loader from loading.io

BIOS Password Cracking, Secure Boot, and Stackwarp - BTS #67

Below the Surface (Audio) - The Supply Chain Security Podcast

Release Date: 01/27/2026

Exploring BMC Vulnerabilities - BTS #80 show art Exploring BMC Vulnerabilities - BTS #80

Below the Surface (Audio) - The Supply Chain Security Podcast

Summary In this episode, the hosts discuss various cybersecurity topics, including the lack of media coverage from the Black Hat conference, the implications of AI in cybersecurity, and the vulnerabilities associated with Baseboard Management Controllers (BMCs). They explore the challenges of patch management, the role of embedded Linux in security vulnerabilities, and the emerging trends in threat actor behavior. The conversation emphasizes the need for better awareness and action regarding BMC vulnerabilities and the importance of understanding the risks associated with AI in security. In...

info_outline
InfraTrust - Understanding Infrastructure Vulnerabilities & Risk - BTS #79 show art InfraTrust - Understanding Infrastructure Vulnerabilities & Risk - BTS #79

Below the Surface (Audio) - The Supply Chain Security Podcast

Check out our free and no-registration-required site for understanding and tracking infrastructure vulnerabilities and advisories: https://infra-trust.org  In this episode, the hosts discuss the challenges of collecting and aggregating vulnerability data, the introduction of Infratrust and Infratrust Pulse, and the importance of actionable data for cybersecurity teams. They explore the differences between vendor advisories and CVEs, the role of Eclipsium in data aggregation, and the ongoing challenges in vulnerability management and patching. The conversation highlights the need for a...

info_outline
Patching: The Race Against Time - BTS #78 show art Patching: The Race Against Time - BTS #78

Below the Surface (Audio) - The Supply Chain Security Podcast

In this episode, the hosts discuss various vulnerabilities affecting network devices, the importance of timely patching in enterprises, and the implications of AI on security. They explore the challenges of compliance programs, the significance of dependency management in software, and the need for better privilege separation in network devices. The conversation also touches on the risks of supply chain attacks and the detection of orphaned packages in software ecosystems. Chapters 00:00 Introduction to Vulnerabilities and Security Trends 02:49 Router Choices and Security Implications 10:41...

info_outline
FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices - BTS #77 show art FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices - BTS #77

Below the Surface (Audio) - The Supply Chain Security Podcast

In this episode, we delve into the recent FortiBleed campaign, exploring how attackers harvest credentials from Fortinet devices, the vulnerabilities in password management, and best practices for defenders to mitigate such threats. Key  topics FortiBleed campaign details and impact Password hash vulnerabilities in FortiOS AI's role in analyzing large security breaches Credential harvesting techniques and defenses Importance of layered security and best practices Chapters 00:00 Introduction and Initial Thoughts on AI Models 10:04 Credential Harvesting and Security Weaknesses 19:58 Hash...

info_outline
Binwalk, Brickstorm, AI Model Madness - BTS #76 show art Binwalk, Brickstorm, AI Model Madness - BTS #76

Below the Surface (Audio) - The Supply Chain Security Podcast

 summary In this episode of Below the Surface, Paul Asadoorian, Chase Snyder, and Vlad Babkin discuss the implications of AI in cybersecurity, the challenges posed by AI guardrails, and the operational risks associated with applying patches. They also explore vulnerabilities in security tools like Binwalk, the complexities of firmware update tools, and the importance of transparency in software signing, particularly in the context of open source software. In this conversation, the speakers delve into the complexities of cybersecurity, focusing on the limitations of security through...

info_outline
Secure Boot Certificates Expiring: What You Need to Know - BTS #75 show art Secure Boot Certificates Expiring: What You Need to Know - BTS #75

Below the Surface (Audio) - The Supply Chain Security Podcast

In this episode of Below the Surface, the team discusses recent cybersecurity trends, including the Verizon DBIR 2026 report, secure boot certificate expirations, and the evolving threat landscape with AI and hardware vulnerabilities. They explore how organizations can adapt their defense strategies to stay ahead of attackers and share insights on supply chain security and malware analysis.               YellowKey update:    Chapters 00:00 Introduction and Technical Issues 02:56 Verizon DBIR Insights 05:50 Trends in Vulnerability...

info_outline
YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74 show art YellowKey, CVE Enrichment, Chipmaker Breach - BTS #74

