Video Library45 curated recordings

Industrial cybersecurity videos for automotive, OT and railway.

Curated technical videos for automotive cybersecurity, OT/ICS security, railway cybersecurity, product security and embedded cyber-physical systems. Each video stays connected to the Analysis that explains the evidence and engineering decision context. Nothing is loaded from YouTube until you press Play.

Topic
Format
45 recordings
Direct evidence1 related Analysis
Webinar & briefing

Free webinar: Telematics Applications TSI (10 March 2026)

Direct context · European Union Agency for Railways
RailwayRegulation

Official ERA webinar dedicated to the 2026 Telematics Applications TSI, covering the new TSI provisions, capacity allocation, traffic monitoring, train composition, freight and intermodal processes, passenger information and ticketing. It is directly relevant context for the Analysis's trust-governance discussion around interoperable shared rail data services.

Direct evidence1 related Analysis
Technical video

Kia Connected-Vehicle API Attack: Researcher Demonstration

Direct evidence · Sam Curry and research team

Watch the researcher demonstration of the dealer/API authorization path discussed in the analysis.

Direct evidence1 related Analysis
Technical video

Oldsmar Water Treatment Cyber Incident: Original Press Conference

Direct evidence · Pinellas County Sheriff's Office

Watch the original public briefing that accompanied the Oldsmar incident response.

Attack technique1 related Analysis
Research demo

Building an ICS Firing Range: Sharing Our Journey and Lessons Learned

Attack technique · BSides Munich

This is not the BPCS/SIS scenario itself. The OT attack-range discussion includes safety-system compromise and helps illustrate why cyber compromise must not collapse independent physical protection layers.

Attack technique1 related Analysis
Research demo

Car Talk: Vehicle Security and the Automotive Attack Surface

Attack technique · BSides Knoxville

This is not the SDV provisioning scenario itself. The talk includes historical examples of malicious firmware delivery and remote vehicle compromise, illustrating how a trusted update path can become the propagation mechanism.

Attack technique1 related Analysis
Research demo

Hacking PLCs and Causing Havoc on Critical Infrastructures

Attack technique · DEF CON / Thiago Alves

This is not the 2026 Minnesota incident itself. The talk demonstrates attacks against industrial PLCs and specifically includes Rockwell MicroLogix 1400, one of the PLC families cited in the Minnesota campaign, making the control-manipulation risk directly relevant.

Attack technique1 related Analysis
Research demo

Hopping on the CAN Bus

Attack technique · Black Hat Asia

This is not a Euro 7 compliance video. It demonstrates why integrity cannot be assumed once automotive data and control messages cross electronic interfaces, which is the technical premise behind the evidence-chain argument.

Attack technique1 related Analysis
Research demo

I Simulated Hacking a Car. Then I Tried to Defend It

Attack technique · BSides Exeter
Automotive

A practical CAN attack-and-defence demonstration showing why detecting spoofing, replay or denial of service is only the beginning of an automotive response decision.

Attack technique1 related Analysis
Research demo

J2497 Cybersecurity Vulnerability Threatens Trailer Brake Systems

Attack technique · J2497 trailer-brake demonstration

This is not the VehicleSec 2026 Bendix EC80 research itself. It demonstrates the security relevance of the J2497 trailer-brake interface and why an externally influenced legacy communication path can turn implementation behavior into a cyber-physical attack surface.

Attack technique1 related Analysis
Research demo

Low Energy to High Energy: Hacking Nearby EV-Chargers Over Bluetooth

Attack technique · Black Hat

A technical demonstration of vulnerabilities exploited across multiple EV chargers, connecting endpoint compromise to the wider cyber-physical charging ecosystem discussed in the analysis.

Attack technique1 related Analysis
Research demo

LTE Security: Facts and Fictions

Attack technique · BSides Charlotte

This predates private 5G and is not the industrial PRACH-jamming research. It is a useful cellular-security primer showing that strong authentication and encryption do not remove radio-layer availability and jamming risk.

Attack technique1 related Analysis
Research demo

Rogue Robots: Testing the Limits of an Industrial Robot's Security

Attack technique · Trend Micro / Politecnico di Milano

This predates TAT and is not the 2026 Trajectory Integrity study. It demonstrates parameter and production-logic manipulation on an industrial robot producing unintended physical behavior, directly illustrating why trusted execution and trusted motion are separate assurance questions.

Attack technique1 related Analysis
Research demo

Server-Side Template Injection: RCE for the Modern Web App

Attack technique · Black Hat / PortSwigger Research
Product Security

This is not the Windchill incident itself. It demonstrates how a server-side application flaw can be developed into remote code execution and a trusted application can become an attacker-controlled execution point.

Attack technique1 related Analysis
Research demo

SpAIware and More: Advanced Prompt Injection Exploits in LLM Applications

Attack technique · Black Hat

Real prompt-injection demonstrations covering tool invocation, privilege escalation, exfiltration and persistence, directly illustrating why untrusted text must not become operational authority.

