~ cueing up the show ~
~ pulling every episode ~
Plaintext with Rich — Every episode — OmList
om
list
Swipe
Tournament
Lists
Friends
All
Movies
TV
Books
Games
Music
Podcasts
People
▾
Sign in
Every episode
Plaintext with Rich
30 episodes
PTC Windchill Vulnerability: Why Your Product Blueprints Are at Risk
Ep 38 · Aug 14, 2026 · 10 min
A company can lose its most valuable product plans without a broken lock, an encrypted laptop, or an obvious warning on the screen. The first clear sign may be an extortion email claiming the files are already gone. This episode of Plaintext with Rich explains the attacks disclosed against PTC Windchill and FlexPLM, two product lifecycle management platforms that can hold designs, bills of materials, manufacturing instructions, supplier details, and launch plans. Rich breaks down CVE-2026-12569,…
CVE-2026-50522: Why SharePoint Patching Is Only Step One
Ep 37 · Aug 7, 2026 · 10 min
A critical SharePoint alert arrives, the update goes in, and the ticket closes. But what if an attacker entered before the lock was fixed and left with secrets that still work? In this episode of Plaintext with Rich, Rich explains why CVE-2026-50522 is more than an ordinary patch story. The actively exploited remote code execution flaw affects on-premises Microsoft SharePoint Server, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.…
AutoJack Attack: How Malicious Pages Hijack AI Browsing Agents
Ep 36 · Jul 31, 2026 · 9 min
You told your AI assistant to book a flight and compare hotels. You come back, and it did all of that. It also ran commands on your machine that you never approved. What just happened? This episode unpacks AutoJack, a demonstrated attack pattern where malicious web pages hijack AI browsing agents through prompt injection. We cover how untrusted web content can steer autonomous agents into unsafe actions, the critical risk of localhost access in agent frameworks like AutoGen, and the chain from r…
North Korea Mastra NPM Supply Chain Attack: How It Works
Ep 35 · Jul 24, 2026 · 10 min
You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code. This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your attac…
Patch Tuesday 206 Vulnerabilities: AI Discovery vs Remediation Speed
Ep 34 · Jul 17, 2026 · 9 min
Your update dashboard keeps climbing. Not ten fixes, not fifty. Two hundred and six security patches waiting for approval, and everyone is asking if work stops now. That was June 2026, the largest Patch Tuesday on record. This episode covers why record patch volumes are becoming normal, what AI-assisted vulnerability discovery has to do with the bug pipeline, how to prioritize under pressure with a four-lens triage framework (exploitability, exposure, impact, compensating controls), and why the…
Instagram AI Takeover: How Attackers Exploited Meta Support Bots
Ep 33 · Jul 10, 2026 · 9 min
Your profile photo vanishes. Your email is changed. A password reset you never requested lands in someone else's inbox. You're locked out of your own Instagram account, and you didn't click a single suspicious link. In early 2026, attackers manipulated Meta's AI support chatbot to approve password resets on roughly 20,225 Instagram accounts over seven weeks. This episode breaks down how social engineering evolved from targeting human support reps to exploiting AI-powered customer service systems…
FortiBleed: When Your Firewall Becomes the Front Door
Ep 32 · Jul 3, 2026 · 10 min
Your firewall is supposed to be the thing that keeps attackers out. FortiBleed is the story of what happens when it becomes the way in. In June 2026, roughly 86,644 sets of working Fortinet credentials turned up circulating among attackers across 194 countries. On June 18th, CISA issued an emergency advisory telling anyone running internet-facing Fortinet gear to terminate active sessions, rotate every credential, and turn on phishing-resistant multi-factor authentication immediately. This episo…
Post-Quantum Cryptography: Start the Inventory Before Q-Day
Ep 31 · Jun 26, 2026 · 10 min
You don't inventory your house the morning of the move. You start months before. So why are most organizations still treating post-quantum cryptography as a 2035 problem? Episode 31 of Plaintext with Rich treats the post-quantum crypto migration as what it actually is. A logistics problem, not a science one. We walk through the news peg that moved the timeline. Google's March 2026 announcement of a 2029 internal deadline, years ahead of federal targets, anchored by Craig Gidney's research at Goo…
Cybersecurity Careers and AI: The Squeeze and the Opening
Ep 30 · Jun 19, 2026 · 10 min
Someone pulled Rich aside at a conference recently. Six years in IT, ready to break into security, and asking the question more people ask every week. Should I even bother right now? Here's what the data actually shows. Episode 30 of Plaintext with Rich unpacks the cybersecurity career paradox of 2026. The bottom rung is getting squeezed as AI automates SOC analyst, threat intelligence, and incident response work. At the same time, demand for AI security engineers, prompt injection specialists,…
Supply Chain Attacks: How One Update Hit OpenAI
Ep 29 · Jun 12, 2026 · 9 min
A routine software update. No phishing. No sketchy download. Then a security team finds the unthinkable: trusted code has been hijacked, and the breach rode in through the exact channels engineers rely on every day. I walk through the supply chain attacks that piled up across April and May 2026, including poisoned open source packages tied to TanStack and trojanized Daemon Tools installers, plus the rapid-fire abuse of major software registries like NPM, PyPI, and Docker Hub. The most important…
Microsoft Exchange Zero-Day Under Attack: One Email Hijacks OWA
