Crestvale Newsroom

Germany approves draft law for active cyber defense

6 min · 1. juni 2026
episode Germany approves draft law for active cyber defense cover

Beskrivelse

Cyber policy, AI cost, and cryptography are all shifting at the same time, and the direction is clear. Governments are moving toward active intervention, AI pricing is normalizing, and post-quantum readiness is becoming an operational requirement. For professional service firms, this is not abstract. Faster government response means higher expectations for your own security posture. Rising AI costs mean margins can erode if usage is not managed tightly. And without a clear inventory of where encryption lives, future compliance and migration will become expensive and disruptive. We also cover the spread of uncensored AI models, new fraud detection approaches from Mastercard, a major breach at Carnival, and why vulnerability management is breaking under scale. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Kommentarer

0

Vær den første til å kommentere

Registrer deg nå og bli medlem av Crestvale Newsroom sitt community!

Prøv gratis

Prøv gratis i 14 dager

99 kr / Måned etter prøveperioden. · Avslutt når som helst.

  • Eksklusive podkaster
  • 20 timer lydbøker i måneden
  • Gratis podkaster

Alle episoder

138 Episoder

episode Check Point VPN flaw bypasses passwords in IKEv1 cover

Check Point VPN flaw bypasses passwords in IKEv1

Today's episode focuses on two failures that point to the same root issue: identity controls breaking under outdated assumptions. A Check Point VPN flaw shows how legacy configurations like IKEv1 can silently become open doors, while Meta's AI-powered recovery flow demonstrates how automation can bypass core verification entirely. For security and IT leaders, the takeaway is direct. Identity is no longer confined to login systems. Any workflow that can modify access or user attributes is now part of your attack surface. That includes AI agents, support tooling, and recovery processes. At the same time, configuration debt is proving just as dangerous as unpatched software. We also cover new data on AI governance gaps, a major healthcare-related breach, MFA bypass tactics, and a critical Linux privilege escalation flaw. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

9. juni 20265 min
episode Miasma worm hit 73 Microsoft GitHub repos cover

Miasma worm hit 73 Microsoft GitHub repos

A new supply chain attack shows that simply opening a code repository can now execute malware inside common developer tools. At the same time, AI search is beginning to surface fraudulent websites, and outages in upstream models are breaking features inside everyday SaaS platforms. For firm leaders, this is a shift in where risk lives. It is no longer just at the network edge. It sits inside tools your teams use every day, from coding environments to research workflows to automation platforms. That means controls, verification, and redundancy need to move closer to how work actually happens. We also cover AI native job roles, tokenized IPO access, and the rise of prediction markets as decision tools. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

I går5 min
episode OpenAI adds Lockdown Mode for ChatGPT cover

OpenAI adds Lockdown Mode for ChatGPT

AI tools are forcing a new tradeoff between capability and control. OpenAI's Lockdown Mode makes that explicit by limiting what ChatGPT can access during sensitive work, rather than trying to eliminate risk entirely. For professional service firms, this shifts AI from a productivity tool into a governance decision. Leaders now need clear policies for when full capability is acceptable and when restricted environments are required. At the same time, runtime AI governance, stricter cybersecurity laws, and the move away from VPNs toward Zero Trust are raising the bar on what "secure" actually means in client work. We also cover new signals from Wallarm, Canada's Bill C-8, and a growing push toward Zero Trust access in law firms. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

7. juni 20266 min
episode Fake IT staff hit law firms in-person cover

Fake IT staff hit law firms in-person

Physical access is becoming the new attack vector for professional service firms. Today's episode looks at the rise of ransomware groups showing up in person at law offices, bypassing traditional cybersecurity defenses entirely. For firm leaders, this shifts the problem from technical controls to operational discipline. Identity verification, front desk protocols, and staff awareness now sit at the center of risk management. At the same time, CMMC enforcement is tightening through contract pressure, and firms that cannot produce evidence of compliance are already being filtered out of revenue opportunities. Meanwhile, platforms like Filevine are racing to become the operational brain of the firm through AI-driven workflows. We also cover changes from the IRS, signals from AI infrastructure markets, and rising pressure on security and software spend. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

6. juni 20266 min
episode Trump AI EO makes patching a compliance issue cover

Trump AI EO makes patching a compliance issue

AI security just became an operational requirement, not a policy discussion. New federal direction is pushing vulnerability management and rapid patching into enforceable territory, with implications that extend well beyond large tech companies. For professional service firms, this shift will show up in client demands, audits, and engagement terms. The ability to prove disciplined security practices is quickly becoming a prerequisite for winning and keeping work. At the same time, leading firms are productizing their expertise, compressing delivery timelines, and changing how services are priced and delivered. We also cover Kirkland and Ellis partnering with Palantir, a fast-moving developer security exploit, and Aprio's continued push toward a multidisciplinary firm model. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

5. juni 20265 min