
Free Daily Podcast Summary
by Eclypsium
A lively discussion of the threats affecting supply chain, specifically focused on firmware and low-level code that is a blind spot for many organizations. This podcast will feature guests from the cybersecurity industry discussing the problems surrounding supply chain-related issues and potential solutions.
The most recent episodes — sign up to get AI-powered summaries of each one.
In this episode of Below the Surface, the hosts discuss cybersecurity topics, including vulnerabilities in UEFI shells, vendor trust issues, Citrix's new dual-boot solution, and techniques for bypassing Windows Defender. They also explore the implications of AI in Linux environments and the ongoing controversy surrounding AI math theft. In this conversation, Vlad and Paul discuss OpenAI's recent controversial achievement in solving a significant mathematical problem, raising ethical concerns about data usage and the implications for the AI community. They explore the future of local AI models, innovations in firmware analysis tools, and techniques attackers use on Linux systems. The discussion emphasizes the importance of cybersecurity practices and the need to stay vigilant about potential vulnerabilities. Articles: https://nerds.xyz/2026/08/citrix-uniconos-linux-dual-boot-windows-recovery/ https://ipurple.team/2026/09/09/windows-security-center/ https://x.com/rynorhn/status/2097223532438487463 https://brownfinesecurity.com/blog/introducing-moria-and-mithril https://sansec.io/research/stylesmuggler-0day Chapters 00:00 Introduction to Below the Surface Podcast 02:06 Vulnerability in UEFI Shells 14:16 Trust Issues with Vendors 15:46 Citrix's Unicon OS: A Dual Boot Solution 21:28 Windows Defender Bypass Techniques 26:54 AI and Linux: New Developments 32:06 The Controversy Over AI Math Theft 32:10 OpenAI's Controversial AI Achievement 35:13 The Ethics of AI and Data Usage 38:12 The Future of Local AI Models 39:19 Innovations in Firmware Analysis Tools 44:58 Understanding Linux Malware Techniques 52:05 Best Practices for Securing Linux Systems
In this episode, Paul and Vlad discuss the latest Infratrust Pulse report, highlighting vulnerability trends, the role of AI in cybersecurity, and the importance of visibility and control in network security. They delve into threats posed by BMCs and management planes, the challenges of persistence mechanisms, and the need for better vendor responsiveness and API practices to strengthen security. In this conversation, Vlad and Paul discuss the evolving role of AI in cybersecurity, particularly its use by threat actors to exploit vulnerabilities. They explore the implications of AI in vulnerability discovery, the importance of secure software development practices, and the risks associated with backdoors in surveillance technology. The discussion emphasizes the need for organizations to adopt better security measures and the potential of AI to enhance software quality and security. Articles: * https://pulse.infra-trust.org/august-2026/ * https://blog.quarkslab.com/defeating-ai-assisted-reverse-engineering-or-at-least-trying-to.html * https://securityaffairs.com/197764/hacking/slovakia-warns-of-cyber-risks-in-road-speed-cameras.html * https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/ * https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/ * https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/ Chapters 00:00 Introduction to Infratrust Pulse and AI in Cybersecurity 05:56 Trends in Vulnerabilities and AI's Role 09:36 The Threat Landscape: BMCs and Management Planes 13:52 Persistence Mechanisms and Forensic Challenges 18:34 Visibility and Control in Network Security 23:41 Vendor Responsiveness and API Best Practices 26:08 AI in Cybersecurity: Threats and Opportunities 30:00 The Role of AI in Vulnerability Discovery 34:00 AI's Impact on Software Development and Security 39:06 Best Practices for Secure Software Development 44:14 Addressing Backdoors in Surveillance Technology
Summary In this episode, the hosts discuss various cybersecurity topics, including the lack of media coverage from the Black Hat conference, the implications of AI in cybersecurity, and the vulnerabilities associated with Baseboard Management Controllers (BMCs). They explore the challenges of patch management, the role of embedded Linux in security vulnerabilities, and the emerging trends in threat actor behavior. The conversation emphasizes the need for better awareness and action regarding BMC vulnerabilities and the importance of understanding the risks associated with AI in security. In this conversation, the speakers delve into the complexities of operational risks associated with AI models, particularly in the context of patch management and firmware security. They discuss the challenges of relying on AI for code reviews and the implications of backdoors found in firmware. The conversation also highlights the critical importance of true randomness in cryptographic applications and the ongoing risks posed by speculative execution attacks. Chapters 00:00 Introduction and Technical Setup 03:01 Black Hat Conference Coverage and Media Silence 06:00 AI and Cybersecurity: Responsibility and Ethics 08:51 BMC Vulnerabilities: Research and Findings 11:57 Scanning Techniques and Tools for BMCs 15:02 Cisco Vulnerabilities and Patch Management Challenges 17:54 The Role of AI in Vulnerability Discovery and Management 21:13 Emerging Threats and Trends in Cybersecurity 24:00 Conclusion and Future Considerations 34:03 Understanding Operational Risks in AI Models 37:10 The Challenges of Patch Management and Configuration 41:26 The Dangers of AI in Code Review 43:00 Backdoors in Firmware: A Growing Concern 49:13 The Importance of True Randomness in Cryptography 58:08 The Implications of Speculative Execution Attacks
