Jason Edwards
Certified: The CompTIA Security+ V8 / SY0-801 Audio Course
Certified: The CompTIA Security+ V8 / SY0-801 Audio Course is built for learners who want a clear, practical path into modern cybersecurity fundamentals without being tied to a desk. It is designed for entry-level security professionals, IT support staff, help desk technicians, junior system administrators, career changers, and anyone preparing for the Security+ exam. The course assumes you may already understand basic networking and computer systems, but it does not assume deep security experience. Each lesson explains the ideas behind the exam objectives in plain language, then connects them...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 44 — Credential Attacks: Password Spraying, Brute Force, User Enumeration, and MFA Bypass 27.04.2026 14:47
This episode covers credential attack patterns and how they differ in visibility, speed, and detection. Password spraying uses a small number of common passwords across many accounts to avoid lockouts, while brute force attacks try many password combinations against one or more accounts. User enumeration attempts to discover valid usernames through login messages, timing differences, password rese...
Episode 43 — Application Attacks: Injection, Buffer Overflow, Replay, Privilege Escalation, Forgery, and Traversal 27.04.2026 15:17
This episode explains common application attack indicators and what attackers are trying to accomplish when they exploit application weaknesses. Injection attacks attempt to send untrusted input that changes how a command, query, or interpreter behaves. Buffer overflows attempt to write more data than memory can safely hold, potentially causing crashes or code execution. Replay attacks reuse captu...
Episode 42 — Indicators of Compromise: Hashes, Domains, Timestamps, Log Manipulation, and Impossible Travel 27.04.2026 15:43
This episode covers indicators of compromise as clues that help analysts connect events to malicious activity. Students should understand how hashes can identify known suspicious files, IP addresses and domains can reveal command-and-control or phishing infrastructure, malicious processes can show execution, and file system artifacts can show persistence or staging. Timestamps help reconstruct act...
Episode 41 — Social Engineering Indicators: Smishing, Vishing, Whaling, Quishing, and Deepfakes 27.04.2026 14:33
This episode explains social engineering indicators across message, voice, executive-targeted, QR-code, impersonation, and synthetic media attacks. Students should understand smishing as phishing through text messages, vishing as voice-based deception, whaling as targeting senior leaders, quishing as using QR codes to send users to malicious destinations, and deepfakes as manipulated audio, video,...
Episode 40 — Physical and Network Attack Indicators (2.5) 27.04.2026 16:58
This episode explains indicators associated with physical and network attacks and how evidence may appear across different sources. Physical attack indicators include tailgating, shoulder surfing, skimming, forced entry, missing equipment, access badge anomalies, and surveillance footage that shows unauthorized presence. Network attack indicators may include DDoS traffic spikes, downgrade attempts...
Episode 39 — Malware Indicators: Ransomware, Trojans, Worms, Spyware, and Fileless Malware (2.5) 27.04.2026 17:12
This episode covers common malware indicators and what they may reveal during detection or investigation. Ransomware may produce encryption notices, renamed files, inaccessible data, or unusual backup deletion attempts. Trojans may appear as legitimate software while creating hidden access, worms may spread automatically, spyware and keyloggers may collect sensitive information, and rootkits may h...
Episode 38 — LLMs, Misconfigurations, Public Repositories, and Public Object Storage (2.4) 27.04.2026 15:19
This episode explains newer and common attack surfaces involving large language models, cloud misconfigurations, exposed repositories, leaked secrets, and public object storage. Students should understand that LLMs become riskier when they are connected to sensitive data, business workflows, plugins, code execution, or internal systems. Misconfigured cloud resources can expose storage buckets, dat...
Episode 37 — Stale Credentials, Rogue Devices, Shadow IT, Wireless, Mobile, and Identity Provider Risks (2.4) 27.04.2026 16:50
This episode covers attack surface risks created by unmanaged identities, unmanaged assets, and uncontrolled technology use. Stale credentials remain active after users change roles, leave the organization, or stop using a service, creating opportunities for unauthorized access. Rogue devices and shadow IT bypass normal approval, monitoring, patching, and configuration standards. Wireless, low-pow...
Episode 36 — Code Weaknesses: Hardcoded Secrets and Unsafe Exception Handling (2.4) 27.04.2026 15:05
This episode explains two code-level weaknesses that frequently create preventable security problems: hardcoded secrets and unsafe exception handling. Hardcoded passwords, API keys, tokens, certificates, and database credentials are dangerous because they may be exposed through repositories, logs, backups, shared scripts, compiled applications, or insider access. Unsafe exception handling can reve...
Episode 35 — Ports, Services, Applications, Race Conditions, and Malicious Updates (2.4) 27.04.2026 15:18
This episode covers several common sources of technical exposure, including open ports, unnecessary services, vulnerable applications, race conditions, time-of-check/time-of-use weaknesses, and malicious updates. Students should understand that attackers look for services that should not be exposed, applications that are poorly maintained, and timing flaws that allow an action to change between va...
Episode 34 — Unsupported, Unpatched, Obsolete, and Unmanaged Systems (2.4) 27.04.2026 15:58
This episode explains why unsupported, unpatched, obsolete, and unmanaged systems create serious attack surface risk. Unsupported systems may no longer receive security updates, unpatched systems may remain vulnerable to known exploits, obsolete systems may rely on weak protocols or outdated dependencies, and unmanaged systems may be invisible to normal monitoring and inventory processes. For Secu...
Episode 33 — Supply Chain, SaaS, USB, Human, IoT, OT, Physical, Bluetooth, RF, and NFC Threats (2.3) 27.04.2026 17:04
This episode explains how attack paths often begin outside an organization’s directly managed systems. Students should understand supply chain risks involving third-party providers, managed service providers, logistics providers, SaaS platforms, contractors, and visitors. The episode also covers malicious USB devices, IoT devices, operational technology, physical access, Bluetooth, radio frequency...
