Podcasts//Below the Surface (Audio) - The Supply Chain Security Podcast
Below the Surface (Audio) - The Supply Chain Security Podcast

Below the Surface (Audio) - The Supply Chain Security Podcast

Acerca de

A lively discussion of the threats affecting supply chain, specifically focused on firmware and low-level code that is a blind spot for many organizations. This podcast will feature guests from the cybersecurity industry discussing the problems surrounding supply chain-related issues and potential solutions. Get the Supply Chain Security Toolkit from Eclypsium here: https://eclypsium.com/go
65
Episodios
English
Idioma
0
Suscriptores
0
Reproducciones
Episodios25
Exploring AI in Firmware Analysis - BTS #65

Exploring AI in Firmware Analysis - BTS #65

Dec 15, 2025·

Summary In this episode, special guest Matt Brown joins us to discuss the integration of AI in firmware analysis, exploring its benefits and challenges. We delve into the transition from traditional methods to AI-driven...

Patching, Evil AI, Supply Chain Breaches - BTS #64

Patching, Evil AI, Supply Chain Breaches - BTS #64

Nov 24, 2025·

Summary In this episode, the hosts discuss various cybersecurity topics, including recent vulnerabilities in Fortinet products, the implications of supply chain breaches, the evolving role of AI in cybersecurity, and...

F5 Breach, Linux Malware, and Hacking Banks - BTS #63

F5 Breach, Linux Malware, and Hacking Banks - BTS #63

Oct 30, 2025·

Summary In this episode of Below the Surface, Paul Asadoorian and Chase Snyder delve into various cybersecurity topics, including the use of Raspberry Pi in cyber attacks, the implications of the F5 breach, and the...

Unpacking the F5 Breach, Framework UEFI Shells - BTS #62

Unpacking the F5 Breach, Framework UEFI Shells - BTS #62

Oct 21, 2025·

In this episode, the hosts discuss the recent F5 breach, exploring the implications of the attack, the tactics used by threat actors, and the importance of vulnerability disclosure. They delve into the complexities of...

Red November, Cisco Vulnerabilities, and Supply Chain Security - BTS #61

Red November, Cisco Vulnerabilities, and Supply Chain Security - BTS #61

Oct 8, 2025·

In this episode of Below the Surface, the hosts discuss various cybersecurity topics, including the Red November campaign targeting network edge devices, the implications of the Cisco SNMP vulnerability, and the recent...

HybridPetya and UEFI Threats - BTS #60

HybridPetya and UEFI Threats - BTS #60

Sep 22, 2025·

In this episode of Below the Surface, the hosts discuss various cybersecurity topics, including the evolution of malware with a focus on Hybrid Petya, the implications of UEFI vulnerabilities, and the security risks...

Exploit Marketplaces - BTS #59

Exploit Marketplaces - BTS #59

Sep 10, 2025·

In this episode of Below the Surface, host Paul Asadoorian speaks with Evan Dornbush, CEO of Desired Effect, about the evolving landscape of exploit marketplaces and vulnerability research. They discuss the challenges...

UEFI Vulnerabilities and Hardware Risks - BTS #58

UEFI Vulnerabilities and Hardware Risks - BTS #58

Sep 4, 2025·

In this episode, the hosts discuss various cybersecurity topics, focusing on hardware vulnerabilities, UEFI attack vectors, and the implications of new regulations on device security. They explore the evolution of Mirai...

Interview with Brian Mullen from AMI - BTS #57

Interview with Brian Mullen from AMI - BTS #57

Aug 15, 2025·

In this episode of Below the Surface, host Paul Asadoorian is joined by Brian Mullen, head of SSDLC at AMI, to discuss the complexities of supply chain and firmware security. They explore the challenges of maintaining...

BTS #56 - Vulnerabilities & Backdoors In IT Infrastructure

BTS #56 - Vulnerabilities & Backdoors In IT Infrastructure

Aug 8, 2025·

In this episode, the hosts discuss various cybersecurity topics, focusing on Nvidia vulnerabilities, the implications of backdoors in technology, and the importance of secure boot and certificate management. They also...

Netgear, Gigabyte, and Rowhammer Vulnerabilities - BTS #55

Netgear, Gigabyte, and Rowhammer Vulnerabilities - BTS #55

Jul 24, 2025·

In this episode of Below the Surface, the hosts discuss critical cybersecurity topics including vulnerabilities in Netgear and Gigabyte devices, the importance of asset inventory, and the implications of Row Hammer...

