38 épisodes
- A company can lose its most valuable product plans without a broken lock, an encrypted laptop, or an obvious warning on the screen. The first clear sign may be an extortion email claiming the files are already gone.
This episode of Plaintext with Rich explains the attacks disclosed against PTC Windchill and FlexPLM, two product lifecycle management platforms that can hold designs, bills of materials, manufacturing instructions, supplier details, and launch plans. Rich breaks down CVE-2026-12569, remote code execution, unsafe deserialization, and web shells in language built for people who do not spend their days reading security advisories. You will also hear why CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, why reporting in July 2026 compared the campaign tactics to Clop, and why attribution was unconfirmed when the episode was prepared. Most importantly, the episode explains why applying the PTC patch is only half the job when attackers may already have copied sensitive data.
This is for business leaders, technology teams, product owners, manufacturers, retailers, and anyone responsible for a central platform that holds concentrated company value. It offers a practical way to think about patching, compromise hunting, incident response, and the business decisions that follow possible data theft.
One Topic, Ten minutes, No panic.
Is there a topic/term you want me to discuss next? Text me!!
YouTube more your speed? → https://links.sith2.com/YouTube
Apple Podcasts your usual stop? → https://links.sith2.com/Apple
Neither of those? Spotify’s over here → https://links.sith2.com/Spotify
Prefer reading quietly at your own pace? → https://links.sith2.com/Blog
Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord
Follow the human behind the microphone → https://links.sith2.com/linkedin
Need another way to reach me? That’s here → https://linktr.ee/rich.greene - A critical SharePoint alert arrives, the update goes in, and the ticket closes. But what if an attacker entered before the lock was fixed and left with secrets that still work?
In this episode of Plaintext with Rich, Rich explains why CVE-2026-50522 is more than an ordinary patch story. The actively exploited remote code execution flaw affects on-premises Microsoft SharePoint Server, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. You will hear why CISA's Known Exploited Vulnerabilities catalog matters, how SharePoint machine keys can extend risk beyond the vulnerable code, and why a clean vulnerability scan cannot prove that nobody arrived earlier. Rich breaks the response into three separate jobs: patch the affected farm, hunt for signs of compromise and persistence, and rotate machine keys, credentials, or tokens that may have been exposed. He also explains why rotation must be coordinated to avoid session, authentication, and integration problems.
This episode is for leaders, business owners, IT teams, and anyone responsible for asking whether a SharePoint incident is truly contained. It gives you better questions for the status meeting without turning a serious risk into panic.
One Topic, Ten minutes, No panic.
Is there a topic/term you want me to discuss next? Text me!!
YouTube more your speed? → https://links.sith2.com/YouTube
Apple Podcasts your usual stop? → https://links.sith2.com/Apple
Neither of those? Spotify’s over here → https://links.sith2.com/Spotify
Prefer reading quietly at your own pace? → https://links.sith2.com/Blog
Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord
Follow the human behind the microphone → https://links.sith2.com/linkedin
Need another way to reach me? That’s here → https://linktr.ee/rich.greene - You told your AI assistant to book a flight and compare hotels. You come back, and it did all of that. It also ran commands on your machine that you never approved. What just happened?
This episode unpacks AutoJack, a demonstrated attack pattern where malicious web pages hijack AI browsing agents through prompt injection. We cover how untrusted web content can steer autonomous agents into unsafe actions, the critical risk of localhost access in agent frameworks like AutoGen, and the chain from reading a bad page to remote code execution on your host machine. You'll learn why giving an agent a browser is fundamentally different from giving it information access, and how ambient authority plus autonomous actions creates a blast radius most teams haven't planned for.
This is for security teams adopting AI agents, engineering leads building agentic tools, and anyone who needs to understand the new attack surface before deploying browsing automation at work.
One Topic, Ten minutes, No panic.
Is there a topic/term you want me to discuss next? Text me!!
YouTube more your speed? → https://links.sith2.com/YouTube
Apple Podcasts your usual stop? → https://links.sith2.com/Apple
Neither of those? Spotify’s over here → https://links.sith2.com/Spotify
Prefer reading quietly at your own pace? → https://links.sith2.com/Blog
Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord
Follow the human behind the microphone → https://links.sith2.com/linkedin
Need another way to reach me? That’s here → https://linktr.ee/rich.greene - You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code.
This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your attack surface, the difference between package takedown and forensic cleanup, and why lockfiles are history snapshots not security verdicts. We walk through the controls that protect teams most: deterministic builds with pinned versions and provenance attestations for verified package origins. The episode includes timeline thinking for exposure windows, hunting for execution artifacts beyond package names, and the specific steps for rotating secrets and rebuilding compromised environments.
This is for developers, security teams, and engineering leaders managing open source dependencies in fast moving stacks.
One Topic, Ten minutes, No panic.
Is there a topic/term you want me to discuss next? Text me!!
YouTube more your speed? → https://links.sith2.com/YouTube
Apple Podcasts your usual stop? → https://links.sith2.com/Apple
Neither of those? Spotify’s over here → https://links.sith2.com/Spotify
Prefer reading quietly at your own pace? → https://links.sith2.com/Blog
Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord
Follow the human behind the microphone → https://links.sith2.com/linkedin
Need another way to reach me? That’s here → https://linktr.ee/rich.greene - Your update dashboard keeps climbing. Not ten fixes, not fifty. Two hundred and six security patches waiting for approval, and everyone is asking if work stops now. That was June 2026, the largest Patch Tuesday on record.
This episode covers why record patch volumes are becoming normal, what AI-assisted vulnerability discovery has to do with the bug pipeline, how to prioritize under pressure with a four-lens triage framework (exploitability, exposure, impact, compensating controls), and why the real problem is not volume but the speed mismatch between finding bugs and fixing them. We walk through CVE-2026-45657, the wormable kernel issue rated CVSS 9.8, and what that severity score actually means for your risk timeline. You will also get a practical approach to building a 24-hour critical patch lane, classifying assets before the next wave, and using temporary containment when patching must wait.
This is for IT leaders managing emergency change windows, security teams ranking exploit paths, and business leaders deciding when downtime is justified.
One Topic, Ten minutes, No panic.
Is there a topic/term you want me to discuss next? Text me!!
YouTube more your speed? → https://links.sith2.com/YouTube
Apple Podcasts your usual stop? → https://links.sith2.com/Apple
Neither of those? Spotify’s over here → https://links.sith2.com/Spotify
Prefer reading quietly at your own pace? → https://links.sith2.com/Blog
Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord
Follow the human behind the microphone → https://links.sith2.com/linkedin
Need another way to reach me? That’s here → https://linktr.ee/rich.greene
Plus de podcasts Technologies
Podcasts tendance de Technologies
À propos de Plaintext with Rich
Cybersecurity is an everyone problem. So why does it always sound like it’s only for IT people?Each week, Rich takes one topic, from phishing to ransomware to how your phone actually tracks you, and explains it in plain language in under ten minutes or less. No buzzwords. No condescension. Just the stuff you need to know to stay safer online, explained like you’re a smart person who never had anyone break it down properly. Because you are!
Site web du podcastÉcoutez Plaintext with Rich, Silicon Carne, un peu de picante dans un monde de Tech ! ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités
Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités


Plaintext with Rich
Scannez le code,
Téléchargez l’app,
Écoutez.
Téléchargez l’app,
Écoutez.
Plaintext with Rich: Podcasts du groupe


































