WSO2
Wikimedia categorywww.wso2.com
36
MENTIONS
7
EPISODES
7
PODCASTS
Search complete. 36 mentions across 7 episodes found for "WSO2".
Sep 17, 2026
How AppSec Needs to Change For the Speed of AI
S
6:34speaker_1NARRATOR
What aspects haven't been considered?
D
6:40David SparkHOST
Maurice Amy of WSO2 said, quote, the gap you highlight is real.
D
6:45David SparkHOST
So just essentially what was sort of referred to by Manduri Chandor and that you had said at the beginning of the show, Steve.
D
6:52David SparkHOST
But it's not just about speed.
Google Patches Pixel Modem Zero-Click Zero-Day Exploited, FBI and Coast Guard Board Oil Tanker VL Prosperity After Cyberattack Cut Comms, Spain Reports 1st Known Agentic AI Data Breach to Regulator
J
0:06James AzarHOST
Screen Connect is being used against the MSPs it was built to protect.
J
0:09James AzarHOST
WSO2 identity servers are handing attackers full admin, and the FBI just boarded an oil tanker off the Texas coast after a cyber attack cut off its communications for 30 hours.
J
0:19James AzarHOST
We've got 12 stories on today's show.
J
0:21James AzarHOST
This is the Cyber Hub Podcast.
7 MINS LATER
J
7:18James AzarHOST
All of that really does matter.
J
7:22James AzarHOST
All right, so let's move to our third story this morning.
J
7:25James AzarHOST
And our third deep dive attackers are actively exploiting the vulnerability in WSO2 products, specifically the WSO2 identity server and API manager.
J
7:34James AzarHOST
They're doing that to gain full administrative access to enterprise middleware environments.
Cyber Mornings Daily - September 16th, 2026
S
2:15speaker_0HOST
Let's start with the enterprise gatekeeper.
S
2:17speaker_0HOST
We have a critical vulnerability in the WSO2 API manager.
S
2:22speaker_1HOST
Oh, this one's just massive.
S
2:24speaker_0HOST
Huge.
S
2:56speaker_0HOST
Now, we know this is a failure of trust verification involving JWTs, so JSON Web Tokens, but I want to dig into the actual mechanism here.
S
3:03speaker_1HOST
Sure, let's get into it.
S
3:04speaker_0HOST
How does a system like WSO2 fundamentally fail to verify a token? What goes wrong?
S
3:10speaker_1HOST
Well, to understand the failure, you really have to look at how a GWT is constructed in the first place, right? Okay.
P
Unknown podcast
2026-09-16: Cisco discloses a critical zero-day in Secure Email Gateway already exploited in the wild with
Sep 16 · 6 Mentions
C
0:03CarolinaHOST
Cisco discloses a critical zero day in secure email gateway already exploited in the wild with root level command execution.
C
0:10CarolinaHOST
Microsoft issues emergency patches after September's 900 and 74 CVE, or Common Vulnerabilities and Exposures, Update broke remote desktop services and Hyper-V. WSO2 API manager JWT bypass vulnerability now under active exploitation with forged admin tokens targeting enterprise APIs.
C
0:30CarolinaHOST
Here's the full breakdown of today's top security stories.
C
0:33CarolinaHOST
Cyber threat brief, September 16, 2026.
C
1:59CarolinaHOST
CIS a KEV due date is September 17.
C
2:02CarolinaHOST
CyberScope.
C
2:04CarolinaHOST
WSO2 a PI, manager JWT bypass under active exploitation, CVE2026-5430.
C
2:09CarolinaHOST
Watch tower observed active exploitation of CVE2026-5430.
Cyber Security News for September 16 2026 - Daily DefSec Brief
J
0:00Jerry BellHOST
If you run WSO2's API Gateway, today's the day to get that 5-month-old patch off the risk register and onto the system.
J
0:07Jerry BellHOST
Happy Hump Day! This is the Daily DevSec Brief for Wednesday, September 16th, 2026.
J
0:12Jerry BellHOST
1.
J
0:13Jerry BellHOST
Anyone who can reach a WSO2 API Gateway can sign a token with an algorithm the product doesn't support and the Gateway validates it and hands back Administrator.
J
0:23Jerry BellHOST
Watchtower caught forged admin tokens arriving at its honeypots over the weekend, and the fix has been on WSO2's website since the first week of May.
J
0:33Jerry BellHOST
Apply the update level for your version, then rotate every consumer key and secret on the gateway.
J
0:38Jerry BellHOST
Two, somebody on an adjacent network with basic privileges on a Pixel phone can escalate through a logic error in the cellular modem with no user interaction and Google says there are indications it's under limited targeted exploitation.
J
4:03Jerry BellHOST
Alert on that certificate and on port 7443 with a self-signed cert.
'Digitizing Government. AI Agents and Secure Interoperability' by Fernando Arditti, Vice President and General Manager, LATAM, WSO2
L
0:00Lorena RuizNARRATOR
Welcome to the Mexico Business Now Podcast, your ultimate source for insights and trends shaping the Mexican business landscape.
L
0:09Lorena RuizNARRATOR
The following expert contributor article of the AI cloud and data industry is Digitizing Government: AI Agents and Secure Interoperability by Fernando Arditi, Vice President and General Manager, LATAM, WSO2.
L
0:25Lorena RuizNARRATOR
Don't forget to follow us, turn on the notifications bell, and leave a five-star rating and a review on this podcast.
L
0:32Lorena RuizNARRATOR
Mexico's digital government transformation is no longer a future ambition.
How to Govern AI in Production With WSO2 AI Gateway
A
1:21Artificial IntelligenceNARRATOR
We needed guardrails.
A
1:23Artificial IntelligenceNARRATOR
Around this time, our team started evaluating the WSO2 API platform, specifically its AI gateway, as a unified control layer for all our AI traffic.
A
1:33Artificial IntelligenceNARRATOR
I was skeptical at first.
A
1:35Artificial IntelligenceNARRATOR
Another vendor promising to solve AI governance with a single dashboard? I'd heard that pitch before.
A
1:41Artificial IntelligenceNARRATOR
But the more I dug in, the more it clicked.
A
1:44Artificial IntelligenceNARRATOR
WSO2's approach wasn't just about bolting a filter onto your LLM calls.
A
1:49Artificial IntelligenceNARRATOR
It was about treating AI traffic the same way you'd treat any critical enterprise API.
A
1:54Artificial IntelligenceNARRATOR
With governance, observability, lifecycle management, and policy enforcement baked in from the start.