POPULARITY
Shortly after the final Enduro World Cup race of the 2026 season, Warner Brothers Discovery and the UCI made the surprise announcement that the series will not continue for 2027. Despite the uncertain future that leaves for top-tier professional Enduro racing, the announcement was met with a surprising amount of excitement from athletes, and a real sense of optimism that something better can rise from the ashes of the short-lived EDR series. So we brought professional racer Eric Olsen back on the show to discuss all of it. The full press release from the UCI can be read here. Note: We Want to Hear From You! Please share with us the questions, topics, or stories you'd like us to cover on Bikes & Big Ideas. You can email us at: info@blisterreview.com RELATED LINKS: Momentous: livemomentous.com use code: Blister OneSkin: oneskin.co/BLISTER Get Yourself Covered: BLISTER+ Blister Mountain Bike Buyer's Guide TOPICS & TIMES: The state of professional Enduro racing (1:42) Online perception vs. reality on the ground (4:13) Broadcasting & marketing Enduro racing (9:29) The Enduro World Series becoming the Enduro World Cup (12:53) New possibilities for Enduro racing (17:43) Eric's vision for what comes next (20:28) Crankworx's announcement of a new series (32:21) How has (and hasn't) the series changed in recent years? (35:39) Optimism for the future (40:24) CHECK OUT OUR OTHER PODCASTS: The Vault Blister Cinematic CRAFTED GEAR:30 Blister Podcast
Shortly after the final Enduro World Cup race of the 2026 season, Warner Brothers Discovery and the UCI made the surprise announcement that the series will not continue for 2027.Despite the uncertain future that leaves for top-tier professional Enduro racing, the announcement was met with a surprising amount of excitement from athletes, and a real sense of optimism that something better can rise from the ashes of the short-lived EDR series. So we brought professional racer Eric Olsen back on the show to discuss all of it.The full press release from the UCI can be read here.Note: We Want to Hear From You!Please share with us the questions, topics, or stories you'd like us to cover on Bikes & Big Ideas. You can email us at: info@blisterreview.comRELATED LINKS:Momentous: livemomentous.com use code: BlisterOneSkin: oneskin.co/BLISTERGet Yourself Covered: BLISTER+ Blister Mountain Bike Buyer's GuideTOPICS & TIMES:The state of professional Enduro racing (1:42)Online perception vs. reality on the ground (4:13)Broadcasting & marketing Enduro racing (9:29)The Enduro World Series becoming the Enduro World Cup (12:53)New possibilities for Enduro racing (17:43)Eric's vision for what comes next (20:28)Crankworx's announcement of a new series (32:21)How has (and hasn't) the series changed in recent years? (35:39)Optimism for the future (40:24)CHECK OUT OUR OTHER PODCASTS:The VaultBlister CinematicCRAFTEDGEAR:30Blister Podcast Hosted on Acast. See acast.com/privacy for more information.
The episode highlights the structural shift toward platform consolidation in security services, illustrated by Coro's unified security platform and its positioning for lean IT teams and MSPs. The mechanism involves the bundling of diverse security tools—email protection, endpoint detection and response (EDR), DLP, security awareness, backup, and cloud app integrations—into a single, managed service. This reduces the operational overhead associated with managing multiple vendors, products, and contracts, a trend now pursued by both established enterprise providers and emergent channel-focused companies. The most significant development cited is Coro's integration of AI and automation within its platform, claiming, according to the company, that 92% to 96% of alert tickets generated by security modules are closed automatically by machine intelligence, depending on the month. The conversational AI integrations such as ChatGPT and Claude are presented as front-end layers through which practitioners can execute mundane security tasks—ticket management, host isolation, incident correlation—without direct console interaction. The claim of offloading 95% of workloads to automation is specified as relating to ticket processing volume, as clarified in the discussion. Supporting evidence centers on the operational layering of AI, with commentary on new risk profiles introduced by integrating large language models (LLMs) into security workflows. Concerns raised include rising exposure to prompt injection, shadow AI (untracked AI usage by end users), and unmanaged cost escalation linked to token-based billing models for third-party AI platforms. Coro's approach distinguishes between AI-related costs incurred internally (absorbed by the vendor) and those incurred when practitioners interact with external AI tools (borne by the MSP or their clients). The need for visibility into AI usage and structured user training is highlighted as a risk mitigation measure. Operationally, MSPs and IT providers face both increased efficiency and new complexity. Vendor dependency consolidates, reducing contract sprawl and administrative burden but raising questions about single-point-of-failure and stack lock-in. Billing risk shifts with AI consumption models, introducing liability for unexpected operational cost surges if token limits are not enforced. The requirement for effective governance intensifies as traditional security controls are extended by AI-managed processes and the detection of unauthorized AI activity becomes part of standard oversight. Providers are advised to scrutinize stack overlap, evaluate whether platform consolidation minimizes genuine operational friction, and remain cautious about over-relying on automated outcomes without maintaining direct accountability. Supported by: Pax8Proofpoint
When Claude Cowork hits a roadblock, it doesn't give up, it writes a custom Python script and downloads an untrusted NPM package just to bypass its restrictions and finish its goal. Are your security tools close enough to stop it? In this episode, Ashish sits down with Michael Leland, VP, Field CTO at Island, to discuss the critical need for an Agentic Control Plane. Michael breaks down why traditional security silos (EDR, DLP, CASB) fail to provide visibility when autonomous AI agents execute tasks outside the network, and why the browser is the ultimate line of defense for monitoring user intent. We explore the massive reality of Shadow AI and the hidden danger of well-intentioned employees accidentally hooking up sensitive data to public LLMs. Finally, Michael shares practical strategies for solving token waste through "model fit steering" and managing the complex "two-hop problem" when an agent calls another agent.Guest Socials - Michael's Linkedin Podcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter If you are interested in AI Security, you can check out our sister podcast - AI Security PodcastQuestions asked:(00:00) Introduction to the Agentic Control Plane(01:50) Michael Leland's Background (Cabletron, Nitro Security, SentinelOne)(03:20) Why Island Evolved from the Browser to the Desktop for AI(05:50) The Failure of Traditional Siloed Security (EDR, DLP, CASB)(07:20) Goal-Oriented AI: How Claude Cowork Downloads Untrusted NPM Packages(08:30) Model Fit Steering: Routing Users to the Right LLM for the Right Price(10:30) The Threat of Malicious AI Skills and Plugins(11:30) The Well-Intentioned Insider Threat (The Next Cambridge Analytica)(13:00) Uncovering Shadow AI: From 8 Tools to 243(15:10) Token Brokering at the MCP Gateway(16:40) Protecting Non-Human Identities (NHI)(18:20) Solving the "Two-Hop" Problem (Agent-to-Agent Communication)(21:00) Fixing Hallucinations with Corporate RAGs(25:40) Calculating AI ROI Beyond "Token Maxing"(28:40) The "You Laugh, You Lose" Cybersecurity Joke Challenge
Recorded on site at Black Hat USA 2026 in Las Vegas, Seth Summersett joins Sean Martin to talk through the volume problem that shapes a modern security operations team. Seth Summersett spent about a decade at the NSA and roughly a decade at Mandiant, finishing there as head of innovation and custom engineering, then a couple of years at Meta supporting business unit level CISOs. He co-founded Embed Security with Jeffrey Johns, who ran the data science team alongside him at Mandiant. The catalyst came from watching a managed service run on human scale day after day. Two analysts and a hundred forwarded phishing emails means someone is choosing which ones to open and carrying the ones they cannot reach. Embed Security sits downstream of existing detection investments, taking signals from SIEM, EDR, identity, and email rather than asking a team to rip and replace what it already runs. What do security analysts actually want from AI in the SOC? According to Seth Summersett, it is not a verdict. Analysts want the work off their plate in a way they can verify, which is why Embed Security built what it calls chain of evidence, showing every question asked and the path to each conclusion. Teams also test it in reverse, running previously dispositioned alerts back through the platform to compare results against their own analysts. The numbers come from a competitive bake off at one of the company's largest clients. Embed Security dispositioned roughly 75% of that client's alerts to the point where the team stopped treating them as primary work, against a daily volume above 10,000 alerts. Why not build this in house? Seth Summersett says the demo is the easy part. What follows is evaluation loops that measure a change across hundreds of thousands of alerts rather than one, governance, and a way to capture organizational knowledge automatically. In regulated sectors, auditors may ask a team to prove how a conclusion was reached and that it holds consistently. There is a people side to this as well. Embed Security has supported a wellness program at BSides across its last two events, backing a calming kit and curriculum for analysts working under incident pressure. Seth Summersett closes with consistency for leaders, since a leader looking at 10% of alerts does not have a full risk profile, and career longevity for analysts who would rather build a long run in security operations than burn out in two or three years. GUEST Seth Summersett, Co-Founder and CEO, Embed Security LinkedIn: https://www.linkedin.com/in/summersett/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Embed Security: https://www.embedsecurity.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS seth summersett, embed security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, security operations, soc analyst burnout, alert triage, agentic ai security, chain of evidence, siem alert fatigue, edr alerts, ai soc platform, security analyst workflow, build versus buy security ai, security operations governance, threat investigation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Wil Santiago, Wil Santiago, chief security and trust officer at Blackpoint Cyber Wil Santiago, chief security and trust officer at Blackpoint Cyber, joins In The Channel to discuss the findings of the company’s 2026 Annual Threat Report – research grounded in thousands of real incidents investigated by Blackpoint’s security operations centre, not surveys. The headline finding: attackers are no longer trying to break in. They’re logging in. Using stolen credentials and commodity remote management tools, threat actors are walking through the front door, hiding in plain sight, and operating with system-level privileges – sometimes for days before anyone notices. Santiago walks through the key trends the SOC identified across 2025: ClickFix and fake CAPTCHA campaigns accounted for more than half of all identifiable incidents, with attackers abusing trusted infrastructure including Azure Blob storage and Cloudflare to deliver payloads. RMM abuse showed up in roughly 30 per cent of triaged incidents – threat actors installing their own version of the same tools MSPs use legitimately, then living off the land with god-mode access. And Adversary-in-the-Middle attacks are now routinely hijacking authenticated sessions even when MFA is in place, by abusing OAuth token handling. The conversation also covers Blackpoint’s detection philosophy: behavioral context over malware signatures. Understanding what normal looks like in an environment – who uses what tool, at what time, from where – is what allows the SOC to catch attackers before they act. It’s a philosophy that is producing results: Blackpoint disrupted 56 per cent of incidents before a payload was ever deployed. Santiago’s closing recommendation for MSPs is straightforward: start with an RMM audit. Know every remote management tool deployed across every endpoint and server you manage. You cannot protect what you don’t know exists. The 2026 Annual Threat Report is available for download on the Blackpoint Cyber website. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. Wil Santiago is Chief Security and Trust Officer at Blackpoint Cyber, an MDR provider whose SOC monitors and responds to threats in real time across a large base of MSPs and their clients. And unlike a lot of threat research that’s survey-based or derived from external reporting, what Blackpoint publishes comes from live incident data, thousands of actual threat responses they’ve worked through in the SOC. Their 2026 annual threat report has a thesis that cuts right through it. Attackers are no longer trying to break in, they’re logging in, using stolen credentials and legitimate IT tools, the same RMMs, the same cloud platforms that MSPs rely on every day, to walk through the front door, hide in plain sight, and work their way towards payday. It’s a theme we’ve been tracking at ChannelBuzz.ca. If you caught our conversation with Tony Anscombe from ESET, that one dug into the mechanics of how MSP tools are being weaponized against the very clients they’re supposed to protect. This conversation is the data layer behind that story, and the detection philosophy that Wil and the Blackpoint team have built to counter it. Their SOC is disrupting 56% of incidents before a payload even deploys. We talk about how. Let’s get right into it. My chat with Wil Santiago. Wil, thanks for taking the time, I appreciate it. Wil Santiago: Thank you, Robert. Robert Dutt: For people who know Blackpoint primarily as an MDR provider, but maybe haven’t dug into the research side, can you give us a quick sense of what your SOC is actually seeing day to day? When you say this report is based on thousands of real incidents, what does that mean in practical terms, in terms of how you gathered this data? Wil Santiago: That’s a great question, Robert. It really starts at the core of what we focus on at Blackpoint Cyber. In 2025, we focused a lot of our detection efforts in the cloud endpoints, but what we realized is that at the core, at that identity layer, that’s the most important thing. But what we’re protecting at Blackpoint is the identity. What we observed in 2025 is this interesting shift where, yes, there’s vulnerabilities, there will continue to be vulnerabilities. However, threat actors don’t necessarily need to weaponize those vulnerabilities to gain access into an environment. They’re not really targeting customers or companies with any specific new zero-day technology or exploits that are novel. They’re just logging in using stolen passwords. We’re still at that pivotal point, but we’re still talking about the same things we’ve been talking about, password reuse, making sure you’re protecting yourself from phishing emails, so on and so forth. But the reality is that threat actors are getting in. They’re stealing credentials and they’re using legitimate tools to just log in, walking through the front door. Robert Dutt: Yeah, the headline from the report was very catchy with the attackers are no longer trying to break in. They’re just logging in, as you say. And that framing echoes what we’ve seen in other reports elsewhere. People are calling 2025 the year of the abuse of trust in terms of security trends, but your numbers are operational and not survey-based. I’m curious what trusted compromise looks like from where you sit. Is there really a shift away from what you were seeing a couple of years ago or three years ago, or has this always been the playbook and we’re only now measuring it properly? Wil Santiago: Yeah, so if I compare back to, let’s say, 2022, I think we at Blackpoint would still see a trend, the threat actors gaining access into an environment, usually using some type of exploit at that time. You can point to a number of Microsoft Exchange exploits that happened during that time. The Hafnium group was doing a lot of Exchange exploits. The reality is there came a certain time where we were detecting Cobalt Strike, a malware commodity tool, every single day in Blackpoint Cyber’s SOC. And then eventually it became once a week, and then it became once a month. So then we started to think, well, what’s happening with the shift of tactics with the threat actors? And what we found is instead of installing Cobalt Strike, they started to install legitimate IT tools. And that’s the trust component. When they’re installing tools that you use internally, they now can abuse those tools the same way that you use those legitimately. And