InfoSec Bites
Welcome to Hello InfoSec, your ultimate hub for all things cybersecurity! Dive into our thrilling podcast series, InfoSec Bites, where we unleash deep dives into Information Security, jaw-dropping Major Security Incidents, cutting-edge Cloud Information Security, crucial…
- Indexed episodes, last 90 days
- 4
- Latest publication
- Aug 23, 2026
- Audience
- Checking…
- Earliest in this view
- Jul 9, 2026
Latest episodes
ISO/IEC 27018: Guidelines for Protecting PII in Public Clouds (opens the original)
Read excerpt
ISO/IEC 27018 is the first international standard specifically designed to protect personally identifiable information (PII) in public cloud environments, acting as a specialized privacy extension to the foundational ISO/IEC 27001 Information Security Management System (ISMS) . Tailored uniquely for cloud service providers (CSPs) acting as contractual PII processors , it translates the eleven privacy principles of ISO/IEC 29100 into concrete, cloud-native operational controls. The standard estab
The Silent Layer: Unmasking Container Base OS Security in AWS Environments (opens the original)
Read excerpt
This podcast discussion provides a technical deep dive into AWS Bottlerocket , a Linux-based, open-source operating system purpose-built by Amazon Web Services to host containerized workloads. Unlike general-purpose distributions that include thousands of packages, Bottlerocket follows a minimalist philosophy , stripping away package managers, scripting interpreters, and interactive shells to reduce the attack surface by approximately 60%. The architecture is rooted in immutability and defense-i
Web Application Attacks & Adversarial Lifecycle: From Passive OSINT to Lateral Movement and Multi-Layered Detection (opens the original)
Read excerpt
Modern cybersecurity operations prioritize multi-layered reconnaissance, moving from passive OSINT gathering using tools like Amass and crt.sh to active verification via port profiling and directory enumeration. This initial phase aims to map the organization's external digital footprint , identifying exposed assets such as misconfigured subdomains, cloud storage buckets, and leaked credentials within public repositories. Once the attack surface is defined, adversaries leverage vulnerabilities l
Authentication and Authorisation bypass: The Invisible Threat (opens the original)
Read excerpt
Access control serves as a foundational security framework divided into authentication , which verifies identity, and authorization , which regulates interaction boundaries between active subjects and passive resources. Despite its criticality, broken access control remains a top vulnerability, frequently exploited through mechanics such as Insecure Direct Object References (IDOR) , parameter tampering, and architectural decoupling that allow attackers to bypass identity checks or escalate privi
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.