Crestvale Newsroom

GentleKiller uses BYOVD to kill EDRs

5 min · Ayer
Portada del episodio GentleKiller uses BYOVD to kill EDRs

Descripción

Ransomware operators are no longer trying to evade detection. They are disabling endpoint defenses at the kernel level before attacks even begin, changing how security teams need to think about control and visibility. This shift matters because many security strategies assume tools will stay active long enough to respond. At the same time, law enforcement is exposing how ransomware depends on large-scale identity fraud to turn crypto into cash. Together, these trends point to two pressure points: kernel access and identity assurance. In this episode, we cover the GentleKiller EDR takedown approach, the AudiA6 laundering network, Malaysia's push toward national digital identity, and a Bluetooth flaw that turns everyday devices into potential listening points. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de Crestvale Newsroom!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

152 episodios

episode OpenAI Daybreak moves from bugs to patches artwork

OpenAI Daybreak moves from bugs to patches

Security is shifting from finding vulnerabilities to fixing them at machine speed. OpenAI's latest moves signal that automated remediation is becoming the new baseline, not an advantage. For security and IT leaders, this changes how teams should operate. Backlogs are no longer acceptable, and tools that cannot generate and apply fixes will fall behind. At the same time, AI is moving into enforcement layers, supply chain breaches are exposing sensitive data outside traditional perimeters, and a live zero-day in Microsoft Defender highlights how quickly risk can evolve. Also covered: Check Point embedding AI into production defenses, the Tata Electronics breach impacting Apple and Tesla data, and active exploitation trends across widely used platforms. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

23 de jun de 20265 min
episode GentleKiller uses BYOVD to kill EDRs artwork

GentleKiller uses BYOVD to kill EDRs

Ransomware operators are no longer trying to evade detection. They are disabling endpoint defenses at the kernel level before attacks even begin, changing how security teams need to think about control and visibility. This shift matters because many security strategies assume tools will stay active long enough to respond. At the same time, law enforcement is exposing how ransomware depends on large-scale identity fraud to turn crypto into cash. Together, these trends point to two pressure points: kernel access and identity assurance. In this episode, we cover the GentleKiller EDR takedown approach, the AudiA6 laundering network, Malaysia's push toward national digital identity, and a Bluetooth flaw that turns everyday devices into potential listening points. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Ayer5 min
episode Gravity SMTP flaw leaks WordPress API keys artwork

Gravity SMTP flaw leaks WordPress API keys

A WordPress plugin flaw is exposing API keys, and attackers are already using it to move beyond simple exploits into account takeover and lateral access. This is not just a CMS issue. It is a reminder that secrets management failures can quickly become identity incidents. For security and IT leaders, the takeaway is immediate. Email infrastructure, API keys, and integrations now sit directly on the identity boundary. At the same time, vendor risk and AI cost control are becoming operational pressures that require proactive planning, not reactive fixes. This episode also covers VMware pricing fallout, a claimed breach of a major water utility, and growing limits on enterprise AI usage. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

21 de jun de 20265 min
episode Klue breach weaponized OAuth tokens into CRM exfiltration artwork

Klue breach weaponized OAuth tokens into CRM exfiltration

A breach at Klue shows how attackers are shifting away from breaking core systems and instead exploiting trusted integrations. By stealing OAuth tokens, they turned normal API access into a high-speed data exfiltration path inside Salesforce environments. This matters because most organizations do not tightly manage their integrations, token lifecycles, or non-human identities. At the same time, a critical Splunk vulnerability is already being exploited, and AI is now acting directly inside financial systems like QuickBooks. These changes are expanding the attack surface in ways traditional controls are not designed to handle. Also covered: a major law enforcement operation disrupting SocGholish infrastructure, new warnings on FortiGate exposure, and why phishing is becoming more precise even as volume drops. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

20 de jun de 20266 min
episode Cisco patches critical ISE command-exec flaw artwork

Cisco patches critical ISE command-exec flaw

Cisco's latest ISE vulnerability is a reminder that when identity infrastructure breaks, everything behind it is exposed. At the same time, CISA is redefining how quickly organizations are expected to respond to real-world threats, with patch timelines shrinking to days when exploitation is active. This episode breaks down what it means when your network access control layer becomes a pivot point, and why risk-based patching is quickly becoming the standard across both government and enterprise environments. There is also a closer look at how Google's new agent discovery standard could shape machine identity and trust, and why ransomware groups are scaling faster with new incentive models. We also cover Teams-based command and control abuse, third-party data exposure, and shifts in vendor risk. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

19 de jun de 20266 min