so we have these threat actors that not only are abusing legitimate tools, but like I said, they’re abusing legitimate identities. So when you have what I call the keys to the kingdom, the passwords, I am you. I am now Robert, for all intents and purposes for this sort of webinar. I think the interesting part that we’ve seen at Blackpoint is that threat actors have really, really focused on leave-behinds. And those leave-behinds are commodity remote management tools. Why do they do that? Because EDRs don’t know how to detect them as malicious, right? These are legitimate IT tools that are being used to service MSPs and their customers. And a threat actor just installs their version of the same exact tool that you’re using legitimately. Right? And so the trust component is you go to review your assets and you see ScreenConnect installed in your environments because you use ScreenConnect, right? But then when you start taking a closer look, you start to realize, wait a second, there’s four different ScreenConnect IDs on this one machine. Now we have a more of a problem, right? And so the attack is a little bit of an invisible signature detection because it’s an authorized tool, right? And so we really have to get to this layer of identifying threat actor activity with behavior context. If you’re an AnyDesk shop, then why do you have TeamViewer installed on your file server that’s publicly facing, right? Let’s start to ask those questions and dig into that a little bit. Robert Dutt: Your SOC found that fake CAPTCHA and ClickFix campaigns accounted for, I think it was 50-odd percent of identifiable incidents. That’s a majority of attacks being driven by a technique that essentially requires the victim to step on the link to execute it themselves. Why is that scaling so fast right now? And especially for an MSP who tends to think, you know, my technicians are too smart to do that. What’s kind of the honest answer for what they need to be looking for and protecting against? Wil Santiago: Yeah. And, you know, ClickFix is such an easy attack when you really get into the root of what it does. But it starts with social engineering. You’re enticing someone, again, just like with phishing, to visit something that you’re going to tell them to do an action. And most of the time, they’re going to do that action. Now, why this is so effective is we’re seeing techniques that really enable the threat actor to deliver the payload. And how do they do that? Search engine optimization, right? These SEO links at the top, when you go look for an OBS installer, because you need your camera to look well, or you get a Google sponsor result. Threat actors are just buying those sponsored results and delivering their payloads on there. You click on it thinking you’re going to download OBS, and then it tells you, hey, wait a second, you have to make sure that you are human. Verify that we’re used to verifying we’re humans to download something. So we go and we click it. But then it says, hey, open up your Windows Run command and maybe run this command on us, on your computer for us. And what happens? Threat actors go and they put the commands on a website. They have this watering hole spread out all throughout infrastructure that’s globally distributed. Google, Microsoft, all these sort of cloud infrastructure hosting providers that exist. Threat actors use those. So when you’re looking at your firewall logs and you’re seeing your internal team going to Microsoft.com, hey, it’s Microsoft, right? But the reality is, it’s likely an Azure Blob site that’s just being hosted on Microsoft, that is a threat actor that’s actually hosting it. And so they’re abusing that trust function to say, hey, you need this OBS installer. You Googled it. I didn’t tell you to go Google that. You were the one that did that. And then they found my link, which I posted a malicious payload there. And so again, that abuse factor is all the things we’ve taught our employees, our customers, our MSPs to do, right? Go to Google, make sure you identify the link. Make sure you look for Microsoft. Make sure you see the end of a URL or domain. Validate that. Well, the adversary goes, okay, they want to play that game. I’m just going to host this on Cloudflare. And now we’re back to this gate where now someone clicks on something. Well, what’s this Cloudflare? That’s a legitimate service. I know that to be true, right? It’s very true. The reality is the infrastructure is very, very easy to set up. And it doesn’t require a lot of action. It just requires someone to take a command and put it on their machine. And all the background work happens in the background, right? And so beyond that, we used to see a lot of threat actors use this sort of technique to download malware onto machines. But again, going back to what I mentioned about RMMs, now they’re just downloading an RMM. And that just looks like a legitimate process to an EDR. Robert Dutt: Right. So for an MSP, especially when training or making sure their technicians are aware, is it just as simple as making sure they’re aware of this threat landscape and this wrinkle in it? Or is there something more that’s sort of the advice there on how to protect yourself as best you can? Wil Santiago: That’s a great question. And really, you know, I would say any MSP watching this show, starting today or tomorrow, the first thing that I always tell people, audit your RMM inventory. Asset inventory is the number one thing that customers should be doing, right? You cannot protect what you don’t know exists. And so every single remote management tool that’s deployed across every endpoint you manage, every server you manage, you need to audit those, right? Like you’re giving direct access to a system. And most of the time, those RMMs run in the system context, which means they have the permissions and privileges of any admin, right? And now you have this adversary that has a foothold. They can deploy tools using admin privileges and permissions. So you have to audit your RMM inventory, right? Making sure that you understand what’s happening across those production servers. And forcing MFA, that’s a big one. We see a lot of incidents that source from RMM abuse because they log into the MSP’s RMM console, the cloud-based consoles. Some of those don’t have MFA involved. Again, keys to the kingdom, MFA everywhere, that needs to be a reality. Then we need to start moving into what I call more resilient engineering, right? Conditional access policies, preventing individuals from logging in from untrusted sources, locations, right? There’s ways that you can lock down access to an RMM and assume a threat actor is able to steal credentials because they maybe installed an info stealer on a user’s machine, stole their browser credentials. They reuse the same credentials for Gmail that they do for their corporate environment. Well, now a threat actor just perusing finds their credentials and says, “Oh, I’ve got IT Glue permissions now. I’m going to go log into this and restore all these configs in IT Glue or whatever tools out there.” Well, now the threat actor has access to that. And so that’s how they’re pivoting across these environments. They’re going from cloud to on-prem, on-prem to cloud. One of the things that we caught at Blackpoint recently, and this was a really cool response, but the threat actor compromised the cloud environment first. They then took that cloud access, deployed an RMM using Intune to the devices, and then they used that on-prem access to go to those machines and do their own work directly from that console. I called it overkill. They didn’t have to do that because they had the cloud environment. But because they did that, that sort of prompted this investigation for this MSP to approach us and say, “Hey, we believe something is happening. We investigated and quickly saw the Intune process was the responsible process for deploying some of this malware. So we told them, “Hey, deploy our cloud response suite. We want to understand what’s happening in your cloud.” And sure enough, seven global admins were compromised. So again, limiting scope is important here, right? Least privilege. Why do we have so many people with admin privileges and permissions? I think there’s 192 admin roles or something like that in Microsoft, but we default to just, you get global admin, you get all the permissions. And so now an adversary compromises a Microsoft 365 tenant. Well, now they have the permissions of a global admin. And unfortunately for us, when we shifted from the on-prem strategy to the cloud strategy, we just started pushing everything in the cloud and we say, “Oh, it’s fine. It’s in SharePoint.” We didn’t realize though that that’s only being protected by a password and an MFA token, both of which can be stolen, right? So the protection is not really there. That’s why we have to move to that resilient engineering. And so it’s moving from that reactive alerting to that posture alerting, right? Why is someone trying to log in from France? We have nobody in France. Robert Dutt: So your report showed almost a third of triaged incidents involved RMM abuse. And that’s something, that kind of trend line is something that we’ve seen in other reports. You know, one of your peers is talking about a 200 plus percent spike in abuse of RMM in attacks. I’m curious, especially since you’re sitting in the SOC there, what does RMM based intrusion actually look like in the SOC here? You know, I’m guessing curious, is there a moment where it’s genuinely hard to tell, you know, is this actually a tech doing a routine task or is this an attacker? And if so, what kind of breaks the tie and causes you to go, “No, no, that’s not right.” Wil Santiago: Yeah. Well, there’s kind of two ways to look at it, right? We have threat actors that are compromising MSP RMM tools. These are tools that are owned, managed by the MSP. They’re usually protected with some cloud login, whether they self-host it or they have the vendor host it for them. Threat actors can log into those systems with a password and a username, right? So we see a lot of brute forcing of those systems, especially if they’re self-hosted systems, they usually don’t have the protections of the vendors. They don’t put a WAF in front of them. And so they’ll try to brute force them and just log in, right? Those are few and far between, to be quite honest. We don’t see those as often, but what we do see often is, again, they gain access into an environment, usually by compromising a VPN. Now they’re on the network. Now they can move throughout that network as they’re on the VPN, and they’ll usually find a foothold. And if they have a credential like a local admin, they’ll take that one foothold and then they’ll distribute their RMM across that entire fleet of the network with one command from that foothold. So for us, when we’re looking at RMM deployments, MSPs deploy RMMs in a certain manner and format. They’re not deploying an RMM at two o’clock in the morning on a Saturday when they’re a US-based company. And oh, by the way, they just logged in from a Chinese-based IP, right? So again, there’s indicators that are very clear cut of like, okay, this deployment of RMM tools absolutely malicious. Most of those cases come to the case of, you know, we have application control within Blackpoint that allows us to alert when someone is installing a new application that’s unauthorized. And so what we tell our MSPs to do is, hey, set up your policies that if you’re a Ninja RMM shop, you cannot have any other installations of any other RMM. ScreenConnect is not going to be involved. And so that allows us and affords us the ability to do is, when we get that alert that says someone’s attempting to install a ScreenConnect, we can go back and sort of recreate the path of how do they get here. And what that allows us to really get into is, again, that response, right? And that response is preventing the installation of the RMM, eradicating the threat actor by isolating the machine, making sure you remove their footholds, getting those SSL VPNs off of the public facing internet, and having that exposure management reduced, right? And so when we look at RMM abuse in practice, once they get that RMM installed, again, they’re living off the land with system privileges. System privileges is something that most people tend to understand, but it’s just keys to the kingdom. You are God mode at that point. You can do whatever you feel to deploy and ultimately spread your access with that level of access, right? And so they’ll use it for backdoors. And oftentimes, they may compromise the environment and say, “You know what? I’m busy.” We’ve actually seen this over the holidays where they go take their breaks. Just like everyone else does. It’s Christmas. I’ve done a lot of hacking. So they leave their leave-behind tools and they come back. That’s their access factor. Again, it’s one of those things where they’re hiding in plain sight. Robert Dutt: You touched on MFA a little while ago and the report flagged the use of adversary-in-the-middle attacks. AiTM attacks that let threat actors hijack authenticated sessions, even when the MFA is there. So I guess what’s the message to MSPs who are thinking, “All right, if we just get MFA everywhere, we’re good, we’re covered.” Wil Santiago: Token protection, right? MFA is great. You have to have it. But understand that there’s flaws in the way that MFA communicates to servers. And so the whole way that an adversary-in-the-middle attack works is by abusing OAuth. And OAuth is a standard protocol of just making sure that we understand how systems should communicate for authentication. And what’s really nice about that is we can take that offensive research and then make defensive practices towards that. And so token protection is really huge there. There are a lot of built-in protections in Microsoft that allow you to invalidate session tokens after a certain period of time. Every hour you could refresh these tokens. You now, again, when you get to this resilient engineering, you start to push the adversary to be a little bit more aggressive. And that’s your detection mechanism. When you allow an adversary to move unfettered throughout a network, they’re going to move unfettered throughout a network. But the moment that you give them that sort of, “Eh, stop here. Let me see your ID.” Then they start to get a little uneasy. They’re like, “Wait a second. I don’t know how to move anymore.” And so specifically in MFA, when we talk about session hijacking and session tokens, the token protection aspect is really important because that’s a conditional access policy that you can implement. And most people do not implement those conditional access policies. Now, there’s a slew of them that work in conjunction with each other. But the idea here is your tokens will likely be compromised at some point. If you are duped into clicking one of these phishing links, it’s very easy to steal a session token. So we have to move past that. Now that we know that’s going to happen, how do we prevent the adversary from actually using those session tokens successfully? And that’s where invalidating the sessions comes in, having the session protection, conditional access policies, protected devices, things of that sort. That prevents them from being able to use those session tokens. Robert Dutt: A stat that I keep looking at in the report was that you guys managed to disrupt in the SOC 55, 56 percent of incidents before a payload was deployed. It’s a real number. That’s pretty significant. I guess what is disrupted before the payload hits mean operationally? And what does it tell us about where the detection opportunity actually lives? Because it sounds like the window isn’t did malware execute? It’s something a lot earlier. Wil Santiago: That’s exactly right. When we look at the cyber kill chain, we want to start pushing our adversaries as far left of boom as possible. Right. And so when you hear about this whole right of boom concept, basically, you’ve met your match. And now boom, you’ve now been impacted. Right. And so there’s a lot of indicators of compromise that we can start to hone in on. That will give us an understanding of whether this is legitimate or illegitimate. Right before an adversary even types the command. And again, that’s the context. And the context is what the SOC is really understanding of a customer. Where do they operate? What are their hours of operation? Where are they globally distributed? What’s the infrastructure they use? What are the tools they use? How did they use those tools? Did they deploy tools every Thursday at 2 p.m.? So there’s this constant checklist that they’re doing every single day to understand this. And so when we talk about living off the land, threat actors are trying to execute commands. Right. They’re just trying to sit there. We’re typing on a keyboard command line. Hey, I’m not going to introduce any new factors to my intrusion. I’m just going to live off the land. Ultimately, they want to deploy a payload at the end of all of that. But if they deploy a payload too early in their kill chain, they risk getting caught. Right. And so what they’ll do is they’ll stage everything. They’ll compromise an