<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0">
<channel>
  <atom:link href="https://feeds.cohostpodcasting.com/TIAo6Zgk" rel="self" title="MP3 Audio" type="application/atom+xml"/>
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <generator>https://cohostpodcasting.com</generator>
  <title><![CDATA[Unsafe: A Cybersecurity Podcast]]></title>
  <description><![CDATA[A Cybersecurity Podcast]]></description>
  <itunes:summary><![CDATA[A Cybersecurity Podcast]]></itunes:summary>
  <language>en</language>
  <copyright><![CDATA[Copyright 2026]]></copyright>
<podcast:guid>19678e47-8ff9-472f-908f-2a2718eb9624</podcast:guid>
  <pubDate>Tue, 28 Jul 2026 16:25:19 -0700</pubDate>
  <lastBuildDate>Wed, 09 Sep 2026 14:00:05 -0700</lastBuildDate>
  <image>
    <link>https://www.cohostpodcasting.com</link>
    <title><![CDATA[Unsafe: A Cybersecurity Podcast]]></title>
    <url>https://files.cohostpodcasting.com/quill-file-prod/79097fe3-19ba-46c5-87bd-9b718cfee100/shows/19678e47-8ff9-472f-908f-2a2718eb9624/cover-art/original_2884fcd3b8f731850e30009c32c175fc.png</url>
  </image>
  <link>https://www.cohostpodcasting.com</link>
  <itunes:type>episodic</itunes:type>
  <itunes:author><![CDATA[Gregory Flatt]]></itunes:author>
  <itunes:explicit>false</itunes:explicit>
  <itunes:image href="https://files.cohostpodcasting.com/quill-file-prod/79097fe3-19ba-46c5-87bd-9b718cfee100/shows/19678e47-8ff9-472f-908f-2a2718eb9624/cover-art/original_2884fcd3b8f731850e30009c32c175fc.png"/>
  <itunes:new-feed-url>https://feeds.cohostpodcasting.com/TIAo6Zgk</itunes:new-feed-url>
  
  <itunes:owner>
    <itunes:name><![CDATA[Gregory Flatt]]></itunes:name>
    <itunes:email>greg@unsafepodcast.com</itunes:email>
  </itunes:owner>
  <itunes:category text="Technology"/>
<item>
  <guid isPermaLink="false"><![CDATA[252f0ccf-b10b-44e2-90b1-6caf25c419bd]]></guid>
  <title><![CDATA[America's Water Infrastructure Hack: When "Convenience" Becomes the Enemy of Security]]></title>
  <description><![CDATA[<p>A coordinated cyberattack has hit water utilities in 12+ US states since late July 2026, and the "hack" is often just a default password nobody ever changed.</p><p><br></p><p>Since late July 2026, a coordinated wave of cyberattacks has targeted municipal water and wastewater systems across at least twelve states: Michigan, Minnesota, Georgia, South Dakota, and more. In this episode, the hosts dig into how attackers are actually getting in: not through some elaborate zero-day, but by finding programmable logic controllers (PLCs) and other operational technology (OT) sitting exposed directly on the internet, often still running the default password from the day they were installed. They trace the root cause back to a familiar culprit, convenience. </p><p><br></p><p>Rural water systems are maintained by third-party contractors managing thousands of devices across dozens of municipalities, and changing a unique password per site just doesn't scale the way leaving the factory default does. The conversation connects this directly to a real, publicly known vulnerability (CVE-2023-6448 (CVSS 9.8)) first weaponized against exposed VNC connections on MicroLogix controllers, and shows how the exact same exposure pattern shows up everywhere from Flock license-plate cameras to hospital medical equipment. </p><p><br></p><p>Greg and Caz also work through the harder question: what's the actual motive here? With attacks spread thin across dozens of small municipalities and no ransom demand in sight, money doesn't add up as an explanation, which points toward something more unsettling: a probing operation designed to map vulnerability and sow fear, possibly state-linked.</p><p><br></p><p>No water contamination has been confirmed as of this recording, but at least one system has already been forced into full manual operation, and boil-water notices have gone out. The fix: get OT off the public internet.  It's simple to state and brutally expensive and slow to actually implement across decades-old infrastructure that was never designed with security in mind.</p><p><br></p><p>0:00 Intro: A Coordinated Wave of Attacks on U.S. Water Systems</p><p>1:29 Why Default Passwords Are Everywhere in OT</p><p>4:14 Small Towns, Big Exposure (and NYC's Not-Quite-Vegan Water)</p><p>6:43 Is This a Probing Attack?</p><p>13:05 The Physical Devices Nobody Can Patch</p><p>20:36 The 2023 CVE That Predicted All of This</p><p>23:01 Beyond Water: Flock Cameras and Hospital Equipment</p><p>27:42 The Power Grid Could Be Next</p><p>34:10 Money Doesn't Explain This: Theories on Motive</p><p>36:25 What Should Utilities Actually Do?</p><p>47:06 Closing Thoughts: Simple Problem, Hard Fix</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>Since late July 2026, water/wastewater utilities in 12+ US states have been hit by a coordinated wave of attacks targeting internet-exposed PLCs and OT.