Episode 32 — Network, Remote Access, and Endpoint Threat Sources (2.3) 27.04.2026 15:44
This episode covers threat sources connected to infrastructure devices, virtualized systems, session keys, remote desktop, VNC, VPNs, mobile devices, servers, tablets, trusted devices, and built-in administrative tools. For the exam, students should recognize that attackers often target normal access paths rather than using unusual traffic that is easy to detect. Remote access services can expose...
Episode 31 — Browser-Based Attacks: Extensions, JavaScript, Cookies, Password Managers, and Session Tokens (2.3) 27.04.2026 15:05
This episode explains why the browser is a major attack surface in modern environments and how attackers target the tools users rely on every day. Students should understand how malicious browser extensions can collect data, inject content, or abuse permissions, while JavaScript can be used for malicious redirects, credential theft, or exploitation of vulnerable web applications. Cookies and sessi...
Episode 30 — Image and Attachment Attacks: QR Codes, CAPTCHA Abuse, Macros, PDFs, and RTF (2.3) 27.04.2026 14:24
This episode explains how attackers use familiar images and file types to deliver malicious content or manipulate user trust. QR-code attacks can move users from a protected screen to a malicious site on a personal device. CAPTCHA abuse may make a fraudulent page look more legitimate or delay automated analysis. Macros, PDFs, and RTF documents can contain embedded content, scripts, links, or explo...
Episode 29 — Message-Based Attacks: Email, SMS, RCS, IM, and Collaboration Tools (2.3) 26.04.2026 14:28
This episode covers message-based attacks delivered through email, SMS, Rich Communication Services, instant messaging, and collaboration platforms. Students should understand that attackers target the communication channels users already trust, especially when those channels support links, attachments, identity cues, urgency, and quick responses. Exam scenarios may include phishing emails, smishi...
Episode 28 — APTs and the Modern Threat Vector Map (2.3) 26.04.2026 15:25
This episode introduces advanced persistent threats and uses them as a bridge into the broader Security+ threat vector landscape. An advanced persistent threat is typically associated with capable actors who use stealth, patience, planning, and repeated access attempts to achieve long-term objectives. For the exam, students should understand that persistence and quiet access can matter as much as...
Episode 27 — Motivations and Capabilities: Money, Espionage, Ideology, and Extortion (2.2) 26.04.2026 15:13
This episode connects attacker motivations to tactics, target selection, persistence, and expected impact. Financially motivated attackers may focus on ransomware, payment fraud, credential theft, or data resale. Espionage-driven attackers may seek intellectual property, government information, business strategy, or sensitive communications. Ideological attackers may deface sites, leak data, or di...
Episode 26 — State-Sponsored, Competitors, Accidental, and Unskilled Attackers (2.2) 26.04.2026 14:41
This episode explains additional threat actor types, including state-sponsored actors, competitors, accidental users, and unskilled attackers. State-sponsored actors may have funding, patience, specialized tools, and long-term intelligence or disruption goals. Competitors may seek business advantage through espionage, data theft, or unethical information gathering. Accidental users create security...
Episode 25 — Threat Actors: Organized Crime, Terrorists, Hacktivists, and Insiders (2.2) 26.04.2026 14:21
This episode introduces major threat actor categories and explains how their goals and behavior differ. Organized crime groups often pursue financial gain through fraud, ransomware, data theft, and extortion. Terrorist actors may seek disruption, fear, attention, or damage to critical services. Hacktivists usually act from ideological or political motivation, using attacks to embarrass, disrupt, o...
Episode 24 — Vulnerability Types and Risk-Based Decisions (2.1) 26.04.2026 15:22
This episode covers common vulnerability types across software, configuration, identity, cloud, and operational processes. Students should recognize that vulnerabilities may come from missing patches, insecure defaults, exposed services, weak passwords, excessive permissions, flawed code, misconfigured storage, unsupported systems, or poor procedures. For the exam, the goal is to connect the type...
Episode 23 — Vulnerability Scoring: CVSS, CVEs, and Prioritization (2.1) 26.04.2026 13:48
This episode explains CVEs and CVSS as common tools for identifying and scoring vulnerabilities. A CVE is a public identifier for a known vulnerability, while CVSS provides a scoring method that helps describe severity using factors such as exploitability, impact, complexity, and required privileges. For Security+ questions, students should remember that a high CVSS score does not always mean the...
Episode 22 — Threat Feeds and Intelligence Sources (2.1) 26.04.2026 13:44
This episode covers threat feeds and intelligence sources as tools that help security teams understand which threats matter most. Students should recognize sources such as advisories, vendor reports, information-sharing groups, open-source intelligence, commercial feeds, internal telemetry, and security research. For the exam, the key idea is that intelligence supports prioritization by adding con...
Episode 21 — Threats vs. Vulnerabilities: Likelihood, Impact, and Life Cycle (2.1) 26.04.2026 14:58
This episode explains the difference between a threat, a vulnerability, and risk, which is essential for understanding Security+ scenarios. A threat is something that could cause harm, a vulnerability is a weakness that could be exploited, and risk combines likelihood with impact. Students should understand that a vulnerable system is not automatically the highest priority unless there is exposure...
Episode 20 — Hashing, Salting, Digital Signatures, Obfuscation, and Crypto Tools (1.3) 26.04.2026 14:34
This episode explains several cryptographic concepts that are often confused on the exam. Hashing creates a fixed output used to verify integrity, while salting adds unique random data before hashing passwords to make precomputed attacks harder. Digital signatures support authentication, integrity, and non-repudiation by proving that data was signed with a private key and has not been altered. Obf...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.