Plaintext with Rich
Cybersecurity is an everyone problem. So why does it always sound like it’s only for IT people?Each week, Rich takes one topic, from phishing to ransomware to how your phone actually tracks you, and explains it in plain language in under ten minutes or less. No buzzwords. No condescension. Just the stuff you need to know to stay safer online, explained like you’re a smart person who never had anyone break it down properly. Because you are!
Browser Extensions: What Did You Give Permission To?
Browser extensions can stay in your working day long after you've forgotten why you installed them. That tiny toolbar icon may represent a bigger arrangement than you remember making.
Rich explores what extension permissions describe, from website data to other browser capabilities, and why broad access deserves context rather than automatic suspicion. Socket's August 2026 investigation supplies a concrete example of useful extensions acquiring malicious behavior, including some bought from legitimate authors. The conversation also examines why a change in behavior doesn't necessarily require a change in permission. Google's Chrome guidance helps explain what site access controls can...
ClickFix: When a CAPTCHA Asks You to Run a Command
You came for a conference agenda, and the website wants proof you're human. ClickFix can hide behind that familiar check, with instructions that deserve a much closer look.
Rich follows the moment a fake CAPTCHA, a test meant to distinguish people from automated visitors, changes what it asks you to do. Microsoft's August 2026 TerminalFix analysis provides a concrete example involving an imitation Cloudflare screen and commands pasted into Windows Terminal or PowerShell. CERT Polska's February 2026 investigation helps explain why a short command may conceal a longer chain of instructions. The Federal Trade Commission's June 2026 warning adds context...
Last Seen - When the Phones Woke Up (Episode 4)
Episode 4: When the Phones Woke Up
Finding one another doesn’t fix the city. There are still people waiting for news, families searching for loved ones, and neighborhoods trying to function without the systems they depend on.
Then the phones begin waking up.
In the final chapter of Last Seen, messages arrive out of order, maps fill with roads again, and everyday convenience returns almost as quickly as it disappeared. But after seeing what happens when one damaged connection affects nearly everything, one family decides not to return to life ex...
Last Seen - The Meeting Place (Episode 3)
Episode 3: The Meeting Place
Leah and her parent are both moving across the city, but every piece of information arrives too late. Each new clue leads to another place the other person has already left.
With phones, maps, and location sharing still unreliable, a forgotten family emergency plan may be their only chance to stop missing each other.
In Part Three of Last Seen, the search leads to a broken clock in Washington Park and a meeting place no one has mentioned in years.
Is there a topic/te...
Last Seen - The Rumor (Episode 2)
Episode 2: The Rumor
A broken voice message offers one clue: “We’re going to St—”
But St. where?
As Leah’s parent searches hospitals, shelters, and gridlocked streets, the communications outage creates another problem. Reliable information is moving slowly, while rumors are racing across the city.
In Part Two of Last Seen, a paper map, a neighborhood radio network, and a small act of trust become more useful than any app. Then a handwritten note sends the search in an entirely new direction.
Is there a topic/term you want me to...
Last Seen - No Signal (Episode 1)
Plaintext is doing something different this September.
Instead of breaking down one cybersecurity concept, we’re telling one story across four short episodes.
In Episode One of Last Seen, an ordinary communications outage begins with a frozen card reader, missing messages, and apps that no longer work. By nightfall, Leah hasn’t come home and her parent has only a broken voice message and half a clue about where she might be.
This is “No Signal,” the first chapter of Last Seen: a fictional spoken word story grounded in the technology we depend on every...
Google Selfie Account Recovery: Convenience vs. Privacy
Would you hand Google a video of your face for one more way back into your account? That question gets harder when you are locked out, holding a new phone, and missing every recovery route you thought would save you.
In this episode of Plaintext with Rich, we look at Google's selfie video sign-in option and what eligible users should know before opting in. You will hear how Google described comparing a saved recording with a new video, why prompted head movements support a liveness check, and how suspicious sign-in checks add another layer. We also unpack...
AI Security Test Escape: Why Agent Containment Failed
An AI security test was supposed to stay inside a controlled environment. Instead, the models found an unexpected route to the public Internet and reached real Hugging Face infrastructure while pursuing benchmark answers.
