TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Autonomous IT

    Go from monotonous to autonomous IT operations with this series. Hosts from Automox, the IT automation platform for modern organizations, will cover the latest IT trends; Patch Tuesday remediations; ways to save time with Worklets (pre-built scripts); reduce risk; slash complexity; and automate OS, third-party, and configuration updates on all your Windows, macOS, and Linux endpoints. Automate confidence everywhere with Automox.

    Advertise

    Copyright: © 2024 Automox

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Patch [FIX] Tuesday – [973 CVEs and a New Patch Tuesday Record], Ep. 36 Sep 08, 2026
    Show notes

    Labor Day is over and Microsoft made up for the day off. Landon Miles and Serena DiPenti sort September's Patch Tuesday down to the six bugs that matter, starting with the only one Microsoft confirms is already exploited: a Windows Update Stack privilege escalation that hands attackers SYSTEM, published with no score and no affected-product list.


    They also cover:


    - An unauthenticated remote code execution in Windows DNS Server, rated more likely to be exploited, and why it's a domain controller problem for most shops

    - A Remote Desktop Services bug that scores 9.8 but carries an Important label, and why the label shouldn't set your patch order

    - SQL Copilot in Management Studio ignoring its own read-only restrictions, and where the real guardrail belongs

    - An Outlook flaw that fires from the Reading Pane with no click, and why a Microsoft 365 subscription doesn't mean the fix is already installed

    - An Exchange Server bug that lets one low-privilege mailbox impersonate every other user


    Plus macOS Tahoe 26.6.2 and what's behind the month's record CVE count. Know what you run, patch the exploited one first, then work down your list.


    Autonomous IT, Live! Turn to Face the StrAInge, Patch Speed vs AI Attacks, E08 Aug 25, 2026
    Show notes

    In April, Jason Kikta and Dmitri Alperovitch landed on a structural conclusion: AI had collapsed patch-to-exploit time to under an hour, 1-10-60 was no longer fast enough, and the only answer was prevention. Patch by default, limit blast radius, stop playing a detection-and-response game built for human-speed attacks.

    This episode picks up where that conversation ended. What's changed since April, and can detection-first models survive the pace of change at all? Kat Traxler is here to stress test that question from the inside.

    Guests: Jason Kikta, Automox CTO, Dmitri Alperovitch, Co-Founder and Chairman, Silverado Policy Accelerator
    Kat Traxler, Principal Security Researcher, Vectra AI

    Host: Landon Miles


    Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35 Aug 11, 2026
    Show notes

    August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only actively exploited vulnerability of the month, CVE-2026-68820, a use-after-free in the Windows AFD driver that trades a race condition for SYSTEM privileges. Serena breaks down CVE-2026-62832, a User Profile Service privilege escalation that lets an attacker load another user's registry hive with no user interaction required.

    Then there's the perfect 10.0 in Microsoft Teams that nobody needs to patch. Jason explains how cloud CVEs ended up in Patch Tuesday releases, why a third of this month's critical count requires zero customer action, and why the industry needs a separate disclosure mechanism before monthly CVE volume becomes pure noise. The crew also covers an ugly macOS screen sharing vulnerability that allowed authentication without credentials, the Linux kernel community's shift to issuing CVEs at scale, fresh takes from Black Hat and DEF CON on AI-driven vulnerability discovery, and why frontier models are forcing patching decisions to happen by policy instead of one CVE at a time.

    Patch your stuff. See you next month.


    Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22 Jul 22, 2026
    Show notes

    Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.

    In this episode of Secure IT, host Jason Kikta is joined by Mark Cooper, CEO and founder of PKI Solutions, to unpack why PKI is so critical to identity, authentication, and trust, and what happens when it fails.

    They explore how certificates enable passwordless authentication, secure TLS connections, IoT devices, endpoints, and enterprise systems, while also examining why misconfigured or poorly monitored PKI environments often become an attacker's fastest path to privilege escalation. From certificate expirations and operational outages to real-world breach scenarios and pen test failures, this conversation maps the full PKI risk spectrum.

    Jason and Mark also challenge a common assumption in cybersecurity: that recovery equals resilience. Instead, they argue that true resilience means staying secure and operational, even during misconfiguration, failure, or attack.

    Whether you're new to PKI or responsible for running it, this episode will change how you think about identity infrastructure, resilience, and trust.

    Topics covered:

    - What PKI is and why most organizations already depend on it
    - Certificates, passwordless authentication, and digital identity
    - How PKI misconfigurations enable high-impact attacks
    - Why recovery is the weakest form of resilience
    - The hidden operational and security risks of foundational systems


    Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34 Jul 14, 2026
    Show notes

    570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin.

    Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown:

    • An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8
    • A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the network
    • An RDP bug you can shut down with a single setting, no patch required
    • A SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner access
    • A 9.9 Hyper-V escape that lets one compromised VM take the whole host
    • A BitLocker bypass (6.1) worth knowing if you manage laptops in the field

    Plus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.


    Executive IT – What IT hiring actually looks like when AI does the work, E07 Jul 01, 2026
    Show notes

    Eighteen months after the Hands-On IT podcast tackled the state of IT careers, Chelsea Rickey, SVP of Human Resources at Automox, comes back to the conversation to assess what held up, what changed, and what nobody quite predicted.