Ep 28 · Jun 5, 2026 · 9 min
It's Monday morning. You open the third email of the day. Nothing visible happens, but in the background, an attacker just borrowed the proof you were logged in. Episode 28 of Plaintext with Rich is a hot take on CVE-2026-42897, the Microsoft Exchange Server zero-day under active exploitation right now. We break down what cross-site scripting actually does inside Outlook Web Access, why session hijacking is more dangerous than the underlying bug, and how a single crafted email becomes business e…
Work-Life Balance in Cybersecurity: The Structural Fix
Ep 27 · May 29, 2026 · 9 min
You finish at 6:00pm. At 6:47 you reopen the laptop, 'just to check something.' By 9:00 the evening is gone. The boundary didn't fail tonight. It was never there. Episode 27 of Plaintext with Rich closes the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we're talking about work-life balance, but not as willpower or time management. As protective infrastructure. We pull the arc together, mental, spiritual, physical, and burnout, and land…
Cybersecurity Burnout: Not a Character Flaw, a System Problem
Ep 26 · May 22, 2026 · 9 min
You're reading a breach report. Third one this month. Last year a story like this would have lit something in you. Today you scroll past it. That's not you. That's the bill. Episode 26 of Plaintext with Rich is the fourth installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we're talking about burnout, what it actually is and why the cybersecurity industry produces it reliably. We use the World Health Organization's classific…
Physical Health in Cybersecurity: The Body Keeps the Receipts
Ep 25 · May 15, 2026 · 8 min
It's Friday morning. You stand up to refill your water and your back doesn’t move the way it used to. The systems are up and running smoothly. Your body hasn’t gotten the same memo. Episode 25 of Plaintext with Rich is the third installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we’re talking about physical health, the silent receipt your body keeps for the cumulative load of this job. We get into the specific body costs of…
Spiritual Health in Cybersecurity: The Why Behind the Work
Ep 24 · May 8, 2026 · 9 min
Spiritual health on a cybersecurity podcast sounds like a stretch. Stay with us. Because somewhere between the vendor pitches, the patch cycles, and the 3 a.m. page, a lot of us stopped working for the why and started working for the number. Episode 24 of Plaintext with Rich is the second installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we define spiritual health as the values that make up who you are, the things you won’…
Mental Health in Cybersecurity: The Weight of Vigilance
Ep 23 · May 1, 2026 · 8 min
It's 6:47 a.m. The incident was contained hours ago. The systems are fine. You're the one still running hot. This episode opens the Month of Mindfulness, a five-week Plaintext with Rich series on mental health, spiritual health, physical health, burnout, and work-life balance for people working in cybersecurity and tech. May 1 happens to fall during Mental Health Awareness Month, which makes it the right time to start. We're talking about the mental load that comes with vigilance work: on-call r…
Threat Intelligence: Why Most Organizations Get It Backwards
Ep 22 · Apr 24, 2026 · 9 min
A dashboard lights up with indicators of compromise. The analyst copies the top five into a ticket, tags it "actionable," and sends it to the SOC. Nobody reads it not because they don't care, but because it didn't tell them what to do or why it mattered. That's not an intelligence failure. That's a confusion about what intelligence actually is. This episode breaks down threat intelligence from the ground up, drawing on Rich's military experience as a case officer in special operations. It separa…
Roll for Security: What D&D Teaches About Cyber Defense
Ep 21 · Apr 17, 2026 · 10 min
The fighter absorbs hits up front. The rogue finds traps before the party walks into them. The cleric keeps everyone alive when things go wrong. And the bard convinces the people with resources to actually fund the quest. Nobody does everything. Everybody has a role. Now replace the dungeon with your company's network. This episode maps cybersecurity roles to D&D character classes, SOC analysts as fighters, pen testers as rogues, incident response as clerics, security architects as wizards, CISO…
Why Reading Code Makes You Dangerous (In a Good Way)
Ep 20 · Apr 10, 2026 · 10 min
A vulnerability advisory drops on a Tuesday. Two people read the same report. One sees a severity score and waits for a patch. The other understands what a heap-based buffer overflow actually means and starts reducing risk before a fix even exists. This episode breaks down why code literacy is a cybersecurity skill, not just a developer skill. It starts with the listener's question about learning C and C++ for security, then widens the lens to cover the full stack: why C still matters because of…
Hacking on Screens and Pages: Pop Culture That Shaped Cybersecurity
Ep 19 · Apr 3, 2026 · 11 min
Someone sits down at a keyboard, mashes keys for six seconds, and says "I'm in." Every security professional dies a little inside but that scene is probably the reason half of us got into this field. This episode walks through the movies, TV shows, books, graphic novels, and video games that shaped how we think about cybersecurity. Each pick lands in one of two buckets: the fantastical, the ones that made hacking look cool even when the tech was nonsense and the accurate or semi accurate, the on…
Linux vs. Windows vs. macOS: Where Security Actually Differs
Ep 18 · Mar 27, 2026 · 8 min