Attack technique1 related Analysis
Research demo

Trust No Format: How ML Models Get Weaponized

Attack technique · BSides SLC
AI Security

This is not the OpenAI/Hugging Face incident itself. It demonstrates how trusted AI artifacts and model-loading workflows can cross a trust boundary and lead to code execution.

Attack technique1 related Analysis
Research demo

Vehicle Cyber Security and Innovative Assessment Techniques

Attack technique · BSides Manchester / NCC Group

This is not the KARR incident itself. It shows how vehicle-facing interfaces, telematics and externally reachable components expand the practical automotive attack surface.

Attack technique1 related Analysis
Research demo

WIP: Learning Adversarial Attacks on Adaptive Traffic Signal Control Systems Under Cooperative Perception

Attack technique · USENIX VehicleSec / Purdue University

This is not a railway incident. It demonstrates falsified perception data being used to fool a learning-based traffic-control system, providing a close cyber-physical analogue for the analysis's poisoned-telemetry and independent-evidence problem.

Technical context1 related Analysis
Technical video

End-to-End Supply Chain Integrity

Technical context · BSides Oslo

This is software-supply-chain rather than automotive-specific, but it demonstrates the underlying evidence problem: provenance, attestations and independently verifiable integrity across supplier boundaries.

Technical context1 related Analysis
Technical video

FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware

Technical context · USENIX Security

This is not the AAOS research used in the analysis. It shows at scale that vendor-supplied Android firmware can contain exploitable vulnerabilities in trusted pre-installed components, reinforcing the distinction between provenance or authenticity and actual vulnerability state.

Technical context1 related Analysis
Technical video

How to Secure Your AI Agents: A Technical Deep-Dive

Technical context · Google for Developers

A technical agent-security workshop covering excessive agency, prompt injection, authentication, authorization and agent-to-tool permissions, closely matching the authority-boundary argument in the analysis.

Technical context1 related Analysis
Technical video

ICS/SCADA Defense

Technical context · BSides Augusta

This is not a Zero Trust implementation guide. It shows the compensating controls, segmentation and monitoring logic that make it possible to protect legacy OT without requiring every controller to become a modern identity endpoint.

Technical context1 related Analysis
Technical video

OT: Air-Gap Is a Myth and Cloud Is Here to Stay

Technical context · BSides Vancouver

This is not a single recovery incident. The talk connects ransomware, OT interconnection, recovery-time constraints and the difficulty of rebuilding industrial environments safely after compromise.

Technical context1 related Analysis
Technical video

The EU Cyber Resilience Act: What You Need to Know

Technical context · UC Berkeley Law

A 2026 CRA briefing covering essential requirements, risk classes and mandatory vulnerability-disclosure duties. The analysis goes further by treating the reporting clock as an operational decision-readiness problem.

Technical context1 related Analysis
Technical video

The Overlooked Security Risk: 3rd Party Risk Management

Technical context · BSides Vancouver

This is not the Stadler incident itself. It explains the vendor lifecycle, due diligence and continuing assurance needed when a third party becomes part of the organisation's trust boundary.

Technical context1 related Analysis
Technical video

VEX Generation Toolset Demonstration

Technical context · Apache Software Foundation / OpenRefactory

A practical exploitability-assessment and VEX-generation demonstration. It complements the analysis by showing why a VEX status is useful only when the underlying assessment is technically defensible.

Technical context1 related Analysis
Technical video

Zero Trust Adoption: Benefits, Applications, and Resources

Technical context · Carnegie Mellon SEI

A Zero Trust architecture primer that supports the article's core decision: remote connectivity should not inherit standing trust merely because a user or device reached the network.

Industry body2025-09-25
Webinar & briefing

Sharing Railway Response to the Iberian Power Outage

International Union of Railways
Railway

Rail operators and infrastructure managers share operational lessons from the April 2025 Iberian power outage, with replays available in English, Spanish and Portuguese.

Why it mattersStrong operational-resilience material grounded in a real cross-operator disruption.
NIST · NCCoEWorkshop recording
Watch on official source ↗
Official2025-04-03
Webinar & briefing

Cyber AI Profile Workshop

NIST National Cybersecurity Center of Excellence
AI Security

NIST workshop on the Cyber AI Profile, including protection of AI systems and the relationship between the Cybersecurity Framework and AI RMF.

Why it mattersHigh-quality governance and architecture context for AI security without vendor framing.
NIST · NCCoEWorkshop recording
Watch on official source ↗
Official2025-03-13
Webinar & briefing

Cybersecurity Framework Profile for Semiconductor Manufacturing

NIST National Cybersecurity Center of Excellence
OT/ICS

Public workshop on the CSF 2.0 Semiconductor Manufacturing Community Profile, its assumptions, impacts and adoption path.

