Video Library25 curated videos

Watch the technique. Keep the decision context.

Every video is selected because it helps explain evidence, an attack technique or a technical constraint used in an Analysis. Nothing is loaded from YouTube until you press Play.

Privacy-first video
Direct evidence1 related Analysis

Kia Connected-Vehicle API Attack: Researcher Demonstration

Direct evidence · Sam Curry and research team

Watch the researcher demonstration of the dealer/API authorization path discussed in the analysis.

Privacy-first video
Direct evidence1 related Analysis

Oldsmar Water Treatment Cyber Incident: Original Press Conference

Direct evidence · Pinellas County Sheriff's Office

Watch the original public briefing that accompanied the Oldsmar incident response.

Privacy-first video
Attack technique1 related Analysis

Building an ICS Firing Range: Sharing Our Journey and Lessons Learned

Attack technique · BSides Munich

This is not the BPCS/SIS scenario itself. The OT attack-range discussion includes safety-system compromise and helps illustrate why cyber compromise must not collapse independent physical protection layers.

Privacy-first video
Attack technique1 related Analysis

Car Talk: Vehicle Security and the Automotive Attack Surface

Attack technique · BSides Knoxville

This is not the SDV provisioning scenario itself. The talk includes historical examples of malicious firmware delivery and remote vehicle compromise, illustrating how a trusted update path can become the propagation mechanism.

Privacy-first video
Attack technique1 related Analysis

Hacking PLCs and Causing Havoc on Critical Infrastructures

Attack technique · DEF CON / Thiago Alves

This is not the 2026 Minnesota incident itself. The talk demonstrates attacks against industrial PLCs and specifically includes Rockwell MicroLogix 1400, one of the PLC families cited in the Minnesota campaign, making the control-manipulation risk directly relevant.

Privacy-first video
Attack technique1 related Analysis

Hopping on the CAN Bus

Attack technique · Black Hat Asia

This is not a Euro 7 compliance video. It demonstrates why integrity cannot be assumed once automotive data and control messages cross electronic interfaces, which is the technical premise behind the evidence-chain argument.

Privacy-first video
Attack technique1 related Analysis

I Simulated Hacking a Car. Then I Tried to Defend It

Attack technique · BSides Exeter

A practical CAN attack-and-defence demonstration showing why detecting spoofing, replay or denial of service is only the beginning of an automotive response decision.

Privacy-first video
Attack technique1 related Analysis

Low Energy to High Energy: Hacking Nearby EV-Chargers Over Bluetooth

Attack technique · Black Hat

A technical demonstration of vulnerabilities exploited across multiple EV chargers, connecting endpoint compromise to the wider cyber-physical charging ecosystem discussed in the analysis.

Privacy-first video
Attack technique1 related Analysis

LTE Security: Facts and Fictions

Attack technique · BSides Charlotte

This predates private 5G and is not the industrial PRACH-jamming research. It is a useful cellular-security primer showing that strong authentication and encryption do not remove radio-layer availability and jamming risk.

Privacy-first video
Attack technique1 related Analysis

Server-Side Template Injection: RCE for the Modern Web App

Attack technique · Black Hat / PortSwigger Research

This is not the Windchill incident itself. It demonstrates how a server-side application flaw can be developed into remote code execution and a trusted application can become an attacker-controlled execution point.

Privacy-first video
Attack technique1 related Analysis

SpAIware and More: Advanced Prompt Injection Exploits in LLM Applications

Attack technique · Black Hat

Real prompt-injection demonstrations covering tool invocation, privilege escalation, exfiltration and persistence, directly illustrating why untrusted text must not become operational authority.

Privacy-first video
Attack technique1 related Analysis

Trust No Format: How ML Models Get Weaponized

Attack technique · BSides SLC

This is not the OpenAI/Hugging Face incident itself. It demonstrates how trusted AI artifacts and model-loading workflows can cross a trust boundary and lead to code execution.

Privacy-first video
Attack technique1 related Analysis

Vehicle Cyber Security and Innovative Assessment Techniques

Attack technique · BSides Manchester / NCC Group

This is not the KARR incident itself. It shows how vehicle-facing interfaces, telematics and externally reachable components expand the practical automotive attack surface.

Privacy-first video
Technical context1 related Analysis

End-to-End Supply Chain Integrity

Technical context · BSides Oslo

This is software-supply-chain rather than automotive-specific, but it demonstrates the underlying evidence problem: provenance, attestations and independently verifiable integrity across supplier boundaries.

Privacy-first video
Technical context1 related Analysis

FIRMSCOPE: Automatic Uncovering of Privilege-Escalation Vulnerabilities in Pre-Installed Apps in Android Firmware

Technical context · USENIX Security

This is not the AAOS research used in the analysis. It shows at scale that vendor-supplied Android firmware can contain exploitable vulnerabilities in trusted pre-installed components, reinforcing the distinction between provenance or authenticity and actual vulnerability state.

Privacy-first video
Technical context1 related Analysis

How to Secure Your AI Agents: A Technical Deep-Dive

Technical context · Google for Developers

A technical agent-security workshop covering excessive agency, prompt injection, authentication, authorization and agent-to-tool permissions, closely matching the authority-boundary argument in the analysis.

Privacy-first video
Technical context1 related Analysis

ICS/SCADA Defense

Technical context · BSides Augusta

This is not a Zero Trust implementation guide. It shows the compensating controls, segmentation and monitoring logic that make it possible to protect legacy OT without requiring every controller to become a modern identity endpoint.

Privacy-first video
Technical context1 related Analysis

OT: Air-Gap Is a Myth and Cloud Is Here to Stay

Technical context · BSides Vancouver

This is not a single recovery incident. The talk connects ransomware, OT interconnection, recovery-time constraints and the difficulty of rebuilding industrial environments safely after compromise.

Privacy-first video
Technical context1 related Analysis

The EU Cyber Resilience Act: What You Need to Know

Technical context · UC Berkeley Law

A 2026 CRA briefing covering essential requirements, risk classes and mandatory vulnerability-disclosure duties. The analysis goes further by treating the reporting clock as an operational decision-readiness problem.

Privacy-first video
Technical context1 related Analysis

The Overlooked Security Risk: 3rd Party Risk Management

Technical context · BSides Vancouver

This is not the Stadler incident itself. It explains the vendor lifecycle, due diligence and continuing assurance needed when a third party becomes part of the organisation's trust boundary.

Privacy-first video
Technical context1 related Analysis

VEX Generation Toolset Demonstration

Technical context · Apache Software Foundation / OpenRefactory

A practical exploitability-assessment and VEX-generation demonstration. It complements the analysis by showing why a VEX status is useful only when the underlying assessment is technically defensible.

Privacy-first video
Technical context1 related Analysis

Zero Trust Adoption: Benefits, Applications, and Resources

Technical context · Carnegie Mellon SEI

A Zero Trust architecture primer that supports the article's core decision: remote connectivity should not inherit standing trust merely because a user or device reached the network.