endpoint. They’ll add a persistent backdoor user. They’ll deploy some small scripts to enumerate the network. Just to get an understanding of what’s happening. But they’ll usually stage those in like a C:UsersMusic folder. And that’s their staging environment. So you can catch them. And we’ve caught at Blackpoint a number of threat actors where their toolkits are still on the machine because we caught them so early left of boom that legitimately all they did was log into a machine, try to mount a share, but it failed. And then that failed share mount is like, wait a second. They have never tried to mount a share on this file server ever. And then you call the MSP and they’re like, yeah, Monday through Friday, our hours are from eight to three and it’s seven p.m. at Thursday. Right. Well, now the context of the intrusion starts to become a little bit more apparent. And so we have to do this very quickly. The reality is for us, behavioral context, it matters more than ever. That is the true bread and butter for stopping threat adversaries is understanding the behaviors in the context of which they employ to compromise the network or compromise an endpoint. And so we focus a lot of our threat intelligence and our adversarial intrusion analysis based off of what hack or tradecraft is. We always say this internally, you cannot protect what you don’t know how to hack. So we spend a lot of our time recreating these attacks, understanding where do we catch them? And one of the things that we found is in those early development cycles of understanding the behaviors of an adversary, we found key indicators of like, wait, that is a very high fidelity indicator that before an adversary even gets on a keyboard, we’ve already caught them. They don’t know that yet. Right. And so that’s a little bit of our secret sauce there. But the reality is that secret sauce was created because we thought like threat actors and we sort of recreated what they did in controlled environments and testing environments to then to make sure the detection and the efficacy of what they’re doing is caught within our product. Robert Dutt: So this is a bit of a sidebar, but it was a new term, at least to me. You flagged Etherhiding in the report, attackers embedding malicious logic and blockchain smart contracts to manage compromised sites. Can you walk me through that real quick? And how real is this in terms of how widely it’s being deployed today? And why does it matter for detection purposes? Wil Santiago: It’s a newer term. You know, I would like to say that we have way too many terms in security and security, you know, sort of like we’re trying to be cool. The reality is this is a technique that leverages transactions on a public blockchain to basically retrieve malicious payloads. Right. And so this is another sort of trend that an adversary is using where they’re just retrieving a payload from something that is trusted. In this case, cryptocurrency. A lot of people trust cryptocurrency. A lot of people trust public blockchains. And so the idea here is that, you know, threat actors are usually going to utilize some type of social engineering and then that social engineering is going to get you to come to like a WordPress site through that WordPress site. They’re going to basically have scripts that you’re going to download and ultimately run. Innocuously. Now, when that happens, you download something that you think is OBS, like the example I gave earlier, it’s actually a JavaScript payload. Well, that JavaScript payload goes and reaches out and it pulls a malicious payload from the ether blockchain. Right. And so that’s that aspect of there’s function calls that we’ve identified within Blackpoint that are related to that remote management of pulling payloads from that blockchain. My personal opinion of this sort of technique is, you know, it gives a lot of advantage to the threat actors in terms of stealth and flexibility. But it is one of those techniques that is complicated for majority of what we see at Blackpoint. Most threat actors are not getting to that complicated level of compromising. They’re just hosting malware on a compromised WordPress site of a legitimate company that they’ve co-opted the passwords for. Right. And again, we see threat actors from different angles. 90 percent of what we see sort of today is cybercrime related. Right. So you have a lot of the fake CAPTCHA, the ClickFix lures, the Etherhiding stuff. The reality is at the end of that payload, we see everything from Etherhiding to Cobalt Strike to ransomware and compromise. The way that they get to that sort of compromise is kind of the same, though. Robert Dutt: Last one for me, if an MSP is listening to this and they’ve just absorbed that, you know, more than half of the attacks they’re going to see start with legitimate credentials, their own tools are showing up in about a third of incidents. MFA isn’t necessarily a guarantee. Where do you start? You know, what’s the one thing they probably aren’t doing today that would meaningfully move the needle for them in terms of making sure things are as locked down, as protected as is possible? Wil Santiago: That’s a great question. I like to say we should probably be spending most of our time right now really focusing on posture and posture management, reducing the attack surface. Right. How do you how do you start? Where do you start reducing the attack surface? This is where frameworks really come into play. And there’s some really great frameworks that are really prescriptive out there. One of them is the Center for Internet Security Controls, CIS version 8.1. It’s very prescriptive and it starts from the very top, right? External facing assets and applications. How do you lock those down? Cloud assets and applications, internal assets, user accounts, passwords, right? And it gives you a prescriptive way to deal with incidents. Beyond that, there’s kind of this like practical implementation groups that they have, right? And so you can start by implementing the CIS Controls with implementing one Implementation Group, right? You don’t have to implement them all. And so I think there’s a subset of Implementation Groups that can be used, but it’s about identifying, you know, what of these sort of subset groups will really resonate with your organization and your maturity level, right? And so I tell most people, look at IG1, start with the essentials. If you’ve already fit the bill on that, then move to IG2, right? But the reality is IG1 is going to give you that foundational security for organizations. And then IG2 and IG3 are going to be a little bit more advanced for more complex things. Most people are probably in that IG1, but they probably could benefit from some of the things in the IG2, the Implementation Groups there. That’s really going to help you really target your defenses against ransomware. That’s going to help you sort of approach a risk-based approach. That’s another thing that, you know, all risk is not the same, right? Risk is treated differently. And it’s important for anyone running a security team to help understand how should I prioritize my risk, right? Where is my risk going to really give me issues if a threat actor gets into it? And therefore, I always say, start there. We all know what keeps us up at night. So that’s the areas that we need to focus on. Robert Dutt: All right. Some sage advice and some sobering numbers as well. I appreciate your taking the time and walking us through some good stuff. Wil Santiago: Thank you, Robert. I really appreciate it. Robert Dutt: There you have it. Wil Santiago from Blackpoint Cyber. I’d like to thank Wil for his time today and for bringing some real energy to what can sometimes be pretty dense subject matter. And of course, I’d like to thank you for listening. The data in this conversation is worth thinking about. More than half of the attacks Blackpoint’s SOC starts with someone simply logging in, using credentials that were stolen sometimes long ago, and that users are still reusing across platforms. A third of triaged incidents involve RMM tools, the same tools your techs are using right now to manage endpoints. And MFA, as much as we’ve come to rely on it, is no longer the finish line it once appeared to be. The antidote Wil describes is behavioral context, understanding what normal looks like in an environment so you can spot when something legitimate is being done illegitimately. Not “Is this malware?” But “Is this person, using this tool at this hour from this location, doing something they’ve never done before?” That’s a fundamentally different way about thinking of detection, and it’s why the human element in the SOC still matters. And I’ll add one thing that Wil mentioned after we wrapped the recording. It’s a dimension of this fight that doesn’t get talked about often enough. Blackpoint’s work doesn’t stop at detection and response. They’re actively working to identify and disrupt adversary infrastructure, notifying law enforcement, including, he noted, Canadian authorities, with the specific goal of making cybercrime economically painful. The logic is straightforward. If your infrastructure gets taken down every time you try to run a campaign, the math of operating a criminal enterprise starts to change. That’s offense, and it sounds like they’re playing it. If you’re finding the show valuable, I’d encourage you to follow or subscribe to the podcast. You can find us on Apple Podcasts, Spotify, YouTube, all the major directories. A rating review always helps. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K's Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund' to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
The episode details a structural shift for MSPs and IT service providers: the separation of security license resale from the value of human-led security services, and the resulting pricing and margin risks. Companies like N-able, SentinelOne, and SonicWall exemplify how technology offerings and delivery mechanisms are forcing providers to re-examine what differentiates their services beyond the products they resell. N-able's financial results illustrate the risk of relying on product-based security revenue. The company reported a drop in annual recurring revenue, driven by lower renewal rates in Unified Endpoint Management and Endpoint Detection and Response lines—both of which relied on reselling portable licenses, notably SentinelOne's product. In contrast, revenue from services tied to human expertise—through the acquired Adlumen's managed detection and response (MDR)—grew, according to both N-able management and analysts. The episode states that when customers can move licenses without losing service continuity, price becomes the only differentiator, undermining provider margins. Related developments reinforce this dynamic. SonicWall launched a combined antivirus and EDR solution available as both a product and a managed service—explicitly marketed for MSP resale—where SonicWall's analysts handle detection and response. Additionally, Proofpoint expanded its managed services platform, providing security, backup, and compliance through an MSP-oriented, multi-tenant console. These offerings blur the line between manufacturer-managed services and traditional MSP-delivered security work, increasing vendor competition at the service layer. For MSPs and IT leaders, these shifts expose the risk in revenue models that bundle security services with third-party product resale, particularly when those products are easily substitutable. The transcript urges providers to re-evaluate their pricing strategies: separating human service from license cost, justifying it independently, and moving away from device- or seat-based billing. The clear risk is that failing to articulate and defend the value of human-led activities will leave providers vulnerable to vendor undercutting and margin erosion, as seen in recent N-able outcomes. 00:00 Recurring Revenue Went Backwards 03:24 They Stopped Saying RMM 06:04 You Already Own It 09:18 Why Do We Care? Supported by: Guardz
Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams. So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it. Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first. How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities. He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop. His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Sumedh Thakar, President and CEO at Qualys On LinkedIn: https://www.linkedin.com/in/sumedhthakar/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Qualys: https://www.qualys.com/ InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Two pen testers have spent thousands of hours inside client networks, and the most common failure they see isn't a missing security product — it's an EDR nobody ever tuned.In this episode, Spencer and Tyler open up the CrowdStrike Falcon console and walk through the specific settings that decide whether your team catches an attack or never sees it. They start with the story that kicked the whole thing off: Tyler running a pen test where every AMSI bypass gets blocked and detections fire left and right, while Spencer runs nearly identical tooling against the same product at another client and the SOC sees nothing all week. Same CrowdStrike. Same version. Different checkboxes.From there it's a tactical walkthrough of Endpoint Security → Prevention Policies and the settings worth your attention: Enhanced Exploitation Visibility, which unlocks command-line and PowerShell telemetry that Microsoft disables by default; Enhanced DLL Load Visibility for side-loading attacks; WSL2 Visibility, which closes a sandbox threat actors have been using to run Kali tooling under the radar; memory scanning for in-memory C# tradecraft; Office malicious macro removal; file system containment for ransomware over SMB; vulnerable driver protection, the direct mitigation for BYOVD attacks and EDR killers; and cloud-based anomalous process execution for living-off-the-land binaries.They also cover custom IOA rule groups for blocking unauthorized RMM tools, centralized firewall policy management, device policies for USB control, and a warning on exclusions — especially wildcard paths, which Tyler calls a threat actor's best dream.The takeaway is simple: you're paying real money for EDR, and default configurations aren't giving you what you paid for. Open your console, work through the settings, test them against an IT pilot group, and enable what fits your environment.TOPICS COVERED- Why EDR vendors ship deficient defaults on purpose- Enhanced Exploitation Visibility and the telemetry gap in PowerShell attacks- DLL side-loading, WSL2 abuse, and vulnerable driver attacks- Memory scanning and in-memory tooling detection- Blocking RMM tools with custom IOA rule groups- Exclusion hygiene and the wildcard path problem- Device policies, USB blocking, and insider threatSentinel One and Defender for Endpoint are next — let us know what else you want covered.Blog: https://offsec.blogWork with us on an internal pen test: https://securit360.comBlog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
“Let your engineers get back to doing what makes you money.” In this Technology Reseller News podcast recorded at ChannelCon 2026, Heather Harlos, Demetrios “Deme” Georgiou and Benjamin Morrell, of Coro Cybersecurity discuss how consolidating security tools can help MSPs reduce complexity, improve margins and serve more customers. Coro brings email security, endpoint protection, EDR, data loss prevention, VPN, secure web gateway, security awareness training, cloud protection and backup into a single platform. It is designed primarily for SMBs and midsized organizations with limited internal IT and security resources. Many MSPs recognize that they have a tool-sprawl problem but hesitate to replace products and vendor relationships they have relied on for years. “Consolidation is a very big objective for channel partners,” the Coro team says. “The challenge is making that change their new normal.” For MSPs, the value extends beyond lowering software costs. A unified platform reduces the time engineers spend moving between consoles, investigating alerts and managing separate systems. That additional capacity can be used to onboard customers, develop new services and increase revenue. Coro uses AI to filter security noise and surface the information that requires attention. The platform is also designed to scale easily across customers of different sizes. The team says smaller businesses are increasingly being targeted by phishing, ransomware and automated attacks. Although these organizations may lack enterprise security budgets, they still expect their MSPs to deliver effective protection. At the same time, MSPs must differentiate themselves through service rather than simply reselling a collection of tools. “Customers should buy from the channel partner because of the partner—not just because of the software being sold,” the team says. By simplifying security operations, Coro aims to help MSPs support more customers without continually adding personnel. Time and resources can then be redirected toward higher-value services, including new AI projects and business growth. Visit Coro.net to learn more.
