
CCT 364: Third Party Risk Management - How One Vendor Breach Exposed 119,000 Users
Send us Fan Mail A breach can hit your headlines even when your own systems never get touched, and that’s exactly why third-party risk management keeps showing up on the CISSP exam and in real inciden...
3 Elo 46min

CCT 363: CISSP AI Governance - What Credit Union Examiners Are Really Asking
Send us Fan Mail One bad AI decision can cost you more than money. It can cost you trust, trigger regulators overnight, and put your name on the hook when the board asks, “Who approved this?” We dig i...
27 Heinä 44min

CCT 362: Security Assessment Strategies & Abandoned Cloud Storage Risks (CISSP 6.1) - REPLAY
Send us Fan Mail That forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and oth...
20 Heinä 34min

CCT 361: Bad Epoll - Root Access in 6 Instructions
Send us Fan Mail A six-instruction timing glitch in the Linux kernel can be the difference between “low-priv user” and full root control, and that is why we dig into the Bad EPoll vulnerability from a...
13 Heinä 32min

CCT 360: SSA Whistleblower and the Thumb Drive: What CISSP Asset Security Tells Us About This Disaster
Send us Fan Mail Imagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigat...
6 Heinä 23min

CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know
Send us Fan Mail A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core ...
29 Kesä 43min

CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know
Send us Fan Mail Your endpoint tool can be world class and still get taken out first. That’s the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a...
22 Kesä 43min

CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP
Send us Fan Mail Someone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryptio...
15 Kesä 32min



















