CISO Insights: Voices in Cybersecurity

The 2026 DBIR Breakdown: Shadow AI, Pretexting, and the Rise of Vulnerabilities

43 min · 20. maj 2026
episode The 2026 DBIR Breakdown: Shadow AI, Pretexting, and the Rise of Vulnerabilities cover

Beskrivelse

The 2026 Data Breach Investigations Report reveals a rapidly shifting threat landscape where the exploitation of vulnerabilities has officially overtaken credential abuse as the top initial access vector. Alongside this shift, defenders are battling the explosion of "Shadow AI" data leaks and sophisticated, synchronous "pretexting" attacks that bypass traditional email-centric security training. Despite these advanced AI-driven threats, the report emphasizes that surviving the modern cyber battlefield requires a refinement of cybersecurity fundamentals—like patch management and access control—rather than a complete revolution. https://cisomarketplace.com/blog/verizon-dbir-2026-ciso-guide-vulnerability-exploitation-credential-theft [https://cisomarketplace.com/blog/verizon-dbir-2026-ciso-guide-vulnerability-exploitation-credential-theft] 2026 Verizon DBIR [https://www.verizon.com/business/resources/reports/dbir/?CMP=OOH_SMB_OTH_22222_MC_20200501_NA_NM20200079_00001]   Sponsors: www.breached.company [http://www.breached.company] www.cisomarketplace.com [http://www.cisomarketplace.com]

Kommentarer

0

Vær den første til at kommentere

Tilmeld dig nu og bliv en del af CISO Insights: Voices in Cybersecurity-fællesskabet!

Kom i gang

1 måned kun 9 kr.

Derefter 99 kr. / måned · Opsig når som helst.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

Alle episoder

477 episoder

episode Zero Trust for AI Agents cover

Zero Trust for AI Agents

As autonomous AI models accelerate the speed of cyber threats, traditional security perimeters are failing, requiring organizations to adopt a Zero Trust architecture specifically designed for agentic systems. This framework adapts core Zero Trust principles to address novel vulnerabilities—such as prompt injection, tool hijacking, and memory poisoning—by enforcing strict identity-based isolation and shifting from traditional "least privilege" to "least agency". By implementing hard cryptographic barriers, automated incident response, and continuous behavioral monitoring, organizations can effectively contain an attacker's blast radius and operate securely even when a breach inevitably occurs.   Claude Zero Trust PDF [https://cdn.prod.website-files.com/6889473510b50328dbb70ae6/6a1611a04085d7cd3dadc924_Claude-eBook-Zero-Trust-for-AI-Agents-05182026.pdf]   Sponsors https://cisomarketplace.services/engagements/claude-cybersecurity-consulting [https://cisomarketplace.services/engagements/claude-cybersecurity-consulting] https://cisomarketplace.services/ai-services [https://cisomarketplace.services/ai-services] https://cisomarketplace.services/program [https://cisomarketplace.services/program]

I går52 min
episode The Dark Side of the Pitch: Securing the 2026 World Cup cover

The Dark Side of the Pitch: Securing the 2026 World Cup

The 2026 FIFA World Cup presents a massive global stage, but its unmatched visibility is already attracting a complex web of physical, digital, and geopolitical security threats across the US, Mexico, and Canada. In this episode, we break down how host nations are preparing for vastly different physical risks, ranging from transnational organized crime in Mexico to violent extremists targeting fan zones during the US 250th Independence Day celebrations. We also dive into the digital battleground, exploring how cybercriminals are using artificial intelligence to scale ticketing fraud, and how state-sponsored threat groups from Russia, China, and Iran are exploiting the tournament for intelligence gathering and disruptive cyberattacks. https://www.recordedfuture.com/research/2026-fifa-world-cup-threats [https://www.recordedfuture.com/research/2026-fifa-world-cup-threats] https://www.recordedfuture.com/blog/2026-fifa-world-cup-cyber-physical-threats-security-guide [https://www.recordedfuture.com/blog/2026-fifa-world-cup-cyber-physical-threats-security-guide]   Sponsors www.breached.company [http://www.breached.company] www.myprivacy.blog [http://www.myprivacy.blog]

I går47 min
episode The Tale of Two Claudes: Unpacking Fable 5 and Mythos 5 cover