Check out our free and no-registration-required site for understanding and tracking infrastructure vulnerabilities and advisories: https://infra-trust.org In this episode, the hosts discuss the challenges of collecting and aggregating vulnerability data, the introduction of Infratrust and Infratrust Pulse, and the importance of actionable data for cybersecurity teams. They explore the differences between vendor advisories and CVEs, the role of Eclipsium in data aggregation, and the ongoing challenges in vulnerability management and patching. The conversation highlights the need for a centralized source of truth for infrastructure vulnerabilities and the evolving landscape of cybersecurity threats. In this conversation, the speakers delve into the complexities of vulnerability management, particularly in the context of AI's rapid evolution in vulnerability discovery. They discuss the biases affecting vulnerability prioritization, the implications of AI on both offensive and defensive capabilities, and the critical risks associated with exposing Baseboard Management Controllers (BMCs) to the internet. The conversation emphasizes the need for better security practices and awareness in the face of evolving threats. Chapters 00:00 Technical Challenges in Data Collection 02:58 Introduction to Infratrust and Infratrust Pulse 05:57 The Evolution of Infrastructure Pulse 09:02 Understanding Vendor Advisories vs CVEs 11:49 The Importance of Actionable Data 14:46 Navigating Vendor Advisory Inconsistencies 17:51 The Role of Eclipsium in Data Aggregation 20:46 Patching Challenges and Vulnerability Management 24:09 Interpreting Risk Scores and Vulnerability Impact 30:34 Understanding Vulnerability Management Challenges 32:43 The Impact of AI on Vulnerability Discovery 35:24 The Arms Race: Offensive vs Defensive Capabilities 38:41 The Dangers of Exposing BMCs to the Internet 41:31 BMC Vulnerabilities: A Deep Dive 49:29 Mitigating Risks: Best Practices for BMC Security
In this episode, the hosts discuss various vulnerabilities affecting network devices, the importance of timely patching in enterprises, and the implications of AI on security. They explore the challenges of compliance programs, the significance of dependency management in software, and the need for better privilege separation in network devices. The conversation also touches on the risks of supply chain attacks and the detection of orphaned packages in software ecosystems. Chapters 00:00 Introduction to Vulnerabilities and Security Trends 02:49 Router Choices and Security Implications 10:41 The Need for Faster Patching in Enterprises 12:22 The Impact of AI on Security and Exploits 18:31 Challenges with Compliance and Vulnerability Management 24:17 The Importance of Dependency Management in Software 30:54 Supply Chain Attacks and Their Consequences 35:34 Privilege Separation and Device Security 40:40 The Role of AI in Exploit Development 53:43 Detecting Orphaned Packages and Security Risks
In this episode, we delve into the recent FortiBleed campaign, exploring how attackers harvest credentials from Fortinet devices, the vulnerabilities in password management, and best practices for defenders to mitigate such threats. Key topics FortiBleed campaign details and impact Password hash vulnerabilities in FortiOS AI's role in analyzing large security breaches Credential harvesting techniques and defenses Importance of layered security and best practices Chapters 00:00 Introduction and Initial Thoughts on AI Models 10:04 Credential Harvesting and Security Weaknesses 19:58 Hash Management and Security Appliances 30:15 Incident Response and Vulnerability Management 39:46 The Future of Security in the Age of AI
summary In this episode of Below the Surface, Paul Asadoorian, Chase Snyder, and Vlad Babkin discuss the implications of AI in cybersecurity, the challenges posed by AI guardrails, and the operational risks associated with applying patches. They also explore vulnerabilities in security tools like Binwalk, the complexities of firmware update tools, and the importance of transparency in software signing, particularly in the context of open source software. In this conversation, the speakers delve into the complexities of cybersecurity, focusing on the limitations of security through obscurity, the challenges posed by UEFI shells and secure boot, and the operational risks associated with DBX updates. They discuss the difficulties in vulnerability management and the role of AI in cybersecurity, highlighting how it may benefit attackers more than defenders. The conversation also touches on emerging threats like Brickstorm malware and the need to rethink edge device security in light of these challenges. Finally, they emphasize the necessity for all companies to adopt robust cybersecurity measures. Chapters 00:00 Introduction to Below the Surface Podcast 01:16 The Rise of AI and Its Implications 06:42 Challenges with AI Guardrails and Restrictions 10:53 Operational Risks in Cybersecurity 17:01 Vulnerabilities in Security Tools 20:11 Exploring Firmware Update Tools 29:07 The Importance of Open Source in Security 34:07 The Need for Transparency in Software Signing 35:12 The Fallacy of Security Through Obscurity 36:36 The Challenges of UEFI Shells and Secure Boot 39:58 The Complexity of DBX Updates and Operational Risks 43:20 The Difficulty of Vulnerability Management 48:11 AI's Role in Cybersecurity: A Double-Edged Sword 52:59 Emerging Threats: The Rise of Brickstorm Malware 55:54 Rethinking Edge Device Security 01:00:08 The Future of Cybersecurity Infrastructure
In this episode of Below the Surface, the team discusses recent cybersecurity trends, including the Verizon DBIR 2026 report, secure boot certificate expirations, and the evolving threat landscape with AI and hardware vulnerabilities. They explore how organizations can adapt their defense strategies to stay ahead of attackers and share insights on supply chain security and malware analysis. https://eclypsium.com/blog/microsoft-secure-boot-certificates-expire-2026/ https://eclypsium.com/blog/verizon-dbir-2026/ https://github.com/iss4cf0ng/OpenPetya https://gbhackers.com/exploit-f5-big-ip-ssh-access/ https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/ https://cybersecuritynews.com/china-linked-hackers-target-southeast-asian-edge-routers/ https://qiita.com/Y4er/items/0b6071745e4b7b240b3e https://www.greynoise.io/blog/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400 YellowKey update: https://www.reddit.com/r/sysadmin/comments/1tkq3x9/yellowkey_bitlocker_exploit_repo_taken_down/ Chapters 00:00 Introduction and Technical Issues 02:56 Verizon DBIR Insights 05:50 Trends in Vulnerability Management 09:04 The Role of AI in Cybersecurity 12:11 Challenges in Vulnerability Management 14:46 Secure Boot Certificates and Their Implications 29:52 Managing Updates and Security Risks 32:57 The Open Petya Project: A Historical Perspective 36:11 Understanding the Yellow Key Attack 39:34 The Dilemma of Independent Researchers 41:34 The Future of Bug Bounty Programs 43:59 The Evolving Landscape of Vulnerabilities 49:51 Visibility Challenges in Network Security 56:16 The Need for Better Information Sharing
Free AI-powered daily recaps. Key takeaways, quotes, and mentions — in a 5-minute read.
Get Free Summaries →Free forever for up to 3 podcasts. No credit card required.
Listeners also like.

