/EP04FINAL.mp3" length="75907701" type="audio/mpeg"/>
        <itunes:summary>Quantum computing will make great advances in science; it will also have the ability to decrypt banking, healthcare, and other industries’ stolen data.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3160</itunes:duration>
                <itunes:episode>5</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/errorcode04.png" />    </item>
    <item>
        <title>EP 03: Hacking Hardware (featuring Joe Grand)</title>
        <itunes:title>EP 03: Hacking Hardware (featuring Joe Grand)</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-03-hacking-hardware-featuring-joe-grand/</link>
                    <comments>https://errorcode.podbean.com/e/ep-03-hacking-hardware-featuring-joe-grand/#comments</comments>        <pubDate>Thu, 10 Nov 2022 17:24:52 -0800</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/9c1034e0-51b3-318d-b647-af0e21cb41bf</guid>
                                    <description><![CDATA[<p>This is the history of hardware hacking and the story of Joe Grand. From testifying before Congress to creating badgelife at DEF CON, Joe has done it all. And he’s darn humble about it, too. Joe just wants to share through his classes, website, and YouTube channel all that he’s learned since his days with the L0pht, the tools he’s created, and the work he’s currently doing with Right to Repair. He just wants to make the art of hardware hacking more accessible to others. </p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This is the history of hardware hacking and the story of Joe Grand. From testifying before Congress to creating badgelife at DEF CON, Joe has done it all. And he’s darn humble about it, too. Joe just wants to share through his classes, website, and YouTube channel all that he’s learned since his days with the L0pht, the tools he’s created, and the work he’s currently doing with Right to Repair. He just wants to make the art of hardware hacking more accessible to others. </p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/7brmbp/EP03FINAL.mp3" length="92045105" type="audio/mpeg"/>
        <itunes:summary>This is the history of hardware hacking and the story of Joe Grand. From testifying before Congress to creating badgelife at DEF CON, Joe has done it all.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3832</itunes:duration>
                <itunes:episode>4</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/ERRORCODE3.png" />    </item>
    <item>
        <title>EP 02: Using Digital Twins To Hack Satellites</title>
        <itunes:title>EP 02: Using Digital Twins To Hack Satellites</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-02-digital-twins/</link>
                    <comments>https://errorcode.podbean.com/e/ep-02-digital-twins/#comments</comments>        <pubDate>Thu, 27 Oct 2022 15:59:41 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/cfaa8695-551f-330d-a426-52b05eea15f7</guid>
                                    <description><![CDATA[<p>What happens now to the digital test environment built for <a href='https://hackasat.com/'>Hack-A-Sat</a> 3? Well, it becomes a rich testing and training environment for all on GitHub. Login Finch and Frank Pound continue sharing some of the behind-the-scenes challenges presented by hosting a Hack-A-Sat capture the flag competition, this time drilling down details behind the Digital Twins environment that needed to be built in advance of next year’s hack of an actual satellite in orbit.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What happens now to the digital test environment built for <a href='https://hackasat.com/'>Hack-A-Sat</a> 3? Well, it becomes a rich testing and training environment for all on GitHub. Login Finch and Frank Pound continue sharing some of the behind-the-scenes challenges presented by hosting a Hack-A-Sat capture the flag competition, this time drilling down details behind the Digital Twins environment that needed to be built in advance of next year’s hack of an actual satellite in orbit.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ahr72f/EP02FINAL.mp3" length="54884563" type="audio/mpeg"/>
        <itunes:summary>What happens now to the digital test environment built for Hack-A-Sat 3? Well, it becomes a rich testing and training environment for all on GitHub.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2284</itunes:duration>
                <itunes:episode>3</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/ErrorCodeEP02.png" />    </item>
    <item>
        <title>EP 01: Hacking Satellites</title>
        <itunes:title>EP 01: Hacking Satellites</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-01-hacking-satellites/</link>
                    <comments>https://errorcode.podbean.com/e/ep-01-hacking-satellites/#comments</comments>        <pubDate>Wed, 19 Oct 2022 08:06:50 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/b4dd1c9f-0a0b-30fc-a446-c5d569248934</guid>
                                    <description><![CDATA[<p>Satellites today lack basic security controls. With as little as $300, you, too, can hack into commercial satellites. So that’s an emerging IoT problem. </p>
<p>
Frank Pound and Login Finch share in this episode their work with <a href='https://hackasat.com/'>Hack-A-Sat</a>. It’s a unique Capture the Flag challenge that’s never been tried before. Here’s the background story of how the project got started … and where it’s going.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Satellites today lack basic security controls. With as little as $300, you, too, can hack into commercial satellites. So that’s an emerging IoT problem. </p>
<p><br>
Frank Pound and Login Finch share in this episode their work with <a href='https://hackasat.com/'>Hack-A-Sat</a>. It’s a unique Capture the Flag challenge that’s never been tried before. Here’s the background story of how the project got started … and where it’s going.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kfmnbx/EP01FINAL.mp3" length="57628674" type="audio/mpeg"/>
        <itunes:summary>Satellites today lack basic security controls. With as little as $300, you, too, can hack into commercial satellites. So that’s an emerging IoT problem.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2398</itunes:duration>
                <itunes:episode>2</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
        <itunes:image href="https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog15244354/ErrorCodeEP01b.png" />    </item>
    <item>
        <title>EP 00: Error Code (promo)</title>
        <itunes:title>EP 00: Error Code (promo)</itunes:title>
        <link>https://errorcode.podbean.com/e/ep-00-error-code-promo/</link>
                    <comments>https://errorcode.podbean.com/e/ep-00-error-code-promo/#comments</comments>        <pubDate>Sat, 15 Oct 2022 10:33:27 -0700</pubDate>
        <guid isPermaLink="false">errorcode.podbean.com/683ca466-151b-33a6-9ca2-bf825962da98</guid>
                                    <description><![CDATA[<p>Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code reliance and dependability. Work that can lead to autonomous vehicles and smart cities. It's your window in the research solving tomorrow's code problems today</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code reliance and dependability. Work that can lead to autonomous vehicles and smart cities. It's your window in the research solving tomorrow's code problems today</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pb663z/EP00TEASER.mp3" length="1542104" type="audio/mpeg"/>
        <itunes:summary>Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code reliance and dependability.</itunes:summary>
        <itunes:author>Robert Vamosi</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>61</itunes:duration>
                <itunes:episode>1</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
</channel>
</rss>