The Tale of Two Claudes: Unpacking Fable 5 and Mythos 5

In this episode, we dive into Anthropic's dual-release of Claude Fable 5 and Mythos 5, two highly capable AI models built from the exact same architecture but designed for vastly different worlds. We explore how Fable 5 protects the general public with novel cyber and biological fallbacks, alongside invisible safeguards that quietly thwart competing frontier AI development. Finally, we unpack the raw, unrestricted power of Mythos 5, detailing its exclusive use by vetted cyberdefenders and researchers through Project Glasswing to secure critical infrastructure.   https://www.anthropic.com/news/claude-fable-5-mythos-5 [https://www.anthropic.com/news/claude-fable-5-mythos-5] System Card: https://www-cdn.anthropic.com/d00db56fa754a1b115b6dd7cb2e3c342ee809620.pdf [https://www-cdn.anthropic.com/d00db56fa754a1b115b6dd7cb2e3c342ee809620.pdf]   Sponsor: https://cisomarketplace.services/program [https://cisomarketplace.services/program] https://cisomarketplace.services/ai-services [https://cisomarketplace.services/ai-services] https://cisomarketplace.services/engagements/claude-cybersecurity-consulting [https://cisomarketplace.services/engagements/claude-cybersecurity-consulting]

10. juni 202642 min
episode Continuous Defense: The AI Security Department for the Mid-Market cover

Continuous Defense: The AI Security Department for the Mid-Market

In a world where software ships daily and attackers automate their methods, traditional point-in-time security assessments like annual pentests leave mid-market organizations blind for most of the year. This episode explores the transition to a continuous, AI-augmented security model built on six interconnected pillars—ranging from automated compliance and incident response to a self-healing DevSecOps pipeline. Discover how human operators maintain absolute control over the entire ecosystem through a centralized "Operator Seat," ensuring that while security is highly automated, it is never unattended.   https://cisomarketplace.services/program [https://cisomarketplace.services/program] https://cisomarketplace.services/ai-services [https://cisomarketplace.services/ai-services]

8. juni 202633 min
episode Zero Theater Sourcing: The Hidden Math of Cyber Procurement cover

Zero Theater Sourcing: The Hidden Math of Cyber Procurement

This podcast explores how the CISO Marketplace streamlines vendor sourcing for security leaders by eliminating repetitive "discovery theater". It dives into how organizations can use ten free total cost of ownership (TCO) and sizing tools to uncover hidden technology costs, such as compounding carrier waste, unbudgeted cloud egress fees, and the true staffing requirements for a 24/7 SOC. Listeners will also learn how leveraging vendor-agnostic, CISSP-credentialed engineers can help them translate their exact needs into actionable RFP specifications and negotiate better contracts. https://sourcing.cisomarketplace.com/tools/sase-readiness [https://sourcing.cisomarketplace.com/tools/sase-readiness] https://sourcing.cisomarketplace.com/tools/ucaas-tco [https://sourcing.cisomarketplace.com/tools/ucaas-tco] https://sourcing.cisomarketplace.com/tools/firewall-sizing [https://sourcing.cisomarketplace.com/tools/firewall-sizing] https://sourcing.cisomarketplace.com/tools/sdwan-vs-mpls [https://sourcing.cisomarketplace.com/tools/sdwan-vs-mpls] https://sourcing.cisomarketplace.com/tools/soc-build-vs-buy [https://sourcing.cisomarketplace.com/tools/soc-build-vs-buy] https://sourcing.cisomarketplace.com/tools/endpoint-planner [https://sourcing.cisomarketplace.com/tools/endpoint-planner] https://sourcing.cisomarketplace.com/tools/cloud-egress-cost [https://sourcing.cisomarketplace.com/tools/cloud-egress-cost] https://sourcing.cisomarketplace.com/tools/mobility-audit [https://sourcing.cisomarketplace.com/tools/mobility-audit] https://sourcing.cisomarketplace.com/tools/iot-risk-surface [https://sourcing.cisomarketplace.com/tools/iot-risk-surface] https://sourcing.cisomarketplace.com/tools/iam-zero-trust-tco [https://sourcing.cisomarketplace.com/tools/iam-zero-trust-tco]

7. juni 202623 min