Skip to content
Artwork for Error Code

Error Code

Robert Vamosi

Error Code is a biweekly narrative podcast that provides you both context and conversation with some of the best minds working today toward code resilience and dependability. Work that can lead to autonomous vehicles and smart cities. It’s your window in the research solving tomorrow’s code problems today.

Play
  • 20 episodes
  • fortnightly
  • Avg 32 min
  • English
  • #92
    August 18 · 26 min

    EP 91: Three Years Until Your Encryption Stops Working

    At Black Hat USA 2026, cybersecurity experts issued a stark warning: we may have just three years to shore up the invisible web of keys and certificates that keeps power grids, billing systems, and critical infrastructure secure. Ellen Boehm of Keyfactor explains why the clock is ticking—and what must happen now with post-quantum cryptography.

  • #91
    July 22 · 35 min

    EP 90: Your Weakest Vendor Is Someone’s Biggest Problem

    Why one vendor breach can take down dozens of banks — third-party risk, AI-driven attacks, and why patching fast may beat patching safe today. Jeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite, explains.

  • #90
    July 7 · 39 min

    EP 89: How AI Is Breaking OT Cybersecurity

    AI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won't save it. Jori VanAntwerp, CEO and founder of Ember OT, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters.

  • #88
    May 27 · 29 min

    EP 87: Backup, Control Gaps, and the Real Cost of Agentic AI Actions

    An AI agent wiped out an entire company’s data in just 9 seconds — no hacker, no ransomware involved. Todd Thorsen, Chief Information Security Officer at CrashPlan, explains how a misconfigured AI agent operating without safeguards may have caused the incident — and asks a troubling question: could your organization be next?

  • #87
    May 12 · 32 min

    EP 86: The Trusted Channel: AT Command Exploits and Cellular IoT Security

    Cellular modules in your IoT devices are trusted and that trust can be an insecure pivot point into your network for attackers. Deral Heiland, Principal Security Research for IoT at Rapid 7 discusses his presentation at RSAC 2026 on AT command exploits and supply chain risk.

  • #85
    April 15 · 37 min

    EP 84: Airports as Critical Infrastructure: OT Security and Operational Disruption

    Airports illustrate the potential impact of OT attacks that disrupt functionality. Dan Gunter, CEO of Insane Cyber, talks about how industrial environments differ from traditional IT, particularly in their reliance on availability and safety, where disruptions can have significant real-world and financial consequences.

  • #84
    March 31 · 24 min

    EP 83: Cybersecurity and Risk in a Decentralized Energy Grid

    The surge in renewables and decentralized power is reshaping grids—and exposing them to new operational and cyber risks. In this episode, Rafael Narezzi, Co-Founder & CEO of Centrii, explains how rising connectivity widens the attack surface, leaving energy infrastructure increasingly vulnerable.

  • #83
    March 4 · 26 min

    EP 82: Kerberos in OT: RC4 Downgrade Attacks

    Kerberos, a decades-old authentication protocol, creates hidden risks in OT environments. Dor Segal, security researcher team lead at Silverfort, discusses delegation abuse, cipher downgrade attacks, and person-in-the-middle threats—highlighting why legacy encryption, patching challenges, and operational constraints make identity security critical in industrial networks.

  • #82
    February 17 · 34 min

    EP 81: Root of Trust: Why Security Now Starts in Silicon

    Rising software complexity in safety-critical industries is forcing cybersecurity requirements on systems previously not thought about before. David Sequino, CEO of OmniTrust (formerly ISS), talks about the need to secure digital certificates on life critical systems like cars and planes and the challenges in doing so.

  • #81
    February 3 · 38 min

    EP 80: The Dangers of White Label Devices

    Many devices on modern networks aren’t what their labels claim. This episode, Rob King, Director of Applied Security Research at runZero, explores white-labeled surveillance and IoT hardware, why some vendors are banned by governments, and how hidden risks can spread across enterprises. Discovery, device fingerprinting, and protocol analysis reveal what’s really connected—and why knowing your true inventory is now essential for security, compliance, and trust.

  • #80
    January 22 · 38 min

    EP 79: Ignore OT Security At Your Own Peril

    The growing importance of OT security, highlighting overlooked risks in critical infrastructure, legacy systems, and supply chains. Through real-world examples, Eric Durr, Chief Product Officer at Tenable, shows why OT security differs from IT, emphasizing visibility, resilience, and risk prioritization to protect safety, operations, and business continuity.

  • #79
    January 7 · 23 min

    EP 78: In Defense of Autonomous Vehicles

    At Black Hat USA 2025, Dan Berte, IoT Director at Bitdefender, discusses the successes and failures of ride-sharing autonomous vehicles in San Francisco, and how these lessons might help design better IoT integrations of cities and AVs in the future.

  • #78
    Dec 9, 2025 · 27 min

    EP 77: Building a Cyber Physical System Device Library

    Do you really know what’s on your network? A lot of OT devices are white labeled, meaning they have a brand name but under the hood they’re made by someone else. Sean Tufts, Field CTO for Claroty, explains how his team is using AI to sift through all the available data and build a cyber physical library that starts to add specificity to remediation operations, and improve cyber physical security overall

  • #77
    Nov 26, 2025 · 36 min

    EP 76: Why Security Certs for New Medical Devices Might Just Work

    Diversity in healthcare devices complicates segmentation, security controls, and zero-trust approaches. New certifications aim to help. Bob Lyle, CRO of Medcrypt, identifies how layered defenses, rigorous cybersecurity requirements for new devices, continuous monitoring, and dark-web credential surveillance can reduce risk.

  • #76
    Nov 11, 2025 · 24 min

    EP 75: IoT-based Living Off The Land Attacks and Air-Gapping Solar Systems

    At Black Hat USA 2025, Dan Berte, IoT Director at Bitdefender, revisits his talk last year about hacking solar panels in light of the blackout in Spain and Portugal. While the Iberian Peninsula blackout wasn’t an attack, it shows how sensitive these systems are when mixing old and new technologies, and how living off the land attacks might someday take advantage of that.

  • #75
    Oct 28, 2025 · 28 min

    EP 74: Turning Surveillance Cameras on their Axis

    At Black Hat USA 2025, Noam Moshe from Claroty’s Team 82 revealed several vulnerabilities in Axis Communications’ IP camera systems, including a deserialization flaw that could let attackers run remote code. The team worked with Axis to patch the issues. Moshe says that this case highlights the broader security risks still common in the billions of common IoT devices in the world today.

  • #74
    Oct 14, 2025 · 37 min

    EP 73: BADBOX 2.0: Blurring the line between bots and human for cybercrime

    Ad fraud driven by both humans and AI agents require new signals beyond traditional bot-vs-human checks. Gavin Reid and Lindsay Kaye from HUMAN Security discuss how monetization includes ad and click fraud (peach pit), selling residential proxy access, and operating botnets for hire and preventing harm requires dismantling criminal infrastructure and collaboration across industry, since many infected devices cannot be practically cleansed by end users.

  • #73
    Sep 30, 2025 · 27 min

    EP 72: Does a CISSP Certification Make Sense For OT?

    Certification exams increasingly reflect the IT OT convergence, acknowledging that many protections apply across both domains requiring holistic security approaches rather than siloed solutions. John France, CISO at ISC2, explains that as threats grow more complex, certifications, continuous learning, and diverse skills are essential to building a resilient global workforce.

Showing 1–20 of 20 episodes