Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

HuggingFace's List of Demands - The 443 Podcast - Episode 381

This week on the podcast, we review HuggingFace's technical write up of their recent run in with a rogue OpenAI model, as well as their CEO's demands from OpenAI in response. We then cover an interesting research whitepaper that describes a side channel attack that could let AI transcribe typed text by an audio recording alone. We end with a threat intelligence report about DNS Poisoning attacks against hotel Wi-Fi systems.

Future-Proof Your Network with Zero Trust

A stolen password should not open the front door to your entire network. Traditional VPNs were built for a different era. Once a user gets in, too much of the network often becomes reachable. That broad, implicit trust gives ransomware exactly what it needs: an entry point, a path to move, and room to spread.

OpenAI's Models Go Rogue - The 443 Podcast - Episode 380

This week on the podcast, we cover the crazy saga that unfolded between the popular open-source AI platform Hugging Face and the frontier AI lab OpenAI. After that, we discuss a recent WordPress remote code execution vulnerability WP2Shell and the research process that Searchlight Cyber followed to uncover it sing artificial intelligence. Finally, we end with a quick analysis of Palo Alto Global Protec's authentication bypass vulnerability CVE-2026-0257.

WatchGuard's Cyber Hygiene Report - The 443 Podcast - Episode 379

This week on the podcast we cover the key takeaways from the just-released Cyber Hygiene Report from WatchGuard. After that, we discuss a recent alert from CISA and other international security agencies on state-sponsored attacks against network equipment. We end with an interesting research post on exfiltrating data from Claude's memory.

The 30-Minute Cloud Risk Assessment Every MSP Should Be Offering

Every time a client gets breached through a cloud app, it's the MSP who gets the call. Compromised Microsoft 365 accounts, unauthorized AI tools, and misconfigured sharing settings. Attackers aren't breaking in anymore. They're logging in through gaps that your endpoint, firewall, and MDR tools were never designed to see.

Lessons from a CISA Security Incident - The 443 Podcast - Episode 378

This week on the podcast, we review an after action report from CISA on a security incident they responded to back in May. After that, we cover a vulnerability in Amazon's Q Extension for VSCode before covering a research post from Microsoft on Giga Wiper.

The End of the VPN: The Rise of Identity-Based Secure Access

Hundreds of MSPs joined our last webinar to discuss the growing security and operational challenges of remote-user VPNs. Since then, the headlines have only reinforced the problem. Fortinet. Ivanti. Palo Alto Networks. SonicWall. Different vendors, same challenge: critical vulnerabilities, credential theft, and ransomware attacks continue to target remote access infrastructure, forcing organizations into a cycle of emergency patching, user disruption, and increased risk.