The Cyber Threat Perspective
The Cyber Threat Perspective
The Cyber Threat Perspective·Jul 31, 2026·22m·Episode #190

Episode 189 | OWASP Top 10 Part 4: Cryptographic Failures

Show notes

Most cryptographic findings on your vulnerability report will never be exploited by a real attacker. So why do they keep showing up — and why should you still fix them?

In this episode of the Cyber Threat Perspective, Brad Causey and Jordan Natter break down OWASP Top 10 A04: Cryptographic Failures — the entry they openly call their least favorite on the list. They explain why SWEET32, BEAST, and the other scary-sounding named TLS vulnerabilities almost never translate into real-world compromise, why platforms like Security Scorecard and BitSight inflate their severity anyway, and where genuine cryptographic risk actually lives.

Jordan also walks through a real penetration test finding: a JSON Web Token signed with HS256, an exposed configuration backup sitting on the web server, and the signing secret that turned a standard user into an administrator.

In this episode:

- Why A04 dropped on the OWASP Top 10 without becoming less important
- The difference between exploitable risk, hygiene risk, and brand reputational risk
- An honest take on Security Scorecard and BitSight scores — what they measure, what they miss, and why a perfect score can coexist with a weak password policy and no MFA
- The two halves of A04: data in transit (TLS/HTTPS, integrity, tampering) and data at rest (secure storage of credentials, PII, and payment data)
- What a JWT actually is, and why pen testers love pulling them apart
- Real pen test story: exposed config backup → leaked JWT secret → signature tampering → privilege escalation to admin
- Broken server-side signature validation and other improperly implemented cryptography
- Why MD5 and SHA-1 still show up for password storage 20 years too late — and what to use instead (Argon2, scrypt, bcrypt)
- HSTS, secure renegotiation, and certificate expiration as A04 subcategories
- The coffee shop scenario: the full chain of conditions required to exploit SWEET32 — including roughly 250 GB of captured traffic — and why no one has ever documented it happening in the wild
- Why a decade-plus-old vulnerability in your environment says more about your vulnerability management program than about your crypto
- Quantum computing: how today's theoretical attacks may not stay theoretical

The takeaway: classify your data, choose modern algorithms, retire deprecated protocols, and keep a functioning vulnerability management program. Not because a threat actor is sitting in your local coffee shop waiting to derive your session key — but because leaving decade-old findings in place is a signal about everything else you might be missing.

Next up: OWASP A05, which Brad promises is way cooler than A04.

Blog: https://securit360.com/blog/
Podcast: https://securit360.buzzsprout.com/
YouTube: https://www.youtube.com/@SecurIT360
Contact: https://securit360.com/contact/

Have a topic you want us to cover? Send it our way.

Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov

Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com

Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.