
Below the Surface (Audio) - The Supply Chain Security Podcast
by Eclypsium
Is this your podcast?Insights from recent episode analysis
Audience Interest
Podcast Focus
Publishing Consistency
Platform Reach
Insights are generated by CastFox AI using publicly available data, episode content, and proprietary models.
Most discussed topics
Brands & references
Est. Listeners
Insufficient chart data. Estimates will improve as the show charts.
- Per-Episode Audience
Est. listeners per new episode within ~30 days
N/A🎙 ~2x weekly·71 episodes·Last published 2w ago - Monthly Reach
Unique listeners across all episodes (30 days)
N/A - Active Followers
Loyal subscribers who consistently listen
N/A
Market Insights
Platform Distribution
Reach across major podcast platforms, updated hourly
Total Followers
—
Total Plays
—
Total Reviews
—
* Data sourced directly from platform APIs and aggregated hourly across all major podcast directories.
On the show
From 17 epsHosts
Recent guests
Recent episodes
Exploring BMC Vulnerabilities - BTS #80
Aug 13, 2026
Unknown duration
InfraTrust - Understanding Infrastructure Vulnerabilities & Risk - BTS #79
Aug 7, 2026
Unknown duration
Patching: The Race Against Time - BTS #78
Jul 16, 2026
56m 12s
FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet Devices - BTS #77
Jun 30, 2026
54m 49s
Binwalk, Brickstorm, AI Model Madness - BTS #76
Jun 16, 2026
1h 00m 41s
Social Links & Contact
Official channels & resources
Official Website
Login
RSS Feed
Login
| Date | Episode | Topics | Guests | Brands | Places | Keywords | Sponsor | Length | |
|---|---|---|---|---|---|---|---|---|---|
| 8/13/26 | Exploring BMC Vulnerabilities - BTS #80 | Summary In this episode, the hosts discuss various cybersecurity topics, including the lack of media coverage from the Black Hat conference, the implications of AI in cybersecurity, and the vulnerabilities associated with Baseboard Management Controllers (BMCs). They explore the challenges of patch management, the role of embedded Linux in security vulnerabilities, and the emerging trends in threat actor behavior. The conversation emphasizes the need for better awareness and action regarding BMC vulnerabilities and the importance of understanding the risks associated with AI in security. In this conversation, the speakers delve into the complexities of operational risks associated with AI models, particularly in the context of patch management and firmware security. They discuss the challenges of relying on AI for code reviews and the implications of backdoors found in firmware. The conversation also highlights the critical importance of true randomness in cryptographic applications and the ongoing risks posed by speculative execution attacks. Chapters 00:00 Introduction and Technical Setup 03:01 Black Hat Conference Coverage and Media Silence 06:00 AI and Cybersecurity: Responsibility and Ethics 08:51 BMC Vulnerabilities: Research and Findings 11:57 Scanning Techniques and Tools for BMCs 15:02 Cisco Vulnerabilities and Patch Management Challenges 17:54 The Role of AI in Vulnerability Discovery and Management 21:13 Emerging Threats and Trends in Cybersecurity 24:00 Conclusion and Future Considerations 34:03 Understanding Operational Risks in AI Models 37:10 The Challenges of Patch Management and Configuration 41:26 The Dangers of AI in Code Review 43:00 Backdoors in Firmware: A Growing Concern 49:13 The Importance of True Randomness in Cryptography 58:08 The Implications of Speculative Execution Attacks | — | ||||||
| 8/7/26 | InfraTrust - Understanding Infrastructure Vulnerabilities & Risk - BTS #79 | Check out our free and no-registration-required site for understanding and tracking infrastructure vulnerabilities and advisories: https://infra-trust.org In this episode, the hosts discuss the challenges of collecting and aggregating vulnerability data, the introduction of Infratrust and Infratrust Pulse, and the importance of actionable data for cybersecurity teams. They explore the differences between vendor advisories and CVEs, the role of Eclipsium in data aggregation, and the ongoing challenges in vulnerability management and patching. The conversation highlights the need for a centralized source of truth for infrastructure vulnerabilities and the evolving landscape