Crestvale Newsroom

ServiceNow bug exposed customer instance data online

6 min · 11. juni 2026
episode ServiceNow bug exposed customer instance data online cover

Description

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A ServiceNow vulnerability exposed how quickly SaaS platforms can become part of your attack surface, while new federal guidance is shrinking vulnerability response windows to just three days. This episode breaks down what the ServiceNow incident means in practice, why CISA's seventy two hour remediation expectation is a major shift, and how AI agents are quietly expanding identity risk inside most organizations. The common thread is speed and visibility. Teams are being forced to make faster decisions with less margin for error, while managing identities and data they often cannot fully see. We also cover Cyera's major funding round and what it signals about data security becoming the control layer for AI, along with key updates from Microsoft, Fortinet, and others. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Comments

0

Be the first to comment

Sign up now and become a member of the Crestvale Newsroom community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

177 episodes

episode wp2shell pre-auth RCE: WordPress 7.0.2 out artwork

wp2shell pre-auth RCE: WordPress 7.0.2 out

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A forced WordPress update, agentic browser risks, and a shift in supply chain attacks all point to the same problem: trust is being exploited faster than teams can validate it. For security and IT leaders, this is a change in where risk lives. Core platforms can be compromised without credentials, browser extensions can act with user privileges, and dependency updates can carry malicious code straight into CI. At the same time, ransomware operators are prioritizing identity access over traditional exploits. The result is a compressed window between exposure and impact. We also cover Microsoft's view on npm trust path attacks, new risks in AI browser agents, and why identity is again the primary entry point for ransomware. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Yesterday6 min
episode DigiCert breach linked to code-signing theft artwork

DigiCert breach linked to code-signing theft

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A breach tied to DigiCert has put code signing certificates in attacker hands, turning a core trust signal into a potential attack vector. At the same time, ransomware is now disrupting real world operations, and vendor risk is showing up in places many teams assume are safe. This episode breaks down why trust in signed software can no longer be assumed, how ransomware is shifting toward direct revenue disruption, and why identity and secrets platforms need deeper scrutiny. The common thread is control. Who has it, how it is verified, and where it quietly fails. We also cover CrowdStrike's move to absorb XM Cyber's technology, a ransomware driven production shutdown at Fairlife, and new concerns around Passwork's origins. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

18. juli 20265 min
episode Microsoft: AI agents need first-class identities artwork

Microsoft: AI agents need first-class identities

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] AI agents are no longer just assistants. They are becoming active participants inside systems, with the ability to take actions across tools and services. That shift is forcing a rethink of identity, access, and control. For security and IT leaders, this changes the threat model. Agents introduce new forms of privilege escalation, cross-system risk, and audit gaps that traditional identity frameworks were not built to handle. At the same time, regulatory pressure and real-world breaches are reinforcing that weak identity controls remain the easiest path for attackers. This episode also covers the CMMC audit pause and why liability remains, new developments tied to Scattered Spider, and Google's move into AI-driven app execution. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

17. juli 20266 min
episode CISA: SharePoint exploits active, patching lags artwork

CISA: SharePoint exploits active, patching lags

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] Active SharePoint exploitation with delayed patches is exposing a growing gap between vulnerability discovery and real world remediation. At the same time, identity is expanding beyond humans, and patching volume is accelerating beyond what most teams can handle. This episode breaks down why these shifts matter now. If attackers are exploiting before fixes arrive, your defenses have to operate in that window. And as machine and agent identities grow, traditional access control models are starting to fail. The result is a security environment that is faster, more complex, and less forgiving of delay. We also cover new funding around identity control planes, a record-breaking patch cycle from Microsoft, and a major milestone in post-quantum cryptography standardization. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

16. juli 20265 min
episode PBAC turns authorization into AI agent control artwork

PBAC turns authorization into AI agent control

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] Authorization is moving from a background function to the control plane for AI systems. As agents take on more actions inside production environments, real time policy enforcement is becoming the difference between safe scale and silent data exposure. For security and IT leaders, this shift forces a rethink of how access is defined and enforced. Identity alone is no longer enough. You need fast, centralized authorization that can evaluate context across humans, services, and AI agents without slowing systems down. We also cover router compromises tied to weak configurations, lessons from CISA's GitHub secrets leak, and why Cribl is betting on detection engineering as the next battleground. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

15. juli 20265 min