All Episodes
Cybersecurity Under Pressure. Real Attacks, Real Lessons — 45 episodes
One Hardcoded Key, Many Systems at Risk: The Johnson Controls Airwall Lesson
Beyond Software Supply Chains: NSA ASIC Assurance and the Problem of Trusting Silicon
Secure at the Factory, Exposed at the Dealership: The BLE Theft Auto Problem
When the Security Router Becomes the Attack Path: Weidmüller and the Fragility of Industrial Segmentation
Frauscher FDS102: Why Railway Diagnostics Belong Inside the Security Boundary
When Edit Permissions Become System-Level Code Execution
A Critical CVE Is Not an Attack Path: Assessing PLCnext Risk in the Plant
When a Vehicle Detects the Attack but Cannot Safely Block It
When the Automotive Update Path Becomes the Attack Path
When AI Lowers the Barrier to Attacking Siemens S7 PLCs
Supported Hardware, Vulnerable Software: The Hidden Lifecycle Risk in Industrial Firewalls
Authenticated but Wrong: When Railway APIs Contradict Physical Reality
Trusted Software, Wrong Weld: Why OT Integrity Is Not Process Integrity
Bendix EC80 Brake Recall: When Safety Urgency Meets Cybersecurity Controls
Railway AI at Risk: When Subcontractor Leaks Break the Trust Chain
Why Signed Firmware Is Still Vulnerable: The Trust Chain Behind the Signature
Minnesota Water Cyberattacks: When OT Security Meets Physical Risk
Aftermarket Car Alarms: The Answer Is Not to Make Vehicles Impossible to Modify
Why Patching Windchill Is Not Enough: Restoring Trust in the Digital Thread
When AI Crossed the Trust Boundary: The OpenAI–Hugging Face Incident
Stadler Rail Extortion: When Supplier Trust Becomes the Attack Surface
The 6-Step Supply Chain Bleed: When Your Safety Blueprints Leak and the Lifeboats Catch Fire
The Device Meant to Secure Your Car Is the Exact Thing Exposing It: The UC San Diego Disclosure
The Euro 7 Data Trap: When Emissions Compliance Becomes an Attack Surface
When Compiling Becomes the Payload: The OpenPLC Supply Chain Trap
The Kudankulam Supply Chain Breach: When Trusted Partners Expose Critical Infrastructure
The Threat Has a Body: Defending Critical Infrastructure Against Kinetic AI
Your License Plate Is the Password: What the Kia API Hack Revealed
The 24-Hour Trap: Defensible Decisions Under the Cyber Resilience Act
Stopping Stealthy Radio Jamming in Industrial 5G: When the Air Interface Becomes the Attack Surface
How EV Chargers Could Crash the Grid: The Cyber Risk Behind Mass Electrification
Defending Industrial Networks from Cyber Attacks: Why Resilience Beats Perimeter Security
Industrial 5G and the Uptime Trap: When Connectivity Becomes a Production Risk
Hacking EV Chargers to Stress the Grid: When Mobility Becomes Critical Infrastructure
Teenage Hackers and Software-Defined Factories: When Industrial Risk Starts with Identity
The Compliance Theater. Draining Supplier R&D and Breaking Automotive Silos.
The Red Signal. Paralyzing a Railway Network with a Single Patch
The Shadow Corridor. Legacy VPNs and the Financial Blast Radius in OT
Missing Cybersecurity Evidence Can Delay Production
An IDPS Alert Is Not an Incident Response Capability
When ECUs Meet Malice
Why Rail Operators Fear the Patch
When Physics is the Final Firewall
That is the part many cybersecurity plans still miss, OT controls under revision
Supply Chain: When the supplier will not cooperate resilience must become