</li><li>The core vulnerability is boring, not exotic: default passwords left in place by third-party installers and maintainers who need scalable remote access.</li><li>This maps directly onto a real, already-known vulnerability class — CVE-2023-6448 (CVSS 9.8), first weaponized in 2023 against exposed VNC connections on MicroLogix controllers.</li><li>The same exposure pattern (no credentials, or defaults, directly on the internet) shows up well beyond water — in license-plate-reader cameras and even hospital medical equipment.</li><li>No confirmed water contamination yet, but at least one utility has moved to fully manual operation, and boil-water notices have been issued.</li><li>The hosts argue the motive doesn't look financial — it looks more like a probing operation testing which communities are vulnerable, possibly state-linked.</li><li>The fix is conceptually simple (get OT off the public internet, segment networks, rotate credentials) but expensive and slow given decades-old infrastructure never designed for this threat model.</li></ul><p><br></p><p>Subscribe for more episodes breaking down the cybersecurity stories that actually matter Follow us on social media for updates between episodes Visit our website for more deep dives and show notes</p>]]></description>
  <pubDate>Wed, 09 Sep 2026 14:00:00 -0700</pubDate>
  <link>https://www.cohostpodcasting.com</link>
  <author><![CDATA[greg@unsafepodcast.com (Gregory Flatt)]]></author>
  <enclosure length="45740364" type="audio/mpeg" url="https://audio-delivery.cohostpodcasting.com/audio/79097fe3-19ba-46c5-87bd-9b718cfee100/episodes/9faf1153-a728-4329-bbd0-98e4b7f90096/episode.mp3" />
  <itunes:title><![CDATA[America's Water Infrastructure Hack: When "Convenience" Becomes the Enemy of Security]]></itunes:title>
  <itunes:duration>47:38</itunes:duration>
  <itunes:summary><![CDATA[<p>A coordinated cyberattack has hit water utilities in 12+ US states since late July 2026, and the "hack" is often just a default password nobody ever changed.</p><p><br></p><p>Since late July 2026, a coordinated wave of cyberattacks has targeted municipal water and wastewater systems across at least twelve states: Michigan, Minnesota, Georgia, South Dakota, and more. In this episode, the hosts dig into how attackers are actually getting in: not through some elaborate zero-day, but by finding programmable logic controllers (PLCs) and other operational technology (OT) sitting exposed directly on the internet, often still running the default password from the day they were installed. They trace the root cause back to a familiar culprit, convenience. </p><p><br></p><p>Rural water systems are maintained by third-party contractors managing thousands of devices across dozens of municipalities, and changing a unique password per site just doesn't scale the way leaving the factory default does. The conversation connects this directly to a real, publicly known vulnerability (CVE-2023-6448 (CVSS 9.8)) first weaponized against exposed VNC connections on MicroLogix controllers, and shows how the exact same exposure pattern shows up everywhere from Flock license-plate cameras to hospital medical equipment. </p><p><br></p><p>Greg and Caz also work through the harder question: what's the actual motive here? With attacks spread thin across dozens of small municipalities and no ransom demand in sight, money doesn't add up as an explanation, which points toward something more unsettling: a probing operation designed to map vulnerability and sow fear, possibly state-linked.</p><p><br></p><p>No water contamination has been confirmed as of this recording, but at least one system has already been forced into full manual operation, and boil-water notices have gone out. The fix: get OT off the public internet.  It's simple to state and brutally expensive and slow to actually implement across decades-old infrastructure that was never designed with security in mind.</p><p><br></p><p>0:00 Intro: A Coordinated Wave of Attacks on U.S. Water Systems</p><p>1:29 Why Default Passwords Are Everywhere in OT</p><p>4:14 Small Towns, Big Exposure (and NYC's Not-Quite-Vegan Water)</p><p>6:43 Is This a Probing Attack?</p><p>13:05 The Physical Devices Nobody Can Patch</p><p>20:36 The 2023 CVE That Predicted All of This</p><p>23:01 Beyond Water: Flock Cameras and Hospital Equipment</p><p>27:42 The Power Grid Could Be Next</p><p>34:10 Money Doesn't Explain This: Theories on Motive</p><p>36:25 What Should Utilities Actually Do?</p><p>47:06 Closing Thoughts: Simple Problem, Hard Fix</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>Since late July 2026, water/wastewater utilities in 12+ US states have been hit by a coordinated wave of attacks targeting internet-exposed PLCs and OT.</li><li>The core vulnerability is boring, not exotic: default passwords left in place by third-party installers and maintainers who need scalable remote access.