Why it mattersStrong manufacturing/OT material that connects cybersecurity governance to cyber-physical production environments.
NIST · NCCoEWebinar
Watch on official source ↗
Official2025-01-29
Webinar & briefing

Cybersecurity for Smart Inverters

NIST National Cybersecurity Center of Excellence
OT/ICSProduct Security

NIST briefing on practical cybersecurity guidance for small-scale solar inverter implementations and product capabilities.

Why it mattersCompact cyber-physical product-security example at the grid edge.
NIST · NCCoERecorded briefing
Watch on official source ↗
Official2025-01-23
Webinar & briefing

Implementing a Zero Trust Architecture

NIST National Cybersecurity Center of Excellence
Product Security

NCCoE panel on lessons from implementing end-to-end Zero Trust architectures aligned with NIST SP 800-207.

Why it mattersPractical architecture context for trust-boundary and remote-access decisions.
Research2024-04-29
Webinar & briefing

Using a Scenario to Reason About Implementing a Zero Trust Strategy

Carnegie Mellon Software Engineering Institute

SEI engineering approach for turning Zero Trust principles into a contextual, prioritised implementation roadmap using mission and workflow scenarios.

Why it mattersA useful antidote to generic Zero Trust checklists, with strong decision and architecture framing.
NIST · NCCoEWebinar
Watch on official source ↗
Official2023-12-07
Webinar & briefing

5G Cybersecurity

NIST National Cybersecurity Center of Excellence
OT/ICS

NCCoE 5G project update with an operational 5G Standalone lab tour, demonstration and infrastructure-security discussion.

Why it mattersRelevant to industrial/private-5G attack surface, supporting infrastructure and availability discussions.
ERA · ENISAWebinar
Watch on official source ↗
Official2023-02-16
Webinar & briefing

Feedback on the ERA-ENISA Conference on Railway Cybersecurity

ERA / ENISA
RailwayRegulation

Catch-up briefing on railway cybersecurity conference findings, including transport-sector security investment and policy developments.

Why it mattersConcise official synthesis for readers who need sector context rather than a full conference.
NIST · NCCoEWorkshop recording
Watch on official source ↗
Official2022-09-19
Webinar & briefing

NCCoE DevSecOps Workshop

NIST National Cybersecurity Center of Excellence
Product SecuritySupply Chain

Workshop covering SSDF, software supply-chain security, open source and practical DevSecOps implementation across government and industry.

Why it mattersDirectly useful for product-security and secure-development lifecycle decisions.
ERA · ENISAWebinar
Watch on official source ↗
Official2021-11-25
Webinar & briefing

Managing Cybersecurity Risks in Railways — Part 2

ERA / ENISA
RailwayOT/ICS

Second part of the ERA-ENISA railway cyber risk session, extending the practical discussion of threats, assets and security measures.

Why it mattersUseful structured learning material for railway cybersecurity assurance and risk treatment.
ERA · ENISAWebinar
Watch on official source ↗
Official2021-11-25
Webinar & briefing

Managing Cybersecurity Risks in Railways — Part 1

ERA / ENISA
RailwayOT/ICS

First part of the ERA-ENISA session on practical cyber risk management approaches for railway IT and OT systems.

Why it mattersStrong bridge between rail operations, IEC 62443 / TS 50701-style engineering and enterprise risk management.
Official2021-10-28
Webinar & briefing

European Data on Rails: The Linked Data Project

European Union Agency for Railways
Railway

ERA explains linked data, knowledge graphs, semantic interoperability and route compatibility across European rail registers.

Why it mattersUseful technical context for shared-data architecture, semantics and interoperability trust boundaries.
Research2021-05-19
Webinar & briefing

Software Supply Chain Concerns for DevSecOps Programs

Carnegie Mellon Software Engineering Institute
Supply ChainProduct Security

SEI uses SolarWinds to examine architectural software-supply-chain risk in complex DevSecOps programmes and practical mitigation needs.

Why it mattersUseful architecture-level treatment of supply-chain risk beyond dependency scanning.
ENISA · ERAConference recording
Watch on official source ↗
Official2021-03-17
Webinar & briefing

Cybersecurity in Railways Conference — Day 2

ENISA / ERA
Railway

Rail research and innovation, technical interoperability, cybersecurity platforms, ER-ISAC and collective incident-response models.

Why it mattersConnects technical rail innovation with information sharing and coordinated response.
ENISA · ERAConference recording
Watch on official source ↗
Official2021-03-16
Webinar & briefing

Cybersecurity in Railways Conference — Day 1

ENISA / ERA
RailwayRegulation

Policy, NIS, railway safety authority, CENELEC WG26 and a TS 50701 application case study in one official rail cybersecurity programme.

Why it mattersHigh-value standards and governance context for railway security engineering.
ERA · ENISAWebinar
Watch on official source ↗
Official2020-11-13
Webinar & briefing

Cybersecurity in Railways

ERA / ENISA
RailwayOT/ICSRegulation

Joint ERA-ENISA overview of the European cybersecurity framework for rail stakeholders and the evolution of railway cybersecurity requirements.

Why it mattersFoundational official context for railway cyber governance and OT security.