FRMCS: The Future Railway Mobile Communication System
Direct context · UICUse the official FRMCS overview as context for the transport-versus-trust boundary.
Cybersecurity Under PressureReal Attacks. Real Lessons.Weekly BriefEvery video is selected because it helps explain evidence, an attack technique or a technical constraint used in an Analysis. Nothing is loaded from YouTube until you press Play.
Use the official FRMCS overview as context for the transport-versus-trust boundary.
Watch the researcher demonstration of the dealer/API authorization path discussed in the analysis.
Watch the original public briefing that accompanied the Oldsmar incident response.
See the demonstrated control-logic modification that underpins the analysis.
This is not the BPCS/SIS scenario itself. The OT attack-range discussion includes safety-system compromise and helps illustrate why cyber compromise must not collapse independent physical protection layers.
This is not the SDV provisioning scenario itself. The talk includes historical examples of malicious firmware delivery and remote vehicle compromise, illustrating how a trusted update path can become the propagation mechanism.
This is not the 2026 Minnesota incident itself. The talk demonstrates attacks against industrial PLCs and specifically includes Rockwell MicroLogix 1400, one of the PLC families cited in the Minnesota campaign, making the control-manipulation risk directly relevant.
This is not a Euro 7 compliance video. It demonstrates why integrity cannot be assumed once automotive data and control messages cross electronic interfaces, which is the technical premise behind the evidence-chain argument.
A practical CAN attack-and-defence demonstration showing why detecting spoofing, replay or denial of service is only the beginning of an automotive response decision.
A technical demonstration of vulnerabilities exploited across multiple EV chargers, connecting endpoint compromise to the wider cyber-physical charging ecosystem discussed in the analysis.
This predates private 5G and is not the industrial PRACH-jamming research. It is a useful cellular-security primer showing that strong authentication and encryption do not remove radio-layer availability and jamming risk.
This is not the Windchill incident itself. It demonstrates how a server-side application flaw can be developed into remote code execution and a trusted application can become an attacker-controlled execution point.
Real prompt-injection demonstrations covering tool invocation, privilege escalation, exfiltration and persistence, directly illustrating why untrusted text must not become operational authority.
This is not the OpenAI/Hugging Face incident itself. It demonstrates how trusted AI artifacts and model-loading workflows can cross a trust boundary and lead to code execution.
This is not the KARR incident itself. It shows how vehicle-facing interfaces, telematics and externally reachable components expand the practical automotive attack surface.
This is software-supply-chain rather than automotive-specific, but it demonstrates the underlying evidence problem: provenance, attestations and independently verifiable integrity across supplier boundaries.
Official railway-sector context for the interaction between cybersecurity, regulation, standards and operational assurance. It is not a demonstration of the patching scenario itself.
This is not the AAOS research used in the analysis. It shows at scale that vendor-supplied Android firmware can contain exploitable vulnerabilities in trusted pre-installed components, reinforcing the distinction between provenance or authenticity and actual vulnerability state.
A technical agent-security workshop covering excessive agency, prompt injection, authentication, authorization and agent-to-tool permissions, closely matching the authority-boundary argument in the analysis.
This is not a Zero Trust implementation guide. It shows the compensating controls, segmentation and monitoring logic that make it possible to protect legacy OT without requiring every controller to become a modern identity endpoint.
This is not a single recovery incident. The talk connects ransomware, OT interconnection, recovery-time constraints and the difficulty of rebuilding industrial environments safely after compromise.
A 2026 CRA briefing covering essential requirements, risk classes and mandatory vulnerability-disclosure duties. The analysis goes further by treating the reporting clock as an operational decision-readiness problem.
This is not the Stadler incident itself. It explains the vendor lifecycle, due diligence and continuing assurance needed when a third party becomes part of the organisation's trust boundary.
A practical exploitability-assessment and VEX-generation demonstration. It complements the analysis by showing why a VEX status is useful only when the underlying assessment is technically defensible.
A Zero Trust architecture primer that supports the article's core decision: remote connectivity should not inherit standing trust merely because a user or device reached the network.
No videos match this filter.