</li><li>This maps directly onto a real, already-known vulnerability class — CVE-2023-6448 (CVSS 9.8), first weaponized in 2023 against exposed VNC connections on MicroLogix controllers.</li><li>The same exposure pattern (no credentials, or defaults, directly on the internet) shows up well beyond water — in license-plate-reader cameras and even hospital medical equipment.</li><li>No confirmed water contamination yet, but at least one utility has moved to fully manual operation, and boil-water notices have been issued.</li><li>The hosts argue the motive doesn't look financial — it looks more like a probing operation testing which communities are vulnerable, possibly state-linked.</li><li>The fix is conceptually simple (get OT off the public internet, segment networks, rotate credentials) but expensive and slow given decades-old infrastructure never designed for this threat model.</li></ul><p><br></p><p>Subscribe for more episodes breaking down the cybersecurity stories that actually matter Follow us on social media for updates between episodes Visit our website for more deep dives and show notes</p>]]></itunes:summary>
  <content:encoded><![CDATA[<p>A coordinated cyberattack has hit water utilities in 12+ US states since late July 2026, and the "hack" is often just a default password nobody ever changed.</p><p><br></p><p>Since late July 2026, a coordinated wave of cyberattacks has targeted municipal water and wastewater systems across at least twelve states: Michigan, Minnesota, Georgia, South Dakota, and more. In this episode, the hosts dig into how attackers are actually getting in: not through some elaborate zero-day, but by finding programmable logic controllers (PLCs) and other operational technology (OT) sitting exposed directly on the internet, often still running the default password from the day they were installed. They trace the root cause back to a familiar culprit, convenience. </p><p><br></p><p>Rural water systems are maintained by third-party contractors managing thousands of devices across dozens of municipalities, and changing a unique password per site just doesn't scale the way leaving the factory default does. The conversation connects this directly to a real, publicly known vulnerability (CVE-2023-6448 (CVSS 9.8)) first weaponized against exposed VNC connections on MicroLogix controllers, and shows how the exact same exposure pattern shows up everywhere from Flock license-plate cameras to hospital medical equipment. </p><p><br></p><p>Greg and Caz also work through the harder question: what's the actual motive here? With attacks spread thin across dozens of small municipalities and no ransom demand in sight, money doesn't add up as an explanation, which points toward something more unsettling: a probing operation designed to map vulnerability and sow fear, possibly state-linked.</p><p><br></p><p>No water contamination has been confirmed as of this recording, but at least one system has already been forced into full manual operation, and boil-water notices have gone out. The fix: get OT off the public internet.  It's simple to state and brutally expensive and slow to actually implement across decades-old infrastructure that was never designed with security in mind.</p><p><br></p><p>0:00 Intro: A Coordinated Wave of Attacks on U.S. Water Systems</p><p>1:29 Why Default Passwords Are Everywhere in OT</p><p>4:14 Small Towns, Big Exposure (and NYC's Not-Quite-Vegan Water)</p><p>6:43 Is This a Probing Attack?</p><p>13:05 The Physical Devices Nobody Can Patch</p><p>20:36 The 2023 CVE That Predicted All of This</p><p>23:01 Beyond Water: Flock Cameras and Hospital Equipment</p><p>27:42 The Power Grid Could Be Next</p><p>34:10 Money Doesn't Explain This: Theories on Motive</p><p>36:25 What Should Utilities Actually Do?</p><p>47:06 Closing Thoughts: Simple Problem, Hard Fix</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>Since late July 2026, water/wastewater utilities in 12+ US states have been hit by a coordinated wave of attacks targeting internet-exposed PLCs and OT.</li><li>The core vulnerability is boring, not exotic: default passwords left in place by third-party installers and maintainers who need scalable remote access.</li><li>This maps directly onto a real, already-known vulnerability class — CVE-2023-6448 (CVSS 9.8), first weaponized in 2023 against exposed VNC connections on MicroLogix controllers.</li><li>The same exposure pattern (no credentials, or defaults, directly on the internet) shows up well beyond water — in license-plate-reader cameras and even hospital medical equipment.</li><li>No confirmed water contamination yet, but at least one utility has moved to fully manual operation, and boil-water notices have been issued.</li><li>The hosts argue the motive doesn't look financial — it looks more like a probing operation testing which communities are vulnerable, possibly state-linked.</li><li>The fix is conceptually simple (get OT off the public internet, segment networks, rotate credentials) but expensive and slow given decades-old infrastructure never designed for this threat model.</li></ul><p><br></p><p>Subscribe for more episodes breaking down the cybersecurity stories that actually matter Follow us on social media for updates between episodes Visit our website for more deep dives and show notes</p>]]></content:encoded>
