Crestvale Newsroom

Verizon DBIR: vulns now fastest path to breach

6 min · 21. maj 2026
episode Verizon DBIR: vulns now fastest path to breach cover

Description

Vulnerability exploitation has now become the fastest way attackers break into organizations, overtaking stolen credentials for the first time in nearly two decades. This episode unpacks what changed, why patching discipline is slipping, and how third‑party exposure is amplifying risk. For firm leaders, the message is direct. Slow remediation timelines and outdated workflows now create predictable openings for attackers. We explain what this shift means for professional services, why regulators are pausing some bank cyber exams, and how AI‑driven reconnaissance is pushing both firms and supervisors to update their assumptions. We also cover new joint threat‑sharing among major carriers, the AI tools gaining real traction inside law firms, and several notable moves across audit and software development workflows. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Comments

0

Be the first to comment

Sign up now and become a member of the Crestvale Newsroom community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

151 episodes

episode GentleKiller uses BYOVD to kill EDRs artwork

GentleKiller uses BYOVD to kill EDRs

Ransomware operators are no longer trying to evade detection. They are disabling endpoint defenses at the kernel level before attacks even begin, changing how security teams need to think about control and visibility. This shift matters because many security strategies assume tools will stay active long enough to respond. At the same time, law enforcement is exposing how ransomware depends on large-scale identity fraud to turn crypto into cash. Together, these trends point to two pressure points: kernel access and identity assurance. In this episode, we cover the GentleKiller EDR takedown approach, the AudiA6 laundering network, Malaysia's push toward national digital identity, and a Bluetooth flaw that turns everyday devices into potential listening points. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

22. juni 20265 min
episode Gravity SMTP flaw leaks WordPress API keys artwork

Gravity SMTP flaw leaks WordPress API keys

A WordPress plugin flaw is exposing API keys, and attackers are already using it to move beyond simple exploits into account takeover and lateral access. This is not just a CMS issue. It is a reminder that secrets management failures can quickly become identity incidents. For security and IT leaders, the takeaway is immediate. Email infrastructure, API keys, and integrations now sit directly on the identity boundary. At the same time, vendor risk and AI cost control are becoming operational pressures that require proactive planning, not reactive fixes. This episode also covers VMware pricing fallout, a claimed breach of a major water utility, and growing limits on enterprise AI usage. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Yesterday5 min
episode Klue breach weaponized OAuth tokens into CRM exfiltration artwork

Klue breach weaponized OAuth tokens into CRM exfiltration

A breach at Klue shows how attackers are shifting away from breaking core systems and instead exploiting trusted integrations. By stealing OAuth tokens, they turned normal API access into a high-speed data exfiltration path inside Salesforce environments. This matters because most organizations do not tightly manage their integrations, token lifecycles, or non-human identities. At the same time, a critical Splunk vulnerability is already being exploited, and AI is now acting directly inside financial systems like QuickBooks. These changes are expanding the attack surface in ways traditional controls are not designed to handle. Also covered: a major law enforcement operation disrupting SocGholish infrastructure, new warnings on FortiGate exposure, and why phishing is becoming more precise even as volume drops. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

20. juni 20266 min
episode Cisco patches critical ISE command-exec flaw artwork

Cisco patches critical ISE command-exec flaw

Cisco's latest ISE vulnerability is a reminder that when identity infrastructure breaks, everything behind it is exposed. At the same time, CISA is redefining how quickly organizations are expected to respond to real-world threats, with patch timelines shrinking to days when exploitation is active. This episode breaks down what it means when your network access control layer becomes a pivot point, and why risk-based patching is quickly becoming the standard across both government and enterprise environments. There is also a closer look at how Google's new agent discovery standard could shape machine identity and trust, and why ransomware groups are scaling faster with new incentive models. We also cover Teams-based command and control abuse, third-party data exposure, and shifts in vendor risk. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

19. juni 20266 min
episode FortiBleed breaches 30k–73k Fortinet devices artwork

FortiBleed breaches 30k–73k Fortinet devices

Credential reuse just turned tens of thousands of edge devices into an attack platform. This episode breaks down how Fortinet systems were accessed without exploits, and why identity at the perimeter is now the real control plane. For security and IT leaders, the pattern is clear. Weak authentication at internet-facing systems is no longer a gap, it is a direct entry point. At the same time, AI platforms are shifting enforcement into runtime, where actions can be stopped before they execute. The combination of human and non-human identity risk is reshaping how security needs to be designed. We also cover Databricks moving AI governance into execution, Tenet Security's approach to preempting agent behavior, regulatory action in Australia tying poor security to financial penalties, and key signals from npm, CISA, and emerging AI-driven attacks. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

18. juni 20266 min