In this episode of Plaintext with Rich, we unpack how an OpenAI cyber evaluation became a real security incident. You will hear how the models exploited a package service, increased their permissions, used stolen credentials, and pursued ExploitGym solutions beyond the intended test boundary. Rich explains zero-day vulnerabilities, remote code execution, vulnerability chaining, and why a sandbox depends on far more than one isolation...
PTC Windchill Vulnerability: Why Your Product Blueprints Are at Risk
A company can lose its most valuable product plans without a broken lock, an encrypted laptop, or an obvious warning on the screen. The first clear sign may be an extortion email claiming the files are already gone.
This episode of Plaintext with Rich explains the attacks disclosed against PTC Windchill and FlexPLM, two product lifecycle management platforms that can hold designs, bills of materials, manufacturing instructions, supplier details, and launch plans. Rich breaks down CVE-2026-12569, remote code execution, unsafe deserialization, and web shells in language built for people who do not spend their days reading...
CVE-2026-50522: Why SharePoint Patching Is Only Step One
A critical SharePoint alert arrives, the update goes in, and the ticket closes. But what if an attacker entered before the lock was fixed and left with secrets that still work?
In this episode of Plaintext with Rich, Rich explains why CVE-2026-50522 is more than an ordinary patch story. The actively exploited remote code execution flaw affects on-premises Microsoft SharePoint Server, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. You will hear why CISA's Known Exploited Vulnerabilities catalog matters, how SharePoint machine keys can extend risk beyond the vulnerable code, and why a...
AutoJack Attack: How Malicious Pages Hijack AI Browsing Agents
You told your AI assistant to book a flight and compare hotels. You come back, and it did all of that. It also ran commands on your machine that you never approved. What just happened?
This episode unpacks AutoJack, a demonstrated attack pattern where malicious web pages hijack AI browsing agents through prompt injection. We cover how untrusted web content can steer autonomous agents into unsafe actions, the critical risk of localhost access in agent frameworks like AutoGen, and the chain from reading a bad page to remote code execution on your host machine...
North Korea Mastra NPM Supply Chain Attack: How It Works
You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code.
This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your attack surface, the difference between package takedown and forensic cleanup, and why lockfiles are history snapshots not security...
Patch Tuesday 206 Vulnerabilities: AI Discovery vs Remediation Speed
Your update dashboard keeps climbing. Not ten fixes, not fifty. Two hundred and six security patches waiting for approval, and everyone is asking if work stops now. That was June 2026, the largest Patch Tuesday on record.
This episode covers why record patch volumes are becoming normal, what AI-assisted vulnerability discovery has to do with the bug pipeline, how to prioritize under pressure with a four-lens triage framework (exploitability, exposure, impact, compensating controls), and why the real problem is not volume but the speed mismatch between finding bugs and fixing them. We walk through CVE-2026...
Instagram AI Takeover: How Attackers Exploited Meta Support Bots
Your profile photo vanishes. Your email is changed. A password reset you never requested lands in someone else's inbox. You're locked out of your own Instagram account, and you didn't click a single suspicious link.
In early 2026, attackers manipulated Meta's AI support chatbot to approve password resets on roughly 20,225 Instagram accounts over seven weeks. This episode breaks down how social engineering evolved from targeting human support reps to exploiting AI-powered customer service systems. We cover identity verification failures, how chatbots became part of the security boundary, the policy response led by California Attorney General...
FortiBleed: When Your Firewall Becomes the Front Door
Your firewall is supposed to be the thing that keeps attackers out. FortiBleed is the story of what happens when it becomes the way in.
In June 2026, roughly 86,644 sets of working Fortinet credentials turned up circulating among attackers across 194 countries. On June 18th, CISA issued an emergency advisory telling anyone running internet-facing Fortinet gear to terminate active sessions, rotate every credential, and turn on phishing-resistant multi-factor authentication immediately. This episode of Plaintext with Rich explains what FortiBleed actually is, why patching alone does not solve a credential-exposure incident, and what the difference between "patch"...
Post-Quantum Cryptography: Start the Inventory Before Q-Day
You don't inventory your house the morning of the move. You start months before. So why are most organizations still treating post-quantum cryptography as a 2035 problem?