    AI is no longer a future-state problem. It's already reshaping what roles look like, how productivity gets measured, and how organizations coordinate. Individual learning agility still matters, but Chelsea argues the harder question now is whether organizations can adapt as fast as the people inside them.


    Product Talk – CISA's BOD 26-04 Directive Explained, E26 Jun 11, 2026
    Show notes

    CISA's BOD 26-04 replaces severity-based patching with an exploit-evidence model and remediation clocks as short as three days, fleet-wide, no exceptions. Peter Pflaster and Jason Kikta unpack the four urgency signals, the 16-row decision tree, and the shift from "justify the patch" to "justify why you can't." They also cover what it means for contractors, cyber insurance, and the future of Patch Tuesday.

    If you own patching or vulnerability management, start here.



    Patch [FIX] Tuesday – [Nothing Weaponized, Everything Exposed], E33 Jun 09, 2026
    Show notes

    June 2026 has no headliner. Instead of one critical bug, the release spreads thin across the kernel, the network stack, a code editor, an AI assistant, a bootloader, and a nine-year-old Linux root bug. It's a breadth problem, not a severity one, and it changes how you triage.

    Jason Kikta and Landon Miles break down the whole release, then step off the patch list for the breaches that never got a CVE: GitHub's internal repos reached through a poisoned VS Code extension, a TanStack compromise carrying valid SLSA provenance, and a Red Hat npm namespace compromise that fired the moment anyone ran npm install.


    Patch [FIX] Tuesday – [AI Hits the Hat Trick], Ep. 32 May 12, 2026
    Show notes

    The May 2026 Microsoft Patch Tuesday release looks quiet on the surface – no actively exploited zero-days, no public disclosures at release, and a CVE count below the four-month average. Don't let that fool you.

    In this episode, Jason Kikta and Landon Miles break down everything that happened between April and May patch cycles, including Apple's macOS Tahoe 26.5 release with 79 CVEs, the Dirty Frag Linux kernel privilege escalation chain, and two pre-authenticated network remote code execution vulnerabilities in Windows core services that belong at the top of your patch list.

    They also dig into one of the month's most significant trends: AI-assisted vulnerability research showing up by name in Microsoft, Apple, and Linux acknowledgments in the same patch cycle – including Anthropic researchers credited on a critical Windows graphics component RCE. Ten AI-attributed vulnerability discoveries shipped fixes across all three major operating systems this month.

    What's covered:

    • CVE-2026-41089: Windows NetLogon RCE (CVSS 9.8) and CVE-2026-41096: Windows DNS Client RCE (CVSS 9.8)
    • CVE-2026-40402: Hyper-V guest-to-host escalation (CVSS 9.3)
    • macOS Tahoe 26.5: Wi-Fi kernel RCE, nine kernel CVEs, 20 WebKit vulnerabilities
    • Dirty Frag Linux privilege escalation chain and the Copy Fail connection
    • AI-credited discoveries from Anthropic, calif.io, Theori, and NIST's Center for AI Standards and Innovation


    - Patch Tuesday Blog
    - DirtyFrag Blog
    - What "Mythos Ready" Means


    Patch [FIX] Tuesday – [Emergency Episode: DirtyFrag Exploit Before Patch], Ep. 31 May 08, 2026
    Show notes

    Breaking from the normal Patch Tuesday cadence for an emergency drop. On May 7, security researcher Hyunwoo Kim published a working proof-of-concept for DirtyFrag - a Linux kernel local privilege escalation chain that gets unprivileged users to root on every major distribution. The embargo was broken by a third party before distribution backports were ready, so the exploit is public and the patch is not.

    CTO Jason Kikta and Landon Miles walk through what makes DirtyFrag different from the Copy Fail mitigation many teams already deployed (spoiler: the CopyFail mitigation does NOT cover this), why AWS is calling it a class rather than a single CVE, and the five kernel modules you need to block right now: esp4, esp6, ipcomp4, ipcomp6, and rxrpc.

    In this episode:

    • Why the embargo break matters and what changed on May 7
    • How DirtyFrag chains CVE-2026-43284 and CVE-2026-43500 to defeat both Ubuntu's namespace policy and the absence of rxrpc.ko on other distros
    • Why this is the third generation of a bug class (DirtyPipe → Copy Fail → DirtyFrag) and what that means for what comes next
    • The Automox Worklet that mitigates both arms across your Linux fleet, and what it deliberately does not do
    • Tested affected platforms: Ubuntu 24.04, RHEL 10.1, AlmaLinux 10, CentOS Stream 10, openSUSE Tumbleweed, Fedora 44

    Back to the regular Patch Tuesday schedule next week.

    Links:

    • Full blog post and mitigation guidance
    • Automox Worklet (in-console for customers):
    • Worklet source on GitHub
    • Hyunwoo Kim's PoC and write-up
    • AWS Security Bulletin 2026-027
    • CVE-2026-31431 (Copy Fail, parent issue)

    1 2 3 23 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights