HelloInfoSec
InfoSec Bites
Welcome to Hello InfoSec, your ultimate hub for all things cybersecurity! Dive into our thrilling podcast series, InfoSec Bites, where we unleash deep dives into Information Security, jaw-dropping Major Security Incidents, cutting-edge Cloud Information Security, crucial Privacy topics, revolutionary Artificial Intelligence, mind-bending Quantum Computing, and so much more! Get ready to geek out with expert insights and stay ahead of the curve—hit that like button, subscribe now, and turn on notifications for fresh episodes that will blow your mind! https://www.youtube.com/@HelloInfoSec
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
The Architecture of Isolation: Virtualization Security and Cloud Exploits 28.01.2026 36:19
In this podcast we examine the critical evolution of virtualisation security within modern cloud environments, highlighting how the hypervisor acts as a vital yet vulnerable point of isolation. It details the transition from complex software emulators to minimalist hardware-assisted architectures designed to reduce potential attack surfaces. By reviewing landmark breaches such as VENOM and...
SS7 Attacks: Decade Old Flow In Your Phone, Vulnerabilities, Exploitation, and Remediation 23.01.2026 42:45
The dicussion provides a detailed expert analysis of the Signaling System 7 (SS7) protocol , identifying it as a foundational yet profoundly vulnerable component of global telecommunications infrastructure. Built on a legacy assumption of a closed and trusted network, SS7 lacks essential security features like encryption and authentication , making it susceptible to widespread exploitation. The di...
Security Architectures: Zero Trust vs Defence in Depth 16.01.2026 28:21
The podcast dicussion provides an extensive comparative analysis of two major cybersecurity paradigms: Defence in Depth (DiD) and Zero Trust Architecture (ZTA) . It explains that traditional DiD, which relies on a layered, location-centric approach with an implicit trust zone once the perimeter is breached, is strategically inadequate for modern distributed environments due to the risk of uncontai...
Salesforce/Salesloft Cyber Incident 2025: Identity and API Crisis Analysis 09.01.2026 36:14
The dicussion in this podcast provides an extensive post-mortem and strategic analysis of the 2025 Salesforce/Salesloft cyber incident , attributed to the threat actor UNC6395, which exposed a critical failure in SaaS supply chain security . The attack circumvented perimeter defenses by compromising the vendor’s infrastructure to steal pre-authorised OAuth tokens , granting the attackers persisten...
MFA Fatigue and Social Engineering Cyber Incidents 26.12.2025 29:48
The discussion in this podcast is about analyzing the rise of Multi-Factor Authentication (MFA) fatigue as a critical new cyber threat, detailing how attackers exploit the human element through social engineering rather than technical flaws. It examines five high-profile 2022 breaches at major companies— Uber, Cisco, Okta, Twilio, and Microsoft —to illustrate the success of this low-tech approach,...
Willow Processor: Fault Tolerance and Verifiable Quantum Advantage 19.12.2025 32:20
This podcast primarily discusses Google’s advancements in processor technology, focusing on the Willow quantum chip and the Tensor series of system-on-chip (SoC) processors . Multiple articles highlight the Willow chip as a significant milestone in quantum computing due to its development of fault tolerance and demonstrated error correction capabilities , potentially solving problems far e...
Cybersecurity Strategies 2025: Attack, Defence, and Future Trends 12.12.2025 44:19
This comprehensive summary outlines in this podcast is about the 4th Edition of "Cybersecurity Attack and Defense Strategies" (2025) by Yuri Diogenes and Erdal Ozkaya, a guide for cybersecurity professionals. It addresses the dynamic and perilous cybersecurity environment of 2025 , highlighting the expansion of the attack surface due to digital transformation and the sophisticated method...
Federal Information Processing Standards(FIPS): Security, Adoption, and Key Standards 05.12.2025 39:38
The discussion in this podcast offers a comprehensive overview of Federal Information Processing Standards (FIPS) , which are guidelines developed by the National Institute of Standards and Technology (NIST) to ensure security, interoperability, and data protection across U.S. federal computer systems. FIPS standards are mandatory for federal agencies under laws like FISMA and serve as a crucial f...
FIDO2: Deep Dive into The New Passwordless Authentication Standard 28.11.2025 29:07
The discussion in this podcast provides an extensive, expert-level overview of FIDO2 , which is presented as the new gold standard for passwordless authentication . It explains that FIDO2 fundamentally replaces the vulnerable "shared secret" password model with a cryptographic public-key system , where a private key is securely stored on the user's device, making it inherently resist...
Virtualisation and VDI: Architecture, Security, Exploitation, and Resilience 21.11.2025 37:45
The discussion in this podcast provides an extensive analysis of the security challenges, exploitation techniques, and resilience strategies necessary for modern Virtual Machine (VM) and Virtual Desktop Infrastructure (VDI) environments . It details the fundamental security trade-offs between Type 1 (bare metal) and Type 2 (hosted) hypervisors , noting that enterprise solutions mandate the superio...
Eternal Blue & WannaCry: How NSA secret leaked & Cost the world $10B 14.11.2025 50:23
The interesting discussion in this podcast provides a comprehensive post-mortem of the EternalBlue cyber crisis, focusing primarily on the devastating WannaCry and NotPetya attacks of 2017. They explain that the root cause was the National Security Agency (NSA) developing and stockpiling the EternalBlue exploit, which was subsequently leaked by the Shadow Brokers hacking group. The discussion anal...
Cozy Bear's(APT29) Quiet Espionage Against the DNC 07.11.2025 33:03
The discussion in this podcast provide an extensive analysis of the Russian threat actor Cozy Bear (APT29) , focusing on its sophisticated cyber espionage operations. The first source concentrates on the 2020 SolarWinds supply chain attack , detailing how the group injected the Sunburst backdoor into legitimate software updates to compromise numerous organizations, including U.S. government entiti...