Episode 31 of Plaintext with Rich treats the post-quantum crypto migration as what it actually is. A logistics problem, not a science one. We walk through the news peg that moved the timeline. Google's March 2026 announcement of a 2029 internal deadline, years ahead of federal targets, anchored by Craig Gidney's research at Google Quantum AI showing that one million noisy qubits could break a 2,048-bit RSA key in under a week. W...
Cybersecurity Careers and AI: The Squeeze and the Opening
Someone pulled Rich aside at a conference recently. Six years in IT, ready to break into security, and asking the question more people ask every week. Should I even bother right now? Here's what the data actually shows.
Episode 30 of Plaintext with Rich unpacks the cybersecurity career paradox of 2026. The bottom rung is getting squeezed as AI automates SOC analyst, threat intelligence, and incident response work. At the same time, demand for AI security engineers, prompt injection specialists, and model risk leads is climbing fast. The episode walks through what prompt injection actually looks like in plain...
Supply Chain Attacks: How One Update Hit OpenAI
A routine software update. No phishing. No sketchy download. Then a security team finds the unthinkable: trusted code has been hijacked, and the breach rode in through the exact channels engineers rely on every day. I walk through the supply chain attacks that piled up across April and May 2026, including poisoned open source packages tied to TanStack and trojanized Daemon Tools installers, plus the rapid-fire abuse of major software registries like NPM, PyPI, and Docker Hub.
The most important twist is what the malware is hunting. These campaigns aren’t primarily chasing customer data. They’re after the a...
Microsoft Exchange Zero-Day Under Attack: One Email Hijacks OWA
It's Monday morning. You open the third email of the day. Nothing visible happens, but in the background, an attacker just borrowed the proof you were logged in.
Episode 28 of Plaintext with Rich is a hot take on CVE-2026-42897, the Microsoft Exchange Server zero-day under active exploitation right now. We break down what cross-site scripting actually does inside Outlook Web Access, why session hijacking is more dangerous than the underlying bug, and how a single crafted email becomes business email compromise. We look at the on-premises versus Exchange Online divide, why ProxyLogon and ProxyShell aren't ancient...
Work-Life Balance in Cybersecurity: The Structural Fix
You finish at 6:00pm. At 6:47 you reopen the laptop, 'just to check something.' By 9:00 the evening is gone. The boundary didn't fail tonight. It was never there.
Episode 27 of Plaintext with Rich closes the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we're talking about work-life balance, but not as willpower or time management. As protective infrastructure. We pull the arc together, mental, spiritual, physical, and burnout, and land on the idea that balance is what keeps the first three from collapsing into the fourth. We borrow...
Cybersecurity Burnout: Not a Character Flaw, a System Problem
You're reading a breach report. Third one this month. Last year a story like this would have lit something in you. Today you scroll past it. That's not you. That's the bill.
Episode 26 of Plaintext with Rich is the fourth installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we're talking about burnout, what it actually is and why the cybersecurity industry produces it reliably. We use the World Health Organization's classification of burnout as an occupational phenomenon and Christina Maslach's three dimensions (exhaustion, cynicism, reduced...
Physical Health in Cybersecurity: The Body Keeps the Receipts
It's Friday morning. You stand up to refill your water and your back doesn’t move the way it used to. The systems are up and running smoothly. Your body hasn’t gotten the same memo.
Episode 25 of Plaintext with Rich is the third installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we’re talking about physical health, the silent receipt your body keeps for the cumulative load of this job. We get into the specific body costs of security work: long incident response shifts, screen...
Spiritual Health in Cybersecurity: The Why Behind the Work
Spiritual health on a cybersecurity podcast sounds like a stretch. Stay with us. Because somewhere between the vendor pitches, the patch cycles, and the 3 a.m. page, a lot of us stopped working for the why and started working for the number.
Episode 24 of Plaintext with Rich is the second installment of the Month of Mindfulness, a five-week series on self-care for people working in security and tech. This week we define spiritual health as the values that make up who you are, the things you won’t trade even for a raise. We get into mission dr...
Mental Health in Cybersecurity: The Weight of Vigilance
It's 6:47 a.m. The incident was contained hours ago. The systems are fine. You're the one still running hot.
This episode opens the Month of Mindfulness, a five-week Plaintext with Rich series on mental health, spiritual health, physical health, burnout, and work-life balance for people working in cybersecurity and tech. May 1 happens to fall during Mental Health Awareness Month, which makes it the right time to start. We're talking about the mental load that comes with vigilance work: on-call rotations, alert fatigue, incident response, and the cost of being the person who carries worst-case scenarios in your...
