Crestvale Newsroom

ACSC warns FortiBleed: rotate creds, enforce MFA

6 min · 30 de jun de 2026
Portada del episodio ACSC warns FortiBleed: rotate creds, enforce MFA

Descripción

Credential-based security is breaking in multiple directions at once. Old passwords are being reused to breach networks, unpatched ERP systems are getting exploited in the wild, and attackers are shifting toward token theft that bypasses traditional login defenses entirely. For security and IT leaders, this is a shift from protecting logins to continuously validating identity across sessions, systems, and now AI-driven actors. The common thread is clear: identity is the new control plane, and gaps in credential hygiene, patching, and token visibility are turning into real-world incidents. This episode also covers a major Oracle EBS vulnerability under active exploitation, the rise of device-code phishing attacks targeting Microsoft environments, and new funding aimed at rebuilding IAM for AI agents. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de Crestvale Newsroom!

Empezar

2 meses por 1 €

Después 4,99 € / mes · Cancela cuando quieras.

  • Podcasts exclusivos
  • 20 horas de audiolibros / mes
  • Podcast gratuitos

Todos los episodios

158 episodios

Portada del episodio ACSC warns FortiBleed: rotate creds, enforce MFA

ACSC warns FortiBleed: rotate creds, enforce MFA

Credential-based security is breaking in multiple directions at once. Old passwords are being reused to breach networks, unpatched ERP systems are getting exploited in the wild, and attackers are shifting toward token theft that bypasses traditional login defenses entirely. For security and IT leaders, this is a shift from protecting logins to continuously validating identity across sessions, systems, and now AI-driven actors. The common thread is clear: identity is the new control plane, and gaps in credential hygiene, patching, and token visibility are turning into real-world incidents. This episode also covers a major Oracle EBS vulnerability under active exploitation, the rise of device-code phishing attacks targeting Microsoft environments, and new funding aimed at rebuilding IAM for AI agents. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

30 de jun de 20266 min
Portada del episodio UK banks pilot consent-led reusable digital ID

UK banks pilot consent-led reusable digital ID

Banks are moving into identity, and that could reshape how authentication and onboarding work across the digital economy. A new UK pilot shows how bank-verified identity attributes may become reusable across services, shifting control away from fragmented KYC systems. For security and IT leaders, this signals a change in where trust lives. Identity may consolidate around institutions that already hold strong signals, while access to advanced AI tools becomes uneven and employee behavior continues to outpace policy. The result is a more fragmented, less controllable environment that requires new approaches to integration, governance, and visibility. This episode also covers OpenAI's restricted GPT-5.6 launch, the rise of shadow AI in the workplace, and a new browser-based surveillance technique using WebRTC. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Ayer6 min
Portada del episodio Bucket hijacking silently reroutes cloud audit logs

Bucket hijacking silently reroutes cloud audit logs

A new cloud attack pattern is quietly undermining one of the most trusted parts of your security stack: logging. By deleting and recreating storage buckets, attackers can reroute audit logs without triggering alerts, leaving teams blind while data continues to flow. This matters because detection, response, and forensics all depend on trustworthy telemetry. At the same time, access to advanced AI security models is becoming restricted by governments, creating uneven capabilities across organizations. Add in a breach that disrupted core insurance risk calculations, and the pattern is clear: control over data and tools is becoming a primary risk surface. We also cover consolidation in industrial security, AI orchestration trends, and the rise of automated exploit discovery. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

28 de jun de 20265 min
Portada del episodio Amazon Q repo bug steals AWS creds

Amazon Q repo bug steals AWS creds

AI developer tools and modern supply chains are introducing new paths to credential theft and account compromise. Today's episode focuses on how routine actions like opening a repository or running a build can now trigger silent execution and expose sensitive access. For security and IT leaders, the shift is structural. Trust boundaries are moving closer to developer workflows, build systems, and browser sessions. That means traditional controls like MFA, dependency scanning, and perimeter defenses are no longer enough on their own. The focus needs to move toward execution paths, session integrity, and tighter control over tooling behavior. We also cover a new coordinated effort to secure open source dependencies before they are exploited, along with emerging phishing techniques that render MFA ineffective. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

27 de jun de 20266 min
Portada del episodio Five Eyes: frontier AI cyber risk soon

Five Eyes: frontier AI cyber risk soon

Frontier AI is collapsing the time between vulnerability discovery and exploitation, and security teams are running out of buffer. This episode breaks down the latest warning from Five Eyes cyber agencies and what it means for how quickly organizations need to act. The shift is not about new tools. It is about speed, identity control, and treating cyber risk as a core business function. When attackers can automate discovery and movement, delays in patching and weak access controls become immediate exposure. The episode also explains why credential theft remains the primary entry point for most attacks and how that shapes defensive priorities. We also cover Operation Endgame disrupting infostealer infrastructure, a Cisco SD WAN zero day with control plane impact, and new federal guidance pushing SASE under TIC 3.0. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

25 de jun de 20265 min