HelloInfoSec

InfoSec Bites

Welcome to Hello InfoSec, your ultimate hub for all things cybersecurity! Dive into our thrilling podcast series, InfoSec Bites, where we unleash deep dives into Information Security, jaw-dropping Major Security Incidents, cutting-edge Cloud Information Security, crucial Privacy topics, revolutionary Artificial Intelligence, mind-bending Quantum Computing, and so much more! Get ready to geek out with expert insights and stay ahead of the curve—hit that like button, subscribe now, and turn on notifications for fresh episodes that will blow your mind! https://www.youtube.com/@HelloInfoSec

Author

HelloInfoSec

Category

Technology

Podcast website

www.youtube.com

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

OAIC vs Australian Clinical Labs: Establishment of Australia's Privacy Enforcement Benchmark 18.10.2025

The dicussion in this podcast details the landmark legal proceedings and outcome against Australian Clinical Labs (ACL) concerning a February 2022 data breach involving its acquired subsidiary, Medlab Pathology. The Australian Federal Court ordered ACL to pay $5.8 million in civil penalties for multiple breaches of the Privacy Act 1988 (Cth), marking the first such penalty under the Act. Specifica...

The AI Crawler Bots Arms Race: Threat Report 17.10.2025

The dicussion in this podcast provides an extensive threat report from 2025 detailing the "AI Crawler Arms Race," which is driven by the urgent need for vast, quality data to train Large Language Models (LLMs). The report explains that traditional bots are being rapidly replaced by highly adaptive, AI-driven crawlers , including Deep Reinforcement Learning (DRL) bots and Autonomous AI Ag...

NIST PQC: The Race for Post-Quantum Standards 16.10.2025

The discussion in this podcast provides an extensive overview of the National Institute of Standards and Technology (NIST) Post-Quantum Cryptography (PQC) standardisation process , which was initiated to combat the existential threat posed by future quantum computers to current public-key algorithms like RSA and ECC. NIST’s multi-year effort, which began in 2016, culminated in the selection of a d...

Active Directory, EntraID, Azure AD: MS Identity Services Architecture, Security & Incidents 15.10.2025

The podcat discussion provides a comprehensive security audit of Microsoft's identity services, comparing the architecture, protocols, and vulnerabilities of three distinct platforms: Active Directory Domain Services (AD DS) , the legacy on-premises solution; Active Directory Federation Services (ADFS) , the traditional federation server; and Entra ID (formerly Azure AD) , the cloud-native ide...

OpenSSL: Architecture, Agility, and Quantum Resilience 14.10.2025

The discussion in this podcast provides an extensive audit of the OpenSSL 3.x toolkit, focusing on its architecture, strategic agility, and quantum resilience. It highlights that the shift to the modular Provider concept in OpenSSL 3.x is a critical evolution enabling cryptographic agility, particularly for the transition to Post-Quantum Cryptography (PQC) using hybrid key exchange schemes in TLS...

AWS Security: An Exhaustive Analysis of its Defense in Depth Architecture 13.10.2025

The podcast discusses an extensive analysis of the Amazon Web Services (AWS) security architecture, focusing on its implementation of the Defense in Depth (DiD) strategy through a multi-layered framework . It establishes the Shared Responsibility Model as the foundational security principle, clearly separating AWS's responsibility for the "Security of the Cloud" from the customer&#39...

HTTP/2 Deep Dive: Architecture, Security, Vulnerabilities & Quantum Threat 12.10.2025

The discussion in this podcast provides an extensive analysis of the HTTP/2 protocol , detailing its architectural shift from the text-based HTTP/1.1 to a more efficient binary and stateful framework using features like multiplexing and HPACK header compression. It thoroughly explains how these performance-enhancing changes, which solve application-layer Head-of-Line (HOL) blocking, simultaneously...

ISO 27001: Strategic Information Security Framework 11.10.2025

The discussion in this podcast provides an extensive overview of the ISO/IEC 27001:2022 standard , which serves as the international framework for an Information Security Management System (ISMS). It explains that the standard is a strategic, risk-driven approach built upon the core principles of Confidentiality, Integrity, and Availability (CIA) , rather than a mere technical checklist. It detail...

AWS ELB, Route 53, and CloudFront Deep Dive 10.10.2025

This podcast provides a comprehensive architectural and security analysis of three core AWS global delivery services: Elastic Load Balancing (ELB) , Amazon Route 53 (DNS) , and Amazon CloudFront (CDN) . It explains the foundational mechanics of each service, detailing how ELB leverages the Hyperplane for scaling, how Route 53 uses an Anycast data plane for global resilience, and how CloudFront rel...

SolarWind's Supply Chain Espionage: How Sunburst Attack Shattered Digital Trust 09.10.2025

The discussion in this podcast provides an extensive analysis of the SolarWinds cyber incident , detailing how the sophisticated, state-sponsored attack leveraged the software supply chain to compromise thousands of customers, including critical U.S. government agencies. The operation, formally attributed to Russia's Foreign Intelligence Service (SVR) , involved a meticulous infiltration of SolarW...

Pillars of Cyber Risk : Vectors, Surface, Appetite, Tolerance 06.10.2025

The podcast provides a comprehensive discussion on the Governance, Risk, and Compliance (GRC) Nexus , specifically exploring four foundational cybersecurity concepts. It first defines the threat landscape from an attacker’s perspective, distinguishing between an Attack Vector , which is the specific method of exploitation (e.g., phishing), and the Attack Surface , which is the totality of an organ...