Cyberside Chats: Cybersecurity Insights from the Experts
Cybersecurity experts discuss emerging threats, defense strategies, and AI's role in protecting organizations.

The Dark Web Diaries
Explores cybersecurity topics, hacker motivations, and weekly cyber news to demystify online safety and the dark web.

Security Now (Audio)
A weekly deep dive into cybersecurity news, hacking trends, and digital defense strategies for professionals and individuals.

Cyber Leaders
Explores cybersecurity trends and strategies through expert insights to help leaders navigate digital threats.

TechSurge: Deep Tech Podcast
Explores emerging technologies, startup challenges, and investment trends through interviews with tech leaders, founders, and investors.

The Cloud Pod | Weekly AI & Cloud News on AWS, Azure & GCP
Covers weekly updates and AI innovations in cloud computing across AWS, Azure, and Google Cloud for tech professionals.

The Digital Executive
A daily tech podcast exploring emerging technologies through interviews with Silicon Valley CEOs, influencers, and celebrities.

Podcast | ice age farmer
Ice Age Farmer, iceagefarmer.com

NatSec Matters
Former national security officials interview top leaders on critical security challenges and U.S. policy responses.

Darknet Diaries
True stories of hacking, cybercrime, and data breaches from the dark side of the Internet.

This Machine Kills
Critiques the intersection of technology, capitalism, and power through a leftist political lens.

Latent Space: The AI Engineer Podcast
Explores AI engineering breakthroughs in foundation models, code generation, and AI agents through interviews with researchers and developers.
A lively discussion of the threats affecting supply chain, specifically focused on firmware and low-level code that is a blind spot for many organizations. This podcast will feature guests from the cybersecurity industry discussing the problems surrounding supply chain-related issues and potential solutions.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from Below the Surface (Audio) - The Supply Chain Security Podcast in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of Below the Surface (Audio) - The Supply Chain Security Podcast as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by Eclypsium.
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
Below the Surface (Audio) - The Supply Chain Security Podcast publishes biweekly. Our AI generates a summary within hours of each new episode.
Below the Surface (Audio) - The Supply Chain Security Podcast covers topics including Technology, Business. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.