Threat Intelligence: Why Most Organizations Get It Backwards
A dashboard lights up with indicators of compromise. The analyst copies the top five into a ticket, tags it "actionable," and sends it to the SOC. Nobody reads it not because they don't care, but because it didn't tell them what to do or why it mattered. That's not an intelligence failure. That's a confusion about what intelligence actually is.
This episode breaks down threat intelligence from the ground up, drawing on Rich's military experience as a case officer in special operations. It separates data, information, and intelligence into three distinct layers, explains why most CTI programs...
Roll for Security: What D&D Teaches About Cyber Defense
The fighter absorbs hits up front. The rogue finds traps before the party walks into them. The cleric keeps everyone alive when things go wrong. And the bard convinces the people with resources to actually fund the quest. Nobody does everything. Everybody has a role. Now replace the dungeon with your company's network.
This episode maps cybersecurity roles to D&D character classes, SOC analysts as fighters, pen testers as rogues, incident response as clerics, security architects as wizards, CISOs as bards, and threat intelligence analysts as rangers. It translates the six core ability scores into an...
Why Reading Code Makes You Dangerous (In a Good Way)
A vulnerability advisory drops on a Tuesday. Two people read the same report. One sees a severity score and waits for a patch. The other understands what a heap-based buffer overflow actually means and starts reducing risk before a fix even exists.
This episode breaks down why code literacy is a cybersecurity skill, not just a developer skill. It starts with the listener's question about learning C and C++ for security, then widens the lens to cover the full stack: why C still matters because of how it handles memory, how offensive operators use that knowledge to...
Hacking on Screens and Pages: Pop Culture That Shaped Cybersecurity
Someone sits down at a keyboard, mashes keys for six seconds, and says "I'm in." Every security professional dies a little inside but that scene is probably the reason half of us got into this field.
This episode walks through the movies, TV shows, books, graphic novels, and video games that shaped how we think about cybersecurity. Each pick lands in one of two buckets: the fantastical, the ones that made hacking look cool even when the tech was nonsense and the accurate or semi accurate, the ones that actually got the culture, the tools, and the...
Linux vs. Windows vs. macOS: Where Security Actually Differs
People love to ask which operating system is the most secure. That's the wrong shape of question. Each one is designed for a different job, and that shapes how it gets attacked.
This episode clears up what Linux actually is, how it compares to Windows and macOS, and why the differences matter for security. It starts by explaining why Linux isn't one product but a family of systems built around a shared kernel, then covers how each OS handles permissions, software installation, and administrator access differently. The episode walks through why Windows attracts commodity malware at scale...
APIs: The Control Points Hiding Inside Every App
You tap a button and a ride shows up. You check out online and your bank approves it in seconds. It feels automatic. But nothing in software is automatic. Something received a request, decided it was valid, did some work, and sent back a response. That something is an API.
This episode breaks down what APIs actually are, why they exist, when to use them, and why they matter far more than most people realize. It starts with a restaurant analogy that makes the concept click, then walks through how modern software is built from modular pieces...
Securing AI at Work: What the Chat Box Actually Touches
At 4:47 p.m., someone pastes a customer escalation into an AI assistant and asks it to rewrite the tone. The reply is perfect. It also includes a private note from the internal thread. No breach. No attacker. Just a new workflow that doesn't know what should stay inside.
This episode breaks down how to secure AI tools in the workplace by treating them like any other system that handles sensitive information and influences decisions. It covers the three patterns where AI quietly breaks: sensitive data going in through normal use, assistants being steered by hidden instructions inside...
AI Is an Umbrella Word (And That's the Problem)
Every company says they're using AI. Some mean chatbots. Some mean automation. Some mean statistics with a new logo. If everything is AI, the word stops meaning anything.
This episode untangles what people actually mean when they say "AI" by breaking the umbrella into its real components. It covers machine learning (systems that learn patterns from data), deep learning (layered neural networks that made modern recognition possible), large language models (text prediction engines driving today's headlines), RAG or retrieval-augmented generation (connecting models to specific documents instead of relying on training alone), and agentic AI (systems that don't...
