Spring til indhold
PodcastsNyhederAutonomous IT

Autonomous IT

Automox
Autonomous IT
Seneste episode

226 episoder

  • Autonomous IT

    Patch [FIX] Tuesday – [Race Conditions, Registry Hives, and Cloud CVEs], Ep. 35

    11.08.2026 | 22 min.
    August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only actively exploited vulnerability of the month, CVE-2026-68820, a use-after-free in the Windows AFD driver that trades a race condition for SYSTEM privileges. Serena breaks down CVE-2026-62832, a User Profile Service privilege escalation that lets an attacker load another user's registry hive with no user interaction required.
    Then there's the perfect 10.0 in Microsoft Teams that nobody needs to patch. Jason explains how cloud CVEs ended up in Patch Tuesday releases, why a third of this month's critical count requires zero customer action, and why the industry needs a separate disclosure mechanism before monthly CVE volume becomes pure noise. The crew also covers an ugly macOS screen sharing vulnerability that allowed authentication without credentials, the Linux kernel community's shift to issuing CVEs at scale, fresh takes from Black Hat and DEF CON on AI-driven vulnerability discovery, and why frontier models are forcing patching decisions to happen by policy instead of one CVE at a time.
    Patch your stuff. See you next month.
  • Autonomous IT

    Secure IT – PKI, Certificates, and What Breaks When Trust Fails, E22

    22.07.2026 | 17 min.
    Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.
    In this episode of Secure IT, host Jason Kikta is joined by Mark Cooper, CEO and founder of PKI Solutions, to unpack why PKI is so critical to identity, authentication, and trust, and what happens when it fails.
    They explore how certificates enable passwordless authentication, secure TLS connections, IoT devices, endpoints, and enterprise systems, while also examining why misconfigured or poorly monitored PKI environments often become an attacker's fastest path to privilege escalation. From certificate expirations and operational outages to real-world breach scenarios and pen test failures, this conversation maps the full PKI risk spectrum.
    Jason and Mark also challenge a common assumption in cybersecurity: that recovery equals resilience. Instead, they argue that true resilience means staying secure and operational, even during misconfiguration, failure, or attack.
    Whether you're new to PKI or responsible for running it, this episode will change how you think about identity infrastructure, resilience, and trust.
    Topics covered:

    - What PKI is and why most organizations already depend on it
    - Certificates, passwordless authentication, and digital identity
    - How PKI misconfigurations enable high-impact attacks
    - Why recovery is the weakest form of resilience
    - The hidden operational and security risks of foundational systems
  • Autonomous IT

    Patch [FIX] Tuesday – [The 570-CVE Month], Ep. 34

    14.07.2026 | 29 min.
    570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin.
     Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown:
    An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8
    A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the network
    An RDP bug you can shut down with a single setting, no patch required
    A SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner access
    A 9.9 Hyper-V escape that lets one compromised VM take the whole host
    A BitLocker bypass (6.1) worth knowing if you manage laptops in the field
    Plus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.
  • Autonomous IT

    Executive IT – What IT hiring actually looks like when AI does the work, E07

    01.07.2026 | 15 min.
    Eighteen months after the Hands-On IT podcast tackled the state of IT careers, Chelsea Rickey, SVP of Human Resources at Automox, comes back to the conversation to assess what held up, what changed, and what nobody quite predicted.
    AI is no longer a future-state problem. It's already reshaping what roles look like, how productivity gets measured, and how organizations coordinate. Individual learning agility still matters, but Chelsea argues the harder question now is whether organizations can adapt as fast as the people inside them.
  • Autonomous IT

    Product Talk – CISA's BOD 26-04 Directive Explained, E26

    11.06.2026 | 27 min.
    CISA's BOD 26-04 replaces severity-based patching with an exploit-evidence model and remediation clocks as short as three days, fleet-wide, no exceptions. Peter Pflaster and Jason Kikta unpack the four urgency signals, the 16-row decision tree, and the shift from "justify the patch" to "justify why you can't." They also cover what it means for contractors, cyber insurance, and the future of Patch Tuesday. 
    If you own patching or vulnerability management, start here.
Flere Nyheder podcasts
Om Autonomous IT
Go from monotonous to autonomous IT operations with this series. Hosts from Automox, the IT automation platform for modern organizations, will cover the latest IT trends; Patch Tuesday remediations; ways to save time with Worklets (pre-built scripts); reduce risk; slash complexity; and automate OS, third-party, and configuration updates on all your Windows, macOS, and Linux endpoints. Automate confidence everywhere with Automox.
Podcast-websted

Lyt til Autonomous IT, Tiden og mange andre podcasts fra hele verden med radio.dk-appen

Hent den gratis radio.dk-app

  • Bogmærke stationer og podcasts
  • Stream via Wi-Fi eller Bluetooth
  • Understøtter Carplay & Android Auto
  • Mange andre app-funktioner