CISSP Domain-8: Software Development Security 05.10.2025

The dicussion in this podcast offers a comprehensive overview of Software Development Security , covering the Software Development Life Cycle (SDLC) and various Development Methodologies . The text systematically explains the phases of the SDLC—including requirements gathering, design, development, testing, and operations and maintenance—while stressing the importance of integrating security at ev...

Capital One Cloud Breach: Misconfigured WAF and Least Privilege Principle Violation 04.10.2025

The podcast discusses post-mortem analysis of the 2019 Capital One cloud breach , detailing the technical, human, and systemic failures that allowed for the compromise of approximately 106 million individuals' data. It explains that the attack was successful due to a misconfigured Web Application Firewall (WAF) and the violation of the Principle of Least Privilege , which allowed an attacker t...

JFrog Artifactory: DevSecOps, Binary Repository Management and Image Security 02.10.2025

The discussion in this podcast provides a comprehensive security overview of JFrog Artifactory , a critical and foundational component acting as a universal binary repository manager within the software supply chain. It explains Artifactory's core architecture , including its server, database, and various repository types (local, remote, virtual), and emphasizes its indispensable role in DevOp...

CISSP Domain-7: Security Operations 01.10.2025

The podcast discussions details critical aspects of maintaining an organisation's security posture and operational resilience. The discussion covers security operational controls such as auditing and logging , enforcing least privilege and separation of duties , and implementing change management and configuration management practices to maintain system integrity. A significant portion address...

CISSP Domain-6: Security Assessment and Testing 30.09.2025

This discussion in the podcast provides an extensive overview of security assessments, testing, and audits , detailing the processes necessary to evaluate an organization's security posture. It explains the differences between vulnerability testing, penetration testing, and formal audits , including various testing methodologies like black box, white box, and gray box approaches. Furthermore,...

Australian Privacy Principles: Deep Dive for InfoSec Professionals 29.09.2025

The podcast dicussion provides an extensive analysis of the Australian Privacy Principles (APPs) , which constitute the core legal framework for data protection under Australia's Privacy Act 1988. It functions as a strategic guide for Information Security (InfoSec) professionals , breaking down the thirteen legally binding principles that govern how most government agencies and private organis...

CISSP Domain-5: Identity and Access Management (IAM) 28.09.2025

The dicussion in this podcast provides an extensive overview of Identity and Access Management (IAM) concepts, focusing on the critical phases of identification, authentication, and authorization within secure systems. They detail various authentication methods, including passwords, multi-factor authentication (MFA), and biometrics , explaining the mechanics and weaknesses of each. A significant p...

ISO 27005: A Strategic Deep Dive into Information Security Risk Management 27.09.2025

The discussion in this podcast provides an extensive comparative analysis of two leading information security risk management methodologies: the ISO/IEC 27005 standard and the NIST Risk Management Framework (RMF) . It establishes that modern organisations require a proactive, systematic approach to manage persistent cyber threats and details the philosophical differences, with ISO 27005 being a fl...

CISSP Domain-4: Communication and Network Security 27.09.2025

The discussion in this podcast provides an extensive overview of networking fundamentals and secure communication channels , primarily focusing on the foundational concepts and technologies within the OSI and TCP/IP models. Key discussions includes the layers of the OSI model (Application, Presentation, Session, etc.) and their functions, as well as a detailed examination of IP addressing (IPv4 an...

CISSP Domain-3: Architectures, Cryptography, and Physical Security. 27.09.2025

The podcast disucssion offers an expansive overview of various information technology (IT) and operational technology (OT) concepts, covering system architectures, cryptology, and security architecture design principles. The discussion initially details system architectures , explaining multi-tier server-based systems and the security implications of Industrial Control Systems (ICS) , where safety...

CISSP Domain-2: Asset Security 27.09.2025

The discussion in this podcast provides a comprehensive overview of asset and data security , focusing heavily on information as an organisation's most valuable asset . The podcast details the data life cycle —from acquisition to destruction—and stresses the critical importance of data classification based on sensitivity and criticality to determine appropriate security controls . Furthermore,...

CISSP Domain-1: Security, Risk, and Compliance Management 27.09.2025

In this podcast we discuss a comprehensive overview of cybersecurity governance, risk management, and compliance within an organizational context. It explores the foundational concepts of the CIA triad (confidentiality, integrity, and availability) , along with authenticity and nonrepudiation, and details the development of an enterprise-wide security program supported by management. Furthermore,...

AWS GuardDuty: Threat Hunting Beyond Alerts, Architecture and Incidents 25.09.2025

The discussion in this podcast provides a comprehensive analysis of Amazon GuardDuty , an intelligent, fully managed threat detection service within the AWS ecosystem. It explains the service's multi-layered architecture , which combines machine learning, anomaly detection, and curated threat intelligence feeds to monitor core data sources like CloudTrail and VPC Flow Logs. The discussion stre...

XSS, CSRF, and SSRF Analysis: Web Application Forgeries. 24.09.2025

The podcast discussion provides an extensive analysis of three major web application security flaws: Cross-Site Scripting (XSS) , Cross-Site Request Forgery (CSRF) , and Server-Side Request Forgery (SSRF) . It explains that these attacks exploit weaknesses in the web's foundational trust relationships, with XSS compromising user trust, CSRF exploiting the website's trust in the browser, and SSRF l...

Listen to the InfoSec Bites podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.