Cybersecurity Under Pressure. Real Attacks, Real Lessons
This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice.
- Indexed episodes, last 90 days
- 35
- Latest publication
- Sep 23, 2026
- Audience
- Checking…
- Earliest in this view
- Jul 6, 2026
Latest episodes
Local Does Not Mean Low Impact: CVE-2026-24083 and Automotive Attack Feasibility (opens the original)
Read excerpt
A vulnerability with a local attack vector can have serious consequences. But “local” does not automatically mean remote vehicle compromise, and it certainly does not prove that an attacker can reach safety-relevant vehicle functions. In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine CVE-2026-24083, a memory-corruption vulnerability affecting Qualcomm Snapdragon Auto platforms including QAM8295P, QCA6696 and SA8295P. The vulnerability occurs while processing
One PLC, Multiple Security Lifecycles: The SIMATIC S7-1500 Linux Subsystem Problem (opens the original)
Read excerpt
An industrial asset may appear as a single box in an inventory, but that does not mean everything inside it follows the same cybersecurity lifecycle. In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine vulnerabilities affecting the additional GNU/Linux subsystem of the Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP and use them to challenge one of the most persistent simplifications in OT asset management: the assumption that one physical device represents on
Security Sign-Off for Silicon: Why Chip Security Must Become a Design Gate (opens the original)
Read excerpt
Semiconductor development already has formal gates for functionality, timing, power and physical implementation. Security is increasingly becoming another condition that must be demonstrated before a design can be considered ready. In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine the emerging concept of security sign-off in semiconductor development and what it means for an industry building increasingly complex, heterogeneous and software-dependent hardwar
One Hardcoded Key, Many Systems at Risk: The Johnson Controls Airwall Lesson (opens the original)
Read excerpt
A hardcoded cryptographic key can look like a relatively simple implementation mistake. In an embedded or industrial system, however, that single decision can undermine an entire security architecture. In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine CVE-2026-64887 affecting Johnson Controls Airwall and use it to explore a broader problem in embedded cybersecurity: what happens when a secret intended to establish trust is permanently built into the product
Beyond Software Supply Chains: NSA ASIC Assurance and the Problem of Trusting Silicon (opens the original)
Read excerpt
When cybersecurity teams discuss supply-chain risk, the conversation usually starts with software. But some of the most consequential trust decisions are made much deeper in the stack — inside the hardware itself. In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine the NSA’s latest guidance for Application Specific Integrated Circuits, or ASICs, and what its Level of Assurance 1 framework tells us about securing custom microelectronics throughout design and ma
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.
See coverage about Cybersecurity Under Pressure. Real Attacks, Real Lessons