<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:podcast="https://podcastindex.org/namespace/1.0">
    <channel>
        <generator>RedCircle VERIFY_TOKEN_6b7e1fac-3398-4e95-a7ae-6b771a6ea3e3  -- Rendered At Tue, 15 Sep 2026 13:46:39 &#43;0000</generator>
        <title>Reflections: Web Security Podcast</title>
        <link>https://redcircle.com/shows/reflections-web-security-podcast</link>
        <language>en-US</language>
        <copyright>All rights reserved.</copyright>
        <itunes:author>Reflectiz</itunes:author>
        <itunes:summary>Reflections: The Web Security Podcast is produced by Reflectiz, the world&#39;s leading AI-powered web exposure platform. Built by world renowned ethical hackers, Reflectiz continuously monitors everything executing on your live website - detecting the threats that firewalls, WAFs, and traditional scanners were never designed to see.

Each episode, we sit down with security practitioners, CISOs, privacy officers, and compliance experts to examine the threats reshaping the modern web and what organizations can actually do about them.

What We Cover:

Magecart attacks, web skimming, and checkout page security
Third-party script risk and unauthorised data exfiltration
PCI DSS 4.0.1 compliance for merchants and payment providers
GDPR, CCPA, and HIPAA enforcement at the client-side layer
AI-generated web attacks and evolving supply-chain compromises
Fourth-party risk and what lives beyond your engineering control
Real breach post-mortems and actionable takeaways for security teams


Who It&#39;s For:

Reflections is essential listening for CISOs, AppSec engineers, privacy and compliance managers, and security-conscious leaders across financial services, e-commerce, healthcare, and the public sector.

Subscribe, reflect, and stay ahead of the web threats your current stack can&#39;t see.

Keywords: web security podcast, Reflections Reflectiz, client-side security podcast, Magecart podcast, third-party script risk, PCI DSS 4.0 compliance podcast, web supply chain security, CISO podcast, cybersecurity podcast, web exposure, application security, website security podcast</itunes:summary>
        <podcast:guid>6b7e1fac-3398-4e95-a7ae-6b771a6ea3e3</podcast:guid>
        
        <description><![CDATA[<p>Reflections: The Web Security Podcast is produced by Reflectiz, the world&#39;s leading AI-powered web exposure platform. Built by world renowned ethical hackers, Reflectiz continuously monitors everything executing on your live website - detecting the threats that firewalls, WAFs, and traditional scanners were never designed to see.</p><p>Each episode, we sit down with security practitioners, CISOs, privacy officers, and compliance experts to examine the threats reshaping the modern web and what organizations can actually do about them.</p><p><strong>What We Cover:</strong></p><ul><li>Magecart attacks, web skimming, and checkout page security</li><li>Third-party script risk and unauthorised data exfiltration</li><li>PCI DSS 4.0.1 compliance for merchants and payment providers</li><li>GDPR, CCPA, and HIPAA enforcement at the client-side layer</li><li>AI-generated web attacks and evolving supply-chain compromises</li><li>Fourth-party risk and what lives beyond your engineering control</li><li>Real breach post-mortems and actionable takeaways for security teams</li></ul><p><br></p><p><strong>Who It&#39;s For:</strong></p><p>Reflections is essential listening for CISOs, AppSec engineers, privacy and compliance managers, and security-conscious leaders across financial services, e-commerce, healthcare, and the public sector.</p><p>Subscribe, reflect, and stay ahead of the web threats your current stack can&#39;t see.</p><p><strong>Keywords:</strong> web security podcast, Reflections Reflectiz, client-side security podcast, Magecart podcast, third-party script risk, PCI DSS 4.0 compliance podcast, web supply chain security, CISO podcast, cybersecurity podcast, web exposure, application security, website security podcast</p>]]></description>
        
        <itunes:type>episodic</itunes:type>
        <podcast:locked>no</podcast:locked>
        <itunes:owner>
            <itunes:name>Reflectiz</itunes:name>
            <itunes:email>marketing@reflectiz.com</itunes:email>
        </itunes:owner>
        
