Home Podcasts Below the Surface (Audio) - The Supply Chain Security Podcast
Below the Surface (Audio) - The Supply Chain Security Podcast

Below the Surface (Audio) - The Supply Chain Security Podcast

Eclypsium 76 Episodes Aug 13, 2026

A lively discussion of the threats affecting supply chain, specifically focused on firmware and low-level code that is a blind spot for many organizations. This podcast will feature guests from the cybersecurity industry discussing the problems surrounding supply chain-related issues and potential solutions.

Episodes

Exploring BMC Vulnerabilities - BTS #80
Exploring BMC Vulnerabilities - BTS #80 Aug 13, 2026 59:26 Summary In this episode, the hosts discuss various cybersecurity topics, including the lack of media coverage from the Black Hat conference, the implications of AI in cybersecurity, and the vulnerabilities associated with Baseboard Management Controllers (BMCs). They explore the challenges of patch management, the role of embedded Linux in security vulnerabilities, and the emerging trends in threa
InfraTrust - Understanding Infrastructure Vulnerabilities & Risk - BTS #79
InfraTrust - Understanding Infrastructure Vulnerabilities & Risk - BTS #79 Aug 7, 2026 54:36 Check out our free and no-registration-required site for understanding and tracking infrastructure vulnerabilities and advisories: https://infra-trust.org  In this episode, the hosts discuss the challenges of collecting and aggregating vulnerability data, the introduction of Infratrust and Infratrust Pulse, and the importance of actionable data for cybersecurity teams. They explore the differences
Patching: The Race Against Time - BTS #78
Patching: The Race Against Time - BTS #78 Jul 16, 2026 56:12 In this episode, the hosts discuss various vulnerabilities affecting network devices, the importance of timely patching in enterprises, and the implications of AI on security. They explore the challenges of compliance programs, the significance of dependency management in software, and the need for better privilege separation in network devices. The conversation also touches on the risks of supply
FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices - BTS #77
FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices - BTS #77 Jun 30, 2026 54:49 In this episode, we delve into the recent FortiBleed campaign, exploring how attackers harvest credentials from Fortinet devices, the vulnerabilities in password management, and best practices for defenders to mitigate such threats. Key  topics FortiBleed campaign details and impact Password hash vulnerabilities in FortiOS AI's role in analyzing large security breaches Credential harvesting techn
Binwalk, Brickstorm, AI Model Madness - BTS #76
Binwalk, Brickstorm, AI Model Madness - BTS #76 Jun 16, 2026 01:00:41  summary In this episode of Below the Surface, Paul Asadoorian, Chase Snyder, and Vlad Babkin discuss the implications of AI in cybersecurity, the challenges posed by AI guardrails, and the operational risks associated with applying patches. They also explore vulnerabilities in security tools like Binwalk, the complexities of firmware update tools, and the importance of transparency in software si
Secure Boot Certificates Expiring: What You Need to Know - BTS #75
Secure Boot Certificates Expiring: What You Need to Know - BTS #75 Jun 3, 2026 55:48 In this episode of Below the Surface, the team discusses recent cybersecurity trends, including the Verizon DBIR 2026 report, secure boot certificate expirations, and the evolving threat landscape with AI and hardware vulnerabilities. They explore how organizations can adapt their defense strategies to stay ahead of attackers and share insights on supply chain security and malware analysis. http
YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74
YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74 May 19, 2026 54:52 In this episode, we explore recent vulnerabilities, the YellowKey BitLocker bypass, supply chain security, CVE data analysis, and the implications of hardware breaches like the one at Foxconn. We also delve into AI's role in vulnerability research and the evolving landscape of cybersecurity threats. Topics https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-
Uncovering Firmware Risks: From Y2K to Modern Malware - BTS #73
Uncovering Firmware Risks: From Y2K to Modern Malware - BTS #73 May 7, 2026 55:01 In this episode of Below the Surface, hosts Paul Asadoorian, Chase Snyder, and guest Brian Richardson explore the evolution of firmware security, the risks of supply chain vulnerabilities, and the latest threats targeting network edge devices like Cisco ASA and FTD. They discuss historical malware like the Chernobyl virus, modern malware campaigns such as Firestarter, and the challenges of securin
AI-Powered Firmware Hacking: The Future of Vulnerability Discovery - BTS #72
AI-Powered Firmware Hacking: The Future of Vulnerability Discovery - BTS #72 Apr 17, 2026 58:59 In this episode, the hosts explore the latest in cybersecurity, including AI-driven vulnerability discovery, firmware analysis tools, secure boot complexities, and recent CVE trends. They discuss practical techniques for hacking devices, the challenges of firmware emulation, and the implications of new security policies on consumer and enterprise hardware. Chapters 00:00 Introduction to Hacking an
What Makes a Device a Router? - BTS #71
What Makes a Device a Router? - BTS #71 Apr 7, 2026 01:01:42  summary In this episode, the hosts discuss the new FCC regulations regarding consumer routers, exploring the implications for cybersecurity, the definitions of what constitutes a router, and the challenges of manufacturing compliant devices. They delve into the debate surrounding the effectiveness of these regulations in mitigating cyber risks, the role of hardware versus software vulnerabilities
How Cheap KVMs Could Be Your Network's Weak Link - BTS #70
How Cheap KVMs Could Be Your Network's Weak Link - BTS #70 Mar 25, 2026 01:02:56 In this episode, we explore the security vulnerabilities of low-cost IP-based KVMs, including firmware flaws, default credentials, and insecure update mechanisms. Two Eclypsium researchers, Paul and Rey, discovered the vulnerabilities and shared the details and behind-the-scenes details! We also discuss real-world testing, vendor responses, and best practices for securing remote management devices
Navigating Network Edge Vulnerabilities - BTS #69
Navigating Network Edge Vulnerabilities - BTS #69 Mar 5, 2026 01:04:13 In this episode of Below the Surface, Paul Asadoorian, Vlad Babkin, and Adrian Sanabria discuss the ongoing vulnerabilities in network edge devices, the implications of legacy systems like Avanti, and the strategies employed by threat actors. They explore the importance of monitoring and detection in cybersecurity, as well as innovative deception techniques to enhance security measures against exp

Recommended