  <itunes:subtitle><![CDATA[A coordinated cyberattack has hit water utilities in 12+ US states since late July 2026, and the "hack" is often just a default password nobody ever changed.Since late July 2026, a coordinated wave of cyberattacks has targeted municipal water and w...]]></itunes:subtitle>
 <itunes:keywords><![CDATA[water system cyberattack,critical infrastructure security,OT security,ICS security,PLC vulnerability,SCADA security,default password vulnerability,CVE-2023-6448,water utility hacking,industrial control systems security,CISA water sector,VNC vulnerability,internet exposed PLC,water treatment cybersecurity,cybersecurity podcast]]></itunes:keywords>
  <itunes:explicit>true</itunes:explicit>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:episode>6</itunes:episode>
  <itunes:season>1</itunes:season>
</item>
<item>
  <guid isPermaLink="false"><![CDATA[f972eda0-c5fe-4d47-9ec5-3ce50915e29a]]></guid>
  <title><![CDATA[Meet Bob, Your North Korean Coworker: Inside the DPRK's Remote Work Con]]></title>
  <description><![CDATA[<p>Your best remote hire might be a North Korean operative funding Kim Jong Un's weapons program.</p><p><br></p><p>Greg and Caz talk with cybersecurity expert Gene Bandy about how North Korean IT workers use stolen identities and rehearsed interviews to land remote tech jobs at Western companies, funneling hundreds of millions of dollars a year back to the regime. They walk through real cases, including a laptop farm bust involving 90 laptops in one house, and share the behavioral and technical warning signs that HR and security teams can watch for, from disabled Wi-Fi to suspicious payment preferences. The conversation also covers why in-person interviews are one of the best defenses against deepfake hiring fraud, and why other countries are starting to copy North Korea's approach.</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>North Korean operatives earn the regime hundreds of millions a year through remote IT jobs.</li><li>Stolen identities and rehearsed interviews let them pass background checks.</li><li>Laptop farms hide where they're really working from.</li><li>In-person interviews are a simple, effective defense.</li><li>Other nations are starting to copy this approach.</li></ul><p><br></p>]]></description>
  <pubDate>Wed, 02 Sep 2026 14:00:00 -0700</pubDate>
  <link>https://www.cohostpodcasting.com</link>
  <author><![CDATA[greg@unsafepodcast.com (Gregory Flatt)]]></author>
  <enclosure length="54054017" type="audio/mpeg" url="https://audio-delivery.cohostpodcasting.com/audio/79097fe3-19ba-46c5-87bd-9b718cfee100/episodes/2d330521-2133-4278-b19c-f31c4459bdd9/episode.mp3" />
  <itunes:title><![CDATA[Meet Bob, Your North Korean Coworker: Inside the DPRK's Remote Work Con]]></itunes:title>
  <itunes:duration>56:18</itunes:duration>
  <itunes:summary><![CDATA[<p>Your best remote hire might be a North Korean operative funding Kim Jong Un's weapons program.</p><p><br></p><p>Greg and Caz talk with cybersecurity expert Gene Bandy about how North Korean IT workers use stolen identities and rehearsed interviews to land remote tech jobs at Western companies, funneling hundreds of millions of dollars a year back to the regime. They walk through real cases, including a laptop farm bust involving 90 laptops in one house, and share the behavioral and technical warning signs that HR and security teams can watch for, from disabled Wi-Fi to suspicious payment preferences. The conversation also covers why in-person interviews are one of the best defenses against deepfake hiring fraud, and why other countries are starting to copy North Korea's approach.</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>North Korean operatives earn the regime hundreds of millions a year through remote IT jobs.</li><li>Stolen identities and rehearsed interviews let them pass background checks.</li><li>Laptop farms hide where they're really working from.</li><li>In-person interviews are a simple, effective defense.</li><li>Other nations are starting to copy this approach.</li></ul><p><br></p>]]></itunes:summary>