        <itunes:image href="https://media.redcircle.com/images/2026/6/24/7/a8a90824-50d0-4a99-b740-3da56c356059_______________5_.jpg"/>
        
        
        
            
            <itunes:category text="Technology" />

            

        
        

        
        <itunes:explicit>false</itunes:explicit>
        
        
        
        
        
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>PCI DSS 4.0: Who Really Owns Payment Security Risk?</itunes:title>
                <title>PCI DSS 4.0: Who Really Owns Payment Security Risk?</title>

                <itunes:episode>3</itunes:episode>
                
                <itunes:author>Reflectiz</itunes:author>
                <itunes:summary>When a payment page breach happens, who is actually accountable: the merchant, the processor, the PSP, or the vendor whose script got compromised? This episode brings together security leaders from across the payment chain to answer that question.



What&#39;s covered:

Where PCI DSS 4.0 succeeds and where it leaves gaps in payment security accountability.

How requirements 6.4.3 and 11.6.1 apply to real third-party script monitoring.

Why client-side vulnerabilities create cardholder data exposure that server-side controls miss.

How global retail, e-commerce, and payment processing teams are dividing payment security responsibility in practice.

What compliance teams should do differently once checking the PCI box is not enough.



Speakers: Una Dillon, Regional Director Europe, PCI Security Standards Council; Deepak Kumar, CISO, APEXX Global; Pete Chenery, Global Head of Cyber Security, Naked Wines; Mark Barry, Senior Security Operations Manager, Domino&#39;s Pizza; Leor Eliashiv, UK Regional Manager, Reflectiz.



Key terms: PCI DSS 4.0, payment security, client-side security, cardholder data protection, third-party risk, Magecart, checkout page security.



Explore Reflectiz&#39;s payment security resources and PCI compliance guides at reflectiz.com/demo. A good next step if you&#39;re mapping out where your own payment risk ownership breaks down.</itunes:summary>
                <description><![CDATA[<p>When a payment page breach happens, who is actually accountable: the merchant, the processor, the PSP, or the vendor whose script got compromised? This episode brings together security leaders from across the payment chain to answer that question.</p><p><br></p><p>What&#39;s covered:</p><p>Where PCI DSS 4.0 succeeds and where it leaves gaps in payment security accountability.</p><p>How requirements 6.4.3 and 11.6.1 apply to real third-party script monitoring.</p><p>Why client-side vulnerabilities create cardholder data exposure that server-side controls miss.</p><p>How global retail, e-commerce, and payment processing teams are dividing payment security responsibility in practice.</p><p>What compliance teams should do differently once checking the PCI box is not enough.</p><p><br></p><p>Speakers: Una Dillon, Regional Director Europe, PCI Security Standards Council; Deepak Kumar, CISO, APEXX Global; Pete Chenery, Global Head of Cyber Security, Naked Wines; Mark Barry, Senior Security Operations Manager, Domino&#39;s Pizza; Leor Eliashiv, UK Regional Manager, Reflectiz.</p><p><br></p><p>Key terms: PCI DSS 4.0, payment security, client-side security, cardholder data protection, third-party risk, Magecart, checkout page security.</p><p><br></p><p>Explore Reflectiz&#39;s payment security resources and PCI compliance guides at reflectiz.com/demo. A good next step if you&#39;re mapping out where your own payment risk ownership breaks down.</p>]]></description>
                <content:encoded>&lt;p&gt;When a payment page breach happens, who is actually accountable: the merchant, the processor, the PSP, or the vendor whose script got compromised? This episode brings together security leaders from across the payment chain to answer that question.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;What&amp;#39;s covered:&lt;/p&gt;&lt;p&gt;Where PCI DSS 4.0 succeeds and where it leaves gaps in payment security accountability.&lt;/p&gt;&lt;p&gt;How requirements 6.4.3 and 11.6.1 apply to real third-party script monitoring.&lt;/p&gt;&lt;p&gt;Why client-side vulnerabilities create cardholder data exposure that server-side controls miss.&lt;/p&gt;&lt;p&gt;How global retail, e-commerce, and payment processing teams are dividing payment security responsibility in practice.&lt;/p&gt;&lt;p&gt;What compliance teams should do differently once checking the PCI box is not enough.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Speakers: Una Dillon, Regional Director Europe, PCI Security Standards Council; Deepak Kumar, CISO, APEXX Global; Pete Chenery, Global Head of Cyber Security, Naked Wines; Mark Barry, Senior Security Operations Manager, Domino&amp;#39;s Pizza; Leor Eliashiv, UK Regional Manager, Reflectiz.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Key terms: PCI DSS 4.0, payment security, client-side security, cardholder data protection, third-party risk, Magecart, checkout page security.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Explore Reflectiz&amp;#39;s payment security resources and PCI compliance guides at reflectiz.com/demo. A good next step if you&amp;#39;re mapping out where your own payment risk ownership breaks down.&lt;/p&gt;</content:encoded>
                
