Zero Signal
Welcome back to Zero Signal! On this episode, Crystal Morin, Chief Cybersecurity Strategist at Sysdig and author of the Sysdig Cloud Native Security and Usage Reports, discusses findings showing vulnerability management has hit a “human ceiling,” with about 5.5% of workloads still running critical/high vulnerabilities year over year despite better tooling. Morin explains why backlog volume and faster exploitation push organizations toward automation and agentic AI, highlights a major drop in exploitable vulnerabilities in production (to under 0.2%), and notes reduced image bloat (unused packages under 1%) as both cost and risk reduction. In this conversation, Crystal, Conor, and Stu discuss how threat actors use AI to exploit CVEs within hours, identity trends and new messy identity governance concerns, and growing autonomous response actions like a 140% increase in “kill process.” They also discuss LLM jacking, regional AI package adoption led by EMEA, and McKinsey’s takers/shapers/makers framework. Read the 2026 Sysdig Cloud Native Security and Usage Report here [https://www.sysdig.com/2026-cloud-native-security-and-usage-report/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal]. Continued Reading: * The NVD Just Threw In The Towel - Now What? [https://www.resilientcyber.io/p/the-nvd-just-threw-in-the-towel-now] * NIST Updates NVD Operations to Address Record CVE Growth [https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth] About the Guest: Crystal Morin is a former Air Force Intelligence analyst and current Senior Cybersecurity Strategist at SYSDIG. Morin has authored four of the nine annual SYSDIG Cloud Native Security and Usage Reports, which serve as the industry's primary source for real customer data on Cloud Native Security trends. These influential reports are published on sysdig.com and cited across Dark Reading, Security magazine, and SANS webinars. Key Topics: * 01:37 Hustle Hard Era Ends * 05:43 Case for Agentic Remediation * 08:09 Image Bloat Drops * 11:10 Threat Actors Move Faster * 14:40 Humans vs Machine Identities * 19:32 Who Owns Identity Risk * 22:09 Machine Identity Risk Stats * 23:48 Breach Math Explained * 24:25 Tokens and Agents * 26:02 Europe Leads AI Packages * 28:20 Compliance Drives Confidence * 30:52 Makers Takers Shapers * 33:02 AI Adoption by Sector * 36:01 Rise of Agentic Defense * 40:20 LLM Jacking and Costs * 45:09 Autonomous Response Ladder Meet our Sponsors: Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North. [https://hamptonnorth.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal] Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending. [https://www.sysdig.com/?utm_source=website&utm_medium=podcast&utm_campaign=aware_global_swsd_all&utm_content=zero-signal]
35 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Zero Signal!