Max talks with Maya Shpak, CEO of SkyPath, about how pilots can avoid turbulence and find smoother air by combining crowdsourced observations, aircraft data, and machine-learning predictions. The idea for SkyPath came from an airline captain and check airman who encountered turbulence and realized that the iPad already carried in the cockpit contained accelerometers capable of measuring aircraft movement. Much like a traffic app gathers information from phones on the road, SkyPath could collect ride-quality observations from participating aircraft, send them to the cloud, and return an updated turbulence picture to other pilots. Maya says the system now receives data from about 40,000 users each day. An iPad observation is only one of five sources used by SkyPath. The system filters accelerometer readings, removes noise, and normalizes each report for aircraft type. That adjustment is important because light turbulence in a large business jet may feel moderate in a smaller general aviation airplane. When two pilots have iPads aboard the same aircraft, SkyPath can compare the two devices and identify a questionable reading. SkyPath also derives turbulence information from ADS-B vertical-rate data. Many aircraft provide both ADS-B reports and iPad observations, allowing the company to compare the two and refine its conversion algorithm. This expands coverage into areas where no participating iPad-equipped aircraft has recently passed. The platform also incorporates PIREPs and eddy dissipation rate, or EDR, reports. EDR is an aircraft-independent measure of atmospheric turbulence widely used in commercial aviation. SkyPath can convert its sensor information into EDR-compatible reports while using existing EDR data to supplement its own observations. The fifth source is SkyPath's predictive model. More than 200 meteorological parameters from NOAA and other government sources are fed into a machine-learning system trained with SkyPath's observational data. This produces estimated ride conditions where direct reports are limited. Maya says this is particularly useful to general aviation pilots flying below normal airline cruise altitudes, although the company generally sees better accuracy above about 5,000 feet. Pilots can use SkyPath before takeoff or during a flight. They may enter a call sign or flight number, paste a route from another electronic flight bag, or operate without a filed IFR flight plan. In its bearing mode, the app monitors an area approximately 100 miles ahead and 15 degrees to either side of the aircraft's direction of flight. It can run in the background and generate an alert about ten minutes before the airplane reaches significant turbulence. For larger operators, the same information can also be delivered through SkyPath's own flight-following tools or integrated EFB systems. Pilots can set the alert threshold, place the app in the background, and continue using their primary navigation display. Dispatchers may receive warnings when an aircraft is approaching rough air and then contact the crew through the operator's normal communications system. Maya says SkyPath was not yet integrated with ForeFlight at the time of the interview, although routes can be copied from ForeFlight into the app. The altitude slider helps pilots compare ride conditions above and below their planned or current altitude. This can support a decision to climb, descend, or choose a different cruising altitude before departure. SkyPath also displays validated smooth-air observations as white hexagons. Knowing where the air is smooth can be more actionable than simply seeing where rough air has been reported. The display uses familiar aviation colors to represent smooth, light, light-to-moderate, moderate, and occasional severe turbulence. Observed and predicted areas appear differently, allowing pilots to distinguish between actual aircraft encounters and conditions generated by the forecast model. Users can filter the display to emphasize the severity levels most relevant to their aircraft and operation. Maya says access to better turbulence information can change pilot behavior. One business aviation operator using SkyPath reported nearly a 50 percent reduction in moderate-turbulence encounters. SkyPath also reviewed 180 published turbulence incidents and found that matching information had been available beforehand in 79 percent of them. The app may also improve communication with passengers. Maya describes pilots showing charter passengers where rough air is expected and when it should end. That visual explanation can help nervous flyers understand why they need to remain seated and keep their seatbelts fastened. Unexpected turbulence can produce injuries, diversions, medical expenses, airport fees, passenger accommodations, replacement-aircraft costs, and schedule disruptions. Even an unsecured passenger, flight attendant, or hot drink can create a serious event. Better information gives pilots more opportunity to avoid the roughest areas or prepare everyone aboard before reaching them. Finally, SkyPath allows pilots to submit a digital PIREP from the app directly into the FAA reporting system. Individual pilots can begin with a free trial and choose between subscription levels. Maya explains how SkyPath is designed to supplement the navigation and weather tools pilots already use while providing a more detailed picture of where they may find rough or smooth air. If you're getting value from this show, please support the show via PayPal, Venmo, Zelle or Patreon. Support the Show by buying a Lightspeed ANR Headsets Max has been using only Lightspeed headsets for nearly 25 years! I love their tradeup program that let's you trade in an older Lightspeed headset for a newer model. Start with one of the links below, and Lightspeed will pay a referral fee to support Aviation News Talk. Lightspeed Delta Zulu Headset $1299NEW – Lightspeed Zulu 4 Headset $1099 Lightspeed Zulu 3 Headset $949Lightspeed Sierra Headset $749 My Review on the Lightspeed Delta Zulu Send us your feedback or comments via email If you have a question you'd like answered on the show, let listeners hear you ask the question, by recording your listener question using your phone. News Stories FAA Expands Approval List For Swift Fuels' 100R Unleaded Avgas FAA Accepts New MOSAIC Light-Sport Standards ForeFlight's Newest Feature ClearNOTAMs Industry urges Congress to provide $20 billion for air traffic control upgrades New Sentry SkyPlay Brings ForeFlight to the Instrument Panel Redbird Unveils G1000 NXi Emulator, Enhanced Simulator Panel Lightspeed Headset Customized For Rotax Power Bad Boy's File: Florida Speeder May Miss His Checkride Mentioned on the ShowBuy Max Trescott's G3000 Book Call 800-247-6553 SkyPath Turbulence App Free Index to the first 282 episodes of Aviation New Talk So You Want To Learn to Fly or Buy a Cirrus seminars Online Version of the Seminar Coming Soon – Register for Notification Check out our recommended ADS-B receivers, and order one for yourself. Yes, we'll make a couple of dollars if you do. Get the Free Aviation News Talk app for iOS or Android. Check out Max's Online Courses: G1000 VFR, G1000 IFR, and Flying WAAS & GPS Approaches. Find them all at: https://www.pilotlearning.com/ Social Media Like Aviation News Talk podcast on Facebook Follow Max on Instagram Follow Max on Twitter Listen to all Aviation News Talk podcasts on YouTube or YouTube Premium "Go Around" song used by permission of Ken Dravis; you can buy his music at kendravis.com If you purchase a product through a link on our site, we may receive compensation.
No Password Required: Next Gen - Ep. 3 - Kieran Human How Lead Cybersecurity Engineers Actually Think In this episode of No Password Required: Next Gen, Yazzel interviews Kieran Human, Lead Cybersecurity Engineer at ThreatLocker. From research to working directly with ThreatLocker's CEO on new security initiatives, Kieran gives an inside look at what it's really like to work on the front lines of cybersecurity. Kieran stands out as a cybersecurity professional by hares why curiosity, strong communication, and understanding the bigger picture are just as valuable as technical skills. He also reflects on one of his proudest career moments, writing a compliance white paper that earned praise from ThreatLocker's CEO Danny Jenkins, and explains how that experience reinforced the importance of research, writing, and always looking for ways to improve. Kieran also explains why Zero Trust security is becoming essential, teaches viewers a few cybersecurity terms that are guaranteed to impress at dinner, and even reveals why the Terminator would be his ultimate cybersecurity teammate! Whether you're exploring a career in cyber or looking for practical advice from someone working in the field every day, this episode is packed with insights for the next generation of cybersecurity professionals. Presented by ThreatLocker Supported by DerScanner Follow Kieran on Linked in here: https://www.linkedin.com/in/kieran-human-5495ab170/ Chapter List: 00:00 Introduction to Cybersecurity and Career Path 02:54 Key Skills and Qualities for Success in Cybersecurity 06:07 Impact of AI and Zero Trust in Cybersecurity 06:56 Fun Insights and Closing Thoughts
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs
This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs
Hackers target Thailand's Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a victim's browser. Attackers target credentials of traveling corporate employees. EDR shutdown is now par for the course for leading ransomware groups. Russian threat actors exploited a Zimbra vulnerability for at least five months before it was patched. Monday business briefing. Our guest is Krishna Sai, CTO at SolarWinds, with security lessons learned from the World Cup. When the feed ends, the fun begins. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Krishna Sai, CTO at SolarWinds, discussing the security risks around the World Cup and how this affects IT teams as they try to manage the growing digital traffic sprawl surrounding the event. Selected Reading Hackers used autonomous AI agent to spy on Thailand's finance ministry (The Record) Nvidia and Tech Giants Launch AI Security Alliance (SecurityWeek) Golden Chickens malware-as-a-service resurfaces with four new families (SC Media) GitHub, PyPI add time-based defenses against supply chain attacks (Bleeping Computer) SourTrade Malvertising Campaign Secretly Builds Malware in the Browser (Infosecurity Magazine) Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials (SecurityWeek) Ransomware Groups Increasingly Deploy EDR Kill Techniques (Infosecurity Magazine) TA488 Targets Zimbra Mailservers with Half-Click Exploits IProofpoint) Endpoint security firm Glow emerges from stealth with $180 million. (N2K Pro Business Briefing) Being a Luddite Is Fun Again (404 Media) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
In this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections. LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR products. What once might have taken months of manual reversing can now be accelerated by “burning tokens”. The takeaway is that defenders increasingly need to assume attackers have visibility into how their endpoint security products work. Show notes
Nadav Cornberg, CEO of Eve Security, highlights the need for real-time security for agentic AI in healthcare environments to enforce policies and map agentic activities within an organization. There are unique risks posed by AI, such as ambiguity from natural language commands, the potential for unintended or malicious actions, and the amplified impact of a single AI error compared to human error. Nadav points out that many hospitals are likely unaware of the extent to which agentic AI is already active in their systems, and of why conducting risk assessments and policy reviews should be a priority. Nadav explains, "Eve Security provides two main services. One is our runtime security solution, which allows us to enforce policies when you connect any type of AI agent to a critical data source or system. The other solution that we provide is our AIDR, where we give you a full topology of what agentic activities are running in your organization. We do that by connecting to security systems like an EDR, NextGen Firewall, or your SIM." "Just like we'll see a manager in the employee environment, in the physical world, that's why we have managers as well to guide employees on the work they want to do. How that works is we sit either on top of existing gateways or proxies, and that's how you will connect those agents to critical systems, or we connect to hooks." "At the end of the day, the reality of how we're communicating and engaging with agents brings that new necessity. Existing security tools do not deal well with natural language. In addition to not dealing well with natural language, they're not doing well with trying to understand the true intent behind an action, and it's more built on static parameters. And that's the real gap that introducing AI agents into environments has brought. The risks are ambiguity and the unpredictable, non-deterministic behavior." #EveSecurity #AgenticAISecurity #SecurityatRuntime #AISecurity #HealthcareAI #PatientSafety #HospitalSecurity #AgenticAI #CyberSecurity #HealthIT #DataProtection Eve.security Download the transcript here
Nadav Cornberg, CEO of Eve Security, highlights the need for real-time security for agentic AI in healthcare environments to enforce policies and map agentic activities within an organization. There are unique risks posed by AI, such as ambiguity from natural language commands, the potential for unintended or malicious actions, and the amplified impact of a single AI error compared to human error. Nadav points out that many hospitals are likely unaware of the extent to which agentic AI is already active in their systems, and of why conducting risk assessments and policy reviews should be a priority. Nadav explains, "Eve Security provides two main services. One is our runtime security solution, which allows us to enforce policies when you connect any type of AI agent to a critical data source or system. The other solution that we provide is our AIDR, where we give you a full topology of what agentic activities are running in your organization. We do that by connecting to security systems like an EDR, NextGen Firewall, or your SIM." "Just like we'll see a manager in the employee environment, in the physical world, that's why we have managers as well to guide employees on the work they want to do. How that works is we sit either on top of existing gateways or proxies, and that's how you will connect those agents to critical systems, or we connect to hooks." "At the end of the day, the reality of how we're communicating and engaging with agents brings that new necessity. Existing security tools do not deal well with natural language. In addition to not dealing well with natural language, they're not doing well with trying to understand the true intent behind an action, and it's more built on static parameters. And that's the real gap that introducing AI agents into environments has brought. The risks are ambiguity and the unpredictable, non-deterministic behavior." #EveSecurity #AgenticAISecurity #SecurityatRuntime #AISecurity #HealthcareAI #PatientSafety #HospitalSecurity #AgenticAI #CyberSecurity #HealthIT #DataProtection Eve.security Listen to the podcast here
Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It's shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability scans. Meta faces trillion dollar fines in state lawsuits. Our guest is Russ Anderson, COO and co-founder of RapidFort, sharing a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. When it comes to breaches, mum's the word. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Russ Anderson, COO and co-founder of RapidFort, is sharing the Linux Foundation's Akrites initiative, a coordinated industry effort to harden the world's most critical open source software against AI-enabled cyber threats. Selected Reading Accenture confirms breach after hacker offers stolen data for sale (Bleeping Computer) Nationwide Telstra outage disrupts thousands, raises questions of foreign launched cyberattack (The Nightly) Britain plans to build autonomous AI 'Cyber Shield' to defend nation (The Record) CISA Eyes September Date for Final Cyber Incident Reporting Rule (MeriTalk) HUMAN Security Disrupts CTV Device Spoofing Operation "NewsJunkie" (Globe Newswire) When AI agents look like attackers: what behavioral telemetry tells us (SOPHOS) Space Force adds Relativity, Impulse Space to national security launch program. (Space News) CISA Deploys Anthropic's Mythos AI to Hunt Vulnerabilities in U.S. Government Code (Security Affairs) Mark Zuckerberg's biggest legal nightmare yet could cost Meta $1.4 trillion (The Independent) Most cybersecurity workers have been told to conceal a breach, report finds (Cybersecurity Dive) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but has evolved into a broader security data platform that can answer questions, drive hunts and drive detections. This product is engineered around the idea that a lot of security is a data problem. So, if we accept this premise, how do we solve security? And how much of that solution is about agents, vs building a good graph? And if you're going to build a good graph, do you want to build it for a person to use, or an agent to use? This is truly a conversation for the security nerd's nerd. Enjoy! This episode is also available on YouTube Show notes
Face à des cyberattaques toujours plus furtives, Benoit Grunemwald, expert cybersécurité chez ESET, décrypte les nouvelles stratégies des cybercriminels. Il explique comment l'intelligence artificielle, la supervision humaine et les nouveaux outils de protection transforment la défense numérique.
