DiscoverAutonomous IT
Autonomous IT
Claim Ownership

Autonomous IT

Author: Automox

Subscribed: 10Played: 299
Share

Description

Go from monotonous to autonomous IT operations with this series. Hosts from Automox, the IT automation platform for modern organizations, will cover the latest IT trends; Patch Tuesday remediations; ways to save time with Worklets (pre-built scripts); reduce risk; slash complexity; and automate OS, third-party, and configuration updates on all your Windows, macOS, and Linux endpoints. Automate confidence everywhere with Automox.
228 Episodes
Reverse
Labor Day is over and Microsoft made up for the day off. Landon Miles and Serena DiPenti sort September's Patch Tuesday down to the six bugs that matter, starting with the only one Microsoft confirms is already exploited: a Windows Update Stack privilege escalation that hands attackers SYSTEM, published with no score and no affected-product list.They also cover:- An unauthenticated remote code execution in Windows DNS Server, rated more likely to be exploited, and why it's a domain controller problem for most shops- A Remote Desktop Services bug that scores 9.8 but carries an Important label, and why the label shouldn't set your patch order- SQL Copilot in Management Studio ignoring its own read-only restrictions, and where the real guardrail belongs- An Outlook flaw that fires from the Reading Pane with no click, and why a Microsoft 365 subscription doesn't mean the fix is already installed- An Exchange Server bug that lets one low-privilege mailbox impersonate every other userPlus macOS Tahoe 26.6.2 and what's behind the month's record CVE count. Know what you run, patch the exploited one first, then work down your list.
In April, Jason Kikta and Dmitri Alperovitch landed on a structural conclusion: AI had collapsed patch-to-exploit time to under an hour, 1-10-60 was no longer fast enough, and the only answer was prevention. Patch by default, limit blast radius, stop playing a detection-and-response game built for human-speed attacks. This episode picks up where that conversation ended. What's changed since April, and can detection-first models survive the pace of change at all? Kat Traxler is here to stress test that question from the inside.Guests: Jason Kikta, Automox CTO, Dmitri Alperovitch, Co-Founder and Chairman, Silverado Policy AcceleratorKat Traxler, Principal Security Researcher, Vectra AIHost: Landon Miles
August 2026 delivers the second-largest Patch Tuesday on record with nearly 400 CVEs, and Landon Miles, Jason Kikta, and Serena DiPenti sort out which ones actually matter. They start with the only actively exploited vulnerability of the month, CVE-2026-68820, a use-after-free in the Windows AFD driver that trades a race condition for SYSTEM privileges. Serena breaks down CVE-2026-62832, a User Profile Service privilege escalation that lets an attacker load another user's registry hive with no user interaction required.Then there's the perfect 10.0 in Microsoft Teams that nobody needs to patch. Jason explains how cloud CVEs ended up in Patch Tuesday releases, why a third of this month's critical count requires zero customer action, and why the industry needs a separate disclosure mechanism before monthly CVE volume becomes pure noise. The crew also covers an ugly macOS screen sharing vulnerability that allowed authentication without credentials, the Linux kernel community's shift to issuing CVEs at scale, fresh takes from Black Hat and DEF CON on AI-driven vulnerability discovery, and why frontier models are forcing patching decisions to happen by policy instead of one CVE at a time.Patch your stuff. See you next month.
Public Key Infrastructure (PKI) underpins nearly every secure interaction in modern IT, but it's also one of the most misunderstood and overlooked foundations of security.In this episode of Secure IT, host Jason Kikta is joined by Mark Cooper, CEO and founder of PKI Solutions, to unpack why PKI is so critical to identity, authentication, and trust, and what happens when it fails.They explore how certificates enable passwordless authentication, secure TLS connections, IoT devices, endpoints, and enterprise systems, while also examining why misconfigured or poorly monitored PKI environments often become an attacker's fastest path to privilege escalation. From certificate expirations and operational outages to real-world breach scenarios and pen test failures, this conversation maps the full PKI risk spectrum.Jason and Mark also challenge a common assumption in cybersecurity: that recovery equals resilience. Instead, they argue that true resilience means staying secure and operational, even during misconfiguration, failure, or attack.Whether you're new to PKI or responsible for running it, this episode will change how you think about identity infrastructure, resilience, and trust.Topics covered:- What PKI is and why most organizations already depend on it- Certificates, passwordless authentication, and digital identity- How PKI misconfigurations enable high-impact attacks- Why recovery is the weakest form of resilience- The hidden operational and security risks of foundational systems
570 vulnerabilities. That's July's Patch Tuesday count, nearly triple last month and a record by a wide margin. Jason Kikta is joined by host Landon Miles and offensive-security researcher Serena DiPenti for the July 2026 rundown:An Active Directory Federation Services bug (CVE-2026-56155) already exploited in the wild, rated a deceptively low 7.8A 9.8 DHCP client flaw (CVE-2026-49181) that reaches every Windows endpoint on the networkAn RDP bug you can shut down with a single setting, no patch requiredA SharePoint deserialization flaw (CVE-2026-50522) reachable by anyone with site-owner accessA 9.9 Hyper-V escape that lets one compromised VM take the whole hostA BitLocker bypass (6.1) worth knowing if you manage laptops in the fieldPlus why hacker summer camp turns every July into a bug dump, and what a 570-CVE release says about how much AI is really driving vulnerability discovery.
loading
Comments