Crestvale Newsroom

Verizon DBIR: vulns now fastest path to breach

6 min · 21 de may de 2026
Portada del episodio Verizon DBIR: vulns now fastest path to breach

Descripción

Vulnerability exploitation has now become the fastest way attackers break into organizations, overtaking stolen credentials for the first time in nearly two decades. This episode unpacks what changed, why patching discipline is slipping, and how third‑party exposure is amplifying risk. For firm leaders, the message is direct. Slow remediation timelines and outdated workflows now create predictable openings for attackers. We explain what this shift means for professional services, why regulators are pausing some bank cyber exams, and how AI‑driven reconnaissance is pushing both firms and supervisors to update their assumptions. We also cover new joint threat‑sharing among major carriers, the AI tools gaining real traction inside law firms, and several notable moves across audit and software development workflows. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de Crestvale Newsroom!

Empezar

2 meses por 1 €

Después 4,99 € / mes · Cancela cuando quieras.

  • Podcasts exclusivos
  • 20 horas de audiolibros / mes
  • Podcast gratuitos

Todos los episodios

144 episodios

Portada del episodio Microsoft pulls 73 GitHub repos after malware

Microsoft pulls 73 GitHub repos after malware

A supply chain attack targeting developer tools forced Microsoft to remove dozens of GitHub repositories, highlighting a shift in where real risk now sits. This episode breaks down how attackers are moving closer to credentials through trusted workflows, and why AI development environments are becoming a high value target. For security and IT leaders, the implication is direct. Developer machines, repositories, and third party access paths now function as part of your identity perimeter. At the same time, passkeys are exposing operational gaps around recovery, and new research shows overreliance on AI can quietly degrade decision making across teams. We also cover a third party access lawsuit with cross client impact, shifts in AI economics, and growing geopolitical pressure on AI partnerships. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

15 de jun de 20266 min
Portada del episodio US export controls shut off Anthropic models

US export controls shut off Anthropic models

AI access is no longer just a product feature. It is becoming controlled infrastructure. In this episode, we break down how U.S. export controls forced Anthropic to shut down major models globally, and what that signals for any team relying on third-party AI. The shift has real consequences. Security workflows can stop overnight. Vendor risk now includes geopolitical decisions. And at the same time, critical vulnerabilities like the Splunk remote code execution flaw show how quickly your core systems can become liabilities if exposed. We also cover Wallarm's push into full visibility for AWS environments, and a new regulatory move as state attorneys general subpoena OpenAI over model behavior and data handling. Plus, key updates on cyber training, AI governance, and the changing shape of security teams. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Ayer6 min
Portada del episodio CISA orders Ivanti Sentry patch by Sunday

CISA orders Ivanti Sentry patch by Sunday

CISA just enforced a seventy two hour patch deadline for actively exploited infrastructure, and that single move signals a broader shift in how fast security teams are expected to operate. This episode breaks down what that means in practice, from Ivanti Sentry exposure to the growing expectation that internet-facing systems must be treated as compromised almost immediately. It also looks at how attackers are accelerating their own timelines, with zero-day exploitation in PeopleSoft leading directly to extortion, and npm-based worms stealing cloud and AI credentials before detection tools can respond. We also cover Google's legal push against AI-driven smishing networks and what it signals about the future of platform-led defense. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

13 de jun de 20266 min
Portada del episodio ServiceNow bug exposed customer instance data online

ServiceNow bug exposed customer instance data online

A ServiceNow vulnerability exposed how quickly SaaS platforms can become part of your attack surface, while new federal guidance is shrinking vulnerability response windows to just three days. This episode breaks down what the ServiceNow incident means in practice, why CISA's seventy two hour remediation expectation is a major shift, and how AI agents are quietly expanding identity risk inside most organizations. The common thread is speed and visibility. Teams are being forced to make faster decisions with less margin for error, while managing identities and data they often cannot fully see. We also cover Cyera's major funding round and what it signals about data security becoming the control layer for AI, along with key updates from Microsoft, Fortinet, and others. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

11 de jun de 20266 min