The US restores exports of Anthropic's most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-only ransomware. New Zealand faces questions about its cyber readiness. Iran's long-running cyber espionage campaign is back in the spotlight. Our guest is Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. VIP backstage access, courtesy of Claude. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Donald Codling, CISO and senior advisor to REGO on cybersecurity and data privacy matters, to discuss the importance of tying security by design to psychological safety and digital trust. Selected Reading Fable and Mythos: Anthropic says US lifts export ban on its advanced AI tools (BBC) Adobe patches seven max severity ColdFusion, Campaign flaws (Bleeping Computer) RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow (SecurityAffairs) Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb' Attack (SecurityWeek) Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs (Expel) Rocket Lab to Acquire Iridium in Historic Deal, Creating A Fully Vertically Integrated Space Powerhouse Primed for Growth (Globe Newswire) Ransomware that runs inside your browser tab, where antivirus cannot see it (Suriq) Three major cybehttps://suriq.io/blog/browser-only-ransomware-file-system-accessrattacks have raised alarms about New Zealand's security (RNZ) Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft (Zero Day) Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
This week on BHIS - Talkin' Bout [infosec] News, the team discusses the Polymarket supply chain compromise that led to the theft of millions from a small number of high-value accounts, emerging phishing campaigns abusing OpenAI invitations and Microsoft 365 device code authentication, and recent Oracle security updates. They also cover convictions tied to the Transport for London and U.S. healthcare intrusions, Google's Android earthquake warning system, concerns over MITRE ATT&CK evaluation methodology, and the ongoing debate surrounding threat intelligence researchers interacting with cybercriminals.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis
Ronald, Marco en Jelle zijn terug met AI-soevereiniteit, ransomware met eigen EDR-killers, een vals noodalarm in Brazilië, Chinese hackers in ArcGIS, je pincode afgeven aan justitie, smart-tv's als proxy en GPS-jamming vanuit de ruimte. Marco begint met Fable 5 en Mythos 5: frontier-modellen van Anthropic die onder Amerikaanse exportcontrole kwamen te liggen. Dat past in een bredere beweging van chipcontrole naar modelcontrole, met een ongemakkelijke vraag voor Europa: wat betekent AI-soevereiniteit als je modellen, chips en clouds alsnog afhankelijk zijn van Amerikaanse infrastructuur? Daarna The Gentlemen, een ransomwaregroep die zijn affiliates niet alleen encryptors geeft, maar ook eigen EDR-killers. Met BYOVD-technieken laden aanvallers kwetsbare maar nog vertrouwde drivers om securitytools uit te zetten voordat de ransomware-payload wordt uitgerold. Ook bij Marco: Brazilië kreeg een vals "Alerta Extremo" via het nationale noodwaarschuwingssysteem. De melding bevatte onder meer het woord "misantropia". De kern is niet alleen het hackverhaal, maar vooral vertrouwen: wat gebeurt er als mensen het noodalarm zelf niet meer vertrouwen? Jelle bespreekt Chinese hackers die ArcGIS misbruikten voor langdurige persistentie. Volgens ReliaQuest werd een legitieme Java Server Object Extension omgebouwd tot webshell, waarna SoftEther VPN Bridge toegang hield. Ronald bespreekt het afgeven van je pincode aan justitie. Volgens het Europees Hof voor de Rechten van de Mens is dat onder voorwaarden geen schending van je zwijgrecht. Maar een telefoon is geen kluisje met een paar documenten; het is een doorlopend logboek van je leven. Het hoofdverhaal van Jelle gaat over smart-tv's, PetFlix en de Bright SDK. Include Security onderzocht hoe apps op smart-tv's en mobiele apparaten een commerciële SDK kunnen bevatten die de internetverbinding van gebruikers inzet als residential proxy. Tot slot neemt Ronald ons mee naar GPS-jamming vanuit de ruimte. Onderzoekers zagen korte, brede storingen in GNSS-signalen boven Europa, Groenland en Canada en herleidden die tot Russische militaire satellieten. GPS is niet alleen navigatie, maar ook timing voor elektriciteitsnetten, financiële transacties, communicatie en andere kritieke infrastructuur. Bronnen: - Anthropic over Fable 5 en Mythos 5: https://www.anthropic.com/news/fable-mythos-access - White House AI executive order: https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/ - ESET over The Gentlemen: https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/ - Check Point over The Gentlemen-leak: https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/ - Brazilië / vals noodalarm: https://agenciabrasil.ebc.com.br/meio-ambiente/noticia/2026-06/sistema-da-defesa-civil-e-suspenso-apos-invasao-e-disparo-falso - ArcGIS / Flax Typhoon: https://www.bleepingcomputer.com/news/security/chinese-hackers-abuse-geo-mapping-tool-for-year-long-persistence/ - Pincode en zwijgrecht: https://blog.iusmentis.com/2026/06/19/je-pincode-moeten-geven-aan-justitie-is-geen-schending-van-je-zwijgrecht/ - Smart-tv / Bright SDK: https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/ - The Verge over PetFlix: https://www.theverge.com/column/885244/smart-tv-web-crawler-ai - Veritasium GPS-video: https://www.youtube.com/watch?v=tz23G_UXCGA - GNSS-paper: https://arxiv.org/html/2606.03673v1 DNS-blocklist uit Include Security: proxyjs.brdtnet.com proxyjs.luminatinet.com proxyjs.bright-sdk.com clientsdk.bright-sdk.com clientsdk.brdtnet.com
Enduro World Cup is back and there are new names at the sharp end of the results sheets. We've had breakout performances, surprise winners, and riders stepping into the spotlight who maybe weren't on everyone's radar a few weeks ago. But it's not just what's happening on track. The coverage itself feels like it's taken a step forward too. More access, more insight, and a better window into what's actually going on inside an EDR weekend. So in this episode, we're breaking it all down. The standout rides, the new characters emerging in the series, what's changed already in 2026, and what it might be telling us about where enduro racing is heading this year. Morgane and Greg join me to provide insight into what went on at the first two rounds in Loudenvielle and Leogang. Thiis is the start of something that already feels like a new era for EDR. So sit back, hit play and listen to this episode with Morgane Charre and Greg Callaghan. You can also watch this episode on YouTube here. Follow these accounts for great enduro coverage – @nextstagemtb, @catalyst.cc and @endurochronicles. You can download the UCI MTB World Series app here. Thanks Patreon I would love it if you were able to support the podcast via a regular Patreon donation. Donations start from as little as £3 per month. That's less than £1 per episode and less than the price of a take away coffee. Every little counts and these donations will really help me keep the podcast going and hopefully take it to the next level. To help out, head here. Merch If you want to support the podcast and represent, then my webstore is the place to head. All products are 100% organic, shipped without plastics, and made with a supply chain that's using renewable energy. We now also have local manufacture for most products in the US as well as the UK. So check it out now over at downtimepodcast.com/shop. Newsletter If you want a bit more Downtime in your life, then you can join my newsletter where I'll provide you with a bit of behind the scenes info on the podcast, interesting bits and pieces from around the mountain bike world, some mini-reviews of products that I've been using and like, partner offers and more. You can do that over at downtimepodcast.com/newsletter. Follow Us Give us a follow on Instagram @downtimepodcast or Facebook @downtimepodcast to keep up to date and chat in the comments. For everything video, including riding videos, bike checks and more, subscribe over at youtube.com/downtimemountainbikepodcast. Are you enjoying the podcast? If so, then don't forget to follow it. Episodes will get delivered to your device as soon as it's available and it's totally free. You'll find all the links you need at downtimepodcast.com/follow. You can find us on Apple Podcast, Spotify, Google and most of the podcast apps out there. Our back catalogue of amazing episodes is available at downtimepodcast.com/episodes Photo – Rick Schubert
We'd love to hear from you. Send us fan mail!Workplace dispute resolution is one of the least discussed and most costly blindspots in executive leadership. In this episode of Shedding the Corporate B!tch, executive coach Bernadette Boas sits down with Felicia Harris Hoss, of Harris Hoss Mediations & Arbitration, a nationally recognized mediator with 30 years of trial law experience, to break down early dispute resolution and why it is one of the most powerful, underutilized tools available to corporate executives and HR leaders.Felicia explains why less than five percent of filed lawsuits ever reach trial, what that means for how executives should be approaching conflict, and why the decision to mediate early is not a sign of weakness, it is a strategic move that preserves relationships, resources, and reputation. She walks through the four Cs of mediation, the questions every executive should be asking their attorney, and how to shift from a reacting posture to a responding one in any dispute.If you lead people, manage HR concerns, or sit in any seat where workplace conflict can escalate into legal action, this conversation will change how you think about resolution. What You Will Learn• What early dispute resolution (EDR) is and why it is ABA official policy• When to engage a mediator before a lawsuit is filed• Why litigation means surrendering control — and what executives can do instead• The four Cs of mediation: confidentiality, control, creativity, certainty• What questions to ask your attorney about workplace disputes and resolution options• How the respond vs. react mindset shifts negotiation outcomes• What 'winning' actually looks like in a corporate dispute Key Quote"If you go to the courthouse, you pass that baton called control to strangers. — Felicia Harris Hoss" Episode Chapters00:00:00 — The Legal Dispute Already Living in Your Organization 00:02:00 — Why Staying in the Room Changes Everything 00:03:00 — Meet Felicia Harris-Hoss: From Trial Partner to Neutral 00:06:00 — What Mediation Actually Is (And Isn't) 00:09:00 — Workplace Scenarios That Call for a Mediator 00:12:00 — Why Early Mediation — Before Positions Harden 00:13:00 — The Human Cost Behind Every Corporate Lawsuit 00:15:00 — Why Early Mediation Wasn't Working — And What Changed 00:17:00 — Ego, Fear, and the Real Reason Leaders Avoid Resolution 00:18:00 — The Courtroom Hands Control to Strangers 00:21:00 — The Four C's of Mediation: Confidentiality, Control, Creativity, Certainty 00:26:00 — Key Questions Every Leader Should Ask Their Attorney 00:27:00 — What to Know Before You Bring a Dispute to HR 00:31:00 — Why Even Lawyers Get Confirmation Bias 00:32:00 — Respond, Don't React: The Mindset That Changes Outcomes 00:34:00 — Bernadette's Takeaways for Every Leader and HR Professional About the GuestFelicia Harris Hoss, of Harris Hoss Mediations & Arbitration, is a 30-year trial attorney and nationally credentialed mediator who specializes in early dispute resolution for executives, corporations, and complex business conflicts. She co-authored Resolution 500 for the American Bar Association, which was unanimously adopted in 2024, making early dispute resolution official ABA policy. She also helped establish the American Arbitration Association's EDR Mediation Panel.Learn more at HarrisHossPLLC| Connect on LinkedIn HERE Related Episodes Employee Engagement Strategies That Actually Move the Needle with Ian Watts— HEREYour Calendar is Lying - The Timer Leadership Framework— HERESlow Down To Go Fast with Loretta Stagnitto — HERE Subscribe CTAIf this conversation gave you a new way to think about conflict, leadership, and control, subscribe to Shedding the Corporate Bitch on YouTube at @ShedtheCorpBitchTV for new episodes every week. You can also DOWNLOAD our free Leadership Gap Diagnostic and identify where your leadership needs the most attention right now. Support the show
A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration credential involved, and engaged CrowdStrike as Icarus threatens extortion, echoing earlier Salesforce token-theft campaigns affecting nearly 1,000 companies. Researchers also detail AriStinger, a new botnet infecting 4,000+ end-of-life D-Link routers to scan, proxy, tunnel, execute commands, and hijack DNS, with many infections in South Korea and China. The episode covers federal cyberstalking charges against Anthony Belford for allegedly using fake accounts and AI-generated nude images, and ESET's report that the "Gentleman" ransomware crew is developing modular EDR-killing tools to disable endpoint defenses. 00:00 Top Stories Teaser 00:29 Clue OAuth Token Breach 02:32 Salesforce Token Attack Trend 04:14 AryStinger Router Botnet 05:33 AI Deepfake Cyberstalking Case 07:50 Gentleman EDR Killer Arsenal 09:37 Wrap Up And Sign Off
Send us Fan MailYour endpoint tool can be world class and still get taken out first. That's the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a-service platforms, where affiliates can plug in advanced evasion without building it themselves. When attackers can blind endpoint detection and response before the ransomware payload runs, the old comfort of “we have EDR, so we're covered” turns into a single point of failure.We unpack the reporting on a highly active ransomware operation and its toolset, then zoom in on the technical path that makes this work: BYOVD, bring your own vulnerable driver. With admin access, attackers load a legitimate but vulnerable signed driver, escalate into kernel mode, and terminate security processes from below the privilege stack. From there, we shift to what matters for real security programs: defence in depth, kernel integrity protections like HVCI and KMCI, strict driver allow and block policies, and aggressive driver hygiene to reduce attack surface.Then we put on the CISSP lens. We tie the scenario to Domain 7 security operations (EDR limits, incident response, monitoring), Domain 3 security architecture and engineering (layered controls, hardening), and Domain 1 security and risk management (risk = threat × vulnerability × impact, plus threat landscape shifts). The big takeaway is simple: your job isn't to find the fanciest tool, it's to build a program that still works when one control fails and to communicate that risk clearly to leadership.If this helps you think like a manager and study smarter, subscribe for weekly CISSP-focused breakdowns, share the episode with a teammate, and leave a review so more people can find the show.Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-591
Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! Show Notes: https://securityweekly.com/swn-591