Below the Surface (Audio) - The Supply Chain Security Podcast

In this episode, we explore recent vulnerabilities, the YellowKey BitLocker bypass, supply chain security, CVE data analysis, and the implications of hardware breaches like the one at Foxconn. We also delve into AI's role in vulnerability research and the evolving landscape of cybersecurity threats. Topics        Chapters 00:00 Introduction to Vulnerability Research and AI 03:42 NIST and CVE Growth Challenges 06:46 Building Tools for CVE Analysis 10:58 The Complexity of CVSS Scoring 15:08 CISA's Role in Vulnerability Enrichment 18:06 Challenges in CWE and CPE...

info_outline
Uncovering Firmware Risks: From Y2K to Modern Malware - BTS #73 show art Uncovering Firmware Risks: From Y2K to Modern Malware - BTS #73

Below the Surface (Audio) - The Supply Chain Security Podcast

In this episode of Below the Surface, hosts Paul Asadoorian, Chase Snyder, and guest Brian Richardson explore the evolution of firmware security, the risks of supply chain vulnerabilities, and the latest threats targeting network edge devices like Cisco ASA and FTD. They discuss historical malware like the Chernobyl virus, modern malware campaigns such as Firestarter, and the challenges of securing complex network infrastructure in a rapidly evolving threat landscape. Links: https://www.linkedin.com/news/story/white-house-pushes-back-on-anthropics-mythos-expansion-8741242/ ...

info_outline
AI-Powered Firmware Hacking: The Future of Vulnerability Discovery - BTS #72 show art AI-Powered Firmware Hacking: The Future of Vulnerability Discovery - BTS #72

Below the Surface (Audio) - The Supply Chain Security Podcast

In this episode, the hosts explore the latest in cybersecurity, including AI-driven vulnerability discovery, firmware analysis tools, secure boot complexities, and recent CVE trends. They discuss practical techniques for hacking devices, the challenges of firmware emulation, and the implications of new security policies on consumer and enterprise hardware. Chapters 00:00 Introduction to Hacking and Security Updates 03:24 Exploring Samsung TV Hacking 06:34 AI in Vulnerability Research 11:17 The Role of AI in Exploiting Vulnerabilities 15:18 CVE Disclosure and Ethical Considerations 20:43 AI...

info_outline
What Makes a Device a Router? - BTS #71 show art What Makes a Device a Router? - BTS #71

Below the Surface (Audio) - The Supply Chain Security Podcast

 summary In this episode, the hosts discuss the new FCC regulations regarding consumer routers, exploring the implications for cybersecurity, the definitions of what constitutes a router, and the challenges of manufacturing compliant devices. They delve into the debate surrounding the effectiveness of these regulations in mitigating cyber risks, the role of hardware versus software vulnerabilities, and the potential impact on consumers and existing devices in homes. In this conversation, the hosts discuss the implications of the FCC's decision to decertify routers and firmware, the...

info_outline
 
More Episodes

In this episode, the hosts discuss various cybersecurity topics, including the challenges of BIOS password cracking, the implications of AMD's Stack Warp vulnerability, and the importance of up-to-date secure boot certificates. They also explore the risks associated with network security appliances, the costs of cybersecurity, and the role of marketing in raising awareness. Additionally, they share insights from an X-ray analysis of USB cables, highlighting the differences between quality and counterfeit products.

 

  • BIOS password cracking can be complex and time-consuming.
  • Physical access to hardware can significantly impact security measures.
  • The Stack Warp vulnerability poses serious risks to virtual machines.
  • Secure boot certificates need regular updates to maintain security.
  • Network security appliances can introduce new vulnerabilities.
  • Cybersecurity costs often outweigh the perceived benefits of cloud solutions.
  • Marketing plays a crucial role in raising awareness about cybersecurity issues.
  • X-ray analysis can reveal the quality of electronic components.
  • Understanding the shared responsibility model is essential for IT teams.
  • The balance between security and operational efficiency is a constant challenge.

 

Chapters

01:59 Introduction to Below the Surface Podcast

04:46 BIOS Password Cracking Techniques

10:14 Exploring AMD's Stack Warp Vulnerability

22:03 Migration Trends in Cloud Computing

23:22 Cost vs. Security in On-Premises Solutions

24:37 Shared Responsibility in Network Security Appliances

27:03 The Risks of Network Security Appliances

28:14 Exploitation of Vulnerabilities in Network Devices

31:18 Challenges in Updating Network Security Appliances

34:59 The Slow Response to Vulnerabilities

39:05 The Complexity of Firmware Updates

45:45 Secure Boot Certificates and Future Vulnerabilities

49:12 Fun Innovations: X-ray Machine in the Office