                <enclosure length="50216124" type="audio/mpeg" url="https://audio3.redcircle.com/episodes/c97496bd-55a3-4740-a070-1d987fe2ac20/stream.mp3"/>
                
                <guid isPermaLink="false">50a49896-1b61-4cd5-8b3d-9b57acd799bf</guid>
                <link>https://www.reflectiz.com/learning-hub/live-panel-discussion-2026/</link>
                <pubDate>Thu, 23 Jul 2026 12:03:00 &#43;0000</pubDate>
                <itunes:duration>3138</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>Magecart Detection: Can AI Code Review Tools Catch It?</itunes:title>
                <title>Magecart Detection: Can AI Code Review Tools Catch It?</title>

                
                
                <itunes:author>Reflectiz</itunes:author>
                
                <description><![CDATA[<p>Can AI-powered code security tools like Claude Code Security catch a live Magecart attack? This episode puts that question to the test using a real-world Magecart campaign that compromised a payment processing system.</p><p><br></p><p>What&#39;s covered:</p><p>Why static code analysis tools miss client-side threats that exploit runtime behavior in third-party scripts.</p><p>What Claude Code Security and similar AI code review tools can and cannot detect.</p><p>How a real Magecart campaign evaded development-time security checks.</p><p>Why payment page protection needs runtime visibility that static analysis cannot provide.</p><p>How to combine static analysis and runtime monitoring in a defense-in-depth strategy.</p><p><br></p><p>Speakers: Elan Hershcovitz, VP R&amp;D, Reflectiz.</p><p><br></p><p>Key terms: Magecart, client-side security, runtime monitoring, static code analysis, third-party script risk, web supply chain security, payment page protection.</p><p><br></p><p>Download the CISO guide referenced in this episode at reflectiz.com/learning-hub/claude-code-security-guide. A useful companion if you&#39;re evaluating where AI code review fits in your security stack.</p>]]></description>
                <content:encoded>&lt;p&gt;Can AI-powered code security tools like Claude Code Security catch a live Magecart attack? This episode puts that question to the test using a real-world Magecart campaign that compromised a payment processing system.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;What&amp;#39;s covered:&lt;/p&gt;&lt;p&gt;Why static code analysis tools miss client-side threats that exploit runtime behavior in third-party scripts.&lt;/p&gt;&lt;p&gt;What Claude Code Security and similar AI code review tools can and cannot detect.&lt;/p&gt;&lt;p&gt;How a real Magecart campaign evaded development-time security checks.&lt;/p&gt;&lt;p&gt;Why payment page protection needs runtime visibility that static analysis cannot provide.&lt;/p&gt;&lt;p&gt;How to combine static analysis and runtime monitoring in a defense-in-depth strategy.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Speakers: Elan Hershcovitz, VP R&amp;amp;D, Reflectiz.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Key terms: Magecart, client-side security, runtime monitoring, static code analysis, third-party script risk, web supply chain security, payment page protection.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Download the CISO guide referenced in this episode at reflectiz.com/learning-hub/claude-code-security-guide. A useful companion if you&amp;#39;re evaluating where AI code review fits in your security stack.&lt;/p&gt;</content:encoded>
                
                <enclosure length="24580179" type="audio/mpeg" url="https://audio3.redcircle.com/episodes/de1c8492-7fd8-438c-898a-294f603bd5ad/stream.mp3"/>
                