of cybersecurity threats. In this conversation, the speakers delve into the complexities of vulnerability management, particularly in the context of AI's rapid evolution in vulnerability discovery. They discuss the biases affecting vulnerability prioritization, the implications of AI on both offensive and defensive capabilities, and the critical risks associated with exposing Baseboard Management Controllers (BMCs) to the internet. The conversation emphasizes the need for better security practices and awareness in the face of evolving threats. Chapters 00:00 Technical Challenges in Data Collection 02:58 Introduction to Infratrust and Infratrust Pulse 05:57 The Evolution of Infrastructure Pulse 09:02 Understanding Vendor Advisories vs CVEs 11:49 The Importance of Actionable Data 14:46 Navigating Vendor Advisory Inconsistencies 17:51 The Role of Eclipsium in Data Aggregation 20:46 Patching Challenges and Vulnerability Management 24:09 Interpreting Risk Scores and Vulnerability Impact 30:34 Understanding Vulnerability Management Challenges 32:43 The Impact of AI on Vulnerability Discovery 35:24 The Arms Race: Offensive vs Defensive Capabilities 38:41 The Dangers of Exposing BMCs to the Internet 41:31 BMC Vulnerabilities: A Deep Dive 49:29 Mitigating Risks: Best Practices for BMC Security | — | ||||||
| 7/16/26 | vulnerabilitiesnetwork security+5 | — | Eclypsium | — | vulnerabilitiespatching+5 | — | 56m 12s | ||
| 6/30/26 | FortiBleed campaigncredential harvesting+4 | — | FortiOSFortinet | — | FortiBleedFortinet+5 | — | 54m 49s | ||
| 6/16/26 | AI in cybersecurityoperational risks+5 | Chase SnyderVlad Babkin | BinwalkBrickstorm+2 | — | cybersecurityAI guardrails+5 | — | 1h 00m 41s | ||
| 6/3/26 | cybersecurity trendssecure boot certificate expirations+4 | — | Secure Boot CertificatesEclypsium+7 | Southeast Asia | cybersecuritysecure boot+5 | — | 55m 48s | ||
| 5/19/26 | vulnerabilitiessupply chain security+4 | — | BitLockerCVSS+5 | — | vulnerabilitiesYellowKey+5 | — | 54m 52s | ||
| 5/7/26 | firmware securitysupply chain vulnerabilities+3 | Brian Richardson | Cisco ASAFTD+3 | — | firmware risksmalware+3 | — | 55m 01s | ||
| 4/17/26 | cybersecurityAI-driven vulnerability discovery+4 | — | Samsung TVEclypsium+1 | — | AIvulnerability discovery+4 | — | 58m 59s | ||
| 4/7/26 | FCC regulationscybersecurity+4 | — | routersfirmware+5 | — | FCC regulationscybersecurity+5 | — | 1h 01m 42s | ||
Want analysis for the episodes below?Free for Pro Submit a request, we'll have your selected episodes analyzed within an hour. Free, at no cost to you, for Pro users. | |||||||||
| 3/25/26 | KVM vulnerabilitiessecurity best practices+4 | PaulRey | KVMsGLINet+3 | — | KVM securityfirmware analysis+5 | — | 1h 02m 56s | ||
| 3/5/26 | network edge vulnerabilitiescybersecurity strategies+5 | Vlad BabkinAdrian Sanabria | AvantiEclypsium | — | network edge devicescybersecurity+8 | — | 1h 04m 13s | ||
| 2/11/26 | cybersecurity threatscritical infrastructure+5 | — | PythonRussian+1 | Poland | cybersecurityRussian cyber attacks+5 | — | 1h 02m 01s | ||
| 1/27/26 | cybersecurityBIOS password cracking+5 | — | BIOSAMD+4 | — | cybersecurityBIOS password cracking+6 | — | 1h 00m 29s | ||
| 1/15/26 | hardware supply chain securitytrust in silicon+5 | Larry PesciJoshua Marpet+1 | Black Hat Asia | — | hardware trustsupply chain security+5 | — | 56m 46s | ||
| 12/15/25 | AI in firmware analysisvulnerability discovery+4 | Matt Brown | Eclypsium | — | firmware analysisAI-driven approaches+6 | — | 1h 00m 35s | ||
| 11/24/25 | cybersecuritysupply chain breaches+3 | — | FortinetOWASP | — | Fortinetsupply chain+4 | — | 1h 08m 03s | ||
| 10/30/25 | cybersecurityF5 breach+5 | — | F5QNAP+6 | — | cyber attacksPolar Edge malware+8 | — | 1h 00m 06s | ||
| 10/21/25 | F5 breachvulnerability disclosure+4 | — | F5Linux+1 | — | F5 breachvulnerability disclosure+5 | — | 53m 20s | ||
