Cybersecurity Under Pressure. Real Attacks, Real Lessons

Cybersecurity Under Pressure. Real Attacks, Real Lessons

Antonio González
Land Vereinigte Staaten
Genres Technologie
Sprache EN
Folgen 67
Letzte 09.10.2026

This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice. Each episode analyzes a recent attack, explains the technical mechanics in clear language, and translates them into concrete lessons for security, engineering, and business teams. Topics covered include OT security, ICS cybersecurity, industrial control systems, critical infrastructure protection, NIS2 compliance, Zero Trust architecture, operational technology resilience, railway cybersecurity, automotive security, and cyber-physical systems.

Folgen

  • Automotive Cybersecurity Evidence: Maintaining Vehicle Type Approval 09.10.2026 1Std. 40Min.
    Cybersecurity evidence cannot stop at the supplier handoff. This episode examines how threat analysis, risk treatment, validation results, configuration records, and incident evidence must remain connected to vehicle type approval throughout the lifecycle. We explore what regulators, manufacturers, and suppliers need in order to prove that cybersecurity claims still hold when software, components, and operational conditions change.Chapters:00:00 Context and central question20:21 The Technical Breakdown39:20 The Operational Decisions59:48 The Pressure Test01:18:16 The Key TakeawaysRelated CUP episodes:Automotive Supply Chains: Who Owns the Cybersecurity Fix?SBOM and VEX: Challenging Supplier Vulnerability ClaimsAutomotive Software Releases: When Security Rejects the CodeEspressif Secure Boot: Where Firmware Trust Can BreakSBOM and VEX: Turning Vulnerability Data into OT Risk DecisionsNIST IR 8536: Verifying the Software Supply ChainNIS2 Supplier Security: When Compliance Costs Become a RiskECU Flashing Security: The Evidence Needed Before Production
  • OT Vendor VPN Security: Closing Hidden Maintenance Paths | CUP Focus 08.10.2026 3Min.
    A VPN can authenticate a supplier while still bypassing the architecture intended to protect production. This CUP Focus shows how flat VLANs, direct Level 1 access and encrypted blind spots can turn legitimate maintenance into an invisible attack path.Related CUP episodes:Legacy VPNs in OT: Remote Access and the Cost of DisruptionOT Remote Access: Closing the Path When the Work EndsOT Session Hijacking: Revoking Trusted Engineering AccessOT Remote Access: Securing the Path to Physical Control
  • Software Supply Chain Provenance: Beyond the Version Number | CUP Micro Brief 08.10.2026 1Min.
    A component name and version do not prove provenance. This CUP Micro Brief explains how pedigree, cryptographic hashes and a verifiable chain of custody can help identify tampered code before it enters the build.Related CUP episodes:NIST IR 8536: Verifying the Software Supply ChainSBOM and VEX: Turning Vulnerability Data into OT Risk DecisionsSBOM and VEX: Challenging Supplier Vulnerability ClaimsSecurity Scanner Supply Chains: The Trivy and CERT-EU Case
  • SBOM and VEX: Turning Vulnerability Data into OT Risk Decisions 07.10.2026 1Std. 31Min.
    A software inventory cannot tell you which vulnerability threatens production. Explore how SBOM, VEX, exploitability and deployment context support defensible treatment decisions in cyber-physical systems. Learn what evidence suppliers and operators need before accepting, mitigating or patching a vulnerability.Chapters:00:00 Context and central question18:10 The Technical Breakdown34:30 The Operational Decisions51:46 The Pressure Test01:09:46 The Key TakeawaysMore analysis: https://cybersecurityunderpressure.com/Related CUP episodes:When VEX Becomes a Bureaucratic ShieldNIST IR 8536: Verifying the Software Supply ChainCyber Gaps in Automotive SupplyNIS2 Supplier Security: When Compliance Costs Become a RiskSupported Hardware, Vulnerable Software: The Hidden Lifecycle Risk in Industrial FirewallsOT Supplier Risk: Building Resilience Without Vendor CooperationA Critical CVE Is Not an Attack Path: Assessing PLCnext Risk in the Plant
