Home Podcasts CISSP Cyber Training Podcast - CISSP Training Program
CISSP Cyber Training Podcast - CISSP Training Program

CISSP Cyber Training Podcast - CISSP Training Program

Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur 360 Episodes Aug 17, 2026

Join Shon Gerber on his weekly CISSP Cyber Training podcast, where his extensive 23-year background in cybersecurity shines through. With a rich history spanning corporate sectors, government roles, and academic positions, Shon imparts the essential insights and advice necessary to conquer the CISSP exam. His expertise is not just theoretical; as a CISSP credential holder since 2009, Shon translates his deep understanding into actionable training. Each episode is packed with invaluable security strategies and tips that you can implement right away, giving you an edge in the cybersecurity realm.

Episodes

CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study)
CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study) Aug 17, 2026 1984 Send us Fan MailA supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the pa
CCT 365: Malicious QR Code Attacks and Digital Forensics Techniques Every CISSP Should Know [REPLAY]
CCT 365: Malicious QR Code Attacks and Digital Forensics Techniques Every CISSP Should Know [REPLAY] Aug 10, 2026 1505 Send us Fan MailOne careless QR scan can quietly turn a “private” chat into a live wiretap. We start with a timely threat story: Russian APT-style actors abusing Signal’s linked device flow by pushing phishing links that contain malicious QR codes, so messages can be mirrored to an attacker device in real time. If you use Signal, WhatsApp, or Telegram at work, this is the kind of simple, human-tri
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users Aug 3, 2026 2768 Send us Fan MailA breach can hit your headlines even when your own systems never get touched, and that’s exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content
CCT 363: CISSP AI Governance - What Credit Union Examiners Are Really Asking
CCT 363: CISSP AI Governance - What Credit Union Examiners Are Really Asking Jul 27, 2026 2685 Send us Fan MailOne bad AI decision can cost you more than money. It can cost you trust, trigger regulators overnight, and put your name on the hook when the board asks, “Who approved this?” We dig into AI governance through a CISSP lens, using real-world banking and credit union scenarios that show how fast things go sideways when AI tools slip outside your controls.We start with the uncomfortabl
CCT 362: Security Assessment Strategies & Abandoned Cloud Storage Risks (CISSP 6.1) - REPLAY
CCT 362: Security Assessment Strategies & Abandoned Cloud Storage Risks (CISSP 6.1) - REPLAY Jul 20, 2026 2040 Send us Fan MailThat forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-sty
CCT 361: Bad Epoll - Root Access in 6 Instructions
CCT 361: Bad Epoll - Root Access in 6 Instructions Jul 13, 2026 1940 Send us Fan MailA six-instruction timing glitch in the Linux kernel can be the difference between “low-priv user” and full root control, and that is why we dig into the Bad EPoll vulnerability from a CISSP-ready, manager-first angle. We start by grounding what the Linux kernel EPoll subsystem does, why it is foundational to high-performance I/O, and why “just disable it” is not a real option when
CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster
CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster Jul 6, 2026 1408 Send us Fan MailImagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach.I walk through what’s being reported about Social Securi
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know Jun 29, 2026 2588 Send us Fan MailA vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact sup
CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know
CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know Jun 22, 2026 2582 Send us Fan MailYour endpoint tool can be world class and still get taken out first. That’s the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a-service platforms, where affiliates can plug in advanced evasion without building it themselves. When attackers can blind endpoint detection and response before the ransomware payload runs, the old co
CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP
CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP Jun 15, 2026 1929 Send us Fan MailSomeone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryption that protects it. I dig into the “Harvest Now, Decrypt Later” strategy, why it matters most for long-term confidentiality, and how security leaders can talk about it as a present-day risk instead of
CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do
CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do Jun 8, 2026 2498 Send us Fan MailYour software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines.I walk through the attack patterns that keep showing up in incidents: maint
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes
CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes Jun 4, 2026 1466 Send us Fan MailThe breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach priva

Recommended