                <guid isPermaLink="false">07cca2e8-6c73-4d87-8b71-479496848ddd</guid>
                <link>https://www.reflectiz.com/</link>
                <pubDate>Thu, 23 Jul 2026 12:02:23 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/13/7/938b22e7-df7d-43b6-8054-edd9461c3ddf_image__3_.jpg"/>
                <itunes:duration>1536</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
            <item>
                <itunes:episodeType>full</itunes:episodeType>
                <itunes:title>AI Supply Chain Attacks: The New Threat to Retail Security</itunes:title>
                <title>AI Supply Chain Attacks: The New Threat to Retail Security</title>

                
                
                <itunes:author>Reflectiz</itunes:author>
                
                <description><![CDATA[<p>Retailers are rolling out AI agents for procurement, inventory forecasting, and customer service, but few security teams have asked what happens when those agents get manipulated. This episode breaks down how attackers are already exploiting AI supply chains in retail.</p><p><br></p><p>What&#39;s covered:</p><p>How prompt injection lets attackers manipulate procurement AI systems without touching your codebase.</p><p>Why rogue suppliers can manipulate inventory forecasts through AI-driven procurement tools.</p><p>How attackers hijack trusted supplier identities to coordinate cartel-style attacks.</p><p>What it means when AI agents sit on payment pages and are trusted by default.</p><p>Practical steps for retail security teams to evaluate whether their AI systems are actually ready for this threat.</p><p><br></p><p>Speakers: Simon Arazi, VP Product, Reflectiz.</p><p><br></p><p>Key terms: client-side security, AI supply chain risk, third-party script risk, agentic AI security, payment page security, retail cybersecurity.</p><p><br></p><p>Watch the full webinar recording and explore Reflectiz&#39;s approach to AI-era retail security at reflectiz.com/demo. Worth a look if your team is rolling out AI procurement or forecasting tools without a clear security review process.</p>]]></description>
                <content:encoded>&lt;p&gt;Retailers are rolling out AI agents for procurement, inventory forecasting, and customer service, but few security teams have asked what happens when those agents get manipulated. This episode breaks down how attackers are already exploiting AI supply chains in retail.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;What&amp;#39;s covered:&lt;/p&gt;&lt;p&gt;How prompt injection lets attackers manipulate procurement AI systems without touching your codebase.&lt;/p&gt;&lt;p&gt;Why rogue suppliers can manipulate inventory forecasts through AI-driven procurement tools.&lt;/p&gt;&lt;p&gt;How attackers hijack trusted supplier identities to coordinate cartel-style attacks.&lt;/p&gt;&lt;p&gt;What it means when AI agents sit on payment pages and are trusted by default.&lt;/p&gt;&lt;p&gt;Practical steps for retail security teams to evaluate whether their AI systems are actually ready for this threat.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Speakers: Simon Arazi, VP Product, Reflectiz.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Key terms: client-side security, AI supply chain risk, third-party script risk, agentic AI security, payment page security, retail cybersecurity.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Watch the full webinar recording and explore Reflectiz&amp;#39;s approach to AI-era retail security at reflectiz.com/demo. Worth a look if your team is rolling out AI procurement or forecasting tools without a clear security review process.&lt;/p&gt;</content:encoded>
                
                <enclosure length="22176914" type="audio/mpeg" url="https://audio3.redcircle.com/episodes/24478ec4-44ac-4f27-9722-52aa1a7e8b25/stream.mp3"/>
                
                <guid isPermaLink="false">443102e6-e800-475f-b600-8b3e1751cc8c</guid>
                <link>https://www.reflectiz.com/</link>
                <pubDate>Thu, 23 Jul 2026 12:01:53 &#43;0000</pubDate>
                <itunes:image href="https://media.redcircle.com/images/2026/8/3/11/723bf3c7-a1da-400d-99a0-843a17d7fa5a_____________.jpg"/>
                <itunes:duration>1386</itunes:duration>
                
                
                <itunes:explicit>false</itunes:explicit>
                
            </item>
        
    </channel>
</rss>