  • When 40 Milliseconds Become an OT Incident | CUP Micro Brief 06.10.2026 2Min.
    Forty milliseconds can turn a wireless disruption into a physical process failure. This CUP Micro Brief connects industrial 5G latency, device isolation and the identity gap between telecom authentication and industrial control.Related CUP episodes:Stopping Stealthy Radio Jamming in Industrial 5G: When the Air Interface Becomes the Attack SurfaceIndustrial 5G and the Uptime Trap: When Connectivity Becomes a Production RiskWhy FRMCS Cannot Trust the Mobile Carrier
  • The Flashing Station Is a Product Trust Boundary | CUP Focus 06.10.2026 3Min.
    A compromised flashing station can turn a factory incident into a fleet-wide product integrity problem. This CUP Focus follows the trust chain from plant server to diagnostic tool, ECU firmware and secure boot.Related CUP episodes:Missing Cybersecurity Evidence Can Delay ProductionWhy Signed Firmware Is Still Vulnerable: The Trust Chain Behind the SignatureWhen ECUs Meet MalicePoisoning the Software Defined Vehicle at BirthEspressif Secure Boot: Where Firmware Trust Can BreakWhen the Automotive Update Path Becomes the Attack PathShipping the Code That Security Rejected
  • Cyber Resilience Act: Making the 24-Hour Reporting Decision 05.10.2026 1Std. 20Min.
    How do manufacturers make a defensible reporting decision while the technical evidence is still incomplete? Explore decision authority, supplier escalation and evidence preservation under the Cyber Resilience Act. The focus is on preparing engineering, product-security, legal and operational teams to assess the reporting threshold under pressure.Chapters:00:00 Context and central question17:59 The Technical Breakdown30:39 The Operational Decisions52:34 The Pressure Test01:03:21 The Key TakeawaysMore analysis: https://cybersecurityunderpressure.com/Related CUP episodes:The 24-Hour Trap: Defensible Decisions Under the Cyber Resilience ActSBOM and VEX: Turning Vulnerability Data into OT Risk Decisions
  • An Automotive Alert Is Not an Incident Response | CUP Focus 03.10.2026 3Min.
    Detection creates a signal, not a decision. This CUP Focus separates the responsibilities of the VSOC and PSIRT, from initial fleet triage and first-mile forensics to root-cause analysis and long-term remediation.Related CUP episodes:An IDPS Alert Is Not an Incident Response CapabilityWhen a Vehicle Detects the Attack but Cannot Safely Block It
  • When Digital Actions Create Physical Impact | CUP Micro Brief 03.10.2026 2Min.
    In OT, a digital action can move machinery, interrupt fabrication or weaken detection without obvious warning. This CUP Micro Brief links active scanning risk, IEC 62443 segmentation and AI model drift to physical resilience.Related CUP episodes:The Threat Has a Body: Defending Critical Infrastructure Against Kinetic AI[2026] Critical: The Plausibility Gap - IEC 62443[2026] Deep Dive: A bad weld passes inspection | OT SecurityTrusted Software, Wrong Weld: Why OT Integrity Is Not Process IntegrityWhen Physics is the Final Firewall
  • PowerLogic T300 Security: When SSH Access Crosses the Trust Boundary 02.10.2026 1Std. 20Min.
    An authenticated account can still cross an unsafe privilege boundary. This episode examines SSH exposure, account governance and command injection in the PowerLogic T300, connecting remediation decisions to electricity-distribution continuity. Learn which access restrictions and monitoring questions matter alongside firmware updates.Chapters:00:00 Context and central question15:33 The Technical Breakdown33:15 The Operational Decisions48:11 The Pressure Test01:00:16 The Key TakeawaysAffected scope: PowerLogic T300 versions 2.9.8-5620 and earlier. Check the latest Schneider Electric guidance before making operational changes.More analysis: https://cybersecurityunderpressure.com/Related CUP episodes:When the Security Router Becomes the Attack Path: Weidmüller and the Fragility of Industrial SegmentationA Critical CVE Is Not an Attack Path: Assessing PLCnext Risk in the PlantSupported Hardware, Vulnerable Software: The Hidden Lifecycle Risk in Industrial FirewallsWhen Edit Permissions Become System-Level Code ExecutionKEV-First Patch Ops: Defending the Exposed Control Plane