International law enforcement disrupts the SocGholish botnet. The UK's cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU's cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Critical patches land from F5, Atlassian, and Splunk. Agentjacking targets AI coding assistants. And Kodak confirms a breach claimed by ShinyHunters. Our guest is Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies on the failure of FISA section 702 to reauthorize. Criminal coders face automation anxiety. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined by Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies, and coh-host of Caveat, as he discusses the failure of FISA section 702 to reauthorize. Selected Reading Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp (Bleeping Computer) Hostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns (Infosecurity Magazine) Cyberspace Locked in a Nation-State Contest, Says NCSC CEO (BankInfo Security) EU grants Ukraine access to cybersecurity reserve for major attacks (The Record) Killing me gently: Inside Gentlemen's EDR killer framework (ESET) ShapedPlugin update flow hacked to infect WordPress sites (Bleeping Computer) F5 issues out-of-band patches for critical NGINX vulnerabilities (Bleeping Computer) Atlassian, Splunk Patch Critical Vulnerabilities (SecurityWeek) Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents (HackRead) Kodak Admits Data Breach After ShinyHunters Hack Claims (SecurityWeek) Cybercriminals Are Worried About AI Taking Their Jobs Too (Infosecurity Magazine) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
At Infosecurity Europe 2026 in London, Matt Ellison, Director of Sales Engineering EMEA & APAC at Corelight, joins Sean Martin to unpack the visibility gap widening across security operations. The SOC is either drowning in data or missing the data that matters most. Corelight, custodian of the open-source Zeek project, builds a platform that turns raw network traffic into evidence teams can actually use. Why do today's most evasive attacks slip past endpoint detection? Because they are designed to. Ellison points to typhoon-style campaigns staged from network and hardware devices specifically to avoid EDR. When a platform sees all of the network traffic moving backwards and forwards, those moves stop being invisible. Seeing more is only half the battle. Ellison describes teams trapped by a fear of missing something, switching on every "just in case" detection until alert volume becomes its own crisis. The real question shifts from "what fired" to "what does this actually mean for my environment." How do you investigate a detection you cannot see inside? A black box hands down a verdict with no evidence behind it. Corelight takes an open approach, exposing the data behind every conclusion so analysts can follow a flow to its root cause and apply the one thing no vendor ships: their own knowledge of the network. The proof tends to show up fast. Ellison recalls a proof of value where, within thirty minutes, the team surfaced sensitive information moving unencrypted across the network. Other finds are smaller but telling, like a finance team's certificate using a weak cipher. Corelight even names its catch-all logs plainly, the "weird" log and the "unknown" log. Visibility feeds compliance too. Frameworks like NIS2, DORA, and GDPR demand evidence, not a tool humming in the corner that no one reviews. Ellison previews a coming release that adds asset classification, identifying every device on the network and explaining the why behind it. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUESTMatt Ellison, Director of Sales Engineering EMEA & APAC, Corelight LinkedIn: https://www.linkedin.com/in/matthewrellison/ RESOURCES Learn more about Corelight, including customer stories: https://corelight.com Zeek, the open-source NDR project Corelight maintains: https://zeek.org Infosecurity Europe 2026 coverage from ITSPmagazine: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Matt Ellison, Corelight, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, network detection and response, NDR, Zeek, open source security, network visibility, threat hunting, SOC alert fatigue, EDR evasion, encrypted traffic analysis, NIS2, DORA, GDPR, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Estamos asistiendo al fin de los utilitarios y el Segmento A. Este tema me toca la fibra sensible porque afecta directamente al derecho a la movilidad de los más jóvenes y de las rentas más bajas. ¿Has intentado comprar un coche pequeño y económico últimamente? Es imposible. El Segmento A ha muerto. Modelos honestos y racionales como el Seat Mii, el Ford Ka o el Citroën C1 han pasado a mejor vida, y no por falta de clientes, sino por un "suicidio financiero" provocado por la normativa. El "impuesto" de la seguridad obligatoria Desde 2024, con implementación total en este 2026, la Unión Europea exige que todos los vehículos nuevos incorporen sistemas ADAS (seguridad activa). Hablamos de frenada de emergencia, asistente de carril, detector de fatiga y la famosa caja negra (EDR). Técnicamente, instalar estos sensores en un coche de 100.000 euros es insignificante, pero en un utilitario diseñado para costar 10.000 euros, supone un sobrecoste directo de unos 2.000 euros. Rediseñar el cableado y el salpicadero de un coche diminuto para que todo quepa dispara los costes de ingeniería. El fabricante se queda sin opciones: o vende el coche a 17.000 euros (y nadie lo compra) o deja de fabricarlo. La estocada final: La Normativa Euro 7 Si la seguridad hirió al segmento, la Euro 7 le ha dado la estocada. Para que un motor de 1.0 litro cumpla con los límites de óxidos de nitrógeno y partículas en condiciones reales de conducción, necesita un sistema de escape extremadamente complejo. Catalizadores de tres vías avanzados y filtros de partículas de última generación añaden otros 1.200 euros de coste mínimo por motor. La física y la química no entienden de presupuestos ajustados; limpiar los gases requiere metales preciosos y tecnología cara. El refugio de los SUV y la rentabilidad Las marcas han descubierto que es mucho más rentable vender un B-SUV que un utilitario tradicional. Mientras que en un coche de 12.000 euros el beneficio neto podía ser de apenas 500 euros, en un SUV basado en la misma plataforma el margen salta a los 3.000 o 4.000 euros. El valor percibido por el cliente es mayor, aunque la tecnología interna sea casi idéntica. Estamos pasando de una industria que buscaba motorizar a las masas a una que busca maximizar el beneficio por unidad. La falsa promesa del coche eléctrico Muchos dicen que el eléctrico salvará el segmento, pero la realidad industrial de 2026 dice lo contrario. Una batería con autonomía digna cuesta hoy cerca de 6.000 euros. Si solo la batería representa el 40% del coste total, es imposible fabricar coches eléctricos de 10.000 euros. El coche eléctrico pequeño se está convirtiendo en un segundo o tercer coche para familias de alto poder adquisitivo, no en una solución para el ciudadano medio. Consecuencias: Un parque móvil envejecido Al encarecer artificialmente los coches pequeños, estamos consiguiendo el efecto contrario al deseado. Como la gente no puede pagar un coche nuevo, mantiene su vehículo de 15 o 20 años. Estamos envejeciendo el parque móvil y, por tanto, contaminando más. Es la paradoja de la movilidad moderna: hemos legislado contra la sencillez y, al final, hemos expulsado a la población de la movilidad privada nueva. En el video de hoy recordamos clásicos como el Fiat Panda de segunda generación, el ejemplo perfecto de lo que hemos perdido: un coche indestructible, lógico y barato que hoy sería ilegal fabricar. Bienvenidos a la era donde la sencillez es un lujo prohibido.
Podcast: Industrial Cybersecurity InsiderEpisode: Five Federal Agencies. One Zero-Trust OT Briefing. Most Haven't Read it.Pub date: 2026-06-03Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationThe joint CISA, FBI, Department of War, Department of Energy, and Department of State briefing on adapting Zero Trust to operational technology landed on April 29. Has OT leadership read it?In this episode, Craig and Dino address how the European Cyber Resilience Act is quietly forcing US plants into failed audits, why IT teams still see less than a third of OT assets, how EDR tools are taking down $100K-an-hour packaging lines, and why only a handful of integrators in North America have a real OT cybersecurity practice. They walk through what zero trust and micro-segmentation actually look like inside a 20-year-old plant with flat layer-two networks, DLR rings, jump boxes, and Cradlepoint workarounds, and lay out the first concrete move every CISO and CIO should make to start closing the IT/OT gap.Chapters:(00:00:00) - Cold Open: How the European CRA Is Failing US Plants(00:01:30) - The April 29 CISA/FBI Zero Trust in OT Briefing Nobody Read(00:05:00) - Compliance Without Teeth: Why US Regulations Aren't Moving the Needle(00:07:30) - When CrowdStrike Shuts Down a $100K-an-Hour Packaging Line(00:10:30) - The Visibility Gap: IT Sees Less Than a Third of OT Assets(00:15:30) - OEM Resistance: The Million-Dollar, Six-Month Cybersecurity Tax(00:18:30) - The Cradlepoint Workaround: How Plant Managers Bypass IT(00:21:30) - Layering Zero Trust onto a 20-Year-Old Plant Without Rip-and-Replace(00:25:30) - Why Only 5–10 of 1,000 Integrators Have a Real OT Cyber Practice(00:31:30) - Where CISOs Should Actually Be Looking (Hint: Not RSA or Black Hat)Links And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you'd like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
In this episode, Raghu Nandakumara sits down with two heavyweights in cybersecurity: Dr. Anton Chuvakin (Google Cloud) and Erik Bloch (Illumio), for a candid, often funny, and occasionally sobering look at why detection and response keeps fighting the same battles it was fighting 20 years ago. From the birth of SIEM and the coining of "EDR," to the short-lived reign of XDR, to today's AI hype cycle, Anton and Erik trace the full arc of the industry's evolution and interrogate why, despite decades of tooling investment, the fundamental outcomes haven't changed. Alert fatigue, signal-to-noise ratios, and the needle-in-the-haystack problem remain as stubborn as ever –and the slides security teams are building in 2025 look suspiciously like the ones from 2003. Raghu, Anton, and Erik discuss: Why the SOC still largely runs on a 1990s operating model and what it would actually take to change that How compliance pulled SIEM away from detection for over a decade and why that hangover still lingers Why a handful of engineering-led organizations (Google, Netflix, a European bank) have cracked the code while nearly everyone else keeps applying band-aids The pharmaceutical industry analogy that explains why security startups keep building band-aids instead of solving root causes What MDRs are doing right and why enterprise SOCs have no incentive to learn from them Why AI is accelerating tooling but, for some organizations, actually slowing down the harder transformation work How securing AI is repeating the exact same mistakes made in the early days of cloud Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com
https://youtu.be/sUyjA0muVgM Tom Kirkham, Founder and CEO of Kirkham IronTech, believes business should create value for everyone involved — employees, clients, vendors, and the broader community. After overcoming major personal challenges and rebuilding his perspective on leadership, Tom embraced stakeholder capitalism and built a company culture focused on long-term partnerships, trust, and continuous learning. In this conversation, Tom shares the IronTech Framework — a practical approach to modern IT management built around three core pillars: Generate ROI and Productivity, Make Cybersecurity Core, and Surround it with a Governance Layer. He explains why businesses should stop treating IT as an expense and instead view it as a strategic investment that improves productivity, protects the company from cyber threats, and aligns technology with leadership goals. Tom also dives into the massive scale of the cybercrime industry, why governance is often the missing piece in cybersecurity, and how proactive IT strategy can dramatically improve business performance. — Turn Your IT into Your Growth Engine with Tom Kirkham Good day. Steve Preda here with the Management Blueprint Podcast, and today’s guest is Tom Kirkham, the Founder and CEO of Kirkham IronTech, where he helps businesses build strong, secure IT foundations, whether fully managed, co-managed, or cybersecurity only. Tom is a keynote speaker on cybersecurity, and he’s the author of two books, Hack the Rich and The Cyber Pandemic. Tom, welcome to the show. Oh, it’s great to be here, Steve. Well, great to have you here. And I am curious to dive in, and would like to ask you my favorite question. What is your personal ‘Why’, and how are you manifesting it in Kirkham IronTech? That’s a great question. So the company’s about twenty-six years old. I went through a lot of personal health problems, and then my wife was real sick, and she ended up passing away—it's been about eleven years ago now. And I was fortunate enough to put a friend of mine in the company, and he was able to take over while I was dealing with this for a couple of years. And when most of it was done, I took some time off and did a lot of traveling and a lot of thinking and a lot of reading. And I’m a lifelong reader, a lifelong learner, and I went back through my history of investing techniques, understanding what makes a good company great. If you’ve read Jim Collins, you know what I’m talking about. And so during those times, I was reflecting, studying philosophy, studying biographies of other CEOs like Elon Musk, Steve Jobs, Andy Grove—gosh, the list goes on and on. Whether you like them or hate them, it doesn’t matter, right? There’s always something you can learn. And I came upon and read a lot about stakeholder capitalism. Like Peter Drucker says, “Culture eats strategy for breakfast.” And I understood what that meant, and it was kind of weird. So when I re-engaged with the company, I identified one of the weaknesses, and I said, “Well, if we need to do marketing in this business—which we have to do in any business—I really need to master marketing.” So I spent a lot of time with marketing gurus, most of them are what I would consider household names these days, and re-engaged with the company to do marketing to establish a great culture around stakeholder capitalism. In other words, we exist as a for-profit business not just for the shareholders but for everyone—the community, vendors, employees. And I really wanted to be around people I enjoyed being around. I wanted them to enjoy coming into work.Share on X And so we’ve been trying to perfect that system in the culture for the past ten years. Of course, no one's perfect, but if you pursue perfection, you can achieve excellence. And I think we've done a really good job. We have very low turnover. Everyone seems genuinely happy to be there, and it's really fulfilling. It's more of a personal feeling because I've been a successful investor practically my whole adult life. I started investing in stocks when I was nineteen, and I'm sixty-four now. So I didn't really need the company. I could have just closed it up or sold it or whatever. But I really wanted to have my own reasons. Those are the things that drive me, and I hope they drive everyone else too. What resonated with you with this idea of stakeholder capitalism? It just made sense. The obvious part is with employees—all of that is true. That's obvious to any good leader or manager, right? As you well know, there's