
CCT 359: ShinyHunters vs. Oracle — Supply Chain Risk Every CISSP Must Know
Send us Fan Mail A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core ...
29 Kesä 43min

CCT 358: EDR Bypass Ransomware: The Gentle Killer Threat Every CISSP Must Know
Send us Fan Mail Your endpoint tool can be world class and still get taken out first. That’s the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a...
22 Kesä 43min

CCT 357: Is Your Encrypted Data Already Stolen? Quantum Risk & Supply Chain Attacks for CISSP
Send us Fan Mail Someone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryptio...
15 Kesä 32min

CCT 356: Supply Chain Attacks Are Exploding in 2026 — Here's What the NCSC Wants You to Do
Send us Fan Mail Your software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open ...
8 Kesä 41min

CCT 355: Zapier Breach Lessons For Cloud Security and Setting Up TPRM Program in 15 Minutes
Send us Fan Mail The breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to r...
4 Kesä 24min

CCT 354: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY
Send us Fan Mail Your firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerabili...
1 Kesä 37min

CCT 353: AI Agent Governance Essentials - CISSP Practice Questions
Send us Fan Mail AI agents are landing in production faster than most security teams can track them, and the scariest part is how normal they can look. When an autonomous agent runs the same workflow ...
28 Touko 28min

CCT 352: Data Security Controls and Compliance Requirements for the CISSP (Domain 2.3) - REPLAY
Send us Fan Mail Your security program can be airtight and still get wrecked by someone else’s breach. We open with a Wired-style reality check: third-party app ecosystems and data brokers collecting ...
25 Touko 40min



