  • When EV Charging Becomes a Cyber-Kinetic Risk | CUP Micro Brief 01.10.2026 1Min.
    An EV charging cable initiates a cloud-connected transaction with physical consequences. This CUP Micro Brief follows the path from complex connectivity, through unsafe input validation, to cyber-kinetic manipulation of electrical limits.Related CUP episodes:How EV Chargers Could Crash the Grid: The Cyber Risk Behind Mass ElectrificationHacking EV Chargers to Stress the Grid: When Mobility Becomes Critical InfrastructureAn IDPS Alert Is Not an Incident Response CapabilityAutomotive Extortion Goes Upstream: Protecting the New Vehicle Perimeter
  • A Clean Backup Does Not Prove a Safe Restart | CUP Focus 01.10.2026 4Min.
    Restoring files is not the same as restoring operational confidence. This CUP Focus explains why an OT restart requires trusted control logic, known-good engineering baselines and a defensible go/no-go decision before physical production resumes.Related CUP episodes:The Restart Bottleneck Is Not the Backup. It Is the Evidence.Beyond Backup RecoveryMinnesota Water Cyberattacks: When OT Security Meets Physical RiskWhen Containment Fails RecoveryWhen Patches Stop ProductionWeekly Roundup: State Machine Breakdown & Engineering the Degraded Mode[2026] Critical: Vendor Lock-in - Ransomware
  • Railway Cybersecurity: Why Attack Detection Does Not Prove Safety 30.09.2026 1Std. 20Min.
    Detecting a railway cyberattack does not establish that the physical system remains safe. Explore IAM4RAIL and the evidence needed to connect detection, operational response and safety assurance. The central question is what an operator can justify after the alert, rather than whether an alert exists.https://cybersecurityunderpressure.com/episodesRelated CUP episodes:Frauscher FDS102: Why Railway Diagnostics Belong Inside the Security BoundaryAuthenticated but Wrong: When Railway APIs Contradict Physical RealityWhy Rail Operators Fear the PatchWhen a Patch Reopens the Safety CaseRail Service Risk Starts Outside the SIL BoundaryRailway OT Segmentation: Protecting the Certified CoreWhy FRMCS Cannot Trust the Mobile CarrierThe Red Signal. Paralyzing a Railway Network with a Single PatchLegacy rail assets do not become secure by policyThe Friday Night Patch & The Illusion of Segmentation
  • What Actually Starts the CRA 24-Hour Clock? | CUP Micro Brief 29.09.2026 1Min.
    Not every vulnerability starts the Cyber Resilience Act reporting clock. This CUP Micro Brief explains the two triggers, why reachability and VEX matter, and how CRA product obligations differ from NIS2 operator duties.Related CUP episodes:The 24-Hour Trap: Defensible Decisions Under the Cyber Resilience ActCyber Resilience Act: Making the 24-Hour Reporting Decision
  • Espressif Secure Boot: Where Firmware Trust Can Break 28.09.2026 1Std. 30Min.
    Secure boot validates part of a trust chain, not every condition that makes a device trustworthy. Explore Espressif AR2026-006 and the boundaries of firmware assurance. Learn why implementation, configuration and supporting evidence matter when assessing what a successful verification actually proves.https://cybersecurityunderpressure.com/episodesRelated CUP episodes:Why Signed Firmware Is Still Vulnerable: The Trust Chain Behind the SignatureWhen the Automotive Update Path Becomes the Attack PathThe Flashing Station Is a Product Trust Boundary | CUP FocusShipping the Code That Security RejectedMissing Cybersecurity Evidence Can Delay ProductionWhen ECUs Meet MalicePoisoning the Software Defined Vehicle at BirthAutomotive Cybersecurity: Why Local Access Can Have High ImpactNSA ASIC Assurance: Verifying Trust in Silicon
  • When a License Plate Becomes a Password | CUP Micro Brief 27.09.2026 1Min.