Due Diligence and Due Care in Security Governance 03.11.2025 29:33
The dicussion in this podcast provides an exhaustive analysis of Due Diligence (DD) and Due Care (DC) , presenting them as the dual legal and operational pillars of robust security governance, particularly in the context of the CISSP certification. Due Diligence is defined as the strategic, investigative, and planning phase, focusing on foresight, risk assessment, and establishing security policie...
Jaguar Land Rover 2025 Cyber Failure: Resilience and IT/OT Breakdown 01.11.2025 35:50
This podcast dicussion provides an extensive post-mortem analysis of the Jaguar Land Rover (JLR) Cyber Incident of 2025 , which caused an estimated £1.9 billion in economic damage and crippled production for approximately 40 days. The analysis attributes the crisis not to a sophisticated new exploit, but to systemic operational resilience failures , particularly catastrophic weaknesses in Identity...
SIEM, SOAR, EDR, and DLP: The Integrated Cybersecurity Ecosystem 30.10.2025 1:05:32
The dicussion in this podcast provides an extensive overview of the integrated cybersecurity ecosystem , detailing the four foundational pillars necessary for a modern Security Operations Center (SOC). It comprehensively examines Security Information and Event Management (SIEM) as the central command post for data aggregation and threat detection, and Security Orchestration, Automation, and Respon...
Single Sign-On(SSO) Protocols: Kerberos, SAML, OAuth, and OpenID Connect 29.10.2025 49:02
The discussion in this podcast is an expert-level analysis of four critical Single Sign-On (SSO) protocols: Kerberos, SAML, OAuth, and OpenID Connect (OIDC) , detailing their architectures, security features, and ideal use cases within a modern enterprise. It explains that while Kerberos is best for internal networks and SAML for enterprise federation, OAuth is for delegated API authorization, whi...
Overflow, RCE, and MITM Attacks: Advanced Cyber Threats 27.10.2025 37:09
The discussion in this podcast provides an extensive analysis of three major categories of cyber threats: Buffer Overflow , Remote Code Execution (RCE) , and Man-in-the-Middle (MITM) attacks. It systematically examines the mechanics of each attack type, from the foundational memory corruption of buffer overflows to the network-based deception used in MITM attacks. It emphasizes that while technica...
Australia's Cyber Security Act 2024: Analysis and Impact 26.10.2025 35:42
The dicussion in this podcast provides an exhaustive analysis of the Australian Cyber Security Legislative Package of 2024, a major government overhaul shifting the nation from a voluntary to a mandatory cyber security posture driven by high-profile systemic failures. This package is composed of three principal acts: the Cyber Security Act 2024 (CSA 2024) , the Security of Critical Infrastructure...
AWS US-EAST-1 Outage: Cascading Failure and Systemic Fragility 25.10.2025 40:28
The podcast discussion provides an extensive forensic analysis of the Amazon Web Services (AWS) US-EAST-1 outage in October 2025 , attributing the initial failure to a latent race condition within the DynamoDB Domain Name System (DNS) management automation. The analysis details how this localised regional DNS failure resulted in a global operational paralysis because critical worldwide services, s...
OAIC and ACSC: Australian Cyber Preparedness and Response Benchmarks 24.10.2025 32:11
The discussion on this podcast is an extensive analysis of the Australian cyber security benchmarks established by the Federal Court's landmark judgment against Australian Clinical Labs (ACL) under the Privacy Act 1988 . This judgment effectively converted guidance from the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC) into mandatory l...
Quantum World Congress 2025: Summary and Key Themes 22.10.2025 34:11
The podcast provides an extensive overview of the rapidly advancing field of quantum technology, focusing heavily on the Quantum World Congress 2025 event and the technical roadmaps of major industry players. A core theme is the shift from theoretical science toward commercialization and real-world deployment , particularly in areas like climate solutions, finance, and security . It detail the pro...
Optus Data Breach: A Deep Analysis of Broken API & Corporate Negligence 21.10.2025 40:59
The discussion in this podcast provides a deep analysis of the 2022 Optus data breach, describing it as a failure of national significance in Australia that exposed the personal information of up to ten million current and former customers. This extensive topic discusses how the breach was not a sophisticated attack but rather the exploitation of a basic and long-standing security flaw in an unaut...
Medibank Cyber Incident 2022: Analysis and Lessons Learned 20.10.2025 32:56
The dicussion in this podcast offers a comprehensive overview of the Medibank cyber incident in 2022 , detailing the catastrophic data breach suffered by Australia's largest health insurer, affecting approximately 9.7 million current and former customers . The breach, linked to Russian national Aleksandr Gennadievich Ermakov and the REvil ransomware group, was primarily enabled by critical sec...
Qantas 2025 Cyber Attack: Supply Chain Attack and Incident Response 19.10.2025 29:30
This podcast discussion provides a comprehensive overview of the Qantas data breach that occurred in July 2025, which compromised approximately 5.7 to 6 million customer records through the exploitation of a third-party customer service platform . Several sources confirm that the attack was attributed to the threat actor group Scattered Spider and involved social engineering tactics like Multi-Fac...
REST APIs and Webhooks: Architecture and Security Deep Dive 18.10.2025 42:39
The discussion in this podcast provides an expert-level analysis of two foundational architectural paradigms in digital communication: REST APIs and Webhooks , emphasizing that they are complementary, not competitive, technologies. It explains that REST APIs operate on a pull-based, stateless model ideal for on-demand data retrieval, while Webhooks use a push-based, event-driven mechanism for real...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.