Crestvale Newsroom

Verizon DBIR: vulns now fastest path to breach

6 min · 21. touko 2026
jakson Verizon DBIR: vulns now fastest path to breach kansikuva

Kuvaus

Vulnerability exploitation has now become the fastest way attackers break into organizations, overtaking stolen credentials for the first time in nearly two decades. This episode unpacks what changed, why patching discipline is slipping, and how third‑party exposure is amplifying risk. For firm leaders, the message is direct. Slow remediation timelines and outdated workflows now create predictable openings for attackers. We explain what this shift means for professional services, why regulators are pausing some bank cyber exams, and how AI‑driven reconnaissance is pushing both firms and supervisors to update their assumptions. We also cover new joint threat‑sharing among major carriers, the AI tools gaining real traction inside law firms, and several notable moves across audit and software development workflows. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Kommentit

0

Ole ensimmäinen kommentoija

Rekisteröidy nyt ja liity Crestvale Newsroom-yhteisöön!

Aloita maksutta

14 vrk ilmainen kokeilu

Kokeilun jälkeen 7,99 € / kuukausi. · Peru milloin tahansa.

  • Podimon podcastit
  • 20 kuunteluaikaa / kuukausi
  • Lataa offline-käyttöön

Kaikki jaksot

145 jaksot

jakson NewCore raises $66M for AI agent IDs kansikuva

NewCore raises $66M for AI agent IDs

AI agents are rapidly becoming first-class actors inside enterprise environments, and identity systems are struggling to keep up. This episode looks at NewCore's $66 million bet on rebuilding identity for a world where agents outnumber employees, and why that shift is already underway. For security and IT leaders, this is not just a tooling change. It is a shift in what identity means. Unmanaged AI agents introduce invisible access, persistent permissions, and new attack paths. At the same time, moves like 1Password acquiring Apono show that the market is pivoting toward real-time access governance, not just credential storage. We also cover a critical Splunk vulnerability that demands immediate patching, and a major phishing network takedown that highlights how industrialized fraud now operates. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

16. kesä 20266 min
jakson Microsoft pulls 73 GitHub repos after malware kansikuva

Microsoft pulls 73 GitHub repos after malware

A supply chain attack targeting developer tools forced Microsoft to remove dozens of GitHub repositories, highlighting a shift in where real risk now sits. This episode breaks down how attackers are moving closer to credentials through trusted workflows, and why AI development environments are becoming a high value target. For security and IT leaders, the implication is direct. Developer machines, repositories, and third party access paths now function as part of your identity perimeter. At the same time, passkeys are exposing operational gaps around recovery, and new research shows overreliance on AI can quietly degrade decision making across teams. We also cover a third party access lawsuit with cross client impact, shifts in AI economics, and growing geopolitical pressure on AI partnerships. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Eilen6 min
jakson US export controls shut off Anthropic models kansikuva

US export controls shut off Anthropic models

AI access is no longer just a product feature. It is becoming controlled infrastructure. In this episode, we break down how U.S. export controls forced Anthropic to shut down major models globally, and what that signals for any team relying on third-party AI. The shift has real consequences. Security workflows can stop overnight. Vendor risk now includes geopolitical decisions. And at the same time, critical vulnerabilities like the Splunk remote code execution flaw show how quickly your core systems can become liabilities if exposed. We also cover Wallarm's push into full visibility for AWS environments, and a new regulatory move as state attorneys general subpoena OpenAI over model behavior and data handling. Plus, key updates on cyber training, AI governance, and the changing shape of security teams. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

14. kesä 20266 min
jakson CISA orders Ivanti Sentry patch by Sunday kansikuva

CISA orders Ivanti Sentry patch by Sunday

CISA just enforced a seventy two hour patch deadline for actively exploited infrastructure, and that single move signals a broader shift in how fast security teams are expected to operate. This episode breaks down what that means in practice, from Ivanti Sentry exposure to the growing expectation that internet-facing systems must be treated as compromised almost immediately. It also looks at how attackers are accelerating their own timelines, with zero-day exploitation in PeopleSoft leading directly to extortion, and npm-based worms stealing cloud and AI credentials before detection tools can respond. We also cover Google's legal push against AI-driven smishing networks and what it signals about the future of platform-led defense. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

13. kesä 20266 min