  <content:encoded><![CDATA[<p>Your best remote hire might be a North Korean operative funding Kim Jong Un's weapons program.</p><p><br></p><p>Greg and Caz talk with cybersecurity expert Gene Bandy about how North Korean IT workers use stolen identities and rehearsed interviews to land remote tech jobs at Western companies, funneling hundreds of millions of dollars a year back to the regime. They walk through real cases, including a laptop farm bust involving 90 laptops in one house, and share the behavioral and technical warning signs that HR and security teams can watch for, from disabled Wi-Fi to suspicious payment preferences. The conversation also covers why in-person interviews are one of the best defenses against deepfake hiring fraud, and why other countries are starting to copy North Korea's approach.</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>North Korean operatives earn the regime hundreds of millions a year through remote IT jobs.</li><li>Stolen identities and rehearsed interviews let them pass background checks.</li><li>Laptop farms hide where they're really working from.</li><li>In-person interviews are a simple, effective defense.</li><li>Other nations are starting to copy this approach.</li></ul><p><br></p>]]></content:encoded>
  <itunes:subtitle><![CDATA[Your best remote hire might be a North Korean operative funding Kim Jong Un's weapons program.Greg and Caz talk with cybersecurity expert Gene Bandy about how North Korean IT workers use stolen identities and rehearsed interviews to land remote tec...]]></itunes:subtitle>
 <itunes:keywords><![CDATA[North Korean IT workers,DPRK IT worker scheme,North Korea laptop farms,remote work fraud,nation-state IT worker infiltration]]></itunes:keywords>
  <itunes:explicit>false</itunes:explicit>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:episode>5</itunes:episode>
  <itunes:season>1</itunes:season>
</item>
<item>
  <guid isPermaLink="false"><![CDATA[d22cd8c6-dab5-4043-a9da-28334e6426a1]]></guid>
  <title><![CDATA[Prompt Injection Exploits: The CVE That Weaponized the AI Coding Workflow]]></title>
  <description><![CDATA[<p>A hidden settings.json file was all it took to turn a normal GitHub download into full remote code execution, and Checkpoint found it inside Claude Code.</p><p><br></p><p>Adam Forrester, from Checkpoint, joins the show to break down a supply-chain vulnerability in the AI coding assistant Claude Code, where an unvalidated settings file let attackers hide commands inside an otherwise ordinary-looking Git repository, no phishing required.</p><p><br></p><p>We dig into how the exploit works, why it had to be patched twice, how it connects to the wider problem of prompt injection, and why NIST has shown AI guardrails can never fully close the gap. </p><p><br></p><p>We also talk through BYOD, shadow AI use in the workplace, and what small and medium businesses without enterprise security budgets can actually do to reduce their exposure.</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>An unvalidated settings file in Claude Code allowed hidden commands to execute the moment a project was run, a new twist on supply-chain attacks.</li><li>Guardrails alone can't solve this: NIST research shows full AI safety coverage is mathematically out of reach.</li><li>Smaller businesses face the same risk as enterprises but with far less budget for AI-specific security tooling.</li></ul><p><br></p>]]></description>
  <pubDate>Wed, 26 Aug 2026 14:00:00 -0700</pubDate>
  <link>https://www.cohostpodcasting.com</link>
  <author><![CDATA[greg@unsafepodcast.com (Gregory Flatt)]]></author>
  <enclosure length="47619470" type="audio/mpeg" url="https://audio-delivery.cohostpodcasting.com/audio/79097fe3-19ba-46c5-87bd-9b718cfee100/episodes/1a0391d1-07fb-4286-9d42-b3f2176adefe/episode.mp3?v=3c996bf2c1" />
  <itunes:title><![CDATA[Prompt Injection Exploits: The CVE That Weaponized the AI Coding Workflow]]></itunes:title>
  <itunes:duration>47:47</itunes:duration>
  <itunes:summary><![CDATA[<p>A hidden settings.json file was all it took to turn a normal GitHub download into full remote code execution, and Checkpoint found it inside Claude Code.</p><p><br></p><p>Adam Forrester, from Checkpoint, joins the show to break down a supply-chain vulnerability in the AI coding assistant Claude Code, where an unvalidated settings file let attackers hide commands inside an otherwise ordinary-looking Git repository, no phishing required.</p><p><br></p><p>We dig into how the exploit works, why it had to be patched twice, how it connects to the wider problem of prompt injection, and why NIST has shown AI guardrails can never fully close the gap. </p><p><br></p><p>We also talk through BYOD, shadow AI use in the workplace, and what small and medium businesses without enterprise security budgets can actually do to reduce their exposure.</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>An unvalidated settings file in Claude Code allowed hidden commands to execute the moment a project was run, a new twist on supply-chain attacks.</li><li>Guardrails alone can't solve this: NIST research shows full AI safety coverage is mathematically out of reach.</li><li>Smaller businesses face the same risk as enterprises but with far less budget for AI-specific security tooling.</li></ul><p><br></p>]]></itunes:summary>