a difference between leadership and management, and understanding that distinction, and the difference between sales and marketing, and understanding those things. A good example is dealing with vendors. There are all sorts of vendors that supply products and services to us, so we carefully vet these tools and vendors to see if their values align with ours, just like we do with prospects. But especially with vendors, if it's something new—a new tool that we're going to invest a lot of time, money, and energy into to make their product or service successful for us and successful for them—we make a commitment to that vendor. So it's not about the money or how cheap I can get it. What I want is a good partnership with every stakeholder. And I want to make sure that when I'm dealing with a vendor, if it fails for us, it's not our fault—it's their fault, right? Either they oversold the product or they didn't deliver on the service component. I didn't want it to be because we failed to do the right training, or didn't communicate properly, or missed all the other things that are just part of doing business the right way. And that applies to our employees, our local community, and every stakeholder in the company. Yeah. I like it. So you're looking for partnership-based relationships where it's win-win. And yeah, if you want people to stick around, it has to make sense for them too. You can't exploit your partners forever without consequences. So that makes a lot of sense. So Tom, let me ask you this other question. This podcast is called The Management Blueprint because I'm always looking for frameworks—something practical that helps businesses achieve results. Usually it's some kind of three-to-five-step process that helps you grow the business, get customers, improve operations, or understand something at a deeper level. So when I ask about your favorite business framework, what comes to mind? Well, we have a thing we call the IronTech Framework. Okay. And it was something that we came up with many years ago and started practicing seven or eight years ago, and it's a framework. It's like the NIST Cybersecurity Framework. I looked at NIST and there's five components to it, and it's about cybersecurity. And I looked at this and I go, “None of this works without the right policies and procedures in place.” The security training—it's not enough just to throw it out there and tell all your people to take it. You've got to follow up, you've got to manage, and coach, and everything like that. And so I started adding this governance component to the way we sold it, presented it, and practiced what we do for our clients day in and day out. Help them develop the policies and procedures for all of the different things, the protocols. If somebody accidentally fires off a ransomware attack, they need to know they're not going to be penalized for it. We need to know as soon as possible to stop it. And just little things like that, there's a lot that really improve the effectiveness of all of these tools and services that we provide to their clients. And unbeknownst to me, NIST, who has the cybersecurity framework, they added governance about three years ago to the other five things. And so that was kind of nice to know that we were exhibiting some thought leadership. And so when we go in, it's all well and good if you want to put these protections in and these particular products, but we're a best-of-breed company. Like one of our critical tools that's required for our clients to put in place, to buy it and use it every single day on every single computer, is what's known as an EDR. And it's basically an AI-based super turbo antivirus. To even call it an antivirus is not doing it justice. So there's three legs to the IronTech Framework. We want to make sure that you're getting a return on your investment in IT, because that's why you buy it. If you treat IT as an expense, you need to kind of change the way you're thinking. You want to improve productivity and efficiency.Share on X The second leg is cybersecurity, because a bad cyberattack can put you out of business. I think the last stats I saw were something like 40 to 60% of businesses go out of business within two years of a significant cyberattack. And then finally, the third is governance. That's the three legs of our IronTech Framework. So part of governance is engaging with our clients' management and leadership—the CEO, finance, of course the CIO, the CISO or security officer, and maybe even the board sometimes. Really getting to know: what are your objectives, and how can we utilize our services to best help your company realize those objectives? Because for most companies, there's no other vendor they engage with as much as us. We're talking to Susie every day. We're talking to Bill every day. We know that Mary's out sick and Steve's on vacation. I mean, when you're running help desk, stopping attacks, providing training, and all the support we provide along those lines, we get to know their company better than practically any other vendor by far. So it really helps if our clients treat us as a partner to help them realize their goals and objectives. And when all of that clicks into place, then it makes recommending things easier.Share on X “Okay, you need to replace these 30 laptops that are four years old. You're not getting an ROI on them.” “This server's five years old. Let's start thinking about replacing it.” “We have this new tool that's really excellent. We're recommending everybody get it.” And because we've developed that trust, those conversations become pretty easy. For the most part, everybody just says yes. But of course, we don't sell just to sell, especially when it comes to things like hardware. That's not really what we're here for. We're here for the day-in, day-out work: keeping things running, stopping breaches, and putting the policies and procedures in place to run your company as smoothly as possible. Yeah. I love that. So when I had an IT back in the 2000s, I had an IT person who was a contractor, but he was very active in my business, and I always wanted to talk to him and pick his brain. What are the new things out there? How can we make our business more efficient, more effective, more attractive to employees? Cooler. I wanted to be cool. So I wanted everyone to have a PDA in the early 2000s with email on it—a PalmPilot. And we had multiple screens, and I was looking at, okay, how can we manage data in the cloud and on our server so we don't have to deal with it in the office? That kind of stuff. And I really thought about it as a great investment because it was much cheaper than hiring people. And if you give people good tools, they're going to be more motivated and more effective. So I thought it was a no-brainer. Yes, but there's still a subset of people that treat IT as an expense. Then there are some companies that tend to put IT under the finance guy because the finance guy usually has a lot of IT experience, but never actually did it as a career or a job, right? And those situations are hard because I need CEO-level or owner-level approval, and I need a direct route to that person. Yeah, that makes sense. So Tom, tell me, what drives growth in your business? Yeah. From a growth perspective, for us, number one is maintaining our clients and reducing churn. Number two is—I don't know if you're asking about tactics or strategy—but of course we want to get new clients for the right reasons. So we prefer inbound strategies. We don't cold call people unless we've already contacted them in another way, if that's what you're asking. Yeah. I'm asking what the real driver of growth is. I understand that you do marketing and inbound marketing, but what makes people want to have an IT service partner like you? Well, they understand those three pillars of the IronTech Framework. They may not believe in stakeholder capitalism, but they don't treat IT as an expense. And they understand—especially after talking to me—the true risk of being hacked. A lot of people don't understand the size and scale of that industry. It's a $10 to $12 trillion industry now. Wow. If it were a country, it would have the third-largest GDP. The US would be first, China second, and then the hacking industry. It is an industry that hacks at scale. So when these companies—maybe a small 10-person accounting firm in North Dakota in the middle of nowhere—get these ransomware emails and someone tries to hack them, and we alert on it and trap it, and nothing goes wrong, everything's fine… If they don't already understand it, they go, “Well, why are they trying to hack me?” And I say, “You don't understand. That email was one of 100,000 emails that got blasted out. They don't know who you are, nor do they care who you are.” They're playing a numbers game. And it's kind of like marketing. They're looking at conversion numbers. Yeah. Let's say it's 100,000 emails. They got a list of all the certified public accountants in 10 different states. They set up the email, they send it all out, and let's say 1% become victims. And let's say they collect an average of $10,000 per victim. Well, that's a multi-million dollar payday for about a week or two of work. And then they rinse and repeat. It's done at scale, and it's a much bigger industry than that. That's just a taste of it. Some of our clients are targeted. In other words, hackers are investing time, money, and energy specifically into that company. We're one of them. Any law firm that does intellectual property law—especially around patents, manufacturing, and things like that—you've got China and other nation states not only trying to get into your client, but you're also a threat vector. You're a way to get into that client's patents and secrets. So we've got to treat that differently. It's not just about the money. There are different types of threat actors, and we have to educate clients, bring them up to speed, and say, “Well, because of this case, you need this other service and tool that we're offering to prevent China from breaking in.” Or, “You need to follow this practice.” Maybe you don't publicly talk about one of your clients being Ford Motor Company or NVIDIA. You just keep that quiet. You don’t want that to be public knowledge. That's one of the things we do. You spent time on our website, and you didn't see a single client name on there. And that's just one of the small things we do to protect our clients' security and privacy, because privacy and security go hand in hand. Yeah. That is fascinating. So what is it that you’re trying to figure out in your business right now? What’s the big thing for you? I think because of all the chaos in the United States, making a decision to do anything—everybody's kind of frozen. There are a lot of hiring freezes. I know we've got a freeze on right now because we're looking to see, well, do we really need to add somebody, or can we do this with AI? The hackers do the same thing. That's one of the challenges, is getting people over the hump. No matter what you do, if you've got an IT company doing your stuff and you only call them when things are broken, there's a much more profitable way to do that. You're spending more money. So there are benchmarks in industries, right? Basically, the research—and these aren't numbers we made up, this is legitimate research from many independent sources—says the average professional service provider, like law firms, accounting firms, healthcare providers, and on and on, should be spending 6 to 12% of their revenue on IT and cybersecurity. And that's everything. I'm talking servers, wiring, cloud, security, defense—all of those things should be 6 to 12%. We know that. That's the way it works. So when we engage with a prospect and find out they're only spending 3 or 4%, then I already know they have gaps. I don't even have to do an assessment to see what they're not doing. They're either not getting a return on investment, or they're not secure. That's it. If all the accounting firms are spending 6%, and you're only spending 4%, don't just pat yourself on the back. That's one of those moments where you should ask, “What am I missing?” Because I do that often. Someone on the management team will come up with an idea, and we all agree. Well, that's a red flag for me. I want to know: what are we missing? If we all agree on this, is there some gotcha or something we haven't uncovered? And those are some of the things we try to educate our clients on. They don't have to tell us their revenue. I can give them the numbers. I can do the math. I can show them the numbers for something like laptop replacement. Maybe it's $1,000 to $3,000 depending on the industry. If the employee using that laptop is making $100,000 a year, why are you trying to squeeze another year out of a $2,000 investment when it's hurting productivity by 10% or more? Yeah. That’s a no-brainer. Yeah. It should be. Yeah. It's not just in IT. I had a client years ago in civil engineering, and they had a rule that they would never keep equipment longer than four years. And they were selling equipment that still looked brand new. And I asked them, “Why are you doing this? It seems like this equipment still has a lot of life left in it. Why are you selling it or giving it back to the lease company?” And he said, “We did the math, and we figured out that this is the optimal time to replace it.” If they got rid of the equipment at that point, they wouldn't have to deal with fixing it. There would be less disruption. They would stay state-of-the-art all the time. And their clients would be impressed. And it actually worked for them. It was a high-margin civil engineering firm. Precisely. I mean, we're so tuned into that that we're a Mac house. We all use Macs. We all have laptops, and we all have setups with screens at home and in the office. We spare no expense on that. If somebody wants an extra screen for their house—alright, here it is. We'll order it and get it there for you. We're so tuned into that, that we went all Mac back when they were still Intel Macs. And I don't know how much you know about Macs, but they were… I have a couple. Okay. Yeah, we're Mac people too. Yeah, so they were running Intel processors. Well, Apple decided to build their own processor and moved to the M-chip. And so I bought an M1, and it was like, holy cow, everybody in the company has got to have one of these. And I don't think there was a single one more than two years old at that time. So we replaced them all. Now, the M-series generations themselves—M1, M2, M3, and on—those changes aren't as dramatic as going from Intel to the first M-series chip. But it's still unusual. I said two years, but there are probably people right now with a three-year-old laptop. But we definitely trade them in. That's where the sweet spot is on trade-in value. We rotate them every two to three years and they're out. I think mine is maybe a year old, but I'll probably keep this one for a couple more years. By the way, you're the first IT company and MSP I've met that doesn't use PCs—you use Macs. Yeah. And I long had this theory that all the IT companies I worked with were always anti-Mac, and I never understood why. And when I got my first Mac, I realized I actually didn't need them anymore since I had the Mac. Yeah, that's kind of funny because it really started with me during Covid. It may not have been seven years now, but whatever it was, it kind of