Artwork for The 443 - Security Simplified
News

The 443 - Security Simplified

Secplicity

Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cybersecurity headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into easily understood and actionable insights.

  • 386 episodes
  • Updated Yesterday

Episodes386

  • March 9 · 39 min

    Hackerbot-Claw Crosses the Line - The 443 Podcast - Episode 361

    This week on the podcast, we chat about an OpenClaw bot that moved beyond vulnerability research and into malicious activity. Before that, we cover an AI-discovered vulnerability in the pac4j-jwt authentication library before ending with a discussion on an upcoming California law designed to help make age verification in the digital age easier, but with massive consequences.

  • March 2 · 36 min

    Cisco's SD-WAN 0-Day - The 443 Podcast - Episode 360

    This week on the podcast, we discuss the recently disclosed and patched 0-Day vulnerability in Cisco's Catalyst SD-WAN Controller which has been under active exploit for 3 years. After that, we cover the latest open source supply chain attack involving a self-propagating worm targeting AI tools. We end with a discussion about another social engineering campaign targeting job hunters in the software development world.

  • February 23 · 50 min

    WatchGuard's Internet Security Report 2025 H2 - The 443 Podcast - Episode 359

    This week on the podcast, we cover the WatchGuard Threat Lab's Internet Security Report for the second half of 2025. In this episode, we cover the latest trends for malware at both the network perimeter and endpoint, network attacks, and the top malicious domains from the period before ending with some tips everyone can use to defend their networks.

  • February 17 · 40 min

    OpenClaw as a Security Threat

    This week on the podcast, we discuss OpenClaw, the open source chatbot that has exploded in popularity since launching late last year, and some of the risk it introduces to organizations. Before that, we chat about Ring's Super Bowl advertisement that caused a stir before ending with a Google Threat Intelligence Group report on advanced threat actor AI usage.

  • February 9 · 31 min

    Moltbook Data Exposure

    This week on the podcast, we cover a recent supply chain compromise involving the popular text editor Notepad++. After that, we discuss a recent vulnerability report in the Moltbook AI social network before ending with a deep-dive review of a recent remote code execution vulnerability in the N8N automation platform.

  • February 3 · 31 min

    ChatGPT Oopsies Series of Information

    This week on the podcast, we cover a Politico report detailing a security lapse at CISA in the United States involving sensitive data and a public version of ChatGPT. Following that, we dive into a couple of vulnerabilities recently resolved in the SolarWinds Web Help Desk application. Finally, we end with some closure on a story about two Coalfire penetration testers who were arrested several years ago for completing a penetration test in Iowa.

  • January 20 · 38 min

    Uncovering A Mass VPN Phishing Campaign - The 443 Podcast - Episode 355

    This week on the podcast, we cover some first-hand research from the WatchGuard Threat Lab on a phishing campaign targeting users of nearly every major VPN vendor. After that, we discuss two recently resolved vulnerabilities in the Fortinet FortiSIEM application, then end with research from Varonis on a new attack flow against Copilot called RePrompt.

  • January 12 · 41 min

    React2Shell - The 443 Podcast - Episode 352

    This week on the podcast, we discuss the recently disclosed React2Shell vulnerability affecting a wide array of web applications. Before that, we review a new phishing campaign that uses a newly coined ConsentFix technique before discussing a security misstep from Home Depot.

  • January 12 · 33 min

    The Botnet that Topped Cloudlfare's Domain Charts - The 443 Podcast - Episode 354

    This week on the podcast, we cover the Kimwolf botnet, a collection of compromised IOT devices that at one point grew so large that it's command and control domain beat out Google.com as the most popular domain on the internet. After that, we discuss yet another devious take on ClickFix style phishing before ending with coverage from Cisco TALOS on another threat actor targeting edge networking equipment.

  • Dec 22, 2025 · 41 min

    2025 Ends With a Bang - The 443 Podcast - Episode 353

    This week on the podcast, we cover a wave of attacks against network edge equipment and internet-exposed systems including an update on the recently patched Firebox 0-Day. After that, we cover two stories on browser extensions siphoning off data and making unwanted modifications to victim’s web browsing activity.