  <content:encoded><![CDATA[<p>A hidden settings.json file was all it took to turn a normal GitHub download into full remote code execution, and Checkpoint found it inside Claude Code.</p><p><br></p><p>Adam Forrester, from Checkpoint, joins the show to break down a supply-chain vulnerability in the AI coding assistant Claude Code, where an unvalidated settings file let attackers hide commands inside an otherwise ordinary-looking Git repository, no phishing required.</p><p><br></p><p>We dig into how the exploit works, why it had to be patched twice, how it connects to the wider problem of prompt injection, and why NIST has shown AI guardrails can never fully close the gap. </p><p><br></p><p>We also talk through BYOD, shadow AI use in the workplace, and what small and medium businesses without enterprise security budgets can actually do to reduce their exposure.</p><p><br></p><p><strong>Key Takeaways:</strong></p><ul><li>An unvalidated settings file in Claude Code allowed hidden commands to execute the moment a project was run, a new twist on supply-chain attacks.</li><li>Guardrails alone can't solve this: NIST research shows full AI safety coverage is mathematically out of reach.</li><li>Smaller businesses face the same risk as enterprises but with far less budget for AI-specific security tooling.</li></ul><p><br></p>]]></content:encoded>
  <itunes:subtitle><![CDATA[A hidden settings.json file was all it took to turn a normal GitHub download into full remote code execution, and Checkpoint found it inside Claude Code.Adam Forrester, from Checkpoint, joins the show to break down a supply-chain vulnerability in t...]]></itunes:subtitle>
 <itunes:keywords><![CDATA[prompt injection podcast,AI security podcast,Claude Code exploit,AI supply chain attack,cybersecurity podcast AI risk]]></itunes:keywords>
  <itunes:explicit>false</itunes:explicit>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:episode>4</itunes:episode>
  <itunes:season>1</itunes:season>
</item>
<item>
  <guid isPermaLink="false"><![CDATA[11a5d89c-c6ac-4c38-9ffb-23ddc4ab1a56]]></guid>
  <title><![CDATA[Breaking Into Cybersecurity: Curiosity Beats Credentials]]></title>
  <description><![CDATA[<p>Cybersecurity careers rarely follow a straight line—and a degree or a stack of certifications is only part of the story.</p><p><br></p><p>In Season 1, Episode 3 of <strong>Unsafe: A Cybersecurity Podcast</strong>, Greg and Caz compare the unconventional paths that brought them into the field and ask what actually makes a candidate stand out. From career changers and home labs to practical experience, professional communities, and the pressure to keep learning, they explore why curiosity and enthusiasm can matter as much as what appears on a résumé.</p><p><br></p><p>The work can be fascinating, demanding, occasionally brutal, and definitely not for the faint of heart. So how do you know whether cybersecurity is the right career—or simply the career everyone thinks they want?</p><p><br></p><p><strong>Subscribe to Unsafe for candid conversations about cybersecurity and the realities behind the job description.</strong></p>]]></description>
  <pubDate>Wed, 19 Aug 2026 14:00:00 -0700</pubDate>
  <link>https://www.cohostpodcasting.com</link>
  <author><![CDATA[greg@unsafepodcast.com (Gregory Flatt)]]></author>
  <enclosure length="44233661" type="audio/mpeg" url="https://audio-delivery.cohostpodcasting.com/audio/79097fe3-19ba-46c5-87bd-9b718cfee100/episodes/84bd1672-b0c2-428d-b00c-fa37b29cf1bb/episode.mp3" />
  <itunes:title><![CDATA[Breaking Into Cybersecurity: Curiosity Beats Credentials]]></itunes:title>
  <itunes:duration>44:51</itunes:duration>
  <itunes:summary><![CDATA[<p>Cybersecurity careers rarely follow a straight line—and a degree or a stack of certifications is only part of the story.</p><p><br></p><p>In Season 1, Episode 3 of <strong>Unsafe: A Cybersecurity Podcast</strong>, Greg and Caz compare the unconventional paths that brought them into the field and ask what actually makes a candidate stand out. From career changers and home labs to practical experience, professional communities, and the pressure to keep learning, they explore why curiosity and enthusiasm can matter as much as what appears on a résumé.</p><p><br></p><p>The work can be fascinating, demanding, occasionally brutal, and definitely not for the faint of heart. So how do you know whether cybersecurity is the right career—or simply the career everyone thinks they want?</p><p><br></p><p><strong>Subscribe to Unsafe for candid conversations about cybersecurity and the realities behind the job description.</strong></p>]]></itunes:summary>
