Skip to main content
WSO2

WSO2

Wikimedia categorywww.wso2.com

Search complete. 36 mentions across 7 episodes found for "WSO2".

Sep 17, 2026

speaker_1NARRATOR
6:34
What aspects haven't been considered?
David SparkHOST
6:40
Maurice Amy of WSO2 said, quote, the gap you highlight is real.
David SparkHOST
6:45
So just essentially what was sort of referred to by Manduri Chandor and that you had said at the beginning of the show, Steve.
David SparkHOST
6:52
But it's not just about speed.
James AzarHOST
0:06
Screen Connect is being used against the MSPs it was built to protect.
James AzarHOST
0:09
WSO2 identity servers are handing attackers full admin, and the FBI just boarded an oil tanker off the Texas coast after a cyber attack cut off its communications for 30 hours.
James AzarHOST
0:19
We've got 12 stories on today's show.
James AzarHOST
0:21
This is the Cyber Hub Podcast.

7 MINS LATER

James AzarHOST
7:18
All of that really does matter.
James AzarHOST
7:22
All right, so let's move to our third story this morning.
James AzarHOST
7:25
And our third deep dive attackers are actively exploiting the vulnerability in WSO2 products, specifically the WSO2 identity server and API manager.
James AzarHOST
7:34
They're doing that to gain full administrative access to enterprise middleware environments.
speaker_0HOST
2:15
Let's start with the enterprise gatekeeper.
speaker_0HOST
2:17
We have a critical vulnerability in the WSO2 API manager.
speaker_1HOST
2:22
Oh, this one's just massive.
speaker_0HOST
2:24
Huge.
speaker_0HOST
2:56
Now, we know this is a failure of trust verification involving JWTs, so JSON Web Tokens, but I want to dig into the actual mechanism here.
speaker_1HOST
3:03
Sure, let's get into it.
speaker_0HOST
3:04
How does a system like WSO2 fundamentally fail to verify a token? What goes wrong?
speaker_1HOST
3:10
Well, to understand the failure, you really have to look at how a GWT is constructed in the first place, right? Okay.

Unknown podcast

2026-09-16: Cisco discloses a critical zero-day in Secure Email Gateway already exploited in the wild with

Sep 16 · 6 Mentions

CarolinaHOST
0:03
Cisco discloses a critical zero day in secure email gateway already exploited in the wild with root level command execution.
CarolinaHOST
0:10
Microsoft issues emergency patches after September's 900 and 74 CVE, or Common Vulnerabilities and Exposures, Update broke remote desktop services and Hyper-V. WSO2 API manager JWT bypass vulnerability now under active exploitation with forged admin tokens targeting enterprise APIs.
CarolinaHOST
0:30
Here's the full breakdown of today's top security stories.
CarolinaHOST
0:33
Cyber threat brief, September 16, 2026.
CarolinaHOST
1:59
CIS a KEV due date is September 17.
CarolinaHOST
2:02
CyberScope.
CarolinaHOST
2:04
WSO2 a PI, manager JWT bypass under active exploitation, CVE2026-5430.
CarolinaHOST
2:09
Watch tower observed active exploitation of CVE2026-5430.
Jerry BellHOST
0:00
If you run WSO2's API Gateway, today's the day to get that 5-month-old patch off the risk register and onto the system.
Jerry BellHOST
0:07
Happy Hump Day! This is the Daily DevSec Brief for Wednesday, September 16th, 2026.
Jerry BellHOST
0:12
1.
Jerry BellHOST
0:13
Anyone who can reach a WSO2 API Gateway can sign a token with an algorithm the product doesn't support and the Gateway validates it and hands back Administrator.
Jerry BellHOST
0:23
Watchtower caught forged admin tokens arriving at its honeypots over the weekend, and the fix has been on WSO2's website since the first week of May.
Jerry BellHOST
0:33
Apply the update level for your version, then rotate every consumer key and secret on the gateway.
Jerry BellHOST
0:38
Two, somebody on an adjacent network with basic privileges on a Pixel phone can escalate through a logic error in the cellular modem with no user interaction and Google says there are indications it's under limited targeted exploitation.
Jerry BellHOST
4:03
Alert on that certificate and on port 7443 with a self-signed cert.
Lorena RuizNARRATOR
0:00
Welcome to the Mexico Business Now Podcast, your ultimate source for insights and trends shaping the Mexican business landscape.
Lorena RuizNARRATOR
0:09
The following expert contributor article of the AI cloud and data industry is Digitizing Government: AI Agents and Secure Interoperability by Fernando Arditi, Vice President and General Manager, LATAM, WSO2.
Lorena RuizNARRATOR
0:25
Don't forget to follow us, turn on the notifications bell, and leave a five-star rating and a review on this podcast.
Lorena RuizNARRATOR
0:32
Mexico's digital government transformation is no longer a future ambition.
Artificial IntelligenceNARRATOR
1:21
We needed guardrails.
Artificial IntelligenceNARRATOR
1:23
Around this time, our team started evaluating the WSO2 API platform, specifically its AI gateway, as a unified control layer for all our AI traffic.
Artificial IntelligenceNARRATOR
1:33
I was skeptical at first.
Artificial IntelligenceNARRATOR
1:35
Another vendor promising to solve AI governance with a single dashboard? I'd heard that pitch before.
Artificial IntelligenceNARRATOR
1:41
But the more I dug in, the more it clicked.
Artificial IntelligenceNARRATOR
1:44
WSO2's approach wasn't just about bolting a filter onto your LLM calls.
Artificial IntelligenceNARRATOR
1:49
It was about treating AI traffic the same way you'd treat any critical enterprise API.
Artificial IntelligenceNARRATOR
1:54
With governance, observability, lifecycle management, and policy enforcement baked in from the start.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.