Eric Lamanna
SEC.co Podcast
A podcast about latest trends, techniques and learnings in cybersecurity and cyberdefense.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
BIOS and UEFI Rootkits: What Infrastructure Teams Need to Know 17.06.2026 8:42
Most security playbooks treat the operating system as the lowest layer worth defending. Firmware rootkits prove that assumption wrong — and they do it quietly, surviving disk wipes and clean installs without blinking. This episode of Cybersecurity draws on this BIOS and UEFI rootkit primer for modern infrastructure teams to walk through one of the most persistent and underestimated threat categori...
Binary Provenance and SBOM Verification in Practice 16.06.2026 8:30
Modern software delivery moves fast — but speed and trust don't always travel together. This episode of Cybersecurity tackles one of supply chain security's most pressing questions: once a binary lands in your environment, how do you actually know it is what it claims to be? Drawing on this in-depth 10-minute read on binary provenance and SBOM verification , the episode translates concepts that to...
Bare-Metal Backdoors: Detecting Persistent Firmware-Level Implants 15.06.2026 8:46
Most incident responders have been burned by a threat that simply refused to die — reimaged machines, rolled-back drivers, a clean incident report, and then the attacker is back three weeks later on the same hardware. This episode of Cybersecurity tackles the reason that happens: persistent firmware-level implants that live below the operating system, below the hypervisor, and well below everythin...
Autonomous Agents as Threat Actors: Simulating Persistent AI Adversaries 14.06.2026 8:04
The threat landscape has quietly crossed a threshold. Autonomous AI agents are no longer a theoretical risk — they're appearing in real intrusion reports, behaving less like malware and more like tireless, self-directed adversaries. This episode of Cybersecurity draws on this seven-minute deep dive into AI adversary simulation to unpack what that shift means for defenders and what practical steps...
Locking Down Android Enterprise: Work Profiles and App Attest Explained 12.06.2026 9:17
Mobile devices are among the least-hardened assets in most corporate environments, yet they sit on the same networks and touch the same data as the endpoints security teams obsess over. This episode of Cybersecurity takes a close look at Android Enterprise — drawing on the Android Enterprise hardening and app attestation guide published by SEC — to walk through what a genuinely robust mobile secur...
AI-Powered Malware: How Machine Learning Became a Weapon Against You 11.06.2026 7:45
The cyber arms race has entered a new phase, and the advantage is shifting. Attackers are no longer just writing malicious code and hoping it slips through — they're weaponizing the same machine learning techniques that defenders rely on, turning AI into an instrument of evasion, deception, and automation. This episode of Cybersecurity examines how that shift is playing out in real-world attacks a...
AI-Powered Behavioral Analytics: How SOC Teams Fight Smarter 10.06.2026 7:45
Modern Security Operations Centers face a paradox: the more alerts their tools generate, the harder it becomes to spot a genuine threat. This episode of Cybersecurity examines how AI-powered behavioral analytics is reshaping the way SOC teams detect, prioritize, and respond to attacks — drawing on this practical four-minute deep dive on AI behavioral analytics for SOC teams to ground the conversat...
Adversarial Machine Learning: How Attackers Are Fooling AI 08.06.2026 8:21
Artificial intelligence has become a cornerstone of modern cybersecurity tooling — but it carries a category of vulnerability that most organizations are dangerously underprepared for. This episode of Cybersecurity examines adversarial machine learning: the discipline of deliberately manipulating AI models into making wrong decisions, often through changes so subtle that no human observer would no...
AI vs. AI: Machine Learning as Both Cyber Weapon and Shield 05.06.2026 7:40
Cybersecurity has entered a new era defined not by individual hackers or static malware, but by artificial intelligence fighting artificial intelligence at a scale and speed no human team can match alone. This episode of Cybersecurity examines the double-edged nature of machine learning — drawing on this six-minute deep dive into how ML is both a cybersecurity threat and a solution — to map out ex...
Adversarial Machine Learning: How Attackers Are Breaking AI 04.06.2026 7:55
Machine learning models power some of the most sensitive decisions in modern security — from malware detection to fraud prevention to autonomous systems. But beneath the surface, these models carry a structural fragility that attackers are actively learning to exploit. This episode of Cybersecurity explores adversarial machine learning: the growing discipline of deliberately manipulating AI system...
Bare Metal Backdoors: Detecting Persistent Firmware-Level Implants 30.05.2026 8:47
Firmware-level implants represent one of the most persistent and difficult-to-detect threats in modern cybersecurity. In this episode, we break down a recent deep dive from the SEC.co cybersecurity blog — specifically the analysis titled Bare Metal Backdoors: Detecting Persistent Firmware-Level Implants — exploring how adversaries plant code beneath the operating system and what defenders can do t...
Cloud Egress Control: Policy-as-Code Best Practices for Cybersecurity Teams 22.05.2026 15:01
Episode summary: Cloud runtimes are noisy neighbors. They spin up, scale out, pull containers in the middle of the night, and sometimes try to befriend the entire internet. Every outbound request is a potential exfiltration lane, a misrouted secret, or a compliance liability. In this episode, we take the SEC.co article "Cloud Egress Control Best Practices: Policy-as-Code" and expand it into a comp...
How to Use OpenTelemetry Traces for Threat Detection and Cloud Security Monitoring 21.05.2026 11:34
Traditional logs and metrics catch pieces of an attack, but traces tell the full story. In this episode, we explore how OpenTelemetry traces transform cloud security monitoring by linking events into narratives that expose attacker intent. Based on a recent article from SEC.co, we cover: Why traces deserve a seat at the security table alongside logs and metrics Latency as a lie detector — how timi...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.