  <content:encoded><![CDATA[<p>Cybersecurity careers rarely follow a straight line—and a degree or a stack of certifications is only part of the story.</p><p><br></p><p>In Season 1, Episode 3 of <strong>Unsafe: A Cybersecurity Podcast</strong>, Greg and Caz compare the unconventional paths that brought them into the field and ask what actually makes a candidate stand out. From career changers and home labs to practical experience, professional communities, and the pressure to keep learning, they explore why curiosity and enthusiasm can matter as much as what appears on a résumé.</p><p><br></p><p>The work can be fascinating, demanding, occasionally brutal, and definitely not for the faint of heart. So how do you know whether cybersecurity is the right career—or simply the career everyone thinks they want?</p><p><br></p><p><strong>Subscribe to Unsafe for candid conversations about cybersecurity and the realities behind the job description.</strong></p>]]></content:encoded>
  <itunes:subtitle><![CDATA[Cybersecurity careers rarely follow a straight line—and a degree or a stack of certifications is only part of the story.In Season 1, Episode 3 of Unsafe: A Cybersecurity Podcast, Greg and Caz compare the unconventional paths that brought them into ...]]></itunes:subtitle>
 <itunes:keywords><![CDATA[Cybersecurity,CybersecurityCareers,BreakingIntoCybersecurity,InfoSec,CareerChange]]></itunes:keywords>
  <itunes:explicit>false</itunes:explicit>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:episode>3</itunes:episode>
  <itunes:season>1</itunes:season>
</item>
<item>
  <guid isPermaLink="false"><![CDATA[800063fd-362a-4d08-a337-999dbffd89f1]]></guid>
  <title><![CDATA[Identity Theft in Real Life: Your Information Is Already Out There]]></title>
  <description><![CDATA[<p>Identity theft does not always begin with malware, a hacked inbox, or a stolen password. Sometimes it begins with a convincing fake ID, enough personal information to answer a few questions, and an employee trying to be helpful.</p><p>In Season 1, Episode 2 of <strong>Unsafe: A Cybersecurity Podcast</strong>, Greg and Caz unpack a real 2026 identity-theft case that crossed financial institutions, state lines, corporate records, and law-enforcement jurisdictions. They examine the personal toll, the blind spots between banks and monitoring services, and the unsettling ease with which low-tech social engineering can defeat supposedly sophisticated safeguards.</p><p><br></p><p>Your information may already be out there. The real question is: who is ready to use it?</p><p><br></p><p><strong>Subscribe to Unsafe for more candid conversations about cybersecurity risks hiding in plain sight.</strong></p>]]></description>
  <pubDate>Wed, 12 Aug 2026 19:00:00 -0700</pubDate>
  <link>https://www.cohostpodcasting.com</link>
  <author><![CDATA[greg@unsafepodcast.com (Gregory Flatt)]]></author>
  <enclosure length="69356845" type="audio/mpeg" url="https://audio-delivery.cohostpodcasting.com/audio/79097fe3-19ba-46c5-87bd-9b718cfee100/episodes/d1fe97b6-7112-41db-b0c1-c9278446d1a3/episode.mp3" />
  <itunes:title><![CDATA[Identity Theft in Real Life: Your Information Is Already Out There]]></itunes:title>
  <itunes:duration>1:10:25</itunes:duration>
  <itunes:summary><![CDATA[<p>Identity theft does not always begin with malware, a hacked inbox, or a stolen password. Sometimes it begins with a convincing fake ID, enough personal information to answer a few questions, and an employee trying to be helpful.</p><p>In Season 1, Episode 2 of <strong>Unsafe: A Cybersecurity Podcast</strong>, Greg and Caz unpack a real 2026 identity-theft case that crossed financial institutions, state lines, corporate records, and law-enforcement jurisdictions. They examine the personal toll, the blind spots between banks and monitoring services, and the unsettling ease with which low-tech social engineering can defeat supposedly sophisticated safeguards.</p><p><br></p><p>Your information may already be out there. The real question is: who is ready to use it?</p><p><br></p><p><strong>Subscribe to Unsafe for more candid conversations about cybersecurity risks hiding in plain sight.</strong></p>]]></itunes:summary>
  <content:encoded><![CDATA[<p>Identity theft does not always begin with malware, a hacked inbox, or a stolen password. Sometimes it begins with a convincing fake ID, enough personal information to answer a few questions, and an employee trying to be helpful.</p><p>In Season 1, Episode 2 of <strong>Unsafe: A Cybersecurity Podcast</strong>, Greg and Caz unpack a real 2026 identity-theft case that crossed financial institutions, state lines, corporate records, and law-enforcement jurisdictions. They examine the personal toll, the blind spots between banks and monitoring services, and the unsettling ease with which low-tech social engineering can defeat supposedly sophisticated safeguards.</p><p><br></p><p>Your information may already be out there. The real question is: who is ready to use it?</p><p><br></p><p><strong>Subscribe to Unsafe for more candid conversations about cybersecurity risks hiding in plain sight.</strong></p>]]></content:encoded>
