{"podcast":{"title":"Below the Surface (Audio) - The Supply Chain Security Podcast","slug":"below-the-surface-audio-the-supply-chain-security-podcast-5987778","podcast_index_feed_id":5987778,"rss_url":"https://feeds.libsyn.com/454509/rss","website_url":"https://eclypsium.com/","image_url":"https://static.libsyn.com/p/assets/2/a/8/7/2a879f07ebbd201d27a2322813b393ee/ecl_bts2_cta_1400x1400-20240911-gw2wy33qw9.png","author":"Eclypsium","episode_count":82,"summary":"A lively discussion of the threats affecting supply chain, specifically focused on firmware and low-level code that is a blind spot for many organizations. This podcast will feature guests from the cybersecurity industry discussing the problems surrounding supply chain-related issues and potential solutions. Get the Supply Chain Security Toolkit from Eclypsium here: https://eclypsium.com/go","last_synced_at":"2026-09-17T04:19:26.188600+00:00","page_url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778"},"episode":{"title":"How Cheap KVMs Could Be Your Network's Weak Link - BTS #70","slug":"how-cheap-kvms-could-be-your-network-s-weak-link-bts-70","published_at":"2026-03-25T20:05:00+00:00","page_url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778/how-cheap-kvms-could-be-your-network-s-weak-link-bts-70","show_page_url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778","url":"https://belowthesurfacesw.libsyn.com/how-cheap-kvms-could-be-your-networks-weak-link-bts-70","audio_url":"https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/belowthesurfacesw/70.mp3?dest-id=3822522","summary":"In this episode, we explore the security vulnerabilities of low-cost IP-based KVMs, including firmware flaws, default credentials, and insecure update mechanisms. Two Eclypsium researchers, Paul and Rey, discovered the vulnerabilities and shared the details and behind-the-scenes details! We also discuss real-world testing, vendor responses, and best practices for securing remote management devices in enterprise environments. Chapters 00:00 Introduction to KVM Vulnerabilities 03:00 Research Background and Team Introduction 05:57 Exploring GLINet and Initial Findings 09:03 Firmware Analysis and Security Expectations 11:58 Vulnerability Disclosure and Response 15:07 Enterprise Risks and Deployment Concerns 17:59 Security Best Practices for KVMs 21:06 Vendor Responses and Community Engagement 23:49 Unique Vulnerabilities in SiP and JetKVM 27:01 Conclusion and Future Directions 31:26 Vulnerability Research and Tool Development 34:14 Vendor Communication and Disclosure Challenges 37:51 Firmware Update Issues and Security Concerns 39:12 The Importance of Reviews and Brand Trust 41:42 Security Best Practices for KVMs 45:38 Network Segmentation and Device Security 49:26 Discovering IoT Devices on the Network 52:11 Open Source Solutions and Community Engagement 55:58 The Future of KVM Security and Regulation","meta_description":"In this episode, we explore the security vulnerabilities of low-cost IP-based KVMs, including firmware flaws, default credentials, and insecure update mec…","key_points":[],"chapters":[],"topics":[],"duration_seconds":3776,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/below-the-surface-audio-the-supply-chain-security-podcast-5987778/episodes/how-cheap-kvms-could-be-your-network-s-weak-link-bts-70/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/below-the-surface-audio-the-supply-chain-security-podcast-5987778/how-cheap-kvms-could-be-your-network-s-weak-link-bts-70.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}