Home Podcasts Cybersecurity Under Pressure. Real Attacks, Real Lessons
Cybersecurity Under Pressure. Real Attacks, Real Lessons

Cybersecurity Under Pressure. Real Attacks, Real Lessons

Antonio González 67 Episodes Aug 21, 2026

This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice. Each episode analyzes a recent attack, explains the technical mechanics in clear language, and translates them into concrete lessons for security, engineering, and business teams. Topics covered include OT security, ICS cybersecurity, industrial control systems, critical infrastructure protection, NIS2 compliance, Zero Trust architecture, operational technology resilience, railway cybersecurity, automotive security, and cyber-physical systems.

Episodes

Authenticated but Wrong: When Railway APIs Contradict Physical Reality
Authenticated but Wrong: When Railway APIs Contradict Physical Reality Aug 21, 2026 00:39:00 A railway API can be correctly authenticated, protected by strong cryptography and accepted by every security control in the chain — while still delivering operationally wrong data.In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine a critical limitation of digital trust in interconnected railway environments: authentication can prove where data came from, but i
Trusted Software, Wrong Weld: Why OT Integrity Is Not Process Integrity
Trusted Software, Wrong Weld: Why OT Integrity Is Not Process Integrity Aug 19, 2026 00:37:51 A welding robot can execute trusted software, accept authorized commands and still produce the wrong physical result.That distinction sits at the heart of this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons.We examine a fundamental problem in industrial cybersecurity: the difference between proving that software and commands are legitimate and proving that the physical process
Bendix EC80 Brake Recall: When Safety Urgency Meets Cybersecurity Controls
Bendix EC80 Brake Recall: When Safety Urgency Meets Cybersecurity Controls Aug 17, 2026 00:41:16 A brake recall is first and foremost a physical safety issue. But what happens when the pressure to act quickly collides with the security controls protecting a critical vehicle system?In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we use the Bendix EC80 brake recall to examine a difficult product cybersecurity problem: how to preserve cyber resilience when safety-cri
Railway AI at Risk: When Subcontractor Leaks Break the Trust Chain
Railway AI at Risk: When Subcontractor Leaks Break the Trust Chain Aug 14, 2026 00:37:12 Your railway systems may be secure. Your AI environment may be protected. But what happens when sensitive information escapes through a subcontractor?In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine a growing challenge for railway cybersecurity: protecting sensitive AI and engineering assets across a supply chain that extends far beyond the organisation itsel
Why Signed Firmware Is Still Vulnerable: The Trust Chain Behind the Signature
Why Signed Firmware Is Still Vulnerable: The Trust Chain Behind the Signature Aug 12, 2026 00:44:23 A valid digital signature tells you that firmware was signed by a trusted key. It does not necessarily tell you that everything behind that signature can still be trusted.In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine one of the most dangerous assumptions in product cybersecurity: that signed firmware automatically means secure firmware.We trace the problem
Minnesota Water Cyberattacks: When OT Security Meets Physical Risk
Minnesota Water Cyberattacks: When OT Security Meets Physical Risk Aug 10, 2026 00:38:57 What happens when a cyberattack moves beyond IT systems and begins to threaten the physical processes communities depend on?In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine the cyberattacks targeting water systems in Minnesota and the deeper OT security lessons behind them.We break down how attackers can exploit weaknesses around industrial environments, use
Aftermarket Car Alarms: The Answer Is Not to Make Vehicles Impossible to Modify
Aftermarket Car Alarms: The Answer Is Not to Make Vehicles Impossible to Modify Aug 7, 2026 00:46:33 A dealer-installed anti-theft device should make a vehicle safer. But what happens when that device introduces a new wireless path into the vehicle itself?Researchers identified serious Bluetooth weaknesses in KARR and SWDS aftermarket alarm systems installed in approximately 2.2 million vehicles. From close range, an attacker could potentially unlock doors, control the alarm and activate the immo
Why Patching Windchill Is Not Enough: Restoring Trust in the Digital Thread
Why Patching Windchill Is Not Enough: Restoring Trust in the Digital Thread Aug 5, 2026 00:44:22 A critical vulnerability in PTC Windchill and FlexPLM exposed more than an enterprise server. It placed the integrity of the digital thread at risk.Patching the vulnerability closes the original entry point. It does not prove that engineering files, source code, approval workflows, test evidence or supplier copies remained untouched while the system was exposed.In this episode of Cybersecurity Und
When AI Crossed the Trust Boundary: The OpenAI–Hugging Face Incident
When AI Crossed the Trust Boundary: The OpenAI–Hugging Face Incident Aug 3, 2026 00:35:55 A routine AI benchmark became a real security incident when a pre-release model crossed the boundaries of its evaluation environment and reached infrastructure belonging to Hugging Face.The incident exposed a deeper architectural problem: transitive trust. The sandbox could access a self-hosted JFrog Artifactory instance to retrieve software dependencies. That trusted connection created a potentia
Stadler Rail Extortion: When Supplier Trust Becomes the Attack Surface
Stadler Rail Extortion: When Supplier Trust Becomes the Attack Surface Jul 31, 2026 00:47:50 Stadler Rail refused a multimillion-dollar extortion demand after attackers accessed technical information through a supplier-linked data exchange platform. Production continued, its core IT environment remained operational, and trains in service were reportedly unaffected.So where did the security failure actually occur?This episode examines an attack that did not begin inside the manufacturer’s
The 6-Step Supply Chain Bleed: When Your Safety Blueprints Leak and the Lifeboats Catch Fire
The 6-Step Supply Chain Bleed: When Your Safety Blueprints Leak and the Lifeboats Catch Fire Jul 29, 2026 00:32:45 In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we follow the evidence into one of the most consequential architectural debates in industrial cybersecurity today: Should Safety Instrumented Systems (SIS) be strictly segregated from Basic Process Control Systems (BPCS)?The conversation is no longer theoretical. CISA Advisory AA-2026-2697 details Iranian-linked actors ac
The Device Meant to Secure Your Car Is the Exact Thing Exposing It: The UC San Diego Disclosure
The Device Meant to Secure Your Car Is the Exact Thing Exposing It: The UC San Diego Disclosure Jul 27, 2026 00:31:52 In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we dissect the staggering UC San Diego research disclosure revealing how dealer-installed aftermarket anti-theft modules bypassed entire OEM security architectures. What starts as a localized dealer convenience ends as a systemic collapse of the trust boundary.We go under the hood—literally—to trace the five-stage failure

Recommended