  • Dec 8, 2025 · 43 min

    WatchGuard's 2026 Cybersecurity Predictions - The 443 Podcast Episode 351

    This week on the podcast, we go through all six of our cybersecurity predictions for 2026. For each prediction, we'll discuss the trends behind them, why we think they'll hit next year, and some takeaways for people and organizations on how to react to them in the coming year.

  • Nov 24, 2025 · 1 hr 23 min

    OWASP Top 10 2025 Edition - The 443 Podcast - Episode 350

    This week on the podcast, we cover OWASP’s update to the top 10 web application security weaknesses and its changes from the 2021 list. We also cover a recently uncovered adversary-in-the-middle campaign that’s pushing malicious software updates to targeted systems. We conclude with our opinions on Microsoft’s latest AI features, which are coming to Windows.

  • Nov 18, 2025 · 43 min

    2025 Security Predictions Recap - 443 Podcast - Episode 349

    This week on the podcast, we review our 2025 security predictions and grade ourselves on our accuracy. We recap all 6 predictions for 2025 from multi-modal AI being used to create entire attack chains to the CISO role becoming the least desirable role in business, and follow up on this year's news to see if they hit or not.

  • Oct 30, 2025 · 38 min

    October Ransomware Update - The 443 Podcast - Episode 348

    This week on the podcast, we have our resident ransomware expert, Ryan Estes, on to give an update on the latest in the ransomware ecosystem. We cover a few recent changes to operators, extortion techniques, and business impact from ransomware attacks in recent months.

  • Oct 13, 2025 · 41 min

    What's Going On at Salesforce? - The 443 Podcast - Episode 347

    This week on the podcast, we discuss the wave of extortion attacks targeting companies that use Salesforce. After that, we discuss Discord's breach involving their customer support application. Finally, we dive deep into the recent Oracle E-Business Suite zero day vulnerability and how attackers chained together multiple low-severity findings into a critical issue.

  • Oct 6, 2025 · 53 min

    An AI/ML Deep Dive with Luke Wolcott - The 443 Podcast - Episode 346

    This week on the podcast, we bring on WatchGuard's head of MDR data science Luke Wolcott to discuss the evolution of machine learning and artificial intelligence in cybersecurity. We dive into the differences in common (and uncommon) machine learning models, the pros and cons of supervised vs unsupervised learning, and why some of the coolest things happening in AI aren't the ones you hear about in the news.

  • Sep 29, 2025 · 30 min

    How GitHub Plans to Fix the Supply Chain - The 443 Podcast - Episode 345

    This week on the podcast, we discuss Cisco's recent zero-day vulnerabilities before covering a Microsoft Threat Intelligence post on a phishing campaign that abuses SVG files. After that, we review GitHub's proposed changes for securing the open source software supply chain.

  • Sep 22, 2025 · 26 min

    One Token to Rule Them All - The 443 Podcast - Episode 344

    This week on the podcast, we cover a vulnerability in Entra ID that could have allowed attackers to gain Global Admin access to any and all Entra ID tenants. After that, we discuss the Shai Hulud NPM worm that ran rampant over the last week, infecting hundreds of packages. Finally, we end with a quick reminder to WatchGuard Firebox customers to update their devices to the latest firmware to resolve CVE-2025-9242z

  • Sep 15, 2025 · 40 min

    Should Microsoft Be More Accountable for Security?

    This week on the podcast, we cover a massive software supply chain compromise involving widely-used NPM packages. After that we discuss an increase in social engineering attacks called ClickFix. Finally, we end with a discussion of Senator Wyden's recent letter to the FTC demanding Microsoft being held accountable for "gross cybersecurity negligence" and whether his claims have any merit.

  • Sep 8, 2025 · 43 min

    Does Security Training Work?

    This week on the podcast, we discuss a recently published research study from UC San Diego on the effectiveness on security awareness training on phishing prevention. After that, we discuss a security researcher's work on identifying vulnerabilities in four separate employee webapps at Intel. Finally, we end with our analysis of a Ponemon Institute research report called The State of File Security.