Why Security Fails When Everyone Is Right
The access made sense. The exception was justified. The shortcut saved time. Each decision worked on its own. And somehow, together, they added up to failure.
This episode tackles the uncomfortable truth that most security failures aren't caused by ignorance or carelessness. They're caused by systems quietly accumulating risk while everyone is doing their best. It walks through the patterns that create this drift: temporary decisions that never expire, blurred ownership where risk becomes nobody's problem, trust that's too broad because convenience won repeatedly, and complexity without clarity where tools exist but don't drive action. The episode...
Zero Trust: What It Actually Means Beyond the Buzzword
The breach didn't come through a broken firewall. It walked in through a valid login. Nothing exploded. Nothing looked suspicious at first. Someone just signed in and kept going.
This episode clears up what Zero Trust actually is and what it isn't. It's not a product, not a box you install, and not a technology you turn on. It's a design decision: don't automatically believe a request just because it comes from inside your network. The episode explains why the old perimeter model stopped working when work moved to laptops, apps moved to the cloud, and being "...
Supply Chain Cybersecurity: When the Breach Starts Upstream
You can lock down every system you own. Patch everything. Train everyone. And still lose control, because the failure didn't start with you. It started somewhere upstream.
This episode breaks down supply chain cybersecurity by explaining why attackers who can't reach you directly look for someone you already trust. It covers the most common patterns: tampered software updates that arrive through legitimate channels, vendor breaches that expose your data through someone else's failure, compromised third-party credentials, and dependency risk hidden inside assembled code libraries. The episode explains why these attacks scale so effectively and why they're hard...
Phishing and Social Engineering: Why the Strongest Defense Is Being Slower
You don't need to break a system if someone will open it for you. You don't need malware if a message feels urgent enough. Most modern breaches don't start with code. They start with a conversation.
This episode breaks down phishing and social engineering by explaining why these attacks keep working: they don't fight logic, they sidestep it. It covers how modern phishing has evolved beyond email to include text messages, voice calls, MFA fatigue attacks, QR code phishing, and AI-assisted impersonation. The episode walks through the emotional triggers attackers rely on (urgency, authority, fear, curiosity, helpfulness...
Ransomware and Double Extortion: Why Backups Alone Don't Save You Anymore
You don't get locked out first. You get watched. Someone maps your systems quietly, copies your data quietly, and waits until they're sure you can't avoid the conversation. Only then do the screens go dark.
This episode breaks down how ransomware actually works today and why double extortion changed the stakes completely. It explains how modern ransomware operations move slowly at first, stealing credentials and exploring systems before copying data and triggering encryption. The real leverage isn't locked files, it's the threat of publishing what was already taken. The episode walks through the most common entry points...
IoT Security: Why Every Smart Device Is a Computer That Inherits Risk
Your house didn't suddenly become unsafe. It just became chatty. Little devices, quietly talking to the internet, all day, all night. Most of them were never meant to be guarded.
This episode explains IoT security by starting with a translation: if a device needs an app to work and Wi-Fi to exist, it's a computer with software, memory, and network access, and computers inherit risk. It covers why manufacturers optimize for convenience over long-term protection, how most IoT compromises happen through automated scanning rather than targeted attacks, and why devices outlive the software inside them. The episode...
Cloud Security: Why Identity and Configuration Are the Real Perimeter
Nothing broke. Nothing crashed. No alarms went off. Someone clicked a box, someone skipped a setting, someone assumed the default was safe. And the cloud did exactly what it was told.
This episode explains cloud security by starting with the most important shift: in the cloud, identity is the perimeter. There is no fence, no lobby, no locked server room. If someone has valid credentials, they don't break in, they sign in. The episode walks through how cloud security goes wrong through misconfigured storage, over-permissioned identities, leaked API keys, missing multi-factor authentication, shadow cloud adoption, and absent...
Passkeys and Passwordless Login: Why Shared Secrets Are the Problem
You don't lose access to an account because someone knows your name. You lose access because they reused something you were told to keep secret. For years, the internet has worked on copying secrets and then acting surprised when copies escape.
This episode breaks down passwordless authentication and passkeys, explaining why the shift away from typed passwords isn't innovation hype but an industry admission that shared secrets have become a liability. It covers what passkeys actually are (cryptographic keys that never leave your device), why they're considered phishing-resistant (your device checks where it's talking, not just what...