started with Covid. And for years I was a PC guy. I tried Macs briefly back in the old MacBook days—you know, the white plastic ones? Whatever that was, 15 or more years ago. Yeah. Classic. Very classic. Yeah. But what I kept trying to do with a Windows laptop—and I like Dell, I had Dell XPSs, good Dell computers, and we're a Dell partner— What I could never get a Windows computer to do was seamlessly come off a docking station and then plug into another monitor at my house. It would always blue screen or something. So when I went back to a Mac, I was like, “Holy cow, it doesn't break. It doesn't mind being unplugged from a docking station. It just works.” Yeah. And then all the other things—that they're generally built better, they have a longer lifespan, and they hold their resale value longer, and all of that. Even as old as I was, I forced myself to really get proficient at using a Mac. And when we sent everybody home during Covid, I said, “Well, everybody's going Mac.” And, oh, there was a revolt. And I said, “Just give it a few months.” Yeah. About half the office resisted it. And I said, “You gotta try it because I think you'll like it, and if you don't, then we'll deal with it then.” We had Linux people, PC people. So then I said, “Well, maybe we should open it up and let people pick what they want.” Yeah, I love it. Yeah. So our time is coming to an end, but if someone is running on Mac and they're finally talking to an IT service company that's not anti-Mac, and they want to connect with you immediately, where should they go and where can they learn more about Kirkham IronTech and maybe connect with you personally? The website is the best place to go. It's www.kirkhamirontech.com. Just give us a call, fill out a form, let us know what you're thinking, because we want to know what you're thinking and see if there's a fit with the way we do things. Macs started becoming important with executives. That's where we first started seeing it. So even though they may still have to run Windows, the owners and executives wanted to carry Macs for the very reasons I mentioned. So we're perfectly happy with that. Yeah. Okay. Very good. So if you're listening to this and you enjoyed hearing about how to make your IT work—how to increase ROI, make sure you're doing cybersecurity right, and implement governance so you can use IT as a strategic tool to run your business better—then definitely reach out to Tom Kirkham. Or stay tuned to this show, because you're going to hear from other entrepreneurs who are very smart about business. And preferably do both. Tom, thank you for coming and sharing your wisdom, and thank you for listening. Oh, it’s been my pleasure, Steve. Important Links: Tom's LinkedIn Tom's website
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460
Basic cyber hygiene — patch management, password management, and MFA — is responsible for stopping roughly 90% of the ransomware attacks that could hit your organization. This episode is the overview: what those three things are, why they matter, and what happens when you skip them.WannaCry infected over 200,000 systems worldwide. A patch existed. People just hadn't applied it. Rackspace lost an entire business line — not because the attack was sophisticated, but because a workaround gave them false confidence and they delayed a critical patch. These aren't edge cases. They're the rule.Dr. Mike Saylor (Black Swan Cybersecurity) and Prasanna Malaiyandi join me to walk through the three pillars of basic cyber hygiene. We cover patch management first — and before you can even patch, you have to know what you have. Inventory is the starting point. Then we get into passwords: why reusing them is a numbers game the bad guys always win, and why a password manager isn't optional anymore. Finally, MFA — what it is, which forms are actually worth using, and why "remember this device" is quietly defeating the whole point.This is an overview episode. We're going deeper on each pillar in three follow-up episodes. But if you're not doing these three things today, stop reading this and go do them. There's no point talking about EDR, XDR, or any other three-letter security product if you haven't nailed the basics first. It's like researching a Roth IRA when you don't have a savings account.Chapters:0:00 Intro0:59 Welcome & Introductions4:20 WannaCry: The Patch That Would Have Saved 200,000 Systems7:33 Rackspace: When a Workaround Isn't Enough12:12 Defining Basic Cyber Hygiene14:53 Why These Three Things Stop 90% of Ransomware17:54 Pillar 1: Patch Management23:55 Pillar 2: Password Management31:55 Pillar 3: MFA & Passkeys37:34 Wrap-Up & What's Next
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-460
Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic: Do the basics, they said. Easier said than done. Guillaume and Adrian discuss the futility of attempting to do all the foundational work standards, best practices, and regulations expect of organizations. Adrian has given up. Fortunately, Guillaume has some excellent advice and hope to share on this front. The weekly enterprise news Finally, in the enterprise security news, a really interesting vibe check funding acquisitions the verizon DBIR we give a tutorial on how to leak AWS keys on github OH NEVERMIND, SOMEONE AT CISA ALREADY MADE THE TUTORIAL agents versus agents exploitbench the vulnpocalypse robot dogs are SO EASY to take out, we don't need to be too scared of them yet All that and more, on this episode of Enterprise Security Weekly. Show Notes: https://securityweekly.com/esw-460
Agentic AI was the theme that pulled away from the pack at RSAC Conference 2026. Tony Anscombe of ESET makes the case that once AI shifts from being directed by humans to operating with its own objectives and logic, the security surface changes with it, and organizations are being forced to rethink what they protect and how. At the show, ESET announced two products that meet that moment head on. The ESET AI Skills Checker is a free-to-use tool coming to market. ESET AI Protection looks inside AI sessions on the endpoint, flagging sensitive data leakage, malicious links returned by AI systems, and suspicious behavior, and surfacing it all inside normal cybersecurity operations for investigation, blocking, or detection. Tony closes with a reminder worth keeping. His first RSA was in 1998, and the technology he worked on then (sandboxing, dynamic code, remote windowing, encryption, authentication) mirrors a lot of what walks the RSAC Conference floor today. The packaging evolves, the core principles do not. Build forward, but do not lose sight of what the past already proved. This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight GUEST Tony Anscombe, Chief Security Evangelist, ESET LinkedIn: https://www.linkedin.com/in/tonyanscombe/ RESOURCES Learn more about ESET: https://www.eset.com ESET AI Skills Checker and ESET AI Protection: https://www.eset.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Tony Anscombe, ESET, Sean Martin, brand story, brand marketing, marketing podcast, brand highlight, agentic AI, AI security, RSAC Conference 2026, threat intelligence, MDR, EDR, endpoint security, AI Skills Checker, AI Protection, cybersecurity community, multifactor authentication, cybersecurity evolution Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-448
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Show Notes: https://securityweekly.com/bsw-448
A dangerous new Microsoft Exchange zero-day is being actively exploited, ransomware gangs are adopting nation-state-style tactics, two fired contractors were caught deleting U.S. government databases after accidentally recording themselves on Microsoft Teams, and Fortinet has patched critical remote code execution flaws. In this episode of Cybersecurity Today, David Shipley breaks down four major cybersecurity stories that security teams need to know. Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security Microsoft has confirmed active exploitation of a new Exchange Server zero-day, CVE-2026-42897, affecting Exchange Server 2016, Exchange Server 2019, and Exchange Subscription Edition. There is currently no patch, only mitigations through the Exchange Emergency Mitigation Service, with some trade-offs for Outlook Web App users. Security researcher Marcus Hutchins highlights an unusually disciplined ransomware affiliate operation using tradecraft more commonly associated with nation-state attackers, including a custom SentinelOne endpoint detection and response (EDR) killer and a stripped-down toolset designed to leave fewer forensic traces. In one of the more astonishing insider threat stories of the week, former OPEX Corporation contractors Muneeb and Sohaib Akhtar were allegedly caught deleting 96 U.S. government databases after leaving a Microsoft Teams recording running. Also in this episode: Fortinet has released urgent patches for critical unauthenticated remote code execution vulnerabilities in FortiAuthenticator (CVE-2026-44277) and FortiSandbox (CVE-2026-26083). If you're responsible for enterprise security, patch management, incident response, or cyber risk, this is one you need to see. Chapters: 00:00 Sponsor Message 00:24 Headlines Intro 00:49 Ransomware Nation-State Discipline 04:18 Exchange Zero-Day Mitigation 07:01 Fired Contractors Caught Recording 09:21 Fortinet Critical Vulnerabilities 11:07 Wrap Up and Sign Off 11:38 Sponsor Deep Dive Ad #Cybersecurity #MicrosoftExchange #ZeroDay #Ransomware #Fortinet #CyberAttack #Infosec #DavidShipley #CybersecurityToday
Greg Murphy of Vectra AI explains why no single security tool is enough in 2026, and how AI is transforming overwhelmed security teams into lean, highly responsive defense operations.Topics Include:Vectra AI helps enterprises detect and respond to cyberattacks before they become breaches.CISOs face millions of alerts monthly with dangerously understaffed security teams.Vectra pioneered AI-driven triage to prioritize only the most critical threats.The result: analysts act on two or three alerts, not thousands.Generative AI is now actively being weaponized by sophisticated bad actors.The first fully AI-orchestrated cyberattack by a nation state has already happened.Vectra and AWS Bedrock are building autonomous agents to fight back.Agentic AI can investigate thousands of incidents and surface only what matters.Over-reliance on single tools like EDR leaves dangerous gaps in defense.Modern attacks move fluidly across identity, network, and cloud environments simultaneously.AI stitches cross-surface signals together, revealing attacks hidden in isolated events.Best practice: assume breach, expand your network definition, and layer best-of-breed solutions.Participants:Greg Murphy – Chief Business Officer, Vectra AISee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon.com/isv/
In this episode, Ken Westin maps AI adoption onto the hero's journey framework, drawing on two decades of security experience to explore how practitioners can move past early resistance, build real fluency with AI tools, and find a working model where humans and AI operate together.Key Topics:Why early AI tools left security teams skeptical and what has genuinely changed since thenHow Ken used AI to accelerate detection engineering without sacrificing analyst oversightWhy AI is best understood as an eager, overconfident intern that still needs supervisionThe importance of hands-on experimentation over passive observation when learning AIHow collaboration and shared prompting practices are shaping how practitioners learnWhy security analysts who engage with AI now will not be left behind as the field evolvesThe case for AI as a tool of empowerment, not replacementAt Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.About Our GuestKen Westin is a Senior Solutions Engineer at LimaCharlie with nearly two decades in the cybersecurity industry. A former startup founder who built tools to track criminal activity, Ken has worked across SIEM, EDR, and detection engineering throughout his career. He also teaches at the college level, where AI and cybersecurity are increasingly intertwined disciplines.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.Why LimaCharlie?Eliminate vendor sprawl and tool complexityDeploy and scale effortlessly on native multi-tenant architectureReduce costs with intelligent data routing and free 1-year retentionBuild custom solutions with 100+ security capabilities on-demandAccelerate response with agentic AI that acts directly within predefined workflowsTry the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieioX: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - Founder at LimaCharlieGuest: Ken Westin - Senior Solutions Engineer at LimaCharlie
Cybersecurity is no longer a nice-to-have for government contractors — CMMC compliance is now a pre-award requirement, and if you haven't addressed it, your proposal may be dead before anyone reads it. In this episode, Eric sits down with a 15-year MIT Lincoln Laboratory veteran whose company now trains US Cyber Command to break down exactly what small and mid-size contractors need to know about cyber readiness in a rapidly shifting AI-driven threat landscape. Here's what you'll learn in this episode: Why CMMC and FedRAMP exist — and why meeting the minimum standard is just the floor, not the finish line, for contractors serious about winning DoD business How AI is accelerating cyberattacks on small businesses — attackers are using the same tools you use to run your business, and they're moving faster than ever What a cyber range actually is and how it works — the fire drill analogy that explains why buying tools without training your team is money wasted The right cybersecurity stack for small contractors — endpoint detection and response (EDR), firewalls, and SIEMs explained in plain language with practical starting points How to stop overspending on tools you don't use — why most CISOs only fully utilize a third of their security tools and how to build a lean, effective stack instead What AI adoption inside your company is actually exposing — prompt injection, data leakage, and the governance controls that protect your sensitive contract data EPISODE CHAPTERS: 0:00 - Sponsor message and why cybersecurity just became mandatory 0:53 - Introducing a 15-year MIT Lincoln Lab cyber expert 6:01 - How the guest built cyber infrastructure for national defense 7:25 - What cyber ranges are and how they work for DoD training 9:16 - The fire drill analogy for understanding cyber readiness 11:07 - Why buying tools without training your team is not enough 13:28 - How the threat landscape has evolved from servers to cloud to AI 16:17 - CMMC and FedRAMP explained as a minimum bar for contractors 19:38 - The real-world financial losses that finally force action on cyber 25:21 - Building a practical cyber stack for small business contractors 31:17 - How AI is changing team size, efficiency, and detection capability 33:36 - Where AI adoption inside your business is creating new vulnerabilities 37:00 - How cyber range assessments work and how long they take 42:14 - What the next five years looks like for cybersecurity in govcon If you want to learn more about the community and to join the webinars go to: https://federalhelpcenter.com/ Website: https://govcongiants.org/ Connect with Encore Funding: http://govcongiants.org/funding Connect with Lee Rossey: https://www.linkedin.com/in/lee-rossey-0873881/