CVE-2024-54085: The First of Its Kind - BTS #54

CVE-2024-54085: The First of Its Kind - BTS #54

Jul 8, 2025·

In this episode, the hosts delve into the critical vulnerabilities associated with Baseboard Management Controllers (BMCs), with a particular focus on CVE-2024-54085. They discuss the ease of exploitation, the potential...

Exploring the Evolution of Zero Trust - BTS #53

Exploring the Evolution of Zero Trust - BTS #53

Jul 7, 2025·

In this episode, the hosts discuss the evolving landscape of AI infrastructure security, focusing on the complexities of building and maintaining AI data centers. They explore the critical role of Baseboard Management...

Securing the Future of AI Infrastructure - BTS #52

Securing the Future of AI Infrastructure - BTS #52

Jul 1, 2025·

In this episode, the hosts discuss the evolving landscape of AI infrastructure security, focusing on the complexities of building and maintaining AI data centers. They explore the critical role of Baseboard Management...

When Windows 10 Expires - BTS #51

When Windows 10 Expires - BTS #51

May 30, 2025·

In this episode, the hosts discuss the impending end of life for Windows 10 and the necessary preparations for upgrading to Windows 11. They explore the specific hardware requirements for Windows 11, including the...

SBOMs, HBOMs, and Supply Chain Visibility - BTS #50

SBOMs, HBOMs, and Supply Chain Visibility - BTS #50

May 15, 2025·

Summary In this episode, Paul Asadoorian and Joshua Marpet delve into the complexities of compliance, inventory management, and the emerging concepts of SBOMs, HBOMs, and FBOMs (no, not that FBOM). They discuss the...

The Hidden Risks of Open Source Components - BTS #49

The Hidden Risks of Open Source Components - BTS #49

May 6, 2025·

In this episode, Paul Asadorian and Josh Bressers delve into the complexities of open source supply chain security, discussing the prevalence of open source components in modern software, the challenges posed by legacy...

Hardware Hacking Tips & Tricks - BTS #48

Hardware Hacking Tips & Tricks - BTS #48

Apr 7, 2025·

In this episode, Paul and Chase delve into the world of hardware hacking, focusing on devices like the Flipper Zero and ESP32. They discuss the various applications of these tools, their impact on awareness in the...

BMC&C Part 3 - BTS #47

BMC&C Part 3 - BTS #47

Mar 19, 2025·

In this episode, Paul Asadoorian, Vlad Babkin, and Chase Snyder delve into the latest vulnerability disclosures related to Baseboard Management Controllers (BMCs), specifically focusing on AMI Megarac and Redfish. They...

Black Basta - Threat Intelligence Insights - BTS #46

Black Basta - Threat Intelligence Insights - BTS #46

Mar 5, 2025·

In this episode, Paul Asadoorian, Vlad Babkin, and Chase Snyder delve into the recent leaks from the Black Basta ransomware group, exploring the implications of the leaked chat logs, the operational tactics of the...

Understanding Firmware Vulnerabilities in Network Appliances - BTS #45

Understanding Firmware Vulnerabilities in Network Appliances - BTS #45

Feb 6, 2025·

In this episode, Paul, Vlad, and Chase discuss the security challenges of Palo Alto devices and network appliances. They explore the vulnerabilities present in these devices, the importance of best practices in device...

Network Appliances: A Growing Concern - BTS #44

Network Appliances: A Growing Concern - BTS #44

Jan 27, 2025·

In this episode, Paul Asadorian and Chase Snyder discuss the latest security threats and vulnerabilities affecting network appliances, particularly focusing on Avanti and Fortinet platforms. They explore the increasing...

CVE Turns 25 - BTS #43

CVE Turns 25 - BTS #43

Dec 9, 2024·

In this episode, Paul Asidorian, Alec Summers, and Lisa Olson discuss the 25th anniversary of the CVE program, its evolution, and the importance of transparency in vulnerability management. They explore the history of...

The China Threat - BTS #42

The China Threat - BTS #42

Nov 21, 2024·

In this episode, Paul Asadoorian, Allan Alford, and Josh Corman discuss the growing threat posed by China, particularly in the context of cyber operations and geopolitical ambitions. They explore the implications of...

Pacific Rim - BTS #41

Pacific Rim - BTS #41

Nov 6, 2024·

In this episode, Paul Asadorian, Larry Pesce, and Evan Dornbusch delve into the recent Sophos reports on threat actors, particularly focusing on the Pacific Rim case. They discuss the implications of the findings...

También te puede gustar