People love to ask which operating system is the most secure. That's the wrong shape of question. Each one is designed for a different job, and that shapes how it gets attacked. This episode clears up what Linux actually is, how it compares to Windows and macOS, and why the differences matter for security. It starts by explaining why Linux isn't one product but a family of systems built around a shared kernel, then covers how each OS handles permissions, software installation, and administrator…
APIs: The Control Points Hiding Inside Every App
Ep 17 · Mar 20, 2026 · 7 min
You tap a button and a ride shows up. You check out online and your bank approves it in seconds. It feels automatic. But nothing in software is automatic. Something received a request, decided it was valid, did some work, and sent back a response. That something is an API. This episode breaks down what APIs actually are, why they exist, when to use them, and why they matter far more than most people realize. It starts with a restaurant analogy that makes the concept click, then walks through how…
Securing AI at Work: What the Chat Box Actually Touches
Ep 16 · Mar 13, 2026 · 8 min
At 4:47 p.m., someone pastes a customer escalation into an AI assistant and asks it to rewrite the tone. The reply is perfect. It also includes a private note from the internal thread. No breach. No attacker. Just a new workflow that doesn't know what should stay inside. This episode breaks down how to secure AI tools in the workplace by treating them like any other system that handles sensitive information and influences decisions. It covers the three patterns where AI quietly breaks: sensitive…
AI Is an Umbrella Word (And That's the Problem)
Ep 15 · Mar 6, 2026 · 8 min
Every company says they're using AI. Some mean chatbots. Some mean automation. Some mean statistics with a new logo. If everything is AI, the word stops meaning anything. This episode untangles what people actually mean when they say "AI" by breaking the umbrella into its real components. It covers machine learning (systems that learn patterns from data), deep learning (layered neural networks that made modern recognition possible), large language models (text prediction engines driving today's…
Why Security Fails When Everyone Is Right
Ep 14 · Feb 27, 2026 · 7 min
The access made sense. The exception was justified. The shortcut saved time. Each decision worked on its own. And somehow, together, they added up to failure. This episode tackles the uncomfortable truth that most security failures aren't caused by ignorance or carelessness. They're caused by systems quietly accumulating risk while everyone is doing their best. It walks through the patterns that create this drift: temporary decisions that never expire, blurred ownership where risk becomes nobody…
Zero Trust: What It Actually Means Beyond the Buzzword
Ep 13 · Feb 20, 2026 · 8 min
The breach didn't come through a broken firewall. It walked in through a valid login. Nothing exploded. Nothing looked suspicious at first. Someone just signed in and kept going. This episode clears up what Zero Trust actually is and what it isn't. It's not a product, not a box you install, and not a technology you turn on. It's a design decision: don't automatically believe a request just because it comes from inside your network. The episode explains why the old perimeter model stopped working…
Supply Chain Cybersecurity: When the Breach Starts Upstream
Ep 12 · Feb 13, 2026 · 8 min
You can lock down every system you own. Patch everything. Train everyone. And still lose control, because the failure didn't start with you. It started somewhere upstream. This episode breaks down supply chain cybersecurity by explaining why attackers who can't reach you directly look for someone you already trust. It covers the most common patterns: tampered software updates that arrive through legitimate channels, vendor breaches that expose your data through someone else's failure, compromise…
Phishing and Social Engineering: Why the Strongest Defense Is Being Slower
Ep 11 · Feb 6, 2026 · 9 min
You don't need to break a system if someone will open it for you. You don't need malware if a message feels urgent enough. Most modern breaches don't start with code. They start with a conversation. This episode breaks down phishing and social engineering by explaining why these attacks keep working: they don't fight logic, they sidestep it. It covers how modern phishing has evolved beyond email to include text messages, voice calls, MFA fatigue attacks, QR code phishing, and AI-assisted imperso…
Ransomware and Double Extortion: Why Backups Alone Don't Save You Anymore
Ep 10 · Jan 30, 2026 · 8 min
You don't get locked out first. You get watched. Someone maps your systems quietly, copies your data quietly, and waits until they're sure you can't avoid the conversation. Only then do the screens go dark. This episode breaks down how ransomware actually works today and why double extortion changed the stakes completely. It explains how modern ransomware operations move slowly at first, stealing credentials and exploring systems before copying data and triggering encryption. The real leverage i…
IoT Security: Why Every Smart Device Is a Computer That Inherits Risk
Ep 9 · Jan 23, 2026 · 8 min
Your house didn't suddenly become unsafe. It just became chatty. Little devices, quietly talking to the internet, all day, all night. Most of them were never meant to be guarded. This episode explains IoT security by starting with a translation: if a device needs an app to work and Wi-Fi to exist, it's a computer with software, memory, and network access, and computers inherit risk. It covers why manufacturers optimize for convenience over long-term protection, how most IoT compromises happen th…
← Back to the show