  <itunes:subtitle><![CDATA[Identity theft does not always begin with malware, a hacked inbox, or a stolen password. Sometimes it begins with a convincing fake ID, enough personal information to answer a few questions, and an employee trying to be helpful.In Season 1, Episode...]]></itunes:subtitle>
 <itunes:keywords><![CDATA[IdentityTheft,Cybersecurity,FraudPrevention,BankFraud,OnlineSecurity]]></itunes:keywords>
  <itunes:explicit>false</itunes:explicit>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:episode>2</itunes:episode>
  <itunes:season>1</itunes:season>
</item>
<item>
  <guid isPermaLink="false"><![CDATA[525de3d8-c139-415f-aa61-ec327285ad3e]]></guid>
  <title><![CDATA[Third-Party Risk: Your Vendor’s Breach Is Still Your Problem]]></title>
  <description><![CDATA[<p>You can outsource the technology. You can outsource the help desk. You can even outsource the security controls. What you cannot outsource are the consequences when someone else loses your data.</p><p>In this episode of <strong>Unsafe: A Cybersecurity Podcast</strong>, co-hosts Greg and Caz examine the uncomfortable reality of third-party risk. Beginning with the 2026 Canvas cybersecurity incident, they explore the hidden dependencies behind SaaS platforms, cloud services, integrations, outsourced support teams, and the vendors behind your vendors.</p><p><br></p><p>How many organizations actually know everyone who can access their critical information—and how many are simply trusting the black box?</p><p><br></p><p>Subscribe to <strong>Unsafe</strong> for candid conversations about cybersecurity risks businesses cannot afford to ignore.</p>]]></description>
  <pubDate>Wed, 05 Aug 2026 15:00:00 -0700</pubDate>
  <link>https://www.cohostpodcasting.com</link>
  <author><![CDATA[greg@unsafepodcast.com (Gregory Flatt)]]></author>
  <enclosure length="56029256" type="audio/mpeg" url="https://audio-delivery.cohostpodcasting.com/audio/79097fe3-19ba-46c5-87bd-9b718cfee100/episodes/644f36e0-387c-425d-8a35-7bb889947bd6/episode.mp3" />
  <itunes:title><![CDATA[Third-Party Risk: Your Vendor’s Breach Is Still Your Problem]]></itunes:title>
  <itunes:duration>56:38</itunes:duration>
  <itunes:summary><![CDATA[<p>You can outsource the technology. You can outsource the help desk. You can even outsource the security controls. What you cannot outsource are the consequences when someone else loses your data.</p><p>In this episode of <strong>Unsafe: A Cybersecurity Podcast</strong>, co-hosts Greg and Caz examine the uncomfortable reality of third-party risk. Beginning with the 2026 Canvas cybersecurity incident, they explore the hidden dependencies behind SaaS platforms, cloud services, integrations, outsourced support teams, and the vendors behind your vendors.</p><p><br></p><p>How many organizations actually know everyone who can access their critical information—and how many are simply trusting the black box?</p><p><br></p><p>Subscribe to <strong>Unsafe</strong> for candid conversations about cybersecurity risks businesses cannot afford to ignore.</p>]]></itunes:summary>
  <content:encoded><![CDATA[<p>You can outsource the technology. You can outsource the help desk. You can even outsource the security controls. What you cannot outsource are the consequences when someone else loses your data.</p><p>In this episode of <strong>Unsafe: A Cybersecurity Podcast</strong>, co-hosts Greg and Caz examine the uncomfortable reality of third-party risk. Beginning with the 2026 Canvas cybersecurity incident, they explore the hidden dependencies behind SaaS platforms, cloud services, integrations, outsourced support teams, and the vendors behind your vendors.</p><p><br></p><p>How many organizations actually know everyone who can access their critical information—and how many are simply trusting the black box?</p><p><br></p><p>Subscribe to <strong>Unsafe</strong> for candid conversations about cybersecurity risks businesses cannot afford to ignore.</p>]]></content:encoded>
  <itunes:subtitle><![CDATA[You can outsource the technology. You can outsource the help desk. You can even outsource the security controls. What you cannot outsource are the consequences when someone else loses your data.In this episode of Unsafe: A Cybersecurity Podcast, co...]]></itunes:subtitle>
 <itunes:keywords><![CDATA[Cybersecurity,ThirdPartyRisk,VendorRisk,SupplyChainSecurity,SaaSSecurity]]></itunes:keywords>
  <itunes:explicit>false</itunes:explicit>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:episode>1</itunes:episode>
  <itunes:season>1</itunes:season>
</item>
</channel>
</rss>