| 10/8/25 | Red November, Cisco Vulnerabilities, and Supply Chain Security - BTS #61 | In this episode of Below the Surface, the hosts discuss various cybersecurity topics, including the Red November campaign targeting network edge devices, the implications of the Cisco SNMP vulnerability, and the recent vulnerabilities associated with Cisco ASA devices. They also delve into the hybrid Petya ransomware and its connection to supply chain security, emphasizing the need for better visibility and security measures in network devices. Chapters: 00:00 Introduction and Overview of Cybersecurity Trends 02:09 Red November Campaign: Targeting Network Edge Devices 11:06 The Shift in Attack Vectors: From Windows to Network Edge 14:59 Cisco SNMP Vulnerability: A Legacy Issue 21:21 The Implications of Targeting Network Edge Devices 28:20 Addressing Legacy Issues in Cybersecurity 29:41 Emerging Threats in Cybersecurity 32:19 The Age of Vulnerabilities 33:40 The Importance of Asset Inventory 35:38 Challenges in Device Security 37:22 Visibility and Detection Limitations 39:28 Vendor Responses to Vulnerabilities 41:24 Supply Chain Security Crisis 46:59 Understanding Hybrid Petya 52:11 The Evolution of Attack Techniques | — | ||||||
| 9/22/25 | HybridPetya and UEFI Threats - BTS #60 | In this episode of Below the Surface, the hosts discuss various cybersecurity topics, including the evolution of malware with a focus on Hybrid Petya, the implications of UEFI vulnerabilities, and the security risks associated with Windows 10's end of life. They also explore the vulnerabilities of Cisco ASA devices, the rise of supply chain attacks exemplified by NPM worms, and the persistent threat of Row Hammer attacks on DDR5 technology. The conversation highlights the significance of visibility in cybersecurity and the necessity for enhanced security practices to counter evolving threats. Chapters 00:00 Introduction and Podcast Overview 02:55 Hybrid Petya: The New Threat Landscape 06:03 Understanding UEFI and Secure Boot Vulnerabilities 09:00 The Evolution of Ransomware Techniques 11:54 Windows 10 End of Life Concerns 14:56 The Future of Secure Boot and User Responsibility 22:50 The Shift in Consumer Trust Towards Microsoft 25:11 The Rise of Alternatives: Linux and SteamOS 28:41 Security Concerns with Windows 10 and 11 31:57 Exploiting End-of-Life Devices 36:39 The Challenge of Legacy Infrastructure 39:41 VPN Security: Risks and Solutions 45:40 The Dilemma of Compliance and Visibility 50:16 Supply Chain Vulnerabilities and NPM Attacks 55:54 The Rowhammer Attack and Hardware Security 01:03:40 The Need for Visibility and Signatures in Security | — | ||||||
| 9/10/25 | Exploit Marketplaces - BTS #59 | In this episode of Below the Surface, host Paul Asadoorian speaks with Evan Dornbush, CEO of Desired Effect, about the evolving landscape of exploit marketplaces and vulnerability research. They discuss the challenges researchers face in monetizing their findings, the ethical implications of selling exploits, and the importance of timely intelligence for defenders. The conversation also touches on the role of AI in vulnerability research, the dynamics between buyers and sellers in the marketplace, and the impact of end-of-life devices on cybersecurity. Overall, the episode provides valuable insights into the complexities of the exploit marketplace and the need for a more proactive approach to cybersecurity. Chapters 00:00 Introduction to Desired Effect and Evan Dornbush 02:35 The Evolution of Exploit Marketplaces 05:06 Monetizing Vulnerability Research 07:46 The Role of Disclosure in Exploit Sales 10:28 Understanding the Value of Exploits 13:14 Ethics and Motivations in Vulnerability Research 15:51 Validation of Vulnerabilities and Exploits 18:29 Buyer Vetting and Market Dynamics 21:31 Proactive Defense Strategies 24:32 Market Insights and Future Trends 27:43 The Marketplace for Exploits 31:08 The Role of Researchers and Vendors 34:51 The Asymmetry in Cybersecurity 38:03 Economic Incentives in Cybersecurity 40:25 The Complexity of Risk Management 43:57 The Future of Exploit Disclosure 47:23 The Role of AI in Cybersecurity 53:31 Closing Thoughts on Exploit Ethics | — | ||||||
