CCT 372: Stolen Sessions and Why MFA Never Saw Them (CISSP Domain 5.6)

CCT 372: Stolen Sessions and Why MFA Never Saw Them (CISSP Domain 5.6)

Send us Fan Mail A stolen password is annoying. A stolen session token can be invisible, valid, and instantly profitable. Today we dig into a real warning sign from Okta threat intelligence: infostealer malware lifted live session tokens from browsers, and thousands of Google sessions were still working weeks later. No MFA prompt. No brute force. Just a legitimate session replayed by the wrong person, with real dollar damage through unauthorized usage and credits. We use that story to sharpe...

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(377)

 CCT 373: An AI Agent Was Told No and Got In Anyway (CISSP Domain 6.2)

CCT 373: An AI Agent Was Told No and Got In Anyway (CISSP Domain 6.2)

Send us Fan Mail An AI agent gets blocked by access controls, then calmly finds another way in anyway and that is the wake-up call. I use a recent Hacker News story about an automated agent bypassing ...

5 Okt 37min

CCT 371: Secure Communication Channels and Who Is Really On Your Call (Domain 4.3)

CCT 371: Secure Communication Channels and Who Is Really On Your Call (Domain 4.3)

Send us Fan Mail One video hotline feels like a single, simple conversation until you trace the call path and realise there may be seven companies involved in making it work. That’s the spark for this...

21 Sep 30min

CCT 370: CISSP Cryptography, FIPS Validation, and Post-Quantum (Domain 3)

CCT 370: CISSP Cryptography, FIPS Validation, and Post-Quantum (Domain 3)

Send us Fan Mail A compliance deadline can change your security posture without changing a single bit of your encryption. We start with a simple sticker-on-the-windshield analogy that maps directly to...

14 Sep 38min

CCT 369: Security Models Demystified - CISSP Domain 3.2 (Replay of CCT 278)

CCT 369: Security Models Demystified - CISSP Domain 3.2 (Replay of CCT 278)

Send us Fan Mail 🔁 REPLAY — this episode originally aired as CCT 278 in September 2025. I'm heads-down finishing a Domain 3 cryptography episode, so I'm re-running one of the strongest episodes in t...

7 Sep 31min

CCT 368: CISSP Asset Security and Data Classification (Domain 2)

CCT 368: CISSP Asset Security and Data Classification (Domain 2)

Send us Fan Mail Nine million images. No password. No encryption. And the defence was basically: “It wasn’t public because you had to know the URL.” That single line opens up one of the most important...

31 Aug 42min

CCT 367: Threat Modeling and the AI Agent That Breached Hugging Face (CISSP Domain 1.10)

CCT 367: Threat Modeling and the AI Agent That Breached Hugging Face (CISSP Domain 1.10)

Send us Fan Mail A rogue AI agent didn’t “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying a...

24 Aug 42min

CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study)

CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study)

Send us Fan Mail A supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poi...

17 Aug 33min

Populärt inom Utbildning

historiepodden-se
det-skaver
rss-bara-en-till-om-beroende-medberoende
nu-blir-det-historia
rss-dr-bjorklund
harrisons-dramatiska-historia
rss-viktmedicinpodden
allt-du-velat-veta
not-fanny-anymore
roda-vita-rosen
johannes-hansen-podcast
rss-foraldramotet-bring-lagercrantz
i-vantan-pa-katastrofen
sa-in-i-sjalen
rikatillsammans-om-privatekonomi-rikedom-i-livet
rss-ai-med-jonas-benjamin
sektledare
rss-basta-livet
rss-max-tant-med-max-villman
rss-sjalsligt-avkladd