Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures episode artwork

EPISODE · Jul 31, 2026 · 22 MIN

Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures

from The Cyber Threat Perspective · host SecurIT360

Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them?In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compromise, why platforms like Security Scorecard and BitSight inflate their severity anyway, and where genuine cryptographic risk actually lives.Jordan also walks through a real penetration test finding: a JSON Web Token signed with HS256, an exposed configuration backup sitting on the web server, and the signing secret that turned a standard user into an administrator.In this episode:- Why A04 dropped on the OWASP Top 10 without becoming less important- The difference between exploitable risk, hygiene risk, and brand reputational risk- An honest take on Security Scorecard and BitSight scores — what they measure, what they miss, and why a perfect score can coexist with a weak password policy and no MFA- The two halves of A04: data in transit (TLS/HTTPS, integrity, tampering) and data at rest (secure storage of credentials, PII, and payment data)- What a JWT actually is, and why pen testers love pulling them apart- Real pen test story: exposed config backup → leaked JWT secret → signature tampering → privilege escalation to admin- Broken server-side signature validation and other improperly implemented cryptography- Why MD5 and SHA-1 still show up for password storage 20 years too late — and what to use instead (Argon2, scrypt, bcrypt)- HSTS, secure renegotiation, and certificate expiration as A04 subcategories- The coffee shop scenario: the full chain of conditions required to exploit SWEET32 — including roughly 250 GB of captured traffic — and why no one has ever documented it happening in the wild- Why a decade-plus-old vulnerability in your environment says more about your vulnerability management program than about your crypto- Quantum computing: how today's theoretical attacks may not stay theoreticalThe takeaway: classify your data, choose modern algorithms, retire deprecated protocols, and keep a functioning vulnerability management program. Not because a threat actor is sitting in your local coffee shop waiting to derive your session key — but because leaving decade-old findings in place is a signal about everything else you might be missing.Next up: OWASP A05, which Brad promises is way cooler than A04.Blog: https://securit360.com/blog/Podcast: https://securit360.buzzsprout.com/YouTube: https://www.youtube.com/@SecurIT360Contact: https://securit360.com/contact/Have a topic you want us to cover? Send it our way.Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.

Episode metadata supplied by the publisher feed · Published Jul 31, 2026

Embed this episode

Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them? In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compro...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Episode 190 | OWASP Top 10 Part 4: Cryptographic Failures

0:00 22:37

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Cyber Threat Perspective?

This episode is 22 minutes long.

When was this The Cyber Threat Perspective episode published?

This episode was published on July 31, 2026.

Can I download this The Cyber Threat Perspective episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!