| 9/4/25 | UEFI Vulnerabilities and Hardware Risks - BTS #58 | In this episode, the hosts discuss various cybersecurity topics, focusing on hardware vulnerabilities, UEFI attack vectors, and the implications of new regulations on device security. They explore the evolution of Mirai variants targeting IoT devices and the challenges of securing firmware. The conversation highlights the need for improved security measures and the complexities of managing vulnerabilities in a rapidly changing technological landscape. 00:00 Introduction and Technical Challenges 02:37 Exploring UEFI Settings and Hardware Vulnerabilities 10:14 The Risks of UEFI Control and Physical Damage 16:33 Static Tundra: Cyber Espionage and Exploits 22:23 Targeting Vulnerable Infrastructure in Cyber Attacks 26:27 Emerging Threats in IoT and Network Devices 31:55 The Evolution of Malware: A Deep Dive 34:30 The Challenge of Securing IoT Devices 35:13 Impact of EU Cyber Resilience Act 38:14 Vulnerability Management and Vendor Responsibilities 41:54 Living Outside the Operating System: New Attack Vectors | — | ||||||
| 8/15/25 | Interview with Brian Mullen from AMI - BTS #57 | In this episode of Below the Surface, host Paul Asadoorian is joined by Brian Mullen, head of SSDLC at AMI, to discuss the complexities of supply chain and firmware security. They explore the challenges of maintaining security in a complicated supply chain, the importance of proactive and reactive security measures, and the implications of end-of-life software. The conversation also touches on the gaming industry's push for secure boot, recent vulnerabilities discovered in firmware, and the role of BMCs in security. Brian shares insights into AMI's approach to vulnerability management and the future of firmware security, including the significance of Software Bill of Materials (SBOMs). Whitepaper: https://eclypsium.com/wp-content/uploads/OpenBMC-Security-in-Practice.pdf Chapters 00:00 Introduction and Technical Setup 01:46 The Challenges of Podcasting and Marketing 03:42 Understanding AMI and Its Role in Firmware Security 06:13 Supply Chain Complexity and Security Measures 08:49 Proactive vs Reactive Security in Firmware 11:17 The Importance of Stable Firmware in Security 13:54 Navigating Vulnerabilities in UEFI and OpenSSL 16:24 The Impact of Cherry-Picking Security Updates 19:11 Tracking Vulnerabilities Across the Supply Chain 21:50 Solutions for Data Center Firmware Management 24:21 Future Directions in Vulnerability Management 24:38 Navigating Vulnerability Management 28:30 End of Life and Support Challenges 31:55 Gaming Security and Anti-Cheat Mechanisms 35:38 The Complexity of Secure Boot Implementation 36:50 Recent Vulnerabilities and Security Research 39:44 Understanding BMC Security 43:34 Open Source and BMC Development 46:30 The Role of SBOMs in Security Compliance | — | ||||||
| 8/8/25 | BTS #56 - Vulnerabilities & Backdoors In IT Infrastructure | In this episode, the hosts discuss various cybersecurity topics, focusing on Nvidia vulnerabilities, the implications of backdoors in technology, and the importance of secure boot and certificate management. They also delve into SonicWall's security challenges and the ongoing debate of building versus buying security solutions, particularly in the context of AI infrastructure and cloud services. Articles and topics for this week: https://blog.trailofbits.com/2025/08/04/uncovering-memory-corruption-in-nvidia-triton-as-a-new-hire/ https://mjg59.dreamwidth.org/72892.html - Secure Boot and certificates https://www.tomshardware.com/pc-components/gpus/nvidia-defiant-over-backdoors-and-kill-switches-in-gpus-as-u-s-mulls-tracking-requirements-calls-them-permanent-flaws-that-are-a-gift-to-hackers - https://www.bleepingcomputer.com/news/security/sonicwall-urges-admins-to-disable-sslvpn-amid-rising-attacks/ - https://www.darkreading.com/endpoint-security/shade-bios-technique-beats-security - Researcher's previous paper on SMM and malware: https://arxiv.org/abs/2405.04355 He presented at Blackhat last year on Option ROMS: https://www.blackhat.com/us-24/briefings/schedule/index.html#youve-already-been-hacked-what-if-there-is-a-backdoor-in-your-uefi-orom-39579 - YouTube video: https://www.youtube.com/watch?v=_S6EymfaBqQ | — | ||||||
Showing 25 of 80
Pitch Fit is a Pro feature
See how bookable this show is for guests, which brands already advertise, the per-episode ad value, and the best-fit guest and sponsor profile. The numbers are blurred on the free plan.
How readily this show books outside guests like you.
How proven this show is for host-read sponsorships.
For Guests
ProFor Advertisers
ProUpgrade to Pro to unlock guest cadence, sponsor categories, fit scores, and per-episode ad value for this show.