    A public vehicle identifier became the starting point for a remote attack chain. This CUP Micro Brief connects the Kia API flaw, the disappearance of the traditional vehicle perimeter and the need for blind exploit validation.Related CUP episodes:Your License Plate Is the Password: What the Kia API Hack RevealedAuthenticated but Wrong: When Railway APIs Contradict Physical RealityJeep, Gateways and the Myth of Clean IsolationAutomotive Extortion Goes Upstream: Protecting the New Vehicle PerimeterBLE Theft Auto: How Aftermarket Devices Bypass Vehicle Security
  • NIST IR 8536: Verifying the Software Supply Chain 25.09.2026 1Std. 2Min.
    A supplier register identifies companies but does not prove the provenance of the software they deliver. Explore NIST IR 8536 and the evidence needed to trace dependencies and responsibilities across a supply chain. The episode examines how to turn supplier declarations into verifiable trust relationships.https://cybersecurityunderpressure.com/episodesRelated CUP episodes:Railway AI at Risk: When Subcontractor Leaks Break the Trust ChainStadler Rail Extortion: When Supplier Trust Becomes the Attack SurfaceSBOM and VEX: Turning Vulnerability Data into OT Risk DecisionsWhen VEX Becomes a Bureaucratic ShieldNIS2 Supplier Security: When Compliance Costs Become a RiskCyber Gaps in Automotive SupplySupported Hardware, Vulnerable Software: The Hidden Lifecycle Risk in Industrial FirewallsOT Supplier Risk: Building Resilience Without Vendor CooperationA Critical CVE Is Not an Attack Path: Assessing PLCnext Risk in the Plant
  • Automotive Cybersecurity: Why Local Access Can Have High Impact 23.09.2026 1Std. 3Min.
    A local attack vector does not establish low impact, but it also does not prove remote access to safety-relevant vehicle functions. Explore Qualcomm Snapdragon Auto vulnerability assessment through exposure, prerequisites and automotive attack feasibility. The episode examines which evidence connects a component vulnerability to a deployed vehicle risk.https://cybersecurityunderpressure.com/episodesRelated CUP episodes:Espressif Secure Boot: Where Firmware Trust Can BreakWhy Signed Firmware Is Still Vulnerable: The Trust Chain Behind the SignatureNSA ASIC Assurance: Verifying Trust in SiliconChip Security Assurance: Making Silicon Security a Design GateWhy Quantum Security Paralyzes Industrial Infrastructure
  • Siemens S7-1500: Managing PLC and Linux Security Lifecycles 21.09.2026 1Std. 15Min.
    One PLC can contain software components with different security lifecycles. Explore the SIMATIC S7-1500 Linux subsystem and the operational consequences of those overlapping dependencies. Learn which lifecycle questions asset owners should ask before treating hardware support as evidence of software security.https://cybersecurityunderpressure.com/episodesRelated CUP episodes:Supported Hardware, Vulnerable Software: The Hidden Lifecycle Risk in Industrial FirewallsA Critical CVE Is Not an Attack Path: Assessing PLCnext Risk in the PlantWhen the Security Router Becomes the Attack Path: Weidmüller and the Fragility of Industrial SegmentationPowerLogic T300 Security: When SSH Access Crosses the Trust BoundaryKEV-First Patch Ops: Defending the Exposed Control Plane[2026] Critical: When the Hypervisor Becomes the Attack Surface - Patching[2026] Critical: Zero Trust for Brownfield OT - IEC 62443
  • Chip Security Assurance: Making Silicon Security a Design Gate 18.09.2026 1Std. 13Min.
    Semiconductor development uses formal gates for functionality, timing, power and physical implementation. Explore security sign-off as another condition to demonstrate before a chip design is ready. The episode examines how hardware assurance connects design evidence to product trust.https://cybersecurityunderpressure.com/episodesRelated CUP episodes:NSA ASIC Assurance: Verifying Trust in SiliconEspressif Secure Boot: Where Firmware Trust Can BreakWhy Signed Firmware Is Still Vulnerable: The Trust Chain Behind the SignatureWhy Quantum Security Paralyzes Industrial InfrastructureAutomotive Cybersecurity: Why Local Access Can Have High Impact

Beliebt in

Dieser Podcast erscheint auch in den Podcast-Charts dieser Länder.